Overview
- Microsoft
- Microsoft Malware Protection Engine
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
🚨 Microsoft Defender zero-day RoguePlanet is now officially CVE-2026-50656.
Microsoft is preparing a patch for the Malware Protection Engine flaw, which can enable privilege escalation.
A public PoC describes a race condition that may grant SYSTEM-level privileges.
Read: https://thehackernews.com/2026/06/microsoft-confirms-rogueplanet-defender_02022423645.html
New zero-day Local Privilege Escalation (EoP) flaw in Microsoft Defender: CVE-2026-50656 (RoguePlanet)! 🚨
Low-privilege users can abuse a TOCTOU race condition to hijack system paths and spawn an NT AUTHORITY\SYSTEM shell. Deep dive analysis here:👇
https://denizhalil.com/2026/06/18/cve-2026-50656-microsoft-defender-eop-vulnerability-analysis/
Overview
Description
Statistics
- 2 Posts
- 7 Interactions
Fediverse
CISA Adds Oracle PeopleSoft Zero-Day CVE-2026-35273 to KEV Catalog After Ransomware Gang Exploitation
#CyberSecurity
https://securebulletin.com/cisa-adds-oracle-peoplesoft-zero-day-cve-2026-35273-to-kev-catalog-after-ransomware-gang-exploitation/
Overview
- libssh2
- libssh2
Description
Statistics
- 1 Post
- 27 Interactions
Fediverse
Oh my.
https://nvd.nist.gov/vuln/detail/CVE-2026-55200
sev:CRIT 9.2 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote code execution.
Overview
Description
Statistics
- 2 Posts
Fediverse
Alert: CVE-2026-48907. A severe access control flaw in Widget Factory Joomla Content Editor allows unauthenticated PHP script execution. Lock down your CMS. Read our tactical engineering runbook for full IOCs and endpoint hardening steps. https://thecybermind.co/unjv
Overview
- F5
- NGINX Open Source
Description
Statistics
- 2 Posts
Fediverse
https://www.cve.org/CVERecord?id=CVE-2026-42055
https://www.cve.org/CVERecord?id=CVE-2026-42530
Overview
- Fortinet
- FortiSandbox
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Fortinet: Da rollt die Lawine an
Nach dem Notfall-Update vor zwei Monaten wurden drei weitere kritische Sicherheitslücken in Fortinet-Produkten gefunden: CVE-2026-39808 und CVE-2026-39813 wurden im April noch geflickt, CVE-2026-25089 erst letzte Woche. Alle drei werden aktuell aktiv für Angriffe ausgenutzt, obwohl Flicken dagegen vorliegen. Anscheinend spielen nicht alle Anwender die verfügbaren (!) Updates zeitnah ein.
Parallel dazu beobachten Sicherheitsforscher/innen eine massive Angriffswelle gegen Fortinet Firewalls*, die auf Passwort-Diebstahl aus ist. Ein Zusammenhang mit den Sicherheitslücken
https://www.pc-fluesterer.info/wordpress/2026/06/18/fortinet-da-rollt-die-lawine-an/
#2fa #closedsource #cybercrime #exploits #firewall #hersteller #Microsoft #passwort #sicherheit #UnplugTrump #verschlüsselung #vorfälle #vpn #zahlen #encryption
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
the moment you visit cve.org you are loading 1.xMB of data. This includes everything except binary data (images etc) and CVE data itself.
You wanna learn more about the board? the DOM is built from that one script & populated from a json blob in that script. Well, a string which is then decoded
Wanna look up the contact method for NVIDIAs CNA? Every website on the path to get there is built from that script & already contained in that script as a json blob.
Want to know the geometry of Antarctica? You bet there is a couple of polygons in that script! (I don't know where they are used).
Every linked youtube video that explains something? It's in there!!
Or in other words: You are downloading 1.xMB of data (uncompressed: 4MB) that is probably not very cacheable data past the current session & of which you probably aren't gonna use much of anyway - you just clicked a link to see whats up with CVE-2026-42069 & now you downloaded 400kB of CNA data!
Overview
- AWS
- bedrock-agentcore
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
🚨 CRITICAL: CVE-2026-12530 impacts AWS Bedrock AgentCore Python SDK (v1.1.3 – 1.6.1). Incomplete input sanitization in install_packages() lets attackers abuse pip flags. Update now! https://radar.offseq.com/threat/cve-2026-12530-improper-neutralization-of-argument-917f42dfcc3cfd56 #OffSeq #AWSSecurity #Python #CVE2026_12530
Overview
- Android
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
CRITICAL: CVE-2026-28573 targets Android 14 & 16 via missing permission check, enabling persistent local DoS — no user interaction or privileges needed. Patch status unknown. Stay updated: https://radar.offseq.com/threat/cve-2026-28573-denial-of-service-in-google-android-3a071465298b8ea9 #OffSeq #Android #InfoSec #CVE #Vuln
Overview
- iba
- ibaPDA
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
#OT #Advisory VDE-2026-051
iba: Deserialization vulnerability in ibaPDA and ibaDatCoordinator
Remote Code Execution (RCE) running under the service user account, thereby allowing privilege escalation.
#CVE CVE-2026-8024
https://certvde.com/en/advisories/vde-2026-051/
#oCSAF
#CSAF https://iba.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-051.json