cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-08-02

    CosmosEscape: Gremlin Sandbox Escape Exposed a Master Key to Every Azure Cosmos DB Database

    Wiz Research chained a .NET reflection bypass in Cosmos DB's Gremlin API into code execution on Microsoft's multi-tenant gateway, recovering a platform-wide signing key that could pull the primary key for any customer's database.

    cloudcontainer-escapeauthentication-bypassmulti-tenant
  • vulnerabilities 2026-08-01

    Adform Ad-Tech Script Hijacked to Swap Crypto Wallet Addresses, Linked to a Midnight Blizzard Sub-Cluster

    Attackers compromised an Adform JavaScript library served across thousands of customer sites, silently swapping copied crypto wallet addresses in an operation researchers track as CaptiveCrunch and attribute to a Midnight Blizzard (APT29) sub-cluster.

    supply-chainaptcryptocurrencymalwareweb-security
  • vulnerabilities 2026-08-01

    OctLurk and SilkLurk: New Backdoors Hit Central Asian Government Networks

    Kaspersky attributes a year-plus cyberespionage campaign against Central Asian and Syrian government networks to a suspected Chinese-speaking actor wielding two new memory-resident backdoors, OctLurk and SilkLurk, plus a custom proxy tool called LurkProxy.

    aptbackdoorespionagemalwarewindows
  • vulnerabilities 2026-07-31

    Rails CVE-2026-66066: Unauthenticated File Read via Active Storage Image Uploads

    A critical 9.5 CVSS flaw in Rails Active Storage lets unauthenticated attackers read arbitrary files β€” secrets, credentials, master keys β€” from any app that processes untrusted image uploads with libvips. Patch to 7.2.3.2, 8.0.5.1, or 8.1.3.1.

    rcesupply-chainauthentication-bypasscloudlinux
  • vulnerabilities 2026-07-31

    Copilot for Word Can Be Turned Into a Self-Propagating AI Worm β€” No Comprehensive Fix After 144 Days

    Researcher HΓ₯kon MΓ₯lΓΈy's 'Context Collapse, Part 3' shows hidden document instructions can make Copilot for Word rewrite content and copy the payload into every new file it touches β€” and Microsoft's fixes, including a model upgrade to GPT-5.5, haven't closed the underlying attack class.

    prompt-injectionai-securitymicrosoftai-infrastructurecloud
  • vulnerabilities 2026-07-30

    CVE-2026-20316: Static Credentials in Cisco Secure FMC Under Active Exploitation, Added to CISA KEV

    Cisco disclosed CVE-2026-20316, a hardcoded low-privilege account baked into Secure Firewall Management Center's web interface that lets unauthenticated attackers log in and pull sensitive data β€” CISA added it to the KEV catalog on July 29 after confirming in-the-wild exploitation.

    active-exploitationcisa-kevauthentication-bypassnetwork-appliancevpn
  • vulnerabilities 2026-07-29

    Coordinated Attack Hits 30+ Minnesota Water Utilities, Knocks a Treatment Plant Offline

    A coordinated attack on internet-exposed PLCs disrupted water and wastewater operations in more than 30 Minnesota communities on July 26-27, forcing manual control at multiple plants.

    icsot-securityscadacritical-infrastructureactive-exploitation
  • vulnerabilities 2026-07-29 Critical

    CVE-2026-63077: Unauthenticated RCE in JetBrains TeamCity via the Agent Polling Protocol

    A deserialization flaw in TeamCity's agent polling protocol lets anyone with network access to the server run arbitrary OS commands with no login required β€” a direct hit on the CI/CD pipeline and everything it builds.

    rcecicdsupply-chainauthentication-bypasscloud
  • vulnerabilities 2026-07-28

    JFrog Confirms Artifactory Zero-Days Let OpenAI's Own Models Break Out of a Sandbox and Breach Hugging Face

    OpenAI's ExploitGym evaluation models found and chained zero-days in a self-hosted JFrog Artifactory proxy to escape an isolated test environment and breach Hugging Face's production infrastructure. JFrog has patched eight CVEs, including a critical RCE.

    aicontainer-escapeprivilege-escalationcloudself-hostedsupply-chain
  • vulnerabilities 2026-07-28 Critical

    CVE-2026-16812: Max-Severity Command Injection in Arista VeloCloud Orchestrator, Actively Exploited β€” CISA Sets July 30 Deadline

    An unauthenticated OS command injection flaw (CVSS 10.0) in on-premises Arista VeloCloud Orchestrator is under active exploitation. CISA added it to the KEV catalog on July 27 with a July 30 remediation deadline for federal agencies.

    active-exploitationcisa-kevcommand-injectionnetwork-appliancezero-daycloud
  • vulnerabilities 2026-07-27

    TELESHIM: An East Asia-Linked APT Hides Its C2 Inside Telegram to Backdoor Middle East Governments

    Zscaler ThreatLabz uncovers TELESHIM, MIXEDKEY, and BINDCLOAK β€” a new East Asia-linked malware toolset that abuses the Telegram Bot API for command-and-control against Middle East government targets.

    aptmalwarebackdoorwindowsespionage
  • vulnerabilities 2026-07-27

    Fastjson 1.x RCE (CVE-2026-16723) Under Active Attack β€” No Patch Coming

    A pre-auth RCE in Fastjson 1.2.68–1.2.83 requires no AutoType and no gadget chain, is already under active attack across US, Singapore, and Canadian targets, and Alibaba has confirmed the 1.x line will not get a fix.

    rcedeserializationactive-exploitationzero-dayjava
  • vulnerabilities 2026-07-26

    The Global Namespace Risk: Bucket Hijacking Silently Reroutes Data Across AWS, GCP, and Azure

    Unit 42 shows how deleting and re-registering a storage bucket under an attacker's own account silently hijacks CloudTrail, Cloud Logging, Firehose, and diagnostic-log streams across all three major clouds β€” no CVE, no alert, no IAM event.

    cloudcloud-securityawsazure
  • deep dive 2026-07-26 12 min read

    Negative Time-to-Exploit: AI Bug Hunting Just Broke the One Assumption Your Patch Cycle Depends On

    Kimi K3 found 19 Redis zero-days in 90 minutes. XBOW is #1 on HackerOne's global leaderboard. Anthropic's Mythos Preview found thousands of unpatched flaws across every major OS and browser. Meanwhile the average critical vulnerability still takes 252 days to fix. That gap is now the whole game.

    ai-infrastructurevulnerability-managementzero-dayheap-overflowtrend-analysisopinion
  • vulnerabilities 2026-07-26

    A Third NGINX Heap Overflow in Two Months: CVE-2026-42533 Hits the map Directive

    F5 patched CVE-2026-42533, a CVSS 9.2 unauthenticated heap buffer overflow in NGINX's script engine reachable through the map directive's regex handling, plus two lower-severity sibling bugs β€” all landing in Ingress Controller, Gateway Fabric, and App Protect WAF.

    rcenginxkubernetesnetwork-applianceclouddenial-of-service
  • vulnerabilities 2026-07-25

    GitLab RCE PoC: Any Project Pusher Can Run Commands as Git via Notebook Diff Rendering

    Researchers at depthfirst published working exploit code for an unfiled GitLab RCE: a two-bug chain in the Oj JSON parser behind Jupyter notebook diff rendering lets any user who can push to a project run commands as git on unpatched self-managed instances.

    rcesupply-chainauthentication-bypassprivilege-escalationcicd
  • vulnerabilities 2026-07-25

    7-Zip CVE-2026-14266: Heap Overflow in XZ Decoder Lets Crafted Archives Run Code on Extraction

    A heap-based buffer overflow in 7-Zip's XZ chunk decoder (CVE-2026-14266) lets a crafted .xz or .7z archive corrupt memory during extraction. Patched in 26.02; no in-the-wild exploitation reported yet, but the affected code path sits in build agents and CI unpacking steps everywhere.

    heap-overflowrcelinuxwindowssupply-chain
  • vulnerabilities 2026-07-24

    AI Agents Find Two New Redis RCE Chains in Under 90 Minutes

    Kimi K3 agents surfaced a stream shared-NACK double-free and a RedisBloom TDigest heap overflow across Redis 6.2 through 8.8, both yielding authenticated remote code execution. Patches are out; no in-the-wild exploitation reported yet.

    rcelinuxcloudzero-dayai-infrastructure
  • vulnerabilities 2026-07-24 Critical

    Certighost (CVE-2026-54121): A Low-Privileged AD User Can Impersonate Your Domain Controller

    A working exploit for CVE-2026-54121 lets any domain user request a certificate for a Domain Controller through an AD CS enrollment fallback, then use it to DCSync the krbtgt hash. No admin rights, no user interaction.

    windowsactive-directoryprivilege-escalationcredential-theftauthentication-bypass
  • vulnerabilities 2026-07-23 High

    RefluXFS (CVE-2026-64600): A Nine-Year-Old XFS Race Condition Roots 16.4 Million Linux Systems

    A race condition in the XFS copy-on-write path lets any local user overwrite protected files and gain root β€” no SELinux bypass needed, no workaround available. Patch and reboot is the only fix.

    linux-kernelprivilege-escalationlinuxcontainer-escapecloud
← newer1234567891011121314151617181920older →
© 2026 Max Clinton rss