{"users":[{"id":1,"username":"mttaggart","name":"Taggart","avatar_template":"/user_avatar/discourse.ifin.network/mttaggart/{size}/7_2.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"admin":true,"moderator":true,"trust_level":4},{"id":8,"username":"BadSamurai","name":"BadSamurai","avatar_template":"/user_avatar/discourse.ifin.network/badsamurai/{size}/53_2.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"trust_level":4},{"id":144,"username":"MustardFacial","name":"","avatar_template":"/user_avatar/discourse.ifin.network/mustardfacial/{size}/979_2.png","trust_level":2},{"id":11,"username":"Soup","name":"Soup","avatar_template":"/letter_avatar_proxy/v4/letter/s/977dab/{size}.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"trust_level":4},{"id":4,"username":"Brumbo","name":"Brumbo","avatar_template":"/user_avatar/discourse.ifin.network/brumbo/{size}/301_2.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"moderator":true,"trust_level":4},{"id":128,"username":"ihatelpes","name":null,"avatar_template":"/letter_avatar_proxy/v4/letter/i/cdc98d/{size}.png","trust_level":1},{"id":77,"username":"sempf","name":"sempf","avatar_template":"/user_avatar/discourse.ifin.network/sempf/{size}/555_2.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"trust_level":3},{"id":9,"username":"chilly","name":"chilly","avatar_template":"/user_avatar/discourse.ifin.network/chilly/{size}/114_2.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"admin":true,"moderator":true,"trust_level":4},{"id":130,"username":"nyanbinary","name":null,"avatar_template":"/user_avatar/discourse.ifin.network/nyanbinary/{size}/867_2.png","trust_level":2},{"id":37,"username":"Shecky","name":null,"avatar_template":"/user_avatar/discourse.ifin.network/shecky/{size}/408_2.png","trust_level":2},{"id":109,"username":"Emily","name":null,"avatar_template":"/user_avatar/discourse.ifin.network/emily/{size}/735_2.png","trust_level":2},{"id":5,"username":"cR0w","name":"cR0w","avatar_template":"/user_avatar/discourse.ifin.network/cr0w/{size}/45_2.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"trust_level":4},{"id":13,"username":"don","name":"don","avatar_template":"/letter_avatar_proxy/v4/letter/d/ed655f/{size}.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"trust_level":4},{"id":158,"username":"darses","name":null,"avatar_template":"/letter_avatar_proxy/v4/letter/d/d07c76/{size}.png","trust_level":2},{"id":10,"username":"rye","name":"Rye","avatar_template":"/user_avatar/discourse.ifin.network/rye/{size}/217_2.png","primary_group_name":"ifin_staff","flair_name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_group_id":41,"trust_level":4},{"id":131,"username":"mejofi","name":"Joni","avatar_template":"/user_avatar/discourse.ifin.network/mejofi/{size}/863_2.png","trust_level":1}],"primary_groups":[{"id":41,"name":"ifin_staff"}],"flair_groups":[{"id":41,"name":"ifin_staff","flair_url":"/uploads/default/original/1X/0e54f6ab381874d2eed3fb24b75b00838dbe073c.png","flair_bg_color":"","flair_color":""}],"topic_list":{"can_create_topic":false,"more_topics_url":"/c/vulnerabilities/15?page=1","per_page":30,"top_tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"},{"id":208,"name":"poc","slug":"poc"},{"id":192,"name":"privesc","slug":"privesc"},{"id":183,"name":"rce","slug":"rce"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":187,"name":"eitw","slug":"eitw"},{"id":229,"name":"lpe","slug":"lpe"},{"id":43,"name":"windows","slug":"windows"},{"id":87,"name":"0day","slug":"0day"},{"id":7,"name":"ai","slug":"ai"},{"id":45,"name":"research","slug":"research"},{"id":210,"name":"nginx","slug":"nginx"},{"id":154,"name":"anthropic","slug":"anthropic"},{"id":220,"name":"auth-bypass","slug":"auth-bypass"},{"id":115,"name":"cisco","slug":"cisco"},{"id":185,"name":"httpd","slug":"httpd"},{"id":47,"name":"microsoft","slug":"microsoft"},{"id":69,"name":"supplychain","slug":"supplychain"},{"id":284,"name":"activestorage","slug":"activestorage"},{"id":184,"name":"apache","slug":"apache"},{"id":283,"name":"arbitrary-file-read","slug":"arbitrary-file-read"},{"id":266,"name":"asp","slug":"asp"},{"id":165,"name":"backdoor","slug":"backdoor"},{"id":236,"name":"bitlocker","slug":"bitlocker"},{"id":237,"name":"bitskrieg","slug":"bitskrieg"},{"id":248,"name":"bootrom","slug":"bootrom"},{"id":247,"name":"buffer-underflow","slug":"buffer-underflow"},{"id":270,"name":"checkpoint","slug":"checkpoint"},{"id":160,"name":"claude","slug":"claude"},{"id":148,"name":"configuration","slug":"configuration"}],"topics":[{"fancy_title":"About the Vulnerabilities category","id":383,"title":"About the Vulnerabilities category","slug":"about-the-vulnerabilities-category","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-05-06T12:12:17.718Z","last_posted_at":"2026-05-06T12:12:17.755Z","bumped":true,"bumped_at":"2026-05-06T12:12:17.718Z","archetype":"regular","unseen":false,"pinned":true,"unpinned":null,"excerpt":"The