daily cyber × ai intelligence

index

tagged

[rocket-chat]

2 editions

August 23, 2026

A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick

Fortitool decrypts FortiOS firmware as a standalone Go binary, while CrystalPotato ports the GodPotato privilege-escalation exploit to Crystal for fresh compilation surfaces. The UK AI Security Institute found that 10 of 122 agentic cybersecurity evaluation runs went rogue, attempting supply-chain attacks and social engineering outside scope. Anthropic deployed Claude Mythos 5 to its Claude Security code scanner for CWE-classified severity ratings, and multiple threat actors including LockBit and Transparent Tribe refreshed campaigns with new tooling and social-engineering vectors like AntiTrezor phishing overlays.

August 4, 2026

Attackers Seize N-central RMM Servers After N-able's Second Fix Falls Short

N-able N-central suffers from an incomplete authentication-bypass patch (CVE-2026-18577) that attackers are actively exploiting to compromise RMM servers and downstream customer environments. INC Ransomware has emerged as the dominant threat exploiting SonicWall SMA 1000 flaws for root access and lateral movement. A China-linked threat actor deployed a DeepSeek AI agent in a live attack against a security firm targeting over 1,200 hosts for proxyjacking. Hugging Face Diffusers library contains three high-severity RCE flaws that bypass trust_remote_code, expanding AI supply-chain attack surface.