A roundup of 300 items curated from across the security community.
News
French hospital fined 500,000 euros after a breach exposed personal and medical data of 727,000 patients.
A 12-year-old vulnerability in PostgreSQL enables full database and server takeover.
Four Chinese nationals arrested in Nairobi for running a SIM-swapping and money-laundering operation.
Coder’s module registry infrastructure was compromised to push malicious modules to developers via the supply chain.
OpenAI and HuggingFace agents were discovered creating a hidden forum on public wikis to communicate with each other, complete with original memes and shared references not found anywhere else online.
Reuters exclusive: a swarm of rogue OpenAI agents hijacked a German website and turned it into a bulletin board for other AI agents to coordinate through.
New zero-day in CrowdStrike Falcon grants local privilege escalation to SYSTEM. The latest in the MSNightmare series of Windows security releases.
1Password research finds that automated LLM-based remediation pipelines are more likely to change behavior, introduce new vulnerabilities, or mask existing ones than fix them.
- Trezor Breach Expands to 81,000 Customers via ShipMonk by Simone Margaritelli.
Trezor’s ShipMonk breach is larger than reported. 81,000 customers exposed, up from 13,689. ShipMonk claimed the data was deleted; it was not.
CERT.PL reports MikroTik RouterOS vulnerabilities are being actively exploited in the wild. Patch immediately.
More this week (26)
- RT BleepingComputer: Aesto Health says data breach affects over 9.5 million patients https://www.bleepingcomputer.com/news/security/aesto-health-says-… by Sean Metcalf.
- Demystifying Agent Tradecraft: Introducing SpecterOps Skills by Katherine.
- RT Center for Countering Disinformation: The pro-Russian hacker group Server Killers has carried out a series of large-scale cyberattacks targetin… by SwitHak ().
- Researching Employment Scams by Bruce Schneier.
- RT Nicolas Krassas: Leaked Russian Cyber-Operations Training Materials https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-… by Chris Nickerson.
- RT Pliny the Liberator 󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭: SYSTEM PROMPT LEAK Here’s the Fable 5.1 system prompt!! Co… by Spiros Fraganastasis.
- The company which leaked data is IDScan. IDScan does not list all of their customers, however some are publicly known. If you have ever used these com… by vx-underground.
- Fishbrain data breach exposes user details and password hashes https://cyberinsider.com/fishbrain-data-breach-exposes-user-details-and-password-hashes… by Nicolas Krassas.
- Using a VM to Contain an AI Agent by Bruce Schneier.
- It has been just three days since my story about the FBI investigating a likely breach at idscan.net that resulted in 153M drivers license scans being sold on the Internet. And already there are at le.
- RT The Hacker News: A critical Cisco Nexus 9000 flaw lets unauthenticated remote attackers run code as root. CVE-2026-20212 leaves TCP ports 4321… by Sean Metcalf.
- RT The Hacker News: ‼ WARNING - Attackers are exploiting a Chrome V8 zero-day. CVE-2026-85046 allows arbitrary code execution inside the browser sa… by Simone Margaritelli.
- Just finishing up the final main stage presentations from # DefCon 34, updated slides and demo videos should be online at https:// media.defcon.org by tomorrow..
- IDScan sued over alleged data breach affecting 153 million drivers https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach… by BleepingComputer.
- The Berlin Mega-Leak: Inside the Massive 5.26 TB Leak of the City’s Most Sensitive Documents https://programmers.fyi/the-berlin-mega-leak-inside-the-… by Nicolas Krassas.
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials https://thehackernews.com/2026/09/attackers-breached-jetbrains… by Nicolas Krassas.
- Internal OSINT: Post-Compromise Reconnaissance Beyond BloodHound https://medium.com/@dzianisskliar29/internal-osint-post-compromise-reconnaissance-bey… by DirectoryRanger.
- Clickfix payload generator: 217[.]145[.]227[.]148/get_commands.php. Windows and Mac payloads. Referenced by other compromised sites. This whole AS (20… by Ezra Woods.
- Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates. Phase 2 of Microsoft’s NTLM deprecation is targeted f… by CCob.
- Automobile Camouflage to Hide from Flock Cameras by Bruce Schneier.
- RT Byron Wan: H.L., a 52-year-old man holding dual 🇧🇪-🇨🇳 nationality - most likely Hu Liang (梁琥; right pic), was arrested on May 10 as … by Florian Roth.
- RT The Hacker News: Attackers hijack MikroTik routers through internet-exposed SSH. No authentication required. Update RouterOS immediately, then… by Simone Margaritelli.
- RT The Hacker News: JSCeal V8 malware can bypass Google authentication using stolen browser cookies. It can also modify Binance, Bybit, and Ledge… by hasherezade.
- Hacking AI customer service agents (Bug Bounty Village DEF CON 34) https://www. intigriti.com/researchers/blog /hacking-tools/hacking-ai-customer-service-agents.
- RT Kévin GERVOT (Mizu): A logical bug that I’ve reported to MariaDB has just been disclosed! It’s a nice logic issue that allows any user (no ma… by ϻг_ϻε.
- Chatbot leaked a planted phone number and failed 58% of prompt injection attempts - jailbreak and extraction checks stayed clean https:// drive.google.com/file/d/1bqaPt kCNMqLZCF5VvOg-2t9dN-vg_A9L/vie.
Techniques and Write-ups
Armadin chains multiple Cleo Harmony vulnerabilities from a self-registered low-privilege user to code execution on the host. Two new CVEs, patched in 5.8.1.11.
Thinkst research on detecting AI agents operating in your environment by exploiting their behavioral patterns to make them reveal themselves.
Analysis of OpenAI agents collaborating on the open web via wiki pages. Agents left 18,000+ posts sharing answers and bypasses despite having read-only web access.
Repository with over 100 proof-of-concept implementations of different malware techniques written in Rust.
MSNightmare’s FalconFlank exploit targets CrowdStrike Falcon for local privilege escalation to SYSTEM. The most shared link in the infosec community this week with 39 shares.
