Recientemente #Radix ha cerrado mi dominio https://t.co/D5Esydjfky, indicando que por Pattern-matching, mi sitio se comporta como campaña de phishing, tienen cero tolerancia y prefieren suspender dominios legitimos, mi sitio solo tiene un login con captcha, nada de registros.
🔴 v12sec tarafından PostgreSQL 18.4'te yeni bir bidirectional RCE 0-day açığı keşfedildi.
Admin yetkisi olmadan Client-server arasında her iki yönde de kod çalıştırma mümkün.
‼️🚨 This is alarming: Researchers found a one-click data exfiltration vulnerability in M365 Copilot. A single click on a trusted microsoft[.]com link let attackers pull emails, MFA codes, meeting notes, and SharePoint/OneDrive files, no permissions or second click required.
Microsoft has patched it as CVE-2026-42824, rated critical.
Exploit PoC Telegram Web app XSS / Session Hijacking 1-click
The XSS vulnerability is triggered using the event type web_app_open_link via postMessage. (CVE-2024–33905)
https://t.co/cGj0ywhSMA
@isaacrrr7 El vídeo proviene de un incidente real en Sunamganj, Bangladesh, alrededor de 25 de marzo de 2026. La turba atacó la casa de una familia musulmana (Ali Hossain y Tarek Miah) por acusaciones de robo. La mujer es musulmana, no cristiana, es un linchamiento por robo, no por religion
⚠️ CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks
Read more: https://t.co/tIXmuvjiEX
CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat actors are actively exploiting the flaw in real-world attacks.
The vulnerability, tracked as CVE-2025-21042, is an out-of-bounds write vulnerability in the libimagecodec.quram[.]so library on Samsung mobile devices.
This security flaw allows remote attackers to execute arbitrary code on vulnerable devices without user interaction, making it particularly dangerous and prone to widespread exploitation.
#cybersecuritynews
‼️ China's largest cybersecurity firm, Knownsec, was breached, exposing details of China's state cyber operations.
The data includes cyberweapon documentation, internal hacking tool source code, and global target lists covering over 20 countries, including Japan, Vietnam, and India.
A spreadsheet lists 80 hacked foreign organizations, plus evidence of 95 GB of stolen Indian immigration data and 3 TB of call records from South Korean mobile operator LG U Plus.
One of the documents mention a malicious power bank, disguised as a charging device.
Knownsec is key to China's cybersecurity, providing advanced defense and offensive capabilities, including espionage tools.
A thread with their tools 🧵
I bypassed user approvals and achieved RCE in VS Code Copilot by flipping 4 bits.
Find out how: https://t.co/lKU2BisgsQ
Thanks to @msftsecresponse for rapidly triaging and patching this vulnerability.