cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-04-22

    Spinnaker Dual 10.0s: Echo SpEL and Clouddriver gitrepo RCE Gut Netflix's CD Platform (CVE-2026-32604, CVE-2026-32613)

    Two critical (CVSS 10.0) RCE bugs in Spinnaker, disclosed April 21, 2026 with working PoCs: SpEL expression injection in Echo and shell injection in Clouddriver gitrepo artifacts. Any authenticated user pops the CD plane and walks out with every stored cloud credential.

    ci-cdrcecommand-injectioncloud
  • vulnerabilities 2026-04-21

    Quest KACE SMA CVE-2025-32975: CVSS 10.0 SSO Auth Bypass Added to CISA KEV as Admin Takeover Campaign Continues

    CISA added CVE-2025-32975 — a CVSS 10.0 SSO authentication bypass in Quest KACE Systems Management Appliance — to the KEV catalog on April 20, 2026. Federal agencies must patch by May 4. Exploitation has been in progress since March.

    authentication-bypasscisa-kevpre-authactive-exploitation
  • vulnerabilities 2026-04-21 High

    Cisco Catalyst SD-WAN Manager: Three CVEs Land on CISA KEV With April 28 Federal Deadline

    CISA added CVE-2026-20122, CVE-2026-20128, and CVE-2026-20133 in Cisco Catalyst SD-WAN Manager (vManage) to the KEV catalog on April 20, 2026. Two of the three were confirmed exploited in the wild by Cisco PSIRT in March; together they let an attacker move from low-privilege API access to full vManage takeover.

    ciscosd-wancisa-kevprivilege-escalationpatch-tuesday
  • threat-actors 2026-04-20

    The Gentlemen RaaS: SystemBC Proxy Botnet Reveals 1,570 Corporate Victims

    A DFIR engagement against The Gentlemen RaaS exposed a SystemBC C2 server proxying over 1,570 likely corporate victims, with affiliates leaning on a 14,700-device FortiGate inventory for initial access.

    ransomwarecobalt-strike
  • supply-chain 2026-04-20

    Vercel Breach: Context.ai OAuth Pivot Exposes Customer Environment Variables

    A Lumma Stealer infection at Context.ai gave attackers an OAuth path into a Vercel employee's Google Workspace, then into customer environment variables. ShinyHunters is now selling the data for $2M.

    supply-chainoauthshinyhunters
  • breach 2026-04-19

    ShinyHunters Dumps 3M Cisco Salesforce Records as UNC6040 Vishing Campaign Expands

    ShinyHunters leaks 3M+ Cisco Salesforce CRM records tied to the UNC6040 vishing/OAuth-abuse campaign, exposing federal procurement data, AWS resource references, and GitHub repo names.

    shinyhunterssalesforceciscooauthdata-breach
  • deep dive 2026-04-19 11 min read

    The Ransomware Dwell Time Collapse: When the Entire Kill Chain Fits Inside an Hour

    Akira is encrypting domains 60 minutes after a VPN login. Storm-1175 is going from zero-day to domain-wide Medusa deployment in under 24 hours. The industry's average detection time is still measured in days. The math no longer works.

    ransomwareincident-responsevpnopinion
  • OT Security 2026-04-19

    ZionSiphon: OT Sabotage Malware Targeting Israeli Water and Desalination Plants

    Darktrace dissects ZionSiphon, a politically motivated OT malware built to tamper with chlorine and pressure in Israeli water systems. Broken by bad crypto, but the blueprint is real.

    oticsscadamalwarecritical-infrastructure
  • ransomware 2026-04-18

    Payouts King Runs Hidden QEMU VMs to Bypass EDR — STAC4713 and CitrixBleed 2 Campaigns

    Sophos tracks two Payouts King campaigns running Alpine Linux inside QEMU on Windows hosts to tunnel reverse SSH and evade endpoint security. STAC3725 chains in CitrixBleed 2 (CVE-2025-5777) against NetScaler.

    ransomwareedr-evasion
  • vulnerabilities 2026-04-18

    RedSun and UnDefend: Two More Defender Zero-Days Dropped, All Three Now Exploited in the Wild

    The same disgruntled researcher who dropped BlueHammer has now released RedSun and UnDefend. Huntress confirms all three Windows Defender zero-days are now being weaponized in hands-on-keyboard intrusions. Two remain unpatched.

    windowszero-dayprivilege-escalation
  • Incidents 2026-04-17

    Operation PowerOFF: 21-Country Takedown Seizes 53 DDoS-for-Hire Domains, Exposes 3 Million User Accounts

    Europol-coordinated action across 21 countries seizes 53 booter/stresser domains, makes four arrests in Poland, and captures databases containing over 3 million DDoS-for-hire user accounts.

