Overview
- GitHub
- Enterprise Server
Description
Statistics
- 5 Posts
- 27 Interactions
Fediverse
Beaucoup de gens vont sans doute résumer la faille de sécurité CVE-2026-3854 en « Mon Dieu, la totalité des logiciels hébergés sur GitHub ont peut-être été compromis ».
Mais, en fait, c'était déjà possible, Microsoft (propriétaire de GitHub) pouvait déjà tout modifier.
Tout ce qu'a permis CVE-2026-3854, si des gens l'ont exploité, c'est de démocratiser cette possibilité, en la rendant accessible à tous les gens ayant un compte GitHub.
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
🚨 BREAKING: Wiz Research discovered Remote Code Execution on GitHub.com with a single git push.
Wiz Researchers uncovered a critical flaw in GitHub that could be exploited for RCE. The flaw allowed unauthorized access to millions of repositories belonging to other users and organizations 🤯
We responsibly disclosed the issue to GitHub, who deployed a fix on GitHub.com the same day (!) and released patches for all supported GHES versions.
GitHub Enterprise Server customers are strongly encouraged to update immediately.
Huge kudos to GitHub for addressing the issue 👏
Full technical breakdown here → https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
RCE in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
Bluesky
Overview
- Hugging Face
- LeRobot
Description
Statistics
- 6 Posts
- 11 Interactions
Fediverse
📰 Critical Unpatched RCE Flaw in Hugging Face's LeRobot AI Platform Puts Robotics Systems at Risk
🚨 CRITICAL FLAW: Unpatched RCE (CVE-2026-25874, CVSS 9.3) in Hugging Face's LeRobot AI platform. Unsafe deserialization allows unauthenticated attackers to execute code. #CVE202625874 #HuggingFace #AI #RCE
⚠️ An unpatched critical flaw in Hugging Face’s LeRobot enables remote code execution (CVSS 9.3).
Untrusted pickle over unauthenticated gRPC (no TLS) lets attackers take over servers, steal keys and models, and impact connected robots.
🔗 Details → https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html
The vulnerability in question is CVE-2026-25874 (CVSS score: 9.3), which has been described as a case of untrusted data deserialization stemming from the use of the unsafe pickle format. https://thehackernews.com/2026/04/critical-cve-2026-25874-leaves-hugging.html
Overview
Description
Statistics
- 6 Posts
- 1 Interaction
Fediverse
#infosec #vulnerability #malware
Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html?m=1
🛡️ Title: Windows Shell Spoofing Vulnerability
Description
🛡️ Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
Bluesky
Overview
- OpenBSD
- OpenSSH
Description
Statistics
- 5 Posts
- 5 Interactions
Fediverse
Kritische OpenSSH-Luecke: Ein Komma in Zertifikatsnamen kann Root-Zugriff ermoeglichen. CVE-2026-35414 mit CVSS 8,1 betrifft Versionen der letzten 15 Jahre. Update auf OpenSSH 10.3 verfuegbar. https://winfuture.de/news,158363.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
@kubikpixel Behoben wurde die Schwachstelle bereits Anfang April mit der Veröffentlichung von OpenSSH 10.3
Detail Description :
https://nvd.nist.gov/vuln/detail/CVE-2026-35414
(mW ein weiterhin funktionierender und gemeinnütziger Service der Regierung der United States :awesome: )
📰 Decade-Old OpenSSH Flaw (CVE-2026-35414) Allows Full Root Access, Exploits Hard to Detect
🚨 CRITICAL: A 15-year-old flaw in OpenSSH (CVE-2026-35414) allows attackers to gain full root access. The bug is trivial to exploit and hard to detect in logs. Update to OpenSSH 10.3p1 immediately! 🛡️ #OpenSSH #CVE #Linux #CyberSecurity
Overview
- PackageKit
- PackageKit
Description
Statistics
- 2 Posts
- 9 Interactions
Fediverse
Pack2TheRoot: Critical Linux Privilege Escalation Flaw in PackageKit Affects 12+ Years of Releases (CVE-2026-41651)
#CyberSecurity
https://securebulletin.com/pack2theroot-critical-linux-privilege-escalation-flaw-in-packagekit-affects-12-years-of-releases-cve-2026-41651/
Article sur une faille sur #PackageKit :
https://goodtech.info/pack2theroot-faille-linux-packagekit-root-cve-2026-41651/
Pour info packagekit est traduit en :
- Kabyle : 31%
- Occitan : 27%
- Breton : 22%
- Basque, Galicien, Catalan : +60%
Overview
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
Microsoft Defender “RedSun” Zero-Day (CVE-2026-33825): Unpatched Exploit Grants Full SYSTEM Access
#CyberSecurity
https://securebulletin.com/microsoft-defender-redsun-zero-day-cve-2026-33825-unpatched-exploit-grants-full-system-access/
Overview
- Microsoft
- ASP.NET Core 10.0
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
The diversity of advisory is key. Look at how good the advisory of GitHub is compared to the others.
Overview
- InternLM
- lmdeploy
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
LMDeploy CVE-2026-33626 Flaw Exploited Within 13 Hours of Disclosure https://thehackernews.com/2026/04/lmdeploy-cve-2026-33626-flaw-exploited.html
Overview
- Milesight
- MS-Cxx63-PD
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-32644 (CRITICAL, CVSS 9.2): Milesight MS-Cxx63-PD cameras have default SSL private keys, exposing encrypted traffic to interception & tampering. No patch yet — restrict access & follow vendor updates. https://radar.offseq.com/threat/cve-2026-32644-cwe-321-in-milesight-ms-cxx63-pd-60e79b90 #OffSeq #IoTSecurity #Vulnerability
Description
Statistics
- 1 Post
- 1 Interaction