A roundup of 283 items curated from across the security community.
News
Black Lantern Security is presenting at DEF CON 34’s Recon Village this week, covering BBOT’s evolution and the new 3.0 architecture with Rust-powered DNS and HTTP engines.
TechCrunch deep dive into Phineas Fisher, the hacktivist behind spectacular breaches of FinFisher and Hacking Team who has never been identified or caught.
Medical billing firm MCBS discloses a data breach affecting 1.26 million patients across healthcare organizations it services.
Arch Linux disables the AUR package adoption mechanism after a wave of malicious packages flooded the user repository through abandoned package takeover.
Bank of America acquires offensive security firm MDSec, the team behind Nighthawk C2. One of the more unexpected acquisitions in the security industry this year.
HackerOne now requires verified government ID via Veriff for all bug bounty submissions. Yearly renewal required. VPN and jailbroken devices rejected during verification. Under-18s cannot verify.
Anthropic publishes a detailed analysis of three real-world incidents that occurred during cybersecurity model evaluations, including the OpenAI/Hugging Face autonomous agent intrusion.
Hardware hacker bunnie Huang designed the DEF CON 34 badge featuring BaoChip, a new open-source secure chip that doubles as a security token after the conference.
Midnight Blizzard sub-cluster Storm-2945 is manipulating DNS and HTTP traffic from hotel, conference, and shared-venue captive portals worldwide. One compromise scales to every traveler who connects to guest Wi-Fi.
Aikido researchers found a malicious npm package that appears to have been published by a Claude Mythos 5 agent during a security evaluation. The package stole SSH keys from real developers and left forensic receipts in plaintext.
More this week (27)
- RT Burp Suite: Introducing Burp AT. Agentic AI for human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skil… by d4d.
- Over 24,000 exposed server BMCs leak password hash via decades-old flaw https://www.bleepingcomputer.com/news/security/over-24-000-exposed-server-bmcs… by BleepingComputer.
- LeakNet Claims 11TB of Data Stolen in NYC Health + Hospitals Breach https://hackread.com/leaknet-11tb-stolen-nyc-health-hospitals-data-breach/ by Nicolas Krassas.
- How AI is powering business email compromise at scale https://research.eye.security/phishing-as-a-service-inside-two-ai-powered-phishing-kits-that-aut… by /r/netsec.
- RT Bitcoin News: 🇷🇺 RUSSIA CHARGES TELEGRAM FOUNDER PAVEL DUROV WITH AIDING TERRORISM, DUROV RESPONDS WITH MIDDLE FINGER Russia’s FSB has charg… by Simone Margaritelli.
- RT chanze: No Pwn Experience, One Lucky Hunch, and a SAML SSO Bypass: My Pwn2Own Ireland 2025 Journey https://chanzep.github.io/posts/pwn2own-ireland-… by ϻг_ϻε.
- Amgen says cloud data breach exposed patient health, proprietary info https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-expo… by BleepingComputer.
- Hacker uses DeepSeek AI to autonomously attack vulnerable servers https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomous… by BleepingComputer.
- South Korea fines telco giant KT $39 million for customer data breach https://www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-… by BleepingComputer.
- ShinyHunters claims Brinks Home breach, threatens to leak stolen data https://www.bleepingcomputer.com/news/security/shinyhunters-claims-brinks-home-b… by BleepingComputer.
- Analog Devices discloses data breach, says operations unaffected https://www.bleepingcomputer.com/news/security/analog-devices-discloses-data-breach-s… by BleepingComputer.
- Lost amid the news cycles on OpenAI’s disclosure about poorly contained AI models that went on to hack into HuggingFace and other companies was this disclosure from the German health insurer Universa,.
- SplitVPN - 865,336 breached accounts https://haveibeenpwned.com/Breach/SplitVPN by Nicolas Krassas.
- Ad Firm Adform’s Script Compromised for Crypto Theft by Nicolas Krassas.
- RT The Hacker News: The attacker’s own server address never appears on the wire. msaRAT uses Cloudflare to establish the connection, then routes the … by Florian Roth.
- RT Unit 42: We analyzed an AI enabled hacking campaign by a Chinese-speaking threat actor. The adversary targeted infrastructure across seven vulnerab… by Florian Roth.
- RT 0x12 Dark Development: AMSI Write Raid, a perfect alternative to classic AMSI patching - Resolve the remote AmsiScanBuffer address - Allocate and w… by Panos Gkatziroulis.
- RT ʞʞıdɐɔoɥƆ: Disclosed CVE-2026-65883: unauthenticated PHP object injection in Aimy Captcha-Less Form Guard for Joomla. A repeating-key XOR pu… by kmkz.
- RT mpgn: Build an MCP for NetExec for small and large models. The AI agent interacts with NetExec, while the user focuses on the path of compromise �… by Swissky.
- RT moton: CVE-2026-42530: NGINX HTTP/3 RCE PoC Disclosed - https://securityonline.info/nginx-http3-rce-cve-2026-42530/ by Rémi GASCOU (Podalirius).
- Brinks Home Discloses Data Breach as Hackers Leak Files https://www.securityweek.com/brinks-home-discloses-data-breach-as-hackers-leak-files/ by Nicolas Krassas.
- UK government investment arm cops to 40-hour leak of officials’ contact details https://www.theregister.com/security/2026/08/03/uk-government-investme… by Nicolas Krassas.
- PNLD Breach Exposes U.K. Police and Government Contact Details on Dark Web https://thehackernews.com/2026/08/pnld-breach-exposes-uk-police-and.html by Nicolas Krassas.
- Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html by Nicolas Krassas.
- Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys https://securityaffairs.com/196510/data-breach/alleged-zabka-breach-exposes-jira-da… by Nicolas Krassas.
- RT solst/ICE of Astarte: A security company that scans malicious pypi packages was compromised by uhhhh scanning a malicious pypi package, in an env w… by Greg Linares (Laughing Mantis).
- RT Alex Rad: It’s BlackHat/DEF CON week so I’d like to interrupt your regularly scheduled chest drumming feed! Let’s talk about a critical WiFi 7 memo… by Dave Aitel.
Techniques and Write-ups
The KB5014754 SID enforcement patch for AD CS can be bypassed via the CMC addExtensions path. A low-privileged domain user escalates to Domain Admin on fully patched systems. MSRC closed it as “by design.”
Arbitrary file read chains to RCE through Rails Active Storage’s libvips image processing. Affects common Rails configurations running versions prior to 7.2.3.2, 8.0.5.1, and 8.1.3.1.
Full reverse engineering of the Eufy Security Video Doorbell’s sync protocol, including extraction and decryption of Wi-Fi credentials from flash memory.
CVE-2026-43499 in the IonStack kernel driver roots a bootloader-locked US Samsung S25 running the latest Android 16 firmware. Working PoC demonstrated on video.
Critical CVSS 9.8 RCE in Gitea via the diffpatch Git hook. Public PoC available. Update to Gitea 1.27.1 immediately.
BackEngineering Lab publishes a detailed approach to statically devirtualizing Tencent’s VM-based code obfuscation. Essential reading for anyone analyzing VM-protected malware.
Pre-auth RCE on any Mac with Screen Sharing enabled. No password, no user interaction. Just an IP address.
Remarkably simple macOS sandbox escape through the posix_spawnattr mechanism. Demonstrates how a sandboxed process can spawn an unsandboxed child.
SpecterOps research shows how compromising a single node in a Windows Server Failover Cluster gives you the entire cluster through shared credentials and forged Kerberos tickets.
Extensive reverse engineering of CrowdStrike Falcon’s internals, covering detection mechanisms, kernel-level hooks, and a bug discovered along the way. One of the most detailed public analyses of the sensor.
More this week (212)
- Clustered Points of Failure by Garrett Foster.
- 1-Click GitHub Token Stealing via a VSCode Bug https://blog.ammaraskar.com/github-token-stealing/ by Swissky.
- Golang code review notes II - By Zoltan Madarassy and Alex Brown https://www.elttam.com/blog/golang-code-review-notes-ii by Swissky.
- RT Patrick Wardle: Wonder if this is what caused SentinelOne to start flagging Apple system binaries on macOS 26.6 as “suspicious threats” H/… by Csaba Fitzl.
- Hi I’ve uploaded another 150,000 malwares to the internet. I haven’t pushed the update file yet, but the malware is there for you to download and enjo… by vx-underground.
- RT Vitalist International: the duress passcode does not delete the phone. it is not the same as remotely destroying data. it forgets how to decrypt it… by Vincent Yiu.
- RT Coffin: You can also use Shodan’s Certificate Transparency (CT) API to enumerate a target’s subdomains directly from the http://crt.sh database. ht… by Vincent Yiu.
- I was so excited when I reported this one only to find out the goat @HackAndDo beat me to it A fun use case I found for this vuln is that if ssh … by Bad_Jubies.
- I have published my writeup for the Projected File System bug I found earlier this year. Thank you to @zodiacon and @JonnyJohnson_ for their previous … by Bad_Jubies.
- Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-s… by BleepingComputer.
- CubePilot drone software dev hit by DNS hijacking to intercept traffic https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit… by BleepingComputer.
- OpenAI models used Artifactory zero-days to escape to the internet https://www.bleepingcomputer.com/news/security/openai-models-used-artifactory-zero-… by BleepingComputer.
- CISA shares advice on isolating vital systems during cyberattacks https://www.bleepingcomputer.com/news/security/cisa-shares-advice-on-isolating-vital… by BleepingComputer.
- vBulletin fixes critical pre-auth RCE flaw with public exploit https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre-auth-rce-fl… by BleepingComputer.
- FCC Blocks New Foreign-Produced Robots and Power Inverters Over Cyber Risks https://thehackernews.com/2026/07/fcc-blocks-new-foreign-produced-robots.h… by Nicolas Krassas.
- Apple accused of letting fake crypto app steal $1.8 million https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-st… by Nicolas Krassas.
- Sixteen strangers and a shared obfuscator: mapping the wool scene https://neurowinter.com/security/2026/07/28/the-cast-and-crew/ by Nicolas Krassas.
- UKCT Report: “One Network, Two Systems: The Research Security Risks of UK/China University Cyber Partnerships” https://www.nattothoughts.com/p/ukct-re… by Nicolas Krassas.
- Cisco warns of FMC static credential flaw exploited in zero-day attacks https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-crede… by Nicolas Krassas.
- Russian hackers exploit Exchange OWA zero-day for long-term mailbox access https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exch… by Nicolas Krassas.
- Flying Eagle Android RAT source code circulates on Telegram https://www.scworld.com/brief/flying-eagle-android-rat-source-code-circulates-on-telegram by Nicolas Krassas.
- Fraud campaign impersonates Russian companies to steal funds https://www.scworld.com/brief/fraud-campaign-impersonates-russian-companies-to-steal-fund… by Nicolas Krassas.
- HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel https://www.picussecurity.com/resource/blog/hollowgraph-backdoor-turns-microsoft-… by Nicolas Krassas.
- Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth…. by Nicolas Krassas.
- CVE-2026-63077: Critical unauthenticated remote code execution in JetBrains TeamCity https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unau… by Nicolas Krassas.
- Word worm crawls into Copilot, spreads chaos https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588 by Nicolas Krassas.
- Closed models refuse to help researcher swat Linux bug https://www.theregister.com/ai-and-ml/2026/07/29/closed-models-refuse-to-help-researcher-swat-l… by Nicolas Krassas.
- RT Yarden Shafir: Very quick blog post to start the week: “enhanced session” shares your host clipboard with virtual machines, even if you didn’t copy… by DirectoryRanger.
- Random thought: You’ll see more threat actors steal AI creds via backdoored projects/environment variables. Think LLMJacking but farming the auth for … by Nick Frichette.
- contentPolicy: FoR EDucATIONaL PUrPOSeS OnLY : https://github.blog/changelog/2026-07-28-npm-publish-time-malware-scanning-and-dual-use-metadat… by Nick Carr.
- Building secure Uniswap v4 hooks.
- Oh my. A trusted source who enabled Google’s new AI feature for Gmail just received this nudge from the service today, which encouraged him as part of his suggested to-dos list to fall for a cryptocur.
- RT MagicSword: How long would it take you to know if a Volt Typhoon technique ran on your endpoints today? Magic-Atomics runs real adversary technique… by The Haag™.
- RT ARIMLABS: We just released MalwareBench, a new eval for static malware reverse engineering. We set out to answer a deceptively simple question: can… by Giuseppe
N3mes1s. - RT bynario: Apple patched an incredible number of bugs in this July release (26.6). We like our CVEs served with a side of PoC, especially those that … by Giuseppe
N3mes1s. - CVE-2026-5674: PipeWire sandbox escape via malicious library loading in PulseAudio compatibility layer #pruva PulseAudio unix socket pulse-server.c do… by Giuseppe
N3mes1s. - JFrog CVEs, All assigned to OpenAI people. Some of them really interesting. https://docs.jfrog.com/releases/docs/artifactory-self-managed-releases The… by Giuseppe
N3mes1s. - American Being Prosecuted for Wiping His Phone Before Handing It Over to Border Officials by Bruce Schneier.
- The July 2026 Apple Security Update Review by Dustin Childs.
- A couple of teasers from the story: Bitsight found the H96 devices were either relaying residential proxy traffic or participating in ad fraud, but never both at the same time. In fact, they concluded.
- New, by me: Read This Before You Buy That TV Streaming Stick Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming.
- RE: https:// infosec.exchange/@tiraniddo/11 6998263081600563 The patch for this seems to have been back ported to Windows 10 as well, which must mean it’s a real bug in the CreateInstance call. https:.
- RT Fabian Bader: So much to watch, do little time to procrastinate. Have to find a way to do both by Sean Metcalf.
- RT sapir federovsky: Everything you need to know about OAuth applications in Azure by @shahardorf , @WEareTROOPERS & I https://www.youtube.com/wa… by Sean Metcalf.
- And well. Direct code execution is also verified working in case permissions are allowed in e.G. Opencode for bash execution No need to backdoor … by S3cur3Th1sSh1t.
- RT Stephen Fewer: Re PoC for CVE-2026-16232 available here: https://github.com/sfewer-r7/CVE-2026-16232 by SinSinology.
- RT Stephen Fewer: We have published our @rapid7 analysis of CVE-2026-16232, the auth bypass in Check Point Security Management Server that was disclos… by SinSinology.
- Interested in old video game vulnerabilities? Checkout our latest blogpost on Titan Quest : Anniversary Edition by @tomtombinary https://www… by Synacktiv.
- RT S3cur3Th1sSh1t: I successfully trained a small LLM to always include backdoor code into any answer. All code generated will execute attacker define… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- RT Atsika: I’ve noticed that @bunjavascript has been gaining a lot of traction lately, so I thought it might be interesting to take a look at its offe… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- Okay, there’s a Reddit thread about this scam. Apparently a lot of people are falling for this. It appears these messages may have abused some email sending trust relationships or credentials, because.
- KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2she… by /r/netsec.
- Detection and Enforcement for Endpoint AI Agents https://research.perplexity.ai/articles/securing-agents-across-perplexity%E2%80%99s-client-endpoints-… by /r/netsec.
- HTTP Request Smuggling in Hiawatha https://fenrisk.com/hiawatha-http-smuggling by /r/netsec.
- Your House Has an FFmpeg Problem - elttam https://www.elttam.com/blog/your-house-has-an-ffmpeg-problem by /r/netsec.
- Claude Mythos degrades HAWK and developed new exploit for round-reduced AES https://www.anthropic.com/research/discovering-cryptographic-weaknesses by /r/netsec.
- Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs https://hunt.io/blog/flying-eagle-android-… by /r/netsec.
- This is dope AF! Didn’t think the research would go far, but glad that it started a good conversation. Thanks @danonit and @riskybiz. @HackingLZ and @… by Adam Chester.
- Started tracking the new mini-articles I’m posting to socials on my blog at https://blog.xpnsec.com/articles Hopefully helps to keep track of what wa… by Adam Chester.
- RT Nextron Research : Linux PAM remains one of the highest-value persistence points on Linux and it’s still surprisingly under-monitored. We recen… by Florian Roth.
- RT JFrog Security: CVSS 10.0, but the evidence doesn’t add up. CVE-2026-51302 in SQLite claims critical impact, but: The supplied PoC does not repro… by Florian Roth.
- RT Nextron Research : Our artifact scanner found a malicious ELF in npm package “streak-metricazbd”. Importing it attempts to launch “REDSHEL… by Florian Roth.
- You may want to update your YARA because Victor shipped some new releases and fixed several bugs https://github.com/VirusTotal/yara/releases by Florian Roth.
- RT Is Now on VT!: Sample is now on VT! Hash: 04d4a9fbb32e967200eb98be014ca914a03bfa6b Actor name: UTA0533 Comment: In early July 2026, Vol… by Florian Roth.
- RT Faruk Sener: Update: the Chinese threat actor behind the #Hermes + #CyberStrikeAI + #SliverC2 exploitation node has shifted operations to a new ser… by Florian Roth.
- RT Nikhil Mittal: Stuff that Microsoft has introduced with Copilot Cowork is scary. This is “local browser with Copilot Cowork”. My favorite foothold … by Florian Roth.
- RT Francesco Piccoli: It is time for the security industry to graduate from CyberGym Level 1. CyberGym has been one of the most impactful cybersecurit… by Dave Aitel.
- RT Matthew Green: In case you missed the previous thread, I wrote up a short blog post giving my thoughts on the new Anthropic cryptanalysis results a… by Dave Aitel.
- RT Hamid Kashfi: Check @AleeAmini ’s post. He has done a remarkable job of analyzing samples from last year’s wipe of Iranian banks. I briefly wrote a… by Dave Aitel.
- RT CERT-FR: CERTFR-2026-AVI-0939: Multiples vulnérabilités dans Samba https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0939/ by Dave Aitel.
- RT Cyber_OSINT: AtlasRAT is a Windows-based remote access malware featuring a four-stage in-memory loader chain starting from a Delphi-dropped disguis… by Arun.
- RT TheRealClarity: As promised, DarkSword Kernel Exploit writeup is now live at https://therealclarity.github.io/blog/clearsword/ This goes over the r… by Dominic Chell.
- “But over time, the Dreadnode team began to see self-improvement with the blue team. The agents started reasoning backward after an attack to better u… by dreadnode.
- Can you prompt away cheating? New research from the Dreadnode crew presents a controlled prompt-ablation study to answer this very question. 23 tasks,… by dreadnode.
- RT Ping: Two of my bugs got fixed in Apple’s July 2026 macOS updates. The one I’d point to is #CVE-2026-43749, a local privilege escalation, unprivile… by Simone Margaritelli.
- RT PagedOut: This wonderful wallpaper and the Issue #9 cover were created by Vasyl/Joker^NAH^TRSI. Both this and other wallpapers, as well as Issue #9… by Gynvael Coldwind.
- RT @bytecodevm: A reverse-engineering walkthrough of SakDriver, a Windows kernel-mode rootkit first mistaken for a Cobalt Strike Beacon. It… by hasherezade.
- RT Eugene Kaspersky: Here’s some research into new malware used by the Mirage Kitten APT, which is targeting the aerospace, aviation, defense, and te… by hasherezade.
- RT cr3ghost: Over 90 binary exploitation challenges with detailed writeups. From your first buffer overflow to House of Orange. All free. All open sou… by hasherezade.
- https://intrusiontruth.wordpress.com/2026/07/28/turns-out-the-ghost-was-the-pla/ by Intrusion Truth.
- New article drops next week. Until then, here’s a recap of the July posts in case you missed them. 1⃣ https://ipurple.team/2026/07/13/amsi-prov… by Panos Gkatziroulis.
- EAA - a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and … by Panos Gkatziroulis.
- Facial Recognition at Madison Square Garden by Bruce Schneier.
- RT 0xor0ne: CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox https://voidsec.com/cve-2026-40369-browser-sandbox-escape/ #infosec by kmkz.
- RT Nebula Security: We’ve open-sourced one-click Docker setups and full exploits for Nginx-{PoolSlip, QuicBurst}, both with remote ASLR bypasses. Try… by kmkz.
- RT Stephen Fewer: we now have a (draft) @metasploit exploit module in the queue for CVE-2026-16232, leveraging the authentication bypass for RCE again… by kmkz.
- RT Smukx.E: Analysis of SakDriver, an advanced kernel driver rootkit that blinds Windows defenses by hooking ETW/CKCL, hiding network ports, and bypas… by kmkz.
- Aaand chained with the CVE-2026-39980 (no public sploit… at least since now) -> preauth root rce with 2 vulns on OpenCTI instance . Another day, ano… by kmkz.
- weaponized + exploited, works like a charm :-* by kmkz.
- RT Quang Vo: Turn out there are heaps of interesting stuffs you can do with Chrome Debugging ( CDP ). From a Red teaming perspective, you can totally … by kmkz.
- RT ZYPHER: Jailbreaking Opus 5 is incredibly easy. You do not need iteration after iteration to find a vulnerability. After these two conditions are m… by Spiros Fraganastasis.
- RT 0x12 Dark Development: Crystal Palace: Changing How You Build Loaders New Medium post! https://medium.com/@s12deff/crystal-palace-the-linker-changi… by Max.
- RT Lsec: I wrote a short blogpost about a technique I found a while ago, executing DCSync attack entirely form the memory of a Windows host using C# a… by Max.
- RT Matthew Green: A few people have asked about the Anthropic Hawk and AES cryptanalysis results. The top-level answer is: It’s very impressive. Thre… by Max.
- RT : This seems handy. Windows agent in Powershell 5.1 that loads C# in memory. No admin needed. Linux server (Go) –route 10.10.10.0/24 –redirec… by Max.
- Anthropic’s Opus 5 Is Better at Resisting Prompt Injection by Bruce Schneier.
- Browser Computer Use in NEO by Nuclei by ProjectDiscovery.
- Enter the WasmForge: Compiling Sliver into WebAssembly - Michael Weber https://www.praetorian.com/blog/wasmforge-sliver-webassembly/ by Swissky.
- GAP - Ghost Anchor Persistence: Fileless Extension Persistence in Chromium Browsers - fir3n0x https://fir3n0x.github.io/posts/GAP-Ghost-Anchor-Persist… by Swissky.
- ESC8s and Where to Find Them - Abdul Mhanni https://www.abdulmhsblog.com/posts/esc8andfindingwebenrollmentendpoints/ by Swissky.
- RT Nick Percoco: Something serious and horrible just happened to people with @COLDCARDwallet wallets. A long-standing firmware bug made the seed phras… by scriptjunkie (Matt).
- RT Yuval Avrahami: We (+@liormama) gained full access to EVERY database on Azure’s flagship DB service And all we needed was a single key Th… by scriptjunkie (Matt).
- RT Calif: Fascinating: Three years ago, we published a generic privilege escalation technique affecting AWS. Last week, OpenAI agent used this techniq… by scriptjunkie (Matt).
- RT Daily CyberSecurity: Discover the critical Fastjson RCE CVE-2026-16723 vulnerability. Learn how attackers exploit Spring Boot applications and find… by ϻг_ϻε.
- RT Objective-See Foundation: We’re live! #OFTW v4 is now streaming live on our YouTube channel: https://www.youtube.com/channel/UCQycc8VDhHuNkZlK… by Csaba Fitzl.
- RT @mikko: Re This is amazing: “Claude found a document that told employees to install a Python package from PyPI that did not actually exist. So, Cla… by thaddeus e. grugq.
- RT 𝚑𝚎𝚗𝚔 𝚟𝚊𝚗 𝚎𝚜𝚜: Tonight I typed just one sentence into Google Earth and put refugees near the Mexican border. Then I pl… by thaddeus e. grugq.
- RT David Wong: HAWK team withdrawing their submission from the NIST competition after Anthropic broke the scheme. I have a blogpost called “AI is brea… by thaddeus e. grugq.
- RT Zion Leonahenahe Basque: I’d like to introduce Kuna, a new Rust-based decompiler that explores a highly experimental direction: self-refining decom… by Lee Chagolla-Christensen.
- RT pilvar (Philippe Dourassov): We added DeepSeek Flash v4 on our cybersecurity benchmark. It’s VERY strong. - It found 24 of 32 CVEs at least once, g… by Vincent Yiu.
- RT Rob Fuller: Anyone else feel like Hugging Face is setting the bar high for Red Team / Incident Response reports? :P https://huggingface.co/blog/age… by Vincent Yiu.
- RT Jonny Johnson: AI Agents have quickly become a part of everyday workflows, and newer features seem to be biased towards convivence vs security. The… by Max Harley.
- Wii U fans thought they had it rough when the servers shut down a few years ago, but it turns out its not over. A popular emulator Cemu recently had i… by Black Lantern Security (BLSOPS).
- CISA warns of cyberattacks disrupting U.S. water utilities https://www.bleepingcomputer.com/news/security/cisa-warns-of-cyberattacks-disrupting-us-wat… by BleepingComputer.
- Claude uploaded malware to PyPI in Anthropic’s botched test - @Ax_Sharma https://www.bleepingcomputer.com/news/security/claude-uploaded-malware-to-pyp… by BleepingComputer.
- Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers https://www.bleepingcomputer.com/news/security/amazon-links-debug-chalk-npm… by BleepingComputer.
- Google says AI helped Chrome fix 1,072 security bugs in two releases https://www.bleepingcomputer.com/news/google/google-says-ai-helped-chrome-fix-1-0… by BleepingComputer.
- Microsoft Teams vishing attacks lead to Chaos ransomware attacks https://www.bleepingcomputer.com/news/security/microsoft-teams-vishing-attacks-lead-t… by BleepingComputer.
- Counteroffensive AI: Pwning AI Pentesters https://www.youtube.com/watch?v=tP6n42NJ9KE by Nicolas Krassas.
- Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.h… by Nicolas Krassas.
- Suspected Chinese-Speaking Hackers Target Central Asian Governments With OctLurk and SilkLurk https://thehackernews.com/2026/08/suspected-chinese-spea… by Nicolas Krassas.
- HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm https://thehackernews.com/2026/07/hollowframe-loader-deploys-matry… by Nicolas Krassas.
- RT International Cyber Digest: Meta’s smart glasses could be banned in Germany and the rest of the EU. Hamburg data protection commissioner Thomas… by Nicolas Krassas.
- RT Karl: Our Troopers 26 talk “Modern Adventures in Azure Privilege Escalation” is now online. Thomas and I have an associated blog and resources in t… by DirectoryRanger.
- RT Enno Rey: Your Android Bluetooth Traffic Captures Should Be Live, on @Insinuator via @twillnix https://insinuator.net/2026/07/your-android-bluetoot… by DirectoryRanger.
- I understand the purpose behind this is to curb junk/spam vuln submissions, but I don’t think increasing friction between researchers and submitting … by Nick Frichette.
- Additional Midnight Blizzard IOC: statistic-g[.]com DNS pivot from referenced 107.189.26[.]194 in @msftsecurity blog and shared nameservers: ns1.domai… by Lloyd Davies.
- Get a file descriptor to an unlinked read/write file in bash without spawning a new process: history -c fc -e ’exec 5<>’ Now /dev/fd/5 is available fo… by Stuart.
- RT KEVIntel: These are the different paths we’ve seen in wp2shell exploitation attempts: /wp-json/batch/v1 /?rest_route=/batch/v1 /index.php?rest_rout… by Giuseppe
N3mes1s. - RT Fletcher Davis: Gonna start dropping research ideas I’ve started, but haven’t finished. Hopefully this inspires others to dig deeper and find some … by Octoberfest7.
- RT James Kettle: In “Can AI Do Novel Security Research?” I’ll share: - A research-machine blueprint for AI enthusiasts - Clearly defined AI fail-point… by PortSwigger Research.
- RT Tech Brandon: For the love of God make this default behavior… Did AD teach us nothing?!?! by Sean Metcalf.
- RT Josh Cook | Microsoft MVP: Microsoft just gave admins a domain blocklist for Copilot web grounding. Up to 1,000 websites can now be excluded from M… by Sean Metcalf.
- RT Chaitanya: new article: https://fuzzing.science/the-reverse-engineers-guide-to-mechanistic-interpretability/ I wrote a reverse engineer’s introduc… by SinSinology.
- RT Pixis: When I saw the CVE-2025-29969 fix (by @safebreach), I knew there was more to it. It’s not as critical as it seems, but it was fun trying to … by SkelSec.
- Building the First Public Linux UEFI Bootkit Framework https://x.com/i/broadcasts/1jGXggrgqDOKZ by Stephen Sims.
- RT Merill Fernando: Re For the longest time Azure AD/Entra ID didn’t support nesting. In fact M365 Groups still don’t support nesting. There were many… by SwiftOnSecurity.
- RT FBI Cyber Division: FBI PSA: Malicious Cyber Actors Targeting Water and Wastewater Sector PLCs The FBI warns that malicious cyber actors are c… by SwitHak ().
- cool paper. fake chain of thought is rly clever. https://www.technologyreview.com/2026/07/30/1140927/a-fundamental-flaw-leaves-llms-vulnerable-to-atta… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- MDSec acquired by BofA and Metasploit is getting Malleable C2. What a day. by Rasta Mouse.
- frontier class vulnerabilities: it gets worse before it (maybe) gets better https://shubs.io/frontier-class-vulnerabilities-it-gets-worse-before-it-ma… by /r/netsec.
- Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldc… by /r/netsec.
- Deterministic Runtime Bounds for Autonomous AI Agents at the C-ABI Syscall Layer https://drive.google.com/file/d/1PTXugwbuqKvw1Eo4_pul-Z3v–dCFJrD/vie… by /r/netsec.
- RT Tim Blazytko: Thanks to @vmray for hosting today’s webinar on agentic malware analysis! We covered tool-driven RE workflows, local LLMs, guardrails… by winterknife.
- New research paper By Daniel Wilkinson and Chris Anley just dropped! A Preliminary Investigation Into Interpretable Adversarial Attacks Through Featur… by Alex Plaskett.
- Game cheat devs are way ahead of most red team operators by 0xBB.
- So this is fun, Nielsen sends out letters with their paid TV/radio survey, which tell you to go to radiotvstudy dot com/survey. I accidentally typed radiotvsurvey dot com, which redirects to a page th.
- the LLM cl0wns wasted no time tearing apart navi_the_clown and prepared some fresh sl0p for your weekend, enjoy! https://warez.sl0p.foo/a… by blasty.
- RT Smukx.E: Position independent Code Crash course by Raphael Mudge. This course will deep dive into Pic basics, understanding COFF, debugging PIC cod… by bohops.
- RT AnMioLink: #WHCP #WHQL signed kernel reflective PE loader (rootkit stealer) is targeting WeGame players and steal credentials. SHA1: 5fdc38f30fefcd… by Florian Roth.
- RT Smukx.E: In this research, I turn Chrome Remote Desktop into a complete red team scenario that can be used for monitoring and even leads to spying…. by Florian Roth.
- RT matteyeux: I built a Binary Ninja diffing tool that lets you visualize differences directly in Binary Ninja, with support for multiple Intermediate… by Dave Aitel.
- RT Dino A. Dai Zovi: Important to note that all of those fixed vulnerabilities were previously latent vulnerabilities in what is also clearly the mo… by Dave Aitel.
- Was interesting research on these files #redteam by David.
- RT Clandestine: GitHub - ricardojoserf/AddUser-SAMR: Create local administrators with the SAMR API (lowest-level technique). Implemented in C#, Crysta… by Chihuahua in charge NotMe.
- RT : This is like ThreatCheck /DefenderCheck and AMSItrigger but way more comprehensive. by Chihuahua in charge NotMe.
- RT Ridgeline Cyber: The audit log query you shouldn’t forget to run: AuditLogs | where TimeGenerated > ago(30d) | where OperationName in ( “Consent to… by Chihuahua in charge NotMe.
- RT Murray: I have no idea how I missed the “IsExchangeCloudManaged” announcements (if there were any), but if you’re an environment that has been forc… by Chihuahua in charge NotMe.
- RT Clandestine: Escaping Linux Sandboxes via PipeWire (CVE-2026-5674) · Embrace The Red https://embracethered.com/blog/posts/2026/pipewire-flatpak-li… by kmkz.
- RT LazyTitan: I discovered CVE-2026-67599, an OS Command Injection in ClearOS’s Log Viewer (CVSS 7.2). Authenticated users can chain it to full root v… by kmkz.
- RT Horizon3.ai: We discovered a new vulnerability in Cisco Secure Firewall Management Center that’s already being actively exploited. Rapid Respo… by kmkz.
- RT Stephen Fewer: Metasploit coverage for the new Ruby on Rails Active Storage via libvips RCE (CVE-2026-66066) from @_CryptoCat https://github.c… by kmkz.
- RT daem0nc0re: For internal education, I wrote a code to get SYSTEM shell with service creation method. By specfying local admin credentials, it allow… by kmkz.
- RT st8le̤̤̤̤̤̤̤̤̤̤ss: Certighost (CVE-2026-54121) An Active Directory Certificate Services (AD CS) vulnerability that allowed a low-privileg… by kmkz.
- RT Kostas: Proofpoint published research on OWAReaper, a browser implant exploiting CVE-2026-42897 in Outlook Web Access. What stands out is that ever… by kmkz.
- Jellyfin remote code execution: Inconsistent validation leads to argument injection - Paul Gerste - @SonarSource https://www.sonarsource.com/blog/jell… by Swissky.
- RT Alex Neff: A new module just got merged into NetExec: rclone Rclone is a popular tool for connecting and synchronizing data to cloud services. … by Swissky.
- Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp - Sai Likhith https://www.stepsecurity.io/blog/binding-gyp-npm-supply-chain-attack… by Swissky.
- lol, not sure if this is by @CTFtime , but people are injecting prompt injections in ctftime archived write-ups with instructions to exfiltrate enviro… by ruikai.
- RT Vivek | Cybersecurity: ADR: Agentic AI Detection & Response Framework Building or securing AI agents in enterprise environments? ADR (Agentic … by Vincent Yiu.
- RT Kostas: Earlier today, I spent a lot of time investigating a widespread issue involving machines crashing or becoming completely unresponsive. Imme… by Bobby Cooke.
- RT tetsuo: Built an educational browser lab for buffer overflows with Grok. • 10 labs • IDA-style disasm + graph • gdb (breakpoints, stepi, context… by sailay(valen).
- Had a great time with @midnightbluelab training us on all the things RF and finally being able to use one of the manf keys to get past keeloq! Also I … by AndrewMohawk⁽ⁿᵘˡˡ⁾ 𝓲𝓷 𝓿𝓮𝓰𝓪𝓼.
- COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-lin… by BleepingComputer.
- Cruising for Shells in Flowise - elttam https://www.elttam.com/blog/cruising-for-shells-in-flowise by Nicolas Krassas.
- RT International Cyber Digest: The slopocalypse is real. MITRE published a critical SQLite vulnerability with a CVSS of 10.0 that does not exist…. by Nicolas Krassas.
- Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-h… by Nicolas Krassas.
- US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States https://www.securityweek.com/us-water-cyberattacks-extend-beyond-minnesota-to… by Nicolas Krassas.
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-co… by Nicolas Krassas.
- Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-… by Nicolas Krassas.
- RCE on MariaDB, chaining the user->root for a full 0day. https://github.com/dinosn/mariadb-13-rce-lab by Nicolas Krassas.
- Sharing a privilege escalation for MariaDB versions 13.0.1, 11.4.12, 10.11.18, and 10.6.27. Any user -> root in one line. Found through raptor-loop-hu… by Nicolas Krassas.
- ConfigManBearPig 2.0 – Things Are Getting Cereal by Chris Thompson.
- Metasploit 6.5 shipped Malleable C2 support for all current Meterpreter payloads - same profile format you already know, now shaping Meterpreter’s HTTP(S) traffic. See it in action: https:// youtu.be/.
- Looks like CyberNwes had released their # DefCon Documentary! “For the first time in over a decade since the founders’ original documentary, Cybernews was granted unprecedented behind-the-scenes acces.
- And the biggest suggestion is coming from @discourse team as well > The defence in depth strategy we opted for is to stop running image processing lib… by Giuseppe
N3mes1s. - Really great read, when you have instruments that can solve simple problems faster, you focus on harder ones. by Giuseppe
N3mes1s. - https:// textslashplain.com/2026/08/03/ authenticode-and-uac/.
- Before the first prompt: Code execution paths in trusted coding-agent projects https:// securitylabs.datadoghq.com/art icles/coding-agent-project-trust-code-execution-before-first-prompt/.
- RT Merill Fernando: Entra Conditional Access gotcha from @andrescanello Selecting every device platform ≠ “Any device.” An attacker can spoof … by SwiftOnSecurity.
- RT Huntress: Critical N-able N-central Vulnerability and Active Exploitation: Update. Read more: https://www.huntress.com/blog/n-able-vulnerability-ex… by SwitHak ().
- Pre-auth macOS RCE on machines with Screen Sharing enabled https://warez.sl0p.foo/apple-screensharing-rce/ by Wojciech Reguła.
- Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category https://hego.red/jackpot by /r/netsec.
- Before the first prompt: Code execution paths in trusted coding-agent projects https://securitylabs.datadoghq.com/articles/coding-agent-project-trust-… by /r/netsec.
- SQLite Critical CVEs or LLM Slop? https://research.jfrog.com/post/sqlite-critical-cves-or-llm-slops/ by /r/netsec.
- The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog https://www.msecops.de/blog/posts/backdoored-llms/ by /r/netsec.
- My PoC exploit for CVE-2026-31695 in the Linux kernel is ready I managed to make it absolutely stable on Fedora 44 Server despite an elusive r… by Alexander Popov.
- I recently updated “The Ultimate WDAC Bypass List” to include TextTransform.exe as well as a few undocumented placeholder entries (despite my personal… by bohops.
- Code Execution via Provisioning Packages https:// ipurple.team/2026/08/04/provis ioning-packages/.
- RT Lukasz Olejnik: China-linked hackers used Claude Code and DeepSeek as a cyberattack AI team. DeepSeek planned exploits and adapted when attacks fai… by Florian Roth.
