SecNoteMorning brief
Latest sync Aug 28, 10:22 PM
1 down

Reading Queue

Help
TodayActionsStack WatchFeedIntelligence
More
VendorMalwareRed TeamAIGlobal RiskUSWorld
HelpMethodologySourcesPrivacy

Queue triage

All feed: 14 matches for "GitHub"

Top item: Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name

Action filterAll items
Showing14Saved0Sources down1

Feed counts show matched items; visible rows may be lower when repeated EPSS/CVE-only items are grouped for readability.

Reading Queue

Showing 14 of 14 visible rows.

Current state
More filters
criticalVulnerability

Pimcore Vulnerable to Remote Code Execution via DataObject Class-Definition Field Name

GitHub Advisories | Aug 28, 2026

## Overview A DataObject **class-definition field name** is concatenated, without an identifier allowlist, into the PHP class source that Pimcore generates for every DataObject class (`protected $ ;`). A user holding only the ordinary `objects` (DataObjects) permission can imp...

Evidence and analyst toolsscore 85
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:17 PM UTC
Score inputsbase score 85, priority score 103, critical severity, 1 CVE, GitHub security advisory, Packages: pimcore/pimcore, pimcore/pimcore
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#pimcore/pimcore#CVE-2026-55634
Sigma searchNuclei searchSentinel search
criticalVulnerability

Pimcore Hotspotimage getDataFromResource() unrestricted Serialize::unserialize over object-store column (PHP Object Injection, CWE-502)

GitHub Advisories | Aug 28, 2026

## Summary `Pimcore\Model\DataObject\ClassDefinition\Data\Hotspotimage::getDataFromResource()` deserializes the `*__hotspots` object-store column through the `Pimcore\Tool\Serialize::unserialize()` wrapper **without a class allowlist** (the wrapper's `$allowedClasses` paramete...

Evidence and analyst toolsscore 85
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:13 PM UTC
Score inputsbase score 85, priority score 103, critical severity, 1 CVE, GitHub security advisory, Packages: pimcore/pimcore, pimcore/pimcore
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#pimcore/pimcore#CVE-2026-55220
Sigma searchNuclei searchSentinel search
criticalVulnerabilityPatch

plone.app.event vulnerable to denial of service via iCalendar import

GitHub Advisories | Aug 28, 2026

### Impact By abusing the iCalendar import functionality, a logged-in editor could take the whole site offline, make the server reach into the internal network and read calendar files off disk (SSRF), and store XSS. ### Patches The problem has been patched in `plone.app.event`...

Evidence and analyst toolsscore 85
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 6:59 PM UTC
Score inputsbase score 85, priority score 103, critical severity, 1 CVE, GitHub security advisory, Packages: plone.app.event, plone.app.event, Patch
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#plone.app.event#CVE-2026-55247
Sigma searchNuclei searchSentinel search
highVulnerability

SeaweedFS: Path traversal in the S3 gateway X-Amz-Copy-Source header allows cross-bucket object read

GitHub Advisories | Aug 28, 2026

### Summary The SeaweedFS S3 API gateway did not reject `..` path segments in the `X-Amz-Copy-Source` header used by `CopyObject` and `UploadPartCopy`. The request URL path was hardened against traversal in 4.30 (CVE-2026-54917), but the copy-source header was only checked for...

Evidence and analyst toolsscore 72
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 10:17 PM UTC
Score inputsbase score 72, priority score 90, high severity, 1 CVE, EPSS 1%, GitHub security advisory, Packages: github.com/seaweedfs/seaweedfs
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided
#GitHub#open-source#github.com/seaweedfs/seaweedfs#CVE-2026-55874
Sigma searchNuclei searchSentinel search
EPSS 0.6%
highVulnerability

Fortigate syslog message parser can be exploited to modify or delete fields from the original message

GitHub Advisories | Aug 28, 2026

### Impact A security issue has been identified in Graylog affecting the parsing of syslog messages that use a key-value format, such as those generated by Fortigate devices. The vulnerability allows attackers to overwrite individual message fields, or to produce invalid messa...

Evidence and analyst toolsscore 72
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 10:13 PM UTC
Score inputsbase score 72, priority score 90, high severity, 1 CVE, GitHub security advisory, Packages: org.graylog2:graylog2-server, org.graylog2:graylog2-server, org.graylog2:graylog2-server
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#org.graylog2:graylog2-server#CVE-2026-55841
Sigma searchNuclei searchSentinel search
highVulnerability

klever-go: SFT add-quantity `int64` overflow bypasses a finite per-nonce MaxSupply

GitHub Advisories | Aug 28, 2026

## Summary On the SFT add-quantity path the only supply bound is `SFTAddCirculation`, which does `meta.Circulation += amount` with **no overflow guard**, then checks `if meta.Circulation > meta.MaxSupply && meta.MaxSupply != 0`. If `amount` overflows `int64` and wraps **negati...

