Aggregator
CVE-2026-25888 | Chartbrew up to 4.8.0 code injection (EUVD-2026-9977)
CVE-2026-28794 | middleapi orpc up to 1.13.5 prototype pollution (GHSA-m272-9rp6-32mc)
CVE-2026-27603 | Chartbrew up to 4.8.3 Chart Filter Endpoint filter missing authentication (GHSA-9fhr-5vvc-p455 / EUVD-2026-9979)
CVE-2026-28685 | Kimai up to 2.50.x /api/invoices/ improper authorization (GHSA-v33r-r6h2-8wr7)
CVE-2026-28787 | oneuptime up to 10.0.11 improper authentication (GHSA-gjjc-pcwp-c74m)
CVE-2026-27605 | Chartbrew up to 4.8.3 HTML File Parser uploads/ unrestricted upload (GHSA-jf6m-hm53-c364 / EUVD-2026-9980)
CVE-2026-28680 | Ghostfolio up to 2.244.x Internal Network Service server-side request forgery (GHSA-hhv6-c34h-pwgh / EUVD-2026-9990)
CVE-2026-28679 | xemle home-gallery up to 1.20.x path traversal (GHSA-xj65-hcj5-h6j3 / EUVD-2026-9989)
CVE-2026-28785 | Ghostfolio up to 2.243.x getHistorical sql injection (GHSA-m5cc-7jw5-34xp / EUVD-2026-9995)
A Guy Who Wrote the Code Died in 2005. I Still Have to Secure It
INC Ransomware Group Holds Healthcare Hostage in Oceania
Why should enterprises be certain about secrets vaulting
Are You Confident in Your Enterprise’s Secrets Vaulting Strategy? Emerging threats and cybersecurity challenges have spurred organizations to reconsider their approach to managing machine identities, especially those categorized where Non-Human Identities (NHIs). By examining the lifecycle management of NHIs and their secrets, enterprises can establish a robust security framework that addresses the needs of various […]
The post Why should enterprises be certain about secrets vaulting appeared first on Entro.
The post Why should enterprises be certain about secrets vaulting appeared first on Security Boulevard.
Are DevOps teams supported by automated configurations
How Can DevOps Teams Enhance Security with Automated Configurations? What are some of the biggest security challenges facing DevOps teams? When organizations shift towards cloud-native environments, the role of machine identities, particularly Non-Human Identities (NHIs), becomes increasingly critical in securing sensitive data. With the proliferation of automated systems, managing these identities is not just an […]
The post Are DevOps teams supported by automated configurations appeared first on Entro.
The post Are DevOps teams supported by automated configurations appeared first on Security Boulevard.
How stable are AI-driven workflows in high-stress environments
How Can Non-Human Identities (NHIs) Foster Stable and Secure Cloud Environments? Are your cloud environments as secure as they should be, or are unseen vulnerabilities putting your organization at risk? Where digital threats are more sophisticated than ever, managing Non-Human Identities (NHIs) and Secrets Security is vital for maintaining robust security postures. NHIs are pivotal […]
The post How stable are AI-driven workflows in high-stress environments appeared first on Entro.
The post How stable are AI-driven workflows in high-stress environments appeared first on Security Boulevard.
pac4j CVE-2026-29000: Sonatype Finds 18 Additional Packages
A newly disclosed critical vulnerability in the widely used pac4j authentication framework is drawing attention across the open source community. Tracked as CVE-2026-29000, the flaw affects the pac4j-jwt library, which is commonly pulled in as a dependency by many popular Java authentication stacks, and could allow attackers to bypass authentication controls in affected Java applications.
The post pac4j CVE-2026-29000: Sonatype Finds 18 Additional Packages appeared first on Security Boulevard.