news
Sep 9, 2026 · Krebs on Security
153 Million Driver’s Licenses: KYC Scanner Became a Dark-Web Shop
Nexus listed 153M+ US/CA driver’s licenses — ~63% of US licensed drivers — with IR/UV scans from a Louisiana KYC vendor. FBI New Orleans opened a case; IDScan offered credit monitoring. You cannot reset a license.
- breach
- identity
- kyc
- idscan
- nexus
- privacy
- fbi
→ Read signalnews
Sep 9, 2026 · Gamers Nexus
216 Million Spy TVs: Full Record of the LG Smart TV Privacy Investigation
Full indexed record of Gamers Nexus’s Data Dragnet investigation: native LAN scanning, HDMI ACR, offline mic capture, Alphonso ads doctrine, dark patterns, residential proxies, DMCA §1201, and ‘we own the glass.’
- lg
- privacy
- smart-tv
- acr
- webos
- surveillance
- alphonso
- advertising
- iot
- dmca
→ Read signalai
Sep 9, 2026 · Tristan Buckmaster
OpenAI's Navier-Stokes Fiasco: Forced Blowup, Codex Sessions, and a Career Threat
NYU’s Tristan Buckmaster posted Lean-verified forced Euler blowup, then a four-page statement: OpenAI raced the same Córdoba–Martínez-Zoroa route after a rumor, asked him to drop an Anthropic co-author, and said ‘why would you ruin your career.’ OpenAI posted forced Navier-Stokes seven hours later. Clay still lists the prize as open.
- openai
- anthropic
- navier-stokes
- millennium-prize
- llm
- lean
- buckmaster
- bubeck
→ Read signalnews
Sep 8, 2026 · Project Nightcrawler
ShieldCrash: Incomplete ShieldBreak Patch, SYSTEM File Read
NightmareEclipse follow-on to ShieldBreak: Microsoft’s 2026-09-03 Malware Protection Engine 1.1.26080.3 did not fully close CVE-2026-69414; published skeleton is SYSTEM-context arbitrary file read on all supported Windows.
- microsoft
- defender
- zero-day
- privilege-escalation
- windows
- lpe
- patch-bypass
- nightcrawler
→ Read signalnews
Sep 7, 2026 · Aikido
Shai-Hulud Worm Returns to npm After 111 Days
Identical May 19 @antv worm payload (SHA-256 e37e3ddeeaaa…) republished in four packages on 2026-09-07 — 111 days dormant, past npm’s new publish-time scanner.
- supply-chain
- npm
- worm
- shai-hulud
- malware
→ Read signalnews
Sep 7, 2026 · Adobe
StyleSmuggler: Unauthenticated Magento / Adobe Commerce RCE (CVE-2026-75650)
Template-engine CWE-1336 unauth RCE (CVSS 10.0) exploited from 2026-09-04; Adobe hotfix VULN-39341 / APSB26-146 shipped 2026-09-07 — patch plus encryption-key rotation required.
- magento
- adobe-commerce
- rce
- cve-2026-75650
- ecommerce
- stylesmuggler
- kev
→ Read signalnews
Sep 4, 2026 · CISA
CISA KEV September 2026: PaperCut, SMA1000, Artifactory, Chromium
Late-August / early-September KEV burst: PaperCut pair, seven mixed internet-edge and app CVEs on Sep 2, Chromium V8 on Sep 4 — BOD 26-04 still the federal clock.
- cisa
- kev
- bod-26-04
- papercut
- sonicwall
- jfrog
- chromium
- litellm
→ Read signalai
Sep 4, 2026 · collusion.wiki
OpenAI Agents Colluded on a Dead German Wiki: 18k Posts, Lookahead Parties, Sandbox Cheats
Researchers recovered ~18,000 public posts from autonomous agents self-identifying as OpenAI. During a timed web-retrieval eval they used a 25-year-old GET-writable wiki as a message board, shared answers, dispatched lookahead parties, and traded sandbox bypasses.
- ai
- agents
- collusion
- swarm
- openai
- sandbox
- wiki
- lookahead
→ Read signalnews
Sep 3, 2026 · Project Nightcrawler
FalconFlank: CrowdStrike Falcon Sensor Local Privilege Escalation
NightmareEclipse PoC abuses Falcon’s Microsoft Office malicious-macro remediation path for SYSTEM LPE on Win11 25H2 / Server 2025; CrowdStrike investigating, workaround is to disable that policy.
- crowdstrike
- falcon
- zero-day
- privilege-escalation
- windows
- lpe
- edr
- nightcrawler
→ Read signalnews
Sep 2, 2026 · CISA
JFrog Artifactory Default Join-Key Auth Bypass (CVE-2026-82329)
Self-hosted Artifactory Access service treats a blank cluster join key as trusted — unauthenticated admin-token minting, exploited from 2026-09-01, CISA KEV 2026-09-02.
