Aggregator
CVE-2026-52719 | GStreamer gst-plugins-bad out-of-bounds (EUVD-2026-36798 / Nessus ID 321147)
CVE-2026-52720 | GStreamer librfb heap-based overflow (EUVD-2026-36803 / Nessus ID 321144)
CVE-2026-52722 | GStreamer VMnc Decoder integer overflow (EUVD-2026-36804 / Nessus ID 321139)
Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT
AtlasRAT is being delivered through a fake Flash Player installer that looks harmless but can give attackers remote control of a Windows computer. The campaign abuses a familiar software name to lower a victim’s guard, then loads much of its malicious code directly into memory, where it is harder for traditional file-based checks to catch. […]
The post Fake Flash Player Installer Uses Microsoft-Themed Certificate to Deploy AtlasRAT appeared first on Cyber Security News.
Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root
Home Assistant’s FFmpeg integration recently came under scrutiny after researchers demonstrated that unsafe argument handling in the Wyoming Assist satellite feature could be exploited to steal Supervisor tokens and ultimately execute commands as root on the host system. The issue arises not from FFmpeg’s core parsing logic but rather from how Home Assistant incorporates attacker-controlled […]
The post Home Assistant FFmpeg Flaw Lets Attackers Steal Supervisor Tokens and Execute Code as Root appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.