#NextJS: Two Critical Vulnerabilities in NextJS allow unauthenticated #RCE: one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604).
Upgrade your NextJS immediately to v15.5.24 or 16.3.3!:
👇
https://t.co/bxfeAl7AES
this wild defcon talk is finally out
researchers created a fake defi startup, hired lazarus it workers, put them into a sandbox and recorded their tooling, workflows, and faces from inside the operation
starts at 5:46:09
https://t.co/NBo6pw4nOl
The watchTowr team is rapidly reacting to the Remote Code Execution vulnerability chain (CVE-2026-63030 and CVE-2026-60137) in WordPress Core across our client-base, a just-disclosed flaw in the REST API batch dispatcher that leads to Remote Code Execution via SQL Injection.
Need to understand your exposure?
WifiForge provides a safe and legal environment for learning WiFi hacking. Based on the open source mininet-wifi, this project automatically sets up the networks and tools needed to run a variety of WiFi exploitation labs, removing the need for the overhead and hardware normally required to perform these attacks.
Credit/Resource: https://t.co/0j7ZoeaDRR
"Urgent Security Notice re: Your Sentry Organization"
Someone tried to hack Sentry-using apps that use coding agents by
1. Sending a fake bug alert to their project (all you need is the app's public Data Source Name)
2. The fake bug tried tricking a coding agent trying to fix it into installing some a compromised NPM package
3. The compromised package would send the env contents of the machine to advisory-tracker[.]com/api/v1/telemetry
This highlights a crucial thing for using agents in an automated way:
I decided to publish my internal Azure Entra ID tool. There are a lot of these already available, but I've added some interesting features that have made a difference for me over the years. You can capture token through the browser using playwright
https://t.co/xiZaz0PKsC
#Azure
VeeamDumper by @MWRCyberSec
Veeam is a ~ backup solution. The dumper detects DB config, pulls registry decryption info and decrypts credentials from the DB.
📕Blog: https://t.co/E7wyCZk8QK
🔧Tool: https://t.co/I3STJTX4Q4
🔩BOF: https://t.co/q5hZBIYhBy
The Internet is falling down, falling down, falling down
Welcome back to another disaster - this time, an Auth Bypass in cPanel/WHM, tracked as CVE-2026-41940
Enjoy with us..
https://t.co/bOzCPy8iS1
So Microsoft Copilot has its own App-Bound Encryption now. The standalone Copilot app (mscopilot.exe) is a full Chromium browser based on Edge, ships with its own elevation_service.exe, a dedicated COM interface (IElevatorCopilot), and a separate ABE key scope.
Decrypting the ABE key gives us some cookies (https://t.co/jDTRHwilyP auth, MUID, MSAL session, Cloudflare tokens) and the Microsoft Account token from the token_service database.
Local Storage also holds MSAL.js cached tokens. An ID token, two access tokens (chatai.readwrite for the Copilot API + https://t.co/Zgut26Y35L for Microsoft Graph), and account metadata for the signed-in MSA.
These use MSAL's own browser-bound CryptoKey encryption, not ABE.
Edge 147 also quietly hardened IElevator2 by switching from oleaut32 to a custom proxy/stub but simultaneously registered IElevatorCopilot with oleautomation. Closed one door, opened another.
Next up: decrypting the MSAL tokens? 🤔
Zscaler ThreatLabz has published a technical analysis of APT37's Ruby Jumper campaign, a DPRK-backed attack leveraging Windows LNK files and newly discovered tools: RESTLEAF, SNAKEDROPPER, THUMBSBD, VIRUSTASK, and FOOTWINE. This campaign leverages removable media to enable surveillance and execute commands on air-gapped systems.
Read our full analysis here: https://t.co/Gadrbxzoom
Forgot to post it, but the recording of my Black Hat talk was released last week. If you're interested in all the hybrid AD attack surface you never knew about, give it a watch: https://t.co/EraL3TPuOB
❗️ ExploitPack[.]com has allegedly been compromised by a threat actor who claims to have exploited a vulnerability on the site to exfiltrate all exploits spanning 2020–2026, totaling approximately 500 MB of data including exploit code, shellcodes, and related files, with plans to release additional kernel and control pack exploits soon.
Remember the old Control Panel applets that were used for initial access. I found that these DLLs can be loaded into memory remotely through an interesting DCOM object, allowing to achieve new command execution technique during lateral movement. Details:
https://t.co/93WgyiuNSJ
THC Release 💥: The world’s largest IP<>Domain database: https://t.co/o4F8M1Pqi1
All forward and reverse IPs, all CNAMES and all subdomains of every domain. For free.
Updated monthly.
Try: curl https://t.co/5V2xLadmx5
Raw data (187GB): https://t.co/cBZOSAE89K
(The fine work of messede 👌)
Interested in the security of AI Agents 💁🛡️?
Then you've likely heard of "prompt injection", but do you know what "task injection" is? If you're curious, check out our latest post for a description and some real-world examples we discovered.
https://t.co/pWdDGX6M0W https://t.co/P8ndgCXtH1