OFFSITE.DARK

Transmission

SIGNALS

Third-party vulnerability intel indexed from public sources — Sploitus, Project Nightcrawler, Church of Malware, vx-underground, Hacker News, and others — for security research inquiry. OFFSITE.DARK does not discover or weaponize exploits; we index, analyze, attribute sources, and ask whether they have research value.

93 signals

news

Jul 29, 2026 · Project Nightcrawler

ByePg Pure-Rust PatchGuard Research Port on Nightcrawler

invalid/ByePg mirrors a pure-Rust WDK #PF/PatchGuard observation driver on Project Nightcrawler — research continuation of can1357’s 2019 technique, not a new NightmareEclipse drop.

  • windows
  • kernel
  • patchguard
  • research
  • rust
  • nightcrawler
  • driver
→ Read signal

news

Jul 28, 2026 · Sploitus

NGINX 2026 Data-Plane Multi-CVE Pack (Proxy/Rewrite/Map/OCSP)

CTI pack covering five config-dependent NGINX data-plane CVEs (OCSP bypass, HTTP/2 injection, rewrite/map/gRPC heap overflows); public scanners indexed on Sploitus.

  • nginx
  • f5
  • cve
  • http2
  • grpc
  • heap-overflow
  • reverse-proxy
→ Read signal

news

Jul 25, 2026 · Sploitus

Android Futex PI UAF Root Chains (CVE-2026-43499)

Futex PI use-after-free (kernel 2.6.39–pre-7.1) powers GhostLock/unplus-style locked-bootloader root on GKI 6.12; dual PoCs topped Sploitus weekly list.

  • android
  • linux
  • kernel
  • lpe
  • cve
  • futex
  • selinux
  • gki
→ Read signal

news

Jul 25, 2026 · Sploitus

Linux AF_ALG + splice Local Privilege Escalation (CVE-2026-31431)

Kernel LPE via AF_ALG crypto sockets and splice() heap corruption; public PoCs claim Ubuntu/RHEL/Amazon/SUSE reachability; patch and blacklist algif_aead.

  • linux
  • kernel
  • lpe
  • cve
  • af-alg
  • crypto
  • local
→ Read signal

news

Jul 25, 2026 · Sploitus

Microweber Unauthenticated File Read (CVE-2026-65694)

Query-parameter path override on /userfiles/{path} yields unauth arbitrary file read (Laravel .env, etc.) in Microweber ≤ 2.0.20; PoC indexed on Sploitus.

  • cms
  • microweber
  • path-traversal
  • cve
  • laravel
  • file-read
→ Read signal

news

Jul 25, 2026 · Sploitus

WatchGuard Fireware IKEv2 Out-of-Bounds Write (CVE-2025-9242)

Critical Fireware IKEv2 flaw with version-pinned PoC and detection-only scanner resurfaced in Sploitus weekly list; triage internet-facing VPN endpoints.

  • watchguard
  • fireware
  • ikev2
  • vpn
  • cve
  • rce
  • appliance
→ Read signal

news

Jul 23, 2026 · Sploitus

Certighost: AD CS Chase Impersonation (CVE-2026-54121)

July 2026 AD CS chase fallback lets low-priv users coerce CA into issuing DC-identity certs; patched Patch Tuesday; public Certighost PoC indexed.

  • microsoft
  • adcs
  • active-directory
  • cve
  • certificate
  • kerberos
  • domain
→ Read signal

news

Jul 23, 2026 · Sploitus

Easy Appointments Unauthenticated IDOR (CVE-2026-61946)

Public reservation endpoint accepted client-supplied appointment id and overwrote victim bookings; fixed in Easy Appointments 3.12.28; PoC on Sploitus.

  • wordpress
  • idor
  • cve
  • appointments
  • patchstack
→ Read signal

news

Jul 21, 2026 · Sploitus

Fastjson 1.x Spring Boot Fat-JAR RCE (CVE-2026-16723)

Default-config RCE in fastjson 1.2.68–1.2.83 on Spring Boot fat-JARs; ITW since late July; fix in 1.2.84 or SafeMode / migrate to fastjson2.

