<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vulnerability &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Tue, 29 Sep 2026 21:53:10 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.9</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>vulnerability &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>GitHub AI Agent Discovers 24 Android Flaws</title>
		<link>https://firsthackersnews.com/ai-agent-android-vulnerabilities/</link>
					<comments>https://firsthackersnews.com/ai-agent-android-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 29 Sep 2026 21:52:56 +0000</pubDate>
				<category><![CDATA[Android malware]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[account takeover]]></category>
		<category><![CDATA[AI security agent]]></category>
		<category><![CDATA[android security]]></category>
		<category><![CDATA[Android vulnerabilities]]></category>
		<category><![CDATA[GitHub Security Lab]]></category>
		<category><![CDATA[mobile security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12493</guid>

					<description><![CDATA[<p>GitHub Security Lab has revealed that its open-source AI security agent found 24 vulnerabilities in Android applications. Some</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/ai-agent-android-vulnerabilities/">GitHub AI Agent Discovers 24 Android Flaws</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>GitHub Security Lab has revealed that its open-source AI security agent found <strong>24 vulnerabilities in Android applications</strong>. Some of the issues were serious enough to allow hidden location tracking and potential account takeovers.</p>



<p>The research shows how AI can help security researchers examine large codebases and spot complicated mobile security problems. However, the findings still need to be checked and tested by human security experts.</p>



<h2 class="wp-block-heading"><strong>How the AI Security Agent Works</strong></h2>



<p>The research used GitHub Security Lab’s <strong>Taskflow Agent</strong>, an open-source framework built to support AI-assisted security testing.</p>



<p>Instead of giving an AI model a huge codebase and asking it to find everything, researchers divided the investigation into smaller tasks designed specifically for Android.</p>



<p>One workflow looked for important Android entry points, including:</p>



<ul class="wp-block-list">
<li>Exported activities and services</li>



<li>Broadcast receivers</li>



<li>Deep links</li>
</ul>



<p>Another workflow then checked these areas for common Android security problems, such as unsafe intents, insecure broadcasts, WebView issues, and cross-app attacks.</p>



<p>This approach helped the AI focus on the parts of an application that could be exposed to other apps or external input.</p>



<h2 class="wp-block-heading"><strong>OsmAnd Flaw Could Reveal User Locations</strong></h2>



<p>One of the notable vulnerabilities was found in <strong>OsmAnd</strong>, a popular Android navigation application with more than 10 million downloads.</p>



<p>Researchers discovered that its exported <code>MapActivity</code> could accept certain attacker-controlled settings through Android intents.</p>



<p>A malicious app installed on the same device could use these inputs to silently change OsmAnd settings. One possible attack could redirect map-tile requests to a server controlled by the attacker.</p>



<p>By watching the requests, an attacker could potentially determine where a user was located and track movements. Routing information, including starting points and destinations, could also be exposed.</p>



<p>The concerning part is that the victim could continue using the navigation app normally without realizing anything had changed.</p>



<h2 class="wp-block-heading"><strong>Wikipedia Bugs Could Lead to Account Takeover</strong></h2>



<p>Another serious chain was found in the <strong>Wikipedia Android app</strong>.</p>



<p>The application uses a <code>wikipedia://</code> deep link to open content inside its WebView. Researchers found that the app used an unsafe domain check that looked at whether a hostname simply ended with <code>wikipedia.org</code>.</p>



<p>That means a domain such as <code>evil-wikipedia.org</code> could potentially pass the check even though it was not an official Wikipedia domain.</p>



<p>Researchers also identified another weakness involving cookie handling. When combined, the issues could potentially expose authentication information to an attacker-controlled webpage.</p>



<p>This could give an attacker access to a victim&#8217;s Wikimedia session and potentially lead to account takeover after the victim interacts with a malicious link.</p>



<h2 class="wp-block-heading"><strong>AI Helps Researchers, But Humans Still Matter</strong></h2>



<p>GitHub emphasized that AI-generated security findings should not automatically be treated as confirmed vulnerabilities.</p>



<p>AI models can be useful for identifying suspicious code, APIs, and attack paths, but they can also produce false positives or misunderstand how a vulnerability behaves in a real environment.</p>



<p>Researchers found that asking the AI to create a proof of concept can help determine whether a suspected issue is actually exploitable. Even then, human testing remains an important part of the process.</p>



<p>The Taskflow Agent and the Android security workflows have been made publicly available, giving security researchers another way to use AI for structured mobile application testing.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/ai-agent-android-vulnerabilities/">GitHub AI Agent Discovers 24 Android Flaws</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/ai-agent-android-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Hackers Exploit File Notifications to Track User Activity</title>
		<link>https://firsthackersnews.com/protect-against-file-notification-attack-linux-windows-macos/</link>
					<comments>https://firsthackersnews.com/protect-against-file-notification-attack-linux-windows-macos/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 28 Sep 2026 18:34:42 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Exploitation]]></category>
		<category><![CDATA[Linux Malware]]></category>
		<category><![CDATA[MacOS]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[windows]]></category>
		<category><![CDATA[cyber attack]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Linux security]]></category>
		<category><![CDATA[macOS Security]]></category>
		<category><![CDATA[privacy]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[Side-Channel Attack]]></category>
		<category><![CDATA[windows security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12479</guid>

					<description><![CDATA[<p>A new security study has uncovered a privacy concern affecting Linux, Windows, and macOS. Researchers found that attackers</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/protect-against-file-notification-attack-linux-windows-macos/">Hackers Exploit File Notifications to Track User Activity</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A new security study has uncovered a privacy concern affecting <strong>Linux, Windows, and macOS</strong>. Researchers found that attackers could use normal file-notification features to monitor user activity without needing administrator privileges.</p>



