<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>vulnerability &#8211; First Hackers News</title>
	<atom:link href="https://firsthackersnews.com/category/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>https://firsthackersnews.com</link>
	<description>Latest cybersecurity news, real attacks, and practical IOCs—made simple and actionable.</description>
	<lastBuildDate>Tue, 02 Jun 2026 20:00:55 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://firsthackersnews.com/wp-content/uploads/2026/03/cropped-FHN_512x512-32x32.png</url>
	<title>vulnerability &#8211; First Hackers News</title>
	<link>https://firsthackersnews.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Meta AI Flaw Linked to Instagram Password Resets</title>
		<link>https://firsthackersnews.com/meta-ai-vulnerability-instagram/</link>
					<comments>https://firsthackersnews.com/meta-ai-vulnerability-instagram/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 22:10:42 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#AccountTakeover]]></category>
		<category><![CDATA[#AISecurity]]></category>
		<category><![CDATA[#ArtificialIntelligence]]></category>
		<category><![CDATA[#CyberNews]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreats]]></category>
		<category><![CDATA[#datasecurity]]></category>
		<category><![CDATA[#DigitalSecurity]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#Instagram]]></category>
		<category><![CDATA[#InstagramSecurity]]></category>
		<category><![CDATA[#MetaAI]]></category>
		<category><![CDATA[#OnlineSafety]]></category>
		<category><![CDATA[#PasswordReset]]></category>
		<category><![CDATA[#privacy]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#SocialMediaSecurity]]></category>
		<category><![CDATA[#TechnologyNews]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11778</guid>

					<description><![CDATA[<p>A recently disclosed issue involving Meta’s AI-powered support system has raised concerns about the security of Instagram accounts.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/meta-ai-vulnerability-instagram/">Meta AI Flaw Linked to Instagram Password Resets</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A recently disclosed issue involving Meta’s AI-powered support system has raised concerns about the security of Instagram accounts. Researchers claim that attackers were able to abuse the platform’s account recovery process to request password reset codes without properly verifying ownership of the targeted account.</p>



<p>While Meta stated that its infrastructure was not breached, the incident highlights the risks of relying on AI systems for sensitive account management functions.</p>



<h2 class="wp-block-heading">How the Issue Worked</h2>



<p>The problem was reportedly linked to the logic used by Meta&#8217;s AI support assistant. Instead of exploiting servers or software vulnerabilities, attackers allegedly manipulated the chatbot into triggering password recovery actions.</p>



<p>According to researchers, the AI system could be persuaded to send password reset links or codes without performing sufficient identity checks. In some cases, simply knowing a target&#8217;s Instagram username may have been enough to initiate the process.</p>



<p>This type of attack is different from traditional hacking methods because it focuses on exploiting the behavior of automated systems rather than technical flaws in infrastructure.</p>



<p>Researchers noted that the issue demonstrated how AI tools can become vulnerable when strict authentication controls and security safeguards are not fully enforced.</p>



<h2 class="wp-block-heading">Valuable Instagram Accounts Were Targeted</h2>



<p>Reports indicate that attackers focused primarily on high-value Instagram usernames and accounts that are often traded in underground marketplaces.</p>



<p>Short, rare, and highly desirable usernames can sell for significant amounts of money, making them attractive targets for cybercriminals.</p>



<p>Security researchers found evidence suggesting that compromised accounts were quickly offered for sale through private online channels, highlighting the growing business of account takeover operations.</p>



<p>This trend reflects an evolving cybercrime ecosystem where attackers target digital identities that can be rapidly monetized.</p>



<h2 class="wp-block-heading">Meta Responds and Fixes the Issue</h2>



<p>Meta has confirmed that the problem has been addressed and stated that user accounts remain secure.</p>



<p>According to the company, the issue allowed certain password reset requests to be triggered improperly, but there was no compromise of Meta&#8217;s backend systems or customer databases.</p>



<p>The company quickly implemented a fix after receiving reports from researchers and emphasized that the vulnerability has been resolved.</p>



<h2 class="wp-block-heading">Lessons for Users and Platforms</h2>



<p>The incident serves as a reminder that AI-powered support tools can introduce new security challenges if they are not carefully designed.</p>



<p>To reduce risk, organizations should implement:</p>



<ul class="wp-block-list">
<li>Strong identity verification controls</li>



<li>Strict rate-limiting mechanisms</li>



<li>Context-aware AI decision making</li>



<li>Enhanced monitoring for abuse attempts</li>



<li>Additional safeguards for account recovery processes</li>
</ul>



<p>Researchers also noted that accounts protected with two-factor authentication (2FA) were not affected by the reported attacks.</p>



<p>As AI becomes more integrated into customer support and account management systems, security experts expect attackers to continue testing these technologies for weaknesses. Strong authentication and layered security controls remain essential for protecting user accounts from emerging threats.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/meta-ai-vulnerability-instagram/">Meta AI Flaw Linked to Instagram Password Resets</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/meta-ai-vulnerability-instagram/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Magento Cache Plugin Vulnerability Enables RCE Attacks</title>
		<link>https://firsthackersnews.com/magento-cache-plugin-vulnerability-rce/</link>
					<comments>https://firsthackersnews.com/magento-cache-plugin-vulnerability-rce/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 01 Jun 2026 13:55:00 +0000</pubDate>
				<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[cyberattack]]></category>
		<category><![CDATA[Cybercriminals]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#AdobeCommerce]]></category>
		<category><![CDATA[#ApplicationSecurity]]></category>
		<category><![CDATA[#CVE202645247]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreats]]></category>
		<category><![CDATA[#datasecurity]]></category>
		<category><![CDATA[#eCommerceSecurity]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#Magento]]></category>
		<category><![CDATA[#MagentoSecurity]]></category>
		<category><![CDATA[#PatchManagement]]></category>
		<category><![CDATA[#RCE]]></category>
		<category><![CDATA[#RemoteCodeExecution]]></category>
		<category><![CDATA[#SecurityFlaw]]></category>
		<category><![CDATA[#SecurityNews]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#Vulnerability]]></category>
		<category><![CDATA[#WebSecurity]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11770</guid>

