Sign in

OffSequence

@offseq.bsky.social
86 followers 0 following 3.4K posts

OffSeq is a cutting-edge European cybersecurity company helping organizations build digital resilience through tailored, proactive security solutions. #CyberSecurity www.offseq.com radar.offseq.com breach.offseq.com

PostsRepliesMedia
OffSequence @offseq.bsky.social · 27/12/2025
MongoDB (3.6–8.2.3) hit by HIGH severity bug—unauthenticated attackers can read uninitialized memory if zlib is enabled. Patch or disable zlib compression now! radar.offseq.com/threat/new-mongodb… #OffSeq #MongoDB #SecurityAlert
Security threat visualization
010
OffSequence @offseq.bsky.social · 27/12/2025
LangChain Core CRITICAL vuln! Serialization injection enables secret theft & LLM manipulation in <1.2.5—upgrade ASAP, disable secrets_from_env, use allowlists. Protect your AI apps! radar.offseq.com/threat/critical-la… #OffSeq #LangChain #AIs...
Security threat visualization
000
OffSequence @offseq.bsky.social · 27/12/2025
LangChain Core faces CRITICAL serialization injection risk—unauthorized access to AI secrets possible. No patch yet: validate/sanitize all serialized inputs & monitor closely! radar.offseq.com/threat/critical-la… #OffSeq #LangChain #AIsecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 27/12/2025
🚨 CRITICAL: IBM API Connect (10.0.8.0–10.0.8.5, 10.0.11.0) hit by auth bypass flaw. Restrict access, enable MFA, watch for alerts until patches land! More info: radar.offseq.com/threat/cve-2025-13… #OffSeq #IBM #APIsecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 27/12/2025
Eigent-ai Eigent v0.0.60 hit by CRITICAL RCE (CVE-2025-68952). Unauthenticated attackers can take control remotely. Patch to 0.0.61 ASAP! 🚨 radar.offseq.com/threat/cve-2025-68… #OffSeq #vulnerability #AIsecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 27/12/2025
🚨 CRITICAL: Prototype pollution in apidoc-core ≥0.2.0 lets remote attackers disrupt JS apps. Audit use, sanitize inputs, and isolate processing ASAP. Patch pending. Details: radar.offseq.com/threat/cve-2025-13… #OffSeq #Security #JavaScript
Security threat visualization
000
OffSequence @offseq.bsky.social · 27/12/2025
n8n-io n8n (v1.0.0–<2.0.0) hit by CRITICAL vuln: CVE-2025-68668 lets auth'd users run arbitrary commands via Python Code Node. Upgrade to v2.0.0+ or disable node now. radar.offseq.com/threat/cve-2025-68… #OffSeq #n8n #Vulnerability
Security threat visualization
001
OffSequence @offseq.bsky.social · 27/12/2025
CRITICAL: RCE in lemon8866 StreamVault (<251126) via /admin/api/saveConfig. Exploitable OS command injection. Patch to 251126 now! radar.offseq.com/threat/cve-2025-66… #OffSeq #CVE202566203 #StreamVault
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
Eaton UPS Companion Software hit by HIGH severity vuln—arbitrary code exec possible via uncontrolled search path. Local access needed. Patch urgently! radar.offseq.com/threat/cve-2025-59… #OffSeq #Vulnerability #IncidentResponse
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
HIGH severity: Eaton UPS Companion flaw lets local attackers execute code due to insecure library loading. Update to latest version ASAP to secure critical power systems! radar.offseq.com/threat/cve-2025-67… #OffSeq #Eaton #Security
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
HIGH severity: Delta DVP-12SE PLCs send Modbus/TCP data in cleartext, allowing attackers to intercept or disrupt operations. Segment your networks & monitor Modbus traffic until a patch is available. radar.offseq.com/threat/cve-2025-62… #OffS...
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
HIGH severity vuln in UTT 进取 512W (≤1.7.7-171114) enables remote buffer overflow via wepkey1. Public exploit code raises risk—patch or segment devices now! radar.offseq.com/threat/cve-2025-15… #OffSeq #Vulnerability #UTT
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
HIGH-severity buffer overflow in UTT 进取 512W (v1.7.7-171114) lets attackers execute code remotely. PoC code is public. Isolate devices and restrict endpoint access now! radar.offseq.com/threat/cve-2025-15… #OffSeq #Vulnerability #NetworkSecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
UTT 进取 512W (≤1.7.7-171114) faces a HIGH severity buffer overflow—remote, no-auth exploit possible. Isolate devices, monitor for attacks, and apply patches ASAP when released. radar.offseq.com/threat/cve-2025-15… #OffSeq #CyberAlert #IoTSecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
UTT 进取 512W (≤1.7.7-171114) faces HIGH severity buffer overflow vulnerability. Public exploit out — restrict access, segment networks, and monitor for attacks. radar.offseq.com/threat/cve-2025-15… #OffSeq #NetworkSecurity #UTT
Security threat visualization
000
OffSequence @offseq.bsky.social · 26/12/2025
Critical RCE in FreeBSD rtsold 15.x: Malicious IPv6 router ads exploiting DNSSL can lead to full system compromise. No patch—disable rtsold & enhance segmentation now. radar.offseq.com/threat/freebsd-rts… #OffSeq #FreeBSD #Security
Security threat visualization
011
OffSequence @offseq.bsky.social · 25/12/2025
Critical alert: Digiever DS-2105 Pro NVRs have an unpatched RCE flaw (CVE-2023-52163) exploited for botnets. Remove internet access & change default creds now. Device is end-of-life—replace ASAP. radar.offseq.com/threat/cisa-flags-… #OffSeq #...
Security threat visualization
000
OffSequence @offseq.bsky.social · 25/12/2025
JayBee Twitch Player (<=2.1.3) hit by CRITICAL missing auth flaw—CVE-2025-68565. Remote attackers can access or manipulate Twitch embeds. Audit & restrict usage ASAP; patch awaited. radar.offseq.com/threat/cve-2025-68… #OffSeq #TwitchSecurity...
Security threat visualization
000
OffSequence @offseq.bsky.social · 25/12/2025
CRITICAL: Captivate Sync (≤3.2.2) hit by Blind SQLi (CVE-2025-68570) — no auth needed! Audit now, enforce input validation, watch for patches. Protect your data. radar.offseq.com/threat/cve-2025-68… #OffSeq #SQLi #SecurityAlert
Security threat visualization
000
OffSequence @offseq.bsky.social · 25/12/2025
CRITICAL: Blind SQL Injection in CRM Perks Integration for Contact Form 7 HubSpot (<=1.4.2) 🚨 No auth needed — risk of data breach. Audit & patch sites now! radar.offseq.com/threat/cve-2025-68… #OffSeq #WordPress #SQLInjection
Security threat visualization
000
OffSequence @offseq.bsky.social · 25/12/2025
CRITICAL SSRF in Yannick Lefebvre Link Library (≤7.8.4) lets attackers access internal systems—no auth required. Lock down outbound traffic & monitor requests. Act before exploits emerge! radar.offseq.com/threat/cve-2025-68… #OffSeq #SSRF #Cy...
Security threat visualization
000
OffSequence @offseq.bsky.social · 25/12/2025
MongoDB faces a critical RCE vuln—patch now to block unauthenticated remote attacks. No exploits yet, but risk is high for anyone running MongoDB in production. Act fast! radar.offseq.com/threat/mongodb-war… #OffSeq #MongoDB #security
Security threat visualization
010
OffSequence @offseq.bsky.social · 25/12/2025
CRITICAL: CVE-2025-68916 in Riello NetMan 208 (<1.12) lets privileged users exploit path traversal for code exec. Restrict access, monitor uploads, and apply updates ASAP. More info: radar.offseq.com/threat/cve-2025-68… #OffSeq #Vulnerability...
Security threat visualization
000
OffSequence @offseq.bsky.social · 25/12/2025
🚨 CRITICAL RCE risk in MegaSys Telenium Online Web App! Perl input validation bug (CVE-2025-8769) allows unauthenticated code execution. Restrict login page access & watch for patches. radar.offseq.com/threat/cve-2025-87… #OffSeq #WebSecurity...
