PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
https://ift.tt/i2Bc59t
Submitted 2026-08-26T18:50:56Z by acronis
via reddit https://ift.tt/ALowWvy
https://ift.tt/i2Bc59t
Submitted 2026-08-26T18:50:56Z by acronis
via reddit https://ift.tt/ALowWvy
Acronis
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
Acronis Threat Research Unit (TRU) has identified an ongoing campaign delivering a previously undocumented custom backdoor against Afghan telecom providers and South Asian critical infrastructure organizations. The backdoor, tracked as PATCHCORD, is a compiled…
LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation
https://ift.tt/mhjQyWV
Submitted 2026-08-27T15:21:53Z by AvenueJay
via reddit https://ift.tt/SOfXlHb
https://ift.tt/mhjQyWV
Submitted 2026-08-27T15:21:53Z by AvenueJay
via reddit https://ift.tt/SOfXlHb
www.elastic.co
The Cost of Understanding: LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation
Elastic Security Labs explores the ongoing arms race between LLM-driven reverse engineering and obfuscation.
A fake resume invoked China’s defence tech elite, then installed VShell
https://ift.tt/tFvIMur
Submitted 2026-08-27T15:43:21Z by unknownhad
via reddit https://ift.tt/uX4N1L6
https://ift.tt/tFvIMur
Submitted 2026-08-27T15:43:21Z by unknownhad
via reddit https://ift.tt/uX4N1L6
Himanshu Anand :: Security & Other Notes
a fake resume invoked China's defence-tech elite, then installed VShell
A fake resume claimed an applicant from one of China's Seven Sons of National Defence, then delivered a Go loader, SNOWLIGHT and a 4.65 MB fileless VShell payload.
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range
https://ift.tt/0rpcB8Z
Submitted 2026-08-27T20:44:41Z by WiseTuna
via reddit https://ift.tt/tRI2JFf
https://ift.tt/0rpcB8Z
Submitted 2026-08-27T20:44:41Z by WiseTuna
via reddit https://ift.tt/tRI2JFf
Boschko Security Blog
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range
Root on a $20,000 humanoid robot from Bluetooth range. One chain crossing Bluetooth, Unitree’s cloud, mobile, and the firmware running the G1 itself. Here’s the complete technical breakdown of the $6,700 bounty and two CVEs it produced: CVE-2026-76639 / CVE…
One Resident Login, an Entire Apartment Complex: The Master PIN in Rently's API (CVE-2026-75960)
https://ift.tt/gDIABjt
Submitted 2026-08-28T09:12:16Z by starsstripesfreedom
via reddit https://ift.tt/uYR7Fkj
https://ift.tt/gDIABjt
Submitted 2026-08-28T09:12:16Z by starsstripesfreedom
via reddit https://ift.tt/uYR7Fkj
Planck Proof
One Resident Login, an Entire Apartment Complex: The Master PIN in Rently's API (CVE-2026-75960)
The app showed two codes. The API returned all of them, master PIN included. The Planck Proof team's coordinated disclosure of CVE-2026-75960.
Slack will not patch this: one link opens a debugging port in the desktop app
https://ift.tt/TLHcIYm
Submitted 2026-08-28T10:04:02Z by trustsigRobert
via reddit https://ift.tt/ajZRG7r
https://ift.tt/TLHcIYm
Submitted 2026-08-28T10:04:02Z by trustsigRobert
via reddit https://ift.tt/ajZRG7r
trustsig.eu
Slack will not patch this: one link opens a debugging port in the desktop app
A link containing devEnv=dev1 makes the Slack desktop client relaunch itself into developer mode with --remote-debugging-port=8315. Anything that reaches that port drives the app. Slack's security team calls it not a security risk.
AI Agent Authentication in 2026: Web Bot Auth, ARD & OAuth
https://ift.tt/NXKnoQ8
Submitted 2026-08-30T15:10:36Z by cport1
via reddit https://ift.tt/4ZG2zWs
https://ift.tt/NXKnoQ8
Submitted 2026-08-30T15:10:36Z by cport1
via reddit https://ift.tt/4ZG2zWs
WebDecoy
AI Agent Authentication in 2026: Web Bot Auth, ARD & OAuth
How Web Bot Auth, ARD, OAuth, and workload identity fit together to authenticate AI agents, preserve user delegation, and create auditable access.
Anatomy of a ServiceNow Red Team
https://ift.tt/qYZROTG
Submitted 2026-08-30T16:46:45Z by gid0rah
via reddit https://ift.tt/WsjbdYE
https://ift.tt/qYZROTG
Submitted 2026-08-30T16:46:45Z by gid0rah
via reddit https://ift.tt/WsjbdYE
MDSec
When it Snows it Pours - Anatomy of a ServiceNow Red Team - MDSec
Introduction What if I told you six thousand of your employees were two steps removed from gaining full control over your IT infrastructure. If we told you this was related...
Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint
https://ift.tt/JgfehrS
Submitted 2026-08-31T07:40:42Z by 1046ica
via reddit https://ift.tt/gjdM23w
https://ift.tt/JgfehrS
Submitted 2026-08-31T07:40:42Z by 1046ica
via reddit https://ift.tt/gjdM23w
www.mannulinux.org
Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint
Learn Basic Concepts of Linux. Best site to learn Linux from beginner to Advanced.
Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models
https://clearbluejar.github.io/posts/does-abliteration-skew-your-bug-hunting/
Submitted 2026-09-01T05:08:07Z by onlinereadme
via reddit https://ift.tt/ygTvz2e
https://clearbluejar.github.io/posts/does-abliteration-skew-your-bug-hunting/
Submitted 2026-09-01T05:08:07Z by onlinereadme
via reddit https://ift.tt/ygTvz2e
clearbluejar
Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models
Abliterated models never refuse, which makes them tempting for bug hunting. But on the same kernel source, they graduate three to four times as many findings to VALID, including false positives the base correctly rejects, and across a 28-file scan of FreeBSD’s…
GeoNetwork - Pre-Auth RCE via Unauthenticated File Upload and Unsafe XSLT Processor (4 CVEs, 121 government deployments, all patched)
https://ift.tt/hEAWIg4
Submitted 2026-09-01T09:29:24Z by ZealousidealHunter80
via reddit https://ift.tt/cLrHQxJ
https://ift.tt/hEAWIg4
Submitted 2026-09-01T09:29:24Z by ZealousidealHunter80
via reddit https://ift.tt/cLrHQxJ
Ethiack
GeoNetwork - PreAuth Remote Code Execution | Ethiack — Autonomous Ethical Hacking for continuous security
How a missing @PreAuthorize line in GeoNetwork led to unauthenticated Remote Code Execution across government geospatial infrastructure in 39 countries.
Authentication bypass in EOL Proxmox VE 7 release
https://ift.tt/aZcbB5P
Submitted 2026-09-01T12:25:06Z by WiuEmPe
via reddit https://ift.tt/0nzUdJw
https://ift.tt/aZcbB5P
Submitted 2026-09-01T12:25:06Z by WiuEmPe
via reddit https://ift.tt/0nzUdJw
Proxmox Support Forum
Proxmox Virtual Environment - Security Advisories
Subject: PSA-2026-00037-1: SCTPhantom Local Privilege Escalation issue
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A use-after-free issue in the Linux kernels SCTP code...
Advisory date: 2026-08-10
Packages: proxmox-kernel-*
Details:
A use-after-free issue in the Linux kernels SCTP code...
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
https://ift.tt/aUCQNxg
Submitted 2026-09-01T12:28:03Z by scopedsecurity
via reddit https://ift.tt/s9GdHog
https://ift.tt/aUCQNxg
Submitted 2026-09-01T12:28:03Z by scopedsecurity
via reddit https://ift.tt/s9GdHog
Horizon3
CVE-2026-9586: Sangoma Switchvox RCE
Horizon3 researchers detail CVE-2026-9586, a critical Switchvox SQL injection leading to RCE, with active exploitation observed in the wild.
