Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

OffSequence

@offseq@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.

144 Followers
0 Following
50 Posts
Joined April 02, 2025
Website:
https://offseq.com
Threat Radar:
https://radar.offseq.com
Guard:
https://guard.offseq.com
Breach:
https://breach.offseq.com
Training & Certifications:
https://training.offseq.com
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. https://radar.offseq.com/threat/cve-2026-66897-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-b6ae23dfc47f5562 #OffSeq #LXD #CVE #Linux

1
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. https://radar.offseq.com/threat/cve-2026-78168-improper-authentication-in-efm-iptime-t24000m-bfa2e716a3fcf0b6 #OffSeq #CVE #IoTSecurity #Exploit

1
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-78211-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-91902877a695e366 #OffSeq #CVE202678211 #Vuln #BlueTeam

1
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT

1
0
2
0
Open post
OffSequence @offseq@infosec.exchange
· 4w ago

CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. https://radar.offseq.com/threat/cve-2026-16149-cwe-269-improper-privilege-management-in-marc4-security-hardener-a438d1f2a5360b5c #OffSeq #WordPress #Vulnerability #Infosec

1
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
FreeRDP <3.29.0 has a CRITICAL buffer over-disclosure (CVE-2026-67292). Malicious WebSocket peers can leak memory or crash clients via crafted Ping frames. No patch confirmed — avoid unknown gateways. Details: https://radar.offseq.com/threat/freerdp-before-3290-contains-a-buffer-over-disclosure-vulnerability-in-the-gateway-websocket-transport-67044e0124c23808 #OffSeq #FreeRDP #CVE202667292 #AppSec
1
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 1h ago
CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-94003-stack-based-buffer-overflow-in-comfast-cf-n1-s-1046130f838f5eec #OffSeq #Infosec #CVE #IoTSecurity
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-67289: FreeRDP ≤3.28.0 has a CRITICAL flaw (CVSS 9.8) in RDP redirection — improper CRLF/control character validation exposes clients to HTTP header injection via proxies. Upgrade to 3.29.0+ now. https://radar.offseq.com/threat/freerdp-before-3290-affected-versions-3280-does-not-validate-crlf-and-control-characters-in-the-server-2a6872dd9d8a1a0c #OffSeq #FreeRDP #CVE202667289 #infosec
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 4w ago

CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. https://radar.offseq.com/threat/cve-2026-78122-insufficient-granularity-of-access-control-in-tecnativa-docker-socket-proxy-6e8e6aaf03a19cce #OffSeq #Docker #Infosec #Vuln

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: https://radar.offseq.com/threat/cve-2026-87931-buffer-overflow-in-behavioral-technology-group-pavlok-behavioral-conditioning-wearable-98a2d4c4edee7864 #OffSeq #CVE202687931 #IoTSecurity
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-13716-cwe-35-path-traversal-in-arcadia-technology-llc-crafty-controller-2cdd2d33980b3ceb #OffSeq #Vuln #CVE202613716
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 5d ago
Cisco Secure Email Gateway faces a CRITICAL zero-day vulnerability, actively exploited in the wild. No CVE or version info yet. Patch available — apply ASAP to protect email infrastructure. https://radar.offseq.com/threat/cisco-patches-secure-email-gateway-zero-day-exploited-in-attacks-76a43690673247c4 #OffSeq #Cisco #ZeroDay #BlueTeam #EmailSecurity
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
ArcadeDB (<26.7.2) hit by CRITICAL vuln (CVE-2026-67341, CVSS 9.3). Improper auth lets users with DB access execute arbitrary JS via DEFINE FUNCTION, bypassing admin-only restrictions. Restrict access, monitor usage, check for patches. https://radar.offseq.com/threat/cve-2026-67341-incorrect-authorization-in-arcadedata-arcadedb-6bb8ad21f1650c1c #OffSeq #CVE #infosec
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-18686: CRITICAL command injection in GL.iNet GL-MT3000 (4.4.0 – 4.4.5). Remote, unauthenticated code execution possible — no patch yet. Limit admin interface exposure & monitor for abuse. https://radar.offseq.com/threat/cve-2026-18686-command-injection-in-glinet-gl-mt3000-14534eb705079787 #OffSeq #CVE #RouterSecurity
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 5d ago
EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 #OffSeq #Vulnerability #IoTSecurity #CVE
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CRITICAL: JetBrains TeamCity On-Premises (all versions) vulnerable to CVE-2026-63077 — auth bypass enables remote code execution via HTTPS. Patch to 2025.11.7/2026.1.3 or apply plugin for 2017.1+. TeamCity Cloud unaffected. https://radar.offseq.com/threat/jetbrains-warns-of-critical-teamcity-remote-code-execution-flaw-b5d2b338dff8d1eb #OffSeq #Vuln #TeamCity #CVE202663077
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. https://radar.offseq.com/threat/cve-2026-77995-cwe-639-authorization-bypass-through-user-controlled-key-in-miniorangecom-miniorange-0e8da876ce4c7e51 #OffSeq #Joomla #Vuln #OAuth

