Overview
- WordPress
- WordPress
Description
Statistics
- 5 Posts
- 5 Interactions
Fediverse
WordPress RCE. Every version ever released (except the latest, 7.0.3). 500+ million sites. 43% of the Internet-facing sites. Hacker's paradise.
"XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638)":
「WordPressの事前認証における新たなXSS脆弱性によりPHPコードの実行につながる可能性あり - 早急に修正を! 」: #TheHackerNews
「WordPressは、ログイン画面に存在する、認証前のリフレクテッドクロスサイトスクリプティング(XSS)の脆弱性を修正しました。この脆弱性は、コンテンツ管理システムのすべてのバージョンに影響を与えます。pwn.aiは、ログインした管理者が攻撃者によって制御されたページを操作する際に、この脆弱性がサーバー上でPHPコードの実行に連鎖的に繋がる仕組みを実証しました。
CVE-2026-64638 (CVSSスコア:8.9)として追跡されている この深刻な脆弱性は、攻撃者に特別な権限を必要としません。 」
https://thehackernews.com/2026/08/new-wordpress-pre-auth-xss-could-lead.html
En las últimas 24 horas, la seguridad informática enfrenta una severa vulnerabilidad en WordPress que permite ejecución remota de código, un retroceso en la confianza hacia plataformas de bug bounty como HackerOne, fallos frecuentes en parches generados por IA, descubrimientos avanzados de OpenAI para proteger sistemas críticos, y una brecha que expuso datos de 3.8 millones en el sector salud, mientras Cloudflare y nuevas herramientas IA mejoran la detección y análisis de amenazas. Descubre estos y más detalles en el siguiente listado de noticias sobre seguridad informática:
🗞️ ÚLTIMAS NOTICIAS EN SEGURIDAD INFORMÁTICA 🔒
====| 🔥 LO QUE DEBES SABER HOY 08/08/26 📆 |====
🔓 ¿QUÉ PASÓ CON HACKERONE?
La plataforma líder mundial en programas de recompensas por errores enfrentó un declive marcado tras su rápido ascenso, reflejando los desafíos en la sostenibilidad y confianza dentro del ecosistema de bug bounty. Entender esta historia es clave para evaluar la evolución de la seguridad colaborativa. Conoce más detalles sobre el devenir de HackerOne aquí 👉 https://djar.co/rh5IIs
💥 XSS2SHELL: CADENA DE XSS A RCE PREAUTENTICACIÓN EN WORDPRESS (CVE-2026-64638)
Una grave vulnerabilidad preautenticación en WordPress permite a atacantes remotos ejecutar código malicioso usando un ataque encadenado de Cross-Site Scripting a Remote Code Execution a través del formulario de login. Este fallo representa un riesgo crítico para millones de sitios, subrayando la necesidad urgente de actualizar y reforzar la seguridad de las plataformas web. Protege tu WordPress ahora revisando esta vulnerabilidad 👉 https://djar.co/LH68
🛡 RESPONDIENDO A LA NUEVA FRONTERA DE CAPACIDADES CIBERCRÍTICAS
OpenAI publica investigaciones preliminares sobre ciberseguridad en su proyecto Astra, detallando medidas avanzadas para fortalecer controles y salvaguardas frente a amenazas emergentes. Este enfoque proactivo es fundamental para anticipar y mitigar riesgos en inteligencia artificial y sistemas críticos. Infórmate sobre estas estrategias de defensa avanzada 👉 https://djar.co/VgIo
⚠️ PARCHEOS GENERADOS POR IA FALLAN LA MITAD DE LAS VECES
Un estudio exhaustivo de más de 6,000 parches automáticos revela que las soluciones generadas por inteligencia artificial no solo fallan frecuentemente, sino que pueden introducir nuevos errores, romper funcionalidades existentes y crear vectores para evasión de seguridad. Este hallazgo alerta sobre la dependencia excesiva en IA para mantenimiento crítico de software. Descubre los detalles del estudio y sus implicaciones 👉 https://djar.co/83x3J
🤖 COMPORTAMIENTOS BUENOS Y MALOS EN EL INTERNET AGÉNTICO
Cloudflare evalúa cómo distintos bots y agentes actúan en la red, diferenciando entre patrones benignos y maliciosos. Con sistemas como BotBase y Precursor, se implementan análisis continuos para mitigar amenazas automáticamente, mejorando la seguridad en el ecosistema digital. Aprende cómo se monitorizan y controlan estas actividades aquí 👉 https://djar.co/9ubDQ
📊 RADAR RESEARCHER: HERRAMIENTA DE IA PARA EXPLORAR DATOS DE INTERNET EN LENGUAJE SENCILLO
Una nueva herramienta impulsada por inteligencia artificial permite a usuarios explorar tendencias globales y datos de tráfico en internet usando lenguaje natural, transformando consultas complejas en gráficos interactivos fáciles de interpretar. Esta innovación facilita el análisis y la toma de decisiones informadas para profesionales de seguridad y tecnología. Prueba Radar Researcher y expande tu capacidad analítica 👉 https://djar.co/xeu6
🚨 BRECHA DE DATOS EN UNLIMITED TECHNOLOGY SYSTEMS AFECTA A 3.8 MILLONES
Una significativa brecha de seguridad en la empresa de software para salud Unlimited Technology Systems expuso datos personales de más de 3.8 millones de personas en octubre de 2025. Este incidente resalta la vulnerabilidad crítica en el sector salud y la urgencia de fortalecer protocolos de protección de datos sensibles. Infórmate sobre el alcance y recomendaciones tras la brecha 👉 https://djar.co/IA7842
Bluesky
Overview
Description
Statistics
- 1 Post
- 33 Interactions
Fediverse
Welp. My Forgejo instance got popped by CVE-2026-60004. Hooray for RCE 🙃
My two screw-ups were
1. I pinned it to v13 "for stability" forever ago, then forgot about it.
2. I accidentally left sign-ups enabled.
Grabbed the seemingly obfuscated payload script from the attacker's server. Looks like it hits a different IP and grabs one of three different binaries depending on the victim's CPU architecture. You best believe I'm grabbing those too
Will probably write a blog post on what I find, but I'll at least post updates here, too
Overview
- Cisco
- Cisco Secure Endpoint
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Cisco disclosed seven ClamAV vulnerabilities that let a remote attacker crash scanning via crafted files. Details are public. Patch now.
Overview
Description
Statistics
- 2 Posts
- 2 Interactions
Fediverse
「18年前のLinux SCTPの脆弱性により、ローカルユーザーがroot権限を取得し、コンテナから脱出できる可能性 」: #TheHackerNews
「LinuxのSCTPネットワークコードに存在する解放済みメモリ使用のバグを悪用すると、ホスト上で完全なroot権限を取得できる可能性がある。Tencentの研究者らは、このバグを利用してコンテナから脱出し、その下にあるマシンにアクセスしたと述べている。
この脆弱性は2008年から存在していました。修正版は既にリリースされており、8月3日にリリースされた安定版カーネル7.1.6、6.18.42、6.12.101、6.6.148で修正されています。SCTP接続可能な古いカーネルを使用しているユーザーはアップデートしてください。
CVE-2026-64564 として追跡され 、 発見者によってSCTPhantom と名付けられたこの脆弱性は、カーネルCVEチームが割り当てた2日後の8月6日に公表された。 」
https://thehackernews.com/2026/08/18-year-old-linux-sctp-flaw-could-let.html
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
Whoa, macOS Sequoia 15.7.9 changes:
> An attacker on the network may be able to authenticate to Screen Sharing without valid credentials
https://xcancel.com/calif_io/status/2086022794840793454
> If Screen Sharing is enabled, any network attacker can exploit the bug to log in as any account, without knowing the password.
Good thing it requires screen sharing to be enabled though.
CVE-2026-65400
CVE-2026-65400: macOS Screen Sharing Authentication Bypass Can Lead to Root-Level Remote Access
CVE-2026-65400 affects macOS Screen Sharing. Learn how the authentication flaw works, affected versions, exploitation research, detection etc.https://thecybersecguru.com/news/cve-2026-65400-macos-screen-sharing-authentication-bypass/
Overview
- brix
- crypto-js
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-71851 (CRITICAL, CVSS 9): brix crypto-js <4.0.0 uses weak RNG in WordArray.random(), risking private key recovery in wallet apps using BIP39. Upgrade to 4.0.0+ now. https://radar.offseq.com/threat/cve-2026-71851-cwe-331-insufficient-entropy-in-brix-crypto-js-e5283f6c465bd95e #OffSeq #CryptoJS #InfoSec #Vulnerability
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
🚨 Tails has released an emergency security update: Tails 7.10.1, patching critical flaws that could enable privilege escalation and potentially deanonymize users. It fixes CVE-2026-64560 (Linux kernel) and multiple Expat XML library issues. 🔐➡️ https://cyberinsider.com/tails-emergency-update-fixes-flaws-that-could-deanonymize-users/ #Tails #Tor #Cybersecurity #Privacy #SecurityUpdate
Overview
- Oracle Corporation
- Oracle WebLogic Server
Description
Statistics
- 1 Post
- 1 Interaction
Bluesky
Overview
- home-assistant
- core
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-66060 – High severity flaw in Home Assistant. Companion app executes NFC/QR tag automations without caller validation, letting malicious apps trigger actions. CVSS 7.1. Update to 2026.5.3+ immediately. #CVE #HomeAssistant #infosec
Overview
- V-Secure
- Jingyun Antivirus
Description
Statistics
- 1 Post
Fediverse
CVE-2026-19195 - Local privilege escalation in V-Secure Jingyun Antivirus via ZyArk.sys improper access controls. CVSS 7.8. Exploit public, no patch. Update or isolate now. #CVE #infosec #cybersecurity