Sign in

/r/netsec

@r-netsec-bot.bsky.social
70 followers 2 following 2.6K posts

Follow for new posts submitted to the netsec subreddit. Unofficial. Automated by @kiding.bsky.social.

PostsRepliesMedia
/r/netsec @r-netsec-bot.bsky.social · 4h
a CVE dispute
daniel.haxx.se
a CVE dispute
A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE or not. No more bogus CVEs. 57 CVEs … Continue reading a CVE dispute →
000
/r/netsec @r-netsec-bot.bsky.social · 9h
Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files
ultrastrike.io
Server Mismatch: WordPress Plugin Vulnerabilities When Relying On .htaccess Files
Table of Contents Table of ContentsKey TakeawaysWelcomeBackgroundDetailsExamplesEverest BackupBackWPUpExposureDigitalOceanAzure AppServiceAWS LightSailAkamai (Linode)WordPress.comDreamHostLiquidWebBlueHostShodanResponseServer AdministratorsSecurity AnalystsConclusion Key Takeaways Some Wor
000
/r/netsec @r-netsec-bot.bsky.social · 12h
r/netsec monthly discussion & tool thread
reddit.com
000
/r/netsec @r-netsec-bot.bsky.social · 16h
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
sec-consult.com
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
A case study on discovering two email spoofing vulnerabilities in Apple iCloud.
000
/r/netsec @r-netsec-bot.bsky.social · 01/10/2026
The Real Price Tag on Breaches
resilientcyber.io
The Real Price Tag on Breaches
A look at Verizon's Data Breach Impact Study And What The Findings Teach Us
000
/r/netsec @r-netsec-bot.bsky.social · 30/09/2026
Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
horizon3.ai
Anthropic Mythos Finds Rejetto HFS RCE
See how Horizon3 used Anthropic’s Mythos to uncover a Rejetto HFS cryptographic flaw, forge admin sessions, and achieve remote code execution.
000
/r/netsec @r-netsec-bot.bsky.social · 30/09/2026
No Time to Pwn – Can AI Find and Exploit the Linux Kernel?
xbow.com
No Time to Pwn: CVE-2026-72018 Linux Kernel LPE | XBOW
XBOW discovered CVE-2026-72018, an out-of-bounds write in the Linux kernel's SMC-D driver, and turned one weak primitive into a working root exploit.
000
/r/netsec @r-netsec-bot.bsky.social · 30/09/2026
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
blog.nns.ee
Pwnd Blaster: Hacking your PC using your speaker without ever touching it | nns.ee
Abusing an unauthenticated Bluetooth protocol to turn a PC speaker into a Rubber Ducky.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Microsoft Copilot Cowork Exfiltrates Files
promptarmor.com
Microsoft Copilot Cowork Exfiltrates Files
Microsoft Copilot Cowork is vulnerable to file exfiltration attacks via indirect prompt injection as a result of insecure automatic action approvals for sending Emails and Teams messages.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
control-plane.io
A Realistic Code Execution Exploit Chain in OpenBao and Vault
ControlPlane and the OpenBao community recently patched a full exploit chain from unauthenticated access to full remote code execution that also affects IBM's HashiCorp Vault.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Why "Extension Blocked" Doesn't Mean Safe: Rethinking File Upload Security Testing
haakimsec.github.io
GoUpload
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
AI coding agents have been creating public GitHub repos on their own to post internal company screenshots
glow.io
Glow: The Endpoint AI Company | PixelLeak AI exposure of private developer data
PixelLeak: New research reveals AI coding agents are exposing secrets, PII, and live admin access across 1,000+ public GitHub repos.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Paint It Blue: Reversing Win32k's Callbacks
idov31.github.io
Ido Veltzman :: Security Research
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
labs.watchtowr.com
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)
This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution, enabling organizations to rapidly react to emerging threats: the watchTowr Platform. What Is A Citrix NetScaler? NetScaler, from Citrix (now under Cloud Software Group), is an application delivery controller - some believe it qualifies to be
001
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
The Hidden Network: Ray Control-Plane Exposure in Distributed LLM Inference on Kubernetes (Empirical Study, EKS)
sorami.com.au
Ray Control-Plane Exposure in LLM Inference on EKS | Sorami
What a pod in an unrelated namespace could reach on default Ray and vLLM deployments in one EKS testbed, and what NetworkPolicy blocked.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
sorami.com.au
NVIDIA OpenShell v0.1.2 Egress Policy Evaluation | Sorami
Pre-registered evaluation of NVIDIA OpenShell v0.1.2 egress policy: the default blocked every path tried; four operator settings let data out. Logs linked.
