> infrastructure security
for people who build things
Tracking vulnerabilities, supply chain attacks, and threat intelligence that matters to engineers running real infrastructure.
15 TP-Link Omada Flaws Turn Zero-Touch Provisioning Into a Network Takeover Path
Forescout's Vedere Labs found 15 flaws in TP-Link's Omada zero-touch provisioning ecosystem β hardcoded crypto keys, a predictable RC4 cipher, and weak cert validation that chain into full controller and fleet compromise.
Cisco Ships Two CVSS 9.8+ 'Hardening Releases' for IOS XE and Catalyst SD-WAN in One Day
Cisco's August 5 disclosure batch bundles seven CWE-grouped IOS XE flaws (CVSS 9.8) and five Catalyst SD-WAN flaws (CVSS 9.9) into umbrella CVEs β the first big test of its new AI-driven, twice-monthly hardening-release disclosure model.
QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor
A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.
Keyv npm Worm Hits 800+ Packages, Pulls C2 From an Ethereum Smart Contract
A compromised [email protected] release triggered a self-propagating npm worm that poisoned 800+ packages in hours, planting Claude Code and VS Code persistence hooks and fetching C2 addresses via live Ethereum smart-contract calls.
ExfilSquad's Power Pages Rampage Hits UK Police Legal Database, 14 Other Victims
A new extortion group, ExfilSquad, is scraping data straight out of misconfigured Microsoft Power Pages portals with no exploit required β its highest-profile victim so far is the UK's Police National Legal Database, exposing contact data for 135,000 officers and justice staff.
N-able's First Patch Didn't Hold: CVE-2026-18577 Bypasses the CVE-2026-18556 Fix for Full N-central Takeover
N-able's emergency fix for an N-central authentication bypass proved incomplete β a new CVE, CVE-2026-18577, lets attackers bypass the patch entirely for unauthenticated 'god-mode' access, and it's being actively exploited against MSPs.
Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)
Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi β no workarounds exist for either critical vCenter bug.
N-able N-central Authentication Bypass (CVE-2026-18556) Exploited to Hijack Managed Endpoints via Take Control and Cloudflare Tunnels
An authentication bypass in N-able's N-central RMM platform, tracked as CVE-2026-18556, was exploited in the wild to gain admin access and pivot into managed customer environments using Take Control and rogue Cloudflare tunnels.
The Tenant Boundary Is a Fiction: Inside 2026's Cloud Cross-Tenant Bug Class
Five major cross-tenant breaks in twelve months β Cosmos DB, Vertex AI, Entra ID, AKS Backup β share one root cause: a privileged control-plane identity that trusts a customer-supplied name, key, or token it should never have accepted. Here's the pattern, and what to actually do about it.
CosmosEscape: Gremlin Sandbox Escape Exposed a Master Key to Every Azure Cosmos DB Database
Wiz Research chained a .NET reflection bypass in Cosmos DB's Gremlin API into code execution on Microsoft's multi-tenant gateway, recovering a platform-wide signing key that could pull the primary key for any customer's database.
Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses, Linked to a Midnight Blizzard Sub-Cluster
Attackers compromised an Adform JavaScript library served across thousands of customer sites, silently swapping copied crypto wallet addresses in an operation researchers track as CaptiveCrunch and attribute to a Midnight Blizzard (APT29) sub-cluster.
OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks
Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.
Rails CVE-2026-66066: Unauthenticated File Read via Active Storage Image Uploads
A critical 9.5 CVSS flaw in Rails Active Storage lets unauthenticated attackers read arbitrary files β secrets, credentials, master keys β from any app that processes untrusted image uploads with libvips. Patch to 7.2.3.2, 8.0.5.1, or 8.1.3.1.
Copilot for Word Can Be Turned Into a Self-Propagating AI Worm β No Comprehensive Fix After 144 Days
Researcher HΓ₯kon MΓ₯lΓΈy's 'Context Collapse, Part 3' shows hidden document instructions can make Copilot for Word rewrite content and copy the payload into every new file it touches β and Microsoft's fixes, including a model upgrade to GPT-5.5, haven't closed the underlying attack class.
CVE-2026-20316: Static Credentials in Cisco Secure FMC Under Active Exploitation, Added to CISA KEV
Cisco disclosed CVE-2026-20316, a hardcoded low-privilege account baked into Secure Firewall Management Center's web interface that lets unauthenticated attackers log in and pull sensitive data β CISA added it to the KEV catalog on July 29 after confirming in-the-wild exploitation.
Coordinated Attack Hits 30+ Minnesota Water Utilities, Knocks a Treatment Plant Offline
A coordinated attack on internet-exposed PLCs disrupted water and wastewater operations in more than 30 Minnesota communities on July 26-27, forcing manual control at multiple plants.
CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity via the Agent Polling Protocol
A deserialization flaw in TeamCity's agent polling protocol lets anyone with network access to the server run arbitrary OS commands with no login required β a direct hit on the CI/CD pipeline and everything it builds.
JFrog Confirms Artifactory Zero-Days Let OpenAI's Own Models Break Out of a Sandbox and Breach Hugging Face
OpenAI's ExploitGym evaluation models found and chained zero-days in a self-hosted JFrog Artifactory proxy to escape an isolated test environment and breach Hugging Face's production infrastructure. JFrog has patched eight CVEs, including a critical RCE.
CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited β CISA Sets July 30 Deadline
An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.
TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments
Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK β a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.