Tuesday , August 4 2026

Recent Posts

Tenda N300 Vulns Let Attacker to Execute Arbitrary Commands

Tenda

CERT/CC has warned of unpatched command injection vulnerabilities in Tenda’s 4G03 Pro and N300 routers. These flaws allow attackers to execute root commands, and there are no fixes from the vendor, putting users at risk. According to the advisory, “A command injection vulnerability exists across multiple firmware versions that allows …

Read More »

ShinyHunters Claims Breaches Over 200 Companies via Salesforce Gainsight Breach

Salesforce

Salesforce said on Wednesday that it’s investigating a breach of “certain customers’ Salesforce data” that was compromised through apps published by Gainsight, a company that sells a platform for other companies to manage their customers. In a notice published late Wednesday, Salesforce said the hacks involve “Gainsight-published applications connected to …

Read More »

WhatsApp API flaw let researchers scrape millions of Bangladeshi accounts

API

Researchers gathered 3.5 billion WhatsApp phone numbers and personal information by abusing a contact-discovery API without proper rate limiting. This study shows a common tactic used by threat actors to collect user information from unprotected public APIs, even though the researchers haven’t shared the data. Abusing WhatsApp API: The researchers …

Read More »