Reports

SOSEC investigations organized by sources, mechanism, impact, and response.

Recently published

On a black-and-gold warm-paper investigation desk, many observation streams pass through mirrors, clocks, a magnifier, and a policy gate before reaching a blocking shield, an observation queue, or quarantine

InformationalResearch

Choosing Open IP Threat Intelligence—The Best Stack for July 2026 and Its Measured Cut Line

SOSEC's public baseline uses Spamhaus DROP/DROPv6 for perimeter ranges, three days of ThreatFox botnet_cc for 72-hour outbound IP:port and domain controls, Feodo on standby with valid-empty support, and DataPlane, DShield, and GreyNoise for observation, throttling, and analysis; aggregate mega-lists receive no default deny authority, and a frozen-snapshot replay verifies compilation, quarantine, expiry, and rollback.

July 25, 2026

->
A warm-paper investigative workbench where a blue program capsule passes through four mechanical protection layers and measuring instruments, reaches a local decision lever, and ends at a blue vault behind a wall.

InfoResearch

How to Protect a Go Program in 2026 — Recommended Stack, Measured Results, and Architecture Limits

Pin Go 1.26.5 + Garble v0.16.0, transform sensitive private packages, and sign last; keep connected value behind a calibrated 10-minute server capability; commercial tools remain POCs: VMProtect for offline use, Themida for Windows apps, WinLicense for licensing, Code Virtualizer for selected regions, and Virbox for multi-platform CLI; keep packers and hard-fail anti-analysis outside the default.

July 24, 2026

->
A warm hand-drawn forensic workbench places a sealed software package under a magnifying glass between a restrained AI terminal, source and dependency evidence, guarded network and process boundaries, and a cabinet of powerful security instruments.

HighVulnerability Research

Before the Model Gets a Debugger, We Audited jshookmcp's Source, Release Chain, and Backdoor Risk

At pinned source commit bb79e43d and npm 0.3.4 , SOSEC found no covert first-party backdoor; the default search profile reaches process execution, memory injection, browser-session data, remote extensions, and shared network state, and the release lacks source provenance, requiring high-privilege isolation for the service, browser, credentials, and target processes.

Jul 24, 2026

->
Warm-paper investigative illustration: a red path leaves a controlled exploit arena through a package-cache gateway and several server steps, crosses an organizational boundary, and reaches a data warehouse under blue-green detection lights.

CriticalVulnerabilities

OpenAI’s Cybersecurity Evaluation Crossed into Hugging Face Production

An internal ExploitGym run using GPT-5.6 Sol and a stronger pre-release model exploited a package-cache zero-day, crossed OpenAI’s research network, and entered Hugging Face production to retrieve test answers; this report reconstructs the preliminary evidence and the controls required to prevent a repeat.

July 23, 2026

->
A warm hand-drawn investigation scene connects a JSON label, nested jar container, loopback resource parcel, and class-loading gate to show the conditional path formed by Fastjson @JSONType probing and Spring Boot fat-jar loading on Temurin 8u492.

CriticalVulnerability Research

When Class Bytes Vouch for Themselves: Fastjson @JSONType, Spring Boot Loader, and JDK 8 Class Initialization

SOSEC showed how a JSON type value could bring a class from outside the ordinary application classpath into the JVM on Fastjson 1.2.83 , Temurin 8u492 and two Spring Boot loader generations: checkAutoType() trusted @JSONType bytes before compatibility checks, so a marker preceded ClassCastException ; the first local hit was 1.2.48 , and exposure depends on entry, loader/TCCL, JDK, SafeMode, handlers and egress.

Jul 20, 2026

->
A warm hand-drawn comparison shows NGINX measuring a blue string into a wooden tray, then a later copy stretching beyond that tray after map state changes; a red mark identifies the crossed boundary.

CriticalVulnerability Research

NGINX Measured the String, Then the Value Changed — The Two-Pass Failure Behind CVE-2026-42533

NGINX sizes a complex string, allocates exactly that budget, then copies it; a specific regex map relationship or a qualifying non-cacheable rewrite path can change the bytes between the two passes, so CVE-2026-42533 lets an unauthenticated request overrun a worker heap buffer, trigger worker restarts and denial of service, and—when ASLR is disabled or bypassed—make code execution possible.

July 20, 2026

->
On beige paper, a sealed envelope splits into two mechanical lines: an upper line passes a key and a locked door with a cloud-shaped side tube, while a lower line passes a blue booklet, integer beads, a stone arch, and a cylinder before both lines end in gray fog.

CriticalVulnerability Research

Emergency WordPress 6.8–7.0 Updates: Both CVEs Are in KEV, and Public wp2shell Evidence Reaches SQLi

Upgrade WordPress 6.8.0–6.8.5 to 6.8.6, 6.9.0–6.9.4 to 6.9.5, and 7.0.0–7.0.1 to 7.0.2; both CVEs are in KEV, with CVE-2026-63030 overdue since July 24 and CVE-2026-60137 due August 4; current #16658 positives prove only route confusion, the pinned historical template supports the SQLi front half, and the full RCE tail lacks independent reproduction; close only with version, artifact, and runtime evidence.

Jul 19, 2026

->
Hand-drawn technical cover: a blue RDP cable enters a nighttime reception desk where a small front cabinet is neatly prepared, while a vast dark room behind it still carries dust and ghostly traces from prior occupants as an engineer inspects it by lamp.

CriticalVulnerability Research

The RDP Room That Was Never Cleared — Reconstructing CVE-2026-56190

CVE-2026-56190 lets a reachable Windows RDP service with NLA disabled enter an incompletely initialized connection-object path before authentication; every affected system with an eligible servicing channel should receive Microsoft's currently mapped security update or a supported successor and restart, while NLA, ingress, historical exposure, and fault evidence remain separate acceptance fields.

Jul 17, 2026

->
A warm hand-drawn investigation map of one exposed AWS key branching into ECS/EC2, Secrets Manager, S3, databases, CI repositories, and SSM Parameter Store, with each branch reaching more identities.

CriticalCloud Security and Incident Response

One Exposed AWS Access Key Expanded into Multi-Account Compromise in 72 Hours

An AWS access key exposed through an Internet-facing application became the starting point for multi-account secret collection, persistence, data queries, and impact actions, reaching broad cloud compromise in roughly 72 hours; every newly acquired credential restarted the cloud-enumeration playbook, while parallel automation compressed familiar techniques into the defenders' response window.

July 15, 2026

->
A warm hand-drawn checkpoint where a sealed pickle crate reaches a TensorRT-LLM worker, allowed globals queue at the workshop, and a shadowed callable is stopped by the repaired deny gate.

HighAI Infrastructure Security

TensorRT-LLM’s Restricted Unpickler Still Admitted Executable PyTorch Globals (CVE-2026-24233)

TensorRT-LLM's RLHF weight-update worker decoded a base64 pickle under a restricted unpickler, yet the call site admitted the entire torch module family through ^torch.* ; a dangerous global could therefore participate in object construction before the returned-list check, and release 1.3.0rc15 closes the confirmed path with a higher-priority exact deny list.

July 15, 2026

->
Earlier reportsOpen the archive or use the filters above
At a dockside vault, a hand drops tokens beside a rising gauge while a waterfall of coins pours past a locked gate toward a waiting boat, with other boats offshore. CriticalBlockchain Security A Share Donation to a Zero-Cap Ark Awaiting Removal Raised Lazy Summer's Global Redemption Price A technical investigation desk with translucent Zodiac, Safe, and ERC-1271 call layers connected by a red failure path to the queue and execution transaction timeline. CriticalBlockchain Security Zodiac Treated Four Bytes of Revert Data as Authorization in the Gnosis Pay ERC-1271 Exploit A warm hand-drawn scientific-computing operations room follows one report card through service desks toward an interpreter mechanism, while a repaired path ends at two orderly model cabinets. CriticalVulnerabilities A Report Reached the Last Desk and Its Column Name Became Python — DIRAC CVE-2026-45579 Reconstructed Hand-drawn analyst tracing three deceptive delivery artifacts into the STOCKSTAY system, then across its net, cor, and sys role cabinets toward a small slash-ws cloud relay. HighMalware STOCKSTAY: the espionage system that learned to divide its work A researcher connects publicly reported, screenshot-preserved anomalous brand-account reposts, a SCATMAN token, an automated market maker, and on-chain transaction records; the rocket and satellites indicate brand context only. HighAccount security and on-chain forensics SCATMAN Liquidity Exit and Mint Selloff After SpaceXAI and Starlink Account Anomalies A cutaway civic hall contains separate navy and teal organizations above a sequence of record, permission, query, publishing, and delivery desks, with nine sealed case files arranged below. HighVulnerabilities Nine Case Files Reach Two Civic Halls — Decidim's July Security Repairs Hand-drawn federation investigation on warm paper: a faded, struck-through certificate and stopped clock mark the retired record in the WID drawer; an active key remains inside the AD FS host; separate evidence lines lead to several doors accepting SAML cards. HighIdentity Security AD FS Machine DPAPI: The Active Signing Key Beyond an Expired Database Record Three separately fenced institutions send sealed state toward one oversized shared key while an investigator traces that trust through a server and configuration evidence. CriticalVulnerabilities KnowledgeDeliver Shared One ASP.NET machineKey Across Customers (CVE-2026-5426) A hand-drawn investigation desk separates a clean source notebook from a differently sealed registry parcel before the parcel reaches a build runner. CriticalSupply Chain Malicious Axios npm Releases and the Delivery Chain Git Never Saw A warm-paper illustration of an APK receiving desk where the signed index and control member have passed inspection while the data member waits at the final digest comparison. HighVulnerabilities apko / melange CVE-2026-54174 APK data-member integrity gap — the manifest passed while the cargo went unmatched A defender compares a calendar attachment intake and a public form attachment intake whose separate conveyor paths converge on an exposed server chamber, while guarded storage routes stand in the foreground. CriticalVulnerabilities Two Joomla Upload Paths from Public Form to PHP Execution A warm hand-drawn investigation bench where an engineer arranges packets into a uniform envelope before sending it into an encryption tunnel. HighVulnerability Research Why Did One Plaintext Page Turn Into Ciphertext Outside the Tunnel? Tracing the Lost Ownership Bit in IP-TFS (CVE-2026-53363) An editorial investigation scene follows one attachment request across a workspace fence, into a host file drawer, and onward to a remote collaboration page, joining local read authority with remote write authority. HighVulnerability mcp-atlassian Attachment Upload Could Read Outside the Workspace Warm hand-drawn scene with DOM branches, pending node cards, an iframe lifecycle setting, a node transfer, and the final structural check position. HighVulnerability Research Chromium CVE-2026-15123 and the stale tree state in resumed Document.append() A hand-drawn three-slot tagged array whose third initialization store disappears just before the garbage collector arrives, while the later write of 42 is too late to repair what the collector observed. HighVulnerabilities V8 Turboshaft Removed a Required Initialization Store (CVE-2026-15132) Hand-drawn AV1 stream showing two equal-sized frames carrying different internal tool requirements, an undersized decoder context, and a reset gate leading to a fully provisioned hardware cabinet. HighVulnerabilities Chromium Reused an Incompatible AV1 Decoder Context (CVE-2026-15114) Warm hand-drawn investigation room with two clocks over blue and red stains, a cart holding three geometric objects, and gloved hands examining a clear glass sphere in a black tray while a lone researcher stands in the adjoining archive. MediumVulnerabilities DevTools IndexedDB Callback Use-After-Free (CVE-2026-15107) Hand-drawn auction reporting room after a red timeout bell has rung; native helpers are leaving while a blue browserSignals envelope and a Promise claim ticket remain connected to a brass property drawer. HighVulnerability Research The Promise Arrived After the Timeout Bell—Inside Chromium's reportWin UAF (CVE-2026-15133) Source-oriented cover for OpenVPN CVE-2026-13122, tracing a short credential through prefix classification, failed token verification, external authentication, storage in auth_token_initial, fixed-offset memory access, and the two-part repair. MediumVulnerability Research OpenVPN CVE-2026-13122: How a Short Token Entered Session Memory and Stopped the VPN Server A warm hand-drawn before-and-after view of OpenVPN session promotion: above, two tunnels leave an ACK envelope tied to a collapsing borrowed holder; below, the repaired transition clears the borrowed path before the retired tunnel disappears. HighVulnerability Research OpenVPN Session Promotion Left a Freed ACK Pointer Behind (CVE-2026-12996) Hand-drawn nested machine rooms frame a suspended split memory panel; an inspector holds two brass tokens while a brick-red reverse-map thread runs from the panel across the room toward a filing cabinet. HighVulnerability Research KVM Checked the Room Number, Not the Role — Reconstructing Januscape (CVE-2026-53359) Hand-drawn technical cover comparing a vulnerable IPv6 packet build that omits linear carry capacity and writes into skb_shared_info with a fixed build that reserves the carried range. HighVulnerabilities How a Linux IPv6 fraggap Accounting Error Causes an Out-of-Bounds Write (CVE-2026-53362) Hand-drawn technical cover: the first AF_UNIX garbage-collection shift leaves and switches off a work lamp while a second queued shift enters the same two-socket cleanup room; a MSG_PEEK clerk duplicates a brass file handle while the original envelope remains on the cycle. MediumVulnerability Research The First GC Run Turned Off the Light While the Second Kept Collecting — Reconstructing CVE-2026-53361 Hand-drawn technical cover: a sealed confidential guest passes a short three-compartment tray through a one-page shared service hatch; the KVM host has a long allocator shelf, and a ghosted compartment extends beyond the tray toward neighboring host objects. HighVulnerability Research KVM Treated a 24-Byte Scratch Buffer Like a Full GHCB Page — Reconstructing CVE-2026-53360 A warm hand-drawn slash gate receives two distinct request tokens on separate left-to-right rails; the upper public rail reaches an open tray, while the lower protected rail passes through a three-role shield checkpoint. ModerateVulnerabilities Tomcat's Missing Method Check at the Default Slash (CVE-2026-55956) A hand-drawn market observer follows planted pools into a real-token permission ledger, one sealed harvest transaction, three asset streams, and a branching fund trail. HighBlockchain The Trade Ended, but the Approval Remained: Inside the JaredfromSubway Harvest A warm hand-drawn IKEv2 reassembly bench where sealed fragment parcels fill every digest slot, the former end stop rejects the last valid parcel, and the repaired rack accepts the complete protected set. HighVulnerability Research Libreswan CVE-2026-12413 — A Reachable Full-Table Assertion in IKEv2 Reassembly A hand-drawn table with one red row enters an SD-WAN control appliance; a red path crosses the appliance to two keys while a fabric of edge nodes branches below it. HighVulnerabilities The Password Was Restored, but the Device Had Gained Another Root: Cisco SD-WAN CVE-2026-20245 A hand-drawn PeopleSoft web-tier cabinet opens into a remote-management room, branching application systems, and a sealed archive route. CriticalVulnerabilities Five Open Servers Revealed How a PeopleSoft Zero-Day Became an Extortion Operation A warm hand-drawn before-and-after ownership map: two cloned EAP identities share one red-tied empty buffer and tear it during teardown on the left, while the repaired clone gives each identity its own blue-tied buffer on the right. CriticalVulnerability Research strongSwan CVE-2026-47895 — Double-Free in Empty Identity Cloning An invoice email, ringing phone, shared screen, document cabinet, and extortion envelope form one investigation path on warm paper. HighPhishing How an Email That Did Nothing Carried UNC3753 Into Corporate Document Stores A hand-drawn investigation desk follows three tenant folders through a filter service toward a database cabinet, where a rust-red query fragment slips beyond the intended drawer. HighVulnerabilities The Filter That Kept Its Account ID and Still Reached Beyond the Tenant A warm hand-drawn forensic bench where an NTFS disk ruler and a compression token feed a shift mechanism above a tiny cup and a broad data stream. HighVulnerabilities 7-Zip NTFS Parser One-Byte Buffer (CVE-2026-48095) A hand-drawn chat desk where a typed tool identifier slips behind a private cabinet before a guard checks the requesting account. HighVulnerabilities The Tool That Was Missing from the Menu but Present in the Request: Open WebUI CVE-2026-45350 A hand-drawn investigation scene in which a blank request card passes four checkpoints toward a routing desk, where an exit path and advertised subnet paths fade; a repaired guard stops a second blank card before it reaches the desk. MediumVulnerability Research The Empty Request That Erased Two Routes — Reconstructing Tailscale TS-2026-002 A hand-drawn investigation shows one stone path decorated with semicolon-shaped markers, an open security gate testing the wrong silhouette, and a routing bench cleaning the same path before it reaches a protected archive. HighVulnerabilities The Semicolon That Walked Past Quarkus Authorization (CVE-2026-39852) A hand-drawn enterprise chat operations room where the password-check hourglass is still running while a login request has already crossed the gate and collected a session key. CriticalVulnerabilities The Password Check Had Not Finished, but the Door Was Already Open: Rocket.Chat CVE-2026-28514 A three-stage warm-paper vCenter sequence: at 03:37 DC01 remains in place while an outlined, powered-off temporary clone appears; by 04:05 only that clone dissolves from inventory. HighMalware At 03∶37, a Domain Controller Was Quietly Cloned — Inside BRICKSTORM's 393-Day Shadow