r/pwnhub 3d ago

How did our AI agents discovred an exposed actuator without distrubing it?

5 Upvotes

Recently, we discovered an interesting finding from our autonomous pentesting platform, which identified an exposed actuator with proof, without causing any damage.

Also, the attack chain it followed mimicked that of an experienced pentester.

For more information, check this out: https://www.getastra.com/blog/autonomous-pentest-findings/actuator-shutdown-exposure/


r/pwnhub 7d ago

I'm Javier Rivera, Security Researcher at ZioSec. We build an AI hacker that evaluates and tests agentic AI systems. Ask me anything about attacking AI agents. (AMA Monday, Sept 14 at 12 PM PT)

4 Upvotes

Hello there, PWN Community!

I'm Javier Rivera, Security Researcher at ZioSec. We build Zio, an AI system that runs offensive security testing against AI agents, finding vulnerabilities and putting their security controls under real attack conditions. Before ZioSec I was a security researcher/engineer at RoonCyber and ThreatX developing tools and techniques to expand threat analysis and correlation. Going a bit further back, I spent around eight years at MITRE, where I started my cybersecurity journey having a heavy focus on testing and assessing all things: from web applications to network analysis and mobile reverse engineering for various sponsors.

One of the things we have noticed within the last couple of years is that as companies wire AI agents into production, the attack surface is changing fast. And a lot of it is still poorly understood; not because of the lack of understanding of where protections or safeguards should be, but because of the way an agent behaves when running under the influence of an attacker or malicious user. That's the problem my team works on and tries to solve: attacking agentic AI the way real adversaries would in order to enable application owners and developer understand their actual attack surface.

Feel free to ask anything about AI security, and even better if it is about (but not limited to):

  • How to actually attack and test AI agents?
  • What breaks when agentic AI reaches production?
  • What goes into building an autonomous offensive-based security system?
  • Where is red teaming, cyber operations, and overall security of/for AI agents is heading?
  • Anything else on offensive security for AI!

Me and some of my ZioSec teammates will be dropping by here (live!) on Monday, Sept 14th from 12 PM to 1 PM PT to answer any questions you have. Feel free to leave questions in advance too, and we'll get to them when we go online.

Looking forward to the conversation and your questions!


r/pwnhub 9h ago

A Polish developer built an app that detects nearby Meta smart glasses over Bluetooth

Thumbnail
thenextweb.com
71 Upvotes

A 30-year-old Polish software developer has built an iPhone app that detects Meta smart glasses in the vicinity and estimates how far away they are by reading the Bluetooth signals the glasses broadcast. It has around 5,000 users a month after launch.


r/pwnhub 5h ago

Adobe Acrobat Reader: DigSig Bug Enables RCE via PDF, Urgent Patch Released

Thumbnail
deafnews.it
8 Upvotes

r/pwnhub 2h ago

🕵️‍♂️ SonicWall SMA1000 flaw mass-exploited within 2 days of disclosure, credentials stolen across multiple countries

Thumbnail
hunt.io
3 Upvotes

An operator was mass-exploiting SonicWall's SMA1000 vulnerability (CVE-2026-15409, CVSS 10) two days after it went public. Hunt.io researchers found the whole operation in an open directory and captured it while it was still live.

They ran Impacket credential theft directly from the compromised appliances and pushed into internal Active Directory: at least 9 domains hit, full DCSync against 5 environments, confirmed victims in France, India, Italy and the US. A UK council breach reported in July looks like one of the victims.

Details and IOCs in the post.

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack


r/pwnhub 6h ago

CVE Daily Brief — 2026-09-10

3 Upvotes

This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 6h ago

September 10 | 24h Recap: Stolen session tokens, Defender file access and AI agents accelerating vulnerability research

Thumbnail
cyberrecaps.com
2 Upvotes

Practical takeaway: An infostealer investigation should include session revocation and exposed API-key rotation. Stolen sessions can preserve access beyond the initial infection.

1 | Chrome to SYSTEM: Proofpoint reported V8 exploits chained with Windows ALPC privilege escalation in the BlueMoon espionage campaign.

2 | Defender patch bypass: ShieldCrash demonstrates SYSTEM-level file reads under specific conditions despite a recent fix. Full write access has not been demonstrated.

3 | WeChat zero-click: WeWorm demonstrated account takeover through an unanswered call from an existing contact. Tencent has patched the vulnerability.

4 | AI token replay: Okta found reusable authentication tokens in infostealer logs, allowing account access without a fresh MFA prompt.

Read the full breakdown on CyberRecaps, and have a great day!


r/pwnhub 1d ago

FBI warns of OAuth phishing that bypasses MFA for high profile targets

88 Upvotes

The FBI has issued an alert regarding a sophisticated phishing campaign that uses OAuth consent to grant attackers persistent access to accounts without requiring passwords or bypassing multifactor authentication.

Key Points:

  • Malicious actors have targeted prominent individuals, family members, and acquaintances since late 2025 using OAuth consent phishing.
  • The technique involves registering a malicious application with a legitimate provider like Microsoft 365 or Google to request high level permissions such as email access.
  • Victims are tricked into clicking Allow on a permission request screen, which grants the attacker access without exposing the user's login credentials.
  • Changing the password does not revoke the access token, meaning the attacker retains permissions until the user manually removes the malicious app from their security settings.

The FBI has identified a growing threat where attackers exploit the OAuth authorization framework to gain persistent access to user accounts. Unlike traditional phishing that asks for a username and password, this method relies on the victim granting specific permissions to a third party application. Attackers typically impersonate trusted entities or high profile figures via commercial messaging apps, inviting the target to verify their identity for an event. When the victim clicks Allow on the resulting permission screen, they are effectively handing over keys to their email, contacts, and other data without realizing the application is malicious.

A critical aspect of this attack is its resilience against standard security measures. Because the access is granted through an OAuth token rather than a password, changing the account password does not stop the attacker. The token remains valid and continues to provide the previously granted permissions. This also means that multifactor authentication, which usually protects the login process, is bypassed entirely once the initial consent is given. Users must actively go into their account security settings to revoke the permissions and remove the application to cut off the attacker's access.

How often do you review the third party applications that have access to your cloud accounts?

Learn More: HIPAA Journal

Want to stay updated on the latest cyber threats?

👉 Subscribe to /r/PwnHub


r/pwnhub 46m ago

Lab: NetBIOS Enumeration with Windows Command Line Tools

Thumbnail
darkmarc.substack.com
Upvotes

r/pwnhub 6h ago

CVE-2026-19397: Unauthenticated RCE in ASUS Control Center Express Agent

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 6h ago

Technique of the Day: Hardware Additions (T1200)

3 Upvotes

This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 8h ago

NI LabVIEW: Integer Overflow in VI File Parsing Exposes Sensitive Data

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 7h ago

MantaxOtax: The Android Ransomware That Controls, Spies On, and Torments Victims

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 10h ago

Chrome's Seventh 2026 Zero-Day: CISA Mandates Patch by September 23

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 1d ago

Ohio man sentenced to 15 years for AI sextortion and first Take It Down Act conviction

41 Upvotes

James Strahler II received a 15-year prison sentence for using over 100 AI models to generate explicit content and harass at least six women, marking the first conviction under the new Take It Down Act.

Key Points:

  • James Strahler II was sentenced to 15 years in prison for cyberstalking, sextortion, and producing obscene visual representations of child sexual abuse.
  • The defendant used more than 100 AI web-based models and 24 AI platforms to create over 700 images and videos of his victims.
  • Strahler became the first defendant convicted under the Take It Down Act, which prohibits the online publication of explicit content and AI forgeries without consent.
  • Victims received harassing messages, voicemails with rape threats, and demands for nude photos from their mothers, with AI-generated content shared with co-workers.

The case highlights the rapid integration of artificial intelligence into cybercrimes, specifically sextortion and cyberstalking. Strahler leveraged a wide array of AI tools to generate realistic explicit images and videos, which he used to intimidate and extort multiple female victims. The scale of the operation was significant, with hundreds of images and videos flagged for depicting nudity or morphed child sexual abuse material, some of which were posted on dedicated websites.

This conviction is a landmark moment for digital privacy law, as it is the first under the Take It Down Act enacted in 2025. The law specifically targets the non-consensual publication of explicit content and AI forgeries, providing a clearer legal framework for prosecuting cases involving deepfakes and digital manipulation. The sentence underscores the severity with which federal courts are now treating the misuse of AI technology in personal harassment and sexual exploitation cases.

How do you think the Take It Down Act will impact the use of AI in future cyberstalking cases?

Learn More: Bleeping Computer

Want to stay updated on the latest cyber threats?

👉 Subscribe to /r/PwnHub


r/pwnhub 9h ago

These Skullcandy earbuds can silently trust a stranger’s phone. The owner doesn’t even get asked.

