Description
Statistics
- 6 Posts
- 7 Interactions
Fediverse
@browserversiontracker For the curious, this includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
And yes, we somehow beat the Chrome team getting this out even though they did the fix. 😂
@vivaldiversiontracker This includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
Bluesky
Overview
- defnull
- multipart
Description
Statistics
- 1 Post
- 35 Interactions
Fediverse
The 'multipart' #python library got an independent #security audit and I only know about that because they found something -> CVE-2026-28356
This is great, actually! Someone looked into it so thoroughly that they found an obscure single-character issue in a regular expression ... and didn't find anything else! Which means I can now be really confident about the security of this library. Nice!
Overview
- Microsoft
- Microsoft Devices Pricing Program
Description
Statistics
- 3 Posts
- 4 Interactions
Bluesky
Overview
- Microsoft
- Microsoft Authenticator for Android
Description
Statistics
- 1 Post
- 8 Interactions
Fediverse
Microsoft Authenticator potrebbe divulgare i codici di accesso: se lo stai usando, aggiorna subito l'app
Una vulnerabilità in Microsoft Authenticator per iOS e Android ( CVE-2026-26123 ) potrebbe far trapelare i codici di accesso monouso o i deep link di autenticazione a un'app dannosa sullo stesso dispositivo.
Overview
Description
Statistics
- 1 Post
- 13 Interactions
Fediverse
Today's CVE stinker: https://github.com/joshuavanderpoll/CVE-2025-69985
You can get auth bypass on a SCADA HMI that already doesn't require auth, and then run a script by sending the script to `api/runscript`
Is this still a useful CVE? Perhaps! I am not an expert on FUXA HMIs specifically, and I'm sure they didn't intend for their runscript endpoint to be used to run *anything*
but still.
"you can run scripts by sending them to /api/runscript" sure is a funny CVE description.
Description
Statistics
- 4 Posts
- 2 Interactions
Fediverse
@browserversiontracker For the curious, this includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
And yes, we somehow beat the Chrome team getting this out even though they did the fix. 😂
@vivaldiversiontracker This includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
Bluesky
Overview
- Microsoft
- Microsoft SQL Server 2016 Service Pack 3 (GDR)
Description
Statistics
- 2 Posts
Bluesky
Overview
- dagu-org
- dagu
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
⚠️ CRITICAL vuln: dagu <2.2.4 suffers from path traversal (CVE-2026-31886). Exploit allows deletion of /tmp, causing system-wide DoS. Upgrade to 2.2.4+ or enforce input validation now! https://radar.offseq.com/threat/cve-2026-31886-cwe-22-improper-limitation-of-a-pat-116cb11a #OffSeq #dagu #security #CVE2026_31886
Overview
- ctfer-io
- monitoring
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-32720 (HIGH): ctfer-io monitoring <0.2.1 has improper access control, allowing lateral movement across Kubernetes namespaces — risks sensitive logs/metrics. Patch to 0.2.1+ ASAP! 🔒 https://radar.offseq.com/threat/cve-2026-32720-cwe-284-improper-access-control-in--c14eb5d2 #OffSeq #Kubernetes #CVE #CloudSecurity
Overview
- nyariv
- SandboxJS
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🔥 CRITICAL: CVE-2026-26954 in SandboxJS (< 0.8.34) enables sandbox escape via Function & Object.fromEntries. Attackers can run arbitrary code remotely! Upgrade to v0.8.34+ now. Full details: https://radar.offseq.com/threat/cve-2026-26954-cwe-94-improper-control-of-generati-35790079 #OffSeq #CVE202626954 #infosec #sandbox