Overview
Description
Statistics
- 11 Posts
- 9 Interactions
Fediverse
Adobe PDF: Zero-Day seit Monaten angegriffen
Wieder einmal hat Adobe mit Acrobat etc. der Welt ein zweifelhaftes Geschenk gemacht. In den Produkten Acrobat DC, Acrobat Reader DC und Acrobat 2024 für Windows und macOS steckte eine öffentlich bisher nicht bekannte Sicherheitslücke, die mindestens seit dem vorigen November für Angriffe ausgenutzt wird (Zero-Day Exploit). Entdeckt wurde die Lücke CVE-2026-34621 im März. In der Meldung steht noch, dass es keinen Flicken gäbe. Das stimmt nicht mehr; Adobe hat gerade Updates veröffentlicht. Für einen Angriff reicht es aus, dem Opfer ein präpariertes PDF unterzuschieben. Außer das PDF
https://www.pc-fluesterer.info/wordpress/2026/04/14/adobe-pdf-zero-day-seit-monaten-angegriffen/
#Allgemein #Empfehlung #Hintergrund #Warnung #0day #cybercrime #exploits #pdf #sicherheit #spionage #trojaner #UnplugTrump #adobe
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CVE-2012-1854 Visual Basic for Applications Insecure Library Loading
CVE-2020-9715 Adobe Acrobat Use-After-Free
CVE-2023-21529 Microsoft Exchange Deserialization of Untrusted
CVE-2023-36424 Microsoft Windows Out-of-Bounds Read
CVE-2025-60710 Microsoft Windows Link Following
CVE-2026-21643 Fortinet SQL Injection
CVE-2026-34621 Adobe Acrobat Reader Prototype
Bluesky
Overview
- ShowDoc
- ShowDoc
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
ShowDoc RCE Flaw CVE-2025-0520 Actively Exploited on Unpatched Servers
https://thehackernews.com/2026/04/showdoc-rce-flaw-cve-2025-0520-actively.html
Read on HackerWorkspace: https://hackerworkspace.com/article/showdoc-rce-flaw-cve-2025-0520-actively-exploited-on-unpatched-servers
Bluesky
Overview
- marimo-team
- marimo
Description
Statistics
- 2 Posts
- 5 Interactions
Fediverse
Critical Marimo Python Notebook Zero-Day (CVE-2026-39987) Exploited Within 10 Hours of Disclosure
#CyberSecurity
https://securebulletin.com/critical-marimo-python-notebook-zero-day-cve-2026-39987-exploited-within-10-hours-of-disclosure/
Bluesky
Overview
- Red Hat
- Red Hat Enterprise Linux 10
- cockpit
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
Red Hat published RHSA-2026:7381 for CVE-2026-4631. The flaw is unauthenticated remote code execution in Cockpit. Cockpit is the default web console on RHEL 9, RHEL 10, Rocky, and AlmaLinux. CVSS 9.8. Cockpit passes hostnames and usernames from the browser straight to SSH, before any password check. One HTTP request to the login page runs commands as the server. Default on, web-facing, unauthenticated. Patch this week.
Overview
- Talend
- Talend JobServer
Description
Statistics
- 2 Posts
Fediverse
🔴 CRITICAL: CVE-2026-6264 affects Talend JobServer 8.0 & 7.3. Unauthenticated RCE via JMX port — patch immediately or require TLS client auth for mitigation. Disable JMX in Runtime if possible. Details: https://radar.offseq.com/threat/cve-2026-6264-cwe-306-missing-authentication-for-c-26a424cb #OffSeq #Talend #Vuln #RCE #Infosec
Overview
- wolfSSL
- wolfSSL
Description
Statistics
- 3 Posts
Fediverse
CVE-2026-5194 : quand un bug dans wolfSSL valide des certificats falsifiés https://www.it-connect.fr/cve-2026-5194-quand-un-bug-dans-wolfssl-valide-des-certificats-falsifies/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Web
Overview
Description
Statistics
- 1 Post
- 31 Interactions
Fediverse
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on Packagist.org and Private Packagist. Details on our blog: https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/ #php #phpc #composerphp
Overview
Description
Statistics
- 1 Post
- 31 Interactions
Fediverse
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on Packagist.org and Private Packagist. Details on our blog: https://blog.packagist.com/composer-2-9-6-perforce-driver-command-injection-vulnerabilities/ #php #phpc #composerphp
Overview
- SAP_SE
- SAP Business Planning and Consolidation and SAP Business Warehouse
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
🚨 CRITICAL: CVE-2026-27681 in SAP BPC & BW (CVSS 9.9). Authenticated users can inject SQL, risking data integrity & availability. No patch yet — restrict access & monitor DB activity. https://radar.offseq.com/threat/cve-2026-27681-cwe-89-improper-neutralization-of-s-a7704991 #OffSeq #SAP #Vuln #SQLi
Overview
Description
Statistics
- 2 Posts
- 3 Interactions
Fediverse
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CVE-2012-1854 Visual Basic for Applications Insecure Library Loading
CVE-2020-9715 Adobe Acrobat Use-After-Free
CVE-2023-21529 Microsoft Exchange Deserialization of Untrusted
CVE-2023-36424 Microsoft Windows Out-of-Bounds Read
CVE-2025-60710 Microsoft Windows Link Following
CVE-2026-21643 Fortinet SQL Injection
CVE-2026-34621 Adobe Acrobat Reader Prototype