Get a Demo
Under Attack?
Stay ahead of the threat curve.

Get expert help, fast.

If you’re dealing with a potential compromise or active threat, our MDR team can help assess and respond.

Keep an eye on your inbox we will reach out immediately

Keep an eye on your phone we will reach out immediately

Security Feed

See the latest insights and analysis from our MDR team.
RSS for Slack
CVE-2026-47698, CVE-2026-47686, GHSA-m5w8-4gq2-6f8x, GHSA-v836-6xw4-9cx3, CVE-2026-47683
By Ido Mizrahi | 
18 August 2026

vm2 multiple sandbox escapes enable arbitrary host command execution

in vm2 `

CVE-2026-64849
By Yogev Levi | 
18 August 2026

MLflow webhook test endpoint redirect bypass enables unauthenticated SSRF to internal services

mlflow < 3.15.0 allows unauthenticated SSRF via POST /api/2.0/mlflow/webhooks/{id}/test. _validate_webhook_url() validates only the initial URL, but mlflow/webhooks/delivery.py follows redirects and re-resolves hostnames (incl. DNS rebinding), enabling access to internal/cloud metadata endpoints and returning response_status and response_body. Upgrade to 3.15.0.

CVE-2026-19478
By Omer Idel | 
17 August 2026

GitLab CE/EE GraphQL directive code injection enables unauthenticated modification or deletion

GitLab CE/EE contains a CWE-94 code injection flaw where a crafted GraphQL directive can let an unauthenticated attacker remotely modify or delete public projects and user data. Affects 18.2 < 18.11.11, 19.0 < 19.0.8, 19.1 < 19.1.6, 19.2 < 19.2.4. Remediate by upgrading to 18.11.11, 19.0.8, 19.1.6, or 19.2.4.

CVE-2026-18428
By Yogev Levi | 
17 August 2026

OpenSearch SQL plugin async direct query handler allows SQL denylist bypass

OpenSearch SQL Plugin Flint extension async query handler validates SQL with insufficient restrictions, letting users with async query access bypass the SQL grammar deny list via the direct query endpoint. Affects open-source v2.13-v3.6 (fixed 3.7 and 2.19.6). Amazon OpenSearch Service v2.13-v3.5 is fixed via service software update

CVE-2026-59310
By Yogev Levi | 
17 August 2026

VMware vCenter Syslog server directory traversal enables remote code execution

VMware vCenter Syslog server has a directory traversal flaw that can be exploited by a network attacker to execute arbitrary code. Affects vCenter 9.1.x (

CVE-2026-74578
By Roy Kalfon | 
17 August 2026

Linux kernel AF_ALG skcipher async IV race allows keystream reuse and plaintext recovery

Linux kernel crypto/algif_skcipher async skcipher_recvmsg() passes ctx->iv into in-flight requests; after io_submit() unlock, concurrent sendmsg(ALG_SET_IV) can overwrite the IV. In CTR/stream modes this enables IV/keystream reuse and plaintext recovery by unprivileged users. Fix: remove AIO branch/force sync. Debian: bullseye fixed 5.10.262-1, bookworm 6.1.180-1, trixie 6.12.101-1.

See More

Secure the new Era of AI & Realtime

Get a Demo
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Threat RSS
Add the Upwind RSS Feed to Slack
Connect the Upwind RSS Feed to your Slack.
Follow the how-to here.
Main RSS