#vulnerabilities

31 posts · Last used 9d

Back to Timeline
Marcus "MajorLinux" Summers @majorlinux@toot.majorshouse.com · Aug 05, 2026
Hopefully, the fixes aren't too far behind. Google Password Manager passkeys could be at risk with new 'Pass-ta-key' attack https://9to5google.com/2026/08/04/google-password-manager-passkeys-could-be-at-risk/ #Google #passwordManager #Passkeys #Vulnerabilities #Security #Tech
0
0
3
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Aug 04, 2026
Apache NiFi vulnerabilities, including CVE-2026-68979, CVE-2026-62354, and CVE-2026-68981, expose users to code execution and resource consumption. #ApacheNiFi #CyberSecurity #Vulnerabilities #CVE #InfoSec https://securityonline.info/apache-nifi-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Rob Pomeroy @robpomeroy@infosec.exchange · Aug 03, 2026
A patch-lag leaderboard is less useful than it looks. The vendor that publishes a discovery date is double-reporting; the one that doesn't shows a misleading zero. The metric that matters is disclosure-to-patch for known-exploited bugs. https://vulntrends.org/blog/which-vendors-patch-the-fastest/ #patching #vulnerabilities #msrc #mttp #infosec
0
0
0
Sam Stepanyan :verified: 🐘 @securestep9@infosec.exchange · Jul 31, 2026
#VMware: three critical #vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Patches released by Broadcom - it's time to patch! 👇 https://www.bleepingcomputer.com/news/security/vmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes/
2
0
3
Rob Pomeroy @robpomeroy@infosec.exchange · Jul 28, 2026
The arrival of 622 CVEs in a single Patch Tuesday is the visible signal of something that has been happening for years: discovery is now machine-speed, and a once-a-month batched disclosure is straining to keep up. Read more: https://vulntrends.org/blog/the-evolution-of-patch-tuesday/ #vulnerabilities #PatchTuesday #AISecurity #Microsoft
0
0
0
Dissent Doe :cupofcoffee: @PogoWasRight@infosec.exchange · Jul 27, 2026
NEW by me: It appears that Frontier Airlines may have had a third security incident this year. A new group called ExfilSquad claims to have hacked them -- and no, they say they are not connected to ShinyHunters or ScatteredLapsus$Hunters. NOTE: Frontier Airlines hasn't confirmed this claimed breach. Then again, they haven't denied it, either. They haven't responded to email inquiries. Hackers Breached an Airline as Known Vulnerabilities Went Unpatched. Now Another Gang Claims It Hacked Them, Too. https://databreaches.net/2026/07/27/hackers-breached-an-airline-as-known-vulnerabilities-went-unpatched-now-another-gang-claims-it-hacked-them-too/ @bobdahacker@infosec.exchange @campuscodi@mastodon.social #FrontierAirlines #infosec #cybersecurity #vulnerabilities #databreach
0
1
0
h3artbl33d :openbsd: :antifa: @h3artbl33d@exquisite.social · Jul 21, 2026
Today I received an email from Supermicro that they've released new BMC firmware and a BIOS for some systems I subscribed to. Nothing special. That is, until I noticed what machine was listed. Introduced late 2015/early 2016 :flan_awe: I have never purchased whatever support. Both Supermicro and Dell work this way. HPE does not. They require you to have overzealous support agreements, costing an arm and a leg. No agreement, no BIOS updates for you :flan_nooo: In most cases, companies do prefer these support agreements. Having someone to assist you when shit hits the fan for a (relatively) small stack of dough is a no-brainer. However - this is completely fucked up. It really hurts the second hand market, homelabs, etc. Imagine not being able to patch against nasty silicon-level vulnerabilities because those fuckers want to see 5K of your hard earned cash :flan_molotov: #Rant #Security #Vulnerabilities #Hardware #Servers #HPE #SysOp #Homelab
1
1
0
Rob Pomeroy @robpomeroy@infosec.exchange · Jul 21, 2026
Some people spend their holiday time on the beach. I play with websites, apparently. Don't tell Mrs P. I've enhanced the data gathered for my open source project VulnTrends (v1.1.0), and the picture is even more pronounced than the project originally showed. It's impossible (and irresponsible) to ignore the impact of frontier (or well-harnessed) LLMs on vulnerability discovery. Will there be a growing disparity between discovery and remedation? That remains to be seen. What IS certain is that the severity and quantity of bugs now discovered place immense pressure on patching. The loop (download, test, pilot, release) needs to be tighter than ever. https://vulntrends.org #bugpocalpyse #ai #llm #vulnerabilities
0
0
0
Dr. Jim Ellsworth @EINS_Institute@infosec.exchange · Jul 16, 2026
0
0
0
Marc Ruef :verified: @mruef@infosec.exchange · Jul 15, 2026
Iran abused mobile networks' vulnerabilities to locate U.S. military in the Middle East, report says | TechCrunch #vulnerability #vulnerabilities https://techcrunch.com/2026/07/14/iran-abused-mobile-networks-vulnerabilities-to-locate-u-s-military-in-the-middle-east-report-says/
0
0
0