Vulnerabilities and CVEs ash_typescript 0.18.0 fixes seven CVEs across RPC and generated clients
Two BEAM atom-table exhaustion paths, denied-field disclosure, missing constraints and URL bugs expose risks at the Elixir–TypeScript boundary.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs Two BEAM atom-table exhaustion paths, denied-field disclosure, missing constraints and URL bugs expose risks at the Elixir–TypeScript boundary.
Cloud, Infrastructure and DevSecOps OS command injection in Plesk for Linux lets a customer or reseller with shell access become root. Fixes are in 18.0.79.9 and 18.0.80.5.
Supply Chain Security A scoped path-traversal package name let pnpm overwrite arbitrary files even with --ignore-scripts. Fixes are available in 10.34.5 and 11.11.0.
Vulnerabilities and CVEs WPLP Cookie Consent for WordPress allowed authorization bypass and arbitrary file upload. Versions through 4.4.1 need an urgent update to 4.4.2.
AI Security Six ash_ai vulnerabilities show why agent security spans the entire runtime: prompt rendering, record filters, error handling, MCP and tool-loop progress.
AI Security Missing workspace containment in Agent Mode file tools let model-supplied paths reach files available to the Theia backend. Version 1.75.0 fixes it.
Vulnerabilities and CVEs A weak 32-bit connect token let a guest trigger plugin installation and activation from a chosen URL. ProfilePress 4.17.2 contains the fix.
Vulnerabilities and CVEs Missing authorization in send_link() and improper token validation in activate() can expose an unconfirmed WordPress account, including an administrator account.
Identity and Access An Erlang OIDC library accepted a JWE carrying attacker-authored claims without a nested signature. Here is why encryption is not sender authentication.
Supply Chain Security CVE-2026-82417 and CVE-2026-82562 show how a hostile object shape and commas under a[] can violate parser assumptions, causing exceptions or memory pressure.
Cloud, Infrastructure and DevSecOps A certificate-validation flaw lets an on-path attacker capture vCenter administrator credentials during routine CPI calls.
AI Security CVE-2026-19286 and CVE-2026-19295 show how a public agent, type evaluation and inconsistent authorization can compromise an AI platform server.
Cloud, Infrastructure and DevSecOps CVE-2026-81490, 81517, 81518 and 81520 show how a SQL-to-MongoDB bridge can expose data or lose availability before authentication completes.
Threats and Incidents A technical analysis of the GRU-linked campaign: backdoored installers, OpenSSH/Tor tunnels, smart-contract infrastructure and Android data theft.
Cloud, Infrastructure and DevSecOps CVE-2025-30156, CVE-2026-39944, CVE-2026-50152 and CVE-2026-54330 show how encryption without integrity and inconsistent authorization lead to cluster compromise.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.
We turn current threats into role-based training, safe exercises and a clear reporting path. The free Academy remains available for self-paced learning.