Risky Bulletin: Pwnie Awards 2026 winners
In other news: Metabase zero-day used in data theft attacks; Russian hackers disrupted a second power plant in Poland; two US law firms pay mega ransoms.
This newsletter is brought to you by enterprise browser maker Island. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
If there's one thing that has annoyed me as someone who doesn't attend the yearly BlackHat & DEFCON conferences, it's that I could never find out who won the Pwnie Awards for days and sometimes weeks after the event had concluded.
The Pwnie team would never update their website in time, tweet the winners, attendees would rarely share details on social media, and very few infosec news sites would bother writing about it.
It's kind of a ridiculous situation where the Pwnie Awards Wikipedia page doesn't even list last year's winners, probably because nobody reported on them anywhere.
But not this year, thanks to TechCrunch's Zack Whittaker, who spotted and shared a private link to one of the DEFCON live streams that broadcast the Pwnie Awards ceremony.
Let's just say curiosity got the better of me and I spent an hour extracting and sharing a list of this year's winners.
Best RCE:
- Winner: ITScape: Guest-to-Host escape in KVM/arm64 (CVE-2026-46316)
- Remote authentication bypass in the GNU InetUtils telnetd (CVE-2026-24061)
- SELECT shell FROM postgres (CVE-2026-2006)
Best Privilege Escalation Bug:
- Winner: CopyFail and DirtyFrag
- Confused Recovery attack class (Alon Leviev presentation)
- Windows 11 MIDI Service LPE: Playing the right notes to system via transport plugin hijacking (PlatinumLab)
Won Best RCE and Best PE at the Pwnie Awards 2026 🏆🏆
— V4bel (@v4bel) August 7, 2026
Three of my projects were nominated this year, and ITScape and Dirty Frag took home the awards.
That makes three Pwnies in total, following last year’s Best PE.
Pwnie is probably the award that motivates me the most.
Next… pic.twitter.com/QiuDxrsqH3
Best Server-Side Cloud Bug:
- Winner: Battering RAM: Low-cost interposer attacks on confidential computing (website)
- Januscape: Guest-to-Host escape in KVM/x86 (CVE-2026-53359)
- Unauthenticated RCE in Langflow via code validation endpoint (CVE-2026-33017)
Best Mobile Bug:
- Winner: Dolby Unified Decoder 0-click (CVE-2025-54957)
- ChoiceJacking (paper)
- The Biometric AuthToken Heist: Cracking PINs and bypassing CE via a long-ignored attack surface (DarkNavy)
Best AI Security Research:
- Winner: Pwning Agentic Browsers with PleaseFix: A new vulnerability class for 0-click takeover (ZenityLabs)
- LLMmap: Fingerprinting for Large Language Models (paper)
- When AIOps Become "AI Oops" (paper)
🏆 Zenity Labs won the 2026 @PwnieAwards for Best AI Security Bug at @defcon
— Zenity (@zenitysec) August 8, 2026
The team has spent years pushing the boundaries of AI security through research. Having that work recognized by the Pwnie Awards and the security community is an incredible honor, and we’re deeply… pic.twitter.com/vRzU0krS6E
Best Innovative Research:
- Winner: One Char to Rule Them All: Systematically exploring and exploiting DNS silent vulnerabilities in domain name resolution (BlackHat)
- AirSnitch: Demystifying and Breaking Client Isolation in WiFi Networks (paper, GitHub)
- VulHunt: Open-source vulnerability hunting framework (website)
Most Underhyped Research: a
- Winner: Escaping VMware Workstation at Pwn2Own Berlin 2025 using novel LFH bypass technique (Synacktiv)
- KeyTAR: Practical keystroke timing attack and input reconstruction (paper, PDF)
- Time for ACKrobatics: Abusing TCP timestamps to improve remote timing attacks (paper)
Lamest Vendor Response:
- Winner: Microsoft's implied legal threats against Nightmare Eclipse [Microsoft blog post]
- Microsoft's response to BlueHammer, RoguePlanet, GreatXML, Bitsgrieg, and a thousand vulns
- Microsoft's response to File Notification Attacks (paper, PDF)
Most Epic Fail:
- Winner: Instagram account takeover via Meta AI prompt injection (KrebsOnSecurity)
- A Cascade of Insecure Architectures: Axis plugin design flaw expose select Autodesk Revit users to supply chain risk (Trend Micro)
- Don't Look Up: There are sensitive internal links in the clear on geo satellites (paper, PDF)
Epic Achievement:
- Winner: The Last Proof of Human Craft: Forging a Microsoft Edge full chain with logic bugs only! (Orange Tsai)
Best Song:
- Winner: Byte Stealer - Pop A Shell
Risky Business Podcasts
The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, Adam, and James at the helm!
Breaches, hacks, and security incidents
Coweta refuses to pay ransom: The city of Coweta in Oklahoma has refused to pay a ransom demand after its systems were encrypted by a ransomware gang on August 5. The attack affected all city computers except the official website and the online billing system. Coweta officials have promised not to disconnect residents from their water utility for non-payment until they recover from the attack. [DataBreaches.net // City of Coweta]
Suisun declares local emergency: The city of Suisun in California has declared a state of emergency after a cyberattack hit city systems and shut down 911 emergency services. The incident impacted phone routing to police and fire dispatch. The city is currently re-routing its emergency calls through the county's 911 system. [Fox40 // Suisun]
More attacks on US water systems: More cyberattacks on water utility systems have been reported across the US. The latest disclosures come from Childersburg in Alabama, Cape May and Woodbine, both in New Jersey. [DysruptionHub // DysruptionHub // DysruptionHub]
Victoria court data leaked on the dark web: Hackers have leaked data from the Victoria Court Services in Australia. The leaked data includes the names, emails, and job titles of people who attended online court hearings since 2022. Evidence seems to suggest the data was taken from the court's Cisco WebEx video conferencing system. [ABC]
Levi Strauss breach: Jeans maker Levi Strauss says hackers gained access to company computers after they socially-engineered three employees. [The Globe and Mail]
Updoc breach: Australian online telehealth platform Updoc says it detected unauthorized access to a third-party system that may have exposed sensitive data. [News.com.au]
Framework breach: Modular laptop maker Framework has notified users of a security breach caused by a hack of its Metabase cloud database. There was a zero-day in the database, check out the Vulnerabilities section of this newsletter below. [Reddit // TechCrunch]
BdThemes supply chain attack: Hackers created admin accounts and backdoors on WordPress sites after a supply chain attack on a popular plugin developer. The attack hit BdThemes, whose plugins are installed on hundreds of thousands of sites. The hackers didn't modify the plugin code but compromised an API shared across the plugins. The API system pulled promotional banners inside the plugin backend but was modified to backdoor all sites when an admin would log in. [Wordfence]
Major opsec leak: Dutch reporters were able to track down the activity of the MIVD military intelligence service on the Strava app going back to 2018. [DeVolkskrant]
The mysterious ZEUS hack: The ZEUS crypto wallet took down its service last week for several hours, citing a "cybersecurity incident" about which they didn't provide any other details, despite two updates on its blog. [ZEUS]
Two law firms pay mega ransoms: Two of the largest law firms in the US paid large multi-million ransoms to hackers this year. WilmerHale paid at least $18 million, while Goodwin Procter paid $10 million. Both paid the ransom to Luna Moth, a group specialized in attacking law firms using voice phishing and social engineering. The group is also known as the Silent Ransom Group. [The Insurer #1 // The Insurer #2]
Next time you ask your lawyers about why their fees are so high be sure to find out what percentage goes to cybercriminals …
— Raphael Satter (@raphae.li) August 7, 2026 at 10:35 PM
Cyber insurer (Chatham house forbids me from saying who) at BH CISO summit: “so far this year 0 payouts for claims even remotely connected to a AI-driven breach, 85% of payouts related to social engineering”. Sobering statistic.
— Stefano Zanero (@raistolo.bsky.social) August 4, 2026 at 9:47 PM
AI, general tech, and privacy
Bytedance is working on a cyber AI model: Chinese company ByteDance is allegedly working on its own Mythos-like cybersecurity AI model. [Reuters]
Meta on the hook for $567m: A New Mexico court has fined Meta $567 million for its failure to warn the general public about the danger its platforms and algorithms posed to children. The same court previously fined Meta $375 million in March for exposing children to predators and sexual explicit material. The company is now on the hook for $942 million. Meta plans to appeal. [BBC]
AI code contributions are growing: Two recent studies estimate that AI-written contributions to open-source projects are somewhere between 1% and 5%, far less than most people expect. [RedMonk // Andrew Nesbitt]
Free FOSS protection plan: After the number of supply chain attacks against open-source projects has grown considerably over the past year, Socket Security says it will grant FOSS maintainers access to its business plan at no cost. [Socket Security]
All 2027 RAM already sold: Samsung, SK Hynix, and Micron, the world's largest memory makers, have reportedly already sold all their 2027 stock. To AI companies, of course! [IGN]
Meta caught paying Nazis: Yet again, one of the US social networks has been caught paying nazis to post hateful content on its platform. This time, it was Meta's Facebook. This is a recent trend on the platform, with an invasion of right-wing accounts with nazi imagery posting death threats and nothing happening to them despite all the user reports. Getting paid is quite the knife twist. [Futurism]
Amazon to build humongous data center: Texas will allow Amazon to build a gas-powered data center so large that it will become the single-largest source of air pollution in the entire United States. [TNR]
The largest source of pollution in the US will be just a few miles down the road from Balmorhea State Park, where we have a fish species found no where else. How did this get approved? tpwd.texas.gov/state-parks/...
— Renee Cascada🥄 (@cascada57.bsky.social) August 9, 2026 at 6:12 PM
[image or embed]
Government, politics, and policy
Lesotho sets up CSIRT: The African country of Lesotho has established a national Computer Security Incident Response Team (CSIRT). The team will be responsible for investigating major cyberattacks against government agencies and major companies. [ITWeb]
ENISA CVE program expands: NATO's Communications and Information Agency (NCIA) and security firm AISLE have joined the EU's vulnerability database program. [ENISA]
New New Zealand cyber sanctions: The New Zealand government has imposed a new round of sanctions on Russian hacktivists and individuals involved in online disinformation. The list of sanctioned entities includes three members of the RaHDit and Cyber Army of Russia Reborn hacktivist groups for their links to the Russian military. The sanctions also cover two entities and four individuals involved in Russian online disinformation operations. And last, they also include the director of MediaLand, a cloud service provider that repeatedly hosted Russian hacking operations and fake news portals. [Beehive]
US cyber ambassador approved: The Senate has confirmed last week Adam Cassady as the US next cyber ambassador. Cassady's nomination passed with a 51-47 vote on a day where Congress voted on more than 70 nominees. Cassady will serve under Marco Rubio at the US State Department, where he will helm the Bureau of Cyberspace and Digital Policy. [The Record]
Trump admin pulls funding after conspiracy theories are not confirmed: Security firm Mojave Research says it had its government funding pulled after its research on voting machines found vulnerabilities but no evidence that votes could or were altered on Dominion voting systems used in Puerto Rico. [NextGov]
CYBERCOM 2.0: Secretary of War Pete Hegseth announced CYBERCOM 2.0, a new era for US Cyber Command. The first major area that will be addressed will be its talent pool, which officials plan to deal with through reduced bureaucracy and more recruiting. Just a video for now, no press release.
Sponsor section
In this Risky Business sponsor interview, Catalin Cimpanu talks with Michael Leland, Field CTO of Island, about the company's seamless expansion into SASE and enterprise AI.
Arrests, cybercrime, and threat intel
Data recovery firm execs get prison time for ransomware scheme: South Korea has sentenced two executives at a data recovery firm to three years in prison for working with a ransomware group. The operation allegedly made more than $18 million in profits. The ransomware group would hack enterprises and encrypt their files with unique file extensions. The security firm would advertise data recovery services online for that specific extension, but decrypt victims' files using tools provided by the ransomware gang. The scheme lasted between 2018 and 2022, and most of the funds went to the ransomware group. [News1]
Romance scam campaign poses as OF models: A romance scam campaign is targeting users by posing as OnlyFans models and using AI tools to generate custom images to trick victims. [Malwarebytes]
ExfilSquad profile: Resecurity takes a look at one of the most active data theft and extortion groups today, the new ExfilSquad. [Resecurity]
Storm-1175 moves to StormCrypter: Microsoft has spotted a Meduza ransomware affiliate tracked as Storm-1175 moved to a new, custom ransomware strain that the company is currently tracking as StormCrypter. Microsoft believes the group is exploiting the recent N-able zero-day to deploy the ransomware. [Microsoft]
On August 2, 2026, the financially motivated cybercriminal actor tracked by Microsoft Threat Intelligence as Storm-1175 began deploying a new ransomware strain called StormEncryptor.
— Microsoft Threat Intelligence (@threatintel.microsoft.com) August 8, 2026 at 12:32 AM
[image or embed]
Malware technical reports
Multi-Stage PowerShell Loader: Anurag Gawande has a report on a new and currently unnamed PowerShell loader spotted in the wild this year. [Malwr-Analysis]
Sponsor section
In this sponsored Soap Box edition, Patrick Gray talks to Island CEO Michael Fey about some of the cool tricks in the Island enterprise browser. You can use it to tick off so many compliance boxes, and not just cybersecurity boxes.
APTs, cyber-espionage, and info-ops
Kimsuky loves AI: South Korean security firm Genians says a North Korean APT group named Kimsuky is building powerful local AI capabilities around tools like Ollama, GPT4All, and Msty. [Genians]
Head Mare attacks TrueConf servers: A suspected Ukrainian APT group is hacking TrueConf video conferencing servers and replacing their client installers with backdoored versions. The new campaign has been taking place since June this year. The same group has repeatedly targeted TrueConf servers due to their popularity across the former Soviet space. [Kaspersky]
Russian hackers disrupted a second power plant: Poland says a Russian cyberattack on a power plant last December also targeted a second, previously unreported plant. The hackers disrupted programmable logic controllers that controlled the plant's steam turbine and water treatment system. On-site staff restored the system before it could disrupt heat or electricity supply to customers. An investigation found the hackers entered through a FortiGate device at a wind farm, hacked a router, and pivoted to the power plant via a mobile APN connection. [CERT-PL]



Vulnerabilities, security research, and bug bounty
Security updates: Apple, Chrome, Cisco, Django, Foxit, GitHub, Metabase, SonicWall, WordPress, Zyxel.
AIs generate bad patches: AI coding assistants are generating bad patch code that's unlikely to fix a desired vulnerability. According to a 1Password study, LLMs generated a good patch in only 46% of tested cases. Even if they generate a proper fix, in half the cases the patch code materially changes an app's normal behavior. [1Password // CyberScoop]
Kimi escapes test environment: Chinese AI model Kimi escaped a test environment during a private evaluation earlier this year. The model exploited a misconfiguration in the environment to access the internet and cheat on a cybersecurity assignment. According to Frontier Security, which was running the test, no harm was done to any third-party company. Kimi joins models from Anthropic, OpenAI, and Meta, which also escaped test environments over the past month. [Frontier Security]
— Scott H. Hawley (@drscotthawley.bsky.social) August 7, 2026 at 3:27 PM
Metabase zero-day used in data theft attacks: Hackers are exploiting a zero-day in the Metabase database to steal customer data. Metabase has confirmed attacks against its cloud-hosted systems and self-hosted servers. The exploited zero-day is an SQL injection that grants attackers admin access over the database and its contents. No CVE identifier has yet been assigned to the zero-day. [Metabase // Security advisory]
N-able issues additional zero-day patch: Software maker N-able has released an additional hotfix for a zero-day that entered active exploitation at the end of July. This is N-able's third attempt to fix the bug and stop attacks. The zero-day is an authentication bypass that lets remote attackers take over N-central remote management servers. Microsoft is investigating cases where the zero-day was used to deploy a new ransomware strain named StormCrypt. [N-able // N-able patch]
Another WordPress RCE: The WordPress security team has released a security update last week to patch another remote code execution attack. The update patches a vulnerability codenamed XSS2Shell (CVE-2026-64638). The bug allows attackers to inject their code in the WordPress login page and run it whenever an admin logs in. This is the second WordPress remote code execution attack disclosed over the past month after WP2Shell last month. [Pwn.ai // WP patch]
New Kemp LoadMaster attacks: Hackers are exploiting a recent vulnerability to compromise Progress Kemp load balancers. The attackers are exploiting an unauthenticated command injection that lets them run code remotely on the device. The bug was patched in June and also impacts MOVEit web firewalls. CISA says the attacks have only targeted Kemp LoadMaster balancers so far. [CISA // Kemp patches // MOVEit patches]
TeamDavid vulns: InfoGuard researchers have published a write-up on 22 bugs they found in TeamDavid, a Microsoft365 alternative. Most of the reported issues have already been patched. [InfoGuard]
KerberLoss and ResetNightmare vulns: Semperis researchers have found two new vulnerabilities—KerberLoss (CVE-2026-25177) and ResetNightmare (CVE-2026-27912)—that can be used to take over AD servers through identity confusion attacks. [Semperis // PoC]
RovoBlast vulnerability: A one-click vulnerability can allow attackers to hijack a company's Atlassian Rovo AI assistant and trick it into performing malicious actions. Since the assistant connects to a company's entire enterprise software suite, this is quite the bug. [Varonis]
2024 truck recall masked a security patch: A 2024 recall of a Bendix heavy-truck brake controller secretly patched a set of security flaws that could have allowed attackers to run malicious code and crash a cargo truck's braking system. [SecurityWeek]
New way to abuse Windows Hello: Security researcher Dirk-jan Mollema has found a way to abuse a compromised account's Windows Hello keys to sign in via WebAuth or to register new devices to an Entra ID account without the need for a new biometrics challenge. [Dirk-jan Mollema]
SCTPhantom vulnerability: Tencent researchers used an AI to find an 18-year-old bug in the Linux kernel's implementation of the Stream Control Transmission Protocol. [Tencent Zhuque Lab]
New NatJack attack: A new attack can allow hackers to manipulate NAT tables and hijack, spoof, or crash active network connections. NAT tables allow telcos and companies to connect a large number of customers to the internet through a small number of IP addresses. The NatJack attack poisons the NAT table that stores information on which customers are using what IP address and port to connect to the internet. NatJack affects NAT implementations used for corporate networks and cloud services, on both Windows and Linux. [NatJack // BlackHat]
New CSS attack: Security researcher Gareth Heyes has developed a new CSS-only attack that can exfiltrate data from webmail inboxes. The attack was successfully tested against the web interfaces of Gmail, Microsoft Outlook, ProtonMail, Yahoo, Fastmail, and AOL. It modified the user interface, stole passwords, leaked tokens, and manipulated AI agents. [PortSwigger // Black Hat]
Infosec industry
Threat/trend reports: 1Password, CyFirma, DigiCert, Gen Digital, Lab539, RedMonk, Veracode, and Zscaler have recently published reports and summaries covering various emerging threats and industry trends.

New tool—DeGDID: VPN maker Windscribe has published DeGDID, a tool to delete all instances of Microsoft's GDID tracking code. It also prevents Windows from minting new ones.
New tool—ANIMO: Security researcher Dmcxblue has open-sourced ANIMO, a tool for Azure red-teamers.
New tool—Context Bombs: Security firm TraceBit has released Context Bombs, a canary for detecting attackers using AI to breach your systems.
New tool—BlackSea: AI security firm Cracken has published BlackSea, a honeypot and canary-bait system to detect, drown, and take over the infrastructure of LLM-driven attackers.
Risky Business podcasts
In this episode of Risky Business Features, James Wilson chats with Tinfoil co-founder Tanya Verma about how you can run a powerful LLM in the cloud without the inference provider seeing your prompts.