					<description><![CDATA[<p>A newly disclosed security vulnerability in a popular Magento caching extension could allow attackers to take complete control</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/magento-cache-plugin-vulnerability-rce/">Magento Cache Plugin Vulnerability Enables RCE Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly disclosed security vulnerability in a popular Magento caching extension could allow attackers to take complete control of affected online stores.</p>



<p>The flaw, tracked as <strong>CVE-2026-45247</strong>, has received a critical severity rating and can be exploited without authentication. Security researchers warn that thousands of Magento and Adobe Commerce stores may be at risk if the vulnerable plugin remains unpatched.</p>



<p>The issue affects the Mirasvit Cache Warmer extension, a tool commonly used to improve website performance by preloading cached pages for visitors.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>The vulnerability is caused by the plugin&#8217;s unsafe handling of data stored inside a cookie called <code>CacheWarmer</code>.</p>



<p>When a visitor sends a request to the website, the extension reads information from the cookie and rebuilds session data using PHP&#8217;s <code>unserialize()</code> function. Because the cookie data is controlled by the user and is not properly validated, attackers can supply specially crafted payloads that trigger malicious object creation on the server.</p>



<p>Researchers found that this behavior opens the door to PHP Object Injection attacks, which can eventually lead to remote code execution.</p>



<p>An attacker can potentially:</p>



<ul class="wp-block-list">
<li>Execute malicious code on the server</li>



<li>Install webshells or backdoors</li>



<li>Access sensitive store data</li>



<li>Take control of the Magento environment</li>



<li>Launch automated attacks against multiple stores</li>
</ul>



<p>The vulnerability affects all Mirasvit Cache Warmer versions released before <strong>1.11.12</strong>.</p>



<h2 class="wp-block-heading"><strong>Thousands of Stores Potentially Affected</strong></h2>



<p>According to researchers, the extension is frequently bundled with other Mirasvit products, meaning some store owners may not even realize it is installed on their systems.</p>



<p>Security experts estimate that more than 6,000 Magento stores may be running vulnerable components, although the actual number could be higher.</p>



<p>The vendor was notified about the issue and quickly released version <strong>1.11.12</strong>, which addresses the vulnerability.</p>



<p>Security teams should monitor web traffic for suspicious <code>CacheWarmer</code> cookie values containing unusual encoded data. Such activity could indicate attempted exploitation.</p>



<h2 class="wp-block-heading"><strong>Recommended Actions</strong></h2>



<p>Organizations using Magento or Adobe Commerce should act immediately to reduce risk.</p>



<p>Recommended steps include:</p>



<ul class="wp-block-list">
<li>Upgrade Mirasvit Cache Warmer to version 1.11.12 or later</li>



<li>Review web server logs for suspicious requests</li>



<li>Scan systems for webshells and backdoors</li>



<li>Inspect public-facing directories for unauthorized PHP files</li>



<li>Deploy a web application firewall for additional protection</li>



<li>Conduct a full compromise assessment if exploitation is suspected</li>
</ul>



<p>Because the flaw can be exploited remotely without authentication, researchers expect attack attempts to increase following public disclosure.</p>



<p>Store administrators are strongly encouraged to patch affected systems as soon as possible to prevent potential compromise and data theft.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/magento-cache-plugin-vulnerability-rce/">Magento Cache Plugin Vulnerability Enables RCE Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/magento-cache-plugin-vulnerability-rce/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Angular Language Service Vulnerabilities Enable RCE Attacks</title>
		<link>https://firsthackersnews.com/angular-language-service-vulnerabilities-enable-rce-attacks/</link>
					<comments>https://firsthackersnews.com/angular-language-service-vulnerabilities-enable-rce-attacks/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Tue, 26 May 2026 21:20:22 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[RCE Flaw]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#Angular]]></category>
		<category><![CDATA[#AngularLanguageService]]></category>
		<category><![CDATA[#CodeSecurity]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#DeveloperSecurity]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#JavaScript]]></category>
		<category><![CDATA[#OpenSourceSecurity]]></category>
		<category><![CDATA[#RCE]]></category>
		<category><![CDATA[#RemoteCodeExecution]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#TypeScript]]></category>
		<category><![CDATA[#VSCode]]></category>
		<category><![CDATA[#Vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11753</guid>

					<description><![CDATA[<p>Angular Language Service Vulnerabilities have exposed developers to serious remote code execution risks through malicious VS Code projects</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/angular-language-service-vulnerabilities-enable-rce-attacks/">Angular Language Service Vulnerabilities Enable RCE Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Angular Language Service Vulnerabilities have exposed developers to serious remote code execution risks through malicious VS Code projects and unsafe extension behavior.</p>



<p>The issues affect the <code>Angular.ng-template</code> extension and stem from unsafe handling of user-controlled input and insecure loading of configuration files. Researchers warned that simply opening a malicious project in VS Code could be enough to trigger an attack.</p>



<p>The vulnerabilities mainly target developers working with Angular projects and could lead to full system compromise if exploited successfully.</p>



<h2 class="wp-block-heading"><strong>Malicious JSDoc Comments Can Trigger Command Execution</strong></h2>



<p>One of the vulnerabilities involves the way the extension processes JSDoc comments inside TypeScript and JavaScript files.</p>



<p>Researchers found that the extension enables trusted Markdown rendering, allowing embedded command links to run inside hover previews. Because the Angular language server does not properly sanitize JSDoc content, attackers can insert malicious command URIs into project files.</p>



<p>In a possible attack scenario:</p>



<ul class="wp-block-list">
<li>An attacker adds a malicious JSDoc comment to a project</li>



<li>The developer opens the file in VS Code</li>



<li>Hovering over the affected symbol displays the malicious link</li>



<li>Clicking the link executes commands on the host system</li>
</ul>



<p>This creates a practical path for remote code execution through normal development workflows.</p>



<h2 class="wp-block-heading"><strong>Workspace Configuration Flaw Allows Silent Code Execution</strong></h2>



<p>A second vulnerability affects how the extension handles the TypeScript SDK (<code>tsdk</code>) configuration.</p>



<p>The extension reads settings directly from the project’s <code>.vscode/settings.json</code> file and loads the specified <code>tsserverlibrary.js</code> file without properly checking workspace trust or requesting user approval.</p>



<p>Attackers can abuse this behavior by:</p>



<ul class="wp-block-list">
<li>Placing a malicious <code>tsserverlibrary.js</code> file inside the repository</li>



<li>Modifying workspace settings to reference the file</li>



<li>Triggering automatic execution when the project is opened</li>
</ul>



<p>Unlike the JSDoc attack, this method requires no user interaction and can run silently during extension initialization.</p>



<p>Researchers noted that this behavior effectively bypasses VS Code’s Workspace Trust protections, which are intended to prevent untrusted projects from executing code automatically.</p>



<h2 class="wp-block-heading"><strong>High Risk for Developers</strong></h2>



<p>Successful exploitation could allow attackers to:</p>



<ul class="wp-block-list">
<li>Execute arbitrary system commands</li>



<li>Access sensitive development data</li>



<li>Install persistent malware</li>



<li>Compromise developer environments</li>
</ul>



<p>A developer cloning and opening a malicious repository could unknowingly trigger the attack immediately after loading the project in VS Code.</p>



<p>The vulnerabilities were disclosed under GitHub advisory <code>GHSA-ccq4-xmxr-8hcq</code> and impact all extension versions before <code>21.2.4</code>.</p>



<p>The issues have now been fixed in the latest release, and developers are strongly advised to upgrade immediately.</p>



<h2 class="wp-block-heading"><strong>Security Recommendations</strong></h2>



<p>To reduce risk, developers should:</p>



<ul class="wp-block-list">
<li>Update Angular Language Service to version <code>21.2.4</code> or later</li>



<li>Avoid opening untrusted repositories</li>



<li>Carefully review <code>.vscode/settings.json</code> files</li>



<li>Use VS Code Workspace Trust features</li>



<li>Monitor suspicious extension behavior</li>



<li>Follow secure coding and repository validation practices</li>
</ul>



<p>The findings highlight growing security risks targeting software development environments and trusted developer tools.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/angular-language-service-vulnerabilities-enable-rce-attacks/">Angular Language Service Vulnerabilities Enable RCE Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/angular-language-service-vulnerabilities-enable-rce-attacks/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Apache OFBiz Vulnerability Enables Authentication Bypass</title>
		<link>https://firsthackersnews.com/apache-ofbiz-vulnerability-authentication-bypass/</link>
					<comments>https://firsthackersnews.com/apache-ofbiz-vulnerability-authentication-bypass/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 21 May 2026 22:43:31 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#apacheofbiz]]></category>
		<category><![CDATA[#apacheofbizvulnerability]]></category>
		<category><![CDATA[#apachevulnerability]]></category>
		<category><![CDATA[#ApplicationSecurity]]></category>
		<category><![CDATA[#AuthenticationBypass]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EnterpriseSecurity]]></category>
		<category><![CDATA[#erpsecurity]]></category>
		<category><![CDATA[#EthicalHacking]]></category>
		<category><![CDATA[#groovy]]></category>
		<category><![CDATA[#Hacking]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#ITSecurity]]></category>
		<category><![CDATA[#RCE]]></category>
		<category><![CDATA[#RemoteCodeExecution]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#ServerSecurity]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#VulnerabilityManagement]]></category>
		<category><![CDATA[#WebSecurity]]></category>
		<category><![CDATA[#ZeroTrust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11731</guid>

					<description><![CDATA[<p>An Apache OFBiz vulnerability tracked as CVE-2026-45434 could allow attackers to bypass authentication protections and execute malicious code</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apache-ofbiz-vulnerability-authentication-bypass/">Apache OFBiz Vulnerability Enables Authentication Bypass</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>An Apache OFBiz vulnerability tracked as CVE-2026-45434 could allow attackers to bypass authentication protections and execute malicious code on vulnerable servers through a crafted HTTP request. The flaw, tracked as CVE-2026-45434, affects all Apache OFBiz versions before 24.09.06 and carries a high CVSS score of 8.8.</p>



<p>Apache OFBiz is a widely used open-source ERP platform used to manage enterprise business operations and workflows. Researchers from Aretiq AI discovered that attackers could abuse the platform’s password-change mechanism to gain unauthorized access and execute malicious code on vulnerable servers.</p>



<h2 class="wp-block-heading">Authentication Bypass Through Password Reset Logic</h2>



<p>The issue originates from the way Apache OFBiz handles forced password-change workflows. Normally, accounts marked with <code>requirePasswordChange=Y</code> should remain restricted until the password reset process is completed.</p>



<p>However, researchers found that the <code>LoginWorker.checkLogin()</code> method incorrectly treats the <code>requirePasswordChange</code> response as a successful login instead of an authentication failure.</p>



<p>The vulnerability becomes more dangerous because the <code>requirePasswordChange</code> value is read directly from user-controlled HTTP request parameters rather than securely validated against database records.</p>



<p>By abusing this behavior, attackers can:</p>



<ul class="wp-block-list">
<li>Inject password-change parameters into a crafted HTTP request</li>



<li>Create an authenticated session without completing a proper login process</li>
</ul>



<p>Researchers also warned that many OFBiz deployments still contain default demo accounts such as <code>admin</code>, <code>flexadmin</code>, and <code>demoadmin</code>, often configured with default credentials like <code>ofbiz</code>.</p>



<h2 class="wp-block-heading">Remote Code Execution and Security Fixes</h2>



<p>The authentication bypass can be chained with another vulnerability affecting <code>ProgramExport.groovy</code>. In vulnerable versions, the component allows execution of user-supplied Groovy code without proper sandboxing or permission checks.</p>



<p>This allows attackers to execute arbitrary system commands directly on the server. Researchers successfully demonstrated remote code execution on OFBiz 24.09.05 using a single crafted POST request targeting <code>/webtools/control/ProgramExport</code>.</p>



<p>Successful exploitation could allow attackers to:</p>



<ul class="wp-block-list">
<li>Execute malicious commands on the server</li>



<li>Deploy malware or backdoors</li>
</ul>



<p>Apache fixed the issue in version 24.09.06 by removing unsafe password-change handling, adding stricter permission checks, and introducing a secure Groovy sandbox to block dangerous command execution patterns.</p>



<p>Organizations are strongly advised to upgrade immediately, remove default demo accounts, change weak credentials, and restrict access to sensitive OFBiz administrative endpoints.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apache-ofbiz-vulnerability-authentication-bypass/">Apache OFBiz Vulnerability Enables Authentication Bypass</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/apache-ofbiz-vulnerability-authentication-bypass/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ExifTool Flaw Allows Mac System Compromise</title>
		<link>https://firsthackersnews.com/exiftool-vulnerability-mac-compromise/</link>
					<comments>https://firsthackersnews.com/exiftool-vulnerability-mac-compromise/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 20 May 2026 01:30:00 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cyber threat]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[MacOS]]></category>
		<category><![CDATA[malicious cyber actors]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#AppleSecurity]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CommandInjection]]></category>
		<category><![CDATA[#cve20263102]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberDefense]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#CyberThreat]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EthicalHacking]]></category>
		<category><![CDATA[#exiftool]]></category>
		<category><![CDATA[#exiftoolvulnerability]]></category>
		<category><![CDATA[#Hacking]]></category>
		<category><![CDATA[#imageprocessing]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#ITSecurity]]></category>
		<category><![CDATA[#macOS]]></category>
		<category><![CDATA[#macOSSecurity]]></category>
		<category><![CDATA[#MacSecurity]]></category>
		<category><![CDATA[#Malware]]></category>
		<category><![CDATA[#metadatasecurity]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#VulnerabilityManagement]]></category>
		<category><![CDATA[#ZeroTrust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11727</guid>

					<description><![CDATA[<p>A newly discovered vulnerability in ExifTool could allow attackers to execute malicious commands on macOS systems through specially</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/exiftool-vulnerability-mac-compromise/">ExifTool Flaw Allows Mac System Compromise</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A newly discovered vulnerability in ExifTool could allow attackers to execute malicious commands on macOS systems through specially crafted image files. The ExifTool vulnerability, tracked as CVE-2026-3102, affects ExifTool versions 13.49 and earlier and raises serious concerns for organizations that process large volumes of media files.</p>



<p>ExifTool is widely used to read and modify metadata in images, PDFs, and multimedia files. Because the tool is heavily integrated into media workflows, automation pipelines, and digital asset management systems, the vulnerability creates a significant security risk in environments that handle untrusted files.</p>



<p>The implications of the ExifTool vulnerability extend to various sectors, where data integrity and security are paramount.</p>



<h2 class="wp-block-heading"><strong>How the Vulnerability Works</strong></h2>



<p>The issue is linked to improper sanitization of metadata fields related to file creation dates on macOS. Researchers found that attackers can embed malicious commands inside image metadata fields such as FileCreateDate or DateTimeOriginal.</p>



<p>When ExifTool processes the manipulated file under specific conditions, the hidden command can be executed through the system shell.</p>



<p>The vulnerability becomes exploitable when:</p>



<ul class="wp-block-list">
<li>ExifTool processes raw metadata values using the <code>-n</code> flag</li>



<li>Malicious metadata is copied through the <code>-tagsFromFile</code> feature</li>



<li>Unsafe input reaches a system() execution call without proper filtering</li>
</ul>



<p>Researchers observed that ExifTool internally builds system commands using metadata values extracted directly from files. While most parameters are sanitized, one execution path allowed unfiltered user-controlled data to be passed into a shell command.</p>



<p>This creates a command injection scenario where attackers can run arbitrary commands with the privileges of the user processing the file.</p>



<h2 class="wp-block-heading"><strong>Security Risks and Patch Information</strong></h2>



<p>The vulnerability is especially dangerous for organizations using automated image-processing workflows, newsroom environments, or media management platforms where files are processed automatically.</p>



<p>Because the malicious payload is hidden inside metadata, the image itself may appear legitimate and bypass traditional security checks.</p>



<p>If exploited successfully, attackers could:</p>



<ul class="wp-block-list">
<li>Execute malicious commands on macOS systems</li>



<li>Deploy malware or backdoors</li>



<li>Steal sensitive information</li>



<li>Move laterally across internal networks</li>
</ul>



<p>Researchers from Kaspersky identified the vulnerability, and ExifTool developers addressed the issue in version 13.50.</p>



<p>The patched release changes how system commands are executed by replacing unsafe string-based command construction with safer argument-based execution methods. This prevents shell interpretation and significantly reduces the risk of command injection.</p>



<p>Users and organizations are strongly advised to update to ExifTool 13.50 or later immediately. Security experts also recommend processing untrusted files inside isolated environments such as sandboxes or virtual machines to reduce exposure to malicious media files.</p>



<p>The incident highlights an ongoing cybersecurity challenge where even trusted file-processing tools can become attack vectors if user-controlled input is not handled securely.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/exiftool-vulnerability-mac-compromise/">ExifTool Flaw Allows Mac System Compromise</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/exiftool-vulnerability-mac-compromise/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>NGINX Vulnerability Enables Remote Code Execution</title>
		<link>https://firsthackersnews.com/nginx-vulnerability-rce/</link>
					<comments>https://firsthackersnews.com/nginx-vulnerability-rce/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Mon, 18 May 2026 18:27:20 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Remote code execution]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#datasecurity]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EthicalHacking]]></category>
		<category><![CDATA[#Hacking]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#ITSecurity]]></category>
		<category><![CDATA[#LinuxSecurity]]></category>
		<category><![CDATA[#nginx]]></category>
		<category><![CDATA[#nginxsecurity]]></category>
		<category><![CDATA[#nginxvulnerability]]></category>
		<category><![CDATA[#RCE]]></category>
		<category><![CDATA[#RemoteCodeExecution]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityFlaw]]></category>
		<category><![CDATA[#SecurityResearch]]></category>
		<category><![CDATA[#ServerSecurity]]></category>
		<category><![CDATA[#ThreatHunting]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#WebSecurity]]></category>
		<category><![CDATA[#ZeroTrust]]></category>
		<category><![CDATA[security update]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11718</guid>

					<description><![CDATA[<p>An NGINX vulnerability tracked as CVE-2026-42945 is being actively exploited by attackers. The flaw affects NGINX Open Source</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/nginx-vulnerability-rce/">NGINX Vulnerability Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>An NGINX vulnerability tracked as CVE-2026-42945 is being actively exploited by attackers. The flaw affects NGINX Open Source and NGINX Plus and could lead to server crashes or remote code execution under specific conditions.</p>



<p>Security researchers observed exploitation attempts within days of the vulnerability becoming public, highlighting how quickly attackers move to abuse flaws in widely used infrastructure software.</p>



<h2 class="wp-block-heading"><strong>How the NGINX Vulnerability Works</strong></h2>



<p>The issue is caused by a heap buffer overflow in the NGINX worker process. Attackers can trigger the flaw by sending specially crafted HTTP requests to vulnerable servers.</p>



<p>Because the vulnerability does not require authentication, exposed systems are at higher risk. In many cases, attackers can crash the NGINX worker process, leading to service disruption. Under specific conditions, the flaw could also be leveraged for remote code execution.</p>



<p>Researchers noted that full remote code execution is more likely on systems where protections such as Address Space Layout Randomization (ASLR) are disabled.</p>



<p>The vulnerability mainly affects servers using specific rewrite configurations, meaning not every NGINX deployment is directly exploitable. However, identifying vulnerable systems at internet scale remains difficult.</p>



<h2 class="wp-block-heading"><strong>Large Exposure and Security Recommendations</strong></h2>



<p>Security researchers estimate that millions of internet-facing NGINX servers could potentially be affected. Even if only a fraction of those systems meet the exact exploitation conditions, the overall attack surface remains significant.</p>



<p>Attackers are already scanning for vulnerable or misconfigured servers, increasing the urgency for organizations to respond quickly.</p>



<p>To reduce risk, security teams should:</p>



<ul class="wp-block-list">
<li>Apply the latest NGINX patches and updates</li>



<li>Review rewrite configurations carefully</li>



<li>Enable protections such as ASLR</li>



<li>Monitor for suspicious or unusual HTTP requests</li>
</ul>



<p>The incident highlights how vulnerabilities in widely deployed technologies can quickly become major security threats, even when exploitation depends on specific configurations.</p>



<p>With active exploitation already underway, rapid patching and continuous monitoring are critical to preventing compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/nginx-vulnerability-rce/">NGINX Vulnerability Enables Remote Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/nginx-vulnerability-rce/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>MongoDB Vulnerability Allows Arbitrary Code Execution</title>
		<link>https://firsthackersnews.com/mongodb-vulnerability-code-execution/</link>
					<comments>https://firsthackersnews.com/mongodb-vulnerability-code-execution/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 14 May 2026 07:24:00 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CodeExecution]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#databasesecurity]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EndpointSecurity]]></category>
		<category><![CDATA[#EnterpriseSecurity]]></category>
		<category><![CDATA[#EthicalHacking]]></category>
		<category><![CDATA[#Hacking]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#ITSecurity]]></category>
		<category><![CDATA[#Malware]]></category>
		<category><![CDATA[#mongodb]]></category>
		<category><![CDATA[#mongodbsecurity]]></category>
		<category><![CDATA[#mongodbvulnerability]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityFlaw]]></category>
		<category><![CDATA[#ThreatHunting]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#ZeroTrust]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11702</guid>

