credentials

AppWizard
May 20, 2026
VWFNDR has launched a new camera app called VWFNDR + MBL, which captures unprocessed Bayer RAW DNG and JPEG files, avoiding modern computational photography. The app supports various aspect ratios and offers manual controls for ISO, shutter speed, focus, and exposure compensation. Each photo includes a tamper-evident record via the open Content Credentials standard from C2PA, verifying the image's source and integrity. VWFNDR is the fourth company globally to achieve C2PA Level 2 conformance and the second to support it for DNG files. The app is currently free for Android 10 or later devices but only supports the primary rear camera.
Winsage
May 20, 2026
Bitdefender's research highlights the use of Microsoft's MSHTA utility in malware attacks, noting its default activation in Windows systems. Cybercriminals exploit MSHTA to execute malicious scripts under the guise of legitimate processes, linking it to various malware families like LummaStealer and PurpleFox. The study reports a rise in MSHTA-related detections, indicating a shift towards "living-off-the-land" tactics that utilize legitimate tools to evade security alerts. Social engineering is identified as a common entry point for attacks, employing deceptive methods such as fake software downloads and phishing links. MSHTA can retrieve and execute additional payloads through multi-stage chains, complicating detection efforts. The attacks target sensitive information, including credentials and financial data, and the continued presence of MSHTA poses risks as it allows threat actors to conceal malicious actions. To mitigate these threats, organizations are advised to restrict or disable legacy scripting tools and exercise caution with untrusted downloads. The report emphasizes the challenge of detecting unusual behaviors associated with legitimate utilities in the context of cyber threats.
Tech Optimizer
May 19, 2026
A public proof-of-concept exploit has been released for CVE-2026-2005, a critical heap-based buffer overflow vulnerability in PostgreSQL's pgcrypto extension, allowing full remote code execution and privilege escalation to the database superuser level. This vulnerability has existed since 2005 and was discovered by an AI-powered security tool during the ZeroDay.Cloud 2025 event in December 2025. An upstream patch was committed on February 8, 2026, and released on February 12, 2026. The vulnerability has a CVSS score of 8.8 and affects approximately 80% of cloud environments using PostgreSQL, with 45% accessible via the internet. The flaw is in the pgp_parse_pubenc_sesskey() function, which lacks bounds checking, allowing attackers to manipulate session key lengths. The pgcrypto extension can be installed by any database role with CREATE privileges, increasing the risk of exploitation. The proof-of-concept exploit involves an information leak, arbitrary write, and privilege escalation to remote code execution. The vulnerability affects all major versions of PostgreSQL prior to the February 2026 releases, which include versions 18.2, 17.8, 16.12, 15.16, and 14.21. Mitigation steps include upgrading to patched versions, restricting CREATE privileges, blocking direct internet exposure, rotating database credentials, auditing the usage of COPY FROM PROGRAM, and verifying patched engine versions for cloud-managed PostgreSQL users.
AppWizard
May 19, 2026
VWFNDR has launched the VWFNDR + MBL, an Android camera app designed for mobile photographers seeking a traditional camera experience rather than a computational filter. Founded in Tokyo in 2023 by Álvaro Nuevo.Tokyo and Mireia Gordi i Vila, VWFNDR aims to enhance photography hardware and user experience. The MBL app captures unprocessed Bayer RAW DNG data and JPEGs, offering manual controls for ISO, shutter speed, focus, and exposure compensation, along with customizable user interface options. It includes six built-in aspect ratios and avoids computational photography features, ensuring images reflect what the sensor captures. Each photo taken with MBL is embedded with Content Credentials, confirming image provenance. VWFNDR is the fourth company to achieve C2PA Level 2 conformance and the second to support Content Credentials for DNG files. Sample images have been captured on various Android models, including Google Pixel and Xiaomi devices. The app is currently available for free on the Google Play Store.
Search