cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • supply-chain 2026-06-17 Critical

    Mastra npm Scope Hijacked: 144 AI-Framework Packages Backdoored with the easy-day-js Stealer

    An attacker hijacked a former contributor's npm account to republish ~144 @mastra packages — including @mastra/core (918K weekly downloads) — each pulling in easy-day-js, a dayjs typosquat that drops a cross-platform crypto/infostealer at install time.

    npmsupply-chaininfostealernodejsnorth-korea
  • vulnerabilities 2026-06-17

    RoguePlanet Gets a CVE: Microsoft Confirms Patch in Progress for Defender SYSTEM Race Condition (CVE-2026-50656)

    One week after a public PoC dropped during Patch Tuesday, Microsoft has assigned CVE-2026-50656 to RoguePlanet — a Defender Malware Protection Engine race condition that hands SYSTEM on fully patched Windows 10 and 11 — and confirmed a fix is in flight. No patch yet.

    windowszero-dayprivilege-escalationlpe
  • threats 2026-06-16

    Velvet Ant's Operation Highland: A China-Nexus APT Backdoored the Linux Auth Stack for a Decade

    Sygnia's Operation Highland report details how the China-nexus group Velvet Ant hid in an isolated network for nearly a decade by backdooring pam_unix.so and OpenSSH binaries — no exploit, no dropped malware, no anomalous logs.

    aptlinuxcredential-theftinfrastructure
  • vulnerabilities 2026-06-16 Critical

    Ivanti Sentry CVE-2026-10520: Unauthenticated Root RCE via handleMessage, Now in CISA KEV

    A CVSS 10.0 OS command injection in Ivanti Sentry's unauthenticated /mics/api/v2/sentry/mics-config/handleMessage endpoint yields remote code execution as root. watchTowr published a PoC on June 10, CISA added it to KEV on June 11 with a June 14 deadline, and exploitation has followed.

    ivanticommand-injectioncisa-kev
  • vulnerabilities 2026-06-15

    Jenkins CVE-2026-53435: config.xml Deserialization RCE Exploited Five Days After Disclosure

    CVE-2026-53435 (CVSS 9.0) is an unsafe-deserialization RCE in Jenkins' config.xml handling. Disclosed June 10, a public PoC is now driving in-the-wild exploitation against internet-exposed CI/CD servers. Patch to weekly 2.568 or LTS 2.555.3.

    deserializationrceci-cdactive-exploitation
  • vulnerabilities 2026-06-15

    Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild — Patch Every Chromium Runtime, Not Just Browsers

    Google patched CVE-2026-11645, an actively exploited out-of-bounds read/write in V8. The real blast radius is every Chromium runtime you operate — headless Chrome in CI, Electron apps, and server-side renderers.

    chromezero-dayrcecisa-kev
  • vulnerabilities 2026-06-14

    Splunk Enterprise CVE-2026-20253: An Unauthenticated Postgres Sidecar Hands Over Pre-Auth RCE

    CVE-2026-20253 (CVSS 9.8) is a pre-auth RCE in Splunk Enterprise. An unauthenticated Postgres sidecar endpoint gives an arbitrary file write that escalates to code execution — on the box holding all your logs. Full exploit details are public; patch now.

    ciscopostgresqlrcepre-authsieminfrastructure
  • vulnerabilities 2026-06-14

    Veeam VBR CVE-2026-44963: Any Domain User Can Own Your Backup Server

    A critical CVSS 9.4 RCE lets any authenticated domain user run code on domain-joined Veeam Backup & Replication servers. Patch to 12.3.2.4854 now.

    rceransomwareactive-directory
  • deep dive 2026-06-14 11 min read

    eBPF Cuts Both Ways: The Kernel Rootkit Is Now Standard Issue in 2026's Supply-Chain Malware

    In two weeks, IronWorm and the atomic-lockfile AUR compromise both shipped an eBPF kernel rootkit as just another payload module. The observability primitive your stack is built on is now the malware's stealth layer — and most detection assumptions are structurally defeated.

    ebpfrootkitlinuxedr-evasionsupply-chaintrend-analysis
  • vulnerabilities 2026-06-13

    Proto6: Six protobuf.js Flaws Turn Trusted Schemas Into RCE and DoS Across gRPC, Cloud, and AI Stacks

    Cyera's Proto6 research discloses six CVEs in protobuf.js, including a prototype-pollution-to-RCE chain, in a library pulled 50M+ times a week across gRPC, Google Cloud SDKs, vector databases, and CI/CD.