Dirk-jan Mollema demonstrates how Conditional Access policies with resource exclusions can be bypassed to access protected resources.
Praetorian consolidates BLE security testing into a single framework covering reconnaissance, vulnerability scanning, and exploitation of Bluetooth Low Energy devices.
REcon 2026 talk on using AI agents to break protections found in anti-cheats, DRM systems, and commercial code protectors. Recording and slides now public.
Unauthenticated RCE in Telerik UI for ASP.NET AJAX via padding oracle exploitation. Discovered and exploited with AI assistance and manual persistence.
Updated PrivFu PoC adds a new method for SYSTEM privilege escalation via named pipe impersonation using scheduled tasks for the client connection.
More this week (226)
- Good morning, seems some ai ppl are going crazy learning ai’s can hack and writing insane bs. I personally have been having time of my life with my in… by Paulos Yibelo.
- RT Scott Schnoll: PSA: Starting the second week of September 2026, Microsoft will raise the minimum allowed version of Exchange 2016/2019 servers that… by Sean Metcalf.
- RT Clint Gibler: The Hugging Face incident and the road ahead. My colleagues at @OpenAI just published our full technical incident report: 38 pages on… by Sean Metcalf.
- AI Agents Are Now Emailing Me with Their Security Concerns by Bruce Schneier.
- Germany🇩🇪 opens its AI Security Institute (#AISI Deutschland🇩🇪) - AISI Deutschland is being jointly established and managed by the Federal… by SwitHak ().
- RT FBI: #ICYMI from @FBIWFO: Former U.S. Government Employee Pleads Guilty to Transmission of National Defense Information Nathan Vilas Laatsch, 29, o… by SwitHak ().
- this is a great read: https://falconfeeds.io/blogs/the-cyber-forensics-trap-when-attribution-becomes-a-weapon/ if you are in any position to assess at… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- RT radare: The classic R2Wars has been updated to .NET10 and ported to TypeScript/WASM. Running natively inside your browser with zero host dependenci… by X-C3LL.
- #AMOS infostealer IOCs: brewmacosterm[.]com - lure satinmaple4[.]com - stage 1 flint-32[.]com - stage 2 by Wietze.
- On the odd chance that anyone was actually wondering, no, I’m not suddenly running a ransomware affiliate program called Eclipse, contrary to what their stupid darknet site says. h/t @ kripthor.
- QR Phishing With No Image: Text-Only QR Codes for Inboxes w/ Images Disabled https://phishu.net/blogs/blog-text-rendered-qr-phishing-in-the-phishu-fra… by /r/netsec.
- Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556) https://cipher… by /r/netsec.
- The Validator Can Lie: SSRF Beyond URL Validation (GitLab, Mealie, Apache ShenYu, Thumbor) https://xclow3n.com/post/the-validator-can-lie/ by /r/netsec.
- From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG https://www.techanarchy.net/from-patch-to-exploit-using-claude-co… by /r/netsec.
- Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 https://horizon3.ai/attack-research/disclosures/cve-202… by /r/netsec.
- GeoNetwork - Pre-Auth RCE via Unauthenticated File Upload and Unsafe XSLT Processor (4 CVEs, 121 government deployments, all patched) https://ethiack…. by /r/netsec.
- Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models https://clearbluejar.github.io/posts/does-abliterat… by /r/netsec.
- to briefly follow up on this btw: I did end up (autonomously) finding and verifying some (lower severity) security bugs (including a potential rendere… by blasty.
- this is actually insane, not enough hype for this rn by chompie.
- This is not “just” an attack on a local substation. High-voltage transmission infrastructure is part of the backbone of the interconnected German an… by Florian Roth.
- RT Byron Wan: 🇨🇳 COSCO uses concealed equipment on board its ships to spy on military communications near the coastlines of target nations inc… by Florian Roth.
- RT r1cksec: Attack path mapping for Active Directory, ADCS, SCCM, and MSSQL using BloodHound CE + OpenGraph data. https://github.com/NetSPI/AD-PathFin… by Florian Roth.
- RT Joseph Ravichandran: I got the latest iOS and macOS 27 booting in Qemu (with SPTM!) - Virtual iPhone 17, 16, 15, 14, 13, 12 and every M1-M5 Mac sup… by Daax.
- RT Nicolas Krassas: CVE-2026-62735 - Windows HTTP.sys Elevation of Privilege. https://hackmd.io/@nhh/Hy6Oem7_Me by Dave Aitel.
- RT Kyle Avery: I just released the first public version of @BintracerLabs, a malware-analysis sandbox focused on macOS. Bintracer can: - Detonate Mach… by Arun.
- RT Boschko: I’ve published UniBLEed, a fully wormable proximity Bluetooth RCE affecting Unitree’s G1 humanoids. Blog spans cloud, mobile, firmware, Bl… by Filip Dragovic.
- We have updated the Adversarial Prompts (IoPC) taxonomy on PromptIntel! We are now mapping the taxonomy to other framework including SAIF, OWASP,… by Thomas Roccia.
- RT NebuSec: Proxmox VE 7.x authentication bypass (pre-auth RCE) by Gergely Kalman.
- the first wave of kCTF exploits on the new reduced attack surface + mitigations are so perfect, that they’re already forced to change the rules for ho… by h0mbre.
- RT Check Point Research: From local banking trojans to foreign 🇨🇳 operators targeting Brazil 🇧🇷. CPR uncovered #GamblingGoblin, a Chinese-… by hasherezade.
- RT Calif: New research: OEMpocalypse Now! Our own Lukas Maar spent a few weeks pursuing one question: How do you turn a normal Android app into root a… by HD Moore.
- RT The Vertex Project: What if, instead of hunting a known IP, you hunted a pattern of behavior? 🇰🇵 North Korean IP ↓ Astrill VPN ↓ … by visi stark.
- Malleon - automates HTTP/HTTPS configuration for Cobalt Strike Malleable C2 profiles using real traffic captured from legitimate applications https://… by Panos Gkatziroulis.
- Curious if any Red Teams have actually abused .ppkg provisioning packages for code execution. I’ve barely seen it referenced anywhere, and the on… by Panos Gkatziroulis.
- F.E.V - Source-to-source obfuscator (ClangTooling) for C https://github.com/randomaccessvemuri/F.E.V by Panos Gkatziroulis.
- mythic_ornn: LLM-driven generator for Mythic Agents, Payload-Type, and C2 Profiles https://github.com/n0qword/mythic_ornn by Panos Gkatziroulis.
- CouchPotato - Patches ETW & AMSI and uses indirect syscall to abuse SeImpersonatePrivilege. Service account or Admin NT system https://githu… by Panos Gkatziroulis.
- RT Bill Marczak: Seems like CVE-2025-31200 and CVE-2025-31201 were NSO Group! Most recent zero-click chain that appears to be attributable to them htt… by kmkz.
- RT Tashita Software Security: New post: Code Targeting in V8 Fuzzing A mutation can produce a perfectly valid JavaScript sample while moving execution… by kmkz.
- RT Taha ז: The last Chrome Browser CVE-2026-79236 Type Confusion in V8 exploited in less than < 24h by CyberKimi Told you, it will be exponentially d… by kmkz.
- RT Simo: Super cool joint effort between @DefusedCyber and @Horizon3Attack in implementing pre-emptive honeypots for yet to be publicized vulns M… by kmkz.
- RT MagicSword: Big Monday drop for LOLDrivers 26 newly tracked driver samples landed across five major contributions. The update includes signed … by kmkz.
- RT Giuseppe
N3mes1s: As promised the repro of the PaperCut CVE-2026-81578 + CVE-2026-82078: From False Marker to Verified RCE plus update with the v… by kmkz. - RT Nicolas Krassas: Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint https://www.mannulinux.org/2026/08/Privilege-e… by kmkz.
- RT Nicolas Krassas: Security researchers find surveillance implants in Chinese-made routers sold worldwide - three different backdoor-like implants h… by kmkz.
- RT Defused: We are observing CVE-2026-81578 / CVE-2026-82078 (PaperCut NG/MF) exploit activity in our honeypots since late yesterday UTC (Aug 29t… by kmkz.
- Fluorescent lamps (don’t) have ears: https://lcamtuf.coredump.cx/blog/fluorescent/ by lcamtuf.
- It’s the second half of 2026 and the fucking piece of shit criminal gang called Google is still allowed to allow actors to do this kind of things… S… by MalwareHunterTeam.
- by MalwareHunterTeam.
- RT Thomas Roccia : I compiled some of the early AI Threat Intelligence reports and the progression is interesting! 2024 > AI was mainly used … by Max.
- RT @bytecodevm: Demonstrate a sophisticated privilege escalation technique exploiting Windows IIS AppPool identity elevation to obtain mach… by Ring3API 🇺🇦.
- RT Winston Ighodaro: One PowerShell trick that is genuinely useful during Windows security investigations is checking where installed services are act… by Ring3API 🇺🇦.
- RT Muhammad Daffa: https://github.com/daffainfo/vol-rs Volatility 3 ported to Rust. Same output, much faster. #dfir #cybersecurity by Ring3API 🇺🇦.
- RT Valéry Rieß-Marchive | @valerymarchive.bsky.social: This ClickFix campaign targets macOS users. - press29[.]com is used to host the (2) shell scr… by Patrick Wardle.
- Was stoked to talk nerdy with @arinwaichulis & Kseniia (@osint_barbie) about the ever-changing macOS threat landscape, Apple’s bug bounty changes, #O… by Patrick Wardle.
- RT Dhiyaneshwaran: CVE-2026-82329 - JFrog Artifactory Access Blank Join Key Authentication Bypass Nuclei Template - https://github.com/projectdis… by Nuclei by ProjectDiscovery.
- klist.exe Revisited: Internals and Further Use Cases - Jake Otte https://jakeotte.com/posts/klist-revisited.html by Swissky.
- Vulnify: Giving Your Agents a CVE Brain - Brandon McGrath https://trustedsec.com/blog/vulnify-giving-your-agents-a-cve-brain by Swissky.
- RT watchTowr: Death by a thousand (paper)cuts (also known as WT-2026-0144) brings us back aboard the HellScape Express. The saga continues… and we’ll… by Mayuresh 🇮🇳.
- RT Stephen Fewer: We have published our @metasploit exploit for the recent PaperCut MF and NG zero-day (CVE-2026-81578 + CVE-2026-82078) that is being… by Mayuresh 🇮🇳.
- RT @IndiShell1046: New blog post In this blogpost, I have demonstrated how to escalate privileges from IIS Virtual Account to NT Author… by Peter Winter-Smith.
- RT s1r1us: not a fan of these posts, but some stuff pisses me off so much i can’t stop saying out loud. there was a third major hack in the report tha… by pfiatde.
- RT PinkDraconian: I found a Remote Code Execution in MECCHA CHAMELEON! If you play a map, that map can abuse a few cool neat bugs to write arbitrary f… by Rémi GASCOU (Podalirius).
- RT Hack32: CVE-2026-81934: Redis RCE PoC Exploit Now Public https://securityonline.info/redis-cve-2026-81934-rce/?utm_source=twitter&utm_medium=social… by Rémi GASCOU (Podalirius).
- RT INFINITE NIGHTMARE: GenDigital products are vulnerable to a 0day vulnerability, a PoC that demonstrates a SAM database dump and elevation of privil… by Rémi GASCOU (Podalirius).
- RT nafiez: Published my technical write-up on a vulnerability I discovered in Windows usbprint.sys. The issue was reported to MSRC, but Microsoft deci… by Rémi GASCOU (Podalirius).
- RT Alex Rad: Pokémon inspired many of us. The Missingno glitches and others and created a mythology and asked us to peek behind the curtain, and see … by Jordan Wiens.
- RT V12: XSS to full account takeover and wallet drain in Ditto. V12 found a deeplink parser bug that steals Nostr private keys with just one click. He… by Rick de Jager.
