🐘 PHP JPEG bugs: how image parsing leads to memory corruption.
Our researcher Nikita Sveshnikov discovered two JPEG-related memory-safety bugs in PHP’s ext/standard: CVE-2025-14177 in getimagesize and a heap buffer overflow in iptcembed.
https://t.co/WCQWlfuPZl
🧑🚒 Our researcher Mikhail Sukhov shares his knowledge and experience in analyzing FreeIPA environments.
He also introduces his new tool, IPAHound 💪
Go ’n see the details ➡️ https://t.co/6n4FYzrDvN
🔥 Read the new article by our researcher Timofey Duditsky.
The write-up dives into the AMD Platform Configuration Blobs mechanism, shows how it works, and reveals the vulnerability CVE-2025-54502.
https://t.co/DQHz8M5bRN
📢 Positive Hack Talks is heading to Kuala Lumpur 🇲🇾!
📍 Kuala Lumpur, Malaysia
🗓 May 5, 2026
Join us for a free in-person hacker event — everyone’s welcome!
CFP & attendee registration now open ⬇️
https://t.co/VdTBKu54t3
Two bugs. One chain. Full RCE.
New research by Aleksandr Zhurnakov on Dell Wyse Management Suite shows how business logic flaws can be chained into complete system compromise.
Read the full writeup!
https://t.co/OvGEX1WznU
🐘 Attack arithmetic: how an integer overflow in PostgreSQL libpq leads to denial of service.
Our researcher Aleksey Solovev discovered the vulnerability CVE-2025-12818, which may cause a product using the libpq PostgreSQL library to crash.
https://t.co/fP2LJFmqPS
🚨 Our researcher Alexander Zhurnakov identified two vulnerabilities in Dell Wyse Management Suite prior to version 5.5.
In certain configurations, they can be chained to achieve unauthenticated remote code execution.
Upgrade now → https://t.co/RGw8facFqE
📑 A new article from our researchers Aleksey Solovev, Nikita Sveshnikov and Vladimir Razov — "Blind trust: what is hidden behind the process of creating your PDF file?".
https://t.co/KUNM4ggDFt
📞 Microsoft fixed an authenticated RCE in Windows Telephony Service (CVE-2026-20931), discovered by our researcher Sergey Bliznyuk @justbronzebee
Read the write-up: https://t.co/nNsMGF1hLK
🏆Two of our research articles are shortlisted for PortSwigger's Top 10 Web Hacking Techniques of 2025 poll!
1⃣ Impossible XXE in PHP
2⃣ Blind trust: what is hidden behind the process of creating your PDF file?
Last day to vote if you found them useful!
https://t.co/Peko7WXB1e
Fala, Brasil! 🇧🇷
Essa é a última chamada para convocar seus amigos e colegas de Cyber pro Positive Hack Talks. Ainda dá tempo de garantir um lugar!
👉 https://t.co/EZ3WUANzJu
Confiem em mim: o evento vai entregar tudo. Garanto que eu não brinco em serviço quando o assunto é comunidade. Preparei algo de altíssimo nível, feito com muito carinho e sem enrolação. Só vem! ❤️🔥
📱 New article by our researcher @Fi5t: Injection for an athlete.
Read about a vulnerability discovered in the Garmin Connect mobile application:
https://t.co/RvdXiMgINI
🌎 Positive Hack Talks lands in Brazil 🇧🇷!
📍 São Paulo
🗓️ Dec 10, 2025
REMINDER: PHT is a fun and free cybersec event, see last pics: https://t.co/8A7UWz5uVT
⬆️ Register to attend or speak. Vamos!
New article by @a13xp0p0v: "Kernel-hack-drill and a new approach to exploiting CVE-2024-50264 in the Linux kernel."
Alexander used his pet project kernel-hack-drill to exploit a hard race condition that received the Pwnie Award 2025.
https://t.co/qiZwf1UvRe
🚨 We've launched https://t.co/o25eURJLtS, a new home for vulnerabilities. More than CVEs. More than MITRE.
✅ Trends & Insights
✅ AI-generated, multi-source vulnerability descriptions
✅ Researcher credits
✅ [drop your own tip in the comments]
Follow the project: @ptdbugs
👑 Our researcher has discovered LPE in VMWare Tools (CVE-2025-22230 & CVE-2025-22247) via VGAuth!
Write-up by the one who broke it: Sergey Bliznyuk (@justbronzebee)
https://t.co/8IECtEVd44
😈 Read the new article "Daemon Ex Plist: LPE via MacOS Daemons" by our researcher Egor Filatov.
This research reveals a vulnerability affecting popular apps like Mozilla VPN, Tunnelblick & more.
https://t.co/9Bz4paiWS0
1/4 dbugs LIVE
https://t.co/Cd6L8AD6Bt — vulnerabilities’ home
See trends, discover more, read AI summaries, have all references at hand, and your profile with all your CVEs and CVSS score on a leaderboard.
⬇️ See thread: what’s live + what’s next ⬇️
🧠 Our researcher Sergey Tarasov discovered a vulnerability (CVE-2025-49689) in NTFS on MS Windows.
The article dives into the exploitation path, file system internals, VHD format, and more.
🔗 Read the article: https://t.co/PJg6wQZKyk
🦊 Mozilla Foundation fixed CVE-2025-6430, discovered by our researcher Daniil Satyaev!
This vulnerability allows the Content-Disposition: attachment header to be ignored if the page is opened using <embed> or <object>, resulting in files being displayed instead of downloaded.