Infrastructure
HollowByte: An 11-Byte TLS Handshake Payload That Bloats OpenSSL Server Memory
A memory-allocation flaw in OpenSSL's TLS handshake parsing, dubbed HollowByte, lets an unauthenticated attacker exhaust server memory with an 11-byte payload per connection. No CVE was assigned; patched in 4.0.1 and backported across the 3.x line.
Progress Tells ShareFile Customers to Power Down Storage Zone Controllers Over 'Credible' Threat
Progress Software is telling on-prem ShareFile Storage Zone Controller admins to physically shut down their Windows servers over an unnamed 'credible external security threat' — no CVE, no patch, no explanation.
DHS Confirms Breach of HSIN, the Federal-State-Local Information-Sharing Backbone
DHS confirms an unattributed threat actor breached HSIN and a connected SharePoint environment used by fusion centers and law enforcement nationwide, with the intrusion window overlapping World Cup security planning.
The Login Path Is the Target: Inside the PAM/OpenSSH Backdoor Playbook Attackers Keep Reusing
Sygnia's Operation Highland found a China-nexus group living inside an air-gapped network for a decade by backdooring pam_unix.so and sshd. It's the same target the XZ Utils and Ebury campaigns went after — because the Linux authentication stack is the softest hard target in your fleet.
FortiBleed: Cracked Admin Credentials Leak for 73,932 Internet-Facing FortiGate Firewalls
A Russian-speaking crew cracked weak legacy FortiOS password hashes to harvest working admin and SSL VPN credentials for 73,932 FortiGate firewalls — roughly half the internet-facing fleet across 194 countries. Assume compromise and rotate now.
Velvet Ant's Operation Highland: A China-Nexus APT Backdoored the Linux Auth Stack for a Decade
Sygnia's Operation Highland report details how the China-nexus group Velvet Ant hid in an isolated network for nearly a decade by backdooring pam_unix.so and OpenSSH binaries — no exploit, no dropped malware, no anomalous logs.
Splunk Enterprise CVE-2026-20253: An Unauthenticated Postgres Sidecar Hands Over Pre-Auth RCE
CVE-2026-20253 (CVSS 9.8) is a pre-auth RCE in Splunk Enterprise. An unauthenticated Postgres sidecar endpoint gives an arbitrary file write that escalates to code execution — on the box holding all your logs. Full exploit details are public; patch now.
HTTP/2 Bomb: One Cheap Client Pins 32GB on NGINX, Apache, IIS, Envoy and Cloudflare
A new HPACK-plus-flow-control DoS lets a home broadband connection hold 32GB of server memory in ~20 seconds. Affects the default HTTP/2 config of every major web server and proxy. NGINX and Apache have fixes; IIS, Envoy and Cloudflare Pingora do not yet.
Apache httpd CVE-2026-23918: HTTP/2 Double-Free Puts Millions of Servers at RCE Risk
Critical double-free in mod_http2's early-reset path lets remote attackers crash or take over Apache 2.4.66. Patch shipped May 4 in 2.4.67.
CrowdStrike LogScale CVE-2026-40050: Unauthenticated Path Traversal Reads Arbitrary Server Files
A critical 9.8 CVSS path traversal in CrowdStrike's LogScale lets unauthenticated attackers read arbitrary files from self-hosted clusters. Patch to 1.235.1, 1.234.1, 1.233.1, or 1.228.2 LTS.