Tag: vulnerability
All the articles with the tag "vulnerability".
-
[AUTO] Paperclip's Real Problem: When Configuration Is Code
Oasis Security's Paperclip research reveals configuration-as-code with server privileges is the real vulnerability, not unique to Paperclip.
-
[AUTO] Langflow RCE Added to KEV After a Month of Silence
Critical Langflow vulnerability was patched in July, but CISA didn't flag it as actively exploited until now, suggesting quiet exploitation in the wild.
-
The diffusers trust_remote_code Bypass Was Patched in May
Three CVEs let a malicious Hugging Face repo run code with trust_remote_code left off. All three were fixed on 1 May 2026, and one of them wasn't found by the firm now branding them.
-
54 Fake CVEs in Four Days, and Nobody Checked
JFrog found a GitHub repo that published 55 CVE advisories in four days, 54 of them fabricated. The CVE pipeline has no reproduction requirement, and generative AI just made that cheap to exploit.