<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<?xml-stylesheet type="text/xsl" media="screen" href="/~files/feed.xsl"?>
                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:feedpress="https://feed.press/xmlns" xmlns:media="http://search.yahoo.com/mrss/" xmlns:podcast="https://podcastindex.org/namespace/1.0" version="2.0">
  <channel>
    <feedpress:locale>en</feedpress:locale>
    <atom:link rel="via" href="https://crowsnest.blacklanternsecurity.com/index.xml"/>
    <title>Crow's Nest on Black Lantern Security: Crow's Nest</title>
    <link>https://crowsnest.blacklanternsecurity.com/</link>
    <description>Recent content in Crow's Nest on Black Lantern Security: Crow's Nest</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 29 Jul 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://feedpress.me/crowsnest" rel="self" type="application/rss+xml"/>
    <item>
      <title>Crow's Nest - 2026-07-29</title>
      <link>https://feedpress.me/link/24414/17393011/crows-nest-2026-07-29</link>
      <pubDate>Wed, 29 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-07-29/</guid>
      <description><![CDATA[<p>A roundup of 448 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://open.substack.com/pub/blacklanternsecurity/p/cve-2026-12118-ibm-webmethods-integration?r=rbmdk&amp;amp%3Butm_campaign=post&amp;amp%3Butm_medium=web&amp;amp%3BshowWelcomeOnShare=true">CVE-2026-12118: IBM webMethods Integration Server Vulnerability</a>.</li>
</ul>
<blockquote>
<p>Black Lantern Security discovered and reported this vulnerability in IBM webMethods Integration Server. Full technical writeup with reproduction steps.</p>
</blockquote>
<ul>
<li><a href="https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps">LG Bans Residential Proxy Apps from Smart TVs</a>.</li>
</ul>
<blockquote>
<p>Krebs reports LG will suspend smart TV apps that turn televisions into residential proxy nodes. Over 42 percent of webOS store apps were found routing third-party traffic through users&rsquo; devices.</p><img src="https://feedpress.me/link/24414/17393011.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-07-20</title>
      <link>https://feedpress.me/link/24414/17383639/crows-nest-2026-07-20</link>
      <pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-07-20/</guid>
      <description><![CDATA[<p>A roundup of 312 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://www.consilium.europa.eu/en/press/press-releases/2026/07/13/cyber-russia-statement-by-the-high-representative-on-behalf-of-the-european-union-denouncing-russia-s-malicious-cyber-ecosystem-targeting-the-eu-its-member-states-and-international-partners">EU Exposes FSB Centre 16 as Controller of TURLA Operations</a> by <a href="https://x.com/thegrugq/status/2077010596009263451">thaddeus e. grugq</a>.</li>
</ul>
<blockquote>
<p>The EU formally attributes TURLA and related cyber operations to the FSB&rsquo;s 16th Centre, alongside its broadest cyber sanctions package yet targeting Russian-linked actors.</p>
</blockquote>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-july-2026-patch-tuesday-fixes-massive-570-flaws-3-zero-days">Microsoft July Patch Tuesday: Record 570 Flaws, 3 Zero-Days</a> by <a href="https://x.com/BleepinComputer/status/2077092089683198455">BleepingComputer</a>.</li>
</ul>
<blockquote>
<p>The largest Patch Tuesday ever. 570 fixes including 3 zero-days (2 actively exploited) and 141 RCE flaws. Microsoft attributes the surge to AI-assisted vulnerability discovery.</p><img src="https://feedpress.me/link/24414/17383639.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-07-13</title>
      <link>https://feedpress.me/link/24414/17379796/crows-nest-2026-07-13</link>
      <pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-07-13/</guid>
      <description><![CDATA[<p>A roundup of 265 items curated from across the security community.</p>
<blockquote>
<h3 id="bbot-30-rust-powered-recon-with-15x-faster-dns"><a href="https://blog.blacklanternsecurity.com/p/bbot-30">BBOT 3.0: Rust-Powered Recon with 15x Faster DNS</a></h3>
<p>The biggest BBOT release ever. Core DNS and HTTP engines rewritten from scratch in Rust, delivering 15x faster DNS resolution and FFUF-class directory brute-forcing without leaving the BBOT process. New modules, native SIEM outputs, ASN targeting via the BBOT.IO API Hub, and reworked scoping. Free and open source.</p>
<p><a href="https://blog.blacklanternsecurity.com/p/bbot-30">Read more</a></p>
</blockquote>
<h2 id="news">News</h2>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/japanese-telecom-giant-kddi-says-data-breach-affects-12-million-people">KDDI Breach Exposes Data of 12 Million Japanese Customers</a> by <a href="https://x.com/BleepinComputer/status/2074816901771878613">BleepingComputer</a>.</li>
</ul>
<blockquote>
<p>Japanese telecom giant KDDI confirms a data breach affecting 12 million customer records, one of the largest telecommunications breaches in recent years.</p><img src="https://feedpress.me/link/24414/17379796.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-07-06</title>
      <link>https://feedpress.me/link/24414/17373874/crows-nest-2026-07-06</link>
      <pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-07-06/</guid>
      <description><![CDATA[<p>A roundup of 160 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://www.ic3.gov/CSA/2026/260702.pdf">FBI PSA: TeamPCP Data Extortion Group Behind Longest Supply-Chain Hack Streak</a>.</li>
</ul>
<blockquote>
<p>FBI releases a PSA on TeamPCP, a data extortion group responsible for the longest running streak of software supply-chain hacks on record, including compromises of Trivy, CheckMarx, LiteLLM, and at least 3,800 GitHub repositories.</p>
</blockquote>
<ul>
<li><a href="https://www.zetter-zeroday.com/arrest-of-iranian-hacker-spotlights-irans-movement-into-economic-espionage-and-ip-theft">Iranian Hacker Arrested for IRGC-Backed University IP Theft Campaign</a> by <a href="https://x.com/KimZetter/status/2072279630929600929">Kim Zetter</a>.</li>
</ul>
<blockquote>
<p>An Iranian hacker arrested in Montenegro for hacking over 100 US universities on behalf of the IRGC highlights Iran&rsquo;s shift toward economic espionage and intellectual property theft.</p><img src="https://feedpress.me/link/24414/17373874.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-07-02</title>
      <link>https://feedpress.me/link/24414/17373004/crows-nest-2026-07-02</link>
      <pubDate>Thu, 02 Jul 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-07-02/</guid>
      <description><![CDATA[<p>A roundup of 277 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial">Scattered Spider Hackers Plead Guilty on Day 1 of Trial https://krebsonsecurity.com/2026/06/scattered-spider-hackers-plead-guilty-on-day-1-of-trial/</a> by <a href="https://x.com/Dinosn/status/2069465127414309308">Nicolas Krassas</a>.</li>
</ul>
<blockquote>
<p>Multiple Scattered Spider members plead guilty on the first day of their federal trial.</p>
</blockquote>
<ul>
<li><a href="https://autodoc.bearblog.dev/last-week-i-told-you-to-check-provenance-heres-the-attack-that-breaks-that-advice">TanStack npm Supply Chain Attack Bypasses SLSA Provenance Verification</a>.</li>
</ul>
<blockquote>
<p>42 TanStack packages published with valid SLSA provenance by stealing OIDC tokens from GitHub Actions runner memory. Provenance verification alone no longer guarantees integrity.</p><img src="https://feedpress.me/link/24414/17373004.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-06-22</title>
      <link>https://feedpress.me/link/24414/17373005/crows-nest-2026-06-22</link>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-22/</guid>
      <description><![CDATA[<p>A roundup of 126 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://x.com/HackingDave/status/2067233153459106140">Mastra-AI npm Supply Chain Attack Hits 80+ Packages</a> by Dave Kennedy.</li>
</ul>
<blockquote>
<p>An attacker hijacked npm accounts to inject a phantom dependency into 80+ Mastra-AI packages. The malicious payload arrived via a &ldquo;dayjs&rdquo; typosquat that ran a post-install script to download and execute a remote binary.</p>
</blockquote>
<ul>
<li><a href="https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation?amp%3Butm_medium=social_organic">Operation Endgame Dismantles SocGholish Infrastructure</a> by <a href="https://x.com/SwitHak/status/2067866513571246159">SwitHak ()</a>.</li>
</ul>
<blockquote>
<p>International law enforcement took down 100 servers and domains, remediating nearly 15,000 websites. SocGholish&rsquo;s &ldquo;FakeUpdates&rdquo; web inject framework has been a persistent ransomware delivery vector since 2018.</p><img src="https://feedpress.me/link/24414/17373005.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-06-15</title>
      <link>https://feedpress.me/link/24414/17373006/crows-nest-2026-06-15</link>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-15/</guid>
      <description><![CDATA[<p>A roundup of 292 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microso">Microsoft Packages Laced with Credential Stealer for Second Time in Weeks</a> by <a href="https://x.com/Dinosn/status/2064193669918269844">Nicolas Krassas</a>.</li>
</ul>
<blockquote>
<p>For the second time in weeks, official Microsoft packages were found laced with credential-stealing malware, raising serious questions about supply chain integrity in the Microsoft ecosystem.</p>
</blockquote>
<ul>
<li><a href="https://www.yahoo.com/news/us/articles/ai-misidentification-results-wrongful-arrest-005933379.html">AI Misidentification Leads to Wrongful Arrest, Months in Prison</a> by <a href="https://x.com/KimZetter/status/2064068610587316273">Kim Zetter</a>.</li>
</ul>
<blockquote>
<p>AI facial recognition identified Jalil Richardson with only 85% accuracy. Police never checked his alibi. He spent months in prison and lost his job, home, and child custody before police admitted the AI was wrong.</p><img src="https://feedpress.me/link/24414/17373006.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-06-08</title>
      <link>https://feedpress.me/link/24414/17373007/crows-nest-2026-06-08</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-08/</guid>
      <description><![CDATA[<p>A roundup of 44 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affect">UN food agency breach exposes 600,000 Gaza households</a> by <a href="https://x.com/Dinosn/status/2062587913443942528">Nicolas Krassas</a>.</li>
</ul>
<blockquote>
<p>The UN World Food Programme discloses a data breach affecting 600,000 households in Gaza.</p>
</blockquote>
<ul>
<li><a href="https://goo.gle/49HfT8g">UNC3753 targets US law firms with vishing and physical intrusion</a> by <a href="https://x.com/scriptjunkie1/status/2062955335858446570">scriptjunkie (Matt)</a>.</li>
</ul>
<blockquote>
<p>Mandiant details UNC3753 using vishing and RMM tools for data extortion against US law firms, with some operators attempting in-person theft.</p>
</blockquote>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-s">CISA: SolarWinds Serv-U flaw now actively exploited</a> by <a href="https://x.com/BleepinComputer/status/2062976683993383341">BleepingComputer</a>.</li>
</ul>
<blockquote>
<p>CISA adds an actively exploited SolarWinds Serv-U vulnerability to the KEV catalog.</p><img src="https://feedpress.me/link/24414/17373007.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-06-04</title>
      <link>https://feedpress.me/link/24414/17373008/crows-nest-2026-06-04</link>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-04/</guid>
      <description><![CDATA[<p>A roundup of 89 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts">Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts</a> by BrianKrebs.</li>
</ul>
<blockquote>
<p>Pro-Iran hackers hijacked high-profile Instagram accounts, including the Obama White House, by tricking Meta&rsquo;s AI support bot into resetting passwords with a spoofed hometown IP.</p>
</blockquote>
<ul>
<li><a href="https://www.technadu.com/massive-17-million-device-botnet-in-the-netherlands-dismantled-in-a-police-and-ncsc-joint-operation/628801">Dutch police dismantle a 17-million-device botnet</a>.</li>
</ul>
<blockquote>
<p>Dutch police and the NCSC dismantled a 17-million-device botnet operating on 200 servers seized from a local hosting provider.</p><img src="https://feedpress.me/link/24414/17373008.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-05-28</title>
      <link>https://feedpress.me/link/24414/17373009/crows-nest-2026-05-28</link>
      <pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-28/</guid>
      <description><![CDATA[<p>A roundup of 82 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://blog.talosintelligence.com/sd-wan-ongoing-exploitation">Active exploitation of a Cisco Catalyst SD-WAN auth bypass (CVE-2026-20182)</a> by Cisco Talos.</li>
</ul>
<blockquote>
<p>Talos is tracking in-the-wild exploitation of CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Manager and Controller.</p>
</blockquote>
<ul>
<li><a href="https://www.thezdi.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn">Pwn2Own Berlin 2026: DEVCORE takes Master of Pwn</a> by Dustin Childs.</li>
</ul>
<blockquote>
<p>DEVCORE took Master of Pwn at Pwn2Own Berlin 2026, capping an event that paid $1,298,250 for 47 zero-days. Orange Tsai chained three bugs to RCE as SYSTEM on Exchange for $200,000.</p><img src="https://feedpress.me/link/24414/17373009.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-05-18</title>
      <link>https://feedpress.me/link/24414/17373010/crows-nest-2026-05-18</link>
      <pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-18/</guid>
      <description><![CDATA[<p>A roundup of 44 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama">Bleeding Llama: unauthenticated memory leak in Ollama (CVE-2026-7482)</a>.</li>
</ul>
<blockquote>
<p>Cyera Research uncovers a critical pre-auth memory disclosure in Ollama. Self-hosted LLM gateways leak adjacent buffer contents to anyone who can hit the API.</p>
</blockquote>
<details markdown="1">
<summary>More this week (2)</summary>
<ul>
<li><a href="https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers">RansomHouse claims Trellix source-code breach</a> by <a href="https://x.com/BleepinComputer/status/2052763427966202314">BleepingComputer</a>.</li>
<li><a href="https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-infor">Zara data breach exposed 197,000 people</a> by <a href="https://x.com/BleepinComputer/status/2052700692716892489">BleepingComputer</a>.</li>
</ul>
</details>
<h2 id="techniques-and-write-ups">Techniques and Write-ups</h2>
<ul>
<li><a href="https://www.zeroday.cloud/blog/mariadb-cve-2026-32710-deep-dive">MariaDB CVE-2026-32710 deep dive: character-constrained overflow to RCE</a> by <a href="https://x.com/kmkz_security/status/2051386774157435177">kmkz</a>.</li>
</ul>
<blockquote>
<p>Tim Becker walks through the heap-grooming primitive Xint used to turn a character-constrained heap overflow in JSON_SCHEMA_VALID into full RCE. ZeroDay Cloud&rsquo;s deep dive on the bug behind GHSA-4rj5-2227-9wgc.</p><img src="https://feedpress.me/link/24414/17373010.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-05-11</title>
      <link>https://feedpress.me/link/24414/17373011/crows-nest-2026-05-11</link>
      <pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-11/</guid>
      <description><![CDATA[<p>A roundup of 54 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://x.com/kmkz_security/status/2052503349107261704">Apache ActiveMQ CVE-2026-40466 exploited in the wild</a> by kmkz.</li>
</ul>
<blockquote>
<p>VulnCheck sees CVE-2026-40466 burning in active campaigns: authenticated RCE in ActiveMQ via the vm:// protocol, a bypass of the original CVE-2026-34197 fix. 2,700+ exposed instances on Shodan.</p>
</blockquote>
<ul>
<li><a href="https://blog.kwiatkowski.fr/mythos">Mythos: a long-form look at the stakes, impact, and PR</a> by <a href="https://x.com/mrgretzky/status/2048402750485016759">Kuba Gretzky</a>.</li>
</ul>
<blockquote>
<p>Ivan Kwiatkowski&rsquo;s deep-dive cuts through weeks of hot takes about Anthropic&rsquo;s Mythos: what the actual capability claims are, what they mean for the bug-finding economy, and what the rollout did to industry trust.</p><img src="https://feedpress.me/link/24414/17373011.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Crow's Nest - 2026-05-08</title>
      <link>https://feedpress.me/link/24414/17373012/crows-nest-2026-05-08</link>
      <pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-08/</guid>
      <description><![CDATA[<p>A roundup of 189 items curated from across the security community.</p>
<h2 id="news">News</h2>
<ul>
<li><a href="https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html">Claude Mythos Has Found 271 Zero-Days in Firefox</a> by Bruce Schneier.</li>
</ul>
<blockquote>
<p>271 Firefox bugs found by Claude Mythos in collaboration with Mozilla. Schneier breaks down the disclosure and what it means for browser security at scale.</p>
</blockquote>
<ul>
<li><a href="https://learn.microsoft.com/en-us/defender-endpoint/restrict-response-actions-high-value-assets">Defender for Endpoint: restrict response actions on high-value assets</a> by <a href="https://x.com/PyroTek3/status/2051707239463817401">Sean Metcalf</a>.</li>
</ul>
<blockquote>
<p>Defender for Endpoint adds a public preview to restrict live response actions on high-value assets. The control SOC analysts running scripts as SYSTEM on tier 0 boxes have been asking for.</p><img src="https://feedpress.me/link/24414/17373012.gif" height="1" width="1"/>]]></description>
    </item>
    <item>
      <title>Welcome to the Crow's Nest</title>
      <link>https://feedpress.me/link/24414/17373013/welcome</link>
      <pubDate>Wed, 06 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/welcome/</guid>
      <description><![CDATA[<p>Welcome aboard. <strong>Crow&rsquo;s Nest</strong> is a curated roundup of security news, techniques, tools, and exploits, published by <a href="https://www.blacklanternsecurity.com">Black Lantern Security</a>.</p>
<h2 id="what-you-can-expect">What You Can Expect</h2>
<p>Each edition will cover:</p>
<ul>
<li><strong>News</strong>: meaningful security news from across the community.</li>
<li><strong>Techniques and Write-ups</strong>: interesting research, blog posts, and analyses.</li>
<li><strong>Tools and Exploits</strong>: new offensive and defensive tooling, PoCs, and exploits.</li>
</ul>
<p>An editor reads and selects every item that lands here. Automation handles the heavy lifting of scraping feeds and keeping tabs on the community, but every post is curated by hand. New editions land when there is enough worth covering, not on a fixed schedule.</p><img src="https://feedpress.me/link/24414/17373013.gif" height="1" width="1"/>]]></description>
    </item>
  </channel>
</rss>
