<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-07-31T17:55:04&#43;02:00</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by O RLY CYBER</title>
  <author>
    <name>O RLY CYBER</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1shlut8mwdmfevu2nt294apayu7e0mxs5mrpfyq8v5ru4ymscg9ysx0kwr0.rss" />
  <link href="https://nostr.ae/npub1shlut8mwdmfevu2nt294apayu7e0mxs5mrpfyq8v5ru4ymscg9ysx0kwr0" />
  <id>https://nostr.ae/npub1shlut8mwdmfevu2nt294apayu7e0mxs5mrpfyq8v5ru4ymscg9ysx0kwr0</id>
  <icon>https://media.swecyb.com/accounts/avatars/116/080/658/609/901/341/original/3e07147832e1eef7.jpg</icon>
  <logo>https://media.swecyb.com/accounts/avatars/116/080/658/609/901/341/original/3e07147832e1eef7.jpg</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsxt5pylqvazkncwre5csaq2vlvknas23pr342p4zq8rp8za8ndlfgzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jeazt7y</id>
    
      <title type="html">(talosintelligence.com) Rethinking Vulnerability Prioritization: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxt5pylqvazkncwre5csaq2vlvknas23pr342p4zq8rp8za8ndlfgzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jeazt7y" />
    <content type="html">
      (talosintelligence.com) Rethinking Vulnerability Prioritization: Beyond CVSS to EPSS and Decentralized CVE Enrichment&lt;br/&gt;&lt;br/&gt;New research challenges traditional vulnerability management, advocating for EPSS alongside CVSS to prioritize patching based on exploit likelihood rather than severity alone.&lt;br/&gt;&lt;br/&gt;In brief - Vulnerability prioritization must evolve beyond CVSS to incorporate EPSS, which predicts exploitation probability within 30 days. Centralized databases like CISA’s KEV are limited; decentralized approaches such as GCVE offer faster, globally relevant enrichment. Cisco Talos’s EvidenceForge tool generates synthetic logs to enhance SOC training without compliance risks.&lt;br/&gt;&lt;br/&gt;Technically - EPSS (Exploit Prediction Scoring System) complements CVSS by quantifying real-world exploitability, enabling risk-based patching. GCVE (Global CVE) decentralizes CVE enrichment, addressing delays in centralized sources like KEV. EvidenceForge leverages AI-assisted scenario authoring to produce temporally and causally consistent synthetic logs, improving detection validation and threat hunting without relying on sensitive datasets.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://blog.talosintelligence.com/less-panic-patching-more-precision/&#34;&gt;https://blog.talosintelligence.com/less-panic-patching-more-precision/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-28T20:05:37&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0vj86ungtpdl6eepxrtkngwkrfm9f3xjta8qfhuhnkv9xukeytwgzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jgvemd0</id>
    
      <title type="html">(safedep.io) Megalodon Campaign: Large-Scale GitHub Repository ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0vj86ungtpdl6eepxrtkngwkrfm9f3xjta8qfhuhnkv9xukeytwgzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jgvemd0" />
    <content type="html">
      (safedep.io) Megalodon Campaign: Large-Scale GitHub Repository Backdooring via Malicious CI Workflows&lt;br/&gt;&lt;br/&gt;New large-scale supply chain attack, *Megalodon*, backdoored 5,561 GitHub repos via malicious CI workflows. Attackers injected 5,718 commits with base64-encoded bash payloads exfiltrating CI secrets, cloud creds (AWS/GCP/Azure), SSH keys, and OIDC tokens to C2 (216.126.225.129:8443).&lt;br/&gt;&lt;br/&gt;In brief - A sophisticated campaign compromised GitHub repos using forged identities and CI workflows, leading to widespread secret exfiltration and npm package poisoning. Two payload variants enabled both mass-scale and targeted attacks, with elevated permissions facilitating cloud identity theft.&lt;br/&gt;&lt;br/&gt;Technically - Attackers leveraged GitHub Actions workflows with two variants: *SysDiag* (automatic trigger on push/pull_request_target) and *Optimize-Build* (dormant, workflow_dispatch-triggered). Payloads used base64-encoded bash scripts to harvest env vars, credential files, AWS CLI/gcloud/IMDS outputs, and 30&#43; secret types via regex. Anti-forensic measures included error suppression, random sleeps, and cleanup traps. Elevated permissions (id-token: write, actions: read) enabled OIDC token theft and cloud impersonation.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows&#34;&gt;https://safedep.io/megalodon-mass-github-repo-backdooring-ci-workflows&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-21T18:41:23&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs2r3d2xkrr6gl5658kcq0fak8f67wjces27x06avakuaesw0lka8qzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jud044f</id>
    
      <title type="html">(qianxin.com) Large-Scale Compromise of Ghost CMS via ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs2r3d2xkrr6gl5658kcq0fak8f67wjces27x06avakuaesw0lka8qzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jud044f" />
    <content type="html">
      (qianxin.com) Large-Scale Compromise of Ghost CMS via CVE-2026-26980 Fuels ClickFix Malware Campaigns&lt;br/&gt;&lt;br/&gt;Active exploitation of CVE-2026-26980 (Ghost CMS SQLi) enables large-scale ClickFix malware campaigns via Admin API key theft and article poisoning.&lt;br/&gt;&lt;br/&gt;In brief - Attackers exploit CVE-2026-26980 to steal Ghost CMS Admin API keys, injecting malicious JavaScript into 700&#43; sites. Users are tricked via FakeCaptcha/ClickFix into executing stealer trojans (Rust/Electron-based). Two threat actor groups compete in this automated, multi-stage campaign.&lt;br/&gt;&lt;br/&gt;Technically - CVE-2026-26980 (SQLi) allows unauthenticated Admin API key exfiltration. Malicious JS (two-stage loader) decodes base64 URLs to fetch cloaking scripts (e.g., clo4shara[.]xyz), redirecting victims to forged Cloudflare pages. Payloads include installer.dll (Rust) and UtilifySetup.exe (Electron), with persistence. Attackers use dynamic C2 domains (e.g., com-apps[.]cc) and cloaking to evade detection.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/&#34;&gt;https://blog.xlab.qianxin.com/ghost-cms-mass-compromised-via-cve-2026-26980-now-fueling-clickfix-attacks/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-21T14:42:34&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsx5q2s53rkx9j7mltms3ew4pkdfsl9g4vsyx740v8j3y3em8kdhvszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jsdc2rj</id>
    
      <title type="html">(wiz.io) TeamPCP Supply Chain Attack: Compromise of DurableTask ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsx5q2s53rkx9j7mltms3ew4pkdfsl9g4vsyx740v8j3y3em8kdhvszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jsdc2rj" />
    <content type="html">
      (wiz.io) TeamPCP Supply Chain Attack: Compromise of DurableTask Python Packages Unleashes Multi-Cloud Credential Theft and Worm Propagation&lt;br/&gt;&lt;br/&gt;New supply chain attack by TeamPCP: Compromised Microsoft DurableTask Python packages (v1.4.1–1.4.3) deploy rope.pyz malware targeting Linux. Credential theft (AWS/Azure/GCP/K8s/Vault) &#43; lateral movement via AWS SSM/Kubernetes. Worm-like propagation with 5-target limit per host. C2: check.git-service.com, t.m-kosche.com.&lt;br/&gt;&lt;br/&gt;In brief - TeamPCP compromised official DurableTask Python packages to distribute malware stealing cloud/K8s credentials and enabling lateral movement across multi-cloud environments. Immediate credential rotation and C2 blocking recommended.&lt;br/&gt;&lt;br/&gt;Technically - Malware (rope.pyz) injected into __init__.py/task.py, persists via ~/.cache/.sys-update-check. Harvests credentials from env vars, .bash_history/.zsh_history, and password managers (Bitwarden/1Password/GPG). Uses AWS SSM (SendCommand) and kubectl exec for lateral movement. Exfil via /v1/models, /audio.mp3. IoCs: rope.pyz hashes, /tmp/managed.pyz, /tmp/rope-*.pyz. RSA Key B for encryption.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack&#34;&gt;https://www.wiz.io/blog/durabletask-teampcp-supply-chain-attack&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-19T21:15:52&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs952vhvw8tqryh853npf9xkjncmcagjml04xfnt52seqcj7n8a2jszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jh740gs</id>
    