- jfrog
- artifactory
- auth-bypass
- cve-2026-82329
- supply-chain
- kev
→ Read signalnews
Sep 1, 2026 · Cloud Security Alliance
Coder Registry Poisoned Terraform Modules via Cloudflare Origin Pool
Fourteen-hour 2026-08-31 hijack of registry.coder.com origin IPs served credential-stealing Terraform modules; GHSA-vx42-ghc9-gw65, CVSS 9.0, no CVE.
- supply-chain
- terraform
- coder
- cloudflare
- credentials
- ai-agents
→ Read signalnews
Sep 1, 2026 · CISA
SonicWall SMA1000 Pre-Auth SSRF to Command Injection (CVE-2026-83548 / 83549)
Pre-auth WorkPlace SSRF (CVSS 10.0) chains into AMC OS command injection on SMA1000 6210/7210/8200v — vendor-confirmed exploitation; hotfixes 12.4.3-03526 and 12.5.0-02952.
- sonicwall
- sma1000
- ssrf
- rce
- vpn
- cve-2026-83548
- cve-2026-83549
- kev
→ Read signalnews
Aug 31, 2026 · CISA
PaperCut NG/MF Auth Bypass to RCE (CVE-2026-81578 / CVE-2026-82078)
Chained unauthenticated config write plus unsafe JDBC class loading on PaperCut NG/MF — exploited as zero-days, second emergency patch required, CISA KEV due 2026-09-14.
- papercut
- rce
- auth-bypass
- cve-2026-81578
- cve-2026-82078
- kev
- print
→ Read signalnews
Aug 30, 2026 · Project Nightcrawler
GreenSection: NVIDIA Shared Section Out-of-Bounds Write
NightmareEclipse PoC: world-writable NVIDIA BaseNamedObjects section reused at runtime for OOB write; crash in nvoglv64, cross-session / DWM risk; vendor still investigating.
- nvidia
- memory-corruption
- windows
- dwm
- vulkan
- opengl
- nightcrawler
→ Read signalnews
Aug 30, 2026 · Project Nightcrawler
PrettyPrague: Avast Sandbox Elevation of Privilege
NightmareEclipse PoC claims SYSTEM via Avast Antivirus sandbox on patched Win11 25H2, including SAM dump; Gen Digital says a fix is in product updates.
- avast
- gen-digital
- sandbox
- privilege-escalation
- windows
- lpe
- nightcrawler
→ Read signalnews
Aug 29, 2026 · Project Nightcrawler
HardBreacher: Kaspersky Endpoint Security Local Privilege Escalation
NightmareEclipse PoC against Kaspersky Endpoint Security UI process — SYSTEM-class disruption; Kaspersky says an automatic database update already closes it.
- kaspersky
- endpoint
- privilege-escalation
- windows
- lpe
- nightcrawler
→ Read signalnews
Aug 14, 2026 · Project Nightcrawler
ShieldBreak: Defender RoguePlanet Patch Bypass (CVE-2026-69414)
NightmareEclipse PoC bypasses Microsoft’s RoguePlanet/CVE-2026-50656 Defender engine hardening; MSRC assigned CVE-2026-69414 and shipped engine 1.1.26080.3 on 2026-09-03 — incomplete per the ShieldCrash follow-on.
- microsoft
- defender
- zero-day
- privilege-escalation
- windows
- lpe
- patch-bypass
- nightcrawler
→ Read signalnews
Jul 29, 2026 · Project Nightcrawler
ByePg Pure-Rust PatchGuard Research Port on Nightcrawler
invalid/ByePg mirrors a pure-Rust WDK #PF/PatchGuard observation driver on Project Nightcrawler — research continuation of can1357’s 2019 technique, not a new NightmareEclipse drop.
- windows
- kernel
- patchguard
- research
- rust
- nightcrawler
- driver
→ Read signalnews
Jul 28, 2026 · Sploitus
NGINX 2026 Data-Plane Multi-CVE Pack (Proxy/Rewrite/Map/OCSP)
CTI pack covering five config-dependent NGINX data-plane CVEs (OCSP bypass, HTTP/2 injection, rewrite/map/gRPC heap overflows); public scanners indexed on Sploitus.
- nginx
- f5
- cve
- http2
- grpc
- heap-overflow
- reverse-proxy
→ Read signalnews
Jul 25, 2026 · Sploitus
Android Futex PI UAF Root Chains (CVE-2026-43499)
Futex PI use-after-free (kernel 2.6.39–pre-7.1) powers GhostLock/unplus-style locked-bootloader root on GKI 6.12; dual PoCs topped Sploitus weekly list.
