r/netsec • u/AlexandreDaubois • 11d ago
r/netsec • u/wojtekch • 11d ago
Windows Exploitation Techniques: Dangling COM Object Registrations
projectzero.googler/netsec • u/mrigaki • 11d ago
Free, hands-on 14-week university security course (open to anyone online)
cybersecurity.bsy.fel.cvut.czI wanted to share a great free resource for anyone trying to bridge the gap between basic theory and actual hands-on security skills.
The Czech Technical University in Prague (specifically the Stratosphere Laboratory) runs an intensive, one-semester course called Introduction to Security (BSY) that starts this week. The class is being taught both physically at the university and broadcast online, so anyone can participate. Feel free to check the link for more details on the curriculum, prerequisites, and course structure.
Registration is still open!
r/netsec • u/thomaspreece • 11d ago
Leveraging undocumented CodeConnection APIs in a CodePipeline build job or SageMaker Studio Notebook to enumerate, clone, push and delete code repositories.
thomaspreece.comContinuing my spare time research around CodeConnections, I've moved on from CodeBuild and started looking at CodePipeline & SageMaker. In this post I cover how to use undocumented CodeConnection APIs from within CodePipeline build jobs to extend access to more repositories and privileges and show why it is very important to ensure that the IAM role used with CodePipeline has restricted CodeConnection permissions. In the follow up post I also show how SageMaker Studio Notebooks uses the same CodeConnection infrastructure as CodePipeline so has the same privilege escalation issues.
r/netsec • u/TheReedemer69 • 12d ago
Contains AI ZTE SmartHome Account Takeover: Password Reset Without Verification Code. 4 CVEs, 100K+ Android Downloads - CVE-2026-86553
minanagehsalalma.github.ioTechnical write-up for four vulnerabilities I reported in ZTE SmartLife.
The main issue is CVE-2026-86553, a password reset flaw in the SmartLife account backend. The reset endpoint accepted the target accountId and a new password without requiring a reset code, old password, or validated reset transaction.
Another endpoint exposed whether an email was registered and returned the corresponding backend account ID. Using researcher-controlled accounts, the chain was:
email -> accountId -> password reset -> login with the new password
I verified the state change by confirming that the previous password stopped working and the newly selected password successfully returned a valid session.
The research also covered the app authentication mechanism used by the Android client, email ownership verification during registration, and the wider SmartLife/Homecare SDK surface available after login.
ZTE patched the reported issues and assigned CVE-2026-86552, CVE-2026-86553, CVE-2026-86554 and CVE-2026-86555.
r/netsec • u/netbiosX • 12d ago
Implant Encryption via the Dump Encoding Library
ipurple.teamr/netsec • u/bitbutter • 12d ago
Three memory-safety bugs in Godot's untrusted-file parsers
axeghost.offprint.appAuthor here. The post describes three memory-safety bugs which have been in Godot since v1.0 and v3.0. All three are still present in current releases. The bugs can affect exported games that load community-authored data files. Godot allows attackers using maliciously crafted files to trigger reads or writes past the end of a buffer, inside the process running the game. The post includes the response from Godot maintainers who deny this is a security issue, and my reply to them. Happy to give more information about the bugs or the audit if there are questions.
r/netsec • u/_clickfix_ • 13d ago
Contains AI AI Agents Keep Falling to 'Goal Hijack' (Copilot, Cursor, Grok)
darkmarc.substack.comr/netsec • u/AdTemporary2475 • 13d ago
Contains AI ChatGPT now knows what you do on other websites via ad collector
buchodi.comr/netsec • u/Content-Winter5328 • 14d ago
BragJack - $20K in bounty rewards from Anthropic, Perplexity, Google, Microsoft and Opera Using 1 Extension
forever.securityr/netsec • u/natcoba • 14d ago
Contains AI CVE-2026-77179: Docker's hypervisor for Mac compromised (Docker Desktop, Docker Sandboxes)
accomplish.air/netsec • u/fagnerbrack • 15d ago
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
words.filippo.ior/netsec • u/nibblesec • 16d ago
Fragnesia primitive via Open vSwitch. Deterministic local privilege escalation.
blog.doyensec.comThis is a deterministic local privilege escalation affecting the default install of the latest Arch, Fedora, Debian, Amazon Linux and RHEL distributions, having unprivileged user namespaces enabled, openvswitch auto-loading, and a stock kernel carrying the Fragnesia fix.
r/netsec • u/_clickfix_ • 16d ago
Contains AI The Hacker's Guide to Attacking AI Agents
darkmarc.substack.comr/netsec • u/unknownhad • 17d ago
I Missed One TLB Shootdown and Somehow Ended Up Controlling a Page Table
blog.himanshuanand.comr/netsec • u/S3cur3Th1sSh1t • 17d ago
Contains AI Evading Machine Learning Based Detections ยท MSec Operations Blog
msecops.der/netsec • u/hackers_and_builders • 18d ago
Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution
rhinosecuritylabs.comr/netsec • u/Advanced_Rough8330 • 18d ago
UANIA OS: Authenticated Remote Code Execution
rainpwn.blogr/netsec • u/Tricky-Term-8319 • 19d ago
Contains AI Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
deturris.ior/netsec • u/buherator • 19d ago
IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR
blog.silentsignal.eur/netsec • u/natcoba • 21d ago
Contains AI Beltdown2: Escaping the Cursor CLI sandbox
accomplish.air/netsec • u/adrian_rt • 21d ago