cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-07-18

    wp2shell: A Two-CVE Chain Turns WordPress Core Into Pre-Auth RCE

    CVE-2026-60137 and CVE-2026-63030 chain a REST API route-confusion bug with a WP_Query SQL injection to give unauthenticated attackers a path to full RCE on default WordPress installs.

    sql-injectionrceauthentication-bypasscmsactive-exploitation
  • vulnerabilities 2026-07-18

    VMSA-2026-0005: Seven Flaws in VMware Avi Load Balancer, Topped by a 9.8 Auth Bypass

    Broadcom patched seven vulnerabilities in VMware Avi Load Balancer, led by CVE-2026-47865, a CVSS 9.8 authentication bypass that gives a network attacker a foothold on the control plane.

    authentication-bypassrceprivilege-escalationnetwork-appliancecloud
  • vulnerabilities 2026-07-17

    HollowByte: An 11-Byte TLS Handshake Payload That Bloats OpenSSL Server Memory

    A memory-allocation flaw in OpenSSL's TLS handshake parsing, dubbed HollowByte, lets an unauthenticated attacker exhaust server memory with an 11-byte payload per connection. No CVE was assigned; patched in 4.0.1 and backported across the 3.x line.

    denial-of-servicelinuxnetwork-applianceinfrastructurecloud
  • vulnerabilities 2026-07-17

    LegacyHive: Unpatched Windows Zero-Day Lets Standard Users Mount Another Account's Registry Hive

    Researcher Nightmare Eclipse has dropped LegacyHive, a working PoC against the Windows User Profile Service that lets a standard user load another account's registry hive — no CVE, no patch, works on fully updated July 2026 systems.

    windowszero-dayprivilege-escalationlpe
  • vulnerabilities 2026-07-17

    AA26-194A: NSA, CISA, FBI Warn Russian FSB Center 16 Is Harvesting Router Configs via Weak SNMP and an 18-Year-Old Cisco CSRF Bug

    A 19-agency joint advisory (AA26-194A) details a years-long Russian FSB Center 16 campaign that scans for default SNMP community strings and an 18-year-old Cisco IOS CSRF flaw (CVE-2008-4128, now in CISA KEV) to exfiltrate router configs and pivot into critical infrastructure.

    aptnetwork-applianceactive-exploitationcisa-kevcritical-infrastructureauthentication-bypass
  • vulnerabilities 2026-07-16

    CVE-2026-58658: GPUStack Worker Ports Leaked LLM Prompts and Completions With No Authentication

    GPUStack, an open-source GPU cluster manager for vLLM/SGLang/TensorRT-LLM inference, shipped worker debug and log-streaming endpoints with zero authentication — letting anyone who can reach the worker port read live prompts, completions, and memory profiles.

    authentication-bypasscloudkubernetesaiinformation-disclosurenetwork-appliance
  • vulnerabilities 2026-07-15

    AsyncAPI npm Packages Backdoored via GitHub Actions 'Pwn Request', Deliver Miasma RAT

    A stolen CI token let attackers push a malicious commit into AsyncAPI's npm packages on July 14, delivering an IPFS-hosted Miasma RAT to millions of weekly installs — this time configured as a stealthy botnet, not a self-propagating worm.

    supply-chainnpmci-cdgithub-actionscredential-theftmalware
  • vulnerabilities 2026-07-15

    CVE-2026-15409 & CVE-2026-15410: SonicWall SMA1000 Zero-Days Chained for Unauthenticated RCE, CISA Deadline July 17

    Two SonicWall SMA1000 zero-days — a CVSS 10.0 SSRF and a post-auth code injection flaw — are being chained in the wild for unauthenticated remote code execution. CISA KEV deadline is July 17, 2026.

    active-exploitationcisa-kevnetwork-appliancevpnzero-dayssrf
  • vulnerabilities 2026-07-14

    Microsoft's July Patch Tuesday Breaks Its Own Record Again: 570 Flaws, Two Zero-Days Under Active Attack

    Microsoft's largest Patch Tuesday ever fixes 570 vulnerabilities, including an exploited AD FS privilege-escalation zero-day, an exploited SharePoint EoP zero-day, and a publicly disclosed BitLocker bypass.

    microsoftpatch-tuesdayzero-dayactive-exploitationprivilege-escalationrce
  • vulnerabilities 2026-07-14

    AssuranceAmerica Breach Exposes 7 Million Driver's Licenses After a Single Phished Employee Account

    A single compromised employee credential at auto insurer AssuranceAmerica led to the theft of driver's license numbers, SSNs, and policy data for nearly 7 million people — one of the largest driver's-license breaches disclosed in the US this year.

    data-breachcredential-theftphishingcritical-infrastructureincident-response
  • supply-chain 2026-07-13

    Injective Labs' @injectivelabs/sdk-ts npm Package Backdoored to Steal Wallet Private Keys

    A compromised release of Injective Labs' TypeScript SDK, @injectivelabs/sdk-ts, and 17 dependent packages hooked wallet key-derivation functions to exfiltrate mnemonic seed phrases and private keys to an endpoint disguised as legitimate Injective infrastructure.

    supply-chainnpmcredential-theftcryptocurrencymalware
  • vulnerabilities 2026-07-13

    Six U-Boot Flaws Let Malicious Firmware Images Execute Code Before Signature Verification Ever Runs

    Binarly found six bugs in U-Boot's FIT image parser — two lead to code execution, four to denial of service — and all six trigger while the bootloader is still reading an untrusted image, before it checks the signature that's supposed to protect it.

    firmwarelinuxrcenetwork-applianceiotsupply-chain
  • vulnerabilities 2026-07-12

    Progress Tells ShareFile Customers to Power Down Storage Zone Controllers Over 'Credible' Threat

    Progress Software is telling on-prem ShareFile Storage Zone Controller admins to physically shut down their Windows servers over an unnamed 'credible external security threat' — no CVE, no patch, no explanation.

    network-appliancewindowscloudinfrastructureincident-response
  • deep dive 2026-07-12 12 min read

    The Agent Is the Payload: How AI Coding Agents Became 2026's Fastest RCE Pipeline

    Six incidents in six weeks show the same failure mode: AI coding agents treat untrusted text as instructions and shell access as a convenience feature. Prompt injection to RCE is no longer theoretical — it's a documented, repeatable kill chain, and the guardrails vendors are shipping don't touch the actual boundary.

    ai-infrastructureprompt-injectionrcesupply-chaincredential-thefttrend-analysis
  • supply-chain 2026-07-12

    Jscrambler npm Package Compromised: Rust Infostealer Shipped via Preinstall Hook

    The official jscrambler npm package was compromised to publish version 8.14.0 with a preinstall hook that drops a cross-platform Rust infostealer targeting cloud credentials, crypto wallets, and password managers.

    supply-chainnpmcredential-theftinfostealerci-cd
  • vulnerabilities 2026-07-11

    PraisonAI: Two More Critical RCEs (CVE-2026-61445, CVE-2026-61447) as AICoder Runs LLM Output Unsandboxed

    PraisonAI's AICoder component writes files and executes shell commands straight from LLM tool calls with no path validation, and CodeAgent._execute_python() runs LLM-generated Python with no AST checks or sandboxing — two CVSS 9.9 and 10.0 flaws, patched in 4.6.78.

    ai-infrastructurerceprompt-injectionsandbox-escapecommand-injectioncve
  • vulnerabilities 2026-07-11

    Zimbra Patches Classic Web Client Stored XSS Reported by Google TAG

    Zimbra shipped 10.1.19 to fix an unauthenticated stored XSS in the Classic Web Client, reachable by simply opening a crafted email — no CVE assigned yet, reported by Google's Threat Analysis Group.

    network-appliancexsscredential-theftemail-securityapt
  • vulnerabilities 2026-07-10

    Langflow Hit With Its Second CISA KEV Entry in Four Months: CVE-2026-55255 IDOR Under Active Exploitation

    CISA adds Langflow CVE-2026-55255, an IDOR letting authenticated attackers hijack other users' AI workflows, to its KEV catalog after Sysdig caught in-the-wild exploitation chained with secret harvesting.

    cisa-kevactive-exploitationauthentication-bypassai-infrastructurecredential-theft
  • vulnerabilities 2026-07-10

    Ubiquiti's Bulletin 066: A CVSS 10.0 in UniFi Connect Leads 25 Flaws Across the Whole UniFi Line

    Ubiquiti Security Advisory Bulletin 066 discloses 25 vulnerabilities across UniFi Connect, Talk, Access, Protect, and UniFi OS — headlined by CVE-2026-50746, a CVSS 10.0 unauthenticated command injection reachable on ~100,000 internet-facing endpoints.

    cisa-kevrcecommand-injectionprivilege-escalationnetwork-applianceauthentication-bypass
  • supply-chain 2026-07-09

    17 Malicious npm/PyPI Packages Impersonate Paysafe, Skrill, and Neteller SDKs to Steal CI/CD Secrets

    A coordinated typosquatting campaign published 13 npm and 4 PyPI packages that mimic Paysafe, Skrill, and Neteller payment SDKs, returning fake success responses while exfiltrating API keys, AWS credentials, and CI tokens to an obfuscated C2 host.

    supply-chainnpmpypicredential-theftci-cdmalware
← newer1234567891011121314older →
© 2026 Max Clinton rss