cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-06-15

    Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild — Patch Every Chromium Runtime, Not Just Browsers

    Google patched CVE-2026-11645, an actively exploited out-of-bounds read/write in V8. The real blast radius is every Chromium runtime you operate — headless Chrome in CI, Electron apps, and server-side renderers.

    chromezero-dayrcecisa-kev
  • vulnerabilities 2026-06-14

    Splunk Enterprise CVE-2026-20253: An Unauthenticated Postgres Sidecar Hands Over Pre-Auth RCE

    CVE-2026-20253 (CVSS 9.8) is a pre-auth RCE in Splunk Enterprise. An unauthenticated Postgres sidecar endpoint gives an arbitrary file write that escalates to code execution — on the box holding all your logs. Full exploit details are public; patch now.

    ciscopostgresqlrcepre-authsieminfrastructure
  • vulnerabilities 2026-06-14

    Veeam VBR CVE-2026-44963: Any Domain User Can Own Your Backup Server

    A critical CVSS 9.4 RCE lets any authenticated domain user run code on domain-joined Veeam Backup & Replication servers. Patch to 12.3.2.4854 now.

    rceransomwareactive-directory
  • deep dive 2026-06-14 11 min read

    eBPF Cuts Both Ways: The Kernel Rootkit Is Now Standard Issue in 2026's Supply-Chain Malware

    In two weeks, IronWorm and the atomic-lockfile AUR compromise both shipped an eBPF kernel rootkit as just another payload module. The observability primitive your stack is built on is now the malware's stealth layer — and most detection assumptions are structurally defeated.

    ebpfrootkitlinuxedr-evasionsupply-chaintrend-analysis
  • vulnerabilities 2026-06-13

    Proto6: Six protobuf.js Flaws Turn Trusted Schemas Into RCE and DoS Across gRPC, Cloud, and AI Stacks

    Cyera's Proto6 research discloses six CVEs in protobuf.js, including a prototype-pollution-to-RCE chain, in a library pulled 50M+ times a week across gRPC, Google Cloud SDKs, vector databases, and CI/CD.

    supply-chainrcenodejsgrpcci-cd
  • supply-chain 2026-06-12

    400+ AUR Packages Compromised: atomic-lockfile npm Payload Drops Credential Stealer With eBPF Rootkit

    Over 400 Arch User Repository packages were modified to pull a malicious npm package that deploys a developer-focused credential stealer with optional root-only eBPF rootkit capabilities.

    supply-chainnpmebpfrootkitinfostealerlinux
  • policy 2026-06-12

    CISA Kills the Flat KEV Deadline: BOD 26-04 Starts a Three-Day Patch Clock

    BOD 26-04 revokes BOD 22-01 and 19-02, replacing flat KEV due dates with risk-tiered deadlines: three days plus mandatory forensic triage for internet-facing, automatable, total-control flaws.

    cisavulnerability-management
  • vulnerabilities 2026-06-11

    Oracle Ships Out-of-Band Fix for PeopleSoft Zero-Day CVE-2026-35273 as ShinyHunters Loots 100+ Orgs

    Oracle pushed an emergency alert for CVE-2026-35273, an unauthenticated CVSS 9.8 RCE in PeopleSoft PeopleTools. Mandiant confirms in-the-wild exploitation, and ShinyHunters claims data theft from 100+ organizations including the University of Nottingham.

    oraclercezero-dayshinyhuntersextortion
  • vulnerabilities 2026-06-09

    Microsoft's June Patch Tuesday Is Its Biggest Ever: 200 Flaws, 33 Critical, Three Public Zero-Days

    Microsoft's largest Patch Tuesday on record fixes 200 vulnerabilities including HTTP.sys and Kerberos KDC RCEs, three Hyper-V escapes, and the HTTP/2 Bomb and YellowKey BitLocker zero-days.

    microsoftpatch-tuesdayzero-dayhttp2active-directory
  • vulnerabilities 2026-06-09

    Cisco Unified CM CVE-2026-20230: Public PoC Turns an SSRF Into Root

    An unauthenticated SSRF in Cisco Unified Communications Manager (CVE-2026-20230) lets attackers write files to the OS and climb to root. PoC code is public, the 15-train fix is months out, and there's no workaround beyond disabling WebDialer.

    ciscossrfprivilege-escalation
  • vulnerabilities 2026-06-08 Critical

    CVE-2026-50751: Check Point VPN Auth Bypass Exploited by Qilin — IKEv1 Sessions Without a Password

