Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

OffSequence

@offseq@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

OffSeq is a cybersecurity company enhancing organizational digital resilience through comprehensive protection against evolving cyber threats. We offer specialized services for businesses of all sizes, with particular expertise in Baltic, Scandinavian, Belgian markets and EU regulatory compliance.

149 Followers
0 Following
50 Posts
Joined April 02, 2025
Website:
https://offseq.com
Threat Radar:
https://radar.offseq.com
Guard:
https://guard.offseq.com
Breach:
https://breach.offseq.com
Training & Certifications:
https://training.offseq.com
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-66897: Canonical LXD CRITICAL path traversal (CVSS 9.9). Attackers with container edit rights or crafted images can overwrite host files as root. Restrict permissions & avoid untrusted images. Patch status unknown. https://radar.offseq.com/threat/cve-2026-66897-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-b6ae23dfc47f5562 #OffSeq #LXD #CVE #Linux

radar.offseq.com
1
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CRITICAL vuln (CVE-2026-78168) in EFM ipTIME T24000M ≤14.20.0: improper authentication in httpcon_check_session_url enables remote exploit. Public exploit disclosed, no vendor fix. Review access controls now. https://radar.offseq.com/threat/cve-2026-78168-improper-authentication-in-efm-iptime-t24000m-bfa2e716a3fcf0b6 #OffSeq #CVE #IoTSecurity #Exploit

radar.offseq.com
1
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

4MOSAn GCB Doctor faces a CRITICAL OS Command Injection (CVE-2026-78211, CVSS 9.8). Unauthenticated attackers can execute arbitrary system commands via ADOdb test page parameter. No patch — restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-78211-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-91902877a695e366 #OffSeq #CVE202678211 #Vuln #BlueTeam

radar.offseq.com
1
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CRITICAL: Stack-based buffer overflow (CVE-2026-78169) in UTT HiPER 1250GW v3.2.7-210907-180535. Public exploit code available — no patch yet. Restrict device access & monitor /goform/aspRemoteApConfTempSend traffic. https://radar.offseq.com/threat/cve-2026-78169-stack-based-buffer-overflow-in-utt-hiper-1250gw-b9697a669a575a95 #OffSeq #CVE #Infosec #IoT

radar.offseq.com
1
0
2
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-16149 (HIGH, CVSS 8.8): marc4 Security Hardener <=2.4.4 allows Subscriber-level users to create Admin accounts or reset passwords via REST API. Disable plugin or limit API access pending patch. https://radar.offseq.com/threat/cve-2026-16149-cwe-269-improper-privilege-management-in-marc4-security-hardener-a438d1f2a5360b5c #OffSeq #WordPress #Vulnerability #Infosec

radar.offseq.com
1
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-78267 (CRITICAL, CVSS 9.8): Cozmoslabs TranslatePress <=3.3.2 is vulnerable to unauthenticated privilege escalation (CWE-266). No patch yet — monitor vendor advisories for updates. https://radar.offseq.com/threat/cve-2026-78267-cwe-266-incorrect-privilege-assignment-in-cozmoslabs-translatepress-ba0caba45d17d814 #OffSeq #WordPress #Vuln #PrivilegeEscalation

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 4w ago
CVE-2026-86296 | D-Link DIR-822A A_101: Critical stack-based buffer overflow in udhcpcd (CVSS 10). Remotely exploitable, no auth needed. Exploit code is public. Isolate devices & check vendor updates. https://radar.offseq.com/threat/a-vulnerability-was-determined-in-d-link-dir-822a-a101-cve-2026-86296-3125c70d27558796 #OffSeq #Vulnerability #DLink #Security
OffSeq Threat Radar

A vulnerability was determined in D-Link DIR-822A A_101. (CVE-2026-86296) - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about A vulnerability was determined in D-Link DIR-822A A_101. (CVE-2026-86296). Get real-time updates, technical details, and mitigation s

