Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Suriq - Always on Watch

@suriq@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Practitioner cybersecurity analysis from the Suriq desk.
What to patch, what to detect, and why it matters, in plain English.

Managed security built on Wazuh. suriq.io

#Cyber #ThreatDetection #CVE #CISA #Cybersecurity

9 Followers
8 Following
50 Posts
Joined June 18, 2026
Suriq - Always on Watch:
https://suriq.io
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1w ago
Our desk triaged 4,609 vulnerabilities this week and published 8. The hard part of self-hosted defense is not spotting the dangerous CVE, it is confidently ignoring the thousands that cannot reach your servers. https://suriq.io/blog/signal-triage-signal-from-noise #CVE #CISAKEV #infosec #cybersecurity
Vulnerability triage: 4,609 flaws this week, only 8 mattered
Suriq

Vulnerability triage: 4,609 flaws this week, only 8 mattered

We triaged 4,609 vulnerabilities in a week and acted on 8. Why reachability and in-the-wild exploitation, not CVSS, decide what a self-hosted team should patch.

1
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

⚠️ PATCH NOW

Microsoft Exchange has an auth-bypass flaw (CVE-2026-62911) that relays a server's own account into a webshell running as SYSTEM.

A public exploit just dropped, and 21,899 servers are still exposed.

Patch, then turn on Extended Protection.

https://suriq.io/blog/exchange-cve-2026-62911-auth-bypass-webshell-poc

#CVE #Windows #infosec #cybersecurity

Exchange CVE-2026-62911: auth-bypass RCE, PoC is out
Suriq

Exchange CVE-2026-62911: auth-bypass RCE, PoC is out

CVE-2026-62911 lets attackers relay an Exchange server

8
0
9
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

Chrome's V8 engine has its sixth zero-day of 2026 (CVE-2026-85046), exploited in the wild.

Chrome 152.0.7977.82 is only half the job. Edge, Brave, Opera and Electron apps run the same engine and patch separately.

https://suriq.io/blog/chrome-v8-cve-2026-85046-exploited

#CVE #Detection #CISAKEV #infosec

suriq.io
1
0
1
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

WP Fastest Cache, a WordPress plugin on 1M+ sites, has a flaw that lets a stranger poison your cached pages and serve malicious code to every visitor.

Fix: update to 1.5.1 and clear your page cache.

A public exploit is due Sept 9. (CVE-2026-74916)

https://suriq.io/blog/wp-fastest-cache-cache-poisoning-cve-2026-74916

#CVE #infosec #cybersecurity

suriq.io
1
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

The Manchester Airports breach did not need a hacked server. An extortion group says it read a marketing API key straight out of the site's JavaScript and exported customer data. Your EDR would never see it.

https://suriq.io/blog/manchester-airports-client-side-api-key-breach

#DataBreach #infosec #cybersecurity

suriq.io
1
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to take over defense and aerospace PCs.

Patched Aug 11, but exploited in the wild first; a kernel rootkit blinded security tools.

Run Windows? Update now and hunt.

https://suriq.io/blog/lazarus-operation-dream-job-windows-zero-day

#CVE #Windows #infosec #cybersecurity

suriq.io
1
0
2
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it leaked to a private repo.

It is marked compromised, so past signatures no longer verify.

Verify by hand or ship Mozilla RPMs? Import the new key.

https://suriq.io/blog/mozilla-firefox-thunderbird-signing-key-revoked

#SupplyChain #DataBreach #Linux #infosec

suriq.io
1
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🚨 BREAKING

Attackers did not breach Steam, ING or bol. They breached the shipping partner all three share, Ceva Logistics.

Customer names, addresses and order details across Europe are exposed. No passwords taken, but expect phishing that quotes your real orders.

https://suriq.io/blog/ceva-logistics-breach-customer-data-exposed

#SupplyChain #DataBreach #Phishing #infosec

suriq.io
1
0
3
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

macOS Screen Sharing has an auth bypass (CVE-2026-65400) that gives a network attacker root with no password.

Apple patched it Aug 6; exposed Macs are already being hit to mine Monero.

Update now, or turn Screen Sharing off.

https://suriq.io/blog/macos-screen-sharing-cve-2026-65400

#CVE #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2mo ago
NatJack lets someone who controls one host behind a shared NAT hijack a neighbor's live TCP session and spoof its DNS. Two CVEs, in Windows NAT and the Linux kernel. Patch both, then stop trusting east-west traffic. https://suriq.io/blog/natjack-shared-nat-session-hijack #CVE #Linux #infosec #cybersecurity
NatJack: a shared-NAT neighbor can seize sessions, forge DNS
Suriq

NatJack: a shared-NAT neighbor can seize sessions, forge DNS

NatJack lets an attacker behind the same NAT hijack live TCP sessions, spoof DNS, and exhaust connection tables. Two CVEs: patch Windows and Linux now.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
⚠️ PATCH NOW Commvault patched a critical flaw (CVSS 9.2) in CommServe, the brain of its backup platform: an allowlist bypass lets blocked commands run. Affects versions 11.36 to 11.46 on Linux and Windows. Fix: update to the patched release now. (CVE-2026-13737) https://suriq.io/blog/commvault-commserve-command-restriction-bypass #Ransomware #CVE #infosec #cybersecurity
Commvault CommServe command bypass flaw (CVSS 9.2)
Suriq

Commvault CommServe command bypass flaw (CVSS 9.2)

Commvault patched CVE-2026-13737, a critical CVSS 9.2 allowlist bypass in CommServe that lets attackers run commands the backup control server should block.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

Gunra ransomware beat multi-factor authentication without phishing anyone. It rewrote a company's login server so one attacker-chosen code always passed.

MFA stayed on; every login looked clean.

It gets in via unpatched Fortinet flaws. Patching won't evict it.

https://suriq.io/blog/gunra-ransomware-mfa-auth-backdoor

#Ransomware #CVE #Detection #infosec

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 3w ago
🔴 EXPLOITED CVE-2025-25249: A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthorized code execution via crafted packets. It is listed in CISA KEV. Affected: FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 and 7.2 branches. Fix: upgrade to the patched releases. CISA due date September 12, 2026. https://www.cve.org/CVERecord?id=CVE-2025-25249 #CISAKEV #infosec #cybersecurity
cve.org
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

LiteLLM, the open-source gateway fronting your LLM providers, has an auth bypass (CVE-2026-59822) CISA confirms is exploited.

Attackers reach its MCP tools and steal the provider keys it stores.

Fix: update to 1.84.0 and rotate keys.

https://suriq.io/blog/litellm-cve-2026-59822-mcp-auth-bypass

#CVE #CISAKEV #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Close to 800 malicious npm packages ship a cross-platform stealer that runs on import, not at install.

Blocked web C2 falls back to DNS.

Pulled a new npm dependency this week? Hunt host and DNS logs.

https://suriq.io/blog/malicious-npm-packages-dns-c2-stealer

#SupplyChain #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Microsoft ties new StormEncryptor ransomware to China-linked Storm-1175, which breaks in via an N-able N-central auth bypass (CVE-2026-18577).

One management console breach reaches every downstream client.

Patch to 2026.3.1.7, then hunt.

https://suriq.io/blog/storm-1175-stormencryptor-rmm-ransomware

#Ransomware #CVE #SupplyChain #Detection

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

⚠️ PATCH NOW

SAP NetWeaver has a critical flaw (CVSS 9.8) that lets a stranger crash the server or leak its memory with no login, through the protocol SAP GUI speaks.

Affects SAP NetWeaver AS ABAP; no public exploit yet.

Fix: apply SAP's August kernel patch. (CVE-2026-34265)

https://suriq.io/blog/sap-netweaver-diag-unauth-memory-corruption

#CVE #DataBreach #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2mo ago
Replying to on social.falkensweb.com
@falken@social.falkensweb.com Hi :) "East-west" just means one of your machines talking to another machine right next to it, NatJack lets a bad neighbor abuse that.
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

The Fabrik add-on for Joomla has a max-severity flaw (CVSS 10, CVE-2026-67282): a stranger can run code on the server with no login.

Every site on Fabrik below 4.6.8 is exposed.

Fix: update to 4.6.8 now, then check for stray PHP files.

https://suriq.io/blog/fabrik-joomla-unauth-rce-cve-2026-67282

#CVE #infosec #cybersecurity

suriq.io
0
1
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

The Unitree G1 humanoid robot has two flaws that give root with no login (CVE-2026-76639, CVE-2026-76640).

One works over Bluetooth from across a room, and a hacked robot can infect other G1 units nearby.

Unitree fixed the cloud part; isolate the rest.

https://suriq.io/blog/unitree-g1-robot-bluetooth-root-rce

#CVE #CloudSecurity #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Ivanti's Endpoint Manager has three new high-severity flaws, all fixed in the 2024 SU7 update.

One leaks stored database passwords, one lets a user rewrite session recordings, one crashes the agents.

Not exploited yet. Patch now. (CVE-2026-18129)

https://suriq.io/blog/ivanti-epm-august-2026-su7-management-plane-flaws

#CVE #DataBreach #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

⚠️ PATCH NOW

Dell PowerStore storage arrays have a critical flaw (CVSS 9.8): reach the management interface with no login and you can read files that hold admin credentials.

Affects the PowerStore T line (500T to 9200T).

Patch, then rotate the array's credentials.

https://suriq.io/blog/dell-powerstore-unauth-credential-leak-cve-2026-58574

#CVE #Phishing #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

AmnesiaStealer, a new macOS stealer, doesn't stop at saved passwords. It clones your browser and drives it live, inside your logged-in sessions.

Spread via fake GitHub pages that tell you to paste a Terminal command.

Reset sessions, not just passwords.

https://suriq.io/blog/amnesiastealer-macos-live-browser-hijack

#Detection #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1w ago
CVE-2026-82294, CVE-2026-82300 and CVE-2026-94396: Elastic patched three uncontrolled resource consumption flaws in Elasticsearch that can cause denial of service. Affected 8.x and 9.x releases run through 9.5.3. No exploitation is confirmed. Update to 8.19.22, 9.4.8 or 9.5.4. https://www.cve.org/CVERecord?id=CVE-2026-82294 #infosec #cybersecurity
cve.org
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

JFrog Artifactory has an unauthenticated bypass (CVE-2026-82329, CVSS 9.8) that lets a stranger forge admin tokens, exploited now.

Self-managed instances in default config are in scope.

Patch, then rotate tokens: the upgrade won't revoke a forged one.

https://suriq.io/blog/jfrog-artifactory-cve-2026-82329-admin-token-forge

#CVE #SupplyChain #Detection #CISAKEV

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

A BGP route hijack redirected Softaculous traffic and pushed a malicious Virtualizor update that ran as root.

Encryption checked the connection, not the file. The updates were not signed.

Run Virtualizor? Patch to 3.2.9.9 and hunt for the rogue service.

https://suriq.io/blog/virtualizor-bgp-hijack-malicious-update

#SupplyChain #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

WHMCS CVE-2026-67399: if you cannot upgrade to 8.13.7 or 9.0.8 yet, we published a stopgap hook that blocks the payload types this bug most likely needs.

Not a fix. Copy it, test it, delete it after you patch.

https://suriq.io/blog/whmcs-cve-2026-67399-stopgap-hook

#CVE #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Adobe patched a critical Magento and Adobe Commerce flaw (CVE-2026-71362, CVSS 9.1): a stranger can switch into any customer's account with no login.

Affects all stores through the July 2026 patch level.

Fix: apply Adobe bulletin APSB26-92 now.

https://suriq.io/blog/magento-adobe-commerce-account-takeover-cve-2026-71362

#CVE #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1w ago
containerd patched CVE-2026-53493: a crafted image can pin a node's CPU and memory during the pull, before any container runs. Moderate, not yet exploited. Pull untrusted images? Update: 1.7.36, 2.0.13, 2.2.9, 2.3.6, 2.4.1. https://suriq.io/blog/containerd-cve-2026-53493-image-pull-dos #CVE #infosec #cybersecurity
containerd CVE-2026-53493: Image-Pull DoS, Update Now
Suriq

containerd CVE-2026-53493: Image-Pull DoS, Update Now

containerd CVE-2026-53493 lets a crafted OCI image burn CPU and memory during image pull, before any container starts. Moderate, not yet exploited. Update.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

A public exploit, HardBreacher, turns Kaspersky's endpoint agent into a local privilege-escalation tool on fully patched Windows 11.

The flaw is in the agent, not Windows, so OS patching misses it.

