thecybersecguru
thecybersecguru@infosec.exchange
Posts
-
View post
@replytomaikel@mastodon.social I'm trying to force myself to sleep early. Waiting for the Galaxy Watch Ultra 2 to arrive to motivate me even more for exercising and proper sleep cycle maintenance
-
View post
🚨 Citrix NetScaler emergency shutdowns Organizations are reportedly being advised to take Citrix NetScaler appliances offline amid warnings about two undisclosed zero-day vulnerabilities. No public CVEs. No patch yet. Limited IOCs. The reported issues potentially affect internet-facing NetScaler ADC and Gateway deployments, putting a critical piece of enterprise edge infrastructure under immediate scrutiny. Security teams are reportedly preparing for emergency mitigation ahead of Citrix'...
-
View post
🚨 OnePlus 15: Zero-Permission Root Exploit Security research has uncovered an exploit chain affecting the OnePlus 15 that can take an untrusted Android app to root (UID 0) without requiring any special permissions. The chain abuses vulnerable OxygenOS components, including AtlasService and the olc2 vendor HAL, allowing an installed app to bypass Android’s normal permission boundaries. Key points: • Zero Android permissions required • Tested on a stock OnePlus 15 • OxygenOS 16 affected • Loca...
-
View post
Prompt injection is becoming one of the biggest security challenges for LLMs and AI agents. Attackers can hide malicious instructions in prompts, webpages, emails, PDFs, images, and other content an AI system processes. 🔐 Direct injection 📄 Indirect injection 🖼️ Multimodal attacks 🤖 AI agent risks 🛡️ Defense strategies I broke down the major types, attack scenarios, and practical mitigation techniques: https://thecybersecguru.com/glossary/prompt-injection-attacks-types-examples-prevention/ #i...
-
View post
🚨 **CVE-2026-80521: Linux kernel container escape** A public exploit chains an **AF_UNIX socket garbage-collector use-after-free** into host-level code execution from an unprivileged container. The bug involves a race in the SCC garbage collector that leaves a freed `unix_vertex` reachable through a stale `scc_entry` pointer. The PoC reportedly works against Ubuntu 26.04 and defeats several kernel hardening mechanisms. Ubuntu 22.04, 24.04 and 26.04 are currently listed as affected in the art...
-
View post
🚨 T-MOBILE HACKED?** An alleged 2026 T-Mobile customer database has surfaced on an underground forum. But the sample raises serious red flags: it reportedly contains **Verizon Wireless records** and fields that look more like a broad consumer-data compilation than a genuine T-Mobile subscriber database. No confirmed record count. No proof of intrusion. No independent confirmation. No T-Mobile disclosure matching the claim. So what is it: a fresh breach, recycled data, broker-sourced informat...
-
View post
🚨 Swiss Bitcoin Pay has CONFIRMED a security breach. A malicious user gained access to its internal systems, with customer emails, Bitcoin addresses, IBANs, transaction history and hashed passwords potentially exposed. Swiss Bitcoin Pay has shut down its servers while investigating. It says user funds are safe and owed funds will be returned. But the bigger security question is the “non-custodial” claim. The company says incoming Lightning payments are temporarily batched into on-chain UTXOs,...
-
View post
🚨 TELUS data breach: attackers reportedly accessed consumer accounts for 16 months using compromised credentials. The intrusion reportedly lasted from February 2025 to June 2026, exposing names, account numbers, billing addresses, phone numbers, email addresses, payment-card last four digits, service details and payment history. The unusual part? The stolen account information was allegedly used to contact customers and persuade them to switch their services to competitors. Some customers also...
-
View post
🚨 Ledger data breach claim A cybercrime forum seller is allegedly offering 471,000 Ledger customer records for $20,000. The claimed dataset includes: • Email addresses • Names • Physical addresses • Phone numbers ⚠️ The data has not been independently verified and may potentially include recycled data from the 2020 Ledger breach. We break down the listing, what may actually be at risk, and what Ledger users should know: https://thecybersecguru.com/news/ledger-data-breach-2026-471000-customer...
-
View post
🚨 Cisco ISE CVE-2026-76460 is being actively exploited. A CVSS 10.0 authentication bypass lets unauthenticated remote attackers send a crafted API request and gain unauthorized access to Cisco ISE/ISE-PIC. Cisco warns successful exploitation can lead to root-level command execution, while attackers may be able to erase evidence of compromise. 🔎 Hunt ISE Kong access logs for suspicious usernames. ⚠️ No workaround is available. 🛠️ Patch releases are available. Technical breakdown, IOCs, affected...
-
View post
Mistral AI source code allegedly offered for sale on a cybercrime forum. A threat actor using the handle “mrwho” claims to have compromised Mistral AI and obtained source code, internal development projects and web application code. The samples reportedly include a 339-file project listing and “webstral” code. The claims remain unverified, and no customer data exposure has been established. Technical breakdown: https://thecybersecguru.com/news/mistral-ai-source-code-leak-2026/
-
View post
Apple’s privacy model deserves a closer look. A review of Apple’s privacy disclosures raises questions around: • First-party behavioral profiling and targeted advertising • The data signals used for Device Trust Scores • Long-term retention of transaction and download data • iCloud sharing metadata exposure • The practical limits of account deletion • Differences between Apple’s privacy messaging and its underlying data-processing practices Apple has made significant investments in security a...
-
View post
Cisco FMC CVE-2026-20324 is a critical sftunnel vulnerability with a CVSS score of 9.9. The flaw involves missing authorization (CWE-862) and can allow an attacker controlling or hijacking a registered sftunnel peer to write arbitrary files and execute commands as root on Secure Firewall Management Center. The important part: this isn't a typical unauthenticated internet-facing RCE. Exploitation requires valid peer context, but compromise of FMC could have significant downstream impact...
-
View post
🚨 Critical Tutor LMS vulnerability: CVE-2026-78175 A critical vulnerability in Tutor LMS can chain broken access control → PHP object injection → arbitrary file write → remote code execution. Affected: Tutor LMS ≤ 4.0.7 Severity: CVSS 8.8 Potential impact: 100,000+ WordPress sites Fixed: Tutor LMS 4.0.8 The issue is particularly concerning because a low-privileged subscriber account can reach the vulnerable withdrawal-account functionality. Administrators should update to 4.0.8 or later and...
-
View post
🚨 Gyazo breach: 23.62M accounts affected, with metadata tied to 490M+ images reportedly exposed. The exposed data reportedly includes: • Email addresses & usernames • Password hashes • Session IDs • Device IDs • X integration tokens • OCR text • IP addresses & EXIF data • Gyazo image IDs The OCR + image-ID exposure is particularly concerning for screenshots containing credentials, API keys, internal infrastructure details, or sensitive corporate information. Full technical bre...
-
View post
🚨 Brevo supply-chain attack: 100,000+ WordPress sites potentially exposed. Attackers reportedly abused a stolen, long-lived Cloudflare API key to modify Brevo’s edge infrastructure and inject malicious JavaScript. The payload could: • Target logged-in WordPress admins via CSRF/session riding • Upload and activate a malicious plugin • Install a persistent PHP backdoor • Show ClickFix overlays to ordinary visitors • Deliver infostealers such as Lumma/Vidar The attack window: Sept. 14, 2026, 16:...
-
View post
🚨 Google Gemini just escaped its sandbox and hacked 3 REAL companies. During an AI security test, Gemini got unintended internet access, found/guessed credentials, and gained access to real systems. It only stopped after realizing the targets were real. The scary part isn't that Gemini stopped. It's that the sandbox let it get there in the first place. Full breakdown: https://thecybersecguru.com/news/google-gemini-hacked-three-companies/
-
View post
A legacy CDN domain has been re-registered and now has wildcard DNS covering `*.wpengine.netdna-ssl.com`. `netdna-ssl.com` was part of the old MaxCDN/WP Engine infrastructure, and thousands of legacy references still exist. The current TLS configuration prevents the deeper hostnames from serving content, but a valid wildcard certificate could turn this into a serious supply-chain risk. Full analysis: https://thecybersecguru.com/news/netdna-ssl-com-takeover-supply-chain-risk/
-
View post
🚨 Click2Shell: Critical WordPress RCE chain A malicious link can trigger an authenticated WordPress admin’s browser to silently install a theme, load its functions.php, abuse an insecure AJAX handler, and reach remote code execution. The Core flaw is patched in WordPress 7.1.1, but vulnerable third-party themes can still complete the chain. Full technical breakdown + PoC analysis: https://thecybersecguru.com/news/click2shell-wordpress-vulnerability-rce/ #InfoSec #WordPress #CyberSecurity #RC...
-
View post
🚨 Chat Control 2.0 hits another major EU trilogue on September 29. The debate is centered on some serious infosec questions: 🔐 End-to-end encryption 📱 Private message scanning ⚖️ Detection orders 🪪 Mandatory age verification 🇪🇺 Chat Control 1.0 vs 2.0 The Council, Parliament and Commission still have fundamentally different positions. Here’s the technical breakdown of what’s actually being negotiated 👇 https://thecybersecguru.com/news/chat-control-2-0-september-29-trilogue/
-
View post
Linux kernel security had a rough week. 4 kernel flaws now have public root exploits, while CISA added 3 more Linux kernel vulnerabilities to its KEV catalog due to active exploitation. The four publicly exploited flaws: • DirtyAH6 • TUNderflow • PPPoEject • DiagSpill The interesting part: the four bugs were discovered using an AI-assisted vulnerability hunting approach. Technical breakdown, affected versions, exploitation requirements, and mitigations: https://thecybersecguru.com/news/linux...
