Posts

/../assets/images/featured/github-breach.png
Breach of GitHub Internal Repositories by TeamPCP: Exfiltration of ~3,800 Repositories via Malicious VS Code Extension

The TeamPCP group (UNC6780) compromised a GitHub employee's device through a trojanized VS Code extension, exfiltrating approximately 3,800 internal repositories from the platform in May 2026.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

8 min read
/../assets/images/featured/DirtyDecrypt.png
CVE-2026-31635 'DirtyDecrypt': Linux Kernel Privilege Escalation Vulnerability and PoC Availability

An inverted validation flaw in the rxgk module allows local attackers to bypass the Copy-On-Write (COW) mechanism and corrupt the page cache to gain root access.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

5 min read
/../assets/images/featured/LinuxCF.jpg
CVE-2026-31431: How a Simple `cp` Is Enough to Become Root on Linux

A memory handling flaw during data copy operations allows any unprivileged user to gain full control of a Linux system.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

6 min read
/../assets/images/featured/nginx_rift_cve.png
NGINX Rift: The 18-Year-Old Vulnerability Turning the World's Most-Used Web Server Into an Entry Point for Attackers

Researchers reveal that CVE-2026-42945, a critical flaw in NGINX's rewrite module, went undetected since 2008. With a CVSS score of 9.2, it allows a remote, unauthenticated attacker to crash servers or execute malicious code on systems without active memory protections.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

9 min read
/../assets/images/featured/bleeding_llama.png
Bleeding Llama: the critical memory leak exposing 300,000 local AI servers

CVE-2026-7482, a critical vulnerability in Ollama that allows any remote attacker to extract prompts, environment variables, and API tokens from server memory in just three unauthenticated HTTP requests.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

10 min read
/../assets/images/featured/DirtyFrag_Linux.png
Dirty Frag: The Zero-Day Vulnerability That Broke the Embargo and Exposed All of Linux

Dirty Frag. A privilege escalation flaw in the Linux kernel affecting all major distributions, with no patches available and an embargo broken ahead of schedule.

Tags: News
obeedt, OscarRV, LuisZavMen

obeedt, OscarRV, LuisZavMen

5 min read