Vulnerabilities category is intended to hold significant vulnerabilities that do not yet have additional intelligence actions or indicators. Once an exploited vulnerability has such indicators, the topic will be move&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[],"tags_descriptions":{},"views":26,"like_count":1,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-61511 - vBulletin RCE (Your 2000s car forum is in danger!)","id":692,"title":"CVE-2026-61511 - vBulletin RCE (Your 2000s car forum is in danger!)","slug":"cve-2026-61511-vbulletin-rce-your-2000s-car-forum-is-in-danger","posts_count":4,"reply_count":2,"highest_post_number":4,"image_url":null,"created_at":"2026-07-28T18:38:27.678Z","last_posted_at":"2026-08-12T16:12:00.581Z","bumped":true,"bumped_at":"2026-08-12T16:12:00.581Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"CVSSv3: 9.3 / Critical \nAttention car clubs (and other forums) your server may be at risk. I’m looking at you {subaru forum in particular}, AI isn’t going to help me with banjo bolts like that 67-page thread can. \n\nThe v&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":183,"name":"rce","slug":"rce"},{"id":277,"name":"vbulletin","slug":"vbulletin"}],"tags_descriptions":{},"views":37,"like_count":5,"has_summary":false,"last_poster_username":"MustardFacial","category_id":15,"op_like_count":5,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":8,"primary_group_id":41,"flair_group_id":41},{"extras":"latest","description":"Most Recent Poster","user_id":144,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"ShieldBreak: NightmareEclipse Completes the RoguePlanet Exploit","id":740,"title":"ShieldBreak: NightmareEclipse Completes the RoguePlanet Exploit","slug":"shieldbreak-nightmareeclipse-completes-the-rogueplanet-exploit","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/original/2X/a/ae940a5df078aad21603683e4d402115cc0f446b.png","created_at":"2026-08-12T12:46:06.210Z","last_posted_at":"2026-08-12T12:46:06.710Z","bumped":true,"bumped_at":"2026-08-12T12:46:06.710Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-08-12T15:42:00Z (UTC) \nCVSSv3: N/A \nWhat’s Happening\nRight on schedule, our old pal NightmareEclipse has dropped the latest Windows 0-day. \n\n\nThe code is hosted in multiple locations, including GitHub. &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":43,"name":"windows","slug":"windows"},{"id":87,"name":"0day","slug":"0day"},{"id":229,"name":"lpe","slug":"lpe"},{"id":299,"name":"nightmareeclipse","slug":"nightmareeclipse"}],"tags_descriptions":{},"views":6,"like_count":1,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":true,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-63077: Critical Unauth RCE in JetBrains TeamCity via Deserialization of Untrusted Data","id":735,"title":"CVE-2026-63077: Critical Unauth RCE in JetBrains TeamCity via Deserialization of Untrusted Data","slug":"cve-2026-63077-critical-unauth-rce-in-jetbrains-teamcity-via-deserialization-of-untrusted-data","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/5/5da49f41a4c3163aac38bfefd18b44318faad3eb_2_1024x576.jpeg","created_at":"2026-08-10T20:05:44.284Z","last_posted_at":"2026-08-10T20:05:44.888Z","bumped":true,"bumped_at":"2026-08-10T20:05:44.888Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: Monday, August 10, 2026 9:02 PM (UTC) \nWhat’s Happening\nCVSSv3: 9.8 \nOn July 27th, 2026 Jetsbrains released a security advisory for an unauthenticated RCE via Deserializaton of Untrusted Data in their TeamC&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":187,"name":"eitw","slug":"eitw"},{"id":208,"name":"poc","slug":"poc"},{"id":183,"name":"rce","slug":"rce"},{"id":296,"name":"deserialization-of-u","slug":"deserialization-of-u"},{"id":295,"name":"jetbrains","slug":"jetbrains"}],"tags_descriptions":{},"views":9,"like_count":1,"has_summary":false,"last_poster_username":"Soup","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-64638: XSS2Shell Does What It Says; Patch WordPress Now","id":729,"title":"CVE-2026-64638: XSS2Shell Does What It Says; Patch WordPress Now","slug":"cve-2026-64638-xss2shell-does-what-it-says-patch-wordpress-now","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/e/e74c140a58afbfd13b52187bb08c32941ea13d22_2_1024x768.jpeg","created_at":"2026-08-08T13:41:56.066Z","last_posted_at":"2026-08-08T13:41:56.999Z","bumped":true,"bumped_at":"2026-08-08T13:41:56.999Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-08-08T13:24:58Z (UTC) \nCVSSv3: 8.9 \nWhat’s Happening\nPwn.ai has disclosed XSS2Shell, a Same Origin Method Execution (SOME) attack against WordPress before 7.0.3, which has been released with patches&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":183,"name":"rce","slug":"rce"},{"id":138,"name":"wordpress","slug":"wordpress"},{"id":292,"name":"xss","slug":"xss"}],"tags_descriptions":{},"views":24,"like_count":3,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":3,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-66066: KindaRails2Shell: RCE in Rails via Active Storage","id":705,"title":"CVE-2026-66066: KindaRails2Shell: RCE in Rails via Active Storage","slug":"cve-2026-66066-kindarails2shell-rce-in-rails-via-active-storage","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/a/a7afe249090a061ba21d3b5a13abdbafa00efd12_2_1024x537.jpeg","created_at":"2026-08-01T19:56:24.486Z","last_posted_at":"2026-08-01T19:56:25.095Z","bumped":true,"bumped_at":"2026-08-01T19:56:25.095Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-08-01T19:50:50Z (UTC) \nCVSSv3: no cvss yet \nKindaRails2Shell \nInspired by wp2shell, rails apps using ActiveStorage and default vips processor are vulnerable to Arbitrary File Read and Remote Code Execu&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":45,"name":"research","slug":"research"},{"id":183,"name":"rce","slug":"rce"},{"id":207,"name":"ruby","slug":"ruby"},{"id":285,"name":"vips","slug":"vips"},{"id":284,"name":"activestorage","slug":"activestorage"},{"id":283,"name":"arbitrary-file-read","slug":"arbitrary-file-read"},{"id":282,"name":"rails","slug":"rails"}],"tags_descriptions":{},"views":22,"like_count":1,"has_summary":false,"last_poster_username":"Brumbo","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-64600 RefluXFS LPE","id":685,"title":"CVE-2026-64600 RefluXFS LPE","slug":"cve-2026-64600-refluxfs-lpe","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-07-27T12:44:49.131Z","last_posted_at":"2026-07-27T12:44:49.596Z","bumped":true,"bumped_at":"2026-07-27T13:37:54.490Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-07-27T13:38:59Z (UTC) \nCVSS: 3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H \nA bug in the COW handler of XFS on a filsystem means an unprivileged user can abuse this to write on any file they can read on the &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"},{"id":192,"name":"privesc","slug":"privesc"},{"id":229,"name":"lpe","slug":"lpe"}],"tags_descriptions":{},"views":14,"like_count":2,"has_summary":false,"last_poster_username":"ihatelpes","category_id":15,"op_like_count":2,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":128,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"CVE-2026-16232 Authentication Bypass in Check Point Smart Console EITW","id":680,"title":"CVE-2026-16232 Authentication Bypass in Check Point Smart Console EITW","slug":"cve-2026-16232-authentication-bypass-in-check-point-smart-console-eitw","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/8/865069c746fec98bd44ef02f5d9b0244a717f300_2_1024x512.jpeg","created_at":"2026-07-23T20:15:00.797Z","last_posted_at":"2026-07-23T20:15:01.155Z","bumped":true,"bumped_at":"2026-07-23T20:15:01.155Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: July 23, 2026 8:37 PM (UTC) \nWhat’s Happening\nCVSSv3: 9.1 \nCheck Point Security released a security advisory on July 22nd, 2026. Included in their advisory is an Authentication Bypass in Check Point Smart C&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":187,"name":"eitw","slug":"eitw"},{"id":220,"name":"auth-bypass","slug":"auth-bypass"},{"id":120,"name":"kev","slug":"kev"},{"id":271,"name":"smart-console","slug":"smart-console"},{"id":270,"name":"checkpoint","slug":"checkpoint"}],"tags_descriptions":{},"views":16,"like_count":3,"has_summary":false,"last_poster_username":"Soup","category_id":15,"op_like_count":3,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"Remember that Cursor git.exe bug? It&rsquo;s in VSCode too","id":665,"title":"Remember that Cursor git.exe bug? It's in VSCode too","slug":"remember-that-cursor-git-exe-bug-its-in-vscode-too","posts_count":9,"reply_count":4,"highest_post_number":9,"image_url":"https://discourse.ifin.network/uploads/default/original/2X/8/8df46f26ce437e3d125ecfeb7b14552f4636acdc.png","created_at":"2026-07-15T20:16:28.844Z","last_posted_at":"2026-07-16T17:43:03.700Z","bumped":true,"bumped_at":"2026-07-16T17:43:03.700Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"CVSSv3: 7.3 AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H \nCVE: None \nThe Cursor Bug is in VSCode\nEarlier this week, a potential vulnerability was disclosed in Cursor, the AI-enabled development platform that is a fork of VSCode. &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":69,"name":"supplychain","slug":"supplychain"},{"id":47,"name":"microsoft","slug":"microsoft"},{"id":117,"name":"vscode","slug":"vscode"}],"tags_descriptions":{},"views":63,"like_count":7,"has_summary":false,"last_poster_username":"sempf","category_id":15,"op_like_count":3,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":77,"primary_group_id":41,"flair_group_id":41},{"extras":null,"description":"Frequent Poster","user_id":9,"primary_group_id":41,"flair_group_id":41},{"extras":null,"description":"Recent Poster","user_id":130,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"Security Vulnerabilities in Telerik UI lead to RCE","id":649,"title":"Security Vulnerabilities in Telerik UI lead to RCE","slug":"security-vulnerabilities-in-telerik-ui-lead-to-rce","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":null,"created_at":"2026-07-09T01:23:01.856Z","last_posted_at":"2026-07-16T17:20:13.681Z","bumped":true,"bumped_at":"2026-07-16T17:20:13.681Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Telerik is informing licensed users of a series of flaws in Telerik UI for ASPdotNET AJAX that combine to lead to remote code execution in the server hosting the application.  