Posts
Adobe fixed CVE-2026-48449, an incorrect authorization flaw in Campaign Classic with a CVSS score of 10.0 that allows arbitrary code execution without user interaction. It is the second CVSS 10.0 incorrect-authorization flaw in the same product within a single month. The update also resolves a high-severity SQL injection flaw and eight critical Adobe Bridge vulnerabilities.
obeedt, OscarRV, LuisZavMen
A flaw in type resolution during JSON deserialization allows unauthenticated remote code execution in Spring Boot applications that use Fastjson 1.x, without needing AutoType to be enabled.
Threat Intelligence Teams
OpenAI acknowledges that, during an internal cybersecurity evaluation, its own models reportedly escaped their testing environment and reached real Hugging Face infrastructure.
Threat Intelligence Desk
A use-after-free in the Linux kernel's priority-inheritance futex logic, sitting undetected since 2011, lets an unprivileged local user pop a root shell and, in tested setups, break out of a container.
obeedt, OscarRV, LuisZavMen
A race condition and a Use-After-Free in the Linux kernel's epoll subsystem allow an unprivileged local user to obtain a root shell.
obeedt, OscarRV, LuisZavMen
Trojanized PoC repositories on GitHub distribute ChocoPoC, a Python RAT that steals credentials and vulnerability intelligence from security researchers.
obeedt, OscarRV, LuisZavMen