An 18-year-old flaw in the NGINX rewrite module is still exposing systems today - legacy code never really disappears, it just waits to be rediscovered. πŸ•°οΈβš οΈ #WebSecurity #LegacyRisk

https://thehackernews.com/2026/05/18-year-old-nginx-rewrite-module-flaw.html

18-Year-Old NGINX Rewrite Module Flaw Enables Unauthenticated RCE

NGINX Rift CVE-2026-42945 scores 9.2 after 18 years, enabling unauthenticated RCE or DoS via crafted HTTP requests.

The Hacker News
Joseph Meuse Past Misconduct Fuels Present Risks
πŸ” Despite his ban ending in 2019, Meuse’s return to shell sales raises fresh red flags.
πŸ”— https://cybercriminal.com/threats/joseph‑meuse
#JosephMeuse #LegacyRisk #FinancialWatch #RegulatoryMonitoring #ScamAlert
RT to share βš–οΈ

πŸ“¬ Russian hackers bypass Gmail MFA using stolen app passwordsβ€”exploiting legacy settings to sidestep modern protections. A wake-up call to audit and disable unused access points.
#MFABypassAlert πŸ›‘ #LegacyRisk πŸ”

https://www.bleepingcomputer.com/news/security/russian-hackers-bypass-gmail-mfa-using-stolen-app-passwords/

Russian hackers bypass Gmail MFA using stolen app passwords

Russian hackers bypass multi-factor authentication and access Gmail accounts by leveraging app-specific passwords in advanced social engineering attacks that impersonate U.S. Department of State officials.

BleepingComputer