A roundup of 445 items curated from across the security community.
News
Aikido demonstrates that many small-model agents find more vulnerabilities than a few large-model agents, outperforming Claude Security Mythos at a fraction of the token cost.
DEF CON talk and tools from Xeno and Veronica Kovah on using AI to automatically reverse engineer Bluetooth firmware. LLM skills repo published.
Research demonstrates how Arena.ai’s platform can be used to exfiltrate personally identifiable information from users.
CISA’s red team targeted two organizations with the same tradecraft against Active Directory and Entra ID. One SOC caught them, one didn’t. Full advisory with TTPs published.
A new deserialization vulnerability in Log4j2 via FilteredObjectInputStream triggered alarm. Investigation confirmed the issue was not practically exploitable in default configurations.
Unpatched Log4j RCE via FilteredObjectInputStream bypass disclosed on Apache’s issue tracker before any CVE was assigned. Workaround available.
OpenAI publishes a technical report reconstructing the agents’ activity during the HuggingFace incident, explains why safeguards failed, and details prevention measures.
- DPRK-Suspected EtherHiding Campaign in npm Package by Florian Roth.
Nextron Research catches compromised npm package using Ethereum as a dead drop resolver. Obfuscated postinstall fetches and evals JavaScript from a C2 server. Suspected DPRK EtherHiding variant.
VulnCheck bought an $88 ZBT router on Amazon and found two implants: DARKLANTERN provides unauthenticated root shell to anyone on the Internet, SPEAKINGSTONE phones home for remote surveillance.
OpenRGB’s daemon runs as root and listens on 0.0.0.0:6742 with a custom TCP protocol. Remote compromise possible on any system with the daemon enabled.
More this week (41)
- Black Hat State of Security Vendors by Bruce Schneier.
- RT Justin Elze: This repo is a great time “Traditional vulnerability disclosure is broken. It’s slow, bureaucratic, and ineffective. In the AI era, we… by Lucas Leong.
- Investigation Scenario While investigating a potentially compromised host, you’ve discovered %LOCALAPPDATA%\Syncthing\config.xml. The user has no… by Chris Sanders.
- RT ar0x: My @x33fcon talk has been published. Hope you like it. by hasherezade.
- RT Netlas.io: CVE-2026-77806: Unauthenticated RCE in SPIP with public exploit and active exploitation, 9.8 rating A recently disclosed vulnerab… by kmkz.
- RT /ˈziːf-kɒn/: #x33fcon 2026 talks: @mez0 - Using EMBER2024 to evaluate red team implants > https://lnkd.in/dNt9cFKp by kmkz.
- RT Cyber Security News: Researcher Discloses Five High-Risk Vulnerabilities in Palo Alto GlobalProtect VPN More Details: https://cybersecuritynew… by Max.
- RT ar0x: Re @x33fcon https://ar0x.com/posts/how-to-tunnel/ The third and probably final part of this blog series (for now), but who knows. by Max.
- RT banteg: this wild defcon talk is finally out researchers created a fake defi startup, hired lazarus it workers, put them into a sandbox and recorde… by Max.
- RT James : My @x33fcon talk is out by Kuba Gretzky.
- RT FBI: CASE UPDATE from @FBIOmaha: Venezuelan Man Sentenced to 8 Years in Prison for ATM Jackpotting Juan Manuel Gouveia-Aguilera, 27, was sentenced … by scriptjunkie (Matt).
- RT The Record From Recorded Future News: The U.S. sanctioned several Iranian nationals on Monday for cyberattacks on critical infrastructure just days… by thaddeus e. grugq.
- LACMA data breach last year exposed social security and medical data https://www.bleepingcomputer.com/news/security/lacma-data-breach-last-year-expose… by BleepingComputer.
- GTA 6 leak hype abused to distribute Vidar infostealer malware https://cyberinsider.com/gta-6-leak-hype-abused-to-distribute-vidar-infostealer-malware… by Nicolas Krassas.
- Carhartt data breach affects 12.9M, half of what ShinyHunters claimed https://www.theregister.com/security/2026/08/26/carhartt-data-breach-affects-129… by Nicolas Krassas.
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia by BrianKrebs.
- Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator https://hunt.io/blog/chinese-speaking-operator-phi… by /r/netsec.
- Looks like Manchester Airport has suffered a breach by Dominic Chell.
- RT etugen.io: Anatomy of an EtherHiding Operation Leak C2 Domains / 14.000+ Active Clients Read: https://etugen.io/blog/etherhiding-blockchain-c2/ #et… by batuu.
- RT Hacker News: This story begins with a 19-year-old researcher buying an expired €5 domain and gaining control of phone-routing DNS for three territ… by scriptjunkie (Matt).
- RT DomainTools: More than just a GRU Hacker School DTI researchers analyzed the internal documents leaked from a long-term training pipeline for R… by thaddeus e. grugq.
- RT John Hammond: The hacker behind TeamPCP was deanonymized and arrested. After a year of headline-making breaches and wild supply-chain attacks, taun… by Vincent Yiu.
- Toy-making giant Hasbro disclose data breach affecting employees https://www.bleepingcomputer.com/news/security/toy-making-giant-hasbro-disclose-data-… by BleepingComputer.
- Love Electric Breach: 877,000 Driver Records Offered for $600 https://securityaffairs.com/198033/data-breach/love-electric-breach-877000-driver-record… by Nicolas Krassas.
- Former DIA IT specialist pleads guilty to attempting to leak classified information https://www.scworld.com/brief/former-dia-it-specialist-pleads-guil… by Nicolas Krassas.
- McKesson discloses breach after ShinyHunters claims patient data theft https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-… by Nicolas Krassas.
- Announcing the Save CTFs Fund - @osec_io https://osec.io/blog/save-ctfs-fund/ by Swissky.
- Hiding Prompt Injection in Legal Filing by Bruce Schneier.
- RT Elli: One curl command on an exposed Azure VM poses a risk of a full subscription compromise via IMDS. Managed Identity tokens are the ultimate bac… by Florian Roth.
- Leaked Russian Cyber-Operations Training Materials by Bruce Schneier.
- What’s the Scam? by Bruce Schneier.
- Ilya is right. I gave a talk on the plague of security weaknesses in neoclouds last summer at DEF CON. Worth a watch! https://www.youtube.com/watch?v=… by Bill Demirkapi.
- Sality botnet infrastructure dismantled in joint global takedown https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantle… by BleepingComputer.
- Aesto Health says data breach affects over 9.5 million patients https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-o… by BleepingComputer.
- Novocure data breach affects more than 1,400 cancer patients https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-4… by BleepingComputer.
- Microsoft Exchange Online outage causes email failures, auth issues https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-c… by BleepingComputer.
- Berlin confirms data theft after Rhysida ransomware attack claims https://www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhys… by BleepingComputer.
- Fake GTA 6 leaked copy drains your crypto wallet https://www.malwarebytes.com/blog/scams/2026/09/fake-gta-6-leaked-copy-drains-your-crypto-wallet by Nicolas Krassas.
- Leaked Russian Cyber-Operations Training Materials https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-training-materials.h… by Nicolas Krassas.
- RT Atitty: NordVPN states that 5 million email addresses got leaked This is why everyone is getting “hacked” today on X by Nicolas Krassas.
- Wireless Routers as Motion Detectors by Bruce Schneier.
Techniques and Write-ups
Kuba Gretzky’s x33fcon talk on credential relay phishing with a live Google phishing demo. Covers techniques for bypassing reverse-proxy phishing detections.
Trail of Bits gave GPT-5.6-Cyber a CTF challenge to escape a QEMU/KVM VM. It escaped three times, including by finding and chaining multiple 0-days after all known bugs were patched.
- Windows 24H2 ETW-TI Events for KASLR Bypass Detection by winterknife.
Windows 11 24H2 generates ETW-TI events when non-admin processes call NtQuerySystemInformation for KASLR bypass. New telemetry for detecting kernel address space enumeration.
New technique for extracting Primary Refresh Token cookies remotely using InteractiveToken scheduled tasks. Works without direct access to the target device.
Purple team playbook for abusing Visual Studio Text Template (.tt) files for code execution. Includes detection strategies for process creation, module loads, and file creation artifacts.
FalconForce’s Black Hat writeup on ETW spoofing and buffer pool exhaustion techniques that deceive analysts and blind EDR sensors.
Unauthenticated root RCE on any Unitree G1 humanoid robot within Bluetooth range. No pairing or authentication required.
MDSec walks through a full ServiceNow red team engagement. Covers discovery, privilege escalation, credential access, and lateral movement through the platform.
ZeroTrace Lab investigates the Windows Global Device Identifier (GDID) to determine whether one device can modify or patch another’s GDID.
Synacktiv releases scripts for flexibly simulating legitimate AD services on the network, demonstrated through GPO exploitation scenarios.
