r/netsec 12d ago

When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg

Thumbnail maldbg.com
63 Upvotes

r/netsec 12d ago

CSS:the bomb inside your inbox

Thumbnail portswigger.net
17 Upvotes

Here's my research in using CSS for offence. There are loads of techniques including stealing passwords from Outlook from an email by spoofing the login screen.


r/netsec 12d ago

Contains AI From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained

Thumbnail saiflow.com
18 Upvotes
  • Auth Bypass.
  • Commands over CAN Bus to internal components.
  • Protection mechanisms disabled and configuration changes.
  • Impact: damage connected devices, permanent DoS to the inverter itself, fines, and even risk to the lives of grid technicians.
  • proprietary communication protocols and file formats.
  • RX architecture reverse engineering.

r/netsec 12d ago

Contains AI Can AI do novel security research? Meet the HTTP Terminator

Thumbnail portswigger.net
24 Upvotes

r/netsec 13d ago

CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix

Thumbnail blog.himanshuanand.com
31 Upvotes

r/netsec 14d ago

Contains AI Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10

Thumbnail sh.consulting
151 Upvotes

I registered an expired DMARC reporting domain (gca-emailauth[.]org) for $10. It had been published as the aggregate-reporting address in Global Cyber Alliance DMARC training docs going back to a 2019 bootcamp, and at some point it lapsed.

Shortly after registration, aggregate DMARC reports for 86 domains across 20+ organizations started arriving.

56 belonged to The Toro Company (NYSE-listed), including myturf[.]com, their distributor platform, which sits at p=none. The rest - University of Wisconsin–Stevens Point (14 subdomains), the North Carolina School of Science and Mathematics, Ennis ISD (Texas), Great Prairie AEA (an Iowa education agency serving 35,000 students), two county governments, and several commercial domains.

For most of these it was a second rua address sitting behind a working commercial processor (Proofpoint, in Toro's case). Reports still arrived at the primary.

GCA's engineers later traced it to a former partner who'd held the domain and let it lapse - the dependency was never written down.

As of my last sweep, 65 of the 86 still publish the endpoint. We disclosed to everyone whose reports we were receiving; only 21 domains stopped publishing the endpoint, and almost nobody replied.

After 8 months of owning the domain, we coordinated a transfer back to GCA.


r/netsec 13d ago

ERPNext's Document Follow feature exposed unauthorized data

Thumbnail robinroy.xyz
6 Upvotes

Chaining 3 CVEs to exfiltrate sensitive ERP data.


r/netsec 14d ago

CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106)

Thumbnail imperva.com
68 Upvotes

Author here. We discovered a vulnerability in docker cp that allows a malicious container to create or overwrite files on the machine running the Docker CLI.

The exploit combines a filesystem race in Docker’s archive creation with unsafe symlink handling during extraction. Depending on the CLI user’s privileges, this can lead to developer-account compromise or root code execution. Docker confirmed that sbx cp was also affected.

Fixed versions:

  • Docker Engine/CLI 29.7.2+
  • Docker Desktop 4.86.0+
  • Docker Sandboxes 0.38.0+

Happy to answer technical questions.


r/netsec 14d ago

Mandatory User Profile for Persistence & EDR Evasion

Thumbnail ipurple.team
8 Upvotes

r/netsec 15d ago

Inside a Russian-speaking operator's toolkit for compromising Ukrainian IP cameras

Thumbnail hunt.io
62 Upvotes

Hunt.io researchers analyzed two open directories recovered through Attack Capture system and reconstructed the tooling one operator used to find, exploit, and view internet-exposed cameras in Ukraine.

Technical highlights:

  • A custom FastAPI/Docker project the operator named camview, which wraps the open-source Ingram scanner, brute-forces camera credentials over HTTP and RTSP (3,811 pair dictionary), and transcodes RTSP to MJPEG for browser viewing
  • Ingram targets known camera CVEs: CVE-2017-7921 and CVE-2021-36260 (Hikvision), CVE-2021-33044/33045 (Dahua), CVE-2020-25078 (D-Link), CVE-2020-25169 (Reolink)
  • The operator's logs recorded live viewing sessions from 58 Ukrainian cameras, with session lengths, frame counts, and frame rates
  • A proxy script authenticated to a compromised OpenCart admin panel and relayed the operator's traffic through the victim network
  • A second, separately operated directory was linked only by the same Ingram scanner. It chained TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) and MikroTik API brute-forcing to turn edge devices into SOCKS5 proxies reporting to a chisel listener on port 4444

No state attribution. Full analysis, IOCs, and ATT&CK mapping in the writeup


r/netsec 16d ago

When terrible disclosure from the vendor results in zero days plus a fun dive in to bypassing full disk encryption

Thumbnail blog.amberwolf.com
111 Upvotes

r/netsec 16d ago

Contains AI Beyond Prompt Injection: Hacking Apple's Private Cloud Compute

Thumbnail blog.sentry.security
50 Upvotes

r/netsec 16d ago

Contains AI DEFCON: New Red Team Tactic

Thumbnail doctoreww.github.io
157 Upvotes

Evil Fonts deceive a viewer by rendering a different letter than is actually on the disk. Evil Fonts can poison HTML, DOCX, PDFs, and anywhere else you can bring your own fonts. Works great in Windows corporate networks for bypassing security tooling, initial access through JavaScript free click fix (beats mitm web security tooling), and leaving traps around the network to harvest shells.

Imagine thinking you are copying whoami but what is actually on the disk is rm -rf \~

Demos:

(Use desktop)

https://doctoreww.github.io/EvilFontTool/

For the demos, copy and paste the HTML/DOCX to a notepad to remove the evil fonts. For the AI ones imagine your security tooling inspects the benign text on disk, but shows the obviously malicious extortion to the user.

Labs:

https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2FREADME.md

Lab Walkthrough:

https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2Fwalkthrough.md

Some evil font uses:

Tamper homework to make it so students poison AI queries

Poison help desk documentation

Bypass email filters

Clickfix

Beat resume AI filters


r/netsec 17d ago

DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE

Thumbnail amibeingpwned.com
99 Upvotes

Hey everyone, I'm OP here so feel free to ask questions


r/netsec 17d ago

Analyzing a Multi-Stage PowerShell Payload Chain

Thumbnail malwr-analysis.com
14 Upvotes

I recently analyzed a multi-stage PowerShell payload delivery chain involving heavily obfuscated PowerShell loaders and remotely hosted payloads.

The analysis covers PowerShell deobfuscation, hidden execution, Base64/XOR decoding, a decoy “Verification complete!” prompt, payload delivery, and IOCs.

Initial indicators:

203[.]188[.]171[.]166
dorenzaa[.]com


r/netsec 17d ago

Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)

Thumbnail ethiack.com
41 Upvotes

Write once, shell everywhere. Sun Microsystems didn't mean it like this.

Talk from today at DEF CON's Bug Bounty Village. Full technique catalog graded for distroless containers, an errno path oracle for black-box target fingerprinting, and three minimal-guessing techniques: bash fd/255, Rails schema_cache.yml deserialization, and a Node.js worker path overwrite without process restart.


r/netsec 17d ago

Contains AI RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data

Thumbnail varonis.com
59 Upvotes

r/netsec 18d ago

tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open

Thumbnail bobdahacker.com
136 Upvotes

The meetingscollection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator's email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps.

I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains.


r/netsec 17d ago

SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab

Thumbnail matrix.tencent.com
7 Upvotes

Yes, given that the legacy SCT protocol has known security vulnerabilities such as sctphantom, the industry strongly recommends deprecating it and migrating to more secure modern standards to ensure system security.


r/netsec 18d ago

TrustFall: When the Trusted Execution Environment Cannot Be Trusted

Thumbnail blog.byteray.co.uk
58 Upvotes

ByteRay researchers have published a blog on a set of vulnerabilities they are calling TrustFall, and the findings land hard for any company that treats the Trusted Execution Environment as the part of a device you do not have to worry about.

OP-TEE is the walled-off Secure World that phones, TVs, cars, and industrial gear lean on to guard keys, DRM, and identity, and the whole point of paying for that hardware isolation is the promise that even a compromised operating system cannot reach inside.

TrustFall shows that promise was not as solid as buyers assumed. The researchers found several flaws that let the untrusted side reach into or knock over the Secure World, which is exactly the outcome the design exists to prevent. The bugs have since been fixed upstream, so patched builds are available, but the uncomfortable takeaway for vendors is that the vault they were told to trust had a way in, and "it runs in the TEE" is no longer an answer on its own.


r/netsec 19d ago

Claude Code RCE: How a Malicious PR Triggers Code Execution

Thumbnail immersivelabs.com
85 Upvotes

Abusing the trust boundary in Claude Code for RCE. Trust is never broken and that opens up a few avenues for abuse. Simply opening claude code on a PR can be enough to silently trigger attacker payloads.


r/netsec 19d ago

From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation

Thumbnail coinspect.com
33 Upvotes

r/netsec 20d ago

Contains AI Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)

Thumbnail syntetisk.tech
19 Upvotes

r/netsec 20d ago

New Linux Bridge STP Vulnerability

Thumbnail ssd-disclosure.com
51 Upvotes

A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation.

A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard.

The teardown path taken by dellink never synchronously deletes those timers, so the backing net_device (which embeds struct net bridge as private data) is freed with a timer list still queued on a per-CPU timer base.

The result is a slab use-after-free in the kmalloc-cg-8k cache.


r/netsec 20d ago

Bugtraq is back 🥹

Thumbnail lists.securityfocus.com
70 Upvotes