Public library
Cybersecurity articles
Automated coverage from researcher feeds — text + code extraction, no thumbnails. Sort by recent, popular, or trending.
All sources ×PortSwigger Research RSSGoogle Project ZeroUnit 42 (Palo Alto)r/netsec RSSSchneier on SecurityZero Day InitiativeMicrosoft MSRC BlogTrail of BitsnccgroupCisco TalosPentesterLand WriteupsSecurelist (Kaspersky)Cloudflare Blogr/bugbounty RSSKrebs on Security RSSSANS Internet Storm Center RSSThe Hacker News RSSbleepingGitHub Security Advisories
asyncssh has an incomplete fix for CVE-2026-45309 — AuthorizedKeysFile %u still escapes the intended directory via a leading ~ (and weakly via ${ENV}) username substitution
Read →**Incomplete fix for CVE-2026-45309 (GHSA-g794-3fmp-753h).** The 2.23.0 guard that sanitises the SSH username before `%u` substitution in `AuthorizedKeysFile` blocks `/`, `\` and `..`, but does not block a leading `~` (or `${ENV}`), both of which are re-introduced by later expansion and reach the...
Prefer original Bugflare research? Browse writeups