Overview
Description
Statistics
- 8 Posts
- 27 Interactions
Fediverse
Watchtowr got RCE via one of the many Citrix Netscaler SAML vulns. https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
RE: https://infosec.exchange/@watchTowr/117092605469478412
Si vous n’avez pas encore patché la RCE NetScaler du mois de juin :
https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX696604
ChatGPT dit que c’est probablement le dernier moment de le faire avant qu’il utilise ça comme opportunité pour s’échapper de sa sandbox.
Parce que, bien évidemment, la fine équipe de watchTowr vient de publier le write-up qui transforme le gentil « memory overflow » en RCE pré-auth root.
#CyberVeille #NetScaler
👇
https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452 https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/
Bluesky
Overview
- VMware
- Cloud Foundation
Description
Statistics
- 7 Posts
- 13 Interactions
Fediverse
「VMware vCenterの重大なリモートコード実行(RCE)の脆弱性が悪用され、リバースSSHアクセスが行われた。 」: #BLEEPINGCOMPUTER
「VMware vCenter Syslog Serverに存在する、最近パッチが適用された重大な脆弱性(CVE-2026-59310)が、永続的な接続とリモートアクセスを目的としたリバースSSHツールの展開を目的としたアクティブな攻撃キャンペーンで悪用されています。
47か国にわたる361のIPアドレスで侵害が確認されており、その半数以上はドイツ、米国、トルコ、イラン、フランスに位置している。
Broadcomは7月29日にCVE-2026-59310を公開し、 vCenter Syslogサーバーにおける重大なディレクトリトラバーサル脆弱性 であり、ネットワークアクセス権を持つ認証されていない攻撃者が悪用して任意のコードを実行できる可能性があると説明した。 」
⚠️ CRITICAL: Global Threat Campaign Hits Critical VMware vCenter Flaw
Active exploitation of CVE-2026-59310 in VMware vCenter Server is ongoing. All organizations running vCenter are at risk of compromise. Patching alone may be insufficient due to suspected persistence mechanisms already deployed by threat actors.
🤖 AI generated summary
⚠️ CRITICAL: Critical VMware vCenter RCE flaw exploited for reverse SSH access
A critical directory traversal vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being actively exploited in the wild to deploy reverse SSH tools for persistence. At least 361 compromised hosts across 47 countries have been identified, with attackers establishing remote access on vi…
🤖 AI generated summary
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
📰 WordPress patches critical RCE flaw (CVE-2026-65640) for author-level users
WordPress 7.0.4 patches a critical RCE flaw (CVE-2026-65640, CVSS 8.8). Authenticated authors could take over sites using a malicious image file on servers with Imagick. Update your WordPress sites immediately! #WordPress #RCE #CyberSecurity
Bluesky
Overview
Description
Statistics
- 3 Posts
Fediverse
⚠️ CRITICAL: Lazarus hackers exploited Windows zero-day to target defense firms
Lazarus Group is actively exploiting Windows zero-day CVE-2026-68820 to target defense, aerospace, and aviation firms worldwide. The vulnerability enables privilege escalation to SYSTEM level and is being weaponized alongside a new backdoor called Troy. Compromised Roundcube instances have also bee…
🤖 AI generated summary
Bluesky
Overview
- Microsoft
- Windows 10 Version 22H2
Description
Statistics
- 1 Post
- 32 Interactions
Fediverse
RE: https://infosec.exchange/@wdormann/117089673520623548
I wrote some detections for CVE-2026-66804 exploitation:
https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/CVE-2026-66804.kql
Overview
- SAP_SE
- SAP Commerce Cloud (Data Hub Adapter)
Description
Statistics
- 2 Posts
Fediverse
Apple Partners With Alibaba to Launch China-Specific AI Model – DTH
[🖼 DTH-6-150x150]France’s Top Court Strikes Down Proposed Social Media Ban for Minors, Google Launches Gemini 3.7 Flash to Boost AI Performance, and the White House Imposes 100% Tariffs on Drones to Boost Domestic Manufacturing and Security.
Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.
A special thanks to all our supporters–without you, none of this would be possible.
If you enjoy what you see you can support the show on Patreon, Thank you!
Send email to feedback@dailytechnewsshow.com
Show Notes
Apple Develops AI Model for China With Alibaba
Apple has developed a proprietary large language model for the China market in partnership with Alibaba, signaling a strategic shift to better compete against domestic rivals. This initiative, designed to integrate with Apple Intelligence, aims to navigate local regulatory challenges and restore Apple’s competitive edge in a critical market where the absence of AI features has previously impacted sales.
