<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security Pills</title>
    <description>Join +5,000 readers getting the latest security articles, tools, and talks straight into their inbox each Monday.</description>
    
    <link>https://newsletter.securitypills.news/</link>
    <atom:link href="https://rss.beehiiv.com/feeds/rbnUHguXFF.xml" rel="self"/>
    
    <lastBuildDate>Fri, 7 Aug 2026 01:46:48 +0000</lastBuildDate>
    <pubDate>Mon, 02 Mar 2026 11:00:00 +0000</pubDate>
    <atom:published>2026-03-02T11:00:00Z</atom:published>
    <atom:updated>2026-08-07T01:46:48Z</atom:updated>
    
      <category>Cybersecurity</category>
      <category>Technology</category>
    <copyright>Copyright 2026, Security Pills</copyright>
    
    <image>
      <url>https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/publication/logo/b5f4e429-9d5d-485e-8963-4457136d364e/Screenshot_2026-02-09_at_11.55.00.png</url>
      <title>Security Pills</title>
      <link>https://newsletter.securitypills.news/</link>
    </image>
    
    <docs>https://www.rssboard.org/rss-specification</docs>
    <generator>beehiiv</generator>
    <language>en-us</language>
    <webMaster>support@beehiiv.com (Beehiiv Support)</webMaster>

      <item>
  <title>💊 Security Pills - #61</title>
  <description>Unrolling the Codex Agent Loop | LLM-Powered AMSI Provider vs. Red Team Agent | Leveraging Codex in an agent-first world</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/756e447c-2d60-4350-82da-93f99551795b/issue61.png" length="1376069" type="image/png"/>
  <link>https://newsletter.securitypills.news/p/security-pills-61</link>
  <guid isPermaLink="true">https://newsletter.securitypills.news/p/security-pills-61</guid>
  <pubDate>Mon, 02 Mar 2026 11:00:00 +0000</pubDate>
  <atom:published>2026-03-02T11:00:00Z</atom:published>
    <dc:creator>Sebas Guerrero</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #a89984; }
  .bh__table_cell { padding: 5px; background-color: #fbfbfb; }
  .bh__table_cell p { color: #4a4a4a; font-family: 'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#ececec; }
  .bh__table_header p { color: #333333; font-family:'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e9de63ca-f517-41b8-8cb0-25b8f839c00f/Screenshot_2026-01-31_at_16.37.16.png?t=1769874963"/></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><b>Release Date: </b></span><span style="font-size:0.8rem;">2nd March 2026</span><span style="font-size:0.8rem;"><b> | Issue: </b></span><span style="font-size:0.8rem;">61 </span><span style="font-size:0.8rem;"><b>| </b></span><span style="font-size:0.8rem;"><a class="link" href="https://securitypills.beehiiv.com/subscribe?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-61" target="_blank" rel="noopener noreferrer nofollow"><b>Subscribe</b></a></span></p><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><i>The Security Pills newsletter is a hand curated zine (delivered once per week) that highlights security related-news. 10+ hours of reading and analysis condensed into a 5-minute summary every Monday morning.</i></span></p></div><div class="section" style="background-color:#F2F2F2;border-color:#DADADA;border-style:dotted;border-width:2px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:center;"><span style="color:#4A4A4A;font-size:0.8rem;"><b>Sponsor</b></span><br><span style="color:#4A4A4A;font-size:0.8rem;">Would you like to become a sponsor for our newsletter? Our mission is to highlight security-related news with a focus on quality content, while we help people staying up to date with this corner of the industry.If you are interested, reach out to </span><span style="color:#4A4A4A;font-size:0.8rem;"><b>hello@securitypills.news</b></span><span style="color:#4A4A4A;font-size:0.8rem;"> with your ad idea to get started!</span></p></div><hr class="content_break"><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Application Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://obaid.wtf/jotbook/2026/02/22/arts-council-database-20k-attendees-exposed.html?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Arts Council of Pakistan Database Exposed with 20k+ Attendee Records</a></b><br>The Arts Council of Pakistan&#39;s event management database was found sitting wide open, exposing over 20,000 attendees including names, emails, phone numbers, payment details, and event tickets. Supabase security controls had been disabled and an API key had been left public since September 2025. Beyond the data exposure, image URL fields could also be pointed at an external server, quietly pulling visitor IP addresses, timestamps, and device info without anyone knowing.</p><p class="paragraph" style="text-align:left;">This is becoming a familiar pattern with Supabase-backed apps, the tooling makes it easy to ship fast, but also easy to ignore every security warning on the way out the door.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://kqx.io/post/firefox0day/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">How a single typo led to RCE in Firefox</a></b><br><i>Alessio Ghidini</i> found a remote code execution vulnerability in Firefox&#39;s SpiderMonkey JavaScript engine caused by a single character typo in the source code. A bitwise AND operator used instead of OR when setting WebAssembly array forwarding pointers causes the engine to store 0 instead of a valid address, which eventually leads to a use-after-free condition during garbage collection. From there, heap spraying turns the corrupted pointer into arbitrary read/write access and code execution.<br></p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/HackingDave/btrpa-scan?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">BLE Scanner with Resolvable Private Address Resolution Using Identity Resolving Keys</a></b><br>btrpa-scan is a Bluetooth Low Energy scanner that can resolve privacy-randomized device addresses using Identity Resolving Keys in real time. It comes with a live terminal view sorted by signal strength, a browser-based radar GUI with an animated sweep display, and batch export with optional CSV streaming. You can filter by signal strength, estimate distance based on environment, set proximity alerts, and run multiple adapters at once, with optional GPS tagging for each detection.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Artificial Intelligence</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://openai.com/index/unrolling-the-codex-agent-loop/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Unrolling the Codex Agent Loop</a></b><br>OpenAI&#39;s <i>Michael Bolin</i> explains how Codex CLI handles long-running agent sessions by building prompts turn by turn, appending tool outputs and user inputs using Server-Sent Events from the Responses API. The design ensures every new prompt is an exact extension of the previous one, keeping caching efficient throughout the session. Configuration changes follow the same logic, getting appended as new messages rather than restructuring what came before.</p><p class="paragraph" style="text-align:left;">When the context gets too long, Codex compresses it automatically through a dedicated endpoint that hands back a smaller list with an encrypted item that preserves the model&#39;s context without eating up the context window.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/hackingdave/nightwire?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Nightwire: A Signal-Based Bot for Remote Code Development and Autonomous Tasks</a></b><br><i>David Kennedy</i> released Nightwire, a Signal-based bot that lets you manage your development workflow through Claude from anywhere. You send messages through Signal, it handles the coding tasks, maintains project context across sessions, and keeps everything organized into stories and parallel workstreams. Basically a dev environment you can drive from your phone.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.provos.org/p/ironcurtain-secure-personal-assistant/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">IronCurtain: A Personal AI Assistant Built Secure from the Ground Up</a></b><br><i>Niels Provos</i> walks through IronCurtain, a personal AI assistant architecture built on the premise that you cannot trust agents to stay in their lane. A trusted MCP proxy sits between agents and everything else, and agents never touch real credentials since a MITM proxy handles authentication behind the scenes. The system supports two sandbox modes: Code Mode runs LLM-generated TypeScript in V8 isolates, while Docker Mode puts autonomous agents in network-restricted containers. Security policies are described in plain text and enforced deterministically, so prompt injection or model drift gets contained without relying on the model to stay honest.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.aikido.dev/blog/ai-pentesting-agent-security?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">How Aikido Secures AI Pentesting Agents and Prevents Scope Drift</a></b><br>Aikido&#39;s <i>Sooraj Shah</i> walks through how the team built scope enforcement into their AI pentesting agents by design rather than relying on prompts or human discipline. At the architectural level, the control plane is fully separated from isolated execution sandboxes, meaning agents have no access to Aikido&#39;s infrastructure or other active sessions. From there, network restrictions block any domain not on an allowlist by default, which handles both accidental scope drift and data exfiltration in one shot. On top of that, production is never assumed in scope, pre-flight checks catch misconfigurations before tests start, and every agent action is visible in real time with the ability to pause immediately.</p><p class="paragraph" style="text-align:left;">If you are building or experimenting with your own agents, this is an interesting blueprint for thinking through the guardrails</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Blue Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow"><b>AI Recommendation Poisoning: Memory Manipulation Across Multiple Attack Vectors</b></a></p><p class="paragraph" style="text-align:left;">Microsoft researchers caught companies embedding hidden instructions in &quot;Summarize with AI&quot; buttons that, when clicked, open your AI assistant with a pre-filled prompt that saves itself to memory. The result is that your AI starts favoring whoever planted it in future responses, with no indication anything changed. They found over 50 of these prompts from 31 companies across industries like finance, health, and security. Microsoft has added protections on their end, but opening your AI assistant&#39;s memory settings to see what&#39;s in there is worth doing.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/HackingLZ/defender_overview?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">Overview of MS Defender: Reverse Engineering Breakdown of the 13-Stage Scan Pipeline</a></b></p><p class="paragraph" style="text-align:left;">This reverse engineering reference maps out Microsoft Defender&#39;s full scan pipeline inside mpengine.dll, the core engine that processes files, scripts, and memory on Windows systems. It covers each stage from trusted file whitelisting through signature scanning, PE emulation, script deobfuscation, recursive content extraction, and cloud escalation.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.cloudflare.com/aspa-secure-internet/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">ASPA: making Internet routing more secure</a></b></p><p class="paragraph" style="text-align:left;">ASPA is a new cryptographic standard that prevents BGP route leaks by validating the full path network traffic takes, not just its destination. While RPKI already handles origin verification through ROA records, ASPA lets networks publish their authorized upstream providers so anyone receiving traffic can check it came through the right hands. Cloudflare&#39;s <i>Mingwei Zhang</i> and <i>Bryton Herdes</i> break down how it works and introduce a new Radar feature for tracking ASPA adoption across regional internet registries.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Cloud Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://trufflesecurity.com/blog/google-api-keys-werent-secrets-but-then-gemini-changed-the-rules?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Google API Keys Weren&#39;t Secrets. But then Gemini Changed the Rules</a></b><br>Truffle Security&#39;s <i>Joe Leon</i> found that Google&#39;s API key design left publicly committed credentials exposed to Gemini API access when the Generative Language API was enabled on projects. A scan of publicly archived pages turned up 2,863 vulnerable keys from major institutions, many deployed years before Gemini existed as nothing more than project identifiers.</p><p class="paragraph" style="text-align:left;">New keys get unrestricted access to all enabled APIs by default, so old keys sitting in public repos suddenly became a way to access uploaded files, cached data, and charge LLM usage to someone else&#39;s account. Google has since committed to scoped defaults for new keys and proactive notification when breaches are identified.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.qualys.com/qualys-insights/2026/02/19/how-security-tool-misuse-is-reshaping-cloud-compromise?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Cloud Credential Misuse: Detection and Prevention Guide 2026</a></b><br>Qualys&#39; <i>Sayali Warekar</i> looks at how attackers are repurposing legitimate secret-scanning tools like TruffleHog to find and validate leaked cloud credentials, often turning a discovery into active access within minutes. The article covers what to look for in CloudTrail logs to catch this behavior early, and makes the case that short-lived keys and tighter IAM scope are what actually limit the damage when credentials leak.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://aws.amazon.com/blogs/security/building-an-ai-powered-defense-in-depth-security-architecture-for-serverless-microservices/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Building an AI-powered defense-in-depth security architecture for serverless microservices</a></b><br>AWS&#39;s <i>Roger Nem</i> walks through a defense-in-depth architecture for serverless microservices that layers independent controls across seven security tiers, from edge protection down to data access. The setup splits traffic across public, private, and data subnets, with GuardDuty using generative AI for threat detection and Lambda pulling secrets at runtime so credentials never touch the codebase. On top of that, Amazon Bedrock monitors DynamoDB Streams and CloudTrail to catch anomalous access patterns and insider threats before they go unnoticed.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Container Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.docker.com/blog/openwebui-docker-model-runner/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">OpenWebUI + Model Runner: Zero-Config Local AI Integration</a></b><br>Docker&#39;s <i>Ignacio Lopez</i> walks through how Docker Model Runner and Open WebUI now work together out of the box. Open WebUI automatically picks up Docker Model Runner running at <a class="link" href="https://localhost:12434?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-61" target="_blank" rel="noopener noreferrer nofollow">localhost:12434</a> with no manual configuration, so you can go from nothing to chatting with a local model through a web interface in a few minutes. Both projects stay independent but connect cleanly through well-defined interfaces, which means you can run the setup on a laptop, a remote machine, or an internal server without changing anything.