Heap-buffer-overflow in EXIF writer for extra IFD tags | Pwno

AI cybersecurity startup finding memory vulnerabilities

FYI: Critical firmware-level vulnerabilities found in Dell laptops (August 2025).

Go update your firmware.

https://www.securityweek.com/flaws-expose-100-dell-laptop-models-to-implants-windows-login-bypass/

#Dell #Latitude #precision #firmward #security #vulnerability #SecurityBug

Flaws Expose 100 Dell Laptop Models to Implants, Windows Login Bypass

ReVault vulnerabilities in the ControlVault3 firmware in Dell laptops could lead to firmware modifications or Windows login bypass.

SecurityWeek

Well, well, well, another day, another data leak. India's income tax portal had a security bug that exposed sensitive taxpayer data. Thankfully, it's fixed now, but it's a stark reminder that 'secure' is a journey, not a destination. How many 'fixes' until we get it right?

https://techcrunch.com/2025/10/07/security-bug-in-indias-income-tax-portal-exposed-taxpayers-sensitive-data/
#Cybersecurity #DataPrivacy #TechNews #Infosec #SecurityBug

Exclusive: Bug in India's income tax portal exposed taxpayers’ sensitive data

TechCrunch verified that the security bug in the Indian Income Tax Department's e-Filing portal exposed taxpayers' data to other users. The security researchers who found the flaw say the data leak is now fixed.

TechCrunch
#WhatsApp fixed a #securitybug in its #iOS and #Mac apps used in a sophisticated #spyware campaign targeting specific users. The attack allowed attackers to steal data from compromised devices. While the exact attacker remains unknown, this incident follows previous #spywareattacks on #WhatsAppusers, including those involving #NSO Group’s #Pegasus spyware. https://techcrunch.com/2025/08/29/whatsapp-fixes-zero-click-bug-used-to-hack-apple-users-with-spyware/?eicker.news #tech #media #news
WhatsApp fixes 'zero-click' bug used to hack Apple users with spyware | TechCrunch

A spyware vendor was behind a recent campaign that abused a vulnerability in WhatsApp to deliver an exploit capable of hacking into iPhones and Macs.

TechCrunch

Two students find #security bug that could let millions do #laundry for free

Two #SantaCruz students uncover #securitybug that could let millions do their laundry for free
#CSCServiceWorks provides laundry machines to thousands of residential homes and universities, but the company ignored requests to fix a security bug.

Who could have seen a free laundry #exploit for internet-connected laundry machines coming?
https://techcrunch.com/2024/05/17/csc-serviceworks-free-laundry-million-machines/
#IoT #IoShit

EXCLUSIVE: Two students uncover security bug that could let millions do their laundry for free

Laundry services giant CSC ServiceWorks belatedly apologized and thanked the security researchers after ignoring a security flaw for months.

TechCrunch

Gaymer.Social has been updated to fix the security issue in v4.3.0-alpha.0 to v4.3.0-alpha.1

(Based on v4.2.5 security fix, thanks to Glitch-Soc for speedy update)

Post about the update

#mastodonupdate #mastodon #security #securitybug #securityfix

Release v4.2.5 · mastodon/mastodon

⚠️ This release is an important security release fixing a critical security issue (CVE-2024-23832). Corresponding security releases are available for the 4.1.x branch, the 4.0.x branch and the 3.5....

GitHub

🪲 Heads up, Bug Hunters 🪲 We’re still searching for vulnerabilities in IDA and the Decompiler. Help us find one, and you might earn a nice cash reward. Read more 🌐 https://hex-rays.com/bugbounty/?utm_source=Social-Media-Post&utm_medium=Mastodon&utm_campaign=bug-bounty-december-2023

#HexRays #BugBounty #IDA #Decompiler #SecurityBug

🔎​🐞​ We are on the lookout for vulnerabilities in IDA and the Decompiler, and if you find one, you might earn a reward. Learn more about our Bug Bounty Program and start hunting today 🌐 https://hex-rays.com/bugbounty/?utm_source=Social-Media-Post&utm_medium=Mastodon&utm_campaign=bug-bounty-june-2023

#HexRays #BugBounty #IDA #Decompiler #SecurityBug

Hex-Rays Security Bug Bounty Program

Hex-Rays Security Bug Bounty Program

It has been a long time since a security bug was reported! Can you find one? We’ve got a reward waiting for you! More info 🌐 https://hex-rays.com/bugbounty/?utm_source=Social-Media-Post&utm_medium=Twitter&utm_campaign=bug-bounty-jan-2023

#HexRays #BugBounty #IDA #Decompiler #SecurityBug

Hex-Rays Security Bug Bounty Program