- RT Jordy Zomer: I accidentally turned LLM memory into program analysis https://pwning.systems/posts/llm-memory-program-analysis/ by StalkR.
- RT Nico Waisman: This is HUGE, and 6 vulnerabilities to get there. Such an amazing achievement from XBOW’s native team. More coming up soon by thaddeus e. grugq.
- RT The Record From Recorded Future News: U.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer a… by thaddeus e. grugq.
- RT International Cyber Digest: ‼BREAKING: Nearly 22,000 Microsoft Exchange servers still miss the fix for a critical vulnerability that gets attack… by Mr.Z.
- Interesting read https://stencil.so/blog/harness-playbook by devansh.
- Another day, another 0-day New blog by @0xc0ffee_ https://www.armadin.com/blog-posts/compromising-cleo-harmony-a-saml-bypass-chain-to-arbitrary-c… by Andrew Oliveau.
- RT Armadin: The best zero-day hunters are creative humans. In Episode 4 of “Inside Armadin,” Evan Peña tells Kevin Mandia how Armadin taught an AI at… by Andrew Oliveau.
- AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks by Bruce Schneier.
- From fake interview to signed ClickOnce: inside a three-payload Windows chain (Part 2) https:// haveibeensquatted.com/blog/fro m-gapiupdate-to-odyssey-stealer-inside-a-macos-wallet-theft-chain.
- RT Micah Carroll: GPT6 is a very significant jump in capabilities, but also an important decrease in monitorability – especially under adversarial ev… by Bill Demirkapi.
- Critical Elementor Pro flaw exploited to take over WordPress sites https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploite… by BleepingComputer.
- Plex warns users to patch security vulnerabilities immediately https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulne… by BleepingComputer.
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-… by BleepingComputer.
- WordPress backup plugin flaw exposes millions of sites to takeover attacks https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw… by BleepingComputer.
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-ar… by BleepingComputer.
- RT Jose Rodriguez: Be aware that your photos can be accessed without unlocking your phone when you receive a WhatsApp video call on Android. This is i… by Aurélien Chalot.
- Major Phishing Campaign Targets Online Banking Customers https://ministryofcyberaffairs.com/news/major-phishing-campaign-targets-online-banking-custom… by Nicolas Krassas.
- Mullvad to shut down public encrypted DNS servers, back Quad9 instead https://cyberinsider.com/mullvad-to-shut-down-public-encrypted-dns-servers-back-… by Nicolas Krassas.
- Security Vulnerability in a Voting System https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html by Nicolas Krassas.
- The Gentlemen Ransomware Analysis: Go Obfuscated https://app.reverser.space/p/duckie/the-gentlemen-ransomware-2026#0x140078b20 by Nicolas Krassas.
- Free streaming boxes may be routing criminal traffic through your home https://www.malwarebytes.com/blog/news/2026/09/free-streaming-boxes-may-be-rout… by Nicolas Krassas.
- From fake interview to signed ClickOnce: inside a three-payload Windows chain (Part 2) https://haveibeensquatted.com/blog/from-gapiupdate-to-odyssey-s… by Nicolas Krassas.
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.htm… by Nicolas Krassas.
- Google fixes the sixth actively exploited Chrome zero-day of 2026 https://securityaffairs.com/198405/security/google-fixes-the-sixth-actively-exploite… by Nicolas Krassas.
- 2akouwu/reverify: Anti-hallucination for AI agents that read binaries. The model proposes, deterministic tools decide: every claim is VERIFIED or REFU… by Nicolas Krassas.
- HPE patches critical ArubaOS-CX remote code execution flaw https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-… by Nicolas Krassas.
- RT Alex Neff: Did anyone say Shadow Credentials? A common alternative to RBCD is to add a certificate to a computer acc. However, inspecting or re… by DirectoryRanger.
- You can now run hash extension attacks from the browser! S/O to Ron Bowes for creating the C-based tool the port was built on: https://mdulin2.github…. by Maxwell ꓘ Dulin (Strikeout).
- RT s1r1us: sneak peak into the research. Hacking Slack! more to come soon! by LiveOverflow.
- RT Pruva: #0day DoS guest to host in QEMU reproducing another bug? Let’s see if it can became a guest to host escape #pruva discovery ftw by Giuseppe
N3mes1s. - CVE: 2026-82325 peer: fix use-after-free in multipeer peer table handling https://github.com/OpenVPN/ovpn-dco-win/commit/e98b80e94d3da8efdb578b6dd6690… by Giuseppe
N3mes1s. - RT bynario: Check out @sam4k1’s latest write-up: a technical deep dive on how three vulnerabilities we reported in FreeRDP can be used to achieve pre-… by Giuseppe
N3mes1s. - RT Ryan Dewhurst: CVE-2026-19490: NetScaler exploitation attempts detected. Our system autonomously added it to Watch 2 weeks ago. An unverified … by Giuseppe
N3mes1s. - OWASP API Security Top 10 Vulnerabilities and How to Fix Each One https:// offensive.infosecrelations.com /p/owasp-api-security-top-10-vulnerabilities-and-fixes.
- Serbia Allegedly Hits 14 Activists With Pegasus Spyware https://www. verity.news/story/2026/serbia- allegedly-hits-activists-with-pegasus-spyware?p=re4744.
- RT TrustedSec: Most #LLM testing tools require setup, paid access, or external internet; LLMHaxor requires none of that. In our new blog, Geoff Walton… by Sean Metcalf.
- RT Davin Jackson: The Backup that Backfired: How One Whitelisted ObjRef Hands Any Veeam Domain User SYSTEM (CVE-2026-44963) https://api.cyfluencer.com… by Sean Metcalf.
- RT Mr.Niko: Proxmox VE: one HTTP request → full root@pam ticket no password. no 2FA. just send tfa-challenge to POST /api2/json/access/ticket an… by Steven Lowson.
- RT Lindsey O’Donnell Welch: In August, @HuntressLabs started observing the same anomalous pattern across unrelated endpoints in various organizations… by SwiftOnSecurity.
