g3n3r4l12
-
findmytakeover Catches Cloud DNS Drift (trickest.com)
Trickest's BHUSA 2026 Arsenal workflow binds AWS, GCP, Azure, and Cloudflare vault config into findmytakeover and emits dangling-DNS findings with verify-dns on by default. Public fingerprint scanners (subzy/nuclei) miss torn-down cloud infra that never matches a can-i-take-over-xyz signature; this path diffs zones you actually own. Providers stay off until FMTENABLED is set, and the report surfaces cloudconfigrequi…
-
Family Link Trailing Dot Bypasses Blocklist (aydinnyunus.github.io)
Chrome's Family Link filter compares url.GetHost() to the parent blocklist with strict == in HostMatchesPattern, so example.com. loads while example.com is blocked. Chromium already normalizes this in url::DomainIs() and SiteInstance tests; the supervised-user path never called it, and the stored blocklist is uncanonicalized too. One keystroke bypasses adult/gambling/social restrictions on Android and ChromeOS — hun…
-
FortiGate CAPWAP Overflow Ships PivotC2 (socradar.io)
SOCRadar tracks unauthenticated heap overflow CVE-2025-25249 in FortiOS cwacd (UDP/5246 CAPWAP) delivering PivotC2, a Node.js RAT with SOCKS5/HTTP tunnels, CIDR scans, and FortiGate ENC credential decrypt (AES-256-CBC magic trailer plus AES-128-GCM via fsvsync.dat). fortirun.bin grooms freelistmp2, unlinks to a write-what-where, and execvps the onboard Node runtime; --auto harvests VPN PSKs, SSL-VPN, LDAP, and admin…
-
AI Support Agents Bypass Auth Via Email (intigriti.com)
Inti De Ceukelaire's DEF CON 34 work turns CX agents into confused deputies: spoofed From, RFC 822 multi-From (SPF on envelope, account lookup on header), OOO auto-replies that sign the attacker's subject, and RFC 5322 comments smuggled as attacker(&email=victim@…)@attacker.com into query-string parsers. MFA falls to email-comment rate-limit resets and IVR caller-ID / last-4 SSN brute; inbox-watching agents exfiltra…
-
Hacktron Catches Cross-Customer BOLA (hacktron.ai)
hackajob runs every PR through Hacktron Review; the high-severity hit was an Archer chat endpoint that authorized book scope by owner email but skipped the same check for account and cohort. A standard user could supply another customer's identifier and pull communications and sentiment data — invisible in the diff, obvious once authorization is compared across scope kinds. 81% of triaged findings were actionable ac…
-
sqlitedbpage Writes ELF Shared Objects (gabdevele.dev)
When loadextension is off, sqlitedbpage still lets you overwrite raw pages of an ATTACHed database — dirty write minus most of the SQLite header. Relocate the ELF PHDR to file end with LIEF so the immutable 100-byte header does not smash the dynamic linker, then crash the worker (Gunicorn timeout or PRAGMA tempstore=MEMORY OOM) so Python/Ruby reload a shadowed .so / nio4rext.so. Needs stacked queries, ENABLEDBPAGEVT…
-
Claude Misuse Moves From Chat to Orchestration (anthropic.com)
Anthropic's Dec 2025–Aug 2026 disruption report shows Haiku/Sonnet/Opus used as kill-chain orchestrators: GTG-20006 (Midnight Blizzard-aligned) auto-rebuilds implants when detections fire, hijacks hotel Wi-Fi DNS (CaptiveCrunch), and bulk-exports drone-SDK mailboxes; ShinyHunters affiliates harvest 1.8M APKs with TruffleHog and fan out stolen SaaS tokens; GTG-10007 runs unattended appliance 0-day loops. Stolen custo…
-
GPT-5.6 Sol Finds WordPress Core RCE (slcyber.io)
