A roundup of 388 items curated from across the security community.
News
Trezor hardware wallet breach via email provider Brevo now confirmed to affect 81,000 customers, up from initial estimates.
Gamers Nexus testing reveals LG Smart TVs scan local networks, identify content, and record audio even in standby mode with no internet connection. WebOS flaws could enable RCE.
Logical bug in MariaDB allows any user, regardless of privileges, to update the password of any other user including root.
Microsoft patches a record 972 vulnerabilities with 112 critical-severity. AI-assisted vulnerability discovery continues to drive unprecedented patch volumes.
Joint NSA/FBI/CISA advisory details how China-based AI companies illicitly distill US frontier AI capabilities, with TTPs and recommended mitigations.
Volexity tracks multiple Chinese APTs chaining Chrome and Windows 0-days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to deliver GRIMWEDGE and a fake Gemini extension.
- Chinese National Charged with Modifying CBP Border Computers by thaddeus e. grugq.
Terry Liu, a Chinese national, was caught on camera replacing processors and memory devices in Customs and Border Patrol computers at the Maine-Canada border before re-inserting them.
The New York Times covers the WeWorm AI-powered zero-click worm that spread through WeChat phone calls. Calif publishes a defensive to-do list for collective defense.
Anthropic publishes its September threat report covering APT misuse of Claude, including Russian threat actors, Chinese distillation operations, and Iranian targeting of naval installations.
- Schneier: AI-Powered Patching and the Shrinking Fix Window by Bruce Schneier.
Schneier analyzes the record-breaking patch volumes driven by AI vulnerability discovery and warns that AI is also accelerating exploit development from published patches.
More this week (37)
- Mathspace discloses data breach affecting over 1 million people https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecti… by BleepingComputer.
- ShinyHunters claims breach of Florida DMV, threatens data leak https://cyberinsider.com/shinyhunters-claims-breach-of-florida-dmv-threatens-data-leak/ by Nicolas Krassas.
- 220 million traveler records exposed in Vietnam-linked APIS leak https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-i… by Nicolas Krassas.
- Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak https://securityaffairs.com/198628/data-breach/conde-nast-data-of-32-8-millio… by Nicolas Krassas.
- Regarding StyleSmuggler - Magento/Adobe Commerce unauthenticated RCE chain exploitation, if you have a Magento shop, you are compromised. Exploitation… by Nicolas Krassas.
- RT Sam Erde: Raid my stash of PowerShell scripts from the past 10+ years of work in Entra, Active Directory, Microsoft 365, Exchange Server, Server, a… by Sean Metcalf.
- Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator’s Own Files https://hunt.io/blog/redis-cryptomining-botnet-3562-serv… by /r/netsec.
- Chatbot leaked a planted phone number and failed 58% of prompt injection attempts - jailbreak and extraction checks stayed clean https://drive.google…. by /r/netsec.
- Hacking AI customer service agents (Bug Bounty Village DEF CON 34) https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-servic… by /r/netsec.
- RT Faruk Sener: Our team analyzed a campaign exploiting CVE-2025-25249 to compromise #FortiGate devices and deploy #PivotC2, a Node.js RAT built … by kmkz.
- Driver’s License Data for Sale by Bruce Schneier.
- Trezor warns users of email provider breach, phishing attacks https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-brea… by BleepingComputer.
- Over 36,000 Plex servers unpatched against recently disclosed flaws https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-… by BleepingComputer.
- An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generate… by BleepingComputer.
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-de… by BleepingComputer.
- Trezor breach victims are now getting malicious QR codes by postal mail https://domainsure.com/crypto/trezor-supply-chain-hack-moves-to-postal-mail-at… by Nicolas Krassas.
- Razer Lycosa.sys analysis: kernel memory disclosure and stack buffer overflow https://github.com/416rehman/razer-lycosa-kernel-lpe-BYOVD-Vulnerability… by Nicolas Krassas.
- Veradigm warns of patient data breach after ransomware gang claims attack https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-da… by Nicolas Krassas.
- RT Enno Rey: Recent AI security related posts on @Insinuator: https://insinuator.net/2026/06/vulnerability-disclosure-stealing-emails-via-firefoxs-ai-… by DirectoryRanger.
- RT Microsoft Security Response Center: Security updates for September are now available: https://msft.it/6018SZEg0. Alongside this month’s release, we… by SwitHak ().
- If you’re going to be a Blackhat and get away with it, don’t buy the yellow Hummer by Adam Chester.
- Cliff Stoll’s DEF CON Talk by Bruce Schneier.
- My Talk at DEF CON by Bruce Schneier.
- RT Tuhin Bose: Found a critical IDOR on a fintech that leaked every customer’s name, email id, phone number, address, bank account number, IFSC, nomin… by Michael G.
- Trezor: Our third-party e-mail provider has been breached. Please be aware that the email named ‘Critical Security Alert: STM32 Entropy Vulnerability’ is not coming from us, and it’s a phishing attemp by vx-underground.
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-… by BleepingComputer.
- Surfshark VPN says hackers breached internal testing, proxy servers https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached… by BleepingComputer.
- IDScan confirms breach tied to 153 million stolen driver’s licenses https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153… by BleepingComputer.
- Florida confirms DMV database breached via stolen police account https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached… by Nicolas Krassas.
- Crypto customers targeted by scammers after email marketing provider breach https://www.malwarebytes.com/blog/news/2026/09/crypto-customers-targeted-b… by Nicolas Krassas.
- RT Josh: I’ll be talking at SAS Con next month about breaking into Car Infotainment systems over Bluetooth for Pwn2Own! Come and say hi and hear about… by SinSinology.
- RT spencer: Hacking for good. DEF CON 34. https://youtube.com/playlist?list=PLQQnglwF9E8Q&si=NEcOQEFywr8CnfsV by kmkz.
- RT Pliny the Liberator 󠅫󠄼󠄿󠅆󠄵󠄐󠅀󠄼󠄹󠄾󠅉󠅭: SYSTEM PROMPT LEAK Got the full system prompts and tools for GP… by Spiros Fraganastasis.
- RT Stephan Berger: Someone at BSides Frankfurt asked me this week if I could share the slides from my talk. Of course - and not just those. All m… by Max.
- New vBulletin Vulnerability! https:// ssd-disclosure.com/vbulletin-r untime-template-runmaths-preauth-rce/.
- Thailand’s Ministry of Finance targeted with an AI agent running with approval prompts disabled https:// hunt.io/blog/thailand-ministry -finance-targeted-with-hermes-ai-agent.
- GitHub issues $100,000 bounty for critical RCE vulnerability https:// runtimewire.com/article/github -issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitz.
Techniques and Write-ups
Calif’s WeWorm research on AI-powered zero-click worm propagation was the most shared security link of the week with 28 mentions. Full research writeup on the autonomous attack chain.
MSNightmare demonstrates a full bypass of Microsoft’s ShieldBreak patch (CVE-2026-69414). Works on the latest September 2026 update. Also bypasses the earlier RoguePlanet fix.
REcon 2026 talk on using AI agents to break protections in anti-cheats, DRM systems, and commercial protectors. Includes the corresponding tool for multi-binary appliance analysis.
- Unmasking SCCM Application Execution by Joshua Prager.
SpecterOps details how SCCM application execution generates different artifacts than script-based execution, evading existing detection tools. Covers the stealthier execution flow and how to detect it.
