Found 1481 bookmarks
Newest
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
Hello! Yes, it's all a disaster again! Let's get this party started: 0:00 /0:12 1× No comments today, so imagine this: * We wrote something that we find very funny, * Nobody else gets it, * But everyone humors us Just like a typical watchTowr Labs blog introduction. As with all
·labs.watchtowr.com·
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940)
QUIC-er Races: HTTP/3 won’t save you from TOCTOU vulnerabilities - International Journal of Information Security
QUIC-er Races: HTTP/3 won’t save you from TOCTOU vulnerabilities - International Journal of Information Security
Race conditions in web applications represent a persistent class of vulnerabilities that allow adversaries to bypass business logic through synchronized request bursts. While the transition from TCP-based HTTP/2 to UDP-based HTTP/3 (QUIC) introduces stochastic processing delays and independent stream delivery, the security implications of these protocol shifts remain under-explored. This work investigates the effectiveness of race condition exploits across modern transport protocols. Our experimental results demonstrate that while the user-space implementation of QUIC provides a resilience threshold against low-volume attacks, this protection is an artifact of scheduling jitter and is inherently fragile. We identify a critical concurrency threshold ( $$N=100$$ N = 100 ) where the density of a Single Datagram Attack (SDA) saturates the protocol parser, achieving an exploitation efficiency (f) that exceeds traditional HTTP/2 methods. However, we also identify a “smothering effect” unique to high-density bursts, where extreme transaction arrival rates trigger database-level lost updates that can paradoxically limit total economic impact. Furthermore, we show that infrastructure-level defenses, such as network pacing, are effectively neutralized by the reverse proxy’s de-multiplexing process. We conclude that protocol-level evolution does not mitigate application-layer concurrency risks; rather, it shifts the attack surface dynamics toward more efficient but higher-contention exploitation primitives.
·link.springer.com·
QUIC-er Races: HTTP/3 won’t save you from TOCTOU vulnerabilities - International Journal of Information Security
Zero-Click RCE in Figma Desktop: A Race-Conditioned Prototype Pollution Chain That Escapes the Plugin Sandbox
Zero-Click RCE in Figma Desktop: A Race-Conditioned Prototype Pollution Chain That Escapes the Plugin Sandbox
A prototype pollution bug in Figma’s variant counter, chained through a plugin-context race against $INTERNAL_DO_NOT_USE$RERUN_PLUGIN$, a jsx_debugging feature-flag flip, and a forgotten writeFileToPath IPC in the Electron desktop app, to achieve zero-click cross-platform RCE from a published plugin. Reported to Figma and patched within hours.
·lab.ctbb.show·
Zero-Click RCE in Figma Desktop: A Race-Conditioned Prototype Pollution Chain That Escapes the Plugin Sandbox
Abusing WinML for In-Memory Staging and EDR Evasion
Abusing WinML for In-Memory Staging and EDR Evasion
Abusing legitimate machine learning infrastructure for payload delivery, in-memory staging, and EDR evasion on Windows 10/11. Introduction Every red team operator knows the arms race: EDR vendors get better at flagging suspicious API sequences, shellcode patterns, and reflective loaders. Meanwhile, Windows keeps shipping new legitimate subsystems that are rarely audited from an offensive perspective. Windows Machine Learning (WinML) - shipped since Windows 10 1809 (build 17763) - is one su
·hxr1.ghost.io·
Abusing WinML for In-Memory Staging and EDR Evasion
Creative approaches to coding FUD Stagers
Creative approaches to coding FUD Stagers
I have had several discussions over the years with folks on tackling EDR bypass as it pertains to fully undetected (FUD) code. In my opinion, there isn’t really a perfect silver bullet approach to tackling FUD. Especially with ML (machine learning) / AI integrated in most modern EDR solutions, you really have to adjust your approach to FUD as you go. I will say that I truly believe script interpreter type languages such as Python, Ruby, Perl, even PHP, are great candidates to meet this need. Scripting languages are not heavily scrutinized when we’re comparing with compiled (PE executable) code. Now I can already hear the disgruntled offsec folks questioning my rationale when they have tried countless times to make their powershell and javascript/vbscript code into FUD worthy code. I get it and I’m with you. It’s not a one size fits all right? Powershell, while also a script interpreter type language, has been so abused by threat actors that it’s incredibly difficult to tackle FUD due to its prolific use in malicious campaigns, but it’s certainly not impossible. Let’s get to it!
·g3tsyst3m.com·
Creative approaches to coding FUD Stagers
CVE-2026-1731 | AttackerKB
CVE-2026-1731 | AttackerKB
On February 6, 2026, BeyondTrust published an advisory for a new critical command injection vulnerability, CVE-2026-1731, affecting their products Remote Suppo…
BeyondTrust
·attackerkb.com·
CVE-2026-1731 | AttackerKB
CVE-2025-24000 - Post SMTP Plugin - Lark Docs
CVE-2025-24000 - Post SMTP Plugin - Lark Docs
Post SMTP Plugin (= 3.2.0) Privilege Escalation Vulnerability Walkthrough Vulnerability Report CVE ID: CVE-2025-24000 Plugin: Post SMTP Type: Privilege Escalation via Broken Authentication Vulnerable Version: = 3.2.0 Fixed Version: 3.3.0 Patch Priority: High CVSS Score: 8.8 (High) OWASP Classification: A7: Identification and Authentication Failures Discovered by: Denver Jackson Published: July 21, 2025 Overview The WordPress plugin "Post SMTP"
·gsgt3hxzpyz3.sg.larksuite.com·
CVE-2025-24000 - Post SMTP Plugin - Lark Docs
RainLoop Webmail - Emails at Risk due to Code Flaw
RainLoop Webmail - Emails at Risk due to Code Flaw
Sonar researchers discovered a critical stored cross-site scripting vulnerability in RainLoop Webmail that allows attackers to hijack user sessions and steal emails simply by sending a malicious email. The article explains the root cause, exploitation, and security implications.
RainLoop
·sonarsource.com·
RainLoop Webmail - Emails at Risk due to Code Flaw
Zero Day Initiative — CVE-2026-33824: Remote Code Execution in Windows IKEv2
Zero Day Initiative — CVE-2026-33824: Remote Code Execution in Windows IKEv2
In this excerpt of a TrendAI Research Services vulnerability report, Richard Chen and Lucas Miller of the TrendAI Research team detail a recently patched double free vulnerability in the Windows Internet Key Exchange (IKE) service. This bug was originally discovered by WARP & MORSE team at
·zerodayinitiative.com·
Zero Day Initiative — CVE-2026-33824: Remote Code Execution in Windows IKEv2
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
Our investigation uncovers two sophisticated telecom surveillance campaigns and, for the first time, links real-world attack traffic to mobile operator signalling infrastructure. The findings expose how suspected commercial surveillance vendors (CSVs) exploit the global telecom interconnect ecosystem, leverage private operator networks, and conduct covert location tracking operations that can persist undetected for years.
·citizenlab.ca·
The Citizen Lab Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
CVE-2026-25874: HuggingFace LeRobot Unauthenticated RCE via Pickle Deserialization in gRPC PolicyServer - Chocapikk's Cybersecurity Blog
CVE-2026-25874: HuggingFace LeRobot Unauthenticated RCE via Pickle Deserialization in gRPC PolicyServer - Chocapikk's Cybersecurity Blog
A critical unauthenticated RCE vulnerability in HuggingFace's LeRobot project (21.5k stars). The gRPC PolicyServer deserializes attacker-controlled data with pickle.loads() in two RPC handlers, allowing instant code execution without authentication.
·chocapikk.com·
CVE-2026-25874: HuggingFace LeRobot Unauthenticated RCE via Pickle Deserialization in gRPC PolicyServer - Chocapikk's Cybersecurity Blog