Overview
Description
Statistics
- 2 Posts
Fediverse
ReliaQuest reports active exploitation of CVE-2026-0257, an authentication-bypass flaw affecting Palo Alto Networks PAN-OS GlobalProtect and Prisma Access.
It says groups Qilin and Settra are using it to create unauthorized VPN connections and enter internal corporate networks; those connections may resemble routine remote work and delay detection.
Exposure is configuration-dependent: authentication override cooki…
Ransomware Actors Weaponize Palo Alto GlobalProtect Authentication Bypass for Stealthy VPN Access
Palo Alto GlobalProtect CVE-2026-0257 is being exploited by Qilin and Settra ransomware actors. Check affected PAN-OS versions, IOCs, and fixeshttps://thecybersecguru.com/news/cve-2026-0257-globalprotect-vpn-ransomware/
Overview
- WuKongOpenSource
- Wukong_HRM
Description
Statistics
- 2 Posts
Fediverse
CRITICAL: CVE-2026-108707 in WuKong_HRM (≤ commit 186115e) enables auth bypass — attackers can access all HRM APIs, gaining admin rights and exposing sensitive HR data. Restrict endpoints & monitor for unauthorized access. https://radar.offseq.com/threat/cve-2026-108707-improper-authentication-in-wukongopensource-wukonghrm-13cec42117273b1c #OffSeq #CVE2026108707 #infosec #vulnerability
CVE-2026-108707 - Critical Auth Bypass in Wukong_HRM allows full API takeover & sensitive HR data theft. CVSS 9.8. Restrict API access immediately. #CVE #infosec #cybersecurity
Overview
Description
Statistics
- 1 Post
- 5 Interactions
Fediverse
The issue now is: Ceph 20 is still on an older NFS Ganesha version which hasn't got the fix yet. Ceph 21 does have the fix, but it also has the fix for this CVE: https://medium.com/rook-io/rook-advisory-for-ceph-cve-2025-30156-cc1f8dee6da3
Which means I'm currently in a bit of a deadlock. I can't really update my hosts to the newer Ubuntu, because of the Ganesha bug. But I also can't update Ceph/Ganesha because I need a newer kernel.
EDIT: I was wrong, the fix does work with older kernels, see the replies to this post.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🚨 Critical Ollama Vulnerability: CVE-2026-103663
A critical security vulnerability has been disclosed in Ollama, the popular platform for running AI models locally and on private infrastructure.
The vulnerability allows unauthenticated attackers to exploit a path traversal weakness in the model-pull functionality, potentially writing malicious files outside the intended model directory.
#SecPoint #Ollama #AISecurity #CyberSecurity #VulnerabilityManagement
Overview
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
from my link log —
Why the OpenSSL punycode vulnerability was not detected by fuzz testing.
http://allsoftwaresucks.blogspot.com/2022/11/why-cve-2022-3602-was-not-detected-by.html
saved 2022-11-21 https://dotat.at/:/U3II7.html
Overview
- topoteretes
- cognee
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
@wdormann ikr? Seems like VulDB has a template of sorts (its not exact, see e.g. the different phrasing in https://www.cve.org/CVERecord?id=CVE-2026-105141 ) that expects a function name which.. just doesn't make sense most of the time? And the followup part of the template
The manipulation of the argument $argname results in $cwe-friendly-name.
just never makes sense for hardcoded credentials? I have said it before, I should become a CNA of my own, doesn't seem to be THAT hard...
Overview
- ThemeREX Group
- IPharm
- ipharm
Description
Statistics
- 1 Post
Fediverse
ThemeREX IPharm ipharm ≤1.2.4 hit by CRITICAL deserialization vuln (CVE-2026-93936, CVSS 9.8) 🛡️ Allows object injection & potential system compromise. No patch yet — restrict access, increase monitoring. https://radar.offseq.com/threat/deserialization-of-untrusted-data-vulnerability-in-themerex-group-ipharm-ipharm-allows-object-9d61996241f7bf9e #OffSeq #vuln #CVE202693936 #infosec
Overview
Description
Statistics
- 1 Post
Fediverse
CVE-2026-93952 Arista VeloCloud Orchestrator on-prem: remote attacker can reach privileged internal functionality, full CIA impact. CVSS 10. Patch under review; hosted already fixed. Patch now: https://www.valtersit.com/cve/CVE-2026-93952/ #CVE #infosec #Arista
Overview
- Tautulli
- Tautulli
Description
Statistics
- 1 Post
Fediverse
CVE-2026-45381 Tautulli before 2.17.2: reflected XSS via /search backslash-quote bypass, CVSS 6.1. Unauthenticated crafted link runs script in an authed user's session. Patch still under review, so restrict exposure until 2.17.2 https://www.valtersit.com/cve/CVE-2026-45381/ #CVE #infosec #Tautulli
Overview
- Unknown
- Veeqo for WooCommerce
Description
Statistics
- 1 Post
Fediverse
CVE-2026-93550 (HIGH): Veeqo for WooCommerce ≤2.2.8 lets Subscriber+ users upload arbitrary PHP files via insufficient URL validation, risking full site compromise. Restrict access & monitor plugin activity. https://radar.offseq.com/threat/cve-2026-93550-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-veeqo-for-woocommerce-e80aa084e9f36826 #OffSeq #WordPress #Vuln #BlueTeam