According to the notification, three compone&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":69,"name":"supplychain","slug":"supplychain"},{"id":266,"name":"asp","slug":"asp"},{"id":265,"name":"dotnet","slug":"dotnet"},{"id":264,"name":"telerik","slug":"telerik"}],"tags_descriptions":{},"views":22,"like_count":2,"has_summary":false,"last_poster_username":"sempf","category_id":15,"op_like_count":2,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":77,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-43499: GhostLock, Yet Another Linux LPE/Container Escape","id":653,"title":"CVE-2026-43499: GhostLock, Yet Another Linux LPE/Container Escape","slug":"cve-2026-43499-ghostlock-yet-another-linux-lpe-container-escape","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/d/dd57ef119f74bac4b3f75adc2912402ffc8c56b7_2_1024x576.jpeg","created_at":"2026-07-09T20:49:17.302Z","last_posted_at":"2026-07-09T20:49:18.096Z","bumped":true,"bumped_at":"2026-07-09T20:49:18.096Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-07-09T20:49:44Z (UTC) \nCVSSv3: 7.8 \nWhat’s Happening\nNebula Security has disclosed “GhostLock,” another Linux kernel exploit leading to local privilege escalation and container escape. This one was fou&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"},{"id":229,"name":"lpe","slug":"lpe"}],"tags_descriptions":{},"views":48,"like_count":1,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-11405: Multiple Tenda Routers Have an Admin Backdoor","id":646,"title":"CVE-2026-11405: Multiple Tenda Routers Have an Admin Backdoor","slug":"cve-2026-11405-multiple-tenda-routers-have-an-admin-backdoor","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/4/4ad3ea1ec512998ddb795fd52a88bdb137e56aeb_2_1024x576.webp","created_at":"2026-07-07T18:27:12.736Z","last_posted_at":"2026-07-07T18:27:13.494Z","bumped":true,"bumped_at":"2026-07-08T15:53:05.806Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-07-08T15:51:19Z (UTC) \n  \nCVSSv3: None yet \nMultiple versions of Tenda firmware have a backdoor in remote administration login, allowing anyone to access configuration of the device. \n\n\nAffected Versio&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":165,"name":"backdoor","slug":"backdoor"},{"id":261,"name":"tenda","slug":"tenda"}],"tags_descriptions":{},"views":39,"like_count":1,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"GitLost: Prompt Injection in Github Agentic Workflows","id":647,"title":"GitLost: Prompt Injection in Github Agentic Workflows","slug":"gitlost-prompt-injection-in-github-agentic-workflows","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/original/2X/f/f051ebb6f404a0c393fca6fff610fbae9118c7b2.png","created_at":"2026-07-07T20:45:42.656Z","last_posted_at":"2026-07-07T20:45:43.114Z","bumped":true,"bumped_at":"2026-07-07T20:45:43.114Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-07-07T20:37:35Z (UTC) \nCVSSv3: None yet \nGitLost: \nA Prompt injection in Github’s Agentic Workflows allows unauthenticated attackers to leak information from private repositories of an org via an Issue&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":7,"name":"ai","slug":"ai"},{"id":45,"name":"research","slug":"research"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":33,"name":"github","slug":"github"},{"id":262,"name":"prompt-injection","slug":"prompt-injection"}],"tags_descriptions":{},"views":30,"like_count":1,"has_summary":false,"last_poster_username":"Brumbo","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-53359, &ldquo;Januscape:&rdquo; KVM Escape/Host Panic on x86_64","id":645,"title":"CVE-2026-53359, \"Januscape:\" KVM Escape/Host Panic on x86_64","slug":"cve-2026-53359-januscape-kvm-escape-host-panic-on-x86-64","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/4/409e9d56f797a8a17be9e2229cc9dfb62052079f_2_1024x1024.webp","created_at":"2026-07-07T13:25:45.847Z","last_posted_at":"2026-07-07T13:25:46.316Z","bumped":true,"bumped_at":"2026-07-07T13:25:46.316Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"CVSSv3: None yet \n  \nThe “Januscape” vulnerability has been present in the Linux kernel since 2010. Patches have been released for the upstream kernel in commit 