cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • deep dive 2026-08-11 12 min read

    Inside the AI-Orchestrated EDR Evasion Lab: What Sophos Actually Found, and Why the Bug Wasn't in the Malware

    Sophos recovered a fully autonomous malware R&D pipeline — a coordinator agent, four subordinate agents, a self-provisioned lab, and 80 evasion modules built against three EDR vendors. The interesting part isn't that it worked. It's the one thing in the whole pipeline that didn't.

    ransomwareedr-evasionai-infrastructurecobalt-strikedetection-engineeringtrend-analysis
  • vulnerabilities 2026-08-11

    First-of-Its-Kind Attack Pivots Through a Private Cellular APN to Sabotage Siemens PLCs at a Polish Power Plant

    CERT Polska details a December 2025 attack that pivoted through a distribution operator's private cellular APN — from a compromised wind farm firewall to Siemens PLCs at a combined heat and power plant, halting a turbine.

    icsot-securityscadacritical-infrastructurenetwork-applianceactive-exploitation
  • vulnerabilities 2026-08-10

    Head Mare Exploits Unpatched TrueConf Servers to Trojanize Client Installers with PhantomCore and PhantomGraph

    Head Mare is chaining two unpatched TrueConf videoconferencing server flaws to reach SYSTEM, then replacing legitimate client installers with trojanized builds that drop the PhantomCore and PhantomGraph backdoors.

    active-exploitationsupply-chainbackdoorprivilege-escalationwindowsapt
  • vulnerabilities 2026-08-10

    Langflow's Third KEV Entry of the Year: CVE-2026-9198 Chains Auto-Login Bypass to Unauthenticated RCE

    CVE-2026-9198 chains an unauthenticated auto-login token mint with an unsandboxed code-validation endpoint to give attackers full RCE on default IBM Langflow deployments, now under active exploitation and CISA KEV.

    cisa-kevactive-exploitationrceai-infrastructureauthentication-bypass
  • vulnerabilities 2026-08-09

    XSS2Shell: WordPress Pre-Auth Login XSS Chains to Full RCE (CVE-2026-64638)

    CVE-2026-64638 lets an unauthenticated attacker plant XSS on WordPress's login screen with a single failed-login attempt, then chain DOM clobbering and a REST API JSONP callback to steal an admin's Application Password and execute PHP. Patch to 7.0.3.

    rceauthentication-bypasscmszero-day
  • vulnerabilities 2026-08-09

    Jenkins CVE-2026-70426: Remoting Deserialization Filter Bypass Enables Controller RCE

    CVE-2026-70426 (CVSS 9.0) lets an attacker with agent-level access bypass Jenkins' JEP-200 class filter via a fallback path in Remoting, achieving code execution on the controller. Patch to 2.576 / LTS 2.568.2 now.

    deserializationrceci-cdsupply-chain
  • vulnerabilities 2026-08-08

    Microsoft Patches Four CVSS 9.9 Flaws Spanning Azure Service Bus, Azure SRE Agent, Entra Provisioning, and Active Directory

    Microsoft quietly shipped fixes for four unrelated CVSS 9.9 flaws — an unauthenticated-adjacent RCE in Azure Service Bus and privilege-escalation bugs in Azure SRE Agent, Entra Provisioning Service, and on-prem Active Directory — all remotely exploitable and disclosed August 6.

    azureactive-directoryprivilege-escalationrceclouddeserialization
  • vulnerabilities 2026-08-08

    SCTPhantom (CVE-2026-64564): An 18-Year-Old Linux Kernel SCTP Bug Gives Local Root and Escapes Containers

    A use-after-free in the Linux kernel's SCTP ASCONF transport handling, present since 2008, lets a local attacker with SCTP reachability escalate to root and, on affected configurations, escape containers.

    linux-kernelprivilege-escalationuse-after-freecontainer-escapezero-daylinux
  • vulnerabilities 2026-08-07

    Metabase Zero-Day: Unauthenticated SQL Injection (CVSS 10.0) Exploited to Breach Framework and Tally

    A pre-auth SQL injection in Metabase's password-reset endpoint let attackers hijack admin access on customer instances, hitting Metabase Cloud tenants Framework and Tally before a patch shipped.

    active-exploitationsql-injectionauthentication-bypassdata-breachcloudsupply-chain
  • vulnerabilities 2026-08-07 High

    CVE-2026-34486: Apache Tomcat's EncryptInterceptor Fix Was Incomplete — Now Under Active Exploitation

    A second, incomplete patch for a Tomcat clustering flaw lets attackers bypass pre-shared-key encryption and reach Java deserialization on the cluster port — CISA gave federal agencies until today to fix it.

    rceactive-exploitationcisa-kevaptjava-deserializationnetwork-appliance
  • vulnerabilities 2026-08-06

