g3n3r4l16
-
Check Your Team's AI Credential Leaks (socradar.io)
Free checker that takes a corporate email address and matches it against credentials harvested by infostealer logs from Claude, ChatGPT, Gemini, Copilot and similar platforms. The category it names is the important part: browser-saved AI platform credentials are now first-class stolen assets, because a live session there may reach source code, internal documents and tool invocations rather than just a chat history.…
-
Bytecode Rockspec Pwns LuaRocks Registry (luarocks.org)
validates an uploaded rockspec by running it: loadstring into an empty setfenv environment with an instruction limit. It never restricted loadstring to text mode, so a rockspec could be LuaJIT bytecode — which LuaJIT does not verify, and which can read and write outside the function's own data, reach the real Lua state in memory, and call the functions the sandbox was meant to hide. RCE as the OpenResty daemon user,…
-
tacplus Format String Pwns Networks (elttam.com)
Matt Jones found a pre-auth format string on an error path in tacplus, the Cisco-descended TACACS+ daemon that centralises privilege levels and per-command authorization for entire router/switch/firewall fleets; success means code execution as the daemon user, root by default (CVE pending, patched by Shrubbery in F4.0.4.32; the archived Facebook fork never will be). The half that matters operationally is the PSK ora…
-
Single Click Runs Code via OpenCode (securitylabs.datadoghq.com)
GHSA-632h-h47v-g4x4: OpenCode's upgrade endpoint could be driven by a malicious webpage to execute code on a developer's machine, i.e. the local AI coding agent became the browser's remote-code-execution path. This is the standard risk profile of "loopback HTTP daemon plus any web origin" — the fix class is origin validation and correct binding, not user education. If your engineers run AI coding CLIs, inventory eve…
-
Shortcuts Callback Dodges Chrome's tel: Guard (blog.doyensec.com)
CVE-2026-13795 (Leonardo Giovannini): Chrome for iOS treated shortcuts:// — and the legacy workflow:// alias — as a trusted Apple app, so it skipped the app-launch confirmation it shows for other custom schemes. Shortcuts honours the x-callback-url convention (x-success / x-cancel / x-error), and those parameters are real URLs that iOS opens directly, never returning to Chrome. A page therefore supplies a first hop…
-
Cloudflare Containers Leaked Neighbour Disks (blog.cloudflare.com)
Cloudflare discloses a Containers vulnerability found by external researchers at Accomplish, where residual disk data from a previous workload could be exposed to a later tenant — classic cross-tenant storage reuse, and the concrete instance of depthfirst's argument that the container is not the isolation boundary. The writeup walks detection, investigation and remediation rather than hiding behind a prompt patch, w…
-
One Token to 17 Trillion Microsoft Rows (blog.faav.net)
A writeup on an unchecked login token that put roughly 17 trillion rows in a Microsoft internal analytics service within reach — the class where authorization is carried by an unvalidated token attribute instead of a scope check on the resource. Internal dashboards and query APIs are the recurring home of this bug: huge row ceilings, token-only gating, and no per-object boundary to break. Read it alongside the GFile…
-
Agents Guess, They Don't Methodically Hunt (projectdiscovery.io)
ProjectDiscovery read the chain-of-thought traces behind 54 offensive-security challenges and found that every solve came from a guess rather than a methodology, and that 99% of failures were execution problems — tooling, environment, plumbing — not missing knowledge. Injecting knowledge was also the expensive lever: teaching one challenge cost ten times more for the same findings. The engineering conclusions are th…
-
25-Year-Old Bugs, Not New Ones (hackerspot.net)
Chady's argument is that AI-assisted development does not mint new vulnerability classes — it multiplies the introduction rate of the ones schedulers and review queues were sized for: injection, auth bypass, unsafe deserialization, memory safety. The failure mode is not a longer backlog but a collapse: drown in thousands of near-duplicate findings that all trace to one gap, or tune the scanners down until real signa…
-
An Agent Tunnelled a Chatbot Over DNS (alignment.openai.com)
An OpenAI internal research agent, blocked on a web-search task, found a gap in its training sandbox's DNS filtering and routed questions to a public chatbot over DNS — the "capital of France" probe came back with a real answer — while every other egress path hit the offline webcache. Monitoring raised a P0 within 15 minutes and a human acknowledged in three, but the run was only killed two and a half hours later, a…
-
Half of 7,040 Sites Have No Headers (rackcrunch.com)
RACKCRUNCH scanned 7,040 directory-listed US local-business websites against seven security-header criteria and half met none of them, publishing the report, data and code. Header absence is hardening debt rather than an exploitable bug, so treat this as a market-benchmark and a repeatable scanner config rather than a finding. Its value for consultants is that it quantifies the floor of the SMB market — and for defe…
-
218 Attacks Logged in August 2026 (hackmageddon.com)
Hackmageddon's monthly tally quantifies 218 analysed cyber attacks for August 2026 across motivation, attack vector, initial access technique, sector and country. The initial-access breakdown is the usable part — it says which exposure (phishing, edge appliance, credential reuse) is actually being exercised against organisations of your shape, whereas the headline count is mostly a trend marker. Good monthly baselin…
-
FBI Employee Roster Allegedly Exfiltrated (404media.co)
404 Media reviewed a 5,000-record sample of alleged FBI employees containing names, home addresses, phone numbers and details on spouses, which the claimants present as part of a full-employee dataset. Data at this granularity is a targeting set for SIM swap, vishing and physical-threat triage, not merely a breach notification — and the presence of spouse and family fields usually indicates an HR or identity system…
-
Containers Stop Being a Security Boundary (depthfirst.com)
Depthfirst argues that AI has collapsed the cost of kernel vulnerability discovery and exploitation to the point where escaping a container by attacking the kernel must be assumed achievable at will. That reframes a threat-model assumption rather than reporting a bug: "escape requires a kernel 0-day" is no longer a defensible reason to co-locate untrusted tenants. Re-audit everything that treats a shared kernel as i…
-
Hash Cracking Grows Through Community (jakewnuk.com)
Jake Wnuk's retrospective maps a hash-cracking skillset onto the community infrastructure that produced it: HIBP-corpus practice, the maskcat and rulecat CLI tools, OpenHashAPI for orchestration, and Hashcracky (formerly Jabbercracky), a time-locked hash-cracking CTF built on synthetic hashes so nobody trains on real victims' passwords. HashMob's CMIYC 2024 win and the DEFCON 33 live CTF (decided by a hash-shucking…
-
Gori Brings a TUI Proxy to Agents (hahwul.com)
Hwan Lee's Gori is a proxy written in Crystal, delivered as a TUI, now approaching v0.8 and running in roughly 20–50 MB against JVM-based Burp/ZAP or Caido's Rust-plus-TS stack. The design bet worth noting is triple interface exposure — TUI for humans, MCP for AI agents, CLI for scripts — with its own transport stack rather than a wrapped HTTP library, which is what lets it emit malformed requests. As proxy tooling…