A roundup of 448 items curated from across the security community.
News
Black Lantern Security discovered and reported this vulnerability in IBM webMethods Integration Server. Full technical writeup with reproduction steps.
Krebs reports LG will suspend smart TV apps that turn televisions into residential proxy nodes. Over 42 percent of webOS store apps were found routing third-party traffic through users’ devices.
Pwn2Own Ireland 2026 announces new targets and categories, including a $300K bounty for a remote iPhone 17 exploit. Registration process has changed.
During a model evaluation, an OpenAI model escaped its sandbox, exploited vulnerabilities, stole credentials, and moved laterally into Hugging Face infrastructure. The first documented autonomous agent cyberattack in the wild.
Gamers Nexus investigation reveals LG monitors silently install McAfee software that displays pop-up ads on the desktop.
Kimi K3 with 32 agents discovered and exploited a zero-day in the latest Redis server in under 30 minutes. PoC published.
Unit 42 tracks CL-STA-1114 (Void Blizzard/LaundryBear) exploiting a zero-click vulnerability to automatically compromise mail accounts when an email loads. No user interaction required.
Researcher gained full control over all users and vehicles on Volvo/Eicher’s fleet management platform through a series of web application flaws.
Italy summoned the Russian ambassador and expelled two Russian military attaches. Russia retaliated by expelling Italian diplomatic personnel from Moscow.
Hugging Face publishes a full technical timeline, interactive replay, and forensic analysis of the autonomous agent intrusion. Includes how they used an open model to defend against the attack.
More this week (45)
- RT kiks: https://1day.dev/posts/linux-kernel-0day.html I was working with some 0-days lately, and one of them was for the pwn2own. Although the regist… by thaddeus e. grugq.
- Introducing the SpecterOps Tradecraft Academy by Katherine.
- RT Sakana AI: Introducing Fugu-Cyber: an update to our Fugu orchestration model. It achieves state-of-the-art performance on real-world security bench… by Vincent Yiu.
- Pwn2Own Ireland 2026 – New Targets and Categories by Dustin Childs.
- Not only will the BLS team be at Defcon 34 this year, but we’re proud to announce that we will also be hosting a hands-on workshop for BBOT 3.0! #OSIN… by Black Lantern Security (BLSOPS).
- Estée Lauder discloses data breach via Oracle E-Business flaw https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-o… by BleepingComputer.
- Hugging Face discloses breach linked to autonomous AI agent https://www.bleepingcomputer.com/news/security/hugging-face-breach-autonomous-ai-agent-sys… by BleepingComputer.
- Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak https://www.bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-c… by Nicolas Krassas.
- GitHub issues $100,000 bounty for critical RCE vulnerability https:// runtimewire.com/article/github -issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitz.
- Andrew Case: To summarize: HuggingFace got autonomously compromised by a model from an American company. HF then tried to use American frontier model(s) to defend themselves, but were blocked by guard by Jon Oberheide.
- RT hacker.house: Updated our inference fuzzing write-up - now with the vuln specifics we held back. Full detail on a pre-auth path traversal in OpenWR… by kmkz.
- This was so well done. @NathanMcNulty is a true hacker and builder. The session was packed with research potential. by Nikhil Mittal.
- South Korea discloses data breach impacting diplomats worldwide https://www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impac… by BleepingComputer.
- RT Qualys: Another important vulnerability disclosure and piece of research from the Qualys Threat Research Unit (#TRU) The TRU team just disclos… by Giuseppe
N3mes1s. - RT watchTowr: Introducing Project Red - the autonomous vulnerability reproduction capability behind the watchTowr Platform. Project Red reproduced wp2… by SinSinology.
- I’m currently in the crunch phase preparing for Defcon and this time BlackHat to showcase the latest feature of OctoPwn, automation workflows for inte… by SkelSec.
- The safety of our community is our highest priority. For this reason, we have decided to postpone DEF CON Middle East. The evolving security situation in the region makes it impossible to concentrate.
- Finding actors that probe a CVE’s exploit path before public disclosure in 30M honeypot records. https://honeylabs.net/blog/probe-17-days-before-the-c… by /r/netsec.
- RT dungnm: Pwn2Own Berlin 2026 took place quite some time ago, but only today have I had the opportunity to share details about our journey during the… by Alex Plaskett.
- RT John Monero: paypal rack up bugs, don’t pay them out, so I personally believe a public disclosure is deserved. Unauthenticated Firebase custom-toke… by Simone Margaritelli.
- RT clem : So proud of our security team! They caught, contained & publicly disclosed an attack unlike anything we’ve seen before, and did it at re… by Halvar Flake.
- Introducing Antares: Highly Efficient Open Weight AI Models for Vulnerability Localization - Amin Karbasi https://blogs.cisco.com/ai/introducing-antar… by Swissky.
- OnTrac notifies customers of data breach after network hack https://www.bleepingcomputer.com/news/security/ontrac-notifies-customers-of-data-breach-af… by BleepingComputer.
- Chick-fil-A data breach affects more than 13,000 customers https://www.bleepingcomputer.com/news/security/chick-fil-a-data-breach-affects-more-than-13… by BleepingComputer.
- Australian energy provider Origin Energy disclosed a data breach impacting customer data https://securityaffairs.com/195973/data-breach/australian-ene… by Nicolas Krassas.
- RT Zhenpeng (Leo) Lin: Open-sourcing our RCE implementation for CVE-2026-42533! This is an incredibly powerful NGINX bug that provides both info leak … by Florian Roth.
- RT DARKNAVY: Our AI agent, deepsec, reproduced @orange_8361’s fabulous pure-logic Microsoft Edge RCE demonstrated at Pwn2Own Berlin 2026, starting onl… by kmkz.
- Cognyte Sells a Mobile Cell Surveillance Van by Bruce Schneier.
- Thailand’s Ministry of Finance targeted with an AI agent running with approval prompts disabled https:// hunt.io/blog/thailand-ministry -finance-targeted-with-hermes-ai-agent.
- RT 0xroot: Overcoming State: Finding Baseband Vulnerabilities by Fuzzing Layer-2 【PDF】 https://i.blackhat.com/BH-US-24/Presentations/REVISED-US24-Go… by thaddeus e. grugq.
- Coca-Cola confirms data theft in Fairlife ransomware attack https://www.bleepingcomputer.com/news/security/coca-cola-confirms-data-theft-in-fairlife-r… by BleepingComputer.
- Ernst & Young data breach claimed by ShinyHunters extortion gang https://www.bleepingcomputer.com/news/security/ernst-and-young-data-breach-claimed-by… by BleepingComputer.
- OnTrac parcel delivery company reports customer data breach https://www.scworld.com/brief/ontrac-parcel-delivery-company-reports-customer-data-breach by Nicolas Krassas.
- Introducing Burp AT: agentic AI, built on two decades of Burp Suite https://portswigger.net/blog/introducing-burp-at by Nicolas Krassas.
- A Canadian intern at NATO’s top military headquarters* in Belgium was arrested Friday on spying charges. Prosecutors say she is suspected of spying fo… by Nick Carr.
- RT EZ: Another day, another Global Admin compromise due to Intune. I’ve been talking about the security issues and privilege escalation paths through … by SwiftOnSecurity.
- New vBulletin Vulnerability! https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/ by /r/netsec.
- Thailand’s Ministry of Finance targeted with an AI agent running with approval prompts disabled https://hunt.io/blog/thailand-ministry-finance-targete… by /r/netsec.
- How AI is powering business email compromise at scale https:// research.eye.security/phishing -as-a-service-inside-two-ai-powered-phishing-kits-that-automate-bec/.
- Hohoho the plot thickens. WASHINGTON, July 28 (Reuters) - The rogue agent that escaped from OpenAI and went on a days-long hacking spree at the AI firm Hugging Face also compromised a customer at a se.
- RT blackorbird: Operation #Triangulation In 2023, Kaspersky’s public IOCs and leaked Snort rules (tagged “EquationGroup-TriangleDB”) confirmed that… by Florian Roth.
- RT Burp Suite: Introducing Burp AT. Agentic AI for human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skil… by Gareth Heyes \u2028.
- AgentHound - Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path anal… by Panos Gkatziroulis.
- RT hacker.house: Multiple remote OpenWrt 0days. Pre-auth paths straight to full device compromise. Unauthenticated command execution as root on millio… by kmkz.
- RT Huntress: In 2021, Silk Typhoon hit Microsoft Exchange and the industry called it “limited and targeted.” But we saw 88K compromised servers and wo… by Kuba Gretzky.
Techniques and Write-ups
Public PoC released for SharePoint SE pre-auth RCE. The researcher notes Microsoft replaced a stable design with one that introduced multiple pre-auth vulnerabilities.
IPv4/IPv6 fragmentation bug in the Linux kernel that provides a direct path to root. May also affect Android. Full writeup with PoC and kernelCTF submission.
Wiz researchers disclose a critical RCE vulnerability in GitHub’s code scanning infrastructure. Exploitation requires no special privileges.
Pure-logic, 100% reliable privilege escalation from normal user to SYSTEM on Windows 11 via the Windows Installer service. Full writeup with PoC.
XBOW’s autonomous agents discovered three separate RCE vulnerabilities in Bing Image Search, each achieving SYSTEM or root-level execution on Microsoft infrastructure.
In a default AD CS setup, a low-privileged domain user creates a rogue machine account, tricks the CA into issuing a DC certificate via PKINIT, gains replication access, and compromises the entire domain.
Calif demonstrates the first public bypass of Apple Memory Isolation Extensions on macOS 26.4.1. Details withheld until Apple shipped fixes in macOS 26.6. Now released as an exploitation challenge ahead of Black Hat USA.
TrustedSec details how device code phishing bypasses MFA in Microsoft 365 environments. Covers the attack flow, detection gaps, and defensive recommendations.
Open-weight models GLM 5.1 and 5.2 found six vulnerabilities across five CVEs in the NGINX codebase. First in a series on AI-assisted vulnerability research using open models.
Detailed writeup covering root cause analysis, kernel-side behavior, and exploit implementation for the DarkSword kernel vulnerability.
More this week (351)
- RT siri@fu4k1: https://github.com/wouijvziqy/Fastjson-JsonType-RCE-PoC by kmkz.
- RT Defused: Update to our Jul 17 SharePoint report: we now assess the undocumented deserialization vector on our honeypots as likely CVE-2026-505… by kmkz.
- RT /r/netsec: Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing https://blog.threatuniverse…. by kmkz.
- RT 7h3h4ckv157: Pre-Auth nginx RCE Across 13 Call Sites: Two-Pass Capture Clobbering CVE-2026-42533 Credit/Author: Cyberstan His blog: https://cyberst… by Spiros Fraganastasis.
- RT Straiker: “Defenders prepared for hostile users and rogue models. Here the model obeys, the user is innocent and the context is the weapon.” https:… by Malware Unicorn.
- So looks another interesting finding… that, as usually, no one will gaf about, because it was not found / written about by some “big experts”… or … by MalwareHunterTeam.
- RT TrustedSec: Azure container services are everywhere. Their attack surface? Often overlooked. Part 1 of this #blog series, @OffsecPierogi walks thro… by nyxgeek.
- C111000: Race Against The Virtual Machine or how a SUID binary in VMware Fusion was raced to gain root privileges on macOS - @Coiffeur0x90 https://the… by Swissky.
- Building an AI-Based Vulnerability Detection Workflow - se1en https://se1en.tistory.com/16 by Swissky.
- RT beac: 0-day in the Aiken compiler (Cardano smart contracts). https://github.com/DK27ss/Aiken-opaque-expect-bypass expect on an opaque type (Di… by Swissky.
- RT Nicolas Krassas: CVE-2026-42980, a Windows kernel WMI integer-underflow vulnerability that can be exploited for local privilege escalation to NT AU… by Rémi GASCOU (Podalirius).
- RT Eli Woodward: U.S. government offering relocation and reward for information. In other words, get out of your current life and start ov… by scriptjunkie (Matt).
- RT Louis Nyffenegger: If you’re using fastjson 1.x, it’s time to move to 2.x. And the big lesson to learn this week (wp2shell and fastjson), once you … by ϻг_ϻε.
- RT Wojciech Reguła: New blog post about another macOS 27 privacy enhancement. Thx @ciphwall for a hint: https://wojciechregula.blog/post/golden-… by Csaba Fitzl.
- MIT to Become Hotbed of AI Video Surveillance by Bruce Schneier.
- Interesting. by V4bel.
- Recently added an async ticket auto-renewal BOF to my tgt-monitor repo (https://github.com/jakobfriedl/tgt-monitor-bof). When the remaining ticket lif… by Jakob.
- Hello, People Living Inside My Computer (PLIMC), If you’re someone who enjoys malware, I have good news. If you’re someone who dislikes malware, I hav… by vx-underground.
- Wordpress, 7zip, the 90s are making a comeback! https://www.zerodayinitiative.com/advisories/ZDI-26-444/ by AndrewMohawk⁽ⁿᵘˡˡ⁾.
- Hackers steal $23.7 million in crypto from Ostium in off-chain attack https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-cryp… by BleepingComputer.
- Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains https://www.securityweek.com/trump-orders-defense-contractor… by Nicolas Krassas.
- India identifies new scam compound in Myanmar, Government successfully rescues two youths https://ministryofcyberaffairs.com/news/india-identifies-new… by Nicolas Krassas.
- Ostium trading platform loses $23.75 million in off-chain exploit https://www.scworld.com/brief/ostium-trading-platform-loses-23-75-million-in-off-cha… by Nicolas Krassas.
- Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/ by Nicolas Krassas.
- The Hidden CCS2 Attack Surface on EV Chargers https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers by Nicolas Krassas.
- AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html by Nicolas Krassas.
- Kratos phishing-as-a-service kit loses its battle with international law enforcement https://www.theregister.com/security/2026/07/21/german-authoritie… by Nicolas Krassas.
- US police now armed with Israeli spy vans simulating mobile phone towers https://cybernews.com/privacy/us-police-israeli-spy-vans-falconet-cognyte/ by Nicolas Krassas.
- Shellph - a portable command-line utility designed to automate encryption and obfuscation of arbitrary shellcode https://github.com/xirtam2669/Shellph by Nicolas Krassas.
- Kali365 Targets US Organizations with Data Theft via Device Code Phishing https://any.run/cybersecurity-blog/kali365-phishing-targeting-us/ by Nicolas Krassas.
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack https://thehackernews.com/2026/07/new-encforge-ransomware-targets-ai.html by Nicolas Krassas.
- Windows LegacyHive zero-day flaw gets free, unofficial patches https://www.bleepingcomputer.com/news/security/windows-legacyhive-zero-day-flaw-gets-fr… by Nicolas Krassas.
- Leaking internal headers in Flask Ninja with deserialization https://eval.blog/research/pickle-gadget-chain-in-flask-ninja/ by Nicolas Krassas.
- Critical Palo Alto VPN bug now exploited by Qilin ransomware gang https://www.bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-ex… by Nicolas Krassas.
- Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data https://www.securityweek.com/meta-pays-78000-bounty-for-vulnerability-exposi… by Nicolas Krassas.
- Salat Stealer – From Telegram Proxy to C2 Infrastructure https://github.com/kaandemir993/Salat-Stealer-Telegram-Proxy-Decoy-C2-Analysis by Nicolas Krassas.
- pipetap. helps you observe, intercept, and replay traffic over Windows Named Pipes, by @leonjza https://github.com/sensepost/pipetap by DirectoryRanger.
- http://ps.exposed. Community-driven PowerShell Detection Indicators #DFIR https://github.com/avasero/psexposed/ by DirectoryRanger.
- RT Enno Rey: Deep-dive analysis of Windows Hello for Business, performed by @BSI_Bund & @ERNW_ITSec https://www.bsi.bund.de/SharedDocs/Downloads/EN/BS… by DirectoryRanger.
- RT Caitlin Condon: New KEV: CVE-2026-29059 is an unauth path traversal @Chocapikk_ discovered in the popular Windmill automation platform. @VulnCheckA… by Giuseppe
N3mes1s. - Really nice research into Microsoft’s GDID that got everyone’s attention recently by Octoberfest7.
- RT cr3ghost: Every malware analyst and reverse engineer has used x64dbg. Most have no idea what else the creator has been building. RiscY Business bre… by Steven Lowson.
- RT Sysdig: JADEPUFFER has evolved. This time it deployed ransomware built specifically to destroy AI models. 180 file types. Model weights. Train… by SwitHak ().
- RT SteelCon: Want a Monday morning treat? Our videos are now online: https://www.youtube.com/playlist?list=PLPmYYKuFkAAM We are missing a couple which… by Andy Gill.
- Some Magic Linker - a tour of Crystal Palace and TCG by Raphael Mudge. http://vimeo.com/1209887681 by Rasta Mouse.
- RT Karl: A new Azure VM command execution method dropping from @Thomasbyrne__ Technically a variation on the other Extension-based methods (Custom Scr… by Scott Sutherland.
- Ask Gemini for a “Walmart MCP” and the first result is malware. try it. https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers… by /r/netsec.
- What happened after we pushed our .env to a public repo https://tachyon.so/blog/what-happened-after-we-pushed-env-to-public-repo by /r/netsec.
- Post-Compilation Obfuscation Is Outdated: Moving Polymorphism Directly into CMake https://sibouzitoun.tech/articles/sindrikit-v1o5/ by /r/netsec.
- Interstitial Risk: When Two Correct Systems Make One Vulnerable One https://gneiss-group.com/writing/interstitial-risk/ by /r/netsec.
- Crawling the Complete IPv4 Reverse DNS Space https://ipapi.is/blog/crawling-the-complete-ipv4-reverse-dns-space.html by /r/netsec.
- Five months of industrial-protocol traffic to our honeypots https://honeylabs.net/blog/knocking-on-the-control-room by /r/netsec.
- Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cv… by /r/netsec.
- Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https://slcyber.io/research-center/exploit-brokers-pay-500… by /r/netsec.
- RT Joe Grand: Video from my Reverse Engineering a Ledger Nano X Hardware Implant talk (@hardwear_io) is up along with firmware extracted from the impl… by Alex Plaskett.
- Found another hilariously trivial Windows PPL, hard to believe I didn’t see this one earlier. Doesn’t work in full PP due to the nature of it, but TBH PPL-WinTCB is really all you need :).
- RT Nextron Research : We’ve identified a Linux backdoor under development Archive Hash 76a360593bf7b068649dcbd8056952a569ebf3a9f7bae480015a7f… by Florian Roth.
- RT Is Now on VT!: Sample is now on VT! Hash: e097f3b445b63b07afacde8d6a67f0be654dd51e228a3610fb0710a1f7e29a69 Actor name: GodDamnRansomware �… by Florian Roth.
- RT blackorbird: Inside #Pegasus : documents Collections https://github.com/AmnestyTech/inside-pegasus/tree/main/documents/products-and-capabilities re… by Florian Roth.
- RT blackorbird: DPRK ClickFake Interview Campaign Drops PylangGhost and GolangGhost RATs Impersonated Platform & Panel’s API Endpoints https://socrad… by Florian Roth.
- RT Group-IB Global: A threat actor operating as “888” advertised the sale of 35GB of data allegedly stolen from #Accenture, claiming the dataset conta… by Florian Roth.
- Everyone can write YARA rules. In the same way that everyone can paint a picture. You can automatically generate thousands of rules within seconds, co… by Florian Roth.
- RT Kyle Cucci: We (@proofpoint Threat Research) just published some of our research where we’ve been tracking a malware crypter service called Crucif… by Florian Roth.
- RT tlansec: If you’re looking into the newest SonicWall exploitation (CVE-2026-15409 & CVE-2026-15410), the Volexity blog is a must read: https://www…. by Florian Roth.
- RT Anderson Nascimento: Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933) https://seclists.org/oss-sec/2026/q3/1… by Dave Aitel.
- RT thesage-: Our VR team’s new research is out! There is an exploitation chain called OnlyShells of 3 vulnerabilities that grants NT AUTHORITY\SYSTEM … by Arun.
- RT Cisco AI: Introducing Antares: @Cisco’s family of small language models for locating known vulnerabilities in code. Antares-350M and Antares-1B are… by Arun.
- RT 𝕡𝕨𝕟𝕚𝕖: Ransomware threat actors adopted new TTPs in H1 2025, including EDR evasion via bring-your-own-installer techniques and custo… by Arun.
- RT rootsecdev: HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels https://www.group-ib.com/blog/hollowgraph-microso… by Arun.
- Can an agent look at a visual artifact - a PCB photograph, a facility layout, a simulated drone feed - extract the spatial structure that matters, a… by dreadnode.
- CVE-2026-50458: Finding a UAF in the Windows Brokering File System https:// rotcee.github.io/posts/CVE-202 6-50458-finding-a-UAF-in-windows-brokering-file-system/.
- RT b33f | 🇺🇦: Round 2, fight! GPT5.6 chains together an impressive set of techniques to gain ACE and uses that to render a Mortal Kombat logo … by h0mbre.
- Being able to represent the whole story is critical to threat actor attribution. Can your platform represent analytically relevant lunch orders? … by visi stark.
- RT 0x12 Dark Development: KernelCallbackTable Process Injection New Medium post, today we are looking at a process injection variant named Kernel Call… by Panos Gkatziroulis.
- Always feels weird seeing my ex‑employer’s JIRA instances show up in my website referrers. If you don’t belong to the above group, here are the … by Panos Gkatziroulis.
- RT C2 Matrix | #C2Matrix: Added Endgame to #C2Matrix - AI-powered command and control for professional red team operations https://github.com/endgamec… by Panos Gkatziroulis.
- RT spencer: Finding insecure permissions in Active Directory doesn’t have to be hard. You don’t have to run Bloodhound or install docker or learn kali… by kmkz.
- RT CISA Cyber: Iranian-affiliated cyber actors are targeting internet-connected PLCs from Rockwell Automation, Schneider Electric, & Siemens. Dis… by kmkz.
- Tried the “AI-assisted vuln research” thing on a real large codebase. No full-auto magic, no “paste repo -> RCE”. But with a strict source-to-sink… by kmkz.
- RT @bytecodevm: Technical breakdown of OnlyShells - a five-vulnerability chain in ONLYOFFICE Desktop Editors combining zero-click XSS, a Ch… by kmkz.
- RT Matthias Deeg: Re We have also created a proof-of-concept video demonstrating arbitrary file deletion, arbitrary file read, and remote code executi… by kmkz.
- RT Matthias Deeg: Today, my colleague @moritz_abrell published his new tech blog article titled “Against All Odds: Exploiting a QNAP NAS” in which he … by kmkz.
- RT vmpr0be: Found 2 vulnerabilities in VirtualBox! CVE-2026-47055: Oracle VirtualBox USB Card Reader Host Heap Buffer Overflow Vulnerability CVE-2026-… by kmkz.
- RT 0xor0ne: Exploiting Realtek SD card reader driver vulnerabilities (@zwclose) Part 1: https://zwclose.github.io/2024/10/14/rtsper1.html Part 2: http… by kmkz.
- RT Login Sécurité: Microsoft : “on a bien patché la CVE-2025-29969” @HackAndDo : “hold my beer” Microsoft : "" Pour les détails, c’est sur le … by kmkz.
- Some “Ubuntu Packages” page here: http://107.189.24[.]181:8080/ But then there is this “Staged Shell Bot” sample here: http://107.189.24[.]181:8080/bo… by MalwareHunterTeam.
- RT Thinkst Canary: Attackers have inserted policy-violating text into malware to trip up agent-based analysis. Defenders can use this too. Enable “Gua… by Max.
- RT Pavel Yosifovich: New video: Windows privileges Two elevated command prompts run the same process enumerator. One reads every path, the other hits … by Max.
- RT Johann Rehberger: Talks from Stanford’s Real-World AI Security Conference are now on YouTube! Full list is here https://seclab.stanford.edu/RealWor… by Max.
- RT Alon Leviev: My research on a new attack class in Windows Recovery - “Confused Recovery” - has been nominated for the Best Privilege Escalation Pwn… by Max.
- RT Nathan McNulty: This was super fun, and I thought I’d share a quick demo I had recorded in the event of technical issues :) I repurposed my Key Vau… by Max.
- RT Panos Gkatziroulis : Bitdefender just published a great deep‑dive into Bind Links (File‑Binding, Process‑Binding, and Silo‑Binding) fo… by Max.
- Re-Engineering Pytune - Rogue devices in the age of conditional access Part 1 https://stra-x.github.io/Re-Engineering-Pytune-Rogue-devices-in-the-age-… by Swissky.
- GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security - Dolev Taler - @varonis https://www.varonis.com/blog/ghosttree-ntfs-tric… by Swissky.
- RT four: Excited to share one of the things I’ve been working on: Gemini 3.5 Flash Cyber: a lightweight, highly capable model built to help the securi… by Swissky.
- RT drm: You can know dump TDO with secretsdump dot py, thanks to Goultarde by Swissky.
- RT Daily CyberSecurity: A public PoC for CVE-2026-42980 details a Windows privilege escalation flaw in the kernel WMI code. It grants SYSTEM on unpatc… by Rémi GASCOU (Podalirius).
- RT Jeff Whitehead: Hugging Face says it resorted to a Chinese AI model to battle a fully autonomous cyberattack because U.S. model guardrails stymied … by Sean Heelan.
- RT max.berlin: okay, so most people don’t know this yet but ChatGPT Work in the web has its own virtual machine with real resources (15gb ram & 9+ cor… by Winslow.
- Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel by Jordyn Dunk.
- RT Lukasz Olejnik: Cyberattacks that use cloud GPUs to destabilize the power grid and disrupt computing. A malicious cloud tenant could synchronize wo… by thaddeus e. grugq.
- RT 0xroot: Nice Talk about iPhone BaseBand Research from @lukasarnld Apple C1 Baseband: https://static.lukasarnold.de/pdfs/obtsv8-diving-into-c1.pdf Q… by thaddeus e. grugq.
- RT FSEC INTEL ES: Emulating Kimsuky’s Initial Access https://0x00sec.org/emulating-kimsukys-initial-access/ by thaddeus e. grugq.
- RT Shubham: btw people are misunderstanding what ExploitGym actually is… the benchmark literally gives the model a real vulnerability, a crashing inp… by Bobby Cooke.
