A roundup of 312 items curated from across the security community.
News
The EU formally attributes TURLA and related cyber operations to the FSB’s 16th Centre, alongside its broadest cyber sanctions package yet targeting Russian-linked actors.
The largest Patch Tuesday ever. 570 fixes including 3 zero-days (2 actively exploited) and 141 RCE flaws. Microsoft attributes the surge to AI-assisted vulnerability discovery.
DOJ charges operators of a Russian bulletproof hosting service used to support cybercriminal infrastructure and evade law enforcement takedowns.
Kim Zetter interviews Unit 221B’s Allison Nixon about unmasking Scattered Spider’s Peter Stokes. He was identified in 2023, years before his biggest crimes and eventual arrest in Finland.
Eleven Chrome extensions marketed as “AI Chat Exporters” silently upload full chat content to external servers on PDF export, despite store listings claiming no external uploads.
FT reports Iran exploited well-known SS7 vulnerabilities in cell networks to track U.S. military personnel and contractors during the conflict.
Oversecured drops the largest mobile vulnerability disclosure in history: 140 bugs across Samsung preinstalled apps.
- EU Sanctions LummaC2 Infostealer Developers by thaddeus e. grugq.
The EU adds LummaC2 infostealer developers to its sanctions list as part of expanded cyber enforcement actions.
- xAI Grok Build CLI Silently Uploaded Entire Git Repos by thaddeus e. grugq.
Wire-level analysis revealed xAI’s Grok Build CLI was uploading entire git repos, including secrets, to a GCS bucket. On a 12 GB test repo, 5.1 GB was exfiltrated while the task needed 192 KB. Still no advisory from xAI.
Two Scattered Spider members sentenced to five and a half years each for the Transport for London cyberattack, with one also convicted for compromising two US healthcare companies.
More this week (28)
- Vulnerability in FIFA’s Network by Bruce Schneier.
- RT Open Source Security mailing list: “we had a webhost running Debian kernel 6.12.90+deb13.1-amd64 being compromised using a root exploit” https://ww… by kmkz.
- RT Ctrl-Alt-Intel: 9 McNuggets & a McChicken burger helped us link a Russian hacker to 🇷🇺 government Denis Obrezko was put on the internatio… by thaddeus e. grugq.
- LastPass, Bitwarden users targeted with fake security alerts https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-targeted-with-fak… by BleepingComputer.
- Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware https://thehackernews.com/2026/07/compromised-asyncapi-npm-packages.html by Nicolas Krassas.
- Fluke - 821,100 breached accounts https://haveibeenpwned.com/Breach/Fluke by Nicolas Krassas.
- RT Decipher: This looks nasty and if @aaronportnoy is using full disclosure, it’s not an arbitrary decision. https://mindgard.ai/blog/cursor-0day-when… by Giuseppe
N3mes1s. - RT klez: [TALK] My latest Black Hat Europe talk is now publicly available. If you can look past the painfully obvious anxiety and a speaker who occasi… by SkelSec.
- Source-reviewing 200+ self-hosted multi-tenant AI/SaaS apps for tenant isolation: 78 leaked across tenants (the “un-retrofitted read sibling”) https:/… by /r/netsec.
- RT The Hacker News: Attackers can validate stolen #Microsoft Entra credentials without generating a successful sign-in event. Researchers tracked… by Florian Roth.
- Protecting Privacy in an AI Era by Bruce Schneier.
- RT VulnCheck: Today, VulnCheck disclosed CVE-2026-60105, a high-severity unauthenticated flaw in Monsta FTP that could expose cloud metadata and inter… by kmkz.
- RT Caitlin Condon: New vuln disclosure out from @Chocapikk_ today: CVE-2026-60105 is an unauthenticated SSRF in Monsta FTP that makes for a nice primi… by kmkz.
- RT OpenAI: Introducing GPT-Red An internal automated red teamer on a mission to find our models’ prompt injection vulnerabilities at scale, helping u… by Spiros Fraganastasis.
- dll hijacking of git.exe, nothing interesting, tbh. but I can confirm Cursor is not responding to security reports. I submitted my Pwn2Own bug to Curs… by vladimir metnew.
- RT Team Cymru Research: INTEL DROP Tracking multiple IP’s possibly performing targeted exploitation against Fortinet devices. 213.177.179.28 213…. by Vincent Yiu.
- RT Stephen Fewer: Earlier this year I built out an unauth RCE chain against SharePoint, we disclosed it to Microsoft in May and today they have patche… by Bobby Cooke.
- Ernst & Young discloses data breach after support system hack https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-data-breach-aft… by BleepingComputer.
- US charges two over laundering $43 million from investment fraud https://www.bleepingcomputer.com/news/security/us-charges-two-over-laundering-43-mill… by BleepingComputer.
- 23andMe to pay $18 million in new genetics data breach settlement https://www.bleepingcomputer.com/news/security/23andme-to-pay-18-million-in-new-gene… by BleepingComputer.
- Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man https://thehackernews.com/2026/07/armenia-detains-russian-tour… by Nicolas Krassas.
- RT forefy: (Redteam) This is how macOS devs get compromised by opening a .docx (file opening a resume, opening a p.o. sow whatever) In short: > docx c… by Florian Roth.
- RT dreadnode: Existing model benchmarks didn’t reflect what we saw in real offensive work. So we built our own. Introducing DreadIndex - an offensive… by Dave Aitel.
- RT Dark Web Informer: ‼ Scattered Spider members Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London have both been sentenced t… by Dominic Chell.
- bindutil-toolset | code and test scenarios for the “Silo-Binding” research presented at #InsomniHack 2026. https://github.com/bitdefender/bindutil-t… by Panos Gkatziroulis.
- RT VulnCheck: VulnCheck recently disclosed CVE-2026-53805 in NVIDIA’s GEN3C inference API. NVIDIA has patched the main branch, but older versions may … by kmkz.
- wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Ch… by /r/netsec.
- On Flock License Plate Tracking Cameras by Bruce Schneier.
Techniques and Write-ups
Unauthenticated SQL injection via REST API batch-route confusion that chains to full remote code execution on WordPress core. No preconditions required.
Pre-auth RCE in ServiceNow achieved by escaping the Rhino JavaScript sandbox. Now being exploited in the wild with variant gadget chains beyond the published PoC.
SpecterOps guide on relaying NTLM authentication through egress channels when operating from a low-privilege C2 foothold. Covers constraints and workarounds seldom documented elsewhere.
Failed D3DKMTCreateAllocation rollback re-reads an allocation handle from user memory and frees whatever it names. Unprivileged double-free in dxgkrnl with writeup and PoC.
At least 673,000 Shark robot vacuums in a single AWS region confirmed vulnerable to unauthenticated remote code execution. Detailed IoT security writeup.
ASUS bsitf.sys driver allows arbitrary physical memory mapping from user mode. Full 0-day writeup with working PoC for CVE-2026-13585.
Registering a malicious AMSI provider delivers persistence that survives reboots and runs in the context of any process loading amsi.dll. Includes detection guidance and a visualization of the attack flow.
Full Chrome exploit chain from V8 renderer to GPU process, developed with AI assistance. Demonstrates a novel GPU compromise technique on Linux where mitigations are harder to defeat.
win32k maps the desktop heap into every process. Offset 0x100 leaks a raw kernel session pool pointer, readable from Low IL, AppContainer, and zero-capability LPAC. A recurring class of bug that keeps reappearing across Windows builds.
Comprehensive walkthrough of every telemetry source EDRs rely on at the kernel level. Covers ETW providers, driver callbacks, object callbacks, and registry callbacks, then shows how a single bit flip can disable monitoring entirely.
More this week (238)
- CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC) https:// mrtiz.github.io/cet-callstack- spoofing-thread-pool-trampoline.
- RT Adel Ka: open sourcing Stinger - an endpoint deception experiment for macOS/Linux. uses FIFO baits and other local traps to catch secret coll… by Giuseppe
N3mes1s. - Pixel Codec3P VPU driver: lifetime issues with fw_debug_buf https://project-zero.issues.chromium.org/issues/492567103 by Project Zero Bugs.
- RT sapir federovsky: As every week, i read the blog posts in the weekly http://entra.news issue, found this one: https://zerobec.com/blog/debull-storm… by Sean Metcalf.
- Malicious browser extensions can be a tricky attack vector and may go unnoticed, been playing with Elastic workflow + Elastic Defend response console,… by Samir.
- RT Czech Permanent Representation to the EU: 🇪🇺 dnes vydala prohlášení odsuzující škodlivé kybernetické aktivity Ruska, konkrétně oper… by SwitHak ().
- RT ANSSI: [1/5] Depuis les années 2010, les membres du C4 - Centre de Coordination des Crises Cyber (ANSSI, @ComcyberFR, @DGA, DGSE, DGSI, @fran… by SwitHak ().
- RT CERT-FR: Les membres du Centre de Coordination des Crises Cyber ont observé le ciblage et la compromission d’entités françaises au moyen du MOA… by SwitHak ().
- RT Pavel Yosifovich: New video: App Execution Aliases. Type notepad, get the Store one, not the System32 one. Why? App Execution Aliases. https://trai… by Rasta Mouse.
- RT JFrog Security: IronWorm returns! Shai-Hulud’s rustier cousin has struck again, and it’s more sophisticated than ever. An evolved varian… by Florian Roth.
- RT NCSC UK: Today, the NCSC, alongside international allies, has published a new advisory on defending against the threat from Russian state intellige… by Dominic Chell.
- The serpent’s tongue: Luring the Python out of its den by Onur Mustafa Erdogan.
- For the past 2–3 years, almost every new lateral‑movement technique I’ve seen leans on COM Hijacking. Is this just my observation, or a… by Panos Gkatziroulis.
- RT Smukx.E: DoublePulsar: A User Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era in rust by MemN0ps Blog:- https://memn0ps.g… by Panos Gkatziroulis.
- After our story the other day about two far-right conspiracy theorists and convicted felons who were running an offensive cybersecurity company called IRIS C2, many readers asked how exactly these clo.
- https:// bobdahacker.com/blog/fifa-hack.
- RT Feross: Active supply chain attack on AsyncAPI. Five malicious @asyncapi packages were published to npm today, shipped through the project’s… by kmkz.
- RT 0xor0ne: Practical on pipe_buffer based Linux kernel exploit primitives (@a13xp0p0v) https://a13xp0p0v.github.io/2026/04/20/pipe-buffer-experiments… by kmkz.
- RT Nicolas Krassas: CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC) https://mrtiz.github.io/cet-callstack-spo… by kmkz.
- RT 8kSec: This deep dive breaks down CVE-2023-26083, where the Mali GPU driver serialized raw kernel pointers into a timeline stream ring buffer that … by kmkz.
- RT SEKTOR7 Institute: Bypassing PatchGuard on Win 11 with Hells Hollow. Hells Hollow hooks the System Service Dispatch Table (SSDT) by abusing an undo… by kmkz.
- RT Nicolas Krassas: Cisco Unified CM Pre-Auth RCE - When the Phone System Becomes the Attacker’s Foothold https://blog.securelayer7.net/cve-2026-202… by kmkz.
- RT Shift: I gave claude the bad epoll vuln to port onto a modern Pixel 10, it got there, w/ my help https://guysrd.github.io/epoll-uaf-agent by Kuba Gretzky.
- Caeruleus is a Bluetooth Low Energy testing toolkit for Linux/BlueZ, implemented as a single Go binary. It covers the full interaction-to-assessment l… by Swissky.
- Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) - Patrik Grobshäuser, Kevin Gervot, Tomais Williamson - @SLCyberSec https… by Swissky.
- The Hardest Security Challenges Live in the Seams Why is securing AI so difficult right now? Because you can’t properly secure what hasn’t settled. Tr… by Phil Venables.
- RT Andy Greenberg (@agreenberg at the other places): Researchers @samwcyo and @xehle_ say SFPD created a link for sharing the videos on drone platform… by Sam Curry.
- RT Ctrl-Alt-Intel: Re Full analysis & writeup here: https://ctrlaltintel.com/research/VoidBlizzard/ by thaddeus e. grugq.
- RT Mike: Dutch intelligence agencies published an official warning: Russian state hackers are hacking the security cameras of private companies in the… by thaddeus e. grugq.
- My first set of Microsoft vulnerabilities have been published in this month’s patch Tuesday https://msrc.microsoft.com/update-guide/vulnerabilit… by Bad_Jubies.
