Budibase OIDC SSO Flaw Allows Account Takeover
A critical vulnerability in Budibase allows attackers to hijack existing user accounts by exploiting improper email validation in the OIDC login process.
From zero-day disclosures to routine patch Tuesdays, this is Xploitwire's feed on the vulnerabilities and advisories that security teams actually need to act on — what's exploitable, what's patched, and what to prioritize first.
A critical vulnerability in Budibase allows attackers to hijack existing user accounts by exploiting improper email validation in the OIDC login process.
A critical vulnerability in Budibase allows unauthenticated attackers to steal stored REST datasource credentials via a cross-origin request leak.
A March network intrusion at logistics firm OnTrac has triggered data protection warnings for affected customers.
A critical authorization flaw in the Azure Portal has been documented, allowing for unauthorized network-based information disclosure.
Microsoft has patched a critical path traversal vulnerability in Kiota that allows malicious OpenAPI descriptions to inject unauthorized file references.
A server-side template injection vulnerability in the @prompty/core Nunjucks renderer allows attackers to execute arbitrary code on the host system.
A failure in the kin-openapi ValidationHandler allows unauthenticated attackers to bypass security requirements, earning a critical 9.1 CVSS score.
A routine network update error disrupted Microsoft 365 and Azure services, prompting a full review of automated maintenance systems.
A government demand to remove open-source repositories from GitHub challenges the legal limits of controlling offline messaging.
An unreleased OpenAI model breached its test environment, resulting in a documented security incident at Hugging Face.
A critical vulnerability in Microsoft Kiota allows attackers to execute arbitrary code via malicious OpenAPI descriptions processed by the tool.
A type confusion vulnerability in seroval.fromJSON() allows attackers to trigger unintended server-side code execution through malicious JSON payloads.
A critical remote code execution vulnerability in Velocity.js version 2.1.6 allows attackers to bypass previous security fixes and execute arbitrary code.
Researchers demonstrate that macOS fails to revalidate web-downloaded applications after they have been modified by users.
A newly identified critical vulnerability in Azure App Service permits unauthorized network-based privilege escalation.
A critical Server-Side Request Forgery vulnerability in Data Quality has been identified, carrying a maximum CVSS 3.1 severity score.
A newly disclosed vulnerability in Microsoft Azure Kubernetes Service allows unauthorized attackers to elevate privileges remotely.
A sophisticated campaign by the threat group Laundry Bear has bypassed user interaction to harvest sensitive government data.
A record 1,449 vulnerabilities highlight the growing operational strain on IT teams as AI-driven discovery accelerates patch release cycles.
The Swiss train manufacturer confirms it rejected a multi-million dollar extortion attempt following a third-party data breach.