Cybersecurity

When the internet’s plumbing catches fire

Cisco Discloses an Unpatched SD-WAN Zero-Day That Gives Attackers Root Access and the Patch Timeline Is ‘We’re Working on It’ — Your Network Management Plane Just Became the Threat Surface

🤚 The Open-Palm Advisory Cisco has disclosed CVE-2026-20245, a zero-day vulnerability in Catalyst SD-WAN Manager that allows attackers to escalate privileges to root — the…

Read more

Anthropic Open-Sources the Glasswing Vulnerability Discovery Pipeline — Your Autonomous Pentest Team Is Now a Git Clone Away

🤚 The Open-Palm Repository Remember Project Glasswing, the initiative where Anthropic pointed its most powerful model at open-source software and it found over 10,000 high-…

Read more

The HTTP/2 Bomb Can Crash Any Web Server on Earth in Ten Seconds — An AI Agent Found the Vulnerability, the Exploit Is on GitHub, and Two Out of Five Platforms Have No Patch

🤚 The Open-Palm Incident Report A new denial-of-service attack called the “HTTP/2 Bomb” can crash a web server with 32 gigabytes of RAM in under…

Read more

Windows Netlogon Has a CVSS 9.8 Remote Code Execution Bug and Belgium Says It’s Already Being Exploited — Microsoft Says It Sees Nothing, Your Domain Controller Has No Comment

🤚 The Open-Palm Incident Report A critical vulnerability in Windows Netlogon — the service that handles authentication for every Windows domain controller on Earth —…

Read more

The Shai Hulud Supply Chain Worm Has a Sequel Called ‘Miasma’ and It Just Compromised 32 Official Red Hat npm Packages — Your Dependency Tree Now Has a Franchise Problem

🤚 The Open-Palm Infection Report Remember Shai Hulud? The supply chain worm that compromised hundreds of signed npm and PyPI packages back in May and…

Read more

Palo Alto GlobalProtect VPN Was Trusting Forged Cookies Without Checking the Signature — The CISA Deadline Is Today and Your Perimeter Just Filed Its Second Incident Report This Year

🤚 The Open-Palm Advisory Palo Alto Networks has confirmed that CVE-2026-0257, an authentication bypass in its GlobalProtect VPN, is being actively exploited in the wild.…

Read more

A SpaceX Engineer Found a Linux Kernel Bug That’s Been Giving Root Since 2007 — Your Server Has Been Running an Open-Door Policy Longer Than Most of Your Employees Have Been Alive

🤚 The Open-Palm Disclosure A SpaceX security engineer named Asim Viladi Oglu Manizada has published a vulnerability he’s calling “CIFSwitch” — a local privilege escalation…

Read more

California Sues 23andMe for Losing 6.9 Million People’s DNA — The Company Changed Its Name to ‘Chrome Holding Co.’ Which Is Exactly What an Innocent Company Would Do

🤚 The Open-Palm Subpoena California Attorney General Rob Bonta has filed suit against 23andMe — or rather, against the corporate husk now operating under the…

Read more

ChatGPT’s Share Link Feature Is Now a Malware Distribution Network — The Chatbot Impersonated Its Own Outage to Install an Infostealer, and the URL Was Legitimate the Entire Time

🤚 The Open-Palm Incident Report Threat actors have discovered that ChatGPT’s share link feature — the one that lets you send a conversation to a…

Read more

Carnival Cruise Loses Six Million Customer Records to ShinyHunters Because Someone Answered the Phone — The Company’s Fourth Breach Since 2020 Suggests the Loyalty Program Extends to Threat Actors

🤚 The Open-Palm Damage Report In what is becoming a disturbingly reliable annual tradition, Carnival Corporation — operator of the world’s largest cruise fleet —…

Read more