cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • breach 2026-05-04

    Trellix Confirms Source Code Repository Breach: Security Vendor's Internal Code Accessed by Unknown Attackers

    Trellix confirms unauthorized access to a portion of its internal source code repository, with forensic experts and law enforcement engaged. The blast radius for a security vendor going public with a code breach is its customer base — every defender running its EDR agents.

    breachincident-response
  • malware 2026-05-03

    DEEP#DOOR: Python Backdoor Hides C2 Behind bore.pub Tunneling Service to Steal Cloud and Browser Credentials

    Securonix details DEEP#DOOR, a Python backdoor that uses the public bore.pub TCP tunneling service for C2, disables Defender/SmartScreen via batch loader, and harvests browser-stored cloud credentials from compromised hosts.

    backdoorcredential-theftpythonwindowscloud-security
  • vulnerabilities 2026-05-03

    Exim 4.99.2 Patches Four Mail Server Flaws: Heap Corruption via JSON Headers, DNS Poisoning, and SPA Auth Bugs

    Exim 4.99.2 fixes four memory-safety bugs (CVE-2026-40684 through 40687) in the world's most-deployed MTA, including a JSON heap-write reachable from untrusted headers.

    cvelinux
  • deep dive 2026-05-03 12 min read

    The OAuth Pivot: How SaaS-to-SaaS Trust Became the 2026 Supply Chain Attack

    Salesloft Drift industrialized it. UNC6040 weaponized vishing into it. Vercel and Context.ai proved it pivots through Google Workspace. The pattern is the same: a third-party SaaS gets popped, the attacker inherits its OAuth grants, and your password reset does absolutely nothing.

    oauthsalesforceshinyhuntersopinion
  • breach 2026-05-02

    Trellix Confirms Source Code Repository Breach as XDR Vendor Becomes the Target

    Trellix has confirmed unauthorized access to a portion of its internal source code repository, putting one of the industry's largest XDR vendors in the unenviable position of being the breached defender.

    endpoint-securitysupply-chainbreach
  • vulnerabilities 2026-05-02

    SimpleHelp Trio Hits CISA KEV as DragonForce Ransomware Tears Through MSP Fleets

    CISA dragged three SimpleHelp RMM bugs into the KEV catalog with a May 8 federal deadline after DragonForce operators chained them to push ransomware across MSP customer fleets in a single shot.

    ransomwarecisa-kevsupply-chain
  • vulnerabilities 2026-05-01

    Windows Shell CVE-2026-32202: Incomplete APT28 Patch Reopens Zero-Click NTLM Coercion

    Microsoft confirms in-the-wild exploitation of CVE-2026-32202, a zero-click Windows Shell flaw born from an incomplete patch of an APT28 zero-day. Browsing a folder with a malicious LNK leaks Net-NTLMv2 hashes.

    windowscisa-kev
  • supply-chain 2026-05-01

    Mini Shai-Hulud: SAP, Intercom, and PyTorch Lightning Hit by Bun-Based Stealer in 48-Hour TeamPCP Cascade

    TeamPCP's Mini Shai-Hulud campaign poisoned SAP CAP, Intercom, and PyTorch Lightning packages on April 29-30 with a Bun-runtime credential stealer that scrapes secrets directly from CI runner memory.

    supply-chainnpmpypiteampcpshai-huludcredential-theftci-cd
  • vulnerabilities 2026-04-30

    Copy Fail (CVE-2026-31431): A 732-Byte Python Script Roots Every Major Linux Distro Since 2017

    A nine-year-old logic bug in the kernel's algif_aead crypto interface lets an unprivileged user plant four bytes anywhere in the page cache — including inside a setuid binary's cached pages. Root in seconds, no on-disk artifacts, breaks containers.

    linux-kernelcopy-faillpeprivilege-escalationcontainer-escape
  • vulnerabilities 2026-04-30

    LiteLLM CVE-2026-42208: Pre-Auth SQLi in the AI Gateway, Exploited 36 Hours After Disclosure

    A pre-authentication SQL injection in LiteLLM's auth path (CVSS 9.3) lets an unauthenticated attacker read and modify the proxy database — including upstream OpenAI and Anthropic API keys. First exploitation hit 36 hours after the advisory.

    litellmsql-injectioncredential-theft
  • vulnerabilities 2026-04-29

    cPanel & WHM CVE-2026-41940: Critical Auth Bypass Triggers Global Hosting Lockdown

