Sign in

OffSequence

@offseq.bsky.social
86 followers 0 following 3.4K posts

OffSeq is a cutting-edge European cybersecurity company helping organizations build digital resilience through tailored, proactive security solutions. #CyberSecurity www.offseq.com radar.offseq.com breach.offseq.com

PostsRepliesMedia
OffSequence @offseq.bsky.social · 8h
CRITICAL: IBM DataPower Gateway 10.5.0.0 – 10.6.6 & 11.0.0.0 – 11.0.0.2 impacted by CVE-2026-16340. Remote code execution risk via out-of-bounds write. Assess & patch when available. radar.offseq.com/threat/cve-2026-16…...
radar.offseq.com
CVE-2026-16340: CWE-787 Out-of-bounds Write in IBM DataPower Gateway 10.6CD
IBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-word
000
OffSequence @offseq.bsky.social · 9h
Iskratel Innbox GPON ONT: CVE-2026-105110 (CRITICAL, 9.8 CVSS) enables unauthenticated remote OS command injection as root. Restrict access, monitor login.xgi, await patch. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-105110: CWE-78 Improper Neutralization of Special Elements used in an O
This vulnerability (CVE-2026-105110) affects Iskratel Innbox GPON ONT devices. The flaw exists in the login.xgi CGI endpoint where improper neutralization of special elements in the CLI parameter allows an unauthenticated remote attacker to
000
OffSequence @offseq.bsky.social · 11h
Infoblox NIOS 9.0.x – 9.1.0 hit by CRITICAL CVE-2026-107510. High-priv users can escalate via argument injection. Limit admin access & watch for patches. radar.offseq.com/threat/cve-2026-10… #OffSeq #Vulnerability
radar.offseq.com
CVE-2026-107510: Vulnerability in Infoblox NIOS
This vulnerability in Infoblox NIOS allows an authenticated user with high privileges to perform argument injection in troubleshooting commands. This injection can result in privilege escalation, enabling the attacker to gain higher privile
000
OffSequence @offseq.bsky.social · 12h
CRITICAL SQL injection (CVE-2026-12260) in NetBoard CRM Demo lets attackers extract or alter data via 'user-name' POST param. Restrict access or patch ASAP. radar.offseq.com/threat/cve-2026-12…...
radar.offseq.com
CVE-2026-12260: CWE-89 Improper neutralization of special elements used in an SQ
SQL injection in the NetBoard CRM demo platform; specifically, the vulnerable component is the ‘user-name’ POST parameter in the ‘/module/auth/recovery.php’ endpoint. The parameter is vulnerable to blind attacks based on Boolean, error, tim
000
OffSequence @offseq.bsky.social · 14h
Openfind SecuShare Pro v4 faces CRITICAL OS command injection (CVE-2026-107459, CVSS 9.3). No patch yet — secure access & monitor for exploitation. radar.offseq.com/threat/cve-2026-10… ...
radar.offseq.com
CVE-2026-107459: CWE-78 Improper Neutralization of Special Elements used in an O
CVE-2026-107459 describes an OS Command Injection vulnerability in Openfind SecuShare Pro version 4. The flaw allows unauthenticated remote attackers to execute arbitrary OS commands on the affected server, due to improper neutralization of
000
OffSequence @offseq.bsky.social · 15h
Super Forms – Drag & Drop Form Builder (<=6.3.316) hit by CRITICAL CVE-2026-17609: unauthenticated directory deletion risk if 'Delete files after form submissions' is on. Disable this setting ASAP. radar.offseq.com/threat/cve-2026-17…...
radar.offseq.com
CVE-2026-17609: CWE-434 Unrestricted Upload of File with Dangerous Type in WebRe
CVE-2026-17609 is a critical vulnerability in the Super Forms – Drag & Drop Form Builder WordPress plugin (versions <=6.3.316). The vulnerability is due to insufficient validation of attacker-controlled JSON field declarations against the f
000
OffSequence @offseq.bsky.social · 17h
CRITICAL: @backstage/plugin-scaffolder-backend pre-4.1.0 lets users access sensitive task data, risking credential leaks. Update to 4.1.0 and restrict task reads to owners. Details: radar.offseq.com/threat/plugin-scaf…...
radar.offseq.com
Plugin scaffolder backend: Backstage: Sensitive information exposure in Scaffold
An authenticated user in Backstage with permission to read Scaffolder tasks can access internal execution data from other users' tasks. If this data contains credentials for external services, it may lead to unauthorized disclosure and unau
000
OffSequence @offseq.bsky.social · 18h
CRITICAL: CVE-2026-76465 in Cisco Nexus 3000/9000 allows remote code execution or DoS by unauthenticated attackers via MPLS OAM. Patch status unconfirmed — monitor Cisco advisories for updates. radar.offseq.com/threat/a-vulnerabi…...
radar.offseq.com
A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) fea
This vulnerability (CVE-2026-76465) arises from improper validation of MPLS echo-request packets in the MPLS OAM feature of Cisco NX-OS Software on Nexus 3000 and 9000 Series Switches. An attacker can exploit this by sending a specially cra
001
OffSequence @offseq.bsky.social · 20h
Cisco NX-OS NGOAM CRITICAL vuln (CVE-2026-76485): Remote unauthenticated attackers can execute code or cause DoS. Disable NGOAM if not required. Patch status pending. Details: radar.offseq.com/threat/a-vulnerabi…...
radar.offseq.com
A vulnerability in the VXLAN Operation, Administration, and Maintenance (OAM) fe
CVE-2026-76485 describes a vulnerability in the NGOAM feature of Cisco NX-OS Software caused by improper input validation of IP traffic when NGOAM is enabled. An attacker can exploit this by sending specially crafted packets to an IP interf
001
OffSequence @offseq.bsky.social · 21h
The Events Calendar plugin (<=6.17.4) hit by CRITICAL deserialization flaw — remote object injection possible. Patch status unknown; check vendor now. radar.offseq.com/threat/deserializa…...
radar.offseq.com
Deserialization of Untrusted Data vulnerability in Liquid Web / StellarWP The Ev
CVE-2026-95606 is a deserialization of untrusted data vulnerability in The Events Calendar plugin by Liquid Web / StellarWP. This flaw allows an attacker to perform object injection, which can lead to remote code execution or other severe i
000
OffSequence @offseq.bsky.social · 07/10/2026
Movable Type Cloud Edition (2.0 – 9.2.1) faces a CRITICAL code injection flaw (CVE-2026-96408). Unauthenticated code execution possible. No patch; restrict upgrade script access now. radar.offseq.com/threat/cve-2026-96…...
radar.offseq.com
CVE-2026-96408: Code injection in Six Apart Ltd. Movable Type Cloud Edition
This vulnerability in Movable Type Cloud Edition's upgrade script permits unauthenticated code injection, enabling execution of arbitrary Perl code or SQL queries. It affects versions >=2.0 <=2.17, >=8.0.0 <=8.0.12, >=8.8.0 <=8.8.5, >=9.0.0
000
OffSequence @offseq.bsky.social · 07/10/2026
Chrome 155 addresses 247 vulnerabilities, including 4 CRITICAL use-after-free flaws (CVE-2026-106382, - 106197, - 106358, - 106347). Update Chrome now on Windows, macOS & Linux for protection. radar.offseq.com/threat/chrome-155-… #OffSeq #...
radar.offseq.com
Chrome 155 Update Patches 247 Vulnerabilities
The Chrome 155 update patches a total of 247 vulnerabilities, among which four are critical use-after-free defects impacting Chromecast, Browser, Navigation, and Track components. These critical vulnerabilities are identified as CVE-2026-10
002
OffSequence @offseq.bsky.social · 07/10/2026
CRITICAL vuln: Eclipse ThreadX NetX Duo ≤6.5.1.202602 hit by out-of-bounds write in TLS 1.3 handshake. No patch yet — block untrusted servers, monitor for fixes. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-103416: CWE-787 Out-of-bounds write in Eclipse Foundation Eclipse Threa
This vulnerability (CWE-787) involves an out-of-bounds write in the TLS 1.3 handshake message cache within Eclipse ThreadX NetX Duo versions up to 6.5.1.202602. When a handshake message exceeds the allocated cache size, it overwrites memory
000
OffSequence @offseq.bsky.social · 07/10/2026
CRITICAL: CVE-2026-107104 in Manacle Multi-tenant ERP System enables remote code execution via unsafe deserialization. Unauthenticated attack possible — review exposure and tighten controls. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-107104: CWE-502 Deserialization of untrusted data in Manacle Technologi
This vulnerability exists in the ERP system due to unsafe deserialization of user controlled data in the affected functionality. An unauthenticated remote attacker could exploit this vulnerability by supplying specially crafted data to the
000
OffSequence @offseq.bsky.social · 07/10/2026
25 Android vulnerabilities patched in Oct 2026, incl. 7 CRITICAL — System bug allows local privilege escalation without user action. Update devices now for protection. radar.offseq.com/threat/androids-oc… #OffSeq #Android #Security
radar.offseq.com
Android’s October 2026 Updates Patch 25 Vulnerabilities
The October 2026 Android security patches resolve 25 vulnerabilities: seven in the Framework and eighteen in the System components. Among these, seven are critical severity, including a critical local privilege escalation vulnerability in t
000
OffSequence @offseq.bsky.social · 07/10/2026
ASUS Routers face a CRITICAL XSS flaw (CVE-2026-14911, CVSS 9.3). Exploitable via crafted URLs — attackers can change settings or cause DoS. No patch yet; avoid untrusted links while authenticated. radar.offseq.com/threat/cve-2026-14…...
radar.offseq.com
CVE-2026-14911: CWE-79 Improper neutralization of input during web page generati
This vulnerability (CWE-79) in ASUS router modules involves improper neutralization of input during web page generation, enabling cross-site scripting attacks. An attacker can exploit this by crafting a URL that, when visited by an authenti
000
OffSequence @offseq.bsky.social · 07/10/2026
Flexera FlexNet Publisher ≤11.19.11 hit by CRITICAL auth bypass (CVE-2026-19572, CVSS 9.3). Unauthenticated users may gain admin access. Patch unavailable — monitor & restrict access. radar.offseq.com/threat/cve-2026-19…...
radar.offseq.com
CVE-2026-19572: CWE-288: Authentication Bypass Using an Alternate Path or Channe
A security vulnerability has been identified in FlexNet Publisher lmadmin. The vulnerability exists in a SOAP handler, where a hardcoded authentication bypass could allow an unauthenticated user to obtain a privileged administrator session
000
OffSequence @offseq.bsky.social · 07/10/2026
wolfSSH versions <1.6.0 face a CRITICAL flaw: ECDSA curve IDs are not verified in key exchange, enabling MitM attacks if public key checks are weak. Update or reinforce validation. radar.offseq.com/threat/cve-2026-16…...
radar.offseq.com
CVE-2026-16516: CWE-345 Insufficient Verification of Data Authenticity in wolfSS
wolfSSH does not validate that the ECDSA curve identifier in a KEXDH_REPLY host key blob matches the algorithm negotiated during key exchange. In ParseECCPubKey() (src/internal.c), the blob's algorithm string is used to derive the curve via
000
OffSequence @offseq.bsky.social · 07/10/2026
IBM Langflow OSS (v1.0.0 – 1.12.2) has a CRITICAL code injection vuln (CVE-2026-93674, CVSS 9.8). Remote code exec possible. Restrict access & monitor systems until a patch arrives. radar.offseq.com/threat/cve-2026-93…...
