Overview
- Microsoft
- Windows Notepad
Description
Statistics
- 1 Post
- 31 Interactions
Fediverse
Vulnerabilidad grave en la fantástica nueva versión de Bloc de notas:
El CVE:
👉 https://www.cve.org/CVERecord?id=CVE-2026-20841
La explicación:
Si abres un archivo de texto MarkDown (MD) que tenga un enlace... dicho enlace puede EJECUTAR CUALQUIER COSA en la máquina.
La URL que hay adentro del enlace, al cual puedes hacer click, la ejecuta Bloc de notas a pelo utilizando "ShellExecuteExW":
👉 https://learn.microsoft.com/en-us/windows/win32/api/shellapi/nf-shellapi-shellexecuteexw
#ciberseguridad #cybersecurity #windows #notepad #blocdenotas
Overview
- 0xJacky
- nginx-ui
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Critical Nginx UI Vulnerability Exposes Server Backups and Sensitive Data
https://thecyberexpress.com/cve-2026-27944-nginx-ui-backup-vulnerability/?utm_source=flipboard&utm_medium=activitypub
Posted into Cybersecurity Today @cybersecurity-today-rhudaur
Bluesky
Overview
- misskey-dev
- misskey
Description
Statistics
- 4 Posts
- 3 Interactions
Fediverse
🚨 CVE-2026-28431 (CRITICAL, CVSS 9.2) in Misskey (8.45.0 – <2026.3.1): Improper authorization allows unauthenticated data access. Patch to 2026.3.1 now! Review access controls and monitor logs. https://radar.offseq.com/threat/cve-2026-28431-cwe-285-improper-authorization-in-m-e4688f7e #OffSeq #Misskey #Vuln #InfoSec
https://www.openwall.com/lists/oss-security/2026/03/09/7
#Fediverse #ActivityPub #misskey #sharkey
CVE-2026-28431
CVE-2026-28432
CVE-2026-28433
Bluesky
Overview
- CODESYS
- CODESYS Installer
Description
Statistics
- 2 Posts
Fediverse
#OT #Advisory VDE-2026-012
CODESYS Installer - Possible Privilege Escalation
Exploitation of this vulnerability can lead to a privilege escalation on the host system.
#CVE CVE-2026-2364
https://certvde.com/en/advisories/vde-2026-012/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2026/advisory2026-01_vde-2026-012.json
🚩 CVE-2026-2364: HIGH severity TOCTOU flaw in CODESYS Installer (all versions) lets local attackers escalate privileges via user-initiated updates. Restrict access & monitor until patch. No active exploits yet. https://radar.offseq.com/threat/cve-2026-2364-cwe-367-time-of-check-time-of-use-to-5eb858d5 #OffSeq #CODESYS #ICS #Vuln
Overview
Description
Statistics
- 1 Post
- 23 Interactions
Fediverse
https://nvd.nist.gov/vuln/detail/CVE-2025-56132
"You can enumerate email addresses by sending a request to password_reset with different test emails and seeing how the server responds"
so we're assigning CVEs to basic HTB tricks now huh?
Overview
Description
Statistics
- 2 Posts
Fediverse
Critical Cisco Catalyst SD-WAN vulnerability (CVE-2026-20127, CVSS 10.0) is now under widespread exploitation.
Attackers are deploying webshells after the flaw moved from targeted zero-day use to global opportunistic campaigns.
https://www.technadu.com/cisco-catalyst-sd-wan-flaw-is-now-fcing-widespread-exploitation/622887/
Have your systems been patched?
Latest Geopolitical, Technology, and Cybersecurity Update (March 6-7, 2026):
Russia is reportedly sharing intelligence with Iran to target US forces in the Middle East, escalating tensions. Cybersecurity faces critical threats as a Cisco SD-WAN flaw (CVE-2026-20127) has been exploited since 2023, and a Qualcomm zero-day (CVE-2026-21385) affects 234 chipsets. Meanwhile, rapid AI advancements are intensifying regulatory debates globally.
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 4 Interactions
Fediverse
https://red.anthropic.com/2026/exploit/
Overview
Description
Statistics
- 1 Post
- 3 Interactions
Fediverse
Wie lukrativ der Handel mit Exploits ist, wird anhand einer aktuellen #Sicherheitslücke für das #Microsoft Betriebssystem #Windows deutlich: So wird im Darknet offenbar ein #Exploit für rund 220.000 US-Dollar angeboten.
Laut den verfügbaren Berichten geht es um eine #Schwachstelle in den Remote Desktop Services, die Windows 10, Windows 11 und mehrere Server-Versionen betreffen soll und mit welcher der Angreifer seine Systemrechte unbefugt ausweiten kann:
https://www.connect.de/news/windows-sicherheit-cve-2026-21533-darknet-3212047.html #cybersecurity
Overview
Description
Statistics
- 1 Post
- 1 Interaction