cybercrime.club_ // where builders track threats
Latest Deep Dives Supply Chain Ransomware Tags About
  • vulnerabilities 2026-05-25

    Ghost CMS CVE-2026-26980: Unauthenticated SQL Injection Powers a 700-Site ClickFix Campaign

    CVE-2026-26980 is a CVSS 9.4 unauthenticated SQL injection in Ghost's Content API. A patch shipped in February; attackers have since industrialized it into an automated campaign that has hijacked 700+ sites — including Harvard, Oxford, and DuckDuckGo — to serve ClickFix malware.

    sql-injectionclickfixweb-securityactive-exploitation
  • Supply Chain 2026-05-25

    TrapDoor: Cross-Ecosystem Supply Chain Attack Plants Credential Stealers and AI-Assistant Backdoors

    A coordinated campaign across npm, PyPI, and Crates.io seeded 34+ malicious packages that steal developer secrets and plant hidden instructions to weaponize AI coding assistants.

    supply-chainnpmpypicredential-theftmalware
  • supply-chain 2026-05-24

    Megalodon: 5,561 GitHub Repos Backdoored With Malicious CI/CD Workflows in Six Hours

    An automated campaign tied to TeamPCP pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window, planting CI/CD workflows that exfiltrate cloud credentials and OIDC tokens at scale.

    supply-chaingithub-actionsci-cdcredential-theftteampcp
  • vulnerabilities 2026-05-24

    LiteSpeed cPanel Plugin CVE-2026-48172: Any User Can Run Scripts as Root

    A CVSS 10.0 flaw in the LiteSpeed User-End cPanel Plugin lets any logged-in cPanel user execute scripts as root. It is being exploited in the wild — patch or uninstall now.

    cpanelprivilege-escalationactive-exploitation
  • deep dive 2026-05-24 12 min read

    The Edge Device Audit: Turn CISA's BOD 26-02 Into a Playbook You Can Actually Run

    CISA's BOD 26-02 just handed every infrastructure team a free edge-device audit checklist. Here is how to run it on your own network — inventory, version, exposure, and end-of-support triage — before an attacker runs theirs.

    network-appliancevulnerability-managementcisa-kevvpn
  • incident 2026-05-23

    The 'Private-CISA' Leak: A Contractor Left GovCloud Keys and Artifactory Creds Public on GitHub for Six Months

    A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, internal Artifactory credentials, and plaintext passwords to dozens of agency systems for roughly six months.

    cisa
  • Supply Chain 2026-05-23

    Laravel-Lang Supply Chain Attack: 233 Package Versions Backdoored to Steal Cloud and CI/CD Secrets

    Attackers repointed git tags across four Laravel-Lang Composer packages to a malicious fork, backdooring 233 versions with a credential stealer that drains cloud, CI/CD, and developer secrets.

    supply-chaincredential-theftmalware
  • vulnerabilities 2026-05-22

    Trend Micro Apex One CVE-2026-34926: Directory Traversal Turns the EDR Server Into a Malware Dropper

    A directory traversal flaw in on-premise Trend Micro Apex One lets an attacker who already holds server admin access poison the agent build and push malicious code to every managed endpoint. CISA added it to KEV after confirmed in-the-wild exploitation.

    cisa-kev
  • vulnerabilities 2026-05-22

    Cisco Secure Workload CVE-2026-20223: Unauthenticated API Flaw Hands Over Site Admin

    A CVSS 10.0 flaw in Cisco Secure Workload lets unauthenticated attackers reach internal REST APIs with Site Admin privileges across tenant boundaries. No workarounds — patch now.

    ciscoauthentication-bypass
  • vulnerabilities 2026-05-21

    Two More Defender Zero-Days in the Wild: CVE-2026-41091 Link-Resolution Bug Lands SYSTEM, Added to CISA KEV

    Microsoft confirms two Defender flaws — an LPE to SYSTEM and a DoS — are publicly disclosed and exploited in the wild. A third RCE ships in the same engine update. CISA gives federal agencies until June 3.

    windowsprivilege-escalationzero-daycisa-kev
  • supply-chain 2026-05-21

    actions-cool/issues-helper Compromised: Every Tag Repointed to a Credential-Stealing Imposter Commit

