Skip to main content

Tag: memory corruption

10 articles

Researcher working on laptop in modern tech lab with code on screen.

AI-Assisted Research Exposes Widespread Flaw in Software Decoders

Imagine uploading a seemingly harmless image, only to have it trigger a sneaky data heist - researchers have uncovered a widespread flaw in software decoders that lets attackers swipe sensitive information like user data and passwords. This cleverly crafted exploit, dubbed HEIF Heist, can even occur without immediate remote code execution.

Analyst 207
Smartphone on a neutral surface with blurred surroundings and daylight in the background.

Malicious Extensions Expose Crypto Data AI Agents Automate Cyber Intrusions Shadow AI Exposes Sensitive Data Fake M&A Deals Drive Wire Fraud 200 Android Flaws Patched 119K Domains Power Fake Shops Chrome Accelerates Security Releases Singpass Scheme Tied to 170 Victims Email Breach Fuels Wallet Phishing 33K+ Plex Servers Remain Exposed EtherRAT Chain Ends in Ransomware CISA Refreshes Insider Threat Guidance AI

Google just patched 200 security flaws in Android, including a critical Wi-Fi vulnerability that could let hackers take control of your device - and it's a stark reminder to stay vigilant about the risks lurking in ordinary access and trusted services.

Analyst 207
Rack-mounted computer equipment in a brightly-lit server room with a blank screen.

SAP Patches Maximum Severity Flaw in Kernel Software

A critical vulnerability, known as CVE-2026-44756, has been discovered in SAP's Extended Passport Processing, allowing attackers to corrupt memory and wreak havoc on systems. This maximum-severity flaw stems from a simple yet devastating oversight: missing boundary validation during data deserialization.

Analyst 207
Close-up of industrial computer server in softly lit corporate data center.

SAP Discloses Maximum-Severity Kernel Vulnerability

Over 10,000 SAP systems are exposed to the public internet, making them vulnerable to a newly disclosed maximum-severity kernel flaw, CVE-2026-44756, that allows attackers to gain admin privileges and take control. This critical vulnerability, dubbed OVERPASS, is a buffer overflow flaw that can be exploited to run arbitrary commands on vulnerable systems.

Analyst 207
Developer examines laptop in institutional setting amidst papers and notes.

Linux Flaw Exposes Local Users to Root via Open vSwitch

A newly discovered Linux flaw, CVE-2026-64531, lets local users potentially gain root access via Open vSwitch, even without an existing OVS bridge, running ovs-vswitchd, or host-level CAP_NET_ADMIN privileges. This vulnerability, with a CVSS score of 7.8, was quickly patched after being responsibly disclosed.

Analyst 207
Technicians in a server room inspect equipment amidst rows of racks and storage devices.

Redis Exposes Zero-Days, RCE Exploit in Latest Security Releases

Redis just released seven security updates to fix major vulnerabilities that could let attackers run malicious code remotely, thanks to newly published proof-of-concept exploits targeting several Redis versions. The fixes cover multiple branches, including 6.x, 7.x, and 8.x, and patch memory-corruption flaws that can be triggered using the RESTORE command and other requirements.

Analyst 207
Dimly lit server room with one server showing high memory usage.

OpenSSL Servers Vulnerable to Memory-Bloating DDoS Attacks

Beware: a simple 11-byte malicious input can cripple OpenSSL servers with a devastating DDoS attack, leaving them permanently bloated and vulnerable. This sneaky exploit, dubbed HollowByte, takes advantage of a weakness in OpenSSL's TLS handshake to drain server resources.

Analyst 207
SAP headquarters building exterior with people walking in and out, surrounded by greenery.

SAP Patches Critical Flaws in NetWeaver, Commerce Cloud

SAP has patched critical flaws in its NetWeaver and Commerce Cloud products, including a vulnerability in NetWeaver Application Server ABAP that allows authenticated attackers to cause memory corruption, potentially leading to data breaches or system downtime. This fix is part of SAP's July 2026 security package, which addresses 16 vulnerabilities across multiple products.

Analyst 207
Technicians work in a dimly lit server room with rows of rack-mounted equipment and cables on the floor.

libssh2 Flaw Exposes Clients to Code Execution Risk

A critical flaw in libssh2, known as CVE-2026-55200, can be exploited by a malicious SSH server to trigger memory corruption on a connecting client, with no credentials or user interaction required. This vulnerability can be easily triggered with a public proof-of-concept now available.

Analyst 207
Close-up of a computer's graphics card focusing on GDDR6 memory modules in a laboratory setting.

NVIDIA Chips Vulnerable to Rowhammer Attacks

Researchers have discovered that NVIDIA chips are vulnerable to Rowhammer attacks, which can be exploited to gain unauthorized access to computer systems. This security threat can lead to a complete compromise of the machine, allowing attackers to read and write data freely.

Analyst 207