- RT Nextron Research : Our artifact scanner found a known #PolinRider payload in a new Chrome extension, “pacbinlicgenenkelgfngadgpghfjjcl”: 1… by Florian Roth.
- RT st8le̤̤̤̤̤̤̤̤̤̤ss: CVE-2026-60206 | CVSS 9.9 Oracle WebLogic SAML Auth Bypass PoC https://github.com/imbas007/POC-CVE-2026-60206 by Florian Roth.
- RT Yarden Shafir: Re @april_ivyyy If you’re asking about Windows, this talk I gave last year could be relevant. The specific examples I give here have… by Daax.
- RT @ryvaneai: New on the journal: MCP Tool Poisoning Attacks, demonstrated end to end. Four runnable demos (description injection, tool sha… by Arun.
- RT MSec Operations: New Blogpost regarding to “Backdooring Open-Weight Models” just published by @ShitSecure: https://www.msecops.de/blog/posts/backdo… by Arun.
- “Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI by Nick Biasini.
- Some Claude Chats Are Searchable on Google by Bruce Schneier.
- HEVD: From Stack Overflows to Modern Pool Grooming https:// sibouzitoun.tech/labs/from-sta ck-overflows-to-modern-pool-grooming/.
- 93% of agent permission prompts get accepted without edit. The Hugging Face intrusion took 17,600 actions. How many of those actions would you have re… by dreadnode.
- Amazing LPE, love the auth.db target by Gergely Kalman.
- RT ippsec: Sometimes I feel silly for not knowing basic things - I always thought etc/group was the only file that had group memberships and when remo… by Gergely Kalman.
- RT Frank Wu: IonStack Blog Series: Part I (Firefox SpiderMonkey JIT RCE): https://nebusec.ai/research/ionstack-part-1-cve-2026-10702/ Part II (GhostLo… by h0mbre.
Tools and Exploits
Version 1.1 “Armor Cannon” adds new techniques, playbooks, and an improved payload system for the adversary simulation platform.
Rasta Mouse writes up the COFF Mixing technique for composing multiple Beacon Object Files into unified payloads.
Major Metasploit release adds Malleable C2 profiles for Meterpreter, improved relay modules, and an integrated MCP server for AI-assisted pentesting workflows.
Proof of concept using Azure PubSub WebSocket service as a C2 channel. Demonstrates how legitimate cloud services can be repurposed for covert command and control.
OffsetInspect v3 and its native Rust companion OffsetScan provide AMSI/Defender detection-boundary analysis, in-memory multi-region discovery, and corpus-scale static triage.
Terminal UI for SMB file browsing by Swissky. Navigate shares with keyboard, preview files, filter directories, and recursively download entire trees.
New Pwndbg release with exit handler enumeration, kernel debug improvements, glibc 2.43 heap support, track-heap location tracking, and richer process info output.
Impacket gains support for connecting to MSSQL databases exposed via named pipes. Integration with NetExec in progress.
Determines whether a CVE is actually reachable in your dependency tree. Outputs SARIF for GitHub code scanning integration.
TrustedSec’s Titanis adds Kerberos ticket forging and armoring capabilities, with new documentation site and shell completions for bash and zsh.
More this week (14)
- RT Artur Marzano: ldapx v1.3.0 just dropped Now with active decryption of security layers on top of LDAP, working with ADExplorer and pretty much … by Rémi GASCOU (Podalirius).
- RT Tibo: More opensource goodness. We have just released a CLI and TypeScript SDK for finding, validating, and fixing security vulnerabilities in your… by Dave Kennedy.
- RT Ollie Whitehouse: At the @NCSC have just released a blog ‘Making forensic observability the norm for network devices’ - including how our guidance … by Dave Aitel.
- Back from mission, I released the exploit I used (it was really helpful) for #Apache Tika XFA XXE exposed through #Elasticsearch’s attachment ingest … by kmkz.
- RT Nicolas Krassas: Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass https://thehackernews.com/2026/07/rapid7-releases… by kmkz.
- RT Soroush Dalili: YSoNet v2026.7.9 is out 31 → 50 gadgets 54 → 88 variants 118 → 235 gadget/serializer combinations across 17 serializers �… by Matthias Kaiser.
- RT ThreatWire: A public PoC has been released for CVE-2026-57239 affecting Foxit PDF Reader and Foxit PDF Editor The flaw allows a local privileg… by Rémi GASCOU (Podalirius).
- RT Greg Lesnewich: So remember last week when we said we hadn’t see TA488/Laundry Bear/Void since Feb? Well… We kinda lied Day before the release, … by thaddeus e. grugq.
- RT Soroush Dalili: YSoNet v2026.7.9 is out 31 → 50 gadgets 54 → 88 variants 118 → 235 gadget/serializer combinations across 17 serializers �… by James .
- RT Zero Day Engineering: VMware just released a critical security update for ESXi hypervisor suite (VMSA-2026-0006). Two attack vectors: 1. Remot… by Giuseppe
N3mes1s. - RT Vivek | Cybersecurity: Vigil365 - Self-Hosted Microsoft 365 Security Dashboard An open-source dashboard that centralizes Microsoft 365 securi… by bohops.
- Screenlogger 0.1.4 adds optional synchronized multi-display capture. https://github.com/radkawar/screenlogger/releases/tag/v0.1.4 by Rad.
- Releasing PLATINUMPICK, a Windows kernel-mode shellcode development framework written in C++20. https://github.com/winterknife/PLATINUMPICK by winterknife.
- RT Unit 42: Adversaries are targeting the macOS developer community through open-source repositories. The latest XCSSET variant spreads by injecting c… by Florian Roth.