    An attacker repointed all 53 tags of the popular actions-cool/issues-helper GitHub Action to a single imposter commit that scrapes live CI/CD secrets out of runner process memory.

    supply-chaingithub-actionsci-cdcredential-theft
  • vulnerabilities 2026-05-20

    Drupal SA-CORE-2026-004: Highly Critical Unauthenticated SQL Injection Hits PostgreSQL Sites

    CVE-2026-9082 is a highly critical SQL injection in Drupal core's database abstraction API. Anonymous attackers can run arbitrary SQL against PostgreSQL-backed sites. Patches dropped May 20; exploitation is expected within days.

    sql-injectionpostgresqlweb-security
  • supply-chain 2026-05-20

    Nx Console VS Code Extension Compromised: Orphan-Commit Stealer Hits a 2.2M-Install Developer Tool

    A compromised Nx Console 18.95.0 extension pulled a 498 KB stealer from an orphan commit in the official nrwl/nx repo, harvesting GitHub, npm, AWS and Vault secrets — and shipped tooling to forge signed npm provenance.

    supply-chainnpm
  • vulnerability 2026-05-19

    SEPPmail Secure Email Gateway: Seven Flaws Including CVSS 10.0 Path Traversal to RCE

    InfoGuard Labs discloses seven vulnerabilities in SEPPmail Secure E-Mail Gateway, including a CVSS 10.0 path-traversal-to-RCE bug and an unauthenticated Perl eval injection — full appliance takeover and mail-traffic interception.

    rcepath-traversal
  • vulnerabilities 2026-05-19

    Ollama CVE-2026-7482 'Bleeding Llama': Heap OOB Read in GGUF Loader Leaks Server Memory to Unauthenticated Attackers

    A heap out-of-bounds read in Ollama's GGUF model loader (CVE-2026-7482, CVSS 9.1) lets unauthenticated attackers exfiltrate server process memory — including API keys, env vars, system prompts, and other users' conversations — from an estimated 300,000+ exposed instances.

    ai-infrastructureheap-overflow
  • vulnerabilities 2026-05-18

    MiniPlasma: Public PoC Hands SYSTEM on Fully Patched Windows 11 via cldflt.sys

    Chaotic Eclipse published a working PoC for MiniPlasma, a Cloud Filter driver LPE that abuses CfAbortHydration to forge .DEFAULT-hive registry keys — the same bug Microsoft was told about in 2020 and claimed to have fixed.

    windowszero-dayprivilege-escalationlpe
  • vulnerability 2026-05-18

    CloudNativePG CVE-2026-44477: Metrics Exporter Escalates Any DB User to Postgres Superuser and Host RCE

    A residual session_user=postgres in CloudNativePG's metrics exporter lets any low-privileged database user RESET ROLE back to superuser and reach OS-level command execution via COPY TO PROGRAM. CVSS 9.4. Patched in 1.28.3 and 1.29.1.

    postgresqlkubernetesrceprivilege-escalation
  • breach 2026-05-17

    Grafana Refuses Ransom After CoinbaseCartel Pwn Request Attack Steals Source Code From Five Repos

    Grafana Labs disclosed that CoinbaseCartel exploited a GitHub Actions pull_request_target misconfiguration to steal privileged CI tokens and pivot into five private repos. A canary token tripped the breach; the company refused the ransom demand.

    github-actionssupply-chainextortion
  • Vulnerabilities 2026-05-17

    YellowKey and GreenPlasma: Same Researcher Drops Two More Windows Zero-Days, BitLocker Bypass via WinRE USB

    The anonymous researcher behind BlueHammer is back with YellowKey, a BitLocker bypass that drops a CMD shell on protected drives via crafted FsTx files in WinRE, plus GreenPlasma, a CTFMON privilege escalation. No CVE, no patch.

    windowszero-dayprivilege-escalationendpoint-security
  • deep dive 2026-05-17 15 min read

    NTLM Coercion's Quiet Resurgence: Why 2026's Zero-Click Attacks Look Like 2021

    Two unrelated bugs in the last month — an incomplete APT28 patch and an unpatched RPC defect — both hand attackers a 1990s-era credential primitive. The fact that NTLM coercion still works in 2026 is not a series of accidents. It is the model.

    windowsactive-directorytrend-analysisopinion
← newer1234567891011121314older →
© 2026 Max Clinton rss