Overview
- Hikvision
- DS-96xxxNI-Hx
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
π CVE-2025-66177 - High (8.8)
There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision NVR/DVR/CVR/IPC models. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially craft...
π https://www.thehackerwire.com/vulnerability/CVE-2025-66177/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Hikvision
- DS-K1T331
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
π CVE-2025-66176 - High (8.8)
There is a Stack overflow Vulnerability in the device Search and Discovery feature of Hikvision Access Control Products. If exploited, an attacker on the same local area network (LAN) could cause the device to malfunction by sending specially craf...
π https://www.thehackerwire.com/vulnerability/CVE-2025-66176/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Overview
- Microsoft
- Windows 10 Version 1809
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Guest Post: 115 CVEs Mark One of the Biggest January Patch Tuesdays Yet
By Tyler Reguly, Associate Director, Security R&D, Fortra CISOs this month should be paying a lot of attention to CVE-2026-21265 and the guidance associated with it. More specifically, they should be looking at the Windows Secure Boot certificate expiration and CA Updates that Microsoft published June 26, 2025. When the Secure Boot certificates expire in June of this year, organizations thatβ¦
The publicly disclosed ones are expiring Secure Boot cert:
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-21265
and an old one that was published in 2023 but is apparently now applicable to all Windows systems with the Agere Soft Modem installed, even if it isn't in use.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-31096
Overview
- Microsoft
- Microsoft Office 2019
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
π CVE-2026-20953 - High (8.4)
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
π https://www.thehackerwire.com/vulnerability/CVE-2026-20953/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
Three of the sev:CRIT RCEs list the Preview Pane as an attack vector.
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20952
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20953
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20944
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
π¨ OWASP Ottawa January Meetup β Featuring Vincent Dragnea! π¨
#OWASP #Ottawa is excited to announce that we are hosting our first monthly meetup of the year! Weβre thrilled to welcome Vincent Dragnea to our in-person meetup at the University of Ottawa on January 21, 2026.
RSVP at:
https://www.meetup.com/owasp-ottawa/events/312793912/
π
Date: January 21, 2026
β° Time: 6:00 PM EST β Arrival, networking & pizza π
6:30 PM EST β Technical Talks
π Location: 150 Louis-Pasteur Private, University of Ottawa, Room 117
ποΈ Talk: "SameSite...or not? Bypassing SameSite cookie protections in browsers"
SameSite cookies are often relied upon too heavily to prevent cross-site request forgery, yet, due to browser implementations, these cookies can be included in unexpected requests. This talk demonstrates novel techniques to attach SameSite=Strict cookies to GET requests originating from another site, including a Google Chrome vulnerability (CVE-2025-8581) discovered while researching these methods. This material aims to help researchers identify insecure behaviors, as well as teach developers how to avoid them.
πΊ Canβt make it in person? Watch live on the YouTube channel at https://www.youtube.com/@OWASP_Ottawa
Overview
- EmbySupport
- security
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
Here's my analysis of the recent-ish 9.3 Critical in #Emby (CVE-2025-64113).
Sadly, the vulnerability turned out to be pretty boring, but I've tried to make the best of it.
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
Did PANW just take a couple months off? They're just now publishing a threat brief on MongoBleed? Maybe that's why we haven't seen any advisories from them. Can't wait to see what's been sitting EITW in their queues.
https://unit42.paloaltonetworks.com/mongobleed-cve-2025-14847/
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Overview
Description
Statistics
- 1 Post
- 1 Interaction