Critical NGINX RCE, V8 flaw, DNS TXT malware
NGINX 1.30.4 (stable) and 1.31.3 (mainline) ship fixes for CVE-2026-42533, a heap buffer overflow that lets unauthenticated attackers crash worker processes or execute code via crafted map‑directive regex requests. Administrators should upgrade immediately to avoid denial‑of‑service and potential remote code execution.
A newly disclosed CVE‑2026‑15903 reveals an out‑of‑bounds read/write bug in Chromium’s V8 JavaScript engine. The flaw can be triggered in Microsoft Edge and any Chromium‑based browser, potentially allowing attackers to read or corrupt memory. Until patches roll out, admins should monitor updates and consider temporary mitigations.
By fragmenting binaries into hex chunks across hundreds of TXT subdomains, threat actors use DNS as a covert storage channel that evades most defenses. DomainTools' analysis reconstructs executable files from these records, proving the method can deliver functional malware while remaining invisible to typical network monitoring.
Subscribe free