The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
https://ift.tt/flHdiSr
Submitted August 3, 2026 at 12:30AM by S3cur3Th1sSh1t
via reddit https://ift.tt/tuNikhP
https://ift.tt/flHdiSr
Submitted August 3, 2026 at 12:30AM by S3cur3Th1sSh1t
via reddit https://ift.tt/tuNikhP
www.msecops.de
The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
A proof of concept: fine-tuning small open-weight coding models into silent backdoors that execute code on the machine of anyone who connects to them.
L2 Reduction: LLL Algorithm With Quadratic Complexity in Python
https://ift.tt/eyRd9rm
Submitted August 3, 2026 at 08:45AM by DataBaeBee
via reddit https://ift.tt/1oBOLRQ
https://ift.tt/eyRd9rm
Submitted August 3, 2026 at 08:45AM by DataBaeBee
via reddit https://ift.tt/1oBOLRQ
Substack
L2 Reduction: LLL Algorithm With Quadratic Complexity
[Python] Fast Floating-Point Variant of LLL Reduction with Proven Termination
Cruising for Shells in Flowise - elttam
https://ift.tt/0gCtOFk
Submitted August 3, 2026 at 05:24PM by AnimalStrange
via reddit https://ift.tt/E8sQeUR
https://ift.tt/0gCtOFk
Submitted August 3, 2026 at 05:24PM by AnimalStrange
via reddit https://ift.tt/E8sQeUR
Elttam
Cruising for Shells in Flowise - elttam
After reviewing Flowise, a popular AI agent/workflow platform, and its history of critical security advisories, we uncovered 6 new remote code execution vulnerabilities in v3.1.1/v3.1.2
SQLite Critical CVEs or LLM Slop?
https://ift.tt/AXN68tL
Submitted August 3, 2026 at 07:34PM by si9int
via reddit https://ift.tt/7qxGjen
https://ift.tt/AXN68tL
Submitted August 3, 2026 at 07:34PM by si9int
via reddit https://ift.tt/7qxGjen
Jfrog
SQLite Critical CVEs or LLM Slop? | JFrog
The JFrog security research team recently identified a supply chain attack targeting the `xinference` package on PyPI. Versions 2.6.0, 2.6.1, and 2.6.2 were compromised and yanked by maintainers after users reported suspicious behavior. If you installed or…
Xpsd: decide if a CVE is actually reachable in your tree (SARIF / GitHub code scanning)
https://ift.tt/NFvBjOQ
Submitted August 4, 2026 at 12:34AM by Emergency_Stable_923
via reddit https://ift.tt/UAkDKFy
https://ift.tt/NFvBjOQ
Submitted August 4, 2026 at 12:34AM by Emergency_Stable_923
via reddit https://ift.tt/UAkDKFy
byteray.co.uk
ByteRay | Autonomous Security, From Source to Silicon
ByteRay is the multi-agent security platform that discovers, verifies, and remediates vulnerabilities across source code, binaries, firmware, web services, and live infrastructure - powered by Argus.
Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category
https://hego.red/jackpot
Submitted August 4, 2026 at 04:38AM by callmejackfrost1
via reddit https://ift.tt/KuqMH46
https://hego.red/jackpot
Submitted August 4, 2026 at 04:38AM by callmejackfrost1
via reddit https://ift.tt/KuqMH46
hego.red
Jackpot: hack 10 AIs, one floor at a time
Ten floors, ten broken AIs. Hack your way up a casino using the real OWASP LLM Top 10 techniques. No signup, runs in your browser.
Before the first prompt: Code execution paths in trusted coding-agent projects
https://ift.tt/SRBKJub
Submitted August 4, 2026 at 03:43AM by RedTermSession
via reddit https://ift.tt/l1P7kyD
https://ift.tt/SRBKJub
Submitted August 4, 2026 at 03:43AM by RedTermSession
via reddit https://ift.tt/l1P7kyD
Datadoghq
Before the first prompt: Code execution paths in trusted coding-agent projects
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.
Code Execution via Provisioning Packages
https://ift.tt/pB4OawH
Submitted August 4, 2026 at 02:08PM by netbiosX
via reddit https://ift.tt/15ISvk9
https://ift.tt/pB4OawH
Submitted August 4, 2026 at 02:08PM by netbiosX
via reddit https://ift.tt/15ISvk9
Purple Team
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse prov…
HEVD: From Stack Overflows to Modern Pool Grooming
https://ift.tt/zNbDjY5
Submitted August 4, 2026 at 03:31PM by Important_Map6928
via reddit https://ift.tt/RmHx47Z
https://ift.tt/zNbDjY5
Submitted August 4, 2026 at 03:31PM by Important_Map6928
via reddit https://ift.tt/RmHx47Z
sibouzitoun.tech
HEVD: From Stack Overflows to Modern Pool Grooming
A four-part deep dive into Windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on Windows 11.
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router
https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
Submitted August 4, 2026 at 08:51PM by Internal-Key64
via reddit https://ift.tt/5A3CdYQ
https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
Submitted August 4, 2026 at 08:51PM by Internal-Key64
via reddit https://ift.tt/5A3CdYQ
Rotce’s Blog
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon’s best-selling router
This will be a blog series where we’ll do a deep dive into the Mercusys MB115-4G router, which, as of today (02/17/2026), is the best-selling router on Amazon Spain. In this first post, we’ll cover the workflow from receiving the device to gaining a root…
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
https://ift.tt/S3d4fPQ
Submitted August 4, 2026 at 11:03PM by Straight-Practice-99
via reddit https://ift.tt/ZF9HGWz
https://ift.tt/S3d4fPQ
Submitted August 4, 2026 at 11:03PM by Straight-Practice-99
via reddit https://ift.tt/ZF9HGWz
hunt.io
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory linked to The Gentlemen revealed EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract.