      <title type="html">(quarkslab.com) Exploiting Unauthenticated Access in GPON OLTs to ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs952vhvw8tqryh853npf9xkjncmcagjml04xfnt52seqcj7n8a2jszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jh740gs" />
    <content type="html">
      (quarkslab.com) Exploiting Unauthenticated Access in GPON OLTs to Compromise ISP Infrastructure&lt;br/&gt;&lt;br/&gt;Critical vulnerabilities in GPON OLTs and Cloud EMS fleet management systems enable unauthenticated network takeover, exposing ISP infrastructure globally.&lt;br/&gt;&lt;br/&gt;In brief - Unauthenticated RCE flaws in VSOL GPON OLTs and Cloud EMS allow full ISP network compromise via command injection, arbitrary file upload, and default credentials. Attackers can pivot from a single OLT to cloud-based fleet managers, risking mass surveillance, data theft, or service disruption.&lt;br/&gt;&lt;br/&gt;Technically - Key vulnerabilities include: (1) SNMP command injection via OIDs 1.3.6.1.4.1.37950.1.1.5.10.12.33.1-3 (newline bypass); (2) TACACS&#43; auth RCE via /action/main.html; (3) Web traceroute RCE via /action/tracert.html; (4) Cloud EMS arbitrary file upload (/uploadBUFile) for JSP webshells; (5) Info leakage via /systemMonitoring/getSystemCpuAndMem. Default creds (admin/Xpon@Olt9417#) and Docker socket access enable privilege escalation. Stored XSS, buffer overflows, and OMCI-based ONT attacks also identified.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;http://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html&#34;&gt;http://blog.quarkslab.com/how-olts-may-have-exposed-entire-isp-networks.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-19T20:11:57&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqszgc8nalyzuz4wnngp60e6zrgunlwh39wxsed00mtn2f8fydfyfrqzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jzhlcpd</id>
    
      <title type="html">(microsoft.com) Fox Tempest: Disruption of a ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqszgc8nalyzuz4wnngp60e6zrgunlwh39wxsed00mtn2f8fydfyfrqzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jzhlcpd" />
    <content type="html">
      (microsoft.com) Fox Tempest: Disruption of a Malware-Signing-as-a-Service Operation Enabling Ransomware and Cybercrime&lt;br/&gt;&lt;br/&gt;Microsoft DCU disrupted Fox Tempest, a Malware-Signing-as-a-Service (MSaaS) operator abusing Microsoft Artifact Signing to issue 72-hour code-signing certs for ransomware &amp;amp; malware (e.g., Rhysida, Oyster backdoor). Over 1K certs revoked, hundreds of Azure tenants dismantled.&lt;br/&gt;&lt;br/&gt;In brief - Fox Tempest ran an MSaaS platform enabling cybercriminals to sign malware via fraudulent Microsoft-issued certificates, facilitating ransomware attacks across healthcare, education, and government sectors. Microsoft’s DCU disrupted the operation, revoking certificates and seizing infrastructure.&lt;br/&gt;&lt;br/&gt;Technically - Fox Tempest exploited Microsoft Artifact Signing to generate short-lived code-signing certificates, distributing them via signspace[.]cloud and later pre-configured Cloudzy VMs. Customers (including Vanilla Tempest, Storm-0501) used signed payloads in malvertising/SEO poisoning campaigns, deploying Rhysida ransomware and Lumma Stealer. Mitigations include Microsoft Defender’s cloud protection, Safe Links, and tamper protection.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/&#34;&gt;https://www.microsoft.com/en-us/security/blog/2026/05/19/exposing-fox-tempest-a-malware-signing-service-operation/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-19T18:09:33&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsp0z3kzmr7pa0lh68k7lzjcm3t08x30zy5nxp9uljts25a5y076zszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5j43zmsr</id>
    
      <title type="html">(sucuri.net) Effective Triage and Response Strategies for Data ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsp0z3kzmr7pa0lh68k7lzjcm3t08x30zy5nxp9uljts25a5y076zszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5j43zmsr" />
    <content type="html">
      (sucuri.net) Effective Triage and Response Strategies for Data Breaches: Protecting Credentials and Securing Websites&lt;br/&gt;&lt;br/&gt;Credential exposure in data breaches demands immediate, structured response—credential stuffing and session hijacking risks escalate rapidly.&lt;br/&gt;&lt;br/&gt;In brief - Breach notifications require tailored triage: verify legitimacy, assess credential blast radius, rotate secrets, enforce phishing-resistant MFA, and audit admin access. Personal data exposure risks SIM-swap and identity theft; proactive measures like credit freezes mitigate fallout.&lt;br/&gt;&lt;br/&gt;Technically - Cross-reference breach alerts with Have I Been Pwned or state portals to avoid phishing lures. For compromised credentials, map reuse across CMS (e.g., WordPress), hosting panels, and repos. Rotate passwords, regenerate session-binding secrets (e.g., WordPress salts), and invalidate active sessions. Enable MFA with hardware keys or passkeys. For web assets, scan for malware (e.g., SocGholish), audit hidden admin accounts, and review access logs for anomalies. Implement WAFs and file integrity checks to counter automated attacks targeting endpoints like /wp-admin.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://blog.sucuri.net/2026/05/what-to-do-when-a-third-party-data-breach-puts-your-website-at-risk.html&#34;&gt;https://blog.sucuri.net/2026/05/what-to-do-when-a-third-party-data-breach-puts-your-website-at-risk.html&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-18T23:11:45&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsxpdmhqt85dsyjhd7htd20xkx8n7py0g9mcauypt5utea6gzvth9czyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jr28zya</id>
    
      <title type="html">(hiddenlayer.com) AI-Powered Code Assistants as Vectors for ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsxpdmhqt85dsyjhd7htd20xkx8n7py0g9mcauypt5utea6gzvth9czyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jr28zya" />
    <content type="html">
      (hiddenlayer.com) AI-Powered Code Assistants as Vectors for Self-Propagating Prompt Injection Attacks: The CopyPasta License Threat&lt;br/&gt;&lt;br/&gt;New AI-powered code assistants like Cursor are being exploited via the CopyPasta License Attack—a self-propagating prompt injection technique that embeds malicious instructions in software licenses. Threat actors use hidden markdown comments and adversarial prompt engineering (HL03.04, HL03.09) to trick AI models into spreading payloads across codebases, risking backdoors, data exfiltration, or resource abuse.&lt;br/&gt;&lt;br/&gt;In brief - AI coding tools are vulnerable to a novel attack vector where malicious instructions disguised as licenses propagate automatically, compromising development environments and supply chains.&lt;br/&gt;&lt;br/&gt;Technically - The CopyPasta License Attack leverages Imperative Emphasis and Syntax-Based Input manipulation in README files to hijack AI assistants (Cursor, Windsurf, Kiro, Aider). Infected templates force the AI to insert payloads into generated code, evading detection via obfuscation. This builds on Morris II AI worm concepts but targets code generation agents with higher practical impact.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://www.hiddenlayer.com/research/prompts-gone-viral-practical-code-assistant-ai-viruses&#34;&gt;https://www.hiddenlayer.com/research/prompts-gone-viral-practical-code-assistant-ai-viruses&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-10T16:01:35&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqstkgvdx68jaj9kyzyu4f4fnh0cxs9jka7k6nx6psrqgaq33xnrz4czyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jl8qsfk</id>
    
      <title type="html">(calif.io) CVE-2026-7270: Root Privilege Escalation in FreeBSD ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqstkgvdx68jaj9kyzyu4f4fnh0cxs9jka7k6nx6psrqgaq33xnrz4czyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jl8qsfk" />
    <content type="html">
      (calif.io) CVE-2026-7270: Root Privilege Escalation in FreeBSD via Kernel Memory Corruption in execve()&lt;br/&gt;&lt;br/&gt;New critical LPE in FreeBSD: CVE-2026-7270 enables root access via a one-character error in `execve()` kernel handling. Exploit targets `sshd-session` with `LD_PRELOAD` injection through a race condition.&lt;br/&gt;&lt;br/&gt;In brief - CVE-2026-7270 is a local privilege escalation flaw in FreeBSD (since 2013) caused by a sign error in `execve()` memory handling. Attackers can corrupt kernel memory during shebang script execution, inject `LD_PRELOAD`, and gain root via `sshd-session`. Affects default installations.&lt;br/&gt;&lt;br/&gt;Technically - The bug in `sys/kern/kern_exec.c` (`exec_args_adjust_args`) miscalculates `memmove` size (`&#43; consume` instead of `- consume`), causing a 2,024-byte overflow into an adjacent `exec_map` entry. Exploit preseeds kernel memory at offset 265,166 bytes to replace `sshd-session` environment with `LD_PRELOAD=/tmp/evil.so`. Race condition optimized via fragmented argument strings to slow `execve` calls. Challenges include avoiding `MADV_FREE` under memory pressure and a 3.1% panic risk. PoC achieves root in seconds.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://blog.calif.io/p/cve-2026-7270-how-i-get-root-on-freebsd&#34;&gt;https://blog.calif.io/p/cve-2026-7270-how-i-get-root-on-freebsd&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-05-07T21:27:57&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs89fe8xjk4uey0ggkv9lp8560lw9tm33ra2lk62j3vz9ace6lgkyqzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jftwzgc</id>
    
