Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
HashiCorp, Veeam, and the Django Software Foundation have released patches for 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and…
A separate bucket-squatting vulnerability in Google Vertex AI Experiments that allowed cross-tenant code execution, model theft, and poisoning. Patched by Google in…
A critical authorization bypass vulnerability (CVSS 9.1) in Dify that allows authenticated editor users to set and enable trace configurations for any…
An authorization bypass vulnerability (CVSS 7.5/5.9) in Dify's file preview endpoint that allows any authenticated user to read up to 3,000 characters…