First, restructure the global vulnerability disclosure process in the AI era.
Second, provide security access control services for all closed-source products
We've already signed up for Y Combinator. Frankly, we're here to acquire more clients, not just money. We're currently a startup, in the most challenging phase of acquiring our first clients. We desperately need our first customers, and we'll do everything we can to provide you with comprehensive security services :)
Has DeepSeek started restricting content security? I asked DeepSeek to perform a vulnerability release, but it said there were content security issues and refused to execute it.
‼️ PostgreSQL closed a 12-year-old flaw that could turn REPLICATION access into code execution.
With logical decoding enabled, an account could load any reachable library and run it as the postgres OS user.
How the flaw worked: https://t.co/vWrfLbnFpH
Finally!!! I've reached 200 stars! This is my first milestone, achieved over two months. I believe that with continued engagement, I can reach 1K stars
🚨 CVE-2026-19490: NetScaler exploitation attempts detected.
Our system autonomously added it to Watch 2 weeks ago. An unverified but credible PoC appeared yesterday. Today, 3 IPs across 3 countries sent matching requests to our sensor.
Patch now (last week):
https://t.co/ZhGGMNrLAD
Unauthenticated root RCE on Minuteman UPS Network Management Cards (CVSS 9.8)
These cards monitor and control UPS battery-backup and PDU power distribution in data centers, server rooms, and industrial facilities. Their system_param handler builds shell commands straight from HTTP POST fields and executes them as root — with no authentication check at all.
One request, no password, no session: an attacker gets root on the power-management plane. They can disrupt power states, tamper with telemetry, and use the card as a foothold inside critical infrastructure.
Full root-cause analysis + working PoC:
https://t.co/XN9On0Rkmu
#Minuteman #UPS #0day #ICS #RCE #CriticalInfrastructure
It turns out that likes and comments from strangers can be incredibly encouraging. A couple of days ago I was feeling quite down and unmotivated, but thanks to everyone's interaction and the slow but steady increase in stars on my GitHub project, I've cheered myself up again. Thank you all so much for your support !!!
Death by a thousand (paper)cuts (also known as WT-2026-0144) brings us back aboard the HellScape Express.
The saga continues… and we'll be back soon.
(We gently, kindly, and calmly suggest pulling PaperCut entirely off the Internet at this point)
We released the ninth batch of vulnerabilities. However, my project hasn't seen any star growth in a long time, which is very frustrating. I always feel like giving up at times like this, and I've actually started another project. Currently, vulnerability discovery doesn't require my intervention; I just need to disclose vulnerabilities periodically.
https://t.co/Dtoz8B24PF
Pre-auth memory corruption in NoMachine Terminal Server 10.0.57 (CVSS 9.8)
NoMachine is a remote-desktop gateway many companies use to let employees reach office machines from anywhere. Its web CGI parses multipart POSTs with an unbounded memory copy — a single crafted request, no credentials, no session, deterministically corrupts heap chunk metadata and triggers a double-free before any authentication runs.
At minimum: the remote-access service can be crashed at will from the internet. With heap grooming: a realistic path toward arbitrary code execution on the gateway — the front door of the corporate network.
Full root-cause analysis + working PoC:
https://t.co/rSAREVNti7
#NoMachine #0day #RCE #InfoSec #Vulnerability
watchTowr Intel is already seeing exploitation of the JFrog Artifactory Auth Bypass (CVE-2026-82329), with attackers minting themselves admin tokens.
Reach out if you need help determining your exposure ahead of exploitation.
Biamp Devio is the DSP controller that runs audio in tens of thousands of meeting rooms — corporate offices, universities, hospitals, and government buildings use it to make calls and presentations sound right.
We found it can be taken over remotely, with no credentials and no user interaction. The device that controls a room's microphones and speakers can be rooted by anyone who can reach it on the network — letting an attacker listen in, hijack room audio, or use the device as a foothold deeper into the building's network.
No credentials. One request. Root on the device that hears the room. CVSS 9.8.
Analysis + PoC:
https://t.co/1Bow2N0COx
#0day #RCE #AVSecurity #MeetingRoom #HardwareSecurity #infosec