Search:

Last Week in Security (LWiS) - 2026-01-12

SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2026-01-05 to 2026-01-12.

News

Techniques and Write-ups

Tools and Exploits

  • PhantomSec | Advanced Offensive Capabilities Automated - EvadeX Sponsored - EvadeX is an evasion-as-a-service platform for red teams and pentesters who want modern, continuously-updated evasive tradecraft without turning every engagement into an R&D project. Generate highly customizable, low-signature payloads through a simple web workflow so you can tune to the target and stay focused on the engagement. Trusted by teams from small consultancies to the Fortune 10. Get callbacks past EDR today!
  • Barbhack CTF 2025 (Pirates - Active Directory Lab) - Originally featured in the Barbhack 2025 CTF, this lab is now available for free to everyone! In this lab, you'll explore how to use the powerful tool NetExec to efficiently compromise an Active Directory domain during an internal pentest. Build on VMware, VirtualBox, or Ludus.
  • watchTowr-vs-SmarterMail-CVE-2025-52691 - SmarterMail Pre-Auth RCE 1day Detection Artifact Generator Tool
  • ScrappyDoo - Opengraph-Compatible JSON Generator for BloodHound.
  • w11_shadow_copies - Create, delete or list Shadows Copies using the VSS API using C++, C# or Python.
  • EDRStartupHinder - A red team tool to prevent Antivirus and EDR from running (Check the blog post for more details.)
  • santamon - Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.
  • flashingestor - A TUI for Active Directory collection.
  • dumpguard_bof - Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.
  • ClipboardStealBOF - An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard history.
  • AfterShell - Fast Windows post-exploitation wins after initial access.
  • RemoveWindowsAI - Force Remove Copilot, Recall and More in Windows 11.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

  • I Built a 1 Petabyte Server From Scratch - A great video of a JBOD built from scratch. The highlight is all the testing done at each step of the build. Remember what Mythbusters tought you, "the only difference between screwing around and science is writing it down."
  • Climbing The Ladder: What Non-Technical Attributes Make a Senior Pentester? - Underapreciated "soft skills" that make you valuable to companies.
  • cc-agent - Another command and control agent.
  • kreuzberg - A polyglot document intelligence framework with a Rust core. Extract text, metadata, and structured information from PDFs, Office documents, images, and 50+ formats. Available for Rust, Python, Ruby, Java, Go, PHP, Elixir, C#, TypeScript (Node/Bun/Wasm/Deno) — or use via CLI, REST API, or MCP server.

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.

page 1 | older articles »