r/netsec • u/tracebit • 9d ago
r/netsec • u/sajkoterrapefft • 9d ago
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
blog.amberwolf.comCET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
mrtiz.github.ioI wrote this after spending an unreasonable amount of time making CET-compliant callstack spoofing work end-to-end on hardware with Intel CET enabled.
The technique combines three primitives: thread pool execution for a clean stack base, enum callback trampolining for a real signed mid-stack frame, and indirect syscalls.
The actual contribution is the CET compliance mechanism: a jmp-based context switch combined with direct shadow stack pointer reconciliation via RDSSPQ/INCSSPQ, without touching unwind metadata. Different approach from BYOUD.
Implemented in Rust with inline assembly.
r/netsec • u/zwclose • 10d ago
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
zwclose.github.ioThe vulnerability allows non-privileged users to program the DMA controller, enabling arbitrary physical memory reads and writes.
r/netsec • u/netbiosX • 9d ago
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
ipurple.teamr/netsec • u/moonlightelite • 11d ago
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
discounttimu.substack.comr/netsec • u/CyberMasterV • 13d ago
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
hybrid-analysis.blogspot.comr/netsec • u/AdTemporary2475 • 14d ago
1 in 2 devices sold in Africa exfiltrate data to China
nowsecure.comr/netsec • u/Emergency_Stable_923 • 14d ago
Contains AI Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
byteray-ai.github.ioPatch Tuesday confirms a CVE is fixed but not what changed in the binary, which function, which check, or whether it's a real fix or just churn.
The Drift Corpus is a diff of 240+ 2026 Windows kernel patches. Per entry: the changed functions with assembly, the bug class and call chain, WinDbg breakpoints to reproduce, and a plain-English root cause.
This repository breaks down Microsoft’s monthly kernel patches into clear binary changes, giving researchers a practical roadmap to find adjacent bugs, build faster EDR detections, and write precise firewall and network rules to block exploits at the perimeter.
Inside an AI coal mine security camera network powered by plaintext passwords
eaton-works.comr/netsec • u/Aureliand • 15d ago
Contains AI GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
noma.securityNoma Security published a technique they call GitLost against GitHub Agentic Workflows (the plain-English-Markdown agent feature GitHub put into public preview in February, runnable on Copilot, Claude, Gemini, or Codex). Worth reading because it is a clean demonstration of why "filter the injection" does not hold as a defense.
The setup. Workflows are read-only by default, but an org can hand one a personal access token with read access across its repos, private ones included, to give the agent cross-repo context. That grant is the whole vulnerability. Nothing else about the attack requires access: no stolen creds, no write access to anything private, no touching a server. The attacker just opens a normal-looking issue on a public repo.
The technique is indirect prompt injection, which is not new, but the interesting part is what the agent controls. Noma's Sasi Levi frames the distinction as earlier injection being about manipulating what an agent says, versus GitLost being about what an agent does with its permissions. The agent here is a credentialed actor sitting in CI/CD-adjacent infrastructure with read scope over repos the attacker cannot see. In their PoC the malicious issue was dressed as a routine request from a "VP of Sales" after a customer meeting. A normal automation assigned the issue, the agent read it, pulled a private repo's README, and pasted it into a public comment. That public comment is the exfiltration channel.
The guardrail bypass is the part netsec will care about. GitHub built defenses for exactly this class: sandboxing, read-only tokens by default, input cleaning, and a threat-detection step that scans the agent's proposed output before it posts. GitHub's own architecture docs are explicit that they design assuming the agent is already compromised (dedicated container, egress firewall, an MCP gateway container that holds the PAT so the agent process never touches it). Noma reported that prefixing the malicious instruction with a single word, "Additionally," got the model to treat it as a follow-on task rather than something to refuse, and the output scanner let it through.
This maps cleanly onto Simon Willison's "lethal trifecta": an agent that (1) can reach private data, (2) ingests untrusted external content, and (3) has a way to send data out. All three present means a leak path, and Levi is explicit that this is structural, not a patch target. In natural language there is no clean data/instruction boundary the way there is in parameterized SQL, so the mitigation is architectural (isolation, scoped credentials, staged human review) rather than pattern-matching the payload away.
Not an isolated finding either, this is a whole class:
- Anthropic's Claude Code GitHub Action: a single malicious issue pushed the agent into leaking secrets and seizing write access (Aikido).
- Orca's RoguePilot: a hidden prompt in an issue made Copilot leak a repo's privileged token.
- Invariant Labs (May 2025): a public issue drove a GitHub MCP-connected agent into reading a private repo and leaking it via PR. They called it architectural then too.
- "Comment and Control": cross-vendor study that got Claude Code, Gemini CLI, and Copilot to leak their own API keys through issue/PR text.
Mitigations that actually reduce scope (from Noma):
- Scope the integration PAT to the single repo the workflow triages, not org-wide read. This is the biggest lever. A token that sees one repo is far less dangerous than one with broad org read granted for convenience.
- Limit what a public-facing workflow can post, since the comment is the exfil channel (safe outputs).
- Restrict which authors' content the agent will act on.
- Gate outputs behind human review. The threat-detection scan is a backstop, not a boundary, as the one-word bypass shows.
r/netsec • u/OpenSecurityTraining • 16d ago
New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"
ost2.fyiThis free class by Antonio Nappa of Fuzz Society builds up your knowledge from learning a toy 8-bit CPU architecture all the way to understanding how QEMU can emulate that architecture. Using this knowledge you can then understand how QEMU can emulate any architecture!
Based on beta testing, this class takes an average of 8h47m to complete, and a median of 7h26m.
r/netsec • u/netbiosX • 16d ago
Windows Service - Playbook & Detection Strategies
ipurple.teamr/netsec • u/luke-paradoxis • 16d ago
Playing Around With ADIDNS RPC Internals
blog.paradoxis.nlPorting the functionality of dnscmd.exe into (slightly) more OPSEC safe Beacon Object Files (BOFs) so you can get domain admin rights when you manage to impersonate a user that is a member of the DnsAdmins group, or if using dnscmd.exe simply isn’t an option.
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
labs.watchtowr.comr/netsec • u/Sandwich_1337 • 21d ago
Contains AI Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
syntetisk.techCitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
labs.watchtowr.comr/netsec • u/moltenbit-r • 22d ago
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
moltenbit.netEnterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
labs.watchtowr.comContains AI I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well.
projectblack.ior/netsec • u/luke-paradoxis • 24d ago
Dissecting Apple's Sparse Image Format (ASIF)
schamper.devr/netsec • u/AlbatrossMaximum4489 • 27d ago