24h | 7d | 30d

Overview

  • Microsoft
  • Microsoft Entra

20 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (10.0)
EPSS
1.37%

KEV

Description

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

Statistics

  • 8 Posts
  • 10 Interactions

Last activity: Last hour

Fediverse

Profile picture fallback

CVE-2026-69836, a CVSS 10 Entra ID remote code execution flaw, was exploited in the wild. Microsoft has fully mitigated it server-side.

securityonline.info/cve-2026-6

  • 2
  • 3
  • 0
  • 13h ago
Profile picture fallback

「Microsoft Entra IDの脆弱性(CVSS 10.0)が実際に悪用され、リモートコード実行が可能になる 」: #TheHackerNews

「マイクロソフトは木曜日、Entra IDに重大なセキュリティ上の欠陥があり、既に悪用されていると警告したが、顧客による対応は不要であると述べた。

CVE-2026-69836 (CVSSスコア:10.0)として追跡されているこの脆弱性は、 リモートコード実行によって、このテクノロジー大手企業のクラウドベースのIDおよびアクセス管理サービスに影響を与える事例です。このサービスは以前はAzure Active DirectoryまたはAzure ADと呼ばれていました。

マイクロソフトは木曜日に発表した警告の中で、 「Microsoft Entra IDにおける信頼できないデータの逆シリアル化により、権限のない攻撃者がネットワーク上でコードを実行できる可能性がある」 と述べた。 」

thehackernews.com/2026/08/micr

#prattohome

  • 1
  • 0
  • 0
  • 8h ago
Profile picture fallback

Microsoft has patched a maximum-severity vulnerability, designated as CVE-2026-69836, within the Entra ID identity platform that previously allowed unauthorized remote code execution. No user action is required as the company has already mitigated the flaw.
bleepingcomputer.com/news/micr

  • 1
  • 0
  • 0
  • 4h ago
Profile picture fallback
  • 0
  • 0
  • 0
  • Last hour

Bluesky

Profile picture fallback
A maximum-severity Entra ID remote code execution flaw (CVE-2026-69836, CVSS 10.0) was exploited in the wild, but Microsoft says it is fully mitigated and needs no customer action.
  • 1
  • 0
  • 0
  • 9h ago
Profile picture fallback
Microsoft corrige falha crítica no Entra ID já explorada em ataques informáticos. A vulnerabilidade CVE-2026-69836 permitia que agentes maliciosos executassem código sem privilégios. #falha #microsoft
  • 1
  • 0
  • 0
  • 3h ago
Profile picture fallback
Critical Microsoft Entra ID vulnerability exploited in the wild (CVE-2026-69836) 🔗 Read more: www.helpnetsecurity.com/2026/08/21/m... #Microsoft #vulnerability #cybersecurity
  • 1
  • 0
  • 0
  • 3h ago
Profile picture fallback
Microsoft patched CVE-2026-69836, a max-severity Entra ID flaw that enabled unauthenticated remote code execution. Microsoft says it is fully mitigated, alongside fixes for Azure Arc, Exchange Online, and Azure Managed Instance for Apache Cassandra.
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • GitLab
  • GitLab

17 Aug 2026
Published
17 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.4)
EPSS
1.51%

KEV

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Statistics

  • 7 Posts
  • 3 Interactions

Last activity: 1 hour ago

Fediverse

Profile picture fallback

GitLab : la faille critique CVE-2026-19478 est déjà exploitée, deux jours après le correctif it-connect.fr/gitlab-cve-2026- #ActuCybersécurité #Cybersécurité #Vulnérabilité

  • 1
  • 0
  • 0
  • 6h ago
Profile picture fallback

Explotan activamente la vulnerabilidad CVE-2026-19478 de GitLab pocos días después de su publicación

blog.elhacker.net/2026/08/expl

  • 0
  • 1
  • 0
  • 2h ago

Bluesky

Profile picture fallback
🚨 GitLab sous pression La faille CVE-2026-19478, corrigée le 17 août 2026 par une mise à jour publiée en urgence... serait déjà exploitée ➡️ Découvrez l'article pour comprendre cette vulnérabilité : www.it-connect.fr/gitlab-cve-2... #Cybersécurité #GitLab
  • 1
  • 0
  • 0
  • 1h ago
Profile picture fallback
CVE-2026-19478 enables unauthenticated code injection in GitLab to modify or delete public projects and rewrite data, with rapid real-world exploitation after disclosure.
  • 0
  • 0
  • 1
  • 7h ago
Profile picture fallback
A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete public projects via GraphQL injection. Exploitation […]
  • 0
  • 0
  • 0
  • 6h ago
Profile picture fallback
GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure thehackernews.com/2026/08/gitl...
  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Elementor
  • Elementor Pro

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.0)
EPSS
0.42%

KEV

Description

Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1.

Statistics

  • 5 Posts
  • 4 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

⚠️ Unauthenticated attackers could turn Elementor Pro uploads into RCE.

CVE-2026-32475 lets an attacker skip the file-extension blocklist and upload PHP when a published Form widget has a File Upload field. Elementor fixed it in 4.2.2.

Read: thehackernews.com/2026/08/elem

  • 1
  • 2
  • 0
  • 9h ago
Profile picture fallback

Elementor Pro : une faille critique permet de prendre le contrôle d’un site WordPress it-connect.fr/elementor-pro-cv #ActuCybersécurité #Cybersécurité #Vulnérabilité #Wordpress

  • 1
  • 0
  • 0
  • 6h ago
Profile picture fallback

「Elementor Proの重大なバグにより、WordPressサイトがリモートコード実行攻撃に晒される 」: #BLEEPINGCOMPUTER

「WordPressプラグイン「Elementor Pro」に存在する重大な脆弱性により、攻撃者が実行可能ファイルをアップロードして、サーバー上でリモートコードを実行できる可能性がある。

CVE-2026-32475として識別されたこの脆弱性は、Elementor Proのバージョン4.2.2より前のバージョンに影響し、ファイル検証と処理に別々のループを使用するファイルアップロードモジュールに起因しており、ファイル名が空のアップロードの処理方法が異なっています。」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 0
  • 0
  • 8h ago
Profile picture fallback

CVE-2026-32475 (CVSS 9.8) is an unauthenticated file upload flaw in Elementor Pro. It threatens complete site compromise across 6 million sites.

securityonline.info/cve-2026-3

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
📢 [VULN] WordPress : cette faille Elementor Pro ouvre votre site aux pirates CVE-2026-32475 Nouvelle alerte à destination de tous les administrateurs de sites WordPress : la faille CVE-2026-32475, corrigée le 19 août 2026 dans Elementor Pro, permet à un visiteur anonyme de dépos… #CVE #Cyberveille
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • NetScaler
  • ADC

19 Aug 2026
Published
20 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.33%

KEV

Description

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Statistics

  • 6 Posts
  • 4 Interactions

Last activity: 2 hours ago

Fediverse

Profile picture fallback

「Citrixは、NetScalerの新たな脆弱性をできるだけ早く修正するよう管理者に強く求めている。」: #BLEEPINGCOMPUTER

「Citrixは、NetScaler GatewayセキュアリモートアクセスソリューションとNetScaler ADCネットワークアプライアンスに影響を与える2つの脆弱性からシステムを保護するため、顧客に対し直ちにセキュリティ対策を講じるよう警告した。

2つのうちより深刻な脆弱性( CVE-2026-19490 として追跡)では、NetScalerのファームウェアバージョンとSAMLアクションが構成されているかどうかに応じて、アプライアンスがAAA仮想サーバーまたはゲートウェイ(SSL VPN、ICAプロキシ、CVPN、RDPプロキシ)として構成されている場合に、権限を持たないリモート攻撃者が認証をバイパスできる可能性があります。 」

bleepingcomputer.com/news/secu

#prattohome

  • 0
  • 0
  • 0
  • 8h ago

Bluesky

Profile picture fallback
"Citrix NetScaler : la CVE-2026-19490 permet de contourner l'authentification sur les passerelles NetScaler (VPN [lire]
  • 1
  • 0
  • 0
  • 12h ago
Profile picture fallback
On August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3 and can be exploited remotely by an unauthenticated attacke..
  • 0
  • 1
  • 0
  • 12h ago
Profile picture fallback
Citrix urges customers to fix critical NetScaler authentication bypass (CVE-2026-19490) 🔗 Read more: www.helpnetsecurity.com/2026/08/21/c... #Citrix #vulnerability #cybersecurity
  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback
Citrix flags urgent NetScaler patching for CVE-2026-19490 and CVE-2026-19489, which can enable auth bypass and denial of service on specific setups. CISA still tracks prior Citrix flaws in KEV. #Citrix #NetScaler #CISA
  • 1
  • 0
  • 0
  • 21h ago
Profile picture fallback
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19489 and CVE-2026-19490 #patchmanagement
  • 0
  • 0
  • 0
  • 2h ago

Overview

  • Zimbra
  • Collaboration

13 Aug 2026
Published
14 Aug 2026
Updated

CVSS v3.1
HIGH (8.9)
EPSS
0.54%

KEV

Description

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Statistics

  • 4 Posts
  • 1 Interaction

Last activity: 7 hours ago

Bluesky

Profile picture fallback
Attackers exploit CVE-2026-73570 on Zimbra servers with zimbra-snmp installed and SNMP notifications enabled, allowing unauthenticated RCE.
  • 0
  • 1
  • 0
  • 7h ago
Profile picture fallback
Actively exploited vulnerability in Zimbra Collaboration Suite CVE-2026-73570
  • 0
  • 0
  • 0
  • 23h ago
Profile picture fallback
CERT Polska reports active exploitation of CVE-2026-73570 in Zimbra Collaboration. The flaw affects systems with zimbra-snmp and SNMP notifications enabled, allowing unauthenticated OS command execution as the Zimbra user. #Zimbra #CERTPolska #Poland
  • 0
  • 0
  • 0
  • 22h ago
Profile picture fallback
Zimbraの未認証リモートコード実行(RCE)脆弱性(CVE-2026-73570、CVSS 8.9)が野生下で悪用中 CVE-2026-73570 Exploited in the Wild: Unauthenticated RCE Hits Zimbra #DailyCyberSecurity (Aug 20) securityonline.info/zimbra-cve-2...
  • 0
  • 0
  • 0
  • 14h ago

Overview

  • TrueConf
  • TrueConf Server

19 Aug 2026
Published
21 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
0.78%

Description

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

Statistics

  • 4 Posts

Last activity: 1 hour ago

Fediverse

Profile picture fallback

Critical Alert: CVE-2026-72529 allows unauthenticated command execution on TrueConf Servers. Our T-SUITE report maps the attack surface and provides immediate hardening steps to secure your perimeter. Read the full brief here. thecybermind.co/jily

  • 0
  • 0
  • 0
  • 1h ago
Profile picture fallback

CISA confirms two TrueConf Server flaws, CVE-2026-72529 and CVE-2026-72530, are exploited in the wild to deliver PhantomCore malware. Patch now.

securityonline.info/trueconf-c

  • 0
  • 0
  • 0
  • 18h ago

Bluesky

Profile picture fallback
~Cisa~ CISA added two actively exploited TrueConf Server vulnerabilities to the KEV Catalog. - IOCs: CVE-2026-72529, CVE-2026-72530 - #CISA #CVE202672529 #ThreatIntel
  • 0
  • 0
  • 0
  • 19h ago
Profile picture fallback
CISAが既知の悪用された脆弱性2件をカタログに追加 CISA Adds Two Known Exploited Vulnerabilities to Catalog #CISA (Aug 20) CVE-2026-72529 TrueConfサーバーの重要な機能に対する認証の欠如の脆弱性 CVE-2026-72530 TrueConfサーバーのコードインジェクション脆弱性 www.cisa.gov/news-events/...
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • PTC
  • Windchill PDMLink

18 Jun 2026
Published
01 Aug 2026
Updated

CVSS v4.0
CRITICAL (9.3)
EPSS
30.20%

Description

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data.  * This advisory also applies to all CPS versions * The identified vulnerability also impacts Windchill and FlexPLM releases prior to 11.0 M030

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 21 hours ago

Fediverse

Profile picture fallback

⚠️ CRITICAL: Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

Clop ransomware operators deployed a custom JSP web shell targeting PTC Windchill and FlexPLM servers, exploiting CVE-2026-12569 to decrypt stored credentials and exfiltrate engineering data. Any organization running vulnerable Windchill instances is at immediate risk of credential compromise, late…

threatnoir.com/focus

🤖 AI generated summary

  • 0
  • 0
  • 0
  • 23h ago

Bluesky

Profile picture fallback
📢 Clop exploite CVE-2026-12569 dans PTC Windchill avec un web shell personnalisé pour extorsion massive 📅 Source : ReliaQuest Threat Research Team, publié le 18 août 2026. Cette analyse technique décrit une campagne d'extorsion de… 🟢 vérification factuelle haute #Clop #PTCWindchill #Cyberveille
  • 1
  • 0
  • 0
  • 21h ago

Overview

  • Headroom Labs
  • Headroom
  • headroom-ai

21 Aug 2026
Published
21 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.1)
EPSS
Pending

KEV

Description

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/proxy/handlers/openai.py, including the chat completion and websocket paths, and nothing binds the value to the caller. A client can therefore name another user's identifier and read or write that user's stored LLM memory. The fix introduces a single resolve_memory_identity seam in headroom/proxy/identity.py that honors the header only for loopback or allowlisted callers and otherwise binds the identity to the proxy-token fingerprint or the operating system user. The pip console script binds 127.0.0.1 by default, but the reference docker-compose.yml ships --host 0.0.0.0 with published ports and no required HEADROOM_PROXY_TOKEN, which the server itself warns about at startup, so a deployment following the shipped compose exposes the affected data-plane routes to the network without authentication.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 1 hour ago

Fediverse

Profile picture fallback

CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. radar.offseq.com/threat/cve-20

  • 1
  • 0
  • 0
  • 4h ago
Profile picture fallback

CVE-2026-77776 - Critical IDOR in Headroom LLM proxy. Spoof x-headroom-user-id to read/write other users' memory. CVSS 9.1. No patch yet - restrict access now. #CVE #Headroom #infosec

valtersit.com/cve/CVE-2026-777

  • 0
  • 0
  • 0
  • 1h ago

Overview

  • Microsoft
  • Microsoft Malware Protection Engine

14 Aug 2026
Published
20 Aug 2026
Updated

CVSS v3.1
HIGH (7.8)
EPSS
0.23%

KEV

Description

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as &quot;ShieldBreak &quot;. We are working to provide a high quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 2 hours ago

Fediverse

Profile picture fallback

This Week in Security: Apple Warns Users, Stripe Merchants Leak Keys, Copilot Helps Hack Itself, and Comcast Senses Movement

Apple has started sending some users push notifications warning that they have been targeted with specific malware. No specific information about the threat Apple detected is available. While multiple iOS attacks were released in spring of 2026, they all target much older versions of iOS and older hardware versions.

Users in 110 countries have received notifications recently, warning them they may have been targeted or already impacted by malware such. Apple typically uses the crash reporting mechanism for system apps to track new attack trends. The majority of users will likely never see an alert from Apple because malware with state-level capabilities like the Pegasus family is extremely expensive to develop. However, commercial availability means that some governments have deployed them against political opponents, protesters, human rights lawyers, and journalists.

If Apple pushes a security alert, it will show up as an email and a standard system notification, but also as a notification inside the Settings application. While email and notifications can be spoofed as part of phishing attempts, to date there is nothing which can generate false alerts inside Settings.

Almost universally in these cases, Apple recommends enabling “Lockdown Mode“, which adds extra protection to devices at the cost of decreased battery life and slower performance. Lockdown mode disables custom fonts on web pages, accelerated JavaScript, restricts message attachments over SMS and iMessage, and disables other common paths used by malware to steal data. Android devices offer a similar feature since Android 15 that is less comprehensive but can still provide additional safeguards for users directly at risk.

Attacking Airplane Networks


With research that will surely result in some breathless reports, researchers presented at Usenix 2026 an attack against the communications bus of a Boeing 737.

The ARINC 429 bus is a communications architecture for planes, similar to the CAN bus used in cars. Once you are connected to that bus, it can be vulnerable in the same ways cars can be vulnerable to data manipulation. In the Usenix paper, researchers discovered that one access port to the airplane communications system is easily reached from the outside of the plane, though “easily” in this context means “by airplane maintenance technicians”. The paper represents over a decade of work by the team in obtaining and building a test lab of avionics equipment to represent an actual airplane, culminating in an embedded device described as “the size of a quarter” that plugs into the communications port and provides remote access over WiFi.

It needs to be emphasized, given other recent news, that this is a piece of hardware being added to the plane which communicates over WiFi, and not a way to attack an unmodified plane via passenger WiFi!

