Karma Pro is an open source code review tool that can assist code reviewers with a multitude of useful tools. Karma Pro
is a macOS source-code security scanner (AST base and Heuristics) that statically analyses projects in multiple
languages. It's backed by an ML classifier trained on real patches to catch subtle issues. Beyond scanning, it offers
interactive call graphs and data-flow diagrams, a bug tracker, a private research wiki,...
Exact place not disclosed until a few weeks before due celebration.
* INTRODUCTIONfulldisclosure () seclists org
The organization has opened CFP proposals. No cON Name is the eldest
Hacking
and Security Conference in Span....
Posted by Louis Sanchez via Fulldisclosure on Sep 22
Posting this as an update rather than a first disclosure. The advisory
went public on 2026-08-04 with no vendor fix. Penpot has shipped two
releases since then, 2.17.1 and 2.17.2 -- the latter 14 days ago, on
2026-08-27 -- and I re-checked the code this morning: the missing
permission check is still missing in both, and in every release before
them. It was fixed on develop the day after this advisory went public.
That fix has never shipped....
0day Rubbish Research Team is publicly disclosing a vulnerability in
LCDS Laquis SCADA.
Type: Unauthenticated /uploade.html file write chained with CMDEXT*.DLL autoload (CWE-434)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary native code execution inside the SCADA web and HMI process, which also hosts the Modbus TCP listener
Authentication: unauthenticated (no password configured is the default)
0day Rubbish Research Team is publicly disclosing a vulnerability in
Ecava IntegraXor IGX 16.0.701.10.
Type: Unauthenticated /FileUpload write chained to the dxmanager cmd.exe sink (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary command execution as Administrator on a Web SCADA HMI host
Authentication: unauthenticated
Full technical analysis and a reproducible proof-of-concept:...
0day Rubbish Research Team is publicly disclosing a vulnerability in
Devolutions Server (DVLS) 2026.2.14.0.
Type: PAM entitlement-gate bypass to SYSTEM PowerShell via the test-script endpoint (CWE-862)
CVSS: 9.1 (AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)
Impact: arbitrary PowerShell execution as NT AUTHORITY\SYSTEM on the Devolutions Server host
Authentication: authenticated administrator (no PAM licence, no PAM role)
0day Rubbish Research Team is publicly disclosing a vulnerability in
CaptureBites MetaServer.
Type: Anonymous WCF SOAP workflow leading to RunPrograms code execution (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: arbitrary command execution as NT AUTHORITY\SYSTEM on the MetaServer host
Authentication: unauthenticated
Full technical analysis and a reproducible proof-of-concept:...
0day Rubbish Research Team is publicly disclosing a vulnerability in
PrizmDoc for Java (VirtualViewer) 5.22.1.
Type: Unauthenticated uploadDocument write into the webapp root to JSP webshell (CWE-306)
CVSS: 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Impact: JSP webshell execution with the JVM privileges, uid 0 (root) in the verified deployment
Authentication: unauthenticated
Full technical analysis and a reproducible proof-of-concept:...
I'm not a traditional security researcher by background - I found this
while working with the ACS and Teams SDKs and followed it through to a full
writeup and PoC. I've done my best to be accurate and responsible
throughout (reporting to MSRC first, giving advance notice of this
disclosure date, and only testing against meetings/tenants I own), but if
anything here is imprecise or doesn't match community...
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said.
The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
$ checksec --file Sofia
[*] '/redacted/Sofia'
Arch: arm-32-little
RELRO: No RELRO
Stack: Canary found
NX: NX unknown - GNU_STACK missing
PIE: No PIE (0x8000)
Stack: Executable
RWX: Has RWX segments
this ones interesting. sofia uses an internal flash fs called WFS. per
an online search:
WFS is a proprietary filesystem developed by Hikvision for its...
Posted by David Brown via Fulldisclosure on Sep 22
A stored cross-site scripting (XSS) vulnerability has been identified in
the H5P module
h5p-nodejs-library by Lumi Education UG in versions up to and including
10.0.4. The
library allows users to upload H5P content that contains malicious
JavaScript. This code
is then executed in the browsers of other users who view the affected
H5P content.
Metadata
========
- Affected product: h5p-nodejs-library
- Affected version: All versions up to and...
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.
On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.
The package, named "tw-pkgprobe-7731," was first uploaded to the npm registry in mid-August 2026 by an npm account named "twdepprobe7731."
ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT financially motivated,” a Shiny spokesperson told The Register. “We want the FBI to correct or retract their statements they made, which included substantial false allegations.” The FBI did not immediately respond to The Register’s request for comment. According to a ShinyHunters spokesperson, the extortion group exploited an Oracle PeopleSoft zero-day vulnerability on the FBI jobs webpage, which it says allowed remote code execution (RCE) on the servers. The group then defaced the website, replacing it with a “This site has been seized by ShinyHunters” banner and image shared with The Register. At press time, the site says it is “currently down for maintenance but will be back up soon!” ShinyHunters also claims it moved laterally from the compromised site onto the FBI’s managed servers on AWS GovCloud, and downloaded about 2 TB to 3 TB of data belonging to current, former, and prospective FBI employees. “We hold data on all FBI employees and applicants,” the spokesperson told us. ShinyHunters claims the compromised FBI services include human resources, MedLink, and Criminal Justice Information Services. Neither Oracle nor AWS immediately responded to our inquiries, including whether Oracle is aware of a PeopleSoft preauth RCE zero-day, and whether AWS has any insight into the alleged data theft. We will update this story if we receive any response. Unlike most of the group’s smash-and-grab operations that involve a multimillion-dollar ransom demand to not leak the stolen files, ShinyHunters said it isn't seeking an extortion payment from the FBI. Instead, it wants the federal cops to retract statements made about ShinyHunters in a May 15 bulletin, shortly after the gang broke into ed-tech giant Instructure's Canvas platform and claimed to have stolen data tied to hundreds of millions of students, teachers, and staff. The FBI said ShinyHunters uses “harassment strategies, sending threatening text messages and phone calls to victims and their family members, and in some cases, swatting.” The security alert also said that extortionists “may falsely claim to have sensitive or compromising information, including embarrassing photographs or videos of victims, which frequently do not exist.” Shiny claims none of this is true. “I have been doing my very best to combat these allegations,” they told us. “And this is the best way to do it.” ®
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain."
The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
Anthropic’s newest Claude model aims to make frontier AI cheaper, faster, and safer, while giving subscribers more breathing room before those frustrating usage limits kick in.
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.
The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is