Skip to content
EN

Security

Vulnerabilities, exploits, hardening and security engineering.

74 links, newest first.

Get the weekly briefing

The best new links of the topics you pick, summarized with the source. At most one email a week.

Topics: Security

Before the first issue we email you to confirm; leaving takes one click. Sent with CommsHarbor. Privacy

  1. A self-replicating AI worm adapts across vulnerability classes

    The post describes a research worm that uses an open-weight LLM on compromised GPU machines and adapts its attack logic. In corporate testbed trials, it reportedly exploited systems and replicated across Linux, Windows, and IoT targets.

    Engineers should assess how adaptive agents could change vulnerability response and network containment.

  2. SecurityPost on X

    Post warns of AI-orchestrated intrusion workflows

    The post argues that agentic orchestration of models with scanners, shells, and other tools could make intrusion workflows more repeatable and cheaper. It urges defenders to expect continuous AI-assisted attempts.

    It highlights orchestration, tool access, and adaptive retries as security concerns for defenders.

  3. SecurityArticle

    Collision Attacks on SHA-2 Extended to 39 Steps

    The paper presents an improved search procedure for SHA-2 collision attacks. Its preview says prior work reached 37 steps but could not reach 38 because of a low-probability uncontrolled part in the differential characteristics.

    Engineers assessing SHA-2’s security can track progress in cryptanalysis, while keeping these reduced-step results distinct from attacks on full SHA-2.

  4. SecurityRepository

    Cybersecurity resources: posts, papers, and tools

    A GitHub awesome list collecting cybersecurity blog posts, writeups, papers, and tools.

    It offers engineers a starting point for discovering cybersecurity resources.

  5. SecurityRepository

    MogVMP statically devirtualizes VMProtect 3.0–3.5

    MogVMP is a static devirtualizer that lifts VMProtect-virtualized code to LLVM using Remill, then removes the VM layer through optimization. The author says the approach lifts the VM’s full x86 code.

    It offers engineers a codebase for studying static devirtualization and LLVM-based reverse engineering.

  6. Browser SSD Timing Side Channel Enables Activity Fingerprinting

    The linked paper describes using the browser’s Origin Private File System to measure SSD latency from a regular tab. The post reports 88% accuracy for identifying visited sites and 95% for detecting launched desktop apps.

    Engineers can assess how storage contention may expose cross-application activity without permissions or native code.

  7. SecurityArticle

    HDD Firmware Hacking: Dumping, Analysis, and Modification

    A series on dumping, reverse engineering, and modifying firmware on HDDs and SSDs. The post also mentions debugging via JTAG.

    It offers engineers a look at firmware-level analysis and modification of storage devices.

  8. SecurityArticle

    Post alleges legal-data extraction and WhatsApp automation tool

    The post alleges that ADV INFINITY extracts court cases, enriches data with Serasa information, and sends WhatsApp messages. It describes HWID licensing and a central heartbeat every 30 seconds.

    The described features raise security and privacy concerns around large-scale collection and handling of personal data.

  9. SecurityRepository

    C2IntelFeeds provides feeds of suspected and verified C2 infrastructure

    C2IntelFeeds is a repository of automatically generated C2 infrastructure feeds based on large-scale internet scanning data. It includes IPs, domains, URL paths, port combinations, and configuration metadata where available.

    Engineers can use the feeds for threat hunting and SIEM enrichment, while validating unverified indicators before blocking.

  10. SecurityRepository

    OpenVul: A Framework for LLM-Based Vulnerability Detection

    OpenVul is an open-source post-training framework for LLM-based vulnerability detection. Its GitHub repository describes the project.

    Engineers can review the framework as a resource for LLM-based vulnerability detection.

  11. SecurityRepository

    Linux kernel security and exploitation collection updated

    The Linux kernel exploitation collection has January and February updates, adding links related to Linux kernel security and exploitation.

    Engineers can use the collection to find resources on Linux kernel security and exploitation.

  12. Limitations of Ultrasonic Microphone Jammers

    The post questions claims made for a portable audio jammer, comparing it with existing ultrasonic jammers and DIY kits. It notes possible limits involving device detection, range, room reflections, fabric, and obstructions.

    Engineers evaluating privacy hardware should account for detection and acoustic constraints before relying on a jammer.

  13. SecurityArticle

    Praetorian’s Multi-Agent Pipeline for CVE Detection Templates

    Praetorian describes a multi-agent pipeline that turns CVE research into validated Nuclei detection templates. It uses specialized agents, three model providers, and an actor-critic refinement loop.

    Engineers can learn how AI agents are orchestrated to research vulnerabilities and produce validated detection templates.

  14. SecurityRepository

    Darkweb Scanner for Keyword Monitoring on .onion Sites

    The post describes osintph/darkweb-scanner as a keyword monitoring tool for .onion sites, intended for threat intelligence and brand monitoring. The linked GitHub page previews a threat intelligence and OSINT platform.

    Engineers evaluating threat intelligence tooling can inspect the linked project and its stated scope.

  15. SecurityArticle

    Technical analysis of Intel Management Engine vulnerabilities

    The article examines Intel Management Engine architecture and firmware, CVE-2017-5689 exploitation, a CVE-2025-20037 TOCTOU race condition, PKfail, and detection methods.

    It offers engineers technical context on Intel ME attack paths and detection.

  16. SecurityArticle

    Secure deletion in magnetic and solid-state storage

    Peter Gutmann’s 1996 paper discusses data remanence and secure deletion from magnetic and solid-state memory, including the limits of simply overwriting data once on magnetic media.

    It highlights why storage media and deletion methods matter when designing data sanitization procedures.

  17. VulnLLM-R-7B: A Reasoning Model for Vulnerability Detection

    VulnLLM-R-7B is presented as a specialized reasoning LLM for vulnerability detection. Its Hugging Face page is linked.

    Engineers evaluating LLM-based vulnerability detection can review the model page.

  18. SecurityArticle

    REMnux MCP Server Connects AI Agents to Malware Analysis Tools

    The REMnux MCP server connects AI agents to more than 200 REMnux tools and provides guidance on selecting tools and interpreting their output. The author describes capturing practitioner expertise to guide malware analysis.

    Engineers exploring AI-assisted malware analysis can see how tool access and expert guidance are combined.

  19. VulnLLM-R-7B: a model for vulnerability analysis

    VulnLLM-R-7B is presented as a reasoning model for finding code vulnerabilities by analyzing data and control flows. The linked Hugging Face page provides access to the model.

    Engineers can review the model and assess its suitability for vulnerability analysis workflows.

  20. Hex-Rays Decompiler Internals: Microcode

    A presentation on the internals of the IDA Pro Hex-Rays decompiler, including microcode. The post links to a video and a PDF.

    Useful background for engineers working with reverse engineering and decompiler internals.

Build with AgentLog

List your MCP, skill or plugin

Reach the engineers who read these briefings.

Sponsor AgentLog

Footer, sidebar or featured slot for 30 days.

From US$ 60

See the slots

Send your own newsletter

CommsHarbor keeps contacts, consent and one-click unsubscribe together.

Free workspace

Open CommsHarbor