๐จ SaaS platform ClickUp, used by 85% of the Fortune 500, has been leaking customer emails through its homepage for at least 465 days, and counting.
ClickUp has a $4 billion valuation. They are SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, and PCI DSS certified. The fix takes about 90 seconds.
Security researcher
weezerOSINT noticed a hardcoded Split[.]io SDK token sitting in plain text inside ClickUp's production JavaScript bundle. The bundle loads before you log in. View source, copy key, send one unauthenticated GET request, and 4.5MB of ClickUp's internal configuration is exposed: 959 customer emails and 3,165 internal feature flags.
The customer list consists of Home Depot. Fortinet, who sells enterprise firewalls. Tenable, who makes Nessus, the vulnerability scanner half the industry runs on. Autodesk. Rakuten. Mayo Clinic. Permira. Akin Gump. A Microsoft contractor. 71 ClickUp employees. Government workers from Wyoming, Arkansas, North Carolina, Montana, Queensland, and New Zealand.
It gets worse, ClickUp has a flag named "enable-missing-authz-checks." It is active in production. It lists five ClickUp API endpoints the company itself documented as having no authorization. They wrote down their own holes in a config anyone with a browser can read.
At first disclosure, another flag carried a live ClickUp API token tied to Fairfax County Public Schools, one of the largest school districts in the US, serving 180,000 students. The token pulled 1,066 staff records, including Chief Financial Services data. ClickUp removed that one token. They never rotated the SDK key that exposed it.
While that report rotted, the same researcher found a second bug. ClickUp's webhook API has zero SSRF protection. Reported via HackerOne on April 8, 2026. Status: "New." 19 days, zero response.
The original report was filed by weezerOSINT on January 17, 2025 (!). The key is still live. The emails still drop with one GET. ClickUp has had 465 days to rotate a single token. Zero response...
The fix is one click in the Split[.]io dashboard... ClickUp still hasn't replied to the researcher.
Original post of the researcher: https://x.com/weezerOSINT/status/2048662702957134199?s=20
ClickUp has a $4 billion valuation. They are SOC 2 Type 2, ISO 27001, ISO 27017, ISO 27018, ISO 42001, and PCI DSS certified. The fix takes about 90 seconds.
Security researcher
weezerOSINT noticed a hardcoded Split[.]io SDK token sitting in plain text inside ClickUp's production JavaScript bundle. The bundle loads before you log in. View source, copy key, send one unauthenticated GET request, and 4.5MB of ClickUp's internal configuration is exposed: 959 customer emails and 3,165 internal feature flags.
The customer list consists of Home Depot. Fortinet, who sells enterprise firewalls. Tenable, who makes Nessus, the vulnerability scanner half the industry runs on. Autodesk. Rakuten. Mayo Clinic. Permira. Akin Gump. A Microsoft contractor. 71 ClickUp employees. Government workers from Wyoming, Arkansas, North Carolina, Montana, Queensland, and New Zealand.
It gets worse, ClickUp has a flag named "enable-missing-authz-checks." It is active in production. It lists five ClickUp API endpoints the company itself documented as having no authorization. They wrote down their own holes in a config anyone with a browser can read.
At first disclosure, another flag carried a live ClickUp API token tied to Fairfax County Public Schools, one of the largest school districts in the US, serving 180,000 students. The token pulled 1,066 staff records, including Chief Financial Services data. ClickUp removed that one token. They never rotated the SDK key that exposed it.
While that report rotted, the same researcher found a second bug. ClickUp's webhook API has zero SSRF protection. Reported via HackerOne on April 8, 2026. Status: "New." 19 days, zero response.
The original report was filed by weezerOSINT on January 17, 2025 (!). The key is still live. The emails still drop with one GET. ClickUp has had 465 days to rotate a single token. Zero response...
The fix is one click in the Split[.]io dashboard... ClickUp still hasn't replied to the researcher.
