The Lab · 2026-05-09 04:01:40 · Mastodon:mastodon.social:#infosec
Security researchers have disclosed a newly identified Linux kernel vulnerability dubbed "Dirty Frag," which allows any local user on an affected system to escalate privileges to root. The flaw, classified as a zero-day, affects most major Linux distributions and has raised significant concern within the information se...
The Lab · 2026-05-09 14:31:44 · Mastodon:mastodon.social:#infosec
A critical vulnerability has been identified in electerm, an open-source terminal and remote access client supporting SSH, SFTP, telnet, serialport, RDP, VNC, Spice, and FTP protocols. Tracked as CVE-2026-2026-43944 with a CVSS score of 9.6, the flaw affects versions 3.0.6 through 3.8.14, leaving a significant number o...
The Lab · 2026-05-09 18:31:47 · Mastodon:mastodon.social:#infosec
A supply chain compromise targeting the official CPUID website (cpuid.com) has been identified, affecting downloads of multiple popular hardware monitoring tools. The incident, reported to have occurred on April 9-10, 2026, represents a significant breach of a trusted software distribution channel used by millions of u...
The Lab · 2026-05-10 18:31:52 · r/bugbounty
A bug bounty researcher has reignited debate over the viability of subdomain takeover as a vulnerability class after reporting a shockingly low discovery rate: just 4 takeoverable domains across 600,000 scanned assets. The researcher spent a week building a tool to scrape eligible subdomains for every program, then ran...
The Lab · 2026-05-10 22:01:42 · Mastodon:mastodon.social:#infosec
JDownloader's official website was compromised through a CMS vulnerability, allowing threat actors to replace legitimate Windows and Linux installers with malware-laden versions. The attack window spans May 6–7, 2026, during which users who downloaded the Windows Alternative Installer or Linux shell script and executed...
The Lab · 2026-05-11 17:38:23 · Mastodon:mastodon.social:#infosec
A security researcher and Flying Penguin blog have raised questions about the four-hour interval between the onset of an attack on Canonical's infrastructure and the appearance of Cloudflare IP addresses on Canonical's repository hostnames. The analysis suggests this gap may represent the time required for Canonical to...
The Lab · 2026-05-12 12:48:35 · Mastodon:hachyderm.io:#infosec
A specific malware signature linked to WordPress compromise campaigns has surfaced, revealing a potentially large-scale attack operation with a notable technical flaw. Security researchers are pointing to the hash identifier "Bwn6fOzW0Zc6VfNNCAo1bWRmG2a" as a hunting marker for malicious payloads targeting WordPress in...
The Lab · 2026-05-12 17:18:25 · Mastodon:mastodon.social:#infosec
A critical deserialization vulnerability has been identified in YetAnotherForum.NET (YAF.NET), a widely deployed C# ASP.NET forum platform. Tracked as CVE-2026-43938 with a CVSS score of 8.1 (High), the flaw resides in the application's database logger component located at YAFNET.Core/Logger/DbLogger.cs. The vulnerabil...
The Lab · 2026-05-13 09:18:29 · Mastodon:mastodon.social:#infosec
Une vulnérabilité critique touche gRPC-Go. Selon les données disponibles, l'absence d'un slash dans l'en-tête `:path` HTTP/2 permettrait de contourner l'ensemble des mécanismes d'autorisation du framework. La faille, baptisée CVE-2026-33186, affiche un CVSS de 9.1, traduisant une gravité élevée dans l'évaluation offici...