Newsletter 2026-07-28
Another week week, another round.
An interesting thought to design platforms to be safe not just for children but for people in general, with child protection added on top. The focus here is on doom scrolling, endless notifications, fake news, and so on. Things we consider unsuitable for children because they influence them also quite clearly influence adults.
Paradoxis found a CVE in Foxit PDF and published their writeup.
We had an article here recently (I think) about an attacker being identified via an ID used by Microsoft. Zero Trace Labs has now published a GDID analysis.
TrustedSec gives a fairly thorough demonstration of device code phishing in M365.
Google is updating its naming schema for threat actors. The new schema consists of two words, where the first is a unique, memorable name and the second reflects attribution, motivation, or activity. Other factors may also play a role.
Another perspective on wp2shell, this time from Elastic, including detections that Elastic registers during exploitation.
A second version of the MCP standard is set to be released on 28.07. The beta is already available. The new version brings several security improvements.
While we’re on the topic of MCP, the Web Scraping Club has written a short guide on using the SearchAPI MCP server. I was already familiar with services for agentic searches, but it never hurts to have a broader setup.
Calif published a bypass for Apple’s memory security system MIE a while back and are now launching an exploitation challenge.
Read you next week.