Overview
Description
Statistics
- 7 Posts
- 2 Interactions
Fediverse
⚠️ Hackers Exploit CVE-2025-55182 to Breach 766 Next.js Hosts, Steal Credentials
「 The campaign is assessed to be targeting Next.js applications that are vulnerable to CVE-2025-55182 (CVSS score: 10.0), a critical flaw in React Server Components and Next.js App Router that could result in remote code execution, for initial access, and then dropping the NEXUS Listener collection framework 」
https://thehackernews.com/2026/04/hackers-exploit-cve-2025-55182-to.html
Bluesky
Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 3 Posts
- 22 Interactions
Fediverse
I'm trying to understand a bit more about CVE-2026-33579, the critical vulnerability in OpenClaw. To exploit, an attacker needs low-level paring privilege permissions. How does one acquire such privileges? Can anyone do it? I'm asking because I want to understand what's required for an attacker to exploit.
Feel free to ping me at DanArs.82, or drop an answer here.
Also, is it possible the github commit links for the patch for CVE-2026-33579 are... just wrong? That commit doesnt really seem to match the description? (Didnt fully check it yet)
@masek Thanks for the screenshot and the reference to CVE-2026-33579 - the reddit comment has been removed. 🙏
Overview
Description
Statistics
- 3 Posts
Fediverse
Geopolitical tensions escalate between Algeria and Morocco, impacting European security and energy stability. In technology, IBM and Arm announced a strategic collaboration on new dual-architecture hardware for future AI and data-intensive workloads. On the cybersecurity front, CISA added a new exploited vulnerability (CVE-2026-3502) to its catalog, while L.A. Metro confirmed a mid-March hack, with systems still being restored.
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
Bluesky
Overview
Description
Statistics
- 3 Posts
Overview
- Cisco
- Cisco Enterprise NFV Infrastructure Software
Description
Statistics
- 2 Posts
- 2 Interactions
Bluesky
Overview
- Krajowa Izba Rozliczeniowa
- SzafirHost
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
Ciekawy błąd, 0/1 click RCE w oprogramowaniu związanym z Szafir/KIR służącym do elektronicznych podpisów, używanym przez 900k użytkowników.
Tldr: wchodzisz w link, (niekoniecznie) klikasz "ok" w zespoofowanym okienku, dostajesz malware.
Research: Michał Leszczyński
https://www.cve.org/CVERecord?id=CVE-2026-26928
Overview
- Fortinet
- FortiClientEMS
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Vulnerabilidad SQLi está siendo explotada en Fortinet FortiClient EMS (CVE-2026-21643)
https://blog.elhacker.net/2026/04/vulnerabilidad-sqli-esta-siendo.html
Overview
- anomalyco
- opencode
Description
Statistics
- 1 Post
Bluesky
Overview
- Microsoft
- Azure Kubernetes Service
Description
Statistics
- 1 Post