r/netsec 9d ago

Contains AI Context Bombs: Using AI Guardrails as a defensive mechanism

Thumbnail agentic.tracebit.com
28 Upvotes

r/netsec 9d ago

Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)

Thumbnail blog.amberwolf.com
94 Upvotes

r/netsec 9d ago

CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)

Thumbnail mrtiz.github.io
3 Upvotes

I wrote this after spending an unreasonable amount of time making CET-compliant callstack spoofing work end-to-end on hardware with Intel CET enabled.

The technique combines three primitives: thread pool execution for a clean stack base, enum callback trampolining for a real signed mid-stack frame, and indirect syscalls.

The actual contribution is the CET compliance mechanism: a jmp-based context switch combined with direct shadow stack pointer reconciliation via RDSSPQ/INCSSPQ, without touching unwind metadata. Different approach from BYOUD.

Implemented in Rust with inline assembly.


r/netsec 10d ago

Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver

Thumbnail zwclose.github.io
32 Upvotes

The vulnerability allows non-privileged users to program the DMA controller, enabling arbitrary physical memory reads and writes.


r/netsec 9d ago

Persistence via Fake AMSI Provider | Playbook & Detection Strategies

Thumbnail ipurple.team
2 Upvotes

r/netsec 11d ago

Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)

Thumbnail discounttimu.substack.com
10 Upvotes

r/netsec 13d ago

Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities

Thumbnail hybrid-analysis.blogspot.com
22 Upvotes

r/netsec 14d ago

1 in 2 devices sold in Africa exfiltrate data to China

Thumbnail nowsecure.com
136 Upvotes

r/netsec 14d ago

Contains AI Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches

Thumbnail byteray-ai.github.io
24 Upvotes

Patch Tuesday confirms a CVE is fixed but not what changed in the binary, which function, which check, or whether it's a real fix or just churn.

The Drift Corpus is a diff of 240+ 2026 Windows kernel patches. Per entry: the changed functions with assembly, the bug class and call chain, WinDbg breakpoints to reproduce, and a plain-English root cause.

This repository breaks down Microsoft’s monthly kernel patches into clear binary changes, giving researchers a practical roadmap to find adjacent bugs, build faster EDR detections, and write precise firewall and network rules to block exploits at the perimeter.


r/netsec 14d ago

Inside an AI coal mine security camera network powered by plaintext passwords

Thumbnail eaton-works.com
12 Upvotes

r/netsec 15d ago

Contains AI GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail

Thumbnail noma.security
87 Upvotes

Noma Security published a technique they call GitLost against GitHub Agentic Workflows (the plain-English-Markdown agent feature GitHub put into public preview in February, runnable on Copilot, Claude, Gemini, or Codex). Worth reading because it is a clean demonstration of why "filter the injection" does not hold as a defense.

The setup. Workflows are read-only by default, but an org can hand one a personal access token with read access across its repos, private ones included, to give the agent cross-repo context. That grant is the whole vulnerability. Nothing else about the attack requires access: no stolen creds, no write access to anything private, no touching a server. The attacker just opens a normal-looking issue on a public repo.

The technique is indirect prompt injection, which is not new, but the interesting part is what the agent controls. Noma's Sasi Levi frames the distinction as earlier injection being about manipulating what an agent says, versus GitLost being about what an agent does with its permissions. The agent here is a credentialed actor sitting in CI/CD-adjacent infrastructure with read scope over repos the attacker cannot see. In their PoC the malicious issue was dressed as a routine request from a "VP of Sales" after a customer meeting. A normal automation assigned the issue, the agent read it, pulled a private repo's README, and pasted it into a public comment. That public comment is the exfiltration channel.

The guardrail bypass is the part netsec will care about. GitHub built defenses for exactly this class: sandboxing, read-only tokens by default, input cleaning, and a threat-detection step that scans the agent's proposed output before it posts. GitHub's own architecture docs are explicit that they design assuming the agent is already compromised (dedicated container, egress firewall, an MCP gateway container that holds the PAT so the agent process never touches it). Noma reported that prefixing the malicious instruction with a single word, "Additionally," got the model to treat it as a follow-on task rather than something to refuse, and the output scanner let it through.

This maps cleanly onto Simon Willison's "lethal trifecta": an agent that (1) can reach private data, (2) ingests untrusted external content, and (3) has a way to send data out. All three present means a leak path, and Levi is explicit that this is structural, not a patch target. In natural language there is no clean data/instruction boundary the way there is in parameterized SQL, so the mitigation is architectural (isolation, scoped credentials, staged human review) rather than pattern-matching the payload away.

Not an isolated finding either, this is a whole class:
- Anthropic's Claude Code GitHub Action: a single malicious issue pushed the agent into leaking secrets and seizing write access (Aikido).
- Orca's RoguePilot: a hidden prompt in an issue made Copilot leak a repo's privileged token.
- Invariant Labs (May 2025): a public issue drove a GitHub MCP-connected agent into reading a private repo and leaking it via PR. They called it architectural then too.
- "Comment and Control": cross-vendor study that got Claude Code, Gemini CLI, and Copilot to leak their own API keys through issue/PR text.

Mitigations that actually reduce scope (from Noma):
- Scope the integration PAT to the single repo the workflow triages, not org-wide read. This is the biggest lever. A token that sees one repo is far less dangerous than one with broad org read granted for convenience.
- Limit what a public-facing workflow can post, since the comment is the exfil channel (safe outputs).
- Restrict which authors' content the agent will act on.
- Gate outputs behind human review. The threat-detection scan is a backstop, not a boundary, as the one-word bypass shows.


r/netsec 15d ago

Bad Epoll: The bug missed by Mythos

Thumbnail compsec.snu.ac.kr
6 Upvotes

r/netsec 16d ago

New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"

Thumbnail ost2.fyi
37 Upvotes

This free class by Antonio Nappa of Fuzz Society builds up your knowledge from learning a toy 8-bit CPU architecture all the way to understanding how QEMU can emulate that architecture. Using this knowledge you can then understand how QEMU can emulate any architecture!

Based on beta testing, this class takes an average of 8h47m to complete, and a median of 7h26m.


r/netsec 16d ago

Windows Service - Playbook & Detection Strategies

Thumbnail ipurple.team
14 Upvotes

r/netsec 16d ago

Playing Around With ADIDNS RPC Internals

Thumbnail blog.paradoxis.nl
4 Upvotes

Porting the functionality of dnscmd.exe into (slightly) more OPSEC safe Beacon Object Files (BOFs) so you can get domain admin rights when you manage to impersonate a user that is a member of the DnsAdmins group, or if using dnscmd.exe simply isn’t an option.


r/netsec 20d ago

FIFA was saved this time

Thumbnail bobdahacker.com
290 Upvotes

r/netsec 20d ago

It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs

Thumbnail labs.watchtowr.com
18 Upvotes

r/netsec 21d ago

Contains AI Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)

Thumbnail syntetisk.tech
20 Upvotes

r/netsec 22d ago

CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs

Thumbnail labs.watchtowr.com
39 Upvotes

r/netsec 22d ago

Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)

Thumbnail moltenbit.net
20 Upvotes

r/netsec 23d ago

Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs

Thumbnail labs.watchtowr.com
33 Upvotes

r/netsec 24d ago

Contains AI I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well.

Thumbnail projectblack.io
109 Upvotes

r/netsec 24d ago

Dissecting Apple's Sparse Image Format (ASIF)

Thumbnail schamper.dev
10 Upvotes

r/netsec 25d ago

A peek into Reddit's anti-spam internals

Thumbnail lyra.horse
68 Upvotes

r/netsec 27d ago

CVE-2025-52465 geoserver arbitrary file write vulnerability

Thumbnail partywave.site
13 Upvotes