DEV Community

Diego Diaz profile picture

Diego Diaz

Systems Engineering student building Sable & AEGIS. Cybersecurity, pentesting & AI enthusiast. Coding from Dominican Republic 🇩🇴

Joined Joined on  Personal website https://sable.somoswilab.com/
ServiceNow CVE-2026-6875: Pre-Auth RCE in the AI Platform Powering 85% of Fortune 500

ServiceNow CVE-2026-6875: Pre-Auth RCE in the AI Platform Powering 85% of Fortune 500

1
Comments
4 min read
HollowGraph Malware Uses Microsoft 365 Calendar Events as Dead-Drop C2 Channel

HollowGraph Malware Uses Microsoft 365 Calendar Events as Dead-Drop C2 Channel

Comments
3 min read
Critical 7‑Zip XZ Buffer Overflow (CVE‑2026‑14266) Discovered and Patched

Critical 7‑Zip XZ Buffer Overflow (CVE‑2026‑14266) Discovered and Patched

Comments
3 min read
Critical NGINX Vulnerability CVE-2026-42533 Allows Remote Code Execution

Critical NGINX Vulnerability CVE-2026-42533 Allows Remote Code Execution

Comments
2 min read
Telus Digital: ShinyHunters robĂł 1PB y exigiĂł $65M

Telus Digital: ShinyHunters robĂł 1PB y exigiĂł $65M

Comments
4 min read
DarkSword: El Exploit que HackeĂł tu iPhone sin que lo Supieras

DarkSword: El Exploit que HackeĂł tu iPhone sin que lo Supieras

Comments
4 min read
Cisco FMC Zero-Day: 36 DĂ­as con Ransomware en tu Red

Cisco FMC Zero-Day: 36 DĂ­as con Ransomware en tu Red

Comments
4 min read
Breach Intuitive Surgical: Un Email Comprometió Datos Médicos

Breach Intuitive Surgical: Un Email Comprometió Datos Médicos

Comments
4 min read
Marquis: CĂłmo un Proveedor Fintech Expuso 672,000 NĂşmeros de Seguro Social

Marquis: CĂłmo un Proveedor Fintech Expuso 672,000 NĂşmeros de Seguro Social

Comments
5 min read
Foster City Declara Emergencia: Ransomware Paraliza Toda una Ciudad

Foster City Declara Emergencia: Ransomware Paraliza Toda una Ciudad

Comments
6 min read
Navia Benefit Solutions: 2.7 Millones de Registros de Salud Robados en Silencio

Navia Benefit Solutions: 2.7 Millones de Registros de Salud Robados en Silencio

Comments
6 min read
BlueLeaks 2.0: Hackers Exponen 8.3 Millones de Tips AnĂłnimos a la PolicĂ­a

BlueLeaks 2.0: Hackers Exponen 8.3 Millones de Tips AnĂłnimos a la PolicĂ­a

Comments
6 min read
LAPSUS$ Reclama el Hack de AstraZeneca: 3GB de CĂłdigo Fuente y Claves Cloud

LAPSUS$ Reclama el Hack de AstraZeneca: 3GB de CĂłdigo Fuente y Claves Cloud

Comments
5 min read
Trivy Comprometido: La Herramienta que Escanea tus Vulnerabilidades Ahora Roba tus Credenciales

Trivy Comprometido: La Herramienta que Escanea tus Vulnerabilidades Ahora Roba tus Credenciales

Comments
6 min read
CanisterWorm: El Mismo Grupo que AtacĂł Trivy Ahora Infecta 135 Paquetes de npm

CanisterWorm: El Mismo Grupo que AtacĂł Trivy Ahora Infecta 135 Paquetes de npm

Comments
5 min read
Crunchyroll Hackeada: 100GB Robados vĂ­a un Empleado de Telus

Crunchyroll Hackeada: 100GB Robados vĂ­a un Empleado de Telus

Comments
5 min read
Dos Zero-Days en Chrome con Exploits Activos: Actualiza Ahora

Dos Zero-Days en Chrome con Exploits Activos: Actualiza Ahora

Comments
5 min read
Pay2Key Regresa: El Ransomware IranĂ­ Que Paga el 80% a Sus Afiliados

Pay2Key Regresa: El Ransomware IranĂ­ Que Paga el 80% a Sus Afiliados

Comments
6 min read
LexisNexis Hackeada: Jueces Federales y Abogados del DOJ Expuestos con Password "Lexis1234"

LexisNexis Hackeada: Jueces Federales y Abogados del DOJ Expuestos con Password "Lexis1234"

Comments
5 min read
Three Microsoft Defender Zero-Days Under Active Attack; Two Remain Unpatched

Three Microsoft Defender Zero-Days Under Active Attack; Two Remain Unpatched

Comments
3 min read
ADT Confirms Data Breach: ShinyHunters Claim 10 Million Records Stolen

ADT Confirms Data Breach: ShinyHunters Claim 10 Million Records Stolen

Comments
5 min read
Anthropic MCP RCE: 7,000 Servers Exposed and Why L1 Fast-Path Matters

Anthropic MCP RCE: 7,000 Servers Exposed and Why L1 Fast-Path Matters

Comments
2 min read
Booking.com Breach: When the Vendor Chain Becomes the Attack Surface

Booking.com Breach: When the Vendor Chain Becomes the Attack Surface

1
Comments
2 min read
Ollama Model Loading RCE: Three Years of the Same Bug Class, One Self-Hosted LLM Runtime

Ollama Model Loading RCE: Three Years of the Same Bug Class, One Self-Hosted LLM Runtime

Comments
7 min read
LMDeploy SSRF Vulnerability Exploited Within 13 Hours: What You Need to Know

LMDeploy SSRF Vulnerability Exploited Within 13 Hours: What You Need to Know

Comments
2 min read
Itron Smart Meter Breach: 28M Utility Customers Exposed via API Flaw

Itron Smart Meter Breach: 28M Utility Customers Exposed via API Flaw

Comments
5 min read
GitHub Actions Supply Chain in 2026: tj-actions, Trivy, Bitwarden, and the Year the Bots Showed Up

GitHub Actions Supply Chain in 2026: tj-actions, Trivy, Bitwarden, and the Year the Bots Showed Up

Comments
8 min read
Adobe Reader Zero-Day CVE-2026-34621: Prototype Pollution + Use-After-Free Exploited Since November 2025

Adobe Reader Zero-Day CVE-2026-34621: Prototype Pollution + Use-After-Free Exploited Since November 2025

Comments
7 min read
SonicWall SMA 1000 Series Hit by Active Zero-Day Exploits (CVE-2026-15409 & CVE-2026-15410)

SonicWall SMA 1000 Series Hit by Active Zero-Day Exploits (CVE-2026-15409 & CVE-2026-15410)

Comments
2 min read
Lovable BOLA: 48 Days, Five API Calls, Source Code + Database Credentials of Other People's Projects

Lovable BOLA: 48 Days, Five API Calls, Source Code + Database Credentials of Other People's Projects

Comments
7 min read
Kubernetes RBAC in 2026: From nodes/proxy to AKS CVE-10.0 — Three Real Paths to Cluster-Admin

Kubernetes RBAC in 2026: From nodes/proxy to AKS CVE-10.0 — Three Real Paths to Cluster-Admin

Comments
7 min read
CVE-2026-41940: cPanel Auth Bypass Exploited 65 Days as 0-Day, 1.5M Servers Exposed

CVE-2026-41940: cPanel Auth Bypass Exploited 65 Days as 0-Day, 1.5M Servers Exposed

Comments
7 min read
France's ID Agency Breach Exposes 19 Million Passport and National ID Records

France's ID Agency Breach Exposes 19 Million Passport and National ID Records

Comments
4 min read
cPanel Zero-Day CVE-2026-41940: Authentication Bypass Hit 1.5M Servers Before Patch

cPanel Zero-Day CVE-2026-41940: Authentication Bypass Hit 1.5M Servers Before Patch

Comments
3 min read
CVE-2026-41940: cPanel Authentication Bypass Hit 1.5M Servers Before Anyone Noticed

CVE-2026-41940: cPanel Authentication Bypass Hit 1.5M Servers Before Anyone Noticed

Comments
3 min read
Next.js API Security Vulnerabilities: The 10 Most Common Findings (2026)

Next.js API Security Vulnerabilities: The 10 Most Common Findings (2026)

Comments
6 min read
¿Qué es el Pentesting? Guía Completa 2026 para Startups

¿Qué es el Pentesting? Guía Completa 2026 para Startups

Comments
5 min read
Supabase Security Checklist 2026: 15 Checks Esenciales para ProducciĂłn

Supabase Security Checklist 2026: 15 Checks Esenciales para ProducciĂłn

Comments
5 min read
Startup Security Audit Checklist 2026: 50 Checks Before You Ship

Startup Security Audit Checklist 2026: 50 Checks Before You Ship

Comments
5 min read
CVE-2026-32202: APT28 Exploits Incomplete Windows Patch to Steal NTLM Hashes Zero-Click

CVE-2026-32202: APT28 Exploits Incomplete Windows Patch to Steal NTLM Hashes Zero-Click

Comments
3 min read
Penetration Testing for Startups in 2026: The Complete Founder's Guide

Penetration Testing for Startups in 2026: The Complete Founder's Guide

Comments
8 min read
CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Lets Attackers Crash Servers and Potentially Execute Remote Code

CVE-2026-23918: Apache HTTP/2 Double-Free Flaw Lets Attackers Crash Servers and Potentially Execute Remote Code

Comments
4 min read
Ivanti EPMM CVE-2026-6973 RCE Is Under Active Exploit — Patch by Sunday

Ivanti EPMM CVE-2026-6973 RCE Is Under Active Exploit — Patch by Sunday

Comments
4 min read
I scanned 100 vibe-coded apps. 73 had a BOLA.

I scanned 100 vibe-coded apps. 73 had a BOLA.

Comments
6 min read
The 8-item security checklist no one tells indie devs

The 8-item security checklist no one tells indie devs

Comments
6 min read
Dirty Frag: Chained Linux Kernel Flaws Give Root on Every Major Distribution

Dirty Frag: Chained Linux Kernel Flaws Give Root on Every Major Distribution

Comments
4 min read
How BOLA killed my MVP (and what I wish I'd done before launch)

How BOLA killed my MVP (and what I wish I'd done before launch)

Comments
5 min read
Fake OpenAI Repo on Hugging Face Delivered Rust Infostealer to 244,000 Developers

Fake OpenAI Repo on Hugging Face Delivered Rust Infostealer to 244,000 Developers

Comments
4 min read
Two Critical CVEs Hit Hugging Face: TGI DoS (CVE-2026-0599) and LeRobot Unauthenticated RCE (CVE-2026-25874)

Two Critical CVEs Hit Hugging Face: TGI DoS (CVE-2026-0599) and LeRobot Unauthenticated RCE (CVE-2026-25874)

Comments
5 min read
Exim CVE-2026-45185 — Unauthenticated RCE in the World's Most Deployed Mail Server

Exim CVE-2026-45185 — Unauthenticated RCE in the World's Most Deployed Mail Server

1
Comments
3 min read
Hackers Used AI to Build a Zero-Day That Bypasses Two-Factor Authentication — Google Stopped It

Hackers Used AI to Build a Zero-Day That Bypasses Two-Factor Authentication — Google Stopped It

Comments
4 min read
Mini Shai-Hulud Worm Hits 172 npm Packages — Including TanStack, Mistral AI, and Guardrails AI

Mini Shai-Hulud Worm Hits 172 npm Packages — Including TanStack, Mistral AI, and Guardrails AI

Comments
3 min read
Microsoft Patches 138 Vulnerabilities: Netlogon and DNS RCE Flaws Lead May Update

Microsoft Patches 138 Vulnerabilities: Netlogon and DNS RCE Flaws Lead May Update

Comments
4 min read
Hugging Face Double CVE: TGI DoS and LeRobot RCE Expose AI Infrastructure

Hugging Face Double CVE: TGI DoS and LeRobot RCE Expose AI Infrastructure

Comments
4 min read
NGINX Rift: 18-Year-Old Heap Overflow Lets Attackers Hijack One-Third of the Web

NGINX Rift: 18-Year-Old Heap Overflow Lets Attackers Hijack One-Third of the Web

Comments
3 min read
PraisonAI Auth Bypass Was Scanned 4 Hours After Disclosure — And It's an AI Agent Framework

PraisonAI Auth Bypass Was Scanned 4 Hours After Disclosure — And It's an AI Agent Framework

Comments
4 min read
Microsoft Patch Tuesday 2026: 622 Fixes Including Two Actively‑Exploited Zero‑Days

Microsoft Patch Tuesday 2026: 622 Fixes Including Two Actively‑Exploited Zero‑Days

Comments
2 min read
Claw Chain: Four OpenClaw Vulnerabilities Expose 245,000 AI Agent Servers to Data Theft

Claw Chain: Four OpenClaw Vulnerabilities Expose 245,000 AI Agent Servers to Data Theft

Comments
3 min read
Cisco SD-WAN Auth Bypass CVE-2026-20182 Added to CISA KEV — Patch by May 17

Cisco SD-WAN Auth Bypass CVE-2026-20182 Added to CISA KEV — Patch by May 17

Comments
3 min read
Microsoft Exchange OWA Zero-Day CVE-2026-42897 Exploited via Crafted Emails

Microsoft Exchange OWA Zero-Day CVE-2026-42897 Exploited via Crafted Emails

Comments
3 min read
loading...