Aggregator
CVE-2022-37453 | Softing OPC UA C++ SDK up to 6.9 Array buffer overflow (EUVD-2022-40079)
CVE-2022-37406 | Ricoh Aficio SP 4210N prior 1.05 cross site scripting (EUVD-2022-40039)
CVE-2022-37391 | Foxit PDF Reader AcroForms deletePages use after free (ZDI-22-1063 / EUVD-2022-40025)
Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253)
CISA has added CVE-2026-20253, a critical, remotely exploitable vulnerability in Splunk Enterprise, to its Known Exploited Vulnerabilities catalog, and ordered US federal civilian agencies to apply mitigations by June 21, 2026. In-the-wild exploitation has also been confirmed by the vendor and Resecurity, who said that its potential for full system compromise should push organizations to prioritize patching and review systems for indicators of compromise such as: Requests containing path traversal sequences (../) PostgreSQL connection parameters … More →
The post Unauthenticated RCE in Splunk Enterprise under active attack (CVE-2026-20253) appeared first on Help Net Security.
Forget traffic lights, Google’s reCAPTCHA may ask for hand gestures
Google has introduced hand gesture verification for reCAPTCHA, a new method for verifying that a user is human. Google’s reCAPTCHA is part of Google Cloud Fraud Defense, a fraud and abuse prevention platform for bot, account, and transaction protection. It uses risk analysis and challenge-based verification to help organizations identify automated activity and suspicious behavior. The service is commonly deployed on login pages, registration forms, password reset pages, and checkout systems, where it can allow … More →
The post Forget traffic lights, Google’s reCAPTCHA may ask for hand gestures appeared first on Help Net Security.