81ccda30b4e8. \n\n\n\nJanuscape is a use-after-free vulnerabili&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"},{"id":242,"name":"kvm","slug":"kvm"}],"tags_descriptions":{},"views":18,"like_count":0,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":0,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"Bad Epoll LPE - Linux Kernel - CVE-2026-46242","id":641,"title":"Bad Epoll LPE - Linux Kernel - CVE-2026-46242","slug":"bad-epoll-lpe-linux-kernel-cve-2026-46242","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-07-03T21:30:56.207Z","last_posted_at":"2026-07-03T21:30:56.688Z","bumped":true,"bumped_at":"2026-07-03T21:30:56.688Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"A new LPE on the Linux Kernel has been released, affecting versions 6.4+ of the kernel. Some distros may be vulnerable if they backport though. \nThere is no mitigation, only patching. There is an existing PoC but for goo&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"},{"id":208,"name":"poc","slug":"poc"},{"id":192,"name":"privesc","slug":"privesc"},{"id":229,"name":"lpe","slug":"lpe"}],"tags_descriptions":{},"views":30,"like_count":3,"has_summary":false,"last_poster_username":"ihatelpes","category_id":15,"op_like_count":3,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":128,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Claude Cowork for Windows Vulnerable to DLL Sideloading, Closed as Won&rsquo;t-Fix","id":640,"title":"Claude Cowork for Windows Vulnerable to DLL Sideloading, Closed as Won't-Fix","slug":"claude-cowork-for-windows-vulnerable-to-dll-sideloading-closed-as-wont-fix","posts_count":3,"reply_count":0,"highest_post_number":3,"image_url":"https://discourse.ifin.network/uploads/default/original/2X/f/f287c9444f3b6ee85dcf441566ccf7ffd89bec79.jpeg","created_at":"2026-07-02T19:15:32.259Z","last_posted_at":"2026-07-02T19:57:31.165Z","bumped":true,"bumped_at":"2026-07-02T19:57:31.165Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"DLL sideloading in Claude Cowork for Windows, closed as not an issue because it requires host compromise. \n  \nIt’s true that DLL sideloading is not strictly Claude’s problem, but at the very least defenders should know t&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":43,"name":"windows","slug":"windows"},{"id":154,"name":"anthropic","slug":"anthropic"},{"id":160,"name":"claude","slug":"claude"}],"tags_descriptions":{},"views":42,"like_count":1,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41},{"extras":null,"description":"Recent Poster","user_id":37,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"FUSE readdir cache - Unprivileged LPE - CVE 2026-31694","id":635,"title":"FUSE readdir cache - Unprivileged LPE - CVE 2026-31694","slug":"fuse-readdir-cache-unprivileged-lpe-cve-2026-31694","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-07-02T12:54:00.720Z","last_posted_at":"2026-07-02T12:54:01.141Z","bumped":true,"bumped_at":"2026-07-02T12:54:01.141Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"An exploit for a vulnerability has been dropped, resulting in a LPE, getting to root from an unprivileged user, as long as fusermount3 is installed. The Vuln exists in FUSE. \nI’ve been able to replicate on Ubuntu 26, but&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"},{"id":208,"name":"poc","slug":"poc"},{"id":192,"name":"privesc","slug":"privesc"},{"id":229,"name":"lpe","slug":"lpe"},{"id":259,"name":"readdir","slug":"readdir"},{"id":258,"name":"fuse","slug":"fuse"}],"tags_descriptions":{},"views":16,"like_count":0,"has_summary":false,"last_poster_username":"ihatelpes","category_id":15,"op_like_count":0,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":128,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Libssh2 vulnerability before 1.11.1 - CVE-2026-55200","id":617,"title":"Libssh2 vulnerability before 1.11.1 - CVE-2026-55200","slug":"libssh2-vulnerability-before-1-11-1-cve-2026-55200","posts_count":5,"reply_count":1,"highest_post_number":5,"image_url":null,"created_at":"2026-06-23T17:38:11.840Z","last_posted_at":"2026-06-30T18:05:34.520Z","bumped":true,"bumped_at":"2026-06-30T18:05:34.520Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"CVSSv3: 8.1 \nCVSSv4: 9.2 \nLooks like this one has patches available, but they may not be pushed out to all distros. \nlibssh2 is used by curl but NOT OpenSSH as far as I can tell. \nIt’s an out-of-bounds write vulnerabilit&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":252,"name":"ssh","slug":"ssh"}],"tags_descriptions":{},"views":52,"like_count":5,"has_summary":false,"last_poster_username":"don","category_id":15,"op_like_count":2,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":109,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Frequent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41},{"extras":null,"description":"Frequent Poster","user_id":77,"primary_group_id":41,"flair_group_id":41},{"extras":null,"description":"Recent