Bugtraq is back 🥹
https://ift.tt/MWikPR9
Submitted August 5, 2026 at 04:18AM by loselasso
via reddit https://ift.tt/pRzTMw5
https://ift.tt/MWikPR9
Submitted August 5, 2026 at 04:18AM by loselasso
via reddit https://ift.tt/pRzTMw5
Traditional networking vs SDN
https://ift.tt/4ZKTHig
Submitted August 5, 2026 at 07:36AM by VEXX452
via reddit https://ift.tt/ogLDczO
https://ift.tt/4ZKTHig
Submitted August 5, 2026 at 07:36AM by VEXX452
via reddit https://ift.tt/ogLDczO
ResearchGate
Fig. 1: Traditional networking versus SDN networking
Download scientific diagram | Traditional networking versus SDN networking from publication: Energy-Aware Routing in Carrier-Grade Ethernet Using SDN Approach | Soft-Defined Networking (SDN) is a new approach that enables operators to easily manage all the…
New Linux Bridge STP Vulnerability
https://ift.tt/TBSoUtC
Submitted August 5, 2026 at 02:34PM by SSDisclosure
via reddit https://ift.tt/oMbIAV6
https://ift.tt/TBSoUtC
Submitted August 5, 2026 at 02:34PM by SSDisclosure
via reddit https://ift.tt/oMbIAV6
SSD Secure Disclosure
Linux Bridge STP Timer Use-After-Free - SSD Secure Disclosure
Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic…
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
https://ift.tt/OidoRhH
Submitted August 5, 2026 at 08:08PM by Sandwich_1337
via reddit https://ift.tt/L2Ua8F7
https://ift.tt/OidoRhH
Submitted August 5, 2026 at 08:08PM by Sandwich_1337
via reddit https://ift.tt/L2Ua8F7
Syntetisk
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
Django's admin auto-linked URLField values without validating the scheme — a stored javascript: value rendered as a live link. Fixed in 6.0.8 and 5.2.17.
OpenAI agents rebuilt a secret message board after the company shut it down
https://ift.tt/4xc7lZk
Submitted August 6, 2026 at 02:47AM by ryanmerket
via reddit https://ift.tt/RWcdIU0
https://ift.tt/4xc7lZk
Submitted August 6, 2026 at 02:47AM by ryanmerket
via reddit https://ift.tt/RWcdIU0
RuntimeWire
EXCLUSIVE: OpenAI agents rebuilt a secret message board after the company shut it down
OpenAI restarted agent training two days after a model-caused Artifactory outage. The agents then rebuilt their deleted communication channel.
From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation
https://ift.tt/g0W3yNU
Submitted August 6, 2026 at 07:42AM by coinspect
via reddit https://ift.tt/1eC3Afw
https://ift.tt/g0W3yNU
Submitted August 6, 2026 at 07:42AM by coinspect
via reddit https://ift.tt/1eC3Afw
Coinspect Security
Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation
How Coinspect traced a wallet-drain investigation back to a twelve-year-old insecure randomness flaw, searched for exposed addresses at scale, and disclosed the findings...
Zbtlink Routers Contain rctl Backdoor
https://ift.tt/OyiRDwC
Submitted August 7, 2026 at 12:27AM by chicksdigthelongrun
via reddit https://ift.tt/wAeSyOX
https://ift.tt/OyiRDwC
Submitted August 7, 2026 at 12:27AM by chicksdigthelongrun
via reddit https://ift.tt/wAeSyOX
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Claude Code RCE: How a Malicious PR Triggers Code Execution
https://ift.tt/LrenChA
Submitted August 7, 2026 at 02:52AM by kev-thehermit
via reddit https://ift.tt/Svzn53y
https://ift.tt/LrenChA
Submitted August 7, 2026 at 02:52AM by kev-thehermit
via reddit https://ift.tt/Svzn53y
Immersivelabs
Claude Code RCE: How a Malicious PR Triggers Code Execution
A hidden .mcp.json file lets attackers achieve remote code execution in Claude Code via a malicious pull request — no user action required. See the PoC.
I made a full JWT hacking tutorial + testing suite
https://ift.tt/rDsaXAb
Submitted August 7, 2026 at 05:13AM by hakluke
via reddit https://ift.tt/afvum9K
https://ift.tt/rDsaXAb
Submitted August 7, 2026 at 05:13AM by hakluke
via reddit https://ift.tt/afvum9K
hakluke
JWT Hacking Toolkit — Decode, Edit & Forge JSON Web Tokens
Decode and edit JWTs live, crack weak secrets, and forge tokens with alg:none, algorithm confusion, jwk/jku and kid injection. Free, and everything runs in your browser.
TrustFall: When the Trusted Execution Environment Cannot Be Trusted
https://ift.tt/QmsDFqx
Submitted August 7, 2026 at 08:38PM by Emergency_Stable_923
via reddit https://ift.tt/KJe695c
https://ift.tt/QmsDFqx
Submitted August 7, 2026 at 08:38PM by Emergency_Stable_923
via reddit https://ift.tt/KJe695c