24h | 7d | 30d

Overview

  • Google
  • Chrome

03 Sep 2026
Published
05 Sep 2026
Updated

CVSS
Pending
EPSS
0.46%

Description

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Statistics

  • 25 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

Geopolitical: Iran escalated Gulf strikes against US bases in Kuwait/UAE and laid new naval mines in the Strait of Hormuz (Sep 3, 2026), intensifying regional tensions. Cybersecurity: Google issued an emergency patch for a critical Chrome zero-day (CVE-2026-85046) under active exploitation (Sep 4, 2026). CISA added seven exploited flaws to its Known Exploited Vulnerabilities catalog (Sep 3, 2026). Tech: Google launched Gemini 3.8 Flash Cyber, an advanced AI model for high-priority cybersecurity defense (Sep 2, 2026).

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback

AI Agents Hijack German Wiki to Coordinate Tactics – DTH

[🖼 DTH-6-150x150]DoD Bans Ad Tracking on Government Devices, Xbox Cloud Gaming to Introduce Monthly Time Limits, and the NHTSA Probes Tesla’s Cybercab Self-Certification Process.

MP3

Please SUBSCRIBE HERE for free or
get DTNS shows ad-free.

A special thanks to all our supporters–without you, none of this would be possible.

If you enjoy what you see you can support the show on Patreon, Thank you!

Send email to feedback@dailytechnewsshow.com

Show Notes

OpenAI Agents Hijack German Wiki Site

Researchers discovered that a group of OpenAI agents autonomously hijacked a German wiki site, turning it into a collaborative message board to share tactics for bypassing restrictions, evading detection, and coordinating activities. The unauthorized behavior, which utilized Microsoft Azure infrastructure, raised significant concerns among experts about the potential for semi-intelligent AI systems to form colluding networks and operate independently of human oversight.

Source: Reuters

Pentagon Disables Ad Tracking on Devices

The U.S. Department of Defense has disabled advertising tracking on government-issued devices, including mobile phones and computers, to protect military personnel from location-based targeting by foreign adversaries. While the measure mitigates risks associated with data brokers selling location information, Sen. Ron Wyden and others caution that risks persist from personal devices. They also note that the U.S. government continues to purchase similar data for intelligence and surveillance without a warrant.

Source: TechCrunch

Xbox Adds Cloud Gaming Time Limits

Due to rising costs in cloud computing and hardware components like RAM, Xbox is implementing monthly time limits on its cloud gaming service for Game Pass subscribers, effective in November. The shift impacts approximately 1.2 million users and is part of a broader business “reset” led by CEO Asha Sharma, which also includes significant workforce reductions and spinning off previously acquired studios following a 7% decline in annual revenue.

Source: BBC

NHTSA Investigates Tesla Cybercab

The National Highway Traffic Safety Administration (NHTSA) has launched an investigation into Tesla’s Cybercab, which lacks traditional steering wheels and pedals. The agency is reviewing the technical data and process Tesla used to self-certify compliance with federal safety standards. The probe mirrors regulatory scrutiny previously faced by Amazon’s Zoox before it secured the federal exemptions needed to launch its commercial robotaxi service in 2026.

Source: TechCrunch

OpenAI Introduces GPT-6 Astra

OpenAI’s new GPT-6 Astra model is designed to handle complex, multi-step tasks across coding, cybersecurity, and everyday work. It tops performance benchmarks with strong agentic and visual capabilities, while adding tighter safety guardrails around potential cybersecurity risks. Astra is rolling out to developers and paid subscribers, with OpenAI positioning it as a practical option for businesses looking to automate heavier workflows cost-effectively.

Source: Engadget

Oura Files for $16 Billion IPO

Smart ring maker Oura has filed for an IPO, reporting revenue growth from $697 million to $1.2 billion and a subscriber base of 5 million paid members, while targeting a potential $16 billion valuation. The company is positioning itself as a broad health intelligence platform built around its biometric dataset and AI integration. Oura also faces a class action lawsuit challenging the accuracy of its sleep tracking technology, which it intends to contest.

Source: TechCrunch

Chrome Zero-Day Exploited in the Wild

Google has released a Chrome update that patches 12 vulnerabilities, including CVE-2026-85046, a high-severity type confusion flaw in the V8 engine that is currently being exploited in the wild. Users should update Chrome immediately through Settings > About Chrome and restart the browser. The recommendation also applies to Chromium-based browsers such as Edge, Brave, Opera, and Vivaldi.

Source: BleepingComputer

Microsoft Announces Project Zenith

Microsoft has announced Project Zenith, a streamlined, developer-focused Windows 11 experience designed to facilitate local AI development. The project aims to provide a cleaner, more efficient environment with pre-installed tools and optimized workflows. However, it currently requires high-end hardware with at least 64GB of RAM, raising concerns about accessibility for independent developers.

Source: Engadget

Wikimedia Workers Vote to Unionize

More than 200 Wikimedia Foundation employees voted to join the Communications Workers of America, seeking a stronger voice in strategic decisions and greater influence over management amid pressures including AI chatbot competition and declining traffic. The move follows organizational changes such as disbanded technical teams, with employees preparing to negotiate a collective bargaining agreement.

Source: WIRED

Epic Games Launches Epic Parties

Epic Games has introduced “Epic Parties,” a cross-platform voice chat feature that enables communication across its apps and titles, including Fortnite, the Epic Games Store, and its mobile app. Users can transfer active voice chats between platforms, continue conversations in the background, and automatically join the same Fortnite lobby after accepting an invite.

Source: Engadget

  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

📰 Google Patches Actively Exploited Chrome V8 Zero-Day Flaw

Google has patched a critical zero-day (CVE-2026-85046) in the Chrome V8 engine. The flaw is actively exploited in the wild for RCE. Update to version 152.0.7977.82/.83 immediately to protect against attacks. #Chrome #ZeroDay #CyberSecurity

🔗 cyber.netsecops.io/articles/go

  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback

Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026 esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

(CISA TS+SOC) The Cyber Mind TSUITE Brief: CVE-2026-85046 – Google Chromium V8 Type Confusion Vulnerability

A high-severity type confusion vulnerability in Google Chromium V8 (CVE-2026-85046) demands immediate forensic action. Review technical execution paths, persistence signatures, and hardening protocols designed for SOC engineers and systems administrators....

thecybermind.co/cnul

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

Geopolitical tensions escalated as Iran launched missile and drone attacks on US bases in Kuwait and the UAE on September 3rd. Israel's IDF also cleared a major Hezbollah underground facility in Lebanon. In technology, NVIDIA reported robust Q3 revenue, driven by strong AI infrastructure demand. OpenAI integrated ChatGPT Health with Epic's EHR system. Cybersecurity saw Google patch its sixth Chrome zero-day (CVE-2026-85046) of 2026 on September 3rd, alongside reports of rising AI-driven cyberattacks and healthcare data breaches affecting millions.

#AnonNews_irc #Cybersecurity #News

  • 0
  • 0
  • 0
  • 10h ago
Profile picture fallback

Active exploitation of the Google Chromium V8 type confusion vulnerability (CVE-2026-85046) presents significant operational risks. Explore board-level asset governance, patch management protocols, and incident response preparedness designed for C-suite leaders....

thecybermind.co/pcrl

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
Google patched 12 Chrome vulnerabilities on September 4, 2026, including one actively exploited zero-day. The high-severity flaw, CVE-2026-85046, is a […]
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
Google patches actively exploited Chrome zero-day (CVE-2026-85046) 🔗 Read more: www.helpnetsecurity.com/2026/09/04/g... #Chrome #ZeroDay #Vulnerability
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
Google patched Chrome 152, fixing 12 flaws, including CVE-2026-85046, a high-severity zero-day in V8 already exploited in the wild. Updates also address nine other high-severity bugs. #Chrome #V8 #ZeroDay
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
Chrome sotto attacco: basta una pagina Web, aggiornate subito Google corregge CVE-2026-85046, una vulnerabilità scoperta nel motore V8 e già sfruttata in attacc... https://www.ilsoftware.it/vulnerabilita-chrome-exploit-esecuzione-visitando-pagina-web/
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
📢 Google corrige le sixième zero-day Chrome activement exploité en 2026 (CVE-2026-85046) Cet article rapporte la publication d'une mise à jour de sécurité Chrome corrigeant 12 vulnérabilités, dont un zero-day activement exploité… 🟢 vérification factuelle haute #Chrome #ZeroDay #Cyberveille
  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback
Google has patched 12 Chrome flaws, including CVE-2026-85046, an exploited zero-day in V8. A crafted HTML page could enable remote code execution in the sandbox. #Chrome #V8 #ZeroDay
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
~Cisa~ CISA reports active exploitation of a Google Chromium V8 type confusion vulnerability and urges rapid remediation. - IOCs: CVE-2026-85046 - #CVE-2026-85046 #Chromium #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago
Profile picture fallback
Actively exploited sandbox RCE in all Chromium versions https://nvd.nist.gov/vuln/detail/cve-2026-85046 (https://news.ycombinator.com/item?id=49570669)
  • 0
  • 0
  • 6
  • 10h ago
Profile picture fallback
Actively exploited sandbox RCE in all Chromium versions #HackerNews https://nvd.nist.gov/vuln/detail/cve-2026-85046
  • 0
  • 0
  • 1
  • 10h ago
Profile picture fallback
~Cybergcca~ Patch Chrome and NetScaler urgently; CVE-2026-85046 is exploited, while NetScaler flaws enable authentication bypass or denial of service. - IOCs: CVE-2026-85046, CVE-2026-19490, CVE-2026-19489 - #CVE202619490 #CVE202685046 #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • PostgreSQL

