News
Is FFmpeg safe? A run of subtitle, audio & video flaws (CVE-2026-64830 and more) — even 8.1.2 needs another update
DevelopmentSecurity
Is FFmpeg safe to use? In July 2026 four more high-severity flaws were disclosed together in the go-to video software—in subtitle and audio parsing and in hardware video playback (CVE-2026-64830/64831/64832/64835), all rated 8.8, where a single crafted file can lead to code execution. None is fixed by June's 8.1.2 release.
2026.06.19108 views
News
Is SignalRGB Safe? Its Driver Flaws Are Fixed. What to Check Now
SecurityLinux
Two flaws in the kernel driver that SignalRGB installs — CVE-2026-8049, where any local user can reach admin-level hardware operations, and CVE-2026-8050, which can repeatedly crash the PC — were disclosed via JVN and CERT/CC. Both are local but usable for privilege escalation, and because the driver is signed it can be carried onto other machines as a BYOVD tool. WhirlwindFX fixed them in 1.3.6 / 1.3.7.0. Here is how to update and what to check.
2026.06.1856 views
News
Picklescan Can Be Bypassed: 8 Flaws Let Malicious AI Models Pass as Safe (CVE-2026-3490), Update to v1.0.4
SecurityAI
Picklescan, the tool that detects dangerous code hidden in AI models, has eight flaws that let attackers slip past the scan. The most severe, CVE-2026-3490, scores a perfect 10.0. Even a model marked safe can hijack your PC or server the moment it loads, and since it runs behind hubs like Hugging Face, the impact is broad. Here is what to do, how to update to v1.0.4, and a safer model format.
2026.06.1830 views
Lab
Python 3.15: locale.getdefaultlocale Won't Be Removed, Plus Lazy Imports and What Breaks
Development
Hit the "'locale.getdefaultlocale' is deprecated and slated for removal in Python 3.15" warning? Swap it for getlocale()/getencoding() — the replacement code is inside. Plus the rest of 3.15, benchmarked on the beta: lazy imports (~4x faster startup), UTF-8 by default, and the APIs that stop working when you upgrade.
2026.06.17101 views
Roundup
Is PSN Down? How to Check, Fixes, and Why It Keeps Happening
InfrastructuregameJapanese Companies
PSN down again? How to check if PlayStation Network is really down, what to do while you wait, the July 24, 2026 global outage, a history of every major PSN outage, and why it keeps happening.
2026.06.1743 views
Roundup
Kitakyushu's national health insurance slips go wrong for 44,000 homes
PrivacyJapanese CompaniesDevelopment
Kitakyushu City found defects in the national health insurance payment slips it mailed out. Another person's slip was enclosed in some envelopes, and the barcodes for the January-March installments carried someone else's data. About 44,000 households are affected. The cause: a vendor program flaw in the system swapped in May, plus an error in the new envelope-stuffing machine. We break down what happened, why it slipped through, and what recipients should do.
2026.06.1726 views
Roundup
Awa Bank's 27,745-record leak: what happened in a test environment left running
PrivacyJapanese CompaniesSecurity
Awa Bank leaked a cumulative 27,745 records of customer and shareholder data. The cause was a test environment left running long after development ended, with real customer data never deleted, then accessed from outside. We break down what leaked, how it could be abused, and how it should have been prevented.
2026.06.1731 views
News
Joomla JCE takeover flaw CVE-2026-48907: update to 2.9.99.9
SecurityDevelopment
A critical flaw, CVE-2026-48907, in JCE, a hugely popular editor add-on used by many Joomla sites, lets attackers take over a server with no login. Severity is a perfect 10.0, exploit code is public, and automated attacks are underway. CISA has ordered urgent remediation. Here are the affected versions and what to do now.
2026.06.17120 views
News
Data-Theft Flaw in WordPress 'The Events Calendar', Fixed in 6.16.3
DevelopmentSecurity
The Events Calendar, a WordPress plugin on 700,000+ sites, has a critical flaw (CVE-2026-49772, severity 9.3) that lets anyone read the database with no login. Here are the affected versions, how to check your site, and how to update to 6.16.3 now.
2026.06.1629 views
News
Zyxel GS1900 Switch Takeover Flaw CVE-2026-7273: Patch 10 Models Now
InfrastructureSecurityGlobal Companies
Zyxel's GS1900 office network switches — 10 models — have a flaw, CVE-2026-7273, that lets anyone on the same local network take the device over without a password, enabling traffic spying or cut-offs. Here are the affected models, the fixed firmware, and the update steps to run now.
2026.06.1632 views
News
i18next Add-ons i18next-fs-backend and i18next-http-middleware: Two Unauthenticated Flaws, Fixed in 2.6.6 / 3.9.7
DevelopmentSecurity
Two companion components of i18next, the JavaScript library widely used to translate web app UIs, have 9.1 flaws (CVE-2026-48713 / 48714). With no login, an attacker can poison the app's shared foundation, chaining to bypassed login checks or service outages. Update to 2.6.6 / 3.9.7.
2026.06.1632 views
News
WordPress Plugin Vulnerabilities: Easy Invoice and GeekyBot Are Fixed in the Latest Versions
DevelopmentSecurity
In June 2026, dozens of WordPress plugins disclosed critical flaws leading to site takeover or data theft. The invoicing plugin Easy Invoice and the chatbot GeekyBot are rated a maximum 10.0, and a dozen-plus form-integration plugins are exploitable with no login. If your site uses an affected plugin, update each one to the latest version now.
2026.06.1623 views