r/netsec bot
@r-netsec.bsky.social
Mirrors r/netsec, "a community-curated link aggregator of technical information security content." Unofficial. Operated by @tweedge.net, open source @ https://github.com/tweedge/xpost-reddit-to-fediverse
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
schaerli.org
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
pop.byteray.co.uk
8 out of 10 Banks HATE This One Weird 3SKey RCE
8 out of 10 Banks HATE This One Weird 3SKey RCE
amibeingpwned.com
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
grizzlysec.com
Azure's Weakest Link - Five Full Cross-Tenant Compromises
Azure's Weakest Link - Five Full Cross-Tenant Compromises
binsec.no
Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files
Server Mismatch: WordPress plugin vulnerabilities when relying on .htaccess files
ultrastrike.io
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
From: anyone@icloud.com - Spoofing Arbitrary Apple iCloud Identities
sec-consult.com
New Local Privilege Escalation on Acer laptops
New Local Privilege Escalation on Acer laptops
intrinsec.com
Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS
horizon3.ai
AI coding agents have been creating public GitHub repos on their own to post internal company screenshots
AI coding agents have been creating public GitHub repos on their own to post internal company screenshots
glow.io
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
blog.nns.ee
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
Critical RCE Alert: Full takeover of HashiCorp Vault and OpenBao. OpenBao is patched. Vault remains exposed
control-plane.io
Paint It Blue: Reversing Win32k's Callbacks
Paint It Blue: Reversing Win32k's Callbacks
idov31.github.io
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772) - watchTowr Labs
labs.watchtowr.com
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
Policy-enforced egress in AI agent sandboxes: an empirical evaluation of NVIDIA OpenShell v0.1.2 (123 trials, pre-registered, logs public)
sorami.com.au
I flooded a legal contract with lookalike letters and gave it to seven GPT and Claude models. None were fooled, but it took up to 5.7x the tokens to read, and the bill for each question rose by up to 3.9x. 'Denial of Spend'
I flooded a legal contract with lookalike letters and gave it to seven GPT and Claude models. None were fooled, but it took up to 5.7x the tokens to read, and the bill for each question rose by up to 3.9x. 'Denial of Spend'
paultendo.github.io
Sender spoofing in Proton Mail via display-name homograph
Sender spoofing in Proton Mail via display-name homograph
alonsovidales.github.io
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771) - watchTowr Labs
labs.watchtowr.com
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
CVE-2026-32740: RCE in a PIE Next.js sharp/libheif Stack
fortbridge.co.uk
RCE in OpenCode (GHSA-632h-h47v-g4x4)
RCE in OpenCode (GHSA-632h-h47v-g4x4)
securitylabs.datadoghq.com
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
heyitsas.im
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
raelize.com