New Local Privilege Escalation on Acer laptops
https://ift.tt/2s6ywBh
Submitted October 1, 2026 at 01:04PM by Intrinsec_
via reddit https://ift.tt/PsqweZX
https://ift.tt/2s6ywBh
Submitted October 1, 2026 at 01:04PM by Intrinsec_
via reddit https://ift.tt/PsqweZX
INTRINSEC
Acer System Monitor: from standard user to SYSTEM with CVE-2026-50610
CVE-2026-50610 : une vulnérabilité Acer permet à un utilisateur standard d’obtenir les privilèges SYSTEM sur Windows. En savoir plus..
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
https://ift.tt/WLOFCUN
Submitted October 1, 2026 at 03:27PM by The_Login
via reddit https://ift.tt/eWAfiNq
https://ift.tt/WLOFCUN
Submitted October 1, 2026 at 03:27PM by The_Login
via reddit https://ift.tt/eWAfiNq
SEC Consult
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
A case study on discovering two email spoofing vulnerabilities in Apple iCloud.
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted October 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/0CZK8gY
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.Rules & GuidelinesAlways maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.Avoid use of memes. If you have something to say, say it with real words.All discussions and questions should directly relate to netsec.No tech support is to be requested or provided on r/netsec.As always, the content & discussion guidelines should also be observed on r/netsec.FeedbackFeedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
Submitted October 1, 2026 at 06:59PM by albinowax
via reddit https://ift.tt/0CZK8gY
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
How to Spot a Compromised MikroTik Router
https://ift.tt/efNAUnX
Submitted October 1, 2026 at 08:16PM by ifritnoises
via reddit https://ift.tt/nZvi0Vy
https://ift.tt/efNAUnX
Submitted October 1, 2026 at 08:16PM by ifritnoises
via reddit https://ift.tt/nZvi0Vy
Ifrit
The Lucifer: How to Spot a Compromised MikroTik Router
How attackers turn a MikroTik router's own features against the network, and how to detect it in the configuration
Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files
https://ift.tt/M6xFZdY
Submitted October 1, 2026 at 09:41PM by ultrastrik3
via reddit https://ift.tt/R2ltLir
https://ift.tt/M6xFZdY
Submitted October 1, 2026 at 09:41PM by ultrastrik3
via reddit https://ift.tt/R2ltLir
UltraStrike Cybersecurity
Server Mismatch: WordPress Plugin Vulnerabilities When Relying On .htaccess Files
Table of Contents
Table of ContentsKey TakeawaysWelcomeBackgroundDetailsExamplesEverest BackupBackWPUpExposureDigitalOceanAzure AppServiceAWS LightSailAkamai (Linode)WordPress.comDreamHostLiquidWebBlueHostShodanResponseServer AdministratorsSecurity An…
Table of ContentsKey TakeawaysWelcomeBackgroundDetailsExamplesEverest BackupBackWPUpExposureDigitalOceanAzure AppServiceAWS LightSailAkamai (Linode)WordPress.comDreamHostLiquidWebBlueHostShodanResponseServer AdministratorsSecurity An…
a CVE dispute
https://ift.tt/Kpnes94
Submitted October 2, 2026 at 03:30AM by fagnerbrack
via reddit https://ift.tt/KMWXTn5
https://ift.tt/Kpnes94
Submitted October 2, 2026 at 03:30AM by fagnerbrack
via reddit https://ift.tt/KMWXTn5
daniel.haxx.se
a CVE dispute
A few years years ago the curl project signed up and became a CNA. This means that we are masters of and can allocate our own CVE identifiers. For any security problems within our territory, it is we who decides if the issue should get a CVE or not. No more…
Prompt like a Butterfly, Sting like a Tracker: A Privacy Analysis ofWeb and Mobile Conversational AI Agents
https://ift.tt/fkD1l5t