<p>File-notification systems are designed to help applications know when files or folders change. However, researchers discovered that the information they provide can also reveal useful clues about what a user is doing.</p>



<p>The research was conducted by researchers at <strong>Graz University of Technology</strong>. Their study, titled <em>“File Notification Attacks: Templating and Exploiting Side-Channel Leakage from the File-Notification Systems on Linux, Windows, and macOS,”</em> explores how these signals can be used as a side channel.</p>



<h2 class="wp-block-heading">How the File Notification Attack Works</h2>



<p>Linux, Windows, and macOS use different technologies to monitor file-system changes. These include <strong>inotify</strong> on Linux, <strong>ReadDirectoryChangesW</strong> on Windows, and <strong>FSEvents</strong> on macOS.</p>



<p>These services are not vulnerabilities by themselves. They are legitimate features used by applications to respond to changes in files and folders.</p>



<p>The problem is that notifications can contain information such as file paths, timing, and activity patterns. By collecting this information and comparing it with previously recorded examples, malicious software can potentially identify what a user is doing.</p>



<p>Researchers created a semi-automated system that records file-system activity while different actions are performed. These recordings can then be used as templates to recognize similar activity later.</p>



<p>The study found that these patterns could reveal activities including <strong>terminal commands, keyboard and mouse input, website visits, printing, virtual machines, containers, VPN changes, Bluetooth activity, and USB-device connections</strong>.</p>



<p>The monitoring also had a very small effect on system performance, with the researchers measuring CPU overhead of no more than <strong>0.21%</strong> in their tests.</p>



<h2 class="wp-block-heading"><strong>Linux and Windows Show Significant Information Leakage</strong></h2>



<p>Linux produced some of the most detailed activity signals in the study. Researchers found that an unprivileged user could receive certain file notifications even when they could not directly read the related files.</p>



<p>This information was enough to identify keystroke patterns in testing involving seven users, with F1 scores ranging from <strong>93.1% to 100%</strong>.</p>



<p>The researchers also monitored pseudo-terminal activity over SSH and achieved a <strong>100% F1 score</strong> in their test scenario. Passwords entered into terminals with input echo disabled were not observable.</p>



<p>On Windows, the researchers found that monitoring the root of the <strong>C: drive</strong> could expose file paths associated with another user&#8217;s profile, even when the monitoring user did not have permission to access those directories.</p>



<p>Browser activity was another concern. File-system patterns created by browser storage could help identify websites visited by a user. In the study, Firefox activity from <strong>975 of the top 1,000 tested websites</strong> could be identified, achieving a <strong>97.8% F1 score</strong> in the researchers&#8217; test. Edge produced fewer site-specific patterns and achieved a <strong>48.5% F1 score</strong>.</p>



<h2 class="wp-block-heading"><strong>macOS Reveals Less, But Still Exposes Activity</strong></h2>



<p>macOS provided stronger separation between users because <strong>FSEvents</strong> does not freely expose private directories belonging to other users.</p>



<p>However, researchers were still able to identify patterns associated with activities such as <strong>application launches, system setting changes, printing, network activity, external storage, Bluetooth devices, and virtual machines</strong>.</p>



<p>The average notification latency on macOS was around <strong>11.48 milliseconds</strong>, making it slower than the other platforms tested. Despite this, researchers said the information could still be useful for behavioral monitoring.</p>



<p>Importantly, this technique is not a remote attack that can compromise a computer over the internet. Malicious software must already be running on the machine as a local, unprivileged user.</p>



<p>That makes the technique more relevant to <strong>post-compromise surveillance</strong>, where malware already present on a system attempts to gather additional information about the victim.</p>



<h2 class="wp-block-heading"><strong>Researchers Recommend Stronger Protection</strong></h2>



<p>The researchers reported their findings to <strong>Linux, Microsoft, Apple, and KDE in October 2025</strong>.</p>



<p>Linux introduced a partial mitigation for certain device files in early 2026. Microsoft classified the behavior as being <strong>by design</strong> and provides the <code>EnforceDirectoryChangeNotificationPermissionCheck</code> policy to restrict certain unauthorized path disclosures. The researchers noted that this setting is disabled by default.</p>



<p>The researchers recommend stronger permission checks that clearly separate files a user owns, files they can read, and protected files belonging to others. They also recommend tighter controls on applications that attempt to monitor large sections of the file system.</p>



<p>Organizations can reduce the risk by keeping systems updated, limiting untrusted software, using application sandboxing, separating service accounts, and applying stricter notification permissions where available.</p>



<p>The research highlights an important security lesson: <strong>attackers do not always need to read sensitive data to learn something about a user.</strong> File paths, timing information, and system notifications can become valuable sources of intelligence when analyzed together.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/protect-against-file-notification-attack-linux-windows-macos/">Hackers Exploit File Notifications to Track User Activity</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/protect-against-file-notification-attack-linux-windows-macos/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Samsung Flaw Turns Devices Into Cryptominers</title>
		<link>https://firsthackersnews.com/samsung-magicinfo-cryptominer/</link>
					<comments>https://firsthackersnews.com/samsung-magicinfo-cryptominer/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 17:01:22 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[cryptominer]]></category>
		<category><![CDATA[CVE-2025-4632]]></category>
		<category><![CDATA[MagicINFO vulnerability]]></category>
		<category><![CDATA[Monero miner]]></category>
		<category><![CDATA[Samsung MagicINFO]]></category>
		<category><![CDATA[Samsung security flaw]]></category>
		<category><![CDATA[windows malware]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12468</guid>

					<description><![CDATA[<p>Attackers exploited a known flaw in Samsung MagicINFO to gain access to a Windows system and use its</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/samsung-magicinfo-cryptominer/">Samsung Flaw Turns Devices Into Cryptominers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Attackers exploited a known flaw in <strong>Samsung MagicINFO</strong> to gain access to a Windows system and use its resources to mine cryptocurrency.</p>



