Attacks & Vulnerabilities
|
A Realistic Code Execution Exploit Chain in OpenBao and Vault (11 minute read)
ControlPlane chained four OpenBao flaws into an unauthenticated-to-RCE exploit that forges a SPIFFE provisioner certificate via an ACME URI SAN bypass, hijacks an admin role through case-insensitive ACL paths, and crosses namespaces to restore a malicious Raft snapshot. The final step executes any pre-existing binary whose SHA-256 the attacker can guess, even on read-only images and auto-unseal nodes, and Vault Community Edition remains unpatched after IBM declined a mutual disclosure agreement. Upgrade to OpenBao v2.6.3 or v2.7.0, or, as a stopgap, remove plugin_directory and enforce ACME EAB via BAO_DISABLE_PUBLIC_ACME.
|
New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses (4 minute read)
Researchers from VUSec and Scuola Superiore Sant'Anna disclosed Branch Target Reuse (BTR), a Spectre-v2 variant that reuses stale indirect branch prediction entries in JIT engines after code is freed and reallocated. Proof-of-concept exploits against the Linux cBPF JIT recover the root password hash in minutes on patched Intel systems with default protections. Mitigations are merged in the Linux kernel (CVE-2026-64507, CVE-2026-64508). Mozilla is prioritizing site isolation over IBPB-based fixes.
|
|
Pwnd Blaster: Hacking your PC using your speaker without ever touching it (6 minute read)
The Creative Sound Blaster Katana V2X soundbar accepts unauthenticated Bluetooth connections and exposes its proprietary CTP control protocol over BLE. Firmware updates also use CTP and verify only a trivial SHA-256 checksum, allowing an attacker within ~15 meters to install custom firmware without pairing or physical access. The modified firmware adds a full USB keyboard HID descriptor and repurposes an existing diagnostic task to type commands after boot, turning the speaker into a remote BadUSB device. A proof-of-concept payload waits ~20 seconds for USB to initialize, then types echo pwned and presses Enter on the connected PC. Bluetooth stays enabled in sleep mode with no user-accessible toggle. Creative initially declined to classify this as a vulnerability.
|
Stack Unwinding Can Lead to Leakless Code Execution (7 minute read)
This post describes a code execution technique in which an exploit abuses POSIX “cancellation points” to eventually execute code. This works by executing DWARF bytecode to mangle the .eh_frame_hdr data that is used when unwinding the stack. While this technique was discovered in the context of CTFs, it has applications outside of CTFs.
|
A GitHub token was stolen. Now what? (11 minute read)
Invictus traced a run of 2026 incidents to stolen classic GitHub PATs, typically lifted from developer endpoints by info-stealers and used to map every reachable repository through bursts of /repositories/{id}/readme API calls before cloning. In one case, a single token exposed 1,100+ potential secrets across 300+ repos, and validating and rotating them took 30+ people over a week. Since GitHub keeps Git clone events for only seven days and api.request events require Enterprise audit log streaming, responders should scope to the token's full reach wherever logs are missing, then migrate off classic PATs to fine-grained tokens, GitHub Apps, or OIDC.
|
|
Reco (Product Launch)
Reco maps active software agents, their identities, permissions, data access, systems, sessions, API connections, tools, workflows, and employee applications. Teams can revoke excessive permissions, disable risky integrations, and enforce access policies.
|
OpenShell (GitHub Repo)
OpenShell is NVIDIA's sandboxed runtime for autonomous AI agents, enforcing per-agent policy on file access, syscalls, and network connections at the kernel level. Its standout feature is formal verification of policy changes, which flags risky new access, like credentialed calls to a new host, and holds it for human review. Agents never see real secrets, since credentials are injected only into requests bound for approved endpoints.
|
cgg (GitHub Repo)
cgg (Call Graph Generator) is a tool that generates Mermaid diagrams of call graphs directly from source code.
|
|
PixelLeak: How AI Agents Exposed Developer Screenshots from Leading Tech Companies (5 minute read)
Glow Labs found 13,000 internal screenshots posted to public GitHub repos by AI coding agents at 300+ orgs. Agents bypassed GitHub's CLI image limits by creating public repos or using gitshot, leaking billing screens, treasury consoles, and unreleased features. Most images lived in developers' personal accounts, evading org scanners. To prevent this, audit personal repositories and gists, restrict agent auto‑approval, and add runtime hooks to block pushes to public or non‑org repos.
|
Agencies Withheld Records Needed to Verify DOGE Data Safeguards (2 minute read)
During the Government Accountability Office (GAO)'s review of DOGE's access to sensitive data, six agencies could not or refused to provide sufficient records. The SEC and NOAA disputed the GAO's authority to conduct the investigation and refused to cooperate. The VA and SBA also did not provide records but didn't cite a reason for doing so. At the CFPB, access was granted to 19 systems, with one DOGE team member being able to view, modify, and delete information in the bureau's primary human resources system. At the Department of Education, one DOGE member received limited access to two federal student aid systems and an admin account on the department's network.
|
GLM-5.3 and the Spread of Advanced Cyber Capabilities (5 minute read)
Anthropic posted a blog detailing the threat posed by GLM-5.3 as a cyber-capable, open-source model. Anthropic stated that GLM-5.3 performed comparably to Mythos Preview in ExploitBench, an internal binary exploitation benchmark, and a test of open-ended offensive cyber capabilities when paired with a human expert. Anthropic also reports that a deceptive prompt subverted GLM-5.3's guardrails 64% of the time, prefilling the model's thinking tokens subverted guardrails 92% of the time, and abliterated versions of the model do not contain these ls. guardrails.
|
|
Love TLDR? Tell your friends and get rewards! |
|
Share your referral link below with friends to get free TLDR swag!
|
|
|
| Track your referrals here. |
|
|
|
0 Comments