A vulnerability marked as problematic has been reported in IBM Langflow OSS up to 1.10.3. This affects an unknown part. Performing a manipulation results in insufficient entropy in prng.
This vulnerability is known as CVE-2026-8470. Remote exploitation of the attack is possible. No exploit is available.
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.
The server-side gate hides the malicious page from crawlers and sandboxes while presenting selected Mac users with a fake software download. Microsoft
A vulnerability labeled as critical has been found in Jenkins Project Ivy Report Plugin up to 1.2. Affected by this issue is some unknown functionality. Such manipulation leads to xml external entity reference.
This vulnerability is traded as CVE-2026-70448. The attack may be launched remotely. There is no exploit available.
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes.
To that end, it banned a coordinated network of ChatGPT accounts likely originating from Southeast Asia and operating from the city of Poipet, a region with extensive
A vulnerability identified as problematic has been detected in Jenkins AWS CodeBuild Plugin up to 0.59. Affected by this vulnerability is an unknown functionality. This manipulation causes permission issues.
This vulnerability appears as CVE-2026-70447. The attack may be initiated remotely. There is no available exploit.
A vulnerability categorized as problematic has been discovered in Jenkins CodeSonar Plugin up to 3.6.0. Affected is an unknown function. The manipulation results in permission issues.
This vulnerability is reported as CVE-2026-70446. The attack can be launched remotely. No exploit exists.
A vulnerability was found in Jenkins Project Sauce OnDemand Plugin up to 2.2.0. It has been rated as problematic. This impacts an unknown function. The manipulation leads to permission issues.
This vulnerability is documented as CVE-2026-70445. The attack can be initiated remotely. There is not any exploit available.
A vulnerability was found in IBM Langflow up to 1.10.3. It has been classified as critical. The impacted element is an unknown function. Performing a manipulation results in server-side request forgery.
This vulnerability is cataloged as CVE-2026-7657. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in Electron up to 39.8.8/40.9.1/41.2.0/42.0.0-beta.2 and classified as critical. The affected element is the function showItemInFolder of the component DevTools. Such manipulation leads to sandbox issue.
This vulnerability is listed as CVE-2026-70611. The attack may be performed from remote. There is no available exploit.
It is suggested to upgrade the affected component.
A vulnerability has been found in Electron up to 39.8.6/40.8.x/41.1.x/42.0.0-beta.0 and classified as critical. Impacted is the function webContents.openDevTools of the component DevTools. This manipulation of the argument mode causes sandbox issue.
This vulnerability is tracked as CVE-2026-70609. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
Compare AI detection & response platforms for 2026, including Dash, Lakera, Operant AI, HiddenLayer and Prisma AIRS, for runtime threat protection and response.