Elektrine lite

← Feed

/r/netsec

_r_netsec@infosec.exchange

<p>Follow for new posts submitted to the netsec subreddit. Unofficial.</p>

Posts

  • View post

    CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack https://fortbridge.co.uk/research/cve-2026-32740-nextjs-sharp-libheif-rce/

  • View post

    AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks https://sorami.com.au/research/ai-kubernetes-helm-chart-security/

  • View post

    Hard Stop: Kernel-Level Preemption and Containment for Rogue Agentic Execution (arXiv:2609.29808) [pdf] https://arxiv.org/abs/2609.29808

  • View post

    Fake Journalist phishing scam targeting tech founders https://casco.com/blog/how-my-unicorn-founder-friend-was-phished

  • View post

    How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail https://idnsec.com/research/linux-local-privilege-escalation-with-af-alg/

  • View post

    CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018 https://daubois.dev/blog/cve-2026-91766-php-http-redirect-credential-leak/

  • View post

    One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts https://blog.doyensec.com/2026/09/24/chrome-ios-policy-bypass.html

  • View post

    How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers https://blog.cloudflare.com/containers-cross-tenant-vulnerability/

  • View post

    Frame: Grounding LLM Vulnerability Detection with a Sound Separation-Logic Core https://lambdasec.github.io/Frame-Grounding-LLM-Vulnerability-Detection-with-a-Sound-Separation-Logic-Core/

  • View post

    AI Agents Keep Falling to &#39;Goal Hijack&#39; (Copilot, Cursor, Grok) https://darkmarc.substack.com/p/hijacking-ai-agents-how-an-agents

  • View post

    Fastest CVE informer | EchelonGraph https://echelongraph.io/pulse

  • View post

    BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension https://forever.security/blog/bragjack-attack-hijacks-every-browser-agent

  • View post

    The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog https://www.msecops.de/blog/posts/backdoored-llms/

  • View post

    Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

  • View post

    Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack https://ethiack.com/info-hub/research/kindarails2shell-how-a-matlab-file-reads-your-secrets-and-pops-a-shell-on-ruby-on-rails

  • View post

    What Every Programmer Should Know About Twists of Elliptic Curves https://leetarxiv.substack.com/p/twists-of-elliptic-curves

  • View post

    Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/

  • View post

    Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models https://clearbluejar.github.io/posts/does-abliteration-skew-your-bug-hunting/

  • View post

    ETW for Security Research: Providers, Sessions, and Detection Engineering https://idov31.github.io/posts/inside-etw-with-etwsuite

  • View post

    SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn&#39;t Work Revealed a Kernel-Wide Design Compromise https://sibouzitoun.tech/articles/smap-is-pre-disarmed/

  • View post

    Mandatory User Profile for Persistence &amp; EDR Evasion https://ipurple.team/2026/08/11/mandatory-user-profile/

  • View post

    Finally, something useful from Google regarding search hijacking https://www.ghacks.net/2026/08/03/google-chrome-prepares-default-block-for-extensions-that-hijack-the-new-tab-page-or-search-engine/

  • View post

    DEFCON: New Red Team Tactic https://doctoreww.github.io/EvilFontTool/

  • View post

    Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village) https://ethiack.com/info-hub/research/write-once-shell-everywhere-arbitrary-file-writes-into-rce

  • View post

    From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation https://www.coinspect.com/blog/ill-bloom-investigation/

  • View post

    OpenAI agents rebuilt a secret message board after the company shut it down https://runtimewire.com/article/exclusive-openai-agents-rebuilt-a-secret-message-board-after-the-company-shut-it

  • View post

    Data leaks between users and sessions are a design problem https://iamvera.ai/blog/data-leaks-between-users-sessions-design-problem/

  • View post

    Traditional networking vs SDN https://www.researchgate.net/figure/Traditional-networking-versus-SDN-networking_fig1_324941281

  • View post

    Code Execution via Provisioning Packages https://ipurple.team/2026/08/04/provisioning-packages/

  • View post

    Xpsd: decide if a CVE is actually reachable in your tree (SARIF / GitHub code scanning) https://byteray.co.uk/xpsd