					<description><![CDATA[<p>A critical vulnerability in MongoDB, tracked as CVE-2026-8053, could allow attackers to execute arbitrary code on affected database</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/mongodb-vulnerability-code-execution/">MongoDB Vulnerability Allows Arbitrary Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>A critical vulnerability in MongoDB, tracked as CVE-2026-8053, could allow attackers to execute arbitrary code on affected database servers. This issue poses a serious risk to organizations relying on MongoDB for handling sensitive data and backend operations.</p>



<p>The flaw was identified during internal security testing by <strong>MongoDB</strong> and primarily impacts core MongoDB Server deployments, particularly in self-managed environments.</p>



<h2 class="wp-block-heading"><strong>Technical Overview of the Vulnerability</strong></h2>



<p>The vulnerability enables arbitrary code execution, a class of flaws that allows threat actors to run malicious instructions directly on the host system. This effectively bypasses standard security boundaries and can grant attackers control over the database server.</p>



<p>Given that MongoDB often stores centralized and high-value data, exploitation of this flaw could lead to unauthorized data access, credential exposure, and system-level compromise. Attackers may also leverage the compromised host to establish persistence or pivot laterally within the network.</p>



<p>The issue affects MongoDB versions 5.0 and later in self-hosted deployments, where patch management depends entirely on the organization’s update practices.</p>



<h2 class="wp-block-heading"><strong>Impact and Mitigation</strong></h2>



<p>Managed cloud users of <strong>MongoDB Atlas</strong> are not impacted, as the vulnerability has already been addressed across the platform through centralized patch deployment.</p>



<p>However, self-hosted environments remain exposed until updates are applied. MongoDB has released patched versions, including updates in recent release cycles such as 7.0.31, 8.0.20, and 8.2.7, to mitigate this risk.</p>



<p>Although there is currently no evidence of active exploitation, the nature of arbitrary code execution vulnerabilities makes them highly attractive to attackers. Systems that remain unpatched could be quickly targeted once exploit techniques become publicly available.</p>



<p>Organizations should ensure their MongoDB deployments are updated to the latest secure versions and aligned with current security baselines. Maintaining timely patching and monitoring practices is essential to reduce the risk of compromise.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/mongodb-vulnerability-code-execution/">MongoDB Vulnerability Allows Arbitrary Code Execution</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/mongodb-vulnerability-code-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Zoom Vulnerability Allows Privilege Escalation Attacks</title>
		<link>https://firsthackersnews.com/zoom-vulnerability-privilege-escalation/</link>
					<comments>https://firsthackersnews.com/zoom-vulnerability-privilege-escalation/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Wed, 13 May 2026 04:33:29 +0000</pubDate>
				<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Internet Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#CloudSecurity]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#datasecurity]]></category>
		<category><![CDATA[#DigitalRisk]]></category>
		<category><![CDATA[#EndpointSecurity]]></category>
		<category><![CDATA[#EnterpriseSecurity]]></category>
		<category><![CDATA[#EthicalHacking]]></category>
		<category><![CDATA[#Hacking]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#ITSecurity]]></category>
		<category><![CDATA[#Malware]]></category>
		<category><![CDATA[#PrivilegeEscalation]]></category>
		<category><![CDATA[#SecurityAwareness]]></category>
		<category><![CDATA[#SecurityFlaw]]></category>
		<category><![CDATA[#ThreatHunting]]></category>
		<category><![CDATA[#ThreatIntelligence]]></category>
		<category><![CDATA[#ZeroTrust]]></category>
		<category><![CDATA[#zoom]]></category>
		<category><![CDATA[#zoomflaw]]></category>
		<category><![CDATA[#zoomsecurity]]></category>
		<category><![CDATA[#zoomvulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11698</guid>

					<description><![CDATA[<p>Zoom has addressed a set of newly discovered vulnerabilities in its software that could be exploited to gain</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zoom-vulnerability-privilege-escalation/">Zoom Vulnerability Allows Privilege Escalation Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Zoom has addressed a set of newly discovered vulnerabilities in its software that could be exploited to gain elevated access or expose sensitive information. These flaws affect Zoom applications on Windows and iOS, with the most critical risks centered around privilege escalation in enterprise environments.</p>



<p>The vulnerabilities allow attackers with basic local access to increase their privileges and operate with administrative-level control. In real-world scenarios, this type of access is often used as a stepping stone for larger attacks, including lateral movement and data exfiltration.</p>



<h2 class="wp-block-heading"><strong>Privilege Escalation Risks in Windows Environments</strong></h2>



<p>Two high-severity vulnerabilities, each rated with a CVSS score of 7.8, impact Zoom’s Windows-based components.</p>



<p>The first issue affects Zoom Rooms for Windows and is caused by an untrusted search path vulnerability within the installer. This means the application may load files from unintended locations, allowing attackers to inject malicious code during execution.</p>



<p>The second flaw targets the Zoom Workplace VDI Plugin. It stems from improper control over file names and paths in the installation process. By manipulating these paths, an attacker can execute arbitrary code and escalate privileges.</p>



