ZeroHour

Search: “validation”

1,380 items

Forgery of C2PA on a Pixel 10

Researcher forged a Google Pixel 10 C2PA content credential with genuine signatures, showing root-level attackers can fake photo provenance.

A Hacker Factor blog post demonstrates an AI-generated 'unicorn glitter milk' news photo carrying a valid, cryptographically signed C2PA manifest traceable to Google's Pixel camera certificate chain, passing validation in Adobe Inspect and the CAI Verify tool with a verified timestamp. The author, working with UMBC's PASAWG working group, reported to Google and C2PA in November 2025 that root access on a Pixel device could sign arbitrary images as camera captures; after 90 days without resolution, details were published. The finding undermines C2PA Assurance Level 2 claims made for Pixel 10 Content Credentials.

Lobsters · security · 15h agoResearch

CVE-2026-73334: Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation

Apache Parquet Hadoop CVE-2026-73334: a file-controlled KMS URL reaches pluggable KmsClients without host validation in parquet-java 1.12 through 1.18.0.

Apache disclosed CVE-2026-73334, a moderate issue in the org.apache.parquet.crypto.keytools package of parquet-java, versions 1.12 through 1.18.0. The package implements envelope encryption that wraps data keys via a Key Management Service. A KMS URL controlled by the Parquet file is forwarded to a pluggable KmsClient that skips host validation, which could allow crafted files to redirect KMS requests.

oss-security · 8d agoVulnerabilityCVE-2026-733341

ZDI-26-605: Microsoft Windows Localized Filenames Improper Input Validation NTLM Response Information Disclosure Vulnerability

ZDI advisory ZDI-26-605 details an improper input validation flaw (CVE-2026-50508, CVSS 3.3) in Microsoft Windows localized filenames that leaks NTLM responses.

The Zero Day Initiative released advisory ZDI-26-605 describing improper input validation in Microsoft Windows handling of localized filenames. Remote attackers can disclose NTLM authentication responses if the target opens a malicious file or visits a crafted page. ZDI rated the issue CVSS 3.3 and assigned CVE-2026-50508. Leaked NTLM responses could enable offline credential cracking.

ZDI Published Advisories · 23d agoAdvisoryCVE-2026-505081