Overview
Description
Statistics
- 4 Posts
- 3 Interactions
Fediverse
Critical CVE-2026-1731 in BeyondTrust RS/PRA is under active exploitation.
Web shells. RATs. PostgreSQL dumps.
Now listed in CISA KEV & tied to ransomware.
Remote support appliances are high-value targets.
Are we giving PAM systems enough monitoring visibility?
Source: https://thehackernews.com/2026/02/beyondtrust-flaw-used-for-web-shells.html
Follow @technadu for independent cybersecurity reporting.
Like and join the discussion below.
#CyberSecurity #Infosec #ZeroDay #Ransomware #PAM #ThreatIntel #SecurityCommunity #CVE20261731
Bluesky
Overview
- NaturalIntelligence
- fast-xml-parser
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
CVE-2026-25896 (CVSS 9.3) disclosed in fast-xml-parser
A critical entity encoding bypass affects fast-xml-parser (40M+ weekly npm downloads).
-Allows attackers to shadow built-in XML entities (<, >, &, ", ')
-Can lead to XSS or injection when parsing untrusted XML and rendering the output
-Exploitable with default settings (processEntities: true)
-Impacts >= 4.1.3 and < 5.3.5, including transitive dependencies
Fix: upgrade to v5.3.5+
Advisory: GHSA-m7jm-9gc2-mpf2
https://www.endorlabs.com/learn/cve-2026-25896-fast-xml-parser
🚨 CRITICAL: CVE-2026-25896 in fast-xml-parser (<5.3.5) lets attackers override built-in XML entities, enabling XSS via crafted XML. Affects web apps using vulnerable versions. Patch to 5.3.5+ ASAP! https://radar.offseq.com/threat/cve-2026-25896-cwe-185-incorrect-regular-expressio-a786da3a #OffSeq #Infosec #XSS #NodeJS
Description
Statistics
- 3 Posts
Fediverse
Bluesky
Overview
- Grandstream
- GXP1610
Description
Statistics
- 2 Posts
Fediverse
CRITICAL: Grandstream VoIP phones hit by unauthenticated RCE (CVE-2026-2329) — allows call interception & device compromise. No patch yet. Restrict access, disable remote mgmt, and monitor for threats. https://radar.offseq.com/threat/critical-grandstream-phone-vulnerability-exposes-c-7d749d0a #OffSeq #VoIP #Security #RCE
Overview
- Dell
- Unisphere for PowerMax
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Honeywell
- I-HIB2PI-UL 2MP IP
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Microsoft
- Windows Admin Center
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- owthub
- Library Management System
Description
Statistics
- 1 Post
Overview
- JonathanWilbur
- asn1-ts
Description
Statistics
- 1 Post
Fediverse
🛡️ CRITICAL: CVE-2026-27452 in JonathanWilbur asn1-ts (<=11.0.5) — Decoding INTEGERs may leak ArrayBuffer, exposing sensitive data. Upgrade to 11.0.6 urgently. Details: https://radar.offseq.com/threat/cve-2026-27452-cwe-200-exposure-of-sensitive-infor-d39700d7 #OffSeq #Vulnerability #Security #CVE202627452
Overview
Description
Statistics
- 1 Post