Supply Chain Security GitPython 3.1.54 fixes three option-injection paths to RCE and file overwrite
CVE-2026-73623–73625 bypass option controls through templates, diff output and kwarg value smuggling. We examine the fixes and CI exposure.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Supply Chain Security CVE-2026-73623–73625 bypass option controls through templates, diff output and kwarg value smuggling. We examine the fixes and CI exposure.
AI Security Missing file_path validation in confluence_upload_attachment exposes every server-readable file. Prompt injection can activate the vulnerable flow.
Vulnerabilities and CVEs PostgreSQL 18.6, 17.11, 16.15, 15.19 and 14.24 address 28 vulnerabilities. We map the highest-risk classes and a safe update plan.
Supply Chain Security OIDC client flaws allowed discovery redirects, verifier-cache poisoning and ServiceAccount token disclosure. Fulcio 1.8.6 fixes all three paths.
Supply Chain Security The archived cloudflare/pages-action is vulnerable in every release and will not be patched. Migration to wrangler-action also requires tighter tokens.
Vulnerabilities and CVEs An authentication flaw allows remote GUI or CLI access without a valid account. We map affected branches, immediate controls and investigation steps.
Cloud, Infrastructure and DevSecOps A legacy gcp auth-provider cmd-path bypassed the existing exec check. A malicious Kubernetes configuration could launch a process on a shared worker.
AI Security Image and Audio parsing performed I/O during coercion. A malicious model could name a local path and send its contents to an LLM endpoint.
Vulnerabilities and CVEs The official MSRC release contains 790 CVE records. An exploited AFD flaw leads the queue, but SharePoint, Office, Azure and active roles also need review.
Supply Chain Security A 32-bit integer wrap corrupts the shared CSPRNG pool offset. Later IDs can become a constant string, so updating alone may not complete the response.
Cloud, Infrastructure and DevSecOps A 35-CVE wave covers command injection, cross-tenant access and authorization flaws. Here is the scope, the 0.29.13 fixes and a safe response plan.
Supply Chain Security A small HDF5 file can declare petabytes of data and stop load_model(). We examine the patch, model supply-chain risk and layered defensive controls.
Vulnerabilities and CVEs Missing authentication and path traversal can enable remote code execution and command submission. We separate the confirmed facts from operational risk.
Vulnerabilities and CVEs InfiniteWP Client before 1.13.6 allowed an attacker-controlled key to be bound and a WordPress Multisite administrator session hijacked. Here is the impact and response.
AI Security Encoded directory sequences bypassed Starlette normalisation before pathlib escaped the UI directory. LoLLMs releases before version 3 require an update.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-paced learning.