cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • incidents 2026-04-15

    Ransomware Hits ChipSoft, the EHR Vendor Behind 80% of Dutch Hospitals

    A ransomware attack on Dutch EHR vendor ChipSoft has disrupted hospital systems nationwide and may have exposed millions of patient records.

    ransomwaresupply-chain
  • vulnerabilities 2026-04-15

    CVE-2026-21643: Pre-Auth SQL Injection in FortiClient EMS 7.4.4 Under Active Exploitation — CISA Deadline Tomorrow

    Critical pre-authentication SQL injection in Fortinet FortiClient EMS 7.4.4 is being actively exploited. CISA KEV remediation deadline is April 16, 2026.

    fortinetsql-injectioncisa-kevpre-authactive-exploitation
  • Vulnerability 2026-04-14

    Composer Command Injection (CVE-2026-40261, CVE-2026-40176): Any Malicious Repository Can Execute Code on Your Build Machines

    Two high-severity command injection flaws in PHP's Composer package manager allow arbitrary command execution via malicious repository metadata — no Perforce installation required for the worst one.

    supply-chaincommand-injectioncverce
  • vulnerabilities 2026-04-14

    Microsoft April 2026 Patch Tuesday Fixes 167 Flaws Including Actively Exploited SharePoint Zero-Day

    Microsoft's second-largest Patch Tuesday ever addresses 167 vulnerabilities, including an actively exploited SharePoint XSS flaw and a critical CVSS 9.8 Windows IKE remote code execution bug.

    microsoftpatch-tuesdayzero-daywindows
  • Vulnerability 2026-04-14

    CVE-2026-31414: Linux Kernel Netfilter Conntrack Flaw Enables Container Escape Privilege Escalation

    A use-after-free in Linux kernel netfilter connection tracking allows local privilege escalation from container workloads — patch your nodes now.

    linux-kernelprivilege-escalationkubernetes
  • vulnerabilities 2026-04-13

    Red Hat OpenShift AI Dashboard Leaks Kubernetes Service Account Tokens (CVE-2026-5483)

    A high-severity flaw in Red Hat OpenShift AI's odh-dashboard exposes Kubernetes Service Account tokens via a NodeJS endpoint, enabling unauthorized cluster access.

    kubernetes
  • Ransomware 2026-04-13

    Anubis Ransomware Gang Claims 2TB Exfiltration from Signature Healthcare as Brockton Hospital Diverts Ambulances

    Anubis RaaS group claims theft of 2TB of patient data from Signature Healthcare while Brockton Hospital diverts ambulances, cancels chemo, and operates on paper charts a week after the attack.

    ransomwaredata-breachincident-response
  • Vulnerabilities 2026-04-12

    Marimo CVE-2026-39987: Pre-Auth RCE Exploited Within 10 Hours of Disclosure

    A missing authentication check on Marimo's terminal WebSocket endpoint (CVE-2026-39987, CVSS 9.3) gave attackers a root shell with no credentials required — and they were actively exploiting it less than 10 hours after the advisory dropped.

    cvercepythoncredential-theftactive-exploitation
  • Vulnerability 2026-04-12

    Adobe Acrobat Reader Zero-Day CVE-2026-34621: Prototype Pollution RCE Exploited Since December

    Adobe patches APSB26-43 after confirming CVE-2026-34621, a CVSS 9.6 prototype pollution flaw in Acrobat Reader actively exploited via malicious PDFs since at least December 2025.

    rcezero-dayactive-exploitation
  • Supply Chain 2026-04-12

    CPUID Website Compromised to Deliver STX RAT via CPU-Z and HWMonitor Downloads

    Attackers compromised CPUID's download infrastructure for ~19 hours, replacing CPU-Z and HWMonitor installers with trojanized builds that sideload STX RAT via a malicious CRYPTBASE.dll.

