Elusive

595 posts

Elusive banner
Elusive

Elusive

@ElusivePrivacy

We talk in @VulnerabilityNw about CVEs, zero-days & what's exploited right now. Monero lovers · Builder of https://t.co/E8G6RsJYtr mining pool for $XMR $TARI

Katılım Ağustos 2024
220 Takip Edilen171 Takipçiler
Sabitlenmiş Tweet
Elusive
Elusive@ElusivePrivacy·
I've just created the Telegram and Discord chats for xmr.pw I'll leave the links below to join: Discord: discord.gg/kJXKrJqUjr Telegram: t.me/xmrpw If you have questions or issues I'll try my best to help you 😅 Happy mining ⛏️
English
5
2
15
576
Elusive
Elusive@ElusivePrivacy·
Broadcom patched a high-severity vulnerability in VMware Fusion. The timing is notable the fix dropped while Broadcom is at Pwn2Own Berlin. No word yet on whether this was a contest-discovered bug or independent finding. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
1
1
32
Elusive
Elusive@ElusivePrivacy·
Broadcom patched a high-severity vulnerability in VMware Fusion. The timing is notable the fix dropped while Broadcom is at Pwn2Own Berlin. No word yet on whether this was a contest-discovered bug or independent finding. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
35
Elusive
Elusive@ElusivePrivacy·
Cargo theft has gone digital. The NMFTA reports that freight hijacking now starts with phishing emails and stolen credentials attackers reroute shipments through compromised logistics accounts rather than physical interception. Supply chain attack surface keeps expanding. Source: BleepingComputer Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
35
Elusive
Elusive@ElusivePrivacy·
The alleged administrator of Dream Market Incognito Market one of the largest dark web marketplaces before shutdown has been indicted in the US on money laundering charges. Arrested in Germany. Extradition pending. Source: BleepingComputer Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
1
1
11
Elusive
Elusive@ElusivePrivacy·
The alleged administrator of Dream Market Incognito Market one of the largest dark web marketplaces before shutdown has been indicted in the US on money laundering charges. Arrested in Germany. Extradition pending. Source: BleepingComputer Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
25
Elusive
Elusive@ElusivePrivacy·
Hackers began exploiting a PraisonAI authentication bypass less than four hours after public disclosure. This is the speed-of-weaponization reality now: patch latency measured in hours, not days. If you're running PraisonAI in production, assume scanning started immediately. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
21
Elusive
Elusive@ElusivePrivacy·
Salt Typhoon has struck an energy entity in Azerbaijan. Twill Typhoon is targeting Asian organizations with an updated RAT. Both Chinese APTs are expanding their target sets and refreshing backdoors in concurrent campaigns. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
1
1
20
Elusive
Elusive@ElusivePrivacy·
Initial access broker KongTuke has shifted from email-based phishing to Microsoft Teams for social engineering. Attackers gain persistent network access in as little as five minutes. The vector: posing as IT support, convincing targets to install remote access tools. Source: BleepingComputer Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
47
Elusive
Elusive@ElusivePrivacy·
CVE-2026-46300 Fragnesia. Another Linux kernel memory management bug yields local privilege escalation. Similar mechanics to Dirty Frag and Copy Fail. Affects multiple distributions. Patch cycle in progress. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
2
75
Elusive
Elusive@ElusivePrivacy·
The flaw affects Cisco Catalyst SD-WAN Controller and SD-WAN Manager. Exploitation confirmed in the wild timing suggests coordinated disclosure or rapid reverse-engineering of the patch. If you manage SD-WAN infrastructure, validate your upgrade status now. Full analysis + raw sources → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
1
1
37
Elusive
Elusive@ElusivePrivacy·
1/2 Cisco Catalyst SD-WAN has a maximum-severity authentication bypass under active exploitation. CVE-2026-20182. Unauthenticated attacker can gain full control of the SD-WAN Controller and Manager. Cisco disclosed and patched the same day.
English
1
1
1
66
Elusive
Elusive@ElusivePrivacy·
Intel and AMD publish 24 advisories covering 70 vulns. Intel's worst: CVE-2026-20794 (CVSS 9.3) buffer overflow in Data Center Graphics Driver for VMware ESXi, privilege escalation + potential RCE. Also patches for UEFI firmware, EMA, and QAT drivers. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
1
1
71
Elusive
Elusive@ElusivePrivacy·
Fortinet patches critical RCE in FortiSandbox and FortiAuthenticator. Ivanti fixes multiple flaws leading to arbitrary code execution. Both vendors assess exploitation as likely. Patch immediately. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
29
Elusive
Elusive@ElusivePrivacy·
Microsoft's MDASH found 16 of the 137 Patch Tuesday flaws autonomously. Palo Alto Networks used Claude Mythos to scan its product portfolio found dozens of real vulns. AI-driven vulnerability discovery is shifting from experiment to production pipeline. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
77
Elusive
Elusive@ElusivePrivacy·
2/2 Mitigation: switch Outlook to plain text mode. No known exploitation in the wild yet. Attack surface: every Outlook + Exchange environment. One of 137 vulns in Microsoft's May Patch Tuesday. Source: SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
1
1
54
Elusive
Elusive@ElusivePrivacy·
1/2 Microsoft patches CVE-2026-40361 zero-click RCE in Outlook via preview pane. Use-after-free in email rendering DLL shared with Word. No user interaction needed. Researcher Haifei Li (Expmon) compares it to BadWinmail (CVE-2015-6172), the "enterprise killer" from 2015.
English
1
1
1
85
Elusive
Elusive@ElusivePrivacy·
House Homeland Security Committee demands Instructure execs testify over ShinyHunters' Canvas breach. Attackers stole student data and disrupted final exams across US schools. Instructure previously claimed it reached an "agreement" with the threat actor to stop the leak. Source: BleepingComputer / SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
1
1
111
Elusive
Elusive@ElusivePrivacy·
Foxconn confirms cyberattack on North American factories. Nitrogen ransomwaregang claims 8TB stolen confidential documents, operational data. World's largest electronics manufacturer's third major cyber incident since 2020. Operations still resuming. Source: BleepingComputer / SecurityWeek Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
23
Elusive
Elusive@ElusivePrivacy·
🔓 PoC released for two unpatched Windows zero-days: YellowKey (BitLocker bypass via WinRE using FsTx files) and GreenPlasma (CTFMON → SYSTEM LPE). Researcher Chaotic Eclipse promises more exploits next Patch Tuesday. Kevin Beaumont confirms YellowKey works. Source: BleepingComputer Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
161
Elusive
Elusive@ElusivePrivacy·
Adobe Patches 52 Vulnerabilities in 10 Products Adobe fixes 52 CVEs across 10 products including After Effects and Illustrator. Two are rated critical CVE-2026-34659 and CVE-2026-34660, both CVSS 9.x, arbitrary code execution vectors. No exploitation in the wild, but patch velocity is rising. Source: SecurityWeek / Adobe Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
0
2
2
96
Elusive
Elusive@ElusivePrivacy·
SAP Critical Flaws in Commerce Cloud & S/4HANA SAP's May 2026 patch batch addresses 15 vulnerabilities, including two critical flaws in Commerce Cloud (CVE-2026-34263) and S/4HANA (CVE-2026-34260). Both could allow remote code execution in enterprise-grade e-commerce and ERP deployments. Patches available on SAP Security Note Day. Source: BleepingComputer / SAP Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
105
Elusive
Elusive@ElusivePrivacy·
Fortinet Critical RCE Flaws Fortinet patches two critical RCE vulnerabilities in FortiSandbox (CVE-2026-44277, CVE-2026-26083) and FortiAuthenticator (CVE-2026-21643, CVE-2026-35616). Unauthenticated attackers can run arbitrary commands or code on affected appliances. No reports of active exploitation yet. Patch immediately. Source: BleepingComputer / Fortinet PSIRT Full analysis → t.me/VulnerabilityN… Follow @VulnerabilityNw
English
1
1
1
141