❌

Normal view

There are new articles available, click to refresh the page.
Today β€” 22 July 2026HackingPassion

Exploitarium Dropped 204 Live Exploits for curl libssh2 and Nmap With No Warning

By: Author
22 July 2026 at 09:01

Someone published 204 exploit files on GitHub for software you almost certainly use, and told the vendors nothing. The makers found out the same way the attackers did, by reading the page. 🧐

The account goes by bikini. The project is called exploitarium, a single archive of ready-to-run exploit code for software that sits underneath much of what you use. The first dated entries go back to June 23, and by June 27 the page was pulling in stars and hundreds of comments, which meant defenders and attackers were reading the same exploits at the same moment.

Yesterday β€” 21 July 2026HackingPassion

Nginx Map Regex Flaw Lets One Request Take Over a Server

By: Author
21 July 2026 at 07:12

For 15 years, a single crafted web request could quietly take over an nginx server, the software that receives and routes incoming traffic for roughly a third of the websites people load. The flaw was documented in public years ago and marked as something to fix, and the danger went unrecognised until a researcher looked again last week.

nginx is the piece of software sitting in front of a large slice of the internet. When you open a site, there is a good chance nginx is the first thing that reads your request, deals with the encryption, decides where the request should go, and passes it to whatever runs the site behind it.

Before yesterdayHackingPassion

7-Zip Carried a Hidden Code Execution Flaw in Its XZ Files for Eight Years

By: Author
20 July 2026 at 09:55

You opened an archive in 7-Zip, and the code that let it take over your machine had been sitting there since 2018. It was quietly patched on June 25. You were not told what it fixed until three weeks later.

On July 15, the Zero Day Initiative laid out the details in advisory ZDI-26-444, tracked as CVE-2026-14266. It described a flaw in 7-Zip that lets a malicious archive run code the moment you open it. Before that day, the only thing 7-Zip had said about it was a June release that explained nothing.

LegacyHive Reopens a Windows Privilege Hole Microsoft Closed 11 Years Ago

By: Author
19 July 2026 at 06:01

For weeks he promised that July 14 would shatter Microsoft’s bones. Patch Tuesday came, Microsoft closed a record 622 holes, and hours later he dropped LegacyHive, a Windows zero-day that lets a normal user break into the administrator’s account. No patch, no CVE yet, and far quieter than he promised. 🧐

If you have followed my posts this year, you know who this is. Nightmare-Eclipse, the researcher who has spent 2026 dropping working Windows exploits on Microsoft after what he says was the company taking his credit and paying him nothing for it. Microsoft did delete the account he reported bugs through. I laid out that full story when the count first hit six, so this post stays on the new bug.

WordPress Let One Request Read Your Database for 227 Days

By: Author
18 July 2026 at 06:59

A hole in WordPress handed your database to someone who never logged in. For 227 days it took one request. It needed no password and no plugin, just an address that has been part of WordPress since December 2020. 🧐

The patch is the problem.

WordPress is open source, so the repair had to be published. It went up on Friday afternoon: three commits, three files, timestamped 16:27 UTC. Put the old version next to the new one and you can read what was broken.

Microsoft Signed 11 Files That Bypass Secure Boot

By: Author
15 July 2026 at 07:29

Some malware loads before Windows even starts, before your antivirus exists. It survives a full reinstall, and 11 files signed by Microsoft are all it takes.

One check is supposed to make that impossible. These 11 get past it, on almost any PC.

ESET’s Martin SmolΓ‘r published this on July 14. The files are old, some more than ten years old, and each one carries a valid Microsoft signature.

When you turn on your computer, something runs before Windows does. It is the firmware, the low-level code built into the machine, and its job is to load the thing that loads Windows. Secure Boot is the check that runs at that moment. It looks at each piece of startup code and asks one question: is this signed by someone I trust? If the answer is yes, it runs. If no, it stops.

DNA Carried Malware Into a Computer for 89 Dollars

By: Author
14 July 2026 at 07:58

89 dollars of DNA was enough to take over a computer. The attack sat in the genetic letters themselves, A, T, C and G. Years later, the machines that read them turned out to be even easier to break.

This research is from 2017, and I’m bringing it back on purpose. It is a clear buffer overflow story you can learn from, and in 2025 it stopped being a party trick.

Signed by Microsoft Does Not Mean Safe

By: Author
11 July 2026 at 07:01

A digital signature on a Windows driver proves who made it. It was never proof that the driver is safe. Attackers built a technique on that gap, called Bring Your Own Vulnerable Driver, and it hands them control of Windows at its deepest level. Some of the malware they use was signed through Microsoft’s own program.

A driver is the piece of software that lets Windows and a device work together, your keyboard, your printer, your graphics card. It runs in the kernel, the core of the operating system, at a level called ring 0, where code has direct access to memory and hardware. Security software mostly watches from a step below. Some of it runs inside the kernel too, but even that cannot protect itself once an attacker controls that level. Reaching the kernel puts an attacker on top.

IonStack Turns One Link Into Full Root on Your Android Phone

By: Author
9 July 2026 at 06:52

IonStack You tap one link, and root is already running on your Android 17 phone. You never download a file or approve a permission box because the page does the work itself while it loads.

The same flaw sits in the Linux kernel behind servers, cloud platforms, and containers, so the phone is only where it starts. Researchers built the attack, put it online, and now anyone can watch it root a device on their own screen.

Windows Hands Your Name to the Police Through One Hidden Number

By: Author
8 July 2026 at 05:29

You are completely anonymous and think no one can trace you. But Windows put a permanent number on your machine, it never turns off, and that number is where the police start when they want your name. That is exactly how the FBI just caught a 19-year-old hacker who thought he had covered every track.

On July 1, US prosecutors in Chicago made their case public against a 19-year-old named Peter Stokes, who holds both a US and an Estonian passport. They say he runs with Scattered Spider, one of the biggest crews in cybercrime, the kind that breaks into companies and then demands money to leave them alone. He has not been found guilty of anything, and under the law he stays innocent until a court says otherwise.

TrojPix Steals Data From Air Gapped Computers Through the Screen

By: Author
7 July 2026 at 07:10

TrojPix pulled a file off a computer that connects to nothing. 8.1 megabits a second. 208 meters away. Straight through a 30 cm concrete wall. It went out over the pixels on the screen, and the screen looked normal.

This came from a research team at Shandong University and Quan Cheng Laboratory. The target is an air-gapped machine, a computer kept off the network on purpose because of the sensitive work it does. You find these in defense, government, banking and nuclear plants.

Why a Vpn Is Not Privacy

By: Author
6 July 2026 at 08:26

The absolutely useless idea of using a VPN for privacy on the internet. A VPN becomes a honeypot. 🧐

Yes, you read that right.

First, what a VPN does. You install an app. The app builds an encrypted tunnel from your device to a server owned by the VPN company. Your traffic travels through that tunnel, and from the VPN server it continues to the sites you visit. The sites see the address of the VPN server instead of your home address. Your internet provider sees an encrypted stream to one server and nothing more.

JADEPUFFER Is the First Ransomware Attack Run Entirely by an AI Agent

By: Author
5 July 2026 at 07:22

JADEPUFFER is the first documented ransomware operation run by an AI agent. The agent broke in, stole credentials, jumped to a second target, encrypted a production database, and destroyed data. This is an agentic threat actor: an attacker whose attack power comes from an AI agent rather than from a human toolkit.

Researchers documented something that changes what a ransomware attack can look like. Ransomware has always needed a person somewhere in the loop. Someone picks the target, tests the stolen logins, and patches up the code when it breaks. This time a large language model did all of it.

FatFs Flaw Lets One SD Card Take Over Millions of Devices

By: Author
4 July 2026 at 06:06

Millions of devices read an SD card with one small piece of code called FatFs, and researchers just found seven ways to break it. The worst one hands the whole device to whoever made the card.

FatFs does one small job. It lets a device read and write the FAT and exFAT format, the same format your USB sticks and SD cards use. Almost any gadget with a card slot or a USB port needs something like this, and FatFs is free, tiny, and easy to drop in, so a big part of the industry grabbed it. One person writes it. Thousands of products copy the file into their own gear and ship it.

Phantom Squatting Lets Hackers Buy the Fake Websites Your AI Invents

By: Author
1 July 2026 at 07:25

Your AI assistant just sent you to a login page that did not exist a few weeks ago, and the person who registered it is already collecting the passwords people type in.

You trust the link because it came from your AI. That trust is the attack itself, and it works without a single phishing email.

It has a name now: phantom squatting. Security researchers wrote it up this week. The idea is simple once you see it.

WinRAR Can Still Drop Malware Into Your Startup Folder a Year After the Patch

By: Author
30 June 2026 at 05:05

You unzipped a file with WinRAR, the way you always do. Nothing on screen looked wrong. The next morning you logged in and malware was already running, and the only thing you did was open an archive someone emailed you.

In July 2025, ESET researchers spotted a file called msedge.dll sitting inside a RAR archive, in a folder path that made no sense. That odd path turned out to be a brand new flaw in WinRAR, and someone was already using it in attacks while it was still unknown. That was last summer, and it has not stopped since.

❌
❌