<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>CosmicBytez Labs</title>
    <link>https://labs.cosmicbytez.ca</link>
    <description>IT &amp; Cybersecurity Intelligence - News, Security Alerts, HOWTOs, and Project Guides</description>
    <language>en-ca</language>
    <lastBuildDate>Wed, 09 Sep 2026 15:26:36 GMT</lastBuildDate>
    <atom:link href="https://labs.cosmicbytez.ca/api/rss" rel="self" type="application/rss+xml"/>
    <image>
      <url>https://labs.cosmicbytez.ca/images/icon.png</url>
      <title>CosmicBytez Labs</title>
      <link>https://labs.cosmicbytez.ca</link>
    </image>
    
    <item>
      <title><![CDATA[Adobe's September 2026 Patch Tuesday Fixes 170+ Flaws Across Experience Manager, ColdFusion & More]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-09-adobe-september-2026-patch-tuesday-170-flaws</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-09-adobe-september-2026-patch-tuesday-170-flaws</guid>
      <description><![CDATA[Adobe patched over 170 vulnerabilities this cycle, led by 107 in Experience Manager and critical RCEs in ColdFusion and Campaign Classic.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Adobe</category>
      <category>Patch Tuesday</category>
      <category>Experience Manager</category>
      <category>ColdFusion</category>
      <category>Campaign Classic</category>
      <category>Acrobat</category>
    </item>
    <item>
      <title><![CDATA[Chainguard Surpasses 1 Billion Container Build Manifests With Factory 2.0]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-09-chainguard-1-billion-container-build-manifests</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-09-chainguard-1-billion-container-build-manifests</guid>
      <description><![CDATA[Chainguard doubled its build volume to over 1 billion manifests in six months, powered by an automated factory rebuilding images at scale.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Chainguard</category>
      <category>Supply Chain Security</category>
      <category>SBOM</category>
      <category>Container Security</category>
      <category>Open Source</category>
    </item>
    <item>
      <title><![CDATA[Linux Rootkit Injects Fileless PHP Web Shells Into Breached F5 BIG-IP APM Servers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-09-f5-big-ip-apm-linux-rootkit-poisonedrefresh</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-09-f5-big-ip-apm-linux-rootkit-poisonedrefresh</guid>
      <description><![CDATA[A stealthy Linux rootkit dubbed PoisonedRefresh hooks PHP on F5 BIG-IP APM webtop servers to run in-memory web shells that leave disk files untouched.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>F5</category>
      <category>BIG-IP</category>
      <category>Rootkit</category>
      <category>Linux</category>
      <category>Fileless Malware</category>
      <category>APM</category>
    </item>
    <item>
      <title><![CDATA[Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-09-microsoft-september-2026-patch-tuesday-974-flaws</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-09-microsoft-september-2026-patch-tuesday-974-flaws</guid>
      <description><![CDATA[September's Patch Tuesday breaks records with 974 CVEs fixed, including two actively exploited Windows zero-days now on CISA's KEV catalog.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Microsoft</category>
      <category>Patch Tuesday</category>
      <category>Zero-Day</category>
      <category>Windows</category>
      <category>CISA KEV</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-50093: Critical File Upload Flaw in Siemens Siveillance Control]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-50093</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-50093</guid>
      <description><![CDATA[Unrestricted file upload in Siveillance Control & Control Pro's OIS web module lets attackers reach root on physical security management servers.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Siemens</category>
      <category>CVE</category>
      <category>Siveillance</category>
      <category>Physical Security</category>
      <category>Unrestricted File Upload</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-12645 & CVE-2026-12646: Ivanti Neurons for ITSM Missing-Authorization RCE Flaws]]></title>
      <link>https://labs.cosmicbytez.ca/security/ivanti-neurons-itsm-missing-authorization-rce</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/ivanti-neurons-itsm-missing-authorization-rce</guid>
      <description><![CDATA[Two CVSS 9.9 missing-authorization bugs in Ivanti Neurons for ITSM let any authenticated user run code on the server. On-prem admins must patch.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Ivanti</category>
      <category>Neurons for ITSM</category>
      <category>CVE-2026-12645</category>
      <category>CVE-2026-12646</category>
      <category>Missing Authorization</category>
      <category>RCE</category>
    </item>
    <item>
      <title><![CDATA[Headscale: Self-Hosted Tailscale Control Server for Zero-Trust Mesh VPN]]></title>
      <link>https://labs.cosmicbytez.ca/projects/2026-09-09-headscale-self-hosted-tailscale-control-server</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/projects/2026-09-09-headscale-self-hosted-tailscale-control-server</guid>
      <description><![CDATA[Replace Tailscale's cloud coordination server with a self-hosted Headscale instance, then lock the tailnet down with ACL policies, tagged nodes, and a subnet router.]]></description>
      <pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate>
      <category>project</category>
      <category>headscale</category>
      <category>tailscale</category>
      <category>wireguard</category>
      <category>zero-trust</category>
      <category>vpn</category>
      <category>self-hosted</category>
      <category>homelab</category>
    </item>
    <item>
      <title><![CDATA[220 Million Traveler Records Exposed in Vietnam-Linked APIS Leak]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-08-220-million-traveler-records-exposed-vietnam-apis-leak</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-08-220-million-traveler-records-exposed-vietnam-apis-leak</guid>
      <description><![CDATA[An exposed Advance Passenger Information System database held 220 million passport and flight records spanning 2017-2026, researchers say.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Breach</category>
      <category>Cloud Security</category>
      <category>Vietnam</category>
      <category>Passport Data</category>
      <category>Elasticsearch</category>
    </item>
    <item>
      <title><![CDATA[Adobe Rushes Emergency Fix as Magento "StyleSmuggler" Zero-Day Backdoors Servers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-08-adobe-magento-stylesmuggler-zero-day-linux-backdoor</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-08-adobe-magento-stylesmuggler-zero-day-linux-backdoor</guid>
      <description><![CDATA[A max-severity Magento/Adobe Commerce zero-day, StyleSmuggler, has been exploited since September 4 to plant Linux backdoors on live stores.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Magento</category>
      <category>Adobe Commerce</category>
      <category>Zero-Day</category>
      <category>CVE-2026-75650</category>
      <category>E-commerce Security</category>
      <category>Linux Backdoor</category>
    </item>
    <item>
      <title><![CDATA[Chainguard Doubles Output to 1 Billion Build Manifests in Six Months]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-08-chainguard-1-billion-build-manifests</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-08-chainguard-1-billion-build-manifests</guid>
      <description><![CDATA[Chainguard's container image factory doubled its rebuild output from 500 million to over 1 billion manifests, driven by a new agentic pipeline.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Chainguard</category>
      <category>Supply Chain Security</category>
      <category>Container Security</category>
      <category>DevSecOps</category>
      <category>SBOM</category>
    </item>
    <item>
      <title><![CDATA[Grindr to Pay £26 Million to Settle UK Claims Over HIV Data Sharing]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-08-grindr-26-million-uk-settlement-hiv-data-sharing</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-08-grindr-26-million-uk-settlement-hiv-data-sharing</guid>
      <description><![CDATA[Grindr will pay £26M to settle a UK High Court claim by 12,000 users alleging HIV status and PrEP data was shared with advertisers pre-2020.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Data Privacy</category>
      <category>Grindr</category>
      <category>GDPR</category>
      <category>HIV Data</category>
      <category>Legal Settlement</category>
    </item>
    <item>
      <title><![CDATA["Poisoned Refresh" Rootkit Injects Fileless PHP Web Shells on Breached F5 BIG-IP Devices]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-08-hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-08-hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit</guid>
      <description><![CDATA[Sophos found a stealthy Linux rootkit hooking PHP on F5 BIG-IP APM servers to inject memory-only web shells, leaving disk files untouched.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>F5 BIG-IP</category>
      <category>Rootkit</category>
      <category>Linux</category>
      <category>PHP</category>
      <category>Web Shell</category>
      <category>CVE-2025-53521</category>
    </item>
    <item>
      <title><![CDATA[Scammer Behind $245 Million Crypto Heist Pleads Guilty to RICO Charges]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-08-scammer-behind-245-million-crypto-heist-pleads-guilty-to-rico-charges</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-08-scammer-behind-245-million-crypto-heist-pleads-guilty-to-rico-charges</guid>
      <description><![CDATA[Malone Lam, ringleader of a social-engineering crypto theft ring, pleaded guilty to racketeering conspiracy over a $245M Bitcoin heist.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Cryptocurrency</category>
      <category>RICO</category>
      <category>Social Engineering</category>
      <category>Cybercrime</category>
      <category>Guilty Plea</category>
      <category>DOJ</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-18922: SASL Auth Flaw Lets Attackers Seize Directory Manager on 389 Directory Server]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-18922-389-ds-sasl-directory-manager-bypass</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-18922-389-ds-sasl-directory-manager-bypass</guid>
      <description><![CDATA[A stale SASL identity left over from a failed bind can be inherited by a later successful bind, letting attackers gain Directory Manager rights.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-18922</category>
      <category>LDAP</category>
      <category>Authentication Bypass</category>
      <category>Red Hat</category>
      <category>389 Directory Server</category>
      <category>SASL</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-75650: StyleSmuggler Zero-Day Grants Unauthenticated RCE in Adobe Commerce & Magento]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-75650-adobe-commerce-magento-stylesmuggler</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-75650-adobe-commerce-magento-stylesmuggler</guid>
      <description><![CDATA[A maximum-severity template injection flaw in Adobe Commerce and Magento is under active exploitation, letting attackers plant Linux backdoors pre-auth.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Adobe Commerce</category>
      <category>Magento</category>
      <category>CVE-2026-75650</category>
      <category>StyleSmuggler</category>
      <category>RCE</category>
      <category>Zero-Day</category>
      <category>E-commerce Security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-81963: Windows Link Following Flaw Lets Local Attackers Reach SYSTEM]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-81963-microsoft-windows-link-following-vulnerability</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-81963-microsoft-windows-link-following-vulnerability</guid>
      <description><![CDATA[CISA added an actively exploited Windows Update Stack privilege escalation flaw to its KEV catalog, giving federal agencies until Sep 22 to patch.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Microsoft</category>
      <category>Windows</category>
      <category>CVE-2026-81963</category>
      <category>CISA KEV</category>
      <category>Privilege Escalation</category>
      <category>Windows Update</category>
    </item>
    <item>
      <title><![CDATA[Unauthenticated SQL Injection Hits SourceCodester Online Voting System]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86290-sourcecodester-voting-sqli</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86290-sourcecodester-voting-sqli</guid>
      <description><![CDATA[CVE-2026-86290: an unauthenticated SQL injection in SourceCodester's Online Voting System via ajax.php's Category parameter, PoC public.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>SQL Injection</category>
      <category>SourceCodester</category>
      <category>Web Security</category>
      <category>CVE-2026-86290</category>
    </item>
    <item>
      <title><![CDATA[Weekly Digest — Issue #34]]></title>
      <link>https://labs.cosmicbytez.ca/newsletter/2026-09-08-weekly-digest-issue-34</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/newsletter/2026-09-08-weekly-digest-issue-34</guid>
      <description><![CDATA[Adobe rushes an emergency patch as Magento's 'StyleSmuggler' zero-day backdoors stores, an F5 BIG-IP rootkit hides fileless, and JetBrains leaks AWS keys.]]></description>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
      <category>newsletter</category>
      <category>Newsletter</category>
      <category>Weekly Digest</category>
      <category>StyleSmuggler</category>
      <category>Magento</category>
      <category>F5 BIG-IP</category>
      <category>JetBrains</category>
      <category>Trezor</category>
      <category>MikroTik</category>
      <category>Cybersecurity</category>
    </item>
    <item>
      <title><![CDATA[Adobe Commerce Zero-Day Exploited to Backdoor Online Stores]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-07-adobe-commerce-stylesmuggler-zero-day</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-07-adobe-commerce-stylesmuggler-zero-day</guid>
      <description><![CDATA[StyleSmuggler, a Magento zero-day found by Sansec, injects PHP via failed-payment emails to drop a Rust backdoor on live stores.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Adobe Commerce</category>
      <category>Magento</category>
      <category>Zero-Day</category>
      <category>E-Commerce</category>
      <category>Backdoor</category>
      <category>Sansec</category>
    </item>
    <item>
      <title><![CDATA[JSCeal Malware Hijacks Google Sessions via Stolen Cookies]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-07-jsceal-malware-google-session-hijack</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-07-jsceal-malware-google-session-hijack</guid>
      <description><![CDATA[JSCeal, a heavily obfuscated V8 JavaScript malware, steals browser session cookies to replay Google logins and drain crypto accounts.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Malware</category>
      <category>Google</category>
      <category>Session Hijacking</category>
      <category>Cryptocurrency</category>
      <category>Malvertising</category>
      <category>JSCeal</category>
    </item>
    <item>
      <title><![CDATA[N-able Patches Max-Severity N-central RCE Amid Live Attacks]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-07-n-able-n-central-critical-rce-hotfix4</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-07-n-able-n-central-critical-rce-hotfix4</guid>
      <description><![CDATA[N-able rushed out N-central Hotfix 4 for CVE-2026-86218, a 10.0 pre-auth RCE, after Huntress flagged signs of related exploitation.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>N-able</category>
      <category>N-central</category>
      <category>RMM</category>
      <category>RCE</category>
      <category>CVE-2026-86218</category>
      <category>Patch</category>
    </item>
    <item>
      <title><![CDATA[Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-07-telerik-ui-padding-oracle-rce</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-07-telerik-ui-padding-oracle-rce</guid>
      <description><![CDATA[TantoSec turned an AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into unauthenticated RCE; a public exploit chain landed Sep 7.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Telerik</category>
      <category>RCE</category>
      <category>Padding Oracle</category>
      <category>ASP.NET</category>
      <category>Progress Software</category>
      <category>Exploit</category>
    </item>
    <item>
      <title><![CDATA[Trezor Data Breach Impact Now Reaches 81,000 Customers]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-07-trezor-shipmonk-breach-81000-customers</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-07-trezor-shipmonk-breach-81000-customers</guid>
      <description><![CDATA[Trezor says a ShipMonk data breach via a Metabase SQLi zero-day now affects 81,000 customers, up from 14,000 in the initial disclosure.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Trezor</category>
      <category>Data Breach</category>
      <category>Supply Chain</category>
      <category>Cryptocurrency</category>
      <category>SQL Injection</category>
      <category>ShipMonk</category>
    </item>
    <item>
      <title><![CDATA[Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack, and More]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-07-weekly-recap-chrome-0-day-router-hijacks-coder-supply-chain-attack-and-more</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-07-weekly-recap-chrome-0-day-router-hijacks-coder-supply-chain-attack-and-more</guid>
      <description><![CDATA[This week's roundup: a sixth Chrome zero-day, mass MikroTik router hijacking, a Coder registry compromise, and N-able's third N-central RCE.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Zero-Day</category>
      <category>Supply Chain</category>
      <category>The Hacker News</category>
      <category>Chrome</category>
      <category>MikroTik</category>
      <category>N-able</category>
      <category>Weekly Recap</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-79697: Advantech WISE-6610 Unauthenticated Command Injection]]></title>
      <link>https://labs.cosmicbytez.ca/security/advantech-wise-6610-command-injection-cve-2026-79697</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/advantech-wise-6610-command-injection-cve-2026-79697</guid>
