DEV Community

Anoymask profile picture

Anoymask

404 bio not found

Joined Joined on  twitter website
Fortra BoKS: Predictable AD Passwords, Root Command Injection, and Pre-Authentication Memory Corruption

Fortra BoKS: Predictable AD Passwords, Root Command Injection, and Pre-Authentication Memory Corruption

1
Comments
12 min read

Want to connect with Anoymask?

Create an account to connect with Anoymask. You can also sign in below to proceed if you already have an account.

Already have an account? Sign in
DTU Breach: IAM Data Theft May Affect Up to 200,000 People

DTU Breach: IAM Data Theft May Affect Up to 200,000 People

1
Comments
8 min read
CloudSyncD: Fake Zoom Installer Hides a Stolen Password with Zero-Width Unicode and Launches a macOS Backdoor

CloudSyncD: Fake Zoom Installer Hides a Stolen Password with Zero-Width Unicode and Launches a macOS Backdoor

2
Comments
8 min read
GitLab AI Gateway CVE-2026-90970: Authenticated Command Execution via Prompt Template Sandbox Escape

GitLab AI Gateway CVE-2026-90970: Authenticated Command Execution via Prompt Template Sandbox Escape

1
Comments
6 min read
Dell CSM: Critical Flaws Enable Storage Admin Access and Kubernetes Privilege Escalation

Dell CSM: Critical Flaws Enable Storage Admin Access and Kubernetes Privilege Escalation

1
Comments
8 min read
FortiMail CVE-2026-104286: Path Traversal and NULL Byte Flaw Exploited for Arbitrary File Writes

FortiMail CVE-2026-104286: Path Traversal and NULL Byte Flaw Exploited for Arbitrary File Writes

1
Comments
8 min read
SConnect CVE-2026-18397: Heap Spraying Bypasses Signature Verification for Drive-by RCE

SConnect CVE-2026-18397: Heap Spraying Bypasses Signature Verification for Drive-by RCE

1
Comments
8 min read
Warlock: Ransomware Deployment from SYSVOL After SharePoint Compromise

Warlock: Ransomware Deployment from SYSVOL After SharePoint Compromise

2
Comments
9 min read
TA419 Targets AI Policy Experts with BitB and Evilginx AiTM Phishing

TA419 Targets AI Policy Experts with BitB and Evilginx AiTM Phishing

1
Comments
7 min read
Kiteworks EPG CVE-2026-54154: Pre-Auth RCE with Potential Root Escalation

Kiteworks EPG CVE-2026-54154: Pre-Auth RCE with Potential Root Escalation

1
Comments
7 min read
September 2026 Security Review: Attacks Following Legitimate Features and AI Execution Capabilities

September 2026 Security Review: Attacks Following Legitimate Features and AI Execution Capabilities

1
Comments
6 min read
GTIG: Vulnerability Trends in the AI Era and AI Infrastructure Attack Surfaces

GTIG: Vulnerability Trends in the AI Era and AI Infrastructure Attack Surfaces

2
Comments
5 min read
Cisco Catalyst SD-WAN Manager CVE-2026-76504: URI Encoding Bypasses Authentication for Admin API Access

Cisco Catalyst SD-WAN Manager CVE-2026-76504: URI Encoding Bypasses Authentication for Admin API Access

1
Comments
6 min read
Two Zammad Zero-Days: DIVD Reports Session Compromise, Root Access, and Data Theft

Two Zammad Zero-Days: DIVD Reports Session Compromise, Root Access, and Data Theft

1
Comments
8 min read
Truffle Security: Over 540,000 Valid Credentials Confirmed in Public GitHub Repositories

Truffle Security: Over 540,000 Valid Credentials Confirmed in Public GitHub Repositories

1
Comments
5 min read
Storm-3068: Account Takeover via SSPR Leads to Kubernetes Credential Theft Through Azure DevOps

Storm-3068: Account Takeover via SSPR Leads to Kubernetes Credential Theft Through Azure DevOps

1
Comments
9 min read
Star Blizzard: RedFlick Uses Scheduled Tasks to Deploy CosmicPulse

Star Blizzard: RedFlick Uses Scheduled Tasks to Deploy CosmicPulse

1
Comments
9 min read
Apple CoreGraphics CVE-2026-86950: Arbitrary Code Execution via Crafted File Processing, with Exploitation Reported

Apple CoreGraphics CVE-2026-86950: Arbitrary Code Execution via Crafted File Processing, with Exploitation Reported

1
Comments
8 min read
Supabase Misconfiguration: Readable Tables in 16,326 Databases, Sensitive Data Confirmed in Some Cases

Supabase Misconfiguration: Readable Tables in 16,326 Databases, Sensitive Data Confirmed in Some Cases

2
Comments
9 min read
Storm-3168 (JADEPUFFER): Azure Resources Mass-Deleted in Seven Minutes Using Compromised Service Principals