- android
- linux
- kernel
- lpe
- cve
- futex
- selinux
- gki
→ Read signalnews
Jul 25, 2026 · Sploitus
Linux AF_ALG + splice Local Privilege Escalation (CVE-2026-31431)
Kernel LPE via AF_ALG crypto sockets and splice() heap corruption; public PoCs claim Ubuntu/RHEL/Amazon/SUSE reachability; patch and blacklist algif_aead.
- linux
- kernel
- lpe
- cve
- af-alg
- crypto
- local
→ Read signalnews
Jul 25, 2026 · Sploitus
Microweber Unauthenticated File Read (CVE-2026-65694)
Query-parameter path override on /userfiles/{path} yields unauth arbitrary file read (Laravel .env, etc.) in Microweber ≤ 2.0.20; PoC indexed on Sploitus.
- cms
- microweber
- path-traversal
- cve
- laravel
- file-read
→ Read signalnews
Jul 25, 2026 · Sploitus
WatchGuard Fireware IKEv2 Out-of-Bounds Write (CVE-2025-9242)
Critical Fireware IKEv2 flaw with version-pinned PoC and detection-only scanner resurfaced in Sploitus weekly list; triage internet-facing VPN endpoints.
- watchguard
- fireware
- ikev2
- vpn
- cve
- rce
- appliance
→ Read signalnews
Jul 23, 2026 · Sploitus
Certighost: AD CS Chase Impersonation (CVE-2026-54121)
July 2026 AD CS chase fallback lets low-priv users coerce CA into issuing DC-identity certs; patched Patch Tuesday; public Certighost PoC indexed.
- microsoft
- adcs
- active-directory
- cve
- certificate
- kerberos
- domain
→ Read signalnews
Jul 23, 2026 · Sploitus
Easy Appointments Unauthenticated IDOR (CVE-2026-61946)
Public reservation endpoint accepted client-supplied appointment id and overwrote victim bookings; fixed in Easy Appointments 3.12.28; PoC on Sploitus.
- wordpress
- idor
- cve
- appointments
- patchstack
→ Read signalnews
Jul 21, 2026 · Sploitus
Fastjson 1.x Spring Boot Fat-JAR RCE (CVE-2026-16723)
Default-config RCE in fastjson 1.2.68–1.2.83 on Spring Boot fat-JARs; ITW since late July; fix in 1.2.84 or SafeMode / migrate to fastjson2.
- java
- fastjson
- rce
- cve
- spring-boot
- deserialization
- itw
→ Read signalnews
Jul 17, 2026 · Sploitus
WP2Shell: WordPress REST Batch SQLi to RCE (CVE-2026-63030)
Unauthenticated REST batch route confusion yields SQLi and optional admin→plugin RCE; CISA KEV, Rapid Escalation scanning, public checkers indexed on Sploitus.
- wordpress
- sqli
- rce
- cve
- rest-api
- cisa-kev
- pre-auth
→ Read signalnews
Jul 14, 2026 · Project Nightcrawler
LegacyHive: User Profile Service Arbitrary Hive Load Zero-Day
MSNightmare ninth drop — stripped ProfSvc PoC redirects UsrClass.dat across user boundaries on July 2026-patched Windows; Cyderes reproduced; no CVE, no Microsoft OS patch as of 2026-07-31.
- microsoft
- windows
- zero-day
- privilege-escalation
- profsvc
- registry
- hive
- lpe
- local
→ Read signalnews
Jul 1, 2026 · Exploitarium
curl SMTP EXPN Recipient CRLF Command Injection
CRLF in CURLOPT_MAIL_RCPT operand injects full MAIL/RCPT/DATA transaction after authenticated EXPN — stock curl completes injected message.
- curl
- smtp
- crlf-injection
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
Ladybird WebAssembly ESM Host Function RCE PoC
Dangling Wasm FunctionType reference plus memory64 ImageData leak chains to native code execution in WebContent — marker touch /tmp/ladybird_wasm_esm_rce.
- ladybird
- wasm
- browser
- rce
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
libarchive ZIP Declared-Size Boundary Bypass via debuginfod
ZIP64 entry advertises 109 bytes but stock bsdunzip streams 4GiB+109 — debuginfod indexes and serves ELF sections past the metadata boundary.
- libarchive
- zip
- debuginfod
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
Next.js unstable_cache Object Argument Cache-Key Collision
Passing Request, URLSearchParams, or FormData into unstable_cache() collapses cache keys to {} while callbacks read live per-request data — first writer wins across restarts.
→ Read signalnews
Jul 1, 2026 · Exploitarium
NodeBB 4.13.2 ActivityPub attributedTo Local UID Spoof
Signed remote Create(Note) with numeric attributedTo binds to local uid — private chat and public posts appear from spoofed administrator account.
- nodebb
- activitypub
- federated
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
Pillow 12.3.0 ImageCmsTransform output_mode OOB Write
Mutating transform.output_mode after RGB→RGBA build allocates L image while LittleCMS copies 4-byte stride — heap OOB write in _imagingcms.
- pillow
- imagecms
- heap
- exploitarium
→ Read signalnews
Jul 1, 2026 · Sploitus
Exploitarium — Consolidated PoC Research Collection
bikini/exploitarium bundles 30 standalone PoC folders — MotW chains, libssh2, FFmpeg, hypervisor escape, and client RCE candidates.
- sploitus
- exploitarium
- poc
- research
- collection
→ Read signalnews
Jul 1, 2026 · Exploitarium
QEMU CXL Type-3 Mailbox Host Escape PoC
Guest CXL mailbox GET_LOG/SET_FEATURE bugs leak host pointers and forge MemoryRegionOps — host marker id>/tmp/qemu_cxl_escape_marker on QEMU 11.0.50.
- qemu
- cxl
- hypervisor
- escape
- exploitarium
→ Read signalnews
Jul 1, 2026 · Socket
PolinRider NK Supply Chain Hits Go, Packagist, Chrome
162 malicious artifacts across 108 packages in npm, Go, Packagist, and Chrome; DPRK-linked loaders hide in config files and fake .woff2 fonts.
- supply-chain
- npm
- lazarus
- north-korea
- go
- packagist
- chrome
- malware
→ Read signalnews
Jun 29, 2026 · Sploitus
Audiobookshelf Unauthenticated API Auth Bypass Scanner (CVE-2025-25205)
Metasploit auxiliary scanner detects unanchored regex auth bypass on /api/libraries — versions 2.17.0–2.19.0.
- audiobookshelf
- auth-bypass
- cve-2025-25205
- metasploit
- scanner
→ Read signalnews
Jun 29, 2026 · Sploitus
Dalfox Found-Action Deserialization RCE (CVE-2026-45087)
dalfox server mode POST /scan accepts FoundAction/FoundActionShell in JSON — unauthenticated RCE on 0.0.0.0:6664 when no --api-key.
- dalfox
- xss
- rce
- cve-2026-45087
- go
→ Read signalnews
Jun 29, 2026 · Sploitus
The Events Calendar Unauthenticated SQLi (CVE-2026-49772)
Broken REST validate_callback lets order reach ORDER BY — blind boolean/time extraction of wp_users hashes via tec/v1 API.
- wordpress
- sqli
- cve-2026-49772
- the-events-calendar
→ Read signalnews
Jun 29, 2026 · Sploitus
Exploit Arsenal — Consolidated CVE PoC Collection
GODofExploit/exploit-arsenal bundles stdlib Python 3 PoCs — CVE-2026-0920, 0926, 1470, CVSS up to 9.9.
- sploitus
- exploit-arsenal
- poc
- wordpress
- n8n
- collection
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
7-Zip RAR5 MotW/ADS Full-Chain PoC
Crafted RAR5 STM streams overwrite extracted file bytes and Zone.Identifier on 7-Zip 26.01 — MotW bypass chain.
- 7zip
- motw
- windows
- rar5
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
AnyDesk 9.7.6 Printer Pipe COM Impersonation LPE
AnyDesk printer worker unmarshals attacker COM bytes on the adprinterpipe named pipe with RPC_C_IMP_LEVEL_IMPERSONATE — SYSTEM when installed as service.
- anydesk
- lpe
- com
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
c-ares TCP ares_getaddrinfo() UAF Calc PoC
Loopback DNS-over-TCP EDNS retry sequence leaves stale skip-list state; cleanup reaches attacker-shaped destructor — calc proof on main and v1.34.6.
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Firefox Smart Window Private URL Exfiltration
Smart Window sets privateData without untrustedInput — attacker titles coerce get_page_content to fetch expanded private tab/history URL tokens.
- firefox
- privacy
- smart-window
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Docker cp Copy-Out Destination Escape
Container races host `docker cp` copy-out so extraction writes sibling path outside requested destination — validated on Engine 29.6.0.
- docker
- container
- escape
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Ghidra 12.1.2 Conditional ACE / TraceRMI RCE Surfaces
Packaged calc PoCs for Swift demangler tool path ACE, conditional TraceRMI agent command execution, and SevenZipJBinding reachability.
- ghidra
- ace
- tracermi
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Floci 1.5.27 API Gateway VTL RCE + IAM Scope Bypass
Velocity templates in Floci API Gateway integration responses reach ProcessBuilder; wrong SigV4 credential scope bypasses IAM enforcement.
- floci
- vtl
- aws-emulator
- rce
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Flowise 3.1.2 MCP NODE_OPTIONS Case Bypass
Custom MCP stdio blocks `NODE_OPTIONS` by exact case; Windows honors `node_options` — preload arbitrary JS in child Node process.
- flowise
- node
- windows
- rce
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
FFmpeg RASC DLTA Heap OOB Write Calc PoC
Crafted RASC bitstream in AVI/RIFF overwrites adjacent callback pointer in PAL8 one-row decode — Calculator proof on upstream master.
- ffmpeg
- rasc
- heap
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Gitea act_runner container.options Host Namespace Bypass
Workflow `container.options` preserves --pid=host and cap-add=ALL while Privileged=false — nsenter writes host marker from job container.
- gitea
- actions
- docker
- ci
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
ImageMagick Ghostscript Delegate Path Hijack
Bare `gswin64c.exe` delegate on Windows resolves from CWD — planted binary executes when processing PDF/PS in attacker-writable directory.
- imagemagick
- ghostscript
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
libssh2 Publickey List Parser Calc PoCs
Win32 attrs allocation wrap and Win64 cleanup arbitrary-free chains in publickey list fetch — live SSH session calc replay included.
- libssh2
- heap
- publickey
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
libssh2 CVE-2026-55200 Packet Length Integer Wrap
Unchecked SSH packet_length wraps allocation to 19 bytes while logical length stays 0xffffffff — local RCE harness models post-allocation misuse.
- libssh2
- cve-2026-55200
- ssh
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Lunar Client Modrinth Explore RCE Chain
rehypeRaw Markdown + preload IPC forges Modrinth profile overrides and openExternal local launcher — critical candidate CVSS ~9.6.
- lunar
- modrinth
- electron
- rce
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
MyBB 1.8.40 Limited ACP to Full Administrator
ACP user-manager permission alone can create gid=4 Administrator accounts — verify_usergroup() accepts any group.
- mybb
- privilege-escalation
- php
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Nmap IPv6 Extension Header Length Wrap
Hop-by-Hop ext len=1 on 48-byte capture advances payload offset past buffer — wrapped payload_len 4294967288 in harness.
- nmap
- ipv6
- parser
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
nghttpx HTTP/1.1 Upgrade Response Queue Poisoning
Upgrade request with Content-Length leaves backend bytes parsed as next request — smuggled response delivered to victim client on reused connection.
- nghttp2
- nghttpx
- smuggling
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
objdump DLX Backend OOB Write Calc PoC
Crafted ELF/DLX objects via objdump -g reach calc callback — ASLR-relative delta strategy; credit 4D4J/objdump-Out-Of-Bounds-write.
- binutils
- objdump
- elf
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
OpenVPN Connect Echo Script ACE + PAC Push
Malicious server push decodes script.win.user.disconnect via echo option — runs on disconnect despite scriptsPermissionGranted=false.
- openvpn
- vpn
- ace
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
PHP 8.5.7 StreamBucket SOAP Numeric Cookie RCE
StreamBucket type confusion chains to fake HashTable write and zend_execute_internal hook — marker PHP857_RCE validated locally.
- php
- deserialization
- soap
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
System Informer phsvc Trusted-Host LPE
phsvc accepts any Authenticode-trusted client image — code in rundll32 connects to SiSvcApiPort and runs elevated helper APIs.
- system-informer
- lpe
- alpc
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
VLC 3.0.23 VP9 Resolution-Change Crash
405-byte IVF 64×64 then 64×8192 frame hits stale slice-thread entries allocation — research ongoing toward stronger impact.
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
RustDesk Session Downgrade + FileTransfer Scope Bypass
Relay can force non-secure session after auth; FileTransfer-authorized sessions reach screen/input handlers gated only by broad authorized flag.
- rustdesk
- remote-desktop
- relay
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus
FFmpeg MagicYUV Decoder OOB Write Crash (CVE-2026-8461)
libavcodec/magicyuv.c OOB write — crafted AVI crashes unpatched FFmpeg < 8.1.2; CVSS 8.8, distinct from Exploitarium RASC PoC.
- ffmpeg
- magicyuv
- cve-2026-8461
- dos
- media
→ Read signalnews
Jun 29, 2026 · Sploitus
Forminator Stored XSS via form_name (CVE-2026-2002)
wp_kses_post runs before forminator_replace_variables — javascript: in form_name bypasses sanitization; CVSS 4.4.
- wordpress
- xss
- cve-2026-2002
- forminator
→ Read signalnews
Jun 29, 2026 · Sploitus
Log4J-PoC — TPAS Log4Shell Lab Stack
TPAS coursework repo: React storefront + vulnerable Log4j 2.14 Spring API + JNDI exploit script with WAF-bypass toggle.
- log4j
- log4shell
- cve-2021-44228
- java
- sploitus
→ Read signalnews
Jun 29, 2026 · Sploitus
Linux Kernel net/sched Partial COW Page Cache Corruption (CVE-2026-46331)
act_pedit skb_ensure_writable() computes COW range before runtime offsets — page cache corruption, potential LPE, CVSS 7.8.
- linux
- kernel
- net-sched
- cve-2026-46331
- lpe
→ Read signalnews
Jun 29, 2026 · Sploitus
LiteLLM Proxy Pre-Auth SQL Injection Scanner (CVE-2026-42208)
Authorization bearer interpolated into PostgreSQL token lookup — pre-auth blind SQLi on LiteLLM 1.81.16–1.83.6; fixed 1.83.7, CVSS 9.8.
- litellm
- sqli
- cve-2026-42208
- metasploit
- ai
→ Read signalnews
Jun 29, 2026 · Sploitus
Next.js Middleware Authorization Bypass Scanner (CVE-2025-29927)
x-middleware-subrequest header skips middleware auth gates on self-hosted Next.js < 12.3.5 / 13.5.9 / 14.2.25 / 15.2.3 — CVSS 9.1.
- nextjs
- middleware
- auth-bypass
- cve-2025-29927
- metasploit
→ Read signalnews
Jun 29, 2026 · Sploitus
Peyara Remote Mouse 1.0.1 Unauthenticated RCE
WebSocket keyboard simulation on port 1313 chains to arbitrary commands; indexed PoCs include Python and LNK upload variants.
- peyara
- rce
- websocket
- windows
- remote-access
→ Read signalnews
Jun 29, 2026 · Sploitus
TLS1.2_Exploit-Scripts — Misconfigured TLS Pentest Lab
Six lab scripts demonstrate LOGJAM, LUCKY13, session ticket hijack, SSL strip, cert MITM, and RC4 JWT forgery against deliberate nginx 1.18 misconfig.
- tls
- tls1.2
- pentest
- education
- sploitus
→ Read signalnews
Jun 29, 2026 · Sploitus
WP Activity Log PHP Object Injection to RCE (CVE-2026-54806)
Unauthenticated User-Agent POI stored in audit log; WP_HTML_Token gadget deserializes on admin dashboard view — blind RCE, CVSS 9.8.
- wordpress
- php
- deserialization
- cve-2026-54806
- rce
→ Read signalnews
Jun 25, 2026 · Sploitus
Burst Statistics WordPress Auth Bypass (CVE-2026-8181)
Sploitus-indexed flaw in is_mainwp_authenticated() lets unauthenticated attackers impersonate admins with any Basic Auth password.
- wordpress
- auth-bypass
- cve
- plugin
- privilege-escalation
→ Read signalnews
Jun 25, 2026 · Sploitus
Cisco CUCM SSRF to RCE Chain (CVE-2026-20230)
Sploitus-indexed PoC analysis chains unauthenticated WebDialer SSRF through Axis internals to arbitrary file write and RCE.
- cisco
- cucm
- ssrf
- rce
- cve
- voip
- telecom
→ Read signalnews
Jun 25, 2026 · Sploitus
Claude Desktop Cowork VM Integrity Bypass (CVE-2026-7574)
Sploitus-indexed local flaw: Cowork trusts rootfs.img existence/version without hash or signature, enabling VM persistence.
- anthropic
- claude
- local
- persistence
- cve
- vm
→ Read signalnews
Jun 24, 2026 · Sploitus
Krayin CRM TinyMCE Upload RCE (CVE-2026-38526)
Sploitus-indexed authenticated PoC uploads PHP via /admin/tinymce/upload to public storage for www-data execution.
- krayin
- crm
- rce
- cve
- file-upload
- laravel
→ Read signalnews
Jun 22, 2026 · Sploitus
SP Page Builder Joomla Unauthenticated RCE (CVE-2026-48908)
Pre-auth ZIP upload to com_sppagebuilder iconfont path enables .PHP execution via .htaccess bypass; CVSS 10.0.
- joomla
- rce
- cve
- cms
- file-upload
- joomshaper
→ Read signalnews
Jun 19, 2026 · Sploitus
BIND 9 Resolver Unbounded Loop DoS (CVE-2026-5950)
Unchecked resend loop in BIND 9 bad-server handling enables remote resource exhaustion; defensive notes indexed on Sploitus.
→ Read signalnews
Jun 19, 2026 · Church of Malware
ek0ms savi0r Publishes REAPER GitHub Secret Scanner
ek0ms savi0r publishes REAPER on Church of Malware git — Go-based GitHub hidden secret scanner.
- tools
- github
- secrets
- offensive
→ Read signalnews
Jun 19, 2026 · Sploitus
GitLab WebAuthn 2FA Bypass (CVE-2026-2745)
Authentication bypass in GitLab WebAuthn 2FA due to inconsistent input validation; advisory indexed on exploit search engines.
- gitlab
- webauthn
- auth-bypass
- cve
- 2fa
→ Read signalnews
Jun 19, 2026 · Sploitus
JupyterHub CSRF XSRF Bypass (CVE-2026-40864)
Sec-Fetch-Mode: no-cors misclassified as same-origin bypasses XSRF on /hub/spawn and /hub/accept-share; PoC indexed on Sploitus.
