A critical vulnerability identified as CVE-2025-49844 has been discovered in Redis, the popular open-source in-memory data store used for caching, analytics, and message brokering. The flaw, rated with a CVSS score of 10.0, allows remote code execution (RCE) through the misuse of Redis’ Lua scripting engine. According to Redis’ advisory, an authenticated attacker could craft a malicious Lua script that manipulates the garbage collector, leading to a use-after-free condition and arbitrary code execution within the Redis server process. This exposure can compromise stored data, enable lateral movement, and potentially disrupt connected systems. The vulnerability originates from improper memory management within the embedded Lua interpreter in Redis. By exploiting freed memory pointers, attackers can execute malicious code on the host system. Alongside CVE-2025-49844, Redis also disclosed three additional Lua-related vulnerabilities—CVE-2025-46817 (integer overflow), CVE-2025-46818 (privilege escalation), and CVE-2025-46819 (out-of-bounds read)—which collectively pose risks of remote code execution, data leakage, or denial of service (DoS). These flaws affect all Redis versions supporting Lua scripting, making both self-hosted and enterprise deployments vulnerable to exploitation. To mitigate the risks, Redis administrators are strongly advised to upgrade to the patched versions 6.2.20, 7.2.11, 7.4.6, 8.0.4, or 8.2.2. As a temporary measure, organizations should restrict Lua commands like EVAL, EVALSHA, and FUNCTION using Access Control Lists (ACLs). Additionally, enforcing network segmentation, limiting external access, and monitoring for unusual Lua activity can further strengthen defenses against potential exploitation.
Cybersecurity researchers have uncovered another evolution of the ongoing supply chain attack linked to the Mini Shai Hulud, Miasma, and Hades malware family, targeting both the np...
Amazon has addressed a high-severity security vulnerability, tracked as CVE-2026-12957, affecting Amazon Q Developer IDE plugins. The flaw could allow a malicious Git repository to...
?An active phishing campaign has targeted hotels and hospitality organizations across Europe and Asia since April 2026. Attackers send emails impersonating "Booking Manager (vi...