News
AI Component Guardrails AI Hit by a Poisoned Package: CVE-2026-45758, TeamPCP's New Target
AISecurity
The PyPI distribution of Guardrails AI, a popular OSS component for validating LLM I/O, was laced with a credential-stealing poisoned version 0.10.1. Tracked as CVE-2026-45758 (CVSS 9.6), it is part of a chain of supply-chain attacks by TeamPCP that spread 400+ poisoned versions across 170+ packages including TanStack and Mistral AI, expanding into AI development. Here are the safe versions and the steps to check and respond.
2026.06.0663 views
News
Markdown Preview Enhanced Vulnerabilities: All Fixed as of 0.8.30, Update If Older
SecurityDevelopment
In Markdown Preview Enhanced, the popular VS Code extension, opening and previewing a malicious Markdown file can run code on your PC (CVE-2026-49492/49493/50733). Update to 0.8.28.
2026.06.0675 views
News
SolarWinds Serv-U Flaw Lets Attackers Crash the Service: CVE-2026-28318, Now Exploited
SecurityInfrastructure
A flaw in the enterprise file-transfer server SolarWinds Serv-U lets attackers crash the service by sending a crafted request without authentication. Tracked as CVE-2026-28318 (CVSS 7.5), CISA added it to KEV on June 5, 2026 as actively exploited and ordered federal agencies to fix it by June 19. Here are the affected versions, the 15.5.4-hotfix-1 fix, and what to do now.
2026.06.0677 views
News
7-Zip Take-Over Flaws Fixed in 26.02: Affected Versions and How to Update
SecurityDevelopment
A flaw in the free 7-Zip compressor lets a crafted file take over a PC just by being opened. Tracked as CVE-2026-48095 (CVSS 8.8), it affects version 26.00 and earlier and can trigger even from files disguised as .zip or .rar. 7-Zip has no auto-update and PoC code is public. Here are the affected versions, update steps, and what to do now.
2026.06.0654 views
News
Tapo D100C, L535E and P300 Leak Setup Data Over Bluetooth (CVE-2026-34126) — Update Now
PrivacySecurity
TP-Link's Tapo smart-home devices — the D100C doorbell chime, L535E bulb, and P300 power strip — leak their initial-setup Bluetooth communication in cleartext, letting someone nearby intercept it or hijack the device (CVE-2026-34126). Fixed firmware is out; here is how to check and update affected models and what to do if already set up.
2026.06.0573 views
News
Unauthenticated Takeover in Label Software BarTender (CVE-2026-25550): Legacy 2010/2016/2019 at Risk
SecurityInfrastructure
BarTender, the label and barcode printing software widely used in factories, warehouses and logistics, has a 9.8-severity flaw (CVE-2026-25550) in its legacy 2010/2016/2019 versions. An attacker can take over the PC remotely with no login and run code at the highest privilege. Block the service and migrate.
2026.06.0547 views
News
Tautulli Vulnerabilities: v2.17.2 Is the Minimum Safe Version
InfrastructureDevelopmentSecurity
Tautulli, the popular dashboard that tracks viewing on the Plex media server, has five vulnerabilities including a 9.9-severity flaw. Some paths work without logging in, and chained together they lead to admin-panel takeover or code execution on your server. Update to v2.17.1.
2026.06.0566 views
News
Critical Takeover Flaw in OpenStack Mistral: CVE-2026-41283 Lets Any Logged-In User Run Code
DevelopmentSecurityInfrastructure
CVE-2026-41283: a 9.9-severity flaw in OpenStack Mistral lets any logged-in user run arbitrary code and steal cloud-wide service credentials. Patch now.
2026.06.0458 views
News
Magento Mirasvit Cache Warmer Takeover Flaw, Fixed in 1.11.12+
DevelopmentInfrastructureSecurity
A Magento extension used by online stores worldwide has a critical flaw (CVE-2026-45247, CVSS 9.8) that lets attackers take over servers without logging in. Real attacks have already begun, risking theft of shoppers' credit card data. Affected stores must update to 1.11.12 now.
2026.06.0417 views
News
Apache MINA Takeover Flaw: The Safe Versions Are 2.2.8, 2.1.15, and 2.0.31
SecurityDevelopmentInfrastructure
Apache MINA, the Java networking library behind many server apps, has a critical flaw (CVE-2026-47065, CVSS 9.8) that lets attackers take over servers without logging in. It is the third bypass of earlier fixes—update to 2.2.8, 2.1.13, or 2.0.29 now.
2026.06.0346 views
News
authentik Identity Platform: 4 Flaws, and the Releases That Fix Them
InfrastructureGlobal CompaniesSecurity
Four serious vulnerabilities have been found in authentik, the identity platform widely used for single sign-on. The worst lets an unauthenticated attacker skip an authentication step by sending empty data and log in as someone else (CVE-2026-49448, CVSS 9.8). Here are the affected versions, the patched releases to update to now, and how to check.
2026.06.0349 views
News
Linux container escape flaw explained: safe on kernel 5.17 and later
InfrastructureSecurityLinux
Linux cgroups v1 flaw CVE-2022-0492 is being exploited and CISA added it to KEV. A missing permission check on release_agent enables container escape and privilege escalation. Escape needs conditions like privileged containers. Update to kernel 5.17+ and harden.
2026.06.0371 views