News
XSS Scanner Dalfox Hit by Unauthenticated RCE: CVE-2026-45087 (CVSS 10.0)
DevelopmentSecurity
Dalfox, the XSS scanner widely used by bug-bounty hunters, exposes an unauthenticated RCE in REST API server mode (CVE-2026-45087, CVSS 10.0). Versions up to 2.12.0 bind 0.0.0.0:6664 with no API key and accept shell commands via JSON. Update to v2.13.0 immediately.
2026.05.289 views
News
free5GC Hit by Five Critical Auth Bypass Flaws: CVE-2026-44315/26/27/29/30
InfrastructureDevelopmentSecurity
Five critical OAuth2 authorization bypass vulnerabilities (CVE-2026-44315/26/27/29/30, three at CVSS 10.0) hit the free5GC 5G core network implementation in versions up to v4.2.1. NEF and SMF API routes accept unauthenticated read/write/delete. Fixed in v4.2.2.
2026.05.2820 views
News Updated 4 days ago
TanStack and Nx Console Supply-Chain Compromise: Which Versions Are Safe Now
AIDevelopmentSecurity
Two CISA KEV-listed npm and VS Code supply-chain breaches in May 2026 turned out to be one connected attack. CVE-2026-45321 hit 84 versions across 42 @tanstack/* packages on May 11; stolen GitHub credentials from that leak then powered CVE-2026-48027, the malicious Nx Console v18.95.0 push on May 18.
2026.05.2839 views
News
LibVNCClient Flaw CVE-2026-44988: Malicious VNC Server Can Hijack Your PC On Connect
SecurityDevelopmentLinux
CVE-2026-44988 (CVSS 8.8) hits LibVNCClient v0.9.15 and earlier. A malicious VNC server can send crafted framebuffer-update rectangles to overwrite memory on the connecting client, leading to potential RCE. Remmina, KRDC, ZoneMinder and other downstream projects are affected. No tagged release with the fix has shipped yet.
2026.05.2820 views
News
IBM Aspera Hit by Two asperahttpd Buffer Overflows: CVE-2026-8175 / CVE-2026-8179
SecurityInfrastructure
IBM disclosed two critical buffer overflow vulnerabilities in Aspera High-Speed Transfer Server and Endpoint on May 21, 2026: CVE-2026-8175 (heap BOF, CVSS 9.8, unauthenticated) and CVE-2026-8179 (stack BOF, CVSS 8.8, authenticated). Used by broadcasters, media, and large enterprises worldwide.
2026.05.2849 views
News
Critical Langflow Flaw CVE-2026-7524: TAR Symlinks Leak JWT Secret, Chain to RCE
SecurityDevelopmentAI
IBM disclosed CVE-2026-7524 (CVSS 9.8) in Langflow OSS on May 27, 2026. Versions 1.0.0 through 1.9.1 are vulnerable: a crafted tar with symlinks can steal the JWT secret, forge tokens, then chain to RCE via Python Interpreter nodes. Update to v1.9.2 or later immediately.
2026.05.2823 views
Lab
CISA KEV Dashboard in Japanese — Browse the Actively Exploited Catalog
InfrastructureSecurity
Browse CISA's Known Exploited Vulnerabilities catalog (1,603 entries) in a Japanese-localized dashboard: full-text search, vendor filtering, Japan-market vendor filter, and ransomware-related extraction. Free, browser-only, no signup. Each CVE deep-links to NVD and our incident articles.
2026.05.2715 views
Lab
OSS Supply Chain Scanner — paste package.json, requirements.txt, pyproject.toml
SecurityDevelopment
Paste a package.json, requirements.txt, or pyproject.toml and instantly check your dependencies against OSV.dev's vulnerability database. Free, browser-only, no signup. Supports npm, pip, Poetry, uv, and Rye. Built as a hub for our axios, LiteLLM, Trivy, and GlassWorm supply chain coverage.
2026.05.2722 views
News Updated 4 days ago
WordPress WPCode code-injection flaw, safe on 2.3.6 and later (CVE-2026-8832)
Global CompaniesDevelopmentSecurity
A code injection flaw (CVE-2026-8832, CVSS 8.8) has been disclosed in WPCode, a WordPress code-snippet management plugin installed on over 3 million sites. The flaw lets any user with Author-level access or higher run arbitrary code on the server. The vendor released v2.3.6 on May 26, 2026; Wordfence published the advisory on May 27.
2026.05.2711 views
News
IBM WebSphere vulnerability roundup: CVE-2026-8633 and the latest July additions
Global CompaniesSecurityInfrastructure
A continuously updated roundup of critical IBM WebSphere-family vulnerabilities. The most severe is CVE-2026-8633 (CVSS 9.8), an unauthenticated server takeover. On top of June's four RCE flaws, June 30 – July 1, 2026 added three admin-console XSS issues (CVE-2026-11708 and others) and a Liberty SSRF, with a version-by-patch table to prioritize fixes.
2026.05.2773 views
News Updated 4 days ago
LiteSpeed cPanel plugin: two takeover bugs, fully fixed only in v2.4.8+
InfrastructureSecurityGlobal Companies
CVE-2026-48172, a CVSS 10 privilege escalation flaw in the LiteSpeed User-End cPanel plugin, is being actively exploited in 2026. Any cPanel user (including a compromised tenant on shared hosting) can run arbitrary scripts as root. CISA added it to the Known Exploited Vulnerabilities catalog. Mirai botnet variants and a ransomware strain are reportedly being dropped via the bug. Patch to plugin v2.4.7 or WHM plugin v5.3.1.0 immediately.
2026.05.2720 views
Column
The Day Google Summons Back the "Obscure Personal Blog": Beyond AI Article Fatigue
DevelopmentFreelance
The "obscure personal blogs" that Google's Helpful Content Update killed in 2023 are being summoned back by the March and May 2026 Core Updates. A field report on E-E-A-T's "Experience" axis, AI-article fatigue, and the strange world of a blog where Bing slightly outranks Google.
2026.05.2618 views