cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-07-01

    GuardFall: Decades-Old Bash Quoting Tricks Defeat Safety Guards in 10 of 11 Open-Source AI Coding Agents

    Adversa AI's GuardFall research shows that quote removal, $IFS spacing, command substitution, and other decades-old shell tricks bypass the command guards in opencode, Goose, Cline, Aider, and seven other open-source AI coding agents β€” turning a poisoned README into silent credential theft.

    supply-chaincommand-injectionci-cdai-infrastructurecredential-theft
  • vulnerabilities 2026-06-30

    Oracle E-Business Suite Payments Flaw Under Active Exploitation Before Patch Window Closed

    CVE-2026-46817, a CVSS 9.8 unauthenticated takeover flaw in Oracle E-Business Suite's Payments module, is being mass-exploited via the ibytransmit endpoint β€” patched in May but hit in the wild before any public PoC existed.

    active-exploitationrceauthentication-bypasscloudapt
  • vulnerabilities 2026-06-30

    Public PoC Drops for Critical libssh2 Heap Overflow β€” curl, Git, and PHP All Carry the Flaw

    A public PoC was released June 29 for CVE-2026-55200, a CVSS 9.2 heap overflow in libssh2 ≀ 1.11.1 that lets a malicious SSH server execute code on any connecting client. curl, Git, PHP, and a long tail of appliances all link the library.

    rcelinuxsshcurlgit
  • vulnerabilities 2026-06-29

    Ubiquiti UniFi OS Server Triple-CVE Chain Enables Unauthenticated Root RCE

    Three max-severity CVEs (2026-34908/09/10) in UniFi OS Server chain from an Nginx auth bypass to root command injection β€” CISA added all three to KEV on June 23 amid Mirai/Gaafgyt botnet exploitation.

    active-exploitationcisa-kevrcecommand-injectionauthentication-bypassnetwork-appliance
  • vulnerabilities 2026-06-29

    Squidbleed: 29-Year-Old Heap Over-Read in Squid Proxy Leaks Cleartext HTTP Traffic (CVE-2026-47729)

    A Heartbleed-style heap buffer over-read in Squid's FTP gateway, tracing to a 1997 commit, lets trusted proxy users drain other users' cleartext HTTP requests including credentials, cookies, and session tokens.

    linuxnetwork-appliancezero-dayinformation-disclosureproxy
  • vulnerabilities 2026-06-28

    CVE-2026-12569: PTC Windchill/FlexPLM Deserialization RCE Exploited in Wild, CISA Deadline Today

    A critical unauthenticated deserialization RCE in PTC Windchill and FlexPLM (CVE-2026-12569, CVSS 9.3) is being actively exploited with JSP web shells; CISA federal patch deadline is today.

    rcedeserializationactive-exploitationcisa-kevics
  • deep dive 2026-06-28 13 min read

    Your Backup Server Is a Domain-Admin Factory: The Kill Chain Ransomware Operators Have Automated

    The backup server is the highest-privilege machine in most environments and the least-hardened. Ransomware operators have known this for years and built repeatable kill chains around it. This is how they work and what it takes to stop them.

    ransomwarebackup-securityactive-directorycredential-theftinfrastructure-hardening
  • vulnerabilities 2026-06-28

    DirtyClone: Linux Kernel LPE via Cloned sk_buff Gives Any Local User Root (CVE-2026-43503)

    JFrog releases a working exploit for DirtyClone, a Linux kernel socket-buffer cloning flaw that silently rewrites in-memory setuid binaries and grants rootβ€”with container escape potential on cloud and Kubernetes hosts.

    linuxlinux-kernelprivilege-escalationcontainer-escapekubernetescloud
  • vulnerabilities 2026-06-27

    Linux Kernel CVE-2026-46331: Pedit COW Traffic-Control Bug Delivers Root Shell, Ubuntu Still Unpatched

    A weaponized PoC for CVE-2026-46331 (Pedit COW) corrupts the kernel page cache via act_pedit to drop a root shell; Ubuntu 18.04–26.04 remain unpatched.

    linux-kernellinuxprivilege-escalationcloudkubernetes
  • vulnerabilities 2026-06-23

    Arista EOS CVE-2026-7473: Tunnel Decap Flaw Bypasses Segmentation β€” and Arista Won't Patch It

    CVE-2026-7473 lets an unauthenticated attacker push arbitrary tunneled traffic through Arista data-center switches that decapsulate it without checking the protocol. Exploited in the wild, on CISA's KEV list with a deadline of today β€” and Arista has confirmed no patch is coming.

    aristanetwork-appliancezero-dayactive-exploitationcisa-kev
  • threat-intelligence 2026-06-22

    AryStinger Turns 4,300 End-of-Life Routers Into a Reconnaissance Proxy Network

    QiAnXin XLab's AryStinger has hijacked 4,300+ legacy Realtek RTL819X routers β€” mostly D-Link DIR-850L β€” into a pre-intrusion recon and proxy mesh using decade-old CVEs.

    botnet
  • supply-chain 2026-06-21

    OptinMonster CDN Supply-Chain Attack: Tampered SDK Backdoors WordPress Admins

    Attackers stole an Awesome Motive CDN key and laced the OptinMonster, TrustPulse, and PushEngage SDKs with code that creates rogue admins and plants a web shell β€” on up to 1.2M fully-patched sites.

    supply-chainwordpressbackdoorcredential-theft
  • Supply Chain 2026-06-21

    Klue OAuth Breach Feeds 'Icarus' Salesforce Data-Theft Spree

    A dormant legacy credential at market-intelligence vendor Klue let the new Icarus extortion crew steal customer OAuth tokens and bulk-export Salesforce CRM data from Huntress, Recorded Future, Tanium, Jamf, and more.

    oauthsalesforcesupply-chaindata-breachextortion
  • deep dive 2026-06-21 12 min read

    One Symlink From Host Root: The runC maskedPaths Escapes and the Myth of the Container Boundary

    Three runC CVEs disclosed in November 2025 turned container escape back into a /dev/null symlink race β€” and one of them walks straight through AppArmor and SELinux. Here is how the maskedPaths breakout works, why seccomp and user namespaces are the layers that actually held, and what to change before the next runtime CVE.

    container-escapekuberneteslinux
  • vulnerabilities 2026-06-20

    Gravity SMTP CVE-2026-4020: Unauthenticated Flaw Leaks Cloud Email API Keys Amid Mass Exploitation

    Attackers are mass-exploiting CVE-2026-4020 in the Gravity SMTP WordPress plugin to dump site config and third-party email provider API keys. Patch to 2.1.5 and rotate every key now.

    wordpress
  • vulnerabilities 2026-06-20

    A Zero-Length Compare and 27 Years: OpenBSD's PAP Authentication Bypass (CVE-2026-55706)

    CVE-2026-55706 is a 27-year-old authentication bypass in OpenBSD's sppp(4) PAP handler. An attacker-controlled compare length means empty credentials produce a PAP_ACK β€” and an oversized one leaks kernel heap. Full details and a working PoC are public.

    authentication-bypass
  • vulnerabilities 2026-06-19

    Two Critical NGINX Flaws Put HTTP/3 and gRPC Proxying One Bug Away From Unauthenticated RCE

    F5 patched CVE-2026-42530 and CVE-2026-42055, two CVSS 9.2 unauthenticated memory-corruption bugs in NGINX's HTTP/3 and HTTP/2 paths. Both reach RCE where ASLR can be bypassed, and both touch NGINX Ingress Controller and Gateway Fabric.

    nginxrcehttp2grpcf5kubernetes
  • breach 2026-06-19

    FortiBleed: Cracked Admin Credentials Leak for 73,932 Internet-Facing FortiGate Firewalls

    A Russian-speaking crew cracked weak legacy FortiOS password hashes to harvest working admin and SSL VPN credentials for 73,932 FortiGate firewalls β€” roughly half the internet-facing fleet across 194 countries. Assume compromise and rotate now.

    fortinetinfrastructure
  • vulnerability 2026-06-18

    LiteSpeed cPanel Plugin CVE-2026-54420: A Symlink Trick That Escapes CageFS for Root

    An actively-exploited symlink flaw in LiteSpeed's user-end cPanel plugin lets any tenant with FTP or web-shell access break out of CageFS and become root. CISA's federal patch deadline is today.

    cpanelprivilege-escalationcisa-kevshared-hosting
  • vulnerabilities 2026-06-18

    Pickle in the Middle: Vertex AI SDK Bucket-Squatting Bug Enabled Cross-Tenant RCE

    Unit 42's 'Pickle in the Middle' shows how a predictable staging-bucket name in the Vertex AI Python SDK let an attacker hijack model uploads and run code cross-tenant. Patched in google-cloud-aiplatform 1.148.0.

    supply-chainrcecloud-security
← newer12345678910111213141516171819older →
© 2026 Max Clinton rss