threatchain

0 Followers
9 Following
88 Posts

Free threat intelligence platform. Search 2.6M+ IOCs, malware analysis, smart contract auditing. Open source SIEM.

πŸ” Free threat intel search:
πŸ‘‰ https://threatchain.io

Threat Searchhttps://threatchain.io
GitHubgithub.com/threatchain
Bloghttps://threatchain.io/blog
Your periodic reminder that "a limited number" is meaningless vendor speak which provides no constraint on the impact: 'Last week, Figure confirmed a data breach allowed hackers to steal β€œa limited number of files” from its systems'
Chaser: 'Troy Hunt, a security researcher and creator of the data breach notification site Have I Been Pwned, analyzed the data allegedly taken from Figure and found it contained 967,200 unique email addresses associated with Figure customers'
https://techcrunch.com/2026/02/18/data-breach-at-fintech-giant-figure-affects-close-to-a-million-customers/
Data breach at fintech giant Figure affects close to a million customers | TechCrunch

The Figure data breach allowed hackers to steal customer names, dates of birth, physical addresses, phone numbers, and email addresses.

TechCrunch

713,000 Emails Exposed: Provecho Recipe Platform Hit by a Major Data Breach

Introduction: A Quiet App, A Loud Breach Another day, another data breach β€” but this one flew under the radar faster than most. Earlier this month, Provecho, a recipe-sharing platform used by home cooks and content creators, allegedly suffered a security incident that exposed hundreds of thousands of user records. The breach was later disclosed by the widely trusted breach-notification service…

https://undercodenews.com/713000-emails-exposed-provecho-recipe-platform-hit-by-a-major-data-breach/

713,000 Emails Exposed: Provecho Recipe Platform Hit by a Major Data Breach - UNDERCODE NEWS

Another day, another data breach β€” but this one flew under the radar faster than most. Earlier this month, Provecho, a recipe-sharing platform used by home

UNDERCODE NEWS

πŸ”΄ CVE-2026-34841 - Critical (9.8)

Bruno is an open source IDE for exploring and testing APIs. Prior to 3.2.1, Bruno was affected by a supply chain attack involving compromised versions of the axios npm package, which introduced a hidden dependency deploying a cross-platform Remote...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-34841/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

πŸ”΄ CVE-2026-34950 - Critical (9.1)

fast-jwt provides fast JSON Web Token (JWT) implementation. In 6.1.0 and earlier, the publicKeyPemMatcher regex in fast-jwt/src/crypto.js uses a ^ anchor that is defeated by any leading whitespace in the key string, re-enabling the exact same JWT ...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-34950/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

πŸ”΄ CVE-2026-35216 - Critical (9)

Budibase is an open-source low-code platform. Prior to version 3.33.4, an unauthenticated attacker can achieve Remote Code Execution (RCE) on the Budibase server by triggering an automation that contains a Bash step via the public webhook endpoint...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-35216/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

Fujisoft Unveils AI-Powered Security System Built on AMD Embedded+ Platform

Introduction: A New Era of Intelligent Site Security As industrial environments continue to evolve toward automation, the demand for smarter and more reliable security systems is rapidly increasing. Factories, warehouses, and large-scale facilities are no longer simple operational spaces. They are complex ecosystems filled with sensors, cameras, and interconnected devices generating massive…

https://undercodenews.com/fujisoft-unveils-ai-powered-security-system-built-on-amd-embedded-platform/

Fujisoft Unveils AI-Powered Security System Built on AMD Embedded+ Platform - UNDERCODE NEWS

As industrial environments continue to evolve toward automation, the demand for smarter and more reliable security systems is rapidly increasing. Factories,

UNDERCODE NEWS

🚨 EUVD-2026-19345

πŸ“Š Score: 8.1/10 (CVSS v3.1)
πŸ“¦ Product: crm
🏒 Vendor: ChurchCRM
πŸ“… Updated: 2026-04-06

πŸ“ ChurchCRM is an open-source church management system. Prior to 7.1.0, authenticated users with Edit Records or Manage Groups permissions can exploit a time-based blind SQL injection vulnerability in the PropertyAssign.php endpoint to exfiltrate or modify any d...

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19345

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🚨 EUVD-2026-19336

πŸ“Š Score: 7.8/10 (CVSS v3.1)
πŸ“¦ Product: Snapdragon, Snapdragon, Snapdragon (+20 more)
🏒 Vendor: Qualcomm, Inc.
πŸ“… Updated: 2026-04-06

πŸ“ Memory Corruption when using deprecated DMABUF IOCTL calls to manage video memory.

πŸ”— https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-19336

#cybersecurity #infosec #euvd #cve #vulnerability

EUVD

European Vulnerability Database

🟠 CVE-2026-35470 - High (8.8)

OpenSTAManager is an open source management software for technical assistance and invoicing. Prior to 2.10.2, confronta_righe.php files across different modules in OpenSTAManager contain an SQL Injection vulnerability. The righe parameter received...

πŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-35470/

#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack