ex-aws-sns-signingcerturl-spoofing-cve-2026-47074
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
CVE-2026-47074: ex_aws_sns verify_message/1 fails to validate SigningCertURL, allowing unauthenticated SNS message signature spoofing; affects versions 2.0.1 to before 2.3.5.
Hard-coded FTP credentials in KlinikaXP allowed an attacker to upload a malicious update to the vendor update server, possibly distributing it to client machines; vendors rotated credentials and removed the hard-coded secrets.
New speed limits on the A68 Pathhead require fleet risk management and policy updates.
A supply chain incident involving Trivy and a self‑propagating CanisterWorm has infected npm packages, giving persistent backdoor access to developer systems.
CVE-2026-33134: authenticated time-based blind SQL injection in WeGIA’s restaurar_produto.php via id_produto, fixed in 3.6.6 — urgent patch and audit required
Regulations set ecodesign and energy information requirements for household tumble dryers, creating new duties for manufacturers and importers.
A new CVE shows Slovensko.Digital Autogram’s XML /sign endpoint can be abused by a crafted website to perform SSRF and read local files; act now to inventory, contain and disable external entities.
Donec ullamcorper nulla non metus auctor fringilla. Cras justo odio, dapibus ac facilisis in, egestas eget
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.
Sign up to receive updates, promotions, and sneak peaks of upcoming products. Plus 20% off your next order.