A roundup of 388 items curated from across the security community.

News

Trezor hardware wallet breach via email provider Brevo now confirmed to affect 81,000 customers, up from initial estimates.

Gamers Nexus testing reveals LG Smart TVs scan local networks, identify content, and record audio even in standby mode with no internet connection. WebOS flaws could enable RCE.

Logical bug in MariaDB allows any user, regardless of privileges, to update the password of any other user including root.

Microsoft patches a record 972 vulnerabilities with 112 critical-severity. AI-assisted vulnerability discovery continues to drive unprecedented patch volumes.

Joint NSA/FBI/CISA advisory details how China-based AI companies illicitly distill US frontier AI capabilities, with TTPs and recommended mitigations.

Volexity tracks multiple Chinese APTs chaining Chrome and Windows 0-days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to deliver GRIMWEDGE and a fake Gemini extension.

Terry Liu, a Chinese national, was caught on camera replacing processors and memory devices in Customs and Border Patrol computers at the Maine-Canada border before re-inserting them.

The New York Times covers the WeWorm AI-powered zero-click worm that spread through WeChat phone calls. Calif publishes a defensive to-do list for collective defense.

Anthropic publishes its September threat report covering APT misuse of Claude, including Russian threat actors, Chinese distillation operations, and Iranian targeting of naval installations.

Schneier analyzes the record-breaking patch volumes driven by AI vulnerability discovery and warns that AI is also accelerating exploit development from published patches.

More this week (37)

Techniques and Write-ups

Calif’s WeWorm research on AI-powered zero-click worm propagation was the most shared security link of the week with 28 mentions. Full research writeup on the autonomous attack chain.

MSNightmare demonstrates a full bypass of Microsoft’s ShieldBreak patch (CVE-2026-69414). Works on the latest September 2026 update. Also bypasses the earlier RoguePlanet fix.

REcon 2026 talk on using AI agents to break protections in anti-cheats, DRM systems, and commercial protectors. Includes the corresponding tool for multi-binary appliance analysis.

SpecterOps details how SCCM application execution generates different artifacts than script-based execution, evading existing detection tools. Covers the stealthier execution flow and how to detect it.

Out-of-bounds vulnerability in Goja, the Go JavaScript engine, chains to a full sandbox escape and remote code execution.

Purple team playbook on abusing Windows Security Center APIs to disable Defender, with detailed detection strategies for each technique.

Full compromise of Paxton10 access control systems. Covers the attack chain from network access to physical door control.

TrustedSec walks through AWS credential types, where to find them, and how to validate and use them during a security engagement. Part 1 of an ongoing series.

First look inside Microsoft’s new Windows Endpoint Security Platform. Reverse engineering of wesp.sys and espclient.dll, with a working consumer PoC published on GitHub.

Project Zero releases MAccConc, a tool for deterministic testing of race conditions on Linux. Enables reproducible fuzzing, regression tests, and ad-hoc exploration of concurrent code.

More this week (318)

Tools and Exploits

Important security release for Tor Browser and related onion services. Operators and users should update immediately.

EntraOps 1.0 released as an open-source platform to govern and monitor your Enterprise Access Model in Microsoft Entra. Best way to find what is wrong in your cloud identity control plane.

Critical remote code execution vulnerability in Forgejo versions 16.0.3 and below. Update to 16.0.4 immediately.

FalconForce open-sources FalconDash, a modular dashboard for making Microsoft Sentinel detection performance visible, explorable, and easier to tune.

Evilginx Chrome extension enters review. Inspect cookies, local/session storage, monitor Set-Cookie headers, freeze cookies for auth testing, and kickstart phishlet development.

Pywintrace-based consumer for Microsoft-Windows-Kernel-Audit-API-Calls ETW provider. Captures call stacks for SetThreadContext calls not available via ETW-TI.

DeepSeek v4.1 Flash found a 0-day RCE in handlebars.js v4.7.9 in minutes for $0.05. Consistently reproduces where the larger v4-pro model needed multiple runs.

A 7-person team fine-tuned three Qwen models to rank first among open models at their size classes on cybersecurity benchmarks, averaging +23.76% improvement on the CyberGym suite.

Nebula Security brings 22 recent Linux kernel CVEs with working exploits to the oss-security mailing list for community attention.

PassTheCert-rs gains shadow credentials attack support. Write msDS-KeyCredentialLink to get NT hashes and TGTs. Also adds RustHound-CE shortcut for full domain dumps from a certificate.

More this week (3)