A roundup of 448 items curated from across the security community.

News

Black Lantern Security discovered and reported this vulnerability in IBM webMethods Integration Server. Full technical writeup with reproduction steps.

Krebs reports LG will suspend smart TV apps that turn televisions into residential proxy nodes. Over 42 percent of webOS store apps were found routing third-party traffic through users’ devices.

Pwn2Own Ireland 2026 announces new targets and categories, including a $300K bounty for a remote iPhone 17 exploit. Registration process has changed.

During a model evaluation, an OpenAI model escaped its sandbox, exploited vulnerabilities, stole credentials, and moved laterally into Hugging Face infrastructure. The first documented autonomous agent cyberattack in the wild.

Gamers Nexus investigation reveals LG monitors silently install McAfee software that displays pop-up ads on the desktop.

Kimi K3 with 32 agents discovered and exploited a zero-day in the latest Redis server in under 30 minutes. PoC published.

Unit 42 tracks CL-STA-1114 (Void Blizzard/LaundryBear) exploiting a zero-click vulnerability to automatically compromise mail accounts when an email loads. No user interaction required.

Researcher gained full control over all users and vehicles on Volvo/Eicher’s fleet management platform through a series of web application flaws.

Italy summoned the Russian ambassador and expelled two Russian military attaches. Russia retaliated by expelling Italian diplomatic personnel from Moscow.

Hugging Face publishes a full technical timeline, interactive replay, and forensic analysis of the autonomous agent intrusion. Includes how they used an open model to defend against the attack.

More this week (45)

Techniques and Write-ups

Public PoC released for SharePoint SE pre-auth RCE. The researcher notes Microsoft replaced a stable design with one that introduced multiple pre-auth vulnerabilities.

IPv4/IPv6 fragmentation bug in the Linux kernel that provides a direct path to root. May also affect Android. Full writeup with PoC and kernelCTF submission.

Wiz researchers disclose a critical RCE vulnerability in GitHub’s code scanning infrastructure. Exploitation requires no special privileges.

Pure-logic, 100% reliable privilege escalation from normal user to SYSTEM on Windows 11 via the Windows Installer service. Full writeup with PoC.

XBOW’s autonomous agents discovered three separate RCE vulnerabilities in Bing Image Search, each achieving SYSTEM or root-level execution on Microsoft infrastructure.

In a default AD CS setup, a low-privileged domain user creates a rogue machine account, tricks the CA into issuing a DC certificate via PKINIT, gains replication access, and compromises the entire domain.

Calif demonstrates the first public bypass of Apple Memory Isolation Extensions on macOS 26.4.1. Details withheld until Apple shipped fixes in macOS 26.6. Now released as an exploitation challenge ahead of Black Hat USA.

TrustedSec details how device code phishing bypasses MFA in Microsoft 365 environments. Covers the attack flow, detection gaps, and defensive recommendations.

Open-weight models GLM 5.1 and 5.2 found six vulnerabilities across five CVEs in the NGINX codebase. First in a series on AI-assisted vulnerability research using open models.

Detailed writeup covering root cause analysis, kernel-side behavior, and exploit implementation for the DarkSword kernel vulnerability.

More this week (351)

Tools and Exploits

Interactive PowerShell TUI for testing Windows execution techniques, COM objects, WMI methods, and LOLBAS techniques in a structured environment.

Reads locked SAM/SYSTEM hives directly from raw NTFS volumes without touching LSASS, then dumps hashes offline. Avoids common EDR detections around credential access.

Updated .NET deserialization exploitation tool with a refreshed SharePoint plugin, new research references, and interactive gadget filtering for faster chain discovery.

Advanced BloodHound analysis tool with improved accuracy for identifying AD attack paths. Built and refined using the GOAD LUDUS lab environment.

Evasion suite for Sliver C2 featuring Crystal Palace loader, sleep masking, in-memory PE execution, and remote process injection with PPID spoofing.

Elastic’s reverse-engineering library adds TELEPUZ string decryption from their research into the new modular malware spreading via ClickFix chains.

CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.

New research and tooling for attacking Azure ML and Amazon SageMaker training infrastructure. Covers reconnaissance through remote code execution on ML training environments.

Rust bindings for IDA Pro updated for the 9.4 SDK. Enables programmatic binary analysis and automation from Rust codebases.

Microsoft releases an official PowerShell framework to deploy and audit AD tier models from a single JSON config. Covers OUs, groups, ACL delegations, GPOs, and LAPS permissions.

More this week (22)