Last Week in Security (LWiS) - 2026-03-16
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内,而且不需要特定的开头。首先,我得仔细阅读用户提供的文章内容。 文章看起来是一个安全周刊的摘要,涵盖了2026年3月2日至16日的新闻、技术、工具和漏洞。新闻部分提到了Armadin公司的成立、伊朗支持的黑客攻击、Meta对jemalloc的承诺、Wiz加入Google以及Meta关闭Instagram的端到端加密。技术方面有RegPwn漏洞利用、Java反序列化工具链、信任机制工具tdo_dump等。工具和漏洞包括远程缓冲区溢出、RegPwn的Exploit代码、Phantom项目等。 接下来,我需要提取关键信息:安全周刊的时间范围,涵盖的主要内容如新闻、技术工具和漏洞,以及提到的一些关键公司和事件,比如Meta和Wiz的变化,RegPwn漏洞的影响等。 然后,我要把这些信息浓缩到100字以内,确保涵盖主要点:时间范围、主要内容类别(新闻、技术工具、漏洞)、关键公司和事件(Meta, Wiz, RegPwn)以及整体趋势或影响。 最后,组织语言使其简洁明了,避免使用复杂术语或不必要的细节。 </think> 这篇文章总结了2026年3月2日至16日的网络安全新闻和技术动态,包括Armadin公司的成立、伊朗支持的网络攻击、Meta对jemalloc项目的承诺以及Wiz被Google收购等新闻。此外还介绍了RegPwn漏洞利用工具链、Java反序列化技术及多种C2框架扩展工具等技术细节。 2026-3-17 03:59:0 Author: blog.badsectorlabs.com(查看原文) 阅读量:0 收藏

Cascade 💉 (@0xfluxsec), 🐍 for Conquest C2 (@virtualloc), Outpacket (@n00py1), RegPwn (@filip_dragovic + @Flangvik), and more!

Last Week in Security is a summary of the interesting cybersecurity news, techniques, tools and exploits from the past week. This post covers 2026-03-02 to 2026-03-16.

News

Techniques and Write-ups

Tools and Exploits

  • Remote Pre-Auth Buffer Overflow in GNU Inetutils telnetd (LINEMODE SLC) - Looks like someone is taking an interest in telnetd... Needs an ASLR bypass on modern systems, but who is running telnetd on modern systems. Embedded devices are a great target for this sort of thing.
  • RegPwn Exploit code for LPE in Windows clients and servers (CVE-2026-24291).
  • RegPwnBOF - Cobalt Strike BOF port of the RegPwn exploit by Filip Dragovic (@Wh04m1001) / MDSec ActiveBreach.
  • llmchainhunter - This repo contains the design plan and runbook for using Claude Code to search for Java Deserialization Gadget chains.
  • coruna - The actual exploits and binaries from last week's Coruna iOS exploit kit.
  • Phantom - Phantom is project created to perform loading and executing .NET assemblies directly in memory within an IIS environment running in full‑trust mode. Instead of relying on file‑based approach, it uses reflective loading techniques to inject and run a DLL inside the memory space of the w3wp.exe worker pool process
  • BYOUD is a framework for x64 stack spoofing on Windows. It tackles a complete opposite approach from classic stack spoofing, manipulating unwind metadata to hide arbitrary chunks of the call chain in debuggers and EDRs.
  • doublepulsar-rs - Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)
  • armory-rs - Rust Beacon Object Files (BOFs) for adversary simulation, threat emulation, security research, and detection engineering. All 115 TrustedSec BOFs ported from C to Rust using the rustbof framework.
  • AdaptixC2-Template-Generators - Standalone scaffolding toolkit for AdaptixC2 extender development. Generates ready-to-implement stub projects for agents, listeners, services (optionally with post-build wrapper pipeline), and custom wire protocols -- all compatible with the axc2 v1.2.0 plugin API.
  • mcp-windbg - A Model Context Protocol server that bridges AI models with WinDbg for crash dump analysis and remote debugging.
  • Outpacket - Tired of impacket? This cheatsheet maps common impacket workflows to their modern alternatives
  • Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator. It generates position-independent shellcode for in-memory execution of VBScript, JScript, EXE, DLL, and .NET assemblies, but with a heavy focus on evasion and signature resistance.

New to Me and Miscellaneous

This section is for news, techniques, write-ups, tools, and off-topic items that weren't released last week but are new to me. Perhaps you missed them too!

  • $75,000,000 Crypto Wallet Bulk Hack - Ultimate proof that physical access == root access. No matter how many secure enclaves or hardware security modules you have, if the attacker is dedicated enough and has physical access, with enough time and resources they can get in.
  • fly-brain - Whole-brain leaky integrate-and-fire model of the adult fruit fly, built from the FlyWire connectome (~138k neurons, ~5M synapses). 🤯
  • VoiceInk - Voice-to-text app for macOS to transcribe what you say to text almost instantly
  • MANPADS-System-Launcher-and-Rocket - 👀
  • PLFM_RADAR - Open-source, low-cost 10.5 GHz PLFM phased array RADAR system

Techniques, tools, and exploits linked in this post are not reviewed for quality or safety. Do your own research and testing.


文章来源: https://blog.badsectorlabs.com/last-week-in-security-lwis-2026-03-16.html
如有侵权请联系:admin#unsafe.sh