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="custom_html"><iframe src="https://embeds.beehiiv.com/871248b5-9b15-458d-a926-7e9d8a922e98" data-test-id="beehiiv-embed" width="100%" height="320" frameborder="0" style="margin: 0; background-color: transparent;"></iframe></div></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Red Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://substack.com/home/post/p-188916866?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">100+ Kernel Bugs in 30 Days: High-Scale Driver Vulnerability Research with Agent Swarms</a></b><br><i>Yaron Dinkin</i> and <i>Eyal Kraft</i> built an automated platform that uses AI agent swarms to audit Windows kernel drivers for memory corruption vulnerabilities at scale, running the entire thing for around $600. From a dataset of over 1,800 binaries, they selected 202 high-risk drivers for full analysis, validating 15 vulnerabilities requiring only unprivileged user access. They estimate over 100 exploitable local privilege escalation paths exist across mainstream vendor drivers from AMD, Intel, NVIDIA, Dell, Lenovo, and IBM.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://dreadnode.io/blog/llm-powered-amsi-provider-vs-red-team-agent?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">LLM-Powered AMSI Provider vs. Red Team Agent</a></b><br>Dreadnode&#39;s <i>Max Harley</i> built a system that runs a Claude Sonnet powered red team agent against an LLM-based AMSI provider to see what gets through. The agent generates PowerShell attack code for user-defined objectives, running scripts in-memory via UnmanagedPowerShell to make sure AMSI actually sees them. When the provider blocks a script, the error goes back to the agent for another evasion attempt, up to ten rounds. The result is AMSI-Eval, a dataset of scripts verified to run on real systems, mixed with clean samples to keep classifier training honest.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://dreadnode.io/blog/186-jailbreaks-applying-mlops-to-ai-red-teaming?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">186 Jailbreaks: Applying MLOps to AI Red Teaming</a></b><br>Dreadnode&#39;s <i>Raja Sekhar</i> documents a systematic red teaming assessment of Llama Maverick using MLOps principles, producing 186 different jailbreaks across eight harm categories in just over two hours.</p><p class="paragraph" style="text-align:left;">Three attack methodologies were tested, and across all of them the pattern was consistent: safety training breaks down under sustained pressure and rephrasing, with Crescendo hitting 97.5% success just by gradually escalating across multiple turns. Multi-modal attacks follow the same logic, slipping through defenses that evaluate each component in isolation rather than looking at intent as a whole. Something to keep in mind as multi-modal models become harder to evaluate at scale.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/Orange-Cyberdefense/GOAD?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">GOAD: Game of Active Directory - Pentest Lab Project</a></b><br>GOAD is a pentest training lab that spins up intentionally vulnerable Active Directory environments in multiple configurations, from basic single-domain setups to complex multi-forest deployments. It also includes specialized configurations for SCCM and challenge-based scenarios.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Supply Chain</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/toborrm9/malicious_extension_sentry?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Malicious Extension Database</a></b><br>Malicious Extension Sentry is an automated database of Chrome extensions removed for malicious behavior. It pulls removal data from multiple sources and comes with a cross-platform scanning tool that checks installed extensions against the database locally. Useful for anyone doing extension vetting or security research.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.cloudflare.com/vinext/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">How we rebuilt Next.js with AI in one week</a></b><br>Cloudflare&#39;s <i>Steve Faulkner</i> rebuilt Next.js as a Vite-based alternative called vinext in under a week with AI, getting to 4x faster builds and 57% smaller bundles that deploy directly to Cloudflare Workers. The interesting part is Traffic-aware Pre-Rendering, which pulls Cloudflare analytics to only pre-render pages that actually get traffic and leaves the rest to on-demand SSR.</p><p class="paragraph" style="text-align:left;">Total cost was around $1,100 in tokens, though it took constant human oversight to stop the agents from going off track. Impressive scope for a solo week-long project.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://openai.com/index/harness-engineering/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Harness engineering: leveraging Codex in an agent-first world</a></b><br>OpenAI&#39;s <i>Ryan Lopopolo</i> shares how his team built a production software product entirely through Codex agents over five months, generating one million lines of code at roughly 10x typical development speed. Engineers stopped writing code and started designing environments, specifying intent, and building feedback loops while agents handled everything from coding to PR reviews to merging. Keeping things consistent required strict structural rules enforced through custom linters and tests, with agents escalating to humans only when judgment was needed.</p><p class="paragraph" style="text-align:left;">Worth reading if you&#39;re thinking seriously about how software engineering actually changes when agents are doing most of the work.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://socket.dev/blog/stegabin-26-malicious-npm-packages-use-pastebin-steganography?utm_medium=email&utm_source=securitypills&utm_campaign=issue-61&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">StegaBin: 26 Malicious npm Packages Use Pastebin Steganography for Credential Theft</a></b><br>Socket&#39;s <i>Philipp Burckhardt</i> and <i>Peter van der Zee</i> uncovered a 26-package npm supply chain campaign attributed to North Korean threat actor FAMOUS CHOLLIMA. The packages hide C2 addresses inside Pastebin images using steganography, pull platform-specific payloads from 31 Vercel domains, and deploy a RAT that phones home to a hardcoded IP. Once in, nine infostealer modules go after everything a developer would have on their machine: VSCode persistence, keylogging, SSH keys, git credentials, crypto wallet data across 86 browser extensions, and a weaponized TruffleHog binary scanning the filesystem for secrets.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;"><b>Threat Hunting</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-gridtide-global-espionage-campaign/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Disrupting the GRIDTIDE Global Cyber Espionage Campaign</a></b><br>Google Threat Intelligence Group and Mandiant disrupted a global espionage campaign by UNC2814, a suspected China-nexus group with confirmed intrusions across 42 countries targeting telecommunications and government organizations. The group deployed GRIDTIDE, a backdoor that abuses Google Sheets as a C2 channel, using cell-based polling with AES-128 encryption to stay under the radar while pulling names, phone numbers, and national IDs. Google shut down the attacker-controlled Cloud Projects, revoked Sheets API access, and published indicators of compromise from activity dating back to at least 2023.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.cloudflare.com/toxic-combinations-security/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Toxic combinations: when small signals add up to a security incident</a></b><br>Cloudflare&#39;s <i>Bashyam Anant</i> and <i>Himanshu Anand</i> look at how small misconfigurations turn into real problems once automated scanners find them. They walk through three patterns they see regularly: exposed monitoring endpoints leaking infrastructure details, unauthenticated search enabling bulk data scraping, and payment fraud that shows up as suspicious spikes in transaction volume and IP density. For each one they cover what to look for and how to shut it down.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://krebsonsecurity.com/2026/02/starkiller-phishing-service-proxies-real-login-pages-mfa/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-61&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Starkiller Phishing Service Proxies Real Login Pages and MFA Credentials</a></b><br><i>Brian Krebs</i> covers Starkiller, a phishing-as-a-service platform that proxies real login pages to intercept credentials and MFA codes in real time. It removes the usual setup friction of configuring domains and certificates, and sidesteps domain blocklisting by design. Attackers with minimal skills can now run credential theft campaigns with session hijacking and analytics capabilities that used to take real expertise to pull off.</p></div><div class="section" style="background-color:#E6E6E6;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#4A4A4A;font-size:1.5rem;"><b>Wrapping Up</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><br>If you enjoyed this newsletter and think others would too, It would mean a lot for us if you&#39;d forward this email to other people who may enjoy it as well. You can also reply to this email, I&#39;d love to get in touch with you.</p><p class="paragraph" style="text-align:left;">Thanks,<br><a class="link" href="https://twitter.com/0xroot?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-61" target="_blank" rel="noopener noreferrer nofollow">Sebas</a><br></p><p class="paragraph" style="text-align:left;"></p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=341ed974-f2d6-4c54-aa78-a0f0c7fe1364&utm_medium=post_rss&utm_source=security_pills">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>💊 Security Pills - #60</title>
  <description>Data Exfiltration in Gemini via Phone Call | Silent Codebase Exfiltration via Skills | Evaluating AI Agents Across Real-World Security Challenges</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/06b9da5e-3677-4704-a045-31aa8dcda146/issue60.png" length="1362617" type="image/png"/>
  <link>https://newsletter.securitypills.news/p/security-pills-60</link>
  <guid isPermaLink="true">https://newsletter.securitypills.news/p/security-pills-60</guid>
  <pubDate>Mon, 23 Feb 2026 15:16:14 +0000</pubDate>
  <atom:published>2026-02-23T15:16:14Z</atom:published>
    <dc:creator>Sebas Guerrero</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #a89984; }
  .bh__table_cell { padding: 5px; background-color: #fbfbfb; }
  .bh__table_cell p { color: #4a4a4a; font-family: 'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#ececec; }
  .bh__table_header p { color: #333333; font-family:'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/e9de63ca-f517-41b8-8cb0-25b8f839c00f/Screenshot_2026-01-31_at_16.37.16.png?t=1769874963"/></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><b>Release Date: </b></span><span style="font-size:0.8rem;">23rd February 2026</span><span style="font-size:0.8rem;"><b> | Issue: </b></span><span style="font-size:0.8rem;">60 </span><span style="font-size:0.8rem;"><b>| </b></span><span style="font-size:0.8rem;"><a class="link" href="https://securitypills.beehiiv.com/subscribe?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-60" target="_blank" rel="noopener noreferrer nofollow"><b>Subscribe</b></a></span></p><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><i>The Security Pills newsletter is a hand curated zine (delivered once per week) that highlights security related-news. 10+ hours of reading and analysis condensed into a 5-minute summary every Monday morning.</i></span></p></div><div class="section" style="background-color:#F2F2F2;border-color:#DADADA;border-style:dotted;border-width:2px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:center;"><span style="color:#4A4A4A;font-size:0.8rem;"><b>Sponsor</b></span><br><span style="color:#4A4A4A;font-size:0.8rem;">Would you like to become a sponsor for our newsletter? Our mission is to highlight security-related news with a focus on quality content, while we help people staying up to date with this corner of the industry.If you are interested, reach out to </span><span style="color:#4A4A4A;font-size:0.8rem;"><b>hello@securitypills.news</b></span><span style="color:#4A4A4A;font-size:0.8rem;"> with your ad idea to get started!</span></p></div><hr class="content_break"><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Application Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.doyensec.com/2026/02/16/electron-safe-updater.html?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Building a Secure Electron Auto-Updater</a></b><br>Doyensec&#39;s <i>Michael Pastor</i> looked at how Signal Desktop handles software updates and built something similar for the broader Electron ecosystem. The result is <code>SafeUpdater</code>, a reference implementation that shows what a proper update pipeline looks like when you actually account for attackers. It verifies signatures, checks file integrity, and controls where temporary files land before anything gets installed. The goal is to give Electron developers a concrete starting point for shipping updates they can actually trust.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://xbow.com/blog/tales-from-the-trace-how-xbow-reasons-its-way-into-finding-idors?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Tales from the Trace: How XBOW reasons its way into finding IDORs</a></b><br>XBOW&#39;s <i>Adrian Losada</i> walks through two IDOR vulnerabilities that the XBOW agent discovered in Spree Commerce, both now fixed. The first was straightforward: address edit pages had no access controls, exposing full user PII to anyone. The second required more work. The agent created two separate shopping carts and found that one cart&#39;s token could access addresses belonging to the other due to missing authorization checks.</p><p class="paragraph" style="text-align:left;">What makes it interesting is how XBOW got there. Instead of just trying random parameter values, it analyzed the application&#39;s access control logic and adjusted when it hit errors.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.sebsrt.xyz/blog/trailing-danger/?utm_campaign=issue-60&utm_medium=email&utm_source=securitypills&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Trailing Danger: Exploring HTTP Trailer Parsing Discrepancies</a></b><br><i>Sebastiano Sartor</i> explores how inconsistent handling of HTTP trailer fields across roughly 70 open-source implementations leads to a request smuggling class he calls Trailer Merge (TR.MRG). The post compares behavior across HTTP/1.1, HTTP/2, and HTTP/3, showing how merging trailers into headers after dechunking lets attackers override security-sensitive headers like Host, Content-Length, or Transfer-Encoding, with lighttpd 1.4.80 as a concrete example.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/spaceraccoon/vulnerability-spoiler-alert?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow"><b>spaceraccoon/vulnerability-spoiler-alert</b></a><br><i>Eugene Lim</i> built Vulnerability Spoiler Alert to catch security patches in popular repositories before a CVE ever gets assigned. Every six hours it pulls commit diffs and runs them through Claude to spot potential vulnerabilities, then posts the findings to a static website with an RSS feed. Confirmed and false positive results get sorted through GitHub Issues labeling.<br></p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Artificial Intelligence</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.wiz.io/cyber-model-arena?