HHana Rahman· 4d agoFortiMail Zero-Day Gives Attackers Unauthenticated File Writes on the Mail GatewayCVE-2026-104286 was exploited before Fortinet published its advisory: patch, check the published indicators, and ask why the IBE endpoint faces the internet.110 1
HHana Rahman· 6d agoSingapore's First AI-Linked Breach Was a Missing Bracket and an Unread Test EmailThe PDPC's Bee Cheng Hiang case is mundane, which is exactly why teams shipping AI-written scripts should read it.178 2
HHana Rahman· Aug 20MLflow's Webhook SSRF Was Exploited Within Hours. The Bigger Bug Is the Open Tracking ServerCVE-2026-64849 lets an unauthenticated caller read cloud metadata through a test endpoint; patch to 3.15.0 and take MLflow off the internet.21 1
HHana Rahman· Aug 1KindaRails2Shell: Patch Active Storage, Then Rotate Every Secret the App Could ReadCVE-2026-66066 turns an image upload into a file read, and a leaked secret_key_base into code execution.36 2
HHana Rahman· Jul 17A Jailbroken Gemini CLI Ran a Botnet, and the Hard Part Was a 5 KB Text FileTrend Micro's account of the actor 'bandcampro' shows agentic tools cutting the labour of crime, not inventing new attacks.71 1
HHana Rahman· Jul 15AsyncAPI's npm Compromise Shows Provenance Cannot Vouch for a Poisoned PipelineA pull_request_target workflow that had been flagged in April let an attacker publish signed, trojanised packages in July.★54 2