puck tools — test your egress policy against real C2 traffic →
#sitrep

Sitrep 2026-08-31

A weekly round-up of security and tech news.

The word SITREP in a heavy technical monospace, set inside the Offensive Context hand-drawn green brush ring, dated 31 August 2026

News

Techniques and Write-ups

Tools and Exploits

  • SLEEPWALKER - SLEEPWALKER recreated with Deepseek v4 Flash/Qwen 3.8 x
  • CrystalPotato - Crystal port of GodPotato x
  • dploot - is Python rewrite of SharpDPAPI x
  • Recon Skills - “skills for external reconnaissance, web applications, APIs, authentication, vulnerability validation, attack-path analysis, and reporting.” x
  • CVE-2026-18963 - Keycloak reset-credentials bypass
  • CVE-2026-62911 - Pre-auth RCE on Microsoft Exchange Server. No credentials needed.
  • Redis TLS Pending-List Remote RCE - “This PoC turns a heap use-after-free in Redis’s TLS pending-data list into arbitrary command execution” x
  • Atlas - is a cross-platform (Windows/Linux) network execution and security assessment toolkit built on TrustedSec’s Titanis. x
  • MadHatter - Qwen Token Perturbation Lab
  • YesWeHack Claude Kit - “an open-source Claude Code plugin that helps hunters structure findings, spot gaps in evidence and review reports” x
  • log4j2 #4255 — FilteredObjectInputStream allowlist bypass - A self-contained, containerised lab that reproduces Apache log4j2 issue #4255 end-to-end against the official Log4j 2.26.1 artifacts on JDK 17
  • tailcat - tailscale opensource pieces remixed to work like netcat over Tailscale’s data plane
  • QEMU CXL mailbox process-execution lab - docker based lab deterministically reproduces a composed CXL Type-3 mailbox issue in QEMU
  • stratum-c2 - Cloud-native C2 framework using cloud storage as dead-drop communication channel
  • darwin-vm - Run iOS/ macOS in Qemu. Virtual iPhone 17, 16, 15, 14, 13, 12 and M5-M1 Apple Si Macs supported. x
  • Into the Dark - DarkSword Kernel Exploit Writeup - Write up focused on DarkSword’s kernel exploit for CVE-2025-43520
  • trustmebro - Confuse LLM guardrails with fabricated output
  • GreenSection - Nvidia GreenSection Memory Corruption 0day vulnerability x

Hodgepodge

Basically a backlog of stuff I missed in previous posts or things that are worth popping up on the stack.

  • pwneye - Your ONVIF and RTSP camera companion for discovering and hacking real-world security cameras
  • yeetsec - Be AI do crime x
  • galvaniclab - IYKYK
  • VRM - Because CVSS isn’t enough
  • InfraGuard - “is a Command & Control Redirection Proxy and Manager which protects your Red Team Infrastructure against threat attribution”
  • SliverMirage - Crystal Palace PICO loader for Sliver C2 dual-layer AMSI bypass, ETW silencing, AES-256-CBC encrypted payloads, 6 delivery variants x