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Cyber Model Arena: Evaluating AI Agents Across Real-World Security Challenges</a></b><br>Wiz Research launched the AI Cyber Model Arena, benchmarking 25 agent/model combinations across 257 offensive security challenges spanning zero days, code vulnerabilities, API/web security, and cloud misconfigurations. Four agents (Gemini CLI, Claude Code, OpenCode, Codex) were tested against nine models including Claude variants, Gemini, GPT 5.2, and Grok 4 in isolated Docker containers with deterministic scoring. The results showed no single pairing dominated all categories, with the same model performing very differently depending on which agent was running it.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/Pavelevich/llm-checker?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow"><b>Pavelevich/llm-checker</b></a><br>LLM Checker is a CLI tool that analyzes your system hardware and recommends which Ollama models you can run locally. It scores 200+ model variants across quality, speed, memory fit, and context length, with weights that adjust based on your use case (coding, chat, reasoning).</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.anthropic.com/news/claude-code-security?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Making frontier cybersecurity capabilities available to defenders</a></b><br>Anthropic launched Claude Code Security in limited research preview, a tool that finds vulnerabilities by reasoning about code like a security researcher, understanding component interactions and tracing data flow rather than matching known patterns. Each finding undergoes multi-stage verification where Claude re-examines its results to filter false positives, assigns severity ratings for prioritization, and surfaces suggested patches for human review.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.linkedin.com/posts/ehsandeepsingh_neo-just-got-a-deploy-agent-for-runtime-validation-activity-7430693676970016768-Qu9j?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Neo Deploy Agent for Runtime Validation in Security Review and Research</a></b><br>ProjectDiscovery&#39;s Neo launched a Deploy Agent that eliminates manual environment setup for security validation. The automated tool accepts CVEs or pull requests, spins up applications, and provides runtime validation with proof-of-concept demonstrations for CVE verification and live PR testing.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://engineering.block.xyz/blog/3-principles-for-designing-agent-skills?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">3 Principles for Designing Agent Skills</a></b><br>Block&#39;s <i>Angie Jones</i> shares three principles for designing Agent Skills. First, be deliberate about what agents should not decide, keeping deterministic tasks like scoring algorithms and CLI commands in hard rules to ensure consistency. Second, let agents handle what they excel at: reasoning about context, interpreting results, and generating tailored recommendations. Third, treat <i>SKILL.md</i> files as strict contracts that prevent agents from improvising in ways that break intended workflows.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Blue Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.okta.com/blog/threat-intelligence/detecting-openclaw-advanced-posture-checks/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">Detecting OpenClaw using advanced posture checks</a></b><br>Okta&#39;s <i>Rafa Bono</i> published a detection guide for OpenClaw built around advanced posture checks that scan devices across eight vectors: launchd services, file searches, running processes, package managers, listening ports (9090, 18789, 18791), installed applications, and Docker containers. Instead of relying on name matches alone, the guide implements a scoring model that requires hits from two or more sources before flagging a detection, keeping false positives low and giving security teams something worth acting on.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://research.cotool.ai/benchmarks/botsv3?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">AI Research in Security Operations: Frontier Model Benchmarks on Real-World SecOps Tasks</a></b><br>Cotool benchmarked frontier and open-weight AI models on real-world security operations tasks using the Splunk BOTSv3 dataset, covering 2.7 million logs and 51 questions across cloud attack investigation, APT intrusions, and threat hunting.</p><p class="paragraph" style="text-align:left;">GPT-5.2 had the highest accuracy at 69%, with GPT-5.1 and Opus 4.5 not far behind. For cost, GPT-5.1 was the most economical frontier option at $1.67 per task, and Opus 4.5 was the quickest at 113 seconds on average. Most models had no trouble completing tasks, though long-context log analysis gave GPT-OSS-120b and several Gemini models a hard time.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Cloud Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.plerion.com/blog/testing-access-to-aws-resources?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Testing Access to AWS Resources Without Angering the People That Pay the Bills</a></b><br>Plerion&#39;s <i>Daniel Grzelak</i> walks through how to verify AWS resource access permissions without reading sensitive data or changing state. The approach exploits the consistent order in which AWS validates requests, where the error you get back reveals whether access exists before any action is performed. The post covers four probing techniques, from comparing authenticated against unauthenticated requests to crafting malformed inputs that pass authorization but fail validation. To confirm a malformed request actually proves authorization, Daniel introduces a three-topic method that tests against allowed, denied, and nonexistent resources in parallel.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.wiz.io/blog/detecting-malicious-oauth-applications?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Automatically detecting malicious Azure OAuth applications using LLMs</a></b><br>Wiz Research developed OAuth Apps Scout, an automated detection pipeline that identifies malicious OAuth applications in Entra ID by analyzing app metadata, reply URLs, permissions, and infrastructure patterns. The system uncovered a 2025 campaign involving 19 malicious applications impersonating Adobe, DocuSign, and OneDrive across multiple organizations. </p><p class="paragraph" style="text-align:left;">The same pipeline also caught seven older applications from 2019 that used Cyrillic homoglyphs to spoof Microsoft services across 50+ organizations. Attackers have moved from impersonating Microsoft directly to spoofing third party SaaS brands, but the artifacts they leave behind haven&#39;t changed much.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Mobile Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://bughunters.google.com/blog/passkeys?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=mobile-security" target="_blank" rel="noopener noreferrer nofollow">A Beginners Guide: Cross-Device Passkeys</a></b><br>Google&#39;s <i>Harsh Lal</i> walks through hybrid transport, a mechanism that lets users authenticate with their passkey on devices where it isn&#39;t stored, like public terminals or shared computers. The flow starts when the client device displays a QR code that the user scans with their phone to establish an end-to-end encrypted tunnel, while Bluetooth Low Energy confirms physical presence to prevent remote attacks. </p><p class="paragraph" style="text-align:left;">The phone then signs a cryptographic challenge from the server using its private key, which never leaves the device, and sends the signature back through the tunnel for verification. It keeps passkeys phishing resistant while solving the main adoption barrier: accessing accounts across devices without exposing credentials on unfamiliar machines.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.starstrike.ai/posts/phoneleak-data-exfiltration-in-gemini-via-phone-call/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=mobile-security" target="_blank" rel="noopener noreferrer nofollow">PhoneLeak: Data Exfiltration in Gemini via Phone Call</a></b><br>Starstrike researchers (alongside rez0, rhynorater, and lupin) won Most Creative Finding and a $9,137 bounty at Google&#39;s Bugswat Live Hacking Event in Tokyo for a data exfiltration vulnerability in Gemini&#39;s Android app. The attack used a fake captcha app to tapjack victims into sending a prompt through Gemini, which then chained tool calls without user confirmation to read notification contents including 2FA codes and PII. </p><p class="paragraph" style="text-align:left;">For exfiltration, the team encoded stolen data into DTMF dial strings, having Gemini&#39;s Phone tool call the attacker&#39;s number and play the data as tones on pickup. A nice callback to the phone phreaking days. Google patched the issue in November 2025.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="custom_html"><iframe src="https://embeds.beehiiv.com/871248b5-9b15-458d-a926-7e9d8a922e98" data-test-id="beehiiv-embed" width="100%" height="320" frameborder="0" style="margin: 0; background-color: transparent;"></iframe></div></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Red Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/deathlabs/hades?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow"><b>deathlabs/hades</b></a><br>HADES (Harnessing AI to Disrupt and Evaluate Security) is an adversary emulation platform built for blue teamers who want to train against realistic attacks without hiring a red team. It runs AI driven adversary agents in Docker containers that coordinate over RabbitMQ and use OpenAI&#39;s API to decide what to do next based on what they discover in the environment, so attacks adapt instead of following a script.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.praetorian.com/blog/mcp-server-security-the-hidden-ai-attack-surface?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">MCP Server Security: The Hidden AI Attack Surface</a></b><br>Praetorian researchers demonstrate how malicious MCP servers exploit authorized connections users have already established, executing arbitrary code, intercepting queries to exfiltrate sensitive data, and injecting social engineering payloads into AI responses while appearing completely legitimate. The research covers server chaining attacks where malicious local servers sit between users and trusted integrations like Slack or Google Drive, capturing data flows without touching the legitimate services. The post also explores supply chain risks, where attackers slip malicious tools into internal MCP development through compromised package managers and CI/CD pipelines.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://blog.voorivex.team/shaking-the-mcp-tree?utm_campaign=issue-60&utm_medium=email&utm_source=securitypills&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow"><b>Shaking the MCP Tree: A Security Deep Dive</b></a><br>Voorivex&#39;s <i>Amirmohammad Safari</i> demonstrates how attackers can identify and exploit open Dynamic Client Registration endpoints in MCP servers. Path normalization tricks can bypass URL validation, while DCR&#39;s flexible redirect URI registration creates open redirects that enable SSRF attacks. Either way, attackers end up with direct access to MCP server tools and internal services intended only for AI assistants, skipping past authorization safeguards and consent mechanisms entirely.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Supply Chain</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.mitiga.io/blog/ai-agent-supply-chain-risk-silent-codebase-exfiltration-via-skills?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Silent Codebase Exfiltration via Skills</a></b><br>Mitiga Labs created a malicious AI agent skill disguised as a test generator that silently exfiltrated an entire codebase to an attacker&#39;s GitHub repository in just four user interactions, leaving no audit trail. When the initial instructions weren&#39;t stealthy enough, Cursor actually helped rewrite the skill to be quieter. In practice, an attacker could publish something like this to a public catalog like <a class="link" href="https://skills.sh?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-60" target="_blank" rel="noopener noreferrer nofollow">skills.sh</a> with bot inflated ratings and reach thousands of developers who install skills without a second look.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/AikidoSec/safe-chain?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow"><b>AikidoSec/safe-chain</b></a><br>Aikido Security&#39;s Safe Chain is a free malware protection tool that intercepts package installations across npm, yarn, pnpm, bun, pip, and other major package managers through a local proxy. It verifies downloads against Aikido&#39;s threat intelligence feed in real time and blocks newly published npm packages under 24 hours old by default. Supports both local development and CI/CD pipelines without requiring tokens.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://github.com/alice-dot-io/caterpillar?utm_source=securitypills&utm_medium=email&utm_campaign=issue-60&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow"><b>alice-dot-io/caterpillar</b></a><br><i>Iftach Orr</i> released Caterpillar, a security scanning library that analyzes AI agent skill files for malicious behavior before installation. The scanner detects threats like credential theft, data exfiltration, persistence mechanisms, crypto wallet theft, and supply chain attacks across three modes: an Alice API for comprehensive remote analysis, OpenAI integration using user credentials, and offline pattern matching.</p></div><div class="section" style="background-color:#E6E6E6;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#4A4A4A;font-size:1.5rem;"><b>Wrapping Up</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><br>If you enjoyed this newsletter and think others would too, It would mean a lot for us if you&#39;d forward this email to other people who may enjoy it as well. You can also reply to this email, I&#39;d love to get in touch with you.</p><p class="paragraph" style="text-align:left;">Thanks,<br><a class="link" href="https://twitter.com/0xroot?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-60" target="_blank" rel="noopener noreferrer nofollow">Sebas</a><br></p><p class="paragraph" style="text-align:left;"></p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=aa83d0a9-b065-485e-b3e6-2a86aa344763&utm_medium=post_rss&utm_source=security_pills">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>💊 Security Pills - #59</title>
  <description>RCE in Google&#39;s Antigravity IDE | Break LLM Workflows with Claude&#39;s Refusal Magic String | macOS Infostealers</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/1854eaec-d9b1-44ed-8ef9-77979e202096/issue59.png" length="980708" type="image/png"/>
  <link>https://newsletter.securitypills.news/p/security-pills-59</link>
  <guid isPermaLink="true">https://newsletter.securitypills.news/p/security-pills-59</guid>
  <pubDate>Mon, 16 Feb 2026 11:00:21 +0000</pubDate>
  <atom:published>2026-02-16T11:00:21Z</atom:published>
    <dc:creator>Sebas Guerrero</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #a89984; }
  .bh__table_cell { padding: 5px; background-color: #fbfbfb; }
  .bh__table_cell p { color: #4a4a4a; font-family: 'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#ececec; }
  .bh__table_header p { color: #333333; font-family:'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/71b81def-b1d8-4ec2-9859-b26a29ebcd62/Screenshot_2026-02-09_at_13.12.56.png?t=1770639417"/></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><b>Release Date: </b></span><span style="font-size:0.8rem;">16th February 2026</span><span style="font-size:0.8rem;"><b> | Issue: </b></span><span style="font-size:0.8rem;">59 </span><span style="font-size:0.8rem;"><b>| </b></span><span style="font-size:0.8rem;"><a class="link" href="https://securitypills.beehiiv.com/subscribe?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-59" target="_blank" rel="noopener noreferrer nofollow"><b>Subscribe</b></a></span></p><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><i>The Security Pills newsletter is a hand curated zine (delivered once per week) that highlights security related-news. 10+ hours of reading and analysis condensed into a 5-minute summary every Monday morning.</i></span></p></div><div class="section" style="background-color:#F2F2F2;border-color:#DADADA;border-style:dotted;border-width:2px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:center;"><span style="color:#4A4A4A;font-size:0.8rem;"><b>Sponsor</b></span><br><span style="color:#4A4A4A;font-size:0.8rem;">Would you like to become a sponsor for our newsletter? Our mission is to highlight security-related news with a focus on quality content, while we help people staying up to date with this corner of the industry.If you are interested, reach out to </span><span style="color:#4A4A4A;font-size:0.8rem;"><b>hello@securitypills.news</b></span><span style="color:#4A4A4A;font-size:0.8rem;"> with your ad idea to get started!</span></p></div><hr class="content_break"><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Application Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.hacktron.ai/blog/hacking-google-antigravity?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Remote Code Execution in Google&#39;s Antigravity IDE - $10,000 Bounty</a></b></p><p class="paragraph" style="text-align:left;">Hacktron AI found an RCE worth $10k in Google&#39;s Antigravity IDE browser extension. Because <code>externally_connectable</code> was set to all URLs, any webpage could message the extension directly. The <code>SaveScreenRecording</code> action passed attacker controlled paths to the language server unsanitized, allowing arbitrary file writes via path traversal in the <code>filename</code> parameter and code execution by dropping an executable in the user&#39;s <code>Startup</code> folder.</p><p class="paragraph" style="text-align:left;">Google added origin validation to the message handler, though the post shows that URL tricks and content script proxies can partially defeat it, with only the tab property check fully holding up.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://gmsgadget.com/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">GMSGadget: JavaScript Gadgets for XSS Mitigation Bypass</a></b></p><p class="paragraph" style="text-align:left;">GMSGadget is a research collection documenting JavaScript gadgets that can bypass XSS mitigations such as Content Security Policy and HTML sanitizers like DOMPurify. The collection catalogs gadgets across dozens of popular JavaScript libraries, providing metadata on browser compatibility, HTML attributes, CSP directives, and execution timing contexts.</p><p class="paragraph" style="text-align:left;">These are patched vulnerabilities and intended JavaScript behaviors rather than active exploits.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://unit42.paloaltonetworks.com/qr-codes-as-attack-vector/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Phishing on the Edge of the Web and Mobile Using QR Codes</a></b></p><p class="paragraph" style="text-align:left;">Palo Alto Unit 42 researchers break down how QR codes are being abused beyond basic phishing across three vectors: shortener services that mask malicious destinations behind trusted domains, in app deep links that trigger account takeovers on Signal, Telegram, WhatsApp and Line or kick off unauthorized payments, and direct APK downloads that skip app store review entirely.</p><p class="paragraph" style="text-align:left;">The real issue is that most people scanning a QR code just expect a webpage, not something linking a device to their messaging account or firing off a crypto transaction.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Artificial Intelligence</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.doyensec.com/2026/02/03/outline-audit-q32025.html?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Auditing Outline: Firsthand Lessons from Comparing Manual Testing and AI Security Platforms</a></b></p><p class="paragraph" style="text-align:left;">Doyensec&#39;s <i>Luca Carettoni</i> details vulnerabilities found during a manual security audit of Outline, including SSRF, XSS, and an IDOR bypassing authorization checks. To compare results, three AI security platforms were run in parallel against the same codebase. One caught the IDOR, but false positives far outnumbered real findings, and their convincing descriptions made triage harder, reinforcing that AI security tools still work better alongside human expertise than in place of it.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.mcp-trust.com/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">MCP Trust Registry — Know What&#39;s Safe to Connect</a></b></p><p class="paragraph" style="text-align:left;">The MCP Trust Registry scanned over 8,000 MCP servers and found that nearly 1 in 10 are compromised by critical vulnerabilities, including command injection flaws below the gateway layer and SSRF exposures that enable single-request access to internal networks. The free directory provides risk scores, vulnerability details, and remediation guidance to inform connection decisions before linking servers to agents.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/trailofbits/skills-curated?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">trailofbits/skills-curated: Curated, community-vetted Claude Code plugin marketplace</a></b></p><p class="paragraph" style="text-align:left;"><i>Trail of Bits</i> launched a security-reviewed Claude Code plugin marketplace to address risks posed by backdoors and malicious hooks discovered in published skills, as well as the lack of built-in quality gates in the plugin ecosystem. The repository hosts plugins that have passed Trail of Bits&#39; code review process, including their own tools and vetted third-party collections.</p><p class="paragraph" style="text-align:left;">Community contributions are welcome but must pass a formal security review and include proper attribution before inclusion.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.promptfoo.dev/blog/indirect-prompt-injection-web-agents/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Indirect Prompt Injection in Web-Browsing Agents</a></b></p><p class="paragraph" style="text-align:left;">promptfoo&#39;s <i>Yash Chhabria</i> explores how adversaries can attack web browsing AI agents by hiding malicious instructions in page content through HTML comments, CSS hidden text, or semantic embedding in legitimate prose. Of these techniques, semantic embedding proves hardest to defend against since models cannot distinguish instructions from content when both look like normal text.</p><p class="paragraph" style="text-align:left;">This matters because different models fail differently: Claude&#39;s instruction hierarchy helps it resist comment based injections, while GPT 4o/4.1&#39;s literal instruction following makes it more vulnerable to authoritative sounding text. Once an injection lands, it enables two outcomes: exfiltrating sensitive data by tricking agents into encoding it in URLs, or manipulating agent behavior by overriding safety guidelines entirely.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/trailofbits/claude-code-config?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits</a></b></p><p class="paragraph" style="text-align:left;"><i>Trail of Bits</i> released a production ready configuration framework for Claude Code targeting security audits, development, and research. It provides standardized templates through global <code>CLAUDE.md</code> files that define coding standards and toolchains, alongside specialized MCP servers for vulnerability scanning, binary analysis, and search. The framework includes context management strategies and security focused skills that bundle vulnerability checklists with analysis patterns, supported by multi agent workflows for automated planning and parallel security analysis.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://red.anthropic.com/2026/zero-days/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Evaluating and mitigating the growing risk of LLM-discovered 0-days</a></b></p><p class="paragraph" style="text-align:left;">Anthropic researchers put Claude Opus 4.6 in a VM with standard utilities and tools like debuggers and fuzzers, no special instructions or custom harnesses, and it found over 500 high severity memory corruption vulnerabilities in open source codebases. Its approach included digging through Git commit histories to find similar unpatched bugs, spotting unsafe function patterns like <code>strcat</code>, and understanding algorithm specific constraints to trigger edge cases that traditional fuzzers miss. Each finding was validated and deduplicated by Claude, then manually triaged by researchers who wrote patches before reporting.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://hackingthe.cloud/ai-llm/exploitation/claude_magic_string_denial_of_service/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Break LLM Workflows with Claude&#39;s Refusal Magic String</a></b></p><p class="paragraph" style="text-align:left;">Anthropic documents a magic string that lets developers trigger Claude 4 refusal behavior during QA testing. Security researcher Austin Parker points out that the real problem is the trigger being deterministic. If an attacker injects the string into prompt context through user input, RAG documents, tool outputs, or shared chat history, Claude immediately halts and returns <code>stop_reason &quot;refusal&quot;</code>. In systems that replay conversation history, that poisoned turn persists and breaks every future request until someone cleans the context. It is not a model vulnerability but an integration failure mode, so teams building on Claude should treat refusal handling and context hygiene as part of their security surface.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.wiz.io/blog/agentic-browser-security-2025-year-end-review?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Agentic Browsers in 2025: Security Risks and Defensive Evolution</a></b></p><p class="paragraph" style="text-align:left;">Wiz&#39;s <i>Rami McCarthy</i> looks back at a year of agentic browser security after every major vendor shipped one in 2025. Researchers kept breaking them through zero interaction exfiltration, CometJacking session hijacks, persistent memory poisoning, and task injection. AI browsers also consistently failed to spot phishing, and while vendors have thrown human in the loop confirmations, architectural isolation, and secondary LLM critics at the problem, prompt injection is still unsolved. </p><p class="paragraph" style="text-align:left;">For those experimenting now, McCarthy recommends three rules: isolate browser profiles from primary credentials, keep human confirmations on, and limit agents to low stakes tasks.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Blue Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://slack.engineering/streamlining-security-investigations-with-agents/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">AI Agents for Security Alert Investigation at Slack</a></b></p><p class="paragraph" style="text-align:left;">Slack&#39;s <i>Dominic Marks</i> walks through how their security team built a multi-agent AI system for investigating alerts, moving away from earlier prompt-based approaches toward a structured setup where separate agents handle coordination, deep analysis, and quality review across defined investigation phases. In one real investigation, the review agent caught a credential exposure the analyst had missed, which led the coordinator to redirect focus and escalate the finding. The underlying service architecture gives the team real-time visibility into investigations and cost controls, and the agents can surface things that static detection rules would never catch.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://slack.engineering/building-slacks-anomaly-event-response/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow"><b>Building Slack’s Anomaly Event Response</b></a></p><p class="paragraph" style="text-align:left;">Slack&#39;s engineering team details Anomaly Event Response (AER), an automated detection and response system for Enterprise Grid that cuts response time from days to minutes. AER monitors billions of daily events with thresholds tuned to each organization&#39;s patterns, detecting access from Tor exit nodes, data scraping, excessive downloads, session fingerprint mismatches, and unusual API activity. When triggered, it kills all active sessions and generates audit logs linking back to the originating anomaly. The system tracks whether suspicious behavior persists after terminations while preventing legitimate users from getting stuck in a loop.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Cloud Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.sysdig.com/blog/ai-assisted-cloud-intrusion-achieves-admin-access-in-8-minutes?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">AI-assisted cloud intrusion achieves admin access in 8 minutes</a></b></p><p class="paragraph" style="text-align:left;">Sysdig researchers documented a cloud intrusion where threat actors used LLM assistance to compromise AWS in under 10 minutes, starting with credentials from public S3 buckets. The attackers escalated privileges through Lambda code injection, moved laterally across 19 AWS principals, created backdoor admin users, abused Bedrock for LLMjacking, and launched GPU instances.</p><p class="paragraph" style="text-align:left;">LLM generated code with Serbian comments, hallucinated account IDs, and non existent GitHub repository references throughout the operation confirmed AI assisted execution.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.tenable.com/blog/google-looker-vulnerabilities-rce-internal-access-lookout?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">LookOut: Discovering RCE and Internal Access on Looker (Google Cloud & On-Prem)</a></b></p><p class="paragraph" style="text-align:left;">Tenable&#39;s <i>Liv Matan</i> discovered two critical vulnerabilities in Google Looker, collectively dubbed &quot;LookOut&quot;, enabling complete system compromise. The first chains path traversal, Git hook manipulation, and timing issues to achieve remote code execution. The second (CVE-2025-12743) bypasses security controls by intercepting web requests to access Looker&#39;s internal MySQL database, then uses SQL injection through LookML data tests to extract user data, system configurations, and stored secrets.</p><p class="paragraph" style="text-align:left;">In Google Cloud environments these flaws could allow cross tenant access to other customers&#39; data. While Google patched its managed Looker instances, organizations running customer hosted or on premises versions remain exposed until they apply the necessary updates.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://medium.com/@xcal/building-a-production-ready-snowflake-audit-log-pipeline-to-s3-6c4203dfa771?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Building a Production-Ready Snowflake Audit Log Pipeline to S3</a></b></p><p class="paragraph" style="text-align:left;">Snowflake audit logs can arrive hours late, so if your export pipeline advances the watermark to <code>CURRENT_TIMESTAMP</code> on each run, you&#39;re permanently skipping events. The fix is using the observed <code>MAX(timestamp)</code> from each export window and only advancing after a successful write. The article provides a full implementation: a stored procedure that runs every five minutes via a Snowflake task, incrementally exporting 20 audit views as partitioned JSON to S3. If something fails, state doesn&#39;t change and the next run picks up where it left off.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://labs.reversec.com/posts/2025/09/staying-sneaky-in-the-office-365?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Staying Sneaky in the Office (365)</a></b></p><p class="paragraph" style="text-align:left;">Reversec&#39;s <i>Christian Philipov</i> digs into SharePoint Online&#39;s pre authentication URL feature, enabled by default across tenants. SharePoint generates signed download URLs with a <code>tempauth</code> token for every file, and these bypass IP allowlists, Conditional Access policies, and sharing restrictions entirely.</p><p class="paragraph" style="text-align:left;">An attacker with read access can enumerate files via SharePoint&#39;s REST APIs and download them from any IP without needing session cookies. MSRC called it a guardrail rather than a security boundary and rated it low severity. Philipov recommends disabling it with <code>Set-SPOTenantPreAuthSettings -IsDisabled $true</code> unless there&#39;s a specific business need.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Container Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.docker.com/blog/docker-sandboxes-run-claude-code-and-other-coding-agents-unsupervised-but-safely/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">Docker Sandboxes </a></b><b><a class="link" href="https://www.docker.com/blog/docker-sandboxes-run-claude-code-and-other-coding-agents-unsupervised-but-safely/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">Run Claude Code and Other Coding Agents Unsupervised (but Safely)</a></b></p><p class="paragraph" style="text-align:left;">Docker released Sandboxes, using microVM isolation to let coding agents run unsupervised in dedicated environments on macOS and Windows. Each sandbox is a full dev environment where agents can install packages and run containers, fully isolated from the host with network controls and instant resets. No more constant permission prompts or risking your system just to let an agent do its job.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="custom_html"><iframe src="https://embeds.beehiiv.com/871248b5-9b15-458d-a926-7e9d8a922e98" data-test-id="beehiiv-embed" width="100%" height="320" frameborder="0" style="margin: 0; background-color: transparent;"></iframe></div></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Red Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/Maldev-Academy/DumpBrowserSecrets?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">DumpBrowserSecrets: Browser Data Extraction Tool for Chromium and Gecko Browsers</a></b></p><p class="paragraph" style="text-align:left;"><i>Maldev Academy</i> released DumpBrowserSecrets, a tool for extracting credentials, cookies, credit cards, tokens, and browsing history from Chrome, Edge, Firefox, Opera, and Vivaldi. It uses an executable to parse browser databases and a specialized DLL to retrieve encryption keys through process injection techniques. The tool handles different encryption schemes across browser families and offers flexible options for targeted or bulk extraction.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><a class="link" href="https://specterops.io/blog/2026/01/30/weaponizing-whitelists-an-azure-blob-storage-mythic-c2-profile/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow"><b>Weaponizing Whitelists: An Azure Blob Storage Mythic C2 Profile</b></a></p><p class="paragraph" style="text-align:left;">SpecterOps&#39; <i>Andrew Gomez</i> and <i>Allen DeMoura</i> released azureBlob, a Mythic C2 profile that routes agent communication through Azure Blob Storage, taking advantage of the broad <code>*.blob.core.windows.net</code> firewall exceptions that vendors like Citrix, Parallels, and Nerdio recommend in their deployment guides. Each agent gets a container scoped SAS token at payload generation so if one gets burned the damage stays contained, and the storage account key never leaves the Mythic server. Agents communicate through simple blob <code>PUTGETDELETE</code> operations, and the server discovers new agents automatically by enumerating containers.</p><hr class="content_break"></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Supply Chain</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/juanandresgs/claude-system?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">JAGS&#39; Batteries-Included Claude Code Configuration</a></b></p><p class="paragraph" style="text-align:left;">A Claude Code configuration system that enforces structured development practices through hooks operating at multiple lifecycle points, replacing unsafe defaults like direct main commits and test skipping with controlled workflows. Three specialized agents (Planner, Implementer, and Guardian) coordinate approval cycles while hooks block destructive operations, rewrite unsafe commands, require test evidence before commits, and enforce plan driven development independent of model behavior or context window pressure.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/spaceraccoon/vulnerability-spoiler-alert-action?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">GitHub Action for Early Detection of Security Vulnerabilities Using Claude AI</a></b></p><p class="paragraph" style="text-align:left;"><i>Eugene Lin</i> built a GitHub Action that uses Claude to detect security vulnerabilities in open source repositories by analyzing commit diffs and PR context, only alerting when concrete exploits can be demonstrated. The tool automatically creates vulnerability issues, prevents duplicate analysis, and supports configurable repository monitoring and alert destinations.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://labs.reversec.com/posts/2025/08/breaking-down-azure-devops-techniques-for-extracting-pipeline-credentials?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Breaking Down Azure DevOps: Techniques for Extracting Pipeline Credentials</a></b></p><p class="paragraph" style="text-align:left;">Reversec&#39;s <i>Thomas Byrne</i> walks through how attackers with write access to Azure DevOps pipelines can extract credentials across multiple vectors, from mapping KeyVault secrets to environment variables for exfiltration, to enumerating secret names via CLI, to pulling GitHub Service Connection tokens from <code>.git/config</code> files. Once extracted, these credentials authenticate to other repositories and downstream services, enabling lateral movement across the org and potentially into on-prem environments through more privileged Service Principals.</p><p class="paragraph" style="text-align:left;"></p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;"><b>Threat Hunting</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://securitylabs.datadoghq.com/articles/tech-impersonators-clickfix-and-macos-infostealers/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Tech impersonators: ClickFix and macOS infostealers</a></b></p><p class="paragraph" style="text-align:left;">Datadog researchers identified a campaign using fake GitHub repositories to deliver macOS infostealers through ClickFix social engineering. The attack redirects users through GitHub Pages staging sites that mimic GitHub interfaces before tricking victims into executing malicious commands in Terminal.</p><p class="paragraph" style="text-align:left;">The malware collects enterprise artifacts like business documents and RDP configurations, profiles how wallet extensions store secrets, and caps folder collection at 100MB to avoid detection. Later versions maintain persistence through a fake GoogleUpdate binary that checks in with C2 every 60 seconds, giving operators ongoing remote access rather than just a one time data grab.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://christian-schneider.net/blog/threat-modeling-agentic-ai/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-59&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Threat modeling agentic AI: a scenario-driven approach</a></b></p><p class="paragraph" style="text-align:left;"><i>Christian Schneider</i> breaks down why STRIDE doesn&#39;t cut it for agentic AI. It evaluates components individually while real attacks chain across them. His five zone model traces how malicious input moves through input surfaces, planning, tool execution, memory, and inter agent communication. He walks through three scenarios to prove the point: RAG poisoning that hijacks reasoning, MCP tool descriptions that exfiltrate credentials, and multi agent cascades where poisoned context passes through trusted peers into unauthorized actions. Each path gets formalized into attack trees mapped to OWASP, MAESTRO, and ATFAA. From there, map trust boundaries, run scenario workshops before picking controls, and ensure two independent controls per high risk node.</p></div><div class="section" style="background-color:#E6E6E6;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#4A4A4A;font-size:1.5rem;"><b>Wrapping Up</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><br>If you enjoyed this newsletter and think others would too, It would mean a lot for us if you&#39;d forward this email to other people who may enjoy it as well. You can also reply to this email, I&#39;d love to get in touch with you.</p><p class="paragraph" style="text-align:left;">Thanks,<br><a class="link" href="https://twitter.com/0xroot?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-59" target="_blank" rel="noopener noreferrer nofollow">Sebas</a></p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=bbf0161d-9155-435c-8311-da8e544ce443&utm_medium=post_rss&utm_source=security_pills">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>💊 Security Pills - #58</title>
  <description>Top 10 Web Hacking Techniques of 2025 | RCE in OpenClaw | OpenClaw AI Agent Skills Being Weaponized</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/a5277e0f-e99a-4688-a285-7cd7b30a580f/issue58.png" length="1219324" type="image/png"/>
  <link>https://newsletter.securitypills.news/p/security-pills-58</link>
  <guid isPermaLink="true">https://newsletter.securitypills.news/p/security-pills-58</guid>
  <pubDate>Mon, 09 Feb 2026 11:00:22 +0000</pubDate>
  <atom:published>2026-02-09T11:00:22Z</atom:published>
    <dc:creator>Sebas Guerrero</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #a89984; }
  .bh__table_cell { padding: 5px; background-color: #fbfbfb; }
  .bh__table_cell p { color: #4a4a4a; font-family: 'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#ececec; }
  .bh__table_header p { color: #333333; font-family:'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/71b81def-b1d8-4ec2-9859-b26a29ebcd62/Screenshot_2026-02-09_at_13.12.56.png?t=1770639417"/></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><b>Release Date: </b></span><span style="font-size:0.8rem;">9th February 2026</span><span style="font-size:0.8rem;"><b> | Issue: </b></span><span style="font-size:0.8rem;">58 </span><span style="font-size:0.8rem;"><b>| </b></span><span style="font-size:0.8rem;"><a class="link" href="https://securitypills.beehiiv.com/subscribe?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-58" target="_blank" rel="noopener noreferrer nofollow"><b>Subscribe</b></a></span></p><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><i>The Security Pills newsletter is a hand curated zine (delivered once per week) that highlights security related-news. 10+ hours of reading and analysis condensed into a 5-minute summary every Monday morning.</i></span></p></div><div class="section" style="background-color:#F2F2F2;border-color:#DADADA;border-style:dotted;border-width:2px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:center;"><span style="color:#4A4A4A;font-size:0.8rem;"><b>Sponsor</b></span><br><span style="color:#4A4A4A;font-size:0.8rem;">Would you like to become a sponsor for our newsletter? Our mission is to highlight security-related news with a focus on quality content, while we help people staying up to date with this corner of the industry.If you are interested, reach out to </span><span style="color:#4A4A4A;font-size:0.8rem;"><b>hello@securitypills.news</b></span><span style="color:#4A4A4A;font-size:0.8rem;"> with your ad idea to get started!</span></p></div><hr class="content_break"><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Application Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/RogoLabs/GhostCVEs?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">GhostCVEs: CVE Intelligence Platform for Identifying Reserved but Public Vulnerabilities</a></b></p><p class="paragraph" style="text-align:left;"><i>Jerry Gamblin</i> publishes GhostCVEs, a tool that finds vulnerability identifiers mentioned in public sources but missing from official CVE databases. The platform scans GitHub commits, security advisories, and RSS feeds to collect CVE references, then checks them against local copies of NVD and MITRE databases to spot gaps. It runs automated scans every six hours and creates reports in various formats. The system stores historical data in an SQLite database and plans to add features for detecting fake or AI-generated CVE mentions.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Security Vulnerability Discovered in Moltbook AI Social Network</a></b></p><p class="paragraph" style="text-align:left;">Wiz&#39;s <i>Gal Nagli </i>details an exposed Supabase API key in client-side JavaScript without Row Level Security protections. The misconfiguration granted unauthenticated access to the entire production database, exposing 1.5 million API authentication tokens, 35,000 email addresses, and private messages containing unencrypted third-party API keys. Write access to the database allowed unauthenticated modification of posts and injection of malicious content. The exposure revealed that the platform&#39;s 1.5 million agents were controlled by only 17,000 human users (88:1 ratio), contradicting its positioning as an autonomous AI-native social network.</p><p class="paragraph" style="text-align:left;">The incident demonstrates a growing problem: AI-powered development tools make building software much easier, but developers often skip essential security practices in the process.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://portswigger.net/research/top-10-web-hacking-techniques-of-2025?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Top 10 Web Hacking Techniques of 2025</a></b></p><p class="paragraph" style="text-align:left;">PortSwigger&#39;s 19th annual Top 10 Web Hacking Techniques, curated from 63 community nominations, was won by Vladislav Korchagin&#39;s <b>Successful Errors</b>, introducing error based techniques for exploiting blind server side template injection with polyglot detection methods.</p><p class="paragraph" style="text-align:left;">The list highlighted the rise of side channels as a core exploitation primitive, featuring two XS-Leak entries alongside ORM based data extraction, Unicode normalization attacks, Next.js internal cache poisoning, HTTP/2 CONNECT abuse, a technique for making blind SSRF visible, SOAP deserialization chains leading to RCE, and parser differentials.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Artificial Intelligence</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/simonw/claude-code-transcripts?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Claude Code Transcripts: Convert Session Files to HTML</a></b></p><p class="paragraph" style="text-align:left;">Built by <i>Simon Willison</i>, Claude Code Transcripts is a command-line tool that converts Claude AI coding session files into readable, paginated HTML documents. The tool can process sessions from three sources: local files stored on your computer, web sessions accessed through Claude&#39;s API, or individual JSON files. It creates organized output with index pages and multi-page transcripts that work well on mobile devices. Users can customize where files are saved, automatically upload results to GitHub Gist for sharing, and include original session data for archival purposes.