home.social

Search

159 results for “offseq”

  1. Chrome 155 patches 247 vulnerabilities, including 4 CRITICAL use-after-free bugs (CVE-2026-106382, - 106197, - 106358, - 106347) across Chromecast, Browser, Navigation & Track. Update on Windows, macOS & Linux. No active exploits. radar.offseq.com/threat/chrome

  2. CVE-2026-103416: CRITICAL out-of-bounds write in Eclipse ThreadX NetX Duo (≤6.5.1.202602). Exploitable pre-cert auth; risk of code execution or DoS. Patch not released — check vendor updates. radar.offseq.com/threat/cve-20

  3. Manacle Technologies Multi-tenant ERP System hit by CVE-2026-107104 (CRITICAL, CVSS 9.3): Unsafe deserialization lets unauthenticated attackers execute code remotely. No fix yet — restrict access & monitor systems. radar.offseq.com/threat/cve-20

  4. Android Oct 2026 security update patches 25 vulnerabilities — 7 CRITICAL, incl. System privilege escalation with no user interaction. Pixel & Automotive OS also patched. No active exploitation yet. Update ASAP. radar.offseq.com/threat/androi

  5. ASUS Router XSS (CVE-2026-14911, CRITICAL, CVSS 9.3): Remote attackers can exploit improper input neutralization to execute scripts, alter settings, or cause DoS if visited by authenticated users. No patch yet. Details: radar.offseq.com/threat/cve-20

  6. Flexera FlexNet Publisher (≤11.19.11) suffers a CRITICAL auth bypass (CVE-2026-19572, CVSS 9.3). SOAP handler flaw allows unauthenticated admin access. Patch not yet available — monitor systems closely. radar.offseq.com/threat/cve-20

  7. wolfSSH <1.6.0 hit by CRITICAL vuln (CVE-2026-16516): ECDSA curve ID not verified in KEXDH_REPLY, allowing MitM signature bypass with weak key checks. Patch or harden key validation. radar.offseq.com/threat/cve-20

  8. IBM Langflow OSS v1.0.0 – 1.12.2 is affected by CRITICAL code injection (CVE-2026-93674, CVSS 9.8). Remote code exec possible via improper OS command neutralization. No patch yet — restrict network access & monitor activity. radar.offseq.com/threat/cve-20

  9. Rockstar Games: CRITICAL multi-vector breaches (2018 – 2026). No zero-days — abused MFA fatigue, OAuth token theft, P2P RCE, poor segmentation. GTA VI dev build stolen. Improve DLP, segmentation, token security. radar.offseq.com/threat/rockst

  10. CVE-2026-82531: CRITICAL code injection bug in smarty-php Smarty (<4.5.8, 5.0.0<5.8.5). Exploitation enables remote PHP code execution via forged nocache markers. Patch to 4.5.8/5.8.5 ASAP. radar.offseq.com/threat/cve-20

  11. Unauthenticated SQL Injection (CVE-2026-41555, CRITICAL, CVSS 9.3) in Weblizar Newsletter Subscription Form <=1.5.9 impacts WordPress sites. Patch status unknown — restrict/disable the component. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #SQLInjection

  12. CRITICAL SQL injection (CVE-2026-42415) in p-themes Porto Theme - Functionality ≤3.9.3. Unauthenticated attackers can steal sensitive data. No official patch yet — restrict access ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE202642415 #Infosec #WordPress #SQLInjection

  13. CVE-2026-42417 (CRITICAL): ARMember Premium <= 7.8 is vulnerable to unauthenticated SQL Injection (CWE-89). No mitigation yet — review deployments & monitor databases closely. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #SQLInjection #WordPress

  14. CVE-2026-105778: CRITICAL stack-based buffer overflow in Tenda AC5 (v02.03.01.111_multi). Remote attackers can execute code via the /goform/setWifi endpoint. No patch yet — restrict remote access & monitor for exploits. radar.offseq.com/threat/cve-20 #OffSeq #CVE #Infosec #IoT

  15. CVE-2026-75962: HIGH severity stored XSS in Post SMTP WordPress plugin (<=4.0.1). Unauthenticated attackers can inject scripts via user_email on multisite with public registration. Patch or restrict registration. radar.offseq.com/threat/cve-20

  16. CVE-2026-91107: CRITICAL auth bypass in openSIS-Classic 9.3 🛑. Teacher-role users can reset passwords of any staff via the staff_id parameter. No patch yet — restrict permissions & monitor password changes. radar.offseq.com/threat/cve-20

  17. TOTOLINK X6000R (9.4.0cu.652_B20230116) hit by CRITICAL OS command injection (CVE-2026-105484). Remote, unauthenticated attackers can gain full control. Restrict interface access & monitor /cgi-bin/cstecgi.cgi. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

  18. CVE-2026-21589 (CRITICAL, CVSS 9.3) in Atlassian Bamboo Data Center <10.2.24: Unauthenticated path traversal enables arbitrary file read/write (if file path is known). Patch to 10.2.24+ required — no workarounds. Details: radar.offseq.com/threat/cve-20 #OffSeq #Atlassian #Infosec

  19. CVE-2026-105763 (CRITICAL): twentyhq twenty CRM v1.20.10 – 2.7.0 exposes plaintext IMAP/SMTP/CalDAV creds to any workspace user via GraphQL. Upgrade to 2.7.0 to prevent mail/calendar compromise. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #CRM #twentyhq

  20. CVE-2026-105207: CRITICAL vuln in ZITADEL 3.0.0 – 3.4.15 & 4.0.0<4.17.3 allows unauthenticated attackers to link their own IdP identity to any account — full takeover possible. Patch status unknown. Details: radar.offseq.com/threat/zitade #OffSeq #ZITADEL #Vuln #AccountSecurity

  21. CRITICAL: gist RubyGem versions 4.0.0 – <6.1.0 vulnerable to improper cert validation (CVE-2026-105221). SSL verification is disabled, exposing GitHub creds to on-path attackers. Patch to 6.1.0+ now! radar.offseq.com/threat/cve-20 #OffSeq #CVE2026105221 #RubyGems #infosec

  22. CVE-2026-105223 (CRITICAL, CVSS 9.1): maclof kubernetes-client v0.17.0 – 0.31.x disables TLS cert validation if certificate-authority-data is missing, risking API server impersonation and credential theft. Check configs & vendor advisories. radar.offseq.com/threat/cve-20 #OffSeq #kubernetes #security

  23. CVE-2026-105222: CRITICAL vuln in alexpechkarev/google-maps (v1.0.3 – 12.16). TLS cert checks off by default — API keys can leak, responses tampered. Set ssl_verify_peer=TRUE. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Laravel #CVE2026_105222

  24. Offset Caught On Camera in Heated Conflict With Casino Officials Over Alleged Blackjack Blunder: ‘I Will F**kin’ Leave’ #Vice twp.ai/E5H7XY

  25. Inside the Knicks' offseason, the 'longest, shortest summer ever' nytimes.com/athletic/7648988/2 Winning an NBA title, especially in New York, comes with a lot of attention, a lot of responsibilities and a lot of perks. #Sports #News

Share on Mastodon

Enter the server where you have an account.