❌

Normal view

Received β€” 26 September 2026 ⏭ /r/netsec - Information Security News & Discussion
Received β€” 25 September 2026 ⏭ /r/netsec - Information Security News & Discussion

Argus Monitor Local Denial-of-Service Vulnerability (CVE-2026-79417)

(1) An exposed IOCTL lets unprivileged users disable the x86 MONITOR & MWAIT instructions used by Hyper-V and other kernel components--triggering a HYPERVISOR_ERROR bugcheck.

(2) Reaching the IOCTL requires exploiting a TOCTOU bug arguably caused by poor documentation of the SeLocateProcessImageName function.

(3) Reimplementation of the driver's security through obscurity IOCTL encryption scheme: SHA-256 KDF-derived XOR keystream & CRC16 Checksum.

See full write-up, and Github for PoC.

submitted by /u/p0xq
[link] [comments]
Received β€” 24 September 2026 ⏭ /r/netsec - Information Security News & Discussion

Leveraging undocumented CodeConnection APIs in a CodePipeline build job or SageMaker Studio Notebook to enumerate, clone, push and delete code repositories.

Continuing my spare time research around CodeConnections, I've moved on from CodeBuild and started looking at CodePipeline & SageMaker. In this post I cover how to use undocumented CodeConnection APIs from within CodePipeline build jobs to extend access to more repositories and privileges and show why it is very important to ensure that the IAM role used with CodePipeline has restricted CodeConnection permissions. In the follow up post I also show how SageMaker Studio Notebooks uses the same CodeConnection infrastructure as CodePipeline so has the same privilege escalation issues.

submitted by /u/thomaspreece
[link] [comments]

September 23 | 24h Recap: Ubuntu container escape, F5 OAuth RCE and Windows process injection

Three technical stories from today’s recap:

Ubuntu container escape: DepthFirst released an exploit for CVE-2026-80521 that reaches host root from a container on Ubuntu 26.04. The AF_UNIX flaw was fixed upstream, but affected distribution kernels still need the patch.

F5 BIG-IP APM RCE: CVE-2026-94127 is being exploited against vulnerable OAuth authorization-server configurations. Management-interface access is not required. Hotfixes are available.

Process Parameter Poisoning: Flashpoint tested Windows code injection through process initialization structures, avoiding common memory-writing APIs. The technique produced no alerts from the EDR controls tested in its lab.

More technical details and source links in today’s recap on CyberRecaps, and have an amazing day :)

submitted by /u/FishingTechnical453
[link] [comments]

I asked my AI agent to inspect a website. The website took over my machine (34-run measurement across 5 agent harnesses)

I set up a local lab to test what happens when a developer asks their coding agent to inspect an untrusted website and clone its sample repo.

Measured 34 runs across 5 harnesses (omp, opencode, Claude Code, Codex, Gemini):

  1. Browser rendering: untrusted JS stole active session tokens in 11 of 12 runs (even with HttpOnly cookies, same-origin API fetches walked away with account data).

  2. Pre-trust RCE: project-scoped .mcp.json spawned declared commands before the model read the prompt (Claude Code executed it even while logged out).

  3. Two harnesses (Codex, Gemini) blocked the launch via workspace trust; three spawned without prompting.

Full comparison table, 1-minute local reproduction, and mitigations in the link.

submitted by /u/DaimoNNN
[link] [comments]
Received β€” 23 September 2026 ⏭ /r/netsec - Information Security News & Discussion
❌