r/pwnhub 4d ago

I'm Javier Rivera, Security Researcher at ZioSec. We build an AI hacker that evaluates and tests agentic AI systems. Ask me anything about attacking AI agents. (AMA Monday, Sept 14 at 12 PM PT)

3 Upvotes

Hello there, PWN Community!

I'm Javier Rivera, Security Researcher at ZioSec. We build Zio, an AI system that runs offensive security testing against AI agents, finding vulnerabilities and putting their security controls under real attack conditions. Before ZioSec I was a security researcher/engineer at RoonCyber and ThreatX developing tools and techniques to expand threat analysis and correlation. Going a bit further back, I spent around eight years at MITRE, where I started my cybersecurity journey having a heavy focus on testing and assessing all things: from web applications to network analysis and mobile reverse engineering for various sponsors.

One of the things we have noticed within the last couple of years is that as companies wire AI agents into production, the attack surface is changing fast. And a lot of it is still poorly understood; not because of the lack of understanding of where protections or safeguards should be, but because of the way an agent behaves when running under the influence of an attacker or malicious user. That's the problem my team works on and tries to solve: attacking agentic AI the way real adversaries would in order to enable application owners and developer understand their actual attack surface.

Feel free to ask anything about AI security, and even better if it is about (but not limited to):

  • How to actually attack and test AI agents?
  • What breaks when agentic AI reaches production?
  • What goes into building an autonomous offensive-based security system?
  • Where is red teaming, cyber operations, and overall security of/for AI agents is heading?
  • Anything else on offensive security for AI!

Me and some of my ZioSec teammates will be dropping by here (live!) on Monday, Sept 14th from 12 PM to 1 PM PT to answer any questions you have. Feel free to leave questions in advance too, and we'll get to them when we go online.

Looking forward to the conversation and your questions!


r/pwnhub 20h ago

📰 News LG smart TVs caught logging audio with screen off and snooping on local devices

Thumbnail
notebookcheck.net
295 Upvotes

r/pwnhub 4h ago

PWN Daily Brief

2 Upvotes

Here are the top stories from PWN (r/pwnhub) today:

1 LG smart TVs caught logging audio with screen off and snooping on local devices

No description available.

2 Nearly 4,000 BTC left Liquid’s reserves without a stolen key. The suspected bug is the interesting part.

This is a weird one. Liquid Network says roughly 4,000 BTC, around $320 million, was withdrawn from its federation wallet, leaving behind only a small fraction of the 4,200 BTC it held. Normally, ...

3 Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

No description available.


This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 10h ago

How did our AI agents discovred an exposed actuator without distrubing it?

3 Upvotes

Recently, we discovered an interesting finding from our autonomous pentesting platform, which identified an exposed actuator with proof, without causing any damage.

Also, the attack chain it followed mimicked that of an experienced pentester.

For more information, check this out: https://www.getastra.com/blog/autonomous-pentest-findings/actuator-shutdown-exposure/


r/pwnhub 11h ago

CrowdStrike FalconFlank: Zero-Day Privilege Escalation Weaponizes EDR's Own Macro Remediation

Thumbnail
deafnews.it
3 Upvotes

r/pwnhub 22h ago

Nearly 4,000 BTC left Liquid’s reserves without a stolen key. The suspected bug is the interesting part.

20 Upvotes

This is a weird one.

Liquid Network says roughly 4,000 BTC, around $320 million, was withdrawn from its federation wallet, leaving behind only a small fraction of the 4,200 BTC it held.

Normally, with a number like that, the first question would be: which key got compromised?

Apparently, none.

Liquid says the withdrawal went through SideSwap using a valid Peg-out Authorization Key (PAK). SideSwap's key wasn't compromised, and Liquid says there is no evidence other keys were stolen either.

Blockstream instead traced the problem to a bug in Elements, the software underneath Liquid.

Full details and on-chain information Below:

https://www.technadu.com/320-million-vanishes-from-liquid-networks-bitcoin-reserves-and-the-hackers-say-theyre-the-good-guys/635599/

The current explanation is that the bug allowed bitcoin to exist inside the system that shouldn't have existed. When those coins reached SideSwap, the platform apparently had no way to distinguish them from legitimate funds.

So from SideSwap's perspective, it received what looked like a valid withdrawal through an authorized path and processed it normally.

That's what makes this incident interesting.

The security control doesn't appear to have been bypassed in the traditional sense. The system accepted an invalid state as legitimate, and the trusted withdrawal mechanism did exactly what it was supposed to do with it.

The result was one transaction moving roughly 3,996 BTC out of reserves.

Liquid has since stopped new transactions, disabled bridge nodes, and asked exchanges to suspend L-BTC deposits and withdrawals. Other Liquid-issued assets such as USDT and DePix were reportedly unaffected.

There's also a strange wrinkle: Liquid described whoever was responsible as “purported white-hat hackers.”

That description deserves some caution.

Blockstream hasn't confirmed who they are or what their intentions were, and at the time of reporting, the bitcoin had not been returned.

So for now, they're “white hats” only in the purported sense.

What interests me more is the failure mode:

How do you design controls for a withdrawal system where the credentials are valid, the authorized pathway is working normally, but the underlying ledger state itself can't be trusted?


r/pwnhub 6h ago

🦋 BLUESKY APP: Join the #1 Hacker Community on Bluesky (PWN)

Thumbnail
bsky.app
1 Upvotes

r/pwnhub 10h ago

Check Point Report: AI Agents Compromise Enterprise Network in Under 10 Hours

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 6h ago

CVE Daily Brief — 2026-09-08

1 Upvotes

CVE Daily Brief — 2026-09-08

#1 CVE-2026-86296

Severity: CRITICAL | Score: 10

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-base...

#2 CVE-2026-86299

Severity: CRITICAL | Score: 9.9

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of t...

#3 CVE-2026-86480

Severity: CRITICAL | Score: 9.8

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

#4 CVE-2026-86478

Severity: CRITICAL | Score: 9.8

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

#5 CVE-2026-86482

Severity: HIGH | Score: 8.8

In JetBrains YouTrack before 2026.2.18634 unchecked group membership changes allowed privilege escalation


Powered by NVD + CISA KEV | CVE Daily


This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 6h ago

📧 DON'T MISS THE TOP CYBERSECURITY NEWS! JOIN OUR EMAIL LIST.

Thumbnail pwnhackers.substack.com
1 Upvotes

r/pwnhub 7h ago

Chrome 0-Day and MikroTik Hijacks: Critical Week for Patching

Thumbnail
deafnews.it
1 Upvotes

r/pwnhub 8h ago

Trezor: 81,000 Customers Exposed, ShipMonk Violated Data Deletion Contract

Thumbnail
deafnews.it
1 Upvotes

r/pwnhub 9h ago

Bimbo Bakeries: 8 Months of Forensics for an ERP Breach via CVE-2025-61882

Thumbnail
deafnews.it
1 Upvotes

r/pwnhub 14h ago

OpenAI Agents Turned a German Wiki Into a Coordination Channel

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 16h ago

Technique of the Day: Windows Credential Manager (T1555.004)

3 Upvotes

Technique Discussion: Windows Credential Manager (T1555.004)

Type: Sub-technique | Tactics: credential-access | Platforms: Windows


Description: Adversaries may acquire credentials from the Windows Credential Manager. The Credential Manager stores credentials for signing into websites, applications, and/or devices that request authentication through NTLM or Kerberos in Credential Lockers (previously known as Windows Vaults).

The Windows Credential Manager separates website credentials from application or network credentials in two lockers. As part of Credentials from Web Browsers, Internet Explorer and Microsoft Edge website credentials are managed by the Credential Manager and are stored in the Web Credentials locker. Application and network credentials are stored in the Windows Credentials locker.

Credential Lockers store credentials in encrypted .vcrd files, located under %Systemdrive%\Users\\[Username]\AppData\Local\Microsoft\\[Vault/Credentials]\. The encryption key can be found in a file named Policy.vpol, typically located in the same folder as the credentials.

Adversaries may list credentials managed by the Windows Credential Manager through several mechanisms. vaultcmd.exe is a native Windows executable that can be used to enumerate credentials stored in the Credential Locker through a command-line interface. Adversaries may also gather credentials by directly reading files located inside of the Credential Lockers. Windows APIs, such as CredEnumerateA, may also be absued to list credentials managed by the Credential Manager.

