Niklas Heringer
Niklas Heringer
Cybersecurity & Math.
⌘K
  • Home
  • Blog
  • #My Work
  • My publications
  • GitHub
  • My Linkedin
  • Events and Traveling
  • My Medium
  • #Aspects
  • Penetration Testing
  • Skills Lab
  • Research
  • Digital Forensics
  • Security News
  • Field Notes
  • #Info and Guidance
  • Privacy Policy and Cookie Policy
  • Impressum
Subscribe Sign in
Niklas Heringer

Security News

Timely analysis of the most critical and current developments in security.
insecure-deserialization

A 10/10: CVE-2025-55182 haunting React and Next.js

React2Shell seems to be the Log4Shell of the JavaScript world. We break down the unsafe deserialization in React's Flight protocol, why APT groups like Earth Lamia tried to exploit it instantly, and why your audit checklist needs to check for architectural integrity. Patch immediately!
06 Dec
Some Welcome Changes: Dissecting the OWASP Top 10 2025
owasp

Some Welcome Changes: Dissecting the OWASP Top 10 2025

See the complete breakdown of the new OWASP Top 10 list. Why Supply Chain (A03) and Misconfiguration (A02) displaced Injection, and how the new A10 (Exceptional Conditions) category defines modern AppSec risks in Cloud and AI environments. See the Migration Cheat Sheet for Builders and Pentesters.
03 Dec
Niklas Heringer © 2026. Published with Ghost & Braun
  • Sign up
Privacy settings niklas-heringer.com

This website uses strictly necessary cookies and browser storage (member sign-in, security, your light or dark choice and this notice). With your consent it also measures anonymous visitor statistics. No advertising or cross-site tracking. Details in our Privacy Policy.

Privacy information
Strictly necessary Always on

Cookies and browser storage needed for the site to work: member sign-in (only after you log in), security features, your light or dark mode choice and the record of this notice. If paid memberships are offered, Stripe sets fraud-prevention cookies during checkout only.

Visitor statistics

Anonymous page-view statistics (Ghost Traffic Analytics, processed by Tinybird in the EU): visited page, referrer, browser and country. No cookies, not used for advertising or tracking across sites. Without your consent nothing is sent.

Newsletter emails Members only

If you subscribe, emails are sent via Mailgun (EU region). Delivery and open events are recorded for the newsletter. You can unsubscribe at any time with the link in every email or in your account.