Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek.
Senaste cybersäkerhetsrådgivningar, sårbarheter och uppdateringar från betrodda källor.
Välj källor du litar på — BleepingComputer, Krebs, CISA, Dev.to — och vi skickar en kurerad veckosammanfattning. Plus valfria CVE-larm för din stack och månadsvis säkerhetsgranskning av din domän.
Kurerad cybersäkerhetsinformation från betrodda europeiska och globala källor. Vårt nyhetsflöde kombinerar sårbarhetsavslöjanden, säkerhetsrådgivningar och analyser från ledande forskare.
Nyheter uppdateras kontinuerligt under dagen. Använd kategorifiltren ovan för att begränsa efter ämne, eller klicka på ett källnamn för att se artiklar från den specifika utgivaren.
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek.

How async job processing moves long-running agent work out of HTTP requests Long-running agent work looks fine right up until it hits real traffic. Then requests start hanging, workers stay busy too long, retries get messy, and users have no clear idea whether anything is still happening. The fix is to move that work out of the request cycle: validate input, enqueue it in a background job queue, return 202 Accepted with a job_id, and let workers finish the task outside the synchronous path. A...
F5 BIG-IP APM CVE-2026-94127: an unauthenticated RCE that a hardening setting does not stop A load balancer can be an attack surface, not only a traffic cop. CVE-2026-94127 in F5 BIG-IP Access Policy Manager (APM) shows why that distinction matters at the edge of the network. What the vulnerability is F5 published advisory K000162605 for CVE-2026-94127 on 2026-09-22, and CISA added the CVE to its Known Exploited Vulnerabilities catalog the same day. F5 rates the flaw 9.8 under CVSS v3.1 and 9...
Sub‑Second Model Routing: How Shadow Avoids Vendor Lock‑In Across Flux, SDXL, and Runware 1. The Core Bottleneck Synthetic image workloads slide from the client into three specialised GPU pools. Flux 1.1 Pro offers deep scene understanding, SDXL delivers global style transfer, and Runware Fast‑Flux delivers raw throughput. The sequence falls apart when one pool stalls: a single stalled API call can push total latency beyond 500 ms, breaking quality‑of‑experience guarantees. A dy...
Most multi-cluster HA setups run active/active, which means paying for full workloads on both clusters around the clock. For our production workloads, I wanted automatic disaster recovery without the standby cluster burning money every day. So I built an active/passive multi-cluster setup with Karmada 👇 🔹 𝗢𝗻𝗲 𝗰𝗼𝗻𝘁𝗿𝗼𝗹 𝗽𝗹𝗮𝗻𝗲, 𝘁𝘄𝗼 𝗞𝘂𝗯𝗲𝗿𝗻𝗲𝘁𝗲𝘀 𝗰𝗹𝘂𝘀𝘁𝗲𝗿𝘀 Karmada runs on a lightweight K3s...
If you've ever been handed a brand-new Azure subscription, AWS account or Google Cloud project and told to "just get something running," you already know the real problem isn't the workload. It's everything around it: who's allowed to log in, how the network is wired, what stops someone from spinning up a public storage bucket at 2am, and where the audit logs actually end up. That governed foundation — the thing you build *before* any workload lands on it — is what the industry calls a **...
I Built an Open-Source Studio for Building and Shipping AI Agents Building an AI chatbot is easy. Shipping one that has tools, knowledge, memory, observability, evaluations, human handoff, multiple model providers, workflows, and an actual interface your users can interact with is a different problem. That gap is what led me to build Chatbot Studio. It's an open-source platform for building AI agents and then publishing those agents as website chatbots or connecting them to channels such as W...
The constraint What if you had to build a useful search engine, but you weren't allowed to install anything? That was the constraint I chose for the Zero Dependency Hackathon. I built FORGE, a crash-safe local document search engine using only Python's standard library. No pip packages. No external runtime dependencies. No database library doing the heavy lifting. Just Python's standard library and a lot of code. What normally happens If I wanted to build local document search quickly, I woul...

Introduction I participated in the Kiro University Challenge and built a TUI app called AWS Public IP Ranges Navigator, which allows users to filter and view AWS's published list of IP ranges directly in the terminal. This challenge was a program where lessons were published daily from September 21 to September 25, 2026. Participants were expected to integrate what they learned into a single project and submit it as a take-home final exam by October 5. Grading is determined by "how well the p...
TLDR: Solved atleast 1 question daily. Creating and following a list to identify and understand patterns Exhilaration, Exhaustion, and the will to continue. Writing this after spending more than 6-7 hours across two days on a single problem. The feeling Feeling mentally drained because of that Leet code 2772 Feels good and unrealistic at the same time (as a personal acheivement) that this much time has passed, somewhere like lost the track of time and To be following a structure, the width of...
Webhook providers deliver at least once, not exactly once. That single fact explains most webhook bugs: duplicate emails, double-credited balances, orders marked paid twice. Here is a pattern for handling deliveries safely with a Postgres table and a small amount of TypeScript, plus the failure cases it is designed around. What the provider actually promises Read the delivery semantics of the provider you integrate with. Stripe's documentation says endpoints may receive the same event more th...

In the previous post in this series, I walked through how to configure the ChatGPT desktop app to use OpenAI models through Amazon Bedrock. That works great if Bedrock is the only environment you want to use. But what if you want to use both your personal ChatGPT account and Amazon Bedrock? That's when it gets awkward. I found that out the hard way after setting up my Bedrock configuration, because my intention was always to keep using my personal ChatGPT account as well and switch between th...