<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel>
<title>OFFSITE.DARK</title>
<link>https://offsitedark.com</link>
<description>Open source security research, malware analysis, and offensive tooling.</description>
<item>
      <title><![CDATA[Burst Statistics WordPress Auth Bypass (CVE-2026-8181)]]></title>
      <link>https://offsitedark.com/news/burst-statistics-auth-bypass-cve-2026-8181</link>
      <description><![CDATA[Sploitus-indexed flaw in is_mainwp_authenticated() lets unauthenticated attackers impersonate admins with any Basic Auth password.]]></description>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Cisco CUCM SSRF to RCE Chain (CVE-2026-20230)]]></title>
      <link>https://offsitedark.com/news/cisco-cucm-ssrf-rce-cve-2026-20230</link>
      <description><![CDATA[Sploitus-indexed PoC analysis chains unauthenticated WebDialer SSRF through Axis internals to arbitrary file write and RCE.]]></description>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Claude Desktop Cowork VM Integrity Bypass (CVE-2026-7574)]]></title>
      <link>https://offsitedark.com/news/claude-cowork-vm-bypass-cve-2026-7574</link>
      <description><![CDATA[Sploitus-indexed local flaw: Cowork trusts rootfs.img existence/version without hash or signature, enabling VM persistence.]]></description>
      <pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Krayin CRM TinyMCE Upload RCE (CVE-2026-38526)]]></title>
      <link>https://offsitedark.com/news/krayin-crm-rce-cve-2026-38526</link>
      <description><![CDATA[Sploitus-indexed authenticated PoC uploads PHP via /admin/tinymce/upload to public storage for www-data execution.]]></description>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[SP Page Builder Joomla Unauthenticated RCE (CVE-2026-48908)]]></title>
      <link>https://offsitedark.com/news/sp-page-builder-joomla-rce-cve-2026-48908</link>
      <description><![CDATA[Pre-auth ZIP upload to com_sppagebuilder iconfont path enables .PHP execution via .htaccess bypass; CVSS 10.0 on Sploitus.]]></description>
      <pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[BIND 9 Resolver Unbounded Loop DoS (CVE-2026-5950)]]></title>
      <link>https://offsitedark.com/news/bind-resolver-loop-cve-2026-5950</link>
      <description><![CDATA[Unchecked resend loop in BIND 9 bad-server handling enables remote resource exhaustion; defensive notes indexed on Sploitus.]]></description>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[ek0ms savi0r Publishes REAPER GitHub Secret Scanner]]></title>
      <link>https://offsitedark.com/news/com-reaper-github-secrets-scanner</link>
      <description><![CDATA[ek0ms savi0r publishes REAPER on Church of Malware git — Go-based GitHub hidden secret scanner.]]></description>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[GitLab WebAuthn 2FA Bypass (CVE-2026-2745)]]></title>
      <link>https://offsitedark.com/news/gitlab-webauthn-auth-bypass-cve-2026-2745</link>
      <description><![CDATA[Authentication bypass in GitLab WebAuthn 2FA due to inconsistent input validation; indexed on Sploitus Exploits of the week.]]></description>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[JupyterHub CSRF XSRF Bypass (CVE-2026-40864)]]></title>
      <link>https://offsitedark.com/news/jupyterhub-xsrf-bypass-cve-2026-40864</link>
      <description><![CDATA[Sec-Fetch-Mode: no-cors misclassified as same-origin bypasses XSRF on /hub/spawn and /hub/accept-share; PoC indexed on Sploitus.]]></description>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[kit-exploits-prv — Sploitus PoC Collection Roundup]]></title>
      <link>https://offsitedark.com/news/kit-exploits-prv-poc-collection</link>
      <description><![CDATA[Sploitus Exploits of the week entry kit-exploits-prv indexes a curated private PoC collection for authorized security testing.]]></description>
      <pubDate>Fri, 19 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[10k GitHub Repos Found Distributing Trojan Malware]]></title>
      <link>https://offsitedark.com/news/github-trojan-malware-campaign</link>
      <description><![CDATA[Researcher identifies ~10,000 GitHub repos cloning legitimate projects and pushing trojanized README zip archives.]]></description>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Nginx HTTP/3 QUIC Zero-Day (CVE-2026-42530)]]></title>
      <link>https://offsitedark.com/news/nginx-quic-zero-day-cve-2026-42530</link>
      <description><![CDATA[Remote code execution in NGINX Open Source 1.31.0–1.31.1 when HTTP/3 QUIC is enabled; patched in 1.31.2.]]></description>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Popa Botnet Linked to NetNut Proxy Provider]]></title>
      <link>https://offsitedark.com/news/popa-botnet-residential-proxy</link>
      <description><![CDATA[Popa Android TV box botnet (~1.5–2.5M daily IPs) linked to publicly-traded Israeli firm Alarum/NetNut.]]></description>
      <pubDate>Thu, 18 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[mastercodeon Publishes Peercord P2P Chat on Church of Malware Git]]></title>
      <link>https://offsitedark.com/news/com-peercord-decentralized-chat</link>
      <description><![CDATA[mastercodeon publishes Peercord on Church of Malware git — decentralized Discord-like social platform.]]></description>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[FortiBleed Leaks VPN Credentials for 73k Devices]]></title>
      <link>https://offsitedark.com/news/fortibleed-fortinet-vpn-leak</link>
      <description><![CDATA[FortiBleed data leak exposes Fortinet VPN credentials for approximately 73,000 devices.]]></description>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Mastra NPM Scope Compromise Targets Crypto Wallets]]></title>
