Welcome aboard. Crow’s Nest is a curated roundup of news, techniques, tools, and exploits from across the security community, brought to you by Black Lantern Security.
Crow's Nest - 2026-09-21
A roundup of 483 items curated from across the security community. News Thailand Finance Ministry Targeted by AI Agent Attack by /r/netsec. Hunt.io documents an AI agent attack targeting Thailand’s Ministry of Finance with Hermes running approval prompts disabled. Cyclops Blink Returns on Compromised Cisco FMC Devices by hasherezade. Sophos discovers a new Cyclops Blink variant on compromised Cisco FMC devices. Extended capabilities beyond the original malware analyzed by UK NCSC. OmniRoute RCE PoC Disclosed (CVE-2026-88062, CVSS 9.5) by kmkz. Public PoC released for OmniRoute CVSS 9.5 RCE vulnerability. ...
Crow's Nest - 2026-09-14
A roundup of 388 items curated from across the security community. News Trezor Data Breach Reaches 81,000 Customers by BleepingComputer. Trezor hardware wallet breach via email provider Brevo now confirmed to affect 81,000 customers, up from initial estimates. LG TVs Record Audio in Standby, Scan Local Networks by Sean Metcalf. Gamers Nexus testing reveals LG Smart TVs scan local networks, identify content, and record audio even in standby mode with no internet connection. WebOS flaws could enable RCE. ...
Crow's Nest - 2026-09-08
A roundup of 300 items curated from across the security community. News French Hospital Fined 500K After 727,000 Patient Breach by BleepingComputer. French hospital fined 500,000 euros after a breach exposed personal and medical data of 727,000 patients. 12-Year-Old PostgreSQL Vulnerability Enables Server Takeover by Nicolas Krassas. A 12-year-old vulnerability in PostgreSQL enables full database and server takeover. Four Arrested in Nairobi Over SIM-Swapping Scheme by Nicolas Krassas. Four Chinese nationals arrested in Nairobi for running a SIM-swapping and money-laundering operation. ...
Crow's Nest - 2026-09-02
A roundup of 445 items curated from across the security community. News Aikido Outperforms Claude Security Mythos with Smaller Models by Dave Aitel. Aikido demonstrates that many small-model agents find more vulnerabilities than a few large-model agents, outperforming Claude Security Mythos at a fraction of the token cost. DEF CON: AI-Automated Bluetooth Firmware Reverse Engineering by thaddeus e. grugq. DEF CON talk and tools from Xeno and Veronica Kovah on using AI to automatically reverse engineer Bluetooth firmware. LLM skills repo published. ...
Crow's Nest - 2026-08-25
A roundup of 429 items curated from across the security community. News Hackers Arrested Over 30M Euro Bank Fraud by BleepingComputer. Hackers arrested for exploiting a service provider flaw to steal over 30 million euros through bank fraud. LiveOverflow Reacts to OpenAI Black Hat Agent Talk by LiveOverflow. LiveOverflow’s reaction to the OpenAI Black Hat talk on AI agents finding vulnerabilities and moving laterally. Explores the implications for defenders. Gold Eagle Vulnerability Clearinghouse Faces Capacity Concerns by SwitHak (). The Gold Eagle vulnerability clearinghouse is meant to rescue vuln management from an AI-fueled discovery crisis. Experts question whether it has the capacity and redundancy to deliver. ...
Crow's Nest - 2026-08-17
A roundup of 611 items curated from across the security community. News OpenAI Agents Weakened Their Own Guardrails to Gain Access. Black Hat talk details how OpenAI’s evaluation agents began weakening their own guardrails, finding ways to communicate and scheme to gain further access and privileges. Recording now on YouTube. XSS2Shell: WordPress Core Pre-Auth XSS to RCE (CVE-2026-64638) by Florian Roth. Pre-auth XSS chains to full RCE on WordPress core, affecting 43% of the internet. Discovered autonomously using open-source models. All WordPress versions affected. ...
Crow's Nest - 2026-08-04
A roundup of 283 items curated from across the security community. News BLS Presents BBOT at DEF CON Recon Village. Black Lantern Security is presenting at DEF CON 34’s Recon Village this week, covering BBOT’s evolution and the new 3.0 architecture with Rust-powered DNS and HTTP engines. The Hacker Who Humiliated Spyware Makers and Was Never Caught by scriptjunkie (Matt). TechCrunch deep dive into Phineas Fisher, the hacktivist behind spectacular breaches of FinFisher and Hacking Team who has never been identified or caught. ...
Crow's Nest - 2026-07-29
A roundup of 448 items curated from across the security community. News CVE-2026-12118: IBM webMethods Integration Server Vulnerability. Black Lantern Security discovered and reported this vulnerability in IBM webMethods Integration Server. Full technical writeup with reproduction steps. LG Bans Residential Proxy Apps from Smart TVs. Krebs reports LG will suspend smart TV apps that turn televisions into residential proxy nodes. Over 42 percent of webOS store apps were found routing third-party traffic through users’ devices. ...
Crow's Nest - 2026-07-20
A roundup of 312 items curated from across the security community. News EU Exposes FSB Centre 16 as Controller of TURLA Operations by thaddeus e. grugq. The EU formally attributes TURLA and related cyber operations to the FSB’s 16th Centre, alongside its broadest cyber sanctions package yet targeting Russian-linked actors. Microsoft July Patch Tuesday: Record 570 Flaws, 3 Zero-Days by BleepingComputer. The largest Patch Tuesday ever. 570 fixes including 3 zero-days (2 actively exploited) and 141 RCE flaws. Microsoft attributes the surge to AI-assisted vulnerability discovery. ...
Crow's Nest - 2026-07-13
A roundup of 265 items curated from across the security community. BBOT 3.0: Rust-Powered Recon with 15x Faster DNS The biggest BBOT release ever. Core DNS and HTTP engines rewritten from scratch in Rust, delivering 15x faster DNS resolution and FFUF-class directory brute-forcing without leaving the BBOT process. New modules, native SIEM outputs, ASN targeting via the BBOT.IO API Hub, and reworked scoping. Free and open source. Read more News KDDI Breach Exposes Data of 12 Million Japanese Customers by BleepingComputer. Japanese telecom giant KDDI confirms a data breach affecting 12 million customer records, one of the largest telecommunications breaches in recent years. ...
