{
  "2026": {
    "W37 (11 Sep – 17 Sep)": [
      {
        "url": "https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls/",
        "title": "Homebrew 7.0.0 gets built-in GUI, better security controls",
        "summary": "Homebrew 7.0.0 introduces a built-in vulnerability scanner using OSV.dev queries, a native GUI (BrewUI), stricter sandboxing, and an advisory database to track and mitigate formula-specific vulnerabilities.",
        "created": "2026-09-15T05:04:13.763188Z"
      }
    ],
    "W36 (04 Sep – 10 Sep)": [
      {
        "url": "https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review/",
        "title": "Staying Ahead of Adversarial AI Through Agentic Source Code Review | Google Cloud Blog",
        "summary": "Google Cloud's Mandiant introduced the Agentic Vulnerability Discovery Harness (AVDH), a multi-agent AI framework that accelerates vulnerability discovery, validation, and exploitation path identification in source code, achieving over 100 critical true-positive findings in two days during an incident response and uncovering 12 assigned CVEs.",
        "created": "2026-09-07T05:39:32.006620Z"
      },
      {
        "url": "https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html?m=1",
        "title": "Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication",
        "summary": "Attackers are exploiting unauthenticated administrative access via exposed SSH on internet-facing MikroTik routers, as disclosed by CERT Polska, necessitating immediate patching and forensic review.",
        "created": "2026-09-07T05:39:32.538925Z"
      },
      {
        "url": "https://github.com/elastic/supply-chain-monitor",
        "title": "GitHub - elastic/supply-chain-monitor",
        "summary": "GitHub's elastic/supply-chain-monitor automates the detection of supply chain compromises in PyPI and npm packages by diffing releases, analyzing changes via Cursor Agent CLI LLM, and alerting malicious findings to Slack.",
        "created": "2026-09-08T06:44:27.853870Z"
      },
      {
        "url": "https://catchingphish.com/clickexfil-my-iteration-on-clickfix-and-filefix/",
        "title": "ClickExfil: My iteration on ClickFix and FileFix",
        "summary": "ClickExfil demonstrates a social engineering-driven exfiltration technique leveraging user interaction to extract plaintext credentials and sensitive data (e.g., ~/.claude/.credentials.json, session transcripts) via browser-based commands, bypassing traditional malware execution and evading EDR detection.",
        "created": "2026-09-08T08:39:38.472776Z"
      },
      {
        "url": "https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/",
        "title": "Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain",
        "summary": "Threat actors compromised over 5,400 WordPress and PrestaShop sites to deliver evolving ClickFix and WebRTC-based payloads via malicious smart contracts on the BNB Smart Chain Testnet, leveraging the EtherHiding technique for resilient, dynamic command-and-control execution.",
        "created": "2026-09-08T09:34:07.565703Z"
      },
      {
        "url": "https://catchingphish.com/clickexfil-my-iteration-on-clickfix-and-filefix/",
        "title": "ClickExfil: My iteration on ClickFix and FileFix",
        "summary": "ClickExfil demonstrates a social engineering-driven exfiltration technique leveraging user interaction to extract plaintext credentials and sensitive session data from AI tools like Claude Code, bypassing traditional EDR detection by masquerading as legitimate user commands.",
        "created": "2026-09-08T09:34:08.124934Z"
      },
      {
        "url": "https://sumeshi.github.io/posts/works/dont-make-ai-your-forensic-analyst-en",
        "title": "Don't Make AI Your Forensic Analyst | SIPDEP",
        "summary": "AI-assisted forensic scribing leverages local LLMs to automate organizational tasks in digital forensics, avoiding full autonomous investigation due to current hardware limitations and reliability concerns.",
        "created": "2026-09-08T10:14:37.642576Z"
      }
    ],
    "W35 (28 Aug – 03 Sep)": [
      {
        "url": "https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/",
        "title": "TerminalFix campaign deploys a reverse tunnel through multistage intrusion | Microsoft Security Blog",
        "summary": "The TerminalFix campaign employs a multi-stage attack chain, starting with a fake Cloudflare CAPTCHA to deliver a malicious PowerShell command that initiates DLL sideloading, steganographic payload extraction, extensive Active Directory reconnaissance, and ultimately deploys a Python-based reverse-tunnel implant for persistent, encrypted WebSocket-based network proxy access.",
        "created": "2026-08-31T07:24:21.778354Z"
      },
      {
        "url": "https://socradar.io/blog/doublecup-clickfix-loader-devicemanager-rats/",
