Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.
https://ift.tt/zocvQ7H
Submitted September 17, 2026 at 12:36PM by nibblesec
via reddit https://ift.tt/pTFN70R
https://ift.tt/zocvQ7H
Submitted September 17, 2026 at 12:36PM by nibblesec
via reddit https://ift.tt/pTFN70R
Doyensec
The skb that wasn't freed - the Fragnesia primitive via Open vSwitch
TLDR: Exploit. This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user namespaces enabled, openvswitch auto-loading, and a stock kernel…
I need Help!!
https://ift.tt/13gzZRx
Submitted September 17, 2026 at 01:17PM by Unusual_Worries
via reddit https://ift.tt/dmOrTSw
https://ift.tt/13gzZRx
Submitted September 17, 2026 at 01:17PM by Unusual_Worries
via reddit https://ift.tt/dmOrTSw
Qualtrics
Qualtrics Survey | Qualtrics Experience Management
The most powerful, simple and trusted way to gather experience data. Start your journey to experience management and try a free account today.
Visual Studio Code Vulnerability that Bypasses Workspace Trust
https://ift.tt/ZThbKVR
Submitted September 17, 2026 at 07:15PM by HyprWave
via reddit https://ift.tt/2EkKHC8
https://ift.tt/ZThbKVR
Submitted September 17, 2026 at 07:15PM by HyprWave
via reddit https://ift.tt/2EkKHC8
Remedio
Visual Studio Code Vulnerability that Bypasses Workspace Trust
How a critical Visual Studio Code vulnerability allows unverified extensions to run automatically, and learn how to secure your workstation.
CVE-2026-90999: A fabricated Sentry bug report can make Seer's coding agent run attacker code
https://ift.tt/tlQG3Yg
Submitted September 17, 2026 at 07:41PM by Ok-Pepper-2354
via reddit https://ift.tt/CfAgRcj
https://ift.tt/tlQG3Yg
Submitted September 17, 2026 at 07:41PM by Ok-Pepper-2354
via reddit https://ift.tt/CfAgRcj
agyn.io
PhantomFix: a fabricated bug that hijacks an AI autofix agent (CVE-2026-90999)
PhantomFix (CVE-2026-90999) is a critical vulnerability in Sentry Seer's autonomous autofix: a fabricated error report sent to a public DSN can reach the coding agent and lead to code execution and access to connected repositories. It's a concrete instance…
Working on a claude Skill
https://ift.tt/RxhdS4q
Submitted September 17, 2026 at 10:35PM by Efficient-Web-8065
via reddit https://ift.tt/3bNhMua
https://ift.tt/RxhdS4q
Submitted September 17, 2026 at 10:35PM by Efficient-Web-8065
via reddit https://ift.tt/3bNhMua
The Information Wars: A Retrospective
https://ift.tt/fJOQ1Z2
Submitted September 18, 2026 at 01:34AM by ximsss
via reddit https://ift.tt/CqBJwdz
https://ift.tt/fJOQ1Z2
Submitted September 18, 2026 at 01:34AM by ximsss
via reddit https://ift.tt/CqBJwdz
Substack
The Information Wars: A Retrospective
10 Lessons From an Invisible Conflict
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
https://ift.tt/rSOeI5U
Submitted September 18, 2026 at 09:57AM by fagnerbrack
via reddit https://ift.tt/nhipUqy
https://ift.tt/rSOeI5U
Submitted September 18, 2026 at 09:57AM by fagnerbrack
via reddit https://ift.tt/nhipUqy
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
Hacking OpenAI
https://ift.tt/mPtD2lW
Submitted September 18, 2026 at 10:28AM by appsec1337
via reddit https://ift.tt/KIBxvsc
https://ift.tt/mPtD2lW
Submitted September 18, 2026 at 10:28AM by appsec1337
via reddit https://ift.tt/KIBxvsc
Hacktron AI
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
https://ift.tt/jHqhZxO
Submitted September 18, 2026 at 01:27PM by ablasionet
via reddit https://ift.tt/vBFle6G
https://ift.tt/jHqhZxO
Submitted September 18, 2026 at 01:27PM by ablasionet
via reddit https://ift.tt/vBFle6G
Hey, it's Asim
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Squeezing four more LPEs out of Linux with agentic vuln hunting: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469
Microsoft Teams Help Desk Impersonation: When IT Support Messages You First
https://ift.tt/ToaIHbh
Submitted September 18, 2026 at 06:25PM by scamdrill
via reddit https://ift.tt/wPzhT6j
https://ift.tt/ToaIHbh
Submitted September 18, 2026 at 06:25PM by scamdrill
via reddit https://ift.tt/wPzhT6j
ScamDrill
The IT Help Desk That Messaged You First on Teams
Teams allows chat from any external domain by default. Lab replication: first message to full endpoint control in 21 minutes. Here is what to change.
CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)
https://ift.tt/qhPuE3W
Submitted September 19, 2026 at 11:55AM by natcoba
via reddit https://ift.tt/hjQZJxX
https://ift.tt/qhPuE3W
Submitted September 19, 2026 at 11:55AM by natcoba
via reddit https://ift.tt/hjQZJxX
Accomplish
Guest to host: escaping Docker's hypervisor — Accomplish Blog
We reported a sandbox escape in Docker's hypervisor for Mac: a container gets complete read and write access to the host filesystem with three lines of bash. Assigned CVE-2026-77179 and fixed in Docker Desktop 4.88.0 and Docker Sandboxes 0.42.0.
