You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: content/posts/crows-nest-2026-05-11.md
+71-5Lines changed: 71 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ draft: false
5
5
tags: ["roundup"]
6
6
---
7
7
8
-
A roundup of 54 items curated from across the security community.
8
+
A roundup of 98 items curated from across the security community.
9
9
10
10
## News
11
11
@@ -24,6 +24,9 @@ A roundup of 54 items curated from across the security community.
24
24
-[Solana router: two critical bugs drain token accounts](https://atlas-it.consulting/post/solana-router-vuln) by [Sam Curry](https://x.com/samwcyo/status/2049596235355689464).
25
25
> Two critical bugs in a popular Solana router let an attacker drain every token account it owns. Full writeup at atlas-it.consulting.
26
26
27
+
-[Bleeding Llama: unauthenticated memory leak in Ollama (CVE-2026-7482)](https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama).
28
+
> Cyera Research uncovers a critical pre-auth memory disclosure in Ollama. Self-hosted LLM gateways leak adjacent buffer contents to anyone who can hit the API.
> Dark Tangent on the CA/B Forum schedule that takes TLS cert validity from 350 days down to 47, plus the deprecation of DANE that left the gap in the first place.
29
32
@@ -32,11 +35,13 @@ A roundup of 54 items curated from across the security community.
32
35
33
36
34
37
<detailsmarkdown="1">
35
-
<summary>More this week (11)</summary>
38
+
<summary>More this week (13)</summary>
36
39
37
40
-[Trenchant exec ordered to pay $10M for selling zero-days to Russia](https://www.zetter-zeroday.com/trenchant-exec-who-sold-zero-days-to-russian-buyer-ordered-to-pay-10-million-in-restitution-to-former-employers).
-[MOVEit Automation: critical auth bypass and priv-esc CVEs](https://community.progress.com/s/article/MOVEit-Automation-Critical-Security-Alert-Bulletin-April-2026-CVE-2026-4670-CVE-2026-5174) by [Vincent Yiu](https://x.com/vysecurity/status/2051009329655066894).
43
+
-[RansomHouse claims Trellix source-code breach](https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers) by [BleepingComputer](https://x.com/BleepinComputer/status/2052763427966202314).
44
+
-[Zara data breach exposed 197,000 people](https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-infor) by [BleepingComputer](https://x.com/BleepinComputer/status/2052700692716892489).
40
45
-[Ivanti EPMM zero-day exploited in the wild](https://www.bleepingcomputer.com/news/security/ivanti-warns-of-new-epmm-flaw-exploited-in-) by [BleepingComputer](https://x.com/BleepinComputer/status/2052408380669452372).
41
46
-[US military data left exposed despite CISA notification](https://www.scworld.com/brief/us-military-data-exposed-in-leaky-directory-despit) by [Nicolas Krassas](https://x.com/Dinosn/status/2052844685668835807).
42
47
-[TCLBANKER trojan spreads via WhatsApp and Outlook](https://thehackernews.com/2026/05/tclbanker-banking-trojan-targets) by [Nicolas Krassas](https://x.com/Dinosn/status/2052825199574221080).
@@ -51,15 +56,33 @@ A roundup of 54 items curated from across the security community.
51
56
52
57
## Techniques and Write-ups
53
58
59
+
-[MariaDB CVE-2026-32710 deep dive: character-constrained overflow to RCE](https://www.zeroday.cloud/blog/mariadb-cve-2026-32710-deep-dive) by [kmkz](https://x.com/kmkz_security/status/2051386774157435177).
60
+
> Tim Becker walks through the heap-grooming primitive Xint used to turn a character-constrained heap overflow in JSON_SCHEMA_VALID into full RCE. ZeroDay Cloud's deep dive on the bug behind GHSA-4rj5-2227-9wgc.
61
+
62
+
-[EasterBunny: 142-page LAB52 report on APT29 espionage](https://lab52.io/blog) by [Lefteris Panos](https://x.com/lefterispan/status/2052450684264419688).
63
+
> LAB52 drops a 142-page open-access report on EasterBunny, an advanced espionage toolset attributed to APT29. Full TTPs, samples, and IOCs in one document.
64
+
54
65
-[Bypassing Windows auth reflection mitigations via Kerberos coercion](https://www.synacktiv.com/en/publications/bypassing-windows-authentication-reflection-mitigations-for-system-shells-part) by [Load.](https://x.com/loadlow/status/2049868200183996636).
