Overview
- zarinpal
- Zarinpal Gateway
Description
Statistics
- 1 Post
Fediverse
🛡️ CVE-2026-2592 (HIGH, CVSS 7.7): Zarinpal Gateway for WooCommerce has improper access control — orders can be marked as paid via reused authority tokens. All versions affected. Audit callback validation & monitor for fraud. Details: https://radar.offseq.com/threat/cve-2026-2592-cwe-284-improper-access-control-in-z-22959dc1 #OffSeq #WooCommerce #WordPress
Overview
- Wireshark Foundation
- Wireshark
Description
Statistics
- 1 Post
Overview
- HKUDS
- nanobot
Description
Statistics
- 1 Post
Fediverse
🔴 CVE-2026-2577: CRITICAL vuln in HKUDS nanobot WhatsApp bridge (port 3001) — no auth required for WebSocket! Attackers can hijack sessions & intercept messages. Restrict access & monitor traffic. https://radar.offseq.com/threat/cve-2026-2577-cwe-306-missing-authentication-for-c-d0d526e7 #OffSeq #CVE20262577 #Infosec #Vuln
Overview
- BVA
- Concierge::Sessions
- Concierge-Sessions
Description
Statistics
- 1 Post
Fediverse
⚠️ CVE-2026-2439 (HIGH): BVA Concierge::Sessions 0.8.1-0.8.4 uses weak session ID generation, risking session hijack. Upgrade or use secure RNG for session IDs! No active exploits, but risk is significant. https://radar.offseq.com/threat/cve-2026-2439-cwe-340-generation-of-predictable-nu-8847b5d6 #OffSeq #Infosec #Vuln #SessionID
Overview
- pretix
- pretix-doistep
- pretix-doistep
Description
Statistics
- 1 Post
Fediverse
⚠️ CVE-2026-2451 (HIGH): pretix-doistep 1.0.0 allows backend users to abuse email template placeholders to exfiltrate config, DB passwords & API keys. Rotate creds, audit templates & restrict edit rights ASAP. https://radar.offseq.com/threat/cve-2026-2451-cwe-627-dynamic-variable-evaluation--3e2879f1 #OffSeq #Vulnerability #pretix #InfoSec
Overview
- EFM
- iptime A6004MX
Description
Statistics
- 2 Posts
Fediverse
CVE-2026-2550 (CRITICAL, CVSS 9.3) in EFM iptime A6004MX 14.18.2: Unrestricted remote file upload via /cgi/timepro.cgi. Exploit public, no vendor response. Isolate affected devices ASAP. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vulnerability #InfoSec #RouterSecurity
CVE-2026-2550 (CRITICAL): EFM iptime A6004MX (fw 14.18.2) allows unauthenticated uploads via /cgi/timepro.cgi — enabling full device compromise. No patch yet. Block access & monitor for malicious activity. https://radar.offseq.com/threat/cve-2026-2550-unrestricted-upload-in-efm-iptime-a6-a8baac0d #OffSeq #Vuln #RouterSecurity #CVE2026
Overview
Description
Statistics
- 2 Posts
Overview
- Soliton Systems K.K.
- FileZen
Description
Statistics
- 1 Post
Fediverse
Recent intelligence (Feb 15-16, 2026): Google patched an actively exploited Chrome zero-day (CVE-2026-2441), and a critical FileZen flaw (CVE-2026-25108) also sees in-the-wild exploitation. Microsoft unveiled an AI Security Dashboard for enterprises. Geopolitically, China's Russian oil imports surged 21%, and Indonesia considers deploying 8,000 troops to Gaza. A Trusted Tech Alliance formed to secure digital infrastructure. AI ethics concerns continue to be prominent.