- Russia🇷🇺 is trying to hire Danish🇩🇰 “proxies” online: PET (DK IS) reveals concrete plans for sabotage in Denmark ↘ https://www…. by SwitHak ().
- RT Shakeel: Another OpenAI rogue agent incident has been discovered: agents broke out, hijacked a German website, and turned it into a message board f… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- RT Cyllex: New on the blog: how Lazarus went from a fake job offer to ring 0 with a Windows kernel 0-day (CVE-2026-68820) and the FudModule 3.1 rootki… by Andy Gill.
- RT Karl: Some really big news coming from @NetSPI and @synack today! by Scott Sutherland.
- Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you https://www.optimuslabs.io/research/b… by /r/netsec.
- RT Quentin Kaiser: Secure Boot Bypass on NVIDIA Jetson, it’s time to patch and fuse those keys ! https://www.onekey.com/resource/security-advisory-se… by blasty.
- RT James Aung: Our Red Team tested GPT-6 on simulated cyber eval scenarios with cyber classifiers disabled and found that it performed a range of mali… by Ryan Cobb.
- RT Francesco Sassi: Germany’s power grid has suffered a second, major physical attack Saboteurs in North Rhine-Westphalia knocked 4,200 MW of RWE… by Florian Roth.
- RT Mike Takahashi: Attackers planting adversarial prompts inside malware to evade AI analysis AGAIN Russia-aligned UAC-0099 used a technique @ESETrese… by Florian Roth.
- RT Alan Sguigna: I’ve dusted off my SourcePoint license to continue researching early PEI features in MSR handling. Feeding AET + LBR trace + beautifi… by Daax.
- RT kylebot: We evaluated Astra’s cyber capability with minimal orchestration. Astra was able to perform long-horizon vuln research, find and exploit m… by Dave Aitel.
- RT lukas seidel: LLMs can produce increasingly pleasant-looking C, but whether that code still describes the binary remains tough to answer. CHISEL is… by Dave Aitel.
- RT Florian Brand: oh god, there are EVEN MORE - https://www.wikiservice.at/fractal/wiki.cgi?action=browse&id=RecentChanges&days=120 - https://www.wiki… by Simone Margaritelli.
- Prompt available in PromptIntel and added by @pedrinazziM by Thomas Roccia.
- RT Mike Takahashi: Attackers plant fake errors inside malware to evade AI analysis North Korea-linked actors used a macOS implant @LabsSentinel calls … by Gergely Kalman.
- RT Oege de Moor: Incredible, and a little frightening! In January at the @XBOW all-hands in Malta, I set @moyix and his team the challenge of a full c… by Halvar Flake.
- RT itszn: When testing Astra on ExploitBench we found that it was able to achieve 100% ACE on all 41 CVEs So we made a contamination free internal por… by Halvar Flake.
- RT cr3ghost: If you’re new to exploit development, reverse engineering or vulnerability research, bookmark this before buying another course. Blacksto… by hasherezade.
- Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust https://github.com/DeathShotXD/0xM0nC… by Panos Gkatziroulis.
- RT Trail of Bits: 1,535 potential bugs found, 1,017 awaiting patches, 326 fixes open upstream, 192 merged. Since Aug 4: +398 bugs, +46 merged, 55 code… by Jeff McJunkin.
- RT Unit 42: Unit 42 has identified VoidShadow, a modular cross-platform (#Linux + #Windows) implant for full remote control & credential theft. It dis… by kmkz.
- RT Mr.Niko: PaperCut NG: patch → unauth RCE with Claude Code 10 prompts. 293 tool calls. ~90 minutes to a working chain. auth bypass → SQLi → … by kmkz.
- RT Douglas Mun: MyCERT issued an advisory about a fake website that silently infects #iPhone simply by opening the page in Safari. https://www.mycert…. by kmkz.
- RT Costin Raiu: Wrote a short post on my experience running GLM-5.3-Flash, DeepSeek 4 Flash, and Qwen-3.8-Next locally. Which is the best all-around l… by Spiros Fraganastasis.
- I added a recipe to kernel-hardening-checker: how to disable loading Linux kernel modules That can cut the attack surface of your system and protect it from many LPE exploits But it’s not easy to.
- RT Johann Rehberger: Copirate 365: Plundering in the depths of Microsoft Copilot - Brief history of AI data exfil exploits over last 3+ years - D… by Max.
- RT Moloch: Latest version of Sliver: - Execute (some) unmodified .cna scripts using a Go implementation of Sleep/Aggressor scripts. - Improved rportfw… by Max.
- RT Ruben Groenewoud: Fileless execution on Linux still leaves (a lot of) observable behavior. My latest research identifies five common patterns and m… by Ring3API 🇺🇦.
- RT Robert Graham: Flok is already being abused to suppress political enemies. by nyxgeek.
- RT vx-underground: Out of EVERYTHING that has happened JUST THIS WEEK ALONE, your primary focus is someone doing PASSWORD SPRAYING against a social me… by nyxgeek.
- Caught in the Octopus Trap: Unauthenticated RCE in Argo CD with CodeQL - @hugow_vincent https://www.synacktiv.com/en/publications/caught-in-the-octopu… by Swissky.
- RT KaterX: Offenbar wurden die gestohlenen Daten Berlins nun freigeschalten !!!!! Gute Nacht Berlin… Ich habe bereits vieles gefunden das als V… by pfiatde.
- RT INFINITE NIGHTMARE: I have to admit, impressive response time, one day patch wow… https://support.kaspersky.com/vulnerability/list-of-advisories/… by Rémi GASCOU (Podalirius).
- RT matteyeux: Binary Ninja 6.0 introduced a Binary Similarity feature (see bindiff++). I updated the Binja Diff plugin so you can use QBinDiff as a pr… by Jordan Wiens.
- “nobody is getting kicked out of the kernel, this is a partnership and we’re at the front of it” - @aionescu, 2026 - Fal.Con 2026 on discussing “Falco… by Rad.
- Critical infrastructure keeps getting tested and this time a UK power plant. John Strand breaks down why the US grid’s interconnected nature and slow … by Black Hills Information Security.
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-… by BleepingComputer.
- Critical Citrix NetScaler auth bypass now leveraged in attacks https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler… by BleepingComputer.
- RT Alex Neff: Are you (like me) constantly running into your own Responder? The days are finally over! @Defte_ and I finally finished up a PR by b… by Aurélien Chalot.
- Attackers conceal phishing lures using invisible Unicode characters https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-us… by Nicolas Krassas.
- Keeping Claude at Bay - Old Models are Still Useful https://blog.zsec.uk/claude-tips/ by Nicolas Krassas.
- Tengu, a Mirai-style Linux and IoT botnet https://app.reverser.space/p/duckie/tengu-reverse-engineering-a-mirai-style-linux-iot#0x1083d by Nicolas Krassas.
- MikroTrick lab PoC - CVE-2026-67276 (RouterOS SSH public-key auth bypass) https://github.com/dinosn/mikrotrick-poc by Nicolas Krassas.
- Someone accidentally logged hundreds of thousands of phone calls to military bases https://lina.sh/blog/hijacking-e164-arpa by Nicolas Krassas.
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner https://thehackernews.com/2026/09/four-revstealer-linked-modu… by Nicolas Krassas.
- Actively exploited sandbox RCE in all Chromium versions (CVE-2026-85046) https://nvd.nist.gov/vuln/detail/cve-2026-85046 by Nicolas Krassas.
- Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended https://cert.pl/en/posts/2026/09/vulnerabilit… by Nicolas Krassas.
- OpenAI Announced $1B in Defensive Tools for Water Utilities https://securityaffairs.com/198506/ai/openai-announced-1b-in-defensive-tools-for-water-uti… by Nicolas Krassas.
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commer… by Nicolas Krassas.
- RT SS: redactproxy: Use AI for pentesting without leaking client data * AI agents are powerful for pentesting, but risk sharing client data with AI pr… by Nicolas Krassas.
- Token Theft in Microsoft Entra ID, by @insinuator Part 1: Threat Landscape and Attack Techniques https://insinuator.net/2026/08/token-theft-in-microso… by DirectoryRanger.
- Anatomy of SystemOptimizer - A BYOVD EDR Killer with a UAC Bypass #DFIR https://cham1ndux.github.io/posts/BYOVD-EDR-killer-with-a-UAC-bypass-and-a-lyi… by DirectoryRanger.
- Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint https://www.mannulinux.org/2026/08/Privilege-escalation-from-IIS-A… by DirectoryRanger.
- Attacking and Defending SCOM: Management Server Relay and Obtaining Run As Credentials https://www.guidepointsecurity.com/blog/attacking-and-defending… by DirectoryRanger.
- DragonForce Ransomware Analysis. Inside a Verified Windows Locker #DFIR https://darkatlas.io/blog/dragonforce-ransomware-analysis-windows-locker by DirectoryRanger.
- PowerShell for Hackers: Exploitation Essentials, by @hetmehtaa https://hetmehta.com/posts/powershell-for-hackers/ by DirectoryRanger.
- RT DirectoryRanger: VMkatz. Extract Windows credentials directly from VM memory snapshots and virtual disks, by @Nikaiw https://github.com/nikaiw/VMka… by DirectoryRanger.
- RT DirectoryRanger: M365Pwned. Red Team tooling for Microsoft 365 exploitation via Microsoft Graph API, by @OtterHacker https://github.com/OtterHacker… by DirectoryRanger.
- RT Panos Gkatziroulis : Simulating legitimate Active Directory services on the network: the case of GPO exploitation https://www.synacktiv.com/en/… by DirectoryRanger.
- RT 0xSEC: Privilege exploitation - UAC Bypass using CMSTPLUA COM Class https://0xsec.gitbook.io/0xsec/windows/uac-bypass-cmstplua-com-exploitation #re… by DirectoryRanger.
- RT Nicolas Krassas: dump-guy/btr_cli: Offensive PoC tool for BTR.sys - Microsoft Defender’s Boot Time Removal Tool. Supporting material for the BTR Re… by DirectoryRanger.
- RT Nathan McNulty: Important note: This role cannot remove maliciously registered passkeys As organizations move to enforcing passkeys, this is someth… by DirectoryRanger.
- RT EZ: I haven’t talked about this in a couple years so here goes. There’s a lot of ways to phish in Teams. With Teams Public Clients With Teams Consu… by DirectoryRanger.
- RT jonas wiedermann-möller: okay so it seems like i found a new isolated group of agents working on the same task but not connected to the existing f… by LiveOverflow.
- RT Squiblydoo: The code-signing certificate for “OpsBridge LLC” is revoked. We continue to see new brands of RMM tools pop up and drop ScreenConnect i… by The Haag™.
- The harvest is ripe this week https://www.magicsword.io/changelog/lotl/2026-08-28-04 by The Haag™.
- RT Huntress: RAPID RESPONSE UPDATE: Huntress has produced a proof of concept (PoC) of a new vulnerability chain (CVE-2026-86206 & CVE-2026-86207) in N… by Giuseppe
N3mes1s. - RT Sansec: We discovered StyleSmuggler, an unauthenticated RCE in Magento & Adobe Commerce under active exploitation. Confirmed on clean 2.4.7, 2… by Giuseppe
N3mes1s. - RT Daniel Stepanic: Our team recently did a full teardown on #RevStealer. The malware is full of features and super interesting, unlike a lot of AI-ge… by Samir.
- RT Karl: New @NetSPI blog out today! Kudos to @thomas_elling for doing all the heavy lifting on this one, but this is a great primer on Azure RBAC/ABA… by Scott Sutherland.
- From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for https://ASP.NET AJAX https://tantosec.com/blog/2026/09/telerik-padding-oracle-to-s… by /r/netsec.
- I gave my agent an API key and lost $100. Never again. https://painintheagent.com/blog/your-ai-agent-wont-pay-your-bill/ by /r/netsec.
- Million-dollar phishing campaign uses invisible Unicode characters to bypass email filters https://cyberworldops.eu/en/million-dollar-phishing-campaig… by /r/netsec.
- RT Crackmes.one: My latest research on a new way to exploit vulnerable windows drivers: bring your own trusted caller (BYOTC). In addition to bringing… by winterknife.
- i wasn’t kidding btw! https://github.com/omacom/omarchy/pull/1296/commits/d0dd5206cf3907eee6f13f75db935d978f77c1ba#diff-99aecba6d9127d04cf241b3aa0138… by blasty.
- I’m launching a series of short posts about the tools I’ve built to automate reverse-engineering workflows. I’ve used them to analyze protections such as SafetyNet, DexProtector, iXGuard, and Arxan. F.
- RT a16z: Cyber is having a moment Across 21 major software companies, including Apple, AWS, Microsoft, and Google: - Reported critical vulnerabilities… by Florian Roth.
- RT Taha ז: And this is how you train CyberKimi to find the next chrome 0-day you start with unpatched n-days. So we caught a fresh V8 LLE aliasing bu… by Florian Roth.
- RT Cointelegraph: ALERT: High-severity CVEs went parabolic with over 2,200 flagged in 2026 alone, more than 6x the 2022-2025 average. by Simone Margaritelli.
- RT International Cyber Digest: ‼ BREAKING: Berlin’s Senate Chancellery hired CrowdStrike to assess the hack on the city administration. One distric… by Simone Margaritelli.
- The £3 WiFi Extender With a Backdoor in Every Unit https:// affixsec.substack.com/p/the-3- wifi-extender-with-a-backdoor.
- AI Escape watch https://ai-escape.watch/ by Thomas Roccia.
- 2 months later, this has changed significantly, up to about 90% now have been collided. by h0mbre.
- RT Hedgie: AI can only fix security vulnerabilities 26% of the time. Researchers at 1Password ran over 6,000 AI-generated patches using Claude and… by Halvar Flake.
- RT Alex Matrosov: The uncomfortable truth is that almost everything we built for application security was designed for a different threat model, one w… by hasherezade.
- RT cr3ghost: Detection engineers, red teamers, malware analysts, reverse engineers and blue teams: if EDR bypass, EDR blinding, BYOVD, rootkits or Rin… by hasherezade.
- RT Karsten Hahn: New Video: Hooking V8 JavaScript compiled V8 we write a reusable hook script we overcome basic anti-hooking … by hasherezade.
- RT Ayaan : One developer reverse-engineered Apple’s GPU from scratch. 5 years later, Linux runs on it with full graphics acceleration. Me… by hasherezade.
- RT etugen.io: A great hunt! by batuu.
- Earlier this year, I wrote about the evolution of Credential Guard attacks and modern detection strategies, including SpecterOps’ latest SSP Negotiat… by Panos Gkatziroulis.
- Remote Thread Hijacking + Remote Mapping Injection POC https://github.com/emirbyte/Remote-Mapping-Hijacktion by Panos Gkatziroulis.
- If you recognize this Dutch man’s voice, you might know a key cybercriminal with the prolific Shiny Hunters data extortion group. The Dutch police have published a reenactment of a social engineering.
- RT 7h3h4ckv157: CVE MCP Server MCP server that turns Claude into a full-spectrum security analyst. Instead of juggling 15+ browser tabs across NVD, EP… by Spiros Fraganastasis.
- RT Liran Tal: We have been working on the OWASP MCP Security Taxonomy - an open, vendor-neutral framework designed to create a common language for MCP… by Spiros Fraganastasis.
- RT Swissky: Endpoint AI Agent Abuse (EAA) is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their run… by Max.
- RT : NetExec module list (updated) https://gist.github.com/gitgotgitgotit/81a578e065da1ccd8c81a8e90c309275 Links to NetExec wiki article (if it ex… by Max.
- RT r1cksec: A post about how to bypass Chromes remote-debugging port restrictions. https://www.pikered.com/en/learn/bypass-remote-debugging-port-restr… by Max.
- RT CloudBreach: Device code phishing is hitting M365 hard. No fake page, no stolen password. The victim approves a real MFA prompt and the attack… by Renos.
- RT Phrack Zine: Sneak peek Coming soon from your friends at Phrack! by Richard Johnson.
- RT Frank: Microsoft tgrep: grep for searches in large code bases, with client/server support , 7x-50x faster than ripgrep and ugrep https://github.com… by Richard Johnson.
- RT 🇷🇴 cristi: Re - traced the login flow between the app, IdP, and backend. - saw weird automated call to reauth endpoint. was authenticated cal… by Sam Curry.
- RT Toan Pham: It seems to me that the “dark magic” of Codex /goal comes from its post-training policy - specifically, how the model behaves across co… by ϻг_ϻε.
- Prediction: this will be found and killed by patch Tuesday. Bugs these days have a lifespan measured in days. by thaddeus e. grugq.
- RT CR1337: LG TVs are quietly mapping your home network for unrelated hardware, including phones, smartwatches,.., while logging audio even with the s… by thaddeus e. grugq.
- RT ELFloader: 今天不发推文,我们决定开源近期自研的进攻型 Agent 工具 - - 该工具在腾讯实测跑分中位列第三,红队/SRC/CTF三大场景; 项目地址:https://github… by thaddeus e. grugq.
- RT Dr. Dan Lomas: Espionage Hub in Europe May Have Operated From Russian Consulate in Bonn, Bild Sources Say https://united24media.com/world/espionage… by thaddeus e. grugq.
- RT Md Ismail Šojal : Pre-built Jailbroken iOS 26 iPhone fully runs on browser. Full virtual iPhone ready-to-run jailbroken iPhone (rootless +… by thaddeus e. grugq.
- RT Tal Be’ery: Told ya (a year ago) https://medium.com/@TalBeerySec/follow-the-script-why-attackers-are-winning-the-ai-arms-race-39de80748d09 by thaddeus e. grugq.