    Check Point confirmed active exploitation of CVE-2026-50751, a CVSS 9.3 authentication bypass in Remote Access VPN and Mobile Access deployments running deprecated IKEv1. Attackers establish VPN sessions without a valid password; one case is tied to a Qilin ransomware affiliate. Earliest exploitation traces to May 7.

    vpnauthentication-bypassransomware
  • vulnerabilities 2026-06-08

    An AI Agent Found 21 Zero-Days in FFmpeg for $1,000 — and Your Container Images Are in Scope

    depthfirst's autonomous agent found 21 zero-days in FFmpeg for about $1,000, including a 23-year-old stack overflow. Nine carry CVEs (CVE-2026-39210 through CVE-2026-39218). FFmpeg is bundled everywhere — patch upstream and your embedded copies.

    ai-securityzero-daysupply-chain
  • threats 2026-06-07

    CISA and the FBI Warn: Internet-Exposed Fuel Tank Gauges Are Under Active Attack

    A June 2 joint advisory from CISA, the FBI, the NSA and five other agencies says attackers are compromising internet-exposed automatic tank gauge systems and modifying them through command execution. Shadowserver counts over 1,000 exposed, 909 in the US — on the same TCP port these consoles have answered on for a decade.

    icsotcritical-infrastructurecisafbiiran
  • supply-chain 2026-06-07

    Claude Code's GitHub Action: One Malicious Issue Could Hijack Any Public Repo

    A permission bypass chained with prompt injection in Anthropic's Claude Code GitHub Action let a single crafted issue make the agent leak CI secrets and OIDC request tokens — a clean path to poisoning the action's own supply chain. Patched in v1.0.94.

    supply-chaingithub-actionsci-cdai-security
  • deep dive 2026-06-07 13 min read

    Anatomy of the Interlock Campaign: How a ClickFix Gang Learned to Burn Firewall Zero-Days

    For a year, the surest way to get hit by Interlock was to paste a command into your own Run dialog. On January 26, 2026, the group stopped waiting for users to make mistakes and started exploiting a pre-auth, root-level Cisco firewall zero-day instead. The same crew now runs both ends of the sophistication ladder — and that should change how you model initial access.

    ransomwarecisconetwork-appliancedeserializationclickfixzero-daycisa-kev
  • vulnerabilities 2026-06-06

    SolarWinds Serv-U DoS Flaw CVE-2026-28318 Hits CISA KEV as Attackers Crash File Transfer Servers

    CISA added SolarWinds Serv-U CVE-2026-28318 to its KEV catalog after attackers began crashing file transfer servers with a single unauthenticated deflate-encoded POST. Patch to 15.5.4 HF1.

    cisa-kev
  • vulnerabilities 2026-06-06

    Cisco Catalyst SD-WAN Manager CVE-2026-20245: Root Command Execution, No Patch Yet

    Cisco's seventh SD-WAN zero-day of 2026. CVE-2026-20245 lets a netadmin upload a crafted file and execute commands as root on SD-WAN Manager. Exploited in the wild, no fix at disclosure.

    ciscosd-wanzero-dayactive-exploitationcommand-injection
  • vulnerabilities 2026-06-06

    Mirasvit Cache Warmer CVE-2026-45247: One Cookie Pops Any Magento Store, No Auth Required

    CISA added CVE-2026-45247 to KEV after Imperva confirmed active exploitation. A single crafted CacheWarmer cookie gives unauthenticated RCE on Magento and Adobe Commerce stores running Mirasvit Full Page Cache Warmer below 1.11.12.

    deserializationrcecisa-kev
  • threat-intel 2026-06-05

    Sophos Finds an AI-Orchestrated Lab That Auto-Builds EDR-Evasion Payloads for an Active Ransomware Crew

    Sophos X-Ops recovered a post-exploitation framework where AI agents read public research, mapped it to MITRE ATT&CK, and generated ~80 Rust and Go payloads tested against Sophos, CrowdStrike, and Microsoft EDR.

    ransomwareedr-evasioncobalt-strike
  • supply-chain 2026-06-04

    IronWorm: A Rust-Built npm Worm With an eBPF Rootkit and Tor C2

    JFrog dissected IronWorm, a self-replicating npm supply-chain worm written in Rust that hides behind an eBPF kernel rootkit, beacons over Tor, and steals 86 env vars and 20+ credential files. 36 packages hit before it was caught.

    supply-chainnpmebpfrootkitshai-hulud
← newer1234567891011121314older →
© 2026 Max Clinton rss