Overview
Description
Statistics
- 10 Posts
- 2 Interactions
Fediverse
This Splunk flaw is no longer just theoretical.
Splunk says it is aware of limited exploitation of CVE-2026-20253.
CISA has added it to KEV, giving federal agencies until June 21, 2026 to patch.
Upgrade now.
Read the update: https://thehackernews.com/2026/06/critical-splunk-enterprise-flaw-lets.html
ACTIVE THREAT: CVE-2026-20253 Splunk Enterprise vulnerability is being exploited in the wild. Our latest TSUITE Brief provides a full SQL injection defense playbook, including n8n automation triggers for your SOC. Secure your infrastructure now. https://thecybermind.co/2yn5
Latest Geopolitical: An interim US-Iran agreement aims to de-escalate tensions and reopen the Strait of Hormuz, while Moscow endured its largest Ukrainian drone attack, hitting an oil refinery.
Technology: Anthropic's Claude Fable 5 AI is back online after a six-day shutdown, as Google makes Gemini 2.5 Flash its default model.
Cybersecurity: CISA issued alerts for an actively exploited Splunk vulnerability (CVE-2026-20253) and widespread Fortinet "FortiBleed" attacks. Accenture also acquired key OT security firms.
Bluesky
Overview
- Microsoft
- Microsoft Malware Protection Engine
Description
Statistics
- 3 Posts
- 6 Interactions
Fediverse
CVE-2026-50656: Microsoft Confirms Defender ‘RoguePlanet’ Zero-Day — No Patch Available Yet
#CyberSecurity
https://securebulletin.com/cve-2026-50656-microsoft-confirms-defender-rogueplanet-zero-day-no-patch-available-yet/
Bluesky
Overview
Description
Statistics
- 4 Posts
- 7 Interactions
Fediverse
"We sent Claude Mythos Preview spelunking through Squid’s guts, and it surfaced clutching a 29-year-old bug.
Meet Squidbleed: a Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration."
https://blog.calif.io/p/squidbleed-cve-2026-47729
Bluesky
Overview
- Government Accountability Office
- Electronic Protest Docketing System (EPDS)
Description
Statistics
- 3 Posts
- 16 Interactions
Fediverse
lol. lmao.
https://nvd.nist.gov/vuln/detail/CVE-2026-54103
The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contract Appeals (CBCA) Electronic Docketing System (EDS) does not authenticate password change requests to the '/update-profile/N' API endpoint. A remote, unauthenticated attacker could change an arbitrary user's password.
CVE-2026-54103 (CRITICAL, CVSS 9.8): GAO EPDS & CBCA EDS lack authentication on password change API, enabling remote takeover. No patch yet. Restrict access, monitor logs. Details: https://radar.offseq.com/threat/cve-2026-54103-cwe-306-missing-authentication-for--c02db531e70d9ca2 #OffSeq #Vuln #CVE202654103 #GovSec
https://db.gcve.eu/vuln/cve-2026-54103
https://db.gcve.eu/vuln/cve-2026-54104
:blobcatthinkingglare:
Overview
Description
Statistics
- 1 Post
- 26 Interactions
Fediverse
I'm more than 25 years into IT at this point, but this is a first for me. Not one I'm proud of, but one I take responsibility for:
My project ansible_jailexec (an Ansible connection plugin for FreeBSD Jails) had a bug that turned out to be a vulnerability. Improper Link Resolution Before File Access (CWE-59), a jail escape. It's been assigned CVE-2026-55074 so people can scan for it (I know it's bundled into Collections out there).
If you're running < 2.0.0: please upgrade. 2.0.0 fixes it.
Advisory: https://github.com/chofstede/ansible_jailexec/security/advisories/GHSA-cxgv-hp74-jj7r
Release: https://github.com/chofstede/ansible_jailexec/releases/tag/v2.0.0
Overview
- themefusion
- Avada (Fusion) Builder
Description
Statistics
- 2 Posts
Fediverse
Critical Unauthenticated Arbitrary File Deletion Vulnerability Patched in Avada Builder WordPress Plugin
Unauthenticated Arbitrary File Deletion (CVE-2026-8713, CVSS 9.1 Critical) in Avada Builder <= 3.15.3 lets attackers delete wp-config.php and take over sites.
Patched in 3.15.4 update now.
CVE-2026-8713: CRITICAL path traversal (CVSS 9.1) in Avada (Fusion) Builder ≤3.15.3. Unauthenticated file deletion possible; RCE risk if wp-config.php is removed. Restrict access, monitor usage, check vendor for fixes. https://radar.offseq.com/threat/cve-2026-8713-cwe-22-improper-limitation-of-a-path-82beab53eaced0fc #OffSeq #WordPress #Infosec
Overview
- deepstreamIO
- deepstream.io
Description
Statistics
- 2 Posts
Fediverse
deepstream.io <10.0.5 has a CRITICAL Prototype Pollution flaw (CVE-2026-49252, CVSS 9.9). Authenticated users with write access can escalate privileges. Patch to 10.0.5+ ASAP! https://radar.offseq.com/threat/cve-2026-49252-cwe-1321-improperly-controlled-modi-de9b0627d448856f #OffSeq #CVE202649252 #deepstreamio #infosec
CVE-2026-49252 - Critical Privilege Escalation in Deepstream. Prototype Pollution bug allows auth'd users with write access to escalate privileges. CVSS 9.9. No patch available yet. Update to 10.0.5 immediately. #CVE #Deepstream #infosec
Overview
- F5
- NGINX Open Source
Description
Statistics
- 3 Posts
Fediverse
⚠️ CRITICAL: F5 Patches Critical, High-Severity NGINX Vulnerabilities
F5 released patches for critical unauthenticated RCE and DoS vulnerabilities in NGINX (CVE-2026-42530, CVE-2026-42055) affecting NGINX Plus, Controller, and related products. Attackers can exploit heap buffer overflows and use-after-free flaws without credentials to crash services or execute arbitr…
Two 9.2s in stock NGINX: inside the HTTP/3 QPACK use-after-free and the gRPC heap overflow F5 just patched
F5 patched two critical NGINX flaws (CVSS 9.2): a QPACK use-after-free in HTTP/3 and a gRPC heap overflow. Full technical breakdown and PoCshttps://thecybersecguru.com/news/nginx-cve-2026-42530-cve-2026-42055-rce/
Overview
- F5
- NGINX Open Source
Description
Statistics
- 3 Posts
Fediverse
⚠️ CRITICAL: F5 Patches Critical, High-Severity NGINX Vulnerabilities
F5 released patches for critical unauthenticated RCE and DoS vulnerabilities in NGINX (CVE-2026-42530, CVE-2026-42055) affecting NGINX Plus, Controller, and related products. Attackers can exploit heap buffer overflows and use-after-free flaws without credentials to crash services or execute arbitr…
Two 9.2s in stock NGINX: inside the HTTP/3 QPACK use-after-free and the gRPC heap overflow F5 just patched
F5 patched two critical NGINX flaws (CVSS 9.2): a QPACK use-after-free in HTTP/3 and a gRPC heap overflow. Full technical breakdown and PoCshttps://thecybersecguru.com/news/nginx-cve-2026-42530-cve-2026-42055-rce/
Overview
- php-standard-library
- php-standard-library
Description
Statistics
- 1 Post
- 2 Interactions