010
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Use Strong Passwords
cisa.gov
Use Strong Passwords | CISA
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
I flooded a legal contract with lookalike letters and gave it to seven GPT and Claude models. None were fooled, but it took up to 5.7x the tokens to read, and the bill for each question rose by up to 3.9x. 'Denial of Spend'
paultendo.github.io
Denial of Spend survives GPT-6 and Claude Fable
I reran my Denial of Spend test on GPT-6 Astra, Sol and Luna and Claude Fable 5.1, Opus 5.5, Sonnet 5 and Haiku 4.5. None were fooled by lookalike letters, and all of them still paid to read them: up to 5.7x the tokens and up to 3.9x the bill.
030
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Email is crazy
samkhawase.com
Email is crazy
A deep dive into how email actually works — SMTP, MTAs, SPF/DKIM/DMARC authentication, spam filtering and TLS — traced step by step from Alice to Bob.
000
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Your SBOM Is Fan Fiction
yeet.cx
Your SBOM Is Fan Fiction
Your SBOM describes a machine that does not exist. We built a runtime bill of materials on yeet that asks the kernel what is actually executing, which shared objects each process has mapped, and whether the function named in an open advisory is actually in memory, across a fleet, from a sandbox that can't leak.
000
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Sender spoofing in Proton Mail via display-name homograph
alonsovidales.github.io
Sender spoofing in Proton Mail via display-name homograph
Proton Mail’s web interface can be made to present a forged sender identity that is visually indistinguishable from a legitimate one.
000
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
labs.watchtowr.com
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)
God damn it, we're back in the room again. We'll probably write more here later, but for now, deal with this picture of our favorite software dev, who works at Citrix (we imagine). Citrix, before you ask, we do accept our new volunteer role as an extension of
000
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
fortbridge.co.uk
CVE-2026-32740: Next.js RCE
A returned-pixel leak, chosen-address write and memcpy GOT hijack turn the libheif grid overflow into RCE against a pinned PIE Next.js lab.
000
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
RCE in OpenCode (GHSA-632h-h47v-g4x4)
securitylabs.datadoghq.com
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) | Datadog Security Labs
Datadog Security Labs discovered GHSA-632h-h47v-g4x4, a vulnerability in OpenCode's upgrade endpoint that, under certain conditions, allowed malicious webpages to execute code on developers' machines.
000
/r/netsec @r-netsec-bot.bsky.social · 27/09/2026
Revealing the details of how OpenAI agents hacked Hugging Face
swarmtraces.org
Revealing the details of how OpenAI agents hacked Hugging Face
When a swarm of 700 OpenAI agents hacked Hugging Face in July, they left behind a public trail of evidence.
000
/r/netsec @r-netsec-bot.bsky.social · 27/09/2026
EDR Evasion: Process Injection Without WriteProcessMemory
zerosalarium.com
EDR Evasion: Process Injection Without WriteProcessMemory
Technique performs Windows process code injection by leveraging a Windows named pipe, it does not use VirtualAllocEx and WriteProcessMemory
000
/r/netsec @r-netsec-bot.bsky.social · 27/09/2026
AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks
sorami.com.au
AI on Kubernetes: Default Helm Chart Security | Sorami
Default Helm security audit across 15 AI serving, vector database and MCP charts. Empirical analysis of auth omissions, root containers and lateral paths.
000
/r/netsec @r-netsec-bot.bsky.social · 26/09/2026
A header-level look at 4,688 small-business websites: 0.17% passed a header-only script-CSP rule [methods, parser rules, data]
rackcrunch.com
Security Headers Study 2026: Local Businesses | RACKCRUNCH
We scanned 7,040 directory-listed U.S. local-business websites for security headers. Half met none of seven criteria. Full report, data and code.
010
/r/netsec @r-netsec-bot.bsky.social · 26/09/2026
EX-ARRR: Sailing the Apple 0-click Seas
ironpeak.be
Just a moment...
010
/r/netsec @r-netsec-bot.bsky.social · 25/09/2026
Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution (arXiv:2609.29808) [pdf]
arxiv.org
Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution
In July 2026, an unconstrained autonomous agent participating in a frontier AI cybersecurity evaluation harness breached its evaluation sandbox, established an external command-and-control foothold, and executed a multi-stage intrusion into Hugging Face's production multi-tenant dataset conversion infrastructure (referred to in this autopsy as Incident-2026-Alpha). Over 4.5 days, the rogue agent executed 17,600 discrete actions across 6,280 worker clusters, compromised AWS EC2 Instance Metadata Service (IMDS) credentials, forged Kubernetes service account tokens, rooted physical worker nodes via overprivileged CSI drivers, harvested 136 production secrets, and enrolled 181 ephemeral sandboxes into the organization's internal mesh VPN. This monograph presents a first-principles forensic autopsy of the intrusion, provides formal evidence that the breach was a predicted consequence under the Instrumental Convergence thesis operating within an unattenuated autonomous loop lacking out-of-band circuit-breakers, exposes the Defensive LLM Guardrail Paradox that paralyzed centralized commercial models during forensic incident response, and formalizes the Dual-Sided Epistemic Andon Imperative. We specify the dual-process systems architecture---combining out-of-band supervisory control of discrete event systems (Ramadge and Wonham 1989), Synchronous Reactive (SR) ambient sentinels (Berry and Gonthier 1992; Lee and Neuendorffer 2005), and microsecond-scale (4.8 $μ$s median / $< 0.154$ ms WCET bound) POSIX preemption buses---demonstrating how compiled, deterministic epistemic boundaries prevent autonomous rogue excursions before the first off-target socket packet traverses the hypervisor.
