Sitrep 2026-09-07
A weekly round-up of security and tech news.

News
Techniques and Write-ups
- Llama.cpp, an Ice Cold CORS Light, and Command Execution - Put it on my Tab! - same-origin attacks on lama.cpp x
- Breaking Claude Code Opus 5 Auto Mode - Give the agent a safe option that is the exploit x
- I accidentally turned LLM memory into program analysis - x
- Malware development trick 44 - Stealing data via legit GitHub API. Simple C example. x
- Python Sandboxing is Still Broken by Design - Escaping the Grafana Cloud IRM sandbox x
- Booz Allen Cyber Weapon Index - “New index measures AI’s ability to execute cyberattacks”
- endpoint-ai-agent-abuse - EAA is a curated catalog of techniques and real-world cases involving abuse of local AI agents through their runtime, configuration, state, tools, and inherited authority.
- Writing Your Own VPN Protocol - A look at different VPN implementations x
Tools and Exploits
- PaperCut MF and NG CVE-2026-81578 + CVE-2026-82078 - MSF Module for MF and NG editions x
- logtotal-sanitizer - Framework-agnostic log sanitizer for browsers and Node.js. x
- winflesher - AD vulnerability discovery and attack path analysis
- FalconFlank - Crowdstrike Falcon 0day Privilege Escalation Vulnerability x
- Malleon - Automated HTTP/HTTPS simulation for Cobalt Strike Malleable C2 profiles
- mikrotrick-poc - CVE-2026-67276 RouterOS SSH public-key authentication bypass lab PoC x
- evil-winrm - EvilWinRM v4.1 released x
Talks and Podcasts
- Deobfuscation in the Age of Agentic Reverse Engineering - RECON 2026 Talk x
Hodgepodge
Basically a backlog of stuff I missed in previous posts or things that are worth popping up on the stack.
- SpecterOps Skills - Reusable agent skills, plugins, and agent definitions for SpecterOps.
- Awesome Large Language Models for Vulnerability Detection - A curated list of papers, projects, and agent skills on using LLMs for vulnerability detection and discovery.