Tag: memory corruption
10 articles

AI-Assisted Research Exposes Widespread Flaw in Software Decoders
Imagine uploading a seemingly harmless image, only to have it trigger a sneaky data heist - researchers have uncovered a widespread flaw in software decoders that lets attackers swipe sensitive information like user data and passwords. This cleverly crafted exploit, dubbed HEIF Heist, can even occur without immediate remote code execution.

Malicious Extensions Expose Crypto Data AI Agents Automate Cyber Intrusions Shadow AI Exposes Sensitive Data Fake M&A Deals Drive Wire Fraud 200 Android Flaws Patched 119K Domains Power Fake Shops Chrome Accelerates Security Releases Singpass Scheme Tied to 170 Victims Email Breach Fuels Wallet Phishing 33K+ Plex Servers Remain Exposed EtherRAT Chain Ends in Ransomware CISA Refreshes Insider Threat Guidance AI
Google just patched 200 security flaws in Android, including a critical Wi-Fi vulnerability that could let hackers take control of your device - and it's a stark reminder to stay vigilant about the risks lurking in ordinary access and trusted services.

SAP Patches Maximum Severity Flaw in Kernel Software
A critical vulnerability, known as CVE-2026-44756, has been discovered in SAP's Extended Passport Processing, allowing attackers to corrupt memory and wreak havoc on systems. This maximum-severity flaw stems from a simple yet devastating oversight: missing boundary validation during data deserialization.

SAP Discloses Maximum-Severity Kernel Vulnerability
Over 10,000 SAP systems are exposed to the public internet, making them vulnerable to a newly disclosed maximum-severity kernel flaw, CVE-2026-44756, that allows attackers to gain admin privileges and take control. This critical vulnerability, dubbed OVERPASS, is a buffer overflow flaw that can be exploited to run arbitrary commands on vulnerable systems.

Linux Flaw Exposes Local Users to Root via Open vSwitch
A newly discovered Linux flaw, CVE-2026-64531, lets local users potentially gain root access via Open vSwitch, even without an existing OVS bridge, running ovs-vswitchd, or host-level CAP_NET_ADMIN privileges. This vulnerability, with a CVSS score of 7.8, was quickly patched after being responsibly disclosed.

Redis Exposes Zero-Days, RCE Exploit in Latest Security Releases
Redis just released seven security updates to fix major vulnerabilities that could let attackers run malicious code remotely, thanks to newly published proof-of-concept exploits targeting several Redis versions. The fixes cover multiple branches, including 6.x, 7.x, and 8.x, and patch memory-corruption flaws that can be triggered using the RESTORE command and other requirements.

OpenSSL Servers Vulnerable to Memory-Bloating DDoS Attacks
Beware: a simple 11-byte malicious input can cripple OpenSSL servers with a devastating DDoS attack, leaving them permanently bloated and vulnerable. This sneaky exploit, dubbed HollowByte, takes advantage of a weakness in OpenSSL's TLS handshake to drain server resources.

SAP Patches Critical Flaws in NetWeaver, Commerce Cloud
SAP has patched critical flaws in its NetWeaver and Commerce Cloud products, including a vulnerability in NetWeaver Application Server ABAP that allows authenticated attackers to cause memory corruption, potentially leading to data breaches or system downtime. This fix is part of SAP's July 2026 security package, which addresses 16 vulnerabilities across multiple products.

libssh2 Flaw Exposes Clients to Code Execution Risk
A critical flaw in libssh2, known as CVE-2026-55200, can be exploited by a malicious SSH server to trigger memory corruption on a connecting client, with no credentials or user interaction required. This vulnerability can be easily triggered with a public proof-of-concept now available.

NVIDIA Chips Vulnerable to Rowhammer Attacks
Researchers have discovered that NVIDIA chips are vulnerable to Rowhammer attacks, which can be exploited to gain unauthorized access to computer systems. This security threat can lead to a complete compromise of the machine, allowing attackers to read and write data freely.