More this week (357)
- Linux: fork() failure path tries to clean up BPF task storage that was never initialized, leading to UAF https://project-zero.issues.chromium.org/issu… by Project Zero Bugs.
- Call center scammers sending accomplices stateside to physically retrieve from victims, as other defenses have increased https://www.yahoo.com/news/us… by SwiftOnSecurity.
- RT CERT-FR: Ciblage de téléphones Apple Le CERT-FR a connaissance de notifications envoyées par Apple le 13 août 2026 à des utilis… by SwitHak ().
- RT Andrew Thompson: Project Swarm is dope for a bunch of reasons. First, selfishly, I want as expansive data as possible to enable evil finding. Secon… by SwitHak ().
- RT PT SWARM: IPAHound has received an important update! Now we support BloodHound CE. You can use the “-O” collector flag to output in OpenGraph fo… by Arseniy Sharoglazov.
- Insight into agentic hacking tools: Hermes, OpenClaw and the Bayesian brain https://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-comp… by /r/netsec.
- Tata’s B2B platform returned OTPs in API responses https://eaton-works.com/2026/08/24/tata-nexarc-hack/ by /r/netsec.
- State divergence enables unauthorized access.
- RT Nebula Security: Re With Demo Day approaching, we’re dropping one end-to-end Linux kernel exploit every day starting today. Daily drops: https://gi… by Lucas Leong.
- RT Nadim Kobeissi: 0 = 1 proven in Lean. Exciting and novel result! https://github.com/endrazine/lean-cve-poc by Lucas Leong.
- https://github.com/basecamp/omarchy/commit/9285b19d6a72eba3df8537d62a4cd5506a803d89 ah, the year of linux on the desktop: strings from USB descriptors… by blasty.
- CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling https:// minanagehsalalma.github.io/zyx el-social-login-bypass-cve-2026-8508/.
- RT Nextron Research : We identified malicious DOC samples with technical and thematic similarities to recent #CloudAtlas activity described by Pos… by Florian Roth.
- RT Nextron Research : We identified multiple LNK samples showing strong technical and thematic overlap with recent #Kimsuky activity described by … by Florian Roth.
- RT Nextron Research : Follow-up on REDSHELL: we found a newer ELF in three npm packages “hydration-dim-kit”, “hydration-dim-ui” and “hydration-ui-… by Florian Roth.
- RT Nicolas Krassas: A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw https://thehackernews.com/2026/08/a-malicious-webpage-… by Simone Margaritelli.
- Here are the Shazzer fuzz vectors I used whilst testing this: https://shazzer.co.uk/vectors/6a68f8a5be9b6c0ce7ba44e2 https://shazzer.co.uk/vectors/6a7… by Gareth Heyes \u2028.
- This is awesome by Gergely Kalman.
- This didn’t take long by Gergely Kalman.
- RT Olivia Gallucci : If you haven’t browsed the @SummerC0n research, I highly recommend Nicole Reichert’s post/talk on packing malware and exploitin… by hasherezade.
- Throttling EDR Agents with QoS Policies https://ipurple.team/2026/06/17/qos-policies/ by Panos Gkatziroulis.
- The Navigator has been updated to include the recent techniques: Provisioning Packages Execution Mandatory User Profile Persistenc… by Panos Gkatziroulis.
- RT St0pp3r: I just published my first blog post on Medium: Threat Hunting Using Pair Probabilities. https://medium.com/@st0pp3r/threat-hunting-using-p… by Panos Gkatziroulis.
- SliverMirage - Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants htt… by Panos Gkatziroulis.
- Rogue-Framework - a desktop workbench for AFL++, cross-architecture QEMU fuzzing, harness development, lightweight Ghidra headless analysis, custom mu… by Panos Gkatziroulis.
- A quick video of how to use MSBuild.exe to target a .csproj file that has been tampered with multiple text template files and execute code embedded in… by Panos Gkatziroulis.
- Beacon Object File (BOF) implementation of the dnscmd.exe functionality used to obtain remote code execution on an ADIDNS server by exploiting the Ser… by Panos Gkatziroulis.
- CrystalPotato - port of GodPotato, a local privilege escalation from accounts with SeImpersonatePrivilege to SYSTEM. Includes: indirect syscalls … by Panos Gkatziroulis.
- RT BlackRoomSec: JUST DROPPED: NIST SP 1347 - Final - Cybersecurity Framework 2.0: Informative References Quick-Start Guide Maps references to Categor… by Chihuahua in charge NotMe.
- RT R136a1: I found a previously undocumented passive Windows backdoor I’m calling SLEEPWALKER. Its defining feature is a custom command language with… by kozmer.
- RT VulnCheck: VulnCheck developed the first weaponized exploit chaining two recently patched Microsoft SharePoint vulnerabilities, CVE-2026-55040 and … by kmkz.
- RT V12: surprise! bonus redis server RCE poc: https://github.com/v12-security/pocs/tree/main/redis/server_ssl use-after-free in tlsProcessPendingData(… by kmkz.
- RT Simo: hunny hunny by kmkz.
- RT Nebula Security: Today’s exploit targets a 13-year-old UAF in Red Hat Enterprise Linux 10: CVE-2026-52923. It was introduced in Jan 2013 and fixed … by kmkz.
- RT Haifei Li: Released the 1st sample (https://pub.expmon.com/analysis/328592/, 594404aac2354fc0185f8de346c06382e4c203ec64673a41a0eae0ed7e37c113) here… by kmkz.
- RT Tashita Software Security: CVE-2026-11645 is a V8 vulnerability that Google confirmed had been actively exploited. Based on the analysis of the PoC… by kmkz.
- RT Pen Test Partners: They could break IT/OT segregation without having to do… Anything? During an OT engagement, @Blackf3ll and @OPSEC_failed found … by kmkz.
- RT I’M H4CK3R 42: No Username. No Password. Just a Header - A $3,000 Authentication Bypass by ALR ALR (x/00xalr) https://med… by Spiros Fraganastasis.
- RT SunSec: Re https://www.slcyber.io/research/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6#is-gpt56-sol-superhuman by Spiros Fraganastasis.
- RT LinearUncle: 要是年轻 10 岁,我大概还会折腾折腾这些东西。Windows 平台上的开源二进制红队逆向神器:x64dbg。 https://x64dbg.com/ 而今天想重点介绍的,… by Spiros Fraganastasis.
- RT UnveiledChina: A developer using Bluetooth headphones accidentally caught Chinese e-commerce giant Alibaba secretly hijacking his computer’s audio … by Spiros Fraganastasis.
- RT pilvar (Philippe Dourassov): We burned 11.7bn tokens benchmarking models to find which one is the best at cyber full blog post about the benchmark … by Spiros Fraganastasis.
- blackorbird: Microsoft Paint and Photos Embed Server-Issued GUIDs as Invisible Watermarks in Locally-Generated Images Reverse engineering reveals how Paint and Photos embed a server-issued GUID into t by MalwareHunterTeam.
- RT : A Real-World Law-Enforcement Hack: The Case of Encrochat https://eprint.iacr.org/2026/1319 LE pulled encryption keys from 2 unencrypted TANG … by Max.
- RT zhassulan zhussupov: https://cocomelonc.github.io/malware/2026/08/24/malware-tricks-63.html next one from my blog. enjoy! https://t.me/maldevcc/262… by Max.
- RT Haidar: Re Sorry I put the wrong link, the correct link: https://sud0ru.ghost.io/rednova-from-arbitrary-file-write-to-command-execution-using-com-i… by Max.
- RT Stephen Sims: Thanks again to @yarden_shafir for sharing her research on exploiting I/O Rings on Windows, along with the work Microsoft has done to… by Mathieu Tarral.
- CVE-2026-72898: A critical unauthenticated SQL injection vulnerability in Metabase is being actively exploited. The vulnerability affects the pas… by OffSec.
- RT Marcelo Rivero: #PamStealer macOS infostealer · new JXA loader fake CleanDev clones DevCleaner → cleandev[.]cc one char-code .js =… by Patrick Wardle.
- Considering attackers’ increasing fondness for dylib-based payloads, I’d argue it’s about time! by Patrick Wardle.
- Detect using nuclei template https://x.com/dhiyaneshdk/status/2092010596980150359 by Nuclei by ProjectDiscovery.
- RoguePlanet: Defender Quarantine Pipeline LPE Zero-Day - @offsitedark https://www.offsitedark.com/signals/rogueplanet-defender-lpe-zero-day by Swissky.
- Local AI for Penetration Testing & Research - Eddie Zhang https://projectblack.io/blog/local-ai-for-cyber-security/ by Swissky.
- Fascinating Steve Yegge post: fences, not sandboxes. I suspect we’ll always need a bit of both in a future pervasively agentic enterprise. That is, sa… by Phil Venables.
- RT Stephan Berger: After a bit of tinkering, I was able to replicate the Google Docs attack vector described in the Huntress blog post [1] Attackers c… by Mari0n.
- Apparently, I’m not done hunting JDBC vulnerabilities in IBM products. It started with my first report years ago. Found another one this year, bringi… by pyn3rd.
- RT careful: leaking Microsoft employee secrets through diagnostic data: https://careful.net/blog/powerlift/ by Sam Curry.
- Chaining three public V8 bugs to escape the V8 sandbox and recover a real Google v8CTF flag https:// blog.himanshuanand.com/2026/08 /i-had-some-free-time-so-i-tried-to-pwn-v8/.
- When the killer robots come, will you know how to fight back? Don’t delay - read my article on the taxonomy of machine-stopping paradoxes to protect yourself and your loved ones: https:// lcamtuf.core.
- RT 丂卄ㄖᗪ卂几 - crack fingers: I remember a hydroelectric dam in the Netherlands They accidentally put their HMI (control panel) on the interne… by thaddeus e. grugq.
- RT Lukasz Olejnik: Enter AI GRINDING to break cryptography! What happens when cryptanalytic ideas become cheap? AI agents allow efficient and mass-sca… by thaddeus e. grugq.
- RT Lukasz Olejnik: We broke a CRT-RLWE fully homomorphic encryption scheme and identified a key & plaintext recovery attack against this recently publ… by thaddeus e. grugq.
- RT Dark Web Intelligence: Researchers Uncover Covert Global Telecom Surveillance Campaigns Citizen Lab has uncovered two sophisticated surveillan… by thaddeus e. grugq.
- RT Nicolas Krassas: Local Privilege Escalation To System In Wibu-Systems CodeMeter Application https://shelltrail.com/research/local-privilege-escalat… by Mike Felch (Stay Ready).
- I wonder if this is what their Project MockingJay https://mockingjay.flocksafety.com/ is all about. Kind of an eerie name for a project at a surveilla… by Mike Felch (Stay Ready).
- > be me > get dm > “smelly, someone sent our company an e-mail with an attachment that looks malicious. i work at a large company. what is it?” > wtf … by vx-underground.
- If you’re going to distribute malware, at least have the common courtesy to do it in a manner which allows EVERYONE to get the malware. Last time on D… by vx-underground.
- Bruh does this just directly set the password? lol be careful if you’re going to run this it’s not an enum check from looks of it. by Vincent Yiu.
- RT Vikas Anil Sharma: Just reproduced the critical CVE-2026-18963 - a Keycloak account takeover vulnerability. Pretty wild time to be doing security r… by Vincent Yiu.
- RT Stephen Fewer: We have published a technical analysis for CVE-2026-63520, the Microsoft SharePoint RCE we disclosed earlier this month: https://www… by Bobby Cooke.
- Read more about our investigation into the Hugging Face incident! by Bill Demirkapi.
- New GPUThor attack defeats NVIDIA ECC protection for root access https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-nvidia-ecc-… by BleepingComputer.
- Hackers target Microsoft SharePoint RCE chain with PoC exploit https://www.bleepingcomputer.com/news/security/hackers-target-microsoft-sharepoint-rce-… by BleepingComputer.
- Hackers now exploit critical Gitea flaw in code injection attacks https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-fl… by BleepingComputer.
- Hackers abuse npm mirrors to host phishing redirect pages https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to-host-phishing-re… by BleepingComputer.
- AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes https://www.bleepingcomputer.com/news/security/anonymouskit-phaas-uses-voice-ai-agen… by BleepingComputer.
- Massive DDoS attack disrupts Norway’s government digital services https://www.bleepingcomputer.com/news/security/massive-ddos-attack-disrupts-norways… by BleepingComputer.
- Hospital operator Nutex Health says data stolen in cyberattack https://www.bleepingcomputer.com/news/security/hospital-operator-nutex-health-says-data… by BleepingComputer.
- FBI Seizes China-Linked Hacking Platforms QScan and QTRouter Used Against Critical Infrastructure https://securityaffairs.com/197873/apt/fbi-seizes-ch… by Nicolas Krassas.
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with… by Nicolas Krassas.
- US lawmakers question CISA workforce cuts amid rising cyber threats https://www.scworld.com/brief/us-lawmakers-question-cisa-workforce-cuts-amid-risin… by Nicolas Krassas.
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions https://thehackernews.com/2026/08/novacookies-campaigns-abu… by Nicolas Krassas.
- Chaining three public V8 bugs to escape the V8 sandbox and recover a real Google v8CTF flag https://blog.himanshuanand.com/2026/08/i-had-some-free-tim… by Nicolas Krassas.
- Boston Scientific says cyberattack disrupted operations globally https://www.bleepingcomputer.com/news/security/boston-scientific-says-cyberattack-dis… by Nicolas Krassas.
- CVE-2026-75604 Next.js Windows RCE poc https://github.com/rafabd1/CVE-2026-75604-poc by Nicolas Krassas.
- FBI disrupts proxy network enabling Chinese espionage operations https://www.bleepingcomputer.com/news/security/fbi-disrupts-proxy-network-enabling-ch… by Nicolas Krassas.
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-c… by Nicolas Krassas.
- Snowflake ends service-account passwords. Now comes the hard part https://www.bleepingcomputer.com/news/security/snowflake-ends-service-account-passwo… by Nicolas Krassas.
- Ubiquiti patches three max severity security vulnerabilities https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-securi… by Nicolas Krassas.
- OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation https://thehackernews.com/2026/08/openai-bans-russian-chatgpt-accounts.html by Nicolas Krassas.
- Dark Caracal Reloaded: New Malware, Same Hunting Grounds https://arcticwolf.com/resources/blog/dark-caracal-reloaded-new-malware-same-hunting-grounds/ by Nicolas Krassas.
- Spyware for Babies https://www.schneier.com/blog/archives/2026/08/spyware-for-babies.html by Nicolas Krassas.
- RT 0x12 Dark Development: The technique works We open a handle to the Notepad process and then redirect its kernel handle pointer to point to the… by DirectoryRanger.
- Ai native RMM! by The Haag™.
- 1st Edition: Living off the Land Magic Quadrant by The Haag™.
- If you need it - https://LOLRMM.io - still there. May not be mentioned in RMM blogs, but hey - if you want a true corpus of the scale of RMMs out ther… by The Haag™.
- ClickGrab gives us some hard data on the delivery side. Across 120 analyzable nightly reports covering 11,924 site observations, we found 11 unique Cl… by The Haag™.
- RT Cyber_OSINT: Malwarebytes reports that PavinLoader operates across RenPy, ClickFix, and fake-downloader campaigns, leveraging multi-stage, obfuscat… by The Haag™.
- CVE-2026-60004: Gitea diffpatch Git hook installation leads to remote code execution https://www.pruva.dev/reproductions/REPRO-2026-00312 It only took… by Giuseppe
N3mes1s. - GHSA-LOG4J2-4255-MARSHALLEDOBJECT: Apache Log4j2 serialized LogEvent filter bypass to conditional RCE https://www.pruva.dev/reproductions/REPRO-2026-0… by Giuseppe
N3mes1s. - Let the agent wrote an article about it: Not Another Log4Shell: A Serialized-Event Receiver Boundary https://www.pruva.dev/research/log4j2-serialized-… by Giuseppe
N3mes1s. - CVE-2026-21962 - Oracle WebLogic Proxy Plug-in (CVSS 10.0, CISA KEV) going to wait a little bit more before publishing this #pruva repro but you can … by Giuseppe
N3mes1s. - RT Previdian: We’re starting to see exploitation attempts for Keycloak Force Password Reset (CVE-2026-18963) against one of our Keycloak sensors in So… by Giuseppe
N3mes1s. - Ever wondered how an external developer can work with Outflank to get their tool into OST? We explore the process of incorporating infraRED, which can… by Outflank.
- RT Gareth Heyes \u2028: Re Full write up and explanation: https://portswigger.net/research/whats-in-a-tag-name-javascript-apparently by PortSwigger Research.
- RT rootsecdev: there is no spoon ..only @Spoonman1091 Super pumped to see this blog out by Sean Metcalf.
- RT Merill Fernando: On 3 Nov, Microsoft retires memberOf for Entra dynamic groups. It won’t throw an error. Your groups will just quietly freeze in th… by Sean Metcalf.
- RT Denis Laskov 🇮🇱: Hacking hardware security key into an air-gap-jumping worm: the hidden features of a YubiKey. More deta… by Sean Metcalf.
- RT ytcracker.sol/.eth : worked hard on this with the homies https://www.aboutamazon.com/news/devices/ring-take-encryptio… by SwiftOnSecurity.
- RT GreyNoise: Most of the Log4Shell probing GreyNoise observed this week came from a single commercial scanning service. Roughly three fifths of the t… by SwitHak ().
- RT FBI Cyber Division: Today, the @FBI and @TheJusticeDept announced the disruption of a global botnet used by Chinese state-sponsored group known as … by SwitHak ().
- PoC is up. Also lifted the task vm portion out into a standalone component technique, in the catalog as Sleepwalker Task VM (BM-T4009). The PoC stays … by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- recreating this right now and lifting pieces for micro techniques to plug into new implants by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- JavaScript obfuscation: From party trick to phishing kit by James Hodgkinson.
- LLM-Based Social Engineering Scams by Bruce Schneier.
- Another CVE on the board CVE-2026-77551 https://community.ui.com/releases/Security-Advisory-Bulletin-067/fc4a3488-7c43-4628-8bab-f715e96dbfc9 by Andy Gill.
- PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure https://www.acronis.com/en/tru/posts/patchcord-new-malwa… by /r/netsec.
- Minimus is shutting down after raising $51M, Twistlock founders returning cash to investors https://www.calcalistech.com/ctechnews/article/bj0s5ikdmx by /r/netsec.
- Ruby Marshal Kick-off Gadgets - elttam https://www.elttam.com/blog/ruby-marshal-kick-off-gadgets by /r/netsec.
- Unauthenticated remote uninstall in my own EDR agent, and the four other auth bugs that turned out to be the same bug https://d3vhex.github.io/2026-08… by /r/netsec.
- Pwning Call of Duty 1: a 20-year-old RCE, found in an evening with AI https://zolder.io/en/blog/pwning-call-of-duty-1/ by /r/netsec.
- Local Privilege Escalation To System In Wibu-Systems CodeMeter Application https://shelltrail.com/research/local-privilege-escalation-to-system-in-wib… by /r/netsec.
- RT Vector 35: Sidekick users are showing us how useful it can be in their work, and we want to make it easier for more Binary Ninja users to experienc… by winterknife.
- RT John U: Re @winterknife Yarden documented the full set of APIs covered. https://windows-internals.com/an-end-to-kaslr-bypasses/ by winterknife.
- RT DARKNAVY: We just got a root shell on a @Starlink terminal antenna! To our knowledge, this is the first full exploit of a “square dish” since @Lenn… by Alex Plaskett.
- by Bad Sector Labs.
- “Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend by David J. Bianco.
- VulnCheck found two more built-in implants in ZBT routers, in addition to ENDLESSDOORS One provides remote root command execution. The other can steal… by Florian Roth.
- RT @eyalsela: In a new report we document Aurora ransomware activity from recent months, includng the use of Cursor Agent to asist with exp… by Florian Roth.
- RT Byron Wan: Aug 26: Department of Justice and FBI announced court-authorized domain seizures to deny malicious cyber actors access to two complement… by Florian Roth.
- RT Nextron Research : We’ve identified “pybitjs”, the first NullReceiver package we’ve observed on PyPI. This is an intentionally crafted ma… by Florian Roth.
- RT Nextron Research : The REDSHELL payload is now disguised as “math.mjs”, replacing the previously used .dat and .bin extensions. Our artifact sc… by Florian Roth.
- RT Daily CyberSecurity: Two critical Next.js vulnerabilities, including CVE-2026-75604 (CVSS 9.0), enable unauthenticated remote code execution. Patch… by Florian Roth.
- RT 0xor0ne: ASLR-independent RCE chain on the stock official nginx 1.30.0 https://blog.verichains.io/p/two-bytes-to-rce-chaining-rift-poolslip #infose… by Florian Roth.
- RT nopnop: Just published the writeup for my RCE in Google Cloud Application Integration, found last year - before this whole AI vulnpocalypse. https:… by Daax.
- RT Giuseppe
N3mes1s: Not it is no the next Log4shell. Ok so i reproduce with #pruva and going to publish as soon as this is patched. There are preco… by Dave Aitel. - Adding more feature day by day, with even more BOFs supported while in development Havoc is a great opportunity to understand and learn C2s all being … by David.
- RT Cyber_OSINT: Group-IB Threat Intelligence enriched public data on the Tortoiseshell APT, hunted for threats, and found new samples sharing similari… by Dominic Chell.
- RT michael : by dreadnode.
- RT Nicolas Krassas: New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access https://thehackernews.com/2026/08/gputhor-rowhammer… by Simone Margaritelli.
- RT Daily CyberSecurity: TeamViewer patched CVE-2026-19042, a Linux command injection flaw, and a path traversal bug. Both TeamViewer vulnerabilities e… by Simone Margaritelli.
- RT JP Aumasson: I used GPT to break MERIDIAN, a blockcipher posted on ePrint https://www.bfswa.blog/p/blood-meridian-131 by Simone Margaritelli.
- RT Invoke RE: We’ve uploaded our live stream from August 18th where we broke Pyarmor with Frida to recover JavaScript malware payloads, enjoy! by hasherezade.
- RT 0x12 Dark Development: PatchGuard Analysis, amazing work!! I’ll definitely be reading this deeply soon. Might try to dig deeper into this Windows … by hasherezade.
- RT etugen.io: Fortigate VPN Exploit And More!!! 38[.]54.68.88 - Exploit TrashPile 43[.]228.124.241 - Reverse Shell Listener 43[.]228.126.36 - Exploit … by batuu.
- RT The Vertex Project: A residential IP with 1,000+ inbound connections to a non-standard high port. What is this box doing? See how Vertex Synap… by visi stark.
- The Power of AI stratumC2 - Cloud-native C2 framework using cloud storage as dead-drop communication channel https://github.com/LAME-Projects/str… by Panos Gkatziroulis.
- MassDriver - Proxying sensitive API calls from shellcode to artifact for CET-compatible clean call stacks. https://github.com/Sizeable-Bingus/MassDriv… by Panos Gkatziroulis.
- MmMapIoSpace Returns NULL: Tracing the Real Kernel Mechanism Through ntoskrnl https://sibouzitoun.tech/articles/mmmapiospace-returns-null-tracing-the-… by Panos Gkatziroulis.
- RT FalconForce Official: What if you could leverage Event Tracing for Windows (ETW) to manipulate telemetry data, challenging the trust placed in endp… by Panos Gkatziroulis.
- ditto - Powershell & Javascript Obfuscator https://github.com/airbus-cert/ditto by Panos Gkatziroulis.
- RT 0x12 Dark Development: Handle Redirect New Medium post. In this one we will see how to redirect a handle’s kernel object pointer to a different EP… by Panos Gkatziroulis.
- Reading an open letter by an array of security firms demanding a “global surge in cyber defense”? First consider the vast cost gap between: 1. Getting all >1000 orgs hit by TeamPCP to run elaborate su.
- RT strandjs - strandjs@bsky.social: NSA, FBI, CISA, DOE, and EPA just went public with AI-assisted attacks on Siemens PLCs hitting critical infrastruc… by Jeff McJunkin.
- RT Moloch: Finally got around to implementing e2e shellcode unit tests; I think Sliver currently has the broadest shellcode/encoder/compression comp… by Chihuahua in charge NotMe.
- RT Tashita Software Security: New post: Fuzzing Complex JavaScript Structures JavaScript fuzzers are good at generating unusual programs. But deeply n… by kmkz.
- RT Himanshu Anand: I chained 3 public V8 bugs against Google’s v8CTF Chrome build and got a real flag. OOB read → GC stale slot → fake array → cage… by kmkz.
- RT Nick Mykhailyshyn 🇺🇦: A deep dive into a pre-auth RCE vulnerability in Plausible Analytics via WebSockets https://whoareme.com/blog/plausible… by kmkz.
- RT Johann Rehberger: Breaking Claude Code Opus 5 Auto Mode 1/ Here is a somewhat hilarious attack chain that hijacks Claude Code Opus 5 for a ful… by Max.
- RT : PCFG -a 4 mode is impressive. If you build from the repo the attacks are now included. A ruleset is included, but to make your own (in re… by Max.
- Hacktics & Telemetry, Episode 13 is live! Courtroom Prompt Injections and WhatsApp’s Blind Spots (ft. Max Günther)! Get it here: https://www.youtube…. by Metasploit Project.
- RT Merill Fernando: Re @nikhil_mitt asked for more so I’ll share here Here’s the reason why it’s not expanding the surface to migrate from AD to … by Nikhil Mittal.
- How to Create a Makeshift C2 with Claude Code as the Operator - @G3tSyst3m https://g3tsyst3m.com/c2/How-to-Create-a-Makeshift-C2-with-Claude-Code-as-t… by Swissky.
- Popping Microsoft’s Sandbox: Dataverse Security Risks in Plugin Containers - Simon Maxwell-Stewart https://www.beyondtrust.com/blog/entry/dataverse-s… by Swissky.