radar.offseq.com
CVE-2026-93674: CWE-94 Improper Control of Generation of Code ('Code Injection')
IBM Langflow OSS versions 1.0.0 through 1.12.2 contain a code injection vulnerability (CWE-94) due to improper neutralization of special elements used in OS commands. This flaw allows remote attackers to execute arbitrary code on affected s
000
OffSequence @offseq.bsky.social · 07/10/2026
Rockstar Games — CRITICAL breaches via MFA fatigue, OAuth theft, P2P RCE, & internal segmentation gaps. Major GTA VI dev build exfiltration. Strengthen MFA, DLP, & network controls. radar.offseq.com/threat/rockstar-ga…...
radar.offseq.com
Rockstar Games has now been compromised several different ways since 2018, and n
Between 2018 and 2026, Rockstar Games experienced four distinct confirmed compromises: (1) In 2022, the Lapsus$ group used MFA fatigue and plaintext credentials in Slack and Confluence to exfiltrate source code. (2) In early 2023, GTA Onlin
000
OffSequence @offseq.bsky.social · 06/10/2026
CRITICAL code injection in smarty-php Smarty (CVE-2026-82531) lets attackers run PHP code remotely. Update to 4.5.8/5.8.5 now to stay protected. radar.offseq.com/threat/cve-2026-82… #OffSeq #CVE ...
radar.offseq.com
CVE-2026-82531: Improper Control of Generation of Code ('Code Injection') in sma
CVE-2026-82531 is a critical code injection vulnerability in smarty-php's Smarty template engine. The issue arises because the top-level nocache_hash is not restored during extends:/multi-component template inheritance, leaving it null. Att
001
OffSequence @offseq.bsky.social · 06/10/2026
Weblizar Newsletter Subscription Form <=1.5.9 hit by CRITICAL unauthenticated SQL Injection (CVSS 9.3). Patch status unknown — disable or restrict immediately. radar.offseq.com/threat/cve-2026-41…...
radar.offseq.com
CVE-2026-41555: CWE-89 Improper Neutralization of Special Elements used in an SQ
This vulnerability (CVE-2026-41555) involves improper neutralization of special elements used in an SQL command (CWE-89) within the Newsletter Subscription Form – User Subscriptions Form, Capture Email component of Weblizar WordPress themes
000
OffSequence @offseq.bsky.social · 06/10/2026
CRITICAL: Porto Theme - Functionality ≤3.9.3 vulnerable to unauthenticated SQL injection (CVE-2026-42415). Patch status unconfirmed — restrict access now. 🔒 radar.offseq.com/threat/cve-2026-42…...
radar.offseq.com
CVE-2026-42415: CWE-89 Improper Neutralization of Special Elements used in an SQ
This vulnerability (CVE-2026-42415) involves improper neutralization of special elements used in SQL commands (CWE-89) in the Porto Theme - Functionality product by p-themes. It affects versions up to 3.9.3 and allows unauthenticated attack
010
OffSequence @offseq.bsky.social · 06/10/2026
CRITICAL SQL Injection in ARMember Premium <= 7.8 (CVE-2026-42417) allows unauthenticated exploitation. No fix yet — audit your sites and restrict access. radar.offseq.com/threat/cve-2026-42…...
radar.offseq.com
CVE-2026-42417: CWE-89 Improper Neutralization of Special Elements used in an SQ
Unauthenticated SQL Injection in ARMember Premium <= 7.8 versions.
