<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
<channel>
<title><![CDATA[ ParaCyberBellum Security Review ]]></title>
<description><![CDATA[ Cybersecurity technical stuff on the fly ]]></description>
<link>https://library.paracyberbellum.io/rss</link>
<atom:link href="https://library.paracyberbellum.io/rss" rel="self" type="application/rss+xml"/>
<language>en</language>
<pubDate>Sat, 22 Aug 2026 08:10:48 +0000</pubDate>
<item>
<title><![CDATA[ [ARTICLE] Yet another RCE in Gogs, but it's fixed this time! ]]></title>
<link>https://www.aikido.dev/blog/fixed-rce-gogs-cve-2026-52813</link>
<guid>https://www.aikido.dev/blog/fixed-rce-gogs-cve-2026-52813</guid>
<pubDate>Fri, 21 Aug 2026 04:04:15 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] This post will primarily focus on the Remote Code Execution vulnerability (CVE-2026-52813) in Gogs, an open-source Git hosting platform like GitHub or GitLab. But I'll also explain a logic bug to write on read-only repositories (CVE-2026-52810), together with an XSS vulnerability in the Jupyter rendering library Gogs was using ]]></description>
<author><![CDATA[ Jorian Woltjer ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive ]]></title>
<link>https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/</link>
<guid>https://research.checkpoint.com/2026/btr-reforged-weaponizing-defenders-remediation-driver-as-a-kernel-operation-primitive/</guid>
<pubDate>Fri, 21 Aug 2026 04:01:05 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads - Obfuscation, Evasion & LoL ] In this publication, we present the first full reverse engineering of the Windows Defender Boot-Time Removal driver (BTR.sys) and its proprietary transaction format. We dissect its encrypted configuration mechanism, integrity validation logic, and execution pipeline, and demonstrate how this legitimate remediation component can be transformed into a universal kernel operation engine. ]]></description>
<author><![CDATA[ Jiri Vinopal ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Web fuzzing for hackers ]]></title>
<link>https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers</link>
<guid>https://www.intigriti.com/researchers/blog/hacking-tools/web-fuzzing-for-hackers</guid>
<pubDate>Fri, 21 Aug 2026 03:58:26 +0000</pubDate>
<description><![CDATA[ [ Application Security - Fuzzing ] In this article, we'll explore web fuzzing from the ground up: what it actually is, the tooling and wordlists that make it work, and how to fuzz to discover more content and find more security vulnerabilities. ]]></description>
<author><![CDATA[ Ayoub, Orwa Atyat ]]></author>
</item>
<item>
<title><![CDATA[ [TOOL] LLVM Obfuscator ]]></title>
<link>https://github.com/und3ath/ollvm</link>
<guid>https://github.com/und3ath/ollvm</guid>
<pubDate>Fri, 21 Aug 2026 03:56:43 +0000</pubDate>
<description><![CDATA[ [ Obfuscation, Evasion & LoL ] An in-tree LLVM obfuscation framework integrated into the new pass manager (NPM). Configuration is driven by source-level annotations (llvm.global.annotations) and resolved once per module into a cached, deterministic configuration map. ]]></description>
<author><![CDATA[ und3ath ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Building an in-tree LLVM obfuscator solo, with an AI pair ]]></title>
<link>https://und3ath.github.io/2026/07/01/llvm-obfuscator-in-tree/</link>
<guid>https://und3ath.github.io/2026/07/01/llvm-obfuscator-in-tree/</guid>
<pubDate>Fri, 21 Aug 2026 03:55:02 +0000</pubDate>
<description><![CDATA[ [ Obfuscation, Evasion & LoL - Tooling ] We dive into  ollvm, an obfuscation framework fused directly into an LLVM 22 checkout, and detail what obfuscation actually does at each layer. ]]></description>
<author><![CDATA[ Und3Ath ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Solar Winds Part 2 Avoided: N-Able Passportal Vault Leak ]]></title>
<link>https://amibeingpwned.com/blog/solar-winds-part-2-avoided</link>
<guid>https://amibeingpwned.com/blog/solar-winds-part-2-avoided</guid>
<pubDate>Fri, 21 Aug 2026 03:52:18 +0000</pubDate>
