Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows

Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443…

European Password Manager Passwork Shares Codebase and Updates With FSTEC-Certified Russian Firm

Passwork Europe, a Spain-based password manager used by European public sector bodies, universities, and private organizations, is facing scrutiny after an investigation led by OCCRP uncovered technical and historical connections to a Russian counterpart certified by Russian state agencies. The…