#KeyID
CVE-2026-52769: YesWiki 4.6.2–4.6.6 SSRF via HTTP Signature keyId in public API. Unauthenticated attacker forces server-side GET to arbitrary URLs. CVSS 8.3. Unpatched—update to 4.6.6 or restrict access now. Details: https://www.valtersit.com/cve/CVE-2026-52769/ #CVE #YesWiki #in
September 8, 2026 at 7:40 AM
I mostly post on Mastodon these days:

infosec.exchange/@bontchev

Although, when I update my blog, I post about it on Twitter, BlueSky, LinkedIn, and Facebook too.
VessOnSecurity (@bontchev@infosec.exchange)
10.1K Posts, 51 Following, 1.54K Followers · Anti-virus, malware and infosec expert, crypto amateur, privacy advocate and general annoyance. PGP keyID: 0x365697c632dd98d9
infosec.exchange
August 26, 2026 at 2:12 PM
Jianjie Luo, Yiming Zhong, Haoming Shen, Yupeng Xiao, Zhenguo Yang
KeyID: Decoupled Drafting and Keyframe Editing for Identity-Preserving Video Generation
https://arxiv.org/abs/2608.16154
August 18, 2026 at 7:06 PM
Jianjie Luo, Yiming Zhong, Haoming Shen, Yupeng Xiao, Zhenguo Yang: KeyID: Decoupled Drafting and Keyframe Editing for Identity-Preserving Video Generation https://arxiv.org/abs/2608.16154 https://arxiv.org/pdf/2608.16154 https://arxiv.org/html/2608.16154
August 18, 2026 at 6:42 AM
CVE-2026-18859 - ESAFENET CDG usbkey;logindojojs sql injection
CVE ID : CVE-2026-18859

Published : Aug. 5, 2026, 1:16 a.m. | 1 hour ago

Description : A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/uk...
CVE-2026-18859 - ESAFENET CDG usbkey;logindojojs sql injection
A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such manipulation of the argument keyid leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early …
cvefeed.io
August 5, 2026 at 2:24 AM
✅ qtz pseudo-language (KeyID) should be buildable in release mode too
🔗 https://bugs.documentfoundation.org/show_bug.cgi?id=72476
July 1, 2026 at 10:28 AM
🚨 EUVD-2026-25790
📊 n/a
🏢 Apache Software Foundation

📝 The Camel-PQC FileBasedKeyLifecycleManager class deserializes the contents of `<keyId>.key` files in the configured key directory using ja...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25790

#cybersecurity #infosec #cve #euvd
April 27, 2026 at 10:01 AM
@hongminhee oh, I'm so happy. I've seen too many implementations that assume the key id is a fragment, and just load that as the actor.

And I saw one that loaded the actor of the received activity and verified the signature against the actor's key, ignoring the keyID entirely!

I knew you would […]
Original post on cosocial.ca
cosocial.ca
March 24, 2026 at 2:39 AM
@evan Yes, that's exactly how it works. When Fedify verifies a draft-cavage signature on an incoming request, it:

1. Extracts the `keyId` from the `Signature` header.
2. Fetches the document at that `keyId` URL, expecting a key object (or an actor with a matching public key embedded).
3 […]
Original post on hollo.social
hollo.social
March 24, 2026 at 2:12 AM
@hongminhee tell me that when Fedify is validating an HTTP Signature you load the key identified by the `keyID`, get its `owner`, and then load the owner ActivityPub object. 🙏🏼
March 24, 2026 at 1:47 AM
CVE-2026-32310 - Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths
CVE ID : CVE-2026-32310

Published : March 20, 2026, 7:16 p.m. | 27 minutes ago

Description : Cryptomator encrypts data being stored on cloud infrastructure. From versio...
CVE-2026-32310 - Cryptomator: Unverified masterkeyfile key IDs can access arbitrary local or UNC paths
Cryptomator encrypts data being stored on cloud infrastructure. From version 1.6.0 to before version 1.19.1, vault configuration is parsed before its integrity is verified, and the masterkeyfile loader uses the unverified keyId as a filesystem path. The loader resolves keyId.getSchemeSpecificPart() directly against the vault path and immediately calls Files.exists(...). This …
cvefeed.io
March 20, 2026 at 10:09 PM
[JP] 1,000垢まで無料!?AIエージェント専用のメール・電話インフラ『KeyID』が革命的だサメ!
[EN] Free Up to 1,000 Accounts?! The Revolutionary Email and Phone Infrastructure for AI Agents,

https://ai-minor.com/blog/en/2026-03-15-1773521273315-show_hn__keyid___free_email_and_phone_infrastructu

#AIエージェント #MCP #KeyID #自動化 #Tech
Free Up to 1,000 Accounts?! The Revolutionary Email and Phone Infrastructure for AI Agents,
Free Up to 1,000 Accounts?! The Revolutionary Email and Phone Infrastructure for AI Agents,
ai-minor.com
March 14, 2026 at 10:45 PM
Show HN: KeyID – Free email and phone infrastructure for AI agents (MCP)

https://keyid.ai/
March 14, 2026 at 7:30 PM
Show HN: KeyID – Free email and phone infrastructure for AI agents (MCP)
L: https://keyid.ai/
C: https://news.ycombinator.com/item?id=47378241
posted on 2026.03.14 at 12:23:20 (c=3, p=5)
March 14, 2026 at 7:20 PM
Or where the keyId & serviceId match?
February 6, 2026 at 1:51 AM
✅ Bug 164488 closed at 2025-11-13 07:38 UTC
⚡ Enhancement request: Add possibility of KeyID language pack, also for non-development-versions
🔗 https://bugs.documentfoundation.org/show_bug.cgi?id=164488
November 13, 2025 at 7:55 AM