Skip to content
feed: live
>_ 0dayNews
Marisol "Fuse" Delgado badge

Marisol "Fuse" Delgado

she/her · Practical defense — Patch Tuesday, the KEV tracker, what to actually do

Fuse isn’t shy about the fact that her past wasn’t a victimless curiosity story — she did real damage for real money in her 20s, got caught, and did federal time for it. What came after was a hard pivot into defensive consulting, because that was the only door still open, and because she’d rather be useful than nostalgic about it.

She has no patience for anyone who romanticizes what she did. She writes the practical stuff: what’s actually exploitable right now, what to patch first, what can wait. She does not discuss the specifics of her own past intrusions, in interviews or in print, ever.

Articles

~/articles/2026-07-13-jamf-crashstealer-werkbit-notarized-macos-stealer
Notarized Werkbit.app carries CrashStealer past Gatekeeper
apple

Notarized Werkbit.app carries CrashStealer past Gatekeeper

Jamf flagged CrashStealer, a native-C++ macOS infostealer arriving inside Werkbit.app — Apple-notarized and gated behind a meeting PIN.

read →
~/articles/2026-07-13-cisa-kev-cve-2008-4128-cisco-ios-12-4-csrf
Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV
● Breaking
cisco

Cisco IOS 12.4 CSRF From 2008 Lands in CISA KEV

CISA added CVE-2008-4128 — a Cisco IOS 12.4 mainline HTTP admin CSRF from 2008 — to the KEV catalog on 2026-07-13. IOS 12.4 mainline is obsolete. Upgrade.

read →
~/articles/2026-07-13-huntress-ai-generated-powershell-ad-enum
Huntress Flags Suspected AI-Written PowerShell in AD Case
threat intel

Huntress Flags Suspected AI-Written PowerShell in AD Case

Huntress attributes an early-June AD enumeration case to a PowerShell script with clear LLM tells — cyan-and-green banners and 'FULLY FIXED' in the title.

read →
~/articles/2026-07-12-redhook-group-ib-wireless-adb-loopback-shizuku-uid-2000
RedHook Android RAT pairs Wireless ADB on-device
mobile

RedHook Android RAT pairs Wireless ADB on-device

Group-IB details RedHook using Accessibility to enable Wireless Debugging, pair over loopback, and run shell as uid 2000. No CVE. Southeast Asia targeted.

read →
~/articles/2026-07-11-jscrambler-npm-8-14-0-preinstall-rust-infostealer
jscrambler 8.14.0 npm hijack: Rust stealer on install
● Breaking
supply chain

jscrambler 8.14.0 npm hijack: Rust stealer on install

Malicious jscrambler 8.14.0 on npm shipped a preinstall hook that dropped a Rust infostealer targeting cloud creds, wallets, and AI-coder configs.

read →
~/articles/2026-07-11-gitea-docker-cve-2026-20896-sysdig-csa-1264-regression
Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms
gitea

Gitea Docker Auth Bypass: Patch 1.26.4, CSA Confirms

Sysdig confirms the first in-the-wild hit on Gitea Docker CVE-2026-20896; Singapore CSA now warns customers; 1.26.3 shipped with a regression, so run 1.26.4.

read →
~/articles/2026-07-11-modbeacon-silver-fox-rust-rat-grpc-c2-qianxin
Silver Fox ships MODBEACON, a Rust RAT with gRPC C2
threat intel

Silver Fox ships MODBEACON, a Rust RAT with gRPC C2

QiAnXin attributes a new Rust-based RAT called MODBEACON to Silver Fox, using gRPC streaming for encrypted C2 and SEO-poisoned installers for delivery.

read →
~/articles/2026-07-11-cisa-kev-balbooa-icagenda-joomla-file-upload
Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days
threat intel

Balbooa, iCagenda Join KEV: Four Joomla RCEs in Four Days

CISA added Balbooa Forms and iCagenda to KEV on July 10 — two unauthenticated file-upload RCEs in Joomla extensions. Federal due date is July 13.

