Click any tag below to further narrow down your results
Links
IBM, Red Hat and Palo Alto Networks are integrating Palo Alto’s network-based virtual patching in Prisma with IBM/Red Hat’s Project Lightwell to spot and shield against open-source software flaws. The joint effort uses shared vulnerability intelligence and AI-driven processes to deliver preemptive, same-day network protections while patches are developed.
Four high-severity flaws in the open-source Dify platform allow authenticated users to read private chats, preview documents, and leak files across tenants by abusing tracing endpoints, plugin daemon APIs, and flawed file permissions. One issue also stems from a vulnerable PDFium version (CVE-2024-5846). Dify 1.14.2 patches these bugs; operators should update immediately and apply WAF rules for CVE-2026-41948.