Overview
Description
Statistics
- 3 Posts
- 13 Interactions
Fediverse
this was some great and necessary debunking of the ridiculous attempt at a "look how cool we are” CVE assignment.
between this and the "it's actually not a real vuln from an internet-perspective" for the recent daft D-Link CVE assignment, the cyber part of 2026 is off to a really horrible start.
Tell your friends.
The vulnerability, tracked as CVE-2026-21858 (CVSS score: 10.0), has been codenamed Ni8mare by Cyera Research Labs. Security researcher Dor Attias discovered and reported it on November 9, 2025.
https://thehackernews.com/2026/01/critical-n8n-vulnerability-cvss-100.html
Overview
Description
Statistics
- 3 Posts
Bluesky
Overview
Description
Statistics
- 3 Posts
- 7 Interactions
Fediverse
🟠 CVE-2025-69194 - High (8.8)
A security issue was discovered in GNU Wget2 when handling Metalink documents. The application fails to properly validate file paths provided in Metalink elements. An attacker can abuse this behavior to write files to unintended locations on the ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69194/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
🟠 CVE-2025-69195 - High (7.6)
A flaw was found in GNU Wget2. This vulnerability, a stack-based buffer overflow, occurs in the filename sanitization logic when processing attacker-controlled URL paths, particularly when filename restriction options are active. A remote attacker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69195/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- coreruleset
- coreruleset
Description
Statistics
- 2 Posts
Bluesky
Overview
- Alibaba
- Fastjson
Description
Statistics
- 2 Posts
- 8 Interactions
Fediverse
🔴 CVE-2025-70974 - Critical (10)
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those meth...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-70974/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda
Perfect 10 in Fastjson. 🥳
It's funny that it appears to be a challenging enough bug that it bypassed at least two previous fixes.
https://www.cve.org/CVERecord?id=CVE-2025-70974
Fastjson before 1.2.48 mishandles autoType because, when an @type key is in a JSON document, and the value of that key is the name of a Java class, there may be calls to certain public methods of that class. Depending on the behavior of those methods, there may be JNDI injection with an attacker-supplied payload located elsewhere in that JSON document. This was exploited in the wild in 2023 through 2025. NOTE: this issue exists because of an incomplete fix for CVE-2017-18349. Also, a later bypass is covered by CVE-2022-25845.
Overview
- Trend Micro, Inc.
- Trend Micro Apex Central
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
Uh... how is https://github.com/n8n-io/n8n/security/advisories/GHSA-v364-rw7m-3263 (CVE-2026-21877) a 10.0 with PR:L? That is not possible, either it's a 9.9 or it has PR:N.
Overview
Description
Statistics
- 1 Post
- 4 Interactions