August 23, 2026
- CVE-2026-76404, a critical unsafe-deserialization RCE in the Splunk MCP Server app, is being flagged as internet-exposed by ZoomEye scanning. MCP servers are increasingly sitting inside privileged data planes — treat them as tier-0 infrastructure, not developer toys (@zoomeye_team via @cyb3rops). · Vulnerabilities & Exploits
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick