From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX
https://ift.tt/Y7E1DS8
Submitted 2026-09-07T03:47:14Z by _pimps
via reddit https://ift.tt/qxlp5ni
https://ift.tt/Y7E1DS8
Submitted 2026-09-07T03:47:14Z by _pimps
via reddit https://ift.tt/qxlp5ni
Tanto Security
From Padding Oracle to Shell: Unauthenticated RCE in Telerik UI for ASP.NET AJAX
TantoSec turned an unauthenticated AES-CBC padding oracle in Telerik UI for ASP.NET AJAX into remote code execution, chaining a decrypt-versus-parse oracle, a predictable HMAC key, and a type-name deserialisation gadget.
The £3 WiFi Extender With a Backdoor in Every Unit
https://ift.tt/YW31TXv
Submitted 2026-09-07T12:31:44Z by sanitybit
via reddit https://ift.tt/z15ZFwj
https://ift.tt/YW31TXv
Submitted 2026-09-07T12:31:44Z by sanitybit
via reddit https://ift.tt/z15ZFwj
Substack
The £3 WiFi Extender With a Backdoor in Every Unit
Pulling the firmware off the flash chip, decompressing the kernel, and finding an undocumented root login the owner cannot change.
Hacking AI customer service agents (Bug Bounty Village DEF CON 34)
https://ift.tt/BqaCXxM
Submitted 2026-09-08T04:22:12Z by qwerty0x41
via reddit https://ift.tt/SMnzmHf
https://ift.tt/BqaCXxM
Submitted 2026-09-08T04:22:12Z by qwerty0x41
via reddit https://ift.tt/SMnzmHf
Intigriti
Hacking AI customer service agents
As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate t...
Chatbot leaked a planted phone number and failed 58% of prompt injection attempts - jailbreak and extraction checks stayed clean
https://drive.google.com/file/d/1bqaPtkCNMqLZCF5VvOg-2t9dN-vg_A9L/view?usp=sharing
Submitted 2026-09-08T08:48:38Z by Former-Ad6661
via reddit https://ift.tt/4mxlnfV
https://drive.google.com/file/d/1bqaPtkCNMqLZCF5VvOg-2t9dN-vg_A9L/view?usp=sharing
Submitted 2026-09-08T08:48:38Z by Former-Ad6661
via reddit https://ift.tt/4mxlnfV
Two critical remote bugs found in ArangoDB
https://ift.tt/OEHWu37
Submitted 2026-09-08T13:06:42Z by HyprWave
via reddit https://ift.tt/TOwdNYl
https://ift.tt/OEHWu37
Submitted 2026-09-08T13:06:42Z by HyprWave
via reddit https://ift.tt/TOwdNYl
Remedio
Trust Me, I'm the System: Two ArangoDB Bugs, One Root Cause
Apply for the open Trust Me Im The System Arango Db Bugs Secure System Architecture position at Remedio. View complete job responsibilities, requirements, and submit your application online today.
🚨 Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
https://ift.tt/eHBW7y9
Submitted 2026-09-08T17:53:35Z by Straight-Practice-99
via reddit https://ift.tt/YIZGoTO
https://ift.tt/eHBW7y9
Submitted 2026-09-08T17:53:35Z by Straight-Practice-99
via reddit https://ift.tt/YIZGoTO
hunt.io
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
A single exposed directory held the full toolkit behind a Redis cryptomining botnet. We parsed the operator's own campaign logs to confirm 3,562 compromised servers and map their tradecraft.
WeWorm - The first zero-click worm to spread through WeChat calls across iOS and Android.
https://ift.tt/y0qf5Eh
Submitted 2026-09-08T19:54:54Z by _vavkamil_
via reddit https://ift.tt/4A1WmFd
https://ift.tt/y0qf5Eh
Submitted 2026-09-08T19:54:54Z by _vavkamil_
via reddit https://ift.tt/4A1WmFd
Calif
WeWorm
The first zero-click worm to spread through WeChat calls across iOS and Android.
Disable Windows Defender via Antivirus Fake Registration
https://ipurple.team/2026/09/09/windows-security-center/
Submitted 2026-09-09T08:21:14Z by netbiosX
via reddit https://ift.tt/EfgCNLF
https://ipurple.team/2026/09/09/windows-security-center/
Submitted 2026-09-09T08:21:14Z by netbiosX
via reddit https://ift.tt/EfgCNLF
Purple Team
Windows Security Center
The Windows Security Center collects and presents information about the status of the antivirus control (Windows Defender or 3rd party). When a third-party antivirus is installed, Windows Defender …
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
https://ift.tt/umqObne
Submitted 2026-09-09T10:47:25Z by acorn222
via reddit https://ift.tt/568HKnc
https://ift.tt/umqObne
Submitted 2026-09-09T10:47:25Z by acorn222
via reddit https://ift.tt/568HKnc
Amibeingpwned
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, let any site set the browser's proxy for the session, open a new tab and stream screen recordings of it to an attacker's server. CVSS 9.1. CVE-2026-84388.
Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine
https://ift.tt/PDzfpxK
Submitted 2026-09-09T11:22:19Z by Mempodipper
via reddit https://ift.tt/zBGYyO2
https://ift.tt/PDzfpxK
Submitted 2026-09-09T11:22:19Z by Mempodipper
via reddit https://ift.tt/zBGYyO2
How Piracy Sites Disguise Video as Fonts to Abuse Cloudflare Caching
https://ift.tt/KU3kFWC
Submitted 2026-09-09T13:54:47Z by ab032tx
via reddit https://ift.tt/jgdhOF6
https://ift.tt/KU3kFWC
Submitted 2026-09-09T13:54:47Z by ab032tx
via reddit https://ift.tt/jgdhOF6
Substrate
How Piracy Sites Disguise Video as Fonts to Abuse Cloudflare Caching · Substrate
A measured investigation into MPEG-TS segments served under .woff2 URLs, cached at Cloudflare, and reproduced across two delivery paths.
Apple mach_o Archive Parser Integer Underflow Vulnerability
https://ift.tt/kvmMx58
Submitted 2026-09-10T04:02:53Z by appsec1337
via reddit https://ift.tt/JaRI36Z
https://ift.tt/kvmMx58
Submitted 2026-09-10T04:02:53Z by appsec1337
via reddit https://ift.tt/JaRI36Z
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
Apple mach_o Archive Parser Integer Underflow Vulnerability
Security research uncovers an integer underflow in Apple's mach_o Archive parser causing OOB reads, DoS, and information disclosure in tools
Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability
https://ift.tt/RnErfLY
Submitted 2026-09-10T09:12:48Z by nibblesec
via reddit https://ift.tt/rAiC8Zk
https://ift.tt/RnErfLY
Submitted 2026-09-10T09:12:48Z by nibblesec
via reddit https://ift.tt/rAiC8Zk
Doyensec
Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability
Bug bounty initiatives can be a useful tool for companies to source security research focused on their products and get ahead of attackers. From a security researcher’s perspective, it’s a great way to gain experience and contribute to the overall security…
Forgejo <=16.0.3 Critical RCE
https://ift.tt/ckC6ANT
Submitted 2026-09-10T17:08:37Z by Motor-Finance-2602
via reddit https://ift.tt/3N9Y2bd
https://ift.tt/ckC6ANT
Submitted 2026-09-10T17:08:37Z by Motor-Finance-2602
via reddit https://ift.tt/3N9Y2bd
🕵️♂️ SonicWall SMA1000 (CVE-2026-15409): SSRF to Erlang RCE chained into automated DCSync from the appliance
https://ift.tt/g5Gtlud
Submitted 2026-09-10T17:48:31Z by Straight-Practice-99
via reddit https://ift.tt/8vierhQ
https://ift.tt/g5Gtlud
Submitted 2026-09-10T17:48:31Z by Straight-Practice-99
via reddit https://ift.tt/8vierhQ
hunt.io
UK Council Attack Linked to SonicWall SMA 1000 Campaign
An operator weaponized CVE-2026-15409 two days after disclosure, extracting LDAP credentials and running DCSync against Active Directory via SonicWall appliances.