Out-of-bounds vulnerability in Goja, the Go JavaScript engine, chains to a full sandbox escape and remote code execution.
Purple team playbook on abusing Windows Security Center APIs to disable Defender, with detailed detection strategies for each technique.
Full compromise of Paxton10 access control systems. Covers the attack chain from network access to physical door control.
TrustedSec walks through AWS credential types, where to find them, and how to validate and use them during a security engagement. Part 1 of an ongoing series.
First look inside Microsoft’s new Windows Endpoint Security Platform. Reverse engineering of wesp.sys and espclient.dll, with a working consumer PoC published on GitHub.
Project Zero releases MAccConc, a tool for deterministic testing of race conditions on Linux. Enables reproducible fuzzing, regression tests, and ad-hoc exploration of concurrent code.
More this week (318)
- TokenFlags2! Currently contains “TokenIsInstaller” and “TokenAgentId”. Both are gated via feature flag - but TokenAgentId doesn’t seem to be currently… by Connor McGarr.
- SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-ke… by BleepingComputer.
- Researchers have discovered 39 methods for compromising passkeys without breaking FIDO2 cryptography. @token explains how attackers instead… by BleepingComputer.
- OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gp… by BleepingComputer.
- Adobe fixes critical Magento zero-day exploited to backdoor servers https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-d… by BleepingComputer.
- Hackers build AI frameworks for widescale credential theft https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-cr… by BleepingComputer.
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploi… by BleepingComputer.
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing… by BleepingComputer.
- Hackers exploit new MikroTik RouterOS flaws to hijack routers https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-fla… by BleepingComputer.
- ConnectWise warns of new ScreenConnect flaw without patch https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-w… by BleepingComputer.
- N-able patches max severity N-central flaw amid ongoing attacks https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-f… by BleepingComputer.
- WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over…. by Nicolas Krassas.
- BigBear phishing crew nets thousands of Microsoft 365 credentials https://www.theregister.com/security/2026/09/08/bigbear-phishing-crew-nets-thousands… by Nicolas Krassas.
- Stealing AI Reasoning Traces https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html by Nicolas Krassas.
- RCE PoC Lab for StyleSmuggler Magento CVE-2026-75650 https://github.com/dinosn/cve-2026-75650-magento-validation-lab by Nicolas Krassas.
- CONTINUITY: Security-Context Contracts for Composable LLM Agent Controls https://arxiv.org/abs/2609.05269 by Nicolas Krassas.
- RT hasherezade: Time to time I see #malware unpacking tutorials using #PEsieve and incorrectly stating that it doesn’t rebuild import table and you … by Nicolas Krassas.
- New attack eavesdrops on headphone audio from 30 meters away https://cyberinsider.com/new-attack-eavesdrops-on-headphone-audio-from-30-meters-away/ by Nicolas Krassas.
- North Korean Hackers Deploy New Linux Espionage Toolkit https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/ by Nicolas Krassas.
- Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts https://thehackernews.com/2026/09/rogue-screenconnect-clients-sp… by Nicolas Krassas.
- Bimbo Bakeries confirms data stolen in Oracle EBS zero-day attack https://cyberinsider.com/bimbo-bakeries-confirms-data-stolen-in-oracle-ebs-zero-day-… by Nicolas Krassas.
- RT DirectoryRanger: Token Theft in Microsoft Entra ID, by @insinuator Part 1: Threat Landscape and Attack Techniques https://insinuator.net/2026/08/to… by DirectoryRanger.
- RT DirectoryRanger: PowerShell for Hackers: Exploitation Essentials, by @hetmehtaa https://hetmehta.com/posts/powershell-for-hackers/ by DirectoryRanger.
- RT daem0nc0re: Updated PoC to get SYSTEM privileges with named pipe impersonation. I add a new method using scheduled tasks for named pipe client conn… by Dave Cossa.
- Random read - seems there’s an Outlook Web 0day (rather than the Outlook Classic app) being sold in black market, be careful. If it’s targeting the … by Haifei Li.
- We shall deprecate ntlm for a more problematic implementation by Jean.
- PowerVR: PVRSRV_MEMALLOCFLAG_OS_LINUX_PREFER_CMA PMR allocations with a large page size causes page allocator corruption https://project-zero.issues.c… by Project Zero Bugs.
- The full source code of this panel, agent, encryptor, etc have been acquired and donated by an anonymous security researcher. If interested in analyzi… by Ezra Woods.
- RT Tanto Security: From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP[.]NET AJAX https://tantosec.com/bl… by S3cur3Th1sSh1t.
- RT Murray: Re As this writes to the UEFI, then can automate deployment from the start of the OOBE, how do I replace, decommission, or otherwise remove… by SwiftOnSecurity.
- SRI🇷🇴, in cooperation with national and international partners, prevented a sabotage operation coordinated by the Russian Federation🇷🇺 on … by SwitHak ().
- RT Cisco Talos Intelligence Group: Cisco Talos is tracking a ClickFix variant that exploits the Google Visualization API for command and control, enab… by SwitHak ().
- AIs as Modern Genies by Bruce Schneier.
- Token Analysis and Tracking System (TATS) by Hope Walker.
- From Findings to Fixes: Getting Value from Red Team Results by Ric Nguyen.
- The September 2026 Security Update Review by Dustin Childs.
- RT Nathan McNulty: There seems to be some confusion about token theft via Attacker in the middle, so I made this diagram by Dirk-jan.
- RT Vandana Verma: Hi Team, We have been working on the OWASP MCP Security Taxonomy an open, vendor-neutral framework designed to create a common langu… by Scott Sutherland.
- Two critical remote bugs found in ArangoDB https://remedio.io/blog/trust-me-im-the-system-arango-db-bugs-secure-system-architecture/ by /r/netsec.
- The £3 WiFi Extender With a Backdoor in Every Unit https://affixsec.substack.com/p/the-3-wifi-extender-with-a-backdoor by /r/netsec.
- RT Vector 35: A bird? A plane? NO! It’s Binary Ninja 6.0, codename “Krypton”. Major new stable with massive performance improvements, built-in MCP, Bi… by winterknife.
- Another 3 Windows LPE’s I found just patched in September patch Tuesday! CVE-2026-68839 - https://msrc.microsoft.com/update-guide/vulnerability/CVE-20… by Alex Plaskett.
- Microsoft Patch Tuesday for September 2026 - Snort rules and prominent vulnerabilities by Cisco Talos.
- Hello again dear Windows (ab)users. I know it probably seems like just yesterday I was yapping about patches, but here we are again. Microsoft cannot seem to express its affection for users enough lat.
- RT Nextron Research : Back in June we analyzed a SideCopy / Transparent Tribe infection chain targeting Indian defense personnel, using an LNK + B… by Florian Roth.
- RT Trail of Bits: OpenSSL’s latest advisory covers 9 patched vulnerabilities. Our engineers Filipe Casal and Opal Wright found 4 of them as part of Pa… by Dave Aitel.
- I’ve just updated a blog post I wrote in 2018 about how to use Burp macros and session handling rules to bypass CSRF protections. You can read the blo… by Robin.
- TIL you can skip Github CI checks, including security checks, if you add specific strings like
[skip ci]to a commit message … by Simone Margaritelli. - by Thomas Roccia.
- RT Volodymyr Styran 🇺🇦: I have dedicated my professional life to positioning Ukraine as a professional hub and a trustworthy partner rather than… by Halvar Flake.
- RT Check Point Research: What if isolated #ChatGPT sessions could secretly exchange data? A shared internal service became a covert channel b… by hasherezade.
- RT cr3ghost: Detection engineers, red teamers, malware analysts, hardware hackers and reverse engineers: bookmark this FREE rabbit hole. @waldoirc is … by hasherezade.
- RT B1lal: During our analysis, we looked into a SystemCheck.msi file we found on a server distributing a fake Adobe/Zoom update, and found that it was… by batuu.
- ntlmrain - Recover NT hashes from NetNTLMv1 responses using local WebGPU computation and local/remote table lookup https://github.com/outflanknl/ntlmr… by Panos Gkatziroulis.
- HashSiphon - NTLM hash extraction through HTTP-layer authentication proxying, zero SSPI calls from the attacker process https://github.com/ivancabrera… by Panos Gkatziroulis.
- Endpoint AI Agent Abuse - a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration… by Panos Gkatziroulis.
- RT BallisKit: Need to automate payload creation and EDR Evasion for your RedTeam? The new version of MacroPack is available! Ready to use EDR evasion,… by Chihuahua in charge NotMe.
- A “proof” of Fermat’s Last Theorem that fits the margin.
- RT Linux Kernel Security: SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free Article about exploiting CVE-2026-64564 in the Stream Contro… by kmkz.
- RT @CPResearch: What if isolated #ChatGPT sessions could secretly exchange data? A shared internal service became a covert channel b… by kmkz.
- RT FuzzingLabs: A file in the Linux kernel with 0% Syzbot coverage is an invitation… That’s how our team at @fuzzinglabs ended up looking in batman-… by kmkz.
- RT Zero Day Engineering: 0-Day Alert: Chrome v8 RCE exploited in the wild CVE-2026-85046: v8 array-builtin callback side-effect to elements-kind … by kmkz.
- RT Inti De Ceukelaire: how i hacked 320+ companies that replaced their cs team with “smart” ai agents: 1. drafted a gdpr request to support@ 2. change… by Max.
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilities by Cisco Talos.
- If you buy networking gear or laptops on Amazon, it’s probably a good idea to re-flash fully before using. Amazon isn’t just “Amazon”, it’s a conglome… by nyxgeek.
- ICYMI: CVE-2026-72898: Critical Metabase SQL injection, CVSS 10.0, no authentication required - and active exploitation has been confirmed. See … by OffSec.
- Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) - @R3n5k1 https://blog.amberwolf.com/blog/2026/july/dell-bios… by Swissky.
- Trust no one: are one-way trusts really one way? - @lowercase_drm - March 2026 https://offsec.almond.consulting/trust-no-one_are-one-way-trusts-really… by Swissky.
- tsk, how many of these were honeypots. by Rad.
- RT V12: Stored XSS in Forgejo, leading to full control over a victim’s account: by Rick de Jager.
- RT Stephen Fewer: Just added a @metasploit exploit for last weeks SonicWall SMA1000 zero-day chain that has been exploited in-the-wild (CVE-2026-83548… by ϻг_ϻε.
- RT Dino A. Dai Zovi: For a long time, I said that we’d never see mass mobile malware… but the calculus have changed with messaging apps with billion… by thaddeus e. grugq.
- RT mRr3b00t: Great spot! CVE-2026-69730 is a Windows Server DNS Server RCE! apparently can be exploited by default! you would need line of sight to a … by thaddeus e. grugq.
- RT ︎: Yea unless Pixel almost all Androids will remain vulnerable for Christmas and New Years. Happy N-Daying all the important or unimportant target… by thaddeus e. grugq.
- RT Tal Be’ery: WhatsApp users were exploited in 2019 using a similar method (that’s the case that led to their lawsuit against NSO) CC: @citizenlab @j… by thaddeus e. grugq.
- RT blackorbird: Beyond Lazarus: Organization of DPRK Cyber Capabilities The old #Lazarus umbrella has been decomposed into six distinct clusters (TEMP… by thaddeus e. grugq.
- RT DaviMatsuyama: I wrote a write-up about a v8 challenge. In that write-up I explain about the v8’s sandbox. I expect that you enjoy reading that wri… by thaddeus e. grugq.
- RT Abdulkadir | Cybersecurity: Your LG OLED is watching your living room while you sleep. Gamers Nexus just ran 135 minutes of bench tests. Retail LG … by James .
- > be me > get dm > “smelly i found goop” > wtf i love goop (malware) > “I lost the goop… but I found a weird file on my computer” > sends file > mal… by vx-underground.
- Attackers burned two rounds of domains on email bomb + fake Teams help desk lures, then stopped registering domains at all. Free M365 trial tenants: n… by Black Hills Information Security.
- Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure… by BleepingComputer.
- AdaptHealth confirms 4.1 million people exposed in July cyberattack https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-peo… by BleepingComputer.
- Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to… by BleepingComputer.
- New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-z… by BleepingComputer.
- Google warns of new Chrome zero-day bug exploited in attacks https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exp… by BleepingComputer.
- DoppelCart fraud network uses 119,000 fake shops to steal credit cards https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-11… by BleepingComputer.
- Dental contractor set up secret account with access to 4,000 patient records then left the company https://www.theregister.com/security/2026/09/10/den… by Nicolas Krassas.
- U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog https://securityaffairs.com/198802/… by Nicolas Krassas.
- BOF, Crystal Palace Linker and The JellyBee KORE Compiler: The new era of implants modularity https://kdrajkit.github.io/blogs/jellybeesystem-internal… by Nicolas Krassas.
- Breaking Efimer’s Pyarmor Infection Chain with Frida https://invokere.com/posts/2026/09/breaking-efimers-pyarmor-infection-chain-with-frida/ by Nicolas Krassas.
- New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.ht… by Nicolas Krassas.
- Google fixes the seventh actively exploited Chrome zero-day of 2026 https://securityaffairs.com/198757/security/google-fixes-the-seventh-actively-expl… by Nicolas Krassas.
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html by Nicolas Krassas.
- Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html by Nicolas Krassas.
- US says Chinese firms extracted billions of tokens from frontier AI models https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extrac… by Nicolas Krassas.
- Ivanti Patches Critical Flaws Across Enterprise Security Products https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-securit… by Nicolas Krassas.
- Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-l… by Nicolas Krassas.
- ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critic… by Nicolas Krassas.
- More than 100,000 fake stores are out to steal your card details https://www.malwarebytes.com/blog/scams/2026/09/more-than-100000-fake-stores-are-out-… by Nicolas Krassas.
- US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models https://securityaffairs.com/198770/security/us-agencies-warn-chinese-ai-firms-are-… by Nicolas Krassas.
- RT Jacob Baines: We bought an $88 router on Amazon looking for the ENDLESSDOORS implant. We found two others instead DARKLANTERN gives anyone on the I… by Nicolas Krassas.
- RT Andrew: Everyone says on-prem AD is picked clean. Nope! AD RMS still ships in Server 2025. It got two pages in “AD in a Month of Lunches.” It deser… by DirectoryRanger.