Original post of the researcher: https://x.com/weezerOSINT/status/2048662702957134199?s=20
๐คฃ17โค5๐ฑ3
โผ๏ธ The arrogance of the official French Ministry for Europe and Foreign Affairs account is beyond comprehension, something you'd only expect from the Russian MFA.
Ridiculing a just concern about the European Commission's proposal that puts millions of Europeans at risk. The 'French Response' account was launched to fight disinformation, instead it is now mocking citizens for reading the Commission's own published documents...
Ridiculing a just concern about the European Commission's proposal that puts millions of Europeans at risk. The 'French Response' account was launched to fight disinformation, instead it is now mocking citizens for reading the Commission's own published documents...
๐คฌ18๐คฃ3๐ญ3๐2๐คช2โค1
โผ๏ธ๐จ BREAKING: Wiz got access to millions of GitHub repositories across users and organizations using one git push.
CVE-2026-3854: git push -o options injected into an internal header split by semicolons, parsed last-write-wins.
GitHub patched production in 6 hours.
Wiz published an article detailing what they've done: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
CVE-2026-3854: git push -o options injected into an internal header split by semicolons, parsed last-write-wins.
GitHub patched production in 6 hours.
Wiz published an article detailing what they've done: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
๐ฑ7โค2๐คฃ1
โผ๏ธ๐ฌ๐ท Greece is moving toward a total ban on anonymous accounts on social media. Every post, every reply, tied to a verified legal identity.
Greece's Digital Governance Minister Dimitris Papastergiou confirmed today that the plan is meant to fight "toxicity," "hoaxes," and "character assassinations."
Mister Papastergiou says modern "digital democracy" should be "inspired" by Ancient Greece, where citizens openly expressed their views.
He apparently forgot the parts of Ancient Greece involving secret ballots, ostracism shards, and pseudonymous political pamphlets. The Athenian Assembly invented anonymous voting precisely because public attribution is dangerous.
Source: https://www.euractiv.com/news/greece-to-ban-anonymity-on-social-media/
Greece's Digital Governance Minister Dimitris Papastergiou confirmed today that the plan is meant to fight "toxicity," "hoaxes," and "character assassinations."
Mister Papastergiou says modern "digital democracy" should be "inspired" by Ancient Greece, where citizens openly expressed their views.
He apparently forgot the parts of Ancient Greece involving secret ballots, ostracism shards, and pseudonymous political pamphlets. The Athenian Assembly invented anonymous voting precisely because public attribution is dangerous.
Source: https://www.euractiv.com/news/greece-to-ban-anonymity-on-social-media/
๐ญ13๐ฉ9๐3๐คฃ3๐จ3โค2๐คฌ1
โ๏ธ๐บ๐ธ๐ฎ๐ฑ Intuit, the US tech giant behind TurboTax, lets employees wear IDF uniforms to work and take months off to fight Israel's wars.
Last month, Intuit data analyst Tom Yacobi joined an all-hands Zoom call in his full IDF uniform.
Roughly 100 million Americans use TurboTax.
Source: https://www.donotpanic.news/p/exclusive-the-us-tech-giant-where
Last month, Intuit data analyst Tom Yacobi joined an all-hands Zoom call in his full IDF uniform.
Roughly 100 million Americans use TurboTax.
Source: https://www.donotpanic.news/p/exclusive-the-us-tech-giant-where
๐จ20โค9๐คฌ6๐ฉ4๐ญ4๐ฅ3๐1๐1๐ฏ1
๐จ๐ช๐บ BREAKING: The European Commission just told all 27 member states to hurry up with rolling out online age verification, demanding deployment before the end of 2026.
Asked today how the system stops anyone bypassing it with a VPN from outside the EU, Vice-President Virkkunen said only that it is "an important part of the next steps."
Asked today how the system stops anyone bypassing it with a VPN from outside the EU, Vice-President Virkkunen said only that it is "an important part of the next steps."
๐คฌ13๐ฉ9โค1
โ๏ธ๐ฉ๐ช Germany says Signal is unsuitable for official communications. Members of the Bundestag have been formally urged to switch from Signal to Wire, after a Russian intelligence operation compromised the Signal account of Bundestag President Julia Klรถckner.
The choice of Wire is also strategic.
Wire is a German company, headquartered in Berlin, operating under EU jurisdiction. The German federal cybersecurity agency BSI has approved Wire Bund for the exchange of classified information up to VS-NfD ("Restricted, For Official Use Only"). The platform is GDPR-compliant, NIS2-aligned, and self-hostable on European infrastructure.
Signal, by contrast, is a US-based non-profit subject to the US CLOUD Act. The CLOUD Act allows American authorities to compel data access from US-headquartered providers regardless of where the data is physically stored. For a European parliament communicating about defence, foreign policy, or intelligence cooperation, that is a structural problem before you even reach the phishing question.
Two operational reasons Wire is harder to phish:
๐ด Registration uses an email address, not a phone number
๐ด The email address is not visible to third parties
Signal binds accounts to phone numbers. Anyone who knows your number can attempt to contact you, and enterprise controls like Single Sign-On are difficult to apply.
The push is not new. Bundestag Vice-President Andrea Lindholz previously called for the same migration and proposed an outright ban on Signal for official parliamentary devices.
Important context. This is not a vulnerability in Signal's encryption protocol. The Signal protocol remains the gold standard for end-to-end encryption. The attacks succeed at the human and account-recovery layer, the layer Signal's phone-number-based identity model exposes by design.
The Bundestag move fits a much larger European pattern. Brussels is pushing GAIA-X for sovereign cloud, the EUDI Wallet for digital identity, and now Wire for parliamentary communications. The throughline is the same: reduce dependence on US-headquartered infrastructure, especially for anything touching classified or politically sensitive data.
Germany is now the highest-profile government to formally treat Signal as unsuitable for official communications. The replacement is European. Other EU members will be watching as Germany takes the lead.
The choice of Wire is also strategic.
Wire is a German company, headquartered in Berlin, operating under EU jurisdiction. The German federal cybersecurity agency BSI has approved Wire Bund for the exchange of classified information up to VS-NfD ("Restricted, For Official Use Only"). The platform is GDPR-compliant, NIS2-aligned, and self-hostable on European infrastructure.
Signal, by contrast, is a US-based non-profit subject to the US CLOUD Act. The CLOUD Act allows American authorities to compel data access from US-headquartered providers regardless of where the data is physically stored. For a European parliament communicating about defence, foreign policy, or intelligence cooperation, that is a structural problem before you even reach the phishing question.
Two operational reasons Wire is harder to phish:
๐ด Registration uses an email address, not a phone number
๐ด The email address is not visible to third parties
Signal binds accounts to phone numbers. Anyone who knows your number can attempt to contact you, and enterprise controls like Single Sign-On are difficult to apply.
The push is not new. Bundestag Vice-President Andrea Lindholz previously called for the same migration and proposed an outright ban on Signal for official parliamentary devices.
Important context. This is not a vulnerability in Signal's encryption protocol. The Signal protocol remains the gold standard for end-to-end encryption. The attacks succeed at the human and account-recovery layer, the layer Signal's phone-number-based identity model exposes by design.
The Bundestag move fits a much larger European pattern. Brussels is pushing GAIA-X for sovereign cloud, the EUDI Wallet for digital identity, and now Wire for parliamentary communications. The throughline is the same: reduce dependence on US-headquartered infrastructure, especially for anything touching classified or politically sensitive data.
Germany is now the highest-profile government to formally treat Signal as unsuitable for official communications. The replacement is European. Other EU members will be watching as Germany takes the lead.
๐8โค3๐ฅ1
โผ๏ธ๐จ BREAKING: An AI found a Linux kernel zero-day that roots every distribution since 2017. The exploit fits in 732 bytes of Python. Patch your kernel ASAP.
The vulnerability is CVE-2026-31431, nicknamed "Copy Fail," disclosed today by Theori. It has been sitting quietly in the Linux kernel for nine years.
