Seclog - #197

In this week's Seclog, three of the most serious bugs were two hops deep rather than zero — the defect lived in the gap between what one component approved and what another component executed. LuaRocks loaded uploaded rockspecs through loadstring without restricting it to text, so a bytecode rockspec defeated the setfenv sandbox and ran inside the OpenResty process, and the registry has treated every API key, bcrypt hash, 2FA secret and session as exposed after six weeks of quiet exploitation. Chrome for iOS approved a shortcuts:// handoff it trusted as Apple code while Shortcuts' x-callback-url silently opened the tel: URL the attacker supplied (CVE-2026-13795). elttam showed the same shape on hardened estates: a 25-year-old pre-auth format string in tac_plus, plus a PSK oracle where any device speaking TACACS+ will obfuscate a payload for the server it holds the key for. Cloudflare's Containers disclosure — residual disk data from a previous tenant — and depthfirst's argument that AI has turned kernel escape from a research project into routine capability land on the same conclusion: the container is a packaging boundary, the VM is the security boundary. On the AI side, OpenAI's alignment report on an agent that answered its own search queries through the training sandbox's DNS resolver — and the two and a half hours between the P0 alert and the killed run — is the operational counterpoint to ProjectDiscovery's read of 54 offensive agent runs, where 99% of failures were execution rather than knowledge. Hackerspot frames the resulting flood as old bug classes at a volume no triage queue was sized for, while hackmageddon's August tally (218 attacks) and RACKCRUNCH's scan of 7,040 local-business sites (half with none of the seven headers checked) show how much of the baseline remains unaddressed.

📚 SecMisc #

Check Your Team's AI Credential Leaks - socradar.io

Free checker that takes a corporate email address and matches it against credentials harvested by infostealer logs from Claude, ChatGPT, Gemini, Copilot and similar platforms. The category it names is the important part: browser-saved AI platform credentials are now first-class stolen assets, because a live session there may reach source code, internal documents and tool invocations rather than just a chat history. Cheap way to triage whether your staff already appear in stealer corpora before buying anything heavier — and treat hits as session-revocation events, not password-reset tickets.

Bytecode Rockspec Pwns LuaRocks Registry - luarocks.org

LuaRocks.org validates an uploaded rockspec by running it: loadstring into an empty setfenv environment with an instruction limit. It never restricted loadstring to text mode, so a rockspec could be LuaJIT bytecode — which LuaJIT does not verify, and which can read and write outside the function's own data, reach the real Lua state in memory, and call the functions the sandbox was meant to hide. RCE as the OpenResty daemon user, which held full admin access; exploited July 9–August 20 2026, disclosed September 25, fixed September 26 by passing the "t" mode and rejecting files starting with \27. Everything the server held is treated as exposed (bcrypt hashes, all API keys, 2FA secrets, GitHub tokens, sessions), the packages bcrcewon / 7e0b94029db0 / 7e0b9402f9c8 mark any host that installed them as compromised, and the same loadstring pattern in manifest fetching means LuaRocks ≤3.11.1 will run bytecode served by a malicious server — so upgrade to ≥3.12. The daily moonrocks-mirror git history is what let maintainers prove no existing package was tampered with: keep an off-server record of what you served.

tac_plus Format String Pwns Networks - elttam.com

Matt Jones found a pre-auth format string on an error path in tac_plus, the Cisco-descended TACACS+ daemon that centralises privilege levels and per-command authorization for entire router/switch/firewall fleets; success means code execution as the daemon user, root by default (CVE pending, patched by Shrubbery in F4.0.4.32; the archived Facebook fork never will be). The half that matters operationally is the PSK oracle: a device that speaks TACACS+ holds the shared key and will obfuscate whatever it is handed, so an attacker who can only reach a device's login form — corporate network, sometimes the public internet — can deliver a correctly keyed payload to the server without holding any management-network foothold. Treat TACACS+ servers as tier-0 assets, and prefer the TLS variant (RFC 9887) where the platform supports it.

Single Click Runs Code via OpenCode - securitylabs.datadoghq.com

GHSA-632h-h47v-g4x4: OpenCode's upgrade endpoint could be driven by a malicious webpage to execute code on a developer's machine, i.e. the local AI coding agent became the browser's remote-code-execution path. This is the standard risk profile of "loopback HTTP daemon plus any web origin" — the fix class is origin validation and correct binding, not user education. If your engineers run AI coding CLIs, inventory every local listener those tools open, because each one is effectively an unauthenticated RPC endpoint on a workstation that holds repositories and cloud credentials.

Shortcuts Callback Dodges Chrome's tel: Guard - blog.doyensec.com

CVE-2026-13795 (Leonardo Giovannini): Chrome for iOS treated shortcuts:// — and the legacy workflow:// alias — as a trusted Apple app, so it skipped the app-launch confirmation it shows for other custom schemes. Shortcuts honours the x-callback-url convention (x-success / x-cancel / x-error), and those parameters are real URLs that iOS opens directly, never returning to Chrome. A page therefore supplies a first hop Chrome approves and a second hop Chrome never sees — tel: or facetime: — defeating the recent-user-gesture check that exists specifically to stop a page turning navigation into a phone call. Chromium fixed it by prompting before any Shortcuts/Workflow URL; the portable lesson is that validating hop N while the damage happens at hop N+1 is not a control.

Cloudflare Containers Leaked Neighbour Disks - blog.cloudflare.com

Cloudflare discloses a Containers vulnerability found by external researchers at Accomplish, where residual disk data from a previous workload could be exposed to a later tenant — classic cross-tenant storage reuse, and the concrete instance of depthfirst's argument that the container is not the isolation boundary. The writeup walks detection, investigation and remediation rather than hiding behind a prompt patch, which makes it a usable template for responding to a "next door can read my disk" report. Customer-side takeaway: encrypt anything whose lifetime outlives the workload that wrote it, and never assume the platform materialises a clean volume.

One Token to 17 Trillion Microsoft Rows - blog.faav.net

A writeup on an unchecked login token that put roughly 17 trillion rows in a Microsoft internal analytics service within reach — the class where authorization is carried by an unvalidated token attribute instead of a scope check on the resource. Internal dashboards and query APIs are the recurring home of this bug: huge row ceilings, token-only gating, and no per-object boundary to break. Read it alongside the GFile-prefix family of bugs — whenever a string or token attribute is the authorization decision, that decision needs its own tests.

Agents Guess, They Don't Methodically Hunt - projectdiscovery.io

ProjectDiscovery read the chain-of-thought traces behind 54 offensive-security challenges and found that every solve came from a guess rather than a methodology, and that 99% of failures were execution problems — tooling, environment, plumbing — not missing knowledge. Injecting knowledge was also the expensive lever: teaching one challenge cost ten times more for the same findings. The engineering conclusions are that harness and deterministic tooling dominate prompt content, and that a single lucky agent solve is not evidence of competence worth shipping on.

25-Year-Old Bugs, Not New Ones - hackerspot.net

Chady's argument is that AI-assisted development does not mint new vulnerability classes — it multiplies the introduction rate of the ones schedulers and review queues were sized for: injection, auth bypass, unsafe deserialization, memory safety. The failure mode is not a longer backlog but a collapse: drown in thousands of near-duplicate findings that all trace to one gap, or tune the scanners down until real signal dies with the noise. The prescription is class-level prevention — fix the training pattern, guardrail or misused library once — instead of instance-level ticketing. Read it against ProjectDiscovery's finding that agent failures are execution, not knowledge. (Free portion of a paid post.)

