It's time to time-travel debug a fuzzer! How's your Saturday going? Original->
@droner.bsky.social
researcher. exploit dev. pdx. hacking @ atredis https://dronesec.net/
We have published our @rapid7.com analysis of CVE-2026-16232, the auth bypass in Check Point Security Management Server that was disclosed last week as a zero-day exploited in-the-wild. Full details and PoC: www.rapid7.com/blog/post/ra...
Next week at @blackhatofficial.bsky.social, join Matt Burch (@emptynebuli.bsky.social) as he dives into the ATM supply chain. If you are attending Black Hat, add this to your schedule! 📅 AUG 5 at 2:35 PM 📍 South Seas C&D, Level 3 #BHUSA2026 #Cybersecurity #InfoSec #BlackHat
Black Hat USA 2026
Black Hat USA 2026
blackhat.com
Apple MIE exploitation challenge blog.calif.io -> "In this blog, we'll share the details of the two vulnerabilities behind our [MIE bypassing] exploit" Original->
#Pwn2Own Ireland returns for 2026! We've got lot's of targets and plan on lot's of good times on the Emerald Isle. We've got a new registration process, so please read the rules carefully to know what to expect. Check it out at www.zerodayinitiative.com/blog/2026/7/... #P2OIreland
Zero Day Initiative — Pwn2Own Ireland 2026 – New Targets and Categories
If you just want to read the rules, you can find them here . Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skie...
zerodayinitiative.com
If you are heading to @defcon.bsky.social this summer, don't miss Atredian Matt Burch (@emptynebuli.bsky.social) and his continued CryptoPro research in Compounding Interest: Exploiting the ATM Supply Chain. See you at Track 4, Saturday Aug 8 at 12:30. defcon.org/html/defcon-...
DEF CON® 34 Hacking Conference - Main Stage Talks
1.1 Million Cameras, One Wildcard: Architectural Surveillance in an IoT Cloud Sammy Azdoufal
defcon.org
Qualys Security Advisory - Local Privilege Escalation in set-capabilities versions of snap-confine (CVE-2026-8933) www.openwall.com -> Original->
The slides from our @reconmtl.bsky.social talk with @nicolo.dev on agentic deobfuscation are now online. Topics: commercial VMs, anti-cheat, DRM systems, malware, and anti-agentic obfuscation. Slides: synthesis.to/presentation...
Need to do an NTLM relay over C2 but local priv-esc isn't possible? @logangoins.bsky.social new post walks through relaying NTLM auth out of a network and back in through red team infra to bypass traditional relay controls, plus how defenders actually stop it. Check it out: https://ghst.ly/4wA3fkg
There and Back Again: An Operators Guide on NTLM Relaying Egress
ghst.ly
@defcon.bsky.social 32 Matt (@emptynebuli.bsky.social) released 6 CE bugs affecting Diebold Nixdorf.. and now he is back with 9 more via the CryptoPro supply chain! 👀 Come join his #BHUSA briefing on Wednesday August 5th - you won't want to miss it! 🏧 🏦 @blackhatofficial.bsky.social
Black Hat USA 2026
Black Hat USA 2026
blackhat.com
Atredian Matt (@emptynebuli.bsky.social) spoke with @DarkReading.bsky.social about his upcoming @BlackHatofficial.bsky.social talk "The Cost of Obscurity: Exploiting the ATM Supply Chain" 🔒️ 💵 Bottom line: Disk encryption doesn't help if the keys are stored right next to the lock.
Fresh ATM Crypto Software Bugs: Jackpot or Bust?
Organizations, and possibly ATMs, are at risk of compromise, thanks to holes in a Microsoft BitLocker security wrapper.
darkreading.com
I recently sat down with @darkreading.bsky.social to discuss my new research into CryptoPro and my @blackhatevents.bsky.social and @defcon.bsky.social talk Exploiting the ATM Supply Chain.. I look forward to catching you this summer 🏧💰
Atredian Matt (@emptynebuli.bsky.social) spoke with @DarkReading.bsky.social about his upcoming @BlackHatofficial.bsky.social talk "The Cost of Obscurity: Exploiting the ATM Supply Chain" 🔒️ 💵 Bottom line: Disk encryption doesn't help if the keys are stored right next to the lock.
Am I crazy, is it common for dry runs to be the same week a CFP closes?
CFP for #OffensiveCon26 Tokyo edition is STILL open. We're looking for real, original work: cutting-edge security research, novel exploit techniques and deep technical investigations that actually move the field forward. And yes, AI it's also in the game.
CFP for #OffensiveCon26 Tokyo edition is STILL open. We're looking for real, original work: cutting-edge security research, novel exploit techniques and deep technical investigations that actually move the field forward. And yes, AI it's also in the game.
[RSS] Exploring cross-domain & cross-forest RBCD: part 2 www.synacktiv.com -> Original->
Thankfully the program actually knows how to triage bugs (the reopened it and triaged it themselves as a critical and paid it out) and clearly cares about the issues (they've already been fixed). This isn't the first time H1 messed up triage for bugs against this program. Makes you wonder.
I can't believe how bad bug bounty platforms have become. You have triagers who are (most likely) dipping their toes into the information security industry for the first time making critical gating decisions for billion dollar companies, putting users at risk because they can't threat model. FFS.
[RSS] Charting your way in: Helm template injection www.synacktiv.com -> Original->
[RSS] Reverse-engineering VMware's encrypted + compressed VM memory checkpoint format (vTPM "partial" encryption) github.com -> Original->
“A vulnerability in Apple’s ‘Hide My Email’ tool lets almost anyone discover a person’s real email address that is supposed to be hidden by the feature, and Apple has failed to fix it for more than a year…”
Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses
”Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” the person who reported the issue said.
404media.co
There are many incredible journalists in the cybersecurity field and I am very lucky to have worked with a lot of them over the last 10-15 years. I share that to say @zackwhittaker.com is definitely one of my favorites and his reflections on 8 years of writing a newsletter is a must read.
Reflections on eight years of writing ~this week in security~
Your favorite weekly cybersecurity newsletter marks eight years on the web.
this.weekinsecurity.com
[RSS] Off By !: Exploiting a Use-after-Free in the Linux Kernel blog.exodusintel.com -> Original->
Interested in becoming a speaker at Offensivecon Tokyo? You have three months to submit your talk on an innovative offensive security topic. More information here 👉️ cfp.offensivecon.jp/offensivecon...
NEW: Microsoft is so mad that a researcher published a handful of zero-days, and code to exploit them, that it is threatening legal action and even calling the cops on them. Yes, it's 2026, and one of the richest companies in the world is beefing about the ethics of disclosing bugs.
Microsoft under fire for threatening security researcher with criminal investigation | TechCrunch
A public spat between Microsoft and an independent security researcher reopens a long-running debate over who is responsible for securing software.
techcrunch.com
Talks from the OffensiveCon 2026 security conference, which took place earlier this month, are now available on YouTube www.youtube.com/playlist?lis...
OffensiveCon26 - YouTube
OffensiveCon 2026 Talks
youtube.com
Please tell your friends, four weeks before @phrack.org submission deadline! We also are seeking both interior and cover art. We are working with our friends at @pagedout.bsky.social again to create a fancy interior design for our main annual release!! Be a part of hacker history!
Submissions are still open! If you've been sitting on a bug, technique, war story, weird research rabbit hole, or beautifully cursed idea: now is the time. Write something worth archiving. Phrack CFP closes June 30. More details on how to submit at phrack.org/news
I've written something about Microsoft's apparent stance that not following made up responsible disclosure frameworks is criminal activity. doublepulsar.com/microsofts-s...
Microsoft’s stance on zero day exploits is a dumpster fire of their own making
Nightmare Eclipse vs Microsoft risks turning into a wildfire of corporate protect over cyber defence.
doublepulsar.com
It's basically summer which means you should be thinking about what video games you should be playing. We submit into record Command & Conquer Generals
We're looking for a cover for the next issue of Phrack! Retro sci-fi, terminals, dystopian systems, chrome futures, hacker manuals from an alternate timeline. Make something timeless and strange. Send your work or idea to arts@phrack.org Deadline June 30th