Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
https://ift.tt/r9KNwBL
Submitted June 30, 2026 at 03:37PM by moltenbit-r
via reddit https://ift.tt/sbVvhDi
https://ift.tt/r9KNwBL
Submitted June 30, 2026 at 03:37PM by moltenbit-r
via reddit https://ift.tt/sbVvhDi
moltenbit
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform
A white-box audit of the end-to-end encrypted booking platform OpenReception found 16 vulnerabilities, four of them critical.
Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website run a drive-by RCE. CVSS 9.3
https://ift.tt/JoyQORH
Submitted June 30, 2026 at 05:02PM by acorn222
via reddit https://ift.tt/I8K6VwN
https://ift.tt/JoyQORH
Submitted June 30, 2026 at 05:02PM by acorn222
via reddit https://ift.tt/I8K6VwN
Amibeingpwned
Trusted by NVIDIA, Amazon and Banks, This Extension Let Any Website Run Code on Your PC
Signer.Digital's browser extension and its native helper turned a path-traversal bug into drive-by remote code execution on Windows. Any web page you visited could load an attacker DLL into a process on your machine, then escalate to administrator with a…
DHIS2 (used across 80+ countries) ships with hardcoded default admin credentials and no forced password change.
https://ift.tt/8S0VLmJ
Submitted June 30, 2026 at 08:21PM by Hadsa_CounterStrike
via reddit https://ift.tt/IKJrXqD
https://ift.tt/8S0VLmJ
Submitted June 30, 2026 at 08:21PM by Hadsa_CounterStrike
via reddit https://ift.tt/IKJrXqD
Scrutora
The Health Data Platform Deployed Across 80+ Countries Ships with No Forced Password Change
The world's largest health information platform ships with default admin credentials and never forces a password change. 90 days of responsible disclosure, no substantive response.
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
https://ift.tt/MQp09xX
Submitted July 1, 2026 at 01:10AM by dx7r__
via reddit https://ift.tt/plkzcX5
https://ift.tt/MQp09xX
Submitted July 1, 2026 at 01:10AM by dx7r__
via reddit https://ift.tt/plkzcX5
watchTowr Labs
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Well, well, well - once again, the cat has dragged us in and spat us out.
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into…
Today, we find ourselves questioning the reality we sit within. Must it be so predictable, and why us? “But watchTowr, what do you mean?”
Well, if you’re here, you likely fit into…
I open-sourced a personal project called Bomly and would appreciate feedback from netsec/AppSec folks
https://ift.tt/cdyUAn4
Submitted July 1, 2026 at 05:16AM by Pleasant-Ad192
via reddit https://ift.tt/y7ZEda0
https://ift.tt/cdyUAn4
Submitted July 1, 2026 at 05:16AM by Pleasant-Ad192
via reddit https://ift.tt/y7ZEda0
bomly.dev
Announcing Bomly — Bomly Blog
A free, open-source CLI and GitHub Action for dependency diffs, SBOMs, vulnerability and license audits, and explaining why packages are present in your builds.
Symfony YAML Security Audit - Shielder
https://ift.tt/hSrE0ev
Submitted July 1, 2026 at 06:25PM by smaury
via reddit https://ift.tt/LThQcgY
https://ift.tt/hSrE0ev
Submitted July 1, 2026 at 06:25PM by smaury
via reddit https://ift.tt/LThQcgY
Shielder
Shielder - Symfony YAML Security Audit
Security audit of the Symfony YAML component, a PHP library to parse and dump YAML. Facilitated by the Open Source Technology Improvement Fund (OSTIF) and performed by Shielder.
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted July 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/0NGLIT8
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted July 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/0NGLIT8
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
https://ift.tt/cmKZnOk
Submitted July 1, 2026 at 06:44PM by Sandwich_1337
via reddit https://ift.tt/fGm4zhw
https://ift.tt/cmKZnOk
Submitted July 1, 2026 at 06:44PM by Sandwich_1337
via reddit https://ift.tt/fGm4zhw
Syntetisk
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
An unprivileged user inside a Lima QEMU guest could reach the root-owned guest-agent socket and run commands as root in the VM. Fixed in Lima v2.1.3.
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
https://ift.tt/cmKZnOk
Submitted July 1, 2026 at 08:22PM by Sandwich_1337
via reddit https://ift.tt/dNnlO2x
https://ift.tt/cmKZnOk
Submitted July 1, 2026 at 08:22PM by Sandwich_1337
via reddit https://ift.tt/dNnlO2x
Syntetisk
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
An unprivileged user inside a Lima QEMU guest could reach the root-owned guest-agent socket and run commands as root in the VM. Fixed in Lima v2.1.3.
Zero-Click Prompt Injection to RCE in Cursor IDE: DuneSlide
https://ift.tt/9VbJ65P
Submitted July 1, 2026 at 09:49PM by bscottrosen21
via reddit https://ift.tt/8KaOFYQ
https://ift.tt/9VbJ65P
Submitted July 1, 2026 at 09:49PM by bscottrosen21
via reddit https://ift.tt/8KaOFYQ
Detecting Agentic AI Threats in Claude: Sigma Rules and Correlation Detections for the Execution Layer
https://ift.tt/3Jdx7MO
Submitted July 1, 2026 at 11:02PM by TheAlphaBravo
via reddit https://ift.tt/cYvFfuA
https://ift.tt/3Jdx7MO
Submitted July 1, 2026 at 11:02PM by TheAlphaBravo
via reddit https://ift.tt/cYvFfuA
PaperMtn
Detecting Agentic Threats in Claude: Writing Rules on the Execution Layer
Detections for Claude on the execution layer: Sigma rules and a correlation runner that catch permission bypasses, rogue MCP servers, and more.
/r/netsec's Q3 2026 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted July 2, 2026 at 01:02PM by netsec_burn
via reddit https://ift.tt/OoTmaVK
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted July 2, 2026 at 01:02PM by netsec_burn
via reddit https://ift.tt/OoTmaVK
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
https://ift.tt/nXJsQE2
Submitted July 2, 2026 at 10:10PM by dx7r__
via reddit https://ift.tt/xoN3FfV
https://ift.tt/nXJsQE2
Submitted July 2, 2026 at 10:10PM by dx7r__
via reddit https://ift.tt/xoN3FfV
watchTowr Labs
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza)
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working.
Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to…
Before we begin our analysis, we want to be clear - given the number of vulnerabilities fixed (and some not mentioned..), we’ve struggled to…
FIFA was saved this time
https://ift.tt/nxPuGXb
Submitted July 2, 2026 at 09:44PM by scorp100n
via reddit https://ift.tt/gvpikw3
https://ift.tt/nxPuGXb
Submitted July 2, 2026 at 09:44PM by scorp100n
via reddit https://ift.tt/gvpikw3
Bobdahacker
I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.
How I found that anyone could register on FIFA's public Agent Platform, gain access to the Football Data Platform's Streaming Management panel, and get RTMP ingest URLs and stream keys for every live FIFA World Cup 2026 camera feed. I then spent hours calling…
Windows Service - Playbook & Detection Strategies
https://ift.tt/QmFYOXR
Submitted July 6, 2026 at 01:47PM by netbiosX
via reddit https://ift.tt/Vap0vqm
https://ift.tt/QmFYOXR
Submitted July 6, 2026 at 01:47PM by netbiosX
via reddit https://ift.tt/Vap0vqm
Purple Team
Windows Service
Windows Services are a common target for adversaries because they provide a reliable mechanism for executing code with elevated privileges, maintaining persistence, and blending malicious activity …
Playing Around With ADIDNS RPC Internals
https://ift.tt/CZXD2F4
Submitted July 6, 2026 at 02:55PM by luke-paradoxis
via reddit https://ift.tt/H1swEn8
https://ift.tt/CZXD2F4
Submitted July 6, 2026 at 02:55PM by luke-paradoxis
via reddit https://ift.tt/H1swEn8
Medium
Playing Around With ADIDNS RPC Internals
TL;DR: I ported the functionality of dnscmd.exe into (slightly) more OPSEC safe Beacon Object Files (BOFs) so you can get domain admin…
New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"
https://ift.tt/lenSwgj
Submitted July 6, 2026 at 08:00PM by OpenSecurityTraining
via reddit https://ift.tt/O3EuZps
https://ift.tt/lenSwgj
Submitted July 6, 2026 at 08:00PM by OpenSecurityTraining
via reddit https://ift.tt/O3EuZps
p.ost2.fyi
Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!
Understanding emulation and fuzzing from scratch!
Call Stack Spoofing via Runtime .pdata Parsing to Evade RtlVirtualUnwind
https://ift.tt/eWyO4Gw
Submitted July 7, 2026 at 04:52PM by Important_Map6928
via reddit https://ift.tt/GsZCvWY
https://ift.tt/eWyO4Gw
Submitted July 7, 2026 at 04:52PM by Important_Map6928
via reddit https://ift.tt/GsZCvWY
sibouzitoun.tech
SindriKit 1.3.0: Defeating EDR Telemetry with Dynamic Stack Spoofing
How SindriKit implements dynamic Fat Frame discovery and JMP-Trampolines to defeat RtlVirtualUnwind and call-stack telemetry.
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
https://ift.tt/ZEKX8jg
Submitted July 7, 2026 at 08:46PM by Aureliand
via reddit https://ift.tt/qTwM4Sh
https://ift.tt/ZEKX8jg
Submitted July 7, 2026 at 08:46PM by Aureliand
via reddit https://ift.tt/qTwM4Sh
noma.security
GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos - Noma Security
TL;DR: Noma Labs discovered a critical prompt injection vulnerability within GitHub’s new Agentic Workflows, allowing an unauthenticated attacker to silently pull data from private repositories by posting a crafted GitHub Issue in a public repository belonging…
A rule mapped to MITRE is not the same as real coverage
https://ift.tt/FloneTN
Submitted July 7, 2026 at 08:39PM by Ok_Attitude9264
via reddit https://ift.tt/uG2mbHE
https://ift.tt/FloneTN
Submitted July 7, 2026 at 08:39PM by Ok_Attitude9264
via reddit https://ift.tt/uG2mbHE
Socauthority
MITRE ATT&CK Detection Coverage: How to Map Your Rules and Find Real Gaps | SOCAuthority
How to map your existing detection rules to MITRE ATT&CK, find the gaps that actually matter, and prioritize what to build next. A practical guide from 10 years of SOC operations.
Bad Epoll: The bug missed by Mythos
https://ift.tt/U1xr4ZW
Submitted July 8, 2026 at 06:41AM by sanxiyn
via reddit https://ift.tt/OZSdTA6
https://ift.tt/U1xr4ZW
Submitted July 8, 2026 at 06:41AM by sanxiyn
via reddit https://ift.tt/OZSdTA6