An integration error routed wallet entropy through MicroPython's deterministic Yasmarang fallback. Updating prevents new weak seeds, but existing ones still require migration.
A crafted image can reach unsafe libvips operations through Active Storage, exposing files and process credentials that a Rails-only update cannot recover.
The flaw reaches an unsafe resource-loading path without AutoType enabled. Exposure is limited to a specific Fastjson 1.x and Spring Boot deployment combination.
CVE-2026-6875 chained query evaluation with a sandbox escape, giving an unauthenticated attacker broad control of a ServiceNow instance and its connected proxy servers.
Researchers put instructions to read .env and encode it into source inside a PNG that text-only pull-request reviewers ignored but vision-capable coding agents later followed.
A stolen npm publisher account added a malicious dependency to more than 140 Mastra packages, giving Sapphire Sleet an install-time path into developer and CI systems.