OpenSSL HollowByte Memory Leak Vulnerability
Eleven bytes are enough to force a weak OpenSSL server to use up to 131 KB of RAM. After that, it waits for a message that never comes. Following a sudden drop, the code...
Eleven bytes are enough to force a weak OpenSSL server to use up to 131 KB of RAM. After that, it waits for a message that never comes. Following a sudden drop, the code...
Changing AI behavior is much easier and cheaper than many people thought. Cyber expert Katie Paxton-Fear put a hidden flaw into an open AI model. Amazingly, she finished this task in just about one...
Robot vacuums have long roamed our homes unattended. Yet on certain Shark models, the cleaning came bundled with an unnoticed doorway for strangers. A security researcher uncovered a critical vulnerability that allows commands to...
Home cameras rarely stray beyond the local network. Nevertheless, vulnerabilities in the TP-Link Kasa EC70 and EC71 allow an attacker already inside that network to intercept administrator credentials and glean the device’s location. CVE-2026-9770:...
A plain archive file can easily turn into a bad hacking tool. Luckily, the maker of 7-Zip just launched version 26.02 to fix a huge flaw in XZ file tasks. During a real attack,...
The security firm Searchlight Cyber just found a major flaw inside the core WordPress code. This remote code execution flaw does not require any login steps. Any rogue user can run harmful code on...
The standard synchronization feature in Google Chrome can quietly transform your browser into a surveillance tool. Furthermore, an attacker requires no malicious software or technical expertise. They merely need brief physical access to another...
Active Exploitation of Critical SharePoint Vulnerabilities The United States Cybersecurity and Infrastructure Security Agency issued an urgent warning. Indeed, this warning concerns active exploits targeting on-premises Microsoft SharePoint servers. Currently, malicious actors leverage three...
The Illusion of Early-Stage Security The Secure Boot mechanism must block malicious code before Windows or Linux even launches. However, ESET researchers recently made a startling discovery. Specifically, attackers could bypass this protection almost...
A Historic Season for Security Experts typically consider summer a quiet season for software updates. Nevertheless, the July patch release from Microsoft proved to be monumental. The corporation resolved an astonishing 570 vulnerabilities simultaneously....
Renowned cybersecurity researcher Nightmare-Eclipse has once again disclosed an unpatched local privilege escalation vulnerability affecting Windows 10 and 11. Orchestrated as a calculated act of retaliation, the researcher deliberately timed the public disclosure to...
Malicious firmware can seize control of a device before Linux starts. It can remain nearly invisible to security software running at the OS level. Researchers at Binarly discovered six vulnerabilities in U-Boot. The open-source...