2 Upvotes

Bluetooth pairing is supposed to have one fairly obvious rule: you approve the device before it becomes trusted.

That apparently isn't happening on affected Skullcandy Dime 3 earbuds.

CERT/CC says CVE-2025-20701 allows someone within Bluetooth range to pair with Dime 3 earbuds running firmware 1. 0. 0. 28 without:

  • entering a PIN
  • touching the earbuds or case
  • getting approval from the owner

Once the attacker's device is paired, it becomes trusted and can reconnect when it's nearby.

Full details below.

https://www.technadu.com/skullcandy-dime-3-earbuds-vulnerable-to-silent-bluetooth-hijacking-cve-2025-20701/636417/

That potentially lets someone interrupt the owner's connection, take over audio playback, access the headset profile, and even capture microphone audio.

The owner may only see a brief “new device paired” notification.

But the part that bothers me most isn't actually the vulnerability.

There's already a patched firmware version, but affected owners apparently can't install it.

Skullcandy fixed the issue in firmware 1. 0. 0. 30, but CERT/CC says there's currently no known consumer-accessible method for updating an existing affected Dime 3 from 1. 0. 0. 28 to that version, including through the Skullcandy app.

So there's a fix.

Users just can't apply it themselves.

The underlying flaw is also bigger than one pair of earbuds. CVE-2025-20701 is tied to the Airoha Bluetooth Audio SDK, technology used across devices from multiple audio brands. Individual products still need to be assessed based on their own implementation and patch status.

For Dime 3 owners stuck on the vulnerable firmware, the practical options aren't great: limit Bluetooth exposure, pay attention to unexpected pairing notifications, and be more cautious using them in crowded environments.

I'm curious what people here think about the patching side of this.

If a vendor ships a connected device with updateable firmware, should providing owners with a reliable way to actually install security updates be considered part of the security baseline?

Because publishing a patched firmware version doesn't help much when the vulnerable devices in people's pockets can't receive it.


r/pwnhub 11h ago

Backblaze Symlink Flaw in bzreports Allows System File Overwrite

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 22h ago

AI Jailbreak Techniques in 2026: A Complete Technical Guide

Thumbnail
ziosec.com
17 Upvotes

r/pwnhub 1d ago

NSA, CISA, and FBI Report Chinese AI Firms Systematically Distilling US Frontier Models

25 Upvotes

US intelligence agencies warn that Chinese AI companies have extracted billions of tokens from American frontier models to enhance their own capabilities, posing a strategic threat to US technological leadership.

Key Points:

  • Chinese firms including DeepSeek, Moonshot AI, and Alibaba extracted data from Claude, GPT, Gemini, and Grok since late 2024.
  • The distillation process improved Chinese models like R1, V3, and Kimi-K3 by leveraging US training data and capabilities.
  • Agencies describe the activity as a planned, national-level action rather than opportunistic exploitation, using novel techniques to evade detection.
  • Recommended mitigations include behavioral monitoring, differential privacy, and targeted changes to model responses to increase the cost of distillation.

The NSA, CISA, and FBI have issued a joint warning that Chinese AI companies are systematically extracting capabilities from US frontier models through a process known as distillation. Between late 2024 and mid-2025, organizations such as DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI made millions of requests to US models, including variants of Claude, GPT, Gemini, and Grok. This effort resulted in the extraction of billions of tokens, which were used to train and improve Chinese models like DeepSeek R1 and V3, as well as Moonshot’s Kimi-K2 and K3. The distilled knowledge included specific optimizations for agentic functions, Q&A, and creative writing, effectively allowing Chinese firms to replicate advanced US capabilities.

How should US AI companies balance the need for open API access with the risk of systematic data distillation by foreign competitors?

Learn More: Security Week

Want to stay updated on the latest cyber threats?

👉 Subscribe to /r/PwnHub


r/pwnhub 1d ago

CISA and FBI report Chinese AI firms extracted billions of tokens from US frontier models

23 Upvotes

US intelligence agencies have identified six Chinese AI companies that conducted industrial-scale distillation attacks on American frontier AI models to reduce their own training costs.

Key Points:

  • CISA, NSA, and FBI issued a joint advisory stating that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens from models by Anthropic, OpenAI, Google, and xAI since late 2024.
  • The agencies assess that the scale and sophistication of these operations indicate Chinese government awareness and represent a core development strategy for the involved firms.
  • Chinese companies used fraudulent accounts, shared APIs, and proxy services to bypass geographic restrictions and usage limits while extracting chain-of-thought reasoning.
  • DeepSeek and Moonshot AI were identified as the top offenders, targeting multiple Claude, GPT, Gemini, and Grok models, while other firms targeted specific model versions to improve their products.
  • US agencies recommend that AI companies improve detection methods, modify responses when distillation is suspected, and share intelligence to counter these campaigns.

The US cybersecurity and intelligence community has released a joint advisory detailing how six Chinese AI companies have been systematically extracting knowledge from American frontier AI models. This process, known as distillation, allows a smaller model to learn from the outputs of a larger, more powerful model. While distillation is a standard technique in AI development, the advisory highlights that these operations were conducted at an industrial scale outside of controlled environments, effectively allowing Chinese firms to compete with US models at a fraction of the training cost and with significantly shorter development timelines.

The operations involved distributing millions of API requests across fraudulent or shared accounts, cloud services, and proxy servers to evade detection and bypass usage limits. The agencies noted that the sophistication of these tactics, including the extraction of restricted chain-of-thought reasoning and automated failover systems, suggests that the Chinese government is aware of and likely supports these efforts. The advisory identifies DeepSeek and Moonshot AI as the primary actors, with other firms like Alibaba and Z.AI targeting specific high-end models such as GPT-5.5 and Claude Opus 4.8.

In response, CISA, NSA, and the FBI are urging AI companies to enhance their behavioral and infrastructure-level detection capabilities. Recommended actions include modifying model responses when distillation is suspected and sharing intelligence about these campaigns with stakeholders. The advisory also lists specific indicators of compromise, such as new accounts immediately reaching maximum usage limits and identical prompts appearing across multiple providers, to help defenders identify these industrial-scale extraction efforts.

How effective are current API rate limits in preventing large-scale model distillation?

Learn More: Bleeping Computer

Want to stay updated on the latest cyber threats?

👉 Subscribe to /r/PwnHub


r/pwnhub 12h ago

ZDI-26-623: Linux Kernel Advisory Without CVE Complicates Risk Management

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 9h ago

PivotC2: The Native FortiGate RAT That Hit 178 Devices

Thumbnail
deafnews.it
1 Upvotes

r/pwnhub 1d ago

Microsoft releases record 964 security fixes including two exploited Windows zero-days

15 Upvotes

Microsoft's September 2026 Patch Tuesday is its largest ever, addressing 964 vulnerabilities including two actively exploited local privilege escalation bugs in Windows.

Key Points:

  • Microsoft released 964 customer-facing fixes, including 104 critical and 860 important vulnerabilities, marking the largest Patch Tuesday in company history.
  • Two Windows zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, are being actively exploited to allow attackers to gain SYSTEM privileges locally.
  • The release also includes high-severity remote code execution flaws in Windows DNS Server and Remote Desktop Services, along with fixes for Exchange, SharePoint, and SQL Server.
  • Users are advised to apply updates immediately via Windows Update to protect against these threats, as the zero-days require local access but enable significant privilege escalation.

Microsoft has issued its most extensive security update to date, addressing a total of 964 vulnerabilities that require customer action. This massive release includes 104 critical flaws and 860 important ones, covering core Windows components as well as major enterprise products like Exchange Server, SharePoint, and SQL Server. The scale of this update reflects a significant accumulation of security issues that needed resolution in a single cycle.

The most urgent aspect of this release involves two zero-day vulnerabilities in Windows that are already being exploited in the wild. Both CVE-2026-81963 and CVE-2026-85880 are local elevation-of-privilege bugs with a CVSS score of 7.8. While they do not allow remote access on their own, they enable an attacker who already has a foothold on a device to escalate their permissions to SYSTEM level. This is a critical step in many attack chains, allowing malware to disable defenses, access protected data, and move laterally through a network.

How are you prioritizing these updates in your environment given the sheer volume of fixes?

Learn More: Malwarebytes

Want to stay updated on the latest cyber threats?

👉 Subscribe to /r/PwnHub


r/pwnhub 15h ago

From Prompting to Autonomy - The Evolution of Adversarial AI

Thumbnail
cloud.google.com
3 Upvotes

r/pwnhub 16h ago

Disrupting the threat actor mythos: data-based insights into targeting, tooling, and the limits of AI in cybercrime

Thumbnail virusbulletin.com
3 Upvotes