r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted 2026-09-01T13:29:15Z by albinowax
via reddit https://ift.tt/4WBL89j
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted 2026-09-01T13:29:15Z by albinowax
via reddit https://ift.tt/4WBL89j
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG
https://ift.tt/ZkBITpJ
Submitted 2026-09-01T14:39:16Z by kev-thehermit
via reddit https://ift.tt/j4yfFe7
https://ift.tt/ZkBITpJ
Submitted 2026-09-01T14:39:16Z by kev-thehermit
via reddit https://ift.tt/j4yfFe7
The Validator Can Lie: SSRF Beyond URL Validation (GitLab, Mealie, Apache ShenYu, Thumbor)
https://ift.tt/UCx4yX3
Submitted 2026-09-02T17:47:32Z by Xclow3n_
via reddit https://ift.tt/aWJBlE4
https://ift.tt/UCx4yX3
Submitted 2026-09-02T17:47:32Z by Xclow3n_
via reddit https://ift.tt/aWJBlE4
xclow3n
The Validator Can Lie: SSRF Beyond URL Validation · xclow3n
A URL validator does not validate a request. It validates one representation of a request at one moment. Thirteen language stacks, twelve bug families, and live product cases - changedetection.io reaching IMDS, GitLab discarding its own DNS pin, Mealie approving…
Rooted in Trust: Three privilege-escalation vulnerabilities in HP Easy Start for macOS (CVE-2026-12554, CVE-2026-12555, CVE-2026-12556)
https://ift.tt/1yaTk9M
Submitted 2026-09-02T19:49:38Z by ciphersecuritylabs
via reddit https://ift.tt/9K0feDk
https://ift.tt/1yaTk9M
Submitted 2026-09-02T19:49:38Z by ciphersecuritylabs
via reddit https://ift.tt/9K0feDk
Ciphersecuritylabs
cipher security labs
cipher security labs performs deep technical security research across real-world software, systems, and adversarial techniques.
QR Phishing With No Image: Text-Only QR Codes for Inboxes w/ Images Disabled
https://ift.tt/rdOqknX
Submitted 2026-09-02T22:32:23Z by redwheel82
via reddit https://ift.tt/PGK3dRp
https://ift.tt/rdOqknX
Submitted 2026-09-02T22:32:23Z by redwheel82
via reddit https://ift.tt/PGK3dRp
PhishU
QR Phishing With No Image: Text-Rendered QR Codes in the PhishU Framework
A QR code built from markup instead of an image gives email filters nothing to scan. Here is how the technique works and what it took to ship it reliably.
From fake interview to signed ClickOnce: inside a three-payload Windows chain(Part 2)
https://ift.tt/iNqmRoL
Submitted 2026-09-04T08:40:27Z by JDBHub
via reddit https://ift.tt/Nbhj95i
https://ift.tt/iNqmRoL
Submitted 2026-09-04T08:40:27Z by JDBHub
via reddit https://ift.tt/Nbhj95i
Have I Been Squatted
GAPIUpdate delivers Odyssey Stealer on macOS - Have I Been Squatted
Analysis of GAPIUpdate.dmg, its macOS execution chain, Odyssey Stealer C2 infrastructure, wallet replacement, and 27 related GitHub DMGs.
Getting Agents to tell on themselves
https://ift.tt/hymTQHL
Submitted 2026-09-04T14:29:57Z by thinkst
via reddit https://ift.tt/ceFs1Zn
https://ift.tt/hymTQHL
Submitted 2026-09-04T14:29:57Z by thinkst
via reddit https://ift.tt/ceFs1Zn
Thinkst Thoughts
Getting Agents to tell on themselves
AI powered agentic attacks are scary, but agents are particularly “suggestible” allowing us to both detect and derail them
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you
https://ift.tt/rVfXWRO
Submitted 2026-09-04T15:32:57Z by rukhrunnin
via reddit https://ift.tt/xEYXiGl
https://ift.tt/rVfXWRO
Submitted 2026-09-04T15:32:57Z by rukhrunnin
via reddit https://ift.tt/xEYXiGl
Optimus Labs
When the Supply-Chain Attack Has No CVE: Inside the Coder Registry Hijack
Coder's own delivery infrastructure was hijacked to serve credential-stealing modules from the real registry.coder.com. No CVE, no poisoned package, nothing for a scanner to match.
Serbia Allegedly Hits 14 Activists With Pegasus Spyware
https://ift.tt/j54VEoi
Submitted 2026-09-04T17:56:03Z by QuantumQuicksilver
via reddit https://ift.tt/k8pMoYb
https://ift.tt/j54VEoi
Submitted 2026-09-04T17:56:03Z by QuantumQuicksilver
via reddit https://ift.tt/k8pMoYb
Million-dollar phishing campaign uses invisible Unicode characters to bypass email filters
https://ift.tt/QtbkuHx
Submitted 2026-09-05T07:44:22Z by CyberWorldOps
via reddit https://ift.tt/C2rfuTw
https://ift.tt/QtbkuHx
Submitted 2026-09-05T07:44:22Z by CyberWorldOps
via reddit https://ift.tt/C2rfuTw
CyberWorldOps
Invisible Unicode Phishing Bypasses Email Filters
Microsoft tracked a million-message phishing campaign using invisible Unicode Tags to hide loan lures and bypass email filters.
Waleed Mubarak | HAI Lab | Substack
https://ift.tt/Vxnh2au
Submitted 2026-09-05T10:16:54Z by Ok_Volume_9616
via reddit https://ift.tt/h7nfM6I
https://ift.tt/Vxnh2au
Submitted 2026-09-05T10:16:54Z by Ok_Volume_9616
via reddit https://ift.tt/h7nfM6I
Substack
Waleed Mubarak | HAI Lab | Substack
Exploring digital survival engineering and protecting humanitarian infrastructure in conflict zones.
I gave my agent an API key and lost $100. Never again.
https://ift.tt/4Kkoyps
Submitted 2026-09-06T15:43:30Z by Imaginary_Dinner2710
via reddit https://ift.tt/7ed2JCz
https://ift.tt/4Kkoyps
Submitted 2026-09-06T15:43:30Z by Imaginary_Dinner2710
via reddit https://ift.tt/7ed2JCz
Pain in the Agent
I gave my agent an API key and lost $100. Never again.
Six months ago, I installed OpenClaw, connected OpenRouter and assumed the agent was just expensive to run. Four days later, I found requests in Chinese that weren't mine. It cost me about $100 over a few days, but you can lose much more. Now I'm building…
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX
https://ift.tt/Y7E1DS8
Submitted 2026-09-07T03:47:14Z by _pimps
via reddit https://ift.tt/qxlp5ni
https://ift.tt/Y7E1DS8
Submitted 2026-09-07T03:47:14Z by _pimps
via reddit https://ift.tt/qxlp5ni
Tanto Security
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX
TantoSec turned an unauthenticated AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into remote code execution, chaining a decrypt-versus-parse oracle, a predictable HMAC key, and a type-name deserialisation gadget.
The £3 WiFi Extender With a Backdoor in Every Unit
https://ift.tt/YW31TXv
Submitted 2026-09-07T12:31:44Z by sanitybit
via reddit https://ift.tt/z15ZFwj
https://ift.tt/YW31TXv
Submitted 2026-09-07T12:31:44Z by sanitybit
via reddit https://ift.tt/z15ZFwj
Substack
The £3 WiFi Extender With a Backdoor in Every Unit
Pulling the firmware off the flash chip, decompressing the kernel, and finding an undocumented root login the owner cannot change.
Hacking AI customer service agents (Bug Bounty Village DEF CON 34)
https://ift.tt/BqaCXxM
Submitted 2026-09-08T04:22:12Z by qwerty0x41
via reddit https://ift.tt/SMnzmHf
https://ift.tt/BqaCXxM
Submitted 2026-09-08T04:22:12Z by qwerty0x41
via reddit https://ift.tt/SMnzmHf
Intigriti
Hacking AI customer service agents
As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate t...
Chatbot leaked a planted phone number and failed 58% of prompt injection attempts - jailbreak and extraction checks stayed clean
https://drive.google.com/file/d/1bqaPtkCNMqLZCF5VvOg-2t9dN-vg_A9L/view?usp=sharing
Submitted 2026-09-08T08:48:38Z by Former-Ad6661
via reddit https://ift.tt/4mxlnfV
https://drive.google.com/file/d/1bqaPtkCNMqLZCF5VvOg-2t9dN-vg_A9L/view?usp=sharing
Submitted 2026-09-08T08:48:38Z by Former-Ad6661
via reddit https://ift.tt/4mxlnfV
Two critical remote bugs found in ArangoDB
https://ift.tt/OEHWu37
Submitted 2026-09-08T13:06:42Z by HyprWave
via reddit https://ift.tt/TOwdNYl
https://ift.tt/OEHWu37
Submitted 2026-09-08T13:06:42Z by HyprWave
via reddit https://ift.tt/TOwdNYl
Remedio
Trust Me, I'm the System: Two ArangoDB Bugs, One Root Cause
Apply for the open Trust Me Im The System Arango Db Bugs Secure System Architecture position at Remedio. View complete job responsibilities, requirements, and submit your application online today.
🚨 Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
https://ift.tt/eHBW7y9
Submitted 2026-09-08T17:53:35Z by Straight-Practice-99
via reddit https://ift.tt/YIZGoTO
https://ift.tt/eHBW7y9
Submitted 2026-09-08T17:53:35Z by Straight-Practice-99
via reddit https://ift.tt/YIZGoTO
hunt.io
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
A single exposed directory held the full toolkit behind a Redis cryptomining botnet. We parsed the operator's own campaign logs to confirm 3,562 compromised servers and map their tradecraft.
WeWorm - The first zero-click worm to spread through WeChat calls across iOS and Android.
https://ift.tt/y0qf5Eh
Submitted 2026-09-08T19:54:54Z by _vavkamil_
via reddit https://ift.tt/4A1WmFd
https://ift.tt/y0qf5Eh
Submitted 2026-09-08T19:54:54Z by _vavkamil_
via reddit https://ift.tt/4A1WmFd
Calif
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
Disable Windows Defender via Antivirus Fake Registration
https://ipurple.team/2026/09/09/windows-security-center/
Submitted 2026-09-09T08:21:14Z by netbiosX
via reddit https://ift.tt/EfgCNLF
https://ipurple.team/2026/09/09/windows-security-center/
Submitted 2026-09-09T08:21:14Z by netbiosX
via reddit https://ift.tt/EfgCNLF
Purple Team
Windows Security Center
The Windows Security Center collects and presents information about the status of the antivirus control (Windows Defender or 3rd party). When a third-party antivirus is installed, Windows Defender …
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
https://ift.tt/umqObne
Submitted 2026-09-09T10:47:25Z by acorn222
via reddit https://ift.tt/568HKnc
https://ift.tt/umqObne
Submitted 2026-09-09T10:47:25Z by acorn222
via reddit https://ift.tt/568HKnc
Amibeingpwned
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, let any site set the browser's proxy for the session, open a new tab and stream screen recordings of it to an attacker's server. CVSS 9.1. CVE-2026-84388.