Aggregator
ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants
A publicly accessible JavaScript file on ClickUp’s homepage has been silently leaking nearly a thousand corporate and government email addresses, including employees from Fortinet, Home Depot, Tenable, Mayo Clinic, and U.S. state government workers, through a hardcoded third-party API key that was first reported in January 2025 and remains unrotated as of April 2026. The […]
The post ClickUp’s Hardcoded API Key Exposes 959 Emails from Fortune 500 Giants appeared first on Cyber Security News.
CVE-2026-7219 | Totolink N300RT 3.4.0-B20250430 /boafrm/formIpQoS entry_name buffer overflow
CVE-2026-7218 | Totolink N300RT 3.4.0-B20250430 libapmib.so /boafrm/formWsc is_cmd_string_valid localPin buffer overflow
Submit #802138: jackwrichards fastly-mcp-server 6f3d0b0e654fc51076badc7fa16c03c461f95620 Command Injection [Accepted]
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
欧洲批准了 Moderna 的流感和 COVID-19 联合疫苗
CVE-2026-7217 | Deepractice PromptX up to 2.4.0 Document File index.ts path absolute path traversal (Issue 571)
Submit #808194: TOTOLINK N300RT Router V3.4.0-B20250430 Buffer Overflow [Accepted]
Submit #802127: Totolink N300RT Router V3.4.0-B20250430 Buffer Overflow [Accepted]
Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit
Kerlab A Rust implementation of Kerberos for FUn and Detection Kerlab was developed just to drill down kerberos protocol and
The post Inside the Protocol: Master Kerberos Defense and Detection with Kerlab’s Rust Toolkit appeared first on Penetration Testing Tools.
Disinformation campaign targeted Tibetan parliament-in-exile elections
CVE-2026-7216 | donchelo processing-claude-mcp-bridge up to e017b20a4b592a45531a6392f494007f04e661bd create_sketch Tool processing_server.py sketch_name path traversal
Submit #802120: Deepractice PromptX 2.4.0 Improper Authorization [Accepted]
CVE-2026-7215 | egtai gmx-vmd-mcp up to 0.1.0 VMD Launch mcp_server.py launch_vmd_gui_tool structure_file/trajectory_file command injection
Submit #802090: donchelo processing-claude-mcp-bridge e017b20a4b592a45531a6392f494007f04e661bd Path Traversal [Accepted]
Submit #802087: egtai gmx-vmd-mcp 0.1.0 Command Injection [Accepted]
Under Active Fire: CISA Warns of New Exploits in Samsung, SimpleHelp, and D-Link Hardware
The United States Cybersecurity and Infrastructure Security Agency (CISA) has once again augmented its repository of vulnerabilities identified
The post Under Active Fire: CISA Warns of New Exploits in Samsung, SimpleHelp, and D-Link Hardware appeared first on Penetration Testing Tools.