A roundup of 483 items curated from across the security community.

News

Hunt.io documents an AI agent attack targeting Thailand’s Ministry of Finance with Hermes running approval prompts disabled.

Sophos discovers a new Cyclops Blink variant on compromised Cisco FMC devices. Extended capabilities beyond the original malware analyzed by UK NCSC.

Public PoC released for OmniRoute CVSS 9.5 RCE vulnerability.

The Revolut hacker claims to have also compromised multiple Italian law enforcement departments, holding 147 GB of internal documents including officer chat logs.

Endpoint Security arrives in the iPhone kernelcache as a kext in iOS 27.2 beta, with libEndpointSecurity.dylib and process execution denial capabilities.

Investigation reveals the Revolut hacker used infostealer-compromised government emails to send fake European Investigation Orders for six months. Revolut never questioned the requests.

Escape from Docker’s hypervisor on Mac affects Docker Desktop and Docker Sandboxes. Full writeup with exploitation details.

ShinyHunters compromises Clop’s leak site and threatens to extort the ransomware gang with their own data.

Calif’s Apple Internals series examines the new Endpoint Security framework appearing in iOS, analyzing what it means for mobile security tools.

First preview article from the upcoming Phrack 73, written by Mikko. Available as a PDF from the Phrack archives.

More this week (23)

Techniques and Write-ups

Check Point Research shows how Defender’s signed BTR.sys driver can be loaded with crafted ADS configs to kill EDR and gain kernel persistence without any vulnerability or BYOVD.

AI-assisted reverse engineering of the full WESP stack (wesp.sys, espclient.dll, wesp_elam.sys) with wire protocols, disposition tables, and esptool research harness with 118 XML rule docs.

Zhiniang Peng’s OffByOne keynote on a year of using LLMs for vulnerability research and exploitation.

CISA publishes guidance on deploying cyber decoys and honeypots to strengthen detection and response capabilities.

Exploiting Logi Options+ peripheral software to achieve SYSTEM-level shells on Windows.

New DCOM lateral movement technique presented at MCTTP conference by Shebin Mathew.

Matt Nelson (enigma0x3) releases a bypass for Constrained Language Mode in App Control for Business environments. Reported to Microsoft, closed as by design.

Vulnerability chain exploiting HEIF image processing. Affects OpenAI (Slack, HuggingFace), Meta, GitHub Enterprise, Rails, and Next.js.

DirtyAH6, PPPoEject, TUNderflow, and DiagSpill. Four Linux local root vulns that have been around for 10 to 21 years. DirtyAH6 is theoretically remote-groomable.

Halvar Flake’s first BlueHat talk since the Vista days. Slides from Microsoft BlueHat Singapore on the current age of security experimentation.

More this week (412)

Tools and Exploits

Chrome extension for Evilginx with cookie monitoring, local/session storage inspection, Cookie Freeze testing, DBSC header blocking, and phishlet development tools.

Apple releases macOS Golden Gate alongside security updates for Tahoe 26.7 and Sequoia 15.8.

Scans AWS, Azure, and GCP for actual attack chains to crown jewels and leaked credentials. Graphed multi-hop attack surface using the RAGE standard.

Process Monitor for macOS rewritten by Patrick Wardle. Open source with CLI, JSON export, on-device AI assistant, code signing verification, and VirusTotal integration.

Rust BloodHound collector reaches 84% attribute compatibility with SharpHound v2.16.0.0. Roadmap targets 90% with remote registry and SMB access.

zsh modules on macOS can establish TCP connections, manipulate files, and access extended attributes without spawning child processes. Detection analysis using Apple Endpoint Security telemetry.

Exfiltrates data by resolving well-known domains that map to characters instead of encoding data in subdomains. The data is the domain that was queried.

One-pass anonymous Active Directory enumeration over SAMR and LSARPC. No credentials required.

Sends NTLM Type-1 negotiate messages across multiple transports, decodes Type-2 challenges, and extracts internal NetBIOS/DNS names, AD forest, OS build, and clock skew.

Major Havoc C2 release with Kaine user-defined C2, expanded Linux post-exploitation, SNI spoofing, in-memory PE execution, BOF-PE support, and a full client UI overhaul.

More this week (18)