Your LLM is prompt injecting you...
https://ift.tt/yakSCmd
Submitted September 19, 2026 at 01:39PM by AImSamy
via reddit https://ift.tt/4VeJg3c
https://ift.tt/yakSCmd
Submitted September 19, 2026 at 01:39PM by AImSamy
via reddit https://ift.tt/4VeJg3c
www.edenai.co
When LLM Routers Turn Malicious: AI Agent Security Risks
Researchers found malicious behavior in LLM routers, revealing new risks for AI agents, tool calls, credentials, and the LLM supply chain.
BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension
https://ift.tt/XMgOl3j
Submitted September 19, 2026 at 10:27PM by Content-Winter5328
via reddit https://ift.tt/UJCQ0Zd
https://ift.tt/XMgOl3j
Submitted September 19, 2026 at 10:27PM by Content-Winter5328
via reddit https://ift.tt/UJCQ0Zd
Forever
BragJack [Technical Overview]: How We Hijacked Top 5 Browsers' Internal Agents With Just One Single Extension · Forever Security
BragJack attack (discovered by Forever Security) allowed ordinary extensions to hijack the internal browser agent of Comet, Chrome, Edge, Opera, and Claude in Chrome
Fastest CVE informer | EchelonGraph
https://ift.tt/nFjQEIc
Submitted September 20, 2026 at 02:21PM by Foreign_Score_4021
via reddit https://ift.tt/CwSxqHb
https://ift.tt/nFjQEIc
Submitted September 20, 2026 at 02:21PM by Foreign_Score_4021
via reddit https://ift.tt/CwSxqHb
EchelonGraph
CVE Pulse — Live Vulnerability Feed
Search and explore cloud infrastructure vulnerabilities with real-time severity filtering and CVSS scoring.
AI Agents Keep Falling to 'Goal Hijack' (Copilot, Cursor, Grok)
https://ift.tt/C7bXHxo
Submitted September 20, 2026 at 11:16PM by _clickfix_
via reddit https://ift.tt/p3CIo8l
https://ift.tt/C7bXHxo
Submitted September 20, 2026 at 11:16PM by _clickfix_
via reddit https://ift.tt/p3CIo8l
Substack
AI Agent Goal Hijack: How Attackers Turn an Agent's Own Tools Against It
AI agents are being handed real power faster than they can be secured, and attackers are turning their own tools against them.
Silent packet loss in PcapSplitter: a file collision bug on TCP session reuse
https://ift.tt/yFW3fA6
Submitted September 21, 2026 at 07:35AM by Hot_Interest_4915
via reddit https://ift.tt/l1KMyOv
https://ift.tt/yFW3fA6
Submitted September 21, 2026 at 07:35AM by Hot_Interest_4915
via reddit https://ift.tt/l1KMyOv
Robin Hayer
PcapSplitter file collision on TCP session reuse
PcapSplitter reported 48 packets, wrote 44, exited zero. Tracing a filename collision on TCP 5-tuple reuse, and the fix merged upstream.
Three memory-safety bugs in Godot's untrusted-file parsers
https://ift.tt/aL0FjdV
Submitted September 21, 2026 at 02:38PM by bitbutter
via reddit https://ift.tt/vL1NnXQ
https://ift.tt/aL0FjdV
Submitted September 21, 2026 at 02:38PM by bitbutter
via reddit https://ift.tt/vL1NnXQ
axeghost.offprint.app
Three memory-safety bugs in Godot's untrusted-file parsers | Axe Ghost. On Steam! | Offprint
I found three serious bugs in Godot 4.7 in an audit conducted with an LLM agent. The bugs are due to missing bounds checking in code that reads untrusted files. Using files that are deliberately...
ChatGPT now knows what you do on other websites via ad collector
https://ift.tt/1WvKSGj
Submitted September 20, 2026 at 09:02PM by AdTemporary2475
via reddit https://ift.tt/o2OsxtR
https://ift.tt/1WvKSGj
Submitted September 20, 2026 at 09:02PM by AdTemporary2475
via reddit https://ift.tt/o2OsxtR
Buchodi's Threat Intel
ChatGPT now knows what you do on other websites via ad collector
OpenAI's ad collector at bzr.openai.com sets a cookie called __obi, scoped to .openai.com. The value is while you are on ChatGPT and tied to your ChatGPT account. __obi is then sent to OpenAI from ordinary websites you visit.
Any company that buys ads on…
Any company that buys ads on…
ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553
https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
Submitted September 21, 2026 at 10:00PM by TheReedemer69
via reddit https://ift.tt/6FZrOV0
https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
Submitted September 21, 2026 at 10:00PM by TheReedemer69
via reddit https://ift.tt/6FZrOV0
minanagehsalalma.github.io
ZTE Smarthome TakeOver
Technical writeup on ZTE SmartLife security findings covering app-auth recovery, account enumeration, password reset behavior, signup abuse, and Homecare SDK reach.
Implant Encryption via the Dump Encoding Library
https://ipurple.team/2026/09/21/dump-encoding-library/
Submitted September 21, 2026 at 11:32PM by netbiosX
via reddit https://ift.tt/2q0XNTG
https://ipurple.team/2026/09/21/dump-encoding-library/
Submitted September 21, 2026 at 11:32PM by netbiosX
via reddit https://ift.tt/2q0XNTG
Purple Team
Dump Encoding Library
The Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic impleme…
Windows Exploitation Techniques: Dangling COM Object Registrations
https://ift.tt/tfrgQJv
Submitted September 22, 2026 at 08:49AM by wojtekch
via reddit https://ift.tt/G3z9VEI
https://ift.tt/tfrgQJv
Submitted September 22, 2026 at 08:49AM by wojtekch
via reddit https://ift.tt/G3z9VEI
projectzero.google
Windows Exploitation Techniques: Dangling COM Object Registrations
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...