Recent Posts
Week 35 – CoSnitch: When Copilot Starts Snitching
24 – 30 Aug 2026 What if your AI assistant could be tricked into handing your data to an attacker? This week’s CVE of the Week looks at CVE-2026-24301 (CoSnitch), a CVSS 8.8 vulnerability in Microsoft Copilot combining automatic prompt execution, data exfiltration and persistent …
Week 34 – From Auto-Login to Full RCE: Inside the IBM Langflow CVE
17 – 23 Aug 2026 AI platforms are increasingly becoming attractive targets for attackers. CVE-2026-9198 affects IBM Langflow OSS and chains security flaws that can lead to unauthenticated Remote Code Execution (RCE). With public PoCs available and the vulnerability already exploited in the wild, affected …
Cyber (In)Security – Issue #208
The fortnightly newsletter of the Cybersecurity Advisors Network (CyAN) — Issue #208, 17 August 2026. This issue leads with crypto custody governance and our autumn mentorship intake, plus two serious CVEs, the latest from our members, and a spotlight on OSINT. In this issue Are …
Week 33 – TeamCity Under Construction: Critical RCE Flaw
10 – 16 Aug 2026 A critical unauthenticated remote code execution (RCE) vulnerability has been disclosed in JetBrains TeamCity On-Premises. Tracked as CVE-2026-63077 with a CVSS score of 9.8, the deserialization flaw could allow remote attackers to bypass authentication and execute arbitrary system commands on …
Week 32 – N-able N-central – Take Control Taken Over
03-09 Aug 2026 CVE-2026-18577 is a critical authentication bypass vulnerability affecting N-able N-central. Due to an incomplete patch, attackers can gain administrative access, abuse the built-in Take Control feature, and pivot to managed endpoints. Read White Hat IT Security’s analysis to understand the attack chain, …



