<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Exploit on Tenu Tech Brief</title>
    <link>https://cluster-site.onrender.com/tags/exploit/</link>
    <description>Recent content in Exploit on Tenu Tech Brief</description>
    <generator>Hugo -- 0.146.0</generator>
    <language>en-us</language>
    <lastBuildDate>Thu, 26 Feb 2026 01:41:33 +0000</lastBuildDate>
    <atom:link href="https://cluster-site.onrender.com/tags/exploit/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>An Exploit ... in CSS?!</title>
      <link>https://cluster-site.onrender.com/posts/an-exploit-...-in-css/</link>
      <pubDate>Wed, 25 Feb 2026 21:31:39 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/an-exploit-...-in-css/</guid>
      <description>• Ok, take a deep breath • We&amp;rsquo;ll have some fun understanding this vulnerability once you make sure your browser isn&amp;rsquo;t affected, using the table below • Chromium-based browser | Am</description>
    </item>
    <item>
      <title>Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker</title>
      <link>https://cluster-site.onrender.com/posts/ex-l3harris-exec-jailed-for-selling-zero-days-to-russian-exploit-broker/</link>
      <pubDate>Wed, 25 Feb 2026 08:21:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ex-l3harris-exec-jailed-for-selling-zero-days-to-russian-exploit-broker/</guid>
      <description>• Ex-L3Harris exec jailed for selling zero-days to Russian exploit broker February 25, 2026 03:21 AM 0 The former head of Trenchant, a specialized U.S. • defense contractor unit, w</description>
    </item>
    <item>
      <title>Millions in crypto funded tools to exploit U.S. software, Treasury says in new sanctions</title>
      <link>https://cluster-site.onrender.com/posts/millions-in-crypto-funded-tools-to-exploit-u.s.-software-treasury-says-in-new-sanctions/</link>
      <pubDate>Tue, 24 Feb 2026 19:48:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/millions-in-crypto-funded-tools-to-exploit-u.s.-software-treasury-says-in-new-sanctions/</guid>
      <description>• Millions in crypto funded tools to exploit U.S. • software, Treasury says in new sanctions An Australian national was said to sell cyber tools designed for the U.S. • government</description>
    </item>
    <item>
      <title>The top 5 sources of secret sprawl, and how attackers exploit them</title>
      <link>https://cluster-site.onrender.com/posts/the-top-5-sources-of-secret-sprawl-and-how-attackers-exploit-them/</link>
      <pubDate>Tue, 24 Feb 2026 00:31:40 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-top-5-sources-of-secret-sprawl-and-how-attackers-exploit-them/</guid>
      <description>• The top 5 sources of secret sprawl, and how attackers exploit them Chandni Patel Risk &amp;amp; compliance Secrets &amp;amp; identity management Vault Radar Jan 28, 2026 Chandni Patel Share arti</description>
    </item>
    <item>
      <title>Wormable XMRig Campaign Uses BYOVD Exploit and Time-Based Logic Bomb</title>
      <link>https://cluster-site.onrender.com/posts/wormable-xmrig-campaign-uses-byovd-exploit-and-time-based-logic-bomb/</link>
      <pubDate>Mon, 23 Feb 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/wormable-xmrig-campaign-uses-byovd-exploit-and-time-based-logic-bomb/</guid>
      <description>• Cybersecurity researchers have disclosed details of a new cryptojacking campaign that uses pirated software bundles as lures to deploy a bespoke XMRig miner program on compromise</description>
    </item>
    <item>
      <title>IoTeX hit by private key exploit draining around $2 million from bridge contracts, per co-founder</title>
      <link>https://cluster-site.onrender.com/posts/iotex-hit-by-private-key-exploit-draining-around-2-million-from-bridge-contracts-per-co-founder/</link>
      <pubDate>Sat, 21 Feb 2026 17:17:22 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/iotex-hit-by-private-key-exploit-draining-around-2-million-from-bridge-contracts-per-co-founder/</guid>
      <description>• IoTeX co-founder Raullen Chai said losses are &amp;lsquo;significantly lower&amp;rsquo; than circulating estimates, but has not provided a specific figure.</description>
    </item>
    <item>
      <title>How AI is helping retail traders exploit prediction market &#39;glitches&#39; to make easy money</title>
      <link>https://cluster-site.onrender.com/posts/how-ai-is-helping-retail-traders-exploit-prediction-market-glitches-to-make-easy-money/</link>
      <pubDate>Sat, 21 Feb 2026 15:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/how-ai-is-helping-retail-traders-exploit-prediction-market-glitches-to-make-easy-money/</guid>
      <description>• How AI is helping retail traders exploit prediction market &amp;lsquo;glitches&amp;rsquo; to make easy money A fully automated bot quietly captured micro-arbitrage opportunities on short-term crypto</description>
    </item>
    <item>
      <title>LA County sues Roblox over &#39;business practices that endanger and exploit children&#39;</title>
      <link>https://cluster-site.onrender.com/posts/la-county-sues-roblox-over-business-practices-that-endanger-and-exploit-children/</link>
      <pubDate>Fri, 20 Feb 2026 17:12:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/la-county-sues-roblox-over-business-practices-that-endanger-and-exploit-children/</guid>
      <description>• Business News LA County sues Roblox over &amp;lsquo;business practices that endanger and exploit children&amp;rsquo; The suit alleges that Roblox failed to protect children from predatory behavior.</description>
    </item>
    <item>
      <title>Update: LA County sues Roblox over &#39;business practices that endanger and exploit children&#39;</title>
      <link>https://cluster-site.onrender.com/posts/update-la-county-sues-roblox-over-business-practices-that-endanger-and-exploit-children/</link>
      <pubDate>Fri, 20 Feb 2026 17:12:15 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/update-la-county-sues-roblox-over-business-practices-that-endanger-and-exploit-children/</guid>
      <description>• Business News Update: LA County sues Roblox over &amp;lsquo;business practices that endanger and exploit children&amp;rsquo; The suit alleges that Roblox failed to protect children from predatory be</description>
    </item>
    <item>
      <title>The top 5 sources of secret sprawl, and how attackers exploit them</title>
      <link>https://cluster-site.onrender.com/posts/the-top-5-sources-of-secret-sprawl-and-how-attackers-exploit-them/</link>
      <pubDate>Thu, 19 Feb 2026 00:46:24 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/the-top-5-sources-of-secret-sprawl-and-how-attackers-exploit-them/</guid>
      <description>• The top 5 sources of secret sprawl, and how attackers exploit them Chandni Patel Risk &amp;amp; compliance Secrets &amp;amp; identity management Vault Radar Jan 28, 2026 Chandni Patel Share arti</description>
    </item>
    <item>
      <title>Telegram channels expose rapid weaponization of SmarterMail flaws</title>
      <link>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</link>
      <pubDate>Wed, 18 Feb 2026 16:27:38 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/telegram-channels-expose-rapid-weaponization-of-smartermail-flaws/</guid>
      <description>• SmarterMail CVE-2026-24423 and CVE-2026-23760 enable remote code execution and auth bypass. • Attackers weaponized these flaws within days of disclosure, sharing exploits on Tele</description>
    </item>
    <item>
      <title>Moonwell hit by $1.78M exploit as AI vibe coding debate reaches DeFi</title>
      <link>https://cluster-site.onrender.com/posts/moonwell-hit-by-1.78m-exploit-as-ai-vibe-coding-debate-reaches-defi/</link>
      <pubDate>Wed, 18 Feb 2026 13:04:46 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/moonwell-hit-by-1.78m-exploit-as-ai-vibe-coding-debate-reaches-defi/</guid>
      <description>• Moonwell hit by $1.78M exploit as AI vibe coding debate reaches DeFi The exploit saw the Moonwell protocol exploited for $1.78 million after cbETH was mispriced at $1.12 instead</description>
    </item>
    <item>
      <title>Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again</title>
      <link>https://cluster-site.onrender.com/posts/ivanti-epmm-zero-day-bugs-spark-exploit-frenzy-again/</link>
      <pubDate>Thu, 12 Feb 2026 22:05:32 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/ivanti-epmm-zero-day-bugs-spark-exploit-frenzy-again/</guid>
      <description>• Endpoint Security Cyberattacks &amp;amp; Data Breaches Vulnerabilities &amp;amp; Threats Perimeter News Ivanti EPMM Zero-Day Bugs Spark Exploit Frenzy - Again It&amp;rsquo;s time to phase out the &amp;lsquo;patch a</description>
    </item>
    <item>
      <title>Nation-State Actors Exploit Notepad&#43;&#43; Supply Chain</title>
      <link>https://cluster-site.onrender.com/posts/nation-state-actors-exploit-notepad-supply-chain/</link>
      <pubDate>Wed, 11 Feb 2026 23:00:54 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/nation-state-actors-exploit-notepad-supply-chain/</guid>
      <description>• Executive Summary Between June and December 2025, the official hosting infrastructure for the text editor Notepad++ was compromised by a state-sponsored threat group known as Lot</description>
    </item>
    <item>
      <title>Breaking the Sound Barrier, Part II: Exploiting CVE-2024-54529</title>
      <link>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</link>
      <pubDate>Fri, 30 Jan 2026 08:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/breaking-the-sound-barrier-part-ii-exploiting-cve-2024-54529/</guid>
      <description>• CVE-2024-54529: type confusion in CoreAudio&amp;rsquo;s com.apple.audio.audiohald Mach service, causing crashes. • Exploitation involved manipulating Mach messages to fetch wrong HALS_Obje</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</link>
      <pubDate>Wed, 14 Jan 2026 18:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</guid>
      <description>• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 2: Cracking the Sandbox with a Big Wave</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</link>
      <pubDate>Wed, 14 Jan 2026 18:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-2-cracking-the-sandbox-with-a-big-wave/</guid>
      <description>• With the advent of a potential Dolby Unified Decoder RCE exploit, it seemed prudent to see what kind of Linux kernel drivers might be accessible from the resulting userland conte</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</link>
      <pubDate>Wed, 14 Jan 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</guid>
      <description>• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change</description>
    </item>
    <item>
      <title>A 0-click exploit chain for the Pixel 9 Part 1: Decoding Dolby</title>
      <link>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</link>
      <pubDate>Wed, 14 Jan 2026 17:59:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-0-click-exploit-chain-for-the-pixel-9-part-1-decoding-dolby/</guid>
      <description>• Over the past few years, several AI-powered features have been added to mobile phones that allow users to better search and understand their messages. • One effect of this change</description>
    </item>
    <item>
      <title>Multiple Threat Actors Exploit React2Shell (CVE-2025-55182)</title>
      <link>https://cluster-site.onrender.com/posts/multiple-threat-actors-exploit-react2shell-cve-2025-55182/</link>
      <pubDate>Fri, 12 Dec 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/multiple-threat-actors-exploit-react2shell-cve-2025-55182/</guid>
      <description>• Multiple Threat Actors Exploit React2Shell (CVE-2025-55182) Google Threat Intelligence Group Google Threat Intelligence Visibility and context on the threats that matter most. •</description>
    </item>
    <item>
      <title>A look at an Android ITW DNG exploit</title>
      <link>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</link>
      <pubDate>Fri, 12 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</guid>
      <description>• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl</description>
    </item>
    <item>
      <title>A look at an Android ITW DNG exploit</title>
      <link>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</link>
      <pubDate>Fri, 12 Dec 2025 10:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/a-look-at-an-android-itw-dng-exploit/</guid>
      <description>• Introduction Between July 2024 and February 2025, 6 suspicious image files were uploaded to VirusTotal. • Thanks to a lead from Meta, these samples came to the attention of Googl</description>
    </item>
    <item>
      <title>Crafting a Full Exploit RCE from a Crash in Autodesk Revit RFA File Parsing</title>
      <link>https://cluster-site.onrender.com/posts/crafting-a-full-exploit-rce-from-a-crash-in-autodesk-revit-rfa-file-parsing/</link>
      <pubDate>Wed, 08 Oct 2025 14:00:00 +0000</pubDate>
      <guid>https://cluster-site.onrender.com/posts/crafting-a-full-exploit-rce-from-a-crash-in-autodesk-revit-rfa-file-parsing/</guid>
      <description>• In April of 2025, my colleague Mat Powell was hunting for vulnerabilities in Autodesk Revit 2025. • While fuzzing RFA files, he found the following crash (CVE-2025-5037 / ZDI-CAN</description>
    </item>
  </channel>
</rss>
