News
Popular AI Agent UI 'Hermes WebUI' Server-Takeover Flaw CVE-2026-58123 — No Password Needed, Plus API-Key Theft; Update Now
SecurityAIDevelopment
A flaw (CVE-2026-58123, severity 9.8) in the popular tool Hermes WebUI—which runs your own AI agent from a browser (15,000+ GitHub stars)—lets attackers take over the server with no password. A second flaw, CVE-2026-58122, strips out paid LLM API keys and messaging credentials. Fixes are out for both, and updating to the latest stops them. We explain the scope and the fix.
2026.07.1050 views
News
Ricoh Printers and MFPs Can Be Used as a Stepping Stone Into Your Network (CVE-2026-63226) — Update the Firmware if SSH Is On
SecurityJapanese Companies
A flaw in Ricoh printers and multifunction machines could let attackers use them as a passageway into a company's internal network. Only devices with the SSH remote-maintenance connection enabled are affected; if ignored, attacks can be relayed to other PCs and servers. Severity is medium, no exploitation has been reported, and updating the firmware fixes it.
2026.07.2316 views
News
Plane Bug CVE-2026-46558 Lets Any Logged-In User Read and Delete Other Teams' Files — Update to v1.3.1
SecurityDevelopment
A flaw in the open-source project management tool Plane (CVE-2026-46558) lets any logged-in user read, overwrite, and delete files belonging to other teams. Companies self-hosting Plane must update to the fixed v1.3.1. A separate flaw leaking member emails even before login was patched at the same time.
2026.07.2214 views
News
SolarWinds Serv-U: 15 flaws fixed in 2026.3 (CVE-2026-28302 et al.)
SecurityInfrastructure
SolarWinds Serv-U, used for enterprise file transfer, has 14 flaws rated 9.1 disclosed at once (CVE-2026-28302 et al.). An admin-privileged user can read/write files beyond limits and reach privileged code execution (server takeover), with larger impact on Linux/Unix. Affected: 15.5.4 HF1 and earlier; update to the latest hotfix.
2026.07.2216 views
News
Pre-Login Takeover Flaw in Linux Remote Desktop 'xrdp': 10 Flaws Fixed at Once (CVE-2026-41252), Update to 0.10.6.1
LinuxSecurity
xrdp, the popular software that accepts Windows Remote Desktop connections to Linux, has a worst-tier flaw exploitable without a password. A malicious relay destination alone can lead to remote takeover, and version 0.10.6.1 fixes 10 flaws at once. Here is who is affected and how to update on each Linux.
2026.07.2113 views
News
Takeover-enabling flaws in the popular self-hosted AI agent OpenClaw, plus no-login impersonation in its checker: CVE-2026-62241 and 9 more — update now
AISecurity
A wave of vulnerabilities has hit OpenClaw, the popular self-hosted AI agent used worldwide, letting people do things they shouldn't. Its companion security-checking tool has a critical (9.1) flaw allowing user impersonation with no login. Fixed versions are out: update OpenClaw to 2026.6.9+ and the checker to 0.7.5+. Here are the affected products and how to fix them.
2026.07.1714 views
News
IntelliJ IDEA: 10.0 Remote Development hijack flaws (CVE-2026-64812) — update to 2026.2
SecurityDevelopment
IntelliJ IDEA has a critical flaw (CVE-2026-59792, severity 9.6): opening a crafted project runs attacker code on your machine. All versions before 2026.1.4 and 2026.2 are affected. Update now.
2026.07.1159 views
Lab
Claude Desktop Comes to Linux: Cowork Runs a Real VM Inside Your PC
DevelopmentLinuxAI
Claude's desktop app now runs on Linux (Ubuntu/Debian). Cowork boots a VM inside your own PC, but Linux trips over a 'kvm' permission. Here's why, and the fix.
2026.07.0394 views
Lab
Python 3.15: Fix the locale.getdefaultlocale Deprecation, Plus Lazy Imports and What Breaks
Development
Hit the "'locale.getdefaultlocale' is deprecated and slated for removal in Python 3.15" warning? Swap it for getlocale()/getencoding() — the replacement code is inside. Plus the rest of 3.15, benchmarked on the beta: lazy imports (~4x faster startup), UTF-8 by default, and the APIs that stop working when you upgrade.
2026.06.1749 views
News
Claude Fable 5 is back after 19 days as US export controls lift
Lawsuits & RegulationGlobal CompaniesAI
Three days after launch, Anthropic disabled Claude Fable 5 and Mythos 5 worldwide to comply with a US Commerce Department export-control directive targeting foreign nationals. Users and companies in Japan are caught in the cutoff too.
2026.06.1321 views
News
axios Proxy Vulnerabilities: You're Safe on 1.18.1 or Later (0.33.0 on the Old Line)
InfrastructureDevelopmentSecurity
axios, the HTTP client used by apps worldwide, has two flaws: an SSRF that leaks cloud credentials (CVE-2026-44492) and a prototype-pollution gadget that escalates to a full man-in-the-middle (CVE-2026-44494). Fixed in 1.16.0+ (0.32.0 on the old line), latest is 1.17.0. Old versions often hide as transitive dependencies, so check with npm ls axios and update.
2026.06.1219 views
News
GitLab Vulnerability Roundup: Self-Managed Servers Should Be on 19.1.2 or Later
DevelopmentInfrastructureSecurity
On June 24, 2026, GitLab fixed 14 more vulnerabilities at once, including a flaw that lets a developer run malicious code in another user's screen and one that leaks information from its AI feature. Companies running GitLab on their own servers should update now to the latest releases (19.1.1 / 19.0.3 / 18.11.6). GitLab.com users are already covered.
2026.06.1114 views