- RT DirectoryRanger: Insights into Entra ID’s (Un)Conditional Access, by @insinuator https://insinuator.net/2026/05/insights-into-entra-ids-unconditio… by DirectoryRanger.
- Jeff does wayyy cooler things than me but still always shares my stuff anyway. Thanks for the support by Maxwell ꓘ Dulin (Strikeout).
- RT Jeff Schroeder: From @Dooflin5, a coworker of mine. A browser port of hash_extender for hash length extension attacks: https://mdulin2.github.io/Ha… by Maxwell ꓘ Dulin (Strikeout).
- AIs Compress Exploit Timeline by Bruce Schneier.
- RT BallisKit: Need to automate payload creation and EDR Evasion for your RedTeam? The new version of MacroPack is available! Ready to use EDR evasion,… by Melvin langvik.
- This Microsoft Patch Tuesday, among with the historical 974 (!) bugs patched, I contributed three. - Microsoft Word Remote Code Execution Vulnerabilit… by Haifei Li.
- I received 37 CVE credits from MSRC this month. Neither the number of vulnerabilities patched nor multiple researchers sharing credit for the same bug… by k0shl.
- RT Steven Adair: We just had some super interesting cases of multiple Chinese APT groups simultaneously using the same chained 0-day exploits in Googl… by L0Psec.
- I generally agree with the main argument of this article: whack-a-mole patching individual vulnerabilities, without using that to inform a larger stra… by LiveOverflow.
- And this is the v8 heap sandbox bypass that I used for my v8ctf n-day submission. thanks Jihyeon Jeong! by LiveOverflow.
- RT Jakub Czekański: Running VW/Skoda (MIB2) infotainment natively on Mac by LiveOverflow.
- RT David Adrian: Putting my markdown where my mouth is https://github.com/zmap/zmap/blob/main/SECURITY.md by LiveOverflow.
- RT Gal Weizman: Security research in the agentic era is completely wild The threat model is so broken that I honestly can’t tell anymore if what I’m f… by LiveOverflow.
- RT Lupin: Like always Inti is doing some wizardry. Seems simple once you have the answer but you need to think about it by LiveOverflow.
- RT Oren Yomtov: Asked Claude to find vulnerabilities in AWS before going to bed, woke up to a scary email, and ended up reporting a critical cross-cus… by Giuseppe
N3mes1s. - RT Previdian: What we know so far about Magento StyleSmuggler https://blog.previdian.com/stylesmuggler-cve-2026-75650-actively-exploited-magento-and-a… by Giuseppe
N3mes1s. - RT Stephen Fewer: While researching last months N-able N-central exploit (CVE-2026-18577, on KEV), we found and reported a new authentication bypass c… by Giuseppe
N3mes1s. - Took MikroTik · RouterOS for a spin, better context provide better defense. by Giuseppe
N3mes1s. - RT haroon meer: Our new “Agent Provocateur” deploys in minutes, lets you know when agents are running wild, and exploits “credulous clankers”. Rea… by Giuseppe
N3mes1s. - RT msuiche: I could not resist the urge after @craiu told me about the vhdx images. by Giuseppe
N3mes1s. - RT Nicolas Krassas: MikroTrick lab PoC - CVE-2026-67276 (RouterOS SSH public-key auth bypass) https://github.com/dinosn/mikrotrick-poc by Giuseppe
N3mes1s. - RT QED Audit: Re Full writeup, including the exploit and the upstream fix: https://qedaudit.io/blog/brilliantly-simple/ (15/n) by Giuseppe
N3mes1s. - https://labs.itresit.es/2026/09/09/prestashop-trust-issues-reading-the-wrong-end-of-x-forwarded-for/ by Peter Gabaldon.
- Windows: CrossDevice Dangling COM Registration Incomplete Fix EoP https://project-zero.issues.chromium.org/issues/538151139 by Project Zero Bugs.
- TIL: Apple Private Cloud Compute “The root of trust for Private Cloud Compute is our compute node: custom-built server hardware that brings the power … by Sean Metcalf.
- “It’s hard to ignore that, in spite of all of these data protections, anyone wearing a new Apple Watch could be siccing “audio intelligence” on, say… by Sean Metcalf.
- RT spencer: I strongly recommend getting your AD domain to NTLM level 5 as quickly as possible. At least 3 for DCs bare minimum (which is the default)… by Sean Metcalf.
- RT BC Security: Empire 7.0 is live! What’s new: • Full crypto rewrite (AES-GCM, PBKDF2) • Pivots on all agents • Multi-tab terminal & dedicat… by Sean Metcalf.
- RT SwiftOnSecurity: Keep in mind devices like this explicitly allow console access and arbitrary code to do cool professional things with them, you do… by Sean Metcalf.
- RT DirectoryRanger: Building a Detection Foundation, by @Carlos_Perez Part 1 The Single-Source Problem https://trustedsec.com/blog/building-a-detectio… by Sean Metcalf.
- RT Jake: @watchtowrcyber Intel captured real, hands-on-keyboard exploitation of the recent PaperCut NG/MF vulnerabilities, including fully decryp… by SinSinology.
- That companies allow open federation on Teams is the craziest shit I’ve ever heard. We knew this was a stupid idea in Lync. by SwiftOnSecurity.
- RT Andrew Thompson: Re Out of the hundreds of popped organizations, the adversary was only able to get domain admin on 12 victims. Where domain admin … by SwiftOnSecurity.
- NATO allies foil Russian🇷🇺 subsea cable sabotage plot (Old from April 2026, GUGI behind it and new details is caught in 4K.) | By @Reuters ↘ … by SwitHak ().
- RT Harry: New blog post: DLL Sideloading Research & HijackLibs Contributions A look at a real-world case involving vmware-vmx.exe and libcrypto-3… by Wietze.
- RT CCob: Weekend project: I added IAKerb support to Rubeus. My god, this is going to open the floodgates. Phase 2 of Micro… by Rasta Mouse.
- A real Carnival Cruise Line email was serving customers malware https://tuxxin.com/blog/carnival-cclpromos-malvertising by /r/netsec.
- The ultimate guide to hacking APIs in 2026 has been updated https://labs.detectify.com/how-to/how-to-hack-apis-in-2026/ by /r/netsec.
- Beltdown: Escaping the Claude Code Sandbox https://www.accomplish.ai/blog/beltdown-escaping-the-claude-code-sandbox/ by /r/netsec.
- No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite’s dbpage https://gabdevele.dev/posts/sqlite-dbpage-shared-objects-rce/ by /r/netsec.
- Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability https://blog.doyensec.com/2026/09/10/oneplus-session-takeover.html by /r/netsec.
- Apple mach_o Archive Parser Integer Underflow Vulnerability https://blog.securelayer7.net/apple-mach-o-archive-parser-integer-underflow/ by /r/netsec.
- How Piracy Sites Disguise Video as Fonts to Abuse Cloudflare Caching https://saimanish.com/blog/cloudflare-woff2-cache-abuse/ by /r/netsec.
- Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab https://amibeingpwned.com/blog/fortinet-pam-vuln by /r/netsec.
- Binary Ninja now supporting its own MCP server, means I can junk my janky plugin \o/ by Adam Chester.
- RT Joe Grand: For over three years, @LennertWo and I have worked on improving fault injection attacks against STM32F2 and STM32F4 devices to make them… by Alex Plaskett.
