Section
Security
Exploitation, supply chain, and the incident response nobody publishes.
19 stories · 0 editors
Topics
Sort: Newest ▾
News
4 min
Citrix published fixes for eight NetScaler ADC and Gateway flaws on September 27 and said two were already being exploited. CISA gave federal agencies until September 30.
News
4 min
WordPress shipped 7.1.2 and backports to every branch since 4.7 on September 22 for an unauthenticated file inclusion in page-template resolution. CISA listed it as exploited on September 25.
10 Sep · Prelo · 4 min
LiteLLM's MCP auth bypass joins CISA's KEV catalog with a two-week remediation deadline.
08 Sep · Prelo · 6 min
Anthropic's August 31 post lays out post-incident sandboxing rules and an RL cleanup that flagged over 10% of environments.
03 Sep · Prelo · 3 min
CISA adds two exploited TrueConf Server flaws used to trojan client installers.
02 Sep · Prelo · 6 min
The Hugging Face incident, read as an infrastructure breach rather than an AI parable.
27 Aug · Prelo · 5 min
A global resolver fallback let Spring AI dispatch tools that were never offered to the request.
26 Aug · Prelo · 4 min
Splunk patches 17 CVEs; the MCP Server app's credential store deserialized untyped data.
19 Aug · Prelo · 6 min
Metabase's unauthenticated password-reset SQLi is in CISA's KEV with a due date that has already passed — and patching once was not enough.
12 Aug · Prelo · 4 min
Tomcat's cluster encryption interceptor logged decryption failures and delivered the message anyway. Now in CISA's KEV catalog.
08 Aug · Prelo · 4 min
OpenAI's Astra trips the Critical cyber threshold — what the designation means, what actually pauses, and what doesn't.
04 Aug · Prelo · 3 min
Actively exploited N-central auth bypass (CVE-2026-18577); patch to 2026.3.1.7 and check for tunnels.
04 Aug · Prelo · 5 min
Three eval runs, three real companies breached, and one uncomfortable lesson about where a capture-the-flag exercise ends.