News
What Is Sakana AI's "Fugu"? The Japanese AI That Bundles Other AIs
Japanese CompaniesDevelopmentAI
Japan's Sakana AI launched Fugu and Fugu Ultra, an AI that bundles and routes between multiple models. What it is, and how it differs from Claude and ChatGPT, explained for non-experts.
2026.06.2362 views
News
ManageEngine CVE-2026-11374: Hard to Exploit, but Patching Isn't Enough
SecurityDevelopment
Unauthenticated account takeover hits ManageEngine products integrated with AD360 (CVE-2026-11374, CVSS 9.0), via predictable SSO tickets. Update now.
2026.06.2358 views
News
KDDI email breach: count corrected to 12,231,954 and resets are done
Japanese CompaniesPrivacySecurity
KDDI's ISP email system was breached, possibly exposing up to 14.22M email addresses and passwords. @nifty, BIGLOBE and more affected. Here's what to do now.
2026.06.2346 views
News
expr-eval Code Injection via toJSFunction (CVE-2026-12866, CVSS 9.8): Never Pass Untrusted Input, Move to expr-eval-fork
SecurityDevelopment
A critical code-injection flaw (CVE-2026-12866, CVSS 9.8) affects expr-eval, a JavaScript math-expression library with 800k+ weekly downloads used in AI and NLP apps. Its toJSFunction() compiles input via new Function(), so untrusted expressions run as code. Stop passing untrusted input and move to expr-eval-fork.
2026.06.2335 views
News
FastStone CVE-2026-30040/30041: 8.5 is out, but no confirmed fix
Security
FastStone Image Viewer (8.3.0.0 and earlier), a free image viewer, has two flaws (CVE-2026-30040 / 30041) that let a crafted image take over a PC; the former triggers from automatic thumbnail generation alone. The vendor is unreachable and no patch exists, so mitigations — not processing untrusted images — are essential.
2026.06.2341 views
News
Windows BitLocker Bypass Flaw YellowKey: Fix Status and What to Do
LinuxSecurity
A flaw (CVE-2026-45585, 'YellowKey') abuses the Windows recovery environment WinRE to defeat BitLocker disk encryption and the UEFI/BIOS password in minutes with physical access and one USB stick. It breaks the 'encrypted, so safe' premise for lost or stolen PCs. Microsoft fixed it in the June 2026 update — apply it now.
2026.06.2379 views
News
Two vLLM Flaws: API-Key Bypass (CVE-2026-48746, CVSS 9.1) & Dependency Confusion (CVE-2026-54232) — Update to 0.22.1
AISecurity
vLLM, the go-to engine for self-hosting LLMs, has two critical flaws. CVE-2026-48746 (CVSS 9.1) lets attackers bypass the API key and use the AI API without authentication; CVE-2026-54232 (CVSS 8.8) is a Docker-build dependency confusion that runs code as root. Updating to 0.22.1 resolves both.
2026.06.2338 views
News
Crawl4AI Vulnerabilities: Update to 0.9.2 or Later to Be Safe
AISecurity
Crawl4AI, a popular crawler for AI data collection, has a critical flaw in its Docker API server, exploitable without authentication (CVE-2026-56266). An attacker can make the server fetch cloud internal data and steal access keys. All versions before 0.8.7 are affected; 0.8.7 also fixes several flaws including a pre-auth RCE. Update now.
2026.06.2337 views
News
Dell Wyse Management Suite SQL Injection Flaw and How 2605 Fixes It
Global CompaniesSecurity
Dell Wyse Management Suite, used to centrally manage fleets of thin clients, has a critical flaw (CVSS 8.8, CVE-2026-44272). A low-privileged logged-in attacker can use SQL injection to reach information and operations beyond their rights, risking the management base. All versions before 2605 are affected; update to 2605 now.
2026.06.2318 views
News
ADSys, Ubuntu's Active Directory Tool: Forged-Certificate Flaw Fixed in 0.16.3
SecurityLinux
ADSys, the official tool for managing Ubuntu under Windows Active Directory, has a critical flaw (CVSS 9.0, CVE-2026-12249). Because certificate auto-enrollment ran over plain HTTP, an attacker on the network can make endpoints trust forged certificates, enabling interception and impersonation. Fixes are out for each Ubuntu release; update now.
2026.06.2323 views
News
Critical RCE in Autodesk Fusion CAD: CVE-2026-10789 (CVSS 9.6) — Update to 2703.1.20
SecurityGlobal Companies
Autodesk Fusion's desktop CAD has a critical flaw (CVSS 9.6, CVE-2026-10789). With the MCP extension enabled, simply opening a malicious web page can run attacker code on your PC, risking design-data theft and full takeover. Versions before 2703.1.20 are affected; update now.
2026.06.2330 views
News
Langflow: all 24 flaws are fixed in 1.11.0, and CVE-2026-19297 makes 25
AISecurity
Serious flaws in the AI tool Langflow keep coming. On June 30, 2026 IBM disclosed 8 more, led by a CVSS 10.0 code execution that takes over the server with no login or interaction (CVE-2026-10134). Up to 1.10.0 is affected; update to the latest release (1.10.1+) now.
2026.06.2395 views