RC RANDOM CHAOS
RC RANDOM CHAOS

Tech · Culture · Fiction

86,644 FortiGate boxes still take the old password Article

86,644 FortiGate boxes still take the old password

The FBI says FortiBleed is still active, using 86,644 Fortinet credentials harvested months ago to plant admin accounts and feed ransomware crews.

Telegram Desktop File Theft Bug
Article Telegram

Telegram Desktop File Theft Bug

Telegram Desktop 7.2.9 fixed a link-triggered file theft bug that could expose local session files without a passcode.

Dell's Thursday patch closes a root-level DSU flaw
Article dell

Dell's Thursday patch closes a root-level DSU flaw

Dell patched CVE-2026-86360, a path traversal flaw in the System Update CLI that gives unauthenticated remote attackers root. Upgrade to DSU 2.3.0.0.

GitLab AI Gateway sandbox escape
Article gitlab

GitLab AI Gateway sandbox escape

GitLab's critical CVE-2026-90970 lets an authenticated Duo user escape the AI Gateway prompt sandbox and run arbitrary commands. Self-hosted operators must patch now.

Kiteworks patches max-severity EPG flaw in Wednesday advisory
Article kiteworks

Kiteworks patches max-severity EPG flaw in Wednesday advisory

Kiteworks patched CVE-2026-54154, a max-severity unauthenticated RCE in its Email Protection Gateway. Upgrade to 9.4.1 and check exposed appliances.

macOS screen sharing flaw went public at Black Hat
Article macos-security

macOS screen sharing flaw went public at Black Hat

CVE-2026-65400, an actively exploited macOS screen sharing flaw, dropped Monero miners via port 5900, and an AI agent on one host caught the compromise.

Math.random() session key lets attackers run code on HFS
Article vulnerability

Math.random() session key lets attackers run code on HFS

A weak Math.random() session key in Rejetto HFS 3.0.0-3.2.0 lets attackers forge admin cookies and run code; CVE-2026-61500 is under active exploitation.

The Wire — latest

All →

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.