A roundup of 483 items curated from across the security community.
News
Hunt.io documents an AI agent attack targeting Thailand’s Ministry of Finance with Hermes running approval prompts disabled.
Sophos discovers a new Cyclops Blink variant on compromised Cisco FMC devices. Extended capabilities beyond the original malware analyzed by UK NCSC.
Public PoC released for OmniRoute CVSS 9.5 RCE vulnerability.
- Revolut Hacker Also Compromised Italian Law Enforcement by thaddeus e. grugq.
The Revolut hacker claims to have also compromised multiple Italian law enforcement departments, holding 147 GB of internal documents including officer chat logs.
Endpoint Security arrives in the iPhone kernelcache as a kext in iOS 27.2 beta, with libEndpointSecurity.dylib and process execution denial capabilities.
- Revolut Hacker Used Stolen Gov Emails for 6 Months by thaddeus e. grugq.
Investigation reveals the Revolut hacker used infostealer-compromised government emails to send fake European Investigation Orders for six months. Revolut never questioned the requests.
Escape from Docker’s hypervisor on Mac affects Docker Desktop and Docker Sandboxes. Full writeup with exploitation details.
ShinyHunters compromises Clop’s leak site and threatens to extort the ransomware gang with their own data.
Calif’s Apple Internals series examines the new Endpoint Security framework appearing in iOS, analyzing what it means for mobile security tools.
First preview article from the upcoming Phrack 73, written by Mikko. Available as a PDF from the Phrack archives.
More this week (23)
- Revolut discloses data breach exposing financial info, passports https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing… by BleepingComputer.
- Using AI for Weapons Development by Bruce Schneier.
- Germany Prosecutor filed charges for espionage activities (to Russian 🇷🇺 benefits) against Ilona W. (Both 🇩🇪&🇺🇦 national) which soug… by SwitHak ().
- On the NSA’s Supercomputer from the 1960s by Bruce Schneier.
- The English version https://winslow1984.com/books/threat-intelligence/page/hey-you-hacked-a-hacker-are-you-ready-for-my-revenge by Winslow.
- Suspected Black Axe gang leaders face cybercrime charges in the US https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to… by BleepingComputer.
- Revolut Data Leak May Trace Back to Compromised Italian Government Accounts https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace… by Nicolas Krassas.
- Pixel Modem Zero-Day Exploited in Targeted Attacks https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks/ by Nicolas Krassas.
- RT Enno Rey: Recent AI security related posts on @Insinuator: https://insinuator.net/2026/06/vulnerability-disclosure-stealing-emails-via-firefoxs-ai-… by DirectoryRanger.
- RT Tal Hoffman: Well, this went viral on Hacker News… In a new post, @Yanir_ shares more details about what we observed when testing DeepSeek V4.1 F… by Yanir Tsarimi.
- The Hacker’s Guide to Attacking AI Agents https://darkmarc.substack.com/p/the-hackers-guide-to-attacking-ai by /r/netsec.
- RT clem : As the first publicly disclosed agent cyberattack victim, we’ve had a front-row seat to this new risk. I formalized my thinking about it… by Alex Plaskett.
- RT Dark Web Intelligence: SPAIN REPORTS ITS FIRST DATA BREACH ALLEGEDLY EXECUTED BY AN AI AGENT Spain’s Data Protection Agency (AEPD) has disclos… by Simone Margaritelli.
- RT Ryx: Public PoC for the Exchange pre-auth chain (CVE-2026-62911 / related) is circulating. Orange Tsai demonstrated the full path at Pwn2Own Berlin… by kmkz.
- Hacker? Signals are your friends by Patrick Wardle.
- RT SpecterOps: Introducing CiliumHound, a new BloodHound OpenGraph extension from @Sw4mp_f0x! Feed it your Cilium network policies (YAML/JSON), get ba… by Chihuahua in charge NotMe.
- RT BallisKit: Need to red team macOS targets but don’t know where to start? Introducing Mirage C2 ! Our new modular, in-memory macOS implant for D… by Chihuahua in charge NotMe.
- https://iTorrents.org Compromised To Spread Windows Malware, Kaspersky Says https://www.pcmag.com/news/itorrentsorg-compromised-to-spread-windows-malw… by Nicolas Krassas.
- Zelle and Apple Gift Cards are used for laundering cybercrime proceeds, India’s call centre raid reveals https://ministryofcyberaffairs.com/news/zelle… by Nicolas Krassas.
- RT Init1Security: Introducing ACLPWN a BOF for abusing ACL permissions in Active Directory. GenericAll GenericWrite WriteDACL WriteOwner ExtendedRight… by DirectoryRanger.
- RT s1r1us: btw, this is exactly why the openai disclosure felt threatening to us. when a ciso starts the conversation angry, of course researchers pan… by LiveOverflow hextree.io.
- CISO reached out and apologized we are good. Also wanted to say that this thread was not part of the disclosure plan, and it was just my personal… by LiveOverflow hextree.io.
- RT s1r1us: you’re all riling up over the $6,500. that wasn’t even an issue for us. the disclosure process itself was nightmarish, we had to get inpu… by blasty.
Techniques and Write-ups
Check Point Research shows how Defender’s signed BTR.sys driver can be loaded with crafted ADS configs to kill EDR and gain kernel persistence without any vulnerability or BYOVD.
AI-assisted reverse engineering of the full WESP stack (wesp.sys, espclient.dll, wesp_elam.sys) with wire protocols, disposition tables, and esptool research harness with 118 XML rule docs.
Zhiniang Peng’s OffByOne keynote on a year of using LLMs for vulnerability research and exploitation.
CISA publishes guidance on deploying cyber decoys and honeypots to strengthen detection and response capabilities.
Exploiting Logi Options+ peripheral software to achieve SYSTEM-level shells on Windows.
- New DCOM Lateral Movement Technique Released at MCTTP by S3cur3Th1sSh1t.
New DCOM lateral movement technique presented at MCTTP conference by Shebin Mathew.
Matt Nelson (enigma0x3) releases a bypass for Constrained Language Mode in App Control for Business environments. Reported to Microsoft, closed as by design.
Vulnerability chain exploiting HEIF image processing. Affects OpenAI (Slack, HuggingFace), Meta, GitHub Enterprise, Rails, and Next.js.
DirtyAH6, PPPoEject, TUNderflow, and DiagSpill. Four Linux local root vulns that have been around for 10 to 21 years. DirtyAH6 is theoretically remote-groomable.
Halvar Flake’s first BlueHat talk since the Vista days. Slides from Microsoft BlueHat Singapore on the current age of security experimentation.
More this week (412)
- Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. https… by BleepingComputer.
- Hackers exploit Tencent app flaw to deploy GrayRabbit malware https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deplo… by BleepingComputer.
- Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn… by BleepingComputer.
- Excellent work, highly recommended ! by Dimitri Os.
- Nintendo warns of Switch code execution flaw via on-screen QR codes https://cyberinsider.com/nintendo-warns-of-switch-code-execution-flaw-via-on-scree… by Nicolas Krassas.
- Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution https://www.securityweek.com/chinese-hackers-exploit-critical-tenc… by Nicolas Krassas.
- CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversa… by Nicolas Krassas.
- The Harness Matters: Cutting AI Reverse-Engineering Tokens by 33% https://reverser.space/blog/the-harness-matters-ai-reverse-engineering/ by Nicolas Krassas.
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users https://thehackernews.com/2026/09/malicious-twitch-browser-extension.ht… by Nicolas Krassas.
- https://UK.gov begins killing off passwords for 23 million users https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-fo… by Nicolas Krassas.
- A Mythic C2 Profile that uses the Microsoft Graph API to communicate through a Microsoft Teams channel https://github.com/Whispergate/msteams by Nicolas Krassas.
- Telus Warns Customers of Account Breaches https://www.securityweek.com/telus-warns-customers-of-account-breaches/ by Nicolas Krassas.
- Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust. https://github.com/DeathShotXD/0xM0n… by Nicolas Krassas.
- Charming Kitten APT Adversary Simulation https://medium.com/@S3N4T0R/charming-kitten-apt-adversary-simulation-fa6257b42811 by Nicolas Krassas.
- StealC Stealer – RuntimeBroker Hollowing, C2 Extraction & Payload Extraction https://github.com/kaandemir993/StealC-Stealer-RuntimeBroker-Hollowing-C… by Nicolas Krassas.
- CISA: Hackers now exploit max severity GitLab flaw in attacks https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-git… by Nicolas Krassas.
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data https://thehackernews.com/2026/09/attackers-use-passkey-phishing… by Nicolas Krassas.
- Microsoft Defender XDR Attack Disruption: Automatic Device Isolation Explained, by @JeffreyAppel7 https://jeffreyappel.nl/microsoft-defender-xdr-attac… by DirectoryRanger.
- Windows Registry Forensics: The Registry as Narrative #DFIR https://sethenoka.com/registry-as-narrative/ by DirectoryRanger.
- When the fuzzers come knocking on port 389: Hunting injection canaries in LDAP #DFIR https://corelight.com/blog/ldap-fuzzers-injection-canaries by DirectoryRanger.
