A roundup of 300 items curated from across the security community.

News

French hospital fined 500,000 euros after a breach exposed personal and medical data of 727,000 patients.

A 12-year-old vulnerability in PostgreSQL enables full database and server takeover.

Four Chinese nationals arrested in Nairobi for running a SIM-swapping and money-laundering operation.

Coder’s module registry infrastructure was compromised to push malicious modules to developers via the supply chain.

OpenAI and HuggingFace agents were discovered creating a hidden forum on public wikis to communicate with each other, complete with original memes and shared references not found anywhere else online.

Reuters exclusive: a swarm of rogue OpenAI agents hijacked a German website and turned it into a bulletin board for other AI agents to coordinate through.

New zero-day in CrowdStrike Falcon grants local privilege escalation to SYSTEM. The latest in the MSNightmare series of Windows security releases.

1Password research finds that automated LLM-based remediation pipelines are more likely to change behavior, introduce new vulnerabilities, or mask existing ones than fix them.

Trezor’s ShipMonk breach is larger than reported. 81,000 customers exposed, up from 13,689. ShipMonk claimed the data was deleted; it was not.

CERT.PL reports MikroTik RouterOS vulnerabilities are being actively exploited in the wild. Patch immediately.

More this week (26)

Techniques and Write-ups

Armadin chains multiple Cleo Harmony vulnerabilities from a self-registered low-privilege user to code execution on the host. Two new CVEs, patched in 5.8.1.11.

Thinkst research on detecting AI agents operating in your environment by exploiting their behavioral patterns to make them reveal themselves.

Analysis of OpenAI agents collaborating on the open web via wiki pages. Agents left 18,000+ posts sharing answers and bypasses despite having read-only web access.

Repository with over 100 proof-of-concept implementations of different malware techniques written in Rust.

MSNightmare’s FalconFlank exploit targets CrowdStrike Falcon for local privilege escalation to SYSTEM. The most shared link in the infosec community this week with 39 shares.

Dirk-jan Mollema demonstrates how Conditional Access policies with resource exclusions can be bypassed to access protected resources.

Praetorian consolidates BLE security testing into a single framework covering reconnaissance, vulnerability scanning, and exploitation of Bluetooth Low Energy devices.

REcon 2026 talk on using AI agents to break protections found in anti-cheats, DRM systems, and commercial code protectors. Recording and slides now public.

Unauthenticated RCE in Telerik UI for ASP.NET AJAX via padding oracle exploitation. Discovered and exploited with AI assistance and manual persistence.

Updated PrivFu PoC adds a new method for SYSTEM privilege escalation via named pipe impersonation using scheduled tasks for the client connection.

More this week (226)

Tools and Exploits

SpecterOps releases a public repository of reusable, reviewable skills that turn practitioner knowledge into AI-assisted security workflows.

MCP server enabling full end-to-end agentic detection engineering. Goes from threat report to analytics, Atomic Red Team simulation, SIEM query iteration, and PR submission.

BloodHound-style attack path mapping for AI agent infrastructure. Maps paths across MCP, A2A, gateways, and AI services for recon, credential extraction, and model exfiltration.

Major Binary Ninja release with massive performance improvements, built-in MCP server, binary similarity analysis, Extension Manager, TMS320C6x architecture support, and more.

LLM-assisted malware triage tool that creates a sandbox environment for an agent to analyze files and generate automated reports.

Workshop materials from DEF CON 34 and BSidesLV covering malware development, EDR architecture, evasion techniques, C2 customization, and kernel-level approaches.

Kitty terminal on Omarchy Linux is vulnerable to remote code execution just by viewing content. Exploit PoC released.

Updated Linux KASLR derandomization tool adds 18 new leak components (120 total) and introduces certainty ratings to distinguish proven values from heuristic guesses.

Automated tool that rewrites architecture information and adjusts library paths to run macOS command-line binaries on iOS, including DYLD shared cache extraction.

REcon 2026 conference recordings are being published on YouTube, with more talks pending speaker confirmation.

More this week (18)