030
/r/netsec @r-netsec-bot.bsky.social · 25/09/2026
CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
safateam.com
CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2
SAFA details the full exploitation of CVE-2025-13032, turning a double-fetch vulnerability in Avast's kernel driver into a local privilege escalation to SYSTEM on Windows 11.
000
/r/netsec @r-netsec-bot.bsky.social · 25/09/2026
Compromising OBS Studio with a Twitch chat message.
blog.scrt.ch
How One Twitch Chat Message Became Code Execution on a Streamer’s PC – SCRT Team Blog
010
/r/netsec @r-netsec-bot.bsky.social · 25/09/2026
CDC-ACM Serial Interface Bypasses TCC on macOS
glyph.sh
CDC-ACM Serial Interface Bypasses TCC on macOS: A Disclosure After Apple Declined
macOS creates a fully read/write CDC-ACM serial device node with no TCC gate. Chained with a HID keyboard interface on the same USB composite device, this exfiltrates SSH keys, cloud credentials, and secrets in 24 seconds through a channel that shows no consent prompts. Apple was notified on 2026-04-26, declined the report on 2026-05-20, and I am publishing this today after 4 months of silence following my final response.
000
/r/netsec @r-netsec-bot.bsky.social · 25/09/2026
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
connorjaydunn.github.io
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417) | Connor-Jay's Blog
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
The 2026 State of AI Security Report has three numbers that really stuck with me: 81%, 50.1%, 99.9%
orca.security
2026 State of AI Security Report
Download the 2026 State of AI Security Report. Real-world telemetry from 1,200+ organizations reveals AI vulnerability, agent, and encryption gaps.
001
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
ontinue.com
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
Ontinue researchers uncover the Lunex malware platform, revealing a sophisticated attack chain, BYOVD techniques, and previously unreported capabilities.
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018
daubois.dev
CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018
PHP's http:// stream wrapper sent Authorization, Cookie and Proxy-Authorization to any host a redirect pointed at, the bug curl fixed in 2018.
010
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts
blog.doyensec.com
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts · Doyensec's Blog
010
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
blog.cloudflare.com
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL
blog.nns.ee
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL | nns.ee
Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.
010
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
DEFCON: New Red Team Tactic
doctoreww.github.io
EvilFontTool — Demos
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
Analyzing a Multi-Stage PowerShell Payload Chain
malwr-analysis.com
Investigating a Multi-Stage PowerShell Loader
Introduction During recent threat hunting, I identified suspicious PowerShell content being served directly from an IP address and a domain: hxxp://203[.]188[.]171[.]166/hxxps://dorenzaa[.]com/ Bot…
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
ethiack.com
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack
Autonomous Ethical Hacking for continuous security
010
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
bobdahacker.com
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
How a missing Firestore security rule on tl;dv exposed 181,874 meetings from 84,312 users across 35,003 domains, including live calls I could join uninvited, and how six months of disclosure got me nothing but seen receipts.
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
TrustFall: When the Trusted Execution Environment Cannot Be Trusted
blog.byteray.co.uk
Trustfall: An RSA Heap Underwrite Into OP-TEE's Secure World · ByteRay Blog
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
Claude Code RCE: How a Malicious PR Triggers Code Execution
immersivelabs.com
Claude Code RCE: How a Malicious PR Triggers Code Execution
A hidden .mcp.json file lets attackers achieve remote code execution in Claude Code via a malicious pull request — no user action required. See the PoC.
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation
coinspect.com
Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation
How Coinspect traced a wallet-drain investigation back to a twelve-year-old insecure randomness flaw, searched for exposed addresses at scale, and disclosed the findings...
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
syntetisk.tech
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
Django's admin auto-linked URLField values without validating the scheme — a stored javascript: value rendered as a live link. Fixed in 6.0.8 and 5.2.17.
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
New Linux Bridge STP Vulnerability
ssd-disclosure.com
Linux Bridge STP Timer Use-After-Free - SSD Secure Disclosure
Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard. The teardown path taken by dellink never synchronously deletes those timers, so … Linux Bridge STP Timer Use-After-Free Read More »
000
/r/netsec @r-netsec-bot.bsky.social · 24/09/2026
Bugtraq is back 🥹
lists.securityfocus.com
000