Vulnerabilities and CVEs Metacat CVE-2026-48528: the public CN API can compromise the database
Unauthenticated SQL injection in DataONE CN endpoints exposes data and enables database changes. We cover the 3.4.1 upgrade and a safe workaround.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs Unauthenticated SQL injection in DataONE CN endpoints exposes data and enables database changes. We cover the 3.4.1 upgrade and a safe workaround.
AI Security An open API, permissive CORS and a scratchpad calling exec() form a complete RCE chain. We explain Minds Platform exposure and response without a patch.
Vulnerabilities and CVEs First- and second-order flaws in backlink search can compromise the SiYuan database. We examine the mechanism, exposure and upgrade to 3.7.4.
Supply Chain Security CVE-2026-73623–73625 bypass option controls through templates, diff output and kwarg value smuggling. We examine the fixes and CI exposure.
AI Security Missing file_path validation in confluence_upload_attachment exposes every server-readable file. Prompt injection can activate the vulnerable flow.
Vulnerabilities and CVEs PostgreSQL 18.6, 17.11, 16.15, 15.19 and 14.24 address 28 vulnerabilities. We map the highest-risk classes and a safe update plan.
Supply Chain Security OIDC client flaws allowed discovery redirects, verifier-cache poisoning and ServiceAccount token disclosure. Fulcio 1.8.6 fixes all three paths.
Supply Chain Security The archived cloudflare/pages-action is vulnerable in every release and will not be patched. Migration to wrangler-action also requires tighter tokens.
Vulnerabilities and CVEs An authentication flaw allows remote GUI or CLI access without a valid account. We map affected branches, immediate controls and investigation steps.
Cloud, Infrastructure and DevSecOps A legacy gcp auth-provider cmd-path bypassed the existing exec check. A malicious Kubernetes configuration could launch a process on a shared worker.
AI Security Image and Audio parsing performed I/O during coercion. A malicious model could name a local path and send its contents to an LLM endpoint.
Vulnerabilities and CVEs The official MSRC release contains 790 CVE records. An exploited AFD flaw leads the queue, but SharePoint, Office, Azure and active roles also need review.
Supply Chain Security A 32-bit integer wrap corrupts the shared CSPRNG pool offset. Later IDs can become a constant string, so updating alone may not complete the response.
Cloud, Infrastructure and DevSecOps A 35-CVE wave covers command injection, cross-tenant access and authorization flaws. Here is the scope, the 0.29.13 fixes and a safe response plan.
Supply Chain Security A small HDF5 file can declare petabytes of data and stop load_model(). We examine the patch, model supply-chain risk and layered defensive controls.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.