Normal view
-
/r/netsec - Information Security News & Discussion
- Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption
Keeping Secrets Out of Logs
-
/r/netsec - Information Security News & Discussion
- Unauthenticated RCE as QSECOFR via IBM i Management Central β port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier)
-
/r/netsec - Information Security News & Discussion
- System Over Model, Tested: Reproducing Mythosβs FreeBSD Find on Local Open-Weight Models
-
/r/netsec - Information Security News & Discussion
- Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
-
/r/netsec - Information Security News & Discussion
- Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
-
/r/netsec - Information Security News & Discussion
- Enter the WasmForge: Compiling Sliver into WebAssembly
Enter the WasmForge: Compiling Sliver into WebAssembly
WebAssembly is traditionally thought of as a mechanism to run compiled code inside your browser, but rarely as a mechanism to run full application code directly on host. We hacked up the Wazero implementation of WebAssembly and modified it to transform existing GoLang security tooling into analyst resistant malware. This isn't just a toy implementation either, we've implemented every major host API such that we can compile a full Sliver binary to run on MacOS or Windows.
This blog post covers the implementation details behind our Go->WASM compilation process and sets up our final blog post (coming next week) where we'll discuss a similar C#->WASM compilation pipeline. The tooling described in this blog post will be open sourced next week. Will be happy to answer any questions about this in the comments!
[link] [comments]
Season VI of the US Games launches TOMORROW!
The speaker lineup is set, and the CTF challenges are ready...
Register to join us for 10 days of programming designed to learn something new, test your skills, and network with the US Cyber Games community!
This virtual series of events is FREE to attend, and open to everyone -- regardless of age, skill level, professional background, etc. June 4th-14th
Virtual Season VI, US Cyber Open Series of Events:
- Kick-Off Celebration: June 4th
- Beginner's Game Room CTF: June 5th-14th
- Cyber Rush Week: June 8th-11th
- Competitive CTF: June 8th-14th
[link] [comments]
-
/r/netsec - Information Security News & Discussion
- EU CRA mandatory vulnerability reporting enters into force September 11, 2026 β what the 24-hour obligation requires
Interesting- What LLM vuln research looks like
-
/r/netsec - Information Security News & Discussion
- Hacking your PC using your speaker without ever touching it
Hacking your PC using your speaker without ever touching it
-
/r/netsec - Information Security News & Discussion
- Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing
Golang code review notes II - elttam
1-Click GitHub Token Stealing via a VSCode Bug
-
/r/netsec - Information Security News & Discussion
- Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
NuGet Code Execution As A Service
-
/r/netsec - Information Security News & Discussion
- Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
Came across an article, product like phpBB still has some potential flaws.
[link] [comments]
r/netsec monthly discussion & tool thread
Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.
Rules & Guidelines
- Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
- Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
- If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
- Avoid use of memes. If you have something to say, say it with real words.
- All discussions and questions should directly relate to netsec.
- No tech support is to be requested or provided on r/netsec.
As always, the content & discussion guidelines should also be observed on r/netsec.
Feedback
Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.
[link] [comments]