Chrome 155 patches 247 vulnerabilities, including 4 CRITICAL use-after-free bugs (CVE-2026-106382, - 106197, - 106358, - 106347) across Chromecast, Browser, Navigation & Track. Update on Windows, macOS & Linux. No active exploits. https://radar.offseq.com/threat/chrome-155-update-patches-247-vulnerabilities-28750e8d96fdecb9 #OffSeq #Chrome #Security
Search
159 results for “offseq”
-
CVE-2026-103416: CRITICAL out-of-bounds write in Eclipse ThreadX NetX Duo (≤6.5.1.202602). Exploitable pre-cert auth; risk of code execution or DoS. Patch not released — check vendor updates. https://radar.offseq.com/threat/cve-2026-103416-cwe-787-out-of-bounds-write-in-eclipse-foundation-eclipse-threadx-netx-duo-509a4f871398c232 #OffSeq #CVE2026103416 #infosec #vuln
-
Manacle Technologies Multi-tenant ERP System hit by CVE-2026-107104 (CRITICAL, CVSS 9.3): Unsafe deserialization lets unauthenticated attackers execute code remotely. No fix yet — restrict access & monitor systems. https://radar.offseq.com/threat/cve-2026-107104-cwe-502-deserialization-of-untrusted-data-in-manacle-technologies-multi-tenant-erp-9e646ff6d0c210e4 #OffSeq #CVE2026107104 #ERP #infosec
-
Android Oct 2026 security update patches 25 vulnerabilities — 7 CRITICAL, incl. System privilege escalation with no user interaction. Pixel & Automotive OS also patched. No active exploitation yet. Update ASAP. https://radar.offseq.com/threat/androids-october-2026-updates-patch-25-vulnerabilities-6aec37e2cd84fef5 #OffSeq #Android #Security #PatchUpdate
-
ASUS Router XSS (CVE-2026-14911, CRITICAL, CVSS 9.3): Remote attackers can exploit improper input neutralization to execute scripts, alter settings, or cause DoS if visited by authenticated users. No patch yet. Details: https://radar.offseq.com/threat/cve-2026-14911-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-81fca42ab40cabc9 #OffSeq #XSS #Cybersecurity
-
Flexera FlexNet Publisher (≤11.19.11) suffers a CRITICAL auth bypass (CVE-2026-19572, CVSS 9.3). SOAP handler flaw allows unauthenticated admin access. Patch not yet available — monitor systems closely. https://radar.offseq.com/threat/cve-2026-19572-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-flexera-flexnet-56f758677e3ccac3 #OffSeq #CVE202619572 #infosec #vuln
-
wolfSSH <1.6.0 hit by CRITICAL vuln (CVE-2026-16516): ECDSA curve ID not verified in KEXDH_REPLY, allowing MitM signature bypass with weak key checks. Patch or harden key validation. https://radar.offseq.com/threat/cve-2026-16516-cwe-345-insufficient-verification-of-data-authenticity-in-wolfssl-inc-wolfssh-844e4ddf5288020d #OffSeq #wolfSSH #infosec #CVE202616516
-
IBM Langflow OSS v1.0.0 – 1.12.2 is affected by CRITICAL code injection (CVE-2026-93674, CVSS 9.8). Remote code exec possible via improper OS command neutralization. No patch yet — restrict network access & monitor activity. https://radar.offseq.com/threat/cve-2026-93674-cwe-94-improper-control-of-generation-of-code-code-injection-in-ibm-langflow-oss-05d9c1873ab3c004 #OffSeq #IBM #Vuln #AppSec
-
Rockstar Games: CRITICAL multi-vector breaches (2018 – 2026). No zero-days — abused MFA fatigue, OAuth token theft, P2P RCE, poor segmentation. GTA VI dev build stolen. Improve DLP, segmentation, token security. https://radar.offseq.com/threat/rockstar-games-has-now-been-compromised-several-different-ways-since-2018-and-none-of-them-were-a-zero-0558b3cb1b7c3715 #OffSeq #RockstarGames #ThreatIntel
