Xpsd: decide if a CVE is actually reachable in your tree (SARIF / GitHub code scanning)
https://ift.tt/NFvBjOQ
Submitted August 4, 2026 at 12:34AM by Emergency_Stable_923
via reddit https://ift.tt/UAkDKFy
https://ift.tt/NFvBjOQ
Submitted August 4, 2026 at 12:34AM by Emergency_Stable_923
via reddit https://ift.tt/UAkDKFy
byteray.co.uk
ByteRay | Autonomous Security, From Source to Silicon
ByteRay is the multi-agent security platform that discovers, verifies, and remediates vulnerabilities across source code, binaries, firmware, web services, and live infrastructure - powered by Argus.
Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category
https://hego.red/jackpot
Submitted August 4, 2026 at 04:38AM by callmejackfrost1
via reddit https://ift.tt/KuqMH46
https://hego.red/jackpot
Submitted August 4, 2026 at 04:38AM by callmejackfrost1
via reddit https://ift.tt/KuqMH46
hego.red
Jackpot: hack 10 AIs, one floor at a time
Ten floors, ten broken AIs. Hack your way up a casino using the real OWASP LLM Top 10 techniques. No signup, runs in your browser.
Before the first prompt: Code execution paths in trusted coding-agent projects
https://ift.tt/SRBKJub
Submitted August 4, 2026 at 03:43AM by RedTermSession
via reddit https://ift.tt/l1P7kyD
https://ift.tt/SRBKJub
Submitted August 4, 2026 at 03:43AM by RedTermSession
via reddit https://ift.tt/l1P7kyD
Datadoghq
Before the first prompt: Code execution paths in trusted coding-agent projects
Learn how trusted coding-agent projects can execute repository-controlled code before the first prompt through Codex MCP configuration and Claude Code environment settings.
Code Execution via Provisioning Packages
https://ift.tt/pB4OawH
Submitted August 4, 2026 at 02:08PM by netbiosX
via reddit https://ift.tt/15ISvk9
https://ift.tt/pB4OawH
Submitted August 4, 2026 at 02:08PM by netbiosX
via reddit https://ift.tt/15ISvk9
Purple Team
Provisioning Packages
Windows Provisioning Packages are used by Administrators to deploy configuration scripts on Windows environments by using a container format. Threat actors with elevated privileges could abuse prov…
HEVD: From Stack Overflows to Modern Pool Grooming
https://ift.tt/zNbDjY5
Submitted August 4, 2026 at 03:31PM by Important_Map6928
via reddit https://ift.tt/RmHx47Z
https://ift.tt/zNbDjY5
Submitted August 4, 2026 at 03:31PM by Important_Map6928
via reddit https://ift.tt/RmHx47Z
sibouzitoun.tech
HEVD: From Stack Overflows to Modern Pool Grooming
A four-part deep dive into Windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on Windows 11.
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router
https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
Submitted August 4, 2026 at 08:51PM by Internal-Key64
via reddit https://ift.tt/5A3CdYQ
https://rotcee.github.io/posts/analyzing-the-mersusys-mb115-4g-router/#cve-2026-12495-finding-a-pre-auth-stack-buffer-overflow-in-the-mercusys-mb115-4g
Submitted August 4, 2026 at 08:51PM by Internal-Key64
via reddit https://ift.tt/5A3CdYQ
Rotce’s Blog
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon’s best-selling router
This will be a blog series where we’ll do a deep dive into the Mercusys MB115-4G router, which, as of today (02/17/2026), is the best-selling router on Amazon Spain. In this first post, we’ll cover the workflow from receiving the device to gaining a root…
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
https://ift.tt/S3d4fPQ
Submitted August 4, 2026 at 11:03PM by Straight-Practice-99
via reddit https://ift.tt/ZF9HGWz
https://ift.tt/S3d4fPQ
Submitted August 4, 2026 at 11:03PM by Straight-Practice-99
via reddit https://ift.tt/ZF9HGWz
hunt.io
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory linked to The Gentlemen revealed EtherRAT, a Node.js backdoor that resolves rotating C2 domains through an Ethereum smart contract.
Bugtraq is back 🥹
https://ift.tt/MWikPR9
Submitted August 5, 2026 at 04:18AM by loselasso
via reddit https://ift.tt/pRzTMw5
https://ift.tt/MWikPR9
Submitted August 5, 2026 at 04:18AM by loselasso
via reddit https://ift.tt/pRzTMw5
Traditional networking vs SDN
https://ift.tt/4ZKTHig
Submitted August 5, 2026 at 07:36AM by VEXX452
via reddit https://ift.tt/ogLDczO
https://ift.tt/4ZKTHig
Submitted August 5, 2026 at 07:36AM by VEXX452
via reddit https://ift.tt/ogLDczO
ResearchGate
Fig. 1: Traditional networking versus SDN networking
Download scientific diagram | Traditional networking versus SDN networking from publication: Energy-Aware Routing in Carrier-Grade Ethernet Using SDN Approach | Soft-Defined Networking (SDN) is a new approach that enables operators to easily manage all the…
New Linux Bridge STP Vulnerability
https://ift.tt/TBSoUtC
Submitted August 5, 2026 at 02:34PM by SSDisclosure
via reddit https://ift.tt/oMbIAV6
https://ift.tt/TBSoUtC
Submitted August 5, 2026 at 02:34PM by SSDisclosure
via reddit https://ift.tt/oMbIAV6
SSD Secure Disclosure
Linux Bridge STP Timer Use-After-Free - SSD Secure Disclosure
Summary A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation. A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic…
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
https://ift.tt/OidoRhH
Submitted August 5, 2026 at 08:08PM by Sandwich_1337
via reddit https://ift.tt/L2Ua8F7
https://ift.tt/OidoRhH
Submitted August 5, 2026 at 08:08PM by Sandwich_1337
via reddit https://ift.tt/L2Ua8F7
Syntetisk
Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
Django's admin auto-linked URLField values without validating the scheme — a stored javascript: value rendered as a live link. Fixed in 6.0.8 and 5.2.17.
