Tag
This post releases a new universal Ruby deserialization gadget chain that turns a single Marshal.load into command execution on Ruby 4.0.6, working unchanged back to Ruby 3.3, built from both new and repurposed gadgets.
A homelab owner details how their Forgejo instance was hacked via CVE-2026-60004, an RCE in Gitea, and shares the postmortem including mistakes made and exploit analysis.
Kimi K3, an AI model, is claimed to autonomously find a zero-day vulnerability and achieve full RCE in 27 minutes with a single prompt, no human reverse-engineering.
A proof-of-concept exploit repository demonstrates remote code execution vulnerabilities in several Redis versions (6.2.22 to 8.8.1) via stream NACK double free and RedisBloom module bugs. The exploits bypass recent patches and require specific conditions.
Using the fastjson 0day to test LLM vulnerability discovery capabilities, found Claude and Doubao performed outstandingly.
Security researcher uses GPT5.6 Sol Ultra to discover a WordPress pre-auth RCE vulnerability, potentially worth $500k to exploit brokers, demonstrating AI's capability in cybersecurity research.
A security researcher discovered an unauthenticated remote code execution vulnerability in Motorola's MR2600 router, allowing attackers to upload and flash malicious firmware without authentication.
This article announces the first browser-to-kernel full-chain remote code execution exploit on Android 17, with source code to be released soon.
A discussion about the lack of vetting for MCP servers before installation, highlighting a study that found 5.5% tool-poisoned and 14.4% with known bugs, plus a systemic RCE in the MCP SDK.
A researcher discovered a remote code execution vulnerability in AMD's AutoUpdate software due to insecure HTTP download links and lack of certificate validation. AMD initially dismissed it as out of scope but later agreed to issue a CVE and fix after public attention.
CVE-2026-52884 describes a zero-click remote code execution vulnerability in Notepad++ via path traversal, affecting users on Windows.
A researcher discovered a 1-click remote code execution vulnerability in PewDiePie's Odysseus Chat and is submitting a PR to fix it.
A security researcher discovered CVE-2026-46529, a 10-year-old remote code execution vulnerability in Linux PDF viewers XReader, Evince, and Atril, caused by insufficient argument quoting when spawning child processes to open remote document links.
XBOW disclosed CVE-2026-45185, a critical unauthenticated remote code execution vulnerability in Exim mail servers caused by a use-after-free error in TLS handling. The article details the technical exploit development and the role of AI models in the discovery process.
Critical security vulnerabilities in Ollama, including a memory leak exploit dubbed 'Bleeding Llama' and a Windows RCE flaw, have been disclosed, prompting urgent upgrades for users.