Feed aggregator
Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability
A vulnerability in the Border Gateway Protocol (BGP) enforce-first-as feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an unauthenticated, remote attacker to trigger BGP peer flaps, resulting in a denial of service (DoS) condition.
This vulnerability is due to incorrect parsing of a transitive BGP attribute. An attacker could exploit this vulnerability by sending a crafted BGP update through an established BGP peer session. If the update propagates to an affected device, it could cause the device to drop the BGP session and flap with the BGP peer that is forwarding this update, resulting in a DoS condition.
Cisco has released software updates that address this vulnerability. There are workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-bgp-iefab-3hb2pwtx
Cisco Secure Workload Unauthorized API Access Vulnerability
A vulnerability in the access validation of internal REST APIs of Cisco Secure Workload could allow an unauthenticated, remote attacker to access site resources with the privileges of the Site Admin role.
This vulnerability is due to insufficient validation and authentication when accessing REST API endpoints. An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint. A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-csw-pnbsa-g8WEnuy
Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability
A vulnerability in the SSL certificate handling of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to execute commands on the underlying operating system as the root user.
This vulnerability is due to insufficient validation of user-supplied input. An authenticated attacker could exploit this vulnerability by uploading a crafted certificate to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system. To exploit this vulnerability, the attacker must have valid administrative credentials.
Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tevacert-rce-RMJVEym5
Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability
A vulnerability in the BrowserBot component of Cisco ThousandEyes Enterprise Agent could have allowed an authenticated, remote attacker to execute arbitrary commands on Agents on behalf of the BrowserBot synthetics orchestration process. Cisco has addressed this vulnerability in the Cisco ThousandEyes Enterprise Agent, and no customer action is needed.
This vulnerability was due to insufficient input validation of command arguments that are supplied by the user. Prior to this vulnerability being addressed, an attacker could have exploited this vulnerability by authenticating to the ThousandEyes SaaS and submitting crafted input into the affected parameter. A successful exploit could have allowed the attacker to execute arbitrary commands within the BrowserBot container as the node user.
To exploit this vulnerability, the attacker must have valid user credentials for the ThousandEyes SaaS and the ability to manage transaction tests.
As mentioned, Cisco has addressed this vulnerability in the ThousandEyes service, and no customer action is necessary to update on-premises software or devices. There are no workarounds that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-tebbot-cmdinj-wN3yQ5gn
Former Spanish police chief, on trial for drug trafficking, claims that UK and Columbian police assisted in creating fictitious intelligence reports to hide use of intercept from encrypted phone networks Sky ECC and Anom
The 5 Google I/O Announcements That Actually Matter
Plex Is Raising Its Lifetime Subscription Price Again, to a Whopping $750
Bose's Memorial Day Deals Let You Have Concert-Quality Sound for as Low as $89
Having Android XR Glasses Support iOS Might Be Their Best Feature
Seagate Sparks Memory Sell-Off As CEO Says It Would 'Take Too Long' To Build New Factories
If an LLM is too expensive it won't be next year
Article URL: http://liveatthewitchtrials.blogspot.com/2026/05/if-llm-is-too-expensive-it-wont-be-next.html
Comments URL: https://news.ycombinator.com/item?id=48212115
Points: 2
# Comments: 0
Citor: A header-only C++20 thread pool tuned for sub-us dispatch
Article URL: https://github.com/Lallapallooza/citor
Comments URL: https://news.ycombinator.com/item?id=48212083
Points: 2
# Comments: 0
Flipper One Tech Specs
Article URL: https://docs.flipper.net/one/general/tech-specs
Comments URL: https://news.ycombinator.com/item?id=48212046
Points: 3
# Comments: 0
Marine scientists discover record number of new species
Article URL: https://abcnews.com/International/marine-scientists-discover-1100-new-species-new-record/story?id=133078227
Comments URL: https://news.ycombinator.com/item?id=48212031
Points: 2
# Comments: 0
Notched sticks to calculators: the history of counting machines
Article URL: https://lcamtuf.substack.com/p/a-brief-history-of-counting-stuff
Comments URL: https://news.ycombinator.com/item?id=48212016
Points: 2
# Comments: 0
Built a CAPTCHA alternative in C with PoW, JA4, and puzzle in complex mode
Article URL: https://github.com/captxa/captxa-backend
Comments URL: https://news.ycombinator.com/item?id=48212006
Points: 1
# Comments: 0
OSS Alternative to AWS Transfer Family Written in Elixir
Article URL: https://hex.pm/packages/sftpd
Comments URL: https://news.ycombinator.com/item?id=48211972
Points: 3
# Comments: 1
Training a small model to write better OCaml with RLVR and GRPO
Article URL: https://blog.nilenso.com/blog/2026/05/18/training-a-small-model-to-write-better-ocaml-with-rlvr-and-grpo/
Comments URL: https://news.ycombinator.com/item?id=48211945
Points: 1
# Comments: 0
Killing in Japan Stirs Fear of New Crime Rings That Recruit the Vulnerable
Article URL: https://www.nytimes.com/2026/05/20/world/asia/japan-tokuryu-crime-killing.html
Comments URL: https://news.ycombinator.com/item?id=48211941
Points: 1
# Comments: 0
