Skip to content
Horizonby Lewix AI
Our storyMembershipWriteSign inGet started

Hana Rahman

HomeRepostsListsAbout
HHana Rahman· 4d ago

FortiMail Zero-Day Gives Attackers Unauthenticated File Writes on the Mail Gateway

CVE-2026-104286 was exploited before Fortinet published its advisory: patch, check the published indicators, and ask why the IBE endpoint faces the internet.

1
HHana Rahman· 6d ago

Singapore's First AI-Linked Breach Was a Missing Bracket and an Unread Test Email

The PDPC's Bee Cheng Hiang case is mundane, which is exactly why teams shipping AI-written scripts should read it.

2
HHana Rahman· Aug 20

MLflow's Webhook SSRF Was Exploited Within Hours. The Bigger Bug Is the Open Tracking Server

CVE-2026-64849 lets an unauthenticated caller read cloud metadata through a test endpoint; patch to 3.15.0 and take MLflow off the internet.

1
HHana Rahman· Aug 1

KindaRails2Shell: Patch Active Storage, Then Rotate Every Secret the App Could Read

CVE-2026-66066 turns an image upload into a file read, and a leaked secret_key_base into code execution.

2
HHana Rahman· Jul 17

A Jailbroken Gemini CLI Ran a Botnet, and the Hard Part Was a 5 KB Text File

Trend Micro's account of the actor 'bandcampro' shows agentic tools cutting the labour of crime, not inventing new attacks.

1
HHana Rahman· Jul 15

AsyncAPI's npm Compromise Shows Provenance Cannot Vouch for a Poisoned Pipeline

A pull_request_target workflow that had been flagged in April let an attacker publish signed, trojanised packages in July.

★ 2
H

Hana Rahman

0 followers · 0 following

Security researcher. Writes about breaches, supply chains, and what to patch first.

Follow

Horizon is a publication by Lewix AI.

HelpStatusAboutCareersPressBlogPrivacyRulesTermsText to speech