000
OffSequence @offseq.bsky.social · 06/10/2026
Tenda AC5 (02.03.01.111_multi) hit by CRITICAL stack-based buffer overflow (CVE-2026-105778). Remote code execution possible. No patch — restrict remote management & monitor for threats. More: radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-105778: Stack-based Buffer Overflow in Tenda AC5
The vulnerability CVE-2026-105778 affects Tenda AC5 firmware version 02.03.01.111_multi. It is a stack-based buffer overflow in the Wifi Handler component's /goform/setWifi functionality. The issue arises from improper manipulation of the w
000
OffSequence @offseq.bsky.social · 06/10/2026
Post SMTP WordPress plugin (<=4.0.1) hit by HIGH severity stored XSS. Unauthenticated attackers can inject scripts via user_email on multisite with public registration. Mitigate now. 🔒 radar.offseq.com/threat/cve-2026-75…...
radar.offseq.com
CVE-2026-75962: CWE-79 Improper Neutralization of Input During Web Page Generati
The Post SMTP – Complete Email Deliverability and SMTP Solution with Email Logs, Alerts, Backup SMTP & Mobile App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'user_email' parameter in all versions up to, and in
000
OffSequence @offseq.bsky.social · 06/10/2026
CVE-2026-91107: CRITICAL in openSIS-Classic 9.3. Teacher-role users can reset any staff password via auth bypass. Audit password changes, restrict permissions until patch. radar.offseq.com/threat/cve-2026-91…...
radar.offseq.com
CVE-2026-91107: CWE-639 Authorization Bypass Through User-Controlled Key in OS4E
The vulnerability identified as CVE-2026-91107 affects openSIS Classic version 9.3. It involves an authorization bypass (CWE-639) where an authenticated user assigned the built-in teacher role can manipulate the staff_id parameter to select
000
OffSequence @offseq.bsky.social · 06/10/2026
TOTOLINK X6000R (9.4.0cu.652_B20230116) faces CRITICAL OS command injection (CVE-2026-105484). Remote attackers can fully compromise devices. Restrict access & monitor now. radar.offseq.com/threat/cve-2026-10… #OffSeq #CVE #IoTSe...
radar.offseq.com
CVE-2026-105484: OS Command Injection in TOTOLINK X6000R
This vulnerability affects TOTOLINK X6000R version 9.4.0cu.652_B20230116. The issue is an OS command injection in the firmware_check function of the /cgi-bin/cstecgi.cgi file, part of the UploadFirmwareFile Handler. By manipulating the file
000
OffSequence @offseq.bsky.social · 06/10/2026
Atlassian Bamboo Data Center <10.2.24 is affected by CRITICAL path traversal (CVE-2026-21589). Unauthenticated attackers can read/write files if the path is known. Patch now: radar.offseq.com/threat/cve-2026-21…...
radar.offseq.com
CVE-2026-21589: Path Traversal (Arbitrary Read/Write) in Atlassian Bamboo Data C
This vulnerability impacts Atlassian Data Center products such as Bitbucket, Confluence, Crowd, Jira Software, Jira Service Management, Bamboo, Crucible, and Fisheye. It enables unauthenticated remote attackers to perform arbitrary file rea
001
OffSequence @offseq.bsky.social · 06/10/2026
CRITICAL: twentyhq twenty (v1.20.10 – 2.7.0) leaks plaintext IMAP/SMTP/CalDAV creds via GraphQL. Any workspace member can access others' credentials. Update to 2.7.0 ASAP. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-105763: CWE-522: Insufficiently Protected Credentials in twentyhq twent
CVE-2026-105763 is a critical vulnerability in the twentyhq twenty CRM platform affecting versions >=1.20.10 and <2.7.0. The vulnerability arises because the /metadata GraphQL connectedAccounts query returns connectionParameters including p
000
OffSequence @offseq.bsky.social · 05/10/2026
CRITICAL SSRF vulnerability in Progress @progress/sitefinity-nextjs-sdk (15.1.8326 – 15.4.8637). Remote attackers may access sensitive data. Monitor for updates and restrict server egress. radar.offseq.com/threat/cve-2026-92…...
radar.offseq.com
CVE-2026-92931: CWE-918: Server-Side Request Forgery in Progress Software @progr
CWE-918: Server-Side Request Forgery in the Progress @progress/sitefinity-nextjs-sdk npm package versions 15.1.8326 through 15.4.8637 may allow a remote attacker to make server-side requests to an attacker-controlled host, potentially expos
011
OffSequence @offseq.bsky.social · 05/10/2026
Totolink A3002MU (v1.0.0-B20230403.1455) faces CRITICAL CVE-2026-105284 (CVSS 10): remote auth bypass due to improper authorization. Public exploit out. Restrict device access & check for updates. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-105284: Improper Authorization in Totolink A3002MU
The vulnerability CVE-2026-105284 exists in the Totolink A3002MU router firmware version 1.0.0-B20230403.1455. It is located in the function sub_40FCFC within the /bin/boa executable, which handles authentication checks. Due to improper aut
000
OffSequence @offseq.bsky.social · 05/10/2026
Totolink A3002MU faces a CRITICAL stack overflow (CVE-2026-105285, CVSS 10). Remote RCE possible — public exploit exists. Restrict admin access & monitor until a patch is out. radar.offseq.com/threat/cve-2026-10… #OffSeq ...
radar.offseq.com
CVE-2026-105285: Stack-based Buffer Overflow in Totolink A3002MU
CVE-2026-105285 is a stack-based buffer overflow vulnerability in Totolink A3002MU firmware version 1.0.0-B20230403.1455. The vulnerability arises from improper handling of the addQos/comment/entry_name argument in the QoS Rule Handler comp
000
OffSequence @offseq.bsky.social · 05/10/2026
Mitel MiVoice Office 400 v11.0.96.0: HIGH severity path traversal (CVSS 8.4) lets privileged users access sensitive files via web portal. Restrict access & watch for vendor updates. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-104706: CWE-31 Path traversal: 'dir\..\..\filename' in Mitel Mitel MiVo
CVE-2026-104706 is a path traversal vulnerability discovered by DigitalCanion in Mitel MiVoice Office 400 version 11.0.96.0. The vulnerability allows an attacker with high privileges and local access to the web portal (https://<ip>:8443) to
000
OffSequence @offseq.bsky.social · 05/10/2026
ShinyHunters leader arrested in Jordan after FBIJobs.gov hack. HIGH severity: 140+ orgs breached, $70M+ extorted. Work with law enforcement if affected. radar.offseq.com/threat/alleged-shi… #OffSeq #Cybercrime #ThreatIntel
radar.offseq.com
Alleged ShinyHunters Leader Arrested in Jordan
Saif al-Din Khader, known as Rey and a member of the ShinyHunters and Scattered Lapsus$ Hunters groups, was arrested in Jordan and is assisting the FBI in identifying other members of the extortion group. ShinyHunters recently hacked the FB
000
OffSequence @offseq.bsky.social · 05/10/2026
CRITICAL: AhsayCBS <10.3.4 vulnerable to unauthenticated OS command injection (CVE-2026-105134). Remote exploit = full compromise. Upgrade to 10.3.4 now. radar.offseq.com/threat/a-flaw-has-… #OffSeq #Vulnerability #Ahs...
radar.offseq.com
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. (CVE-2026-105134)
CVE-2026-105134 is a critical remote OS command injection vulnerability in Ahsay AhsayCBS affecting versions up to 10.3.2. The vulnerability resides in the Replication Receiver component's /rps/api/json/UpdateReceivers.do endpoint, where im
001
OffSequence @offseq.bsky.social · 05/10/2026
ZITADEL versions 3.0.0 – 3.4.15 & 4.0.0<4.17.3 hit by CRITICAL vuln (CVE-2026-105207) — attackers can hijack accounts via IdP link. Patch status unclear: monitor advisories. 🚨 radar.offseq.com/threat/zitadel-300…...
