Finding Hidden Internal Apps Through Public Certificate Logs
https://ift.tt/bkA9q82
Submitted 2026-08-15T13:39:43Z by Huge-Wear-125
via reddit https://ift.tt/zmCtDl7
https://ift.tt/bkA9q82
Submitted 2026-08-15T13:39:43Z by Huge-Wear-125
via reddit https://ift.tt/zmCtDl7
naveen srinivasan
Finding Hidden Internal Apps Through Public Certificate Logs
Here is how anyone can unwrap the organization’s internal tools/products that no one is supposed to know about.
Typically, in software organizations, most of us don’t want to share internal applications on the internet, but we unintentionally share application…
Typically, in software organizations, most of us don’t want to share internal applications on the internet, but we unintentionally share application…
CVE-2026-33696: From a Schema Name to RCE in n8n
https://ift.tt/MFuR0Lj
Submitted 2026-08-16T13:33:02Z by TradeGold6317
via reddit https://ift.tt/KVTb40e
https://ift.tt/MFuR0Lj
Submitted 2026-08-16T13:33:02Z by TradeGold6317
via reddit https://ift.tt/KVTb40e
Simon Koeck
CVE-2026-33696: From a Schema Name to RCE in n8n | Simon Koeck
n8n uses a user-supplied schema name as a bare object key. Set it to __proto__, pollute the prototype, chain into RCE via the Git node. One request, full shell.
CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling
https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
Submitted 2026-08-16T18:48:50Z by TheReedemer69
via reddit https://ift.tt/sZzVEHv
https://minanagehsalalma.github.io/CVE-2026-6837-zyxel-export-cgi-command-injection/
Submitted 2026-08-16T18:48:50Z by TheReedemer69
via reddit https://ift.tt/sZzVEHv
minanagehsalalma.github.io
CVE-2026-6837: Zyxel export-cgi command injection + Full emulation guide
Technical writeup for CVE-2026-6837 covering the PKCS#12 export command-injection path, proof, affected models, and full emulation workflow.
AMA with Black Hat Speakers Lidor B. & Elad Meged (Pre-Auth RCE in Enterprise Java, Hijacking AI Coding Agents)
https://ift.tt/WNijy60
Submitted 2026-08-16T19:38:08Z by _cybersecurity_
via reddit https://ift.tt/B7PDlTq
https://ift.tt/WNijy60
Submitted 2026-08-16T19:38:08Z by _cybersecurity_
via reddit https://ift.tt/B7PDlTq
Substack
Breaking Enterprise Java; Breaking Claude Code, Gemini CLI, and Codex: AMA with Two Black Hat Speakers
Don’t miss the AMA with Black Hat speakers Lidor B.
They patched their SaaS and left the self-hosted OSS version vulnerable - AppFlowy Authenticated SQL Injection
https://ift.tt/xUCYvns
Submitted 2026-08-17T10:30:37Z by ezzzzz
via reddit https://ift.tt/VMDXgKk
https://ift.tt/xUCYvns
Submitted 2026-08-17T10:30:37Z by ezzzzz
via reddit https://ift.tt/VMDXgKk
Research Blog | Project Black
AppFlowy Authenticated SQL Injection
The actual bug isn't the interesting part in this case, it was the vendor's response - although it's crazy that we're still finding SQL injection in 2026.
From AKS node root vulnerability to Microsoft Copilot hijack (CVE-2026-32193)
https://ift.tt/5ulFYzP
Submitted 2026-08-17T12:17:40Z by Master_Access_486
via reddit https://ift.tt/UKPfDkd
https://ift.tt/5ulFYzP
Submitted 2026-08-17T12:17:40Z by Master_Access_486
via reddit https://ift.tt/UKPfDkd
Rubrik
Breaking the M365 Copilot Sandbox with ChatMate | CXO Transformation
ChatMate, the first documented instance of remote prompt execution, shows how a malicious document can lead to sandbox escape.
Unauthenticated RCE in CircleCI's MCP server: Host/Origin allowlist bypassed by any non-browser client (GHSA-xv5j-cwgj-22r4)
https://ift.tt/fx1FytD
Submitted 2026-08-17T14:14:44Z by HyprWave
via reddit https://ift.tt/24r3GWB
https://ift.tt/fx1FytD
Submitted 2026-08-17T14:14:44Z by HyprWave
via reddit https://ift.tt/24r3GWB
Remedio
Unauthenticated RCE in CircleCI MCP Server Explained
Remedio discovered an unauthenticated RCE flaw in CircleCI's MCP server allowing for full pipeline takeover. Learn how and why it matters »
How Codex found replayable state transitions and a lost-update race in a Supabase browser game
https://ift.tt/KwV3oeb
Submitted 2026-08-17T16:45:14Z by SHMULC8
via reddit https://ift.tt/SIhupVO
https://ift.tt/KwV3oeb
Submitted 2026-08-17T16:45:14Z by SHMULC8
via reddit https://ift.tt/SIhupVO
Substack
How Many Exploits Does It Take to Turn an Egg into a Legendary Roc?
I found a cute game about refusing birds. So I told Codex it was a CTF, and it stopped playing by the rules
DeadLock ransomware: Rust-based encryptor with decentralized recovery infrastructure
https://ift.tt/oL7rFJP
Submitted 2026-08-18T00:06:58Z by Doug_Vitale
via reddit https://ift.tt/KtN35QU
https://ift.tt/oL7rFJP
Submitted 2026-08-18T00:06:58Z by Doug_Vitale
via reddit https://ift.tt/KtN35QU
Microsoft News
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion…
Git repo forensics: a seven-phase process for investigating suspicious commits
https://ift.tt/IOWoQ57
Submitted 2026-08-18T04:47:36Z by d3nika
via reddit https://ift.tt/68OpPy7
https://ift.tt/IOWoQ57
Submitted 2026-08-18T04:47:36Z by d3nika
via reddit https://ift.tt/68OpPy7
root-security.eu
Git Repo Forensics: My Seven Phases Investigation Process
My seven phase forensics process for investigating suspicious Git repositories: preserving evidence, analysing patch content and committer identity, confirmi...
Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design
https://ift.tt/qjeyPmZ
Submitted 2026-08-18T13:45:26Z by p80n-sec
via reddit https://ift.tt/UWStY59
https://ift.tt/qjeyPmZ
Submitted 2026-08-18T13:45:26Z by p80n-sec
via reddit https://ift.tt/UWStY59
Endorlabs
Hacking your life with AI can get you hacked | Blog | Endor Labs
Dissecting House of Apple 2 on modern glibc
https://jazho76.github.io/house_of_apple_2/
Submitted 2026-08-18T16:05:30Z by jpxzurich
via reddit https://ift.tt/oUSiv1V
https://jazho76.github.io/house_of_apple_2/
Submitted 2026-08-18T16:05:30Z by jpxzurich
via reddit https://ift.tt/oUSiv1V
🎥 Operation CameraSwarm: over 14,000 Dahua cameras compromised across Ukraine and Russia
https://ift.tt/piN2ArG
Submitted 2026-08-18T17:34:14Z by Straight-Practice-99
via reddit https://ift.tt/ezOtnKj
https://ift.tt/piN2ArG
Submitted 2026-08-18T17:34:14Z by Straight-Practice-99
via reddit https://ift.tt/ezOtnKj
hunt.io
Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia
Hunt.io recovered a single operator's toolkit from an open directory: 14,530+ Dahua cameras compromised across Ukraine and Russia in 35 days. Inside the campaign
prompt injection containment as a structural property instead of a detector (interactive, real code, no llm)
https://meghavi.me/gate
Submitted 2026-08-18T17:47:11Z by Pretend_Glass_1232
via reddit https://ift.tt/VkJt1g9
https://meghavi.me/gate
Submitted 2026-08-18T17:47:11Z by Pretend_Glass_1232
via reddit https://ift.tt/VkJt1g9
Meghavi Rao
The Front Door — can you make my AI agent obey you?
AI agents take orders from other AI agents. Mine won't. Try to break it.
How a popular Android library silently exposed thousands of apps to Arbitrary File Overwrite (AFO). https://itis911.github.io/writeups/cropper-vulnerability.html
https://itis911.github.io/writeups/cropper-vulnerability.html
Submitted 2026-08-18T16:24:33Z by Fit_Veterinarian4403
via reddit https://ift.tt/cHeKYrL
https://itis911.github.io/writeups/cropper-vulnerability.html
Submitted 2026-08-18T16:24:33Z by Fit_Veterinarian4403
via reddit https://ift.tt/cHeKYrL
Reddit
From the netsec community on Reddit: How a popular Android library silently exposed thousands of apps to Arbitrary File Overwrite…
Posted by Fit_Veterinarian4403 - 0 votes and 0 comments
Kimi Desktop Ships With an Updater That Can Install Unverified Code
https://ift.tt/2oJWuCq
Submitted 2026-08-18T23:27:51Z by ryanmerket
via reddit https://ift.tt/ikcsqCH
https://ift.tt/2oJWuCq
Submitted 2026-08-18T23:27:51Z by ryanmerket
via reddit https://ift.tt/ikcsqCH
RuntimeWire
Kimi Desktop Ships With a Group Chat Updater That Can Install Unverified Code
Kimi Desktop's Windows group-chat updater downloads an executable and agent instructions from mutable locations without enforcing Moonshot's code signature.
When Burp Suite Isn't Enough: Intercepting Thick Client Traffic
https://ift.tt/SPIyJq2
Submitted 2026-08-19T03:45:57Z by Ano_F
via reddit https://ift.tt/QdDapuG
https://ift.tt/SPIyJq2
Submitted 2026-08-19T03:45:57Z by Ano_F
via reddit https://ift.tt/QdDapuG
Interceptsuite
When Burp Suite Isn't Enough: Intercepting Thick Client Traffic | InterceptSuite
Burp Suite is built for HTTP. When you're testing a thick client that speaks raw TCP, TLS, or a custom binary protocol, you need a different tool. Here's how to intercept non-HTTP thick client traffic with InterceptSuite.
The Curious Incidents with DNS in the Sandbox at Escape-Time
https://ift.tt/BM5tkEP
Submitted 2026-08-19T03:58:53Z by lowlevelprog
via reddit https://ift.tt/1odOKbL
https://ift.tt/BM5tkEP
Submitted 2026-08-19T03:58:53Z by lowlevelprog
via reddit https://ift.tt/1odOKbL
Chasersystems
The Curious Incidents with DNS in the Sandbox at Escape-Time | Chaser Systems
What the Agent attempted with DNS in the Hugging Face–OpenAI Intrusion Incident of July 2026
How to break secure boot without touching any cryptography
https://ift.tt/KOpdh8m
Submitted 2026-08-19T12:01:19Z by 0x00rick
via reddit https://ift.tt/WyQkioq
https://ift.tt/KOpdh8m
Submitted 2026-08-19T12:01:19Z by 0x00rick
via reddit https://ift.tt/WyQkioq
Low-level adventures
Breaking secure boot without breaking the crypto
This will be mostly rambling disguised as a technical walkthrough. I will touch on certain topics such as hardware roots of trust, signed image formats, Qualcomm boot stages, Android Verified Boot, UEFI, measured boot, and remote evidence (remote attestation).…
CRLF-Powered Desync Attacks: Beheading HTTP Streams
https://ift.tt/PeLy6BI
Submitted 2026-08-19T12:58:25Z by t0xodile
via reddit https://ift.tt/fsgyJkn
https://ift.tt/PeLy6BI
Submitted 2026-08-19T12:58:25Z by t0xodile
via reddit https://ift.tt/fsgyJkn
PortSwigger Research
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
ValleyRAT campaign uses fake GSTR-3B overdue notice targeting Indian taxpayers
https://ift.tt/nGIDjOB
Submitted 2026-08-19T13:18:26Z by unknownhad
via reddit https://ift.tt/MYJLkPK
https://ift.tt/nGIDjOB
Submitted 2026-08-19T13:18:26Z by unknownhad
via reddit https://ift.tt/MYJLkPK
Himanshu Anand :: Security & Other Notes
someone is filing your GST return, and it is not your CA
Disclosure: this research was conducted using an ANY.RUN account provided as part of a collaboration. All analysis and conclusions are my own.
TLDR Found an unreported Silver Fox campaign serving ValleyRAT to Indian taxpayers with a fake “GSTR-3B overdue”…
TLDR Found an unreported Silver Fox campaign serving ValleyRAT to Indian taxpayers with a fake “GSTR-3B overdue”…