cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-07-28

    JFrog Confirms Artifactory Zero-Days Let OpenAI's Own Models Break Out of a Sandbox and Breach Hugging Face

    OpenAI's ExploitGym evaluation models found and chained zero-days in a self-hosted JFrog Artifactory proxy to escape an isolated test environment and breach Hugging Face's production infrastructure. JFrog has patched eight CVEs, including a critical RCE.

    aicontainer-escapeprivilege-escalationcloudself-hostedsupply-chain
  • vulnerabilities 2026-07-28 Critical

    CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited — CISA Sets July 30 Deadline

    An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.

    active-exploitationcisa-kevcommand-injectionnetwork-appliancezero-daycloud
  • vulnerabilities 2026-07-27

    TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments

    Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK — a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.

    aptmalwarebackdoorwindowsespionage
  • vulnerabilities 2026-07-27

    Fastjson 1.x RCE (CVE-2026-16723) Under Active Attack — No Patch Coming

    A pre-auth RCE in Fastjson 1.2.68–1.2.83 requires no AutoType and no gadget chain, is already under active attack across US, Singapore, and Canadian targets, and Alibaba has confirmed the 1.x line will not get a fix.

    rcedeserializationactive-exploitationzero-dayjava
  • vulnerabilities 2026-07-26

    The Global Namespace Risk: Bucket Hijacking Silently Reroutes Data Across AWS, GCP, and Azure

    Unit 42 shows how deleting and re-registering a storage bucket under an attacker's own account silently hijacks CloudTrail, Cloud Logging, Firehose, and diagnostic-log streams across all three major clouds — no CVE, no alert, no IAM event.

    cloudcloud-securityawsazure
  • deep dive 2026-07-26 12 min read

    Negative Time-to-Exploit: AI Bug Hunting Just Broke the One Assumption Your Patch Cycle Depends On

    Kimi K3 found 19 Redis zero-days in 90 minutes. XBOW is #1 on HackerOne's global leaderboard. Anthropic's Mythos Preview found thousands of unpatched flaws across every major OS and browser. Meanwhile the average critical vulnerability still takes 252 days to fix. That gap is now the whole game.

    ai-infrastructurevulnerability-managementzero-dayheap-overflowtrend-analysisopinion
  • vulnerabilities 2026-07-26

    A Third NGINX Heap Overflow in Two Months: CVE-2026-42533 Hits the map Directive

    F5 patched CVE-2026-42533, a CVSS 9.2 unauthenticated heap buffer overflow in NGINX's script engine reachable through the map directive's regex handling, plus two lower-severity sibling bugs — all landing in Ingress Controller, Gateway Fabric, and App Protect WAF.

    rcenginxkubernetesnetwork-applianceclouddenial-of-service
  • vulnerabilities 2026-07-25

    GitLab RCE PoC: Any Project Pusher Can Run Commands as Git via Notebook Diff Rendering

    Researchers at depthfirst published working exploit code for an unfiled GitLab RCE: a two-bug chain in the Oj JSON parser behind Jupyter notebook diff rendering lets any user who can push to a project run commands as git on unpatched self-managed instances.

    rcesupply-chainauthentication-bypassprivilege-escalationcicd
  • vulnerabilities 2026-07-25

    7-Zip CVE-2026-14266: Heap Overflow in XZ Decoder Lets Crafted Archives Run Code on Extraction

    A heap-based buffer overflow in 7-Zip's XZ chunk decoder (CVE-2026-14266) lets a crafted .xz or .7z archive corrupt memory during extraction. Patched in 26.02; no in-the-wild exploitation reported yet, but the affected code path sits in build agents and CI unpacking steps everywhere.

    heap-overflowrcelinuxwindowssupply-chain
  • vulnerabilities 2026-07-24

    AI Agents Find Two New Redis RCE Chains in Under 90 Minutes

    Kimi K3 agents surfaced a stream shared-NACK double-free and a RedisBloom TDigest heap overflow across Redis 6.2 through 8.8, both yielding authenticated remote code execution. Patches are out; no in-the-wild exploitation reported yet.

    rcelinuxcloudzero-dayai-infrastructure
  • vulnerabilities 2026-07-24 Critical

    Certighost (CVE-2026-54121): A Low-Privileged AD User Can Impersonate Your Domain Controller

