14
May
2026
Posted by in Blog |
 A heap-based buffer overflow in nginx’s ngx_http_rewrite_module, disclosed as CVE-2026-42945 and nicknamed NGINX Rift, allows an unauthenticated attacker to crash a worker process, or potentially achieve remote code execution on hosts with ASLR disabled, by sending a single crafted HTTP request. If you operate an internet-facing nginx instance, especially one with non-trivial rewrite rules in […]
7
April
2026
Posted by in Blog |
A massive automated cyberattack campaign is actively targeting web applications built on the popular Next.js framework to steal highly sensitive information. Cybersecurity researchers at Cisco Talos have uncovered a severe credential harvesting operation tracked as “UAT-10608” that compromised at least 766 servers worldwide within just 24 hours. The core of this attack relies on CVE-2025-55182, a severe […]
7
April
2026
Posted by in Blog |
The OpenSSH project has released version 10.3 and its portable counterpart, 10.3p1, delivering critical security patches that system administrators worldwide should prioritize immediately. Following a brief testing phase in late March 2026, this major update addresses several high-impact vulnerabilities, with the most urgent being a dangerous shell injection flaw in the SSH client. Shell Injection […]