Once part of the ARINC bus, it seems access is basically unfettered: the team describes being able to reprogram the autopilot, feed the pilot displays false data, and being able to modify the temperature and weight data shown, which could lead to miscalculations in take-off speeds with obviously catastrophic results. Fortunately, the researchers have also been working with Boeing since 2020 to address the issues being found, and the practicality of the attack in the wild remains largely theoretical. The research team has recommended removing the external ports in future aircraft, and blocking access to them physically, like with epoxy, in the current designs.

If reading security research papers is your kind of fun, be sure to check out the rest of the papers that were part of Usenix 2026.

Copilot Reveals Secrets


Microsoft Copilot was tricked into executing hostile prompts without user intervention, and the team that accomplished it used Copilot itself to expose the vulnerability.

Copilot has a set of guardrails in place intended to safeguard against disclosing private information. Given the initial question — asking how to submit a prompt without the user confirming — the model said this was impossible. Over the course of many questions, researchers at Varonis were able to get Copilot to disclose the exact errors and restrictions that prevented running unauthorized queries, culminating in it admitting that there was an undocumented URL parameter (“autorun=1”, naturally) that would automatically execute a query.

Why such a parameter would exist in the first place is a little unclear. The Ars Technica article says that when Microsoft removed the parameter as part of the initial fix, it caused several AI browser extensions to fail, hinting that it may have been in place to enable automation on behalf of the user without showing the user the actual prompts being run. Regardless, prompts set to autorun were allowed to execute with no intervention, including prompts to disclose the contents of the users inbox, stored information in the users Copilot session, and any connected apps and services.

Comcast Senses Motion With WiFi


Comcast is enabling “WiFi Motion Detection” on its fleet of home router/access point devices. Conceptually, it’s a fairly simple trick. When a WiFi device changes position, or if something partially blocks the signal, the signal level of the device will change. People and pets are basically various sized bags of radio-blocking water, and as we move around we cause fluctuations in the signal levels of surrounding devices.

The risks lie in the second-order aspects: how much data is collected, how is it stored, and what does it expose about your home? Comcast says the feature is optional, and is opt-in: it won’t be turned on unless a customer enables it. This is refreshing, but once enabled, how is the data protected? Currently, Comcast states that the fidelity of the information may not be able to distinguish between a large pet and a small child, and can not identify individual people, but other public projects have refined a similar process to identify the number of people and characteristics about specific people, all based on the signal level. (Be careful when looking for other projects, though. There are several that appear to be completely AI generated, with both false claims and false data!)

As a company subject to the laws of any countries they operate in, Comcast may also be legally compelled to turn over motion and presence data in criminal or civil cases, or may opt to re-sell the data for other training or advertising purposes. Leveraging equipment you already have to collect more data is cool, but personally I’m not sure I want even more tracking data of when I’m home or where I spend time in my home to be that easily collected by a third party.

Stripe Merchant Keys Leaked


The payment processor Stripe has not been hacked, but it looks like 650 companies using it may have been.

Someone has collected hundreds of Stripe API keys, probably from GitHub, mis-configured servers, and infostealer malware, and made them available on trading forums. Despite guardrails by GitHub, a common mistake is committing configuration files, environment files, or code with API keys into public repositories. Once data goes into git, it’s fairly hard to remove it without resetting the entire repository: the whole point of code management is to be able to go back in time and identify the changes! The prevalence of information stealing malware on developer devices, VSCode plugin repositories, and inside packaging systems is another excellent source of stolen authentication tokens for many services.

A Stripe API token acts as the login credentials for the company using Stripe to process payments: it allows creating charging, listing past customers, extracting stored payment data, and essentially anything else a logged in administrator can do.

Stripe themselves say that they actively scan GitHub and other source management platforms looking for leaked keys and notifying customers, and hopefully impacted companies will be notified and can rotate their API tokens before they are used against actual customers.

More Windows Defender Issues


Last week was another Microsoft Patch Tuesday, which somehow didn’t set a third record for the highest number of security fixes in a month. Nonetheless, it would hardly be a proper Patch Tuesday in 2026 without another bypass of Windows Defender.

Previous exploits released by the researcher known as NightmareEclipse have demonstrated bypasses for BitLocker and Windows Defender and have stirred legal threats from Microsoft. Previous attacks against Windows Defender were fixed in the July set of patches, however now the “ShieldBreak” exploit, identified as CVE-2026-69414, uses Windows Defender itself to escalate to admin privileges.

The current fix? Disable Windows Defender. Which probably isn’t a great plan. Hopefully Microsoft is able to release an official fix rapidly.

Kicking Out Hackers by Cutting the Cable


A new article discusses how, during the Salt Typhoon attacks, T-Mobile operators drove to the datacenter physically cut the cable from a compromised system to prevent the attackers from accessing the rest of the network.

Salt Typhoon is believed to be a group based in China, often credited as part of the Ministry of State Security, which perpetrated widespread hacks of the United States telecom industry in 2024. The attackers utilized the hooks in the infrastructure devices required for US wiretap law, which gave them access to call records, contents of text messages, and voice recording of calls, targeting industry, government, and election officials.

Stopping a hack with a pair of wire cutters is definitely a story worth remembering.

Supply Chain Attacks Hit Rust


Supply chain attacks appear to be spreading to Rust packages now. The Rust Security Response Team was notified that a set of packages were downloading malicious payloads during build and confirmed the behavior.

To facilitate building required components, Rust packages can include a build script that is automatically compiled and executed. This is extremely similar to the build hooks enabling the spread of malware in the NPM and PyPI repositories, and could be used to perform the same authentication token theft and manipulation of packages.

Time will show if the Rust Cargo repository is able to prevent a similar scourge of infected packages now that the alarm is raised.

DEF CON Speakers and Attendees Targeted


Huntress reports some DEF CON speakers and attendees are being targeted with a phishing campaign on X/Twitter.

Starting with a claim to be the vice president of Coindesk, the phishing lure asks to collaborate on a future conference and provides a link to a Google document. The Google doc then tries to trick the user into running a click-fix style attack where the user is asked to copy and paste malware into a command shell, or into downloading a malware binary outright.

The malware payload targets the usual selection of cryptocurrency, authentication tokens, SSH keys, and the like. The Huntress article dives deep into the makeup of the malware, which has custom deployments if the victim is on Windows or macOS and can download several dynamic stages as the infection is triggered.

hackaday.com/2026/08/21/this-w…

  • 0
  • 0
  • 0
  • 2h ago

Bluesky

Profile picture fallback
CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days | Qualys blog.qualys.com/product-tech...
  • 1
  • 0
  • 0
  • 5h ago

Overview

  • Significant-Gravitas
  • AutoGPT

19 May 2026
Published
19 May 2026
Updated

CVSS v3.1
MEDIUM (5.0)
EPSS
0.30%

KEV

Description

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions 0.1.0 through 0.6.51, SendEmailBlock in autogpt_platform/backend/backend/blocks/email_block.py accepts a user-supplied smtp_server (string) and smtp_port (integer) as per-execution block inputs, then passes them directly to Python's smtplib.SMTP() to open a raw TCP connection with no IP address validation. This completely bypasses the platform's hardened SSRF protections in backend/util/request.py — the validate_url_host() function and BLOCKED_IP_NETWORKS blocklist that every other block uses to block connections to private, loopback, link-local, and cloud metadata addresses. An authenticated user on a shared AutoGPT deployment can use this to perform non-blind internal network port scanning and service fingerprinting: smtplib reads the target's TCP banner on connect and embeds it in the exception message, which is persisted as user-visible block output via the execution framework. This issue has been fixed in version 0.6.52.

Statistics

  • 2 Posts
  • 1 Interaction

Last activity: 15 hours ago

Bluesky

Profile picture fallback
How an AutoGPT Email Block Became an SSRF Surface CVE-2026-33234 let authenticated AutoGPT users scan internal networks and leak SSH banners through its unprotected SMTP connection path. Telegram AI Digest #ai #autogpt #gpt
  • 0
  • 1
  • 0
  • 15h ago
Profile picture fallback
Как блокировка электронной почты AutoGPT стала поверхностью для SSRF CVE-2026-33234 позволяет аутентифицированным пользователям AutoGPT сканировать внутренние сети и утекать SSH-баннеры через незащищенный путь SMTP-соединения. Telegram ИИ Дайджест #ai #autogpt #gpt
  • 0
  • 0
  • 0
  • 15h ago
Showing 1 to 10 of 69 CVEs