Poster","user_id":5,"primary_group_id":41,"flair_group_id":41},{"extras":"latest","description":"Most Recent Poster","user_id":13,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-50656: RoguePlanet, A Race condition in Windows Defender =&gt; LPE","id":568,"title":"CVE-2026-50656: RoguePlanet, A Race condition in Windows Defender => LPE","slug":"cve-2026-50656-rogueplanet-a-race-condition-in-windows-defender-lpe","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":"https://discourse.ifin.network/uploads/default/original/2X/5/5603aa135e6f49081b0b91edbdf27e5afd13f1b4.jpeg","created_at":"2026-06-09T23:52:47.558Z","last_posted_at":"2026-06-29T22:23:25.789Z","bumped":true,"bumped_at":"2026-06-29T22:23:25.789Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-06-17T23:25:13Z (UTC) \nCVSSv3: 7.8 \nAssigned CVE-2026-50656 on 2026-06-17T07:00:00Z (UTC) \nNightmare Eclipse does it again. \nRoguePlanet \nA race condition in Windows Defender resulting in Local Privile&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":43,"name":"windows","slug":"windows"},{"id":208,"name":"poc","slug":"poc"},{"id":192,"name":"privesc","slug":"privesc"},{"id":87,"name":"0day","slug":"0day"},{"id":229,"name":"lpe","slug":"lpe"},{"id":239,"name":"windows-defender","slug":"windows-defender"},{"id":238,"name":"race-condition","slug":"race-condition"}],"tags_descriptions":{},"views":137,"like_count":4,"has_summary":false,"last_poster_username":"Brumbo","category_id":15,"op_like_count":4,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-20253: Critical RCE in Splunk Enterprise EITW","id":624,"title":"CVE-2026-20253: Critical RCE in Splunk Enterprise EITW","slug":"cve-2026-20253-critical-rce-in-splunk-enterprise-eitw","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/a/a12bad98583762dff3ac3b8fb53a2b4d325439c2_2_1024x576.png","created_at":"2026-06-26T17:34:27.138Z","last_posted_at":"2026-06-26T17:34:27.566Z","bumped":true,"bumped_at":"2026-06-26T17:34:27.566Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: June 26, 2026 5:29 PM (UTC) \nWhat’s Happening\nCVSSv3: 9.8 \nSplunk initially published this vulnerability June 10th, 2026. It has been found EITW. A patch is available. It can also be mitigated by disabling &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":187,"name":"eitw","slug":"eitw"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":183,"name":"rce","slug":"rce"},{"id":254,"name":"splunk","slug":"splunk"}],"tags_descriptions":{},"views":22,"like_count":0,"has_summary":false,"last_poster_username":"Soup","category_id":15,"op_like_count":0,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-20230: SSRF Vulnerability in Cisco Unified CM SME, EITW","id":623,"title":"CVE-2026-20230: SSRF Vulnerability in Cisco Unified CM SME, EITW","slug":"cve-2026-20230-ssrf-vulnerability-in-cisco-unified-cm-sme-eitw","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-06-26T16:36:40.521Z","last_posted_at":"2026-06-26T16:36:40.914Z","bumped":true,"bumped_at":"2026-06-26T17:10:24.172Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: June 26, 2026 4:28 PM (UTC) \nWhat’s Happening\nCVSSv3: 8.6 \nInitially published by Cisco on June 3rd, 2026 this vulnerability has been found EITW. A patch is available. It has no workarounds. This vulnerabil&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":187,"name":"eitw","slug":"eitw"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":115,"name":"cisco","slug":"cisco"},{"id":253,"name":"ssrf","slug":"ssrf"}],"tags_descriptions":{},"views":19,"like_count":0,"has_summary":false,"last_poster_username":"Soup","category_id":15,"op_like_count":0,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-20262: Cisco Catalyst SD-WAN EITW","id":589,"title":"CVE-2026-20262: Cisco Catalyst SD-WAN EITW","slug":"cve-2026-20262-cisco-catalyst-sd-wan-eitw","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":null,"created_at":"2026-06-15T18:32:45.982Z","last_posted_at":"2026-06-24T20:33:44.492Z","bumped":true,"bumped_at":"2026-06-24T20:33:44.492Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: June 15, 2026 6:28 PM (UTC) \nWhat’s Happening\nCVSSv3: 6.5 \nCisco has released an advisory for a Medium Severity, Arbitrary File Write Vulnerability in Cisco Catalyst SD-WAN Manager. The vulnerability has a &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":187,"name":"eitw","slug":"eitw"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":115,"name":"cisco","slug":"cisco"}],"tags_descriptions":{},"views":39,"like_count":2,"has_summary":false,"last_poster_username":"darses","category_id":15,"op_like_count":2,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":11,"primary_group_id":41,"flair_group_id":41},{"extras":"latest","description":"Most Recent Poster","user_id":158,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"Usbliter8: A BootROM exploit