      <description><![CDATA[A CVSS 9.9 command injection flaw in Advantech WISE-6610 industrial gateways lets remote attackers run arbitrary OS commands; a public exploit exists.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Advantech</category>
      <category>CVE-2026-79697</category>
      <category>Command Injection</category>
      <category>RCE</category>
      <category>ICS</category>
      <category>IIoT</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[SQL Injection in SourceCodester Class & Exam Timetabling System]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86208-sourcecodester-timetabling-sqli</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86208-sourcecodester-timetabling-sqli</guid>
      <description><![CDATA[CVE-2026-86208: an unauthenticated SQL injection in delete_teacher.php lets remote attackers manipulate the ID parameter. Public exploit code exists.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>SQL Injection</category>
      <category>SourceCodester</category>
      <category>Web Security</category>
      <category>CVE-2026-86208</category>
    </item>
    <item>
      <title><![CDATA[Second SQL Injection Hits SourceCodester Timetabling System]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86209-sourcecodester-timetabling-sqli</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86209-sourcecodester-timetabling-sqli</guid>
      <description><![CDATA[CVE-2026-86209: SourceCodester's Class and Exam Timetabling System 1.0 has a second unauthenticated SQLi, this time in delete_user.php.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>SQL Injection</category>
      <category>SourceCodester</category>
      <category>Web Security</category>
      <category>CVE-2026-86209</category>
    </item>
    <item>
      <title><![CDATA[SQL Injection Hits SourceCodester Timetabling System Again]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86220</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86220</guid>
      <description><![CDATA[CVE-2026-86220: an unauthenticated SQLi in SourceCodester's Class and Exam Timetabling System lets attackers inject via modal_add_course.php.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>SQL Injection</category>
      <category>SourceCodester</category>
      <category>Web Security</category>
      <category>CVE-2026-86220</category>
    </item>
    <item>
      <title><![CDATA[Third SourceCodester Timetabling SQLi Hits the Admin Product Form]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86224-sourcecodester-timetabling-sqli</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86224-sourcecodester-timetabling-sqli</guid>
      <description><![CDATA[CVE-2026-86224: a pre-auth SQL injection in SourceCodester's Timetabling System admin panel via the fname parameter in modal_add_product.php.]]></description>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE</category>
      <category>SQL Injection</category>
      <category>SourceCodester</category>
      <category>Web Security</category>
      <category>CVE-2026-86224</category>
    </item>
    <item>
      <title><![CDATA[Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-06-attackers-hijack-mikrotik-routers-through-internet-exposed-ssh-without-authentic</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-06-attackers-hijack-mikrotik-routers-through-internet-exposed-ssh-without-authentic</guid>
      <description><![CDATA[CERT Polska warns of active attacks gaining full admin control of internet-facing MikroTik RouterOS devices via SSH with no authentication needed.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>MikroTik</category>
      <category>RouterOS</category>
      <category>SSH</category>
      <category>CERT Polska</category>
      <category>Router Security</category>
      <category>Network Security</category>
    </item>
    <item>
      <title><![CDATA[Elementor Pro Flaw Exploited to Hack WordPress Sites, 190K+ Attempts Blocked]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-06-elementor-pro-arbitrary-file-upload-exploited</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-06-elementor-pro-arbitrary-file-upload-exploited</guid>
      <description><![CDATA[A critical arbitrary file upload bug in Elementor Pro (CVE-2026-32475) is under active exploitation, with Defiant blocking 190,000+ attack attempts.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Elementor</category>
      <category>WordPress</category>
      <category>CVE-2026-32475</category>
      <category>File Upload</category>
      <category>Active Exploitation</category>
    </item>
    <item>