OpenAI agents rebuilt a secret message board after the company shut it down
https://ift.tt/4xc7lZk
Submitted August 6, 2026 at 02:47AM by ryanmerket
via reddit https://ift.tt/RWcdIU0
https://ift.tt/4xc7lZk
Submitted August 6, 2026 at 02:47AM by ryanmerket
via reddit https://ift.tt/RWcdIU0
RuntimeWire
OpenAI agents rebuilt a secret message board after the company shut it down
OpenAI restarted agent training two days after a model-caused Artifactory outage. The agents then rebuilt their deleted communication channel.
From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation
https://ift.tt/g0W3yNU
Submitted August 6, 2026 at 07:42AM by coinspect
via reddit https://ift.tt/1eC3Afw
https://ift.tt/g0W3yNU
Submitted August 6, 2026 at 07:42AM by coinspect
via reddit https://ift.tt/1eC3Afw
Coinspect Security
Ill Bloom: Investigating a Wallet Generation Vulnerability During Active Exploitation
How Coinspect traced a wallet-drain investigation back to a twelve-year-old insecure randomness flaw, searched for exposed addresses at scale, and disclosed the findings...
Zbtlink Routers Contain rctl Backdoor
https://ift.tt/OyiRDwC
Submitted August 7, 2026 at 12:27AM by chicksdigthelongrun
via reddit https://ift.tt/wAeSyOX
https://ift.tt/OyiRDwC
Submitted August 7, 2026 at 12:27AM by chicksdigthelongrun
via reddit https://ift.tt/wAeSyOX
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Claude Code RCE: How a Malicious PR Triggers Code Execution
https://ift.tt/LrenChA
Submitted August 7, 2026 at 02:52AM by kev-thehermit
via reddit https://ift.tt/Svzn53y
https://ift.tt/LrenChA
Submitted August 7, 2026 at 02:52AM by kev-thehermit
via reddit https://ift.tt/Svzn53y
Immersivelabs
Claude Code RCE: How a Malicious PR Triggers Code Execution
A hidden .mcp.json file lets attackers achieve remote code execution in Claude Code via a malicious pull request — no user action required. See the PoC.
I made a full JWT hacking tutorial + testing suite
https://ift.tt/rDsaXAb
Submitted August 7, 2026 at 05:13AM by hakluke
via reddit https://ift.tt/afvum9K
https://ift.tt/rDsaXAb
Submitted August 7, 2026 at 05:13AM by hakluke
via reddit https://ift.tt/afvum9K
hakluke
JWT Hacking Toolkit — Decode, Edit & Forge JSON Web Tokens
Decode and edit JWTs live, crack weak secrets, and forge tokens with alg:none, algorithm confusion, jwk/jku and kid injection. Free, and everything runs in your browser.
TrustFall: When the Trusted Execution Environment Cannot Be Trusted
https://ift.tt/QmsDFqx
Submitted August 7, 2026 at 08:38PM by Emergency_Stable_923
via reddit https://ift.tt/KJe695c
https://ift.tt/QmsDFqx
Submitted August 7, 2026 at 08:38PM by Emergency_Stable_923
via reddit https://ift.tt/KJe695c
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
https://ift.tt/4HRr68i
Submitted August 7, 2026 at 11:53PM by kochurshak
via reddit https://ift.tt/gQpTGRc
https://ift.tt/4HRr68i
Submitted August 7, 2026 at 11:53PM by kochurshak
via reddit https://ift.tt/gQpTGRc
Bobdahacker
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
How a missing Firestore security rule on tl;dv exposed 181,874 meetings from 84,312 users across 35,003 domains, including live calls I could join uninvited, and how six months of disclosure got me nothing but seen receipts.
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab
https://ift.tt/29w7eVr
Submitted August 8, 2026 at 07:50AM by thobiso
via reddit https://ift.tt/gBQZMCK
https://ift.tt/29w7eVr
Submitted August 8, 2026 at 07:50AM by thobiso
via reddit https://ift.tt/gBQZMCK
Tencent Zhuque Lab
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab
SCTPhantom is a Linux kernel use-after-free in SCTP's dynamic address reconfiguration code.
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
https://ift.tt/Bdbl6s7
Submitted August 8, 2026 at 09:27AM by lohacker0
via reddit https://ift.tt/OBVxLwz
https://ift.tt/Bdbl6s7
Submitted August 8, 2026 at 09:27AM by lohacker0
via reddit https://ift.tt/OBVxLwz
Varonis
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
With access to Jira, Confluence, Microsoft 365, Google Workspace, Slack, and more, RovoBlast shows how a single link turns AI permissions into a low-friction path for data exposure.
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
https://ift.tt/fQl2U7h
Submitted August 8, 2026 at 02:40PM by ZealousidealHunter80
via reddit https://ift.tt/mDAWY6e
https://ift.tt/fQl2U7h
Submitted August 8, 2026 at 02:40PM by ZealousidealHunter80
via reddit https://ift.tt/mDAWY6e
Ethiack
Write Once, Shell Everywhere: Turning Arbitrary File Writes into RCE | Ethiack — Autonomous Ethical Hacking for continuous security