🚨 Unauthenticated attackers could turn Grafana MCP servers into proxies for internal networks and cloud metadata endpoints.
@Pillar_sec's research team found affected releases accepted self-generated session IDs in place of authentication, exposing the server's Grafana service account to anyone who could reach it.
A chained SSRF (CVE-2026-19516, CVSS 9.1) then let callers pick the destination, method, headers, and body of outbound requests. The server has passed 1.9 million Docker Hub downloads; Grafana shipped fixes in mcp-grafana v1.1.0.
Full details here: https://t.co/JeMvtEiCR1
In the latest episode of the Inside the FBI Podcast, experts discuss online dangers facing teens, including sextortion, grooming, violent online networks, and predators who use information shared online to target young people.
Parents and trusted adults can help by:
🔒 Knowing the child's phone password and privacy settings
📵 Setting boundaries around phone use
👀 Talking openly about online activity
🤝 Encouraging teens to trust their instincts and alert a trusted adult if something feels wrong
🛑 Reminding them that once something is shared online, it can be difficult to take back
Young people who are victimized are never to blame.
🎧 Listen to the latest episode of Inside the FBI and learn more about keeping teens safe online: https://t.co/ZIQQ2D0KfU
‼️ WARNING - Attackers are exploiting a Chrome V8 zero-day.
CVE-2026-85046 allows arbitrary code execution inside the browser sandbox via a crafted HTML page. Google fixed it in Chrome 152.0.7977.82/.83.
How the V8 type confusion works: https://t.co/oi8DcrCAQG
NEW: South Korea's Financial Services Commission unveils a three-stage plan to tokenize all securities, starting with private bonds and funds for institutions in February 2027, expanding to public equities and stablecoin settlement.
.@POTUS highlights his Administration's commitment to America's farmers and ranchers — from historic tax relief and cutting crop insurance premiums by more than $400M to eliminating the death tax and reducing the drought threshold, and much more.
Roy Cooper is a liar. He didn't keep criminals behind bars in North Carolina. He enabled the largest mass prison release in state history with 4,200 criminals released.
If Roy Cooper gets to the Senate, he'll bring his soft on crime views to the floor.
CASE UPDATE from @FBIWFO: Former Homeland Security Employee Pleads Guilty in $250,000 Fraud Scheme
Richeline Anisso Fung, 46 pleaded guilty to making false, fictitious, or fraudulent claims while working as a full-time employee for the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (DHS-CISA). The defendant served in multiple federal contractor positions and often misrepresented her hours. In February 2022, for example, she claimed she worked 33 hours per day for four days straight.
Learn more: https://t.co/BXLNB7mZdS
🚨 Attackers compiled the newly documented Ted backdoor into HAProxy builds at two South Korean organizations.
It keeps C2 out of backend logs and HAProxy statistics while serving altered pages only to selected visitors.
How the filtering and log evasion work → https://t.co/heRcTH0Ug1
Trump Administration Announces $120 Million to Expand Maternal and Infant Health Services, Increase Primary Care Access and Grow the Healthcare Workforce Across Indiana https://t.co/1FCXAPQn1n
🛑 Attackers are exploiting Super Forms and Elementor Pro RCE flaws.
Wordfence has blocked over 440,000 attempts. Both bugs allow unauthenticated PHP uploads; Elementor attacks require a published page with a Form widget and File Upload field.
Inside the bypass: https://t.co/FABvq9J4k9
Today's exploit is for the latest Ubuntu 26.04, a 9-year-old OOB in SCTP: CVE-2026-52924.
It was introduced in Oct 2017 and fixed upstream in Jun 2026.
Discovered and exploited by the NebuSec security pipeline.
EXP source: https://t.co/3XVCKU1fPL
‼️ BREAKING: The breach at Trezor's shipping provider ShipMonk is far bigger than first thought. Trezor now puts the number of affected customers at about 81,000, up from 13,689.
Another 67,000 US buyers who placed orders between November 2019 and August 2021 had names, phone numbers and shipping addresses exposed. Trezor says ShipMonk repeatedly confirmed in writing that this data was deleted. Turns out it wasn't.
Trezor is warning of physical security risks and says it has emailed all affected customers directly.
@WhiteHouse Sadly, I had to cash out my 401k when my husband got sick just to pay the bills and take care of the home and children. I regret it everyday but life happens.
@FCNightingale@JG_Nuke As a young man my first job had a pension plan that was switching to 401k. 50% of the investment was in executive life. Put into a seperate account. Received some periodic payments as it settled but lost money. Hard lesson about saftey of retirement assets to forget.
@milne25@RealLifeLoot@pulte Question for you, I’ve been trying to help my wife get access to her Merrill Lynch 401k account she’s since lost access to since @Walmart refuses to give her information from the time she worked there. Does ML have an at risk team to help authenticate?
Texas is an oil and gas POWERHOUSE! It employs almost three million people. But @jamestalarico wants to abolish the oil and gas industry.
Republican Senate candidate @KenPaxtonTX: "This is a guy that is not friendly to the Texas industry."
🚨BREAKING — America First Legal just sued the state of California on behalf of @nickshirleyy to BLOCK the enforcement of a new California law known as the “Stop Nick Shirley Act.”