Aggregator
CVE-2026-4426 | libarchive ISO File Parser pz_log2_bs incorrect bitwise shift of integer
CVE-2025-71257 | BMC FootPrints up to 20.24.01.001 REST API Endpoint missing authentication
CVE-2026-4424 | libarchive RAR out-of-bounds
CVE-2025-71260 | BMC FootPrints up to 20.24.01.001 ASP.NET Servlet VIEWSTATE deserialization
CVE-2026-30951 | Sequelize up to 6.37.7 _traverseJSON sql injection (GHSA-6457-6jrx-69cr / Nessus ID 301792)
CVE-2026-30952 | harttle liquidjs up to 10.24.x path traversal (GHSA-wmfp-5q7x-987x)
CVE-2026-31954 | Emlog up to 2.6.6 LoginAuth::checkToken cross-site request forgery
CVE-2026-32102 | OliveTin up to 3000.10.1 access control (GHSA-228v-wc5r-j8m7)
CVE-2026-32101 | studiocms up to 0.3.0 PUT isAuthorized authorization (GHSA-mm78-fgq8-6pgr)
CVE-2026-31815 | django-commons django-unicorn up to 0.66.x access control (GHSA-ffv6-jj46-x367)
CVE-2026-31837 | Istio up to 1.27.7/1.28.4/1.29.0 information disclosure (GHSA-v75c-crr9-733c)
CVE-2026-31838 | Istio up to 1.27.7/1.28.4/1.29.0 authorization (GHSA-974c-2wxh-g4ww)
CVE-2026-31825 | Sylius up to 2.2.2 orderBy sql injection (GHSA-xcwx-r2gw-w93m)
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations
The U.K.’s media regulator Ofcom fined 4chan £450,000 under the Online Safety Act for failing to introduce age checks to stop children from accessing pornographic content on its platform. 4chan is an online forum notorious for its extreme right-wing content, gory videos, and non-consensual pornography. The regulator ordered the company to introduce age assurance measures by 2 April 2026 and said additional daily penalties of £500 could apply if the issue is not resolved, with … More →
The post 4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations appeared first on Help Net Security.
Versa Secure Enterprise Browser delivers browser-native security for enterprise apps
Versa has revealed early access to Versa Secure Enterprise Browser, a new browser-native security capability within the VersaONE Universal SASE Platform that protects employees, contractors, and partner users as they access web, SaaS, and enterprise AI applications by enforcing security, access, and data protection policies directly within the browser session. The browser has become the dominant execution environment for enterprise work, yet it often remains outside the reach of consistent security, access, and data protection … More →
The post Versa Secure Enterprise Browser delivers browser-native security for enterprise apps appeared first on Help Net Security.