-
CVE-2026-82531: CRITICAL code injection bug in smarty-php Smarty (<4.5.8, 5.0.0<5.8.5). Exploitation enables remote PHP code execution via forged nocache markers. Patch to 4.5.8/5.8.5 ASAP. https://radar.offseq.com/threat/cve-2026-82531-improper-control-of-generation-of-code-code-injection-in-smarty-php-smarty-eb57bcca29bb7350 #OffSeq #CVE #infosec #php
-
Unauthenticated SQL Injection (CVE-2026-41555, CRITICAL, CVSS 9.3) in Weblizar Newsletter Subscription Form <=1.5.9 impacts WordPress sites. Patch status unknown — restrict/disable the component. https://radar.offseq.com/threat/cve-2026-41555-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-07f0f81651ae4a40 #OffSeq #WordPress #Infosec #SQLInjection
-
CRITICAL SQL injection (CVE-2026-42415) in p-themes Porto Theme - Functionality ≤3.9.3. Unauthenticated attackers can steal sensitive data. No official patch yet — restrict access ASAP. https://radar.offseq.com/threat/cve-2026-42415-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-3eb4b18a06bf1443 #OffSeq #CVE202642415 #Infosec #WordPress #SQLInjection
-
CVE-2026-42417 (CRITICAL): ARMember Premium <= 7.8 is vulnerable to unauthenticated SQL Injection (CWE-89). No mitigation yet — review deployments & monitor databases closely. https://radar.offseq.com/threat/cve-2026-42417-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-559a21ef978d1d38 #OffSeq #Vulnerability #SQLInjection #WordPress
-
CVE-2026-105778: CRITICAL stack-based buffer overflow in Tenda AC5 (v02.03.01.111_multi). Remote attackers can execute code via the /goform/setWifi endpoint. No patch yet — restrict remote access & monitor for exploits. https://radar.offseq.com/threat/cve-2026-105778-stack-based-buffer-overflow-in-tenda-ac5-d56799a413fc396a #OffSeq #CVE #Infosec #IoT
-
CVE-2026-75962: HIGH severity stored XSS in Post SMTP WordPress plugin (<=4.0.1). Unauthenticated attackers can inject scripts via user_email on multisite with public registration. Patch or restrict registration. https://radar.offseq.com/threat/cve-2026-75962-cwe-79-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-4d025f1757070abe #OffSeq #WordPress #XSS #Infosec
-
CVE-2026-91107: CRITICAL auth bypass in openSIS-Classic 9.3 🛑. Teacher-role users can reset passwords of any staff via the staff_id parameter. No patch yet — restrict permissions & monitor password changes. https://radar.offseq.com/threat/cve-2026-91107-cwe-639-authorization-bypass-through-user-controlled-key-in-os4ed-opensis-classic-f7eb55a7a5a0f52d #OffSeq #Vulnerability #openSIS #CVE202691107
-
TOTOLINK X6000R (9.4.0cu.652_B20230116) hit by CRITICAL OS command injection (CVE-2026-105484). Remote, unauthenticated attackers can gain full control. Restrict interface access & monitor /cgi-bin/cstecgi.cgi. Details: https://radar.offseq.com/threat/cve-2026-105484-os-command-injection-in-totolink-x6000r-ffaed0dcf0c90a02 #OffSeq #CVE #IoTSecurity
-
CVE-2026-21589 (CRITICAL, CVSS 9.3) in Atlassian Bamboo Data Center <10.2.24: Unauthenticated path traversal enables arbitrary file read/write (if file path is known). Patch to 10.2.24+ required — no workarounds. Details: https://radar.offseq.com/threat/cve-2026-21589-path-traversal-arbitrary-readwrite-in-atlassian-bamboo-data-center-24a2d0e4e6de8f44 #OffSeq #Atlassian #Infosec
-
CVE-2026-105763 (CRITICAL): twentyhq twenty CRM v1.20.10 – 2.7.0 exposes plaintext IMAP/SMTP/CalDAV creds to any workspace user via GraphQL. Upgrade to 2.7.0 to prevent mail/calendar compromise. https://radar.offseq.com/threat/cve-2026-105763-cwe-522-insufficiently-protected-credentials-in-twentyhq-twenty-8c5491429285ac63 #OffSeq #Vuln #CRM #twentyhq
-
CVE-2026-105207: CRITICAL vuln in ZITADEL 3.0.0 – 3.4.15 & 4.0.0<4.17.3 allows unauthenticated attackers to link their own IdP identity to any account — full takeover possible. Patch status unknown. Details: https://radar.offseq.com/threat/zitadel-300-through-3415-and-400-before-4173-creates-links-between-user-accounts-and-external-identity-cb61bb81cf2dabad #OffSeq #ZITADEL #Vuln #AccountSecurity
-
CRITICAL: gist RubyGem versions 4.0.0 – <6.1.0 vulnerable to improper cert validation (CVE-2026-105221). SSL verification is disabled, exposing GitHub creds to on-path attackers. Patch to 6.1.0+ now! https://radar.offseq.com/threat/cve-2026-105221-improper-certificate-validation-in-defunkt-gist-a4b1b7125f9195f8 #OffSeq #CVE2026105221 #RubyGems #infosec
-
CVE-2026-105223 (CRITICAL, CVSS 9.1): maclof kubernetes-client v0.17.0 – 0.31.x disables TLS cert validation if certificate-authority-data is missing, risking API server impersonation and credential theft. Check configs & vendor advisories. https://radar.offseq.com/threat/cve-2026-105223-improper-certificate-validation-in-maclof-kubernetes-client-8fb4f3aba9271610 #OffSeq #kubernetes #security
-
CVE-2026-105222: CRITICAL vuln in alexpechkarev/google-maps (v1.0.3 – 12.16). TLS cert checks off by default — API keys can leak, responses tampered. Set ssl_verify_peer=TRUE. Patch status unknown. https://radar.offseq.com/threat/cve-2026-105222-improper-certificate-validation-in-alexpechkarev-google-maps-f327aeed77a71a14 #OffSeq #Vulnerability #Laravel #CVE2026_105222
-
Offseason Outlook: San Francisco Giants https://www.rawchili.com/mlb/822630/ #Baseball #Giants #MLB #SanFrancisco #SanFranciscoGiants #SanFrancisco #SanFranciscoGiants #SF #SFGiants #SFGiants
-
Offset Caught On Camera in Heated Conflict With Casino Officials Over Alleged Blackjack Blunder: ‘I Will F**kin’ Leave’ #Vice https://twp.ai/E5H7XY
-
One Offseason Mistake the Giants Cannot Afford to Repeat https://www.rawchili.com/mlb/822753/ #Baseball #Giants #MLB #SanFrancisco #SanFranciscoGiants #SanFrancisco #SanFranciscoGiants #SF #SFGiants #SFGiants
-
Bruins’ big JJ Peterka offseason risk is already starting to pay off https://www.rawchili.com/nhl/680474/ #Boston #BostonBruins #BostonBruins #Bruins #Hockey #NHL
-
Ranking Miami Marlins’ Biggest Offseason Priorities https://www.rawchili.com/mlb/823107/ #Baseball #Marlins #Miami #MiamiMarlins #MiamiMarlins #MLB
-
Detroit Tigers Offseason Content Hub: Free Agents, Needs, Targets, Trades & Decisions https://www.rawchili.com/mlb/822907/ #Baseball #Minnesota #MinnesotaTwins #MinnesotaTwins #MLB #Twins
-
Inside the Knicks' offseason, the 'longest, shortest summer ever' https://www.nytimes.com/athletic/7648988/2026/10/06/knicks-summer-celebration-nba-title/ Winning an NBA title, especially in New York, comes with a lot of attention, a lot of responsibilities and a lot of perks. #Sports #News