Kaspersky says it is fixed. Check your agent version.

https://suriq.io/blog/kaspersky-endpoint-security-hardbreacher-privilege-escalation

#CVE #Detection #DataBreach #Windows

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, then rewrote the logs to stay invisible. The routers logged only "Health" heartbeats, so liveness checks passed while everything else vanished. Off-host logging catches it. https://suriq.io/blog/fire-ant-cisco-router-tacacs-credential-theft #Detection #Phishing #infosec #cybersecurity
suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🚨 BREAKING

Police, the FBI and CrowdStrike disrupted Sality, a botnet that has infected 15,000+ machines since 2003.

The catch: it breaks the operator's control, not the infections. Every hit machine is still infected.

Run old Windows hosts? Hunt for it now.

https://suriq.io/blog/sality-botnet-takedown-machines-still-infected

#ThreatIntel #Detection #Windows #infosec

Sality botnet disrupted after 23 years, PCs still infected
Suriq

Sality botnet disrupted after 23 years, PCs still infected

Police and CrowdStrike disrupted the 23-year-old Sality botnet across 15,000+ machines. The takedown breaks its control, not the infections. What to do now.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

A Cisco firewall flaw (CVE-2026-20349) lets a stranger crash your ASA or FTD with one crafted request. No login, no workaround, already exploited.

When the box reloads, your VPN tunnels drop and its logs go dark.

Patch to the fixed build by August 14.

https://suriq.io/blog/cisco-asa-ftd-cve-2026-20349-dos-exploited

#CVE #CISAKEV #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

Sangoma Switchvox has a critical unauthenticated flaw (CVE-2026-9586, CVSS 9.3) that lets a stranger run code on the phone system.

Patched in July, mass-exploited since Aug 30. Around 4,000 consoles are exposed.

Fix: update to 8.4.0.2 and hunt the logs.

https://suriq.io/blog/switchvox-cve-2026-9586-unauth-rce-exploited

#CVE #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

GeoServer, the open-source map server, has an unpatched zero-day: unauthenticated SQL injection that can reach remote code execution.

No fix yet; probing began within hours.

Restrict access and cut the database account's privileges now.

https://suriq.io/blog/geoserver-zero-day-sql-injection-rce-no-patch

#CVE #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

AJCloud camera firmware (CVE-2026-56718) lets anyone on the network read the files as root, no login.

The dump leaks your Wi-Fi password and video-stream logins in the clear.

Fix: firmware 01.10715.11.37, then isolate the camera.

https://suriq.io/blog/ajcloud-ipc-camera-path-traversal-cve-2026-56718

#CVE #CloudSecurity #Phishing #infosec

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Evooo1Bot is a new Linux botnet that exploits internet-facing devices, then turns them into proxies and credential thieves.

It targets Confluence, WSO2 and ingress-nginx, not just routers.

Watch for rogue services and odd outbound traffic.

https://suriq.io/blog/evooo1bot-linux-botnet-servers-socks-relay

#CVE #ThreatIntel #Detection #DataBreach

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Two of this week's five critical WordPress flaws (GiveWP, CVSS 10.0, and Avada) don't just take over the site, they run code on the hosting server. All five are unauthenticated. Patch now.

https://suriq.io/blog/wordpress-five-critical-plugin-theme-flaws-server-rce

#CVE #CloudSecurity #infosec #cybersecurity

suriq.io
0
0
1
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Opening a booby-trapped code repository can run an attacker's commands in editors built on Eclipse Theia (the framework under Arduino IDE 2.x and other tools).

A crafted git config runs on folder open, no trust prompt. CVE-2026-19884, CVSS 8.4.

Fix: update to Theia 1.70.0.

https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884

#infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

⚠️ PATCH NOW

WHMCS, the billing platform many hosting firms run, has a critical flaw (CVE-2026-67399): a stranger with no login can run code on the server.

Affects 9.x before 9.0.8 and 8.x before 8.13.7. No workaround.

Patch now.

https://suriq.io/blog/whmcs-unauthenticated-rce-cve-2026-67399-patch

#CVE #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

The "malicious LiteLLM packages" headlines miss it. The real breach was Trivy, the container scanner, poisoned in CI five days earlier.

CloudSEK maps 2,500+ orgs of potential exposure, not confirmed breaches.

