A critical deserialization bug in Jenkins places controller-side XML handling under scrutiny, with reported live attack attempts raising the stakes for exposed installations.
A deserialization flaw tied to Jenkins config.xml shows how a routine admin file can turn into a high-risk route to code execution inside CI/CD systems.
Public proof-of-concept code for three patched Notepad++ flaws turns a familiar Windows editor into a reminder that local trust boundaries can be just as dangerous as remote ones.
Version 8.9.6.1 closes three vulnerabilities in the Windows editor, including two that can lead to arbitrary code execution, and the case shows why configuration files deserve the same scrutiny as executable code.