Overview
Description
Statistics
- 5 Posts
- 139 Interactions
Fediverse
New stable kernels landed today in Alpine Linux. They address ssh-keysign-pwn (CVE-2026-46333)
- 6.18.31
- 6.12.89
- 6.6.139
- 6.1.173
- 5.15.207
These have been backported all the way down to Alpine Linux 3.16.
Edit: These versions fix ssh-keysign-pwn, not Fragnesia
Looks like a new kernel, patched for CVE-2026-46333, has arrived for #Debian #Linux
https://lists.debian.org/debian-security-announce/2026/msg00185.html
Overview
Description
Statistics
- 13 Posts
- 3 Interactions
Fediverse
Explotan vulnerabilidad CVE-2026-42897 en Microsoft Exchange Server local mediante correos manipulados
https://blog.elhacker.net/2026/05/explotan-vulnerabilidad-cve-2026-42897.html
Microsoft Exchange Server Spoofing Vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-42897
#Microsoft #Exchange: 0-Day Schwachstelle (CVE-2026-42897) wird angegriffen
CVE-2026-42897 exploits improper HTML sanitization in OWA, allowing JavaScript execution within the email rendering context. The script inherits authentication tokens, accesses the full DOM, and can read emails, harvest...
Microsoft has released mitigations for a high-severity Microsoft Exchange Server vulnerability that is being actively exploited in attacks.
The flaw enables threat actors to execute arbitrary code through a cross-site scripting (XSS) attack targeting Outlook on the web users.
Tracked as CVE-2026-42897, the vulnerability affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE).
Recent reports (May 15-16, 2026): Foxconn's N. American operations were hit by Nitrogen ransomware, exfiltrating client infrastructure maps. OpenAI confirmed a supply chain attack on employee devices. Microsoft warned of an actively exploited Exchange Server zero-day (CVE-2026-42897).
**Global Briefing: May 17, 2026**
Geopolitical: The US extended the Israel-Lebanon ceasefire by 45 days. Russia and Ukraine completed a 205-for-205 prisoner exchange.
Technology: Tech stocks experienced a downturn as April's CPI exceeded expectations. xAI has officially launched Grok Build, its first AI coding agent.
Cybersecurity: A critical Microsoft Exchange zero-day vulnerability (CVE-2026-42897) is under active exploitation, targeting Outlook Web Access. Canada's Bill C-22, related to lawful access, faces strong opposition from tech giants over encryption concerns.
Bluesky
Overview
Description
Statistics
- 6 Posts
- 5 Interactions
Fediverse
And of course we're covering it at IFIN and I knew that because I read it all the time. Right? RIGHT??
https://discourse.ifin.network/t/cve-2026-42945-heap-buffer-overflow-in-nginx/441
🚨 PoC code for CRITICAL NGINX vuln (CVE-2026-42945) now public! Heap buffer overflow in ngx_http_rewrite_module — can cause DoS or RCE if ASLR is disabled. Patch NGINX Plus/open source ASAP. https://radar.offseq.com/threat/poc-code-published-for-critical-nginx-vulnerabilit-3d78edaa #OffSeq #NGINX #Vuln #InfoSec
Recent News: Nitrogen ransomware breached Foxconn's North American operations, exfiltrating 8TB of data, including Apple and Nvidia network maps (May 15). A critical NGINX vulnerability (CVE-2026-42945) with public PoC exploit code was patched on May 16. Geopolitically, the US-China summit addressed trade, Taiwan, and Nvidia AI chips. Concurrently, Trump's diplomatic efforts with Iran remain at a stalemate.
Bluesky
Overview
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
CISA incluye la vulnerabilidad CVE-2026-20182 de Cisco SD-WAN en su catálogo de vulnerabilidades explotadas tras ataques al acceso de administrador
https://blog.elhacker.net/2026/05/cisa-incluye-la-vulnerabilidad-cve-2026.html
Latest Geopolitical, Technology, and Cybersecurity News (May 15-16, 2026):
Geopolitical: Trump-Xi talks ended without major breakthroughs. The US canceled troop deployment to Poland amid a rift with Germany over Iran war fatigue. Taiwan plans HIMARS deployment.
Technology: Quantum computing advancements raise dual-use security challenges; AI military systems are under global debate. OpenAI debuted personal finance tools for ChatGPT Pro.
Cybersecurity: NIST is advancing post-quantum cryptography standards. Cisco patched its sixth SD-WAN zero-day of 2026 (CVE-2026-20182). The Turla group deployed its Kazuar P2P botnet.
Bluesky
Overview
- Microsoft
- Microsoft 365 Apps for Enterprise
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Outlook – CVE-2026-40361 : cette faille zero-click menace les entreprises, patchez ! https://www.it-connect.fr/outlook-cve-2026-40361-cette-faille-zero-click-menace-les-entreprises-patchez/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Microsoft #Outlook
Overview
- Microsoft
- Windows 10 Version 20H2
Description
Statistics
- 2 Posts
- 8 Interactions
Overview
- MervinPraison
- PraisonAI
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
CVE-2026-44338: PraisonAI Framework Actively Exploited Within Hours of Disclosure — No Auth Required
#CyberSecurity
https://securebulletin.com/cve-2026-44338-praisonai-framework-actively-exploited-within-hours-of-disclosure-no-auth-required/
Overview
- Amazon
- Amazon Redshift JDBC Driver
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
CVE-2026-8178: Critical Amazon Redshift JDBC Driver Flaw Enables RCE via Malicious Connection URLs — Patch Now
#CyberSecurity
https://securebulletin.com/cve-2026-8178-critical-amazon-redshift-jdbc-driver-flaw-enables-rce-via-malicious-connection-urls-patch-now/
Overview
Description
Statistics
- 1 Post
- 12 Interactions
Fediverse
🚀 FrankenPHP 1.12.3 is out with a nice performance boost!
A refreshed PGO profile delivers a 7–8% throughput bump for baseline HTTP requests right out of the box.
This release also patches a critical security flaw (CVE-2026-45062, CVSS 8.1) via unsafe Unicode handling in CGI path splitting. Upgrading from v1.11.2–v1.12.2 is highly recommended.
Ships with:
• Per-thread max_requests
• Stuck thread force-kill primitive
• SLSA build attestations
Release notes: https://github.com/php/frankenphp/releases/tag/v1.12.3
Overview
Description
Statistics
- 1 Post
- 8 Interactions
Fediverse
Why you should always prefer Debian over Ubuntu:
Ubuntu: https://ubuntu.com/security/CVE-2026-43284: Needs evaluation
Debian: https://security-tracker.debian.org/tracker/CVE-2026-43284: fixed