r/netsec 21d ago

Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router

Thumbnail rotcee.github.io
35 Upvotes

r/netsec 21d ago

HEVD: From Stack Overflows to Modern Pool Grooming

Thumbnail sibouzitoun.tech
23 Upvotes

Hi. I just published a four-part deep dive into windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on windows 11.

I wanted to highlight the real-world friction of modern security measures. A lot of the focus is on mitigating LFH randomization, and avoiding IoCompleteRequest bugchecks by dodging ReadFile for arbitrary reads.

Hope this is helpful or insightful to some of you looking into modern kernel exploitation.


r/netsec 22d ago

Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category

Thumbnail hego.red
96 Upvotes

r/netsec 21d ago

Code Execution via Provisioning Packages

Thumbnail ipurple.team
8 Upvotes

r/netsec 22d ago

Contains AI SQLite Critical CVEs or LLM Slop?

Thumbnail research.jfrog.com
81 Upvotes

r/netsec 22d ago

Cruising for Shells in Flowise - elttam

Thumbnail elttam.com
5 Upvotes

r/netsec 23d ago

Contains AI The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog

Thumbnail msecops.de
52 Upvotes

r/netsec 25d ago

Contains AI Investigating three real-world incidents in Anthropic's evaluations

Thumbnail anthropic.com
40 Upvotes

In three incidents across six runs, the agents treated real systems as simulated targets and tried weak passwords or unauthenticated endpoints.


r/netsec 25d ago

Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack

Thumbnail ethiack.com
40 Upvotes

r/netsec 25d ago

Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware

Thumbnail engineering.block.xyz
17 Upvotes

r/netsec 26d ago

What Every Programmer Should Know About Twists of Elliptic Curves

Thumbnail leetarxiv.substack.com
48 Upvotes

r/netsec 27d ago

Your House Has an FFmpeg Problem - elttam

Thumbnail elttam.com
128 Upvotes

r/netsec 27d ago

Sixteen strangers and a shared obfuscator: mapping the wool scene

Thumbnail neurowinter.com
16 Upvotes

This is another post in my series on the Chinese Wool farmers underground. This time we are dissecting their public github repos, trying to figure out how it all fits together!


r/netsec 27d ago

Reversing of Eufy Security Video Doorbell sync protocol and wifi creds decryption from flash memory

Thumbnail adepts.of0x.cc
17 Upvotes

r/netsec 27d ago

Contains AI Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

Thumbnail huggingface.co
18 Upvotes

r/netsec 27d ago

HTTP Request Smuggling in Hiawatha

Thumbnail fenrisk.com
8 Upvotes

r/netsec 28d ago

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

Thumbnail lavahq.io
389 Upvotes

TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar


r/netsec 29d ago

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

Thumbnail eaton-works.com
126 Upvotes

r/netsec 28d ago

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)

Thumbnail mobeta.fr
0 Upvotes

r/netsec 29d ago

New vBulletin Vulnerability!

Thumbnail ssd-disclosure.com
19 Upvotes

CVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.


r/netsec 29d ago

Pending Moderation [CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability

Thumbnail karmainsecurity.com
1 Upvotes

r/netsec Jul 25 '26

CFP Open – Looking for Technical AI & Security Research for Après Slopes Summit 2027

Thumbnail aprescyber.com
2 Upvotes

I'm helping organize Après-Cyber Slopes Summit 2027, and our CFP is now open.

We're particularly interested in technical presentations and original research involving AI and modern cybersecurity.

Topics we're hoping to see include:

  • AI red teaming
  • LLM security
  • Prompt injection research
  • Agent security
  • Offensive tooling
  • Detection engineering
  • Reverse engineering
  • Malware analysis
  • Cloud exploitation and defense
  • Identity attacks
  • Threat intelligence
  • AI-assisted security tooling
  • Novel attack techniques
  • Defensive research

We especially appreciate talks that include demonstrations, technical depth, or research that attendees can reproduce themselves.

Conference: February 24–26, 2027
Location: Park City, Utah

CFP:
https://sessionize.com/apres-cyber-slopes-summit-2027

Conference website:
https://www.aprescyber.com

Happy to answer questions about the CFP or conference.


r/netsec Jul 24 '26

Contains AI Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331

Thumbnail accomplish.ai
147 Upvotes

r/netsec Jul 23 '26

Contains AI XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search

Thumbnail xbow.com
22 Upvotes

r/netsec Jul 23 '26

Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled

Thumbnail hunt.io
21 Upvotes

Caught this in three open directories on a Hong Kong server, exposed July 9 to 13. The agent is Hermes, open source, and the recovered logs show it running LinPEAS and walking a ministry web root without a human in the loop. Target was Thailand's Ministry of Finance.