❌

Reading view

CVE-2026-6837: Command Injection in Zyxel export-cgi PKCS#12 Export Handling

Technical analysis of CVE-2026-6837, an authenticated command-injection vulnerability in Zyxel’s PKCS#12 certificate export flow.

The post covers the vulnerable execution path, root cause, affected firmware scope, and the firmware-emulation methodology used during analysis.

submitted by /u/TheReedemer69
[link] [comments]
  •  

Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt.

For full disclosure I'm part of the security engineering team at Escape but this finding is something I found really interesting and wanted to share to see!

Our AI pentesting engine Cascade recently got a production AI agent to return its entire system prompt, just by wrapping the ask in a different pretext - framing it as a documentation request instead of an attack.

The agent then handed over everything: full tool list, calling rules, citation format, and session IDs.

What I found really interesting is there's nothing technical that broke because we didn't bypass the guardrail with a cleverer string but because the request just sounded reasonable to the agent.

The Cascade engine, after being refused when asking for the prompt directly, simply adjusted the framing to get the agent to give up the informaiton.

Thought this would be an interesting insight for the community and curious to hear if anyone else has seen similar discoveries in agents in prod?

If you want to see more about the reproduction and write-up you can find it here

submitted by /u/PriorPuzzleheaded880
[link] [comments]
  •  

From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained

  • Auth Bypass.
  • Commands over CAN Bus to internal components.
  • Protection mechanisms disabled and configuration changes.
  • Impact: damage connected devices, permanent DoS to the inverter itself, fines, and even risk to the lives of grid technicians.
  • proprietary communication protocols and file formats.
  • RX architecture reverse engineering.
submitted by /u/_solid_snail
[link] [comments]
  •  

Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10

I registered an expired DMARC reporting domain (gca-emailauth[.]org) for $10. It had been published as the aggregate-reporting address in Global Cyber Alliance DMARC training docs going back to a 2019 bootcamp, and at some point it lapsed.

Shortly after registration, aggregate DMARC reports for 86 domains across 20+ organizations started arriving.

56 belonged to The Toro Company (NYSE-listed), including myturf[.]com, their distributor platform, which sits at p=none. The rest - University of Wisconsin–Stevens Point (14 subdomains), the North Carolina School of Science and Mathematics, Ennis ISD (Texas), Great Prairie AEA (an Iowa education agency serving 35,000 students), two county governments, and several commercial domains.

For most of these it was a second rua address sitting behind a working commercial processor (Proofpoint, in Toro's case). Reports still arrived at the primary.

GCA's engineers later traced it to a former partner who'd held the domain and let it lapse - the dependency was never written down.

As of my last sweep, 65 of the 86 still publish the endpoint. We disclosed to everyone whose reports we were receiving; only 21 domains stopped publishing the endpoint, and almost nobody replied.

After 8 months of owning the domain, we coordinated a transfer back to GCA.

submitted by /u/PlasmaJam
[link] [comments]
  •  
❌