Sender spoofing in Proton Mail via display-name homograph
https://alonsovidales.github.io/protonmail-sender-spoofing/
Submitted September 28, 2026 at 06:52PM by __ThePasanger__
via reddit https://ift.tt/fsuUoLx
https://alonsovidales.github.io/protonmail-sender-spoofing/
Submitted September 28, 2026 at 06:52PM by __ThePasanger__
via reddit https://ift.tt/fsuUoLx
protonmail-sender-spoofing
Sender spoofing in Proton Mail via display-name homograph
Proton Mail’s web interface can be made to present a forged sender identity that is visually indistinguishable from a legitimate one.
Your SBOM Is Fan Fiction
https://ift.tt/5hfHuml
Submitted September 29, 2026 at 02:24AM by Confident_Milk6013
via reddit https://ift.tt/7EIgGiH
https://ift.tt/5hfHuml
Submitted September 29, 2026 at 02:24AM by Confident_Milk6013
via reddit https://ift.tt/7EIgGiH
yeet.cx
Your SBOM Is Fan Fiction
Your SBOM describes a machine that does not exist. We built a runtime bill of materials on yeet that asks the kernel what is actually executing, which shared objects each process has mapped, and whether the function named in an open advisory is actually in…
Email is crazy
https://ift.tt/fpgeRo7
Submitted September 29, 2026 at 03:30AM by fagnerbrack
via reddit https://ift.tt/Y1mugjN
https://ift.tt/fpgeRo7
Submitted September 29, 2026 at 03:30AM by fagnerbrack
via reddit https://ift.tt/Y1mugjN
Ryze
Email is crazy
A deep dive into how email actually works — SMTP, MTAs, SPF/DKIM/DMARC authentication, spam filtering and TLS — traced step by step from Alice to Bob.
I flooded a legal contract with lookalike letters and gave it to seven GPT and Claude models. None were fooled, but it took up to 5.7x the tokens to read, and the bill for each question rose by up to 3.9x. 'Denial of Spend'
https://paultendo.github.io/posts/denial-of-spend-gpt-6-claude-fable/
Submitted September 29, 2026 at 06:11AM by paultendo
via reddit https://ift.tt/nkTrUVN
https://paultendo.github.io/posts/denial-of-spend-gpt-6-claude-fable/
Submitted September 29, 2026 at 06:11AM by paultendo
via reddit https://ift.tt/nkTrUVN
paultendo.github.io
Lookalike letters don’t fool GPT-6 or Claude, but nearly quadruple the bill
I reran my Denial of Spend test on GPT-6 Astra, Sol and Luna and Claude Fable 5.1, Opus 5.5, Sonnet 5 and Haiku 4.5. None were fooled by lookalike letters, and all of them still paid to read them: up to 5.7x the tokens and up to 3.9x the bill.
Use Strong Passwords
https://ift.tt/PrqIuBC
Submitted September 29, 2026 at 11:27AM by Lucky07072026
via reddit https://ift.tt/NEF3mLH
https://ift.tt/PrqIuBC
Submitted September 29, 2026 at 11:27AM by Lucky07072026
via reddit https://ift.tt/NEF3mLH
Cybersecurity and Infrastructure Security Agency CISA
Use Strong Passwords | CISA
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
https://ift.tt/3XaBvtg
Submitted September 29, 2026 at 03:03PM by No-Peanut-6988
via reddit https://ift.tt/OWcSZft
https://ift.tt/3XaBvtg
Submitted September 29, 2026 at 03:03PM by No-Peanut-6988
via reddit https://ift.tt/OWcSZft
Sorami Consulting
NVIDIA OpenShell v0.1.2 Egress Policy Evaluation | Sorami
Pre-registered evaluation of NVIDIA OpenShell v0.1.2 egress policy: the default blocked every path tried; four operator settings let data out. Logs linked.
The Hidden Network: Ray Control-Plane Exposure in Distributed LLM Inference on Kubernetes (Empirical Study, EKS)
https://ift.tt/Qq9gnoX
Submitted September 29, 2026 at 03:20PM by No-Peanut-6988
via reddit https://ift.tt/rE4SKbI
https://ift.tt/Qq9gnoX
Submitted September 29, 2026 at 03:20PM by No-Peanut-6988
via reddit https://ift.tt/rE4SKbI
Sorami Consulting
Ray Control-Plane Exposure in LLM Inference on EKS | Sorami
What a pod in an unrelated namespace could reach on default Ray and vLLM deployments in one EKS testbed, and what NetworkPolicy blocked.
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
https://ift.tt/e2O5Uas
Submitted September 29, 2026 at 07:27PM by dx7r__
via reddit https://ift.tt/CxVsHN9
https://ift.tt/e2O5Uas
Submitted September 29, 2026 at 07:27PM by dx7r__
via reddit https://ift.tt/CxVsHN9
watchTowr Labs
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)
Part 1 of this week's saga can be found here.
This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution, enabling organizations to rapidly react to emerging threats: the watchTowr Platform.
What Is A Citrix…
This research is a glimpse into the capabilities that power our Preemptive Exposure Management solution, enabling organizations to rapidly react to emerging threats: the watchTowr Platform.
What Is A Citrix…
Paint It Blue: Reversing Win32k's Callbacks
https://idov31.github.io/posts/paint-it-blue-reverse-win32k
Submitted September 29, 2026 at 11:10PM by Idov31
via reddit https://ift.tt/PJUmjMd
https://idov31.github.io/posts/paint-it-blue-reverse-win32k
Submitted September 29, 2026 at 11:10PM by Idov31
via reddit https://ift.tt/PJUmjMd
AI coding agents have been creating public GitHub repos on their own to post internal company screenshots
https://ift.tt/vDKB07L
Submitted September 29, 2026 at 09:47PM by Fit-Management2067
via reddit https://ift.tt/5KMyj2T
https://ift.tt/vDKB07L
Submitted September 29, 2026 at 09:47PM by Fit-Management2067
via reddit https://ift.tt/5KMyj2T
www.glow.io
Glow: The Endpoint AI Company | PixelLeak AI exposure of private developer data
PixelLeak: New research reveals AI coding agents are exposing secrets, PII, and live admin access across 1,000+ public GitHub repos.
Why "Extension Blocked" Doesn't Mean Safe: Rethinking File Upload Security Testing
https://haakimsec.github.io/GoUpload-site/research
Submitted September 30, 2026 at 12:47AM by Additional_Resort653
via reddit https://ift.tt/VWuniGr
https://haakimsec.github.io/GoUpload-site/research
Submitted September 30, 2026 at 12:47AM by Additional_Resort653
via reddit https://ift.tt/VWuniGr
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
https://ift.tt/iAnSr61
Submitted September 30, 2026 at 03:13AM by the_hypotenuse
via reddit https://ift.tt/wkivrPp
https://ift.tt/iAnSr61
Submitted September 30, 2026 at 03:13AM by the_hypotenuse
via reddit https://ift.tt/wkivrPp
control-plane.io
A Realistic Code Execution Exploit Chain in OpenBao and Vault
ControlPlane and the OpenBao community recently patched a full exploit chain from unauthenticated access to full remote code execution that also affects IBM's HashiCorp Vault.
Microsoft Copilot Cowork Exfiltrates Files
https://ift.tt/kVHJPis
Submitted September 30, 2026 at 03:30AM by fagnerbrack
via reddit https://ift.tt/GgHPybh
https://ift.tt/kVHJPis
Submitted September 30, 2026 at 03:30AM by fagnerbrack
via reddit https://ift.tt/GgHPybh
Promptarmor
Microsoft Copilot Cowork Exfiltrates Files
Microsoft Copilot Cowork is vulnerable to file exfiltration attacks via indirect prompt injection as a result of insecure automatic action approvals for sending Emails and Teams messages.
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
https://ift.tt/7qIwXVl
Submitted September 30, 2026 at 06:30AM by fagnerbrack
via reddit https://ift.tt/FKuybte
https://ift.tt/7qIwXVl
Submitted September 30, 2026 at 06:30AM by fagnerbrack
via reddit https://ift.tt/FKuybte
nns.ee
Pwnd Blaster: Hacking your PC using your speaker without ever touching it | nns.ee
Abusing an unauthenticated Bluetooth protocol to turn a PC speaker into a Rubber Ducky.
No Time to Pwn – Can AI Find and Exploit the Linux Kernel?
https://ift.tt/AuahTKf
Submitted September 30, 2026 at 03:28AM by fede_k
via reddit https://ift.tt/fKrpY1l
https://ift.tt/AuahTKf
Submitted September 30, 2026 at 03:28AM by fede_k
via reddit https://ift.tt/fKrpY1l
XBOW
No Time to Pwn: CVE-2026-72018 Linux Kernel LPE | XBOW
XBOW discovered CVE-2026-72018, an out-of-bounds write in the Linux kernel's SMC-D driver, and turned one weak primitive into a working root exploit.
Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
https://ift.tt/onXPywh
Submitted September 30, 2026 at 06:38PM by scopedsecurity
via reddit https://ift.tt/u0Bk2gM
https://ift.tt/onXPywh
Submitted September 30, 2026 at 06:38PM by scopedsecurity
via reddit https://ift.tt/u0Bk2gM
Horizon3
Anthropic Mythos Finds Rejetto HFS RCE
See how Horizon3 used Anthropic’s Mythos to uncover a Rejetto HFS cryptographic flaw, forge admin sessions, and achieve remote code execution.
The Real Price Tag on Breaches
https://ift.tt/8m1EybX
Submitted October 1, 2026 at 06:31AM by fagnerbrack
via reddit https://ift.tt/hqzG7WQ
https://ift.tt/8m1EybX
Submitted October 1, 2026 at 06:31AM by fagnerbrack
via reddit https://ift.tt/hqzG7WQ
www.resilientcyber.io
The Real Price Tag on Breaches
A look at Verizon's Data Breach Impact Study And What The Findings Teach Us
New Local Privilege Escalation on Acer laptops
https://ift.tt/2s6ywBh
Submitted October 1, 2026 at 01:04PM by Intrinsec_
via reddit https://ift.tt/PsqweZX
https://ift.tt/2s6ywBh
Submitted October 1, 2026 at 01:04PM by Intrinsec_
via reddit https://ift.tt/PsqweZX
INTRINSEC
Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610
CVE-2026-50610 : une vulnérabilité Acer permet à un utilisateur standard d’obtenir les privilèges SYSTEM sur Windows. En savoir plus..
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
https://ift.tt/WLOFCUN
Submitted October 1, 2026 at 03:27PM by The_Login
via reddit https://ift.tt/eWAfiNq
https://ift.tt/WLOFCUN
Submitted October 1, 2026 at 03:27PM by The_Login
via reddit https://ift.tt/eWAfiNq
SEC Consult
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
A case study on discovering two email spoofing vulnerabilities in Apple iCloud.
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted October 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/0CZK8gY
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted October 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/0CZK8gY
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
How to Spot a Compromised MikroTik Router
https://ift.tt/efNAUnX
Submitted October 1, 2026 at 08:16PM by ifritnoises
via reddit https://ift.tt/nZvi0Vy
https://ift.tt/efNAUnX
Submitted October 1, 2026 at 08:16PM by ifritnoises
via reddit https://ift.tt/nZvi0Vy
Ifrit
The Lucifer: How to Spot a Compromised MikroTik Router
How attackers turn a MikroTik router's own features against the network, and how to detect it in the configuration