VS Code zero-day lets hackers steal GitHub tokens in one click
…They also marked it as not having any security impact. "As I mentioned in that post, going forward I would be doing full public disclosure for any security bugs I found in…
Dirty Frag Won't Be The Last Exploit
CopyFail Compromises The Last 9 Years Of Linux Distros
The First Exploit - Pwn2Own Documentary (Part 2)
The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)
Another Linux Distro Dropped Deepin Desktop
This Linux Bug Gives Attackers Root
IPv8 Changes Everything We Know About IP
…They also marked it as not having any security impact. "As I mentioned in that post, going forward I would be doing full public disclosure for any security bugs I found in…
…Licensee must refrain from any public disclosure of the issue prior to reaching agreement with Intel on the timetable and content for such disclosure. For further details on reporting security issues to…
…material disclosures that might affect their fortunes, they’re legally required to inform investors — and Netgear did do that in this case, submitting these two documents to the US Securities and Exchange…
Security Critical Microsoft Excel bug weaponizes Copilot Agent for zero-click information disclosure attack Could steal sensitive personal and financial data After a whopper of a Patch Tuesday last month , with six…
https://securityaffairs.com/193128/security/researcher-drops-a-new-vs-code-zero-day-after-losing-trust-in-microsofts-disclosure-process.html
This one has been building for a month and it came to a head this week. A researcher going by Chaotic Eclipse has released six Windows zero-days publicly over the past several weeks, covering Defender, BitLocker, and Win…
The traditional vulnerability disclosure timeline relies on a fundamental assumption: exploit development and vulnerability discovery take time. Over the last 12 months the integration of LLMs into offensive tooling has …
Disclosure: I work on Forkline, which maintains a fork of the retired Kubernetes ingress-nginx controller. NGINX published a security advisory for ngx_http_rewrite_module. The affected versions are NGINX Open Source belo…
TL;DR: If you are running NGINX Open Source below 1.30.1 or 1.31.0, you are affected by the current ngx_http_rewrite_module CVE batch. For Kubernetes ingress-nginx users this is especially relevant — the retired controll…
…Both AMD and Intel have rolled out new updates for Linux customers among other security disclosures today. Thankfully though the vulnerabilities don't appear to be too widespread or impactful. Hitting the…
…TweakTown News Hacking, Security & Privacy TL;DR: Microsoft threatened criminal charges against researcher Nightmare Eclipse for uncoordinated zero-day disclosures of six Windows vulnerabilities, sparking backlash from the cybersecurity community. Three exploits…
…But what caught cyber security researcher Kevin Beaumont’s eye was how Microsoft has responded. Microsoft suggests it plans to bring a criminal case against Nightmare Eclipse for failing to follow “proper…
…Security researchers are also raising the alarm regarding some highly suspicious disclosures and framing of the underlying issues. With Spectre and Meltdown, an early disclosure spilled the beans about a week earlier…
…The company has also partnered with the Open Source Security Foundation's Alpha-Omega project to help overwhelmed maintainers handle the surge in AI-generated bug disclosures. The patch bottleneck could be…
…the Openwall oss-security mailing list suggests that the vulnerability and the working exploit were publicly disclosed without prior coordination with Linux distribution maintainers. In typical responsible disclosure processes, vendors are given…