{"ok":true,"trend":{"id":864422,"platform":"mastodon","region":"global","key":"nasa-ammos ait-core ≤3.1.1 has a critical vuln (cve-2026-105105): zeromq bus lacks auth, exposing command & telemetry to","title":"NASA-AMMOS AIT-Core ≤3.1.1 has a CRITICAL vuln (CVE-2026-105105): ZeroMQ bus lacks auth, exposing command & telemetry to","url":"https://infosec.exchange/@offseq/117377218887743973","first_seen":"2026-10-03T13:33:53.253529Z","last_seen":"2026-10-03T13:33:53.253529Z","last_rank":11,"peak_rank":11,"last_volume":1,"peak_volume":1,"seen_count":1,"score":0.78734375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"NASA's AMMOS AIT-Core toolkit, used for spacecraft ground systems, has a critical vulnerability tracked as CVE-2026-105105. The flaw affects versions up to 3.1.1: its ZeroMQ bus ships without authentication, potentially exposing spacecraft commands and telemetry to remote attackers. NASA has released version 3.1.2, which restricts bus access to the local loopback interface, and users are urged to upgrade immediately.","why":"A newly disclosed critical flaw in NASA software used for mission command and telemetry raises fresh concerns about space infrastructure security.","tone":"negative","entities":["NASA","AMMOS AIT-Core","ZeroMQ","CVE-2026-105105"],"summarized_at":"2026-10-03T13:35:23.348230Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":1124},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Critical vulnerability found in NASA's AIT-Core software","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-03T13:33:53.253529Z","rank":11,"volume":1}],"posts":[{"platform":"mastodon","url":"https://infosec.exchange/@offseq/117377218887743973","author":"offseq@infosec.exchange","title":null,"snippet":"NASA-AMMOS AIT-Core ≤3.1.1 has a CRITICAL vuln (CVE-2026-105105): ZeroMQ bus lacks auth, exposing command & telemetry to remote attackers. Upgrade to 3.1.2 restricts access to loopback. Details: https:// radar.offseq.com/threat/cve-20…","posted_at":"2026-10-03T13:30:23Z","likes":1}],"elsewhere":[],"window":"7d"}}