The Information Wars: A Retrospective
https://ift.tt/fJOQ1Z2
Submitted September 18, 2026 at 01:34AM by ximsss
via reddit https://ift.tt/CqBJwdz
https://ift.tt/fJOQ1Z2
Submitted September 18, 2026 at 01:34AM by ximsss
via reddit https://ift.tt/CqBJwdz
Substack
The Information Wars: A Retrospective
10 Lessons From an Invisible Conflict
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
https://ift.tt/rSOeI5U
Submitted September 18, 2026 at 09:57AM by fagnerbrack
via reddit https://ift.tt/nhipUqy
https://ift.tt/rSOeI5U
Submitted September 18, 2026 at 09:57AM by fagnerbrack
via reddit https://ift.tt/nhipUqy
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
Hacking OpenAI
https://ift.tt/mPtD2lW
Submitted September 18, 2026 at 10:28AM by appsec1337
via reddit https://ift.tt/KIBxvsc
https://ift.tt/mPtD2lW
Submitted September 18, 2026 at 10:28AM by appsec1337
via reddit https://ift.tt/KIBxvsc
Hacktron AI
Hacking OpenAI
A heap overflow and SSO misconfiguration to compromise OpenAI internal repositories
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
https://ift.tt/jHqhZxO
Submitted September 18, 2026 at 01:27PM by ablasionet
via reddit https://ift.tt/vBFle6G
https://ift.tt/jHqhZxO
Submitted September 18, 2026 at 01:27PM by ablasionet
via reddit https://ift.tt/vBFle6G
Hey, it's Asim
A quartet of Linux local root vulns: DirtyAH6, PPPoEject, TUNderflow, and DiagSpill
Squeezing four more LPEs out of Linux with agentic vuln hunting: CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469
Microsoft Teams Help Desk Impersonation: When IT Support Messages You First
https://ift.tt/ToaIHbh
Submitted September 18, 2026 at 06:25PM by scamdrill
via reddit https://ift.tt/wPzhT6j
https://ift.tt/ToaIHbh
Submitted September 18, 2026 at 06:25PM by scamdrill
via reddit https://ift.tt/wPzhT6j
ScamDrill
The IT Help Desk That Messaged You First on Teams
Teams allows chat from any external domain by default. Lab replication: first message to full endpoint control in 21 minutes. Here is what to change.
CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)
https://ift.tt/qhPuE3W
Submitted September 19, 2026 at 11:55AM by natcoba
via reddit https://ift.tt/hjQZJxX
https://ift.tt/qhPuE3W
Submitted September 19, 2026 at 11:55AM by natcoba
via reddit https://ift.tt/hjQZJxX
Accomplish
Guest to host: escaping Docker's hypervisor — Accomplish Blog
We reported a sandbox escape in Docker's hypervisor for Mac: a container gets complete read and write access to the host filesystem with three lines of bash. Assigned CVE-2026-77179 and fixed in Docker Desktop 4.88.0 and Docker Sandboxes 0.42.0.
Your LLM is prompt injecting you...
https://ift.tt/yakSCmd
Submitted September 19, 2026 at 01:39PM by AImSamy
via reddit https://ift.tt/4VeJg3c
https://ift.tt/yakSCmd
Submitted September 19, 2026 at 01:39PM by AImSamy
via reddit https://ift.tt/4VeJg3c
www.edenai.co
When LLM Routers Turn Malicious: AI Agent Security Risks
Researchers found malicious behavior in LLM routers, revealing new risks for AI agents, tool calls, credentials, and the LLM supply chain.
BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension
https://ift.tt/XMgOl3j
Submitted September 19, 2026 at 10:27PM by Content-Winter5328
via reddit https://ift.tt/UJCQ0Zd
https://ift.tt/XMgOl3j
Submitted September 19, 2026 at 10:27PM by Content-Winter5328
via reddit https://ift.tt/UJCQ0Zd
Forever
BragJack [Technical Overview]: How We Hijacked Top 5 Browsers' Internal Agents With Just One Single Extension · Forever Security
BragJack attack (discovered by Forever Security) allowed ordinary extensions to hijack the internal browser agent of Comet, Chrome, Edge, Opera, and Claude in Chrome
Fastest CVE informer | EchelonGraph
https://ift.tt/nFjQEIc
Submitted September 20, 2026 at 02:21PM by Foreign_Score_4021
via reddit https://ift.tt/CwSxqHb
https://ift.tt/nFjQEIc
Submitted September 20, 2026 at 02:21PM by Foreign_Score_4021
via reddit https://ift.tt/CwSxqHb
EchelonGraph
CVE Pulse — Live Vulnerability Feed
Search and explore cloud infrastructure vulnerabilities with real-time severity filtering and CVSS scoring.
AI Agents Keep Falling to 'Goal Hijack' (Copilot, Cursor, Grok)
https://ift.tt/C7bXHxo
Submitted September 20, 2026 at 11:16PM by _clickfix_
via reddit https://ift.tt/p3CIo8l
https://ift.tt/C7bXHxo
Submitted September 20, 2026 at 11:16PM by _clickfix_
via reddit https://ift.tt/p3CIo8l
Substack
AI Agent Goal Hijack: How Attackers Turn an Agent's Own Tools Against It
AI agents are being handed real power faster than they can be secured, and attackers are turning their own tools against them.
Silent packet loss in PcapSplitter: a file collision bug on TCP session reuse
https://ift.tt/yFW3fA6
Submitted September 21, 2026 at 07:35AM by Hot_Interest_4915
via reddit https://ift.tt/l1KMyOv
https://ift.tt/yFW3fA6
Submitted September 21, 2026 at 07:35AM by Hot_Interest_4915
via reddit https://ift.tt/l1KMyOv
Robin Hayer
PcapSplitter file collision on TCP session reuse
PcapSplitter reported 48 packets, wrote 44, exited zero. Tracing a filename collision on TCP 5-tuple reuse, and the fix merged upstream.
Three memory-safety bugs in Godot's untrusted-file parsers
https://ift.tt/aL0FjdV
Submitted September 21, 2026 at 02:38PM by bitbutter
via reddit https://ift.tt/vL1NnXQ
https://ift.tt/aL0FjdV
Submitted September 21, 2026 at 02:38PM by bitbutter
via reddit https://ift.tt/vL1NnXQ
axeghost.offprint.app
Three memory-safety bugs in Godot's untrusted-file parsers | Axe Ghost. On Steam! | Offprint
I found three serious bugs in Godot 4.7 in an audit conducted with an LLM agent. The bugs are due to missing bounds checking in code that reads untrusted files. Using files that are deliberately...
ChatGPT now knows what you do on other websites via ad collector
https://ift.tt/1WvKSGj
Submitted September 20, 2026 at 09:02PM by AdTemporary2475
via reddit https://ift.tt/o2OsxtR
https://ift.tt/1WvKSGj
Submitted September 20, 2026 at 09:02PM by AdTemporary2475
via reddit https://ift.tt/o2OsxtR
Buchodi's Threat Intel
ChatGPT now knows what you do on other websites via ad collector
OpenAI's ad collector at bzr.openai.com sets a cookie called __obi, scoped to .openai.com. The value is while you are on ChatGPT and tied to your ChatGPT account. __obi is then sent to OpenAI from ordinary websites you visit.
Any company that buys ads on…
Any company that buys ads on…
ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553
https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
Submitted September 21, 2026 at 10:00PM by TheReedemer69
via reddit https://ift.tt/6FZrOV0
https://minanagehsalalma.github.io/zte-smartlife-app-pwned/
Submitted September 21, 2026 at 10:00PM by TheReedemer69
via reddit https://ift.tt/6FZrOV0
minanagehsalalma.github.io
ZTE Smarthome TakeOver
Technical writeup on ZTE SmartLife security findings covering app-auth recovery, account enumeration, password reset behavior, signup abuse, and Homecare SDK reach.
Implant Encryption via the Dump Encoding Library
https://ipurple.team/2026/09/21/dump-encoding-library/
Submitted September 21, 2026 at 11:32PM by netbiosX
via reddit https://ift.tt/2q0XNTG
https://ipurple.team/2026/09/21/dump-encoding-library/
Submitted September 21, 2026 at 11:32PM by netbiosX
via reddit https://ift.tt/2q0XNTG
Purple Team
Dump Encoding Library
The Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic impleme…
Windows Exploitation Techniques: Dangling COM Object Registrations
https://ift.tt/tfrgQJv
Submitted September 22, 2026 at 08:49AM by wojtekch
via reddit https://ift.tt/G3z9VEI
https://ift.tt/tfrgQJv
Submitted September 22, 2026 at 08:49AM by wojtekch
via reddit https://ift.tt/G3z9VEI
projectzero.google
Windows Exploitation Techniques: Dangling COM Object Registrations
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...
Inside BambooToken’s Linux implant: shell and file control over MQTT
https://app.reverser.space/p/duckie/inside-bambootoken-s-linux-implant-shell-and-file
Submitted September 22, 2026 at 09:06AM by 420ass_slayer69
via reddit https://ift.tt/trEyg7s
https://app.reverser.space/p/duckie/inside-bambootoken-s-linux-implant-shell-and-file
Submitted September 22, 2026 at 09:06AM by 420ass_slayer69
via reddit https://ift.tt/trEyg7s
reverser.space
Inside BambooToken’s Linux implant: shell and file control over MQTT | Reverser Space
BambooToken turns an MQTT broker into a remote-control hub for Linux. Behind a 59-byte configuration blob, hex-encoded topics, and repeating XOR lies a backdoor built...
From a Sandbox Pod to cluster-admin: Benchmarking Autonomous LLM Agents on K8s Privilege Escalation
https://ift.tt/CJ153X4
Submitted September 22, 2026 at 11:45AM by vishalmurugan1986
via reddit https://ift.tt/IS8a6Ah
https://ift.tt/CJ153X4
Submitted September 22, 2026 at 11:45AM by vishalmurugan1986
via reddit https://ift.tt/IS8a6Ah
Substack
From a Sandbox Pod to cluster-admin: Benchmarking Autonomous LLM Agents on K8s Privilege Escalation
Why static linters miss multi-stage lateral movement, how autonomous LLMs navigate graph-based escalation, and defensive strategies for AI infrastructure.
Agent Blast Radius: Graph-Based Modeling, Admission Prevention, and LLM Benchmarking for Kubernetes Privilege Escalation
https://ift.tt/CJ153X4
Submitted September 22, 2026 at 11:52AM by vishalmurugan1986
via reddit https://ift.tt/tSe2MuH
https://ift.tt/CJ153X4
Submitted September 22, 2026 at 11:52AM by vishalmurugan1986
via reddit https://ift.tt/tSe2MuH
Substack
From a Sandbox Pod to cluster-admin: Benchmarking Autonomous LLM Agents on K8s Privilege Escalation
Why static linters miss multi-stage lateral movement, how autonomous LLMs navigate graph-based escalation, and defensive strategies for AI infrastructure.
vCenter pre-auth RCE: CVE-2026-59309/59310
https://ift.tt/zJ9a7yN
Submitted September 22, 2026 at 01:28PM by MobetaSec
via reddit https://ift.tt/UohWrc9
https://ift.tt/zJ9a7yN
Submitted September 22, 2026 at 01:28PM by MobetaSec
via reddit https://ift.tt/UohWrc9
Mobeta
vCenter pre-auth RCE: CVE-2026-59309/59310 | Mobeta
CVE-2026-59309 & CVE-2026-59310: patch-diffing VMware vCenter reveals two pre-auth 9.8 bugs - an auth bypass and a syslog path traversal to RCE.
CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS)
https://ift.tt/F7GwLVQ
Submitted September 22, 2026 at 04:45PM by AlexandreDaubois
via reddit https://ift.tt/ir6ZaF5
https://ift.tt/F7GwLVQ
Submitted September 22, 2026 at 04:45PM by AlexandreDaubois
via reddit https://ift.tt/ir6ZaF5
daubois.dev
CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS)
A JSONPath filter taken from a query string lets an attacker pick the regex a Symfony app runs, once per node in the document.