cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-06-08 Critical

    CVE-2026-50751: Check Point VPN Auth Bypass Exploited by Qilin — IKEv1 Sessions Without a Password

    Check Point confirmed active exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Remote Access VPN and Mobile Access deployments running deprecated IKEv1. Attackers establish VPN sessions without a valid password; one case is tied to a Qilin ransomware affiliate. Earliest exploitation traces to May 7.

    vpnauthentication-bypassransomware
  • vulnerabilities 2026-06-08

    An AI Agent Found 21 Zero-Days in FFmpeg for $1,000 — and Your Container Images Are in Scope

    depthfirst's autonomous agent found 21 zero-days in FFmpeg for about $1,000, including a 23-year-old stack overflow. Nine carry CVEs (CVE-2026-39210 through CVE-2026-39218). FFmpeg is bundled everywhere — patch upstream and your embedded copies.

    ai-securityzero-daysupply-chain
  • threats 2026-06-07

    CISA and the FBI Warn: Internet-Exposed Fuel Tank Gauges Are Under Active Attack

    A June 2 joint advisory from CISA, the FBI, the NSA and five other agencies says attackers are compromising internet-exposed automatic tank gauge systems and modifying them through command execution. Shadowserver counts over 1,000 exposed, 909 in the US — on the same TCP port these consoles have answered on for a decade.

    icsotcritical-infrastructurecisafbiiran
  • supply-chain 2026-06-07

    Claude Code's GitHub Action: One Malicious Issue Could Hijack Any Public Repo

    A permission bypass chained with prompt injection in Anthropic's Claude Code GitHub Action let a single crafted issue make the agent leak CI secrets and OIDC request tokens — a clean path to poisoning the action's own supply chain. Patched in v1.0.94.

    supply-chaingithub-actionsci-cdai-security
  • deep dive 2026-06-07 13 min read

    Anatomy of the Interlock Campaign: How a ClickFix Gang Learned to Burn Firewall Zero-Days

    For a year, the surest way to get hit by Interlock was to paste a command into your own Run dialog. On January 26, 2026, the group stopped waiting for users to make mistakes and started exploiting a pre-auth, root-level Cisco firewall zero-day instead. The same crew now runs both ends of the sophistication ladder — and that should change how you model initial access.

    ransomwarecisconetwork-appliancedeserializationclickfixzero-daycisa-kev
  • vulnerabilities 2026-06-06

    SolarWinds Serv-U DoS Flaw CVE-2026-28318 Hits CISA KEV as Attackers Crash File Transfer Servers

    CISA added SolarWinds Serv-U CVE-2026-28318 to its KEV catalog after attackers began crashing file transfer servers with a single unauthenticated deflate-encoded POST. Patch to 15.5.4 HF1.

    cisa-kev
  • vulnerabilities 2026-06-06

    Cisco Catalyst SD-WAN Manager CVE-2026-20245: Root Command Execution, No Patch Yet

    Cisco's seventh SD-WAN zero-day of 2026. CVE-2026-20245 lets a netadmin upload a crafted file and execute commands as root on SD-WAN Manager. Exploited in the wild, no fix at disclosure.

    ciscosd-wanzero-dayactive-exploitationcommand-injection
  • vulnerabilities 2026-06-06

    Mirasvit Cache Warmer CVE-2026-45247: One Cookie Pops Any Magento Store, No Auth Required

    CISA added CVE-2026-45247 to KEV after Imperva confirmed active exploitation. A single crafted CacheWarmer cookie gives unauthenticated RCE on Magento and Adobe Commerce stores running Mirasvit Full Page Cache Warmer below 1.11.12.

    deserializationrcecisa-kev
  • threat-intel 2026-06-05

    Sophos Finds an AI-Orchestrated Lab That Auto-Builds EDR-Evasion Payloads for an Active Ransomware Crew

    Sophos X-Ops recovered a post-exploitation framework where AI agents read public research, mapped it to MITRE ATT&CK, and generated ~80 Rust and Go payloads tested against Sophos, CrowdStrike, and Microsoft EDR.

    ransomwareedr-evasioncobalt-strike
  • supply-chain 2026-06-04

    IronWorm: A Rust-Built npm Worm With an eBPF Rootkit and Tor C2

    JFrog dissected IronWorm, a self-replicating npm supply-chain worm written in Rust that hides behind an eBPF kernel rootkit, beacons over Tor, and steals 86 env vars and 20+ credential files. 36 packages hit before it was caught.

    supply-chainnpmebpfrootkitshai-hulud
  • vulnerabilities 2026-06-04

    Redis CVE-2026-23479: AI-Discovered Use-After-Free Yields RCE on a Database That's Everywhere

    An authenticated use-after-free in Redis's blocking-client path (CVE-2026-23479, CVSS 8.8) gives a low-privilege user OS command execution on the host. It sat unnoticed for over two years and was found by an autonomous AI bug-hunting tool.

    use-after-freercecloud-security
  • vulnerabilities 2026-06-03

    HTTP/2 Bomb: One Cheap Client Pins 32GB on NGINX, Apache, IIS, Envoy and Cloudflare

    A new HPACK-plus-flow-control DoS lets a home broadband connection hold 32GB of server memory in ~20 seconds. Affects the default HTTP/2 config of every major web server and proxy. NGINX and Apache have fixes; IIS, Envoy and Cloudflare Pingora do not yet.

    http2nginxapachedenial-of-serviceinfrastructure
  • vulnerabilities 2026-06-03

    Android Framework Zero-Day CVE-2025-48595: Silent Privilege Escalation Under Active Attack

    CVE-2025-48595 is a high-severity integer overflow in the Android Framework that escalates privilege with no user interaction and no special permissions. Google confirms limited, targeted exploitation; CISA added it to KEV on June 2 with a June 5 federal deadline. Affects Android 14, 15, 16, and 16 QPR2.

    zero-dayprivilege-escalationcisa-kev
  • vulnerabilities 2026-06-02

    DirtyDecrypt (CVE-2026-31635): Public PoC Roots Fedora, Arch, and openSUSE via the Kernel's RxGK Path

    A released proof-of-concept weaponizes CVE-2026-31635, a missing copy-on-write guard in the Linux kernel's RxGK receive path, for local root on Fedora, Arch, and openSUSE Tumbleweed — and pod escape on affected worker nodes.

    linux-kernellpeprivilege-escalationcontainer-escapecopy-fail
  • vulnerabilities 2026-06-02

    Oracle WebLogic CVE-2024-21182 Hits CISA KEV: Two-Year-Old T3 Bug Now Under Active Exploitation

    CISA added the unauthenticated Oracle WebLogic T3/IIOP flaw CVE-2024-21182 to its Known Exploited Vulnerabilities catalog on June 1. The patch has shipped for two years — this is a story about exposed, unpatched middleware.

    oracledeserializationcisa-kev
  • supply-chain 2026-06-01

    Red Hat Cloud Services npm Packages Hijacked in 'Miasma' Shai-Hulud Worm

    A Mini Shai-Hulud wave dubbed 'Miasma' poisoned ~30 @redhat-cloud-services npm packages on June 1 via a compromised CI/CD pipeline, dropping a Bun-based credential stealer with a destructive dead-man switch.

    supply-chainnpmshai-huludteampcpcredential-theftci-cdgithub-actionskubernetes
  • supply-chain 2026-06-01 High

    codexui-android: npm Package Silently Exfiltrated OpenAI Codex Auth Tokens for a Month

    A 29K-weekly-download npm package advertised as a remote web UI for OpenAI Codex has been quietly exfiltrating ~/.codex/auth.json — including non-expiring refresh tokens — to a fake Sentry endpoint since v0.1.82.

    npmsupply-chaincredential-theftoauthnodejs
  • threat-intel 2026-05-31

    AI at the Wheel: An LLM Agent Ran a Full Cloud Intrusion in Under an Hour

    Sysdig's Threat Research Team documented one of the first in-the-wild intrusions where a large language model agent — not a human — drove the entire post-exploitation chain, pivoting from a marimo RCE to a full PostgreSQL dump in four hops.

    ai-securityllmcloud-securityaws
  • threat-intel 2026-05-31 Medium

    GREYVIBE: Russia's AI-Assisted APT Is Vibe-Coding Its Way Through Ukraine

    WithSecure attributes a year-long espionage campaign against Ukraine to GREYVIBE, a Russia-nexus group that runs generative AI through nearly every phase of its operation — lure art, obfuscators, full-stack RAT development, and post-compromise commands.

    aptclickfixllm
  • deep dive 2026-05-31 14 min read

    SSRF to the Model, Model to the Cloud: The Inference Layer Is 2026's Softest Attack Surface

    Model gateways and inference servers are repeating two decades of solved web-security mistakes — default-open binds, pickle RCE, pre-auth SQLi, and SSRF straight into cloud credentials. A field guide to the AI control plane's softest links and how to harden them before the next 36-hour exploitation window.

    ai-infrastructuressrfrcedeserializationlitellmimdscisa-kevtrend-analysis
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss