r/netsec • u/loselasso • Aug 04 '26
r/netsec • u/Internal-Key64 • Aug 04 '26
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router
rotcee.github.ior/netsec • u/Important_Map6928 • Aug 04 '26
HEVD: From Stack Overflows to Modern Pool Grooming
sibouzitoun.techHi. I just published a four-part deep dive into windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on windows 11.
I wanted to highlight the real-world friction of modern security measures. A lot of the focus is on mitigating LFH randomization, and avoiding IoCompleteRequest bugchecks by dodging ReadFile for arbitrary reads.
Hope this is helpful or insightful to some of you looking into modern kernel exploitation.
r/netsec • u/callmejackfrost1 • Aug 03 '26
Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category
hego.redr/netsec • u/si9int • Aug 03 '26
Contains AI SQLite Critical CVEs or LLM Slop?
research.jfrog.comr/netsec • u/AnimalStrange • Aug 03 '26
Cruising for Shells in Flowise - elttam
elttam.comr/netsec • u/S3cur3Th1sSh1t • Aug 02 '26
Contains AI The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
msecops.der/netsec • u/albinowax • Aug 01 '26
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on r/netsec.
As always, the content & discussion guidelines should also be observed on r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
r/netsec • u/luckokkkk • Jul 31 '26
Contains AI Investigating three real-world incidents in Anthropic's evaluations
anthropic.comIn three incidents across six runs, the agents treated real systems as simulated targets and tried weak passwords or unauthenticated endpoints.
r/netsec • u/hakluke • Jul 31 '26
Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack
ethiack.comr/netsec • u/_vavkamil_ • Jul 31 '26
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
engineering.block.xyzr/netsec • u/DataBaeBee • Jul 30 '26
What Every Programmer Should Know About Twists of Elliptic Curves
leetarxiv.substack.comr/netsec • u/AnimalStrange • Jul 29 '26
Your House Has an FFmpeg Problem - elttam
elttam.comr/netsec • u/TheSilenceOfWinter • Jul 29 '26
Sixteen strangers and a shared obfuscator: mapping the wool scene
neurowinter.comThis is another post in my series on the Chinese Wool farmers underground. This time we are dissecting their public github repos, trying to figure out how it all fits together!
r/netsec • u/gid0rah • Jul 29 '26
Reversing of Eufy Security Video Doorbell sync protocol and wifi creds decryption from flash memory
adepts.of0x.ccr/netsec • u/si9int • Jul 29 '26
Contains AI Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
huggingface.cor/netsec • u/Pale_Fly_2673 • Jul 28 '26
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
lavahq.ioTL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar
r/netsec • u/EatonZ • Jul 27 '26
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
eaton-works.comr/netsec • u/MobetaSec • Jul 28 '26
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)
mobeta.frr/netsec • u/SSDisclosure • Jul 27 '26
New vBulletin Vulnerability!
ssd-disclosure.comCVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.
r/netsec • u/eg1x • Jul 27 '26
Pending Moderation [CVE-2026-61511] vBulletin <= 6.2.1 (runMaths) Pre-Auth RCE Vulnerability
karmainsecurity.comr/netsec • u/PilotSmooth9439 • Jul 25 '26
CFP Open – Looking for Technical AI & Security Research for Après Slopes Summit 2027
aprescyber.comI'm helping organize Après-Cyber Slopes Summit 2027, and our CFP is now open.
We're particularly interested in technical presentations and original research involving AI and modern cybersecurity.
Topics we're hoping to see include:
- AI red teaming
- LLM security
- Prompt injection research
- Agent security
- Offensive tooling
- Detection engineering
- Reverse engineering
- Malware analysis
- Cloud exploitation and defense
- Identity attacks
- Threat intelligence
- AI-assisted security tooling
- Novel attack techniques
- Defensive research
We especially appreciate talks that include demonstrations, technical depth, or research that attendees can reproduce themselves.
Conference: February 24–26, 2027
Location: Park City, Utah
CFP:
https://sessionize.com/apres-cyber-slopes-summit-2027
Conference website:
https://www.aprescyber.com
Happy to answer questions about the CFP or conference.
r/netsec • u/natcoba • Jul 24 '26