g3n3r4l11
-
Executing arbitrary Python code from a comment (hacktron.ai)
-
Cloud Build Race Condition Bypass (adnanthekhan.com)
A subtle race condition in Google Cloud Build's GitHub integration could bypass maintainer review for pull request tests, highlighting critical access control risks in CI/CD systems.
-
CrushFTP RCE via DMZ Proxy Flaw (pwn.guide)
CVE-2025-54309 exploited security check failures in CrushFTP's DMZ proxy, bypassing protections for the internal admin server.
-
Hijacking Multi-Agent System Risks (blog.trailofbits.com)
Multi-agent systems (MASs) face failures from unknown components, paralleling distributed system vulnerabilities, enabling new exploit avenues.
-
PyPI Phishing Attack Incident Report (blog.pypi.org)
A recent campaign targeted PyPI users via email, prompting awareness and initial details about the attack vector.
-
AI Prompt Injection Risks and Mitigation (medium.com)
With rising LLM adoption, prompt injection poses new threats; an example illustrates real-world exploitation and defensive strategies.
-
Pixel 8 Kernel Debugging via KGDB Guide (xairy.io)
Techniques include building custom kernels, breaking into KGDB using ADB or serial connections, and attaching GDB for debugging.
-
https://blog.trailofbits.com/2024/01/12/how-to-introduce-semgrep-to-your-organization/ (blog.trailofbits.com)
Semgrep Adoption Strategies and MAS Risks – Introducing Semgrep requires organizational planning for security gains, while multi-agent systems face distributed failure risks akin to traditional infrastructure. \Read More\
-
TerraMaster NAS Firmware Extraction to RCE (offensive.blog)
Firmware extraction and PHP analysis led to remote code execution on TerraMaster NAS devices, starting from an IoT security research idea.
-
Gemini CLI Silent Code Execution Risk (tracebit.com)
A silent attack on Gemini CLI combined improper validation, prompt injection, and misleading UX to execute malicious commands during untrusted code inspection.
-
A flaw in the AI "vibe coding" platform Base44 allowed unauthorized access to users' private applications, identified by Wiz Research.
g1thub7
-
Proton's Lumo AI Assistant Prompt (gist.github.com)
Defines a cat-like, upbeat AI personality with guidelines for curiosity and respectful user interactions. Explore on GitHub
-
Java RMI Vulnerability Scanner Tool (github.com)
Remote-Method-Guesser identifies and exploits vulnerabilities in Java RMI services efficiently. Explore on GitHub
-
Amazon MWAA Remote Code Execution (github.com)
Details an RCE vulnerability in Amazon Managed Workflows for Apache Airflow (MWAA). Explore on GitHub
-
S3DNS: Cloud Bucket Discovery Tool (github.com)
Acts as a DNS server to identify AWS/GCP/Azure buckets, following CNAMEs and matching patterns during surfing. Explore on GitHub
-
CVE.ICU (github.com)
Project Code Release – Hosts the source code for the CVE.ICU initiative, though specifics remain sparse from the highlight. Explore on GitHub
-
Pwnat: Firewall/NAT Hole-Punching (github.com)
Exploits NAT translation tables to connect clients/servers behind separate NATs without third-party tools. Explore on GitHub