Live Threat Intelligence Feed Kategorie #9
Reverse Engineering

Reverse Engineering

Binary Analysis, Disassembly & Reverse Engineering. Technische Anleitungen zu Ghidra, IDA Pro, Malware Decompilation und Firmware-Untersuchungen.

Sichere ProgrammierungRate Limiting: The Traffic Cop Your API Needs(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungI Built the MVP First. Then I Wrote the README.(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungHow to add a loading screen with a progress bar in Godot 4(20.09.2026 um 14:52 Uhr)
Sichere ProgrammierungCanada is about to break your scheduler(20.09.2026 um 14:59 Uhr)
Sichere ProgrammierungWhat Does an AI Automation Agency Actually Do?(20.09.2026 um 15:00 Uhr)
Sichere ProgrammierungRate Limiting: The Traffic Cop Your API Needs(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungI Built the MVP First. Then I Wrote the README.(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungHow to add a loading screen with a progress bar in Godot 4(20.09.2026 um 14:52 Uhr)
Sichere ProgrammierungCanada is about to break your scheduler(20.09.2026 um 14:59 Uhr)
Sichere ProgrammierungWhat Does an AI Automation Agency Actually Do?(20.09.2026 um 15:00 Uhr)
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence

Reverse Engineering

Sicherheitslücken (CVE) DEV Community
AI Didn't Hack OpenAI. A Missed Debian Backport and an SSO Misconfiguration Did

The headline that circulated this week sounds like a movie trailer: hackers breached OpenAI's internal codebase in 72 hours, and an AI model wrote…

vor 10 Std. 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) DEV Community
Your AI Agent Should Be a Guest, Not a Tenant

Why standing credentials are the quiet root cause behind this week's agent security headlines, and what zero standing privilege looks like in…

vor 12 Std. 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) DEV Community
StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento

StyleSmuggler: How a Payment Failure Email Became a Remote Code Execution Path in Magento A storefront can pass every routine security check and…

vor 18 Std. 1 Min
+1
Weiterlesen ↗
Sicherheitslücken (CVE) DEV Community
Poisoning the Context: Securing RAG Pipelines Against Knowledge Injection Attacks

Originally published on tamiz.pro. The Silent Vulnerability in Retrieval-Augmented Generation Retrieval-Augmented Generation (RAG) has become the de…

vor 19 Std. 1 Min
0
Weiterlesen ↗
Reverse Engineering Reverse Engineering
New weekly CTF challenge is now live. Ranking is based on solve order.

submitted by /u/Electronic-Part6194 [link] [comments]

vor 23 Std. 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90601 | getzep graphiti up to 0.30.2 REST API main.py improper authentication (Issue 1716)

A vulnerability labeled as critical has been found in getzep graphiti up to 0.30.2.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90710 | taisan tarzan-cms 1.0.0 Theme Download Function ThemeService.java openConnection httpUrl server-side request forgery (IK768M)

A vulnerability categorized as critical has been discovered in taisan tarzan-cms 1.0.0.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90690 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 API Tools Endpoint hexstrike_server.py subprocess.Popen os command injection (Issue 224)

A vulnerability categorized as critical has been discovered in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90619 | 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04 Execute Endpoint hexstrike_server.py code/script os command injection (Issue 222)

A vulnerability classified as critical has been found in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90603 | Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0 S3 Upload /api/upload-binary x-proxy-target-url unrestricted upload (Issue 310)

A vulnerability described as critical has been identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90580 | FlowiseAI Flowise up to 3.0.2 Evaluations Endpoint index.ts axios.post Host/X-Forwarded-Proto server-side request forgery (Issue 6687)

A vulnerability was found in FlowiseAI Flowise up to 3.0.2. It has been declared as critical. This vulnerability affects the function axios.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) DEV Community
Rotating Secrets After an AI-Tooling Compromise: A Checklist for the September 2026 KEV Wave

Rotating Secrets After an AI-Tooling Compromise: A Checklist for the September 2026 KEV Wave Three of the seven vulnerabilities CISA added to its…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Feed: Artificial Intelligen…
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening

AI labs are toying with an industry-wide pact to slow development.

🛡️ Security Fix
vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90533 | FlowiseAI Flowise up to 3.1.3 /api/v1/organizationuser access control

A vulnerability marked as problematic has been reported in FlowiseAI Flowise up to 3.1.3.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90535 | FlowiseAI Flowise up to 3.1.3 Text To Speech Abort abort chatflowId/chatId denial of service

A vulnerability categorized as problematic has been discovered in FlowiseAI Flowise up to 3.1.3.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-67211 | Apache OpenNLP up to 3.0.0-M5 opennlp-spellcheck extension SymSpellModelSerializer.create unigramCount/bigramCount allocation of resources

A vulnerability, which was classified as problematic, has been found in Apache OpenNLP up to 3.0.0-M5.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-90534 | FlowiseAI Flowise up to 3.1.3 Credential Resolution /api/v1/node-load-method getCredentialData nodeName permission

A vulnerability was found in FlowiseAI Flowise up to 3.1.3. It has been rated as critical.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-89332 | AWS Kiro IDE up to 0.8.134 Kiro Powers redirect

A vulnerability identified as problematic has been detected in AWS Kiro IDE up to 0.8.134.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-79394 | XiongMai Sofia IPC daemon up to 0608.1837 RTSP Server access control

A vulnerability described as problematic has been identified in XiongMai Sofia IPC daemon up to 0608.1837.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-91847 | Online Scheduling and Appointment Booking System Plugin authorization (EUVD-2026-83509)

A vulnerability was found in Online Scheduling and Appointment Booking System Plugin up to 28.1 on WordPress and classified as critical.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-92421 | Hydra Booking Plugin up to 1.2.2 on WordPress authorization (EUVD-2026-83514)

A vulnerability was found in Hydra Booking Plugin up to 1.2.2 on WordPress. It has been rated as critical.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-92420 | Hydra Booking Plugin up to 1.2.1 on WordPress authorization (EUVD-2026-83513)

A vulnerability was found in Hydra Booking Plugin up to 1.2.1 on WordPress. It has been declared as problematic. Affected is an unknown function.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-92425 | Hydra Booking Plugin up to 1.2.3 on WordPress authorization (EUVD-2026-83515)

A vulnerability marked as problematic has been reported in Hydra Booking Plugin up to 1.2.3 on WordPress.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-92435 | WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress Permission Callback authorization (EUVD-2026-83517)

A vulnerability marked as critical has been reported in WooCommerce Mailchimp for WooCommerce Plugin up to 6.1.0 on WordPress.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-52098 | FlowiseAI Flowise 3.1.2 /api/v1/prediction code injection

A vulnerability, which was classified as critical, was found in FlowiseAI Flowise 3.1.2.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Cyber Security News
Click2Shell WordPress Flaw Lets Attackers Gain RCE With a Single Malicious Link

WordPress administrators are being urged to update after researchers disclosed Click2Shell, an exploit chain that can turn one malicious link into…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-85170 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 Mail Composer server-side request forgery

A vulnerability categorized as critical has been discovered in n8n-io n8n. Impacted is an unknown function of the component Mail Composer.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-85169 | n8n-io n8n prior 1.123.73/2.35.4/2.36.2 $fromAI handler sandbox

A vulnerability described as critical has been identified in n8n-io n8n.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2025-27771 | uptrain-ai UpTrain up to 0.7.1 add_prompts checks/metadata code injection (EUVD-2025-210735)

A vulnerability labeled as critical has been found in uptrain-ai UpTrain up to 0.7.1. This affects an unknown part of the component add_prompts.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2025-27770 | uptrain-ai UpTrain up to 0.7.1 checks/metadata code injection

A vulnerability identified as critical has been detected in uptrain-ai UpTrain up to 0.7.1. Affected by this issue is some unknown functionality.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2025-27621 | UpTrain AI up to 0.7.1 Backend uptrain-access-token cross-domain policy

A vulnerability categorized as problematic has been discovered in UpTrain AI UpTrain up to 0.7.1.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2025-27772 | uptrain-ai UpTrain up to 0.7.1 checks/metadata code injection

A vulnerability classified as critical was found in uptrain-ai UpTrain up to 0.7.1. Affected by this vulnerability is an unknown functionality.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-73420 | NextAuth.js auth-core-next-auth Email Normalization defaultNormalizer improper authentication

A vulnerability classified as critical was found in NextAuth.js auth-core-next-auth.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-73644 | OpenIdentityPlatform OpenDJ up to 5.1.1 SASL PlainSASLMechanismHandler.java improper authorization

A vulnerability was found in OpenIdentityPlatform OpenDJ up to 5.1.1. It has been classified as very critical.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) VulDB Updates
CVE-2026-73648 | rails rails-html-sanitizer up to 1.7.0 PermitScrubber cross-domain policy

A vulnerability labeled as problematic has been found in rails rails-html-sanitizer up to 1.7.0.

vor 1 Tag 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) DEV Community
Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1. Basic Information Original Title: Hacking OpenAI Source: Hacktron AI Published Date: 2026-09-13 Updated Date: None Severity: Critical Severity…

vor 1 Tag 1 Min
0
Weiterlesen ↗
Weitere 36 Beiträge laden
Seite 1 von 10 • Gesamt: 328 Artikel
1 Quelle 27
F5 NGINX Plus R33: Report Usage to F5 in Connected Environment
1 Quelle 15
Microsoft has two weeks to make a Surface event that isn't an embarrassment — can arguably the 'best laptop ever made' make that happen?
1 Quelle 26
Influencing Software Security: The Impact of the Kernel Self-Protection Project ⚔️🛡️🐧
1 Quelle 26
Introducing Shared Memory Versioning to improve slow interactions
1 Quelle 26
Building the Next Generation of Developer Tools: Inside the HYNAWEB Ecosystem 🐯
1 Quelle 26
Rate Limiting: The Traffic Cop Your API Needs
1 Quelle 26
I Built the MVP First. Then I Wrote the README.
1 Quelle 26
How to add a loading screen with a progress bar in Godot 4
1 Quelle 26
Sticky in process, gone on restart: auditing the state your CLI daemon keeps in memory
1 Quelle 26
My Weekly Tech Digest: What I Learned in Linux Essentials with Akwannya Hub
1 Quelle 26
Canada is about to break your scheduler
1 Quelle 26
Blacksmith's GitHub Actions runners finished the same job 3 to 4 times faster than GitHub hosted Actions, across 10 trials
Threat Hunter Status-Update verfassen
Community Stream
News-Deck Reverse Engineering 📖 0 · ⏭ 0 · 🗳️ 0

Karten werden geladen …

Hoch = in der Vorschau lesen · Rechts = vor · Links/Runter = zurück · Enter/Karte tippen = Vorschau · V = Voting