A roundup of 160 items curated from across the security community.

News

FBI releases a PSA on TeamPCP, a data extortion group responsible for the longest running streak of software supply-chain hacks on record, including compromises of Trivy, CheckMarx, LiteLLM, and at least 3,800 GitHub repositories.

An Iranian hacker arrested in Montenegro for hacking over 100 US universities on behalf of the IRGC highlights Iran’s shift toward economic espionage and intellectual property theft.

A startup is suing Palo Alto Networks after an AI-generated threat report falsely linked them to Chinese espionage. A cautionary tale about AI in threat intelligence attribution.

DOJ announces the arrest of an alleged Scattered Spider member in Finland. Court documents reveal Microsoft’s GDID telemetry was used to track the suspect across VPNs and reimages.

Major Russian-language cybercrime forum XSS.is has been shut down and its alleged administrator arrested in a law enforcement operation.

First documented case of a ransomware group deploying an autonomous AI agent to execute the full attack chain, from initial access through encryption.

GMO Cybersecurity reports a privilege escalation vulnerability that went unnoticed in the Linux kernel for over 19 years. Now patched.

A new Linux kernel vulnerability affecting 6.4+ kernels and newer Android devices. PoC achieves 99% reliability for local-to-root escalation and may trigger from Chrome’s renderer sandbox.

Nextron Research confirms the Lazarus-linked npm supply chain campaign is ongoing, with new packages using fresh JSONKeeper URLs and C2 infrastructure dropping and executing payloads via Node.

More this week (10)

Techniques and Write-ups

FBI seizes hundreds of domains associated with NetNut, a residential proxy service operated by Israeli company Alarum Technologies, connected to the 2-million-device Popa botnet.

Routes memory allocation APIs through Firefox’s signed mozglue.dll so the allocating module appears as a trusted Firefox component. Includes detection guidance.

Synacktiv pointed a local LLM at FreeBSD and found a local root exploit plus an ASLR bypass on SUID binaries. Both now patched as CVE-2026-49415 and CVE-2026-49414.

Synacktiv demonstrates how a single Helm chart misconfiguration leads to full Kubernetes cluster compromise through unauthenticated RCE in Argo CD, found using CodeQL.

watchTowr dissects a batch of CVEs in Adobe ColdFusion from security bulletin APSB26-68, with detailed root cause analysis.

Two critical RCE vulnerabilities in the Cursor IDE allow zero-click exploitation through prompt injection, turning an AI code editor into a remote code execution vector.

SpecterOps demonstrates how simple LLM harnesses can extract EDR rulesets, YARA rules, and behavioral detections from local endpoint agents. The barrier to reverse-engineering defensive tooling just dropped to a single prompt.

watchTowr analyzes CVE-2026-8037, an uninitialized heap vulnerability in Progress Kemp LoadMaster that leads to pre-authentication remote code execution.

Raphael Mudge returned to the industry and is publishing evasion tradecraft openly. Crystal Palace provides position-independent code, binary transformation, register randomization, and a PICO convention for reusable tradecraft modules.

SpecterOps releases a Time Travel Debugging MCP server for Windows, enabling LLM-powered reverse engineering workflows through recorded execution traces.

watchTowr identified and disclosed a zero-day memory overread in Citrix NetScaler appliances. Patches now available. If you run NetScaler, patch immediately.

CyberCakeX’s Harden Windows Security app has matured into a full-featured hardening platform, now available on the Microsoft Store. Described as “$250k cyber consultant advice” for home users.

A new method to escalate privileges from a Microsoft Virtual Account using only certreq (a LoLBin) and AD-CS, successfully bypassing CrowdStrike without potato-class exploits.

Crowdfense chains two bypasses into a fresh RCE on fully patched Apache ActiveMQ 6.2.5 on Windows via WebDAV, found while researching CVE-2026-34197.

France’s ANSSI will halt certification of security products lacking quantum-resistant encryption, forcing government bodies and critical infrastructure operators to migrate.

More this week (113)

Tools and Exploits

New open-source tool for unauthenticated enumeration of authentication methods on Microsoft accounts, revealing whether targets use passkeys, certificate auth, or passwordless push.

SpecterOps built Oracle, a framework that generates, compiles, deploys, and QA-tests Mythic C2 agents autonomously across Python, Go, Zig, C#, and Rust. Every agent is unique and disposable.

Q2 release brings GNOME 50, KDE 6.6, new helper scripts, APT format changes, and VM boot tweaks.

Major release of the open-source reverse engineering platform adds config var preferences, searchable keybindings, debugging tooltips, and improved type management.

Trail of Bits added binary-level reachability analysis to cargo-audit 0.22.2+. It checks whether vulnerable functions are actually called, labeling matches as “Affected” to separate real exposure from noise.

A modular ASM and vulnerability scanning framework with 299 built-in modules covering OSINT, subdomain enumeration, DNS, port scanning, web fingerprinting, and active security testing.

Open-source implementation of the Cobalt Strike UDC2 spec, enabling open-source C2 frameworks to benefit from existing CS tooling. Ships with Adaptix PoC and drop-in UDC2 support.

More this week (6)