Forem

Cybersecurity

Articles related to cybersecurity and much more

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-23991: Panic at the Distro: Crashing go-tuf with Malformed JSON

CVE-2026-23991: Panic at the Distro: Crashing go-tuf with Malformed JSON

Comments
2 min read
GHSA-H3HW-29FV-2X75: Context Bleeding: When GraphQL Requests Swap Identities in Envelop

GHSA-H3HW-29FV-2X75: Context Bleeding: When GraphQL Requests Swap Identities in Envelop

Comments
2 min read
CVE-2026-23946: Pickle Rick-rolled Again: The Zombie RCE in Tendenci CMS

CVE-2026-23946: Pickle Rick-rolled Again: The Zombie RCE in Tendenci CMS

Comments
2 min read
CVE-2026-22036: Death by a Thousand Gzips: The Node.js Undici Decompression Loop

CVE-2026-22036: Death by a Thousand Gzips: The Node.js Undici Decompression Loop

Comments
2 min read
CVE-2025-69229: Death by a Thousand Chunks: The aiohttp O(N^2) DoS

CVE-2025-69229: Death by a Thousand Chunks: The aiohttp O(N^2) DoS

Comments
2 min read
CVE-2026-24688: Ouroboros in the Outline: Infinite Loops in pypdf (CVE-2026-24688)

CVE-2026-24688: Ouroboros in the Outline: Infinite Loops in pypdf (CVE-2026-24688)

Comments
2 min read
CVE-2026-24765: The CI/CD Trojan Horse: Inside PHPUnit's Unsafe Deserialization

CVE-2026-24765: The CI/CD Trojan Horse: Inside PHPUnit's Unsafe Deserialization

Comments
2 min read
CVE-2025-36070: The Glass House: Shattering IBM Db2 with a Single SELECT

CVE-2025-36070: The Glass House: Shattering IBM Db2 with a Single SELECT

Comments
2 min read
CVE-2026-24473: The Infinite Fallback: How Hono Leaked Your Cloudflare KV Keys

CVE-2026-24473: The Infinite Fallback: How Hono Leaked Your Cloudflare KV Keys

Comments
2 min read
CVE-2025-59471: Next.js Image Optimizer: The 4GB Hello World

CVE-2025-59471: Next.js Image Optimizer: The 4GB Hello World

Comments
2 min read
The Kernel's Blind Spot: Deconstructing the Advanced Techniques of the Singularity Rootkit

The Kernel's Blind Spot: Deconstructing the Advanced Techniques of the Singularity Rootkit

Comments
3 min read
CVE-2024-7721: CVE-2024-7721: 'MemFray' - The Stack Overflow That Broke the 'Secure' Gateway

CVE-2024-7721: CVE-2024-7721: 'MemFray' - The Stack Overflow That Broke the 'Secure' Gateway

Comments
2 min read
How to Choose the Right Anti-Bot + WAF Combination for an E-Commerce Site

How to Choose the Right Anti-Bot + WAF Combination for an E-Commerce Site

Comments
4 min read
The Rise of Fake Employees: How Hackers Infiltrate Companies Through Hiring
Cover image for The Rise of Fake Employees: How Hackers Infiltrate Companies Through Hiring

The Rise of Fake Employees: How Hackers Infiltrate Companies Through Hiring

Comments
7 min read
Passkeys in Production: What “Passwordless” Really Means for Engineers
Cover image for Passkeys in Production: What “Passwordless” Really Means for Engineers

Passkeys in Production: What “Passwordless” Really Means for Engineers

Comments
5 min read
CVE-2025-69211: The Invisible Path: Bypassing NestJS Middleware with URL Encoding

CVE-2025-69211: The Invisible Path: Bypassing NestJS Middleware with URL Encoding

Comments
2 min read
CVE-2025-29914: The Double-Slash Deception: Bypassing Coraza WAF with RFC Compliance

CVE-2025-29914: The Double-Slash Deception: Bypassing Coraza WAF with RFC Compliance

Comments
2 min read
Beyond the Screen: 5 Surprising Facts About the Internet's Engine
Cover image for Beyond the Screen: 5 Surprising Facts About the Internet's Engine

Beyond the Screen: 5 Surprising Facts About the Internet's Engine

Comments
4 min read
CVE-2026-24490: MobSF Stored XSS: When the Scanner Becomes the Target

CVE-2026-24490: MobSF Stored XSS: When the Scanner Becomes the Target

Comments
2 min read
CVE-2025-29927: Next.js Middleware Bypass: When 'I'm With The Band' Actually Works

CVE-2025-29927: Next.js Middleware Bypass: When 'I'm With The Band' Actually Works

Comments
2 min read
CVE-2026-24048: Backstage Pass: Bypassing SSRF Protections via Redirect Hijacking

CVE-2026-24048: Backstage Pass: Bypassing SSRF Protections via Redirect Hijacking

Comments
2 min read
CVE-2026-22864: Deno on Windows: How a Capital Letter Broke the Security Model

CVE-2026-22864: Deno on Windows: How a Capital Letter Broke the Security Model

Comments
2 min read
PHP Shell Ultimate Backdoor

PHP Shell Ultimate Backdoor

Comments
2 min read
Malicious .htaccess Injection and Fake Index.php Dropper

Malicious .htaccess Injection and Fake Index.php Dropper

Comments
2 min read
Goto Obfuscated Dropper

Goto Obfuscated Dropper

Comments
2 min read
loading...