A roundup of 611 items curated from across the security community.
News
Black Hat talk details how OpenAI’s evaluation agents began weakening their own guardrails, finding ways to communicate and scheme to gain further access and privileges. Recording now on YouTube.
Pre-auth XSS chains to full RCE on WordPress core, affecting 43% of the internet. Discovered autonomously using open-source models. All WordPress versions affected.
Angelboy’s Black Hat USA 2026 slides on AFD (Ancillary Function Driver) research that led to 30+ Windows kernel vulnerabilities through a novel perspective on a classic attack surface.
CVE-2026-34348 exploitation demo from Black Hat. WebAuthn assertions from recent YubiKey authentication extracted from Windows Event Logs and replayed against Microsoft Entra ID. Whitepaper and Passkey Injector tool released.
Guest-to-host escape on KVM/x86 exploiting a use-after-free in the shadow MMU’s recursive ZAP path. Affects x86 public clouds exposing nested virtualization. Separate from Januscape.
Zero-day vulnerability in Windows Defender with public exploit code released.
Presidential memorandum creates a program authorizing private companies to conduct cyber surveillance and effects operations against foreign transnational criminal organizations under federal oversight.
Heap overflow in Windows SMB leads to remote code execution. Discovered and reported to MSRC in June, patched in August Patch Tuesday.
A single XOR instruction unlocks CPU microcode, the platform security processor, system management mode, and every internal processor register on ~100 million AMD CPUs. Appears unfixable.
PortSwigger research on using CSS features to exfiltrate data and execute attacks through email clients without JavaScript. Novel approach to a constrained attack surface.
More this week (75)
- RT Johann Rehberger: Is your companies AI Gateway compromised right now? How would you even know? Are you looking? Post-exploitation, an adversary can… by Max.
- When “Moderate” Means “Sometimes” - Andrew Schwartz - @HuntressLabs https://www.huntress.com/blog/unpatched-ntlm-leak-windows-search-uri-handler by Swissky.
- RT Burp Suite: Introducing Burp AT. Agentic AI for human-led pentesting, with Burp Suite’s proven tools, your project context, and purpose-built skil… by Shantanu Khandelwal.
- RT Alex Rad: It’s BlackHat/DEF CON week so I’d like to interrupt your regularly scheduled chest drumming feed! Let’s talk about a critical WiFi 7 memo… by Axel Souchet.
- TP-Link patches Omada ZTP flaws allowing hackers to breach networks https://www.bleepingcomputer.com/news/security/tp-link-patches-omada-ztp-flaws-all… by BleepingComputer.
- New XCSSET variant targets macOS devs via compromised Xcode projects https://www.bleepingcomputer.com/news/security/new-xcsset-variant-targets-macos-d… by BleepingComputer.
- Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts https://www.bleepingcomputer.com/news/security/hotel-wi-fi-attacks-use-custom-… by BleepingComputer.
- Brown Health Medical Group-MA Data Breach Exposes Information of 311,000 Individuals https://securityaffairs.com/196681/uncategorized/brown-health-med… by Nicolas Krassas.
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft https://thehackernews.com/2026/08/leaked-n8n-api-tokens-exposed-live.html by Nicolas Krassas.
- Claude Mythos 5 Tried to Backdoor an Open-Source Project by Nicolas Krassas.
- RT Aikido: ‼ The popular npm package keyv is being actively compromised (127 million weekly downloads). The attacker is still pushing malware acros… by Joe Leon.
- New Linux Bridge STP Vulnerability https://ssd-disclosure.com/linux-bridge-stp-timer-use-after-free/ by /r/netsec.
- Black Hat invited us to speak tomorrow about the Hugging Face incident. Given its complexity, we think it’s important to share what happened, what we… by DANΞ.
- Good morning DEF CON! All of the # DefCon 34 files have gone live on https:// media.defcon.org/ including workshop files, presentations, badge files, music and even the Hardware Hacking Village’s spec.
- RT Cody Thomas: I might not be attending hacker summer camp, but I still want to contribute to the fun! https://specterops.io/blog/2026/08/04/mythic-4… by Will Schroeder.
- I might not be attending hacker summer camp, but I still want to contribute to the fun! https://specterops.io/blog/2026/08/04/mythic-4-public-beta/ My… by Cody Thomas.
- RT Eric Geller: OpenAI employees shared new details about the Hugging Face hack at Black Hat today and warned that this new era will require a differe… by pfiatde.
- More Killchains Kill Chain 1: SSRF to API RCE to Kubernetes and the Cloud Kill Chain 2: Assumed Breach Leading to OT https://www.armadin.com/blog… by Andrew Oliveau.
- One H1 2026 campaign spread banking malware through compromised inboxes. Another hijacked crypto payments by replacing wallet addresses. @… by BleepingComputer.
- Swiss government SharePoint breach compromised 200 accounts https://www.bleepingcomputer.com/news/security/swiss-government-sharepoint-breach-compromi… by BleepingComputer.
- Ransom Cartel ransomware creator sentenced to 16 years in prison https://www.bleepingcomputer.com/news/security/ransom-cartel-ransomware-creator-sente… by BleepingComputer.
- Levi Strauss discloses data breach after social engineering attack on employees https://cyberinsider.com/levi-strauss-discloses-data-breach-after-soci… by Nicolas Krassas.
- RT The Hacker News: ‼ BREAKING - A newly discovered #WordPress pre-auth XSS affects every version. XSS2Shell (CVE-2026-64638) can run attacker-cont… by Paulos Yibelo.
- Following my @defcon talk, the blog post about the vulnerabilities I found in the cloud environment of Python in Excel is now public on the @safebreac… by Ron BY.
- Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village) https:// ethiack.com/info-hub/research/ write-once-shell-everywhere-arbitrary-file-writes-into-rce.
- RT Mr. The Plague : Shout out to @badsectorlabs and @RedTeamVillage_ for this absolutely sick tool demo Go try BloodBash out at @defcon 34 in… by Bad Sector Labs.
- RT Costin Raiu: Investigating a suspected ClickFix campaign affecting compromised WordPress sites globally. We confirmed polymorphic JavaScript i… by Florian Roth.
- The best part of BSidesLV/BlackHat/DEFCON is getting to meet the people you admire. I got a chance to nerd out with Thai Duong of http://calif.io toda… by HD Moore.
- RT Oleksandr Mirosh: Thanks to everyone who came out to my #BlackHat talk on insecure string transformation, Transformers: Dark Side of the Type. … by ϻг_ϻε.
- When terrible disclosure from the vendor results in zero days plus a fun dive in to bypassing full disk encryption https:// blog.amberwolf.com/blog/2026/a ugust/hp-thinpro-tpm-sealed-disk-encryption-t.
- Hackers breach TrueConf to trojanize client installers with backdoors https://www.bleepingcomputer.com/news/security/hackers-breach-trueconf-to-trojan… by BleepingComputer.
- Metabase SQLi zero-day exploited in customer data-theft attacks https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-… by BleepingComputer.
- Unlimited Technology Systems breach impacts 3.8 million people https://www.bleepingcomputer.com/news/security/unlimited-technology-systems-breach-impa… by BleepingComputer.
- Alcon - 218,395 breached accounts https://haveibeenpwned.com/Breach/Alcon by Nicolas Krassas.
- DEFCON: New Red Team Tactic https://doctoreww.github.io/EvilFontTool/ by Nicolas Krassas.
- Brinks Home - 732,162 breached accounts https://haveibeenpwned.com/Breach/BrinksHome by Nicolas Krassas.
- RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data https://www.varonis.com/blog/rovoblast by Nicolas Krassas.
- RT Tal Be’ery: Re @_dirkjan You should check @MGrafnetter recent @blackhat talk slides: https://i.blackhat.com/BH-USA-26/Presentations/BHUS26-Grafnett… by DirectoryRanger.
- The blog post on the research I presented at @BlackHatEvents and @defcon is public https://www.safebreach.com/blog/forgotten-but-not-gone-telnet-samba… by Ron BY.
- Python Now Has a Post-Quantum Encryption Library by Bruce Schneier.
- DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE https://amibeingpwned.com/blog/8-in-10-banks-in-belgium by /r/netsec.
- RT Xeno Kovah: Slides and BT RE LLM skills from yesterday’s #DEFCON talk are posted here: https://github.com/darkmentorllc/bt-re-mad-skillz https://g… by Alex Plaskett.
- RT Simon Willison: Thanks to the video from the Black Hat security conference of OpenAI’s presentation about “The Hugging Face Incident” we now have a… by Alex Plaskett.
- OpenAI Releases GPT-5.6-Cyber for Exploit Development by Axel Souchet.
- Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-… by BleepingComputer.
- DentaQuest breach exposes data of 15M people, a record this year https://www.healthcaredive.com/news/Dental-benefits-administrator-discloses-breach/82… by Nicolas Krassas.
- DeadLock ransomware uses blockchain to resist infrastructure takedown https://www.bleepingcomputer.com/news/security/deadlock-ransomware-uses-blockcha… by Nicolas Krassas.
- Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE https://thehackernews.com/2026/08/researchers-disclose-ai-assis… by Nicolas Krassas.
- RT Eric Geller: One of the biggest topics at last week’s @BlackHatEvents and @defcon conferences was the future of the CVE Program, which assigns vuln… by SwitHak ().
- RT Taha ז: In just 5 days of work (during the hacker summer camp week) we are almost reaching Mythos level capabilities and we already beat any open … by Florian Roth.
- RT hacker.house: Here is the complete attack chain executables being used by a suspected DPRK-nexus linked adversary, targeting Web3/DeFI users on Soc… by Dominic Chell.
- The blog exposes several operator Adversarial Prompts or Indicator of Prompt Compromise (IoPC) from the logs Microsoft Defender “How do I di… by Thomas Roccia.
- RT Lorenzo Franceschi-Bicchierai: NEW: Someone jammed the in-flight Wi-Fi on a Delta plane after the Def Con hacking conference in Las Vegas and repla… by hasherezade.
- RT Stephen Fewer: Today we are also disclosing the RCE vulnerability from our SharePoint exploit chain, CVE-2026-63520. Disclosure details are here an… by kmkz.
- RT The Hacker News: ‼ Microsoft patched RoguePlanet. Now the researcher has dropped another zero-day that claims to bypass the fix. ShieldBreak is … by Max.
- RT /ˈziːf-kɒn/: #x33fcon 2026 talks: @TEMP43487580 & Ryunosuke Tsuruda - Signed, Trusted, Abused: Advanced BYOSI Malware Loader Techniques > https:… by Max.
- RT The Hacker News: ‼ A malicious SIM can take over the modem from inside the device. Researchers found 9 of 26 tested phones and cellular modules … by Rémi GASCOU (Podalirius).
- RT Jonathan Brossard: The slides from our @defcon presentation in Las Vegas this week are available ! Featuring #AI #cybersecurity upper limits, a con… by thaddeus e. grugq.
- RT Signal: Introducing Automatic Key Verification! Complementing the existing safety number system, automatic key verification provides an additional,… by thaddeus e. grugq.
- RT _ZN4DionC1Ev: Our BH slides are up at: https://i.blackhat.com/BH-USA-26/Presentations/US-26-Blazakis-Apple-macOS-Kernel-Wednesday-REV-01.pdf we’ll… by thaddeus e. grugq.
- RT Smukx.E: DEF CON 33 - Turning your Active Directory into the attackers C2. TL;DR: GPOs can turn Active Directory into a powerful C2 primitive. This… by topotam.
- Hackers breach govt webmail while running parallel crypto fraud https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-runni… by Nicolas Krassas.
- Questel confirms Microsoft 365 breach after ShinyHunters leaks data https://cyberinsider.com/questel-confirms-microsoft-365-breach-after-shinyhunters-… by Nicolas Krassas.
- Trezor discloses data breach affecting nearly 14,000 customers https://www.bleepingcomputer.com/news/security/trezor-discloses-data-breach-affecting-n… by Nicolas Krassas.
- RingCentral - 1,596,490 breached accounts https://haveibeenpwned.com/Breach/RingCentral by Nicolas Krassas.
- Who’s Tracking You? Use This New Service to Find Out by BrianKrebs.
- RT /ˈziːf-kɒn/: #x33fcon 2026 talks: @thefLinkk & Dominik Phillips: Fingerprinting Modern C2 Implants Through Runtime Telemetry > https://youtu.be/… by S3cur3Th1sSh1t.
- RT s1r1us in sf : i talked to a lot of people who played the defcon ctf finals to understand how llms affected them, both professionally and menta… by Swissky.
- RT Zack Korman: Anthropic trained a version of Opus on environments with reward hacking opportunities, and named that model Hacker-Opus. In evals it a… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- RT Hugow: Our talk from #x33fcon is now on YouTube. We present a DCOMillusionist, an in memory lateral movement technique by bohops.
- RT Justin Elze: This repo is a great time “Traditional vulnerability disclosure is broken. It’s slow, bureaucratic, and ineffective. In the AI era, we… by bohops.
- Hacking Public Wi-Fi DNS to Steal Credentials by Bruce Schneier.
- EDR Evasion Workshop - Workshop materials from: Evading EDR from Loaders to the Kernel, presented at DEF CON 34 and BSidesLV 2026. Covers: Malware … by Panos Gkatziroulis.
- RT SSD Secure Disclosure: New advisory was just published! A critical vulnerability in UNISOC modem firmware allows an attacker to disable protec… by kmkz.
- RT Clandestine: Massive Azure Exfiltration Campaign Exposes Millions of Enterprise Records via Compromised Credentials (Mcdonald’s, Vodafone, Kyndryl… by kmkz.
Techniques and Write-ups
Proofpoint documents OWAReaper, a browser implant exploiting CVE-2026-42897 in Outlook Web Access. Persists through localStorage and IndexedDB, uses GitHub commit search for C2, and exfiltrates via CDN proxies and DNS tunneling.
Semperis research presented at Black Hat and DEF CON reveals novel Active Directory attack paths through Kerberos downgrade that lead to full domain takeover.
Self-propagating worm targets npm packages via stolen tokens with write permissions. Over 400 packages compromised including keyv (600M monthly downloads). Elastic Security Labs provides full analysis and IOCs.
TrustedSec drops two new tools for Azure cloud credential hunting. Includes a WHOAMI module that grabs permissions, owned apps/devices, groups, RBAC capabilities, and token permissions.
Rapid7 publishes full analysis, IOCs, and PoC for CVE-2026-63077, an unauthenticated RCE in JetBrains TeamCity already in CISA’s KEV. Features a gnarly gadget chain and a polyglot SQL/JSP payload.
Full playlist of TROOPERS26 conference talks now available on YouTube. Covers AD security, cloud attacks, hardware hacking, and more.
Technical analysis of CVE-2026-62737, a critical vulnerability with detailed exploitation writeup.
Dirk-jan Mollema’s BH/DC week blog on extracting Windows Hello keys for authentication replay and persistence. Covers PRT token theft and injection into downstream modules.
S3cur3Th1sSh1t’s x33fcon talk on evasion techniques is now on YouTube. Covers current approaches to bypassing endpoint detection.
Technique writeup on emulating mandatory user profiles for persistence, with detection strategies and a visual diagram of the attack flow.
More this week (476)
- Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon’s best-selling router https:// rotcee.github.io/posts/analyzi ng-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-au.
- RT Niebezpiecznik: Żabka zhackowana. Sieć sklepów potwierdziła nam, że doszło do nieautoryzowanego dostępu do infrastruktury. Co wyciekło… by hasherezade.
- RT Hex-Rays SA: idalib is now available in IDA Home. That means hobbyists and enthusiasts can now call IDA’s analysis engine as a library - runn… by hasherezade.
- RT Ivan (ethical vulnerability researcher): How to APT ep 2: https://klydz.net/post.php?slug=how-to-apt-ep2-lying-to-the-whole-netns-through-bpfprogty… by hasherezade.
- SquidC5 - Security-first AI-native C5 teamserver (Command · Control · Cognitive · Collaborative · Coordination) https://github.com/SquidSec/SquidC… by Panos Gkatziroulis.
- From Stack Overflows to Modern Pool Grooming Step-by-step development of kernel primitives, from simple stack corruption to advanced heap groomin… by Panos Gkatziroulis.
- EkkoNtProtect - Arbitrary NtProtectVirtualMemory calls from Ekko-style timer-based sleep obfuscation using internal ntdll functions https://github.com… by Panos Gkatziroulis.
- Rusty Bootkit - Windows UEFI Bootkit in Rust (Codename: RedLotus) https://memn0ps.github.io/rusty-windows-uefi-bootkit/ by Panos Gkatziroulis.
- RT Lsec: I just deployed a short blogpost about evading egress firewall configurations using an internal system as a Sliver C2 traffic redirector. htt… by Chihuahua in charge NotMe.
- RT adam_cyber: Hot off the press: @CrowdStrike 2026 Threat Hunting Report Read about detailed sector analysis, the targeting of AI, CI/CD supply chain… by Chihuahua in charge NotMe.
- RT SEKTOR7 Institute: Extracting and analyzing Windows service configurations and ACLs. A tool by Panagiotis Chartas (@t3l3machus) Source: https://git… by Chihuahua in charge NotMe.
- RT Hack32: VMkatz in action: Offline extraction of SAM, LSA, and DPAPI directly from a .vdi virtual disk by Chihuahua in charge NotMe.
- Hey blueteamers, in case you’re using #opencti , ensure you are up to date + defaults admin disabled. A weeks ago I fully weaponized the pre-auth RCE … by kmkz.
- RT Frank Wu: IonStack Blog Series: Part I (Firefox SpiderMonkey JIT RCE): https://nebusec.ai/research/ionstack-part-1-cve-2026-10702/ Part II (GhostLo… by kmkz.
- Pre-auth SSRF. Security policy bypass PoC Reported a pre-auth blind SSRF in #Keycloak OIDC Dynamic Client Registration. The interesting part isn’t the… by kmkz.
- Iran Cyberattacks Against Minnesota Water Systems by Bruce Schneier.
- RT : Checked a few benchmarks of different GPU’s and depending on your setup, kerberoasted AES ‘hashes’ (hashcat mode 19700), that are now the def… by Max.
- RT codewhisperer84: I’ve been working on a Titanis documentation site => https://trustedsec.github.io/Titanis/UserGuide/ Source tree now includes comp… by Max.
- RT Matt Zorich: For those that missed it the Active Directory tier model documentation recently had a huge uplift, and even more importantly, the scri… by Max.
- Metasploit 6.5 shipped Malleable C2 support for all current Meterpreter payloads - same profile format you already know, now shaping Meterpreter’s HT… by Metasploit Project.
- I’ve just updated the M365 2.0 phishlet for Evilginx Pro with full Browser-in-the-Browser compatibility. To remove frame-busting code from an… by Kuba Gretzky.
- Bugtraq is back https:// lists.securityfocus.com/hyperk itty/list/bugtraq@securityfocus.com/thread/CHKLXLA7SJEWLDFHWXB3QU57ADOXGL2E/.
- AI agents don’t pentest like humans, and @KoyalwarTarun’s BSidesLV research shows just how differently they operate. Across 54 black-box web app tar… by ProjectDiscovery.
- Poisoning Claude Code: One GitHub Issue to Break the Supply Chain - GMO Flatt Security, https://flatt.tech/research/posts/poisoning-claude-code-one-gi… by Swissky.
- Unauthenticated RCE as QSECOFR via IBM i Management Central - @SilentSignalHU https://blog.silentsignal.eu/2026/06/05/unauthenticated-rce-as-qsecofr-v… by Swissky.
- SMBLoot has been updated with: - OPSEC mode: directory trees are cached when opened, preventing new requests when revisiting them; for example, when n… by Swissky.
- RT V12: Arbitrum Nitro normally runs natively, but disputes rely on fraud proofs run in a WASM VM. If these two environments don’t fully agree, it can… by Sam Curry.
- RT zqxwce: vPhone Workstation is officially out! https://github.com/zqxwce/vphone-ws by Csaba Fitzl.
- RT Arin Waichulis: Apple has confirmed it’s capping how many bug reports a researcher can have open at once, plus a 30-day cool-off period, as AI slop… by thaddeus e. grugq.
- RT MTS: SITUATION DETECTED: The House Committee on Homeland Security has written a letter to Sam Altman requesting a briefing from OpenAI on the Huggi… by Vincent Yiu.
- RT Galaxy Research: LOSSES FROM COLDCARD HACK EXCEED $100M High confidence 1,596 BTC has been stolen from ~7300 addresses across 3 confirmed waves… by Vincent Yiu.
- I hate writing pattern-matching code for function identification in my .NET #deobfuscator and config extractor. So I built a tool to help me out with … by Washi.
- The chances of you finding RWX pages in NTDLL are low, but never zero. by db.
- RT S3cur3Th1sSh1t: For anyone who was wondering “how to” regarding to my last two Posts - here is a small writeup and Proof of Concept by db.
- A few notes on AWS Nitro Enclaves: KMS integration.
- RT Chris Thompson: ConfigManBearPig adds SCCM attack paths to the BloodHound graph, including all of the known hierarchy TAKEOVERs. I rewrote 2.0 in P… by Andrew Chiles.
- Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 1 by Beyviel David.
- Turning Enterprise Update Servers Into Backdoor Factories (0_o) – Part 2 by Beyviel David.
- Of Course We Built a WSUS Ludus Lab by Beyviel David.
- NEW BHIS | Blog You’ve just confirmed it: that alert isn’t a false positive. Whether it’s suspicious PowerShell execution, unusual network traffic… by Black Hills Information Security.
- “The tool is purpose-built for this kind of audit - whether you’re a penetration tester on an internal engagement, a security engineer hardening you… by Black Hills Information Security.
- When an attacker steals a machine key, they are no longer impersonating a user: they’re impersonating the machine itself. https://www.scworld.com/new… by Black Hills Information Security.
- CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploit… by BleepingComputer.
- Phishing service spoofs RingCentral to steal Microsoft 365 accounts https://www.bleepingcomputer.com/news/security/phishing-service-spoofs-ringcentral… by BleepingComputer.
- 77 Open VSX extensions found harvesting developer info https://www.bleepingcomputer.com/news/security/77-open-vsx-extensions-found-harvesting-develope… by BleepingComputer.
- Massive ChainDrop npm supply-chain attack infects hundreds of packages https://www.bleepingcomputer.com/news/security/massive-chaindrop-npm-supply-cha… by BleepingComputer.
- New Pass-ta-key attacks let malware hijack Google-synced passkeys https://www.bleepingcomputer.com/news/security/new-pass-ta-key-attacks-let-malware-h… by BleepingComputer.
- New DOUBLECUP ClickFix service hides malware in browser cache images https://www.bleepingcomputer.com/news/security/new-doublecup-clickfix-service-hid… by BleepingComputer.
- Fake Roblox Xeno script launcher pushes infostealer, RAT malware https://www.bleepingcomputer.com/news/security/fake-roblox-xeno-script-launcher-pushe… by BleepingComputer.
- N-able warns of N-central auth bypass flaw exploited in attacks https://www.bleepingcomputer.com/news/security/n-able-warns-of-n-central-auth-bypass-f… by BleepingComputer.
- BTMOB has evolved into an ecosystem of resellers, source-code sellers, and possible impersonators. @flaresystems examines how the Android … by BleepingComputer.
- Finally got around to getting a working PoC of my native object file to LLVM IR lifter. Started this small side-project to see how far can I push my o… by 5pider.
- Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt https://thehackernews.com/2026/08/poison-claude-sells-disco… by Nicolas Krassas.
- IBM’s agentic AI platform is under active attack - patch now https://www.theregister.com/security/2026/08/05/ibms-agentic-ai-platform-is-under-active-… by Nicolas Krassas.
- OVSwrap: 13-Year-Old Linux Kernel Flaw Lets Local Users Become Root https://securityaffairs.com/196657/hacking/ovswrap-13-year-old-linux-kernel-flaw-l… by Nicolas Krassas.
- Brazil Health Surveillance Database Exposed 79GB of Sensitive Records https://hackread.com/brazil-health-surveillance-database-exposed-records/ by Nicolas Krassas.
- Samsung bans smart TV apps that turn user connections into proxies https://cyberinsider.com/samsung-bans-smart-tv-apps-that-turn-user-connections-into… by Nicolas Krassas.
