[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
Submitted July 16, 2026 at 07:45PM by swinglr
via reddit https://ift.tt/iIXZKkf
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
Submitted July 16, 2026 at 07:45PM by swinglr
via reddit https://ift.tt/iIXZKkf
weirdmachine64.github.io
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking // weirdmachine64
RFC 8628's device authorization grant lets a TV or CLI
New Exploitable BOLA Found in Immich (self-hosted media platform)
https://ift.tt/rA93gJd
Submitted July 16, 2026 at 10:58PM by EscapeSecurity
via reddit https://ift.tt/THlS0Z1
https://ift.tt/rA93gJd
Submitted July 16, 2026 at 10:58PM by EscapeSecurity
via reddit https://ift.tt/THlS0Z1
Escape - Application Security & Offensive Security Blog
How Escape Bypassed Immich's Locked Folders And Found a BOLA
How the Escape DAST uncovered a missing default that lets any Immich user read locked-folder photos without the PIN.
Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
Submitted July 17, 2026 at 06:48PM by ShufflinMuffin
via reddit https://ift.tt/By6Od2o
https://davidcarliez.github.io/blog/windows-appresolver-lpe-to-system/
Submitted July 17, 2026 at 06:48PM by ShufflinMuffin
via reddit https://ift.tt/By6Od2o
David Carliez
Windows AppResolver LPE: From AppContainer to SYSTEM
Exploit development for a Windows AppResolver authorization issue fixed in July 2026, from a zero-capability AppContainer to an interactive SYSTEM shell.
Openwrt pre-auth remote root exploit
https://ift.tt/njcWN6u
Submitted July 18, 2026 at 12:26AM by supernetworks
via reddit https://ift.tt/w5eOkLB
https://ift.tt/njcWN6u
Submitted July 18, 2026 at 12:26AM by supernetworks
via reddit https://ift.tt/w5eOkLB
Nitter
hacker.house (@hackerfantastic)
Don't believe that this is real? OpenWRT pre-auth remote root exploit 0day (CVSS 9.6, CRITICAL). Submitted this morning to the project. Technical details with-held for future publication. I have so far ran against OpenWRT, Horde, Django, WordPress, Gitlab…
wp2shell: Pre Authentication RCE in WordPress Core
https://wp2shell.com/
Submitted July 18, 2026 at 06:43AM by Mempodipper
via reddit https://ift.tt/YITui8X
https://wp2shell.com/
Submitted July 18, 2026 at 06:43AM by Mempodipper
via reddit https://ift.tt/YITui8X
wp2shell
wp2shell: Pre Authentication RCE in WordPress Core
Check whether your WordPress site is affected by the pre-authentication RCE in WordPress Core. A free checker from Searchlight Cyber.
Keeping private namespaces private - Quad9 blog
https://ift.tt/f7PY6yo
Submitted July 18, 2026 at 06:30AM by nicholashairs
via reddit https://ift.tt/Pz9KsMr
https://ift.tt/f7PY6yo
Submitted July 18, 2026 at 06:30AM by nicholashairs
via reddit https://ift.tt/Pz9KsMr
Quad9
Quad9 | A public and free DNS service for a better security and privacy
White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
https://ift.tt/7aPSkQ5
Submitted July 18, 2026 at 09:40AM by Emergency_Stable_923
via reddit https://ift.tt/5UkZQoh
https://ift.tt/7aPSkQ5
Submitted July 18, 2026 at 09:40AM by Emergency_Stable_923
via reddit https://ift.tt/5UkZQoh
The White House
White House Launches Gold Eagle Initiative for Unprecedented Cybersecurity Vulnerability Coordination
President Trump’s bold vision to secure and accelerate American artificial intelligence (AI) innovation is being actioned through the creation of “GOLD
Source Code Analysis: A Pentester's Guide
https://ift.tt/y24OfQr
Submitted July 18, 2026 at 01:10PM by Ok_Host1989
via reddit https://ift.tt/pCGWq2j
https://ift.tt/y24OfQr
Submitted July 18, 2026 at 01:10PM by Ok_Host1989
via reddit https://ift.tt/pCGWq2j
Vulnsy
Source Code Analysis A Pentester's Guide
A practical guide to source code analysis for pentesters. Learn SAST, manual review, tooling, and how to integrate code review into your pentest reports.
