frontier class vulnerabilities: it gets worse before it (maybe) gets better
https://ift.tt/AXsvNYV
Submitted August 1, 2026 at 05:21PM by Mempodipper
via reddit https://ift.tt/wXDJWVc
https://ift.tt/AXsvNYV
Submitted August 1, 2026 at 05:21PM by Mempodipper
via reddit https://ift.tt/wXDJWVc
shubs
frontier class vulnerabilities: it gets worse before it (maybe) gets better
Early in my career as a consultant, I was put on source code review engagements despite not being experienced. This forced me to deliver on projects that, looking back, were of a ludicrous size and scope for my skills at the time.
Those early career opportunities…
Those early career opportunities…
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted August 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/bAcGs8F
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted August 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/bAcGs8F
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
https://ift.tt/flHdiSr
Submitted August 3, 2026 at 12:30AM by S3cur3Th1sSh1t
via reddit https://ift.tt/tuNikhP
https://ift.tt/flHdiSr
Submitted August 3, 2026 at 12:30AM by S3cur3Th1sSh1t
via reddit https://ift.tt/tuNikhP
www.msecops.de
The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
A proof of concept: fine-tuning small open-weight coding models into silent backdoors that execute code on the machine of anyone who connects to them.
L2 Reduction: LLL Algorithm With Quadratic Complexity in Python
https://ift.tt/eyRd9rm
Submitted August 3, 2026 at 08:45AM by DataBaeBee
via reddit https://ift.tt/1oBOLRQ
https://ift.tt/eyRd9rm
Submitted August 3, 2026 at 08:45AM by DataBaeBee
via reddit https://ift.tt/1oBOLRQ
Substack
L2 Reduction: LLL Algorithm With Quadratic Complexity
[Python] Fast Floating-Point Variant of LLL Reduction with Proven Termination
Cruising for Shells in Flowise - elttam
https://ift.tt/0gCtOFk
Submitted August 3, 2026 at 05:24PM by AnimalStrange
via reddit https://ift.tt/E8sQeUR
https://ift.tt/0gCtOFk
Submitted August 3, 2026 at 05:24PM by AnimalStrange
via reddit https://ift.tt/E8sQeUR
Elttam
Cruising for Shells in Flowise - elttam
After reviewing Flowise, a popular AI agent/workflow platform, and its history of critical security advisories, we uncovered 6 new remote code execution vulnerabilities in v3.1.1/v3.1.2
SQLite Critical CVEs or LLM Slop?
https://ift.tt/AXN68tL
Submitted August 3, 2026 at 07:34PM by si9int
via reddit https://ift.tt/7qxGjen
https://ift.tt/AXN68tL
Submitted August 3, 2026 at 07:34PM by si9int
via reddit https://ift.tt/7qxGjen
Jfrog
SQLite Critical CVEs or LLM Slop? | JFrog
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or…
Xpsd: decide if a CVE is actually reachable in your tree (SARIF / GitHub code scanning)
https://ift.tt/NFvBjOQ
Submitted August 4, 2026 at 12:34AM by Emergency_Stable_923
via reddit https://ift.tt/UAkDKFy
https://ift.tt/NFvBjOQ
Submitted August 4, 2026 at 12:34AM by Emergency_Stable_923
via reddit https://ift.tt/UAkDKFy
byteray.co.uk
ByteRay | Autonomous Security, From Source to Silicon
ByteRay is the multi-agent security platform that discovers, verifies, and remediates vulnerabilities across source code, binaries, firmware, web services, and live infrastructure - powered by Argus.
Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category
https://hego.red/jackpot
Submitted August 4, 2026 at 04:38AM by callmejackfrost1
via reddit https://ift.tt/KuqMH46
https://hego.red/jackpot
Submitted August 4, 2026 at 04:38AM by callmejackfrost1
via reddit https://ift.tt/KuqMH46
hego.red
Jackpot: hack 10 AIs, one floor at a time
Ten floors, ten broken AIs. Hack your way up a casino using the real OWASP LLM Top 10 techniques. No signup, runs in your browser.
Before the first prompt: Code execution paths in trusted coding-agent projects
https://ift.tt/SRBKJub
Submitted August 4, 2026 at 03:43AM by RedTermSession
via reddit https://ift.tt/l1P7kyD
https://ift.tt/SRBKJub
Submitted August 4, 2026 at 03:43AM by RedTermSession
via reddit https://ift.tt/l1P7kyD
Datadoghq
Before the first prompt: Code execution paths in trusted coding-agent projects
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.
Code Execution via Provisioning Packages
https://ift.tt/pB4OawH
Submitted August 4, 2026 at 02:08PM by netbiosX
via reddit https://ift.tt/15ISvk9
https://ift.tt/pB4OawH
Submitted August 4, 2026 at 02:08PM by netbiosX
via reddit https://ift.tt/15ISvk9
Purple Team
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse prov…
HEVD: From Stack Overflows to Modern Pool Grooming
https://ift.tt/zNbDjY5
Submitted August 4, 2026 at 03:31PM by Important_Map6928
via reddit https://ift.tt/RmHx47Z
https://ift.tt/zNbDjY5
Submitted August 4, 2026 at 03:31PM by Important_Map6928
via reddit https://ift.tt/RmHx47Z
sibouzitoun.tech
HEVD: From Stack Overflows to Modern Pool Grooming
A four-part deep dive into Windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on Windows 11.
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router
https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
Submitted August 4, 2026 at 08:51PM by Internal-Key64
via reddit https://ift.tt/5A3CdYQ
https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
Submitted August 4, 2026 at 08:51PM by Internal-Key64
via reddit https://ift.tt/5A3CdYQ
Rotce’s Blog
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon’s best-selling router
This will be a blog series where we’ll do a deep dive into the Mercusys MB115-4G router, which, as of today (02/17/2026), is the best-selling router on Amazon Spain. In this first post, we’ll cover the workflow from receiving the device to gaining a root…
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
https://ift.tt/S3d4fPQ
Submitted August 4, 2026 at 11:03PM by Straight-Practice-99
via reddit https://ift.tt/ZF9HGWz
https://ift.tt/S3d4fPQ
Submitted August 4, 2026 at 11:03PM by Straight-Practice-99
via reddit https://ift.tt/ZF9HGWz
hunt.io
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory linked to The Gentlemen revealed EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract.
Bugtraq is back 🥹
https://ift.tt/MWikPR9
Submitted August 5, 2026 at 04:18AM by loselasso
via reddit https://ift.tt/pRzTMw5
https://ift.tt/MWikPR9
Submitted August 5, 2026 at 04:18AM by loselasso
via reddit https://ift.tt/pRzTMw5
Traditional networking vs SDN
https://ift.tt/4ZKTHig
Submitted August 5, 2026 at 07:36AM by VEXX452
via reddit https://ift.tt/ogLDczO
https://ift.tt/4ZKTHig
Submitted August 5, 2026 at 07:36AM by VEXX452
via reddit https://ift.tt/ogLDczO
ResearchGate
Fig. 1: Traditional networking versus SDN networking
Download scientific diagram | Traditional networking versus SDN networking from publication: Energy-Aware Routing in Carrier-Grade Ethernet Using SDN Approach | Soft-Defined Networking (SDN) is a new approach that enables operators to easily manage all the…
New Linux Bridge STP Vulnerability
https://ift.tt/TBSoUtC
Submitted August 5, 2026 at 02:34PM by SSDisclosure
via reddit https://ift.tt/oMbIAV6
https://ift.tt/TBSoUtC
Submitted August 5, 2026 at 02:34PM by SSDisclosure
via reddit https://ift.tt/oMbIAV6
SSD Secure Disclosure
Linux Bridge STP Timer Use-After-Free - SSD Secure Disclosure
Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic…
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
https://ift.tt/OidoRhH
Submitted August 5, 2026 at 08:08PM by Sandwich_1337
via reddit https://ift.tt/L2Ua8F7
https://ift.tt/OidoRhH
Submitted August 5, 2026 at 08:08PM by Sandwich_1337
via reddit https://ift.tt/L2Ua8F7
Syntetisk
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
Django's admin auto-linked URLField values without validating the scheme — a stored javascript: value rendered as a live link. Fixed in 6.0.8 and 5.2.17.
OpenAI agents rebuilt a secret message board after the company shut it down
https://ift.tt/4xc7lZk
Submitted August 6, 2026 at 02:47AM by ryanmerket
via reddit https://ift.tt/RWcdIU0
https://ift.tt/4xc7lZk
Submitted August 6, 2026 at 02:47AM by ryanmerket
via reddit https://ift.tt/RWcdIU0
RuntimeWire
EXCLUSIVE: OpenAI agents rebuilt a secret message board after the company shut it down
OpenAI restarted agent training two days after a model-caused Artifactory outage. The agents then rebuilt their deleted communication channel.
From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation
https://ift.tt/g0W3yNU
Submitted August 6, 2026 at 07:42AM by coinspect
via reddit https://ift.tt/1eC3Afw
https://ift.tt/g0W3yNU
Submitted August 6, 2026 at 07:42AM by coinspect
via reddit https://ift.tt/1eC3Afw
Coinspect Security
Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation
How Coinspect traced a wallet-drain investigation back to a twelve-year-old insecure randomness flaw, searched for exposed addresses at scale, and disclosed the findings...
Zbtlink Routers Contain rctl Backdoor
https://ift.tt/OyiRDwC
Submitted August 7, 2026 at 12:27AM by chicksdigthelongrun
via reddit https://ift.tt/wAeSyOX
https://ift.tt/OyiRDwC
Submitted August 7, 2026 at 12:27AM by chicksdigthelongrun
via reddit https://ift.tt/wAeSyOX
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Claude Code RCE: How a Malicious PR Triggers Code Execution
https://ift.tt/LrenChA
Submitted August 7, 2026 at 02:52AM by kev-thehermit
via reddit https://ift.tt/Svzn53y
https://ift.tt/LrenChA
Submitted August 7, 2026 at 02:52AM by kev-thehermit
via reddit https://ift.tt/Svzn53y
Immersivelabs
Claude Code RCE: How a Malicious PR Triggers Code Execution
A hidden .mcp.json file lets attackers achieve remote code execution in Claude Code via a malicious pull request — no user action required. See the PoC.