The Button Was the Payload: A2UI CVE-2026-10032
CVE-2026-10032 shows how an agent-generated button can turn declarative UI data into browser behavior. Trace the sink, safe lab, patch, and detections.
Practical Shodan.io guide for security teams: build precise queries, use facets, avoid false positives, automate checks, and validate internet exposure.

CVE-2026-10032 shows how an agent-generated button can turn declarative UI data into browser behavior. Trace the sink, safe lab, patch, and detections.
CVE-2026-61742 turned a browser into a network pivot against DBHub MCP. We reproduce the DNS rebinding flaw, compare 0.22.4 with 0.22.5, and map practical detection and defense.
Five Nuclei flaws show how alternate loaders, embedded runtimes, and response evaluation can turn a security scanner into the asset under attack.
Three http4s Ember flaws let proxies and origins disagree about HTTP request boundaries. Trace the mechanics, safe lab, detection, and durable fixes.
CVE-2026-86060 turned a crafted RouterOS SSH identity into administrative policy. Trace MikroTrick, a safe lab, detection logic, and trusted recovery.
CVE-2026-81963 is an exploited Windows Update link-following flaw. Trace the SYSTEM escalation model, safe mechanism lab, detection logic, and patch validation.
Jenkins configuration forms can become constructor dispatch. Trace the September 2026 flaws, a safe mechanism lab, detection signals, and durable fixes.
CVE-2026-47849 let JSON Patch mutate Spring Data REST identifiers and version fields. This analysis verifies the binding flaw, traces the cross-record overwrite path, and maps practical detection and hardening controls.
CVE-2026-60004 turns duplicate Gitea diffpatch requests into an executable Git hook. Analyze the attack chain, detection signals, and containment.
CVE-2026-61539 turned attacker-influenced Llama tool output into Python RCE inside Xinference. This analysis traces the parser boundary, validates the primitive in a safe local lab, and maps durable detection and hardening controls.
ShieldBreak (CVE-2026-69414) abuses file-path resolution around Microsoft Defender. Trace the privilege chain, detection telemetry, and interim controls.
Unit 42’s Pass-ta-key research exposes device-trust and recovery attacks around Google-synced passkeys. Trace the mechanics, detection, and defensive choices.
Gunra’s locker is the last stage. Detect the earlier handoff from VPN compromise to remote access, exfiltration, backup deletion, and offline encryption.
A macOS ClickFix campaign hid its lure behind browser fingerprinting. This analysis reproduces the gate safely and builds detection across web, endpoint and identity telemetry.
CISA’s 2026 SBOM baseline improves software identity and evidence quality. This advanced guide turns that inventory into an auditable VEX pipeline for exploitability decisions, release policy, and detection.