Evidence and analyst toolsscore 72
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 10:08 PM UTC
Score inputsbase score 72, priority score 90, high severity, 1 CVE, GitHub security advisory, Packages: github.com/klever-io/klever-go
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#github.com/klever-io/klever-go#CVE-2026-55764
Sigma searchNuclei searchSentinel search
highVulnerability

Portainer has Unauthenticated Restore Endpoint that Allows Admin Takeover on Uninitialized Instances

GitHub Advisories | Aug 28, 2026

## Summary Portainer supports restoring an instance from a backup archive via the /api/restore endpoint. This endpoint is intentionally unauthenticated to allow restoring before the first admin account is created, and remains accessible for the five-minute initialization windo...

Evidence and analyst toolsscore 72
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 8:28 PM UTC
Score inputsbase score 72, priority score 90, high severity, 1 CVE, EPSS 0%, GitHub security advisory, Packages: github.com/portainer/portainer, github.com/portainer/portainer
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided
#GitHub#open-source#github.com/portainer/portainer#CVE-2026-55761
Sigma searchNuclei searchSentinel search
EPSS 0.5%
highVulnerability

klever-go: Percentage-transfer royalty skips the source debit at exactly-100% splits

GitHub Advisories | Aug 28, 2026

## Summary In `processPercentageRoyaltiesTransfer` the royalty pool is collected from the sender by `SubFromBalance` that is ordered **after** the split loop and after `if royaltiesToPay royaltiesToPay`), so a split entry of **exactly 100%** (`PercentTransferPercentage = 10000...

Evidence and analyst toolsscore 72
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 8:27 PM UTC
Score inputsbase score 72, priority score 90, high severity, 1 CVE, GitHub security advisory, Packages: github.com/klever-io/klever-go
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#github.com/klever-io/klever-go#CVE-2026-55763
Sigma searchNuclei searchSentinel search
highVulnerability

alos-http has unauthenticated remote DoS: malformed path starting with "?" triggers out-of-bounds panic in sanitizeRequestPath, crashing entire server

GitHub Advisories | Aug 28, 2026

### Summary A single unauthenticated HTTP request to a path starting with `?` (e.g. `GET ? HTTP/1.1`) crashes the entire server process. The request line parser passes the path to `sanitizeRequestPath` which indexes the first byte of the path after stripping the query string. ...

Evidence and analyst toolsscore 71
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:19 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, GitHub security advisory, Packages: github.com/guno1928/alos-http
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#github.com/guno1928/alos-http#CVE-2026-55484
Sigma searchNuclei searchSentinel search
highVulnerability

Pimcore: Insufficient Permission Check on Class Definition Creation Endpoint Allows Privilege Escalation

GitHub Advisories | Aug 28, 2026

### Summary The Studio API class definition creation endpoint in `pimcore/studio-backend-bundle` is guarded by the `objects` permission instead of the `classes` permission, allowing any standard editor-level user to create class definitions without admin privileges. Class defi...

Evidence and analyst toolsscore 71
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:05 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, EPSS 0%, GitHub security advisory, Packages: pimcore/studio-backend-bundle, pimcore/studio-backend-bundle
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided
#GitHub#open-source#pimcore/studio-backend-bundle#CVE-2026-55212
Sigma searchNuclei searchSentinel search
EPSS 0.4%
highVulnerability

Pimcore: SQL Injection via Column Name in DateFilter allows authenticated user to extract arbitrary database data including admin password hashes

GitHub Advisories | Aug 28, 2026

## Summary An authenticated user extracts the admin password hash and any other database content through a time-based blind SQL injection in the `DateFilter` column key parameter. The `POST /pimcore-studio/api/website-settings` endpoint (and 11 other listing endpoints) accepts...

Evidence and analyst toolsscore 71
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:04 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, EPSS 0%, GitHub security advisory, Packages: pimcore/studio-backend-bundle, pimcore/studio-backend-bundle
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided
#GitHub#open-source#pimcore/studio-backend-bundle#CVE-2026-55208
Sigma searchNuclei searchSentinel search
EPSS 0.4%
highVulnerability

Pimcore: Account Takeover via Password Reset URL Injection allows unauthenticated attacker to hijack any admin account with 2FA bypass

GitHub Advisories | Aug 28, 2026

## Summary An unauthenticated attacker takes over any Pimcore admin account by sending a password reset request with an attacker-controlled `resetPasswordUrl`. The server generates a real cryptographic recovery token, appends it to the attacker's URL, and emails the link to th...

Evidence and analyst toolsscore 71
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:04 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, EPSS 1%, GitHub security advisory, Packages: pimcore/studio-backend-bundle, pimcore/studio-backend-bundle
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided
#GitHub#open-source#pimcore/studio-backend-bundle#CVE-2026-55207
Sigma searchNuclei searchSentinel search
EPSS 0.7%
highVulnerability

MariaDB's connector leaks the cleartext password to an MitM despite `ssl: true`

GitHub Advisories | Aug 28, 2026

### Summary When SSL/TLS is enabled but no CA / server certificate is provided, the connector verifies the server's identity using fingerprint validation. The check is effective, the connection is ultimately rejected when it fails, but it happens *after* the authentication exc...