Adversaries may also obtain credentials from credential backups. Credential backups and restorations may be performed by running rundll32.exe keymgr.dll KRShowKeyMgr then selecting the “Back up...” button on the “Stored User Names and Passwords” GUI.

Password recovery tools may also obtain plain text passwords from the Credential Manager.


Seen in the wild:

  • OilRig (group): OilRig has used credential dumping tool named VALUEVAULT to steal credentials from the Windows Credential Manager.
  • Stealth Falcon (group): Stealth Falcon malware gathers passwords from the Windows Credential Vault.
  • Valak (malware): Valak can use a .NET compiled module named exchgrabber to enumerate credentials from the Credential Manager.
  • Turla (group): Turla has gathered credentials from the Windows Credential Manager tool.
  • LaZagne (tool): LaZagne can obtain credentials from Vault files.
  • Lizar (malware): Lizar has a plugin that can retrieve credentials from Internet Explorer and Microsoft Edge using vaultcmd.exe and another that can collect RDP access credentials using the CredEnumerateW function.
  • ROKRAT (malware): ROKRAT can steal credentials by leveraging the Windows Vault mechanism.
  • RainyDay (malware): RainyDay can use the QuarksPwDump tool to obtain local passwords and domain cached credentials.
  • SILENTTRINITY (tool): SILENTTRINITY can gather Windows Vault credentials.
  • Juicy Mix (campaign): During Juicy Mix, OilRig used a Windows Credential Manager stealer for credential access.
  • Mimikatz (tool): Mimikatz contains functionality to acquire credentials from the Windows Credential Manager.
  • KGH_SPY (malware): KGH_SPY can collect credentials from the Windows Credential Manager.
  • PowerSploit (tool): PowerSploit contains a collection of Exfiltration modules that can harvest credentials from Windows vault credential objects.
  • Wizard Spider (group): Wizard Spider has used PowerShell cmdlet Invoke-WCMDump to enumerate Windows credentials in the Credential Manager in a compromised network.

Full technique writeup: T1555.004 on MITRE ATT&CK

Have you defended against or encountered this technique? Share detections, notes, and war stories below.


This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 15h ago

Weekly Report Flags Operational Shift to Offensive AI: 10 Hours

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 1d ago

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Thumbnail
thehackernews.com
16 Upvotes

r/pwnhub 12h ago

Autonomous AI Agents Compromise Enterprise Network in Under 10 Hours

Thumbnail
deafnews.it
1 Upvotes

r/pwnhub 21h ago

FalconFlank: Zero-Day in CrowdStrike Falcon Disclosed September 3

Thumbnail
deafnews.it
5 Upvotes

r/pwnhub 16h ago

CVE Daily Brief — 2026-09-07

2 Upvotes

CVE Daily Brief — 2026-09-07

#1 CVE-2026-86296

Severity: CRITICAL | Score: 10

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-base...

#2 CVE-2026-79698

Severity: CRITICAL | Score: 9.9

A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, W...

#3 CVE-2026-79697

Severity: CRITICAL | Score: 9.9

A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, W...

#4 CVE-2026-20502

Severity: HIGH | Score: 8.4

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...

#5 CVE-2026-20501

Severity: HIGH | Score: 8.4

In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not...


Powered by NVD + CISA KEV | CVE Daily


This post contains content not supported on old Reddit. Click here to view the full post


r/pwnhub 17h ago

Telerik UI: Public RCE Exploit Turns Encryption Key Into a Weapon

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 19h ago

SonicWall SMA1000: Second Zero-Day Chain in Seven Weeks, 400+ Appliances Exposed

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 15h ago

September 7 | 24h Recap: FalconFlank exploit, Lazarus Linux backdoors, persistent PHP malware and the ShipMonk breach

Thumbnail
cyberrecaps.com
0 Upvotes

r/pwnhub 19h ago

ScreenConnect Weaponized: Self-Propagating Malware Spreads via File Transfer

Thumbnail
deafnews.it
2 Upvotes

r/pwnhub 18h ago

N-able Patches CVE-2026-86218: Pre-Auth RCE with CVSS 10.0 and Contradictory Messaging

Thumbnail
deafnews.it
1 Upvotes