news
Jul 29, 2026 · Project Nightcrawler
ByePg Pure-Rust PatchGuard Research Port on Nightcrawler
invalid/ByePg mirrors a pure-Rust WDK #PF/PatchGuard observation driver on Project Nightcrawler — research continuation of can1357’s 2019 technique, not a new NightmareEclipse drop.
- windows
- kernel
- patchguard
- research
- rust
- nightcrawler
- driver
→ Read signalnews
Jul 28, 2026 · Sploitus
NGINX 2026 Data-Plane Multi-CVE Pack (Proxy/Rewrite/Map/OCSP)
CTI pack covering five config-dependent NGINX data-plane CVEs (OCSP bypass, HTTP/2 injection, rewrite/map/gRPC heap overflows); public scanners indexed on Sploitus.
- nginx
- f5
- cve
- http2
- grpc
- heap-overflow
- reverse-proxy
→ Read signalnews
Jul 25, 2026 · Sploitus
Android Futex PI UAF Root Chains (CVE-2026-43499)
Futex PI use-after-free (kernel 2.6.39–pre-7.1) powers GhostLock/unplus-style locked-bootloader root on GKI 6.12; dual PoCs topped Sploitus weekly list.
- android
- linux
- kernel
- lpe
- cve
- futex
- selinux
- gki
→ Read signalnews
Jul 25, 2026 · Sploitus
Linux AF_ALG + splice Local Privilege Escalation (CVE-2026-31431)
Kernel LPE via AF_ALG crypto sockets and splice() heap corruption; public PoCs claim Ubuntu/RHEL/Amazon/SUSE reachability; patch and blacklist algif_aead.
- linux
- kernel
- lpe
- cve
- af-alg
- crypto
- local
→ Read signalnews
Jul 25, 2026 · Sploitus
Microweber Unauthenticated File Read (CVE-2026-65694)
Query-parameter path override on /userfiles/{path} yields unauth arbitrary file read (Laravel .env, etc.) in Microweber ≤ 2.0.20; PoC indexed on Sploitus.
- cms
- microweber
- path-traversal
- cve
- laravel
- file-read
→ Read signalnews
Jul 25, 2026 · Sploitus
WatchGuard Fireware IKEv2 Out-of-Bounds Write (CVE-2025-9242)
Critical Fireware IKEv2 flaw with version-pinned PoC and detection-only scanner resurfaced in Sploitus weekly list; triage internet-facing VPN endpoints.
- watchguard
- fireware
- ikev2
- vpn
- cve
- rce
- appliance
→ Read signalnews
Jul 23, 2026 · Sploitus
Certighost: AD CS Chase Impersonation (CVE-2026-54121)
July 2026 AD CS chase fallback lets low-priv users coerce CA into issuing DC-identity certs; patched Patch Tuesday; public Certighost PoC indexed.
- microsoft
- adcs
- active-directory
- cve
- certificate
- kerberos
- domain
→ Read signalnews
Jul 23, 2026 · Sploitus
Easy Appointments Unauthenticated IDOR (CVE-2026-61946)
Public reservation endpoint accepted client-supplied appointment id and overwrote victim bookings; fixed in Easy Appointments 3.12.28; PoC on Sploitus.
- wordpress
- idor
- cve
- appointments
- patchstack
→ Read signalnews
Jul 21, 2026 · Sploitus
Fastjson 1.x Spring Boot Fat-JAR RCE (CVE-2026-16723)
Default-config RCE in fastjson 1.2.68–1.2.83 on Spring Boot fat-JARs; ITW since late July; fix in 1.2.84 or SafeMode / migrate to fastjson2.
- java
- fastjson
- rce
- cve
- spring-boot
- deserialization
- itw
→ Read signalnews
Jul 17, 2026 · Sploitus
WP2Shell: WordPress REST Batch SQLi to RCE (CVE-2026-63030)
Unauthenticated REST batch route confusion yields SQLi and optional admin→plugin RCE; CISA KEV, Rapid Escalation scanning, public checkers indexed on Sploitus.
- wordpress
- sqli
- rce
- cve
- rest-api
- cisa-kev
- pre-auth
→ Read signalnews
Jul 14, 2026 · Project Nightcrawler
LegacyHive: User Profile Service Arbitrary Hive Load Zero-Day
MSNightmare ninth drop — stripped ProfSvc PoC redirects UsrClass.dat across user boundaries on July 2026-patched Windows; Cyderes reproduced; no CVE, no Microsoft OS patch as of 2026-07-31.
- microsoft
- windows
- zero-day
- privilege-escalation
- profsvc
- registry
- hive
- lpe
- local
→ Read signalnews
Jul 1, 2026 · Exploitarium
curl SMTP EXPN Recipient CRLF Command Injection
CRLF in CURLOPT_MAIL_RCPT operand injects full MAIL/RCPT/DATA transaction after authenticated EXPN — stock curl completes injected message.
- curl
- smtp
- crlf-injection
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
libarchive ZIP Declared-Size Boundary Bypass via debuginfod
ZIP64 entry advertises 109 bytes but stock bsdunzip streams 4GiB+109 — debuginfod indexes and serves ELF sections past the metadata boundary.
- libarchive
- zip
- debuginfod
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
Ladybird WebAssembly ESM Host Function RCE PoC
Dangling Wasm FunctionType reference plus memory64 ImageData leak chains to native code execution in WebContent — marker touch /tmp/ladybird_wasm_esm_rce.
- ladybird
- wasm
- browser
- rce
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
NodeBB 4.13.2 ActivityPub attributedTo Local UID Spoof
Signed remote Create(Note) with numeric attributedTo binds to local uid — private chat and public posts appear from spoofed administrator account.
- nodebb
- activitypub
- federated
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
Next.js unstable_cache Object Argument Cache-Key Collision
Passing Request, URLSearchParams, or FormData into unstable_cache() collapses cache keys to {} while callbacks read live per-request data — first writer wins across restarts.
→ Read signalnews
Jul 1, 2026 · Exploitarium
Pillow 12.3.0 ImageCmsTransform output_mode OOB Write
Mutating transform.output_mode after RGB→RGBA build allocates L image while LittleCMS copies 4-byte stride — heap OOB write in _imagingcms.
- pillow
- imagecms
- heap
- exploitarium
→ Read signalnews
Jul 1, 2026 · Exploitarium
QEMU CXL Type-3 Mailbox Host Escape PoC
Guest CXL mailbox GET_LOG/SET_FEATURE bugs leak host pointers and forge MemoryRegionOps — host marker id>/tmp/qemu_cxl_escape_marker on QEMU 11.0.50.
- qemu
- cxl
- hypervisor
- escape
- exploitarium
→ Read signalnews
Jul 1, 2026 · Sploitus
Exploitarium — Consolidated PoC Research Collection
bikini/exploitarium bundles 30 standalone PoC folders — MotW chains, libssh2, FFmpeg, hypervisor escape, and client RCE candidates.
- sploitus
- exploitarium
- poc
- research
- collection
→ Read signalnews
Jul 1, 2026 · Socket
PolinRider NK Supply Chain Hits Go, Packagist, Chrome
162 malicious artifacts across 108 packages in npm, Go, Packagist, and Chrome; DPRK-linked loaders hide in config files and fake .woff2 fonts.
- supply-chain
- npm
- lazarus
- north-korea
- go
- packagist
- chrome
- malware
→ Read signalnews
Jun 29, 2026 · Sploitus
Audiobookshelf Unauthenticated API Auth Bypass Scanner (CVE-2025-25205)
Metasploit auxiliary scanner detects unanchored regex auth bypass on /api/libraries — versions 2.17.0–2.19.0.
- audiobookshelf
- auth-bypass
- cve-2025-25205
- metasploit
- scanner
→ Read signalnews
Jun 29, 2026 · Sploitus
Dalfox Found-Action Deserialization RCE (CVE-2026-45087)
dalfox server mode POST /scan accepts FoundAction/FoundActionShell in JSON — unauthenticated RCE on 0.0.0.0:6664 when no --api-key.
- dalfox
- xss
- rce
- cve-2026-45087
- go
→ Read signalnews
Jun 29, 2026 · Sploitus
The Events Calendar Unauthenticated SQLi (CVE-2026-49772)
Broken REST validate_callback lets order reach ORDER BY — blind boolean/time extraction of wp_users hashes via tec/v1 API.
- wordpress
- sqli
- cve-2026-49772
- the-events-calendar
→ Read signalnews
Jun 29, 2026 · Sploitus
Exploit Arsenal — Consolidated CVE PoC Collection
GODofExploit/exploit-arsenal bundles stdlib Python 3 PoCs — CVE-2026-0920, 0926, 1470, CVSS up to 9.9.