<p>Instead of downloading a ready-made miner, the attackers <strong>built the mining software directly on the compromised computer</strong>. This unusual step created activity that security tools could detect.</p>



<p>The incident was discovered in early September 2026 during an investigation of a MagicINFO Premium system. After gaining access, the attackers installed a remote access tool, created an administrator account, disabled Microsoft Defender, and used the machine to mine <strong>Monero</strong>.</p>



<p>Huntress researchers found the activity while investigating a managed endpoint. The case involved one confirmed system and shows how a vulnerable internet-facing service can lead to long-term access and unauthorized use of computing resources.</p>



<h2 class="wp-block-heading">Attackers Exploited a MagicINFO Vulnerability</h2>



<p>The initial access was linked to <strong>CVE-2025-4632</strong>, a vulnerability in MagicINFO that allows attackers to write files with system-level privileges.</p>



<p>Samsung released a fix for the flaw in May 2025.</p>



<p>After the initial alert, the customer was advised to address the issue. However, investigators observed new activity eight days later through the same access route.</p>



<p>The attackers attempted to install <strong>AnyDesk</strong>, a legitimate remote access application, three times.</p>



<p>The first two attempts were blocked by Microsoft Defender. The attackers eventually succeeded and configured a password so they could reconnect to the machine.</p>



<p>They then created a local administrator account and disabled Microsoft Defender, giving themselves a more reliable way to maintain access.</p>



<h2 class="wp-block-heading">The Miner Was Built on the Infected PC</h2>



<p>Once the system was under their control, the attackers launched a Monero miner builder from the user&#8217;s Documents folder.</p>



<p>The process started several development tools and C compilers to create the mining software directly on the machine.</p>



<p>This approach helped the attackers avoid simply dropping a finished miner onto the system, but it also created a noticeable trail.</p>



<p>The unsigned builder generated unusual compiler activity that could stand out in endpoint monitoring.</p>



<p>Afterward, investigators observed the miner connecting to a public mining pool and using the compromised system&#8217;s computing resources.</p>



<p>The mining activity also appeared to involve Windows Explorer, making the behavior even more suspicious.</p>



<h2 class="wp-block-heading">What Security Teams Should Watch For</h2>



<p>The incident highlights why patching internet-facing MagicINFO installations is important.</p>



<p>Security teams should pay attention to:</p>



<ul class="wp-block-list">
<li>Unexpected remote access software</li>



<li>New administrator accounts</li>



<li>Microsoft Defender being disabled</li>



<li>Unusual compiler activity</li>



<li>Unknown processes using high CPU resources</li>



<li>Unexpected connections to cryptocurrency mining pools</li>
</ul>



<p>Removing the miner is not enough. Teams should also determine <strong>how the attacker gained access and whether the vulnerable entry point is still exposed</strong>.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/samsung-magicinfo-cryptominer/">Samsung Flaw Turns Devices Into Cryptominers</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/samsung-magicinfo-cryptominer/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Critical Next.js Bug Puts Applications at Risk</title>
		<link>https://firsthackersnews.com/nextjs-remote-code-execution-vulnerability/</link>
					<comments>https://firsthackersnews.com/nextjs-remote-code-execution-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 15:04:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CVE-2026-94545]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Next.js]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[SVG Security]]></category>
		<category><![CDATA[Web Security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12453</guid>

					<description><![CDATA[<p>A serious security issue in Next.js could allow attackers to run code on a server by sending specially</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/nextjs-remote-code-execution-vulnerability/">Critical Next.js Bug Puts Applications at Risk</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A serious security issue in Next.js could allow attackers to run code on a server by sending specially crafted SVG content.</p>



<p>Tracked as <strong>CVE-2026-94545</strong>, the vulnerability affects the Node.js version of the <strong><code>ImageResponse</code></strong> feature in the <code>next/og</code> package. It can become dangerous when applications use untrusted data inside SVG images.</p>



<p>The issue affects <strong>Next.js 16.2.0 through versions before 16.3.6</strong>. Developers should upgrade to <strong>Next.js 16.3.6</strong>, which includes the fix.</p>



<h2 class="wp-block-heading"><strong>How the Attack Can Happen</strong></h2>



<p><code>ImageResponse</code> is commonly used to generate Open Graph images, social media previews, and other graphics directly from a Next.js application.</p>



<p>The problem appears when user-controlled information is placed into SVG content, attributes, or styles during image generation.</p>



<p>For example, an application might take information from a URL parameter, form, or API request and insert it into an SVG before generating an image.</p>



<p>An attacker could send specially crafted input that reaches the vulnerable image-rendering process. If the application is configured in a vulnerable way, this could result in <strong>remote code execution on the server</strong>.</p>



<p>The potential impact depends on the application&#8217;s permissions and what resources the server can access. A compromised environment could potentially expose sensitive information, modify content, disrupt services, or provide access to other connected systems.</p>



<h2 class="wp-block-heading"><strong>Who Is Affected?</strong></h2>



<p>Not every Next.js application is vulnerable.</p>



<p>According to the provided advisory information, applications using the <strong>Edge implementation of <code>ImageResponse</code> are not affected</strong>.</p>



<p>Applications using the Node.js implementation may also be unaffected if they never place attacker-controlled data into SVG content, attributes, or CSS styles.</p>



<p>The vulnerability has been rated <strong>Critical</strong> and can be exploited remotely without authentication or user interaction.</p>



<h2 class="wp-block-heading"><strong>Update to Next.js 16.3.6</strong></h2>



<p>Developers should review applications that generate images through <strong><code>next/og</code></strong>, especially Open Graph image endpoints that accept URL parameters or other external input.</p>



<p>The recommended action is to:</p>



<ul class="wp-block-list">
<li>Upgrade affected Next.js installations to <strong>16.3.6</strong>.</li>



<li>Check image-generation routes for untrusted input.</li>



<li>Review SVG content, attributes, and styles that use user-controlled data.</li>



<li>Avoid passing untrusted input directly into SVG processing.</li>



<li>Review internet-facing image-generation endpoints.</li>
</ul>



<p>If an immediate upgrade is not possible, removing attacker-controlled input from SVG processing can reduce the risk.</p>



<p>The vulnerability was reported by security researchers <strong>RaghavMaheshwari124 and rafabd1</strong>. Given that image-generation endpoints can be exposed to the internet, organizations using the affected Node.js <code>ImageResponse</code> implementation should review and patch their applications promptly.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/nextjs-remote-code-execution-vulnerability/">Critical Next.js Bug Puts Applications at Risk</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/nextjs-remote-code-execution-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>GitLab Flaw Lets Attackers Push Code to Private Repos</title>
		<link>https://firsthackersnews.com/gitlab-email-feature-vulnerability/</link>
					<comments>https://firsthackersnews.com/gitlab-email-feature-vulnerability/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 23 Sep 2026 12:53:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CI/CD Security]]></category>
		<category><![CDATA[Code Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Git Repository]]></category>
		<category><![CDATA[gitlab]]></category>
		<category><![CDATA[GitLab Security]]></category>
		<category><![CDATA[GitLab vulnerability]]></category>
		<category><![CDATA[Software Security]]></category>
		<category><![CDATA[supply chain security]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12450</guid>

					<description><![CDATA[<p>GitLab’s “Email work item to this project” feature could create a security risk when its private email address</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gitlab-email-feature-vulnerability/">GitLab Flaw Lets Attackers Push Code to Private Repos</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>GitLab’s <strong>“Email work item to this project”</strong> feature could create a security risk when its private email address becomes exposed, according to research from Aikido Security researcher Joe Leon.</p>



<p>The email address contains a long-lived <strong>incoming-email token</strong>. GitLab documentation says this token must remain private because anyone who has it can perform actions as the token owner, including creating issues and merge requests.</p>



<p>The problem becomes more serious because the feature can also be used to send code changes into a repository.</p>



<h2 class="wp-block-heading"><strong>A Private Email Address Can Trigger Code Changes</strong></h2>



<p>Aikido found that email addresses created for different projects can contain the same account-level token.</p>



<p>An attacker who obtains the address can reportedly change the email format from an issue address to a <strong>merge-request address</strong> and include a Git patch. By specifying a source branch in the email subject, GitLab can apply the patch using the permissions of the token owner.</p>



<p>This means the feature is not limited to creating unwanted issues.</p>



<p>For example, an attacker could modify a project’s <strong><code>.gitlab-ci.yml</code></strong> file. If the change triggers a CI/CD pipeline, attacker-controlled commands could potentially run within the victim’s project.</p>



<p>Depending on the user’s permissions and pipeline setup, this could expose source code, CI/CD variables, job tokens, or other sensitive information.</p>



<h2 class="wp-block-heading"><strong>Network Restrictions May Not Stop It</strong></h2>



<p>The research also found that GitLab’s incoming email workflow can bypass assumptions about IP-based restrictions.</p>



<p>Aikido reported testing a private project that allowed access only from a specific IP address. While browser access and Git cloning were blocked, the emailed patch was still accepted and resulted in a commit to the main branch.</p>



<p>GitLab now documents that <strong>incoming email is not covered by IP restrictions</strong>, meaning an IP allowlist should not be considered a complete security control for this feature.</p>



<p>An attacker does not necessarily need to spoof the sender either, because GitLab does not currently require the email to come from an address verified on the token owner’s account.</p>



<h2 class="wp-block-heading"><strong>What GitLab Users Should Check</strong></h2>



<p>GitLab has treated the behavior as part of the feature’s design rather than a traditional vulnerability. The company has nevertheless updated its interface and documentation to better explain the risks and the capabilities of incoming email addresses.</p>



<p>Organizations should search repositories, documentation, tickets, logs, and public pages for exposed <strong><code>glimt-</code></strong> email addresses and older incoming-mail token formats.</p>



<p>If an address has been exposed, the associated incoming email token should be <strong>reset</strong>, which invalidates the related project email addresses.</p>



<p>Security teams should also review:</p>



<ul class="wp-block-list">
<li>User permissions</li>



<li>Protected branch settings</li>



<li>CI/CD pipelines</li>



<li>CI/CD variables</li>



<li>Recent commits</li>



<li>Audit events</li>
</ul>



<p>The main takeaway is simple: <strong>GitLab project email addresses containing incoming-mail tokens should be treated like credentials and kept secret.</strong></p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/gitlab-email-feature-vulnerability/">GitLab Flaw Lets Attackers Push Code to Private Repos</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/gitlab-email-feature-vulnerability/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>SharePoint Vulnerability Enables Remote Code Execution</title>
		<link>https://firsthackersnews.com/microsoft-sharepoint-remote-code-execution/</link>
					<comments>https://firsthackersnews.com/microsoft-sharepoint-remote-code-execution/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 13:54:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[CVE-2026-65660]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[microsoft security]]></category>
		<category><![CDATA[rce]]></category>
		<category><![CDATA[remote code execution]]></category>
		<category><![CDATA[sharepoint]]></category>
		<category><![CDATA[SharePoint Vulnerability]]></category>
		<category><![CDATA[Zero-day]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12445</guid>

					<description><![CDATA[<p>Microsoft has disclosed a high-severity security flaw in its on-premises SharePoint Server products that could allow an authenticated</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-sharepoint-remote-code-execution/">SharePoint Vulnerability Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Microsoft has disclosed a high-severity security flaw in its on-premises SharePoint Server products that could allow an authenticated attacker with low-level access to execute malicious code remotely.</p>



<p>The vulnerability is tracked as <strong>CVE-2026-65660</strong> and has a <strong>CVSS score of 8.8</strong>. It affects <strong>SharePoint Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition</strong>.</p>



<p>Since SharePoint environments can contain sensitive company documents and operate with powerful service accounts, a successful attack could potentially lead to credential theft, data theft, movement across the network, or continued access.</p>



<h2 class="wp-block-heading"><strong>A Problem With SharePoint Security Checks</strong></h2>



<p>The vulnerability was discovered by <strong>Dinh Ho Anh Khoa from Viettel Cyber Security</strong>.</p>



<p>The issue involves SharePoint&#8217;s <strong>SafeControls protection</strong>, which is designed to prevent potentially unsafe server-side classes from being loaded while processing Web Part and page content.</p>



<p>The problem occurs when the <strong>ToolPane</strong> component handles specially crafted Register directives. An attacker can manipulate the way certain values are reconstructed, potentially changing the directive after SharePoint has already performed its security validation.</p>



<p>This can allow dangerous .NET classes to be registered and used as part of a code-execution chain.</p>



<p>The research demonstrated an attack chain involving <strong>XamlServices.Parse(), ExpandedWrapper, ObjectDataProvider, and LosFormatter</strong>.</p>



<p>The technique can also create an <strong>in-memory webshell</strong>, meaning an attacker may not need to leave a traditional webshell file on the server.</p>



<h2 class="wp-block-heading"><strong>What Organizations Should Do</strong></h2>



<p>Microsoft released fixes for the vulnerability on <strong>August 11, 2026</strong>.</p>



<p>The affected SharePoint builds mentioned in the provided advisory are:</p>



<ul class="wp-block-list">
<li><strong>SharePoint 2016:</strong> 16.0.5565.1001</li>



<li><strong>SharePoint 2019:</strong> 16.0.10417.20198</li>



<li><strong>SharePoint Subscription Edition:</strong> 16.0.19725.20522</li>
</ul>



<p>Microsoft requires organizations to install all applicable update packages. SharePoint 2016 administrators may need to install both listed packages.</p>



<p>The research also points to a possible connection with an authentication weakness in ToolPane. Under certain configurations that allowed anonymous access, the vulnerabilities could potentially be chained to achieve pre-authentication remote code execution. The provided information says Microsoft addressed that anonymous-access route in its June 9, 2026 update.</p>



<p>Security teams should patch affected SharePoint servers, reduce unnecessary anonymous or internet-facing access, and review activity for suspicious Web Part requests.</p>



<p>During an investigation, teams should also examine <strong>IIS logs, ULS logs, Windows events, PowerShell activity, endpoint telemetry, unexpected processes, unusual assemblies, and memory activity</strong>.</p>



<p>SharePoint 2013 was also reportedly affected by the underlying technique, but that version reached end of support in 2023. Organizations still running it should consider migration or isolation rather than relying on a future security update.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/microsoft-sharepoint-remote-code-execution/">SharePoint Vulnerability Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/microsoft-sharepoint-remote-code-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Active Attacks Target Check Point 0-Day</title>
		<link>https://firsthackersnews.com/check-point-management-server-zero-day/</link>
					<comments>https://firsthackersnews.com/check-point-management-server-zero-day/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 22 Sep 2026 12:41:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Vulnerability Research]]></category>
		<category><![CDATA[Zero Day Attack]]></category>
		<category><![CDATA[check point]]></category>
		<category><![CDATA[Check Point Zero-Day]]></category>
		<category><![CDATA[CVE-2026-93616]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Network Security]]></category>
		<category><![CDATA[Security Management Server]]></category>
		<category><![CDATA[Zero-day]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12441</guid>

					<description><![CDATA[<p>Check Point has released emergency security updates for a critical zero-day vulnerability affecting its Security Management products. The</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-management-server-zero-day/">Active Attacks Target Check Point 0-Day</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Check Point has released emergency security updates for a <strong>critical zero-day vulnerability</strong> affecting its Security Management products. The flaw, tracked as <strong>CVE-2026-93616</strong>, has a <strong>CVSS score of 9.8</strong> and is already being exploited in targeted attacks, according to Check Point.</p>



<p>The vulnerability is particularly concerning because it can be exploited <strong>without authentication</strong>. An attacker who reaches a vulnerable Management Server may be able to upload and execute malicious scripts and load arbitrary Java classes.</p>



<p>Since these systems are used to manage security policies and collect information across enterprise networks, a successful compromise could give an attacker access to a highly privileged part of the security environment.</p>



<h2 class="wp-block-heading">How the Zero-Day Works</h2>



<p>CVE-2026-93616 involves a combination of <strong>directory traversal and unsafe file-upload behavior</strong> in the Check Point Management web service.</p>



<p>An attacker can manipulate file paths to make the service access files from unintended locations. According to Check Point, the vulnerability can also allow an attacker to load an arbitrary Java class without first logging in.</p>



<p>Check Point said it has observed a small number of targeted attacks. The company reported that the activity began before the vulnerability was publicly disclosed, which is why it is classified as a zero-day. The vendor has not publicly identified the attackers or disclosed the full objectives of the observed attacks.</p>



<p>Affected products include <strong>Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server and SmartEvent</strong>.</p>



<h2 class="wp-block-heading">Which Versions Are Affected?</h2>



<p>Check Point lists several affected releases, including older and currently supported versions. Administrators should check their exact release and Jumbo Hotfix level against the vendor&#8217;s advisory before deciding whether their systems are vulnerable.</p>



<p>Check Point says the fix is included in:</p>



<ul class="wp-block-list">
<li><strong>R82.10 Take 45</strong></li>



<li><strong>R82 Take 127</strong></li>



<li><strong>R81.20 Take 170</strong></li>



<li><strong>R81.10 Take 192</strong></li>
</ul>



<p>The company has also released an <strong>R82.20 Security Hotfix</strong>. Smart-1 Cloud is not affected because the required fix has already been applied.</p>



<h2 class="wp-block-heading">What Security Teams Should Do</h2>



<p>Organizations running affected Check Point Management products should prioritize applying the appropriate security update.</p>



<p>Until systems can be patched, Check Point recommends keeping Management Servers behind a Security Gateway or firewall and restricting <strong>TCP port 19009</strong> to trusted IP addresses. Trusted Clients configured in SmartConsole should also be limited to known internal addresses.</p>



<p>Security teams should also review logs for signs of exploitation rather than checking only internet-facing systems. Check Point provides indicators and investigation guidance that can help identify suspicious activity.</p>



<p>If a vulnerable Management Server shows signs of compromise, teams should preserve relevant logs and forensic data, investigate activity that occurred after the initial access, and contact Check Point Support.</p>



<p>The active exploitation of this vulnerability shows why <strong>management infrastructure deserves the same patching priority as internet-facing security appliances</strong>. A compromised management server can potentially provide an attacker with access to a central administrative layer of an organization&#8217;s security environment.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-management-server-zero-day/">Active Attacks Target Check Point 0-Day</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/check-point-management-server-zero-day/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Chrome 153 Fixes 16 Security Vulnerabilities</title>
		<link>https://firsthackersnews.com/chrome-153-security-vulnerabilities/</link>
					<comments>https://firsthackersnews.com/chrome-153-security-vulnerabilities/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 22:52:54 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[Browser Security]]></category>
		<category><![CDATA[Browser Vulnerabilities]]></category>
		<category><![CDATA[Chrome 153]]></category>
		<category><![CDATA[Chrome 153 Security Vulnerabilities]]></category>
		<category><![CDATA[Chrome Security Flaws]]></category>
		<category><![CDATA[Chrome Security Update]]></category>
		<category><![CDATA[Chrome vulnerabilities]]></category>
		<category><![CDATA[CVE-2026-93372]]></category>
		<category><![CDATA[CVE-2026-93374]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[Dawn Vulnerability]]></category>
		<category><![CDATA[google chrome]]></category>
		<category><![CDATA[Google Chrome Security]]></category>
		<category><![CDATA[WebGL Vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12425</guid>

					<description><![CDATA[<p>Google has released Chrome 153 for Windows, macOS, and Linux, fixing 16 security vulnerabilities, including two critical memory-safety</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/chrome-153-security-vulnerabilities/">Chrome 153 Fixes 16 Security Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Google has released <strong>Chrome 153</strong> for Windows, macOS, and Linux, fixing <strong>16 security vulnerabilities</strong>, including two critical memory-safety bugs affecting Dawn and WebGL.</p>



<p>The new versions are:</p>



<ul class="wp-block-list">
<li><strong>Windows:</strong> 153.0.8010.52/.53</li>



<li><strong>macOS:</strong> 153.0.8010.52/.53</li>



<li><strong>Linux:</strong> 153.0.8010.52</li>
</ul>



<p>The two most serious vulnerabilities affect Chrome&#8217;s graphics technologies and could potentially allow malicious web content to cause memory corruption.</p>



<h2 class="wp-block-heading"><strong>Critical Dawn and WebGL Vulnerabilities</strong></h2>



<p>The most serious issue is <strong>CVE-2026-93374</strong>, a critical use-after-free vulnerability in <strong>Dawn</strong>, Chrome&#8217;s implementation of the WebGPU graphics API.</p>



<p>A use-after-free occurs when software continues to access memory after that memory has already been released. In a browser, successful exploitation could potentially cause crashes, memory corruption, or arbitrary code execution through a specially crafted website or web application.</p>



<p>Security researcher Florian Schweitzer reported the Dawn vulnerability to Google on April 8, 2026. Google has not disclosed the reward associated with the report.</p>



<p>Chrome 153 also fixes <strong>CVE-2026-93372</strong>, a critical buffer overflow in <strong>WebGL</strong>. WebGL allows websites to display interactive 2D and 3D graphics directly in the browser.</p>



<p>A buffer overflow happens when a program writes more data into a memory area than it was designed to hold. An attacker could potentially use this to overwrite nearby memory and influence program execution.</p>



<p>Google&#8217;s internal security team reported the WebGL vulnerability on August 17, 2026.</p>



<p>Google has not published detailed technical information about either critical flaw. Keeping those details private gives users and organizations time to install the security update before information that could assist exploitation becomes widely available.</p>



<h2 class="wp-block-heading"><strong>High-Severity Chrome Bugs</strong></h2>



<p>Chrome 153 also addresses <strong>eight high-severity vulnerabilities</strong> across several browser components.</p>



<p>The high-severity issues include:</p>



<ul class="wp-block-list">
<li><strong>CVE-2026-93375</strong> — Incorrect reference resolution in Tracing</li>



<li><strong>CVE-2026-93382</strong> — Use-after-free in PDFium</li>



<li><strong>CVE-2026-93387</strong> — Improper state validation in Skia</li>



<li><strong>CVE-2026-93373</strong> — Use-after-free in Extensions</li>



<li><strong>CVE-2026-93381</strong> — Buffer overflow in PDFium</li>



<li><strong>CVE-2026-93379</strong> — Authorization flaw in ORB</li>



<li><strong>CVE-2026-93377</strong> — Type confusion in V8</li>
</ul>



<p>The V8 issue is particularly important because V8 is Chrome&#8217;s JavaScript engine and processes code from websites.</p>



