-APT28 jumps on new Office zero-day
-A look at a KGB internal memo on viruses
-Survey of legal threats against researchers and infosec reporters
-Metro4Shell attacks
-How RRLP and LLP tracking works
-GatewayToHeaven vuln
-Unfixable Chrome URL bug
-APT28 jumps on new Office zero-day
-A look at a KGB internal memo on viruses
-Survey of legal threats against researchers and infosec reporters
-Metro4Shell attacks
-How RRLP and LLP tracking works
-GatewayToHeaven vuln
-Unfixable Chrome URL bug
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package #HackerNews (Feb 3)
thehackernews.com/2026/02/hack...
Hackers Exploit Metro4Shell RCE Flaw in React Native CLI npm Package #HackerNews (Feb 3)
thehackernews.com/2026/02/hack...
"Critical React Native Vulnerability Exploited in the Wild" #bolhasec
"Critical React Native Vulnerability Exploited in the Wild" #bolhasec
https://www.tecmundo.com.br/seguranca/410436-falha-critica-no-react-native-e-explorada-ha-mais-de-mes-por-criminosos.htm?utm_source=flipboard&utm_medium=activitypub
Posted into Tecnologia @tecnologia-FlipboardBR
https://www.tecmundo.com.br/seguranca/410436-falha-critica-no-react-native-e-explorada-ha-mais-de-mes-por-criminosos.htm?utm_source=flipboard&utm_medium=activitypub
Posted into Tecnologia @tecnologia-FlipboardBR
CVE-2025-11953 (CVSS スコア 9.8) として追跡され、 11 月初旬に公開されたこのバグは、毎週約 200 万回ダウンロードされる、非常に人気の高い React Native Community CLI NPM パッケージ (@react-native-community/cli) に影響します。
これは、メンテナンス性を向上させるためにオープンソース フレームワークから抽出された React Native Community CLI プロジェクトの一部であり、アプリ構築用のコマンドライン ツールのセットを提供...
CVE-2025-11953 (CVSS スコア 9.8) として追跡され、 11 月初旬に公開されたこのバグは、毎週約 200 万回ダウンロードされる、非常に人気の高い React Native Community CLI NPM パッケージ (@react-native-community/cli) に影響します。
これは、メンテナンス性を向上させるためにオープンソース フレームワークから抽出された React Native Community CLI プロジェクトの一部であり、アプリ構築用のコマンドライン ツールのセットを提供...
Elle affecte un paquet téléchargé 2 millions de fois par semaine sur npm.
Tous les détails par ici 👇
- www.it-connect.fr/react-native...
#infosec #react #cybersecurite #cve
Elle affecte un paquet téléchargé 2 millions de fois par semaine sur npm.
Tous les détails par ici 👇
- www.it-connect.fr/react-native...
#infosec #react #cybersecurite #cve
Researchers also observed overlap with Metro4Shell exploitation campaigns.
Cloud misconfigurations continue to fuel persistent threats.
#CyberSecurity #CloudSecurity
Researchers also observed overlap with Metro4Shell exploitation campaigns.
Cloud misconfigurations continue to fuel persistent threats.
#CyberSecurity #CloudSecurity
👉 sctocs.com/hackers-expl...
👉 sctocs.com/hackers-expl...
📌 Link all'articolo : www.redhotcyber.com/post/met...
#redhotcyber #news #vulnerabilita #meteo4shell #reactnative #sicurezzainformatica #cve202511953 #endpointhttp
📌 Link all'articolo : www.redhotcyber.com/post/met...
#redhotcyber #news #vulnerabilita #meteo4shell #reactnative #sicurezzainformatica #cve202511953 #endpointhttp
#Metro4Shell
#SoftwareSupplyChainSecurity
👇
www.bleepingcomputer.com/news/securit...
#Metro4Shell
#SoftwareSupplyChainSecurity
👇
www.bleepingcomputer.com/news/securit...
📝 Selon VulnCheck, des expl…
https://cyberveille.ch/posts/2026-02-04-exploitation-active-de-cve-2025-11953-metro4shell-sur-metro-react-native-observee-par-vulncheck/ #CVE_2025_11953 #Cyberveille
📝 Selon VulnCheck, des expl…
https://cyberveille.ch/posts/2026-02-04-exploitation-active-de-cve-2025-11953-metro4shell-sur-metro-react-native-observee-par-vulncheck/ #CVE_2025_11953 #Cyberveille
Threat actors have been observed exploiting a critical security flaw impacting the Metro Development Server in the popular "@react-native-community/cli" npm package.
Cybersecurity company VulnCheck said it first…
#hackernews #news
Threat actors have been observed exploiting a critical security flaw impacting the Metro Development Server in the popular "@react-native-community/cli" npm package.
Cybersecurity company VulnCheck said it first…
#hackernews #news
A Silent Shift From Theory to Real-World Attacks A critical React Native vulnerability once dismissed as a low-probability risk has quietly crossed into active exploitation, catching developers…
A Silent Shift From Theory to Real-World Attacks A critical React Native vulnerability once dismissed as a low-probability risk has quietly crossed into active exploitation, catching developers…
A critical vulnerability in the Metro server for React Native, tracked as CVE-2025-11953, is actively being exploited by hackers to deliver malicious payloads to both Windows and Linux systems. This flaw exposes…
A critical vulnerability in the Metro server for React Native, tracked as CVE-2025-11953, is actively being exploited by hackers to deliver malicious payloads to both Windows and Linux systems. This flaw exposes…
A new, dangerous threat is targeting developers who use React Native. Security researchers have discovered that a critical vulnerability in Metro, the default JavaScript bundler for React Native, is being actively exploited…
A new, dangerous threat is targeting developers who use React Native. Security researchers have discovered that a critical vulnerability in Metro, the default JavaScript bundler for React Native, is being actively exploited…