Skip to content
feed: live
>_0dayNews
Nadia "Loop" Park badge

Nadia "Loop" Park

she/her · Infrastructure — SCADA, ICS, telecom, the physical layer nobody looks at

Nadia covers telecom, ICS/OT, embedded systems, and the legacy protocols carrying critical services. Her reporting emphasizes how vulnerabilities behave in real environments shaped by old hardware, limited downtime, and long replacement cycles.

Articles

~/articles/2026-08-17-discourse-cve-2026-55674-csp-bypass
Discourse: Critical CSP Bypass Fixed, Three More CVEs
discourse

Discourse: Critical CSP Bypass Fixed, Three More CVEs

Discourse patched CVSS 9.3 HTML injection bypassing nonce-CSP plus three info-disclosure flaws. Update: 2026.1.6, 2026.5.2, 2026.6.1, or 2026.7.0.

read →
~/articles/2026-08-16-linux-kernel-can-subsystem-race-condition-patch-wave
Linux CAN Subsystem Gets 14-CVE Race Condition Fix Wave
linux kernel

Linux CAN Subsystem Gets 14-CVE Race Condition Fix Wave

The August 15 Linux stable drop patches 14 CVEs in the CAN broadcast manager and ISO 15765-2 transport: data races and use-after-frees.

read →
~/articles/2026-08-15-cisa-icsa-26-225-01-ics-deserialization-cve-2025-7639
CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639
ics ot

CISA ICS Advisory: SCADA Deserialization Bug CVE-2025-7639

CISA advisory ICSA-26-225-01 covers CVE-2025-7639, a deserialization flaw that lets authenticated ICS operators execute code at elevated privilege.

read →
~/articles/2026-08-13-ics-patch-tuesday-siemens-schneider-phoenix-contact
ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact
ics ot

ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact

Siemens, Schneider Electric, and Phoenix Contact issued security bulletins on August 12. CISA published parallel ICS advisories the same day. OT operators should review now.

read →
~/articles/2026-08-11-malicious-sim-code-exec-cellular-iot-modules
Rogue SIM Cards Execute Attacker Code on Industrial Modems
ics ot

Rogue SIM Cards Execute Attacker Code on Industrial Modems

SIM Toolkit commands give rogue SIMs code execution on cellular modules in EV chargers, industrial routers, and car telematics units, University of Birmingham and Fuzzware researchers confirm.

read →
~/articles/2026-08-10-iran-water-plc-attacks-multistate
Iran Suspected in Multistate Water System PLC Attacks
ics ot

Iran Suspected in Multistate Water System PLC Attacks

Internet-exposed PLCs at water utilities across 12+ U.S. states are under active attack, with Iran-linked actors suspected. Default credentials and unencrypted protocols remain the core exposure.

read →
~/articles/2026-08-07-langflow-cve-2026-9198-unauth-rce-public-poc
Public PoC Lands for Langflow's 9.8 Unauth RCE — Patch to 1.10.1 Now
langflow

Public PoC Lands for Langflow's 9.8 Unauth RCE — Patch to 1.10.1 Now

CVE-2026-9198 lets an unauthenticated network caller reach full remote code execution on default Langflow deployments. It's on CISA's KEV list, it's exploited, and a public proof-of-concept is now out.

read →
~/articles/2026-08-02-ntu-84-flaws-4g-5g-core-networks
84 Flaws Found in Open-Source 4G and 5G Cores
ics ot

84 Flaws Found in Open-Source 4G and 5G Cores

Researchers at NTU Singapore found 84 flaws in open-source 4G/5G core software, enabling DoS and session hijacking via GTP-C and PFCP protocol weaknesses.

read →
~/articles/2026-07-31-cisa-water-utilities-plc-attacks
CISA Warns of Rising Attacks on Water System PLCs
ics ot

CISA Warns of Rising Attacks on Water System PLCs

CISA flags a surge in attacks targeting internet-exposed PLCs in U.S. water and wastewater systems. Patch, segment, and remove direct internet exposure.

read →
~/articles/2026-07-29-ot-isolation-field-reality-explainer
Why OT Isolation Is Harder Than the Advisory Says
Explainer
ics ot

Why OT Isolation Is Harder Than the Advisory Says

CISA and ASD's joint OT isolation guidance is correct in what it recommends. What it leaves to inference is the physical-layer reality that makes the recommendation hard to execute.

read →
~/articles/2026-07-27-operation-bluedash-fake-teams-rmm-lure
BlueDash Delivers RMM Agents via Fake Teams Update
threat intel

BlueDash Delivers RMM Agents via Fake Teams Update

ZeroBEC researchers flagged Operation BlueDash, a phishing campaign delivering Level RMM and ScreenConnect via a counterfeit Microsoft Teams update page.

read →
~/articles/2026-07-27-n8n-sandbox-escape-cve-2026-27577-bypass
n8n Sandbox Escape Bypasses February CVE-2026-27577 Patch
n8n

n8n Sandbox Escape Bypasses February CVE-2026-27577 Patch

Security Joes found a new n8n expression-sandbox escape while auditing the February CVE-2026-27577 fix. Update to 2.31.5 or 2.32.1.

read →
~/articles/2026-07-27-steam-forum-clickfix-xmrig-cryptominer
Steam Forums Used to Deliver XMRig via ClickFix
threat intel

Steam Forums Used to Deliver XMRig via ClickFix

Steam game forums are being seeded with fake troubleshooting posts that use ClickFix to deliver XMRig cryptomining malware on unsuspecting players.

read →
~/articles/2026-07-26-hotel-wifi-dns-hijack-m365-credential-theft
Hotel Wi-Fi DNS Hijacked to Serve Fake M365 Pages
microsoft

Hotel Wi-Fi DNS Hijacked to Serve Fake M365 Pages

Attackers are reconfiguring DNS on hotel Wi-Fi devices to redirect guests to fake Microsoft 365 login pages and harvest corporate credentials.

read →
~/articles/2026-07-25-certighost-ad-cs-domain-controller-exploit
Certighost: Working Exploit Reaches AD Domain Controllers
microsoft

Certighost: Working Exploit Reaches AD Domain Controllers

Researchers published a working Certighost exploit: any AD user can obtain a Domain Controller certificate and run DCSync to extract the krbtgt hash. No CVE assigned.

read →
~/articles/2026-07-24-microsoft-365-outage-maintenance-bug-root-cause
M365 Outage: Automation Bug Pulled Too Many IP Routes
microsoft

M365 Outage: Automation Bug Pulled Too Many IP Routes

Microsoft traced the July 23 M365 outage to a bug in its automated maintenance system that removed IP routes from more network devices than intended, taking down Azure and M365.

read →
~/articles/2026-07-24-hotel-wifi-dns-hijack-microsoft-365
Hotel Wi-Fi DNS Hijacked to Steal Microsoft 365 Accounts
threat intel

Hotel Wi-Fi DNS Hijacked to Steal Microsoft 365 Accounts

Attackers modify hotel Wi-Fi gateway DNS to redirect guests to fake Microsoft 365 login pages. ReliaQuest links the campaign to APT28, active since June 2025.

read →
~/articles/2026-07-24-openai-chatgpt-agentforger-phishing-workspace-agents
OpenAI Fixes Bug That Let Phishing Forge Workspace AI Agents
threat intel

OpenAI Fixes Bug That Let Phishing Forge Workspace AI Agents

A phishing link could build and deploy a rogue AI agent inside any ChatGPT Workspace org. OpenAI fixed the AgentForger flaw on June 8, 2026.

read →
~/articles/2026-07-24-nodebb-eight-ai-found-flaws-admin-access
NodeBB Patches Eight AI-Found High-Severity Flaws
cloud

NodeBB Patches Eight AI-Found High-Severity Flaws

Eight high-severity NodeBB flaws expose admin access and private chats in all pre-4.14.0 versions. Aikido Security's AI pentest found them in six hours. Patch to 4.14.2.