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3h ago
HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. https://radar.offseq.com/threat/cve-2026-92965-cwe-862-missing-authorization-in-tiktok-38fbb3b8076a5adb #OffSeq #WordPress #Vuln #Security
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
Tranquil IT WAPT Server 2.6.0.16767 hit by CVE-2026-33591 (CRITICAL, CVSS 10). Remote attackers can bypass authentication & grab session tokens via crafted packets. No patch yet — restrict access & monitor logs. https://radar.offseq.com/threat/cve-2026-33591-cwe-288-authentication-bypass-using-an-alternate-path-or-channel-in-tranquil-it-systems-98c0bb813dbf7caa #OffSeq #CVE202633591 #Infosec #Vulnerability
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. https://radar.offseq.com/threat/cve-2026-78568-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-52b70f977190d0ba #OffSeq #WordPress #SQLi #Vuln

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2d ago
@kartyk-github-org/takedown-b (npm) contains CRITICAL malware: full system compromise if installed/run. All secrets and keys must be rotated from a clean device. Removal alone is insufficient — investigate for persistence. No CVE. https://radar.offseq.com/threat/malicious-code-in-kartyk-github-orgtakedown-b-npm-3a3addb0368973b9 #OffSeq #npm #malware #infosec
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-14804: CRITICAL (CVSS 9.1) in HUMANIST Digital HR v26.0 🛡️ Hard-coded cryptographic key (CWE-321) allows data exposure & integrity loss. No official fix — limit access & track vendor updates. https://radar.offseq.com/threat/cve-2026-14804-cwe-321-use-of-hard-coded-cryptographic-key-in-bilin-software-and-informatics-7feb29c78f0c5d49 #OffSeq #Vulnerability #CVE202614804
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2d ago
Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. https://radar.offseq.com/threat/check-point-kaspersky-tanium-patch-product-vulnerabilities-ae8c3757ea9b181a #OffSeq #Vulnerability #RCE #PatchNow
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
BC-JAVA users: CVE-2026-59650 (CRITICAL, CVSS 9.3) exposes MTI/A0 Diffie-Hellman via improper input validation. Affects <1.85, 2.73.0 – 2.73.11. No patch yet — avoid affected versions & monitor for updates. https://radar.offseq.com/threat/cve-2026-59650-cwe-20-improper-input-validation-in-legion-of-the-bouncy-castle-inc-bc-java-bfb9720e803b614a #OffSeq #Vulnerability #Java #Cryptography
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. https://radar.offseq.com/threat/cve-2026-78267-cwe-266-incorrect-privilege-assignment-in-cozmoslabs-translatepress-ba0caba45d17d814 #OffSeq #WordPress #Vuln #PrivilegeEscalation

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. https://radar.offseq.com/threat/cve-2026-78265-cwe-502-deserialization-of-untrusted-data-in-nexcess-the-events-calendar-3dd3af18547313e0 #OffSeq #WordPress #Infosec #CVE2026_78265

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
Tenable's 30-day Claude Mythos Preview AI integration proves CRITICAL RCE & DoS exploits in internal code. No CVE; this is a novel testing approach, not a public vuln. Requires senior security expertise & orchestration harnesses. https://radar.offseq.com/threat/30-days-with-claude-mythos-preview-how-tenable-adapted-our-security-program-and-why-yours-is-next-8b547c9780f46717 #OffSeq #AIsecurity #AppSec #BlueTeam
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. https://radar.offseq.com/threat/cve-2026-78570-cwe-269-improper-privilege-management-in-klbtheme-total-donations-fcfd73df270b6d37 #OffSeq #WordPress #CVE #Vuln

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. https://radar.offseq.com/threat/cve-2026-77994-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-d508026cac86e490 #OffSeq #Joomla #SQLInjection #Infosec

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! https://radar.offseq.com/threat/cve-2026-78251-cwe-798-use-of-hard-coded-credentials-in-dji-neo-98f2d4e34b35b2e0 #OffSeq #CVE2026_78251 #DJI #DroneSec

