Skip to content

Commit e8adba1

Browse files
committed
crows-nest-2026-05-11 (98 items)
1 parent d2e3379 commit e8adba1

1 file changed

Lines changed: 71 additions & 5 deletions

File tree

content/posts/crows-nest-2026-05-11.md

Lines changed: 71 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@ draft: false
55
tags: ["roundup"]
66
---
77

8-
A roundup of 54 items curated from across the security community.
8+
A roundup of 98 items curated from across the security community.
99

1010
## News
1111

@@ -24,6 +24,9 @@ A roundup of 54 items curated from across the security community.
2424
- [Solana router: two critical bugs drain token accounts](https://atlas-it.consulting/post/solana-router-vuln) by [Sam Curry](https://x.com/samwcyo/status/2049596235355689464).
2525
> Two critical bugs in a popular Solana router let an attacker drain every token account it owns. Full writeup at atlas-it.consulting.
2626
27+
- [Bleeding Llama: unauthenticated memory leak in Ollama (CVE-2026-7482)](https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama).
28+
> Cyera Research uncovers a critical pre-auth memory disclosure in Ollama. Self-hosted LLM gateways leak adjacent buffer contents to anyone who can hit the API.
29+
2730
- [The WebPKI cert renewal apocalypse](https://cabforum.org/2025/04/11/ballot-sc081v3-introduce-schedule-of-reducing-validity-and-data-reuse-periods).
2831
> Dark Tangent on the CA/B Forum schedule that takes TLS cert validity from 350 days down to 47, plus the deprecation of DANE that left the gap in the first place.
2932
@@ -32,11 +35,13 @@ A roundup of 54 items curated from across the security community.
3235
3336

3437
<details markdown="1">
35-
<summary>More this week (11)</summary>
38+
<summary>More this week (13)</summary>
3639

3740
- [Trenchant exec ordered to pay $10M for selling zero-days to Russia](https://www.zetter-zeroday.com/trenchant-exec-who-sold-zero-days-to-russian-buyer-ordered-to-pay-10-million-in-restitution-to-former-employers).
3841
- [CVE-2026-42511: 21-year-old FreeBSD RCE](https://aisle.com/blog/aisle-discovers-cve-2026-42511-a-21-year-old-freebsd-remote-command-execution-vulnerability).
3942
- [MOVEit Automation: critical auth bypass and priv-esc CVEs](https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174) by [Vincent Yiu](https://x.com/vysecurity/status/2051009329655066894).
43+
- [RansomHouse claims Trellix source-code breach](https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers) by [BleepingComputer](https://x.com/BleepinComputer/status/2052763427966202314).
44+
- [Zara data breach exposed 197,000 people](https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-infor) by [BleepingComputer](https://x.com/BleepinComputer/status/2052700692716892489).
4045
- [Ivanti EPMM zero-day exploited in the wild](https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-) by [BleepingComputer](https://x.com/BleepinComputer/status/2052408380669452372).
4146
- [US military data left exposed despite CISA notification](https://www.scworld.com/brief/us-military-data-exposed-in-leaky-directory-despit) by [Nicolas Krassas](https://x.com/Dinosn/status/2052844685668835807).
4247
- [TCLBANKER trojan spreads via WhatsApp and Outlook](https://thehackernews.com/2026/05/tclbanker-banking-trojan-targets) by [Nicolas Krassas](https://x.com/Dinosn/status/2052825199574221080).
@@ -51,15 +56,33 @@ A roundup of 54 items curated from across the security community.
5156

5257
## Techniques and Write-ups
5358

59+
- [MariaDB CVE-2026-32710 deep dive: character-constrained overflow to RCE](https://www.zeroday.cloud/blog/mariadb-cve-2026-32710-deep-dive) by [kmkz](https://x.com/kmkz_security/status/2051386774157435177).
60+
> Tim Becker walks through the heap-grooming primitive Xint used to turn a character-constrained heap overflow in JSON_SCHEMA_VALID into full RCE. ZeroDay Cloud's deep dive on the bug behind GHSA-4rj5-2227-9wgc.
61+
62+
- [EasterBunny: 142-page LAB52 report on APT29 espionage](https://lab52.io/blog) by [Lefteris Panos](https://x.com/lefterispan/status/2052450684264419688).
63+
> LAB52 drops a 142-page open-access report on EasterBunny, an advanced espionage toolset attributed to APT29. Full TTPs, samples, and IOCs in one document.
64+
5465
- [Bypassing Windows auth reflection mitigations via Kerberos coercion](https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part) by [Load.](https://x.com/loadlow/status/2049868200183996636).
5566
> Synacktiv's yaumn_ closes out his Windows auth-reflection series with a new Kerberos coercion technique that remotely compromises Windows systems even with the post-PetitPotam mitigations on. Bonus payload at the end.
5667
68+
- [Hacking Microsoft Copilots: CVE-2026-24299 (Copirate 365)](https://embracethered.com/blog/posts/2026/defcon-) by [Max](https://x.com/maxime_tz/status/2051416672553120072).
69+
> Johann Rehberger's DEF CON Singapore talk writeup on CVE-2026-24299. End-to-end exploitation chain against Microsoft Copilot, full slides and PoCs included.
70+
5771
- [kCaddy: a malleable Caddy redirector for Evilginx](https://knifesec.com/blog/kcaddy-redirector-evilginx) by [Kuba Gretzky](https://x.com/mrgretzky/status/2049437750940561752).
5872
> Walkthrough on putting Caddy in front of Evilginx as a malleable redirector, with kCaddy automating the wiring. M365 and Google Workspace impersonation flows covered.
5973
6074
- [ShadeStager and Phoenix: two new macOS threats added to Objective-See repo](https://9to5mac.com/2026/04/22/mosyle-identifies-two-new-macos-threats-invisible-to-antivirus-engines) by [Patrick Wardle](https://x.com/patrickwardle/status/2048211532904087593).
6175
> Patrick Wardle uploads two fresh Mosyle-discovered macOS samples to the public Objective-See repo: ShadeStager (stealer) and Phoenix (first-stage persistent backdoor). Password infect3d.
6276
77+
- [Recovering AES-128 from a Bluetooth chip via 10-meter RF eavesdrop](https://x.com/podalirius_/status/2051630625984057523) by Rémi GASCOU (Podalirius).
78+
> Crypto-engine switching noise couples into the chip's 2.4 GHz RF chain and leaks out as radio. Owen Brake's writeup shows the AES-128 key recovered from 10 meters away with nothing but a listener.
79+
80+
- [Chinese OPPO phones crack and emulate MIFARE Classic cards in seconds](https://x.com/samwcyo/status/2050732278171803728) by Sam Curry.
81+
> Iceman flags consumer-grade Chinese smartphones that read, crack, and emulate MIFARE Classic cards out of the box. Hotel keys, access control, transit cards: pocket cloning, no extra hardware.
82+
83+
- [CVE-2026-7865: command injection in Crestron touch panels](https://www.cve.org/CVERecord?id=CVE-2026-7865) by [spaceraccoon | Eugene Lim](https://x.com/spaceraccoonsec/status/2052764024052564087).
84+
> spaceraccoonsec lands a CVE on Crestron's enterprise touch panels for unauthenticated command injection. Firmware patch shipped; expect a long tail of unpatched conference-room units.
85+
6386
- [Needle crypto-stealer C2: plaintext API key unlocks 1,932 victims](https://beelzebub.ai/blog/needle-c2-crypto-stealer-analysis).
6487
> beelzebub.ai reverses the Needle crypto-stealer, finds a plaintext API key inside the Rust binary, and walks back into the operator's panel to enumerate 1,932 victims and the withdrawal config.
6588
@@ -69,6 +92,15 @@ A roundup of 54 items curated from across the security community.
6992
- [Approve once, exploit forever: trust persistence in AI coding agents](https://mindgard.ai/blog/approve-once-exploit-forever-the-trust-persistence-problem-in-ai-coding-agents).
7093
> Mindgard demonstrates that one-time trust grants in Claude Code, Codex, and Gemini CLI become permanent attack surface. Sticky approvals turn into long-lived backdoors.
7194
95+
- [Salesforce Experience Site pentesting: how to be an apex predator](https://www.reco.ai/blog/salesforce-experience-site-pentest-apex-predator).
96+
> Reco.ai catalogs the novel Salesforce Experience Site attack surface: Apex injection, guest-user privilege confusion, and SOQL primitives that turn a misconfigured site into wide reach.
97+
98+
- [Five-bug chain to arbitrary APK install on Samsung Galaxy S25](https://bugscale.ch/blog/here-we-go-again-a-five-bug-chain-to-arbitrary-apk-install-on-samsung-s25) by [ϻг_ϻε](https://x.com/steventseeley/status/2050048524814016683).
99+
> Bugscale chains five separate bugs in Samsung's cloud gaming component to install arbitrary APKs on the Galaxy S25 from an app with no install permissions.
100+
101+
- [Grok prompt-injected into draining $175K from a crypto wallet](https://x.com/vysecurity/status/2051350708214260040) by Vincent Yiu.
102+
> An attacker fed Grok a prompt that walked the agent into authorizing a 3 billion DRB transfer (about $175,000) on Base. Elegant payload, expensive lesson on AI agents wired to crypto rails.
103+
72104
- [CVE-2026-7270: FreeBSD root with a shell script](https://open.substack.com/pub/calif/p/cve-2026) by [Axel Souchet](https://x.com/0vercl0k/status/2052762732785766630).
73105
> CVE-2026-7270, FreeBSD root via a shell script. Calif's writeup of a setuid-program flaw exploitable without compiling a thing. "My human authorized this post" footer included.
74106
@@ -89,24 +121,51 @@ A roundup of 54 items curated from across the security community.
89121
90122

91123
<details markdown="1">
92-
<summary>More this week (18)</summary>
124+
<summary>More this week (45)</summary>
93125

94126
- [Silencing ETW Threat Intelligence via BYOVD](https://medium.com/@s12deff/silencing-etw-threat-intelligence-via-byovd-c2ba9e3bb072) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052501473775243607).
95127
- [Cross-Session Activation: CLSIDs for lateral movement](https://ipurple.team/2026/05/04/cross-session-activation) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052058498926604753).
128+
- [CrystalForge: AdaptixC2 beacon with Crystal Palace loader support](https://github.com/k1ng0fn0th1ng/CrystalForge) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052033266362802628).
129+
- [net_use: modernized BOF for mapped drives via MPR API](https://github.com/atomiczsec/Adrenaline/tree/main/community/net_use) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052085370083299535).
96130
- [Silencing EDR network telemetry via WFP callout patching](https://medium.com/@s12deff/silencing-edr-network-telemetry-wfp-callout-patching-via-byovd-1f9ee7ed0e67) by [Panos Gkatziroulis](https://x.com/ipurple/status/2051776469244764621).
131+
- [morphkatz: polymorphic PE rewriter for Windows x64](https://github.com/0xM) by [Panos Gkatziroulis](https://x.com/ipurple/status/2051737155127394456).
97132
- [CVE-2026-6307: Turbofan JS-to-Wasm deopt type confusion](https://tashita.net/turbofan-js-to-wasm-deopt-type-confusion) by [kmkz](https://x.com/kmkz_security/status/2052504986345468154).
133+
- [Pwning V8CTF with TurboFan type confusion (CVE-2025-2135)](https://www.zellic.io/blog/pwning-v8ctf) by [kmkz](https://x.com/kmkz_security/status/2051787888174490008).
134+
- [Wiz launches zeroday.cloud: writeups for PostgreSQL and MariaDB RCEs](https://zeroday.cloud/) by [kmkz](https://x.com/kmkz_security/status/2051387049991610617).
135+
- [GadgetExplorer: .NET deserialization gadget chain finder](https://github.com/nines-nine/GadgetExplorer) by [Lefteris Panos](https://x.com/lefterispan/status/2047993517104910708).
136+
- [Bug bounty writeup repos: HackerOne, Google VRP, Facebook](https://github.com/reddelexc/hackerone-reports) by [Spiros Fraganastasis](https://x.com/m3g9tr0n/status/2051895958036742233).
137+
- [Finding open-source 0-days with an LLM multi-agent workflow](https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-day) by [Spiros Fraganastasis](https://x.com/m3g9tr0n/status/2050692504379359671).
98138
- [LLVM-based devirtualizer beats a VM-protected crackme](https://eversinc33.com/2026/05/07/llvm-devirtualizer) by [Max](https://x.com/maxime_tz/status/2052656320562463089).
99139
- [Wi-Fi pentesting in 2026: WPA3 bypasses and RBCD across forests](https://www.synacktiv.com/en/publications/wireless-infidelity-pentest) by [Max](https://x.com/maxime_tz/status/2052457755391271128).
100-
- [Autonomous vulnerability research with Claude Code and MCP](https://blog.zsec.uk/bullyingllms) by [Max](https://x.com/maxime_tz/status/2052071367399420367).
140+
- [The other side of the MCP threat conversation: MCP servers as attack surface](https://www.akamai.com/blog/security/other-side-mcp-threat-conversation) by [Max](https://x.com/maxime_tz/status/2052071812347957516).
141+
- [Bullying LLMs: autonomous vulnerability research with Claude Code and MCP](https://blog.zsec.uk/bullyingllms) by [Max](https://x.com/maxime_tz/status/2052071367399420367).
142+
- [Impacket IoCs: 50+ defender indicators in one repo](https://github.com/ThatTotallyRealMyth/Impacket-IoCs) by [n00py](https://x.com/n00py1/status/2050182460038918194).
101143
- [New Odyssey macOS stealer hides in PLIST files](https://x.com/patrickwardle/status/2052396305293701130) by Patrick Wardle.
102144
- [3Crypt: a macOS RAT zero AV vendors caught](https://x.com/patrickwardle/status/2049069636608761913) by Patrick Wardle.
145+
- [MS-RPC-Fuzzer escalates to SYSTEM via recursive structures](https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring) by [Rémi GASCOU (Podalirius)](https://x.com/podalirius_/status/2051590484481429801).
146+
- [ShareHound: BloodHound OpenGraph plugin for network shares](https://github.com/p0dalirius/sharehound) by [Rémi GASCOU (Podalirius)](https://x.com/podalirius_/status/2050518777444303244).
147+
- [EnvWatch: scan for exposed cloud secrets locally](https://github.com/cloudbreach/envwatch) by [Renos](https://x.com/r3n_hat/status/2047952113938911567).
148+
- [FreeBSD dhclient: rogue DHCP server gets root RCE (FreeBSD-SA-26:12)](https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc) by [Solar Designer](https://x.com/solardiz/status/2050027322212856090).
149+
- [Linux Kernel Runtime Guard (LKRG) 1.0.1 released](https://www.openwall.com/lists/announce/2026/04/23/1) by [Solar Designer](https://x.com/solardiz/status/2047894308464775418).
150+
- [Discovering vulnerabilities in enterprise AV hardware](https://spaceraccoon.dev/discovering-vulnerabilities-enterprise-audiovisual-hardware) by [spaceraccoon | Eugene Lim](https://x.com/spaceraccoonsec/status/2050141894957768937).
151+
- [Preauth root RCE in Oscar-grade nonlinear editing software](https://infosec.exchange/@codecolorist/116490264321417336).
103152
- [BitLocker bypass in 5 minutes via CVE-2025-48804 downgrade](https://www.intrinsec.com/en/contournement-bitlocker-la-realite-des-downgrade-attacks).
153+
- [Non-determinism of maps in Golang: why, how, and the consequences](https://maxwelldulin.com/BlogPost/Golang-Map-Non-Determinism).
154+
- [Anti-DDoS firm heaped attacks on Brazilian ISPs](https://krebsonsecurity.com/2026/04/anti-ddos-firm-heaped-attacks-on-brazilian-isps).
155+
- [CVE-2026-25654: Siemens SINEC NMS auth bypass priv-esc (ZDI-26-297)](https://www.zerodayinitiative.com/advisories/ZDI-26-297) by [ϻг_ϻε](https://x.com/steventseeley/status/2050082139883053382).
104156
- [Adobe Reader prototype pollution chained to arbitrary file read](https://starlabs.sg/blog/2026/04-three-bugs-walk-into-a-pdf-prototype-pollution-served-cold) by [ϻг_ϻε](https://x.com/steventseeley/status/2049554347240099999).
157+
- [ARP-around and find out: hijacking GPO UNC paths for code exec and NTLM relay](https://trustedsec.com/blog/arp-around-and-find-out-hijacking-gpo-unc-paths-for-code-execution-and-ntlm-relay) by [stuk0v](https://x.com/stuk0v_/status/2049881279017939374).
105158
- [MiniRAT: Go macOS RAT delivered via compromised npm package](https://www.iru.com/blog/minirat) by [Csaba Fitzl](https://x.com/theevilbit/status/2049249866237280630).
159+
- [VeeamDumper-BOF: credential extraction for Veeam Backup and Replication](https://github.com/MWR-CyberSec/VeeamDumper-BOF) by [Mr.Z](https://x.com/zux0x3a/status/2051955745453727938).
160+
- [zig-bof-template: Cobalt Strike BOFs in Zig](https://github.com/nbaertsch/zig-bof-template) by [Mr.Z](https://x.com/zux0x3a/status/2048073292636905661).
161+
- [zig-pe: reflective PE loader written in Zig](https://github.com/Thoxy67/zig-pe) by [Mr.Z](https://x.com/zux0x3a/status/2047778847177793676).
106162
- [Memory poisoning AI agents via ChromaDB](https://mamtaupadhyay.com/2026/05/09/agent-memory-poisoning-demo).
107163
- [Seclens: role-specific LLM eval for vuln detection](https://arxiv.org/abs/2604.01637).
108164
- [Securing CI/CD: lessons from Cilium](https://cilium.io/blog/2026/05/06/securing-cicd-open-source-lessons-from-cilium).
165+
- [Oh myAudi: poking at Audi's connected vehicle APIs](https://decoder.cloud/2026/05/08/oh-myaudi) by [sailay(valen)](https://x.com/404death/status/2052751778186502204).
109166
- [Skip the LSASS theatre: walk the $MFT instead](https://x.com/404death/status/2052425115800084815) by sailay(valen).
167+
- [Former govt contractor convicted for wiping federal databases](https://www.bleepingcomputer.com/news/security/former-govt-contractor-convicte) by [BleepingComputer](https://x.com/BleepinComputer/status/2052671168579059825).
168+
- [JDownloader's official website delivered a Python RAT](https://app.any.run/tasks/e0cecc2d-5571-49fe-a549-cc7d1b8b5908) by [Nicolas Krassas](https://x.com/Dinosn/status/2052766136194699343).
110169
- [Walking through Windows minifilter drivers](https://hackyboiz.github.io/2025/08/15/banda/Minifilter-Driver/en) by [DirectoryRanger](https://x.com/DirectoryRanger/status/2053051947905626354).
111170
- [Commonly abused administrative utilities](https://www.blackhillsinfosec.com/commonly-abused-admini) by [DirectoryRanger](https://x.com/DirectoryRanger/status/2053051773233799399).
112171

@@ -115,14 +174,21 @@ A roundup of 54 items curated from across the security community.
115174

116175
## Tools and Exploits
117176

177+
- [Zellic audit of rust-coreutils: 113 issues, 44 CVEs](https://www.openwall.com/lists/oss-security/2026/05/02/1) by [Solar Designer](https://x.com/solardiz/status/2050598719699952033).
178+
> Zellic's security audit of uutils coreutils lands 113 findings across two rounds (7 critical, 11 high, 29 medium, 26 low) and 44 CVEs. The very codebase Canonical wants shipped by default.
179+
118180
- [BitlockMove: lateral movement via BitLocker DCOM](https://github.com/rtecCyberSec/BitlockMove) by [DirectoryRanger](https://x.com/DirectoryRanger/status/2053052157583114582).
119181
> A new lateral movement primitive that pivots through BitLocker's DCOM service via COM hijacking. PoC drops from rtecCyberSec.
120182
121183

122184
<details markdown="1">
123-
<summary>More this week (5)</summary>
185+
<summary>More this week (9)</summary>
124186

125187
- [Awesome Google VRP writeups](https://github.com/xdavidhu/awesome-google-vrp-writeups) by [kmkz](https://x.com/kmkz_security/status/2051390343837274290).
188+
- [CodeNeedle: stealthy VS Code plugin for arbitrary JS evaluation](https://github.com/chvancooten/code-needle) by [Lefteris Panos](https://x.com/lefterispan/status/2050576650060906625).
189+
- [maSSO: weaponized IdP for Multi-SSO AWS Cognito testing](https://blog.doyensec.com/2026/05/05/cloudsectidbits-masso-cognito-sso.html) by [Maxence SCHMITT](https://x.com/maxenceschmitt/status/2051679190324330865).
190+
- [CVE-2026-41163: bubblewrap setuid root priv-esc via ptrace](https://www.openwall.com/lists/oss-s) by [Solar Designer](https://x.com/solardiz/status/2048953401820475731).
191+
- [CVE-2026-41651: PackageKit TOCTOU leads to local root](https://www.openwall.com/lists/oss-security/2026/04/22/6) by [Solar Designer](https://x.com/solardiz/status/2048953303594111321).
126192
- [Sentinai-Core: AI auditor that red-teams PRs](https://www.npmjs.com/package/sentinai-core).
127193
- [Quacc++: automated open-source vulnerability discovery](https://www.somersetrecon.com/blog/2026/4/27/quacc-automated-open-source-vulnerability-discovery).
128194
- [AiSOC: open-source AI Security Operations Center](https://github.com/beenuar/AiSOC) by [Nicolas Krassas](https://x.com/Dinosn/status/2053021144748261489).

0 commit comments

Comments
 (0)