cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • threat-intelligence 2026-04-08

    APT28's FrostArmada Hijacked 18,000 SOHO Routers to Steal Microsoft 365 Credentials β€” FBI Disrupts Operation

    Russia-linked APT28 compromised 18,000 MikroTik and TP-Link routers across 120 countries to hijack DNS and steal Microsoft 365 OAuth tokens. FBI disrupts the operation.

    oauthfbi
  • Vulnerabilities 2026-04-08

    BlueHammer: Unpatched Windows Defender Zero-Day Turns Definition Updates Into SYSTEM Shells

    A disgruntled researcher leaked BlueHammer, a Windows Defender LPE zero-day that chains TOCTOU race conditions with Cloud Files oplocks to dump SAM hives and escalate to SYSTEM. No patch available.

    windowszero-dayprivilege-escalation
  • Attacks 2026-04-07

    Over 1,000 Exposed ComfyUI Instances Hijacked for Cryptomining and Proxy Botnet

    Active campaign targets unauthenticated ComfyUI deployments across cloud providers, enlisting them into Monero mining and a Hysteria V2 proxy botnet via malicious custom nodes.

    botnetai-infrastructure
  • vulnerabilities 2026-04-07

    Docker AuthZ Bypass Returns: CVE-2026-34040 Lets Attackers Create Privileged Containers With a Single Padded Request

    An incomplete fix for a 2024 Docker AuthZ bypass has resurfaced as CVE-2026-34040, allowing unauthenticated container creation with host filesystem access via oversized HTTP requests.

    cveprivilege-escalation
  • vulnerability 2026-04-07

    Three High-Severity Command Injection Flaws in AWS Research and Engineering Studio Give Authenticated Users Root RCE

    AWS patches three CVSS 8.8 command injection and privilege escalation bugs in Research and Engineering Studio (RES) β€” any authenticated user could get root on virtual desktop hosts or the cluster manager.

    awscloudcommand-injectionrceprivilege-escalation
  • Vulnerabilities 2026-04-07

    Flowise AI Under Active Exploitation: CVSS 10.0 RCE via CustomMCP Node Hits 12,000+ Exposed Instances

    Critical unauthenticated RCE in Flowise AI's CustomMCP node (CVE-2025-59528, CVSS 10.0) is under active exploitation. Over 12,000 instances are exposed. Patch to 3.0.6 immediately.

    rceai-infrastructuremcp
  • threat-intelligence 2026-04-07

    Storm-1175 Chains Zero-Days to Deploy Medusa Ransomware in Under 24 Hours

    Microsoft exposes Storm-1175 as a primary Medusa ransomware affiliate, weaponizing zero-days in SmarterMail and GoAnywhere MFT with sub-24-hour dwell times.

    ransomwarezero-dayapt
  • Threat Intelligence 2026-04-06

    Akira Ransomware Now Encrypts in Under an Hour: SonicWall VPNs Are the Front Door

    Akira ransomware operators are completing full attack chains from initial VPN access to encryption in under 60 minutes, targeting SonicWall SSL VPNs even on patched devices.

    ransomwarevpnincident-response
  • vulnerabilities 2026-04-06

    CVE-2026-23442: Remote Kernel Panic via SRv6 NULL Pointer Dereference Threatens IPv6 Infrastructure

    A CVSS 8.2 flaw in the Linux kernel's SRv6 implementation lets remote attackers crash systems with crafted IPv6 packets. Patches are outβ€”update now.

    linux-kernelcvedenial-of-service
  • vulnerabilities 2026-04-06

    CVE-2026-34612: Kestra SQL Injection Chains to Host RCE via PostgreSQL COPY TO PROGRAM

    Critical CVSS 9.9 flaw in Kestra orchestration platform lets authenticated attackers chain SQL injection through PostgreSQL COPY TO PROGRAM for arbitrary command execution on the Docker host.

    cvesql-injectionrcecontainer-escapepostgresql
  • Vulnerabilities 2026-04-06

    CVE-2026-32211: Azure MCP Server Ships with No Auth β€” Your DevOps Secrets Are One Request Away

    Critical CVSS 9.1 flaw in Azure MCP Server has zero authentication on critical functions, exposing API keys, tokens, repos, and pipeline configs to unauthenticated attackers. No patch available.

    azuremcpmicrosoftci-cd
  • vulnerabilities 2026-04-06

    Ubiquiti UniFi Network Application Hit With CVSS 10 Path Traversal β€” Unauthenticated Account Takeover Possible

    CVE-2026-22557 is a maximum-severity path traversal in Ubiquiti UniFi Network Application that enables unauthenticated full account takeover. Chain it with CVE-2026-22558 for admin escalation. Patch to 10.1.89 immediately.

    path-traversal
  • Threats 2026-04-05

    Device Code Phishing Attacks Surge 37x as EvilTokens PhaaS Fuels OAuth Abuse Against Microsoft 365

    Device code phishing attacks exploiting the OAuth 2.0 Device Authorization Grant have surged 37x in 2026, driven by turnkey PhaaS kits like EvilTokens that bypass MFA and compromise enterprise M365 tenants.

    oauth
  • vulnerabilities 2026-04-05

    CVE-2026-4681: CVSS 10.0 Deserialization RCE in PTC Windchill Has German Police Knocking on Doors

    A maximum-severity deserialization flaw in PTC Windchill and FlexPLM (CVE-2026-4681, CVSS 10.0) prompted German federal police to physically visit companies and wake up sysadmins. No patch yet. Here's what you need to know.

    deserializationrceicscisa
  • Supply Chain 2026-04-05

    36 Malicious npm Packages Disguised as Strapi Plugins Deploy Redis Exploits, PostgreSQL Credential Harvesting, and Persistent Implants

    A coordinated campaign planted 36 fake Strapi CMS plugins on npm that exploit Redis and PostgreSQL instances, harvest credentials, and install persistent C2 implants targeting production infrastructure.

    supply-chainnpmpostgresqlc2
  • deep dive 2026-04-05 9 min read

    Severity Drift: Why Your Vulnerability Triage Process Is Working With Bad Data

    From silent reclassifications to incomplete patches to NVD enrichment backlogs, the severity data your vuln management program depends on is wrong more often than you think. Here's the proof β€” and what to do about it.

    vulnerability-managementcisa-kevf5ciscolangflowopinion
  • vulnerabilities 2026-04-05

    CVE-2026-33032: Nginx UI MCP Endpoint Lets Anyone Hijack Your Web Server β€” No Auth Required

    Critical 9.8 CVSS flaw in Nginx UI exposes unauthenticated MCP endpoint. Public PoC available, no patch yet. Disable or firewall Nginx UI immediately.

    nginxmcpauthentication-bypasszero-daycve
  • Incidents 2026-04-05

    $285M Gone in 12 Minutes: DPRK-Linked Attackers Weaponize Solana Durable Nonces to Gut Drift Protocol

    North Korean threat actors drained $285M from Solana's largest perpetual futures exchange by weaponizing durable nonces, fabricating a fake token, and socially engineering governance multisig signers.

    social-engineering
  • incidents 2026-04-04

    Ransomware Hits Minot Water Treatment Plant SCADA System, FBI Investigating

    Ransomware compromised the SCADA server at Minot, North Dakota's water treatment plant, forcing 16 hours of manual operations. FBI released a statement today confirming active investigation.

    ransomwarescadaicscritical-infrastructureot-security
  • vulnerabilities 2026-04-04

    FortiClient EMS Zero-Day Under Active Exploitation β€” Emergency Hotfixes Released (CVE-2026-35616)

    Critical API authentication bypass in FortiClient EMS 7.4.5–7.4.6 is being exploited in the wild. CVSS 9.1. Hotfixes available now.

    fortinetzero-day
← newer1234567891011older →
© 2026 Max Clinton rss