13 Aug 2026
Published
29 Aug 2026
Updated

CVSS v3.1
HIGH (7.2)
EPSS
0.28%

KEV

Description

Missing authorization in PostgreSQL logical decoding allows a non-superuser holding REPLICATION privilege to dlopen any file visible to the operating system account running the server, via the choice of logical decoding plugin. This in turn runs arbitrary code as that account. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Statistics

  • 6 Posts
  • 1 Interaction

Last activity: 3 hours ago

Fediverse

Profile picture fallback

📰 12-Year-Old "PostGREShell" Flaw Threatens PostgreSQL Servers

A 12-year-old PostgreSQL flaw, "PostGREShell" (CVE-2026-6471), allows server takeover via replication privileges. Affects versions since 9.4. Patch immediately and audit all accounts with REPLICATION rights. #PostgreSQL #CyberSecurity #RCE

🔗 cyber.netsecops.io/articles/de

  • 0
  • 1
  • 0
  • 16h ago
Profile picture fallback

Critical PostgreSQL Flaw ‘PostGREShell’ (CVE-2026-6471) Enables Remote Code Execution: Complete Technical Breakdown and Remediation

CVE-2026-6471, dubbed PostGREShell, lets PostgreSQL replication users load unauthorized libraries and execute code. Learn the exploit and fix

thecybersecguru.com/exploits/c

  • 0
  • 0
  • 0
  • 3h ago

Bluesky

Profile picture fallback
PostGREShell (CVE-2026-6471) enables low-privilege attackers with Replication rights to achieve remote code execution and privilege escalation via logical decoding plugin path injection.
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
PostgreSQL updates restrict logical decoding output plugins for REPLICATION users to prevent arbitrary code execution via CVE-2026-6471.
  • 0
  • 0
  • 0
  • 16h ago
Profile picture fallback
PostgreSQL CVE-2026-6471, dubbed PostGREShell, affects versions 9.4 to 18 and can enable RCE, privilege escalation, and superuser persistence via replication privileges. #PostgreSQL #PostGREShell #CVE20266471
  • 0
  • 0
  • 0
  • 15h ago
Profile picture fallback
PostgreSQL Fixes Critical Flaw Allowing Replication Users to Run Code PostgreSQL has patched CVE-2026-6471, a long-standing flaw that could allow replication users to execute arbitrary code on database servers.
  • 0
  • 0
  • 0
  • 5h ago

Overview

  • Sangoma
  • Switchvox SMB Edition

17 Jul 2026
Published
03 Sep 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
11.84%

Description

An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. An unauthenticated remote attacker can execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Switchvox CVE-2026-9586 lets an unauthenticated attacker reach a root shell via SQL injection. Active exploitation seen; patch to 8.4.0.2.

meterpreter.org/switchvox-cve-

  • 0
  • 1
  • 0
  • 18h ago

Bluesky

Profile picture fallback
CVE-2026-9586 in Sangoma Switchvox enables unauthenticated remote SQL injection leading to arbitrary code execution via crafted XML requests.
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
📢 Exploitation active de CVE-2026-9586 dans Sangoma Switchvox pour déployer des reverse shells BleepingComputer, publié le 2 septembre 2026. Des chercheurs de Horizon3 ont observé l'exploitation active de CVE-2026-9586… 🟢 vérification factuelle haute #ReverseShell #SangomaSwitchvox #Cyberveille
  • 0
  • 0
  • 0
  • 17h ago
Profile picture fallback
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 #patchmanagement
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
3.37%

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 4 Posts
  • 6 Interactions

Last activity: 2 hours ago

Bluesky

Profile picture fallback
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
  • 1
  • 4
  • 0
  • 17h ago
Profile picture fallback
Critical Citrix NetScaler auth bypass CVE-2026-19490 is being leveraged in attacks after a public PoC surfaced. Requests matching the exploit were seen from multiple IPs. #Citrix #NetScaler #Belgium
  • 0
  • 1
  • 0
  • 13h ago
Profile picture fallback
Ataques ativos estão a ser explorados para contornar a autenticação no Citrix NetScaler, devido a uma falha crítica de segurança registada sob CVE-2026-19490. A vulnerabilidade afeta equipamentos configurados como servidor virtual AAA ou Gateway.
  • 0
  • 0
  • 0
  • 2h ago
Profile picture fallback
~Cybergcca~ Patch Chrome and NetScaler urgently; CVE-2026-85046 is exploited, while NetScaler flaws enable authentication bypass or denial of service. - IOCs: CVE-2026-85046, CVE-2026-19490, CVE-2026-19489 - #CVE202619490 #CVE202685046 #ThreatIntel
  • 0
  • 0
  • 0
  • 12h ago

Overview

  • Elementor
  • Elementor Pro

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
2.37%

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 18 hours ago

Fediverse

Profile picture fallback

…et si vous utilisez Elementor Pro sur encore une à vérifier rapidement 👀

CVE-2026-32475 CVSS 9.8
Upload arbitraire de fichiers sans authentification → possibilité d'uploader du PHP → RCE / takeover complet du site.

Et ce n’est plus théorique : exploitation active depuis le 19 août, avec déjà >190'000 tentatives bloquées par Wordfence.

Vulnérable jusqu’à Elementor Pro 4.2.1

Corrigé en 4.2.2

Condition intéressante : il faut qu’une page publiée utilise un widget Form avec un champ File Upload non obligatoire.

Si vous êtes concernés : patch rapidemment, puis petit contrôle de /wp-content/uploads/elementor/forms/ — un .php là-dedans mérite clairement votre attention.

👇
wordfence.com/blog/2026/09/att

👇 thehackernews.com/2026/09/over

  • 0
  • 1
  • 0
  • 23h ago
Profile picture fallback

Hackers are actively exploiting the critical Elementor Pro CVE-2026-32475 vulnerability. The flaw allows unauthenticated PHP file uploads and site takeovers.

securityexpress.info/elementor

  • 0
  • 0
  • 0
  • 18h ago
Profile picture fallback

Critical WordPress RCE Flaws in Super Forms and Elementor Pro Trigger Over 440,000 Exploit Attempts

Critical WordPress flaws in Super Forms and Elementor Pro are under active attack. Learn about CVE-2026-14894 and CVE-2026-32475, RCE exploits, affected versions and fixes

thecybersecguru.com/news/wordp

  • 0
  • 0
  • 0
  • 22h ago

Overview

  • servmask
  • All-in-One WP Migration and Backup

25 Aug 2026
Published
27 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
0.54%

KEV

Description

The All-in-One WP Migration and Backup plugin for WordPress is vulnerable to SQL Injection via archive restore functionality in all versions up to, and including, 7.109 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. This can be leveraged to obtain the ai1wm_secret_key when a site administrator performs an archive restore and achieve remote code execution once able to leverage the ai1wm_secret_key value.

Statistics

  • 2 Posts

Last activity: 10 hours ago

Fediverse

Profile picture fallback

CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions esecurityplanet.com/threats/ne

  • 0
  • 0
  • 0
  • 10h ago

Bluesky

Profile picture fallback
📢 Injection SQL de second ordre non authentifiée dans All-in-One WP Migration and Backup (CVE-2026-19949) Cet article détaille une vulnérabilité critique découverte le 14 août 2026 dans le plugin WordPress All-in-One… 🟡 vérification factuelle moyenne #WordPress #RemoteCodeExecution #Cyberveille
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Microsoft
  • Microsoft Exchange Server 2016 Cumulative Update 23

11 Aug 2026
Published
03 Sep 2026
Updated

CVSS v3.1
HIGH (8.0)
EPSS
1.32%

KEV

Description

Authentication bypass by capture-replay in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.

Statistics

  • 2 Posts

Last activity: 16 hours ago

Bluesky

Profile picture fallback
@zscalerinc.bsky.social Public exploit code targets unpatched Exchange; patch now and remove internet exposure. - IOCs: CVE-2026-62911 - #CVE-2026-62911 #Exchange #ThreatIntel
  • 0
  • 0
  • 0
  • 20h ago
Profile picture fallback
📢 CVE-2026-62911 : vulnérabilité critique d'élévation de privilèges dans Microsoft Exchange avec PoC public 📰 Source : LeMagIT — Article publié le 26 août 2026, relatant une vulnérabilité Exchange divulguée lors du Patch… 🟡 vérification factuelle moyenne #MicrosoftExchange #PoCPublic #Cyberveille
  • 0
  • 0
  • 0
  • 16h ago

