π VENDOR BULLETINS & ADVISORIES
- Microsoft: Some Dell PCs shut down after recent Windows updates β BleepingComputer
Microsoft is blocking this monthβs Windows 11 security updates on select Dell devices due to shutdowns and performance degradation. Organizations with Dell hardware should delay applying these updates until a fix is released to avoid operational disruptions.
π VULNERABILITIES & CVEs
-
Joomla Extension EDocman Unauthenticated Blind SQL Injection (CVE-2026-57832) β CVE ThreatInt
An unauthenticated blind SQL injection vulnerability affects the Joomla EDocman extension, enabling remote attackers to extract sensitive database information without credentials. Immediate patching or mitigation is advised to prevent data leakage. -
Joomla Extension DP Calendar Unauthenticated Blind SQL Injection (CVE-2026-57831) β CVE ThreatInt
Similar to EDocman, the DP Calendar Joomla extension suffers from an unauthenticated blind SQL injection vulnerability. This flaw allows attackers to perform database reconnaissance and potentially escalate attacks. Update or disable the extension until patched. -
(More) Unauthenticated Arbitrary Code Execution in ServiceNow β r/netsec
New reports detail unauthenticated arbitrary code execution vulnerabilities in ServiceNow instances, posing critical risks for remote compromise. Organizations using ServiceNow should urgently review vendor advisories and apply mitigations or patches.
π΅οΈ THREAT RESEARCH & DEEP DIVES
- The Memory Heist β How I tricked Claude into leaking your deepest, darkest secrets β r/netsec
A technical deep dive reveals novel prompt injection techniques to exfiltrate sensitive data from AI language models like Claude. This research highlights emerging risks in AI-assisted environments and the need for hardened input validation and monitoring.
π° LESSER-KNOWN / UNDER-REPORTED
- Weekly update: IoT Lockout Fail and Post-holiday Tech Fixes β @troyhunt@infosec.exchange
This weekβs update covers real-world IoT lockout failures and practical remediation steps post-holiday. While not a new vulnerability, the report provides actionable insights for securing consumer IoT devices against common misconfigurations and lockout scenarios.