๐Ÿ”ด No Login Needed To Own Your Server

Hackers need zero credentials to hijack your entire server right now.

https://www.youtube.com/shorts/DKcU8AR01Rw

#cybersecurity #zeroday #infosec #hacking #dataprotection #cve #vulnerability #threatintel #security #redteam

No Login Needed To Own Your Server #Shorts

YouTube

fast16: il framework di cybersabotaggio pre-Stuxnet riemerso dai tool segreti NSA dei ShadowBrokers

SentinelLABS ha scoperto fast16, un framework di cybersabotaggio datato 2005 che precede Stuxnet di cinque anni. Il tool altera sottilmente i calcoli floating-point nei software di simulazione come LS-DYNA, target del programma nucleare iraniano, e appare nei leak NSA dei ShadowBrokers come strumento "da non toccare".

https://insicurezzadigitale.com/fast16-il-framework-di-cybersabotaggio-pre-stuxnet-riemerso-dai-tool-segreti-nsa-dei-shadowbrokers/

๐Ÿ”ด New security advisory:

CVE-2026-34275 affects multiple systems.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-34275-oracle-e-biz-unauth-takeover

#InfoSec #ZeroDay #ThreatIntel

Oracle E-Biz unauth takeover (CVE-2026-34275)

CVE-2026-34275: Oracle E-Business Suite 12.2.3-12.2.15 unauthenticated remote takeover (CVSS 9.8). Apply the July 2026 Critical Patch Update immediately.

Yazoul Security
Low Level

180 likes, 17 comments. "we're hacking PDFs again?"

YouTube

๐Ÿ”ด New security advisory:

CVE-2026-6771 affects multiple systems.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-6771-firefox-mitigation-bypass-unauthenticated

#InfoSec #ZeroDay #ThreatIntel

Firefox mitigation bypass, unauthenticated (CVE-2026-6771)

CVE-2026-6771: Firefox and Thunderbird DOM mitigation bypass allows remote code execution without user interaction (CVSS 9.8). Update to Firefox 150 or ESR 140.10.

Yazoul Security

Lukasz Olejnik (@lukOlejnik)

์ค‘๊ตญ๊ณ„ AI๊ฐ€ ์†Œํ”„ํŠธ์›จ์–ด ์ทจ์•ฝ์ ์„ ์•ˆ์ •์ ์œผ๋กœ ํƒ์ง€ํ•˜๋ฉฐ ๋น„์šฉ ํšจ์œจ์ ์ด๋ผ๋Š” ์—ฐ๊ตฌ ๊ฒฐ๊ณผ๊ฐ€ ์†Œ๊ฐœ๋๋‹ค. ์˜คํ”ˆ์›จ์ดํŠธ ๋ชจ๋ธ Kimi K2.5๋ฅผ Chrome ๋Œ€์ƒ ์—์ด์ „ํ‹ฑ ํ”„๋ ˆ์ž„์›Œํฌ์— ์ ์šฉํ•ด ์ด์ „์— ์•Œ๋ ค์ง€์ง€ ์•Š์€ ์ œ๋กœ๋ฐ์ด 10๊ฑด์„ ์ฐพ์•„๋ƒˆ๊ณ , ์ด ์ค‘ 2๊ฑด์€ ์น˜๋ช…์ ์ธ ์ƒŒ๋“œ๋ฐ•์Šค ํƒˆ์ถœ CVE์˜€๋‹ค.

https://x.com/lukOlejnik/status/2047324127338303942

#cybersecurity #opensource #agenticai #llm #zeroday

Lukasz Olejnik (@lukOlejnik) on X

Research shows that Chinese AI can reliably detect software vulnerabilities - and it is cost efficient. Kimi K2.5, an open-weight model was deployed in an agentic framework against Chrome and produced 10 previously unknown zero-days, including two critical sandbox-escape CVEs.

X (formerly Twitter)

CISA just ordered federal agencies to patch a Microsoft Defender flaw actively exploited as a zero-day. The patch exists. The exploitation is real. The window between "known vulnerability" and "patched system" is exactly where attackers live.

Every day that gap stays open is a day too many. ๐Ÿ”

#infosec #CVE #zeroday
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-microsoft-defender-flaw-exploited-in-zero-day-attacks/

CISA orders feds to patch BlueHammer flaw exploited as zero-day

CISA has ordered U.S. federal agencies to patch a Microsoft Defender privilege escalation flaw (dubbed BlueHammer) that has been exploited in zero-day attacks.

BleepingComputer

๐ŸŸก THREAT INTELLIGENCE

Apple Fixes iOS Flaw That Let FBI Recover Deleted Signal Messages

Vulnerability | MEDIUM

Apple has released out-of-band security updates for iPhone and iPad devices to fix a Notification Services flaw that could allow notifications marked...

Full analysis:
https://www.yazoul.net/news/article/apple-fixes-ios-flaw-that-let-fbi-recover-deleted-signal-messages

#InfoSec #ZeroDay #ThreatHunting

iOS Bug Let FBI Recover Deleted Signal Messages

Apple has released out-of-band security updates for iPhone and iPad devices to fix a Notification Services flaw that could allow notifications marked for deletion to remain stored on the device. [...]

Yazoul Security

๐Ÿ”ด New security advisory:

CVE-2026-41679 affects multiple systems.

โ€ข Impact: Remote code execution or complete system compromise possible
โ€ข Risk: Attackers can gain full control of affected systems
โ€ข Mitigation: Patch immediately or isolate affected systems

Full breakdown:
https://www.yazoul.net/advisory/cve/cve-2026-41679-paperclip-unauthenticated-remote-code-execution

#InfoSec #ZeroDay #ThreatIntel

Paperclip unauthenticated remote code execution (CVE-2026-41679)

CVE-2026-41679: Unauthenticated attackers can achieve full remote code execution on Paperclip AI agent servers in authenticated mode (CVSS 10.0). Patch immediately to version 2026.416.0.

Yazoul Security

Anthropic's Mythos Model Exposes Limited Capabilities

Anthropic's highly anticipated Mythos model, designed to proactively identify vulnerabilities, has been compromised - with a small group of individuals reportedly gaining unauthorized access to the preview through a third-party vendor environment. The incident has raised concerns about the model's limited capabilities to protect itself fromโ€ฆ

https://osintsights.com/anthropics-mythos-model-exposes-limited-capabilities?utm_source=mastodon&utm_medium=social

#ZeroDay #Anthropic #MythosModel #ProjectGlasswing #ThirdpartyVendor

Anthropic's Mythos Model Exposes Limited Capabilities

Discover Anthropic's Mythos model's limited capabilities and security concerns, learn more about Project Glasswing and take action now to protect your organization from potential vulnerabilities today.

OSINTSights