LodeHQSubscribe →

Critical NGINX RCE, V8 flaw, DNS TXT malware

Infosec · 2026-07-19

Vulnerabilities & Exploits
NGINX patches critical CVE-2026-42533 heap overflow, prevents crashes and RCE1 MIN

NGINX 1.30.4 (stable) and 1.31.3 (mainline) ship fixes for CVE-2026-42533, a heap buffer overflow that lets unauthenticated attackers crash worker processes or execute code via crafted map‑directive regex requests. Administrators should upgrade immediately to avoid denial‑of‑service and potential remote code execution.

Out-of-Bounds V8 Flaw Threatens Edge and All Chromium Browsers1 MIN

A newly disclosed CVE‑2026‑15903 reveals an out‑of‑bounds read/write bug in Chromium’s V8 JavaScript engine. The flaw can be triggered in Microsoft Edge and any Chromium‑based browser, potentially allowing attackers to read or corrupt memory. Until patches roll out, admins should monitor updates and consider temporary mitigations.

Threats & Malware
Malware Stored in DNS TXT Records: How Attackers Reassemble Hidden Payloads2 MIN

By fragmenting binaries into hex chunks across hundreds of TXT subdomains, threat actors use DNS as a covert storage channel that evades most defenses. DomainTools' analysis reconstructs executable files from these records, proving the method can deliver functional malware while remaining invisible to typical network monitoring.

Get Infosec in your inbox, every issue.
Subscribe free
Privacy · Terms · About · Contact
© 2026 LodeHQ