Overview
Description
Statistics
- 4 Posts
- 1 Interaction
Fediverse
Docker : la faille CVE-2026-34040 permet d’obtenir un accès root sur l’hôte ! https://www.it-connect.fr/docker-la-faille-cve-2026-34040-permet-dobtenir-un-acces-root-sur-lhote/ #ActuCybersécurité #Cybersécurité #Vulnérabilité #Docker
#Docker CVE-2026-34040 Lets Attackers Bypass Authorization and Gain Host Access:
👇
https://thehackernews.com/2026/04/docker-cve-2026-34040-lets-attackers.html
Bluesky
Overview
Description
Statistics
- 3 Posts
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
https://mail-index.netbsd.org/source-changes/2026/04/08/msg161497.html
> Import OpenSSL-3.5.6 (previous was 3.5.5)
CVE-2026-31790, CVE-2026-2673, CVE-2026-28387, CVE-2026-28388, CVE-2026-28389, CVE-2026-28390, CVE-2026-31789
https://mail-index.netbsd.org/source-changes/2026/04/08/msg161500.html
> Import OpenSSH-10.3 (previous was 10.2)
これは CVE はなくて Security 関連仕様変更のみ?
https://mail-index.netbsd.org/source-changes/2026/04/08/msg161505.html
> Import xz-5.8.3 (previous was 5.2.4)
> Fix a buffer overflow in lzma_index_append()
はあるけど、そもそも backdoor 以前のバージョンからの更新なのか?
少なくとも bind に加えて openssl は 11.0_RC4 不可避なのか
Bluesky
Overview
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
CVE-2025-59718 analysis shows attackers bypassing FortiGate SSO, exfiltrating configs, and establishing persistent VPN access over 2 weeks of dwell time. They targeted hypervisors, DCs, and backup infrastructure—classic pre-ransomware reconnaissance. Detection gaps: firewall config changes blend into routine admin tasks. #CVE202559718 #ransomware #firewall #incidentresponse #threatintel
Overview
- abetlen
- llama-cpp-python
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Llama Drama:AIアプリ開発用Pythonパッケージに重大な欠陥 システムやデータが侵害される恐れ(CVE-2024-34359) | Codebook|Security News https://www.yayafa.com/2776397/ #AgenticAi #AI #ArtificialGeneralIntelligence #ArtificialIntelligence #LLAMA #Meta #MetaAI #エージェント型AI #人工知能 #汎用人工知能
Overview
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-0232 Cortex XDR Agent: Local Administrator can disable the agent on Windows
https://security.paloaltonetworks.com/CVE-2026-0232
Read on HackerWorkspace: https://hackerworkspace.com/article/cve-2026-0232-cortex-xdr-agent-local-administrator-can-disable-the-agent-on-windows
Overview
- SaturdayDrive
- Ninja Forms - File Uploads
Description
Statistics
- 2 Posts
Fediverse
#WordPress - Nachrichten direkt aus der PlugIn Hölle live. 🤢
"With over 600,000 downloads, Ninja Forms is a popular WordPress form builder that lets users create forms without coding using a drag-and-drop interface. Its File Upload extension, included in the same suite, serves 90,000 customers."
CVE-2026-0740 severity rating 9.8
"After patch reviews and a partial fix on February 10, the vendor released a complete fix in version 3.3.27, available since March 19."
"Identified as CVE-2026-0740, the issue is currently exploited in attacks. According to WordPress security company Defiant, its Wordfence firewall blocked more than 3,600 attacks over the past 24 hours."
Bin gespannt wie viele Naivlinge es diesmal erwischt? 🙈
Fragen Sie immer einen erfahrenen Spezialisten wie man sein #WordPress sicher betreiben muss. 😊
Hackers Take Advantage of Major Vulnerability in Ninja Forms Plugin for WordPress #wordpress
Critical vulnerability in Ninja Forms File Uploads for WordPress prompts urgent action. CVE-2026-0740 allows unauthenticated file uploads and potential remote code execution. Wordfence reports thousands of attacks daily. Upgrade to version 3.3.27+ now: https://ift.tt/K0kScOZ
Source: https://ift.tt/K0kScOZ | Image: https://ift.tt/ufylkGI
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
Chrome’s Fourth Zero-Day of 2026: CISA Orders Federal Agencies to Patch CVE-2026-5281 by April 15
#CyberSecurity
https://securebulletin.com/chromes-fourth-zero-day-of-2026-cisa-orders-federal-agencies-to-patch-cve-2026-5281-by-april-15/
Overview
- Kubernetes
- Kubernetes
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
Next in my series of blogs on unpatchable Kubernetes vulnerabilities is out. This time it's about TOCTOUs and SSRF
https://securitylabs.datadoghq.com/articles/unpatchable-kubernetes-vulnerabilities-cve-2020-8562/
Overview
- WAGO
- CC100 (0751-9x01)
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
#OT #Advisory VDE-2024-008
Wago: Vulnerability in WBM through Open VPN
A security vulnerability has been identified in the Web-Based Management (WBM) function when OpenVPN is enabled.
#CVE CVE-2024-1490
https://certvde.com/en/advisories/vde-2024-008/
#oCSAF
#CSAF https://wago.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2024-008.json