        "title": "Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs",
        "summary": "DOUBLECUP, a Russian Loader-as-a-Service (LaaS) for ClickFix campaigns, delivers CountLoader (v4.5p for Windows/macOS) and a new RAT, DeviceManager, via a multi-stage steganographic PNG dropper that decrypts payloads in-memory using a custom SHA-256 CTR-mode stream cipher and victim IP-derived XOR key.",
        "created": "2026-09-01T05:59:27.985914Z"
      }
    ],
    "W33 (14 Aug – 20 Aug)": [
      {
        "url": "https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/",
        "title": "DNS Poisoning Tactics Expand to Hospitality Wi-Fi | ReliaQuest Threat Spotlight",
        "summary": "Threat actors, likely linked to APT28, are compromising hotel and conference center Wi-Fi gateways to perform DNS poisoning, redirecting corporate employees to attacker-controlled infrastructure for credential harvesting and Microsoft 365 account compromise, mitigable via always-on full-tunnel VPN.",
        "created": "2026-08-18T12:14:11.606753Z"
      },
      {
        "url": "https://github.com/zizmorcore/zizmor",
        "title": "GitHub - zizmorcore/zizmor: Static analysis for GitHub Actions",
        "summary": "zizmor is a static analysis tool for GitHub Actions and CI/CD pipelines that detects template injection vulnerabilities, credential leakage, excessive permissions, and impostor commits to mitigate security risks in automation workflows.",
        "created": "2026-08-19T06:54:14.703837Z"
      },
      {
        "url": "https://www.wiz.io/blog/red-agent-snowflake-copilot-cicd-bug",
        "title": "Red Agent Exploits Snowflake Vuln Missed by Github Copilot | Wiz Blog",
        "summary": "Wiz Red Agent autonomously exploited a GitHub Actions script injection vulnerability in Snowflake’s public repository, bypassing GitHub Advanced Security and AI-assisted PR reviews to exfiltrate Jira credentials within five days of the flaw becoming live.",
        "created": "2026-08-19T06:54:15.256907Z"
      }
    ],
    "W30 (24 Jul – 30 Jul)": [
      {
        "url": "https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-plus-plugins-to-stealthily-install-malware/",
        "title": "Hackers abuse Notepad++ plugins to stealthily install malware",
        "summary": "Threat actor UAC-0099 abused legitimate Notepad++ plugins and DLL hijacking in version 8.8.3 to stealthily deliver LunchPoke malware, BurnyBear loader, and MatchBoil V2 payload via a multi-stage VBScript and ZIP archive attack chain targeting Ukrainian organizations.",
        "created": "2026-07-24T06:39:33.696972Z"
      }
    ],
    "W29 (17 Jul – 23 Jul)": [
      {
        "url": "https://www.group-ib.com/blog/clicklock-stealer-macos-malware/",
        "title": "ClickLock Stealer: Paste Once, Lose Everything",
        "summary": "Group-IB discovered ClickLock Stealer, a new modular macOS info-stealer malware distributed via ClickFix phishing pages and compromised WordPress domains, which exfiltrates browser credentials, password manager data, crypto wallet files, macOS Keychain, shell history, and FTP credentials while deploying a GSocket-based backdoor for persistent access.",
        "created": "2026-07-17T06:29:14.452168Z"
      },
      {
        "url": "https://center-for-threat-informed-defense.github.io/top-attack-techniques/#/",
        "title": "Top ATT&CK Techniques",
        "summary": "",
        "created": "2026-07-17T07:34:16.439851Z"
      },
      {
        "url": "https://octopus-project.ddns.net/d/p8L16gTjG_nB",
        "title": "OCTOPUS",
        "summary": "Octopus is an AI-driven automation system integrating three operational modes—assistive decision support, task execution, and autonomous remote operation—while dynamically learning workflows from user interactions without requiring separate tuning processes.",
        "created": "2026-07-19T11:19:18.779840Z"
      },
      {
        "url": "https://aws.amazon.com/blogs/security/introducing-the-amazon-guardduty-investigation-agent-on-demand-ai-powered-threat-assessment/",
        "title": "Introducing the Amazon GuardDuty investigation agent: on-demand AI-powered threat assessment | Amazon Web Services",
        "summary": "Amazon GuardDuty's new investigation agent, now in public preview, leverages AI-powered cross-Region inference to automate and accelerate security investigations across AWS environments, delivering structured risk assessments, MITRE ATT&CK mappings, and actionable remediation steps with reduced manual effort.",
        "created": "2026-07-21T05:39:17.909975Z"
      },
      {
        "url": "https://www.imperialviolet.org/tourofwebauthn/tourofwebauthn.html",
        "title": "A Tour of WebAuthn",
        "summary": "WebAuthn leverages public key cryptography (e.g., ECDSA, RSA) to mitigate password-related risks like brute-force attacks, credential stuffing, and phishing by replacing password hashes with public keys and using hardware-backed private keys for authentication.",
