July 30, 2026 at 08:56PM

■□□□□ Israel: The Jewish 🐁 RAT from 2012 Flame (sKyWIper): A highly modular, highly complex malware platform (discovered in 2012) deployed in Middle Eastern intelligence operations. While primarily a data-gathering and espionage toolkit rather than a standard commercial RAT, it featured remote-control capabilities including audio recording, network traffic sniffing, screenshot capture, and command-and-control execution.

July 28, 2026 at 10:50PM

■■■■□ 🖥️ VMkatz — Extract Windows Secrets from Virtual Machine Snapshots. An open-source incident response and security research tool that analyzes virtual machine memory snapshots and disks to extract forensic artifacts and credential material from Windows systems during authorized assessments. ✨ Features • 💾 Supports VMware, VirtualBox, QEMU/KVM, Hyper-V, and raw disk formats • 🔍…

July 28, 2026 at 01:52PM

■■□□□ Thread: CrowdStrike published a blog at the beginning of the month, exposing new prompt injection techniques. This time, 18 new injection techniques have been added, bringing the project’s total coverage to over 200 different injection techniques. The CrowdStrike AI security research team claims to maintain the industry’s largest-scale prompt injection classification system, providing a…

July 25, 2026 at 11:27PM

👩‍💻 Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities. Technical Summary: https://depthfirst.com/research/going-depthfirst-achieving-gitlab-rce-via-two-ruby-memory-corruption-vulnerabilities PoC: https://github.com/wupco/gitlab-rce-demo/tree/main Overview: https://depthfirst.com/gitlab-rce-oj-spill Thread: 🧵 https://x.com/i/status/2080763568044290535

July 25, 2026 at 07:52PM

 Malicious sites use JavaScript to build malware in browser memory A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. […] https://www.bleepingcomputer.com/news/security/malicious-sites-use-javascript-to-build-malware-in-browser-memory/

July 25, 2026 at 01:52PM

■■■■□ Open-sourcing RCE implementation for CVE-2026-42533 This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!). F5 released the security advisory a week ago on July 15th. Fun fact: this bug appears to have been found concurrently by multiple groups. Our team at…

July 24, 2026 at 11:03PM

■■■□□ Microsoft admits Windows 11 has a GDID tracker with no off switch, first documented publicly in an FBI hacker complaint. https://www.windowslatest.com/2026/07/10/you-cant-fully-disable-microsofts-gdid-windows-11-tracker-but-these-settings-limit-what-it-captures/

July 21, 2026 at 05:09AM

■■■■■ An interesting thread on the Frag Gap (CVE-2026-53362/CVE-2026-53366) https://blog.qwerty.or.kr/en/posts/cdf3008a-c1a4-4eca-a373-aa3a2bcf1489/ Exploit code: https://github.com/qwerty-po/security-research/tree/cve-2026-53362/pocs/linux/kernelctf/CVE-2026-53362_lts https://x.com/i/status/2079239619611332780