-
View post
AI-assisted TikTok exploit reportedly demonstrated a zero-click RCE chain capable of reaching a device’s camera, microphone and photos. DepthFirst Labs’ autonomous agent found and chained the vulnerabilities, raising a bigger question for defenders: what happens when exploit development becomes automated? Full breakdown: https://thecybersecguru.com/news/tiktok-ai-hack-depthfirst-labs-zero-click-rce/
-
View post
🚨 OpenAI breached through an image upload? Hacktron’s “HEIF Heist” campaign reportedly chained a HEIC/HEIF parser vulnerability to RCE, then used compromised authentication to reach internal OpenAI infrastructure. The wild part: Claude reportedly helped discover the memory corruption bug and develop the exploit. The attack chain: HEIC → libheif → RCE → SSO tokens → internal access OpenAI, Slack, GitHub Enterprise & Meta were reportedly affected. Technical breakdown 👇 https://thecyberse...
-
View post
🚨 Docker Sandboxes escape vulnerabilities Two flaws could allow malicious code running inside a Docker Sandbox to break out of the microVM isolation and reach the underlying host: • CVE-2026-77179 | CVSS 9.4 Critical | virtio-fs symlink escape • CVE-2026-79994 | CVSS 8.7 High | Unix socket relay TOCTOU The risk is especially interesting for AI coding agents that can autonomously execute code and interact with untrusted repositories. Docker addressed the flaws in Sandbox 0.42.0. Technical br...
-
View post
🚨 Dropbox Hack / Data Breach: Lenovo ID Flaw Enabled Account Takeover A serious Dropbox security incident highlights a dangerous weakness in federated identity. Attackers allegedly registered Lenovo IDs using victims’ email addresses, then abused Dropbox SSO / OIDC federation** to authenticate against existing Dropbox accounts. The disturbing part: • No Dropbox password was required • Victims didn't necessarily have a Lenovo ID • The attack relied on email-based account matching • A rogu...
-
View post
🔥 VMware vCenter → ESXi → Ransomware A suspected China-nexus actor reportedly weaponized CVE-2026-59310 just 5 days after disclosure. The campaign hit an estimated 361 IPs across 47 countries and ultimately deployed Babuk-derived ransomware against ESXi hosts. The interesting part is the attack chain: vCenter compromise → root access → persistence → credential theft → ESXi lateral movement → VMFS encryption I broke down the full chain, including the attacker’s persistence and ESXi ransomwar...
-
View post
GitHub experiencing widespread outage, API errors reach ~20% GitHub is currently experiencing a widespread service disruption affecting multiple core services. GitHub reports approximately 20% error rates across web experiences and API traffic, while archive downloads and raw repository content are seeing around 50% errors**. Affected services include: * GitHub API * GitHub Actions * Pull Requests * Issues * Webhooks * GitHub Copilot * SAML/OIDC authentication * SCIM and Team Sync * Reposito...
-
View post
🚨 Critical GitLab GraphQL vulnerability: CVE-2026-19478 GitLab has released an out-of-band security patch for a CVSS 9.4 critical vulnerability affecting self-managed CE/EE installations. Under certain conditions, an unauthenticated remote attacker could use a malicious GraphQL directive to modify or delete public projects and user data. Affected branches include: • 18.2 → before 18.11.11 • 19.0 → before 19.0.8 • 19.1 → before 19.1.6 • 19.2 → before 19.2.4 GitLab also fixed CVE-2026-19650 (...
-
View post
🚨 Critical WordPress vulnerabilities! CVE-2026-15748 affects Forminator Forms and can allow unauthenticated arbitrary file uploads leading to RCE on vulnerable configurations. Versions ≤ 1.56.1 are affected; 1.56.2 is patched. CVE-2026-15826 affects User Profile Builder and enables unauthenticated authentication bypass via type confusion, potentially resulting in administrator takeover. Versions ≤ 3.16.4 are affected. Both carry CVSS 9.8 Critical. I've broken down the exploit chains,...
-
View post
🚨 GTA VI LEAK: Cyberleek vs. Rockstar A group calling itself Cyberleek has published alleged GTA VI gameplay footage and an extensive **Leonida map**, reportedly revealing details including: • Possible 6-star wanted system • New stamina/combat mechanics • Vehicle storage & fuel systems • Previously unseen locations across the map But the more interesting (or not so much) part is the response. Rockstar/Take-Two are reportedly issuing DMCA takedowns at near-real-time speed, with gamepl...