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA & strong passwords. No CVE assigned. https://radar.offseq.com/threat/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks-21f9fb8717cf2802 #OffSeq #CloudSecurity #ThreatIntel
0
1
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. https://radar.offseq.com/threat/cve-2026-8445-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-42aabed1c30bf24b #OffSeq #XSS #AppSec #CVE20268445

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: https://radar.offseq.com/threat/cve-2026-7808-improper-input-validation-in-emilstenstrom-justhtml-86dd54d29e0645e9 #OffSeq #CVE20267808 #infosec #XSS

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
Azure Cosmos DB suffers a CRITICAL improper access control vulnerability (CVE-2026-66803) allowing unauthorized remote code execution. No patch yet — restrict network access & monitor Microsoft advisories. https://radar.offseq.com/threat/improper-access-control-in-azure-cosmos-db-allows-an-unauthorized-attacker-to-execute-code-over-a-db3b78e9f6a886eb #OffSeq #Azure #Vuln #CyberSecurity
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
FlowiseAI Flowise (<3.1.3) has a CRITICAL vuln (CVE-2026-70478): unauthenticated POST endpoint leaks refreshed OAuth tokens if credential ID is known. Upgrade to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70478-cwe-200-exposure-of-sensitive-information-to-an-unauthorized-actor-in-flowiseai-flowise-2c912baff770743c #OffSeq #CVE202670478 #OAuth #infosec
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 13h ago
CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. https://radar.offseq.com/threat/cve-2026-93741-buffer-overflow-in-totolink-a3002mu-bc2e06f7d2d53482 #OffSeq #CVE202693741 #IoT #Exploit
0
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CosmosEscape: CRITICAL flaw in Azure Cosmos DB exposed primary keys, granting full DB access. No CVE or mitigation yet. Monitor access keys and watch for official fixes. https://radar.offseq.com/threat/critical-flaw-led-to-azure-cosmos-db-pwnage-79bd9e6a4135bd53 #OffSeq #Azure #CloudSecurity #Vulnerability
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-59638 (CRITICAL, CVSS 9.3) in BC-JAVA: Improper cert validation due to default CN-fallback can expose TLS connections to MITM. Affects <1.85, LTS <2.73.12. Patch status unknown — monitor vendor & consider disabling fallback. https://radar.offseq.com/threat/cve-2026-59638-cwe-297-improper-validation-of-certificate-with-host-mismatch-in-legion-of-the-bouncy-aa319f6f20b27a8a #OffSeq #CVE202659638 #infosec
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe #OffSeq #CVE202678676 #git #infosec

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments & monitor for fixes. https://radar.offseq.com/threat/cve-2026-78477-cwe-266-incorrect-privilege-assignment-in-mvpthemes-jawn-ec6b466fa423dd3f #OffSeq #WordPress #Vuln #PrivilegeEscalation

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features & monitor for patches. https://radar.offseq.com/threat/cve-2026-9273-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-stellarwp-membership-10c6cffc948a3c97 #OffSeq #WordPress #Vuln #Security
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. https://radar.offseq.com/threat/cve-2026-16985-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-squeeze-a1de64d348b6591f #OffSeq #WordPress #CVE2026_16985 #infosec
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-17561: Logsign SIEM <6.4.108 faces CRITICAL code injection (CWE-94, CVSS 9.8). Exploitable remotely, no patch yet. Full system compromise possible. Monitor for updates. https://radar.offseq.com/threat/cve-2026-17561-cwe-94-improper-control-of-generation-of-code-code-injection-in-innotim-software-30d176d2929ded6e #OffSeq #CVE202617561 #SIEM #Vuln #BlueTeam
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. https://radar.offseq.com/threat/cve-2026-13214-memory-safety-in-zephyrproject-zephyr-042d724fd93f46c2 #OffSeq #Zephyr #CVE202613214 #IoTSec

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago

CVE-2026-72702 | Grav CMS <2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-72702-origin-validation-error-in-getgrav-grav-4b8f0ff64f944a7c #OffSeq #CVE202672702 #GravCMS #WebSecurity

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. https://radar.offseq.com/threat/cve-2026-54212-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-2e946f5b4b7b0ab5 #OffSeq #CVE #bufferOverflow #infosec
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. https://radar.offseq.com/threat/cve-2026-16955-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ai-72905be644e71053 #OffSeq #WordPress #CVE2026_16955 #Security
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:51:47 UTC