Saturday, May 2, 2026
HomeUncategorized

Uncategorized

WinRAR Directory Vulnerability Allows Arbitrary Code Execution via Malicious File

A critical security vulnerability has been discovered in RARLAB's popular WinRAR archiving software that allows remote attackers to execute arbitrary code on affected systems through directory traversal exploitation. The vulnerability, designated as CVE-2025-6218 with a CVSS score of 7.8, affects WinRAR installations and requires...

Aviatrix Cloud Controller Authentication Vulnerabilities Allows Remote Code Execution by Attackers

A two severe security vulnerabilities in Aviatrix Controller, a popular Software-Defined Networking (SDN) utility used to create links between different cloud vendors and regions. The vulnerabilities, tracked as CVE-2025-2171 and CVE-2025-2172, allowed researchers to bypass authentication and gain root-level command execution on a fully...

New Echo Chamber Attack Hacks Most AI Models by Exploiting Indirect References

A sophisticated new jailbreak technique that successfully bypasses the safety mechanisms of leading artificial intelligence models with alarming effectiveness. The so-called "Echo Chamber Attack" achieved success rates exceeding 90% against major AI systems including GPT-4 variants and Google Gemini models, raising serious concerns about...

Notepad++ Vulnerability Allows Attacker to Take Full Control of System – PoC Released

A critical privilege escalation vulnerability has been discovered in Notepad++ v8.8.1 installer that enables unprivileged users to gain SYSTEM-level privileges through exploiting insecure executable search paths. The vulnerability, tracked as GHSA-9vx8-v79m-6m24 and published by donho three days ago, affects the popular text editor's installer...

Google Uses GenAI to Tackle Evolving Prompt Injection Vectors

Google has unveiled a comprehensive security framework to combat the rising threat of indirect prompt injection attacks targeting generative AI systems, introducing multiple layers of protection across its Gemini platform. The tech giant's latest security measures represent a significant escalation in the ongoing battle...

IPFire 2.29 Core Update 194 Launches With Enhanced VPN Protocol Support

IPFire has announced the release of Core Update 195 for IPFire 2.29, marking a significant milestone with the introduction of native WireGuard VPN support alongside various system improvements and security enhancements. This long-awaited update transforms the open-source firewall distribution by integrating modern VPN capabilities...