cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-08-19

    ShieldBreak (CVE-2026-69414): A Full Bypass of Microsoft's RoguePlanet Defender Patch, Still Unfixed

    Nightmare Eclipse's ShieldBreak fully bypasses the fix for RoguePlanet, Microsoft Defender's earlier SYSTEM-privilege zero-day. Microsoft has assigned CVE-2026-69414 and confirmed a patch is in progress, but none has shipped.

    windowszero-dayprivilege-escalationlpemicrosoft
  • vulnerabilities 2026-08-18

    CVE-2026-65400: macOS Screen Sharing Auth Bypass Exploited for Root Access, Added to CISA KEV

    CISA added CVE-2026-65400, a pre-auth bypass in macOS Screen Sharing, to its KEV catalog after attackers used it to gain root on internet-exposed Macs and drop Monero miners; CVSS was raised to 9.8 following public PoC release.

    active-exploitationcisa-kevauthentication-bypassmacosprivilege-escalation
  • vulnerabilities 2026-08-18

    CVE-2025-62593: Browser-Based DNS Rebinding RCE in Ray Added to CISA KEV Amid ShadowRay 2.0 Exploitation

    CISA has added CVE-2025-62593, a critical DNS-rebinding RCE in the Ray AI compute framework, to its KEV catalog after RondoDox botnet operators weaponized it and ShadowRay 2.0 continued hijacking exposed clusters for GPU cryptomining.

    active-exploitationcisa-kevrcecloudauthentication-bypasskubernetes
  • vulnerabilities 2026-08-17

    SharePoint JWT Bypass (CVE-2026-55040) Chains With BCS Gadget Chain (CVE-2026-63520) for Unauthenticated RCE

    A JWT validation bypass under active exploitation since mid-August now chains with a newly disclosed Business Connectivity Services gadget chain, giving unauthenticated attackers full RCE on on-prem SharePoint farms.

    active-exploitationrceauthentication-bypassmicrosoftzero-day
  • vulnerabilities 2026-08-17

    Evooo1Bot: New Mirai-Derived Linux Botnet Chains Eight CVEs Spanning 2007–2025 Against Routers and Edge Devices

    Evooo1Bot, a modular Mirai-derived Linux botnet tracked by FortiGuard Labs, exploits eight known CVEs dating back to 2007 across routers, firewalls, and industrial gateways to build a SOCKS5 proxy and DDoS network.

    botnetnetwork-applianceactive-exploitationlinuxcommand-injection
  • vulnerabilities 2026-08-16

    Supply Chain Security Vendor RapidFort Allegedly Breached in CanisterWorm Fallout — 569GB of Customer Pipeline Data Listed for Sale

    A threat actor claims to be selling 569GB of RapidFort's internal pipeline data — including customer cross-account IAM templates, kubeconfigs, and plaintext AWS credentials — allegedly extracted during the March 2026 CanisterWorm/TeamPCP campaign.

    supply-chainci-cdcredential-theftdata-breachteampcpcloud
  • deep dive 2026-08-16 10 min read

    The Modem Nobody Audited: Inside the 2026 Water Utility PLC Attacks

    Thirty-plus Minnesota water utilities lost control of their PLCs in a single weekend, and the entry point wasn't the internet-facing HMI everyone scans for — it was a cellular modem nobody put on the asset inventory. A look at what CyberAv3ngers actually did, why a 2021 CVE is still unpatched, and why 'get it off the internet' misses the real exposure.

    icsotcritical-infrastructurevulnerability-managementtrend-analysiscisa-kev
  • vulnerabilities 2026-08-15

    CVE-2026-58231: Max-Severity Unauth RCE in SAP Commerce Cloud Now Under Active Exploitation

    CVE-2026-58231, a CVSS 10.0 flaw in SAP Commerce Cloud's Data Hub Adapter, lets unauthenticated attackers execute arbitrary code via a default authentication client. Exploitation attempts began August 14, three days after SAP shipped a patch.

    active-exploitationrceauthentication-bypasscloudsupply-chain
  • vulnerabilities 2026-08-14

    Critical Use-After-Free in Microsoft QUIC Allows Unauthenticated RCE (CVE-2026-62815)

    CVE-2026-62815, a CVSS 9.8 use-after-free in Microsoft's QUIC/HTTP-3 implementation, lets an unauthenticated remote attacker execute code with a single crafted packet — no user interaction required.

    rcewindowszero-daycloudpatch-tuesdaymicrosoft
  • vulnerabilities 2026-08-14

    Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE

    An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.

    zero-dayactive-exploitationrceauthentication-bypasscloudnetwork-appliance
  • vulnerabilities 2026-08-13

    Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws

    CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.

    rcewindowsnetwork-appliancecisa-kevzero-day
  • vulnerabilities 2026-08-13

    CopyEscape (CVE-2026-17106): A Malicious Container Can Overwrite Files on the Docker Host via `docker cp`

    CVE-2026-17106 ('CopyEscape'), found by Imperva's Red Team, lets a malicious or compromised container hijack docker cp to overwrite arbitrary files on the host — and, when the copy runs with elevated privileges, replace runc to get root. Docker has shipped fixes across Engine, Desktop, and Sandboxes.

    container-escaperceprivilege-escalationcloudlinux
  • vulnerabilities 2026-08-12

    Cisco ASA and FTD Under Active Attack: Unauthenticated VPN Flaw Reloads Firewalls On Demand (CVE-2026-20349)

    CVE-2026-20349, an unauthenticated heap inspection flaw in Cisco ASA and FTD's Remote Access SSL VPN service, is being actively exploited to remotely crash firewalls — CISA gave federal agencies until August 14 to patch, and no workaround exists.

    active-exploitationcisa-kevnetwork-appliancevpndenial-of-service
  • vulnerabilities 2026-08-12

    Lazarus Burned a Windows Kernel Zero-Day to Deploy FudModule Before Patch Tuesday Shipped

    CVE-2026-68820, a use-after-free in the Windows AFD.sys WinSock driver, was exploited by North Korea's Lazarus group to deploy an upgraded FudModule rootkit weeks before Microsoft's August Patch Tuesday fix shipped.

    active-exploitationzero-dayprivilege-escalationwindowsapt
  • vulnerabilities 2026-08-11

    BdThemes Supply Chain Attack: Poisoned JSON Feed Creates Rogue WordPress Admins Without Touching a Single Plugin File

    Attackers compromised BdThemes' vendor infrastructure and poisoned a promotional-banner JSON feed served to 100,000+ WordPress sites, hijacking admin sessions to plant rogue accounts and a persistent webshell — no plugin update required.

    supply-chainwordpressbackdoorcredential-theftxss
  • deep dive 2026-08-11 12 min read

    Inside the AI-Orchestrated EDR Evasion Lab: What Sophos Actually Found, and Why the Bug Wasn't in the Malware

    Sophos recovered a fully autonomous malware R&D pipeline — a coordinator agent, four subordinate agents, a self-provisioned lab, and 80 evasion modules built against three EDR vendors. The interesting part isn't that it worked. It's the one thing in the whole pipeline that didn't.

    ransomwareedr-evasionai-infrastructurecobalt-strikedetection-engineeringtrend-analysis
  • vulnerabilities 2026-08-11

    First-of-Its-Kind Attack Pivots Through a Private Cellular APN to Sabotage Siemens PLCs at a Polish Power Plant

    CERT Polska details a December 2025 attack that pivoted through a distribution operator's private cellular APN — from a compromised wind farm firewall to Siemens PLCs at a combined heat and power plant, halting a turbine.

    icsot-securityscadacritical-infrastructurenetwork-applianceactive-exploitation
  • vulnerabilities 2026-08-10

    Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph

    Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.

    active-exploitationsupply-chainbackdoorprivilege-escalationwindowsapt
  • vulnerabilities 2026-08-10

    Langflow's Third KEV Entry of the Year: CVE-2026-9198 Chains Auto-Login Bypass to Unauthenticated RCE

    CVE-2026-9198 chains an unauthenticated auto-login token mint with an unsandboxed code-validation endpoint to give attackers full RCE on default IBM Langflow deployments, now under active exploitation and CISA KEV.

    cisa-kevactive-exploitationrceai-infrastructureauthentication-bypass
  • vulnerabilities 2026-08-09

    XSS2Shell: WordPress Pre-Auth Login XSS Chains to Full RCE (CVE-2026-64638)

    CVE-2026-64638 lets an unauthenticated attacker plant XSS on WordPress's login screen with a single failed-login attempt, then chain DOM clobbering and a REST API JSONP callback to steal an admin's Application Password and execute PHP. Patch to 7.0.3.

    rceauthentication-bypasscmszero-day
← newer12345678910111213141516171819older →
© 2026 Max Clinton rss