#uploads


OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

Sep 17, 2026 // 18:52

OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new […]

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Aug 17, 2026 // 23:54

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve […]

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Jul 30, 2026 // 00:59

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted […]

Grok Build Uploads Entire Git Repositories to xAI Storage, Not Just Files It Reads

Jul 14, 2026 // 12:10

xAI’s Grok Build coding CLI was uploading entire Git repositories, full commit history and all, to a Google Cloud Storage bucket run by xAI, not […]

Google Vertex AI SDK Flaw Let Attackers Hijack Model Uploads via Bucket Squatting

Jun 16, 2026 // 22:11

A flaw in the Google Cloud Vertex AI SDK for Python let an attacker with no access to a victim’s project hijack the victim’s machine […]

Magento PolyShell: Unauth. Uploads & RCE Lead to Account Takeover (Security Flaw)

Mar 20, 2026 // 14:43

Sansec is alerting users to a serious security vulnerability in Magento’s REST API. This flaw could allow unauthorized individuals to upload harmful files, potentially leading […]