<description><![CDATA[ [ Browser Security - Credentials Dumps, Theft and Cracking - Exploits & Payloads ] N-Able's PassPortal extension, on Chrome and Edge allowed any site or iframe a user is presented with to gain complete, persisted access to the decrypted vault. ]]></description>
<author><![CDATA[ James Arnott ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Breaking secure boot without breaking the crypto ]]></title>
<link>https://0x434b.dev/breaking-secure-boot-without-breaking-the-crypto/</link>
<guid>https://0x434b.dev/breaking-secure-boot-without-breaking-the-crypto/</guid>
<pubDate>Thu, 20 Aug 2026 04:31:37 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads - Hardware & Bios ] We first review the concepts of hardware boot components security, then detail vulnerabilities affecting them allowing unsigned or malicious code to run despite valid signatures. The impact stems from ignored verification results, incorrect coverage of signed metadata, misuse of authority or rollback policies, and TOCTOU or pointer-swap attacks that break secure-boot enforcement and remote attestation. ]]></description>
<author><![CDATA[ Christopher Krah ]]></author>
</item>
<item>
<title><![CDATA[ [TOOL] AWSHound ]]></title>
<link>https://github.com/AWSHound/AWSHound</link>
<guid>https://github.com/AWSHound/AWSHound</guid>
<pubDate>Thu, 20 Aug 2026 04:21:18 +0000</pubDate>
<description><![CDATA[ [ Enumeration, Reconnaissance & Scanning - Public Cloud ] AWS Bloodhound OpenGraph Connector, collects AWS IAM/authorization data and builds a BloodHound OpenGraph. ]]></description>
</item>
<item>
<title><![CDATA[ [ARTICLE] BOFScale: A CDN-Fronted Tailnet from a BOF-PE ]]></title>
<link>https://www.netspi.com/blog/technical-blog/red-teaming/bofscale-a-cdn-fronted-tailnet-from-a-bof-pe/</link>
<guid>https://www.netspi.com/blog/technical-blog/red-teaming/bofscale-a-cdn-fronted-tailnet-from-a-bof-pe/</guid>
<pubDate>Thu, 20 Aug 2026 04:19:15 +0000</pubDate>
<description><![CDATA[ [ C2 & Exfiltration - Tooling ] We explain how we managed to have BOFScale leveraging a modified Tailscale daemon compiled as a BOF-PE to seamlessly hide C2 traffic and DERP relays behind CDNs using standard WebSockets. ]]></description>
<author><![CDATA[ Ceri Coburn ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] CRLF-Powered Desync Attacks: Beheading HTTP Streams ]]></title>
<link>https://portswigger.net/research/crlf-powered-desync-attacks</link>
<guid>https://portswigger.net/research/crlf-powered-desync-attacks</guid>
<pubDate>Thu, 20 Aug 2026 04:13:04 +0000</pubDate>
<description><![CDATA[ [ Application Security ] We introduce the CRLF-Powered desync attacks. They exploit HTTP header injection in Nginx (e.g., using $uri in proxy_pass) to achieve request smuggling, response queue poisoning, cache poisoning, XSS, session hijacking and cross-user account takeover, including stealing HTTPOnly cookies and injecting malicious Set-Cookie headers. ]]></description>
<author><![CDATA[ Tom Stacey ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Git Repo Forensics: My Seven Phases Investigation Process ]]></title>
<link>https://root-security.eu/notebook/git-forensics-process/</link>
<guid>https://root-security.eu/notebook/git-forensics-process/</guid>
<pubDate>Wed, 19 Aug 2026 03:59:59 +0000</pubDate>
<description><![CDATA[ [ DevOps - Incident Response & Forensics ] We provide a structured, seven‑phase workflow for investigating suspicious Git commits - from case registration and evidence preservation, through technical analysis, stakeholder interviews, and credential review, to containment, root‑cause mitigation, and final reporting - emphasizing thorough documentation, hash‑based integrity, and the importance of commit signing and audit‑log retention to reliably attribute and remediate supply‑chain compromises. ]]></description>
<author><![CDATA[ Denis Rendler ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Hacking your life with AI can get you hacked ]]></title>
<link>https://www.endorlabs.com/learn/hacking-your-life-with-ai-can-get-you-hacked</link>
<guid>https://www.endorlabs.com/learn/hacking-your-life-with-ai-can-get-you-hacked</guid>
<pubDate>Wed, 19 Aug 2026 03:53:49 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads - Machine Learning & AI ] I uncovered 14 critical and high severity vulnerabilities, including multiple unauthenticated prompt-injection to RCE chains, across seven AI orchestration platforms. ]]></description>
<author><![CDATA[ Peyton Kennedy ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Dissecting House of Apple 2 on modern glibc ]]></title>
<link>https://jazho76.github.io/house_of_apple_2/</link>
<guid>https://jazho76.github.io/house_of_apple_2/</guid>
<pubDate>Wed, 19 Aug 2026 03:51:08 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] A GDB walkthrough of House of Apple 2, from FSOP to stack pivot and ROP on glibc 2.43. This article provides an interactive walkthrough that readers can follow alongside the sandbox to develop a more intuitive understanding of the primitive. ]]></description>
<author><![CDATA[ Joaquin Pinillos ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] How a popular Android image cropping library silently exposed thousands of apps to Arbitrary File Overwrite (AFO) ]]></title>
<link>https://itis911.github.io/writeups/cropper-vulnerability.html</link>
<guid>https://itis911.github.io/writeups/cropper-vulnerability.html</guid>
<pubDate>Wed, 19 Aug 2026 03:47:56 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads - Mobile ] This is a story about what happens when a widely-used image cropping library ships android:exported="true" on an Activity and root-scoped <paths> on a FileProvider as its defaults. ]]></description>
<author><![CDATA[ Ahmed Sabry ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] How to Stop AI-Generated Rogue Entra Device Joins ]]></title>
<link>https://www.wiz.io/blog/detecting-entra-device-registration-abuse</link>
<guid>https://www.wiz.io/blog/detecting-entra-device-registration-abuse</guid>
<pubDate>Wed, 19 Aug 2026 03:32:22 +0000</pubDate>
<description><![CDATA[ [ Intrusion Detection ] Instead of leaving behind recognizable fingerprints from public tooling, adversaries can now generate realistic device names that blend naturally into enterprise environments. This blog explores how that changes Entra ID detection and what are the behavioral signals that still expose these attacks. ]]></description>
<author><![CDATA[ Shahar Dorfman, Sapir Federovsky ]]></author>
</item>
<item>
<title><![CDATA[ [REFERENCE] Anthropic Cybersecurity Skills ]]></title>
<link>https://github.com/mukul975/Anthropic-Cybersecurity-Skills</link>
<guid>https://github.com/mukul975/Anthropic-Cybersecurity-Skills</guid>
<pubDate>Tue, 18 Aug 2026 04:10:24 +0000</pubDate>
<description><![CDATA[ [ Machine Learning & AI ] This repo contains 817 structured cybersecurity skills spanning 29 security domains, each following the agentskills.io open standard. The library maps across six industry frameworks - MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, MITRE D3FEND, NIST AI RMF, and the MITRE Fight Fraud Framework (F3) - with each skill mapped to the frameworks relevant to its type (a forensics skill carries ATT&CK + CSF; an AI-security skill adds ATLAS and AI RMF). ]]></description>
<author><![CDATA[ Mahipal ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Breaking the M365 Copilot Sandbox with ChatMate ]]></title>
<link>https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate</link>
<guid>https://zerolabs.rubrik.com/blog/breaking-m365-copilot-sandbox-chatmate</guid>
<pubDate>Tue, 18 Aug 2026 04:03:12 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads - Machine Learning & AI ] ChatMate, the first documented instance of remote prompt execution, shows how a malicious document can lead to sandbox escape. ]]></description>
<author><![CDATA[ Ori Lahav ]]></author>
</item>
<item>
<title><![CDATA[ [TOOL] ShaderGhost ]]></title>
<link>https://github.com/Joe12387/ShaderGhost</link>
<guid>https://github.com/Joe12387/ShaderGhost</guid>
<pubDate>Tue, 18 Aug 2026 03:57:16 +0000</pubDate>
<description><![CDATA[ [ Fingerprinting ] An undeletable supercookie that lives in your GPU's cache ]]></description>
<author><![CDATA[ Joe Rutkowski ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Rooting Android 17 with GhostLock ]]></title>
<link>https://nebusec.ai/research/ionstack-part-3/</link>
<guid>https://nebusec.ai/research/ionstack-part-3/</guid>
<pubDate>Tue, 18 Aug 2026 03:52:49 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads - Mobile ] GhostLock (CVE-2026-43499) is a Linux kernel vulnerability that exists in every major distribution since 2011. After turning it into a stable privilege escalation and container escape, we migrated the exploit for Android. ]]></description>
</item>
<item>
<title><![CDATA[ [ARTICLE] How Codex Hacked EggGame Into a Legendary Roc ]]></title>
<link>https://shmulc.substack.com/p/how-many-exploits-does-it-take-to</link>
<guid>https://shmulc.substack.com/p/how-many-exploits-does-it-take-to</guid>
<pubDate>Tue, 18 Aug 2026 03:48:37 +0000</pubDate>
<description><![CDATA[ [ Games ] In this article, I detail how Codex found authorization and replay flaws plus a race condition in EggGame - and used them to turn a simple browser egg into a legendary Roc. ]]></description>
<author><![CDATA[ Shmulik Cohen ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Bypassing Android Hardware Attestation from the Analyst's Chair ]]></title>
<link>https://blog.quarkslab.com/bypassing-android-hardware-attestation.html</link>
<guid>https://blog.quarkslab.com/bypassing-android-hardware-attestation.html</guid>
<pubDate>Tue, 18 Aug 2026 03:40:10 +0000</pubDate>
<description><![CDATA[ [ Mobile - Reverse Engineering ] Hardware key attestation lets an Android app prove to its backend that a key lives in secure hardware on a locked, verified device. This article opens the mechanism from the analyst's chair, from the certificate chain and the attestation extension down to the root of trust, then shows a simple bypass that never touches the secure hardware. ]]></description>
<author><![CDATA[ Eric Le Guevel ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Turning a TURN server into an evil proxy ]]></title>
<link>https://purpleshift.io/purple/2026-07-29-xfzo/</link>
<guid>https://purpleshift.io/purple/2026-07-29-xfzo/</guid>
<pubDate>Tue, 18 Aug 2026 03:36:47 +0000</pubDate>
<description><![CDATA[ [ C2 & Exfiltration ] We explain how TURN (Traversal Using Relays around NAT) servers, a video conferencing relay host, can redirect traffic to C2. ]]></description>
<author><![CDATA[ Marsel Shagiev ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] C2Looper Backdoor Uses GitHub for C2 ]]></title>
<link>https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2</link>
<guid>https://www.zscaler.com/blogs/security-research/c2looper-new-backdoor-likely-tied-ransomware-github-c2</guid>
<pubDate>Tue, 18 Aug 2026 03:34:49 +0000</pubDate>
<description><![CDATA[ [ Malware Analysis ] We analyze C2Looper, a new backdoor likely affiliated with an initial access broker for ransomware that uses GitHub for C2 communications. ]]></description>
</item>
<item>
<title><![CDATA[ [ARTICLE] Unauthenticated RCE in CircleCI MCP Server Explained ]]></title>
<link>https://remedio.io/blog/the-critical-unauthenticated-rce-vulnerability-in-circlecis-mcp-server/</link>
<guid>https://remedio.io/blog/the-critical-unauthenticated-rce-vulnerability-in-circlecis-mcp-server/</guid>
<pubDate>Tue, 18 Aug 2026 03:31:57 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] We discovered an unauthenticated RCE flaw in CircleCI's MCP server allowing for full pipeline takeover. The flaw lies in sending Host: localhost header with no Origin that results in passing security checks. ]]></description>
<author><![CDATA[ Omri Dar ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] ARM64 stack internals and obfuscation on Apple Silicon ]]></title>
<link>https://www.mdsec.co.uk/2026/08/arm64-stack-internals-and-obfuscation-on-apple-silicon/</link>
<guid>https://www.mdsec.co.uk/2026/08/arm64-stack-internals-and-obfuscation-on-apple-silicon/</guid>
<pubDate>Mon, 17 Aug 2026 04:51:49 +0000</pubDate>
<description><![CDATA[ [ EDR - Obfuscation, Evasion & LoL ] This post explains how macOS EDR tools (via the built‑in spindump utility) unwind ARM64 call stacks, details the ARM64 stack layout, compact‑unwind recipes, and pointer‑authentication (PAC) that protect return addresses, and then shows how to craft PAC‑aware synthetic frames and a trampoline gadget to obfuscate a stack trace and evade detection on Apple‑Silicon systems. ]]></description>
<author><![CDATA[ Anandeshwar Unnikrishnan ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Understanding safeguards/guardrails for cybersecurity work to not get blocked ]]></title>
<link>https://www.incendium.rocks/posts/bypassing-guardrails-for-cybersecurity-work/</link>
<guid>https://www.incendium.rocks/posts/bypassing-guardrails-for-cybersecurity-work/</guid>
<pubDate>Mon, 17 Aug 2026 04:44:36 +0000</pubDate>
<description><![CDATA[ [ Machine Learning & AI - Obfuscation, Evasion & LoL ] Hitting AI guardrails on frontier models is annoying, therefore this blog explains them and describes how to work around them. ]]></description>
<author><![CDATA[ Remco Van Der Meer ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] SysReptor: chaining a Host header injection to application-user RCE ]]></title>
<link>https://hippie.cat/post/Research/SysReptor-host-header-to-rce</link>
<guid>https://hippie.cat/post/Research/SysReptor-host-header-to-rce</guid>
<pubDate>Mon, 17 Aug 2026 04:41:16 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] How I chained a conditional SysReptor Host header account takeover with Ghostscript and GnuPG behaviours to achieve application-user RCE. ]]></description>
<author><![CDATA[ Hippolyte Quere ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Bring Your Own EDR: How to Turn a Commercial EDR into a Trojan Horse ]]></title>
<link>https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse</link>
<guid>https://www.akamai.com/blog/security-research/bring-your-own-edr-turn-commercial-edr-trojan-horse</guid>
<pubDate>Mon, 17 Aug 2026 04:36:53 +0000</pubDate>
<description><![CDATA[ [ EDR - Keyloggers, Backdoors & Rootkits ] We detail how legitimate SentinelOne installers and accessible COM interfaces can be abused to bypass Protected Process Light (PPL) protections and execute unsigned code - completely bypassing the need for kernel vulnerabilities or traditional exploits. ]]></description>
<author><![CDATA[ Shahak Morag ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Citrix NetScaler Pre-Auth RCE CVE-2026-8452 ]]></title>
<link>https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/</link>
<guid>https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth-rce-cve-2026-8452/</guid>
<pubDate>Mon, 17 Aug 2026 04:34:48 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] In this post, we’re going to walk through a vulnerability a Heap Overflow vulnerability in Citrix NetScaler and show how it can be used to achieve Remote Code Execution. ]]></description>
<author><![CDATA[ Sina Kheirkhah ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] CVE-2026-33696: From a Schema Name to RCE in n8n ]]></title>
<link>https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce</link>
<guid>https://simonkoeck.com/writeups/n8n-gsuiteadmin-prototype-pollution-rce</guid>
<pubDate>Mon, 17 Aug 2026 04:31:52 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] n8n uses a user-supplied schema name as a bare object key. Set it to __proto__, pollute the prototype, chain into RCE via the Git node. One request, full shell. ]]></description>
<author><![CDATA[ Simon Koeck ]]></author>
</item>
<item>
<title><![CDATA[ [TOOL] Ping 007 ]]></title>
<link>https://github.com/franckferman/ping-007</link>
<guid>https://github.com/franckferman/ping-007</guid>
<pubDate>Mon, 17 Aug 2026 04:31:07 +0000</pubDate>
<description><![CDATA[ [ C2 & Exfiltration ] Covert ICMP C2 framework - AES-256-GCM stealth exfil, OS ping mimicry (Linux/Windows), multi-packet reassembly & anti-SOC evasion. Written in Go. ]]></description>
<author><![CDATA[ Franck FERMAN ]]></author>
</item>
<item>
<title><![CDATA[ [REFERENCE] HackTheBox Cheatsheets ]]></title>
<link>https://github.com/Fr6ey/HackTheBox-All-Cheatsheets</link>
<guid>https://github.com/Fr6ey/HackTheBox-All-Cheatsheets</guid>
<pubDate>Mon, 17 Aug 2026 04:30:07 +0000</pubDate>
<description><![CDATA[ [ Labs & Simulation - Pentests & Red Teams ] Cheatsheets for Hack the Box challenges ]]></description>
<author><![CDATA[ Frey  ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] CVE-2026-6837 ]]></title>
<link>https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/</link>
<guid>https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/</guid>
<pubDate>Mon, 17 Aug 2026 04:28:01 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] Technical writeup for CVE-2026-6837, a post-authentication command injection vulnerability in Zyxel export-cgi PKCS#12 export handling. ]]></description>
<author><![CDATA[ Mina Zekry ]]></author>
</item>
<item>
<title><![CDATA[ [TOOL] PhantomTap ]]></title>
<link>https://github.com/Krishita17/PhantomTap</link>
<guid>https://github.com/Krishita17/PhantomTap</guid>
<pubDate>Mon, 17 Aug 2026 04:26:23 +0000</pubDate>
<description><![CDATA[ [ Hardware & Bios ] A Flipper Zero that stops guessing and starts reasoning: ML-guided RFID/NFC fuzzing & access-control auditing that turns raw card reads into a prioritized, explainable security assessment. Defensive-use only. ]]></description>
<author><![CDATA[ Krishita Sanjay Choksi ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Entry, Escalation, Persistence: Taking Apart Frappe's Document Follow ]]></title>
<link>https://robinroy.xyz/blog/frappe-document-follow-vulnerability/</link>
<guid>https://robinroy.xyz/blog/frappe-document-follow-vulnerability/</guid>
<pubDate>Fri, 14 Aug 2026 05:39:25 +0000</pubDate>
<description><![CDATA[ [ Authentication - Exploits & Payloads ] Write-up on three authorization failures in Frappe - one at the object level, one at the field level, and one in the lifetime of the grant itself - that allowed an attacker to access data they aren't authorized to. ]]></description>
<author><![CDATA[ Robin Roy ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] I found a KVM guest-to-host heap corruption bug and someone else got there first ]]></title>
<link>https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/</link>
<guid>https://blog.himanshuanand.com/2026/08/i-found-a-kvm-guest-to-host-heap-corruption-bug-and-someone-else-got-there-first/</guid>
<pubDate>Fri, 14 Aug 2026 05:37:48 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads - Virtualization ] I found a heap out-of-bounds read/write in KVM';s SEV-SNP Page State Change handler. A malicious guest VM can corrupt host kernel heap memory and leak its layout, across the VM boundary, as many times as it wants. ]]></description>
<author><![CDATA[ Himasnhu Anand ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders ]]></title>
<link>https://specterops.io/blog/2026/08/12/blacklight-ai-agent-endpoint-artifacts/</link>
<guid>https://specterops.io/blog/2026/08/12/blacklight-ai-agent-endpoint-artifacts/</guid>
<pubDate>Fri, 14 Aug 2026 05:33:08 +0000</pubDate>
<description><![CDATA[ [ Machine Learning & AI - Tooling ] A review of Blacklight, an open-source security research toolkit for discovering and analyzing AI agent artifacts that reside on endpoints. It helps authorized security teams assess exposure, guide next decisions, and develop detection and hardening guidance ]]></description>
<author><![CDATA[ Gavin Kramer ]]></author>
</item>
<item>
<title><![CDATA[ [TOOL] Blacklight ]]></title>
<link>https://github.com/SpecterOps/Blacklight</link>
<guid>https://github.com/SpecterOps/Blacklight</guid>
<pubDate>Fri, 14 Aug 2026 05:32:10 +0000</pubDate>
<description><![CDATA[ [ Machine Learning & AI - Vulnerability Analysis & Scanning ] Blacklight is a cross-platform toolkit for mapping, analyzing, and understanding the local AI agent attack surface across Windows, macOS, and Linux. ]]></description>
</item>
<item>
<title><![CDATA[ [ARTICLE] Turning Enterprise Update Servers Into Backdoor Factories - Part 2 ]]></title>
<link>https://specterops.io/blog/2026/08/05/turning-enterprise-update-servers-into-backdoor-factories-part-2/</link>
<guid>https://specterops.io/blog/2026/08/05/turning-enterprise-update-servers-into-backdoor-factories-part-2/</guid>
<pubDate>Fri, 14 Aug 2026 05:27:15 +0000</pubDate>
<description><![CDATA[ [ Keyloggers, Backdoors & Rootkits - Relay ] In this second part we detail how to bypass WSUS signature checks using .esd or .txt file extensions and deploy unsigned payloads via BITS for stealthy C2 persistence. ]]></description>
<author><![CDATA[ Beyviel David ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Turning Enterprise Update Servers Into Backdoor Factories - Part 1 ]]></title>
<link>https://specterops.io/blog/2026/08/05/turning-enterprise-update-servers-into-backdoor-factories-part-1/</link>
<guid>https://specterops.io/blog/2026/08/05/turning-enterprise-update-servers-into-backdoor-factories-part-1/</guid>
<pubDate>Fri, 14 Aug 2026 05:26:28 +0000</pubDate>
<description><![CDATA[ [ Keyloggers, Backdoors & Rootkits - Relay ] A deep dive into WSUS exploitation, showing how NTLM relay grants SQL database access and lets attackers push malicious updates to targets. ]]></description>
<author><![CDATA[ Beyviel David ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] AmnesiaStealer: macOS Infostealer That Hijacks Browsers ]]></title>
<link>https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/</link>
<guid>https://www.jamf.com/blog/amnesia-stealer-macos-infostealer-clickfix/</guid>
<pubDate>Fri, 14 Aug 2026 05:24:17 +0000</pubDate>
<description><![CDATA[ [ Malware Analysis ] A technical analysis of  AmnesiaStealer, a multi-stage Rust-based macOS infostealer spread through a counterfeit GitHub download page that captures the login password, reaches for macOS bypasses Apple has already patched, and can hand the operator live, hidden control of the victim's Chromium browser to steal authenticated sessions. ]]></description>
</item>
<item>
<title><![CDATA[ [ARTICLE] From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained ]]></title>
<link>https://www.saiflow.com/blog/from-unauthenticated-api-to-grid-risk-a-hybrid-inverter-vulnerability-explained</link>
<guid>https://www.saiflow.com/blog/from-unauthenticated-api-to-grid-risk-a-hybrid-inverter-vulnerability-explained</guid>
<pubDate>Fri, 14 Aug 2026 05:22:09 +0000</pubDate>
<description><![CDATA[ [ IoT & ICS ] A single misconfigured listening socket on FIMER's React 2 hybrid inverter lets an unauthenticated attacker send commands straight to the Supervisor MCU that governs the device's grid protections. ]]></description>
<author><![CDATA[ Itai Shmueli ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Return of the Cookie Monster ]]></title>
<link>https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/</link>
<guid>https://specterops.io/blog/2026/08/13/chrome-devtools-protocol-cookie-theft/</guid>
<pubDate>Fri, 14 Aug 2026 05:20:07 +0000</pubDate>
<description><![CDATA[ [ Browser Security - Post-Exploitation & Lateral Movement ] Cookie protections have made traditional session theft harder, but they do not eliminate the value of an authenticated browser session to adversaries. This post explores enabling the Chrome DevTools Protocol (CDP) inside a running Chromium browser to perform post-ex activities such as browser enumeration, cookie theft, and browser takeover. ]]></description>
<author><![CDATA[ Andrew Gomez ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] XSS2Shell: WordPress Preauth XSS to RCE Chain (CVE-2026-64638) ]]></title>
<link>https://pwn.ai/blog/xss2shell</link>
<guid>https://pwn.ai/blog/xss2shell</guid>
<pubDate>Fri, 14 Aug 2026 05:18:43 +0000</pubDate>
<description><![CDATA[ [ Application Security - Exploits & Payloads ] A pre-authentication XSS to RCE chain in WordPress Core that allows unauthenticated attackers to achieve remote code execution on any default WordPress installation through the login page. ]]></description>
<author><![CDATA[ Nigusu Kasahun ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Spaghettifying DRAM ]]></title>
