§ Trackr.Live
Latest writing

Notes from Trackr.Live

The landing site for Trackr Services

AU

metabase_database.details, the Column Storing Snowflake Credentials in Cleartext

Metabase’s CVE-2026-72898 patch closes an unauthenticated SQL injection in the password-reset endpoint, but it does not remove the admin accounts, API keys, or rotated connected-database credentials an attacker created before you upgraded. Here is what the retro-hunt actually looks like in ingress logs and the Metabase application database.

·
AC

CoreBreak: Tool Execution Without a Model Turn in Three Runtimes

Four CVEs across AWS, Google, and Vercel agent runtimes converge on one authorization failure: tool execution could proceed with no trustworthy binding to a model-authorized event. Here is what the audit record shows, what the detection actually looks like in CloudWatch and Splunk, and why the Strands branch that started it all is still open.

·
Cyber Tools

Rebuild and Reissue: SMA 1000 Remediation After INC Ransomware

The SonicWall SMA 1000 exploit chain gets from unauthenticated HTTP to root through a loopback service and a control-service password derived from the appliance’s DMI product_uuid. Rapid7 and Resecurity assess INC Ransomware as the dominant actor now weaponizing it, and the loot — session databases and TOTP seeds — is why patching alone does not end the incident.

·
AC

Valid Credentials and Overbroad Grants: Inside the Hugging Face Intrusion

Hugging Face’s July 27 timeline of the autonomous agent intrusion reads as a sequence of identity operations: node impersonation via IMDS, TokenRequest minting, an over-scoped CSI ClusterRole spent on a privileged pod, and forged tokens from a stolen EdDSA signing key. The lessons sit in key custody and least privilege, plus one correction worth stating plainly: audience binding does not contain a compromised signer.

·
CM

LegacyHive Mounts a Target’s Hive Into the Helper’s Session

A working Windows exploit dropped roughly half an hour after July’s Patch Tuesday, with no CVE and no Microsoft advisory. LegacyHive edits a registry hive while it is unmounted, so live registry auditing never sees the write, and the payoff is another account’s hive mounted into a session the attacker controls. Here is what actually fires, what the first published rule got wrong, and which controls cut the class.

·
Artificial Intelligence

Half the Validated Prompt Injections Rode in HTTP Headers

An indicator-driven study built a corpus from 1.2 billion Common Crawl URLs plus indicator-matched Censys and Shodan snapshots, and 51.2% of its 15,387 validated injections sat in custom HTTP response headers rather than page content. Here is what that number does and does not measure, why header presence is a serialization problem rather than a protocol problem, and why the representation your pipeline hands the model matters more than the header namespace.

·
AC

Gmail Content Compliance: The Audit Event Retires After August

A PRC-nexus actor exfiltrated years of medical and defense research by creating a single domain-level Gmail content compliance rule that silently BCC’d matching mail to an attacker Gmail account. It produced no endpoint telemetry and no user-visible forwarding setting, and the admin audit event family that authoritatively records it is mid-migration, with the legacy events retiring after August 2026.

·
AC

Residential Exit Nodes Your Impossible-Travel Rule May Never See

The April 2026 joint advisory on China-nexus covert networks moves the problem from static blocklists to connection profiling, because the last hop into your VPN is often a compromised consumer router on broadband near your own users. Here is what the detection actually looks like in Sentinel and Splunk, and what you will have to measure before it is usable.

·