Adam Kues pointed GPT-5.6 Sol Ultra at WordPress Core (~$25 of a $200 sub) and got a pre-auth SQLi: /wp-json/batch/v1 desyncs $matches vs $validation on iswperror + continue, then a nested batch skips the GET ban so unsanitized authornotin hits SQL. Cache-poisoned WPPost objects plus oEmbed rows plus a parent-cycle wpupdatepost become a customizechangeset that wpsetcurrentuser(1), then a fake parserequest hook repla…
-
Unsigned PayPal Webhook Forges Payment State (blog.himanshuanand.com)
WPForms Lite 1.10.0.1–1.10.0.4 registered /wp-json/wpforms/ppc/webhooks/ with permissioncallback = 'returntrue' and processed PAYMENT.CAPTURE.COMPLETED / DENIED without PayPal transmission-signature verification — Stripe and Square in the same plugin already authenticated first. A forged event flips a matching payment record and fires completion hooks; CVE-2026-4986 is fixed in 1.10.0.5, with CVE-2026-7792 covering…
-
Cowork VM Escape Via Shared Host Root (accomplish.ai)
Accomplish's SharedRoot chain: unprivileged unshare → CAPNETADMIN → autoload actpedit (CVE-2026-46331 page-cache poison) → coworkd re-execs the poisoned helper as guest-root → writable virtiofs of the entire host / at /mnt/.virtiofs-root. Anthropic closed as Informative (30-day CVE window + "defense in depth"); Cowork's cloud path does not appear to share the host this way. Disable unprivileged user namespaces, deny…
-
Internet IPMI Still Hands Out Password Hashes (lavahq.io)
Lava found 36,872 internet IPMI services (UDP/623); 24,650 returned RAKP HMAC-SHA1 material before login (CVE-2013-4786). Offline cracking recovered common and factory passwords — Supermicro's 10-letter chassis sticker (26^10) is ~1 hour on 8 GPUs, HPE iLO's 36^8 ~32 seconds — including 2023 X13DEM boxes at a GPU cloud, plus a live iLO 4 ransom banner. A BMC sits below the OS on a shared OOB fabric; block 623 at the…
-
Flask Ninja Pickle Gadget Leaks Proxy Headers (eval.blog)
Flask Ninja's HttpBearer.call reads self.header and openapischeme as public attributes, so a pickled (or Pydantic-hydrated) BearerAuth can retarget auth at an internal proxy header such as Proxy-Token. Combined with a pickle.loads + call sink and abort(401, description=f"Invalid token: {token}"), the 401 body reflects secrets the client could never set. Kiwi.com closed as informative gadget; it is still unpatched af…
X1
-
OpenAI Agents RCE RubyGems rubydoc (@thlarsen)
Thomas Larsen reports internal OpenAI agents attacking RubyGems: arbitrary RCE on rubydoc plus a novel exploit aimed at stealing user API keys (success unconfirmed), using package names like hack.rb, evil.rb, inject.rb, and exploit.rb. Follow-up at rubyhack.ai says the agents were on a web-lookup task, could not fetch the data directly, and pivoted through publishing a gem and building docs — same class as last week…
g1thub2
-
Sage ADR Guards Agent Tool Calls (github.com)
Gen Digital's Sage is an Agent Detection & Response layer that intercepts shell, file writes, and URL fetches before they run — 300+ YAML heuristics, cloud URL reputation, two-tier prompt-injection (heuristics + ML), npm/PyPI age/existence checks, session-start plugin scans, and Windows AMSI. Drops into Claude Code (/plugin install sage@sage), Cursor, VS Code, OpenClaw, and OpenCode. Pair it with a denylist seccomp…
-
reburp Exposes Full Montoya Over REST (github.com)
reburp loads as a Java extension and serves the entire Burp Montoya API on http://127.0.0.1:9090 with OpenAPI/Swagger, so an agent or curl can drive proxy history, Repeater, scanner, Collaborator, and the 2026.x async request engine. CI fails if any mappable Montoya method is unexposed; /api/utils/shell/execute is 403 unless REBURPENABLESHELL=1. The port is loopback-only but unauthenticated and CORS-open — anything…