cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-08-31

    Mini Shai-Hulud "Trinitite": TanStack Codegen Tool Poisoned via Hijacked GitHub OIDC Release Workflow

    A new Mini Shai-Hulud wave dubbed Trinitite compromised @7nohe/openapi-react-query-codegen, a 150K-download-a-week TanStack code generator, by hijacking its GitHub Actions OIDC publish workflow rather than stealing a token.

    supply-chainnpmci-cdcredential-theftgithub-actionsshai-hulud
  • vulnerabilities 2026-08-31

    ATF Confirms Qilin Ransomware Breach of System Holding Investigation Targets

    The Bureau of Alcohol, Tobacco, Firearms and Explosives confirms a 'major incident' after the Qilin ransomware gang listed it on a dark-web leak site, with the breached system holding data on active investigation targets.

    ransomwaredouble-extortiondata-breachgovernmentqilin
  • vulnerabilities 2026-08-30

    CVE-2026-8452: 'DoS-Only' NetScaler Flaw Turns Out to Be Pre-Auth Root RCE, Now Under Active Exploitation

    watchTowr Labs turned a Citrix NetScaler bug Citrix rated as a crash-only memory overflow into pre-auth root code execution; CISA confirms in-the-wild exploitation with web shells on unpatched appliances.

    active-exploitationcisa-kevnetwork-appliancercevpnzero-day
  • deep dive 2026-08-30 11 min read

    The ECC Excuse Is Dead: A Hardening Guide for Multi-Tenant GPU Infrastructure After GPUThor

    For four months, 'enable ECC' was the official fix for GPU Rowhammer. GPUThor just showed that advice was wrong. Here's what to actually change on GPU fleets that run untrusted CUDA code from more than one tenant.

    hardware-securityai-infrastructuremulti-tenantcloudinfrastructure-hardening
  • vulnerabilities 2026-08-30

    GPUThor: First Rowhammer Attack to Defeat ECC on NVIDIA Workstation GPUs

    University of Toronto researchers show GPUThor beats NVIDIA's ECC mitigation for GDDR6 Rowhammer, closing the gap the GPUBreach disclosure left open for host root access.

    privilege-escalationcloudcontainer-escapelinux
  • vulnerabilities 2026-08-29

    ShinyHunters Claims 284M-Record McKesson Breach After Vishing Two Employees Into Salesforce

    ShinyHunters says it vished two McKesson employees into authorizing a rogue connected app, then pulled patient and physician records out of Salesforce and Snowflake — a $55M ransom followed.

    shinyhuntersdata-breachsocial-engineeringsalesforcecloudextortion
  • vulnerabilities 2026-08-28

    Manchester Airports Group Breach Exposes Data of 8.7 Million Airport Customers

    An unauthorized third party accessed customer data across Manchester, Stansted, and East Midlands airports, exposing contact and vehicle details for 8.7 million people. MAG refused a ransom demand and hasn't named the attacker publicly.

    data-breachcritical-infrastructureransomwarethird-party-riskincident-response
  • vulnerabilities 2026-08-28

    Critical Veeam ONE Flaw Lets Unauthenticated Attackers Coerce SMB Auth From the Service Account

    CVE-2026-65641 (CVSS 9.3) lets an unauthenticated network attacker force Veeam ONE's service account into an SMB authentication attempt, exposing Net-NTLM material for relay or offline cracking.

    authentication-bypassnetwork-appliancebackup-infrastructurewindowscredential-theft
  • vulnerabilities 2026-08-27

    PaperCut Ships Emergency Out-of-Cycle Build After Zero-Day Hits Every Supported NG/MF Version

    PaperCut confirmed active zero-day exploitation of an unpatched flaw affecting every currently supported PaperCut NG/MF release and shipped emergency out-of-cycle builds hours after a university's forensics team caught it in the wild.

    zero-dayactive-exploitationrcenetwork-appliancecisa-kev
  • vulnerabilities 2026-08-27

    CISA, NSA, FBI Warn of AI-Generated Exploit Scripts Targeting Siemens S7 PLCs

    A joint advisory from NSA, CISA, FBI, DOE, and EPA warns that threat actors are pairing AI-assisted scripting with snap7 libraries to build custom reconnaissance and exploitation tools against internet-exposed Siemens S7 PLCs.

    icsot-securityscadacritical-infrastructurenetwork-applianceactive-exploitation
  • vulnerabilities 2026-08-26

