14
May
2026
Posted by in Blog |
 A heap-based buffer overflow in nginx’s ngx_http_rewrite_module, disclosed as CVE-2026-42945 and nicknamed NGINX Rift, allows an unauthenticated attacker to crash a worker process, or potentially achieve remote code execution on hosts with ASLR disabled, by sending a single crafted HTTP request. If you operate an internet-facing nginx instance, especially one with non-trivial rewrite rules in […]
19
March
2026
Posted by in Blog |
Google has yet again, officially rolled out a crucial update for its Chrome browser, promoting version 146 to the stable channel for Windows, Mac, and Linux users. Many of these flaws involve deep-seated memory corruption issues that, if left unpatched, could allow remote attackers to execute arbitrary code and fully compromise affected systems. The current […]
9
February
2026
Posted by in Blog |
Discovered during holiday tinkering, this issue (CVE-2026-25916) affects versions before 1.5.13 and 1.6.13. In a sneaky bypass of email security features, a vulnerability in Roundcube Webmail exposes users to hidden tracking even when “Block remote images” is enabled. Attackers can now confirm if you’ve opened their emails, logging your IP address and browser details without […]