read →
~/articles/2026-07-24-microsoft-365-outage-teams-sharepoint-admin-center
M365 Outage Drops Teams, SharePoint, Admin Center
microsoft

M365 Outage Drops Teams, SharePoint, Admin Center

Microsoft 365 outage July 23 took Teams, SharePoint, and the M365 Admin Center offline, stranding security teams without their primary management console.

read →
~/articles/2026-07-23-synthetic-identity-fraud-machine-credentials
Synthetic Identity Fraud Comes for Machine Credentials
Analysis
threat intel

Synthetic Identity Fraud Comes for Machine Credentials

The same technique used to manufacture fake people — assembling real fragments with fabricated filler — is now being applied to machine identities that nobody watches.

read →
~/articles/2026-07-23-fake-claude-sectoprat-bing-malvertising-loop
Fake Claude Installer in Bing Ads Drops SectopRAT
threat intel

Fake Claude Installer in Bing Ads Drops SectopRAT

Active Bing malvertising is serving a fake Claude desktop app installer that delivers SectopRAT. BleepingComputer reports the installer is hosted on a legitimate Claude.ai domain.

read →
~/articles/2026-07-23-fedramp-20x-rev5-transition-continuous-monitoring-loop
FedRAMP 20x Ends Point-in-Time Authorization
cloud

FedRAMP 20x Ends Point-in-Time Authorization

FedRAMP 20x moves federal cloud authorization from periodic 3PAO assessments to continuous, machine-readable control evidence — what that shift requires from cloud operators.

read →
~/articles/2026-07-23-eclypsium-infratrust-pulse-firmware-patch-priority
Eclypsium Launches InfraTrust for Firmware Patch Priority
threat intel

Eclypsium Launches InfraTrust for Firmware Patch Priority

Eclypsium's new InfraTrust knowledge base and monthly Pulse report gives network teams a prioritized view of firmware and edge-device vulnerabilities.

read →
~/articles/2026-07-22-google-deepmind-gemini-35-flash-cyber-codemender-loop
Google Gemini 3.5 Flash Cyber Targets Vuln Discovery
google

Google Gemini 3.5 Flash Cyber Targets Vuln Discovery

Google DeepMind's Gemini 3.5 Flash Cyber is a fine-tuned model for vulnerability discovery, validation, and patching, restricted to governments via CodeMender.

read →
~/articles/2026-07-22-lg-webos-residential-proxy-sdk-ban-spur-brightdata-42-percent
LG bans residential-proxy SDKs from webOS TV apps
threat intel

LG bans residential-proxy SDKs from webOS TV apps

LG will suspend webOS apps that ship residential-proxy SDKs, a month after Spur documented such SDKs in 42% of LG apps and 25% of Samsung Tizen apps.

read →
~/articles/2026-07-20-ostium-arbitrum-off-chain-oracle-forgery-23-75m-lp-vault-drain
Ostium's LP vault down $23.75M after oracle-feed forgery
threat intel

Ostium's LP vault down $23.75M after oracle-feed forgery

Attackers compromised off-chain price signing for Ostium's Arbitrum perpetuals DEX, submitted forged price attestations, and drained $23.75M from the LP vault.

read →
~/articles/2026-07-20-pillar-week-sandbox-escapes-cursor-codex-gemini-cli-antigravity
Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes
threat intel

Cursor, Codex, Gemini CLI, Antigravity: sandbox escapes

Pillar Security walks the same file out of the sandbox in four AI coding agents — each time by getting a trusted host tool to run what the agent wrote.

read →
~/articles/2026-07-20-group-ib-hollowgraph-m365-calendar-events-2050-c2-dead-drop
HollowGraph hides M365 C2 in calendar events dated 2050
threat intel

HollowGraph hides M365 C2 in calendar events dated 2050

Group-IB's HollowGraph hides M365 command-and-control in calendar events dated 2050-05-13, moving tasking and stolen files through legitimate Graph API traffic.

read →
~/articles/2026-07-20-aivd-mivd-russian-intel-ip-cameras-nato-military-transport-ukraine
AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes
ics ot

AIVD/MIVD: Russia hijacks IP cameras on NATO convoy routes

AIVD and MIVD say Russian intel is hijacking exposed IP cameras across EU, NATO states, and Ukraine to watch military convoys and weapons shipments to Kyiv.

read →
~/articles/2026-07-20-wsus-sync-fix-new-installs-only-old-servers-metadata-cleanup
WSUS sync fix only for new installs, old servers still stuck
microsoft

WSUS sync fix only for new installs, old servers still stuck

WSUS servers on Windows Server 2012+ have failed to sync since roughly July 13. Microsoft's July 18 mitigation restores fresh installs; older ones wait on a metadata cleanup step.

read →
~/articles/2026-07-20-microsoft-kb5121767-oob-dell-intel-ipf-driver-hold-fix
Microsoft ships KB5121767 OOB for Dell IPF driver hold
microsoft

Microsoft ships KB5121767 OOB for Dell IPF driver hold

Microsoft shipped KB5121767 on 2026-07-20 to patch the Intel IPF driver incompatibility stranding a subset of Dell PCs off July's Windows 11 security update.

read →
~/articles/2026-07-20-stepsecurity-sleepergem-rubygems-dormant-accounts-forgejo-loader
SleeperGem loader hides in dormant RubyGems, skips CI/CD
supply chain

SleeperGem loader hides in dormant RubyGems, skips CI/CD

StepSecurity: three RubyGems, two dormant since 2018-2020, ship a Forgejo-hosted loader that fingerprints CI runners and skips them before dropping a daemon.

read →
~/articles/2026-07-18-microsoft-acr-stealer-april-june-webdav-etherhiding
Microsoft ties ACR Stealer surge to WebDAV, blockchain C2
threat intel

Microsoft ties ACR Stealer surge to WebDAV, blockchain C2

Microsoft's July 16 writeup links a late-April through mid-June ACR Stealer surge to WebDAV-hosted payloads and a blockchain dead-drop for C2 updates.

read →
~/articles/2026-07-18-checkmarx-vitevenom-chainveil-seven-npm-tron-blockchain-c2
Seven Vite-adjacent npm packages route a RAT through Tron
supply chain

Seven Vite-adjacent npm packages route a RAT through Tron

Checkmarx flagged a fresh cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem. Codenamed ViteVenom, they route through a four-tier blockchain C2 including Tron to drop a RAT.

read →
~/articles/2026-07-16-microsoft-windows-11-24h2-home-pro-eos-october-13-25h2-enablement
Windows 11 24H2 Home and Pro: 90 days to end of updates
microsoft

Windows 11 24H2 Home and Pro: 90 days to end of updates

Microsoft has set October 13, 2026 as the last patch day for Windows 11 24H2 Home and Pro. Enterprise and Education get one more year — the usual split.

read →
~/articles/2026-07-16-anyrun-phantomenigma-brazil-gov-br-hijack-dmarc-inno-node
PhantomEnigma rides Brazilian .gov.br sites and mailboxes
threat intel

PhantomEnigma rides Brazilian .gov.br sites and mailboxes

ANY.RUN links a Brazilian banking crimeware operation to 20+ hijacked .gov.br sites and mailboxes, using signature-valid mail and trusted redirects.

read →
~/articles/2026-07-16-daxin-srt64-stupig-winlogon-taiwan-digiwin-jdk
Daxin resurfaces in Taiwan alongside new Stupig backdoor
threat intel

Daxin resurfaces in Taiwan alongside new Stupig backdoor

Symantec finds the Daxin kernel rootkit resurfacing at a Taiwan manufacturer, alongside a previously unreported pre-login SYSTEM backdoor called Stupig.

read →
~/articles/2026-07-16-mindgard-cursor-workspace-git-hijack-windows-no-patch
Cursor: opening a repo runs its git.exe. No patch, 7 months.
supply chain

Cursor: opening a repo runs its git.exe. No patch, 7 months.

Mindgard disclosed a Cursor zero-day July 14 after seven months without a fix. Opening a repo with a git.exe file runs it as you. Windows only. No patch.

read →
~/articles/2026-07-16-microsoft-kb5099539-windows-10-esu-july-22h2-ltsc-2021
KB5099539 lands: Windows 10 ESU carries the July zero-days
microsoft

KB5099539 lands: Windows 10 ESU carries the July zero-days

Microsoft's KB5099539 delivers July's Patch Tuesday to Windows 10 22H2 and LTSC 2021 fleets, including two exploited zero-days. Enrollment required.

read →
~/articles/2026-07-15-trend-micro-bandcampro-gemini-cli-c2-botnet-operator
Trend Micro: bandcampro ran a C2 botnet on Gemini CLI
threat intel

Trend Micro: bandcampro ran a C2 botnet on Gemini CLI

Trend Micro logs 200+ Gemini CLI sessions from a Russian-speaking actor tracked as bandcampro: C2 migration, credential work, and daily botnet ops.

read →
~/articles/2026-07-15-knx-cve-2023-4346-cisa-kev-account-lockout-bod-26-04
KNX account-lockout flaw added to CISA KEV, three years on
ics ot

KNX account-lockout flaw added to CISA KEV, three years on

CVE-2023-4346 turns the KNX Association's account-lockout mechanism into a device-purge weapon on a building-automation bus. CISA added it to KEV under BOD 26-04.

read →
~/articles/2026-07-15-zyxel-cve-2023-28771-epss-099-three-years-post-patch
Zyxel CVE-2023-28771: EPSS 0.99 three years after the patch
Analysis
zyxel

Zyxel CVE-2023-28771: EPSS 0.99 three years after the patch

Zyxel's 2023 firewall command-injection bug still ranks EPSS 0.99 three years post-patch. Scans stay constant; unpatched SMB perimeter boxes remain plentiful.

read →
~/articles/2026-07-15-mindgard-cursor-git-exe-workspace-root-no-patch
Mindgard: Cursor still runs git.exe from repo root
threat intel

Mindgard: Cursor still runs git.exe from repo root

Aaron Portnoy's Mindgard team went public today: Cursor 3.11 on Windows executes any git.exe sitting in a cloned repo's root — seven months, no patch.

read →
~/articles/2026-07-15-spain-140m-bec-fraud-ring-800-accounts-67-mules
Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules
threat intel

Spain Dismantles €140M BEC Ring; 800 Accounts, 67 Mules

Spanish National Police dismantle a €140M BEC and investment fraud network using 800 bank accounts, 120 companies, and 67 mules; four arrested across three countries.

read →
~/articles/2026-07-14-ku-leuven-distrinet-85-crypto-wallet-extensions-address-linking
KU Leuven: 85 wallet extensions leak addresses cross-site
browser

KU Leuven: 85 wallet extensions leak addresses cross-site

KU Leuven's DistriNet tested 85 Chrome crypto wallet extensions with ~35M installs. 17 link separate addresses in a single request. 22 of 36 ignore site disconnects.

read →
~/articles/2026-07-14-eset-uefi-shim-cve-2026-8863-secure-boot-bypass
ESET: 11 old signed UEFI shims still bypass Secure Boot
microsoft

ESET: 11 old signed UEFI shims still bypass Secure Boot

ESET's Martin Smolár found 11 old Microsoft-signed UEFI shims that still bypass Secure Boot — CVE-2026-8863, revoked via the June DBX update.

read →
~/articles/2026-07-14-jfrog-148-npm-packages-browser-ddos-botnet-may
148 npm packages ran a browser-based DDoS botnet in May
supply chain

148 npm packages ran a browser-based DDoS botnet in May

JFrog: 148 npm packages hosted a fake student web proxy that turned visiting browsers into a DDoS botnet for about two weeks in May. Not a supply-chain attack.

read →
~/articles/2026-07-14-jscrambler-npm-post-mortem-four-versions-8-22-clean
Jscrambler: four npm versions hit, publish creds revoked
supply chain

Jscrambler: four npm versions hit, publish creds revoked

Jscrambler's post-incident report widens its July 11 npm compromise from one release to four (8.14, 8.16, 8.17, 8.20). 8.22 clean; publish creds revoked.

read →
~/articles/2026-07-13-nca-russian-coms-five-charged-1-8m-spoofed-calls
NCA charges five over Russian Coms spoofing platform
threat intel

NCA charges five over Russian Coms spoofing platform

The NCA charged five London residents over Russian Coms — a caller-ID spoofing platform behind 1.8M scam calls and 170,000 victims. Westminster court date Aug 14.

read →
~/articles/2026-07-13-memghost-arxiv-persistent-memory-poison-openclaw
MemGhost: an email that rewrites an AI agent's memory
Analysis
threat intel

MemGhost: an email that rewrites an AI agent's memory

arXiv paper: one crafted email talks a memory-enabled AI agent into writing attacker-supplied 'facts' into its memory files. Future sessions load them.

read →
~/articles/2026-07-13-fsb-centre-16-cve-2018-0171-router-hygiene-csa
Seven years on, CVE-2018-0171 draws a 13-state advisory
ics ot

Seven years on, CVE-2018-0171 draws a 13-state advisory

US, UK, and eleven allied governments co-signed a July 13 advisory naming FSB Centre 16 as the actor still pulling configs off end-of-life Cisco routers via CVE-2018-0171.

read →
~/articles/2026-07-11-mvpnalyzer-281-android-vpn-study-leaks-tracking
281 free Android VPN apps: 29 leak, 246 track
Analysis
mobile

281 free Android VPN apps: 29 leak, 246 track

MVPNalyzer, a University of Michigan / UNM / IIT Delhi tool presented at NDSS 2026, ran 281 top free Android VPN apps and found leaks, plaintext, and trackers.

read →
~/articles/2026-07-11-ptc-windchill-flexplm-cve-2026-12569-kev-jsp-webshell
PTC Windchill PLM RCE is on KEV — shells still landing
ptc

PTC Windchill PLM RCE is on KEV — shells still landing

PTC Windchill PDMLink and FlexPLM ship an unauth deserialization RCE. CISA added it to KEV on 2026-06-25. Unpatched instances are still catching JSP webshells.

read →
~/articles/2026-07-11-u-boot-libfdt-fit-parsing-six-brly-flaws
Six U-Boot flaws trace to one libfdt helper
ics ot

Six U-Boot flaws trace to one libfdt helper

Binarly disclosed six bugs in U-Boot's FIT-image parsing on July 9 — two potential RCE, four DoS — all tracing to unchecked libfdt calls present since 2013.07.

read →
~/articles/2026-07-11-metasploit-weekly-flowise-csv-packagekit-modules
Metasploit Weekly Adds Flowise CSV, macOS PackageKit
threat intel

Metasploit Weekly Adds Flowise CSV, macOS PackageKit

Rapid7's Metasploit weekly drops two modules — a Flowise CSV Agent prompt-injection RCE and a macOS PackageKit LPE. New tooling, not new bugs.

read →
~/articles/2026-07-11-npm-12-allowscripts-off-default-gats-oidc-branch
npm 12 turns install scripts off by default
Analysis
supply chain

npm 12 turns install scripts off by default

npm 12 defaults allowScripts to off and deprecates 2FA-bypass tokens. Closes the install-hook branch; does not touch the maintainer-account one.

read →
~/articles/2026-07-09-talos-vdr-wolfssl-geovision-vtk-dicom-disclosure
Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM
ics ot

Talos discloses 18 vulns in WolfSSL, GeoVision, VTK-DICOM

Cisco Talos published a bulk third-party disclosure covering 3 WolfSSL, 14 GeoVision, and 1 VTK-DICOM vulnerabilities — all patched before publication.

read →
~/articles/2026-07-08-socket-paysafe-skrill-npm-pypi-fake-sdks
Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI
supply chain

Socket: 17 fake Paysafe, Skrill, Neteller SDKs on npm and PyPI

Socket disclosed 17 malicious packages posing as Paysafe, Skrill, and Neteller SDKs across npm and PyPI. Payload steals payment API keys, AWS keys, and GitHub/npm tokens.

read →
~/articles/2026-07-08-hallusquatting-npm-ai-hallucinated-packages-tel-aviv
HalluSquatting weaponizes AI-hallucinated npm packages
supply chain

HalluSquatting weaponizes AI-hallucinated npm packages

Tel Aviv researchers register the fake package names AI coding assistants keep inventing. Up to 100% hit rate on skill installs, no confirmed exploitation yet.

read →
~/articles/2026-07-08-ubiquiti-unifi-connect-command-injection-cve-2026-50746
Ubiquiti Patches Max-Severity UniFi Connect Command Injection
ubiquiti

Ubiquiti Patches Max-Severity UniFi Connect Command Injection

Ubiquiti Bulletin 066 patches seven critical UniFi flaws, headlined by a CVSS 10.0 command injection in UniFi Connect 3.4.16 and earlier. Fix: 3.4.20 or later.

read →
~/articles/2026-07-07-januscape-cve-2026-53359-kvm-guest-host-escape
Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape
linux kernel

Januscape (CVE-2026-53359): 16-year KVM guest-to-host escape

A 16-year-old use-after-free in KVM's shadow MMU lets a guest VM panic — or, with an unreleased exploit, root — the host on Intel and AMD. Patched June 19.

read →
~/articles/2026-07-06-trojpix-air-gap-video-cable-emanation-shandong
TrojPix: air-gap exfil via video-cable RF emanation
Analysis
ics ot

TrojPix: air-gap exfil via video-cable RF emanation

Shandong University researchers show a covert-channel technique that turns invisible pixel changes into a radio signal a nearby receiver can decode from the display cable itself.

read →
~/articles/2026-07-05-jfrog-rollup-polyfill-npm-six-packages-follow-up
Four More Rollup Polyfill Typosquats Surface
supply chain

Four More Rollup Polyfill Typosquats Surface

JFrog's disclosure names six npm packages in the Rollup polyfill typosquat cluster, not two. The extra four sit inside the same infrastructure the earlier reporting described, and the audit surface hasn't moved.

read →
~/articles/2026-07-04-armored-likho-busysnake-power-sector-kaspersky
Armored Likho Ties BusySnake to Power-Sector Spying
ics ot

Armored Likho Ties BusySnake to Power-Sector Spying

Kaspersky attributes a previously undocumented threat actor, Armored Likho, to a campaign hitting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan using the BusySnake stealer.

read →
~/articles/2026-07-04-consentfix-clickfix-m365-oauth-consent-phishing
ConsentFix + ClickFix: M365 Grants Outlive Resets
cloud

ConsentFix + ClickFix: M365 Grants Outlive Resets

BleepingComputer covered two M365 hijack patterns and Opera's Paste Protect defense this week. The clipboard lane can be closed. The OAuth grant substrate underneath is unchanged.

read →
~/articles/2026-07-03-fatfs-runzero-seven-flaws-embedded-firmware
runZero Discloses Seven FatFs Firmware Flaws
supply chain

runZero Discloses Seven FatFs Firmware Flaws

runZero disclosed seven vulnerabilities in FatFs, a small filesystem library shipped inside ESP-IDF, STM32Cube, Zephyr, MicroPython, and other embedded stacks. Only one has an upstream fix.

read →
~/articles/2026-07-03-argo-cd-repo-server-unauth-rce-unpatched
Unpatched Argo CD Flaw Lets Unauth Cluster Takeover
cloud

Unpatched Argo CD Flaw Lets Unauth Cluster Takeover

Synacktiv disclosed an unpatched code-execution flaw in Argo CD's repo-server component. No fix, no CVE. Reachability of the internal port is the whole game.

read →