Security threat visualization
000
OffSequence @offseq.bsky.social · 24/12/2025
CRITICAL Coolify flaw: Authenticated users can inject OS commands as root via Database Import (pre-4.0.0-beta.451). Upgrade ASAP to block RCE! Details: radar.offseq.com/threat/cve-2025-66… #OffSeq #Coolify #vulnerability
Security threat visualization
000
OffSequence @offseq.bsky.social · 24/12/2025
CRITICAL: Coolify <4.0.0-beta.451 lets authenticated users run arbitrary root commands via PostgreSQL script injection. Upgrade ASAP! radar.offseq.com/threat/cve-2025-66… #OffSeq #Coolify #Vulnerability
Security threat visualization
000
OffSequence @offseq.bsky.social · 24/12/2025
Tenda WH450 v1.0.0.18 faces CRITICAL risk — public exploit enables remote stack overflow via PPTPDClient. Isolate & restrict access now. Patch pending. radar.offseq.com/threat/cve-2025-15… #OffSeq #CVE202515047 #NetworkSecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 24/12/2025
🚨 CRITICAL: Print Invoice & Delivery Notes for WooCommerce plugin (≤5.8.0) allows unauthenticated RCE. Update or disable now to prevent server takeover! More info: radar.offseq.com/threat/cve-2025-13… #OffSeq #WordPress #Vulnerability
Security threat visualization
001
OffSequence @offseq.bsky.social · 24/12/2025
Coolify CRITICAL vuln (CVSS 9.4): Authenticated users can inject root commands via proxy config filenames in <4.0.0-beta.451. Upgrade now & restrict admin permissions! radar.offseq.com/threat/cve-2025-66… #OffSeq #Coolify #Vulnerability
Security threat visualization
000
OffSequence @offseq.bsky.social · 24/12/2025
Coolify CRITICAL RCE: Auth users can inject OS commands as root (CVE-2025-66213). Upgrade to 4.0.0-beta.451 to secure your systems! 🛡️ radar.offseq.com/threat/cve-2025-66… #OffSeq #Coolify #RCE
Security threat visualization
000
OffSequence @offseq.bsky.social · 24/12/2025
LangChain CRITICAL vuln (CVE-2025-68664): Untrusted deserialization lets attackers run code or leak data. Affects <=1.2.4, <0.3.81. Upgrade to 1.2.5/0.3.81+ now! 🔒 radar.offseq.com/threat/cve-2025-68… #OffSeq #LangChain #AppSec
Security threat visualization
001
OffSequence @offseq.bsky.social · 24/12/2025
CRITICAL RCE in nanbingxyz 5ire ≤0.15.2: Malicious Mermaid diagrams can exploit markdown-it-mermaid to run code. Audit and disable the plugin until patched! radar.offseq.com/threat/cve-2025-68… #OffSeq #SecurityAlert #RCE
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
PhastPress plugin (≤3.7) hit by CRITICAL vuln: unauthenticated file reads via null byte injection. Remove or disable plugin, block %2500 requests, monitor logs. No patch yet — act fast! radar.offseq.com/threat/cve-2025-14… #OffSeq #WordPress ...
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
FCC issues CRITICAL ban on foreign-made drones & parts, citing national security threats 🚁. Assess supply chains, update procurement, and enhance drone monitoring now. radar.offseq.com/threat/fcc-bans-fo… #OffSeq #DroneSecurity #SupplyChain
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
MacSync malware dropper evades macOS Gatekeeper—HIGH severity alert for EU orgs! Boost EDR, app whitelisting, & user awareness to stay protected. 🍏 radar.offseq.com/threat/new-macsync… #OffSeq #macOS #Malware
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
CRITICAL: Frappe Framework v15.89.0 hit by CVE-2025-67289. Unauthenticated attackers can execute code via XML uploads. Restrict file types & monitor for abuse. Patch awaited. radar.offseq.com/threat/cve-2025-67… #OffSeq #Frappe #Security
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
🚨 Umbraco CMS 16.3.3 hit by CRITICAL vuln (CVE-2025-67288): attackers can upload crafted PDFs to run code. No patch—apply strict file upload controls & monitor closely! radar.offseq.com/threat/cve-2025-67… #OffSeq #Umbraco #VulnAlert
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
ClipBucket 5.5.2 CRITICAL flaw: default admin creds allow remote takeover. Change all admin passwords now & restrict panel access! No patch yet. Details: radar.offseq.com/threat/cve-2025-67… #OffSeq #ClipBucket #Security
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
CVE-2025-65856 (CRITICAL): Xiongmai XM530 IP cameras on affected firmware can be accessed remotely—no auth needed for 31 ONVIF endpoints. Disable ONVIF, segment networks, and watch for patches. radar.offseq.com/threat/cve-2025-65… #OffSeq #IoTSecurity #Surveillance
Security threat visualization
000
OffSequence @offseq.bsky.social · 23/12/2025
Sharp MP-01 Media Player CRITICAL flaw: No auth on web interface (all versions). Attackers can change settings & push content. Segment networks, restrict remote access until patched. radar.offseq.com/threat/cve-2025-12… #OffSeq #CVE202512049 ...
