Can AI do novel security research? Meet the HTTP Terminator
https://ift.tt/rpFZhQT
Submitted 2026-08-13T12:19:41Z by albinowax
via reddit https://ift.tt/6CGrJES
https://ift.tt/rpFZhQT
Submitted 2026-08-13T12:19:41Z by albinowax
via reddit https://ift.tt/6CGrJES
PortSwigger Research
Can AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained
https://ift.tt/W6t4852
Submitted 2026-08-13T15:20:01Z by _solid_snail
via reddit https://ift.tt/osCHpLB
https://ift.tt/W6t4852
Submitted 2026-08-13T15:20:01Z by _solid_snail
via reddit https://ift.tt/osCHpLB
Saiflow
From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained
A single misconfigured listening socket on FIMER's React 2 hybrid inverter lets an unauthenticated attacker send commands straight to the Supervisor MCU that governs the device's grid protections.
CSS:the bomb inside your inbox
https://ift.tt/JXyDFen
Submitted 2026-08-13T20:15:35Z by garethheyes
via reddit https://ift.tt/lSf1q3X
https://ift.tt/JXyDFen
Submitted 2026-08-13T20:15:35Z by garethheyes
via reddit https://ift.tt/lSf1q3X
PortSwigger Research
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg
https://ift.tt/249rCw7
Submitted 2026-08-13T20:51:00Z by tohitsugu
via reddit https://ift.tt/wJZAxtm
https://ift.tt/249rCw7
Submitted 2026-08-13T20:51:00Z by tohitsugu
via reddit https://ift.tt/wJZAxtm
Maldbg
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg - Malware Analysis Blog
Taking apart a freshly compiled Interlock ESXi decryptor, and what it reveals about how the encryptor works.
Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam
https://ift.tt/pkERxb0
Submitted 2026-08-14T04:46:39Z by AnimalStrange
via reddit https://ift.tt/a5S8DBA
https://ift.tt/pkERxb0
Submitted 2026-08-14T04:46:39Z by AnimalStrange
via reddit https://ift.tt/a5S8DBA
Elttam
Ruby 4.0 Universal RCE Deserialization Gadget Chain - elttam
This post releases a new universal chain that turns a single Marshal.load into command execution on Ruby, built with new gadgets from untapped sources as well as old gadgets put to new use.
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) - watchTowr Labs
https://ift.tt/o6GuSYV
Submitted 2026-08-14T07:10:17Z by dx7r__
via reddit https://ift.tt/Gvno0eD
https://ift.tt/o6GuSYV
Submitted 2026-08-14T07:10:17Z by dx7r__
via reddit https://ift.tt/Gvno0eD
watchTowr Labs
You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?))
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.
You know the drill - it’s the typical enterprise “please don’t be a bad person or we may have
You know the drill - it’s the typical enterprise “please don’t be a bad person or we may have
Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt.
https://ift.tt/u2VrQCd
Submitted 2026-08-14T17:01:27Z by PriorPuzzleheaded880
via reddit https://ift.tt/v8MhVLi
https://ift.tt/u2VrQCd
Submitted 2026-08-14T17:01:27Z by PriorPuzzleheaded880
via reddit https://ift.tt/v8MhVLi
Escape - Application Security & Offensive Security Blog
AI vs AI: How Cascade exploited an AI agent in production
We pointed Cascade, Escape's AI pentesting engine, at a production AI agent. The agent had a guardrail built to catch prompt injection. Cascade got past it on the second try.
The trick wasn't a smarter payload, just a different pretext, and the agent handed…
The trick wasn't a smarter payload, just a different pretext, and the agent handed…
I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies
https://ift.tt/DPo4rO9
Submitted 2026-08-14T19:43:10Z by wtfse
via reddit https://ift.tt/etZv5JV
https://ift.tt/DPo4rO9
Submitted 2026-08-14T19:43:10Z by wtfse
via reddit https://ift.tt/etZv5JV
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
Part 1/6 | Systemic Risks in the Managed PostgreSQL Industry: Extension Risks Are Real! Exploiting PostGis Memory Corruption Bug…
Back in April, I was talking with our system and software engineering teams at PRODAFT about the possibilities of using a managed database service. Due to the nature of our business, we simply cannot start using managed services right away. I told my team…
Finding Hidden Internal Apps Through Public Certificate Logs
https://ift.tt/bkA9q82
Submitted 2026-08-15T13:39:43Z by Huge-Wear-125
via reddit https://ift.tt/zmCtDl7
https://ift.tt/bkA9q82
Submitted 2026-08-15T13:39:43Z by Huge-Wear-125
via reddit https://ift.tt/zmCtDl7
naveen srinivasan
Finding Hidden Internal Apps Through Public Certificate Logs
Here is how anyone can unwrap the organization’s internal tools/products that no one is supposed to know about.
Typically, in software organizations, most of us don’t want to share internal applications on the internet, but we unintentionally share application…
Typically, in software organizations, most of us don’t want to share internal applications on the internet, but we unintentionally share application…
CVE-2026-33696: From a Schema Name to RCE in n8n
https://ift.tt/MFuR0Lj
Submitted 2026-08-16T13:33:02Z by TradeGold6317
via reddit https://ift.tt/KVTb40e
https://ift.tt/MFuR0Lj
Submitted 2026-08-16T13:33:02Z by TradeGold6317
via reddit https://ift.tt/KVTb40e
Simon Koeck
CVE-2026-33696: From a Schema Name to RCE in n8n | Simon Koeck
n8n uses a user-supplied schema name as a bare object key. Set it to __proto__, pollute the prototype, chain into RCE via the Git node. One request, full shell.