Evidence and analyst toolsscore 71
Sourceapi | ok | GitHub Advisories
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Aug 28, 2026, 7:03 PM UTC
Score inputsbase score 71, priority score 89, high severity, 1 CVE, GitHub security advisory, Packages: mariadb, mariadb, mariadb
ConfidenceStructured/API source-backed signal.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#GitHub#open-source#mariadb#CVE-2026-55215
Sigma searchNuclei searchSentinel search
highCyber newsIdentity

Lessons Learned from CISA’s Recent GitHub Leak

KrebsOnSecurity | Jul 13, 2026

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months before being notified by...

Evidence and analyst toolsscore 46
Sourcerss | ok | KrebsOnSecurity
FetchedBriefing Aug 28, 2026, 10:22 PM UTC; source published Jul 13, 2026, 3:03 PM UTC
Score inputsbase score 46, priority score -19, high severity, KrebsOnSecurity feed item, Watchlist: CISA, AWS, Identity
ConfidencePublic source-backed signal; summary and tags are triage aids.
Stack matchNo configured Stack Watch match
Missing dataCVSS not provided; EPSS not provided
#CISA#AWS#KrebsOnSecurity
Sigma searchNuclei searchSentinel search
TrustSource health1 failed and 4 degraded sources in this run.

Source Health

69 sources
Coverage impact: failed: GDELT. degraded: NPR Politics, Defense.gov News, Federal Reserve Press, GovInfo Federal Register. Treat affected lanes as incomplete until refresh succeeds.

BleepingComputer

rss | 15 items

ok

The Hacker News

rss | 18 items

ok

SecurityWeek

rss | 10 items

ok

Dark Reading

rss | 18 items

ok

KrebsOnSecurity

rss | 10 items

ok

OpenAI News

rss | 8 items

ok

TechCrunch AI

rss | 10 items

ok

VentureBeat AI

rss | 7 items

ok

The Verge AI

rss | 8 items

ok

Google AI

rss | 10 items

ok

MIT News AI

rss | 8 items

ok

MIT Technology Review

rss | 6 items

ok

The Register AI/ML

rss | 8 items

ok

Google Project Zero

rss | 7 items

ok

CISA Advisories

rss | 18 items

ok

CISA ICS Advisories

rss | 8 items

ok

Microsoft Security

rss | 8 items

ok

Microsoft MSRC Updates

rss | 10 items

ok

Cisco Security Advisories

rss | 8 items

ok

Palo Alto Security Advisories

rss | 8 items

ok

FortiGuard Outbreak Alerts

rss | 8 items

ok

FortiGuard Threat Signal

rss | 8 items

ok

Chrome Releases

rss | 8 items

ok

Mozilla Security

rss | 8 items

ok

Unit 42

rss | 8 items

ok

Cisco Talos

rss | 8 items

ok

ESET WeLiveSecurity

rss | 8 items

ok

Malwarebytes Labs

rss | 8 items

ok

SentinelOne

rss | 6 items

ok

SANS Internet Storm Center

rss | 8 items

ok

CrowdStrike

rss | 7 items

ok

CyberScoop

rss | 8 items

ok

The Record

rss | 5 items

ok

DataBreaches.net

rss | 6 items

ok

BBC World

rss | 7 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 3 items

ok

NPR Politics

rss | 0 items | Source responded but no relevant items matched.

degraded

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian US Politics

rss | 5 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Politics

rss | 3 items

ok

Defense.gov News

rss | 0 items | Source responded but no relevant items matched.

degraded

Federal Reserve Press

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Federal Register

rss | 0 items | Source responded but no relevant items matched.

degraded

GovInfo Congressional Bills

rss | 6 items

ok

NPR News

rss | 8 items

ok

NPR National

rss | 8 items

ok

NPR Politics

rss | 6 items

ok

NYTimes U.S.

rss | 6 items

ok

NYTimes Politics

rss | 6 items

ok

The Guardian U.S.

rss | 6 items

ok

BBC U.S. & Canada

rss | 6 items

ok

BBC World

rss | 8 items

ok

BBC Business

rss | 6 items

ok

NPR World

rss | 8 items

ok

Al Jazeera

rss | 8 items

ok

The Guardian World

rss | 6 items

ok

The Guardian Business

rss | 6 items

ok

NYTimes World

rss | 6 items

ok

NYTimes Business

rss | 6 items

ok

CISA KEV

structured | 22 items

ok

GitHub Advisories

api | 24 items

ok

NVD Recent CVEs

api | 18 items

ok

FIRST EPSS

api | 20 items

ok

Hacker News

api | 5 items

ok

GDELT

api | 0 items | fetch failed

failed

1 source currently timed out or rejected the request. Refresh reruns every source, including failed pulls.

ScopeWatchlist75 terms used to highlight recurring products, tactics, and security topics.

Watchlist

CISAKEVzero-dayransomwareregulationtarifftradeexport controlsupply chaininitial accessidentityphishingAI securityprompt injectionmodel poisoningagentic AIdeepfakeMicrosoftWindowsAzureEntraActive DirectoryOktaCiscoPalo AltoFortinetIvantiVMware