appsec.fyi · Sources

securityweek.com

18 curated AppSec resources from securityweek.com across 5 topics on appsec.fyi.

securityweek.com

Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-04-22.

Date Added Resource Excerpt
2026-04-22 2026Critical Apache Tika Vulnerability Leads to XXE InjectionXXECritical Apache Tika Vulnerability Leads to XXE Injection
2026-04-22 2026Are SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM DataSupply ChainAre SBOMs Failing? Supply Chain Attacks Rise as Security Teams Struggle With SBOM Data https://ift.tt/GMVqgjU
2026-04-22 2026Google Antigravity in Crosshairs of Security Researchers CybercriminalsRCEGoogle Antigravity in Crosshairs of Security Researchers, Cybercriminals https://ift.tt/ZgkxGsP
2026-04-16 2026Splunk Enterprise Update Patches Code Execution VulnerabilityRCESplunk Enterprise Update Patches Code Execution Vulnerability https://ift.tt/yEFDJYv
2026-04-15 2026Fortinet Patches Critical FortiSandbox VulnerabilitiesRCEFortinet Patches Critical FortiSandbox Vulnerabilities https://ift.tt/pyBwK5D
2026-04-13 2026OpenAI Impacted by North Korea-Linked Axios Supply Chain HackSupply ChainOpenAI Impacted by North Korea-Linked Axios Supply Chain Hack https://ift.tt/wPCoQdT
2026-04-10 2026Orthanc DICOM Vulnerabilities Lead to Crashes RCERCEOrthanc DICOM Vulnerabilities Lead to Crashes, RCE https://ift.tt/nFMqEBl
2026-04-10 2026Critical Marimo Flaw Exploited Hours After Public DisclosureRCECritical Marimo Flaw Exploited Hours After Public Disclosure https://ift.tt/gzb32yH
2026-04-08 2026RCE Bug Lurked in Apache ActiveMQ Classic for 13 YearsRCERCE Bug Lurked in Apache ActiveMQ Classic for 13 Years https://ift.tt/cfuOEAB
2026-04-08 2026Hackers Targeting Ninja Forms Bug That Exposes WordPress Sites to TakeoverRCEHackers Targeting Ninja Forms Bug That Exposes WordPress Sites to Takeover https://ift.tt/Fz0BpSJ
2026-04-07 2026Guardarian Users Targeted With Malicious Strapi NPM PackagesSupply ChainGuardarian Users Targeted With Malicious Strapi NPM Packages https://ift.tt/jK1NqyB
2026-04-07 2026Critical Flowise Vulnerability in Attacker CrosshairsRCECritical Flowise Vulnerability in Attacker Crosshairs https://ift.tt/idUQSub
2026-04-07 2026North Korean Hackers Target High-Profile Node.js MaintainersSupply ChainNorth Korean Hackers Target High-Profile Node.js Maintainers https://ift.tt/gxul7qM
2026-04-04 2026European Commission Confirms Data Breach Linked to Trivy Supply Chain AttackSupply ChainEuropean Commission Confirms Data Breach Linked to Trivy Supply Chain Attack https://ift.tt/rtNZKwj
2026-04-03 2026Critical ShareFile Flaws Lead to Unauthenticated RCERCECritical ShareFile Flaws Lead to Unauthenticated RCE https://ift.tt/ge2ZksB
2026-03-19 2026Russian APT Exploits Zimbra Vulnerability Against UkraineXSSRussian APT Exploits Zimbra Vulnerability Against Ukraine https://ift.tt/MVsWfZC
2024-12-10 2024SAP Patches Critical Vulnerability in NetWeaverSSRFSAP has addressed a critical vulnerability in its NetWeaver platform through patches. The vulnerability posed a significant security risk, prompting the need for immediate action to protect systems using NetWeaver. By releasing these patches, SAP aims to enhance the security of its software and prevent potential exploitation of the vulnerability by malicious actors. This highlights the importance of timely updates and security measures to safeguard sensitive data and systems from cyber threats.
2024-10-11 2024GitLab Patches Pipeline Execution SSRF XSS VulnerabilitiesSSRFGitLab recently addressed security vulnerabilities related to Pipeline Execution, Server-Side Request Forgery (SSRF), and Cross-Site Scripting (XSS) through patches. These vulnerabilities could potentially be exploited by attackers to compromise the security of GitLab instances. The patches aim to prevent these vulnerabilities from being exploited, enhancing the overall security of the platform.