Archive

Archive

1481 bookmarks
Custom sorting
CDC-ACM Serial Interface Bypasses TCC on macOS: A Disclosure After Apple Declined
CDC-ACM Serial Interface Bypasses TCC on macOS: A Disclosure After Apple Declined
macOS creates a fully read/write CDC-ACM serial device node with no TCC gate. Chained with a HID keyboard interface on the same USB composite device, this exfiltrates SSH keys, cloud credentials, and secrets in 24 seconds through a channel that shows no consent prompts. Apple was notified on 2026-04-26, declined the report on 2026-05-20, and I am publishing this today after 4 months of silence following my final response.
·glyph.sh·
CDC-ACM Serial Interface Bypasses TCC on macOS: A Disclosure After Apple Declined
One Login, Two RCEs: CVE-2026-90822 and CVE-2026-90823
One Login, Two RCEs: CVE-2026-90822 and CVE-2026-90823
During a recent assessment, I came upon a VPN management portal I had never seen before that I found to be a FatPipe MPVPN appliance. After a little research I discovered this was a monolithic native application, ideal for pointing Claude/GPT 5.6 sol at to hopefully find some vulnerabilities and land an old-fashioned native
·securifera.com·
One Login, Two RCEs: CVE-2026-90822 and CVE-2026-90823
CVE-2026-20093: Unauthenticated Admin Reset on Cisco IMC
CVE-2026-20093: Unauthenticated Admin Reset on Cisco IMC
CVE-2026-20093 is a CVSS 9.8 pre-auth password change on Cisco IMC via configConfMo/aaaUser. Lab notes unpack HUU 4.3.2.250063 vs 4.3.2.260007: nginx /nuova, FastCGI, xapireqproc manageUsers. Patch or isolate the BMC.
·core-jmp.org·
CVE-2026-20093: Unauthenticated Admin Reset on Cisco IMC
Activating Chrome DevTools Protocol in Memory: Bypassing -remote-debugging-port Restrictions - Pikered
Activating Chrome DevTools Protocol in Memory: Bypassing -remote-debugging-port Restrictions - Pikered
A technical walkthrough of a new offensive technique that activates the Chrome Debugging Protocol directly in memory, bypassing Google's --remote-debugging-port mitigations. Covers chrome.dll signature scanning, DevToolsSocketFactory vtable reconstruction, PartitionAlloc constraints, and Special APC-based shellcode injection into the Chrome parent process.
·pikered.com·
Activating Chrome DevTools Protocol in Memory: Bypassing -remote-debugging-port Restrictions - Pikered
How to get a free .arpa domain
How to get a free .arpa domain
Learn how to get a free .arpa domain by abusing IPv6 reverse DNS delegations on Hurricane Electric, configuring deSEC, and hosting a live website.
·hawksley.dev·
How to get a free .arpa domain
Inside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research
Inside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research
Analysis of server-side data associated with The Gentlemen ransomware group identified the complete TukTuk C2 project structure, DLL side-loading configurations, EDR neutralization research, vulnerable driver materials, and data assessed to have been exfiltrated from multiple organizations.
·oasis-security.io·
Inside The Gentlemen: Undisclosed TukTuk C2 Framework and EDR Neutralization Research
PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 unauthenticated RCE chain
PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 unauthenticated RCE chain
Prove or reject unauthenticated remote OS command execution as the PaperCut service account on stock PaperCut NG/MF 25.0.11 via a pre-auth Release Station / MFD card-ID flow reaching the external card-lookup runtime, then replay identically on stock 25.0.12 to confirm the fix blocks the chain. This maps to the PaperCut NG/MF URGENT Security Bulletin of 27 Aug 2026 active exploitation, all versions affected . Whether a stock remote mechanism exists is an open question; card-ID SQL injection and JDBC URL injection are unproven hypotheses only.
·pruva.dev·
PaperCut NG/MF CVE-2026-81578 + CVE-2026-82078 unauthenticated RCE chain