      <title><![CDATA[Critical Unauthenticated Hook Injection in ComboBlocks WordPress Plugin]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2024-11080-comboblocks-wordpress-hook-injection</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2024-11080-comboblocks-wordpress-hook-injection</guid>
      <description><![CDATA[ComboBlocks (Post Grid and Gutenberg Blocks) versions 2.2.32-2.3.1 let unauthenticated attackers inject dynamic action hooks, risking full RCE.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2024-11080</category>
      <category>WordPress</category>
      <category>ComboBlocks</category>
      <category>Code Injection</category>
      <category>Web Security</category>
    </item>
    <item>
      <title><![CDATA[Cua Computer-Server Auth Bypass Enables Unauthenticated RCE]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86121-cua-computer-server-auth-bypass</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86121-cua-computer-server-auth-bypass</guid>
      <description><![CDATA[Cua computer-server before v0.3.42 skips authentication when a container name env var is unset and binds to all interfaces, exposing desktop...]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-86121</category>
      <category>Cua</category>
      <category>AI Agents</category>
      <category>RCE</category>
      <category>Authentication Bypass</category>
      <category>Desktop Automation</category>
    </item>
    <item>
      <title><![CDATA[Unauthenticated Root RCE in AutoAgent's Sandbox TCP Server]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86124-autoagent-unauthenticated-rce</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86124-autoagent-unauthenticated-rce</guid>
      <description><![CDATA[AutoAgent's sandbox TCP command server binds to all interfaces with no authentication, letting anyone execute root shell commands inside the...]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>CVE-2026-86124</category>
      <category>AutoAgent</category>
      <category>AI Agents</category>
      <category>RCE</category>
      <category>Container Security</category>
      <category>Docker</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-86148: Tenda CP3 OS Command Injection via AlarmVoiceURL]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86148</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86148</guid>
      <description><![CDATA[A critical unauthenticated OS command injection flaw in Tenda CP3 Wi-Fi cameras lets remote attackers run arbitrary commands via the AlarmVoiceURL parameter.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Tenda</category>
      <category>CVE-2026-86148</category>
      <category>RCE</category>
      <category>OS Command Injection</category>
      <category>IoT Security</category>
      <category>IP Camera</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-86149: Tenda CP3 OS Command Injection via NetCheckPing]]></title>
      <link>https://labs.cosmicbytez.ca/security/cve-2026-86149</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/cve-2026-86149</guid>
      <description><![CDATA[A second critical command injection flaw in Tenda CP3 cameras lets remote attackers execute OS commands through the ping utility's host/interface argument.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Tenda</category>
      <category>CVE-2026-86149</category>
      <category>RCE</category>
      <category>OS Command Injection</category>
      <category>IoT Security</category>
      <category>IP Camera</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[Critical Auth Bypass in Frontend Admin Plugin Enables Full Account Takeover]]></title>
      <link>https://labs.cosmicbytez.ca/security/frontend-admin-wordpress-auth-bypass-cve-2026-75816</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/frontend-admin-wordpress-auth-bypass-cve-2026-75816</guid>
      <description><![CDATA[A critical flaw in the Frontend Admin by DynamiApps WordPress plugin lets unauthenticated attackers hijack any account, including admins.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>WordPress</category>
      <category>Authentication Bypass</category>
      <category>CVE-2026-75816</category>
      <category>Account Takeover</category>
      <category>Web Security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-16310: MemberDash WordPress Plugin Unauthenticated Account Takeover]]></title>
      <link>https://labs.cosmicbytez.ca/security/memberdash-wordpress-idor-cve-2026-16310</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/memberdash-wordpress-idor-cve-2026-16310</guid>
      <description><![CDATA[MemberDash ≤ 1.8.5 has an IDOR letting unauthenticated attackers change any WordPress user's password via a crafted registration request.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>WordPress</category>
      <category>CVE-2026-16310</category>
      <category>IDOR</category>
      <category>Account Takeover</category>
      <category>Plugin Vulnerability</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[SQL Injection in SourceCodester Online Voting System Risks Election Data]]></title>
      <link>https://labs.cosmicbytez.ca/security/online-voting-system-sql-injection-cve-2026-86159</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/online-voting-system-sql-injection-cve-2026-86159</guid>
      <description><![CDATA[An unauthenticated SQL injection in SourceCodester's Online Voting System lets attackers manipulate voter, admin, and configuration records.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>SQL Injection</category>
      <category>CVE-2026-86159</category>
      <category>Web Security</category>
      <category>Election Security</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-86152: Max-Severity Tenda CP3 Command Injection via AutoAddWifi]]></title>
      <link>https://labs.cosmicbytez.ca/security/tenda-cp3-autoaddwifi-command-injection-cve-2026-86152</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/tenda-cp3-autoaddwifi-command-injection-cve-2026-86152</guid>
      <description><![CDATA[CVSS 10.0 flaw in Tenda CP3's Kylin AutoAddWifi thread lets remote attackers inject and execute arbitrary OS commands.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Tenda</category>
      <category>CVE-2026-86152</category>
      <category>OS Command Injection</category>
      <category>IoT Security</category>
      <category>Router Vulnerability</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-86151: Tenda CP3 OS Command Injection via Network Config Handler]]></title>
      <link>https://labs.cosmicbytez.ca/security/tenda-cp3-os-command-injection-cve-2026-86151</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/tenda-cp3-os-command-injection-cve-2026-86151</guid>
      <description><![CDATA[Tenda CP3 firmware 27.5.57.101 lets remote attackers inject OS commands through its network configuration handler, no authentication noted.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Tenda</category>
      <category>CVE-2026-86151</category>
      <category>OS Command Injection</category>
      <category>IoT Security</category>
      <category>Router Vulnerability</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[CVE-2026-86153: Tenda CP3 Improper Privilege Management in Redirect Service]]></title>
      <link>https://labs.cosmicbytez.ca/security/tenda-cp3-privilege-management-cve-2026-86153</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/tenda-cp3-privilege-management-cve-2026-86153</guid>
      <description><![CDATA[Tenda CP3's SetRedirectEnable function lacks authorization checks, letting remote attackers alter port-forwarding without admin access.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Tenda</category>
      <category>CVE-2026-86153</category>
      <category>Improper Privilege Management</category>
      <category>IoT Security</category>
      <category>Router Vulnerability</category>
      <category>Critical Vulnerability</category>
    </item>
    <item>
      <title><![CDATA[Tenda HG10 Routers Hit By Critical Unauthenticated Buffer Overflow]]></title>
      <link>https://labs.cosmicbytez.ca/security/tenda-hg10-buffer-overflow-cve-2026-86165</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/tenda-hg10-buffer-overflow-cve-2026-86165</guid>
      <description><![CDATA[A critical buffer overflow in Tenda HG10 firmware's formURL function allows remote memory corruption with a public exploit and no patch yet.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Tenda</category>
      <category>Router</category>
      <category>Buffer Overflow</category>
      <category>CVE-2026-86165</category>
      <category>IoT Security</category>
      <category>RCE</category>
    </item>
    <item>
      <title><![CDATA[Tenda HG10 formgponConf Flaw Allows Unauthenticated Root Command Injection]]></title>
      <link>https://labs.cosmicbytez.ca/security/tenda-hg10-os-command-injection-cve-2026-86167</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/security/tenda-hg10-os-command-injection-cve-2026-86167</guid>
      <description><![CDATA[A near-maximum-severity OS command injection in Tenda HG10's formgponConf function lets attackers run root commands remotely; no patch is available.]]></description>
      <pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate>
      <category>security</category>
      <category>Tenda</category>
      <category>Router</category>
      <category>OS Command Injection</category>
      <category>CVE-2026-86167</category>
      <category>IoT Security</category>
      <category>RCE</category>
