Anti-bots don't catch the lie — they catch the disagreement. Benchmarked Camoufox: 23/23 checks, rotating identities, timezone+locale pinned to the exit IP. Scraped through a real 4G mobile exit. #WebScraping#AntiBot#Camoufox
https://t.co/M5ZjKJy8CM
CVE-2026-68929 (9.3 Critical): FastGPT guarded its WeChat channel with the one ID it publishes in every share link. One request kills a team's bot; three steal it - scan the QR with your WeChat and their app answers in your inbox.
#FastGPT#LLM#AppSec
https://t.co/aE9bGDZi8K
CVE-2026-67602 (9.3 Critical): phpIPAM cached API rows by value, not column — so the app_id lookup answered the app_code check. The integer 1 was a valid API token. The real secret was never compared. Fixed in 1.8.2. #phpIPAM#AppSec
https://t.co/zSMJtlKiAr
CVE-2026-76036: CVSS 9.6. One createTexture() call - depth format, 259x127, mipmaps - overflows Chrome's GPU process on PowerVR phones. Code exec outside the sandbox; the fix reinstates a 2007-era rule. Patch: 151.0.7922.169. #Android#Chrome#WebGPU
https://t.co/nln3aBQUnK
CVE-2026-71960 (CVSS 9.1): every Cudy WR3000 signs its mesh MQTT JWTs with one fleet-wide key — the DES literal guarding it ships in the public firmware. Forge a token, CONNECT :1883, chain CVE-2026-71961 → root. Fixed silently in 2.5.24. #Cudy#MQTT
https://t.co/042AIUcdiW
CVE-2026-73678: unauthenticated RCE in MindsDB's Cowork agent. No auth on the API, CORS *, and the scratchpad exec()s whatever the LLM writes. Bring your own LLM key — the victim doesn't need one. CVSS 10.0. #LLM#RCE#MindsDB
https://t.co/Cip7RtyYAy
CVE-2026-68749 & 68750 (CVSS 8.2 High): the Elixir HTML sanitizer you trust to clean untrusted HTML pinned a BEAM scheduler for 2.4 s with ONE request. The fix was bounding a regex: [-\w]+ -> [-\w]{1,64}. Six characters. #Elixir#ReDoS#InfoSec
https://t.co/YrbfQcvxsj
CVE-2026-18907 (7.5): TECNO Hi Browser trusted a Content-Disposition filename as a path. Two ../ and a download writes anywhere under /sdcard/. The CGI-era bug, alive on a billion pockets. Fix = one getCanonicalPath() check. #Android#PathTraversal#TECNO
https://t.co/SSyhG3rErf
CVE-2026-67822 (CVSS 9.8): Tenda W6-S AP stack overflow — but the bug is NOT in the SSID logic. It is in the redirect-URL builder. 64-byte buffer + unbounded sprintf = root. Default admin/admin = trivially reachable. #Tenda#BufferOverflow
https://t.co/WXPZuYxnZb
CVE-2026-70638 (CVSS 7.8): llama.cpp's Android JNI wrapper multiplies sizeof(int) by an attacker value read straight from the GGUF model file — no bounds check, no NULL check. The fix? A rewrite that deleted the function. #llamacpp#Android#LLM
https://t.co/skVPBUbNl3
New: CVE-2026-17543 — SQL injection in PHP core's pgsql extension. CVSS 9.8.
The escaping was correct. Then PHP wrapped it in E'...' and re-armed the backslash it just made safe. One \ before a quote = full breakout.
The fix? Delete one letter.
https://t.co/HBlqj7NuLt
CVE-2024-6387: Unauth RCE in OpenSSH 🔥
The vulnerability, discovered by Qualys researchers, allows an attacker to perform RCE on any OpenSSH server.
Search at https://t.co/z0h36Bd4rQ:
👉🏻 Link: https://t.co/AYprRyIwfY
#cybersecurity#vulnerability_map#openssh
🚨 i just found NEW XSS On Salesforce 🚨 the “component” allow to bypass the CSP and Firewall. The path appears like that: /apex/CommVisualforce?params=eyJjb21wb25lbnQiOiJjb21tQWxyZWFkeUN1c3RvbWVyIn0=
{"component":"commAlreadyCustomer"}
#bugbounty#bugbountytips