- Blueprint Inheritance Abuse in Entra Agent ID https://cyberdom.blog/blueprint-inheritance-abuse-in-entra-agent-id/ by DirectoryRanger.
- Living Off the Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure https://www.ontinue.com/resource/python-implant-hiding-its-en… by DirectoryRanger.
- DFIR4vSphere. PowerShell module collects logs and forensics artefacts on both ESXi hosts and the vCenter console, by https://github.com/ANSSI-FR/DFIR4… by DirectoryRanger.
- RT 0x12 Dark Development: You may not know this, but with NtSaveKeyEx you can dump the current state of a Windows Registry hive and load it locally la… by DirectoryRanger.
- RT Ru Campbell: New video: deep dive into Entra passkey registration campaigns before Microsoft’s SMS/voice MFA changes start pushing more users throu… by DirectoryRanger.
- RT Ruslan Sayfiev: AD Explorer snapshots without Windows. https://github.com/crypt0p3g/adexsnap adexsnap is a Python CLI that talks LDAP from Linux or… by DirectoryRanger.
- RT SpecterOps: Why does SCCM app execution spawn from WmiPrvSE.exe instead of CcmExec.exe? @Praga_Prag traced the full chain with ProcMon + Ghidra, fr… by DirectoryRanger.
- RT SEKTOR7 Institute: Deep dive into Windows kernel pool internals for exploitation and analysis. A post by @r0keb Source: https://r0keb.github.io/pos… by DirectoryRanger.
- RT DirectoryRanger: Token Theft in Microsoft Entra ID, by @insinuator Part 1: Threat Landscape and Attack Techniques https://insinuator.net/2026/08/to… by DirectoryRanger.
- Spent the morning checking Microsoft’s patches for my Office bugs that were patched in this Patch Tuesday. After applying the patches, my PoC for the … by Haifei Li.
- Same. I see vulnerabilities, and the sandbox architecture for that matter, as mistakes by some engineer, and they are probably a really cool person. A… by LiveOverflow hextree.io.
- RT Pruva: Unauthenticated raw HTTP paths containing %5f, simple-action JSON selecting _users, recovered root credential, and authenticated task JSON w… by Giuseppe
N3mes1s. - Microsoft today released an out of band update that includes a security update to a vulnerability they first patched in August. I guess the first patch didn’t work broadly enough or introduced more fl.
- RT Paula Januszkiewicz: Microsoft Entra ID can look completely locked down and still let you in through an Xbox. We started with a standard low-privil… by Sean Metcalf.
- RT Nathan McNulty: Can someone explain to me how users will ignore all communications from IT but be like “yeah sure attacker, let me figure out how t… by Sean Metcalf.
- RT Martin Bengtsson: 1/ Your Conditional Access policies aren’t protected by Conditional Access. Unless you turn this on. There’s a feature calle… by Sean Metcalf.
- RT Swissky: Exploiting AD ResetNightmare (CVE-2026-27912) and KerberLoss (CVE-2026-25177) from Linux - @rouge_cravate https://cravaterouge.com/article… by Sean Metcalf.
- RT Ayush Anand: BlackFile shut down in May. The crew is still in play as Redact, Pink, Helix and Falcon. Helpdesk call to your personal phone, then a … by SwiftOnSecurity.
- RT stacksmashing: Verifying lawful requests is so difficult: - they don’t sign their emails/requests - they don’t provide a way to verify the reques… by SwitHak ().
- do i even have to say anything at this point? its all bullshit by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- RT unusual_whales: BREAKING: OpenAI has hired an army of contractors who read real ChatGPT users’ chats, per 404Media by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- Someone in cyber security had to address Dario Amodei’s headline persistent internet botnet AI fears in “We Must Pace the Frontier”. So here’s why even frontier artificial superintelligence with recur.
- RT International Cyber Digest: Nightmare Eclipse, the person who has been dropping Windows zero-days, has finally decided to share his story. He’s an … by Rasta Mouse.
- RT Mike McQuaid: Today, I’m proud to announce Homebrew 7.0.0. The most significant changes since 6.0.0 are faster installations, stronger sandboxing,… by Wojciech Reguła.
- Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents https://deturris.io/posts/n8n-ai-agents-authorization-bypasses/ by /r/netsec.
- IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR https://blog.silentsignal.eu/2026/09/14/IBM-Db2-Mirror-for-i-pre-auth-RCE-and-the-road-to-Q… by /r/netsec.
- A revisit of remote Spectre attacks on Cloudflare Workers https://blog.cloudflare.com/revisiting-spectre-attacks-on-workers by /r/netsec.
- How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability https://lavahq.io/research/bmc-exposure-alert by /r/netsec.
- Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles https://eaton-works.com/2026/07/27/my-eicher-hack/ by /r/netsec.
- [CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability https://karmainsecurity.com/KIS-2026-13 by /r/netsec.
- Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 https://www.accomplish.ai/blog/sharedroot-escaping-claude-cowork-sandbox/ by /r/netsec.
- XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search https://xbow.com/blog/bing-images-rce-vulnerabilities by /r/netsec.
- GitHub issues $100,000 bounty for critical RCE vulnerability https://runtimewire.com/article/github-issues-100-000-bounty-for-critical-rce-vulnerabili… by /r/netsec.
- CVE-2026-50458: Finding a UAF in the Windows Brokering File System https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-fi… by /r/netsec.
- I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-w… by /r/netsec.
- The Hidden CCS2 Attack Surface on EV Chargers https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers by /r/netsec.
- Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/ by /r/netsec.
- Leaking internal headers in Flask Ninja with deserialization https://eval.blog/research/pickle-gadget-chain-in-flask-ninja/ by /r/netsec.
- Crawling the Complete IPv4 Reverse DNS Space https://ipapi.is/blog/crawling-the-complete-ipv4-reverse-dns-space.html by /r/netsec.
- RT Off-By-One Conference: THE ROOM WAS ELECTRIC! “I Let A.I. Loose on Google. It Found RCE. Twice.” by @brutecat had everyone completely locked… by skull.
- RT Bernardo Quintero: https://ai.virustotal.com by Florian Roth.
- RT Eyal Sela: You can detect some AI-enabled attacks by searching for explicit indications of penetration testing. This happens because threat actors … by Florian Roth.
- RT /r/netsec: Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 https://slcyber.io/research-center/exploit-b… by Dave Aitel.
- RT Iron Hulk : It took me a while to reverse-engineer Havoc’s C2 and really understand what was happening under the hood I ended up building my o… by Arun.
- RT Matthew Green: Hey Anthropic! I reported these encryption issues to you in May and you told me there was no relevance because replay attacks were n… by Dan Guido.
- 25 Years of Mass Surveillance Is Enough by Bruce Schneier.
- 1Password’s AI patching benchmark is misleading.
- RT Justin Elze: Kevins been cleaning up a lot of BOFs lately and added a bad_alloc_tracking branch to COFFLoader that helps catch memory leaks, corrup… by freefirex.
- RT Alex Neff: ItsNotAlwaysSMB: DPAPI in other protocols SMB is monitored closely nowadays, stopping attacks like looting DPAPI secrets. Thanks to … by Will Schroeder.
- RT Md Ismail Šojal : Claude just got a red-team playbook. Claude-Red just dropped a full pentest skill pack for Claude : - 78 SKILL.md files…. by hasherezade.
- RT Ido Veltzman: I’m thrilled to make Silverseal public!. It is among the first publicly available UEFI bootkit research frameworks for Linux-based sy… by hasherezade.
- RT etugen.io: APT-C-55 CC: JaffaCakes118 https://www.virustotal.com/gui/user/JaffaCakes118/ Platform: https://app.etugen.io/threats/217.60.36.94:22 ht… by batuu.
- ReflectivePluginLoader - A minimal PE mapper that loads DLLs straight from memory and calls into a clean plugin interface, no LoadLibrary needed https… by Panos Gkatziroulis.
- The technique abstract outlines the data sources necessary for detecting the technique. by Panos Gkatziroulis.
- The last few days, I’ve been digging into MITRE ATT&CK sub‑technique T1059.007. Mapping all procedures tied to this sub‑technique is challenging du… by Panos Gkatziroulis.
- EvidenceForge - Generate realistic synthetic security logs for cybersecurity threat hunting training and research https://github.com/Cisco-Talos/Evide… by Panos Gkatziroulis.
- RingKiller - BYOD PoC for vulnerable driver DCRCVDrv.sys. Abuses IOCTL 0x2205C0 to kill arbitrary processes from ring 0 via ZwTerminateProcess. EDR/AV… by Panos Gkatziroulis.
- 0xM0nCrush - A cross-version Windows process terminator. It loads a signed HONOR kernel driver (MonProcessEX.sys), resolves the PID of every target pr… by Panos Gkatziroulis.
- Beyond Tier Zero by Redstamp.
- Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution https:// rhinosecuritylabs.com/research /multiple-vulnerabilities-in-frappe-lms-leading-to-remote-code-execution/.
