A roundup of 429 items curated from across the security community.
News
Hackers arrested for exploiting a service provider flaw to steal over 30 million euros through bank fraud.
LiveOverflow’s reaction to the OpenAI Black Hat talk on AI agents finding vulnerabilities and moving laterally. Explores the implications for defenders.
The Gold Eagle vulnerability clearinghouse is meant to rescue vuln management from an AI-fueled discovery crisis. Experts question whether it has the capacity and redundancy to deliver.
Creators harmj0y, wald0, and CptJesus celebrate a decade of BloodHound with a two-part retrospective on attack graphs and what comes next.
New details on how French police hacked the EncroChat cryptophone network using malware sourced from GitHub. Raises the question: how do you defend against an adversary that can seize your private keys and change your DNS?
- Binance Gave Russia Crypto Account Data Leading to Arrest by thaddeus e. grugq.
Russian authorities arrested an IT specialist over crypto donations to Ukraine. Binance provided extensive account data including IDs, transactions, logins, and device info to Russia’s Investigative Committee.
Hunt.io documents over 14,000 Dahua cameras compromised across Ukraine and Russia as part of a coordinated surveillance operation.
Z.ai’s GLM-5.3 demonstrates emergent security capabilities, discovering 1,097 critical and high severity bugs across kernels, browsers, and infrastructure. Oldest flaw dates to 1981.
Follow-up analysis reveals three North American MSPs serving seven of the top ten US hotel chains were compromised. Activity from Las Vegas IP addresses appeared in the weeks before Black Hat and DEF CON.
x33fcon talk now on YouTube. Explores gaps in Microsoft’s Secure Edge network security model and what attackers can still reach.
More this week (54)
- RT /ˈziːf-kɒn/: #x33fcon 2026 talks: @k3vinTell & @RWXstoned - DDD: DCOM, DotNet, Deserialization > https://youtu.be/lQD_Pz4IR5A by Rob Fuller.
- Your AI Just Leaked a Secret - Yunus Aydın @aydinnyunuss https://aydinnyunus.github.io/2026/06/30/hunting-leaked-secrets-on-github-archive/ by Swissky.
- RT Bill Marczak: Wow: turns out there’s source code overlap between the leaked code from Geedge Networks and China’s Great Firewall! (Same DNS and RS… by thaddeus e. grugq.
- RT Dr. Dan Lomas: 2 ex-Chinese military personnel arrested in South Korea for alleged espionage https://apnews.com/article/south-korea-china-us-espion… by thaddeus e. grugq.
- Hacker claims 3.6 million Azure account records stolen from major companies https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-az… by BleepingComputer.
- French tax authority data breach affects 678,000 individuals https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-6… by BleepingComputer.
- SafePal data breach impacts 39,798 customers, stolen info for sale https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-c… by BleepingComputer.
- Heights Finance data breach: What customers need to know https://www.malwarebytes.com/blog/data-breaches/2026/08/heights-finance-data-breach-what-cust… by Nicolas Krassas.
- Pokémon Center data breach exposes customer info, cancels some orders https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-expos… by Nicolas Krassas.
- RT Enno Rey: Very interesting read: “Oh, what people would do with my knife?” Navigating the Dual-Use Dilemma in PoC Exploit Development, Disclosure… by DirectoryRanger.
- RT Co11ateral: Abusing Printers to Compromise Active Directory Printers are easy targets that can store AD credentials. If the DC is vulnerable, then … by DirectoryRanger.
- RT b0yd: While we wait for my 0days to reach 90 day disclosure deadlines, here’s a really fun memory corruption to root RCE in ClamAV via the ZendTo s… by Giuseppe
N3mes1s. - Today I had to face a server compromise starting with a WordPress site affected by CVE-2026-18322. I have been analyzing the vuln and writing an explo… by Peter Gabaldon.
- RT Robert Graham: Sidejacking for the next generation. “Sidejacking” was the thing I demonstrated 20 years ago at Black Hat. Back then, websites use s… by SwiftOnSecurity.
- RT Chris Myers: Claude Sonnet 4.5 fully compromised GOAD on 7/12 runs. It “captured the flag”, and traditionally we’d view this as success! But add ev… by Rasta Mouse.
- I wrote an article on some of my talk highlights from this year’s BlackHat and DEFCON! https://www.nccgroup.com/research/postcards-from-las-vegas-bla… by Alex Plaskett.
- RT cr3ghost: Citrix admins, your weekend plans just changed. CVE-2026-8452 was disclosed as a NetScaler memory overflow / DoS. Now @watchtowrcyber has… by Florian Roth.
- ICE Collecting DNA Samples by Bruce Schneier.
- I click the link to read the GitHub outage postmortem and… How is GitHub real? https://www. githubstatus.com/incidents/zkx wbgr0cnmx.
- RT Invoke RE: We’ve uploaded the materials from our 3 hour workshop presented at REcon 2026 titled “C++ Symbol and Type Recovery in Binary Ninja”, you… by hasherezade.
- RT Mr. The Plague : I built BloodBash to help me pass my OSCP+ with more confidence It worked The most surreal thing I experienced at DefCon … by Rob Fuller.
- What can a Markdown file do? In this case, compromise a developer’s machine through a supply-chain attack. We used Neo to audit a VS Code extension w… by ProjectDiscovery.
- RT Alex Plaskett: Just published “Vulnerability Analysis of CVE 2025 22226 Information Disclosure Due to OOB Read in VMwares HGFS” by Alex Zaviyalov… by Axel Souchet.
- UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations by Joey Chen.
- Healthtech firm CareCloud data breach impacts 3.7 million patients https://www.bleepingcomputer.com/news/security/healthtech-firm-carecloud-data-breac… by BleepingComputer.
- Hackers compromise 14,500 Dahua web cameras in 35-day campaign https://www.bleepingcomputer.com/news/security/hackers-compromise-14-500-dahua-web-came… by BleepingComputer.
- US charges Iranian hackers over $3.4 billion intellectual property theft https://www.bleepingcomputer.com/news/security/us-charges-iranian-hackers-ove… by BleepingComputer.
- Detailed Timeline of OpenAI’s Cyberattack on Hugging Face by Bruce Schneier.
- analysis of a Stripe breach that just dropped, confirmed vendor leaks and claims of 20k compromised apis https://www.infostealers.com/article/analyzin… by Nicolas Krassas.
- RT Alex Plaskett: I wrote an article on some of my talk highlights from this year’s BlackHat and DEFCON! https://www.nccgroup.com/research/postcards-… by Ken Gannon (伊藤 剣).
- Solar Winds Part 2 Avoided: N-Able Passportal Vault Leak https://amibeingpwned.com/blog/solar-winds-part-2-avoided by /r/netsec.
- Iran’s Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictment has more me… by /r/netsec.
- RT Margin Research: New terminology alert! Welcome to the multiverse of the half-day: https://margin.re/2026/08/introducing-the-half-day-0-day-in-the-… by Dave Aitel.
- RT AmirMohammad Safari: There are two solutions to this challenge. One lets you leak the full URL using pure CSS in Chrome 150+! Full write-up here: h… by Gareth Heyes \u2028.
- RT The Hacker News: A CVSS 10.0 Entra ID flaw was exploited in the wild. CVE-2026-69836 allows an unauthorized attacker to remotely execute code … by kmkz.
- RT /ˈziːf-kɒn/: #x33fcon 2026 talks: Levi Cailleret - EDR Introspection > https://youtu.be/zAm8GkPCcxA by Max.
- For your weekend: The first early release talk from DEF CON 34 has made it to our YouTube channel. Please enjoy national treasure Cliff Stoll updating his ‘Stalking the Wily Hacker’ and casually dropp.
- Missed our CEO HD Moore’s “Lights Out” research at Black Hat & DEF CON? His findings reveal that BMCs, found in nearly every enterprise server, are a… by runZero, Inc..
- RT Aikido: ‼Two popular Rust crates, arrayref and append-only-vec, were compromised in a supply chain attack. arrayref alone has 244M downloads. Th… by scriptjunkie (Matt).
- How about a moratorium on reporting vulnerabilities in the terminators?? Responsible disclosure… more like responsibility to the human race! by thaddeus e. grugq.
- RT Lukasz Olejnik: Remote code vulnerability found in Unitree robots and the scary part is that the exploit is wormable. That means one compromised ro… by thaddeus e. grugq.
- Hundreds of leaked AWS keys give full control over corporate accounts https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-… by BleepingComputer.
- Introducing EchoBench: A Human Calibrated Benchmark for Autonomous Pentesting https://www.netspi.com/blog/technical-blog/ai-ml-pentesting/introducing-… by Nicolas Krassas.
