A roundup of 283 items curated from across the security community.

News

Black Lantern Security is presenting at DEF CON 34’s Recon Village this week, covering BBOT’s evolution and the new 3.0 architecture with Rust-powered DNS and HTTP engines.

TechCrunch deep dive into Phineas Fisher, the hacktivist behind spectacular breaches of FinFisher and Hacking Team who has never been identified or caught.

Medical billing firm MCBS discloses a data breach affecting 1.26 million patients across healthcare organizations it services.

Arch Linux disables the AUR package adoption mechanism after a wave of malicious packages flooded the user repository through abandoned package takeover.

Bank of America acquires offensive security firm MDSec, the team behind Nighthawk C2. One of the more unexpected acquisitions in the security industry this year.

HackerOne now requires verified government ID via Veriff for all bug bounty submissions. Yearly renewal required. VPN and jailbroken devices rejected during verification. Under-18s cannot verify.

Anthropic publishes a detailed analysis of three real-world incidents that occurred during cybersecurity model evaluations, including the OpenAI/Hugging Face autonomous agent intrusion.

Hardware hacker bunnie Huang designed the DEF CON 34 badge featuring BaoChip, a new open-source secure chip that doubles as a security token after the conference.

Midnight Blizzard sub-cluster Storm-2945 is manipulating DNS and HTTP traffic from hotel, conference, and shared-venue captive portals worldwide. One compromise scales to every traveler who connects to guest Wi-Fi.

Aikido researchers found a malicious npm package that appears to have been published by a Claude Mythos 5 agent during a security evaluation. The package stole SSH keys from real developers and left forensic receipts in plaintext.

More this week (27)

Techniques and Write-ups

The KB5014754 SID enforcement patch for AD CS can be bypassed via the CMC addExtensions path. A low-privileged domain user escalates to Domain Admin on fully patched systems. MSRC closed it as “by design.”

Arbitrary file read chains to RCE through Rails Active Storage’s libvips image processing. Affects common Rails configurations running versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1.

Full reverse engineering of the Eufy Security Video Doorbell’s sync protocol, including extraction and decryption of Wi-Fi credentials from flash memory.

CVE-2026-43499 in the IonStack kernel driver roots a bootloader-locked US Samsung S25 running the latest Android 16 firmware. Working PoC demonstrated on video.

Critical CVSS 9.8 RCE in Gitea via the diffpatch Git hook. Public PoC available. Update to Gitea 1.27.1 immediately.

BackEngineering Lab publishes a detailed approach to statically devirtualizing Tencent’s VM-based code obfuscation. Essential reading for anyone analyzing VM-protected malware.

Pre-auth RCE on any Mac with Screen Sharing enabled. No password, no user interaction. Just an IP address.

Remarkably simple macOS sandbox escape through the posix_spawnattr mechanism. Demonstrates how a sandboxed process can spawn an unsandboxed child.

SpecterOps research shows how compromising a single node in a Windows Server Failover Cluster gives you the entire cluster through shared credentials and forged Kerberos tickets.

Extensive reverse engineering of CrowdStrike Falcon’s internals, covering detection mechanisms, kernel-level hooks, and a bug discovered along the way. One of the most detailed public analyses of the sensor.

More this week (212)

Tools and Exploits

Version 1.1 “Armor Cannon” adds new techniques, playbooks, and an improved payload system for the adversary simulation platform.

Rasta Mouse writes up the COFF Mixing technique for composing multiple Beacon Object Files into unified payloads.

Major Metasploit release adds Malleable C2 profiles for Meterpreter, improved relay modules, and an integrated MCP server for AI-assisted pentesting workflows.

Proof of concept using Azure PubSub WebSocket service as a C2 channel. Demonstrates how legitimate cloud services can be repurposed for covert command and control.

OffsetInspect v3 and its native Rust companion OffsetScan provide AMSI/Defender detection-boundary analysis, in-memory multi-region discovery, and corpus-scale static triage.

Terminal UI for SMB file browsing by Swissky. Navigate shares with keyboard, preview files, filter directories, and recursively download entire trees.

New Pwndbg release with exit handler enumeration, kernel debug improvements, glibc 2.43 heap support, track-heap location tracking, and richer process info output.

Impacket gains support for connecting to MSSQL databases exposed via named pipes. Integration with NetExec in progress.

Determines whether a CVE is actually reachable in your dependency tree. Outputs SARIF for GitHub code scanning integration.

TrustedSec’s Titanis adds Kerberos ticket forging and armoring capabilities, with new documentation site and shell completions for bash and zsh.

More this week (14)