🚨 Successful PoC for Linux Kernel CVE-2026-43503 (DirtyFrag variant) 🚨
JFrog researchers successfully developed a privilege escalation exploit for CVE-2026-43503, a newly discovered DirtyFrag variant we dubbed "DirtyClone".
The vulnerability was patched and merged into mainline Linux on May 21 (v7.1-rc5, commit 9e171fc1d7d7). Make sure your systems are up to date.
Read the full technical writeup: https://t.co/y7a3dduBsD
🚨Weaponized media files! JFrog has uncovered "PixelSmash" (CVE-2026-8461), a high-severity flaw in FFmpeg's MagicYUV decoder (CVSS 8.8). 🛑
📦 By simply uploading a crafted 50 KB video, researchers achieved reliable RCE on Jellyfin and Nextcloud, and triggered immediate DoS crashes across mpv, Kodi, OBS, and vLLM AI pipelines. 📉
🛡️ See if you're exposed: https://t.co/aa3o4bNAPC
A security vulnerability has been discovered in the mcp-remote project.
For the first time, full remote code execution has been achieved in the real world on the client operating system when connecting to an untrusted remote MCP server. Read the blog: https://t.co/WE5611NNP6
#mcp #security #agenticAI
Confirmed! Or Peles, Omer Kaspi and Uriya Yavnieli from JFrog Security Research used a stack exhaustion bug to perform a DoS on the OPC Foundation OPC UA .NET Standard. They earn another $5,000 and 5 more Master of Pwn points. #Pwn2Own#P2OMiami
The team of Or Peles, Omer Kaspi and Uriya Yavnieli from JFrog Security Research succeeded with their DoS of the Unified Automation C++ Demo Server. They head off to the disclosure room for confirmation. #Pwn2Own#P2O
Security Alert: a newly-discovered integer overflow vulnerability in #HAProxy could lead to an HTTP request smuggling attack. Learn about the problem and its mitigation in this blog by Ori Hollander and @peles_o https://t.co/mPNnI0xH5i
#CyberAttack#cybersecurty#http
Read how our researchers are helping secure #OpenSource projects by discovering zero-day #vulnerabilities in the Lighttpd web server, the Live555 Media Library and a #Linux driver for the Realtek’s RTL8189ES Wi-Fi chip.
https://t.co/2bqaB9Ko8r
Our latest research here at @VDOOSecurity by @peles_o, showcasing the significant cyber threats on connected physical security products #iot#iotsecurity
https://t.co/q06PWilSpF
My detailed writeup on our newly discovered vulnerabilities in Foscam cameras that lead to a remote unauthenticated root shell. CVE-2018-6830, CVE-2018-6831, CVE-2018-6832 https://t.co/dhaYExEGc9
First batch of Huawei mobile pwn2own vulnerabilities fixed. Only time we needed an arbitrary delete primitive as part of a exploit chain :) Detailed write-up to follow at a later stage! https://t.co/UrkdeWtU2A
We review some #javadeser vulnerabilities in Android and showed how to find them using QL, these include CVE-2014-7911(@tehjh), CVE-2015-3825 (@peles_o and @roeehay), CVE-2017-411/412(@laginimaineb) and a new one CVE-2017-0871: https://t.co/V8p0NilyaM