Submitted September 30, 2026 at 08:45PM by Alarming_Minute5260
via reddit https://ift.tt/WZLBX1t
https://ift.tt/fkD1l5t
Submitted September 30, 2026 at 08:45PM by Alarming_Minute5260
via reddit https://ift.tt/WZLBX1t
Azure's Weakest Link - Five Full Cross-Tenant Compromises
https://ift.tt/k6r4HM1
Submitted October 2, 2026 at 05:45PM by piraterapper
via reddit https://ift.tt/tVhYymq
https://ift.tt/k6r4HM1
Submitted October 2, 2026 at 05:45PM by piraterapper
via reddit https://ift.tt/tVhYymq
Binary Security AS
Azure’s Weakest Link - Five Full Cross-Tenant Compromises
In my previous blog posts, Azure’s Weakest Link? and Azure’s Weakest Link - Full Cross-Tenant Compromise, I gave an overview of the severely insecure architecture behind API Connections in Azure, a part of Azure Logic Apps, and an instance of a full cross…
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
https://ift.tt/P0dDKqr
Submitted October 2, 2026 at 07:20PM by ricveloso
via reddit https://ift.tt/T4cf6Dj
https://ift.tt/P0dDKqr
Submitted October 2, 2026 at 07:20PM by ricveloso
via reddit https://ift.tt/T4cf6Dj
Grizzlysec
The zero-hour phishing gap
Nearly half the credential-phishing Grizzly catches isn't on Google's blocklist yet. Here's exactly how we measure that.
8 out of 10 Banks HATE This One Weird 3SKey RCE
https://ift.tt/w5WXKqx
Submitted October 2, 2026 at 09:35PM by acorn222
via reddit https://ift.tt/KDWSc9e
https://ift.tt/w5WXKqx
Submitted October 2, 2026 at 09:35PM by acorn222
via reddit https://ift.tt/KDWSc9e
Amibeingpwned
8 out of 10 Banks HATE This One Weird 3SKey RCE
SConnect (1M+ users), the extension and native host used to authenticate with 3SKey, SWIFT, eIDs and other hardware signing tokens, had a drive-by RCE: any site or iframe could silently download and run a DLL by exploiting an uninitialised-memory bypass in…
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
https://ift.tt/vlmoKwM
Submitted October 2, 2026 at 10:20PM by Emergency_Stable_923
via reddit https://ift.tt/fJRQzIt
https://ift.tt/vlmoKwM
Submitted October 2, 2026 at 10:20PM by Emergency_Stable_923
via reddit https://ift.tt/fJRQzIt
security.txt on the Czech web: Scanning 1k popular .cz domains
https://ift.tt/qjxInmk
Submitted October 2, 2026 at 10:22PM by _vavkamil_
via reddit https://ift.tt/R7BtaiU
https://ift.tt/qjxInmk
Submitted October 2, 2026 at 10:22PM by _vavkamil_
via reddit https://ift.tt/R7BtaiU
Kamil Vavra @vavkamil
security.txt on the Czech web: Scanning 1k popular .cz domains
Adding security.txt to the web should be easy. The RFC is fairly simple, and there aren’t many ways to fail. Well, at least I thought that, until now. Let’s look at how a very small standard can fail in surprisingly creative ways.
A peek into Reddit's anti-spam internals
https://lyra.horse/blog/2026/06/reddit-spam-internals/
Submitted October 3, 2026 at 09:30AM by fagnerbrack
via reddit https://ift.tt/Iw6VxG1
https://lyra.horse/blog/2026/06/reddit-spam-internals/
Submitted October 3, 2026 at 09:30AM by fagnerbrack
via reddit https://ift.tt/Iw6VxG1
lyra's epic blog
A peek into Reddit's anti-spam internals
How Reddit accidentally leaked its spamurai system.
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
https://ift.tt/A6W9Tr1
Submitted October 3, 2026 at 12:13PM by pascalschaerli
via reddit https://ift.tt/Cx8BjqO
https://ift.tt/A6W9Tr1
Submitted October 3, 2026 at 12:13PM by pascalschaerli
via reddit https://ift.tt/Cx8BjqO
Pascal Schärli
Post-Quantum Crypto Won't Fix Your Architecture
Adding PQC to this product was like installing a vault door on a tent. The server could intercept your keys and an RCE let attackers run code on your desktop.