Entry Thumbnail

Norton Secure VPN Installation Insecure Operation On Junction Privilege Escalation Vulnerability

CVE-2025-58074 A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges. The versions below were either tested or verified […]

Posted by
Entry Thumbnail

Inspektor Gadget Security Audit

In early 2026, Shielder was hired by OSTIF to perform a security audit of Inspektor Gadget, an eBPF-based framework that provides powerful and flexible observability tools for Kubernetes and Linux hosts. **Today, we are publishing the full report in our dedicated repository**. Inspektor Gadget is both a framework and a […]

Posted by
Entry Thumbnail

Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold

# Three Bugs Walk Into a PDF: Prototype Pollution, Served Cold **Table of Contents** ## TL;DR In April 2026, Adobe disclosed three critical security issues (CVE-2026-34621,CVE-2026-34622,CVE-2026-34626) affecting Acrobat DC, Acrobat Reader DC, and Acrobat 2024. According to Adobe’s advisories, these vulnerabilities could allow attackers to execute arbitrary code and leak […]

Posted by
Entry Thumbnail

Carrot disclosure: Forgejo

Since Fedora moved from Pagure to Forgejo, I finally had an incentive to take a good look at Forgejo’s security posture. The results aren’t pretty to be honest: SSRF in a lot of places, no CSP/Truste-Types, a bit of ghetto templating in javascript, cryptographic malpractices, overlooks in the authentication mechanisms […]

Posted by
Entry Thumbnail

VECT: Ransomware by design, Wiper by accident

`–fast,` `–medium, and` `–secureflags present across` **VECT Ransomware** is a Ransomware-as-a-Service (RaaS) program that made its first appearance in December 2025 on a Russian-language cybercrime forum. After claiming their first two victims in January 2026, the group got back into the public eye due to an announcement of a partnership […]

Posted by