0
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-8445: EmilStenstrom justhtml <=1.11.0 suffers CRITICAL XSS due to improper escaping in Markdown output. Remote attackers can inject scripts. Update to v1.12.0 now. https://radar.offseq.com/threat/cve-2026-8445-improper-neutralization-of-input-during-web-page-generation-cross-site-scripting-in-42aabed1c30bf24b #OffSeq #XSS #AppSec #CVE20268445

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2mo ago
CVE-2026-16955: HIGH severity path traversal in AI Engine WP plugin <3.6.6. Subscribers can read arbitrary files if public API is enabled. Restrict API & admin privileges. Await patch. https://radar.offseq.com/threat/cve-2026-16955-cwe-22-improper-limitation-of-a-pathname-to-a-restricted-directory-path-traversal-in-ai-72905be644e71053 #OffSeq #WordPress #CVE2026_16955 #Security
radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago
Cisco Secure Email Gateway faces a CRITICAL zero-day vulnerability, actively exploited in the wild. No CVE or version info yet. Patch available — apply ASAP to protect email infrastructure. https://radar.offseq.com/threat/cisco-patches-secure-email-gateway-zero-day-exploited-in-attacks-76a43690673247c4 #OffSeq #Cisco #ZeroDay #BlueTeam #EmailSecurity
OffSeq Threat Radar

Cisco patches Secure Email Gateway zero-day exploited in attacks - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about Cisco patches Secure Email Gateway zero-day exploited in attacks. Get real-time updates, technical details, and mitigation strategies

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2mo ago
Kadence Memberships (stellarwp) ≤4.0.0 suffers CRITICAL vuln (CVE-2026-9273, CVSS 9.3): attackers can hijack any account by poisoning password reset links. Restrict reset features & monitor for patches. https://radar.offseq.com/threat/cve-2026-9273-cwe-640-weak-password-recovery-mechanism-for-forgotten-password-in-stellarwp-membership-10c6cffc948a3c97 #OffSeq #WordPress #Vuln #Security
radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2w ago
CVE-2026-19599: CRITICAL RCE in ManageEngine OpManager MSP (<12.8.711). Improper OS command neutralization enables remote command execution (CVSS 9.9). Upgrade to 12.8.711+ ASAP. https://radar.offseq.com/threat/cve-2026-19599-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-d62870fccbe1d229 #OffSeq #Vuln #InfoSec #RCE
radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2w ago
Check Point Security Mgmt & Log Server hit by CRITICAL RCE (CVE-2026-91843) via unauthenticated login. No active exploitation yet. Patch ASAP. Tanium (SQLi, RCE) & Kaspersky (Redis) also patched. https://radar.offseq.com/threat/check-point-kaspersky-tanium-patch-product-vulnerabilities-ae8c3757ea9b181a #OffSeq #Vulnerability #RCE #PatchNow
OffSeq Threat Radar

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about Check Point, Kaspersky, Tanium Patch Product Vulnerabilities. Get real-time updates, technical details, and mitigation strategies.

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-72702 | Grav CMS <2.0.16 | CRITICAL (CVSS 9.3): Origin validation bypass via weak Referer checks lets attackers defeat CSRF defenses. No fix confirmed — use extra controls, monitor vendor updates. https://radar.offseq.com/threat/cve-2026-72702-origin-validation-error-in-getgrav-grav-4b8f0ff64f944a7c #OffSeq #CVE202672702 #GravCMS #WebSecurity

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-13214 (CRITICAL, CVSS 9.8) in Zephyr OCPP 1.6 client: Unbounded strcpy() in parse_getconfig_msg() enables RCE/DoS via stack overflow. Affects =4.3.0, >=4.3.0 <4.4.2. Restrict untrusted WebSocket access. Patch status pending. https://radar.offseq.com/threat/cve-2026-13214-memory-safety-in-zephyrproject-zephyr-042d724fd93f46c2 #OffSeq #Zephyr #CVE202613214 #IoTSec

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-77995 (CRITICAL, CVSS 10): miniOrange OAuth Client for Joomla (v1.0.0 – 3.1.9) allows arbitrary account takeover via cookie manipulation. Patch to 3.2.0+ required. https://radar.offseq.com/threat/cve-2026-77995-cwe-639-authorization-bypass-through-user-controlled-key-in-miniorangecom-miniorange-0e8da876ce4c7e51 #OffSeq #Joomla #Vuln #OAuth

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CVE-2026-16985: Squeeze WP plugin <1.7.12 has a CRITICAL vuln — users with upload_files can upload PHP files, enabling remote code execution. Restrict permissions, monitor uploads, and check for updates. https://radar.offseq.com/threat/cve-2026-16985-cwe-434-unrestricted-upload-of-file-with-dangerous-type-in-squeeze-a1de64d348b6591f #OffSeq #WordPress #CVE2026_16985 #infosec
OffSeq Threat Radar

CVE-2026-16985: CWE-434 Unrestricted Upload of File with Dangerous Type in Squeeze - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-16985: CWE-434 Unrestricted Upload of File with Dangerous Type in Squeeze affecting null Squeeze. Get real-time updates, tec

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
CVE-2026-100721: CRITICAL auth bypass in vm2 <3.12.2's NodeVM external-module resolver. Sandbox escape & arbitrary code exec possible. Upgrade to 3.12.2+ ASAP. https://radar.offseq.com/threat/vm2-before-3122-contains-an-authorization-bypass-in-the-nodevm-external-module-resolver-cve-2026-100721-5c70167d00dbbf82 #OffSeq #CVE2026100721 #vm2 #infosec
OffSeq Threat Radar

vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. (CVE-2026-100721) - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. (CVE-2026-100721). Get real-time updates,

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
Critical: Google Cloud Application Integration is affected by CVE-2026-81867 (CVSS 9.4) — deserialization of untrusted data lets authenticated users run code on shared servers. Patched 2026-06-28. Confirm your environment is current. Details: https://radar.offseq.com/threat/cve-2026-81867-cwe-502-deserialization-of-untrusted-data-in-google-cloud-application-integration-14d58452543f7963 #OffSeq #CloudSecurity #CVE202681867
OffSeq Threat Radar

CVE-2026-81867: CWE-502 Deserialization of Untrusted Data in Google Cloud Application Integration - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-81867: CWE-502 Deserialization of Untrusted Data in Google Cloud Application Integration affecting Google Cloud Application

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
CVE-2026-100551: OpenClaw for iOS (>=2026.7.1, <2026.8.11) has a CRITICAL vuln in Control UI WebViews — TLS pins not enforced. Attackers can steal Gateway creds if they can redirect traffic. Patch to 2026.8.11 ASAP! https://radar.offseq.com/threat/openclaw-for-ios-versions-202671-and-2026811-do-not-enforce-saved-gateway-tls-pins-in-the-control-ui-5ff1fd58a7f58c18 #OffSeq #Vulnerability #iOS #AppSec
radar.offseq.com
0
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 2mo ago
CRITICAL: Snowflake accounts hacked — no MFA, stolen creds from infostealer malware led to massive data theft (100M+ affected, $9.5M loss). All orgs: enforce MFA & strong passwords. No CVE assigned. https://radar.offseq.com/threat/canadian-pleads-guilty-to-snowflake-cloud-data-theft-attacks-21f9fb8717cf2802 #OffSeq #CloudSecurity #ThreatIntel
OffSeq Threat Radar

Canadian pleads guilty to Snowflake cloud data-theft attacks - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about Canadian pleads guilty to Snowflake cloud data-theft attacks. Get real-time updates, technical details, and mitigation strategies.

0
1
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago
CRITICAL path traversal (CVE-2026-13716, CVSS 9.1) found in Crafty Controller v4.4.0 (Arcadia). Authenticated attackers can upload files to arbitrary paths, risking RCE. Restrict admin/file upload access & monitor activity. Details: https://radar.offseq.com/threat/cve-2026-13716-cwe-35-path-traversal-in-arcadia-technology-llc-crafty-controller-2cdd2d33980b3ceb #OffSeq #Vuln #CVE202613716
OffSeq Threat Radar

CVE-2026-13716: CWE-35: Path Traversal: '.../...//' in Arcadia Technology, LLC Crafty Controller - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-13716: CWE-35: Path Traversal: '.../...//' in Arcadia Technology, LLC Crafty Controller affecting Arcadia Technology, LLC Cr

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-77994: CRITICAL SQL injection in Joomla Page Builder CK (v1.0.0-3.6.4). Unauthenticated remote SQL execution possible. No official fix yet — disable/remove vulnerable versions. CVSS 9.3. https://radar.offseq.com/threat/cve-2026-77994-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-d508026cac86e490 #OffSeq #Joomla #SQLInjection #Infosec

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
CVE-2026-18467: CRITICAL privilege escalation in Paytium: Mollie payment forms (≤5.0.3). Unauthenticated users can create admin accounts via exploited payment forms. Restrict forms or disable plugin until full fix. https://radar.offseq.com/threat/cve-2026-18467-cwe-269-improper-privilege-management-in-paytiumsupport-paytium-mollie-payment-forms-816d892a2e04a4c5 #OffSeq #WordPress #CVE202618467 #Security
OffSeq Threat Radar

CVE-2026-18467: CWE-269 Improper Privilege Management in paytiumsupport Paytium: Mollie payment forms & donations - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-18467: CWE-269 Improper Privilege Management in paytiumsupport Paytium: Mollie payment forms & donations affecting paytiumsu

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2w ago
CVE-2026-93741: Totolink A3002MU (Hh-B20211125.1046) hit by CRITICAL buffer overflow in formWlWds (CVSS 10). Exploit is public; remote code exec risk. Isolate affected routers or block attacks at the network. https://radar.offseq.com/threat/cve-2026-93741-buffer-overflow-in-totolink-a3002mu-bc2e06f7d2d53482 #OffSeq #CVE202693741 #IoT #Exploit
OffSeq Threat Radar

CVE-2026-93741: Buffer Overflow in Totolink A3002MU - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-93741: Buffer Overflow in Totolink A3002MU affecting Totolink A3002MU. Get real-time updates, technical details, and mitigat

0
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-7808 | justhtml <1.16.0 faces CRITICAL XSS risk via HTML sanitization bypass in advanced use cases. Upgrade to 1.16.0+ to fix. Impacts apps with custom/mutated policies. Details: https://radar.offseq.com/threat/cve-2026-7808-improper-input-validation-in-emilstenstrom-justhtml-86dd54d29e0645e9 #OffSeq #CVE20267808 #infosec #XSS

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago
EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 #OffSeq #Vulnerability #IoTSecurity #CVE
OffSeq Threat Radar

CVE-2026-90847: OS Command Injection in EFM ipTIME C200E - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-90847: OS Command Injection in EFM ipTIME C200E affecting EFM ipTIME C200E. Get real-time updates, technical details, and mi

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-78568: CRITICAL SQL Injection in KlbTheme Total Donations ≤2.0.5. Unauthenticated attackers can extract sensitive DB data via improper input handling. No fix yet — disable the plugin. https://radar.offseq.com/threat/cve-2026-78568-cwe-89-improper-neutralization-of-special-elements-used-in-an-sql-command-sql-injection-52b70f977190d0ba #OffSeq #WordPress #SQLi #Vuln

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2w ago
F5 BIG-IP APM (OAuth Authorization Server) is facing a CRITICAL RCE zero-day, CVE-2026-94127, with active exploitation. Versions 21.1.0, 17.5.0 – 17.5.1, 17.1.0 – 17.1.3 affected. Apply hotfixes now. Details: https://radar.offseq.com/threat/critical-f5-big-ip-vulnerability-exploited-as-zero-day-024f528e7ee83eed #OffSeq #F5 #ZeroDay #Infosec
OffSeq Threat Radar

Critical F5 BIG-IP Vulnerability Exploited as Zero-Day - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about Critical F5 BIG-IP Vulnerability Exploited as Zero-Day. Get real-time updates, technical details, and mitigation strategies.

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
CVE-2026-101002: Critical OS command injection in Netcore NBR200V2 v1.3.241127.071246 via Tools Ping Handler. Public exploit code available; no vendor patch. Isolate devices, restrict network access. https://radar.offseq.com/threat/cve-2026-101002-os-command-injection-in-netcore-nbr200v2-8a15ef317ba62749 #OffSeq #CVE2026101002 #Netcore #Vuln
OffSeq Threat Radar

CVE-2026-101002: OS Command Injection in Netcore NBR200V2 - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-101002: OS Command Injection in Netcore NBR200V2 affecting Netcore NBR200V2. Get real-time updates, technical details, and m

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CRITICAL CVE-2026-78265: Nexcess The Events Calendar <=6.17.2 has unauthenticated PHP Object Injection (CWE-502). Full system compromise possible. No patch yet — remove or disable plugin for now. https://radar.offseq.com/threat/cve-2026-78265-cwe-502-deserialization-of-untrusted-data-in-nexcess-the-events-calendar-3dd3af18547313e0 #OffSeq #WordPress #Infosec #CVE2026_78265

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 4w ago
D-Link DIR-822A routers are affected by CVE-2026-86510 (CRITICAL, CVSS 9.4): remote out-of-bounds write in L2TP parser can lead to system compromise. No patch yet — restrict access and monitor updates. https://radar.offseq.com/threat/cve-2026-86510-out-of-bounds-write-in-d-link-dir-822a-e90339b14a1aa39b #OffSeq #CVE202686510 #RouterSecurity #Infosec
OffSeq Threat Radar

CVE-2026-86510: Out-of-bounds Write in D-Link DIR-822A - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-86510: Out-of-bounds Write in D-Link DIR-822A affecting D-Link DIR-822A. Get real-time updates, technical details, and mitig

0
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 2w ago
CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-94003-stack-based-buffer-overflow-in-comfast-cf-n1-s-1046130f838f5eec #OffSeq #Infosec #CVE #IoTSecurity
OffSeq Threat Radar

CVE-2026-94003: Stack-based Buffer Overflow in Comfast CF-N1-S - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-94003: Stack-based Buffer Overflow in Comfast CF-N1-S affecting Comfast CF-N1-S. Get real-time updates, technical details, a

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

KlbTheme Total Donations <=2.0.5 has a CRITICAL privilege escalation vuln (CVE-2026-78570, CVSS 9.8). Unauthenticated attackers can gain admin access. No patch yet — disable/remove plugin & monitor for advisories. https://radar.offseq.com/threat/cve-2026-78570-cwe-269-improper-privilege-management-in-klbtheme-total-donations-fcfd73df270b6d37 #OffSeq #WordPress #CVE #Vuln

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-78676 | GitPython <3.1.59 has a CRITICAL argument injection flaw: multi-line git-config values can become active directives, enabling arbitrary code execution via git hooks. Patch status unknown — avoid untrusted configs. https://radar.offseq.com/threat/cve-2026-78676-improper-neutralization-of-argument-delimiters-in-a-command-argument-injection-in-98aef85f24190fbe #OffSeq #CVE202678676 #git #infosec

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 3w ago
CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: https://radar.offseq.com/threat/cve-2026-87931-buffer-overflow-in-behavioral-technology-group-pavlok-behavioral-conditioning-wearable-98a2d4c4edee7864 #OffSeq #CVE202687931 #IoTSecurity
OffSeq Threat Radar

CVE-2026-87931: Buffer Overflow in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-87931: Buffer Overflow in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable affecting Behavioral Technolog

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2mo ago
CVE-2026-70553: CRITICAL RCE in MaxSite CMS 105.2 (CVSS 9.3). Attackers can inject PHP via POST to the install endpoint, gaining persistent code exec as www-data. Restrict endpoint & monitor traffic until patched. Details: https://radar.offseq.com/threat/cve-2026-70553-improper-control-of-generation-of-code-code-injection-in-maxsite-maxsite-cms-5161bdfb2e6804e9 #OffSeq #CVE #websecurity #RCE
OffSeq Threat Radar

CVE-2026-70553: Improper Control of Generation of Code ('Code Injection') in MaxSite MaxSite CMS - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-70553: Improper Control of Generation of Code ('Code Injection') in MaxSite MaxSite CMS affecting MaxSite MaxSite CMS. Get r