- RT 0xor0ne: QNAP devices CGI handlers exploitation (CVE-2026-34007, CVE-2026-34008) https://runiclabs.io/research/qnap-architecture/ #infosec by kmkz.
- RT Zero Day Engineering: 0-Day Alert: Chrome v8 RCE CVE-2026-87491: WasmGetOwnProperty builtin may invoke a getter from user’s JavaScript, leadin… by kmkz.
- RT 0xor0ne: 0-click exploit chain targeting Pixel 9, from RCE in mediacodec to kernel LPE (@natashenka and @__sethJenkins) Part 1: https://projectzero… by kmkz.
- Race Condition on Runtime Diagnostic Files in #Yealink SIP‑T33G + Yealink IP Phone Directory Traversal Vulnerability = High-privs arbitrary file-dele… by kmkz.
- Again, public issues/feature requests & behaviours that are not classified as vulnerabilities can still provide very juicy attack primitives to someon… by kmkz.
- RT SEKTOR7 Institute: Carefully crafted LDAP tactics to stay under the AD detection radar. A post by Baptiste Crépin. Source: https://cravaterouge.co… by Spiros Fraganastasis.
- RT Agapios Tsolakis: BLOG ALERT The #DetectionEngineering maintenance series continues! As a detection engineer, the real challenge is keepi… by Spiros Fraganastasis.
- At least here they are doing it clearly/visibly/etc… But how many people noticed/knows about what shady shit these fucking clowns did on VT, at leas… by MalwareHunterTeam.
- Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit https://www. acronis.com/en/tru/posts/red-h eron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-.
- RT Stephan Berger: My new “field note” shows how a seemingly generic Microsoft Defender alert can lead to a much more useful forensic finding when cor… by Max.
- RT John Hammond: I yapped about this in a video without techno trance music. Also shrunk down the proof of concept to PowerShell. clicky clicky ——… by Kuba Gretzky.
- RT : For fun I half ported this to Powershell. Not pure PS! Script uses dotnet publish to compile C# into .wam-bin dir. This is not an improvement… by Nikhil Mittal.
- RT Justin Elze: Yep we have been talking about this for a while now :) “Not only can skilled human attackers move at machine speed, but they can also … by nyxgeek.
- And protection will only improve when Apple makes the
es_event_paste_tEndpoint Security event available to 3rd-party security tools!! #Sha… by Patrick Wardle. - SQL Injection - Bypassing Baffin Bay WAF to Exploit PostgreSQL ORDER BY Injection - @p3n7a90n https://p3n7a90n.github.io/blogs/sql-injection-waf-bypas… by Swissky.
- Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities - @wupco1996 https://depthfirst.com/research/going-depthfirst-ac… by Swissky.
- RT bet3rd: BREAKING: A Steam vulnerability (0-Day) on Windows lets any normal user silently escalate to full SYSTEM privileges ‼ Showcase attach… by Rémi GASCOU (Podalirius).
- RT V12: Default configuration of WKWebView can cause downloaded files to instead be rendered on the host page. This allows HTML injection, and sometim… by Rick de Jager.
- Houses is cool thing i’ve recently been working on, it’s a 135 tasks In-band RL environment for glibc heap-exploitation. the fun part is the “in-band”… by ruikai.
- As requested, I added a comprehensive appendix of IOC and investigation pivots for both Chinese and English version of the write-up. by Winslow.
- RT Lizzie Dearden: Exclusive: Russian agents are “hijacking” online networks of violence-obsessed children and offering them money, guns and coachin… by thaddeus e. grugq.
- RT haroon meer: Just chatted to @riskybusiness about getting agents to tell on themselves. https://blog.thinkst.com/2026/09/getting-agents-to-tell-on-… by thaddeus e. grugq.
- oh wait… its @eric_capuano! how cool.. great read on the GitLab vuln. by Mike Felch (Stay Ready).
- Securing the unpatchable in an age of AI-driven vulnerabilities by Martin Lee.
- RT clibm079: An index of public APT reports, 2018–2026. https://www.wokb.cz/Blog/apt_blog.html by Sudheer Varma.
- AI agents hijacked a wiki. Humans blew up substations. Our own Ashley Knowles weighs in on what should actually worry us more right now. https://www.m… by Black Hills Information Security.
- Windows Server 2022 reaches end of mainstream support next month https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-ma… by BleepingComputer.
- Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-pl… by BleepingComputer.
- CenterPoint Energy confirms customer data stolen in cyberattack https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-da… by BleepingComputer.
- BambooToken malware controls Windows and Linux systems via MQTT https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-an… by BleepingComputer.
- Hackers target WordPress sites via third-party WooCommerce plugin https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-th… by BleepingComputer.
- CISA: Critical VMware RCE flaw now exploited by ransomware gangs https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-… by BleepingComputer.
- Cisco patches Secure Email Gateway zero-day exploited in attacks https://www.bleepingcomputer.com/news/security/new-cisco-secure-email-zero-day-exploi… by BleepingComputer.
- Microsoft releases emergency Windows updates to fix RDS failures https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-… by BleepingComputer.
- Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-f… by BleepingComputer.
- Homebrew 7.0.0 gets built-in GUI, better security controls https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-securi… by BleepingComputer.
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-acc… by BleepingComputer.
- Hackers target exposed Vite dev servers to steal AWS, Azure secrets https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-ser… by BleepingComputer.
- Bypassing Referer-Based CSRF with strict-origin-when-cross-origin https:// afine.com/blogs/bypassing-refe rer-based-csrf-with-strict-origin-when-cross-origin.
- Fake CAPTCHA Scams https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html by Nicolas Krassas.
- Apple uses secure camera hardware to verify photos are real captures https://cyberinsider.com/apple-uses-secure-camera-hardware-to-verify-photos-are-r… by Nicolas Krassas.
- Spain gets its first taste of AI-aided cyber attack https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-at… by Nicolas Krassas.
- Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000… by Nicolas Krassas.
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.ht… by Nicolas Krassas.
- US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-br… by Nicolas Krassas.
- Oracle Patches 800+ Vulnerabilities in September 2026 Security Update https://www.securityweek.com/oracle-patches-800-vulnerabilities-in-september-202… by Nicolas Krassas.
- Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens https://thehackernews.com/2026/09/active-exploitation-attempt… by Nicolas Krassas.
- Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells https://thehackernews.com/2026/09/attackers-exploit-woocommerce-whol… by Nicolas Krassas.
- Ministry of Justice apologizes after court staff accessed Southport victims’ files https://www.theregister.com/security/2026/09/16/ministry-of-justice… by Nicolas Krassas.
- Google fixes actively exploited Android zero-day on Pixel devices https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-andro… by Nicolas Krassas.
- Using Reflective Loaders to Replace LoadLibrary for Hot Swappable Modules in C++ https://racoten.gitbook.io/red-team-developments-and-operations by Nicolas Krassas.
- Acronis warns of actively exploited flaw in its cPanel backup plugin https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploite… by Nicolas Krassas.
- Thai Broadband Provider Hacked via Fortinet Vulnerability https://www.securityweek.com/thai-broadband-provider-hacked-via-fortinet-vulnerability/ by Nicolas Krassas.
- RT EZ: Great article summarizing some of the attacks I’ve been avising on for a few years now. Attack: AITM Defense: Managed device and/or phishing re… by DirectoryRanger.
- RT 0x12 Dark Development: Domain Credential Dumping via File Handle Redirection New Medium post. In this article, we’ll extend the File Handle Redire… by DirectoryRanger.
- RT DirectoryRanger: SharePointDumper. PowerShell-based extraction and auditing utility that enumerates SharePoint sites a user can access via Microsof… by DirectoryRanger.
- RT SANS Institute: The incident response process most teams still follow hasn’t been updated in roughly two decades. Yesterday SANS Institute publish… by Dave Kennedy.
- RT Sami Laiho: Thorough reorganization at NSA will create five ‘mission centers,’ including cyber and AI https://therecord.media/nsa-reorganization-fi… by Dave Kennedy.
- What? ppl selling @virustotal accounts in black market? This was not on my bingo card. (I wish I can have one, so I can feed all the samples to @… by Haifei Li.
- SilkParasite Infrastructure Exposed: pivoting from one page hash and a single TLS cert to a 13-server SpiceRAT cluster https:// hunt.io/blog/silkparasite-spic erat-central-asia-infrastructure.
- New, exclusive (and cathartic), from me: The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search servi.
- RT jonas wiedermann-möller: Reuters wrote an article about my findings about two accounts on HF that got hijacked over by agents in May. The agents p… by LiveOverflow hextree.io.
- RT MG193_7: I used /goal + ASC + adb to analyze my phone. The agent pulled 50+ APKs with uid=1000, then used ASC to analyze them without exporting any… by LiveOverflow hextree.io.
- RT tihmstar: Smart speakers are ALWAYS listening and can hear the ENTIRE HOUSE!!! https://tihmstar.net/homepodmini.mov by LiveOverflow hextree.io.
- Ok, one more for the road - https://LOLDrivers.io by The Haag™.
- Another good LOLRMM in the wild - https://lolrmm.io/tools/tiflux by The Haag™.
