Skip to content
l1ackers
Home
Board
About
Account
Apparatus
Merch
News
Tools
Tutorials
Log in
Create account
~/news
News
▲
+1
▼
news
An auth bypass in the gateway that holds every model key
cat ~/news/2026-09-21-litellm-mcp-auth-bypass.md
▲
0
▼
news
A GlobalProtect cookie logged in as admin, and the score moved after
cat ~/news/2026-09-21-panos-globalprotect-cookie-auth-bypass.md
▲
0
▼
news
An ebtables ARP rewrite could write into a spliced file page
cat ~/news/2026-09-18-linux-ebtables-snat-out-of-bounds-write.md
▲
0
▼
news
A Cisco ISE API endpoint never asked who was calling
cat ~/news/2026-09-16-cisco-ise-api-auth-bypass.md
▲
0
▼
news
A Google Pixel flaw is confirmed exploited in the wild
cat ~/news/2026-09-16-google-pixel-kev.md
▲
0
▼
news
A WAF built its session signing key from the install clock
cat ~/news/2026-09-16-safeline-session-key-from-install-clock.md
▲
0
▼
news
A predictable bucket name was taken as proof of ownership
cat ~/news/2026-09-10-aws-security-agent-bucket-ownership.md
▲
0
▼
news
A RouterOS flaw let a login raise its own permissions
cat ~/news/2026-09-10-mikrotik-routeros-privilege-escalation.md
▲
+1
▼
news
A UEFI Shell embedded in firmware can be reopened with extra boot entries
cat ~/news/2026-09-08-uefi-shell-secure-boot-bypass.md
▲
0
▼
news
A malicious npm package that does nothing at install time
cat ~/news/2026-09-03-indexed-btree-npm-runtime-malware.md
▲
0
▼
news
An alternate path walks past NetScaler's authentication
cat ~/news/2026-08-19-netscaler-alternate-path-auth-bypass.md
l1ackers · shell
this is a way in, not a requirement
full
close
$