France’s Highest Court Rejects Social Media Ban for Children Under 15
France’s highest court has declared a proposed ban on social media for children under 15 unconstitutional, ruling that it infringes upon youths’ freedom of speech and communication. This decision, a setback for President Emmanuel Macron, signals potential legal and technical challenges for global efforts to restrict social media access for younger teenagers. Despite this ruling, the French government intends to pursue revised legislation while other nations and the EU continue to explore similar regulatory approaches, highlighting the ongoing tension between protective digital policies and privacy concerns.
Google Launches Gemini 3.7 Flash
Google has launched its new Gemini 3.7 Flash AI model, which offers improved performance in coding, debugging, and efficiency for app production while integrating enhanced safety features. Despite this release, the company continues to face pressure due to delays with its more powerful Gemini 3.5 Pro model and competition from rivals like OpenAI and Anthropic, leading to investor questions regarding Google’s AI roadmap and its ability to maintain a leading market position.
White House Introduces Tariffs of Up to 100 Percent on Drones
The White House has introduced new tariffs of up to 100 percent on drones and associated components to enhance national security and encourage domestic manufacturing, or “on-shoring.” These measures, which target both heavy-duty and sensitive commercial drones, are expected to increase costs for consumers as vendors pass on the expenses. The policy aims to reduce dependence on Chinese-manufactured models, like those from DJI, though industry experts note the significant challenge of replicating China’s advanced drone supply chains and specialized engineering capabilities within the US.
Flock Implements Stricter Data Retention Policies
Flock is implementing stricter data retention policies and mandating a new “Audit Assistance” tool designed to flag atypical search patterns for administrative review. Despite Flock’s claims of efficacy, privacy experts and critics from the ACLU and EFF argue that the company has provided insufficient technical details about how the tool works and lacks independent auditing evidence to prove it effectively prevents abuse, suggesting that stronger legal constraints on technology use are more critical for ensuring accountability.
Heart Aerospace Completes First Flight of All-Electric X1 Prototype
Heart Aerospace has successfully completed the first flight of its all-electric X1 prototype, marking a significant milestone for the company as it eyes regional aviation markets. With interest from airlines like United and Air Canada, Heart aims to follow this success with the ES-30, a hybrid-electric model designed to replace traditional turboprops by 2031 through lower operational costs and enhanced reliability, though the company’s ambitious timeline remains dependent on future advancements in battery density and weight.
Netflix Shutters Two Internal Game Studios
Netflix is shuttering two internal game studios, Night School Studio and Moonloot, as part of an ongoing restructuring of its gaming division. This decision follows a series of previous studio closures and divestments, signaling a consolidation of the company’s internal game development strategy. Moving forward, Netflix’s gaming focus is shifting toward four specific areas: kids, party, narrative, and mainstream titles, with increasing emphasis on cloud gaming and mobile-controller-based experiences.
Critical SAP Commerce Cloud Vulnerability Is Being Actively Exploited
A critical remote code execution vulnerability in SAP Commerce Cloud (CVE-2026-58231) is being actively exploited in the wild three days after patch release. Caused by improper authorization in the Data Hub Adapter, the flaw allows unauthenticated attackers to execute arbitrary code on e-commerce platforms. Despite no public proof-of-concept, researchers confirmed active attacks, underlining persistent security threats for SAP.
Uber Expands Robotaxi Strategy With Pony.ai
Uber is expanding its global robotaxi strategy by partnering with Pony.ai to deploy 2,000 self-driving vehicles across Europe and the Middle East, building on their existing pilot service in Zagreb. This collaboration, which includes plans for four additional European cities, is part of Uber’s broader effort to become a leading platform for autonomous commercialization by working with partners like WeRide and Baidu Apollo Go to scale operations in cities like Madrid and Tokyo, while gathering data to accelerate development against competitors like Waymo.
X Tests Tool to Show Post-Limiting Labels
X is testing a tool giving select users visibility into post-limiting labels like spam or NSFW. Aimed at clarifying algorithmic “shadowbanning,” the complex data remains hard to interpret. Concurrently, X expanded open-sourcing its recommendation algorithm while continuing to withhold sensitive advertising and non-timeline data.
Bluesky
Overview
- Microsoft
- Windows 10 Version 21H2
Description
Statistics
- 2 Posts
Bluesky
Overview
- Adobe
- Adobe Commerce
Description
Statistics
- 3 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- Fortinet
- FortiWeb
Description
Statistics
- 2 Posts
Fediverse
📰 Fortinet patches critical auth bypass in FortiWeb WAF (CVE-2026-26035)
Fortinet patches a critical authentication bypass in FortiWeb WAF (CVE-2026-26035). The flaw allows admin access with any password if a non-default 'admin wildcard' is set. Patch and check your configs now! #Fortinet #CyberSecurity #Vulnerability