radar.offseq.com
ZITADEL 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3 creates links between user
The vulnerability in ZITADEL affects versions 3.0.0 through 3.4.15 and 4.0.0 before 4.17.3. It arises because the system creates links between user accounts and external identity providers without proper verification of a primary authentica
000
OffSequence @offseq.bsky.social · 05/10/2026
CVE-2026-105221: gist RubyGem <6.1.0 has a CRITICAL SSL validation flaw. Attackers can steal GitHub credentials via intercepted API traffic. Upgrade to 6.1.0+ ASAP. radar.offseq.com/threat/cve-2026-10… #OffSeq #CVE2026105...
radar.offseq.com
CVE-2026-105221: Improper Certificate Validation in defunkt gist
The gist RubyGem versions from 4.0.0 up to but not including 6.1.0 contain an improper certificate validation vulnerability. The vulnerability arises because the http_connection method in lib/gist.rb sets SSL verification to VERIFY_NONE, ef
000
OffSequence @offseq.bsky.social · 05/10/2026
maclof kubernetes-client v0.17.0 – 0.31.x hit by CRITICAL vuln: TLS cert checks bypassed, enabling API server impersonation & token theft. Avoid affected versions or enforce proper certs until patch lands. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-105223: Improper Certificate Validation in maclof kubernetes-client
The maclof kubernetes-client versions 0.17.0 through 0.31.x disable TLS certificate verification in the parseKubeconfig() and parseKubeconfigFile() functions when the kubeconfig file does not contain certificate-authority-data. This behavio
010
OffSequence @offseq.bsky.social · 05/10/2026
CRITICAL: alexpechkarev/google-maps v1.0.3 – 12.16 disables TLS cert validation by default. API keys at risk; responses can be altered. Enable ssl_verify_peer=TRUE until a fix. Details: radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-105222: Improper Certificate Validation in alexpechkarev google-maps
The alexpechkarev/google-maps Laravel package versions from 1.0.3 through 12.16 disable TLS certificate verification by default because the bundled configuration sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. This
000
OffSequence @offseq.bsky.social · 04/10/2026
LaraDashboard <1.4.8 has a HIGH severity flaw: settings.view users can access sensitive secrets via API. Patch to 1.4.8+ now. radar.offseq.com/threat/laradashboa… #OffSeq #Vulnerabilit...
radar.offseq.com
LaraDashboard before 1.4.8 contains an incorrect authorization vulnerability tha
CVE-2026-105129 describes an incorrect authorization vulnerability in LaraDashboard prior to version 1.4.8. Authenticated users possessing only the settings.view permission can exploit this flaw to retrieve sensitive stored secrets by query
000
OffSequence @offseq.bsky.social · 04/10/2026
StylemixThemes Cost Calculator Builder (<4.0.18) faces a HIGH severity vuln (CVE-2026-97307): can leak sensitive data via sent info. Patch status unknown — monitor advisories. 🔒 radar.offseq.com/threat/cve-2026-97…...
radar.offseq.com
CVE-2026-97307: Insertion of Sensitive Information Into Sent Data in StylemixThe
The vulnerability identified as CVE-2026-97307 in StylemixThemes Cost Calculator Builder allows an attacker to cause sensitive information to be inserted into data sent by the plugin, enabling retrieval of embedded sensitive data. This affe
000
OffSequence @offseq.bsky.social · 04/10/2026
AhsayCBS 10.3.0 – 10.3.2 hit by CRITICAL OS command injection (CVE-2026-105134). Remote code execution possible — exploit is public. Upgrade to 10.3.4+ immediately. radar.offseq.com/threat/cve-2026-10… #OffSeq #Vulnerability #CVE
radar.offseq.com
CVE-2026-105134: OS Command Injection in Ahsay AhsayCBS
Ahsay AhsayCBS up to version 10.3.2 contains an OS command injection vulnerability in the Replication Receiver component, specifically in the /rps/api/json/UpdateReceivers.do file. An attacker can remotely manipulate the 'random' argument t
001
OffSequence @offseq.bsky.social · 04/10/2026
CRITICAL: SQL Injection in Unlimited Elements For Elementor (<2.0.21). Sites at risk — monitor for fixes & restrict access. radar.offseq.com/threat/cve-2026-10… #OffSeq #WordPress #SQLI...
