Overview
Description
Statistics
- 5 Posts
- 103 Interactions
Fediverse
Significant number of vulnerabilities fixed in #OpenSSL - https://openssl-library.org/news/secadv/20260609.txt
The most serious one is CVE-2026-45447: Use-After-Free in the PKCS7_verify() Function that could lead to remote code execution in some conditions.
OpenSSL has released patches for 18 vulnerabilities, including a high-severity heap user-after-free bug identified as CVE-2026-45447 that could enable remote code execution. Discovered with the assistance of Claude AI, this flaw affects PKCS#7 signature verification and is one of several security issues addressed in the latest update.
https://www.securityweek.com/openssl-patches-high-severity-vulnerability-found-with-ai/
Thai Duong sent OpenSSL a crafted PKCS#7 message with an empty digestAlgorithms ASN.1 SET, and PKCS7_verify() went and freed a BIO the caller still owned. Later use corrupts the heap or, in some contexts, opens the door to remote code execution. That's CVE-2026-45447, the high-severity entry in a fresh 18-CVE batch. Applications on the CMS APIs aren't affected. Anyone still wired to the legacy PKCS#7 functions and reading this with mild dread?
#OpenSSL #infosec
Bluesky
Overview
Description
Statistics
- 6 Posts
- 1 Interaction
Fediverse
TSUITE INTEL: Critical vulnerability CVE-2026-42271 hits LiteLLM enterprise routing and n8n pipelines. Active CISA KEV exploitation verified. Deploy this forensic playbook for immediate environment sandboxing and egress security controls. Read at https://thecybermind.co/3jgn
Geopolitical tensions escalated with US "self-defense strikes" against Iranian targets (June 9-10, 2026) following a helicopter downing and missile launches. Israel also intensified operations in Southern Lebanon amidst a fragile Iran ceasefire. In technology, Apple's Siri is now powered by Google's Gemini. Cybersecurity saw active exploitation of the LiteLLM AI framework flaw (CVE-2026-42271) and Microsoft's June Patch Tuesday fixing 4 zero-days, including critical RCEs. Anthropic's new AI model, Claude Fable, raises crypto security concerns due to its zero-day exploit capabilities.
⚠️ CRITICAL: LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
A critical command injection vulnerability (CVE-2026-42271) in LiteLLM AI gateway versions 1.74.2 through 1.83.7 is being actively exploited in the wild. Researchers have chained this with a Starlette flaw to achieve unauthenticated RCE, bypassing authentication entirely. Compromised systems face i…
Bluesky
Overview
Description
Statistics
- 5 Posts
- 6 Interactions
Fediverse
⚠️ High-severity vulnerability in Linux caused by a single errant character
「 The presence of a single mis-issued exclamation point in code implementing nf_tables introduced a use-after-free, a class of vulnerability that corrupts memory by placing malicious code at memory addresses that haven’t been properly freed of their previous contents. CVE-2026-23111 can be exploited by an unprivileged user or process to elevate system rights to root 」
As someone who has worked directly with nftables and netlink sockets I can say both that I am not surprised and getting these things correct is hard. The patch for CVE-2026-23111 is a single ! character.
It's real easy to write meaningless bytes into a netlink socket but also useful when you need to reverse engineer undocumented xtables features 🤣
https://thehackernews.com/2026/06/one-character-linux-kernel-flaw-enables.html?m=1
https://blog.exodusintel.com/2026/06/08/off-by-exploiting-a-use-after-free-in-the-linux-kernel/
⚠️ CRITICAL: One-Character Linux Kernel Flaw Enables Local Root Access, Exploits Now Public
CVE-2026-23111 is a use-after-free in Linux kernel nf_tables code allowing unprivileged users to escalate to root and escape containers. Public exploits are now available. Unpatched systems with unprivileged user namespaces enabled are at immediate risk.
Bluesky
Overview
- ivanti
- Sentry
Description
Statistics
- 8 Posts
- 2 Interactions
Fediverse
🚨 CVE-2026-10520, a critical (CVSS 10.0) OS Command Injection vulnerability in Ivanti Sentry is now under active exploitation as reported by Defused
Scan infrastructure to see if you're vulnerable:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-10520.yaml
Patches are available as per Ivanti's advisory:
https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Sentry-CVE-2026-10520-CVE-2026-10523?language=en_US
Bluesky
Description
Statistics
- 5 Posts
Fediverse
@browserversiontracker Both updates (Vivaldi & Opera) include a fix for CVE-2026-11645 (Out of bounds memory access in V8), which has a known exploit in the wild. Brave and Chrome (+ESR) already had this fix in their previous round of updates.
Edge is the only Chromium based brower listed here that does not yet have a fix for this AFAIK.
Bluesky
Overview
Description
Statistics
- 5 Posts
- 6 Interactions
Fediverse
Affecting many different Arm CPU cores, CVE-2025-10263 could allow for privilege escalation on affected systems due to a specific timing condition during a memory permission change: Linux Sees Patches For "Critical" Vulnerability Affecting Many Arm CPUs - Phoronix https://www.phoronix.com/news/Arm-CPU-Critical-CVE-2025-10263
Bluesky
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Two Russian APT groups are exploiting a WinRAR flaw patched nearly a year ago to hit Ukraine
https://thenextweb.com/news/winrar-flaw-gamaredon-russia-ukraine-cve-2025-8088?utm_source=flipboard&utm_medium=activitypub
Posted into Fintech and ecommerce @fintech-and-ecommerce-thenextweb
Russia-aligned threat actors are actively exploiting a patched WinRAR vulnerability, CVE-2025-8088, to conduct cyber espionage and credential theft against Ukrainian government and military organizations. Because WinRAR lacks native auto-update features, many unpatched systems remain vulnerable to these phishing-based attacks that leverage malicious archives to execute arbitrary code.
https://www.darkreading.com/vulnerabilities-threats/russian-groups-winrar-flaw-ukrainian-orgs
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
https://github.com/v-p-b/avpwn
Overview
Description
Statistics
- 4 Posts
Fediverse
Bluesky
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
Notfall-Update bei Check Point VPN
Nanu? Sind die Israelis nicht die besten Hacker? Oder haben etwa Missetäter hier eine versteckte Hintertür gefunden? Die israelische Firma Check Point (zwei Worte!) hat gerade ein Notfall-Update veröffentlicht. Damit werden die beiden Sicherheitslücken CVE-2026-50751 und CVE-2026-50752 geschlossen. Die erste der beiden Lücken fiel auf, als ein Ransomware-Befall untersucht wurde. Bei der Untersuchung dieser Lücke fanden die Experten gleich noch eine weitere, die - im Gegensatz zur ersten - noch nicht für Angriffe ausgenutzt wird. Die weitere Analyse ergab, dass die erste Lücke bereits seit 2026-05-07 für Angriffe genutzt wird. Die Hacker hatten also vier
https://www.pc-fluesterer.info/wordpress/2026/06/10/notfall-update-bei-check-point-vpn/
#0day #closedsource #cybercrime #exploits #firewall #verschlüsselung #vpn