π¨ CRITICAL: CVE-2025-67446 (CVSS 9.8)
Neterbit NW-431F Router β€20241014-IR03 has authentication bypass via predictable cookie manipulation. Attackers can gain full admin access remotely.
Patch immediately if affected.
#CVE#PatchNow#ThreatIntel
π¨ HIGH SEVERITY: CVE-2026-50213 (CVSS 7.5)
User validation endpoint exposes full profile data via predictable ID enumeration. Network-accessible, no auth required.
Patch immediately or disable /v1/User/validate.
#CVE#Vulnerability#PatchNow#ThreatIntel
Insertion of Sensitive Information Into Sent Data vulnerability in Argus Technology Inc. BILGER allows Choosing Message Identifier.
This issue affects BILGER: before 2.4.9.
A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component Administrative Backend. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit is publicly available and might be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The project was informed of the problem early through an issue report but has not responded yet.
DrΓ€ger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM privileges.
Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie.
PCAP files are the gold standard of network forensics β full packet captures that preserve complete network conversations, including payloads.
Unlike flow records or connection logs, PCAPs capture everything: every byte transmitted, every protocol exchange, every payload. This makes them invaluable for deep-dive investigations into data exfiltration (T1041), command-and-control traffic (T1071), and lateral movement.
Capture methods include tcpdump on Linux/Unix systems, Wireshark for targeted collection, or enterprise-grade network taps and SPAN port configurations. Analysis tools range from Wireshark and tshark for manual inspection to NetworkMiner for automated artifact extraction and Zeek for converting PCAPs into structured logs.
PCAPs enable file carving from network streams, credential harvesting from cleartext protocols (FTP, HTTP Basic Auth, Telnet), malware payload extraction, and full reconstruction of attacker C2 sessions. You can literally replay what happened on the wire.
The tradeoff: storage. A 1 Gbps link generates approximately 450 GB of uncompressed PCAP data per hour. Plan your retention strategy accordingly β many orgs capture selectively at chokepoints or use triggered capture during incidents.
When logs fail you, PCAPs tell the truth.
#DFIR #NetworkForensics
π¨ HIGH SEVERITY: CVE-2025-14101 (CVSS 7.1)
Authorization bypass in PaperWork by GG Soft (v5.2.0.9427 - <6.0). Attackers can exploit trusted identifiers for unauthorized access.
Update to v6.0+ immediately.
#CVE#PatchNow#ThreatIntel
π¨ HIGH SEVERITY: CVE-2026-10796 (CVSS 7.5)
nvm β€0.40.4 executes arbitrary commands from malicious mirror version strings. Attackers controlling mirrors or MitM attacks can achieve RCE.
Mitigation: Use default HTTPS mirror, update to patched version
#CVE#Vulnerability
π¨ HIGH Severity: CVE-2025-69755 (CVSS 8.2)
Neterbit NW-431F Router vulnerable to remote code execution & info disclosure via at_command[.]asp. No authentication required.
Patch immediately if affected.
#CVE#Vulnerability#PatchNow
π¨ HIGH SEVERITY: CVE-2025-13506 (CVSS 8.8)
Nebim V3 ERP privilege escalation flaw allows attackers to expand control from database to OS. Affects versions 2.0.59 to <3.0.1.
Update to v3.0.1+ immediately.
#CVE#PatchNow#ThreatIntel