Cybersecurity
When the internet’s plumbing catches fire
NFCShare Android Malware Steals Your Credit Card by Asking You to Tap It — 56 Fake Banking Apps on GitHub Would Like to Verify Your Identity and Your PIN
🤚 The Open-Palm Tap A new Android trojan called NFCShare would like you to hold your credit card against your phone for “security verification.” It…
Read moreThe C0XMO Botnet Exploits a Five-Year-Old DD-WRT Vulnerability, Supports Seven Architectures, and Murders Every Rival Botnet on Your Router — Your Firmware Update Can Wait, Said Nobody Ever
A new botnet variant called C0XMO is exploiting a five-year-old vulnerability in DD-WRT router firmware to compromise devices across seven CPU architectures — and its…
Read moreA Magecart Campaign Is Using Stripe’s Own API to Steal and Store Credit Card Data — Your Content Security Policy Is the Accomplice
🤚 The Open-Palm Transaction A new Magecart credit card theft campaign has achieved something genuinely elegant in the annals of cybercrime: it is using Stripe’s…
Read moreCisco Discloses an Unpatched SD-WAN Zero-Day That Gives Attackers Root Access and the Patch Timeline Is ‘We’re Working on It’ — Your Network Management Plane Just Became the Threat Surface
🤚 The Open-Palm Advisory Cisco has disclosed CVE-2026-20245, a zero-day vulnerability in Catalyst SD-WAN Manager that allows attackers to escalate privileges to root — the…
Read moreAnthropic Open-Sources the Glasswing Vulnerability Discovery Pipeline — Your Autonomous Pentest Team Is Now a Git Clone Away
🤚 The Open-Palm Repository Remember Project Glasswing, the initiative where Anthropic pointed its most powerful model at open-source software and it found over 10,000 high-…
Read moreThe HTTP/2 Bomb Can Crash Any Web Server on Earth in Ten Seconds — An AI Agent Found the Vulnerability, the Exploit Is on GitHub, and Two Out of Five Platforms Have No Patch
🤚 The Open-Palm Incident Report A new denial-of-service attack called the “HTTP/2 Bomb” can crash a web server with 32 gigabytes of RAM in under…
Read moreWindows Netlogon Has a CVSS 9.8 Remote Code Execution Bug and Belgium Says It’s Already Being Exploited — Microsoft Says It Sees Nothing, Your Domain Controller Has No Comment
🤚 The Open-Palm Incident Report A critical vulnerability in Windows Netlogon — the service that handles authentication for every Windows domain controller on Earth —…
Read moreThe Shai Hulud Supply Chain Worm Has a Sequel Called ‘Miasma’ and It Just Compromised 32 Official Red Hat npm Packages — Your Dependency Tree Now Has a Franchise Problem
🤚 The Open-Palm Infection Report Remember Shai Hulud? The supply chain worm that compromised hundreds of signed npm and PyPI packages back in May and…
Read morePalo Alto GlobalProtect VPN Was Trusting Forged Cookies Without Checking the Signature — The CISA Deadline Is Today and Your Perimeter Just Filed Its Second Incident Report This Year
🤚 The Open-Palm Advisory Palo Alto Networks has confirmed that CVE-2026-0257, an authentication bypass in its GlobalProtect VPN, is being actively exploited in the wild.…
Read moreA SpaceX Engineer Found a Linux Kernel Bug That’s Been Giving Root Since 2007 — Your Server Has Been Running an Open-Door Policy Longer Than Most of Your Employees Have Been Alive
🤚 The Open-Palm Disclosure A SpaceX security engineer named Asim Viladi Oglu Manizada has published a vulnerability he’s calling “CIFSwitch” — a local privilege escalation…
Read more