Tag
#Security
CVE-2026-27971 : Qwik server$ Unauthenticated Remote Code Execution
A technical breakdown of CVE-2026-27971, a CVSS 9.2 critical unauthenticated remote code execution vulnerability in Qwik (< 1.19.1). Unsafe deserialization in the server$ RPC flow allows attacker-controlled QRL objects to be reconstructed from application/qwik-json requests, enabling arbitrary module path and symbol resolution and, where require() is available,remote code execution via crafted server-side function invocation.
Apr 01, 2026
CVE-2026-2599: WordPress PHP Object Injection to RCE
A technical breakdown of CVE-2026-2599, a CVSS 9.8 Critical unauthenticated PHP Object Injection ...
Mar 25, 2026
CVE-2025-68461: Roundcube SVG Animate XSS Bypass
CVE-2025-68461 (CVSS 7.2) lets SVG animate tags slip past the Roundcube sanitizer via namespace p...
Mar 17, 2026
GHSA-cr3w-cw5w-h3fj: 1-Click RCE in Saltcorn
Analysis of GHSA-cr3w-cw5w-h3fj, a CVSS 9.7 critical XSS-to-RCE vulnerability in Saltcorn (≤ 1.5....
Mar 11, 2026
More tagged #Security
CVE-2026-26019 : LangChain RecursiveUrlLoader Server-Side Request Forgery Vulnerability
A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain Community JavaScript package (< 1.1.14). The RecursiveUrlLoader class uses a naive string prefix check to validate crawled URLs, allowing an attacker to bypass the default preventOutside restriction with a suffixed domain and redirect the crawler to internal network assets, potentially exposing sensitive credentials and metadata endpoints.
Mar 04, 2026
DORA Compliance for Mobile Teams: Understanding scope and what you need to do
A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.
Mar 03, 2026
CVE-2025-64712: Path Traversal RCE in Unstructured Library MSG Processing
A technical breakdown of CVE-2025-64712, a CVSS 9.8 critical path traversal remote code execution vulnerability in the Unstructured Python library (< 0.18.18). Unsanitized attachment filenames in Outlook MSG processing allow for path traversal, enabling an attacker to overwrite arbitrary files via a crafted MSG file and achieve code execution.
Feb 23, 2026
CVE-2026-1357: Unauthenticated RCE in WPvivid Backup Plugin
A technical breakdown of CVE-2026-1357, a CVSS 9.8 critical unauthenticated remote code execution vulnerability in the WPvivid Backup & Migration plugin (≤ 0.9.123). Two chained flaws, a cryptographic fail-open and an unsanitized path traversal, allow arbitrary file write and shell upload without credentials.
Feb 20, 2026
8 Open-Source AI Pentesting Tools Compared (2026)
PentestGPT, PentAGI, HexStrike AI, Strix, CAI, Nebula, NeuroSploit and Deadend CLI compared: key features of each AI pentest agent, GitHub stars and licenses.
Jan 30, 2026
Android Developer Verification 2026: Who Needs It
From 2026, certified Android devices can block apps from unverified developers. What changes for sideloading, who is affected, and how Google is responding.
Jan 27, 2026
Android WebView addJavascriptInterface Risks
Case study: Ostorlab's AI pentest engine finds an Android WebView JavaScript bridge reachable via deep links and chains it into native UI manipulation.
Jan 07, 2026
Best Mobile App Security Testing Platforms 2026
Compare Ostorlab, NowSecure, Appknox, Data Theorem, Quokka, Zimperium and MobSF for Android and iOS, with a feature matrix and vendor proof-of-value questions.
Jan 05, 2026
Android FLAG_SECURE: Block Screenshots and Recording
How Android's FLAG_SECURE blocks screenshots, screen recording and recent-apps previews, with code samples, use cases, limitations and casting behavior.
Dec 29, 2025
AI Pentest Engine Discovers Critical WebSocket BFLA in GraphQL Subscriptions
Ostorlab's AI Pentest Engine systematically uncovered a critical Broken Function-Level Authorization (BFLA) vulnerability in a GraphQL WebSocket endpoint, allowing unauthenticated access to a real-time translation service. This case study details the AI's step-by-step process, from discovery to proof-of-concept.
Dec 26, 2025