cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • deep dive 2026-07-19 11 min read

    Six Bulletins, One Bug Class: What Ubiquiti's 2026 UniFi Cadence Reveals About Shared-OS Edge Platforms

    Since October 2025, Ubiquiti has shipped six security bulletins covering the UniFi line — five of them containing CVSS 9.9-10.0 flaws, two of them the exact same shell-injection bug class shipped seven months apart. This is what happens when one Nginx gateway and one OS layer sit in front of your network, your cameras, and your door locks.

    network-appliancecommand-injectionauthentication-bypasscisa-kevtrend-analysis
  • supply-chain 2026-07-19

    ViteVenom: Scoped npm Packages Impersonate @vitejs to Deliver a Blockchain-C2 RAT

    Checkmarx tracks ViteVenom, a sequel to the ChainVeil campaign, in which seven scoped npm packages impersonating the @vitejs namespace deploy a RAT that fetches its C2 address from Tron and Aptos blockchain transactions.

    supply-chainnpmcryptocurrencymalwarecredential-theft
  • vulnerabilities 2026-07-18

    wp2shell: A Two-CVE Chain Turns WordPress Core Into Pre-Auth RCE

    CVE-2026-60137 and CVE-2026-63030 chain a REST API route-confusion bug with a WP_Query SQL injection to give unauthenticated attackers a path to full RCE on default WordPress installs.

    sql-injectionrceauthentication-bypasscmsactive-exploitation
  • vulnerabilities 2026-07-18

    VMSA-2026-0005: Seven Flaws in VMware Avi Load Balancer, Topped by a 9.8 Auth Bypass

    Broadcom patched seven vulnerabilities in VMware Avi Load Balancer, led by CVE-2026-47865, a CVSS 9.8 authentication bypass that gives a network attacker a foothold on the control plane.

    authentication-bypassrceprivilege-escalationnetwork-appliancecloud
  • vulnerabilities 2026-07-17

    HollowByte: An 11-Byte TLS Handshake Payload That Bloats OpenSSL Server Memory

    A memory-allocation flaw in OpenSSL's TLS handshake parsing, dubbed HollowByte, lets an unauthenticated attacker exhaust server memory with an 11-byte payload per connection. No CVE was assigned; patched in 4.0.1 and backported across the 3.x line.

    denial-of-servicelinuxnetwork-applianceinfrastructurecloud
  • vulnerabilities 2026-07-17

    LegacyHive: Unpatched Windows Zero-Day Lets Standard Users Mount Another Account's Registry Hive

    Researcher Nightmare Eclipse has dropped LegacyHive, a working PoC against the Windows User Profile Service that lets a standard user load another account's registry hive — no CVE, no patch, works on fully updated July 2026 systems.

    windowszero-dayprivilege-escalationlpe
  • vulnerabilities 2026-07-17

    AA26-194A: NSA, CISA, FBI Warn Russian FSB Center 16 Is Harvesting Router Configs via Weak SNMP and an 18-Year-Old Cisco CSRF Bug

    A 19-agency joint advisory (AA26-194A) details a years-long Russian FSB Center 16 campaign that scans for default SNMP community strings and an 18-year-old Cisco IOS CSRF flaw (CVE-2008-4128, now in CISA KEV) to exfiltrate router configs and pivot into critical infrastructure.

    aptnetwork-applianceactive-exploitationcisa-kevcritical-infrastructureauthentication-bypass
  • vulnerabilities 2026-07-16

    CVE-2026-58658: GPUStack Worker Ports Leaked LLM Prompts and Completions With No Authentication

    GPUStack, an open-source GPU cluster manager for vLLM/SGLang/TensorRT-LLM inference, shipped worker debug and log-streaming endpoints with zero authentication — letting anyone who can reach the worker port read live prompts, completions, and memory profiles.

    authentication-bypasscloudkubernetesaiinformation-disclosurenetwork-appliance
  • vulnerabilities 2026-07-15

    AsyncAPI npm Packages Backdoored via GitHub Actions 'Pwn Request', Deliver Miasma RAT

    A stolen CI token let attackers push a malicious commit into AsyncAPI's npm packages on July 14, delivering an IPFS-hosted Miasma RAT to millions of weekly installs — this time configured as a stealthy botnet, not a self-propagating worm.

    supply-chainnpmci-cdgithub-actionscredential-theftmalware
  • vulnerabilities 2026-07-15

    CVE-2026-15409 & CVE-2026-15410: SonicWall SMA1000 Zero-Days Chained for Unauthenticated RCE, CISA Deadline July 17

    Two SonicWall SMA1000 zero-days — a CVSS 10.0 SSRF and a post-auth code injection flaw — are being chained in the wild for unauthenticated remote code execution. CISA KEV deadline is July 17, 2026.

    active-exploitationcisa-kevnetwork-appliancevpnzero-dayssrf
  • vulnerabilities 2026-07-14

    Microsoft's July Patch Tuesday Breaks Its Own Record Again: 570 Flaws, Two Zero-Days Under Active Attack

    Microsoft's largest Patch Tuesday ever fixes 570 vulnerabilities, including an exploited AD FS privilege-escalation zero-day, an exploited SharePoint EoP zero-day, and a publicly disclosed BitLocker bypass.

    microsoftpatch-tuesdayzero-dayactive-exploitationprivilege-escalationrce
  • vulnerabilities 2026-07-14

    AssuranceAmerica Breach Exposes 7 Million Driver's Licenses After a Single Phished Employee Account

    A single compromised employee credential at auto insurer AssuranceAmerica led to the theft of driver's license numbers, SSNs, and policy data for nearly 7 million people — one of the largest driver's-license breaches disclosed in the US this year.

    data-breachcredential-theftphishingcritical-infrastructureincident-response
  • supply-chain 2026-07-13

    Injective Labs' @injectivelabs/sdk-ts npm Package Backdoored to Steal Wallet Private Keys

    A compromised release of Injective Labs' TypeScript SDK, @injectivelabs/sdk-ts, and 17 dependent packages hooked wallet key-derivation functions to exfiltrate mnemonic seed phrases and private keys to an endpoint disguised as legitimate Injective infrastructure.

    supply-chainnpmcredential-theftcryptocurrencymalware
  • vulnerabilities 2026-07-13

    Six U-Boot Flaws Let Malicious Firmware Images Execute Code Before Signature Verification Ever Runs

    Binarly found six bugs in U-Boot's FIT image parser — two lead to code execution, four to denial of service — and all six trigger while the bootloader is still reading an untrusted image, before it checks the signature that's supposed to protect it.

    firmwarelinuxrcenetwork-applianceiotsupply-chain
  • vulnerabilities 2026-07-12

    Progress Tells ShareFile Customers to Power Down Storage Zone Controllers Over 'Credible' Threat

    Progress Software is telling on-prem ShareFile Storage Zone Controller admins to physically shut down their Windows servers over an unnamed 'credible external security threat' — no CVE, no patch, no explanation.

    network-appliancewindowscloudinfrastructureincident-response
  • deep dive 2026-07-12 12 min read

    The Agent Is the Payload: How AI Coding Agents Became 2026's Fastest RCE Pipeline

    Six incidents in six weeks show the same failure mode: AI coding agents treat untrusted text as instructions and shell access as a convenience feature. Prompt injection to RCE is no longer theoretical — it's a documented, repeatable kill chain, and the guardrails vendors are shipping don't touch the actual boundary.

    ai-infrastructureprompt-injectionrcesupply-chaincredential-thefttrend-analysis
  • supply-chain 2026-07-12

    Jscrambler npm Package Compromised: Rust Infostealer Shipped via Preinstall Hook

    The official jscrambler npm package was compromised to publish version 8.14.0 with a preinstall hook that drops a cross-platform Rust infostealer targeting cloud credentials, crypto wallets, and password managers.

    supply-chainnpmcredential-theftinfostealerci-cd
  • vulnerabilities 2026-07-11

    PraisonAI: Two More Critical RCEs (CVE-2026-61445, CVE-2026-61447) as AICoder Runs LLM Output Unsandboxed

    PraisonAI's AICoder component writes files and executes shell commands straight from LLM tool calls with no path validation, and CodeAgent._execute_python() runs LLM-generated Python with no AST checks or sandboxing — two CVSS 9.9 and 10.0 flaws, patched in 4.6.78.

    ai-infrastructurerceprompt-injectionsandbox-escapecommand-injectioncve
  • vulnerabilities 2026-07-11

    Zimbra Patches Classic Web Client Stored XSS Reported by Google TAG

    Zimbra shipped 10.1.19 to fix an unauthenticated stored XSS in the Classic Web Client, reachable by simply opening a crafted email — no CVE assigned yet, reported by Google's Threat Analysis Group.

    network-appliancexsscredential-theftemail-securityapt
  • vulnerabilities 2026-07-10

    Langflow Hit With Its Second CISA KEV Entry in Four Months: CVE-2026-55255 IDOR Under Active Exploitation

    CISA adds Langflow CVE-2026-55255, an IDOR letting authenticated attackers hijack other users' AI workflows, to its KEV catalog after Sysdig caught in-the-wild exploitation chained with secret harvesting.

    cisa-kevactive-exploitationauthentication-bypassai-infrastructurecredential-theft
← newer123456789101112131415older →
© 2026 Max Clinton rss