Sitrep 2026-09-14
A weekly round-up of security and tech news.

News
- Detecting and countering misuse of AI: September 2026 - Detailed writeup of what malicious activities Anthropic is seeing and disrupting.
- 216,000,000 Spy TVs | The LG Smart TV Problem - LG Smart TVs are doing all sorts of nasty stuff.
- GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI - Threat actors are transitioning from prompts to agentic workflows. x
Techniques and Write-ups
- WeWorm - Analysis of zero-click worm to spread through WeChat calls across iOS and Android
- Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF - GreyNoise observed an adversary using AI to weaponize an exploit and breach organizations
- Pivotc2 FortiGate Post-Exploitation RAT - Write up of CVE-2025-25249 heap-based buffer overflow and PivotC2
- Survival of the Basics - Survival of the Basics: Which Security Fundamentals Were Secretly Relying on Lazy Attackers?
- The Anthropic Glasswing Receipts Are Starting to Trickle In - A look at Anthropic’s claims vs reality
- Once in a BlueMoon - Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days
- REVSTEALER ramps up - Elastic Security Labs details emerging infostealer targeting gamers
- PaperCut NG/MF Zero-Day: CVE-2026-81578, CVE-2026-82078 (Active Exploitation Underway) - Intel from active exploitation of a PaperCut honeypot x
- Beltdown:EscapingtheClaudeCodesandbox - escaping the claude code sandbox on macOS
- The Decompilation Book - The first three chapters of “The Decomplilation Book” x
- Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine - Remote Code Execution in the GoJa Javascript Sandbox x
- Moria & Mithril - ioT Firmware Extraction and Analysis Without External Dependencies x
- MAccConc - Testing race conditions with memory access tracing and stack-based delay injection x
- NetNTLMv1 Is Dead. Long Live NetNTLMv1 - “Fitting lossless rainbow tables on a 4 TB disk and cracking NetNTLMv1 with WebGPU and ntlmrain.”
Tools and Exploits
- KeySniper - CVE-2026-18963 unauthenticated Keycloak account takeover via the reset-credentials flow. x
- Fileless ELF Execution via Kernel Keyring - stage an ELF in slab memory and execute it via userland exec x
- zvec-grep - Local-first search across your workspace, built for humans and AI agents.
- Generating Alerts in Your Microsoft Defender Environment - A practical lab guide for validating Microsoft Defender for Endpoint protections, detections, alerts, and Advanced Hunting telemetry. x
- RustHound-CE - RustHound-CE version 2.5.13 x
- PassTheCert-rs - cross platform pure-Rust implementation of the PassTheCert technique x
- moria - IoT firmware identification and extraction
- mithril - IoT static scanner for secrets, SBOM, CVEs and more
- MAccConc - tooling for exploring Linux kernel race conditions and for general kernel debugging
Talks and Videos
- Using the Empire C2 on Hack Smarter’s DarkHaven Range - Part 1 - Jacob Krasnov and Rey Bango run through red teaming the Hack Smarter Labs cyber range DarkHaven x