Exploitation ongoing with high activity in latest observed window (1 mentions)
Immediate actions
Prioritize remediation for canonical command_center systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Track advisory updates for patch or workaround availability
Recommended action window: Immediate (within 24h)
NVD description
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of pkexec doesn't handle the calling parameters count correctly and ends trying to execute environment variables as commands. An attacker can leverage this by crafting environment variables in such a way it'll induce pkexec to execute arbitrary code. When successfully executed the attack can cause a local privilege escalation given unprivileged users administrative rights on the target machine.
pkexec ships SUID-root on every major Linux distro. it had a local root exploit in its very first commit, May 2009, hidden for 12 years. CVE-2021-4034, "PwnKit".
the bug isn't a clever overflow. it's what happens when you assume argc is never 0.
execve lets you run a program with an empty argument list: argv = {NULL}, argc = 0. here's main() processing the args:
534 for (n = 1; n < (guint) argc; n++)
if argc is 0 the loop never runs and n stays 1. a few lines down:
610 path = g_strdup (argv[n]);
639 argv[n] = path = s;
it reads and writes argv[1]. but argc was 0, so argv[1] doesn't exist. the kernel lays argv and envp back-to-back on the stack, so argv[1] is actually envp[0], your first environment variable.
so pkexec reads a program name from your env, resolves it via PATH, and writes the result back over envp[0]. that's an arbitrary write into the environment of a SUID-root process, the exact thing http://ld.so strips for SUID binaries.
re-introduce GCONV_PATH, point it at your own .so, trigger an error message, and pkexec loads your library as root.
no ASLR bypass, no ROP, no arch-specific offsets. instant, reliable, works even with the polkit daemon dead.
https://www.qualys.com/2022/01/25/cve-2021-4034/pwnkit.txt
Post summary
The passage details how CVE‑2021‑4034 (PwnKit) can be leveraged by manipulating environment variables, provides PoC logic, and links to an external write‑up, but does not report live exploitation or patches.
Operation Master exposed: a single Brazilian 🇧🇷 threat actor ran a full intrusion-to-fraud pipeline, exploiting CVE-2026-0257 across 7 GlobalProtect gateways in four countries, stealing 600+ companies' data, then weaponizing it inside an automated multi-tenant invoice fraud platform that generated 2.4M+ messages and R$150.4M in attempted PIX fraud.
- CVE-2026-0257 (GlobalProtect authentication bypass) was the primary at-scale access vector. The actor forged auth cookies from target certificate context and fed candidates through a 30-worker automated exploit loop driven by continuous masscan output across 277.5M scanned hosts. The same CVE is being exploited separately by ransomware actors including Qilin, making it a high-priority patch target. Beyond VPN access, parallel campaigns hit SQLi targets via sqlmap and xp_cmdshell chains to pivot from database access to host execution, with DNS subdomain tunneling (470,268 queries from a single compromised host, structured as task.row.chunk.base64.x.random.victim-hostname) as the primary exfil rail, and rclone syncing to MEGA as a redundant second channel. Staged webshells (beacon.dll, wmsvc.dll, gopher_new.exe) and AdaptixC2 on 91.92.241[.]187 (ports 8443/4444/4321) provided C2 over HTTP and raw TCP. Additional techniques: SAM/SYSTEM/SECURITY hive theft (T1003.002), ntds.dit recovery (T1003.003), GodPotato token impersonation, PwnKit (CVE-2021-4034), CVE-2024-1086, and CVE-2023-7028 (CVSS 10.0 GitLab dual-email reset) hardcoding cyberkill2025[@]http://gmail.com as the attacker-controlled recovery address.
- The fraud monetization layer is a Node.js multi-tenant "master-panel" at /opt/master-panel/, running under PM2, backed by PostgreSQL and SQLite, and exposed externally on yzs[.]fi. Lookalike domains igreenfaturas[.]to, wattiofaturas[.]com, and nuvfaturas[.]com hosted per-victim invoice pages with URL parameters embedding the victim's real name, due date, consumption, and billing amount pulled from stolen utility databases. Email delivery routed through 12 hijacked M365 mailboxes (retail, healthcare, education) to inherit sender reputation. SMS ran across 8 SMPP gateways. PIX payments routed through a serverless Vercel proxy at pix-proxy-sable.vercel[.]app. The lead source was 1.8M records scraped via a passwordless JWT flaw in iGreen Energia's API. The fraud engine logged 622,666 personalized links, 317,696 click events, and R$38.9M in fraudulent invoices opened by victims.
- Attribution converges on forum persona masterblack and primary email cyberkill2025[@]http://gmail.com, which appears across: 34 fraud panel lead test records, the GitLab CVE-2023-7028 exploit hardcoding, OSINT API registrations (Shodan, VirusTotal, SecurityTrails, WPScan, AlienVault OTX), a recovered pentest report listing the operator, and a leaked hacker forum database record directly linking the email to the masterblack account that sold stolen iGreen and Wattio data weeks before the fraud campaigns began. The two-stage strategy, sell the data first, then phish the same victims with their own billing records, is confirmed by the 9 to 14 week gap between forum sale listings and bulk tenant seeding. The operator's AI agent workspace (36+ offensive subagents, ~45 persistent memory files) was exposed via a misconfigured cloud backup reachable from the first exploitation server at 85.120.216[.]8.
