CVE-2026-63220
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as s...
Read full story at vulners.comMore Tech news

Apple’s new Upgrade program makes getting a Mac easier, but it may not save you money
Image via Apple Apple has expanded its upgrade program beyond the iPhone, giving customers a new way to get Macs, iPads, Apple Watches, and iPhones without paying the full price upfront. The catch

US' first sixth-gen fighter jet could fly with less powerful engine
Regardless of the engine used initially, the F-47 is expected to be significantly more capable than previous generations of fighters in terms of survivability, networking, sensor fusion, and long-range operations.
RevAPK: Reverse engineer Android apps
submitted by /u/cronocr [link] [comments]
CVE-2026-56672 ComfyUI: Stored XSS via /userdata/{file} due to Missing Content-Type Sanitization
ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/file served user-controlled HTML and SVG files with extension-derived content types, allowing stored cross-site scripting in the ComfyUI origin and access to browser-stored API tokens, settings, workflows, ...