August 25, 2026
- SliverMirage — a Sliver C2 fork using a Crystal Palace PICO loader, dual-layer AMSI bypass, ETW silencing and AES-256-CBC encrypted payloads across six staged/stageless delivery variants (GitHub).
· New Tools & Releases
in The Rogue Agent Staged an Apology, Then Pushed More Malware
July 14, 2026
A new CET-compliant callstack spoofing PoC from @_MrTiz demonstrates how to defeat EDR telemetry despite Intel CET shadow stacks, while AI agents face compound threats from MemGhost memory-poisoning attacks and prompt-injection via steganography. xAI's Grok Build CLI inadvertently uploaded private Git repositories to Google Cloud, exposing AI dev tooling as a fresh supply-chain vector. The FBI and Google dismantled "Outsider," an $88-per-week phishing-as-a-service platform responsible for ~$1.9 billion in losses, and the US Treasury sanctioned 1VPNS and its administrator for enabling ransomware infrastructure targeting hospitals and schools.
June 27, 2026
- CrystalSliver — a Crystal Palace evasion kit that swaps Sliver's default reflective loader and post-ex execution path for Raphael Mudge's Crystal Palace (BSD). GitHub
· New Tools & Releases
in Amazon Q Coding Assistant Hijacked Through Malicious MCP Configs as Washington Starts Gating Frontier Models Customer-by-Customer
June 26, 2026
- CrystalSliver — swaps Sliver's default reflective loader and post-ex execution path for Raphael Mudge's Crystal Palace evasion kit. GitHub
· New Tools & Releases
in Malware Weaponizes Prompt Injection to Sabotage AI Analysis as Gamaredon Retools Against Ukraine
June 25, 2026
- CrystalSliver swaps Sliver's default reflective loader and post-ex execution path for Raphael Mudge's Crystal Palace, improving evasion. GitHub
· New Tools & Releases
in Cisco SD-WAN Manager Zero-Day Gives Root via a Malicious CSV as Operation Endgame Smashes Amadey and StealC
June 24, 2026
Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.