cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • supply-chain 2026-05-21

    actions-cool/issues-helper Compromised: Every Tag Repointed to a Credential-Stealing Imposter Commit

    An attacker repointed all 53 tags of the popular actions-cool/issues-helper GitHub Action to a single imposter commit that scrapes live CI/CD secrets out of runner process memory.

    supply-chaingithub-actionsci-cdcredential-theft
  • vulnerabilities 2026-05-20

    Drupal SA-CORE-2026-004: Highly Critical Unauthenticated SQL Injection Hits PostgreSQL Sites

    CVE-2026-9082 is a highly critical SQL injection in Drupal core's database abstraction API. Anonymous attackers can run arbitrary SQL against PostgreSQL-backed sites. Patches dropped May 20; exploitation is expected within days.

    sql-injectionpostgresqlweb-security
  • supply-chain 2026-05-20

    Nx Console VS Code Extension Compromised: Orphan-Commit Stealer Hits a 2.2M-Install Developer Tool

    A compromised Nx Console 18.95.0 extension pulled a 498 KB stealer from an orphan commit in the official nrwl/nx repo, harvesting GitHub, npm, AWS and Vault secrets — and shipped tooling to forge signed npm provenance.

    supply-chainnpm
  • vulnerability 2026-05-19

    SEPPmail Secure Email Gateway: Seven Flaws Including CVSS 10.0 Path Traversal to RCE

    InfoGuard Labs discloses seven vulnerabilities in SEPPmail Secure E-Mail Gateway, including a CVSS 10.0 path-traversal-to-RCE bug and an unauthenticated Perl eval injection — full appliance takeover and mail-traffic interception.

    rcepath-traversal
  • vulnerabilities 2026-05-19

    Ollama CVE-2026-7482 'Bleeding Llama': Heap OOB Read in GGUF Loader Leaks Server Memory to Unauthenticated Attackers

    A heap out-of-bounds read in Ollama's GGUF model loader (CVE-2026-7482, CVSS 9.1) lets unauthenticated attackers exfiltrate server process memory — including API keys, env vars, system prompts, and other users' conversations — from an estimated 300,000+ exposed instances.

    ai-infrastructureheap-overflow
  • vulnerabilities 2026-05-18

    MiniPlasma: Public PoC Hands SYSTEM on Fully Patched Windows 11 via cldflt.sys

    Chaotic Eclipse published a working PoC for MiniPlasma, a Cloud Filter driver LPE that abuses CfAbortHydration to forge .DEFAULT-hive registry keys — the same bug Microsoft was told about in 2020 and claimed to have fixed.

    windowszero-dayprivilege-escalationlpe
  • vulnerability 2026-05-18

    CloudNativePG CVE-2026-44477: Metrics Exporter Escalates Any DB User to Postgres Superuser and Host RCE

    A residual session_user=postgres in CloudNativePG's metrics exporter lets any low-privileged database user RESET ROLE back to superuser and reach OS-level command execution via COPY TO PROGRAM. CVSS 9.4. Patched in 1.28.3 and 1.29.1.

    postgresqlkubernetesrceprivilege-escalation
  • breach 2026-05-17

    Grafana Refuses Ransom After CoinbaseCartel Pwn Request Attack Steals Source Code From Five Repos

    Grafana Labs disclosed that CoinbaseCartel exploited a GitHub Actions pull_request_target misconfiguration to steal privileged CI tokens and pivot into five private repos. A canary token tripped the breach; the company refused the ransom demand.

    github-actionssupply-chainextortion
  • Vulnerabilities 2026-05-17

    YellowKey and GreenPlasma: Same Researcher Drops Two More Windows Zero-Days, BitLocker Bypass via WinRE USB

    The anonymous researcher behind BlueHammer is back with YellowKey, a BitLocker bypass that drops a CMD shell on protected drives via crafted FsTx files in WinRE, plus GreenPlasma, a CTFMON privilege escalation. No CVE, no patch.

    windowszero-dayprivilege-escalationendpoint-security
  • deep dive 2026-05-17 15 min read

    NTLM Coercion's Quiet Resurgence: Why 2026's Zero-Click Attacks Look Like 2021

    Two unrelated bugs in the last month — an incomplete APT28 patch and an unpatched RPC defect — both hand attackers a 1990s-era credential primitive. The fact that NTLM coercion still works in 2026 is not a series of accidents. It is the model.

    windowsactive-directorytrend-analysisopinion
  • vulnerabilities 2026-05-16

    ssh-keysign-pwn (CVE-2026-46333): Six-Year-Old Linux Kernel Race Hands Unprivileged Users SSH Host Keys and /etc/shadow

    Qualys disclosed a six-year-old logic flaw in __ptrace_may_access that lets any local user race ssh-keysign and chage out of their host keys and shadow file. Public PoC works out of the box on Debian, Ubuntu, Arch, and the EL9/EL10 families. Patch or set kernel.yama.ptrace_scope=2 now.

    linux-kernel
  • vulnerability 2026-05-16

    Cisco Catalyst SD-WAN CVE-2026-20182: Second vdaemon Auth Bypass Lands in CISA KEV

    Cisco patched a CVSS 10.0 auth bypass in Catalyst SD-WAN Controller's vdaemon service. UAT-8616 is already exploiting it. CISA added it to KEV May 15 with a May 17 deadline.

    ciscosd-wancisa-kevactive-exploitationcvss-10
  • vulnerability 2026-05-15

    Exchange Server CVE-2026-42897: Unpatched OWA XSS Zero-Day Exploited via Crafted Email

    Microsoft confirms in-the-wild exploitation of an unpatched XSS spoofing flaw in on-prem Exchange Server 2016, 2019, and Subscription Edition. Mitigation is automatic only if EEMS is enabled.

    microsoftzero-day
  • vulnerabilities 2026-05-15

    NGINX Rift: 18-Year-Old Rewrite Module Heap Overflow Hits Unauthenticated RCE With Public PoC

    CVE-2026-42945 is a CVSS 9.2 heap buffer overflow in ngx_http_rewrite_module that has lived in NGINX since 2008. A working unauthenticated RCE PoC is public; reachability hinges on a specific rewrite-directive pattern most prod configs actually contain.

    nginxrceheap-overflowf5
  • vulnerability 2026-05-14

    Outlook CVE-2026-40361: Zero-Click Word RCE Resurrects BadWinmail's Enterprise-Killer Class

    A use-after-free in a shared Office DLL lets a malicious message fire RCE through the Outlook Reading Pane and Explorer Preview Pane. Microsoft rates exploitation 'more likely.'

    microsoftuse-after-freepatch-tuesday
  • vulnerability 2026-05-14

    Every Windows Endpoint is a Target: CVE-2026-41096 Heap Overflow in DNS Client Enables Remote Code Execution

    CVE-2026-41096 is a CVSS 9.8 heap overflow in the Windows DNS Client. A single malicious DNS response can yield code execution on any Windows host — no auth, no user click, no document opened. The blast radius is every Windows endpoint that resolves a name.

    windowsrcepatch-tuesdayheap-overflowendpoint-security
  • vulnerabilities 2026-05-13

    Windows Netlogon CVE-2026-41089: Unauthenticated RCE on Every Domain Controller

    May Patch Tuesday's marquee bug is a stack-based buffer overflow in MS-NRPC that hands SYSTEM on any domain controller reachable over the network. Patch DCs first, before anything else.

    windowsactive-directorypatch-tuesdayrce
  • supply-chain 2026-05-13

    RubyGems Disables New Signups After Hundreds of Malicious Packages Target Registry Staff

    RubyGems froze new account registration after an attacker uploaded hundreds of malicious gems on May 11-12 specifically targeting RubyGems engineers, with XSS payloads and credential-stealing exploits embedded in the packages.

    supply-chaincredential-theftci-cd
  • supply-chain 2026-05-12

    Mini Shai-Hulud Wave 4: TanStack, Mistral AI, UiPath Hit by First-Ever SLSA-Attested Malicious npm Packages (CVE-2026-45321)

    TeamPCP's fourth Mini Shai-Hulud wave compromised 42 TanStack packages, the Mistral AI SDK, UiPath, OpenSearch, and Guardrails AI by stealing OIDC tokens out of a GitHub Actions runner's process memory — and shipped malicious versions with valid SLSA Build Level 3 provenance attestations.

    supply-chainnpmpypigithub-actionsteampcpshai-huludci-cd
  • vulnerabilities 2026-05-11

    Apache CloudStack CVE-2026-25077: Malicious Template Lands Code Execution on KVM Hosts

    Apache CloudStack 4.20.3.0 and 4.22.0.1 ship fixes for seven flaws — the headliner lets any account user execute arbitrary code on KVM hypervisor hosts via a malicious template name.

    rcecloudapache
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss