Skip to content

The Edge of the Cyber World See the latest

Author:

Cyber Security

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&

Read summary

Technology

Speedo’s new smart goggles module can track all four swim strokes

Speedo is launching a removable smart module for its Vanquisher goggles that can analyze a swimmer’s performance across all four swim strokes: freestyle, backstroke, breaststroke, and butterfly. The new Speedo iQ system uses swim-specific sensors to analyze head movement in the water, time breaths, and track distance per stroke. Unlike other smart goggles, such as…

Read summary

AI

Jensen Huang says Nvidia achieved AGI, again — not that it matters

On Nvidia’s earnings call Wednesday, CEO Jensen Huang casually announced the company had “achieved AGI,” one of the tech industry’s ultimate goals some of its biggest players have spent years chasing. Almost immediately, Huang dismissed the coveted milestone as “senseless.” He’s right. For the supposed finish line of the AI race, there is no consensus…

Read summary

Technology

Socure hits $5.2 billion valuation, acquires AI startup Fravity to bring AI agents to fraud and compliance

Identity verification startup Socure has landed a new strategic growth investment valuing the identity verification company at $5.2 billion and acquired Fravity, an AI startup that automates fraud, risk, and compliance work. The two deals arrive as financial institutions and […] The post Socure hits $5.2 billion valuation, acquires AI startup Fravity to bring AI…

Read summary

Apps

Applied Systems Engineering ASE2000 V2 Communications Test Set

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the trusted peer, complete the TLS handshake, and read or modify the protected communications. The following versions of Applied Systems Engineering ASE2000…

Read summary

Cyber Security

Mitsubishi Electric CNC Series (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi Electric CNC Series (Update A) are affected: Mitsubishi Electric M800VW (BND-2051W000) <=BB (CVE-2025-2399) Mitsubishi Electric M800VS (BND-2052W000) <=BB (CVE-2025-2399) Mitsubishi Electric M80V (BND-2053W000)…

Read summary