Attacks & Vulnerabilities
|
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials (3 minute read)
JetBrains is urging users of Cadence, its hosted cloud computing service, to revoke and rotate all credentials after unidentified attackers exploited CVE-2026-63077 (CVSS 9.8) to breach its own environment. The vulnerability stems from deserializing untrusted data and allows an unauthenticated attacker with access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process. Attackers reached a 2024 Cadence backup holding AWS IAM credentials, S3 files, PyCharm-synced source code, and personal data, so defenders should treat all executions as untrusted and audit connected AWS accounts, registries, and repositories for activity since August 8.
|
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities (2 minute read)
Threat actors are chaining CVE-2026-81578 and CVE-2026-82078, an authentication bypass and remote code execution pair in PaperCut, to steal credentials from K-12 schools and major universities across the US and Europe. Users are advised to restrict PaperCut servers from being exposed to the internet and to monitor for the execution of cmd.exe, powershell.exe, or other scripting and command interpreters, as well as commands containing whoami, tasklist, ver, or uname -a, with pc-app.exe as the parent process.
|
|
ASCII smuggling crosses over from AI prompt injection to phishing evasion (11 minute read)
Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII smuggling. Rather than hiding instructions from people while exposing them to AI models, the attacker used the characters to split financial lure words so email filters could not parse them, turning "funding" into fun, an invisible tag character, then ding. The code points come from the deprecated Unicode Tags block, U+E0000 to U+E007F, which renders as nothing at all, and Microsoft surfaced the campaign while hunting for prompt injection in Defender for Office 365, where the first version of the signature kept firing on the England, Scotland, and Wales flag emoji because each is built from a base flag code point plus an invisible tag sequence. Defenders should strip invisible Unicode before content signatures run, treat unexplained tag characters as a high-confidence anomaly, and apply the same normalization upstream of any AI assistant that ingests email.
|
Improving our alignment and security efforts (12 minute read)
Anthropic paused cyber evaluations after three July incidents exposed real systems through third-party environments. It added real-time classifiers, stronger sandbox isolation, and outbound network blocks, while partners testing reduced-safeguard models must verify isolation, define scope, validate tasks, and stop violations. The company also froze RL environment changes, flagged over 10% for defects, and rebuilt review controls.
|
Turning Chrome Remote Desktop into Pure Red Team Ops (12 minute read)
A researcher at ZeroTrace Lab went down a rabbit hole to try and understand how they can disable the Chrome Remote Desktop connection banner after it was bothering them on a computer they remote into. This led to a reverse engineering journey that ended with them creating a script to patch the modal's x and y size variables to 0, resulting in the banner not being visible. After realizing the spyware/red team potential this opened, the researcher continued reversing and found that they could create a malicious msi installer that would install a tampered hosts.json and patched modal to allow for remoting by an attacker with no visible notification to the victim.
|
|
Hetty (GitHub Repo)
Hetty is an HTTP toolkit for security research. It aims to be an open-source alternative to commercial software like Burp Suite Pro, with powerful features tailored to the needs of the infosec and bug-bounty community.
|
Pigeon (GitHub Repo)
Pigeon allows creating delegated authority for AI agents. A Pigeon Pass says what an agent may do by issuing a narrowed, signed credential for what it may do, not a copy of everything you can do.
|
IRFlow Timeline (GitHub Repo)
IRFlow Timeline is a native macOS forensic timeline analysis tool. The 1.0.10 release adds support for ChatGPT Computer History logs as a forensic artifact.
|
|
Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the US and the Middle East (9 minute read)
Gambit Security tied Ababil of Minab, the pro-Iranian persona that claimed responsibility for the attack on LA Metro in March, to Black Shadow, an Iran-linked group that the Israel National Cyber Directorate attributed to Iran's Ministry of Intelligence and Security, undercutting the crew's claim to be a new standalone hacktivist outfit. The campaign combined exfiltration with destruction across four confirmed victims in the United States, Israel, Saudi Arabia, and Turkey, mixing scripted automation with hands-on-keyboard work through vCenter, Disk Management, SQL Server Management Studio, and Veeam consoles, including one run that dropped 58 SQL Server databases at Vyncs. Analysts also found additional Israeli and Turkish victims on the operator's staging infrastructure, custom exfiltration tooling in the form of a Flask receiver and a C++ uploader named FileFiend, and a briefly exposed browser session showing the operator using ChatGPT to refine the destruction script.
|
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests (3 minute read)
OpenAI released GPT-6 Astra after it scored 100% on ExploitBench, up from GPT-5.6 Sol's 78.5%. Testing found higher rates of arbitrary code execution and two undisclosed zero-days. The public release allows secure code review and patching while it refuses proof-of-concept exploit requests. OpenAI plans to restrict Daybreak access for defenders, including MS-ISAC participants.
|
|
Love TLDR? Tell your friends and get rewards! |
|
Share your referral link below with friends to get free TLDR swag!
|
|
|
| Track your referrals here. |
|
|
|
0 Comments