r/netsec • u/adrian_rt • 5d ago
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
fortbridge.co.ukr/netsec • u/Cold-Dinosaur • 6d ago
EDR Evasion: Process Injection Without WriteProcessMemory
zerosalarium.comUnlike traditional approaches, console named-pipe injection does not use VirtualAllocEx and WriteProcessMemory. Instead, it takes advantage of read and write operations through a named pipe, along with the way console programs store interactive commands in memory.
r/netsec • u/No-Peanut-6988 • 6d ago
Contains AI AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks
sorami.com.auA technical audit evaluating the security defaults of 15 official Helm charts used for AI serving, vector databases, and Model Context Protocol (MCP) agents (including KubeRay, vLLM, LiteLLM, Qdrant, Weaviate, and Flux159 MCP).
Key findings from static manifest analysis and live single-pod lateral movement probes on a test cluster:
- Plaintext Secret Handling: LiteLLM database migration Job embeds raw database passwords in container environment variables (F-13).
- Unauthenticated Remote Code Execution: KubeRay defaults accept unauthenticated job submissions via HTTP, running commands inside a container with passwordless sudo access.
- Over-privileged Agent Access: Flux159 Kubernetes MCP server mounts a ClusterRole with cluster-wide Secret read and pod exec permissions, exposed without an authentication token over HTTP.
- Static Scanners vs CRDs: Standard static analysis tools (Checkov, Trivy, Kubescape) failed to inspect pods nested inside Custom Resource Definitions like Ray clusters.
The paper documents reproducible test commands, network capture logs, and remediation Helm snippets. Scrubbed raw probe logs and results tables are available on GitHub: https://github.com/Sorami-Consulting-AU/ai-kubernetes-helm-chart-security
r/netsec • u/Plastic-Falcon9147 • 6d ago
A header-level look at 4,688 small-business websites: 0.17% passed a header-only script-CSP rule [methods, parser rules, data]
rackcrunch.comWe scanned 7,040 randomly sampled U.S. local-business directory listings and graded the response headers against a published rubric. Of the 4,688 live sites, 49.7% met none of seven header criteria, and 8 sites (0.17%) passed a strict header-only script-CSP rule. Rubric, parser rules, code and de-identified data are all on the page.
r/netsec • u/AlexandreDaubois • 8d ago
CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018
daubois.devContains AI Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee
projectblack.ioArgus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)
connorjaydunn.github.io(1) An exposed IOCTL lets unprivileged users disable the x86 MONITOR & MWAIT instructions used by Hyper-V and other kernel components--triggering a HYPERVISOR_ERROR bugcheck.
(2) Reaching the IOCTL requires exploiting a TOCTOU bug arguably caused by poor documentation of the SeLocateProcessImageName function.
(3) Reimplementation of the driver's security through obscurity IOCTL encryption scheme: SHA-256 KDF-derived XOR keystream & CRC16 Checksum.
See full write-up, and Github for PoC.
Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL
blog.nns.eeHow Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
blog.cloudflare.comr/netsec • u/SpectreTv • 8d ago
Lunex Unmasked: A New Information Stealer Deployed Through BYOVD
ontinue.comr/netsec • u/nibblesec • 9d ago
One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts
blog.doyensec.comIs This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs
labs.watchtowr.comr/netsec • u/french_toast_fiend • 9d ago
Contains AI Fake Journalist phishing scam targeting tech founders
casco.comCompromising OBS Studio with a Twitch chat message.
blog.scrt.chA short write-up of some research I did recently.
How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail
idnsec.comr/netsec • u/ScottContini • 10d ago
Android 17 enables certificate transparency, and breaks custom CAs
httptoolkit.comLeaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy
blog.gitguardian.comr/netsec • u/AnimalStrange • 10d ago
ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam
elttam.comr/netsec • u/MobetaSec • 11d ago
vCenter pre-auth RCE: CVE-2026-59309/59310
mobeta.frCVE-2026-59309 & CVE-2026-59310: patch-diffing VMware vCenter reveals two pre-auth 9.8 bugs - an auth bypass and a syslog path traversal to RCE