Overview
- Red Hat
- Red Hat Enterprise Linux 10
- xorg-x11-server-Xwayland
Description
Statistics
- 2 Posts
Fediverse
...
* glx: fix reversed length check in ChangeDrawableAttributes (CVE-2026-50262) (Closes: #1138680)
* saver: re-fetch screen private after CheckScreenPrivate in CreateSaverWindow (CVE-2026-50263) (Closes: #1138680)
* dix: increase XLFDMAXFONTNAMELEN to match libXfont2's MAXFONTNAMELEN (CVE-2026-50256) (Closes: #1138680)
* dri2: Use booleans for (fake) front buffer tracking in do_get_buffers (CVE-2026-50264) (Closes: #1138680)
...
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
Langflow Cryptominer Malware Exploits CVE-2026-33017
At least 39 rival malware families appear on a kill list used by a new Langflow cryptominer malware campaign. Threat actors now target exposed artificial intelligence application endpoints to breach enterprise networks. They exploit CVE-2026-33017, which is a critical remote code execution vulnerability. Consequently, attackers hijack servers to mine cryptocurrency. At a glance Malware Family: Modified KORKERDS/MALXMR variant Threat Actor:
Description
Statistics
- 1 Post
Fediverse
Exploit Heartbleed (CVE-2014-0160) with OpenSSL s_client: send a malformed heartbeat request with oversized payload length to extract up to 64KB of heap memory. Use -no_ssl3 -no_tls1 for TLS 1.0/1.1, -msg to capture leaked data. #cve #snippet #heartbleed #cve-2014-0160 #ValtersIT
https://www.valtersit.com/vault/heartbleed-memory-extraction-via-openssl-sclient-80ed4a/
Overview
Description
Statistics
- 1 Post
Fediverse
CVE-2026-52784 - Critical CSRF in OpenProject. Attackers can escalate privileges via /users/:id. CVSS 8.8. Update to 17.3.3 or 17.4.1 immediately. #CVE #OpenProject #infosec
Overview
- Uutils
- coreutils
- coreutils
Description
Statistics
- 1 Post
Fediverse
CVE-2026-35373 introduces a critical operational divergence in modern Linux system utilities, causing strict encoding enforcement to break automated backup and data migration pipelines. Access our strategic CSUITE briefing to audit system integrity: https://thecybermind.co/393z
Overview
- Apache Software Foundation
- Apache Kerby
- org.apache.kerby:kerb-server
Description
Statistics
- 1 Post
Fediverse
Apache Kerby, the Java implementation of Kerberos, shipped a fix for CVE-2026-57915: an authentication bypass where an attacker could skip pre-authentication by sending PA-DATA with an unrecognized or unsupported type. The severity is rated important, and the fix is in Kerby 2.1.2. How many Kerberos stacks silently accept PA-DATA types they do not understand, and how many of those are known to operators?
#Kerberos #security
Overview
Description
Statistics
- 1 Post
Overview
- Amazon Web Services
- Language Servers for AWS
Description
Statistics
- 1 Post
Fediverse
🚨 AWS Language Server Flaw!
CVE-2026-12957 allows zero-click command injection and cloud credential theft simply by opening a poisoned repository inside your IDE (affecting Amazon Q Developer).
https://denizhalil.com/2026/06/27/cve-2026-12957-aws-language-server-command-injection/
Overview
- notepad-plus-plus
- notepad-plus-plus
Description
Statistics
- 1 Post