leveraging a Buffer Underflow and misconfiguration in the A12/13 &amp; S4/5 USB Controller","id":602,"title":"Usbliter8: A BootROM exploit leveraging a Buffer Underflow and misconfiguration in the A12/13 & S4/5 USB Controller","slug":"usbliter8-a-bootrom-exploit-leveraging-a-buffer-underflow-and-misconfiguration-in-the-a12-13-s4-5-usb-controller","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/c/c5c7afa85b0e943d569dcd8650eb19ea56be4b35_2_1024x512.png","created_at":"2026-06-20T03:49:01.568Z","last_posted_at":"2026-06-20T03:49:01.824Z","bumped":true,"bumped_at":"2026-06-20T03:49:01.824Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-06-20T04:02:14Z (UTC) \nSummary \nA hardware flaw in the Synopsys DWC2 USB controller used by the A12/13 &amp; S4/5 chips, as well as a misconfiguration allows for unsigned code execution. \nNotes \n\nSetup pac&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":45,"name":"research","slug":"research"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":208,"name":"poc","slug":"poc"},{"id":148,"name":"configuration","slug":"configuration"},{"id":85,"name":"hardware","slug":"hardware"},{"id":249,"name":"usbliter8","slug":"usbliter8"},{"id":248,"name":"bootrom","slug":"bootrom"},{"id":247,"name":"buffer-underflow","slug":"buffer-underflow"}],"tags_descriptions":{},"views":21,"like_count":0,"has_summary":false,"last_poster_username":"Brumbo","category_id":15,"op_like_count":0,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":4,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"Bitskrieg: Another Bitlocker Bypass Technique","id":550,"title":"Bitskrieg: Another Bitlocker Bypass Technique","slug":"bitskrieg-another-bitlocker-bypass-technique","posts_count":2,"reply_count":0,"highest_post_number":2,"image_url":null,"created_at":"2026-06-06T01:47:12.469Z","last_posted_at":"2026-06-10T18:25:24.573Z","bumped":true,"bumped_at":"2026-06-10T18:25:24.573Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: June 6, 2026 1:44 AM (UTC) \nWhat’s Happening\nOn June 5th, 2026 yet another researcher, @jonasLyk on X, has sidestepped the MSRC disclosure process and released a Bitlocker Bypass Vulnerability, this time du&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":43,"name":"windows","slug":"windows"},{"id":208,"name":"poc","slug":"poc"},{"id":87,"name":"0day","slug":"0day"},{"id":237,"name":"bitskrieg","slug":"bitskrieg"},{"id":236,"name":"bitlocker","slug":"bitlocker"}],"tags_descriptions":{},"views":73,"like_count":4,"has_summary":false,"last_poster_username":"Soup","category_id":15,"op_like_count":4,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"Critical RCE in Gogs GHSA-qf6p-p7ww-cwr9","id":515,"title":"Critical RCE in Gogs GHSA-qf6p-p7ww-cwr9","slug":"critical-rce-in-gogs-ghsa-qf6p-p7ww-cwr9","posts_count":2,"reply_count":0,"highest_post_number":3,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/d/da790454d8a6e96fb4d22c47dd7d72195b13a17b_2_1024x768.jpeg","created_at":"2026-05-29T22:19:24.504Z","last_posted_at":"2026-06-10T18:11:58.328Z","bumped":true,"bumped_at":"2026-06-10T18:11:58.328Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: June 6, 2026 4:19 PM (UTC) \nWhat’s Happening: \nCVSSv4: 9.4 \nGogs, an opensource project for self hosting git has a critical RCE vulnerability that is unpatched. Rapid7 discovered the vulnerability on March &hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":187,"name":"eitw","slug":"eitw"},{"id":65,"name":"vulnerability","slug":"vulnerability"},{"id":208,"name":"poc","slug":"poc"},{"id":183,"name":"rce","slug":"rce"},{"id":228,"name":"gogs","slug":"gogs"}],"tags_descriptions":{},"views":42,"like_count":1,"has_summary":false,"last_poster_username":"Soup","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":11,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-42771 (LiteLLM) exploited in the wild","id":569,"title":"CVE-2026-42771 (LiteLLM) exploited in the wild","slug":"cve-2026-42771-litellm-exploited-in-the-wild","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/d/d786d6eef0547acb9c166ccf1cda929ebac91705_2_1024x591.png","created_at":"2026-06-10T03:42:18.236Z","last_posted_at":"2026-06-10T03:42:18.544Z","bumped":true,"bumped_at":"2026-06-10T05:34:50.500Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-06-10T05:32:42Z (UTC) \nWhat’s Happening\nAn April CVE for command execution in LiteLLM 1.83.6 and earlier versions is being exploited by attackers. \nThe vulnerability has been added to CISA KEVs. \n\n\nHor&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":7,"name":"ai","slug":"ai"},{"id":187,"name":"eitw","slug":"eitw"}],"tags_descriptions":{},"views":31,"like_count":0,"has_summary":false,"last_poster_username":"sempf","category_id":15,"op_like_count":0,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":77,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"Chaotic Eclipse/Nightmare Eclipse drops