AIがやらかすコードの話で、JWTとLocalStorageの話が出てましたが、似たようなので
MVPとかで、未認証local accountが作れる状態GoogleAuthを後付けするとき
User user = findByEmail(googleEmail);
みたいな同じemail=同じユーザーでmergeして
Pre-Account Takeover系もわりと踏みやすい気がする
WordPress 7.0 “Armstrong” is here. 🎷
This major release introduces foundational AI tools, a refreshed admin experience, expanded design controls, new blocks, and powerful developer APIs.
Explore what’s new, update when you’re ready, and start building with WordPress 7.0 today. https://t.co/0aF3CG0WOt
A vulnerability I reported to Strapi is now public:
CVE-2026-22707
Thanks to the maintainers for the fix and disclosure.
Advisory:
https://t.co/NID2atcLd0
#CVE#AppSec#Security#Strapi
@francecarlucci Hi @francecarlucci
Have you confirmed that the PclZip path traversal vulnerability we discovered has been identified as a CVE?
Some media outlets have published the CVE number, but NIST hasn't confirmed it.
⚠️ Critical Apache HTTP Server Flaw Exposes Millions of Servers to RCE Attacks
Source: https://t.co/nyaOOtouZa
The Apache Software Foundation has released a critical security update for Apache HTTP Server, patching five vulnerabilities, including a dangerous double-free flaw capable of enabling Remote Code Execution (RCE) in version 2.4.67, released on May 4, 2026.
All users running version 2.4.66 or earlier are strongly urged to upgrade immediately. The most severe of the five vulnerabilities is CVE-2026-23918, rated High with a CVSS base score of 8.8.
The flaw is a double-free memory corruption bug triggered within Apache's HTTP/2 protocol implementation during an "early stream reset" sequence.
#cybersecuritynews #vulnerability
A vulnerability I reported to Craft CMS is now public:
CVE-2026-41128
Thanks to the maintainers for the fix and disclosure.
Advisory:
https://t.co/0WZzQ1gxVg
#CVE#AppSec#Security#CraftCMS
Two vulnerabilities I reported to baserCMS are now public:
CVE-2026-21861
CVE-2026-30940
Thanks to the maintainers for the fix and disclosure.
Advisory:
https://t.co/WjZpkOE7Mb
#CVE#AppSec#Security