- Having a lot of fun digging into this. Going to post more info about it by Giuseppe
N3mes1s. - This. Attribution is still complicated even when it is there all the time. by Giuseppe
N3mes1s. - RT Cisco AI: Most security benchmarks assume the vulnerable code is already known. In practice, defenders first have to find it. Cisco @fdtn_ai introd… by Giuseppe
N3mes1s. - Here are some key Conditional Access policies that @TechBrandon & I put together. You should also have a “catch-all” policy that applies to all users … by Sean Metcalf.
- RT TrustedSec: UPDATE Organizations used to ask themselves “if” they’d adopt passkeys; #Microsoft decided the “when” for us, as of Sept 1, 2026. … by Sean Metcalf.
- RT spencer: If you do this, your environment will be harder to attack, be it by humans or AI by Sean Metcalf.
- RT Christoph Kuderna: Great article if you’re using PAWs: https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/locking-down-paw… by Sean Metcalf.
- The Apple Security Update Review for September 2026 by Dustin Childs.
- RT _leon_jacobs(): New gowitness, 3.20! https://github.com/sensepost/gowitness/releases/tag/3.2.0 by SkelSec.
- RT Zach Edwards: I’m out today with some new casino research I’ve been working on for a few months with the team at @Infoblox. If you work with malw… by SwitHak ().
- RT Internet Archive: “Fix the Wayback Machine!” We’ve heard you. The @waybackmachine has been dealing with waves of high-volume automated traffic. … by SwitHak ().
- RT Craig S. Blackie: Another post from me, this time looking at a how I hacked an RFID CTF to get to the top of the leaderboard: https://techanarchy.n… by X-C3LL.
- Evading Machine Learning Based Detections · MSec Operations Blog https://msecops.de/blog/posts/ml-evasion/ by /r/netsec.
- I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table https://blog.himanshuanand.com/2026/09/i-missed-one-tlb-shootdown/ by /r/netsec.
- Bypassing Referer-Based CSRF with strict-origin-when-cross-origin https://afine.com/blogs/bypassing-referer-based-csrf-with-strict-origin-when-cross-o… by /r/netsec.
- Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit https://www.acronis.com/en/tru/posts/red-heron-exploits-gite… by /r/netsec.
- Escaping the OpenAI Codex sandbox, twice https://accomplish.ai/blog/escaping-the-openai-codex-sandbox-twice/ by /r/netsec.
- Getting into EMFI for 30€ thanks to globalization https://www.errno.fr/EMFI_basics by /r/netsec.
- UANIA OS: Authenticated Remote Code Execution https://rainpwn.blog/blog/uania-os-rce/ by /r/netsec.
- I gave a talk at Bluehat Singapore. Here is a link to the slides, and a photo that perfectly frames it. https:// thomasdullien.github.io/about/ slides/An-age-of-experimentation-BlueHat-Asia-2026.pdf.
- One of my last reports to @GoogleVRP as an external researcher, now they’ve given me a badge Super excited for this new chapter as a Googler :) by skull.
- Investigation Scenario A workstation’s $UsnJrnl shows a .lnk file created and deleted from %APPDATA%\Microsoft\Windows\Recent\ within 4 seconds,… by Chris Sanders.
- Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin’s AI use by Takahiro Takeda.
- RT Nextron Research : Our THOR Thunderstorm-based artifact scanning pipeline identified a coordinated npm campaign hiding malicious behavior insid… by Florian Roth.
- RT Clarín: MURIÓ ANDRÉS BLANCO, REFERENTE DEL HACKING ARGENTINO Tenía 44 años y era especialista en seguridad de redes Wi-Fi. Trabajó en Core Se… by Dave Aitel.
- RT Suha: There are glaring issues in this paper beyond the evaluation problems raised by Davi and ToB, including ones that make me question the ratio … by Dan Guido.
- RT NCSC UK: Today, the NCSC alongside the @FBI and the Dutch AIVD, has published an advisory exposing spyware used by Iranian state actors to target d… by Dominic Chell.
- RT Mickey: I’ve create an iOS app called Signal Watch Guard that listens for nearby Bluetooth devices and alerts you when one on your watchlist is nea… by RPW: @rpw@chaos.social.
- RT smaury 5.1: Attacker in the Loop(back) by Simone Margaritelli.
- by Thomas Roccia.
- by Thomas Roccia.
- Visual Studio Code Vulnerability that Bypasses Workspace Trust https:// remedio.io/blog/bypassing-vs-c ode-workspace-trust-with-a-single-link/.
- RT YesWeHack ⠵: Cache poisoning isn’t always about unkeyed input At @BugBountyDEFCON, @brumens2 showed how cache key injection can lead to unaut… by Gareth Heyes \u2028.
- Did a small post about mutating Safari a behaviour that Shazzer found. https://thespanner.co.uk/mutating-safari by Gareth Heyes \u2028.
- Content-Disposition: attachment rendered HTML W.T.F by Gareth Heyes \u2028.
- O_TMPFILE is so dope. Apple should implement this by Gergely Kalman.
- Uh-oh @Guluisacat is at it again by Gergely Kalman.
- RT Ilya Andr: Missed one more from the drop lol CVE-2026-43783 - macOS LPE via DesktopServicesHelper. One XPC request -> arbitrary chown -> root. PT S… by Gergely Kalman.
- The slides from my talk at Microsoft Bluehat Singapore are public here: https://thomasdullien.github.io/about/slides/An-age-of-experimentation-BlueHat… by Halvar Flake.
- RT Michael Grafnetter: Bad news for red teamers: Microsoft Entra ID now detects the WebAuthn / #FIDO2 assertion replay attack. As a result, two o… by Will Schroeder.
- RT Matt Brown: Wanna find IoT vulns before you ever get your hands on the device? Download some firmware and lets go! In this video we show off how mo… by hasherezade.
- RT Ben Herzog: This is something I was working on during late 2025 and can finally share: stealth obfuscated prompts hiding in plain English. At the t… by hasherezade.
- RT Antoine Vastel: Side project update: https://obfuscatejs.com/deobfuscate I created a JS deobfuscator to target my own obfuscator (and improve it). … by hasherezade.
- RT Microsoft BlueHat: Sometimes the biggest discoveries start with a simple question: What happens if I try this? At BlueHat Asia, Vaisha Bernard (@th… by Stefan Esser.
- Autonomous offensive LLM Handbook: An ongoing research on a proposed deterministic harnessing for offensive security agents https://github.com/mouteee… by Panos Gkatziroulis.
- A curated list of AI-enabled security testing tools by @joevest https://aisecuritymatrix.com/ by Panos Gkatziroulis.
- RT MSec Operations: New blog post “Evading machine learning based detections” - https://www.msecops.de/blog/posts/ml-evasion/ by Panos Gkatziroulis.
- Probe Microsoft’s Self-Service Password Reset (SSPR) endpoint to enumerate registered verification methods and flag any that lack a strong second fact… by Panos Gkatziroulis.
- RT Thomas Roccia : I just published a short video about PromptIntel, the threat intelligence feed for AI. PromptIntel is an open database tha… by Panos Gkatziroulis.
- Windows BYOVD research on DCRCVDrv.sys and Alinubx.sys, reverse engineering their kernel primitives, IOCTL surfaces, and detection opportunities https… by Panos Gkatziroulis.
- Writing Beacon Object Files In Mythic Using Dark Agent For MacOS https://umsundu.co.uk/posts/Writing-Beacon-Object-Files-In-Mythic-Using-Dark-Agent-Fo… by Panos Gkatziroulis.
- Offensive SIEM - Practical techniques & queries for leveraging SIEM as an offensive discovery tool https://github.com/ekitji/siem by Panos Gkatziroulis.
- RT 0x12 Dark Development: The PID Mutation lesson is added into the BYOVD module of the Evasion course https://0x12darkdev.net/courses/windows-offensi… by Panos Gkatziroulis.
- A foundational C library for building operationally credible offensive capabilities https://github.com/youssefnoob003/SindriKit/ by Panos Gkatziroulis.
- RT spencer: For all the the IT admins asking, how do I make Active Directory MORE defensible. This is how… Jerry Devore’s awesome series on Active D… by Jeff McJunkin.
- RT Eiji Kitamura / えーじ: 許可されたURLパターン以外へのあらゆる送信通信をブラウザのネットワーク層で一括遮断する “Connection Allowlists” がChrome 152… by Masato Kinugawa.
- RT Paula Januszkiewicz: An Xbox in a Microsoft Entra ID attack? Yes, really. In CQURE Hacks #82, we explore how a Conditional Access policy relying on… by kmkz.
- RT Ryx: Public PoC for isomorphic-git prototype pollution (GHSA-83vg-jxvh-fx76) Malicious ref names in getRemoteInfo pollute Object.prototype. Follow-… by kmkz.
- RT CISA Cyber: We added Cisco Identity Services Engine vulnerability CVE-2026-76460 & Acronis Backup vulnerability CVE-2026-87886 to our KEV Ca… by kmkz.
