Zero-day allows code execution in WindChill and FlexPLM

The manufacturer warns and urges admins to urgently secure their instances with a workaround. A patch is still pending.

https://www.heise.de/en/news/Zero-day-allows-code-execution-in-WindChill-and-FlexPLM-11220546.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Exploit #IT #Security #news

Zero-day allows code execution in WindChill and FlexPLM

The manufacturer warns and urges admins to urgently secure their instances with a workaround. A patch is still pending.

heise online
An #election #exploit like a cowgirl roping a fucking bull taking down an #election by winning two states and making #healthcare and the end of #homelessness happen. That's pretty fucking #gangster, call it #outlaw, give it a fucking name. I might just show you how to play the game. Booyah!
VoidStealer malware steals Chrome master key via debugger trick

An information stealer called VoidStealer uses a new approach to bypass Chrome's Application-Bound Encryption (ABE) and extract the master key for decrypting sensitive data stored in the browser.

BleepingComputer

USR just collapsed! 🚨

The stablecoin fell to $0.25 after an $80M unbacked mint exploit. Here’s what we know so far: https://auriccrypto.com/stable/stablecoin-shock-resolvs-usr-loses-peg-after-80m-mint/

#Stablecoin #Crash #Hack #Exploit

Stablecoin Shock: Resolv’s USR Loses Peg After $80M Mint

Resolv’s USR stablecoin experienced a sharp breakdown after an attacker minted around $80 million worth of unbacked tokens. The price quickly fell from its $1

Auric Crypto News

Zero-Day erlaubt Codeausführung in WindChill und FlexPLM

Der Hersteller warnt und bittet Admins, dringend ihre Instanzen mit einer Notlösung abzusichern. Ein Patch steht noch aus.

https://www.heise.de/news/Zero-Day-erlaubt-Codeausfuehrung-in-WindChill-und-FlexPLM-11220521.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon

#Exploit #IT #Security #news

Zero-Day erlaubt Codeausführung in WindChill und FlexPLM

Der Hersteller warnt und bittet Admins, dringend ihre Instanzen mit einer Notlösung abzusichern. Ein Patch steht noch aus.

heise online
LLVM Adventures: Fuzzing Apache Modules

LLVM Adventures: Fuzzing Apache Modules

( ͡◕ _ ͡◕)👌

Cuidado con los teléfonos #Qualcomm antiguos, están sufriendo una vulnerabilidad, otra razón para empezar a usar custom ROM's, obvio si tienen la posibilidad y el conocimiento para hacerlo, así para estar al dia con las actualizaciones de seguridad que son muy importantes

Eso o ir ahorrando para otro teléfono mas actual...

https://thehackernews.com/2026/03/google-confirms-cve-2026-21385-in.html

https://youtu.be/J7O9PZPzsSo

#Android #Exploit #Security

Google Confirms CVE-2026-21385 in Qualcomm Android Component Exploited

Google’s March 2026 Android update patches 129 vulnerabilities, including exploited Qualcomm flaw CVE-2026-21385 and critical RCE CVE-2026-0006.

The Hacker News
wpForo Forum <= 2.4.14 - SQL Injection (CVE-2026-1581)

Unauthenticated attackers can extract sensitive information from the database, leading to data disclosure.

Pentest-Tools.com
Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

Oracle fixes CVE-2026-21992 (CVSS 9.8) flaw enabling unauthenticated RCE via HTTP, risking full system compromise.

The Hacker News
RAXE-2026-040: Claude Code Workspace Trust Dialog Bypass via Repository Settings (CVE-2026-33068) | RAXE Labs

A high-severity configuration loading order defect (`CVE-2026-33068`, CVSS v4.0 7.7 HIGH) in Anthropic's Claude Code CLI tool allows a malicious repository to bypass the workspace trust confirmation dialog.

RAXE