Aggregator
CVE-2026-9632 | UTT HiPER 1250GW up to 3.2.7-210907-180535 Web Management Interface /goform/formGroupConfig strcpy Profile stack-based overflow (EUVD-2026-32038)
CVE-2026-7493 | croixhaug Appointment Booking Calendar Plugin up to 1.6.11.5 on WordPress REST API Endpoint /wp-json/ssa/v1/async sleep resource consumption (EUVD-2026-32036)
CVE-2026-49014 | GDAL up to 3.13.0 netCDF Driver netcdfsg.cpp geometry stack-based overflow (Issue 14594 / EUVD-2026-32039)
CVE-2026-6565 | analogwp Style Kits for Elementor Plugin up to 2.5.0 on WordPress save Title cross site scripting (EUVD-2026-32037)
CVE-2026-49017 | OpenStack Swift up to 2.36.1/2.37.1 StreamingInput infinite loop (EUVD-2026-32040)
The Underminr Paradigm: Subverting DNS Filters via CDN Networks
The cybersecurity researchers at ADAMnetworks recently unveiled a novel evasion technique. This method allows malicious data packets to conceal themselves behind trusted domains and Content Delivery Networks (CDNs). Consequently, this development threatens organizations relying...
The post The Underminr Paradigm: Subverting DNS Filters via CDN Networks appeared first on Information Security News.
can someone help or teach me in this situation?
Critical Security Defect Exploits NTFS Processing Architecture Within 7-Zip
Researchers have unearthed a critical security vulnerability within the ubiquitous 7-Zip data compression utility. Opening a meticulously engineered disk image triggers arbitrary remote code execution rather than a standard decompression failure. Crucially, this memory...
The post Critical Security Defect Exploits NTFS Processing Architecture Within 7-Zip appeared first on Information Security News.
RHEL替代品AlmaLinux 10.2版发布 新增Btrfs启动支持以及完善支持i686架构
Remediation of the Critical Privilege Escalation Flaw in LiteSpeed’s cPanel Extension
Perimeter Compromise and Systemic Risk LiteSpeed recently resolved a critical privilege escalation vulnerability within its user-facing cPanel plugin. This severe security defect is tracked globally as CVE-2026-48172. Threat actors are already exploiting this flaw...
The post Remediation of the Critical Privilege Escalation Flaw in LiteSpeed’s cPanel Extension appeared first on Information Security News.
Architectural Rectification of the FatGid Flaw: Securing the FreeBSD Kernel Against Privilege Escalation
The FreeBSD security apparatus has successfully resolved a high-severity vulnerability, cataloged as CVE-2026-45250, within the setcred(2) system call architecture. This fundamental defect resided within the core kernel logic, empowering an unauthenticated local adversary to...
The post Architectural Rectification of the FatGid Flaw: Securing the FreeBSD Kernel Against Privilege Escalation appeared first on Information Security News.
Астероид Психея может быть обнажённым ядром древней планеты, разрушенной миллиарды лет назад. И наш зонд уже летит туда
Windows 11 Secure Boot: 2026 Expiration Warning
Microsoft has issued a cautionary directive to proprietors of Windows 11 ecosystems: failure to transition computational hardware to the modernized Secure Boot cryptographic certificates prior to June 2026 will not precipitate catastrophic boot failures;...
The post Windows 11 Secure Boot: 2026 Expiration Warning appeared first on Information Security News.
Verus Recovers the Majority of Exploited Bridge Assets
The Verus project has successfully reclaimed most of its capital following the recent cryptographic bridge exploit. The community reported that the attacker returned 4,052.4 ETH. Consequently, the team now controls approximately 75% of the...
The post Verus Recovers the Majority of Exploited Bridge Assets appeared first on Information Security News.
GitLab Suspends Windows Exploit Researcher Nightmare-Eclipse After GitHub Ban
The anonymous researcher known as Nightmare-Eclipse has been blocked from two major code-hosting platforms in less than a week, as their disruptive public zero-day campaign against Microsoft draws serious real-world consequences. GitLab moved to suspend the account of security researcher Nightmare-Eclipse on May 26, 2026, just days after GitHub, owned by Microsoft, terminated the researcher’s […]
The post GitLab Suspends Windows Exploit Researcher Nightmare-Eclipse After GitHub Ban appeared first on Cyber Security News.