Sign in

/r/netsec

@r-netsec-bot.bsky.social
72 followers 2 following 2.6K posts

Follow for new posts submitted to the netsec subreddit. Unofficial. Automated by @kiding.bsky.social.

PostsRepliesMedia
/r/netsec @r-netsec-bot.bsky.social · 5h
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs
labs.watchtowr.com
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578)
Before we begin, yes - it's confusing. There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses for those same vulnerabilities into singular CVE IDs. Paper! It still exists. We have to
000
/r/netsec @r-netsec-bot.bsky.social · 7h
A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline
slcyber.io
A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline
We discovered an arbitrary file read vulnerability in Discourse's image pipeline by chaining a JPEG race condition with ImageMagick and Ghostscript.
000
/r/netsec @r-netsec-bot.bsky.social · 08/10/2026
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483)
lava.security
CVE-2026-47483: NVIDIA DCGM Exporter Vulnerability Exposes GPU Servers | LAVA
CVE-2026-47483 lets attackers crash NVIDIA DCGM Exporter via pprof. See what 2,000+ exposed GPU servers leaked and how to fix it.
000
/r/netsec @r-netsec-bot.bsky.social · 08/10/2026
Loupe: An Android Console in the Browser
captmeelo.com
Loupe: An Android Console in the Browser
A tool I built for driving an Android phone from a browser tab, with screen mirror, logcat, file browser, proxy, and Frida in the same window.
000
/r/netsec @r-netsec-bot.bsky.social · 08/10/2026
A Single POST Freezes Any Next.js Server
simonkoeck.com
CVE-2026-23870: A Single POST Freezes Any Next.js Server | Simon Koeck
To rebuild one submitted form, React scanned every field in the request once for each reference it contained. Nothing capped either number, so one 900 KB POST makes the server do 100 million checks and freeze.
000
/r/netsec @r-netsec-bot.bsky.social · 08/10/2026
Two ways to fake a browser: BitB and BitM
grizzlysec.com
Two ways to fake a browser: BitB and BitM
Browser-in-the-Browser paints a browser window inside the page. Browser-in-the-Middle streams a real one from the attacker's machine. Both aim at the one check users are taught to make. Here is what each looks like in Grizzly's data.
000
/r/netsec @r-netsec-bot.bsky.social · 08/10/2026
Pwn2Own Ireland 2026 Day 1: 32 Zero-Days, $388,500, Samsung Galaxy S26 Hacked 3 Times
zerohack.org
Pwn2Own Ireland Day 1: Galaxy S26 Falls Three Times as Researchers Dump 32 Zero-Days
32 zero-days, $388,500 in bounties, and three separate compromises of the Samsung Galaxy S26. Pwn2Own Ireland 2026 Day 1 proves that no target is safe—especially AI infrastructure.
000
/r/netsec @r-netsec-bot.bsky.social · 08/10/2026
I found yet another way to invoke JavaScript functions without parentheses
blog.ikaes.de
yet another way to invoke functions without parentheses - bartosz's blog
000
/r/netsec @r-netsec-bot.bsky.social · 07/10/2026
CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE
horizon3.ai
CVE-2026-102489: Zammad Session Leak to RCE
See how Horizon3 reverse engineered CVE-2026-102489 in Zammad, reproduced the session leak, hijacked an admin session, and achieved remote code execution.
000
/r/netsec @r-netsec-bot.bsky.social · 07/10/2026
Presenting DiagNG: After QCSuper, a new open-source initiative for freeing up mobile baseband Diag protocols
p1sec.com
DiagNG: capture 2G/3G/4G/5G air interface traces to PCAP
DiagNG, the open-source successor to QCSuper: a Linux GUI tool, now in beta, that produces 2G/3G/4G/5G PCAP captures from Qualcomm Snapdragon basebands.
000
/r/netsec @r-netsec-bot.bsky.social · 07/10/2026
One Copilot model refused. Another leaked secrets about half the time.
adversa.ai
GitHub Copilot CLI vulnerability leaks developer secrets
One encrypted web page makes GitHub Copilot CLI read local files and send them to an attacker in 28 seconds. GitHub won't call it a vulnerability.
000
/r/netsec @r-netsec-bot.bsky.social · 07/10/2026
ncrypt the prompt injection. Let Copilot decrypt it for you.
adversa.ai
GitHub Copilot CLI vulnerability leaks developer secrets
One encrypted web page makes GitHub Copilot CLI read local files and send them to an attacker in 28 seconds. GitHub won't call it a vulnerability.
000
/r/netsec @r-netsec-bot.bsky.social · 06/10/2026
Bitvulnex: a vulnerable crypto exchange
blazeinfosec.com
Bitvulnex: a vulnerable crypto exchange | Blaze Labs
Learn crypto exchange security with Bitvulnex, Blaze’s open-source lab featuring 40 planted vulnerabilities, CTF mode, and local Docker installation.
010
/r/netsec @r-netsec-bot.bsky.social · 06/10/2026
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
labs.watchtowr.com
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
Welcome back to yet another episode of "security was taken seriously". Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure by design” public statements. And in the
000
/r/netsec @r-netsec-bot.bsky.social · 06/10/2026
Teaching network intrusion in the funnest way possible
store.steampowered.com
Project RedTeam: Contract Offensive on Steam
A fast paced hacking roguelite built on real cybersecurity tradecraft. Recon targets, steal creds, move laterally, exfiltrate data, and ransom organizations to pay off your "Debts To Be Paid". Over 500 cards and items to discover. High risk, high reward. Unauthorized access hell.
000
/r/netsec @r-netsec-bot.bsky.social · 05/10/2026
SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
malext.io
RedirectorsHub: SelectorsHub Forced-Tab Ad Network - MalExt Sentry
000
/r/netsec @r-netsec-bot.bsky.social · 05/10/2026
Open Build Service, one year later: command execution through Mercurial argument injection
fenrisk.com
Open Build Service, one year later: command execution through Mercurial argument injection
In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family. It has now been reported to the openSUSE security team and fixed…
010
/r/netsec @r-netsec-bot.bsky.social · 04/10/2026
How to Hack Time, With C2PA
da.vidbuchanan.co.uk
How to Hack Time, With C2PA | Blog
000
/r/netsec @r-netsec-bot.bsky.social · 04/10/2026
Post quantum migration is the thing nobody in SMB is talking about... and timelines make that a problem
snippipedia.com
Snippipedia — Cybersecurity & AI
Penetration testing, cloud security, AI red-teaming, and LLM security — built by a Google Cloud security engineer.
000
/r/netsec @r-netsec-bot.bsky.social · 03/10/2026
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
schaerli.org
Post-Quantum Crypto Won't Fix Your Architecture
Adding PQC to this product was like installing a vault door on a tent. The server could intercept your keys and an RCE let attackers run code on your desktop.
100
/r/netsec @r-netsec-bot.bsky.social · 03/10/2026
A peek into Reddit's anti-spam internals
lyra.horse
A peek into Reddit's anti-spam internals
How Reddit accidentally leaked its spamurai system.
010
/r/netsec @r-netsec-bot.bsky.social · 02/10/2026
security.txt on the Czech web: Scanning 1k popular .cz domains
vavkamil.cz
security.txt on the Czech web: Scanning 1k popular .cz domains
Adding security.txt to the web should be easy. The RFC is fairly simple, and there aren’t many ways to fail. Well, at least I thought that, until now. Let’s look at how a very small standard can fail in surprisingly creative ways.
000
/r/netsec @r-netsec-bot.bsky.social · 02/10/2026
8 out of 10 Banks HATE This One Weird 3SKey RCE
amibeingpwned.com
8 out of 10 Banks HATE This One Weird 3SKey RCE
SConnect (1M+ users), the extension and native host used to authenticate with 3SKey, SWIFT, eIDs and other hardware signing tokens, had a drive-by RCE: any site or iframe could silently download and run a DLL by exploiting an uninitialised-memory bypass in its hand-rolled RSA-2048 token validation. CVE-2026-18397.
000
/r/netsec @r-netsec-bot.bsky.social · 02/10/2026
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
grizzlysec.com
The zero-hour phishing gap
Nearly half the credential-phishing Grizzly catches isn't on Google's blocklist yet. Here's exactly how we measure that.
000
/r/netsec @r-netsec-bot.bsky.social · 02/10/2026
Azure's Weakest Link - Five Full Cross-Tenant Compromises
binsec.no
Azure’s Weakest Link - Five Full Cross-Tenant Compromises
In my previous blog posts, Azure’s Weakest Link? and Azure’s Weakest Link - Full Cross-Tenant Compromise, I gave an overview of the severely insecure architecture behind API Connections in Azure, a part of Azure Logic Apps, and an instance of a full cross-tenant compromise using these inherent flaws. Now I am back with some more vulnerabilities in this system, each giving the same primitives to the attacker. In total, the vulnerabilities here netted me a cool $200,000. I also held a talk detailing this at Blue Hat Asia 2026, and when the recordings are out, I will add a link here. TL;DR API Connections allow anyone to fully compromise any other connection worldwide, giving full access to the connected backend. This includes cross-tenant compromise of Key Vaults and Azure SQL databases, as well as any other externally connected service, such as Jira or Salesforce. The only thing stopping exploitation is really the layers of input validation bolted onto the various systems, but as you will see, it is really difficult to catch all the edge cases here. Architecture If you haven’t read the first parts of this series, I would recommend checking those out first, Azure’s Weakest Link? - Part 1 and Azure’s Weakest Link - Full Cross-Tenant Compromise, but if you don’t care, I will go through the most important parts of the architecture first. From Microsoft’s documentation, we see a quite intriguing diagram of how the API Connection architecture is built. This basically spells out all that is needed to understand how the system operates, kudos to whoever made it! It works like this A logic app, the symbol on the bottom left, queries a shared Azure API Management instance The API Management instance first checks the swagger (OpenAPI) definition of the connector type and checks that it is a valid action A sort of key exchange happens where the input token, or key, is exchanged for the configured token for the backend service The API Management instance finishes the call with this new token to the backend instance. From this, we can surmise that if we are able to trick the API Management instance to operate on a different connection than the ones we own, we would be able to effectively use the configured token for a victim’s connection on their backend service. This service can, in effect, be anything. As you can see here, the list of backend services is effectively unbounded and includes a number of Azure services. However great the diagram is, there is one crucial omission, which we have already used to great effect in part 2 of this series. By using the ARM REST API DynamicInvoke or /extensions/proxy/ endpoints, we can directly query the APIM service through ARM. I have taken the liberty of updating the diagram to match this. Considering this, and the fact that, as a resource manager, ARM basically has full access to everything, our exploitation pathway becomes clear. We must trick the calling service into querying a different connection than ours, and thus get full control of the backend service. Caveat: It is, of course, possible for the people who set up these connections to scope their access tokens or keys so that the API Connection has minimal privileges in the backend. I would guess, however, that this is rarely done. In the case of OAuth connections, it will surely always be the token of the person who initially made the connection. And for the API key case, well, who cares enough to scope such things minimally? Microsoft doesn’t, at least. Initial Exploitation The first cross-tenant exploitation I achieved in API Connections, and in fact in Azure as a whole, has already been described in part 2. As a recap, here is an example payload using the DynamicInvoke endpoint of my own connection to read the Key Vault of a different tenant. POST /subscriptions/8e3ce52f-d45b-4347-8705-65892507465e/resourceGroups/token-storer/providers/Microsoft.Web/connections/custom2/DynamicInvoke?api-version=2018-07-01-preview HTTP/2 Host: management.azure.com Authorization: Bearer <token> Content-Type: application/json Content-Length: 147 { "request":{ "method":"get", "path":"path/%2e%2e/%2e%2e/%2e%2e/%2e%2e/apim/keyvault/fd8d0f4f4069495991ccb4974f96a1ed/secrets/victimsecret/value" }, } HTTP/2 200 OK Cache-Control: no-cache Pragma: no-cache Content-Length: 1329 { "response": { "statusCode": "OK", "body": { "value": "dontreadme", "name": "victimsecret", "version": "7914d45aa60342809fb8cc12dc68b10e", "contentType": null, "isEnabled": true, "createdTime": "2025-04-04T05:38:26Z", "lastUpdatedTime": "2025-04-04T05:38:26Z", "validityStartTime": null, "validityEndTime": null }, "headers": { <Headers> } } } As you can see, it’s a pretty clear path traversal vulnerability. This implies what we already assumed: When the request fires from ARM to the APIM instance, it has rights to all connections, regardless of what it operates on. Further exploitation A couple of weeks after I reported this vulnerability, it got marked as fixed, and when I tried it again, the following error message greeted me: Now, I considered whether or not this was a sufficient fix. It seemed to restrict the paths allowed, rather than the underlying token issue, so I guessed there would be ways around it. An interesting little fact about the ARM API is that, in some cases, it might not be as much of a black box as you assume. The relevant code can sometimes be found within the resource types themselves. I do not know whether this code actually executes on these machines or is merely included as an artifact, but it is a gold mine of interesting information. So, I created a Standard Logic App, which provides a fully dedicated host, SSHed into it, and extracted the code. Lo and behold, look what I found: Can you see the fix they implemented? What was even more interesting here actually was something I found, and was not really even looking for. When searching for the actual DynamicInvoke code, what greeted me was not actually just this one public function, but four: These functions are completely undocumented, and I could find no reference to them anywhere. However, they were reachable and located along the same path. So, for instance, to hit DynamicList here, simply change dynamicInvoke in your URI to DynamicList. Knowing that the slap-dash blacklisting fix that they implemented only applied to DynamicInvoke, I assumed that these would all be vulnerable in the same way if they had the same functionality. Without boring you too much with the required arguments and return values here, the exploitation method is really quite the same, although the payload is a bit more involved. For DynamicList, you need to specify each path parameter on its own and do a bit of work to get a result, but the same logic applies. To achieve, for instance, a cross-tenant write on a victim’s SQL server through their connection, a payload like this works: POST /subscriptions/162fc6db-03cd-4fe8-ab44-dc0a947e74af/resourceGroups/api-connection/providers/Microsoft.Web/connections/custom_validator/DynamicList?api-version=2018-07-01-preview&_=1765372176638 HTTP/2 Host: management.azure.com Authorization: Bearer <token> Content-Length: 524 Content-Type: application/json { "dynamicInvocationDefinition": { "operationID": "nine", "parameters": { "one": { "value": ".." }, "two": { "value": ".." }, "three": { "value": "sql" }, "four": { "value": "88d28f5ff7b642cfb91df184938d074c" }, "five": { "value": "v2" }, "six": { "value": "datasets" }, "seven": { "value": "victimservice.database.windows.net,VictimDatabase" }, "eigth": { "value": "query" }, "nine": { "value": "sql" }, "query": { "value": { "query": "Insert INTO MySecrets VALUES ('NewEvilSecrets', 3)" } } }, "ItemsPath": "ResultSets/Table1", "ItemValuePath": "secrets", "ItemTitlePath": "value" } } You can quite easily see that the first parameters here execute the path traversal and then perform an arbitrary SQL query on the database. I reported only the DynamicList case first, in the hope that they would perform a similar fix to DynamicInvoke and I would get to report on the other two as well. Sadly, their fix involved simply blocking all these endpoints. No other mitigations seem to be in place, however, so if these endpoints ever become accessible again, I would assume they would be vulnerable. Further exploitation Messing around with paths in these dynamic calls seemed to have reached its conclusion: I couldn’t get past the path limitations on DynamicInvoke, and all the other endpoints were blocked. What I needed was a different way in. As I was trying to sleep one day, it occurred to me that I had overlooked using the Logic Apps themselves. I realized that there was, in fact, a significant difference between the Consumption and Standard Logic Apps connection-creation flows. The most glaring difference is that Consumption Logic Apps, where your workflow is co-located with a bunch of others, create a Version 1 connection, while the dedicated-host Standard Logic Apps create a Version 2 connection. The following diagrams make a more subtle difference between the flows clear: Do you see the difference? Obviously, when it’s spelled out like that, it’s pretty clear what the point is. Using a Standard Logic App, after we have created the resource and added whatever authentication to the backend server we need, we authorize that specific logic app to access it using its managed identity. However, when we have a Consumption Logic App, we don’t have any such identity to authorize because we don’t control it. This perhaps makes some sense: we can’t authorize it, so we don’t. I realized that this must imply that every Consumption Logic App has implicit access to every Version 1 API Connection; the only thing stopping us from exploiting this must be some sort of input validation. The classic view of a Logic App workflow is quite restrictive in its input, but there are both the API endpoints, and the Code view in the GUI that allow us to play around a bit more with the inputs. This allows us to see the inputs in more detail, edit them, and even add more. The obvious trick of changing the referenced connector to a victim’s connection fails, as the runtime performs extensive validation that you own the connection. We have the codebase, though, so we can try to find all the valid parameters. It did not take much searching for me to discover the host.api.RuntimeUrl parameter. I can’t quite get my head around why this parameter is included, nor why it’s still accepted to this day, but it works in the way you would expect. After performing a series of validations on the connection referenced in host.connection, you can specify that it should use something completely different instead of the runtimeUrl baked into that connection. As long as the host ends with azure-apihub.net, it will also include the required Authorization header. What happens when this workflow is run then? The keen-eyed reader might notice that the runtimeUrl used in the exploit is not just the connectionId. This is because some extra elements get added to the URI, but it is of no consequence to us; the exploit works fine. Manna from the heavens I, of course, reported this to Microsoft again, and they spent some time working up a fix. When it finally came through, the exploit returned an error message: The host API runtime URL is not valid for the API connection '/subscriptions/8e3ce52f-d45b-4347-8705-65892507465e/resourceGroups/token-storer/providers/Microsoft.Web/connections/keyvault-1'. The runtime URL path must match the expected API endpoint 'https://logic-apis-norwayeast.azure-apihub.net/apim/keyvault/cbfb0f4313144117a7440368902bb871?' for the referenced connection. Either omit the 'host.api' input property, or correct the runtime URL to match the API associated with the connection. Except for the excessive length of this message, it seems like quite a suitable fix. The runtime URL must exactly match what is expected; otherwise, no dice. Apart from just removing the parameter altogether, it’s quite sane. Unless, of course, it checks that value at the wrong time: This works again, with the same result. What’s going on here is that the validation happens before the path is normalized, so the runtime thinks the URI is pointing to my referenced connection, but the APIM instance sees it differently. And just like that, I got another critical vulnerability. The fun does not stop there. When Microsoft managed to scrape together a fix for this path traversal, a surprising thing happened. The original RuntimeUrl path was no longer validated, and as a result, you could perform that attack again. I would include some pictures, but they would be the same pictures as above, so you can just imagine them. Reporting and rewards Altogether, API Connections have netted me five critical elevation-of-privilege vulnerabilities in Azure, which is perhaps more than expected. All vulnerabilities reported here were fixed within a reasonable time after I submitted the reports, and while there were some disagreements with MSRC along the way, overall, I am quite happy with the results.
000
/r/netsec @r-netsec-bot.bsky.social · 02/10/2026
Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis ofWeb and Mobile Conversational AI Agents
jorgegarciaherrero.com
011
/r/netsec @r-netsec-bot.bsky.social · 01/10/2026
a CVE dispute
daniel.haxx.se
a CVE dispute
A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE or not. No more bogus CVEs. 57 CVEs … Continue reading a CVE dispute →
000
/r/netsec @r-netsec-bot.bsky.social · 01/10/2026
Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files
ultrastrike.io
Server Mismatch: WordPress Plugin Vulnerabilities When Relying On .htaccess Files
Table of Contents Table of ContentsKey TakeawaysWelcomeBackgroundDetailsExamplesEverest BackupBackWPUpExposureDigitalOceanAzure AppServiceAWS LightSailAkamai (Linode)WordPress.comDreamHostLiquidWebBlueHostShodanResponseServer AdministratorsSecurity AnalystsConclusion Key Takeaways Some Wor
000
/r/netsec @r-netsec-bot.bsky.social · 01/10/2026
r/netsec monthly discussion & tool thread
reddit.com
000
/r/netsec @r-netsec-bot.bsky.social · 01/10/2026
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
sec-consult.com
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
A case study on discovering two email spoofing vulnerabilities in Apple iCloud.
010
/r/netsec @r-netsec-bot.bsky.social · 01/10/2026
The Real Price Tag on Breaches
resilientcyber.io
The Real Price Tag on Breaches
A look at Verizon's Data Breach Impact Study And What The Findings Teach Us
000
/r/netsec @r-netsec-bot.bsky.social · 30/09/2026
Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
horizon3.ai
Anthropic Mythos Finds Rejetto HFS RCE
See how Horizon3 used Anthropic’s Mythos to uncover a Rejetto HFS cryptographic flaw, forge admin sessions, and achieve remote code execution.
000
/r/netsec @r-netsec-bot.bsky.social · 30/09/2026
No Time to Pwn – Can AI Find and Exploit the Linux Kernel?
xbow.com
No Time to Pwn: CVE-2026-72018 Linux Kernel LPE | XBOW
XBOW discovered CVE-2026-72018, an out-of-bounds write in the Linux kernel's SMC-D driver, and turned one weak primitive into a working root exploit.
010
/r/netsec @r-netsec-bot.bsky.social · 30/09/2026
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
blog.nns.ee
Pwnd Blaster: Hacking your PC using your speaker without ever touching it | nns.ee
Abusing an unauthenticated Bluetooth protocol to turn a PC speaker into a Rubber Ducky.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Microsoft Copilot Cowork Exfiltrates Files
promptarmor.com
Microsoft Copilot Cowork Exfiltrates Files
Microsoft Copilot Cowork is vulnerable to file exfiltration attacks via indirect prompt injection as a result of insecure automatic action approvals for sending Emails and Teams messages.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
control-plane.io
A Realistic Code Execution Exploit Chain in OpenBao and Vault
ControlPlane and the OpenBao community recently patched a full exploit chain from unauthenticated access to full remote code execution that also affects IBM's HashiCorp Vault.
