Skip to content
The Nexus
DossierENTITY

remote code execution (RCE)

Coverage of remote code execution (RCE) in the Nexus archive.

Earliest in view: Apr 9 · 12:57 UTCMost recent: Jul 27 · 23:49 UTC
Co-mentioned in this coverage
Recent coverage
  • SECURITYJul 27 · 23:49 UTCBLEEPING COMPUTER
    Hackers target US firms in FastJson RCE zero-day attacks

    Hackers are exploiting a vulnerability in the FastJson open-source Java library to launch remote code execution (RCE) attacks against US firms. The attacks allow remote code execution without requiring user interaction or elevated privileges.

  • SECURITYJul 25 · 08:34 UTCTHE HACKER NEWS
    Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

    Security researcher Yuhang Wu at depthfirst published a proof-of-concept exploit for a GitLab vulnerability that allows authenticated users to execute commands as 'git' on unpatched self-managed GitLab 18.11.3 servers. The exploit involves committing two crafted Jupyter notebooks and requesting their diff, requiring no administrator rights or victim interaction.

  • SECURITYJun 10 · 05:08 UTCTHE HACKER NEWS
    Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS

    Cybersecurity researchers identified six vulnerabilities in protobuf.js, a JavaScript and TypeScript implementation of Protocol Buffers, which could allow remote code execution (RCE) and denial-of-service (DoS) attacks in Node.js applications through malicious schemas or payloads.

  • SECURITYJun 9 · 14:27 UTCBLEEPING COMPUTER
    New Veeam vulnerability exposes backup servers to RCE attacks

    Veeam has released security updates to address a critical vulnerability in its Backup & Replication software that could allow attackers to execute remote code on domain-joined backup servers. The flaw poses a risk of remote code execution (RCE) exploitation.

  • SECURITYApr 20 · 10:42 UTCTHE HACKER NEWS
    Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain

    Cybersecurity researchers identified a critical design flaw in the Model Context Protocol (MCP) that could enable remote code execution (RCE), posing significant risks to systems using vulnerable MCP implementations and threatening the AI supply chain.

  • SECURITYApr 16 · 13:05 UTCTHE HACKER NEWS
    ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-Year-Old Excel RCE and 15 More Stories

    The ThreatsDay Bulletin highlights multiple cybersecurity threats, including a Microsoft Defender 0-Day vulnerability, a SonicWall brute-force attack, and a 17-year-old Excel remote code execution (RCE) flaw. The article emphasizes the persistence of ancient vulnerabilities, supply chain risks, and creative hacking tactics.

  • SECURITYApr 13 · 15:42 UTCHACKER NEWS
    Stealthy RCE on Hardened Linux: Noexec and Userland Execution PoC

    A proof-of-concept (PoC) demonstrates a stealthy remote code execution (RCE) vulnerability on hardened Linux systems, exploiting Noexec and userland execution mechanisms. The article details techniques bypassing security measures, raising concerns about system vulnerabilities.

  • SECURITYApr 9 · 12:57 UTCTHE HACKER NEWS
    ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache RCE and 18 More Stories

    The ThreatsDay Bulletin highlights a hybrid P2P botnet, a 13-year-old Apache RCE vulnerability resurfacing, and 18 other security issues. The report emphasizes overlooked vulnerabilities, questionable security practices, and attackers exploiting trusted platforms.

remote code execution (RCE) · Dossier · The Nexus