Grilled Cheese

ExploreLog inSign up
Terms of UsePrivacy PolicyCommunity StandardsHelpGet the app

Grilled Cheese is a product of Village Compute

Version devBuilt at: 2026-10-10 01:38:52 EDT

Explore

PostsPeople
LatestRanked
@theravenfile.bsky.socialOct 6, 2026, 1:45 PM

Today, I just dropped an article which might be useful while hunting ongoing #0day #exploit of #citrix #netscalar!

theravenfile.com/2026/10/06/cit
rix-0-day-exploits-cve-2026-88771-cve-2026-88772-in-the-wild/

#ZeroDay #Malware #Slapshot #Whipshot #Python #infosec #security #OSINT #ThreatIntel #CVE

@jax-89p13.bsky.socialOct 5, 2026, 2:41 PM

Possible new pfp?? Yes or no, people? #zeroday #0day #calgabriel #calrobertson #:P

@hackread.bsky.socialOct 3, 2026, 12:09 PM

βš οΈπŸ“’ The Dutch Institute for Vulnerability Disclosure (DIVD) was breached through 2 #Zammad 0-days in what it describes as an β€œagentic AI-powered attack,” leading to code execution and root access.

Listen/Read: hackread.com/dutch-instit...

#Cybersecurity #0Day #AI #CyberAttack #AgenticAI

@webrecordmedia.bsky.socialOct 3, 2026, 11:16 AM

HaftalΔ±k GΓΌvenlik Zafiyeti GΓΌndemi #6

#vulnerability #0day #poc #güvenlikaçığı

webrecord.media/haftalik-guv...

@helpnetsecurity.comOct 1, 2026, 10:23 AM

New Cisco SD-WAN zero-day exploited in-the-wild (CVE-2026-76504)

πŸ“– Read more: www.helpnetsecurity.com/2026/10/01/n...

#cybersecurity #cybersecuritynews #0day #exploit @cisco.com

@jax-89p13.bsky.socialSep 30, 2026, 6:59 AM

Me and bro. #zeroday #zeroday2003 #0day

@helpnetsecurity.comSep 29, 2026, 3:01 PM

NetScaler zero-day exploitation escalates into mass attacks (CVE-2026-88771)

πŸ“– Read more:
www.helpnetsecurity.com/2026/09/29/n...

#CyberSecurity #CyberSecurityNews #CVE #0day #ZeroDay

@helpnetsecurity.comSep 29, 2026, 9:54 AM

Apple squashes zero-day bug exploited in β€œextremely sophisticated” attack (CVE-2026-86950)

πŸ“– Read more: www.helpnetsecurity.com/2026/09/29/a...

#cybersecurity #cybersecuritynews #Apple #0day #iOS #iPad #macOS

@toxy4ny.bsky.socialSep 28, 2026, 10:32 AM

Monday's fuck up - This Time great Citrix - β€ŠU.S. CISA adds Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

securityaffairs.com/199891/hacki... #redteam #citrix #real #attack #cisa #exploit #0day #critical

@helpnetsecurity.comSep 28, 2026, 10:04 AM

Citrix NetScaler RCE zero-days exploited globally for weeks (CVE-2026-88771, CVE-2026-88772)

πŸ“– Read more: www.helpnetsecurity.com/2026/09/28/c...

#cybersecurity #cybersecuritynews #0day #exploit #vulnerability @ncsc-nl.bsky.social @doublepulsar.com @satn.am @tenablesecurity.bsky.social

@jax-89p13.bsky.socialSep 27, 2026, 12:12 AM

π™²πšŠπš•πšŸπš’πš—/π™»πšŽπšŽπš›πš˜πš’/π™΅πšŽπš•πš’πš‘(+) πŸͺ–

π–¦Ή Χ‚ π“ˆ’ πŸ₯ž / ⋆ Ϋͺπ”Έπ•π• π•π•’π•Ÿ β„π•’π•šπ•”π•™π•¦ π•–π•Ÿπ•₯π•™π•¦π•€π•šπ•’π•€π•₯

α‘•α ΅γƒ‡α‘α Šβ•Ύβ” β‚•β‚‘ / α΅’β‚œ + β‚“β‚‘β‚™β‚’β‚›

Ask to be moots :P <33

#slitsky #shtwt #988twt #988sky #zeroday #0day

@helpnetsecurity.comSep 23, 2026, 10:32 AM

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

πŸ“– Read more: www.helpnetsecurity.com/2026/09/23/c...

#cybersecurity #cybersecuritynews #0day #accessmanagement #CVE #firewall #MSP #SMBs

@toxy4ny.bsky.socialSep 22, 2026, 11:17 AM

Tuesday's fuck up - Now Windows -
Windows Exploitation Techniques:
Dangling COM Object Registrations
projectzero.google/2026/09/wind...
// This post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows 11 (CVE-2026-66804) #redteam #exploit #0day #windows #LPE #COM

@hhackenbecker.bsky.socialSep 22, 2026, 2:44 AM

Meta releases yet another service to really zuck up your life - Muse, an AI agent that watches EVERYTHING you do, ostensibly to drive your device for you.
UNDER NO CIRCUMSTANCES should you install it, there's already one #0day security bypass.
Leading security expert Patrick Wardle explains:

Patrick replies to a Zuck tweet.

Zuck said:
Introducing Muse, the personal agent that understands your goals and works 24/7 to get things done for you.

Pat replied:
Please don't install - it's trivial to turn Muse into the ultimate backdoor πŸ’€πŸ‘€

Ya, as an AI assistant built to manage your Mac, Muse needs broad access to your digital life. 

But serious 0-day flaw(s) can let local malware/attackers invisibly hijack it.

source: https://x.com/patrickwardle/status/2102045926474785265https://x.com/patrickwardle/status/2102046354444791888

First, one of 0day PoCs: https://github.com/pwardle/not-a-mused

Run with `-h` for some fun options from the 50+ commands Muse exposes.

Then click Muse’s πŸŽ™οΈ and dictate a prompt. That’s the trigger. πŸ‘€

image shows some commands as an example:
options:
-h,
--help
show this help message and exit
-response, --response RESPONSE
Optional replacement transcript; otherwise pass through
--port PORT
--dump-environment,-dump-environment
After capturing ABRA, create one Muse side chat requesting environment. describe on the selected device and print the JSON result
--list-commands
Fear capturing ABRAde print dah account deVice's command schemas and permissions directly from the API once per run; does not invoke
commands or create a chat.
--dump-chats
List chat sessions and print their messages, including older pages, after capturing ABRA. Disabled by default; once per distinct token
per run.
--take-photo
After ABRA capture, create a Muse side chat requesting one camera.snap on the selected device. Save its image in ~/Downloads; once per run. Requires camera permission; image passes through Muse's VM .
-notify, -notify TEXT
Request system.notify once on the selected device, with title "Not aMused" and this body. Creates a Muse side chat after ABRA capture.
-write, -write PATH TEXT
Request files.write once on the selected device with this exact text. Creates/OVERWRITES the file; parent folder must exist. Muse
approval may be required. Creates side chat after ABRA capture.
https://x.com/patrickwardle/status/2102046556522160473

#3 (This) bug details

Muse has an undocumented setting: 
endo_voyager_dictation_endpoint

...that can be redirected locally with no special privileges! 

So when you click πŸŽ™οΈ and dictate a prompt, Muse sends it to the attacker’s endpoint instead πŸ€¦β€β™‚οΈ

image highlighting the undocumented command with an example.https://x.com/patrickwardle/status/2102047208539320709

#4 Why is this bad? 

On a scale of meh to f*cked:
πŸŽ™οΈ Steal your dictated audio
πŸ’‰ Inject prompts Muse trusts/executes
πŸ”‘ Steal your auth token & invisibly control Muse directly

Anything you gave Muse access to? Now the (local) attacker has it too: msgs, emails, finances... πŸ’€

image shows an example, one of Patricks other Macs is now controlling Muse on the compromised Mac.
@jax-89p13.bsky.socialSep 18, 2026, 5:31 PM

Calling my friend and making him watch zero day :O #Zeroday #zd #zeroday2003 #0day

@hackread.bsky.socialSep 15, 2026, 11:26 AM

Hackers are actively exploiting the critical #StyleSmuggler zero-day to compromise Adobe Commerce and Magento stores, with researchers finding Linux backdoors and PHP web shells on affected systems.

Listen/Read: hackread.com/stylesmuggle...

#Cybersecurity #Magento #Adobe #0Day #Vulnerability

@helpnetsecurity.comSep 15, 2026, 11:14 AM

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

πŸ”— Read more: www.helpnetsecurity.com/2026/09/15/c...

#cybersecurity #cybersecuritynews #0day #emailsecurity #enterprise #SMBs @cisco.com

@toxy4ny.bsky.socialSep 14, 2026, 10:14 AM

Finally, the great magician has revealed himself! Respect and admiration for him for this and for the explanation of why he started writing exploits for Windows and other systems. He's a really cool dude! x.com/MSNightmare2... #MSNightmare #windows #0day #exploit #PoC #cybersecurity #real #people

@toxy4ny.bsky.socialSep 14, 2026, 10:02 AM

Monday's red team tool collection - Great Stuxnet - github.com/Sadpainy/Stu... - New Potato - github.com/aaron-kidwel... - 0day Defender exploit - github.com/MSNightmare/... - SSHamble - github.com/runZeroInc/s... #redteam #tool #fresh #new #monday #exploit #0day #stuxnet #potato #ssh #defender

@hackread.bsky.socialSep 10, 2026, 3:51 PM

βš οΈπŸ“’ Hackers are using hundreds of AI agents to exploit two PaperCut zero-days at scale, with at least 440 servers compromised across 395 organizations in 48 countries.

Listen/Read: hackread.com/hackers-use-...

#Cybersecurity #PaperCut #AI #0Day #Vulnerability

Load more