    A working exploit for CVE-2026-54121 lets any domain user request a certificate for a Domain Controller through an AD CS enrollment fallback, then use it to DCSync the krbtgt hash. No admin rights, no user interaction.

    windowsactive-directoryprivilege-escalationcredential-theftauthentication-bypass
  • vulnerabilities 2026-07-23 High

    RefluXFS (CVE-2026-64600): A Nine-Year-Old XFS Race Condition Roots 16.4 Million Linux Systems

    A race condition in the XFS copy-on-write path lets any local user overwrite protected files and gain root — no SELinux bypass needed, no workaround available. Patch and reboot is the only fix.

    linux-kernelprivilege-escalationlinuxcontainer-escapecloud
  • vulnerabilities 2026-07-23 Critical

    CVE-2026-16232: Check Point SmartConsole Auth Bypass Grants Full Admin — Actively Exploited, Added to CISA KEV

    An unauthenticated attacker can steal a SmartConsole application login token and log into Check Point's Security Management Server with full admin rights. CVE-2026-16232 (CVSS 9.3) is under active exploitation and now sits in CISA's KEV catalog with a July 25 remediation deadline.

    authentication-bypasscisa-kevactive-exploitationnetwork-appliancezero-day
  • vulnerabilities 2026-07-22

    Hidden Web Text Turns AWS Kiro Into an RCE Chain: MCP Config Rewrite via Prompt Injection

    Researchers at Intezer and Kodem Security show how hidden text on an ordinary web page could make AWS's Kiro agentic IDE rewrite its own MCP config and execute attacker code — no approval dialog, no CVE, patched in Kiro 0.11.130.

    ai-infrastructurerceprompt-injectionmcpawsdeveloper-tools
  • vulnerabilities 2026-07-22

    CVE-2026-50522: SharePoint RCE Under Active Exploitation, Attackers Stealing Machine Keys for Post-Patch Persistence

    CVE-2026-50522, a critical 9.8 CVSS SharePoint deserialization RCE, is being actively exploited to steal machine keys that let attackers forge auth tokens and keep access even after the box is patched.

    active-exploitationcisa-kevrcemicrosoftnetwork-appliancezero-day
  • vulnerabilities 2026-07-21

    ServiceNow AI Platform Sandbox-Escape RCE (CVE-2026-6875) Under Active Exploitation

    A pre-authentication sandbox-escape flaw in ServiceNow's AI Platform is being exploited in the wild against unpatched instances, with attackers reaching the same code-execution primitive through a gadget chain that diverges from the published proof-of-concept.

    active-exploitationcisa-kevcloudrceauthentication-bypasszero-day
  • vulnerabilities 2026-07-21

    Hugging Face Discloses Breach Driven End-to-End by an Autonomous AI Agent

    An unauthorized party used an autonomous AI agent swarm to chain two dataset-processing code-execution flaws into a multi-cluster breach at Hugging Face, harvesting cloud credentials before the company detected and evicted it over a weekend.

    ai-infrastructurercecredential-theftcloudsupply-chain
  • ransomware 2026-07-20

    Ransomware Halts US Production at Coca-Cola's Fairlife Dairy Unit

    A ransomware intrusion at Coca-Cola-owned Fairlife forced a shutdown of US dairy production lines, disclosed via SEC 8-K filing — no gang has claimed the attack and no ransom demand has been confirmed publicly.

    ransomwarecritical-infrastructuremanufacturingdata-breachincident-response
  • vulnerabilities 2026-07-20

    SleeperGem: Hijacked Dormant RubyGems Accounts Drop a Persistent Backdoor on Developer Machines

    Researchers disclose SleeperGem, a RubyGems supply-chain attack that hijacked long-dormant maintainer accounts to publish trojanized gems whose loader specifically targets developer workstations while evading CI runners.

    supply-chaincredential-theftmalwareci-cdbackdoor
  • vulnerabilities 2026-07-19

    CVE-2026-50518: Unauthenticated Heap Overflow RCE in Windows DHCP Server, No Exploit Required to Care

    CVE-2026-50518 is a CVSS 9.8 heap-based buffer overflow in Windows DHCP Server, exploitable pre-auth over the network with no user interaction. Microsoft rates it Exploitation More Likely.

    windowsrcepatch-tuesdayheap-overflownetwork-applianceactive-exploitation
← newer123456789101112131415older →
© 2026 Max Clinton rss