SShortSingh.
Back to feed

Security audit finds multiple flash loan vulnerabilities in Sky Lending protocol

0
·1 views

A security analysis of the Sky Lending DeFi protocol identified multiple vulnerabilities related to flash loan attacks. The report, prepared by a senior DeFi security research team and dated October 8, 2026, examined the protocol's core contracts and a recent upgrade. The most critical risks involve oracle price manipulation and a re-entrancy flaw in reward withdrawals, which could lead to significant losses. The protocol has a total value locked of approximately $5.9 billion across Ethereum and several layer-2 networks. The overall flash loan exposure was assessed as moderate-high.

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

AI researcher exposes Meta's Muse assistant tracking personal social connections hourly

In early October 2026, independent researcher Karan Joshi discovered Meta's AI assistant Muse maintains detailed files on people in users' social circles. The system compiles and refreshes personal information hourly from messages, photos, and past interactions without those individuals' consent. This revelation sparked debate about AI memory systems, contrasting Meta's transparency claims against privacy researchers' dossier concerns. Meanwhile, engineer Kevin Liao argued that current AI memory approaches using vector databases are flawed because they prioritize text similarity over accuracy. Liao proposed replacing such systems with structured documentation that agents and humans can review and update collaboratively.

0
ProgrammingDEV Community ·

New tool scrapes public Meetup event data from embedded cache, bypassing API restrictions

A tool called Meetup Events Scraper extracts public event data from Meetup.com without requiring login or API keys. It works by reading the Apollo GraphQL cache embedded in the public search page's HTML, which Next.js applications provide. This approach bypasses Meetup's official API, which is restricted to paying Pro subscribers. The service is offered on a pay-per-use basis, charging for each search run and per event retrieved.

0
ProgrammingDEV Community ·

Verify patches for critical NetScaler flaw CVE-2026-88772, advisories warn

Security agencies NCSC-NL and CERT-FR have issued advisories regarding the critical vulnerability CVE-2026-88772 in Citrix NetScaler ADC and Gateway devices. The flaw, which requires DTLS to be enabled for exploitation, was actively exploited before fixes were released. The fixed software builds are version 14.1-73.37 and later for the 14.1 branch. Organizations are urged to verify their patches across all systems, including failover units, and to preserve logs from the exposure period. Over 239,000 internet-facing Citrix NetScaler instances were identified in a recent scan.

0
ProgrammingDEV Community ·

Firebase Token Toolkit simplifies API testing by generating valid ID tokens

A new tool called Firebase Token Toolkit helps developers generate valid Firebase ID tokens for testing backend APIs. It bypasses the need for custom scripts by using a service account to create a custom token and exchange it via Google's authentication system. The resulting ID token is indistinguishable from one generated by a real client sign-in. The tool also assists with related tasks like managing custom claims and App Check tokens. It is a native application available for Linux, Windows, and macOS.