cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • Incidents 2026-04-17

    Operation PowerOFF: 21-Country Takedown Seizes 53 DDoS-for-Hire Domains, Exposes 3 Million User Accounts

    Europol-coordinated action across 21 countries seizes 53 booter/stresser domains, makes four arrests in Poland, and captures databases containing over 3 million DDoS-for-hire user accounts.

  • vulnerabilities 2026-04-17

    Kyverno apiCall Service Helper Leaks ServiceAccount Token to Attacker-Controlled Endpoints (CVE-2026-40868)

    A high-severity flaw in Kyverno's apiCall servicecall helper implicitly attaches the controller's ServiceAccount bearer token to policy-controlled outbound URLs, letting any ClusterPolicy author exfiltrate the token and impersonate the Kyverno controller.

    kubernetes
  • vulnerabilities 2026-04-16

    CISA Adds Apache ActiveMQ CVE-2026-34197 to KEV as 13-Year-Old Jolokia RCE Sees Active Exploitation

    CISA added CVE-2026-34197 to the KEV catalog today with an April 30 patch deadline. The 13-year-old Jolokia MBean flaw yields RCE on the broker JVM and is unauthenticated on ActiveMQ 6.0.0–6.1.1 when chained with CVE-2024-32114.

    rcecisa-kev
  • vulnerabilities 2026-04-16

    Two Critical FortiSandbox Flaws Let Unauthenticated Attackers Execute Commands and Bypass Auth

    Fortinet discloses CVE-2026-39808 and CVE-2026-39813 — two CVSS 9.1 flaws in FortiSandbox allowing unauthenticated command execution and authentication bypass via crafted HTTP requests.

    fortinetcommand-injectionauthentication-bypass
  • incidents 2026-04-15

    Ransomware Hits ChipSoft, the EHR Vendor Behind 80% of Dutch Hospitals

    A ransomware attack on Dutch EHR vendor ChipSoft has disrupted hospital systems nationwide and may have exposed millions of patient records.

    ransomwaresupply-chain
  • vulnerabilities 2026-04-15

    CVE-2026-21643: Pre-Auth SQL Injection in FortiClient EMS 7.4.4 Under Active Exploitation — CISA Deadline Tomorrow

    Critical pre-authentication SQL injection in Fortinet FortiClient EMS 7.4.4 is being actively exploited. CISA KEV remediation deadline is April 16, 2026.

    fortinetsql-injectioncisa-kevpre-authactive-exploitation
  • Vulnerability 2026-04-14

    Composer Command Injection (CVE-2026-40261, CVE-2026-40176): Any Malicious Repository Can Execute Code on Your Build Machines

    Two high-severity command injection flaws in PHP's Composer package manager allow arbitrary command execution via malicious repository metadata — no Perforce installation required for the worst one.

    supply-chaincommand-injectioncverce
  • vulnerabilities 2026-04-14

    Microsoft April 2026 Patch Tuesday Fixes 167 Flaws Including Actively Exploited SharePoint Zero-Day

    Microsoft's second-largest Patch Tuesday ever addresses 167 vulnerabilities, including an actively exploited SharePoint XSS flaw and a critical CVSS 9.8 Windows IKE remote code execution bug.

    microsoftpatch-tuesdayzero-daywindows
  • Vulnerability 2026-04-14

    CVE-2026-31414: Linux Kernel Netfilter Conntrack Flaw Enables Container Escape Privilege Escalation

    A use-after-free in Linux kernel netfilter connection tracking allows local privilege escalation from container workloads — patch your nodes now.

    linux-kernelprivilege-escalationkubernetes
  • vulnerabilities 2026-04-13

    Red Hat OpenShift AI Dashboard Leaks Kubernetes Service Account Tokens (CVE-2026-5483)

    A high-severity flaw in Red Hat OpenShift AI's odh-dashboard exposes Kubernetes Service Account tokens via a NodeJS endpoint, enabling unauthorized cluster access.

    kubernetes
  • Ransomware 2026-04-13

    Anubis Ransomware Gang Claims 2TB Exfiltration from Signature Healthcare as Brockton Hospital Diverts Ambulances

    Anubis RaaS group claims theft of 2TB of patient data from Signature Healthcare while Brockton Hospital diverts ambulances, cancels chemo, and operates on paper charts a week after the attack.

    ransomwaredata-breachincident-response
  • Vulnerabilities 2026-04-12

    Marimo CVE-2026-39987: Pre-Auth RCE Exploited Within 10 Hours of Disclosure

    A missing authentication check on Marimo's terminal WebSocket endpoint (CVE-2026-39987, CVSS 9.3) gave attackers a root shell with no credentials required — and they were actively exploiting it less than 10 hours after the advisory dropped.

    cvercepythoncredential-theftactive-exploitation
  • Vulnerability 2026-04-12

    Adobe Acrobat Reader Zero-Day CVE-2026-34621: Prototype Pollution RCE Exploited Since December

    Adobe patches APSB26-43 after confirming CVE-2026-34621, a CVSS 9.6 prototype pollution flaw in Acrobat Reader actively exploited via malicious PDFs since at least December 2025.

    rcezero-dayactive-exploitation
  • Supply Chain 2026-04-12

    CPUID Website Compromised to Deliver STX RAT via CPU-Z and HWMonitor Downloads

    Attackers compromised CPUID's download infrastructure for ~19 hours, replacing CPU-Z and HWMonitor installers with trojanized builds that sideload STX RAT via a malicious CRYPTBASE.dll.

    supply-chainratwindowsmalware
  • deep dive 2026-04-12 11 min read

    Self-Hosted and Unprotected: The AI Workflow Tool Security Crisis

    Langflow, Flowise, n8n, ComfyUI — every major self-hosted AI workflow tool has shipped unauthenticated RCE vulnerabilities in 2026. This isn't a coincidence. It's a structural failure baked into how these tools were designed.

    ai-infrastructurercelangflowmcpself-hostedcredential-theft
  • supply-chain 2026-04-10

    Smart Slider 3 Pro Update Infrastructure Compromised — Backdoored Build Pushed to 800K+ WordPress Sites

    Attackers compromised Nextend's update servers to distribute a weaponized Smart Slider 3 Pro build containing a multi-layered RAT with credential exfiltration and persistent backdoors.

    supply-chainwordpressbackdoorweb-security
  • Vulnerability 2026-04-10

    GPUBreach: GDDR6 Rowhammer Attack Achieves Root Shell, Bypasses IOMMU

    University of Toronto researchers demonstrate full CPU privilege escalation from an unprivileged CUDA kernel via GDDR6 bit-flips, bypassing IOMMU — no patch exists yet.

    privilege-escalationcloud
  • Vulnerability 2026-04-09

    Project Glasswing: Anthropic's Claude Mythos AI Autonomously Found Thousands of Zero-Days in Every Major OS and Browser

    Anthropic's Claude Mythos Preview autonomously discovered thousands of unpatched zero-days across FreeBSD, Linux, OpenBSD, FFmpeg, and every major browser — including a sandbox escape that emailed a researcher.

    zero-daylinux
  • vulnerabilities 2026-04-09

    Chrome 147 Patches 60 Security Flaws Including Two Critical WebML RCE Bugs

    Google ships Chrome 147.0.7727.55 with fixes for 60 vulnerabilities—two critical heap buffer overflow and integer overflow flaws in the WebML component enable remote code execution via crafted HTML pages.

    chromerceheap-overflowbrowser-security
  • Threat Intelligence 2026-04-09

    CISA AA26-097A: CyberAv3ngers Exploit Rockwell PLCs Across US Water, Energy, and Government Systems

    Six US agencies issue joint advisory after Iranian-affiliated CyberAv3ngers compromise Rockwell Allen-Bradley PLCs in water, energy, and government sectors, manipulating SCADA displays and control logic.

    icsot-securityirancisacritical-infrastructurescada
← newer1234567891011121314older →
© 2026 Max Clinton rss