Security things from the last few days:
- CopyFail (linux pwn'd)
- CopyFail 2/Dirty Frag
- 13 advisories in Next.js
- Over 70 CVEs addressed in MacOS 26.5
- ~50 CVEs addressed in iOS 26.5
- YellowKey (Windows Bitlocker pwn'd entirely)
- GreenPlasma (Windows privilege escalation)
- CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE
- CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access
- Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning)
- Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too"
- Canvas (popular LMS used in most schools) pwn'd entirely
- PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300
Are you scared yet?
- XZ utils backdoor: found by guy debugging 200ms latency
- LiteLLM hack: found by guy debugging oom issue
These could have been the most impactful compromises ever.
Forget security vendors, weaponize your engineers’ autism.
“The largest supply chain compromise in npm, Inc. history just happened, packages with a total of 2 billion weekly downloads just got turned malicious”
LinkedIn Post
https://t.co/dJ0tlPrSBJ
More info on hacker news
https://t.co/uncwjtFgxT
Excited to present at @sectorca in Toronto for the second year! Join me & @MoritzLThomas for "Volatile Vault: Data Exfiltration in 2024"
Discover how our platform evades DLP systems. Let's connect! #CyberSecurity#redteam@NVISO_Labs
We are thrilled to announce that the schedule for the event is now available online! Make sure you don't miss any of the amazing sessions. We can't wait to see you there! https://t.co/IDQHklcpcc
🚨Alert🚨CVE-2024-5655(CVSS 9.6): Run pipelines as any user
🔗Hunter Link: https://t.co/9pVvUtoQsJ
⚠This flaw allows attackers to trigger pipelines as another user under specific conditions, posing a significant security risk.
📊2.3M+ Services are found on https://t.co/g3tSyh1Boc
📰Refer:https://t.co/MX5tclql6I
👇Query
Hunter: /product.name="GitLab"
FOFA: app="GitLab"
SHODAN: http.component:"GitLab"
#GitLab #hunterhow #infosec #infosecurity #Infosys #Vulnerability
⚠️0-click #RCE in Outlook⚠️
The #CVE-2024-30103 vulnerability leverages a flaw in how Microsoft Outlook handles specific types of email content. An attacker can embed malicious code within the body of an email, which gets executed as soon as the email is opened.
🚨Alert🚨CVE-2024-30103: Microsoft Outlook Remote Code Execution Vulnerability
⚠This Microsoft Outlook vulnerability can be circulated from user to user and doesn’t require a click to execute. Rather, execution initiates when an affected email is opened.This is notably dangerous for accounts using Microsoft Outlook’s auto-open email feature.
📰Refer: https://t.co/QEiHf8iwtH
#Outlook #Microsoft #hunterhow #infosec #infosecurity #Infosys #Vulnerability
We've expanded our #RedTeam arsenal with a new awesome Windows LPE BOF for #CobaltStrike and #BruteRatel thanks to the original exploit author @varwara.
Get your copy here! https://t.co/ZYno3mbLz5