cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-05-30 High

    CVE-2026-0257: Palo Alto GlobalProtect Auth Bypass Now Exploited — Unauthorized VPN Access Into Your Network

    Palo Alto confirmed active exploitation of CVE-2026-0257, a CVSS 7.8 GlobalProtect authentication bypass that lets attackers establish unauthorized VPN sessions into the internal network. Rapid7 traced exploitation back to May 17. CISA KEV deadline is June 1.

    palo-altopan-osauthentication-bypassvpncisa-kev
  • Supply Chain 2026-05-30

    Malicious NuGet Package Impersonates Sicoob Banking SDK, Exfiltrates mTLS Certificates Through Sentry

    A trojanized NuGet package posing as the official Sicoob C# SDK reads PFX certificates off disk and ships them, plus the password, to an attacker-controlled Sentry endpoint — abusing a trusted telemetry service as its exfiltration channel.

    supply-chaincredential-theftmalware
  • Supply Chain 2026-05-29

    JINX-0164: Fake Recruiters, a macOS RAT, and a Pivot Into Code Distribution Pipelines

    Wiz details JINX-0164, a financially motivated actor that uses LinkedIn recruiter lures to drop the AUDIOFIX macOS RAT, then moves from developer laptops into code distribution and CI/CD infrastructure.

    supply-chainci-cdinfostealersocial-engineeringnpm
  • vulnerability 2026-05-29

    Gogs 0-Day: Argument Injection in Rebase Merging Gives Any User RCE — and There's No Patch

    Rapid7 disclosed an unpatched CVSS 9.4 RCE in Gogs. A malicious branch name injects --exec into git rebase during 'Rebase before merging,' giving any registered user code execution on the server. No CVE, no fix — only config-level mitigations.

    self-hostedrcezero-day
  • vulnerabilities 2026-05-28

    BadHost (CVE-2026-48710): A Forged Host Header Walks Past Auth in Every Starlette App

    BadHost (CVE-2026-48710) is a Host-header authentication bypass in Starlette before 1.0.1. One malformed header makes request.url.path lie to your middleware — unlocking protected routes on FastAPI, vLLM, LiteLLM, and MCP servers without credentials.

    authentication-bypassmcpai-infrastructurelitellm
  • vulnerability 2026-05-28

    KnowledgeDeliver CVE-2026-5426: Shared ASP.NET Machine Key Burns Every Japanese LMS Tenant at Once

    A hardcoded ASP.NET machineKey shipped in Digital Knowledge's KnowledgeDeliver LMS web.config gives any attacker who reads one tenant's config unauthenticated RCE on every other internet-facing instance. Mandiant tied active exploitation to BLUEBEAM web shells and Cobalt Strike beacons consistent with Chinese-speaking APTs.

    zero-daycobalt-strike
  • vulnerability 2026-05-27

    Gitea CVE-2026-27771: Container Registry Hands Out Private Images Without Authentication, 30,000 Instances Exposed

    A four-year-old flaw in Gitea's OCI container registry lets anyone on the internet pull images marked private. 30,000+ deployments are exposed, Forgejo inherits the bug, and the only real fix is upgrading to 1.26.2 or forcing sign-in for all content.

    self-hostedsupply-chain
  • vulnerabilities 2026-05-27

    SharePoint CVE-2026-45659: Site Member Permissions Are Enough to Pop the Farm

    Microsoft patched CVE-2026-45659, an 8.8-severity SharePoint deserialization RCE that only requires Site Member permissions — the lowest tier any authenticated user can have.

    microsoftdeserializationrcepatch-tuesday
  • Vulnerabilities 2026-05-26

    7-Zip CVE-2026-48095: NTFS Parser Heap Overflow Lets Any Double-Clicked Archive Hijack a vtable

    A signed-shift bug in 7-Zip's NTFS handler under-allocates a 1-byte buffer, then writes up to 256 MB of attacker-controlled data straight through the adjacent stream object's vtable pointer. Patched in 26.01.

    heap-overflowrcewindowslinux
  • threat-actor 2026-05-26

    Lazarus RemotePE: Memory-Only RAT Behind $577M Crypto Theft Surfaces in Fox-IT Disclosure

    Fox-IT and The Hacker News detail RemotePE, a fileless C++ RAT used by North Korea's Lazarus Group against fintech and crypto firms via a DPAPI-bound loader chain. Tied to $577M in 2026 crypto theft.

    ratedr-evasionapt
  • vulnerabilities 2026-05-25

    Ghost CMS CVE-2026-26980: Unauthenticated SQL Injection Powers a 700-Site ClickFix Campaign

    CVE-2026-26980 is a CVSS 9.4 unauthenticated SQL injection in Ghost's Content API. A patch shipped in February; attackers have since industrialized it into an automated campaign that has hijacked 700+ sites — including Harvard, Oxford, and DuckDuckGo — to serve ClickFix malware.

    sql-injectionclickfixweb-securityactive-exploitation
  • Supply Chain 2026-05-25

    TrapDoor: Cross-Ecosystem Supply Chain Attack Plants Credential Stealers and AI-Assistant Backdoors

    A coordinated campaign across npm, PyPI, and Crates.io seeded 34+ malicious packages that steal developer secrets and plant hidden instructions to weaponize AI coding assistants.

    supply-chainnpmpypicredential-theftmalware
  • supply-chain 2026-05-24

    Megalodon: 5,561 GitHub Repos Backdoored With Malicious CI/CD Workflows in Six Hours

    An automated campaign tied to TeamPCP pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window, planting CI/CD workflows that exfiltrate cloud credentials and OIDC tokens at scale.

    supply-chaingithub-actionsci-cdcredential-theftteampcp
  • vulnerabilities 2026-05-24

    LiteSpeed cPanel Plugin CVE-2026-48172: Any User Can Run Scripts as Root

    A CVSS 10.0 flaw in the LiteSpeed User-End cPanel Plugin lets any logged-in cPanel user execute scripts as root. It is being exploited in the wild — patch or uninstall now.

    cpanelprivilege-escalationactive-exploitation
  • deep dive 2026-05-24 12 min read

    The Edge Device Audit: Turn CISA's BOD 26-02 Into a Playbook You Can Actually Run

    CISA's BOD 26-02 just handed every infrastructure team a free edge-device audit checklist. Here is how to run it on your own network — inventory, version, exposure, and end-of-support triage — before an attacker runs theirs.

    network-appliancevulnerability-managementcisa-kevvpn
  • incident 2026-05-23

    The 'Private-CISA' Leak: A Contractor Left GovCloud Keys and Artifactory Creds Public on GitHub for Six Months

    A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, internal Artifactory credentials, and plaintext passwords to dozens of agency systems for roughly six months.

    cisa
  • Supply Chain 2026-05-23

    Laravel-Lang Supply Chain Attack: 233 Package Versions Backdoored to Steal Cloud and CI/CD Secrets

    Attackers repointed git tags across four Laravel-Lang Composer packages to a malicious fork, backdooring 233 versions with a credential stealer that drains cloud, CI/CD, and developer secrets.

    supply-chaincredential-theftmalware
  • vulnerabilities 2026-05-22

    Trend Micro Apex One CVE-2026-34926: Directory Traversal Turns the EDR Server Into a Malware Dropper

    A directory traversal flaw in on-premise Trend Micro Apex One lets an attacker who already holds server admin access poison the agent build and push malicious code to every managed endpoint. CISA added it to KEV after confirmed in-the-wild exploitation.

    cisa-kev
  • vulnerabilities 2026-05-22

    Cisco Secure Workload CVE-2026-20223: Unauthenticated API Flaw Hands Over Site Admin

    A CVSS 10.0 flaw in Cisco Secure Workload lets unauthenticated attackers reach internal REST APIs with Site Admin privileges across tenant boundaries. No workarounds — patch now.

    ciscoauthentication-bypass
  • vulnerabilities 2026-05-21

    Two More Defender Zero-Days in the Wild: CVE-2026-41091 Link-Resolution Bug Lands SYSTEM, Added to CISA KEV

    Microsoft confirms two Defender flaws — an LPE to SYSTEM and a DoS — are publicly disclosed and exploited in the wild. A third RCE ships in the same engine update. CISA gives federal agencies until June 3.

    windowsprivilege-escalationzero-daycisa-kev
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss