SecNoteMorning brief
Latest sync Aug 28, 9:16 PM
1 down

Red Team Radar

Help
TodayActionsStack WatchFeedIntelligence
More · Red Team
VendorMalwareRed TeamAIGlobal RiskUSWorld
HelpMethodologySourcesPrivacy

Red team radar

36 tool, exploit, and technique signals

Public PoC: Prioritize exposure review, detection mapping, and authorized lab validation. Lead item: CISA Adds Six Known Exploited Vulnerabilities to Catalog

Red team feedSources
Signals36Emerging4PoC / exploit6

Tradecraft radar

Red Team Intel

Ranked entities5
Source count16
Fresh <=72h18
Library families4/5

Common right now

Tools and Techniques

5/5 shownPoC available
EntityTrendEvidenceLast signal
Emerging tradecraft4

New / emerging

Fresh Tooling and Technique Signals

4 signals
EvasionBleepingComputer | Aug 28, 2026

PaperCut releases second emergency patch for exploited flaws

Review detection assumptions and compensating telemetry for this technique family.

ToolingThe Hacker News | Aug 27, 2026

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Track adoption signals, repo activity, and overlap with planned exercise scope.

Public PoCThe Hacker News | Aug 27, 2026

Learn How to Build Security Operations Ready for AI-Powered Attacks

Prioritize exposure review, detection mapping, and authorized lab validation.

TechniqueHacker News | Aug 28, 2026

Just the rumour of a bug is enough to find an exploit these days

Keep as tradecraft context and connect it to detections, exposure, and approved testing scope.

Attack-path detail7

Attack path

Stage Tool Frequency

7/8 active
  1. 01

    Initial access

    Edge, identity, email, and public-facing entry points.

    8
    Exploit-DB2 hitsNucleiwatchMetasploitwatchBurp Suitewatch
    Signals1 tools
    Learn How to Build Security Operations Ready for AI-Powered AttacksAug 28, 2026
    T1190 Exploit Public-Facing ApplicationT1566 Phishing
  2. 02

    Exploit validation

    PoC confirmation, scanner templates, and lab reproduction.

    4
    Exploit-DB2 hitsMetasploitwatchNucleiwatchProjectDiscoverywatch
    Signals1 tools
    CISA Adds Six Known Exploited Vulnerabilities to CatalogAug 27, 2026
    T1588 CapabilitiesT1595 Active Scanning
  3. 03

    Identity recon

    Directory, Kerberos, OAuth, token, and privilege graphing.

    7
    BloodHoundwatchCertipywatchRubeuswatchImpacketwatch
    Signals0 tools
    Ubiquiti UniFi OS RCEAug 26, 2026
    T1087 Account DiscoveryT1069 Permission Groups Discovery
  4. 04

    Post-exploitation recon

    Privilege pathing, host discovery, cloud identity, and route mapping.

    3
    Pacu2 hitsBloodHoundwatchCloudFoxwatchROADtoolswatch
    Signals1 tools
    CISA Adds Six Known Exploited Vulnerabilities to CatalogAug 26, 2026
    T1087 Account DiscoveryT1482 Domain Trust Discovery
  5. 05

    Lateral movement

    Remote services, protocol tooling, tunnels, and pivot paths.

    0
    ImpacketwatchNetExecwatchLigolowatchChiselwatch
    Signals0 tools

    Standing tool coverage

    T1021 Remote ServicesT1047 Windows Management Instrumentation
  6. 06

    C2 and operations

    Beacons, payload delivery, operator frameworks, and persistence.

    3
    SliverwatchMythicwatchHavocwatchCobalt Strikewatch
    Signals0 tools
    UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiesAug 20, 2026
    T1095 Non-Application Layer ProtocolT1105 Ingress Tool Transfer
  7. 07

    Evasion and stealth

    Bypass research, loaders, LOLBins, and detection-resistant execution.

    2
    LOLBASwatchPowerShellwatchmshtawatchrundll32watch
    Signals0 tools
    JavaScript obfuscation: From party trick to phishing kitAug 27, 2026
    T1562 Impair DefensesT1027 Obfuscated Files or Information
  8. 08

    Detection validation

    Atomic tests, rules, ATT&CK mapping, and defensive validation.

    2
    Atomic Red TeamwatchSigmawatchYARAwatchMITRE ATT&CKwatch
    Signals0 tools
    UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiesAug 25, 2026
    ATT&CK technique emulationDetection validation

Selected evidence

Public PoC / exploit code

score 321

Public proof-of-concept, exploit code, exploitability, or weaponization chatter tied to current exposure.

PoC availableNew releaseRising
TacticInitial access
Sources5
ATT&CK mapping
T1190 Exploit Public-Facing ApplicationT1588 Capabilities
Source mix
FortiGuard Threat SignalBleepingComputerCISA AdvisoriesFortiGuard Outbreak AlertsThe Hacker News
CVE-2015-3246 — Red Hat Libuser Race Condition +5 more (CISA KEV)CISA Advisories | Aug 26, 2026PaperCut releases second emergency patch for exploited flawsBleepingComputer | Aug 28, 2026Learn How to Build Security Operations Ready for AI-Powered AttacksThe Hacker News | Aug 27, 2026PTC Windchill & FlexPLM RCEFortiGuard Threat Signal | Jul 28, 2026
External lookups

Source evidence

External Lookups

GitHub topicsRepos, releases, and issue activity for Public PoC / exploit codeX / TwitterFresh researcher chatter mentioning Public PoC / exploit codeRedditCommunity discussion and practitioner questions for Public PoC / exploit codeHacker NewsHN mentions and adjacent engineering discussion for Public PoC / exploit codeExploit sourcesExploit and PoC references tied to Public PoC / exploit code