ZDI-26-129: Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability

ZDI-26-129: Socomec DIRIS A-40 HTTP API Authentication Bypass Vulnerability

• CVE ID | CVE-2026-2491 | CVSS SCORE | 6 • 3, AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L | AFFECTED VENDORS | Socomec | AFFECTED PRODUCTS | DIRIS A-40 | VULNERABILITY DETAILS | This vuln

Threat Intelligence · February 25, 2026 (updated February 25, 2026) · 1 min · 198 words
Safely inject credentials in HTTP headers with Vercel Sandbox

Safely inject credentials in HTTP headers with Vercel Sandbox

• 2 min read Vercel Sandbox can now automatically inject HTTP headers into outbound requests from sandboxed code. • This keeps API keys and tokens safely outside the sandbox VM bou

Web Development · February 24, 2026 (updated February 25, 2026) · 2 min · 363 words
MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP

• MuddyWater Targets MENA Organizations with GhostFetch, CHAR, and HTTP_VIP The Iranian hacking group known asMuddyWater(aka Earth Vetala, Mango Sandstorm, and MUDDYCOAST) has targ

Cybersecurity · February 23, 2026 (updated February 25, 2026) · 3 min · 443 words
HTTP Archive 2025 Web Almanac

HTTP Archive 2025 Web Almanac

• I love me some good web research reports. • I’m a sucker for them. • HTTP Archive’s Web Almanac is one report I look forward to every year, and I know I’m not alone there. • It’s

Web Development · January 16, 2026 (updated February 24, 2026) · 2 min · 218 words