- Don’t swing at everything by Thorsten Rosendahl.
- “Carl was a helpdesk technician […] To save time, Carl came up with a secure password that was easy to dictate over the phone and met the password c… by Black Hills Information Security.
- New Dolphin X malware uses AI to rank high-value targets https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-ai-to-rank-high-val… by BleepingComputer.
- Fake Claude app promoted by Bing ads pushes SectopRAT malware https://www.bleepingcomputer.com/news/security/fake-claude-app-promoted-by-bing-ads-push… by BleepingComputer.
- New msaRAT malware uses Chrome, Edge browsers to route C2 traffic https://www.bleepingcomputer.com/news/security/new-msarat-malware-uses-chrome-edge-b… by BleepingComputer.
- Check Point warns of SmartConsole zero-day exploited in attacks https://www.bleepingcomputer.com/news/security/check-point-patches-smartconsole-zero-d… by BleepingComputer.
- Upbound says hack caused $13 million in fraudulent Acima leases https://www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-… by BleepingComputer.
- How Starlink Became the Unkillable Wi-Fi for a $114 Billion Crime Empire https://ministryofcyberaffairs.com/news/how-starlink-became-the-unkillable-wi… by Nicolas Krassas.
- Millions of California-bought cars can be hijacked via Bluetooth https://www.theregister.com/security/2026/07/23/millions-of-california-bought-cars-ca… by Nicolas Krassas.
- Hackers abuse Notepad++ plugins to stealthily install malware https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-t… by Nicolas Krassas.
- Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-… by Nicolas Krassas.
- Year-long Russian attacks infect users as soon as they look at an email https://www.theregister.com/patches/2026/07/23/year-long-russian-attacks-infec… by Nicolas Krassas.
- Russian hackers exploit Zimbra zero-click flaw for email theft https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-zimbra-zero-clic… by Nicolas Krassas.
- Open Evaluation Framework for AI Pentesting Agents on Real-World Targets https://arxiv.org/abs/2605.10834 by Nicolas Krassas.
- Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html by Nicolas Krassas.
- Microsoft admits SMS and voice MFA can’t stop AI attacks, mandates passkeys in Entra by February 2027 https://www.windowslatest.com/2026/07/22/micros… by Nicolas Krassas.
- In regards to the OpenAI hack, as more data and information comes out. A couple of thoughts. One - OpenAI’s sandbox environment was not setup or desig… by Dave Kennedy.
- RT Tal Be’ery: An Anatomy of the ExploitGym Incident : When an OpenAI model hacked its own benchmark 1/ Sources: @OpenAI , @huggingface official p… by Dave Kennedy.
- Is it really “rogue” if someone failed to lock the door? “OpenAI failed to properly configure what it called a ‘highly isolated environment,’ allowing… by Kim Zetter.
- It is a feature not a bug cit. If you put a lot of attentions to the logs you noticed this already then it was happening by Giuseppe
N3mes1s. - RT Kirill Firsov: Original write-up on the fastjson 1.2.83 gadget-free RCE. Have fun reading, I hope you missed writeups without AI slop. Comment here… by Giuseppe
N3mes1s. - LWIS kernel driver OOB write in lwis_io_buffer_write https://project-zero.issues.chromium.org/issues/507772918 by Project Zero Bugs.
- RT rootsecdev: GDID: The Windows Global Device Identifier Deep technical analysis of Windows Global Device Identifier (GDID), a persistent 64-bit devi… by Sean Metcalf.
- RT MSec Operations: Initial access. Post-exploitation. Persistence. These are the phases most of you need to simulate in your day-to-day engagements. … by S3cur3Th1sSh1t.
- RT Microsoft Threat Intelligence: The continuing effects of Microsoft’s disruption of the Tycoon2FA phishing platform contributed to sustained decline… by SwitHak ().
- RT NSA Cyber: Russian state-supported actors are targeting Zimbra Collaboration Suite users to exfiltrate sensitive communications and email directori… by SwitHak ().
- RT Andrew Curran: The Hugging Face attack has led Representatives Ted Lieu (D-Califk) and Nathaniel Moran (R-Texas) to introduce the AI Kill Switch Ac… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- RT EuskalHack: Ya puedes consultar las presentaciones de las ponencias de EuskalHack Security Congress IX en nuestra página web. Gracias a todos los … by X-C3LL.
- Why AI Needs a “Genie Coefficient” by Bruce Schneier.
- Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA http://scamdrill.com/blog/m365-oauth-device-code-phishing by /r/netsec.
- PE OopsSec: Mind your PE, guard your OPSEC https://www.zerosalarium.com/2026/07/pe-oopssec-mind-your-pe-guard-your-opsec.html?m=1 by /r/netsec.
- GitHub issues $100,000 bounty for critical RCE vulnerability https://runtimewire.com/article/github-issues-100-000-bounty-for-critical-rce-vulnerabili… by /r/netsec.
- CVE-2026-50458: Finding a UAF in the Windows Brokering File System https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-fi… by /r/netsec.
- I ran a paid bug-bounty-style game against my own multimodal prompt firewall, it didn’t make money, so here’s the code, the model and 13k real bypass … by /r/netsec.
- I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-w… by /r/netsec.
- Wrote my first WinDbg JS extension to find and display some members of the kernel debugger data block. Goal is to serve as a blueprint for a C++ imple… by winterknife.
- #HuggingFaceHack by Florian Roth.
- RT TomU | I’m still here… til the end 🇨🇭: “Using NetBIOS names for pivoting and threat clustering” Blog post updated with current stats,… by Florian Roth.
- RT Aaron Jornet: #APT #OceanLotus #APT32 #SeaLotus #malware #threat #HiveSwarming #Shellcode 🇻🇳 🇨🇳 #Phishing > ZIP > #IMG… by Florian Roth.
- RT ZoomEye: CVE-2026-60206: Oracle WebLogic Server Arbitrary File Read Critical Vulnerability Alert! Oracle WebLogic is affected by CVE-2026-6020… by Florian Roth.
- RT Smukx.E: Advanced Module Stomping & Stack & Heap Encryption TLDR;- This blog will talk about the in depth analysis and implementation of Heap & Thr… by Florian Roth.
- RT Hunt.io: North Korean Campaign Hides OTTERCOOKIE Inside SVG Images https://gbhackers.com/ottercookie-malware-in-svg-images/ North Korea’s Con… by Florian Roth.
- RT Eugene Kaspersky: HelloNet: a new APT campaign abusing the ViPNet update system to deploy malicious modules. The toolset includes a DLL sideloader,… by Florian Roth.
- RT Lukasz Olejnik: For fun, I pointed GPT-5.6 Sol at the security design of SHA-3, a foundational hash function, specifically the Keccak reference and… by Dave Aitel.
- RT SentinelLabs: New Research Can frontier models actually run a long-horizon malware investigation start to finish? We built a benchmark fr… by Dave Aitel.
- RT R.B.C.: Hey everyone! Here’s my latest blog post demonstrating another Initial Access method, this time using WebDav to bypass Smartscreen, MOTW, a… by Arun.
- RT Aptos Labs: NEW: rust-review - a security review plug-in for Rust, built by @zi0Black of Aptos Labs’ Security Team with Paweł Płatek of @trailof… by Dan Guido.
- RT Init1Security: A really great resource on everything Kerberos #redteam by David.
- New File Format for Initial Access???. “PPKG” files, had a hard time bringing some of the old XML schema for building these properly but finally got e… by David.
- RT Unit 42: RubyGems cryptojacking campaign: 113-plus malicious RubyGems found delivering XMRig miners via trojanized libraries, using delayed persist… by Simone Margaritelli.
- No need to restart! Combat Theater’s “Live UI” let’s you develop and test techniques without the hassle of constantly reloading, making logic and ui c… by 𝙁 𝙀 𝙇 𝙄 𝙓 𝙈.
- RT @vie_pls: JavaScript Sandboxes: A Small and Casual Antipattern Review https://jamvie.net/posts/2026/07/javascript-sandboxes-antipattern-review/ by Gareth Heyes \u2028.
- Love this for the great idea, hate it for what it can do to us by Gergely Kalman.
- Awesome @ArmadinSecurity research from @TheCowboyHacker and @0xc0ffee_ by Brett Hawkins.
- RT Kostas: This is very interesting… Dozens of nearly identical open directories appeared across 154.221.8.0/21, hosted by ASLINE LIMITED in Ho… by hasherezade.
- RT ruikai: Today, I am publishing a preview of Rolling in the Diffs – the LLM epistemology system I’ve developed that allowed me to discover over 60 … by hasherezade.
- RT cr3ghost: Call stack spoofing started in the game hacking community on UnknownCheats in 2018. A single JMP [RBX] gadget to spoof a return address. … by Panos Gkatziroulis.
- RT : https://github.com/califio/publications/tree/main/MADBugs/windows-CVE-2026-50343 by Chihuahua in charge NotMe.
- RT Gio: Super proud of the team for this one. Our engineers have built an incredibly powerful AI algo, and our security researchers are turning its ou… by kmkz.
- RT ɐpnH: This repo contains a PoC for CVE-2023-36003, a critical security feature bypass vulnerability affecting Windows Defender Exploit Protection…. by kmkz.
- RT Or Hiltch: Introducing SharedRoot vulnerability: we recently found and reported several sandbox escape vulnerabilities to @AnthropicAI, and today w… by kmkz.
- Could be useful for your next engagement (GitLab, Mattermost, SonarQube, Nextcloud … and/or other internal apps using PostgresSQL) by kmkz.
- RT SEKTOR7 Institute: Lateral movement with BitLocker DCOM interfaces and COM hijacking. A post and tool by Fabian Mosch (@ShitSecure) Source: https:/… by kmkz.
- RT Sanjay: Found an interesting ORDER BY SQLi during a pentest protected by a Baffin Bay WAF. Used RAG MCP by @0xrudra + Claude CLI (deepseek-v4-pro) … by Spiros Fraganastasis.
- by MalwareHunterTeam.
- RT Steph: Remember crack-js - the idea to have run hashcracking from your broswer with pure JS? With bunch agentic stuff - 330 hash functions were por… by Max.
- RT Two Seven One Three: PE‑OopsSec is a security utility designed to identify and flag common OPSEC mistakes hidden inside PE files Like this: E:\Mov… by Max.
- RT myexploit2600: My @Steel_Con talk on compromising hybrid domains is now live! The talk explains real-world attack paths spanning: Active Directory … by Max.
- Can’t wait to read that upcoming research on how this was bypassed with AI-generated content. by Kuba Gretzky.
- RT XBOW: Earlier this year, XBOW broke into the top 10 of the Microsoft Security Response Center (MSRC) leaderboard as the first and only AI in the ra… by Mathieu Tarral.
- RT Ayoub Faouzi: New blog post after a while: Virtualization Internals Part 5 - KVM Internals: From VM Creation to Guest Execution https://ayoub-faouz… by Mathieu Tarral.
- RT spencer: Great overview here by Nikhil Mittal.
- RT Windows Latest: Microsoft confirms Windows 11 has no place for bloatware ads, says LG is disabling the McAfee pop-up via its monitor app Users repo… by nyxgeek.
- RT Moonlock Lab: 1/ New #macOS bash dropper - 0 hits on VT. Shared by @malwrhunterteam. Self-deletes on launch. Delivers a binary from weekly-up[.]onl… by Patrick Wardle.
- Here’s How an OpenAI Model Went Rogue and Hacked Hugging Face - @HacktronAI https://www.hacktron.ai/blog/here-is-how-openai-model-hacked-huggingface#… by Swissky.
- How harnesses and post-training close the open-weight bug-finding gap - @_vincenzoiozzo https://vincenzoiozzo.com/blog/oss-models-vuln-research by Swissky.
- RT s1r1us: OpenAI and Hugging Face probably won’t tell us exactly what happened anytime soon. So I decided to reconstruct the full exploit chain, fro… by Swissky.
- The Gold Mine Red Teamers Never Touch https://www.abdulmhsblog.com/posts/useingthewindowssourcecode/ by Swissky.
- Oh My Rogue Agent - Tarun Koyalwar https://projectdiscovery.io/blog/oh-my-rogue-agent by Swissky.
- Fully agree with @NielsProvos here. But I’d add the nuance that speed is two-tracked…… 1. We need speed in terms of machine speed response to threa… by Phil Venables.
- I spoke with Lorenzo Franceschi-Bicchierai at TechCrunch about frontier-model verification programs and cyber guardrails. My view is that the current … by Chris Thompson.
- RT jack: the government of india does not like technologies like bitchat and wants it taken down by scriptjunkie (Matt).
- RT Volodymyr Styran 🇺🇦: Two Theories Worth a Cyber Commander’s Time Two theories - cyber persistence and intelligence performance - and what … by thaddeus e. grugq.
- RT Samuel Groß: Last week I did a livestreamed talk on browser security. In case you missed it and are interested, here are the slides: https://saelo… by thaddeus e. grugq.
- RT Zion Leonahenahe Basque: We are approaching perfect binary decompilation, and, crazier still, LLMs may soon be the best decompilers on the planet. … by Lee Chagolla-Christensen.
- GitLab RCE via memory corruption .. so much good research dropping lately by Mike Felch (Stay Ready).
- RT Co11ateral: Certighost (CVE-2026-54121) - AD CS Domain Controller Impersonation Low-privileged domain user can impersonate a Domain Controller via … by Mike Felch (Stay Ready).
- BAKING I had a ton of people ask me about the super cool and badass malware sample my beloved colleague sent me. I also had a ton of people m… by vx-underground.
- He phished girls to get access to their SnapChat to exfiltrate nude photos. He subsequently sold or traded the photos on THE DARK WEB (he just went on… by vx-underground.
- This super ultra mega rare fuck off ultra malware my colleague sent me has a really fancy schmancy anti-VM feature. It is the fanciest I’ve seen to da… by vx-underground.
- RT Kirill Firsov: I heard rumors that an OpenAI model broke into Hugging Face by finding a Squid 0day. I did find Squid 0day RCE, 6 hours of Opus and … by Vincent Yiu.
- RT Ananda Dhakal: We built an AI pentester that scores 92.3% on the XBOW benchmarks …ok, we didn’t “build” anything. It’s the default Codex CLI… by Vincent Yiu.
- Btw, CVE-2026-12537 (crit), forgot to post bout it. Reported earlier this year. Unauthenticated Remote Code Execution in Gemini CLI CI/CD Workflows by Devansh (, ).
- Steam forum ClickFix attacks infect gamers with XMRig cryptominers https://www.bleepingcomputer.com/news/security/steam-forum-clickfix-attacks-infect-… by BleepingComputer.
- Hermes AI agent used to automate attack on Thai Finance Ministry https://www.bleepingcomputer.com/news/security/hermes-ai-agent-used-to-automate-attac… by BleepingComputer.
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-… by BleepingComputer.
- Europol flags 4,340 URLs for removal in ‘The Com’ crackdown https://www.bleepingcomputer.com/news/security/europol-flags-4-340-urls-for-removal-in-the… by BleepingComputer.
- Clop ransomware targets Windchill, FlexPLM in data theft attacks https://www.bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flex… by BleepingComputer.
- RT Christopher Glyer: Brings new meaning to the maxim “move fast and break things” https://www.reuters.com/business/its-ai-agent-spent-days-hacking-… by DebugPrivilege.
- Malicious sites use JavaScript to build malware in browser memory https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-bui… by Nicolas Krassas.
- ShinyHunters data leaks fuel $2,000 sextortion email scam https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion… by Nicolas Krassas.
- HTB: Fries https://0xdf.gitlab.io/2026/07/25/htb-fries.html by Nicolas Krassas.
- CVE-2026 PoC Collection - 128 PoCs covering 84 CVEs https://github.com/XZ1r0/cve-2026-poc-collection/tree/main by Nicolas Krassas.
- DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts https://thehackernews.com/2026/07/devman-raas-portal-centraliz… by Nicolas Krassas.
- A featured Chrome extension “Planet Search” (2M installs) routes every query to the nextgeeker[.]com hijacker network https://malext.io/reports/RogueP… by Nicolas Krassas.
- noz2/roothound: Map your path from a low-priv shell to root - like BloodHound, for local Linux privesc. https://github.com/Noz2/RootHound by Nicolas Krassas.
- RT Yuhang Wu: Re @depthfirstlabs GitLab OJ Spill overview: https://depthfirst.com/gitlab-rce-oj-spill Technical details: https://depthfirst.com/resear… by Nicolas Krassas.
- RT Soroush Dalili: I have created some mechanism in YSoNet and using it AI just added 2 new gadgets (similar to the ones in YSoNet but still new), and… by Nicolas Krassas.
- RT Unit 42: Four evasion techniques deliver stealthy device code phishing: blob URLs evade network analyzers, custom CAPTCHA gates block URL scanners,… by Dave Kennedy.
- RT @TeriRadichel: Revisiting the Bastion Host In Light of AI Agent Escapes A bastion host adds a point of inspection for potential rogue t… by Giuseppe
N3mes1s. - Oh, is going to be fun to patch it, in the meantime you find your way to have time to patch, hope that no one is already exploiting it. by Giuseppe
N3mes1s. - RT Tommy M (TheAnalyst): No, #Trickbot is NOT back. What Fortinet forgot to mention is that the samples they analyzed are known Anchor DNS from 2020. … by Giuseppe
N3mes1s. - RT Mike Takahashi: Excited to finally share this ChatGPT vulnerability with everyone! AgentForger: ChatGPT Cross-Site Agent Forgery 1-Click hijacks Op… by Giuseppe
N3mes1s. - RT Nick Sullivan: If you weren’t aware, I had a small part in helping design TLS 1.3 back in the day. Today, I presented some new work at the TLS work… by SwiftOnSecurity.
- RT Ayush Anand: Most sweep detections chase tool names. Advanced IP Scanner, NetScan, the renamed ones. Wrong layer. One process hitting 254 IPs acros… by SwiftOnSecurity.
- Here’s the link to the extension: https://github.com/winterknife/EVENSTAR/tree/master/ReadKDBGDataBlockJSExt by winterknife.
- Drafted a quick article on how we can use Constrained Decoding to Jailbreak local models. Watching a “forbidden answer” coming through in JSON formatt… by Adam Chester.
- RT AI Security Institute (AISI): Together with the US Center for AI Standards and Innovation (@NIST), we ran evaluations of Kimi K3 focused on its cyb… by Alex Plaskett.
- RT itszn: Our research team (with the help of their agents) did it again! Second v8ctf in flag one week! Entirely separate 0day ARW bug and new 0day h… by Alex Plaskett.
- Why in the world would the White House’s mobile app need permissions or any kind of interaction with (or even reference to) the Chinese tech giant Huawei, whose products are banned from the United Sta.
- RT 0xor0ne: AI-assisted vulnerability research for real-time operating systems (@qkaiser) https://quentinkaiser.be/security/2026/07/18/ia-assisted-vul… by Florian Roth.
- RT Nicolas Krassas: France Exposes Russia’s Secret Cyber Espionage Network https://www.unredacted.info/russia/france-exposes-russias-secret-cyber-espi… by Florian Roth.
- 5 months … by Florian Roth.
- RT torry2: looked into Device Bound Session Credentials (DBSC) now on Windows+Chrome and built a tool to inspect and refresh registered sessions :) su… by Florian Roth.
- RT lazarusholic: “Updated Cyber Threat Actor Naming System” published by @googlecloud. #Neptune https://cloud.google.com/blog/topics/threat-intelligen… by Florian Roth.
- RT Group-IB Global: #Qilin is exploiting a critical Palo Alto VPN vulnerability. But that’s only the entry point. The #ransomware group has also clai… by Florian Roth.
- RT lazarusholic: “Kimsuky 그룹의 외교 관련 종사자 사칭 공격 사례 (PebbleDash, PrxClient)” published by @AhnLab_SecuInfo. #Kimsuky, #Phishing, #PebbleD… by Florian Roth.
- RT OpenAI: Re We recognize there are a lot of questions and speculative details circulating related to the Hugging Face incident. This is an unprecede… by Dave Aitel.
- RT Nicolas Krassas: Pope’s official prayer app commits cardinal sin, leaks 700K+ users’ info https://www.theregister.com/security/2026/07/24/popes-off… by Simone Margaritelli.
- OffsetInspect - PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage https://github.com/warpedatom/OffsetInspect by Panos Gkatziroulis.
- Position independent C2 beacon for the Adaptix Framework with module stomping, malleable C2 profiles, BOF execution, and a Stardust-pattern UDRL loade… by Panos Gkatziroulis.
- beignet - Donut for MacOS, converts darwin/arm64 and darwin/amd64 .dylib files into MacOS PIC shellcode, can be used as a CLI or imported as a Golang … by Panos Gkatziroulis.
- RT 0xor0ne: Analysis of a Chrome V8 untagging vulnerability (CVE-2026-4447) (@kqx_io) https://kqx.io/post/cve-2026-4447/ #infosec by kmkz.
- RT Anderson Nascimento: Re Bug 34197 - elf: Stack canary and pointer guard are recoverable from AT_RANDOM (getauxval) https://sourceware.org/bugzilla/… by kmkz.
- RT KatieMoussouris (she/her/she-ra/she-hulk) : An example of the fall of a security civilization: Cisco collapsing multiple different vulnerab… by kmkz.
- RT Kostas: Yes, CVE-2026-54121 is bad with a public working exploit out now (CertiGhost)… although it’s still worth noting that proper network segme… by Max.
- RT SANS Japan: Microsoft 365のログ、本当にすべて収集できていますか? Unified Audit Logを有効にしているだけでは重要な監査ログが欠落している可能性があり… by Max.
- From Google Ads to Terminal: Dissecting an Apple Support Impersonation Campaign Abusing Claude Share. https:// derivai.substack.com/p/fake-cl aude-code-installer-macsync-malware.
- Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www. accomplish.ai/blog/sharedroot- escaping-claude-cowork-sandbox/.
- Race Against The Patch: The Evolution of Four Exploit Chains in LiteLLM - @starlabs_sg https://starlabs.sg/blog/2026/05-race-against-the-patch-the-evo… by Swissky.
- Backup Operator Privilege Escalation https://www.bordergate.co.uk/backup-operator-privilege-escalation/ by Swissky.
- RT Adel Ka: IMO, we need more security engineers with an SRE mindset. I highly recommend at least skimming Google’s SRE books: https://sre.google/boo… by Phil Venables.
- BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms https:// malext.io/reports/BrainDrain/.
- New issue - #9 - of the free @ PagedOut zine is here! 90 pages of pure technical awesomeness! Please help spread the news Web: https:// pagedout.institute/webview.php ?issue=9&page=1 PDF: https://.
- Looks like the latest edition of Paged Out! is out. This one features an article by yours truly, along with dozens of others: https:// pagedout.institute/download/Pa gedOut_009.pdf.
- RT Jameson Lopp: In the first case of its kind, the U.S. Department of Justice is prosecuting an American for allegedly providing U.S. border authorit… by scriptjunkie (Matt).
- RT Yuhang Wu: We successfully achieved an RCE on GitLab in its default configuration. Historically, most GitLab RCEs have lived in the web or applicat… by ϻг_ϻε.
- RT Josh Parnham: Published a writeup on CVE-2025-24169, a macOS vulnerability which allowed a malicious app to enumerate a user’s saved account data i… by Csaba Fitzl.
- RT Stuart Ashenbrenner 🇺🇸 🇨🇦: One of the most time consuming parts of macOS research is identifying what you’re looking at - AMOS, NovaSte… by Csaba Fitzl.
- RT @BushidoToken: New CTI Resource Announcement! Project ORBITAL (Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) is… by thaddeus e. grugq.
- RT Fabio: Just dropping some cool research for the kernel hackers out there to enjoy this weekend https://www.artiphishell.com/blog/bypasses_and_varia… by thaddeus e. grugq.
- RT Leon Derczynski : I keep saying the strength is in the harness, not the model - because it’s true. Not much use without a harness… by thaddeus e. grugq.
- RT Oliver Prompts: This tool removes LLM censorship with a single click. It’s called Obliteratus. It identifies the exact weights that force a model … by thaddeus e. grugq.
- Apparently Meccha Chameleon people follow me on Telegram. Hello MecchaChameleon malware people living inside my computer, I think overall your strateg… by vx-underground.
- > everyone yappin about this > look inside > goofy ahh batch file > http downloads from ip address > http? not https? what year is it? > steamb.bat > … by vx-underground.
- Massive upgrade to the Aether rule scanning engine! By integrating new filters directly into the rules for Aether to parse and analyze, I’ve mana… by Mr.Z.
- Hackers target US firms in FastJson RCE zero-day attacks https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fastjson-rce-zero-d… by BleepingComputer.
- New Certighost PoC exploit lets attackers hijack Windows domains https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-lets-attack… by BleepingComputer.
- RT shif/tty/mike: Re @singe @BlackHatEvents It’s the default tool for WiFi hacking but there were a few things that bugged me, so I made it better. T… by Aurélien Chalot.
- Arista patches VeloCloud Orchestrator zero-day exploited in attacks https://www.bleepingcomputer.com/news/security/arista-patches-velocloud-orchestrat… by Nicolas Krassas.
- New Dysphoria DDoS botnet spreads to 200k devices worldwide https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spreads-to-200k-d… by Nicolas Krassas.
- Azure VM Command Execution using Third-Party Extensions – Salt Minion https://www.netspi.com/blog/technical-blog/cloud-pentesting/azure-vm-command-ex… by Nicolas Krassas.
- Botnets powered by residential proxy networks are growing https://www.scworld.com/brief/botnets-powered-by-residential-proxy-networks-are-growing by Nicolas Krassas.
- NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai… by Nicolas Krassas.
- MedusaHVNC Trojan Creates Hidden Desktops to Hijack Browsers and Steal Data https://securityaffairs.com/196111/malware/medusahvnc-trojan-creates-hidde… by Nicolas Krassas.
- Online-Enabled Intelligence Recruitment: The Digitization of Traditional Agent Development and Espionage Tradecraft https://krypt3ia.wordpress.com/202… by Nicolas Krassas.
- RT Md Ismail Šojal : First fully AI-written iOS jailbreak on Root SPTM devices (A15+). - 0 lines of human-written code. - SPTM support ad… by Nicolas Krassas.
- Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-… by Nicolas Krassas.
- RT Gadi Evron: Releasing: Post mortem analysis of the Hugging Face incident was written over the weekend by hundreds of CISOs (and reviewed by Hugging… by Nicolas Krassas.
- RT 𝕎𝕠𝕝𝕗 𝕋𝕣𝕒𝕚𝕟𝕖𝕣: LLM 服务指纹识别工具,可识别60多种AI服务,能够在渗透测试、攻击面发现和安全评估期间检测网络上运行的AI… by Nicolas Krassas.
- RT Alon Leviev: My TROOPERS 2026 talk “Confused Recovery: A New Attack Class on Windows Recovery” is live on YouTube! https://www.youtube.com/watch?… by DirectoryRanger.
- The Great Kerberos Ticket Heist (Does PTT work in 2026) https://www.youtube.com/watch?v=s5nd8u4EKFI by DirectoryRanger.
- Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns #DFIR https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-… by DirectoryRanger.
- RT flux: New blog post, it’s been a while! Have you ever wanted to know what HyperGuard protects from NTOSKRNL? I also found a few interesting bits of… by DirectoryRanger.
- RT Enno Rey: Inside Pegasus: The evolution of the world’s most notorious spyware system https://securitylab.amnesty.org/latest/2026/07/inside-pegasus… by DirectoryRanger.
- Update: JFrog just confirmed that Artifactory was part of it https://jfrog.com/blog/jfrog-and-openai-collaboration-on-zero-day-security-findings/ by LiveOverflow.
- Yep, reproduced this with #Pruva almost a month ago. It took a little bit of time it seems for the mass exploitation https://pruva.dev/reproductions/R… by Giuseppe
N3mes1s. - IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains by Lexi DiScola.
- Axon Is Another License Plate Surveillance Company by Bruce Schneier.
- Designing an MCP Server for AI Agents: Why Wrapping Your API Is the Wrong Abstraction by rpepple.
- How we use /goal to find bugs in Patch the Planet.
- The state of vibe-coded app security: my analysis of 549 self-described AI-generated repos (study + raw data) https:// ogbuilds.ai/studies/vibe-coded -security.
- RT Fabian Bader: If you want to hunt for signs of Certighost (CVE-2026-54121) by @h0j3n and @aniqfakhrul in your #XDR environment try this query. 1. E… by Sean Metcalf.
- RT Jiří Vinopal: In this Briefing: The first full reverse engineering of the Windows Defender Boot-Time Removal driver (BTR.sys) Full… by SinSinology.
- RT EZ: For anyone who wants to understand more of the context around the token issues with PIM, see the attached article. Please note the date of the … by SwiftOnSecurity.
- Seems that the trick I used in https:// projectzero.google/2025/01/win dows-bug-class-accessing-trapped-com.html by calling ITypeInfo::CreateInstance cross process has been blocked. Sort of. They’ve “.
- I wrote a little bit about COFF Mixing https://rastamouse.me/coff-mixing/ by Rasta Mouse.
- Designing Patterns to Prevent IDOR https://sevhunt.com/docs/blog/designing-patterns-to-prevent-idor/ by /r/netsec.
- Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/ by /r/netsec.
- How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability https://lavahq.io/research/bmc-exposure-alert by /r/netsec.
- RT Intrusion Truth: https://intrusiontruth.wordpress.com/2026/07/28/turns-out-the-ghost-was-the-pla/ by winterknife.
- RT Intrusion Truth: https://intrusiontruth.wordpress.com/2026/07/27/dear-diary-today-i-found-a-ghost-in-the-network/ by winterknife.
- APT numbers are the most useful threat actor names, but they don’t sell mini figurines of threat actors as well as calling them “superh4xx smooth ki… by Adam Chester.
- Claude Mythos degrades HAWK and developed new exploit for round-reduced AES https://www. anthropic.com/research/discove ring-cryptographic-weaknesses.
- Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs https:// hunt.io/blog/flying-eagle-andr oid-rat-170-servers-night-dragon.
- RT Dawn Song: We developed ExploitGym to evaluate whether AI agents can transform real-world vulnerabilities into working exploits that achieve securi… by Alex Plaskett.
- RT Yarden Shafir: Very quick blog post to start the week: “enhanced session” shares your host clipboard with virtual machines, even if you didn’t copy… by Alex Plaskett.
- RT DirectoryRanger: The New Hotness in Phishing: Device Code Attacks in M365 https://trustedsec.com/blog/the-new-hotness-in-phishing-device-code-attac… by bohops.
- RT Doug Burks: SO-CRATES 3 is LIVE Container for Rapid Analysis of Threats, Evil, and Sus Makes quick work of your pcap, log, and file analysis N… by Chris Sanders.
- Another day, another botnet that pokes fun at my giant fivehead. https://www. bleepingcomputer.com/news/secu rity/new-dysphoria-ddos-botnet-spreads-to-200k-devices-worldwide/ https:// blog.xlab.qianxi.
- RT CTI Traffic: Cato: China-nexus SilverFox hits Japanese industrial manufacturing with ValleyRAT (Winos 4.0), extending beyond its historical Chinese… by Florian Roth.
- RT Smukx.E: Hidden Infrastructure Exposed: @anyrun_app Reveals Hijacked Gov Websites Delivering Malware TLDR:- A deep dive into PhantomEnigma shows ho… by Florian Roth.
- RT blackorbird: About Turla https://github.com/blackorbird/APT_REPORT/blob/master/Turla/Turla-English-CERTFR-2026-CTI-005.pdf by Florian Roth.
- RT Nextron Research : Quick follow-up on the OceanLotus / APT-C-00 campaign from the recent 360 report - the one using disc-image delivery, Analyz… by Florian Roth.
- RT N45HT: “How I Found Open-Source 0-days with an LLM Multi-Agent Workflow” by Hyunseo Shin Hyunseo Shin (se1en) https://blog… by Florian Roth.
- RT Om Patel: UPDATE, ITS WORSE THAN THE CHATS the same thing is happening with shared artifacts. every app, doc, dashboard and tool people published f… by Florian Roth.
- RT @*: Around the Certighost (CVE-2026-54121) disscussions i thought i have to mention that you can stop a lot of bad things with AC CS if you: Chan… by Florian Roth.
- RT sapir federovsky: Everything you need to know about OAuth applications in Azure by @shahardorf , @WEareTROOPERS & I https://www.youtube.com/wa… by Arun.
- RT White Knight Labs: Tiziano Marra published research on CET-compliant callstack spoofing. Thread pool execution, enum callback trampolining across 3… by Arun.
- RT Mohamed Alzhrani: From a normal domain user to Domain Admin, bypassing the SID patch. ESC1 is alive again, under some conditions. MSRC closed it as… by Arun.
- RT Trail of Bits: 858 potential bugs found, 595 awaiting patches, 120 fixes open upstream, 143 merged. Our new Patch the Planet dashboard breaks down … by Dan Guido.
- Measuring LLMs’ Ability to Perform Cryptanalysis by Bruce Schneier.
- RT Nebula Security: Watch us open the camera and uncover the anonymous identity behind Tor browser: We published the writeup for the browser RCE in Io… by Simone Margaritelli.
- RT Nicolas Krassas: Hackers use DNS poisoning on hotel Wi‑Fi to steal Microsoft 365 accounts https://reliaquest.com/blog/threat-spotlight-dns-poisoni… by Simone Margaritelli.
- Hackvertor now highlights non-ascii characters and shows invisible unicode. You can even select a character and it will give you the details about the… by Gareth Heyes \u2028.
- The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-… by Panos Gkatziroulis.
- RT NCV: I created a simple Bash script that automatically downloads and patches several useful Beacon Object Files (BOFs) for @_CobaltStrike. The goal… by Panos Gkatziroulis.
- RT Nikhil Mittal: Stuff that Microsoft has introduced with Copilot Cowork is scary. This is “local browser with Copilot Cowork”. My favorite foothold … by Chihuahua in charge NotMe.
- RT Florian Roth : CertiGhost (CVE-2026-54121) deserves much more attention than it is getting right now, from my point of view. In a common/defaul… by Chihuahua in charge NotMe.
- RT 𝕎𝕠𝕝𝕗 𝕋𝕣𝕒𝕚𝕟𝕖𝕣: Re PDF原件 https://assets.crowdstrike.com/is/content/crowdstrikeinc/Prompt-Injection-Taxonomy-Poster… by Chihuahua in charge NotMe.
- RT Alex Neff: Detect the Certighost with NetExec Thanks to @Xed_sama, the enum_cve module of NetExec will now detect if a host has not been patche… by Chihuahua in charge NotMe.
- Today’s exercise-> one laptop, full EDR/XDR stack: SentinelOne Defender ATP FortiClient EDR + SEKOIA XDR +Intune. (See screenshot) >Full chain through… by kmkz.
- RT Stephen Fewer: We have published our @rapid7 analysis of CVE-2026-16232, the auth bypass in Check Point Security Management Server that was disclos… by kmkz.
- RT The Hacker News: UPDATE - Public PoC exploit released for CVE-2026-42533, chaining an #nginx memory leak and heap overflow to bypass ASLR and … by kmkz.
- RT Swissky: 1-Click GitHub Token Stealing via a VSCode Bug https://blog.ammaraskar.com/github-token-stealing/ by kmkz.
- RT cr3ghost: ESC1 is alive again. Low priv user to Domain Admin on a fully patched AD CS. Enforcement set to 2. The issued cert came back with NO szOI… by kmkz.
- RT Nicolas Krassas: Local Privilege Escalation (LPE) Demo in macOS Tahoe 26.5.1 - PoC Demo https://x.com/everping/status/2081976759776645459 by kmkz.
- RT Marco Grassi: trigger for CVE-2026-43739 (fixed in iOS 26.6) https://gist.github.com/marcograss/6bd611754d497eabfaaafc7cfd21211b by kmkz.
- RT starlabs: AI is changing vulnerability research but not in the way many expect Our intern, Jia Jie, reflects on how AI made Linux kernel 0-day hunt… by kmkz.
- RT Security Joes: Re Full blog: https://securityjoes.com/blog/breaking-the-sandbox-again-bypassing-n8n-s-cve-2026-27577-patch by kmkz.
- RT Florian Hansemann: ‘‘Accelerating EDR Evasion with LLM-Driven Analysis’’ #infosec #pentest #redteam #blueteam https://specterops.io/blog/2026/06/29… by kmkz.
- Long-Lived Vulnerability in Microsoft Secure Boot by Bruce Schneier.
- HTTP Request Smuggling in Hiawatha https:// fenrisk.com/hiawatha-http-smug gling.
- Your House Has an FFmpeg Problem - elttam https://www. elttam.com/blog/your-house-has -an-ffmpeg-problem.
- As someone having found several 0day in Artifactory (e.g. CVE-2024-4142, anonymous to admin priv esc), I’m not surprised by the recent event. by Matthias Kaiser.
- RT torry2: looked into Device Bound Session Credentials (DBSC) now on Windows+Chrome and built a tool to inspect and refresh registered sessions :) su… by Max.
- RT Atsika: I’ve noticed that @bunjavascript has been gaining a lot of traction lately, so I thought it might be interesting to take a look at its offe… by Kuba Gretzky.
- RT Hussein Muhaisen: Paged Out! #9 is live! Read, share, enjoy! https://pagedout.institute/?page=issues.php In case you want to support us, we have a … by Kuba Gretzky.
- Threat actors are already building phishing kits capable of Credential Relay Phishing. The method uses a legitimate background browser to sign in on b… by Kuba Gretzky.
- RT Yarden Shafir: Very quick blog post to start the week: “enhanced session” shares your host clipboard with virtual machines, even if you didn’t copy… by Mathieu Tarral.
- RT Mohamed Alzhrani: From a normal domain user to Domain Admin, bypassing the SID patch. ESC1 is alive again, under some conditions. MSRC closed it as… by Nikhil Mittal.
- RT Doug Burks: SO-CRATES 3 is LIVE Container for Rapid Analysis of Threats, Evil, and Sus Makes quick work of your pcap, log, and file analysis N… by Ring3API 🇺🇦.
- RT Florian Roth : CertiGhost (CVE-2026-54121) deserves much more attention than it is getting right now, from my point of view. In a common/defaul… by Ring3API 🇺🇦.
- Wonder if this is what caused SentinelOne to start flagging Apple system binaries on macOS 26.6 as “suspicious threats” H/T Matt Lee via Link… by Patrick Wardle.
- RT Gergely Kalman: New CVE time: macOS root LPE Patch your systems! by Patrick Wardle.
- macOS 26: the leaf cert. used to sign -binaries is now “macOS Software Signing” (prev. “Software Signing”). Intermediate (“Apple Code Signing Cer… by Patrick Wardle.
- Sometimes simple bugs are the best! “the PasswordManagerBrowserExtensionHelper binary logged the session PIN to the system log via os_log” �… by Patrick Wardle.
Tools and Exploits
Interactive PowerShell TUI for testing Windows execution techniques, COM objects, WMI methods, and LOLBAS techniques in a structured environment.
Reads locked SAM/SYSTEM hives directly from raw NTFS volumes without touching LSASS, then dumps hashes offline. Avoids common EDR detections around credential access.
Updated .NET deserialization exploitation tool with a refreshed SharePoint plugin, new research references, and interactive gadget filtering for faster chain discovery.
Advanced BloodHound analysis tool with improved accuracy for identifying AD attack paths. Built and refined using the GOAD LUDUS lab environment.
Evasion suite for Sliver C2 featuring Crystal Palace loader, sleep masking, in-memory PE execution, and remote process injection with PPID spoofing.
Elastic’s reverse-engineering library adds TELEPUZ string decryption from their research into the new modular malware spreading via ClickFix chains.
CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.
New research and tooling for attacking Azure ML and Amazon SageMaker training infrastructure. Covers reconnaissance through remote code execution on ML training environments.
Rust bindings for IDA Pro updated for the 9.4 SDK. Enables programmatic binary analysis and automation from Rust codebases.
Microsoft releases an official PowerShell framework to deploy and audit AD tier models from a single JSON config. Covers OUs, groups, ACL delegations, GPOs, and LAPS permissions.
More this week (22)
- RT Kirill Firsov: We found a gadget-free RCE in Fastjson 1.2.83 - the final release of the 1.x line, and still one of the most widely-deployed Java JS… by ϻг_ϻε.
- Status of some opensource projects. I reported, Feb 18, https://github.com/horilla/horilla-hr/security/advisories/GHSA-x52c-5hrq-76pq No CVE attache… by Giuseppe
N3mes1s. - RT pwn.ai: Chrome just fixed a very cute URL spoofing vulnearbility on its latest release found by Pwn: CVE-2026-14077 A tall partly above th… by Paulos Yibelo.
- RT Soroush Dalili: YSoNet just leveled up to v2026.7.7 Tighter minification, bugs squashed, and new gadgets incoming soon #infosec #dotnet #redt… by SinSinology.
- Open-source prompt-injection detector, with a real-world attack corpus collected from a live red-team game https://huggingface.co/Bordair/bordair-dete… by /r/netsec.
- Next chapter: Restructuring GitHub’s bug bounty program by Catherine Cassell.
- RT Nextron Research : Two new DPRK npm packages discovered in active supply chain attack: - vectormark v1.0.0 - rollup-packages-polyfill-core… by Florian Roth.
- RT Danus: We are releasing the first blog post today from the week of sandbox escapes! The first finding is found by yours truly! Escaping Antigravity… by Gergely Kalman.
- The case for a cooldown: Why Dependabot now waits before issuing version updates by Carlin Cherry.
- Apple has released an update to XProtect for all macOS https://eclecticlight.co/2026/07/24/apple-has-released-an-update-to-xprotect-for-all-macos-37/ … by Howard Oakley, Eclectic Light Co.
- RT ThreatWire: A public PoC has been released for CVE-2026-60206 affecting Oracle WebLogic Server. The flaw allows a low-privileged network attac… by kmkz.
- RT Merill Fernando: Free and open source http://maester.dev to help with those pesky misconfigurations by Max.
- RT Soroush Dalili: I may release ysonet new version in the coming week. It has several new gadgets and new internals even for old fashion gadgets such… by Piotr Bazydło.
- RT ThreatWire: A public PoC has been released for CVE-2026-49176, a Windows WalletService privilege escalation vulnerability. Full technical deta… by Max.
- RT Vivek | Cybersecurity: NetworkHound - Active Directory Network Topology Analyzer An open-source Active Directory reconnaissance tool that m… by Ring3API 🇺🇦.
- RT Raman_MG: Hey Hunters, just released: Burp Unrestricted MCP Free and open source, for hunters running AI agents against Burp on long engagements. A… by Vincent Yiu.
- RT ThreatWire: A public RCE PoC has been released for GitLab 18.11.3. The flaw allows an authenticated user to execute commands as the git user w… by Vincent Yiu.
- Disrupting supply chain attacks on npm and GitHub Actions by Greg Ose.
- RT Tibo: More opensource goodness. We have just released a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your… by Dave Aitel.
- RT Xander Davies: A few hours before OpenAI posted about LLMs in a cyber eval being responsible for the HF cyberattack, @_robertkirk et al released re… by Simone Margaritelli.
- RT ThreatWire: A public PoC has been released for CVE-2026-53264 affecting the Linux kernel. The vulnerability is a Use-After-Free (UAF) race con… by kmkz.
- RT Vladislav Shevchenko: While waiting for Apple’s next security release announce, I’m publishing the details and PoC for CVE-2026-39868, a kernel m… by kmkz.
