Newsletter 2026-07-14
Another week, another round. This time, the focus seems, by coincidence, to be more on escapes in various forms.
Synacktiv’s Paul Barbé presents a Helm template injection
SpecterOps has released a new LLM jailbreaking tool
The DFIR Report has analyzed and written up an Akira incident. A very detailed report, as usual, but also very exciting.
A short and crisp explanation of a container escape via IPv6, including a PoC
Elliot Belt has recaptured his talk from the HackTheBox Meetup on his blog. Even though the clickbait title “How to Make Your First Billion in Bug Bounty (Easily)” suggests something bad, the post still offers a few exciting insights. Several research papers are also linked for diving deeper into the topic.
Kimsuky relies almost exclusively on built-in Windows tools and COM objects in its current multi-stage infection chain. Robin Dost presents the approach in detail.
Daniel gives a few tips on his blog for reports that he would rate as excellent.
Josh Lospinoso is releasing a six-part series on reading bus systems. On board: CAN, DBC, UART, Modbus RTU, and MIL-STD-1553.
A chain of 3 vulnerabilities in QEMU CXL can allow a root user in the guest system to achieve RCE on the host system with a complete ASLR bypass. I wouldn’t claim to have understood everything, but I found it exciting to read.
Another QEMU escape, but this time found with the help of AI.
Gurucul has put together an extensive write-up on ShinyHunters, including MITRE mapping
Arctic Wolf analyzed various Anubis ransomware incidents and identified common steps across different affiliates. Both VPN credentials and the exploitation of CVEs are used. Regular tools are often used, with fewer C2 agents involved.
Backdoors and Breaches has a new expansion
Norwegian police were able to trace Monero in one case, which had long been considered untraceable. Nevertheless, Monero is not generally broken.
Read you next week.