<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Hacker Posts — Blog</title>
    <link>https://www.hackerposts.org/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Mon, 08 Jun 2026 06:11:37 GMT</lastBuildDate>
    <atom:link href="https://www.hackerposts.org/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>CISA adds SolarWinds Serv-U CVE-2026-28318 to KEV, DoS in the wild</title>
      <link>https://www.hackerposts.org/en/blog/solarwinds-serv-u-cve-2026-28318-kev-dos</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/solarwinds-serv-u-cve-2026-28318-kev-dos</guid>
      <description>CISA added CVE-2026-28318 — an unauthenticated DoS in SolarWinds Serv-U — to KEV on June 5. CVSS 7.5. Fix is 15.5.4 Hotfix 1. FCEB deadline June 19.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Anthropic patches Claude Code GitHub Action repo-takeover chain</title>
      <link>https://www.hackerposts.org/en/blog/claude-code-github-action-prompt-injection-supply-chain</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/claude-code-github-action-prompt-injection-supply-chain</guid>
      <description>GMO Flatt Security&apos;s RyotaK chained a checkWritePermissions bot bypass with prompt injection to hijack any public repo running claude-code-action. Fix shipped in v1.0.94.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Sun, 07 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Cisco SD-WAN Manager CVE-2026-20245 exploited, no patch yet</title>
      <link>https://www.hackerposts.org/en/blog/cisco-sd-wan-manager-cve-2026-20245-zero-day</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/cisco-sd-wan-manager-cve-2026-20245-zero-day</guid>
      <description>Cisco disclosed a command-injection zero-day in Catalyst SD-WAN Manager on June 5. Mandiant credited as reporter. CVSS 7.8, exploitation observed, no fix available.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>VS Code github.dev zero-day exposed full GitHub OAuth tokens in one click</title>
      <link>https://www.hackerposts.org/en/blog/vscode-github-dev-oauth-token-zero-day</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/vscode-github-dev-oauth-token-zero-day</guid>
      <description>Researcher Ammar Askar dropped a webview-postMessage exploit on June 2 that steals github.dev OAuth tokens via a single click. Microsoft shipped a stopgap fix the next day.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CISA adds Oracle WebLogic CVE-2024-21182 to KEV catalog</title>
      <link>https://www.hackerposts.org/en/blog/oracle-weblogic-cve-2024-21182-cisa-kev</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/oracle-weblogic-cve-2024-21182-cisa-kev</guid>
      <description>CISA added the two-year-old Oracle WebLogic auth-bypass CVE-2024-21182 to KEV on June 1, citing active exploitation. Federal agencies have until June 4 to patch.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Fri, 05 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Android Framework zero-day CVE-2025-48595 added to CISA KEV</title>
      <link>https://www.hackerposts.org/en/blog/android-cve-2025-48595-framework-zero-day-kev</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/android-cve-2025-48595-framework-zero-day-kev</guid>
      <description>Google&apos;s June 2026 Android Security Bulletin fixes 124 flaws, including a Framework integer overflow under limited, targeted exploitation. CISA wants federal agencies patched by 5 June.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>HTTP/2 Bomb (CVE-2026-49975) drops nginx, Apache, IIS, Envoy</title>
      <link>https://www.hackerposts.org/en/blog/http2-bomb-cve-2026-49975-nginx-apache-dos</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/http2-bomb-cve-2026-49975-nginx-apache-dos</guid>
      <description>Calif researchers crash 32 GB of Envoy memory in seconds with one connection. nginx 1.29.8 and Apache mod_http2 2.0.41 are patched; IIS, Envoy and Cloudflare Pingora are not.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Thu, 04 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Red Hat npm packages backdoored: Miasma worm hits @redhat-cloud-services</title>
      <link>https://www.hackerposts.org/en/blog/redhat-npm-miasma-supply-chain-rhsb-2026-006</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/redhat-npm-miasma-supply-chain-rhsb-2026-006</guid>
      <description>Red Hat security bulletin RHSB-2026-006 confirms 32 @redhat-cloud-services npm packages were trojaned on June 1, 2026 with a self-spreading credential-stealing worm derived from Shai-Hulud.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Wed, 03 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Windows Netlogon RCE CVE-2026-41089 now exploited in the wild</title>
      <link>https://www.hackerposts.org/en/blog/windows-netlogon-cve-2026-41089-active-exploitation</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/windows-netlogon-cve-2026-41089-active-exploitation</guid>
      <description>Belgium&apos;s CCB confirms active exploitation of the CVSS 9.8 Netlogon stack-overflow patched by Microsoft in May. Unauthenticated, no user interaction, domain controller takeover.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CIFSwitch: 19-year-old Linux CIFS bug gives any local user root</title>
      <link>https://www.hackerposts.org/en/blog/cifswitch-linux-cifs-spnego-local-root</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/cifswitch-linux-cifs-spnego-local-root</guid>
      <description>Researcher Asim Manizada disclosed CIFSwitch on May 28 — a cifs.spnego upcall flaw that grants root on default Mint, Rocky, AlmaLinux, Kali, and SUSE 15 SP7.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Marimo CVE-2026-39987 RCE chains into LLM-driven post-exploit</title>
      <link>https://www.hackerposts.org/en/blog/marimo-cve-2026-39987-llm-agent-post-exploit</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/marimo-cve-2026-39987-llm-agent-post-exploit</guid>
      <description>Sysdig documents an LLM agent driving post-exploitation after a CVE-2026-39987 Marimo notebook compromise: cloud creds and SSH key pulled in under three minutes.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>npm supply-chain campaign: 14 typosquats target AWS, Vault, npm tokens</title>
      <link>https://www.hackerposts.org/en/blog/npm-vpmdhaj-14-typosquats-cloud-secrets</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/npm-vpmdhaj-14-typosquats-cloud-secrets</guid>
      <description>Microsoft says a single maintainer &apos;vpmdhaj&apos; pushed 14 typosquatted npm packages on May 28 that exfiltrate AWS, ECS, HashiCorp Vault and npm tokens via a Bun-runtime payload.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Palo Alto GlobalProtect auth bypass (CVE-2026-0257) added to CISA KEV after weeks of exploitation</title>
      <link>https://www.hackerposts.org/en/blog/palo-alto-globalprotect-cve-2026-0257-auth-bypass</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/palo-alto-globalprotect-cve-2026-0257-auth-bypass</guid>
      <description>PAN-OS portals with authentication-override cookies on a shared certificate let attackers forge a valid session. Rapid7 observed exploitation since May 17. Federal patch deadline June 19.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Sun, 31 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>FortiClient EMS bug CVE-2026-35616 now drops EKZ stealer as fake patch</title>
      <link>https://www.hackerposts.org/en/blog/forticlient-ems-cve-2026-35616-ekz-stealer</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/forticlient-ems-cve-2026-35616-ekz-stealer</guid>
      <description>Arctic Wolf says attackers are using the pre-auth FortiClient EMS flaw to push a previously undocumented infostealer disguised as a Fortinet endpoint update.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Sat, 30 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CISA links GitHub repo exfiltration to malicious Nx Console 18.95.0</title>
      <link>https://www.hackerposts.org/en/blog/cisa-nx-console-cve-2026-48027-github-breach</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/cisa-nx-console-cve-2026-48027-github-breach</guid>
      <description>CISA&apos;s May 28 alert ties the 3,800-repo GitHub breach to a poisoned Nx Console VS Code extension. CVE-2026-48027 is in KEV. Federal deadline June 10.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Gitea CVE-2026-27771: anyone could pull your private container images, no login</title>
      <link>https://www.hackerposts.org/en/blog/gitea-cve-2026-27771-private-images</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/gitea-cve-2026-27771-private-images</guid>
      <description>An access-control flaw in Gitea&apos;s container registry let anonymous clients pull images marked private. Patched in 1.26.2. Forgejo affected too.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Starlette BadHost (CVE-2026-48710): one Host header bypasses auth in FastAPI, vLLM, MCP</title>
      <link>https://www.hackerposts.org/en/blog/starlette-cve-2026-48710-badhost</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/starlette-cve-2026-48710-badhost</guid>
      <description>X41 D-Sec discloses CVE-2026-48710 in Starlette &lt;1.0.1: a Host-header re-parse desync that lets attackers forge request.url.path. Upgrade to 1.0.1.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>KnowledgeDeliver CVE-2026-5426: Mandiant traces RCE to shared ASP.NET keys</title>
      <link>https://www.hackerposts.org/en/blog/knowledgedeliver-cve-2026-5426-viewstate-rce</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/knowledgedeliver-cve-2026-5426-viewstate-rce</guid>
      <description>Mandiant traces a zero-day in Japan&apos;s KnowledgeDeliver LMS to ASP.NET machineKey values reused across customers — enabling unauthenticated ViewState RCE and BLUEBEAM web-shell drops.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>CISA flags Langflow CVE-2025-34291: CORS chain yields RCE</title>
      <link>https://www.hackerposts.org/en/blog/langflow-cve-2025-34291-cisa-kev-rce</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/langflow-cve-2025-34291-cisa-kev-rce</guid>
      <description>CISA added CVE-2025-34291 to the KEV catalog on May 21. An overly permissive CORS plus a misconfigured refresh-token cookie chain to account takeover and code execution in Langflow ≤ 1.6.9.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Ghost CMS SQLi (CVE-2026-26980) hijacks 700+ sites — Harvard, Oxford, DuckDuckGo serve ClickFix</title>
      <link>https://www.hackerposts.org/en/blog/ghost-cms-cve-2026-26980-clickfix-campaign</link>
      <guid isPermaLink="true">https://www.hackerposts.org/en/blog/ghost-cms-cve-2026-26980-clickfix-campaign</guid>
      <description>An unauthenticated SQL injection in Ghost&apos;s Content API leaks admin API keys. Attackers chain it into stored XSS and a fake Cloudflare ClickFix lure. Upgrade to 6.19.1.</description>
      <author>Hacker Posts Desk</author>
      <pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>