RSS Anyway
Sign in
RSS Anyway
Hot
Latest
Following
Status
About
Sign in
RSS Anyway
Hot
Latest
Following
Status
About
corgea.com
Sign in to follow
corgea.com
RSS
Atom
JSON
items
|
feeds
61.
CVE-2026-10796 lets hostile mirrors turn `nvm install` into shell RCE
corgea.com
·
/rss.xml
▲ 0
· Jun 5
62.
Changelog - June 4, 2026
corgea.com
·
/rss.xml
▲ 0
· Jun 4
63.
Phantom Gyp Miasma hit Vapi, ai-sdk-ollama, and 55 more npm packages
corgea.com
·
/rss.xml
▲ 0
· Jun 4
64.
CVE-2026-44488: Axios fetch adapter bypasses maxContentLength and maxBodyLength
corgea.com
·
/rss.xml
▲ 0
· Jun 4
65.
CVE-2024-21182: Oracle WebLogic T3 and IIOP exposure is now exploited
corgea.com
·
/rss.xml
▲ 0
· Jun 2
66.
Miasma poisoned Red Hat Cloud Services npm packages through trusted publishing
corgea.com
·
/rss.xml
▲ 0
· Jun 2
67.
Weekly Briefing - 02-06-2026
corgea.com
·
/rss.xml
▲ 0
· Jun 2
68.
10 Best SonarQube Alternatives in 2026 (Ranked by Accuracy & Auto-Fix)
corgea.com
·
/rss.xml
▲ 0
· Jun 2
69.
CIFSwitch turns Linux CIFS SPNEGO upcalls into local root
corgea.com
·
/rss.xml
▲ 0
· Jun 1
70.
CVE-2026-27771 exposed private Gitea and Forgejo container images
corgea.com
·
/rss.xml
▲ 0
· Jun 1
71.
roberts/leads Packagist dev branch hid a Famous Chollima blockchain loader
corgea.com
·
/rss.xml
▲ 0
· Jun 1
72.
oob.moika.tech npm campaign used dependency confusion to profile developer environments
corgea.com
·
/rss.xml
▲ 0
· May 31
73.
14 OpenSearch-themed npm typosquats stole AWS, Vault, GitHub, and npm secrets
corgea.com
·
/rss.xml
▲ 0
· May 31
74.
CVE-2026-48864: libsolv .solv page decompression can overflow parser buffers
corgea.com
·
/rss.xml
▲ 0
· May 29
75.
js-logger-pack turns Hugging Face into a malware CDN and exfiltration backend
corgea.com
·
/rss.xml
▲ 0
· May 29
76.
Sicoob.Sdk NuGet impersonator steals mTLS certificates through Sentry telemetry
corgea.com
·
/rss.xml
▲ 0
· May 29
77.
TinyMCE CVE-2026-47759 through 47762 turn editor sanitization gaps into stored XSS
corgea.com
·
/rss.xml
▲ 0
· May 29
78.
Changelog - May 28, 2026
corgea.com
·
/rss.xml
▲ 0
· May 28
79.
codexui-android npm package exfiltrates Codex OAuth tokens on startup
corgea.com
·
/rss.xml
▲ 0
· May 28
80.
@velora-dex/sdk 9.4.1 loaded a macOS MINIRAT backdoor on import
corgea.com
·
/rss.xml
▲ 0
· May 28
81.
CVE-2026-48172: exploited LiteSpeed cPanel plugin bug lets any tenant reach root
corgea.com
·
/rss.xml
▲ 0
· May 27
82.
Joomla 5.4.6 and 6.1.1 patch com_users privilege-escalation paths
corgea.com
·
/rss.xml
▲ 0
· May 27
83.
Snipe-IT 8.4.1 closes API admin escalation, component-note XSS, and open redirect flaws
corgea.com
·
/rss.xml
▲ 0
· May 27
84.
CVE-2026-9082: exploited Drupal PostgreSQL SQL injection reaches KEV
corgea.com
·
/rss.xml
▲ 0
· May 26
85.
Laravel-Lang tag rewrites turned Composer autoload into credential theft
corgea.com
·
/rss.xml
▲ 0
· May 26
86.
TrapDoor used npm, PyPI, and Crates.io lures to steal developer secrets
corgea.com
·
/rss.xml
▲ 0
· May 26
87.
Weekly Briefing - 26-05-2026
corgea.com
·
/rss.xml
▲ 0
· May 26
88.
art-template npm compromise delivered a Coruna-like iOS exploit kit
corgea.com
·
/rss.xml
▲ 0
· May 22
89.
CVE-2026-46333: Linux ptrace race leaks privileged file descriptors
corgea.com
·
/rss.xml
▲ 0
· May 22
90.
CVE-2025-34291: Langflow CORS and refresh-token chain reaches RCE
corgea.com
·
/rss.xml
▲ 0
· May 22
← prev
page 3
next →