    OVSwrap (CVE-2026-64531): 13-Year-Old Linux Kernel Bug in Open vSwitch Gives Any Local User Root

    A 16-bit integer wraparound in the Linux kernel's Open vSwitch action parser (CVE-2026-64531, 'OVSwrap') lets any unprivileged local user become root — no OVS configuration, no CAP_NET_ADMIN, no container privileges required. A public PoC ships precomputed offsets for ~800 kernel builds.

    privilege-escalationlinux-kernellinuxcloudkubernetes
  • vulnerabilities 2026-08-06

    15 TP-Link Omada Flaws Turn Zero-Touch Provisioning Into a Network Takeover Path

    Forescout's Vedere Labs found 15 flaws in TP-Link's Omada zero-touch provisioning ecosystem — hardcoded crypto keys, a predictable RC4 cipher, and weak cert validation that chain into full controller and fleet compromise.

    network-applianceauthentication-bypassman-in-the-middleiotcloud
  • vulnerabilities 2026-08-05

    Cisco Ships Two CVSS 9.8+ 'Hardening Releases' for IOS XE and Catalyst SD-WAN in One Day

    Cisco's August 5 disclosure batch bundles seven CWE-grouped IOS XE flaws (CVSS 9.8) and five Catalyst SD-WAN flaws (CVSS 9.9) into umbrella CVEs — the first big test of its new AI-driven, twice-monthly hardening-release disclosure model.

    cisconetwork-applianceprivilege-escalationsd-wanlinux
  • vulnerabilities 2026-08-05

    QuickFox VPN Installer Trojanized for a Year to Deliver Mustang Panda's FDMTP Backdoor

    A trojanized QuickFox VPN Windows installer quietly delivered the FDMTP backdoor for roughly a year, with Fortinet linking the campaign to Chinese state-sponsored actor Mustang Panda.

    supply-chainaptvpnbackdoormalwarewindows
  • vulnerabilities 2026-08-04

    Keyv npm Worm Hits 800+ Packages, Pulls C2 From an Ethereum Smart Contract

    A compromised keyv@6.0.0 release triggered a self-propagating npm worm that poisoned 800+ packages in hours, planting Claude Code and VS Code persistence hooks and fetching C2 addresses via live Ethereum smart-contract calls.

    supply-chainnpmshai-huludcredential-theftci-cdinstall-time-execution
  • vulnerabilities 2026-08-04

    ExfilSquad's Power Pages Rampage Hits UK Police Legal Database, 14 Other Victims

    A new extortion group, ExfilSquad, is scraping data straight out of misconfigured Microsoft Power Pages portals with no exploit required — its highest-profile victim so far is the UK's Police National Legal Database, exposing contact data for 135,000 officers and justice staff.

    cloudmisconfigurationdata-breachextortiongovernment
  • vulnerabilities 2026-08-03

    N-able's First Patch Didn't Hold: CVE-2026-18577 Bypasses the CVE-2026-18556 Fix for Full N-central Takeover

    N-able's emergency fix for an N-central authentication bypass proved incomplete — a new CVE, CVE-2026-18577, lets attackers bypass the patch entirely for unauthenticated 'god-mode' access, and it's being actively exploited against MSPs.

    active-exploitationauthentication-bypassnetwork-appliancecloudprivilege-escalation
  • vulnerabilities 2026-08-03

    Broadcom Patches Two CVSS 9.8 vCenter Auth Bypass/RCE Flaws and an ESXi VM Escape (VMSA-2026-0006)

    Broadcom's VMSA-2026-0006 patches two unauthenticated, CVSS 9.8 vCenter Server flaws (auth bypass and directory-traversal RCE) plus a VMXNET3 VM escape in ESXi — no workarounds exist for either critical vCenter bug.

    cloudauthentication-bypassrcecontainer-escapenetwork-appliance
  • vulnerabilities 2026-08-02

    N-able N-central Authentication Bypass (CVE-2026-18556) Exploited to Hijack Managed Endpoints via Take Control and Cloudflare Tunnels

    An authentication bypass in N-able's N-central RMM platform, tracked as CVE-2026-18556, was exploited in the wild to gain admin access and pivot into managed customer environments using Take Control and rogue Cloudflare tunnels.

    active-exploitationauthentication-bypassnetwork-applianceremote-monitoringcloud
  • deep dive 2026-08-02 11 min read

    The Tenant Boundary Is a Fiction: Inside 2026's Cloud Cross-Tenant Bug Class

    Five major cross-tenant breaks in twelve months — Cosmos DB, Vertex AI, Entra ID, AKS Backup — share one root cause: a privileged control-plane identity that trusts a customer-supplied name, key, or token it should never have accepted. Here's the pattern, and what to actually do about it.

    cloudcloud-securitymulti-tenantauthentication-bypasstrend-analysisopinion
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss