24h | 7d | 30d

Overview

  • Palo Alto Networks
  • Cloud NGFW

13 May 2026
Published
30 May 2026
Updated

CVSS v4.0
HIGH (7.8)
EPSS
41.50%

Description

Authentication bypass vulnerabilities in the GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection. Panorama and Cloud NGFW are not impacted by these issues.

Statistics

  • 9 Posts
  • 9 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-0257: Palo Alto PAN-OS Authentication Bypass Actively Exploited — Patch Immediately
#CyberSecurity
securebulletin.com/cve-2026-02

  • 5
  • 0
  • 0
  • 4h ago
Profile picture fallback

En las últimas 24 horas se detectaron ataques que explotan vulnerabilidades críticas en PAN-OS GlobalProtect, un paquete malicioso en NuGet que roba credenciales bancarias, una filtración masiva de datos en programa social y una controversia entre Microsoft y un investigador de seguridad que cuestiona la transparencia en ciberseguridad. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:

🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 30/05/26 📆 |====

🔓 EXPLOTACIÓN ACTIVA DE VULNERABILIDAD EN PAN-OS GLOBALPROTECT (CVE-2026-0257)

Se ha detectado la explotación activa de una grave vulnerabilidad en PAN-OS GlobalProtect que permite a los atacantes evadir la autenticación. Esta brecha compromete la seguridad de las redes corporativas que usan este sistema, facilitando accesos no autorizados con potencial daño en la confidencialidad y control de los sistemas. Es vital actualizar y reforzar las políticas de seguridad para mitigar este riesgo. Conoce cómo proteger tus sistemas frente a esta amenaza 👉 djar.co/t3SSdE

⚠️ MICROSOFT EN EL OJO DE LA TORMENTA POR AMENAZAS A INVESTIGADOR DE SEGURIDAD

Una disputa pública reciente entre Microsoft y un investigador de seguridad independiente ha reavivado el debate sobre la transparencia y responsabilidad en la seguridad del software. La amenaza de una investigación criminal contra el experto plantea preocupaciones respecto a la colaboración entre grandes empresas y la comunidad de ciberseguridad, fundamental para mejorar la protección global. Entiende las implicaciones de este conflicto y su impacto en la seguridad informática 👉 djar.co/vUhRNw

💀 PAQUETE MALICIOSO EN NUGET ROBÓ CREDENCIALES BANCARIAS

Investigadores han identificado un paquete malicioso llamado Sicoob.Sdk en NuGet que robaba certificados PFX e identificadores de clientes, poniendo en riesgo la autenticidad de APIs y la seguridad de pagos digitales. Esta amenaza resalta la importancia de revisar y controlar estrictamente las dependencias y librerías externas utilizadas en proyectos para evitar filtraciones y suplantaciones. Descubre cómo detectar y prevenir este tipo de ataques 👉 djar.co/bsW9

🚨 FILTRACIÓN MASIVA EN PÁGINA DE PROGRAMAS SOCIALES: DATOS DE BENEFICIARIOS EXPUESTOS

Un ataque cibernético comprometió la página oficial de programas sociales, dejando expuestos datos personales de miles de beneficiarios de la Pensión Bienestar. Este incidente pone en peligro la privacidad y seguridad de personas vulnerables, subrayando la necesidad urgente de reforzar la ciberseguridad en plataformas gubernamentales y sociales. Infórmate sobre los riesgos y recomendaciones para proteger tu información 👉 djar.co/f14k

  • 1
  • 1
  • 0
  • 5h ago
Profile picture fallback

CVE-2026-0257 exploits a missing signature verification in GlobalProtect's cookie validation. Attackers forge authentication cookies using the /usr/local/bin/gpsvc binary's RSA private keys, gaining VPN access without...

captechgroup.com/about-us/thre

  • 1
  • 0
  • 0
  • 22h ago

Bluesky

Profile picture fallback
Palo Alto Networks says CVE-2026-0257 in PAN-OS and Prisma Access is being actively exploited, enabling auth bypass and unauthorized GlobalProtect VPN access. #PANOS #GlobalProtect #PrismaAccess
  • 0
  • 1
  • 0
  • 4h ago
Profile picture fallback
~Cisa~ CISA added CVE-2026-0257, an actively exploited Palo Alto PAN-OS auth bypass flaw, to its KEV catalog. - IOCs: CVE-2026-0257 - #CVE20260257 #PaloAlto #threatintel
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
CVE-2026-0257 enables authentication bypass in PAN-OS/Prisma Access GlobalProtect, allowing unauthorized VPN connections and has been actively exploited in the wild.
  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback
Alerte #CyberSecurity 🚨 : Une faille d’authentification dans PAN-OS #GlobalProtect (CVE-2026-0257, score 7.8) est activement exploitée, permettant de contourner la sécurité VPN. #calimeg
  • 0
  • 0
  • 0
  • 7h ago
Profile picture fallback
PAN-OS GlobalProtect Authentication Bypass (CVE-2026-0257) Under Active Exploitation thehackernews.com/2026/05/pan-...
  • 0
  • 0
  • 0
  • 4h ago
Profile picture fallback
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities #patchmanagement
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Microsoft
  • Windows 10 Version 1809

25 Feb 2021
Published
03 Aug 2024
Updated

CVSS v3.1
MEDIUM (5.5)
EPSS
3.49%

KEV

Description

Windows Mobile Device Management Information Disclosure Vulnerability

Statistics

  • 1 Post
  • 225 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

RE: c.im/@cdarwin/1166607696958375

One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.

Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.

On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.

For the record, I think @GossiTheDog called it that this person was a former MS employee.

x.com/ChaoticEclipse0/with_rep

  • 105
  • 120
  • 0
  • 13h ago

Overview

  • Microsoft
  • Windows

12 Nov 2019
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
0.49%

Description

An elevation of privilege vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.To exploit this vulnerability, an authenticated attacker would need to run a specially crafted application to elevate privileges.The security update addresses the vulnerability by correcting how AppX Deployment Extensions manages privileges., aka 'Windows AppX Deployment Extensions Elevation of Privilege Vulnerability'.

Statistics

  • 2 Posts
  • 261 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

RE: c.im/@cdarwin/1166607696958375

One reason that Microsoft might be issuing such harshly worded language here to describe the researcher may be that, according to Nightmare Eclipse, they until recently worked as a security researcher at Microsoft.

Scroll back far enough through their Xitter account (to June 2020) and you will see they claimed CVE-2019-1385 was theirs.

On July 1, 2021, Nightmare Eclipse complained that Microsoft failed to fix one of the weaknesses they reported in CVE-2021-24084. Microsoft credits both of these flaws to the same researcher, whose LinkedIn account says they are in Germany and worked full time at Microsoft from Sept. 2022 to June 2025.

For the record, I think @GossiTheDog called it that this person was a former MS employee.

x.com/ChaoticEclipse0/with_rep

  • 105
  • 120
  • 0
  • 13h ago
Profile picture fallback

This person has been a prolific bug finder for quite some time. Here's their public HackerOne profile: hackerone.com/halove23/hacktiv

Reading their Xitter timeline over the years is pretty interesting. They went from working w/ a lot of these bug bounty programs and giving MS time to fix stuff beyond the usual 90-day window to increasing frustration in dealing w/ vendors. I wish that were less of a common experience than it still is today, but some dynamics in this industry never seem to change.

Also just noticed something interesting. Back in 2019, MS was including hyperlinks to researchers in their advisories. In this advisory, they actually link to the researcher's shitposting Facebook profile, which has posts up until this month.

facebook.com/com.android.vendi

msrc.microsoft.com/update-guid

  • 12
  • 24
  • 0
  • 2h ago

Overview

  • Microsoft
  • Microsoft SharePoint Enterprise Server 2016

22 May 2026
Published
27 May 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.62%

KEV

Description

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Statistics

  • 2 Posts
  • 7 Interactions

Last activity: 4 hours ago

Fediverse

Profile picture fallback

CVE-2026-45659: vulnerabilità RCE ad alta severità in SharePoint Server — patch disponibile
#tech
spcnet.it/cve-2026-45659-vulne
@informatica

  • 7
  • 0
  • 0
  • 4h ago

Bluesky

Profile picture fallback
✨ CVE-2026-45659: vulnerabilità RCE ad alta severità in SharePoint Server — patch disponibile Leggi il blog: spcnet.it/cve-2026-456...
  • 0
  • 0
  • 0
  • 4h ago

Overview

  • Pending

Pending
Published
Pending
Updated

CVSS
Pending
EPSS
Pending

KEV

Description

This candidate has been reserved by a CVE Numbering Authority (CNA). This record will be updated by the assigning CNA once details are available.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 3 hours ago

Fediverse

Profile picture fallback

CVE-2026-47187: Symlink escape - rogue SFTP server -> local file read/write
Severity: Critical (CVSS 9.3, CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N)
CWE: CWE-59 (Improper Link Resolution Before File Access)

A rogue SFTP server can return symlink targets (absolute paths or relative "../../../" escapes) that sshfs passes to the kernel unchanged. The kernel resolves them on the client's local filesystem, so an ordinary "cp" through the mountpoint can read local files back to the server or write server-controlled bytes to local files. transform_symlinks does not cover relative targets.

openwall.com/lists/oss-securit

  • 2
  • 2
  • 0
  • 3h ago

Overview

  • Linux
  • Linux

22 Apr 2026
Published
18 May 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
2.24%

Description

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different mappings. Get rid of all the complexity added for in-place operation and just copy the AD directly.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 22 hours ago

Fediverse

Profile picture fallback
  • 2
  • 1
  • 0
  • 22h ago

Overview

  • Hewlett Packard Enterprise (HPE)
  • HPE Aruba Networking InstantOS and Aruba Access Points running ArubaOS 10

06 Aug 2024
Published
08 Aug 2024
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.27%

KEV

Description

There is a vulnerability in the AP Certificate Management Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system compromise.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 7 hours ago

Fediverse

Profile picture fallback

CVE-2024-42395 - Critical RCE in AP Certificate Management Service. Unauthenticated RCE, CVSS 9.8. Exploitation leads to full system compromise. Patch status unknown, monitor for updates urgently. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2024-423

  • 1
  • 0
  • 0
  • 7h ago

Overview

  • juliangruber
  • brace-expansion

29 May 2026
Published
29 May 2026
Updated

CVSS v3.1
MEDIUM (6.5)
EPSS
0.03%

KEV

Description

The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large numeric range like {1..10000000}, the sequence generation loop generates all 10 million intermediate elements before the max limit is applied With max=10, the output is correctly limited to 10 items, but the process still allocates ~505 MB and spends ~800ms building the full intermediate array. This vulnerability is fixed in 5.0.6.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 4 hours ago

Bluesky

Profile picture fallback
🚨 New MEDIUM CVE detected in AWS Lambda 🚨 CVE-2026-45149 impacts brace-expansion in 3 Lambda base images. Details: https://github.com/aws/aws-lambda-base-images/issues/542 More: https://lambdawatchdog.com/ #AWS #Lambda #CVE #CloudSecurity #Serverless
  • 0
  • 1
  • 0
  • 4h ago

Overview

  • marimo-team
  • marimo

09 Apr 2026
Published
24 Apr 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
82.17%

Description

marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands. Unlike other WebSocket endpoints (e.g., /ws) that correctly call validate_auth() for authentication, the /terminal/ws endpoint only checks the running mode and platform support before accepting connections, completely skipping authentication verification. This vulnerability is fixed in 0.23.0.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 12 hours ago

Bluesky

Profile picture fallback
Attackers exploited Marimo CVE-2026-39987 for RCE, then used an LLM agent to harvest creds, access AWS Secrets Manager, gain SSH bastion access, and exfiltrate PostgreSQL data. #Marimo #AWSSecrets #PostgreSQL
  • 0
  • 1
  • 0
  • 12h ago

Overview

  • Toshiba Tec Corporation
  • Toshiba Tec e-Studio multi-function peripheral (MFP)

14 Jun 2024
Published
13 Feb 2025
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.19%

KEV

Description

Toshiba printers use SNMP for configuration. Using the private community, it is possible to remotely execute commands as root on the remote printer. Using this vulnerability will allow any attacker to get a root access on a remote Toshiba printer. This vulnerability can be executed in combination with other vulnerabilities and difficult to execute alone. So, the CVSS score for this vulnerability alone is lower than the score listed in the "Base Score" of this vulnerability. For detail on related other vulnerabilities, please ask to the below contact point. https://www.toshibatec.com/contacts/products/ As for the affected products/models/versions, see the reference URL.

Statistics

  • 1 Post

Last activity: 2 hours ago

Fediverse

Profile picture fallback

CVE-2024-27143 - Critical RCE in Toshiba printers via SNMP private community. Attackers can execute commands as root. CVSS 9.8. Unpatched. Update firmware immediately. #CVE #Toshiba #infosec

valtersit.com/cve/CVE-2024-271

  • 0
  • 0
  • 0
  • 2h ago
Showing 1 to 10 of 33 CVEs