> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation
watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.
The ECC Excuse Is Dead: A Hardening Guide for Multi-Tenant GPU Infrastructure After GPUThor
For four months, 'enable ECC' was the official fix for GPU Rowhammer. GPUThor just showed that advice was wrong. Here's what to actually change on GPU fleets that run untrusted CUDA code from more than one tenant.
GPUThor: First Rowhammer Attack to Defeat ECC on NVIDIA Workstation GPUs
University of Toronto researchers show GPUThor beats NVIDIA's ECC mitigation for GDDR6 Rowhammer, closing the gap the GPUBreach disclosure left open for host root access.
ShinyHunters Claims 284M-Record McKesson Breach After Vishing Two Employees Into Salesforce
ShinyHunters says it vished two McKesson employees into authorizing a rogue connected app, then pulled patient and physician records out of Salesforce and Snowflake — a $55M ransom followed.
Manchester Airports Group Breach Exposes Data of 8.7 Million Airport Customers
An unauthorized third party accessed customer data across Manchester, Stansted, and East Midlands airports, exposing contact and vehicle details for 8.7 million people. MAG refused a ransom demand and hasn't named the attacker publicly.
Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Auth From the Service Account
CVE-2026-65641 (CVSS 9.3) lets an unauthenticated network attacker force Veeam ONE's service account into an SMB authentication attempt, exposing Net-NTLM material for relay or offline cracking.
PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version
PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.
CISA, NSA, FBI Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs
A joint advisory from NSA, CISA, FBI, DOE, and EPA warns that threat actors are pairing AI-assisted scripting with snap7 libraries to build custom reconnaissance and exploitation tools against internet-exposed Siemens S7 PLCs.
CVE-2026-60004: Gitea diffpatch Code Injection Now Under Active Exploitation, Added to CISA KEV
A critical Gitea flaw lets any repository writer install a malicious Git hook via the diffpatch endpoint and run shell commands as the Gitea OS user. CISA confirms in-the-wild exploitation and gave federal agencies until August 28 to patch.
NVIDIA NemoClaw Flaw Lets Any Website Hijack a Local AI Agent via DNS Rebinding
CVE-2026-65105 in NVIDIA NemoClaw lets a single malicious webpage use DNS rebinding to reach an unauthenticated local Ollama instance and permanently poison the model's chat template.
CVE-2026-21962: Max-Severity Oracle HTTP Server / WebLogic Proxy Flaw Added to CISA KEV After Months of Exploitation
CISA added CVE-2026-21962, a CVSS 10.0 auth-bypass and path-traversal flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its KEV catalog on August 24 — seven months after Oracle patched it and after mass automated scanning had already begun.
Iran-Linked Hackers Force UK Power Plant Offline for Four Days
A small UK generating station went dark for four days after an intrusion The Telegraph attributes to Iran-linked hackers, the first confirmed case of an IRGC-affiliated actor shutting down British energy infrastructure.
Keycloak's Reset-Credentials Flow Lets Unauthenticated Attackers Take Over Any Account (CVE-2026-18963)
CVE-2026-18963 lets an unauthenticated attacker skip email verification in Keycloak's password-reset flow and set new credentials on any account. Patch to 26.7.2 (or 26.4.15/26.6.6 for Red Hat builds) now.
9,300+ Leaked AWS Keys Are Still Active — 768 Give Attackers Full Admin Control
A large-scale scan of public repos, Hugging Face datasets, Docker images, and CI logs found over 9,300 leaked AWS keys still authenticate — 768 with full corporate admin control.
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Fourteen npm packages disguised as calendar and streak utilities smuggle in RedC2 4.0, a commercial Linux implant whose LLM-driven operator console turns plain-English prompts into post-exploitation commands.
Phishing the Protocol: How 2026 Attackers Made MFA Irrelevant
Device code grants, app passwords, OAuth consent screens, and WhatsApp device linking all share one property: they're real login flows, not bugs. 2026's biggest identity attacks stopped stealing passwords and started collecting the tokens MFA can't protect.
GTIG Tracks Three Russian Clusters Weaponizing App Passwords, OAuth Consent, and WhatsApp Linking
Google's Threat Intelligence Group details three Russia-nexus clusters — UNC6293, UNC7005, UNC5976 — abusing app-password generation, OAuth consent flows, and WhatsApp device linking to hijack accounts of diplomats, academics, and defense researchers without tripping MFA.
Poisoned arrayref, internment, and append-only-vec Crates Pull Build-Time Malware via a proc-macro2 Typosquat
A compromised maintainer account published malicious releases of three popular Rust crates that pull in a typosquatted proc-macro2 lookalike whose build.rs script downloads and runs a platform-specific payload at compile time — with infrastructure overlapping known DPRK supply-chain campaigns.
CVE-2026-69836: Perfect-10 Entra ID Deserialization RCE Exploited in the Wild
Microsoft confirms in-the-wild exploitation of CVE-2026-69836, a maximum-severity unauthenticated deserialization RCE in Entra ID's backend — already patched server-side, but the identity plane behind Microsoft 365 and Azure was exposed with no customer visibility into the attack.
CVE-2026-73570: Unauthenticated Zimbra RCE via SNMP Notifications Under Active Exploitation
CERT Polska confirms in-the-wild exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration's SNMP notification handling — patched in 10.1.20, but plenty of mail servers haven't updated.