cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • Vulnerabilities 2026-04-04

    Ni8mare: CVSS 10.0 Unauthenticated RCE in n8n Workflow Automation (CVE-2026-21858)

    A CVSS 10.0 content-type confusion bug in n8n's webhook handler lets unauthenticated attackers read arbitrary files, steal credentials, forge admin sessions, and achieve full RCE. Patch to 1.121.0 immediately.

    cvercecvss-10
  • Vulnerabilities 2026-04-04

    Progress ShareFile Pre-Auth RCE Chain: CVE-2026-2699 and CVE-2026-2701 Give Attackers Full Server Takeover

    Two critical Progress ShareFile flaws chain into a pre-authentication RCE — with ~30,000 Storage Zone Controllers exposed and a public POC now available.

    rceauthentication-bypass
  • incident 2026-04-04

    European Commission Confirms Cloud Breach — Trivy Supply Chain Attack Cascades Into 30+ EU Entities

    The European Commission confirms a data breach affecting 30+ EU entities after the compromised Trivy scanner leaked AWS API keys to TeamPCP. ShinyHunters published 92 GB of stolen data.

    supply-chaintrivyawsshinyhuntersteampcpclouddata-breach
  • Vulnerabilities 2026-04-03

    CVE-2026-33186: gRPC-Go Auth Bypass Lets Attackers Skip Deny Rules With a Missing Slash

    A critical CVSS 9.1 flaw in gRPC-Go lets unauthenticated attackers bypass path-based authorization by omitting the leading slash from HTTP/2 :path headers.

    grpckubernetes
  • vulnerabilities 2026-04-03

    Langflow's 'Patched' Version Is Still Exploitable — CVE-2026-33017 Deadline Hits April 8

    JFrog confirms Langflow 1.8.2 remains vulnerable to CVE-2026-33017 unauthenticated RCE despite being widely reported as fixed. CISA KEV deadline is April 8.

    langflowrceai-infrastructurecisa-kevpython
  • vulnerabilities 2026-04-03

    Cisco Patches Two 9.8 CVSS Flaws in IMC and Smart Software Manager — No Workarounds Available

    Critical authentication bypass in Cisco IMC (CVE-2026-20093) and unauthenticated root RCE in SSM On-Prem (CVE-2026-20160) both score CVSS 9.8. Patch immediately — no workarounds exist.

    ciscoauthentication-bypassrce
  • vulnerabilities 2026-04-03

    CVE-2026-33105: Azure Kubernetes Service RBAC Bypass Scores Perfect 10.0 CVSS

    Critical AKS vulnerability allows privilege escalation to cluster admin via RBAC bypass. CVSS 10.0. Patch now.

    kubernetesazureprivilege-escalationcve
  • vulnerabilities 2026-04-03

    React2Shell Under Mass Exploitation: 766+ Next.js Hosts Breached in Credential Harvesting Campaign

    Threat actor UAT-10608 is mass-exploiting CVE-2025-55182 (React2Shell) to breach Next.js deployments and harvest cloud credentials, SSH keys, and API tokens at scale.

    rcecredential-theftcloud-security
  • Incidents 2026-04-03

    FBI Classifies Salt Typhoon Breach of Wiretap Infrastructure as 'Major Cyber Incident'

    The FBI has formally classified the Salt Typhoon compromise of its DCSNet wiretap system as a FISMA major incident, the bureau's first such designation since 2020.

    fbisupply-chain
  • vulnerabilities 2026-04-02 High

    15-Year-Old strongSwan Integer Underflow Lets Unauthenticated Attackers Crash VPN Gateways

    CVE-2026-25075 is an integer underflow in strongSwan's EAP-TTLS AVP parser that lets remote, unauthenticated attackers crash the charon IKE daemon — affecting every version since 4.5.0.

    vpndenial-of-service
  • vulnerability 2026-04-02

    CVE-2026-32746: 32-Year-Old GNU Telnetd Bug Gives Unauthenticated Attackers Root via Port 23

    A CVSS 9.8 pre-authentication buffer overflow in GNU inetutils telnetd lets remote attackers get root before the login prompt. Patch is incomplete across major distros and a public PoC exists.

    rcebuffer-overflowicsot
  • deep dive 2026-04-02 12 min read

    Dead Drops on the Chain: Why Blockchain Became the C2 Infrastructure Defenders Can't Take Down

    From EtherHiding to CanisterWorm to GlassWorm — attackers spent three years systematically proving that blockchain is the unkillable C2 channel. Here's how each technique works and what you can actually do about it.

    c2supply-chainmalware
  • vulnerabilities 2026-04-02

    CVE-2026-1579: Critical PX4 Autopilot Flaw Gives Attackers Full Drone Control via MAVLink

    CISA advisory for CVE-2026-1579 reveals a CVSS 9.8 authentication bypass in PX4 Autopilot that lets unauthenticated attackers gain shell access to drones over MAVLink.

    cveicscisaot-security
  • supply-chain 2026-04-02

    TeamPCP's Supply Chain Cascade: Trivy, KICS, LiteLLM, Telnyx Compromised — Now Pivoting to Ransomware via Vect

    TeamPCP poisoned Trivy, KICS, LiteLLM, and Telnyx across GitHub Actions and PyPI in March 2026, harvested ~300 GB of CI/CD secrets, breached Cisco and AstraZeneca, and has now partnered with Vect RaaS to convert stolen credentials into ransomware deployments.

    supply-chaintrivylitellmgithub-actionspypiransomwareteampcpci-cdkubernetes
  • vulnerabilities 2026-04-02 Critical

    Oracle Identity Manager Pre-Auth RCE: CVE-2026-21992 Emergency Patch

    Oracle issued an out-of-band emergency fix for CVE-2026-21992, a CVSS 9.8 unauthenticated RCE in Oracle Identity Manager's REST WebServices component affecting versions 12.2.1.4.0 and 14.1.2.1.0.

    oraclercepre-auth
  • vulnerabilities 2026-04-02 Critical

    CVE-2026-0625: Unauthenticated RCE via DNS Config Endpoint Hits Millions of End-of-Life D-Link Routers

    A critical command injection flaw in the dnscfg.cgi endpoint of legacy D-Link DSL, DIR, and DNS devices enables unauthenticated RCE — with no patches coming and active exploitation dating back to November 2025.

    zero-daycommand-injectionbotnet
  • vulnerabilities 2026-04-01 Critical

    F5 BIG-IP APM Flaw Silently Upgraded from DoS to RCE — Now Actively Exploited

    A five-month-old F5 BIG-IP APM bug just got reclassified from denial-of-service to pre-auth RCE. Attackers didn't wait for the memo.

    f5rcecisa-kevnetwork-appliance
  • threat-intel 2026-04-01 High

    TrueConf Zero-Day Weaponized by Chinese-Nexus APT to Backdoor Southeast Asian Governments

    Operation TrueChaos exploited CVE-2026-3502 in TrueConf's update mechanism to push Havoc C2 payloads across government networks via a compromised on-premises server.

    zero-daysupply-chainapt
  • vulnerabilities 2026-04-01 High

    Chrome Zero-Day CVE-2026-5281: WebGPU Use-After-Free Under Active Exploitation

    Google patches fourth Chrome zero-day of 2026 — a use-after-free in the Dawn WebGPU implementation that enables arbitrary code execution via crafted HTML pages.

    chromezero-dayuse-after-freebrowser-security
  • deep dive 2026-04-01 11 min read

    Your Firewall Is the Foothold: Q1 2026's Edge Device Exploitation Epidemic

    Three months into 2026, edge devices are the dominant entry point for attackers. A deep dive into the FortiGate SSO bypass and Ivanti EPMM RCE chains, and why this pattern shows no signs of stopping.

    network-appliancefortinetivantiauthentication-bypassransomwarecve
← newer1234567891011older →
© 2026 Max Clinton rss