Newsletter 2026-08-25

Posted on Aug 25, 2026

Another week, another round.


Mandiant presents what AVDH (Agentic Vulnerability Discovery Harness) has been doing for them and how it fits into the existing AI landscape alongside CodeMender.


Varonis reported a vulnerability to Microsoft in Copilot Personal. Almost as interesting as the one-click data exfiltration itself is the timeline. It was reported in December 2025, and the patches were released on 18.08.2026, the same day as the article. With the time from publication to exploit getting shorter and shorter, I find that a bit of a stretch.


LevelBlue takes a look at Shieldbreak by nightmare eclipse.


After OpenAI posted several CVEs related to Artifactory, Edra went looking for a pre-auth RCE and walks us through the journey from no credentials to RCE in 5 steps.


Talos has taken apart the Linux variant of the current SPECTRE malware and created a write up of the whole process in detail.


Julian Catrambone and Daniel Heinsen from SpecterOps apparently had a painful time with AWS and came to the conclusion that it made sense to write a new tool. True to SpecterOps style, the new tool is compatible with BloodHound Community Edition and goes by AWSHound. Definitely worth a try on the next AWS engagement.


Intruder introduces their new tool gitreaper, which they used to search a large number of Git repos for secrets and were quite successful at it.


Kaspersky has found what they describe as the first malware living exclusively in car head units, used for ad fraud and as a proxy network.


Varonis’ Hai Vaknin introduces the usernamemixed Azure endpoint, which through multiple return values allows enumeration of MFA-protected accounts and password spraying. Disabling legacy authentication is a solid mitigation here.


Threat actor profile on Qilin including MITRE mappings of their typical tactics, put together by Gurucul.


Jiří Vinopal from Checkpoint introduces the latest tool BTR_CLI, which takes Microsoft Defender’s Boot Time Removal Tool (BTR.sys) as a starting point to bypass EDR/AV and relies on Alternative Data Streams. The tool makes it possible to get a Ring-0 entry point from user mode.


Read you next week.