- RT Panos Gkatziroulis : R2Socks - SOCKS5 proxy tunneled through Cloudflare R2 buckets The proxy runs a local SOCKS5 server on the operator’… by kmkz.
- RT Nicolas Krassas: bl4ckr0ss3/knife: A reverse engineer’s binary Swiss-army knife in Rust: triage, disassembly, function/CFG recovery, crypto-constan… by Spiros Fraganastasis.
- RT Altered Security: Fantastic. The attacks look straight out of CRTP! by Nikhil Mittal.
- RT Battle Programmer Yuu: goto? considered harmful by nyxgeek.
- How long before XCSSET ’evolves’ and starts infecting JSON-based Xcode projects? @noarfromspace by Patrick Wardle.
- RT Jiska: With Siri Recap, Apple sends everything people say to Private Cloud Compute. Apple Reference Image extends this and also sends your photos t… by Patrick Wardle.
- RT mayllart: Oh yeah baby! 2 Gatekeeper bypass CVEs awarded: CVE-2026-84579 and CVE-2026-28899. More to come on this soon! Let’s goooooo! by Patrick Wardle.
- RT Zhongquan Li: Apple has made some changes to their bug bounty policy. In the past, the first external researcher to find the vulnerability would ge… by Patrick Wardle.
- damn, @brutecat got $100k from Google for an arbitrary file read interesting writeup to see how he approached the bug starting from analysing Goo… by payloadartist.
- Too much has been written about the OpenAI and Hugging Face incident to keep up with. We wrote the simplified version for security researchers and eng… by ProjectDiscovery.
- RT Ambionics Security: Casse-Spip: pre-auth RCE on SPIP, the CMS behind thousands of French public and media sites. Our auditor @WaykoDev fo… by Swissky.
- Bug write-up for “AI Studio Auth bypass” - @ndevtk https://ndevtk.github.io/writeups/2026/07/28/ais-bypass/ by Swissky.
- The Cyber Gap : How to Counter China’s Threat to America’s Critical Networks Great CFR report, that I was happy to help with. https://www.cfr.org/re… by Phil Venables.
- RT Gadi Evron: “The AI Reversing Panel: Are we all powerful, or out of a job?” I moderated at @reconmtl is out They don’t do panels, but @hugoforti… by Mari0n.
- RT CloudBreach: RedAmon: an autonomous #redteam agent that goes from first packet to a merged PR with zero human keystrokes in between. �… by Renos.
- RT CBS News: U.S. Coast Guard personnel and FBI agents boarded two Texas-bound energy tankers last month after cyberattacks struck the vessels while t… by scriptjunkie (Matt).
- Quantum Computers Are Not a Threat to 128-bit Symmetric Keys https:// words.filippo.io/128-bits/.
- RT Swissky: Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities - @wupco1996 https://depthfirst.com/research/going-d… by ϻг_ϻε.
- RT Pete Markowsky: We made it possible for Santa to stop the pid_suspend call against a client. SIGKILL and SIGSTOP still left as an exercise for the … by Csaba Fitzl.
- RT John Scott-Railton: “Who’s a good boy?!” Hackers just dumped the contents of a Flock camera. They found: Software explicitly detecting peopl… by thaddeus e. grugq.
- RT Oren Yomtov: We escaped OpenAI’s Codex sandbox by dumping V8’s shared JavaScript heap and scanning it for the privileged UUID-shaped token belongin… by thaddeus e. grugq.
- RT Christo Grozev: Another major GRU/FSB blunder, on par with the Google Translate fiasco. And another win for the FBI. (We at @InsiderEng and @derspi… by thaddeus e. grugq.
- Another month, another KVM escape. Patch if you’re affected. https://www.openwall.com/lists/oss-security/2026/09/16/14 by V4bel.
- RT 𝐑𝐀𝐢𝐡𝐚𝐧: Zero-Auth to Domain Admin - Automated Active Directory Attack Chain A fully automated penetration testing tool that chai… by Vincent Yiu.
- RT Nathan McNulty: You might want to patch this one. It’s not specified whether RhService.exe is affected, but if it is, then this DLL hijacking is pr… by Vincent Yiu.
- RT Aftermath Labs: Using BLARE2 for binary instrumentation to guide fuzzing via coverage. Seems to work well, two discord/chromium crasher media files… by x86byte.
- CISA’s report makes it clear that these techniques are valuable, especially when attackers use legitimate credentials and tools that make malicious activity harder to distinguish from normal behavior..
- They’re low effort. They require very little tuning. And because legitimate users have no reason to interact with them, they can produce incredibly high-confidence alerts with very few false positives.
- I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically aligned with the work I’ve done on Intrusion Detection Honeypots (IDHs). I’ve been be.
- RT Pavel Yosifovich: How do you run your own service inside Svchost.exe? https://trainsec.net/library/malware-analysis/how-to-run-a-windows-service-in… by sailay(valen).
- NEW BHIS | Blog Want to learn how adversaries leave tracks the moment they touch a system - and how to find them before they dig in? Threat Hunti… by Black Hills Information Security.
- Microsoft Teams will let admins block custom file extensions https://www.bleepingcomputer.com/news/security/microsoft-teams-will-let-admins-block-cust… by BleepingComputer.
- New Check Point flaw lets hackers execute code with root privileges https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-let… by BleepingComputer.
- New RatHat Android malware uses AI to automate device control https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-aut… by BleepingComputer.
- OpenAI details more cases of AI agents taking unauthorized actions https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agen… by BleepingComputer.
- Brevo supply-chain attack injected ClickFix scripts on customer sites https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injecte… by BleepingComputer.
- US takes down NightmareStresser DDoS-for-hire platform https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-t… by BleepingComputer.
- Microsoft shares workaround for Windows domain login issues https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-workaround-for-windows-… by BleepingComputer.
- Cisco warns of max severity ISE zero-day exploited in attacks https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-ze… by BleepingComputer.
- Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation https://thehackernews.com/2026/09/microsoft-patches-cvss-… by Nicolas Krassas.
- An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html by Nicolas Krassas.
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-gith… by Nicolas Krassas.
- New Android malware uses AI to steal bank logins and PINs https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-log… by Nicolas Krassas.
- North Korea’s fake job interviews infected 30,000 devices https://www.theregister.com/security/2026/09/18/north-koreas-fake-job-interviews-infected-30… by Nicolas Krassas.
- INTERPOL says it used AI to identify 126 criminals from 100,000 images https://cyberinsider.com/interpol-says-it-used-ai-to-identify-126-criminals-fro… by Nicolas Krassas.
- FBI: Fake cop and government impersonation scams cost victims $1.6B https://www.theregister.com/cyber-crime/2026/09/18/fbi-fake-cop-and-government-imp… by Nicolas Krassas.
- A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity https://unit42.paloaltonetworks.com/securing-aws-agentcore-ha… by Nicolas Krassas.
- Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts https://www.bleepingcomputer.com/news/security/microsoft-fixes-bug-behind-defen… by Nicolas Krassas.
- WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-… by Nicolas Krassas.
- Fake LastPass downloads on GitHub pushed password-stealing malware https://cyberinsider.com/fake-lastpass-downloads-on-github-pushed-password-stealing… by Nicolas Krassas.
- Are AIs Still Struggling with CAPTCHAs? https://www.schneier.com/blog/archives/2026/09/are-ais-still-struggling-with-captchas.html by Nicolas Krassas.
- Auditing in the age of (good enough) AI https://blog.trailofbits.com/2026/09/18/auditing-in-the-age-of-good-enough-ai/ by Nicolas Krassas.
- Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.ht… by Nicolas Krassas.
- Hacking OpenAI https://www.hacktron.ai/blog/hacking-openai by Nicolas Krassas.
- Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-… by Nicolas Krassas.
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files https://thehackernews.com/2026/09/critical-docker-sandboxes-… by Nicolas Krassas.
- RT ferstar: Hey @Zai_org , why does ZCode silently pack entire workspaces + full .git history and upload to Aliyun OSS on login? - Server holds the on… by Nicolas Krassas.
- Visual Studio Extensions Revisited, by @domchell https://www.mdsec.co.uk/2026/05/visual-studio-extensions-revisited/ by DirectoryRanger.
- Cached Token Theft: Extracting Azure and Microsoft Graph Refresh Tokens from the macOS Keychain via PowerShell, by @Thomas_Live https://www.cloud-arch… by DirectoryRanger.
- RT Enno Rey: Good series on Pwning AI Agents Part 1: Exploiting AI Coding Agents https://m10x.de/posts/2026/04/pwning-ai-agents-part-1/4-exploiting-ai… by DirectoryRanger.
- RT Co11ateral: Group Policy for Hackers – Basics We tried to simplify the concept of GPOs and how they work in Active Directory. As you can see, cred… by DirectoryRanger.
- RT EZ: In offsec, we all have our favorite attack paths. For me, I commonly abused the highlighted items below in addition to netNTLMv2 authn downgrad… by DirectoryRanger.
- RT TrustedSec: Six stages. Multiple encryption layers. One static analysis. In our new #blog, Principal Research Analyst @_snus walks through a multi-… by Dave Kennedy.
- RT OpenAI: We’re sharing our new framework for tracking, investigating, and disclosing instances of model misalignment at OpenAI. The framework sets c… by Dave Kennedy.
- RT Sean Metcalf: There are two main password attacks leveraged by adversaries; one is called Password Spraying and the other is called Kerberoasting. … by Dave Kennedy.
- RT Thijs Xhaflaire: Doing a lot with virtual machines on macOS? Give Box of Apples a try, you will love it! It’s loaded with cool new stuff for macOS… by L0Psec.
- Side Channel Comms has literally been in our entire industry’s basic assessment plan for systems for the last 10 years It’s not like I didn’t write to… by Greg Linares (Laughing Mantis).
- RT Malte Ubl: When I might have sounded alarmist over the last few weeks, it was because I was aware @S1r1u5_’s excellent work here that is the perfec… by LiveOverflow hextree.io.
- Marketing is now not aware of us updating the site - so - you are first - https://www.loldrivers.io/ - click now! by The Haag™.
- Living in the shell is an excellent way around execve/argv-based detections. I’d say “don’t tell the blue team,” but too late I guess? by Stuart.
- RT Previdian: An attacker targeting Langflow CVE-2026-0768 across Previdian’s honeypots left directory listing enabled. We analysed 10 hosted files: … by Giuseppe
N3mes1s. - RT Cyllex: New writeup: Patch-Gap Zero-Days: BlueMoon. Five China-nexus clusters chained two V8 patch-gap bugs (CVE-2026-85046, CVE-2026-87491) to one… by Giuseppe
N3mes1s. - RT H4x0r.DZ: 1-Click wordpress RCE That’s easy to exploit; just send a link to contact@Domain[.]com by Paulos Yibelo.
- RT pwn.ai: So… we decided to hack WordPress Core, AGAIN! Click2Shell is a one-click unauthenticated remote command execution chain (Preaut… by Paulos Yibelo.
- ZDI @thezdi has published the Microsoft vuln I discovered beginning of this year. https://www.zerodayinitiative.com/advisories/ZDI-26-708/ Details com… by Peter Gabaldon.
- RT spencer: Much the same for me as well. But also one of the most impactful issues that affects AD that is not directly AD is… Unsecured credential … by Sean Metcalf.
- RT spencer: What breaks when NTLM is disabled and what are the most likely blockers you may have? See screenshots below.. And here’s a good source of… by Sean Metcalf.
- RT sapir federovsky: They always use passkey naming for the phishing sites but they never configure passkey Anyway, some KQLs here we can work wi… by Sean Metcalf.
- RT Nathan McNulty: Huge news! Get-MgServicePrincipalAppRoleAssignedTo -ServicePrincipalId (Get-MgServicePrincipal -Filter “appId eq ‘00000003-0000-000… by Sean Metcalf.
- RT Brian in Pittsburgh: Be still my beating heart: ASD, CISA, NSA and other Five Eyes agencies have published a guidance document on hardening Act… by Sean Metcalf.
- RT Elastic Security Labs: We are investigating a malicious package, apexacc/cli, distributed in the npm registry. Initial assessment shows that the pa… by Samir.
- The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog https://www. msecops.de/blog/posts/backdoor ed-llms/.
- Investigating three real-world incidents in Anthropic’s evaluations https://www. anthropic.com/news/investigati ng-incidents-cybersecurity-evals.
- Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https:// engineering.block.xyz/blog/pre dictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware.
- Full Rails RCE technical writeup… KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack https:// ethiack.com/info-hub/research/ kindarails2shell-how-a-ma.
- What Every Programmer Should Know About Twists of Elliptic Curves https:// leetarxiv.substack.com/p/twist s-of-elliptic-curves.
- Sixteen strangers and a shared obfuscator: mapping the wool scene https:// neurowinter.com/security/2026/ 07/28/the-cast-and-crew/.
- Reversing of Eufy Security Video Doorbell sync protocol and wifi creds decryption from flash memory https:// adepts.of0x.cc/eufy-doorbell-h acking/.
- Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident https:// huggingface.co/blog/agent-intr usion-technical-timeline.
- HTTP Request Smuggling in Hiawatha https:// fenrisk.com/hiawatha-http-smug gling.
- Your House Has an FFmpeg Problem - elttam https://www. elttam.com/blog/your-house-has -an-ffmpeg-problem.
- Some new LNK abuse techniques from @Wietze at @MCTTP_Con by S3cur3Th1sSh1t.
- RT C.J. May: The biggest hurdle for this ASR rule at my org was in-house software. So we deployed Dev Drive to all engineers, which gave us an easy pa… by SwiftOnSecurity.
- RT Adam Goss: 5 controls that actually work against Scattered Spider: -> Verified callback protocol at every help desk -> FIDO2 hardware keys for priv… by SwiftOnSecurity.
- RT @BfV_Bund: Gemeinsam warnen u. a. #NPA_KOHO (Japan), FBI, BND und #BfV_Bund vor weltweiten nordkoreanischen Cyberaktivitäten, deren Ziel… by SwitHak ().
- RT ClearSky Cyber Security: ClearSky is tracking a new VBScript-based RAT used in activity targeting the Ukrainian defense sector, with a lure themed … by SwitHak ().
- Microsoft Teams Help Desk Impersonation: When IT Support Messages You First https://scamdrill.com/blog/teams-help-desk-impersonation-smb by /r/netsec.
- A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill https://heyitsas.im/posts/lpe-quartet/ by /r/netsec.
- CVE-2026-90999: A fabricated Sentry bug report can make Seer’s coding agent run attacker code https://agyn.io/blog/sentry-seer-autofix-vulnerability by /r/netsec.
- Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation. https://blog.doyensec.com/2026/09/17/ovs.html by /r/netsec.
- RT Marcos Oviedo: Re @yarden_shafir @aionescu Been digging deep on this for the past week, fascinating stuff. I put together an analysis of the entire… by Alex Ionescu.
- by bakki.
- RT Chris Sanders : I read CISA’s new report on using cyber decoys to strengthen detection and response, and it’s very philosophically align… by Chris Sanders.
- RT Applied Network Defense: Adversaries can manipulate filesystem timestamps to confuse defenders and evade detection. In this lesson, @DunhamSec will… by Chris Sanders.
- RT Dark Web Informer: Google reveals undercover Mandiant analyst infiltrated TeamPCP during massive supply-chain hacking spree Google says an und… by Florian Roth.
- RT Dark Web Informer: 🇫🇷 Mistral AI full source code allegedly offered for sale ⠀ Mistral AI is a French artificial intelligence company he… by Florian Roth.
- RT Renwa: My PlayStation 5 $10,000 bounty along with Firefox XSS bugs and many more vulnerable apps research are now public by Dave Aitel.
- The DNS protocol and all of its possible configurations should be one of the largest targets for finding possible exploits to patch ASAP before it bec… by d3d aka dead (dead, мёртв, 死了).
- RT nisedo: “find bugs make no mistakes” is one way to use AI in auditing, but usually we go a bit further by Dan Guido.
- ACLPwn while researching a new BOF came into mind, to keep this still OPSEC friendly PowerShell and C# are still incredible tools but growing the BOF … by David.
- RT Oleg Shakirov: Kaspersky reports on NightEagle’s attacks on firms in Russia, an expansion of geography This actor was first exposed in July 2025 by… by Dominic Chell.
- Need to circumvent Constrained Language Mode while operating in an environment with App Control for Business enabled? https://gist.github.com/enigma0x… by Matt Nelson.
- RT Ryx: n8n just got a CVSS 10.0 public exploit. CVE-2026-21858 (“Ni8mare”): unauthenticated file read → full RCE. Working PoC is circulating. Any … by Simone Margaritelli.
- Combat Theater now supports MCP! Connect your LLM detection engineering workflows directly to CT, launch real malware techniques through our C++ h… by 𝙁 𝙀 𝙇 𝙄 𝙓 𝙈.
- I’ve improved the sandbox in web Hackvertor to prevent tags from interfering with each other. For example if one tag executes first it used to be able… by Gareth Heyes \u2028.
- I’ve released Burp Hackvertor v2.2.67. This version supports the check tag and expressions. You can read how to use them here: https://github.com/hack… by Gareth Heyes \u2028.
- RT Armadin: From Okta self-registration to full production RCE in Cleo Harmony. By chaining SAML XML Signature Wrapping (XSW) with Cross-Store Identit… by Brett Hawkins.
- BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension https:// forever.security/blog/bragjack -attack-hijacks-every-browser-agent.
- RT xuan (ɕɥɛn / sh-yen): I personally think that the primary routes to AI-mediated catastrophe are because we fail to ensure that it’s not too unre… by Halvar Flake.
- RT Olaf Hartong: I’ve been quietly working on big Sysmon-modular improvements over the past months. The most important: - New tooling to validate and … by Panos Gkatziroulis.
- Telegram provides a Mythic C2 profile for the Athena agent. It uses Telegram private bot-to-bot messages as a transport and Mythic’s Push C2 gRPC serv… by Panos Gkatziroulis.
- Doing some digging in the latest research of @zux0x3a by Panos Gkatziroulis.
- RT Kostas: This is such a nice report from CISA (see below) on using decoys for detection and response. One thing I really like about this approach is… by Jeff McJunkin.
- RT Kuba Gretzky: I’ve just released the first video in the Evilginx Pro Tutorials series, where I’ll be providing hands-on tutorials on how to use Evi… by Chihuahua in charge NotMe.
- RT Rıdvan Yağlı: CVE-2026-43783 için Exploit/PoC yayınlandı: macOS’ta kötü amaçlı uygulamalar root yetkisine yükselebiliyor! LPE -> Ro… by kmkz.
- RT IRIS C2: NEW: Apple is preparing to implement a kernel level EDR system in iOS When activated, the watchdog, known as https://com.apple.iokit.Endpo… by kmkz.
- RT Nathan McNulty: OK, so this is actually a pretty big deal Microsoft removed the Entra P1 license requirement to export logs from Entra to Azur… by Max.
- RT quarkslab: Optical network security often sounds like an obscure incantation: PON, ONU, OLT, PLOAM, OMCI, GEM, GPON, XG-PON, 50G-PON, T-CON.. To co… by Max.
- RT Gal Weizman: Excited to finally share my recent research, where I managed to hack Chrome, Comet, Edge, Opera and Claude in Chrome using one single … by Max.
- RT UmbrielAI: Umbriel’s Caleb Gross (@noperator) has an article in the latest Phrack 73 issue (@phrack) “Word Machines for Weird Machines” - check it … by Caleb Gross.
- Local AI for Penetration Testing & Research - Eddie Zhang https://projectblack.io/blog/local-ai-for-cyber-security/ by Swissky.
- Adminer - SQLite RCE Regex Filter Bypass - @SorceryIE https://blog.sorcery.ie/posts/adminer_sqlite_rce_regex_bypass/ by Swissky.
- RT Mia: Oh no Apparently ZCode has been storing your data in its own cloud with no way to disable it This is very similar to what happened early … by Swissky.
- Autonomic Defense: Countering AI-Driven Offense at Machine Speed - High and increasing baselines of control are more critical. AI can and should be us… by Phil Venables.
- #WAF Bypassing #AWS #CloudFront & #ALB WAF: Exploring the attack surface of a dual-layer web protection architecture. The first layer: a malicious XSS… by pyn3rd.
- Interestingly this is a very similar primitive to one of the “unexploitable” dead ends in @trailofbits recent article about sandbox escapes. (although… by Rick de Jager.
- RT Mark Satter: SCOOP: A shipment of F-35 fighter jet parts was rerouted to Hong Kong this summer - then vanished. Congress and DOD are inves… by thaddeus e. grugq.
- RT Lukasz Olejnik: Hackers broke into the firm building Russia’s new election system, which also processes e-voting results. They exfiltrated 200 GB o… by thaddeus e. grugq.
- RT ESET Research: #ESETresearch discovered SparroWocky, a new backdoor of the #FamousSparrow APT group. This new malware has quickly replaced SparrowD… by thaddeus e. grugq.
- CISA just cut 6 free cybersecurity assessment programs for critical infrastructure, the same orgs that can’t afford commercial alternatives. John Stra… by Black Hills Information Security.
- I suspect we will see a continued trend of weaponizing patched vulnerabilities at scale with AI. Zero days are overrated. by Bill Demirkapi.
- Malicious npm packages evade install-script defenses at runtime https://www.bleepingcomputer.com/news/security/malicious-npm-packages-evade-install-sc… by BleepingComputer.
- Researchers escape OpenAI Codex sandbox to run commands on host, with no prompt shown on screen - @Ax_Sharma https://www.bleepingcomputer.com/news/sec… by BleepingComputer.
- BragJack attacks hijack AI browser agents through malicious extensions - @Ax_Sharma https://www.bleepingcomputer.com/news/security/bragjack-attacks-hi… by BleepingComputer.
- Viral AI actress’ video hotline face-scans every caller, watches their mood - @Ax_Sharma https://www.bleepingcomputer.com/news/security/calling-viral-… by BleepingComputer.
- Gyazo server flaw exploited to steal 23.6 million user records https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236… by BleepingComputer.
- Hmmm……. by Dimitri Os.
- How hackers fake ANY login - JWT attacks explained (beginner friendly) - EP01 https://youtu.be/lehE8K5mk7A?si=cM0STWk7p7AAMGaTw by Nicolas Krassas.
- CnaEmulator - a standalone, general-purpose development, emulation, and testing harness for Cobalt Strike Aggressor Scripts (.cna) https://github.com/… by Nicolas Krassas.
- Below the Waterline Stage 1 - Red Team Planning https://blog.zsec.uk/below-the-waterline-stage-1-red-team-planning/ by Nicolas Krassas.
- OneDrive as a covert C2 transport for Cobalt Strike https://github.com/nmht3t/OneDrive-UDC2 by Nicolas Krassas.
- Cache key injection: Smuggling poison through the door https://www.yeswehack.com/lab/research-cache-key-injection by Nicolas Krassas.
- BragJack attacks hijack AI browser agents through malicious extensions https://www.bleepingcomputer.com/news/security/bragjack-attacks-hijack-ai-brows… by Nicolas Krassas.
- North Korean WaterPlum hackers infected 30,000 devices worldwide https://www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infecte… by Nicolas Krassas.
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html by Nicolas Krassas.
- Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up https://thehackernews.com/2026/09/google-gemini-broke-into-real-compan… by Nicolas Krassas.
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html by Nicolas Krassas.
- Flock Safety camera teardown: 53 hardcoded credentials, Android 8.1 with June 2018 patches, encryption key stored in plaintext on the same partition, … by Nicolas Krassas.
- From Registry-Stored PowerShell to In-Memory Cryptocurrency Mining: A Multi-Stage Infection Chain https://labs.k7computing.com/index.php/from-registry… by DirectoryRanger.
- OneDriveExplorer, by @bmmaloney97 https://github.com/Beercow/OneDriveExplorer by DirectoryRanger.
- Sysmon Modular updated, a new toolkit for building, maintaining and tuning your configuration, by @olafhartong #DFIR https://medium.com/@olafhartong/s… by DirectoryRanger.
- RT Smukx.E: KernelSight is an interactive knowledge base that maps how Windows kernel drivers get exploited. It tracks 156 CVEs across 64 drivers, org… by DirectoryRanger.
- RT Smukx.E: pretender is a tool developed by RedTeam Pentesting to obtain machine-in-the-middle positions via spoofed local name resolution and DHCPv6… by DirectoryRanger.
- RT : Active Directory Attack Architecture Map https://kypvas.github.io/ad_attack_architecture/ by DirectoryRanger.
- RT Smukx.E: PassTheCert-rs: a cross-platform, pure Rust implementation of Pass the Certificate. Uses Schannel certificate authentication over LDAP/S, … by DirectoryRanger.
- RT Ryx: Another Windows kernel LPE got full public source!! CVE-2026-42980: integer underflow in the NT OS Kernel lets a low-priv local user reach SYS… by DirectoryRanger.
- RT Enno Rey: mcp_binder, from @pyotam2 https://github.com/plutosecurity/mcp_binder by DirectoryRanger.
- RT Enno Rey: Slides & transcript of #ScapyCon keynote here: https://static.ernw.de/talks/ERNW_Rey_Enno_ScapyCon_2026_Keynote.pdf [PDF] https://static…. by DirectoryRanger.
- RT Enno Rey: Part II: Sniffing Bluetooth Auracast, from @ttdennis via @Insinuator https://insinuator.net/2026/09/auracast-part2/ by DirectoryRanger.
- RT DirectoryRanger: Nice little series on WHfB security, by @insinuator Past and Present Attacks https://insinuator.net/2025/06/windows-hello-for-busi… by DirectoryRanger.
- RT msuiche: ELEGANTBOUNCER update to scan heic,heif,avif,hif files for CVE-2026-32741, CVE-2026-32882, CVE-2026-84383 + the no CVE exploit attempts in… by LiveOverflow hextree.io.
- RT trial: Flirting: https://www.wiz.io/blog/wiz-research-codebreach-vulnerability-aws-codebuild Harassment: https://www.hacktron.ai/blog/hacking-opena… by LiveOverflow hextree.io.
- RT Harsh Jaiswal: I have been on both side of such submissions and sometimes people go outside scope, knowingly or unkowningly, try to show max impact… by LiveOverflow hextree.io.
- RT Jessica Ruan: Re My humble thoughts, inspired by @leilavclark’s framework https://jessicaruan.com/posts/openai-bug-bounty by LiveOverflow hextree.io.
- Silent packet loss in PcapSplitter: a file collision bug on TCP session reuse https:// robinhayer.dev/pcapsplitter-fi le-collision-tcp-session-reuse.
- I think Noam @polynoamial is receiving a lot of undeserving flak for this and I wanted to chip in as someone who escaped sandboxes for a living (as we… by Paulos Yibelo.
- While on the train I was wondering how Claude Code is sending messages from one session to another. This is how and you can manually inject “teammate”… by S3cur3Th1sSh1t.
- Three memory-safety bugs in Godot’s untrusted-file parsers https:// axeghost.offprint.app/a/3mvs6z o4blo23-three-memory-safety-bugs-in-godots-untrusted-file-parsers.
- RT Rob Fuller: Added more training to the AI-CTF (it won’t be fast but you can run this on a halfway decent laptop) - https://github.com/mubix/ai-ctf … by Scott Sutherland.
- Three memory-safety bugs in Godot’s untrusted-file parsers https://axeghost.offprint.app/a/3mvs6zo4blo23-three-memory-safety-bugs-in-godots-untrusted-… by /r/netsec.
- AI Agents Keep Falling to ‘Goal Hijack’ (Copilot, Cursor, Grok) https://darkmarc.substack.com/p/hijacking-ai-agents-how-an-agents by /r/netsec.
- Fastest CVE informer | EchelonGraph https://echelongraph.io/pulse by /r/netsec.
- BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension https://forever.security/blog/bragjack-att… by /r/netsec.
- Your LLM is prompt injecting you… https://www.edenai.co/post/when-your-llm-router-turns-against-you-the-hidden-security-risk-in-ai-agents by /r/netsec.
- RT SAFA Team: Part 2 of our CVE-2025-13032 research is live. From a paged pool overflow to full LPE on Windows 11: IORing RegBuffers corruption, MDL-b… by winterknife.
- RT Raspberry Pi: Lasers. Microscopes. $250K. One secured chip. Ledger Donjon just showed how they cracked debug access on RP2350-A4, a break worthy of… by Alex Plaskett.
- SAML: A fractal of bad design.
- Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon’s best-selling router https:// rotcee.github.io/posts/analyzi ng-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-au.
- HEVD: From Stack Overflows to Modern Pool Grooming https:// sibouzitoun.tech/labs/from-sta ck-overflows-to-modern-pool-grooming/.
- Code Execution via Provisioning Packages https:// ipurple.team/2026/08/04/provis ioning-packages/.
- Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category https:// hego.red/jackpot.
- SQLite Critical CVEs or LLM Slop? https:// research.jfrog.com/post/sqlite -critical-cves-or-llm-slops/.
- Cruising for Shells in Flowise - elttam https://www. elttam.com/blog/cruising-for-s hells-in-flowise.
- ChatGPT now knows what you do on other websites via ad collector https://www. buchodi.com/chatgpt-now-knows- what-you-do-on-other-websites-via-ad-collector/.
- runZero is now a Dragos company! We are thrilled to join Dragos, alongside NetRise, to advance the shared mission of protecting critical systems and safeguarding civilization. Together, we’re delive.
- RT Md Ismail Šojal : Pentest is not a workflow, It is a search problem. - Known start. - Defined goal. - Unknown path. - Zero predefined role… by Dave Aitel.
- RT Mr. Anthony 安東尼: Our primary co-author @wwkenwong @ https://unprompted.au Topic: The Fuzzer Reached the Code, yet Missed the State. SOSP 2026: S… by Dave Aitel.
- RT popzxc: For years I wanted to be able to write custom clippy-like lints. Turns out, the solution exists for quite a long time now: dylint by @trail… by Dan Guido.
- Windows Exploitation Techniques: Dangling COM Object Registrations by James Forshaw.
- Reverse-Engineering Flock Cameras by Bruce Schneier.
- Implant Encryption via the Dump Encoding Library https:// ipurple.team/2026/09/21/dump-e ncoding-library/.
- ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553 https:// minanagehsalalma.github.io/zte -smartlife-app-pwned/.
- RT Bitcoin News: MALICIOUS IPHONE APP USED TO STEAL CRYPTO PRIVATE KEYS Security researchers found that FomoPeek versions 1.1 and 1.2, distributed thr… by Simone Margaritelli.
- RT Mikko Ohtamaa: Zero-day remote code execution vulnerability in iPhone Safari. Click a link, and your crypto, passwords and everything else on your … by Simone Margaritelli.
- RT thaidn: Here are my fav talks at the first @UnpromptedAU: @chompie1337 shared her 1-day exploit factory. Although she focused on Windows, many of t… by Halvar Flake.
- RT Smukx.E: Antidbg: A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineer… by hasherezade.
- RT @zooko: Wow, these slides are fantastic to just read through and contemplate. https://thomasdullien.github.io/about/slides/An-age-of-experimen… by HD Moore.
Tools and Exploits
- Evilginx Chrome Extension 1.0 by Stephen Sims.
Chrome extension for Evilginx with cookie monitoring, local/session storage inspection, Cookie Freeze testing, DBSC header blocking, and phishlet development tools.
Apple releases macOS Golden Gate alongside security updates for Tahoe 26.7 and Sequoia 15.8.
Scans AWS, Azure, and GCP for actual attack chains to crown jewels and leaked credentials. Graphed multi-hop attack surface using the RAGE standard.
Process Monitor for macOS rewritten by Patrick Wardle. Open source with CLI, JSON export, on-device AI assistant, code signing verification, and VirusTotal integration.
Rust BloodHound collector reaches 84% attribute compatibility with SharpHound v2.16.0.0. Roadmap targets 90% with remote registry and SMB access.
zsh modules on macOS can establish TCP connections, manipulate files, and access extended attributes without spawning child processes. Detection analysis using Apple Endpoint Security telemetry.
Exfiltrates data by resolving well-known domains that map to characters instead of encoding data in subdomains. The data is the domain that was queried.
One-pass anonymous Active Directory enumeration over SAMR and LSARPC. No credentials required.
Sends NTLM Type-1 negotiate messages across multiple transports, decodes Type-2 challenges, and extracts internal NetBIOS/DNS names, AD forest, OS build, and clock skew.
- Havoc C2 0.8 Leviathan: Kaine User-Defined C2 by Lefteris Panos.
Major Havoc C2 release with Kaine user-defined C2, expanded Linux post-exploitation, SNI spoofing, in-memory PE execution, BOF-PE support, and a full client UI overhaul.
More this week (18)
- RT Quentin Texier : New update for RustHound-CE version 2.5.13 New in this release: - Pass-the-Certificate auth support (PFX / PEM, LDAPS… by DirectoryRanger.
- OpenHunterAI releases an AI red-team engine after killing the startup https:// runtimewire.com/article/openhu nterai-ai-security-startup-red-team-engine-release.
- Releasing another pywintrace-based ETW consumer for SysCallEnter + StackWalk events. TL;DR: System call tracing from user mode but it’s asynchronous, … by winterknife.
- RT @0xjohnny: To celebrate iOS 27’s release, why not release a sandbox escape? Announcing airlift: a PoC abusing a media sync path for out… by Gergely Kalman.
- RT @0xjohnny: To celebrate iOS 27’s release, why not release a sandbox escape? Announcing airlift: a PoC abusing a media sync path for out… by Patrick Wardle.
- macOS RC release notes: “Resolved Issues: Fixed: launchd no longer supports loading launchd property list files with the quarantine extended attribute… by Patrick Wardle.
- RT Nicolas Krassas: We were building an AI Security startup. We killed the startup idea and released the red-team engine instead - OpenHunterAI https… by thaddeus e. grugq.
- Ghostwriter v7.3.0: A Fresh New Look by Katherine.
- RT Persona: We’re releasing a new benchmark for evaluating selfie fraud and face anti-spoofing systems. Developed by researchers at Persona and the @… by Greg Linares (Laughing Mantis).
- RT Ryan Dowd: Found that 3 of my bug submissions had been rolled up into CVE-2026-84589. I’ll aim to get a blog released when they’ve formally been … by Gergely Kalman.
- RT 5pider: New Release Havoc Professional 0.8: Leviathan - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored p… by Kuba Gretzky.
- RT 5pider: New Release Havoc Professional 0.8: Leviathan - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored p… by Swissky.
- RT 5pider: New Release Havoc Professional 0.8: Leviathan - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored p… by Bobby Cooke.
- RT ALI TAJRAN: Microsoft releases Entra Connect v2.6.91.0 with security fixes and recommends upgrading to this version as soon as possible! This re… by Sean Metcalf.
- RT 5pider: New Release Havoc Professional 0.8: Leviathan - Introducing Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Refactored p… by K̵i̵r̵k̵ ̵T̵r̵y̵c̵h̵e̵l̵.
- Apple has released an update to XProtect Remediator https://eclecticlight.co/2026/09/18/apple-has-released-an-update-to-xprotect-remediator-5/ via @ho… by Howard Oakley, Eclectic Light Co.
- RT InfinityCurve Labs: New Release Havoc Professional 0.8: Leviathan - Introduce Kaine User-Defined C2 - Expanded Linux post-ex capabilities - Re… by stuk0v.
- RT @evilcos: 最近一些 iPhone 用户的钱包被盗,是因为安装了 FomoPeek 这个 App,v1.1-1.2 主要版本引入了恶意 SDK,其包含一套专业的 iOS 内核攻击框架,… by Nicolas Krassas.
