🚨 CVE-2026-23898: Joomla! Core - [20260305] - Arbitrary file deletion in com_joomlaupdate
Joomla Autoupdate Server Allows Arbitrary File Deletion
Attackers can bypass input validation in Joomla's autoupdate server endpoint by supplying crafted file paths (e.g., via directory traversal or unfiltered filenames), resulting in deletion of arbitrary files on the web server filesystem with web server privileges.
Full Vulnerability Details & Analysis at DarkEye:
🔗 https://t.co/uRru6J1srC
🔍 Identify Targets via ZoomEye:
Filter: vul.cve="CVE-2026-23898"
Search Dork: app="Joomla"
Exposure: 125.5k+ instances identified globally.
ZoomEye Search Link:
👉 https://t.co/sQGBd30jc5
#Joomla #ArbitraryFileDeletion #CVE202623898 #InputValidation #WebServerExploit #DarkEye
🚨‼️ BREAKING: PyPI package telnyx has been compromised by TeamPCP in yet another supply chain attack.
The malware executes immediately upon importing telnyx. It drops a valid WAV audio file and runs an executable embedded within the frames.
Software horror: litellm PyPI supply chain attack.
Simple `pip install litellm` was enough to exfiltrate SSH keys, AWS/GCP/Azure creds, Kubernetes configs, git credentials, env vars (all your API keys), shell history, crypto wallets, SSL private keys, CI/CD secrets, database passwords.
LiteLLM itself has 97 million downloads per month which is already terrible, but much worse, the contagion spreads to any project that depends on litellm. For example, if you did `pip install dspy` (which depended on litellm>=1.64.0), you'd also be pwnd. Same for any other large project that depended on litellm.
Afaict the poisoned version was up for only less than ~1 hour. The attack had a bug which led to its discovery - Callum McMahon was using an MCP plugin inside Cursor that pulled in litellm as a transitive dependency. When litellm 1.82.8 installed, their machine ran out of RAM and crashed. So if the attacker didn't vibe code this attack it could have been undetected for many days or weeks.
Supply chain attacks like this are basically the scariest thing imaginable in modern software. Every time you install any depedency you could be pulling in a poisoned package anywhere deep inside its entire depedency tree. This is especially risky with large projects that might have lots and lots of dependencies. The credentials that do get stolen in each attack can then be used to take over more accounts and compromise more packages.
Classical software engineering would have you believe that dependencies are good (we're building pyramids from bricks), but imo this has to be re-evaluated, and it's why I've been so growingly averse to them, preferring to use LLMs to "yoink" functionality when it's simple enough and possible.
🚨 It’s here! p3rf3ctr00t CTF 2025 💥
🗓 5th–7th Dec 2025 | 18:00 GMT+3
⚡ 48 hours of hacking madness — Web, Forensics, Crypto & more!
Register now : https://t.co/GNbeyq4nHa
The event is also live on https://t.co/z0hY7vf8xh :- https://t.co/cTXEkZ38MB
#p3rf3ctr00tCTF#CTF2025
🗣️🗣️The wait is almost over! P3rf3ctr00t CTF 2025 is around the corner — bigger, tougher, and more thrilling than ever.🎉
Gear up to test your skills, push your limits, and prove your dominance in the cybersecurity arena.🔥🔥
💥 Coming soon…
Thanks to all our partners🙏🙏
A new NetExec module: certipy-find🔥
As ADCS is still configured insecurely in many environments, I decided to integrate the certipy find command into NetExec.
Now you can quickly find and enumerate vulnerable templates before bringing out the big guns.
Had a blast solving challenges at the @AcdfNetworks Cyberlympics Finals hosted by @CTF_Room.
Props to my crew @p3rf3ctr00t for holding it down and keeping us on top from start to finish.
Ops executed, flags captured,locks picked and scoreboard conquered.
On to the next target...
Just had a Eureka moment on @hackthebox_eu!
Explored some interesting service discovery behaviour and turned into a learning adventure. Always amazed by how much you can uncover with a curious mindset
#HTB#CyberSecurity#redteam#EthicalHacking