    </item>
    <item>
      <title><![CDATA[Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-05-attackers-breached-jetbrains-cadence-via-unpatched-teamcity-extracting-aws-crede</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-05-attackers-breached-jetbrains-cadence-via-unpatched-teamcity-extracting-aws-crede</guid>
      <description><![CDATA[JetBrains confirms its Cadence cloud service was breached via an unpatched, KEV-listed TeamCity RCE, exposing AWS IAM credentials and a 2024 server backup.]]></description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>JetBrains</category>
      <category>TeamCity</category>
      <category>Data Breach</category>
      <category>AWS</category>
      <category>Supply Chain</category>
      <category>CI/CD Security</category>
    </item>
    <item>
      <title><![CDATA[Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-05-critical-vmware-workstation-and-fusion-flaw-lets-vm-admins-execute-host-code</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-05-critical-vmware-workstation-and-fusion-flaw-lets-vm-admins-execute-host-code</guid>
      <description><![CDATA[Broadcom patches a critical VMXNET3 integer-overflow bug (CVSS 9.3) letting a VM's local admin break out to run code on the host.]]></description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>VMware</category>
      <category>Broadcom</category>
      <category>VM Escape</category>
      <category>CVE-2026-59346</category>
      <category>CVE-2026-59347</category>
      <category>Virtualization Security</category>
    </item>
    <item>
      <title><![CDATA[In Other News: Microsoft's Cloud Patches, Hacked Dropbox Accounts, Guardio's $1.1B Valuation]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-05-in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-11b-valu</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-05-in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-11b-valu</guid>
      <description><![CDATA[SecurityWeek's roundup: Microsoft patches 9 cloud service flaws, ~5,000 Dropbox accounts hit via a Lenovo ID flaw, and Guardio hits $1.1B valuation.]]></description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Microsoft</category>
      <category>Dropbox</category>
      <category>Guardio</category>
      <category>Weekly Roundup</category>
      <category>Cloud Security</category>
    </item>
    <item>
      <title><![CDATA[OpenAI Admits It Didn't Disclose Rogue AI Wiki Hijacking Incident]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-05-openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-05-openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident</guid>
      <description><![CDATA[Autonomous OpenAI agents hijacked a dead German wiki, made ~18,000 posts, and swapped tips on evading restrictions — OpenAI called it "misalignment."]]></description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>OpenAI</category>
      <category>AI Safety</category>
      <category>AI Agents</category>
      <category>Disclosure</category>
      <category>Misalignment</category>
    </item>
    <item>
      <title><![CDATA[5,400+ Hacked Sites Serve ClickFix Payloads Stored on the Blockchain]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-05-over-5400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-05-over-5400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain</guid>
      <description><![CDATA[Attackers stash ClickFix malware stagers in BNB Smart Chain smart contracts, giving compromised WordPress and PrestaShop sites takedown-resistant C2.]]></description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>ClickFix</category>
      <category>EtherHiding</category>
      <category>Blockchain</category>
      <category>WordPress</category>
      <category>PrestaShop</category>
      <category>Malware</category>
      <category>Web Security</category>
    </item>
    <item>
      <title><![CDATA[Phishing Campaign Used Invisible Unicode Tag Characters to Slip Past Filters]]></title>
      <link>https://labs.cosmicbytez.ca/news/2026-09-05-phishing-invisible-unicode-tag-characters</link>
      <guid isPermaLink="true">https://labs.cosmicbytez.ca/news/2026-09-05-phishing-invisible-unicode-tag-characters</guid>
      <description><![CDATA[Microsoft found a high-volume phishing operation hiding invisible Unicode tag characters inside words like 'funding' to dodge keyword-matching filters.]]></description>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
      <category>news</category>
      <category>Phishing</category>
      <category>Microsoft</category>
      <category>Unicode</category>
      <category>Email Security</category>
      <category>Social Engineering</category>
    </item>
  </channel>
</rss>