Most Linux privilege-escalation bugs are picky. They need a precise timing window (a "race"), or specific kernel addresses leaked from somewhere, or careful tuning per distribution. Copy Fail needs none of that. It is a straight-line logic mistake that works on the first try, every time, on every mainstream Linux box.
The attacker just needs a normal user account on the machine. From there, the script asks the kernel to do some encryption work, abuses how that work is wired up, and ends up writing 4 bytes into a memory area called the "page cache" (Linux's high-speed copy of files in RAM). Those 4 bytes can be aimed at any program the system trusts, like /usr/bin/su, the shortcut to becoming root.
Result: the next time anyone runs that program, it lets the attacker in as root.
What should worry most: the corruption never touches the file on disk. It only exists in Linux's in-memory copy of that file. If you imaged the hard drive afterwards, the on-disk file would match the official package hash exactly. Reboot the machine, or just put it under memory pressure (any normal system load that needs the RAM), and the cached copy reloads fresh from disk.
Containers do not help either. The page cache is shared across the whole host, so a process inside a container can use this bug to compromise the underlying server and reach into other tenants.
The original sin was a 2017 "in-place optimization" in a kernel crypto module called algif_aead. It was meant to make encryption slightly faster. The change broke a critical safety assumption, and nobody noticed for nine years. That bug then rode every kernel update from 2017 to today.
This vulnerability affects the following:
๐ด Shared servers (dev boxes, jump hosts, build servers): any user becomes root
๐ด Kubernetes and container clusters: one compromised pod escapes to the host
๐ด CI runners (GitHub Actions, GitLab, Jenkins): a malicious pull request becomes root on the runner
๐ด Cloud platforms running user code (notebooks, agent sandboxes, serverless functions): a tenant becomes host root
Timeline:
๐ด March 23, 2026: reported to the Linux kernel security team
๐ด April 1: patch committed to mainline (commit a664bf3d603d)
๐ด April 22: CVE assigned
๐ด April 29: public disclosure
Mitigation: update your kernel to a build that includes mainline commit a664bf3d603d. If you cannot patch immediately, turn off the vulnerable module:
echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf
rmmod algif_aead 2>/dev/null || true
For environments that run untrusted code (containers, sandboxes, CI runners), block access to the kernel's AF_ALG crypto interface entirely, even after patching. Almost nothing legitimate needs it, and blocking it shuts the door on this whole class of bug...
Write-up and PoC: https://copy.fail/
The vulnerability is CVE-2026-31431, nicknamed "Copy Fail," disclosed today by Theori. It has been sitting quietly in the Linux kernel for nine years.
Most Linux privilege-escalation bugs are picky. They need a precise timing window (a "race"), or specific kernel addresses leaked from somewhere, or careful tuning per distribution. Copy Fail needs none of that. It is a straight-line logic mistake that works on the first try, every time, on every mainstream Linux box.
The attacker just needs a normal user account on the machine. From there, the script asks the kernel to do some encryption work, abuses how that work is wired up, and ends up writing 4 bytes into a memory area called the "page cache" (Linux's high-speed copy of files in RAM). Those 4 bytes can be aimed at any program the system trusts, like /usr/bin/su, the shortcut to becoming root.
Result: the next time anyone runs that program, it lets the attacker in as root.
What should worry most: the corruption never touches the file on disk. It only exists in Linux's in-memory copy of that file. If you imaged the hard drive afterwards, the on-disk file would match the official package hash exactly. Reboot the machine, or just put it under memory pressure (any normal system load that needs the RAM), and the cached copy reloads fresh from disk.
Containers do not help either. The page cache is shared across the whole host, so a process inside a container can use this bug to compromise the underlying server and reach into other tenants.
The original sin was a 2017 "in-place optimization" in a kernel crypto module called algif_aead. It was meant to make encryption slightly faster. The change broke a critical safety assumption, and nobody noticed for nine years. That bug then rode every kernel update from 2017 to today.