- Nearly 300 GitHub repos pose as legit software to push malware https://www.bleepingcomputer.com/news/security/nearly-300-github-repos-pose-as-legit-so… by BleepingComputer.
- Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown https://www.bleepingcomputer.com/news/security/progress-confirms-sharefile-zero… by BleepingComputer.
- New phishing kits target Microsoft 365 accounts, evade MFA https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-microsoft-365-accou… by BleepingComputer.
- US sanctions VPN, malware providers for enabling ransomware attacks https://www.bleepingcomputer.com/news/security/us-sanctions-vpn-malware-providers-… by BleepingComputer.
- Japan’s largest taxi operator shuts systems after cyberattack https://www.bleepingcomputer.com/news/security/japans-largest-taxi-operator-shuts-system… by BleepingComputer.
- A Video Screen That Is Also a Camera https://www.schneier.com/blog/archives/2026/07/a-video-screen-that-is-also-a-camera.html by Nicolas Krassas.
- ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-sieme… by Nicolas Krassas.
- CISA warns admins to patch actively exploited SharePoint flaws https://www.bleepingcomputer.com/news/security/cisa-warns-admins-to-patch-actively-expl… by Nicolas Krassas.
- This fake Apple app can unlock your Mac’s password vault https://www.malwarebytes.com/blog/threat-intel/2026/07/this-fake-apple-app-can-unlock-your-m… by Nicolas Krassas.
- ADPathFinder: OpenGraph Attack Path Mapping in BloodHound CE https://www.netspi.com/blog/technical-blog/network-pentesting/adpathfinder-opengraph-atta… by Nicolas Krassas.
- SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data https://thehackernews.com/2026/07/sap-patches-cvss-99-netweaver-abap-flaw.ht… by Nicolas Krassas.
- Spanish Police take down €140 million cyber fraud ring, arrest four https://www.bleepingcomputer.com/news/security/spanish-police-take-down-140-milli… by Nicolas Krassas.
- SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-sma1000-fl… by Nicolas Krassas.
- Cursor vulnerability allows execution of malicious binaries https://www.scworld.com/brief/cursor-vulnerability-allows-execution-of-malicious-binaries by Nicolas Krassas.
- RT Chumy: This is the auth by pass which I chain with Flow2Shell CVE-2026-47298 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-47298 C… by Nicolas Krassas.
- RT TrustedSec: Azure container services are everywhere. Their attack surface? Often overlooked. Part 1 of this #blog series, @OffsecPierogi walks thro… by Dave Kennedy.
- RT Fabian Bader: If your company is using #EntraID and any of your users does MFA with either phone or SMS this announcement is crucial https://www.mi… by Sean Metcalf.
- RT CERT-UA: UAC-0145 (subcluster of UAC-0002, aka #Sandworm/#APT44): fake “antivirus” spread via Signal, #ClickFix, Android backdoor. Details (UA only… by SwitHak ().
- The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets https://www.ayush.digital/blog/the-memory-heist by /r/netsec.
- (More) Unauthenticated Arbitrary Code Execution in ServiceNow https://palk.sh/unauthenticated-arbitrary-code-execution-in-servicenow/ by /r/netsec.
- How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist https://www.hudsonrock.com/blog/how-an-infostealer-infection-led-to-a… by /r/netsec.
- When LLMs do more than they have to https://nytrosecurity.com/2026/07/14/when-llms-do-more-than-they-have-to/ by /r/netsec.
- Writing an Evasive .NET Shellcode Loader https://slashsec.at/en/blog/writing-an-evasive-dotnet-shellcode-loader by /r/netsec.
- AXON Body camera 3 of 4 hardware reverse cracking output video! https://b23.tv/gtjjcQo by /r/netsec.
- Context Bombs: Using AI Guardrails as a defensive mechanism https://agentic.tracebit.com/context-bombs/ by /r/netsec.
- Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) https://blog.amberwolf.com/blog/2026/july/dell-bios-passwords… by /r/netsec.
- LIEF 1.0.0 is out featuring a brand-new Runtime API https://lief.re/blog/2026-07-13-lief-1-0-0/ by /r/netsec.
- Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver https://zwclose.github.io/2026/07/08/… by /r/netsec.
- CVE-2026-47291: Windows Critical Unauthenticated Remote Code Execution in HTTP.sys https://byteray-ai.github.io/drift-corpus/item/http_a10f1434-http-r… by /r/netsec.
- RT Andrea Allievi: https://windows-internals.com/goodbye-secure-pool-hello-kdp-pool/ Someone documented the work that Ben, me and my team did about KD… by winterknife.
- RT James Aung: Our Cyber and Autonomous Systems Team at @AISecurityInst performed early access testing of GPT-5.6 Sol for offensive cyber capabilities… by Alex Plaskett.
- RT Hunt.io: 🇨🇳 𝗦𝘂𝘀𝗽𝗲𝗰𝘁𝗲𝗱 𝗖𝗵𝗶𝗻𝗲𝘀𝗲 𝗼𝗽𝗲𝗿𝗮𝘁𝗼𝗿𝘀 𝘄𝗶𝗿𝗲𝗱 … by Florian Roth.
- RT Nextron Research : We spotted three new malicious npm packages impersonating legitimate blockchain libraries: - solana-key-utils@1.0.2 - crypto… by Florian Roth.
- RT USENIX WOOT Conference on Offensive Technologies: By reverse engineering AirDrop and building the AIRFUZZ fuzzer, @microsvuln @notippenhauer uncove… by Dave Aitel.
- RT 0xroot: Hidden vulns in 5G basebands: Using AI and pre-auth messages to hack 64 modems 【PDF】 https://www.usenix.org/system/files/conference/useni… by Dave Aitel.
- RT itszn: A team effort between me and gpt-5.6-sol, we finally checked off v8ctf from my bucket list with a 0day ARW and a 0day heap sandbox escape :) by Dave Aitel.
- RT hackyboiz: [Wipeload Project - Step 4] Chrome Full-Chain Exploitation After achieving Renderer RCE, what comes next? In this article, we dive… by Arun.
- UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign by Alex Karkins.
- RT Stephen Fewer: PoC for the recent SonicWall SMA1000 0day, CVE-2026-15409, courtesy of @the_emmons https://github.com/remmons-r7/rapid7-CVE-202… by Dominic Chell.
- RT Nicolas Krassas: No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE https://tokay0.com/posts/millions-of-shark-vacuums-vulnerable-to… by Simone Margaritelli.
- Another example of attackers using LLMs to develop malware! “TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development” https://unit42.p… by Thomas Roccia.
- CVE, Congress, and the NDAA: A Merge Story In today’s blog, runZero’s Tod Beardsley explores an amendment that could make significant changes to the CVE program and explains why the security community.
- RT HawkTrace: Windows Admin Center Remote Code Execution CVE-2026-56196 CVE-2026-58631 https://msrc.microsoft.com/update-guide/vulnerability/C… by batuu.
- A collection of techniques for process injection on Windows https://github.com/toneillcodes/windows-process-injection by Panos Gkatziroulis.
- Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data https://github.com/NetSPI/AD-PathFinder by Panos Gkatziroulis.
- Modular PIC Implant Design https://kirchware.com/Modular-PIC-Implant-Design by Panos Gkatziroulis.
- Detections for LegacyHive exploitation by @GossiTheDog https://github.com/GossiTheDog/ThreatHunting/blob/master/AdvancedHuntingQueries/LegacyHive.kql by Panos Gkatziroulis.
- RT C2 Matrix | #C2Matrix: We added KHAOS to the #C2Matrix today KHAØS is a modern post-exploitation C2 framework with 5 covert channels and full evas… by Panos Gkatziroulis.
- UnwindRaven - a Windows x64 offensive research framework that constructs fully synthetic call stacks at thread startup time https://github.com/toneill… by Panos Gkatziroulis.
- RT 0x12 Dark Development: Registry Snapshots for Post Exploitation Enumeration Welcome to this Medium post! I’ll introduce rsnap, a tool that snapshot… by Panos Gkatziroulis.
- One of the articles that I wrote last month was a detection approach and emulation playbook of abusing QoS Policies to throttle EDR traffic. Not … by Panos Gkatziroulis.
- BingusLdr - CET Compatible Stack Spoofing https://bigbingus.com/posts/bingusldr-cet-stack-spoofing/ by Panos Gkatziroulis.
- RT cr3ghost: If you are building offensive tooling, writing detection rules for C2 implants, or analysing modern malware evasion, this blog covers the… by Chihuahua in charge NotMe.
- RT RussianPanda 🇺🇦: Ever wonder why you keep finding rogue RMMs in your environment? Because it ain’t “shadow IT”. It’s a RAT with a suppor… by Chihuahua in charge NotMe.
- Reported today an undocumented persistence primitive in #Keycloak: Offline tokens are a legitimate OIDC feature. With the right config combo t… by kmkz.
- Critical Unauthenticated Remote Code Execution (RCE) in #Salesforce Workbench via Pre-Auth XSS and Dynamic Code Injection (cvss 9.8) https://github.co… by kmkz.
- RT Shota Zaizen (財前 匠汰): [$4,500] Remote Code Execution Vulnerability in Meta’s Manus AI #bugbounty https://zaizen.me/blog/manus-ai-deep-link-rce…. by kmkz.
- Nice Android confused-deputy bug in Signal’s website APK The update receiver was exported and would relaunch a caller-controlled nested Intent. … by kmkz.
- Why “Least Privilege” Fails in Real Environments by SpecterOps Team.
- RT Nicolas Krassas: Zetsu, A personal RAG system for offensive security knowledge https://github.com/Chaelsoo/Zetsu by Spiros Fraganastasis.
- Is reverse proxy phishing slowly dying? This is what I’ve been trying to find out during the past several months. Major websites have caught … by Kuba Gretzky.
- RT Objective-See Foundation: Also, have posted a sample of PamStealer to our free/public Mac Malware repo! PamStealer: https://github.com/obj… by Patrick Wardle.
- RT Objective-See Foundation: Just added a sample of CrashStealer our free public Mac malware repo! CrashStealer: https://github.com/objective… by Patrick Wardle.
- RT Stuart Ashenbrenner 🇺🇸 🇨🇦: One of the most time consuming parts of macOS research is identifying what you’re looking at - AMOS, NovaSte… by Patrick Wardle.
- Device Code Phishing Is Dead, Long Live New Azure AD Attacks! - Elias Issa (@shadow_gatt) https://youtu.be/JFQj79j6O4Q by Swissky.
- AI-FI: Giving Claude Code Glitch Skills for Bypassing Secure Boot - @raelizecom https://raelize.com/blog/ai-fi-giving-claude-code-glitch-skills-for-by… by Swissky.
- StubZero: $148,337 RCE in Google Cloud Production - @brutecat https://brutecat.com/articles/google-cloud-rce/ by Swissky.
- RT : New option in impacket for ADCS ESC relay attacks: –altsid This option is needed with StrongCertificateBindingEnforcement, enforced on DC’s … by Swissky.
- RT Nicolas Krassas: Windows Privilege Escalation: SeTcbPrivilege https://www.hackingarticles.in/windows-privilege-escalation-setcbprivilege/ by Rémi GASCOU (Podalirius).
- RT Rick de Jager: Here’s the Age of Empires RCE from yesterday’s Patch Tuesday: CVE-2026-50663. Join an attacker’s lobby, (auto-)accept UCG, and yo… by Rémi GASCOU (Podalirius).
- RT Md Ismail Šojal : Crazy, Capacitive Touchscreens Just Got Hacked From 5cm Away. Your Phone’s Screen Is Whispering Your Secrets, New Re… by Rémi GASCOU (Podalirius).
- RT Paul Moore - Security Consultant : Bypassing the latest #EU #ageVerification app (2026.07-1) with a Chrome extension… again. Despite 3 months o… by Rémi GASCOU (Podalirius).
- RT Andy: Just had my 0-day go public on today’s Patch Tuesday Found a 1 click RCE in Windows PowerShell got CVE-2026-40400 assigned along with the fix by scriptjunkie (Matt).
- RT Scoubi: This is amazing work! by stuk0v.
- RT Wojciech Reguła: Looks like macOS Golden Gate also introduced another new TCC change. Some apps that ARE not sandboxed (they don’t have their own … by Csaba Fitzl.
- RT John Hultquist: What China is taking away from cyber ops in Ukraine and Venezuela. by thaddeus e. grugq.
- RT @MalwareBibleJP: ゲームチート界隈では以前から使われてきたがセキュリティ研究側ではあまり活用されてこなかったEPTフッキング(CPUのメモリ仮想化機能を使… by thaddeus e. grugq.
- RT YogSotho: TP-Link Archer BE900 v2 Firmware 1.1.6 Multiple critical vulnerabilities enable unauthenticated remote code execution, au… by Vincent Yiu.
- Details of Alan Turing’s Voice Encryption System by Bruce Schneier.
- RT solst/ICE of Astarte: If I wanted to scan C++ with semgrep I always used @0xdea‘s rules, and they just got an upgrade! https://github.com/0xdea/se… by raptor.
- RT Armadin: Found a CLAUDE.md file sitting publicly readable on a customer’s auction site. It’s the file devs leave behind for their AI coding assista… by Andrew Oliveau.
- NEW Blog | BHIS Why grab one artifact when you can catch ’em all? KAPE 101: A Kroll Artifact Parser and Extractor Cheatsheet by: Gerard Johansen |… by Black Hills Information Security.
- New Windows LegacyHive zero-day gives hackers admin privileges https://www.bleepingcomputer.com/news/security/new-windows-legacyhive-zero-day-exploit-… by BleepingComputer.
- New ClickLock macOS malware traps users into revealing login password https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-traps… by BleepingComputer.
- Claude Chrome extension flaw lets malicious extensions trigger AI actions https://www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-… by BleepingComputer.
- New OkoBot framework deploys 20 payloads to steal data, crypto https://www.bleepingcomputer.com/news/security/new-okobot-framework-deploys-20-payloads… by BleepingComputer.
- CISA orders feds to patch actively exploited Oracle flaw by Saturday https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively… by BleepingComputer.
- New Spirals ransomware encrypts victim network in under 24 hours https://www.bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim… by BleepingComputer.
- Italy fines Wind Tre $2 million for data breaches affecting 365k customers https://cyberinsider.com/italy-fines-wind-tre-2-million-for-data-breaches-a… by Nicolas Krassas.
- Inside the Search for “Clean” Residential Proxies for Carding https://www.bleepingcomputer.com/news/security/inside-the-search-for-clean-residential-p… by Nicolas Krassas.
- Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-syst… by Nicolas Krassas.
- New North Korean campaign uses fake coding interviews to steal developer credentials https://www.elastic.co/security-labs/contagious-interview-malware… by Nicolas Krassas.
- “Remcos RAT – Svchost Injection, API Hooking & Obfuscated Payload Analysis” https://github.com/kaandemir993/-Remcos-RAT-Fileless-svchost-Injection-Ob… by Nicolas Krassas.
- New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage https://thehackernews.com/2026/07/new-goserpent-malware-targets-… by Nicolas Krassas.
- Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei https://www.securityweek.com/cyberattack-disrupts-operations-of-japanese-frozen… by Nicolas Krassas.
- Google fixing Android lock screen bug that lets Gemini send SMS without a PIN https://www.theregister.com/security/2026/07/17/google-fixing-android-lo… by Nicolas Krassas.
- Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ by Nicolas Krassas.
- CISA urges immediate action on actively exploited Fortinet flaws https://www.bleepingcomputer.com/news/security/cisa-warns-feds-to-patch-exploited-for… by Nicolas Krassas.
- RT tuckner: Look closely at the detections Samir uses here. What is really interesting about extensions is that some of the best context like develope… by Samir.
- RT SolidSnake: Check out our latest research on an #AI slop of a #banking toolkit targeting mexican banking customers. We found the promts in their co… by Samir.
- RT Soroush Dalili: YSoNet now supports interactive mode + autocomplete in PowerShell. String obfuscation has also been added to GitHub builds to reduc… by SinSinology.
- RT watchTowr: Overnight our global honeypot network picked up broad scale exploitation of CVE-2026-15409 targeting SonicWall SMA1000 SSL-VPN appliance… by SinSinology.
- RT SSSCIP Ukraine: CERT-UA has detected new tactics employed by the Russian hacking group #Sandworm. The actors disguise malware as legitimate antivir… by SwitHak ().
- #TSW #PEGASUS #PegasusProject by SwitHak ().
- RT Casey: The interns added yml files for synthetic data. And now we can gzip/base64 decode files on access. This opens up a number of neat and intere… by Scott Sutherland.
- New blog post about another macOS 27 privacy enhancement. Thx @ciphwall for a hint: https://wojciechregula.blog/post/golden-gate-appdata-protecti… by Wojciech Reguła.
- Keeping private namespaces private - Quad9 blog https://quad9.net/news/blog/keeping-private-namespace-queries-private/ by /r/netsec.
- Openwrt pre-auth remote root exploit https://xcancel.com/hackerfantastic/status/2074871544984064163 by /r/netsec.
- New Exploitable BOLA Found in Immich (self-hosted media platform) https://escape.tech/blog/how-escape-dast-bypassed-immichs-locked-folder/ by /r/netsec.
- [$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking https://weirdmachine64.github.io/research/google-oauth-… by /r/netsec.
- Interesting analysis from @AISecurityInst on the gap between open and closed models for cyber capabilities by Alex Plaskett.
- RT Bjoern Kerler: I just added full @HexRaysSA IDA 9.4 support for ida-rpc, including Windows/Linux support (Mac untested): https://github.com/bkerler… by Alex Plaskett.
- RT stratan: What The Claude, episode 3. We’re taking a break from content-process RCEs for Bug 2022034. A raw NaN. Typed JS actor IPC. A parent-proces… by Alex Plaskett.
- RT Nextron Research : “asphomer” published 10 backdoored npm packages targeting n8n users: - exfiltrates hostnames, IPs, environment variable… by Florian Roth.
- RT Nextron Research : We identified further activity linked to Iranian APT Nimbus Manticore (UNC1549), including two fake LinkedIn recruiter accou… by Florian Roth.
- RT Nextron Research : Our artifact scanner flagged 8 malicious RubyGems from a single publisher (monib110), all Monero miners paying into one… by Florian Roth.
- RT Kostas: This is one of the funniest intrusions I’ve seen this week… It started with SheetRAT, dropped XWorm, created fake RuntimeBroker binaries,… by Florian Roth.
- RT Hunt.io: UAT-11795 Trojanizes Fake Installers to Deliver Starland RAT https://www.bleepingcomputer.com/news/security/russian-hackers-trojanize… by Florian Roth.
- RT Nicolas Krassas: An intentionally vulnerable OWASP LLM Top 10 training platform for AI Security, Prompt Injection, RAG Security, Agent Security, an… by Florian Roth.
- RT 𝕡𝕨𝕟𝕚𝕖: APT41 built malware called Calendarwalk that uses Google Calendar events as its command and control channel. The malware read… by Florian Roth.
- RT bbsz: This is not DPRK. Let me present the case. Happy to be proven wrong because it relates to a massive cluster we are tracking and it would infl… by Florian Roth.
- RT 0xroot: LLFuzz: An Over-the-Air Dynamic Testing Framework for Cellular Baseband Lower Layers 【PDF】 https://www.usenix.org/system/files/usenixsecu… by Dave Aitel.
- RT SEKTOR7 Institute: Exploiting symlink weaknesses in Windows for local privilege escalation. A post by Michael Zhmaylo. Source: https://cicada-8.med… by Dave Aitel.
- RT SpecterOps: Nemesis 2.2 brings new capabilities for offensive security teams, from full disk image ingestion and automated DPAPI decryption to AI-a… by Dominic Chell.
- RT International Cyber Digest: ‼ BREAKING: A hacker breached AI music company Suno using the Shai-Hulud worm and released source code showing how i… by Simone Margaritelli.
- @SecurityBreakAI Research has just published a threat report, authored by @pedrinazziM that explores how attackers are currently abusing HTTP hea… by Thomas Roccia.
- RT Josh Parnham: Published a writeup on CVE-2025-24169, a macOS vulnerability which allowed a malicious app to enumerate a user’s saved account data i… by Gergely Kalman.
- RT Wojciech Reguła: New blog post about another macOS 27 privacy enhancement. Thx @ciphwall for a hint: https://wojciechregula.blog/post/golden-… by Gergely Kalman.
- RT Kyle Cucci: We’re tracking a malware crypter (blog coming soon!) that uses some uncommon stealth tricks. One I haven’t seen before: it repeatedly c… by hasherezade.
- RT ESET Research: #ESETresearch discovered and reported to @certcc 11 old Microsoft-signed UEFI shim bootloaders that allow bypassing UEFI Secure Boot… by hasherezade.
- Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing https:// blog.threatuniverse.co.uk/post s/asyncrat-bitmap-steganography-dropper/.
- RT Tyler: New blog post about the trends section of detection chokepoints featuring @DefusedCyber Intel feed as a data set. https://playingwithpackets… by Panos Gkatziroulis.
- Bitdefender just published a great deep‑dive into Bind Links (File‑Binding, Process‑Binding, and Silo‑Binding) for blinding EDR sensors + mor… by Panos Gkatziroulis.
- The cool thing about publishing work is that others can comment, and based on their feed-back you can improve things. One of the Sysmon rules that… by Panos Gkatziroulis.
- RT Nathan McNulty: This was super fun, and I thought I’d share a quick demo I had recorded in the event of technical issues :) I repurposed my Key Vau… by Chihuahua in charge NotMe.
- RT Casey: Had some fun testing PhaontomFS against Praetorian titus. Which is a cool cred scanner. https://github.com/praetorian-inc/titus So far we’ve… by Chihuahua in charge NotMe.
- RT Nick VanGilder: Red team and offensive security tradecraft is scattered across maybe a few hundred operator blogs. Some are active. Some are stale…. by Chihuahua in charge NotMe.
- RT Simo: Sharepoint activity by kmkz.
- RT Nicolas Krassas: Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 https://davidcarliez.github.io/blog/windows-app… by kmkz.
- RT April: How I found an integer overflow in tcpip.sys (CVE-2026-58532) https://aprl.pet/writing/cve-2026-58532 by kmkz.
- RT Ariel: #0day Heap out-of-bounds write in Google’s Skia library. Google wont fix since its considered unreachable through Chrome’s font pipeline. T… by kmkz.
- RT Marcin Noga: CVE-2026-58613 - Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteRequest use-after-free vulnerability Details : htt… by kmkz.
- RT Toan Pham: 22 Windows LPE reported by one of my colleagues at @Seasecresponse . This data should not be in any public dataset so if you plan to do … by Max.
- RT cr3ghost: One anonymous researcher dropped 9 working Windows zero-days in 3 months. Each one timed for the day after Patch Tuesday to maximize the … by Max.
- RT BallisKit: Did you know macOS Office macro are still a thing? Use the latest DarwinOps to generate a Word/Excel payload to load Sliver and Poseidon… by Ring3API 🇺🇦.
- How I Found Open-Source 0-days with an LLM Multi-Agent Workflow - Hyunseo Shin https://blog.cykor.kr/2026/02/How-I-Found-Open-Source-0-days-with-an-LL… by Swissky.
- RT solst/ICE of Astarte: I “ported” @hashcat to the GBA, the ultimate password cracking rig ever (my dumbest project yet). The monstrously powerful 16… by Swissky.
- RT nad: CVE-2026-50343 - InstallService Windows local privilege Escelation - Writeup and POC Found another cool one! https://github.com/Rat5ak/CVE-202… by Rémi GASCOU (Podalirius).
- Vulnerability management in #OT is a different ballgame. In OT, patching is often impossible, and a simple DoS can have catastrophic real-world impact… by runZero, Inc..
- RT Rob T. Lee: Sandra Joyce, VP Google Threat Intelligence, spent the past year arguing that disrupting adversary infrastructure has to become normal … by thaddeus e. grugq.
- RT Spy Collection: NSA’s hackers, the TAO, was dissolved in the NSA21 reorg. Putting its staff under CNO. Last week, DoD reestablished the office with… by thaddeus e. grugq.
- RT 𝕡𝕨𝕟𝕚𝕖: Unit42 started analyzing a sample that looked like a new Equation Group implant. Same exported function name as known Equatio… by thaddeus e. grugq.
- RT Kostas: This is a really interesting report from Hugging Face about their recent intrusion. I also love the transparency here. The biggest takeaway… by thaddeus e. grugq.
- Chat, big shenanigans are afoot. Zyaire Dontaevious Zamarion Wilkins, one of the individuals behind the “BlockBlasters” steam malware campaign, also s… by vx-underground.
- RT AI Security Institute: Our first public analysis of the open/closed weight gap in frontier cyber capabilities finds it is 4–7 months with GLM-5.2 … by Bill Demirkapi.
- Abbott Laboratories probes two cyber incidents amid extortion claims https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-two-cyb… by BleepingComputer.
- HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload https://www.bleepingcomputer.com/news/security/hollowbyte-ddos-flaw-bloats-open… by BleepingComputer.
- UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware https://thehackernews.com/2026/07/uac-0145-uses-clickfix-captchas-to.html by Nicolas Krassas.
- Hackers abuse ViPNet software to target Russian govt agencies https://www.bleepingcomputer.com/news/security/hackers-abuse-vipnet-software-to-target-r… by Nicolas Krassas.
- Pro-Russia Information Operations Leverage Russian Drone Incursions into Polish Airspace https://cloud.google.com/blog/topics/threat-intelligence/pro-… by Nicolas Krassas.
- CVE-2026-42980, a Windows kernel WMI integer-underflow vulnerability that can be exploited for local privilege escalation to NT AUTHORITY\SYSTEM on vu… by Nicolas Krassas.
- haxxm0nkey/credshound: Nuclei-like credential surface scanner with BloodHound support. Audits local hosts for exposed secrets, cloud tokens, DevOps, a… by Nicolas Krassas.
- illiahaidar/mcptrustchecker: MCP security scanner - offline, deterministic A–F Trust Score for Model Context Protocol servers. Detects tool poisonin… by Nicolas Krassas.
- Update now: 7-Zip fixes RCE flaw exploitable with malicious archives https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-flaw-ex… by Nicolas Krassas.
- Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing https://blog.threatuniverse.co.uk/posts/as… by Nicolas Krassas.
- HTB: Logging https://0xdf.gitlab.io/2026/07/18/htb-logging.html by Nicolas Krassas.
- Microsoft warns of surge in ACR Stealer attacks on customers https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-acr-stealer-at… by Nicolas Krassas.
- The British teenager who hacked into Vegas casinos from an east London flat http://inews.co.uk/news/british-teenager-hacked-vegas-casinos-east-london-… by Nicolas Krassas.
- AddUser-SAMR. Create local administrators using the SAMR API, operating at a lower level than net.exe, PowerShell’s New-LocalUser or NetUserAdd API ht… by DirectoryRanger.
- TokenSmith. generates Entra ID access & refresh tokens on offensive engagements, by @JumpsecLabs https://github.com/JumpsecLabs/TokenSmith by DirectoryRanger.
- swarmer. tool for sneakily adding registry keys to HKCU without EDR/AV being able to see what’s happening even if you don’t have administrator access … by DirectoryRanger.
- WELA (Windows Event Log Analyzer). tool for auditing Windows event log settings #DFIR https://github.com/Yamato-Security/WELA by DirectoryRanger.
- No single pane of glass: Anatomy of an Azure permission takeover https://webflow.sysdig.com/blog/no-single-pane-of-glass-anatomy-of-an-azure-permissio… by DirectoryRanger.
- The Mimikatz Missing Manual, by @Carlos_Perez https://github.com/darkoperator/mimikatz-missing-manual by DirectoryRanger.
- ADWSDomainDump. Active Directory information dumper via ADWS (Active Directory Web Services) https://github.com/mverschu/adwsdomaindump by DirectoryRanger.
- Kratos PhaaS Targets US and EU: How to Reduce Microsoft 365 Account Takeover Risk https://any.run/cybersecurity-blog/kratos-phaas-account-takeover/ by DirectoryRanger.
- Bind Link Abuse: One Windows Feature, Many Ways to Blind Your EDR https://www.bitdefender.com/en-us/blog/businessinsights/bind-link-abuses-windows-fea… by DirectoryRanger.
- RT nSinus-R (@nsr@infosec.exchange): Great summary of the work we recently shared at @WEareTROOPERS. For everyone interested in this, stay tuned for o… by DirectoryRanger.
- RT Enno Rey: Deep-dive analysis of Windows Hello for Business, performed by @BSI_Bund & @ERNW_ITSec https://www.bsi.bund.de/SharedDocs/Downloads/EN/BS… by DirectoryRanger.
- RT DirectoryRanger: Microsoft-Analyzer-Suite. collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID https://gi… by DirectoryRanger.
- Nooooo, my favorite milk / protein shake by Dave Kennedy.
- RT Justin Bollinger: The updated randomly generated NTLMv1 time trials are in for my fork of #rainbowcrackalack that ports to CUDA/Metal. Using https:… by Steven Lowson.
- RT Forbidden Stories: #PegasusProject | [NEW VIDEO ONLINE] For certain targets, Moroccan intelligence does not rely on a single tool. It may… by SwitHak ().
- RT Volexity: Re @Volexity has published details on a recent incident response investigation involving the exploitation of multiple #0day vulnerabiliti… by SwitHak ().
- Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable https://neurowinter.com/security/2026/07/16/forging-t… by /r/netsec.
- Source Code Analysis: A Pentester’s Guide https://www.vulnsy.com/blog/source-code-analysis by /r/netsec.
- Five months of industrial-protocol traffic to our honeypots https:// honeylabs.net/blog/knocking-on -the-control-room.
- Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https:// blog.paradoxis.nl/escalating-a ll-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492.
- Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https:// slcyber.io/research-center/exp loit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/.
- COM: The retro tech gift that keeps on giving by bohops.
- Crawling the Complete IPv4 Reverse DNS Space https:// ipapi.is/blog/crawling-the-com plete-ipv4-reverse-dns-space.html.
- RT 𝕡𝕨𝕟𝕚𝕖: Microsoft blocked Office macros in 2022. Attackers moved to ISO files. Microsoft fixed ISO files. Attackers moved to LNK and … by Florian Roth.
- RT Adam: My Time Travel Debugging for Windows project has a website now: http://wintrace.io Since last post I implemented breakpoint support & more st… by Florian Roth.
- RT YungBinary: New blog is out! Digging into TAG-150’s evolving tradecraft across #DinDoor, #DenoRAT, and #NightshadeC2. We break down the infection … by Florian Roth.
- RT Quentin Kaiser: Re AI Assisted Vulnerability Research on Embedded Targets - https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/ by Dave Aitel.
- RT 7h3h4ckv157: Sliver GUI A desktop operator console for the Sliver C2framework in the spirit of Cobalt Strike and Havoc. Designed and Developed by R… by ege.
- Post-Compilation Obfuscation Is Outdated: Moving Polymorphism Directly into CMake https:// sibouzitoun.tech/articles/sind rikit-v1o5/.
- Interstitial Risk: When Two Correct Systems Make One Vulnerable One https:// gneiss-group.com/writing/inter stitial-risk/.
- Glorious by Gergely Kalman.
- RT Swissky: C111000: Race Against The Virtual Machine or how a SUID binary in VMware Fusion was raced to gain root privileges on macOS - @Coiffeur0x90… by Gergely Kalman.
- RT Brad Spengler: https://1day.dev/posts/linux-kernel-0day.html by h0mbre.
- RT @Lakr233: 终于拆出来了,jailbroken iPhone 15 Pro Max + iOS 17.3.1 -> root 但是尼玛 sptm/gfx write 的调度,触发方式居然是锁定屏幕等电源发一个 g… by hasherezade.
- RT Kyle Cucci: We (@proofpoint Threat Research) just published some of our research where we’ve been tracking a malware crypter service called Crucif… by hasherezade.
- RT cr3ghost: Every malware analyst and reverse engineer has used x64dbg. Most have no idea what else the creator has been building. RiscY Business bre… by hasherezade.
- Shellph - a portable command-line utility designed to automate encryption and obfuscation of arbitrary shellcode. https://github.com/xirtam2669/Shellp… by Panos Gkatziroulis.
- Custom Adaptix-compatible C2 agent - PIC beacon + Stardust UDRL + Go extender plugins https://github.com/MaorSabag/NaX by Panos Gkatziroulis.
- RT myexploit2600: My @Steel_Con talk on compromising hybrid domains is now live! The talk explains real-world attack paths spanning: Active Directory … by Panos Gkatziroulis.
- GhostHound - a BloodHound OpenGraph extension Enumerating CN=Deleted Objects and who can restore them https://github.com/JVBotelho/ghosthound by Panos Gkatziroulis.
Tools and Exploits
Windows privilege escalation tool from Project Nightcrawler. Targets legacy components for local privilege escalation with working PoC and detection KQL queries.
Credential harvesting project focused on living-off-the-land techniques. Useful for both red team operators testing credential exposure and defenders building detection rules.
Passive Active Directory enumeration using native ADSI/COM interfaces. No .NET, no PowerShell, no managed runtime required.
Updated Semgrep ruleset for finding vulnerabilities in C and C++ codebases. Ready for integration into CI pipelines and local scanning workflows.
IDA 9.4 ships with Swift decompilation support, Qualcomm Hexagon and MCore processor modules, a rebuilt Dyld Shared Cache workflow, and Pathfinder navigation. idalib now included with IDA Home.
DLL loader built on Crystal Palace that uses CET-compatible callback trampolining for stack spoofing. Rust implementation with working PoC.
Curated collection of open-source user-defined reflective loaders that bypass CrowdStrike, Elastic, Defender, and SentinelOne. Compatible with Cobalt Strike, Nighthawk, Havoc, Sliver, and more.
Latest Metasploit update adds HTTP to SMB relay, Fetch Multi payloads for automatic architecture identification, and expanded RISC-V support.
New LOLBAS entries for TextTransform.exe, TextTransformCore.exe, MSTest.exe, and Microsoft.XslDebugger.Host bypass Windows Defender Application Control policies.
Major release of the commercial C2 framework with CET-compatible user-defined synthetic frames, new OpSec features, and quality-of-life improvements for operators.
More this week (16)
- strix 41,107 stars Deploy autonomous AI hackers to pentest your codebase. This open-source tool doesn’t just find vulnerabilities - it automati… by Marco Ramilli.
- RT Open Source Security mailing list: Apache Kylin CVE-2026-62390: SQL Injection in Catalog Cache Refresh API https://openwall.com/lists/oss-security/… by kmkz.
- jestasecurity/thumper: Thumper is an open-source tripwire for the Shai-Hulud npm worm. Plant fake-but-realistic credentials where the worm scans - the… by Nicolas Krassas.
- RT MSec Operations: Backdooring existing executables or DLLs for stealthy payload execution? With version 1.7.0 of RustPack, this can be easily done i… by S3cur3Th1sSh1t.
- RT Óscar Alfonso Díaz: airgeddon v12.01 is out! More stable Evil Twin Better Ctrl+C interruption handling WPS fixes & improvements … by Alberto Verza.
- RT es3n1n: Today, we’re releasing rCTF v2, an open-source platform for hosting cybersecurity capture-the-flag competitions. by Daax.
- RT Smukx.E: MS has written detections for LegacyHive an LPE. So its safe and i’m releasing the PoC template for LegacyHive-rs. The poc can be extended… by kmkz.
- RT es3n1n: Today, we’re releasing rCTF v2, an open-source platform for hosting cybersecurity capture-the-flag competitions. by Swissky.
- RT Katie Paxton-Fear: Can we trust Chinese open weight models? Was a question a lot of people asked after GLM 5.2 was released, scoring very well … by thaddeus e. grugq.
- RT Soroush Dalili: I’ve finally updated Sharpener for #BurpSuite. With fully automated AI-powered coding and UI testing, this release includes major … by SinSinology.
- RT Nicolas Krassas: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative https://www.securityweek.com/white-house-launc… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- White House launches AI-driven “Gold Eagle” clearinghouse to centralize public-private vulnerability coordination https://www. whitehouse.gov/releases/2026/0 7/white-house-launches-gold-eagle-initiati.
- Some unreal features coming in our next release - we finally made it to 1.0, well done @peterwintrsmith @s4ntiago_p @modexpblog @GigelV41464 @saab_sec… by Dominic Chell.
- RT Enno Rey: Windows Hello for Business – Full Report Has Been Released, via @Insinuator https://insinuator.net/2026/07/windows-hello-for-business-fu… by DirectoryRanger.
- Open-source prompt-injection detector, with a real-world attack corpus collected from a live red-team game https:// huggingface.co/Bordair/bordair -detector.
- RT Nextron Research : Our artifact scanner found new npm packages in the ongoing DPRK “Rollup Polyfills” campaign: - react-hot-svg v1.1.7 (st… by Florian Roth.
