Overview
Description
Statistics
- 2 Posts
- 11 Interactions
Fediverse
Earlier today the JRuby team was informed of a low-severity vulnerability in the bcrypt-ruby gem. We worked with the library's maintainers to arrange a fix and disclosure. The issue is now fixed in versions 3.1.22 and higher. Exposure risk is low, but upgrading is recommended.
CVE-2026-33306: Integer Overflow Causes Zero Key-Strengthening Iterations at Cost=31 on JRuby
https://github.com/bcrypt-ruby/bcrypt-ruby/security/advisories/GHSA-f27w-vcwj-c954
Overview
Description
Statistics
- 2 Posts
- 9 Interactions
Fediverse
#CVE_2017_11882 or some similar BS from an Excel file attached to a message sent to my blog email address. Final malware seems to be an AgentTesla/SnakeKeyLogger/VIP Recovery variant. Sample at:
https://bazaar.abuse.ch/sample/263b3f3c5e91c8fe858803ceae4b268af40536487828cf980e8d6e4d793648c0/
Calls for follow-up files at:
- hxxp[:]//91.92.242[.]3:7777/noesisllc.online/wealt1818/wealtt/nerdfwiqtwqhdgfrwt6fntdwrgonht.js
- hxxp[:]//91.92.242[.]3:7777/noesisllc.online/wealt1818/ENCRYPT.Ps1
Samples of these follow-up files at:
- https://bazaar.abuse.ch/sample/c47d92db7ed3cc5fdbb3296f3f4ab328cd8b66ac079f5bf658d4f2fa5f8a6af7/
- https://bazaar.abuse.ch/sample/dd737dea20792860147b53679f68e964778a2b47e98d7187ccd4ead0127aec76/
Bluesky
Overview
- VMware
- Spring AI
- Spring AI
Description
Statistics
- 4 Posts
- 1 Interaction
Bluesky
Overview
- VMware
- Spring AI
- Spring AI
Description
Statistics
- 6 Posts
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 2 Posts
- 6 Interactions
Fediverse
Seriously, any iOS experts looked into if CVE-2025-43520 from the DarkSword vulns could be used for KFD/MacDirtyCow-style file modding?
https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain
According to TAG’s analysis, DarkSword “uses CVE-2025-43520, a kernel-mode race condition in XNU’s virtual filesystem (VFS) implementation” I’m guessing it’s https://github.com/apple-oss-distributions/xnu/blob/bbb1b6f9e71b8cdde6e5cd6f4841f207dee3d828/bsd/vfs/vfs_cluster.c#L3700 ? There’s several VFS changes; not sure if this is the right one.
If it is this one, I guess you’d somehow
- Make a contiguous memory region,
- start reading a file into it,
- then switch it to a non-contiguous region after it’s validated the region, but before it actually starts reading the file,
- so it ends up writing what it thinks is your contiguous area, but actually is the first part of your area followed by some other memory?
Overview
- apostrophecms
- import-export
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
🚨 CRITICAL: CVE-2026-32731 in ApostropheCMS import-export (<3.5.3) allows path traversal via crafted .tar.gz uploads — attackers can write files anywhere the Node.js process can. Upgrade to 3.5.3+ ASAP! https://radar.offseq.com/threat/cve-2026-32731-cwe-22-improper-limitation-of-a-pat-efa014e1 #OffSeq #CVE202632731 #ApostropheCMS #infosec
Overview
- opf
- openproject
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🚨 CRITICAL: CVE-2026-32698 in OpenProject (CVSS 9.1) enables SQL injection via admin-created custom fields, leading to potential RCE if chained with repo module bug. Patch to 16.6.9/17.0.6/17.1.3/17.2.1+ now! https://radar.offseq.com/threat/cve-2026-32698-cwe-89-improper-neutralization-of-s-a9afd70e #OffSeq #SQLInjection #OpenProject #InfoSec
Overview
- Artifex Software Inc. *PyMuPDF*
- PyMuPDF
Description
Statistics
- 1 Post
- 1 Interaction
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 1 Post
- 1 Interaction