Recent Advisories

Severity ID Title Vendor Product Date Type
NONE THN:E7B27AF7990...

Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain_THN:E7B27AF79906373961790705D467275B

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIM725Ni41-PBwM_6zXNdsydP1eZO7oSsWIlAqpwdOu9dOcZM6ZI1iaqwSsL3yZKT4lbFRM-eZVq3ARKDbLR...

N/A N/A THN
NONE THN:0B57AAEC379...

The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes_THN:0B57AAEC379BB19269BA5F6FA540F390

![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgjNWtaK_WkFnKnaLTIwg043i_I6YVi5XuZGVzh30SGeK-iutwr6t2Ed3S6Qk0V9uykYueDD5WETtQ4sW1QwG...

N/A N/A THN
NONE 267A765B-AF6E-

PhantomCommits-CTF_267A765B-AF6E-5280-849A-0BDCD33EBD9F

STS-PR-13: Code Review CTF — Writeups Writeups for STS-PR-13: Conduct Security-Focused Code Review with Justification, a 3-challenge CTF built arou...

N/A N/A GITHUBEXPLOIT
NONE MALWAREBYTES:70...

Nearly 15,000 infected websites cleaned in SocGholish crackdown_MALWAREBYTES:705B2D633D6C25DA1D25345CF3273B27

We’re always happy to end the week with some positive news. A law enforcement action called Operation Endgame just delivered a major win against th...

N/A N/A MALWAREBYTES
NONE HACKREAD:CDD4B7...

Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime_HACKREAD:CDD4B73BFA0E5B80AED134963121A750

Meteor 3.0 helped Rocket.Chat move from Node.js 14 to Node.js 20, cutting runtime debt after Fibers removal and reducing supply-chain risk across f...

N/A N/A HACKREAD
MEDIUM 5.3 CVE-2026-12622

Open Redirect Vulnerability in Password Reset Submission in GridTime™ 3000 GNSS Time Server_CVE-2026-12622

The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issue affects GridTime 3000: fr...

Microchip GridTime 3000 1.0r0.03 CVE
MEDIUM 5.3 CVE-2026-12621

Cross-Site Scripting (XSS) Vulnerability in Password Reset Redirect in GridTime™ 3000 GNSS Time Server_CVE-2026-12621

Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form) allows XSS. This issue a...

Microchip GridTime 3000 1.0r0.03 CVE
MEDIUM 4.6 CVE-2026-12620

Access Token Exposure in URL Parameters in GridTime™ 3000 GNSS Time Server_CVE-2026-12620

The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects GridTime 3000: from 1.0r0.03...

Microchip GridTime 3000 1.0r0.03 CVE
MEDIUM 5.1 CVE-2026-12619

GridTime™ 3000 GNSS Time Server CSRF to XSS_CVE-2026-12619

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip GridTime 3000 allows Cross-S...

Microchip GridTime 3000 1.0r0.03 CVE
HIGH 8.1 CVE-2026-56211

Libaom: libaom: remote code execution via svc layer context handling with attacker-controlled frames_CVE-2026-56211

A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encode...

Red Hat Red Hat Enterprise Linux 10 CVE