Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gonepivoting
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
gonepivoting
10mo ago
Hey, researcher from Wiz here - we definitely didn't discover these vulns and all the credit goes to Lachlan Davidson. We have been investigating these vulns throughout the day and decided not to disclose the full extent of our conclus
2.
▲
by
gonepivoting
10mo ago
Just to simplify this - our exploitation tests so far have shown that a standard Next.js application created via create-next-app and built for production is vulnerable to CVE-2025-66478 without any specific code modifications by the develop
3.
▲
Critical RCE Vulnerabilities in React and Next.js
(wiz.io)
134 points
by
gonepivoting
10mo ago
|
77 comments
4.
▲
by
gonepivoting
10mo ago
We're monitoring this activity as well and updating the list of affected packages here: https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-... Currently reverse engineering the malicious payload and will
5.
▲
by
gonepivoting
1y ago
Very cool - it reminds me of some of the programming-language-like magic systems in Sanderson's books, especially AonDor in Elantris and Lines in The Rithmatist.