55
66
> Synacktiv's yaumn_ closes out his Windows auth-reflection series with a new Kerberos coercion technique that remotely compromises Windows systems even with the post-PetitPotam mitigations on. Bonus payload at the end.
56
67
68
+
-[Hacking Microsoft Copilots: CVE-2026-24299 (Copirate 365)](https://embracethered.com/blog/posts/2026/defcon-) by [Max](https://x.com/maxime_tz/status/2051416672553120072).
69
+
> Johann Rehberger's DEF CON Singapore talk writeup on CVE-2026-24299. End-to-end exploitation chain against Microsoft Copilot, full slides and PoCs included.
70
+
57
71
-[kCaddy: a malleable Caddy redirector for Evilginx](https://knifesec.com/blog/kcaddy-redirector-evilginx) by [Kuba Gretzky](https://x.com/mrgretzky/status/2049437750940561752).
58
72
> Walkthrough on putting Caddy in front of Evilginx as a malleable redirector, with kCaddy automating the wiring. M365 and Google Workspace impersonation flows covered.
59
73
60
74
-[ShadeStager and Phoenix: two new macOS threats added to Objective-See repo](https://9to5mac.com/2026/04/22/mosyle-identifies-two-new-macos-threats-invisible-to-antivirus-engines) by [Patrick Wardle](https://x.com/patrickwardle/status/2048211532904087593).
61
75
> Patrick Wardle uploads two fresh Mosyle-discovered macOS samples to the public Objective-See repo: ShadeStager (stealer) and Phoenix (first-stage persistent backdoor). Password infect3d.
62
76
77
+
-[Recovering AES-128 from a Bluetooth chip via 10-meter RF eavesdrop](https://x.com/podalirius_/status/2051630625984057523) by Rémi GASCOU (Podalirius).
78
+
> Crypto-engine switching noise couples into the chip's 2.4 GHz RF chain and leaks out as radio. Owen Brake's writeup shows the AES-128 key recovered from 10 meters away with nothing but a listener.
79
+
80
+
-[Chinese OPPO phones crack and emulate MIFARE Classic cards in seconds](https://x.com/samwcyo/status/2050732278171803728) by Sam Curry.
81
+
> Iceman flags consumer-grade Chinese smartphones that read, crack, and emulate MIFARE Classic cards out of the box. Hotel keys, access control, transit cards: pocket cloning, no extra hardware.
82
+
83
+
-[CVE-2026-7865: command injection in Crestron touch panels](https://www.cve.org/CVERecord?id=CVE-2026-7865) by [spaceraccoon | Eugene Lim](https://x.com/spaceraccoonsec/status/2052764024052564087).
84
+
> spaceraccoonsec lands a CVE on Crestron's enterprise touch panels for unauthenticated command injection. Firmware patch shipped; expect a long tail of unpatched conference-room units.
85
+
63
86
-[Needle crypto-stealer C2: plaintext API key unlocks 1,932 victims](https://beelzebub.ai/blog/needle-c2-crypto-stealer-analysis).
64
87
> beelzebub.ai reverses the Needle crypto-stealer, finds a plaintext API key inside the Rust binary, and walks back into the operator's panel to enumerate 1,932 victims and the withdrawal config.
65
88
@@ -69,6 +92,15 @@ A roundup of 54 items curated from across the security community.
69
92
-[Approve once, exploit forever: trust persistence in AI coding agents](https://mindgard.ai/blog/approve-once-exploit-forever-the-trust-persistence-problem-in-ai-coding-agents).
70
93
> Mindgard demonstrates that one-time trust grants in Claude Code, Codex, and Gemini CLI become permanent attack surface. Sticky approvals turn into long-lived backdoors.
71
94
95
+
-[Salesforce Experience Site pentesting: how to be an apex predator](https://www.reco.ai/blog/salesforce-experience-site-pentest-apex-predator).
96
+
> Reco.ai catalogs the novel Salesforce Experience Site attack surface: Apex injection, guest-user privilege confusion, and SOQL primitives that turn a misconfigured site into wide reach.
97
+
98
+
-[Five-bug chain to arbitrary APK install on Samsung Galaxy S25](https://bugscale.ch/blog/here-we-go-again-a-five-bug-chain-to-arbitrary-apk-install-on-samsung-s25) by [ϻг_ϻε](https://x.com/steventseeley/status/2050048524814016683).
99
+
> Bugscale chains five separate bugs in Samsung's cloud gaming component to install arbitrary APKs on the Galaxy S25 from an app with no install permissions.
100
+
101
+
-[Grok prompt-injected into draining $175K from a crypto wallet](https://x.com/vysecurity/status/2051350708214260040) by Vincent Yiu.
102
+
> An attacker fed Grok a prompt that walked the agent into authorizing a 3 billion DRB transfer (about $175,000) on Base. Elegant payload, expensive lesson on AI agents wired to crypto rails.
103
+
72
104
-[CVE-2026-7270: FreeBSD root with a shell script](https://open.substack.com/pub/calif/p/cve-2026) by [Axel Souchet](https://x.com/0vercl0k/status/2052762732785766630).
73
105
> CVE-2026-7270, FreeBSD root via a shell script. Calif's writeup of a setuid-program flaw exploitable without compiling a thing. "My human authorized this post" footer included.
74
106
@@ -89,24 +121,51 @@ A roundup of 54 items curated from across the security community.
89
121
90
122
91
123
<detailsmarkdown="1">
92
-
<summary>More this week (18)</summary>
124
+
<summary>More this week (45)</summary>
93
125
94
126
-[Silencing ETW Threat Intelligence via BYOVD](https://medium.com/@s12deff/silencing-etw-threat-intelligence-via-byovd-c2ba9e3bb072) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052501473775243607).
95
127
-[Cross-Session Activation: CLSIDs for lateral movement](https://ipurple.team/2026/05/04/cross-session-activation) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052058498926604753).
128
+
-[CrystalForge: AdaptixC2 beacon with Crystal Palace loader support](https://github.com/k1ng0fn0th1ng/CrystalForge) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052033266362802628).
129
+
-[net_use: modernized BOF for mapped drives via MPR API](https://github.com/atomiczsec/Adrenaline/tree/main/community/net_use) by [Panos Gkatziroulis](https://x.com/ipurple/status/2052085370083299535).
96
130
-[Silencing EDR network telemetry via WFP callout patching](https://medium.com/@s12deff/silencing-edr-network-telemetry-wfp-callout-patching-via-byovd-1f9ee7ed0e67) by [Panos Gkatziroulis](https://x.com/ipurple/status/2051776469244764621).
131
+
-[morphkatz: polymorphic PE rewriter for Windows x64](https://github.com/0xM) by [Panos Gkatziroulis](https://x.com/ipurple/status/2051737155127394456).
97
132
-[CVE-2026-6307: Turbofan JS-to-Wasm deopt type confusion](https://tashita.net/turbofan-js-to-wasm-deopt-type-confusion) by [kmkz](https://x.com/kmkz_security/status/2052504986345468154).
133
+
-[Pwning V8CTF with TurboFan type confusion (CVE-2025-2135)](https://www.zellic.io/blog/pwning-v8ctf) by [kmkz](https://x.com/kmkz_security/status/2051787888174490008).
134
+
-[Wiz launches zeroday.cloud: writeups for PostgreSQL and MariaDB RCEs](https://zeroday.cloud/) by [kmkz](https://x.com/kmkz_security/status/2051387049991610617).
135
+
-[GadgetExplorer: .NET deserialization gadget chain finder](https://github.com/nines-nine/GadgetExplorer) by [Lefteris Panos](https://x.com/lefterispan/status/2047993517104910708).
136
+
-[Bug bounty writeup repos: HackerOne, Google VRP, Facebook](https://github.com/reddelexc/hackerone-reports) by [Spiros Fraganastasis](https://x.com/m3g9tr0n/status/2051895958036742233).
137
+
-[Finding open-source 0-days with an LLM multi-agent workflow](https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-day) by [Spiros Fraganastasis](https://x.com/m3g9tr0n/status/2050692504379359671).
98
138
-[LLVM-based devirtualizer beats a VM-protected crackme](https://eversinc33.com/2026/05/07/llvm-devirtualizer) by [Max](https://x.com/maxime_tz/status/2052656320562463089).
99
139
-[Wi-Fi pentesting in 2026: WPA3 bypasses and RBCD across forests](https://www.synacktiv.com/en/publications/wireless-infidelity-pentest) by [Max](https://x.com/maxime_tz/status/2052457755391271128).
100
-
-[Autonomous vulnerability research with Claude Code and MCP](https://blog.zsec.uk/bullyingllms) by [Max](https://x.com/maxime_tz/status/2052071367399420367).
140
+
-[The other side of the MCP threat conversation: MCP servers as attack surface](https://www.akamai.com/blog/security/other-side-mcp-threat-conversation) by [Max](https://x.com/maxime_tz/status/2052071812347957516).
141
+
-[Bullying LLMs: autonomous vulnerability research with Claude Code and MCP](https://blog.zsec.uk/bullyingllms) by [Max](https://x.com/maxime_tz/status/2052071367399420367).
142
+
-[Impacket IoCs: 50+ defender indicators in one repo](https://github.com/ThatTotallyRealMyth/Impacket-IoCs) by [n00py](https://x.com/n00py1/status/2050182460038918194).
101
143
-[New Odyssey macOS stealer hides in PLIST files](https://x.com/patrickwardle/status/2052396305293701130) by Patrick Wardle.
102
144
-[3Crypt: a macOS RAT zero AV vendors caught](https://x.com/patrickwardle/status/2049069636608761913) by Patrick Wardle.
145
+
-[MS-RPC-Fuzzer escalates to SYSTEM via recursive structures](https://www.incendium.rocks/posts/Fuzzing-MS-RPC-structures-and-monitoring) by [Rémi GASCOU (Podalirius)](https://x.com/podalirius_/status/2051590484481429801).
146
+
-[ShareHound: BloodHound OpenGraph plugin for network shares](https://github.com/p0dalirius/sharehound) by [Rémi GASCOU (Podalirius)](https://x.com/podalirius_/status/2050518777444303244).
147
+
-[EnvWatch: scan for exposed cloud secrets locally](https://github.com/cloudbreach/envwatch) by [Renos](https://x.com/r3n_hat/status/2047952113938911567).
148
+
-[FreeBSD dhclient: rogue DHCP server gets root RCE (FreeBSD-SA-26:12)](https://www.freebsd.org/security/advisories/FreeBSD-SA-26:12.dhclient.asc) by [Solar Designer](https://x.com/solardiz/status/2050027322212856090).
149
+
-[Linux Kernel Runtime Guard (LKRG) 1.0.1 released](https://www.openwall.com/lists/announce/2026/04/23/1) by [Solar Designer](https://x.com/solardiz/status/2047894308464775418).
150
+
-[Discovering vulnerabilities in enterprise AV hardware](https://spaceraccoon.dev/discovering-vulnerabilities-enterprise-audiovisual-hardware) by [spaceraccoon | Eugene Lim](https://x.com/spaceraccoonsec/status/2050141894957768937).
151
+
-[Preauth root RCE in Oscar-grade nonlinear editing software](https://infosec.exchange/@codecolorist/116490264321417336).
103
152
-[BitLocker bypass in 5 minutes via CVE-2025-48804 downgrade](https://www.intrinsec.com/en/contournement-bitlocker-la-realite-des-downgrade-attacks).
153
+
-[Non-determinism of maps in Golang: why, how, and the consequences](https://maxwelldulin.com/BlogPost/Golang-Map-Non-Determinism).
154
+
-[Anti-DDoS firm heaped attacks on Brazilian ISPs](https://krebsonsecurity.com/2026/04/anti-ddos-firm-heaped-attacks-on-brazilian-isps).
155
+
-[CVE-2026-25654: Siemens SINEC NMS auth bypass priv-esc (ZDI-26-297)](https://www.zerodayinitiative.com/advisories/ZDI-26-297) by [ϻг_ϻε](https://x.com/steventseeley/status/2050082139883053382).
104
156
-[Adobe Reader prototype pollution chained to arbitrary file read](https://starlabs.sg/blog/2026/04-three-bugs-walk-into-a-pdf-prototype-pollution-served-cold) by [ϻг_ϻε](https://x.com/steventseeley/status/2049554347240099999).
157
+
-[ARP-around and find out: hijacking GPO UNC paths for code exec and NTLM relay](https://trustedsec.com/blog/arp-around-and-find-out-hijacking-gpo-unc-paths-for-code-execution-and-ntlm-relay) by [stuk0v](https://x.com/stuk0v_/status/2049881279017939374).
105
158
-[MiniRAT: Go macOS RAT delivered via compromised npm package](https://www.iru.com/blog/minirat) by [Csaba Fitzl](https://x.com/theevilbit/status/2049249866237280630).
159
+
-[VeeamDumper-BOF: credential extraction for Veeam Backup and Replication](https://github.com/MWR-CyberSec/VeeamDumper-BOF) by [Mr.Z](https://x.com/zux0x3a/status/2051955745453727938).
160
+
-[zig-bof-template: Cobalt Strike BOFs in Zig](https://github.com/nbaertsch/zig-bof-template) by [Mr.Z](https://x.com/zux0x3a/status/2048073292636905661).
161
+
-[zig-pe: reflective PE loader written in Zig](https://github.com/Thoxy67/zig-pe) by [Mr.Z](https://x.com/zux0x3a/status/2047778847177793676).
106
162
-[Memory poisoning AI agents via ChromaDB](https://mamtaupadhyay.com/2026/05/09/agent-memory-poisoning-demo).
107
163
-[Seclens: role-specific LLM eval for vuln detection](https://arxiv.org/abs/2604.01637).
108
164
-[Securing CI/CD: lessons from Cilium](https://cilium.io/blog/2026/05/06/securing-cicd-open-source-lessons-from-cilium).
165
+
-[Oh myAudi: poking at Audi's connected vehicle APIs](https://decoder.cloud/2026/05/08/oh-myaudi) by [sailay(valen)](https://x.com/404death/status/2052751778186502204).
109
166
-[Skip the LSASS theatre: walk the $MFT instead](https://x.com/404death/status/2052425115800084815) by sailay(valen).
167
+
-[Former govt contractor convicted for wiping federal databases](https://www.bleepingcomputer.com/news/security/former-govt-contractor-convicte) by [BleepingComputer](https://x.com/BleepinComputer/status/2052671168579059825).
168
+
-[JDownloader's official website delivered a Python RAT](https://app.any.run/tasks/e0cecc2d-5571-49fe-a549-cc7d1b8b5908) by [Nicolas Krassas](https://x.com/Dinosn/status/2052766136194699343).
110
169
-[Walking through Windows minifilter drivers](https://hackyboiz.github.io/2025/08/15/banda/Minifilter-Driver/en) by [DirectoryRanger](https://x.com/DirectoryRanger/status/2053051947905626354).
111
170
-[Commonly abused administrative utilities](https://www.blackhillsinfosec.com/commonly-abused-admini) by [DirectoryRanger](https://x.com/DirectoryRanger/status/2053051773233799399).
112
171
@@ -115,14 +174,21 @@ A roundup of 54 items curated from across the security community.
115
174
116
175
## Tools and Exploits
117
176
177
+
-[Zellic audit of rust-coreutils: 113 issues, 44 CVEs](https://www.openwall.com/lists/oss-security/2026/05/02/1) by [Solar Designer](https://x.com/solardiz/status/2050598719699952033).
178
+
> Zellic's security audit of uutils coreutils lands 113 findings across two rounds (7 critical, 11 high, 29 medium, 26 low) and 44 CVEs. The very codebase Canonical wants shipped by default.
179
+
118
180
-[BitlockMove: lateral movement via BitLocker DCOM](https://github.com/rtecCyberSec/BitlockMove) by [DirectoryRanger](https://x.com/DirectoryRanger/status/2053052157583114582).
119
181
> A new lateral movement primitive that pivots through BitLocker's DCOM service via COM hijacking. PoC drops from rtecCyberSec.
120
182
121
183
122
184
<detailsmarkdown="1">
123
-
<summary>More this week (5)</summary>
185
+
<summary>More this week (9)</summary>
124
186
125
187
-[Awesome Google VRP writeups](https://github.com/xdavidhu/awesome-google-vrp-writeups) by [kmkz](https://x.com/kmkz_security/status/2051390343837274290).
188
+
-[CodeNeedle: stealthy VS Code plugin for arbitrary JS evaluation](https://github.com/chvancooten/code-needle) by [Lefteris Panos](https://x.com/lefterispan/status/2050576650060906625).
189
+
-[maSSO: weaponized IdP for Multi-SSO AWS Cognito testing](https://blog.doyensec.com/2026/05/05/cloudsectidbits-masso-cognito-sso.html) by [Maxence SCHMITT](https://x.com/maxenceschmitt/status/2051679190324330865).
190
+
-[CVE-2026-41163: bubblewrap setuid root priv-esc via ptrace](https://www.openwall.com/lists/oss-s) by [Solar Designer](https://x.com/solardiz/status/2048953401820475731).
191
+
-[CVE-2026-41651: PackageKit TOCTOU leads to local root](https://www.openwall.com/lists/oss-security/2026/04/22/6) by [Solar Designer](https://x.com/solardiz/status/2048953303594111321).
126
192
-[Sentinai-Core: AI auditor that red-teams PRs](https://www.npmjs.com/package/sentinai-core).
-[AiSOC: open-source AI Security Operations Center](https://github.com/beenuar/AiSOC) by [Nicolas Krassas](https://x.com/Dinosn/status/2053021144748261489).
0 commit comments