Rose debug info
---------------

Human Factor Blog

how human behavior affects security

Programmer’s Digest #196

07/29/2026-08/07/2026 Critical cPanel Vulnerability, JetBrains TeamCity Vulnerability, Trojanized npm Packages Employ NullReceiver Tactic And More.

1. Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User 

A critical privilege-escalation flaw in cPanel & WHM, tracked as CVE-2026-58048, could let authenticated hosting users with MySQL/MariaDB access execute SQL commands with full database administrator privileges. In shared hosting environments, this lets low-privileged users exceed their assigned permissions, potentially exposing customer databases, altering user permissions, extracting credentials, deploying malicious triggers, or reading files via database functions. Where MySQL/MariaDB has elevated filesystem access, exploitation could escalate to full server compromise.The flaw affects all unpatched supported versions of cPanel & WHM. Administrators should update immediately to versions 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, or 138.1.6 (WP2). Where immediate patching isn’t possible, revoking the MySQL feature from affected users mitigates risk while preserving access to existing databases. Security teams should audit logs for unusual database activity—new users, altered privileges, modified stored procedures, or suspicious file operations—especially on accounts with recently created databases.Organizations should treat this as high-priority patching.

2. Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers exploited a SQL injection flaw in a public-facing web app to reach an organization’s Oracle database, then used Oracle’s embedded Java Virtual Machine to compile Java source code directly into schema objects—achieving code execution without ever writing an executable to disk. Huntress, tracking the toolkit as “khunt,” traced credential-theft alerts from July 27, 2026 to SYSTEM-level access on the underlying Windows server. The compromised JDBC connection had enough privilege to create Java objects; no Oracle patch fixes this, since it relies on legitimate features and over-permissioned accounts.

The toolkit included six Java classes for command execution, hash extraction, and file operations, plus PL/SQL wrappers. Attackers ran cmd.exe as SYSTEM and staged registry hives and credential files locally, though exfiltration wasn’t confirmed. The technique dates back to a 2006 proof-of-concept but is rarely seen exploited in the wild. Defense requires parameterized queries, input validation, and stripping unnecessary database privileges from application accounts—since EDR tools don’t inspect Oracle’s internals.

3. Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability

CISA warns that threat actors have started exploiting a recently patched critical vulnerability in JetBrains TeamCity, a widely used CI/CD platform central to enterprise development workflows. Tracked as CVE-2026-63077 (CVSS 9.8), the flaw stems from deserialization of untrusted data and lets unauthenticated attackers achieve remote code execution via HTTP/S requests, exploiting the TeamCity agent polling protocol. It affects all TeamCity On-Premises versions, allowing attackers to bypass authentication and run OS commands with server-process privileges.

JetBrains patched the issue in versions 2025.11.7 and 2026.1.3, plus a plugin for 2017.1+, after a private report—initially with no evidence of active exploitation. About a week after disclosure, CISA added the flaw to its KEV catalog, giving federal agencies three days to patch under BOD 26-04. No public details on the attacks have emerged yet. Organizations running TeamCity On-Premises should patch immediately.

4. Critical Paperclip AI Flaws Enable Unauthenticated RCE and Agent Takeover

Oasis disclosed three vulnerabilities in Paperclip, an open-source control plane for autonomous AI agents. The most severe, CVE-2026-41679 (CVSS 10.0), lets unauthenticated attackers self-register, self-approve a board-level API credential via the CLI authorization flow, then exploit a missing authorization check in the company-import route. This allows uploading a malicious agent config that executes arbitrary OS commands once “woken”—yielding full remote code execution and exposing secrets and internal services. It affects versions before 2026.416.0 with default self-registration enabled.

A second flaw (CVSS 8.3) allowed unauthenticated access to cross-tenant data and verbose health endpoints useful for reconnaissance. A third (CVSS 9.6) let attackers use DNS rebinding against Paperclip’s local_trusted mode, tricking victims’ browsers into triggering command execution with no credentials required.

All three stem from implicit trust at authorization boundaries. Paperclip patched the issues in version 2026.416.0; operators should upgrade immediately and treat agent configs as privileged, executable code.