- Google’s synchronized passkeys can be stolen in ‘Pass‑ta‑key’ attacks https://www.malwarebytes.com/blog/news/2026/08/googles-synchronized-passkey… by Nicolas Krassas.
- UK charities count the cost of Beacon CRM cyberattack https://www.theregister.com/security/2026/08/05/uk-charities-count-the-cost-of-beacon-crm-cybera… by Nicolas Krassas.
- REMOTE-003 Path Traversal in Configuration Subsystem of Apache Dubbo 3.3.x https://blog.securelayer7.net/apache-dubbo-remote-003-path-traversal/ by Nicolas Krassas.
- London cops handed victim’s new address and number to her stalker, watchdog says https://www.theregister.com/security/2026/08/05/london-cops-handed-vi… by Nicolas Krassas.
- RT Alex: The not so new “Windows Health and Optimized Experiences” service audited. One more user -> SYSTEM EoP (2nd in August and 5th in Q3). Let’s h… by Nicolas Krassas.
- Vulnerabilities in Car Anti-Theft Device https://www.schneier.com/blog/archives/2026/08/vulnerabilities-in-car-anti-theft-device.html by Nicolas Krassas.
- Full read and write control of a Daikin VAM heat-recovery ventilation unit over the P1/P2 bus, using an Arduino Uno registered as a genuine BRC301B61-… by Nicolas Krassas.
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer https://thehackernews.com/2026/08/quickfox-supply-chain-attack-d… by Nicolas Krassas.
- Execution 3h 3m 30s Total 3h 3m 34s Spend $14.8082 rtnetlink bridge lifecycle -> designated-port desync via priority toggle while port DISABLED -> STP… by Giuseppe
N3mes1s. - RT Microsoft Threat Intelligence: Microsoft Threat Intelligence is tracking active Mini Shai-Hulud npm supply chain attacks in which a threat actor co… by SwitHak ().
- RT Team Cymru Research: INTEL DROP Remote-management tools are the access layer for a lot of live intrusions. We’re tracking 949 malicious IPs running… by Alberto.
- From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation https://www.coinspect.com/blog/ill-bloom-investigation/ by /r/netsec.
- OpenAI agents rebuilt a secret message board after the company shut it down https://runtimewire.com/article/exclusive-openai-agents-rebuilt-a-secret-m… by /r/netsec.
- Stored XSS in Django’s admin via an unvalidated URLField display path (CVE-2026-15920) https://syntetisk.tech/blog/posts/stored-xss-in-djangos-admin-v… by /r/netsec.
- The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2 https://hunt.io/blog/the-gentlemen-etherrat-ethereum… by /r/netsec.
- Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon’s best-selling router https://rotcee.github.io/posts/analyzing-the-mersusys-… by /r/netsec.
- Ever found yourself in an environment with heavy Application Control for Business (formery WDAC) controls? Some research on how to bypass those contro… by 0xBB.
- Deserialization strikes again for a WDAC bypass in imgmgr.exe (cc Dr. Tim Baker at dotSec) https://www.dotsec.com/insecure-deserialisation-app-control… by bohops.
- Adversarial Clothing Designed to Fool Facial Recognition Systems by Bruce Schneier.
- RT watchTowr: Following it’s debut at @BlackHatEvents Europe last year, Principal Vulnerability Researcher at watchTowr @chudyPB’s talk - Pwning .NE… by Piotr Bazydło.
- RT Nextron Research : While reviewing the recent 360 Advanced Threat Research Institute report on APT-C-24 (Rattlesnake), we identified additional… by Florian Roth.
- RT Nextron Research : We recently identified malicious Excel documents related to #DoNot APT activity. The samples include shipping- and invitatio… by Florian Roth.
- RT Nextron Research : We reproduced Certighost (CVE-2026-54121) end to end in a controlled lab The vulnerability allows a low-privileged domain us… by Florian Roth.
- 7 year old rules FTW Other matches with that rule : https://valhalla.nextron-systems.com/info/rule/MAL_NK_Malware_Hermit_BAT_May19_2 by Florian Roth.
- RT Pavel Durov: Last night Apple briefly removed Telegram from the AppStore because a user had planted illegal porn in a public chat. Telegram was res… by Florian Roth.
- RT Nextron Research : We just uploaded new observed payloads to VT. Hashes below: setup.mjs fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda80… by Florian Roth.
- RT Student Of Things: Just confirmed, I found the Coldcard RNG bug 11 months ago and never reported it because they didn’t acknowledge me on the firs… by Florian Roth.
- Two of our researchers hit the #BHUSA stage for the first time. Angelboy(@scwuaptx ) shares how a different angle on AFD led to 30+ new #Windows kerne… by DEVCORE.
- A good example of why trusting AI with all of your RE needs and letting your skills stagnate or just not develop them at all will cause headaches in t… by Daax.
- RT International Cyber Digest: The slopocalypse is real. MITRE published a critical SQLite vulnerability with a CVSS of 10.0 that does not exist…. by Daax.
- RT Antonio Viggiano: Great post by @trailofbits - threat model - /goal fan out - variant analysis - agentflow (Easter egg from Figure 4) https://blog…. by Dave Aitel.
- Shane (@shanejcaldwell) just landed in Vegas, ready to talk runtime oversight and judges for the next 72 hours. Check out his latest research, ScopeJu… by dreadnode.
- How we took malware advisories beyond npm by Ankit Kumar Honey.
- RT NetAskari: Incredible: Greek cyber sec researcher gets access to North Korean operator’s communication and operational infrastructure for 2 years (… by Simone Margaritelli.
- RT Feng Xue: when root runs ‘su - user1’ interactively and exit, user1 becomes root http://x.com/i/article/2084830838043377664 by Gergely Kalman.
- Due to the time constraints, live demos didn’t make it to the talk, but you can see them here: by hasherezade.
- RT Jiří Vinopal: Just delivered the talk “BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive” at #BHUSA 2026 �… by hasherezade.
- Hello Las Vegas (and hackers following along at home)! I’m excited to share the first batch of our Out-of-Band / Baseboard Management Controller resea… by HD Moore.
- Can you disable Gatekeeper and XProtect? https://eclecticlight.co/2026/08/06/can-you-disable-gatekeeper-and-xprotect/ via @howardnoakley by Howard Oakley, Eclectic Light Co.
- New, by me: Canadian Man Pleads Guilty in Snowflake Data Extortions: A 26-year-old Canadian man described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to comput.
- Claude-red - a curated library of offensive security skills designed for the Claude skills system https://github.com/0xwilliamortiz/claude-red by Panos Gkatziroulis.
- SOCKSRelayd - SOCKS-focused NTLM relay with persistent session packages and a long-lived SessionBank that owns authenticated TCP connections https://g… by Panos Gkatziroulis.
- Blacksea - an active honeypot and canary-bait control system built to detect and drown LLM-driven attackers. Exploits flaws in the attacker’s LLM ju… by Panos Gkatziroulis.
- adhammer - Active Directory security-assessment toolkit in Rust https://github.com/icedracon/adhammer by Panos Gkatziroulis.
- RT Panos Gkatziroulis : The following event IDs are required to detect malicious .ppkg files (used for code execution): 10 - Container… by Panos Gkatziroulis.
- RT : Direct link to tools. It’s recommended to read the blog. https://github.com/rootsecdev/SecretsStalker https://github.com/rootsecdev/SecretsS… by Chihuahua in charge NotMe.
- RT spencer: If you’re looking for a quick and easy way to harden your environment, then look no further! Download this list of RMM tools and block al… by Chihuahua in charge NotMe.
- RT Nicolas Krassas: arcanum-sec/wraith: WRAITH - a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers, and educ… by kmkz.
- RT dbugs: CVE-2026-57256: RCE via JavaScript in Foxit PDF Reader The use of V8 JavaScript in PDF rendering engines and editors enables the creation of… by kmkz.
- Ok, originally planned to publish after vacations but… The discussions following my previous post & questions around the possible bypass of the curr… by kmkz.
- RT bohops: I recently updated “The Ultimate WDAC Bypass List” to include TextTransform.exe as well as a few undocumented placeholder entries (despite … by kmkz.
- RT _SiCk: I Lied: A little crippled so it’s not a full weapon. reads/writes some things via mdo and sets up said socket as root… if you can figure o… by kmkz.
- RT Calif: wp2root as promised :-) https://blog.calif.io/p/the-wordpress-chain-massacre Our chain is nothing fancy. Its value is in showing what real-w… by lcamtuf.
- My favorite talk I saw today! by Maddie Stone.
- RT : If you found a pattern in passwords used, you can ask your favorite LLM to generate a rule file. Example prompt for 1@ = 1example… by Max.
- RT ATTACKD: We built a C2 implant that walked past Microsoft Defender clean. No static hits or behavioral alerts. Then Windows SmartScreen killed it. … by Max.
- Anyone who’s ever had to debug HTTP traffic remembers Fiddler. Here’s a great story about the product, told by its creator, Eric. by Kuba Gretzky.
- RT YungBinary: We’re tracking a new EDR killer using a #BYOVD driver that isn’t in Microsoft’s block lists / #LOLDrivers and enumerates 140+ security … by Rob Fuller.
- [RT Mr. OS: #Research #Malware_analysis “EDR Introspection: Enabling deep insights into EDR detection approaches”, 2026. ]-> https://github.com/evilele...](https://github.com/evilele/EDR-Introspection) by Ring3API 🇺🇦.
- RT kernelstub (Prepakis Georgios): A new Apache RCE vulnerability has been identified in the latest version. I have not redacted the specific details … by nyxgeek.
- ESC8s and Where to Find Them - Abdul Mhanni @abdo_mhanni https://www.abdulmhsblog.com/posts/esc8andfindingwebenrollmentendpoints/ by Swissky.
- The SQL Server Unicode problem: why your data might not be what you think it is? - Alexandre Zanni https://www.synacktiv.com/en/publications/the-sql-s… by Swissky.
- RT Swissky: SMBLoot update Several quality-of-life and performance improvements landed today: in-preview regex search, clearer folder statistics, … by Swissky.
- RT Alan Woodward: Hugging Face incident just got real for OpenAI https://www.iowaattorneygeneral.gov/media/cms/08_5392C9E17791C.pdf by pfiatde.
- RT V12: Type text into Wikipedia. Get the shell’s output back on the page. A bug introduced 22 years ago. Still alive in the wild, until it was found … by ϻг_ϻε.
- “For SOC teams the priority is no longer simply preventing ransomware encryption - it’s detecting unauthorized activity during the narrow window bet… by Black Hills Information Security.
- ClickFix attack pushes macOS infostealer for crypto theft attacks https://www.bleepingcomputer.com/news/security/clickfix-attack-pushes-macos-infostea… by BleepingComputer.
- Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group https://www.bleepingcomputer.com/news/security/hedge-fund-cyberattacks-tied-t… by BleepingComputer.
- New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes https://www.bleepingcomputer.com/news/security/new-tontou-cpu-attack-bypa… by BleepingComputer.
- Meta AI model hacked a company during misconfigured cyber test https://www.bleepingcomputer.com/news/security/meta-ai-model-hacked-a-company-during-mi… by BleepingComputer.
- Canadian pleads guilty to Snowflake cloud data-theft attacks https://www.bleepingcomputer.com/news/security/canadian-pleads-guilty-to-snowflake-cloud-… by BleepingComputer.
- Hackers run khunt post-exploitation toolkit from Oracle database https://www.bleepingcomputer.com/news/security/hackers-run-khunt-post-exploitation-to… by BleepingComputer.
- COLDCARD security audit phishing attack installs remote access tool https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phishing-at… by BleepingComputer.
- https://www.securityweek.com/how-a-50000-exploit-chain-turned-bixby-against-samsung-phones/ by Dimitri Os.
- N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands https://www.theregister.com/networks/2026/08/07/n-abl… by Nicolas Krassas.
- TrustFall: When the Trusted Execution Environment Cannot Be Trusted https://blog.byteray.co.uk/blog/optee-rsa-nopad-heap-underwrite.html by Nicolas Krassas.
- Living off the coding agent: Two tales of tunnels and LaunchAgents https://www.elastic.co/security-labs/coding-agent-launchagent-tunnel-detection by Nicolas Krassas.
- Nice one by Nicolas Krassas.
- North Carolina Ports confirms cyberattack disrupting operations https://www.bleepingcomputer.com/news/security/north-carolina-ports-confirms-cyberatta… by Nicolas Krassas.
- AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day https://thehackernews.com/2026/08/ai-assisted-http-terminator-finds… by Nicolas Krassas.
- Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails https://thehackernews.com/2026/08/microsoft-365-aitm-phishing-hijac… by Nicolas Krassas.
- RT Ru Campbell: Just updated my Defender for Endpoint/Defender for Business feature comparison by OS. Main changes: • AI agent capabilities in previe… by DirectoryRanger.
- RT bohops: Deserialization strikes again for a WDAC bypass in imgmgr.exe (cc Dr. Tim Baker at dotSec) https://www.dotsec.com/insecure-deserialisation-… by DirectoryRanger.
- RT hasherezade: Slides from my today’s talk at #BlackHatUSA2026 : “Breaking the Seal: Static Deobfuscation of Compiled #V8 JavaScript Bytecode #Malwar… by Giuseppe
N3mes1s. - RT rootsecdev: Pass the hash never went away.. it just evolved when orgs moved to the cloud. @_dirkjan blogs never disappoint. https://dirkjanm.io/bor… by Steven Lowson.
- RT Ayush Anand: When did your last backup target 127.0.0 . 1? That’s wbadmin dumping creds, not backing up. Two tells: -include isolates the offline-c… by SwiftOnSecurity.
- RT Andy Greenberg (@agreenberg at the other places): Two security researchers shipped me a kid’s smartwatch from Amazon. When I wore it, they tracked … by SwiftOnSecurity.
- SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-645… by /r/netsec.
- tl;dv (Too Lazy; Didn’t Validate): 181,874 Meetings Left Wide Open https://bobdahacker.com/blog/tldv-hack by /r/netsec.
- I made a full JWT hacking tutorial + testing suite https://hakluke.com/jwt-hacking by /r/netsec.
- Claude Code RCE: How a Malicious PR Triggers Code Execution https://www.immersivelabs.com/resources/blog/claude-code-rce-vulnerability-how-a-malicious… by /r/netsec.
- Zbtlink Routers Contain rctl Backdoor https://www.vulncheck.com/blog/zbt-endlessdoors by /r/netsec.
- The slides from my Blackhat USA 2026 presentation “Beam Me Up Luke: A Review of Teleport Attack Scenarios” are now available #BHUSA https://i.blackhat… by Adam Chester.
- RT EZ: This is real stuff folks. It’s not just Claude. Browser agents come with incredible capabilities but also incredible risk. What’s worse, there … by Florian Roth.
- RT Unit 42: We’ve identified further malicious infrastructure from npm and PyPI packages. Techniques include cloud credential exfiltration, EtherHidin… by Florian Roth.
- Gotta get back on MacOS by David.
- Worked really hard on this tool and I know many great community tools exist for Azure/Entra, I am aware maybe some modules are not well documented or … by David.
- RT NCSC UK: Re Read more from our CTO, Ollie Whitehouse: https://www.ncsc.gov.uk/news/ncsc-statement-in-response-to-recent-incidents-resulting-from-fr… by Dominic Chell.
- RT Joshua Saxe: Slides for my AI security forum keynote proposing a pivot in frontier AI security policy https://docs.google.com/presentation/d/1aFwK7… by dreadnode.
- It’s about time by Gergely Kalman.
- Told you guys H1 sucks by Gergely Kalman.
- RT John Hultquist: Blackfile (UNC6671) is still at it and has been operating under a series of rebrands. They are currently hitting the financial sect… by hasherezade.
- PyPsPipeJack - Python implementation of OpenPsPipeJack TL;DR: You have local admin on a remote host, connect to remote PowerShell sessions on that hos… by Panos Gkatziroulis.
- sift - Credential and sensitive-data exposure triage for file shares https://github.com/HotStartLabs/sift by Panos Gkatziroulis.
- RT staturnz: momentarius: PPL Bypass for A12/A13 by me and @imnotclarity https://github.com/staturnzz/momentarius by kmkz.
- RT REMnux: The REMnux project now distributes @hasherezade’s JSC Deobfuscator as a container. It turns obfuscated V8 bytecode (.jsc) into readable Vie… by Max.
- RT InfoGuard Labs: New Post from our Pentest Team: One pentest turned into 22 CVEs in TeamDavid®. From an unauthenticated single-request DoS all the … by Manuel.
- RT Geekboy: Re @pdnuclei detection template - https://github.com/projectdiscovery/nuclei-templates/pull/16785 by Nuclei by ProjectDiscovery.
- CVE-2026-45454 - Microsoft SharePoint Server Upload Page Folder Path Traversal to Remote Code Execution - @AretiqAI https://aretiq.ai/research/vul260… by Swissky.
- Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 - Justin Kalnasy - @SpecterOps https://specterops.io/blog/2026/06/10/oops-i-we… by Swissky.
- RT Stephen Fewer: Re @rapid7 PoC for CVE-2026-63077 here: https://github.com/sfewer-r7/CVE-2026-63077 by Mayuresh 🇮🇳.
- RT V12: Type text into Wikipedia. Get the shell’s output back on the page. A bug introduced 22 years ago. Still alive in the wild, until it was found … by Rick de Jager.
- RT Boyd Kane (quantized): Hey @OpenAI you can still download the scripts used by AIs to hack @huggingface (full report & commands in reply) by Sam Curry.
- RT Chris Wysopal: “AI systems appear to have an easier time exploiting flaws than patching them, an unfortunate asymmetry in capabilities” https://w… by Sean Heelan.
- After many years, I finally found a vulnerability which allowed me to install arbitrary profiles (including MDM) without user interaction. �… by Csaba Fitzl.
- RT International Cyber Digest: US Cyber Command is reviewing an unusually high number of deaths by suicide among its personnel, as many as five people… by thaddeus e. grugq.
- RT SpecterOps: Re Check out @bagelByt3s’ blog series to dive even further! Part 1: https://ghst.ly/4w4SDt7 Part 2: https://ghst.ly/4gerXBr Part 3: htt… by topotam.
- thanks to everyone who came to my @RedTeamVillage_ session. Here’s a link to all the slides, course materials, etc. https://rtv.two06.co.uk/ by James .
- Beyond Prompt Injection: Hacking Apple’s Private Cloud Compute https:// blog.sentry.security/beyond-pr ompt-injection-hacking-apples-private-cloud-compute/.
- HTTP/3 Trailer HEADERS Frame Triggers Unhandled Exception in Google ESF: 60s Hang & QUIC INTERNAL_ERROR 0x0001 | Protocol RE | Netacoding https:// netacoding.com/posts/blog_post _esf_h3/.
- Ransomware gangs skip the CEO, head straight for the 40-something IT manager https://www.theregister.com/security/2026/08/09/ransomware-gangs-skip-the… by Nicolas Krassas.
- Weaponizing Windows Updates with NotWSUSpicious https://specterops.io/blog/2026/08/05/weaponizing-windows-updates-with-notwsuspicious/ by Nicolas Krassas.
- WinGuard - A User-Mode Windows Threat Detection Tool Inspired by EDR Techniques, To Help Monitor And Log Suspicious Activities https://github.com/Poly… by Nicolas Krassas.
- LockBit 5.0 Linux Malware Analysis: ChaCha20 + Curve25519 Offline Encryption, strace Evasion & IOCs https://netacoding.com/posts/lockbit5-analysis/ by Nicolas Krassas.
- Analyzing a Multi-Stage PowerShell Payload Chain https://malwr-analysis.com/2026/08/08/investigating-a-multi-stage-powershell-loader/ by Nicolas Krassas.
- Agent Tesla – APC Injection, Token Manipulation & Payload Extraction https://github.com/kaandemir993/Agent-Tesla-APC-Injection-Token-Manipulation-Reg… by Nicolas Krassas.
- Palo Alto Networks Faces China Cybersecurity Review Amid Rising Tech Tensions https://securityaffairs.com/196881/intelligence/palo-alto-networks-faces… by Nicolas Krassas.
- HTB: Helix https://0xdf.gitlab.io/2026/08/08/htb-helix.html by Nicolas Krassas.
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts https://thehackernews.com/2026/08/progress-kemp-loadmaster-flaw-hits-c… by Nicolas Krassas.
- RT @Enno_Insinuator: New @ERNW_ITSec white paper “Breaking Multi-Tenancy in Kubernetes over and over, and What We Can Learn from This” http… by DirectoryRanger.
- RT Thorsten E.: Pretty-Policy-Analyzer A desktop/web app for security engineers and Active Directory administrators to load, browse, compare, audit, a… by DirectoryRanger.
- RT Elias Bachaalany: Reverse engineering, run entirely from my phone. @OpenAI’s @ChatGPT Work recovered compiling source from a stripped binary while … by Giuseppe
N3mes1s. - RT Calif: PoC for a critical vulnerability in Apple macOS Screen Sharing (CVE-2026-65400). If Screen Sharing is enabled, any network attacker can expl… by Giuseppe
N3mes1s. - RT Michael Bargury: we got an RCE on your machine thru Comet by sending a calendar invite you ask Comet any question about your calendar? we pop a she… by Giuseppe
N3mes1s. - RT MSec Operations: New Blogpost regarding to “Backdooring Open-Weight Models” just published by @ShitSecure: https://www.msecops.de/blog/posts/backdo… by Steven Lowson.
- The APT group #HeadMare exploits vulnerabilities in an unpatched TrueConf server to deliver #PhantomCore and #PhantomGraph malware to video conferenci… by SwitHak ().
- Beyond Prompt Injection: Hacking Apple’s Private Cloud Compute https://blog.sentry.security/beyond-prompt-injection-hacking-apples-private-cloud-compu… by /r/netsec.
- I just came across this blog post: https://www.countercraftsec.com/blog/arbitrary-vs-kernel/ It’s a very cool read! I disagree with the conclusion tho… by winterknife.
- Slides and whitepaper of Gone in 60 Frames – USB Video Exploitation by @robHerrera_ and myself seem to be on the #defcon34 media server now! Slides -… by Alex Plaskett.
- RT Kuzey Arda Bulut: Exploiting Mali GPU CVE-2025-8045 on Pixel 7 Pro! Turning a double-free into a Dirty Pagetable primitive via race, timer-whee… by Alex Plaskett.
- RT msuiche: But it didn’t solve @calif_io MIE challenge https://www.msuiche.com/posts/calif-mie-kimi-k3/ by Alex Plaskett.
- RT Tarjei Mandt: I’ve been looking at how to leverage frontier-sized open models for domain-specific use. Here’s an attempt at creating a much smaller… by Alex Plaskett.
- RT AI Security Institute (AISI): On July 28th, we identified an incident during a routine cyber evaluation in which AI agents took sustained, unsancti… by Alex Plaskett.
- RT Blackstorm Security: CVE-2026-24294 - Local NTLM Reflection LPE via SMB Arbitrary Port: https://github.com/0xNDI/CVE-2026-24294 #smb #vulnerability… by codewhisperer84.
- RT The Telegraph: Royal Navy spy drones used by Britain’s elite special forces secretly sent data to China, The Telegraph can reveal. The cameras on … by Florian Roth.
- RT AnMioLink: It seems Silver Fox Group is now using unverified (Fake/Stolen?) Microsoft Windows Third Party Component CA certificate chain(s) to sign… by Florian Roth.
- I had a discussion with a friend in threat intelligence about AI-driven attacks, and one thing stuck with me. Threat actors used to have a certain fin… by Florian Roth.
- RT Swissky: CVE-2026-45454 - Microsoft SharePoint Server Upload Page Folder Path Traversal to Remote Code Execution - @AretiqAI https://aretiq.ai/res… by Florian Roth.
- RT Sina BI Report: So the ColdCard entropy bug that lead to at least $100M of theft, was introduced by then CTO and co-founder himself, who u… by Florian Roth.
- Single prompt Rust re-write with Opus 5 Let me know if anything breaks. https://github.com/EgeBalci/sgn by ege.
- Whoops. That’s quite an unexpected result if it checks out. by RPW: @rpw@chaos.social.
- RT Mars: Oh this looks fun and SCARY! If your ISP uses shared GPON fibre and has not correctly enabled downstream encryption, another customer on the … by Simone Margaritelli.
- Thanks to everybody that came out to my #BHUSA2026 Arsenal talk last week! I have posted the slides here - https://github.com/h4wkst3r/Conferences/blo… by Brett Hawkins.
