Recent Advisories

Severity ID Title Vendor Product Date Type
NONE SCHNEIER:7A1236...

Embedding Forbidden Text in Spyware to Discourage AI Analysis_SCHNEIER:7A1236483F174AEC1AD949F80DF69235

At least one malware developer is adding text about nuclear and biological weapons to their spyware, in an effort to stop automatic AI analysis. D...

N/A N/A SCHNEIER
NONE THN:E39759F4A03...

Dawn of the Apex Agentic Adversary_THN:E39759F4A03F44F39AA790935B0FBE4A

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuQ2GvCcnjBgMTXoXBXqazE9MU3nbNgeccOlWELBQOL9WcHHH4uXS1BKCrrmv6iWWAn6vu1LZJzpHl1MGetv...

N/A N/A THN
MEDIUM 5.5 CVE-2026-11968

Improper Neutralization of Argument Delimiters in a Command (‘Argument Injection’) in TortoiseGit_CVE-2026-11968

Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit

TortoiseGit team TortoiseGit 1.8.10.0 CVE
MEDIUM 6.9 CVE-2026-13150

SSRF in Pentestify PDF generation endpoint via Host header_CVE-2026-13150

Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) in ccyl13 Pentestify 1.0.0 ...

Pentestify Pentestify CVE
HIGH 7.8 4BA3261D-2DE6-

Exploit for Incorrect Resource Transfer Between Spheres in Linux Linux_Kernel_4BA3261D-2DE6-5D66-AE25-4FA760E8F87D

rootpacket CVE-2026-31431 A Linux Docker-to-host cryptojacking toolkit captured from live attacks on Kinryū Labs honeypots. It breaks in through an...

N/A N/A GITHUBEXPLOIT
CRITICAL 10 776C9ED4-3841-

Exploit for Code Injection in Craftcms Craft_Cms_776C9ED4-3841-5FC1-B7D1-370CEAB62FAB

PoCCVE-2025-32432 CraftCMS CVE-2025-32432 - Clean PoC Version nettoyée et améliorée du PoC original. Crédits - Recherche originale : Orange Cyberde...

N/A N/A GITHUBEXPLOIT
HIGH 8.8 3F58B0E8-968C-

Exploit for Uncontrolled Search Path Element in Checkmk_3F58B0E8-968C-5526-9652-3C321B0F8C30

CVE-2024-0670 - CheckMK Agent MSI Repair Privilege Escalation NanoCorp HTB This repository contains a PowerShell script used to exploit CVE-2024-06...

N/A N/A GITHUBEXPLOIT
NONE F66CF4CF-53AC-

agentslastexam_F66CF4CF-53AC-54A7-B775-49F009E71162

pwnremotecapture A remote binary-exploitation task contributed to Agents' Last Exam. Two variants from one task module: the agent gets a running ne...

N/A N/A GITHUBEXPLOIT
NONE QUALYSBLOG:A246...

CERT-In’s AI Vulnerability Blueprint: Why Indian CISOs Need Machine-Speed Risk Operations in the Post-Mythos Era_QUALYSBLOG:A2463FDB3F5DB3414AFD13F999ADEC69

__A Qualys India perspective on CERT-In 's blueprint, the post-Mythos threat landscape India faces, and why the operating model needs to change.__ ...

N/A N/A QUALYSBLOG
NONE HACKREAD:F2E2A7...

Best Crypto Payment Solutions for E-Commerce Businesses_HACKREAD:F2E2A74ACB99D1596B11AE1540520FD6

Compare crypto payment gateways for ecommerce, including checkout tools, stablecoin payments, fiat settlement, plugins, APIs and business payouts.

N/A N/A HACKREAD