- RT Het Mehta: someone just plugged a cable into a Tesla charger and turned it into a computer virus. @ScepticCtf compromised a Tesla Universal Wall Co… by Kim Zetter.
- RT The Hacker News: ‼ Warning - Expired Visa payment cards can be revived for real purchases. New “Zombie Card” attack rewrites the expiry date a… by Simone Margaritelli.
- RT Matico: O hacker do GTA 6 inventou o sistema de contato mais insano que já vi Ele tá vazando toda a gameplay e está pedindo 400 monero:native (R… by thaddeus e. grugq.
- My @x33fcon talk is out by James .
- RT Justin Elze: If you only watch one talk from Defcon https://youtu.be/656058JxTM0?is=rNRfVx-cghUILPSS by Sudheer Varma.
- ReliaQuest confirms failed data-theft attack after ShinyHunters breach https://www.bleepingcomputer.com/news/security/reliaquest-confirms-failed-data-… by BleepingComputer.
- South Korean startup platform breach exposes key management failures https://www.bleepingcomputer.com/news/security/south-korean-startup-platform-brea… by Nicolas Krassas.
- Uber Fined Nearly $1 Billion by Dutch Regulators Over Automated Suspensions of Driver Accounts https://www.securityweek.com/uber-fined-nearly-1-billio… by Nicolas Krassas.
- RT Enno Rey: From Black Hat USA 2026 to ERNW Whitepaper 78: Breaking Kubernetes Multi-Tenancy, via @Insinuator https://insinuator.net/2026/08/from-bla… by DirectoryRanger.
- Insight into agentic hacking tools: Hermes, OpenClaw and the Bayesian brain https:// dreamgroup.com/blog/inside-a-m ulti-agent-ai-framework-used-to-compromise-government-entities-in-asia.
- Increasing your attack/leak surface by Giuseppe
N3mes1s.
Techniques and Write-ups
Kernel code execution achieved via IDT table hijacking on Windows 11 with VBS, HVCI, and kCET enabled. Alex Ionescu notes HLAT/HVPT mitigates this class of attack.
Run a fake MDM server and gain SYSTEM with two clicks on targets that have permission to elevate. PoC included in the AmberWolf blog post.
Csaba Fitzl used Claude to find CVE-2026-43774, a memory corruption vulnerability in macOS Spotlight’s PostScript parser. Fixed in macOS 26.6.
Wiz research on detecting and outsmarting attackers who abuse Entra device registration for persistence and lateral movement.
Academic paper exploring Apple’s Secure Page Table Monitor, TXM, and Exclaves architecture on modern iOS. Covers the internal security boundaries protecting the kernel and its trusted extensions.
New PoC from daem0nc0re for executing SYSTEM processes via scheduled task registration, extending the ArtsOfGetSystem privilege escalation toolkit.
Runs an entire Tailscale daemon from memory inside a C2 implant. Zero disk artifacts, no kernel drivers, traffic indistinguishable from HTTPS to a CDN, with relay connections back through the tailnet.
Check Point research shows how Defender’s signed BTR.sys driver can be abused as a kernel primitive to bypass Tamper Protection, delete EDR components before boot, and gain persistence without any vulnerability or BYOVD.
Yarden Shafir’s talk on exploiting I/O Rings on Windows and the mitigations Microsoft has built to counter the technique. Full recording now on YouTube.
Signed Google Chrome installers can be abused to achieve arbitrary code execution on target systems. Full writeup from AmberWolf.
More this week (331)
- Unauthenticated RCE in CircleCI’s MCP server: Host/Origin allowlist bypassed by any non-browser client (GHSA-xv5j-cwgj-22r4) https:// remedio.io/blog/the-critical-u nauthenticated-rce-vulnerability-in.
- RT cr3ghost: Your AV ships a hypervisor. What happens if you use its own virtualization layer to hook Windows syscalls? @iPowerPower ’s KasperskyHook … by Max.
- RT Luca Beurer-Kellner: We decrypted the reasoning traces of frontier models! Huge credit to @AlexPanfilov, @DavidSchmotz and the whole team. I wr… by Max.
- RT Louis Nyffenegger: I have spent a fair amount of time writing SQL (Injections), and today I learnt that LIKE has an ESCAPE clause that lets you red… by Max.
- RT Akamai Security Intelligence Group: Endpoint detection and response is a main defense layer, but it can also become a weaponized Trojan horse. Our … by Max.
- RT Coontzy1: So, if you don’t need a signed payload… you can serve whatever you want with wsuks https://github.com/NeffIsBack/wsuks Cool blog and fi… by Max.
- RT DirectoryRanger: Suzaku. Sigma-based threat hunting and fast forensics timeline for cloud logs. Black Hat Arsenal USA 2026 Release https://github.c… by Max.
- RT Pavel Yosifovich: New video: Process Memory Map in Code (Part 1). VMMap shows you a process’s memory layout from a GUI. This time I build a similar… by Kuba Gretzky.
- RT Objective-See Foundation: #OFTW v4 in Berlin is a wrap! 🇩🇪 All photos + talk recordings are now online: https://objective-see.org/oftw/v4… by Patrick Wardle.
- RT Dhiyaneshwaran: Unauthenticated SQL injection in the jsonArrayContains filter function against PostGIS layers Nuclei Template : https://cl… by Nuclei by ProjectDiscovery.
- RT Steve S.: Qwen3.8-27b is good. Like really good for local inference. It’s completely changed the game as far as what’s possible on consumer hardwar… by Swissky.
- Mitigated API authentication bypass for https://python.org download metadata https://pyfound.blogspot.com/2026/06/mitigated-api-bypass-for-download-me… by Swissky.
- “DeltaWifi” it’s called. Excellent. No notes. https://x.com/singe/status/2089064026332422418 by scriptjunkie (Matt).
- RT Perly : I compiled over 11k bug bounty reports into one library a little bit ago, I wanted to run some analysis on bounty reports, but had a ha… by thaddeus e. grugq.
- RT 𝕡𝕨𝕟𝕚𝕖: microslop i mean Microsoft patched a privilege escalation in the Windows User Profile Service this week and credited the disc… by thaddeus e. grugq.
- RT J4X: Really interesting research from Anthropic on using multi-agent systems for vulnerability research: https://www.anthropic.com/research/multiag… by thaddeus e. grugq.
- RT GangExposed RU: 1/5 I have something new on LockBitSupp. This is Evgeny Dementyev - the leader of LockBit. Instagram username: dementev23 Photo fro… by thaddeus e. grugq.
- RT Smukx.E: Introduction to Windows shellcode development series Part 1:- https://securitycafe.ro/2015/10/30/introduction-to-windows-shellcode-develop… by Mike Felch (Stay Ready).
- RT Quang Vo: I wrote a short blog post about capability of Chrome Debugging Protocol in Red teaming. My favorite caps are probably Browse as victim an… by Mr.Z.
- DC34 Badge hackin’ https://andrewmohawk.com/2026/08/16/dc34-badge-hackin/ DC34 app to modify your badge colours: https://genemate.andrewmohawk.xyz/ by AndrewMohawk⁽ⁿᵘˡˡ⁾.
- Philips and GE investigating Clop ransomware data theft claims https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransom… by BleepingComputer.
- Microsoft working on Defender patch for ShieldBreak zero-day https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-sh… by BleepingComputer.
- Large-scale DDoS attacks disrupted Threema secure messaging service https://www.bleepingcomputer.com/news/security/large-scale-ddos-attacks-disrupted-… by BleepingComputer.
- New AmnesiaStealer macOS malware hijacks browser sessions via remote control https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-m… by BleepingComputer.
- I love seeing folks use IWAs for the unbelievably OP direct socket capabilities that are built into Chrome. But if you’re sideloading stuff these days… by Michael Weber.
- One Attacker Has Scraped Both Salesforce and ServiceNow Portals Since 2025 https://thehackernews.com/2026/08/one-attacker-has-scraped-both.html by Nicolas Krassas.
- 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-ste… by Nicolas Krassas.
- RT International Cyber Digest: ‼ BREAKING: A threat actor, who hacked three French state systems in eight weeks, namely the tax and land authority,… by Nicolas Krassas.
- CISA: Windows Task Host flaw now exploited by ransomware gangs https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploite… by Nicolas Krassas.
- Microsoft starts removing WMIC tool used by cybercriminals https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolbin-tool-in-windo… by Nicolas Krassas.
- New Mirai-Based Evooo1Bot Botnet Targets Linux Devices https://securityaffairs.com/197434/malware/new-mirai-based-evooo1bot-botnet-targets-linux-devic… by Nicolas Krassas.
- CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.htm… by Nicolas Krassas.