      <link>https://offsitedark.com/news/mastra-npm-crypto-stealer</link>
      <description><![CDATA[140+ @mastra packages hijacked via dormant maintainer account; typosquat easy-day-js drops cross-platform stealer.]]></description>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Malicious Steam Workshop Wallpapers Steal Accounts]]></title>
      <link>https://offsitedark.com/news/steam-wallpaper-engine-malware</link>
      <description><![CDATA[Kaspersky finds dozens of trojanized Wallpaper Engine app wallpapers on Steam Workshop with tens of thousands of downloads.]]></description>
      <pubDate>Wed, 17 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[152 Chrome Wallpaper Extensions Hide Ad Fraud]]></title>
      <link>https://offsitedark.com/news/chrome-wallpaper-extension-ad-fraud</link>
      <description><![CDATA[Network of 152 Chrome live wallpaper extensions faked web traffic and AdSense clicks; 105,000+ combined installs.]]></description>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Mirai Variant Targets IoT Telnet]]></title>
      <link>https://offsitedark.com/news/mirai-variant-iot-telnet</link>
      <description><![CDATA[Modified Mirai strain scanning telnet with updated credentials and DGA C2.]]></description>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[shell-quote quote() Newline Command Injection (CVE-2026-9277)]]></title>
      <link>https://offsitedark.com/news/shell-quote-injection-cve-2026-9277</link>
      <description><![CDATA[Sploitus-indexed PoC shows object-token newline in shell-quote quote() becomes POSIX command separator; fix in 1.8.4.]]></description>
      <pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Bookly WordPress Stored XSS via Cookie (CVE-2026-5513)]]></title>
      <link>https://offsitedark.com/news/bookly-stored-xss-cve-2026-5513</link>
      <description><![CDATA[Unauthenticated stored XSS in Bookly ≤27.2 via bookly-customer-full-name cookie; scanner PoC indexed on Sploitus.]]></description>
      <pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Apache HTTP/2 Bomb DoS (CVE-2026-49975)]]></title>
      <link>https://offsitedark.com/news/apache-http2-bomb-cve-2026-49975</link>
      <description><![CDATA[Single-connection HPACK bomb plus flow-control stall can exhaust gigabytes of RAM; public PoC indexed on Sploitus.]]></description>
      <pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Avada Builder WordPress Unauthenticated RCE (CVE-2026-6279)]]></title>
      <link>https://offsitedark.com/news/avada-builder-rce-cve-2026-6279</link>
      <description><![CDATA[Sploitus-indexed PoC abuses fusion_get_widget_markup AJAX with leaked nonce to call_user_func arbitrary PHP functions.]]></description>
      <pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[PeopleSoft SSRF PoC Enables Unauthenticated RCE (CVE-2026-35273)]]></title>
      <link>https://offsitedark.com/news/peoplesoft-ssrf-poc-cve-2026-35273</link>
      <description><![CDATA[Sploitus-indexed PoC chains SSRF via PSIGW HttpListeningConnector into cloud credential theft and remote code execution.]]></description>
      <pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[JCE Joomla Unauthenticated RCE (CVE-2026-48907)]]></title>
      <link>https://offsitedark.com/news/jce-joomla-rce-cve-2026-48907</link>
      <description><![CDATA[Sploitus-indexed PoCs chain unauthenticated JCE profile import to PHP execution in Joomla tmp/; CVSS 10.0.]]></description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Patch Tuesday: 3 Zero-Days Addressed]]></title>
      <link>https://offsitedark.com/news/patch-tuesday-zero-days</link>
      <description><![CDATA[June Patch Tuesday addresses 67 CVEs including 3 actively exploited zero-days.]]></description>
      <pubDate>Thu, 11 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Windows Shellcode Entry Points]]></title>
      <link>https://offsitedark.com/research/windows-shellcode-entry-points</link>
      <description><![CDATA[A survey of shellcode entry techniques on modern Windows x64.]]></description>
      <pubDate>Wed, 10 Jun 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[WP Maps Pro Unauthenticated Admin Creation (CVE-2026-8732)]]></title>
      <link>https://offsitedark.com/news/wp-maps-pro-admin-cve-2026-8732</link>
      <description><![CDATA[Sploitus mass-scanner PoCs abuse wpgmp_temp_access_ajax with public fc-call-nonce to create administrator accounts.]]></description>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[Static Malware Triage: YARA-First Workflow]]></title>
      <link>https://offsitedark.com/research/static-malware-triage-yara</link>
      <description><![CDATA[YARA-first static triage for high-volume malware feeds.]]></description>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[NGINX Rift Heap Overflow RCE (CVE-2026-42945)]]></title>
      <link>https://offsitedark.com/news/nginx-rift-cve-2026-42945</link>
      <description><![CDATA[18-year-old rewrite-module desync enables pre-auth RCE; depthfirst PoC indexed on Sploitus with Docker lab and exploit modes.]]></description>
      <pubDate>Fri, 22 May 2026 00:00:00 GMT</pubDate>
    </item><item>
      <title><![CDATA[React2Shell RCE in React Server Components (CVE-2025-55182)]]></title>
      <link>https://offsitedark.com/news/react2shell-cve-2025-55182</link>
      <description><![CDATA[Critical CVSS 10.0 RCE in react-server-dom-webpack affects React 19 and Next.js App Router; public PoC scanner indexed on Sploitus.]]></description>
      <pubDate>Sat, 13 Dec 2025 00:00:00 GMT</pubDate>
    </item>
</channel></rss>