Neutron, our AI engine, scored 96.75% on UC Berkeley's CyberGym benchmark. Learn more

Tag

#Security

94 articles

A technical breakdown of CVE-2026-27971, a CVSS 9.2 critical unauthenticated remote code execution vulnerability in Qwik (< 1.19.1). Unsafe deserialization in the server$ RPC flow allows attacker-controlled QRL objects to be reconstructed from application/qwik-json requests, enabling arbitrary module path and symbol resolution and, where require() is available,remote code execution via crafted server-side function invocation.

Security

CVE-2026-2599: WordPress PHP Object Injection to RCE

A technical breakdown of CVE-2026-2599, a CVSS 9.8 Critical unauthenticated PHP Object Injection ...

Mar 25, 2026

Security

CVE-2025-68461: Roundcube SVG Animate XSS Bypass

CVE-2025-68461 (CVSS 7.2) lets SVG animate tags slip past the Roundcube sanitizer via namespace p...

Mar 17, 2026

Security

GHSA-cr3w-cw5w-h3fj: 1-Click RCE in Saltcorn

Analysis of GHSA-cr3w-cw5w-h3fj, a CVSS 9.7 critical XSS-to-RCE vulnerability in Saltcorn (≤ 1.5....

Mar 11, 2026

More tagged #Security

CVE-2026-26019 : LangChain RecursiveUrlLoader Server-Side Request Forgery Vulnerability

A technical breakdown of CVE-2026-26019, a CVSS 4.1 medium Server-Side Request Forgery vulnerability in the LangChain Community JavaScript package (< 1.1.14). The RecursiveUrlLoader class uses a naive string prefix check to validate crawled URLs, allowing an attacker to bypass the default preventOutside restriction with a suffixed domain and redirect the crawler to internal network assets, potentially exposing sensitive credentials and metadata endpoints.

Mar 04, 2026

DORA Compliance for Mobile Teams: Understanding scope and what you need to do

A mobile-first guide to DORA regulation and DORA compliance for BFSI teams. Learn how to define your scope, simplify your release process, and avoid the traps that create unnecessary compliance work.

Mar 03, 2026

CVE-2025-64712: Path Traversal RCE in Unstructured Library MSG Processing

A technical breakdown of CVE-2025-64712, a CVSS 9.8 critical path traversal remote code execution vulnerability in the Unstructured Python library (< 0.18.18). Unsanitized attachment filenames in Outlook MSG processing allow for path traversal, enabling an attacker to overwrite arbitrary files via a crafted MSG file and achieve code execution.

Feb 23, 2026

CVE-2026-1357: Unauthenticated RCE in WPvivid Backup Plugin

A technical breakdown of CVE-2026-1357, a CVSS 9.8 critical unauthenticated remote code execution vulnerability in the WPvivid Backup & Migration plugin (≤ 0.9.123). Two chained flaws, a cryptographic fail-open and an unsanitized path traversal, allow arbitrary file write and shell upload without credentials.

Feb 20, 2026

8 Open-Source AI Pentesting Tools Compared (2026)

PentestGPT, PentAGI, HexStrike AI, Strix, CAI, Nebula, NeuroSploit and Deadend CLI compared: key features of each AI pentest agent, GitHub stars and licenses.

Jan 30, 2026

Android Developer Verification 2026: Who Needs It

From 2026, certified Android devices can block apps from unverified developers. What changes for sideloading, who is affected, and how Google is responding.

Jan 27, 2026

Android WebView addJavascriptInterface Risks

Case study: Ostorlab's AI pentest engine finds an Android WebView JavaScript bridge reachable via deep links and chains it into native UI manipulation.

Jan 07, 2026

Best Mobile App Security Testing Platforms 2026

Compare Ostorlab, NowSecure, Appknox, Data Theorem, Quokka, Zimperium and MobSF for Android and iOS, with a feature matrix and vendor proof-of-value questions.

Jan 05, 2026

Android FLAG_SECURE: Block Screenshots and Recording

How Android's FLAG_SECURE blocks screenshots, screen recording and recent-apps previews, with code samples, use cases, limitations and casting behavior.

Dec 29, 2025

AI Pentest Engine Discovers Critical WebSocket BFLA in GraphQL Subscriptions

Ostorlab's AI Pentest Engine systematically uncovered a critical Broken Function-Level Authorization (BFLA) vulnerability in a GraphQL WebSocket endpoint, allowing unauthenticated access to a real-time translation service. This case study details the AI's step-by-step process, from discovery to proof-of-concept.

Dec 26, 2025