Overview
Description
Statistics
- 2 Posts
Overview
- GitHub
- Enterprise Server
Description
Statistics
- 1 Post
Fediverse
@DrHyde To put a fine point on it: GitHub's status page showed nothing alarming on April 23—no major outage, no partial outage—because its calculus excludes "Degraded Performance" from downtime numbers. The platform never went down; it was just silently producing wrong merge results, corrupting repository history across 230 organizations and about 3,000 pull requests. That's not a blip. That's a data integrity failure.
Here's GitHub's own heavily-spun blog post on the matter (which also covers another incident on April 27).
Bonus: Five days after the merge queue incident, GitHub disclosed CVE-2026-3854, a critical remote code execution vulnerability where a crafted git push could execute code on GitHub's servers. Patched on github.com in 75 minutes, but 88% of GitHub Enterprise Server instances were still exposed when the disclosure went public.
One bad week doesn't explain a year of red squares, but it does crystallize the pattern.
/cc @choroba
Overview
- Microsoft
- Windows Admin Center
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 2 Posts
Bluesky
Overview
- isaacs
- node-glob
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
- ci4-cms-erp
- ci4ms
Description
Statistics
- 1 Post
Fediverse
⚠️ CRITICAL XSS in ci4ms 0.31.4.0 (CVE-2026-41201): Stored DOM XSS via backup filename lets attackers fully take over accounts. Upgrade to 0.31.5.0 now! https://radar.offseq.com/threat/cve-2026-41201-cwe-79-improper-neutralization-of-i-fc417f58 #OffSeq #XSS #Vuln #InfoSec
Overview
- argoproj
- argo-cd
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: CVE-2026-42880 in Argo CD (v3.2.0 – 3.2.10, 3.3.0 – 3.3.8) allows attackers with read-only access to extract plaintext Kubernetes Secrets via the ServerSideDiff endpoint. Patch to 3.2.11/3.3.9+ now! https://radar.offseq.com/threat/cve-2026-42880-cwe-200-exposure-of-sensitive-infor-40029159 #OffSeq #ArgoCD #Kubernetes #CVE202642880
Overview
- Spring
- Spring Cloud Config
Description
Statistics
- 1 Post
Fediverse
⚠️ CRITICAL: CVE-2026-40982 in Spring Cloud Config (3.1.0 – 5.0.0) enables path traversal — attackers can access arbitrary files via crafted URLs. Upgrade to a safe version ASAP: 3.1.14, 4.1.10, 4.2.7, 4.3.3, or 5.0.3. Details: https://radar.offseq.com/threat/cve-2026-40982-cwe-22-improper-limitation-of-a-pat-df996457 #OffSeq #SpringCloud #CVE202640982