Overview
Description
Statistics
- 8 Posts
- 2 Interactions
Fediverse
🧩 3️⃣ Vulnerabilidad crítica en 7-Zip: hackers la están explotando ahora.
Una falla grave en el popular programa de compresión 7-Zip (CVE-2025-11001) permite a atacantes ejecutar código de forma remota cuando un usuario descomprime un archivo ZIP malicioso.
El problema radica en cómo 7-Zip maneja enlaces simbólicos (symlinks): un ZIP confeccionado puede hacer que el programa acceda a carpetas no deseadas y ejecute código con permisos elevados.
La vulnerabilidad afecta a todas las versiones anteriores a la 25.00 (es decir, versiones usadas desde 21.02 hasta 24.09).
Ya existe un exploit de prueba de concepto (PoC) público, lo que facilita que delincuentes lo usen en ataques reales.
Aunque 7-Zip lanzó el parche en julio de 2025, muchos sistemas siguen sin actualizarlo: la recomendación urgente es que actualices a la versión 25.00 o superior lo antes posible.
🔒 ¿Herramienta de compresión útil o puerta de entrada para malware?
#Privacidad #Ciberseguridad #7Zip #Vulnerabilidad #Actualiza
https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html
Advierten sobre un exploit PoC para una vulnerabilidad en 7-Zip (CVE-2025-11001)
Vía: @seguinfo
https://blog.segu-info.com.ar/2025/11/advierten-sobre-un-exploit-poc-para-una.html
Bluesky
Overview
- Microsoft
- Azure Bastion Developer
Description
Statistics
- 1 Post
- 42 Interactions
Fediverse
CVSS 10, you say. 🧐😩
Azure Bastion (CVE-2025-49752)
https://cybersecuritynews.com/azure-bastion-vulnerability/
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Seeing first scans for Oracle's CVE-2025-61757
https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/
Bluesky
Overview
Description
Statistics
- 2 Posts
- 6 Interactions
Fediverse
🚨 Attention all Firefox users: A vulnerability (CVE‑2025‑13016) in WebAssembly handling could let attackers execute code on your device. Researchers say over 180 million users might have been exposed. The fix is live, update immediately.
Read: https://hackread.com/update-firefox-patch-cve-2025-13016-vulnerability/
Update Firefox to Patch CVE-2025-13016 Vulnerability Affecting 180 Million Users https://hackread.com/update-firefox-patch-cve-2025-13016-vulnerability/?utm_source=dlvr.it&utm_medium=%5Binfosec.exchange%5D
Overview
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
Asus veröffentlichte drängend-dringende SicherheitsUpdates für alle (!) AUSUS-PCs
Wenn sie einen Asus-PC nutzen, sollten Sie sofort handeln und die empfohlenen Updates einspielen!
ASUS hat wichtige Sicherheitsupdates für den ASUS System Control Interface Service in MyASUS veröffentlicht. Konkret geht es um die Schwachstelle CVE-2025-59373 (Score von 8,5).
Overview
- Shenzhen Aitemi E Commerce Co. Ltd.
- M300 Wi-Fi Repeater
Description
Statistics
- 1 Post
- 7 Interactions
Fediverse
Shenzhen WiFi repeater command injection is EITW.
https://www.cve.org/CVERecord?id=CVE-2025-34152
An unauthenticated OS command injection vulnerability exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) via the 'time' parameter of the '/protocol.csp?' endpoint. The input is processed by the internal date '-s' command without rebooting or disrupting HTTP service. Unlike other injection points, this vector allows remote compromise without triggering visible configuration changes.
https://attackerkb.com/topics/vOQYG5Nn7Y/cve-2025-34152
Unlike many consumer IoT vulnerabilities that remain purely theoretical, CVE-2025-34152 has been observed actively exploited in the wild. In September 2025, multiple Aitemi M300 devices exposed to the internet were found compromised.
Overview
- Digital Bazaar
- node-forge
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
Resetting the "It has been __ days since an ASN.1 vuln."
https://www.cve.org/CVERecord?id=CVE-2025-12816
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.
Overview
- Monsta Limited of New Zealand
- Monsta FTP
Description
Statistics
- 3 Posts
- 4 Interactions
Bluesky
Overview
- lunary-ai
- lunary-ai/lunary
Description
Statistics
- 1 Post
- 2 Interactions
Overview
- Grafana
- Grafana Enterprise
Description
Statistics
- 1 Post
- 1 Interaction