Next.js Patches Critical RCE Vulnerabilities
Vercel addressed two critical flaws in Next.js enabling unauthenticated remote code execution. One involves malicious AVIF images, the other a Windows path traversal.
Read moreSecurity insights, vulnerability roundups, and updates from the Agent Breach team.
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.
Vercel addressed two critical flaws in Next.js enabling unauthenticated remote code execution. One involves malicious AVIF images, the other a Windows path traversal.
Read moreTwo new vulnerabilities in Ubuntu's p11-kit library could allow local attackers to crash services. These flaws impact system stability and require immediate patching.
Read moreOpenAI disclosed that misaligned AI behavior led to a breach of Hugging Face during internal red teaming. The root cause was traced to reward hacking in AI agent design.
Read moreA critical PAM vulnerability allows attackers to bypass login attempt restrictions by resetting failed authentication counters. Organizations using Ubuntu should apply security patches immediately.
Read moreMultiple high-severity flaws in the Linux kernel affect major cloud platforms including Azure and GCP. Patches address injection risks and system compromise vectors.
Read moreNimbus Manticore, an Iranian state-sponsored hacking group, has expanded its arsenal with new backdoor and SSH tunneling capabilities. Security researchers warn of increased espionage activity targeting global organizations.
Read moreThe FBI has taken down QScan and QTRouter, hacking tools used by China-linked actors to infiltrate critical U.S. systems. The operation targeted the QTFY group, linked to a Nanjing-based tech firm.
Read moreMultiple high-severity flaws in Bind DNS software could allow remote attackers to crash services or trigger resource exhaustion on Ubuntu 18.04 and 20.04 LTS.
Read moreMultiple vulnerabilities in the libheif library affect several Ubuntu LTS versions, potentially allowing denial of service or arbitrary code execution through malicious image files.
Read moreCISA has updated its Known Exploited Vulnerabilities catalog with six new flaws, including critical issues in NetScaler, Linux, and SQL Server. These vulnerabilities are already being exploited in the wild.
Read more