<?xml version="1.0" encoding="UTF-8" ?>
<rss version="2.0">
  <channel>
    <title>CYBERCULT</title>
    <link>https://blog.cybercult.biz</link>
    <description>Daily briefings on critical security disclosures, vulnerabilities, and threat intelligence.</description>
    <language>en-us</language>
    <lastBuildDate>Fri, 04 Sep 2026 10:45:25 +0000</lastBuildDate>
    <item>
      <title>Coder Registry Hijacked via Cloudflare Origin Manipulation to Push Malicious Terraform Modules</title>
      <link>https://blog.cybercult.biz/posts/2026-09-04-coder-registry-compromise/</link>
      <description>On August 31, 2026, threat actors compromised the Cloudflare account governing cloud development platform Coder, injecting unauthorized IP addresses into the origin pool for &lt;code&gt;registry.coder.com&lt;/code&gt;. Over a fourteen-hour window, the rogue endpoints selectively intercepted inbound requests and delivered modified Terraform modules containing credential-harvesting code to engineers across enterprise and public-sector environments. Coder responded by removing the rogue IP addresses, terminating active administrative sessions, and distributing updated integrity hashes, though the breach underscores how upstream traffic tampering can outmaneuver otherwise vigilant cybersecurity defenses.</description>
      <pubDate>Fri, 04 Sep 2026 12:00:00 +0000</pubDate>
      <guid isPermaLink="true">https://blog.cybercult.biz/posts/2026-09-04-coder-registry-compromise/</guid>
    </item>
  </channel>
</rss>
