Overview
- defnull
- multipart
Description
Statistics
- 1 Post
- 36 Interactions
Fediverse
The 'multipart' #python library got an independent #security audit and I only know about that because they found something -> CVE-2026-28356
This is great, actually! Someone looked into it so thoroughly that they found an obscure single-character issue in a regular expression ... and didn't find anything else! Which means I can now be really confident about the security of this library. Nice!
Description
Statistics
- 5 Posts
- 8 Interactions
Fediverse
@browserversiontracker For the curious, this includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
And yes, we somehow beat the Chrome team getting this out even though they did the fix. 😂
@vivaldiversiontracker This includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
Overview
- Microsoft
- Microsoft Authenticator for Android
Description
Statistics
- 1 Post
- 10 Interactions
Fediverse
Microsoft Authenticator potrebbe divulgare i codici di accesso: se lo stai usando, aggiorna subito l'app
Una vulnerabilità in Microsoft Authenticator per iOS e Android ( CVE-2026-26123 ) potrebbe far trapelare i codici di accesso monouso o i deep link di autenticazione a un'app dannosa sullo stesso dispositivo.
Overview
Description
Statistics
- 2 Posts
- 4 Interactions
Fediverse
Your package manager's D-Bus interface is root-privileged, always-on, and crashes instantly if you whisper the wrong locale at it.
CVE-2026-3836.
CVSS 7.5.
No auth required.
The tool patching your system was the hole. Upgrade dnf5 now.
https://portallinuxferramentas.blogspot.com/2026/03/critical-fedora-42-update-analyzing-cve.html?m=1
Overview
- Microsoft
- Microsoft Devices Pricing Program
Description
Statistics
- 1 Post
- 3 Interactions
Bluesky
Overview
- dagu-org
- dagu
Description
Statistics
- 1 Post
- 2 Interactions
Fediverse
⚠️ CRITICAL vuln: dagu <2.2.4 suffers from path traversal (CVE-2026-31886). Exploit allows deletion of /tmp, causing system-wide DoS. Upgrade to 2.2.4+ or enforce input validation now! https://radar.offseq.com/threat/cve-2026-31886-cwe-22-improper-limitation-of-a-pat-116cb11a #OffSeq #dagu #security #CVE2026_31886
Overview
- ctfer-io
- monitoring
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
CVE-2026-32720 (HIGH): ctfer-io monitoring <0.2.1 has improper access control, allowing lateral movement across Kubernetes namespaces — risks sensitive logs/metrics. Patch to 0.2.1+ ASAP! 🔒 https://radar.offseq.com/threat/cve-2026-32720-cwe-284-improper-access-control-in--c14eb5d2 #OffSeq #Kubernetes #CVE #CloudSecurity
Overview
- nyariv
- SandboxJS
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
🔥 CRITICAL: CVE-2026-26954 in SandboxJS (< 0.8.34) enables sandbox escape via Function & Object.fromEntries. Attackers can run arbitrary code remotely! Upgrade to v0.8.34+ now. Full details: https://radar.offseq.com/threat/cve-2026-26954-cwe-94-improper-control-of-generati-35790079 #OffSeq #CVE202626954 #infosec #sandbox
Description
Statistics
- 3 Posts
- 3 Interactions
Fediverse
@browserversiontracker For the curious, this includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
And yes, we somehow beat the Chrome team getting this out even though they did the fix. 😂
@vivaldiversiontracker This includes security fixes for CVE-2026-3909 & CVE-2026-3910 from Chromium 146.0.7680.80.
Overview
- GNU
- inetutils
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
⚠️ CRITICAL: CVE-2026-32746 in GNU inetutils telnetd (<=2.7) enables remote buffer overflow — unauthenticated code execution or DoS possible. Disable telnet, restrict access, monitor for threats. No patch yet! https://radar.offseq.com/threat/cve-2026-32746-cwe-120-buffer-copy-without-checkin-0ceead78 #OffSeq #CVE202632746 #infosec