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing
https://ift.tt/xZu4TS3
Submitted July 18, 2026 at 10:56PM by SpectreTv
via reddit https://ift.tt/O7HZvkd
https://ift.tt/xZu4TS3
Submitted July 18, 2026 at 10:56PM by SpectreTv
via reddit https://ift.tt/O7HZvkd
Rhys Downing
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT
A technical teardown of a multi-stage .NET dropper chain that hides its loaders inside bitmap pixel channels, wraps an Eazfuscator crypter around an academic epidemiology simulator, and delivers AsyncRAT 0.5.8. Includes pixelchain, a keyless end-to-end chain…
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner
https://ift.tt/zD3KEOe
Submitted July 19, 2026 at 02:47AM by mazen160
via reddit https://ift.tt/2x5WumZ
https://ift.tt/zD3KEOe
Submitted July 19, 2026 at 02:47AM by mazen160
via reddit https://ift.tt/2x5WumZ
FullHunt Blog
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core
How three small bugs in WordPress Core chain into CVE-2026-63030 (wp2shell), a pre-auth RCE reachable with a single anonymous POST to the REST API batch endpoint.
Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable
https://ift.tt/qFktAcv
Submitted July 19, 2026 at 04:16AM by TheSilenceOfWinter
via reddit https://ift.tt/8dDGJXM
https://ift.tt/qFktAcv
Submitted July 19, 2026 at 04:16AM by TheSilenceOfWinter
via reddit https://ift.tt/8dDGJXM
Alex Manson
Forging the government’s lottery: China’s civic apps run on a shared reward backend with no real secret
Dozens of Chinese city, civic and state-media apps run their points-and-lottery campaigns on a handful of shared B2B SaaS backends. The signing that protects them uses a public salt and a key the server hands you on request. Here’s the multi-tenant exposure…
wp2shell (CVE-2026-63030) update: public working exploit now available for the WordPress core pre-auth RCE
https://ift.tt/6Zx48eQ
Submitted July 19, 2026 at 01:50PM by lexcor
via reddit https://ift.tt/u4RJI2s
https://ift.tt/6Zx48eQ
Submitted July 19, 2026 at 01:50PM by lexcor
via reddit https://ift.tt/u4RJI2s
Ransomnews
wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)
wp2shell chains a REST batch-route bypass and a SQL injection into pre-auth RCE on WordPress core. WordPress shipped forced auto-updates in 7.0.2, 6.9.5 and 6.8.6.
wp2shell: a defender’s guide (CVE-2026-63030 + CVE-2026-60137) with a list of forensic artifacts, a compromise scanner WordPress plugin and a free Chrome/Edge/Firefox browser extension to in-browser check if a website has been patched.
https://ift.tt/eZOqth6
Submitted July 20, 2026 at 05:26AM by eyesecurity
via reddit https://ift.tt/c3Lls4A
https://ift.tt/eZOqth6
Submitted July 20, 2026 at 05:26AM by eyesecurity
via reddit https://ift.tt/c3Lls4A
Eye Research
wp2shell: a defender's guide (CVE-2026-63030 + CVE-2026-60137)
A critical pre-auth RCE hit WordPress core (wp2shell). A blog on how to check if you're exposed, hunt for compromise, and respond, plus two new free tools.
Five months of industrial-protocol traffic to our honeypots
https://ift.tt/Fd9mDkq
Submitted July 20, 2026 at 02:24PM by Honeylabs
via reddit https://ift.tt/eNAFfwc
https://ift.tt/Fd9mDkq
Submitted July 20, 2026 at 02:24PM by Honeylabs
via reddit https://ift.tt/eNAFfwc
HoneyLabs
Someone keeps knocking on the control room | HoneyLabs blog
Our honeypots run no industrial equipment, yet 2,661 hosts sent a real Modbus, DNP3, S7comm or IEC-104 handshake in five months. Decoding the payloads: which scanners, which PLCs they hunt, and how far each probe goes.