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
CRITICAL zero-day hits WatchGuard Firebox (Fireware OS iked process): Unauthenticated RCE exploited in the wild. Patch now, restrict access, monitor logs. radar.offseq.com/threat/watchguard-… #OffSeq #Firebox #ZeroDay
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
CRITICAL: Sharp projectors (all models) vulnerable to rogue firmware (CVE-2025-11543, CVSS 9.5). Isolate & restrict network access, monitor for abuse. Patch not available—act now! radar.offseq.com/threat/cve-2025-11… #OffSeq #CVE2025_11543 #A...
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
CRITICAL: CVE-2025-11544 in Sharp projectors allows remote, unauthorized firmware installs—no user interaction. All versions affected. Inventory and isolate devices, monitor for patches. radar.offseq.com/threat/cve-2025-11… #OffSeq #CVE2025 #...
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
🚨 CRITICAL: Sharp projectors (all models/versions) allow remote, unauthenticated access to sensitive info via HTTP. Segment your network, restrict access, and monitor now! radar.offseq.com/threat/cve-2025-11… #OffSeq #CVE2025 #IoTSecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
CRITICAL: Ragic Enterprise Cloud Database flaw (CVE-2025-15016) allows remote logins as any user via hard-coded key. Audit systems, restrict access, & monitor now while awaiting a patch. radar.offseq.com/threat/cve-2025-15… #OffSeq #CloudSecu...
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
CRITICAL: Tenda WH450 v1.0.0.18 has a remote stack overflow (CVE-2025-15007). Public exploit code out—restrict HTTP, monitor for attacks, and patch ASAP. radar.offseq.com/threat/cve-2025-15… #OffSeq #CVE202515007 #RouterSecurity
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
Tenda WH450 1.0.0.18 faces a CRITICAL stack-based buffer overflow—public exploit out now! Remote attacks possible. Review exposure & monitor for threats. radar.offseq.com/threat/cve-2025-15… #OffSeq #CVE202515006 #SecurityAlert
Security threat visualization
000
OffSequence @offseq.bsky.social · 22/12/2025
🚨 HIGH: themeisle Redirection for Contact Form 7 plugin—arbitrary file upload flaw in all versions. Disable plugin & 'allow_url_fopen', monitor for fixes. Act now! radar.offseq.com/threat/cve-2025-14… #OffSeq #WordPress #Security
Security threat visualization
000
OffSequence @offseq.bsky.social · 21/12/2025
Tenda FH1201 (v1.2.0.14[408]) hit by HIGH severity buffer overflow (CVE-2025-14995). Remote, unauthenticated exploit risk—no patch yet. Restrict access & monitor endpoints! radar.offseq.com/threat/cve-2025-14… #OffSeq #RouterSecurity #Vulnera...
Security threat visualization
000
OffSequence @offseq.bsky.social · 21/12/2025
Tenda FH1201/FH1206 routers (1.2.0.8/1.2.0.14) face HIGH severity buffer overflow (public exploit out). Restrict remote access & monitor traffic until patched. Details: radar.offseq.com/threat/cve-2025-14… #OffSeq #NetworkSecurity #Vulnerability
Security threat visualization
000