Product
high
advisory
Out-of-Bounds Write in NGINX JavaScript (njs) XML Module
1 CVECVE-2026-78689 allows remote unauthenticated attackers to trigger an out-of-bounds heap write in the NGINX JavaScript (njs) and QuickJS (qjs) XML module via crafted namespace prefix lists.
njs +2
vulnerability
denial-of-service
cve-2026-78689
1c
medium
advisory
BadIIS Malware-as-a-Service Ecosystem Targeting IIS Servers
2 rules 1 TTP 6 IOCsA commodity BadIIS malware variant is fueling a thriving malware-as-a-service (MaaS) ecosystem for Chinese-speaking cybercrime groups, allowing them to execute malicious SEO fraud, hijack server content, and redirect traffic to illicit sites.
Photoshop +3
iis
malware
maas
seo fraud
2r
1t
6i