Skip to content

Threat Intel & Field Notes

CVE deep-dives, offensive tradecraft, AI security, and enterprise defense β€” straight from the lab.

// filter feed
#PHPSpreadsheet πŸ•“ 10 min
PHPSpreadsheet RCE Patch Bypass (CVE-2026-45034) via Phar Deserialization
This post delves into CVE-2026-45034, a critical patch bypass vulnerability in PHPSpreadsheet that leads to Remote Code Execution via Phar deserialization. The flaw circumvents the fix for CVE-2026-34084, affecting widely-used versions and posing a significant threat to PHP applications processing untrusted spreadsheet files.
#macOS πŸ•“ 10 min
Pre-Authenticated Root RCE in macOS Screen Sharing (CVE-2026-65400) Actively Exploited
This post details CVE-2026-65400, a critical pre-authenticated Remote Code Execution vulnerability in Apple macOS Screen Sharing with active exploitation in the wild. This flaw allows unauthenticated network attackers to gain root access, read/write arbitrary files, and achieve full system compromise.
#SharePoint πŸ•“ 5 min
Critical Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) Actively Exploited
In-depth analysis of CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint utilizing JWT token validation flaws, actively exploited in the wild and potentially leading to RCE when chained.
#Security Research πŸ•“ 7 min
Microsoft Windows AFD.sys Use-After-Free Zero-Day (CVE-2026-68820) Exploited by Lazarus Group for SYSTEM Privilege Escalation
In-depth analysis of CVE-2026-68820, a critical use-after-free zero-day in Windows AFD.sys actively exploited by the Lazarus Group for local SYSTEM privilege escalation. Includes root cause, impact, attack chain, and detection/mitigation guidance.
#Security Research πŸ•“ 5 min
Cisco ASA & FTD Remote Access SSL VPN Denial of Service Zero-Day (CVE-2026-20349) Actively Exploited in the Wild
In-depth analysis of CVE-2026-20349, a critical denial-of-service zero-day in Cisco ASA and FTD Remote Access SSL VPN services, actively exploited in the wild. Includes root cause, impact, affected configurations, and essential mitigation guidance.
#Security Research πŸ•“ 7 min
Critical Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Zero-Day Exploited in the Wild
In-depth analysis of CVE-2026-16232, a critical authentication bypass zero-day affecting Check Point Security Management and Multi-Domain Management products, actively exploited in the wild. Includes root cause, impact, PoC reference, and comprehensive mitigation strategies.
#Zero-Day πŸ•“ 4 min
ShieldBreak: Nightmare Eclipse Bypasses Microsoft Defender Patch for RoguePlanet (CVE-2026-50656 Redux)
In-depth analysis of ShieldBreak, the latest exploit by Nightmare Eclipse that bypasses Microsoft Defender’s patch for RoguePlanet (CVE-2026-50656), enabling SYSTEM privilege escalation on Windows.
#Android πŸ•“ 5 min
CVE-2025-21042 Deep Dive: Samsung Zero-Click Zero-Day Exploited by LANDFALL Spyware
An in-depth analysis of CVE-2025-21042, a critical zero-click zero-day in Samsung devices exploited by LANDFALL spyware, detailing the attack chain and impact.
[root@purplesec ~]# ls -l /var/log/archive/
drwxr-xr-x 2026 [-]
[Aug 16] Critical SAP Commerce Cloud RCE (CVE-2026-58231) Actively Exploited Post-Patch [Aug 16] PHPSpreadsheet RCE Patch Bypass (CVE-2026-45034) via Phar Deserialization [Aug 16] Pre-Authenticated Root RCE in macOS Screen Sharing (CVE-2026-65400) Actively Exploited [Aug 15] Critical Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040) Actively Exploited [Aug 14] Microsoft Windows AFD.sys Use-After-Free Zero-Day (CVE-2026-68820) Exploited by Lazarus Group for SYSTEM Privilege Escalation [Aug 14] Cisco ASA & FTD Remote Access SSL VPN Denial of Service Zero-Day (CVE-2026-20349) Actively Exploited in the Wild [Aug 14] Critical Check Point SmartConsole Authentication Bypass (CVE-2026-16232) Zero-Day Exploited in the Wild [Aug 13] ShieldBreak: Nightmare Eclipse Bypasses Microsoft Defender Patch for RoguePlanet (CVE-2026-50656 Redux) [Aug 13] CVE-2025-21042 Deep Dive: Samsung Zero-Click Zero-Day Exploited by LANDFALL Spyware [Aug 13] CVE-2026-72898 Deep Dive: Unauthenticated SQL Injection in Metabase Leading to Admin Takeover [Aug 13] Lazarus Group Exploits New Windows Zero-Day (CVE-2026-68820) in Operation Dream Job [Aug 13] Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA [Aug 13] Critical VMware vCenter RCE (CVE-2026-59310) Actively Exploited in the Wild [Aug 13] Cisco ASA & FTD Zero-Days: ArcaneDoor Campaign Deep Dive (CVE-2025-20333, CVE-2025-20362) [Aug 13] Adobe Commerce Privilege Escalation (CVE-2026-71362) Actively Exploited Post-Disclosure [Jul 31] The Great Korean AI Crash: Inside the $2 Trillion Meltdown That Shattered the KOSPI [Jul 23] When AI Hacks AI: How OpenAI's Models Escaped Containment and Breached Hugging Face [Jul 22] LegacyHive: The Windows Zero-Day That Loads Another User's Registry Hive [Jul 11] Your Passkey Is Now Theirs: How Hackers Are Hijacking Microsoft Entra Passkey Enrollment to Own Microsoft 365 Accounts [Jul 04] JADEPUFFER: The First Fully Autonomous AI-Agent Ransomware β€” A Complete Technical Analysis [Jul 02] 81 Million Login Attempts in 14 Days: Inside the Massive Azure CLI Password Spray Campaign [Jul 01] The Samy Worm: Dissecting the Fastest-Spreading XSS Worm in History [Jul 01] Claude Fable 5 Is Back: Inside Anthropic's 19-Day Exile and the New Safety Architecture That Ended It [Jun 30] WhatsApp Is Finally Getting Usernames β€” And It's a Bigger Deal Than You Think [Jun 30] GuardFall: Why Modern AI Agents Are Falling for Decades-Old Shell Tricks [Jun 30] FIFA World Cup 2026: The Largest Cyber Attack Surface in Sporting History [Jun 30] The Phishing Epidemic of 2026: How Generative AI Reshaped Social Engineering [Jun 30] The Invisible Hook: How Clean GitHub Repos Are Tricking AI Agents into Running Malware [Jun 23] Windows 11 26H2: Everything You Need to Know β€” Features, AI Integration, Security, and the Great Architecture Split [Jun 21] Wi-Fi Snitching: How Microsoft Teams' New Auto-Detect Feature Works (And How to Opt-Out) [Jun 21] RoguePlanet: Deep Dive into the Microsoft Defender TOCTOU Zero-Day (CVE-2026-50656) [Jun 21] The Anatomy of a Botnet: History, Architecture, and the Botnet Economy [Jun 20] An AI Agent Is an Identity β€” and Most Organizations Don't Treat Them That Way [Jun 17] The Great Telegram Lockdown: Exam Leaks, Timestamp Forgery, and the Global War on Moderation [Jun 16] Deep Dive: CVE-2025-57819 - Critical RCE in Sangoma FreePBX [Jun 15] Deep Dive: BadSuccessor (CVE-2025-53779) β€” The Windows Server 2025 dMSA Exploit That Shook Active Directory [Jun 13] The Ban on "Foreign Nationals": US Government's Unprecedented Move Against Anthropic's Fable and Mythos Models [Jun 12] Quantum Computing and PKI: The Looming Cryptographic Apocalypse and How to Survive It [Jun 11] NVIDIA RTX Spark & DGX Spark: The Dawn of Personal AI Supercomputers and What It Means for Local LLM Enthusiasts [Jun 11] How GitHub and npm Are Fighting Back Against Supply Chain Attacks β€” And What You Need to Do Before July 2026 [Jun 11] June 2026 Patch Tuesday: A Record-Breaking 206 CVEs, Three Zero-Days & Two BitLocker Bypasses [Jun 10] To Err is Algorithm: Case Studies Where AI Messed Up Big Time [Jun 10] The Nightmare Eclipse Zero-Day Campaign: A Complete Technical Analysis of the 2026 Microsoft Vendetta [Jun 09] A Comprehensive Guide to Modern AI: Concepts, Architecture, and Local Deployment [Jun 09] The Anatomy of the Meta AI Support Hack: Why AI Should Never Reset Passwords [Jun 09] The Golden Skeleton Key: A Deep Dive into CVE-2026-45585 (YellowKey) BitLocker Bypass
_