CVE-2026-50458: Finding a UAF in the Windows Brokering File System
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at the time, while the details were still fresh. I hope you enjoy it!
https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
🎖@malwr
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at the time, while the details were still fresh. I hope you enjoy it!
https://rotcee.github.io/posts/CVE-2026-50458-finding-a-UAF-in-windows-brokering-file-system/
🎖@malwr
Rotce’s Blog
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
On Tuesday, July 14, Microsoft released the largest Patch Tuesday update in its history, fixing more than 600 vulnerabilities. A bug I reported to Microsoft on May 17 was patched as CVE-2026-50458 in this release, so I am publishing the writeup I wrote at…
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.
https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
🎖@malwr
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations can implement.
https://www.trendmicro.com/en_us/research/26/g/device-code-phishing.html
🎖@malwr
Trend Micro
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
Device code phishing abuses a legitimate authentication feature designed for devices with limited input capabilities. This article breaks down how the technique works, examines a recent observed case, and outlines the layered security measures organizations…
PE OopsSec: Mind your PE, guard your OPSEC
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
https://www.zerosalarium.com/2026/07/pe-oopssec-mind-your-pe-guard-your-opsec.html
🎖@malwr
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
https://www.zerosalarium.com/2026/07/pe-oopssec-mind-your-pe-guard-your-opsec.html
🎖@malwr
Zerosalarium
PE OopsSec: Mind your PE, guard your OPSEC
PE-OopsSec helps red teams, pentesters, and game developers give their payloads a final once‑over before putting them into the real world
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html
🎖@malwr
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-used-ai-to-deploy-c2-botnet.html
🎖@malwr
Trend Micro
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
TrendAI™ Research analyzed over 200 Gemini CLI session logs showing how a Russian-speaking threat actor used AI to run a live botnet, finishing a full C&C migration in six minutes while doing just 11% of the work himself.
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
🎖@malwr
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over TURN.
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/
🎖@malwr
Cisco Talos
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel
The Chaos ransomware group uses new malware "msaRAT" that hijacks browsers. The malware doesn't communicate directly with C2 but connects through the browser. It enables arbitrary command execution while hiding the attacker's IP from victims via WebRTC over…
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem
https://www.recordedfuture.com/research/tag-195-evolves-maas-ecosystem
https://assets.recordedfuture.com/insikt-report-pdfs/2026/cta-2026-0723.pdf
🎖@malwr
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
https://hunt.io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent
🎖@malwr
hunt.io
Thailand's Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged
An exposed open directory on a Hong Kong server revealed an autonomous AI agent running unattended, an unreported Go implant, and target-specific tooling used against Thailand's Ministry of Finance.
oxasploits/PacketSnitch: PacketSnitch is a network analysis platform that transforms packet captures into searchable, protocol-aware intelligence, helping security professionals, developers, and researchers rapidly uncover hosts, credentials, certificates, files, locations, protocols, anomalies, threat intel, and other actionable insights.
https://github.com/oxasploits/PacketSnitch
🎖@malwr
https://github.com/oxasploits/PacketSnitch
🎖@malwr
❤1
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant
https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant
🎖@malwr
www.enki.co.kr
Analysis of Kimsuky's Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant | Enki White Hat
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
https://7h3kn0w3r.github.io/blog/windows-data-deduplication/
https://github.com/7h3kn0w3r/DedupInspector
🎖@malwr
7h3kn0w3r.github.io
Windows Data Deduplication // Noir Trace Writeups
A Forensic Investigation into Windows Data Deduplication [The Vanishing File]
❤2
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC threat intelligence reveals how Iran‑aligned MuddyWater uses Russian malware‑as‑a‑service and blockchain C2, blurring cybercrime and nation‑state espionage.
https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit/
🎖@malwr
JUMPSEC
Inside a DPRK BlueNoroff ClickFix Kit | JUMPSEC
JUMPSEC researchers analyse an active BlueNoroff phishing kit used to impersonate Zoom and Microsoft Teams meetings, revealing source code, infrastructure, malware delivery and victim targeting techniques.
petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contact filtering, and conversation export.
https://github.com/petrk94/smsviewer
🎖@malwr
https://github.com/petrk94/smsviewer
🎖@malwr
GitHub
GitHub - petrk94/smsviewer: A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup &…
A web-based application to parse, view, and manage SMS backup files (XML format) from "SMS Backup & Restore" with advanced features like phone number normalization, contac...
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1
nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
https://github.com/nikaiw/VMkatz
🎖@malwr
https://github.com/nikaiw/VMkatz
🎖@malwr
GitHub
GitHub - nikaiw/VMkatz: Extract Windows credentials directly from VM memory snapshots and virtual disks
Extract Windows credentials directly from VM memory snapshots and virtual disks - nikaiw/VMkatz
xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse.
https://github.com/xec412/NocturneLdr
🎖@malwr
https://github.com/xec412/NocturneLdr
🎖@malwr
GitHub
GitHub - xec412/NocturneLdr: A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function…
A CET-compatible Windows x64 loader that produces fully backed call stacks through runtime function table manipulation, code cave injection, and inverted function table collapse. - xec412/NocturneLdr
warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage — maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.
https://github.com/warpedatom/OffsetInspect
🎖@malwr
https://github.com/warpedatom/OffsetInspect
🎖@malwr
GitHub
GitHub - warpedatom/OffsetInspect: PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps…
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to...
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
https://specterops.io/blog/2026/06/29/llm-powered-edr-analysis/
🎖@malwr
SpecterOps
Accelerating EDR Evasion with LLM-Driven Analysis
SpecterOps reverse engineered Cortex XDR with LLMs to extract YARA rules, ML models, and behavioral detections.
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
https://sethenoka.com/persistence-artefacts-services-scheduled-tasks-and-intentional-longevity/
🎖@malwr
Seth Enoka – DFIR
Windows Persistence Forensics: Services, Scheduled Tasks, and Autoruns
A DFIR guide to Windows persistence forensics, including services, scheduled tasks, Run keys, autoruns, and what persistence artefacts can and can't prove.
haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC.
https://github.com/haarisxk/Waypoint
🎖@malwr
https://github.com/haarisxk/Waypoint
🎖@malwr
GitHub
GitHub - haarisxk/Waypoint: A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise…
A stealth-focused kernel-mode virtual HID mouse driver for Windows. Built with KMDF and VHF for precise, hardware-level input simulation using covert shared-memory IPC. - haarisxk/Waypoint
❤1