Get expert help, fast.
Security Feed
Fastify JWT key override allows cross-domain token acceptance
@fastify/jwt `
Pandora TAR extraction path traversal allows arbitrary file write and potential RCE
Affects `pandora
Kibana missing authorization allows unprivileged response actions via Elastic Security rules
Missing authorization (CWE-862) in Kibana allows a user who can author/evaluate Elastic Security detection rules to execute Osquery live queries and Elastic Defend response actions on enrolled agents without the required privileges. Affects 8.5.0-8.19.19 and 9.0.0-9.4.4. Patch to 8.19.20 or 9.4.5.
Prowler Kubernetes provider connection test allows OS command injection via legacy GCP kubeconfig auth-provider
Prowler < 5.36.0 accepts kubeconfig_content with legacy gcp auth-provider config.cmd-path/config.cmd-args during POST /api/v1/providers/{id}/connection. Because kubeconfig_contains_exec_auth checks only exec blocks, config.load_kube_config_from_dict triggers kubernetes-python CommandTokenSource.token to run attacker commands via subprocess.Popen on the shared worker. Upgrade to 5.36.0.
Windows DNS stack-based buffer overflow enables unauthenticated network RCE
A stack-based buffer overflow (CWE-121) in Windows DNS allows an unauthenticated attacker to execute code over a network (CVSS:3.1 9.8 AV:N/AC:L/PR:N/UI:N). Affects Windows builds before 10.0.14393.9418 (Win10 1607/Server 2016) and 10.0.17763.9115 (Win10 1809/Server 2019). Apply the Microsoft patch per MSRC guidance.
Adobe Campaign Classic incorrect authorization allows network RCE without user interaction
Adobe Campaign Classic (ACC) has an incorrect authorization (CWE-863) flaw exploitable over the network with no privileges or user interaction, enabling arbitrary code execution as the current user (scope changed). Affects ACC v7 up to 7.4.3 build 9399; fixed in 7.4.4 build 9400. Upgrade to 7.4.4 build 9400 or later.
Deep Threat Research
Metabase Instances Actively Exploited: Unauthenticated Admin Takeover via BI Layer Reset Password SQL Injection (CVE-2026-72898)

Keyv Supply Chain Compromise: An npm Worm That Takes Its Orders From an Ethereum Smart Contract

Mastra Supply Chain Compromise: easy-day-js Dropper Pulls a Cross-Platform RAT Into @mastra Installs








