#infosec
CVE-2026-72738: Dokploy Backup: Authenticated Remote Code Execution via Command Injection (stackflag.com)
CVE-2026-72738 - dokploy An authenticated user with backup access can execute arbitrary commands on the Dokploy server. This can lead to data loss or system compromise. Update to version 0.29.13 or later to fix this… Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-72736: Dokploy: Malicious Code Can Run on Host Server (stackflag.com)
CVE-2026-72736 - dokploy Dokploy, a self-hosted Platform as a Service, had a security issue where an attacker could potentially run malicious code on the host server. This was fixed in version 0.29.13, so update to… Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-72737: Dokploy: Unauthorized Access to Another Organization's AWS Credentials (stackflag.com)
CVE-2026-72737 - dokploy Dokploy's backup feature in versions 0.29.8 and earlier allows an authenticated user with backup permissions to access another organization's AWS credentials, read their backups, or redirect… Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2021-34498 — Windows GDI Elevation of Privilege Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-34498: Windows GDI Elevation of Privilege Vulnerability CVSS 7.8 · EPSS 1.0% · 0day https://beta.vulnsea.com/cve/CVE-2021-34498
CVE-2021-34473 — Microsoft Exchange Server Remote Code Execution Vulnerability (beta.vulnsea.com)
🌑 HADAL · actively exploited critical CVE-2021-34473: Microsoft Exchange Server Remote Code Execution Vulnerability CVSS 9.1 · EPSS 100.0% · CISA KEV · 0day https://beta.vulnsea.com/cve/CVE-2021-34473
CVE-2021-34468 — Microsoft SharePoint Server Remote Code Execution Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-34468: Microsoft SharePoint Server Remote Code Execution Vulnerability CVSS 7.1 · EPSS 1.9% · 0day https://beta.vulnsea.com/cve/CVE-2021-34468
CVE-2021-33771 — Windows Kernel Elevation of Privilege Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-33771: Windows Kernel Elevation of Privilege Vulnerability CVSS 7.8 · EPSS 6.3% · CISA KEV · 0day https://beta.vulnsea.com/cve/CVE-2021-33771
CVE-2021-33766 — Microsoft Exchange Server Information Disclosure Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-33766: Microsoft Exchange Server Information Disclosure Vulnerability CVSS 7.3 · EPSS 97.5% · CISA KEV · 0day https://beta.vulnsea.com/cve/CVE-2021-33766
CVE-2026-72733: Dokploy: Malicious Commands Can Be Executed on Server (stackflag.com)
CVE-2026-72733 - dokploy Dokploy's database restore feature allows authenticated users with permission to execute arbitrary commands on the server. This could lead to unauthorized access or data loss. Update to… Too many irrelevant or confusing CVEs? Use stackflag.com
CVE-2026-72735: Dokploy: Unauthorized commands can be executed on remote servers (stackflag.com)
CVE-2026-72735 - dokploy Dokploy's remote server management feature allows unauthorized commands to be executed on remote servers with the configured SSH user's privileges. This is due to an incomplete fix for a… Too many irrelevant or confusing CVEs? Use stackflag.com
The Linux Kernel Dev Staging Area Now Rejects AI-Generated Patches (linuxnews.net)
[Linux Magazine] The Linux Kernel Dev Staging Area Now Rejects AI-Generated Patches
CVE-2021-33751 — Windows Storage Spaces Controller Elevation of Privilege Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-33751: Windows Storage Spaces Controller Elevation of Privilege Vulnerability CVSS 7 · EPSS 0.7% · 0day https://beta.vulnsea.com/cve/CVE-2021-33751
CVE-2021-31979 — Windows Kernel Elevation of Privilege Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-31979: Windows Kernel Elevation of Privilege Vulnerability CVSS 7.8 · EPSS 2.6% · CISA KEV · 0day https://beta.vulnsea.com/cve/CVE-2021-31979
CVE-2021-31206 — Microsoft Exchange Server Remote Code Execution Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-31206: Microsoft Exchange Server Remote Code Execution Vulnerability CVSS 7.6 · EPSS 9.8% · 0day https://beta.vulnsea.com/cve/CVE-2021-31206
CVE-2021-31196 — Microsoft Exchange Server Remote Code Execution Vulnerability (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-31196: Microsoft Exchange Server Remote Code Execution Vulnerability CVSS 7.2 · EPSS 46.4% · CISA KEV https://beta.vulnsea.com/cve/CVE-2021-31196
CVE-2021-34527 — A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations (beta.vulnsea.com)
🌊 ABYSSAL · critical with a public exploit CVE-2021-34527: A remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file … CVSS 8.8 · EPSS 99.8% · CISA KEV https://beta.vulnsea.com/cve/CVE-2021-34527
CVE-2026-19429: Jenkins Project Jenkins - Unauthorized Access to Sensitive Files (stackflag.com)
CVE-2026-19429 - jenkins A security patch for Jenkins Project Jenkins is incomplete, allowing an authenticated attacker to access sensitive files on the server. This can happen because the patch does… Too many irrelevant or confusing CVEs? Use stackflag.com
Original post on thistlenfern.org (thistlenfern.org)
Seven billion logs and millions of GPU hours, and they're still reconstructing it. OpenAI walked through the Hugging Face incident. Agents from different evaluations — some of them different models #InfoSec #CyberSecurity #BlackHat #OpenAI #HuggingFace #AI #NoAI #Privacy #Linux #FOSS […]
Manufacturing cybersecurity needs tested recovery plans (iottechnews.com)
30% of manufacturers experienced a cyber incident affecting operations directly or through the supply chain.
Original post on thistlenfern.org (thistlenfern.org)
Seven billion logs and millions of GPU hours, and they're still reconstructing it. At Black Hat, OpenAI walked through the Hugging Face incident. Agents from different evaluations — some of them different models — worked out they could leave notes for each […] [Original post on thistlenfern.org]
The model didn't escape. Someone left the door open. (insights.rmkeefer.com)
This summer's AI "escapes" ran on weak passwords, unauthenticated endpoints, secrets in environment variables, and a vendor assurance nobody verified. Nobody picked a lock. The doors were open. New piece: insights.rmkeefer.com/door-open?ref=bluesky
Ransomware crew mined crypto in Colombia before encrypting (intelfusions.com)
Colombia's national CERT pulled apart an intrusion where the attackers quietly mined cryptocurrency on the victim's machines before encrypting them. The encryptor itself looks like parts of three different ransomware families bolted together.