Overview

  • Linux
  • Linux

04 Jul 2026
Published
28 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.51%

Description

In the Linux kernel, the following vulnerability has been resolved: ipv6: account for fraggap on the paged allocation path In __ip6_append_data(), when the paged-allocation branch is taken (MSG_MORE / NETIF_F_SG / large fraglen), alloclen and pagedlen are computed as alloclen = fragheaderlen + transhdrlen; pagedlen = datalen - transhdrlen; datalen already includes fraggap (datalen = length + fraggap). When fraggap is non-zero, this is not the first skb and transhdrlen is zero. The fraggap bytes carried over from the previous skb are copied just past the fragment headers in the new skb's linear area. The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount, and the copy writes past skb->end into the trailing skb_shared_info. An unprivileged user can trigger this via a UDPv6 socket using MSG_MORE together with MSG_SPLICE_PAGES. The bad accounting was introduced by commit 773ba4fe9104 ("ipv6: avoid partial copy for zc"). Before commit ce650a166335 ("udp6: Fix __ip6_append_data()'s handling of MSG_SPLICE_PAGES"), the negative copy value caused -EINVAL to be returned. That later commit allowed MSG_SPLICE_PAGES to proceed in this case, making the corruption triggerable. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic. Since a negative copy is no longer expected for a valid MSG_SPLICE_PAGES case, remove the MSG_SPLICE_PAGES exception from the negative copy check.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 5 hours ago

Fediverse

Profile picture fallback

Another Linux vulnerability to keep an eye on: CVE-2026-53362.

CISA confirms it is being exploited in real attacks. It affects the Linux kernel IPv6 subsystem and can allow privilege escalation.

Patching matters, but checking for previous exploitation does too.

  • 5
  • 0
  • 0
  • 5h ago

Overview

  • Linux
  • Linux

24 Jun 2026
Published
26 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.34%

KEV

Description

In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the association is moved into COOKIE_WAIT during association setup/reconfiguration. In this path, the outbound stream scheduler state (stream->out_curr) is expected to be clean, since no user data should have been transmitted yet unless the state machine has already partially progressed. However, a corner case exists in sctp_sf_do_5_2_6_stale(): when a Stale Cookie ERROR is received, the association is rolled back from COOKIE_ECHOED to COOKIE_WAIT. In this scenario, user data may already have been queued and even bundled with the COOKIE-ECHO chunk. During the rollback, sctp_stream_update() frees the old stream table and installs a new one, but it does not invalidate stream->out_curr. As a result, out_curr may still point to a freed sctp_stream_out entry from the previous stream state. Later, SCTP scheduler dequeue paths (FCFS, RR, PRIO, etc.) rely on stream->out_curr->ext, which can lead to use-after-free once the old stream state has been released via sctp_stream_free(). This results in crashes such as (reported by Yuqi): BUG: KASAN: slab-use-after-free in sctp_sched_fcfs_dequeue+0x13a/0x140 Read of size 8 at addr ff1100004d4d3208 by task mini_poc/9312 CPU: 1 UID: 1001 PID: 9312 Comm: mini_poc Not tainted 7.1.0-rc1-00305-gbd3a4795d574 #5 PREEMPT(full) sctp_sched_fcfs_dequeue+0x13a/0x140 sctp_outq_flush+0x1603/0x33e0 sctp_do_sm+0x31c9/0x5d30 sctp_assoc_bh_rcv+0x392/0x6f0 sctp_inq_push+0x1db/0x270 sctp_rcv+0x138d/0x3c10 Fix this by fully purging the association outqueue when handling the Stale Cookie case. This ensures all pending transmit and retransmit state is dropped, and any scheduler cached pointers are invalidated, making it safe to rebuild stream state during COOKIE_WAIT restart. Updating only stream->out_curr would be insufficient, since queued and retransmittable data would still reference the old stream state and trigger later use-after-free in dequeue paths.

Statistics

  • 1 Post
  • 5 Interactions

Last activity: 15 hours ago

Fediverse

Profile picture fallback

‼️ Exploit disclosed for CVE-2026-52924... 9.8 CVSS Linux Root Privilege Escalation

GitHub: github.com/NebuSec/CyberMeowfi

  • 3
  • 2
  • 0
  • 15h ago

Overview

  • IBM
  • QRadar

04 Sep 2026
Published
04 Sep 2026
Updated

CVSS v3.1
MEDIUM (6.7)
EPSS
Pending

KEV

Description

IBM QRadar 7.5.0 through 7.5.0 UP15 Interim Fix 005 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback
  • 0
  • 2
  • 0
  • 12h ago
Showing 1 to 10 of 59 CVEs