      <title type="html">(akamai.com) Active Exploitation of D-Link DIR-823X Command ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs89fe8xjk4uey0ggkv9lp8560lw9tm33ra2lk62j3vz9ace6lgkyqzyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5jftwzgc" />
    <content type="html">
      (akamai.com) Active Exploitation of D-Link DIR-823X Command Injection Vulnerability Deploys Mirai Botnet Variant&lt;br/&gt;&lt;br/&gt;Active exploitation of CVE-2025-29635 (command injection in D-Link DIR-823X routers) detected, deploying Mirai variant &amp;#39;tuxnokill.&amp;#39;&lt;br/&gt;&lt;br/&gt;In brief - Threat actors are exploiting a critical command injection flaw in end-of-life D-Link DIR-823X routers to deploy the &amp;#39;tuxnokill&amp;#39; Mirai botnet variant. Organizations should retire vulnerable devices or apply patches immediately.&lt;br/&gt;&lt;br/&gt;Technically - CVE-2025-29635 affects D-Link DIR-823X firmware versions 240126/24082, enabling unauthenticated RCE via crafted POST requests to /goform/set_prohibiting (macaddr parameter). The &amp;#39;tuxnokill&amp;#39; Mirai variant uses XOR encoding (key 0x30), targets multiple architectures, and communicates with C2 64.89.161.130:44300. Hard-coded strings include &amp;#39;AI.NEEDS.TO.DIE&amp;#39; and &amp;#39;segmentation fault (core dumped).&amp;#39; IOCs: downloader IP 88.214.20.14, five SHA256 hashes, and Snort/YARA rules available.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devices&#34;&gt;https://www.akamai.com/blog/security-research/2026/apr/cve-2025-29635-mirai-campaign-targets-d-link-devices&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity #ThreatIntel
    </content>
    <updated>2026-04-21T21:07:03&#43;02:00</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqs0c7f5j3zma7yfxdxk5s0taqttv4lyjjykjjj4klwhvvd7l3xzqtszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5j3vrj3g</id>
    
      <title type="html">(zsec.uk) Autonomous LLM-Driven Vulnerability Hunting at Scale: ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqs0c7f5j3zma7yfxdxk5s0taqttv4lyjjykjjj4klwhvvd7l3xzqtszyzzll3vldehd89n32ddgkh585nnm9lv6znvv9ysqajs0j5nwrpq5j3vrj3g" />
    <content type="html">
      (zsec.uk) Autonomous LLM-Driven Vulnerability Hunting at Scale: Architecture, Methodology, and Discovered Zero-Days&lt;br/&gt;&lt;br/&gt;New research details an autonomous LLM-driven vulnerability hunting system using Claude Code and Model Context Protocol (MCP), uncovering multiple zero-days including critical Go standard library flaws and a four-stage OEM exploit chain.&lt;br/&gt;&lt;br/&gt;In brief - A security researcher built an end-to-end autonomous system integrating 300&#43; tools across five VMs, discovering confirmed CVEs (CVE-2026-33809, CVE-2026-33812) and a complex OEM service exploit chain achieving SYSTEM execution. The system eliminates false positives through a rigorous multi-gate validation pipeline.&lt;br/&gt;&lt;br/&gt;Technically - The architecture leverages FastMCP-based Python servers for SSH/WinRM, Proxmox VM orchestration, Ghidra/radare2/Frida RE, grammar-based fuzzing (WinAFL, Jackalope, DynamoRIO), and FAISS-backed RAG. Key findings: CVE-2026-33809 (Go TIFF parsing OOM via unchecked IFD offset), CVE-2026-33812 (Go SFNT font parsing OOM via unchecked uint16 class count), and an OEM exploit chain combining WCF named pipe auth bypass, SSRF, catalog injection, and BYOVD for SYSTEM execution. Validation requires PoC compilation, clean-VM crash reproduction, and exploitability confirmation.&lt;br/&gt;&lt;br/&gt;Source: &lt;a href=&#34;https://blog.zsec.uk/bullyingllms/&#34;&gt;https://blog.zsec.uk/bullyingllms/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#Cybersecurity
    </content>
    <updated>2026-04-04T14:13:40&#43;02:00</updated>
  </entry>

</feed>