ZeroPath Labs (@zeropathlabs) 's Twitter Profile
ZeroPath Labs

@zeropathlabs

Security Research Team @zeropathai

ID: 1901759841724719104

linkhttp://zeropath.com calendar_today17-03-2025 22:17:37

2 Tweet

11 Followers

3 Following

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Mattermost OAuth State Token Validation Flaw CVE-2025-12419 lets attackers bypass OAuth checks in Mattermost. This critical bug allows full account takeover via forged state tokens. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec #Mattermost

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Mattermost CVE-2025-12421: Critical SSO Flaw A critical SSO code exchange bug in Mattermost lets attackers take over accounts. Patch ASAP to secure your teams. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec #SSO zeropath.com/blog/mattermos…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Keras CVE-2025-12060: Path Traversal Flaw A critical path traversal bug in Keras lets attackers access files outside intended directories. Patch ASAP to stay secure. For more details, read ZeroPath's blog on this vuln. #AppSec #MLSecurity #InfoSec zeropath.com/blog/cve-2025-…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Avast Antivirus CVE-2025-3500: Integer Overflow A new integer overflow in Avast Antivirus could allow privilege escalation. Patch ASAP if you use Avast in your environment. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec #Vulnerability

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Avast Antivirus for macOS: CVE-2025-8351 A heap-based buffer overflow and out-of-bounds read vulnerability puts users at risk of code execution and data leaks. Patch as soon as you can. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

IBM Informix Dynamic Server: Local Auth Bypass Issue CVE-2024-45675 allows local attackers to bypass authentication on Windows systems. Patch ASAP if you rely on Informix for critical data. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

vLLM RCE via Model Config Auto-Mapping: CVE-2025-66448 Attackers can trigger remote code execution in vLLM through unsafe model config mapping in unpatched versions. Patch ASAP. For more details, read ZeroPath's blog on this vuln. #AppSec #MachineLearning #InfoSec

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

SureMail WordPress Plugin: Unrestricted File Upload Vulnerability CVE-2025-13516 in SureMail allows attackers to upload malicious files without restriction. Sites running this plugin should update now. For more details, read ZeroPath's blog on this vuln. #WordPress #AppSec

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

AI Finds 8 New FFmpeg Vulnerabilities ZeroPath researchers used AI to autonomously discover 8 vulnerabilities in FFmpeg. Automation is accelerating vulnerability discovery in key open source projects. For more details, read ZeroPath's blog on this vuln. #AppSec #AI

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

7 FFmpeg Vulnerabilities Uncovered by AI Our latest research uses AI to autonomously discover 7 new vulnerabilities in FFmpeg. For more details, read ZeroPath's blog on this vuln. #AppSec #CyberSecurity #AI zeropath.com/blog/autonomou…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Openclaw (Clawdbot) Vulnerability Alert Malicious websites can exploit Openclaw to steal user credentials through crafted payloads. Tighten browser security and check configs. For more details, read ZeroPath's blog on this vuln. #AppSec #CyberSecurity #InfoSec

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

ZeroPath Exploit Development CTFs Looking to sharpen your exploit dev skills? ZeroPath runs hands-on CTFs focused on real-world vulnerabilities and practical techniques. For more details, read ZeroPath's blog on this vuln. #AppSec #ExploitDev #InfoSec zeropath.com/blog/zeropath-…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Why Commenda Chose ZeroPath for Security Commenda picked ZeroPath to protect their global tax platform, citing our deep expertise in risk assessment and proactive threat detection. For more details, read ZeroPath's blog on this vuln. #AppSec #CyberSecurity #InfoSec

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Scaling AppSec at Aptos Labs: AI SAST for Rust Aptos Labs is securing over 1M lines of Rust code with AI-powered SAST, enabling rapid detection of bugs and vulnerabilities at scale. For more details, read ZeroPath's blog on this vuln. #AppSec #Rust #AI zeropath.com/blog/aptos-lab…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Best SAST Tools for 2026: What to Know Choosing the right SAST tool is tough. We break down the top 7 for AppSec teams and CISOs, comparing features and use cases. For more details, read ZeroPath's blog on this vuln. #AppSec #DevSecOps #SAST zeropath.com/blog/best-sast…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

36 Sudo Bug Fixes Reduce CrackArmor Impact ZeroPath uncovered that 36 recent Sudo patches directly limit CrackArmor exploitation routes. For more details, read ZeroPath's blog on this vuln. #AppSec #Linux #InfoSec zeropath.com/blog/sudo-bug-…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Opus 4.6 Vulnerability Detection: Pros and Cons Opus 4.6 shows promise for catching vulns but beware the high false positive rate. Teams will need solid tuning for real-world use. For more details, read ZeroPath's blog on this vuln. #AppSec #VulnDetection #InfoSec

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

RAGFlow Post-Auth RCE Vulnerability A serious post-auth RCE bug in RAGFlow lets attackers execute code after login. Patch ASAP to protect your environment. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec #RCE zeropath.com/blog/ragflow-r…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

Critical RCE in Spinnaker: Patch Now Two critical Spinnaker vulnerabilities (CVSS 10.0) allow remote code execution and full production takeover. Patch ASAP. For more details, read ZeroPath's blog on this vuln. #AppSec #CloudSecurity #ZeroTrust zeropath.com/blog/spinnaker…

ZeroPath Labs (@zeropathlabs) 's Twitter Profile Photo

CVE-2026-42167 impacts ProFTPD This vuln enables auth bypass, privilege escalation, and code execution. Prioritize patching if you're running ProFTPD. For more details, read ZeroPath's blog on this vuln. #AppSec #InfoSec #ProFTPD zeropath.com/blog/proftpd-c…