Overview
- Zbtlink
- CPE2801 Firmware
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.
The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.
The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
CISA added three bugs to its KEV list. An N-able N-central authentication bypass is exploited in the wild to deploy RMM tools. Patch by August 7.
#Nable #Ncentral #CISA #KEV #CVE202618556 #ExploitedInTheWild #RMM #Langflow #ApacheTomcat #CyberSecurity #InfoSec
🚨 CISA KEV ALERT: CVE-2026-18556 exposes N-able N-central installations to authentication bypass via alternate channel paths. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection logic, and hardening guidance now: https://thecybermind.co/radr
Overview
- WebPros
- cPanel
Description
Statistics
- 2 Posts
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 2 Posts
Fediverse
OVSwrap (CVE-2026-64531): How a 13-Year-Old Open vSwitch Bug Became a Reliable Linux Root Exploit
OVSwrap (CVE-2026-64531) is a Linux kernel privilege escalation flaw affecting Open vSwitch. Explore the vulnerability, exploit chain and morehttps://thecybersecguru.com/news/ovswrap-cve-2026-64531-linux-kernel-openvswitch-root-vulnerability/
Overview
Description
Statistics
- 2 Posts
Fediverse
🚨 CISA KEV ALERT: CVE-2026-9198 identifies a critical unauthenticated code injection flaw in IBM Langflow allowing full RCE on default deployments. Active exploitation confirmed. Get the execution mechanics, CrowdStrike CQL detection, and compensating controls now: https://thecybermind.co/fi0v
Overview
Description
Statistics
- 2 Posts
Fediverse
🚨 CISA KEV ALERT: CVE-2026-34486 exposes Apache Tomcat installations to EncryptInterceptor bypasses and data interception. Active exploitation confirmed. Get the forensic breakdown, Splunk/KQL/Chronicle detection queries, and hardening steps: https://thecybermind.co/it1p
Top-of-the-Line LinkedIn Post
Overview
- djangoproject
- Django
- django
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
A high-severity Django vulnerability, CVE-2026-15307, can enable remote code execution through spatial lookups. Update to Django 6.0.8 or 5.2.17 now.
#Django #DjangoSecurity #CVE202615307 #RCE #RemoteCodeExecution #Vulnerability #Python #WebSecurity #InfoSec #CyberSecurity
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
🚨 Tails 7.10.1: Actualizare de urgență pentru rezolvarea unor vulnerabilități critice în kernel-ul Linux și biblioteca Expat! Proiectul Tails (The Amnesic Incognito Live System) a lansat versiunea 7.10.1, o actualizare de securitate critică destinată protejării sistemului împotriva atacurilor ce ar putea duce la de-anonimizarea utilizatorilor. ✨ Principalele remedieri și noutăți din versiunea 7.10.1:🔒 Patch de securitate pentru Kernel-ul Linux (v6.12.100):• Rezolvă vulnerabilitatea CVE-2026-64560. O pagină web răuvoitoare ar fi putut exploata această breșă prin intermediul Tor Browser pentru a obține privilegii de administrator (root), preluând controlul asupra sesiunii și deconspirând identitatea utilizatorului. 🛡️ Actualizare pentru biblioteca Expat (v2.8.2):• Adresează vulnerabilitățile din librăria de analiză XML (Expat) conform avizului Debian DSA-6404-1. Acestea puteau fi exploatate la deschiderea unor fișiere malițios concepute în aplicații precum LibreOffice, Audacity sau Git. ⚡ Actualizări mai rapide cu Zstandard (zstd):• Procesul de actualizare automată folosește acum compresia Zstandard, ceea ce îmbunătățește considerabil viteza de pornire în timpul aplicării update-urilor. 📉 Imagine mai mică și consum redus de date:• Prin eliminarea unor pachete de firmware neutilizate, dimensiunea imaginii ISO/USB și a pachetelor de actualizare automată a fost redusă cu aproximativ 70 MB. ⚠️ Recomandare: Echipa Tails le recomandă tuturor utilizatorilor să efectueze imediate upgrade-uri (automate sau manuale) la versiunea 7.10.1 pentru a rămâne protejați. #Tails #TailsOS #Linux #TorNetwork #CyberSecurity #Privacy #Debian #OpenSource #TechNews #FOSS
Overview
- pgadmin.org
- pgAdmin 4
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Qualcomm, Inc.
- Snapdragon
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-24084 - High severity security gap in 5G UE capability verification. Weak config allows replayed security capabilities, risking network integrity. CVSS 7.5. Unpatched - assess and monitor immediately. #CVE #5G #cybersecurity