        "created": "2026-07-21T06:09:39.321499Z"
      },
      {
        "url": "https://citizendot.github.io/articles/fake-job-interview-git-hook-malware/",
        "title": "I Inspected My Take-Home Interview Project. It Was a Whole Operation.",
        "summary": "A malicious take-home interview project embedded Git hooks that executed OS-specific remote payloads, installing obfuscated Node.js-based malware with suspicious dependencies like Hardhat, clipboardy, and fs, likely for cryptocurrency wallet exploitation or data exfiltration.",
        "created": "2026-07-23T12:19:18.712220Z"
      }
    ],
    "W28 (10 Jul – 16 Jul)": [
      {
        "url": "https://www.crowdstrike.com/en-us/blog/crowdstrike-uncovers-new-prompt-injection-techniques/",
        "title": "CrowdStrike Uncovers New Prompt Injection Techniques",
        "summary": "CrowdStrike's research team unveiled 18 new prompt injection techniques, expanding their taxonomy to over 200 distinct methods, highlighting evolving threats such as delayed triggers, semantic constraints, and boundary spoofing that adversaries leverage to manipulate AI agents and systems.",
        "created": "2026-07-13T05:04:23.875570Z"
      },
      {
        "url": "https://blog.gitguardian.com/laptop-as-credential-store/",
        "title": "Every Laptop Is a Credential Store: Complete Map of Hidden Secrets",
        "summary": "Research reveals that developer laptops store dozens of long-lived, unrotated credentials across multiple hidden locations—including shell history, cloud caches, AI agent configs, and browser storage—which are systematically harvested by infostealers and evade traditional repo/CI secret scanners.",
        "created": "2026-07-13T05:19:25.084491Z"
      },
      {
        "url": "https://blog.cloudflare.com/build-your-own-vulnerability-harness/",
        "title": "Build your own vulnerability harness",
        "summary": "The article describes the development of a model-agnostic vulnerability discovery harness that treats AI models as interchangeable components to mitigate context exhaustion, persistence gaps, and cross-repo dependency blind spots, while employing a two-stage workflow (VDH and VVS) with distinct models for discovery and validation to enhance security coverage.",
        "created": "2026-07-13T10:14:37.267270Z"
      }
    ],
    "W27 (03 Jul – 09 Jul)": [
      {
        "url": "https://javoriuski.com/post/youtube",
        "title": "The Setup",
        "summary": "Researcher demonstrated a prompt injection attack in YouTube Studio's Ask Studio AI assistant, enabling attackers to manipulate AI responses to exfiltrate private video titles via crafted comments, bypassing creator awareness through comment editing and trusted UI interactions.",
        "created": "2026-07-05T05:14:29.272131Z"
      },
      {
        "url": "https://khaelkugler.com/blogs/meccha_chameleon.html",
        "title": "2-Click Remote Code Execution in Meccha Chameleon",
        "summary": "A 2-click remote code execution (RCE) vulnerability in *Meccha Chameleon* was exploited via malicious Steam Workshop maps containing UE5 Blueprints that leveraged the LaunchURL function to execute arbitrary batch files hosted in predictable Workshop directories.",
        "created": "2026-07-07T05:14:17.538606Z"
      }
    ],
    "W26 (26 Jun – 02 Jul)": [
      {
        "url": "https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-million-in-supply-chain-attack/",
        "title": "Polymarket customers lose $3 million in supply-chain attack",
        "summary": "A supply-chain attack via a compromised third-party frontend dependency enabled malicious JavaScript injection on Polymarket, leading to approximately $3 million in cryptocurrency theft from a limited number of user accounts.",
        "created": "2026-06-26T19:34:44.870886Z"
      },
      {
        "url": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/",
        "title": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox",
        "summary": "A Rust-based macOS implant, tracked as macOS.Gaslight and assessed as DPRK-aligned, employs a 3.5 KB prompt-injection payload of 38 fabricated system messages to mislead LLM-assisted triage analysis, while using a Telegram Bot API C2 channel with AES-GCM encryption over certificate-pinned TLS and self-redacting bot tokens in runtime output.",
        "created": "2026-06-28T20:14:44.548841Z"
      }
    ],
    "W25 (19 Jun – 25 Jun)": [
      {
        "url": "https://spur.us/blog/smart-tv-apps-residential-proxy-sdks",
        "title": "Smart TV Apps Exploited as Residential Proxy SDKs",
        "summary": "",
        "created": "2026-06-23T20:34:04.083761Z"
      },
      {
        "url": "https://novee.security/blog/cordyceps/",
        "title": "Cordyceps: The Silent Parasite Consuming Your Supply Chain",
