A roundup of 445 items curated from across the security community.

News

Aikido demonstrates that many small-model agents find more vulnerabilities than a few large-model agents, outperforming Claude Security Mythos at a fraction of the token cost.

DEF CON talk and tools from Xeno and Veronica Kovah on using AI to automatically reverse engineer Bluetooth firmware. LLM skills repo published.

Research demonstrates how Arena.ai’s platform can be used to exfiltrate personally identifiable information from users.

CISA’s red team targeted two organizations with the same tradecraft against Active Directory and Entra ID. One SOC caught them, one didn’t. Full advisory with TTPs published.

A new deserialization vulnerability in Log4j2 via FilteredObjectInputStream triggered alarm. Investigation confirmed the issue was not practically exploitable in default configurations.

Unpatched Log4j RCE via FilteredObjectInputStream bypass disclosed on Apache’s issue tracker before any CVE was assigned. Workaround available.

OpenAI publishes a technical report reconstructing the agents’ activity during the HuggingFace incident, explains why safeguards failed, and details prevention measures.

Nextron Research catches compromised npm package using Ethereum as a dead drop resolver. Obfuscated postinstall fetches and evals JavaScript from a C2 server. Suspected DPRK EtherHiding variant.

VulnCheck bought an $88 ZBT router on Amazon and found two implants: DARKLANTERN provides unauthenticated root shell to anyone on the Internet, SPEAKINGSTONE phones home for remote surveillance.

OpenRGB’s daemon runs as root and listens on 0.0.0.0:6742 with a custom TCP protocol. Remote compromise possible on any system with the daemon enabled.

More this week (41)

Techniques and Write-ups

Kuba Gretzky’s x33fcon talk on credential relay phishing with a live Google phishing demo. Covers techniques for bypassing reverse-proxy phishing detections.

Trail of Bits gave GPT-5.6-Cyber a CTF challenge to escape a QEMU/KVM VM. It escaped three times, including by finding and chaining multiple 0-days after all known bugs were patched.

Windows 11 24H2 generates ETW-TI events when non-admin processes call NtQuerySystemInformation for KASLR bypass. New telemetry for detecting kernel address space enumeration.

New technique for extracting Primary Refresh Token cookies remotely using InteractiveToken scheduled tasks. Works without direct access to the target device.

Purple team playbook for abusing Visual Studio Text Template (.tt) files for code execution. Includes detection strategies for process creation, module loads, and file creation artifacts.

FalconForce’s Black Hat writeup on ETW spoofing and buffer pool exhaustion techniques that deceive analysts and blind EDR sensors.

Unauthenticated root RCE on any Unitree G1 humanoid robot within Bluetooth range. No pairing or authentication required.

MDSec walks through a full ServiceNow red team engagement. Covers discovery, privilege escalation, credential access, and lateral movement through the platform.

ZeroTrace Lab investigates the Windows Global Device Identifier (GDID) to determine whether one device can modify or patch another’s GDID.

Synacktiv releases scripts for flexibly simulating legitimate AD services on the network, demonstrated through GPO exploitation scenarios.

More this week (357)

Tools and Exploits

DEF CON 34 talk on defeating facial recognition systems through strategic styling. Full recording now available.

Intune’s Remote Help now allows helpdesk staff to remotely access physical Windows devices by signing in with their own credentials, without user presence or consent. Red team relevant.

Python-based consumer for Windows Threat Intelligence ETW events. Filter telemetry by target process for both implant development and malware reverse engineering.

Network pentesting tool built on top of TrustedSec’s Titanis framework. Similar to CrackMapExec/NetExec with a growing feature set.

YSoNet grows from 50 to 62 .NET deserialization gadgets with new Framework 2.0 to 3.5 support, dedicated 4.0 coverage, and 508 archived researcher references.

CICADA8 Research ports offensive tools into Chrome via Isolated Web Apps. Run pentest tools entirely from the browser with no local installation.

Claude Code with the Ludus skill spins up a lab with two Exchange 2019 servers for testing CVE-2026-62911. Demonstrates AI-assisted vulnerability reproduction workflows.

The latest Windows 0-day from the anonymous MSNightmare researcher. The tenth in a series timed for the day after Patch Tuesday to maximize the unpatched window.

SpecterOps research recovers cleartext discovery credentials from ServiceNow without coercion or relay. Works on SSH keys, AWS keys, Entra secrets, and LDAP credentials.

New threat intelligence feeds added to the curated open-source collection for security teams and threat hunters.

More this week (17)