🕵️ RESEARCH & DEEP DIVES
-
GitLab Memory-Safety Flaws in Oj JSON Parser Enable Remote Code Execution Two memory-safety bugs in GitLab's Oj JSON parser allow remote code execution by authenticated users.
- Applies to self-managed GitLab CE/EE versions 15.2.0–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1
- Vulnerabilities are two long-standing memory-safety flaws in the Ruby Oj JSON parser used by GitLab
- Attack exploits crafted Jupyter Notebook (.ipynb) files pushed by any authenticated user with push and diff-view rights
- Chained flaws enable heap pointer leak and callback pointer overwrite, defeating ASLR and executing code as 'git' user
- Exploitation risks exposure of source code, Rails secrets, internal services, and allows lateral movement 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News
-
Security Flaw in Vatican’s Click to Pray App Exposes Data of 700,000+ Users The Vatican’s Click to Pray app has leaked user data for over six months.
- Applies to over 700,000 global users of the Vatican’s Click to Pray mobile app
- User data was exposed due to a security flaw in the app
- Data leak persisted for more than six months without being fixed
- Details on attack vector or exploited vulnerability have not been disclosed 📎 Coverage: tomshardware.com · 👁 via r/cybersecurity
-
Researcher Claims Universal Jailbreak for Leading AI Models Including GPT-5.6 A researcher claims to have developed a universal jailbreak effective on all major AI models.
- Applies to top large language models: GPT-5.6 Sol, Claude Opus 5, and Fable
- The jailbreak bypasses safety filters to produce disallowed or high-risk outputs
- Claimed universal method works across all tested models and categories
- Researcher withholding full technique for responsible disclosure amid regulatory concerns
- Highlights gaps in safety training, guardrail robustness, and cross-model attack generalization 📎 Coverage: cybersecuritynews.com · 👁 via Cyber Security News
📋 ADVISORIES
- ExtremeXOS suffers two high-severity privilege escalation flaws CVE-2026-8169 and CVE-2026-8170
CVE-2026-8169CVE-2026-8170Extreme Networks ExtremeXOS has two high-severity privilege escalation vulnerabilities.- Applies to Extreme Networks ExtremeXOS Switch Engine products
- CVE-2026-8169 involves debug-mode privilege escalation via weak PRNG
- CVE-2026-8170 involves privilege escalation via symlink following in file utilities
- Attackers with low-privilege CLI access can exploit symlink flaw to gain root access
- Exploitation possible remotely or locally via serial console; fixed in EXOS versions 31.7.4 and later 📎 Coverage: community.extremenetworks.com · 📄 Original: community.extremenetworks.com · 👁 via InfraTrust Advisories (+1)