CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
https://ift.tt/I7MBj5o
Submitted May 20, 2026 at 07:52PM by FanImmediate5874
via reddit https://ift.tt/hjOA8u7
https://ift.tt/I7MBj5o
Submitted May 20, 2026 at 07:52PM by FanImmediate5874
via reddit https://ift.tt/hjOA8u7
ZeroDay Brief
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
CVE-2026-45585 (CVSS 6.8): YellowKey bypasses BitLocker encryption via Windows Recovery Environment. No password cracking. No TPM exploit. Just a maintenance request the OS processed exactly as designed.
The IBM X-Force Index 2026 explains all three in one finding.
https://ift.tt/Kv82Hmu
Submitted May 21, 2026 at 11:48AM by dhakalster123
via reddit https://ift.tt/WklTKbF
https://ift.tt/Kv82Hmu
Submitted May 21, 2026 at 11:48AM by dhakalster123
via reddit https://ift.tt/WklTKbF
Hitechies — AI, Crypto, Security & Dev News for Tech Profession
Grafana breached yesterday. Vercel last month. Stryker in March. IBM just published why.
IBM X-Force Index 2026: supply chain attacks 4x in 5 years. 50% of global orgs had an AI-related security incident. North America most attacked for first time in 6 years. The common thread is preventable.
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
https://ift.tt/LwaUOEA
Submitted May 21, 2026 at 03:15PM by tapendradev
via reddit https://ift.tt/HeuWBU2
https://ift.tt/LwaUOEA
Submitted May 21, 2026 at 03:15PM by tapendradev
via reddit https://ift.tt/HeuWBU2
Secureblink
3,800 GitHub Repos Breached via Poisoned VS Code Extension by TeamPCP
GitHub confirms ~3,800 internal repos breached via poisoned VS Code extension. TeamPCP (UNC6780) sells stolen source code for $50,000
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
https://ift.tt/T3NyCQl
Submitted May 21, 2026 at 09:28PM by Void_Sec
via reddit https://ift.tt/4E30Dlo
https://ift.tt/T3NyCQl
Submitted May 21, 2026 at 09:28PM by Void_Sec
via reddit https://ift.tt/4E30Dlo
VoidSec
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox - VoidSec
Technical analysis of CVE-2026-40369, a 12-byte Windows kernel write reachable from browser sandboxes via NtQuerySystemInformation, leading to SYSTEM.
CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
https://minanagehsalalma.github.io/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure/
Submitted May 21, 2026 at 09:16PM by TheReedemer69
via reddit https://ift.tt/uATBo7j
https://minanagehsalalma.github.io/cve-2026-34474-zte-h298a-h108n-sensitive-data-exposure/
Submitted May 21, 2026 at 09:16PM by TheReedemer69
via reddit https://ift.tt/uATBo7j
minanagehsalalma.github.io
CVE-2026-34474: ZTE H298A / H108N Credential Leak via ETHCheat
Unauthenticated ETHCheat requests return admin and WLAN secrets in the page markup on affected ZTE H298A and H108N router builds.
GitHub Actions Cache Poisoning is eating open source
https://ift.tt/qbF7yGY
Submitted May 21, 2026 at 09:59PM by creasta29
via reddit https://ift.tt/DjXghzN
https://ift.tt/qbF7yGY
Submitted May 21, 2026 at 09:59PM by creasta29
via reddit https://ift.tt/DjXghzN
Neciu Dan
GitHub Actions Cache Poisoning is eating open source
Angular. tj-actions. Cline. TanStack. The same class of attack has been quietly hijacking publish pipelines for two years. Here's what it is, how it works, and what you need to do today.
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave
https://ift.tt/8z725LA
Submitted May 22, 2026 at 01:19AM by Upstairs_Safe2922
via reddit https://ift.tt/OtuTyvA
https://ift.tt/8z725LA
Submitted May 22, 2026 at 01:19AM by Upstairs_Safe2922
via reddit https://ift.tt/OtuTyvA
www.aikido.dev
Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!
Three progressively compromised versions of a Microsoft-adjacent Python package deliver a full-featured infostealer that spreads through AWS and Kubernetes, exfiltrates every cloud credential it can find, and wipes disks on Israeli and Iranian systems
pnpm 11 Might Finally Be a Better Default Than npm
https://ift.tt/8yuqbSs
Submitted May 22, 2026 at 05:00PM by root0ps
via reddit https://ift.tt/yGtAI40
https://ift.tt/8yuqbSs
Submitted May 22, 2026 at 05:00PM by root0ps
via reddit https://ift.tt/yGtAI40
Medium
You Should Move to pnpm from npm Now
Upgrade your package manager before a supply chain attack makes that decision for you.
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
https://ift.tt/utyG5w9
Submitted May 21, 2026 at 08:55PM by Mempodipper
via reddit https://ift.tt/uCp0AtF
https://ift.tt/utyG5w9
Submitted May 21, 2026 at 08:55PM by Mempodipper
via reddit https://ift.tt/uCp0AtF
Searchlight Cyber
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) › Searchlight Cyber
Inside SA-Core2026-004 On the 20th of May, the Drupal Security Team released SA-CORE-2026-004 (CVE-2026-9082), a Highly critical (20/25) SQL injection in Drupal core. The issue is reachable by fully anonymous users on any deployment that backs Drupal with…
Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
https://minanagehsalalma.github.io/zyxel-cve-2021-35036-super-admin-password-leak/
Submitted May 22, 2026 at 08:01PM by TheReedemer69
via reddit https://ift.tt/dfF8xQE
https://minanagehsalalma.github.io/zyxel-cve-2021-35036-super-admin-password-leak/
Submitted May 22, 2026 at 08:01PM by TheReedemer69
via reddit https://ift.tt/dfF8xQE
minanagehsalalma.github.io
CVE-2021-35036: Zyxel Super-Admin Password Leak Across CPE, ONT, LTE, and 5G Routers
Evidence-backed root-cause analysis of CVE-2021-35036, showing how low-privilege users could extract super-admin, TR-069, FTPS, and other credentials across Zyxel router, ONT, LTE, and 5G product lines.
[Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled
https://ift.tt/evQqEVx
Submitted May 22, 2026 at 12:02AM by Only_End_1541
via reddit https://ift.tt/taN9SnE
https://ift.tt/evQqEVx
Submitted May 22, 2026 at 12:02AM by Only_End_1541
via reddit https://ift.tt/taN9SnE
Medium
How the U.S. Cyber Defense Agency Left AWS GovCloud Admin Keys on Public GitHub for 183 Days — And Nobody Noticed
By Faris | Cybersecurity Engineer & Threat Researcher | @farixzz | NullByte Collective
FatGid - FreeBSD 14.x kernel LPE
https://fatgid.io/#bug
Submitted May 21, 2026 at 09:08PM by moviuro
via reddit https://ift.tt/o5XA2pm
https://fatgid.io/#bug
Submitted May 21, 2026 at 09:08PM by moviuro
via reddit https://ift.tt/o5XA2pm
fatgid.io
FatGid - FreeBSD 14.x kernel LPE
A four-byte type, an eight-byte stride, one root shell.
Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension
https://ift.tt/5EfZjtD
Submitted May 22, 2026 at 08:42PM by 0xdea
via reddit https://ift.tt/2kcLZp8
https://ift.tt/5EfZjtD
Submitted May 22, 2026 at 08:42PM by 0xdea
via reddit https://ift.tt/2kcLZp8
HN Security
HN Security - Restoring Testability: Slides, Code & Video - Articles
Hi! Last Thursday, as part of the Burp Extensibility Month on the PortSwigger Discord server, I gave a talk on […]
Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't)
https://ymsniper.github.io/NoEyes/
Submitted May 22, 2026 at 11:41PM by Trick-Resolve-6085
via reddit https://ift.tt/jqROFQy
https://ymsniper.github.io/NoEyes/
Submitted May 22, 2026 at 11:41PM by Trick-Resolve-6085
via reddit https://ift.tt/jqROFQy
AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22
http://kubearmor.io/ctf
Submitted May 23, 2026 at 12:28AM by HighnessAtharva
via reddit https://ift.tt/UmVneh0
http://kubearmor.io/ctf
Submitted May 23, 2026 at 12:28AM by HighnessAtharva
via reddit https://ift.tt/UmVneh0
kubearmor.io
KubeArmor AI Security CTF | KubeArmor
Browser-first CTF landing page for KubeArmor AI security challenges.
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
https://ift.tt/j6C1ZPc
Submitted May 23, 2026 at 01:15AM by thenickdude
via reddit https://ift.tt/1k39AWL
https://ift.tt/j6C1ZPc
Submitted May 23, 2026 at 01:15AM by thenickdude
via reddit https://ift.tt/1k39AWL
F5
NGINX ngx_http_rewrite_module vulnerability CVE-2026-9256
Security Advisory Description NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression…