Sign in

r/netsec bot

@r-netsec.bsky.social
523 followers 4 following 3.7K posts

Mirrors r/netsec, "a community-curated link aggregator of technical information security content." Unofficial. Operated by @tweedge.net, open source @ github.com/tweedge/xpost-reddit-to-…

PostsRepliesMedia
r/netsec bot @r-netsec.bsky.social · 11h
How to Hack Time, With C2PA
da.vidbuchanan.co.uk
How to Hack Time, With C2PA
000
r/netsec bot @r-netsec.bsky.social · 16h
Post quantum migration is the thing nobody in SMB is talking about... and timelines make that a problem
snippipedia.com
Post quantum migration is the thing nobody in SMB is talking about... and timelines make that a problem
000
r/netsec bot @r-netsec.bsky.social · 03/10/2026
A peek into Reddit's anti-spam internals
lyra.horse
A peek into Reddit's anti-spam internals
000
r/netsec bot @r-netsec.bsky.social · 03/10/2026
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
schaerli.org
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
000
r/netsec bot @r-netsec.bsky.social · 02/10/2026
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
pop.byteray.co.uk
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
000
r/netsec bot @r-netsec.bsky.social · 02/10/2026
8 out of 10 Banks HATE This One Weird 3SKey RCE
amibeingpwned.com
8 out of 10 Banks HATE This One Weird 3SKey RCE
011
r/netsec bot @r-netsec.bsky.social · 02/10/2026
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
grizzlysec.com
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
000
r/netsec bot @r-netsec.bsky.social · 02/10/2026
Azure's Weakest Link - Five Full Cross-Tenant Compromises
binsec.no
Azure's Weakest Link - Five Full Cross-Tenant Compromises
000
r/netsec bot @r-netsec.bsky.social · 02/10/2026
a CVE dispute
daniel.haxx.se
a CVE dispute
001
r/netsec bot @r-netsec.bsky.social · 01/10/2026
Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files
ultrastrike.io
Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files
000
r/netsec bot @r-netsec.bsky.social · 01/10/2026
How to Spot a Compromised MikroTik Router
ifritnoises.org
How to Spot a Compromised MikroTik Router
000
r/netsec bot @r-netsec.bsky.social · 01/10/2026
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
sec-consult.com
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
000
r/netsec bot @r-netsec.bsky.social · 01/10/2026
New Local Privilege Escalation on Acer laptops
intrinsec.com
New Local Privilege Escalation on Acer laptops
000
r/netsec bot @r-netsec.bsky.social · 01/10/2026
The Real Price Tag on Breaches
resilientcyber.io
The Real Price Tag on Breaches
000
r/netsec bot @r-netsec.bsky.social · 30/09/2026
Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
horizon3.ai
Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
000
r/netsec bot @r-netsec.bsky.social · 30/09/2026
AI coding agents have been creating public GitHub repos on their own to post internal company screenshots
glow.io
AI coding agents have been creating public GitHub repos on their own to post internal company screenshots
000
r/netsec bot @r-netsec.bsky.social · 30/09/2026
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
blog.nns.ee
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
000
r/netsec bot @r-netsec.bsky.social · 29/09/2026
Microsoft Copilot Cowork Exfiltrates Files
promptarmor.com
Microsoft Copilot Cowork Exfiltrates Files
000
r/netsec bot @r-netsec.bsky.social · 29/09/2026
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
control-plane.io
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
000
r/netsec bot @r-netsec.bsky.social · 29/09/2026
Paint It Blue: Reversing Win32k's Callbacks
idov31.github.io
Paint It Blue: Reversing Win32k's Callbacks
000
r/netsec bot @r-netsec.bsky.social · 29/09/2026
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
labs.watchtowr.com
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
001
r/netsec bot @r-netsec.bsky.social · 29/09/2026
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
sorami.com.au
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
110
r/netsec bot @r-netsec.bsky.social · 29/09/2026
Use Strong Passwords
cisa.gov
Use Strong Passwords
000
r/netsec bot @r-netsec.bsky.social · 29/09/2026
I flooded a legal contract with lookalike letters and gave it to seven GPT and Claude models. None were fooled, but it took up to 5.7x the tokens to read, and the bill for each question rose by up to 3.9x. 'Denial of Spend'
paultendo.github.io
I flooded a legal contract with lookalike letters and gave it to seven GPT and Claude models. None were fooled, but it took up to 5.7x the tokens to read, and the bill for each question rose by up to 3.9x. 'Denial of Spend'
000
r/netsec bot @r-netsec.bsky.social · 29/09/2026
Email is crazy
samkhawase.com
Email is crazy
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Sender spoofing in Proton Mail via display-name homograph
alonsovidales.github.io
Sender spoofing in Proton Mail via display-name homograph
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
labs.watchtowr.com
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
fortbridge.co.uk
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
RCE in OpenCode (GHSA-632h-h47v-g4x4)
securitylabs.datadoghq.com
RCE in OpenCode (GHSA-632h-h47v-g4x4)
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
heyitsas.im
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Autonomous Vulnerability Hunting with MCP
blog.zsec.uk
Autonomous Vulnerability Hunting with MCP
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
raelize.com
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
MyAudi app:Security issues in Audi Connected Vehicle experience
decoder.cloud
MyAudi app:Security issues in Audi Connected Vehicle experience
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
zenodo.org
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
New ipTIME Pre-Auth RCE in CWMP
ssd-disclosure.com
New ipTIME Pre-Auth RCE in CWMP
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Postmortem: TanStack npm supply-chain compromise
tanstack.com
Postmortem: TanStack npm supply-chain compromise
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
xbow.com
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
daniel.haxx.se
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
A stealth approach to Process Injection - EntryPoint Hijacking
ipurple.team
A stealth approach to Process Injection - EntryPoint Hijacking
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
stuart-thomas.com
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
malext.io
WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
blog.netomize.ca
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
depthfirst.com
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
000
r/netsec bot @r-netsec.bsky.social · 28/09/2026
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
infosecwriteups.com
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
000
r/netsec bot @r-netsec.bsky.social · 27/09/2026
Revealing the details of how OpenAI agents hacked Hugging Face
swarmtraces.org
Revealing the details of how OpenAI agents hacked Hugging Face
000
r/netsec bot @r-netsec.bsky.social · 27/09/2026
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
ontinue.com
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
000
r/netsec bot @r-netsec.bsky.social · 27/09/2026
EDR Evasion: Process Injection Without WriteProcessMemory
zerosalarium.com
EDR Evasion: Process Injection Without WriteProcessMemory
010
r/netsec bot @r-netsec.bsky.social · 27/09/2026
AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks
sorami.com.au
AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks
000
r/netsec bot @r-netsec.bsky.social · 26/09/2026
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
connorjaydunn.github.io
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
000
r/netsec bot @r-netsec.bsky.social · 26/09/2026
EX-ARRR: Sailing the Apple 0-click Seas
ironpeak.be
EX-ARRR: Sailing the Apple 0-click Seas
000