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

Privilege escalation vuln (CRITICAL, CVSS 9.8) in MVPThemes Jawn WordPress theme (≤1.4.2): CVE-2026-78477 lets unauth users elevate to admin. Review deployments & monitor for fixes. https://radar.offseq.com/threat/cve-2026-78477-cwe-266-incorrect-privilege-assignment-in-mvpthemes-jawn-ec6b466fa423dd3f #OffSeq #WordPress #Vuln #PrivilegeEscalation

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2w ago
HIGH severity: CVE-2026-92965 in TikTok WordPress plugin (1.2.0 – 1.4.2) allows any visitor to redeem sign-in codes via URL, risking ad platform abuse. Restrict or disable the plugin while awaiting a patch. https://radar.offseq.com/threat/cve-2026-92965-cwe-862-missing-authorization-in-tiktok-38fbb3b8076a5adb #OffSeq #WordPress #Vuln #Security
OffSeq Threat Radar

CVE-2026-92965: CWE-862 Missing Authorization in TikTok - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-92965: CWE-862 Missing Authorization in TikTok affecting null TikTok. Get real-time updates, technical details, and mitigati

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
CVE-2026-89055 (CRITICAL, CVSS 9.1): Customer Reviews for WooCommerce <=5.120.0 lets unauthenticated attackers delete arbitrary media via public review-form links. Restrict link access, monitor suspicious review activity. https://radar.offseq.com/threat/cve-2026-89055-cwe-862-missing-authorization-in-ivole-customer-reviews-for-woocommerce-49ae0564154df323 #OffSeq #CVE202689055 #WordPress #Infosec
OffSeq Threat Radar

CVE-2026-89055: CWE-862 Missing Authorization in ivole Customer Reviews for WooCommerce - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-89055: CWE-862 Missing Authorization in ivole Customer Reviews for WooCommerce affecting ivole Customer Reviews for WooComme

0
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-73570: Actively exploited CRITICAL RCE in Zimbra Collaboration Suite <10.1.20 via SNMP command injection. Patch to 10.1.20 now. Watch for suspicious service restarts & files in /opt/zimbra/jetty/webapps/. Details: https://radar.offseq.com/threat/cisa-orders-urgent-patching-of-actively-exploited-zimbra-flaw-b89f77b410f3bb5f #OffSeq #Zimbra #Infosec #RCE

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2mo ago
FlowiseAI Flowise (<3.1.3) has a CRITICAL vuln (CVE-2026-70478): unauthenticated POST endpoint leaks refreshed OAuth tokens if credential ID is known. Upgrade to 3.1.3+ ASAP. https://radar.offseq.com/threat/cve-2026-70478-cwe-200-exposure-of-sensitive-information-to-an-unauthorized-actor-in-flowiseai-flowise-2c912baff770743c #OffSeq #CVE202670478 #OAuth #infosec
OffSeq Threat Radar

CVE-2026-70478: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI Flowise - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-70478: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI Flowise affecting FlowiseAI Flowise.

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
OS command injection (CVE-2026-101009) in aaPanel BaoTa <=11.8.0: CRITICAL severity. Exploit public, vendor silent. Remote attackers can execute commands via panelTask.bt_task._unzip. Review and mitigate now. https://radar.offseq.com/threat/cve-2026-101009-os-command-injection-in-aapanel-baota-2affddad69ededf3 #OffSeq #CVE2026101009 #infosec
OffSeq Threat Radar

CVE-2026-101009: OS Command Injection in aaPanel BaoTa - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-101009: OS Command Injection in aaPanel BaoTa affecting aaPanel BaoTa. Get real-time updates, technical details, and mitigat

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2w ago
@kartyk-github-org/takedown-b (npm) contains CRITICAL malware: full system compromise if installed/run. All secrets and keys must be rotated from a clean device. Removal alone is insufficient — investigate for persistence. No CVE. https://radar.offseq.com/threat/malicious-code-in-kartyk-github-orgtakedown-b-npm-3a3addb0368973b9 #OffSeq #npm #malware #infosec
OffSeq Threat Radar

