HackerOne Bug Bounty Disclosure: -use-after-free-read-of-the-freed-referer-buffer-in-curl-easy-setopt-curlopt-referer-stale-heap-bytes-transmitted-in-an-outbound-referer-heade-ferdinandus-lau-tae - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-use-after-free-read-of-the-freed-referer-buffer-in-curl-easy-setopt-curlopt-referer-stale-heap-bytes-transmitted-in-an-outbound-referer-heade-ferdinandus-lau-tae-2/
RedPacket Security
HackerOne Bug Bounty Disclosure: -use-after-free-read-of-the-freed-referer-buffer-in-curl-easy-setopt-curlopt-referer-stale-heap…
Companycurl
HackerOne Bug Bounty Disclosure: libcurl-secure-cookie-flag-bypasses-the-fix-and-leaks-over-http-wonyoung-jung - https://www.redpacketsecurity.com/hackerone-bugbounty-disclosure-libcurl-secure-cookie-flag-bypasses-the-fix-and-leaks-over-http-wonyoung-jung/
RedPacket Security
HackerOne Bug Bounty Disclosure: libcurl-secure-cookie-flag-bypasses-the-fix-and-leaks-over-http-wonyoung-jung - RedPacket Security
Companycurl
[PANZER] - Ransomware Victim: SweetRush - https://www.redpacketsecurity.com/panzer-ransomware-victim-sweetrush/
RedPacket Security
[PANZER] - Ransomware Victim: SweetRush - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[INCRANSOM] - Ransomware Victim: magnals[.]com - https://www.redpacketsecurity.com/incransom-ransomware-victim-magnals-com/
RedPacket Security
[INCRANSOM] - Ransomware Victim: magnals[.]com - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CVE Alert: CVE-2026-106038 - kvcache-ai - Mooncake - https://www.redpacketsecurity.com/cve-alert-cve-2026-106038-kvcache-ai-mooncake/
RedPacket Security
CVE Alert: CVE-2026-106038 - kvcache-ai - Mooncake - RedPacket Security
Mooncake Store master through 0.3.13.post1 contains a missing authentication vulnerability that allows unauthenticated attackers to force-delete any object
CVE Alert: CVE-2026-105840 - Uwe Ohse - lrzsz - https://www.redpacketsecurity.com/cve-alert-cve-2026-105840-uwe-ohse-lrzsz/
RedPacket Security
CVE Alert: CVE-2026-105840 - Uwe Ohse - lrzsz - RedPacket Security
lrzsz before 0.13.0 contains a path traversal vulnerability in the lrz receive utility's restricted mode that allows malicious ZMODEM senders to write files
CVE Alert: CVE-2026-105920 - Kusalkasilva - Learning-Management-System - https://www.redpacketsecurity.com/cve-alert-cve-2026-105920-kusalkasilva-learning-management-system/
RedPacket Security
CVE Alert: CVE-2026-105920 - Kusalkasilva - Learning-Management-System - RedPacket Security
A vulnerability was determined in Kusalkasilva Learning-Management-System up to ffeb873f8803f1e9664384ff75000c7da45466d2. The impacted element is an unknown
CVE Alert: CVE-2026-105841 - Uwe Ohse - lrzsz - https://www.redpacketsecurity.com/cve-alert-cve-2026-105841-uwe-ohse-lrzsz/
RedPacket Security
CVE Alert: CVE-2026-105841 - Uwe Ohse - lrzsz - RedPacket Security
lrzsz before 0.13.0 contains an OS command injection vulnerability in the lrz receive utility's pipe mode that allows remote senders to execute commands by
CVE Alert: CVE-2026-106040 - kvcache-ai - Mooncake - https://www.redpacketsecurity.com/cve-alert-cve-2026-106040-kvcache-ai-mooncake/
RedPacket Security
CVE Alert: CVE-2026-106040 - kvcache-ai - Mooncake - RedPacket Security
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk
CVE Alert: CVE-2026-104073 - netbox-community - netbox - https://www.redpacketsecurity.com/cve-alert-cve-2026-104073-netbox-community-netbox/
RedPacket Security
CVE Alert: CVE-2026-104073 - netbox-community - netbox - RedPacket Security
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom
CVE Alert: CVE-2026-83550 - Red Hat - Multicluster Global Hub - https://www.redpacketsecurity.com/cve-alert-cve-2026-83550-red-hat-multicluster-global-hub/
RedPacket Security
CVE Alert: CVE-2026-83550 - Red Hat - Multicluster Global Hub - RedPacket Security
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A
CVE Alert: CVE-2026-85523 - Felisify Information Technologies Industry and Trade Inc. - SambaBox - https://www.redpacketsecurity.com/cve-alert-cve-2026-85523-felisify-information-technologies-industry-and-trade-inc-sambabox/
RedPacket Security
CVE Alert: CVE-2026-85523 - Felisify Information Technologies Industry and Trade Inc. - SambaBox - RedPacket Security
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and
[QILIN] - Ransomware Victim: Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi - https://www.redpacketsecurity.com/qilin-ransomware-victim-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi/
RedPacket Security
[QILIN] - Ransomware Victim: Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: BNYH - https://www.redpacketsecurity.com/qilin-ransomware-victim-bnyh/
RedPacket Security
[QILIN] - Ransomware Victim: BNYH - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[PANZER] - Ransomware Victim: EDFelectronics - https://www.redpacketsecurity.com/panzer-ransomware-victim-edfelectronics/
RedPacket Security
[PANZER] - Ransomware Victim: EDFelectronics - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[UMBRA] - Ransomware Victim: Beni Suef Technological University – BTU - https://www.redpacketsecurity.com/umbra-ransomware-victim-beni-suef-technological-university-btu/
RedPacket Security
[UMBRA] - Ransomware Victim: Beni Suef Technological University – BTU - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[VEXY RANSOMWARE] - Ransomware Victim: KOOKABARRA JUICE - https://www.redpacketsecurity.com/vexy-ransomware-ransomware-victim-kookabarra-juice/
RedPacket Security
[VEXY RANSOMWARE] - Ransomware Victim: KOOKABARRA JUICE - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CVE Alert: CVE-2026-101258 - Red Hat - Red Hat Enterprise Linux 10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-101258-red-hat-red-hat-enterprise-linux-10/
RedPacket Security
CVE Alert: CVE-2026-101258 - Red Hat - Red Hat Enterprise Linux 10 - RedPacket Security
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell
CVE Alert: CVE-2026-106062 - Red Hat - Red Hat Enterprise Linux 10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-106062-red-hat-red-hat-enterprise-linux-10/
RedPacket Security
CVE Alert: CVE-2026-106062 - Red Hat - Red Hat Enterprise Linux 10 - RedPacket Security
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height,
[QILIN] - Ransomware Victim: EPTISA - https://www.redpacketsecurity.com/qilin-ransomware-victim-eptisa/
RedPacket Security
[QILIN] - Ransomware Victim: EPTISA - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[TERMITE] - Ransomware Victim: Aon - https://www.redpacketsecurity.com/termite-ransomware-victim-aon/
RedPacket Security
[TERMITE] - Ransomware Victim: Aon - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating