gg

Joined October 2024
9 Photos and videos
May 31
Huge Instagram exploit going around where threat actors are social engineering meta employees and spoofing ip addresses to force password resets and take over accounts. Make sure your MFA is setup, the username @hey was stolen. I personally just had an account recovery code emailed to me, was logged out of my account and received a 2FA text #instagram #exploit
4
3
12
2,642
May 28
Microsoft Warns Against Public Release of Zero-Day Details Before Vendor Coordination. patch tuesday came early. assume mass scanning starts within 48h. #Microsoft #0day valtikstudios.com/blog
2
2
259
May 27
cpanel dropped CVE-2026-48172. privilege escalation, CVSS high, actively exploited in the wild. if you operate shared hosting with WHM open, block external access to the affected endpoint until patched. #ActiveExploitation #PrivEsc #SharedHosting valtikstudios.com
1
1
181
May 27
Windows Kernel Vulnerability Lets Attackers Modify Kernel Memory Counters. kernel CVEs cascade. patch the host, expect container escapes to follow within days. #CVE-2026-40369 valtikstudios.com
1
1
89
May 18
github CVE-2026-44789: RCE. cloud misconfigs scale your blast radius by every region you operate in. audit IAM first. #GitHub #RCE #CVE-2026-44789 valtikstudios.com
2
2
111
May 18
openai dropped CVE-2026-33017. unauth RCE, CVSS high, exploit available. if you have openai in your stack, block external access to the affected endpoint until patched. #OpenAI #RCE #GitHub #CVE-2026-33017 valtikstudios.com/blog/langf…

2
2
149
May 18
cisco dropped CVE-2026-20182. an unauth bug, CVSS 10.0, exploit available. if you have cisco in your stack, rotate keys and lock down 0.0.0.0/0 access on port 22. #Cisco #exploit #CVE-2026-20182 valtikstudios.com/blog/cisco…

1
1
113
May 18
vendor dropped CVE-2026-42897. unauth RCE, CVSS high, actively exploited in the wild. if you run the affected stack, block external access to the affected endpoint until patched. #0day #RCE #CVE-2026-42897 valtikstudios.com/blog/excha…

1
1
181
May 14
cisco did the thing the privacy policy said they wouldnt. significant scale. the thing they swore wasnt happening was happening the entire time. #Cisco #AuthBypass #CVE-2026-20182 valtikstudios.com/blog
1
1
119
May 14
wordpress CVE-2026-8181: auth bypass. shared hosting outdated CMS = a botnet recruitment ad. assume compromise if you cant patch fast. #AuthBypass #WordPress #CVE-2026-8181 valtikstudios.com
1
1
86
May 13
if you run microsoft, patch tonight. CVE-2026-32185 weaponized, CVSS high. workaround: block external access to the affected endpoint until patched. #Microsoft #PatchTuesday #CVE-2026-32185 valtikstudios.com/blog
1
1
65
May 12
microsoft dropped CVE-2025-48804. an unauth bug, CVSS high, exploit available. if you have microsoft in your stack, block external access to the affected endpoint until patched. #Microsoft #0day #CVE-2025-48804 valtikstudios.com/blog
1
1
701
May 12
if you ran npm install on a tanstack package today, your laptop is rigged to self-destruct the moment you try to revoke your aws keys. not a joke. it's already in 42 packages with 12M weekly downloads. here's what happened and how to clean up without bricking your machine: valtikstudios.com/blog/tanst…
1
3
88
May 11
apache CVE-2026-23918: double-free in mod_http2. apache calls it "possible RCE", CVSS 8.8. "possible" is doing work. that bug class is reliable RCE in skilled hands. PoCs land in 2-3 weeks. workaround if you can't patch: Protocols http/1.1 #Apache #RCE valtikstudios.com
1
1
135
May 11
new phishing campaign: real Google/Outlook calendar invites, signed by the platform. landing page steals creds TOTP, relays live to M365. variants drop signed RMM installers. FIDO2 keys break the kill chain. #phishing #M365 valtikstudios.com/blog
1
2
68