CVE
CVE-2026-42945
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when the rewrite directive is followed by a rewrite, if, or set directive and an unnamed Perl-Compatible Regular Expression (PCRE) capture (for example, $1, $2) with a replacement string that includes a question mark (?). An unauthenticated attacker along with conditions beyond its control can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap buf
Exploitation IoCs 3
Domain corepack[.]org
Filename lib/.threadpool.rb
IP 165[.]154[.]236[.]93
MITRE ATT&CK TTPs 13
T1027 T1056.001 T1059.001 T1071.001 T1082 T1083 T1098 T1105 T1114 T1555 T1566 T1570 T1588
Obfuscated Files or Information
Defense Evasion
Keylogging
Collection
PowerShell
Execution
Web Protocols
Command And Control
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Account Manipulation
Persistence
Ingress Tool Transfer
Command And Control
Email Collection
Collection
Credentials from Password Stores
Credential Access
Phishing
Initial Access
Lateral Tool Transfer
Lateral Movement
Obtain Capabilities
Resource Development
Source Articles
⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
Multiple active threats were reported this week, including Russian threat actors exploiting a Microsoft OWA XSS vulnerability (CVE-2026-42897) to deploy a JavaScript-based implant called OWAReaper for persistent mailbox access. A critical Ruby on Rails vulnerability (CVE-2026-66066) allows unauthenticated attackers to read arbitrary files via crafted image uploads, potentially leading to remote code execution. Additionally, Iranian-linked actors are suspected in coordinated attacks on over 30 Minnesota water systems, where exposed PLCs were targeted to disrupt operations. Storm-2945 (APT29) conducted DNS hijacking via compromised Wi-Fi networks to deliver CornFlake malware and ChocoShell infostealer, while a malicious campaign in RubyGems distributed 199 trojanized packages embedding XMRig cryptojacking payloads.
hacker-news Aug 3, 2026
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
A critical vulnerability in NGINX, tracked as CVE-2026-42533, allows remote unauthenticated attackers to trigger a heap buffer overflow via crafted HTTP requests, potentially leading to denial of service or remote code execution. The flaw exists in NGINX's script engine under specific configurations involving regex-based maps and capture overwrites. Exploitation may bypass ASLR, increasing the risk even on default systems, though no public exploits have been observed yet. F5 has released patches for core NGINX and NGINX Plus, but downstream products lack updated builds at the time of publication.
hacker-news Jul 19, 2026