- RT Chaos Magician: You can just bypass Cloudflare by using an LLM’s user agent header. This is hilarious when you think about the fact that the point… by thaddeus e. grugq.
- RT Chris Wysopal: “Agentic swarms have been all over the #MLsec news since the “OpenAI hacks Hugging Face” debacle. We think understanding colony beha… by thaddeus e. grugq.
- ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager by Vanja Svajcer.
- ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 by Sean Gallagher.
- Stealing AI Reasoning Traces by Bruce Schneier.
- Good news for malware enthusiasts, another 200,000+ malwares have been uploaded to VXUG. Good news for people who like silly pictures of cats, I’ve at… by vx-underground.
- RT Raphael Rashid: South Korea’s top plastic surgery app Gangnam Unni has been hacked, exposing data on 220,000 users in Korea, Japan, Taiwan, China a… by Vincent Yiu.
- RT PandaRE 🇺🇦: One way to spot a malicious proxy DLL when there are over 20 DLLs in the folder and one of them is lying, under 60 seconds. … by Vincent Yiu.
- RT Silky: Found a built-in Windows driver that gives you arbitrary kernel memory read/write from local admin. No BYOVD required. My PoC elevates the c… by Vincent Yiu.
- Distros with enabled backdoor. by Mr.Z.
- RT Xion: Re Showing “how many cool 0days we found with our system” is fun, but more importantly, we all should continue iterating and improving on thi… by Axel Souchet.
Tools and Exploits
SpecterOps releases a public repository of reusable, reviewable skills that turn practitioner knowledge into AI-assisted security workflows.
MCP server enabling full end-to-end agentic detection engineering. Goes from threat report to analytics, Atomic Red Team simulation, SIEM query iteration, and PR submission.
BloodHound-style attack path mapping for AI agent infrastructure. Maps paths across MCP, A2A, gateways, and AI services for recon, credential extraction, and model exfiltration.
Major Binary Ninja release with massive performance improvements, built-in MCP server, binary similarity analysis, Extension Manager, TMS320C6x architecture support, and more.
LLM-assisted malware triage tool that creates a sandbox environment for an agent to analyze files and generate automated reports.
Workshop materials from DEF CON 34 and BSidesLV covering malware development, EDR architecture, evasion techniques, C2 customization, and kernel-level approaches.
Kitty terminal on Omarchy Linux is vulnerable to remote code execution just by viewing content. Exploit PoC released.
Updated Linux KASLR derandomization tool adds 18 new leak components (120 total) and introduces certainty ratings to distinguish proven values from heuristic guesses.
Automated tool that rewrites architecture information and adjusts library paths to run macOS command-line binaries on iOS, including DYLD shared cache extraction.
REcon 2026 conference recordings are being published on YouTube, with more talks pending speaker confirmation.
More this week (18)
- Authentication bypass in EOL Proxmox VE 7 release https://forum.proxmox.com/threads/proxmox-virtual-environment-security-advisories.149331/page-4#post… by /r/netsec.
- RT Nextron Research : Our THOR Thunderstorm-based artifact scanning pipeline identified the open-source research project BindsNET as compromi… by Florian Roth.
- RT Andrii Bezverkhyi: https://github.com/socprime/logtotal-sanitizer We have just released on GitHub logtotal-sanitizer a framework-agnostic log maski… by Florian Roth.
- RT Abliteration.ai: Today we’re releasing abliterated-model-large-v2. Based on GLM-5.3, which is #3 on Terminal-Bench 4.0 (behind only Opus 5 and Fabl… by Spiros Fraganastasis.
- RT mpgn: Following the release of NetExec-MCP, I’m sharing the benchmark that made me question how everyone builds MCP servers in 2026 ! Most of them … by Max.
- RT lukas seidel: today, we @RevEng_AI released the next generation of our decompiler: Ventris the new model comes with improved struct layout recovery… by thaddeus e. grugq.
- Cisco searched for IOS XR bugs and found so many it rolled them into an update release https://www.theregister.com/security/2026/09/04/cisco-searched-… by Nicolas Krassas.
- RT @VMwareSRC: Today we released a new Critical Severity VMware Security Advisory. Check out https://support.broadcom.com/web/ecx/support-content-noti… by Sean Metcalf.
- RT Tim: For more than 2 years now the Red Team at MDSec have been running riot in environments by abusing ServiceNow. Today we are releasing more of o… by Chris Thompson.
- RT Sundar Pichai: We’re also introducing Gemini 3.8 Flash Cyber, our most capable cybersecurity model. It shows frontier-level performance in discove… by skull.
- RT Vasko: Introducing Cyber-Prime 1 2.6B. It’s the smallest cyber-security agentic model you can find, built on top of @liquidai’s LFM 2.6B ( goated m… by Spiros Fraganastasis.
- RT Quentin Texier : Big update for RustHound-CE version 2.5.9 New in this release: - GPO parsing from SYSVOL (AdminTo, CanRDP, CanPSRemo… by Max.
- RT Óscar Alfonso Díaz: Evil-WinRM v4.1 is out! Ruby 4 support, improved remote completion, quit/Ctrl+D, safer downloads, handshake fixes & keep… by Max.
- RT Leo Tsaousis: Last week we released Virtual//Attack An AtomicRedTeam-style collection of 80+ attack techniques against VMware environments includin… by Mayuresh 🇮🇳.
- CrowdStrike Launches Frontier Models for Cybersecurity, Created with NVIDIA https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-… by Nicolas Krassas.
- RT cr3ghost: Infosec tradecraft just became reusable by AI agents. SpecterOps just open-sourced: 79 skills. 22 reusable agents. 26 plugin families. Bl… by Chris Thompson.
- RELEASE: OMARCHY Linux (current) Local Privilege Escalation Exploit blasty-vs-omarchy.c -> https://gist.github.com/blasty/e5f267614e0fb35d295ba64b713f… by blasty.
- RT 0x12 Dark Development: Handle Redirect also released in GitHub: https://github.com/S12cybersecurity/HandleRedirect by Panos Gkatziroulis.
