BBUGFLARE

Public library

Cybersecurity articles

Automated coverage from researcher feeds — text + code extraction, no thumbnails. Sort by recent, popular, or trending.

GitHub Advisories20
s2n-quic has excessive memory allocation

s2n-quic is a Rust implementation of the QUIC protocol. An unauthenticated user can attempt to exhaust server memory on an s2n-quic endpoint by sending crafted CRYPTO frames with high offsets. The buffer used for processing CRYPTO frames does not enforce a maximum size. In the worst case, a singl...

Read →
GitHub Advisories20
Token Optimizer MCP: Unauthenticated Path Traversal in Dashboard Session Log API Endpoints

# Unauthenticated Path Traversal in Dashboard Session Log API Endpoints | Field | Value | | ---------------- | ----- | | Repository | ooples/token-optimizer-mcp | | Affected version | 5.0.1 (commit 8137147) | | Vulnerability | CWE-22 — Improper Limitation of a Pathname to a Restricted Directory |...

Read →
GitHub Advisories35
Token Optimizer MCP: OS command injection in smart_user via username in get-user-info

### Summary `token-optimizer-mcp` is vulnerable to OS command injection in the `smart_user` tool. The `get-user-info` operation accepts a user-controlled `username` argument and later interpolates it into a shell command executed through `execAsync()`: ```ts getent passwd "${username}" || grep "^...

Read →
GitHub Advisories20
ContextForge: DNS TOCTOU race condition causes SSRF protection bypass (`/admin/gateways/test`)

## Summary The `/admin/gateways/test` endpoint validates submitted URLs by resolving the hostname at validation time and blocking private address ranges. The HTTP client independently re-resolves DNS at connection time with no IP binding between the two operations, creating a TOCTOU window exploi...

Read →
GitHub Advisories20
SurrealDB: Array element-level (field.*) SELECT permissions leak denied elements to record users

A `SELECT` permission defined on an array element (`DEFINE FIELD field.* … PERMISSIONS FOR select …`) is not enforced correctly for `RECORD` users. Instead of hiding the denied elements, the query leaks a subset of them: a deny-all returns the odd-indexed elements, and a per-element predicate kee...

Read →
The August 2026 Security Update Review

I’ve successfully survived Hacker Summer Camp, and I have returned with a new outlook on patch density. When even Linus Torvalds says that huge updates are the “ new normal ”, it’s time to readjust what we consider a true bug apocalypse. This month’s release is thankfully smaller than last months...

Read →
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise appeared first on Microsoft Se...

Read →
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims. Th...

Read →
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide

A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities. The post From open lures to cloaked gates: How a macOS ...

Read →
The July 2026 Apple Security Update Review

Welcome to our monthly look at Apple security patches. This release shows that Apple is not immune to the bug apocalypse that is impacting other vendors. Last month, they released 37 unique CVEs compare to this month’s 210. Quite a jump. For July 2026, Apple released 210 unique CVEs across iOS/iP...

Read →
Pwn2Own Ireland 2026 – New Targets and Categories

If you just want to read the rules, you can find them here . Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random banshee ), we had an amazing event, even if we did end up in a jail at the end. Wit...

Read →

Prefer original Bugflare research? Browse writeups