A curated dispatch from GajShield

The GajShield Gazette

Lead story

Gitea Vulnerability Exposes Private Container Images without Authentication

The Gitea vulnerability is a serious reminder that “private” only means private when the platform enforces it correctly. The flaw, tracked as CVE-2026-27771, affects Gitea versions before 1.26.2 and allows unauthenticated remote attackers to pull private container images from …

Also today
In brief

Wireshark 4.6.6 Released, (Sun, May 24th)

The SANS ISC diary notes that Wireshark 4.6.6 has been released, fixing one vulnerability and 11 bugs. For Windows users, the bundled packe…

May 27, 2026

TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities

Cisco Talos’ vulnerability roundup is a useful reminder that risk is not limited to one category of product. The disclosures cover TP-Link …

May 27, 2026

Possible ACR Stealer From Page Impersonating Claude, (Tue, May 26th)

The SANS ISC diary on a fake Claude download page shows how attackers are abusing AI brand trust to deliver malware. The page impersonated …

May 27, 2026

Charter confirms data breach after ShinyHunters extortion threat

The Charter Communications breach is another reminder that attackers do not always need to break complex infrastructure directly. Sometimes…

May 27, 2026

MuddyWater Uses DLL Side-Loading in Espionage Campaign Targeting 9 Countries

The MuddyWater campaign shows how espionage groups continue to rely on practical, low-noise techniques rather than flashy zero-days. Accord…

May 26, 2026

Eppendorf BioFlo 320

CISA’s ICSMA-26-146-01 medical advisory is another reminder that cybersecurity in healthcare is directly tied to patient safety, clinical c…

May 26, 2026

Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions

Microsoft’s patch for CVE-2026-45659 in SharePoint is another reminder that collaboration platforms are high-value enterprise targets, not …

May 26, 2026

CISA orders feds to patch actively exploited Drupal vulnerability

CISA’s order to patch the actively exploited Drupal vulnerability is a clear reminder that internet-facing CMS platforms remain a favorite …

May 26, 2026

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

The KnowledgeDeliver LMS exploit is a strong reminder that shared deployment secrets can turn one vulnerable installation into a risk for m…

May 26, 2026

Microsoft: Domain Controller lookup may fail on Windows Server 2016

Microsoft’s Windows Server 2016 domain controller lookup issue is a reminder that even routine security updates can create operational impa…

May 26, 2026

FBI warns of Kali365 phishing service targeting Microsoft 365 accounts

The TrapDoor supply-chain campaign is another warning that attackers are no longer targeting only one package ecosystem at a time. Accordin…

May 25, 2026