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling
https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
Submitted 2026-08-16T18:48:50Z by TheReedemer69
via reddit https://ift.tt/sZzVEHv
https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
Submitted 2026-08-16T18:48:50Z by TheReedemer69
via reddit https://ift.tt/sZzVEHv
minanagehsalalma.github.io
CVE-2026-6837: Zyxel export-cgi command injection + Full emulation guide
Technical writeup for CVE-2026-6837 covering the PKCS#12 export command-injection path, proof, affected models, and full emulation workflow.
AMA with Black Hat Speakers Lidor B. & Elad Meged (Pre-Auth RCE in Enterprise Java, Hijacking AI Coding Agents)
https://ift.tt/WNijy60
Submitted 2026-08-16T19:38:08Z by _cybersecurity_
via reddit https://ift.tt/B7PDlTq
https://ift.tt/WNijy60
Submitted 2026-08-16T19:38:08Z by _cybersecurity_
via reddit https://ift.tt/B7PDlTq
Substack
Breaking Enterprise Java; Breaking Claude Code, Gemini CLI, and Codex: AMA with Two Black Hat Speakers
Don’t miss the AMA with Black Hat speakers Lidor B.
They patched their SaaS and left the self-hosted OSS version vulnerable - AppFlowy Authenticated SQL Injection
https://ift.tt/xUCYvns
Submitted 2026-08-17T10:30:37Z by ezzzzz
via reddit https://ift.tt/VMDXgKk
https://ift.tt/xUCYvns
Submitted 2026-08-17T10:30:37Z by ezzzzz
via reddit https://ift.tt/VMDXgKk
Research Blog | Project Black
AppFlowy Authenticated SQL Injection
The actual bug isn't the interesting part in this case, it was the vendor's response - although it's crazy that we're still finding SQL injection in 2026.
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)
https://ift.tt/5ulFYzP
Submitted 2026-08-17T12:17:40Z by Master_Access_486
via reddit https://ift.tt/UKPfDkd
https://ift.tt/5ulFYzP
Submitted 2026-08-17T12:17:40Z by Master_Access_486
via reddit https://ift.tt/UKPfDkd
Rubrik
Breaking the M365 Copilot Sandbox with ChatMate | CXO Transformation
ChatMate, the first documented instance of remote prompt execution, shows how a malicious document can lead to sandbox escape.
Unauthenticated RCE in CircleCI's MCP server: Host/Origin allowlist bypassed by any non-browser client (GHSA-xv5j-cwgj-22r4)
https://ift.tt/fx1FytD
Submitted 2026-08-17T14:14:44Z by HyprWave
via reddit https://ift.tt/24r3GWB
https://ift.tt/fx1FytD
Submitted 2026-08-17T14:14:44Z by HyprWave
via reddit https://ift.tt/24r3GWB
Remedio
Unauthenticated RCE in CircleCI MCP Server Explained
Remedio discovered an unauthenticated RCE flaw in CircleCI's MCP server allowing for full pipeline takeover. Learn how and why it matters »
How Codex found replayable state transitions and a lost-update race in a Supabase browser game
https://ift.tt/KwV3oeb
Submitted 2026-08-17T16:45:14Z by SHMULC8
via reddit https://ift.tt/SIhupVO
https://ift.tt/KwV3oeb
Submitted 2026-08-17T16:45:14Z by SHMULC8
via reddit https://ift.tt/SIhupVO
Substack
How Many Exploits Does It Take to Turn an Egg into a Legendary Roc?
I found a cute game about refusing birds. So I told Codex it was a CTF, and it stopped playing by the rules
DeadLock ransomware: Rust-based encryptor with decentralized recovery infrastructure
https://ift.tt/oL7rFJP
Submitted 2026-08-18T00:06:58Z by Doug_Vitale
via reddit https://ift.tt/KtN35QU
https://ift.tt/oL7rFJP
Submitted 2026-08-18T00:06:58Z by Doug_Vitale
via reddit https://ift.tt/KtN35QU
Microsoft News
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion…
Git repo forensics: a seven-phase process for investigating suspicious commits
https://ift.tt/IOWoQ57
Submitted 2026-08-18T04:47:36Z by d3nika
via reddit https://ift.tt/68OpPy7
https://ift.tt/IOWoQ57
Submitted 2026-08-18T04:47:36Z by d3nika
via reddit https://ift.tt/68OpPy7
root-security.eu
Git Repo Forensics: My Seven Phases Investigation Process
My seven phase forensics process for investigating suspicious Git repositories: preserving evidence, analysing patch content and committer identity, confirmi...
Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design
https://ift.tt/qjeyPmZ
Submitted 2026-08-18T13:45:26Z by p80n-sec
via reddit https://ift.tt/UWStY59
https://ift.tt/qjeyPmZ
Submitted 2026-08-18T13:45:26Z by p80n-sec
via reddit https://ift.tt/UWStY59
Endorlabs
Hacking your life with AI can get you hacked | Blog | Endor Labs
Dissecting House of Apple 2 on modern glibc
https://jazho76.github.io/house_of_apple_2/
Submitted 2026-08-18T16:05:30Z by jpxzurich
via reddit https://ift.tt/oUSiv1V
https://jazho76.github.io/house_of_apple_2/
Submitted 2026-08-18T16:05:30Z by jpxzurich
via reddit https://ift.tt/oUSiv1V
🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia
https://ift.tt/piN2ArG
Submitted 2026-08-18T17:34:14Z by Straight-Practice-99
via reddit https://ift.tt/ezOtnKj
https://ift.tt/piN2ArG
Submitted 2026-08-18T17:34:14Z by Straight-Practice-99
via reddit https://ift.tt/ezOtnKj
hunt.io
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia
Hunt.io recovered a single operator's toolkit from an open directory: 14,530+ Dahua cameras compromised across Ukraine and Russia in 35 days. Inside the campaign