cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • Ransomware 2026-04-13

    Anubis Ransomware Gang Claims 2TB Exfiltration from Signature Healthcare as Brockton Hospital Diverts Ambulances

    Anubis RaaS group claims theft of 2TB of patient data from Signature Healthcare while Brockton Hospital diverts ambulances, cancels chemo, and operates on paper charts a week after the attack.

    ransomwaredata-breachincident-response
  • Vulnerabilities 2026-04-12

    Marimo CVE-2026-39987: Pre-Auth RCE Exploited Within 10 Hours of Disclosure

    A missing authentication check on Marimo's terminal WebSocket endpoint (CVE-2026-39987, CVSS 9.3) gave attackers a root shell with no credentials required — and they were actively exploiting it less than 10 hours after the advisory dropped.

    cvercepythoncredential-theftactive-exploitation
  • Vulnerability 2026-04-12

    Adobe Acrobat Reader Zero-Day CVE-2026-34621: Prototype Pollution RCE Exploited Since December

    Adobe patches APSB26-43 after confirming CVE-2026-34621, a CVSS 9.6 prototype pollution flaw in Acrobat Reader actively exploited via malicious PDFs since at least December 2025.

    rcezero-dayactive-exploitation
  • Supply Chain 2026-04-12

    CPUID Website Compromised to Deliver STX RAT via CPU-Z and HWMonitor Downloads

    Attackers compromised CPUID's download infrastructure for ~19 hours, replacing CPU-Z and HWMonitor installers with trojanized builds that sideload STX RAT via a malicious CRYPTBASE.dll.

    supply-chainratwindowsmalware
  • deep dive 2026-04-12 11 min read

    Self-Hosted and Unprotected: The AI Workflow Tool Security Crisis

    Langflow, Flowise, n8n, ComfyUI — every major self-hosted AI workflow tool has shipped unauthenticated RCE vulnerabilities in 2026. This isn't a coincidence. It's a structural failure baked into how these tools were designed.

    ai-infrastructurercelangflowmcpself-hostedcredential-theft
  • supply-chain 2026-04-10

    Smart Slider 3 Pro Update Infrastructure Compromised — Backdoored Build Pushed to 800K+ WordPress Sites

    Attackers compromised Nextend's update servers to distribute a weaponized Smart Slider 3 Pro build containing a multi-layered RAT with credential exfiltration and persistent backdoors.

    supply-chainwordpressbackdoorweb-security
  • Vulnerability 2026-04-10

    GPUBreach: GDDR6 Rowhammer Attack Achieves Root Shell, Bypasses IOMMU

    University of Toronto researchers demonstrate full CPU privilege escalation from an unprivileged CUDA kernel via GDDR6 bit-flips, bypassing IOMMU — no patch exists yet.

    privilege-escalationcloud
  • Vulnerability 2026-04-09

    Project Glasswing: Anthropic's Claude Mythos AI Autonomously Found Thousands of Zero-Days in Every Major OS and Browser

    Anthropic's Claude Mythos Preview autonomously discovered thousands of unpatched zero-days across FreeBSD, Linux, OpenBSD, FFmpeg, and every major browser — including a sandbox escape that emailed a researcher.

    zero-daylinux
  • vulnerabilities 2026-04-09

    Chrome 147 Patches 60 Security Flaws Including Two Critical WebML RCE Bugs

    Google ships Chrome 147.0.7727.55 with fixes for 60 vulnerabilities—two critical heap buffer overflow and integer overflow flaws in the WebML component enable remote code execution via crafted HTML pages.

    chromerceheap-overflowbrowser-security
  • Threat Intelligence 2026-04-09

    CISA AA26-097A: CyberAv3ngers Exploit Rockwell PLCs Across US Water, Energy, and Government Systems

    Six US agencies issue joint advisory after Iranian-affiliated CyberAv3ngers compromise Rockwell Allen-Bradley PLCs in water, energy, and government sectors, manipulating SCADA displays and control logic.

