❌

Reading view

Code Security Review tool

Posted by E. Kellinis on Sep 22

Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro
is a macOS source-code security scanner (AST base and Heuristics) that statically analyses projects in multiple
languages. It's backed by an ML classifier trained on real patches to catch subtle issues. Beyond scanning, it offers
interactive call graphs and data-flow diagrams, a bug tracker, a private research wiki,...
  •  

CFP No cON Name 2k26 - Palma, Mallorca - Spain

Posted by Jose Nicolas Castellano on Sep 22

No cON Name 2026 - Palma, Mallorca - Balearic Islands

************************************
*****  Call For Papers        ******
************************************

https://www.noconname.org/call-for-papers/

Exact place not disclosed until a few weeks before due celebration.

    * INTRODUCTIONfulldisclosure () seclists org
The organization has  opened CFP proposals. No cON Name is the eldest
Hacking
and Security Conference in Span....
  •  

CVE-2026-17613: Penpot cross-team file takeover via import-binfile (unpatched in 2.17.2)

Posted by Louis Sanchez via Fulldisclosure on Sep 22

Posting this as an update rather than a first disclosure. The advisory
went public on 2026-08-04 with no vendor fix. Penpot has shipped two
releases since then, 2.17.1 and 2.17.2 -- the latter 14 days ago, on
2026-08-27 -- and I re-checked the code this morning: the missing
permission check is still missing in both, and in every release before
them. It was fixed on develop the day after this advisory went public.
That fix has never shipped....
  •  

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27

Posted by Apple Product Security via Fulldisclosure on Sep 22

APPLE-SA-09-14-2026-1 iOS 27 and iPadOS 27

iOS 27 and iPadOS 27 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/149034.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accelerate Framework
Available for: iPhone 11 and later, iPad Pro 12.9-inch 4th generation
and later, iPad Pro 11-inch...
  •  

[0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Opengear NGCS 25.11.8.

Type: Authenticated PDU name command injection to root via io.popen (CWE-78)
CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Impact: root command execution on the out-of-band console manager
Authentication: authenticated administrator

Full technical analysis and a reproducible proof-of-concept:...
  •  

[0day-rubbish] LCDS Laquis SCADA Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
LCDS Laquis SCADA.

Type: Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (CWE-434)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary native code execution inside the SCADA web and HMI process, which also hosts the Modbus TCP listener
Authentication: unauthenticated (no password configured is the default)

Full technical analysis and a...
  •  

[0day-rubbish] Ecava IntegraXor IGX 16.0.701.10 Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Ecava IntegraXor IGX 16.0.701.10.

Type: Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary command execution as Administrator on a Web SCADA HMI host
Authentication: unauthenticated

Full technical analysis and a reproducible proof-of-concept:...
  •  

[0day-rubbish] Devolutions Server (DVLS) 2026.2.14.0 PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (9.1)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
Devolutions Server (DVLS) 2026.2.14.0.

Type: PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (CWE-862)
CVSS: 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Impact: arbitrary PowerShell execution as NT AUTHORITY\SYSTEM on the Devolutions Server host
Authentication: authenticated administrator (no PAM licence, no PAM role)

Full technical analysis and a...
  •  

[0day-rubbish] CaptureBites MetaServer Anonymous WCF SOAP workflow leading to RunPrograms code execution (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
CaptureBites MetaServer.

Type: Anonymous WCF SOAP workflow leading to RunPrograms code execution (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary command execution as NT AUTHORITY\SYSTEM on the MetaServer host
Authentication: unauthenticated

Full technical analysis and a reproducible proof-of-concept:...
  •  

[0day-rubbish] PrizmDoc for Java (VirtualViewer) 5.22.1 Unauthenticated uploadDocument write into the webapp root to JSP webshell (9.8)

Posted by disclosure via Fulldisclosure on Sep 22

0day Rubbish Research Team is publicly disclosing a vulnerability in
PrizmDoc for Java (VirtualViewer) 5.22.1.

Type: Unauthenticated uploadDocument write into the webapp root to JSP webshell (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: JSP webshell execution with the JVM privileges, uid 0 (root) in the verified deployment
Authentication: unauthenticated

Full technical analysis and a reproducible proof-of-concept:...
  •  

Teams meeting audio and roster data remain accessible via ACS Call Automation connectCall after a participant is removed from the meeting

Posted by Jacob Greenway on Sep 22

Hi Full Disclosure team,

I'm not a traditional security researcher by background - I found this
while working with the ACS and Teams SDKs and followed it through to a full
writeup and PoC. I've done my best to be accurate and responsible
throughout (reporting to MSRC first, giving advance notice of this
disclosure date, and only testing against meetings/tenants I own), but if
anything here is imprecise or doesn't match community...
  •  

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point

  •  

UAF in XMEye Security Camera

Posted by evan on Sep 22

checksec:

$ checksec --file Sofia
[*] '/redacted/Sofia'
Arch: arm-32-little
RELRO: No RELRO
Stack: Canary found
NX: NX unknown - GNU_STACK missing
PIE: No PIE (0x8000)
Stack: Executable
RWX: Has RWX segments

this ones interesting. sofia uses an internal flash fs called WFS. per
an online search:

WFS is a proprietary filesystem developed by Hikvision for its...
  •  

SCHUTZWERK-SA-2024-007: Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education

Posted by David Brown via Fulldisclosure on Sep 22

A stored cross-site scripting (XSS) vulnerability has been identified in
the H5P module
h5p-nodejs-library by Lumi Education UG in versions up to and including
10.0.4. The
library allows users to upload H5P content that contains malicious
JavaScript. This code
is then executed in the browsers of other users who view the affected
H5P content.

Metadata
========

- Affected product: h5p-nodejs-library
- Affected version: All versions up to and...
  •  

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners

  •  

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."

  •  

ShinyHunters claims FBI hack: 'This is NOT financially motivated'

ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT financially motivated,” a Shiny spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.” The FBI did not immediately respond to The Register’s request for comment. According to a ShinyHunters spokesperson, the extortion group exploited an Oracle PeopleSoft zero-day vulnerability on the FBI jobs webpage, which it says allowed remote code execution (RCE) on the servers. The group then defaced the website, replacing it with a “This site has been seized by ShinyHunters” banner and image shared with The Register. At press time, the site says it is “currently down for maintenance but will be back up soon!” ShinyHunters also claims it moved laterally from the compromised site onto the FBI’s managed servers on AWS GovCloud, and downloaded about 2 TB to 3 TB of data belonging to current, former, and prospective FBI employees. “We hold data on all FBI employees and applicants,” the spokesperson told us. ShinyHunters claims the compromised FBI services include human resources, MedLink, and Criminal Justice Information Services. Neither Oracle nor AWS immediately responded to our inquiries, including whether Oracle is aware of a PeopleSoft preauth RCE zero-day, and whether AWS has any insight into the alleged data theft. We will update this story if we receive any response. Unlike most of the group’s smash-and-grab operations that involve a multimillion-dollar ransom demand to not leak the stolen files, ShinyHunters said it isn't seeking an extortion payment from the FBI. Instead, it wants the federal cops to retract statements made about ShinyHunters in a May 15 bulletin, shortly after the gang broke into ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff. The FBI said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” The security alert also said that extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.” Shiny claims none of this is true. “I have been doing my very best to combat these allegations,” they told us. “And this is the best way to do it.” ®

  •  

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver

  •  

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

  •  
❌