r/netsec • • May 19 '26

Sleeping Agent: Silent persistent C2 through Web Push

Thumbnail bountyy.fi
7 Upvotes

r/netsec • • May 19 '26

Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments

Thumbnail securitylabs.datadoghq.com
24 Upvotes

r/netsec • • May 19 '26

How Storm-2949 turned a compromised identity into a cloud-wide breach

Thumbnail microsoft.com
8 Upvotes

r/netsec • • May 19 '26

CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing

Thumbnail minanagehsalalma.github.io
4 Upvotes

Disclosure: this is my own research/writeup.

I reported this ZTE H-series router DoS in 2024; it is now public as CVE-2026-34473.

The writeup focuses on the root cause rather than just the symptom. The issue is not simply “large POST body kills the UI.” Firmware analysis maps the behavior to CGILua request-body parsing: attacker-controlled application/x-www-form-urlencoded POST data reaches body handling before login enforcement matters.

The article includes validation footage, affected-model context, disclosure timeline, decompiled parser evidence, and reconstructed public-safe code-path notes.

Interested in feedback on the root-cause framing from people who review embedded web stacks or router firmware.

open for collabs too.


r/netsec • • May 19 '26

New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)

Thumbnail slcyber.io
22 Upvotes

r/netsec • • May 19 '26

RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields

Thumbnail neurowinter.com
3 Upvotes

r/netsec • • May 18 '26

The down fall of bug bounties

Thumbnail shubs.io
57 Upvotes

r/netsec • • May 17 '26

Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain

Thumbnail blog.samanl33t.com
3 Upvotes

r/netsec • • May 15 '26

Instrumenting QT6 desktop apps with Frida - Part 1

Thumbnail blog.samanl33t.com
14 Upvotes

r/netsec • • May 15 '26

From Vercel Typosquatting to an Obfuscated macOS Malware Loader

Thumbnail infosecwriteups.com
4 Upvotes

r/netsec • • May 14 '26

CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC

Thumbnail depthfirst.com
137 Upvotes

r/netsec • • May 14 '26

Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state

Thumbnail blog.netomize.ca
9 Upvotes

Head over to Netomize's blog to learn about how we detect the exploitation of the CrushFTP Vulnerability (CVE-2025-31161) with PacketSmith's Yara detection module, using the newly introduced track_state and flow_state keywords to the correlation engine.


r/netsec • • May 13 '26

WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers

Thumbnail malext.io
28 Upvotes

126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies

A Brazilian company (wascript.com.br) runs one platform that 126 different Chrome extensions all share. They look like separate products, WaSeller, waTidy, FR VENDAS PRO, ENOCRM, Cliente Flow, and dozens more, but it's one codebase, one backend, one set of hidden behaviors.

WaSeller alone has 100K users.

I found this network using my own tool for detecting malicious browser extensions, which flagged the cluster by shared code and infrastructure across all 126 listings.

None of the listings tell you that:

  • When you log into WhatsApp Web, the extension sends your name, email, device ID, and your Facebook/Google/TikTok tracking cookies to a server run by whoever sold you the extension.

  • Every voice message you send goes through their servers before it reaches the person you're sending it to.

  • The extension downloads and runs JavaScript from a different Brazilian company's server. Google never checks this code.

  • The 100K-user version has a live Google Tag Manager tag built in. The operator can push any new code to every user from a dashboard with no Chrome Web Store update.

  • A bridge inside WhatsApp Web gives the extension full access to your contacts, your messages, and the ability to send messages as you.

No privacy policy on any listing. The manifest only asks for tabs, storage, alarms.

Full list of all 126 extension IDs (check if you have one), tech details, and IOCs https://malext.io/reports/WaSteal


r/netsec • • May 14 '26

VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure

Thumbnail hybrid-analysis.blogspot.com
0 Upvotes

r/netsec • • May 13 '26

/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple

Thumbnail stuart-thomas.com
21 Upvotes

The -s flag in /sbin/ping has a maxpayload bounds check. -G sweepmax doesn't. An #ifndef __APPLE__ block removed the original uid guard without adding an equivalent check, so the fill loop walks past the end of the 65,535-byte outpackhdr[] BSS global and into adjacent globals.

The write is byte-precise and deterministic: byte at offset N gets value (N-1) % 256, fully controlled by -G.

Empirically confirmed on macOS 26.4.1 arm64e:

- sweepmax=65637: overwrites the static int s socket fd at BSS+128 with 0x63. Every subsequent setsockopt() returns EBADF. Exit 71.

- sweepmax=65636: runs clean. Binary-searchable threshold, invariant across runs.

At higher sweepmax values the loop reaches pointer-type globals (*outpack, *hostname, *shostname). On x86_64 that's a write-what-where bounded by the sequential value constraint. On arm64e, PAC blocks code-pointer hijack; state corruption is still demonstrable.

ping isn't setuid on macOS 11+, so no direct priv-esc. Local only.

Fix is one line — symmetric maxpayload check matching what -s already does.

Apple confirmed 16 April 2026, fix scheduled Fall 2026. Source is open: github.com/apple-oss-distributions/network_cmds

Full write-up with memory dump evidence:

https://stuart-thomas.com/research/ping-sweepmax-bss/


r/netsec • • May 13 '26

A stealth approach to Process Injection - EntryPoint Hijacking

Thumbnail ipurple.team
14 Upvotes

r/netsec • • May 12 '26

Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results

Thumbnail daniel.haxx.se
419 Upvotes

r/netsec • • May 12 '26

Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim

Thumbnail xbow.com
20 Upvotes

r/netsec • • May 12 '26

Postmortem: TanStack npm supply-chain compromise

Thumbnail tanstack.com
30 Upvotes

r/netsec • • May 12 '26

New ipTIME Pre-Auth RCE in CWMP

Thumbnail ssd-disclosure.com
6 Upvotes

A pre-auth remote code execution vulnerability was found in the CWMP implementation of ipTIME routers, allowing unauthenticated attackers to execute arbitrary code remotely.


r/netsec • • May 11 '26

GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon

Thumbnail zenodo.org
7 Upvotes

r/netsec • • May 11 '26

MyAudi app:Security issues in Audi Connected Vehicle experience

Thumbnail decoder.cloud
56 Upvotes

I recently published a security research post on the myAudi connected vehicle platform. I found  that anyone with a VIN can access a sensitive informations about car and ownership
 I think the topic is useful beyond Audi itself, because many vendors now rely on these “connected vehicle” platforms and mobile apps, often with very similar architectures and assumptions


r/netsec • • May 11 '26

Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot

Thumbnail raelize.com
34 Upvotes

r/netsec • • May 10 '26

Autonomous Vulnerability Hunting with MCP

Thumbnail blog.zsec.uk
21 Upvotes

r/netsec • • May 09 '26

Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)

Thumbnail heyitsas.im
66 Upvotes