BlueHammer abuses Windows Defender's update process to gain SYSTEM access
https://hackingpassion.com/bluehammer-windows-defender-zero-day/
#HackerNews #BlueHammer #WindowsDefender #ZeroDay #Cybersecurity #Vulnerability #HackingNews
BlueHammer abuses Windows Defender's update process to gain SYSTEM access
https://hackingpassion.com/bluehammer-windows-defender-zero-day/
#HackerNews #BlueHammer #WindowsDefender #ZeroDay #Cybersecurity #Vulnerability #HackingNews
My new article is out, this time it’s about internet-connected cameras, mostly being marketed as spy cameras. While the cameras themselves are very different, the common factor is the LookCam app used to manage them.
There is already a considerable body of research on these and similar P2P cameras, so it shouldn’t be a surprise that their security is nothing short of horrible. Still, how the developers managed to make all the wrong choices here on every level (firmware, communication protocol, cloud functionality) is quite something.
https://palant.info/2025/09/08/a-look-at-a-p2p-camera-lookcam-app/
Register now for “CVE/FIRST VulnCon 2026” on April 13–16, 2026!!!
In-person & virtual available: https://www.first.org/conference/vulncon26/registration
#CVE #FIRST #VulnCon26 #VulnerabilityManagement #Vulnerability
Security update: Hollo 0.6.12 is now available
We've released #Hollo 0.6.12 to fix a critical privacy #vulnerability where direct messages were being exposed in the replies section of public posts. Please update your instances immediately to ensure your private conversations remain private.
🔒 Security Update for BotKit Users
We've released #security patch versions BotKit 0.1.2 and 0.2.2 to address CVE-2025-54888, a security #vulnerability discovered in #Fedify. These updates incorporate the latest patched version of Fedify to ensure your bots remain secure.
We strongly recommend all #BotKit users update to the latest patch version immediately. Thank you for keeping the #fediverse safe! 🛡️
We've released #security updates for #Hollo (0.4.12, 0.5.7, and 0.6.6) to address a #vulnerability in the underlying #Fedify framework. These updates incorporate the latest Fedify security patches that fix CVE-2025-54888.
We strongly recommend all Hollo instance administrators update to the latest version for their respective release branch as soon as possible.
Update Instructions:
Railway users: Go to your project dashboard, select your Hollo service, click the three dots menu in deployments, and choose “Redeploy”
Docker users: Pull the latest image with docker pull ghcr.io/fedify-dev/hollo:latest and restart your containers
Manual installations: Run git pull to get the latest code, then pnpm install and restart your service
Please secure your routers!
Most Wi-Fi routers vulnerable to AirSnitch attack – here's what to do
#WiFi #Routers #Vulnerability #AirSnitch #Privacy #Security #Tech
500+ Organizations Now Participating as CVE Numbering Authorities (CNAs)!
As of March 31, 2026, there are 502 CNAs (499 CNAs and 3 CNA-LRs) from 42 countries participating in the CVE Program
Learn more:
https://www.cve.org/Media/News/item/blog/2026/03/31/502-Organizations-Participating-as-CNAs
#cve #cna #vulnerability #vulnerabilitymanagement #informationsecurity #infosec #cybersecurity
I'm now GNA 119 under CIRCL's GCVE system — a decentralized vulnerability
identification authority. I have authority to mint vulnerability
identifiers for cloud findings, including ones where vendor CNAs decline
to issue CVEs.
I could start assigning IDs to my own research today. I won't.
Cloud vulnerability validation shouldn't be one person's judgment. Mine
or anyone else's.
I'm forming a consensus panel of practitioners for each major cloud
platform — AWS, GCP, Azure, and managed services. GCVE-119 allocations
will go through panel review, not solo decisions.
Charter, scope, and membership criteria coming. Community input on
structure welcome before anything is finalized.
Background on GCVE and the cloud finding gap:
https://olearysec.com/gcve/
CVSS 10.0 in Google Config Connector — still unpatched.
Any K8s namespace user can become GCP Org Owner with 3 lines of YAML. Google's engineer said "Nice catch!" Then VRP called it "working as intended."
Their defense contradicts their own documentation.
Full writeup + video PoC: https://olearysec.com/research/config-connector-authorization-bypass
#infosec #cloudsecurity #gcp #kubernetes #bugbounty #vulnerability #google #k8s #iam #cybersecurity
The Python Software Foundation is hiring a Security Developer to join @miketheman and I on triaging vulnerability reports and mitigating malware published to PyPI.
If you've got experience with Python, security, and collaborating with open source projects then we'd love to hear from you:
https://jobs.pyfound.org/apply/ei03ut60y4/Security-Developer?referrer=20260730140256DSN5BCNCWZA5MXAO