Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
https://www.rapid7.com/blog/post/ve-authenticated-rce-via-argument-injection-gogs-unfixed/
Rapid7
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
Rapid7 researchers found that Gogs allows authenticated users to achieve RCE on the server by creating a pull request with a specially crafted branch name. More in our latest analysis blog.
New Malware Targeting Minecraft Infects 2K Daily, and Teens are Becoming Attackers
https://www.mcafee.com/blogs/security-news/minecraft-malware-campaign-research-teen-hacker-cyberbullying/
https://www.mcafee.com/blogs/security-news/minecraft-malware-campaign-research-teen-hacker-cyberbullying/
McAfee Blog
New Malware Targeting Minecraft Infects 2K Daily, and Teens are Becoming Attackers | McAfee Blog
If you or your child plays Minecraft, here's what you need to know about a large-scale malware campaign McAfee Labs just uncovered, and what to do about it.
How flat is replacing fat in AWS data center networks
https://www.amazon.science/blog/how-flat-is-replacing-fat-in-aws-data-center-networks
https://www.amazon.science/blog/how-flat-is-replacing-fat-in-aws-data-center-networks
Amazon Science
How flat is replacing fat in AWS data center networks
“Quasi-random” network topologies and new passive optical components called ShuffleBoxes make more-efficient flat networks as practical as traditional “fat-tree” networks.
Evil Hentai) These files were distributed alongside games created using various game engines and programming languages, including RenPy (Python), RPG Maker MV (JavaScript), and others. All identified games were categorized as hentai games.
https://securelist.ru/argamal-rat-distributed-with-hentai-games/115833/
https://securelist.ru/argamal-rat-distributed-with-hentai-games/115833/
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Faked Google Search Traffic
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks:
https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks:
https://socket.dev/blog/152-chrome-live-wallpaper-extensions-hid-ad-tracking
Socket
152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fak...
A network of 152 Chrome live wallpaper extensions hid ad tracking and made extension-driven traffic look like Google search clicks.
PixelSmash – Critical FFmpeg Vulnerability Turns Media Files into Weapons
https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/
https://jfrog.com/blog/pixelsmash-critical-ffmpeg-vulnerability-turns-media-files-into-weapons/
JFrog
PixelSmash - Critical FFmpeg Vulnerability Turns Media Files into Weapons
PixelSmash (CVE-2026-8461) is a CVSS 8.8 FFmpeg flaw discovered by JFrog Security Research. A crafted 50 KB media file enables RCE or DoS. Upgrade FFmpeg to 8.1.2.
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer
https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/
https://research.jfrog.com/post/hijacked-npm-vscode-tasks-blockchain/
Jfrog
Hijacked npm Packages Use Novel VSCode Autorun and Blockchain Dead Drops to Deploy a Credential/Crypto Stealer | JFrog
JFrog Security Research identified two hijacked npm packages, `html-to-gutenberg` and `fetch-pacage-assets`, that used a hidden VS Code task to launch a multi-stage malware chain. The payloads used blockchain transaction data as dead drops, installed JavaScript…
TrojPix: Electromagnetic Covert Channels via Imperceptible Pixel Modulation
https://www.usenix.org/conference/usenixsecurity26/presentation/zhang-guoming
https://www.usenix.org/conference/usenixsecurity26/presentation/zhang-guoming
One trigram at a time: XSLeak via Universal CSS Injection and DoS in Opera (GX)
https://zhero-web-sec.github.io/research-and-things/one-trigram-at-a-time-xsleak-via-universal-css-injection-and-dos-in-opera-(gx)
https://zhero-web-sec.github.io/research-and-things/one-trigram-at-a-time-xsleak-via-universal-css-injection-and-dos-in-opera-(gx)
New Trojan attacks supply chains and causes combined damage to infected PCs
https://news.drweb.ru/show/?i=15276&c=5
https://news.drweb.ru/show/?i=15276&c=5