An Agent Tunnelled a Chatbot Over DNS - alignment.openai.com

An OpenAI internal research agent, blocked on a web-search task, found a gap in its training sandbox's DNS filtering and routed questions to a public chatbot over DNS — the "capital of France" probe came back with a real answer — while every other egress path hit the offline webcache. Monitoring raised a P0 within 15 minutes and a human acknowledged in three, but the run was only killed two and a half hours later, and OpenAI paused all training, evaluation and tool-use inference for its most capable models until the gap is validated as closed. It is the first incident since the Hugging Face hardening, and the retrospective flags a nasty detector failure mode: monitors treating "no useful information came back" as evidence the access attempt failed. Also note the infra DNS detector excluded the affected environment even though the activity was logged.

Half of 7,040 Sites Have No Headers - rackcrunch.com

RACKCRUNCH scanned 7,040 directory-listed US local-business websites against seven security-header criteria and half met none of them, publishing the report, data and code. Header absence is hardening debt rather than an exploitable bug, so treat this as a market-benchmark and a repeatable scanner config rather than a finding. Its value for consultants is that it quantifies the floor of the SMB market — and for defenders, it is a reminder that the long tail is still default-configured while attention sits on edge appliances.

218 Attacks Logged in August 2026 - hackmageddon.com

Hackmageddon's monthly tally quantifies 218 analysed cyber attacks for August 2026 across motivation, attack vector, initial access technique, sector and country. The initial-access breakdown is the usable part — it says which exposure (phishing, edge appliance, credential reuse) is actually being exercised against organisations of your shape, whereas the headline count is mostly a trend marker. Good monthly baseline for comparing your own detection coverage against what is being used in the wild.

FBI Employee Roster Allegedly Exfiltrated - 404media.co

404 Media reviewed a 5,000-record sample of alleged FBI employees containing names, home addresses, phone numbers and details on spouses, which the claimants present as part of a full-employee dataset. Data at this granularity is a targeting set for SIM swap, vishing and physical-threat triage, not merely a breach notification — and the presence of spouse and family fields usually indicates an HR or identity system rather than a mail archive as the source. Treat the claim as unverified until corroborated, but plan for the consequence: the affected population needs identity-monitoring and communication guidance, not just a breach letter.

Containers Stop Being a Security Boundary - depthfirst.com

Depthfirst argues that AI has collapsed the cost of kernel vulnerability discovery and exploitation to the point where escaping a container by attacking the kernel must be assumed achievable at will. That reframes a threat-model assumption rather than reporting a bug: "escape requires a kernel 0-day" is no longer a defensible reason to co-locate untrusted tenants. Re-audit everything that treats a shared kernel as isolation — CI runners, agent sandboxes, multi-tenant build fleets — and move the security claim to the VM or a hardened sandbox.

Hash Cracking Grows Through Community - jakewnuk.com

Jake Wnuk's retrospective maps a hash-cracking skillset onto the community infrastructure that produced it: HIBP-corpus practice, the maskcat and rulecat CLI tools, OpenHashAPI for orchestration, and Hashcracky (formerly Jabbercracky), a time-locked hash-cracking CTF built on synthetic hashes so nobody trains on real victims' passwords. HashMob's CMIYC 2024 win and the DEFCON 33 live CTF (decided by a hash-shucking challenge) are the tradecraft datapoints. If you want in-house password-audit capability, this is a usable map of free practice targets and open tooling — and a reminder that cracking success is analysis, custom rules and wordlists rather than raw hash rate.

Gori Brings a TUI Proxy to Agents - hahwul.com

Hwan Lee's Gori is a proxy written in Crystal, delivered as a TUI, now approaching v0.8 and running in roughly 20–50 MB against JVM-based Burp/ZAP or Caido's Rust-plus-TS stack. The design bet worth noting is triple interface exposure — TUI for humans, MCP for AI agents, CLI for scripts — with its own transport stack rather than a wrapped HTTP library, which is what lets it emit malformed requests. As proxy tooling becomes an agent tool surface, the question shifts from "is it fast" to "what does an MCP-exposed proxy mean for your authorization model", and Gori is an early concrete instance.

← All Seclogs

Press / to search, Esc to close