16Articles
3Categories
2026-05-17Date
๐Ÿ›
CVE-2026-46483 Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag
๐Ÿ›
CVE-2026-44283 etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks
๐Ÿ›
CVE-2026-8368 LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects
๐Ÿ›
CVE-2026-8328 FTP PASV SSRF, ftpcp() does not use actual peer address, trusts server-supplied PASV host address
๐Ÿ›
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
KEV
๐Ÿ›
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 97
โš ๏ธ
Pwn2Own Berlin 2026, Day Three: DEVCORE Crowned Master of Pwn, $1.298 Million Total
โš ๏ธ
Grafana GitHub Token Breach Led to Codebase Download and Extortion Attempt
โš ๏ธ
Week in review: Cisco patches SD-WAN 0-day, unpatched Microsoft Exchange Server flaw exploited
โš ๏ธ
GitHub Actions Cache Poisoning is eating open source
โš ๏ธ
Pwn2Own Berlin 2026 concludes with $1.29 million paid for 47 zero-days
โš ๏ธ
Security Affairs newsletter Round 577 by Pierluigi Paganini โ€“ INTERNATIONAL EDITION
โš ๏ธ
Attackers exploit Funnel Builder bug to inject e-skimmers into e-stores
KEV
โš ๏ธ
iodรฉOS review: Privacy-focused Android that doesnโ€™t get in your way
โš ๏ธ
Debian 13.5 point release lands with security fixes, bug patches
๐ŸŽ™๏ธ
From cyberspace to space-cyber.