Insight into agentic hacking tools: Hermes, OpenClaw and the Bayesian brain
https://ift.tt/6yTlqEb
Submitted 2026-08-24T21:27:14Z by Ok-Bed5648
via reddit https://ift.tt/QgPpSks
https://ift.tt/6yTlqEb
Submitted 2026-08-24T21:27:14Z by Ok-Bed5648
via reddit https://ift.tt/QgPpSks
Dreamgroup
Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia | | Dream Security Blog
Local Privilege Escalation To System In Wibu-Systems CodeMeter Application
https://ift.tt/1ybiQCO
Submitted 2026-08-25T10:41:27Z by dr-w0bbinat0rz
via reddit https://ift.tt/dr0a57y
https://ift.tt/1ybiQCO
Submitted 2026-08-25T10:41:27Z by dr-w0bbinat0rz
via reddit https://ift.tt/dr0a57y
Shelltrail
Local Privilege Escalation To System In Wibu-Systems CodeMeter Application | Shelltrail
This research post describes the process of finding and exploiting a local privilege escalation in the Wibu-Systems CodeMeter application
CVE-2026-8508: Trust-Boundary Bypass in Zyxel social_login.cgi Facebook Identity Handling
https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/
Submitted 2026-08-25T13:37:06Z by TheReedemer69
via reddit https://ift.tt/fXJHB8O
https://minanagehsalalma.github.io/zyxel-social-login-bypass-cve-2026-8508/
Submitted 2026-08-25T13:37:06Z by TheReedemer69
via reddit https://ift.tt/fXJHB8O
minanagehsalalma.github.io
CVE-2026-8508: Zyxel captive-portal bypass + Full emulation guide
Technical writeup for CVE-2026-8508 covering the social-login bypass path, affected models, proof, and full captive-portal emulation workflow.
Pwning Call of Duty 1: a 20-year-old RCE, found in an evening with AI
https://ift.tt/VlxBvMP
Submitted 2026-08-25T17:14:25Z by wez32
via reddit https://ift.tt/2i56LRX
https://ift.tt/VlxBvMP
Submitted 2026-08-25T17:14:25Z by wez32
via reddit https://ift.tt/2i56LRX
Zolder
Pwning Call of Duty 1: a 20-year-old RCE, found in an evening with AI
A memory-corruption RCE in the Call of Duty 1 dedicated server, a binary that has been on the internet for two decades, found and weaponized in a single evening with an AI agent driving the disassembly.
Unauthenticated remote uninstall in my own EDR agent, and the four other auth bugs that turned out to be the same bug
https://d3vhex.github.io/2026-08-25-unauthenticated-remote-uninstall/
Submitted 2026-08-25T19:26:25Z by RevolutionaryPie4948
via reddit https://ift.tt/HkE01nL
https://d3vhex.github.io/2026-08-25-unauthenticated-remote-uninstall/
Submitted 2026-08-25T19:26:25Z by RevolutionaryPie4948
via reddit https://ift.tt/HkE01nL
Oğuz
Unauthenticated remote uninstall in my own EDR agent, and the four other auth bugs that turned out to be the same bug
A postmortem on my own EDR: no auth on self-destruct, permissive agent keys, forged automation results, LDAP injection, and 8 routes with no authorization check.
Ruby Marshal Kick-off Gadgets - elttam
https://ift.tt/p7CsYTS
Submitted 2026-08-26T06:06:26Z by AnimalStrange
via reddit https://ift.tt/R1LDOEp
https://ift.tt/p7CsYTS
Submitted 2026-08-26T06:06:26Z by AnimalStrange
via reddit https://ift.tt/R1LDOEp
Elttam
Ruby Marshal Kick-off Gadgets - elttam
This post surveys everything Marshal.load calls on its own, on Ruby 4.0.6, and finds six kick-off gadgets, hash, eql?, <=>, to_str, to_s and respond_to?, that were never written for deserialisation and can't be hardened away like marshal_load.
How Arena.ai can potentially leak your PII
https://ift.tt/WO2mNvX
Submitted 2026-08-26T06:51:50Z by Top_Dinner_9121
via reddit https://ift.tt/bkut1Hq
https://ift.tt/WO2mNvX
Submitted 2026-08-26T06:51:50Z by Top_Dinner_9121
via reddit https://ift.tt/bkut1Hq
Cjeremy
Arena PII Exfiltration: The agent who leaks your data · CJeremy
Well, this sounds awkward.
☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator
https://ift.tt/65TJSm9
Submitted 2026-08-26T13:59:47Z by Straight-Practice-99
via reddit https://ift.tt/f5aDA7r
https://ift.tt/65TJSm9
Submitted 2026-08-26T13:59:47Z by Straight-Practice-99
via reddit https://ift.tt/f5aDA7r
hunt.io
Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
An exposed staging server reveals ownCloud pre-signed URL abuse against a Philippine nuclear agency and exploitation of a naval contractor's WordPress website.
Chaining three public V8 bugs to escape the V8 sandbox and recover a real Google v8CTF flag
https://ift.tt/eFZrqPc
Submitted 2026-08-26T15:09:44Z by unknownhad
via reddit https://ift.tt/0PMCnYm
https://ift.tt/eFZrqPc
Submitted 2026-08-26T15:09:44Z by unknownhad
via reddit https://ift.tt/0PMCnYm
Himanshu Anand :: Security & Other Notes
I had some free time, so I tried to pwn V8
How I chained three public V8 bugs against Google's v8CTF, escaped the V8 sandbox, printed a real flag, and still received no bounty.
Minimus is shutting down after raising $51M, Twistlock founders returning cash to investors
https://ift.tt/NUSxyHj
Submitted 2026-08-26T17:55:39Z by DakPrescottQBDraw
via reddit https://ift.tt/7oV1rSB
https://ift.tt/NUSxyHj
Submitted 2026-08-26T17:55:39Z by DakPrescottQBDraw
via reddit https://ift.tt/7oV1rSB
ctech
After raising $51 million, Minimus shuts down as Twistlock founders return remaining cash to investors
The cybersecurity startup failed to gain enough commercial momentum to continue operating. Customers will have 60 days to migrate before the company's registry is switched off.
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
https://ift.tt/i2Bc59t
Submitted 2026-08-26T18:50:56Z by acronis
via reddit https://ift.tt/ALowWvy
https://ift.tt/i2Bc59t
Submitted 2026-08-26T18:50:56Z by acronis
via reddit https://ift.tt/ALowWvy
Acronis
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled…