» Tag
security
437 postsAuthenticated RCE Exploits Hit Redis via Stream, TDigest, TopK Bugs
Authenticated RCE chain hits Redis 6.2.22 through 8.8.1 via stream NACK double-free, TDigest and TopK module bugs, bypassing two prior CVE patches.
RefluXFS: XFS reflink race lets Linux users escalate to root (CVE-2026-64600)
Qualys details RefluXFS (CVE-2026-64600), an XFS reflink race enabling local privilege escalation to root on default RHEL, Rocky, and Fedora Server installs.
Source review of 200 self-hosted AI tools finds 78 leak tenant data
A source review of 200+ self-hosted multi-tenant AI/SaaS tools found 78 with cross-tenant data leaks via unguarded read endpoints, 31 filed as CVEs.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comNAT Slipstreaming v2.0 Bypasses NAT/Firewalls via the Browser
NAT Slipstreaming v2.0 abuses ALG connection tracking to let attackers remotely open any TCP/UDP port behind a victim's NAT via the browser.
Linux Page Cache Vulnerability via TC Pedit: A New Exploit
Discover the Linux TC Pedit page cache exploit enabling root access. Learn about the vulnerability and its fix.
Cracken Launches Blacksea, an Open-Source Honeypot for AI Attackers
Cracken releases Blacksea, an open-source honeypot that baits LLM-driven attackers into executing code on their own machines for attribution.
RubyGems CDN Caching Bug Could Leak Legacy API Keys to Other Users
A RubyGems.org CDN caching flaw could leak legacy API keys between users for up to an hour; CVSS 7.2, all legacy keys have been revoked.
Docker Desktop Bypass Lets AI Coding Agents Escape Their Sandboxes
Docker Desktop lets AI coding agents bypass strict sandboxes in Codex, Cursor, and Gemini CLI via a privileged socket and VirtioFS mount.
$13,337 Bounty: Google Device Code Flow Account Takeover Bug
Google paid a $13,337 bounty for a confused-deputy flaw in its RFC 8628 device authorization flow enabling account takeover.
AI Agent Runtime Policy: Stop Dangerous Tool Calls Before They Execute
A runtime policy layer stops AI agents from calling dangerous tools in production: risk tiers, delegation scopes, and argument validation explained.