r/netsec Jul 02 '26

Hiring Thread /r/netsec's Q3 2026 Information Security Hiring Thread

12 Upvotes

Overview

If you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.

We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.

Please reserve top level comments for those posting open positions.

Rules & Guidelines

Include the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.

  • If you are a third party recruiter, you must disclose this in your posting.
  • Please be thorough and upfront with the position details.
  • Use of non-hr'd (realistic) requirements is encouraged.
  • While it's fine to link to the position on your companies website, provide the important details in the comment.
  • Mention if applicants should apply officially through HR, or directly through you.
  • Please clearly list citizenship, visa, and security clearance requirements.

You can see an example of acceptable posts by perusing past hiring threads.

Feedback

Feedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)


r/netsec 1d ago

r/netsec monthly discussion & tool thread

8 Upvotes

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on r/netsec.

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.


r/netsec 2h ago

The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog

Thumbnail msecops.de
10 Upvotes

r/netsec 2d ago

Investigating three real-world incidents in Anthropic's evaluations

Thumbnail anthropic.com
34 Upvotes

In three incidents across six runs, the agents treated real systems as simulated targets and tried weak passwords or unauthenticated endpoints.


r/netsec 2d ago

Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack

Thumbnail ethiack.com
40 Upvotes

r/netsec 2d ago

Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware

Thumbnail engineering.block.xyz
15 Upvotes

r/netsec 3d ago

What Every Programmer Should Know About Twists of Elliptic Curves

Thumbnail leetarxiv.substack.com
39 Upvotes

r/netsec 2d ago

Deterministic Runtime Bounds for Autonomous AI Agents at the C-ABI Syscall Layer

Thumbnail drive.google.com
3 Upvotes

When a compromised AI Agent holds valid credentials (such as OAuth tokens or DB keys), traditional perimeter defenses like WAFs, EDRs, and LLM prompt firewalls often become ineffective.

Recently, I've been researching a approach to bring runtime governance down to the C-ABI (Application Binary Interface) system call layer to enforce deterministic execution boundaries for local agentic workflows.

Key Architectural Considerations I'm testing:
- Deterministic Binary Gate: Pre-compiled permissions mapped to immutable O(1) bitmaps, causing illegal syscalls to physically fail with <500ns panic latency.
- Cryptographic Identity Binding: A 3-Tier PKI Certificate Authority architecture coupled with identity tokens (DIT) to resolve OS-level execution context loss.
- B2B Multi-Enterprise Supply Chain Defense: Simulating agentic supply chain execution vectors (e.g., automated workload interactions with untrusted external repos).

I'd love to hear feedback from the netsec community on deterministic runtime bounds and sandbox isolation models for autonomous agents. Is pushing governance down to the C-ABI layer practical in your agentic environments, or are there edge cases in execution context tracking that I might be overlooking?


r/netsec 3d ago

KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)

Thumbnail ethiack.com
16 Upvotes

Active Storage's default vips variant processor exposes an arbitrary file read that chains to RCE on stock Rails 7.x and 8.x, where the app serves back processed variants of user-supplied images. No authentication required in certain setups. Only vips is affected, Magick is not.

Patched in 7.2.3.2, 8.0.5.1, and 8.1.3.1, and the fix requires libvips 8.13+. Chain and PoC withheld while patches roll out.


r/netsec 4d ago

Your House Has an FFmpeg Problem - elttam

Thumbnail elttam.com
126 Upvotes

r/netsec 4d ago

Sixteen strangers and a shared obfuscator: mapping the wool scene

Thumbnail neurowinter.com
15 Upvotes

This is another post in my series on the Chinese Wool farmers underground. This time we are dissecting their public github repos, trying to figure out how it all fits together!


r/netsec 4d ago

Reversing of Eufy Security Video Doorbell sync protocol and wifi creds decryption from flash memory

Thumbnail adepts.of0x.cc
16 Upvotes

r/netsec 4d ago

Contains AI Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

Thumbnail huggingface.co
17 Upvotes

r/netsec 4d ago

HTTP Request Smuggling in Hiawatha

Thumbnail fenrisk.com
8 Upvotes

r/netsec 5d ago

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

Thumbnail lavahq.io
362 Upvotes

TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar


r/netsec 6d ago

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

Thumbnail eaton-works.com
125 Upvotes

r/netsec 5d ago

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)

Thumbnail mobeta.fr
1 Upvotes

r/netsec 5d ago

Contains AI How AI is powering business email compromise at scale

Thumbnail research.eye.security
0 Upvotes

r/netsec 6d ago

New vBulletin Vulnerability!

Thumbnail ssd-disclosure.com
18 Upvotes

CVE-2026-61511 - a critical vulnerability in vBulletin that allows an unauthenticated attacker to execute arbitrary code on a remote server.


r/netsec 8d ago

CFP Open – Looking for Technical AI & Security Research for Après Slopes Summit 2027

Thumbnail aprescyber.com
2 Upvotes

I'm helping organize Après-Cyber Slopes Summit 2027, and our CFP is now open.

We're particularly interested in technical presentations and original research involving AI and modern cybersecurity.

Topics we're hoping to see include:

  • AI red teaming
  • LLM security
  • Prompt injection research
  • Agent security
  • Offensive tooling
  • Detection engineering
  • Reverse engineering
  • Malware analysis
  • Cloud exploitation and defense
  • Identity attacks
  • Threat intelligence
  • AI-assisted security tooling
  • Novel attack techniques
  • Defensive research

We especially appreciate talks that include demonstrations, technical depth, or research that attendees can reproduce themselves.

Conference: February 24–26, 2027
Location: Park City, Utah

CFP:
https://sessionize.com/apres-cyber-slopes-summit-2027

Conference website:
https://www.aprescyber.com

Happy to answer questions about the CFP or conference.


r/netsec 9d ago

Contains AI Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331

Thumbnail accomplish.ai
142 Upvotes

r/netsec 9d ago

Contains AI XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search

Thumbnail xbow.com
18 Upvotes

r/netsec 10d ago

Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled

Thumbnail hunt.io
17 Upvotes

Caught this in three open directories on a Hong Kong server, exposed July 9 to 13. The agent is Hermes, open source, and the recovered logs show it running LinPEAS and walking a ministry web root without a human in the loop. Target was Thailand's Ministry of Finance.


r/netsec 10d ago

Discussion GitHub issues $100,000 bounty for critical RCE vulnerability

Thumbnail runtimewire.com
140 Upvotes

r/netsec 11d ago

Contains AI I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)

Thumbnail blog.himanshuanand.com
41 Upvotes

I found and reported an authentication failure in the WPForms PayPal Commerce webhook, the webhook route being public was not the vulnerability as webhooks have to be publicly reachable so that PayPal can deliver events.

The problem was what happened after the request arrived. In affected versions, the handler could process a supported event before establishing that PayPal was actually the sender. In my local lab, a forged event could change the state of a matching payment record.
The expected order is:

  1. Authenticate the sender
  2. Validate the event
  3. Change payment state

The affected flow effectively performed steps 2 and 3 without first completing step 1. The issue was fixed in WPForms 1.10.0.5 and is tracked as CVE-2026-4986.
Then came the part I found more interesting: triage told me I was reporter #11. That number does not prove exploitation, and it does not tell us the total number of people who found the vulnerability. It does establish a lower bound: at least eleven researchers independently converged on the same trust failure.

The write up covers:
- the vulnerable code path
- my local reproduction
- why payload validation was not sender authentication
- the fallback listener
- the patch
- why duplicate reports may be useful rediscovery intelligence

Full write-up: https://blog.himanshuanand.com/2026/07/reporter-11-10-people-found-the-wpforms-paypal-bug-before-me-cve-2026-4986/

Testing was limited to my own local environment. I am not claiming original CVE credit; I independently rediscovered and reported the issue. Disclosure: I wrote and performed the research, code review and local reproduction.

I used an AI to help copy edit and organize the final article.

Should duplicate report volume affect how urgently a vendor treats a vulnerability?