FEATURE Two supply chain attacks in March infected open source tools with malware and used this access to steal secrets from ...
CVE-2026-34040 lets attackers bypass some Docker authentication plugins by allowing an empty request body. Present since 2024, this bug was caused by a previous fix to the auth workflow. In the ...
A single unauthenticated connection gives attackers a full shell; credential theft observed in under three minutes on honeypot servers.