- Investigation Scenario Your SIEM alerted on mshta.exe spawning PowerShell, but an overly aggressive analyst reimaged the host before you could in… by Chris Sanders.
- There is no other phishing framework like Reel. Simply amazing work by @two06. Get the tool/info here: https://rtv.two06.co.uk/ by Jason Lang.
- RT Nextron Research : We detected fresh samples related to the ongoing #OceanLotus (APT-C-00 / APT32) campaign. The samples use a custom XOR-ciphe… by Florian Roth.
- RT Haifei Li: Thanks @greglesnewich for the LNK sample. With the initial RTF sample plus the LNK sample, I’ve successful reproduced the full exploit … by Dave Aitel.
- RT OpenAI: We mobilized 250+ people to strengthen our defenses across hundreds of systems. Our latest cyber models helped us find and fix vulnerabilit… by Dave Aitel.
- RT Johann Rehberger: I found a pre-auth integer overflow in SQL Server. Yes, pre-auth Slammer vibes. In practice, the impact is limited to DoS th… by Dave Aitel.
- RT 0x12 Dark Development: Guard Page Neutralization New Medium post. In this one, we are going to look at two very simple ways to bypass or evade Guar… by Arun.
- RT cyber-ipman: NIST published some high level IAM Agentic AI guidance on August 27, they specifically recommend a separate identity with separate cre… by Arun.
- RT Co11ateral: Group Policy for Hackers – Basics We tried to simplify the concept of GPOs and how they work in Active Directory. As you can see, cred… by Arun.
- RT 𝙁 𝙀 𝙇 𝙄 𝙓 𝙈: Our licensing model has changed! Previously, we followed the C2 framework style of licensing per user. We found… by d3d aka dead (dead, мёртв, 死了).
- GLM-5.3-Flash results now on DreadIndex: https://dreadnode.io/research/dreadindex/?model=openrouter%2Fz-ai%2Fglm-5.3 by dreadnode.
- RT Wiz: We built a Cyber Arena to find out how good AI really is at hacking. We tested AI like an attacker would (For science) with over 300 real… by Simone Margaritelli.
- Abdelhamid Naceri: Microsoft has failed to properly patch ShieldBreak CVE-2026-69414 - https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-69414 ShieldCrash demonstrates a full bypass of t by Filip Dragovic.
- Because sometimes you need AES keys from latest Unifying dongles (fixed 12.11) “Fun” fact, you need to plug the dongle to a non AMD/ASMedia USB… by Benjamin Delpy.
- RT ZaufanaTrzeciaStrona @zaufanatrzeciastrona@infosec: To ważne, a wiele firm nie ma o tym pojęcia. by hasherezade.
- RT Check Point Research: Can you detect adversarial prompts with just a quick LLM and an eye for Base64, Morse code, and similar artifacts? We show th… by hasherezade.
- RT Binary Wizards: Re @reconmtl And a deep dive into GhidraSQL: https://www.youtube.com/watch?v=ceSd1-j-hH4 by hasherezade.
- RT Farenain: As promised, here is a thread about the research I’ve done in VMProtect! First, the decompiled version with Binja (@vector35) from the or… by hasherezade.
- RT MatheuZ: Fileless ELF execution via the Linux kernel keyring Stored an ELF in kernel slab memory via the keyring and ran it with a direct jump. The… by hasherezade.
- RT Farenain: I have spent some time improving my tool dragon-tales, and asking @claudeai to help me with an analysis of VMProtect in a small binary pr… by hasherezade.
- RT Patrik Grobshäuser: Re @SLCyberSec Labs Team found a Remote Code Execution in the GoJa Javascript Sandbox that is used by a lot of products includ… by shubs.
- RT etugen.io: Thousands of files in a public directory. Maybe only three are what you’re looking for. Etugen filters out the noise and leaves you wit… by batuu.
- RT B1lal: While our analysis, we came across a Switzerland🇨🇭 based server at 179.43.175.2. We found 41 files on it belonging to a #UAC bypass la… by batuu.
- RT The Vertex Project: When multiple signals line up, an interesting lead can become a high-confidence assessment. Our DPRK IT worker investigation un… by visi stark.
- Read the Bits, Not the Integer: msPKI-Certificate-Name-Flag and the ESC4 ESC1 Chain https://secretmyth.blog/adcs/demystifying-mspki-certificate-n… by Panos Gkatziroulis.
- VBA macro for Outlook Classic - bulk sends a personalized email from an OFT template using a recipient list from Excel. Supports: per-recipient nam… by Panos Gkatziroulis.
- CheckPlz - Scan files for potential threats while leveraging AMSI (Antimalware Scan Interface) and Windows Defender. By isolating malicious content. h… by Panos Gkatziroulis.
- Maybe an AI-Assisted repository, but it has a nice list of 25 threat scenarios. Useful for a red team perspective. I am sharing the article for a refr… by Panos Gkatziroulis.
- Cross-platform syscall-powered implant & C2 direct syscalls (Win) raw syscalls (Linux) HTTPS/DNS/ICMP channels No winapi layer https://git… by Panos Gkatziroulis.
- BEAR-C2 - an adversary simulation and emulation framework built around real-world TTPs inspired by Russian, Chinese, North Korean, and Iranian APT gro… by Panos Gkatziroulis.
- Hacking AI customer service agents https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents by Panos Gkatziroulis.
- RT spencer: This Microsoft Defender for Endpoint ASR rule is really strong: Block executable files from running unless they meet a prevalence, age, or… by Jeff McJunkin.
- RT spencer: I’ve seen a lot of Active Directory environments in the last 5+ years. These are some of the most dangerous issues I recommend reviewing a… by Jeff McJunkin.
- RT Matt Zorich: One of our researchers from DART has been putting together a series on ADCS security, well worth your time to have a read. ADCS can of… by Chihuahua in charge NotMe.
- RT Yarden Shafir: Latest preview build (29661) ships wesp.sys! The long-awaited initiative that should make it easier for EDRs to move capabilities to… by Johnny Shaw.
- RT watchTowr: watchTowr Intel is already observing in-the-wild probes for the latest critical GitLab vulnerability, CVE-2026-85706, which allows attac… by kmkz.
- RT Rıdvan Yağlı: CVE-2026-85046 PoC: https://chromium.googlesource.com/v8/v8/+/e0562d87ad9c17042b581582c99237d798572e67/test/mjsunit/regress/regres… by kmkz.
- RT /r/netsec: SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance https://hunt.io/blo… by kmkz.
- RT Amir Etemadieh: Curiosity got the best of me, so I reverse engineered the latest Plex Media Server security patches and put together PoCs for each … by kmkz.
- RT xvonfers: (CVE-2026-87491)[543557673][wasm][sandbox]OOBW, exploited ITW https://chromium.googlesource.com/v8/v8/+/36079c36283aaf3d0cee0797e46ddc278… by kmkz.
- RT Selâmi Haktan: Araştırmacılar 500 saat ve 70.000 dolar harcayarak gerçeği ortaya çıkardı: LG televizyonlar bekleme (standby) modundayken b… by kmkz.
- RT cr3ghost: Windows kernel 0-day. Ring 0 rootkit. EDR visibility disruption. Post-quantum crypto. Lazarus. This attack chain is ridiculous. CVE-2026-… by kmkz.
- RT Andrew Thompson: Organizations are not helpless against agentic attacks and traditional hardening does have a positive impact on the security postu… by Max.
- RT Mehmet Ergene: Brace yourself for Windows Hello for Business attacks. https://academy.bluraven.io/blog/look-into-borrowing-windows-hello-keys-… by Max.
- The newest Hacktics and Telemetry is live: Meccha Chameleon RCE and Browser Hacking (ft. PinkDraconian)! Get it here: https://www.youtube.com/watch?v=… by Metasploit Project.
- RT Altered Security: One Logic App. Multiple ways to attack. Explore Red Labs and take on 25 FREE hands-on Logic Apps challenges covering workflow abu… by Nikhil Mittal.
- RT @bytecodevm: CVE-2026-20093 is a CVSS 9.8 pre-auth password change on Cisco IMC via configConfMo/aaaUser. Lab notes unpack HUU 4.3.2.250… by nyxgeek.
- RT Justin Bollinger: FYI the tool uses the remote lookup service by default with no warning. So even if you have the tables you might accidentally be … by nyxgeek.
- RT Craig H. Rowland: Another cool addition to fileless hiding on Linux. This one using an interesting kernel keyring vector. @SandflySecurity still se… by nyxgeek.
- RT Sean Metcalf: Domain Controllers typically run Microsoft DNS so this RCE is effectively an Active Directory RCE. Patch ASAP! by nyxgeek.
- RT xiu: From the macOS side: layered persistence so one failed write doesn’t kill the implant. If you only check LaunchAgents you will miss the fallb… by Patrick Wardle.
- Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux - @rouge_cravate https://cravaterouge.com/articles/resetnight… by Swissky.
- Hacking With AI and Hacking AI: Two Sides of the Same Problem | Mohan Krishna (@S1r1u5_ ) @ HackAICon https://www.youtube.com/watch?v=yAOb7ko9ogI by Swissky.
- AI Assisted Vulnerability Research on Embedded Targets - @qkaiser https://quentinkaiser.be/security/2026/07/18/ia-assisted-vuln-research/ by Swissky.
- Process Parameter Poisoning - Max Hirschberger & Ogulcan Ugur https://sensepost.com/blog/2026/process-parameter-poisoning/ by Swissky.
- RT Matt Brown: Today I’m introducing two new open source IoT firmware analysis tools: Moria and Mithril Moria is a firmware extraction tool just like … by Mayuresh 🇮🇳.
- Good work by Cloudflare on PQC in DNSSEC. But the broader lesson here is the extent of the work to deal with practical effects across protocols becaus… by Phil Venables.
- RT John Scott-Railton: Meet CyberGlobes: they conduct mass monitoring help dictators select victims for spyware hacking. LLMs are poised to turboc… by thaddeus e. grugq.
- RT Covert Intel and Operations: Full article: Inside NATO Intelligence: Practitioners’ Perspectives on the Intelligence Cycle https://www.tandfonline… by thaddeus e. grugq.
- RT Kim Zetter: OpenAI, which failed to secure its sandbox and prevent 700 of its agents from hacking Hugging Face, met with electric utilities (while … by thaddeus e. grugq.
- RT Comfortably Smug: Holy shit. Anthropic caught Iran using Claude to target Navy bases, automate dossiers on Americans, and run influence campaigns o… by thaddeus e. grugq.
- RT Dino A. Dai Zovi: ngl, this is blowing my mind: “the craziest part is claude kept telling itself the internet was simulated, despite evidence that … by thaddeus e. grugq.
- RT Jake Halloran: MSS guy who accidentally uploads MSS data to the US because of attempted claude distillation is top 10 funniest things to happen wit… by thaddeus e. grugq.
- RT zhod: I just went through Anthropic’s threat report & woah! This is genuinely the craziest article I’ve read all month. They documented hackers, … by Vincent Yiu.
- RT sam4k: In case you missed it, last week @bynar_io shared my write-up on several FreeRDP bugs I found & chained to get pre-auth RCE via GNOME Remote… by Axel Souchet.
- CFAA be damned! by AndrewMohawk⁽ⁿᵘˡˡ⁾.
- After a remote assistance session, a VPN client sits in your user’s AppData. 14 of its 19 files are genuine and signed. Hash sweep returns the fleet. … by Black Hills Information Security.
- Hacking back is now (partially..) legal for U.S. companies. Our founder John Strand breaks down what Trump’s new memo actually allows and the big ques… by Black Hills Information Security.
- DeepSeek is catching up in cyber benchmarks. The ExploitGym jump is interesting, I wonder if they’ve started to RL on cyber tasks or this is emergent. by Bill Demirkapi.
- Passkey-themed phishing attacks lead to Microsoft 365 data theft https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-t… by BleepingComputer.
- Artifactory flaws chained in attacks deploying backdoor malware https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-de… by BleepingComputer.
- New Android malware encrypts files, steals data, and harasses victims https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-file… by BleepingComputer.
- September Windows Server updates break Remote Desktop Services https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-… by BleepingComputer.
- AI-powered attack exploited PaperCut flaws to hack 395 organizations https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-paperc… by BleepingComputer.
- New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-c… by BleepingComputer.
- Wow, people had a full Chrome 0day chain and they used it to install malicious chrome extensions for persistence? “…[The] loader executable…then i… by Michael Weber.
- FBI cyber leader details bureau’s first unclassified cyber strategy https://federalnewsnetwork.com/cybersecurity/2026/09/fbi-cyber-leader-details-bur… by Nicolas Krassas.
- Astra Just Raised the Bar for AI-Enabled Attacks. Here’s What That Means for Defenders https://arcticwolf.com/resources/blog/astra-raised-the-bar-for… by Nicolas Krassas.
- Hackers abused Claude to extract secrets from 1.8M Android apps https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secret… by Nicolas Krassas.
- Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks https://thehackernews.com/2026/09/anthropic-says-seven-china… by Nicolas Krassas.
- Anthropic finds 4th real-world attack by Claude agent, details models’ ‘biased reasoning’ https://www.scworld.com/news/anthropic-finds-4th-real-wor… by Nicolas Krassas.
- Read the Bits, Not the Integer: msPKI-Certificate-Name-Flag and the ESC4⤍ESC1 Chain https://secretmyth.blog/adcs/demystifying-mspki-certificate-name-… by Nicolas Krassas.
- Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware https://securityaffairs.com/198884/cyber-crime/attackers-exploit-critical-cisco-f… by Nicolas Krassas.
- Check Point Patches Critical VPN Vulnerabilities https://www.securityweek.com/check-point-patches-critical-vpn-vulnerabilities/ by Nicolas Krassas.
- EU’s Cyber Resilience Act starts the 24-hour vulnerability clock https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-2… by Nicolas Krassas.
- GitLab urges users to patch max severity path traversal flaw https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-p… by Nicolas Krassas.
- Ukrainian lawyer’s second career as a Conti coder earns him 4 years behind bars https://www.theregister.com/cyber-crime/2026/09/11/ukrainian-lawyers-s… by Nicolas Krassas.
- This is getting wild. by Dave Kennedy.
- Two recent weird/wild cases related to MSRC. 1. One bug was processed for 5 months, reported on April 2nd, got the only update in early Sep, that… by Haifei Li.
- It’s a pretty deep research on the CVE-2026-21509 0day patches - thanks for sharing! @78_lab https://x.com/78_lab/status/2047530939866353730 by Haifei Li.
- RT freakyclown: Back in the day if you knew a HVT was staying in a particular hotel but not what suite, we’d make implants for the make/model of tv t… by Nick Carr.
- RT stacksmashing: Verifying lawful requests is so difficult: - they don’t sign their emails/requests - they don’t provide a way to verify the reques… by LiveOverflow hextree.io.
- You all have to follow this guy. Him and a few others do really great public science into all the artifacts left over by the rogue OpenAI agents. Whil… by LiveOverflow hextree.io.
- RT jonas wiedermann-möller: Re i found a almost fully functional RL env in some deleted ruby gems. i managed to recover some things and rebuilt parts… by LiveOverflow hextree.io.
- RT Justin: https://lolskills.io just added to https://lolol.farm, along with a few other existing projects by The Haag™.
- CVE-2026-85706 GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read Four distinct alternate triggers of … by Giuseppe
N3mes1s. - RT Pruva: https://www.pruva.dev/reproductions/REPRO-2026-00345 Today we have a frontpage hackernews RCE in forgejo https://news.ycombinator.com/item?i… by Giuseppe
N3mes1s. - RT Marcos Oviedo: Re had a quick look at this. The userspace counterpart is espclient.dll. Kernel hot path is rust-heavy (own arc/nt_types, hashbrown,… by Giuseppe
N3mes1s. - RT Stephen Fewer: New (draft) @metasploit exploit module in the queue for the latest N-able N-central unauth RCE, CVE-2026-86218. Already being exploi… by Giuseppe
N3mes1s. - In @routefifty, James Turgal highlights why recent attacks on water utilities should serve as a wake-up call for strengthening critical infrastructure… by Optiv.
- RT Previdian: Today we’re seeing a huge spike in Magento StyleSmuggler (CVE-2026-75650) exploitation by Peter Gabaldon.
- RT SwiftOnSecurity: We operationalized this. If you make the concessions you need to make this work with exclusions, it goes brrrrrrrr. Don’t be afrai… by Sean Metcalf.
- RT Rudy Ooms: It looks like the Defender engine 4.18.26080.4 is fixing the Compliance issues everyone has been noticing (Defender Race condition with … by SwiftOnSecurity.
- RT The Insider: В Болгарии загорелся склад боеприпасов EMCO. Это второй пожар за два месяца… by SwitHak ().
- RT ANSSI: Vulnérabilité Metabase Le CERT-FR publie une alerte de sécurité ayant connaissance de compromissions de Metabase vulnérables … by SwitHak ().
- RT The Citizen Lab: 1/ A bipartisan group of U.S. lawmakers have called for three Indian companies that have hacked and stolen data from Americans to … by SwitHak ().
- dayum by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- Magento StyleSmuggler RCE: Report Poisoning to Code Execution https://fortbridge.co.uk/research/stylesmuggler-magento-unauthenticated-rce/ by /r/netsec.
- Beltdown2: Escaping the Cursor CLI sandbox https://www.accomplish.ai/blog/beltdown2-escaping-the-cursor-cli-sandbox/ by /r/netsec.
- CSA Zero Trust Microsegmentation Guidance - formalizes topology-defined vs. connection-defined segmentation models https://cloudsecurityalliance.org/a… by /r/netsec.
- Autonomous Systems Emissions Index https://honeylabs.net/asn-index?window=90d&sort=aei&scanners=hide by /r/netsec.
- RT Crackmes.one: I know a lot of people are looking at WESP (Windows Endpoint Security Platform ), I had my AI agent look at it, make it work, and do … by winterknife.
- RT Jonny Johnson: Finally got a POC working. Working on a blog now, hopefully out in a couple of days by Alex Ionescu.
- Locating Flutter’s TLS certificate verifier in a stripped libflutter.so without byte signatures https:// crossfyre.io/publications/blog /finding-flutters-certificate-verifier.
- A few things I’d like journalists to keep in mind before writing about Anthropic’s latest reports. Some of the posts going around make these inciden… by Florian Roth.
- RT Chaofan Shou: I bought a Fable dataset from one of the top Chinese LLM routers yesterday. With just 6TB data, I can take over 7 Chinese/CIS gov ent… by Florian Roth.
- People abusing the Frontier models is only going to provide the justification they need to lock top models down behind KYC and credentialed access. I … by d3d aka dead (dead, мёртв, 死了).
- RT lain: hi, omarchy user-to-root LPE by Simone Margaritelli.
- Burp Hackvertor now has jigsaw mode too! by Gareth Heyes \u2028.
- RT Internet of Shit: lg tvs just literally wiretapping everything you say around them just make a goddamn tv without internet i can use in peace you c… by Gergely Kalman.
- RT Kasif Dekel: AFL fuzzing MapleStory for… successful jump quests afl-fuzz + IJON driving the game client, to automatically solve difficult ma… by h0mbre.
- RT Abhishek: malware is living in .claude/ folders now Google’s new threat report: a stealer dropping malicious configs into folders AI coding ag… by hasherezade.
- RT Kasif Dekel: I found a silly bug in @WhatsApp that let attackers spoof a normal-looking link preview while controlling the URI opened - allowing ar… by hasherezade.
- A revisit of remote Spectre attacks on Cloudflare Workers https:// blog.cloudflare.com/revisiting -spectre-attacks-on-workers.
- RT B1lal: IOC #Russia 🇷🇺 (Global Internet Solutions LLC) - open directory on port 8000 with 21 files exposing a Python-based Telegram C2/RAT pan… by batuu.
- SSHamble - a research tool for SSH implementations that includes: Interesting attacks against authentication Post-session authentication attacks… by Panos Gkatziroulis.
- RT Ruslan Sayfiev: One more to go: adexview - browse, search and audit an AD Explorer snapshot offline, in your browser, from any OS. https://github.c… by Panos Gkatziroulis.
- RT 0x12 Dark Development: You may not know this, but with NtSaveKeyEx you can dump the current state of a Windows Registry hive and load it locally la… by Panos Gkatziroulis.
- askWAM - Requests Microsoft Entra access tokens silently through Windows Web Account Manager (WAM) by @_dirkjan https://github.com/dirkjanm/askWAM by Panos Gkatziroulis.
- There are two additional LOLBins capable of executing code that are part of the .NET ecosystem. dotnet-trace dotnet-counters Discovery by Iv… by Panos Gkatziroulis.
- RT ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs: A practical lab guide for validating Microsoft Defender for Endpoint protections, detections, alerts, and Advanced… by Chihuahua in charge NotMe.
- RT SecurIT360: Our password list is 180GB. With mutation rules that is about 4 quadrillion permutations. We have cracked 20+ character passphrases bui… by Chihuahua in charge NotMe.
- RT FBI Cyber Division: Today, we’re announcing the FBI’s new Cyber Strategy, our roadmap for defending the American people and the nation’s critica… by Chihuahua in charge NotMe.
- this one was very helpful so I created the module, enjoy ! by kmkz.
- RT Ark: JavaScript Sandbox Escape 1. https://github.com/nyariv/SandboxJS/security/advisories/GHSA-w2c7-wq77-2wj7 2. https://github.com/nyariv/SandboxJ… by kmkz.
- RT @bytecodevm: Lazarus spent a Windows kernel zero-day in afd.sys on a fake recruiter PDF. CVE-2026-68820 is a local UAF that skips BYOVD… by kmkz.
- RT Denis Laskov 🇮🇱: Vulns in Android WLAN for Qualcomm and Samsung: attack surface for QCACLD and SCSC. 🆘 More details: Linke… by kmkz.
- RT Ruslan Sayfiev: AD Explorer snapshots without Windows. https://github.com/crypt0p3g/adexsnap adexsnap is a Python CLI that talks LDAP from Linux or… by Max.
- RT Hiroshi Suzuki: pstrings: a parallel strings extractor. - 5.5 GB in 14 s (~278x faster than Sysinternals strings, ~10x faster than bstrings) - ASCI… by Max.
- RT KF: Lol a homie of mine just went H.A.M. on drone GCS software https://github.com/nicholasaleks/infected-drones by nyxgeek.
- Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https:// mobeta.fr/simple-job-board-una uth-rce-cve-2024-1813/.
- How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability https:// lavahq.io/research/bmc-exposur e-alert.
- Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles https:// eaton-works.com/2026/07/27/my- eicher-hack/.
- [CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability https:// karmainsecurity.com/KIS-2026-13.
- Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www. accomplish.ai/blog/sharedroot- escaping-claude-cowork-sandbox/.
- XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search https:// xbow.com/blog/bing-images-rce- vulnerabilities.
- CVE-2026-50458: Finding a UAF in the Windows Brokering File System https:// rotcee.github.io/posts/CVE-202 6-50458-finding-a-UAF-in-windows-brokering-file-system/.
- I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https:// blog.himanshuanand.com/2026/07 /reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/.
- The Hidden CCS2 Attack Surface on EV Chargers https://www. saiflow.com/blog/the-hidden-cc s2-attack-surface-on-ev-chargers.
- Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) https:// davidcarliez.github.io/blog/cv e-2026-49176-walletservice-to-system/.
- Leaking internal headers in Flask Ninja with deserialization https:// eval.blog/research/pickle-gadg et-chain-in-flask-ninja/.
- Crawling the Complete IPv4 Reverse DNS Space https:// ipapi.is/blog/crawling-the-com plete-ipv4-reverse-dns-space.html.
- Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https:// blog.paradoxis.nl/escalating-a ll-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492.
- Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https:// slcyber.io/research-center/exp loit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/.
- Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable https:// neurowinter.com/security/2026/ 07/16/forging-the-government-lottery/.
- wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner https:// fullhunt.io/blog/2026/07/17/wp 2shell-wordpress-core-pre-auth-rce-cve-2026-63030.html.
- $15k - CSPT to full account takeover, then 2FA bypass via the prototype chain - @whoareme33 https://whoareme.com/blog/cspt-account-takeover-2fa-bypass… by Swissky.
- RT jonas wiedermann-möller: I did read the openai incident report again and found some inconsistency with my own research. They mention that the firs… by Swissky.
- RT International Cyber Digest: Nightmare Eclipse, the person who has been dropping Windows zero-days, has finally decided to share his story. He’s an … by Mayuresh 🇮🇳.
- If you’ve seen EchelonGraphBot in your logs, here’s exactly what it does and how to block it http:// echelongraph.io/radar.
- RT Mike Bradley: Just as a reminder because it’s easy to get lost in the rhetoric nowadays. The Hugging Face attack required approximately seven hund… by scriptjunkie (Matt).
- RT Jurre van Bergen: FWIW, this is not just an Omarchy problem, it’s a wider Linux desktop problem. I used two kernel bugs one n-day one 0day to achie… by scriptjunkie (Matt).
- RT MG193_7: Guys, I built a super fast Android decompiler called ASC. It completely replaced Jadx MCP for me and lets me analyze 10+ APKs in parallel…. by ϻг_ϻε.
- RT Zach Dorfman: Biggest internal organizational shake-up at NSA in a least a decade set to launch. NEW from @wstrobel @noahjrobertson and me: https:/… by thaddeus e. grugq.
- RT Spy Collection: #SpyNews - week 37 (September 6-12): A summary of 63 espionage-related stories from week 37 coming from 🇧🇪🇨🇳🇷🇺�… by thaddeus e. grugq.
- RT Henry Gao: What are China’s biggest concerns about AI? A new article by Chen Yixin, China’s Minister of State Security, in the latest issue of Ch… by thaddeus e. grugq.
- RT b33f | 🇺🇦: I wanted to understand this ruby issue in a bit more detail. Here is what actually happened. The AI posts a gem to RubyGems cont… by thaddeus e. grugq.
- RT Dr. Dan Lomas: Revealed: Known Russian spy was behind Leipzig drone attack https://www.telegraph.co.uk/world-news/2026/09/12/revealed-known-russian… by thaddeus e. grugq.
- RT Nick Frichette: AWS: Look at this fun new feature! Offsec: sick, new exfil technique! AWS: What? by thaddeus e. grugq.
- > be me > get dm > “smelly i found goop” > wtf i love goop (malware) > sends like to GitHub > download > look inside .zip > instantly, at the blink of… by vx-underground.
Tools and Exploits
Important security release for Tor Browser and related onion services. Operators and users should update immediately.
EntraOps 1.0 released as an open-source platform to govern and monitor your Enterprise Access Model in Microsoft Entra. Best way to find what is wrong in your cloud identity control plane.
Critical remote code execution vulnerability in Forgejo versions 16.0.3 and below. Update to 16.0.4 immediately.
FalconForce open-sources FalconDash, a modular dashboard for making Microsoft Sentinel detection performance visible, explorable, and easier to tune.
- Evilginx Chrome Extension 1.0 by Kuba Gretzky.
Evilginx Chrome extension enters review. Inspect cookies, local/session storage, monitor Set-Cookie headers, freeze cookies for auth testing, and kickstart phishlet development.
Pywintrace-based consumer for Microsoft-Windows-Kernel-Audit-API-Calls ETW provider. Captures call stacks for SetThreadContext calls not available via ETW-TI.
- DeepSeek v4.1 Flash Finds Handlebars.js 0-Day RCE for $0.05 by Jeff McJunkin.
DeepSeek v4.1 Flash found a 0-day RCE in handlebars.js v4.7.9 in minutes for $0.05. Consistently reproduces where the larger v4-pro model needed multiple runs.
A 7-person team fine-tuned three Qwen models to rank first among open models at their size classes on cybersecurity benchmarks, averaging +23.76% improvement on the CyberGym suite.
Nebula Security brings 22 recent Linux kernel CVEs with working exploits to the oss-security mailing list for community attention.
PassTheCert-rs gains shadow credentials attack support. Write msDS-KeyCredentialLink to get NT hashes and TGTs. Also adds RustHound-CE shortcut for full domain dumps from a certificate.
More this week (3)
- RT Microsoft Exchange: Released: September 2026 Exchange Server Security Updates https://techcommunity.microsoft.com/blog/Exchange/released-september-… by DebugPrivilege.
- RT Enclave: DeepSeek V4.1 Flash completed all 11 vulnerable runs in our AI Hacking Race. Each success required real command execution and a fresh valu… by Yanir Tsarimi.
- RT Sam Thomas: I’m pleased to announce a new release of the #idalib #Rust bindings for @HexRaysSA IDA Pro! This release provides new APIs and bug fixe… by raptor.
