Last Week in Security (LWiS) - 2026-01-12
嗯,用户让我总结一下这篇文章的内容,控制在100字以内,而且不需要特定的开头。我先看看文章的大致结构。文章分为新闻、技术和工具、新增内容等几个部分。 首先,新闻部分提到了伊朗断网、德国招聘CTF玩家、隐私问题以及微软的更新。技术部分有预授权RCE漏洞、Claude代码执行、VSS创建工具和EDR绕过工具。工具部分包括PhantomSec、Barbhack CTF实验室和一些检测工具。新增内容主要是关于服务器搭建和红队工具。 接下来,我需要把这些信息浓缩到100字以内,涵盖主要的安全事件和技术亮点。要注意不要遗漏关键点,比如漏洞、工具和趋势。 可能的结构是:先总述安全事件和技术亮点,然后分点列出主要内容。比如提到漏洞、工具、隐私问题和微软更新等。 最后,确保语言简洁明了,不使用复杂的术语,让读者一目了然。 </think> 这篇文章总结了过去一周的网络安全动态,包括伊朗互联网断网、德国情报机构招聘CTF选手、隐私监控争议及微软更新等新闻。技术方面涉及SmarterMail预授权RCE漏洞、Claude代码执行滥用及VSS创建工具等。此外还介绍了PhantomSec红队工具、Barbhack CTF实验室及多种检测与绕过工具。 2026-1-13 10:52:54 Author: blog.badsectorlabs.com(查看原文) 阅读量:2 收藏

SmarterMail Pre-auth RCE (@chudyPB + @SinSinology), Claude Code code execution (@ryotkak), VSS create (@RicardoJoseRF ), EDRStartupHinder (@TwoSevenOneT), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2026-01-05 to 2026-01-12.

News

Techniques and Write-ups

Tools and Exploits

  • PhantomSec | Advanced Offensive Capabilities Automated - EvadeX Sponsored - EvadeX is an evasion-as-a-service platform for red teams and pentesters who want modern, continuously-updated evasive tradecraft without turning every engagement into an R&D project. Generate highly customizable, low-signature payloads through a simple web workflow so you can tune to the target and stay focused on the engagement. Trusted by teams from small consultancies to the Fortune 10. Get callbacks past EDR today!
  • Barbhack CTF 2025 (Pirates - Active Directory Lab) - Originally featured in the Barbhack 2025 CTF, this lab is now available for free to everyone! In this lab, you'll explore how to use the powerful tool NetExec to efficiently compromise an Active Directory domain during an internal pentest. Build on VMware, VirtualBox, or Ludus.
  • watchTowr-vs-SmarterMail-CVE-2025-52691 - SmarterMail Pre-Auth RCE 1day Detection Artifact Generator Tool
  • ScrappyDoo - Opengraph-Compatible JSON Generator for BloodHound.
  • w11_shadow_copies - Create, delete or list Shadows Copies using the VSS API using C++, C# or Python.
  • EDRStartupHinder - A red team tool to prevent Antivirus and EDR from running (Check the blog post for more details.)
  • santamon - Lightweight macOS detection agent built on Santa’s Endpoint Security telemetry.
  • flashingestor - A TUI for Active Directory collection.
  • dumpguard_bof - Beacon Object File (BOF) port of DumpGuard for extracting NTLMv1 hashes from sessions on modern Windows systems.
  • ClipboardStealBOF - An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard history.
  • AfterShell - Fast Windows post-exploitation wins after initial access.
  • RemoveWindowsAI - Force Remove Copilot, Recall and More in Windows 11.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

  • I Built a 1 Petabyte Server From Scratch - A great video of a JBOD built from scratch. The highlight is all the testing done at each step of the build. Remember what Mythbusters tought you, "the only difference between screwing around and science is writing it down."
  • Climbing The Ladder: What Non-Technical Attributes Make a Senior Pentester? - Underapreciated "soft skills" that make you valuable to companies.
  • cc-agent - Another command and control agent.
  • kreuzberg - A polyglot document intelligence framework with a Rust core. Extract text, metadata, and structured information from PDFs, Office documents, images, and 50+ formats. Available for Rust, Python, Ruby, Java, Go, PHP, Elixir, C#, TypeScript (Node/Bun/Wasm/Deno) — or use via CLI, REST API, or MCP server.

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.


文章来源: https://blog.badsectorlabs.com/last-week-in-security-lwis-2026-01-12.html
如有侵权请联系:admin#unsafe.sh