Normal view
-
/r/netsec - Information Security News & Discussion
- Billion-Dollar Bait & Switch: Exploiting a Race Condition in Blockchain Infrastructure
Cloudflare Zero-day: Accessing Any Host Globally
-
/r/netsec - Information Security News & Discussion
- Frida 17.6.0 released β major Android stability improvements, Android 16 support
Frida 17.6.0 released β major Android stability improvements, Android 16 support
-
/r/netsec - Information Security News & Discussion
- After the Takedown: Excavating Abuse Infrastructure with DNS Sinkholes
After the Takedown: Excavating Abuse Infrastructure with DNS Sinkholes
-
/r/netsec - Information Security News & Discussion
- Successful Errors: New Code Injection and SSTI Techniques
Successful Errors: New Code Injection and SSTI Techniques
Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads are limited to a couple of specific examples. This research focuses on two such techniques for Code Injection and SSTI.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Account Takeover in Facebook mobile app due to usage of cryptographically unsecure random number generator and XSS in Facebook JS SDK
-
/r/netsec - Information Security News & Discussion
- StackWarp: Exploiting Stack Layout Vulnerabilities in Modern Processors
StackWarp: Exploiting Stack Layout Vulnerabilities in Modern Processors
-
/r/netsec - Information Security News & Discussion
- Multiple cross-site leaks disclosing Facebook users in third-party websites
Multiple cross-site leaks disclosing Facebook users in third-party websites
-
/r/netsec - Information Security News & Discussion
- Instagram account takeover via Meta Pixel script abuse
Instagram account takeover via Meta Pixel script abuse
-
/r/netsec - Information Security News & Discussion
- Leaking Meta FXAuth Token leading to 2 click Account Takeover
Leaking Meta FXAuth Token leading to 2 click Account Takeover
WinBoat: Drive by Client RCE + Sandbox escape.
Winboat lets you "Run Windows apps on π§ Linux with β¨ seamless integration"
I chained together an unauthenticated file upload to an "update" route and a command injection in the host election app to active full "drive by" host takeover in winboat.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Closing the Door on Net-NTLMv1: Releasing Rainbow Tables to Accelerate Protocol Deprecation
-
/r/netsec - Information Security News & Discussion
- Demonstration: prompt-injection failures in a simulated help-desk LLM
Demonstration: prompt-injection failures in a simulated help-desk LLM
I built this as a small demonstration to explore prompt-injection and instruction-override failure modes in help-desk-style LLM deployments.
The setup mirrors common production patterns (role instructions, refusal logic, bounded data access) and is intended to show how those controls can be bypassed through context manipulation and instruction override.
Iβm interested in feedback on realism, missing attack paths, and whether these failure modes align with what others are seeing in deployed systems.
This isnβt intended as marketing - just a concrete artefact to support discussion.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center
CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center
Found a new Azure vulnerability -
CVE-2026-2096, a high-severity flaw in the Azure SSO implementation of Windows Admin Center that allows a local administrator on a single machine to break out of the VM and achieve tenant-wide remote code execution.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
-
/r/netsec - Information Security News & Discussion
- Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC
-
/r/netsec - Information Security News & Discussion
- I'm The Captain Now: Hijacking a global ocean supply chain network
I'm The Captain Now: Hijacking a global ocean supply chain network
-
/r/netsec - Information Security News & Discussion
- Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover
Multiple XSS in Meta Conversion API Gateway Leading to Zero-Click Account Takeover
-
/r/netsec - Information Security News & Discussion
- Fortinet Forticlient EMS RCE CVE-2025-59922 and one IMG tag to rule them all