View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Millions of Shark Vacuums Vulnerable to Remote Code Execution

🚨 ACTIVE EXPLOITS & INCIDENTS

🔓 VULNERABILITIES & CVEs

  • VU#326070: SGLang Pickle Deserialization RCE (CVE-2026-14890) — CERT/CC
    SGLang, an open-source framework for large language models, contains a critical pickle deserialization flaw in its expert-parallel backup subsystem enabling remote code execution. Exploitation requires network access and the subsystem to be enabled. No patch or maintainer response yet. CVSS likely high due to RCE and LLM integration.

  • PipeWire Sandbox Escape and Arbitrary Code Execution (CVE-2026-5674) — CVE ThreatInt
    A sandbox escape vulnerability in PipeWire’s PulseAudio compatibility layer allows attackers to break out of Flatpak and similar sandboxed apps. This elevates risk for Linux desktop environments relying on PipeWire for multimedia services.

  • HCL DFXAnalytics Internal File Path Disclosure — CVE ThreatInt
    HCL DFXAnalytics dashboard leaks sensitive internal file path information, potentially aiding attackers in reconnaissance and further exploitation. Immediate review of dashboard exposure and patching recommended.

  • n8n Token Exchange Flaw Enables Cross-Issuer Account Takeover — The Hacker News
    n8n’s Enterprise instances trusting multiple external token issuers improperly authenticate users by sub claim alone, ignoring iss. Valid tokens from one issuer can log in as users from another, bypassing passwords. Critical for organizations using n8n Enterprise with multi-issuer configs to apply mitigations.

  • Google IdP Universal Account Takeover via Device Code Flow Hijacking — r/netsec
    Google’s implementation of RFC 8628 device authorization grant is vulnerable to a confused deputy attack allowing invisible, one-click account takeovers across browsers. The authorization server fails to validate client_id and scope consistency, enabling session hijacking. Urgent review of OAuth device flow security advised.

🕵️ THREAT RESEARCH & DEEP DIVES

  • Protecting Privacy in an AI Era — Schneier on Security
    Daniel Solove advocates shifting privacy regulation focus from individual control to corporate accountability, recommending data minimization, fiduciary duties, and liability for negligent AI design. This framework is critical as AI systems increasingly handle sensitive personal data.

  • AI Agents Broke the Security Playbook. Here's What Replaces It. — BleepingComputer
    Traditional security workflows fail against AI agents operating at machine speed. Token Security proposes a new model based on live identity foundations and customizable workflows, signaling a paradigm shift in identity and access management for AI-driven environments.

📰 LESSER-KNOWN / UNDER-REPORTED

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check