  • java
  • fastjson
  • rce
  • cve
  • spring-boot
  • deserialization
  • itw
→ Read signal

news

Jul 17, 2026 · Sploitus

WP2Shell: WordPress REST Batch SQLi to RCE (CVE-2026-63030)

Unauthenticated REST batch route confusion yields SQLi and optional admin→plugin RCE; CISA KEV, Rapid Escalation scanning, public checkers indexed on Sploitus.

  • wordpress
  • sqli
  • rce
  • cve
  • rest-api
  • cisa-kev
  • pre-auth
→ Read signal

news

Jul 14, 2026 · Project Nightcrawler

LegacyHive: User Profile Service Arbitrary Hive Load Zero-Day

MSNightmare ninth drop — stripped ProfSvc PoC redirects UsrClass.dat across user boundaries on July 2026-patched Windows; Cyderes reproduced; no CVE, no Microsoft OS patch as of 2026-07-31.

  • microsoft
  • windows
  • zero-day
  • privilege-escalation
  • profsvc
  • registry
  • hive
  • lpe
  • local
→ Read signal

news

Jul 1, 2026 · Exploitarium

curl SMTP EXPN Recipient CRLF Command Injection

CRLF in CURLOPT_MAIL_RCPT operand injects full MAIL/RCPT/DATA transaction after authenticated EXPN — stock curl completes injected message.

  • curl
  • smtp
  • crlf-injection
  • exploitarium
→ Read signal

news

Jul 1, 2026 · Exploitarium

libarchive ZIP Declared-Size Boundary Bypass via debuginfod

ZIP64 entry advertises 109 bytes but stock bsdunzip streams 4GiB+109 — debuginfod indexes and serves ELF sections past the metadata boundary.

  • libarchive
  • zip
  • debuginfod
  • exploitarium
→ Read signal

news

Jul 1, 2026 · Exploitarium

Ladybird WebAssembly ESM Host Function RCE PoC

Dangling Wasm FunctionType reference plus memory64 ImageData leak chains to native code execution in WebContent — marker touch /tmp/ladybird_wasm_esm_rce.

  • ladybird
  • wasm
  • browser
  • rce
  • exploitarium
→ Read signal

news

Jul 1, 2026 · Exploitarium

NodeBB 4.13.2 ActivityPub attributedTo Local UID Spoof

Signed remote Create(Note) with numeric attributedTo binds to local uid — private chat and public posts appear from spoofed administrator account.

  • nodebb
  • activitypub
  • federated
  • exploitarium
→ Read signal

news

Jul 1, 2026 · Exploitarium

Next.js unstable_cache Object Argument Cache-Key Collision

Passing Request, URLSearchParams, or FormData into unstable_cache() collapses cache keys to {} while callbacks read live per-request data — first writer wins across restarts.

  • nextjs
  • cache
  • exploitarium
→ Read signal

news

Jul 1, 2026 · Exploitarium

Pillow 12.3.0 ImageCmsTransform output_mode OOB Write

Mutating transform.output_mode after RGB→RGBA build allocates L image while LittleCMS copies 4-byte stride — heap OOB write in _imagingcms.

  • pillow
  • imagecms
  • heap
  • exploitarium
→ Read signal

news

Jul 1, 2026 · Exploitarium

QEMU CXL Type-3 Mailbox Host Escape PoC

Guest CXL mailbox GET_LOG/SET_FEATURE bugs leak host pointers and forge MemoryRegionOps — host marker id>/tmp/qemu_cxl_escape_marker on QEMU 11.0.50.

  • qemu
  • cxl
  • hypervisor
  • escape
  • exploitarium
→ Read signal

news

Jul 1, 2026 · Sploitus

Exploitarium — Consolidated PoC Research Collection

bikini/exploitarium bundles 30 standalone PoC folders — MotW chains, libssh2, FFmpeg, hypervisor escape, and client RCE candidates.

  • sploitus
  • exploitarium
  • poc
  • research
  • collection
→ Read signal

news

Jul 1, 2026 · Socket

PolinRider NK Supply Chain Hits Go, Packagist, Chrome

162 malicious artifacts across 108 packages in npm, Go, Packagist, and Chrome; DPRK-linked loaders hide in config files and fake .woff2 fonts.

  • supply-chain
  • npm
  • lazarus
  • north-korea
  • go
  • packagist
  • chrome
  • malware
→ Read signal

news

Jun 29, 2026 · Sploitus

Audiobookshelf Unauthenticated API Auth Bypass Scanner (CVE-2025-25205)

Metasploit auxiliary scanner detects unanchored regex auth bypass on /api/libraries — versions 2.17.0–2.19.0.

  • audiobookshelf
  • auth-bypass
  • cve-2025-25205
  • metasploit
  • scanner
→ Read signal

news

Jun 29, 2026 · Sploitus

Dalfox Found-Action Deserialization RCE (CVE-2026-45087)

dalfox server mode POST /scan accepts FoundAction/FoundActionShell in JSON — unauthenticated RCE on 0.0.0.0:6664 when no --api-key.

  • dalfox
  • xss
  • rce
  • cve-2026-45087
  • go
→ Read signal

news

Jun 29, 2026 · Sploitus

The Events Calendar Unauthenticated SQLi (CVE-2026-49772)

Broken REST validate_callback lets order reach ORDER BY — blind boolean/time extraction of wp_users hashes via tec/v1 API.

  • wordpress
  • sqli
  • cve-2026-49772
  • the-events-calendar
→ Read signal

news

Jun 29, 2026 · Sploitus

Exploit Arsenal — Consolidated CVE PoC Collection

GODofExploit/exploit-arsenal bundles stdlib Python 3 PoCs — CVE-2026-0920, 0926, 1470, CVSS up to 9.9.

  • sploitus
  • exploit-arsenal
  • poc
  • wordpress
  • n8n
  • collection
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

7-Zip RAR5 MotW/ADS Full-Chain PoC

Crafted RAR5 STM streams overwrite extracted file bytes and Zone.Identifier on 7-Zip 26.01 — MotW bypass chain.

  • 7zip
  • motw
  • windows
  • rar5
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

AnyDesk 9.7.6 Printer Pipe COM Impersonation LPE

AnyDesk printer worker unmarshals attacker COM bytes on the adprinterpipe named pipe with RPC_C_IMP_LEVEL_IMPERSONATE — SYSTEM when installed as service.

  • anydesk
  • lpe
  • com
  • windows
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

c-ares TCP ares_getaddrinfo() UAF Calc PoC

Loopback DNS-over-TCP EDNS retry sequence leaves stale skip-list state; cleanup reaches attacker-shaped destructor — calc proof on main and v1.34.6.

  • c-ares
  • uaf
  • dns
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Docker cp Copy-Out Destination Escape

Container races host `docker cp` copy-out so extraction writes sibling path outside requested destination — validated on Engine 29.6.0.

  • docker
  • container
  • escape
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Floci 1.5.27 API Gateway VTL RCE + IAM Scope Bypass

Velocity templates in Floci API Gateway integration responses reach ProcessBuilder; wrong SigV4 credential scope bypasses IAM enforcement.

  • floci
  • vtl
  • aws-emulator
  • rce
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Flowise 3.1.2 MCP NODE_OPTIONS Case Bypass

Custom MCP stdio blocks `NODE_OPTIONS` by exact case; Windows honors `node_options` — preload arbitrary JS in child Node process.

  • flowise
  • node
  • windows
  • rce
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Firefox Smart Window Private URL Exfiltration

Smart Window sets privateData without untrustedInput — attacker titles coerce get_page_content to fetch expanded private tab/history URL tokens.

  • firefox
  • privacy
  • smart-window
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Ghidra 12.1.2 Conditional ACE / TraceRMI RCE Surfaces

Packaged calc PoCs for Swift demangler tool path ACE, conditional TraceRMI agent command execution, and SevenZipJBinding reachability.

  • ghidra
  • ace
  • tracermi
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

FFmpeg RASC DLTA Heap OOB Write Calc PoC

Crafted RASC bitstream in AVI/RIFF overwrites adjacent callback pointer in PAL8 one-row decode — Calculator proof on upstream master.

  • ffmpeg
  • rasc
  • heap
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Gitea act_runner container.options Host Namespace Bypass

Workflow `container.options` preserves --pid=host and cap-add=ALL while Privileged=false — nsenter writes host marker from job container.

  • gitea
  • actions
  • docker
  • ci
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

ImageMagick Ghostscript Delegate Path Hijack

Bare `gswin64c.exe` delegate on Windows resolves from CWD — planted binary executes when processing PDF/PS in attacker-writable directory.

  • imagemagick
  • ghostscript
  • windows
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

libssh2 Publickey List Parser Calc PoCs

Win32 attrs allocation wrap and Win64 cleanup arbitrary-free chains in publickey list fetch — live SSH session calc replay included.

  • libssh2
  • heap
  • publickey
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

MyBB 1.8.40 Limited ACP to Full Administrator

ACP user-manager permission alone can create gid=4 Administrator accounts — verify_usergroup() accepts any group.

  • mybb
  • privilege-escalation
  • php
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

libssh2 CVE-2026-55200 Packet Length Integer Wrap

Unchecked SSH packet_length wraps allocation to 19 bytes while logical length stays 0xffffffff — local RCE harness models post-allocation misuse.

  • libssh2
  • cve-2026-55200
  • ssh
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

nghttpx HTTP/1.1 Upgrade Response Queue Poisoning

Upgrade request with Content-Length leaves backend bytes parsed as next request — smuggled response delivered to victim client on reused connection.

  • nghttp2
  • nghttpx
  • smuggling
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Lunar Client Modrinth Explore RCE Chain

rehypeRaw Markdown + preload IPC forges Modrinth profile overrides and openExternal local launcher — critical candidate CVSS ~9.6.

  • lunar
  • modrinth
  • electron
  • rce
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

objdump DLX Backend OOB Write Calc PoC

Crafted ELF/DLX objects via objdump -g reach calc callback — ASLR-relative delta strategy; credit 4D4J/objdump-Out-Of-Bounds-write.

  • binutils
  • objdump
  • elf
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

OpenVPN Connect Echo Script ACE + PAC Push

Malicious server push decodes script.win.user.disconnect via echo option — runs on disconnect despite scriptsPermissionGranted=false.

  • openvpn
  • vpn
  • ace
  • windows
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

Nmap IPv6 Extension Header Length Wrap

Hop-by-Hop ext len=1 on 48-byte capture advances payload offset past buffer — wrapped payload_len 4294967288 in harness.

  • nmap
  • ipv6
  • parser
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

RustDesk Session Downgrade + FileTransfer Scope Bypass

Relay can force non-secure session after auth; FileTransfer-authorized sessions reach screen/input handlers gated only by broad authorized flag.

  • rustdesk
  • remote-desktop
  • relay
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

PHP 8.5.7 StreamBucket SOAP Numeric Cookie RCE

StreamBucket type confusion chains to fake HashTable write and zend_execute_internal hook — marker PHP857_RCE validated locally.

  • php
  • deserialization
  • soap
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

System Informer phsvc Trusted-Host LPE

phsvc accepts any Authenticode-trusted client image — code in rundll32 connects to SiSvcApiPort and runs elevated helper APIs.

  • system-informer
  • lpe
  • alpc
  • windows
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus / Exploitarium

VLC 3.0.23 VP9 Resolution-Change Crash

405-byte IVF 64×64 then 64×8192 frame hits stale slice-thread entries allocation — research ongoing toward stronger impact.

  • vlc
  • vp9
  • crash
  • exploitarium
→ Read signal

news

Jun 29, 2026 · Sploitus

FFmpeg MagicYUV Decoder OOB Write Crash (CVE-2026-8461)

libavcodec/magicyuv.c OOB write — crafted AVI crashes unpatched FFmpeg < 8.1.2; CVSS 8.8, distinct from Exploitarium RASC PoC.

  • ffmpeg
  • magicyuv
  • cve-2026-8461
  • dos
  • media
→ Read signal

news

Jun 29, 2026 · Sploitus

Forminator Stored XSS via form_name (CVE-2026-2002)

wp_kses_post runs before forminator_replace_variables — javascript: in form_name bypasses sanitization; CVSS 4.4.

  • wordpress
  • xss
  • cve-2026-2002
  • forminator
→ Read signal

news

Jun 29, 2026 · Sploitus

Linux Kernel net/sched Partial COW Page Cache Corruption (CVE-2026-46331)

act_pedit skb_ensure_writable() computes COW range before runtime offsets — page cache corruption, potential LPE, CVSS 7.8.

  • linux
  • kernel
  • net-sched
  • cve-2026-46331
  • lpe
→ Read signal

news

Jun 29, 2026 · Sploitus

Log4J-PoC — TPAS Log4Shell Lab Stack

TPAS coursework repo: React storefront + vulnerable Log4j 2.14 Spring API + JNDI exploit script with WAF-bypass toggle.

  • log4j
  • log4shell
  • cve-2021-44228
  • java
  • sploitus
→ Read signal

news

Jun 29, 2026 · Sploitus

LiteLLM Proxy Pre-Auth SQL Injection Scanner (CVE-2026-42208)

Authorization bearer interpolated into PostgreSQL token lookup — pre-auth blind SQLi on LiteLLM 1.81.16–1.83.6; fixed 1.83.7, CVSS 9.8.

  • litellm
  • sqli
  • cve-2026-42208
  • metasploit
  • ai
→ Read signal

news

Jun 29, 2026 · Sploitus

Next.js Middleware Authorization Bypass Scanner (CVE-2025-29927)

x-middleware-subrequest header skips middleware auth gates on self-hosted Next.js < 12.3.5 / 13.5.9 / 14.2.25 / 15.2.3 — CVSS 9.1.

  • nextjs
  • middleware
  • auth-bypass
  • cve-2025-29927
  • metasploit
→ Read signal

news

Jun 29, 2026 · Sploitus

Peyara Remote Mouse 1.0.1 Unauthenticated RCE

WebSocket keyboard simulation on port 1313 chains to arbitrary commands; indexed PoCs include Python and LNK upload variants.

  • peyara
  • rce
  • websocket
  • windows
  • remote-access
→ Read signal

news

Jun 29, 2026 · Sploitus

TLS1.2_Exploit-Scripts — Misconfigured TLS Pentest Lab

Six lab scripts demonstrate LOGJAM, LUCKY13, session ticket hijack, SSL strip, cert MITM, and RC4 JWT forgery against deliberate nginx 1.18 misconfig.

  • tls
  • tls1.2
  • pentest
  • education
  • sploitus
→ Read signal

news

Jun 29, 2026 · Sploitus

WP Activity Log PHP Object Injection to RCE (CVE-2026-54806)

Unauthenticated User-Agent POI stored in audit log; WP_HTML_Token gadget deserializes on admin dashboard view — blind RCE, CVSS 9.8.

  • wordpress
  • php
  • deserialization
  • cve-2026-54806
  • rce
→ Read signal

news

Jun 25, 2026 · Sploitus

Burst Statistics WordPress Auth Bypass (CVE-2026-8181)

Sploitus-indexed flaw in is_mainwp_authenticated() lets unauthenticated attackers impersonate admins with any Basic Auth password.

  • wordpress
  • auth-bypass
  • cve
  • plugin
  • privilege-escalation
→ Read signal

news

Jun 25, 2026 · Sploitus

Cisco CUCM SSRF to RCE Chain (CVE-2026-20230)

Sploitus-indexed PoC analysis chains unauthenticated WebDialer SSRF through Axis internals to arbitrary file write and RCE.

  • cisco
  • cucm
  • ssrf
  • rce
  • cve
  • voip
  • telecom
→ Read signal

news

Jun 25, 2026 · Sploitus

Claude Desktop Cowork VM Integrity Bypass (CVE-2026-7574)

Sploitus-indexed local flaw: Cowork trusts rootfs.img existence/version without hash or signature, enabling VM persistence.

  • anthropic
  • claude
  • local
  • persistence
  • cve
  • vm
→ Read signal

news

Jun 24, 2026 · Sploitus

Krayin CRM TinyMCE Upload RCE (CVE-2026-38526)

Sploitus-indexed authenticated PoC uploads PHP via /admin/tinymce/upload to public storage for www-data execution.

  • krayin
  • crm
  • rce
  • cve
  • file-upload
  • laravel
→ Read signal

news

Jun 22, 2026 · Sploitus

SP Page Builder Joomla Unauthenticated RCE (CVE-2026-48908)

Pre-auth ZIP upload to com_sppagebuilder iconfont path enables .PHP execution via .htaccess bypass; CVSS 10.0.

  • joomla
  • rce
  • cve
  • cms
  • file-upload
  • joomshaper
→ Read signal

news

Jun 19, 2026 · Sploitus

BIND 9 Resolver Unbounded Loop DoS (CVE-2026-5950)

Unchecked resend loop in BIND 9 bad-server handling enables remote resource exhaustion; defensive notes indexed on Sploitus.

  • bind
  • dns
  • dos
  • cve
  • isc
→ Read signal

news

Jun 19, 2026 · Church of Malware

ek0ms savi0r Publishes REAPER GitHub Secret Scanner

ek0ms savi0r publishes REAPER on Church of Malware git — Go-based GitHub hidden secret scanner.

  • tools
  • github
  • secrets
  • offensive
→ Read signal

news

Jun 19, 2026 · Sploitus

GitLab WebAuthn 2FA Bypass (CVE-2026-2745)

Authentication bypass in GitLab WebAuthn 2FA due to inconsistent input validation; advisory indexed on exploit search engines.

  • gitlab
  • webauthn
  • auth-bypass
  • cve
  • 2fa
→ Read signal

news

Jun 19, 2026 · Sploitus

JupyterHub CSRF XSRF Bypass (CVE-2026-40864)

Sec-Fetch-Mode: no-cors misclassified as same-origin bypasses XSRF on /hub/spawn and /hub/accept-share; PoC indexed on Sploitus.

  • jupyterhub
  • csrf
  • xsrf
  • cve
  • jupyter
→ Read signal

news

Jun 19, 2026 · Sploitus

kit-exploits-prv — Sploitus PoC Collection Roundup

kit-exploits-prv indexes a curated private PoC collection for authorized security testing.

  • sploitus
  • poc
  • exploit-kit
  • research
→ Read signal

news

Jun 18, 2026 · Hacker News

10k GitHub Repos Found Distributing Trojan Malware

Researcher identifies ~10,000 GitHub repos cloning legitimate projects and pushing trojanized README zip archives.

  • malware
  • supply-chain
  • github
→ Read signal

news

Jun 18, 2026 · Hacker News

Nginx HTTP/3 QUIC Zero-Day (CVE-2026-42530)

Remote code execution in NGINX Open Source 1.31.0–1.31.1 when HTTP/3 QUIC is enabled; patched in 1.31.2.

  • nginx
  • zero-day
  • rce
  • cve
  • quic
→ Read signal

news

Jun 18, 2026 · Hacker News

Popa Botnet Linked to NetNut Proxy Provider

Popa Android TV box botnet (~1.5–2.5M daily IPs) linked to publicly-traded Israeli firm Alarum/NetNut.

  • botnet
  • iot
  • proxy
  • android
→ Read signal

news

Jun 17, 2026 · Church of Malware

mastercodeon Publishes Peercord P2P Chat on Church of Malware Git

mastercodeon publishes Peercord on Church of Malware git — decentralized Discord-like social platform.

  • tools
  • p2p
  • infra
  • decentralized
→ Read signal

news

Jun 17, 2026 · Hacker News

FortiBleed Leaks VPN Credentials for 73k Devices

FortiBleed data leak exposes Fortinet VPN credentials for approximately 73,000 devices.

  • fortinet
  • vpn
  • breach
  • credentials
  • info-disclosure
→ Read signal

news

Jun 17, 2026 · Hacker News

Mastra NPM Scope Compromise Targets Crypto Wallets

140+ @mastra packages hijacked via dormant maintainer account; typosquat easy-day-js drops cross-platform stealer.

  • npm
  • supply-chain
  • stealer
  • lazarus
→ Read signal

news

Jun 17, 2026 · vx-underground

Malicious Steam Workshop Wallpapers Steal Accounts

Kaspersky finds dozens of trojanized Wallpaper Engine app wallpapers on Steam Workshop with tens of thousands of downloads.

  • malware
  • stealer
  • gaming
  • steam
→ Read signal

news

Jun 16, 2026 · vx-underground

152 Chrome Wallpaper Extensions Hide Ad Fraud

Network of 152 Chrome live wallpaper extensions faked web traffic and AdSense clicks; 105,000+ combined installs.

  • malware
  • chrome
  • ad-fraud
  • extensions
→ Read signal

news

Jun 15, 2026 · vx-underground

Mirai Variant Targets IoT Telnet

Modified Mirai strain scanning telnet with updated credentials and DGA C2.

  • mirai
  • iot
  • botnet
  • telnet
→ Read signal

news

Jun 15, 2026 · Sploitus

shell-quote quote() Newline Command Injection (CVE-2026-9277)

Sploitus-indexed PoC shows object-token newline in shell-quote quote() becomes POSIX command separator; fix in 1.8.4.

  • npm
  • nodejs
  • command-injection
  • cve
  • supply-chain
→ Read signal

news

Jun 14, 2026 · Sploitus

Bookly WordPress Stored XSS via Cookie (CVE-2026-5513)

Unauthenticated stored XSS in Bookly ≤27.2 via bookly-customer-full-name cookie; scanner PoC indexed on Sploitus.

  • wordpress
  • bookly
  • xss
  • cve
  • plugin
→ Read signal

news

Jun 13, 2026 · Sploitus

Apache HTTP/2 Bomb DoS (CVE-2026-49975)

Single-connection HPACK bomb plus flow-control stall can exhaust gigabytes of RAM; public PoC indexed on Sploitus.

  • apache
  • http2
  • dos
  • cve
  • hpack
→ Read signal

news

Jun 13, 2026 · Sploitus

Avada Builder WordPress Unauthenticated RCE (CVE-2026-6279)

Sploitus-indexed PoC abuses fusion_get_widget_markup AJAX with leaked nonce to call_user_func arbitrary PHP functions.

  • wordpress
  • avada
  • rce
  • cve
  • php
  • fusion-builder
→ Read signal

news

Jun 13, 2026 · Sploitus

PeopleSoft SSRF PoC Enables Unauthenticated RCE (CVE-2026-35273)

Sploitus-indexed PoC chains SSRF via PSIGW HttpListeningConnector into cloud credential theft and remote code execution.

  • peoplesoft
  • ssrf
  • rce
  • cve
  • oracle
  • cloud
→ Read signal

news

Jun 11, 2026 · Sploitus

JCE Joomla Unauthenticated RCE (CVE-2026-48907)

Sploitus-indexed PoCs chain unauthenticated JCE profile import to PHP execution in Joomla tmp/; CVSS 10.0.

  • joomla
  • jce
  • rce
  • cve
  • cms
  • file-upload
→ Read signal

news

Jun 11, 2026 · Project Nightcrawler

GreatXML: WinRE Defender Offline Scan BitLocker Bypass

MSNightmare PoC plants unattend.xml and Recovery artifacts on the WinRE partition — Shift+Restart into Defender offline-scan state spawns a shell with BitLocker volume access; no CVE, contested reproduction.

  • microsoft
  • bitlocker
  • zero-day
  • windows
  • winre
  • defender
  • physical-access
  • bypass
  • unattend
→ Read signal

news

Jun 11, 2026 · Microsoft MSRC

Patch Tuesday: 3 Zero-Days Addressed

June Patch Tuesday addresses 67 CVEs including 3 actively exploited zero-days.

  • windows
  • patches
  • zero-day
→ Read signal

news

Jun 10, 2026 · Cyderes Howler Cell

RoguePlanet: Defender Quarantine Pipeline LPE Zero-Day

MSNightmare PoC races Defender's quarantine pipeline via NTFS junctions and oplocks to reach NT AUTHORITY\SYSTEM — no CVE, no patch, reproduced on fully patched Win11.

  • microsoft
  • defender
  • zero-day
  • privilege-escalation
  • windows
  • toctou
  • lpe
  • local
→ Read signal

news

Jun 8, 2026 · Project Nightcrawler

MiniPlasma: Cloud Files Driver Regression LPE (CVE-2020-17103)

Nightmare-Eclipse weaponizes James Forshaw's 2020 cldflt!HsmOsBlockPlaceholderAccess bug — original Project Zero PoC works unchanged on fully patched Win11; race to SYSTEM shell.

  • microsoft
  • windows
  • cve
  • privilege-escalation
  • cldflt
  • lpe
  • local
  • zero-day
  • regression
→ Read signal

news

May 30, 2026 · Sploitus

WP Maps Pro Unauthenticated Admin Creation (CVE-2026-8732)

Sploitus mass-scanner PoCs abuse wpgmp_temp_access_ajax with public fc-call-nonce to create administrator accounts.

  • wordpress
  • privilege-escalation
  • cve
  • plugin
  • auth-bypass
→ Read signal

news

May 22, 2026 · Sploitus

NGINX Rift Heap Overflow RCE (CVE-2026-42945)

18-year-old rewrite-module desync enables pre-auth RCE; depthfirst PoC indexed on Sploitus with Docker lab and exploit modes.

  • nginx
  • rce
  • cve
  • rewrite
  • depthfirst
→ Read signal

news

May 15, 2026 · Project Nightcrawler

YellowKey: WinRE BitLocker Security Bypass (CVE-2026-45585)

Nightmare-Eclipse PoC replays FsTx transactions in WinRE via USB/EFI staging — CTRL during recovery reboot spawns shell with BitLocker volume access; patched June 2026.

  • microsoft
  • bitlocker
  • cve
  • windows
  • winre
  • physical-access
  • bypass
→ Read signal

news

May 13, 2026 · Project Nightcrawler

GreenPlasma: CTFMON Arbitrary Section LPE (CVE-2026-45586)

Nightmare-Eclipse PoC races Winlogon desktop switch to redirect CTF.AsmListCache section creation via Object Manager symlinks — stripped PoC, full SYSTEM chain left as CTF challenge.

  • microsoft
  • windows
  • cve
  • privilege-escalation
  • ctfmon
  • lpe
  • local
  • zero-day
→ Read signal

news

Apr 20, 2026 · Project Nightcrawler

UnDefend: Defender Update-Pipeline DoS (CVE-2026-45498)

Nightmare-Eclipse standard-user PoC locks Defender signature/engine files — passive mode blocks updates, aggressive mode can disable the engine on platform updates; CISA KEV.

  • microsoft
  • defender
  • cve
  • denial-of-service
  • windows
  • edr
  • local
→ Read signal

news

Apr 16, 2026 · Project Nightcrawler

RedSun: Defender Cloud-Tag Remediation LPE (CVE-2026-41091)

Nightmare-Eclipse PoC abuses Defender's cloud-tagged file restore path to write TieringEngineService.exe into System32 as SYSTEM — CISA KEV, patched May 2026 OOB.

  • microsoft
  • defender
  • cve
  • privilege-escalation
  • windows
  • toctou
  • lpe
  • local
  • zero-day
→ Read signal

news

Apr 3, 2026 · Project Nightcrawler

BlueHammer: Defender Signature-Update TOCTOU LPE (CVE-2026-33825)

Nightmare-Eclipse PoC races MpSigStub.exe signature updates via oplocks and NTFS junctions to duplicate SAM/SYSTEM hives as SYSTEM — CISA KEV, patched April 2026.

  • microsoft
  • defender
  • cve
  • privilege-escalation
  • windows
  • toctou
  • lpe
  • local
  • zero-day
→ Read signal

news

Dec 13, 2025 · Sploitus

React2Shell RCE in React Server Components (CVE-2025-55182)

Critical CVSS 10.0 RCE in react-server-dom-webpack affects React 19 and Next.js App Router; public PoC scanner indexed on Sploitus.

  • react
  • nextjs
  • rce
  • cve
  • deserialization
→ Read signal