Threat Surface Pulse
Real-time snapshots from CISA KEV and other signals. Highlights exposed risk and trending CVEs.
- Recent KEV additions
- Exec-ready talking points
Gladinet
Gladinet CentreStack and TrioFox contain a hardcoded cryptographic keys vulnerability for their implementation of the AES cryptoscheme. This vulnerability degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without authentication.
Apple
Apple iOS, iPadOS, macOS, and other Apple products contain a use-after-free vulnerability in WebKit. Processing maliciously crafted web content may lead to memory corruption. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.
Sierra Wireless
Sierra Wireless AirLink ALEOS contains an unrestricted upload of file with dangerous type vulnerability. A specially crafted HTTP request can upload a file, resulting in executable code being uploaded, and routable, to the webserver. An attacker can make an authenticated HTTP request to trigger this vulnerability. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization.
Google Chromium contains an out of bounds memory access vulnerability in ANGLE that could allow a remote attacker to perform out of bounds memory access via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.
OSGeo
OSGeo GeoServer contains an improper restriction of XML external entity reference vulnerability that occurs when the application accepts XML input through a specific endpoint /geoserver/wms operation GetMap and could allow an attacker to define external entities within the XML request.
AI/ML Signal Tracker
Tracks model releases, repos, and outages; summarizes impact for platform roadmaps.
- Top moving repos
- Signal strength
PeterHovng/HUTECH_DACS.CyberSecurity
Nghiên cứu khoa học & Đồ án cơ sở - ngành An ninh mạng "Hệ thống phát hiện và phòng chống tấn công Web bằng Machine Learning (Web Intrusion Detection System - WIDS)"
daryllundy/wp-ai-security-scanner
An AI-powered WordPress security scanner with intelligent threat detection and automated remediation capabilities
durellwilson/security-awareness-course
🛡️ Comprehensive security course: Deepfakes & Prompt Injections - Detection, Prevention & Response
natinew77-creator/SmartGuard-SMS-Security
A real-time SMS security agent that uses Deep Learning to intercept and blur phishing threats in <100ms.
MUKUL-TIWARI/CyberShield-Security-Suite
AI-powered phishing, email, and vishing detection system.
Farimah20/cctv-security-system
AI-Powered CCTV Security Monitor with Theft Detection