<p>A type confusion vulnerability can cause the browser to incorrectly treat one type of object as another. Under the right conditions, this can lead to memory corruption and potentially become part of a larger browser exploitation chain.</p>



<h2 class="wp-block-heading"><strong>Medium and Low-Severity Fixes</strong></h2>



<p>The remaining vulnerabilities affect several other Chrome components.</p>



<p>These include:</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><tbody><tr><th>CVE</th><th>Severity</th><th>Vulnerability</th><th>Component</th></tr><tr><td>CVE-2026-93380</td><td>Medium</td><td>Race condition</td><td>FileSystem</td></tr><tr><td>CVE-2026-93384</td><td>Medium</td><td>SSRF</td><td>Omnibox</td></tr><tr><td>CVE-2026-93383</td><td>Medium</td><td>Information leak</td><td>Permissions</td></tr><tr><td>CVE-2026-93376</td><td>Medium</td><td>Out-of-bounds read</td><td>DataTransfer</td></tr><tr><td>CVE-2026-93378</td><td>Medium</td><td>Authorization flaw</td><td>Storage</td></tr><tr><td>CVE-2026-93385</td><td>Medium</td><td>Information leak</td><td>Paint</td></tr><tr><td>CVE-2026-93386</td><td>Low</td><td>UI spoofing</td><td>WebAppInstalls</td></tr></tbody></table></figure>



<p>These bugs include race conditions, server-side request forgery, information disclosure, out-of-bounds memory reads, authorization weaknesses, and a user-interface spoofing issue.</p>



<p>Google said it will continue restricting technical details and related links until a large portion of Chrome users have installed the update. Some information may also remain restricted when affected third-party libraries are used by other projects that have not yet released their own fixes.</p>



<h2 class="wp-block-heading"><strong>Update Chrome Now</strong></h2>



<p>Users should update Chrome as soon as possible.</p>



<p>To manually check for the update:</p>



<ol start="1" class="wp-block-list">
<li>Open Chrome.</li>



<li>Select the <strong>three-dot menu</strong>.</li>



<li>Go to <strong>Help → About Google Chrome</strong>.</li>



<li>Allow Chrome to download and install the update.</li>



<li>Restart the browser when prompted.</li>
</ol>



<p>Chrome normally updates automatically, but the browser must be restarted before a downloaded security update becomes active.</p>



<p>For organizations, deploying the update across managed endpoints should be a priority. Browser vulnerabilities can be triggered during everyday activities such as visiting malicious websites, opening phishing pages, viewing compromised legitimate websites, or encountering malicious advertising.</p>



<p>Keeping browsers fully patched is therefore an important part of endpoint security and helps reduce the opportunity for attackers to turn a simple web visit into a security incident.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/chrome-153-security-vulnerabilities/">Chrome 153 Fixes 16 Security Vulnerabilities</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/chrome-153-security-vulnerabilities/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Four Linux Kernel Flaws Could Enable Root Access</title>
		<link>https://firsthackersnews.com/linux-kernel-flaws-root-access/</link>
					<comments>https://firsthackersnews.com/linux-kernel-flaws-root-access/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 12:31:00 +0000</pubDate>
				<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Linux Malware]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[kernel security]]></category>
		<category><![CDATA[linux kernel]]></category>
		<category><![CDATA[Linux security]]></category>
		<category><![CDATA[privilege escalation]]></category>
		<category><![CDATA[root access]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[threat research]]></category>
		<category><![CDATA[vulnerabilities]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12416</guid>

					<description><![CDATA[<p>Four recently disclosed vulnerabilities in the Linux kernel could allow local attackers to corrupt kernel memory and potentially</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/linux-kernel-flaws-root-access/">Four Linux Kernel Flaws Could Enable Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Four recently disclosed vulnerabilities in the Linux kernel could allow local attackers to corrupt kernel memory and potentially gain root-level privileges on vulnerable systems.</p>



<p>The flaws affect several networking components that have been part of the Linux kernel for years. They are known as <strong>DirtyAH6, TUNderflow, PPPoEject, and DiagSpill</strong> and are tracked as:</p>



<ul class="wp-block-list">
<li><strong>CVE-2026-80844 — DirtyAH6</strong></li>



<li><strong>CVE-2026-81000 — TUNderflow</strong></li>



<li><strong>CVE-2026-68121 — PPPoEject</strong></li>



<li><strong>CVE-2026-74469 — DiagSpill</strong></li>
</ul>



<p>Upstream fixes are now available for the affected kernel code.</p>



<h2 class="wp-block-heading"><strong>DirtyAH6: IPv6 Memory Handling Bug</strong></h2>



<p>DirtyAH6 affects Linux IPsec/XFRM code responsible for processing IPv6 Authentication Headers.</p>



<p>The problem occurs when specially crafted IPv6 routing-header values are processed without properly checking the <code>segments_left</code> field. This can cause the kernel to use an invalid memory location and perform an out-of-bounds operation.</p>



<p>The main concern is <strong>local privilege escalation</strong>, particularly on systems where an attacker can create or control network namespaces.</p>



<p>In certain configurations, IPv6 routers or gateways using Authentication Header transport mode could also face a denial-of-service condition.</p>



<p>Researchers demonstrated root access in a controlled laboratory environment, although carrying out the same technique remotely was described as difficult.</p>



<h2 class="wp-block-heading"><strong>TUNderflow Targets Virtual Networking</strong></h2>



<p>TUNderflow affects the Linux <strong>TUN/TAP virtual networking subsystem</strong>.</p>



<p>A local attacker can potentially provide unusually large receive-headroom values through certain network-device configurations, including paths involving Open vSwitch.</p>



<p>This can trigger an integer underflow while the kernel allocates a socket buffer. As a result, packet data may be placed outside the expected memory area, creating opportunities for out-of-bounds reads and writes.</p>



