❌

Reading view

Leveraging undocumented CodeConnection APIs in a CodePipeline build job or SageMaker Studio Notebook to enumerate, clone, push and delete code repositories.

Continuing my spare time research around CodeConnections, I've moved on from CodeBuild and started looking at CodePipeline & SageMaker. In this post I cover how to use undocumented CodeConnection APIs from within CodePipeline build jobs to extend access to more repositories and privileges and show why it is very important to ensure that the IAM role used with CodePipeline has restricted CodeConnection permissions. In the follow up post I also show how SageMaker Studio Notebooks uses the same CodeConnection infrastructure as CodePipeline so has the same privilege escalation issues.

submitted by /u/thomaspreece
[link] [comments]
  •  

September 23 | 24h Recap: Ubuntu container escape, F5 OAuth RCE and Windows process injection

Three technical stories from today’s recap:

Ubuntu container escape: DepthFirst released an exploit for CVE-2026-80521 that reaches host root from a container on Ubuntu 26.04. The AF_UNIX flaw was fixed upstream, but affected distribution kernels still need the patch.

F5 BIG-IP APM RCE: CVE-2026-94127 is being exploited against vulnerable OAuth authorization-server configurations. Management-interface access is not required. Hotfixes are available.

Process Parameter Poisoning: Flashpoint tested Windows code injection through process initialization structures, avoiding common memory-writing APIs. The technique produced no alerts from the EDR controls tested in its lab.

More technical details and source links in today’s recap on CyberRecaps, and have an amazing day :)

submitted by /u/FishingTechnical453
[link] [comments]
  •  

I asked my AI agent to inspect a website. The website took over my machine (34-run measurement across 5 agent harnesses)

I set up a local lab to test what happens when a developer asks their coding agent to inspect an untrusted website and clone its sample repo.

Measured 34 runs across 5 harnesses (omp, opencode, Claude Code, Codex, Gemini):

  1. Browser rendering: untrusted JS stole active session tokens in 11 of 12 runs (even with HttpOnly cookies, same-origin API fetches walked away with account data).

  2. Pre-trust RCE: project-scoped .mcp.json spawned declared commands before the model read the prompt (Claude Code executed it even while logged out).

  3. Two harnesses (Codex, Gemini) blocked the launch via workspace trust; three spawned without prompting.

Full comparison table, 1-minute local reproduction, and mitigations in the link.

submitted by /u/DaimoNNN
[link] [comments]
  •  

Free, hands-on 14-week university security course (open to anyone online)

I wanted to share a great free resource for anyone trying to bridge the gap between basic theory and actual hands-on security skills.

The Czech Technical University in Prague (specifically the Stratosphere Laboratory) runs an intensive, one-semester course called Introduction to Security (BSY) that starts this week. The class is being taught both physically at the university and broadcast online, so anyone can participate. Feel free to check the link for more details on the curriculum, prerequisites, and course structure.

Registration is still open!

submitted by /u/mrigaki
[link] [comments]
  •  

The finding said RCE. The second tester asked one question and the ticket died.

Last year I inherited a β€œcritical RCE” from an automated pass.

The request looked perfect. Parameter host. Payload 8.8.8.8; sleep 5. Status 200. Response time jumped from ~800ms to ~6s. The scanner wrote OS command injection, confidence high. The client had already seen the word critical in the draft.

I replayed it once. Same delay. Replay again. 1.1s. Again. 7s. Again. 900ms. The sleep was not in the response body. id came back as the literal string id. expr 41 + 1 came back as the literal string. The page was a diagnostics form. It echoed the query and, under load, the WAF in front of it spent extra time on anything that looked like a shell metacharacter.

That is a known failure mode, not a rare one. Time-based command-injection checks fire when the response is merely slower, which also happens when the scan itself saturates the app, when a WAF inspects a β€œmore suspicious” request, when a CDN queues you, or when the page is just doing a heavier search. SANS has been writing this up for years: ping -c 20 127.0.0.1 during a busy scan is not proof. ZAP’s sleep payloads have the same problem, and in some rules even reflecting the command string is enough to raise the issue. A 200 that contains bash -c is often a docs page, not a shell. οΏΌ

The useful question is not β€œdid a payload land.” It is β€œwhat value in this response can only exist if the server evaluated my input?”
What I do now, on the same request, before I write the word confirmed:

  1. Send a benign twin. Same cookies, same content-type, same parameter, no metacharacters. That is the control. If the β€œinteresting” string is already there, stop. That is echo, not execution.

  2. Do not ask the server to say whoami. Ask it to compute something it has never seen. Two random integers, added, wrapped in canaries that are also random for that probe. If the body contains the sum and the control does not, you have a result that reflection cannot invent.

  3. If there is no output channel, do not promote a single slow request. Change the delay. Plot it. If 3 / 7 / 11 seconds do not track the payload, it is jitter or a WAF. PortSwigger has a nice version of this trap: an exec-looking parameter delayed because the WAF worked harder, not because a binary ran. οΏΌ

  4. A DNS callback is a sink, not a shell. Collaborator lighting up after you plant a URL is often a link previewer, a safe-browsing fetch, or a JNDI lookup that never loaded a class. Fastjson / Log4j writeups on here keep dying at that step: four DNS hits, zero command. Say lookup. Do not say RCE until a value only the target could have computed comes back, or you have a class-load you can show.

  5. If your flags never built a probe for that sink, the result is not negative. It is untested. I have watched people paste β€œnot vulnerable” into a report because the scanner used shell separators against an OGNL parameter. Struts will happily evaluate %{7*7} and still return nothing useful to ; id. Wrong claim, clean-looking ticket.

The ticket I inherited was closed as a false positive in fifteen minutes once the control existed. The next one, on a lab Webmin box, survived because the response contained a sum the request never sent. Same scanner family. Different question.

If you only remember one thing from this: before you file P1, ask whether a second person can reproduce a value, not a delay. Triage queues are full of the second kind. That is why β€œnot reproducible” shows up on reports that felt obvious at 1 a.m.

I later wrapped the control + random-arithmetic check into a small stdlib-only helper so I would stop doing it by hand on jump boxes. That is not the point of the post. The point is the question. If you want the benches against Webmin / Struts2 / a Log4j lookup so you can disagree with the verdict names, I will drop the repo in a comment.

submitted by /u/No-View3333
[link] [comments]
  •  
❌