Reproducing a Double Free RCE in Apache CVE-2026-23918 on the most used software on the internet with one prompt that costs like $0.001 via DeepSeek is scary as hell.
Now, anyone with zero knowledge can hack the internet.
(Not default installs though. You need mod_http2 enabled.)
❗️🚨 Microsoft Edge keeps every saved password in process memory as cleartext from the moment it launches. Microsoft's responsed when reported: "by design."
All of them. Including credentials for sites you won't open this session.
Researcher @L1v1ng0ffTh3L4N tested every major Chromium browser. Edge is the only one that behaves this way.
Chrome decrypts credentials on demand, and App-Bound Encryption locks the keys to an authenticated Chrome process so other processes can't reuse them.
In Chrome, plaintext surfaces only during autofill or when a password is viewed, making memory scraping far less useful.
What makes this extra weird is that Edge still demands re-authentication before revealing those passwords in its Password Manager UI, while the same browser process already holds every one of them in plaintext.
In shared environments, this turns into a credential harvest. On a terminal server, an attacker with admin rights can read the memory of every logged-on user process. In the published PoC video, a compromised admin account lifts stored credentials from two other logged-on (and even disconnected) users with Edge running.
Microsoft's official response when notified: "by design."
The finding was disclosed April 29 at BigBiteOfTech by PaloAltoNtwks Norway, alongside a small educational tool that lets anyone verify the cleartext storage for themselves.
@Justin_Gaethje
3 eye pokes and paddy doesn’t complain, 1 gut shot and you say it’s a nut shot.
What a pathetic fighter you are, should have been paddy’s win.
#justingaethje#UFC324
Latest late night project, a realtime updating Tor relay tracker with historical data.
I was gambling with the idea of collecting tor bridge servers but scrapped that due to ethical considerations.
https://t.co/AnrpDjmcNn
#data#tor#archives
If your using #spacedesk by datronicsoft on a public network please lock it otherwise your leaving your device free to anyone with the app.
For example this cs student leaving their laptop unattended with spacedesk open, on a student accommodation network!
#CyberSecurity #CyberAwareness