Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MALWAREBYTES:25...

We found this fake-invoice campaign while scammers were still building it_MALWAREBYTES:25837C9966B4BAC9D5751BE5031B9FC8

A new batch of fake payment invoices is being staged right now, and we caught the campaign while it was still being put together. The emails impers...

N/A N/A MALWAREBYTES
NONE WIRED:1EAF5DF8A...

xAI Asks Court to Strip Alleged Grok Deepfake Nudes Victims of Anonymity_WIRED:1EAF5DF8A74C5E2543ACF401BFDFAF11

Four people suing Elon Musk's AI firm under pseudonyms due to the risks of being identified may face a difficult choice: Reveal your real names, or...

N/A N/A WIRED
NONE THN:39C53E79409...

WhatsApp, Slack Notifications Could Hijack Google Gemini on Android_THN:39C53E7940941BA527D7D41B5E56D8C8

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCJpW9I-QTgQOkP7AV3rwUtEOEs96ek2ySR06Go-xq5AThZV84qY3mDN1Dkh0oQ-94jZHc7zB21ax9ljU0dW...

N/A N/A THN
NONE 420BEB65-BD63-

Exploit for CVE-2026-26897_420BEB65-BD63-521E-90B1-5065E05B96C0

EcoOnline EHS Android — Deep Link Validation Bypass → WebView Open Redirect CVE-2026-26897 Public disclosure / advisory for CVE-2026-26897, a deep ...

N/A N/A GITHUBEXPLOIT
NONE PACKETSTORM:222620

📄 Gogs Git Rebase Argument Injection / Remote Code Execution_PACKETSTORM:222620

This Metasploit module exploits an argument injection vulnerability in the pull request merge flow of Gogs versions less than or equal to 0.14.2 an...

N/A N/A PACKETSTORM
NONE QUALYSBLOG:CB6A...

Stop Patching at Human Speed: Peer-to-Peer (P2P) Distribution Closes the Remediation Gap Before Attackers Strike_QUALYSBLOG:CB6AB0F22D373D44641F0A459EDB5DFD

* * * #### Executive Summary _Knowing what’s exploitable is only half the battle. P2P patch distribution turns your endpoints into a delivery net...

N/A N/A QUALYSBLOG
NONE THN:EBEF4474475...

Google DoubleClick Abused in New Malspam Campaign to Deliver DesckVB RAT_THN:EBEF4474475574D09B83167D16690C6D

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpQ6QXxFH4zkfeHGdcm1WXVcNXMpyJm-1dlZLbFCdp6rKDRhuwICzYaKaR-rCpn61qod6A1F98PZejZbmYux...

N/A N/A THN
NONE 8D02FC42-E11E-

ParamStriker_8D02FC42-E11E-5436-870C-E4CD77B99D8D

ParamStriker Offline JSON & Query Parameter Exploit Framework by Mohnad Alshobaili · X: @Mohnad ParamStriker is a offensive, offline payload-genera...

N/A N/A GITHUBEXPLOIT
NONE D2A2BDA2-A827-

Exploit for CVE-2026-35904_D2A2BDA2-A827-5C81-ACD9-A68148EC42CC

T3 Technology CPE — Security Advisories Multiple critical vulnerabilities discovered in T3 Technology CPE ONU/Router devices deployed by TrueOnline...

N/A N/A GITHUBEXPLOIT
NONE FEF41599-6B58-

1click-gh-token-stealing-via-vscode-POC_FEF41599-6B58-5BDB-BB48-0E38230B7291

1-Click GitHub Token Stealing via VSCode Proof-of-Concept exploit for a critical VS Code zero-day vulnerability that allows attackers to steal GitH...

N/A N/A GITHUBEXPLOIT