daily cyber × ai intelligence

index

tagged

[havoc-c2]

3 editions · 1 item

August 12, 2026

When the AI Is the One Finding the Zero-Days

A frontier AI agent discovered a zero-click RCE in Zoom (CVE-2026-53413, CVE-2026-53414) in under 24 hours, demonstrating rapid offensive AI capability in vulnerability research. Rapid7 disclosed an AI-assisted unauthenticated RCE in Microsoft SharePoint (CVE-2026-63520), while CISA confirmed ransomware crews are actively exploiting a related flaw. Researchers extracted encrypted reasoning traces and leaked credentials from OpenAI, Anthropic, and Google models by manipulating extended-thinking APIs. Microsoft's August Patch Tuesday fixed 421 CVEs including an actively exploited kernel zero-day (CVE-2026-68820) already in Lazarus hands, along with a pre-auth IDOR in Langflow (CVE-2026-55255) being exploited in the wild.

July 6, 2026

The Gentlemen Weaponize a Signed Kontron Driver Into an EDR Killswitch

The Gentlemen ransomware crew exploited a zero-day in a signed Kontron driver to disable endpoint defenses via BYOVD, gaining kernel-level access to terminate security processes before deploying ransomware. CVE-2026-46242 (Bad Epoll) now has a public proof-of-concept for a Linux kernel use-after-free that enables privilege escalation on 6.4+ kernels with 99% reliability. Medtronic is notifying 3.8 million individuals after a ShinyHunters data breach exposed personal and medical data. Multiple new red-team tools and offensive-security frameworks including T3MP3ST, goshs, and Knossos were released, alongside DOJ filings revealing how Microsoft telemetry helped the FBI identify alleged Scattered Spider member Peter Stokes via Windows Global Device ID correlation.