Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
https://ift.tt/dYFySP3
Submitted September 24, 2026 at 11:34AM by ezzzzz
via reddit https://ift.tt/pUlhwbu
https://ift.tt/dYFySP3
Submitted September 24, 2026 at 11:34AM by ezzzzz
via reddit https://ift.tt/pUlhwbu
Research Blog | Project Black
Bypassing EDR with Local AI
How hard is it to bypass EDR in the modern times with AI? As it turns out, not very hard.
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL
https://ift.tt/AV1BnZ7
Submitted September 24, 2026 at 04:32PM by nns_ee
via reddit https://ift.tt/B6gYv1u
https://ift.tt/AV1BnZ7
Submitted September 24, 2026 at 04:32PM by nns_ee
via reddit https://ift.tt/B6gYv1u
nns.ee
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL | nns.ee
Chaining an AtlasService binder command injection and an olc2 HAL binder method into uid 0 with all Linux capabilities from a plain installable app on OxygenOS 16.
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
https://ift.tt/fB1r4k6
Submitted September 24, 2026 at 08:37PM by natcoba
via reddit https://ift.tt/lC1UY52
https://ift.tt/fB1r4k6
Submitted September 24, 2026 at 08:37PM by natcoba
via reddit https://ift.tt/lC1UY52
Cloudflare Blog
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts
https://ift.tt/vpou0O9
Submitted September 24, 2026 at 09:15PM by nibblesec
via reddit https://ift.tt/syLYUa7
https://ift.tt/vpou0O9
Submitted September 24, 2026 at 09:15PM by nibblesec
via reddit https://ift.tt/syLYUa7
Doyensec
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts
While testing deep links in Chrome for iOS, we noticed a small but important difference. Opening a third-party app through a custom URL scheme normally produced a confirmation prompt. Shortcuts were an exception. As they’re handled by a native Apple app,…
CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018
https://ift.tt/M2eFuLp
Submitted September 25, 2026 at 01:49AM by AlexandreDaubois
via reddit https://ift.tt/tkbDPoW
https://ift.tt/M2eFuLp
Submitted September 25, 2026 at 01:49AM by AlexandreDaubois
via reddit https://ift.tt/tkbDPoW
daubois.dev
CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018
PHP's http:// stream wrapper sent Authorization, Cookie and Proxy-Authorization to any host a redirect pointed at, the bug curl fixed in 2018.
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
https://ift.tt/ACX1q9n
Submitted September 25, 2026 at 02:26AM by SpectreTv
via reddit https://ift.tt/GHz7Byu
https://ift.tt/ACX1q9n
Submitted September 25, 2026 at 02:26AM by SpectreTv
via reddit https://ift.tt/GHz7Byu
Ontinue
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
Ontinue researchers uncover the Lunex malware platform, revealing a sophisticated attack chain, BYOVD techniques, and previously unreported capabilities.
The 2026 State of AI Security Report has three numbers that really stuck with me: 81%, 50.1%, 99.9%
https://ift.tt/hUDYLmO
Submitted September 25, 2026 at 03:24AM by Aayushman_Shopbell
via reddit https://ift.tt/XtGsuvA
https://ift.tt/hUDYLmO
Submitted September 25, 2026 at 03:24AM by Aayushman_Shopbell
via reddit https://ift.tt/XtGsuvA
Orca Security
2026 State of AI Security Report
Download the 2026 State of AI Security Report. Real-world telemetry from 1,200+ organizations reveals AI vulnerability, agent, and encryption gaps.
Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/
Submitted September 25, 2026 at 07:43AM by p0xq
via reddit https://ift.tt/tmw1q3z
https://connorjaydunn.github.io/blog/posts/argus-monitor-ldos-cve-2026-79417/
Submitted September 25, 2026 at 07:43AM by p0xq
via reddit https://ift.tt/tmw1q3z
CDC-ACM Serial Interface Bypasses TCC on macOS
https://ift.tt/c8juXNe
Submitted September 25, 2026 at 08:53AM by NoRequirement8551
via reddit https://ift.tt/6hoORkf
https://ift.tt/c8juXNe
Submitted September 25, 2026 at 08:53AM by NoRequirement8551
via reddit https://ift.tt/6hoORkf
glyph.sh
CDC-ACM Serial Interface Bypasses TCC on macOS: A Disclosure After Apple Declined
macOS creates a fully read/write CDC-ACM serial device node with no TCC gate. Chained with a HID keyboard interface on the same USB composite device, this exfiltrates SSH keys, cloud credentials, and secrets in 24 seconds through a channel that shows no consent…
How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail
https://ift.tt/aprxnFv
Submitted September 24, 2026 at 08:14PM by idnsec
via reddit https://ift.tt/TwPxk8b
https://ift.tt/aprxnFv
Submitted September 24, 2026 at 08:14PM by idnsec
via reddit https://ift.tt/TwPxk8b
IDNSEC
How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail
A retrospective on CVE-2025-39964, an AF_ALG race condition I found in 2025 before Copy Fail drew attention to the same subsystem. I explain the out-of-bounds scatterlist access, the usercopy oracle, and the exploit that achieved root and a Docker container…
Compromising OBS Studio with a Twitch chat message.
https://ift.tt/r7fAbFy
Submitted September 24, 2026 at 02:18AM by 2daii
via reddit https://ift.tt/KIZV1zu
https://ift.tt/r7fAbFy
Submitted September 24, 2026 at 02:18AM by 2daii
via reddit https://ift.tt/KIZV1zu
Fake Journalist phishing scam targeting tech founders
https://ift.tt/1B2oSyh
Submitted September 24, 2026 at 09:31PM by french_toast_fiend
via reddit https://ift.tt/N7sycAu
https://ift.tt/1B2oSyh
Submitted September 24, 2026 at 09:31PM by french_toast_fiend
via reddit https://ift.tt/N7sycAu
Casco
How My Unicorn Founder Friend Was Phished
A fake WIRED interview routed through Calendly gave attackers access to Peter Reinhardt’s X account for a few minutes. I traced the campaign, filed abuse reports, and documented the offline status and provider receipts.