🚨 Critical 18-Year-Old NGINX Vulnerability Enables Remote Code Execution Attacks
Source: https://t.co/JRMGVhvuEC
A critical heap buffer overflow vulnerability, lurking in NGINX's source code since 2008, has been publicly disclosed. This vulnerability has been publicly disclosed, along with a working proof-of-concept exploit that can enable unauthenticated remote code execution (RCE) against one of the most widely used web servers in the world.
Assigned a CVSS score of 9.2, CVE-2026-42945 resides in NGINX's ngx_http_rewrite_module. This engine powers URL rewriting and variable assignment in virtually every modern NGINX deployment.
#cybersecuritynews
QUER SE DESAFIAR COM WEB HACKING?
https://t.co/40xxK1qcew
https://t.co/42fQ9J0eUp
https://t.co/dyrajCyj60
https://t.co/6bAOwUu1fH
QUER SE DESAFIAR COM EXPLORAÇÃO BINÁRIA?
https://t.co/8GKG8XwDhl
https://t.co/PaZLQh4YIA
https://t.co/i0KICBl3Sh
https://t.co/Tapjepoxjl
QUER SE DESAFIAR COM CRIPTOGRAFIA?
https://t.co/Kd9HrRxFJ9
https://t.co/Haey6o9oqV
https://t.co/ieUXHHOMDF
QUER SE DESAFIAR COM ENGENHARIA REVERSA?
https://t.co/E1kpWfyi8E
https://t.co/xAgtETuio0
https://t.co/oI9smjdU77
https://t.co/roerii4wtO
https://t.co/YmJ0XkSWa0
QUER SE DESAFIAR COM FORENSICS?
https://t.co/WvASrNB7Vn
https://t.co/Htm9ZeeLom
https://t.co/vxeGzu6FcH
QUER SE DESAFIAR COM OSINT?
https://t.co/hyeg8cKWaJ
https://t.co/3hGGTGIWpu
https://t.co/9FU2L1k3gK
https://t.co/pTFzF6ID8Y
QUER SE DESAFIAR COM TUDO?
https://t.co/0VnJrPWyqu
https://t.co/sOy2NcukDv
People are asking how the OSINT nerds found the guy that drained the cancer bro.
Well, it's very shrimple
The shitty malware sent all the stolen data to a Telegram the scammers made.
We connected to the Telegram channel using the same credentials that were inside of the shitty malware
Inside the channel was the scammer(s)
We got their Telegram IDs
OSINT nerds used their Telegram IDs to see if they were in any other public facing chatrooms.
One of the scammers in there was in several fraud chatrooms. He advertised looking for a video game programmer to make a basic 2D game. He also advertised needing help with some malware stuff.
In a different chatroom he talked about how much he likes skateboarding.
In a different channel he shared his Instagram and was sharing photos of himself next to expensive cars
Then, OSINT nerds looked at his Instagram which had a LinkTree. His LinkTree linked to literally everything about the guy including his YouTube, PayPal, Kick, Twitter, etc.
So either he is a master of disguise, and ran a year long detrace campaign to throw off OSINT nerds in the event he's caught scamming
Or alternatively, he wasn't aware public Telegram chatrooms are public and could be searched easily.
Le @SecretService des USA a démantelé un réseau de +300 serveurs SIM et 100 000 cartes SIM à New York.
Ils attribuent cette opération à un acteur malveillant très probablement parrainé par un état -on parle souvent de "state sponsored actor"-
Le dispositif visait à paralyser les systèmes de télécommunications et de mener des attaques téléphoniques anonymes.
Ils se rejouissent de cette opération qui laissait peser une vraie menace avant l'arrivée des dirigeants mondiaux à l'Assemblée Générale des Nations Unies.
📰https://t.co/KkcWWcQRQJ
Decided to do some digging to track down the scammers who stole $32k from a cancer patient.
His clueless bimbo girlfriend couldn’t help but flex on TikTok with money stolen from multiple victims.
The biggest mistake most of these scammers make is showing off their lifestyle on social media, leaving clues for everyone to trace them.
1/4
I've released a DOMLogger++ config that helps detect any replacements occurring in a DOMPurify output by inserting and tracking a canary value at runtime.
I think it highlights how useful DOMLogger++ can be for tracking JS execution :D
👉 https://t.co/ScqNSP1j8b
1/3
Introduction to Windows Kernel Exploitation for Beginners
Part 1: https://t.co/iytco8khA0
Part 2: https://t.co/Kr5z56e0pV
Part 3: https://t.co/sdI2uEndk6
Part 4: https://t.co/6DmUNO3iQU
Part 5: https://t.co/CW1ulPqGqq
#windows#infosec#kernal#exploit#100xSecurity
The latest Google Pixel 6 pwned with a 0day in kernel! Achieved arbitrary read/write to escalate privilege and disable SELinux without hijacking control flow. The bug also affects Pixel 6 Pro, other Pixels are not affected :)
Voici un rapport d’Incident/Réponse (source interne) qui donne un peu plus de détails sur la cyber attaque qu’a subi Cisco il y a quelques jours :
https://t.co/PTa9d2YByR
Le gouvernement des Etat-Unis double la récompense et offre dorénavant 10M$ pour des renseignements sur les cyber groupes nord-coréens 😮
https://t.co/Gouf9zK2AV
A new user on the Russian cybercrime forum Exploit just posted a video claiming to show a zero-day, remote code execution exploit in Google's latest Chrome browser running on Windows 10. Asking price: $2M. h/t @HoldSecurity