News Updated 7 days ago
SGLang CVE-2026-5760 and 3 more RCE flaws hit AI inference server (3 unpatched)
InfrastructureSecurityAI
Four critical RCE vulnerabilities disclosed in SGLang, the AI inference server used by xAI, AMD, NVIDIA, and major cloud providers. CVSS 9.8, no auth required, three remain unpatched as of May 26, 2026. JPCERT/CC issued an advisory.
2026.05.2639 views
News Updated 4 days ago
NEC Aterm Router Vulnerabilities: Fixed Firmware Versions for All 11 Affected Models
InfrastructureSecurityJapanese Companies
NEC Platforms disclosed two more vulnerabilities in its Aterm router line on May 25, 2026 — a cross-site scripting flaw across nine popular Wi-Fi 6/6E/7 home models and an OS command injection in two business-grade LTE routers. The advisories follow a much larger March 2026 disclosure that affected 21 models and included an undocumented telnet backdoor.
2026.05.2528 views
News Updated 4 days ago
Drupal Core Flaw Lets Anyone Hijack PostgreSQL Sites Without a Login
InfrastructureSecurityDevelopment
The U.S. CISA gave federal agencies just five days to patch CVE-2026-9082, a highly critical SQL injection in Drupal core that lets anonymous attackers take over PostgreSQL-backed sites. Imperva already counts 15,000 attack attempts against 6,000 sites across 65 countries, including Drupal-powered government and university portals in Japan.
2026.05.2332 views
News
UniFi hit by 15 flaws at once: cameras, door locks, routers, CVE-2026-50746
InfrastructureSecurity
On July 2, 2026, networking brand UniFi disclosed 15 new vulnerabilities. Security cameras, door-access control, and routers are all in scope, and 6 can be exploited with no login. Earlier holes are already used in real attacks; we lay out the fixed version per product and the update steps to do first.
2026.05.22141 views
News
Langflow CVE-2025-34291: visiting a web page can hijack your AI agent stack
SecurityDevelopmentAI
A CVSS 9.4 flaw has been found in Langflow, the popular AI agent OSS, and CISA has added it to the Known Exploited Vulnerabilities catalog. Visiting a malicious web page is enough to steal a user's session and hijack the entire AI agent stack, including configured OpenAI and Anthropic API keys. A fix is available in version 1.9.3.
2026.05.2222 views
News Updated 4 days ago
IINA Vulnerability Explained: Update to 1.4.4, the 1.4.3 Fix Was Incomplete
DevelopmentSecurityLinux
A critical CVSS 8.8 vulnerability has been found in IINA, the popular open-source video player for Mac. Just clicking a malicious link and approving the open prompt lets attackers run arbitrary commands on your Mac. Used by 44K+ GitHub stargazers, the project has shipped a fix in version 1.4.3 and immediate updates are advised.
2026.05.2255 views
News
Apex One Hit by 14 Vulnerabilities; Console Hijack Could Reach All Company PCs
InfrastructureSecurityJapanese Companies
Trend Micro has disclosed 14 vulnerabilities in its enterprise antivirus Apex One. Two of them are rated at the maximum severity tier, letting attackers hijack the management console without login and push malware to every PC in the company. With past zero-day exploitation on record, immediate patching is advised.
2026.05.2238 views
News Updated 4 days ago
GUARDIANWALL MailSuite Vulnerability: Affected Versions and How to Respond
SecurityInfrastructureJapanese Companies
A critical CVSS 9.8 vulnerability in Canon ITS's GUARDIANWALL MailSuite lets attackers run code without login. Used by 4,000+ Japanese organizations (5.8M users), exploitation is already confirmed. Here is how to identify your edition and apply the patch.
2026.05.2119 views
News
Japan's Joh-Pla Act: 5 Platforms on a 7-Day Deletion Clock
Global CompaniesPrivacyLawsuits & Regulation
Japan's Joh-Pla Act (in force since April 2025) makes Google, Meta, X, TikTok and LINE Yahoo decide on defamation-deletion requests within 7 days. Corporate fines reach 100M yen. A year in, what changed?
2026.05.1930 views
News
Docomo phones won't connect: morning outage reports, carrier says "not equipment failure"
InfrastructureMobileJapanese Companies
NTT Docomo acknowledged on the morning of May 19 that social-media complaints about mobile service difficulties have been increasing. Users report being out of service since before 4 a.m. and unable to connect for more than eight hours. Docomo says no equipment failure has been confirmed and is still investigating as of 11:30 a.m. Cause and recovery timeline are unknown.
2026.05.19114 views
News
NGINX Rift (CVE-2026-42945): Affected versions, how to check, and workaround
InfrastructureSecurity
A critical 18-year-old vulnerability (CVE-2026-42945, codenamed NGINX Rift, CVSS 9.2) has been disclosed in the NGINX rewrite module. Unauthenticated remote code execution is possible and a PoC is public. This article covers affected products, how to check your environment, the patch procedure, and a workaround.
2026.05.15249 views
News Updated 4 days ago
Linux Kernel 'Fragnesia' Vulnerability (CVE-2026-46300): Which Versions Are Safe and How to Patch
LinuxSecurityInfrastructure
A new Linux kernel privilege escalation "Fragnesia" (CVE-2026-46300) was disclosed on May 13 — the third root-takeover bug in three weeks after Copy Fail and Dirty Frag. We explain the structural pattern of XFRM/ESP's aging design and a five-layer mitigation frame for operators.
2026.05.1458 views