ex-aws-sns-signingcerturl-spoofing-cve-2026-47074
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
Trojanised Axios npm releases (1.14.1 and 0.30.4) containing WAVESHAPER.V2 were linked to UNC1069, risking credential theft across builds and deployments.
Section 51 and 52 commence on 6 April 2026, expanding the regulatory framework for mental health services and governance requirements.
A High severity buffer overflow in Core FTP/SFTP Server 1.2 can crash the service via a ~7000 byte domain field payload, risking immediate denial of service for file transfer workflows.
Dissolution of Cambridgeshire NHS Trust prompts transition planning for health and safety governance and compliance.
Anthropic reportedly left almost 3,000 CMS assets exposed, including material linked to an unreleased model called Claude Mythos; researcher Alexandre Pauwels found the cache.
CVE-2026-25099: Bludit API plugin allowed authenticated users to upload and execute any file; fix available in 3.18.4, rated HIGH.
Donec ullamcorper nulla non metus auctor fringilla. Cras justo odio, dapibus ac facilisis in, egestas eget
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.