This vulnerability affects the following:
๐ด Shared servers (dev boxes, jump hosts, build servers): any user becomes root
๐ด Kubernetes and container clusters: one compromised pod escapes to the host
๐ด CI runners (GitHub Actions, GitLab, Jenkins): a malicious pull request becomes root on the runner
๐ด Cloud platforms running user code (notebooks, agent sandboxes, serverless functions): a tenant becomes host root
Timeline:
๐ด March 23, 2026: reported to the Linux kernel security team
๐ด April 1: patch committed to mainline (commit a664bf3d603d)
๐ด April 22: CVE assigned
๐ด April 29: public disclosure
Mitigation: update your kernel to a build that includes mainline commit a664bf3d603d. If you cannot patch immediately, turn off the vulnerable module:
echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf
rmmod algif_aead 2>/dev/null || true
For environments that run untrusted code (containers, sandboxes, CI runners), block access to the kernel's AF_ALG crypto interface entirely, even after patching. Almost nothing legitimate needs it, and blocking it shuts the door on this whole class of bug...
Write-up and PoC: https://copy.fail/
โค12๐ญ6๐ฅ1
๐จ BREAKING: cPanel and WHM, the control panels behind an estimated 70+ million websites, have a critical security flaw that lets anyone become root admin without a password. CVE-2026-41940 affects every supported version. Itโs already being exploited in the wild.
watchTowr Labs published the full attack today, after the hosting company KnownHost confirmed the bug was already being used to break into a significant chunk of the internet.
If you've never heard of cPanel: it's the dashboard that hosting providers and millions of website owners use to manage their servers, domains, email accounts, databases, and SSL certificates. WHM is the admin version that controls the entire server. If someone gets root access to WHM, they get the keys to the kingdom and to every apartment inside it.
How the attack works, in plain English:
๐ด Step 1: The attacker sends a deliberately wrong login. cPanel still creates a temporary "you tried to log in" record on disk and gives the attacker a cookie tied to it.
๐ด Step 2: The attacker tweaks the cookie to disable cPanel's password encryption. Normally cPanel encrypts the password field on disk. With one small change to the cookie, cPanel just stores it as plain text instead.
๐ด Step 3: The attacker sends a fake login attempt where the password field secretly contains hidden line breaks. cPanel does not strip these line breaks out, so they get written straight to the session file. Each line break creates a brand new fake record. The attacker uses this to inject lines that say "this user is root" and "this user already authenticated successfully."
๐ด Step 4: The attacker visits one more random page on the site to nudge cPanel into re-reading the file. cPanel then promotes the injected fake lines into its main session memory.
๐ด Step 5: On the next request, cPanel sees a flag that says "this user already passed the password check." cPanel trusts that flag, skips checking the actual password, and lets the attacker in as root.
From start to finish, the attack takes a handful of HTTP requests.
If you run cPanel or WHM, the patched versions are:
๐ด cPanel/WHM 110.0.x โ 11.110.0.97
๐ด cPanel/WHM 118.0.x โ 11.118.0.63
๐ด cPanel/WHM 126.0.x โ 11.126.0.54
๐ด cPanel/WHM 132.0.x โ 11.132.0.29
๐ด cPanel/WHM 134.0.x โ 11.134.0.20
๐ด cPanel/WHM 136.0.x โ 11.136.0.5
If your version is older than these, assume someone has already broken in and act accordingly. Patch right now, then rotate every password and key the server touched: root passwords, API tokens, SSL private keys, SSH keys, mail passwords, and database passwords.
watchTowr has released a free tool on GitHub to help check if a server is vulnerable.
Detection tool: https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
Full write-up: https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
watchTowr Labs published the full attack today, after the hosting company KnownHost confirmed the bug was already being used to break into a significant chunk of the internet.
If you've never heard of cPanel: it's the dashboard that hosting providers and millions of website owners use to manage their servers, domains, email accounts, databases, and SSL certificates. WHM is the admin version that controls the entire server. If someone gets root access to WHM, they get the keys to the kingdom and to every apartment inside it.
How the attack works, in plain English:
๐ด Step 1: The attacker sends a deliberately wrong login. cPanel still creates a temporary "you tried to log in" record on disk and gives the attacker a cookie tied to it.
๐ด Step 2: The attacker tweaks the cookie to disable cPanel's password encryption. Normally cPanel encrypts the password field on disk. With one small change to the cookie, cPanel just stores it as plain text instead.
๐ด Step 3: The attacker sends a fake login attempt where the password field secretly contains hidden line breaks. cPanel does not strip these line breaks out, so they get written straight to the session file. Each line break creates a brand new fake record. The attacker uses this to inject lines that say "this user is root" and "this user already authenticated successfully."
๐ด Step 4: The attacker visits one more random page on the site to nudge cPanel into re-reading the file. cPanel then promotes the injected fake lines into its main session memory.
๐ด Step 5: On the next request, cPanel sees a flag that says "this user already passed the password check." cPanel trusts that flag, skips checking the actual password, and lets the attacker in as root.
From start to finish, the attack takes a handful of HTTP requests.
If you run cPanel or WHM, the patched versions are:
๐ด cPanel/WHM 110.0.x โ 11.110.0.97
๐ด cPanel/WHM 118.0.x โ 11.118.0.63
๐ด cPanel/WHM 126.0.x โ 11.126.0.54
๐ด cPanel/WHM 132.0.x โ 11.132.0.29
๐ด cPanel/WHM 134.0.x โ 11.134.0.20
๐ด cPanel/WHM 136.0.x โ 11.136.0.5
If your version is older than these, assume someone has already broken in and act accordingly. Patch right now, then rotate every password and key the server touched: root passwords, API tokens, SSL private keys, SSH keys, mail passwords, and database passwords.
watchTowr has released a free tool on GitHub to help check if a server is vulnerable.
Detection tool: https://github.com/watchtowrlabs/watchTowr-vs-cPanel-WHM-AuthBypass-to-RCE.py
Full write-up: https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
๐คฏ9โค3๐ฅ2๐2๐คฃ2๐คช1
โ๏ธ Apple accidentally shipped Claude[.]md files in the Apple Support app update (v5.13).
For context, Claude[.]md is the instruction file Anthropic's Claude Code uses to understand a project's structure, conventions, and developer guidance. They typically live in source repos and are not meant to ship inside production apps.
Source: aaronp613
For context, Claude[.]md is the instruction file Anthropic's Claude Code uses to understand a project's structure, conventions, and developer guidance. They typically live in source repos and are not meant to ship inside production apps.
Source: aaronp613
๐ญ11๐5๐1๐ฅ1๐1๐ฏ1๐คช1
๐จ Two US cybersecurity professionals have been sentenced for moonlighting as ALPHV BlackCat ransomware affiliates.
Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, deployed BlackCat ransomware against multiple US victims between April and December 2023. They paid the operators a 20% cut for access to the platform, hit medical and engineering firms, leaked patient data to pressure payment, and split a $1.2 million Bitcoin ransom three ways with co-conspirator Angelo Martino.
Martino had a second job. He worked as a ransomware negotiator for victims, and used that role to leak confidential victim information to the attackers to push ransom prices up.
When Goldberg tried to flee abroad, the FBI tracked him through 10 countries before he was caught.
Both men were sentenced yesterday. Martino is sentenced July 9.
Ryan Goldberg, 40, of Georgia, and Kevin Martin, 36, of Texas, deployed BlackCat ransomware against multiple US victims between April and December 2023. They paid the operators a 20% cut for access to the platform, hit medical and engineering firms, leaked patient data to pressure payment, and split a $1.2 million Bitcoin ransom three ways with co-conspirator Angelo Martino.
Martino had a second job. He worked as a ransomware negotiator for victims, and used that role to leak confidential victim information to the attackers to push ransom prices up.
When Goldberg tried to flee abroad, the FBI tracked him through 10 countries before he was caught.
Both men were sentenced yesterday. Martino is sentenced July 9.
๐ฅ8โค4๐4๐ฅฐ2