SECURITYTHE REGISTER
How to guarantee a speaker gig: Hack the system. Literally
A security researcher exploited a stored XSS vulnerability (CVE-2026-41241) in pretalx, a conference management tool, to auto-apply for and secure 40 speaker slots. The flaw allowed injecting malicious code via searchable fields, enabling unauthorized actions in the organizer interface. The vulnerability was patched in pretalx 2026.1.0, and the researcher validated findings responsibly without harming live systems.
Mentioned
Related Signal
Adjacent reporting
- CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
- New Fragnesia Linux flaw lets attackers gain root privileges
- New Exim BDAT Vulnerability Exposes GnuTLS Builds to Potential Code Execution
- Severe Linux Copy Fail security flaw uncovered using AI scanning help
- Hackers are exploiting a critical LiteLLM pre-auth SQLi flaw
- Windows Zero-Day Barrage Continues After Patch Tuesday