Skip to content
feed: live
>_ 0dayNews
Loop badge

Loop

she/her · Infrastructure — SCADA, ICS, telecom, the physical layer nobody looks at

Loop doesn’t use a legal name in her byline and never has — in the circles she came up in, your handle was your name, full stop. She started exploring the phone network as a teenager because she wanted to understand how it actually worked, not to cause trouble, and that curiosity turned into an actual telecom engineering career by her early twenties.

She’s meticulous about the physical and technical reality under the abstraction — the copper, the protocols, the boxes nobody’s opened since the last decade — because she’s seen firsthand how thin the margin is between “still running” and “the reason everything downstream broke.”

Articles

~/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw
MemGhost: an email that rewrites an AI agent's memory
Analysis
threat intel

MemGhost: an email that rewrites an AI agent's memory

arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

read →
~/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa
Seven years on, CVE-2018-0171 draws a 13-state advisory
ics ot

Seven years on, CVE-2018-0171 draws a 13-state advisory

US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.

read →
~/articles/2026-07-11-mvpnalyzer-281-android-vpn-study-leaks-tracking
281 free Android VPN apps: 29 leak, 246 track
Analysis
mobile

281 free Android VPN apps: 29 leak, 246 track

MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.

read →
~/articles/2026-07-11-ptc-windchill-flexplm-cve-2026-12569-kev-jsp-webshell
PTC Windchill PLM RCE is on KEV — shells still landing
ptc

PTC Windchill PLM RCE is on KEV — shells still landing

PTC Windchill PDMLink and FlexPLM ship an unauth deserialization RCE. CISA added it to KEV on 2026-06-25. Unpatched instances are still catching JSP webshells.

read →
~/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws
Six U-Boot flaws trace to one libfdt helper
ics ot

Six U-Boot flaws trace to one libfdt helper

Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

read →
~/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules
Metasploit Weekly Adds Flowise CSV, macOS PackageKit
threat intel

Metasploit Weekly Adds Flowise CSV, macOS PackageKit

Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

read →
~/articles/2026-07-11-npm-12-allowscripts-off-default-gats-oidc-branch
npm 12 turns install scripts off by default
Analysis
supply chain

npm 12 turns install scripts off by default

npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

read →
~/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure
Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
ics ot

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM

Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

read →
~/articles/2026-07-09-infoblox-lurking-lizard-230-domain-fake-7zip-residential-proxy
Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy
threat intel

Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy

Infoblox ties a China-based residential-proxy operator to 230+ lookalike domains active since 2022, seeding fake 7-Zip and WireVPN installers.

read →
~/articles/2026-07-08-socket-paysafe-skrill-npm-pypi-fake-sdks
Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
supply chain

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI

Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

read →
~/articles/2026-07-08-hallusquatting-npm-ai-hallucinated-packages-tel-aviv
HalluSquatting weaponizes AI-hallucinated npm packages
supply chain

HalluSquatting weaponizes AI-hallucinated npm packages

Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

read →
~/articles/2026-07-08-ubiquiti-unifi-connect-command-injection-cve-2026-50746
Ubiquiti Patches Max-Severity UniFi Connect Command Injection
ubiquiti

Ubiquiti Patches Max-Severity UniFi Connect Command Injection

Ubiquiti Bulletin 066 patches seven critical UniFi flaws, headlined by a CVSS 10.0 command injection in UniFi Connect 3.4.16 and earlier. Fix: 3.4.20 or later.

read →
~/articles/2026-07-07-januscape-cve-2026-53359-kvm-guest-host-escape
Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape
linux kernel

Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape

A 16-year-old use-after-free in KVM's shadow MMU lets a guest VM panic — or, with an unreleased exploit, root — the host on Intel and AMD. Patched June 19.

read →
~/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong
TrojPix: air-gap exfil via video-cable RF emanation
Analysis
ics ot

TrojPix: air-gap exfil via video-cable RF emanation

Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

read →
~/articles/2026-07-05-jfrog-rollup-polyfill-npm-six-packages-follow-up
Four More Rollup Polyfill Typosquats Surface
supply chain

Four More Rollup Polyfill Typosquats Surface

JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

read →
~/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky
Armored Likho Ties BusySnake to Power-Sector Spying
ics ot

Armored Likho Ties BusySnake to Power-Sector Spying

Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

read →
~/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing
ConsentFix + ClickFix: M365 Grants Outlive Resets
cloud

ConsentFix + ClickFix: M365 Grants Outlive Resets

BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

read →
~/articles/2026-07-03-fatfs-runzero-seven-flaws-embedded-firmware
runZero Discloses Seven FatFs Firmware Flaws
supply chain

runZero Discloses Seven FatFs Firmware Flaws

runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

read →
~/articles/2026-07-03-argo-cd-repo-server-unauth-rce-unpatched
Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
cloud

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover

Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.

read →