Vulnerabilities and CVEs NASA F Prime GDS CVE-2026-72577: RCE in a ground control system
Missing authentication and path traversal can enable remote code execution and command submission. We separate the confirmed facts from operational risk.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs Missing authentication and path traversal can enable remote code execution and command submission. We separate the confirmed facts from operational risk.
Vulnerabilities and CVEs InfiniteWP Client before 1.13.6 allowed an attacker-controlled key to be bound and a WordPress Multisite administrator session hijacked. Here is the impact and response.
AI Security Encoded directory sequences bypassed Starlette normalisation before pathlib escaped the UI directory. LoLLMs releases before version 3 require an update.
AI Security New flaws in DataWorks MCP, mcp-google-search, Skill Ninja and spec-workflow show how a tool-call URL or path crosses network and workspace boundaries.
Vulnerabilities and CVEs CVE-2026-71983 through CVE-2026-71993 affect WPS, VPN, filtering and router administration. We explain the shared weakness, exposure and response plan.
AI Security A malicious link and indirect prompt injection used a Rovo user's permissions. We explain retrieval, exfiltration, connectors and egress control.
Vulnerabilities and CVEs CISA added the critical command injection to KEV. We explain the buffer-initialisation flaw, path to root commands, fixed releases and appliance triage.
Penetration Testing and AppSec Container queries, web fonts and ligatures turned decrypted text into network requests without JavaScript. We explain the attack and correct isolation.
Supply Chain Security Compromised TrueConf servers distributed a client containing the PhantomPxPigeon backdoor. We examine supply-chain trust, code signing and response.
AI Security Coding-agent harness flaws enabled pre-sandbox command execution and secret exfiltration. We examine the trust boundaries and practical CI hardening.
Penetration Testing and AppSec James Kettle's system analysed thousands of HTTP rules and exposed new parser discrepancies. We explain desync, RQP, human validation and defence.
Threats and Incidents A critical Metabase SQL injection was exploited before a patch was published. We examine the endpoint, attack chain, fixed versions and response plan.
Vulnerabilities and CVEs A use-after-free in SCTP Dynamic Address Reconfiguration enabled local privilege escalation and container escape. We explain the mechanism and defence.
AI Security Five agent-runtime flaws allowed forged tool calls or approvals to bypass LLM inference. We explain why the model cannot serve as an authorisation layer.
Threats and Incidents WordArray.random() produced recoverable seeds in five wallet apps. We examine entropy, on-chain investigation and safe fund migration.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.