Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that frontier AI is changing the speed of that race, and the gap between discovering a vulnerability and exploiting […]
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
A vulnerability has been found in lenve vhr 1.0-SNAPSHOT and classified as critical. This issue affects some unknown processing of the component MailReceiver. Performing a manipulation results in deserialization.
This vulnerability is reported as CVE-2026-90490. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability classified as problematic was found in langbot-app LangBot up to 4.10.10. Affected is an unknown function of the component Password Recovery. Executing a manipulation can lead to insufficient entropy.
This vulnerability is registered as CVE-2026-90562. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is advised.
A vulnerability was found in LibreNMS up to 1.65.0. It has been declared as critical. This vulnerability affects unknown code of the file ajax_table.php of the component API Endpoint. Executing a manipulation of the argument searchPhrase can lead to sql injection.
This vulnerability appears as CVE-2020-15875. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
A vulnerability classified as critical has been found in FlowiseAI Flowise up to 3.1.2. This issue affects some unknown processing of the file packages/components/nodes/tools/MCP/core.ts of the component MCP Server. The manipulation leads to os command injection.
This vulnerability is referenced as CVE-2026-69263. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability has been found in FlowiseAI Flowise up to 3.1.2 and classified as critical. Affected by this vulnerability is the function validatePythonCodeForDataFrame of the component CSVAgent. The manipulation of the argument csvFile leads to os command injection.
This vulnerability is listed as CVE-2026-69264. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
A vulnerability has been found in Bestechnic BES2300 Bluetooth Audio SoC firmware up to 4.x and classified as critical. Affected by this issue is the function SBC_DecodeFrames. This manipulation causes buffer overflow.
The identification of this vulnerability is CVE-2026-79379. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.