CyberScroll

Your space

Phantom theme

CyberScroll

Your feed

Security, technology & research

Auto-updating

Latest stories 0

Cyber Security Dog: Vault ACL policy evaluation vulnerability may bypass access denial restrictions (10.08)

Vault and Vault Enterprise expose a high-severity ACL policy evaluation flaw (CVE-2026-89322) that can bypass explicit deny rules, enabling privilege escalation.

cn-sec.com·29 minutes agoVulnerability Management

Vault and Vault Enterprise expose a high-severity ACL policy evaluation flaw (CVE-2026-89322) that can bypass explicit deny rules, enabling privilege escalation. Patches exist in multiple release lines (2.1.2, 1.21.12, 1.20.17, 1.19.23); surrounding coverage includes related AsyncHttpClient vulnerabilities (CVE-2026-107279/107281/107282/107230) and notable security events (MonsterCloud ransom payments, Qilin extradition, Trump Mobile data claim, ASOS data exposure).

Vulnerability ManagementThreatsMalware Analysis
Read full article

Fix it as soon as possible! Atlassian Jira unauthenticated arbitrary file read vulnerability.

Unauthenticated arbitrary file read in Atlassian Jira and eight other products via atlassian-plugins-webresource.

cn-sec.com·33 minutes agoVulnerability Management

Unauthenticated arbitrary file read in Atlassian Jira and eight other products via atlassian-plugins-webresource. Attack chained to read Tomcat webroot and, in Crowd deployments, to read credentials and create an admin account; PoC exists and advisories urge immediate upgrade.

Vulnerability ManagementCveThreatsMalware Analysis
Read full article

Weaponization development of a C2 reflective DLL plugin.

Weaponized reflective DLLs enable in-memory execution of DLL code without dropping to disk, using a mini PE loader (ReflectiveLoader) to map sections, resolve imports, apply relocations, and call DllMain.

cn-sec.com·34 minutes agoMalware Analysis

Weaponized reflective DLLs enable in-memory execution of DLL code without dropping to disk, using a mini PE loader (ReflectiveLoader) to map sections, resolve imports, apply relocations, and call DllMain. The workflow leverages C2-delivered reflective DLLs for pop-up windows and privilege escalation via BYPASS UAC, enabling one-click weaponization of common elevation tools by compiling them as reflective DLL plugins.

Malware AnalysisTechnicalResearch
Read full article

BRuteLogic Disclosure: Prototype pollution in EJS < v6.0.0-alpha can lead to RCE.

Prototype pollution in EJS before v6.0.0-alpha enables remote code execution (RCE) by polluting Object.prototype through unsafe recursive merge of user input into EJS options.

cn-sec.com·36 minutes agoTechnical

Prototype pollution in EJS before v6.0.0-alpha enables remote code execution (RCE) by polluting Object.prototype through unsafe recursive merge of user input into EJS options. The attacker injects __proto__ payload via /api/config, causing EJS to inherit polluted client and escapeFunction values, which are then executed server-side during template rendering. Official fix arrives with EJS 6.0.0-alpha+ (6.0.1 released later), highlighting risk for many Node.js apps still on 3.x/4.x/5.x lines.

TechnicalVulnerability ManagementThreatsResearchMalware Analysis
Read full article

Open Source Report: Xini Capital and the U.S. Treasury's plan for overseas expansion.

Mercuria-backed Heeney Capital assembles a cross-border asset-and-trade system to seed US critical mineral supply chains via VaultCo, linking front-facing investment shells to four anchor traders (Mercuria, Glencore, Traxys, Hartree) and a growing set of overseas assets (Zanaga iron ore, Siguiri gold, Antilla copper, Venalum aluminum, PIM III gold, Pinnacle steel/vanadium, Mayfair Gold).

cn-sec.com·37 minutes agoResearch

Mercuria-backed Heeney Capital assembles a cross-border asset-and-trade system to seed US critical mineral supply chains via VaultCo, linking front-facing investment shells to four anchor traders (Mercuria, Glencore, Traxys, Hartree) and a growing set of overseas assets (Zanaga iron ore, Siguiri gold, Antilla copper, Venalum aluminum, PIM III gold, Pinnacle steel/vanadium, Mayfair Gold). The arrangement hinges on EXIM financing, private equity, and strategic off-take contracts that push Western-market priority procurement, with Venezuela and Trinidad projects highlighting geopolitical risk and governance concerns. The narrative exposes a replicable model for integrating foreign mineral assets into US supply chains while raising questions about oversight, source diversification, and long-term sustainability.

ResearchThreatsMalware Analysis
Read full article