<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>fullchain.sh</title>
  <subtitle>from bug to shell.</subtitle>
  <link href="https://fullchain.sh/"/>
  <link rel="self" href="https://fullchain.sh/feed.xml"/>
  <id>https://fullchain.sh/</id>
  <updated>2026-09-02T08:00:00Z</updated>
  <entry>
    <title>Wednesday 2 September — 3 priority findings, 6 secondary</title>
    <link href="https://fullchain.sh/2026-09-02"/>
    <id>https://fullchain.sh/2026-09-02</id>
    <updated>2026-09-02T08:00:00Z</updated>
    <category term="important"/>
    <summary type="text">A no-interaction iMessage chain installed Pegasus, multiple coding agents ran repository-selected Git helpers before trust, and PaperCut’s second emergency patch left attack paths open in the wild.

Pegasus delivered device-wide surveillance; coding-agent remediation remains partial, and PaperCut says Release 2 must be replaced by Release 3.</summary>
  </entry>
  <entry>
    <title>Tuesday 1 September — 2 priority findings, 3 secondary</title>
    <link href="https://fullchain.sh/2026-09-01-r2"/>
    <id>https://fullchain.sh/2026-09-01-r2</id>
    <updated>2026-09-01T08:00:00Z</updated>
    <category term="interesting"/>
    <summary type="text">A public exploit turns Avast's own sandbox into a SYSTEM shell for any standard Windows user, and no patch exists; separately, Zimbra servers running an optional SNMP package are being compromised through SMTP input that becomes a shell command.

SecurityAffairs and Cyber Kendra reported the same claimed capability and that no vendor fix and no CVE were public at the time they checked. Exploitation requires SMTP reachability to a Zimbra server that has the optional zimbra-snmp package installed, snmp_notify enabled, and swatchdog running.</summary>
  </entry>
</feed>