🚨 We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. (1/6)
🚨 Security advisory: Composer 2.9.8 and 2.2.28 are out and fix a vulnerability leaking GitHub Actions new format GITHUB_TOKENs into job logs via error messages.
Update now (composer self-update) or disable affected Actions workflows.
#composerphp#phpc#php
🚨 Alerte Cyber - CPANEL
Une faille d'authentification critique a été découverte dans cPanel, permettant à des attaquants de se connecter sans autorisation aux interfaces cPanel et WHM (autrement dit, ils peuvent accéder à des panneaux d'administration de serveurs web sans connaître les identifiants légitimes.)
Un patch a été publié pour les versions supportées. La mise à jour se fait avec une seule commande :
👉bash/scripts/upcp
Si la mise à jour est impossible ➡️ bloquer les ports via le pare-feu
🚨 Composer 2.9.6 and 2.2.27 are out with fixes for CVE-2026-40261 and CVE-2026-40176, both command injection issues in the Perforce driver. Run composer self-update now. No exploitation detected on https://t.co/Gf5b9WSiRn and Private Packagist. #php#phpc#composerphp
Introducing EmDash — the spiritual successor to WordPress.
Serverless. TypeScript. Securely sandboxed plugins via Dynamic Workers.
https://t.co/AQorxEmiKM
What if I told you there was a new CMS that includes the bad WordPress interface from 2015, the tinymce editor, and that it also won't work with normal WordPress plugins.
How excited are we, people?
Every WordPress plugin you install is a blind trust exercise.
Full database access. Full filesystem access. No isolation. Hope for the best.
EmDash plugins can only do what they declare upfront. Sandboxed. Scoped. Auditable.
96% of WordPress security issues come from plugins. We fixed that.
HEADS UP. Popular JSON formatter extension has started injecting geolocation tracking and donation UI into websites
Reddit thread seems to think they are also swapping tracking IDs for affiliates (a-la honey)
Uninstall and switch to another one
🚨 Security Alert: axios versions 1.14.1 and 0.30.4 were compromised on npm with a remote access trojan hidden in a postinstall script. Both versions have since been removed.
This was not a Laravel vulnerability — but we're taking proactive steps to protect our community from this supply chain attack.
If you installed or updated axios in the last 24 hours, scan your machine.
What we did:
• Pinned axios to safe versions in laravel/laravel
• laravel/installer now runs package installs with --ignore-scripts by default
• Blocked the attacker's domain across Laravel Cloud
More info: https://t.co/GhcKIAIEXE
👋 PSA / Message to all Saloon users
We've published 3 CVEs affecting all versions of Saloon, including one rated high. We strongly recommend upgrading to v4 as soon as possible.
Upgrade guide (v3 → v4) https://t.co/SBHGgeFEUE
⚠️ Abonnés Freebox ⚠️
Avant, le code achat était activé par défaut pour tout achat (VOD, abonnements, chaîne, etc)
Depuis le 20/03 pour les anciens et nouveaux abonnés, le code achat n’est plus systématiquement demandé !
RDV dans l’espace abonné rubrique TV pour le réactiver !
@DFintelligence C'est exactement ce que j'ai fait l'autre jour, plus orienté explication du fonctionnement mais oui je confirme que c'est une bonne idée de le faire