6 Aug 2026, 15:53 UTC116 views1 reactionsread 7 August 2026 Photo
About Elevation of Privilege - NT OS Kernel (CVE-2026-42980) vulnerability. Information about this vulnerability was disclosed as part of the June Microsoft Patch Tuesday on June 9. The vulnerability was not specifically highlighted in Microsoft Patch Tuesday reviews published by VM vendors. This Microsoft Windows NT OS Kernel elevation of privilege vulnerability is caused by improper handling of integer values durin…
👍1
5 Aug 2026, 17:50 UTC166 views1 reactionsread 7 August 2026 Photo
About Remote Code Execution - ViPNet Client (BDU:2026-09885) vulnerability. The ViPNet Client software suite is designed to protect corporate users' workstations by providing secure data exchange over IP networks, controlling the network activity of applications and operating system components, and performing personal firewall functions (in the ViPNet Client for Windows version). ViPNet Client operates within the ViP…
👍1
1 Aug 2026, 00:20 UTC249 views1 reactionsread 7 August 2026 Photo
July Linux Patch Wednesday. A total of 2,017 vulnerabilities were addressed (539 in the Linux kernel and 504 in Chromium). For comparison, there were 1,888 vulnerabilities in June. Once again, a new record. Moreover, next month will most likely set another record, as 1,704 vulnerabilities have already been addressed 2.5 weeks before the August LPW. 🤷♂️ But for now, let's take a closer look at the July report. Only o…
👍1
27 Jul 2026, 07:18 UTC317 views3 reactionsread 7 August 2026 Photo
July Microsoft Patch Tuesday. In the second week of July, I was on vacation in St. Petersburg. After that, I got caught up with a bunch of other tasks, so I'm only publishing this roundup now. Better late than never, especially considering how unusual this MSPT turned out to be. 😉 In total, 571 vulnerabilities were addressed - almost three times (❗️) more than in June. There are four vulnerabilities that have been re…
❤1👍1👏1
25 Jul 2026, 20:37 UTC318 views2 reactionsread 7 August 2026 Photo
I wonder how this typo even happened? 🤔 Does Microsoft actually fill in vulnerability descriptions manually every time, retyping the text from scratch? 🙄
Though I kind of like the word "Vulernability". It sounds like something related to the ability to learn. 😅 If anyone's working on an educational project related to vulnerabilities, consider this a hint. 😉
@avleonovcom
👍2
20 Jul 2026, 20:55 UTC454 views3 reactionsread 7 August 2026 Photo
July "In the Trend of VM" (#29): Microsoft Exchange Server vulnerability. Here is my traditional monthly roundup of trending vulnerabilities, according to Positive Technologies. The previous June edition featured four vulnerabilities. This time, there's only one.
🗞 Post on Habr (rus)
🗒 Digest on the PT website (rus)
🔻 XSS - Microsoft Exchange (CVE-2026-42897). The vulnerability allows attackers to execute arbitrary…
❤2👍1
2 Jul 2026, 20:40 UTC625 views2 reactionsread 7 August 2026 Photo
About Cross Site Scripting - Microsoft Exchange (CVE-2026-42897) vulnerability. The vulnerability was fixed on May 14 outside the regular Microsoft Patch Tuesday cycle. Improper neutralization of input during web page generation (CWE-79, XSS) in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network. In practical terms, this means that a remote attacker could exploit this vulnera…
⚡1👍1
29 Jun 2026, 11:58 UTC495 views1 reactionsread 7 August 2026 Photo
June Linux Patch Wednesday. A total of 1,888 vulnerabilities (324 in the Linux kernel, and a whopping 728 in Chromium ❗️). For comparison, there were 1,638 vulnerabilities in May. The increase isn't as dramatic as it was from April to May, but it's still a new record. One of the vulnerabilities has been flagged as actively exploited in the wild:
🔻 RCE - Chromium (CVE-2026-11645). Chromium is the open-source web brow…
❤1
19 Jun 2026, 07:20 UTC499 viewsread 7 August 2026 Photo
June Microsoft Patch Tuesday. Last week I was on vacation in Veliky Novgorod, so I'm publishing this overview only now. A total of 202 vulnerabilities were addressed, approximately twice as many as in May. There are currently no vulnerabilities marked as exploited in the wild. However, there are two vulnerabilities with publicly available exploits:
🔸 RCE - HTTP.sys (CVE-2026-47291). This critical vulnerability allow…
17 Jun 2026, 23:02 UTC398 viewsread 7 August 2026 Photo
June "In the Trend of VM" (#28): Linux kernel, Microsoft Defender, and Palo Alto Networks device vulnerabilities. Presenting the traditional monthly roundup of trending vulnerabilities according to Positive Technologies. In the previous May edition, we covered four vulnerabilities. This time, there are also four vulnerabilities associated with five CVE identifiers.
🗞 Post on Habr (rus)
🗒 Digest on the PT website (ru…
16 Jun 2026, 14:02 UTC398 viewsread 7 August 2026 Photo
About Elevation of Privilege - Microsoft Defender "RedSun" (CVE-2026-41091) vulnerability. Microsoft Defender is a built-in security solution developed by Microsoft to protect the Windows operating system and user data from viruses, malware, and other cyber threats in real time. An improper link resolution vulnerability prior to file access ("link following", CWE-59) in Microsoft Defender, specifically within the Mal…
15 Jun 2026, 22:35 UTC381 viewsread 7 August 2026 Added an indicator of in-the-wild exploitation to the illustration and to the post on the website post:
"👾 On May 11, the vulnerability chain was added to VulnCheck KEV, indicating that it has been exploited in the wild."
Showing the 12 most recent of 20 posts we hold for @avleonovcom. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.