1. X
  2. CyStack
Log inSign up
CyStack
253 posts
Image
user avatar
CyStack
@CyStackSecurity
An innovative #Cybersecurity company provides comprehensive and tailored solutions to combat security threats. Product: @whitehubnet @lockerpm
Hà Nội, Việt Nam
cystack.net
Joined September 2017
216
Following
3,676
Followers
RepliesRepliesMediaMedia
  • user avatar
    CyStack
    @CyStackSecurity
    Aug 4
    CVE-2026-40691: Heap overflow in Unbound, one of the most widely deployed open-source DNS resolvers with 4.7k GitHub stars. Send one DNSCrypt query over TCP. Reply overflows the heap. Resolver crashes. Users behind it lose DNS. Patched in v1.25.2. Found by a CyStack researcher.
    Image
  • user avatar
    CyStack
    @CyStackSecurity
    Jul 30
    🚨 SECURITY ADVISORY CyStack researchers responsibly disclosed 6 vulnerabilities across Oracle VM VirtualBox, Coherence & MySQL Server, all fixed in Oracle's July 2026 Critical Patch Update. For more, visit cystack.net/disclosures #CyStack #Oracle #CyberSecurity #InfoSec
    Image
  • user avatar
    CyStack
    @CyStackSecurity
    Jul 28
    Amazing work from one of our researcher, Mr. Trung Nguyen. We discovered 2 vulnerabilities that affected recent versions of Apple's macOS. One of which is an LPE unprivileged app escalates to root. The other related to memory handling flaw in HFS: remote kernel panic and kernel
    user avatar
    Ping
    @everping
    Jul 28
    Two of my bugs got fixed in Apple's July 2026 macOS updates. The one I'd point to is #CVE-2026-43749, a local privilege escalation, unprivileged user to root, on a fully patched macOS with SIP on. Also credited on #CVE-2026-43682 (kernel memory bug in HFS).
    Image
    00:00
  • user avatar
    CyStack
    @CyStackSecurity
    Jul 23
    CVE-2026-55852: TarSlip in Frappe Framework, the core platform behind ERPNext with 10.4k GitHub stars. Import a malicious package. The tar archive contains ../ paths that escape the target directory. Arbitrary file write on the server. Full RCE. Patched in v16.23.0 and
    Image
  • user avatar
    CyStack
    @CyStackSecurity
    Jul 21
    CVE-2026-54572: Symlink path traversal in rclone, the cloud sync tool with 58.5k GitHub stars. Sync from a malicious remote with --links. Rclone writes arbitrary files on the victim's machine. Overwrite authorized_keys or crontab and you have RCE. Plus a setuid binary planting
    Image

Log in or sign up for X

See what’s happening and join the conversation

Continue with phone
or
Log in with username or email
Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Advertisement
Advertisement