- RT Martin Sohn Christensen: Preview of upcoming BloodHound multi-hop-pathfinding feature https://github.com/SpecterOps/BloodHound/pull/2954 by Swissky.
- RT Laluka@OffenSkill: Gg to my guys TableBasse & Midfirewear, students at @OteriaCS for their frappe RCE under @OffenSkillCorp supervised research! �… by Swissky.
- RT bluerust: We’ve open-sourced an alternative IDA Pro MCP server for AI-assisted reverse engineering! Originally inspired by Duncan Ogilvie’s … by Mayuresh 🇮🇳.
- Every now and again I read a blog post that I wish I’d written. This is one of them. Good stuff. https://dadrian.io/blog/posts/whack-a-mole-is-losing/ by Phil Venables.
- In the Tomcat August security bulletin, 6 CVEs were independently discovered and reported by our team (@4ra1n_x and unam4). Official severity ratings:… by pyn3rd.
- RT Dmitri Alperovitch: Black Mirror hacking group publishes what it claims are internal Russia’s Sberbank assessments of the war. Perhaps the most in… by thaddeus e. grugq.
- RT Alexandre Becholey: HvArm Ch.5: the UEFI shell is now interactive at EL1, under the hypervisor. A frozen prompt is a dead timer. I nearly wrote GIC… by Axel Souchet.
- RT K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵: Communications learning path. Recently added Reverse Socks Pivot and Framed Magic-Packet (Sleepwalker) by Bobby Cooke.
- RT nullptrs: Reverse Engineering My ADHD Test by @blastbots https://nullpt.rs/reverse-engineering-adhd-test by Jord.
- I got the latest iOS and macOS 27 booting in Qemu (with SPTM!) - Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac supported - Debug, patch, o… by Joseph Ravichandran.
- We recently stood up an isolated lab to reproduce a Log4j deserialization issue, and what stuck with us was how little the victim showed for it. Read … by Black Hills Information Security.
- Over 8,300 Gitea servers exposed online are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks. https… by BleepingComputer.
- ServiceNow warns of three max severity security vulnerabilities https://www.bleepingcomputer.com/news/security/servicenow-warns-of-three-max-severity-… by BleepingComputer.
- Android 17 adds ECH support to make web browsing harder to track https://www.bleepingcomputer.com/news/security/android-17-adds-ech-support-to-make-we… by BleepingComputer.
- Australia arrests alleged TeamPCP hackers behind supply-chain attacks https://www.bleepingcomputer.com/news/security/australia-arrests-alleged-teampcp… by BleepingComputer.
- RT tuckner: This is basically a full blown browser C2 over an encrypted websocket channel. Many have been sneaking into marketplaces. by Michael Weber.
- Researcher shows how Claude Code can be tricked simply by asking it to summarize a website https://www.theregister.com/research/2026/08/28/researcher-… by Nicolas Krassas.
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable https://thehackernews.com/2026/08/cosmos-evm-flaw-exploite… by Nicolas Krassas.
- Skimming on the Blockchain: A Magecart Campaign That Uses EtherHiding, Found by Malvertising Scanning https://blog.confiant.com/p/skimming-on-the-bloc… by Nicolas Krassas.
- PaperCut releases second emergency patch for exploited flaws https://www.bleepingcomputer.com/news/security/papercut-releases-second-emergency-patch-f… by Nicolas Krassas.
- Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network https://thehackernews.com/2026/08/berlin-refuses-to-pay-hackers-who-stole.h… by Nicolas Krassas.
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.ht… by Nicolas Krassas.
- GiveWP WordPress donation plugin flaw lets hackers execute server commands https://www.bleepingcomputer.com/news/security/givewp-wordpress-donation-pl… by Nicolas Krassas.
- Suspected Chinese Bot farm of approx 200,000 accounts, involved in influence operations idenfied by X https://ministryofcyberaffairs.com/news/suspecte… by Nicolas Krassas.
- US government snitch-finder pleads guilty to leaking state secrets to foreign spies https://www.theregister.com/security/2026/08/28/us-government-snit… by Nicolas Krassas.
- RT Giuseppe
N3mes1s: Re @PaperCutDev PaperCut NG / MF has been hit by an undisclosed attacker through a 0day! #pruva was able to reproduce the 0day … by Nicolas Krassas. - RT DirectoryRanger: Token Theft in Microsoft Entra ID (Part 1 of 4): Threat Landscape and Attack Techniques, by @Insinuator https://insinuator.net/202… by DirectoryRanger.
- RT Zack Korman: Confirming what we already knew: The OpenAI Hugging Face incident would have been prevented had OpenAI been monitoring the agents in a… by Azeria.
- RT METR: METR & Redwood Research investigated agent behavior in the Hugging Face incident. We found agents developed a universal cheat for ExploitGym … by Azeria.
- RT Matthew Green: More TEE attacks, this time on Signal’s contact discovery enclaves. https://v12.sh/blog/signal by Dave Kennedy.
- Ok probably I need to publish the repro as well! Tomorrow will do it. Stay tuned. by Giuseppe
N3mes1s. - RT Previdian: CVEs have now been assigned to these vulnerabilities. CVE-2026-81578 and CVE-2026-82078 Our pre-CVE temp ID (VULN-2026-0001) now links t… by Giuseppe
N3mes1s. - RT Huntress: Huntress has observed an active zero-day vulnerability being exploited in PaperCut NG / MF. @PaperCutDev has confirmed this gives an unau… by Giuseppe
N3mes1s. - Is a video teaser enough to find the bug ? i would say yes by Giuseppe
N3mes1s. - RT H4x0r.DZ 🇰🇵: 127.0.0.1:3000/_next/image?url=/poc.avif&w=128&q=75 https://github.com/vercel/next.js/security/advisories/GHSA-2xp9-vwfh-vxw4 ht… by Giuseppe
N3mes1s. - PrestaShop team have fixed the vuln I reported some months ago https://github.com/PrestaShop/PrestaShop/security/advisories/GHSA-2cr4-vw9p-pjvf by Peter Gabaldon.
- Learning macOS Internals Through Reverse Engineering https://x.com/i/broadcasts/1OxwbnDNRjPJB by Stephen Sims.
- RT Global Government Affairs: The X Safety team conducted an investigation into suspected Chinese inauthentic accounts involved in influence operation… by SwitHak ().
- BlueDelta🇷🇺 which overlaps with APT28/Fancy Bear/Forest Blizzard, Targets Defense and Diplomacy with HOOKEDGE | By @RecordedFuture INS… by SwitHak ().
- RT Validin: Researching 3 clusters recently reported by GTIG to find unreported fake banquet invitations, Google Drive links, and more. Inhospitable: … by SwitHak ().
- RT Jigsaw: Every time you open an app, your phone reveals more than you might think. Even with HTTPS, the domain name you’re connecting to is visible … by SwitHak ().
- Started digging into ServiceNow at the annual SpecterOps hackathon earlier this year after being intrigued by @_invictus ’s “Red Teaming with Servic… by Matt Creel.
- Just what you want to see 5 mins after ordering new UniFi gear :D by Rasta Mouse.
- RT Alexander Culafi: NEW on @DarkReading: The Vulnpocalypse Is Repricing the Bug Bounty Economy Feat. @Hacker0x01 @Bugcrowd @dustin_childs @D0rkerDevi… by Wojciech Reguła.
- Slack will not patch this: one link opens a debugging port in the desktop app https://trustsig.eu/blog/slack-devenv-remote-debugging-port/ by /r/netsec.
- One Resident Login, an Entire Apartment Complex: The Master PIN in Rently’s API (CVE-2026-75960) https://planckdefense.com/blog/rently-master-pin-idor… by /r/netsec.
- A fake resume invoked China’s defence tech elite, then installed VShell https://blog.himanshuanand.com/2026/08/a-fake-resume-invoked-chinas-defence-t… by /r/netsec.
- LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation https://www.elastic.co/security-labs/llm-reversing-vs-llm-obfuscation by /r/netsec.
- Wicked talk from @two06 on IVR’s for social engineering https://www.youtube.com/watch?v=T7lKFDta530 by Adam Chester.
- RT Jordy Zomer: I accidentally turned LLM memory into program analysis https://pwning.systems/posts/llm-memory-program-analysis/ by Alex Plaskett.
- RT Nicolas Krassas: adscanpro/claude-ad: Active Directory pentest methodology for Claude Code: skills, agents and slash commands for internal AD red-t… by Ben Turner 🇬🇧.
- SonicWall GMS unuath remote root https://blog.amberwolf.com/blog/2026/august/sonicwall-gms-unauthenticated-rce-and-encrypted-password-hash-extraction/ by Rich Warren.
- RT International Cyber Digest: ‼🇩🇪 BREAKING: Threat actor Rhysida is auctioning 5.79TB it says it stole from German capital Berlin’s state ag… by Florian Roth.
- RT vx-underground: Two individuals behind TeamPCP were apprehended today in Australia. TeamPCP was the Threat Group responsible for a series of high-p… by Florian Roth.
- RT Eyal Sela: In a new report, we document Aurora ransomware activity from recent months, including the use of Cursor Agent to assist with the exploit… by Florian Roth.
- RT Max Aitel: Related: I’ll be coming to unprompted this year by Dave Aitel.
- RT H4x0r.DZ 🇰🇵: ServiceNow 4 Critical CVEs, including sandbox escape, RCE, sql injection https://support.servicenow.com/kb?id=kb_article_view&sy… by Dominic Chell.
- RT Nicolas Krassas: CVE-2026-63077: XStream Deserialization in JetBrains TeamCity’s Agent Polling Protocol Enables Pre-Auth RCE https://blog.securela… by Simone Margaritelli.
- I’ve made a major change to Shazzer. It will now collate historical fuzz result data. Previously to save costs it would remove older result data. I’ve… by Gareth Heyes \u2028.
- RT Johann Rehberger: Re Breaking Claude Code Opus 5 Auto Mode Full write-up with more details: https://embracethered.com/blog/posts/2026/breaking… by Gareth Heyes \u2028.
- i added a bunch of semantic feedback types under an IJON-like umbrella. the fuzzer can recognize novel temporal events/sequences and hill climb towa… by h0mbre.
- RT Chris Peikert: The other shoe has dropped: the authors have updated the paper with a plausible key-recovery attack and concrete cost estimates. (… by Halvar Flake.
- https://www.darkreading.com/cyberattacks-data-breaches/hundreds-openai-agents-invaded-hugging-face-servers When your llm escapes all your controls so … by Chris Nickerson.
- RT r1cksec: Run unsigned kernel payloads in a signed kernel driver via wasm3. No JIT/W^x (HVCI/etc., compliant) https://github.com/zer0condition/Goodm… by kmkz.
- RT Rich Warren: SonicWall GMS unuath remote root https://blog.amberwolf.com/blog/2026/august/sonicwall-gms-unauthenticated-rce-and-encrypted-password-… by kmkz.
- RT Attila Szasz: https://red.anthropic.com/2026/cvd/ledger/ with the ledger updated, now I know for a fact that Mythos has false negatives even compar… by kmkz.
- RT Smukx.E: Good talk about TraceLogging ETW… by Spiros Fraganastasis.
- RT Smukx.E: Building an Encrypted C2 Implant Using QUIC by @G3tSyst3m This is an good read if you want an introduction to QUIC protocol for implants. … by Spiros Fraganastasis.
- by MalwareHunterTeam.
- RT Hunterino: Another amazing Red Team Tool from Whispergate made by Lavender, an awesome redirector with support for all major C2 servers and tons of… by Max.
- RT Heather Mahalik Barnhart: Another blog! This time on phase 1 of the @SANSInstitute DFIR AI frameworks. https://smarterforensics.com/2026/08/ai-assi… by Max.
- RT anemone_fish: 5つのKEV(CISA/ENISA/CIRCL/KEVIntel/VulnCheck)を横断比較できるKEV Cross-Catalog Viewerを使いやすくしました。 https://cyberdivemaster.g… by Ring3API 🇺🇦.
- RT Moonlock Lab: 1/ Spent the morning on a batch of #macOS #infostealers and one of their components caught our eye: a keylogging thread literally nam… by Patrick Wardle.
- RT Jiska: Recordings from Objective for the We are out Take a look at our latest research on iMessage and the work of other renowned invited spea… by Patrick Wardle.
- GPOHound - Offensive GPO dumping and analysis tool that leverages and enriches BloodHound data https://github.com/cogiceo/GPOHound by Swissky.
- AI Agent Authentication in 2026: Web Bot Auth, ARD & OAuth https:// webdecoy.com/blog/ai-agent-aut hentication-web-bot-auth-ard-oauth/.
- Over 13 years since weev incremented an AT&T URL. How time flies. https://x.com/TheCooperYoung/status/2093503598235992181 by scriptjunkie (Matt).
- “Flock misread a license plate!” Ok, you do realize saying that will not bring the cameras down, right? You’re just giving them more ammo. They’re goi… by scriptjunkie (Matt).
- RT Smukx.E: New blog from our @zerotracelab. How chinese state group hid espionage traffic inside a paid commercial proxy subscription, why endpoint t… by thaddeus e. grugq.
- RT Co11ateral: PwnEye PwnEye can test cameras through ONVIF and RTSP. It can play the stream, deface a camera, move it and get a shell. Cameras should… by thaddeus e. grugq.
- RT 7h3h4ckv157: The Rise of AI Pentesting Agents: A Technical Analysis (2026) Written by Suphi Cankurt Source: https://appsecsanta.com/research/ai-pen… by thaddeus e. grugq.
- RT 0x0さん: If you do Windows internals / reversing, bookmark this. @j00ru’s syscall table tracks x86-64 Nt* syscall IDs across Windows XP all the way… by thaddeus e. grugq.
- RT Jeff Stein: How the Russians Got Inside My Phone. By Michael @Isikoff https://open.substack.com/pub/spytalk/p/how-the-russians-got-inside-my-phone?… by thaddeus e. grugq.
- RT Jeremy Morgan: Tailscale shipped netcat over their data plane with no control plane and no account. WireGuard plus DERP for rendezvous, gVisor nets… by thaddeus e. grugq.
- RT ESET Research: #ESETresearch discovered #GuardBreaker - a technique used by 🇷🇺 Russia-aligned UAC-0099 against a victim in 🇺🇦Ukraine, i… by thaddeus e. grugq.
- RT INFINITE NIGHTMARE: Nvidia user mode dlls are a bit funny, here is a 0day that can be used to cross-user boundaries (maybe get SYSTEM ?) https://gi… by Mr.Z.
- RT Cube: I’ve been wanting to publish a series of blog posts where I tackle a complex and tricky target - from harnessing and instrumentation to … by Axel Souchet.
- https:// github.com/JayRHa/EndpointAnal yticsRemediationScripts/.
- Exclusive: FulcrumSec extortion group claims Manchester Airports hack, theft of 86 GB of data - @Ax_Sharma https://www.bleepingcomputer.com/news/secur… by BleepingComputer.
- Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint https://www.mannulinux.org/2026/08/Privilege-escalation-from-IIS-A… by Nicolas Krassas.
- Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks https://www.techradar.com/pro/security/top-ai-too… by Nicolas Krassas.
- Chrome Web Store extensions caught stealing crypto, browser data https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-ste… by Nicolas Krassas.
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage https://www.bleepingcomputer.com/news/artificial-intelligence/anthropi… by Nicolas Krassas.
- Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch https://securityaffairs.com/198107/uncategorized/hackers-are-probing-papercut-server… by Nicolas Krassas.
- Testing Security on Al Shopping Assistants: from Chat Box to Remote Code Execution on a Top US Retailer’s Servers. https://pwnhackers.substack.com/p/h… by Nicolas Krassas.
- Security researchers find surveillance implants in Chinese-made routers sold worldwide - three different backdoor-like implants hidden in firmware ht… by Nicolas Krassas.
- Turns out Brits would quite like their private messages to stay private https://www.theregister.com/security/2026/08/30/turns-out-brits-would-quite-li… by Nicolas Krassas.
- RT CryptoCat: Long name make ZIP go brrrr https://cryptocat.me/blog/research/analysis/cve_2026_45308/ by Nicolas Krassas.
- TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html by Nicolas Krassas.
- RCE PoC for CVE-2026-82222 GiveWP (CVSS 10) https://github.com/dinosn/givewp-cve-2026-82222-rce-lab by Nicolas Krassas.
- Bypass llm guardrails by confusing it with fabricated tool output. https://github.com/DavidCarliez/trustmebro by Nicolas Krassas.
- No Privileges, No Lockout, No Trace: Kerberoasting with SPN Misconfigurations https://www.trellix.com/blogs/research/no-privileges-no-lockout-no-trace… by DirectoryRanger.
- Hunting Abuse: Detecting Privilege Escalation Through the ADCS Database #DFIR https://www.guidepointsecurity.com/blog/detecting-privilege-escalaction-… by DirectoryRanger.
- Abusing Azure VMs: When BitLocker Recovery Turns into an Attack Vector https://www.alteredsecurity.com/post/abusing-azure-vms-when-bitlocker-recovery-… by DirectoryRanger.
- RT Insinuator: Long time no post here, just busy elsewhere. Part 1 of our new 4-part series on token theft in Microsoft Entra ID is live on Insinuator… by DirectoryRanger.
- RT DirectoryRanger: ERNW White Paper 80: Token Theft in Microsodt Entra ID – An Analysis of Controls, by @Insinuator https://insinuator.net/2026/08/e… by DirectoryRanger.
