Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Penligent
penligent.ai > hackinglabs > cve-2025-38236

CVE-2025-38236: Linux AF_UNIX MSG_OOB Use-After-Free and Sandbox Escape Risk

9+ hour, 53+ min ago   (1690+ words) CVE-2025-38236 is a Linux kernel use-after-free in the AF_UNIX stream-socket implementation. A low-privileged process can create a particular sequence of out-of-band sends and receives that leaves the socket’s oob_skb field pointing to an already freed socket buffer. A later receive operation with…...

DEV Community
dev.to > pyhacksecgp > htb-orion-craftcms-rce-a-reverse-shell-that-wouldnt-connect-and-a-telnetd-auth-bypass-4nj2

HTB Orion — CraftCMS RCE, a Reverse Shell That Wouldn't Connect, and a Telnetd Auth Bypass

1+ hour, 35+ min ago   (331+ words) Orion is rated "Very Easy" on Hack The Box, but the path to root turned into a genuinely useful debugging exercise — less about the exploit chain itself and more about what happens when your tooling fights you. This is a…...

CloudSEK
cloudsek.com > knowledge-base > common-vulnerabilities-exposures

What is a CVE? Common Vulnerabilities & Exposures

6+ hour, 35+ min ago   (1488+ words) Common Vulnerabilities and Exposures (CVE) is a public, standardized catalog of known security vulnerabilities, where each flaw receives a unique identifier so that everyone refers to the same issue in the same way. A single CVE is one entry in…...

Google News
cyberkendra.com > 2026 > 07 > public-exploit-lands-for-gitlab-bug.html

Public Exploit Lands for GitLab Bug Patched Without a CVE

8+ hour, 52+ min ago   (164+ words) Follow Cyber Kendra on Google News! | WhatsApp | Telegram Ruby is supposed to be a memory-safe language. That assumption just cost GitLab administrators six weeks of quiet exposure. Any authenticated user who can push to a project can run it. No…...

Cyber Security News
cybersecuritynews.com > gitlab-vulnerabilities-enable-code-execution

GitLab Vulnerabilities Allow Attackers to Execute Remote Code on Default GitLab Installations

9+ hour, 22+ min ago   (591+ words) A newly disclosed exploit chain in GitLab shows how two long-buried memory-safety flaws in a Ruby JSON parsing library, Oj, could be combined to achieve remote code execution on default GitLab installations, exposing source code, Rails secrets, and internal services....

Google News
mallory.ai > vulnerabilities > CVE-2025-68613

Authenticated RCE via Expression Injection in n8n (CVE-2025-68613)

15+ hour, 6+ min ago   (269+ words) Outcomes by security role Intelligence your team can act on. Mallory reasons across your attack surface and the global threat landscape. Before adversaries strike. Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities…...

DEV Community
dev.to > pavelespitia > a-typosquat-package-almost-got-my-keys-dissecting-the-attack-safely-4pbn

A Typosquat Package Almost Got My Keys: Dissecting the Attack Safely

11+ hour, 30+ min ago   (627+ words) I do smart contract security, but the boring truth is most attacks against developers do not touch the chain at all. They touch your machine, your environment variables, and your wallet files. This one wanted all three. The repo was…...

Bitcoinist.com
bitcoinist.com > eigenlayer-elip-018-proposes-irreversible-exit-route-for-restakers > amp

EigenLayer ELIP-018 Proposes Irreversible Exit Route For Restakers

15+ hour, 3+ min ago   (762+ words) EigenLayer’s forum is debating ELIP-018, a draft proposal that introduces a framework called RETIRE, short for Retirement Enabling Terminal, Irreversible Restaking Exit. The name is a mouthful, but the goal is fairly direct: create a terminal exit route for restakers…...

The Hacker News
thehackernews.com > 2026 > 07 > fastjson-1x-rce-vulnerability-targeted.html

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

9+ hour, 46+ min ago   (597+ words) Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process....

Mallory
mallory.ai > vulnerabilities > CVE-2025-27840

Undocumented Bluetooth HCI Debug Commands in Espressif ESP32 (CVE-2025-27840)

1+ day, 4+ hour ago   (272+ words) Outcomes by security role Intelligence your team can act on. Mallory reasons across your attack surface and the global threat landscape. Before adversaries strike. Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities…...