cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-08-29

    ShinyHunters Claims 284M-Record McKesson Breach After Vishing Two Employees Into Salesforce

    ShinyHunters says it vished two McKesson employees into authorizing a rogue connected app, then pulled patient and physician records out of Salesforce and Snowflake — a $55M ransom followed.

    shinyhuntersdata-breachsocial-engineeringsalesforcecloudextortion
  • vulnerabilities 2026-08-28

    Manchester Airports Group Breach Exposes Data of 8.7 Million Airport Customers

    An unauthorized third party accessed customer data across Manchester, Stansted, and East Midlands airports, exposing contact and vehicle details for 8.7 million people. MAG refused a ransom demand and hasn't named the attacker publicly.

    data-breachcritical-infrastructureransomwarethird-party-riskincident-response
  • vulnerabilities 2026-08-28

    Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Auth From the Service Account

    CVE-2026-65641 (CVSS 9.3) lets an unauthenticated network attacker force Veeam ONE's service account into an SMB authentication attempt, exposing Net-NTLM material for relay or offline cracking.

    authentication-bypassnetwork-appliancebackup-infrastructurewindowscredential-theft
  • vulnerabilities 2026-08-27

    PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version

    PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.

    zero-dayactive-exploitationrcenetwork-appliancecisa-kev
  • vulnerabilities 2026-08-27

    CISA, NSA, FBI Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs

    A joint advisory from NSA, CISA, FBI, DOE, and EPA warns that threat actors are pairing AI-assisted scripting with snap7 libraries to build custom reconnaissance and exploitation tools against internet-exposed Siemens S7 PLCs.

    icsot-securityscadacritical-infrastructurenetwork-applianceactive-exploitation
  • vulnerabilities 2026-08-26

    CVE-2026-60004: Gitea diffpatch Code Injection Now Under Active Exploitation, Added to CISA KEV

    A critical Gitea flaw lets any repository writer install a malicious Git hook via the diffpatch endpoint and run shell commands as the Gitea OS user. CISA confirms in-the-wild exploitation and gave federal agencies until August 28 to patch.

    active-exploitationcisa-kevrceself-hostedgitcommand-injection
  • vulnerabilities 2026-08-26

    NVIDIA NemoClaw Flaw Lets Any Website Hijack a Local AI Agent via DNS Rebinding

    CVE-2026-65105 in NVIDIA NemoClaw lets a single malicious webpage use DNS rebinding to reach an unauthenticated local Ollama instance and permanently poison the model's chat template.

    ai-infrastructureauthentication-bypasssandbox-escapellmcloud
  • vulnerabilities 2026-08-25

    CVE-2026-21962: Max-Severity Oracle HTTP Server / WebLogic Proxy Flaw Added to CISA KEV After Months of Exploitation

    CISA added CVE-2026-21962, a CVSS 10.0 auth-bypass and path-traversal flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its KEV catalog on August 24 — seven months after Oracle patched it and after mass automated scanning had already begun.

    active-exploitationcisa-kevauthentication-bypassrcecloud
  • vulnerabilities 2026-08-25

    Iran-Linked Hackers Force UK Power Plant Offline for Four Days

    A small UK generating station went dark for four days after an intrusion The Telegraph attributes to Iran-linked hackers, the first confirmed case of an IRGC-affiliated actor shutting down British energy infrastructure.

    icsot-securitycritical-infrastructureiranaptscada
  • vulnerabilities 2026-08-24

    Keycloak's Reset-Credentials Flow Lets Unauthenticated Attackers Take Over Any Account (CVE-2026-18963)

    CVE-2026-18963 lets an unauthenticated attacker skip email verification in Keycloak's password-reset flow and set new credentials on any account. Patch to 26.7.2 (or 26.4.15/26.6.6 for Red Hat builds) now.

    authentication-bypassidentity-providercritical-infrastructureprivilege-escalation
  • vulnerabilities 2026-08-24

    9,300+ Leaked AWS Keys Are Still Active — 768 Give Attackers Full Admin Control

    A large-scale scan of public repos, Hugging Face datasets, Docker images, and CI logs found over 9,300 leaked AWS keys still authenticate — 768 with full corporate admin control.

