Aggregator
CVE-2026-31815 | django-commons django-unicorn up to 0.66.x access control (GHSA-ffv6-jj46-x367)
CVE-2026-31837 | Istio up to 1.27.7/1.28.4/1.29.0 information disclosure (GHSA-v75c-crr9-733c)
CVE-2026-31838 | Istio up to 1.27.7/1.28.4/1.29.0 authorization (GHSA-974c-2wxh-g4ww)
CVE-2026-31825 | Sylius up to 2.2.2 orderBy sql injection (GHSA-xcwx-r2gw-w93m)
ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More
4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations
The U.K.’s media regulator Ofcom fined 4chan £450,000 under the Online Safety Act for failing to introduce age checks to stop children from accessing pornographic content on its platform. 4chan is an online forum notorious for its extreme right-wing content, gory videos, and non-consensual pornography. The regulator ordered the company to introduce age assurance measures by 2 April 2026 and said additional daily penalties of £500 could apply if the issue is not resolved, with … More →
The post 4chan shrugs off UK regulator, refuses to pay £520,000 in fines over online safety violations appeared first on Help Net Security.
Versa Secure Enterprise Browser delivers browser-native security for enterprise apps
Versa has revealed early access to Versa Secure Enterprise Browser, a new browser-native security capability within the VersaONE Universal SASE Platform that protects employees, contractors, and partner users as they access web, SaaS, and enterprise AI applications by enforcing security, access, and data protection policies directly within the browser session. The browser has become the dominant execution environment for enterprise work, yet it often remains outside the reach of consistent security, access, and data protection … More →
The post Versa Secure Enterprise Browser delivers browser-native security for enterprise apps appeared first on Help Net Security.
CVE-2026-3419 | fastify up to 5.8.0 Header Content-Type incorrect regex (GHSA-573f-x89g-hqp9)
CVE-2026-29791 | Agentgateway up to 0.11.x input validation
CVE-2026-30942 | FlintSH Flare up to 1.7.2 Path Validation path.join path traversal (GHSA-h639-p7m9-mpgp)
CVE-2026-30934 | gtsteffaniak filebrowser up to 1.2.1-stable/1.3.0-beta /public/share/ cross site scripting
CVE-2026-25960 | vLLM up to 0.16.x Incomplete Fix CVE-2026-24779 urllib3.util.parse_url server-side request forgery (GHSA-qh4c-xf7m-gxfc)
CVE-2026-30937 | ImageMagick up to 6.9.13-40/7.1.2-15 XWD Encoder heap-based overflow (EUVD-2026-10402)
CVE-2026-31802 | isaacs node-tar up to 7.5.10 path traversal
CVE-2026-30909 | TIMLEGGE Crypt::NaCl::Sodium up to 2.002 on Perl Message bin2hex/aes256gcm_encrypt_afternm/seal integer overflow (EUVD-2026-10199 / CNNVD-202603-1448)
CVE-2026-29795 | stellar rs--xdr up to 25.0.0 StringM::from_str allocation of resources
CVE-2025-69651 | GNU Binutils up to 2.46 readelf process_got_section_contents denial of service (Nessus ID 301408)
CVE-2025-69650 | GNU Binutils up to 2.46 readelf process_got_section_contents denial of service (Nessus ID 301402)
Nagomi Security expands into agent-driven exposure elimination with Agentic Exposure Ops
Nagomi Security has announced the next evolution of its platform with Agentic Exposure Ops, expanding Nagomi from exposure visibility to agent-driven exposure elimination. Most exposure management programs generate findings faster than teams can validate what’s real, route fixes to the right owners, and re-check outcomes as environments change. Agentic Exposure Ops closes that execution loop so high-impact conditions get eliminated and stay closed over time. That loop breaks in enterprises for a simple reason: the … More →
The post Nagomi Security expands into agent-driven exposure elimination with Agentic Exposure Ops appeared first on Help Net Security.