CVE-2026-102489 Deep-Dive: Zammad Session Leak to RCE
https://ift.tt/gGX16qt
Submitted October 7, 2026 at 06:41PM by scopedsecurity
via reddit https://ift.tt/aGitbmE
https://ift.tt/gGX16qt
Submitted October 7, 2026 at 06:41PM by scopedsecurity
via reddit https://ift.tt/aGitbmE
Horizon3
CVE-2026-102489: Zammad Session Leak to RCE
See how Horizon3 reverse engineered CVE-2026-102489 in Zammad, reproduced the session leak, hijacked an admin session, and achieved remote code execution.
I found yet another way to invoke JavaScript functions without parentheses
https://ift.tt/fQGM3TP
Submitted October 8, 2026 at 11:08AM by DrAdalbbert
via reddit https://ift.tt/b4seV1l
https://ift.tt/fQGM3TP
Submitted October 8, 2026 at 11:08AM by DrAdalbbert
via reddit https://ift.tt/b4seV1l
Pwn2Own Ireland 2026 Day 1: 32 Zero-Days, $388,500, Samsung Galaxy S26 Hacked 3 Times
https://ift.tt/2ktT6P7
Submitted October 8, 2026 at 11:45AM by LandscapePutrid4194
via reddit https://ift.tt/r4Tjt0x
https://ift.tt/2ktT6P7
Submitted October 8, 2026 at 11:45AM by LandscapePutrid4194
via reddit https://ift.tt/r4Tjt0x
ZeroHack
Pwn2Own Ireland Day 1: 32 Zero-Days & $388,500 in Payouts
Samsung Galaxy S26 hacked three times. OpenAI Codex falls to a single bug. Oracle AI Database chained with 5 zero-days. Here is the full Day 1 breakdown. #Pwn2Own #ZeroDay #ZeroHack
A Single POST Freezes Any Next.js Server
https://ift.tt/oGIOvi7
Submitted October 8, 2026 at 09:47PM by TradeGold6317
via reddit https://ift.tt/RPwuyGi
https://ift.tt/oGIOvi7
Submitted October 8, 2026 at 09:47PM by TradeGold6317
via reddit https://ift.tt/RPwuyGi
Simon Koeck
CVE-2026-23870: A Single POST Freezes Any Next.js Server | Simon Koeck
To rebuild one submitted form, React scanned every field in the request once for each reference it contained. Nothing capped either number, so one 900 KB POST makes the server do 100 million checks and freeze.
Loupe: An Android Console in the Browser
https://ift.tt/ny3hdN9
Submitted October 9, 2026 at 02:57AM by CaptMeelo
via reddit https://ift.tt/3fhNOQS
https://ift.tt/ny3hdN9
Submitted October 9, 2026 at 02:57AM by CaptMeelo
via reddit https://ift.tt/3fhNOQS
Capt. Meelo
Loupe: An Android Console in the Browser
A tool I built for driving an Android phone from a browser tab, with screen mirror, logcat, file browser, proxy, and Frida in the same window.
How We Found Thousands of Exposed NVIDIA GPUs and a Way to Disrupt Them (CVE-2026-47483)
https://ift.tt/RAqDIvX
Submitted October 9, 2026 at 03:19AM by Pale_Fly_2673
via reddit https://ift.tt/qL6oaGh
https://ift.tt/RAqDIvX
Submitted October 9, 2026 at 03:19AM by Pale_Fly_2673
via reddit https://ift.tt/qL6oaGh
LAVA
CVE-2026-47483: NVIDIA DCGM Exporter Vulnerability Exposes GPU Servers | LAVA
CVE-2026-47483 lets attackers crash NVIDIA DCGM Exporter via pprof. See what 2,000+ exposed GPU servers leaked and how to fix it.
A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline
https://ift.tt/tXzg17B
Submitted October 9, 2026 at 05:02AM by Mempodipper
via reddit https://ift.tt/uZzFbHh
https://ift.tt/tXzg17B
Submitted October 9, 2026 at 05:02AM by Mempodipper
via reddit https://ift.tt/uZzFbHh
www.slcyber.io
A JPEG, a Race, and a Ghost: Breaking Discourse's Image Pipeline
We discovered an arbitrary file read vulnerability in Discourse's image pipeline by chaining a JPEG race condition with ImageMagick and Ghostscript.
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE-2026-81578) - watchTowr Labs
https://ift.tt/WFoPhy8
Submitted October 9, 2026 at 11:47PM by dx7r__
via reddit https://ift.tt/jC7ESBZ
https://ift.tt/WFoPhy8
Submitted October 9, 2026 at 11:47PM by dx7r__
via reddit https://ift.tt/jC7ESBZ
watchTowr Labs
Death By A Thousand PaperCuts (PaperCut Pre-Auth RCE Chain and Patch Bypasses WT-2026-0141-0144/CVE-2026-82077/CVE-2026-82078/CVE…
Before we begin, yes - it's confusing. There are more vulnerabilities with watchTowr IDs in this blog post than there are CVE IDs (assigned by PaperCut), due to PaperCut bundling vulnerabilities and then patch bypasses for those same vulnerabilities into…
GitHub Actions leaking secrets when Miri output is cached
https://ift.tt/xw7hYnz
Submitted October 10, 2026 at 05:24PM by Beaconamber
via reddit https://ift.tt/8UeyTEV
https://ift.tt/xw7hYnz
Submitted October 10, 2026 at 05:24PM by Beaconamber
via reddit https://ift.tt/8UeyTEV
blog.rust-lang.org
GitHub Actions leaking secrets when Miri output is cached | Rust Blog
Empowering everyone to build reliable and efficient software.
Smashing the token limit with overlapping fragments (CSS injection token exfiltration, PortSwigger Research)
https://ift.tt/NmJazve
Submitted October 10, 2026 at 03:30PM by theomkamble
via reddit https://ift.tt/qKh026C
https://ift.tt/NmJazve
Submitted October 10, 2026 at 03:30PM by theomkamble
via reddit https://ift.tt/qKh026C
PortSwigger Research
Smashing the token limit with overlapping fragments
I'm delighted to introduce Alex, my fellow swigger who I've collaborated with in the past with tools like DOM Invader. He showed me that it's possible to exfiltrate larger tokens than demonstrated in
AI Agent Security: Six Controls From Nine Real Incidents
https://ift.tt/am5KGqJ
Submitted October 10, 2026 at 07:38PM by guedou
via reddit https://ift.tt/sktvemi
https://ift.tt/am5KGqJ
Submitted October 10, 2026 at 07:38PM by guedou
via reddit https://ift.tt/sktvemi
GitGuardian Blog - Take Control of Your Secrets Security
AI Agent Security: Six Controls From Nine Real Incidents
An AI agent runs with your credentials and acts before you can stop it. Nine incidents show what that costs. Six controls limit the damage: sandbox the agent, scope its credentials, lock its configuration, log every call, scan the workspace first, and deny…
A story of wifi secrets, UART lockdowns and a damaged flash memory chip
https://ift.tt/wyZsvM7
Submitted October 10, 2026 at 11:02PM by gid0rah
via reddit https://ift.tt/rmG2D4T
https://ift.tt/wyZsvM7
Submitted October 10, 2026 at 11:02PM by gid0rah
via reddit https://ift.tt/rmG2D4T
A story of wifi secrets, UART lockdowns and a damaged flash memory chip |
A story of wifi secrets, UART lockdowns and a damaged flash memory chip | AdeptsOf0xCC
Analyzing Eufy Security Ecosystem and reverse engineering of its Homebase2 component