Storm-3168 (JADEPUFFER): Azure Resources Mass-Deleted in Seven Minutes Using Compromised Service Principals

1
Comments
9 min read
Kiteworks Advanced Forms: Precautionary Shutdown Following Critical Vulnerability and Conditional Resumption

Kiteworks Advanced Forms: Precautionary Shutdown Following Critical Vulnerability and Conditional Resumption

1
Comments
8 min read
Bitget: $387.5M Stolen via Wallet Backend Compromise and Transaction Data Tampering

Bitget: $387.5M Stolen via Wallet Backend Compromise and Transaction Data Tampering

2
Comments
10 min read
SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites Allowing Anonymous Access

SharePoint CVE-2026-65660: Two-Stage Web Shell Deployment Attempts on Sites Allowing Anonymous Access

1
Comments 3
9 min read
Cloudflare Containers: Vulnerability Allowing Reading of Residual Data from Other Tenants via Reused Blocks

Cloudflare Containers: Vulnerability Allowing Reading of Residual Data from Other Tenants via Reused Blocks

1
Comments 3
7 min read
Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Pre-Authentication RCE Zero-Days Under Active Exploitation

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772: Pre-Authentication RCE Zero-Days Under Active Exploitation

1
Comments 3
10 min read
Oracle PeopleSoft CVE-2026-35273: WAF Bypassed via URL Normalization Mismatch to Deploy Web Shells and SIDEEYE

Oracle PeopleSoft CVE-2026-35273: WAF Bypassed via URL Normalization Mismatch to Deploy Web Shells and SIDEEYE

1
Comments
11 min read
Mini Shai-Hulud Re-Exposure: Re-Enabled GitHub Action Repositories Trigger Malicious Code Execution in CI

Mini Shai-Hulud Re-Exposure: Re-Enabled GitHub Action Repositories Trigger Malicious Code Execution in CI

1
Comments
10 min read
Elementor 4.3.0 and 4.3.1: CSRF Enables Administrator Account Creation via a Flawed REST Route Check

Elementor 4.3.0 and 4.3.1: CSRF Enables Administrator Account Creation via a Flawed REST Route Check

3
Comments
5 min read
TDengine CVE-2026-42542: Unauthenticated Integer Underflow Crashes taosd with a Single Packet

TDengine CVE-2026-42542: Unauthenticated Integer Underflow Crashes taosd with a Single Packet

3
Comments
6 min read
File Change Notification Side Channel: Estimating Keystroke Timing and Browsing Activity on Linux, Android, and Windows

File Change Notification Side Channel: Estimating Keystroke Timing and Browsing Activity on Linux, Android, and Windows

2
Comments
7 min read
MemTensor MemOS Supply Chain Attack: sckit Triggered by Python Imports and OpenClaw Runtime Hooks

MemTensor MemOS Supply Chain Attack: sckit Triggered by Python Imports and OpenClaw Runtime Hooks

2
Comments
6 min read
SalesBleed: Zero-Click DNS Data Exfiltration from Agentforce Through Indirect Prompt Injection

SalesBleed: Zero-Click DNS Data Exfiltration from Agentforce Through Indirect Prompt Injection

1
Comments
5 min read
Exposed GitLab Incoming Email Tokens Allow Unauthorized Code Modifications and CI Execution

Exposed GitLab Incoming Email Tokens Allow Unauthorized Code Modifications and CI Execution

1
Comments 1
8 min read
Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

Roundcube CVE-2026-48842: Active Exploitation Reported for Pre-Authentication SQL Injection in virtuser_query

1
Comments
5 min read
SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

SolarWinds Observability Self-Hosted: Two Pre-Authentication RCE Vulnerabilities Fixed with Different Configuration Requirements

1
Comments
6 min read
CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

CARBONATO: A Botnet Built Around an AI Agent via Exposed Docker APIs

1
Comments
6 min read
Arista VeloCloud Orchestrator CVE-2026-93952: Active Exploitation of Authentication Bypass Zero-Day

Arista VeloCloud Orchestrator CVE-2026-93952: Active Exploitation of Authentication Bypass Zero-Day

1
Comments
6 min read
F5 BIG-IP APM CVE-2026-94127: Pre-authentication RCE Zero-Day Targeting OAuth Configurations

F5 BIG-IP APM CVE-2026-94127: Pre-authentication RCE Zero-Day Targeting OAuth Configurations

1
Comments
6 min read
Autonomous AI Agents Breach Online Retailers in Chained Attacks to Steal Payment Card Data

Autonomous AI Agents Breach Online Retailers in Chained Attacks to Steal Payment Card Data

1
Comments 2
8 min read
RemControl: Android Banking Trojan Uses AI-Assisted Overlays and a Local VPN

RemControl: Android Banking Trojan Uses AI-Assisted Overlays and a Local VPN

1
Comments
6 min read
WordPress CVE-2026-87902: Probing and PHP File-Write Attempts Observed on Patch Day

WordPress CVE-2026-87902: Probing and PHP File-Write Attempts Observed on Patch Day

1
Comments
7 min read
Check Point CVE-2026-93616: Actively Exploited Pre-Authentication Path Traversal Leading to Script Execution

Check Point CVE-2026-93616: Actively Exploited Pre-Authentication Path Traversal Leading to Script Execution

1
Comments
9 min read
BigDiskBuster: Public PoC Claims to Block Microsoft Defender Platform and Security Intelligence Updates

BigDiskBuster: Public PoC Claims to Block Microsoft Defender Platform and Security Intelligence Updates

1
Comments
8 min read
CLOSEDQUORUM: An Autonomous Windows Implant Using Multiple LLMs for Attack Decisions

CLOSEDQUORUM: An Autonomous Windows Implant Using Multiple LLMs for Attack Decisions

1
Comments
7 min read
D-Link DIR-822A: Pre-authentication DHCP Buffer Overflow and L2TP Out-of-Bounds Write

D-Link DIR-822A: Pre-authentication DHCP Buffer Overflow and L2TP Out-of-Bounds Write

1
Comments
6 min read
Kapibala: Government Data Theft via WordPress and Active Exploitation of Zyxel CVE-2026-7273

Kapibala: Government Data Theft via WordPress and Active Exploitation of Zyxel CVE-2026-7273

1
Comments
7 min read
EvilTokens: AI-Powered PhaaS Abusing Device Code Authentication to Compromise Over 12,000 Mailboxes

EvilTokens: AI-Powered PhaaS Abusing Device Code Authentication to Compromise Over 12,000 Mailboxes

1
Comments
7 min read
LLM Relay Infrastructure: Over 80,000 Nodes Obscure User Attribution and Regional Controls

LLM Relay Infrastructure: Over 80,000 Nodes Obscure User Attribution and Regional Controls

1
Comments
7 min read
TrustSink: Password Theft via a Rogue External MFA Provider in Microsoft Entra ID

TrustSink: Password Theft via a Rogue External MFA Provider in Microsoft Entra ID

1
Comments
6 min read
Colorado Small Water Utility OT Breaches: Attackers Alter Settings, Disable Alarms, and Change Pumping Cycles

Colorado Small Water Utility OT Breaches: Attackers Alter Settings, Disable Alarms, and Change Pumping Cycles

1
Comments
5 min read
BigCommerce Third-Party App Compromise: Malicious Script Injected into Storefronts via Ribon Credentials

BigCommerce Third-Party App Compromise: Malicious Script Injected into Storefronts via Ribon Credentials

1
Comments
5 min read
Three Linux Kernel Vulnerabilities Added to CISA KEV: Active Exploitation Reported in AF_ALG, ebtables, and kTLS

Three Linux Kernel Vulnerabilities Added to CISA KEV: Active Exploitation Reported in AF_ALG, ebtables, and kTLS

1
Comments
6 min read
CrowdSec Source Code Leak: GitHub OAuth Token Abused in TanStack Supply Chain Attack

CrowdSec Source Code Leak: GitHub OAuth Token Abused in TanStack Supply Chain Attack

1
Comments
7 min read
Click2Shell: One-Click Chain from Automatic WordPress Theme Installation to PHP Execution

Click2Shell: One-Click Chain from Automatic WordPress Theme Installation to PHP Execution

1
Comments
6 min read
Gemini Accessed Three Real Companies During a Security Evaluation via Password Guessing and Publicly Exposed Credentials

Gemini Accessed Three Real Companies During a Security Evaluation via Password Guessing and Publicly Exposed Credentials

1
Comments
6 min read
Overpatch and Heapjack: Two Techniques for Bypassing Codex's Write Restrictions and Escaping Its Read-Only Sandbox

Overpatch and Heapjack: Two Techniques for Bypassing Codex's Write Restrictions and Escaping Its Read-Only Sandbox

2
Comments
9 min read
indexed-btree: npm Supply Chain Malware Executes at Runtime and Uses a Smart Contract on Ethereum Sepolia for C2

indexed-btree: npm Supply Chain Malware Executes at Runtime and Uses a Smart Contract on Ethereum Sepolia for C2

1
Comments
8 min read
ShinyHunters Hacks Clop Leak Site: Claims an Unauthenticated File Upload Led to Tor Private Key Theft

ShinyHunters Hacks Clop Leak Site: Claims an Unauthenticated File Upload Led to Tor Private Key Theft

1
Comments
6 min read
Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

Rapuncel: Fake GitHub Repositories Disable EDR with a Signed Kernel Driver

1
Comments
5 min read
Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

Reaching an Internal OpenAI Repository Through an HEIF RCE and Overprivileged SSO Token Chain

1
Comments
5 min read
loading...