AI Security FastGPT CVE-2026-68929: a public shareId can hijack a WeChat channel
Missing authorization in the iLink integration lets an attacker sign out a bot or bind their account to another tenant's application. FastGPT 4.15.2 fixes it.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
AI Security Missing authorization in the iLink integration lets an attacker sign out a bot or bind their account to another tenant's application. FastGPT 4.15.2 fixes it.
Vulnerabilities and CVEs Fireware OS 2026.2.2, 12.12.2 and 12.5.20 fix overflows, type confusion and double-free bugs in IKE handling plus a critical Mobile Security flaw.
Cloud, Infrastructure and DevSecOps Six CVEs cover two cluster.key leaks, worker file writes, path traversal and argument injection in Active Response, plus an agent-enrolment crash.
Identity and Access KubePi through 1.6.15 mixed public login routes with OIDC and SAML administration. Analysis of takeover, SSRF, version 2.0.0 and safe migration.
Cloud, Infrastructure and DevSecOps CVE-2026-77298, CVE-2026-77317, CVE-2026-77368 and CVE-2026-77611 show how separate data paths can bypass a shared authorization policy.
AI Security CVE-2026-47851 and CVE-2026-47852 affect document ingestion and model caching. Analysis of RAG availability, artifact integrity and Spring AI fixes.
Vulnerabilities and CVEs Tomcat 11.0.25, 10.1.58 and 9.0.121 close constraint bypasses, a fail-open Realm path, RewriteValve errors, HTTP/2 DoS and persistent WebSocket sessions.
Identity and Access OSSA-2026-037 covers CVE-2026-80182 and CVE-2026-80184: delegated tokens could extend access lifetime and cross an intended project boundary.
Identity and Access DPoPProofJwtDecoderFactory could forget a used jti after cache pressure. We explain replay preconditions, fixed versions and OAuth 2.0 monitoring.
AI Security CVE-2026-62862 and CVE-2026-62865 combine weak login codes with file exfiltration through Nodemailer. A technical review and Typebot 3.18.0 response plan.
AI Security TransitionParser used an unrestricted unpickler, then the first allowlist trusted whole modules. Analysis of RCE, versions 3.10.0 and 3.10.3, and NLP pipeline defence.
Vulnerabilities and CVEs Three Moderate and six Low issues include double free, heap overflow, DoS and skipped AEAD-tag verification. Exposure analysis and fixed releases 4.0.2–3.0.22.
Threats and Incidents An anonymous form passed sender_name into a Fluid View as template source. Analysis of active exploitation, ViewHelpers, versions 10.9.3/12.6.1/13.2.1 and response.
Vulnerabilities and CVEs An authenticated control-panel user could pass behavior/event configuration through condition.config. Analysis of Yii, versions 4.18.2 and 5.10.6, and response.
AI Security Six loaders trusted model remote code. Analysis of trust_remote_code, version 2.12.0, model-launch privileges and AI worker isolation.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.