MetaMask Is Exiting Ethereum Validators Without Defining the Incident’s Scope

MetaMask reports no immediate wallet threat. Our analysis separates the validator response from the still-unknown infrastructure scope.

MetaMask reports no immediate wallet threat. Our analysis separates the validator response from the still-unknown infrastructure scope.

Australia’s privacy regulator has explained a 10 December disclosure duty for software-assisted decisions that significantly affect people. Human review and third-party tools do not automatically remove a decision from scope.

GitPython 3.1.60 fixes a repository discovery flaw.

Next.js 16.3.8 fixes seven security flaws, but the announced critical fix remains pending. The 15.5.27 release has a narrower list, with one branch-scope conflict.

Star Blizzard’s RedFlick campaigns turn an email reply into a path toward a protected archive. Defenders need to distinguish mail exposure from endpoint execution.

The 11 fixes in wolfSSL 5.9.4 need an application-level exposure check. Long-lived certificate and session state also belongs in the change plan.

TeamViewer fixed five client and host vulnerabilities. The lead flaw could let a remote session bypass permissions the user had explicitly denied.

Cisco says attackers are exploiting a critical SD-WAN Manager flaw that turns one encoded HTTP request into administrator-level API access.

Two LightLLM helper services can accept unsafe network input outside the model API. Check multimodal and profiling nodes, their live ports and their network boundaries.

WatchGuard fixed 15 Fireware vulnerabilities, including a root-command path through a hostile BOVPN over TLS server and adjacent-network code execution.