<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Roundup on Black Lantern Security: Crow&#39;s Nest</title>
    <link>https://crowsnest.blacklanternsecurity.com/tags/roundup/</link>
    <description>Recent content in Roundup on Black Lantern Security: Crow&#39;s Nest</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 22 Jun 2026 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://crowsnest.blacklanternsecurity.com/tags/roundup/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Crow&#39;s Nest - 2026-06-22</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-22/</link>
      <pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-22/</guid>
      <description>&lt;p&gt;A roundup of 126 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://x.com/HackingDave/status/2067233153459106140&#34;&gt;Mastra-AI npm Supply Chain Attack Hits 80+ Packages&lt;/a&gt; by Dave Kennedy.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;An attacker hijacked npm accounts to inject a phantom dependency into 80+ Mastra-AI packages. The malicious payload arrived via a &amp;ldquo;dayjs&amp;rdquo; typosquat that ran a post-install script to download and execute a remote binary.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.proofpoint.com/us/blog/threat-insight/sayonara-socgholish-operation-endgame-disrupts-major-cybercrime-operation?amp%3Butm_medium=social_organic&#34;&gt;Operation Endgame Dismantles SocGholish Infrastructure&lt;/a&gt; by &lt;a href=&#34;https://x.com/SwitHak/status/2067866513571246159&#34;&gt;SwitHak ()&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;International law enforcement took down 100 servers and domains, remediating nearly 15,000 websites. SocGholish&amp;rsquo;s &amp;ldquo;FakeUpdates&amp;rdquo; web inject framework has been a persistent ransomware delivery vector since 2018.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Crow&#39;s Nest - 2026-06-15</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-15/</link>
      <pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-15/</guid>
      <description>&lt;p&gt;A roundup of 292 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microso&#34;&gt;Microsoft Packages Laced with Credential Stealer for Second Time in Weeks&lt;/a&gt; by &lt;a href=&#34;https://x.com/Dinosn/status/2064193669918269844&#34;&gt;Nicolas Krassas&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;For the second time in weeks, official Microsoft packages were found laced with credential-stealing malware, raising serious questions about supply chain integrity in the Microsoft ecosystem.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.yahoo.com/news/us/articles/ai-misidentification-results-wrongful-arrest-005933379.html&#34;&gt;AI Misidentification Leads to Wrongful Arrest, Months in Prison&lt;/a&gt; by &lt;a href=&#34;https://x.com/KimZetter/status/2064068610587316273&#34;&gt;Kim Zetter&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;AI facial recognition identified Jalil Richardson with only 85% accuracy. Police never checked his alibi. He spent months in prison and lost his job, home, and child custody before police admitted the AI was wrong.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Crow&#39;s Nest - 2026-06-08</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-08/</link>
      <pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-08/</guid>
      <description>&lt;p&gt;A roundup of 44 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/un-world-food-programme-breach-affect&#34;&gt;UN food agency breach exposes 600,000 Gaza households&lt;/a&gt; by &lt;a href=&#34;https://x.com/Dinosn/status/2062587913443942528&#34;&gt;Nicolas Krassas&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;The UN World Food Programme discloses a data breach affecting 600,000 households in Gaza.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://goo.gle/49HfT8g&#34;&gt;UNC3753 targets US law firms with vishing and physical intrusion&lt;/a&gt; by &lt;a href=&#34;https://x.com/scriptjunkie1/status/2062955335858446570&#34;&gt;scriptjunkie (Matt)&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Mandiant details UNC3753 using vishing and RMM tools for data extortion against US law firms, with some operators attempting in-person theft.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-solarwinds-s&#34;&gt;CISA: SolarWinds Serv-U flaw now actively exploited&lt;/a&gt; by &lt;a href=&#34;https://x.com/BleepinComputer/status/2062976683993383341&#34;&gt;BleepingComputer&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;CISA adds an actively exploited SolarWinds Serv-U vulnerability to the KEV catalog.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Crow&#39;s Nest - 2026-06-04</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-04/</link>
      <pubDate>Thu, 04 Jun 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-06-04/</guid>
      <description>&lt;p&gt;A roundup of 89 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://krebsonsecurity.com/2026/06/hackers-used-metas-ai-support-bot-to-seize-instagram-accounts&#34;&gt;Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts&lt;/a&gt; by BrianKrebs.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Pro-Iran hackers hijacked high-profile Instagram accounts, including the Obama White House, by tricking Meta&amp;rsquo;s AI support bot into resetting passwords with a spoofed hometown IP.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.technadu.com/massive-17-million-device-botnet-in-the-netherlands-dismantled-in-a-police-and-ncsc-joint-operation/628801&#34;&gt;Dutch police dismantle a 17-million-device botnet&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Dutch police and the NCSC dismantled a 17-million-device botnet operating on 200 servers seized from a local hosting provider.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Crow&#39;s Nest - 2026-05-28</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-28/</link>
