🕵️ RESEARCH & DEEP DIVES
-
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws — The Hacker News
-
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day — The Hacker News
-
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests — The Hacker News
-
Libsoup: libsoup: heap use-after-free in libsoup http/2 client on_data_read()... — CVE ThreatInt
-
Information Disclosure in Pik Online Software's PortalUse of a One-Way hash w... — CVE ThreatInt
-
Apache Allura: Stored XSS via code repositoriesApache Allura: stored XSS via ... — CVE ThreatInt
-
Apache SkyWalking: CWE-79 stored XSS in Booster UI dashboard widgets (incompl... — CVE ThreatInt
-
Apache Allura: Information exposure via searchApache Allura: exposure of non-... — CVE ThreatInt
-
Apache SkyWalking: PagerDuty alarm hook transmits the integration routing key... — CVE ThreatInt
-
Apache Allura: Server-side request forgeryApache Allura's webhooks are vulner... — CVE ThreatInt
-
Apache Allura: Stored XSS via markdown HTML processingStored XSS via markdown... — CVE ThreatInt
-
ACPT (Premium) through 2.0.66 - Unauthenticated Privilege Escalation via 'acpt_for... — CVE ThreatInt
-
XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone wit... — CVE ThreatInt
-
XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with ... — CVE ThreatInt
-
XING CPTrans-ME-X contains an Exposure of Sensitive System Information to an ... — CVE ThreatInt
-
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated ... — CVE ThreatInt
-
The Canva Android App before 2.376.0 did not restrict the headers returned to... — CVE ThreatInt
-
The Canva Android App before 2.376.0 allowed an external origin to be loaded ... — CVE ThreatInt
-
Xpro Elementor Addons before 1.7.8 - Unauthenticated Draft/Private Product Disclos... — CVE ThreatInt
-
Directorist before 8.9 - Subscriber+ Arbitrary Post Meta Write via atbdp_post_atta... — CVE ThreatInt
-
WPvivid Backup & Migration before 0.9.134 - Admin+ Arbitrary File Deletion via Pat... — CVE ThreatInt
-
WPvivid Backup & Migration before 0.9.134 - Admin+ File Write Outside the Backup D... — CVE ThreatInt
-
WPLP Cookie Consent before 4.4.2 - Admin+ SQLi via 'offset' ParameterThe WPLP Cook... — CVE ThreatInt
-
14 Fake macOS Installers Linked to DPRK Campaign Deliver Credential-Stealing RAT — Cyber Security News
-
Dahua Camera Backdoor Survives Password Changes and Factory Resets on Compromised Devices — Cyber Security News
-
-New StreamRAT -PhaaS reports on BlueKit, Knight Office, Outsider -New Prince of Persia infrastructure -US offers... — @campuscodi@mastodon.social
-
-OpenAI prepares Astra launch -Google releases Gemini 3.8 Flash Cyber -Microsoft enables Memory Integrity for more... — @campuscodi@mastodon.social
-
-Russia tells data centers to deploy drone defenses -Dropbox discloses security breach -New spyware wave hits Serbians... — @campuscodi@mastodon.social
-
Canva Android App: Privileged WebView Session Hijack — thehackerwire.com (discovered)
-
SmartIT Desktop Manager Hard-coded Credentials Vulnerability — thehackerwire.com (discovered)
-
From fake interview to signed ClickOnce: inside a three-payload Windows chain (Part 2) — r/netsec
-
Fal.Con 2026: Fast and Frictionless Breach Readiness — securityboulevard.com (discovered)