Overview
Description
Statistics
- 5 Posts
- 10 Interactions
Fediverse
Bluesky
Overview
Description
Statistics
- 3 Posts
- 2 Interactions
Fediverse
📰 Critical cPanel Flaw Allows Hosting Customers to Gain Root Access
Critical cPanel vulnerability (CVE-2026-65643) allows any authenticated user to gain full root access on shared hosting servers by abusing the domain parking feature. Patches are available and must be applied immediately. #cPanel #Vulnerability #Cybe...
⚠️ CRITICAL: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
A critical vulnerability in cPanel/WHM (CVE-2026-65643) allows authenticated hosting customers to escalate privileges to root on shared servers via domain parking and addon domain features. Any customer account can exploit this to achieve full server compromise. If your infrastructure runs cPanel/W…
🤖 AI generated summary
Overview
Description
Statistics
- 4 Posts
Fediverse
Geopolitical tensions persist with US-Iran disputes over the Strait of Hormuz, while a devastating glacial collapse hits Nepal-Tibet. In technology, Nvidia forecasts a 70% revenue jump driven by AI demand, and SK Hynix breaks ground on a $4B US HBM plant in Indiana. Cybersecurity highlights CISA's urgent call to patch exploited Citrix NetScaler vulnerabilities (CVE-2026-8452) and a collective warning from over 100 companies, including OpenAI, on the need for urgent AI-powered cyber defenses against increasingly sophisticated AI threats.
CISA impone un parche urgente por un fallo crítico en Citrix NetScaler con explotación activa
CISA ha metido CVE-2026-8452 en su catálogo Known Exploited Vulnerabilities y obliga a las agencias federales de EEUU a parchear Citrix NetScaler antes del 29 de agosto de 2026. La falla, que empezó describiéndose como un problema de denegación de servicio
CISA urges immediate patching for a critical Citrix NetScaler vulnerability (CVE-2026-8452) actively exploited in the wild. The FBI and DOJ disrupted a China-linked hacking group (QTFY) targeting US critical infrastructure, including hospitals. Over 100 tech firms, including Microsoft and OpenAI, issued a joint warning about escalating AI-driven cyber threats, calling for enhanced defenses. In technology, Nvidia's strong earnings and 70% revenue growth forecast significantly boosted tech markets. Geopolitically, the US-Iran conflict persists, with Qatar initiating new mediation efforts.
Overview
Description
Statistics
- 3 Posts
Fediverse
🚨 Critical Threat Intel: CVE-2023-49105 impacts ownCloud via improper authentication, enabling unauthenticated file access if signing-keys are missing. Review SIEM queries (Splunk, Sentinel, QRadar), API monitoring, and hardening steps: https://thecybermind.co/jily
Bluesky
Overview
- Microsoft
- Microsoft Exchange Server 2016 Cumulative Update 23
Description
Statistics
- 1 Post
- 28 Interactions
Fediverse
🚨 Für die kritische Schwachstelle CVE-2026-62911 in Microsoft Exchange wurde ein PoC-Exploit veröffentlicht, der die vollständige Übernahme von Systemen aus der Ferne ohne Authentifizierung ermöglicht. Der Hersteller veröffentlichte am 11.08. einen Patch. Aktuell sind jedoch noch rund 85% der on-premises Exchange-Server in Deutschland für diese Schwachstelle verwundbar. CERT-Bund benachrichtigt deutsche Netzbetreiber seit dem 14.08. regelmäßig zu noch verwundbaren Systemen in ihren Netzen.
Overview
- ServiceNow
- ServiceNow AI Platform
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
📰 ServiceNow Patches Three Critical CVSS 10.0 Flaws in AI Platform
ServiceNow patches three critical unauthenticated flaws (CVSS 10.0) in its AI Platform. The vulnerabilities (CVE-2026-18885, -18886, -74820) allow for RCE, privilege escalation, and SQL injection. Self-hosted customers must patch immediately. #Servic...
ServiceNow Patches Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Code Execution and SQL Injection
ServiceNow patched three CVSS 10.0 vulnerabilities allowing unauthenticated code execution, privilege escalation and SQL injectionhttps://thecybersecguru.com/news/servicenow-cve-2026-18885-18886-74820-cvss-10/
Overview
- Ebyte
- Ebyte NE2-D11 Firmware
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
🚨 Critical CVE-2026-73125 impacts Ebyte NE2-D11 devices
A critical missing-authentication vulnerability in the Ebyte NE2-D11 web management interface could allow a remote, unauthenticated attacker to access administrative functionality.
CVE-2026-73125 carries a CVSS 3.1 score of 9.8 and requires no privileges or user interaction. Successful exploitation could allow attackers to:
• Access sensitive configuration data
• Modify device settings
• Disrupt device availability
Affected firmware: FW-9167-0-11
Ebyte indicated a patch was under development, but CISA says it has not been informed of the patch's current availability. No confirmed active exploitation has been reported at this time.
CISA: https://www.cisa.gov/news-events/ics-advisories/icsa-26-237-06
Critical Ebyte NA111-M vulnerabilities like CVE-2026-73125 could allow attackers to fully compromise the device. Review CISA guidance and mitigations.
#Ebyte #NA111M #CISA #Vulnerability #Cybersecurity #CVE202673125
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Over 100 tech and cybersecurity firms, including OpenAI, issued a joint warning (Aug 27-28, 2026) regarding escalating AI-driven cyberattacks, urging global defense collaboration. Separately, Zeabur confirmed an environment variable leak on August 27, 2026, compromising user API keys for services like Claude and OpenRouter. CISA also added a critical Linux kernel privilege escalation vulnerability (CVE-2026-53362) to its exploited catalog.
Overview
- Unitree Robotics
- G1 EDU
Description
Statistics
- 2 Posts
Bluesky
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
Week in Fediverse 2026-08-28
Servers
- Hollo v0.9.13
- gush! v0.0.41
- tootik v0.25.0
- Mitra v5.10.0
- Pixelfed v0.12.9
- Hollo v0.9.15
- Funkwhale v2.0.10
- PieFed v1.7.13
- tootik v0.25.1
- NeoDB v0.17.8
Clients
- Pachli v3.8.1
- Fedilab v3.43.2
- RaccoonForFriendica v1.1.0
For developers
Protocol
- FEP-49eb: Batched Inbox Delivery
Articles
- A crawler wanted to know who talks to whom on our server
- The Problems and Successes of Fediverse Comments on my blog
- The Fediverse is Throwing a Music Festival
-----
#WeekInFediverse #Fediverse #ActivityPub
Previous edition: https://mitra.social/objects/01a0269e-d9e5-7a03-a62d-6ef77099e4a7