- sploitus
- exploit-arsenal
- poc
- wordpress
- n8n
- collection
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
7-Zip RAR5 MotW/ADS Full-Chain PoC
Crafted RAR5 STM streams overwrite extracted file bytes and Zone.Identifier on 7-Zip 26.01 — MotW bypass chain.
- 7zip
- motw
- windows
- rar5
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
AnyDesk 9.7.6 Printer Pipe COM Impersonation LPE
AnyDesk printer worker unmarshals attacker COM bytes on the adprinterpipe named pipe with RPC_C_IMP_LEVEL_IMPERSONATE — SYSTEM when installed as service.
- anydesk
- lpe
- com
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
c-ares TCP ares_getaddrinfo() UAF Calc PoC
Loopback DNS-over-TCP EDNS retry sequence leaves stale skip-list state; cleanup reaches attacker-shaped destructor — calc proof on main and v1.34.6.
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Docker cp Copy-Out Destination Escape
Container races host `docker cp` copy-out so extraction writes sibling path outside requested destination — validated on Engine 29.6.0.
- docker
- container
- escape
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Floci 1.5.27 API Gateway VTL RCE + IAM Scope Bypass
Velocity templates in Floci API Gateway integration responses reach ProcessBuilder; wrong SigV4 credential scope bypasses IAM enforcement.
- floci
- vtl
- aws-emulator
- rce
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Flowise 3.1.2 MCP NODE_OPTIONS Case Bypass
Custom MCP stdio blocks `NODE_OPTIONS` by exact case; Windows honors `node_options` — preload arbitrary JS in child Node process.
- flowise
- node
- windows
- rce
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Firefox Smart Window Private URL Exfiltration
Smart Window sets privateData without untrustedInput — attacker titles coerce get_page_content to fetch expanded private tab/history URL tokens.
- firefox
- privacy
- smart-window
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Ghidra 12.1.2 Conditional ACE / TraceRMI RCE Surfaces
Packaged calc PoCs for Swift demangler tool path ACE, conditional TraceRMI agent command execution, and SevenZipJBinding reachability.
- ghidra
- ace
- tracermi
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
FFmpeg RASC DLTA Heap OOB Write Calc PoC
Crafted RASC bitstream in AVI/RIFF overwrites adjacent callback pointer in PAL8 one-row decode — Calculator proof on upstream master.
- ffmpeg
- rasc
- heap
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Gitea act_runner container.options Host Namespace Bypass
Workflow `container.options` preserves --pid=host and cap-add=ALL while Privileged=false — nsenter writes host marker from job container.
- gitea
- actions
- docker
- ci
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
ImageMagick Ghostscript Delegate Path Hijack
Bare `gswin64c.exe` delegate on Windows resolves from CWD — planted binary executes when processing PDF/PS in attacker-writable directory.
- imagemagick
- ghostscript
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
libssh2 Publickey List Parser Calc PoCs
Win32 attrs allocation wrap and Win64 cleanup arbitrary-free chains in publickey list fetch — live SSH session calc replay included.
- libssh2
- heap
- publickey
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
MyBB 1.8.40 Limited ACP to Full Administrator
ACP user-manager permission alone can create gid=4 Administrator accounts — verify_usergroup() accepts any group.
- mybb
- privilege-escalation
- php
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
libssh2 CVE-2026-55200 Packet Length Integer Wrap
Unchecked SSH packet_length wraps allocation to 19 bytes while logical length stays 0xffffffff — local RCE harness models post-allocation misuse.
- libssh2
- cve-2026-55200
- ssh
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
nghttpx HTTP/1.1 Upgrade Response Queue Poisoning
Upgrade request with Content-Length leaves backend bytes parsed as next request — smuggled response delivered to victim client on reused connection.
- nghttp2
- nghttpx
- smuggling
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Lunar Client Modrinth Explore RCE Chain
rehypeRaw Markdown + preload IPC forges Modrinth profile overrides and openExternal local launcher — critical candidate CVSS ~9.6.
- lunar
- modrinth
- electron
- rce
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
objdump DLX Backend OOB Write Calc PoC
Crafted ELF/DLX objects via objdump -g reach calc callback — ASLR-relative delta strategy; credit 4D4J/objdump-Out-Of-Bounds-write.
- binutils
- objdump
- elf
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
OpenVPN Connect Echo Script ACE + PAC Push
Malicious server push decodes script.win.user.disconnect via echo option — runs on disconnect despite scriptsPermissionGranted=false.
- openvpn
- vpn
- ace
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
Nmap IPv6 Extension Header Length Wrap
Hop-by-Hop ext len=1 on 48-byte capture advances payload offset past buffer — wrapped payload_len 4294967288 in harness.
- nmap
- ipv6
- parser
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
RustDesk Session Downgrade + FileTransfer Scope Bypass
Relay can force non-secure session after auth; FileTransfer-authorized sessions reach screen/input handlers gated only by broad authorized flag.
- rustdesk
- remote-desktop
- relay
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
PHP 8.5.7 StreamBucket SOAP Numeric Cookie RCE
StreamBucket type confusion chains to fake HashTable write and zend_execute_internal hook — marker PHP857_RCE validated locally.
- php
- deserialization
- soap
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
System Informer phsvc Trusted-Host LPE
phsvc accepts any Authenticode-trusted client image — code in rundll32 connects to SiSvcApiPort and runs elevated helper APIs.
- system-informer
- lpe
- alpc
- windows
- exploitarium
→ Read signalnews
Jun 29, 2026 · Sploitus / Exploitarium
VLC 3.0.23 VP9 Resolution-Change Crash
405-byte IVF 64×64 then 64×8192 frame hits stale slice-thread entries allocation — research ongoing toward stronger impact.
→ Read signalnews
Jun 29, 2026 · Sploitus
FFmpeg MagicYUV Decoder OOB Write Crash (CVE-2026-8461)
libavcodec/magicyuv.c OOB write — crafted AVI crashes unpatched FFmpeg < 8.1.2; CVSS 8.8, distinct from Exploitarium RASC PoC.
- ffmpeg
- magicyuv
- cve-2026-8461
- dos
- media
→ Read signalnews
Jun 29, 2026 · Sploitus
Forminator Stored XSS via form_name (CVE-2026-2002)
wp_kses_post runs before forminator_replace_variables — javascript: in form_name bypasses sanitization; CVSS 4.4.
- wordpress
- xss
- cve-2026-2002
- forminator
→ Read signalnews
Jun 29, 2026 · Sploitus
Linux Kernel net/sched Partial COW Page Cache Corruption (CVE-2026-46331)
act_pedit skb_ensure_writable() computes COW range before runtime offsets — page cache corruption, potential LPE, CVSS 7.8.
- linux
- kernel
- net-sched
- cve-2026-46331
- lpe
→ Read signalnews
Jun 29, 2026 · Sploitus
Log4J-PoC — TPAS Log4Shell Lab Stack
TPAS coursework repo: React storefront + vulnerable Log4j 2.14 Spring API + JNDI exploit script with WAF-bypass toggle.
- log4j
- log4shell
- cve-2021-44228
- java
- sploitus
→ Read signalnews
Jun 29, 2026 · Sploitus
LiteLLM Proxy Pre-Auth SQL Injection Scanner (CVE-2026-42208)
Authorization bearer interpolated into PostgreSQL token lookup — pre-auth blind SQLi on LiteLLM 1.81.16–1.83.6; fixed 1.83.7, CVSS 9.8.
- litellm
- sqli
- cve-2026-42208
- metasploit
- ai
→ Read signalnews
Jun 29, 2026 · Sploitus
Next.js Middleware Authorization Bypass Scanner (CVE-2025-29927)
x-middleware-subrequest header skips middleware auth gates on self-hosted Next.js < 12.3.5 / 13.5.9 / 14.2.25 / 15.2.3 — CVSS 9.1.
- nextjs
- middleware
- auth-bypass
- cve-2025-29927
- metasploit
→ Read signalnews
Jun 29, 2026 · Sploitus
Peyara Remote Mouse 1.0.1 Unauthenticated RCE
WebSocket keyboard simulation on port 1313 chains to arbitrary commands; indexed PoCs include Python and LNK upload variants.
- peyara
- rce
- websocket
- windows
- remote-access
→ Read signalnews
Jun 29, 2026 · Sploitus
TLS1.2_Exploit-Scripts — Misconfigured TLS Pentest Lab
Six lab scripts demonstrate LOGJAM, LUCKY13, session ticket hijack, SSL strip, cert MITM, and RC4 JWT forgery against deliberate nginx 1.18 misconfig.
- tls
- tls1.2
- pentest
- education
- sploitus
→ Read signalnews
Jun 29, 2026 · Sploitus
WP Activity Log PHP Object Injection to RCE (CVE-2026-54806)
Unauthenticated User-Agent POI stored in audit log; WP_HTML_Token gadget deserializes on admin dashboard view — blind RCE, CVSS 9.8.
- wordpress
- php
- deserialization
- cve-2026-54806
- rce
→ Read signalnews
Jun 25, 2026 · Sploitus
Burst Statistics WordPress Auth Bypass (CVE-2026-8181)
Sploitus-indexed flaw in is_mainwp_authenticated() lets unauthenticated attackers impersonate admins with any Basic Auth password.
- wordpress
- auth-bypass
- cve
- plugin
- privilege-escalation
→ Read signalnews
Jun 25, 2026 · Sploitus
Cisco CUCM SSRF to RCE Chain (CVE-2026-20230)
Sploitus-indexed PoC analysis chains unauthenticated WebDialer SSRF through Axis internals to arbitrary file write and RCE.
- cisco
- cucm
- ssrf
- rce
- cve
- voip
- telecom
→ Read signalnews
Jun 25, 2026 · Sploitus
Claude Desktop Cowork VM Integrity Bypass (CVE-2026-7574)
Sploitus-indexed local flaw: Cowork trusts rootfs.img existence/version without hash or signature, enabling VM persistence.
- anthropic
- claude
- local
- persistence
- cve
- vm
→ Read signalnews
Jun 24, 2026 · Sploitus
Krayin CRM TinyMCE Upload RCE (CVE-2026-38526)
Sploitus-indexed authenticated PoC uploads PHP via /admin/tinymce/upload to public storage for www-data execution.
- krayin
- crm
- rce
- cve
- file-upload
- laravel
→ Read signalnews
Jun 22, 2026 · Sploitus
SP Page Builder Joomla Unauthenticated RCE (CVE-2026-48908)
Pre-auth ZIP upload to com_sppagebuilder iconfont path enables .PHP execution via .htaccess bypass; CVSS 10.0.
- joomla
- rce
- cve
- cms
- file-upload
- joomshaper
→ Read signalnews
Jun 19, 2026 · Sploitus
BIND 9 Resolver Unbounded Loop DoS (CVE-2026-5950)
Unchecked resend loop in BIND 9 bad-server handling enables remote resource exhaustion; defensive notes indexed on Sploitus.
→ Read signalnews
Jun 19, 2026 · Church of Malware
ek0ms savi0r Publishes REAPER GitHub Secret Scanner
ek0ms savi0r publishes REAPER on Church of Malware git — Go-based GitHub hidden secret scanner.
- tools
- github
- secrets
- offensive
→ Read signalnews
Jun 19, 2026 · Sploitus
GitLab WebAuthn 2FA Bypass (CVE-2026-2745)
Authentication bypass in GitLab WebAuthn 2FA due to inconsistent input validation; advisory indexed on exploit search engines.
- gitlab
- webauthn
- auth-bypass
- cve
- 2fa
→ Read signalnews
Jun 19, 2026 · Sploitus
JupyterHub CSRF XSRF Bypass (CVE-2026-40864)
Sec-Fetch-Mode: no-cors misclassified as same-origin bypasses XSRF on /hub/spawn and /hub/accept-share; PoC indexed on Sploitus.
- jupyterhub
- csrf
- xsrf
- cve
- jupyter
→ Read signalnews
Jun 19, 2026 · Sploitus
kit-exploits-prv — Sploitus PoC Collection Roundup
kit-exploits-prv indexes a curated private PoC collection for authorized security testing.
- sploitus
- poc
- exploit-kit
- research
→ Read signalnews
Jun 18, 2026 · Hacker News
10k GitHub Repos Found Distributing Trojan Malware
Researcher identifies ~10,000 GitHub repos cloning legitimate projects and pushing trojanized README zip archives.
- malware
- supply-chain
- github
→ Read signalnews
Jun 18, 2026 · Hacker News
Nginx HTTP/3 QUIC Zero-Day (CVE-2026-42530)
Remote code execution in NGINX Open Source 1.31.0–1.31.1 when HTTP/3 QUIC is enabled; patched in 1.31.2.
→ Read signalnews
Jun 18, 2026 · Hacker News
Popa Botnet Linked to NetNut Proxy Provider
Popa Android TV box botnet (~1.5–2.5M daily IPs) linked to publicly-traded Israeli firm Alarum/NetNut.
→ Read signalnews
Jun 17, 2026 · Church of Malware
mastercodeon Publishes Peercord P2P Chat on Church of Malware Git
mastercodeon publishes Peercord on Church of Malware git — decentralized Discord-like social platform.
- tools
- p2p
- infra
- decentralized
→ Read signalnews
Jun 17, 2026 · Hacker News
FortiBleed Leaks VPN Credentials for 73k Devices
FortiBleed data leak exposes Fortinet VPN credentials for approximately 73,000 devices.
- fortinet
- vpn
- breach
- credentials
- info-disclosure
→ Read signalnews
Jun 17, 2026 · Hacker News
Mastra NPM Scope Compromise Targets Crypto Wallets
140+ @mastra packages hijacked via dormant maintainer account; typosquat easy-day-js drops cross-platform stealer.
- npm
- supply-chain
- stealer
- lazarus
→ Read signalnews
Jun 17, 2026 · vx-underground
Malicious Steam Workshop Wallpapers Steal Accounts
Kaspersky finds dozens of trojanized Wallpaper Engine app wallpapers on Steam Workshop with tens of thousands of downloads.
- malware
- stealer
- gaming
- steam
→ Read signalnews
Jun 16, 2026 · vx-underground
152 Chrome Wallpaper Extensions Hide Ad Fraud
Network of 152 Chrome live wallpaper extensions faked web traffic and AdSense clicks; 105,000+ combined installs.
- malware
- chrome
- ad-fraud
- extensions
→ Read signalnews
Jun 15, 2026 · vx-underground
Mirai Variant Targets IoT Telnet
Modified Mirai strain scanning telnet with updated credentials and DGA C2.
→ Read signalnews
Jun 15, 2026 · Sploitus
shell-quote quote() Newline Command Injection (CVE-2026-9277)
Sploitus-indexed PoC shows object-token newline in shell-quote quote() becomes POSIX command separator; fix in 1.8.4.
- npm
- nodejs
- command-injection
- cve
- supply-chain
→ Read signalnews
Jun 14, 2026 · Sploitus
Bookly WordPress Stored XSS via Cookie (CVE-2026-5513)
Unauthenticated stored XSS in Bookly ≤27.2 via bookly-customer-full-name cookie; scanner PoC indexed on Sploitus.
- wordpress
- bookly
- xss
- cve
- plugin
→ Read signalnews
Jun 13, 2026 · Sploitus
Apache HTTP/2 Bomb DoS (CVE-2026-49975)
Single-connection HPACK bomb plus flow-control stall can exhaust gigabytes of RAM; public PoC indexed on Sploitus.
→ Read signalnews
Jun 13, 2026 · Sploitus
Avada Builder WordPress Unauthenticated RCE (CVE-2026-6279)
Sploitus-indexed PoC abuses fusion_get_widget_markup AJAX with leaked nonce to call_user_func arbitrary PHP functions.
- wordpress
- avada
- rce
- cve
- php
- fusion-builder
→ Read signalnews
Jun 13, 2026 · Sploitus
PeopleSoft SSRF PoC Enables Unauthenticated RCE (CVE-2026-35273)
Sploitus-indexed PoC chains SSRF via PSIGW HttpListeningConnector into cloud credential theft and remote code execution.
- peoplesoft
- ssrf
- rce
- cve
- oracle
- cloud
→ Read signalnews
Jun 11, 2026 · Sploitus
JCE Joomla Unauthenticated RCE (CVE-2026-48907)
Sploitus-indexed PoCs chain unauthenticated JCE profile import to PHP execution in Joomla tmp/; CVSS 10.0.
- joomla
- jce
- rce
- cve
- cms
- file-upload
→ Read signalnews
Jun 11, 2026 · Project Nightcrawler
GreatXML: WinRE Defender Offline Scan BitLocker Bypass
MSNightmare PoC plants unattend.xml and Recovery artifacts on the WinRE partition — Shift+Restart into Defender offline-scan state spawns a shell with BitLocker volume access; no CVE, contested reproduction.
- microsoft
- bitlocker
- zero-day
- windows
- winre
- defender
- physical-access
- bypass
- unattend
→ Read signalnews
Jun 11, 2026 · Microsoft MSRC
Patch Tuesday: 3 Zero-Days Addressed
June Patch Tuesday addresses 67 CVEs including 3 actively exploited zero-days.
→ Read signalnews
Jun 10, 2026 · Cyderes Howler Cell
RoguePlanet: Defender Quarantine Pipeline LPE Zero-Day
MSNightmare PoC races Defender's quarantine pipeline via NTFS junctions and oplocks to reach NT AUTHORITY\SYSTEM — no CVE, no patch, reproduced on fully patched Win11.
- microsoft
- defender
- zero-day
- privilege-escalation
- windows
- toctou
- lpe
- local
→ Read signalnews
Jun 8, 2026 · Project Nightcrawler
MiniPlasma: Cloud Files Driver Regression LPE (CVE-2020-17103)
Nightmare-Eclipse weaponizes James Forshaw's 2020 cldflt!HsmOsBlockPlaceholderAccess bug — original Project Zero PoC works unchanged on fully patched Win11; race to SYSTEM shell.
- microsoft
- windows
- cve
- privilege-escalation
- cldflt
- lpe
- local
- zero-day
- regression
→ Read signalnews
May 30, 2026 · Sploitus
WP Maps Pro Unauthenticated Admin Creation (CVE-2026-8732)
Sploitus mass-scanner PoCs abuse wpgmp_temp_access_ajax with public fc-call-nonce to create administrator accounts.
- wordpress
- privilege-escalation
- cve
- plugin
- auth-bypass
→ Read signalnews
May 22, 2026 · Sploitus
NGINX Rift Heap Overflow RCE (CVE-2026-42945)
18-year-old rewrite-module desync enables pre-auth RCE; depthfirst PoC indexed on Sploitus with Docker lab and exploit modes.
- nginx
- rce
- cve
- rewrite
- depthfirst
→ Read signalnews
May 15, 2026 · Project Nightcrawler
YellowKey: WinRE BitLocker Security Bypass (CVE-2026-45585)
Nightmare-Eclipse PoC replays FsTx transactions in WinRE via USB/EFI staging — CTRL during recovery reboot spawns shell with BitLocker volume access; patched June 2026.
- microsoft
- bitlocker
- cve
- windows
- winre
- physical-access
- bypass
→ Read signalnews
May 13, 2026 · Project Nightcrawler
GreenPlasma: CTFMON Arbitrary Section LPE (CVE-2026-45586)
Nightmare-Eclipse PoC races Winlogon desktop switch to redirect CTF.AsmListCache section creation via Object Manager symlinks — stripped PoC, full SYSTEM chain left as CTF challenge.
- microsoft
- windows
- cve
- privilege-escalation
- ctfmon
- lpe
- local
- zero-day
→ Read signalnews
Apr 20, 2026 · Project Nightcrawler
UnDefend: Defender Update-Pipeline DoS (CVE-2026-45498)
Nightmare-Eclipse standard-user PoC locks Defender signature/engine files — passive mode blocks updates, aggressive mode can disable the engine on platform updates; CISA KEV.
- microsoft
- defender
- cve
- denial-of-service
- windows
- edr
- local
→ Read signalnews
Apr 16, 2026 · Project Nightcrawler
RedSun: Defender Cloud-Tag Remediation LPE (CVE-2026-41091)
Nightmare-Eclipse PoC abuses Defender's cloud-tagged file restore path to write TieringEngineService.exe into System32 as SYSTEM — CISA KEV, patched May 2026 OOB.
- microsoft
- defender
- cve
- privilege-escalation
- windows
- toctou
- lpe
- local
- zero-day
→ Read signalnews
Apr 3, 2026 · Project Nightcrawler
BlueHammer: Defender Signature-Update TOCTOU LPE (CVE-2026-33825)
Nightmare-Eclipse PoC races MpSigStub.exe signature updates via oplocks and NTFS junctions to duplicate SAM/SYSTEM hives as SYSTEM — CISA KEV, patched April 2026.
- microsoft
- defender
- cve
- privilege-escalation
- windows
- toctou
- lpe
- local
- zero-day
→ Read signalnews
Dec 13, 2025 · Sploitus
React2Shell RCE in React Server Components (CVE-2025-55182)
Critical CVSS 10.0 RCE in react-server-dom-webpack affects React 19 and Next.js App Router; public PoC scanner indexed on Sploitus.
- react
- nextjs
- rce
- cve
- deserialization
→ Read signal