View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Zip Slip vulnerability in SonicWall Network Security Manager NSM

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Incomplete fix for CVE-2026-75936 memory-amplification denial of service in A... β€” CVE ThreatInt

  • code-projects Online Shopping System adduser.php mysqli_query sql injectionA ... β€” CVE ThreatInt

  • jofpin trape Telemetry Endpoint user.py race conditionA security vulnerabilit... β€” CVE ThreatInt

  • Unverified access point ownership in Amazon EFS CSI DriverUnverified ownershi... β€” CVE ThreatInt

  • jofpin trape user.py authorizationA weakness has been identified in jofpin tr... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Physical Memory Disclos... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Null Pointer Der... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary I/O Port Acce... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Privilege Escalation vi... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Kernel Crash via Direct... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Hard-coded Credentials ... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Arbitrary Bit Clear via... β€” CVE ThreatInt

  • PassMark PerformanceTest, BurnInTest, and OSForensics Improper Access Control... β€” CVE ThreatInt

  • jofpin trape Admin Endpoint sockets.py join_room missing authenticationA secu... β€” CVE ThreatInt

  • A Zip Slip vulnerability in the SonicWall Network Security Manager (NSM) On-P... β€” CVE ThreatInt

  • A missing authorization vulnerability in the SonicWall Network Security Manag... β€” CVE ThreatInt

  • Frappe CRM: Authentication Bypass via Logged Invitation Keys in crm/apiFrappe... β€” CVE ThreatInt

  • jofpin trape Login Endpoint stats.py missing authenticationA vulnerability wa... β€” CVE ThreatInt

  • Nango before 0.71.6 Missing Authentication RCE via runner tRPC serverNango before ... β€” CVE ThreatInt

  • The US government has taken the Xbox, Nintendo and Sega logos and made them into a campaign website called https://... β€” @GossiTheDog@cyberplace.social

  • I'm live! Weekly Update 520: The Unscripted Edition: No agenda, all impromptu, here's what I'm up to, AMA, etc... β€” @troyhunt@infosec.exchange

  • Amazon EFS CSI Driver: Unauthorized Recursive Deletion (CVE-2026-85781) β€” thehackerwire.com (discovered)

  • 153 Million Reasons to Rethink Identity Data Retention β€” securityboulevard.com (discovered)

  • How Differential Privacy Will Transform Enterprise Data Strategy β€” securityboulevard.com (discovered)

  • The Braid: Rethinking Trust, Continuity and Human-AI Systems β€” securityboulevard.com (discovered)

  • Dissecting Attacks Is Only Valuable If It Informs Controls: What the Unit 42 agentic AI investigation should change in your control set, stage by stage. β€” securityboulevard.com (discovered)

  • Why Hiring More Analysts Won’t Solve an Infinite Automation Attack β€” securityboulevard.com (discovered)

  • How Keeper Helps Enforce Zero Standing Privilege β€” securityboulevard.com (discovered)

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check