    icsot-securityirancisacritical-infrastructurescada
  • vulnerabilities 2026-04-09

    CVE-2026-39860: Nix Package Manager Symlink Bug Gives Any User Root on Multi-User Installs

    A critical symlink-following flaw in the Nix daemon lets unprivileged users overwrite arbitrary files as root during fixed-output derivation builds.

    privilege-escalationcvelinux
  • vulnerabilities 2026-04-09

    CVE-2026-32922: OpenClaw Privilege Escalation Lets Any Paired Device Achieve Full RCE

    A missing scope validation in OpenClaw's device.token.rotate endpoint lets any device with operator.pairing scope mint admin tokens and execute arbitrary code on connected nodes.

    cveprivilege-escalationrcecloud-security
  • vulnerabilities 2026-04-08

    CISA Adds Ivanti EPMM Zero-Days to KEV as Mass Exploitation Ramps Up

    CISA adds CVE-2026-1340 to the Known Exploited Vulnerabilities catalog as attackers chain two Ivanti EPMM zero-days for unauthenticated RCE against mobile device management infrastructure.

    ivantizero-daycisa-kevrce
  • Supply Chain 2026-04-08

    North Korea's Contagious Interview Campaign Hits 1,700 Malicious Packages Across Five Ecosystems

    DPRK-linked Contagious Interview operation now spans npm, PyPI, Go Modules, crates.io, and Packagist with 1,700+ poisoned packages delivering BeaverTail and InvisibleFerret malware.

    supply-chainnorth-koreanpmpypiaptmalware
  • threat-intelligence 2026-04-08

    APT28's FrostArmada Hijacked 18,000 SOHO Routers to Steal Microsoft 365 Credentials — FBI Disrupts Operation

    Russia-linked APT28 compromised 18,000 MikroTik and TP-Link routers across 120 countries to hijack DNS and steal Microsoft 365 OAuth tokens. FBI disrupts the operation.

    oauthfbi
  • Vulnerabilities 2026-04-08

    BlueHammer: Unpatched Windows Defender Zero-Day Turns Definition Updates Into SYSTEM Shells

    A disgruntled researcher leaked BlueHammer, a Windows Defender LPE zero-day that chains TOCTOU race conditions with Cloud Files oplocks to dump SAM hives and escalate to SYSTEM. No patch available.

    windowszero-dayprivilege-escalation
  • Attacks 2026-04-07

    Over 1,000 Exposed ComfyUI Instances Hijacked for Cryptomining and Proxy Botnet

    Active campaign targets unauthenticated ComfyUI deployments across cloud providers, enlisting them into Monero mining and a Hysteria V2 proxy botnet via malicious custom nodes.

    botnetai-infrastructure
  • vulnerabilities 2026-04-07

    Docker AuthZ Bypass Returns: CVE-2026-34040 Lets Attackers Create Privileged Containers With a Single Padded Request

    An incomplete fix for a 2024 Docker AuthZ bypass has resurfaced as CVE-2026-34040, allowing unauthenticated container creation with host filesystem access via oversized HTTP requests.

    cveprivilege-escalation
  • vulnerability 2026-04-07

    Three High-Severity Command Injection Flaws in AWS Research and Engineering Studio Give Authenticated Users Root RCE

    AWS patches three CVSS 8.8 command injection and privilege escalation bugs in Research and Engineering Studio (RES) — any authenticated user could get root on virtual desktop hosts or the cluster manager.

    awscloudcommand-injectionrceprivilege-escalation
  • Vulnerabilities 2026-04-07

    Flowise AI Under Active Exploitation: CVSS 10.0 RCE via CustomMCP Node Hits 12,000+ Exposed Instances

    Critical unauthenticated RCE in Flowise AI's CustomMCP node (CVE-2025-59528, CVSS 10.0) is under active exploitation. Over 12,000 instances are exposed. Patch to 3.0.6 immediately.

    rceai-infrastructuremcp
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss