Trusted Updates Turned Weaponized: Snap Store Publisher Hijacking Leads to Silent Crypto Theft on Linux
Executive Summary This incident describes a supply-chain attack targeting Linux users through the Snap application ecosystem operated…
continue reading..
861 GB Stolen: Inside the Alleged Everest Ransomware Breach of McDonald’s India
Executive Summary In 2024, McDonald’s India became the subject of a ransomware extortion claim by the Everest…
continue reading..
Critical Trust & Isolation Failures in IBM Platforms: JWT Admin Takeover and Container Command Execution (CVE-2025-36418 & CVE-2025-36059)
IBM ApplinX – JWT Privilege Escalation (Admin Impersonation) Product overview (at top)IBM ApplinX is an application modernization…
continue reading..
CVE-2025-56353: tinyMQTT Memory Leak Enables Remote Resource Exhaustion Attacks
This issue is in the tinyMQTT message broker, an implementation of the MQTT protocol used in many…
continue reading..
Multiple High and Critical Severity Flaws Discovered in NVIDIA Transformers4Rec and Nsight Tools
NVIDIA Product Vulnerabilities – Detailed Security Assessment (2025) Vendor: NVIDIAAffected Products: The following vulnerabilities impact NVIDIA developer…
continue reading..
CVE-2025-55130 : Node.js Permission Model Sandbox Escape via Symbolic Link Resolution
CVE-2025-55130 — Node.js Permission Model Sandbox Escape Field Details CVE Identifier CVE-2025-55130 Product Node.js Vulnerability Type Permission…
continue reading..
CVE-2026-21983: When a Local User Can Turn Oracle VM VirtualBox into a Hypervisor Takeover Gateway
Vulnerability Type: Privilege Escalation / Hypervisor TakeoverComponent Affected: VirtualBox CoreAttack Vector: LocalSeverity: HighCVSS v3.1 Base Score: 7.5…
continue reading..
CVE-2026-21945: Silent Java SSRF That Can Freeze Your JVM and Take Services Offline
Affected Software: Oracle Java SE, Oracle GraalVM for JDK, and Oracle GraalVM Enterprise Edition (many major supported…
continue reading..
CVE-2026-0610 & CVE-2026-1007: Critical Access Control and Database Security Failures in Devolutions Server
Devolutions Server – Security Vulnerability Analysis Product: Devolutions ServerAffected Branch: 2025.3.xImpact Level: High to CriticalAttack Surface: Network-exposed…
continue reading..
