The Register reports that researchers found two characters that can trick Chromium…

The Register reports that researchers found two characters that can trick Chromium browsers into showing lookalike URLs as genuine web addresses. The issue affects Chromium-based browsers such as Chrome and Edge, and the fake domains can bypass browser safety checks. Windows users should update their browser when a fix is available and be careful with links that look like familiar sites but use unusual characters.

The RegisterTwo characters open up a world of typosquatting opportunities in Chromium browsers

Source: theregister.com

More in this rubric
all →

SecurityWeek reports that Citrix is urging immediate patching of a critical NetScaler vulnerability that could lead to remote code execution or denial of service. The flaw affects NetScaler ADC and NetScaler Gateway appliances in specific SAML configurations, as well as Secure Private Access Hybrid deployments. Citrix says it is not aware of unmitigated exploits, but users should update to the fixed versions as soon as possible.

SecurityWeekCitrix Urges Immediate Patching of Critical NetScaler Vulnerability

Source: securityweek.com

SecurityWeek reports that TP-Link has disclosed five vulnerabilities in its Aginet line of ISP-managed mesh systems, routers and modems. The bugs can let an attacker on the same network take over an affected device, create a super-administrator account, enable SSH access, or recover passwords and Wi-Fi credentials from configuration files. TP-Link says firmware updates are distributed by ISPs, so users should check the device management interface or app for updates and contact their ISP if none are available.

SecurityWeekTP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws

Source: securityweek.com

Help Net Security reports that attackers have already started trying to exploit a critical arbitrary file access flaw in Atlassian’s self-managed Data Center products, including Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye. Atlassian urged customers to upgrade to a fixed version as soon as possible. Those who cannot update quickly should remove vulnerable instances from the internet or block external access, and check access logs for signs of compromise.

Help Net SecurityExploitation attempts against critical Atlassian flaw have begun (CVE-2026-21589)

Source: helpnetsecurity.com

5,454 members already hereReading, writing, commenting and voting. 0 verified · 179 joined this year