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted 2026-09-01T13:29:15Z by albinowax
via reddit https://ift.tt/4WBL89j
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted 2026-09-01T13:29:15Z by albinowax
via reddit https://ift.tt/4WBL89j
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG
https://ift.tt/ZkBITpJ
Submitted 2026-09-01T14:39:16Z by kev-thehermit
via reddit https://ift.tt/j4yfFe7
https://ift.tt/ZkBITpJ
Submitted 2026-09-01T14:39:16Z by kev-thehermit
via reddit https://ift.tt/j4yfFe7
The Validator Can Lie: SSRF Beyond URL Validation (GitLab, Mealie, Apache ShenYu, Thumbor)
https://ift.tt/UCx4yX3
Submitted 2026-09-02T17:47:32Z by Xclow3n_
via reddit https://ift.tt/aWJBlE4
https://ift.tt/UCx4yX3
Submitted 2026-09-02T17:47:32Z by Xclow3n_
via reddit https://ift.tt/aWJBlE4
xclow3n
The Validator Can Lie: SSRF Beyond URL Validation · xclow3n
A URL validator does not validate a request. It validates one representation of a request at one moment. Thirteen language stacks, twelve bug families, and live product cases - changedetection.io reaching IMDS, GitLab discarding its own DNS pin, Mealie approving…
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556)
https://ift.tt/1yaTk9M
Submitted 2026-09-02T19:49:38Z by ciphersecuritylabs
via reddit https://ift.tt/9K0feDk
https://ift.tt/1yaTk9M
Submitted 2026-09-02T19:49:38Z by ciphersecuritylabs
via reddit https://ift.tt/9K0feDk
Ciphersecuritylabs
cipher security labs
cipher security labs performs deep technical security research across real-world software, systems, and adversarial techniques.
QR Phishing With No Image: Text-Only QR Codes for Inboxes w/ Images Disabled
https://ift.tt/rdOqknX
Submitted 2026-09-02T22:32:23Z by redwheel82
via reddit https://ift.tt/PGK3dRp
https://ift.tt/rdOqknX
Submitted 2026-09-02T22:32:23Z by redwheel82
via reddit https://ift.tt/PGK3dRp
PhishU
QR Phishing With No Image: Text-Rendered QR Codes in the PhishU Framework
A QR code built from markup instead of an image gives email filters nothing to scan. Here is how the technique works and what it took to ship it reliably.
From fake interview to signed ClickOnce: inside a three-payload Windows chain(Part 2)
https://ift.tt/iNqmRoL
Submitted 2026-09-04T08:40:27Z by JDBHub
via reddit https://ift.tt/Nbhj95i
https://ift.tt/iNqmRoL
Submitted 2026-09-04T08:40:27Z by JDBHub
via reddit https://ift.tt/Nbhj95i
Have I Been Squatted
GAPIUpdate delivers Odyssey Stealer on macOS - Have I Been Squatted
Analysis of GAPIUpdate.dmg, its macOS execution chain, Odyssey Stealer C2 infrastructure, wallet replacement, and 27 related GitHub DMGs.
Getting Agents to tell on themselves
https://ift.tt/hymTQHL
Submitted 2026-09-04T14:29:57Z by thinkst
via reddit https://ift.tt/ceFs1Zn
https://ift.tt/hymTQHL
Submitted 2026-09-04T14:29:57Z by thinkst
via reddit https://ift.tt/ceFs1Zn
Thinkst Thoughts
Getting Agents to tell on themselves
AI powered agentic attacks are scary, but agents are particularly “suggestible” allowing us to both detect and derail them
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you
https://ift.tt/rVfXWRO
Submitted 2026-09-04T15:32:57Z by rukhrunnin
via reddit https://ift.tt/xEYXiGl
https://ift.tt/rVfXWRO
Submitted 2026-09-04T15:32:57Z by rukhrunnin
via reddit https://ift.tt/xEYXiGl
Optimus Labs
When the Supply-Chain Attack Has No CVE: Inside the Coder Registry Hijack
Coder's own delivery infrastructure was hijacked to serve credential-stealing modules from the real registry.coder.com. No CVE, no poisoned package, nothing for a scanner to match.