<link>https://github.com/xoreaxeaxeax/skitter-creek-bath-salts</link>
<guid>https://github.com/xoreaxeaxeax/skitter-creek-bath-salts</guid>
<pubDate>Fri, 14 Aug 2026 05:14:01 +0000</pubDate>
<description><![CDATA[ [ Hardware & Bios ] By modifying the bottom layers of the memory hierarchy to rewire the physical DRAM address translations, we scramble platform memory, exposing protected regions of DRAM - carveouts invisible even to the kernel. When the address translations break, so do the security primitives built on them, and we unlock everything. ]]></description>
<author><![CDATA[ Christopher Domas ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor ]]></title>
<link>https://maldbg.com/interlock-esxi-decryptor-internals</link>
<guid>https://maldbg.com/interlock-esxi-decryptor-internals</guid>
<pubDate>Fri, 14 Aug 2026 05:06:55 +0000</pubDate>
<description><![CDATA[ [ Malware Analysis - Reverse Engineering ] We dissect an Interlock ransomware ESXi decryptor - revealing it embeds the victim's RSA‑4096 private key, uses AES‑256‑GCM (with the authentication tag ignored) in a progressive, in‑place "strided" decryption that overwrites data without integrity checks, and includes several design flaws that can silently destroy files. ]]></description>
<author><![CDATA[ Ian French ]]></author>
</item>
<item>
<title><![CDATA[ [TOOL] Dark-Agent ]]></title>
<link>https://github.com/ServiceNow/dark-agent</link>
<guid>https://github.com/ServiceNow/dark-agent</guid>
<pubDate>Fri, 14 Aug 2026 05:02:14 +0000</pubDate>
<description><![CDATA[ [ C2 & Exfiltration ] Dark Agent is a fully-featured Mythic C2 Agent for Linux and macOS environments. Built in Crystal with statically-linked OpenSSL, it provides comprehensive post-exploitation capabilities through COFF/BOF loading, extensive system commands, SOCKS proxy support, and flexible communication profiles. ]]></description>
</item>
<item>
<title><![CDATA[ [ARTICLE] Attack of The Extensions ]]></title>
<link>https://specterops.io/blog/2026/08/13/chromium-extension-c2-persistence/</link>
<guid>https://specterops.io/blog/2026/08/13/chromium-extension-c2-persistence/</guid>
<pubDate>Fri, 14 Aug 2026 04:57:18 +0000</pubDate>
<description><![CDATA[ [ Browser Security - C2 & Exfiltration ] Browser extensions can turn Chromium into a persistent foothold. This post introduces a way to silently install extensions turning Chromium browsers into a command and control (C2) platform for persistent cookie theft. ]]></description>
<author><![CDATA[ Andrew Gomez ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Beats Studio Buds: Insecure Pairing Window ]]></title>
<link>https://insinuator.net/2026/08/beats-studio-buds-insecure-pairing-window/</link>
<guid>https://insinuator.net/2026/08/beats-studio-buds-insecure-pairing-window/</guid>
<pubDate>Fri, 14 Aug 2026 04:56:16 +0000</pubDate>
<description><![CDATA[ [ Bluetooth - Exploits & Payloads ] We found a security vulnerability in Apple's Beats Studio Buds' pairing mechanism. The devices were found vulnerable to an insecure Bluetooth pairing window in which an attacker could pair with the earbuds without user interaction and establish a valid Bluetooth bonding. This would allow an attacker to eavesdrop on the victim through the earbuds' microphone, play audio on the device, or track the device via Bluetooth Low Energy. ]]></description>
<author><![CDATA[ Dennis Heinze ]]></author>
</item>
<item>
<title><![CDATA[ [ARTICLE] Ruby 4.0 Universal RCE Deserialization Gadget Chain ]]></title>
<link>https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain</link>
<guid>https://www.elttam.com/blog/ruby-4-0-universal-rce-deserialization-gadget-chain</guid>
<pubDate>Fri, 14 Aug 2026 04:51:53 +0000</pubDate>
<description><![CDATA[ [ Exploits & Payloads ] This post releases a new universal chain that turns a single Marshal.load into command execution on Ruby, built with new gadgets from untapped sources as well as old gadgets put to new use. ]]></description>
<author><![CDATA[ Luke Jahnke ]]></author>
</item>
</channel>
</rss>