WarrenBarr
SEC-01
Advisories
Published findings
OPS-02
Methodology
How an engagement runs
ENG-03
IT & Dev
Build and administer
ARM-04
Software
Tooling I wrote
MSP-05
MSSP
Flat-rate managed
REC-06
Case Studies
Work, in full
WEB-07
Websites
Sites that convert
SUP-08
Gear
Coming soon
DOC-09
Doctrine
What I will not do
WHO-10
About
Who you'd be hiring
Last published August 2026 — BCY-ADV-2026-02222 advisories · first published May 2026
By month
BCY-ADV-2026-001May 2026
Axios npm Supply Chain Attack
North Korean State-Sponsored RAT Distribution
CRITICAL
State-sponsored supply chain compromise of the Axios npm library. Malicious versions silently installed a RAT on any machine that updated during a three-hour window on March 31, 2026. Windows, macOS, and Linux affected. IOCs, detection commands, and remediation steps documented.
Supply ChainnpmRATNorth Korea
BCY-ADV-2026-002 — CVE-2017-0144 — CVSS 8.8May 2026
EternalBlue — SMBv1 Remote Code Execution
WannaCry · NotPetya · No Authentication Required
CRITICAL 8.8
Unauthenticated RCE via crafted SMBv1 packets. Weaponized by WannaCry and NotPetya. KEV listed. Still actively exploited on unpatched and misconfigured systems. One vulnerable machine can pivot to full network compromise.
SMBv1RCEKEVWannaCryWindows
BCY-ADV-2026-003 — CVE-2021-34527 — CVSS 8.8May 2026
PrintNightmare — Print Spooler Remote Code Execution
SYSTEM Privileges · Active Exploitation Confirmed
CRITICAL 8.8
RCE and privilege escalation via Windows Print Spooler. Authenticated attacker gains SYSTEM. KEV listed with confirmed active exploitation. Multiple follow-on CVEs in the same family.
Print SpoolerRCEKEVSYSTEMWindows
BCY-ADV-2026-004 — CVE-2021-1675 — CVSS 7.8May 2026
PrintNightmare LPE — Print Spooler Local Privilege Escalation
SYSTEM Access · KEV Listed
HIGH 7.8
Local privilege escalation via Windows Print Spooler. Part of the PrintNightmare family. Grants SYSTEM-level access from a standard user context. KEV listed.
Print SpoolerLPEKEVSYSTEM
BCY-ADV-2026-005 — CVE-2016-3236 — CVSS 7.5May 2026
WPAD Proxy Hijack — Network Traffic Interception
Same-Network Attack · All Web Traffic at Risk
HIGH 7.5
Windows WPAD protocol mishandles proxy discovery, allowing any attacker on the same network to intercept all web traffic silently. Particularly dangerous in shared network environments including hospitality properties.
WPADProxy HijackNetworkMitM
BCY-ADV-2026-006 — CVE-2017-5715 / CVE-2017-5754 — CVSS 5.6May 2026
Spectre & Meltdown — CPU Speculative Execution
Hardware-Level · OS & Microcode Mitigations Required
MEDIUM 5.6
Hardware-level speculative execution vulnerabilities affecting virtually all modern CPUs. Allows side-channel extraction of sensitive data from memory. OS and microcode patches available and must be verified active.
CPUSpectreMeltdownSide-ChannelHardware
BCY-ADV-2026-007 — MITRE T1557.001May 2026
LLMNR & NBT-NS Poisoning — Responder
Silent Credential Theft · No User Interaction Required
TECHNIQUE
Protocol-level design weakness. Attackers use Responder to answer broadcast name resolution queries and harvest NTLM credential hashes silently. Any device on the same network is at risk. Particularly effective in shared environments.
LLMNRNetBIOSResponderNTLMNetwork
BCY-ADV-2026-008 — MITRE T1003.001May 2026
LSASS Credential Dumping — Mimikatz
Password Hash Extraction · BYOVD Bypass Risk
TECHNIQUE
Mimikatz and variants exploit legitimate LSASS memory access to dump plaintext passwords and NTLM hashes. LSASS PPL blocks commodity tools. Advanced BYOVD bypasses exist but require elevated privileges and driver deployment.
LSASSMimikatzPPLCredential DumpingBYOVD
BCY-ADV-2026-009 — MITRE T1550.002May 2026
Pass-the-Hash via RDP
Authentication Abuse · No Plaintext Password Needed
TECHNIQUE
Captured NTLM hashes used to authenticate as users without knowing plaintext passwords. RDP is a primary delivery vector. Restricted Admin mode blocks this technique entirely at the protocol level.
Pass-the-HashRDPNTLMLateral Movement
BCY-ADV-2026-010 — MITRE T1059.001May 2026
PowerShell Living-Off-the-Land Scripting
Built-In Abuse · CLM Mitigation
TECHNIQUE
PowerShell is abused in the majority of modern intrusions because it is trusted, built in, and capable of nearly anything. Constrained Language Mode significantly raises the cost of commodity attacks without removing legitimate admin capability.
PowerShellLOTLCLMScriptingWindows
BCY-ADV-2026-011 — MITRE T1091May 2026
USB & Removable Media AutoRun Malware
Physical Vector · No User Interaction on Insertion
TECHNIQUE
AutoRun and AutoPlay allow malicious payloads on USB drives to execute automatically on insertion without user interaction. Configuration weakness — not a software bug. One registry key eliminates this entire attack class.
USBAutoRunPhysicalRemovable Media
BCY-ADV-2026-012 — CWE-798 / CWE-521May 2026
Default & Predictable Account Names
First Target in Every Automated Scan
CONFIG
Default Windows account names are hardcoded into every attacker toolset and targeted first in automated credential attacks. A single rename and a 12-character complexity policy closes this vector entirely at zero cost.
Default AccountsPassword PolicyConfigurationWindows
BCY-ADV-2026-013July 2026
SimpleHelp RMM — OIDC Authentication Bypass
CRITICAL
Unauthenticated attackers forge OIDC tokens to obtain a fully authenticated Technician session, then deploy TaskWeaver and Djinn Stealer across every managed endpoint. MSP supply chain attack. CISA KEV June 29, 2026.
CVE-2026-48558CVSS 10.0CISA KEVRMMMSP Supply ChainTaskWeaver
BCY-ADV-2026-014July 2026
Ubiquiti UniFi OS — Unauthenticated RCE Chain (3x CVSS 10.0)
CRITICAL
Three chained CVSS 10.0 vulnerabilities give any network-reachable attacker root on UniFi gateways, cameras, and access controllers. ~50,000 US endpoints exposed. CISA KEV June 23, 2026.
CVE-2026-34908CVE-2026-34909CVE-2026-34910CVSS 10.0CISA KEVAuth BypassRoot RCE
BCY-ADV-2026-015July 2026
Adobe ColdFusion — RDS Path Traversal Leading to Unauthenticated RCE
CRITICAL
A single unauthenticated HTTP request writes a CFML webshell to the ColdFusion web root via the RDS FILEIO handler. NT AUTHORITY\SYSTEM on Windows. Honeypot exploitation confirmed. Public PoC active. CISA KEV July 8, 2026.
CVE-2026-48282CVSS 10.0CISA KEVPath TraversalWebshellPublic PoC
BCY-ADV-2026-016July 2026
SonicWall SMA1000 — Zero-Day SSRF + Command Injection Chain
CRITICAL
Two zero-days chained for unauthenticated root on SonicWall SSL VPN gateways. Discovered by Rapid7 MDR during active exploitation. Custom malware deployed in the wild before patches existed. CISA KEV July 14, 2026.
CVE-2026-15409CVE-2026-15410CVSS 10.0CISA KEVZero-DaySSL VPNCustom Malware
BCY-ADV-2026-017July 2026
Microsoft SharePoint Server — Four Active CVEs, CISA Hardening Alert
CRITICAL
CISA issued a dedicated hardening alert for four SharePoint CVEs exploited in combination. Zero-day found by Mandiant/FLARE during a live incident. Microsoft scored it 5.3; NVD scored it 9.8. Post-exploitation IIS machine key theft enables persistence beyond patching. CISA KEV July 14, 2026.
CVE-2026-56164CVE-2026-45659CVE-2026-58644CISA KEVZero-DayDeserialization RCEIIS Key Theft
BCY-ADV-2026-018July 2026
Microsoft AD FS — Privilege Escalation Zero-Day Found During Active Intrusion
HIGH
Low-privileged local user reads the AD FS DKM container via insufficient ACLs, extracts token signing material, and forges federation tokens for any identity. Found by Microsoft DART during a live intrusion. Manual DKM ACL hardening required beyond the patch. CISA KEV July 14, 2026.
CVE-2026-56155CVSS 7.8CISA KEVZero-DayAD FSToken ForgeryDART Discovery
BCY-ADV-2026-019August 2026
FakeGit — 7,600 Counterfeit GitHub Repos Delivering SmartLoader, Recommended By AI Agents
HIGH
An active supply-chain campaign running ~7,600 fake GitHub repositories with 14M+ downloads. Over 800 pose as AI Skills or MCP servers, and Claude Code, Gemini and ChatGPT have all surfaced them unprompted — a technique researchers call AgentBaiting. Delivers SmartLoader, then StealC. C2 resolved from a Polygon smart contract, so there is no domain to seize.
T1195.002SmartLoaderStealCSupply ChainMCP / AI SkillsAgentBaitingActive Campaign
BCY-ADV-2026-020August 2026
N-able N-central Auth Bypass — The First Patch Did Not Hold
CRITICAL
Two authentication bypasses in the RMM platform MSPs use to manage customer endpoints. Attackers took over N-central servers, used Take Control to reach managed machines, and registered Cloudflare tunnels as services — persistence that survives a reboot and survives revoking the N-central route. Upgrading to 2026.3 is not enough; only 2026.3.1.7 is safe.
CVE-2026-18556CVE-2026-18577CWE-288CVSS 8.2RMMCISA KEVActively Exploited
BCY-ADV-2026-021August 2026
Apache Tomcat CVE-2026-34486 — Exploited By An AI That Picked Its Own Targets
HIGH
An EncryptInterceptor bypass in clustered Tomcat, four months after the fix shipped. Notable for who used it: an AI agent wired into the Hermes framework that hit 460+ targets, researched alternative vulnerabilities on its own when its first exploit failed, and managed its own compute budget. Also used to deliver SNOWLIGHT across 100+ countries.
CVE-2026-34486CVSS 7.5Tomcat ClusterSNOWLIGHTAutonomous AICISA KEVActively Exploited
BCY-ADV-2026-022August 2026
Langflow Unauthenticated RCE — 650 Attempts From 244 Addresses
CRITICAL
CVSS 9.8 code injection giving full remote code execution on a default Langflow deployment, no credentials required. Broad opportunistic scanning from 41 countries. The real problem is inventory: AI workflow tools get stood up fast, hold model-provider API keys and internal data, sit inside the perimeter, and never make it onto the patch schedule.
CVE-2026-9198CVSS 9.8CWE-94LangflowAI InfrastructureCISA KEVActively Exploited
⚠ Advisory list

Get these when they're published.

I publish an advisory when something is actually being exploited and there is something useful to say about it — indicators you can hunt for, the version that actually fixes it, and what patching does not fix. Not a newsletter. No roundups, no vendor content, no "5 tips for cyber awareness month."

Realistically that's a handful of emails a month, and fewer in a quiet one.

One-click unsubscribe in every email Your address is never sold or shared Nothing else sent to this list