    CVE-2026-60004: Gitea diffpatch Code Injection Now Under Active Exploitation, Added to CISA KEV

    A critical Gitea flaw lets any repository writer install a malicious Git hook via the diffpatch endpoint and run shell commands as the Gitea OS user. CISA confirms in-the-wild exploitation and gave federal agencies until August 28 to patch.

    active-exploitationcisa-kevrceself-hostedgitcommand-injection
  • vulnerabilities 2026-08-26

    NVIDIA NemoClaw Flaw Lets Any Website Hijack a Local AI Agent via DNS Rebinding

    CVE-2026-65105 in NVIDIA NemoClaw lets a single malicious webpage use DNS rebinding to reach an unauthenticated local Ollama instance and permanently poison the model's chat template.

    ai-infrastructureauthentication-bypasssandbox-escapellmcloud
  • vulnerabilities 2026-08-25

    CVE-2026-21962: Max-Severity Oracle HTTP Server / WebLogic Proxy Flaw Added to CISA KEV After Months of Exploitation

    CISA added CVE-2026-21962, a CVSS 10.0 auth-bypass and path-traversal flaw in Oracle HTTP Server and the WebLogic Server Proxy Plug-in, to its KEV catalog on August 24 — seven months after Oracle patched it and after mass automated scanning had already begun.

    active-exploitationcisa-kevauthentication-bypassrcecloud
  • vulnerabilities 2026-08-25

    Iran-Linked Hackers Force UK Power Plant Offline for Four Days

    A small UK generating station went dark for four days after an intrusion The Telegraph attributes to Iran-linked hackers, the first confirmed case of an IRGC-affiliated actor shutting down British energy infrastructure.

    icsot-securitycritical-infrastructureiranaptscada
  • vulnerabilities 2026-08-24

    Keycloak's Reset-Credentials Flow Lets Unauthenticated Attackers Take Over Any Account (CVE-2026-18963)

    CVE-2026-18963 lets an unauthenticated attacker skip email verification in Keycloak's password-reset flow and set new credentials on any account. Patch to 26.7.2 (or 26.4.15/26.6.6 for Red Hat builds) now.

    authentication-bypassidentity-providercritical-infrastructureprivilege-escalation
  • vulnerabilities 2026-08-24

    9,300+ Leaked AWS Keys Are Still Active — 768 Give Attackers Full Admin Control

    A large-scale scan of public repos, Hugging Face datasets, Docker images, and CI logs found over 9,300 leaked AWS keys still authenticate — 768 with full corporate admin control.

    cloudawscredential-theftcloud-securitydata-breach
  • vulnerabilities 2026-08-23

    14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2

    Fourteen npm packages disguised as calendar and streak utilities smuggle in RedC2 4.0, a commercial Linux implant whose LLM-driven operator console turns plain-English prompts into post-exploitation commands.

    supply-chainnpmbackdoorlinuxcredential-theftmalware
  • deep dive 2026-08-23 11 min read

    Phishing the Protocol: How 2026 Attackers Made MFA Irrelevant

    Device code grants, app passwords, OAuth consent screens, and WhatsApp device linking all share one property: they're real login flows, not bugs. 2026's biggest identity attacks stopped stealing passwords and started collecting the tokens MFA can't protect.

    oauthphishingcredential-theftauthentication-bypasstrend-analysissocial-engineering
  • vulnerabilities 2026-08-22

    GTIG Tracks Three Russian Clusters Weaponizing App Passwords, OAuth Consent, and WhatsApp Linking

    Google's Threat Intelligence Group details three Russia-nexus clusters — UNC6293, UNC7005, UNC5976 — abusing app-password generation, OAuth consent flows, and WhatsApp device linking to hijack accounts of diplomats, academics, and defense researchers without tripping MFA.

    aptphishingoauthcredential-theftsocial-engineeringespionage
  • vulnerabilities 2026-08-22

    Poisoned arrayref, internment, and append-only-vec Crates Pull Build-Time Malware via a proc-macro2 Typosquat

    A compromised maintainer account published malicious releases of three popular Rust crates that pull in a typosquatted proc-macro2 lookalike whose build.rs script downloads and runs a platform-specific payload at compile time — with infrastructure overlapping known DPRK supply-chain campaigns.

    supply-chainrusttyposquattingcredential-theftbuild-pipelineapt
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss