Overview
- OpenClaw
- OpenClaw
Description
Statistics
- 2 Posts
- 1 Interaction
Overview
- alexcrichton
- tar-rs
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
First supply chain problems for Rust as well. No more unique to Node https://blog.rust-lang.org/2026/03/21/cve-2026-33056/ #Rust #rustlang #Programming 🦀
Overview
- graphiti-api
- graphiti
Description
Statistics
- 1 Post
Fediverse
🚨 CRITICAL: CVE-2026-33286 in Graphiti (<1.10.2) lets unauthenticated attackers invoke arbitrary public methods via JSONAPI write requests. Patch to v1.10.2, restrict access, and validate inputs! https://radar.offseq.com/threat/cve-2026-33286-cwe-913-improper-control-of-dynamic-fd76d864 #OffSeq #CVE202633286 #Ruby #APIsecurity
Overview
Description
Statistics
- 1 Post
Overview
- Coppermine Photo Gallery
- Coppermine Photo Gallery
Description
Statistics
- 2 Posts
Overview
- Microsoft
- Windows Admin Center
Description
Statistics
- 1 Post
Bluesky
Overview
Description
Statistics
- 1 Post
Fediverse
🛡️ CVE-2026-4601: CRITICAL bug in jsrsasign <11.1.1 misses a vital DSA signing step, letting attackers recover private keys if exploited. No active attacks yet, but update ASAP! Details: https://radar.offseq.com/threat/cve-2026-4601-missing-cryptographic-step-in-jsrsas-1b19c447 #OffSeq #CVE20264601 #Crypto #Vuln
Overview
- fastify
- fastify
Description
Statistics
- 2 Posts
Fediverse
🚨 Moderate-severity security fix in fastify@5.8.3 just released!
Patches CVE-2026-3635 — vulnerable to request (protocol and host) spoofable via X-Forwarded-Proto/Host from untrusted connections when trustProxy uses restrictive trust function
https://github.com/fastify/fastify/security/advisories/GHSA-444r-cwp2-x5xf
Overview
- GeoVision
- GV-Edge Recording Manager
- GV-Edge Recording Manager
Description
Statistics
- 1 Post
Overview
- Apache Software Foundation
- Apache Struts
- com.opensymphony:xwork
Description
Statistics
- 1 Post
Fediverse
ZAST engine has identified and verified hundreds of previously undisclosed 0-days so far in Q1 2026 across modern web applications, software supply chain code, and IoT systems.
One highlighted case is CVE-2025-68493 in Apache Struts, a widely deployed Java web framework: https://struts.apache.org/
Ecosystem exposure remains significant. Sonatype reported more than 387,000 downloads in one week for affected org.apache.struts:* artifacts, with most usage concentrated in end-of-life branches. That combination of legacy adoption and delayed remediation is exactly why verification matters for enterprise infrastructure.
Technically, the issue was an XXE in com.opensymphony.xwork2.util.DomHelper.parse(), where SAXParserFactory hardening was incomplete and external entity handling was not fully disabled.
ZAST.AI focuses on autonomous verification. Findings are promoted into reports only after successful PoC validation, which supports our zero-false-positive reporting standard and helps engineering teams spend time on issues that are demonstrably real.
Full report: https://blog.zast.ai/cybersecurity/artificial%20intelligence/The-End-of-Probabilistic-Assessment/
Source (Sonatype): https://www.sonatype.com/blog/years-old-apache-struts2-vulnerability-downloaded-325k-times-in-the-past-week