      <pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-28/</guid>
      <description>&lt;p&gt;A roundup of 82 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://blog.talosintelligence.com/sd-wan-ongoing-exploitation&#34;&gt;Active exploitation of a Cisco Catalyst SD-WAN auth bypass (CVE-2026-20182)&lt;/a&gt; by Cisco Talos.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Talos is tracking in-the-wild exploitation of CVE-2026-20182, an authentication bypass in Cisco Catalyst SD-WAN Manager and Controller.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.thezdi.com/blog/2026/5/16/pwn2own-berlin-2026-day-three-results-and-master-of-pwn&#34;&gt;Pwn2Own Berlin 2026: DEVCORE takes Master of Pwn&lt;/a&gt; by Dustin Childs.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;DEVCORE took Master of Pwn at Pwn2Own Berlin 2026, capping an event that paid $1,298,250 for 47 zero-days. Orange Tsai chained three bugs to RCE as SYSTEM on Exchange for $200,000.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Crow&#39;s Nest - 2026-05-18</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-18/</link>
      <pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-18/</guid>
      <description>&lt;p&gt;A roundup of 44 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.cyera.com/research/bleeding-llama-critical-unauthenticated-memory-leak-in-ollama&#34;&gt;Bleeding Llama: unauthenticated memory leak in Ollama (CVE-2026-7482)&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Cyera Research uncovers a critical pre-auth memory disclosure in Ollama. Self-hosted LLM gateways leak adjacent buffer contents to anyone who can hit the API.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;details markdown=&#34;1&#34;&gt;
&lt;summary&gt;More this week (2)&lt;/summary&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/trellix-source-code-breach-claimed-by-ransomhouse-hackers&#34;&gt;RansomHouse claims Trellix source-code breach&lt;/a&gt; by &lt;a href=&#34;https://x.com/BleepinComputer/status/2052763427966202314&#34;&gt;BleepingComputer&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://www.bleepingcomputer.com/news/security/zara-data-breach-exposed-personal-infor&#34;&gt;Zara data breach exposed 197,000 people&lt;/a&gt; by &lt;a href=&#34;https://x.com/BleepinComputer/status/2052700692716892489&#34;&gt;BleepingComputer&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;/details&gt;
&lt;h2 id=&#34;techniques-and-write-ups&#34;&gt;Techniques and Write-ups&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.zeroday.cloud/blog/mariadb-cve-2026-32710-deep-dive&#34;&gt;MariaDB CVE-2026-32710 deep dive: character-constrained overflow to RCE&lt;/a&gt; by &lt;a href=&#34;https://x.com/kmkz_security/status/2051386774157435177&#34;&gt;kmkz&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Tim Becker walks through the heap-grooming primitive Xint used to turn a character-constrained heap overflow in JSON_SCHEMA_VALID into full RCE. ZeroDay Cloud&amp;rsquo;s deep dive on the bug behind GHSA-4rj5-2227-9wgc.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Crow&#39;s Nest - 2026-05-11</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-11/</link>
      <pubDate>Mon, 11 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-11/</guid>
      <description>&lt;p&gt;A roundup of 54 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://x.com/kmkz_security/status/2052503349107261704&#34;&gt;Apache ActiveMQ CVE-2026-40466 exploited in the wild&lt;/a&gt; by kmkz.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;VulnCheck sees CVE-2026-40466 burning in active campaigns: authenticated RCE in ActiveMQ via the vm:// protocol, a bypass of the original CVE-2026-34197 fix. 2,700+ exposed instances on Shodan.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://blog.kwiatkowski.fr/mythos&#34;&gt;Mythos: a long-form look at the stakes, impact, and PR&lt;/a&gt; by &lt;a href=&#34;https://x.com/mrgretzky/status/2048402750485016759&#34;&gt;Kuba Gretzky&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Ivan Kwiatkowski&amp;rsquo;s deep-dive cuts through weeks of hot takes about Anthropic&amp;rsquo;s Mythos: what the actual capability claims are, what they mean for the bug-finding economy, and what the rollout did to industry trust.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Crow&#39;s Nest - 2026-05-08</title>
      <link>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-08/</link>
      <pubDate>Fri, 08 May 2026 00:00:00 +0000</pubDate>
      <guid>https://crowsnest.blacklanternsecurity.com/posts/crows-nest-2026-05-08/</guid>
      <description>&lt;p&gt;A roundup of 189 items curated from across the security community.&lt;/p&gt;
&lt;h2 id=&#34;news&#34;&gt;News&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://www.schneier.com/blog/archives/2026/04/claude-mythos-has-found-271-zero-days-in-firefox.html&#34;&gt;Claude Mythos Has Found 271 Zero-Days in Firefox&lt;/a&gt; by Bruce Schneier.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;271 Firefox bugs found by Claude Mythos in collaboration with Mozilla. Schneier breaks down the disclosure and what it means for browser security at scale.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://learn.microsoft.com/en-us/defender-endpoint/restrict-response-actions-high-value-assets&#34;&gt;Defender for Endpoint: restrict response actions on high-value assets&lt;/a&gt; by &lt;a href=&#34;https://x.com/PyroTek3/status/2051707239463817401&#34;&gt;Sean Metcalf&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Defender for Endpoint adds a public preview to restrict live response actions on high-value assets. The control SOC analysts running scripts as SYSTEM on tier 0 boxes have been asking for.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
