Recent Advisories

Severity ID Title Vendor Product Date Type
NONE HACKREAD:1B091E...

Alcasec, “Robin Hood of Spanish Hackers,” Jailed for 31 Months Over Data Theft_HACKREAD:1B091E00C3A0107DC2AB5D2619BD0758

Alcasec, the "Robin Hood of Spanish Hackers," is jailed for 31 months after admitting to stealing and selling Spanish citizens' banking data.

N/A N/A HACKREAD
NONE THN:AEE9050720F...

Shrinking the IAM Attack Surface through Identity Visibility and Intelligence Platforms (IVIP)_THN:AEE9050720F4221CAE4212FDF733F7E8

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuT21gubKVL2cAsQrEiju_yAE3Pxe1IPxsl9RlGfhMEeis2IuQglnZjwTme6xM1_IJNymXFY1kZsouMGecR2...

N/A N/A THN
NONE THN:03D274E5DC0...

New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare_THN:03D274E5DC00F0C51BABA09EEB613CF0

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhP07q0cgsa0a9VyTU6oPpxqvoZ5Gg2spx-ClmUIzn9LjYzDfuKNxnLXNuXMexiMB8GjKewhk7CnAL5HXgpCL...

N/A N/A THN
NONE H1:3773293

curl: curl/libcurl 8.20.0 NOPROXY bypass via uppercase-hex IPv4 aliases leaks off-proxy Basic credentials to the configured proxy_H1:3773293

## Summary: curl/libcurl 8.20.0 fails to enforce `CURLOPT_NOPROXY`, `--noproxy`, and `NO_PROXY` consistently for uppercase-hex IPv4 aliases such as...

N/A N/A HACKERONE
NONE A91DA5A9-9F01-

Linux-privesc-PoC_A91DA5A9-9F01-5898-AD64-4416D436FF4E

Linux Privilege Escalation PoC Lab Educational disclaimer: This repository is intended only for authorized security training, CTF practice, and def...

N/A N/A GITHUBEXPLOIT
NONE MALWAREBYTES:85...

These convincing copyright notices are designed to steal Google logins_MALWAREBYTES:85EC87F7CBD6CC83B7BF9E5573AE598C

A new scam is targeting people who publish Chrome extensions. The scam arrives as an official-looking "copyright removal request" claiming your e...

N/A N/A MALWAREBYTES
NONE PACKETSTORM:222526

📄 WebRemoteControl Unauthenticated Remote Filesystem Access_PACKETSTORM:222526

Proof of concept tool that demonstrates how WebRemoteControl suffers from unauthenticated remote filesystem access and potential remote code execut...

N/A N/A PACKETSTORM
NONE PACKETSTORM:222478

📄 Samba Print Command Injection_PACKETSTORM:222478

This Python proof of concept framework analyzes Samba printing configurations for unsafe print command usage involving the %J variable and demonstr...

N/A N/A PACKETSTORM
NONE PACKETSTORM:222452

📄 dcontrol 1.0.9 Screen Capture_PACKETSTORM:222452

The script is a fully featured remote screen-capture client targeting an exposed WebSocket service /ws associated with a dcontrol deployment. It in...

N/A N/A PACKETSTORM
NONE MSSECURE:B9ED78...

Microsoft Build 2026: Securing code, agents, and models across the development lifecycle_MSSECURE:B9ED7816138DDCF9595DC80BC4BD5769

In this article 1. Secure your code 2. Secure your agents 3. Trust agents with your data 4. Secure your models 5. Trust starts with secu...

N/A N/A MSSECURE