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.praetorian.com/blog/introducing-julius-open-source-llm-service-fingerprinting?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Julius: Open-Source LLM Service Fingerprinting Tool</a></b></p><p class="paragraph" style="text-align:left;">Praetorian&#39;s <i>Evan Leleux </i>released Julius, an open source tool that identifies LLM server software running on network endpoints, addressing the growing shadow AI problem of thousands of unauthenticated inference servers exposed on the internet. Julius distinguishes between platforms like Ollama, vLLM, and Hugging Face deployments using YAML based probes.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/thedotmack/claude-mem?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Claude-Mem: Persistent Memory Compression System for Claude Code</a></b></p><p class="paragraph" style="text-align:left;">A persistent memory system for Claude Code that maintains project context across sessions through automatic observation capture and semantic summarization. It employs a token-efficient 3-layer search workflow combining full-text queries, chronological context retrieval, and selective detail fetching.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.jimmyvo.com/posts/agentic-task-management/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Task Management for Agentic Coding</a></b></p><p class="paragraph" style="text-align:left;"><i>Jimmy Vo</i> explores task management for agentic coding, comparing his custom <code>tk</code> CLI tool with Anthropic&#39;s native Claude Code tasks. His approach uses a bash script that stores tickets as markdown files in <code>.tickets/</code>, paired with a Claude skill and project manager agent that generates tickets from RFCs and tracks dependencies. Anthropic&#39;s solution evolved from simple todos to structured JSON-based dependency graphs. Both give AI agents structured task tracking and dependency awareness.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Blue Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://securitylabs.datadoghq.com/articles/web-traffic-hijacking-nginx-configuration-malicious/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">Web Traffic Hijacking: When Your Nginx Configuration Turns Malicious</a></b></p><p class="paragraph" style="text-align:left;">Datadog&#39;s <i>Ryan Simon </i>identified a campaign that hijacked web traffic through malicious NGINX configuration injection, likely gaining initial access via React2Shell exploitation (CVE-2025-55182). Attackers deployed shell scripts that discovered NGINX installations, including Baota panel environments, and injected malicious <code>location</code> blocks routing requests through attacker controlled proxies, validating syntax and using graceful reloads to avoid disruption.</p><p class="paragraph" style="text-align:left;">The campaign targeted Asian TLDs, government and educational domains, and generic TLDs, each mapped to different attacker backends and gambling related URL paths, while exfiltrating hijacked domain mappings to C2 infrastructure</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/backbay-labs/clawdstrike?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">Clawdstrike: Runtime Security Enforcement for Agent-Based Systems</a></b></p><p class="paragraph" style="text-align:left;">Clawdstrike provides runtime security enforcement for agent-based systems and EDR development on OpenClaw. Features seven security guards, multi-layer jailbreak detection, output sanitization, and cryptographically signed audit trails.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://cloud.google.com/blog/topics/threat-intelligence/disrupting-largest-residential-proxy-network?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">Disrupting IPIDEA: One of the World&#39;s Largest Residential Proxy Networks</a></b></p><p class="paragraph" style="text-align:left;">Google&#39;s <i>Threat Intelligence Group</i> disrupted IPIDEA, one of the world&#39;s largest residential proxy networks, which operated through four SDK brands sharing ~7,400 proxy servers. The network embedded these SDKs into 600+ Android apps and 3,075 Windows programs, silently turning devices into proxy exit nodes. IPIDEA also controlled 13 proxy/VPN brands and facilitated botnets including BadBox2.0, Aisuru, and Kimwolf. In a single week, 550+ tracked threat groups from China, DPRK, Iran, and Russia were observed using IPIDEA for SaaS compromise and password spraying.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://medium.com/@vanvleet/ttpis-extending-the-classic-model-058c572b76f3?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">Extending TTP to TTPI: Procedures vs. Instances in Detection Engineering</a></b></p><p class="paragraph" style="text-align:left;"><i>Van Vleet</i> proposes extending the TTP framework with a fourth layer, Instances, creating TTPI. The current model mixes abstract patterns (procedures) with real-world examples (instances). Procedures are stable recipes; instances are the ever-changing dishes made from them.</p><p class="paragraph" style="text-align:left;">This distinction helps teams prioritize detection: blocking procedures forces attackers into a limited playbook, while chasing individual instances leads to an endless cycle where attackers generate new variations faster than defenders can respond.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Cloud Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/trailofbits/dropkit?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Dropkit: Command-Line Tool for Managing DigitalOcean Droplets</a></b></p><p class="paragraph" style="text-align:left;">Dropkit is a command-line tool for managing DigitalOcean droplet lifecycles with automated SSH configuration and Tailscale VPN integration. It enables cost optimization through hibernation, snapshotting and destroying droplets to stop billing while preserving state for restoration.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.riptides.io/ritptides-openai-apikeys/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">The growing challenge of credential management for AI agents</a></b></p><p class="paragraph" style="text-align:left;"><i>Sebastian Toader</i> presents Riptides, a platform that replaces long-lived OpenAI API keys with short-lived credentials through an identity-first architecture. It verifies workload identity using SPIFFE standards, exchanges identity tokens for temporary keys via Vault or OpenBao, and enforces access at the kernel level through a custom Linux sysfs file. Credentials default to 15-minute TTLs and are automatically revoked, letting developers retrieve keys via simple file reads without embedding Vault SDKs.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://omeramiad.com/posts/gatewaytoheaven-gcp-cross-tenant-vulnerability/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">GatewayToHeaven: A Cross-Tenant Vulnerability in Google Cloud Apigee</a></b></p><p class="paragraph" style="text-align:left;"><i>Omer Amiad</i> discovered GatewayToHeaven (CVE-2025-13292), a cross tenant vulnerability in Google Cloud&#39;s Apigee allowing read and write access to analytics data across all tenants, potentially enabling end user impersonation across any organization using the service.</p><p class="paragraph" style="text-align:left;">The attack began by targeting the GKE metadata endpoint through an Apigee API proxy, bypassing SSRF protections via the AssignMessage policy to obtain the Message Processor&#39;s service account token. That token&#39;s bucket write permissions allowed replacing Dataflow pipeline JARs with malicious code, then triggering autoscaling via PubSub floods to execute them. The resulting Dataflow service account had cross tenant access to metadata buckets and GCS datastores containing request logs with plaintext access tokens for all Apigee customers.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Container Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/trailofbits/claude-code-devcontainer?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">Sandboxed Development Environment for Claude Code with Unrestricted Permissions</a></b></p><p class="paragraph" style="text-align:left;"><i>Trail of Bits</i> has released a containerized development environment that allows Claude AI to execute commands freely while keeping your main system safe. The tool uses Docker containers to create isolated workspaces where Claude can run unrestricted operations during security audits and code reviews. Users can choose between single-project containers or shared workspaces for multiple repositories. For sensitive work, network access can be restricted using firewall rules. The system works with both command-line tools and popular IDEs, with specific performance tweaks available for Mac users running Apple Silicon processors.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.palantir.com/securing-agents-in-production-agentic-runtime-1-5191a0715240?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">Securing Agents Across the Operational Lifecycle in Palantir AIP</a></b></p><p class="paragraph" style="text-align:left;"><i>Palantir </i>outlines five security dimensions for deploying AI agents in production. Scalable model access is provided through regional hubs with guarantees that no data is retained by third party providers. Agent orchestration runs on ephemeral Kubernetes infrastructure with 48 hour node limits and a three factor permission model combining owner, service user, and delegated user rights. Memory governance unifies four modalities (working, episodic, semantic, and procedural) through their Ontology system, applying consistent marking and role based policies at runtime. Tool usage is secured through provenance based controls that resolve entire call chains at runtime, blocking unauthorized data flows across nested tools. Integrated observability traces agent activity from data to decision, linking queries to version histories and LLM functions to evaluation suites.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="custom_html"><iframe src="https://embeds.beehiiv.com/871248b5-9b15-458d-a926-7e9d8a922e98" data-test-id="beehiiv-embed" width="100%" height="320" frameborder="0" style="margin: 0; background-color: transparent;"></iframe></div></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Red Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://castilho.sh/salesforce-oauth-ato?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">XSS Vulnerability in Salesforce Commerce Cloud Escalated to OAuth Token Theft via Cloudflare WAF</a></b></p><p class="paragraph" style="text-align:left;"><i>Rafael Castilho</i> found reflected XSS in Salesforce Commerce Cloud&#39;s EinsteinCarousel-Load controller, bypassed Cloudflare WAF using Unicode escapes, then weaponized the WAF to block OAuth callbacks and intercept one-time authentication codes for account takeover.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://depthfirst.com/post/1-click-rce-to-steal-your-moltbot-data-and-keys?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">Critical Remote Code Execution Vulnerability Found in OpenClaw AI Assistant</a></b></p><p class="paragraph" style="text-align:left;">Depthfirst&#39;s <i>Mav Levin</i> chained two vulnerabilities in OpenClaw into a 1-click RCE exploit. First, a logic flaw discovered by depthfirst&#39;s automated scanning: clicking a URL with a malicious <code>gatewayUrl</code> parameter forces OpenClaw to connect to an attacker controlled server and leak the user&#39;s auth token during the handshake. Second, a missing WebSocket origin validation that Levin discovered, enabling Cross-Site WebSocket Hijacking to reach the victim&#39;s <a class="link" href="https://localhost?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-58" target="_blank" rel="noopener noreferrer nofollow">localhost</a> OpenClaw instance from a malicious webpage. With the stolen admin scoped token, the attacker disables safety features (user approval prompts and container sandboxing) via the API and executes arbitrary commands on the host, all without user interaction beyond the initial click.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Supply Chain</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.dnsimple.com/2025/11/managing-repositories-terraform-github/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">How We Scaled Code Repository Management at DNSimple</a></b></p><p class="paragraph" style="text-align:left;"><i>DNSimple </i>transformed GitHub repository management from manual configuration to automated infrastructure as code using Terraform. An initial Ruby tool (Repocop) failed because it required local execution with no review process or change tracking. The breakthrough came in 2024 when GitHub Actions and Terraform Cloud enabled a PR based workflow where proposed changes generated preview plans automatically and approved merges triggered deployment, no local Terraform required. Starting with basic settings, they expanded to templates, code ownership files, and configurations across hundreds of repositories, later adopting the same pattern for DNS, cloud, and server infrastructure.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.sysdig.com/blog/how-threat-actors-are-using-self-hosted-github-actions-runners-as-backdoors?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Self-Hosted GitHub Actions Runners Weaponized as Persistent Backdoors</a></b></p><p class="paragraph" style="text-align:left;">Sysdig&#39;s <i>Alberto Pellitteri</i> analyzed how the Shai-Hulud worm weaponized self hosted GitHub Actions runners as persistent backdoors. After compromising machines through trojanized NPM packages, the worm created repositories with discussions enabled, installed runners with root privileges in hidden directories, and used an intentionally vulnerable workflow as a C2 channel, executing commands posted as discussion comments. Persistence was achieved by disabling process cleanup and optionally installing the runner as a system service. All traffic flowed to <code>github.com</code>, evading traditional network defenses.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://engineering.block.xyz/blog/kube-policies-binauthz-closing-the-supply-chain-gap-in-kubernetes?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Binary Authorization: Enforcing Supply Chain Security in Kubernetes Admissions</a></b></p><p class="paragraph" style="text-align:left;">Block built BinauthZ, a plugin for their existing admission controller that cryptographically verifies container images are signed and come from trusted build pipelines before running in Kubernetes. Verification rules are configuration-driven, and the plugin handles scale through concurrent verification and layered caching while distinguishing real policy violations from temporary infrastructure issues. Block built this in-house to avoid operational complexity, vendor lock-in, and per-node pricing.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.virustotal.com/2026/02/from-automation-to-infection-how.html?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">OpenClaw AI Agent Skills Being Weaponized as Malware Delivery Channel</a></b></p><p class="paragraph" style="text-align:left;">OpenClaw skills in the ClawHub marketplace are being exploited as malware delivery vectors, with VirusTotal identifying hundreds of malicious packages among 3,016+ analyzed. These attacks weaponize setup workflows that instruct users to execute untrusted code, since the skill files themselves are nearly empty, traditional antivirus fails to detect them.</p><p class="paragraph" style="text-align:left;">VirusTotal&#39;s Code Insight surfaces these patterns by analyzing <code>SKILL.md</code> behavior. Notable case: user &quot;hightower6eu&quot; published 314+ malicious skills delivering Windows packed trojans and macOS Atomic Stealer (AMOS), which harvests passwords, browser credentials, and crypto wallets.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.chainguard.dev/unchained/running-renovate-as-a-github-action?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Running Renovate as a GitHub Action Without Personal Access Tokens</a></b></p><p class="paragraph" style="text-align:left;">Chainguard&#39;s <i>Adrian Mouat</i> shows how to eliminate long lived GitHub Personal Access Tokens when running Renovate as a GitHub Action by using Octo STS, an open source security token service built by Chainguard that exchanges the action&#39;s OIDC token for a short lived GitHub token whose permissions are defined in a per repository YAML policy file. This also addresses the default GitHub Action token&#39;s inability to update workflow files.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;"><b>Threat Hunting</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.jamf.com/blog/threat-actors-expand-abuse-of-visual-studio-code/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Threat Actors Expand Abuse of Microsoft Visual Studio Code</a></b></p><p class="paragraph" style="text-align:left;">Jamf Threat Labs&#39; <i>Thijs Xhaflaire</i> uncovered a North Korean campaign abusing Visual Studio Code&#39;s task configuration to deliver malware, extending the &quot;Contagious Interview&quot; operation. Victims clone malicious GitHub or GitLab repositories and, upon trusting the workspace in VS Code, unknowingly execute commands embedded in <code>tasks.json</code> that fetch JavaScript payloads from Vercel infrastructure.</p><p class="paragraph" style="text-align:left;">The payload establishes a persistent backdoor that beacons to a command server every five seconds, enabling remote code execution while collecting system details such as hostname, MAC addresses, and public IP for victim fingerprinting. Jamf recommends developers scrutinize repository contents and task configurations before granting workspace trust.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.rapid7.com/blog/post/dr-threat-actors-aws-workmail-phishing-campaigns/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-58&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Threat Actors Using AWS WorkMail in Phishing Campaigns</a></b></p><p class="paragraph" style="text-align:left;">Rapid7 researchers <i>Jan Blažek </i>and <i>Calvin House</i> found threat actors leveraging AWS WorkMail to sidestep SES sandbox restrictions and build phishing infrastructure. Using compromised AWS credentials, attackers escalated to AdministratorAccess, created WorkMail organizations via <code>workmail:CreateOrganization</code>, and verified domains through <code>ses:VerifyDomainIdentity</code> and <code>ses:VerifyDomainDkim</code>. By pivoting to WorkMail rather than requesting SES sandbox removal, they gained immediate external sending to up to 100,000 recipients per day per organization, far exceeding the sandbox limit of 200 messages daily to verified recipients.</p><p class="paragraph" style="text-align:left;">This technique makes web-sent emails appear in CloudTrail as <code>ses:SendRawEmail</code> events but mask the sender&#39;s real IP behind <code>workmail..amazonaws.com</code>, while SMTP-sent emails produce no CloudTrail logs at all, even with SES data events enabled.</p></div><div class="section" style="background-color:#E6E6E6;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#4A4A4A;font-size:1.5rem;"><b>Wrapping Up</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><br>If you enjoyed this newsletter and think others would too, It would mean a lot for us if you&#39;d forward this email to other people who may enjoy it as well. You can also reply to this email, I&#39;d love to get in touch with you.</p><p class="paragraph" style="text-align:left;">Thanks,<br><a class="link" href="https://twitter.com/0xroot?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-58" target="_blank" rel="noopener noreferrer nofollow">Sebas</a><br></p><p class="paragraph" style="text-align:left;"></p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=f2ea5f69-f70f-4563-996f-531c899001fa&utm_medium=post_rss&utm_source=security_pills">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

      <item>
  <title>💊 Security Pills - #57</title>
  <description>Scanning 5.6 million public Gitlab repositories for secrets | Debugging your GitHub Actions | Mastering Privilege Management for Developers</description>
      <enclosure url="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/66f6d28a-531d-45aa-886f-81afc8c5ab96/issue57.png" length="1165755" type="image/png"/>
  <link>https://newsletter.securitypills.news/p/security-pills-issue-57</link>
  <guid isPermaLink="true">https://newsletter.securitypills.news/p/security-pills-issue-57</guid>
  <pubDate>Mon, 02 Feb 2026 11:00:22 +0000</pubDate>
  <atom:published>2026-02-02T11:00:22Z</atom:published>
    <dc:creator>Sebas Guerrero</dc:creator>
    <category><![CDATA[Newsletter]]></category>
  <content:encoded><![CDATA[
    <div class='beehiiv'><style>
  .bh__table, .bh__table_header, .bh__table_cell { border: 1px solid #a89984; }
  .bh__table_cell { padding: 5px; background-color: #fbfbfb; }
  .bh__table_cell p { color: #4a4a4a; font-family: 'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
  .bh__table_header { padding: 5px; background-color:#ececec; }
  .bh__table_header p { color: #333333; font-family:'Roboto',-apple-system,BlinkMacSystemFont,Tahoma,sans-serif !important; overflow-wrap: break-word; }
</style><div class='beehiiv__body'><div class="image"><img alt="" class="image__image" style="" src="https://media.beehiiv.com/cdn-cgi/image/fit=scale-down,format=auto,onerror=redirect,quality=80/uploads/asset/file/71b81def-b1d8-4ec2-9859-b26a29ebcd62/Screenshot_2026-02-09_at_13.12.56.png?t=1770639194"/></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><b>Release Date: </b></span><span style="font-size:0.8rem;">2nd February 2026</span><span style="font-size:0.8rem;"><b> | Issue: </b></span><span style="font-size:0.8rem;">57 </span><span style="font-size:0.8rem;"><b>| </b></span><span style="font-size:0.8rem;"><a class="link" href="https://securitypills.beehiiv.com/subscribe?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow"><b>Subscribe</b></a></span></p><p class="paragraph" style="text-align:center;"><span style="font-size:0.8rem;"><i>The Security Pills newsletter is a hand curated zine (delivered once per week) that highlights security related-news. 10+ hours of reading and analysis condensed into a 5-minute summary every Monday morning.</i></span></p></div><div class="section" style="background-color:#F2F2F2;border-color:#DADADA;border-style:dotted;border-width:2px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:center;"><span style="color:#4A4A4A;font-size:0.8rem;"><b>Sponsor</b></span><br><span style="color:#4A4A4A;font-size:0.8rem;">Would you like to become a sponsor for our newsletter? Our mission is to highlight security-related news with a focus on quality content, while we help people staying up to date with this corner of the industry.If you are interested, reach out to </span><span style="color:#4A4A4A;font-size:0.8rem;"><b>hello@securitypills.news</b></span><span style="color:#4A4A4A;font-size:0.8rem;"> with your ad idea to get started!</span></p></div><hr class="content_break"><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Application Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://labs.watchtowr.com/soapwn-pwning-net-framework-applications-through-http-client-proxies-and-wsdl/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=appsec&utm_term=article-8" target="_blank" rel="noopener noreferrer nofollow">SOAPwn: Remote Code Execution Through .NET Framework HTTP Client Proxies</a></b></p><p class="paragraph" style="text-align:left;">Watchtowr&#39;s <i><a class="link" href="https://x.com/chudyPB?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Piotr Bazydlo</a></i> shows that <code>ServiceDescriptionImporter</code>, .NET&#39;s tool for generating SOAP client proxies from WSDL files, doesn&#39;t validate URL schemes. Attackers who supply a malicious WSDL can point the generated proxy at <code>file://</code> paths, writing XML directly to disk to embed webshells. Barracuda, Ivanti, Microsoft, and Umbraco products were confirmed vulnerable. Microsoft has declined to patch the issue, stating that URLs passed to <code>SoapHttpClientProtocol</code> should never be user-controlled and input validation is the developer&#39;s responsibility.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://trufflesecurity.com/blog/scanning-5-6-million-public-gitlab-repositories-for-secrets?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Scanning 5.6 million public GitLab repositories for secrets</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/luke-marshall-914a1a219?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Luke Marshall</a></i> describes how he scanned ~5.6 million public GitLab Cloud repositories with TruffleHog, using an AWS Lambda + SQS pipeline to validate findings and identify more than 17,000 live secrets. He also explains how Claude Sonnet 3.7 supported triage and reporting, which ultimately led to over $9,000 in bug bounty payouts.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://huggingface.co/blog/sionic-ai/claude-code-skills-training?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=appsec" target="_blank" rel="noopener noreferrer nofollow">Skill Registry Validation and Marketplace Automation with GitHub Actions</a></b></p><p class="paragraph" style="text-align:left;">Sionic AI has developed a system that prevents research teams from repeating failed experiments by creating a shared knowledge registry managed through GitHub Actions and Claude Code. The solution addresses a common problem: valuable experimental insights getting lost in Slack threads and notebooks, leading to duplicate work months later. </p><p class="paragraph" style="text-align:left;">Researchers use simple commands like <code>/retrospective</code> to have Claude automatically extract and document their discoveries, while <code>/advise</code> lets team members quickly access past learnings before starting new experiments. GitHub Actions handle the technical infrastructure by validating new contributions and automatically updating the shared registry, ensuring the system stays current and properly structured without manual maintenance.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Artificial Intelligence</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.promptfoo.dev/blog/building-a-security-scanner-for-llm-apps/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Code Scanning for LLM Security Vulnerabilities</a></b></p><p class="paragraph" style="text-align:left;"><a class="link" href="https://www.linkedin.com/in/daneschneider/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow"><i>Dane Schneider</i></a> walks through Promptfoo Scanner, a GitHub Action that catches LLM-specific vulnerabilities in pull requests. It traces untrusted inputs into prompts, then follows LLM outputs to dangerous sinks (code execution, database queries, that sort of thing). The focus is on &quot;capability combinations&quot;: the lethal trifecta (private data access + untrusted content + external communication) or the deadly duo (untrusted content + privileged actions). Tested against real CVEs, the scanner identifies not just vulnerable code paths but often the exact commit that introduced the problem.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/FuzzingLabs/mcp-security-hub?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Production-Ready Dockerized MCP Servers for Offensive Security Tools</a></b><br><br>A collection of 28 Dockerized MCP servers from <i><a class="link" href="https://x.com/FuzzingLabs?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">FuzzingLabs</a></i> bringing offensive security tools to AI assistants. Includes Nmap, Ghidra, Nuclei, SQLMap and 163+ total security tools across reconnaissance, web security, binary analysis, cloud security, OSINT, Active Directory, and more. Containers are production-hardened with non-root execution, minimal images, and Trivy vulnerability scanning.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/0xroot-bf/wooyun-legacy?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">88,636 Real Vulnerabilities: Lessons from a Security Knowledge Base</a></b></p><p class="paragraph" style="text-align:left;">A security knowledge base from 88,636 WooYun vulnerability cases (2010-2016) that enables Claude to analyze security issues with expert-level reasoning across 15 vulnerability types.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/affaan-m/everything-claude-code?tab=readme-ov-file&utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=ai-security" target="_blank" rel="noopener noreferrer nofollow">Claude Code Configuration Repository from Anthropic Hackathon</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/affaanmustafa/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Affaan Mustafa</a></i> has released a comprehensive Claude Code configuration toolkit built over 10+ months of real-world product development. The collection includes specialized agents for code review and planning, automated workflows, custom commands, and cross-platform scripts. Two guides accompany the release: <a class="link" href="https://x.com/affaanmustafa/status/2012378465664745795?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">a foundational guide</a> covering setup and core concepts, and an <a class="link" href="https://x.com/affaanmustafa/status/2014040193557471352?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">advanced guide</a> detailing performance optimization, memory management, testing approaches, and scaling techniques.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Blue Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.amazon.science/blog/how-amazon-uses-ai-agents-to-anticipate-and-counter-cyber-threats?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">How Amazon uses AI agents to anticipate and counter cyber threats</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/dweiss93/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Daniel Weiss</a></i> describes Amazon&#39;s Autonomous Threat Analysis (ATA) system, which uses competing AI agents to reason about and adapt security testing strategies in isolated environments. The system executes 10–30 technique variations concurrently, reducing detection-rule testing from weeks to hours while grounding all results against actual infrastructure to mitigate hallucination.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.huntress.com/blog/ldap-active-directory-detection-part-one?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">Bridging the Detection Engineering Gap: Building Rules from Attacker Source Code</a></b></p><p class="paragraph" style="text-align:left;">Huntress’ <i><a class="link" href="https://www.linkedin.com/in/schwartzah/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Andrew Schwartz</a></i> explains why LDAP detections that rely on “expected” source-code or protocol syntax often miss in Active Directory: there’s a translation gap between what’s sent over the wire and what actually shows up in telemetry. AD rewrites OID-based filters before they’re logged in Event ID 1644, and 1644 preserves formatting exactly as processed, so the same query can show up in different shapes depending on the tool.</p><p class="paragraph" style="text-align:left;">He also shares a practical approach to detection engineering: use source code to understand how tooling behaves, then validate and refine your hypotheses against real logs. The goal is to turn implementation details into repeatable signals, not exact-match rules that break when formatting changes.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.prophetsecurity.ai/blog/rethinking-soc-capacity-how-ai-changes-the-human-cost-curve?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=blue-team" target="_blank" rel="noopener noreferrer nofollow">SOC Capacity and the Analyst Time Constraint</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/jhencinski/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Jon Hencinski</a></i> argues SOC scaling breaks because analyst time is the bottleneck: as alerts and tools grow, you hit a “Human Cost Curve” where adding headcount increases cost and coordination more than results. He recommends a hybrid model where AI handles front-line triage and enrichment, escalating only the small set of alerts worth investigation, so a 10-person SOC can process ~200 alerts/day, keep utilization under ~70%, and retain capacity for deeper investigations and continuous improvements.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Cloud Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.softwaresecured.com/post/aws-privilege-escalation-iam-risks-service-based-attacks-and-new-ai-driven-bedrock-agentcore-vectors?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">AWS Privilege Escalation Techniques: Evolution from IAM to AI-Driven Services</a></b></p><p class="paragraph" style="text-align:left;">Software Secured&#39;s <i><a class="link" href="https://www.linkedin.com/in/bengoodspeed/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Ben GoodSpeed</a></i> describes how AWS privilege escalation has evolved from traditional IAM policy manipulation through service-based attacks to modern AI-driven orchestration via Bedrock and AgentCore. Testing across 16 scenarios, Ben identifies which AWS actions can be blocked with SCPs, which cannot, and provides a framework for assessing escalation risk across cloud and AI workloads.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/Adversis/tailsnitch?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Tailsnitch: Security Auditor for Tailscale Configurations</a></b></p><p class="paragraph" style="text-align:left;">A security auditing tool by <i><a class="link" href="https://www.linkedin.com/in/noahpotti/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Noah Potti</a></i> for Tailscale configurations that runs 52 checks across seven categories to detect misconfigurations, weak access controls, and policy gaps. It supports OAuth or API key authentication, produces actionable findings, and can apply safe remediations with dry-run previews.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://securitylabs.datadoghq.com/articles/introducing-pathfinding.cloud/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=cloud-security" target="_blank" rel="noopener noreferrer nofollow">Pathfinding.cloud: IAM Privilege Escalation Knowledge Base</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/sethart/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Seth Art</a></i> released <a class="link" href="https://pathfinding.cloud?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">pathfinding.cloud</a>, a comprehensive knowledge base documenting 60+ AWS IAM privilege escalation paths (27 uncovered by existing OSS tools). These techniques show how attackers gain administrative access after initial AWS account compromise. The library uses service-specific identifiers and YAML format, with each entry detailing required permissions, resource constraints, and exploitation prerequisites.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Container Security</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://pitfallen.net/blog/hands-on-with-aws-bottlerocket/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">Hands On with AWS Bottlerocket: Evaluating the Security of Amazon&#39;s Hardened OS</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/terryf82/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Terry Franklin</a></i> explains in this article how AWS Bottlerocket, a well-known minimalist operating system that provides a reliable container hosting environment, is capable of defeating established container escape techniques, including: abusing the kernel usermode helper by triggering a coredump, mounting the host filesystem and loading a custom kernel module.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://cybersecnerds.com/badpods-series-everything-allowed-on-aws-eks/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">Kubernetes Security: Exploring Pod Escape and Lateral Movement with Misconfigured Manifests</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/kirandawadi/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Kiran Dawadi</a></i> walks through a controlled “assume-breach” test on an Amazon EKS cluster using BishopFox’s <a class="link" href="https://github.com/BishopFox/badPods?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">BadPods</a> to show how risky pod configurations (such as privileged containers, host namespace sharing, and host networking) can effectively remove container isolation. The write-up follows a realistic escalation from an initial compromised pod to host-level access, pivoting to other workloads on the node, and ultimately pulling AWS credentials from IMDS.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.docker.com/blog/making-small-llms-smarter/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=container-security" target="_blank" rel="noopener noreferrer nofollow">Using Small Language Models Locally for Code Writing Assistance</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://www.linkedin.com/in/phcharriere/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Philippe Charrière</a></i> describes how to run small language models (0.5-7 billion parameters) locally for code assistance, particularly when cloud services are unavailable due to confidentiality restrictions or offline environments. The author demonstrates using a 3 billion parameter Qwen2.5-Coder model with Docker Model Runner to build a code assistance system for a custom Golang library.</p><p class="paragraph" style="text-align:left;">Since small models don&#39;t know proprietary codebases and have limited context windows, the solution implements Retrieval Augmented Generation (RAG) to feed relevant code snippets to the model. The article emphasizes that RAG effectiveness depends on proper configuration of embedding models, chunk splitting strategies, and similarity thresholds, with practical solutions including adjusting thresholds, increasing returned results, and adding metadata keywords when retrieval fails.</p></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><div class="custom_html"><iframe src="https://embeds.beehiiv.com/871248b5-9b15-458d-a926-7e9d8a922e98" data-test-id="beehiiv-embed" width="100%" height="320" frameborder="0" style="margin: 0; background-color: transparent;"></iframe></div></div><div class="section" style="background-color:transparent;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><hr class="content_break"></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Red Team</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://blog.zsec.uk/capd/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">Detecting Conditional Access Payload Delivery via Cloudflare Pages</a></b><br><br><i><a class="link" href="https://x.com/ZephrFish?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Andy Gill</a></i> describes how conditional access payload delivery (CAPD) can be implemented using Cloudflare Pages and Workers to selectively deliver payloads based on request context, noting that Cloudflare’s shared infrastructure and HTTPS encryption limit detection to sparse network signals, endpoint telemetry, and TLS-terminating proxies.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://github.com/almounah/silph?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">SILPH: An In-Memory Credential Dumping Tool for Windows</a></b><br><br>An open-source red team tool by <i><a class="link" href="https://www.linkedin.com/in/haroun-al-mounayar-571830211/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Haroun Al Mounayar</a></i> that extracts Windows credentials (LSA secrets, SAM hashes, and DCC2) entirely in memory without disk writes or RPC services. It has been built to be integrated into the <a class="link" href="https://github.com/almounah/orsted?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Orsted C2 framework</a></p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://sean.heelan.io/2026/01/18/on-the-coming-industrialisation-of-exploit-generation-with-llms/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=red-team" target="_blank" rel="noopener noreferrer nofollow">AI Agents Successfully Generate Exploits for Zero-Day Vulnerability; Implications for Offensive Cyber Security Industrialization</a></b></p><p class="paragraph" style="text-align:left;"><i><a class="link" href="https://x.com/seanhn?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Sean Heelan</a></i> demonstrates how current LLMs can automatically generate functional exploits for zero-day vulnerabilities when equipped with appropriate tools and iterative debugging capabilities. In experiments using Opus 4.5 and GPT-5.2, both AI agents successfully generated over 40 distinct exploits for a QuickJS zero-day across six scenarios with various modern mitigations.</p><p class="paragraph" style="text-align:left;">Heelan argues that current AI safety tests don&#39;t accurately measure real-world hacking capabilities. Most evaluations use practice scenarios, simulated environments, or old vulnerabilities instead of testing against genuinely difficult targets with fresh zero-day flaws. He calls for AI labs and security researchers to run more realistic tests using actual zero-day vulnerabilities and to share detailed results, including costs and success rates.</p><p class="paragraph" style="text-align:left;">You can find a technical write-up of the experiments and the results on <a class="link" href="https://github.com/SeanHeelan/anamnesis-release/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Github</a></p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:10.0px 10.0px 10.0px 10.0px;"><h6 class="heading" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;">Supply Chain</span></h6></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.sonarsource.com/blog/zombie-workflows-a-github-actions-horror-story/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Zombie Workflows: GitHub Actions Vulnerabilities That Persist Across </a></b><a class="link" href="https://www.sonarsource.com/blog/zombie-workflows-a-github-actions-horror-story/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">Branches</a><br><br>Sonar&#39;s <i><a class="link" href="https://www.linkedin.com/in/paul-gerste/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Paul Gerste</a></i> describes a GitHub Actions vulnerability pattern (<b>Zombie Workflows</b>) in which older repository branches can leave exploitable workflows in place, enabling <b>Pwn Request</b> attacks. Their analysis identified 188 potentially vulnerable workflows across projects, including repositories associated with Microsoft, NVIDIA, and Azure.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://www.aikido.dev/blog/promptpwnd-github-actions-ai-agents?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=supply-chain" target="_blank" rel="noopener noreferrer nofollow">PromptPwnd: AI Prompt Injection Vulnerabilities in GitHub Actions and GitLab CI/CD Pipelines</a></b><br><br>Aikido&#39;s <i><a class="link" href="https://www.linkedin.com/in/rein-daelman/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Rein Daelman</a></i> describes PromptPwnd, a vulnerability pattern in CI/CD pipelines where untrusted user input embedded in AI prompts causes AI agents to execute privileged operations and leak secrets. Aikido Security identified the issue across multiple AI-powered actions including Claude Code, Codex, and GitHub AI Inference, affecting at least five Fortune 500 companies and numerous high-profile repositories.</p></div><div class="section" style="background-color:#333333;border-color:#161616;border-style:solid;border-width:1px;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#ffffff;font-size:1.5rem;"><b>Threat Hunting</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://socket.dev/blog/malicious-chrome-extensions-phantom-shuttle?utm_medium=email&utm_source=securitypills&utm_campaign=issue-57&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">Destructive Malware Rising Across Open Source Registries with Kill Switches and Delays</a></b><br><br>Socket&#39;s <i><a class="link" href="https://www.linkedin.com/in/kush-pandya-8664a6197/?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Kush Pandya</a></i> analyzes two malicious Chrome extensions called Phantom Shuttle, distributed since 2017, that route traffic from 170+ targeted domains through attacker-controlled MITM proxies. The extensions intercept HTTP authentication challenges using hardcoded credentials and continuously exfiltrate plaintext credentials from sites including AWS, Azure, GitHub, and adult platforms.</p><hr class="content_break"><p class="paragraph" style="text-align:left;"><b><a class="link" href="https://ipurple.team/2026/01/12/edr-silencing/?utm_source=securitypills&utm_medium=email&utm_campaign=issue-57&utm_content=threat-hunting" target="_blank" rel="noopener noreferrer nofollow">EDR Silencing via Windows Filtering Platform, Hosts File, Name Resolution Policy, and IPSec Rules</a></b></p><p class="paragraph" style="text-align:left;">Pentest Laboratories explores advanced EDR Silencing techniques that attackers use to disable security monitoring without triggering alerts. When threat actors discover EDR software running, they prioritize evading detection while maintaining stealth.</p><p class="paragraph" style="text-align:left;">The research covers four approaches that block EDR communication with cloud management consoles: Windows Filtering Platform abuse, hosts file modification, Name Resolution Policy Table manipulation, and IPSec Filter Rules. These techniques disrupt network communication rather than crashing the EDR process, which would generate obvious alerts. Attackers can avoid triggering detection rules using indirect system calls or legitimate tools, gain administrator privileges to install kernel-level bypass modules preventing malicious activity logging, or completely remove the EDR software.</p></div><div class="section" style="background-color:#E6E6E6;margin:0.0px 0.0px 0.0px 0.0px;padding:0.0px 0.0px 0.0px 0.0px;"><p class="paragraph" style="text-align:left;"><span style="color:#4A4A4A;font-size:1.5rem;"><b>Wrapping Up</b></span></p></div><div class="section" style="background-color:transparent;border-color:#C0C0C0;border-style:dashed;border-width:1px;margin:1.0px 1.0px 1.0px 1.0px;padding:10.0px 10.0px 10.0px 10.0px;"><p class="paragraph" style="text-align:left;"><br>If you enjoyed this newsletter and think others would too, It would mean a lot for us if you&#39;d forward this email to other people who may enjoy it as well. You can also reply to this email, I&#39;d love to get in touch with you.</p><p class="paragraph" style="text-align:left;">Thanks,<br><a class="link" href="https://twitter.com/0xroot?utm_source=newsletter.securitypills.news&utm_medium=newsletter&utm_campaign=security-pills-57" target="_blank" rel="noopener noreferrer nofollow">Sebas</a></p></div></div><div class='beehiiv__footer'><br class='beehiiv__footer__break'><hr class='beehiiv__footer__line'><a target="_blank" class="beehiiv__footer_link" style="text-align: center;" href="https://www.beehiiv.com/?utm_campaign=de26df09-6341-4b47-bf29-dbe9dbc5d96e&utm_medium=post_rss&utm_source=security_pills">Powered by beehiiv</a></div></div>
  ]]></content:encoded>
</item>

  </channel>
</rss>