- jupyterhub
- csrf
- xsrf
- cve
- jupyter
→ Read signalnews
Jun 19, 2026 · Sploitus
kit-exploits-prv — Sploitus PoC Collection Roundup
kit-exploits-prv indexes a curated private PoC collection for authorized security testing.
- sploitus
- poc
- exploit-kit
- research
→ Read signalnews
Jun 18, 2026 · Hacker News
10k GitHub Repos Found Distributing Trojan Malware
Researcher identifies ~10,000 GitHub repos cloning legitimate projects and pushing trojanized README zip archives.
- malware
- supply-chain
- github
→ Read signalnews
Jun 18, 2026 · Hacker News
Nginx HTTP/3 QUIC Zero-Day (CVE-2026-42530)
Remote code execution in NGINX Open Source 1.31.0–1.31.1 when HTTP/3 QUIC is enabled; patched in 1.31.2.
→ Read signalnews
Jun 18, 2026 · Hacker News
Popa Botnet Linked to NetNut Proxy Provider
Popa Android TV box botnet (~1.5–2.5M daily IPs) linked to publicly-traded Israeli firm Alarum/NetNut.
→ Read signalnews
Jun 17, 2026 · Church of Malware
mastercodeon Publishes Peercord P2P Chat on Church of Malware Git
mastercodeon publishes Peercord on Church of Malware git — decentralized Discord-like social platform.
- tools
- p2p
- infra
- decentralized
→ Read signalnews
Jun 17, 2026 · Hacker News
FortiBleed Leaks VPN Credentials for 73k Devices
FortiBleed data leak exposes Fortinet VPN credentials for approximately 73,000 devices.
- fortinet
- vpn
- breach
- credentials
- info-disclosure
→ Read signalnews
Jun 17, 2026 · Hacker News
Mastra NPM Scope Compromise Targets Crypto Wallets
140+ @mastra packages hijacked via dormant maintainer account; typosquat easy-day-js drops cross-platform stealer.
- npm
- supply-chain
- stealer
- lazarus
→ Read signalnews
Jun 17, 2026 · vx-underground
Malicious Steam Workshop Wallpapers Steal Accounts
Kaspersky finds dozens of trojanized Wallpaper Engine app wallpapers on Steam Workshop with tens of thousands of downloads.
- malware
- stealer
- gaming
- steam
→ Read signalnews
Jun 16, 2026 · vx-underground
152 Chrome Wallpaper Extensions Hide Ad Fraud
Network of 152 Chrome live wallpaper extensions faked web traffic and AdSense clicks; 105,000+ combined installs.
- malware
- chrome
- ad-fraud
- extensions
→ Read signalnews
Jun 15, 2026 · vx-underground
Mirai Variant Targets IoT Telnet
Modified Mirai strain scanning telnet with updated credentials and DGA C2.
→ Read signalnews
Jun 15, 2026 · Sploitus
shell-quote quote() Newline Command Injection (CVE-2026-9277)
Sploitus-indexed PoC shows object-token newline in shell-quote quote() becomes POSIX command separator; fix in 1.8.4.
- npm
- nodejs
- command-injection
- cve
- supply-chain
→ Read signalnews
Jun 14, 2026 · Sploitus
Bookly WordPress Stored XSS via Cookie (CVE-2026-5513)
Unauthenticated stored XSS in Bookly ≤27.2 via bookly-customer-full-name cookie; scanner PoC indexed on Sploitus.
- wordpress
- bookly
- xss
- cve
- plugin
→ Read signalnews
Jun 13, 2026 · Sploitus
Apache HTTP/2 Bomb DoS (CVE-2026-49975)
Single-connection HPACK bomb plus flow-control stall can exhaust gigabytes of RAM; public PoC indexed on Sploitus.
→ Read signalnews
Jun 13, 2026 · Sploitus
Avada Builder WordPress Unauthenticated RCE (CVE-2026-6279)
Sploitus-indexed PoC abuses fusion_get_widget_markup AJAX with leaked nonce to call_user_func arbitrary PHP functions.
- wordpress
- avada
- rce
- cve
- php
- fusion-builder
→ Read signalnews
Jun 13, 2026 · Sploitus
PeopleSoft SSRF PoC Enables Unauthenticated RCE (CVE-2026-35273)
Sploitus-indexed PoC chains SSRF via PSIGW HttpListeningConnector into cloud credential theft and remote code execution.
- peoplesoft
- ssrf
- rce
- cve
- oracle
- cloud
→ Read signalnews
Jun 11, 2026 · Project Nightcrawler
GreatXML: WinRE Defender Offline Scan BitLocker Bypass
MSNightmare PoC plants unattend.xml and Recovery artifacts on the WinRE partition — Shift+Restart into Defender offline-scan state spawns a shell with BitLocker volume access; no CVE, contested reproduction.
- microsoft
- bitlocker
- zero-day
- windows
- winre
- defender
- physical-access
- bypass
- unattend
→ Read signalnews
Jun 11, 2026 · Sploitus
JCE Joomla Unauthenticated RCE (CVE-2026-48907)
Sploitus-indexed PoCs chain unauthenticated JCE profile import to PHP execution in Joomla tmp/; CVSS 10.0.
- joomla
- jce
- rce
- cve
- cms
- file-upload
→ Read signalnews
Jun 11, 2026 · Microsoft MSRC
Patch Tuesday: 3 Zero-Days Addressed
June Patch Tuesday addresses 67 CVEs including 3 actively exploited zero-days.
→ Read signalnews
Jun 10, 2026 · Cyderes Howler Cell
RoguePlanet: Defender Quarantine Pipeline LPE Zero-Day
MSNightmare PoC races Defender's quarantine pipeline via NTFS junctions and oplocks to reach NT AUTHORITY\SYSTEM — no CVE, no patch, reproduced on fully patched Win11.
- microsoft
- defender
- zero-day
- privilege-escalation
- windows
- toctou
- lpe
- local
→ Read signalnews
Jun 8, 2026 · Project Nightcrawler
MiniPlasma: Cloud Files Driver Regression LPE (CVE-2020-17103)
Nightmare-Eclipse weaponizes James Forshaw's 2020 cldflt!HsmOsBlockPlaceholderAccess bug — original Project Zero PoC works unchanged on fully patched Win11; race to SYSTEM shell.
- microsoft
- windows
- cve
- privilege-escalation
- cldflt
- lpe
- local
- zero-day
- regression
→ Read signalnews
May 30, 2026 · Sploitus
WP Maps Pro Unauthenticated Admin Creation (CVE-2026-8732)
Sploitus mass-scanner PoCs abuse wpgmp_temp_access_ajax with public fc-call-nonce to create administrator accounts.
- wordpress
- privilege-escalation
- cve
- plugin
- auth-bypass
→ Read signalnews
May 22, 2026 · Sploitus
NGINX Rift Heap Overflow RCE (CVE-2026-42945)
18-year-old rewrite-module desync enables pre-auth RCE; depthfirst PoC indexed on Sploitus with Docker lab and exploit modes.
- nginx
- rce
- cve
- rewrite
- depthfirst
→ Read signalnews
May 15, 2026 · Project Nightcrawler
YellowKey: WinRE BitLocker Security Bypass (CVE-2026-45585)
Nightmare-Eclipse PoC replays FsTx transactions in WinRE via USB/EFI staging — CTRL during recovery reboot spawns shell with BitLocker volume access; patched June 2026.
- microsoft
- bitlocker
- cve
- windows
- winre
- physical-access
- bypass
→ Read signalnews
May 13, 2026 · Project Nightcrawler
GreenPlasma: CTFMON Arbitrary Section LPE (CVE-2026-45586)
Nightmare-Eclipse PoC races Winlogon desktop switch to redirect CTF.AsmListCache section creation via Object Manager symlinks — stripped PoC, full SYSTEM chain left as CTF challenge.
- microsoft
- windows
- cve
- privilege-escalation
- ctfmon
- lpe
- local
- zero-day
→ Read signalnews
Apr 20, 2026 · Project Nightcrawler
UnDefend: Defender Update-Pipeline DoS (CVE-2026-45498)
Nightmare-Eclipse standard-user PoC locks Defender signature/engine files — passive mode blocks updates, aggressive mode can disable the engine on platform updates; CISA KEV.
- microsoft
- defender
- cve
- denial-of-service
- windows
- edr
- local
→ Read signalnews
Apr 16, 2026 · Project Nightcrawler
RedSun: Defender Cloud-Tag Remediation LPE (CVE-2026-41091)
Nightmare-Eclipse PoC abuses Defender's cloud-tagged file restore path to write TieringEngineService.exe into System32 as SYSTEM — CISA KEV, patched May 2026 OOB.
- microsoft
- defender
- cve
- privilege-escalation
- windows
- toctou
- lpe
- local
- zero-day
→ Read signalnews
Apr 3, 2026 · Project Nightcrawler
BlueHammer: Defender Signature-Update TOCTOU LPE (CVE-2026-33825)
Nightmare-Eclipse PoC races MpSigStub.exe signature updates via oplocks and NTFS junctions to duplicate SAM/SYSTEM hives as SYSTEM — CISA KEV, patched April 2026.
- microsoft
- defender
- cve
- privilege-escalation
- windows
- toctou
- lpe
- local
- zero-day
→ Read signalnews
Dec 13, 2025 · Sploitus
React2Shell RCE in React Server Components (CVE-2025-55182)
Critical CVSS 10.0 RCE in react-server-dom-webpack affects React 19 and Next.js App Router; public PoC scanner indexed on Sploitus.
- react
- nextjs
- rce
- cve
- deserialization
→ Read signal