How to Hack Time, With C2PA
https://ift.tt/niGhOW7
Submitted October 4, 2026 at 03:42PM by si9int
via reddit https://ift.tt/QXzZBp7
https://ift.tt/niGhOW7
Submitted October 4, 2026 at 03:42PM by si9int
via reddit https://ift.tt/QXzZBp7
Open Build Service, one year later: command execution through Mercurial argument injection
https://ift.tt/Vx0WRoG
Submitted October 5, 2026 at 01:48PM by SzLam__
via reddit https://ift.tt/Rcf7CBP
https://ift.tt/Vx0WRoG
Submitted October 5, 2026 at 01:48PM by SzLam__
via reddit https://ift.tt/Rcf7CBP
Fenrisk
Open Build Service, one year later: command execution through Mercurial argument injection
In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family.…
Wordpress libheif RCE
https://ift.tt/Qp7IP5m
Submitted October 5, 2026 at 03:16PM by adrian_rt
via reddit https://ift.tt/jWYFDu0
https://ift.tt/Qp7IP5m
Submitted October 5, 2026 at 03:16PM by adrian_rt
via reddit https://ift.tt/jWYFDu0
FORTBRIDGE
WordPress libheif RCE
How a WordPress libheif RCE uses returned pixels to bypass ASLR, trigger a heap overflow and execute commands on exact Ubuntu and Debian stacks.
SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
https://ift.tt/ymeN1TE
Submitted October 6, 2026 at 02:24AM by Huge-Skirt-6990
via reddit https://ift.tt/nlFgurj
https://ift.tt/ymeN1TE
Submitted October 6, 2026 at 02:24AM by Huge-Skirt-6990
via reddit https://ift.tt/nlFgurj
malext.io
RedirectorsHub: SelectorsHub Forced-Tab Ad Network - MalExt Sentry
Threat intelligence report: RedirectorsHub: SelectorsHub Forced-Tab Ad Network. Research by MalExt Sentry.
Teaching network intrusion in the funnest way possible
https://ift.tt/PiVj6o3
Submitted October 6, 2026 at 07:27PM by ProjectRedTeam
via reddit https://ift.tt/8BYpGX6
https://ift.tt/PiVj6o3
Submitted October 6, 2026 at 07:27PM by ProjectRedTeam
via reddit https://ift.tt/8BYpGX6
Steampowered
Project RedTeam: Contract Offensive on Steam
A fast paced hacking roguelite built on real cybersecurity tradecraft. Recon targets, steal creds, move laterally, exfiltrate data, and ransom organizations to pay off your "Debts To Be Paid". Over 500 cards and items to discover. High risk, high reward.…
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
https://ift.tt/aXb5fm0
Submitted October 6, 2026 at 10:36PM by dx7r__
via reddit https://ift.tt/NHwvXGU
https://ift.tt/aXb5fm0
Submitted October 6, 2026 at 10:36PM by dx7r__
via reddit https://ift.tt/NHwvXGU
watchTowr Labs
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
Welcome back to yet another episode of "security was taken seriously".
Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure…
Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure…
Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day
https://ift.tt/Od0TKYA
Submitted October 7, 2026 at 01:25AM by lares-hacks
via reddit https://ift.tt/N9piZ1n
https://ift.tt/Od0TKYA
Submitted October 7, 2026 at 01:25AM by lares-hacks
via reddit https://ift.tt/N9piZ1n
Lares
Technical Analysis of the Rockstar Games Compromises: Exploit Chaining and Zero Trust Failures (2018–2026)
What the Rockstar Games security incidents teach defenders about phishing-resistant MFA, SaaS token risk, internal segmentation, and data exfiltration detection.
Bitvulnex: a vulnerable crypto exchange
https://ift.tt/72en0Pj
Submitted October 7, 2026 at 02:59AM by juliocesarfort
via reddit https://ift.tt/ZPBxb9T
https://ift.tt/72en0Pj
Submitted October 7, 2026 at 02:59AM by juliocesarfort
via reddit https://ift.tt/ZPBxb9T
Blazeinfosec
Bitvulnex: a vulnerable crypto exchange | Blaze Labs
Learn crypto exchange security with Bitvulnex, Blaze’s open-source lab featuring 40 planted vulnerabilities, CTF mode, and local Docker installation.
ncrypt the prompt injection. Let Copilot decrypt it for you.
https://ift.tt/yrxVw4e
Submitted October 7, 2026 at 11:48AM by Haunting_Ganache_850
via reddit https://ift.tt/teDlOXd
https://ift.tt/yrxVw4e
Submitted October 7, 2026 at 11:48AM by Haunting_Ganache_850
via reddit https://ift.tt/teDlOXd
Adversa AI
GitHub Copilot CLI vulnerability leaks developer secrets
One encrypted web page makes GitHub Copilot CLI read local files and send them to an attacker in 28 seconds. GitHub won't call it a vulnerability.
One Copilot model refused. Another leaked secrets about half the time.
https://ift.tt/yrxVw4e
Submitted October 7, 2026 at 12:15PM by Haunting_Ganache_850
via reddit https://ift.tt/mtgpxD1
https://ift.tt/yrxVw4e
Submitted October 7, 2026 at 12:15PM by Haunting_Ganache_850
via reddit https://ift.tt/mtgpxD1
Adversa AI
GitHub Copilot CLI vulnerability leaks developer secrets
One encrypted web page makes GitHub Copilot CLI read local files and send them to an attacker in 28 seconds. GitHub won't call it a vulnerability.
Presenting DiagNG: After QCSuper, a new open-source initiative for freeing up mobile baseband Diag protocols
https://ift.tt/l8QWRDd
Submitted October 7, 2026 at 03:14PM by marin-m
via reddit https://ift.tt/iqcKYCj
https://ift.tt/l8QWRDd
Submitted October 7, 2026 at 03:14PM by marin-m
via reddit https://ift.tt/iqcKYCj
P1Sec
DiagNG: capture 2G/3G/4G/5G air interface traces to PCAP
DiagNG, the open-source successor to QCSuper: a Linux GUI tool, now in beta, that produces 2G/3G/4G/5G PCAP captures from Qualcomm Snapdragon basebands.
CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE
https://ift.tt/gGX16qt
Submitted October 7, 2026 at 06:41PM by scopedsecurity
via reddit https://ift.tt/aGitbmE
https://ift.tt/gGX16qt
Submitted October 7, 2026 at 06:41PM by scopedsecurity
via reddit https://ift.tt/aGitbmE
Horizon3
CVE-2026-102489: Zammad Session Leak to RCE
See how Horizon3 reverse engineered CVE-2026-102489 in Zammad, reproduced the session leak, hijacked an admin session, and achieved remote code execution.
I found yet another way to invoke JavaScript functions without parentheses
https://ift.tt/fQGM3TP
Submitted October 8, 2026 at 11:08AM by DrAdalbbert
via reddit https://ift.tt/b4seV1l
https://ift.tt/fQGM3TP
Submitted October 8, 2026 at 11:08AM by DrAdalbbert
via reddit https://ift.tt/b4seV1l
Pwn2Own Ireland 2026 Day 1: 32 Zero-Days, $388,500, Samsung Galaxy S26 Hacked 3 Times
https://ift.tt/2ktT6P7
Submitted October 8, 2026 at 11:45AM by LandscapePutrid4194
via reddit https://ift.tt/r4Tjt0x
https://ift.tt/2ktT6P7
Submitted October 8, 2026 at 11:45AM by LandscapePutrid4194
via reddit https://ift.tt/r4Tjt0x
ZeroHack
Pwn2Own Ireland Day 1: 32 Zero-Days & $388,500 in Payouts
Samsung Galaxy S26 hacked three times. OpenAI Codex falls to a single bug. Oracle AI Database chained with 5 zero-days. Here is the full Day 1 breakdown. #Pwn2Own #ZeroDay #ZeroHack
A Single POST Freezes Any Next.js Server
https://ift.tt/oGIOvi7
Submitted October 8, 2026 at 09:47PM by TradeGold6317
via reddit https://ift.tt/RPwuyGi
https://ift.tt/oGIOvi7
Submitted October 8, 2026 at 09:47PM by TradeGold6317
via reddit https://ift.tt/RPwuyGi
Simon Koeck
CVE-2026-23870: A Single POST Freezes Any Next.js Server | Simon Koeck
To rebuild one submitted form, React scanned every field in the request once for each reference it contained. Nothing capped either number, so one 900 KB POST makes the server do 100 million checks and freeze.
Loupe: An Android Console in the Browser
https://ift.tt/ny3hdN9
Submitted October 9, 2026 at 02:57AM by CaptMeelo
via reddit https://ift.tt/3fhNOQS
https://ift.tt/ny3hdN9
Submitted October 9, 2026 at 02:57AM by CaptMeelo
via reddit https://ift.tt/3fhNOQS
Capt. Meelo
Loupe: An Android Console in the Browser
A tool I built for driving an Android phone from a browser tab, with screen mirror, logcat, file browser, proxy, and Frida in the same window.
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483)
https://ift.tt/RAqDIvX
Submitted October 9, 2026 at 03:19AM by Pale_Fly_2673
via reddit https://ift.tt/qL6oaGh
https://ift.tt/RAqDIvX
Submitted October 9, 2026 at 03:19AM by Pale_Fly_2673
via reddit https://ift.tt/qL6oaGh
LAVA
CVE-2026-47483: NVIDIA DCGM Exporter Vulnerability Exposes GPU Servers | LAVA
CVE-2026-47483 lets attackers crash NVIDIA DCGM Exporter via pprof. See what 2,000+ exposed GPU servers leaked and how to fix it.