Your Cybersecurity
Learning Base
Free CEH-aligned courses, live CVE threat intelligence, and in-depth security research — everything you need to learn ethical hacking and stay ahead of real threats.
Learn ethical hacking — in plain words.
Beginner-friendly cybersecurity courses covering 100% of the CEH exam, with narrated whiteboard videos, quizzes, and spaced-repetition review. No login required — start learning in seconds.
Latest CVEs
A flaw was found in the ipa_getkeytab module of the community.general Ansible collection. The module's bind_pw parameter, used to supply the LDAP simple-bind password when retrieving a Kerberos keytab, is not declared with no_log, unlike the sibling password parameter in the same module. As a consequence, the supplied IPA/LDAP bind password is recorded in cleartext in the managed host's system journal/syslog (the module's "Invoked with" record), is included in the module's return values and verbose (-v) output, and is displayed in Automation Controller / AWX job output. The password is additionally passed on the command line to the ipa-getkeytab helper (as --bindpw <value>), exposing it in the process list to local users while the command runs. An attacker able to read these logs, job output, or the process table can obtain the directory bind credential, potentially compromising the accounts and objects that credential can access.
Aug 26
A vulnerability has been found in SourceCodester Simple Online Food Ordering System 1.0. This affects an unknown function of the file /admin/ajax.php?action=login2. The manipulation of the argument email leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Aug 26
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API endpoints are exposed on the same public routing boundary as the SSO login and callback endpoints, so SSO, OIDC, and SAML management operations can be reached without administrator authorization. Because reading, creating, and updating the global SSO configuration is not restricted to administrators, an unauthorized or low-privileged user can inspect or alter the authentication configuration, which under certain conditions can lead to account takeover or privilege escalation. The SSO connectivity-test function can additionally be abused as a server-side request forgery primitive, and the user list API returns user objects without consistently clearing authentication-related fields. This issue is fixed in version 2.0.0.
Aug 26
KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 2.0.0, cluster-scoped APIs do not consistently validate per-cluster access, allowing an authenticated user with cluster management permissions to operate on clusters outside the scope they were granted. Because the affected endpoints act on cluster-specific data without confirming that the requesting user is authorized for that particular cluster, a user assigned management rights over one cluster can, under certain role and cluster configurations, read or modify data in clusters they should not manage. This issue is fixed in version 2.0.1.
Aug 26
Latest Articles
BSI IT-Grundschutz: Complete Implementation Guide for 2026
Everything about BSI IT-Grundschutz: how it works, how it compares to ISO 27001, the three protection levels, and how German and international organizations can implement it.
CVD Policy Template: How to Build a Responsible Disclosure Program
Step-by-step guide to creating a Coordinated Vulnerability Disclosure (CVD) policy: what to include, safe harbor language, response timelines, and a free policy template for your organization.
DORA Compliance: Technical Requirements for Financial Institutions
A practical guide to DORA (Digital Operational Resilience Act): ICT risk management, incident classification, TLPT testing, third-party risk, and what financial firms must implement by January 2025.
Want to test the AI scanner?
Our AI penetration testing agent is in private beta — it autonomously scans, exploits, and verifies vulnerabilities with zero false positives. Try it on your own targets.