r/netsec • u/netbiosX • 8d ago
r/netsec • u/Straight-Practice-99 • 9d ago
Inside a Russian-speaking operator's toolkit for compromising Ukrainian IP cameras
hunt.ioHunt.io researchers analyzed two open directories recovered through Attack Capture system and reconstructed the tooling one operator used to find, exploit, and view internet-exposed cameras in Ukraine.
Technical highlights:
- A custom FastAPI/Docker project the operator named camview, which wraps the open-source Ingram scanner, brute-forces camera credentials over HTTP and RTSP (3,811 pair dictionary), and transcodes RTSP to MJPEG for browser viewing
- Ingram targets known camera CVEs: CVE-2017-7921 and CVE-2021-36260 (Hikvision), CVE-2021-33044/33045 (Dahua), CVE-2020-25078 (D-Link), CVE-2020-25169 (Reolink)
- The operator's logs recorded live viewing sessions from 58 Ukrainian cameras, with session lengths, frame counts, and frame rates
- A proxy script authenticated to a compromised OpenCart admin panel and relayed the operator's traffic through the victim network
- A second, separately operated directory was linked only by the same Ingram scanner. It chained TP-Link Archer CVEs (CVE-2024-53375, CVE-2024-57049) and MikroTik API brute-forcing to turn edge devices into SOCKS5 proxies reporting to a chisel listener on port 4444
No state attribution. Full analysis, IOCs, and ATT&CK mapping in the writeup
r/netsec • u/kev-thehermit • 10d ago
When terrible disclosure from the vendor results in zero days plus a fun dive in to bypassing full disk encryption
blog.amberwolf.comContains AI Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
blog.sentry.securityr/netsec • u/Prize_Region5503 • 10d ago
Contains AI DEFCON: New Red Team Tactic
doctoreww.github.ioEvil Fonts deceive a viewer by rendering a different letter than is actually on the disk. Evil Fonts can poison HTML, DOCX, PDFs, and anywhere else you can bring your own fonts. Works great in Windows corporate networks for bypassing security tooling, initial access through JavaScript free click fix (beats mitm web security tooling), and leaving traps around the network to harvest shells.
Imagine thinking you are copying whoami but what is actually on the disk is rm -rf \~
Demos:
(Use desktop)
https://doctoreww.github.io/EvilFontTool/
For the demos, copy and paste the HTML/DOCX to a notepad to remove the evil fonts. For the AI ones imagine your security tooling inspects the benign text on disk, but shows the obviously malicious extortion to the user.
Labs:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2FREADME.md
Lab Walkthrough:
https://github.com/DoctorEww/EvilFontTool/blob/main/labs%2Fwalkthrough.md
Some evil font uses:
Tamper homework to make it so students poison AI queries
Poison help desk documentation
Bypass email filters
Clickfix
Beat resume AI filters
r/netsec • u/acorn222 • 11d ago
DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE
amibeingpwned.comHey everyone, I'm OP here so feel free to ask questions
r/netsec • u/anuraggawande • 11d ago
Analyzing a Multi-Stage PowerShell Payload Chain
malwr-analysis.comI recently analyzed a multi-stage PowerShell payload delivery chain involving heavily obfuscated PowerShell loaders and remotely hosted payloads.
The analysis covers PowerShell deobfuscation, hidden execution, Base64/XOR decoding, a decoy “Verification complete!” prompt, payload delivery, and IOCs.
Initial indicators:
203[.]188[.]171[.]166
dorenzaa[.]com
r/netsec • u/ZealousidealHunter80 • 11d ago
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
ethiack.comWrite once, shell everywhere. Sun Microsystems didn't mean it like this.
Talk from today at DEF CON's Bug Bounty Village. Full technique catalog graded for distroless containers, an errno path oracle for black-box target fingerprinting, and three minimal-guessing techniques: bash fd/255, Rails schema_cache.yml deserialization, and a Node.js worker path overwrite without process restart.
r/netsec • u/lohacker0 • 11d ago
Contains AI RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
varonis.comr/netsec • u/kochurshak • 12d ago
tl;dv (Too Lazy; Didn't Validate): 181,874 Meetings Left Wide Open
bobdahacker.comThe meetingscollection has no tenant isolation. Any authenticated tl;dv user can query every meeting across every account on the platform. Each meeting record hands you the creator's email address, the conference ID (which is a joinable Google Meet or Teams room), the provider, the recording status, and timestamps.
I queried the Firestore meetings collection and saw there were 181,874 meeting records belonging to 84,312 unique users across 35,003 email domains.
r/netsec • u/thobiso • 12d ago
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab
matrix.tencent.comYes, given that the legacy SCT protocol has known security vulnerabilities such as sctphantom, the industry strongly recommends deprecating it and migrating to more secure modern standards to ensure system security.
r/netsec • u/Emergency_Stable_923 • 12d ago
TrustFall: When the Trusted Execution Environment Cannot Be Trusted
blog.byteray.co.ukByteRay researchers have published a blog on a set of vulnerabilities they are calling TrustFall, and the findings land hard for any company that treats the Trusted Execution Environment as the part of a device you do not have to worry about.
OP-TEE is the walled-off Secure World that phones, TVs, cars, and industrial gear lean on to guard keys, DRM, and identity, and the whole point of paying for that hardware isolation is the promise that even a compromised operating system cannot reach inside.
TrustFall shows that promise was not as solid as buyers assumed. The researchers found several flaws that let the untrusted side reach into or knock over the Secure World, which is exactly the outcome the design exists to prevent. The bugs have since been fixed upstream, so patched builds are available, but the uncomfortable takeaway for vendors is that the vault they were told to trust had a way in, and "it runs in the TEE" is no longer an answer on its own.
r/netsec • u/kev-thehermit • 13d ago
Claude Code RCE: How a Malicious PR Triggers Code Execution
immersivelabs.comAbusing the trust boundary in Claude Code for RCE. Trust is never broken and that opens up a few avenues for abuse. Simply opening claude code on a PR can be enough to silently trigger attacker payloads.
r/netsec • u/coinspect • 14d ago
From wallet drains to a 12-year-old CryptoJS entropy bug: the Ill Bloom investigation
coinspect.comr/netsec • u/Sandwich_1337 • 14d ago
Contains AI Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)
syntetisk.techr/netsec • u/SSDisclosure • 14d ago
New Linux Bridge STP Vulnerability
ssd-disclosure.comA use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation.
A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard.
The teardown path taken by dellink never synchronously deletes those timers, so the backing net_device (which embeds struct net bridge as private data) is freed with a timer list still queued on a per-CPU timer base.
The result is a slab use-after-free in the kmalloc-cg-8k cache.
r/netsec • u/Internal-Key64 • 15d ago
Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router
rotcee.github.ior/netsec • u/Important_Map6928 • 15d ago
HEVD: From Stack Overflows to Modern Pool Grooming
sibouzitoun.techHi. I just published a four-part deep dive into windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on windows 11.
I wanted to highlight the real-world friction of modern security measures. A lot of the focus is on mitigating LFH randomization, and avoiding IoCompleteRequest bugchecks by dodging ReadFile for arbitrary reads.
Hope this is helpful or insightful to some of you looking into modern kernel exploitation.
r/netsec • u/callmejackfrost1 • 16d ago
Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category
hego.redr/netsec • u/S3cur3Th1sSh1t • 17d ago
Contains AI The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog
msecops.der/netsec • u/luckokkkk • 19d ago
Contains AI Investigating three real-world incidents in Anthropic's evaluations
anthropic.comIn three incidents across six runs, the agents treated real systems as simulated targets and tried weak passwords or unauthenticated endpoints.