No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite's dbpage
https://ift.tt/FvkJHQG
Submitted 2026-09-10T21:46:38Z by gabdevele
via reddit https://ift.tt/93TmlUZ
https://ift.tt/FvkJHQG
Submitted 2026-09-10T21:46:38Z by gabdevele
via reddit https://ift.tt/93TmlUZ
gabdevele
No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite's dbpage
A novel technique for writing ELF shared objects and achieving code execution in Python, Ruby, and Node.js using the sqlite_dbpage virtual table.
Beltdown: Escaping the Claude Code Sandbox
https://ift.tt/IL6H41n
Submitted 2026-09-10T21:57:43Z by natcoba
via reddit https://ift.tt/tDyfUAY
https://ift.tt/IL6H41n
Submitted 2026-09-10T21:57:43Z by natcoba
via reddit https://ift.tt/tDyfUAY
Accomplish
Beltdown: Escaping the Claude Code sandbox — Accomplish Blog
An untrusted repository opened in Claude Code can escape the macOS sandbox and run commands on your computer as your privileged user. You never get the permission prompt.
The ultimate guide to hacking APIs in 2026 has been updated
https://ift.tt/UmclkHn
Submitted 2026-09-10T22:53:46Z by hakluke
via reddit https://ift.tt/6xzuNEq
https://ift.tt/UmclkHn
Submitted 2026-09-10T22:53:46Z by hakluke
via reddit https://ift.tt/6xzuNEq
Labs Detectify
How to hack APIs in 2026
Learn how to hack APIs in 2026. This updated guide covers BOLA/IDOR, GraphQL flaws, OAuth misconfigurations, race conditions, and AI-backed API vulnerabilities.
A real Carnival Cruise Line email was serving customers malware
https://ift.tt/u5LGnyt
Submitted 2026-09-10T23:23:43Z by tuxxin
via reddit https://ift.tt/kVwPtnl
https://ift.tt/u5LGnyt
Submitted 2026-09-10T23:23:43Z by tuxxin
via reddit https://ift.tt/kVwPtnl
Tuxxin
A real Carnival Cruise Line email was serving customers malware
A real Carnival booking confirmation passed SPF, DKIM and DMARC while one link served customers malware. The lapsed domain behind it, and what it delivered.
Autonomous Systems Emissions Index
https://ift.tt/VmESiBc
Submitted 2026-09-11T05:51:32Z by Robbedoes_
via reddit https://ift.tt/GcmRoAt
https://ift.tt/VmESiBc
Submitted 2026-09-11T05:51:32Z by Robbedoes_
via reddit https://ift.tt/GcmRoAt
honeylabs.net
Autonomous Systems Emissions Index | HoneyLabs
Networks ranked by how much they probe the internet relative to the address space they announce. Live from open honeypot telemetry.
CSA Zero Trust Microsegmentation Guidance - formalizes topology-defined vs. connection-defined segmentation models
https://ift.tt/xXOhkME
Submitted 2026-09-11T08:36:58Z by PhilipLGriffiths88
via reddit https://ift.tt/dyhTX6t
https://ift.tt/xXOhkME
Submitted 2026-09-11T08:36:58Z by PhilipLGriffiths88
via reddit https://ift.tt/dyhTX6t
cloudsecurityalliance.org
Zero Trust Microsegmentation Guidance | CSA
A Zero Trust microsegmentation guide, with special consideration for agentic AI security & hybrid IT and OT security. Implement lateral movement prevention.