g3n3r4l6
-
Meta Open-Sources Zurp Burp Toolkit (bugbounty.meta.com)
Meta released Zurp, a set of Burp Suite capabilities built "for agents from day one" so researchers can drive them manually, via automated agents, or both. The standout is Meta Context, which resolves opaque IDs and GraphQL operations into human-readable meaning so you skip the manual reverse-engineering, plus automatic CSRF-token capture/refresh so replayed requests stop failing on expired tokens, and FBDL access t…
-
Cheap LLMs Underperform on CVSS Scoring (blog.vidocsecurity.com)
Vidoc benchmarked eight models on generating full CVSS v3.1 base vectors across 31 GitHub Security Advisories (744 metric decisions). The cheap classifier Jev hit 80.4% bare and 85% with the CVSS spec in-prompt, but Claude Sonnet 5 reached ~89%, and cheaper LLMs like gpt-5.6-luna beat Jev at only ~1.9x the cost — so the savings are real but too small to justify the accuracy loss inside a vuln-detection pipeline. All…
-
WorstFit: Windows Best-Fit Charset Injection (worst.fit)
WorstFit turns Windows' internal Best-Fit charset conversion — which silently swaps an unmappable Unicode character for a "similar" ANSI one — into path traversal, argument injection, and ultimately RCE. Because the substitution happens in file paths, command lines, and environment variables, apps that shell out through vulnerable CLI tools (pip, composer, git) or runtimes like PHP-CGI, cURL, and Office inherit the…
-
Prompt Injection Escalates SQL Copilot to Sysadmin (embracethered.com)
CVE-2026-65669: SSMS's SQL Copilot runs queries with the connected user's DB privileges and enforced "read-only" via a regex blocklist (LocalSqlExecutionAccessChecker) plus system-prompt instructions — neither a real boundary. Bypasses include DECLARE @p sysname='spwho'; EXEC @p and spexecutesql to regain write, then xpdirtree/RestoreVerifyBackupFile for exfiltration. The escalation: a low-priv database owner plants…
-
GPT Recovers 20-Year-Old Encrypted Disk (eurekaengine.co.uk)
A researcher who lost a dm-crypt keyfile two decades ago handed the disk image to GPT 5.6, which recovered it not by cryptanalysis but by forensics: it read unencrypted system files to learn the disk used plain dm-crypt (no LUKS header to validate a key against), estimated the deleted 80-byte keyfile's size, scanned raw blocks near its original location, and validated each candidate in milliseconds by decrypting a s…
-
Unauthenticated SQL to RCE in JCTables (vulncheck.com)
CVE-2026-76570 in the JCTables Joomla component (free edition ≤1.10.31.2) chains two flaws into no-login RCE: unauthenticated DB-modifying endpoints plus a broken escape helper that treats quote-wrapped input as already-escaped instead of parameterizing. An attacker reads arbitrary tables via getdatarow, extracts the random table prefix with boolean-blind injection, then writes through updatecell to overwrite the ad…
g1thub1
-
macOS-TBM: Trust Boundary Attack-Surface Mapper (github.com)
macOS-TBM (Trust Boundary Mapper) correlates launchd plists, Mach-O structure, code signatures, entitlements, and Mach/XPC signals into a ranked review queue, helping researchers decide which privileged system services deserve a closer look. It ships evidence-backed findings (not just flags), HTML/terminal/JSON/graph outputs, and optional Radare2 enrichment for deeper binary inspection. Still research-beta, so treat…