5. Trojanized npm Packages Employ NullReceiver Tactic to Decode C2 IP from Blockchain

Researchers have identified NullReceiver, a North Korea-linked evolution of the EtherHiding blockchain C2 technique, found in trojanized npm packages “bianira-ui” and “fluid-type-ui.” Rather than embedding a C2 address in smart contract calldata, malware decodes the C2 IP directly from the recipient address bytes of an empty, zero-value Ethereum transfer—eliminating any fixed, trackable destination or fingerprintable payload field, while making transactions cheaper.

The malware looks up a hardcoded attacker wallet, reads its latest outbound transaction’s destination address, and converts the first four bytes into an IP. Both packages, downloaded hundreds of times before removal, connected victims to 166.88.134[.]62. OpenSourceMalware later found five more npm packages using this technique.

Shared wallet infrastructure linked these packages to North Korean campaigns, including PolinRider, which has compromised 20+ packages across npm, Go, and PHP over five months using fake interviews, poisoned forks, and typosquatting to infiltrate developer machines.

6. Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks

A supply-chain attack compromised the Keyv and Cacheable npm namespaces, spreading malicious packages across multiple organizations. SafeDep initially confirmed 353 poisoned versions and later raised the total to 1,684 versions across 420 package names, while Aikido reported a different count. The malware used a preinstall script to steal GitHub, npm, cloud, Kubernetes, database, and private-key credentials from developer and CI environments, then reused stolen npm publishing access to spread further. A separate execution path through Claude Code and VS Code workspace hooks also remained in the repository. Researchers warn that any system running an affected version should be treated as compromised. Because package tags changed rapidly, organizations should verify exact package versions and lockfiles instead of relying on namespace blocklists. Although the malicious releases were built through legitimate GitHub Actions workflows with valid OIDC and SLSA provenance, those attestations verified the build process—not that the source code was trustworthy.

7 h   digest   programmers'

Programmer’s Digest #195

07/22/2026-07/29/2026 Trojanized Newtonsoft.Json Fork; New RefluXFS Linux Flaw; Windmill Flaw And More.

1. Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Researchers at JFrog uncovered a NuGet typosquat, “Newtonsoftt.Json.Net,” a trojanized fork of Newtonsoft.Json that rigs betting results rather than stealing data. Seven versions (11.0.4–11.0.11) were published between August 13–October 10, 2025, downloaded ~1,200 times, and later unlisted by owner MagicalPuff96—though still downloadable.The package works normally until JsonConvert.DefaultSettings initializes, triggering a randomized delay to evade detection. It then targets servers running Digitain’s FG-Crash betting-game backend, exfiltrating rigged round results to 185.126.237[.]64:5341 via header “X-Seq-ApiKey: theperfectheist2025,” disguised as telemetry. Metadata leaks an internal Digitain repo URL, suggesting the author had source-code access.

Across three generations, obfuscation evolved: Gen-1 was a local proof-of-concept, Gen-2 added exfiltration hidden via reflection/ConfuserEx, Gen-3 stabilized exfiltration, with 11.0.11 left unobfuscated. Researcher Guy Korolevski noted the malware has no credential theft or persistence—only integrity compromise targeting one organization.

Developers should remove the package, block the C2 address, and pin Newtonsoft.Json via packages.lock.json. Digitain says it’s addressing the issue; full exposure remains unclear.

2. Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Researchers detailed a campaign turning compromised GitHub repositories into attack infrastructure targeting cPanel/WHM servers. Attackers compromised a PHP maintainer’s account and pushed malicious GitHub Actions workflows across 10 Packagist packages (July 12–13, 2026), syncing 583 malicious workflow files.

Triggered by a push or manual run, the workflows spin up GitHub-hosted runners, detect CPU architecture, and download a Linux payload that exploits CVE-2026-41940, a cPanel/WHM authentication bypass flaw, then harvests credentials—AWS, GitHub/GitLab tokens, API keys, Stripe, database, and SSH data—exfiltrating results via HTTP POST. Unlike typical package attacks, this doesn’t target package users; GitHub’s own runners do the scanning and exploitation.

Roughly 6,100 workflow files sharing a common identifier suggest a broader campaign beyond one maintainer. Separately, Socket flagged “Operation Muck and Load,” using 200 GitHub repos across 190 accounts to deliver Windows malware (stealers, RATs, miners) via multi-stage chains pulling payloads from Pastebin, Telegram, and similar platforms—tactically linked to the “Water Curse” threat cluster.

3. New RefluXFS Linux Flaw Lets Attackers Gain Root Privileges

A nine-year-old Linux kernel flaw in XFS, CVE-2026-64600 (“RefluXFS”), lets local attackers gain root by exploiting a race condition in reflink-enabled systems (default on major enterprise distros) running kernel 4.11+. Attackers reflink-clone a target file like /etc/passwd, then race concurrent writes so changes land on the original file’s physical block—bypassing SELinux, lockdown, and memory protections since it operates below the filesystem layer. Exploitation is reliable, leaves no logs, and survives reboot.

Found by Qualys TRU, the bug dates to a 2017 kernel commit and was patched July 16. Affected distros include RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, and CloudLinux—an estimated 16.4 million systems. Notably, the flaw was surfaced through a Qualys-Anthropic research initiative using Claude Mythos Preview to hunt for Dirty COW-style race conditions; Qualys researchers then verified and reproduced the exploit independently. Immediate patching and reboot are recommended, as no mitigations exist.

4. Ubuntu Snap-Confine Vulnerability Enables Local Root Access

A newly disclosed flaw in snap-confine, the component isolating Ubuntu’s snap applications, lets any local user gain full root on default Ubuntu Desktop 24.04, 25.10, and 26.04 installs. Qualys TRU disclosed the high-severity bug, CVE-2026-8933, on July 21—the second snap-confine root-escalation flaw from the same team in four months.

The issue traces to a July 2025 hardening change that moved snap-confine to a set-capabilities model, leaving a brief window where temporary sandbox files remain owned by the unprivileged caller before root takes over. Attackers exploit this with two race conditions: mounting a FUSE filesystem over the scratch directory to escape isolation, and redirecting a symlink so snap-confine writes to an attacker-controlled target before ownership transfers. A malicious rules file dropped via /run/udev/rules.d/ bypasses AppArmor, forcing systemd-udevd to execute commands as root. Canonical has released patches. Since affected snapd ships by default, workstations and developer systems are in scope—administrators should verify installed snapd versions and update immediately.

5. Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity flaw in open-source developer platform Windmill, CVE-2026-29059 (CVSS 7.5), is under active exploitation, according to VulnCheck. The bug is an unauthenticated path traversal in Windmill’s “get_log_file” endpoint: an unsanitized filename parameter lets attackers use “../” sequences to read arbitrary server files.

The main risk is exposure of the SUPERADMIN_SECRET environment variable, which—if set—can be used as a Bearer token to gain superadmin access and execute arbitrary code via the job preview API. It’s not set by default, so unconfigured standalone instances face only arbitrary file read. The flaw was patched in Windmill 1.603.3 (January 2026).

Researcher Valentin Lobstein discovered and reported the issue; VulnCheck says attackers are targeting the endpoint to extract “/etc/passwd,” hitting both direct Windmill endpoints and the Nextcloud proxy path. About 170 vulnerable systems remain exposed across 24 countries. Affected organizations should upgrade immediately, as SUPERADMIN_SECRET exposure can escalate to full remote code execution.

9 d   digest   programmers'

Programmer’s Digest #194

07/15/2026-07/22/2026 Critical SNMP Command Injection and Four XSS Vulnerabilities; Critical NGINX Vulnerability; SharePoint RCE Vulnerability CVE-2026-50522 And More.

1. Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has released fixes for nine security vulnerabilities in Zimbra 10.1.20, the most severe being a command injection flaw in the SNMP monitoring component that triggers when SNMP notifications are enabled. Four cross-site scripting (XSS) flaws in the Classic Web Client were also patched, involving malicious attachment filenames, crafted fields, and crafted attachments that could execute scripts under certain conditions. Separately, the update fixes a mail forwarding restriction bypass (CVE-2026-50055) that let authenticated users exfiltrate email even with forwarding restrictions enabled, discovered by Rapid7’s Jonah Burgess.

Zimbra withheld further technical details, saying “in line with industry best practices, information disclosure is limited for security vulnerability fixes.” This follows a patch issued just over a week ago for a critical stored XSS bug in the Classic Web Client that could enable arbitrary code execution.

None of the newly patched flaws are known to be actively exploited, but given XSS bugs’ history of exploitation in email platforms, prompt patching is strongly advised.