- RT Neogram: Purpose-built Windows PE sets for reverse engineering, detector validation and malware-analysis education https://www.orderofsixangles.com… by hasherezade.
- RT Smukx.E: Windows Internals crash course by x64dbg creator @mrexodia This video covers about Process Creation (Kernel), PE Structure, PEB, TEB, Call… by hasherezade.
- RT Andrew Thompson: CERT Polska: Follow-Up Analysis of the 29 December 2025 Energy Sector Incident “To the best of our knowledge, the attack vector us… by hasherezade.
- RT eversinc33 : A handy .NET reverse engineering trick: Add a sample.exe.config file next to your sample and you can trace e.g. all network re… by hasherezade.
- RT cr3ghost: They did it again. This time it’s Tencent’s kernel anticheat VM. 815 of 865 virtualized functions across four kernel drivers statically d… by hasherezade.
- New article lands tomorrow. Until then, here’s your chance to revisit the breakdown on how to use .ppkg files for code execution. Don’t miss it… by Panos Gkatziroulis.
- SgrmFault - Process Impairment Exploit Chain Revives a COM-based code injection in WerFaultSecure to abuse an APC-based process tampering feature expo… by Panos Gkatziroulis.
- RT Brett Hawkins: Thanks to everybody that came out to my #BHUSA2026 Arsenal talk last week! I have posted the slides here - https://github.com/h4wkst… by Panos Gkatziroulis.
- Authenticode signature manipulation toolkit for Red Team operations and security research. Covers signature stealing, metadata cloning, SIP hijacking … by Panos Gkatziroulis.
- Command & Conquer - A hands-on C2 workshop for aspiring Red teamers Covers a unified view of C2 fundamentals for both offensive and defensive … by Panos Gkatziroulis.
- RT 0x12 Dark Development: Writing Your First PIC Shellcode with Crystal Palace New Medium post. In this one we are building two PICOs from scratch, a … by Panos Gkatziroulis.
- ResetNightmare POC - a validation flaw in the Kerberos Change Password protocol that allows for resetting the password of any target user/computer acc… by Panos Gkatziroulis.
- A Windows userland tool developed by @Sphinx_321 for enumerating and classifying Advanced Local Procedure Call (ALPC) ports, including those owned by … by Panos Gkatziroulis.
- From Square Root to /root: Escalating Privileges in Azure Containers with Python in Excel https://www.safebreach.com/blog/python-in-excel-vulnerabilit… by Panos Gkatziroulis.
- EvilFontTool - hides machine-readable text inside a document that displays completely different text to a human reader. https://github.com/DoctorEww/E… by Panos Gkatziroulis.
- Interesting by kmkz.
- RT : Helper script for this attack https://github.com/Semperis-Community/ResetNightmare by kmkz.
- RT 0xor0ne: 21 bugs in BlueZ Bluetooth Stack (@xchglabs) https://xchglabs.com/blog/bluez-zero-click.html #infosec #bluetooth by kmkz.
- RT @bytecodevm: Windows Application Control (formerly WDAC) blocks binaries that are not signed by an approved authority - but a Microsoft-… by Max.
- RT David Kaplan: Yup. Wrote about these downgrade/model routing attacks a week or so ago if anyone is interested https://www.originhq.com/research/a-p… by Max.
- Incredible research. It’s like an LPE 0-day factory with an on-demand BYOVD when you plug in the USB stick. by Kuba Gretzky.
- RT Shepherd: Bypassing server-side validation on a SaaS target .Spoofed GIF magic bytes inside the JSON payload & tricked the API into signing an AWS … by Rob Fuller.
- This is such a good read. Fantastic sandbox and guardrail escapes and…. “It fell in about five minutes to a straight dictionary word. The password w… by Nikhil Mittal.
- RT Swissky: Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 - Justin Kalnasy - @SpecterOps https://specterops.io/blog/2026/06/… by Nikhil Mittal.
- RT Hors: obfus.h is the very powerfull compile-time obfuscator for C (win32/64). Supports virtualization, anti-debugging, control flow obfuscation and… by Ring3API 🇺🇦.
- Hacking in the age of AI: LLMs, agentic CLIs and MCP servers for Bug Bounty hunters - @yeswehack https://www.yeswehack.com/learn-bug-bounty/llm-bug-bo… by Swissky.
- RT @Cravaterouge.infosec.exchange: Exploit demo on Linux and Patch Analysis of ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177), two Ac… by Swissky.
- WAF Bypasses via h2 framing - Diyan Apostolov (@thefosi) https://lab.ctbb.show/research/h2-WAF-Bypasses by Swissky.
- RT @MauroEldritch: 🇰🇵 We built a fake company. We recruited DPRK IT workers. We recorded everything. The full story is finally out: hour… by scriptjunkie (Matt).
- How Trail of Bits helps verify the integrity of your Signal chats.
- RT Open Source Security mailing list: Re AI+manual analysis of all those Linux kernel CVEs and more by @kerneltoast from @CtrlIQ https://www.openwall…. by Solar Designer.
- RT V12: seems like the is out of the here’s our poc for MariaDB 13 RCE, currently still unpatched: https://github.com/v12-security/pocs/… by ϻг_ϻε.
- RT Byron Wan: ‼ Royal Navy spy drones used by Britain’s elite special forces secretly sent data to China. ‼ The cameras on the K3 Scout surveil… by thaddeus e. grugq.
- RT Andrew Curran: A man in Australia asked his agent (Claude running on OpenClaw) to book him a spot in a popular gym class. The agent found a softwar… by thaddeus e. grugq.
- Some good research got nuked in iOS 27 beta but a great read nonetheless. by Mike Felch (Stay Ready).
- This looks pretty neat. Device emulation to priv esc.. by Mike Felch (Stay Ready).
- RT Smukx.E: A hands-on walkthrough of exploiting a Windows stack buffer overflow and bypassing DEP using a manually crafted ROP chain, leveraging Virt… by Mike Felch (Stay Ready).
- The August 2026 Security Update Review by Dustin Childs.
- The 1Password analysis mentioned in today’s story is worth reading: “By all accounts, AI is quite good at finding security holes in software. But for now at least, patching the resulting bugpocalypse.
- My dear Windows (ab)users! It’s time to get your patch chaps on! Microsoft today shipped updates to fix nearly 400 security vulnerabilities in its various Windows OSes and related software. “August’s.
- I sat down and did some schizo ranting for my attempt at a book I might name “Malware 4 Noobs” (no idea yet). Here is my introduction segment, part ze… by vx-underground.
- siddharth ahuja: URGENT: My Github got hacked and all my ownership rights were stripped. Repositories like Blender MCP (25k stars) and Ableton MCP (2.6k stars) along with personal projects I’m working by vx-underground.
- The timer for #flareon13 started on http://flare-on.com I will likely participate, but not sure I will try to speed-solve it like previous years. Last… by Washi.
- Great work getting this fixed upstream, and great writeup by x86byte.
- goat by devansh.
- Microsoft Patch Tuesday for August 2026 - Snort rules and prominent vulnerabilities by Cisco Talos.
- I really do think harnesses are falling away, but mines still going for now, forgot to add this to the list from Aug 04 CVE-2026-15830 – https://www…. by AndrewMohawk⁽ⁿᵘˡˡ⁾.
- Recent incident in the UK might have many feeling this way: “The most concerning part to me is that in the age of AI where criminals have access to ad… by Black Hills Information Security.
- Sandworm hackers target IT pros with trojanized WireGuard VPN client https://www.bleepingcomputer.com/news/security/sandworm-hackers-target-it-pros-wi… by BleepingComputer.
- Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch-tuesday-f… by BleepingComputer.
- Wesco confirms security incident after ExfilSquad claims data theft https://www.bleepingcomputer.com/news/security/wesco-confirms-security-incident-af… by BleepingComputer.
- Mozilla updates GPG signing key for Firefox releases after exposure https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-signing… by BleepingComputer.
- CISA: Microsoft SharePoint flaw now exploited in ransomware attacks https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-flaw-now-… by BleepingComputer.
- Cisco warns of high-severity ClamAV flaws with public exploits https://www.bleepingcomputer.com/news/security/cisco-warns-of-high-severity-clamav-flaw… by BleepingComputer.
- US and South Korea warn of Gunra ransomware targeting govt agencies https://www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attack… by BleepingComputer.
- BdThemes plugins supply-chain hack creates rogue WordPress admins https://www.bleepingcomputer.com/news/security/bdthemes-plugins-supply-chain-hack-cr… by BleepingComputer.
- RT Azox: Exploit ResetNightmare with NetExec CVE-2026-27912: a logical flaw in the Kerberos Change Password protocol lets an attacker with Generi… by Aurélien Chalot.
- This is an amazing attack https:// plugandpwn.com/.
- 0xaled/vipere: BOF exploiting the Visual Studio Installer Elevation Service for SYSTEM LPE and persistence via AppDomainManager hijacking, with native… by Nicolas Krassas.
- Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee’s Client https://thehackernews.com/2026/08/zoom-annotation-flaws-could-l… by Nicolas Krassas.
- Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-ht… by Nicolas Krassas.
- Cisco warns of ASA and FTD VPN flaw exploited to crash devices https://www.bleepingcomputer.com/news/security/cisco-warns-of-asa-and-ftd-vpn-flaw-expl… by Nicolas Krassas.
- Signal adds an extra layer of security to make sure you’re actually chatting with the right person https://www.theregister.com/security/2026/08/11/sig… by Nicolas Krassas.
- ExfilSquad targets 13 organizations, uses torrents for data distribution https://www.scworld.com/brief/exfilsquad-targets-13-organizations-uses-torren… by Nicolas Krassas.
- RT Enno Rey: HotWire: Real-World Impersonation and Discharge Attacks on Electric Vehicle Charging Systems https://www.usenix.org/system/files/woot26-c… by DirectoryRanger.
- RT Enno Rey: #WOOT26 SoK: Insecurity of Cellular Basebands https://www.usenix.org/system/files/woot26-carnot.pdf [PDF] by DirectoryRanger.
- There’s been a lot of interesting macOS malware recently. All added to the @objective_see sample collection for anyone to poke at. Even a .NET dropper… by L0Psec.
- RT Rami McCarthy: If you are self-hosting Metabase, patch the SQLi urgently. PoCs are being published, so I wanted to share some more details on t… by Giuseppe
N3mes1s. - RT 0xedh: You don’t need a USB. You need to look like one. Emulate the device, Windows fetches a signed package off Windows Update and runs vendor cod… by Oddvar Moe.
- Prompt Injections for Defense by Bruce Schneier.
- Sakerhetpolisen🇸🇪 thwarted Russian🇷🇺 intelligence operation (operation aiming at influencing Swedish decision-making and discrediting Swed… by SwitHak ().
- RT FBI Cyber Division: Gunra ransomware is targeting victims across multiple sectors, including government and critical infrastructure organizations. … by SwitHak ().
- RT M1: Anthropic says new Claude models will embed invisible watermarks in all generated text, everywhere Claude is offered. The watermark is part of … by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders by Gavin Kramer.
- Talk about pushing to prod before a long vacation…this is from the security researcher Prepakis Georgios ( @ kernelstub ), who’s been quite open about hosting and administrating a Matrix chat platfo.
- ERPNext’s Document Follow feature exposed unauthorized data https://robinroy.xyz/blog/frappe-document-follow-vulnerability/ by /r/netsec.
- GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group) https://asset-group.github.io… by /r/netsec.
- Expired DMARC reporting endpoint exposed a NYSE Fortune 1000’s infrastructure for $10 https://www.sh.consulting/blog/abandoned-dmarc-reporting-domain by /r/netsec.
- CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106) https://www.imperva.com/blog/copyescape-taking-over-docker-hosts-wit… by /r/netsec.
- ETW for Security Research: Providers, Sessions, and Detection Engineering https://idov31.github.io/posts/inside-etw-with-etwsuite by /r/netsec.
- Inside a Russian-speaking operator’s toolkit for compromising Ukrainian IP cameras https://hunt.io/blog/russian-speaking-operator-ukrainian-camera-too… by /r/netsec.
- RT David Schmotz: New paper!! We decoded the “encrypted” chain-of-thought of Anthropic, OpenAI and Google models and used this for multiple attacks! E… by Alex Plaskett.
- I keep getting asked the same question lately: Attackers are increasingly running large parts of intrusions with AI agents, and everyone can see the a… by Florian Roth.
- RT Nextron Research : A threat actor continues attempting to push malicious extensions delivering XWorm through the VS Code Marketplace. The … by Florian Roth.
- RT lazarusholic: “Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup” published by @anyrun_app. #ITWorker, #Fam… by Florian Roth.
- RT Brad Spengler: https://www.linkedin.com/pulse/badgarbagec-afunix-container-escape-resurrected-twice-oldani-sicvf/ by Dave Aitel.
- RT Calif: Check out this fascinating story of two macOS Screen Sharing exploits we built over the weekend: https://blog.calif.io/p/no-country-for-old-… by Dominic Chell.
- RT Nick Carr: Russian threat actor Midnight Blizzard is conducting widespread traffic manipulation attacks at hotels worldwide. Result: delivering mal… by Dominic Chell.
- RT Nicolas Krassas: 737 Chrome VPN extensions impersonate brands to hijack browser traffic https://cyberinsider.com/737-chrome-vpn-extensions-imperson… by Simone Margaritelli.
- RT Mathy Vanhoef: This refers to repeatedly connecting using different passwords & optimizing the speed of connection attempts What’s most interesting… by Simone Margaritelli.
- RT Clandestine: Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation… by Simone Margaritelli.
- Interesting findings about how DPRK is leveraging AI in their operations: AI-generated decoys: Generated polished documents for spear-phishing ca… by Thomas Roccia.
- RT Smukx.E: ETW for Security Research: Providers, Sessions, and Detection Engineering. Very good explanation about Etw video by @Idov31 https://youtu…. by hasherezade.
- RT Muqsit 𝕏: Vulnerability discovery in Java applications Blog: https://0xpat.github.io/Vuln_discovery_Java/ Author: @0xPat by hasherezade.
- RT Karsten Hahn: New video: Compiled V8 JavaScript for reversers V8 compilation pipeline bytecode caching how bytenode abuses cach… by hasherezade.
- RT lanadelreyslefthood: Dynamic Analysis of VEH Dispatch and Exception-Context RIP Modification Using ROP Gadgets in ntdll.dll https://mooofin.git… by hasherezade.
- RT domas: Here’s an unassuming tool I’ve been sitting on for a decade. Measure address latency, and timing leaks hardware structure. Unexpectedly us… by hasherezade.
- RT Guillermo Casaus: Acaban de liberar una de las mayores bases de datos de malware en GitHub. Se llama Malware Research Hub y contiene miles de … by hasherezade.
- RT Nextron Research : We identified a cluster of WHQL-signed Windows kernel drivers that all contain the same Authenticode metadata reference: Spc… by hasherezade.
- RT trish: a free tutorial series takes you from an empty boot sector to a working 32-bit protected mode kernel you build the bootloader GDT the A20 li… by hasherezade.
- Extract domain hashes straight out of a Veeam .vbk backup https://github.com/mattmillen15/vbkVomit by Panos Gkatziroulis.
- http://NTUSER.MAN loads into HKCU at logon without RegCreateKey or RegSetValue ever being called, and it needs no admin rights. Two Sysmon r… by Panos Gkatziroulis.
- Win x64 Shellcode – Part 3: PE Structure and Export Directory https://proteqtum.com/posts/03-win-x64-shellcode-pe-export-directory_en/ by Panos Gkatziroulis.
- Pure-impacket parallel local-admin discovery via RBCD https://github.com/nnnnino/rbcdbrute by Panos Gkatziroulis.
- ALPC-Enumerator - A Windows userland tool to enumerate and classify ALPC ports, including PPL-protected processes https://github.com/talha-nazeef-ahme… by Panos Gkatziroulis.
- EtwSuite - Windows native ETW inspection suite for browsing providers, reading metadata, consuming live events, recording ETL traces, filtering result… by Panos Gkatziroulis.
- More data for my lab environment ⤵ EvidenceForge - Generate realistic synthetic security logs for cybersecurity threat hunting training and re… by Panos Gkatziroulis.
- NoiseHound - Detection-aware BloodHound attack-path scoring - find the quietest route to your objective, calibrated across audit/EDR/SIEM tiers https:… by Panos Gkatziroulis.
- RT Rapid7: In July 2026, while conducting a 0-day research project against Microsoft #SharePoint, Rapid7 Labs discovered 2 new vulns that, when c… by Jeff McJunkin.
- RT dbugs: A PoC/exploit has been discovered for vulnerability CVE-2026-26119 Vendor: Microsoft Product: Windows Admin Center Description: Improper aut… by kmkz.
- Two Parsers, One JSON and a Flag: Intigriti’s July 2026 Challenge https:// blog.himanshuanand.com/2026/08 /two-parsers-one-json-and-a-flag-intigritis-july-2026-challenge/.
- RT Sunil kumar: LLMVault 2.0 is here. Two ways to learn. Two ways to break things. Play Mode - CTF-style, guided labs built for learning an… by Max.
- Dissecting the JWR phishing framework by Chetan Raghuprasad.
- A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months https://www. helpnetsecurity.com/2026/08/12 /salesforce-servicenow-guest-user-exposure/.
- you should tune in to this by Caleb Gross.
- RT stoyky: Want to deploy a CAPE sandbox in under 30 minutes? Now you can! Check out the latest update to #Figment : https://github.com/stoyky/figment… by Ring3API 🇺🇦.
- Always interesting to see how macOS malware is evolving, and what stays the same Solid report from @moonlock_com on macOS malware & threa… by Patrick Wardle.
- RT Dhiyaneshwaran: CVE-2026-72898 - Metabase - Unauthenticated SQL Injection Nuclei Template: https://cloud.projectdiscovery.io/library/CVE-2026-… by Nuclei by ProjectDiscovery.
- Successfully Failing As A Reverse Engineer - Max ‘Libra’ Kersten @Libranalysis https://www.youtube.com/watch?v=35JWMENMRjw by Swissky.
- Age of Post-Exploitation - Dima & Pieter Ceelen (@ptrpieter) https://youtu.be/j0T5cYSo7Z0 by Swissky.
- PQC migration update. This is great stuff (yes, I’m biased given my former role) but a few thoughts: 1. Great to see focus on integrity/authentication… by Phil Venables.
- Return of the Cookie Monster by Andrew Gomez.
- Attack of The Extensions by Andrew Gomez.
- From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained https://www. saiflow.com/blog/from-unauthen ticated-api-to-grid-risk-a-hybrid-inverter-vulnerability-explained.
- RT Stephen Fewer: Today we have published the technical analysis and PoC for CVE-2026-55040, the Microsoft SharePoint authentication bypass we disclos… by ϻг_ϻε.
- RT cr3ghost: If you’re writing implants, doing C2 persistence, trying to bypass top tier EDR, or building detections for registry-based persistence te… by thaddeus e. grugq.
- RT JP Aumasson: proof of 0 = 1 in Lean, exploiting a hash collision (weak 32-bit hash Expr.hash/mixhash) https://github.com/endrazine/lean-cve-poc by thaddeus e. grugq.
- RT GangExposed RU: I’m on the BBC. Cyber Hack: The Conti Files is a six-part BBC documentary podcast about Conti. I was interviewed by Geoff White as… by thaddeus e. grugq.
- RT The Record From Recorded Future News: Germany’s cabinet approved legislation that would let its intelligence agencies hack foreign systems, sabota… by Vincent Yiu.
- RT _ZN4DionC1Ev: I’m certainly biased but I really enjoyed Brandon’s @_bazad discussion yesterday in our livestream. He discussed VR, mitigation des… by Axel Souchet.
- Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam https://www. elttam.com/blog/ruby-4-0-unive rsal-rce-deserialization-gadget-chain.
- NEW BHIS | Blog How far would you go to exploit a CVE without a proof of concept? No PoC, No Problem: Rediscovering CVE-2025-29902 in the Telex RD… by Black Hills Information Security.
- AI ‘watermark removers’ flood the web as Anthropic begins marking Claude-generated output. Almost none can prove they work. - @Ax_Sharma https://www.b… by BleepingComputer.
- Critical VMware vCenter RCE flaw exploited for reverse SSH access https://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-expl… by BleepingComputer.
- White House taps security firms for offensive hack-back operations https://www.bleepingcomputer.com/news/security/white-house-taps-security-firms-for-… by BleepingComputer.
- Android malware combo takes out loans and relays victims’ credit cards https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-out-… by BleepingComputer.
- Hackers exploit critical Adobe Commerce flaw to hijack customer accounts https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-adobe… by BleepingComputer.
- Hundreds of fake Chrome VPN extensions route traffic through a proxy https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-extens… by BleepingComputer.
- Lazarus hackers exploited Windows zero-day to target defense firms https://www.bleepingcomputer.com/news/security/lazarus-hackers-exploited-windows-ze… by BleepingComputer.
- <3 out to my peers doing work in this absolutely absurd attack surface. I thought this would be long dead when I gave a presentation at DerbyCon about… by Michael Weber.
- PhishU Framework now supports text-based QR codes! Based on some research by researchers from Kaspersky, I decided to bake this in by default, replaci… by 𝐂𝐮𝐫𝐭𝐢𝐬 𝐁𝐫𝐚𝐳𝐳𝐞𝐥𝐥.
- Time for #DenialOfPleasure attack https://www.whid.ninja/blog/denial-of-pleasure-attacking-unusual-ble-targets-with-a-flipper-zero by Luca Bongiorni.
- GeoServer jsonArrayContains SQLi -> PostgreSQL RCE python PoC https://gist.github.com/portbuster1337/70d75ec246b85e3199037ce212ff1a06 by Nicolas Krassas.
- Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with… by Nicolas Krassas.
- Ukraine shuts down 94 fraudulent call centers, seize millions in cash https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudulent-… by Nicolas Krassas.
- Loongson processors vulnerable to LoongLeak cache attack https://www.scworld.com/brief/loongson-processors-vulnerable-to-loongleak-cache-attack by Nicolas Krassas.
- Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notif… by Nicolas Krassas.
- Timor-Leste Raids Expose Growing Transnational Cyber-Fraud Network: Hundreds of Foreigners Detained as Scam Centers Relocate https://ministryofcyberaf… by Nicolas Krassas.
- Microsoft patches LegacyHive Windows zero-day vulnerability https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-… by Nicolas Krassas.
- Self-contained malware research hub: curated catalog of 80 families (1971-2024) + 2,764 real encrypted samples, indexed and searchable. Local Flask ap… by Nicolas Krassas.
- RT 秋风: 实话说今天是非常不开心的一天 实际上最近一段时间我都非常沮丧 各种事情 所以我公布一个0day 希望让你们心情变的开心 GeoServer jsonArrayContains 未… by Nicolas Krassas.
- RT @Enno_Insinuator: Beats Studio Buds: Insecure Pairing Window, via @ttdennis on @Insinuator https://insinuator.net/2026/08/beats-studio-buds-insecur… by DirectoryRanger.
- Talks & resources from the #TROOPERS25 AD & Entra ID Security track, on @Insinuator, featuring @dirkjan, @DrAzureAD, @al3x_n3ff, @sapirxfed, @Thomas… by DirectoryRanger.
- Hayabusa. Windows event log fast forensics timeline generator and threat hunting tool. BlackHat Arsenal USA 2026 Release https://github.com/Yamato-Sec… by DirectoryRanger.
- Holy Shuck! Weaponizing NTLM Hashes as a Wordlist https://trustedsec.com/blog/holy-shuck-weaponizing-ntlm-hashes-as-a-wordlist by DirectoryRanger.
- wbadmin NTDS.dit dump detection for Domain Controllers #DFIR https://www.securityinbits.com/detection-engineering/wbadmin-ntds-dit-dump-detection/ by DirectoryRanger.
- Taps the sign by Nick Frichette.
- Looks like new threat notifications went out. A lot of great details in this thread by @jsrailton. by L0Psec.
- RT BINARLY: Can AI hack firmware? We gave frontier LLMs compiled UEFI modules and our VulHunt binary-analysis framework, and asked them to find vu… by Giuseppe
N3mes1s. - RT Dr Heidy Khlaaf (هايدي خلاف): With Anthropic announcing auto-mode as the new default setting, and AI labs touting defensive AI as the only… by Giuseppe
N3mes1s. - RT Gareth Heyes \u2028: I stole an Outlook password with nothing but CSS inside an email Whitepaper below by PortSwigger Research.
- RT Tom Stacey: Did you know you can use HTTP header injection to trigger response queue poisoning and make it rain credentials? Learn how with the new… by PortSwigger Research.
- RT Tech Brandon: You aren’t properly protecting your Entra Connect. It straddles two trust boundaries, but most orgs don’t give it the Tier 0 attentio… by Sean Metcalf.
- RT Coontzy1: So, if you don’t need a signed payload… you can serve whatever you want with wsuks https://github.com/NeffIsBack/wsuks Cool blog and fi… by S3cur3Th1sSh1t.
- really proud of this one, i was stuck a while on solving the filesystem persistence issue which all the previous citrix research were pointing to “pro… by SinSinology.
- RT Janggggg: https://testbnull.medium.com/hunting-exchange-server-0day-like-a-detective-3fd5e0dc9779 Some note of recent Exchange Server Pre-Auth RCE!… by SinSinology.
- RT Adam G: Intune 2607 introduces Controlled Configuration for Microsoft Defender antivirus settings in preview. When enabled, Defender settings deliv… by SwiftOnSecurity.
- I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it … by /r/netsec.
- You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs https://labs.watchtowr.com/youre-back-in-the-room-citrix-ne… by /r/netsec.
- When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg https://maldbg.com/interlock-esxi-decryptor-internals by /r/netsec.
- Can AI do novel security research? Meet the HTTP Terminator https://portswigger.net/research/can-ai-do-novel-security-research by /r/netsec.
- RT Aziz Farghly : some samples : related to this campaign Troy Backdoor loader : 3a0bf3cf54f9e704c9350666ac854abce129c4e413070a6e2c7e7b28c623d744 fo… by Florian Roth.
- RT Megatron: Overserved Few more Hashes likely related to “Sassy Code Campaign” c79021247a0375c5316c47d6faebf994799fc8bbfb43009fe73f260957747829 a090f… by Florian Roth.
- RT Nextron Research : We discovered DPRK-linked NullReceiver loaders in two infected GitHub repositories. The samples reuse the Ethereum wall… by Florian Roth.
- RT 0x0さん: Windows kernel pool internals are a goldmine for vulnerability researchers. Large pool allocations have page-aligned addresses and can lan… by Florian Roth.
- RT 7h3h4ckv157: You Don’t Need Mimikatz for DCSync Anymore (SharpDCSync) Credit/Resource: https://lsecqt.github.io/Red-Teaming-Army/active-directory/y… by Florian Roth.
- RT Margin Research: New blog post up for your Friday afternoon reading: https://margin.re/2026/08/analyzing-iranian-russian-uav-touchpoints-and-innova… by Dave Aitel.
- RT Trail of Bits: PATCH THE PLANET BUG SPOTLIGHT: We found a medium-severity bug in aiohttp, Python’s HTTP engine that had 600M+ downloads last month…. by Dave Aitel.
- RT joshua steinman (🇺🇸,🇺🇸): Wake up babe the new @WhiteHouse cyber privateering construct just dropped https://www.whitehouse.gov/presiden… by Dave Aitel.
- RT 0x12 Dark Development: Process Parameter Poisoning New Medium post. In this one we will see a process injection technique published by SensePost th… by Arun.
- RT SpecterOps: AI coding agents leave a lot behind on endpoints. Consulting Services intern @atomiczsec built Blacklight to show defenders exactly wha… by Arun.
- This reminds me of “Ashley” Initial Access Framework, some great ideas and love the integration to Mythic, amazing project!! by David.
- RT Nicolas Krassas: Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-ga… by Simone Margaritelli.
- RT Olivia Gallucci : If anyone wants to see my @BlackHatEvents talk, it was uploaded to YouTube! https://www.youtube.com/watch?v=x6vr4GWToYc by Gergely Kalman.
- RT msuiche: I’ve implemented projective mode for control vectors; ablating a direction out of the residual stream instead of adding one to it. 478 KB … by Halvar Flake.
- RT yed: We discovered a Rootkit version of CoolClient by Mustang Panda in Pakistan, Mongolia, Myanmar, and Russia. The kernel-mode driver of CoolClien… by hasherezade.
- RT Elias Bachaalany: GhidraSQL, all you need to know. One of my longest videos, and deservedly so. Some topics are better served by being complete tha… by hasherezade.
- RT Anton: Another U-Boot Verified Boot bypass, this time in the SPL code! Take a look at how we achieved arbitrary code execution on a real device run… by hasherezade.
- RT B1lal: During our research we found a new Condi -Mirai variant IoT botnet infrastructure. Payloads for every architecture are still live. The confi… by batuu.
- Abusing Windows Access Controls https://www.corporalbugz.com/post/whos-afraid-of-the-big-bad-wolf/ by Panos Gkatziroulis.
- RT diversenok: New blog post: “On COM/WinRT Initialization, Apartments, and lpacCom Capability Bypasses, Part 1” The series discusses a capability tha… by Panos Gkatziroulis.
- [RT The DFIR Report: Two indicators from a case we are actively investigating: rezbackcup[.]blob[.]core[.]windows[.]net frontend148[.]blob[.]core… by Jeff McJunkin.
- RT MagicSword: “Does my SIEM detect this?” Most testing tools are built around that question. Magic-Atomics flips that. Does your prevention actually … by Chihuahua in charge NotMe.
- I heard artifactory is hot now https://www.netspi.com/blog/technical-blog/red-teaming/stealing-the-artifact-jfrog-artifactory-vulnerability/ by Vylegzhanin Daniil.
- RT 0xor0ne: CVE-2026-20182: Cisco Catalyst SD-WAN Controller auth bypass https://rapid7.com/blog/post/ve-cve-2026-20182-critical-authentication-bypass… by kmkz.
- RT cr3ghost: One of the most talented reverse engineers in the industry that keeps his techniques private due to the industry. Highly recommend readin… by kmkz.
- RT Nicolas Krassas: GeoServer jsonArrayContains SQLi -> PostgreSQL RCE python PoC https://gist.github.com/portbuster1337/70d75ec246b85e3199037ce212ff1… by kmkz.
- RT Alejandro Ramos: I have published a Proof of Concept for the security note CVE-2026-24031: Dovecot SQL authentication bypass (authentication + user… by kmkz.
- RT MagicSword: New entry in LOLDrivers: KKYUM.sys This driver exposes unauthenticated IOCTLs wrapping MmCopyVirtualMemory, no privilege checks, no acc… by kmkz.
- RT cr3ghost: An undocumented ETW flag guards some of Windows’ most interesting security telemetry. Connor McGarr (@33y0re) found a way to consume Micr… by kmkz.
- Again: Keep it stupid simple -> it works by kmkz.
- RT Nicolas Krassas: CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix https://blog.himanshuanand.com/2026/08/i-found… by kmkz.
- RT Alejandro Ramos: I’ve published a proof of concept for CVE-2026-68138, race condition in the Linux kernel’s traffic-control subsystem (net/sched)… by kmkz.
- Finding Hidden Internal Apps Through Public Certificate Logs https:// naveensrinivasan.com/posts/202 6-08-07-finding-hidden-internal-apps-through-public-certificate-logs/.
- RT Ru Campbell: New video: device-bound vs. syncable passkeys in Microsoft Entra • technical differences e.g. private key handling • where Microsoft… by Max.
- Thirteen modules in this week’s wrap-up! Get it here: https://rapid7.com/blog/post/pt-metasploit-wrap-up-lot-of-summer-shells-and-fit-http-profiles/ by Metasploit Project.
- I have finally started working on the official Evilginx cookie manager extension for Chrome. Over the years, I recommended either EditThisCookie,… by Kuba Gretzky.
- RT Jason Koebler: A person representing themselves in court hid a prompt injection attack in a filing asking an AI system to side with them. Really go… by nyxgeek.
- RT Moonlock Lab: 1/ DPRK’s Contagious Interview campaign is still running, the infrastructure is rotating often, and the payload is aimed at Mac users… by Patrick Wardle.
- RT Moonlock by MacPaw: A fake macOS update that takes over your entire screen, then asks you to paste a “verification code” into Terminal. Real macOS … by Patrick Wardle.
- RT Harald Monihart: It was a blast to have been part of this amazing conference #OFTW by Patrick Wardle.
- Jamf has uncovered another macOS stealer that they’ve dubbed “Amnesia” Just added the sample to the @objective_see Foundation’s free/public m… by Patrick Wardle.
- Disposable Tooling: Building LLM-Generated Mythic Agents from Prompt to Deployment - @xpn https://specterops.io/blog/2026/06/24/disposable-tooling-b… by Swissky.
- Windows 11 Hibernation on ARM64: the Boot Manager, winresume, and the hiberfil.sys Format - @msuiche https://www.msuiche.com/posts/windows-11-arm64-hi… by Swissky.
- A backdoor in a LinkedIn job offer - @rdotpy https://roman.pt/posts/linkedin-backdoor/ by Swissky.
- RT Émile Fugulin: Re @BugBountyDEFCON @busf4ctor Slides and instructions: https://github.com/Sytten/defcon2026 by Swissky.
- Blog post alert Arm64/Arm64e internals Stack masking on Apple Silicon @MDSecLabs https://www.mdsec.co.uk/2026/08/arm64-stack-internals-and… by sabotage.
- RT Kostas: The amount of endpoint visibility coming out of Computer History (new Codex feature) is kinda wild. Some EDR vendors might be getting jealo… by thaddeus e. grugq.
- RT The Insider: German counterintelligence warns of Russian Matryoshka bot campaign before September’s state and local elections “Using sensationali… by thaddeus e. grugq.
- RT John Wang: Anthropic started watermarking Claude’s output. I did a little investigation into what method they used: https://johnjwang.com/post/202… by thaddeus e. grugq.
- RT International Cyber Digest: ‼ BREAKING: Security researchers have uncovered all of those who fell victim to the LiteLLM supply chain attack … by thaddeus e. grugq.
- > be me > get dm > its my friend @Intel80x86 > author of @HyperDbg > wtf i love him > open message > “smelly i got goop” > wtf i love goop > “i found … by vx-underground.
- RT Maher Azzouzi: VsockDrop: unprivileged Linux kernel LPE in the io_uring/vsock zerocopy path, no user namespaces needed. Bug affects Linux 6.7 -> 7…. by Vincent Yiu.
- RT SpecterOps: Cookie theft got harder. Browser hijacking didn’t. @KingOfTheNOPs shows how enabling the Chrome DevTools Protocol inside a live Chrome/… by Rio.
- APT36 Suspected in PATCHCORD Espionage Campaign Using Google Sheets C2 https://securityaffairs.com/197266/intelligence/apt36-suspected-in-patchcord-es… by Nicolas Krassas.
- phaedra: coverage-guided fuzzer that uses a local LLM to bootstrap seeds for undocumented binary formats https://github.com/zaydmulani09/phaedra by Nicolas Krassas.
- SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild https://securityaffairs.com/197244/security/sap-commerce-cloud-cve-2026-58231-exploited-in-the… by Nicolas Krassas.
- HTB: Cobblestone https://0xdf.gitlab.io/2026/08/15/htb-cobblestone.html by Nicolas Krassas.
- Finding Hidden Internal Apps Through Public Certificate Logs https://naveensrinivasan.com/posts/2026-08-07-finding-hidden-internal-apps-through-public… by Nicolas Krassas.
- New Evooo1Bot Linux botnet turns routers into traffic relay nodes https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-rout… by Nicolas Krassas.
- ChainDrop worm crawls into npm supply chain, evades standard defenses https://www.theregister.com/security/2026/08/15/chaindrop-worm-crawls-into-npm-s… by Nicolas Krassas.
- RT EXPMON: Interesting… My analysis showed that the second detected sample (https://pub.expmon.com/analysis/328599/, 323bea300e26482070c0edf1dfa1df8… by Haifei Li.
- RT incendiumrocks: New blog: Hitting AI safeguards/guardrails for cybersecurity work on frontier models is annoying, therefore this blog builds an und… by S3cur3Th1sSh1t.
