Breach of Confidence: 10 April 2026
I spent most of one day this week trying to access a perfectly ordinary online service and felt like I was applying for witness protection. By the end of it, I’d supplied a password, a code, a backup ...
Related Vulnerabilities
- CVE-2026-40103: Vikunja: Scoped API tokens with projects.background permission can delete project backgrounds MEDIUM
- CVE-2026-34483: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache MEDIUM
- CVE-2026-6033: A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of MEDIUM
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-5144: The BuddyPress Groupblog plugin for WordPress is vulnerable to Privilege Escalation in all versions HIGH
Related Coverage
Threat Actors