XPR Network patched a smart contract vulnerability in proton.swaps that allowed negative withdrawals. Recovery efforts recovered approximately 1.856 billion XPR tokens (87% of stolen assets) and 100% of stablecoins, with 20 block producers coordinating the multisig recovery and broader infrastructure improvements underway.
Cisco email security appliances can be remotely rooted through a malicious email, representing a critical vulnerability in widely deployed on-premise security infrastructure. The flaw allows attackers to gain complete control of the devices, potentially compromising email security for affected organizations.
Security firm Strix discovered a GitHub personal access token with admin rights to Baseten's production repositories by accessing a publicly exposed Harbor container registry, finding the credential in Docker image build history from March 2023 that remained valid in July 2026. Baseten's security team quickly confirmed and resolved the critical issue within hours.