Wednesday , September 17 2025

Recent Posts

CVE-2025-43859
Request Smuggling Vulnerability in Python’s h11 HTTP Library

HTTP

A critical vulnerability tracked as CVE-2025-43859 has been disclosed in h11, a minimalist, I/O-agnostic HTTP/1.1 protocol library written in Python. Rated CVSS 9.1, the flaw could enable request smuggling attacks in applications where h11 is paired with a misconfigured or buggy HTTP proxy. “A leniency in h11’s parsing of line …

Read More »

NVIDIA Releases Security Update For GPU Driver Vulnerabilities

NVIDIA has released a software security update for its GPU Display Driver to fix multiple vulnerabilities affecting both the driver and NVIDIA VGPU Software on various operating systems. The security bulletin lists various identified Common Vulnerabilities and Exposures (CVEs). The NVIDIA GPU Driver for Linux has a vulnerability (CVE-2025-23244) that …

Read More »

‘SessionShark’ ToolKit Bypasses Microsoft Office 365 MFA

SessionShark

The SessionShark phishing kit bypasses Office 365 MFA by stealing session tokens. Experts warn about real-time attacks using fake login pages and Telegram alerts. SlashNext security experts have found a new tool, “SessionShark,” used by cyber criminals to steal Microsoft Office 365 login information. It can bypass multi-factor authentication (MFA), …

Read More »