ex-aws-sns-signingcerturl-spoofing-cve-2026-47074
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
New Lincoln airspace restrictions require organisations to adapt aerial operations and risk controls under UK health and safety law.
A public exploit targets the fromSafeMacFilter function in Tenda F456 routers, version 1.0.0.5; remote code or disruption is possible and organisations should inventory and isolate affected devices immediately.
SiYuan desktop’s notification endpoint could render attacker HTML into an Electron renderer with nodeIntegration enabled, enabling local code execution; update to 3.6.5 and harden Electron settings.
P4 Server versions before 2026.1 permit unauthenticated attackers to create accounts and access depot contents via the ‘remote’ user; upgrade, isolate and audit now.
New airspace restrictions around Drax require updated risk assessments and contractor controls to ensure regulatory compliance under UK health and safety law.
A high-severity path traversal in the LabOne Web Server can let unauthenticated attackers read arbitrary files; if you run LabOne, stop the Web Server, check file permissions and rotate exposed credentials.
Donec ullamcorper nulla non metus auctor fringilla. Cras justo odio, dapibus ac facilisis in, egestas eget
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.