Recent Posts
Week 38 – GitLab Under Attack: Critical Arbitrary File Read Vulnerability
14 – 20 Sept 2026 What if an unauthenticated user could read your sensitive data from the GitLab server? This week’s CVE of the Week highlights CVE-2026-85706 in GitLab – a critical CVSS 10.0 flaw that could allow unauthenticated attackers to read arbitrary files from …
Week 37 – SAP Attack: When the Buffer Says “No More”
07 – 12 Sept 2026 A critical CVSS 10.0 vulnerability puts thousands of Internet-facing SAP systems potentially at risk. Our latest CVE of the Week covers CVE-2026-44756, a buffer overflow vulnerability in the SAP Kernel that could enable remote attackers to execute code with administrative …
Week 35 – CoSnitch: When Copilot Starts Snitching
24 – 30 Aug 2026 What if your AI assistant could be tricked into handing your data to an attacker? This week’s CVE of the Week looks at CVE-2026-24301 (CoSnitch), a CVSS 8.8 vulnerability in Microsoft Copilot combining automatic prompt execution, data exfiltration and persistent …
Week 34 – From Auto-Login to Full RCE: Inside the IBM Langflow CVE
17 – 23 Aug 2026 AI platforms are increasingly becoming attractive targets for attackers. CVE-2026-9198 affects IBM Langflow OSS and chains security flaws that can lead to unauthenticated Remote Code Execution (RCE). With public PoCs available and the vulnerability already exploited in the wild, affected …
Cyber (In)Security – Issue #208
The fortnightly newsletter of the Cybersecurity Advisors Network (CyAN) — Issue #208, 17 August 2026. This issue leads with crypto custody governance and our autumn mentorship intake, plus two serious CVEs, the latest from our members, and a spotlight on OSINT. In this issue Are …



