A roundup of 429 items curated from across the security community.

News

Hackers arrested for exploiting a service provider flaw to steal over 30 million euros through bank fraud.

LiveOverflow’s reaction to the OpenAI Black Hat talk on AI agents finding vulnerabilities and moving laterally. Explores the implications for defenders.

The Gold Eagle vulnerability clearinghouse is meant to rescue vuln management from an AI-fueled discovery crisis. Experts question whether it has the capacity and redundancy to deliver.

Creators harmj0y, wald0, and CptJesus celebrate a decade of BloodHound with a two-part retrospective on attack graphs and what comes next.

New details on how French police hacked the EncroChat cryptophone network using malware sourced from GitHub. Raises the question: how do you defend against an adversary that can seize your private keys and change your DNS?

Russian authorities arrested an IT specialist over crypto donations to Ukraine. Binance provided extensive account data including IDs, transactions, logins, and device info to Russia’s Investigative Committee.

Hunt.io documents over 14,000 Dahua cameras compromised across Ukraine and Russia as part of a coordinated surveillance operation.

Z.ai’s GLM-5.3 demonstrates emergent security capabilities, discovering 1,097 critical and high severity bugs across kernels, browsers, and infrastructure. Oldest flaw dates to 1981.

Follow-up analysis reveals three North American MSPs serving seven of the top ten US hotel chains were compromised. Activity from Las Vegas IP addresses appeared in the weeks before Black Hat and DEF CON.

x33fcon talk now on YouTube. Explores gaps in Microsoft’s Secure Edge network security model and what attackers can still reach.

More this week (54)

Techniques and Write-ups

Kernel code execution achieved via IDT table hijacking on Windows 11 with VBS, HVCI, and kCET enabled. Alex Ionescu notes HLAT/HVPT mitigates this class of attack.

Run a fake MDM server and gain SYSTEM with two clicks on targets that have permission to elevate. PoC included in the AmberWolf blog post.

Csaba Fitzl used Claude to find CVE-2026-43774, a memory corruption vulnerability in macOS Spotlight’s PostScript parser. Fixed in macOS 26.6.

Wiz research on detecting and outsmarting attackers who abuse Entra device registration for persistence and lateral movement.

Academic paper exploring Apple’s Secure Page Table Monitor, TXM, and Exclaves architecture on modern iOS. Covers the internal security boundaries protecting the kernel and its trusted extensions.

New PoC from daem0nc0re for executing SYSTEM processes via scheduled task registration, extending the ArtsOfGetSystem privilege escalation toolkit.

Runs an entire Tailscale daemon from memory inside a C2 implant. Zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, with relay connections back through the tailnet.

Check Point research shows how Defender’s signed BTR.sys driver can be abused as a kernel primitive to bypass Tamper Protection, delete EDR components before boot, and gain persistence without any vulnerability or BYOVD.

Yarden Shafir’s talk on exploiting I/O Rings on Windows and the mitigations Microsoft has built to counter the technique. Full recording now on YouTube.

Signed Google Chrome installers can be abused to achieve arbitrary code execution on target systems. Full writeup from AmberWolf.

More this week (331)

Tools and Exploits

Public exploit for CVE-2026-47301 (CVSS 8.8) in Microsoft SCCM. Chains improper access control into domain user to SYSTEM code execution on the primary site server.

Full workshop materials from DEF CON 34 and BSidesLV. Covers malware development, EDR architecture, evasion techniques, C2 customization, and kernel-level approaches.

Launches from a one-liner, visualizes scan results in real-time in the browser. Designed to answer one question: is this computer compromised?

Updated DreadIndex benchmarks Kimi K3 against frontier models on offensive security tasks. K3 doubles performance in web pentesting, crypto, and reversing over earlier versions.

All talks from the Objective-See Foundation’s OFTW v4 event in Berlin are now available on YouTube. Beginner-friendly Apple security content.

Public PoC for CVE-2026-56197, a command injection vulnerability in Windows Admin Center. Exploitable over the network by an authorized attacker.

Semgrep evaluates GLM-5.3 for vulnerability detection. Open-weight models are challenging frontier labs on cost-per-vulnerability found, though they still use more tokens.

Apple patches a batch of WebKit bugs disclosed by itszn. Update Safari now.

Red team PoC using Windows Filtering Platform to temporarily block EDR outbound connections, with detection strategies and Event ID guidance for defenders.

The latest volume of the underground security zine. 21 papers covering viruses, rootkits, ELF internals, weird machines, and more.

More this week (14)