CWE-347 - Improper Verification of Cryptographic Signature is a cwe tracked across 4 threat clusters and 5 intelligence report mentions on ThreatCluster. First observed May 29, 2026; most recent activity July 5, 2026.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has identified a critical authentication bypass vulnerability in SimpleHelp, tracked as CVE-2026-48558, which is actively being exploited. This flaw…
Fortinet reported two vulnerabilities affecting FortiOS, FortiManager, FortiAnalyzer, and FortiProxy related to FortiCloud SSO authentication. The first vulnerability, an Authentication Bypass (CWE-288), allows…
CVE-2026-58426, published on July 3, 2026, reveals a critical vulnerability in Gitea Actions Artifacts V4. This flaw allows attackers to exploit HMAC ambiguities in signed URLs, enabling unauthorized cross-repository…
Recent analyses of vibe-coded applications reveal common security vulnerabilities due to the nature of AI coding agents. Tenzai's research identified 69 vulnerabilities across five popular coding agents, focusing on…