Decision Insights Threat Desk
CISA advisories, vendor security bulletins, and CVE disclosures, summarized into sourced briefs. Produced under our Standards & Methodology.
CISA advisories, vendor security bulletins, and CVE disclosures, summarized into sourced briefs. Produced under our Standards & Methodology.
Decision Insights Threat Desk • October 1, 2026
HP PC BIOS with InsydeH2O IHISI is affected by CVE-2026-12855, which enables arbitrary physical memory writes via an SMI handler.
Decision Insights Threat Desk • September 28, 2026
Authlib versions up to 1.7.2 allow JWS verification bypass when “signatures” is an empty array.
Decision Insights Threat Desk • September 25, 2026
Readwise Reader Android 8.7.2 has stored XSS bugs tied to CVE-2026-18311, CVE-2026-18312, and CVE-2026-18320.
Decision Insights Threat Desk • September 24, 2026
Overview Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency…
Decision Insights Threat Desk • September 24, 2026
ViewSonic vCast contains unauthenticated flaws CVE-2026-82989, -82988, and -82987 that can be chained for full device compromise.
Decision Insights Threat Desk • September 23, 2026
Cinnamon’s Kotaemon (all versions up to v0.12.0) improperly checks conversation ownership, letting authenticated users read, delete, rename, or overwrite others’ conversations.