(01) - Writing and disclosure[ Cybersecurity - 14 posts ]
Blog
Coordinated security disclosures and engineering notes. No hot takes, no reposted news.
- 001CybersecurityReportsDenial of Service in Next.js Server Actions via Malformed Origin HeaderA vulnerability in Next.js Server Actions allows attackers to trigger unhandled exceptions using malformed Origin headers, leading to Denial of Service.13 April 20263 min
- 002CybersecurityReportsInsufficient Rate Limiting and Chatbot Abuse in Chatwoot Web WidgetMultiple issues in the Chatwoot web chatbot widget allow message spamming, external iframe reuse, and lack of origin enforcement, leading to potential abuse and service degradation.26 February 20263 min
- 003CybersecurityReportsRCE Vulnerability Found in BeValk - React2ShellA critical Remote Code Execution vulnerability was discovered in BeValk due to its use of React 19, allowing attackers to escape Docker containers and escalate privileges.12 December 20254 min
- 004CybersecurityReportsCritical RCE Found in Teleparty Chrome ExtensionA Remote Code Execution vulnerability in the Teleparty browser extension allows attackers to take control of users' tabs and execute arbitrary code.29 November 20253 min
- 005CybersecurityReportsPhishing Campaign Targeting lto.gov.ph - PhilippinesAutomated security scans detected a phishing operation impersonating the Land Transportation Office of the Philippines, harvesting personal and payment information.19 November 20253 min
- 006CybersecurityReportsPhishing Campaign Impersonating pcivil.rj.gov.brSecurity researchers identified a phishing campaign mimicking the Civil Registry Portal of Rio de Janeiro, Brazil, designed to steal user credentials and personal data.28 October 20253 min
- 007CybersecurityReportsEmail Exposure Vulnerability in e-Nidhi Bihar PortalAn automated scan detected that the e-Nidhi Bihar Portal potentially exposed users' email addresses to unauthorized access due to a security misconfiguration.16 October 20252 min
- 008CybersecurityReportsSubdomain Vulnerability in Vinnytsia Municipal Portal - UkraineA misconfiguration in the Vinnytsia Municipal Portal subdomains could allow attackers to host malicious content under official-looking subdomains.02 October 20252 min
- 009CybersecurityReportsSubdomain Vulnerability in Spanish DGT DomainA misconfiguration in subdomain management for dgt.es was discovered, potentially allowing attackers to host malicious content under official-looking subdomains.29 September 20252 min
- 010CybersecurityReportsEmail Authentication Vulnerability in US Social Security SystemA critical flaw in the US Social Security email systems allows attackers to send fraudulent emails appearing to come from official government accounts, including the minister's address.23 September 20253 min
- 011CybersecurityReportsEmail Authentication Vulnerability in Ministry of Women of ParaguayA flaw in the Ministry of Women's email servers allows attackers to send fraudulent emails appearing to come from official government accounts.21 August 20252 min
- 012CybersecurityReportsEmail Authentication Vulnerability in Legislative Assembly of Costa RicaA vulnerability in the Legislative Assembly of Costa Rica's email servers allows attackers to send fraudulent cryptocurrency-related campaigns from official addresses.23 June 20252 min
- 013CybersecurityReportsEmail Authentication Vulnerability in Public Prosecution Office of OmanA critical vulnerability in the Public Prosecution Office of Oman's email servers allows attackers to send fraudulent cryptocurrency-related campaigns from official addresses.21 June 20252 min
- 014CybersecurityReportsEmail Authentication Vulnerability in National Police of EcuadorA flaw in the Ecuadorian National Police email servers allows attackers to send fraudulent emails appearing to come from official government accounts.14 April 20252 min