radar.offseq.com
CVE-2026-103355: Improper Neutralization of Special Elements used in an SQL Comm
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Blind SQL In
000
OffSequence @offseq.bsky.social · 04/10/2026
InternLM MindSearch 0.1.0 faces CRITICAL code injection (CVE-2026-105135). Remote attackers can run arbitrary code — no patch yet. Restrict access & monitor vendor updates. radar.offseq.com/threat/cve-2026-10… #OffSeq #CVE202610513...
radar.offseq.com
CVE-2026-105135: Code Injection in InternLM MindSearch
This vulnerability in InternLM MindSearch 0.1.0 arises from improper handling of the inputs argument in the ExecutionAction.run function within the Planner Agent component. An attacker can remotely manipulate this argument to perform code i
000
OffSequence @offseq.bsky.social · 04/10/2026
HIGH severity in Bouncy Castle for Java <1.86: OpenPGP API flaw lets restricted subkeys issue trusted certifications. Validate key flags — no patch yet. radar.offseq.com/threat/in-bouncy-c…...
radar.offseq.com
In Bouncy Castle for Java before 1.86, the high-level OpenPGP certificate API ac
In Bouncy Castle for Java versions prior to 1.86, the OpenPGP certificate API's methods getCertificationBy() and getDelegationBy() accepted third-party signatures from any component key of the issuing certificate without verifying that the
000
OffSequence @offseq.bsky.social · 04/10/2026
Vulnerability CVE-2026-88779 (HIGH, CVSS 8.7) affects NetScaler ADC/Gateway pre-14.1-73.41. Remote attacks possible — patch now. No active exploits detected. radar.offseq.com/threat/cve-2026-88… #OffSeq #NetScaler #Security
radar.offseq.com
CVE-2026-88779: Vulnerability in NetScaler ADC
This vulnerability affects NetScaler ADC and NetScaler Gateway versions prior to 14.1-73.41, 13.1-64.28, and 13.1-37.282. The CVSS 4.0 vector indicates a network attack vector with low attack complexity, no privileges or user interaction re
000
OffSequence @offseq.bsky.social · 04/10/2026
ShinyHunters operations disrupted (HIGH severity): key member Rey detained in Jordan, now assisting the FBI. Group remains active — monitor law enforcement updates and review incident response. radar.offseq.com/threat/shinyhunter…...
radar.offseq.com
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
The ShinyHunters hacking group, involved in extensive data theft and extortion campaigns targeting organizations worldwide, has suffered a significant law enforcement setback with the detention of a suspected member, Saif al-Din Khader (ali
000
OffSequence @offseq.bsky.social · 04/10/2026
vincent-peugnet wcms ≤3.18.0 has a HIGH-severity vuln: CVE-2026-105123 allows editor-level RCE via arbitrary file upload. Restrict privileges & monitor endpoints. radar.offseq.com/threat/cve-2026-10…...
radar.offseq.com
CVE-2026-105123: Unrestricted Upload of File with Dangerous Type in vincent-peug
The vulnerability in vincent-peugnet wcms (up to 3.18.0) allows authenticated users with editor privileges to upload files without proper validation of file types or paths. This enables attackers to upload malicious .php files that the web
001
OffSequence @offseq.bsky.social · 04/10/2026
CRITICAL: Bouncy Castle for Java <1.86 lets attackers hijack X.509 identities in MLS groups. Upgrade to v1.86+ for protection. radar.offseq.com/threat/in-bouncy-c… #OffSeq #BouncyCast...
radar.offseq.com
In Bouncy Castle for Java before 1.86, the Messaging Layer Security (MLS, RFC 94
In Bouncy Castle for Java versions prior to 1.86, the MLS implementation did not enforce that the X.509 certificate's public key matched the LeafNode's signature_key as required by RFC 9420 section 5.3. The LeafNode.verify() method validate
000