read →
~/articles/2026-07-11-zimbra-10-1-19-classic-web-client-xss-google-tag
Zimbra ships 10.1.19; Google TAG reported the XSS
zimbra

Zimbra ships 10.1.19; Google TAG reported the XSS

Zimbra 10.1.19 patches a stored XSS in the Classic Web Client. No CVE yet, no confirmed exploitation — Google TAG reported it, which is the reason to patch now.

read →
~/articles/2026-07-09-openmandriva-beatrici-mumble-contributor-repo-sabotage
OpenMandriva ex-contributor wipes GNOME, Cosmic packages
supply chain

OpenMandriva ex-contributor wipes GNOME, Cosmic packages

Mumble developer Davide Beatrici used leftover admin from a repo migration to delete OpenMandriva GitHub content and obsolete GNOME, Cosmic packages.

read →
~/articles/2026-07-09-injectivelabs-sdk-ts-npm-1-20-21-wallet-stealer
Injective SDK 1.20.21 on npm shipped a wallet stealer
supply chain

Injective SDK 1.20.21 on npm shipped a wallet stealer

Attacker pushed @injectivelabs/sdk-ts 1.20.21 with mnemonic and private-key exfil after compromising a contributor's GitHub. 310 installs before the pull.

read →
~/articles/2026-07-09-forg365-phaas-m365-aitm-device-code-zerobec
Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365
microsoft

Forg365 PhaaS Chains AiTM + Device-Code + AI Lures at M365

ZeroBEC flagged a new phishing-as-a-service, Forg365, bundling AiTM proxying with OAuth device-code prompts and AI lures against Microsoft 365 accounts.

read →
~/articles/2026-07-09-microsoft-defender-rogueplanet-cve-2026-50656-lpe-patch
Microsoft patches Defender 'RoguePlanet' LPE; PoC public
microsoft

Microsoft patches Defender 'RoguePlanet' LPE; PoC public

Microsoft shipped an out-of-band Defender engine update for RoguePlanet (CVE-2026-50656), a race-condition LPE to SYSTEM. Public PoC. Verify auto-update landed.

read →
~/articles/2026-07-09-simplehelp-cve-2026-48558-oidc-bypass-past-kev-deadline
SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now
simplehelp

SimpleHelp OIDC Auth Bypass Past CISA Deadline: Patch Now

SimpleHelp Server 5.5.15 and earlier accept forged OIDC tokens as valid technician sessions. CVSS 10.0, KEV, patch is 5.5.16 — CISA deadline was July 2.

read →
~/articles/2026-07-08-writeout-writer-ai-cross-tenant-session-sand-security
WriteOut: One Preview Link Took Over Writer AI Accounts
cloud

WriteOut: One Preview Link Took Over Writer AI Accounts

SAND Security's WriteOut let a Writer AI agent preview link steal a signed-in user's session cookie across tenants. Writer has patched — the pattern hasn't.

read →
~/articles/2026-07-08-gitlost-github-agentic-workflows-noma-security-private-repos
GitLost: Public Issue Leaks Private GitHub Repo Data
cloud

GitLost: Public Issue Leaks Private GitHub Repo Data

Noma Security's GitLost shows how a public GitHub issue can trick Agentic Workflows into leaking private repos. Not patchable — scope your agent tokens today.

read →
~/articles/2026-07-08-ghostlock-linux-kernel-cve-2026-43499-container-escape
GhostLock: 15-Year Linux Kernel Root/Container Escape
linux kernel

GhostLock: 15-Year Linux Kernel Root/Container Escape

Nebula Security's GhostLock (CVE-2026-43499) — a 15-year-old futex use-after-free — hits every mainstream Linux distro. Escapes containers. Patch again.

read →
~/articles/2026-07-08-cisa-kev-langflow-joomla-page-builder-adds
CISA Adds Langflow and Two Joomla Builders to KEV
threat intel

CISA Adds Langflow and Two Joomla Builders to KEV

CISA added three vulnerabilities to KEV on July 7 — a Langflow IDOR and two Joomla page-builder RCEs. Federal due date is July 10. Priority order below.

read →
~/articles/2026-07-07-tenda-router-backdoor-cve-2026-11405-unpatched
Tenda Router Backdoor Has No Patch. Here's What to Do.
ics ot

Tenda Router Backdoor Has No Patch. Here's What to Do.

CERT/CC flagged an authentication backdoor in multiple Tenda router firmware builds. Tenda didn't respond. No fix is coming — here's the mitigation.

read →
~/articles/2026-07-07-beyondtrust-remote-support-pra-auth-bypass
BeyondTrust Patches Four RS/PRA Flaws — Patch Now
beyondtrust

BeyondTrust Patches Four RS/PRA Flaws — Patch Now

BeyondTrust shipped fixes on July 6 for four vulnerabilities in Remote Support and Privileged Remote Access, including a CVSS 9.8 pre-auth bypass. No in-wild exploitation reported. Here's the priority order.

read →
~/articles/2026-07-06-gitea-docker-cve-2026-20896-header-auth-bypass
Gitea Docker's Auth Bypass: Probing Already Underway
gitea

Gitea Docker's Auth Bypass: Probing Already Underway

The Gitea Docker image up through 1.26.2 shipped a wildcard reverse-proxy trusted list, collapsing auth to a header. Fixed in 1.26.3. The Hacker News reports opportunistic scanning 13 days after disclosure; ~6,200 exposed instances.

read →
~/articles/2026-07-06-adobe-coldfusion-cve-2026-48282-active-exploitation
Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited
adobe

Adobe ColdFusion CVE-2026-48282: CVSS 10, Exploited

A max-severity unauthenticated path-traversal-to-RCE in ColdFusion 2023 and 2025 is under active attack. Adobe's 72-hour patch window has already passed. Shadowserver counts ~800 exposed instances.

read →
~/articles/2026-07-06-quimarat-java-cross-platform-maas-levelblue
QuimaRAT: A $150 Cross-Platform Java RAT MaaS
threat intel

QuimaRAT: A $150 Cross-Platform Java RAT MaaS

LevelBlue profiled a new cross-platform Java RAT sold as MaaS. No confirmed campaigns yet — but the price is low, the payload runs everywhere, and the loader is built to walk past SmartScreen. Assume it lands somewhere soon.

read →
~/articles/2026-07-06-opera-gx-mods-auto-install-flaw-patched
Opera GX Patches Auto-Install Mods Flaw
browser

Opera GX Patches Auto-Install Mods Flaw

Opera fixed a flaw that let a malicious website force-install a GX Mod and use CSS injection to lift data from pages you visited. Patched; no CVE; no in-wild exploitation reported.

read →
~/articles/2026-07-06-skillcloak-scanners-miss-agent-skill-malware-hkust
SkillCloak: Scanners Miss 90%+ of Skill Malware
supply chain

SkillCloak: Scanners Miss 90%+ of Skill Malware

HKUST researchers show static scanners for AI agent skill marketplaces miss over 90% of malware repackaged with simple tricks. If you rely on them, that gate is broken.

read →
~/articles/2026-07-05-flipper-zero-firmware-maintenance-only-community-driven
Flipper Zero Firmware Goes Maintenance-Only
threat intel

Flipper Zero Firmware Goes Maintenance-Only

Flipper Devices says the Flipper Zero firmware is stable at 1.0 and full-time feature work is over. Community PRs run the future, filtered through GitHub Discussions voting and stricter review. Here's what changes.

read →
~/articles/2026-07-04-metasploit-weekly-smb-meterpreter-peyara-detection
Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara
threat intel

Metasploit's July 3 Drop: SMB-to-Meterpreter, Peyara

Rapid7 shipped an SMB-to-Meterpreter session upgrade and a Peyara Remote Mouse RCE module this week. Neither is novel research. Both change what your alerts will look like. Here's the tune.

read →
~/articles/2026-07-04-polinrider-108-dprk-packages-contagious-interview
PolinRider: DPRK Seeds 108 Malicious Packages
supply chain

PolinRider: DPRK Seeds 108 Malicious Packages

The Hacker News reports 108 malicious npm, Packagist, Go, and Chrome extension listings tied to the DPRK Contagious Interview cluster. Here's what a dev shop actually does about it this week.

read →
~/articles/2026-07-04-toddycat-umbrij-oauth-gmail-kaspersky
Umbrij: ToddyCat Hijacks Gmail OAuth via Browser
cloud

Umbrij: ToddyCat Hijacks Gmail OAuth via Browser

Kaspersky Securelist detailed Umbrij, a ToddyCat post-compromise tool that self-grants Google Workspace OAuth tokens by driving a logged-in Chromium session. Nothing to patch. Plenty to audit.

read →
~/articles/2026-07-04-artoken-eviltokens-m365-device-code-phishing-talos
ARToken PhaaS Targets M365 Device-Code Phishing
cloud

ARToken PhaaS Targets M365 Device-Code Phishing

Cisco Talos exposed ARToken, a React-panel phishing-as-a-service tied to EvilTokens. Device code flow is the mechanic. Conditional Access is the fix, and most tenants still haven't turned it on.

read →
~/articles/2026-07-03-chocopoc-rat-fake-poc-github-pypi-yeswehack
ChocoPoC: Fake CVE PoC Repos Ship a Stealer
supply chain

ChocoPoC: Fake CVE PoC Repos Ship a Stealer

YesWeHack and Sekoia disclosed a stealer campaign hiding inside GitHub PoC repos and PyPI packages, targeting the researchers who clone them. Treat every fresh 'PoC for hot CVE' repo as hostile until you've read every dependency.

read →
~/articles/2026-07-03-bad-epoll-linux-kernel-lpe-cve-2026-46242
Bad Epoll: Linux Kernel LPE Also Hits Android
linux kernel

Bad Epoll: Linux Kernel LPE Also Hits Android

A newly disclosed use-after-free in Linux 6.4+ kernels lets an unprivileged local user gain root. Android on affected kernels is in scope; the upstream fix is in.

read →
~/articles/2026-07-03-pamstealer-macos-maccy-impersonation-jamf
PamStealer: A Fake Maccy Site Steals macOS Creds
threat intel

PamStealer: A Fake Maccy Site Steals macOS Creds

Jamf Threat Labs disclosed a new macOS credential stealer today that impersonates the Maccy clipboard app, validates the victim's login password against PAM in real time, and exfiltrates keychain and browser data. Apple Silicon only. Here's what defenders should do.

read →
~/articles/2026-07-03-cisco-unified-cm-active-exploitation-confirmed
Cisco Confirms Active Exploitation of Unified CM Flaw
cisco

Cisco Confirms Active Exploitation of Unified CM Flaw

Cisco updated its Unified Communications Manager advisory this week to state attackers are exploiting the flaw in the wild. Patched builds have been out for a month. If yours isn't on one, that's the whole conversation.

read →
~/articles/2026-07-03-kemp-loadmaster-cve-2026-8037-pre-auth-rce
Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now
progress

Kemp LoadMaster Pre-Auth RCE: PoC Is Out, Patch Now

A functional proof-of-concept for a critical pre-auth RCE in Progress Kemp LoadMaster hit the internet on June 29 and eSentire started seeing exploitation attempts the same day. Progress's fix has been available since June 4.

read →
~/articles/2026-07-03-sharepoint-cve-2026-45659-kev-active-exploitation
SharePoint RCE now on CISA KEV: patch it this week, not next
microsoft

SharePoint RCE now on CISA KEV: patch it this week, not next

CISA added CVE-2026-45659, a high-severity SharePoint Server deserialization RCE, to the Known Exploited Vulnerabilities catalog on July 2 after confirming active exploitation. Microsoft's May patch is your remediation.

read →