Search

Showing top 120 results for "Security disclosures"

Top stories

Discussions and forums

r/cybersecurity · u/sunychoudhary · 5h ago

Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process

https://securityaffairs.com/193128/security/researcher-drops-a-new-vs-code-zero-day-after-losing-trust-in-microsofts-disclosure-process.html

r/cybersecurity · u/Aureliand · 1w ago

Microsoft vs Chaotic Eclipse: three zero-days now actively exploited

This one has been building for a month and it came to a head this week. A researcher going by Chaotic Eclipse has released six Windows zero-days publicly over the past several weeks, covering Defender, BitLocker, and Win…

r/netsec · u/unknownhad · 3w ago

The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.

The traditional vulnerability disclosure timeline relies on a fundamental assumption: exploit development and vulnerability discovery take time. Over the last 12 months the integration of LLMs into offensive tooling has …

r/devops · u/pando85 · 3w ago

NGINX CVE-2026-42945 (ngx_http_rewrite_module) — patched boundary is 1.30.1 / 1.31.0

Disclosure: I work on Forkline, which maintains a fork of the retired Kubernetes ingress-nginx controller. NGINX published a security advisory for ngx_http_rewrite_module. The affected versions are NGINX Open Source belo…

r/kubernetes · u/pando85 · 3w ago

NGINX CVE-2026-42945 (rewrite module) — check your version if you are below 1.30.1 or 1.31.0

TL;DR: If you are running NGINX Open Source below 1.30.1 or 1.31.0, you are affected by the current ngx_http_rewrite_module CVE batch. For Kubernetes ingress-nginx users this is especially relevant — the retired controll…