Remote
/r/netsec
@_r_netsec@infosec.exchange
Follow for new posts submitted to the netsec subreddit. Unofficial.
0 Followers
0 Following
50 Posts
Joined December 01, 2022
Subreddit:
Automated by:
The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog https://www.msecops.de/blog/posts/backdoored-llms/
Open post
Code Execution via Provisioning Packages https://ipurple.team/2026/08/04/provisioning-packages/
0
0
0
0
Open post
From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation https://www.coinspect.com/blog/ill-bloom-investigation/
0
0
0
0
Open post
SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn't Work Revealed a Kernel-Wide Design Compromise https://sibouzitoun.tech/articles/smap-is-pre-disarmed/
0
0
0
0
Open post
CFP Open – Looking for Technical AI & Security Research for Après Slopes Summit 2027 https://www.aprescyber.com/
0
0
0
0
Open post
ETW for Security Research: Providers, Sessions, and Detection Engineering https://idov31.github.io/posts/inside-etw-with-etwsuite
0
0
0
0
Open post
Mandatory User Profile for Persistence & EDR Evasion https://ipurple.team/2026/08/11/mandatory-user-profile/
0
0
0
0
Open post
What Every Programmer Should Know About Twists of Elliptic Curves https://leetarxiv.substack.com/p/twists-of-elliptic-curves
0
0
0
0
Open post
Designing Patterns to Prevent IDOR https://sevhunt.com/docs/blog/designing-patterns-to-prevent-idor/
0
0
0
0
Open post
OpenAI agents rebuilt a secret message board after the company shut it down https://runtimewire.com/article/exclusive-openai-agents-rebuilt-a-secret-message-board-after-the-company-shut-it
0
0
0
0
Open post
BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms https://malext.io/reports/BrainDrain/
0
0
0
0
Open post
Hush Security raises $30 million to govern enterprise AI agents https://runtimewire.com/article/hush-security-raises-30m-ai-agent-governance
0
0
0
0
Open post
Finding actors that probe a CVE's exploit path before public disclosure in 30M honeypot records. https://honeylabs.net/blog/probe-17-days-before-the-cve
0
0
0
0
Open post
What Every Programmer Should Know About Twists of Elliptic Curves https://leetarxiv.substack.com/p/twists-of-elliptic-curves
0
0
0
0
Open post
Xpsd: decide if a CVE is actually reachable in your tree (SARIF / GitHub code scanning) https://byteray.co.uk/xpsd
0
0
0
0
Open post
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
0
0
0
0
Open post
From Google Ads to Terminal: Dissecting an Apple Support Impersonation Campaign Abusing Claude Share. https://derivai.substack.com/p/fake-claude-code-installer-macsync-malware
0
0
0
0
Open post
Traditional networking vs SDN https://www.researchgate.net/figure/Traditional-networking-versus-SDN-networking_fig1_324941281
0
0
0
0
Open post
Cruising for Shells in Flowise - elttam https://www.elttam.com/blog/cruising-for-shells-in-flowise
0
0
0
0
Open post
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) https://mobeta.fr/simple-job-board-unauth-rce-cve-2024-1813/
0
0
0
0
Open post
Ask Gemini for a "Walmart MCP" and the first result is malware. try it. https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware
0
0
0
0
Open post
PE OopsSec: Mind your PE, guard your OPSEC https://www.zerosalarium.com/2026/07/pe-oopssec-mind-your-pe-guard-your-opsec.html?m=1
0
0
0
0
Open post
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit https://www.acronis.com/en/tru/posts/red-heron-exploits-gitea-n-day-flaw-in-multinational-campaign-exposing-new-linux-rootkit/
0
0
0
0
Open post
Data leaks between users and sessions are a design problem https://iamvera.ai/blog/data-leaks-between-users-sessions-design-problem/
0
0
0
0
Open post
New vBulletin Vulnerability! https://ssd-disclosure.com/vbulletin-runtime-template-runmaths-preauth-rce/
0
0
0
0
Open post
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066) https://ethiack.com/info-hub/research/kindarails2shell-rails-rce-cve-2026-66066
0
0
0
0
Open post
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village) https://ethiack.com/info-hub/research/write-once-shell-everywhere-arbitrary-file-writes-into-rce
0
0
0
0
Open post
Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
0
0
0
0
Open post
The FCC Wants to Ban Burner Phones. The CNET Reporter Tracking This Story is Here to Chat. Ask Him Anything. https://open.substack.com/pub/pwnhackers/p/the-fcc-wants-to-ban-burner-phones?utm_source=direct&r=56wibp&utm_campaign=post-expanded-share&utm_medium=web
0
0
0
0
Open post
BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension https://forever.security/blog/bragjack-attack-hijacks-every-browser-agent
0
0
0
0
Open post
Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models https://clearbluejar.github.io/posts/does-abliteration-skew-your-bug-hunting/
0
0
0
0
Open post
Claude Mythos degrades HAWK and developed new exploit for round-reduced AES https://www.anthropic.com/research/discovering-cryptographic-weaknesses
0
0
0
0
Open post
The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog https://www.msecops.de/blog/posts/backdoored-llms/
0
0
0
0
Open post
The state of vibe-coded app security: my analysis of 549 self-described AI-generated repos (study + raw data) https://ogbuilds.ai/studies/vibe-coded-security
0
0
0
0
Open post
How AI is powering business email compromise at scale https://research.eye.security/phishing-as-a-service-inside-two-ai-powered-phishing-kits-that-automate-bec/
0
0
0
0
Open post
Your House Has an FFmpeg Problem - elttam https://www.elttam.com/blog/your-house-has-an-ffmpeg-problem
0
0
0
0
Open post
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident https://huggingface.co/blog/agent-intrusion-technical-timeline
0
0
0
0
Open post
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
0
0
0
0
Open post
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA http://scamdrill.com/blog/m365-oauth-device-code-phishing
0
0
0
0
Open post
Open post
WP2Shell: Hands-On Lab Reproducing the Pre-Auth WordPress Core RCE https://learn.uphack.io/lab/wp2shell-wordpress-rce
0
0
0
0
Open post
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability https://lavahq.io/research/bmc-exposure-alert
0
0
0
0
Open post
Detection and Enforcement for Endpoint AI Agents https://research.perplexity.ai/articles/securing-agents-across-perplexity%E2%80%99s-client-endpoints-with-numbat
0
0
0
0
Open post
Pollard's P-1 Factoring Algorithm in Plain C https://leetarxiv.substack.com/p/pollards-p-1-factoring-algorithm
0
0
0
0
Open post
Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack https://ethiack.com/info-hub/research/kindarails2shell-how-a-matlab-file-reads-your-secrets-and-pops-a-shell-on-ruby-on-rails
0
0
0
0
Open post
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/
0
0
0
0
Open post
Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack https://ethiack.com/info-hub/research/kindarails2shell-how-a-matlab-file-reads-your-secrets-and-pops-a-shell-on-ruby-on-rails
0
0
0
0
Open post
Finally, something useful from Google regarding search hijacking https://www.ghacks.net/2026/08/03/google-chrome-prepares-default-block-for-extensions-that-hijack-the-new-tab-page-or-search-engine/
0
0
0
0
Open post
Sixteen strangers and a shared obfuscator: mapping the wool scene https://neurowinter.com/security/2026/07/28/the-cast-and-crew/
0
0
0
0






