Overview
- Samsung Electronics
- MagicINFO 9 Server
Description
Statistics
- 2 Posts
Fediverse
🟠 CVE-2026-25201 - High (8.8)
An unauthenticated user can upload arbitrary files to execute remote code, leading to privilege escalation in MagicInfo9 Server.
This issue affects MagicINFO 9 Server: less than 21.1090.1.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25201/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 2 Posts
Fediverse
🟠 CVE-2026-25253 - High (8.8)
OpenClaw (aka clawdbot or Moltbot) before 2026.1.29 obtains a gatewayUrl value from a query string and automatically makes a WebSocket connection without prompting, sending a token value.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-25253/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
Description
Statistics
- 2 Posts
Fediverse
https://hackingpassion.com/openssl-12-cves-ai-january-2026/
AI found 12 of 12 #OpenSSL #CVE's . CVE-2025-15467 is most remarkable
Bluesky
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
‼️ CVE-2026-1281: Safe indicator check for Ivanti EPMM & CVE-2026-1340 related paths
GitHub: https://github.com/Ashwesker/Ashwesker-CVE-2026-1281
Critical cybersecurity updates from February 1-2, 2026: Microsoft patched an actively exploited Office zero-day (CVE-2026-21509), and Fortinet fixed a critical FortiCloud SSO flaw (CVE-2026-24858). Ivanti released fixes for two exploited EPMM zero-days (CVE-2026-1281, CVE-2026-1340) by February 1, and Bitdefender reported Android RAT malware distributed via Hugging Face (February 2).
In technology, Apple overhauled its online Mac store for a "build-it-yourself" experience (February 1), and Google extended the Fitbit data migration deadline to Google accounts until May 2026.
Overview
- Ivanti
- Endpoint Manager Mobile
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
‼️ CVE-2026-1281: Safe indicator check for Ivanti EPMM & CVE-2026-1340 related paths
GitHub: https://github.com/Ashwesker/Ashwesker-CVE-2026-1281
Critical cybersecurity updates from February 1-2, 2026: Microsoft patched an actively exploited Office zero-day (CVE-2026-21509), and Fortinet fixed a critical FortiCloud SSO flaw (CVE-2026-24858). Ivanti released fixes for two exploited EPMM zero-days (CVE-2026-1281, CVE-2026-1340) by February 1, and Bitdefender reported Android RAT malware distributed via Hugging Face (February 2).
In technology, Apple overhauled its online Mac store for a "build-it-yourself" experience (February 1), and Google extended the Fitbit data migration deadline to Google accounts until May 2026.
Overview
- coreruleset
- coreruleset
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CVE-2026-21876: Critical Multipart Charset Bypass Fixed in CRS 4.22.0 and 3.3.8 https://coreruleset.org/20260106/cve-2026-21876-critical-multipart-charset-bypass-fixed-in-crs-4.22.0-and-3.3.8/
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
I like to point out issues at Apple. They are an easy target because even with the amount of money they make, they still don't manage to fix glaring known issues.
But #Xiaomi is no better. On #HyperOS many devices have not received 2026-01-05 security patch level including critical CVE-2025-54957.
Fun fact: currently you can't even ask about this since their forum won't load. Not that they care or give sensible answers when it is operational, so ... 🙄
Overview
- Johnson Controls
- Metasys
Description
Statistics
- 1 Post
Fediverse
A critical SQL injection vulnerability (CVE-2025-26385) with a maximum CVSS score of 10.0 affects multiple Johnson Controls products, including Application and Data Server (ADS) and Extended Application and Data Server (ADX), allowing remote attackers to execute arbitrary SQL commands without authentication. The vulnerability impacts systems used in critical infrastructure sectors such as commercial facilities, energy, government, and transportation, and CISA recommends network isolation, firewalls, and VPNs for mitigation.
https://cybersecuritynews.com/johnson-controls-products-vulnerabilities/
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post