❌

Normal view

Dangling DNS record for bastion.certb.cdp.bethesda.net

6 August 2026 at 19:40

Posted by shed riot on Aug 06

# Summary

The hostname resolved to an address within a dynamic cloud IP pool.
The address had been released and was no longer controlled by the
organisation operating the hostname.

This condition is referred to as an "afterlife" issue.

Unlike a conventional CNAME-based subdomain takeover, the DNS record
pointed directly to a reusable cloud IP address. An attacker obtaining
that address could receive traffic intended for the...

CL.0 desync in www.microsoft.com

6 August 2026 at 19:40

Posted by shed riot on Aug 06

# Summary

I reported the issue to the Microsoft Security Response Center twice:

* VULN-165381, MSRC case 102964
* VULN-165876, MSRC case 103259

In both cases, they do not appear to have even looked at the PoCs, and so
have failed to adequately investigate before reaching a decision.

# Vulnerability

CWE-444: HTTP Request/Response Smuggling

The observed behaviour was consistent with CL.0 HTTP desync within the
request-processing chain.

#...

CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated Authentication Bypass (PoC)

6 August 2026 at 19:36

Posted by Γ–ner Efe GΓΌngΓΆr on Aug 06

Hello Full Disclosure,

I'd like to share an independent lab Proof-of-Concept for CVE-2026-15013.

### CVE-2026-15013 – miniOrange SAML SSO <= 5.4.3 Unauthenticated
Authentication Bypass

SAML Signature Algorithm Confusion vulnerability. An unauthenticated
attacker can forge a valid SAMLResponse by forcing HMAC-SHA1 verification
against the IdP's public key, allowing full account takeover (including
administrators).

Root cause:...

[KIS-2026-16] Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

-------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (nice) Local Privilege Escalation
Vulnerability
-------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected as well.

[-]...

[KIS-2026-15] Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

-------------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (action_audio.php) OS Command Injection
Vulnerability
-------------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected...

[KIS-2026-14] Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

---------------------------------------------------------------------------------
Telenia Software TVox <= 26.5.3 (set_env.php) Authentication Bypass
Vulnerability
---------------------------------------------------------------------------------

[-] Software Link:

https://www.teleniasoftware.com

[-] Affected Versions:

Version 26.5.3 and prior 26.x versions.
Version 24.9.21 and prior 24.x versions.
Older versions may be affected as well....

[KIS-2026-13] vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability

6 August 2026 at 19:34

Posted by Egidio Romano on Aug 06

-----------------------------------------------------------------
vBulletin <= 6.2.1 (runMaths) Remote Code Execution Vulnerability
-----------------------------------------------------------------

[-] Software Link:

https://www.vbulletin.com

[-] Affected Versions:

Version 5.7.5 and prior 5.x versions.
Version 6.2.1 and prior 6.x versions.

[-] Vulnerability Description:

The vulnerable code is located within the...

[SYSS-2026-050]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

6 August 2026 at 19:31

Posted by Matthias Deeg via Fulldisclosure on Aug 06

Advisory ID: SYSS-2026-050
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: Medium
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

[SYSS-2026-049]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

6 August 2026 at 19:31

Posted by Matthias Deeg via Fulldisclosure on Aug 06

Advisory ID: SYSS-2026-049
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

[SYSS-2026-048]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

6 August 2026 at 19:31

Posted by Matthias Deeg via Fulldisclosure on Aug 06

Advisory ID: SYSS-2026-048
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

[SYSS-2026-047]: DICOM Toolkit (DCMTK) - Path traversal (CWE-22)

6 August 2026 at 19:31

Posted by Matthias Deeg via Fulldisclosure on Aug 06

Advisory ID: SYSS-2026-047
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Path traversal (CWE-22)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure: 2026-07-31
CVE...

[SYSS-2026-046]: DICOM Toolkit (DCMTK) - Integer Overflow or Wraparound (CWE-190)

6 August 2026 at 19:31

Posted by Matthias Deeg via Fulldisclosure on Aug 06

Advisory ID: SYSS-2026-046
Product: DCMTK (DICOM ToolKit)
Manufacturer: OFFIS e.V. / DCMTK Community
Affected Version(s): 3.7.0
Tested Version(s): 3.7.0
Vulnerability Type: Integer Overflow or Wraparound (CWE-190)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2026-07-02
Solution Date: 2026-07-03
Public Disclosure:...

APPLE-SA-07-27-2026-8 Safari 26.6

6 August 2026 at 19:27

Posted by Apple Product Security via Fulldisclosure on Aug 06

APPLE-SA-07-27-2026-8 Safari 26.6

Safari 26.6 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/128073.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Safari
Available for: macOS Sonoma and macOS Sequoia
Impact: An app may be able to access sensitive user data
Description: An...

APPLE-SA-07-27-2026-7 visionOS 26.6

6 August 2026 at 19:27

Posted by Apple Product Security via Fulldisclosure on Aug 06

APPLE-SA-07-27-2026-7 visionOS 26.6

visionOS 26.6 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/128070.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accounts Framework
Available for: Apple Vision Pro (all models)
Impact: An app may be able to fingerprint the user...

APPLE-SA-07-27-2026-6 watchOS 26.6

6 August 2026 at 19:27

Posted by Apple Product Security via Fulldisclosure on Aug 06

APPLE-SA-07-27-2026-6 watchOS 26.6

watchOS 26.6 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/128068.

Apple maintains a Security Releases page at
https://support.apple.com/100100 which lists recent
software updates with security advisories.

Accounts Framework
Available for: Apple Watch Series 6 and later
Impact: An app may be able to fingerprint the user
Description:...

A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits

23 July 2026 at 02:03

Posted by zz lin on Jul 22

I came across a project, "0day Rubbish", that states it will continuously
disclose 0-day vulnerabilities discovered by an AI-driven research process
(a multi-LLM ensemble of Claude, OpenAI, DeepSeek and GLM). For each
vulnerability the project publishes a full technical analysis together with
a working exploit script and step-by-step reproduction instructions. The
project's content is hosted at:

https://0day-rubbish.com/blog...

Synology stale DNS allows practical interception of traffic from vulnerable DSM clients

23 July 2026 at 02:02

Posted by shed riot on Jul 22

# Synology stale DNS allows practical interception of traffic from
vulnerable DSM clients

Vendor case: 904909
Suggested severity: High

## Customer advisory

Synology customers using the affected DSM and Relayd versions listed below
should upgrade immediately.

The relevant man-in-the-middle vulnerabilities were fixed in DSM
6.2.3-25426 Update 3. Customers should install the latest DSM version
available for their device, and in no case remain on...

Amplitude customers using domain proxies should update their configuration immediately.

23 July 2026 at 02:02

Posted by shed riot on Jul 22

After receiving live analytics requests intended for `api2.amplitude.com`,
I contacted `security () amplitude com` and was invited to submit the issue
through Amplitude's private Bugcrowd programme.

In my view, Amplitude's handling of the report, including closing it as
"Not applicable" despite evidence of intercepted customer traffic, caused
by insecure configurations and documentation, constitutes a negligent
approach to...

ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver

21 July 2026 at 05:41

Posted by Hayaturehman Ahmadzai on Jul 20

Hi all,

I'm disclosing a vulnerability (CVE-2026-13585) in the ASUS bsitf.sys /
AsusBSItf.sys kernel driver, shipped with ASUS Business Manager and
Software Manager. ASUS has assigned the CVE and published a vendor advisory
with countermeasures.

Summary: The driver exposes a device (\\.\bsitf, admin-required to open)
with an IOCTL that allocates a caller-specified amount of physically
contiguous kernel memory, maps it into the calling...

New Release: UFONet v2.0 - "R3DST4R!"...

21 July 2026 at 05:40

Posted by psy on Jul 20

Hi Community,

I am glad to present a new release of this tool:

- https://ufonet.03c8.net

---------

"UFONet is a free software, P2P and cryptographic -disruptive toolkit-
that allows to perform DoS and DDoS attacks; on the Layer 7 (APP/HTTP)
through the exploitation of Open Redirect vectors on third-party
websites to act as a botnet and on the Layer3 (Network) abusing the
protocol."

"It also works as an encrypted DarkNET to...
❌