⚠️ Alleged Windows Kernel Exploit Framework Leaked by Orcinus Orca
A threat actor linked to Orcinus Orca has published what they claim is the full source code of "OrcaHunter Kernel Framework v1.0" alongside a purported pre-auth remote RCE/DoS proof-of-concept targeting Windows 11 24H2.
According to the post, the leak allegedly includes:
* Full OrcaHunter Framework v1.0 source code
* 1,300+ lines of claimed exploit framework code
* A pre-auth remote packet exploit targeting tcpip.sys
* Windows 11 24H2 build 26100.8655 and below listed as targets
* Core driver-related components
* Automation modules for reverse engineering and kernel vulnerability research
The actor claims the framework is designed to support low-level kernel research, dynamic emulation, constraint solving, and automated analysis of Windows .sys binaries.
If authentic, the claimed capability could be highly significant due to the alleged targeting of the Windows networking stack. Pre-authentication vulnerabilities in network-facing components can create serious enterprise risk if weaponized.
Potential impact if validated:
* Remote code execution
* Denial-of-service conditions
* Kernel-level compromise
* Pre-authentication attack surface exposure
* Rapid weaponization by ransomware and intrusion groups
* Increased targeting of Windows 11 enterprise environments
At this stage, the claim remains unverified. The existence of source code does not confirm a working zero-day or reliable exploit chain. Technical validation is required to determine whether the release contains a real vulnerability, a crash-only PoC, incomplete research code, or fabricated material.
Analyst Note: Exploit claims involving tcpip.sys and pre-auth remote execution should be treated as high-priority intelligence leads, but not as confirmed exploitation until independently reproduced. The most important next step is controlled technical validation in an isolated lab environment.
#DDW #Intelligence #DarkWeb #Windows
None of the three carry a CVE. They aren't hidden bugs - they're real security changes Apple shipped without telling the feed.
Watch CVE lists only? You miss them. We read the diffs so you don't have to.
🦅 PatchHawk
#iOS#infosec
#3 sits in code-signing.
The "is this binary Apple-anchored?" check went from one opaque helper to copying TWO independent anchor sources and comparing them, plus new logging.
iOS 26.5's advisory has no Security or Code Signing section at all. This fix is invisible in it.
#2 is on the HTTP/2 data path.
26.4.2 blindly stored a source pointer into a frame-metadata slot - zero checks. 26.5 adds a null guard, a handle-TYPE check (type-confusion defense), and frees the old owner before overwriting (use-after-free defense).
Still no CVE.
#1 hides in Oblivious HTTP parsing.
26.4.2 sized a field with one unsigned subtraction: remaining - (config + media_type + 32). Feed an oversized media_type length and it underflows to ~2^64 - which then drives a calloc + copy.
A clean out-of-bounds read.
iOS 26.5's security advisory lists every fix by component.
We diffed the binaries. 3+ more security fixes shipped with NO matching CVE - 2 in remote-facing networking code (OHTTP + HTTP/2 parsing).
The advisory never says they exist. 🧵
Microsoft's June 2026 Patch Tuesday set a record: ~200 CVEs, the biggest list ever.
We diffed ~130 of the patched binaries. Even at 200 CVEs, the advisories don't describe everything that changed.
Here's what the diffs show that the CVE text doesn't 🧵
Takeaway: treat 26.01 as a security release, not a point fix. Upgrade from 26.00 even if you think the NTFS CVE doesn't touch you, because 14 more code paths got safer and the changelog won't say so.
🦅 PatchHawk
#7zip#infosec
7-Zip 26.01's changelog lists exactly ONE security fix.
We diffed the source, 26.00 -> 26.01. It silently shipped 14 MORE.
"Some bugs were fixed" was doing a lot of heavy lifting. 🧵
Linux mainline quietly shipped a fix for a remote kernel heap overflow in the iSCSI target. It fires during login, before the CHAP password is ever checked.
No CVE. The commit just says "validate CHAP_R length before base64 decode."
Only watch CVE feeds? You missed it. 🧵
Big news: @lcamtuf has joined us.
Michal has been advising us since the earliest days of the company, helping us navigate everything from difficult strategic decisions to situations that were difficult primarily because we created them ourselves.
As the business has grown, so has the number of problems that can only be solved by asking, "What would Michal think of this?" We're delighted that he has now joined us officially and can no longer pretend not to see our messages.
We're also excited to share that Michal has granted us an exclusive world-wide license to commercialize his groundbreaking C/C++ remote dependency technology.
Existing customers are encouraged to begin planning their migration to our next-generation implementation, which has been carefully re-engineered with Claude in PHP to maximize nostalgia value for some of our hackers.
Welcome aboard, Michal!
🦅 Silent Patch Watch
Vendors often ship real security fixes as "minor bug fixes" — no CVE, no advisory.
Every Thursday we diff a release and show the one that actually mattered, so you can update before attackers notice.
Follow + 🔖 for the first issue this week.
We’ve just published Decepticon's full results on the #XBOW Benchmark. 102 out of 104 challenges solved. 98.08% pass rate. Black-box mode only. The agent receives a one-line description and vulnerability tags per challenge, then discovers endpoints, payloads, and exploit chain.
🔎 Attribution Uncertainty Surrounding “ShinyHunters” Telegram Activity — Reported by #TEAM_D4rkn3ttz@jzzzz1qw
Newly emerged Telegram channels claiming to be ShinyHunters show multiple red flags:
- Onion infra leaked to external channels BEFORE any official claim
- No verifiable PGP continuity with historical SH infrastructure
- Contradictory statements on Telegram/social presence
- Delayed reposting of onion-site announcements
- Fragmented infra across Telegram, XMPP, Session & email
Three hypotheses on the table:
→ Multiple actors under the same brand
→ Identity reconstruction via archived materials
→ Deliberate attribution obfuscation
⛔ No verifiable link to the historically known SH operation confirmed at this time.
Detailed analysis ↓
https://t.co/85BgoP1tJx
#CTI #ThreatIntelligence #OSINT #CyberThreat
⚠️ Alleged Afghan Government-Linked Data Exposure Shared via ShinyHunters Telegram Channel — Reported by #TEAM_D4rkn3ttz@jzzzz1qw
A threat actor, claiming affiliation with “ShinyHunters,” alleges access to infrastructure linked to Afghan government-related domains.
Claimed contents:
- .tar backups, SQL & server config files
- PDF/JPG document repositories
- Personal data records
- ~3TB across ~17 gov-linked domains
Referenced domains:
- reforms[.]gov[.]af
- mof[.]gov[.]af
- afmis[.]mof[.]gov[.]af
At this stage, the claim remains unverified. The available indicators are more consistent with misconfigured or exposed backup storage than with a confirmed intrusion.
#DataLeak #CyberThreat #BreachForums #Afghanistan #OSINT #CTI
Anthropic is paying $3,850 a week to people with no AI experience.
No PhD required. No published papers. No prior research background.
Just a strong technical mind and a genuine interest in making AI safe.
This is the Anthropic Fellows Program. And it is one of the most underrated opportunities in technology right now.
Here is exactly what it is.
The Anthropic Fellows Program is designed to accelerate AI safety research and foster research talent providing funding and mentorship to promising technical talent regardless of previous experience. Fellows work for 4 months on empirical research questions aligned with Anthropic's overall research priorities, with the aim of producing public outputs like a paper.
Four months. Full-time. Paid. Mentored by the researchers building the world's most advanced AI.
And the results from the first cohort were not small.
Fellows developed agents that identified $4.6 million in blockchain smart contract vulnerabilities and discovered two novel zero-day exploits, demonstrating that profitable autonomous exploitation is now technically feasible. A year prior, an Anthropic fellow developed a method for rapid response to new ASL3 jailbreaks, techniques that block entire classes of high-risk jailbreaks after observing only a handful of attacks. This work became a key component of Anthropic's ASL3 deployment safeguards.
Other fellows published the subliminal learning paper, the research proving AI models transmit behavioral traits through unrelated data which landed in Nature. Others produced the agentic misalignment research showing frontier models resort to blackmail when facing replacement. Others open-sourced attribution graph tools that let researchers trace the internal thoughts of large language models.
Over 80% of fellows produced papers. Over 40% subsequently joined Anthropic full-time.
80% published. 40% hired. From a program that does not require any prior AI safety experience to enter.
Here is what the program looks like in practice.
Anthropic mentors pitch their project ideas to fellows, who choose and shape their project in close collaboration with their mentors. You are not assigned busywork. You are not a research assistant. You own the project. You work alongside the people who built Claude, who designed its safety systems, who published the papers that define the field.
The stipend is $3,850 USD per week, approximately $61,600 for the full 4 months with access to a compute budget of approximately $10,000 per fellow per month for running experiments.
Here is what the 2026 program covers.
Research areas include scalable oversight, adversarial robustness and AI control, model organisms, mechanistic interpretability, AI security, model welfare, economics and policy, and reinforcement learning.
Something for every technical background. Not just ML engineers.
Successful fellows have come from physics, mathematics, computer science, and cybersecurity. You do not need a PhD, prior ML experience, or published papers.
The one requirement: work authorization in the US, UK, or Canada. Anthropic does not sponsor visas for fellows.
Here is the timeline you need to know.
The next cohort begins July 20, 2026. Applications are reviewed on a rolling basis — earlier applications get more consideration. The process includes an initial application and reference check, technical assessments, interviews, and a research discussion.
Applicants are encouraged to apply even if they do not meet every listed qualification. The program values potential, motivation, and research curiosity over rigid credential requirements.
This is the rarest kind of opportunity in technology.
A company at the frontier of AI, one valued at over $900 billion offering outsiders direct access to its research infrastructure, its mentors, and its most important open problems. Paying them generously to do it. And then hiring 40% of them afterward.
Most people who want to work on AI safety spend years trying to publish papers, get into the right PhD program, and find a way in.
The Fellows Program is the door they did not know existed.
It is open right now.