πŸ”΄ New security advisory:

CVE-2026-32975 affects multiple systems.

β€’ Impact: Remote code execution or complete system compromise possible
β€’ Risk: Attackers can gain full control of affected systems
β€’ Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-32975-openclaw-authorization-bypass-update-immediately

#InfoSec #ZeroDay #ThreatIntel

Critical: OpenClaw Authorization Bypass (CVE-2026-32975) - Update Immediately | Yazoul Security

Critical OpenClaw vulnerability (CVSS 9.8) allows attackers to bypass channel authorization by creating groups with duplicate names, routing unauthorized messages. Update to 2026.3.12.

Yazoul Security

🟑 THREAT INTELLIGENCE

Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels

Vulnerability | MEDIUM

Microsoft has pulled a buggy Windows 11 non-security preview update to investigate a known issue that triggers 0x80073712 errors during installation...

Full analysis:
https://www.yazoul.net/news/news/russian-ctrl-toolkit-delivered-via-malicious-lnk-files-hijacks-rdp-via-frp-tunne

#InfoSec #ZeroDay #ThreatHunting

Russian CTRL Toolkit Hijacks RDP via Malicious LNK Files

Microsoft has pulled a buggy Windows 11 non-security preview update to investigate a known issue that triggers 0x80073712 errors during installation. [...]

Yazoul Security

🟑 THREAT INTELLIGENCE

Russian CTRL Toolkit Delivered via Malicious LNK Files Hijacks RDP via FRP Tunnels

Vulnerability | MEDIUM

Microsoft has pulled a buggy Windows 11 non-security preview update to investigate a known issue that triggers 0x80073712 errors during installation...

Full analysis:
https://www.yazoul.net/news/news/russian-ctrl-toolkit-delivered-via-malicious-lnk-files-hijacks-rdp-via-frp-tunne

#InfoSec #ZeroDay #ThreatHunting

Russian CTRL Toolkit Hijacks RDP via Malicious LNK Files

Microsoft has pulled a buggy Windows 11 non-security preview update to investigate a known issue that triggers 0x80073712 errors during installation. [...]

Yazoul Security

πŸ”΄ New security advisory:

CVE-2026-32922 affects multiple systems.

β€’ Impact: Remote code execution or complete system compromise possible
β€’ Risk: Attackers can gain full control of affected systems
β€’ Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-32922-openclaw-privilege-escalation

#InfoSec #ZeroDay #ThreatIntel

Critical: OpenClaw Privilege Escalation (CVE-2026-32922) - Critical Update Required | Yazoul Security

Critical OpenClaw privilege escalation flaw allows attackers to gain admin access and remote code execution. CVSS 9.9. Update to version 2026.3.11 immediately to mitigate.

Yazoul Security

🚨 New security advisory:

CVE-2026-33976 affects multiple systems.

β€’ Impact: Remote code execution or complete system compromise possible
β€’ Risk: Attackers can gain full control of affected systems
β€’ Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-33976-notesnook-remote-code-execution-vulnerability-patch

#InfoSec #ZeroDay #ThreatIntel

Critical: Notesnook Remote Code Execution Vulnerability (CVE-2026-33976) - Patch Immediately | Yazoul Security

Critical stored XSS flaw in Notesnook prior to v3.3.11/3.3.17 can be escalated to remote code execution on desktop. CVSS 9.6. Update immediately to prevent compromise.

Yazoul Security

🚨 New security advisory:

CVE-2016-20049 affects multiple systems.

β€’ Impact: Remote code execution or complete system compromise possible
β€’ Risk: Attackers can gain full control of affected systems
β€’ Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2016-20049-jad-buffer-overflow-vulnerability

#InfoSec #ZeroDay #ThreatIntel

Critical: JAD Buffer Overflow Vulnerability (CVE-2016-20049) - Critical Update Required | Yazoul Security

Critical stack-based buffer overflow in JAD up to v1.5.8e allows arbitrary code execution via crafted input. CVSS 9.8. Immediate patching or mitigation is essential.

Yazoul Security

🚨 New security advisory:

CVE-2016-20049 affects multiple systems.

β€’ Impact: Remote code execution or complete system compromise possible
β€’ Risk: Attackers can gain full control of affected systems
β€’ Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2016-20049-jad-buffer-overflow-vulnerability

#InfoSec #ZeroDay #ThreatIntel

Critical: JAD Buffer Overflow Vulnerability (CVE-2016-20049) - Critical Update Required | Yazoul Security

Critical stack-based buffer overflow in JAD up to v1.5.8e allows arbitrary code execution via crafted input. CVSS 9.8. Immediate patching or mitigation is essential.

Yazoul Security

Listen very carefully on this ...

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

https://www.youtube.com/watch?v=1sd26pWhfmg

#cybersecurity #aisecurity #zeroday

Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

YouTube

β›” New security advisory:

CVE-2026-30533 affects multiple systems.

β€’ Impact: Remote code execution or complete system compromise possible
β€’ Risk: Attackers can gain full control of affected systems
β€’ Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-30533-sourcecodester-food-ordering-system-sql-injection

#InfoSec #ZeroDay #ThreatIntel

Critical: SourceCodester Food Ordering System SQL Injection (CVE-2026-30533) - Critical Update | Yazoul Security

Critical SQL Injection vulnerability in SourceCodester Online Food Ordering System v1.0 allows attackers to compromise admin panels and databases. CVSS 9.8. Apply patches immediately.

Yazoul Security

β›” New security advisory:

CVE-2026-30532 affects multiple systems.

β€’ Impact: Remote code execution or complete system compromise possible
β€’ Risk: Attackers can gain full control of affected systems
β€’ Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-30532-sourcecodester-food-ordering-system-sql-injection

#InfoSec #ZeroDay #ThreatIntel

Critical: SourceCodester Food Ordering System SQL Injection (CVE-2026-30532) - Critical Update | Yazoul Security

Critical SQL Injection vulnerability in SourceCodester Online Food Ordering System v1.0 allows admin panel compromise. CVSS 9.8. Apply patch or mitigation immediately.

Yazoul Security