Posts

/../assets/images/featured/adobe_critical.png
Adobe Campaign Classic — Second CVSS 10.0 Flaw in a Month Allows Code Execution Without User Interaction (CVE-2026-48449)

Adobe fixed CVE-2026-48449, an incorrect authorization flaw in Campaign Classic with a CVSS score of 10.0 that allows arbitrary code execution without user interaction. It is the second CVSS 10.0 incorrect-authorization flaw in the same product within a single month. The update also resolves a high-severity SQL injection flaw and eight critical Adobe Bridge vulnerabilities.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

9 min read
/../assets/images/featured/Fastjson.png
CVE-2026-16723: Active Exploitation of a Critical RCE (0-Day) Vulnerability in Fastjson 1.x

A flaw in type resolution during JSON deserialization allows unauthenticated remote code execution in Spring Boot applications that use Fastjson 1.x, without needing AutoType to be enabled.

Tags: News
Threat Intelligence Teams

Threat Intelligence Teams

6 min read
/../assets/images/featured/OpenAIHF.png
OpenAI Models Reportedly Escaped Their Testing Environment to Breach Hugging Face Servers

OpenAI acknowledges that, during an internal cybersecurity evaluation, its own models reportedly escaped their testing environment and reached real Hugging Face infrastructure.

Tags: News
Threat Intelligence Desk

Threat Intelligence Desk

4 min read
/../assets/images/featured/GhostLock.png
GhostLock: Breaking Down the Critical Linux Kernel Privilege-Escalation and Container-Escape Flaw (CVE-2026-43499)

A use-after-free in the Linux kernel's priority-inheritance futex logic, sitting undetected since 2011, lets an unprivileged local user pop a root shell and, in tested setups, break out of a container.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

10 min read
/../assets/images/featured/bad-epoll.png
Bad Epoll: analysis of the critical privilege escalation vulnerability in the Linux kernel (CVE-2026-46242)

A race condition and a Use-After-Free in the Linux kernel's epoll subsystem allow an unprivileged local user to obtain a root shell.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

5 min read
/../assets/images/featured/ChocoPoC.png
ChocoPoC RAT: when the exploit itself is the trap

Trojanized PoC repositories on GitHub distribute ChocoPoC, a Python RAT that steals credentials and vulnerability intelligence from security researchers.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

5 min read