This day 02:03 06:03 10:03 14:03 18:03 22:03
Info  2026-08-23 18:03Z · last 4h · 15 findings · glm-5.2:cloud

Threat Brief — 2026-08-23 — Defender turned against itself

Executive summary: The most actionable item today is a developing detail on the Microsoft Defender driver abuse story — the same signed-driver protocol now appears to span every Windows build from 7 through 11 25H2, broadening the attack surface considerably. On the mobile front, ToxicPanda has added VPN-permission abuse to block Google Play Protect, a meaningful evolution in its anti-detection capability. Two genuinely new items round out the brief: a novel social-engineering technique for bypassing LLM safety filters, and research highlighting attack potential in emerging Time-Sensitive Networking (TSN) industrial protocols.

Top items

Themes

Trust inversion attacks dominate. Three of today's items share a common pattern: the defender's own trusted mechanism is turned against it. Defender's signed driver deletes the AV it protects; ToxicPanda uses Android's VPN permission (a security feature) to disable Play Protect; and the LLM bypass exploits the model's own fairness guardrails to produce prohibited content. Defenders should audit not just for external attacks but for ways their own trust infrastructure can be subverted.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db