rce

Tag

Cards List
#rce

Ruby 4.0 Universal RCE Deserialization Gadget Chain

Hacker News Top · 2026-08-14 Cached

This post releases a new universal Ruby deserialization gadget chain that turns a single Marshal.load into command execution on Ruby 4.0.6, working unchanged back to Ruby 3.3, built from both new and repurposed gadgets.

0 favorites 0 likes
#rce

My Homelab Got Hacked - A Postmortem

Lobsters Hottest · 2026-08-12 Cached

A homelab owner details how their Forgejo instance was hacked via CVE-2026-60004, an RCE in Gitea, and shares the postmortem including mistakes made and exploit analysis.

0 favorites 0 likes
#rce

@0x0SojalSec: Kimi K3 can found a 0-day in 27 minutes, One simple prompt then Full RCE & it fully exploited , No human reverse-engine…

X AI KOLs Timeline · 2026-07-23 Cached

Kimi K3, an AI model, is claimed to autonomously find a zero-day vulnerability and achieve full RCE in 27 minutes with a single prompt, no human reverse-engineering.

0 favorites 0 likes
#rce

Kimi K3 exploited the latest Redis server

Hacker News Top · 2026-07-23 Cached

A proof-of-concept exploit repository demonstrates remote code execution vulnerabilities in several Redis versions (6.2.22 to 8.8.1) via stream NACK double free and RedisBloom module bugs. The exploits bypass recent patches and require specific conditions.

0 favorites 0 likes
#rce

@seclink: This fastjson 0day can be used to test the vulnerability discovery capabilities of LLMs. Without providing explicit information, only setting the goal (achieving a gadget-free RCE vulnerability), see how many steps the LLM takes to discover it and verify itself. Practice has shown: Claude indeed…

X AI KOLs Following · 2026-07-21 Cached

Using the fastjson 0day to test LLM vulnerability discovery capabilities, found Claude and Doubao performed outstandingly.

0 favorites 0 likes
#rce

Exploit brokers pay $500k for WordPress RCEs. I found one with GPT5.6 and $25

Hacker News Top · 2026-07-20 Cached

Security researcher uses GPT5.6 Sol Ultra to discover a WordPress pre-auth RCE vulnerability, potentially worth $500k to exploit brokers, demonstrating AI's capability in cybersecurity research.

0 favorites 0 likes
#rce

Unauthenticated RCE in Motorola's MR2600 Router

Hacker News Top · 2026-07-12 Cached

A security researcher discovered an unauthenticated remote code execution vulnerability in Motorola's MR2600 router, allowing attackers to upload and flash malicious firmware without authentication.

0 favorites 0 likes
#rce

Elevating Privileges from Firefox to Android Root

Hacker News Top · 2026-07-03 Cached

This article announces the first browser-to-kernel full-chain remote code execution exploit on Android 17, with source code to be released soon.

0 favorites 0 likes
#rce

How are you actually vetting MCP servers before you install them?

Reddit r/AI_Agents · 2026-06-21

A discussion about the lack of vetting for MCP servers before installation, highlighting a study that found 5.5% tool-poisoned and 14.4% with known bugs, plus a systemic RCE in the MCP SDK.

0 favorites 0 likes
#rce

The RCE that AMD wouldn't fix

Hacker News Top · 2026-06-11 Cached

A researcher discovered a remote code execution vulnerability in AMD's AutoUpdate software due to insecure HTTP download links and lack of certificate validation. AMD initially dismissed it as out of scope but later agreed to issue a CVE and fix after public attention.

0 favorites 0 likes
#rce

Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)

Hacker News Top · 2026-06-10 Cached

CVE-2026-52884 describes a zero-click remote code execution vulnerability in Notepad++ via path traversal, affecting users on Windows.

0 favorites 0 likes
#rce

Just found a 1-click RCE in pewdiepie's Odysseus Chat

Reddit r/LocalLLaMA · 2026-06-01

A researcher discovered a 1-click remote code execution vulnerability in PewDiePie's Odysseus Chat and is submitting a PR to fix it.

0 favorites 0 likes
#rce

CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril)

Lobsters Hottest · 2026-05-22 Cached

A security researcher discovered CVE-2026-46529, a 10-year-old remote code execution vulnerability in Linux PDF viewers XReader, Evince, and Atril, caused by insufficient argument quoting when spawning child processes to open remote document links.

0 favorites 0 likes
#rce

Dead.Letter (CVE-2026-45185) – How XBOW found an unauthenticated RCE on Exim

Hacker News Top · 2026-05-12 Cached

XBOW disclosed CVE-2026-45185, a critical unauthenticated remote code execution vulnerability in Exim mail servers caused by a use-after-free error in TLS handling. The article details the technical exploit development and the role of AI models in the discovery process.

0 favorites 0 likes
#rce

Critical Ollama Bugs Expose AI Servers to Memory Leaks and Windows RCE

Reddit r/ArtificialInteligence · 2026-05-11 Cached

Critical security vulnerabilities in Ollama, including a memory leak exploit dubbed 'Bleeding Llama' and a Windows RCE flaw, have been disclosed, prompting urgent upgrades for users.

0 favorites 0 likes
← Back to home

Submit Feedback