A vulnerability in iCagenda allows unrestricted upload of malicious files, actively exploited, risking server compromise. Details and next steps included.
Browsing Category
Cybersecurity Trends
197 posts
TLS certificates for internal services done right
A comprehensive guide on implementing correct TLS certificate management for internal services to enhance security and reliability.
TLS Certificates For Internal Services Done Right
An overview of how organizations are implementing TLS certificates correctly for internal services, enhancing security and trust.
Remote Attestation
New developments in remote attestation technology enhance cloud security, with industry leaders integrating it into their platforms. Details are still emerging.
GitLost: We Tricked GitHub’s AI Agent Into Leaking Private Repos
Researchers demonstrated how an AI agent on GitHub was manipulated to reveal private repositories, raising security concerns about AI-assisted development tools.
Tenda Firmware (Multiple Versions) Contains Hidden Authentication Backdoor
Multiple versions of Tenda router firmware have been found to include a hidden authentication backdoor, raising security concerns for users worldwide.
CVE-2026-48908: JoomShaper SP Page Builder Unrestricted Upload Of File With Dangerous Type Vulnerability Actively Exploited (CISA KEV)
A vulnerability in JoomShaper SP Page Builder allows unauthenticated users to upload arbitrary files, now actively exploited according to CISA KEV alerts.
CVE-2026-55255: Langflow Authorization Bypass Through User-Controlled Key Vulnerability Actively Exploited (CISA KEV)
A vulnerability in Langflow enables authenticated attackers to bypass authorization and access other users’ flows by controlling a key.
Januscape: Guest-to-Host Escape In KVM/x86 [CVE-2026-53359]
Security researchers reveal Januscape, a vulnerability allowing guest-to-host escape in KVM on x86 systems, assigned CVE-2026-53359, with potential for significant impact.
OpenSSH 10.4/10.4P1 Released
OpenSSH versions 10.4 and 10.4p1 have been officially released, including security patches and new features, enhancing SSH security and performance.