An event bus that never drops the critical stuff: QoS and backpressure in pwnproxy
https://ift.tt/wRxcTSm
Submitted 2026-09-11T19:58:51Z by elguapoRoot
via reddit https://ift.tt/AZitMcV
https://ift.tt/wRxcTSm
Submitted 2026-09-11T19:58:51Z by elguapoRoot
via reddit https://ift.tt/AZitMcV
Nextech Solutions
An event bus that never drops the critical stuff: QoS and backpressure in pwnproxy
How we designed pwnproxy's event bus with bounded per-channel, per-subscriber queues, three QoS classes (CRITICAL with retries, IMPORTANT with coalescing, BEST_EFFORT with drops) and a producer that never blocks.
Beltdown2: Escaping the Cursor CLI sandbox
https://ift.tt/MNUqeYG
Submitted 2026-09-12T15:31:47Z by natcoba
via reddit https://ift.tt/bQcGD05
https://ift.tt/MNUqeYG
Submitted 2026-09-12T15:31:47Z by natcoba
via reddit https://ift.tt/bQcGD05
Accomplish
Beltdown2: Escaping the Cursor CLI sandbox — Accomplish Blog
An attacker-controlled workspace/project folder, containing a .git/ directory, can escape the Cursor CLI's macOS sandbox and run code on your Mac with the logged-in user's full authority, no permission prompt, regardless of tool permission mode. The same…
Magento StyleSmuggler RCE: Report Poisoning to Code Execution
https://ift.tt/LyXWvlI
Submitted 2026-09-12T15:46:30Z by adrian_rt
via reddit https://ift.tt/B6wYXJR
https://ift.tt/LyXWvlI
Submitted 2026-09-12T15:46:30Z by adrian_rt
via reddit https://ift.tt/B6wYXJR
FORTBRIDGE
Magento StyleSmuggler RCE: Report Poisoning to Code Execution
Two unauthenticated requests: poison a Magento failure report, then drive the email template system into the DI compiler that includes it.
Locating Flutter's TLS certificate verifier in a stripped libflutter.so without byte signatures
https://ift.tt/HDQY8bz
Submitted 2026-09-13T04:30:09Z by magixer
via reddit https://ift.tt/qSPC1Ls
https://ift.tt/HDQY8bz
Submitted 2026-09-13T04:30:09Z by magixer
via reddit https://ift.tt/qSPC1Ls
crossfyre.io
Flutter doesn't care what Android trusts
Every interception tool works by editing one Android config file. Flutter has never read that file. Here is how we find the function that actually decides, without a byte signature, and what happened when we ran it against every Flutter app on one phone.
A revisit of remote Spectre attacks on Cloudflare Workers
https://ift.tt/EbeRVHI
Submitted 2026-09-12T08:52:12Z by SunnyBadger66
via reddit https://ift.tt/C1LUwsj
https://ift.tt/EbeRVHI
Submitted 2026-09-12T08:52:12Z by SunnyBadger66
via reddit https://ift.tt/C1LUwsj
Cloudflare Blog
A revisit of remote Spectre attacks on Cloudflare Workers
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers.
If you've seen EchelonGraphBot in your logs, here's exactly what it does and how to block it
https://ift.tt/CWxZLpw
Submitted 2026-09-14T00:14:40Z by Foreign_Score_4021
via reddit https://ift.tt/jXLnQ05
https://ift.tt/CWxZLpw
Submitted 2026-09-14T00:14:40Z by Foreign_Score_4021
via reddit https://ift.tt/jXLnQ05
EchelonGraph
Radar — what the open web answers when we ask politely
Reachability, status, TLS and latency for 7,097 public hosts, measured with one identified, rate-limited request and published with the method and the limits.
IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR
https://ift.tt/VSFxG60
Submitted 2026-09-14T13:20:24Z by buherator
via reddit https://ift.tt/Yq2xCoL
https://ift.tt/VSFxG60
Submitted 2026-09-14T13:20:24Z by buherator
via reddit https://ift.tt/Yq2xCoL
Silent Signal Techblog
IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR
Because we can!
Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
https://ift.tt/ZxJsiYN
Submitted 2026-09-14T14:19:22Z by Tricky-Term-8319
via reddit https://ift.tt/CBfPwiU
https://ift.tt/ZxJsiYN
Submitted 2026-09-14T14:19:22Z by Tricky-Term-8319
via reddit https://ift.tt/CBfPwiU
Antonio De Turris
Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
Two authorization bypasses in n8n’s AI agents let low-privileged users perform actions beyond those allowed by their role, including executing arbitrary nodes and exfiltrating credentials in cleartext. In some configurations, the same attack path can also…
OpenHunterAI releases an AI red-team engine after killing the startup
https://ift.tt/vVZFNB5
Submitted 2026-09-14T19:18:50Z by ryanmerket
via reddit https://ift.tt/msCIEnN
https://ift.tt/vVZFNB5
Submitted 2026-09-14T19:18:50Z by ryanmerket
via reddit https://ift.tt/msCIEnN
RuntimeWire
OpenHunterAI releases an AI red-team engine after killing the startup
Nicolas Krassas says his group killed its AI security startup idea and released OpenHunterAI, a source-available red-team engine for web, API and LLM apps.
EchelonGraph
https://ift.tt/UtK2csy
Submitted September 15, 2026 at 11:41AM by Foreign_Score_4021
via reddit https://ift.tt/80wWoCY
https://ift.tt/UtK2csy
Submitted September 15, 2026 at 11:41AM by Foreign_Score_4021
via reddit https://ift.tt/80wWoCY
EchelonGraph
CVE Pulse — Live Vulnerability Feed
Search and explore cloud infrastructure vulnerabilities with real-time severity filtering and CVSS scoring.
UANIA OS: Authenticated Remote Code Execution
https://ift.tt/6GtwoOF
Submitted September 15, 2026 at 12:20PM by Advanced_Rough8330
via reddit https://ift.tt/xjvyBTp
https://ift.tt/6GtwoOF
Submitted September 15, 2026 at 12:20PM by Advanced_Rough8330
via reddit https://ift.tt/xjvyBTp
rainpwn
UANIA OS: Authenticated Remote Code Execution
The UaniaBOX hands its admin a web GUI and no shell. Its packet capture page validated the one field that looked dangerous, then handed me arbitrary file...
Getting into EMFI for 30€ thanks to globalization
https://ift.tt/kmQ2UTo
Submitted September 15, 2026 at 05:26PM by gquere
via reddit https://ift.tt/WX76zn1
https://ift.tt/kmQ2UTo
Submitted September 15, 2026 at 05:26PM by gquere
via reddit https://ift.tt/WX76zn1
Escaping the OpenAI Codex sandbox, twice
https://ift.tt/NOgSmda
Submitted September 15, 2026 at 07:15PM by natcoba
via reddit https://ift.tt/ae8k3oK
https://ift.tt/NOgSmda
Submitted September 15, 2026 at 07:15PM by natcoba
via reddit https://ift.tt/ae8k3oK
Accomplish
Escaping the OpenAI Codex sandbox, twice — Accomplish Blog
Two ways out. One lets a patch write anywhere on the disk with no prompt. The other gets unsandboxed command execution out of read-only, the strictest mode Codex has.
Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution
https://ift.tt/KOat7re
Submitted September 15, 2026 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/3AuQr1H
https://ift.tt/KOat7re
Submitted September 15, 2026 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/3AuQr1H
Rhino Security Labs
Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution
Frappe LMS is an open-source learning management system built on the Frappe framework. It provides organizations with tools to create and manage online courses, track student progress, post job opportunities, and run learning batches.
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
https://ift.tt/OWkoxve
Submitted September 15, 2026 at 11:35PM by acronis
via reddit https://ift.tt/xFt8zAD
https://ift.tt/OWkoxve
Submitted September 15, 2026 at 11:35PM by acronis
via reddit https://ift.tt/xFt8zAD
Acronis
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management…