This day 02:10 06:01 10:01 14:02 18:01 22:02
Info  2026-09-28 14:02Z · last 4h · 16 findings · glm-5.2:cloud

Threat Brief — 2026-09-28 — Cloud principals, proxy sprawl, repo domains

Executive summary

A destructive Azure campaign attributed to JADEPUFFER demonstrates how compromised service principals can be weaponised to delete cloud resources — a reminder that machine identities remain a prime attack surface. Separately, 737 Chrome VPN extensions were revealed as a single covert proxy network, and a domain referenced by 1,700+ code repositories has been turned into an active Windows attack vector. OnePlus has escalated its unpatched root-chain story by threatening the discovering researcher with legal action, raising concerns about vulnerability disclosure suppression.

Top items

Themes

Machine-identity abuse in the cloud. JADEPUFFER's use of compromised service principals follows a well-established pattern but remains under-defended; service principals frequently hold standing privileged access with weaker monitoring than human accounts.

Benign infrastructure weaponised. Both the Chrome extension proxy network and the repurposed repository domain illustrate how trust accumulated over time — extension marketplace listings, long-standing code dependencies — can be flipped into attack infrastructure with minimal warning.

Disclosure suppression. OnePlus's legal threat against a vulnerability researcher signals that vendor response to security findings can shift from remediation to intimidation, potentially leaving critical flaws unpatched and undisclosed.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db