The Curious Incidents with DNS in the Sandbox at Escape-Time
https://ift.tt/BM5tkEP
Submitted 2026-08-19T03:58:53Z by lowlevelprog
via reddit https://ift.tt/1odOKbL
https://ift.tt/BM5tkEP
Submitted 2026-08-19T03:58:53Z by lowlevelprog
via reddit https://ift.tt/1odOKbL
Chasersystems
The Curious Incidents with DNS in the Sandbox at Escape-Time | Chaser Systems
What the Agent attempted with DNS in the Hugging Face–OpenAI Intrusion Incident of July 2026
How to break secure boot without touching any cryptography
https://ift.tt/KOpdh8m
Submitted 2026-08-19T12:01:19Z by 0x00rick
via reddit https://ift.tt/WyQkioq
https://ift.tt/KOpdh8m
Submitted 2026-08-19T12:01:19Z by 0x00rick
via reddit https://ift.tt/WyQkioq
Low-level adventures
Breaking secure boot without breaking the crypto
This will be mostly rambling disguised as a technical walkthrough. I will touch on certain topics such as hardware roots of trust, signed image formats, Qualcomm boot stages, Android Verified Boot, UEFI, measured boot, and remote evidence (remote attestation).…
CRLF-Powered Desync Attacks: Beheading HTTP Streams
https://ift.tt/PeLy6BI
Submitted 2026-08-19T12:58:25Z by t0xodile
via reddit https://ift.tt/fsgyJkn
https://ift.tt/PeLy6BI
Submitted 2026-08-19T12:58:25Z by t0xodile
via reddit https://ift.tt/fsgyJkn
PortSwigger Research
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
ValleyRAT campaign uses fake GSTR-3B overdue notice targeting Indian taxpayers
https://ift.tt/nGIDjOB
Submitted 2026-08-19T13:18:26Z by unknownhad
via reddit https://ift.tt/MYJLkPK
https://ift.tt/nGIDjOB
Submitted 2026-08-19T13:18:26Z by unknownhad
via reddit https://ift.tt/MYJLkPK
Himanshu Anand :: Security & Other Notes
someone is filing your GST return, and it is not your CA
Disclosure: this research was conducted using an ANY.RUN account provided as part of a collaboration. All analysis and conclusions are my own.
TLDR Found an unreported Silver Fox campaign serving ValleyRAT to Indian taxpayers with a fake “GSTR-3B overdue”…
TLDR Found an unreported Silver Fox campaign serving ValleyRAT to Indian taxpayers with a fake “GSTR-3B overdue”…
I escaped the WebAssembly's sandbox and got arbitrary shell execution on the host.
https://ift.tt/UChpW3K
Submitted 2026-08-19T15:54:04Z by trustsigRobert
via reddit https://ift.tt/v7xb8Eh
https://ift.tt/UChpW3K
Submitted 2026-08-19T15:54:04Z by trustsigRobert
via reddit https://ift.tt/v7xb8Eh
trustsig.eu
Table flip: a wasm2c guest runs a shell command on the host, through one unchecked calloc
wasm2c sets a table's size from the element count the guest declared, then ignores whether the allocation succeeded. Make it fail and every table index becomes an absolute address on the host.
Iran's Mabna Institute ran a 3-phase spearphishing campaign against university professors for a decade. The 50-page superseding indictment has more methodological detail than the press coverage suggests.
https://ift.tt/GaNSEQl
Submitted 2026-08-19T16:34:25Z by Robert-Nogacki
via reddit https://ift.tt/nL9bR7p
https://ift.tt/GaNSEQl
Submitted 2026-08-19T16:34:25Z by Robert-Nogacki
via reddit https://ift.tt/nL9bR7p
Kancelaria Prawna Skarbiec
17 Iranians Indicted for $3.4 Billion Academic Hack
Federal indictment charges 17 members of Iran's Mabna Institute with stealing $3.4B in research from 322 universities in 22 countries.
Hacking SAML with Claude Code
https://ift.tt/xbauAhj
Submitted 2026-08-19T18:40:47Z by ericchiang
via reddit https://ift.tt/h3pLY9b
https://ift.tt/xbauAhj
Submitted 2026-08-19T18:40:47Z by ericchiang
via reddit https://ift.tt/h3pLY9b
Oblique
Hacking SAML with Claude Code | Oblique
After many years of complaining about how insecure SAML is, I decided to try to prove it by using Claude Code to hack every SAML implementation I could find.
Graphing AWS Attack Paths in Bloodhound
https://ift.tt/xPshKkw
Submitted 2026-08-19T20:26:22Z by n0pe_sled
via reddit https://ift.tt/yMnjul1
https://ift.tt/xPshKkw
Submitted 2026-08-19T20:26:22Z by n0pe_sled
via reddit https://ift.tt/yMnjul1
n0pe-sled
AWSHound: An Open-Source AWS OpenGraph Collector
A free, read-only collector that turns an AWS account or Organization into a BloodHound OpenGraph dataset, drawing edges only where an offline IAM evaluation resolves to Allow.
GLM-5.3's emergent security capabilities: 1,097 critical/high severity bugs discovered across kernels, browsers, and infrastructure, oldest flaw from 1981
https://ift.tt/63cwNvB
Submitted 2026-08-20T12:48:26Z by Sinver_Nightingale27
via reddit https://ift.tt/DI4chNz
https://ift.tt/63cwNvB
Submitted 2026-08-20T12:48:26Z by Sinver_Nightingale27
via reddit https://ift.tt/DI4chNz
Tata’s B2B platform returned OTPs in API responses
https://ift.tt/BPgRGzc
Submitted 2026-08-24T14:33:25Z by EatonZ
via reddit https://ift.tt/EtI1TAk
https://ift.tt/BPgRGzc
Submitted 2026-08-24T14:33:25Z by EatonZ
via reddit https://ift.tt/EtI1TAk
Eaton-Works
Tata’s B2B platform returned OTPs in API responses
Tata’s nexarc platform had a vulnerability where OTPs could be decrypted from API responses, making it easy to take over any account.
Code Execution via Text Template Files | Playbook & Detection
https://ipurple.team/2026/08/24/text-template/
Submitted 2026-08-24T16:01:49Z by netbiosX
via reddit https://ift.tt/pnx1yPM
https://ipurple.team/2026/08/24/text-template/
Submitted 2026-08-24T16:01:49Z by netbiosX
via reddit https://ift.tt/pnx1yPM
Purple Team
Text Template
Text template files can contain C# or Visual Basic code that could be compiled and executed at build time. Threat actors can create or modify .tt files to execute code in the context of a trusted p…
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
https://ift.tt/zH1dOuR
Submitted 2026-08-24T21:00:38Z by Ok-Bed5648
via reddit https://ift.tt/crEKaed
https://ift.tt/zH1dOuR
Submitted 2026-08-24T21:00:38Z by Ok-Bed5648
via reddit https://ift.tt/crEKaed
The Citizen Lab
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit…
Insight into agentic hacking tools: Hermes, OpenClaw and the Bayesian brain
https://ift.tt/6yTlqEb
Submitted 2026-08-24T21:27:14Z by Ok-Bed5648
via reddit https://ift.tt/QgPpSks
https://ift.tt/6yTlqEb
Submitted 2026-08-24T21:27:14Z by Ok-Bed5648
via reddit https://ift.tt/QgPpSks
Dreamgroup
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia | | Dream Security Blog
Local Privilege Escalation To System In Wibu-Systems CodeMeter Application
https://ift.tt/1ybiQCO
Submitted 2026-08-25T10:41:27Z by dr-w0bbinat0rz
via reddit https://ift.tt/dr0a57y
https://ift.tt/1ybiQCO
Submitted 2026-08-25T10:41:27Z by dr-w0bbinat0rz
via reddit https://ift.tt/dr0a57y
Shelltrail
Local Privilege Escalation To System In Wibu-Systems CodeMeter Application | Shelltrail
This research post describes the process of finding and exploiting a local privilege escalation in the Wibu-Systems CodeMeter application
CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling
https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/
Submitted 2026-08-25T13:37:06Z by TheReedemer69
via reddit https://ift.tt/fXJHB8O
https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/
Submitted 2026-08-25T13:37:06Z by TheReedemer69
via reddit https://ift.tt/fXJHB8O
minanagehsalalma.github.io
CVE-2026-8508: Zyxel captive-portal bypass + Full emulation guide
Technical writeup for CVE-2026-8508 covering the social-login bypass path, affected models, proof, and full captive-portal emulation workflow.
Pwning Call of Duty 1: a 20-year-old RCE, found in an evening with AI
https://ift.tt/VlxBvMP
Submitted 2026-08-25T17:14:25Z by wez32
via reddit https://ift.tt/2i56LRX
https://ift.tt/VlxBvMP
Submitted 2026-08-25T17:14:25Z by wez32
via reddit https://ift.tt/2i56LRX
Zolder
Pwning Call of Duty 1: a 20-year-old RCE, found in an evening with AI
A memory-corruption RCE in the Call of Duty 1 dedicated server, a binary that has been on the internet for two decades, found and weaponized in a single evening with an AI agent driving the disassembly.
Unauthenticated remote uninstall in my own EDR agent, and the four other auth bugs that turned out to be the same bug
https://d3vhex.github.io/2026-08-25-unauthenticated-remote-uninstall/
Submitted 2026-08-25T19:26:25Z by RevolutionaryPie4948
via reddit https://ift.tt/HkE01nL
https://d3vhex.github.io/2026-08-25-unauthenticated-remote-uninstall/
Submitted 2026-08-25T19:26:25Z by RevolutionaryPie4948
via reddit https://ift.tt/HkE01nL
Oğuz
Unauthenticated remote uninstall in my own EDR agent, and the four other auth bugs that turned out to be the same bug
A postmortem on my own EDR: no auth on self-destruct, permissive agent keys, forged automation results, LDAP injection, and 8 routes with no authorization check.