        "summary": "Researchers discovered Cordyceps, a critical class of exploitable CI/CD vulnerabilities in GitHub Actions workflows, enabling unauthenticated attackers to execute command injection, privilege escalation, artifact poisoning, and supply chain compromise across thousands of high-impact repositories, including those of Microsoft, Google, Apache, and Cloudflare.",
        "created": "2026-06-24T05:24:16.491844Z"
      }
    ],
    "W24 (12 Jun – 18 Jun)": [
      {
        "url": "https://www.bleepingcomputer.com/news/security/steam-workshop-abused-to-spread-malware-via-wallpaper-engine-app/",
        "title": "Steam Workshop abused to spread malware via Wallpaper Engine app",
        "summary": "Threat actors abused Steam Workshop’s Wallpaper Engine app to distribute malware via malicious application wallpapers, enabling account hijacking, backdoor deployment, cryptomining, and credential theft, with payloads executing automatically upon installation.",
        "created": "2026-06-16T19:19:12.801395Z"
      }
    ],
    "W23 (05 Jun – 11 Jun)": [
      {
        "url": "https://detection.studio/",
        "title": "Detection Studio – detection.studio",
        "summary": "Detection Studio by north.sh is a tool designed to generate SIEM queries, such as Splunk SPL, from Sigma rules for correlating suspicious events.",
        "created": "2026-06-10T17:29:12.978124Z"
      }
    ],
    "W22 (29 May – 04 Jun)": [
      {
        "url": "https://www.bleepingcomputer.com/news/security/chatgpt-share-links-abused-to-host-fake-outage-pages-to-deliver-malware/",
        "title": "ChatGPT share links abused to host fake outage pages to deliver malware",
        "summary": "Threat actors abused ChatGPT's LLMShare feature via Google ads to deliver malware by hosting fake outage pages on legitimate chatgpt.com/s/ links, redirecting users to a malicious OpenAI impersonation site (openew[.]app) that deploys infostealers.",
        "created": "2026-05-29T19:34:21.819075Z"
      },
      {
        "url": "https://pushsecurity.com/blog/llmshare-malvertising-campaign",
        "title": "LLMShare: using shared chatbot pages to distribute malware",
        "summary": "Attackers are abusing AI chatbot platforms' shared content features (ChatGPT and Claude) to host malicious pages on trusted domains, distributing malware via malvertising and SEO poisoning, evading URL reputation checks and leveraging code rendering to mimic legitimate service disruption notices.",
        "created": "2026-05-29T19:39:24.224603Z"
      },
      {
        "url": "https://newsroom.ibm.com/2026-05-28-ibm-and-red-hat-commit-5-billion-to-redefine-the-future-of-open-source-in-the-ai-era",
        "title": "IBM and Red Hat Commit $5 Billion to Redefine the Future of Open Source in the AI Era",
        "summary": "IBM and Red Hat announced Project Lightwell, a $5 billion initiative leveraging AI and 20,000 engineers to establish a trusted open-source security clearinghouse for large-scale vulnerability identification, validation, and remediation across enterprise software supply chains.",
        "created": "2026-05-29T20:34:32.245691Z"
      },
      {
        "url": "https://www.bleepingcomputer.com/news/security/new-cifswitch-linux-flaw-gives-root-on-multiple-distributions/",
        "title": "New CIFSwitch Linux flaw gives root on multiple distributions",
        "summary": "A local privilege escalation vulnerability in the Linux kernel's CIFS subsystem (CVE-2026-46243) allows attackers to forge cifs.spnego key requests, abuse the cifs.upcall helper, and achieve root privileges via malicious NSS module loading.",
        "created": "2026-05-31T16:34:37.823144Z"
      },
      {
        "url": "https://blog.sekoia.io/fsbs-matryoshka-1-3-gamaredons-gifts-that-keeps-unpacking-gammaphish-and-gammaworm/",
        "title": "FSB’s matryoshka #1/3: Inside Gamaredon Cyber Operations",
        "summary": "Sekoia.io’s analysis reveals Gamaredon’s 2026 modular malware arsenal—GammaPhish, GammaLoad, GammaWorm, and GammaSteel—used in a multi-stage infection chain exploiting CVE-2025-8088 for initial access, employing ADS, DDRs, and DPAPI to evade detection while enabling persistent espionage and data exfiltration against Ukrainian targets.",
        "created": "2026-06-03T06:34:15.641194Z"
      },
      {
        "url": "https://www.bleepingcomputer.com/news/security/vs-code-zero-day-lets-hackers-steal-github-tokens-in-one-click/",
        "title": "VS Code zero-day lets hackers steal GitHub tokens in one click",
        "summary": "A zero-day vulnerability in Visual Studio Code's sandboxed webview message-passing system enables attackers to steal GitHub OAuth tokens via malicious extensions, exploiting github.dev's OAuth token handling to gain full repository access.",
        "created": "2026-06-04T10:09:15.114565Z"
      }
    ]
  }
}