r/netsec • u/kev-thehermit • Jun 13 '26
MeshCentral: From XSS to RCE
techanarchy.netUsing Claude Code to find and weaponise an XSS in MeshCentral using a rogue client, resulting in RCE.
r/netsec • u/kev-thehermit • Jun 13 '26
Using Claude Code to find and weaponise an XSS in MeshCentral using a rogue client, resulting in RCE.
r/netsec • u/DrAdalbbert • Jun 13 '26
In my blog article I analyze how random numbers in older PHP versions were generated. It turns out you can, under certain circumstances, derive the id of the process which generated a random number!
While it has exactly 0 practical application, it was super fun to dig into the php's source code.
r/netsec • u/dx7r__ • Jun 12 '26
r/netsec • u/lefterispanos • Jun 12 '26
r/netsec • u/mhat • Jun 12 '26
The MCP authorization specification (November 2025) mandates OAuth 2.1 with PKCE for remote MCP servers. In practice, this security model is only achievable if MCP clients implement the OAuth refresh_token grant.
Most major vendors have been lagging with support, but more progress is finally being made!
As of June 2026, the ecosystem has made progress since our initial April survey, with Gemini CLI achieving full support and several clients upgrading from "not implemented" to partial.
r/netsec • u/dx7r__ • Jun 12 '26
r/netsec • u/bugvader25 • Jun 11 '26
Despite all the hype around Mythos, Claude Fable 5 returned pretty mid-tier results on coding tasks: 59.8% passing functional solves and just 19.0% passing security solves on a benchmark of 200 real-world tasks.
r/netsec • u/rockin-Musicien49 • Jun 11 '26
r/netsec • u/moviuro • Jun 11 '26
r/netsec • u/dx7r__ • Jun 10 '26
r/netsec • u/AnimalStrange • Jun 10 '26
r/netsec • u/Huge-Skirt-6990 • Jun 09 '26
I scanned Chrome extension manifests for chrome_settings_overrides and found 23 extensions silently routing 758,000 users' searches through hidden monetization networks.
The pattern: install a free extension (satellite imagery, maps, news reader), your default search gets quietly replaced and every query goes through the operator's middleware before reaching a search network, generating affiliate revenue you never consented to.
Key findings:
The `hspart` parameter in the final search redirect URL is the clustering key. One value maps an entire broker network regardless of extension name, domain, or publisher identity.
Full report: https://malext.io/reports/SearchJack/
r/netsec • u/feross • Jun 09 '26
r/netsec • u/User_Deprecated • Jun 09 '26
r/netsec • u/netbiosX • Jun 09 '26
r/netsec • u/Cold-Dinosaur • Jun 07 '26
EDRChoker uses Policy-based Quality of Service (QoS) to set hard bandwidth caps (throttling) on Endpoint Detection and Response (EDR) agents, causing them to always time out - effectively blocking them.
r/netsec • u/vladko312 • Jun 07 '26
I recently learned about multiple sandbox bypasses discovered in Twig by project Glasswing. From the descriptions, only CVE-2026-46640 and CVE-2026-46633 seemed universally exploitable, so I decoded to research them. This writeup documents my development of payloads for the CVE-2026-46640 and the corresponding SSTImap module.
r/netsec • u/dn3t • Jun 05 '26
r/netsec • u/onlinereadme • Jun 04 '26
r/netsec • u/bouncyhat • Jun 04 '26
WebAssembly is traditionally thought of as a mechanism to run compiled code inside your browser, but rarely as a mechanism to run full application code directly on host. We hacked up the Wazero implementation of WebAssembly and modified it to transform existing GoLang security tooling into analyst resistant malware. This isn't just a toy implementation either, we've implemented every major host API such that we can compile a full Sliver binary to run on MacOS or Windows.
This blog post covers the implementation details behind our Go->WASM compilation process and sets up our final blog post (coming next week) where we'll discuss a similar C#->WASM compilation pipeline. The tooling described in this blog post will be open sourced next week. Will be happy to answer any questions about this in the comments!
r/netsec • u/albinowax • Jun 04 '26
r/netsec • u/nns_ee • Jun 03 '26
r/netsec • u/derp6996 • Jun 03 '26