Lyrie
← Home

#CVE

31 stories tagged.

Master Key Over Wi-Fi: CVE-2026-0073 Android Zero-Click ADB Auth Bypass — PoC Now Public

9 min · 0 sources

CVE-2026-0300: The PAN-OS Captive Portal Zero-Day That Handed State Actors Root on 225,000 Firewalls

10 min · 0 sources

Burning the Perimeter: CVE-2026-0300 — Unauthenticated Root RCE in Palo Alto PAN-OS Actively Exploited

11 min · 0 sources

Two Frames to Own the Server: CVE-2026-23918 and the Apache HTTP/2 Double-Free That Stole May's Patch Cycle

10 min · 0 sources

The Trust Boundary Is Gone: 2026's Cascade of Agentic AI CVEs Proves the Framework Layer Is Now Critical Infrastructure

11 min · 0 sources

CVE-2026-42208: The SQL Injection That Opens Your Entire AI Stack — LiteLLM's CISA KEV Crisis

9 min · 0 sources

When Prompts Become Shells: CVE-2026-25592 & CVE-2026-26030 Prove AI Agent Frameworks Are the New OS — And They Have Root Bugs

10 min · 0 sources

The Firewall That Opened the Door: CVE-2026-0300 and the State-Sponsored Operation Hiding Inside Your Perimeter

10 min · 0 sources

Copy Fail: How a 9-Year-Old, 732-Byte Bug Gives Any Local User Root on Every Major Linux Distribution — and Escapes Your Kubernetes Cluster

10 min · 0 sources

The Defender's Dilemma: CVE-2026-32202 NTLM Zero-Click, BlueHammer, RedSun, and UnDefend — Windows' Most Dangerous Fortnight in Years

11 min · 0 sources

Credential Chain Detonation: How CVE-2026-6973 Turns Ivanti EPMM's January Breach Into a May Ambush

9 min · 0 sources

The Mother of All AI Supply Chains: Anthropic's MCP Architectural Flaw Puts 200,000 Servers and 150M Downloads at Risk

10 min · 0 sources

The Firewall That Opened the Door: CVE-2026-0300 PAN-OS Captive Portal Zero-Day Under Active State-Sponsored Exploitation

10 min · 0 sources

CVE-2026-0300: The PAN-OS Captive Portal Zero-Day That Handed State Actors the Keys to the Kingdom

9 min · 0 sources

The Firewall Flipped: CVE-2026-0300 Turns PAN-OS Captive Portal Into a State-Sponsored Entry Point

11 min · 0 sources

The Device Manager Is Compromised: Ivanti EPMM's Five-CVE Zero-Day Bundle and the January Credential Domino

10 min · 0 sources

The Data Lake Is Poisoned: Apache Polaris Triple CVSS-9.9 Cluster Exposes Enterprise Lakehouses to Credential Hijack and Arbitrary Storage Access

9 min · 0 sources

Root on the Perimeter: CVE-2026-0300 — The PAN-OS Captive Portal Zero-Day Being Exploited by State Actors Right Now

11 min · 0 sources

Firewall as Entry Point: CVE-2026-0300 PAN-OS Captive Portal RCE and the State-Sponsored Campaign That Moved First

10 min · 0 sources

The Master Key to 1.5 Million Servers: CVE-2026-41940 and the cPanel CRLF Authentication Bypass

10 min · 0 sources

Your Firewall Is the Exploit: CVE-2026-0300 Grants Root RCE on Palo Alto PA-Series via Captive Portal Buffer Overflow — No Patch Yet

10 min · 0 sources

The Eyes That Guard You Are Blind: Five Critical CVEs Turn GeoVision Surveillance Hardware Into an Attacker's Beachhead

11 min · 0 sources

The Incomplete Patch Trilogy: Apache MINA's Deserialization Crisis and the Allowlist That Wasn't (CVE-2026-42779, CVE-2026-42778, CVE-2026-41635)

10 min · 0 sources

The Key to 70 Million Kingdoms: CVE-2026-41940 — cPanel/WHM CRLF Auth Bypass Exploited as Zero-Day

9 min · 0 sources

CISA KEV analysis: what gets actively exploited and why

1 min · 1 sources

How Lyrie Sentinel works — the 4-minute timeline

1 min · 1 sources

CVE to @lyrie_ai tweet: 4 minutes. Autonomous.

1 min · 1 sources

The 136-Day Invisible Exploit: CVE-2026-34621's Prototype Pollution Turned Adobe's JavaScript Sandbox Into a Lie

10 min · 0 sources

The Four-CVE KEV Cluster: How DragonForce and Mirai Turned CISA's April 24 Drop Into a Live Ransomware-and-Botnet Race

10 min · 0 sources

The MCP Path Traversal Epidemic: How AI Tool Servers Became the New Attack Surface

8 min · 0 sources

Your AI Dev Stack Is the Attack Surface: CVE-2026-39987 (Marimo) and CVE-2026-5760 (SGLang) Signal a New Threat Class

10 min · 0 sources