25 results//sorted by published//last sync 2026-10-11 04:05Z
2026-04-16
2026-04-16 23:19Z
MED
WerReportCreate API
Hexacorn·hexacorn.com
Hexacorn documents the WerReportCreate API, a Windows error reporting mechanism used across native OS binaries and libraries. The research catalogs how various system components invoke this API with unique event names for diagnostic purposes, revealing the breadth of Windows error reporting infrastructure.
SRFOsTACTA0007VNDMicrosoftTYPResearchTECT1014
62
Edit Score
2026-04-16
2026-04-16 22:16Z
HIGH
CVE-2026-41113 — sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto
sagredo qmail before 2026.04.07 allows tls_quit remote code execution because of popen in notlshosts_auto in qmail-remote.c.
CVSSv3.1 8.1 (HIGH) · EPSS 26th percentile
CVE-2026-33032 is a critical missing authentication vulnerability (CVSS 9.8) in Nginx UI that allows unauthenticated attackers to access a Model Context Protocol (MCP) server capable of performing privileged operations on managed Nginx instances. The vulnerability is being actively exploited in the wild as part of a two-stage attack chain with CVE-2026-27944 (information leak), affecting versions 2.3.5 and below. Patched in version 2.3.6.
A privilege escalation vulnerability in Microchip IStaX allows an authenticated low-privileged user to recover a shared per-device cookie secret from their own webstax_auth session cookie and forge a new cookie with administrative privileges.This issue affects IStaX before 2026.03.
CVSSv3.1 8.8 (HIGH) · EPSS 10th percentile
CWECWE 331VNDMicrochipTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-16
2026-04-16 18:16Z
CRIT
CVE-2026-27820 — Ruby-lang Zlib: Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability
zlib is a Ruby interface for the zlib compression/decompression library. Versions 3.0.0 and below, 3.1.0, 3.1.1, 3.2.0 and 3.2.1 contain a buffer overflow vulnerability in the Zlib::GzipReader. The zstream_buffer_ungets function prepends caller-provided bytes ahead of previously produced output but fails to guarantee the backing Ruby string has enough capacity before the memmove shifts the existing data. This can lead to memory corruption when the buffer length exceeds capaci
CVSSv3.1 9.8 (CRITICAL) · EPSS 2th percentile
CWECWE 120CWECWE 131VNDRuby LangTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-16
2026-04-16 16:16Z
CRIT
CVE-2026-5426 — Hard: Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026
Hard-coded ASP.NET/IIS machineKey value in Digital Knowledge KnowledgeDeliver deployments prior to February 24, 2026 allows adversaries to circumvent ViewState validation mechanisms and achieve remote code execution via malicious ViewState deserialization attacks
CVSSv3.1 9.1 (CRITICAL) · EPSS 20th percentile
CWECWE 502CWECWE 321VNDHardTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-16
2026-04-16 16:00Z
HIGH
Into The Rainbow: Google’s NTLMv1 Rainbow Tables Explained in a Bit Too Much Detail
SpecterOps·specterops.io
SpecterOps published an in-depth technical breakdown of Google's NTLMv1 rainbow tables (8.8 TB across 4,096 tables covering ~2^59 DES keys) and the three-phase recovery process (precompute, lookup, check) to extract NT hashes from NTLMv1 authentication responses. The work operationalizes the attack against legacy NTLM, particularly targeting systems with Credential Guard enabled via tools like DumpGuard, and includes open-sourced tooling and performance benchmarks (~1 hour per ciphertext on consumer hardware).
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
CVSSv3.1 8.2 (HIGH) · EPSS 68th percentile
CWECWE 288VNDZohocorpTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-04-16
2026-04-16 14:22Z
HIGH
GodPotatoBOF — Cobalt Strike BOF used to perform privilege escalation by exploiting the SeImpersonate privilege. Based on the original
GitHub · LPE exploits·github.comGITHUB POC
GodPotatoBOF is a Cobalt Strike Beacon Object File that ports the GodPotato privilege escalation exploit to CS, enabling attackers to abuse the SeImpersonate privilege to steal SYSTEM tokens and either spawn privileged processes or apply tokens to the current beacon. The tool supports multiple execution modes including direct command execution and token impersonation.
@fastify/middie versions 9.3.1 and earlier do not register inherited middleware directly on child plugin engine instances. When a Fastify application registers authentication middleware in a parent scope and then registers child plugins with @fastify/middie, the child scope does not inherit the parent middleware. This allows unauthenticated requests to reach routes defined in child plugin scopes, bypassing authentication and authorization checks. Upgrade to @fastify/middie 9.
CVSSv3.1 9.1 (CRITICAL) · EPSS 18th percentile
CWECWE 436VNDFastifyTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-04-16
2026-04-16 13:28Z
INFO
v3.4.0.57
Mythic releases·github.com
Mythic v3.4.0.57 released with a Dockerfile tag bump to match the release version. No detailed changelog or feature/fix information is provided in the GitHub release page.
VNDMythicTYPTool
15
Edit Score
2026-04-16
2026-04-16 13:16Z
CRIT
CVE-2026-31843 — Laravel: The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any() without authentication middleware, enabling remote access without credentials. User-controlled input is directly written into executable PHP files using file_put_contents(). These files are later executed via require() during n
CVSSv3.1 9.8 (CRITICAL) · EPSS 78th percentile
CWECWE 284VNDLaravelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-16
2026-04-16 13:00Z
HIGH
Taking Maestro in Stride: AI Threat Modeling Frameworks
Bishop Fox Labs·bishopfox.com
Bishop Fox publishes a threat modeling framework comparison for agentic AI systems, introducing MAESTRO (Multi-Agent Environment, Security, Threat, Risk and Outcome) as a complement to traditional STRIDE modeling. The article demonstrates how AI agents break classical threat modeling assumptions by acting simultaneously as processes, data stores, and actors across trust boundaries, requiring layered architectural analysis across seven dimensions: foundation models, data operations, agent frameworks, deployment infrastructure, observability, security/compliance, and ecosystem interactions.
TACTA0001TACTA0003SRFAiTYPResearchTYPTechnique
72
Edit Score
2026-04-16
2026-04-16 13:00Z
HIGH
ClickFix Phishing Campaign Masquerading as a Claude Installer
Rapid7 Research·rapid7.com
Rapid7 observed a ClickFix phishing campaign impersonating a Claude AI installer, delivering a multi-stage payload chain via fake MSIX bundles. The attack chain progresses from mshta execution through obfuscated VBS/PowerShell stages, culminating in AMSI bypass and process injection with encrypted shellcode. Detection relied on RunMRU registry monitoring and behavioral analysis of suspicious Run utility execution.
From APT28 to RePythonNET: automating .NET malware analysis
Sekoia.io·sekoia.io
Sekoia TDR published RePythonNET-MCP, an open-source tool automating .NET malware analysis via pythonnet and dnlib integration with AI-assisted decompilation. The research demonstrates practical reverse engineering of APT28's obfuscated Covenant C2 implant, including automated string decryption, function renaming, and configuration extraction through an MCP server exposing 30+ analysis tools.
The Career Section plugin for WordPress is vulnerable to Cross-Site Request Forgery leading to Path Traversal and Arbitrary File Deletion in all versions up to, and including, 1.6. This is due to missing nonce validation and insufficient file path validation on the delete action in the 'appform_options_page_html' function. This makes it possible for unauthenticated attackers to delete arbitrary files on the server via a forged request, granted they can trick a site administra
CVSSv3.1 8.8 (HIGH) · EPSS 33th percentile
CWECWE 22VNDCareerTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-16
2026-04-16 06:30Z
HIGH
OID-See — OID-See is an identity attack surface mapping tool that models OAuth trust, persistence, and impersonation paths in Entr
GitHub · Azure / Entra tools·github.comGITHUB POC
OID-See is an open-source identity attack surface mapping tool for Microsoft Entra ID that discovers, analyzes, and visualizes risky third-party and multi-tenant applications through OAuth trust relationships, persistence paths, and impersonation vectors. Version 1.1.1 adds Microsoft's official permission tiering data, BloodHound OpenGraph interoperability, and offline-capable first-party app detection; v1.1.0 introduced large-tenant performance optimization (30k+ nodes) and external identity posture scanning.
CVE-2026-6350 — Openfind: MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers
MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.
CVSSv3.1 9.8 (CRITICAL) · EPSS 23th percentile
CWECWE 121VNDOpenfindTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-16
2026-04-16 03:16Z
CRIT
CVE-2026-6349 — HGiga: The iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local
The
iSherlock developed by HGiga has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 78VNDHgigaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-16
2026-04-16 03:16Z
HIGH
CVE-2026-6348 — WinMatrix: agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local
WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machine as well as on all hosts within the environment where the agent is installed.
CVSSv3.1 8.8 (HIGH) · EPSS 1th percentile
CWECWE 306VNDWinmatrixTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-16
2026-04-16 02:16Z
CRIT
CVE-2026-40504 — Creolabs: Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function
Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string literals at global scope. Attackers can exploit insufficient bounds checking in gravity_fiber_reassign() to corrupt heap metadata and achieve arbitrary code execution in applications that evaluate untrusted scripts.
CVSSv3.1 9.8 (CRITICAL) · EPSS 10th percentile
CWECWE 122VNDCreolabsTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-04-16
2026-04-16 01:16Z
CRIT
CVE-2026-40959 — Luanti: 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via
OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient distinction between local-only and remote-safe commands in the gateway handler. Attackers can execute administrative commands such as /permissions full_auto through remote chat sessions to change permission modes of a running OpenHarness instance without operator authorization.
CVSSv3.1 8.8 (HIGH)
CWECWE 862VNDHkudsVNDOpenharnessTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-16
2026-04-16 00:16Z
HIGH
CVE-2026-5363 — Tp-link Archer_c7_firmware: Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows
Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using RSA-1024 before sending it to the router during login.
An adjacent attacker with the ability to intercept network traffic could potentially perform a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext administrator password, leading to unauth
CVSSv3.1 8.8 (HIGH)
CWECWE 326VNDTp LinkVNDInadequateTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-04-16
2026-04-16 00:00Z
CRIT
QEMU abused to evade detection and enable ransomware delivery
Sophos X-Ops documents active abuse of QEMU by threat actors to deploy hidden virtual machines for defense evasion, credential harvesting, and ransomware delivery. Two campaigns (STAC4713 linked to PayoutsKing/GOLD ENCOUNTER, and STAC3725 exploiting CitrixBleed2) use QEMU VMs to host attack toolkits while remaining invisible to endpoint security controls. Initial access vectors include unpatched SolarWinds Web Help Desk (CVE-2025-26399), exposed VPNs, and Citrix NetScaler exploitation (CVE-2025-5777).