Lab
OSS Supply Chain Scanner — paste package.json, requirements.txt, pyproject.toml
SecurityDevelopment
Paste a package.json, requirements.txt, or pyproject.toml and instantly check your dependencies against OSV.dev's vulnerability database. Free, browser-only, no signup. Supports npm, pip, Poetry, uv, and Rye. Built as a hub for our axios, LiteLLM, Trivy, and GlassWorm supply chain coverage.
2026.05.2752 views
News
WordPress WPCode code-injection flaw, safe on 2.3.6 and later (CVE-2026-8832)
Global CompaniesDevelopmentSecurity
A code injection flaw (CVE-2026-8832, CVSS 8.8) has been disclosed in WPCode, a WordPress code-snippet management plugin installed on over 3 million sites. The flaw lets any user with Author-level access or higher run arbitrary code on the server. The vendor released v2.3.6 on May 26, 2026; Wordfence published the advisory on May 27.
2026.05.2741 views
News
IBM products hit by unauthenticated takeover flaws: webMethods, HMC, App Connect, Langflow in late July
Global CompaniesSecurityInfrastructure
A continuously updated roundup of critical IBM WebSphere-family vulnerabilities. The most severe is CVE-2026-8633 (CVSS 9.8), an unauthenticated server takeover. On top of June's four RCE flaws, June 30 – July 1, 2026 added three admin-console XSS issues (CVE-2026-11708 and others) and a Liberty SSRF, with a version-by-patch table to prioritize fixes.
2026.05.27126 views
News
LiteSpeed cPanel plugin: two takeover bugs, fully fixed only in v2.4.8+
InfrastructureSecurityGlobal Companies
CVE-2026-48172, a CVSS 10 privilege escalation flaw in the LiteSpeed User-End cPanel plugin, is being actively exploited in 2026. Any cPanel user (including a compromised tenant on shared hosting) can run arbitrary scripts as root. CISA added it to the Known Exploited Vulnerabilities catalog. Mirai botnet variants and a ransomware strain are reportedly being dropped via the bug. Patch to plugin v2.4.7 or WHM plugin v5.3.1.0 immediately.
2026.05.2738 views
Column
The Day Google Summons Back the "Obscure Personal Blog": Beyond AI Article Fatigue
DevelopmentFreelance
The "obscure personal blogs" that Google's Helpful Content Update killed in 2023 are being summoned back by the March and May 2026 Core Updates. A field report on E-E-A-T's "Experience" axis, AI-article fatigue, and the strange world of a blog where Bing slightly outranks Google.
2026.05.2641 views
News
SGLang CVE-2026-5760 and 3 more RCE flaws hit AI inference server (3 unpatched)
InfrastructureSecurityAI
Four critical RCE vulnerabilities disclosed in SGLang, the AI inference server used by xAI, AMD, NVIDIA, and major cloud providers. CVSS 9.8, no auth required, three remain unpatched as of May 26, 2026. JPCERT/CC issued an advisory.
2026.05.2668 views
News
NEC Aterm Router Vulnerabilities: Fixed Firmware Versions for All 11 Affected Models
InfrastructureSecurityJapanese Companies
NEC Platforms disclosed two more vulnerabilities in its Aterm router line on May 25, 2026 — a cross-site scripting flaw across nine popular Wi-Fi 6/6E/7 home models and an OS command injection in two business-grade LTE routers. The advisories follow a much larger March 2026 disclosure that affected 21 models and included an undocumented telnet backdoor.
2026.05.2578 views
News
Drupal Core Flaw Lets Anyone Hijack PostgreSQL Sites Without a Login
InfrastructureSecurityDevelopment
The U.S. CISA gave federal agencies just five days to patch CVE-2026-9082, a highly critical SQL injection in Drupal core that lets anonymous attackers take over PostgreSQL-backed sites. Imperva already counts 15,000 attack attempts against 6,000 sites across 65 countries, including Drupal-powered government and university portals in Japan.
2026.05.2351 views
News
UniFi hit by 25 flaws at once: cameras, door locks and routers
InfrastructureSecurity
On July 2, 2026, networking brand UniFi disclosed 15 new vulnerabilities. Security cameras, door-access control, and routers are all in scope, and 6 can be exploited with no login. Earlier holes are already used in real attacks; we lay out the fixed version per product and the update steps to do first.
2026.05.22300 views
News
Langflow CVE-2025-34291: visiting a web page can hijack your AI agent stack
SecurityDevelopmentAI
A CVSS 9.4 flaw has been found in Langflow, the popular AI agent OSS, and CISA has added it to the Known Exploited Vulnerabilities catalog. Visiting a malicious web page is enough to steal a user's session and hijack the entire AI agent stack, including configured OpenAI and Anthropic API keys. A fix is available in version 1.9.3.
2026.05.2244 views
News
IINA Vulnerability Explained: Update to 1.4.4, the 1.4.3 Fix Was Incomplete
DevelopmentSecurityLinux
A critical CVSS 8.8 vulnerability has been found in IINA, the popular open-source video player for Mac. Just clicking a malicious link and approving the open prompt lets attackers run arbitrary commands on your Mac. Used by 44K+ GitHub stargazers, the project has shipped a fix in version 1.4.3 and immediate updates are advised.
2026.05.2289 views
News
Apex One Hit by 14 Vulnerabilities; Console Hijack Could Reach All Company PCs
InfrastructureSecurityJapanese Companies
Trend Micro has disclosed 14 vulnerabilities in its enterprise antivirus Apex One. Two of them are rated at the maximum severity tier, letting attackers hijack the management console without login and push malware to every PC in the company. With past zero-day exploitation on record, immediate patching is advised.
2026.05.2264 views