- RT SSSCIP Ukraine: The Invisible Threat: Russian Hackers Exploit WinRAR and MS Office Flaws to Target Ukraine’s Public Sector https://cip.gov.ua/… by SwitHak ().
- CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling https:// minanagehsalalma.github.io/CVE -2026-6837-zyxel-export-cgi-command-injection/.
- “DeltaWifi” it’s called. Excellent. No notes. https:// github.com/sensepost/hostapd-m ana/releases/tag/2.12.
- CVE-2026-33696: From a Schema Name to RCE in n8n https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce by /r/netsec.
- RestrictSetThreadContext is what I’d call a phantom mitigation. There’s a bit for it in EPROCESS.Flags2, and there’s a check for it in nt!NtSetContext… by winterknife.
- RT J4X: Really interesting research from Anthropic on using multi-agent systems for vulnerability research: https://www.anthropic.com/research/multiag… by Alex Plaskett.
- RT Eyal Sela: A threat actor used Claude Code with Sonnet 4.6 as part of an intrusion, likely for ransomware. Sonnet took on many tasks, like writing … by Florian Roth.
- RT 𝕡𝕨𝕟𝕚𝕖: North Korea has exploited the same Windows driver four times in four years. afd.sys, the Ancillary Function Driver for W… by Florian Roth.
- RT Adel Ka: i believe more in proper investigation methodology and agent design/workflow than in which model you use.. especially now that most models… by Dave Aitel.
- RT MDSec: Synthetic frames on macOS? @saab_sec brings call stack spoofing to macOS https://www.mdsec.co.uk/2026/08/arm64-stack-internals-and-obfu… by Dominic Chell.
- RT Omri Baso: 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗖𝗼𝗻𝗳𝗶𝗴𝘂𝗿𝗮𝘁𝗶𝗼𝗻 𝗠𝗮𝗻𝗮𝗴𝗲𝗿 𝗥𝗖𝗘 𝟬… by Dominic Chell.
- RT watchTowr: You’re back in the room, trapped with us - and a Citrix NetScaler Pre-Auth RCE (CVE-2026-8452) Enjoy… https://labs.watchtowr.com/youre… by Dominic Chell.
- RT Quang Vo: I wrote a short blog post about capability of Chrome Debugging Protocol in Red teaming. My favorite caps are probably Browse as victim an… by Dominic Chell.
- This video from @LiveOverflow is pretty nice! And I agree with him the zero days are impressive but the agent to agent communication channel created b… by Thomas Roccia.
- RT Tal Be’ery: The Nearest Neighbor Attack: A Unicorn or an Iceberg? Revisiting the single public sighting of one of the most sophisticated Wi-Fi base… by Halvar Flake.
- RT Pavel Yosifovich: New video: Process Memory Map in Code (Part 1). VMMap shows you a process’s memory layout from a GUI. This time I build a similar… by hasherezade.
- RT GangExposed RU: 1/5 I have something new on LockBitSupp. This is Evgeny Dementyev - the leader of LockBit. Instagram username: dementev23 Photo fro… by hasherezade.
- RT Blackstorm Security: Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse: https://www.akamai.com/blog/security-research/bring-your… by hasherezade.
- RT Arthur “Gerhart” Khudyaev: There is another way to load unsigned driver without bcdedit /set testsigning option in Windows 11, but without enabled … by hasherezade.
- From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193) https:// zerolabs.rubrik.com/blog/break ing-m365-copilot-sandbox-chatmate.
- They patched their SaaS and left the self-hosted OSS version vulnerable - AppFlowy Authenticated SQL Injection https:// projectblack.io/blog/appflowy- authenticated-sql-injection/.
- WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking https://www.varonis.com/blog/ws-trust-autologon-endpoint by Panos Gkatziroulis.
- KaplaStrike - A Cobalt Strike RL built with Crystal Palace; module overloading, NtContinue entry transfer, call stack spoofing, sleep masking, and sta… by Panos Gkatziroulis.
- RPC-Triage - A zero-symbol static analysis engine that extracts and mathematically ranks the Windows RPC attack surface using an AHP-based risk model…. by Panos Gkatziroulis.
- Some late night expirements of executing code via MessageBoxIndirectW API. by Panos Gkatziroulis.
- RT Ham Radio Village: The first talk from HRV @ DC34 has dropped on our YouTube! Come check out @Jon - K4CHN talk about Meshtastic! https://www.youtub… by Chihuahua in charge NotMe.
- #CVE-2026-73683: #Laravel Socialite No nonce validation. Capture a victim Facebook “id_token”, r… by kmkz.
- RT Clandestine: GitHub - franckferman/ping-007: Covert ICMP C2 framework - AES-256-GCM stealth exfil, OS ping mimicry (Linux/Windows), multi-packet re… by kmkz.
- RT Co11ateral: SCCM - Remote Code Execution (CVE-2026-47301) Exploit chain (CVE-2026-47301) for Microsoft Configuration Manager (SCCM), combining a br… by kmkz.
- RT blackorbird: A lightweight (~12 KB) custom Windows backdoor, nicknamed “KB-Backdoor,” was discovered masquerading as a legitimate Realtek audio c… by kmkz.
- RT Alejandro Ramos: This is my third Proof of Concept (PoC) for privilege escalation in Linux. In this case, it comes from a commit that fixes the pro… by kmkz.
- RT hackyboiz: [Wipeload Project - Step 8] Chrome Full-Chain Exploitation Time to complete the Full Chain In this final step, we take the Me… by kmkz.
- RT Eugene Kaspersky: HoneyMyte (a.k.a. Mustang Panda) upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit https://kas.pr/sv8c by kmkz.
Tools and Exploits
MCP server for NetExec enables AI agents to interact with the post-exploitation framework while operators focus on the compromise path. Works with both small and large models.
- Binary Ninja Diffing Plugin Released by L0Psec.
New Binary Ninja plugin for diffing binaries across CFG, disassembly, and all IL levels. Save and restore diffs, port function names between binaries.
SpecterOps releases tools and resources for the Pass-the-Passkey family of attacks targeting WebAuthn and FIDO2 authentication in Windows environments.
MCP server for HyperDbg enables AI-assisted kernel debugging and hypervisor-level analysis workflows.
Dreadnode benchmarks Kimi K3 against frontier models on offensive security tasks. K3 doubles performance in web app pentesting, crypto, and reversing compared to earlier versions.
- LUKSbox v0.5.1: TPM 2.0 Hardware Keyslots on Windows by hasherezade.
LUKSbox gains TPM 2.0 hardware keyslots on Windows via TBS. No driver, no admin rights. Vault keys can now live in real hardware on every desktop OS.
Black Hat Arsenal release from Yamato Security. Sigma-based threat hunting and fast forensics timeline for cloud logs.
New releases of Process Explorer, Process Monitor, PsPing, ZoomIt, CoreInfo, RDCMan, and NotMyFault with new features and bug fixes.
First serious macOS/Linux implant with a COFF loader. Enables cross-platform post-exploitation with Beacon Object File support on non-Windows targets.
Alongside GLM-5.3, the OpenVuln project launches on Hugging Face. Submit any public GitHub repo for automated vulnerability scanning powered by open models.
More this week (30)
- RT Yamato Security Tools: Just released Hayabusa v4! csv-timeline and json-timeline commands have been consolidated into a single dfir-timeline comman… by Max.
- “In the most serious case an agent tried to insert malicious code into an open-source project…. the agent engaged in social engineering - creating fa… by Kim Zetter.
- Today I updated iOS Security Suite, my iOS runtime protection library Changelog, version 2.3.0: * New jailbreak detection checks added (thx Rohan… by Wojciech Reguła.
- Titanis v0.9.330 => https://github.com/trustedsec/Titanis/releases/tag/v0.9.330 Featuring support for Kerberos ticket forging, FAST armoring, and seve… by codewhisperer84.
- RT Seongsu Park: Amazing research led by NIS in collaboration with South Korean security vendors has been released on Lazarus campaign. After reading … by Dave Aitel.
- At @BlackHatEvents we released a new version of NOVA the open source prompt pattern matching for AI! On the project page, you can now use a playg… by Thomas Roccia.
- RT Md Ismail Šojal : Open-source OffSec model for local Run, A 35B MoE (only 3B active) specifically for autonomous real offensive security a… by Florian Roth.
- RT Patrick Wardle: Re Also released a new version of “RansomWhere?” that you can grab (for free!) from the @objective_see website: https://objective-s… by Howard Oakley, Eclectic Light Co.
- Apple has just released security updates for 26.6.1, 15.7.9 and 14.8.9 https://eclecticlight.co/2026/08/06/apple-has-just-released-security-updates-fo… by Howard Oakley, Eclectic Light Co.
- RT Patrik Grobshäuser: so Mythos scanned a thousand open source projects and WordPress wasn’t one of them? new blogpost with some thoughts on in… by shubs.
- RT cr3ghost: Re If you want every SpecterOps open source tool in one place, they published a full documentation index. BloodHound, GhostPack, Mythic a… by Chihuahua in charge NotMe.
- RT cr3ghost: Three zero-days in Windows 11 and Microsoft Entra ID. Over 20 novel attack techniques against passkeys. Toolkit open sourced. Microsoft d… by Rémi GASCOU (Podalirius).
- RT Alexandre Borges: As promised, I will continue maintaining the Malwoverview project, which has been created 8 years ago. Malwoverview version 8.1.0… by Max.
- RT OpenAI: We’re expanding our cybersecurity initiative Daybreak and introducing GPT-5.6-Cyber, a new model for advanced, authorized cybersecurity wo… by Swissky.
- RT Open Source Security mailing list: CVE-2026-64561,Zapscape: Linux kernel: Guest-to-Host Escape in KVM/x86 https://www.openwall.com/lists/oss-securi… by Solar Designer.
- RT Open Source Security mailing list: CVE-2026-64564: Linux kernel: SCTP ASCONF transport UAF leading to local privilege escalation and container esca… by Solar Designer.
- RT Open Source Security mailing list: CVE-2026-64531,OVSwrap: Linux kernel: Local root vuln in Open vSwitch datapath https://www.openwall.com/lists/os… by Solar Designer.
- RT Jacob Bartlett: Apple’s internal private frameworks are basically open-source thanks to MachOSwiftSection, which lets you reverse-engineer and insp… by Gergely Kalman.
- RT Ashar Javed: WordPress 7.0.4 is now available, and it fixes an RCE. First of all, credit to @pwn_ai, who reported this vulnerability before I did. … by Mayuresh 🇮🇳.
- RT Lukasz Olejnik: Releasing a multi-month work today! We conducted the first fully autonomous information operation (under controlled conditions). It… by thaddeus e. grugq.
- RT fr0g: Last year @trailofbits won second place in the AIxCC and released buttercup. It’s a tool they built during the challenge and released. I took… by thaddeus e. grugq.
- RT pwn.ai: WordPress just released another emergency update (after XSS2Shell) patching another RCE chain reported by @pwn_ai: CVE-2026-65640 https://w… by Paulos Yibelo.
- Google released Gemini 3.7 Flash today, so I immediately ran it through my THOR Finding Triage Benchmark. And… we have a new #1. By quite some distan… by Florian Roth.
- RT shane: We’ve got some research on how a “guardian model” operates in this sort of context along with an open-source dataset so you can try it out y… by dreadnode.
- I missed this when it was posted, but @Antonlovesdnb released a new tool (ATEN) to enhance endpoint visibility for AI agents. Well done! https://… by Panos Gkatziroulis.
- if you don’t trust the big mega corp with your data - try Screenlogger. Open source and completely local. https://github.com/radkawar/screenlogger by Rad.
- Docker lab reproducing CVE-2026-71362 (Adobe Commerce / Magento Open Source customer-session identity-switch account takeover, APSB26-92, CVSS 9.1) ht… by Nicolas Krassas.
- Apache IoTDB v2.0.10 pre-auth/unauth attack-surface validation lab + reproducible PoCs (0day RCE) https://github.com/dinosn/iotdb-2.0.10-security by Nicolas Krassas.
- RT ThreatWire: PoC RELEASED: Public exploit code is now available for CVE-2026-47301, a CVSS 8.8 privilege escalation flaw in Microsoft Configura… by CCob.
- RT Open Source Security mailing list: rsync 3.5.0 released with fixes for 33 CVEs https://www.openwall.com/lists/oss-security/2026/08/13/1 by Dave Aitel.
