Recent Posts
Week 34 – From Auto-Login to Full RCE: Inside the IBM Langflow CVE
17 – 23 Aug 2026 AI platforms are increasingly becoming attractive targets for attackers. CVE-2026-9198 affects IBM Langflow OSS and chains security flaws that can lead to unauthenticated Remote Code Execution (RCE). With public PoCs available and the vulnerability already exploited in the wild, affected …
Cyber (In)Security #208
The fortnightly newsletter of the Cybersecurity Advisors Network (CyAN) — Issue #208, 17 August 2026. This issue leads with crypto custody governance and our autumn mentorship intake, plus two serious CVEs, the latest from our members, and a spotlight on OSINT. In this issue Are …
Week 33 – TeamCity Under Construction: Critical RCE Flaw
10 – 16 Aug 2026 A critical unauthenticated remote code execution (RCE) vulnerability has been disclosed in JetBrains TeamCity On-Premises. Tracked as CVE-2026-63077 with a CVSS score of 9.8, the deserialization flaw could allow remote attackers to bypass authentication and execute arbitrary system commands on …
Week 32 – N-able N-central – Take Control Taken Over
03-09 Aug 2026 CVE-2026-18577 is a critical authentication bypass vulnerability affecting N-able N-central. Due to an incomplete patch, attackers can gain administrative access, abuse the built-in Take Control feature, and pivot to managed endpoints. Read White Hat IT Security’s analysis to understand the attack chain, …
Applications now closed for CyAN’s Mentorship Programme, Autumn 2026
Note: applications are now closed CyAN’s mentorship programme is back for its autumn 2026 cohort, running from mid-September to mid-December. The programme is free and volunteer-led. It pairs people building a career in cybersecurity, or a related field, with experienced CyAN members for three months …
Cyber (In)Security — Issue #207
The fortnightly newsletter of the Cybersecurity Advisors Network (CyAN) — Issue #207, 4 August 2026. This issue leads with governance and civil-society resilience, plus the latest from our members and partners. Downloadable full PDF at the bottom of this post. In this issue Are you …
Week 31 – CertiGhost: The Certificate That Shouldn’t Exist
27 July – 02 Aug 2026 This week’s CVE of the Week is CVE-2026-54121, also known as CertiGhost, a critical vulnerability affecting Microsoft Active Directory Certificate Services (AD CS). The flaw allows a low-privileged authenticated domain user to obtain a certificate for a Domain Controller, …



