⤷ Title: Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 14 May 2025 00:46:33 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #Cloud Security #CVE_2025_22248 #CVSS 9.4 #database security #Helm chart #Kubernetes #Pgpool #PostgreSQL #unauthenticated access
Daily CyberSecurity
Critical Misconfiguration in Bitnami Pgpool Enables Unauthenticated PostgreSQL Access (CVE-2025-22248)
Bitnami Pgpool flaw (CVE-2025-22248) exposes PostgreSQL to unauthenticated access. Update to Pgpool 4.6.0-1 or Helm chart 16.0.0 to fix.
⤷ Title: Bitnami Helm Chart Flaw (CVSS 10.0) Exposes Kubernetes Secrets: Publicly Accessible & Exploitable Remotely
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 09:45:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #cloud_native #cybersecurity #Helm Charts #Kubernetes #Secrets Exposure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 24 Jul 2025 09:45:30 +0000
════════════════════════
⌗ Tags: #Vulnerability #Bitnami #cloud_native #cybersecurity #Helm Charts #Kubernetes #Secrets Exposure
Daily CyberSecurity
Bitnami Helm Chart Flaw (CVSS 10.0) Exposes Kubernetes Secrets: Publicly Accessible & Exploitable Remotely
A critical flaw (CVE-2025-41240, CVSS 10.0) in Bitnami Helm charts exposes Kubernetes secrets via publicly accessible paths, allowing unauthenticated remote access. Update immediately!
⤷ Title: Kubernetes Alert: Headlamp Flaw (CVE-2025-14269) Lets Unauthenticated Users Hijack Helm Clusters
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:50:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cluster Management #Credential Caching #CVE_2025_14269 #DevSecOps #Headlamp #Helm #K8s Security #Kubernetes #Patch Update #Vulnerability
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 19 Dec 2025 00:50:55 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Cluster Management #Credential Caching #CVE_2025_14269 #DevSecOps #Headlamp #Helm #K8s Security #Kubernetes #Patch Update #Vulnerability
Daily CyberSecurity
Kubernetes Alert: Headlamp Flaw (CVE-2025-14269) Lets Unauthenticated Users Hijack Helm Clusters
A Headlamp flaw allows unauthenticated users to reuse cached credentials to hijack Kubernetes Helm operations. Update to v0.39.0!
⤷ Title: The End of Insecure Pulls: Docker Open Sources Its Hardened Images Catalog
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 03:16:19 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Apache 2.0 #Container Security #DevOps #DHI #Docker #Helm #Kubernetes #open source #SBOM #SLSA #Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 29 Dec 2025 03:16:19 +0000
════════════════════════
⌗ Tags: #Technology #AI Infrastructure #Apache 2.0 #Container Security #DevOps #DHI #Docker #Helm #Kubernetes #open source #SBOM #SLSA #Supply Chain
Penetration Testing Tools
The End of Insecure Pulls: Docker Open Sources Its Hardened Images Catalog
Docker has announced that its Docker Hardened Images (DHI) are now free and fully open: they can be
⤷ Title: Humble Image Security Tracking with Syft & Grype under the hood
════════════════════════
𐀪 Author: Sergei Ovchinnikov
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 20:55:09 GMT
════════════════════════
⌗ Tags: #application_security #automation #helm #security #image_scanning
════════════════════════
𐀪 Author: Sergei Ovchinnikov
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 20:55:09 GMT
════════════════════════
⌗ Tags: #application_security #automation #helm #security #image_scanning
Medium
Humble Image Security Tracking with Syft & Grype under the hood
Hello everybody! In this article, we want to show a small tool that Ilya(@typecookie) and I built to monitor vulnerabilities in Docker…
⤷ Title: Humble Image Security Tracking with Syft & Grype under the hood
════════════════════════
𐀪 Author: Sergei Ovchinnikov
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 20:55:09 GMT
════════════════════════
⌗ Tags: #application_security #automation #helm #security #image_scanning
════════════════════════
𐀪 Author: Sergei Ovchinnikov
════════════════════════
ⴵ Time: Tue, 30 Dec 2025 20:55:09 GMT
════════════════════════
⌗ Tags: #application_security #automation #helm #security #image_scanning
Medium
Humble Image Security Tracking with Syft & Grype under the hood
Hello everybody! In this article, we want to show a small tool that Ilya(@typecookie) and I built to monitor vulnerabilities in Docker…
⤷ Title: Critical 9.9 CVSS Rancher Fleet Flaw Grants Full Cluster-Admin Access
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:29:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_41050 #cybersecurity #Fleet #GitOps #Helm Deployer #infosec #Kubernetes Security #Multi_tenancy #Patch Alert #ServiceAccount Impersonation #SUSE Rancher
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 01:29:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_41050 #cybersecurity #Fleet #GitOps #Helm Deployer #infosec #Kubernetes Security #Multi_tenancy #Patch Alert #ServiceAccount Impersonation #SUSE Rancher
Daily CyberSecurity
Critical 9.9 CVSS Rancher Fleet Flaw Grants Full Cluster-Admin Access
Rancher Fleet fixes a 9.9 CVSS flaw (CVE-2026-41050) allowing tenants to bypass ServiceAccount isolation and steal secrets. Upgrade your GitOps engine now!
⤷ Title: CVE-2026-10090: Red Hat ACM Privilege Escalation Flaw Grants Cluster-Admin, Rated CVSS 9.9
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ACM #Cluster Admin #CVE_2026_10090 #Helm #Kubernetes #privilege escalation #red hat
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 10 Aug 2026 13:37:56 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ACM #Cluster Admin #CVE_2026_10090 #Helm #Kubernetes #privilege escalation #red hat
Daily CyberSecurity
CVE-2026-10090: Red Hat ACM Privilege Escalation Flaw Grants Cluster-Admin, Rated CVSS 9.9
TL;DR Red Hat disclosed a critical privilege escalation flaw in Advanced Cluster Management (ACM) for Kubernetes. Tracked as CVE-2026-10090, it scores 9.9 on CVSS. A user with only namespace edit …