2. FakeGit Campaign Uses 7,600 GitHub Repos to Push SmartLoader Malware

A campaign dubbed “FakeGit” is distributing SmartLoader and StealC malware through 7,600 malicious GitHub repositories with over 14 million downloads. More than 800 repositories posed as AI skills or MCP servers, appearing 600+ times in public AI registries—a technique researchers call “agentbaiting,” designed to increase visibility to AI agents.

Attributed to threat actor “Water Kurita” and building on an earlier Lumma Stealer campaign, FakeGit’s AI focus emerged in March, peaking in April. Repositories impersonate tools like Gmail, WhatsApp, and Docker, using fake stars, forks, and documentation. READMEs direct victims to ZIP files disguised as installers that trigger SmartLoader, which establishes persistence, fetches its C2 address via a Polygon smart contract, and deploys StealC.

Island researchers found ChatGPT, Gemini, and Claude sometimes surfaced these repositories and relayed installation instructions when prompted. In controlled tests, Claude Code cloned malicious repos and downloaded files but halted before execution upon detecting suspicious indicators.

3. Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution

F5 has patched a critical nginx flaw, CVE-2026-42533, that lets an unauthenticated attacker trigger a heap buffer overflow via crafted HTTP requests. Fixed in nginx 1.30.4/1.31.3 and NGINX Plus 37.0.3.1 on July 15, it affects every version since 0.9.6 (2011). The bug arises when a regex-based map variable is referenced alongside an earlier regex capture—nginx’s two-pass engine sizes a buffer for one capture but writes data from another, causing overflow. It can crash worker processes (DoS) and, F5 says, enable RCE if ASLR is bypassable.

Researcher Stan Shaw argues the flaw supplies its own ASLR bypass by leaking heap data, potentially making RCE far easier than F5’s advisory suggests—a claim he says tested 10/10 but hasn’t published proof for yet. He also found F5’s suggested mitigation (named captures) incomplete, leaving a secondary path open. CISA hasn’t flagged active exploitation yet, but similar recent nginx bugs were quickly weaponized, so patching promptly is advised.

4. CISA Warns Admins to Patch Actively Exploited SharePoint Flaws

CISA warned that attackers are actively exploiting three on-premises SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164), affecting all supported self-hosted versions, including Subscription Edition. Attackers are using them to bypass authentication, gain remote code execution, steal IIS machine keys, and deploy malware.

CISA also flagged two newly patched flaws (CVE-2026-55040, CVE-2026-58644) as likely future targets, though not yet exploited. Shadowserver tracks nearly 10,000 exposed SharePoint servers, with over 800 unpatched against the first two CVEs.
CISA recommends applying patches, enabling AMSI and Microsoft Defender detections, rotating IIS machine keys after hunting for intrusion artifacts, restricting SharePoint’s internet exposure, and using reverse proxies where exposure is unavoidable. Federal agencies must secure or disconnect affected servers by July 17 under BOD 26-04.

Since 2021, CISA has flagged 11 exploited SharePoint vulnerabilities, seven also used in ransomware attacks.

5. Public PoC Triggers Active Exploitation of critical SharePoint RCE Vulnerability CVE-2026-50522

A critical SharePoint vulnerability, CVE-2026-50522 (CVSS 9.8), is under active exploitation following release of a public proof-of-concept. Patched in Microsoft’s July 2026 Patch Tuesday, the deserialization flaw lets attackers with Site Owner privileges execute arbitrary code remotely. It’s paired with CVE-2026-58644, both unauthenticated-exploitable deserialization bugs; CVE-2026-50522 was demonstrated at Pwn2Own Berlin, yet Microsoft’s advisory lists exploit maturity as unknown. watchTowr’s honeypot network captured exploitation attempts within hours of the PoC’s release, with attackers stealing SharePoint machine keys via a single request to maintain persistent access—meaning patching alone won’t remove attacker access. Security firm Defused Cyber also observed attacks delivering a .NET deserialization payload through SharePoint’s sign-in endpoint.

This follows earlier exploited SharePoint flaws CVE-2026-45659, CVE-2026-32201, and CVE-2026-20963, all added to CISA’s KEV catalog since March. Organizations should patch immediately and rotate potentially exposed credentials.

16 d   digest   programmers'
Earlier Ctrl + ↓