Caitlin Condon
Adventurer. Takes a lot of photos, calls many places home. VP of research @vulncheck@infosec.exchange. Previously vulnerability research director @ Rapid7 + @metasploit@infosec.exchange. Opinions mine, etc. She/her.
@darfplatypus@infosec.exchange can’t stop won’t stop (none of these are mine, I’m stealing them all from one person who is very cool but shall remain nameless)
So it turns out Strasbourg is real effing pretty and also extremely chill
Happy hour in the States: 4-6 PM, the six cheapest items on the menu. Everyone is still at work. Keep ordering or gtfo you impoverished pieces of shit.
Happy hour in France: 3 PM - 10 PM. Or midnight. Have all the wines. Have all the cocktails. We do not believe in food. Stay forever, we don’t really care.
After disclosing ENDLESSDOORS this month, @albinolobster@infosec.exchange began researching the global ZBT router supply chain. He expected to find more ENDLESSDOORS.
Instead, he found two totally different implants: #DARKLANTERN and #SPEAKINGSTONE.
DARKLANTERN is a backdoor that listens on the WAN and executes arbitrary commands. VulnCheck Target Intelligence found DARKLANTERN in 22 countries worldwide, primarily in the United States.
SPEAKINGSTONE is a phone-home implant that can execute commands as root, redirect DNS traffic, and open remote-access tunnels. It had a hard-coded C2 backup domain that was unregistered at time of discovery. So @albinolobster@infosec.exchange registered it, and hundreds of implants started calling in.
Callbacks to the VulnCheck-sinkholed domain came almost exclusively from China (83% came from China Mobile's network). In other words, SPEAKINGSTONE is domestic surveillance technology that made its way into the global supply chain.
https://www.vulncheck.com/blog/zbt-darklantern-speakingstone
If you've missed any super dope research from @lobsterjerusalem@infosec.exchange recently, pleez don't miss it anymore:
Oh no the internet is awash with AI slop PoCs, send poor Jonathan tiny cupcakes and quick: https://www.vulncheck.com/blog/death-by-20k-pocs
SharePoint RCE:
https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
Chaining CVE-2026-55040 and CVE-2026-63520 for full auth bypass-to-RCE in Microsoft SharePoint: https://www.vulncheck.com/blog/cve-2026-63520-sharepoint-unsafe-type-rce
New vulnerability disclosure from
@chocapikk_@bird.makeup:
CVE-2026-14863 is an OS command injection-to-RCE in FileRun, a commercial self-hosted file manager. Internet footprint is an appreciable 3.5K or so based on the team's ASM queries. Good stuff as always from Valentin.
https://www.vulncheck.com/blog/filerun-thumbnail-command-injection-rce
VulnCheck curated 20K+ public exploits and vulnerability analyses in 2025. As of mid-August 2026, we’ve already incorporated 17,800+ PoCs and write-ups, putting us 87% of the way to 2025’s numbers with another 4+ months left to go in the year.
Our team wrote about what the acceptance rate looks like for GitHub exploits (a bellwether for broader exploit trends), and surprise surprise! AI slop is leading to noticeably higher rejection rates.
The vulns might be real, but that doesn't mean the exploits are.
Interviewing candidates used to be like, "I hope this person can computer good and isn't a psychopath." Now it's like, "This threat actor is slightly less qualified than the threat actor from last week, they should pair."
Today, VulnCheck is disclosing #ENDLESSDOORS, a phone-home implant CTO @albinolobster@infosec.exchange discovered in Zbtlink routers. ENDLESSDOORS starts automatically, runs with root privileges, and attempts to connect to command-and-control infrastructure roughly every 35 seconds. The backdoor ships by default across 20+ Zbtlink router models, which are white-labeled and sold on popular retail sites including Amazon, AliExpress, and Alibaba.
The implant and server implement no encryption or verification, meaning anyone along the network path can hijack the client-server communication and obtain a root shell on the device, regardless of the router's network position.
The VulnCheck CNA has assigned CVE-2026-66747 to track backdoored firmware versions; our blog also has guidance for defenders, including affected firmware images, hashes, network indicators, a YARA rule, and network signatures (Suricata / Snort).
The VulnCheck CVE Numbering Authority has issued thousands of CVEs over the past year for vulnerabilities reported to us by researchers and the community. We're looking for a US-based senior vulnerability analyst to join our CNA team, which vets community researcher reports, coordinates disclosure across researchers and suppliers (and sometimes CERTs), and publishes (a lot of) CVEs.
If you care about coordinated vulnerability disclosure (CVD) and have experience coordinating disclosures for vulns reported to you by third parties, we want to talk to you! The VulnCheck CNA team is highly engaged with both the research community and our peers in the #CVE and #CVD space. This role is a hands-on operational role doing day-to-day CVD, but you'll also have the opportunity to give input into global CVE and CVD efficacy in the age of AI.
"That's the dumbest shit I've read in a bit"
- Quote from the team exploit mines 2026-05-16T00:06:00Z
👋 There's been a lot of discussion recently about the volume of vulnerability reports that PSIRTs, open-source maintainers, and technology producers are receiving. The CVE Program's Researcher Working Group (RWG), which I've been chairing for the last 9 months, is developing guidance for security researchers on how to most effectively report new vulnerabilities to supplier organizations.
👉 We're seeking input from the community on the data points, report characteristics, and reporting practices that help reduce time-to-verification for new vulnerabilities. If you're a researcher, a PSIRT, a VM or SecOps practitioner, or a bug bounty provider who's been on the hook for looking at or validating vulnerability reports in your career, we want your feedback on what works — and what doesn't!
🗓️ The discussion will stay open through (at least) June 5, 2026. Feedback is best submitted by commenting on the GitHub issue below!
https://github.com/CVEProject/researcher-working-group/discussions/29
New list! 2026 routinely targeted vulnerabilities (so far)
https://www.vulncheck.com/blog/routinely-targeted-vulnerabilities-may-2026
Someone should tell the North Korean IT workers to stop using the Golden Gate bridge as their Zoom backgrounds.
Full Rapid7 analysis of #Cleo CVE-2024-55956 now available c/o @stephenfewer@bird.makeup. It's neither a patch bypass of CVE-2024-50623 nor part of a chain after all — totally new bug, different exploitation strategies across the two issues (though the same endpoint gets used either way).
I'm not sure it's been mentioned much yet that Cleo evidently released IOCs related to CVE-2024-50623 in October 2024, implying the older bug's been exploited for a minute. Would sure be helpful to know more about who was doing that exploiting, particularly now that Cl0p has claimed credit for last week's attack.
https://attackerkb.com/topics/geR0H8dgrE/cve-2024-55956/rapid7-analysis
🙄 I see the AI hype machine is AI hype machining real hard today.
@darfplatypus@infosec.exchange everyone else is going to be v confused by this thread 😂 Here’s one req: https://job-boards.greenhouse.io/vulncheck/jobs/4397769009
