CVE Alert: CVE-2026-106040 - kvcache-ai - Mooncake - https://www.redpacketsecurity.com/cve-alert-cve-2026-106040-kvcache-ai-mooncake/
RedPacket Security
CVE Alert: CVE-2026-106040 - kvcache-ai - Mooncake - RedPacket Security
Mooncake Store master through 0.3.13.post1 contains a missing authorization vulnerability that allows unauthenticated attackers to erase any object's disk
CVE Alert: CVE-2026-104073 - netbox-community - netbox - https://www.redpacketsecurity.com/cve-alert-cve-2026-104073-netbox-community-netbox/
RedPacket Security
CVE Alert: CVE-2026-104073 - netbox-community - netbox - RedPacket Security
NetBox versions 2.9.5 before 4.7.0 contain a server-side template injection vulnerability that allows a low-privileged user with the "Can add custom
CVE Alert: CVE-2026-83550 - Red Hat - Multicluster Global Hub - https://www.redpacketsecurity.com/cve-alert-cve-2026-83550-red-hat-multicluster-global-hub/
RedPacket Security
CVE Alert: CVE-2026-83550 - Red Hat - Multicluster Global Hub - RedPacket Security
A flaw was found in postgres-exporter. Due to the blank import of `net/http/pprof`, debug endpoints are exposed on the unauthenticated metrics listener. A
CVE Alert: CVE-2026-85523 - Felisify Information Technologies Industry and Trade Inc. - SambaBox - https://www.redpacketsecurity.com/cve-alert-cve-2026-85523-felisify-information-technologies-industry-and-trade-inc-sambabox/
RedPacket Security
CVE Alert: CVE-2026-85523 - Felisify Information Technologies Industry and Trade Inc. - SambaBox - RedPacket Security
Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Felisify Information Technologies Industry and
[QILIN] - Ransomware Victim: Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi - https://www.redpacketsecurity.com/qilin-ransomware-victim-ciftay-insaat-taahhut-ve-ticaret-anonim-sirketi/
RedPacket Security
[QILIN] - Ransomware Victim: Ciftay Insaat Taahhut Ve Ticaret Anonim Sirketi - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[QILIN] - Ransomware Victim: BNYH - https://www.redpacketsecurity.com/qilin-ransomware-victim-bnyh/
RedPacket Security
[QILIN] - Ransomware Victim: BNYH - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[PANZER] - Ransomware Victim: EDFelectronics - https://www.redpacketsecurity.com/panzer-ransomware-victim-edfelectronics/
RedPacket Security
[PANZER] - Ransomware Victim: EDFelectronics - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[UMBRA] - Ransomware Victim: Beni Suef Technological University – BTU - https://www.redpacketsecurity.com/umbra-ransomware-victim-beni-suef-technological-university-btu/
RedPacket Security
[UMBRA] - Ransomware Victim: Beni Suef Technological University – BTU - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[VEXY RANSOMWARE] - Ransomware Victim: KOOKABARRA JUICE - https://www.redpacketsecurity.com/vexy-ransomware-ransomware-victim-kookabarra-juice/
RedPacket Security
[VEXY RANSOMWARE] - Ransomware Victim: KOOKABARRA JUICE - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
CVE Alert: CVE-2026-101258 - Red Hat - Red Hat Enterprise Linux 10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-101258-red-hat-red-hat-enterprise-linux-10/
RedPacket Security
CVE Alert: CVE-2026-101258 - Red Hat - Red Hat Enterprise Linux 10 - RedPacket Security
A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell
CVE Alert: CVE-2026-106062 - Red Hat - Red Hat Enterprise Linux 10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-106062-red-hat-red-hat-enterprise-linux-10/
RedPacket Security
CVE Alert: CVE-2026-106062 - Red Hat - Red Hat Enterprise Linux 10 - RedPacket Security
A heap-based buffer overflow was found in GIMP’s DirectDraw Surface (DDS) loader. When loading a crafted DDS image, buffer sizes derived from width, height,
[QILIN] - Ransomware Victim: EPTISA - https://www.redpacketsecurity.com/qilin-ransomware-victim-eptisa/
RedPacket Security
[QILIN] - Ransomware Victim: EPTISA - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[TERMITE] - Ransomware Victim: Aon - https://www.redpacketsecurity.com/termite-ransomware-victim-aon/
RedPacket Security
[TERMITE] - Ransomware Victim: Aon - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
[SILENTRANSOMGROUP] - Ransomware Victim: Andersen Group - https://www.redpacketsecurity.com/silentransomgroup-ransomware-victim-andersen-group/
RedPacket Security
[SILENTRANSOMGROUP] - Ransomware Victim: Andersen Group - RedPacket Security
NOTE: No files or stolen information are exfiltrated, downloaded, taken, hosted, seen, reposted, or disclosed by RedPacket Security. Any legal issues relating
Insider Threat Management: Reduce Risk Without Losing Trust - https://www.redpacketsecurity.com/insider-threat-management-reduce-risk-without-losing-trust/
RedPacket Security
Insider Threat Management: Reduce Risk Without Losing Trust - RedPacket Security
Insider threat management is the work of reducing and responding to security risks involving people who have authorised access to an organisation’s systems or
CVE Alert: CVE-2026-93443 - IBM - Langflow OSS - https://www.redpacketsecurity.com/cve-alert-cve-2026-93443-ibm-langflow-oss/
RedPacket Security
CVE Alert: CVE-2026-93443 - IBM - Langflow OSS - RedPacket Security
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements
CVE Alert: CVE-2026-104335 - IBM - Langflow OSS - https://www.redpacketsecurity.com/cve-alert-cve-2026-104335-ibm-langflow-oss/
RedPacket Security
CVE Alert: CVE-2026-104335 - IBM - Langflow OSS - RedPacket Security
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper access control.
CVE Alert: CVE-2026-103360 - IBM - Langflow OSS - https://www.redpacketsecurity.com/cve-alert-cve-2026-103360-ibm-langflow-oss/
RedPacket Security
CVE Alert: CVE-2026-103360 - IBM - Langflow OSS - RedPacket Security
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to
CVE Alert: CVE-2026-88962 - IBM - Langflow OSS - https://www.redpacketsecurity.com/cve-alert-cve-2026-88962-ibm-langflow-oss/
RedPacket Security
CVE Alert: CVE-2026-88962 - IBM - Langflow OSS - RedPacket Security
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation.
CVE Alert: CVE-2026-101331 - IBM - Langflow OSS - https://www.redpacketsecurity.com/cve-alert-cve-2026-101331-ibm-langflow-oss/
RedPacket Security
CVE Alert: CVE-2026-101331 - IBM - Langflow OSS - RedPacket Security
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to insufficiently protected credentials.
CVE Alert: CVE-2026-93675 - IBM - Langflow OSS - https://www.redpacketsecurity.com/cve-alert-cve-2026-93675-ibm-langflow-oss/
RedPacket Security
CVE Alert: CVE-2026-93675 - IBM - Langflow OSS - RedPacket Security
IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion.