⤷ Title: Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
════════════════════════
𐀪 Author: Harikishan
════════════════════════
ⴵ Time: Thu, 01 Oct 2026 14:43:39 GMT
════════════════════════
⌗ Tags: #remote_access #metasploit #hacking #ethical_hacking #javascript
Medium
Exploiting Java RMI on Metasploitable 2: CVE-2011–3556
Java RMI (Remote Method Invocation) is a way for one Java application to ask another Java application on a different machine to perform a…
⤷ Title: ClickFix RAT Disguised as Custom ChatGPT Bot Strikes
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 14:22:06 +0000
════════════════════════
⌗ Tags: #Malware #ChatGPT #ClickFix #phishing #Remote Access Trojan
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 14:22:06 +0000
════════════════════════
⌗ Tags: #Malware #ChatGPT #ClickFix #phishing #Remote Access Trojan
Information Security News
ClickFix RAT Disguised as Custom ChatGPT Bot Strikes
The most compelling element of this novel cyberattack resides not upon a disparate phishing domain, but directly within the authentic ChatGPT interface. Huntress unveiled a sophisticated campaign …
⤷ Title: OpenBao Security Vulnerabilities Enable Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 02:05:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #OpenBao #Remote Code Execution #Secrets Management #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 02:05:49 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #cybersecurity #OpenBao #Remote Code Execution #Secrets Management #Vulnerability
Daily CyberSecurity
OpenBao Security Vulnerabilities Enable Code Execution
TL;DR OpenBao maintainers issued security updates to address two critical flaws in the secrets management platform. These OpenBao security vulnerabilities allow attackers to execute arbitrary code…
⤷ Title: GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 21:42:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #AI security #CVE_2026_90970 #gitlab #GitLab Duo #Remote Code Execution #Template Injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 02 Oct 2026 21:42:34 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Gateway #AI security #CVE_2026_90970 #gitlab #GitLab Duo #Remote Code Execution #Template Injection
Daily CyberSecurity
GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands
TL;DR GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970. The GitLab AI Gateway vulnerability scores 9.9 on CVSS 3.1. It lets a logged-in Duo Agent Platform user …
⤷ Title: Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 03 Oct 2026 05:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Apache Directory LDAP API #Apache OpenOffice #Apache Traffic Server #CVE_2026_102795 #CVE_2026_103877 #CVE_2026_59265 #LDAP #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 03 Oct 2026 05:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #apache #Apache Directory LDAP API #Apache OpenOffice #Apache Traffic Server #CVE_2026_102795 #CVE_2026_103877 #CVE_2026_59265 #LDAP #Remote Code Execution
Daily CyberSecurity
Unpatched Apache OpenOffice Vulnerability Leads New Apache Advisories for LDAP API and Traffic Server
TL;DR The Apache Software Foundation disclosed eight CVEs on October 2, 2026, across three projects. The most urgent is an Apache OpenOffice vulnerability, CVE-2026-59265, that runs attacker code …
⤷ Title: Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 09:16:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_100102 #CVE_2026_100103 #CVE_2026_103510 #Helix Core #P4 Search #Perforce #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 05 Oct 2026 09:16:59 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Authentication Bypass #CVE_2026_100102 #CVE_2026_100103 #CVE_2026_103510 #Helix Core #P4 Search #Perforce #Remote Code Execution
Daily CyberSecurity
Perforce Fixes Six P4 Search Vulnerabilities, Including a CVSS 10 Default Token Flaw
TL;DR Perforce has patched six P4 Search vulnerabilities in version 2026.4.2. The worst, CVE-2026-100103, scores a perfect 10.0 on CVSS 4.0 and lets an unauthenticated attacker take full control o…
⤷ Title: AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 00:35:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #AMD Instinct #CVE_2026_43598 #GPU Security #RCCL #Remote Code Execution #ROCm
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 00:35:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AMD #AMD Instinct #CVE_2026_43598 #GPU Security #RCCL #Remote Code Execution #ROCm
Daily CyberSecurity
AMD RCCL Vulnerability Could Enable Remote Code Execution on Instinct GPU Clusters
TL;DR AMD has disclosed CVE-2026-43598, an AMD RCCL vulnerability rated 7.7 on CVSS 4.0. The flaw sits in the ROCm Communication Collectives Library and could let a compromised peer run code remot…
⤷ Title: PoC Exploit and Technical Details Released for LibreOffice Calc Code Execution Flaw CVE-2026-63277
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 02:51:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_63266 #CVE_2026_63267 #CVE_2026_63277 #LibreOffice #LibreOffice Calc #proof_of_concept #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 02:51:45 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_63266 #CVE_2026_63267 #CVE_2026_63277 #LibreOffice #LibreOffice Calc #proof_of_concept #Remote Code Execution
Daily CyberSecurity
PoC Exploit and Technical Details Released for LibreOffice Calc Code Execution Flaw CVE-2026-63277
TL;DR The Document Foundation has fixed six flaws in LibreOffice, led by CVE-2026-63277, a LibreOffice Calc vulnerability that runs attacker code when a user opens a spreadsheet. Researchers have …
⤷ Title: IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 01:22:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #code_injection #CVE_2026_104334 #CVE_2026_93674 #CVE_2026_93675 #IBM #Langflow #Remote Code Execution
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 01:22:35 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #code_injection #CVE_2026_104334 #CVE_2026_93674 #CVE_2026_93675 #IBM #Langflow #Remote Code Execution
Daily CyberSecurity
IBM Patches 25 Langflow Vulnerabilities, Including Two Critical Remote Code Execution Flaws
TL;DR IBM has published a security bulletin covering 25 Langflow vulnerabilities in Langflow OSS versions 1.0.0 through 1.12.2. Two flaws, CVE-2026-104334 and CVE-2026-93674, score 9.8 on CVSS 3.1…
⤷ Title: Researchers Publish Full Details and PoC Exploit for a WordPress libheif RCE Chain
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 07:01:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #heap overflow #HEIC #ImageMagick #libheif #proof_of_concept #Remote Code Execution #wordpress
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 06 Oct 2026 07:01:53 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #heap overflow #HEIC #ImageMagick #libheif #proof_of_concept #Remote Code Execution #wordpress
Daily CyberSecurity
Researchers Publish Full Details and PoC Exploit for a WordPress libheif RCE Chain
TL;DR Fortbridge researcher Adrian Tiron has published a working proof-of-concept for a WordPress libheif RCE chain. It turns an authenticated HEIC image upload into code execution as the web serv…