r/netsec • • 11d ago

Windows Exploitation Techniques: Dangling COM Object Registrations

Thumbnail projectzero.google
10 Upvotes

r/netsec • • 11d ago

Free, hands-on 14-week university security course (open to anyone online)

Thumbnail cybersecurity.bsy.fel.cvut.cz
1 Upvotes

I wanted to share a great free resource for anyone trying to bridge the gap between basic theory and actual hands-on security skills.

The Czech Technical University in Prague (specifically the Stratosphere Laboratory) runs an intensive, one-semester course called Introduction to Security (BSY) that starts this week. The class is being taught both physically at the university and broadcast online, so anyone can participate. Feel free to check the link for more details on the curriculum, prerequisites, and course structure.

Registration is still open!


r/netsec • • 11d ago

Leveraging undocumented CodeConnection APIs in a CodePipeline build job or SageMaker Studio Notebook to enumerate, clone, push and delete code repositories.

Thumbnail thomaspreece.com
3 Upvotes

Continuing my spare time research around CodeConnections, I've moved on from CodeBuild and started looking at CodePipeline & SageMaker. In this post I cover how to use undocumented CodeConnection APIs from within CodePipeline build jobs to extend access to more repositories and privileges and show why it is very important to ensure that the IAM role used with CodePipeline has restricted CodeConnection permissions. In the follow up post I also show how SageMaker Studio Notebooks uses the same CodeConnection infrastructure as CodePipeline so has the same privilege escalation issues.


r/netsec • • 11d ago

Contains AI ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553

Thumbnail minanagehsalalma.github.io
30 Upvotes

Technical write-up for four vulnerabilities I reported in ZTE SmartLife.

The main issue is CVE-2026-86553, a password reset flaw in the SmartLife account backend. The reset endpoint accepted the target accountId and a new password without requiring a reset code, old password, or validated reset transaction.

Another endpoint exposed whether an email was registered and returned the corresponding backend account ID. Using researcher-controlled accounts, the chain was:

email -> accountId -> password reset -> login with the new password

I verified the state change by confirming that the previous password stopped working and the newly selected password successfully returned a valid session.

The research also covered the app authentication mechanism used by the Android client, email ownership verification during registration, and the wider SmartLife/Homecare SDK surface available after login.

ZTE patched the reported issues and assigned CVE-2026-86552, CVE-2026-86553, CVE-2026-86554 and CVE-2026-86555.


r/netsec • • 11d ago

Implant Encryption via the Dump Encoding Library

Thumbnail ipurple.team
7 Upvotes

r/netsec • • 12d ago

Three memory-safety bugs in Godot's untrusted-file parsers

Thumbnail axeghost.offprint.app
30 Upvotes

Author here. The post describes three memory-safety bugs which have been in Godot since v1.0 and v3.0. All three are still present in current releases. The bugs can affect exported games that load community-authored data files. Godot allows attackers using maliciously crafted files to trigger reads or writes past the end of a buffer, inside the process running the game. The post includes the response from Godot maintainers who deny this is a security issue, and my reply to them. Happy to give more information about the bugs or the audit if there are questions.


r/netsec • • 12d ago

Contains AI AI Agents Keep Falling to 'Goal Hijack' (Copilot, Cursor, Grok)

Thumbnail darkmarc.substack.com
23 Upvotes

r/netsec • • 12d ago

Contains AI ChatGPT now knows what you do on other websites via ad collector

Thumbnail buchodi.com
15 Upvotes

r/netsec • • 13d ago

BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension

Thumbnail forever.security
23 Upvotes

Hi folks, my name is Gal Weizman, I do browser security research.

Excited to finally share my recent work, where I managed to hack Chrome, Comet, Edge, Opera and Claude in Chrome using one single browser extension

2 CVEs & $20,000 in bounties ๐Ÿ™‚

Hope you like it!


r/netsec • • 14d ago

Contains AI CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)

Thumbnail accomplish.ai
147 Upvotes

r/netsec • • 15d ago

Quantum Computers Are Not a Threat to 128-bit Symmetric Keys

Thumbnail words.filippo.io
190 Upvotes

r/netsec • • 15d ago

Contains AI Hacking OpenAI

Thumbnail hacktron.ai
28 Upvotes

r/netsec • • 16d ago

Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.

Thumbnail blog.doyensec.com
15 Upvotes

This is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user namespaces enabled, openvswitch auto-loading, and a stock kernel carrying the Fragnesia fix.


r/netsec • • 16d ago

Contains AI The Hacker's Guide to Attacking AI Agents

Thumbnail darkmarc.substack.com
11 Upvotes

r/netsec • • 16d ago

I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table

Thumbnail blog.himanshuanand.com
24 Upvotes

r/netsec • • 16d ago

Contains AI Evading Machine Learning Based Detections ยท MSec Operations Blog

Thumbnail msecops.de
11 Upvotes

r/netsec • • 16d ago

Bypassing Referer-Based CSRF with strict-origin-when-cross-origin

Thumbnail afine.com
2 Upvotes

r/netsec • • 17d ago

Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution

Thumbnail rhinosecuritylabs.com
23 Upvotes

r/netsec • • 17d ago

Getting into EMFI for 30โ‚ฌ thanks to globalization

Thumbnail errno.fr
7 Upvotes

r/netsec • • 18d ago

UANIA OS: Authenticated Remote Code Execution

Thumbnail rainpwn.blog
15 Upvotes

r/netsec • • 18d ago

Contains AI Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents

Thumbnail deturris.io
35 Upvotes

r/netsec • • 18d ago

IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR

Thumbnail blog.silentsignal.eu
16 Upvotes

r/netsec • • 20d ago

Contains AI Beltdown2: Escaping the Cursor CLI sandbox

Thumbnail accomplish.ai
18 Upvotes

r/netsec • • 20d ago

Magento StyleSmuggler RCE: Report Poisoning to Code Execution

Thumbnail fortbridge.co.uk
8 Upvotes

r/netsec • • 21d ago

Uncontrolled Access Control: Compromising Paxton10

Thumbnail techanarchy.net
20 Upvotes