A roundup of 160 items curated from across the security community.
News
FBI releases a PSA on TeamPCP, a data extortion group responsible for the longest running streak of software supply-chain hacks on record, including compromises of Trivy, CheckMarx, LiteLLM, and at least 3,800 GitHub repositories.
An Iranian hacker arrested in Montenegro for hacking over 100 US universities on behalf of the IRGC highlights Iran’s shift toward economic espionage and intellectual property theft.
A startup is suing Palo Alto Networks after an AI-generated threat report falsely linked them to Chinese espionage. A cautionary tale about AI in threat intelligence attribution.
DOJ announces the arrest of an alleged Scattered Spider member in Finland. Court documents reveal Microsoft’s GDID telemetry was used to track the suspect across VPNs and reimages.
Major Russian-language cybercrime forum XSS.is has been shut down and its alleged administrator arrested in a law enforcement operation.
First documented case of a ransomware group deploying an autonomous AI agent to execute the full attack chain, from initial access through encryption.
GMO Cybersecurity reports a privilege escalation vulnerability that went unnoticed in the Linux kernel for over 19 years. Now patched.
A new Linux kernel vulnerability affecting 6.4+ kernels and newer Android devices. PoC achieves 99% reliability for local-to-root escalation and may trigger from Chrome’s renderer sandbox.
Nextron Research confirms the Lazarus-linked npm supply chain campaign is ongoing, with new packages using fresh JSONKeeper URLs and C2 infrastructure dropping and executing payloads via Node.
More this week (10)
- Using #Helm and #Kubernetes in your CI/CD pipeline? An attacker only needs access to the values.yaml file to compromise your cluster. Recent research … by Synacktiv.
- I somehow missed out on the latest big Tor update for our # DefCon .onion server. I’m in the process of upgrading. https:// gitlab.torproject.org/tpo/core /tor/-/raw/tor-0.4.9.11/ChangeLog # Tor # Pri.
- RT The Hacker News: A new #Linux kernel exploit (CVE-2026-46331) gets root without modifying a single file on disk. It poisons the cached copy of… by Simone Margaritelli.
- RT REcon: For those who are looking for talk slides you can find them in schedules for the speaker who have uploaded their slides https://cfp.recon.cx… by hasherezade.
- RT hacker.house: Wild things going on at the water coolers of @HuntressLabs this week. According to a former employee, an insider threat has been tipp… by kmkz.
- RT VulnCheck: VulnCheck recently disclosed CVE-2026-53805, an NVIDIA GEN3C inference API flaw that could let unauthenticated attackers run code on vul… by kmkz.
- Dawg, the Peter Stokes affadavit (nerd from Scattered Spider who was arrested) is fucked This dude was on Snapchat sending people pictures of him with… by vx-underground.
- RT SEKTOR7 Institute: Analysis of how IPv6 auto-configuration enables MITM6 and NTLM relay for domain compromise. A post by @RESecurity Source: https:… by Steven Lowson.
- RT Ayush Anand: If you detect Advanced IP Scanner, stop treating it like “just recon.” It often means the attacker already has an interactive deskto… by SwiftOnSecurity.
- RT vx-underground: > Peter Stokes > Scattered Spider guy > Arrested > Microsoft helps FBI > Read court documents > Page 12 > Microsoft tracks Stokes f… by Florian Roth.
Techniques and Write-ups
FBI seizes hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies, connected to the 2-million-device Popa botnet.
Routes memory allocation APIs through Firefox’s signed mozglue.dll so the allocating module appears as a trusted Firefox component. Includes detection guidance.
Synacktiv pointed a local LLM at FreeBSD and found a local root exploit plus an ASLR bypass on SUID binaries. Both now patched as CVE-2026-49415 and CVE-2026-49414.
Synacktiv demonstrates how a single Helm chart misconfiguration leads to full Kubernetes cluster compromise through unauthenticated RCE in Argo CD, found using CodeQL.
watchTowr dissects a batch of CVEs in Adobe ColdFusion from security bulletin APSB26-68, with detailed root cause analysis.
Two critical RCE vulnerabilities in the Cursor IDE allow zero-click exploitation through prompt injection, turning an AI code editor into a remote code execution vector.
SpecterOps demonstrates how simple LLM harnesses can extract EDR rulesets, YARA rules, and behavioral detections from local endpoint agents. The barrier to reverse-engineering defensive tooling just dropped to a single prompt.
watchTowr analyzes CVE-2026-8037, an uninitialized heap vulnerability in Progress Kemp LoadMaster that leads to pre-authentication remote code execution.
Raphael Mudge returned to the industry and is publishing evasion tradecraft openly. Crystal Palace provides position-independent code, binary transformation, register randomization, and a PICO convention for reusable tradecraft modules.
SpecterOps releases a Time Travel Debugging MCP server for Windows, enabling LLM-powered reverse engineering workflows through recorded execution traces.
watchTowr identified and disclosed a zero-day memory overread in Citrix NetScaler appliances. Patches now available. If you run NetScaler, patch immediately.
CyberCakeX’s Harden Windows Security app has matured into a full-featured hardening platform, now available on the Microsoft Store. Described as “$250k cyber consultant advice” for home users.
A new method to escalate privileges from a Microsoft Virtual Account using only certreq (a LoLBin) and AD-CS, successfully bypassing CrowdStrike without potato-class exploits.
Crowdfense chains two bypasses into a fresh RCE on fully patched Apache ActiveMQ 6.2.5 on Windows via WebDAV, found while researching CVE-2026-34197.
- France to Stop Certifying Non-Quantum-Safe Encryption by Bruce Schneier.
France’s ANSSI will halt certification of security products lacking quantum-resistant encryption, forcing government bodies and critical infrastructure operators to migrate.
More this week (113)
- The email provider Securence (US Internet, now owned by a joint venture between T-Mobile and KKR) has disabled its administrative portal for a week now, although email is still flowing. The company wo.
- zlib bugs?! We’re all gonna die before that gets patched everywhere. https:// blog.trailofbits.com/2026/07/0 2/field-reports-from-patch-the-planet/.
- Migrated my blog and published a new post. It covers a common type confusion vulnerability pattern I found last year in RPC servers. I don’t think th… by k0shl.
- RT Armadin: Claude Cowork runs agent tasks in a local Linux VM. From a host foothold, Armadin’s red team sideloaded into the signed claude.exe, recons… by Giuseppe
N3mes1s. - RT Adnan Khan: There is an unpatched #GitHub privesc #0day actively exploited right now that allows dumping Actions secrets/OIDC abuse without workflo… by Giuseppe
N3mes1s. - Interesting food for thought concerning payload dev… Same basic unsigned console app (calls MessageBoxA and exits): - Left: Compiled w/ mingw-gcc - … by Octoberfest7.
- PowerVR: virtual/physical unit confusion in DevmemIntComputeVirtualIndicesFromLogical() leads to OOB kernel write https://project-zero.issues.chromium… by Project Zero Bugs.
- Quick Assist is a built-in Windows remote support tool that’s increasingly abused in social engineering campaigns. Because it’s installed by default o… by Samir.
- I could not find source code so I asked my friend Claude to create some code for this to better understand it. https://github.com/S3cur3Th1sSh1t/Kassa… by S3cur3Th1sSh1t.
- Essential. There is a sub 1% population of networks for this isn’t just an instant win for them if you’re not using LAPS. by SwiftOnSecurity.
- RT crep1x: Together with @yeswehack and @plebourhis, we documented a campaign targeting vulnerability researchers, pen-testers, and possibly cybercrim… by SwitHak ().
- RT Rem: I get to be that guy again! @HuntressLabs has once again observed a large influx of successful malicious authentications against SonicWall SSL… by SwitHak ().
- Effective July 14, 2026, Adobe is moving from monthly to twice-monthly2⃣ publication of Adobe Security Bulletins and Advisories… by SwitHak ().
- RT CISA Cyber: Russian Intelligence Services cyber threat actors are conducting phishing campaigns on commercial messaging apps. Read our updated PSA … by SwitHak ().
- Kindle research, exploitation methodology, and jailbreak development. Missed @leHACK? @SidewayRE’s talk, “Bootstrapping Kindle Research for the… by Synacktiv.
- Been working on this post for a few weeks, here’s the second part of my LLM/AI-Assisted work flow series looking at harnesses and how they’re designed… by Andy Gill.
- FIFA was saved this time https://bobdahacker.com/blog/fifa-hack by /r/netsec.
- Detecting Agentic AI Threats in Claude: Sigma Rules and Correlation Detections for the Execution Layer https://www.papermtn.co.uk/detecting-agentic-th… by /r/netsec.
- Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) https://syntetisk.tech/blog/posts/privilege-escala… by /r/netsec.
- Symfony YAML Security Audit - Shielder https://www.shielder.com/blog/2026/06/symfony-yaml-security-audit/ by /r/netsec.
- Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website run a drive-by RCE. CVSS 9.3 https://amibeingpwned.com/blog/signer-digital-rce by /r/netsec.
- Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)… by /r/netsec.
- RT Cisco Talos Intelligence Group: Malware authors often hide their tracks using COM, but our latest guide provides the roadmap you need to decode tho… by Arris Huijgen.
- RT Abdul Mhanni: Wrote a new blog about caveats with tools detecting(or mis detecting) relay exploit primitives against http(ESC8) and MSSQL endpoints… by Arris Huijgen.
- RT International Cyber Digest: Re Link: https://blog.otterpwn.com/projects/heavener by bohops.
- New blog by my colleagues Dave (@johnnyspandex) and Adam: Microsoft Graph API - Hidden Exclusions with Overly Scoped Permissions https://blog.amb… by Rich Warren.
- RT @MalwareBibleJP: EDRのテーブル完全性チェックをすり抜けるWindowsプロセスインジェクション手法が公開されています。従来手法がPEB(Process-Environment-Bl… by Florian Roth.
- RT Zscaler ThreatLabz: Zscaler ThreatLabz has identified malicious websites that use indirect prompt injection (IPI) attacks to manipulate AI agents. … by Florian Roth.
- RT Eyal Sela: n4d is an active exploitation campaign that installs an implent on internet-exposed MCP endpoints that provide code execution tools. The… by Florian Roth.
- RT BleepingComputer: CISA: Microsoft SharePoint RCE flaw now actively exploited https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoi… by Florian Roth.
- RT blackorbird: Attackers systematically query LLMs to probe which fake domain names the models are most prone to generating for target brands. This p… by Florian Roth.
- RT BleepingComputer: FortiBleed credential-theft campaign linked to Lynx ransomware https://www.bleepingcomputer.com/news/security/fortibleed-credenti… by Florian Roth.
- RT Expel: The Gentlemen ransomware, in a BYOVD attack, used a zero-day exploit to kill EDRs before deploying their payload. The driver they abused was… by Dave Aitel.
- RT itszn: We found another exploitable V8 JIT bug CVE-2026-14431; fixed in the most recent Chrome update This one was an interesting case of sloppy mo… by Dave Aitel.
- RT SpecterOps: Testing an LLM once is easy. Testing it consistently is harder. Neeraj Gupta’s latest GhostWorks research introduces Jailbreaker, an op… by Matt Nelson.
- Flock Cameras Can Surveil Cars Without License Plates by Bruce Schneier.
- RT International Cyber Digest: ‼ BREAKING: Apple’s Hide My Email lets almost anyone uncover the real address behind a “hidden” alias, and Apple has… by Simone Margaritelli.
- Carnage. LOL. by Gareth Heyes \u2028.
- Not only NFC-Laboratory, @Jose4Vi is also playing with Emulation, take a look at his other project: https://github.com/josevcm/hce-laboratory by Benjamin Delpy.
- RT Jonathan Bar Or (JBO) 🇮🇱🇺🇸🇺🇦: Made a thing - Arbitrary Code Execution in Sid Meier’s Civilization! https://github.com/yo-yo-yo-jb… by Gergely Kalman.
- RT cr3ghost: Orange Tsai found hidden character transformations buried in Windows ANSI encoding that most applications have no idea exist. WorstFit ex… by Gergely Kalman.
- RT Check Point Research: Can a website turn into ransomware on Android? We found an AI-generated malware sample that suggests the answer is closer to … by hasherezade.
- RT Thomas Roccia : FuzzingLabs has created a curated repo of offensive MCP servers you can wire to your agents! https://github.com/FuzzingLab… by hasherezade.
- RT YungBinary: New blog is out! Digging into an obfuscating compiler used in building EKZ Stealer, a CLI-based infostealer delivered after a Fortinet … by hasherezade.
- RT cr3ghost: Satoshi Tanda found bugs in Microsoft’s own Hyper-V hypervisor and HVCI implementation as a by-product of learning how they work. Let tha… by hasherezade.
- RT dbugs: Analysis of the CVE-2026-45504 vulnerability in Microsoft Exchange that allows reading arbitrary files PT ID: PT-2026-47976 The article… by batuu.
- TABPE: A monthly Windows PE baseline dataset for Cyber-security researchers https://github.com/onhexgroup/TABPE by Panos Gkatziroulis.
- RT Swissky: Re @ipurple The official front-end is here https://swisskyrepo.github.io/PayloadsAllTheThings/ by Panos Gkatziroulis.
- TEB, PEB and List of Loaded Modules https://proteqtum.com/posts/02-win-x64-shellcode-teb-peb_en/ by Panos Gkatziroulis.
- GadgetSniper - Scans PE32+ binaries for instruction sequences of the form “call X ; jmp qword ptr [non-volatile-reg]”, the exact primitive needed to b… by Panos Gkatziroulis.
- skewrun - an Active Directory time discovery toolkit for Red Teams. Dynamically resolves the Domain Controller’s time via network protocols (CLDAP, SM… by Panos Gkatziroulis.
- Read the description ⤵ https://github.com/n0qword/win32k-callback-detouring by Panos Gkatziroulis.
- An x64 BOF that enables the Chrome DevTools Protocol msedge.exe chrome.exe Talk: Modern Session Hijacking by Living off the DevTools Prot… by Panos Gkatziroulis.
- RT 0x12 Dark Development: PEB Corruption: A Remote Process Crash Technique New Medium post, explores a direct approach to process termination: remote … by Panos Gkatziroulis.
- RT Nick VanGilder: Last night I added a new section to http://redteam.community called Books (https://www.redteam.community/books). The premise is sup… by Chihuahua in charge NotMe.
- RT Off-By-One Conference: Welcome Evangelos Daravigkas (@freddo_1337) & Ben Koo (@kiddo_pwn) of Team DDOS to @offbyoneconf! They present “No Time to P… by kiddo.
- “Cohesity TranZman (formerly developed by Stone Ram) is a migration appliance used to transition, merge, or replatform enterprise backup environments”… by kmkz.
- Zscaler ThreatLabz identified a new campaign in-the-wild, tracked as Operation Neusploit, targeting countries in the Central and Eastern European regi… by kmkz.
- RT Jλckλι: CVE-2026-6307 PoC + Report: [PoC]: https://github.com/J4ck3LSyN-Gen2/CVE-2026-6307-Longinus [Report]: https://github.com/J4ck3LSyN-Gen2/… by kmkz.
- RT dbugs: Container escape via IPv6 fragmentation bug in Linux kernel Researcher demonstrated PoC “IPV6_FRAG_ESCAPE” exploiting a memory-handling flaw… by kmkz.
- RT 8kSec: This blog reverse-engineers how Apple’s MIE works inside the iOS 26 kernel - hardware memory tagging that mitigates buffer overflows, UaF, a… by kmkz.
- RT Dark Web Informer: ‼ One POST to RCE: Unauthenticated Code Execution in Langflow (CVE-2026-33017) https://darkwebinformer.com/one-post-to-rce-un… by kmkz.
- Maybe interesting… by MalwareHunterTeam.
- RT Karl: Here are the slides from our @WEareTROOPERS presentation - “Modern Adventures in Azure Privilege Escalation” This was a fantastic conference … by Max.
- RT Kyle Meyer: As every bug bounty hunter and offensive security firm is building their own agentic testing platform… this is so massive by ProjectDiscovery.
- RT Marc Smeets: How the f can we still be having NTLM insecurities in the year 2026. Just how?! At this rate we will not be done with NTLM by 2033, mi… by Rémi GASCOU (Podalirius).
- RT V12: And here’s postgres bidirectional RCE no admin required, client infects server, server infects client by Rick de Jager.
- RT Doug Burks: Wireshark is a great tool but looking at traffic packet by packet can be overwhelming and you may lose the plot of the story. It’s much… by thaddeus e. grugq.
- RT Ionut Popescu: The mythos report for #curl 2026-05-06 made public: https://gist.github.com/bagder/c9b83a19f30e82e41b11f6315465b17a by Vincent Yiu.
- “Welcome to GoGatoZ - a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain.” Read mor… by Black Hills Information Security.
- 55.2% of respondents to Bitdefender’s 2026 Cybersecurity assessment were instructed to keep silent when they should have contacted the authorities. “R… by Black Lantern Security (BLSOPS).
- ARToken PhaaS exposes EvilTokens’ Microsoft 365 phishing toolkit https://www.bleepingcomputer.com/news/security/artoken-phaas-exposes-eviltokens-micro… by BleepingComputer.
- we need this … https://github.com/lautarovculic/ioscpy by Dimitri Os.
- [RT Enno Rey: Bitlocker downgrade attacks https://archives.pass-the-salt.org/Pass%20the%20SALT/2026/slides/PTS2026-TALK-13-bitlocker_talk_deck.pdf PDF… by DirectoryRanger.
- Plex Explorer. learning aid for security researchers explaining Microsoft’s Dataverse plugin sandbox architecture, aka Plex. By @kidtronnix @WEareTRO… by DirectoryRanger.
- RT Fabian Bader: Running Microsoft Defender for Endpoint on Linux? Then better wait with updating or manually re-enable and start it after the next re… by DirectoryRanger.
- RT 𝕡𝕨𝕟𝕚𝕖: Windows has an undocumented kernel function called MiReadWriteVirtualMemory. It’s what NtReadVirtualMemory and NtWriteVirtual… by DirectoryRanger.
- RT spencer: I’ve spent a good portion of the last 2 days testing coercion attacks against Server 2025. It’s holding up surprisingly well. IT Admins, i… by SwiftOnSecurity.
- People concerned about Windows telemetry, might I recommend the Windows Restricted Traffic Limited Functionality Baseline: https://learn.microsoft.com… by winterknife.
- Matched an almost ten year old rule that I remember very well - everyone interested in the China Nexus should take a look at this sample by Florian Roth.
- RT Smukx.E: how i ruined my vacation by reverse engineering wsc ! https://blog.es3n1n.eu/posts/how-i-ruined-my-vacation #reversing by Florian Roth.
- If a vuln is publicly exploited and ends up in CISA’s KEV catalog, patching is only half the job!! We also need to know how to determine whether a se… by Florian Roth.
- RT dbugs: LDAP Ping as a blind spot in AD discovery Researchers from (@HuntressLabs, @4ndr3w6S) showed that using “.LDAP Ping” (also called “.cLDAP”) … by Florian Roth.
- I’ve added performance/feature vectors to Shazzer. Along with stats. You can now see which browsers perform better. It uses the same shared fuzzing ne… by Gareth Heyes \u2028.
- RT zhero;: Pleased to publish a browser-related research paper (w/@inzo____) titled: One trigram at a time: XSLeak via Universal CSS Injection and DoS… by Gareth Heyes \u2028.
- RT Martin Sohn Christensen: #TROOPERS26 afterglow: @4ndr3w6S on building a solid LDAP detection stack - why signature-based detection is failing and v… by Will Schroeder.
- RT r1cksec: A sleepmask based on Ekko that preserves unwind data at sleep time. https://github.com/kapla0011/InsomniacUnwinding #infosec #cybersecurit… by hasherezade.
- RT Pass the SALT Conference: ALL VIDEOS & SLIDES(*) ARE ONLINE Our video team & Ubicast friends are terrific, period! Videos: http… by hasherezade.
- Extend log analysis with Logistician 1.3 https://eclecticlight.co/2026/07/06/extend-log-analysis-with-logistician-1-3/ via @howardnoakley by Howard Oakley, Eclectic Light Co.
- Hunting Sleeping Giants - Detecting Encrypted Beacon Sleep Obfuscation https://justruss.tech/index.php/2026/06/21/hunting-sleeping-giants-detecting-en… by Panos Gkatziroulis.
- Havoc C2 BOF port of the KslD.sys BYOVD technique. Credential extraction from lsass via physical memory, no OpenProcess, no auditable API calls https:… by Panos Gkatziroulis.
- Exploring cross-domain & cross-forest RBCD: part 2 https://www.synacktiv.com/en/publications/exploring-cross-domain-cross-forest-rbcd-part-2 by Panos Gkatziroulis.
- RT CodeX: Open sourcing another of my random BOFs that I think may be useful to people. Obtains location data, thats pretty much it. May be useful if … by Panos Gkatziroulis.
- Feature-rich single-binary file server for red teamers and developers. A powerful python3 -m http.server replacement HTTP/S WebDAV FTP/SFTP SM… by Panos Gkatziroulis.
- ironcurtain - A secure runtime for autonomous AI agents, where security policy is derived from a human-readable constitution https://github.com/provos… by Panos Gkatziroulis.
- Active Directory Post-Exploitation and Relay Automation Utilities https://github.com/JssNGC/harpyTools by Panos Gkatziroulis.
- Automatically deploying Mythic C2 in Azure using Terraform https://github.com/qmadev/tf-mythic-azure by Panos Gkatziroulis.
- RT DirectoryRanger: MSFDefender: Metasploit Windows Modules Detonation & Analysis #DFIR https://bloo.io/blog/msfdefender-metasploit-windows-modules-de… by Chihuahua in charge NotMe.
- RT JS0N Haddix: Re https://arcanum-sec.github.io/ai-sec-resources/ by Chihuahua in charge NotMe.
- Remove the threat of certain LOLBAS based on analysis at @magicswordio from Mandiant, Red Canary, CrowdStrike vendors reports! https://www.magicsword…. by Chihuahua in charge NotMe.
- RT Smukx.E: Breaking eBPF Security: How Kernel Rootkits Blind Observability Tools TLDR:- Deep technical analysis of eBPF-based security solutions thro… by kmkz.
- RT Florian Hansemann: ‘‘CVE-2025-38352 (Part 1) - In-the-wild Android Kernel Vulnerability Analysis + PoC’’ #infosec #pentest #redteam #blueteam https… by kmkz.
- Is it only me or 2026 seems to be “the year of the path traversal vulns” ? by kmkz.
- RT Open Source Security mailing list: CVE-2026-43503: Linux kernel: Analysis of the “DirtyClone” LPE (Dirty Frag family variant) https://www.openwall…. by kmkz.
- Fun story: #Apache patched a Tomcat padding oracle and shipped a worse bug doing it. #CVE-2026-29146: EncryptInterceptor defaults to AES/CBC/PKCS5, a … by kmkz.
- RT bynario: Now that Canonical has fully patched CVE-2026-31694, we’re sharing our code (along with a lil demo) for the FUSE LPE Source @ https:/… by kmkz.
- Playing Around With ADIDNS RPC Internals https:// blog.paradoxis.nl/playing-arou nd-with-adidns-rpc-internals-0c59c15d0a15.
- Windows Service - Playbook & Detection Strategies https:// ipurple.team/2026/07/06/window s-service/.
- This time @1ZRR4H looked at a possible interesting finding I gave him… turned out to be some botnet called N4D, but it is not some usual botnet it s… by MalwareHunterTeam.
- RT : https://techcommunity.microsoft.com/blog/windows-itpro-blog/reducing-ntlm-dependency-iakerb-and-localkdc-in-windows-insider-preview/4524615 … by Max.
- RT ret2src: Escalating from On-prem to Entra through MITM Attacks My colleague @0x64616e just published his latest research on lateral movement betwee… by Max.
- RT William R. Messmer: You might notice a few changes if you update WinDbg from the store. For “attach to process”, there is now a “Show processes fro… by Max.
- RT Unrealisedd: Microsoft patched UnDefend (CVE-2026-45498) back in May but all they did was block one locking method. The actual root cause, permissi… by Max.
Tools and Exploits
New open-source tool for unauthenticated enumeration of authentication methods on Microsoft accounts, revealing whether targets use passkeys, certificate auth, or passwordless push.
- Disposable Tooling: LLM-Generated Mythic C2 Agents From Prompt to Deployment by Chihuahua in charge NotMe.
SpecterOps built Oracle, a framework that generates, compiles, deploys, and QA-tests Mythic C2 agents autonomously across Python, Go, Zig, C#, and Rust. Every agent is unique and disposable.
Q2 release brings GNOME 50, KDE 6.6, new helper scripts, APT format changes, and VM boot tweaks.
Major release of the open-source reverse engineering platform adds config var preferences, searchable keybindings, debugging tooltips, and improved type management.
- cargo-audit Now Checks If Your Code Actually Calls Vulnerable Functions by Lee Chagolla-Christensen.
Trail of Bits added binary-level reachability analysis to cargo-audit 0.22.2+. It checks whether vulnerable functions are actually called, labeling matches as “Affected” to separate real exposure from noise.
A modular ASM and vulnerability scanning framework with 299 built-in modules covering OSINT, subdomain enumeration, DNS, port scanning, web fingerprinting, and active security testing.
Open-source implementation of the Cobalt Strike UDC2 spec, enabling open-source C2 frameworks to benefit from existing CS tooling. Ships with Adaptix PoC and drop-in UDC2 support.
More this week (6)
- How GitHub used secret scanning to reach inbox zero by Natalie Guevara.
- Brute Ratel 2.6 Catalyst is released and available for download. This version includes major changes to the Commander and Badger for various QOL and O… by Chetan Nayak (Brute Ratel C4 Author).
- Binary Hardening released cfgrip v1.0.0 - PE/ELF x86/x64 control flow graph extractor. Resolves indirect branches through GOT, jump tables, register t… by x86byte.
- RT Armadin: MLOKit could already steal an enterprise’s ML models and training data. Its new release runs code inside the infrastructure that builds th… by Sudheer Varma.
- Friday @magicswordio Feature Share First party support of CLM-Forge and our (soon to be released) Magic-Atomics. Import from CLM-Forge||Magic-Ato… by The Haag™.
- RT The Vertex Project: Synapse 3.0 Beta is now available! Built on 10+ years of analyst feedback, Synapse 3.0 introduces a redesigned data model,… by visi stark.
