← Back to feed
general The Hacker News

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

The Hacker News Oracle

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against ap...

T1190 1 IOC
Read the full story The Hacker News →

Related Coverage

general New Rapuncel infostealer campaign uses fake GitHub repos to disable antivirus SC Media · Sep 21 general BigCommerce alerts merchants of data breach linked to Ribon apps BleepingComputer · Sep 21 general Google Fined €403 Million Over Location Data Practices Security Affairs · Sep 21