#offseq — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #offseq, aggregated by home.social.
-
CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. https://radar.offseq.com/threat/cve-2026-77776-authorization-bypass-through-user-controlled-key-in-headroom-labs-headroom-0c2eff15c1a3dc1f #OffSeq #CVE #infosec #LLM
-
CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: https://radar.offseq.com/threat/cve-2026-77651-cwe-506-embedded-malicious-code-in-droundy-arrayref-c761153d40c2552d #OffSeq #RustLang #CVE2026 #Infosec
-
CareCloud breach (CRITICAL): 3.7M+ individuals' PII & health records compromised after AWS environment intrusion. No CVE. Sensitive info, including SSN & medical data, stolen. Monitor for fraud. Details: https://radar.offseq.com/threat/carecloud-data-breach-impact-grows-to-37-million-individuals-3b1801475e9fe5de #OffSeq #databreach #healthcare #infosec
-
CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: https://radar.offseq.com/threat/cve-2026-75094-os-command-injection-in-comfast-cf-n1-s-07737fa4c8cac0ee #OffSeq #CVE #IoT #Security
-
CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. https://radar.offseq.com/threat/cve-2026-13610-cwe-269-improper-privilege-management-in-kivicare-c9bee31557a60fdb #OffSeq #WordPress #Infosec #Healthcare
-
LiteLLM supply chain attack (no CVE) hit 2,500+ orgs & 434K+ pipelines. Malicious code in 1.82.7 & 1.82.8 stole secrets (keys, tokens). Severity: CRITICAL. Rotate all credentials, review logs. Details: https://radar.offseq.com/threat/over-2500-organizations-impacted-by-litellm-supply-chain-attack-94d62ad89571c8ed #OffSeq #SupplyChain #Python #Infosec
-
CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. https://radar.offseq.com/threat/cve-2026-70398-unintended-proxy-or-intermediary-confused-deputy-in-red-hat-red-hat-advanced-cluster-3d1f26674efa89dc #OffSeq #Kubernetes #RedHat #CVE202670398
-
CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. https://radar.offseq.com/threat/cve-2026-18948-vulnerability-in-red-hat-red-hat-openshift-ai-rhoai-ae1bc718efe1cce9 #OffSeq #RedHat #CVE #infosec
-
CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. https://radar.offseq.com/threat/cve-2026-15534-cwe-190-integer-overflow-or-wraparound-in-leont-perl-b58a44fbf0b93abe #OffSeq #Perl #Vuln #AppSec
-
CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA & strong passwords. No CVE assigned. https://radar.offseq.com/threat/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks-21f9fb8717cf2802 #OffSeq #CloudSecurity #ThreatIntel
-
CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: https://radar.offseq.com/threat/cve-2026-18685-command-injection-in-glinet-gl-mt3000-32060ee21fb81c76 #OffSeq #vuln #IoT #infosec
-
CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. https://radar.offseq.com/threat/cve-2026-63720-improper-control-of-generation-of-code-code-injection-in-koxudaxi-datamodel-code-a0a27f1d30c87e2e #OffSeq #infosec #Python #CVE202663720
-
CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. https://radar.offseq.com/threat/cve-2026-16766-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-9e7c09567b0712f8 #OffSeq #infosec #perl #vuln
-
CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. https://radar.offseq.com/threat/cve-2026-61884-cwe-288-in-tycon-systems-tpdin-monitor-web2-38fd252c1e4f018a #OffSeq #CVE #IoT #Infosec
-
CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: https://radar.offseq.com/threat/cve-2026-56191-cwe-287-improper-authentication-in-microsoft-microsoft-exchange-online-2fb5560625ca8222 #OffSeq #CVE202656191 #ExchangeOnline #Vuln
-
CVE-2026-13577 | HIGH severity in CROMEDOME Dancer2 ≤2.1.0: Predictable session IDs if CSPRNG modules are missing. Install Math::Random::ISAAC::XS/Crypt::URandom to mitigate. Full info: https://radar.offseq.com/threat/cve-2026-13577-cwe-340-generation-of-predictable-numbers-or-identifiers-in-cromedome-dancer2-858dec6ffe258cee #OffSeq #CVE202613577 #infosec #Perl
-
CVE-2026-63831: Linux kernel mac802154 llsec vuln (HIGH) could cause data corruption & kernel crashes via unsafe crypto ops on shared skb buffers. Update to patched kernel for stability. More: https://radar.offseq.com/threat/in-the-linux-kernel-the-following-vulnerability-has-been-resolved-mac802154-llsec-add-skbcowdata-9cf2707b26af2cc3 #OffSeq #Linux #CVE202663831 #Infosec
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-16096: HIGH severity stack buffer overflow in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 (/proc/webmon_recent_domains). Remote exploit possible, no official patch. Migrate to FreshTomato. https://radar.offseq.com/threat/a-vulnerability-has-been-found-in-shibby-tomato-128-rt-n5x-mipsr2-build-124-cve-2026-16096-68e7082f09658d0a #OffSeq #Vulnerability #RouterSecurity #CVE #IoT
-
scikit-hep uproot has a HIGH-severity code injection flaw (CVE-2026-9147, CVSS 8.5). Malicious ROOT files can trigger arbitrary Python code execution. Avoid untrusted files until fixed. Full details: https://radar.offseq.com/threat/cve-2026-9147-improper-control-of-generation-of-code-code-injection-in-scikit-hep-uproot-a352d097ded08c6a #OffSeq #Vulnerability #Python #ThreatIntel
-
Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. https://radar.offseq.com/threat/critical-vulnerabilities-patched-with-fresh-chrome-e977806d68193e89 #OffSeq #Vuln #PatchNow #BrowserSecurity
-
CRITICAL threat: Russian FSB-linked cyber espionage & sabotage campaign hits gov & infrastructure across Europe since 2010. No CVE, but big impact on power, heating, transport. Follow national guidance; boost vigilance. https://radar.offseq.com/threat/eu-targets-russian-intelligence-officers-accused-o-fc2dc036f7820f41 #OffSeq #CyberEspionage #FSB #EU
-
CVE-2026-14380 | CRITICAL eval injection in HMBRAND DBI <1.650 lets attackers execute arbitrary Perl code via Profile. Remote code exec possible with exposed DBI::Gofer/ProxyServer. Restrict access & monitor for patches. https://radar.offseq.com/threat/cve-2026-14380-cwe-95-improper-neutralization-of-d-632b564b1d788778 #OffSeq #Perl #Security
-
CVE-2026-14803: HIGH severity vuln in Mojo::JSON <9.47 — pure-Perl decoder allows uncontrolled recursion. Apps may face DoS if Cpanel::JSON::XS isn’t enabled. Install XS module or limit JSON depth. https://radar.offseq.com/threat/cve-2026-14803-cwe-674-uncontrolled-recursion-in-s-622d5e94b9c3bd9b #OffSeq #infosec #Perl #DoS
-
CVE-2026-14570: HIGH severity in TIMLEGGE Crypt::DSA (<1.22) — insufficiently random values in DSA signing allow attackers to recover private keys using lattice attacks. Replace all affected keys and upgrade to 1.22+. https://radar.offseq.com/threat/cve-2026-14570-cwe-330-use-of-insufficiently-rando-539cd2ae349f5a7a #OffSeq #Vuln #Perl #Crypto
-
Malicious code in tailwind-animates (npm) ⚠️ Severity: CRITICAL. Systems with this package installed are fully compromised — rotate all secrets & consider full rebuild. Removal alone is not enough. No CVE. https://radar.offseq.com/threat/mal-2026-6727-malicious-code-in-tailwind-animates--429472d232b35d7b #OffSeq #npm #Malware #SupplyChain
-
CVE-2026-12243: NLTK 3.9.4 suffers from a HIGH severity path traversal bug — percent-encoded sequences like ..%2f bypass directory checks, allowing arbitrary file reads in NLP apps/Jupyter/CLI. Audit usages & restrict resource loading. https://radar.offseq.com/threat/cve-2026-12243-cwe-22-improper-limitation-of-a-pat-3eae11979fc43a41 #OffSeq #NLTK #Python
-
CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. https://radar.offseq.com/threat/cve-2026-13601-protection-mechanism-failure-in-red-844c9044ecdb0d62 #OffSeq #Linux #Vuln #RedHat
-
CVE-2026-13491: MEDIUM severity DoS flaw in 78 xiaozhi-esp32 (v2.2.0 – 2.2.6) via MQTT Goodbye Handler. Exploitable remotely with public exploit. Patch via commit e182471f8c5a. https://radar.offseq.com/threat/cve-2026-13491-denial-of-service-in-78-xiaozhi-esp-7a05af4bbbaaa50e #OffSeq #Vuln #IoT #DoS
-
MEDIUM severity: 50 Chrome extensions use a shared backend & hardcoded API key, risking user privacy via centralized control. WhatsApp Web CSP is replaced, persistent comms enabled. No active exploitation yet. Details: https://radar.offseq.com/threat/50-chrome-extensions-one-codebase-one-backend-one--096a1f09392f1ba3 #OffSeq #Chrome #Security #Privacy