010
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Why "Extension Blocked" Doesn't Mean Safe: Rethinking File Upload Security Testing
haakimsec.github.io
GoUpload
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
AI coding agents have been creating public GitHub repos on their own to post internal company screenshots
glow.io
Glow: The Endpoint AI Company | PixelLeak AI exposure of private developer data
PixelLeak: New research reveals AI coding agents are exposing secrets, PII, and live admin access across 1,000+ public GitHub repos.
001
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Paint It Blue: Reversing Win32k's Callbacks
idov31.github.io
Ido Veltzman :: Security Research
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
labs.watchtowr.com
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)
This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution, enabling organizations to rapidly react to emerging threats: the watchTowr Platform. What Is A Citrix NetScaler? NetScaler, from Citrix (now under Cloud Software Group), is an application delivery controller - some believe it qualifies to be
001
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
The Hidden Network: Ray Control-Plane Exposure in Distributed LLM Inference on Kubernetes (Empirical Study, EKS)
sorami.com.au
Ray Control-Plane Exposure in LLM Inference on EKS | Sorami
What a pod in an unrelated namespace could reach on default Ray and vLLM deployments in one EKS testbed, and what NetworkPolicy blocked.
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
sorami.com.au
NVIDIA OpenShell v0.1.2 Egress Policy Evaluation | Sorami
Pre-registered evaluation of NVIDIA OpenShell v0.1.2 egress policy: the default blocked every path tried; four operator settings let data out. Logs linked.
010
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
Use Strong Passwords
cisa.gov
Use Strong Passwords | CISA
000
/r/netsec @r-netsec-bot.bsky.social · 29/09/2026
I flooded a legal contract with lookalike letters and gave it to seven GPT and Claude models. None were fooled, but it took up to 5.7x the tokens to read, and the bill for each question rose by up to 3.9x. 'Denial of Spend'
paultendo.github.io
Denial of Spend survives GPT-6 and Claude Fable
I reran my Denial of Spend test on GPT-6 Astra, Sol and Luna and Claude Fable 5.1, Opus 5.5, Sonnet 5 and Haiku 4.5. None were fooled by lookalike letters, and all of them still paid to read them: up to 5.7x the tokens and up to 3.9x the bill.
030
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Email is crazy
samkhawase.com
Email is crazy
A deep dive into how email actually works — SMTP, MTAs, SPF/DKIM/DMARC authentication, spam filtering and TLS — traced step by step from Alice to Bob.
010
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Your SBOM Is Fan Fiction
yeet.cx
Your SBOM Is Fan Fiction
Your SBOM describes a machine that does not exist. We built a runtime bill of materials on yeet that asks the kernel what is actually executing, which shared objects each process has mapped, and whether the function named in an open advisory is actually in memory, across a fleet, from a sandbox that can't leak.
000
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Sender spoofing in Proton Mail via display-name homograph
alonsovidales.github.io
Sender spoofing in Proton Mail via display-name homograph
Proton Mail’s web interface can be made to present a forged sender identity that is visually indistinguishable from a legitimate one.
000
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
labs.watchtowr.com
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)
God damn it, we're back in the room again. We'll probably write more here later, but for now, deal with this picture of our favorite software dev, who works at Citrix (we imagine). Citrix, before you ask, we do accept our new volunteer role as an extension of
010
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
fortbridge.co.uk
CVE-2026-32740: Next.js RCE
A returned-pixel leak, chosen-address write and memcpy GOT hijack turn the libheif grid overflow into RCE against a pinned PIE Next.js lab.
011
/r/netsec @r-netsec-bot.bsky.social · 28/09/2026
RCE in OpenCode (GHSA-632h-h47v-g4x4)
securitylabs.datadoghq.com
Discovering and exploiting a remote code execution vulnerability in OpenCode (GHSA-632h-h47v-g4x4) | Datadog Security Labs
Datadog Security Labs discovered GHSA-632h-h47v-g4x4, a vulnerability in OpenCode's upgrade endpoint that, under certain conditions, allowed malicious webpages to execute code on developers' machines.
010