> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
CVE-2026-9586: Unauthenticated SQLi-to-RCE in Sangoma Switchvox Under Active Exploitation
An unauthenticated SQL injection in Sangoma Switchvox's phone-provisioning endpoint escalates to root command execution and is now being used in the wild to plant reverse shells on internet-exposed VoIP servers.
The WannaCry Bugs Never Left: Windows' Core Network Stack Just Had Its Worst Year Since EternalBlue
Netlogon, DNS Client, DHCP Server, DNS Server — four unauthenticated, network-reachable, CVSS-9.8-class memory corruption bugs in Windows' core infrastructure services in five months. This is not four unlucky patch cycles. It's a pattern, and most vulnerability-management programs are triaging it wrong.
PostGREShell (CVE-2026-6471): A 12-Year-Old PostgreSQL Flaw Turns Replication Access Into Root RCE
A missing-authorization bug in PostgreSQL logical decoding, present since version 9.4 in 2014, lets any account with REPLICATION privilege load an arbitrary library and execute code as the database server's OS user.
Cisco Nexus 9000 CVE-2026-20212: Unauthenticated Root RCE on Silicon One Data Center Switches
A CVSS 9.8 flaw lets unauthenticated attackers execute code as root on Cisco Nexus 9000 switches with Silicon One ASICs by reaching two hard-coded, unrestricted TCP ports.
CVE-2026-49869: Kestra OSS Auth-Bypass Lets Unauthenticated Attackers Get Root RCE, CISA Sets Today as Federal Deadline
A suffix-match flaw in Kestra OSS's AuthenticationFilter lets anyone skip Basic Auth entirely and reach unauthenticated remote code execution as root, CVSS 10.0, now on CISA's KEV list.
HPE Aruba AOS-CX: Two Independent Unauthenticated RCE Paths in the Same Switch OS (CVE-2026-73749, CVE-2026-73782)
HPE's September security bulletin for ArubaOS-CX patches 24 flaws, including two unrelated bugs that each let an unauthenticated attacker fully compromise a switch with a single crafted packet.
FalconFlank: Unpatched Local Privilege Escalation Zero-Day in CrowdStrike Falcon Sensor, PoC Public
A public PoC dubbed FalconFlank abuses CrowdStrike Falcon Sensor's malicious-macro remediation to escalate a local user to SYSTEM on fully patched Windows 11 and Server 2025. No CVE, no vendor fix yet — only a workaround.
CVE-2026-83548 & CVE-2026-83549: SonicWall SMA1000 Hit by Third Zero-Day Chain of 2026, CVSS 10.0 SSRF to Root RCE
SonicWall SMA1000 appliances are under active exploitation via a chained SSRF and OS command injection pair, CVE-2026-83548 and CVE-2026-83549, the product line's third zero-day incident this year.
CVE-2026-82329: Critical JFrog Artifactory Auth Bypass Under Active Exploitation for Admin Tokens
Attackers are exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, to mint themselves administrator tokens and enumerate credentials on internet-facing build-artifact repositories.
CVE-2026-0768: Unauthenticated Root RCE in Langflow's Validate Endpoint Under Mass Exploitation
CVE-2026-0768, an unauthenticated code-injection RCE in Langflow's custom component validator, is under active mass exploitation — VulnCheck honeypots logged 360 attacks since August 29 hunting for AWS and OpenAI keys.
Rhysida Breaches Berlin State Government Network, Claims 5.79 TB Including Water-Infrastructure Vulnerability Data
Rhysida claims 5.79 TB and 1.44 million files from Berlin's state government network, including water-supply vulnerability assessments and plaintext credentials, after a week-long gap between detection and network isolation.
Fire Ant Expands From VMware Hypervisors to Cisco IOS XR Routers and TACACS Servers
China-nexus actor Fire Ant has moved beyond VMware ESXi hosts to implant Cisco IOS XR routers and TACACS+ authentication servers, using purpose-built tooling to hijack GRE tunnels, hide commands from admins, and intercept credentials at the network's control plane.
Mini Shai-Hulud "Trinitite": TanStack Codegen Tool Poisoned via Hijacked GitHub OIDC Release Workflow
A new Mini Shai-Hulud wave dubbed Trinitite compromised @7nohe/openapi-react-query-codegen, a 150K-download-a-week TanStack code generator, by hijacking its GitHub Actions OIDC publish workflow rather than stealing a token.
ATF Confirms Qilin Ransomware Breach of System Holding Investigation Targets
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirms a 'major incident' after the Qilin ransomware gang listed it on a dark-web leak site, with the breached system holding data on active investigation targets.
CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation
watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.
The ECC Excuse Is Dead: A Hardening Guide for Multi-Tenant GPU Infrastructure After GPUThor
For four months, 'enable ECC' was the official fix for GPU Rowhammer. GPUThor just showed that advice was wrong. Here's what to actually change on GPU fleets that run untrusted CUDA code from more than one tenant.
GPUThor: First Rowhammer Attack to Defeat ECC on NVIDIA Workstation GPUs
University of Toronto researchers show GPUThor beats NVIDIA's ECC mitigation for GDDR6 Rowhammer, closing the gap the GPUBreach disclosure left open for host root access.
ShinyHunters Claims 284M-Record McKesson Breach After Vishing Two Employees Into Salesforce
ShinyHunters says it vished two McKesson employees into authorizing a rogue connected app, then pulled patient and physician records out of Salesforce and Snowflake — a $55M ransom followed.
Manchester Airports Group Breach Exposes Data of 8.7 Million Airport Customers
An unauthorized third party accessed customer data across Manchester, Stansted, and East Midlands airports, exposing contact and vehicle details for 8.7 million people. MAG refused a ransom demand and hasn't named the attacker publicly.
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Auth From the Service Account
CVE-2026-65641 (CVSS 9.3) lets an unauthenticated network attacker force Veeam ONE's service account into an SMB authentication attempt, exposing Net-NTLM material for relay or offline cracking.