Urgent.News

What's breaking now, across thousands of outlets.

Tech

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in Tech

When I would stop trying PDF extractors and ask for the source

After trying three PDF extractors on the same damaged notice, I still did not have the Chinese text I needed. The outputs looked different, but none contained the original Chinese title.

  • Tried PDF extractors on damaged Chinese text notice with no success
  • Controlled test with synthetic notice showed extractors need source text
  • Requesting source content is key to verifying document accuracy

More from Monday 5 October →