    An unauthenticated CRLF-injection auth bypass in cPanel & WHM (CVSS 9.8) sent every major hosting provider into emergency port-blocking mode within hours of disclosure. All supported release tracks are affected.

    cpanelauthentication-bypassshared-hosting
  • Vulnerabilities 2026-04-29

    CVE-2026-3854: A Single Git Push Owned GitHub.com — and 88% of Enterprise Servers Were Still Vulnerable at Disclosure

    Wiz disclosed a CVSS 8.7 RCE in GitHub's internal git push pipeline. Any authenticated user could execute arbitrary commands on backend servers with one git push. 88% of Enterprise Server instances were still unpatched on disclosure day.

    rcecommand-injectionci-cd
  • vulnerability 2026-04-28

    CrowdStrike LogScale CVE-2026-40050: Unauthenticated Path Traversal Reads Arbitrary Server Files

    A critical 9.8 CVSS path traversal in CrowdStrike's LogScale lets unauthenticated attackers read arbitrary files from self-hosted clusters. Patch to 1.235.1, 1.234.1, 1.233.1, or 1.228.2 LTS.

    path-traversalsieminfrastructure
  • cloud-security 2026-04-28

    Entra Agent ID Administrator Role Could Hijack Any Service Principal — CVE-2026-35431

    A built-in Entra ID role meant to manage AI agents could be used to take ownership of any service principal in the tenant — including Global Administrator-equivalent ones — and authenticate as it. Microsoft patched cloud-side on April 9; Silverfort published technical details April 27.

    azureprivilege-escalation
  • vulnerability 2026-04-27

    CrowdStrike LogScale CVE-2026-40050: Unauthenticated Path Traversal Reads Arbitrary Files (CVSS 9.8)

    A critical unauthenticated path-traversal flaw (CVSS 9.8) in CrowdStrike LogScale Self-Hosted lets remote attackers read arbitrary server files via an exposed cluster API endpoint. SaaS already mitigated; on-prem operators must patch immediately.

    path-traversalsiemself-hosted
  • Incidents 2026-04-27

    Itron Discloses Internal Network Breach: Smart Meter and Grid Software Vendor Reports Unauthorized System Access

    Itron, a major U.S. supplier of smart metering and grid management software for electricity, water, and gas utilities, disclosed in an SEC 8-K filing that an unauthorized third party gained access to its internal IT network on April 13, 2026.

    critical-infrastructuresupply-chainbreach
  • vulnerability 2026-04-26

    PhantomRPC: Five Endpoint-Spoofing Paths to SYSTEM on Every Windows Build, No Patch Coming

    Kaspersky disclosed PhantomRPC at Black Hat Asia 2026 — an architectural flaw in rpcrt4.dll that lets a low-priv process register a rogue RPC endpoint and hijack SYSTEM-level callers. Microsoft declined to patch.

    windowsprivilege-escalationlpe
  • vulnerabilities 2026-04-26

    LMDeploy CVE-2026-33626: SSRF in LLM Inference Server Exploited 12 Hours After Disclosure, Honeypot Sees AWS IMDS Theft

    A 7.5-severity SSRF in Shanghai AI Lab's LMDeploy LLM serving toolkit was hit in the wild within 12h31m of the GitHub advisory. Sysdig's honeypot caught an attacker using the vision-language image loader to scrape AWS instance metadata, then pivot to internal Redis and MySQL.

    ssrfai-infrastructureawsimdsllmcloud-security
  • deep dive 2026-04-26 15 min read

    The Controller Token Leak Epidemic: Kubernetes Has a Confused-Deputy Problem

    Six CVEs in three months, four against a single Kyverno feature, plus OpenShift AI and Argo CD: every modern Kubernetes platform is shipping helper code that hands its controller's bearer token to attacker-controlled URLs. The bug class isn't going to fix itself.

    kubernetesssrfopinion
  • vulnerability 2026-04-25

    Clerk CVE-2026-41248: createRouteMatcher Bypass Skips Middleware Gating Across Next.js, Nuxt, and Astro

    Crafted requests slip past createRouteMatcher in @clerk/nextjs, @clerk/nuxt, and @clerk/astro, bypassing middleware-level route protection. Patches landed across three major version branches per SDK on April 24.

← newer1234567891011older →
© 2026 Max Clinton rss