August 6, 2026
- Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920), with a full write-up of the injection (syntetisk.tech). · Vulnerabilities & Exploits
in OpenAI's Rogue-Agent Post-Mortem: A Swarm That Rebuilt Its Own Message Board