cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-08-21

    CVE-2026-69836: Perfect-10 Entra ID Deserialization RCE Exploited in the Wild

    Microsoft confirms in-the-wild exploitation of CVE-2026-69836, a maximum-severity unauthenticated deserialization RCE in Entra ID's backend — already patched server-side, but the identity plane behind Microsoft 365 and Azure was exposed with no customer visibility into the attack.

    active-exploitationrcecloudauthentication-bypassunauthenticated
  • vulnerabilities 2026-08-21

    CVE-2026-73570: Unauthenticated Zimbra RCE via SNMP Notifications Under Active Exploitation

    CERT Polska confirms in-the-wild exploitation of CVE-2026-73570, an unauthenticated OS command injection in Zimbra Collaboration's SNMP notification handling — patched in 10.1.20, but plenty of mail servers haven't updated.

    active-exploitationcommand-injectionrceemail-securityunauthenticated
  • vulnerabilities 2026-08-20

    Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Breaks Guest-to-Host Isolation for AI Agent Sandboxes

    A type confusion in isolated-vm's ExternalCopy transferList handling lets code running inside a V8 sandbox corrupt host memory and hijack control flow — a full guest-to-host escape in a library millions of AI agent and automation deployments trust to run untrusted code.

    container-escapenpmsupply-chainauthentication-bypasscloud
  • vulnerabilities 2026-08-20

    Unauthenticated MLflow Webhook SSRF (CVE-2026-64849) Exploited Within Hours to Steal Cloud Credentials

    An unauthenticated SSRF in MLflow's webhook-test endpoint, CVE-2026-64849, lets attackers bypass an existing SSRF guard via HTTP redirects to reach cloud metadata services — and exploitation began within hours of the CVE going public.

    active-exploitationcloudserver-side-request-forgeryauthentication-bypassmlops
  • vulnerabilities 2026-08-19

    CVE-2026-19490: Critical NetScaler Auth Bypass Lets Attackers Skip the Login Screen Entirely

    A critical CVSS 9.3 authentication bypass in Citrix NetScaler ADC and Gateway lets unauthenticated attackers reach protected resources behind SSL VPN, ICA Proxy, and AAA virtual servers — patch CTX696939 now.

    authentication-bypassvpnnetwork-appliancezero-dayactive-exploitation
  • vulnerabilities 2026-08-19

    ShieldBreak (CVE-2026-69414): A Full Bypass of Microsoft's RoguePlanet Defender Patch, Still Unfixed

    Nightmare Eclipse's ShieldBreak fully bypasses the fix for RoguePlanet, Microsoft Defender's earlier SYSTEM-privilege zero-day. Microsoft has assigned CVE-2026-69414 and confirmed a patch is in progress, but none has shipped.

    windowszero-dayprivilege-escalationlpemicrosoft
  • vulnerabilities 2026-08-18

    CVE-2026-65400: macOS Screen Sharing Auth Bypass Exploited for Root Access, Added to CISA KEV

    CISA added CVE-2026-65400, a pre-auth bypass in macOS Screen Sharing, to its KEV catalog after attackers used it to gain root on internet-exposed Macs and drop Monero miners; CVSS was raised to 9.8 following public PoC release.

    active-exploitationcisa-kevauthentication-bypassmacosprivilege-escalation
  • vulnerabilities 2026-08-18

    CVE-2025-62593: Browser-Based DNS Rebinding RCE in Ray Added to CISA KEV Amid ShadowRay 2.0 Exploitation

    CISA has added CVE-2025-62593, a critical DNS-rebinding RCE in the Ray AI compute framework, to its KEV catalog after RondoDox botnet operators weaponized it and ShadowRay 2.0 continued hijacking exposed clusters for GPU cryptomining.

    active-exploitationcisa-kevrcecloudauthentication-bypasskubernetes
  • vulnerabilities 2026-08-17

    SharePoint JWT Bypass (CVE-2026-55040) Chains With BCS Gadget Chain (CVE-2026-63520) for Unauthenticated RCE

    A JWT validation bypass under active exploitation since mid-August now chains with a newly disclosed Business Connectivity Services gadget chain, giving unauthenticated attackers full RCE on on-prem SharePoint farms.

    active-exploitationrceauthentication-bypassmicrosoftzero-day
  • vulnerabilities 2026-08-17

    Evooo1Bot: New Mirai-Derived Linux Botnet Chains Eight CVEs Spanning 2007–2025 Against Routers and Edge Devices

    Evooo1Bot, a modular Mirai-derived Linux botnet tracked by FortiGuard Labs, exploits eight known CVEs dating back to 2007 across routers, firewalls, and industrial gateways to build a SOCKS5 proxy and DDoS network.

    botnetnetwork-applianceactive-exploitationlinuxcommand-injection
  • vulnerabilities 2026-08-16

