Critical Security Exposure in Coolify: Multiple Vulnerabilities Enabling Full Host Compromise
Product Overview Product Name: CoolifyCategory: Self-hosted Platform-as-a-Service (PaaS)Architecture: Web application + privileged backend services + Docker host…
continue reading..
Critical iccDEV Vulnerabilities Expose Image Pipelines to High-Risk Attacks – Patch Immediately
Product: iccDEV iccDEV is a color profile processing library commonly embedded in image pipelines, document converters, print…
continue reading..
CVE-2026-21449 & CVE-2026-21450: Bagisto Template Injection Flaws Expose Servers to Full Compromise
Product: BagistoAffected versions: All versions prior to 2.3.10Vulnerability type: Server-Side Template Injection (SSTI)Impact: Remote Code Execution (RCE)Severity:…
continue reading..
CVE-2026-0625: Unauthenticated RCE in D-Link DSL Gateways via dnscfg.cgi
D-Link DSL Gateways — Unauthenticated Command Injection in dnscfg.cgi CVE ID: CVE-2026-0625Affected Products: D-Link DSL Series GatewaysVulnerability…
continue reading..
CVE-2026-21411: Critical OpenBlocks Firmware Authentication Bypass Enabling Full Device Takeover
CVE ID: CVE-2026-21411Affected Product: OpenBlocks devicesVendor: Plat’HomeAffected Versions: OpenBlocks firmware earlier than 5.0.8Vulnerability Class: Authentication Bypass /…
continue reading..
CVE-2025-62877: Critical SSH Default Password Exposure During Harvester Installation
Vulnerability Overview (At a Glance) What Is the Issue? CVE-2025-62877 is a critical security flaw in the…
continue reading..
Hidden in Plain Sight: Fileless Tuoni C2 Malware Uses Images and AI to Infiltrate U.S. Real Estate Firms
Executive overview In early January 2026, security researchers disclosed a highly sophisticated, stealth-focused malware campaign leveraging the…
continue reading..
CVE-2025-15444: Silent Cryptographic Validation Flaw Allows Malicious Ed25519 Points to Bypass Trust Checks
Related upstream issue: CVE-2025-69277 (libsodium)Affected component: Crypt::Sodium::XS (Perl module)Affected versions: All versions prior to 0.000042Fixed version: 0.000042Underlying…
continue reading..
Silent Breach: How a Zero-Day Flaw Exposed Tens of Thousands at Dartmouth
Executive Overview Dartmouth College suffered a major data breach after cybercriminals associated with the Clop extortion group…
continue reading..
