‼️ Hardcoded root credentials in @Worksnaps (CVE‑2025‑10560) enabling to take over the AWS Infrastructure and gain access to all customer data. Patch available (v1.6.20260201+) and should be installed immediately.
👉 https://t.co/1RrllFTngb
#CloudSecurity#Vulnerability
Local #PrivilegeEscalation in Quanos SCHEMA ST4.
Vulnerabilities in the update service allow low-privileged users to execute code or overwrite files.
➡️ On‑premise versions affected
➡️ Workaround available – disable update service
➡️ SaaS not affected
👉 https://t.co/LSK6tin7KS
Broken access control in Secure Login (2FA) for Confluence (CVE‑2026‑12225)! Attackers with valid credentials could bypass MFA in @SyracomApps Secure Login for #Jira, #Confluence & #Bitbucket.➡️ Patch available - update immediately. 👉https://t.co/dyNzIvLTjY
#Vulnerability#MFA
Critical #vulnerabilities in WERTHEIM SafeController (hard- & software): 10+ issues enabling potential unauthorized access. Vendor provides patches, but unresponsive lately, we advise contacting them for guidance.👉SW: https://t.co/SZ6dzyc36k;
👉 HW: https://t.co/PtNCUH1jz5
🚨 New advisory out on @SlateDigital Connect (macOS). We found LPE flaws due to insufficient validation in privileged components, enabling elevated access. Systems may be at risk.
❗ No patch available – contact vendor.
Full read👉 https://t.co/BAzKdIWXEr
#CyberSecurity#macOS
🚨 New advisory: @WavesAudioLtd Waves Central (CVE-2026-24064, CVE-2026-24065). Our experts found LPE #vulnerabilities via XPC misconfig & DYLIB injection, enabling access to privileged components. Systems may be compromised - patch ASAP‼️
👉 https://t.co/CFJ4SEsaG3
#AppSec
🚨 New advisory by @Kruxinator & Christian Hager: Local privilege escalation in @genetec 's #RabbitMQ deployment (#CVE-2026-25112)
Writable dir + missing binary + SeImpersonatePrivilege = SYSTEM via Rotten Potato 🥔
Patch available. Apply now!
🔗 https://t.co/B5vRETRqIq
#privesc
May the 4th be with you - and your security strong.
Because in cybersecurity, there’s no room for the Dark Side. At SEC Consult, we help you stay one step ahead of the threats in this galaxy and beyond.
#MayTheFourth#Cybersecurity#Cyberthreats
❗️ New advisory: vulnerability in @desktime app (CVE‑2025‑10539). Missing TLS cert validation lets attackers inject a malicious update and gain user‑level code execution. If you use DeskTime, urge the vendor to fix. https://t.co/8PjQrNj2Zi
#AppSec#VulnerabilityResearch#Infosec
❗️ New high‑impact advisory: EfficientLab @ControlioNet (CVE‑2025‑10549). DLL hijacking allows local privilege escalation to NT AUTHORITY\SYSTEM via Controlio service. Patch v 1.3.95 immediately.
https://t.co/uSchmLhRX7
#AppSec#PatchNow
Ethical hacking is more than finding bugs - it comes with responsibility. Our latest research analyzes ethical challenges in #IoT security using a consumer pet‑tracking ecosystem.
Responsible research matters.
Read more: https://t.co/FV9oIoJpXx
#EthicalHacking#SecurityResearch
‼️ New advisory: Broken Access Control in @LiteLLM config endpoint (CVE-2026-35029).
A missing auth check lets low‑privileged users access sensitive host data via /config/update. Patch available - apply immediately.
Full advisory 👉https://t.co/XhuaWGtKPM
#LLMSecurity#SecureAI
🚨 High‑impact: @SAP HANA Cockpit (CVE‑2026‑34262) Users with Database Explorer access could extract X.509 private keys - enabling server impersonation.⚠️SAP’s patch is not sufficient - certificates must be manually revoked & rotated.
👉 https://t.co/zINcWLowMZ
#SAPSecurity#mTLS
🚨 New Advisory: @Kiuwan SAST (CVE‑2026‑24069)
Disabled local accounts could still log in via SSO due to improper account lock enforcement (on‑prem & SaaS). Patch available – apply immediately.
👉 https://t.co/52dgPca0of
#CyberSecurity#Vulnerability#CVE#AppSec#SAST#SSO
‼️ New advisory from our Vulnerability Lab on @OpenWebUI: An auth flaw allowed low‑privileged users to access sensitive tool data incl. API keys (CVE‑2026‑34222). Patch immediately & conduct a security review.
👉 https://t.co/QMnQtSJjhd
#CyberSecurity#LLMSecurity#OpenWebUI#CV
High-risk privilege escalation in the Vienna Symphonic library - Vienna Assistant for macOS (CVE‑2026‑24068). No vendor response → no patch available. Contact the vendor and request a fix.
🔎 https://t.co/x3f7oFyVT3
#NoPatchAvailable#PrivilegeEscalation#VulnerabilityResearch
Multiple privilege escalation flaws in the @ArturiaOfficial Software Center for macOS. The vendor did not respond, so no patch is available.
🔐 Users are urged to contact Arturia and request a fix.
👉 https://t.co/wMqXS3H3Op
#CyberSecurity#InfoSec#VulnerabilityDisclosure
⚠️ New advisory: Multiple vulnerabilities in CryptoPro Secure Disk for BitLocker. Impact: Bypass of pre-boot integrity checks and execution of code as root – enabling backdoors and unauthorized data access. Patch available!
👉 https://t.co/pZINsxDZvV
#cybersecurity#infosec