cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-08-09

    Jenkins CVE-2026-70426: Remoting Deserialization Filter Bypass Enables Controller RCE

    CVE-2026-70426 (CVSS 9.0) lets an attacker with agent-level access bypass Jenkins' JEP-200 class filter via a fallback path in Remoting, achieving code execution on the controller. Patch to 2.576 / LTS 2.568.2 now.

    deserializationrceci-cdsupply-chain
  • vulnerabilities 2026-08-08

    Microsoft Patches Four CVSS 9.9 Flaws Spanning Azure Service Bus, Azure SRE Agent, Entra Provisioning, and Active Directory

    Microsoft quietly shipped fixes for four unrelated CVSS 9.9 flaws β€” an unauthenticated-adjacent RCE in Azure Service Bus and privilege-escalation bugs in Azure SRE Agent, Entra Provisioning Service, and on-prem Active Directory β€” all remotely exploitable and disclosed August 6.

    azureactive-directoryprivilege-escalationrceclouddeserialization
  • vulnerabilities 2026-08-08

    SCTPhantom (CVE-2026-64564): An 18-Year-Old Linux Kernel SCTP Bug Gives Local Root and Escapes Containers

    A use-after-free in the Linux kernel's SCTP ASCONF transport handling, present since 2008, lets a local attacker with SCTP reachability escalate to root and, on affected configurations, escape containers.

    linux-kernelprivilege-escalationuse-after-freecontainer-escapezero-daylinux
  • vulnerabilities 2026-08-07

    Metabase Zero-Day: Unauthenticated SQL Injection (CVSS 10.0) Exploited to Breach Framework and Tally

    A pre-auth SQL injection in Metabase's password-reset endpoint let attackers hijack admin access on customer instances, hitting Metabase Cloud tenants Framework and Tally before a patch shipped.

    active-exploitationsql-injectionauthentication-bypassdata-breachcloudsupply-chain
  • vulnerabilities 2026-08-07 High

    CVE-2026-34486: Apache Tomcat's EncryptInterceptor Fix Was Incomplete β€” Now Under Active Exploitation

    A second, incomplete patch for a Tomcat clustering flaw lets attackers bypass pre-shared-key encryption and reach Java deserialization on the cluster port β€” CISA gave federal agencies until today to fix it.

    rceactive-exploitationcisa-kevaptjava-deserializationnetwork-appliance
  • vulnerabilities 2026-08-06

    OVSwrap (CVE-2026-64531): 13-Year-Old Linux Kernel Bug in Open vSwitch Gives Any Local User Root

    A 16-bit integer wraparound in the Linux kernel's Open vSwitch action parser (CVE-2026-64531, 'OVSwrap') lets any unprivileged local user become root β€” no OVS configuration, no CAP_NET_ADMIN, no container privileges required. A public PoC ships precomputed offsets for ~800 kernel builds.

    privilege-escalationlinux-kernellinuxcloudkubernetes
  • vulnerabilities 2026-08-06

    15 TP-Link Omada Flaws Turn Zero-Touch Provisioning Into a Network Takeover Path

    Forescout's Vedere Labs found 15 flaws in TP-Link's Omada zero-touch provisioning ecosystem β€” hardcoded crypto keys, a predictable RC4 cipher, and weak cert validation that chain into full controller and fleet compromise.

    network-applianceauthentication-bypassman-in-the-middleiotcloud
  • vulnerabilities 2026-08-05

    Cisco Ships Two CVSS 9.8+ 'Hardening Releases' for IOS XE and Catalyst SD-WAN in One Day

    Cisco's August 5 disclosure batch bundles seven CWE-grouped IOS XE flaws (CVSS 9.8) and five Catalyst SD-WAN flaws (CVSS 9.9) into umbrella CVEs β€” the first big test of its new AI-driven, twice-monthly hardening-release disclosure model.

    cisconetwork-applianceprivilege-escalationsd-wanlinux
  • vulnerabilities 2026-08-05

    QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor

    A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.

    supply-chainaptvpnbackdoormalwarewindows
  • vulnerabilities 2026-08-04

    Keyv npm Worm Hits 800+ Packages, Pulls C2 From an Ethereum Smart Contract

    A compromised [email protected] release triggered a self-propagating npm worm that poisoned 800+ packages in hours, planting Claude Code and VS Code persistence hooks and fetching C2 addresses via live Ethereum smart-contract calls.

    supply-chainnpmshai-huludcredential-theftci-cdinstall-time-execution
  • vulnerabilities 2026-08-04

    ExfilSquad's Power Pages Rampage Hits UK Police Legal Database, 14 Other Victims

    A new extortion group, ExfilSquad, is scraping data straight out of misconfigured Microsoft Power Pages portals with no exploit required β€” its highest-profile victim so far is the UK's Police National Legal Database, exposing contact data for 135,000 officers and justice staff.

    cloudmisconfigurationdata-breachextortiongovernment
  • vulnerabilities 2026-08-03

    N-able's First Patch Didn't Hold: CVE-2026-18577 Bypasses the CVE-2026-18556 Fix for Full N-central Takeover

    N-able's emergency fix for an N-central authentication bypass proved incomplete β€” a new CVE, CVE-2026-18577, lets attackers bypass the patch entirely for unauthenticated 'god-mode' access, and it's being actively exploited against MSPs.

    active-exploitationauthentication-bypassnetwork-appliancecloudprivilege-escalation
  • vulnerabilities 2026-08-03

    Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)

    Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi β€” no workarounds exist for either critical vCenter bug.

    cloudauthentication-bypassrcecontainer-escapenetwork-appliance
  • vulnerabilities 2026-08-02

    N-able N-central Authentication Bypass (CVE-2026-18556) Exploited to Hijack Managed Endpoints via Take Control and Cloudflare Tunnels

    An authentication bypass in N-able's N-central RMM platform, tracked as CVE-2026-18556, was exploited in the wild to gain admin access and pivot into managed customer environments using Take Control and rogue Cloudflare tunnels.

    active-exploitationauthentication-bypassnetwork-applianceremote-monitoringcloud
  • deep dive 2026-08-02 11 min read

    The Tenant Boundary Is a Fiction: Inside 2026's Cloud Cross-Tenant Bug Class

    Five major cross-tenant breaks in twelve months β€” Cosmos DB, Vertex AI, Entra ID, AKS Backup β€” share one root cause: a privileged control-plane identity that trusts a customer-supplied name, key, or token it should never have accepted. Here's the pattern, and what to actually do about it.

    cloudcloud-securitymulti-tenantauthentication-bypasstrend-analysisopinion
  • vulnerabilities 2026-08-02

    CosmosEscape: Gremlin Sandbox Escape Exposed a Master Key to Every Azure Cosmos DB Database

    Wiz Research chained a .NET reflection bypass in Cosmos DB's Gremlin API into code execution on Microsoft's multi-tenant gateway, recovering a platform-wide signing key that could pull the primary key for any customer's database.

    cloudcontainer-escapeauthentication-bypassmulti-tenant
  • vulnerabilities 2026-08-01

    Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses, Linked to a Midnight Blizzard Sub-Cluster

    Attackers compromised an Adform JavaScript library served across thousands of customer sites, silently swapping copied crypto wallet addresses in an operation researchers track as CaptiveCrunch and attribute to a Midnight Blizzard (APT29) sub-cluster.

    supply-chainaptcryptocurrencymalwareweb-security
  • vulnerabilities 2026-08-01

    OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks

    Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.

    aptbackdoorespionagemalwarewindows
  • vulnerabilities 2026-07-31

    Rails CVE-2026-66066: Unauthenticated File Read via Active Storage Image Uploads

    A critical 9.5 CVSS flaw in Rails Active Storage lets unauthenticated attackers read arbitrary files β€” secrets, credentials, master keys β€” from any app that processes untrusted image uploads with libvips. Patch to 7.2.3.2, 8.0.5.1, or 8.1.3.1.

    rcesupply-chainauthentication-bypasscloudlinux
  • vulnerabilities 2026-07-31

    Copilot for Word Can Be Turned Into a Self-Propagating AI Worm β€” No Comprehensive Fix After 144 Days

    Researcher HΓ₯kon MΓ₯lΓΈy's 'Context Collapse, Part 3' shows hidden document instructions can make Copilot for Word rewrite content and copy the payload into every new file it touches β€” and Microsoft's fixes, including a model upgrade to GPT-5.5, haven't closed the underlying attack class.

    prompt-injectionai-securitymicrosoftai-infrastructurecloud
← newer12345678910111213141516171819older →
© 2026 Max Clinton rss