• Kulkan Newsletter
  • Posts
  • How a single typo silently downgraded AES encryption (and more)

How a single typo silently downgraded AES encryption (and more)

The latest from Kulkan: our team reported a silent AES encryption downgrade hiding in a Python library recommended by LLMs; the vulnerability became CVE-2026-44722. Plus, what's coming at Black Hat & DEF CON 2026, and the cybersecurity news and write-ups to keep you ahead of the threat landscape.

πŸ“ Latest from Our Blog:

CVE-2026–44722: A Zip encryption downgrade caused by an incorrect operator

A single-character typo (a "|" where an "or" belonged) silently downgraded AES encryption and left a CRC32 checksum exposed, enabling attackers to recover small files by brute force without ever attacking the password.

The post walks through the vulnerability, zooms out to the class of bug it belongs to, and builds a reproducible PoC along the way.

πŸ—“οΈ Key Industry Events:

Kulkan at Black Hat & DEF CON 2026!

We bring our attacker mindset to the most influential cybersecurity events, sharing what we've learned across 25+ years in pentesting so more businesses can raise their security bar.

Our team will be in Vegas connecting with security leaders and practitioners from the US and beyond, and of course, handing out free stickers to anyone lucky enough to cross our path! πŸ‰βœ¨

Will you be in Vegas next week? Let's connect!

🌐 Industry News:

Want to keep up with the threat landscape?

OpenAI models escaping a sandbox to compromise Hugging Face's infrastructure, an unauthenticated RCE in WordPress core affecting 500 million sites, and other cybersecurity stories that caught our attention.

πŸ“ Also From Our Blog:

Catch up on other technical blog posts; you’re still on time to read them!

Reversing a 433 MHz Weather Sensor: From RF Capture to Payload Forgery

By Matias Fumega

Breaking Into a Govee Smart Display: From UART Shell to Device Impersonation

By Matias Fumega

See no Evil(ginx) / Detecting and stopping AitM phishing threats

By Matias Forti

Any penetration test in scope?

Let's start the conversation and explore how an attacker-led approach can strengthen your defenses and support your business growth.