tech-insider.org
Resources curated from this publisher and indexed across appsec.fyi topic pages. Last item added: 2026-07-24.
| Date Added | Resource | Excerpt |
|---|---|---|
| 2026-07-24 2026 | Splunk Zero-Day CVE-2026-20253: CVSS 9.8 CISA KEV [2026]RCE | Splunk has a critical zero-day vulnerability, CVE-2026-20253, with a CVSS score of 9.8, making it highly severe. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog for 2026, indicating active exploitation. Users are strongly advised to update their Splunk instances immediately to mitigate the risk of exploitation. No bug bounty payout amount is mentioned in the provided content. |
| 2026-07-16 2026 | Windows Netlogon Flaw CVE-2026-41089: CVSS 9.8 [2026]RCE | Writeup of CVE-2026-41089, a critical Windows Netlogon flaw, details a stack-based buffer overflow in the MS-NRPC protocol. This vulnerability, rated CVSS 9.8, allows unauthenticated remote attackers to execute arbitrary code with SYSTEM privileges on domain controllers. Researchers flagged it as wormable due to its lack of authentication requirements, network reachability prerequisite, and direct SYSTEM-level code execution, drawing comparisons to the 2020 Zerologon attack. Active exploitation was confirmed weeks after Microsoft's May 12, 2026, patch release. |
| 2026-07-07 2026 | SharePoint Vulnerability CVE-2026-45659 Exploited [2026]RCE | Writeup of CVE-2026-45659, a SharePoint RCE vulnerability, details how a flaw initially assessed as "less likely to be exploited" by Microsoft became a federally mandated fix by CISA within weeks. The deserialization bug requires only "Site Member" privileges and low complexity, making authenticated access a potent attack vector. This "n-day" exploit highlights the danger of unpatched on-premises SharePoint servers, impacting sectors like government and finance, and underscores the urgency of CISA's Known Exploited Vulnerabilities catalog. |
| 2026-07-06 2026 | npm Supply Chain Attack: North Korea Hits Mastra AI [2026]Supply Chain | Analysis of the @mastra npm supply chain attack reveals North Korea's Sapphire Sleet (BlueNoroff, APT38) compromised over 140 packages via a stolen maintainer account. The attackers leveraged a typosquatted dependency, `easy-day-js`, within a `postinstall` script to inject malware. This implant disabled TLS verification, contacted C2 infrastructure, deployed a persistent implant, and targeted cryptocurrency wallets like MetaMask, Phantom, and Coinbase Wallet, along with cloud credentials, demonstrating a significant maturation in nation-state-sponsored open-source malware campaigns. |
| 2026-06-01 2026 | Mercor Hit: 4TB Stolen via LiteLLM (95M Downloads) [2026]Supply Chain | Library providing a unified interface to over 100 LLM providers, LiteLLM was compromised, leading to a 4TB data exfiltration from Mercor. The attack chain involved compromising Trivy, injecting malicious code into LiteLLM, and exfiltrating credentials from downstream environments. This incident highlights the risks of fast-moving open-source projects in AI infrastructure and the critical importance of pinned dependencies to prevent supply-chain attacks. |