IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR
https://ift.tt/VSFxG60
Submitted 2026-09-14T13:20:24Z by buherator
via reddit https://ift.tt/Yq2xCoL
https://ift.tt/VSFxG60
Submitted 2026-09-14T13:20:24Z by buherator
via reddit https://ift.tt/Yq2xCoL
Silent Signal Techblog
IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR
Because we can!
Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
https://ift.tt/ZxJsiYN
Submitted 2026-09-14T14:19:22Z by Tricky-Term-8319
via reddit https://ift.tt/CBfPwiU
https://ift.tt/ZxJsiYN
Submitted 2026-09-14T14:19:22Z by Tricky-Term-8319
via reddit https://ift.tt/CBfPwiU
Antonio De Turris
Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
Two authorization bypasses in n8n’s AI agents let low-privileged users perform actions beyond those allowed by their role, including executing arbitrary nodes and exfiltrating credentials in cleartext. In some configurations, the same attack path can also…
OpenHunterAI releases an AI red-team engine after killing the startup
https://ift.tt/vVZFNB5
Submitted 2026-09-14T19:18:50Z by ryanmerket
via reddit https://ift.tt/msCIEnN
https://ift.tt/vVZFNB5
Submitted 2026-09-14T19:18:50Z by ryanmerket
via reddit https://ift.tt/msCIEnN
RuntimeWire
OpenHunterAI releases an AI red-team engine after killing the startup
Nicolas Krassas says his group killed its AI security startup idea and released OpenHunterAI, a source-available red-team engine for web, API and LLM apps.
EchelonGraph
https://ift.tt/UtK2csy
Submitted September 15, 2026 at 11:41AM by Foreign_Score_4021
via reddit https://ift.tt/80wWoCY
https://ift.tt/UtK2csy
Submitted September 15, 2026 at 11:41AM by Foreign_Score_4021
via reddit https://ift.tt/80wWoCY
EchelonGraph
CVE Pulse — Live Vulnerability Feed
Search and explore cloud infrastructure vulnerabilities with real-time severity filtering and CVSS scoring.
UANIA OS: Authenticated Remote Code Execution
https://ift.tt/6GtwoOF
Submitted September 15, 2026 at 12:20PM by Advanced_Rough8330
via reddit https://ift.tt/xjvyBTp
https://ift.tt/6GtwoOF
Submitted September 15, 2026 at 12:20PM by Advanced_Rough8330
via reddit https://ift.tt/xjvyBTp
rainpwn
UANIA OS: Authenticated Remote Code Execution
The UaniaBOX hands its admin a web GUI and no shell. Its packet capture page validated the one field that looked dangerous, then handed me arbitrary file...
Getting into EMFI for 30€ thanks to globalization
https://ift.tt/kmQ2UTo
Submitted September 15, 2026 at 05:26PM by gquere
via reddit https://ift.tt/WX76zn1
https://ift.tt/kmQ2UTo
Submitted September 15, 2026 at 05:26PM by gquere
via reddit https://ift.tt/WX76zn1
Escaping the OpenAI Codex sandbox, twice
https://ift.tt/NOgSmda
Submitted September 15, 2026 at 07:15PM by natcoba
via reddit https://ift.tt/ae8k3oK
https://ift.tt/NOgSmda
Submitted September 15, 2026 at 07:15PM by natcoba
via reddit https://ift.tt/ae8k3oK
Accomplish
Escaping the OpenAI Codex sandbox, twice — Accomplish Blog
Two ways out. One lets a patch write anywhere on the disk with no prompt. The other gets unsandboxed command execution out of read-only, the strictest mode Codex has.
Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution
https://ift.tt/KOat7re
Submitted September 15, 2026 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/3AuQr1H
https://ift.tt/KOat7re
Submitted September 15, 2026 at 09:30PM by hackers_and_builders
via reddit https://ift.tt/3AuQr1H
Rhino Security Labs
Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution
Frappe LMS is an open-source learning management system built on the Frappe framework. It provides organizations with tools to create and manage online courses, track student progress, post job opportunities, and run learning batches.
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
https://ift.tt/OWkoxve
Submitted September 15, 2026 at 11:35PM by acronis
via reddit https://ift.tt/xFt8zAD
https://ift.tt/OWkoxve
Submitted September 15, 2026 at 11:35PM by acronis
via reddit https://ift.tt/xFt8zAD
Acronis
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit
Acronis Threat Research Unit (TRU) uncovered a multinational campaign in which a Chinese-speaking threat actor, tracked as Red Heron, rapidly weaponized CVE-2026-60004 to compromise internet-facing instances of Gitea, a self-hosted source-code management…
Bypassing Referer-Based CSRF with strict-origin-when-cross-origin
https://ift.tt/MB3pYE8
Submitted September 16, 2026 at 07:22PM by bajk
via reddit https://ift.tt/5qEOPhK
https://ift.tt/MB3pYE8
Submitted September 16, 2026 at 07:22PM by bajk
via reddit https://ift.tt/5qEOPhK
Afine
Bypassing Referer-Based CSRF with strict-origin-when-cross-origin
strict-origin-when-cross-origin: A Referer CSRF Bypass
I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table
https://ift.tt/yQ3XpuZ
Submitted September 16, 2026 at 07:33PM by unknownhad
via reddit https://ift.tt/7BbK2Ul
https://ift.tt/yQ3XpuZ
Submitted September 16, 2026 at 07:33PM by unknownhad
via reddit https://ift.tt/7BbK2Ul
Himanshu Anand :: Security & Other Notes
I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table
How a missed x86 TLB shootdown became page-table control in Google kernelCTF.
Evading Machine Learning Based Detections · MSec Operations Blog
https://ift.tt/4vEiLUr
Submitted September 16, 2026 at 08:51PM by S3cur3Th1sSh1t
via reddit https://ift.tt/p4wCMHE
https://ift.tt/4vEiLUr
Submitted September 16, 2026 at 08:51PM by S3cur3Th1sSh1t
via reddit https://ift.tt/p4wCMHE
SilkParasite Infrastructure Exposed: pivoting from one page hash and a single TLS cert to a 13-server SpiceRAT cluster
https://ift.tt/nH3wDL2
Submitted September 16, 2026 at 10:30PM by Straight-Practice-99
via reddit https://ift.tt/UTHLbDS
https://ift.tt/nH3wDL2
Submitted September 16, 2026 at 10:30PM by Straight-Practice-99
via reddit https://ift.tt/UTHLbDS
hunt.io
SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia
Hunt.io SpiceRAT detections identified shared infrastructure artifacts across malware families in Bitdefender’s SilkParasite report, connecting servers to Central Asian energy, government, and telecom targets.
The Hacker's Guide to Attacking AI Agents
https://ift.tt/PE2KMyU
Submitted September 17, 2026 at 03:26AM by _clickfix_
via reddit https://ift.tt/D8yml07
https://ift.tt/PE2KMyU
Submitted September 17, 2026 at 03:26AM by _clickfix_
via reddit https://ift.tt/D8yml07
Substack
The Hacker's Guide to Attacking AI Agents
This is a practical guide to assessing the security of an agentic AI system.
Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.
https://ift.tt/zocvQ7H
Submitted September 17, 2026 at 12:36PM by nibblesec
via reddit https://ift.tt/pTFN70R
https://ift.tt/zocvQ7H
Submitted September 17, 2026 at 12:36PM by nibblesec
via reddit https://ift.tt/pTFN70R
Doyensec
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user namespaces enabled, openvswitch auto-loading, and a stock kernel…
I need Help!!
https://ift.tt/13gzZRx
Submitted September 17, 2026 at 01:17PM by Unusual_Worries
via reddit https://ift.tt/dmOrTSw
https://ift.tt/13gzZRx
Submitted September 17, 2026 at 01:17PM by Unusual_Worries
via reddit https://ift.tt/dmOrTSw
Qualtrics
Qualtrics Survey | Qualtrics Experience Management
The most powerful, simple and trusted way to gather experience data. Start your journey to experience management and try a free account today.
Visual Studio Code Vulnerability that Bypasses Workspace Trust
https://ift.tt/ZThbKVR
Submitted September 17, 2026 at 07:15PM by HyprWave
via reddit https://ift.tt/2EkKHC8
https://ift.tt/ZThbKVR
Submitted September 17, 2026 at 07:15PM by HyprWave
via reddit https://ift.tt/2EkKHC8
Remedio
Visual Studio Code Vulnerability that Bypasses Workspace Trust
How a critical Visual Studio Code vulnerability allows unverified extensions to run automatically, and learn how to secure your workstation.
CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code
https://ift.tt/tlQG3Yg
Submitted September 17, 2026 at 07:41PM by Ok-Pepper-2354
via reddit https://ift.tt/CfAgRcj
https://ift.tt/tlQG3Yg
Submitted September 17, 2026 at 07:41PM by Ok-Pepper-2354
via reddit https://ift.tt/CfAgRcj
agyn.io
PhantomFix: a fabricated bug that hijacks an AI autofix agent (CVE-2026-90999)
PhantomFix (CVE-2026-90999) is a critical vulnerability in Sentry Seer's autonomous autofix: a fabricated error report sent to a public DSN can reach the coding agent and lead to code execution and access to connected repositories. It's a concrete instance…
Working on a claude Skill
https://ift.tt/RxhdS4q
Submitted September 17, 2026 at 10:35PM by Efficient-Web-8065
via reddit https://ift.tt/3bNhMua
https://ift.tt/RxhdS4q
Submitted September 17, 2026 at 10:35PM by Efficient-Web-8065
via reddit https://ift.tt/3bNhMua
The Information Wars: A Retrospective
https://ift.tt/fJOQ1Z2
Submitted September 18, 2026 at 01:34AM by ximsss
via reddit https://ift.tt/CqBJwdz
https://ift.tt/fJOQ1Z2
Submitted September 18, 2026 at 01:34AM by ximsss
via reddit https://ift.tt/CqBJwdz
Substack
The Information Wars: A Retrospective
10 Lessons From an Invisible Conflict
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
https://ift.tt/rSOeI5U
Submitted September 18, 2026 at 09:57AM by fagnerbrack
via reddit https://ift.tt/nhipUqy
https://ift.tt/rSOeI5U
Submitted September 18, 2026 at 09:57AM by fagnerbrack
via reddit https://ift.tt/nhipUqy
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.