  • vulnerabilities 2026-04-17

    Kyverno apiCall Service Helper Leaks ServiceAccount Token to Attacker-Controlled Endpoints (CVE-2026-40868)

    A high-severity flaw in Kyverno's apiCall servicecall helper implicitly attaches the controller's ServiceAccount bearer token to policy-controlled outbound URLs, letting any ClusterPolicy author exfiltrate the token and impersonate the Kyverno controller.

    kubernetes
  • vulnerabilities 2026-04-16

    CISA Adds Apache ActiveMQ CVE-2026-34197 to KEV as 13-Year-Old Jolokia RCE Sees Active Exploitation

    CISA added CVE-2026-34197 to the KEV catalog today with an April 30 patch deadline. The 13-year-old Jolokia MBean flaw yields RCE on the broker JVM and is unauthenticated on ActiveMQ 6.0.0–6.1.1 when chained with CVE-2024-32114.

    rcecisa-kev
  • vulnerabilities 2026-04-16

    Two Critical FortiSandbox Flaws Let Unauthenticated Attackers Execute Commands and Bypass Auth

    Fortinet discloses CVE-2026-39808 and CVE-2026-39813 — two CVSS 9.1 flaws in FortiSandbox allowing unauthenticated command execution and authentication bypass via crafted HTTP requests.

    fortinetcommand-injectionauthentication-bypass
  • incidents 2026-04-15

    Ransomware Hits ChipSoft, the EHR Vendor Behind 80% of Dutch Hospitals

    A ransomware attack on Dutch EHR vendor ChipSoft has disrupted hospital systems nationwide and may have exposed millions of patient records.

    ransomwaresupply-chain
  • vulnerabilities 2026-04-15

    CVE-2026-21643: Pre-Auth SQL Injection in FortiClient EMS 7.4.4 Under Active Exploitation — CISA Deadline Tomorrow

    Critical pre-authentication SQL injection in Fortinet FortiClient EMS 7.4.4 is being actively exploited. CISA KEV remediation deadline is April 16, 2026.

    fortinetsql-injectioncisa-kevpre-authactive-exploitation
  • Vulnerability 2026-04-14

    Composer Command Injection (CVE-2026-40261, CVE-2026-40176): Any Malicious Repository Can Execute Code on Your Build Machines

    Two high-severity command injection flaws in PHP's Composer package manager allow arbitrary command execution via malicious repository metadata — no Perforce installation required for the worst one.

    supply-chaincommand-injectioncverce
  • vulnerabilities 2026-04-14

    Microsoft April 2026 Patch Tuesday Fixes 167 Flaws Including Actively Exploited SharePoint Zero-Day

    Microsoft's second-largest Patch Tuesday ever addresses 167 vulnerabilities, including an actively exploited SharePoint XSS flaw and a critical CVSS 9.8 Windows IKE remote code execution bug.

    microsoftpatch-tuesdayzero-daywindows
  • Vulnerability 2026-04-14

    CVE-2026-31414: Linux Kernel Netfilter Conntrack Flaw Enables Container Escape Privilege Escalation

    A use-after-free in Linux kernel netfilter connection tracking allows local privilege escalation from container workloads — patch your nodes now.

    linux-kernelprivilege-escalationkubernetes
  • vulnerabilities 2026-04-13

    Red Hat OpenShift AI Dashboard Leaks Kubernetes Service Account Tokens (CVE-2026-5483)

    A high-severity flaw in Red Hat OpenShift AI's odh-dashboard exposes Kubernetes Service Account tokens via a NodeJS endpoint, enabling unauthorized cluster access.

    kubernetes
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss