home.social

#offseq — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #offseq, aggregated by home.social.

fetched live
  1. CRITICAL: CVE-2026-77776 in Headroom Labs Headroom (<0.36.1) allows unauth'd attackers to spoof x-headroom-user-id and access/modify any user's LLM memory. Default configs expose this via 0.0.0.0 binding. Restrict access & use auth tokens. radar.offseq.com/threat/cve-20 #OffSeq #CVE #infosec #LLM

  2. CVE-2026-77651 | CRITICAL in Rust 'arrayref' 0.3.10 🛑 Malicious dependency enables remote code execution during build. Full build environment compromise possible. Avoid 0.3.10, audit dependencies. Details: radar.offseq.com/threat/cve-20 #OffSeq #RustLang #CVE2026 #Infosec

  3. CareCloud breach (CRITICAL): 3.7M+ individuals' PII & health records compromised after AWS environment intrusion. No CVE. Sensitive info, including SSN & medical data, stolen. Monitor for fraud. Details: radar.offseq.com/threat/carecl #OffSeq #databreach #healthcare #infosec

  4. CVE-2026-75094: CRITICAL OS command injection in COMFAST CF-N1-S v2.6.0.1. Exploit code is public, no official patch. Restrict access to /cgi-bin/mbox-config to reduce risk. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Security

  5. CVE-2026-13610 | CRITICAL privilege flaw in KiviCare <4.5.2 lets unauthenticated attackers create privileged staff accounts, risking patient data exposure 🏥. Restrict registration endpoint & monitor user creation. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #Healthcare

  6. LiteLLM supply chain attack (no CVE) hit 2,500+ orgs & 434K+ pipelines. Malicious code in 1.82.7 & 1.82.8 stole secrets (keys, tokens). Severity: CRITICAL. Rotate all credentials, review logs. Details: radar.offseq.com/threat/over-2 #OffSeq #SupplyChain #Python #Infosec

  7. CRITICAL CVE-2026-70398 in Red Hat Advanced Cluster Management for Kubernetes 2: Authenticated tenants can redirect bearer tokens via GitOpsCluster controller. No official fix. Restrict privileges & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Kubernetes #RedHat #CVE202670398

  8. CVE-2026-18948: CRITICAL in RHOAI Feast — unsafe UDF deserialization allows unauth RCE on feature-server. Auth attackers can bypass auth to run code on registry-server. Mitigate by enforcing `auth.type: kubernetes`. radar.offseq.com/threat/cve-20 #OffSeq #RedHat #CVE #infosec

  9. CVE-2026-15534: HIGH severity in LEONT perl (≤5.45.1) — Integer overflow in regex engine can cause heap corruption or crashes when large inputs and crafted patterns are processed. Avoid risky patterns until patched. radar.offseq.com/threat/cve-20 #OffSeq #Perl #Vuln #AppSec

  10. CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA & strong passwords. No CVE assigned. radar.offseq.com/threat/canadi #OffSeq #CloudSecurity #ThreatIntel

  11. CVE-2026-18685: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated RCE possible. No patch yet — restrict access & monitor for abuse. Details: radar.offseq.com/threat/cve-20 #OffSeq #vuln #IoT #infosec

  12. CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. radar.offseq.com/threat/cve-20 #OffSeq #infosec #Python #CVE202663720

  13. CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. radar.offseq.com/threat/cve-20 #OffSeq #infosec #perl #vuln

  14. CVE-2026-61884 (CRITICAL, CVSS 9.8) in Tycon TPDIN-Monitor-WEB2 v2.3.9: Server-side auth validation missing — empty creds grant admin access. Restrict management interface, monitor for unauthorized logins. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoT #Infosec

  15. CVE-2026-56191: CRITICAL improper authentication in Microsoft Exchange Online (CVSS 10). Remote, unauthenticated attackers can tamper with systems. Official fix available — patch ASAP. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE202656191 #ExchangeOnline #Vuln

  16. CVE-2026-13577 | HIGH severity in CROMEDOME Dancer2 ≤2.1.0: Predictable session IDs if CSPRNG modules are missing. Install Math::Random::ISAAC::XS/Crypt::URandom to mitigate. Full info: radar.offseq.com/threat/cve-20 #OffSeq #CVE202613577 #infosec #Perl

  17. CVE-2026-63831: Linux kernel mac802154 llsec vuln (HIGH) could cause data corruption & kernel crashes via unsafe crypto ops on shared skb buffers. Update to patched kernel for stability. More: radar.offseq.com/threat/in-the #OffSeq #Linux #CVE202663831 #Infosec

  18. CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE #IoTSecurity

  19. CVE-2026-16096: HIGH severity stack buffer overflow in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124 (/proc/webmon_recent_domains). Remote exploit possible, no official patch. Migrate to FreshTomato. radar.offseq.com/threat/a-vuln #OffSeq #Vulnerability #RouterSecurity #CVE #IoT

  20. scikit-hep uproot has a HIGH-severity code injection flaw (CVE-2026-9147, CVSS 8.5). Malicious ROOT files can trigger arbitrary Python code execution. Avoid untrusted files until fixed. Full details: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Python #ThreatIntel

  21. Firefox 152.0.6 and Chrome 150.0.7871.124/.125 resolve CRITICAL flaws. Firefox bugs (CVE-2026-15718, CVE-2026-15719) have public exploits, but no in-the-wild attacks. Patch ASAP. Chrome fixes 15 issues. radar.offseq.com/threat/critic #OffSeq #Vuln #PatchNow #BrowserSecurity

  22. CRITICAL threat: Russian FSB-linked cyber espionage & sabotage campaign hits gov & infrastructure across Europe since 2010. No CVE, but big impact on power, heating, transport. Follow national guidance; boost vigilance. radar.offseq.com/threat/eu-tar #OffSeq #CyberEspionage #FSB #EU

  23. CVE-2026-14380 | CRITICAL eval injection in HMBRAND DBI <1.650 lets attackers execute arbitrary Perl code via Profile. Remote code exec possible with exposed DBI::Gofer/ProxyServer. Restrict access & monitor for patches. radar.offseq.com/threat/cve-20 #OffSeq #Perl #Security

  24. CVE-2026-14803: HIGH severity vuln in Mojo::JSON <9.47 — pure-Perl decoder allows uncontrolled recursion. Apps may face DoS if Cpanel::JSON::XS isn’t enabled. Install XS module or limit JSON depth. radar.offseq.com/threat/cve-20 #OffSeq #infosec #Perl #DoS

  25. CVE-2026-14570: HIGH severity in TIMLEGGE Crypt::DSA (<1.22) — insufficiently random values in DSA signing allow attackers to recover private keys using lattice attacks. Replace all affected keys and upgrade to 1.22+. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #Perl #Crypto

  26. Malicious code in tailwind-animates (npm) ⚠️ Severity: CRITICAL. Systems with this package installed are fully compromised — rotate all secrets & consider full rebuild. Removal alone is not enough. No CVE. radar.offseq.com/threat/mal-20 #OffSeq #npm #Malware #SupplyChain

  27. CVE-2026-12243: NLTK 3.9.4 suffers from a HIGH severity path traversal bug — percent-encoded sequences like ..%2f bypass directory checks, allowing arbitrary file reads in NLP apps/Jupyter/CLI. Audit usages & restrict resource loading. radar.offseq.com/threat/cve-20 #OffSeq #NLTK #Python

  28. CVE-2026-13601 (HIGH, CVSS 7.1) in Red Hat Enterprise Linux 10: Yelp’s help viewer can leak sensitive files via crafted Flatpak apps due to weak Content Security Policy. No patch yet — restrict untrusted Flatpaks. radar.offseq.com/threat/cve-20 #OffSeq #Linux #Vuln #RedHat

  29. CVE-2026-13491: MEDIUM severity DoS flaw in 78 xiaozhi-esp32 (v2.2.0 – 2.2.6) via MQTT Goodbye Handler. Exploitable remotely with public exploit. Patch via commit e182471f8c5a. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoT #DoS

  30. MEDIUM severity: 50 Chrome extensions use a shared backend & hardcoded API key, risking user privacy via centralized control. WhatsApp Web CSP is replaced, persistent comms enabled. No active exploitation yet. Details: radar.offseq.com/threat/50-chr #OffSeq #Chrome #Security #Privacy