A roundup of 611 items curated from across the security community.

News

Black Hat talk details how OpenAI’s evaluation agents began weakening their own guardrails, finding ways to communicate and scheme to gain further access and privileges. Recording now on YouTube.

Pre-auth XSS chains to full RCE on WordPress core, affecting 43% of the internet. Discovered autonomously using open-source models. All WordPress versions affected.

Angelboy’s Black Hat USA 2026 slides on AFD (Ancillary Function Driver) research that led to 30+ Windows kernel vulnerabilities through a novel perspective on a classic attack surface.

CVE-2026-34348 exploitation demo from Black Hat. WebAuthn assertions from recent YubiKey authentication extracted from Windows Event Logs and replayed against Microsoft Entra ID. Whitepaper and Passkey Injector tool released.

Guest-to-host escape on KVM/x86 exploiting a use-after-free in the shadow MMU’s recursive ZAP path. Affects x86 public clouds exposing nested virtualization. Separate from Januscape.

Zero-day vulnerability in Windows Defender with public exploit code released.

Presidential memorandum creates a program authorizing private companies to conduct cyber surveillance and effects operations against foreign transnational criminal organizations under federal oversight.

Heap overflow in Windows SMB leads to remote code execution. Discovered and reported to MSRC in June, patched in August Patch Tuesday.

A single XOR instruction unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register on ~100 million AMD CPUs. Appears unfixable.

PortSwigger research on using CSS features to exfiltrate data and execute attacks through email clients without JavaScript. Novel approach to a constrained attack surface.

More this week (75)

Techniques and Write-ups

Proofpoint documents OWAReaper, a browser implant exploiting CVE-2026-42897 in Outlook Web Access. Persists through localStorage and IndexedDB, uses GitHub commit search for C2, and exfiltrates via CDN proxies and DNS tunneling.

Semperis research presented at Black Hat and DEF CON reveals novel Active Directory attack paths through Kerberos downgrade that lead to full domain takeover.

Self-propagating worm targets npm packages via stolen tokens with write permissions. Over 400 packages compromised including keyv (600M monthly downloads). Elastic Security Labs provides full analysis and IOCs.

TrustedSec drops two new tools for Azure cloud credential hunting. Includes a WHOAMI module that grabs permissions, owned apps/devices, groups, RBAC capabilities, and token permissions.

Rapid7 publishes full analysis, IOCs, and PoC for CVE-2026-63077, an unauthenticated RCE in JetBrains TeamCity already in CISA’s KEV. Features a gnarly gadget chain and a polyglot SQL/JSP payload.

Full playlist of TROOPERS26 conference talks now available on YouTube. Covers AD security, cloud attacks, hardware hacking, and more.

Technical analysis of CVE-2026-62737, a critical vulnerability with detailed exploitation writeup.

Dirk-jan Mollema’s BH/DC week blog on extracting Windows Hello keys for authentication replay and persistence. Covers PRT token theft and injection into downstream modules.

S3cur3Th1sSh1t’s x33fcon talk on evasion techniques is now on YouTube. Covers current approaches to bypassing endpoint detection.

Technique writeup on emulating mandatory user profiles for persistence, with detection strategies and a visual diagram of the attack flow.

More this week (476)

Tools and Exploits

MCP server for NetExec enables AI agents to interact with the post-exploitation framework while operators focus on the compromise path. Works with both small and large models.

New Binary Ninja plugin for diffing binaries across CFG, disassembly, and all IL levels. Save and restore diffs, port function names between binaries.

SpecterOps releases tools and resources for the Pass-the-Passkey family of attacks targeting WebAuthn and FIDO2 authentication in Windows environments.

MCP server for HyperDbg enables AI-assisted kernel debugging and hypervisor-level analysis workflows.

Dreadnode benchmarks Kimi K3 against frontier models on offensive security tasks. K3 doubles performance in web app pentesting, crypto, and reversing compared to earlier versions.

LUKSbox gains TPM 2.0 hardware keyslots on Windows via TBS. No driver, no admin rights. Vault keys can now live in real hardware on every desktop OS.

Black Hat Arsenal release from Yamato Security. Sigma-based threat hunting and fast forensics timeline for cloud logs.

New releases of Process Explorer, Process Monitor, PsPing, ZoomIt, CoreInfo, RDCMan, and NotMyFault with new features and bug fixes.

First serious macOS/Linux implant with a COFF loader. Enables cross-platform post-exploitation with Beacon Object File support on non-Windows targets.

Alongside GLM-5.3, the OpenVuln project launches on Hugging Face. Submit any public GitHub repo for automated vulnerability scanning powered by open models.

More this week (30)