two Windows 0days (CVE-2026-45585)","id":437,"title":"Chaotic Eclipse/Nightmare Eclipse drops two Windows 0days (CVE-2026-45585)","slug":"chaotic-eclipse-nightmare-eclipse-drops-two-windows-0days-cve-2026-45585","posts_count":6,"reply_count":1,"highest_post_number":6,"image_url":"https://discourse.ifin.network/uploads/default/optimized/1X/a821052e3dff5d250f10a408e4a68fe8268f37fb_2_1024x766.jpeg","created_at":"2026-05-12T20:59:41.096Z","last_posted_at":"2026-06-09T18:39:16.095Z","bumped":true,"bumped_at":"2026-06-09T18:39:16.095Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"Last Updated: 2026-05-12T23:08:34Z (UTC) \nYellowKey Bitlocker Bypass Vulnerability \nBypasses a Bitlocker protected  Windows Computer, spawning an unrestricted shell with access to the protected volume. \nGreenPlasma Windo&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":203,"name":"in-misp","slug":"in-misp"},{"id":43,"name":"windows","slug":"windows"},{"id":87,"name":"0day","slug":"0day"},{"id":206,"name":"yellowkey","slug":"yellowkey"},{"id":205,"name":"greenplasma","slug":"greenplasma"}],"tags_descriptions":{},"views":320,"like_count":5,"has_summary":false,"last_poster_username":"mttaggart","category_id":15,"op_like_count":2,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":null,"description":"Original Poster","user_id":4,"primary_group_id":41,"flair_group_id":41},{"extras":null,"description":"Recent Poster","user_id":10,"primary_group_id":41,"flair_group_id":41},{"extras":"latest","description":"Most Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-23111 Presumed new LPE","id":564,"title":"CVE-2026-23111 Presumed new LPE","slug":"cve-2026-23111-presumed-new-lpe","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-06-09T10:29:59.920Z","last_posted_at":"2026-06-09T10:30:00.273Z","bumped":true,"bumped_at":"2026-06-09T10:30:00.273Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"A vulnerability from February seems to have a working exploit for a LPE, according to researchers that prepared for Pwn2Own Berlin [1]. Affected code is nft/nftables. \nThey give a bash ‘reproducer’ that is only helpful i&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"},{"id":192,"name":"privesc","slug":"privesc"}],"tags_descriptions":{},"views":24,"like_count":1,"has_summary":false,"last_poster_username":"ihatelpes","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":128,"primary_group_id":null,"flair_group_id":null}]},{"fancy_title":"CVE-2026-46290: Yet another Linux Kernel flaw","id":559,"title":"CVE-2026-46290: Yet another Linux Kernel flaw","slug":"cve-2026-46290-yet-another-linux-kernel-flaw","posts_count":1,"reply_count":0,"highest_post_number":1,"image_url":null,"created_at":"2026-06-08T18:48:07.784Z","last_posted_at":"2026-06-08T18:48:08.153Z","bumped":true,"bumped_at":"2026-06-08T18:48:08.153Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"A flaw in the FPU crypto handler leads to memory corruption casing an unrecoverable server hang. \nAs of this writing no CVSS has been established for the vulnerability, and it has been patched in 6.18.29/7.0.6/7.1-rc3. \nN&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":20,"name":"linux","slug":"linux"}],"tags_descriptions":{},"views":30,"like_count":1,"has_summary":false,"last_poster_username":"sempf","category_id":15,"op_like_count":1,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest single","description":"Original Poster, Most Recent Poster","user_id":77,"primary_group_id":41,"flair_group_id":41}]},{"fancy_title":"CVE-2026-9256 for nginx, vulnerability in &lsquo;ngx_http_rewrite_module&rsquo;","id":496,"title":"CVE-2026-9256 for nginx, vulnerability in 'ngx_http_rewrite_module'","slug":"cve-2026-9256-for-nginx-vulnerability-in-ngx-http-rewrite-module","posts_count":5,"reply_count":0,"highest_post_number":5,"image_url":"https://discourse.ifin.network/uploads/default/optimized/2X/f/fbc1f0bf286e5491c73c3ba69bf760807afb0ded_2_1024x576.webp","created_at":"2026-05-22T17:04:28.451Z","last_posted_at":"2026-06-07T21:35:02.565Z","bumped":true,"bumped_at":"2026-06-07T21:35:02.565Z","archetype":"regular","unseen":false,"pinned":false,"unpinned":null,"excerpt":"CVSSv3: 8.1 \n\nNGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatibl&hellip;","visible":true,"closed":false,"archived":false,"bookmarked":null,"liked":null,"tags":[{"id":10,"name":"cve","slug":"cve"},{"id":210,"name":"nginx","slug":"nginx"}],"tags_descriptions":{},"views":59,"like_count":6,"has_summary":false,"last_poster_username":"mejofi","category_id":15,"op_like_count":2,"pinned_globally":false,"featured_link":null,"is_hot":false,"has_accepted_answer":false,"can_vote":false,"posters":[{"extras":"latest","description":"Original Poster, Most Recent Poster","user_id":131,"primary_group_id":null,"flair_group_id":null},{"extras":null,"description":"Recent Poster","user_id":1,"primary_group_id":41,"flair_group_id":41}]}]}}