puck tools — test your egress policy against real C2 traffic →
#sitrep

Sitrep 2026-09-21

A weekly round-up of security and tech news.

The word SITREP in a heavy technical monospace, set inside the Offensive Context hand-drawn green brush ring, dated 21 September 2026

Techniques and Write-ups

  • Relational Attack Graph Exchange - RAGE is a vendor-neutral file format for offensive security graphs, plus the open corpus that gives it meaning: the node and edge taxonomy, the AWS/GCP/Azure mappings and collection recipes, and the edge-derivation rules. x
  • Breaking into Google’s GFile for $100k - how brutecat found a vulnerability in Google’s internal APIs, bypassing authorization to exploit the GFile library to gain access to internal filesystems and storage x
  • Stamping my own passport -a master-key flaw in the DEF CON 34 RFID scavenger hunt x
  • CVE-2026-43783 - LPE via DesktopServicesHelper in macOS 26.5 x
  • ParaShells - Parallels Desktop Turns Appliance Install Into a Root Shell
  • Agents at Large - Tracing Illicit OpenAI Agent Activity on Hugging Face
  • The Hacker’s Guide to Attacking AI Agents - This is a practical guide to assessing the security of an agentic AI system.
  • Building an AI Detection Engine That Understands Agent Intent - Analyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behavior
  • Guest to host - CVE-2026-77179 Escaping Docker Desktop sandboxes on macOS x
  • HEIF Heist - is Hacktron’s name for a class of remote attack paths targeting services that decode attacker-controlled HEIF, HEIC, or AVIF images via vulnerable libheif and libde265. x
  • Inside ZCode - AI Coding desktop app silently uploading entire git history to the cloud x
  • Living Inside the Shell - investigating zsh module capabilities on macOS. x
  • BragJack - How We Hijacked 5 Of The World’s Most Popular Browsers Using Their Built-In AI Assistants x

Tools and Exploits

  • thunderstorm - maps your environment, evaluates effective permissions and trust, and writes a complete attack graph as a single .rage.ndjson file. x
  • R2Socks - x
  • OpenHunterAI - brings scope, scan activity, findings, and remediation into one local workspace. x
  • airlift - An AirTraffic sandbox escape for iOS 27.0. x
  • adnullenum - A single-pass Active Directory enumerator for an anonymous (null) session x
  • CVE-2026-42980 - Windows kernel WMI integer-underflow vulnerability that can be exploited for local privilege escalation to NT AUTHORITY\SYSTEM
  • cups2root - 0-day CUPS privesc x
  • Box of Apples - is a native macOS workspace built on Apple’s Virtualization framework. x
  • go-responder - Responder ported to golang x
  • TaskExplorer - Process Monitor but for macOS, open source, & much more powerful x
  • ResetSpy - Enumerate user accounts and registered authentication methods via the Microsoft Self-Service Password Reset (SSPR) portal x
  • ntlmscout - Enumerate exposed NTLM endpoints
  • BrokenPipe - Steam Client Service Local Privilege Escalation Vulnerability x

Talks and Podcasts

Hodgepodge

Basically a backlog of stuff I missed in previous posts or things that are worth popping up on the stack.