A roundup of 277 items curated from across the security community.

News

Multiple Scattered Spider members plead guilty on the first day of their federal trial.

42 TanStack packages published with valid SLSA provenance by stealing OIDC tokens from GitHub Actions runner memory. Provenance verification alone no longer guarantees integrity.

USB controller implementation flaw on Apple A12 and A13 devices allows bootloader compromise. Exploit code published; no software patch possible.

Bidirectional RCE in Redis 8.8.0. Client plus server exploitability makes it wormable. PoC withheld pending patch.

Russian cybercriminals offering $500 via Telegram for people to physically visit US law firms and plug in USB sticks.

NTLM reflection bypass with public PoC gives SYSTEM on Windows Server 2025. Patch now.

Attackers compromised HSIN, the Homeland Security Information Network used for inter-agency intelligence sharing.

More this week (27)

Techniques and Write-ups

Entra ID conditional access policies with resource exclusions can be bypassed to access protected resources. Enable baseline enforcement if you have such policies.

Heartbleed-style pre-auth memory overread in Citrix NetScaler. watchTowr walks through discovery and exploitation of CVE-2026-8451.

Uninitialized heap memory in Progress Kemp LoadMaster leads to pre-auth remote code execution. watchTowr walks through the full chain.

Boeing published an emergency notice canceling shifts at multiple plants as IT systems went down. Echoes of the Jaguar Land Rover production halt.

Two critical vulnerabilities in Cursor IDE turn prompt injection into full remote code execution with no user interaction required.

Zero-day local privilege escalation exploiting the Windows Defender quarantine pipeline.

LLMs make local EDR rulesets, YARA rules, and behavioral detections trivial to extract. Demonstrates how simple the harness can be.

From a host foothold, researchers sideloaded into the signed claude.exe, reconstructed its RPC client, and achieved root inside the Cowork VM with full egress.

Custom FortiGate sniffer harvesting credentials at scale, now linked to INC and Lynx ransomware operations.

Fake PoC exploit repositories delivering a full-featured RAT specifically targeting security researchers.

Synacktiv pointed a local LLM at FreeBSD and found a local root exploit (CVE-2026-49415) plus an ASLR bypass on SUID binaries (CVE-2026-49414). Both patched.

Escaped the Dataverse plugin sandbox to access a million lines of Microsoft proprietary source code and more.

One-shot LLM-generated Stage-0 agents for Mythic, from prompt to deployment in roughly two hours. First post in a series on disposable tooling.

More this week (200)

Tools and Exploits

Compiles Rubeus and Seatbelt to WebAssembly and runs them outside the CLR entirely, bypassing AMSI and ETW. Open source.

Linux memory forensics via virtual filesystem, modeled after MemProcFS. Mount memory and browse processes, network connections, and artifacts as files.

Beacon Interpreter lets operators write and execute C directly in Beacon’s VM with no extra memory allocation, eliminating the BOF compile loop.

Kali Linux 2026.2 Release (GNOME 50, KDE 6.6, Helper Scripts, APT Formats & VM Boot Tweaking): It’s the final week of Q2, and Kali Linux 2026.2 is here - right on schedule ;) We have been heads down since our last rel…

x64 BOF that enables Chrome DevTools Protocol on Edge and Chrome for browser session hijacking during engagements.

Enumerates authentication methods (passkeys, certificate auth, passwordless push) for Microsoft accounts without credentials.

Raphael Mudge returned to publish his evasion tradecraft openly. Crystal Palace handles PIC code, binary transformation, register randomization, and YARA generation from invariant instructions.

New persistent workspace for Frida with interactive REPL, frida-trace integration, and collaboration. Available for macOS, iOS, Linux, and Windows.

Adds sysvol, ldap, and parse modules for offline and remote GPO auditing in Active Directory environments.

Scans Windows kernel drivers for dangerous imports, extracts IOCTL surfaces, and cross-references against LOLDrivers, the MS Blocklist, and KDU.

More this week (20)