π¨ ACTIVE EXPLOITATION
- TONIC Price Manipulation Drains $74 Million From Cronosβ Tectonic
An attacker drained about $74 million from Cronos lending protocol Tectonic through TONIC price manipulation.- Cronos users and Tectonic depositors were affected; Crypto.comβs app and exchange were unaffected.
- Tectonic, Cronosβs largest lending protocol, was drained of roughly $74 million.
- Validators halted the entire Cronos blockchain, freezing unrelated transactions and positions.
- The attacker drove TONICβs price up about 100-fold in 20 minutes and used it as collateral to borrow liquid assets.
- TONIC had a 20% collateral factor, about $1.34 million in liquidity, and roughly $11,000 in daily volume; about $6 million was bridged to Ethereum before the halt.
π Source: x.com Β· π Coverage: decrypt.co Β· π via BleepingComputer
π΅οΈ RESEARCH & DEEP DIVES
-
Free LLM Endpoint Exposed Coding-Agent Session Data to a Honeypot
A suspected free LLM backend received sensitive coding-agent session data.- Coding-agent users relying on free LLM backends are affected.
- The exposed data included session history, filesystem output, working paths, and a local tool manifest.
- An internet-exposed inference honeypot was discovered and relabeled with sought-after model names.
- The honeypot was incorporated into infrastructure apparently providing free LLM backends and received a real coding-agent session without executing tools.
π Source: isc.sans.edu Β· π Coverage: malware.news Β· π via SANS ISC
-
Internet scan finds 1,776 exposed satellite mission-control systems
Internet-wide scanning identified 1,776 exposed satellite mission-control systems.- Satellite operators with internet-facing ground-segment mission-control systems are affected.
- A scanning index listed 1,776 apparent exposed systems.
- Only 18 results appeared distinct; the other 1,758 showed the same static web page.
- SNMP scanning revealed satellite ground-segment exposure that HTTP scans missed.
π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
π CVEs & KEV
-
CVE-2026-53552 β CVSS 9.6 β Goploy: Cross-namespace IDOR and RCE via body-supplied row id in project and ...
-
CVE-2026-83497 β CVSS 8.7 β Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor PaginationU...
-
CVE-2026-72001 β CVSS 8.6 β Pangolin before 1.22.0 Authentication Bypass via Share-Link EndpointPangolin befor...
-
CVE-2026-53507 β CVSS 8.3 β oasdiff actions resolve external $refs by default, enabling SSRF and disclosu...
-
CVE-2026-53553 β CVSS 7.7 β Goploy: Arbitrary File Read via Path Traversal in /deploy/fileDiff allows Rem...
-
CVE-2023-20511 β CVSS 6.4 β Release of an invalid pointer in the AMD kernel mode driver (KMD) could allow...
-
CVE-2026-53508 β CVSS 6.0 β oasdiff does not enforce --allow-external-refs=false on the git-revision load...
π ADVISORIES
- π Source for TerminalFix ClickFix Campaign Uses Fake CAPTCHAs to Deploy Reverse Tunnel β microsoft.com