- RT Enno Rey: DNS Cache Poisoning Like it’s 2006 https://www.usenix.org/system/files/usenixsecurity26-ben-simhon.pdf [PDF] by DirectoryRanger.
- Curlrevshell without anything interesting in argv, at the cost of two symlinks. by Stuart.
- RT Previdian: PaperCut MF/NG exploitation is in full swing. Our sensor caught the CVE-2026-81578 + CVE-2026-82078 exploit chain over the weekend. Othe… by Giuseppe
N3mes1s. - I can confirm this. Papercut is just the latest. Repro used after hours of the announcement with the logs info and the diff between versions. Some oth… by Giuseppe
N3mes1s. - YARA rules for bincrypter and gsocket https://gist.github.com/PeterGabaldon/e5b9a6c4ad4e3278481fb5cb02d67a8c by Peter Gabaldon.
- Here is a pattern file to analyze UPX packed binaries in imhex. https://gist.github.com/PeterGabaldon/2ff25fa1a13aeab0adae0d40c72ae84e by Peter Gabaldon.
- Some gsockets binaries can have the configuration embedded (beta branch in Github). I have just published to extraxct it. https://github.com/PeterGaba… by Peter Gabaldon.
- I have released a blog post about a detailed analysis of Bincrypter and gsocket embedded configuration mechanism. It is a case study from a real compr… by Peter Gabaldon.
- This is a good example of what informed @CroodSolutions and I’s talk at @cloudsa last week. If you think running EDR alone keeps you safe from ClickF… by Ezra Woods.
- Is Someone Hacking DoD Refrigerators? by Bruce Schneier.
- My research blog about # JSCeal is finally out! It was quite a journey. I hope you will like it! https:// research.checkpoint.com/2026/b reaking-the-seal-static-deobfuscation-of-jsceals-compiled-v8-by.
- RT V12: Signal’s Contact Discovery automatically sends your contact list information to an SGX enclave in the cloud. V12 broke into that enclave and l… by Lucas Leong.
- RT DHH: Omarchy 4.0.2 included a bunch of security patches that were responsibly reported by researchers. We recognize their collaboration and thank t… by Bad Sector Labs.
- Let’s start the week with another early release talk from DEF CON 34 - this time it’s ‘ESP32 as a counter-surveillance platform’. The humble, reasonably-priced microcontroller, along with an emerging.
- This is so strange to me. why invest in a fancy security chip (with a million dollar bounty), advanced boot loader security, forcing kernel mitigation… by chompie.
- RT watchTowr: Death by a thousand (paper)cuts (also known as WT-2026-0144) brings us back aboard the HellScape Express. The saga continues… and we’ll… by Piotr Bazydło.
- Couple years later, @Cymulate_Ltd got a closer look at this oddity and it turned fruitful https://cymulate.com/blog/kerberos-authentication-relay-… by Clément Notin.
- Put email, chat, meetings and half the company on a single platform, they said. Move it all to the cloud, they said. More resilient, they said. No sin… by Florian Roth.
- To make it a bit clearer why this Virtualizor thing matters, we added IOCs + YARA rules and some context around the incident. Even if you’ve never hea… by Florian Roth.
- RT Florian Hansemann: ‘‘The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS’’ #infosec #pentest #redteam #bluetea… by Florian Roth.
- RT INFINITE NIGHTMARE: GenDigital products are vulnerable to a 0day vulnerability, a PoC that demonstrates a SAM database dump and elevation of privil… by Daax.
- Reminder that you can scan your skills for free here: https://novahunting.ai/skill-scanner/ by Thomas Roccia.
- Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models https:// clearbluejar.github.io/posts/d oes-abliteration-skew-your-bug-hunting/.
- Fluorescent lamps (don’t) have ears: https:// lcamtuf.coredump.cx/blog/fluor escent/.
- RT Jiska: Apple: “We had to work on MTE stability and security for 5 years, now we ship it with the iPhone 17 enabled by default.” Google: “We shipped… by Halvar Flake.
- RT R.B.C.: Just wrapped up my latest blog post! In short: We explore same-origin attacks using bookmarklets and browser extensions to coerce an alread… by hasherezade.
- How security updates to Sequoia and Sonoma were changed silently https://eclecticlight.co/2026/08/31/how-security-updates-to-sequoia-and-sonoma-were-c… by Howard Oakley, Eclectic Light Co.
- Abusing Azure VMs: BitLocker Recovery Key as an Attack Vector https://www.alteredsecurity.com/post/abusing-azure-vms-when-bitlocker-recovery-turns-int… by Panos Gkatziroulis.
- RT KevTheHermit: Took a couple of hours and a couple or prompts / iterations but Claude successfully reverse engineered a functional exploit for the r… by Jeff McJunkin.
- RT : (Forgot about this, maybe it’s handy for someone) Prompt to generate BloodHound CE query from natural language: https://gist.github.com… by Chihuahua in charge NotMe.
- RT Hieu Vu: Another Windows kernel 0-day LPE, reported to MSRC. Looks like they’ve been pretty busy lately :D by kiddo.
- GeoNetwork - Pre-Auth RCE via Unauthenticated File Upload and Unsafe XSLT Processor (4 CVEs, 121 government deployments, all patched) https:// ethiack.com/info-hub/research/ geonetwork-preauth-RCE.
- RT MagicSword: Big Monday drop for LOLDrivers 26 newly tracked driver samples landed across five major contributions. The update includes signed … by Max.
- RT Sean Metcalf: There are numerous ways to extract cloud credentials (like tokens) once an attacker gains access to a workstation. Protect your cloud… by Max.
- RT r1cksec: Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data. https://github.com/NetSPI/AD-PathFin… by Max.
- From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG https://www. techanarchy.net/from-patch-to- exploit-using-claude-code-to-reverse-engineer-a-zero-day-in-papercut-ng.
- Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 https:// horizon3.ai/attack-research/di sclosures/cve-2026-9586-sangoma-switchvox-rce/.
- RT mRr3b00t: SMS Blasters…. whilst people talk about OMG never use a usb charger socket (insane for the general public to be told that) or NEVER con… by scriptjunkie (Matt).
- RT Giuseppe
N3mes1s: As promised the repro of the PaperCut CVE-2026-81578 + CVE-2026-82078: From False Marker to Verified RCE plus update with the v… by ϻг_ϻε. - RT Brendan Dolan-Gavitt: Apparently Astra can full chain by thaddeus e. grugq.
- RT @BushidoToken: Definitely check this BGP Hijack incident out… “a small number of Virtualizor installations received a malicious update p… by thaddeus e. grugq.
- RT Clément Dumas: - remove guardrails of a frontier model with high cyber capabilities - no system card - eval on ExploitGym (the one that made openA… by thaddeus e. grugq.
- RT BrendanEich: https://github.com/bilawalsidhu/gods-eye-view is pretty cool. Governments may get :mad: about it, don’t care. Remember Gilmore’s Maxim… by thaddeus e. grugq.
- RT Philippe Lemoine: It’s hilarious that the agents involved in the OpenAI/HF hacking incident came up with a scheme to cryptographically sign message… by thaddeus e. grugq.
- RT cr3ghost: If you’re new to exploit development, reverse engineering or vulnerability research, bookmark this before buying another course. Blacksto… by thaddeus e. grugq.
- RT Matt Burch: I released 9 CVEs and tooling against the ATM supply chain at both @BlackHatEvents and @defcon this summer. I am pleased to share this … by Garrett.
- What!! by Mike Felch (Stay Ready).
- RT Nicolas Krassas: CVE-2026-62735 - Windows HTTP.sys Elevation of Privilege. https://hackmd.io/@nhh/Hy6Oem7_Me by Mike Felch (Stay Ready).
- > be me > get DM > “smelly, want to see my malware?” > its a threat actor lmfao > “just please dont share” > ok lol lemme see ur goop > download their… by vx-underground.
- If you’ve got some spare time today, I really recommend skimming the comment section on this post. by vx-underground.
- RT : https://github.com/logangoins/Stifle “Stifle, .NET post-exploitation utility that uses a passed certificate to set explicit certificate mapp… by Vincent Yiu.
- RT U.S. Embassy Australia: A joint @FBI, @AusFedPolice and @WA_Police investigation has led to the arrest of two Western Australian men charged with a… by Vincent Yiu.
- RT Calif: New research: OEMpocalypse Now! Our own Lukas Maar spent a few weeks pursuing one question: How do you turn a normal Android app into root a… by Axel Souchet.
- RT Anthropic: We’re sharing an update on our alignment and security efforts. In July, we reported three incidents in which Claude models, running wit… by Bill Demirkapi.
- SonicWall warns of actively exploited SMA1000 zero-day flaws https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1… by BleepingComputer.
- Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attac… by BleepingComputer.
