Make a deal with OffSequence
🔒 Paid proposals held safely in escrow — released only when the work's approved.
Known for
1 views
CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. https://radar.offseq.com/threat/cve-2026-63720-improper-control-of-generation-of-code-code-injection-in-koxudaxi-datamodel-code-a0a27f1d30c87e2e #OffSeq #infosec #Python #CVE202663720
1 views
xo-member-components v28.0.0 (npm) flagged as malicious (HIGH severity): connects to a known malicious domain. No patch exists — remove or avoid this version. No active exploits reported. https://radar.offseq.com/threat/malicious-code-in-xo-member-components-npm-19227206998cf01d #OffSeq #npm #SupplyChain #Infosec
1 views
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-request-forgery-ssrf-in-microsoft-microsoft-purview-data-governance-0983080847f54f67 #OffSeq #Vuln #SSRF #Microsoft #CyberSec
📊 Post engagement
🔥 Top post: CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 · 1 likes + reposts
📊 Activity & format
Recent posts
View on Mastodon ↗
🔥 Top post
CVE-2026-63720 (HIGH): koxudaxi datamodel-code-generator <0.70.0 is vulnerable to code injection. Malicious input schemas can trigger remote Python code execution. Avoid untrusted schemas & update when possible. https://radar.offseq.com/threat/cve-2026-63720-improper-control-of-…
'f0-form-manipulator' v28.0.0 (npm) flagged as malicious (HIGH) by OpenSSF. Package communicates with a known bad domain — no CVE or CVSS, no exploits yet. Remove or avoid this version. Monitor advisories for updates. https://radar.offseq.…
xo-member-components v28.0.0 (npm) flagged as malicious (HIGH severity): connects to a known malicious domain. No patch exists — remove or avoid this version. No active exploits reported. https://radar.offseq.com/threat/malicious-code-in-x…
Malicious behavior found in npm 'identityscimapiserv' v28.0.0 🛑 Severity: HIGH. Package communicates with a domain tied to malicious activity. Remove if used; no patch yet. Monitor advisories. No CVE assigned. https://radar.offseq.com/thre…
Malicious npm package alert: 'page-navigation' v1.0.1 (HIGH severity) flagged by OpenSSF for contacting malicious domains. No active exploits, but remove or avoid use. No CVE assigned. Info: https://radar.offseq.com/threat/malicious-code-i…
CVE-2026-10818: WPForms Pro <=1.10.1.1 has a HIGH severity file upload vuln (CVSS 8.1). Unauthenticated RCE possible via ajax_chunk_upload_finalize. Restrict access & monitor uploads until a patch is released. https://radar.offseq.com/thre…
CVE-2026-66012: CRITICAL flaw in siyuan-note siyuan (<3.7.2). Missing authorization on /mcp lets remote attackers read secrets & plant malicious plugins for admin takeover. Disable anonymous Publish mode & restrict /mcp access. https://rad…
CVE-2026-12503 (CRITICAL, CVSS 9.2) affects Loytec LIP-ME20xC: improper link resolution in larm_starter lets larmapp users escalate to root via /etc/passwd symlink. Limit access & monitor! https://radar.offseq.com/threat/cve-2026-12503-cwe…
CVE-2026-16766: CRITICAL OS command injection in Catalyst::View::Wkhtmltopdf (<0.6.1). Exploitable via unsanitized PDF options — remote code execution possible. No maintained patch; upgrade to 0.6.1+ or migrate. https://radar.offseq.com/th…
Microsoft Purview Data Governance is impacted by CVE-2026-57106 (SSRF, CVSS 10, CRITICAL). Remote attackers can escalate privileges — patch ASAP using the official fix: https://radar.offseq.com/threat/cve-2026-57106-cwe-918-server-side-req…
CVE-2026-58630: Improper access control in Azure App Service for Linux (CVSS 10, CRITICAL) lets remote attackers escalate privileges with no auth or user action. Patched by Microsoft — verify updates. Details: https://radar.offseq.com/thre…
CVE-2026-56163: CRITICAL (CVSS 10) in Azure Kubernetes Service — Missing authentication allows remote privilege escalation. Microsoft has released a fix; verify your AKS is updated. https://radar.offseq.com/threat/cve-2026-56163-cwe-306-mi…
🐘 Community & instance
💡 Facts
🕵️ Fake follower check
Estimated- Est. 84% real, active audience · Low fake-follower risk.
- Engagement (~0.7% of followers engage each post) is around typical for Mastodon.
Heuristic estimate from engagement, follower ratios, account age & growth — a screening signal, not a guarantee.
About
📸 Gallery
🔀 Audience overlap
EstimatedEstimated shared audience with similar creators — useful for avoiding overlap (or doubling down) when planning a campaign.
More like this
Find more →✉ Message OffSequence
Reaching out to influencers is a Pro feature. Upgrade to message any influencer directly — perfect for brands and agencies booking sponsorships.
- ✓ Message any influencer from their listing
- ✓ The influencer gets notified by email
- ✓ Manage every conversation in one inbox
Already Pro? Log in.
🎤 Event / appearance with OffSequence
Booking an event / appearance is a Pro feature. Upgrade to book OffSequence for an in-person or virtual appearance — payment held safely in escrow until the event is done.
- ✓ Book them for events, livestreams, panels & more
- ✓ OffSequence gets notified by email
- ✓ Fee held in escrow, released after the appearance
Already Pro? Log in.
You're out of free requests this month
Free accounts get 5 per month. Go Pro for unlimited sponsor pitches, collab requests & sponsorship deals — plus featured placement, the Verified badge, free withdrawals and more.
Upgrade to Pro — $9.95/mo →Your free limit resets on the 1st of next month.
Auto-generated from Mastodon's public data — no affiliation with or endorsement by SocialDB. Is this you? Claim it · Remove