Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AI18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
A critical 18-year-old use-after-free vulnerability in Linux's SCTP networking code enables local privilege escalation to root access and container escape. Tencent researchers demonstrated successful exploitation to break out of containers and compromise the underlying host system. Patches are available in stable kernel versions released August 3, 2025, making immediate updates essential for syste
AIGrowing Up The Hard Way
Open source software enjoyed two decades of informal, trust-based development characterized by free distribution and minimal oversight. This idealistic period operated without formal governance, licensing enforcement, or accountability mechanisms. The industry is now facing a maturation phase that requires more structured approaches to sustainability and security.
AIAI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
PortSwigger's AI-assisted research system, HTTP Terminator, developed by James Kettle, successfully identified novel HTTP desynchronization attack techniques after analyzing 30,000 candidate attack vectors. The research also uncovered a zero-day vulnerability in Apache Traffic Server through a separate human-guided investigation, demonstrating the effectiveness of combining AI automation with expe
AIMicrosoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
A widespread phishing campaign is leveraging adversary-in-the-middle (AitM) techniques to compromise Microsoft 365 accounts, specifically targeting employees involved in payroll and financial operations. The attackers use residential proxies to mask malicious sign-ins as legitimate consumer traffic, making detection more difficult and enabling unauthorized access to sensitive financial communicati
AIMalware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has unveiled NatJack, a novel attack methodology that exploits network address translation (NAT) vulnerabilities to hijack TCP sessions, manipulate DNS responses, and compromise network infrastructure. The techniques, demonstrated at Black Hat USA 2026, enable attackers to expose victim IP addresses, exhaust NAT tables, and gain unauthorized access across various
AINew NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has revealed NatJack, a new class of attacks that exploit network address translation (NAT) vulnerabilities to hijack TCP sessions, spoof DNS responses, and compromise network security. Presented at Black Hat USA 2026, the research demonstrates that these vulnerabilities affect multiple independently developed NAT implementations, including Windows systems, indica
AITeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
Threat actor TeamPCP has been identified as conducting cyberattacks since 2020, initially targeting internet-facing infrastructure through Redis attacks before pivoting to software supply chain campaigns. The attribution is based on overlapping domains, malware deployment methods, staging techniques, and backend infrastructure patterns that connect the earlier Redis compromises to more recent supp
AICisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs
Cisco has released security patches addressing 12 vulnerabilities in its Catalyst SD-WAN and IOS XE Software, including three critical flaws with CVSS scores of 9.8. The vulnerabilities affect systems regardless of device configuration and impact both autonomous and controller mode deployments. These issues were discovered during a comprehensive internal security review.
AINew Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
A critical Linux kernel vulnerability dubbed Zapscape (CVE-2026-64561) has been discovered that enables attackers with kernel privileges in L1 guest VMs to break KVM isolation and execute code on host systems. The flaw resides in KVM/x86's shadow memory management unit (MMU) and poses significant risk in environments where nested virtualization is exposed to untrusted guests.
AINew Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
MIT CSAIL researchers have discovered a new attack called INTERRUPT INJECTION that can bypass Spectre v2 defenses on Intel and AMD CPUs. The attack exploits a timing vulnerability where an unprivileged Linux program can inject a hardware interrupt between the processor sanitizing its branch predictor and the kernel using it, effectively re-poisoning the predictor after security measures have been
AIThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories
This week's security landscape demonstrates how attackers are exploiting minimal user interaction through automated execution vectors. Threats now leverage exposed infrastructure, supply chain vulnerabilities, and trusted defaults to achieve compromise before users can respond. The attack surface has expanded to include repository auto-execution, hidden malicious packages, weaponized documents, an
AIOver 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
Forescout's research revealed 4,407 internet-exposed Rockwell Automation PLCs globally, with 2,844 in the United States. Notably, 22 of these exposed controllers were located in cities recently targeted by cyberattacks on water utilities, with 19 sharing the same mobile carrier network, raising significant concerns about critical infrastructure security.
AIApple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses
Security researchers have identified a vulnerability in Apple's iCloud Private Relay that can expose users' actual IP addresses despite the service's dual-hop architecture designed to protect privacy. The issue affects the privacy tool introduced in iOS 15, which routes Safari traffic through two separate relays to prevent any single party, including Apple, from identifying the origin of web reque
AICryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps
Security firm Coinspect has traced $5.7 million in cryptocurrency wallet drains to a weak random number generator in CryptoJS that has existed for 12 years. The vulnerable CryptoJS.lib.WordArray.random() function provided insufficient entropy for generating recovery phrases in five affected crypto wallet applications, enabling attackers to compromise wallets in two major sweeps since late May.
AIAWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Critical security vulnerabilities have been discovered in agent infrastructure from AWS, Google, and Vercel that allow attackers to bypass AI model authorization and directly trigger agent tools. These flaws enable malicious instructions to reach tools without running through the model, circumventing system prompts, content filters, and guardrails designed to prevent unauthorized actions.
AIAttackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers exploited a SQL injection vulnerability in a public-facing web application to compromise an Oracle database, then deployed a post-exploitation toolkit called 'khunt' by compiling Java source code directly within the database engine rather than writing executables to disk. This technique allowed them to execute commands from inside Oracle and escalate privileges to Windows SYSTEM level ac
AIRansom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
Maksim Silnikau received a 16-year prison sentence for creating and operating Ransom Cartel, a ransomware-as-a-service (RaaS) platform that operated from 2021 to 2023. The operation targeted at least 18 companies across the United States and internationally, representing a significant law enforcement action against cybercrime infrastructure providers.
AIChinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers at VulnCheck have discovered a factory-installed backdoor in at least 20 router models manufactured by Chinese company Zbtlink. The backdoor, present in all 21 available firmware images spanning over two years, automatically initiates unauthenticated root shell access and attempts to communicate with Chinese servers.
AISnowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka, a 26-year-old Canadian, pleaded guilty to multiple federal charges including computer fraud and wire fraud related to the 2024 Snowflake customer account breaches. The attacks compromised at least 165 organizations and exposed personal data of over 100 million individuals, with Moucka personally profiting at least $495,000 from the scheme.
