All topics

vulnerability

103 pieces of writing

ics8 min read

CVE-2025-10492: a Java deserialisation flaw in JasperReports gives attackers remote code execution on Hitachi Energy Ellipse

CVE-2025-10492, a CVSS 9.8 Java deserialisation flaw in the JasperReports component of Hitachi Energy Ellipse, enables unauthenticated RCE on critical manufacturing systems. No patch exists for the community edition of the underlying library.

Edict's file:// handler let anyone read files outside the project directory (CWE-22)
vulnerability5 min read

Edict's file:// handler let anyone read files outside the project directory (CWE-22)

AIPex's localhost daemon let any website control your browser through a WebSocket
vulnerability5 min read

AIPex's localhost daemon let any website control your browser through a WebSocket

siemens6 min read

Two CVEs in Siemens SICAM 8 firmware expose three product families to unauthenticated denial of service

CVE-2026-27663 and CVE-2026-27664 affect shared firmware components across Siemens SICAM A8000, EGS and S8000 product lines, enabling unauthenticated denial of service in power grid infrastructure.

security10 min read

LangFlow, n8n and the pattern where AI configuration becomes code execution

ics6 min read

Anritsu's spectrum monitors have no authentication and the vendor has no plans to add it

Every MCPHub instance started with the same admin password. I changed that.
vulnerability7 min read

Every MCPHub instance started with the same admin password. I changed that.

MCPHub shipped every installation with the hardcoded credential admin/admin123 and published it in the README. The fix generates a cryptographically random password per instance.

LightRAG's Memgraph backend had a Cypher injection vulnerability hiding in plain sight
vulnerability7 min read

LightRAG's Memgraph backend had a Cypher injection vulnerability hiding in plain sight

security12 min read

Environment variables are the new command line: how AI agents keep leaking secrets through configuration files

A single index change bypassed daily_stock_analysis's entire rate limiter
vulnerability7 min read

A single index change bypassed daily_stock_analysis's entire rate limiter

A self-hosted stock analysis platform trusted the leftmost X-Forwarded-For entry for rate limiting, letting attackers rotate IPs and brute-force the admin login at will.

PraisonAI let YAML config files set LD_PRELOAD and nobody checked
vulnerability7 min read

PraisonAI let YAML config files set LD_PRELOAD and nobody checked

Git tags, package registries and extension marketplaces share the same broken authentication model
security12 min read

Git tags, package registries and extension marketplaces share the same broken authentication model

gptme was passing API keys on the command line where any user could read them
vulnerability8 min read

gptme was passing API keys on the command line where any user could read them

gptme's evaluation runner passed API keys as Docker CLI arguments, exposing them to every user on the system via ps or /proc. The fix took one file and five tests.

Hermes Agent's worktree feature copied arbitrary files from your filesystem
security7 min read

Hermes Agent's worktree feature copied arbitrary files from your filesystem

Summarize's localhost daemon accepted requests from any website
security7 min read

Summarize's localhost daemon accepted requests from any website

Weekly digests

Weekly threat intelligence digest — 2026-W25

Digest

Weekly threat intelligence digest — 2026-W23

Digest

Weekly threat intelligence digest — 2026-W22

Digest

Weekly threat intelligence digest — 2026-W21

Digest

Weekly threat intelligence digest — 2026-W20

Digest

Weekly threat intelligence digest — 2026-W19

Digest

Weekly threat intelligence digest — 2026-W17

Digest

Weekly threat intelligence digest — 2026-W16

Digest

Weekly threat intelligence digest — 2026-W15

Digest

Weekly threat intelligence digest — 2026-W14

Digest

Weekly threat intelligence digest — 2026-W13

Digest

Weekly threat intelligence digest — 2026-W12

Digest

Weekly threat intelligence digest — 2026-W11

Digest

Weekly threat intelligence digest — 2026-W10

Digest

Weekly threat intelligence digest — 2026-W09

Digest

Weekly threat intelligence digest — 2026-W08

Digest

Weekly threat intelligence digest — 2026-W07

Digest

Weekly threat intelligence digest — 2026-W06

Digest

Weekly threat intelligence digest — 2026-W05

Digest

Weekly threat intelligence digest — 2026-W04

Digest

Weekly threat intelligence digest — 2026-W03

Digest

Weekly threat intelligence digest — 2026-W02

Digest

Weekly threat intelligence digest — 2025-W52

Digest

Weekly threat intelligence digest — 2025-W51

Digest

Weekly threat intelligence digest — 2025-W50

Digest

Weekly threat intelligence digest — 2025-W49

Digest

Weekly threat intelligence digest — 2025-W48

Digest

Weekly threat intelligence digest — 2025-W47

Digest

Weekly threat intelligence digest — 2025-W46

Digest

Weekly threat intelligence digest — 2025-W45

Digest

Weekly threat intelligence digest — 2025-W44

Digest

Weekly threat intelligence digest — 2025-W43

Digest

Weekly threat intelligence digest — 2025-W42

Digest

Weekly threat intelligence digest — 2025-W41

Digest

Weekly threat intelligence digest — 2025-W40

Digest

Weekly threat intelligence digest — 2025-W39

Digest

Weekly threat intelligence digest — 2025-W38

Digest

Weekly threat intelligence digest — 2025-W37

Digest

Weekly threat intelligence digest — 2025-W36

Digest

Weekly threat intelligence digest — 2025-W35

Digest

Weekly threat intelligence digest — 2025-W34

Digest

Weekly threat intelligence digest — 2025-W33

Digest

Weekly threat intelligence digest — 2025-W32

Digest

Weekly threat intelligence digest — 2025-W31

Digest

Weekly threat intelligence digest — 2025-W30

Digest

Weekly threat intelligence digest — 2025-W29

Digest

Weekly threat intelligence digest — 2025-W28

Digest

Weekly threat intelligence digest — 2025-W27

Digest

Weekly threat intelligence digest — 2025-W26

Digest

Weekly threat intelligence digest — 2025-W25

Digest

Weekly threat intelligence digest — 2025-W24

Digest

Weekly threat intelligence digest — 2025-W23

Digest

Weekly threat intelligence digest — 2025-W21

Digest

Weekly threat intelligence digest — 2025-W20

Digest

Weekly threat intelligence digest — 2025-W19

Digest

Weekly threat intelligence digest — 2025-W17

Digest

Weekly threat intelligence digest — 2025-W16

Digest

Weekly threat intelligence digest — 2025-W15

Digest

Weekly threat intelligence digest — 2025-W13

Digest

Weekly threat intelligence digest — 2025-W12

Digest

Weekly threat intelligence digest — 2025-W11

Digest

Weekly threat intelligence digest — 2025-W10

Digest

Weekly threat intelligence digest — 2025-W07

Digest

Weekly threat intelligence digest — 2025-W06

Digest

Weekly threat intelligence digest — 2025-W05

Digest

Weekly threat intelligence digest — 2025-W03

Digest

Weekly threat intelligence digest — 2025-W02

Digest

Weekly threat intelligence digest — 2025-W01

Digest