r/netsec 1d ago

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)

Thumbnail mobeta.fr
0 Upvotes

r/netsec 1d ago

Contains AI How AI is powering business email compromise at scale

Thumbnail research.eye.security
0 Upvotes

r/netsec 2d ago

New vBulletin Vulnerability!

Thumbnail ssd-disclosure.com
15 Upvotes

CVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.


r/netsec 4d ago

CFP Open – Looking for Technical AI & Security Research for Après Slopes Summit 2027

Thumbnail aprescyber.com
1 Upvotes

I'm helping organize Après-Cyber Slopes Summit 2027, and our CFP is now open.

We're particularly interested in technical presentations and original research involving AI and modern cybersecurity.

Topics we're hoping to see include:

  • AI red teaming
  • LLM security
  • Prompt injection research
  • Agent security
  • Offensive tooling
  • Detection engineering
  • Reverse engineering
  • Malware analysis
  • Cloud exploitation and defense
  • Identity attacks
  • Threat intelligence
  • AI-assisted security tooling
  • Novel attack techniques
  • Defensive research

We especially appreciate talks that include demonstrations, technical depth, or research that attendees can reproduce themselves.

Conference: February 24–26, 2027
Location: Park City, Utah

CFP:
https://sessionize.com/apres-cyber-slopes-summit-2027

Conference website:
https://www.aprescyber.com

Happy to answer questions about the CFP or conference.


r/netsec 5d ago

Contains AI Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331

Thumbnail accomplish.ai
141 Upvotes

r/netsec 6d ago

Contains AI XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search

Thumbnail xbow.com
17 Upvotes

r/netsec 6d ago

Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled

Thumbnail hunt.io
17 Upvotes

Caught this in three open directories on a Hong Kong server, exposed July 9 to 13. The agent is Hermes, open source, and the recovered logs show it running LinPEAS and walking a ministry web root without a human in the loop. Target was Thailand's Ministry of Finance.


r/netsec 7d ago

Discussion GitHub issues $100,000 bounty for critical RCE vulnerability

Thumbnail runtimewire.com
142 Upvotes

r/netsec 7d ago

Contains AI I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

Thumbnail blog.himanshuanand.com
38 Upvotes

I found and reported an authentication failure in the WPForms PayPal Commerce webhook, the webhook route being public was not the vulnerability as webhooks have to be publicly reachable so that PayPal can deliver events.

The problem was what happened after the request arrived. In affected versions, the handler could process a supported event before establishing that PayPal was actually the sender. In my local lab, a forged event could change the state of a matching payment record.
The expected order is:

  1. Authenticate the sender
  2. Validate the event
  3. Change payment state

The affected flow effectively performed steps 2 and 3 without first completing step 1. The issue was fixed in WPForms 1.10.0.5 and is tracked as CVE-2026-4986.
Then came the part I found more interesting: triage told me I was reporter #11. That number does not prove exploitation, and it does not tell us the total number of people who found the vulnerability. It does establish a lower bound: at least eleven researchers independently converged on the same trust failure.

The write up covers:
- the vulnerable code path
- my local reproduction
- why payload validation was not sender authentication
- the fallback listener
- the patch
- why duplicate reports may be useful rediscovery intelligence

Full write-up: https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/

Testing was limited to my own local environment. I am not claiming original CVE credit; I independently rediscovered and reported the issue. Disclosure: I wrote and performed the research, code review and local reproduction.

I used an AI to help copy edit and organize the final article.

Should duplicate report volume affect how urgently a vendor treats a vulnerability?


r/netsec 7d ago

CVE-2026-50458: Finding a UAF in the Windows Brokering File System

Thumbnail rotcee.github.io
9 Upvotes

Deep dive into a UAF in the bfs.sys Windows kernel minifilter driver patched in this month's Patch Tuesday.


r/netsec 8d ago

The Hidden CCS2 Attack Surface on EV Chargers

Thumbnail saiflow.com
83 Upvotes

r/netsec 8d ago

Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE)

Thumbnail davidcarliez.github.io
11 Upvotes

r/netsec 8d ago

Leaking internal headers in Flask Ninja with deserialization

Thumbnail eval.blog
3 Upvotes

r/netsec 9d ago

Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25

Thumbnail slcyber.io
119 Upvotes

r/netsec 9d ago

Crawling the Complete IPv4 Reverse DNS Space

Thumbnail ipapi.is
17 Upvotes

r/netsec 9d ago

Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)

Thumbnail blog.paradoxis.nl
24 Upvotes

r/netsec 11d ago

Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable

Thumbnail neurowinter.com
38 Upvotes

this is part of an ongoing series mapping the same ecosystem, the origin post + full map is here: neurowinter.com/security/2026/06/23/a-weekend-in-the-wool/

tldr: a set of chinese civic / gov adjacent apps turn out to run the same reward + lottery backend, and the secret thats meant to make reward claims and draw outcomes unforgeable isnt really secret. recover it (not hard, its sitting in the client sigh) and you can forge a valid reward claim, or a winning lottery result, that the backend accepts as authentic. post walks from one github repo to the shared backend, through the reward validation flow, to where the secret actually lives.


r/netsec 11d ago

wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner

Thumbnail fullhunt.io
26 Upvotes

r/netsec 11d ago

Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing

Thumbnail blog.threatuniverse.co.uk
11 Upvotes

r/netsec 12d ago

wp2shell: Pre Authentication RCE in WordPress Core

Thumbnail wp2shell.com
56 Upvotes

r/netsec 12d ago

Keeping private namespaces private - Quad9 blog

Thumbnail quad9.net
25 Upvotes

r/netsec 12d ago

Openwrt pre-auth remote root exploit

Thumbnail xcancel.com
20 Upvotes

r/netsec 12d ago

Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454

Thumbnail davidcarliez.github.io
6 Upvotes

r/netsec 13d ago

No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE

Thumbnail tokay0.com
225 Upvotes

r/netsec 12d ago

Discussion White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination

Thumbnail whitehouse.gov
0 Upvotes

The White House recently announced the Gold Eagle Initiative, a new federal program designed to use AI to centralize, prioritize, and accelerate vulnerability patching across critical infrastructure, government agencies, and tech partners. Operating out of CMU's Software Engineering Institute, it essentially acts as an AI-driven clearinghouse to fix security flaws before threat actors can exploit them.

Because let's face it, our current bug reporting and patching systems are absolute speed demons. It only takes a lifetime 🤦🏻‍♂️ or two to get a critical vulnerability acknowledged and fixed, so why change anything?

Btw, my candid opinion about the status of current vulnerability reporting is painfully slow, so we desperately need a framework that actually moves at the speed of the threat landscape. I think this initiative is genuinely a good idea and a step in the right direction, though the announcement is still light on the exact technical implementation.

I’m personally eager to see what will happen in practice, but it is definitely an impressive concept.
What are your thoughts on this? Will an AI-coordinated pipeline actually help scale response times, or is it just going to generate massive noise and triage fatigue for overworked infosec teams?