- Five Venezuelans plead guilty to ATM jackpotting attacks in US https://www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jac… by BleepingComputer.
- Recently patched PaperCut zero-days used in data theft attacks https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used… by BleepingComputer.
- Microsoft warns of TerminalFix attacks deploying reverse tunnels https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks… by BleepingComputer.
- Chinese Fire Ant hackers turn Cisco routers into spying platforms https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-r… by BleepingComputer.
- RT Kyle Avery: I just released the first public version of @BintracerLabs, a malware-analysis sandbox focused on macOS. Bintracer can: - Detonate Mach… by Cn33liz.
- Hidden Attack Slips Past Claude Code Auto Mode https://www.bankinfosecurity.com/hidden-attack-slips-past-claude-code-auto-mode-a-32693 by Nicolas Krassas.
- Lumma Stealer – dllhost.exe Hollowing, C2 Domains & Payload Extraction https://github.com/kaandemir993/Lumma-Stealer-dllhost-Hollowing-C2-Domains-Pay… by Nicolas Krassas.
- Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks https://www.theregister.com/security/2026/09/01/attacker-stol… by Nicolas Krassas.
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-t… by Nicolas Krassas.
- Another Artifactory CVE under attack by AI agents or humans https://www.theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai… by Nicolas Krassas.
- FBI Probes Service Selling 153M+ Drivers Licenses https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/ by Nicolas Krassas.
- Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes https://www.theregister.com/cyber-crime/2026/09/02/cops-… by Nicolas Krassas.
- Cronos network resumes activity after $74 million lending exploit https://www.scworld.com/brief/cronos-network-resumes-activity-after-74-million-lendi… by Nicolas Krassas.
- CVE-2026-82329 JFrog Artifactory unauthenticated auth-bypass: reproducible Docker lab + URL-parameter validator PoC + patch-diff analysis https://gith… by Nicolas Krassas.
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems https://thehackernews.com/2026/09/breeze-comet-executes-hundre… by Nicolas Krassas.
- Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague https://securityaffairs.com/198243/hacking/chaotic-eclipse-releases-gendigita… by Nicolas Krassas.
- Critical Langflow flaw exploited to steal OpenAI and AWS keys https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal… by Nicolas Krassas.
- Google removes uBlock Origin from Chrome Web Store in final Manifest V2 purge https://cyberinsider.com/google-removes-ublock-origin-from-chrome-web-st… by Nicolas Krassas.
- From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG https://www.techanarchy.net/from-patch-to-exploit-using-claude-co… by Nicolas Krassas.
- Hackers push malicious Virtualizor update in BGP hijacking attack https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-up… by Nicolas Krassas.
- RT GrapheneOS: We have a partial port of GrapheneOS to the Pixel 11 series after a week of work on it. We’re unable to complete the port due to lack o… by Maxwell ꓘ Dulin (Strikeout).
- RT TrustedSec: Turns out #AWSWAF logs are keeping receipts, including your session tokens. Enter waf-fu! @confused_binary walks through default loggin… by Dave Kennedy.
- RT Jacob Baines: Re Then we found something unexpected. SPEAKINGSTONE contains an obfuscated backup C2 domain: findmyipaddr[.]com Nobody owned it. So … by Nick Carr.
- US Postal Service whistleblower says USPS is implementing “secretive, rushed” system to control mail voting despite court order blocking Trump move…. by Kim Zetter.
- we’ve significantly expanded ics / ot coverage at infrawatch. 500+ technologies across water, rail, solar, manufacturing, agriculture and other indus… by Lloyd Davies.
- RT nafiez: Published my technical write-up on a vulnerability I discovered in Windows usbprint.sys. The issue was reported to MSRC, but Microsoft deci… by The Haag™.
- This is kinda cool approach! by Giuseppe
N3mes1s. - Autonomous Defense by Giuseppe
N3mes1s. - RT Previdian: Our August Known Exploited Vulnerabilities Report is out! Our sensors captured 160,586 exploitation events, up 204.9% from July. We adde… by Giuseppe
N3mes1s. - CVE-2026-82329: JFrog Artifactory critical unauthenticated authentication bypass leading to administrative takeover #pruva reproduction. With 3 varian… by Giuseppe
N3mes1s. - RT Stephen Fewer: We have published our @metasploit exploit for the recent PaperCut MF and NG zero-day (CVE-2026-81578 + CVE-2026-82078) that is being… by Giuseppe
N3mes1s.
Tools and Exploits
DEF CON 34 talk on defeating facial recognition systems through strategic styling. Full recording now available.
Intune’s Remote Help now allows helpdesk staff to remotely access physical Windows devices by signing in with their own credentials, without user presence or consent. Red team relevant.
Python-based consumer for Windows Threat Intelligence ETW events. Filter telemetry by target process for both implant development and malware reverse engineering.
Network pentesting tool built on top of TrustedSec’s Titanis framework. Similar to CrackMapExec/NetExec with a growing feature set.
YSoNet grows from 50 to 62 .NET deserialization gadgets with new Framework 2.0 to 3.5 support, dedicated 4.0 coverage, and 508 archived researcher references.
CICADA8 Research ports offensive tools into Chrome via Isolated Web Apps. Run pentest tools entirely from the browser with no local installation.
Claude Code with the Ludus skill spins up a lab with two Exchange 2019 servers for testing CVE-2026-62911. Demonstrates AI-assisted vulnerability reproduction workflows.
The latest Windows 0-day from the anonymous MSNightmare researcher. The tenth in a series timed for the day after Patch Tuesday to maximize the unpatched window.
SpecterOps research recovers cleartext discovery credentials from ServiceNow without coercion or relay. Works on SSH keys, AWS keys, Entra secrets, and LDAP credentials.
New threat intelligence feeds added to the curated open-source collection for security teams and threat hunters.
More this week (17)
- RT Tobias Scharnowski: Our @BlackHatEvents USA slides and demo video are now available! We plugged into a Tesla Universal Wall Connector and showed ho… by Alex Plaskett.
- RT NSA Cyber: NSA today released two technical reports addressing threats to application specific integrated circuits (ASICs) during the design and ma… by scriptjunkie (Matt).
- RT ElfMaster: Pleased to announce the release of my paper in tmp.0ut issue 5: Fine grained load-time ASLR for ELF executables in X86_64 Linux (https:/… by tmp.0ut.
- RT @PiotrBania: yo ppl, check out https://phrack.org and the new phracktro :D and stay tuned for the new phrack release(s) cheers! ht… by tmp.0ut.
- More .. the hose of solid research is at a point of release faster than consumption for me. by Mike Felch (Stay Ready).
- Apple has just released an update to XProtect for macOS Sequoia and later https://eclecticlight.co/2026/08/26/apple-has-just-released-an-update-to-xpr… by Howard Oakley, Eclectic Light Co.
- RT Thomas Seigneuret: New release of DPLoot Now DPLoot can recover secrets over multiple protocols : SMB, WMI, WinRM, MSSQL, Local and Cobalt Str… by Swissky.
- New blog & tool release by @jotter_jotter PRTremote: Extract PRT Cookies Remotely with InteractiveToken Scheduled Tasks https://github.com/arm… by Andrew Oliveau.
- RT Scan Malware: Scan Malware is now a source for the excellent tool subfinder by @pdiscoveryio. Subfinder is an open-source passive subdomain enumera… by ProjectDiscovery.
- RT Anil Madhavapeddy: I’ve had to respond to multiple open-source security issues recently (some public, some not), and the wild thing is that coding … by Giuseppe
N3mes1s. - I have released a tool to extract the original ELF from a obfuscated shell script created with Bincrypter. https://github.com/PeterGabaldon/Bincrypter… by Peter Gabaldon.
- Authentication bypass in EOL Proxmox VE 7 release https:// forum.proxmox.com/threads/prox mox-virtual-environment-security-advisories.149331/page-4#post-867929.
- RT Gavin K: fun weekend experiment, trying to control Windows Event Logs and their channels through a BOF…it went pretty well: released event_log_… by Max.
- RT Tailscale: Tailscale without Tailscale, by Tailscale. Meet tailcat. tailcat is an open-source Go package and CLI that lets you use Tailscale’s dat… by scriptjunkie (Matt).
- RT Andrew Curran: GPT-Astra has been cleared for release, and OpenAI plans to release it soon. My guess would be Thursday. The version of Astra with u… by Dave Kennedy.
- RT Sean Metcalf: IMPORTANT: Upgrade Microsoft Entra Connect Sync before September 30th! You must be on at least version 2.5.79.0 released in May 2025…. by Dave Kennedy.
- RT Abliteration.ai: Today we’re releasing abliterated-model-large-v2. Based on GLM-5.3, which is #3 on Terminal-Bench 4.0 (behind only Opus 5 and Fabl… by Dave Kennedy.
