startupfortune.com
Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-09-03.
| Date Added | Resource | Excerpt |
|---|---|---|
| 2026-09-03 2026 | Hackers Are Exploiting a Critical Flaw in JFrog's Artifactory ToolSupply Chain | Hackers are actively exploiting a critical vulnerability in JFrog's Artifactory, a widely used software artifact repository. This flaw allows unauthorized access and potential data compromise. Organizations relying on Artifactory are urged to update their systems immediately to patch the vulnerability and mitigate risks. The exploit targets the tool's authentication mechanisms, enabling attackers to bypass security controls. Further details on the specific CVE are available through the provided link. |
| 2026-08-29 2026 | A critical Gitea flaw is under active attack and 8300 servers are still exposedRCE | Library for securing Gitea instances against CVE-2026-60004, a critical remote code execution flaw allowing attackers with repository write access to execute shell commands by abusing the diffpatch endpoint. Exploitation involves crafting a patch that triggers an add/add collision in Git's three-way fallback, enabling the execution of Git hooks. Versions 1.17 through 1.27.0 are vulnerable. The fix involves upgrading to Gitea 1.27.1 or later and disabling open registration. |
| 2026-08-21 2026 | CISA Gives Agencies Three Days to Patch a Critical Flaw in RayRCE | Library for patching CVE-2025-62593, a critical remote code execution flaw in the Ray distributed computing framework. Versions prior to 2.52.0 are exploitable via DNS rebinding combined with a weak User-Agent header check, allowing attackers to execute arbitrary commands with Ray process privileges. This vulnerability was added to CISA's Known Exploited Vulnerabilities catalog, mandating a three-day patching deadline for federal agencies under Binding Operational Directive 26-04. |
| 2026-07-13 2026 | Two npm attacks in four days show crypto's weak point is the supply chainSupply Chain | Library for securing JavaScript supply chains, addressing recent npm attacks like those on `@injectivelabs/sdk-ts` and Jscrambler. These incidents highlight vulnerabilities where malicious code is executed at runtime, bypassing `--ignore-scripts`, and exfiltrates sensitive data like wallet mnemonics and cloud credentials via disguised HTTP requests. The attacks exploit compromised GitHub accounts and stolen publishing tokens, demonstrating a critical need for defenses against supply chain compromise beyond traditional smart contract audits. |
| 2026-04-21 2026 | Lovables API flaw exposed private project data from the $6.6 billion AI app builder used by Nvidia and Microsoft teamsAPI Sec | Analysis of a Lovable API vulnerability that exposed chat histories, source code, and Supabase API keys from projects created before November 2025. The flaw, reported via HackerOne in March 2026, stemmed from missing ownership checks on API endpoints, allowing any authenticated user to access data from older projects, impacting users at companies like Nvidia and Microsoft. Affected users are advised to rotate all credentials used within the platform. |