CVE-2026-7273 nei Zyxel GS1900: exploit attivo e firmware da aggiornare
CVE-2026-7273 nei switch Zyxel GS1900 è nel catalogo CISA KEV. Analisi del buffer overflow, prerequisiti LAN e firmware corretti per modello.
CVE e dintorni
16 articoli
CVE-2026-7273 nei switch Zyxel GS1900 è nel catalogo CISA KEV. Analisi del buffer overflow, prerequisiti LAN e firmware corretti per modello.
CVE-2026-84869 colpisce il client ScreenConnect durante sessioni attive. Analisi di impatto, CVSS 9.9, versioni e remediation in 26.6.5.
CVE-2026-81642 colpisce Unbound fino alla 1.26.0: analizziamo il bug DNSKEY, l'esposizione reale e come aggiornare alla 1.26.1.
Come E4del e PINHOLE RAT usano il banner FTP come dead drop per ricevere comandi, con analisi PCAP, regole Suricata e hardening.
Un difetto nel modo in cui Adobe Commerce e Magento legano l'identità del cliente alla sua sessione permette a un attaccante non autenticato di imposs...
Due bug distinti nel core di WordPress, uno nella REST API e uno in WP_Query, uniti in un'unica catena che porta dritti a una web shell senza username...
CSRF remains in the OWASP Top 10 and hits applications that look secure. How it really works, with exploit examples and concrete countermeasures to im...
A specially crafted animated sticker file can execute remote code on Telegram for Android and Linux with no user interaction at all. ZDI-CAN-30207, CV...
Una falla critica nell'assistente AI integrato di Chrome, battezzata 'Glic Jack', permetteva ad estensioni malevole di accedere a camera, microfono e ...
A bot requesting dozens of password resets per minute on a WordPress site, with a different user-agent on every request. Here's how to spot it in ngin...
La prompt injection rappresenta una debolezza strutturale dei sistemi basati su LLM. Quando comandi e dati viaggiano nello stesso canale, basta una fr...
Software supply chain attacks are a growing, insidious threat: compromising a single library or DevOps tool is enough to hit thousands of systems. Fro...
SQL Injection is still among the most exploited vulnerabilities. Here's how it really works, with practical examples and concrete solutions for develo...
Cross-site scripting (XSS) is a serious vulnerability that lets hackers inject malicious scripts into web applications. Covers prevention, types of XS...
A massive collection of stolen data, nicknamed "the Mother of All Breaches", has recently been discovered, including 26 billion records from LinkedIn,...
There are several types of malware, including spyware, adware, backdoors, ransomware, scareware, rootkits, viruses, trojans and worms, each with a dif...