daily cyber × ai intelligence

index

tagged

[curl]

2 editions · 2 items

September 4, 2026

  • curl disclosed a large batch of HackerOne reports, several with real exploitation relevance: an OpenLDAP SASL flaw letting a malicious server bypass authentication and inject LDAP responses (CVE-2026-13608), a pinned-key validation bypass with anonymous ciphers and --insecure (CVE-2026-80230), plus cookie-parsing bugs that store Secure cookies insecurely and Windows Negotiate connection reuse with the wrong ambient credentials. · Exploitation & Vulnerabilities

in Malware That Gaslights the AI Analyst

June 26, 2026

  • curl shipped fixes for a large batch of CVEs including its oldest-ever reported bug (~24–25 years old), with HackerOne reports detailing several credential-leak and connection-reuse flaws — stale proxy passwords (CVE-2026-9079), .netrc password mispairing (CVE-2026-8926), an SSH host-key mismatch silently accepted (CVE-2026-9547), STARTTLS session reuse enabling MITM (CVE-2026-8286), and ASan-validated UAF/Referer leaks (CVE-2026-9546). Aisle, SecurityWeek · Vulnerabilities & Exploits

in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine