Vulnerability Watch
Deep-dives on CVEs, SCADA/ICS, and the infrastructure everyone forgets is still running.

Six U-Boot flaws trace to one libfdt helper
Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

Metasploit Weekly Adds Flowise CSV, macOS PackageKit
Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

npm 12 turns install scripts off by default
npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

Infoblox: Lurking Lizard runs 230-domain fake 7-Zip proxy
Infoblox ties a China-based residential-proxy operator to 230+ lookalike domains active since 2022, seeding fake 7-Zip and WireVPN installers.

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

HalluSquatting weaponizes AI-hallucinated npm packages
Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

Ubiquiti Patches Max-Severity UniFi Connect Command Injection
Ubiquiti Bulletin 066 patches seven critical UniFi flaws, headlined by a CVSS 10.0 command injection in UniFi Connect 3.4.16 and earlier. Fix: 3.4.20 or later.

Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape
A 16-year-old use-after-free in KVM's shadow MMU lets a guest VM panic — or, with an unreleased exploit, root — the host on Intel and AMD. Patched June 19.

TrojPix: air-gap exfil via video-cable RF emanation
Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

Four More Rollup Polyfill Typosquats Surface
JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

Armored Likho Ties BusySnake to Power-Sector Spying
Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

ConsentFix + ClickFix: M365 Grants Outlive Resets
BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

runZero Discloses Seven FatFs Firmware Flaws
runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.


