🕵️ RESEARCH & DEEP DIVES
- Chinese Civic Apps Share Vulnerable Reward Backend Allowing Forged Lottery Claims — neurowinter.com
Multiple Chinese civic apps use a shared reward backend with a recoverable signing secret enabling forged reward claims.- Applies to multiple Chinese civic and government-adjacent apps across Zhejiang and Guangdong prefectures
- Vulnerability in shared multi-tenant SaaS reward backends from providers like tmuyun, aihoge, jinhua, and Duiba
- Signing secret intended to secure reward claims is publicly recoverable from client-side code
- Attackers can forge valid reward claims and lottery wins accepted by backend APIs
- Forged claims can target daily bonuses, quizzes, sweepstakes, and potentially access citizen PII
🔓 CVEs & KEV
-
CVE-2026-10130: QueryWeaver Authentication Bypass via Email Signup Token Issuance — CVSS 8.2
Authentication bypass vulnerability in QueryWeaver via email signup token issuance for existing users. -
CVE-2026-16197: Sipeed PicoClaw Group Message feishu_64.go handleMessageReceive Authorization Issue — CVSS 6.3
Authorization flaw in Sipeed PicoClaw Group Message handling. -
CVE-2026-16196: Sipeed PicoClaw web_fetch web.go isPrivateOrRestrictedIP SSRF — CVSS 6.3
Server-side request forgery vulnerability in Sipeed PicoClaw web_fetch component. -
CVE-2026-16195: Sipeed PicoClaw Group Message wecom.go dispatchIncoming Authorization Issue — CVSS 6.3
Security issue in authorization for incoming dispatch in Sipeed PicoClaw Group Message.