    Supply Chain Security Vendor RapidFort Allegedly Breached in CanisterWorm Fallout — 569GB of Customer Pipeline Data Listed for Sale

    A threat actor claims to be selling 569GB of RapidFort's internal pipeline data — including customer cross-account IAM templates, kubeconfigs, and plaintext AWS credentials — allegedly extracted during the March 2026 CanisterWorm/TeamPCP campaign.

    supply-chainci-cdcredential-theftdata-breachteampcpcloud
  • deep dive 2026-08-16 10 min read

    The Modem Nobody Audited: Inside the 2026 Water Utility PLC Attacks

    Thirty-plus Minnesota water utilities lost control of their PLCs in a single weekend, and the entry point wasn't the internet-facing HMI everyone scans for — it was a cellular modem nobody put on the asset inventory. A look at what CyberAv3ngers actually did, why a 2021 CVE is still unpatched, and why 'get it off the internet' misses the real exposure.

    icsotcritical-infrastructurevulnerability-managementtrend-analysiscisa-kev
  • vulnerabilities 2026-08-15

    CVE-2026-58231: Max-Severity Unauth RCE in SAP Commerce Cloud Now Under Active Exploitation

    CVE-2026-58231, a CVSS 10.0 flaw in SAP Commerce Cloud's Data Hub Adapter, lets unauthenticated attackers execute arbitrary code via a default authentication client. Exploitation attempts began August 14, three days after SAP shipped a patch.

    active-exploitationrceauthentication-bypasscloudsupply-chain
  • vulnerabilities 2026-08-14

    Critical Use-After-Free in Microsoft QUIC Allows Unauthenticated RCE (CVE-2026-62815)

    CVE-2026-62815, a CVSS 9.8 use-after-free in Microsoft's QUIC/HTTP-3 implementation, lets an unauthenticated remote attacker execute code with a single crafted packet — no user interaction required.

    rcewindowszero-daycloudpatch-tuesdaymicrosoft
  • vulnerabilities 2026-08-14

    Unpatched GeoServer Zero-Day Lets Unauthenticated Attackers Turn SQL Injection Into RCE

    An unpatched, unauthenticated SQL injection in GeoServer's jsonArrayContains filter function is under active probing days after public disclosure, with a documented path to remote code execution on PostgreSQL-backed instances.

    zero-dayactive-exploitationrceauthentication-bypasscloudnetwork-appliance
  • vulnerabilities 2026-08-13

    Microsoft Patches a Wormable Windows DNS Server RCE Alongside Three More Critical DNS Flaws

    CVE-2026-62878, a CVSS 9.8 stack-based buffer overflow in Windows DNS Server, is wormable and needs no authentication — and it shipped alongside three more critical DNS Server RCEs in the same Patch Tuesday round.

    rcewindowsnetwork-appliancecisa-kevzero-day
  • vulnerabilities 2026-08-13

    CopyEscape (CVE-2026-17106): A Malicious Container Can Overwrite Files on the Docker Host via `docker cp`

    CVE-2026-17106 ('CopyEscape'), found by Imperva's Red Team, lets a malicious or compromised container hijack docker cp to overwrite arbitrary files on the host — and, when the copy runs with elevated privileges, replace runc to get root. Docker has shipped fixes across Engine, Desktop, and Sandboxes.

    container-escaperceprivilege-escalationcloudlinux
  • vulnerabilities 2026-08-12

    Cisco ASA and FTD Under Active Attack: Unauthenticated VPN Flaw Reloads Firewalls On Demand (CVE-2026-20349)

    CVE-2026-20349, an unauthenticated heap inspection flaw in Cisco ASA and FTD's Remote Access SSL VPN service, is being actively exploited to remotely crash firewalls — CISA gave federal agencies until August 14 to patch, and no workaround exists.

    active-exploitationcisa-kevnetwork-appliancevpndenial-of-service
  • vulnerabilities 2026-08-12

    Lazarus Burned a Windows Kernel Zero-Day to Deploy FudModule Before Patch Tuesday Shipped

    CVE-2026-68820, a use-after-free in the Windows AFD.sys WinSock driver, was exploited by North Korea's Lazarus group to deploy an upgraded FudModule rootkit weeks before Microsoft's August Patch Tuesday fix shipped.

    active-exploitationzero-dayprivilege-escalationwindowsapt
  • vulnerabilities 2026-08-11

    BdThemes Supply Chain Attack: Poisoned JSON Feed Creates Rogue WordPress Admins Without Touching a Single Plugin File

    Attackers compromised BdThemes' vendor infrastructure and poisoned a promotional-banner JSON feed served to 100,000+ WordPress sites, hijacking admin sessions to plant rogue accounts and a persistent webshell — no plugin update required.

    supply-chainwordpressbackdoorcredential-theftxss
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss