🪟 Windows TippsMicrosoft to Hold Surface and Windows Event on October 7(16.09.2026 um 18:25 Uhr)
🪟 Windows TippsNissan bringt seinen Verkaufsschlager Kicks nach Europa(16.09.2026 um 16:34 Uhr)
🪟 Windows ServerBrowser: Firefox 156 bekommt Werbeeinblendungen - Golem.de(16.09.2026 um 17:14 Uhr)
🪟 Windows TippsMicrosoft to Hold Surface and Windows Event on October 7(16.09.2026 um 18:25 Uhr)
🪟 Windows TippsNissan bringt seinen Verkaufsschlager Kicks nach Europa(16.09.2026 um 16:34 Uhr)
🪟 Windows ServerBrowser: Firefox 156 bekommt Werbeeinblendungen - Golem.de(16.09.2026 um 17:14 Uhr)

🔧 Programmierung 🕛 vor 4 Monaten 4 Min Lesezeit CVE-2026-3854
0

Critical RCEs in Microsoft AI & GitHub, plus CrowdSec for Hardening

Cyber Threat & Vulnerability Dossier CVSS 10.0 CRITICAL EPSS 85.7%
ANGRIPPSVEKTOR
💻 Lokal
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (dev.to)
🗣️ Stimme:
📑 Inhaltsübersicht




Critical RCEs in Microsoft AI & GitHub, plus CrowdSec for Hardening






Today's Highlights



This week, major RCE vulnerabilities in Microsoft's AI frameworks and GitHub.com highlight critical supply chain and AI-specific security risks. Additionally, a practical guide to integrating CrowdSec with Nginx Proxy Manager offers robust defensive techniques for self-hosted applications.






[Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses) (r/netsec)



Source:



A critical Remote Code Execution (RCE) vulnerability, identified as CVE-2026-3854, has been disclosed affecting both GitHub.com and GitHub Enterprise Server instances. While the future-dated CVE is unusual, the implications of an RCE in GitHub are profound, as it represents a core component of the software supply chain for countless organizations and projects. This type of vulnerability could allow attackers to execute arbitrary code within GitHub's infrastructure or on Enterprise Server deployments, granting them significant control over repositories, build processes, and potentially leading to widespread supply chain attacks.



The severity of an RCE in GitHub cannot be overstated. Compromise of GitHub.com could impact the integrity of open-source projects, enable malicious code injection into widely used libraries, and facilitate sophisticated attacks against downstream users. For GitHub Enterprise Server users, immediate patching and vigilance are paramount to prevent internal system compromise and data exfiltration. This disclosure highlights the ongoing challenge of securing foundational developer platforms and the cascading effects a single vulnerability can have across the entire software development ecosystem.



Comment: An RCE in GitHub is a nightmare scenario for supply chain security. If you're running GitHub Enterprise Server, you need to prioritize this patch immediately. For GitHub.com users, this reinforces the need for strong branch protection, code review, and dependency scanning practices.






NPMplus + CrowdSec setup, my notes (r/selfhosted)



Source: https://reddit.com/r/selfhosted/comments/1sydvmr/npmplus_crowdsec_setup_my_notes/



This practical guide offers detailed notes on integrating Nginx Proxy Manager (NPMplus) with CrowdSec, a free and open-source behavior detection engine. The setup provides a robust defensive layer for self-hosted applications, enhancing security against various threats like brute-force attacks, credential stuffing, and malicious bot activity. NPMplus simplifies reverse proxy management with a user-friendly web interface, making it an ideal front-end for CrowdSec's capabilities, which analyze logs from various services to identify and block suspicious IPs based on a global threat intelligence network.



The notes likely cover installation steps, configuration specifics for linking NPMplus's access logs to CrowdSec's parsers, and setting up bouncers to automatically block identified attackers at the proxy level. This combination enables users to effectively protect their exposed services, moving beyond basic firewall rules to dynamic, behavior-based threat detection and response. For self-hosters and small businesses looking to implement practical hardening guides without significant cost, this integration serves as an excellent example of a layered security approach that contributes to a more resilient infrastructure.



Comment: I've been looking for a better way to protect my self-hosted services, and this NPMplus + CrowdSec combo sounds like a solid, actionable solution. CrowdSec's community-driven threat intelligence is a game-changer for dynamic IP blocking right at the edge.

Vollständiger Original-Artikel
Den kompletten Beitrag mit allen Details direkt auf dev.to lesen.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Microsoft to Hold Surface and Windows Event on October 7
1 Quelle
Thrustmaster's new flight stick is a heavy and authentic A-10C HOTAS replica for PC simulator fans who crave digital dogfights
1 Quelle
Nissan bringt seinen Verkaufsschlager Kicks nach Europa
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Critical RCEs in Microsoft AI & GitHub, plus CrowdSec for Hardening

Thematisch verwandte Begriffe: Critical, RCEs, Microsoft, GitHub · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...