Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 5 days ago

MongoBleed

https://github.com/joe-desimone/mongobleed/blob/main/mongobleed.py

#HackerNews #MongoBleed #cybersecurity #vulnerabilities #data #breach #hacking #security

GitHub

mongobleed/mongobleed.py at main · joe-desimone/mongobleed

Contribute to joe-desimone/mongobleed development by creating an account on GitHub.
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 3 weeks ago

Update Now: iOS 26.2 Fixes 20 Security Vulnerabilities, 2 Actively Exploited

https://www.macrumors.com/2025/12/12/ios-26-2-security-vulnerabilities/

#HackerNews #iOS262 #Update #Security #Vulnerabilities #Cybersecurity #Exploits #MacRumors

  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 3 weeks ago

React2Shell and related RSC vulnerabilities threat brief

https://blog.cloudflare.com/react2shell-rsc-vulnerabilities-exploitation-threat-brief/

#HackerNews #React2Shell #RSC #vulnerabilities #threat #brief #Cloudflare #security #React #vulnerabilities #web #security

The Cloudflare Blog

React2Shell and related RSC vulnerabilities threat brief- early exploitation activity and threat actor techniques

Early activity indicates that threat actors quickly integrated this vulnerability into their scanning and reconnaissance routines and targeted critical infrastructure including nuclear fuel, uranium and rare earth elements. We outline the tactics they appear to be using and how Cloudflare is protecting customers.
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 3 weeks ago

Two new RSC protocol vulnerabilities uncovered

https://nextjs.org/blog/security-update-2025-12-11

#HackerNews #RSCprotocol #vulnerabilities #securityupdate #cybersecurity #HackerNews #technews

Next.js Security Update: December 11, 2025

Two additional vulnerabilities have been identified in React Server Components. Users should upgrade to patched versions immediately.
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 4 weeks ago

Critical RCE Vulnerabilities in React and Next.js

https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182

#HackerNews #CriticalRCE #Vulnerabilities #React #Nextjs #Cybersecurity #Vulnerabilities #CVE-2025-55182

  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp last month

GoSign Desktop RCE flaws affecting users in Italy

https://www.ush.it/2025/11/14/multiple-vulnerabilities-gosign-desktop-remote-code-execution/

#HackerNews #GoSignDesktop #RCE #Italy #vulnerabilities #cybersecurity #remoteCodeExecution

ush.it - a beautiful place

  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

Defeating Kaslr by Doing Nothing at All

https://googleprojectzero.blogspot.com/2025/11/defeating-kaslr-by-doing-nothing-at-all.html

#HackerNews #DefeatingKaslr #DoingNothing #Cybersecurity #Vulnerabilities #HackerNews #ProjectZero

Defeating KASLR by Doing Nothing at All

  Posted by Seth Jenkins, Project Zero Introduction I've recently been researching Pixel kernel exploitation and as part of this research I ...
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

https://arstechnica.com/gadgets/2025/10/leaker-reveals-which-pixels-are-vulnerable-to-cellebrite-phone-hacking/

#HackerNews #Leaker #Cellebrite #Vulnerabilities #Pixels #Hacking #News

Ars Technica

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

Cellebrite can apparently extract data from most Pixel phones, unless they’re running GrapheneOS.
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

NPM flooded with malicious packages downloaded more than 86k times

https://arstechnica.com/security/2025/10/npm-flooded-with-malicious-packages-downloaded-more-than-86000-times/

#HackerNews #NPM #malicious #packages #security #vulnerabilities #cyber #threats #software #development

Ars Technica

NPM flooded with malicious packages downloaded more than 86,000 times

Packages downloaded from NPM can fetch dependancies from untrusted sites.
  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

Are these real CVEs? VulDB entries for dnsmasq rely on replacing config files

https://seclists.org/oss-sec/2025/q4/79

#HackerNews #CVE #Vulnerabilities #dnsmasq #VulDB #SecurityIssues #ConfigFiles

oss-sec: Re: Questionable CVE's reported against dnsmasq

  • Copy link
  • Flag this post
  • Block
Hacker News
Hacker News
@h4ckernews@mastodon.social  ·  activity timestamp 2 months ago

Cisco opensourced MCP-Scanner for finding vulnerabilties in MCP server

https://github.com/cisco-ai-defense/mcp-scanner

#HackerNews #Cisco #OpenSource #MCP-Scanner #Vulnerabilities #CyberSecurity #OpenSource #Tools #MCPScanner

  • Copy link
  • Flag this post
  • Block
ProPublica
ProPublica
@ProPublica@newsie.social  ·  activity timestamp 5 months ago

After a ProPublica investigation revealed how Microsoft’s “digital escort” tech support service could expose sensitive government data to cyberattacks, the company says China-based engineers will no longer provide assistance on DOD cloud services.

https://www.propublica.org/article/defense-department-pentagon-microsoft-digital-escort-china?utm_source=mastodon&utm_medium=social&utm_campaign=mastodon-post

#News#Microsoft#Tech #Technology#Defense#Government#DOD#Cybercrime

Arena Cops 🇺🇦✌
Arena Cops 🇺🇦✌
@ArenaCops@infosec.exchange replied  ·  activity timestamp 5 months ago
@ProPublica You really gotta wonder how dumbfucking stupid U.S.-based software corps can be to let Chinese government-dependent hackers & crackers fiddle with U.S. DoD systems — without DoD professionals suspecting & discovering???

Aiding & abetting much?

#Microsoft#DOD#China#Vulnerabilities#Backdoors#Trojans#NationalSecurity#USPol#USPolitics

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.41 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct