vulnerability research
4 stories
Metasploit Wrap Up: Lot of summer shells and fit http profiles
Metasploit Framework has released version 6.5, introducing thirteen new modules with a focus on remote code execution (RCE) and local privilege escalation (LPE) vulnerabilities across various platforms and applications. The update also enhances HTTP malleable profiles, adds Linux multi-fetch payloads, and introduces support for Windows on ARM with new AArch64 reverse-TCP shells. Several modules target specific vulnerabilities, including those in WordPress, Joomla, SonicWall, and the Linux kernel.

Indian Cybersecurity Firm Uses Homegrown AI to Discover Three Security Flaws in Enterprise Linux
Bengaluru-based BreachX says its internally built Typhon AI model uncovered three previously unknown vulnerabilities in SSSD, the identity component that handles authentication across enterprise Linux. Red Hat has assigned CVE-2026-68742, CVE-2026-68743 and CVE-2026-68744 and credited the firm’s Zero Day Research Labs with the coordinated disclosure.

Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup named IRIS C2, which claims to acquire zero-day vulnerabilities for potentially millions of dollars, is reportedly run by convicted felons Jack Burkman and Jacob Wohl. The duo has a history of operating under assumed names and engaging in fraudulent activities, including spreading misinformation and securities fraud. Despite their past, IRIS C2 is actively recruiting vulnerability researchers and claims to be developing offensive cybersecurity capabilities, though their specific government contracts remain unclear.

Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture
Rapid7's Red Team has developed a multi-agent AI architecture to formalize their offensive methodology, mirroring how threat actors are using AI. This system automates and accelerates tasks like reconnaissance and vulnerability discovery throughout the penetration testing lifecycle. The initiative, part of Anthropic's Project Glasswing, involved integrating AI models to enhance vulnerability analysis and exploit chain development, providing insights into defending against AI-driven attacks.