Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 60+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
High
CVE-2026-18953: Pathname Limitation Vulnerability in AWS Transform MCP Server Leading to LPE
CVE-2026-18953 · github.com · 2026-08-06
AWS Transform MCP Server <0.1.5
Read more
Premium intel
High
CVE-2026-18830: Amazon Bedrock AgentCore Input Validation Bypass
CVE-2026-18830 · aws.amazon.com · 2026-08-05
Amazon Bedrock AgentCore harness InvokeHarness API versions before 2026-07-31
Read more
Unknown
CVE-2026-18655: AWS Amazon MQ MCP Server Credential Disclosure via Prompt Injection
CVE-2026-18655 · aws.amazon.com · 2026-08-04
aws-labs.amazon-mq-mcp-server <= 2.0.23
Read more
Premium intel
High
AWS Ops Wheel Stored XSS via Participant URL Leads to Account Takeover (CVE-2024-1441)
CVE-2024-1441 · github.com · 2026-08-01
AWS Ops Wheel versions prior to 168
Read more
High
Strands Agents Tools http_request Unauthorized Access Vulnerability CVE-2026-18394 Advisory
CVE-2026-18394 · aws.amazon.com · 2026-08-01
strands-agents-tools < 0.8.2
Read more
Medium
Strands Agents Tools http_request Proxy Injection Vulnerability Advisory
GHSA-qh6w-2h72-m84v · github.com · 2026-08-01
strands-agents/tools < 0.8.2
Read more
Premium intel
Critical
CVE-2026-18481: Stored XSS in AWS Ops Wheel Participant URL Field Leads to Account Takeover
CVE-2026-18481 · aws.amazon.com · 2026-08-01
AWS Ops Wheel v2 (versions prior to or including PR #168)
Read more
High
AWS aws-smithy-json CVE-2026-18140 Uncontrolled Recursion DoS Vulnerability
CVE-2026-18140 · aws.amazon.com · 2026-07-31
aws-smithy-json <= 0.62.6
Read more
High
CVE-2025-18140: Uncontrolled recursion in aws-smithy-json allows remote DoS
CVE-2025-18140 · github.com · 2026-07-31
aws-smithy-json <= 0.62.6
Read more
Premium intel
Critical
CVE-2025-4318: Code Injection in @aws-amplify/codegen-ui-react (CWE-94)
CVE-2025-4318 · github.com · 2026-07-31
@aws-amplify/codegen-ui-react < 2.20.6
Read more
Premium intel
Premium intel
High
AWS Bedrock AgentCore RCE via install_packages() (CVE-2026-16796)
CVE-2026-16796 · github.com · 2026-07-24
AWS Bedrock AgentCore Python SDK <1.18.1
Read more
Premium intel
High
Unauthenticated DoS via Slowloris in aws-smithy-http-server due to missing connection limits
GHSA-jxpx-qmx7-gjgx · github.com · 2026-07-24
aws-smithy-http-server <= 0.66.4
Read more
Premium intel
High
CVE-2026-16584: AWS API MCP Server Security Policy Bypass via Startup Failure
CVE-2026-16584 · aws.amazon.com · 2026-07-24
AWS API MCP Server >= 0.2.15 AND < 1.3.47
Read more
High
s2n-tls CVE-2026-16317/16318: TLS 1.3 Silent Discard and QUIC Memory Leak
CVE-2026-16317 · aws.amazon.com · 2026-07-22
s2n-tls
Read more
Medium
s2n-tls CVE-2026-15317: Silent Drop of TLS 1.3 Encrypted Records Vulnerability
CVE-2026-15317 · github.com · 2026-07-22
s2n-tls <v1.7.5
Read more
Critical
smithy-rs/Rust SDK Deserializer Uncontrolled Recursion DoS (CVE-2026-15967)
CVE-2026-15967 · github.com · 2026-07-22
smithy-rs < release-2026-06-02 · aws-sdk-rust crates < release-2026-06-02
Read more
Unknown
Path Traversal and Arbitrary File Write in AWS HealthOmics MCP Server <0.36
github.com · 2026-07-18
aws-healthomics-mcp-server <0.36
Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.