<p>These vulnerabilities are particularly dangerous because they require minimal effort to exploit once initial access is obtained. Attackers can leverage them to:</p>



<ul class="wp-block-list">
<li>Disable or bypass endpoint security controls</li>



<li>Access and extract sensitive enterprise data</li>



<li>Maintain persistence within the environment</li>



<li>Move laterally across systems inside the network</li>



<li>Deploy additional payloads such as ransomware</li>
</ul>



<p>Such privilege escalation flaws are highly valuable in targeted attacks, especially in corporate environments where Zoom is widely used.</p>



<h2 class="wp-block-heading"><strong>iOS Vulnerability and Overall Impact</strong></h2>



<p>A separate vulnerability affects Zoom Workplace on iOS devices, though its severity is significantly lower. This issue involves a failure in a protection mechanism that could allow limited data exposure.</p>



<p>However, exploitation requires physical access to the device, which reduces the likelihood of large-scale attacks. Still, it highlights the importance of securing mobile endpoints alongside desktop systems.</p>



<p>The key concern across all these vulnerabilities is the potential for unauthorized access to sensitive data and system resources, particularly in organizations that rely heavily on collaboration tools.</p>



<p>To address these risks, <strong>Zoom Video Communications</strong> has released security patches for all affected components. Because these flaws are now publicly disclosed, unpatched systems may become targets for active exploitation.</p>



<p>Users and organizations should immediately update:</p>



<ul class="wp-block-list">
<li>Zoom Rooms for Windows to version 7.0.0 or later</li>



<li>Zoom Workplace VDI Plugin to version 6.6.11 or newer</li>



<li>Zoom Workplace for iOS to version 7.0.0 or above</li>
</ul>



<p>Timely patching, combined with proper access controls and endpoint monitoring, is essential to prevent these vulnerabilities from being exploited in real-world attacks.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/zoom-vulnerability-privilege-escalation/">Zoom Vulnerability Allows Privilege Escalation Attacks</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/zoom-vulnerability-privilege-escalation/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>SonicWall Flaw Allows Access Bypass and Firewall Crash</title>
		<link>https://firsthackersnews.com/sonicwall-security-flaw/</link>
					<comments>https://firsthackersnews.com/sonicwall-security-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 30 Apr 2026 07:01:08 +0000</pubDate>
				<category><![CDATA[Cybersecurity]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#CyberAttack]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#FirewallSecurity]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#NetworkSecurity]]></category>
		<category><![CDATA[#SecurityFlaw]]></category>
		<category><![CDATA[#SecurityRisk]]></category>
		<category><![CDATA[#SonicOS]]></category>
		<category><![CDATA[#SonicWall]]></category>
		<category><![CDATA[#Vulnerability]]></category>
		<category><![CDATA[CVE]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security patch]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<category><![CDATA[sonicwall]]></category>
		<category><![CDATA[SonicWall Firewall]]></category>
		<category><![CDATA[vulnerability impact]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11663</guid>

					<description><![CDATA[<p>SonicWall has disclosed multiple security issues in its SonicOS software that could impact firewall security and availability. These</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/sonicwall-security-flaw/">SonicWall Flaw Allows Access Bypass and Firewall Crash</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>SonicWall has disclosed multiple security issues in its SonicOS software that could impact firewall security and availability. These vulnerabilities, revealed in a recent advisory, could allow attackers to bypass access controls, access restricted areas, and even crash firewall systems.</p>



<p>While some of these issues require prior access or valid credentials, the overall risk remains significant—especially for organizations relying heavily on SonicWall firewalls to protect their networks. Immediate attention and updates are strongly recommended.</p>



<h2 class="wp-block-heading"><strong>Major Security Risks Identified</strong></h2>



<p>The most serious issue involves a flaw in how access controls are handled. Under certain conditions, an attacker on a nearby network could bypass normal authentication checks and gain access to sensitive management functions.</p>



<p>This type of access can be highly dangerous. If exploited, attackers may be able to:</p>



<ul class="wp-block-list">
<li>Change firewall rules</li>



<li>Disable security protections</li>



<li>Modify system configurations</li>
</ul>



<p>In addition to this, two other vulnerabilities affect users who already have access to the system. One allows attackers to move outside restricted directories and interact with protected services, while another can overload the system and force the firewall to crash.</p>



<h2 class="wp-block-heading"><strong>Breakdown of the Vulnerabilities</strong></h2>



<p>The advisory highlights three key issues that administrators should be aware of:</p>



<ul class="wp-block-list">
<li><strong>Access control bypass flaw</strong> – Allows unauthorized access to management functions from adjacent networks</li>



<li><strong>Path traversal issue</strong> – Lets authenticated users reach restricted system areas</li>



<li><strong>Buffer overflow vulnerability</strong> – Can be used to crash the firewall and disrupt operations</li>
</ul>



<p>Each of these issues presents a different level of risk, but together they create a serious security concern for affected systems.</p>



<h2 class="wp-block-heading"><strong>What Organizations Should Do</strong></h2>



<p>SonicWall has provided fixes and recommended actions to reduce the risk. Organizations using SonicOS should review the advisory and apply updates as soon as possible.</p>



<p>Delaying patches could leave systems exposed to attacks that impact both security and uptime. Ensuring that firewall software is up to date is critical to maintaining a strong defense.</p>



<p>These vulnerabilities highlight how even core security systems like firewalls can become targets. A single flaw can lead to access bypass or service disruption, affecting the entire network.</p>



