Sitrep 2026-08-24
A weekly round-up of security and tech news.

I have too many browser tabs open to keep track of… This is my attempt to fix that. All credit to badsectorlabs for the format
News
-
Omacom Foundation launches with $8 million - @dhh working hard to make this finally be the year of linux on the desktop x
-
Prompt Injection EP - Inspired by @uwu_underground, Jhaddix of @arcanuminfosec drops their first EP. x
-
Claude subagent got bored and prompt injected my main session into deleting my database - A user on Reddit reports a Claude subagent prompt injected the main session to delete the database.
-
Popular Rust crates arrayref, append-only-vec, and internment compromised in Supply Chain Attack -
arrayref,append-only-vecandinternmentcompromised in a supply chain attack. x - A compromised user gets rejected by the Anthropic API while investigating the malware on their machine. x -
OpenAI releases seemingly harmful iMessage plugin - New OpenAI plugin for Codex and ChatGPT Work reads iMessage. Seems problematic. If someone you know installs the plugin, any of your messages to them are now in the training data forever. As expected everybody hates it. It looks like codex keeps iMessage history in plaintext in the user’s
~/.codex/sessionsfolder. x -
A new model enters the chat -Opencode announces Ox Alpha in stealth mode by an anonymous lab, free for the next week. There was much speculation. - Surprise: @elder_plinius leaks the prompt. x
Techniques and Write-ups
-
Executing Code via Google’s Own Signed Installer - “… how an attacker can take a legitimately signed Google Chrome Enterprise MSI and modify it to execute arbitrary commands” x
-
tmp.0ut v5 - “Get your viruses, rootkits, strange ELFs, weird machines, tiny files, cool art, and phresh beats here!!” x
Tools and Exploits
-
Qwen3.8 27B Uncensored / Abliterated - Oracarouter’s collection of Uncensored Qwen3.8 27B models… probably pretty useful for security related things - eg Reversing
-
CVE-2026-52912 - NebuSec PoC against Fedora 6.19.10-300. x
-
Fortitool FortIOS Decryption - is a tool to decrypt and unpack FortiOS firmware end to end. x github
Talks and Podcasts
-
DefCon 34 - Stalking the Wily Hacker: 40 years later - Did Cliff Stoll give the best talk at Defcon? Many @HackingLZ think @tuckner so @caseyjohnellis
-
Microsoft Killed My Exploit! Enforcing User-Kernel Separation on Windows with Exploit Mitigations - @yarden_shafir shares research with @Steph3nSims on exploiting I/O Rings on Windows and what M$ has done to mitigate - x
Hodgepodge
Basically a backlog of stuff I missed in previous posts or things that are worth popping up on the stack.
-
Sticker of the week - be ai do crime goose badge - @caseyjohnellis
-
USENIX Security ’18: Q: Why Do Keynote Speakers Keep Suggesting That Improving Security Is Possible? - How I learned to be skeptical of doing stuff or are we just wasting our time? - youtube
-
AI Mythos Recovered PR - Repo of the mythos social engineering attack
-
Blacklight: Illuminating AI Agent Artifacts for Attackers and Defenders - “Blacklight is an open-source security research toolkit for discovering and analyzing AI agent artifacts that reside on endpoints.”
-
claudemon - A POC by @UK_Daniel_Card proving that yes it is still possible to monitor processes running on computers
-
Kioskonomicon - DEF CON 34 Red Team Village Tactic From Kiosk to Domain Compromise: Learning to Walk Up and Take it All brought to us by @techspence, @CroodSolutions and @Shammahwoods – x
-
VulnHunter - “is an open-source, agentic AI security tool that applies proactive, attacker-first analysis directly to source code.”