Elektrine lite

← Feed

/r/netsec

_r_netsec@infosec.exchange

<p>Follow for new posts submitted to the netsec subreddit. Unofficial.</p>

Posts

  • Post #4501799

    ETW for Security Research: Providers, Sessions, and Detection Engineering https://idov31.github.io/posts/inside-etw-with-etwsuite

  • Post #4496856

    SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn&#39;t Work Revealed a Kernel-Wide Design Compromise https://sibouzitoun.tech/articles/smap-is-pre-disarmed/

  • Post #4493162

    Mandatory User Profile for Persistence &amp; EDR Evasion https://ipurple.team/2026/08/11/mandatory-user-profile/

  • Post #4461466

    Finally, something useful from Google regarding search hijacking https://www.ghacks.net/2026/08/03/google-chrome-prepares-default-block-for-extensions-that-hijack-the-new-tab-page-or-search-engine/

  • Post #4458323

    DEFCON: New Red Team Tactic https://doctoreww.github.io/EvilFontTool/

  • Post #4443087

    Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village) https://ethiack.com/info-hub/research/write-once-shell-everywhere-arbitrary-file-writes-into-rce

  • Post #4402401

    From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation https://www.coinspect.com/blog/ill-bloom-investigation/

  • Post #4395564

    OpenAI agents rebuilt a secret message board after the company shut it down https://runtimewire.com/article/exclusive-openai-agents-rebuilt-a-secret-message-board-after-the-company-shut-it

  • Post #4391648

    Data leaks between users and sessions are a design problem https://iamvera.ai/blog/data-leaks-between-users-sessions-design-problem/

  • Post #4387987

    Traditional networking vs SDN https://www.researchgate.net/figure/Traditional-networking-versus-SDN-networking_fig1_324941281

  • Post #4370456

    Code Execution via Provisioning Packages https://ipurple.team/2026/08/04/provisioning-packages/

  • Post #4362463

    Xpsd: decide if a CVE is actually reachable in your tree (SARIF / GitHub code scanning) https://byteray.co.uk/xpsd

  • Post #4353649

    Cruising for Shells in Flowise - elttam https://www.elttam.com/blog/cruising-for-shells-in-flowise

  • Post #4334332

    The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog https://www.msecops.de/blog/posts/backdoored-llms/

  • Post #4281294

    Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware

  • Post #4276383

    Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack https://ethiack.com/info-hub/research/kindarails2shell-how-a-matlab-file-reads-your-secrets-and-pops-a-shell-on-ruby-on-rails

  • Post #4245036

    What Every Programmer Should Know About Twists of Elliptic Curves https://leetarxiv.substack.com/p/twists-of-elliptic-curves

  • Post #4243059

    KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066

  • Post #4219540

    Detection and Enforcement for Endpoint AI Agents https://research.perplexity.ai/articles/securing-agents-across-perplexity%E2%80%99s-client-endpoints-with-numbat

  • Post #4211708

    Sixteen strangers and a shared obfuscator: mapping the wool scene https://neurowinter.com/security/2026/07/28/the-cast-and-crew/

  • Post #4202341

    Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident https://huggingface.co/blog/agent-intrusion-technical-timeline

  • Post #4197466

    Your House Has an FFmpeg Problem - elttam https://www.elttam.com/blog/your-house-has-an-ffmpeg-problem

  • Post #4172373

    Hush Security raises $30 million to govern enterprise AI agents https://runtimewire.com/article/hush-security-raises-30m-ai-agent-governance

  • Post #4172352

    Claude Mythos degrades HAWK and developed new exploit for round-reduced AES https://www.anthropic.com/research/discovering-cryptographic-weaknesses

  • Post #4170335

    CFP Open – Looking for Technical AI &amp; Security Research for Après Slopes Summit 2027 https://www.aprescyber.com/

  • Post #4170085

    How AI is powering business email compromise at scale https://research.eye.security/phishing-as-a-service-inside-two-ai-powered-phishing-kits-that-automate-bec/

  • Post #4170081

    Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon

  • Post #4166367

    Designing Patterns to Prevent IDOR https://sevhunt.com/docs/blog/designing-patterns-to-prevent-idor/

  • Post #4165841

    Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/

  • Post #4165089

    How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability https://lavahq.io/research/bmc-exposure-alert