Overview
Description
Statistics
- 12 Posts
- 8 Interactions
Fediverse
[hack cvss 10.0]
Si vous utilisez React Server Components / Next.js
Lisez cela :
- "CERT-FR a connaissance de multiples exploitations de la vulnérabilité CVE-2025-55182. Les serveurs avec une version vulnérable exposés après la publication des preuves de concept publiques du 5 décembre 2025 doivent être considérés comme compromis."
https://www.cert.ssi.gouv.fr/alerte/CERTFR-2025-ALE-014/
- https://medium.com/@cdcore/react-got-hacked-and-its-way-worse-than-you-think-c43781fd8381
Critical React2Shell Vulnerability (CVE-2025-55182) Analysis: Surge in Attacks Targeting RSC-Enabled Services Worldwide https://hackread.com/react2shell-vulnerability-cve-2025-55182-analysis/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D
Bluesky
Description
Statistics
- 4 Posts
Fediverse
Huh, I somehow missed this CVE:
https://mastodon.social/@verbrecher/115720201828646496
Thx to for the pointer @verbrecher
CVE-2025-14174 is related to this commit in the ANGLE repo:
https://github.com/google/angle/commit/95a32cb37edbb90eac0b83727b38fedbbb32307b
For CVE-2025-43529 there's much less info.
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-day-flaws-exploited-in-sophisticated-attacks/
Apple has released emergency updates to patch two zero-day vulnerabilities
that were exploited in an “extremely sophisticated attack” targeting specific
individuals.
The zero-days are tracked as CVE-2025-43529 and CVE-2025-14174 and were both
issued in response to the same reported exploitation.
"Apple is aware of a report that this issue may have been exploited in an
extremely sophisticated attack against specific targeted individuals on
versions of iOS before iOS 26," reads Apple's security bulletin.
Bluesky
Overview
Description
Statistics
- 2 Posts
Fediverse
CISA Adds Actively Exploited Sierra Wireless Router Flaw Enabling RCE Attacks
https://thehackernews.com/2025/12/cisa-adds-actively-exploited-sierra.html
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday
added a high-severity flaw impacting Sierra Wireless AirLink ALEOS routers to
its Known Exploited Vulnerabilities (KEV) catalog, following reports of active
exploitation in the wild.
CVE-2018-4063 (CVSS score: 8.8/9.9) refers to an unrestricted file upload
vulnerability that could be exploited to achieve remote code execution by
means of a malicious HTTP request.
"A specially crafted HTTP request can upload a file, resulting in executable
code being uploaded, and routable, to the webserver," the agency said. "An
attacker can make an authenticated HTTP request to trigger this
vulnerability."
Overview
Description
Statistics
- 1 Post
- 10 Interactions
Fediverse
Posted a fast demo https://cr.yp.to/2025/20251215-recover-isc-key.c for CVE-2025-40780, where https://gitlab.isc.org/isc-projects/bind9/-/commit/6876753c7ccd67d445a6a2341219fe79cff6c77f says it was "discovered during research for an upcoming academic paper" that BIND's ID RNG is predictable. The attack is easy; what's interesting is why such a poor RNG ended up deployed.
Overview
Description
Statistics
- 3 Posts
Fediverse
Huh, I somehow missed this CVE:
https://mastodon.social/@verbrecher/115720201828646496
Thx to for the pointer @verbrecher
CVE-2025-14174 is related to this commit in the ANGLE repo:
https://github.com/google/angle/commit/95a32cb37edbb90eac0b83727b38fedbbb32307b
For CVE-2025-43529 there's much less info.
Apple fixes two zero-day flaws exploited in 'sophisticated' attacks
https://www.bleepingcomputer.com/news/security/apple-fixes-two-zero-day-flaws-exploited-in-sophisticated-attacks/
Apple has released emergency updates to patch two zero-day vulnerabilities
that were exploited in an “extremely sophisticated attack” targeting specific
individuals.
The zero-days are tracked as CVE-2025-43529 and CVE-2025-14174 and were both
issued in response to the same reported exploitation.
"Apple is aware of a report that this issue may have been exploited in an
extremely sophisticated attack against specific targeted individuals on
versions of iOS before iOS 26," reads Apple's security bulletin.
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
1996 called—it wants its stack overflow back.
2025 firewall, pre-auth RCE via IKEv2, no canaries, no PIE, leaks its version in base64 like a name tag.
“First line of defense” popping RIP to DEADBEEF. 🔥 yIKEs.
https://labs.watchtowr.com/yikes-watchguard-fireware-os-ikev2-out-of-bounds-write-cve-2025-9242/
Overview
- SourceCodester
- Warehouse Management System
Description
Statistics
- 1 Post
Overview
- NXLog
- NXLog Agent
Description
Statistics
- 1 Post
Fediverse
⚠️ HIGH severity: CVE-2025-67900 in NXLog Agent <6.11 lets local attackers alter OpenSSL configs via OPENSSL_CONF, risking confidentiality & integrity. Patch to 6.11+ & restrict local access! https://radar.offseq.com/threat/cve-2025-67900-cwe-829-inclusion-of-functionality--155a752c #OffSeq #Vulnerability #InfoSec
Overview
- Shiguangwu
- sgwbox N3
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2025-14706 (CRITICAL, CVSS 9.3): Shiguangwu sgwbox N3 v2.0.25 has an unpatched remote command injection in /usr/sbin/http_eshell_server. Public exploit, no vendor fix. Isolate, restrict, & monitor now! https://radar.offseq.com/threat/cve-2025-14706-command-injection-in-shiguangwu-sgw-4786a150 #OffSeq #CVE202514706 #Infosec #NetworkSecurity