    cloudawscredential-theftcloud-securitydata-breach
  • vulnerabilities 2026-08-23

    14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

    Fourteen npm packages disguised as calendar and streak utilities smuggle in RedC2 4.0, a commercial Linux implant whose LLM-driven operator console turns plain-English prompts into post-exploitation commands.

    supply-chainnpmbackdoorlinuxcredential-theftmalware
  • deep dive 2026-08-23 11 min read

    Phishing the Protocol: How 2026 Attackers Made MFA Irrelevant

    Device code grants, app passwords, OAuth consent screens, and WhatsApp device linking all share one property: they're real login flows, not bugs. 2026's biggest identity attacks stopped stealing passwords and started collecting the tokens MFA can't protect.

    oauthphishingcredential-theftauthentication-bypasstrend-analysissocial-engineering
  • vulnerabilities 2026-08-22

    GTIG Tracks Three Russian Clusters Weaponizing App Passwords, OAuth Consent, and WhatsApp Linking

    Google's Threat Intelligence Group details three Russia-nexus clusters — UNC6293, UNC7005, UNC5976 — abusing app-password generation, OAuth consent flows, and WhatsApp device linking to hijack accounts of diplomats, academics, and defense researchers without tripping MFA.

    aptphishingoauthcredential-theftsocial-engineeringespionage
  • vulnerabilities 2026-08-22

    Poisoned arrayref, internment, and append-only-vec Crates Pull Build-Time Malware via a proc-macro2 Typosquat

    A compromised maintainer account published malicious releases of three popular Rust crates that pull in a typosquatted proc-macro2 lookalike whose build.rs script downloads and runs a platform-specific payload at compile time — with infrastructure overlapping known DPRK supply-chain campaigns.

    supply-chainrusttyposquattingcredential-theftbuild-pipelineapt
  • vulnerabilities 2026-08-21

    CVE-2026-69836: Perfect-10 Entra ID Deserialization RCE Exploited in the Wild

    Microsoft confirms in-the-wild exploitation of CVE-2026-69836, a maximum-severity unauthenticated deserialization RCE in Entra ID's backend — already patched server-side, but the identity plane behind Microsoft 365 and Azure was exposed with no customer visibility into the attack.

    active-exploitationrcecloudauthentication-bypassunauthenticated
  • vulnerabilities 2026-08-21

    CVE-2026-73570: Unauthenticated Zimbra RCE via SNMP Notifications Under Active Exploitation

    CERT Polska confirms in-the-wild exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration's SNMP notification handling — patched in 10.1.20, but plenty of mail servers haven't updated.

    active-exploitationcommand-injectionrceemail-securityunauthenticated
  • vulnerabilities 2026-08-20

    Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Breaks Guest-to-Host Isolation for AI Agent Sandboxes

    A type confusion in isolated-vm's ExternalCopy transferList handling lets code running inside a V8 sandbox corrupt host memory and hijack control flow — a full guest-to-host escape in a library millions of AI agent and automation deployments trust to run untrusted code.

    container-escapenpmsupply-chainauthentication-bypasscloud
  • vulnerabilities 2026-08-20

    Unauthenticated MLflow Webhook SSRF (CVE-2026-64849) Exploited Within Hours to Steal Cloud Credentials

    An unauthenticated SSRF in MLflow's webhook-test endpoint, CVE-2026-64849, lets attackers bypass an existing SSRF guard via HTTP redirects to reach cloud metadata services — and exploitation began within hours of the CVE going public.

    active-exploitationcloudserver-side-request-forgeryauthentication-bypassmlops
  • vulnerabilities 2026-08-19

    CVE-2026-19490: Critical NetScaler Auth Bypass Lets Attackers Skip the Login Screen Entirely

    A critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway lets unauthenticated attackers reach protected resources behind SSL VPN, ICA Proxy, and AAA virtual servers — patch CTX696939 now.

    authentication-bypassvpnnetwork-appliancezero-dayactive-exploitation
← newer12345678910111213141516171819older →
© 2026 Max Clinton rss