cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-04-01 Critical

    F5 BIG-IP APM Flaw Silently Upgraded from DoS to RCE — Now Actively Exploited

    A five-month-old F5 BIG-IP APM bug just got reclassified from denial-of-service to pre-auth RCE. Attackers didn't wait for the memo.

    f5rcecisa-kevnetwork-appliance
  • threat-intel 2026-04-01 High

    TrueConf Zero-Day Weaponized by Chinese-Nexus APT to Backdoor Southeast Asian Governments

    Operation TrueChaos exploited CVE-2026-3502 in TrueConf's update mechanism to push Havoc C2 payloads across government networks via a compromised on-premises server.

    zero-daysupply-chainapt
  • vulnerabilities 2026-04-01 High

    Chrome Zero-Day CVE-2026-5281: WebGPU Use-After-Free Under Active Exploitation

    Google patches fourth Chrome zero-day of 2026 — a use-after-free in the Dawn WebGPU implementation that enables arbitrary code execution via crafted HTML pages.

    chromezero-dayuse-after-freebrowser-security
  • deep dive 2026-04-01 11 min read

    Your Firewall Is the Foothold: Q1 2026's Edge Device Exploitation Epidemic

    Three months into 2026, edge devices are the dominant entry point for attackers. A deep dive into the FortiGate SSO bypass and Ivanti EPMM RCE chains, and why this pattern shows no signs of stopping.

    network-appliancefortinetivantiauthentication-bypassransomwarecve
  • vulnerabilities 2026-04-01 Critical

    CVE-2026-20127: Cisco SD-WAN Zero-Day Exploited for Three Years Before Disclosure

    UAT-8616 abused a CVSS 10.0 auth bypass in Cisco Catalyst SD-WAN Controller and Manager since 2023, inserting rogue control-plane peers and escalating to root via a deliberate version-downgrade chain. Cisco disclosed in late February.

    ciscosd-wanauthentication-bypasszero-daycvss-10privilege-escalation
  • supply-chain 2026-03-31 Critical

    Axios npm Hijacked: Compromised Maintainer Account Drops Cross-Platform RAT in 100M-Download Package

    DPRK-linked UNC1069 compromised the axios npm maintainer's account and published two backdoored versions that deployed the WAVESHAPER.V2 RAT to macOS, Windows, and Linux — present in ~80% of cloud environments.

    npmsupply-chainratnorth-koreanodejs
  • vulnerabilities 2026-03-31 Critical

    CVE-2026-3055: NetScaler SAML IDP Memory Overread Is Under Active Recon — Patch Before April 2

    Attackers are actively probing Citrix NetScaler ADC/Gateway for CVE-2026-3055, a CVSS 9.3 memory overread that can leak session tokens from SAML IDP-configured appliances. CISA deadline is April 2.

    cisa-kev
  • vulnerabilities 2026-03-31 Critical

    Cisco FMC Zero-Day Exploited by Interlock Ransomware for 36 Days Before Disclosure

    CVE-2026-20131 scores a perfect CVSS 10.0. Interlock ransomware had 36 days of free rein before Cisco went public.

    ciscozero-dayransomwarenetwork-appliance
  • supply-chain 2026-03-30 Critical

    CanisterWorm and GlassWorm: Two Independent Supply Chain Attacks Using Blockchain as C2

    Both attacks use blockchain infrastructure — ICP and Solana respectively — as command-and-control channels. Trivy itself was compromised.

    supply-chaintrivynpmc2
  • vulnerabilities 2026-03-29 High

    CrackArmor: Nine AppArmor Flaws Enable Container Escape on Debian, Ubuntu, and SUSE

    Every Kubernetes node running these distros is potentially exposed. Root escalation from within containers confirmed.

    kuberneteslinuxcontainer-escape
  • analysis 2026-03-28 High

    Three Chrome Zero-Days Patched in March Alone — What's Driving the Surge

    Google patched three actively exploited Chrome zero-days this month. The browser attack surface is expanding faster than it's being hardened.

    chromezero-daybrowser-security
← newer1234567891011121314
© 2026 Max Clinton rss