Forem

Security

Hopefully not just an afterthought!

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-23946: Pickle Rick-rolled Again: The Zombie RCE in Tendenci CMS

CVE-2026-23946: Pickle Rick-rolled Again: The Zombie RCE in Tendenci CMS

Comments
2 min read
CVE-2026-23643: Let Them Eat XSS: Breaking CakePHP's PaginatorHelper

CVE-2026-23643: Let Them Eat XSS: Breaking CakePHP's PaginatorHelper

Comments
2 min read
GHSA-H3HW-29FV-2X75: Context Bleeding: When GraphQL Requests Swap Identities in Envelop

GHSA-H3HW-29FV-2X75: Context Bleeding: When GraphQL Requests Swap Identities in Envelop

Comments
2 min read
CVE-2025-69229: Death by a Thousand Chunks: The aiohttp O(N^2) DoS

CVE-2025-69229: Death by a Thousand Chunks: The aiohttp O(N^2) DoS

Comments
2 min read
CVE-2026-22036: Death by a Thousand Gzips: The Node.js Undici Decompression Loop

CVE-2026-22036: Death by a Thousand Gzips: The Node.js Undici Decompression Loop

Comments
2 min read
Storage for a public website
Cover image for Storage for a public website

Storage for a public website

6
Comments 4
4 min read
CVE-2026-24688: Ouroboros in the Outline: Infinite Loops in pypdf (CVE-2026-24688)

CVE-2026-24688: Ouroboros in the Outline: Infinite Loops in pypdf (CVE-2026-24688)

Comments
2 min read
Your JavaScript source code is public. Here's what we do about it.

Your JavaScript source code is public. Here's what we do about it.

Comments
2 min read
Reestudando sua infraestrutura
Cover image for Reestudando sua infraestrutura

Reestudando sua infraestrutura

Comments
3 min read
CVE-2026-24765: The CI/CD Trojan Horse: Inside PHPUnit's Unsafe Deserialization

CVE-2026-24765: The CI/CD Trojan Horse: Inside PHPUnit's Unsafe Deserialization

Comments
2 min read
Week 6 Scripting Challenge: Build a TLS Certificate Security Validator

Week 6 Scripting Challenge: Build a TLS Certificate Security Validator

Comments
46 min read
CVE-2025-36070: The Glass House: Shattering IBM Db2 with a Single SELECT

CVE-2025-36070: The Glass House: Shattering IBM Db2 with a Single SELECT

Comments
2 min read
đź’€ EDR Blind Spots: Kernel Callbacks

đź’€ EDR Blind Spots: Kernel Callbacks

2
Comments
6 min read
An ablation study on security outcomes: Which parts of an AI skill actually matter?

An ablation study on security outcomes: Which parts of an AI skill actually matter?

Comments
5 min read
AWS Security Services Overview

AWS Security Services Overview

Comments
12 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.