Checkmarx Zero

408 posts

Checkmarx Zero banner
Checkmarx Zero

Checkmarx Zero

@CheckmarxZero

Checkmarx Zero Working to Keep the Open Source Ecosystem Safe https://t.co/3yB6kPHV9B

Katılım Nisan 2022
18 Takip Edilen242 Takipçiler
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
🚨 Critical CVE-2026-66066 found in Ruby on Rails may let unauthenticated users read arbitrary files from the server and achieve #RCE. It affects applications that use libvips for Active Storage image processing and allow image uploads from untrusted users. This #CVE covers default configurations of active storage in versions up to 7.2.3.1, 8.0.5, and 8.1.3. Non default configurations are affected from 6.0.0 prior to 6.1.7.10. Stay safe by updating Rails to 7.2.3.2, 8.0.5.1 or 8.1.3.1. devhub.checkmarx.com/cve-details/CV…
English
0
1
7
559
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
Come test your skill at secure code review, and learn to spot flaws in source! Checkmarx Zero is running 4 sessions of our "AppSec Quiz Gauntlet: Spot the Vulnerability" pod game at #AppSecVillage for #DEFCON with our researchers Tal Folkman, Alon Lerner, and Darren Meyer No need to spend the whole time, most player spend about 20 minutes. Stop by and chat, hang out, and test your skill! 1> Friday (7. Aug) 13:00–15:00 2> Saturday (8. Aug) 13:00–15:00 3> Saturday (8. Aug) 15:00–17:00 4> Sunday (9. Aug) 11:00–13:00 #AppSec #ApplicationSecurity #HackerSummerCamp
Checkmarx Zero tweet media
English
0
2
3
80
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
The #ChainVeil npm malware campaign seems to have a new variant targeting the Vite ecosystem. This #ViteVenom variant uses the same C2 infrastructure and tactics, but further evolves the payload and delivery. Our researcher, Pavan, provides analysis, IOC, and defensive rules for your organization: checkmarx.com/zero-post/sequ…
English
0
0
0
86
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
If you're on the hook for securing MCP servers (whether you're consuming, producing, or deploying them) then you should check out Ricardo Gonçalves' talk from this year's #DevWorld in Amsterdam The Model Context Protocol: A Deep Dive into the New AI Security Attack Surface on YouTube: youtube.com/watch?v=_fAH3f…
YouTube video
YouTube
English
0
0
0
158
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
It's always nice to see our work cited in academic research! Two recent works are citing our work on HITL Dialog Forging (aka "Lies in the Loop"), which explains how the "human in the loop" verification of AI chatbots and assistants can be subverted to serve an attacker. First, we have: Modular and agentic AI design, jailbreaking, and scheming behaviours as challenges to the EU AI Act. Law, Innovation and Technology, 18(1), 141–163. Henriksen, T. Ø., & Hoffmann, T. (2026). doi.org/10.1080/175799… And then we have the pre-publication What You Approve Is What Executes: Consent Integrity for Black-Box LLM Agents. Preprint. IEEE conference format. Xiaoqi Weng (2026). doi.org/10.48550/arXiv…
English
0
0
1
89
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
Checkmarx Zero uncovered and helped take down a PyPI malware campaign targeted at Telegram bot developers; we're referring to it as "Operation Navy Ghost". Organizations use bots on the Telegram messaging service for everything from customer service to transaction support, and attackers have paid attention — Operation Navy Ghost attempted to promote forks of an extremely well-known Telegram framework (pyrogram), and achieved some success in doing so. Command and control uses Telegram itself, making it difficult to block for organizations that use Telegram itself for business purposes. checkmarx.com/zero-post/oper… #Telegram #pyrogram #PyPI #SupplyChainSecurity
English
0
0
0
95
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
🚨 CVE-2026-44914 (High) affects Apache NiFi versions 1.12.0 through 2.9.0. The vulnerability stems from missing authorization enforcement that allows users with general write access to add Restricted components when replacing Process Groups, bypassing the elevated permissions normally required, and enabling actions beyond intended privileges. Upgrading to Apache NiFi 2.9.0 is the recommended mitigation, as it removes the framework’s implementation of Restricted status authorization. More details: devhub.checkmarx.com/cve-details/CV…
English
0
0
2
89
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
Another day, another npm malware campaign. Checkmarx Zero researcher Pavan Guidmalla and team discovered ChainViel: a pernicious campaign with an unblockable command and control (C2) system built on the public blockchain. All affected packages have been removed from npm, but there's a good chance more will appear. Read for complete IOC, blocking rules, and a deep dive into how the malware, C2, and obfuscation systems work. checkmarx.com/zero-post/chai…
English
0
3
3
254
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
AI doesn't replace established security testing tools, but it can augment them — if you're thoughtful about how you do so. We've been in the lab for months working on generating real data on various approaches that improve overall accuracy (not just reducing FPs, but reducing FNs / increasing coverage too). There's exciting news coming soon, but meanwhile we thought it might be nice to share how we built our research system to make sure we're making data-driven decisions about results quality. There are already too many vendors building hype and then trying to cherry-pick data to justify it, we don't want to be that. So we figured out a way to assess scan accuracy that's highly repeatable, reflects real-world applications, and introduces as little error as possible while still being affordable to run. And with that process in place, we're seeing dramatic AI + SAST accuracy improvements in the lab, some of which will be coming to our product soon! Learn about our approach and what we're seeing in the data: checkmarx.com/zero-post/proo…
English
0
2
4
179
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
🚨 CVE-2026-44578 just dropped with a CVSS score of 8.6 affecting Next.js versions from 13.4.13 prior to 15.5.16 and 16.0.0 prior to 16.0.5. This fixes a Server-Side Request Forgery vulnerability that allows an unauthenticated attacker to retrieve internal content of any host reachable via port 80. The issue is related to how Next.js deals with HTTP/1.1 WebSocket upgrade handler impacting self-hosted applications that are directly exposed to the internet. This vulnerability is fixed in v15.5.16 and v16.2.5. More details: devhub.checkmarx.com/cve-details/cv…
English
0
0
1
113
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
🚨 Exim v4.99.3 is out, patching a critical use-after-free vulnerability. CVE-2026-45185 allows an unauthenticated attacker to achieve #RCE, affecting all versions prior to v4.99.3. #AppSec teams should pay close attention. Exim often sits as a core dependency under other mail-handling stacks and appliances, meaning the blast radius extends well past direct deployments. Be sure to upgrade to v4.99.3 devhub.checkmarx.com/cve-details/cv…
English
0
0
1
170
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
What can you learn from n8n's OverDoS vulnerability? Mainly how to handle design decisions around implementing OpenID's DCR (Dynamic Client Registration). If you have an OAuth 2.0 enabled application, you might want DCR: but you also have to think it through! See more on our first-ever Substack post: "OverDoS: How OpenID bit n8n" -- checkmarxzero.substack.com/p/overdos-how-… We'll show you how reasonable design decisions led to potential for a massive denial of service, and how the folks at n8n made small changes to dramatically reduce the risk.
English
0
0
1
55
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
Make sure you've patched #n8n to avoid #OverDoS, a vulnerability that allows attackers to take down any n8n instance they can connect to. Three safe patch levels, depending on your branch: 1.123.32; 2.18.1; 2.17.4 Checkmarx Zero researcher Ori Ron reported this unauthenticated DoS issue to n8n, who responded promptly with a fix and coordinated disclosure as #CVE-2026-42236 (CVSS v4.0 = 8.7). Root cause is the implementation of Dynamic Client Registration (#DCR), which makes the vulnerability very difficult to mitigate sufficiently; we're recommending that you prioritize patch deployment, **especially if your n8n server is reachable on the public internet**. Details, tactics, demo, and more information available on the Checkmarx Zero blog: checkmarx.com/zero-post/n8n-…
English
0
0
3
128
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
#CopyFail has been added to the CISA KEV; and it's an AppSec consideration that too many practitioners are ignoring. The Linux vulnerability (CVE-2026-31431) can allow for privesc from unprivileged to root, and is seeing active exploitation. AppSec teams sometimes ignore such things as an "ops problem". But if you're using containers to distribute your app, that's a clear #SoftwareSupplyChain matter, and should definitely be in scope for AppSec teams. But look further as well: even if you're running your application on a more traditional server, or on something like EC2 instances, don't think of host OS vulnerabilities as purely an ops problem. The OS your apps run on top of massively affects the operational safety and security of the application. You're a stakeholder. Even if ops "owns" the patching of the OS, you should have a seat at that table, influencing priority and tracking patching progress.
English
0
0
0
176
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
A Critical unauthenticated #RCE via Import Authorization Bypass (CVE-2026-41679) was found in #Paperclip with a CVSS score of 10.0. The issue was found in @paperclipai/server npm package affecting all versions prior to v2026.416.0 and canary/v2026.410.0-canary.1. The vulnerability was disclosed with a working PoC that chains 6 API requests leading to full control of the paperclip server OS. Stay safe by upgrading paperclipai to v2026.416.0 or `canary/v2026.424.0-canary.0`. In times where agents are given broad permissions to run systems, it's more important than ever to know what you're running, who built it, and whether the front door is actually locked. More details here: devhub.checkmarx.com/cve-details/CV…
English
0
1
2
174
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
Come meet Erez Yalon and Darren Meyer at #OWASP's #SnowFROC conference this Friday! At 2pm local time in #Denver, they'll be on stage talking about breaking #MCP in Agentic AI systems.
Checkmarx Zero tweet mediaCheckmarx Zero tweet media
English
0
0
1
107
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
With the #Axios supply chain issue last week, you might have missed a couple of other supply chain issues. #LastWeekInAppSec included: 🔨 rapid exploitation of a code injection + RCE in #Langflow AI platform (#CVE-2026-33017) 🕵️‍♂️ a clever malicious #Python package (#Telnyx) that used a valid .wav audio file to hide its payload. ▷ Read the details: checkmarx.com/zero-post/rapi… #AppSec #DevSecOps #MaliciousPackage #SupplyChainSecurity #DevOps #LLM #AISecurity
English
0
0
0
106
Checkmarx Zero
Checkmarx Zero@CheckmarxZero·
A critical path traversal vulnerability (CVE-2025-15036) has been identified in MLflow with a CVSS score of 9.6. The extract_archive_to_dir function within mlflow/pyfunc/dbconnect_artifact_cache.py lacks validation of tar member paths during extraction. An attacker with control over a tar.gz file can exploit this to overwrite arbitrary files or gain elevated privileges, potentially escaping the sandbox directory entirely. This is especially dangerous in multi-tenant or shared cluster environments, and affects all versions before v3.7.0. Stay safe by upgrading to MLflow v3.7.0 or later and restricting access to untrusted tar.gz archives until you've patched. Path Traversal in mlflow - CVE-2025-15036 devhub.checkmarx.com/cve-details/cv…
English
0
0
1
188