- File Drop to RCE – CVE-2026-20217 https://www.securifera.com/blog/2026/08/07/file-drop-to-rce-cve-2026-20217/ by Nicolas Krassas.
- [0day-rubbish] InsightEdge Enterprise (XAP IMDg) 16.1.1 Pre-authentication RCE (path traversal + JSP webshell) (9.8) https://seclists.org/fulldisclosu… by Nicolas Krassas.
- Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw… by Nicolas Krassas.
- Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-ena… by Nicolas Krassas.
- ERNW White Paper 80: Token Theft in Microsodt Entra ID – An Analysis of Controls, by @Insinuator https://insinuator.net/2026/08/ernw-white-paper-80-t… by DirectoryRanger.
- RT Dr. Nestori Syynimaa: by DirectoryRanger.
- Entra Agent ID: from Detection to Response #DFIR https://www.youtube.com/watch?v=uZvRyn1Dj8k by DirectoryRanger.
- Hunting Exchange Server 0day like a detective https://testbnull.medium.com/hunting-exchange-server-0day-like-a-detective-3fd5e0dc9779 by DirectoryRanger.
- LinXcoded (Mirage2FA): Microsoft 365 Phishing Platform Uses HTML Attachments to Steal Post-MFA Sessions https://abnormal.ai/blog/linxcoded-mirage2fa-m… by DirectoryRanger.
- RT Enno Rey: https://Passkeys.Tools Encode, Decode, Intercept, Modify, and Exploit WebAuthn Operations https://passkeys.tools by DirectoryRanger.
- RMM’s are up! FakeCAPTCHA are more up! Expect more on the rise. Check out https://lolrmm.io If you need help - just holler! by The Haag™.
- Cve cannot catchup with the exploitation pace right now. No mitigation Exploited ITW https://github.com/geotools/geotools/security/advisories/GHSA-mqj… by Giuseppe
N3mes1s. - RT elttam: New blog post: Ruby 4.0 Universal RCE Deserialization Gadget Chain https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadge… by Giuseppe
N3mes1s. - [You can hide a line of a file using the following ANSI characters - ESC[2K –> Delete current line - ESC1A –> Move cursor one line up Depending how … by Peter Gabaldon.
- RT Wild West Hackin’ Fest: Check out Garrett Foster’s talk, “Attacking SCCM with SCCMHunter,” from WWHF @ Mile High 2026! https://www.youtube.com/watc… by Sean Metcalf.
- RT Chris Thompson: Patch SCCM with https://learn.microsoft.com/en-us/intune/configmgr/hotfix/2603/38232642 or you’re likely vulnerable to a new hierar… by Sean Metcalf.
- Please join us for the next @offby1security stream this Friday, August 21st at 11AM PT with the amazing @yarden_shafir for a session on “Enforcing Use… by Stephen Sims.
- I saw this finally fixed in a very complex environment where it was thought it could never be removed. Definitely work on resolving this. (Office IP m… by SwiftOnSecurity.
- RT Kevin Villarreal: Microsoft Defender for Identity just added 2 new health alerts: Missing DC network traffic Missing Windows events f… by SwiftOnSecurity.
- RT Virus Bulletin: Huntress researcher James Northey shows how an Akira affiliate rebooted the victim host into Safe Mode with Networking to defeat ED… by SwiftOnSecurity.
- RT Centralne Biuro Zwalczania Cyberprzestępczości: Funkcjonariusze Centralnego Biura Zwalczania Cyberprzestępczości prowadzą czynności pod nadzo… by SwitHak ().
- NASK PL🇵🇱 Report Russian Voice in the Chinese Information Space: The Case of Poland🇵🇱 PRC🇨🇳–Russian Federation🇷🇺 Joint Effort… by SwitHak ().
- Kimi Desktop Ships With an Updater That Can Install Unverified Code https://runtimewire.com/article/kimi-desktop-ships-with-a-group-chat-updater-that-… by /r/netsec.
- prompt injection containment as a structural property instead of a detector (interactive, real code, no llm) https://meghavi.me/gate by /r/netsec.
- How a popular Android library silently exposed thousands of apps to Arbitrary File Overwrite (AFO). https://itis911.github.io/writeups/cropper-vulnera… by /r/netsec.
- Dissecting House of Apple 2 on modern glibc https://jazho76.github.io/house_of_apple_2/ by /r/netsec.
- Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design https://www.endorlabs.com/learn/hacking-your-life-with… by /r/netsec.
- Git repo forensics: a seven-phase process for investigating suspicious commits https://root-security.eu/notebook/git-forensics-process/ by /r/netsec.
- DeadLock ransomware: Rust-based encryptor with decentralized recovery infrastructure https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock… by /r/netsec.
- How Codex found replayable state transitions and a lost-update race in a Supabase browser game https://shmulc.substack.com/p/how-many-exploits-does-it… by /r/netsec.
- From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193) https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate by /r/netsec.
- They patched their SaaS and left the self-hosted OSS version vulnerable - AppFlowy Authenticated SQL Injection https://projectblack.io/blog/appflowy-a… by /r/netsec.
- Came across this blog post: https://www.praetorian.com/blog/etw-threat-intelligence-and-hardware-breakpoints/ Pretty solid read! Except EtwTiLogSetCon… by winterknife.
- OK that is pretty cool :D by Adam Chester.
- RT Neeraj Gupta: Recent Jailbreaker CE updates I missed sharing: configurable Judge policies (Now you can define success failure, or a whole new rubri… by Adam Chester.
- Investigation Scenario While investigating potential intellectual property theft, you discover the pictured registry artifact on a Windows 11 sys… by Chris Sanders.
- RT Nextron Research : We identified a new campaign targeting German-speaking businesses via hiring-themed lures. Malicious archives contain fake N… by Florian Roth.
- Generic detection rules FTW by Florian Roth.
- RT Olivia Gallucci : If anyone wants to see my @BlackHatEvents talk, it was uploaded to YouTube! https://www.youtube.com/watch?v=x6vr4GWToYc by Dave Aitel.
- An interesting technique, we have created new scripts taking advantage of the malwareless techniques the scripts use the same formats as impacket by David.
- For those who can’t sleep tonight. https://forum.0x00sec.org/t/low-waters-3rd-layer-phishing/779 by David.
- RT Daily CyberSecurity: CVE-2026-18051 (CVSS 10) is an unauthenticated arbitrary file write in W3 Total Cache, exposing 900k+ WordPress sites. Update … by Simone Margaritelli.
- RT LuemmelSec: https://plugandpwn.com/ by Simone Margaritelli.
- RT Interesting AF: A website lets you check if your license plate has been searched up in Flock’s database HaveIBeenFlocked displays the reason for e… by Simone Margaritelli.
- Describing attacks with crime script analysis by Martin Lee.
- An amazing blogpost by @_rdowd by Gergely Kalman.
- If you are into Apple CVEs, this is for you by Gergely Kalman.
- RT isopach: I found an interesting bug but MSRC says it’s not a security vuln, so here’s the writeup https://isopach.dev/Windows-ctfmon-Japanese-IME-h… by Gergely Kalman.
- RT Check Point Research: #StopAndProtect blends ransomware, data theft and hands-on keyboard control. OPSEC failures reveals logs from over 6,000 … by hasherezade.
- RT Monnappa K A: Exploring Agentic Malware Reverse Engineering. Watch an AI agent use IDAPython exposed tools to analyze malware and identify the encr… by hasherezade.
- RT BytecodeAssassin (Husam): This might be the most insane C Compiler I’ve ever seen in my life. It turns C Code into Turing-complete single instructi… by hasherezade.
- RT 1Password: Our Security team has identified an active phishing campaign targeting 1Password users. The phishing emails claim your account’s payment… by Howard Oakley, Eclectic Light Co.
- RT etugen.io: 0day Claim - Kamailio SIP Heap Overflow - 0day PoC - Miniupnpd Heap Overflow - 0day PoC Platform: https://app.etugen.io/trashp… by batuu.
- IDT Table Hijacking under VBS/HVCI/kCET in Windows 11 https://www.exploitpack.com/blogs/news/idt-table-hijacking-under-vbs-hvci-kcet-in-windows-11 by Panos Gkatziroulis.
- DutchOven - a deliberately small Windows red-team primitive that places explicit executable paths behind a deterministic network gate. During each per… by Panos Gkatziroulis.
- A Rust library that replaces sleep() with real, varied work to evade behavioral pattern matching by EDR https://github.com/PatchRequest/BusyWork by Panos Gkatziroulis.
- RedForge - A modern Python-based Red Team Operations Workbench for managing engagements, intelligence, evidence, and reporting https://github.com/arpi… by Panos Gkatziroulis.
- meridian - Modular C2 framework Server - Python async core with aiohttp, SQLite persistence, and a rich operator console Implant - Single static… by Panos Gkatziroulis.
- TrickDump - Dump lsass without generating a Minidump file https://ricardojoserf.github.io/trickdump/ by Panos Gkatziroulis.
- I spent some time this weekend performing Code Injection via the 𝐌𝐞𝐬𝐬𝐚𝐠𝐞𝐁𝐨𝐱𝐈𝐧𝐝𝐢𝐫𝐞𝐜𝐭𝐖 API… by Panos Gkatziroulis.
- RT Noth1ng Real: Learn how to write an APC injection Malware from scratch! In my second blog post on malware, I write about Windows APCs, how they wor… by Panos Gkatziroulis.
- RT Eyal Sela: A threat actor used Claude Code with Sonnet 4.6 as part of an intrusion, likely for ransomware. Sonnet took on many tasks, like writing … by Jeff McJunkin.
- RT White Knight Labs: Wilecurity’s breakdown of MSCodePhish, Raunak Parmar’s Dynamic Device Code Phishing Framework, is out. Watch the full breakdown…. by Chihuahua in charge NotMe.
- RT Winston Ighodaro: The employee changed his Microsoft 365 password twice. The attacker still logged back in. That was the moment we knew we were not… by Chihuahua in charge NotMe.
- RT Kostas: Really happy to introduce the Hunting Leads! The idea is to share smaller pieces of real intrusion activity that are too narrow for a … by Chihuahua in charge NotMe.
- RT Kévin GERVOT (Mizu): Recently, I’ve been looking at DOMPurify again, trying to find ways to bypass 3.x.x after browsers started encoding attrs dur… by Masato Kinugawa.
- RT watchTowr: GitLab CVE-2026-19478: a critical vulnerability lets unauthenticated attackers modify or delete public projects in one request. wat… by kmkz.
- RT OS Dev: CVE-2026-66804 is an interesting Windows LPE. The PoC uses GodPotato to exploit the Windows Cross Device Service and escalate from a low-pr… by kmkz.
- RT qwerty: Interesting compiler based V8 sandbox bypass \w @physicube https://issues.chromium.org/issues/500771385 by kmkz.
- RT SEKTOR7 Institute: Weaponizing WDAC to disable EDR protections. A post by Jonathan Beierle and Logan Goins. Source: https://beierle.win/2024-12-20-… by kmkz.
- RT Nicolas Krassas: Reverse Engineering CVE-2026-6837: From Zyxel Firmware to Root Command Execution with full firmware emulation https://minanagehsal… by kmkz.
- RT J4X: Re Correct link: https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review by Max.
- RT Hedgie: Security researchers tricked Microsoft’s Copilot into revealing how to hack itself. They asked why a certain attack wouldn’t work, and … by Max.
- This is nothing new but yeah, I asked gpt sol to write a reflective loader on iOS on top of my old Mistune exploit and it worked. 6 years ago I couldn’t finish that part and left a very ugly codebase..
- RT Dhiyaneshwaran: CVE-2026-19478 - GitLab CE/EE - GraphQL @ gl_introduced Arbitrary Method Invocation Nuclei Template - https://github.com/pr… by Nuclei by ProjectDiscovery.
- Vulnerability and malware checks in uv - William Woodruff https://astral.sh/blog/uv-audit by Swissky.
- GLM-5.2, not Mythos, is the real security emergency - Joshua Saxe https://joshuasaxe181906.substack.com/p/glm-52-not-mythos-is-the-real-security by Swissky.
- RT Nagli: Re Funny enough, we only realized after the fact that the vulnerable code was only 5 days old. A commit co-authored by @github’s Copilot “Au… by Swissky.
- RT CloudBreach: @wiz_io scanned the internet for exposed MCP servers. MCP is in 80% of cloud environments. 1 in 6 expose a server to the internet… by Renos.
- 6 MiB binaries / small …? May I point you to my talk: “Writing Tiny, Efficient, And Reliable Malware” https://youtu.be/TfG9lBYCOq8 by Rad.
- RT V12: another one (poc) for redis server RCE: https://github.com/v12-security/pocs/tree/main/redis/server handleClientsBlockedOnKey() use-after-free… by Rick de Jager.
- RT V12: and here’s our poc for postgres server RCE: https://github.com/v12-security/pocs/tree/main/postgresql/server CVE-2026-14669. patched postgreSQ… by Rick de Jager.
- RT Nebula Security: Re With Demo Day approaching, we’re dropping one end-to-end Linux kernel exploit every day starting today. Daily drops: https://gi… by scriptjunkie (Matt).
- RT The Register: Expired credit cards revived by researchers to make unauthorized payments https://www.theregister.com/security/2026/08/18/expired-cre… by scriptjunkie (Matt).
- The research continues! by spaceraccoon | Eugene Lim.
- RT Synack Red Team: Unauthenticated root, from the network, on an appliance that terminates an organization’s voice and conferencing traffic. Synack R… by ϻг_ϻε.
- RT @MalwareBibleJP: Windowsのどのカーネルドライバがどのような脆弱性で権限昇格に使われてきたかを、ダッシュボードなどで可視化したナレッジベース「KernelS… by thaddeus e. grugq.
- RT @MalwareBibleJP: なりすまして企業に入り込む北朝鮮のIT労働者について、それを管理する側の内部Webサイトが特定され調査がまとめられた詳細分析。身元を偽… by thaddeus e. grugq.
- RT solst/ICE of Astarte: Wait so all of these incidents are attributed to a single company responsible for the sandboxing failures? Lmao by thaddeus e. grugq.
- RT Abdul Mhanni: One of the best ways to kick off IoT/OT/Hardware pen tests when your client was a bit stingy with information is using Federal Commun… by thaddeus e. grugq.
- RT Connor McGarr: “Outside-in-protection” in the latest insider preview. Objects have “anti-tamper” associated w/ them. Even new IFEO to read from for… by Mike Felch (Stay Ready).
- RT Brute: 403 Access Bypass Tester - UnKover Built to find this and many more across our 33 cases testbed. Fewer false positives, cleaner results. htt… by Vincent Yiu.
- RT PandaRE 🇺🇦: New research: Shadow HVNC and Shadow Loader: The Kit That Protects Its License Better Than Its Customers The seller cal… by Vincent Yiu.
- RT shuffle2: I’ve updated the ps5-uart (somewhat a misnomer now) repo with full documentation of the NAND storage (cell mode, geometry, descrambling, … by Axel Souchet.
- UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities by Joey Chen.
- Police Are Hiding Their Use of Flock Surveillance Cameras by Bruce Schneier.
- RT Master_寒蝉: CVE-2026-42980 Windows 内核 WMI 整数下溢本地提权漏洞,低权限攻击者可利用该漏洞将自身权限提升至 SYSTEM,进而完全控制受影响主机。 (切记… by sailay(valen).
- Citrix urges admins to patch new NetScaler flaws as soon as possible https://www.bleepingcomputer.com/news/security/citrix-urges-admins-to-patch-new-n… by BleepingComputer.
- CISA warns of hackers exploiting critical MLflow vulnerability https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critica… by BleepingComputer.
- Rogue ransomware affiliate poses as data recovery firm to steal payments https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-ran… by BleepingComputer.
- Sakura Internet hack exposes data of up to 1.36 million accounts https://www.bleepingcomputer.com/news/security/sakura-internet-hack-exposes-data-of-u… by BleepingComputer.
- US warns of AI-powered attacks on Siemens PLCs in critical infrastructure https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attack… by BleepingComputer.
- Microsoft fixes known issue causing Windows Defender crashes https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-known-issue-causing-windo… by BleepingComputer.
- Critical RCE flaw in Windows IKE Extension now actively exploited https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-f… by BleepingComputer.
- CISA: Medusa ransomware hit over 500 critical infrastructure orgs https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-c… by BleepingComputer.
- RT Moloch: Random vibe coded things others may find useful: Pure Go cross-platform in-memory shared library loader: https://github.com/sliverarmory/re… by Michael Weber.
- Opening the Wordpress Forminator PoC validation lab https://github.com/dinosn/forminator-poc-lab/ a work with @mcipekci by Nicolas Krassas.
- Researcher tricks Apple’s Find My into sharing location data with Linux https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-find… by Nicolas Krassas.
- A security-research Proof-of-Concept (POC) demonstrating hardware-breakpoint (CPU debug register) based function hooking as an alternative to traditio… by Nicolas Krassas.
- Data analyst tried to extort his former employer for $2.5 million https://www.bitdefender.com/en-us/blog/hotforsecurity/prison-data-analyst-extort-emp… by Nicolas Krassas.
- Malware-as-a-Service Cocktail: ErrTraffic and Cruciferra - Killing Your EDR Since 2025 https://www.esentire.com/blog/malware-as-a-service-cocktail-err… by Nicolas Krassas.
- Chinese hackers use AI to automate attacks on 170,000 servers https://cyberinsider.com/chinese-hackers-use-ai-to-automate-attacks-on-170000-servers/ by Nicolas Krassas.
- Critical Elementor Pro bug exposes WordPress sites to RCE attacks https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-exposes-wo… by Nicolas Krassas.
- CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html by Nicolas Krassas.
- Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices https://thehackernews.com/2026/08/manic-android-malware-exfiltr… by Nicolas Krassas.
- BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive https://research.checkpoint.com/2026/btr-reforged-weaponizing… by Nicolas Krassas.
- Grok chat duped into swallowing injected instructions https://www.theregister.com/ai-and-ml/2026/08/20/grok-chat-duped-into-swallowing-injected-instru… by Nicolas Krassas.
- 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-a… by Nicolas Krassas.
- NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands https://thehackernews.com/2026/08/nasa-ait-gui-flaws-could-let.html by Nicolas Krassas.
- AI-Assisted Tool Helped Secure Satellite Communication System After 2022 Russian Hacking https://www.securityweek.com/ai-assisted-tool-helped-secure-s… by Nicolas Krassas.
- Largest Applebee’s franchisee says hackers stole sensitive data https://cyberinsider.com/largest-applebees-franchisee-says-hackers-stole-sensitive-da… by Nicolas Krassas.
- 9 million images of people’s faces exposed by reverse lookup service https://www.malwarebytes.com/blog/privacy/2026/08/9-million-images-of-peoples-fa… by Nicolas Krassas.
- French tax authority says break-in exposed data of 600K, including some private messages https://www.theregister.com/security/2026/08/20/french-tax-au… by Nicolas Krassas.
- RT Enno Rey: DNS Cache Poisoning Like it’s 2006 https://www.usenix.org/system/files/usenixsecurity26-ben-simhon.pdf [PDF] by DirectoryRanger.
- lowkey cable looking chopped asf right now by Nick Carr.
- Is Cyber missing the Marque? by Mick Baccio.
- Speaking of Fresh RMMs off the pallet - Just merged 2 new ones: Teleport Connect: https://github.com/magicsword-io/LOLRMM/pull/233 and this epic one: … by The Haag™.
- Ok - hear me out. This is a sleeper. “…ensures a Tcl/Tk GUI runtime is present..” I may have trolled Lua for too long - but - is that Tcl!? https://… by The Haag™.
- RT 𝕡𝕨𝕟𝕚𝕖: Avast researchers notified Microsoft in 2025 about a privilege escalation vulnerability in appid.sys, the Windows AppLocker d… by The Haag™.
- RT Nebula Security: CVE-2023-2156 was believed to be just a remote kernel DoS, patched in 2023. We found a bypass and achieve privilege escalation and… by Giuseppe
N3mes1s. - RT domas: New primitive against x86’s shadiest mode: SMM has a critical barrier forcing cores to sync before running privileged code. Conveniently, th… by Giuseppe
N3mes1s. - Virtual Machine integration for BRc4 is now complete. I have to agree that building the VM was the easy part. The hard part was the integration while … by Chetan Nayak (Brute Ratel C4 Author).
- RT spencer: You may not want to believe it but it doesn’t make it any less true. You absolutely can defend Active Directory. Start by doing this: P… by Sean Metcalf.
- RT EZ: Great post and thank you for sharing this because it’s really important. #1 Always revoke the signin as the first step. Let’s talk a bit about … by Sean Metcalf.
- RT Nebula Security: Today’s exploit is from a ipv6 UAF, introduced in Nov 2021, fixed on upstream in Aug 2026. Discovered and exploit by NebuSec secu… by Steven Lowson.
- RT Daniel Bradley: Check it out, Microsoft have just given Security Administrators more permissions in Entra > https://ourcloudnetwork.com/microsoft-a… by SwiftOnSecurity.
- RT FBI Cyber Division: The #FBI and its partners are warning industrial control system owners and operators about an active cyber threat targeting Sie… by SwitHak ().
- RT ReliaQuest Threat Research: ReliaQuest discovered a custom web shell highly likely linked to Clop, deployed following exploitation of CVE-2026… by SwitHak ().
- RT Cybersecurity and Infrastructure Security Agency: We’ve updated our joint Cybersecurity Advisory on Medusa ransomware with @FBICyberDiv & @HHSgov … by SwitHak ().
- RT Bob Swallower: The Spanish police are investigating the access of the pro‑Russian hacking group NoName057(16) to confidential data belonging to a … by SwitHak ().
- RT Chetan Nayak (Brute Ratel C4 Author): Virtual Machine integration for BRc4 is now complete. I have to agree that building the VM was the easy part…. by Rasta Mouse.
- RT Ohm-I (Oh My): Graph tools are just fun to make for anything. This looks dope for defenders. by dylan.
- Hacking SAML with Claude Code https://oblique.security/blog/hacking-saml/ by /r/netsec.
- I escaped the WebAssembly’s sandbox and got arbitrary shell execution on the host. https://trustsig.eu/blog/wasm2c-tableflip-unchecked-calloc/ by /r/netsec.
- ValleyRAT campaign uses fake GSTR-3B overdue notice targeting Indian taxpayers https://blog.himanshuanand.com/2026/08/someone-is-filing-your-gst-retur… by /r/netsec.
- CRLF-Powered Desync Attacks: Beheading HTTP Streams https://portswigger.net/research/crlf-powered-desync-attacks by /r/netsec.
- How to break secure boot without touching any cryptography https://0x434b.dev/breaking-secure-boot-without-breaking-the-crypto/ by /r/netsec.
- The Curious Incidents with DNS in the Sandbox at Escape-Time https://chasersystems.com/blog/the-curious-incidents-with-dns-in-the-sandbox-at-escape-ti… by /r/netsec.
- When Burp Suite Isn’t Enough: Intercepting Thick Client Traffic https://interceptsuite.com/blog/burp-suite-thick-client-traffic-interception/ by /r/netsec.
- RT quarkslab: “Software protection is futile, AI will break it”, they said. But, does it? how? To shine some light read about Rémy Salim’s experiment… by winterknife.
- TIL that ETW TI events for APC insertion and thread context modification don’t include user-mode frames in their stack traces. In other words, it migh… by winterknife.
- More Incidents of AIs Going Rogue in Cybersecurity Challenges by Bruce Schneier.
- RIP to the Windows I/O Ring exploit technique, one of my favorites . Be sure to check out Yarden’s stream! by chompie.
- But how will I rewrite pentest tools now? by Jason Lang.
- lol what exactly did they cut now? by Jason Lang.
- I ran Ox Alpha through my threat triage benchmark too. No hard misses. It caught all real threats. But it overclassified a lot. 45.4% of the benign ca… by Florian Roth.
- This is pretty embarrassing Microsoft has a signed Defender driver that can be abused to kill Defender/EDR and modify protected files and registr… by Florian Roth.
- Generic detection rules FTW Two generic YARA rules flagged the malicious proc-macro1 package in our artifact stream. That was enough to send it into L… by Florian Roth.
- RT ZoomEye: CVE-2026-76404: Remote Code Execution (RCE) through Deserialization of Untrusted Data in Splunk MCP Server app Critical Vulnerability… by Florian Roth.
- RT Nextron Research : Our artifact scanner identified two malicious Rust crates impersonating the legitimate proc-macro2 crate: proc-macro1 v… by Florian Roth.
- FTP banners are being used as dead drop resolvers to deploy two new RATs (E4del & PINHOLE) https:// hubs.la/Q04tQxV30.
- RT cr3ghost: Chad Everdox appreciation post. Nick ‘Everdox’ Peterson (@nickeverdox) is genuinely one of the most underrated reverse engineers and Wi… by Daax.
- RT depthfirst: Today we are announcing dfbench, a cybersecurity benchmark we developed to evaluate frontier models and agentic systems. A few weeks ag… by Dave Aitel.
- RT J4X: Google just shared some results from their agentic vulnerability discovery harness. In one engagement it found 100+ true positive critical vul… by Dave Aitel.
- RT Brad Spengler: Just want to highlight this for anyone enabling unprivileged user namespaces: by Dave Aitel.
- RT Nicolas Krassas: Hackers abuse FTP server banners to deliver new Windows malware https://www.bleepingcomputer.com/news/security/hackers-abuse-ftp-s… by Simone Margaritelli.
- RT eversinc33 : I was thinking about how to hunt/detect prompt malware & once I started treating it like a compiler problem, the answer was cl… by 𝙁 𝙀 𝙇 𝙄 𝙓 𝙈.
- AI Is Learning to Write Genetic Code by Bruce Schneier.
- RT Michal Melewski: Finally it got published. by Halvar Flake.
- RT Jiří Vinopal: This one is special! Honored to have shared it on the main stages at #BHUSA & #DEFCON. Now the full write-up, every detail, is… by hasherezade.
- RT Florian Hansemann: ‘‘SakDriver: Reversing a Kernel Driver Rootkit | 0xSec’’ #infosec #pentest #redteam #blueteam https://0xsec.gitbook.io/0xsec/mal… by hasherezade.
- RT etugen.io: Another malicious Chrome extension distributor exposed. The extension is called Smart Bookmarks and comes with silent installation and a… by batuu.
- Interesting TTPs, including Fake Login Screens https://expel.com/blog/synkloader-when-you-throw-in-everything-but-the-kitchen-sink/ by Panos Gkatziroulis.
- The data sources required to detect the persistence technique of Mandatory User Profiles (http://NTUSER.MAN): Microsoft-Windows-User-Profile… by Panos Gkatziroulis.
- ⤵ MS-Nightmare Un-defend v2 - What Happens When Signatures Can’t Land https://weedhashpeddler.medium.com/every-antivirus-and-edr-product-depends-… by Panos Gkatziroulis.
- Mythic C2 profile for peer-to-peer communication over IEEE 802.1AB (LLDP). C2 data is carried inside Organizationally Specific TLVs (Type 127) with a … by Panos Gkatziroulis.
- Earlier this month, I wrote about .ppkg packages and how to use them for code execution, including a detailed detection strategy. It looks like the on… by Panos Gkatziroulis.
- RT Patchi/fyi: Re @daaximus @ipurple an example how to do this can be seen in my mythic agent: https://github.com/PatchRequest/Kassandra i break patte… by Panos Gkatziroulis.
- Reading an offline ntds.dit with one binary https://zaferbalkan.com/ditjson/ by Panos Gkatziroulis.
- RT BlackRoomSec: OUT NOW (8-19-26) - SP 1353 Initial Public Draft - NIST Cybersecurity Framework 2.0: Quick-Start Guide for Using Artificial Intellige… by Chihuahua in charge NotMe.
- RT SpecterOps: “Can this role read that bucket?” and “Can it decrypt that key?” aren’t the same question. @n0pe_sled’s latest blog post introduces AWS… by Chihuahua in charge NotMe.
- RT Nathan McNulty: Why detect when you could prevent? =) Just download and import: https://github.com/nathanmcnulty/nathanmcnulty/blob/main/Entra/cond… by Chihuahua in charge NotMe.
- A role labelled read-only is a claim, what the API actually returns is the fact. #Keycloak just proved the gap between the two, twice in two months –… by kmkz.
- RT Hossein Lotfi: Exploitation steps and a reliable exploit for Google Chrome ITW V8 TryFastAddDataProperty vulnerability (CVE-2026-11645 [506689381])… by kmkz.
- RT Mitja Kolsek: CVE-2026-33824 is now being exploited in the wild. The only patches available for legacy Windows systems can be obtained from @0patch… by kmkz.
- RT Ian Lee: $250,000 bounty for CVE-2026-9876, reported by happy2me. Critical WebGL UAF in Chrome. Chromium’s issue title links it to a bypass of the… by kmkz.
- RT Out of Bounds: Our researcher @generally_oui reported CVE-2026-64784, an out-of-bounds bug in WebKit fixed in Safari 26.6.1. https://support.apple…. by kmkz.
- RT SEKTOR7 Institute: Kerberos persistence with Windows tokens and CS beacon. A post by Romain de Reydellet (@pentest_soka) Source: https://sokarepo.g… by Max.
- RT Tony/Humpty: If you operate a SIEM I’d recommend giving a look st https://detection.wiki. Absolute fantastic work! by Max.
- RT The DFIR Report: Hunt idea: rank DNS queries by the process making them, ascending, then read the tail. In one week, this approach surfaced several… by Max.
- RT Maurice Heumann: 200 Billion Tokens Later: A Month of Letting AI Agents Decompile MW2 As promised, a blog post on the MW2 decompilation, focusing m… by Max.
- Have just added this sample to the @objective_see public macOS malware collection …as ‘BotKing’ https://github.com/objective-see/Malware/blob/m… by Patrick Wardle.
- [FR] Sthack 2026 : Red Team: 20 missions plus tard - Autopsie de quatre années de mutation offensive - @M4yFly https://youtu.be/lZM1G62YH9I by Swissky.
- Building an in-tree LLVM obfuscator solo, with an AI pair - @und3ath1 https://und3ath.github.io/2026/07/01/llvm-obfuscator-in-tree/ by Swissky.
- RT Michael Grafnetter: Last week I had a nice chat with @merill, where we discussed my recent #BHUSA talk about passkey security and what it mean… by Rémi GASCOU (Podalirius).
- RT Yarden Shafir: Microsoft killed my exploit This Friday on @offby1security I’ll talk to @Steph3nSims about what why, how and if this is the end… by Richard Johnson.
- RT zeze : Just noticed that starting with Process Monitor 4.10, Procmon now supports IPC monitoring, including Named Pipe events. by SAERXCIT.
- RT BlueSky: Hey look, the Fake Escrow Scam is back. Now hosted at hxxps://solanoautotransport[.]com/about-us/ https://textslashplain.com/202… by scriptjunkie (Matt).
- They delegated targeting analysis and had limited success… seems like they should’ve invested in targeting analysis instead… by thaddeus e. grugq.
- RT @zooko: Supply-chain attack in the Rust ecosystem: https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/ by thaddeus e. grugq.
- RT Lindsey O’Donnell Welch: “Measuring only whether an exploit succeeds may miss important changes in how that success is achieved.” ExploitGym is … by thaddeus e. grugq.
- RT Ed Newton-Rex: Oh wow - Reuters found the GitHub record of the attempt by AI models being tested by the UK’s AI Security Institute to deploy malwar… by thaddeus e. grugq.
- RT misaki: 四川无声信息技术(Sichuan Silence)は、无糖信息(NoSugarTech)やi-SOONのリークデータを調べている際につながりを見つけました。 「双螺旋攻防实验室… by thaddeus e. grugq.
- RT CNX Software: Yesterday, I received a request for a modified Raspberry Pi Pico 2 with an Apple Lightning cable. https://www.cnx-software.com/2026/0… by thaddeus e. grugq.
- RT RajΞΞv: First CVE wave from AI-assisted vulnerability discovery. https://www.vulncheck.com/blog/ai-assisted-vulnerability-discovery by thaddeus e. grugq.
- RT Mike Takahashi: The CEO of Irregular, the AI security lab that ran evals where OpenAI models attacked real systems, just published his take on wher… by thaddeus e. grugq.
- RT Charlie Miller: When I see this, as a former nsa guy, I wonder are these guys finding vulns, writing exploits, writing rootkits, using exploits, do… by thaddeus e. grugq.
- RT Justin Elze: Somewhere there is a pentester trying to get this into a report or a team reviewing it as CTI. https://x.com/ipurple/status/2090502956… by James .
- RT Jorian: There’s never enough Unauthenticated RCE’s. Here I took a limited AI finding and through some clever Git structures, escalate it to Remote … by Vincent Yiu.
- The BHIS ActiveSOC team recently responded to an incident that we have attributed to the Aur0ra ransomware group. Read the full story here! https://ac… by Black Hills Information Security.
- New SynkLoader malware pushed in Microsoft Teams phishing campaign https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-mic… by BleepingComputer.
- CISA orders feds to patch actively exploited TrueConf Server flaws https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-e… by BleepingComputer.
- Microsoft warns of max severity Entra ID flaw exploited in attacks https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-of-max-severity-ent… by BleepingComputer.
- SickKids says a ‘cybersecurity incident’ exposed employee and job applicant data via a third-party software flaw - @Ax_Sharma https://www.bleepingcomp… by BleepingComputer.
- Hackers poison arrayref Rust crate to push infostealer malware https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-pu… by BleepingComputer.
- If you’re not using AI to attack your own systems, your adversaries will https://www.theregister.com/security/2026/08/22/if-youre-not-using-ai-to-atta… by Nicolas Krassas.
- Hackers infect Android car head units with proxy botnet malware https://www.bleepingcomputer.com/news/security/hackers-infect-android-car-head-units-w… by Nicolas Krassas.
- Named Pipes Under Attack: Securing Windows Interprocess Communication https://www.bleepingcomputer.com/news/security/named-pipes-under-attack-securing… by Nicolas Krassas.
- 140+ free security awareness and application security exercises. Fully white-labeled, no strings attached https://github.com/ransomleak/training-secur… by Nicolas Krassas.
- 14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2 https://thehackernews.com/2026/08/14-trojanized-npm-packages-drop-redc2.h… by Nicolas Krassas.
- AWS Security makes an inscrutable choice https://www.theregister.com/security/2026/08/22/aws-security-makes-an-inscrutable-choice-corey-quinn/5291446 by Nicolas Krassas.
- We burned 11.7bn tokens to find the best cyber AI model https://www.aikido.dev/blog/ai-model-benchmarks-aug-21-2026 by Nicolas Krassas.
- Homeland security cybercops say patch TrueConf (Russia’s Zoom) if you’re using it https://www.theregister.com/patches/2026/08/21/homeland-security-cyb… by Nicolas Krassas.
- Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot https://thehackernews.com/2026/08/microsoft-defenders-own-driver… by Nicolas Krassas.
- Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini https://www.securityweek.com/encrypted-prompts-bypass-ai-safety-guardrails-in-grok-an… by Nicolas Krassas.
- The Taiwan attack was built with two free downloads from vendors nobody rates https://www.scworld.com/perspective/the-taiwan-attack-was-built-with-two… by Nicolas Krassas.
- I know the industry’s focus is all in on AI, but we have threat actors exploiting cloud 0days in the wild. Don’t forget we still have to secure the … by Nick Frichette.
- Update: if you want to do your own investigation (I’m not really sure if this has been patched, or which CVE-ID it is), the sample can be downloaded h… by Haifei Li.
- RT Brian in Pittsburgh: APT 29, doing APT 29 things. Hacking MSPs to hack hotels to hack guests to hack their employing organizations. by Nick Carr.
- Cool to see threat intel overlap visuals alongside in-the-wild tradecraft examples for 3 very creative intrusions sets serving Russian interests. This… by Nick Carr.
- Working Timeline of CaptiveCrunch (new details from Lumen / Black Lotus Labs*) • February 27 - Microsoft observed the first DNS resolver and AitM nod… by Nick Carr.
- RT Gabby Roncone 🇺🇦 🇵🇸: Today GTIG published a blog from @wxs and me regarding operations from three distinct Russian APTs that target ind… by Nick Carr.
- Quick look at the rust mach-O referenced in the blog post: 74d3447e7cf99c99ea01a16332ec27432dfb0f491e10e67cd118065a60483306. (0 VT hits currently) The… by L0Psec.
- RT MagicSword: Re LOLDrivers has tracked both families since February 2023: more than three years of public, actionable intelligence for defenders. RT… by The Haag™.
- RT stacksmashing: Anyone who thinks it’s smart to put something that says “SIEMENS” on it on the internet needs a different job. by Peter Gabaldon.
- RT Justin Bollinger: Your fourth amendment rights are being eroded by Sean Metcalf.
- Great find! Existing Elastic coverage, plus a new detection for changelist Alternate Data Stream creation by unusual process (MRT.exe) https://github…. by Samir.
- Microsoft Killed My Exploit! Enforcing User-Kernel Separation on Windows with Exploit Mitigations https://x.com/i/broadcasts/1XxygwzkyjvGM by Stephen Sims.
- RT Intigriti: Testing Salesforce Lightning and Aura framework apps manually can quickly turn into a nightmare… But they’re often high-value tar… by Steven Lowson.
- RT U.S. Department of Justice: Today, a $400 million settlement was announced with TikTok, ByteDance, and affiliated entities (TikTok) resolving litig… by SwitHak ().
- RT Splinters.io: https://github.com/Splinters-io/honion by Andy Gill.
- by Wojciech Reguła.
- An LPE in Windows 11 an agent found and exploited for me end-to-end got patched in the August updates https://msrc.microsoft.com/update-guide/en-… by Alex Plaskett.
- RT leor: I recreated the bliss hack! Shout out to everyone who helped - I guess I have to make a write up ontop of what Markus (Doom) did. - It is tru… by Alex Plaskett.
- Wrote a blog post about abusing signed Google Chrome installers to achieve arbitrary code execution https://blog.amberwolf.com/blog/2026/august/tag-yo… by Rich Warren.
- RT Adel Ka: stay tuned for maratus , a macOS static analysis tool i’ll be releasing soon as part of the prep for my upcoming #OBTS v9.0 talk: … by Dave Aitel.
- RT Dennis: Re Read Lindsey’s amazing piece on ExploitGym here: https://decipher.sc/2026/08/20/inside-exploitgym-how-researchers-are-measuring-ai-agent… by Dave Aitel.
- RT Boschko: Now that Unitree has IPO’d, I’ll drop what will likely be my last blog sometime next week. I’m not quite done writing just yet It’s ~… by Simone Margaritelli.
- If you’re using Teltonika network devices, you might have to patch - Dejan from our team at HexArcana found two security bugs there, which were just p… by Gynvael Coldwind.
- RT Adam T.: En mai 2023, j’ai cassé le chiffrement du ransomware Rhysida. Plusieurs victimes ont récupéré leurs fichiers sans payer la rançon. L’… by hasherezade.
- Mimic - Frameless Browser‑in‑the‑Browser (BitB) A single‑script Shadow DOM / MutationObserver library for realistic phishing simulations, easily i… by Panos Gkatziroulis.
- Collection of Beacon Object Files (BOFs). Includes: Enumeration BoFs System Token Stealing https://github.com/beune/bof_collection by Panos Gkatziroulis.
- RT Nicolas Krassas: Opening public the lab + safe PoC for GitLab CVE-2026-19478 / CVE-2026-19650 (GraphQL @gl_introduced ) , since it’s already around… by kmkz.
- RT Valéry Rieß-Marchive | @valerymarchive.bsky.social: Hey @MarceloRivero & @patrickwardle we have a new one here, still targeting macOS, obfuscated… by Patrick Wardle.
- The Bug Bounty Singularity: Our Hackbot - @rez0__ https://josephthacker.com/hacking/2026/07/01/we-built-a-hackbot.html by Swissky.
- Fantastic clear-text passwords and where to collect them (Part 2 - Windows) - @malmoeb https://dfir.ch/posts/fantastic_passwords_windows/ by Swissky.
- RT Martin Sohn Christensen: Recent http://queries.specterops.io updates: • 70+ queries updated, many updates came from community members - thank you … by Rémi GASCOU (Podalirius).
- RT Daily CyberSecurity: A Keycloak account takeover flaw, CVE-2026-18963, lets attackers reset any user’s password with no email verification. Update … by Rémi GASCOU (Podalirius).
- RT Ali Mosajjal: Introducing fortitool: one static Go binary that decrypts and unpacks FortiOS firmware end to end, no openssl, no binwalk, no Python,… by Rémi GASCOU (Podalirius).
- RT Perly : I compiled 11k+ bug bounty reports into one research library last week this week i made some updates based on your responses: > we now … by thaddeus e. grugq.
- RT Ananda Dhakal: I’m finding more bugs than ever. But honestly? I’m enjoying it less than ever. I wrote a blog post on how AI has changed vulnerabili… by thaddeus e. grugq.
- RT 0x12 Dark Development: The technique works We open a handle to the Notepad process and then redirect its kernel handle pointer to point to the… by thaddeus e. grugq.
- RT Raelize: Our @offensive_con 2026 slides are now publicly available: https://raelize.com/upload/research/2026/OffensiveCon-2026_Exploiting-QSEE-Vuln… by thaddeus e. grugq.
- RT VollRagm: About a year ago I built GhostDebug, an x64 VEH-based Windows debugger designed to bypass common debugger-detection checks by avoiding th… by thaddeus e. grugq.
- RT Tony Diver: Exclusive: Iran shut down a British power plant for four days in an unprecedented cyber attack, @Telegraph can reveal tonight. It is th… by thaddeus e. grugq.
- Thank you to everyone who has sent me the magnet link for what they suspect to be a masqueraded GTA VI malware payload. I won’t have time today to bon… by vx-underground.
- Also reproduced. Pretty easy one this. by Vincent Yiu.
- Code Execution via Text Template Files | Playbook & Detection https:// ipurple.team/2026/08/24/text-t emplate/.
- Hackers target WordPress sites in miniOrange auth bypass attacks https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-in-mini… by BleepingComputer.
- TikTok reaches $400M settlement with US over COPPA violations https://www.bleepingcomputer.com/news/legal/tiktok-reaches-400m-settlement-with-us-over-… by BleepingComputer.
- CISA orders urgent patching of actively exploited Zimbra flaw https://www.bleepingcomputer.com/news/security/cisa-orders-urgent-patching-of-actively-e… by BleepingComputer.
- ToxicPanda Android malware uses VPN permissions to block Google Play https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vp… by BleepingComputer.
- Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520) https://www.rapid7.com/blog/post/ra-microsoft-sharepoint-remote-code-exec… by Nicolas Krassas.
- duty1g/x64dbg-mcp-server: x64dbg-MCP Server is a native MCP (Model Context Protocol) plugin for x64dbg that exposes the debugger’s full functionality … by Nicolas Krassas.
- How bot & fraud detection actually works, layer by layer (browser flags → anti-detect engines → sandbox detection → obfuscation) https://trustsig.e… by Nicolas Krassas.
- Tata’s B2B platform returned OTPs in API responses https://eaton-works.com/2026/08/24/tata-nexarc-hack/ by Nicolas Krassas.
- Fake Microsoft security scans trick victims into uninstalling their antivirus https://www.malwarebytes.com/blog/threat-intel/2026/08/fake-microsoft-se… by Nicolas Krassas.
- WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords https://thehackernews.com/2026/08/wordlistloader-delivers-amatera-v… by Nicolas Krassas.
- 24th August – Threat Intelligence Report https://research.checkpoint.com/2026/24th-august-threat-intelligence-report/ by Nicolas Krassas.
- Microsoft Teams now lets admins block external bots from meetings https://www.bleepingcomputer.com/news/security/microsoft-teams-now-lets-admins-block… by Nicolas Krassas.
- Operation QUICSILVER Targets Myanmar Government and IT with QUICAgent Backdoor https://thehackernews.com/2026/08/operation-quicsilver-targets-myanmar…. by Nicolas Krassas.
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account https://thehackernews.com/2026/08/critical-keycloak-pa… by Nicolas Krassas.
- ASOS credential-stuffing attack exposed data of 138,828 customers https://cyberinsider.com/asos-credential-stuffing-attack-exposed-data-of-138828-cust… by Nicolas Krassas.
- AcrStealer – Custom Protocol, Credential Theft & Payload Extraction https://github.com/kaandemir993/AcrStealer-Custom-Protocol-Credential-Theft-Paylo… by Nicolas Krassas.
- AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a dev’s headphones https://www.theregister.com/security/2026/08/… by Nicolas Krassas.
- Token Theft in Microsoft Entra ID (Part 1 of 4): Threat Landscape and Attack Techniques, by @Insinuator https://insinuator.net/2026/08/token-theft-in-… by DirectoryRanger.
- RT Panos Gkatziroulis : CrystalPotato - port of GodPotato, a local privilege escalation from accounts with SeImpersonatePrivilege to SYSTEM. Inclu… by DirectoryRanger.
- Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking https://www.levelblue.com/blogs/spiderla… by DirectoryRanger.
- Detecting a ScreenConnect RMM Attack with Agents https://nebulock.io/blog/detecting-screenconnect-rmm-attack-with-agents by DirectoryRanger.
- RT Haidar: RedNova: From Arbitrary File Write to Command Execution Using COM in Windows Months ago, I wrote a post (https://x.com/haider_kabibo/status… by DirectoryRanger.
- RT Enno Rey: Security Testing of WireGuard Implementations, from @vanhoefm et al. https://papers.mathyvanhoef.com/esorics2026.pdf [PDF] by DirectoryRanger.
- RT Enno Rey: Side-Channel Attacks on Open vSwitch https://www.usenix.org/system/files/usenixsecurity26-kim-daewoo.pdf [PDF] by DirectoryRanger.
- The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors https:// citizenlab.ca/research/uncover ing-global-telecom-exploitation-by-covert-surveillance-acto.
- RT LinearUncle: 突发:Grok Bot 0.18.0 被Bennett 小哥发现打包时未关闭 source maps,原始源代码被他完整逆向还原。 GitHub: https://github.com/b-nnett/… by Dave Kennedy.
- Released the 1st sample (https://pub.expmon.com/analysis/328592/, 594404aac2354fc0185f8de346c06382e4c203ec64673a41a0eae0ed7e37c113) here (password: “e… by Haifei Li.
- RT Mike Manrod: So, a little late to posting this, but if you run CrowdStrike EDR be sure to watch this video by @techspence and Tyler Roberts on @cyb… by The Haag™.
- CVE-2026-18963: Keycloak reset-credentials flow: unauthenticated account takeover CWE-640 https://www.pruva.dev/reproductions/REPRO-2026-00337 #pruva by Giuseppe
N3mes1s. - RT R136a1: I found a previously undocumented passive Windows backdoor I’m calling SLEEPWALKER. Its defining feature is a custom command language with… by Giuseppe
N3mes1s. - CVE-2026-73570: Zimbra Collaboration unauthenticated RCE via Swatchdog/SNMP log-injection command injection swatchrc dosnmp Perl backtick https://www…. by Giuseppe
N3mes1s.
Tools and Exploits
Public exploit for CVE-2026-47301 (CVSS 8.8) in Microsoft SCCM. Chains improper access control into domain user to SYSTEM code execution on the primary site server.
Full workshop materials from DEF CON 34 and BSidesLV. Covers malware development, EDR architecture, evasion techniques, C2 customization, and kernel-level approaches.
Launches from a one-liner, visualizes scan results in real-time in the browser. Designed to answer one question: is this computer compromised?
Updated DreadIndex benchmarks Kimi K3 against frontier models on offensive security tasks. K3 doubles performance in web pentesting, crypto, and reversing over earlier versions.
All talks from the Objective-See Foundation’s OFTW v4 event in Berlin are now available on YouTube. Beginner-friendly Apple security content.
Public PoC for CVE-2026-56197, a command injection vulnerability in Windows Admin Center. Exploitable over the network by an authorized attacker.
- Semgrep Evaluates GLM-5.3 Vulnerability Detection by thaddeus e. grugq.
Semgrep evaluates GLM-5.3 for vulnerability detection. Open-weight models are challenging frontier labs on cost-per-vulnerability found, though they still use more tokens.
- Batch of WebKit Bugs Fixed by Apple by LiveOverflow.
Apple patches a batch of WebKit bugs disclosed by itszn. Update Safari now.
- DutchOven: WFP-Based Network Gating with Detection Strategies by Florian Roth.
Red team PoC using Windows Filtering Platform to temporarily block EDR outbound connections, with detection strategies and Event ID guidance for defenders.
The latest volume of the underground security zine. 21 papers covering viruses, rootkits, ELF internals, weird machines, and more.
More this week (14)
- RT pwn.ai: WordPress just released another emergency update (after XSS2Shell) patching another RCE chain reported by @pwn_ai: CVE-2026-65640 https://w… by Vincent Yiu.
- Reproduced GitLab CVE-2026-19478, on the few times that I’ll held back the lab release as this is a direct destructive operation. Still 90 days embarg… by Nicolas Krassas.
- RT forcequit: So 26.6.1’s final release has a new build number… …but Apple didn’t patch bad_query, so there’s a zero-day sandbox escape in an iOS … by Gergely Kalman.
- AWSHound: An OpenSource AWS OpenGraph Collector by Katherine.
- RT BallisKit: The new BallisKit tool soon to be released, an advanced macOS Mythic implant! All modular, in memory execution, includes private methods… by Melvin langvik.
- Graphing AWS Attack Paths in Bloodhound https://blog.n0pe-sled.com/2026/08/10/awshound-an-opensource-aws-opengraph-collector/ by /r/netsec.
- RT Sysinternals: We’re excited to release Process Monitor with IPC events, ZoomIt for macOS with DemoMirror, and RDCMan and ZoomIt with bug fixes… by Max.
- RT Ollie Whitehouse: The @NCSC has today released initial guidance on ‘Managing the cyber risk of agentic AI’ - this provides defense in depth guidanc… by Rad.
- RT pilvar (Philippe Dourassov): Holy moly: GLM-5.3 got much better in cybersecurity since our pre-release evaluation with @Zai_org. It now matches GPT… by thaddeus e. grugq.
- Decent injection styles here.. by Mike Felch (Stay Ready).
- RT Cristofaro Mune: Slides from #Offensivecon2026 have been released! You may want to peek into our use of secure ranges and XPUs to pwn QSEE on Googl… by Kuba Gretzky.
- RT Piotr Bania: yo ppl, check out https://phrack.org and the new phracktro :D and stay tuned for the new phrack release(s) cheers! by Kuba Gretzky.
- Zscaler Client Connector - Remote Code Execution [CVE-2026-59568] https://help.zscaler.com/zscaler-client-connector/client-connector-app-release-summa… by Nicolas Krassas.
- RT Thomas Seigneuret: New release of DPLoot Now DPLoot can recover secrets over multiple protocols : SMB, WMI, WinRM, MSSQL, Local and Cobalt Str… by DirectoryRanger.
