CISA issues guidance on default admin credentials in GoHarbor Harbor
GoHarbor Harbor deployments that keep the default admin password allow remote authentication and full registry compromise.
Decision Insights Threat Desk • March 24, 2026
GoHarbor Harbor deployments that keep the default admin password allow remote authentication and full registry compromise.
Decision Insights Threat Desk • March 16, 2026
A log-injection flaw in LibreChat RAG API 0.7.0 lets authenticated users alter system logs and audit records.
Decision Insights Threat Desk • March 12, 2026
graphql-upload-minimal v1.6.1 contains a prototype pollution flaw that can modify Object.prototype and affect Node.js processes.
Decision Insights Threat Desk • March 12, 2026
CISA details unsafe pickle deserialization in SGLang that can allow remote code execution via the ZMQ broker or replay_request_dump.py
Decision Insights Threat Desk • March 9, 2026
CISA reports antivirus and EDR scanners can miss payloads in ZIP archives with tampered compression metadata.
Decision Insights Threat Desk • March 5, 2026
Viber's Cloak mode on Android and Windows uses a static TLS ClientHello that can be detected and blocked, possibly causing DoS.