460 articles
CVE-2024-46508 (CVSS 7.5) in Yeti platform before 2.1.12 lets attackers forge valid JWT tokens when the default secret key is unchanged — full account takeover risk.
Braintrust disclosed a breach on May 4 where attackers accessed an AWS account, compromising AI provider API keys for firms like Box and Stripe. At least one customer affected.
CVE-2026-7891 in DIVD's VerySecureApp (Mendix Studio Pro 11.8.0 Beta) exposes all stored records to anonymous users via an authorization misconfiguration — no access rights...
CVE-2026-8106: Reflected HTML injection in GitHub Enterprise Server Management Console login page enables credential theft via crafted redirect_to parameter.
CVE-2026-8034: A server-side request forgery flaw in GitHub Enterprise Server notebook viewer exploits URL parser confusion, letting attackers access internal services.
CVE-2026-39825 in Go's ReverseProxy allows query parameters invisible to Rewrite functions to be forwarded, bypassing sanitization in net/http.
CVE-2026-8114 (CVSS 6.5) in JeecgBoot up to 3.9.1 enables remote SQL injection via the /sys/dict/loadTreeData endpoint. Exploit code is public.
Attackers repurpose the Bun JavaScript runtime to distribute NWHStealer, a Rust-based infostealer targeting browsers, crypto wallets, and FTP apps via game lures and fake software.
Kaspersky attributes a PyPI supply chain campaign to OceanLotus APT, using fake wheel packages to drop ZiChatBot malware that abuses Zulip chat APIs for C2 on Windows and Linux.
CVE-2026-40213 (CVSS 7.4) in OpenStack Cyborg before 16.0.1 uses rule:allow as default policy, letting any authenticated Keystone token holder reprogram FPGA bitstreams on...
A new Linux backdoor named PamDOORa, sold for $1,600 on the Rehub forum, uses PAM modules to steal SSH credentials via a magic password and TCP port combination.
A new Linux implant codenamed QLNX steals developer credentials, keystrokes, and clipboard data. Targets DevOps environments for software supply chain compromise.