ZeroHour
Vendor

NGINX

2 mentions in 7 days · 2 in 30 days · 3 total · first seen · last

Timeline

BlackHatSect0r Hackers Disable AI Safety Controls to Automate Credential Theft and Cyberattacks

French-speaking crew BlackHatSect0r disabled AI agent safety controls to automate scanning, credential harvesting, and vishing, exposing 16,834 stolen credentials.

Socradar researchers analyzed the exposed infrastructure of a French-speaking crew called BlackHatSect0r && DXQRTXX, which ran a Nous Research Hermes agent on a DeepSeek model with safety controls removed via HERMES_DISABLE_SAFETY=1. A custom Go-based C2 platform, DXSCAN, was exposed on port 8080 with over 200 secret-detection patterns, a vault of 16,834 harvested credentials, and scanning activity queuing 2.75 million domains and reaching more than 726,000 hosts. The kit also held a database of roughly 450,000 French telecom subscriber records used to prepare vishing lures impersonating Société Générale, plus JWT-forging tooling for a cryptocurrency exchange. Most confirmed compromises relied on exposed secrets and cloud misconfiguration rather than novel exploits; the one cited vulnerability, CVE-2026-42530, is an NGINX HTTP/3 QPACK use-after-free fixed in version 1.31.2.

GBHackersupdated · 2h agofirst · 5h agoThreat actor in the wild 4 sourcesCVE-2026-42530

Hackers Turn AI Agent Into a Cyber Weapon After Deleting Its Safety Refusals

Researchers exposed BlackHatSect0r && DXQRTXX infrastructure showing a safety-disabled Hermes AI agent used to automate scanning, credential harvesting, and vishing against French telecom subscribers.

Socradar-analyzed infrastructure attributed to French-speaking crew BlackHatSect0r && DXQRTXX exposed 4.9 GB across 9,299 files, including the DXSCAN Go-based C2 platform, 16,834 harvested credentials, and a database of nearly 450,000 records used for a vishing campaign targeting older French telecom subscribers with Societe Generale-themed lures. The crew ran a self-hosted Nous Research Hermes agent on a DeepSeek model with refusal instructions removed and HERMES_DISABLE_SAFETY=1 set, using it for scanning, secret hunting, and Telegram reporting. DXSCAN queued 2.75 million domains and reached over 726,000 hosts; the toolkit relied on exposed secrets and misconfigurations rather than novel exploitation.

GBHackersupdated · 2h agofirst · 5h agoThreat actor in the wild 4 sourcesCVE-2026-425301

ZDI-26-578: NGINX HTTP Dav Module Alias Directive Integer Underflow Remote Code Execution Vulnerability

An unauthenticated integer underflow (CVE-2026-27654, CVSS 8.1) in NGINX's HTTP Dav module alias directive enables remote code execution.

ZDI advisory ZDI-26-578 describes an integer underflow in the alias directive of the NGINX HTTP Dav module that allows remote attackers to execute arbitrary code. Authentication is not required to exploit the vulnerability. ZDI rated the issue 8.1 on CVSS and assigned CVE-2026-27654.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-27654

Related CVEs

  • NGINX Open Source has a vulnerability in the ngx_http_v3_module module.
    NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the HTTP/3 QUIC module, a remote unauthenticated attacker along with conditions beyond their control can use a specially crafted HTTP/3 session to reopen a QPACK encoder stream. This may cause a Use-after-Free in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS)…
    · f5 nginx gateway fabric · f5 nginx ingress controller
  • Buffer Overflow in NGINX ngx_http_dav_module via DAV MOVE/COPY with Alias
    NGINX Open Source and NGINX Plus contain a buffer overflow (CWE-122/CWE-120) in the ngx_http_dav_module that can be triggered by an unauthenticated remote attacker. Exploitation requires a configuration that enables the DAV module's MOVE or COPY methods together with a prefix (non-regular-expression) location and an alias directive, after which crafted MOVE/COPY requests can overflow a buffer in the worker process. A successful attack can terminate the NGINX worker process (denial of service, high availability impact) or modify source or destination file names outside the document root, with integrity impact limited because the worker process runs with low privileges. Only deployments using that specific DAV configuration are affected, and versions that have reached End of Technical Support were not evaluated. No public proof-of-concept or CISA KEV listing exists yet, but EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile), and the ZDI advisory (ZDI-26-578) describes the underlying integer underflow as potentially leading to remote code execution.
    · f5 nginx open source · f5 nginx pluslarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.