Ran Trivy in March? Rotate your keys.

https://suriq.io/blog/trivy-litellm-supply-chain-2500-orgs

#CVE #SupplyChain #DataBreach #infosec

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago
CVE-2026-63278 affects LibreOffice from The Document Foundation. Crafted document links could expand environment variable or INI file values and exfiltrate that data to a remote server when a document is opened. Versions before 26.2.5 are affected. Update to LibreOffice 26.2.5. No exploitation has been confirmed. https://www.libreoffice.org/about-us/security/advisories/CVE-2026-63278 #infosec #cybersecurity
libreoffice.org
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1w ago
🚨 BREAKING A stranger with no login can upload a PHP file and run it on your WooCommerce store. Request a Quote for WooCommerce (through 2.9.2) has a critical file-upload flaw, and there is no patch yet. Disable the popup quote form now. (CVE-2026-18143) https://suriq.io/blog/request-a-quote-woocommerce-cve-2026-18143 #CVE #infosec #cybersecurity
Request a Quote WooCommerce RCE Flaw (CVE-2026-18143)
Suriq

Request a Quote WooCommerce RCE Flaw (CVE-2026-18143)

CVE-2026-18143 is a critical unauthenticated file-upload flaw in Request a Quote for WooCommerce (through 2.9.2), with no patch yet. Act now.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1w ago
🔴 EXPLOITED WordPress core CVE-2026-87902 is being exploited to run code on sites, and it affects every release back to 4.7.0. No login needed. CISA wants it patched by Sept 28. Fix: update to WordPress 7.1.2. https://suriq.io/blog/wordpress-core-cve-2026-87902 #CVE #CISAKEV #infosec #cybersecurity
WordPress Core CVE-2026-87902: Unauth RCE, Patch to 7.1.2
Suriq

WordPress Core CVE-2026-87902: Unauth RCE, Patch to 7.1.2

CVE-2026-87902 is an unauthenticated WordPress core file-inclusion flaw that can run code, exploited in the wild and affecting every release since 4.7.0. Patch to 7.1.2.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

⚠️ PATCH NOW

Predis, a widely used PHP client for Redis, has a critical flaw (CVSS 9.8, CVE-2026-84372): attacker-controlled cache keys can smuggle extra Redis commands.

Hits versions 3.0 to 3.2 on cluster and replication setups.

Fix: upgrade to Predis 3.3.0.

https://suriq.io/blog/predis-crlf-command-injection-cve-2026-84372

#CVE #SupplyChain #infosec #cybersecurity

Critical Predis flaw injects Redis commands, fix in 3.3.0
Suriq

Critical Predis flaw injects Redis commands, fix in 3.3.0

CVE-2026-84372 is a CVSS 9.8 command-injection flaw in the Predis PHP client. It hits 3.0 to 3.2 on cluster and replication connections. Upgrade to 3.3.0.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2mo ago
A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root when a Linux machine boots over the network. June's fix for the first bug missed it. Only network-booted systems are exposed. Update dracut and rebuild your initramfs. https://suriq.io/blog/dracut-cve-2026-15816-dhcp-root-execution #CVE #Linux #infosec #cybersecurity
suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Encrypted AI reasoning blocks from OpenAI, Anthropic, and Google can be decoded by a weaker model from the same provider.

Researchers pulled 182 credentials from 315,320 blocks in public repos. Stop sharing raw AI logs.

https://suriq.io/blog/ai-reasoning-traces-leak-api-keys-pii

#DataBreach #infosec #cybersecurity

suriq.io
0
0
1
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

ClickFix trained people to paste into the Run box, and defenders learned to watch it. TerminalFix moved the paste into Windows Terminal, where old rules do not look. The fix did not change: watch the sequence.

https://suriq.io/blog/terminalfix-clickfix-windows-terminal-reverse-tunnel

#Detection #Windows #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Undertow, the web server inside Red Hat JBoss, has a pre-login flaw (CVE-2026-15565) that lets anyone crash the server by flooding a WebSocket until it runs out of memory.

Affects JBoss EAP 7/8 and Data Grid 8. No patch yet.

Fix: disable WebSockets where you can.

https://suriq.io/blog/undertow-jboss-websocket-preauth-dos

#CVE #Detection #infosec #cybersecurity

suriq.io
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

VulnCheck found two more factory backdoors in ZBT router firmware: SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233).

One calls out, one listens on an open port for anyone to reach as root.

No fix. Replace the hardware.

https://suriq.io/blog/zbt-speakingstone-darklantern-router-backdoors

#CVE #SupplyChain #infosec #cybersecurity

suriq.io
0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 10:36:55 UTC