Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The…

Car Alarm Devices Vulnerable to Hacking

Millions of vehicles contain hackable aftermarket alarm systems that dealerships installed without owner knowledge or consent, according to new security research. This article has been indexed from CyberMaterial Read the original article: Car Alarm Devices Vulnerable to Hacking

Paidwork breach exposes 23M users

A data breach at Paidwork has exposed personal information belonging to more than 23 million users of the microtask platform. This article has been indexed from CyberMaterial Read the original article: Paidwork breach exposes 23M users