Overview
Description
Statistics
- 2 Posts
- 278 Interactions
Fediverse
This is next level infosec shitposing:
"It is the FreeBSD analogue of Linux's Dirty Pipe, CopyFail, Fragnesia, and Dirty Frag — except we gave it a BETTER name, with a BETTER logo, on a BETTER website. The other bug websites? Disasters. Sad. Many people have told us this."
Overview
- ivanti
- Sentry
Description
Statistics
- 8 Posts
- 51 Interactions
Fediverse
RE: https://infosec.exchange/@i0null/113632100951178053
CVSS 10 in Ivanti again #CVE_2026_10520
📰 Ivanti Patches Critical Sentry Flaws Allowing Root-Level RCE
⚠️ CRITICAL: Ivanti patches two severe flaws in Sentry, including a root-level unauthenticated RCE (CVE-2026-10520). Technical details are public, exploitation risk is high. Patch immediately! #Ivanti #Vulnerability #RCE #CyberSecurity
🌐 cyber[.]netsecops[.]io
🚨 Ivanti Sentry Pre-Auth RCE (CVE-2026-10520) 🚨
Ivanti recently patched a CVSS 10.0 OS Command Injection flaw in Ivanti Sentry, granting remote, unauthenticated attackers instant root privileges.
In my latest post, I break down the exploit chain, covering mics-core.jar decompilation, Nuclei scanning, and Python PoC verification. Immediate patching is highly recommended.
👉 Full Analysis: https://denizhalil.com/2026/06/11/exploitation-ivanti-sentry-os-command-injection-cve-2026-10520/
Geopolitical tensions heightened as the US conducted strikes in Iran following an Apache helicopter downing, with Iran responding by closing the Strait of Hormuz. In technology, Apple launched the Vision Pro 2, and over 30 countries enacted new AI regulations. Cybersecurity saw critical Ivanti Sentry flaws (CVE-2026-10520) patched, while South Korea fined Coupang $409M for a significant data breach.
Bluesky
Overview
- langflow-ai
- langflow
Description
Statistics
- 11 Posts
- 5 Interactions
Fediverse
🚨 CRITICAL ALERT: N/A
CVSS 9.0/10
📋 WHAT IT IS:
Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. [...]
🎯 WHO'S AFFECTED:
• See NVD for affected products
⚔️ HOW IT'S EXPLOITED:
Attack vector: unknown vector
Impact: impact varies
✅ WHAT TO DO:
1. Check if you're running affected software NOW
2. Apply patches immediately — this is critical
3. If no patch: i
🚨 ACTIVE EXPLOIT: AI Platform Langflow Under Attack
CVE-2026-5027 | CVSS 9.8 | Path Traversal
📋 WHAT IT IS:
Attackers are actively exploiting a critical path traversal vulnerability in Langflow — a popular open-source AI development platform. The flaw allows unauthenticated attackers to read arbitrary files on the server, including environment variables and API keys.
🎯 WHO'S AFFECTED:
• Langflow instances exposed to the internet
• Any AI/ML pipeline using Langflow for workflow orchestration
•
Threat Actors exploiting High Severity Vulnerability in Langflow
Threat actors are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in Langflow, a popular low-code platform for building AI applications....
https://itnerd.blog/2026/06/11/threat-actors-exploiting-high-severity-vulnerability-in-langflow/
Bluesky
Overview
- Oracle Corporation
- PeopleSoft Enterprise PeopleTools
Description
Statistics
- 7 Posts
- 10 Interactions
Fediverse
Oracle has released an out-of-band security alert for an unauth RCE in PeopleSoft
CVE-2026-35273
https://www.oracle.com/security-alerts/alert-cve-2026-35273.html
CRITICAL: Oracle PeopleSoft PeopleTools 8.61 & 8.62 (CVE-2026-35273) has a remotely exploitable flaw (CVSS 9.8). Unauthenticated attackers can fully compromise affected systems. Apply patches immediately! https://radar.offseq.com/threat/cve-2026-35273-vulnerability-in-the-peoplesoft-ent-9ad1390c #OffSeq #Oracle #Vuln #Patch
Bluesky
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
📰 Google Patches Fifth Actively Exploited Chrome Zero-Day of 2026
⚠️ Google patches its FIFTH Chrome zero-day this year! CVE-2026-11645 is a high-severity V8 bug actively exploited in the wild. Update your browser to version 149.0.7827.103+ immediately! #CyberSecurity #ZeroDay #GoogleChrome #PatchNow
🌐 cyber[.]netsecops[.]io
Here's a summary of recent geopolitical, technology, and cybersecurity news:
Geopolitical: US-Iran tensions escalated with retaliatory strikes following a helicopter downing near the Strait of Hormuz. Israel's ongoing actions in Lebanon against Hezbollah are straining fragile ceasefire efforts in the region.
Technology: Apple unveiled AI-powered Siri updates and iOS 27 at WWDC. Microsoft advanced hybrid quantum-classical AI algorithms for optimization. Over 30 countries have enacted AI regulations.
Cybersecurity: CISA issued new risk-based vulnerability remediation deadlines for federal agencies, citing AI-driven automated attacks. Google patched a critical Chrome zero-day (CVE-2026-11645) actively exploited in the wild.
Bluesky
Overview
- Krajowa Izba Rozliczeniowa
- Szafir SDK
Description
Statistics
- 1 Post
- 38 Interactions
Fediverse
🐛 Media tego tematu nie podjęły, następuje coś w stylu "ciszej nad tą trumną". O co chodzi?
Przez lata w ZUS, krócej w innych instytucjach, można było zalogować się do systemu niemal każdej (z małymi wyjątkami) instytucji państwowej, odpowiednio preparując dokument do "Logowania podpisem kwalifikowanym".
Wystarczyło znać imię, nazwisko i pesel.
Na czym polegał błąd?
Na złej interpretacji struktury zwracanej przez SDK.
W skrócie: ignorowano pole zawierające informację, czy przesłany podpis jest zaufany, ograniczając się do sprawdzenia, czy proces przetwarzania zakończył się bez błędów.
Tak, przy spreparowanych kluczach i dokumencie proces przetwarzania kończył się bez błędów...
Wnioski? Państwo nie dowozi w software. Nie dowozi w audyty (jeśli były?).
Dodatkowy smaczek?
Od zgłoszenia, naprawa potrafiła trwać miesiące!
Co by się stało, gdyby kod był otwarty?
Poddany audytowi społeczności, która jest bardzo zainteresowana systemami udostępnianymi przez państwo? Zapewne problem zostałby wyłapany, bo to jakby podstawa podstaw...
No ale systemy są zamknięte, bo wg decydentów tak jest bezpieczniej... To błąd i myślenie "odwrotne".
CVE-2026-9058
Prezentacja Michała Leszczyńskiego, który odkrył, odpowiedzialnie zgłosił i PRZYPILNOWAŁ naprawienia podatności (44 minuty):
https://www.youtube.com/watch?v=pMdnS8I18Ts
Invidious:
https://inv.nadeko.net/watch?v=pMdnS8I18Ts
#bezpieczeństwo #zaufanie #KluczPubliczny #CERT #PKI #MinisterstwoCyfryzacji #Państwo #systemy
Overview
Description
Statistics
- 3 Posts
Fediverse
📰 Active Exploitation of Critical PAN-OS Auth Bypass (CVE-2026-0257) Detected in the Wild
⚠️ Active Exploitation Alert! Unidentified actors are exploiting PAN-OS auth bypass CVE-2026-0257 to access GlobalProtect VPNs. CISA KEV listed. Patch or apply mitigations immediately to prevent unauthorized access. #PANOS #CVE #CyberSecurity
🌐 cyber[.]netsecops[.]io
Bluesky
Overview
Description
Statistics
- 4 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 2 Posts
Fediverse
🚨 [CRITICAL INFRASTRUCTURE ALERT]: CVE-2025-10263
• CVE ID: CVE-2025-10263
• CVSS Score: 9.1 (Critical)
• Affected: Microsoft Record Flaws
What it is:
Linux Sees Patches for "Critical" Vulnerability Affecting Many Arm CPUs https://www.phoronix.com/news/Arm-CPU-Critical-CVE-2025-10263