    supply-chainrcenodejsgrpcci-cd
  • supply-chain 2026-06-12

    400+ AUR Packages Compromised: atomic-lockfile npm Payload Drops Credential Stealer With eBPF Rootkit

    Over 400 Arch User Repository packages were modified to pull a malicious npm package that deploys a developer-focused credential stealer with optional root-only eBPF rootkit capabilities.

    supply-chainnpmebpfrootkitinfostealerlinux
  • policy 2026-06-12

    CISA Kills the Flat KEV Deadline: BOD 26-04 Starts a Three-Day Patch Clock

    BOD 26-04 revokes BOD 22-01 and 19-02, replacing flat KEV due dates with risk-tiered deadlines: three days plus mandatory forensic triage for internet-facing, automatable, total-control flaws.

    cisavulnerability-management
  • vulnerabilities 2026-06-11

    Oracle Ships Out-of-Band Fix for PeopleSoft Zero-Day CVE-2026-35273 as ShinyHunters Loots 100+ Orgs

    Oracle pushed an emergency alert for CVE-2026-35273, an unauthenticated CVSS 9.8 RCE in PeopleSoft PeopleTools. Mandiant confirms in-the-wild exploitation, and ShinyHunters claims data theft from 100+ organizations including the University of Nottingham.

    oraclercezero-dayshinyhuntersextortion
  • vulnerabilities 2026-06-09

    Microsoft's June Patch Tuesday Is Its Biggest Ever: 200 Flaws, 33 Critical, Three Public Zero-Days

    Microsoft's largest Patch Tuesday on record fixes 200 vulnerabilities including HTTP.sys and Kerberos KDC RCEs, three Hyper-V escapes, and the HTTP/2 Bomb and YellowKey BitLocker zero-days.

    microsoftpatch-tuesdayzero-dayhttp2active-directory
  • vulnerabilities 2026-06-09

    Cisco Unified CM CVE-2026-20230: Public PoC Turns an SSRF Into Root

    An unauthenticated SSRF in Cisco Unified Communications Manager (CVE-2026-20230) lets attackers write files to the OS and climb to root. PoC code is public, the 15-train fix is months out, and there's no workaround beyond disabling WebDialer.

    ciscossrfprivilege-escalation
  • vulnerabilities 2026-06-08 Critical

    CVE-2026-50751: Check Point VPN Auth Bypass Exploited by Qilin — IKEv1 Sessions Without a Password

    Check Point confirmed active exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Remote Access VPN and Mobile Access deployments running deprecated IKEv1. Attackers establish VPN sessions without a valid password; one case is tied to a Qilin ransomware affiliate. Earliest exploitation traces to May 7.

    vpnauthentication-bypassransomware
  • vulnerabilities 2026-06-08

    An AI Agent Found 21 Zero-Days in FFmpeg for $1,000 — and Your Container Images Are in Scope

    depthfirst's autonomous agent found 21 zero-days in FFmpeg for about $1,000, including a 23-year-old stack overflow. Nine carry CVEs (CVE-2026-39210 through CVE-2026-39218). FFmpeg is bundled everywhere — patch upstream and your embedded copies.

    ai-securityzero-daysupply-chain
  • threats 2026-06-07

    CISA and the FBI Warn: Internet-Exposed Fuel Tank Gauges Are Under Active Attack

    A June 2 joint advisory from CISA, the FBI, the NSA and five other agencies says attackers are compromising internet-exposed automatic tank gauge systems and modifying them through command execution. Shadowserver counts over 1,000 exposed, 909 in the US — on the same TCP port these consoles have answered on for a decade.

    icsotcritical-infrastructurecisafbiiran
  • supply-chain 2026-06-07

    Claude Code's GitHub Action: One Malicious Issue Could Hijack Any Public Repo

    A permission bypass chained with prompt injection in Anthropic's Claude Code GitHub Action let a single crafted issue make the agent leak CI secrets and OIDC request tokens — a clean path to poisoning the action's own supply chain. Patched in v1.0.94.

    supply-chaingithub-actionsci-cdai-security
  • deep dive 2026-06-07 13 min read

    Anatomy of the Interlock Campaign: How a ClickFix Gang Learned to Burn Firewall Zero-Days

    For a year, the surest way to get hit by Interlock was to paste a command into your own Run dialog. On January 26, 2026, the group stopped waiting for users to make mistakes and started exploiting a pre-auth, root-level Cisco firewall zero-day instead. The same crew now runs both ends of the sophistication ladder — and that should change how you model initial access.

    ransomwarecisconetwork-appliancedeserializationclickfixzero-daycisa-kev
← newer12345678910111213141516171819older →
© 2026 Max Clinton rss