@ernst_klaus Sie sollten weniger RT konsumieren. Putin versucht seit über vier Jahren die Unterstützung der Ukraine in Europa zu brechen und droht alle paar Wochen entweder mit Atomschlägen oder das die NATO mit Russland im Krieg sei. Der einzige der seit Jahren eskaliert ist Putin.
🛑 A new #Linux kernel flaw lets a local user rewrite /usr/bin/su in memory and gain #root.
The file on disk never changes. No audit trail.
DirtyClone (CVE-2026-43503) is the fourth bug with this failure mode in two months.
Details and what to do ↓ https://t.co/nYsNZKu7Mk
🛑 A new #Linux kernel exploit (CVE-2026-46331) gets root without modifying a single file on disk.
It poisons the cached copy of /bin/su in memory. The binary on disk stays untouched. File-integrity checks come back clean.
The root shell is already open.
Details here ↓ https://t.co/y2FDVjcSEq
🚨 ALERT - A critical Splunk Enterprise flaw can go from “no login required” to remote code execution.
Tracked as CVE-2026-20253, the bug carries a 9.8 CVSS score and affects vulnerable Splunk Enterprise servers through exposed PostgreSQL sidecar endpoints.
The exploit chain is now public.
Read the full story: https://t.co/arMFjVVt10
⚠️ Security release pre-alert: The Node.js project will release new versions of the 26.x, 24.x, 22.x
releases lines on or shortly after, Wednesday, June 17, 2026 in order to address one or more security issues, the highest severity is HIGH.
Details: https://t.co/lsjkOtkuxG
ssh-keysign-pwn is the fourth local-root Linux kernel disclosure in roughly two weeks. (But who's counting?)
AlmaLinux 9 and 10 are both vulnerable. AlmaLinux 8 is not exploitable with the current public PoCs, but is getting the patch as well.
Patched kernel versions are available for testing now: https://t.co/O98TDOZ4JN
⚡ An 18-year-old flaw in NGINX can let unauthenticated attackers run code or crash servers using crafted HTTP requests.
Tracked as CVE-2026-42945 and named NGINX Rift, the bug affects NGINX Plus and Open Source.
Patch details and mitigation steps: https://t.co/Xfz4sQ4Xtz
🚨 Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks
Source: https://t.co/JRMGVhvuEC
A critical heap buffer overflow vulnerability, lurking in NGINX's source code since 2008, has been publicly disclosed. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution (RCE) against one of the most widely used web servers in the world.
Assigned a CVSS score of 9.2, CVE-2026-42945 resides in NGINX's ngx_http_rewrite_module. This engine powers URL rewriting and variable assignment in virtually every modern NGINX deployment.
#cybersecuritynews
🛑 3rd Linux kernel LPE in just ~2 weeks: Fragnesia (CVE-2026-46300) just dropped.
Attackers can now gain root by corrupting the kernel page cache through a flaw in XFRM ESP-in-TCP.
PoC is public. Major distros have already issued advisories.
Details: https://t.co/s8S9XA3sl1
@sparbuchfeinde Wer damals vernünftig gerechnet hat, der hat entweder eine entsprechend lange Zinsbindung abgeschlossen oder bewusst das Risiko von höheren Zinsen bei der Anschlussfinanzierung in Kauf genommen.
⚠️ Security releases are now available for the 25.x, 24.x, 22.x, 20.x Node.js release lines.
Please see the blog post for additional details: https://t.co/c7hHpc8CDf
@sparbuchfeinde Für Junge mag das passieren, bei Älteren wird sich das häufig nicht rechnen, weil nicht billiger und wenn Vorerkrankungen bestehen kann es sein, dass der ein oder andere auch ganz abgelehnt wird.
⚠️ Security release pre-alert:
We will release new versions of 20, 22, 24, 25 release lines on or shortly after 24th March, 2026 in order to address:
* 2 high severity issues
* 5 medium severity issues
* 2 low severity issues
https://t.co/c7hHpc8CDf