Normal view
-
/r/netsec - Information Security News & Discussion
- Multiple Vulnerabilities in Frappe LMS Leading to Remote Code Execution
Escaping the OpenAI Codex sandbox, twice
-
/r/netsec - Information Security News & Discussion
- Getting into EMFI for 30β¬ thanks to globalization
Getting into EMFI for 30β¬ thanks to globalization
UANIA OS: Authenticated Remote Code Execution
-
/r/netsec - Information Security News & Discussion
- Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
Ask the Agent Nicely: Two Authorization Bypasses in n8n AI Agents
-
/r/netsec - Information Security News & Discussion
- IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR
IBM Db2 Mirror for i: pre-auth RCE and the road to QSECOFR
-
/r/netsec - Information Security News & Discussion
- Magento StyleSmuggler RCE: Report Poisoning to Code Execution
Magento StyleSmuggler RCE: Report Poisoning to Code Execution
Beltdown2: Escaping the Cursor CLI sandbox
-
/r/netsec - Information Security News & Discussion
- A revisit of remote Spectre attacks on Cloudflare Workers
A revisit of remote Spectre attacks on Cloudflare Workers
-
/r/netsec - Information Security News & Discussion
- Uncontrolled Access Control: Compromising Paxton10
Uncontrolled Access Control: Compromising Paxton10
-
/r/netsec - Information Security News & Discussion
- The ultimate guide to hacking APIs in 2026 has been updated
The ultimate guide to hacking APIs in 2026 has been updated
Back in 2021 I wrote a "how to hack APIs" blog for Detectify that got loads of traction, but it's way out of date now. I rewrote it for 2026 to include a bunch of the newer popular technologies and AI.
[link] [comments]
Beltdown: Escaping the Claude Code Sandbox
-
/r/netsec - Information Security News & Discussion
- No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite's dbpage
No Extensions? You Forgot One: Writing Shared Objects to RCE via SQLite's dbpage
A novel technique for writing ELF shared objects and achieving code execution in Python, Ruby, and Node.js using the sqlite_dbpage virtual table.
[link] [comments]
Forgejo <=16.0.3 Critical RCE
-
/r/netsec - Information Security News & Discussion
- Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability
Preinstalled but Not Safe. OnePlus OEM App Session Takeover Vulnerability
-
/r/netsec - Information Security News & Discussion
- Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine
Out of Bounds, Out of Sandbox: RCE in Go JavaScript Engine
-
/r/netsec - Information Security News & Discussion
- Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
Fortinet Privileged Access Agent: Any Site Could Control Your Proxy and Watch Your Tab
TL;DR. The FortiPAM Chrome extension (1M+ users), used for Privileged Access Management, allowed any site to set the browser's proxy for the session, alongside allowing any site to create a new tab and send screen recordings of it to an attacker's server. That makes for trivial phishing attacks which only require the user to view something sensitive in the attacker-opened tab. CVSS 9.1 | CVE-2026-84388.
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- Disable Windows Defender via Antivirus Fake Registration
Disable Windows Defender via Antivirus Fake Registration
-
/r/netsec - Information Security News & Discussion
- WeWorm - The first zero-click worm to spread through WeChat calls across iOS and Android.
WeWorm - The first zero-click worm to spread through WeChat calls across iOS and Android.
-
/r/netsec - Information Security News & Discussion
- π¨ Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
π¨ Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files
Researchers indexed an open directory on 188.245.99.156 (Hetzner) that held an operator's full Redis cryptomining toolkit, not just a payload. 147 files in total: Python exploit source, JSON campaign logs, a bundled portable Python 3.11 runtime, and two exported Windows registry hives.
Because the raw campaign logs were sitting there, the numbers come from the operator's own per-host records, not the summaries their scripts print:
- 3,562 distinct Redis servers compromised out of 12,966 targeted, across two independently coded runs
- The only technique that scaled is rogue replication: PING to confirm no-auth, CONFIG SET dir/dbfilename, SLAVEOF to a rogue master, then a crafted RDB blob with an embedded newline that drops a cron entry into /etc/cron.d/
- That cron job pulls a legit XMRig release straight from GitHub and points it at pool.moneroocean.stream:443 over TLS
- SSH key injection via AOF returned 0 of 2,342, MongoDB JS sandbox escape 0 of 468. Every SSH attempt bounced at the first CONFIG SET with AUTH_REQUIRED
- Confirmed victims span Redis 2.8.17 to 7.2.0, so this is missing authentication, not a version-specific bug
- A third run against a pre-qualified no-auth list hit 72.6%, roughly triple the full-fleet rate, so target-list freshness is the real limiter, not the technique
- The same Monero wallet turns up in a separate February 2026 open directory in Moldova with Meterpreter and XMRig deployers and no Redis component, which pushes known activity back at least five months
Fix is config, not patching: requirepass, disable SLAVEOF/REPLICAOF where replication is not in use, or enable protected-mode. Upgrading does nothing here.
Full write-up with IOCs: https://hunt.io/blog/redis-cryptomining-botnet-3562-servers
[link] [comments]