Malicious code in @kartyk-github-org/takedown-b (npm) - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about Malicious code in @kartyk-github-org/takedown-b (npm) affecting null @kartyk-github-org/takedown-b. Get real-time updates, technical

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-78251 (CRITICAL): DJI Neo & related drones have hard-coded FTP creds, letting attackers fill storage & disrupt logging/updates via network or USB. Patch required! https://radar.offseq.com/threat/cve-2026-78251-cwe-798-use-of-hard-coded-credentials-in-dji-neo-98f2d4e34b35b2e0 #OffSeq #CVE2026_78251 #DJI #DroneSec

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
Boosted by @welcome@friends.deko.cloud
OffSeq is an European offensive security company. We do pentesting, red teaming, OT/ICS and critical infrastructure security, and NIS2/DORA work across the EU. Here we post our research: vulnerability disclosures (latest in Latvian and Estonian eID software and X-Road), monthly Mirage honeypot field reports and open-source tools. Open to collaboration, DMs are open. https://offseq.com/en/ #Introduction #InfoSec #PenTest #RedTeam #ThreatIntel #OffensiveSecurity
Offensive Security for Cyber Resilience – OffSeq
OffSeq

Offensive Security for Cyber Resilience – OffSeq

European offensive-security company providing red team operations, threat intelligence, security audits, continuous monitoring and NIS2 compliance support.

0
0
1
0
Open post
OffSequence @offseq@infosec.exchange
· 2mo ago
CVE-2026-16594: WP Directory Kit <1.5.5 has a HIGH severity info exposure flaw. Any authenticated user (even Subscribers) can access API keys/secrets due to missing authorization on AJAX action. Restrict user roles & monitor logs. https://radar.offseq.com/threat/cve-2026-16594-cwe-200-information-exposure-in-wp-directory-kit-3d8a39f4c5fd7c8a #OffSeq #WordPress #CVE
OffSeq Threat Radar

CVE-2026-16594: CWE-200 Information Exposure in WP Directory Kit - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-16594: CWE-200 Information Exposure in WP Directory Kit affecting null WP Directory Kit. Get real-time updates, technical de

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 2mo ago
CVE-2026-54212: CRITICAL buffer overflow in Tobit TeamDavid Webbox API (≤ Rollout 524). Crafted JSON lets unauthenticated attackers crash servers; RCE possible if combined with other flaws. Restrict API, monitor activity. https://radar.offseq.com/threat/cve-2026-54212-cwe-787-out-of-bounds-write-in-tobit-laboratories-ag-teamdavid-2e946f5b4b7b0ab5 #OffSeq #CVE #bufferOverflow #infosec
OffSeq Threat Radar

CVE-2026-54212: CWE-787 Out-of-bounds write in Tobit… | Threat Radar

Vulnerability: Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting…

0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1mo ago

CVE-2026-78122: HIGH severity in Tecnativa docker-socket-proxy (CVSS 8.3). Insufficient access control enables attackers to read files & export entire container filesystems via Docker API. Restrict access, check vendor guidance. https://radar.offseq.com/threat/cve-2026-78122-insufficient-granularity-of-access-control-in-tecnativa-docker-socket-proxy-6e8e6aaf03a19cce #OffSeq #Docker #Infosec #Vuln

radar.offseq.com
0
0
0
0
Open post
OffSequence @offseq@infosec.exchange
· 1w ago
Seetong T8108 series (v4.6.1.4-build202604241011) hit by CRITICAL CVE-2026-100886: improper authentication in Debug Service. Exploitable remotely — public exploit code available. No patch. Restrict network access ASAP. https://radar.offseq.com/threat/cve-2026-100886-improper-authentication-in-seetong-t8108-acea634abd75f700 #OffSeq #CVE2026100886 #IoTSecurity #Vuln
OffSeq Threat Radar

CVE-2026-100886: Improper Authentication in Seetong T8108 - Live Threat Intelligence - Threat Radar | OffSeq.com

Detailed information about CVE-2026-100886: Improper Authentication in Seetong T8108 affecting Seetong T8108. Get real-time updates, technical details, and miti

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 18:56:23 UTC