Intelligence Feed

Dispatches from the lab

The Sherlock Forensics Intelligence Feed provides expert analysis of AI code security, vibe coding vulnerabilities, CVE advisories and digital forensics methodologies from certified examiners with over 20 years of field experience in Vancouver, BC.

Featured Analysis

AI Security

Can AI Be Hacked?

A forensic examination of AI attack surfaces. Model extraction, data poisoning, adversarial inputs and the security gaps most teams overlook.

CVE Intelligence

Latest CVE Alerts

High and critical vulnerabilities relevant to cloud, web and AI infrastructure. Updated daily from the National Vulnerability Database.

CVE Severity CVSS Affected Product Vulnerability
CVE-2026-23696 CRITICAL 9.9 Windmill CE/EE SQL injection in folder ownership management
CVE-2021-4473 CRITICAL 9.8 Tianxin Management System Command injection in Reporter component
CVE-2026-22679 CRITICAL 9.8 Weaver E-cology 10.0 Unauthenticated RCE via debug endpoint
CVE-2026-3296 CRITICAL 9.8 Everest Forms (WordPress) PHP Object Injection via deserialization
CVE-2026-4631 CRITICAL 9.8 Cockpit (Linux) SSH command injection via login endpoint
CVE-2026-1346 CRITICAL 9.3 IBM Verify Identity Access Privilege escalation for local users
CVE-2026-22683 HIGH 8.8 Windmill Missing authorization bypasses operator restrictions
CVE-2026-3357 HIGH 8.8 IBM Langflow Desktop Insecure FAISS deserialization enables code execution
CVE-2026-1342 HIGH 8.5 IBM Verify Identity Access Local users can execute malicious scripts
CVE-2026-4788 HIGH 8.4 IBM Tivoli Netcool Impact Sensitive data exposure in log files
CVE-2026-4740 HIGH 8.2 Red Hat ACM / Open Cluster Mgmt Certificate forgery via improper validation
CVE-2026-5736 HIGH 7.3 PowerJob detailPlus endpoint manipulation
CVE-2026-5739 HIGH 7.3 PowerJob Code injection via OpenAPI workflow endpoint
CVE-2026-5741 HIGH 7.3 docker-mcp-server OS command injection via HTTP interface
CVE-2026-1343 HIGH 7.2 IBM Verify Identity Access SSRF exposes internal auth endpoints
CVE-2026-22682 HIGH 7.1 OpenHarness Improper access control exposes local files
View Weekly CVE Roundup