Sitrep 2026-08-31
A weekly round-up of security and tech news.

News
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia - Alleged members of TeamPCP arrested in Australia
- Best Practices to Mitigate Threats in Development of ASICs - NSA ASICs Best Practices Threat Catalog and ASICs Level of Assurance x
- The Hugging Face incident and the road ahead - OpenAI’s investigation into how the collective escaped containment and compromised hugging face x
Techniques and Write-ups
- A Tale of Two SOCs: Insights From Two Red Team Assessments - Detailed write up comparing defensive responses from two red team engagements x
- SLEEPWALKER: A Passive Backdoor With Its Own Command Language - C2 that listens instead of beaconing out with a custom bytecode instruction format x
- Local Privilege Escalation To System In Wibu-Systems CodeMeter Application - “describes the process of finding and exploiting a local privilege escalation in the Wibu-Systems CodeMeter application”
- I’m in your logs now: deceiving analysts and blinding EDRs - Generating telemetry for testing turns into an exercise in blinding ETW via cloud limits. x
- Chinese Implants in the Supply Chain - Uncovering multiple implants on a $88 router from amazon x
- UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range - Getting root on humanoid robots x
- When it Snows it Pours – Anatomy of a ServiceNow Red Team - The tools you use to manage systems are always some of the most tempting targets x
- Cleartext Credential Recovery in ServiceNow - Keep an eye out for the creds you store in managment systems x
- CVE-2026-66145 - SonicWall GMS - Unauthenticated RCE and Encrypted Password Hash Extraction
- GDID: The Windows Global Device Identifier - Deep dive on GDID with an extraction tool x
- Vulnerability Research on Bitdefender’s Antivirus Engine - Part one in the series builds a linux harness for the AV components x
- University Leak Exposes Russia’s Military Cyber Training Pipeline - Analysis of leaked training documents related to Russian military intelligence and cyber operations.
Tools and Exploits
- SLEEPWALKER - SLEEPWALKER recreated with Deepseek v4 Flash/Qwen 3.8 x
- CrystalPotato - Crystal port of GodPotato x
- dploot - is Python rewrite of SharpDPAPI x
- Recon Skills - “skills for external reconnaissance, web applications, APIs, authentication, vulnerability validation, attack-path analysis, and reporting.” x
- CVE-2026-18963 - Keycloak reset-credentials bypass
- CVE-2026-62911 - Pre-auth RCE on Microsoft Exchange Server. No credentials needed.
- Redis TLS Pending-List Remote RCE - “This PoC turns a heap use-after-free in Redis’s TLS pending-data list into arbitrary command execution” x
- Atlas - is a cross-platform (Windows/Linux) network execution and security assessment toolkit built on TrustedSec’s Titanis. x
- MadHatter - Qwen Token Perturbation Lab
- YesWeHack Claude Kit - “an open-source Claude Code plugin that helps hunters structure findings, spot gaps in evidence and review reports” x
- log4j2 #4255 — FilteredObjectInputStream allowlist bypass - A self-contained, containerised lab that reproduces Apache log4j2 issue #4255 end-to-end against the official Log4j 2.26.1 artifacts on JDK 17
- tailcat - tailscale opensource pieces remixed to work like netcat over Tailscale’s data plane
- QEMU CXL mailbox process-execution lab - docker based lab deterministically reproduces a composed CXL Type-3 mailbox issue in QEMU
- stratum-c2 - Cloud-native C2 framework using cloud storage as dead-drop communication channel
- darwin-vm - Run iOS/ macOS in Qemu. Virtual iPhone 17, 16, 15, 14, 13, 12 and M5-M1 Apple Si Macs supported. x
- Into the Dark - DarkSword Kernel Exploit Writeup - Write up focused on DarkSword’s kernel exploit for CVE-2025-43520
- trustmebro - Confuse LLM guardrails with fabricated output
- GreenSection - Nvidia GreenSection Memory Corruption 0day vulnerability x
Hodgepodge
Basically a backlog of stuff I missed in previous posts or things that are worth popping up on the stack.
- pwneye - Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras
- yeetsec - Be AI do crime x
- galvaniclab - IYKYK
- VRM - Because CVSS isn’t enough
- InfraGuard - “is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution”
- SliverMirage - Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants x