Aggregator
CVE-2026-40166 | goauthentik up to 2025.12.4/2026.2.2 OAuth2 Access Token access_tokens client_id/client_secret information disclosure (GHSA-hhpc-rqgm-pxj4)
CVE-2026-39969 | baptisteArno typebot.io up to 3.16.x Webhook Message webhook improper authentication (GHSA-8vqp-r5w7-v47f / EUVD-2026-31485)
CVE-2026-48700 | LXQt PCManFM-Qt up to 2.4.0 org.freedesktop.FileManager1.ShowFolders dynamically-managed code resources
CVE-2026-39967 | baptisteArno typebot.io up to 3.15.x startChat Endpoint authorization (GHSA-f475-7m4x-m6mx)
CVE-2026-39970 | baptisteArno typebot.io up to 3.15.x SVG File cross site scripting (GHSA-jj87-c343-26vp)
CVE-2026-39968 | baptisteArno typebot.io up to 3.15.x Preview Chat Endpoint getCredentials access control (GHSA-cq66-9cwr-x8jr)
CVE-2026-39966 | baptisteArno typebot.io up to 3.15.x getLinkedTypebots API Endpoint Array.filter authorization (GHSA-3fr5-999r-84qj)
CVE-2026-9291 | AWS Amazon Braket Python SDK up to 1.116.x Job Results Processing deserialization (GHSA-g697-2xrc-gc46)
Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos
A highly sophisticated supply chain attack has compromised the Laravel-Lang ecosystem, injecting credential-stealing remote code execution backdoors into 233 package versions across 700 GitHub repositories. Discovered in May 2026 by Socket and Aikido, threat actors manipulated GitHub tags to distribute malware through Composer’s autoloader, granting complete remote access to developer environments. The attackers bypassed direct […]
The post Hackers Compromised 233 Versions of Laravel-Lang Packages by Hacking 700 GitHub Repos appeared first on Cyber Security News.
Карпову 75: чемпион, после партий с которым соперники не сразу понимали, где проиграли
CVE-2026-9284 | WooCommerce PayPal Payments Plugin up to 4.0.1 on WordPress ppc-create-order/ppc-get-order authorization (EUVD-2026-31524)
Запуск посреди эскалации, но "не про политику". США испытали ядерную ракету, которой уже 55 лет
Frigate NVR 0.16.3 Remote Code Execution
Linux nf_tables 6.19.3 Local Privilege Escalation
ThingsBoard IoT Platform 4.2.0 Server-Side Request Forgery (SSRF)
Linux Kernel Local Privilege Escalation (CVE-2026-43284 / CVE-2026-43500 / CVE-2026-46300)
SUSE Manager 4.3.15 Code Execution
Sub2Api Codex登录出现严重问题 账号无法认证且可能必须手机号验证
The War for Your Documents: Why The Document Foundation is Challenging Microsoft’s OOXML Monopoly
The Document Foundation (TDF), the steward of the open-source office suite LibreOffice, has long been embroiled in an irreconcilable conflict with Microsoft regarding document interoperability. The heart of this contention lies in the divergence...
The post The War for Your Documents: Why The Document Foundation is Challenging Microsoft’s OOXML Monopoly appeared first on Information Security News.