Sign in

CyberHub

@cyberhub.blog
507 followers 376 following 31K posts

→ News, podcast, subreddit and yt video summaries → CVE alerts → CTF challenges www.cyberhub.blog #cybersecurity #hacking #cve #tech #news #ai

PostsRepliesMedia
CyberHub @cyberhub.blog · 28m
📌 CVE-2026-86132 - An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by... www.cyberhub.blog/cves/CVE-2026-861…
cyberhub.blog
CVE-2026-86132
An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.
000
CyberHub @cyberhub.blog · 58m
📌 CVE-2026-86128 - A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denia... www.cyberhub.blog/cves/CVE-2026-861…
cyberhub.blog
CVE-2026-86128
A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.
000
CyberHub @cyberhub.blog · 1h
📌 CTF Challenge Embedded in Free Browser Hacking Simulation Game NULLSHELL www.cyberhub.blog/article/33002-ctf…
cyberhub.blog
CTF Challenge Embedded in Free Browser Hacking Simulation Game NULLSHELL
A Capture The Flag (CTF) challenge has been tucked inside NULLSHELL, a free browser-based hacking simulation game. The game is described as a red team versus blue team browser game that contains CTF challenges using the NULLSHELL{} flag format. This provides an interactive way for security enthusiasts to practice their skills through gamified hacking scenarios directly in their web browser.
000
CyberHub @cyberhub.blog · 2h
📌 CVE-2026-86104 - An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a den... www.cyberhub.blog/cves/CVE-2026-861…
cyberhub.blog
CVE-2026-86104
An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.
000
CyberHub @cyberhub.blog · 2h
📌 CVE-2026-86134 - A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the m... www.cyberhub.blog/cves/CVE-2026-861…
cyberhub.blog
CVE-2026-86134
A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of service.
020
CyberHub @cyberhub.blog · 3h
📌 SANS Internet Storm Center Stormcast: Action1 Tool Abuse, libheif Vulnerability, SonicWall Critical ... www.cyberhub.blog/article/32994-san…
cyberhub.blog
SANS Internet Storm Center Stormcast: Action1 Tool Abuse, libheif Vulnerability, SonicWall Critical Flaw, OpenSSH Update, and DNS Root Key Change
This October 7th, 2026 SANS Internet Storm Center Stormcast covers several cybersecurity developments. Attackers are abusing Action1's legitimate remote management tool (A1 Agent) by distributing it through malicious PDFs disguised as fake Adobe updates, using Visual Basic scripts to download the tool after victims open URLs embedded in the PDFs. A vulnerability in libheif, used for parsing HEIF image files, enables remote code execution, with multiple similar vulnerabilities recently discovered in HEIF parsers. SonicWall's SMA 1000 appliance has a CVSS score 10 server-side request forgery vulnerability allowing unauthenticated users to perform arbitrary actions by using the front end as a proxy to reach internal services. OpenSSH version 10.6 has been released with a more accelerated release schedule due to increased AI-generated vulnerability submissions and duplicate reports indicating vulnerabilities are easily discoverable. On October 11th, the DNS root zone key signing key will change for only the second time, with the new key having been published for over a year.
010
CyberHub @cyberhub.blog · 3h
📌 CVE-2026-100774 - Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird ... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100774
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
010
CyberHub @cyberhub.blog · 4h
📌 CVE-2026-100773 - Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbir... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100773
Use-after-free in the Storage: IndexedDB component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
010
CyberHub @cyberhub.blog · 4h
📌 CVE-2026-100772 - Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird ... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100772
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
010
CyberHub @cyberhub.blog · 5h
📌 CVE-2026-100769 - Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thund... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100769
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
010
CyberHub @cyberhub.blog · 5h
📌 CVE-2026-100768 - Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157. www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100768
Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Thunderbird 157 and Firefox 157.
010
CyberHub @cyberhub.blog · 6h
📌 CVE-2026-100776 - Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thund... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100776
Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, and Firefox ESR 140.17.
010
CyberHub @cyberhub.blog · 6h
📌 CVE-2026-100254 - In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipelin... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100254
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 authenticated users could execute commands on Windows servers via CRLF injection in Pipeline Git connection settings
010
CyberHub @cyberhub.blog · 7h
📌 CVE-2026-100253 - In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100253
In JetBrains TeamCity before 2026.2, 2026.1.4, 2025.11.8 sandbox escape leading to code execution was possible via the versioned settings Kotlin DSL
010
CyberHub @cyberhub.blog · 7h
📌 CVE-2026-102424 - Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Ba... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102424
Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the c
010
CyberHub @cyberhub.blog · 8h
📌 CVE-2026-92222 - Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were... www.cyberhub.blog/cves/CVE-2026-922…
cyberhub.blog
CVE-2026-92222
Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.
010
CyberHub @cyberhub.blog · 8h
📌 CVE-2026-87830 - In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the ... www.cyberhub.blog/cves/CVE-2026-878…
cyberhub.blog
CVE-2026-87830
In the StAX streaming WS-SecurityPolicy validator, certain relative or unsupported XPath expressions can be converted into paths that never match the actual XML element path. A remote SOAP peer may therefore send a required element without the expected signature or encryption. Users are recommended
010
CyberHub @cyberhub.blog · 9h
📌 CVE-2026-89238 - WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentia... www.cyberhub.blog/cves/CVE-2026-892…
cyberhub.blog
CVE-2026-89238
WSS4J EncryptedHeader child confusion could promote an attacker-controlled plaintext element as the decrypted header, leading to incorrect confidentiality coverage and possible policy bypass. Users are recommended to upgrade to versions 4.0.2 or 3.0.6 or 2.4.4, which fix this issue.
010
CyberHub @cyberhub.blog · 9h
📌 CVE-2026-86131 - A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN... www.cyberhub.blog/cves/CVE-2026-861…
cyberhub.blog
CVE-2026-86131
A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.
010
CyberHub @cyberhub.blog · 10h
📌 CVE-2026-102425 - Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-d... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102425
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, t
010
CyberHub @cyberhub.blog · 10h
📌 CVE-2026-100770 - Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thun... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100770
Sandbox escape due to use-after-free in the DOM: Content Processes component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
000
CyberHub @cyberhub.blog · 11h
📌 CVE-2026-76570 - Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller perf... www.cyberhub.blog/cves/CVE-2026-765…
cyberhub.blog
CVE-2026-76570
Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 - The front-end CRUD API controller performs no Joomla token validation and no authentication check on any task. Table names, column names, and values are taken directly from request paramet
010
CyberHub @cyberhub.blog · 11h
📌 WordPress libheif Remote Code Execution Vulnerability www.cyberhub.blog/article/32979-wor…
cyberhub.blog
WordPress libheif Remote Code Execution Vulnerability
The Reddit post shares a link to a security research article about a Remote Code Execution (RCE) vulnerability related to WordPress and libheif. The research is published by Fortbridge at the URL https://fortbridge.co.uk/research/wordpress-libheif-rce/.
000
CyberHub @cyberhub.blog · 12h
📌 MI5 Warns Over 100 Academics Assisted China's Intelligence Gathering Efforts www.cyberhub.blog/article/32943-mi5…
cyberhub.blog
MI5 Warns Over 100 Academics Assisted China's Intelligence Gathering Efforts
MI5 issued a Security Service Espionage Alert on September 30, 2026, warning that more than 100 academics have assisted China in enhancing its intelligence gathering efforts for Beijing's state security service. The alert identified the China General Technology Research Institute (CGTRI) as an organization whose primary purpose is to fund research supporting these intelligence activities. The academics mentioned have U.K. links and their research has been funded by China's Ministry of State Security (MSS) through CGTRI.
010
CyberHub @cyberhub.blog · 12h
📌 Tooldump v2: a free platform to discover cybersecurity tools for CTFs and investigations www.cyberhub.blog/article/32946-too…
cyberhub.blog
Tooldump v2: a free platform to discover cybersecurity tools for CTFs and investigations
The creator of Tooldump announced the release of version 2, a free platform for discovering open-source cybersecurity tools. The platform contains over 1,100 open-source GitHub projects organized into 9 categories and 82 subcategories, covering areas including offensive security, cyber defense, and learning resources. Version 2 features a rebuilt UI, categorization system, backend, and infrastructure, plus new sections for cybersecurity-related MCP servers and agent skills. The platform is completely free with unlimited access and no account required, available at https://tooldump.eu.
010
CyberHub @cyberhub.blog · 13h
📌 Google Suspends Open Source Vulnerability Rewards Program Due to AI-Generated Submissions www.cyberhub.blog/article/32951-goo…
cyberhub.blog
Google Suspends Open Source Vulnerability Rewards Program Due to AI-Generated Submissions
Google has suspended its Open Source Vulnerability Rewards Program due to receiving a flood of submissions generated by artificial intelligence. The program, which rewards security researchers for finding vulnerabilities in open-source software, was paused as a result of the overwhelming volume of AI-generated bug reports. No specific numbers, dates, or technical details about the AI submissions were provided in the article.
010
CyberHub @cyberhub.blog · 13h
📌 Bouncy Castle Vulnerability, Car Privacy Issues, and ShinyHunters Arrest in Jordan www.cyberhub.blog/article/32958-bou…
cyberhub.blog
Bouncy Castle Vulnerability, Car Privacy Issues, and ShinyHunters Arrest in Jordan
The article content appears to be empty between the designated tags, containing no text or information to extract. Based on the metadata, the article title references three topics: a Bouncy Castle vulnerability, car privacy issues, and a ShinyHunters arrest in Jordan, but no actual details, CVE numbers, dates, technical specifications, or impacts are provided in the article body itself.
010
CyberHub @cyberhub.blog · 14h
📌 Gu3ssWeak: Deliberately Vulnerable Android App for Mobile Security Research and Bug Bounty Practice www.cyberhub.blog/article/32959-gu3…
cyberhub.blog
Gu3ssWeak: Deliberately Vulnerable Android App for Mobile Security Research and Bug Bounty Practice
A developer has created Gu3ssWeak, a deliberately vulnerable Android application designed for practicing mobile application security testing. The app includes intentionally vulnerable components such as WebView and deep link abuse, JavaScript interfaces, XSS, insecure local storage, SQL injection, hardcoded credentials, Frida-based runtime analysis, and vulnerability chaining. The project is intended to provide a realistic APK for practicing tools like JADX, APKTool, ADB, Frida, Burp Suite, and dynamic analysis in a controlled environment, and the developer is seeking feedback and suggestions for additional vulnerabilities.
010
CyberHub @cyberhub.blog · 14h
📌 Iranian Hacker Accused of Stealing 31TB from University Inboxes Extradited to US www.cyberhub.blog/article/32975-ira…
cyberhub.blog
Iranian Hacker Accused of Stealing 31TB from University Inboxes Extradited to US
Amir Barati, a 40-year-old dual Turkish and Iranian citizen, was arrested in Montenegro on June 25 and extradited to the United States following a Montenegrin court approval this week. Barati is accused of participating in an Iranian hacking campaign that stole 31 terabytes of data from university inboxes. The extradition enables US authorities to prosecute him for the alleged data theft operation targeting academic institutions.
010
CyberHub @cyberhub.blog · 15h
📌 Darknet Diaries EP 180: Inside Conti - The Rise and Fall of a Devastating Ransomware Empire www.cyberhub.blog/article/32960-dar…
cyberhub.blog
Darknet Diaries EP 180: Inside Conti - The Rise and Fall of a Devastating Ransomware Empire
This episode provides an extensive investigation into Conti, one of the most successful and devastating ransomware operations in history. The story traces the evolution of Russian cybercrime groups through multiple iterations, like Russian nesting dolls stacking inside each other. Before Conti existed, there was the Dyre gang led by a crime boss named Bentley. When Russian authorities raided Dyre in 2015, the operation morphed into TrickBot, which eventually became known as Conti. Bentley himself transformed into a new identity called Stern and continued leading operations. These groups operated with remarkable sophistication, even creating a film production company called the 25th Floor Film Company to launder their cybercrime profits. Bizarrely, they planned to produce a movie called Botnet about their own hacking operations, featuring characters based on actual gang members. The episode details how Conti recruited members through legitimate job-seeking websites in Russia, presenting themselves as a fast-moving startup. One key recruit was a Latvian programmer named Max, whose real name is Alavita. She was a middle-aged mother with a degree in applied mathematics who unknowingly joined the operation after passing a coding test. When she discovered she was working for a ransomware gang after being shown a ransomware note template, she chose to continue working with them. Max eventually became involved in writing ransomware notes and web development for the group. Her poor operational security led to her arrest when she landed in Miami for a connecting flight, making her the first Conti member to be apprehended by US authorities. Conti's most devastating attack targeted Ireland's entire healthcare system in 2021, during the height of the COVID-19 pandemic. Over 70,000 computers across 4,000 locations and forty hospitals were infected with ransomware. The attack caused total chaos, forcing hospitals to revert to pen and paper for patient records and appointments. Cancer treatments were delayed, maternity wards were disrupted, and the entire country's medical infrastructure was thrown into crisis. Conti demanded twenty million dollars for decryption. Ireland refused to pay, and after weeks of struggle, Conti surprisingly provided the decryption key without payment, possibly due to pressure from the Russian embassy in Ireland. However, this demonstrated Conti's evolution to double-dip ransomware, where they both encrypted systems and stole sensitive data, giving them leverage even if victims had backups. Another significant Conti operation targeted Graff, a luxury jeweler whose clients included celebrities and royalty. Conti stole customer data and began leaking it when Graff didn't immediately pay. However, the leaked data inadvertently included purchase records of the Saudi royal family. This mistake led to what appears to have been serious threats against Conti from powerful security teams protecting these high-profile individuals. In an unprecedented move for a cybercrime group, Conti issued a public apology specifically to Prince Mohammed bin Salman and other royal family members, promising to delete the data and implement better review processes. Internal chat logs showed Conti members were genuinely frightened, with one member writing that the Saudis would find them and they would be gone. Graff ultimately paid 7.5 million dollars in Bitcoin. The episode reveals how cybersecurity researcher Alex Holden and his team at Hold Security infiltrated Conti by posing as hackers and building relationships with members over years. They gained access to Conti's Jabber server and cloned their network, obtaining hundreds of thousands of internal messages. This provided unprecedented insight into how Conti operated like a legitimate corporation with departments, budgets, physical offices, and even allocated twenty-five million dollars for infrastructure improvements in 2021. The chat logs also revealed internal ethical debates, with some members refusing to attack hospitals while others, like a member named Dollar, ignored these boundaries. When Russia invaded Ukraine in February 2022, Conti publicly declared full support for the Russian government, which enraged a Ukrainian IT specialist who had access to their systems. This Ukrainian analyst, working with Alex Holden, executed a massive data breach against Conti itself, creating the Twitter account contileaks and releasing tens of thousands of internal messages, member photos, cryptocurrency accounts, and organizational details. The leaks exposed the gang's structure, revealed member identities, and created chaos within the organization. The timing was particularly devastating because Conti's membership was split between Russians and Ukrainians, and the war had already created internal tensions. The leaks included everything from attack planning discussions to personal photos of members living luxurious lifestyles. The cybersecurity community watched in real-time as one of the world's most successful ransomware operations unraveled publicly. While Alex Holden expressed concerns that the leaks caused Conti to splinter into multiple smaller groups that became harder to track, the disclosure led to numerous indictments and fundamentally changed how law enforcement understood ransomware operations. After the leaks, Conti attempted one final major attack against the entire government of Costa Rica before the organization disbanded, with members scattering to join or form other ransomware groups.
010
CyberHub @cyberhub.blog · 15h
📌 Discord community for beginners in CTF competitions www.cyberhub.blog/article/32973-dis…
cyberhub.blog
Discord community for beginners in CTF competitions
A Discord server has been created for beginners to start their journey into CTFs (Capture The Flag competitions). The community is designed for learners to interact with each other and provide mutual support. The server will feature group discussions and challenges based on participant involvement.
000
CyberHub @cyberhub.blog · 16h
📌 Multiple Remote Code Execution Vulnerabilities Discovered in OpenOffice www.cyberhub.blog/article/32967-mul…
cyberhub.blog
Multiple Remote Code Execution Vulnerabilities Discovered in OpenOffice
Multiple vulnerabilities have been discovered in OpenOffice, as reported by CERT-FR on October 5, 2026. These vulnerabilities allow an attacker to execute arbitrary code remotely. No specific CVE identifiers, version numbers, or technical details about the nature of the flaws are provided in the notice. The advisory indicates that remote code execution is the primary impact of these security issues.
010
CyberHub @cyberhub.blog · 16h
📌 CVE-2026-73636 - Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the... www.cyberhub.blog/cves/CVE-2026-736…
cyberhub.blog
CVE-2026-73636
Authentication bypass by capture-replay in mod_auth_digest in Apache Software Foundation Apache HTTP Server 2.4.x on all platforms allows a man-in-the-middle (MITM) attacker to replay captured digest authentication credentials via crafted requests that trigger garbage collection of the client's shar
010
CyberHub @cyberhub.blog · 17h
📌 CVE-2026-94483 - Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS... www.cyberhub.blog/cves/CVE-2026-944…
cyberhub.blog
CVE-2026-94483
Next.js is a React framework for building full-stack web applications. From 16.0.0 until 16.3.8, Image Optimization can follow attacker-controlled DNS resolution for a remote URL that matches images.remotePatterns, allowing the optimized image fetch to reach private IP addresses after the URL passes
010
CyberHub @cyberhub.blog · 17h
📌 CVE-2026-103102 - Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a softwa... www.cyberhub.blog/cves/CVE-2026-103…
cyberhub.blog
CVE-2026-103102
Pexip Infinity before 41.0 is affected by improper input validation in the signaling implementation which allows a remote attacker to trigger a software abort resulting in a denial of service. Exploitation of this issue requires accessing a gateway call from a WebRTC/API client.
010
CyberHub @cyberhub.blog · 18h
📌 CVE-2026-103101 - Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a P... www.cyberhub.blog/cves/CVE-2026-103…
cyberhub.blog
CVE-2026-103101
Pexip Infinity 30.0 through 40.x before 41.0 is affected by improper input validation in the web server that allows a malicious attacker to render a Pexip Infinity node inaccessible.
010
CyberHub @cyberhub.blog · 18h
📌 CVE-2026-84739 - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under ... www.cyberhub.blog/cves/CVE-2026-847…
cyberhub.blog
CVE-2026-84739
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to im
000
CyberHub @cyberhub.blog · 19h
📌 CVE-2026-102994 - pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number to... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102994
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.0, a crafted PDF containing indirect-object identifiers or generation-number tokens that continue for a long time without whitespace can cause pypdf/_reader.py and pypdf/generic/_base.py to scan excessive input through read_until
000
CyberHub @cyberhub.blog · 19h
📌 CVE-2026-102996 - pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually ... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102996
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can provide a TrueType or Type1 simple font with an unusually large /Widths array, causing pypdf/_font.py Font._collect_tt_t1_character_widths to process entries beyond the 256 character codes meaningful for a si
030
CyberHub @cyberhub.blog · 20h
📌 CVE-2026-102995 - pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string to... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102995
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF can place unusually large source-code or destination-string tokens in a font /ToUnicode mapping, causing pypdf/_cmap.py parse_bfchar to decode and retain oversized values during operations such as text extraction
000
CyberHub @cyberhub.blog · 20h
📌 CVE-2026-103000 - pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values tha... www.cyberhub.blog/cves/CVE-2026-103…
cyberhub.blog
CVE-2026-103000
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF can provide unusually large alphabetical page-label values that cause pypdf/_page_labels.py to generate strings beyond a reasonable page-label length when an application retrieves document page labels, consuming
000
CyberHub @cyberhub.blog · 21h
📌 CVE-2026-102999 - pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based ... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102999
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF containing many embedded files can cause the dictionary-based attachments API in pypdf/_doc_common.py to reparse the full attachment list for each content lookup, producing repeated work and long runtimes when an
010
CyberHub @cyberhub.blog · 21h
Path Traversal: Escaping the Documents Directory via the Files API koadt.github.io/oss-oopssec-store/p…
koadt.github.io
Path Traversal: Escaping the Documents Directory via the Files API | OopsSec Store - Walkthroughs
Exploiting an unsanitized file path parameter in OopsSec Store's documents API to read files outside the intended directory and retrieve a flag.
020
CyberHub @cyberhub.blog · 21h
📌 CVE-2026-102998 - pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_str... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102998
pypdf is a free and open-source pure-python PDF library. Prior to 6.19.0, a crafted PDF with form field values can cause pypdf/generic/_appearance_stream.py appearance-stream generation to repeat invariant selection-data work inside a loop when an application updates fields with flattening enabled,
000
CyberHub @cyberhub.blog · 22h
📌 CVE-2026-102997 - pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padd... www.cyberhub.blog/cves/CVE-2026-102…
cyberhub.blog
CVE-2026-102997
pypdf is a free and open-source pure-python PDF library. Prior to 6.18.1, a crafted PDF containing a partially malformed /FlateDecode stream with padded data can force pypdf/filters.py to use inefficient byte-by-byte decompression while the earlier recovery counter fails to advance for bytes that su
000
CyberHub @cyberhub.blog · 22h
📌 CVE-2026-100780 - Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird ... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100780
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
000
CyberHub @cyberhub.blog · 23h
📌 CVE-2026-100779 - Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firef... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100779
Use-after-free in the XSLT component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
000
CyberHub @cyberhub.blog · 23h
📌 CVE-2026-100777 - Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbir... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100777
Use-after-free in the Graphics: Canvas2D component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
000
CyberHub @cyberhub.blog · 06/10/2026
📌 CVE-2026-100785 - Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird ... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100785
Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
000
CyberHub @cyberhub.blog · 06/10/2026
📌 CVE-2026-100784 - Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunde... www.cyberhub.blog/cves/CVE-2026-100…
cyberhub.blog
CVE-2026-100784
Use-after-free in the Layout: Text and Fonts component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, Firefox 157, Firefox ESR 115.42, and Firefox ESR 140.17.
000