Newsletter 2026-08-18
Another week, another round. This week a little later and a tad shorter.
A Security has discovered multiple vulnerabilities in Zoom that allow a remote attacker in a meeting to hit all participants with a zero-click RCE.
Talos has come across a new phishing framework. It works as live phishing, meaning the user directly enters their MFA for the attacker and essentially hands over access themselves.
Practical Security Analytics has shared their approach (tool-assisted) to adversary emulation. A good example of how red teaming doesn’t have to be purely about objective completion.
Another Talos article, this time looking at AI-assisted attacks they have observed so far.
Tom Jarvis dug through patents and did a different kind of OSINT. He chose a Chinese rocket test track as his subject.
PortSwigger and TurtleSec have taken a very thorough look at HTTP header injection and are presenting their findings in a new research publication. Definitely worth reading if you do application testing from time to time.
Sentry found a path traversal vulnerability (CVE-2026-20685) in Apple’s Private Cloud Compute and was able to write files with root privileges without authorization, redirecting confidential AI telemetry data and inference metadata to their own server. Apple’s cryptographic attestation did not detect the tampered configuration files on the writable data volume. I’ll be honest, I’m not deep enough in the topic to describe it any better than that.
Intel Techniques has updated their available OSINT tools, along with their firewall guide and blog hosting.
Read you next week.