<p>Staying updated, applying patches quickly, and monitoring systems closely remain essential steps in preventing such risks.</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/sonicwall-security-flaw/">SonicWall Flaw Allows Access Bypass and Firewall Crash</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/sonicwall-security-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Apple Notification Privacy Flaw Fixed in iOS Update</title>
		<link>https://firsthackersnews.com/apple-notification-privacy-flaw/</link>
					<comments>https://firsthackersnews.com/apple-notification-privacy-flaw/#respond</comments>
		
		<dc:creator><![CDATA[FHN]]></dc:creator>
		<pubDate>Thu, 23 Apr 2026 06:23:04 +0000</pubDate>
				<category><![CDATA[Apple]]></category>
		<category><![CDATA[Application Security]]></category>
		<category><![CDATA[Secuirty Update]]></category>
		<category><![CDATA[Security Advisory]]></category>
		<category><![CDATA[Security Update]]></category>
		<category><![CDATA[vulnerability]]></category>
		<category><![CDATA[#ApplePrivacy]]></category>
		<category><![CDATA[#CyberSecurity]]></category>
		<category><![CDATA[#DataPrivacy]]></category>
		<category><![CDATA[#infosec]]></category>
		<category><![CDATA[#iOSUpdate]]></category>
		<category><![CDATA[#iPhoneSecurity]]></category>
		<category><![CDATA[#NotificationBug]]></category>
		<category><![CDATA[#PrivacyProtection]]></category>
		<category><![CDATA[#SecurityFlaw]]></category>
		<category><![CDATA[#TechNews]]></category>
		<category><![CDATA[security advisory]]></category>
		<category><![CDATA[security fix]]></category>
		<category><![CDATA[security flaw]]></category>
		<category><![CDATA[security patch]]></category>
		<category><![CDATA[security update]]></category>
		<category><![CDATA[security vulnerability]]></category>
		<guid isPermaLink="false">https://firsthackersnews.com/?p=11626</guid>

					<description><![CDATA[<p>Apple has released iOS 26.4.2 and iPadOS 26.4.2 to fix a serious privacy issue related to notifications. This</p>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-notification-privacy-flaw/">Apple Notification Privacy Flaw Fixed in iOS Update</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>Apple has released iOS 26.4.2 and iPadOS 26.4.2 to fix a serious privacy issue related to notifications. This issue affected how message previews were stored on devices and could expose sensitive information even after apps were removed.</p>



<p>The flaw impacted apps like Signal, where message previews could remain on the device even after the app was deleted. This created a privacy risk, as users would assume their data was completely removed.</p>



<h2 class="wp-block-heading">Apple Notification Privacy Flaw Explained</h2>



<p>The vulnerability, tracked as CVE-2026-28950, was caused by a problem in Apple’s notification logging system. Instead of fully deleting notifications, some data was still being stored in system logs.</p>



<p>This meant that message previews, including private conversations, could still exist on the device. Reports showed that investigators were able to recover this data, even after the app had been uninstalled.</p>



<h2 class="wp-block-heading">Why This Matters</h2>



<p>This issue is important because it shows that even secure apps can be affected by system-level behavior. While Signal uses strong encryption, the operating system storing notification previews created an unexpected privacy gap.</p>



<p>Key concerns included:</p>



<ul class="wp-block-list">
<li>Notifications not being fully deleted</li>



<li>Sensitive message previews remaining accessible</li>



<li>Data exposure happening outside the app itself</li>
</ul>



<h2 class="wp-block-heading">Apple’s Fix and Improvements</h2>



<p>Apple resolved the issue by improving how notification data is handled and cleared from the system.</p>



<p>With the update:</p>



<ul class="wp-block-list">
<li>Notification data is properly removed</li>



<li>Previously stored data is cleared automatically</li>



<li>Future notifications are no longer retained after deletion</li>
</ul>



<p>Signal also acknowledged the fix and supported the update, highlighting its importance for user privacy.</p>



<h2 class="wp-block-heading">Devices That Receive the Update</h2>



<p>The update is available for multiple Apple devices, including:</p>



<ul class="wp-block-list">
<li>iPhone 11 and newer</li>



<li>iPad Pro (recent models)</li>



<li>iPad Air (3rd generation and later)</li>



<li>iPad (8th generation and later)</li>



<li>iPad mini (5th generation and later)</li>
</ul>



<p>Older supported devices can receive similar security fixes through updated versions.</p>



<h2 class="wp-block-heading">What Users Should Do</h2>



<p>Users should update their devices as soon as possible to stay protected. Keeping your system updated helps prevent privacy risks and ensures your data is secure.</p>



<p>To install the update, go to Settings, tap General, and select Software Update.</p>



<blockquote class="wp-block-quote is-layout-flow wp-block-quote-is-layout-flow">
<p><strong>&#x200d;Follow Us on:<strong><a href="https://www.linkedin.com/in/firsthackers-news/" target="_blank" rel="noopener">Linkedin</a>,<a href="https://www.instagram.com/firsthackersnews/" target="_blank" rel="noreferrer noopener"> Instagram</a>, <a href="https://www.facebook.com/FirsthackerNews" target="_blank" rel="noreferrer noopener">Facebook</a></strong> to get the latest security news!</strong></p>
</blockquote>
<p>The post <a rel="nofollow" href="https://firsthackersnews.com/apple-notification-privacy-flaw/">Apple Notification Privacy Flaw Fixed in iOS Update</a> appeared first on <a rel="nofollow" href="https://firsthackersnews.com">First Hackers News</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://firsthackersnews.com/apple-notification-privacy-flaw/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