- Key detection opportunities from the article: sqlservr.exe spawning cmd.exe or PowerShell is a high-fidelity signal for the xp_cmdshell chain. High-entropy DNS queries from database service identities indicate active tunneling. rclone or unauthorized cloud-sync binaries on servers warrant immediate investigation. OAuth device-code grants without corresponding enrollment events indicate T1598 phishing. Unauthorized reads of SAM, SYSTEM, SECURITY hives or ntds.dit by service accounts are critical alerts. For the fraud infrastructure specifically, URL parameters matching the schema ?ref=, venc=, v=, v0=, kwh= on lookalike utility domains are a structural indicator of the invoice fraud platform's output.
Full IOC table (IPs, domains, SHA-256 hashes for all beacon and agent variants, qTox IDs) and the complete MITRE ATT&CK mapping are in the SOCRadar report. Prioritize hunting for AdaptixC2 gopher agent artifacts (gopher_new.exe SHA-256 54caa256483876debd21c264bfc31bd96f925b2167f6d9358ab7ee0c87e6e37b, beacon.dll SHA-256 d566ccdd099b0decb7e7288c20097f34da2613e3ffe8c5acbc1a1d01b6fe217c) and block the four operation server IPs: 85.120.216[.]8, 91.92.241[.]187, 91.92.241[.]184, and 185.242.3[.]14.
#DFIR_Radar
Post summary
A Brazilian threat actor exploited CVE‑2026‑0257 to compromise GlobalProtect gateways, stole data, and ran an automated invoice‑fraud operation resulting in millions of dollars of attempted fraud.
How does a Linux vulnerability hide for more than a decade?
PwnKit did.
CVE-2021-4034 created a path from an unprivileged user to root.
See how PwnKit works and what defenders can learn from it:⤵️ https://bit.ly/4iN2Wip https://t.co/YJ6SeBZjFS
Post summary
The post highlights how CVE-2021-4034 enables privilege escalation via PwnKit, provides a link for deeper insight, and outlines key technical details without claiming active exploitation or offering fixes.
How does a Linux vulnerability hide for more than a decade?
PwnKit did.
CVE-2021-4034 created a path from an unprivileged user to root.
See how PwnKit works and what defenders can learn from it:⤵️ https://bit.ly/4qW84mr https://t.co/svfzvNHuv3
Post summary
The tweet references CVE‑2021‑4034, a long‑hidden privilege‑escalation flaw in PwnKit, and provides a link that presumably contains a proof‑of‑concept exploit for defenders to review.
PwnKit (CVE-2021-4034): Análisis de la Escalada de Privilegios Crítica en Linux
https://nksistemas.com/pwnkit-cve-2021-4034-analisis-de-la-escalada-de-privilegios-critica-en-linux/
Post summary
The article provides a Spanish technical analysis of CVE-2021-4034 (PwnKit) focusing on privilege escalation details, but it does not include PoC code, exploit tools, patch guidance, or reports of active exploitation.
I just completed Pwnkit: CVE-2021-4034 room on TryHackMe! Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package https://tryhackme.com/room/pwnkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=65869e2abbbd1398b6caad7d #tryhackme via @tryhackme
Post summary
The tweet announces completion of a TryHackMe lab that demonstrates exploitation and remediation of Pwnkit (CVE-2021-4034), indicating a proof‑of‑concept is available but no further exploit or technical details are shared.
The tweet simply references CVE‑4034 (Pwnkit) with a year marker, providing no additional details, PoC, exploit, patch, or evidence of active exploitation.
I just completed Pwnkit: CVE-2021-4034 room on TryHackMe! Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package https://tryhackme.com/room/pwnkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme#tryhackme#LearningInPublic
Post summary
The user completed a TryHackMe lab that demonstrates exploiting and remediating the Pwnkit (CVE-2021-4034) vulnerability, sharing the lab link for others to view.
I just completed Pwnkit: CVE-2021-4034 room on TryHackMe! Interactive lab for exploiting and remediating Pwnkit (CVE-2021-4034) in the Polkit package https://tryhackme.com/room/pwnkit?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme
Post summary
The tweet announces a TryHackMe interactive lab that demonstrates exploitation and remediation of the Pwnkit vulnerability (CVE-2021-4034) in Polkit.
"Exploiting PwnKit (CVE-2021–4034)" by Shivam Bathla
#BugBounty#Cybersecurity#Hacking#InfoSec
https://medium.com/@shivam_bathla/exploiting-pwnkit-cve-2021-4034-ac5d6995c499
Post summary
The linked Medium post likely presents a demonstration of exploiting the PwnKit vulnerability (CVE-2021-4034), but the provided excerpt offers no explicit PoC details, exploit code, or patch information.