<h2 class="wp-block-heading"><strong>PPPoEject Creates a Use-After-Free</strong></h2>



<p>PPPoEject affects Linux&#8217;s PPP-over-Ethernet implementation.</p>



<p>The vulnerability occurs because <code>pppoe_sendmsg()</code> can retain a pointer to a PPPoE header while another function modifies the underlying socket buffer.</p>



<p>If that buffer is reallocated, the original pointer becomes invalid. Subsequent operations using the stale pointer can then modify memory that has already been freed.</p>



<p>The upstream fix addresses the issue by retrieving the header pointer again after the device-header operation completes.</p>



<h2 class="wp-block-heading"><strong>DiagSpill Can Corrupt Kernel Memory</strong></h2>



<p>DiagSpill affects SCTP diagnostic processing through <code>sock_diag</code>.</p>



<p>The vulnerability is related to a mismatch between the maximum number of SCTP peer transports and the size of the counter used to track them.</p>



<p>When the counter reaches its limit, it can wrap around to zero. The kernel may then allocate too little space before copying peer information, potentially causing data to be written beyond the allocated Netlink response buffer.</p>



<p>Unlike the other three vulnerabilities, DiagSpill does not require unprivileged user namespaces or special capabilities when SCTP and <code>sctp_diag</code> are enabled.</p>



<p>Remote crash scenarios may also be possible when certain SCTP address-configuration features are active, although those features are disabled by default.</p>



<h2 class="wp-block-heading"><strong>Linux Kernel Updates Available</strong></h2>



<p>The vulnerabilities were reported to the Linux kernel security team in July, and fixes have now been released through the coordinated disclosure process.</p>



<p>The stable kernel releases containing fixes for all four vulnerabilities include:</p>



<ul class="wp-block-list">
<li>Linux 5.10.270</li>



<li>Linux 5.15.221</li>



<li>Linux 6.1.188</li>



<li>Linux 6.6.157</li>



<li>Linux 6.12.109</li>



<li>Linux 6.18.50</li>



<li>Linux 7.2.4</li>
</ul>



<p>Administrators should update affected systems to a kernel version containing the fixes.</p>



<p>If an immediate update is not possible, organizations can reduce exposure by restricting unprivileged user namespaces and disabling networking features that are not required, such as AH6, TUN/TAP, PPPoE, SCTP, or <code>sctp_diag</code>.</p>



<p>These workarounds provide only partial protection. In particular, disabling user namespaces does <strong>not</strong> prevent DiagSpill, so applying the appropriate kernel security updates remains the primary mitigation.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/linux-kernel-flaws-root-access/">Four Linux Kernel Flaws Could Enable Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/linux-kernel-flaws-root-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Check Point Vulnerability Allows Remote Root Access</title>
		<link>https://firsthackersnews.com/check-point-unauthenticated-root-access/</link>
					<comments>https://firsthackersnews.com/check-point-unauthenticated-root-access/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 13:47:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity News]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=12385</guid>

					<description><![CDATA[<p>Check Point has issued an urgent security update for CVE-2026-91843, a critical buffer overflow vulnerability that could allow</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-unauthenticated-root-access/">Check Point Vulnerability Allows Remote Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Check Point has issued an urgent security update for <strong>CVE-2026-91843</strong>, a critical buffer overflow vulnerability that could allow a remote attacker to run code with <strong>root-level privileges without logging in</strong>.</p>



<p>The vulnerability has a <strong>CVSS score of 9.8</strong>, making it a high-priority issue. It can be exploited remotely without user interaction or existing privileges.</p>



<p>The problem occurs during the login process. An attacker can submit an unusually long username, causing a stack overflow before authentication is completed.</p>



<p>If successfully exploited, the attacker could gain complete control of the affected system and potentially access management information, security policies, administrator details, and stored logs.</p>



<h2 class="wp-block-heading"><strong>Affected Check Point Products</strong></h2>



<p>The vulnerability affects several Check Point management and logging products, including:</p>



<ul class="wp-block-list">
<li>Security Management Server</li>



<li>Multi-Domain Security Management Server</li>



<li>Log Server</li>



<li>Multi-Domain Log Server</li>
</ul>



<p>Affected releases include <strong>R82.20</strong>, older builds of R82.10, R82, R81.20, and unsupported R81.10, R80, R80.40, and R81 versions.</p>



<p>Check Point says <strong>Smart-1 Cloud is not affected</strong>, as the fix has already been applied to that environment.</p>



<p>Check Point has not reported active exploitation or publicly disclosed technical details of an exploit.</p>



<h2 class="wp-block-heading"><strong>What Security Teams Should Do</strong></h2>



<p>Organizations should treat this vulnerability as an urgent patching priority.</p>



<p>Security teams should check SmartConsole Audit and Admin login records for:</p>



<p><strong>“Administrator failed to log in: Username too long.”</strong></p>



<p>This could indicate an attempted exploit, but the surrounding activity should be reviewed before confirming compromise.</p>



<p>Check Point has distributed the fix through <strong>Check Point LivePatch</strong>. Organizations using automatic security updates should still verify that the patch is active on every affected management and logging server.</p>



<p>Administrators can check the LivePatch status from Expert mode using:</p>



<p><code>cplp list</code></p>



<p>The affected systems should show the <strong>fwm</strong> patch as armed and running in livepatch mode, with CVE-2026-91843 listed in the patch details.</p>



<p>Until patching is confirmed, organizations should also limit SmartConsole Trusted Clients to known and approved IP addresses or subnets.</p>



<p>Because this vulnerability can provide <strong>root access without authentication</strong>, organizations should prioritize exposed and unsupported Check Point management systems and move to supported releases as part of remediation.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/check-point-unauthenticated-root-access/">Check Point Vulnerability Allows Remote Root Access</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/check-point-unauthenticated-root-access/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