    supply-chainratwindowsmalware
  • deep dive 2026-04-12 11 min read

    Self-Hosted and Unprotected: The AI Workflow Tool Security Crisis

    Langflow, Flowise, n8n, ComfyUI — every major self-hosted AI workflow tool has shipped unauthenticated RCE vulnerabilities in 2026. This isn't a coincidence. It's a structural failure baked into how these tools were designed.

    ai-infrastructurercelangflowmcpself-hostedcredential-theft
  • supply-chain 2026-04-10

    Smart Slider 3 Pro Update Infrastructure Compromised — Backdoored Build Pushed to 800K+ WordPress Sites

    Attackers compromised Nextend's update servers to distribute a weaponized Smart Slider 3 Pro build containing a multi-layered RAT with credential exfiltration and persistent backdoors.

    supply-chainwordpressbackdoorweb-security
  • Vulnerability 2026-04-10

    GPUBreach: GDDR6 Rowhammer Attack Achieves Root Shell, Bypasses IOMMU

    University of Toronto researchers demonstrate full CPU privilege escalation from an unprivileged CUDA kernel via GDDR6 bit-flips, bypassing IOMMU — no patch exists yet.

    privilege-escalationcloud
  • Vulnerability 2026-04-09

    Project Glasswing: Anthropic's Claude Mythos AI Autonomously Found Thousands of Zero-Days in Every Major OS and Browser

    Anthropic's Claude Mythos Preview autonomously discovered thousands of unpatched zero-days across FreeBSD, Linux, OpenBSD, FFmpeg, and every major browser — including a sandbox escape that emailed a researcher.

    zero-daylinux
  • vulnerabilities 2026-04-09

    Chrome 147 Patches 60 Security Flaws Including Two Critical WebML RCE Bugs

    Google ships Chrome 147.0.7727.55 with fixes for 60 vulnerabilities—two critical heap buffer overflow and integer overflow flaws in the WebML component enable remote code execution via crafted HTML pages.

    chromerceheap-overflowbrowser-security
  • Threat Intelligence 2026-04-09

    CISA AA26-097A: CyberAv3ngers Exploit Rockwell PLCs Across US Water, Energy, and Government Systems

    Six US agencies issue joint advisory after Iranian-affiliated CyberAv3ngers compromise Rockwell Allen-Bradley PLCs in water, energy, and government sectors, manipulating SCADA displays and control logic.

    icsot-securityirancisacritical-infrastructurescada
  • vulnerabilities 2026-04-09

    CVE-2026-39860: Nix Package Manager Symlink Bug Gives Any User Root on Multi-User Installs

    A critical symlink-following flaw in the Nix daemon lets unprivileged users overwrite arbitrary files as root during fixed-output derivation builds.

    privilege-escalationcvelinux
  • vulnerabilities 2026-04-09

    CVE-2026-32922: OpenClaw Privilege Escalation Lets Any Paired Device Achieve Full RCE

    A missing scope validation in OpenClaw's device.token.rotate endpoint lets any device with operator.pairing scope mint admin tokens and execute arbitrary code on connected nodes.

    cveprivilege-escalationrcecloud-security
  • vulnerabilities 2026-04-08

    CISA Adds Ivanti EPMM Zero-Days to KEV as Mass Exploitation Ramps Up

    CISA adds CVE-2026-1340 to the Known Exploited Vulnerabilities catalog as attackers chain two Ivanti EPMM zero-days for unauthenticated RCE against mobile device management infrastructure.

    ivantizero-daycisa-kevrce
  • Supply Chain 2026-04-08

    North Korea's Contagious Interview Campaign Hits 1,700 Malicious Packages Across Five Ecosystems

    DPRK-linked Contagious Interview operation now spans npm, PyPI, Go Modules, crates.io, and Packagist with 1,700+ poisoned packages delivering BeaverTail and InvisibleFerret malware.

    supply-chainnorth-koreanpmpypiaptmalware
← newer1234567891011older →
© 2026 Max Clinton rss