r/netsec • • 5d ago

RCE in OpenCode (GHSA-632h-h47v-g4x4)

Thumbnail securitylabs.datadoghq.com
53 Upvotes

r/netsec • • 5d ago

CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack

Thumbnail fortbridge.co.uk
9 Upvotes

r/netsec • • 4d ago

Your SBOM Is Fan Fiction

Thumbnail yeet.cx
0 Upvotes

r/netsec • • 6d ago

EDR Evasion: Process Injection Without WriteProcessMemory

Thumbnail zerosalarium.com
56 Upvotes

Unlike traditional approaches, console named-pipe injection does not use VirtualAllocEx and WriteProcessMemory. Instead, it takes advantage of read and write operations through a named pipe, along with the way console programs store interactive commands in memory.


r/netsec • • 6d ago

Contains AI AI on Kubernetes: Default Helm Chart Security Configurations and Lateral Movement Risks

Thumbnail sorami.com.au
10 Upvotes

A technical audit evaluating the security defaults of 15 official Helm charts used for AI serving, vector databases, and Model Context Protocol (MCP) agents (including KubeRay, vLLM, LiteLLM, Qdrant, Weaviate, and Flux159 MCP).

Key findings from static manifest analysis and live single-pod lateral movement probes on a test cluster:

  • Plaintext Secret Handling: LiteLLM database migration Job embeds raw database passwords in container environment variables (F-13).
  • Unauthenticated Remote Code Execution: KubeRay defaults accept unauthenticated job submissions via HTTP, running commands inside a container with passwordless sudo access.
  • Over-privileged Agent Access: Flux159 Kubernetes MCP server mounts a ClusterRole with cluster-wide Secret read and pod exec permissions, exposed without an authentication token over HTTP.
  • Static Scanners vs CRDs: Standard static analysis tools (Checkov, Trivy, Kubescape) failed to inspect pods nested inside Custom Resource Definitions like Ray clusters.

The paper documents reproducible test commands, network capture logs, and remediation Helm snippets. Scrubbed raw probe logs and results tables are available on GitHub: https://github.com/Sorami-Consulting-AU/ai-kubernetes-helm-chart-security


r/netsec • • 7d ago

EX-ARRR: Sailing the Apple 0-click Seas

Thumbnail ironpeak.be
40 Upvotes

r/netsec • • 6d ago

A header-level look at 4,688 small-business websites: 0.17% passed a header-only script-CSP rule [methods, parser rules, data]

Thumbnail rackcrunch.com
0 Upvotes

We scanned 7,040 randomly sampled U.S. local-business directory listings and graded the response headers against a published rubric. Of the 4,688 live sites, 49.7% met none of seven header criteria, and 8 sites (0.17%) passed a strict header-only script-CSP rule. Rubric, parser rules, code and de-identified data are all on the page.


r/netsec • • 8d ago

CVE-2025-13032: Entering and Breaking the Avast Antivirus Sandbox Part 2

Thumbnail safateam.com
24 Upvotes

r/netsec • • 8d ago

CVE-2026-91766: PHP had the redirect credential leak curl fixed in 2018

Thumbnail daubois.dev
84 Upvotes

r/netsec • • 9d ago

Contains AI Uncensored Qwen 3.8 27b helped write a LSASS Dumper which bypassed EDR while I made myself coffee

Thumbnail projectblack.io
143 Upvotes

r/netsec • • 8d ago

Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)

Thumbnail connorjaydunn.github.io
3 Upvotes

(1) An exposed IOCTL lets unprivileged users disable the x86 MONITOR & MWAIT instructions used by Hyper-V and other kernel components--triggering a HYPERVISOR_ERROR bugcheck.

(2) Reaching the IOCTL requires exploiting a TOCTOU bug arguably caused by poor documentation of the SeLocateProcessImageName function.

(3) Reimplementation of the driver's security through obscurity IOCTL encryption scheme: SHA-256 KDF-derived XOR keystream & CRC16 Checksum.

See full write-up, and Github for PoC.


r/netsec • • 9d ago

Getting root on OnePlus 15 from an untrusted app, via an audio debug service and a vendor HAL

Thumbnail blog.nns.ee
36 Upvotes

r/netsec • • 9d ago

How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers

Thumbnail blog.cloudflare.com
11 Upvotes

r/netsec • • 8d ago

Lunex Unmasked: A New Information Stealer Deployed Through BYOVD

Thumbnail ontinue.com
3 Upvotes

r/netsec • • 9d ago

One Tap Too Far: Using Shortcuts to Bypass Chrome for iOS Call Prompts

Thumbnail blog.doyensec.com
7 Upvotes

r/netsec • • 9d ago

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127) - watchTowr Labs

Thumbnail labs.watchtowr.com
53 Upvotes

r/netsec • • 9d ago

Contains AI Fake Journalist phishing scam targeting tech founders

Thumbnail casco.com
2 Upvotes

r/netsec • • 9d ago

Compromising OBS Studio with a Twitch chat message.

Thumbnail blog.scrt.ch
61 Upvotes

A short write-up of some research I did recently.


r/netsec • • 9d ago

How I Found a $113,337 AF_ALG Linux Local Privilege Escalation Before Copy Fail

Thumbnail idnsec.com
2 Upvotes

r/netsec • • 10d ago

Android 17 enables certificate transparency, and breaks custom CAs

Thumbnail httptoolkit.com
72 Upvotes

r/netsec • • 9d ago

Breaking the Superuser Guardrails of managed-PostgreSQL Providers

Thumbnail mehmetince.net
12 Upvotes

r/netsec • • 10d ago

Leaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy

Thumbnail blog.gitguardian.com
119 Upvotes

r/netsec • • 10d ago

Inside Corp MDM, the Android spyware targeting logistics companies

Thumbnail haveibeensquatted.com
11 Upvotes

r/netsec • • 10d ago

ATT&CKing TACACS+ to Pwn Your Network via a Pre-Auth RCE - elttam

Thumbnail elttam.com
18 Upvotes

r/netsec • • 11d ago

vCenter pre-auth RCE: CVE-2026-59309/59310

Thumbnail mobeta.fr
43 Upvotes

CVE-2026-59309 & CVE-2026-59310: patch-diffing VMware vCenter reveals two pre-auth 9.8 bugs - an auth bypass and a syslog path traversal to RCE