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)
https://ift.tt/b1RgESZ
Submitted July 20, 2026 at 01:49PM by luke-paradoxis
via reddit https://ift.tt/2ZXgUk1
https://ift.tt/b1RgESZ
Submitted July 20, 2026 at 01:49PM by luke-paradoxis
via reddit https://ift.tt/2ZXgUk1
Medium
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)
TL;DR: it was possible to obtain NT AUTHORITY\SYSTEM privileges from the perspective of an unprivileged user using Foxit PDF Reader. The…
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
https://ift.tt/BYCAj50
Submitted July 20, 2026 at 01:42PM by Mempodipper
via reddit https://ift.tt/N5vIgc3
https://ift.tt/BYCAj50
Submitted July 20, 2026 at 01:42PM by Mempodipper
via reddit https://ift.tt/N5vIgc3
Searchlight Cyber
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 › Searchlight Cyber
Stay current: Get research alerts for newly disclosed vulnerabilities and exposures If you're running WordPress and want to check if your instance is vulnerable, you can use our tool we've hosted here: https://wp2shell.com/. We held off on publishing this…
Interstitial Risk: When Two Correct Systems Make One Vulnerable One
https://ift.tt/C2cTZdU
Submitted July 20, 2026 at 09:13PM by Blank_1
via reddit https://ift.tt/OTN7PZc
https://ift.tt/C2cTZdU
Submitted July 20, 2026 at 09:13PM by Blank_1
via reddit https://ift.tt/OTN7PZc
Gneiss Group
Interstitial Risk: When Two Correct Systems Make One Vulnerable One
Two components can each pass every scan and still combine into a vulnerability that lives in the seam between them.
Crawling the Complete IPv4 Reverse DNS Space
https://ift.tt/lVhoFRz
Submitted July 20, 2026 at 08:39PM by incolumitas
via reddit https://ift.tt/qwWK8id
https://ift.tt/lVhoFRz
Submitted July 20, 2026 at 08:39PM by incolumitas
via reddit https://ift.tt/qwWK8id
ipapi.is
ipapi.is - Crawling the Complete IPv4 Reverse DNS Space
ipapi.is offers precise IP data via a user-friendly API, encompassing geolocation, ASN data, hosting detection, VPN detection, and proxy detection.
Post-Compilation Obfuscation Is Outdated: Moving Polymorphism Directly into CMake
https://ift.tt/BU93SXp
Submitted July 20, 2026 at 10:06PM by Important_Map6928
via reddit https://ift.tt/ZifLNIW
https://ift.tt/BU93SXp
Submitted July 20, 2026 at 10:06PM by Important_Map6928
via reddit https://ift.tt/ZifLNIW
sibouzitoun.tech
SindriKit 1.5.0: The SND_MORPH Mutation Engine
SindriKit 1.5.0 introduces structural and instruction-level polymorphism via the SND_MORPH engine to eradicate static signatures on every build.
Leaking internal headers in Flask Ninja with deserialization
https://ift.tt/egEGHMT
Submitted July 21, 2026 at 03:38PM by 0xcrypto
via reddit https://ift.tt/lg3yIho
https://ift.tt/egEGHMT
Submitted July 21, 2026 at 03:38PM by 0xcrypto
via reddit https://ift.tt/lg3yIho
eval.blog
Leaking internal headers in Flask Ninja with deserialization
Evaluations and research on security, software, and AI by Vikrant Singh Chauhan.
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE)
https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
Submitted July 21, 2026 at 08:12PM by ShufflinMuffin
via reddit https://ift.tt/v52dnCr
https://davidcarliez.github.io/blog/cve-2026-49176-walletservice-to-system/
Submitted July 21, 2026 at 08:12PM by ShufflinMuffin
via reddit https://ift.tt/v52dnCr
David Carliez
CVE-2026-49176 Exploit Development: WalletService to SYSTEM
Exploit development for the Windows WalletService vulnerability, from caller-controlled known-folder resolution to a persisted ESE callback and an interactive SYSTEM shell.