l1ackers

Board

Everything posted, in the order readers decided it deserves. Not a link dump: everything here has been read, used, or broken by somebody, and it says which.

  1. 1
    An auth bypass in the gateway that holds every model key
    +1
    agentic-tooling·2026-09-21·cat ~/news/2026-09-21-litellm-mcp-auth-bypass.md
  2. 2
    A GlobalProtect cookie logged in as admin, and the score moved after
    0
    exploited-in-the-wild·2026-09-21·cat ~/news/2026-09-21-panos-globalprotect-cookie-auth-bypass.md
  3. 3
    An ebtables ARP rewrite could write into a spliced file page
    0
    memory-safety·2026-09-18·cat ~/news/2026-09-18-linux-ebtables-snat-out-of-bounds-write.md
  4. 4
    A Cisco ISE API endpoint never asked who was calling
    0
    auth-bypass·2026-09-16·cat ~/news/2026-09-16-cisco-ise-api-auth-bypass.md
  5. 5
    A Google Pixel flaw is confirmed exploited in the wild
    0
    auth-bypass·2026-09-16·cat ~/news/2026-09-16-google-pixel-kev.md
  6. 6
    A WAF built its session signing key from the install clock
    0
    crypto·2026-09-16·cat ~/news/2026-09-16-safeline-session-key-from-install-clock.md
  7. 7
    A predictable bucket name was taken as proof of ownership
    0
    cloud-misconfig·2026-09-10·cat ~/news/2026-09-10-aws-security-agent-bucket-ownership.md
  8. 8
    A RouterOS flaw let a login raise its own permissions
    0
    exploited-in-the-wild·2026-09-10·cat ~/news/2026-09-10-mikrotik-routeros-privilege-escalation.md
  9. 9
    A UEFI Shell embedded in firmware can be reopened with extra boot entries
    +1
    firmware-embedded·2026-09-08·cat ~/news/2026-09-08-uefi-shell-secure-boot-bypass.md
  10. 10
    A malicious npm package that does nothing at install time
    0
    supply-chain·2026-09-03·cat ~/news/2026-09-03-indexed-btree-npm-runtime-malware.md
  11. 11
    An alternate path walks past NetScaler's authentication
    0
    auth-bypass·2026-08-19·cat ~/news/2026-08-19-netscaler-alternate-path-auth-bypass.md
l1ackers · shell this is a way in, not a requirement
$