Overview
Description
Statistics
- 5 Posts
- 2 Interactions
Fediverse
🚀 MongoDB has disclosed a high-severity vulnerability (CVE-2025-14847) with a CVSS score of 8.7. This flaw allows unauthenticated remote attackers to read uninitialized heap memory due to improper handling of length parameter inconsistencies in compressed protocol headers. The vulnerability impacts specific releases in the 7.0, 8.0, and 8.2 series, necessitating immediate patching.
#Cybersecurity #InfoSec #Hacking #Privacy #TechSafety
👉 Full Story: https://www.nexaspecs.com/2025/12/mongodb-cve-2025-14847-security-fix.html
Hunting MongoBleed (CVE-2025-14847): https://blog.ecapuano.com/p/hunting-mongobleed-cve-2025-14847
Bluesky
Overview
Description
Statistics
- 2 Posts
- 7 Interactions
Bluesky
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
Stubborn AI honeypots give me grey hair.
Attacker sends payload:
"username=anonymous%00]]%0dlocal+h+%3d+io.popen("this is vulnerable to CVE-2025-47812")%0dlocal+r+%3d+h%3aread("*a")%0dh%3aclose()%0dprint(r)%0d--&password=
"
And the AI responsible for handling the response sends the following back to the attacker:
"This system is not affected by CVE-2025-47812.
"
*sigh*
Overview
- IBM
- API Connect
Description
Statistics
- 2 Posts
Bluesky
Overview
- agronholm
- cbor2
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Codedraft
- Mediabay - WordPress Media Library Folders
Description
Statistics
- 1 Post
Fediverse
🟠 CVE-2025-28949 - High (8.5)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: fr...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-28949/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda
Overview
- SmarterTools
- SmarterMail
Description
Statistics
- 1 Post
Fediverse
CSA has published guidance on CVE-2025-52691, a critical SmarterMail vulnerability enabling potential unauthenticated remote code execution through arbitrary file uploads.
Although exploitation has not been observed, the advisory highlights the continued exposure of mail server infrastructure and the importance of timely upgrades to fixed builds.
Engage in the discussion and follow TechNadu for sober, research-driven security reporting.
#InfoSec #VulnerabilityResearch #EmailInfrastructure #RCE #PatchManagement #CyberDefense #TechNadu
Overview
- Python Software Foundation
- CPython
Description
Statistics
- 1 Post
Overview
- kromitgmbh
- titra
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2025-69288 - Critical (9.1)
Titra is open source project time tracking software. Prior to version 0.99.49, Titra allows any authenticated Admin user to modify the timeEntryRule in the database. The value is then passed to a NodeVM value to execute as code. Without sanitizati...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69288/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda