##VulnerabilityResearch
RE: https://infosec.exchange/@hnsec/116923239649243702

My #semgrep C/C++ ruleset is ready for prime time again!

Grab it before our new robot overlords take over the field of #vulnerabilityresearch entirely 🤖
Our Technical Director @raptor just shipped v2.0.0 of his #semgrep C/C++ ruleset — now officially included in the @semgrep registry.

Marco built this ruleset back in 2022 to speed up C/C++ #vulnerabilityresearch, and it's since become a go-to reference, featured in several guides and toolkits […]
Original post on infosec.exchange
infosec.exchange
July 15, 2026 at 9:18 AM
Big win at #DefCon33! Qualys Threat Research Unit (TRU) takes home Epic Achievement + Best RCE at the #PwnieAwards for:
🔹 CVE-2024-6387 (regreSSHion) — 1st pre-auth RCE in OpenSSH in 20 yrs
🔹 CVE-2025-26465 — MITM attack on OpenSSH client

#vulnerabilityresearch #Qualys #TRU
August 9, 2025 at 11:38 PM
I've just pushed to crates.io updated releases of my #vulnerabilityresearch tools written in #rust, compatible with Hex-Rays IDA Pro 9.1 and upgraded to the Rust 2024 Edition.

Thanks to @xorpse and Yegor Vasilenko at @binarly_io for the immediate update of their idalib Rust bindings!

For more […]
Original post on infosec.exchange
infosec.exchange
March 3, 2025 at 9:19 AM
These posts are mainly focused on topics of #ThreatResearch, #VulnerabilityResearch , #DetectionEngineering , getting people comfortable with #Snort and #Suricata, and #Homelab

Enjoy!
April 25, 2026 at 9:39 PM
#BSidesLuxembourg2026 recording: "When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax" by Adrian Denkiewicz https://infosec.exchange/@adenkiewicz

Find all the talks from this track/village here […]

[Original post on infosec.exchange]
September 24, 2026 at 6:35 AM
PrimSynth: An Agentic Approach to Discover, Validate, and Synthesize Exploit Primitives for Linux Kernel Vulnerabilities
Linux kernel vulnerabilities are critical to downstream systems. Despite extensive research on automated kernel exploitation, a fundamental challenge remains the conceptual gap between abstract exploit strategies and concrete technical operations. To fill this gap, this paper introduces a systematic characterization that formalizes six classes of exploit primitives from logical capability to validatable effect. Then, an extended exploit strategy representation is proposed, which couples primitive upgrading strategies with primitive path code synthesis rules governing object constraints, temporal sequencing, environment prerequisites, and validation constraints. Building upon this foundation, this paper presents \textsc{PrimSynth}, a multi-agent framework that encapsulates these representations through coordinated agents to discover, validate, and synthesize exploit primitives for memory corruption vulnerabilities in the Linux kernel. These agents operate in an iterative closed loop until valid primitives are found, leveraging validation signals as evidence of exploitable state transitions to ground primitive synthesis decisions. An automated method for extracting and validating primitives is also proposed based on vulnerability-directed execution and a rebootable validation environment. \textsc{PrimSynth} is evaluated on 16 real-world Linux kernel CVEs spanning 5 vulnerability types. Experimental results show that PrimSynth achieves reliable primitive extraction, maintaining a 100% primitive match rate. For primitive synthesis, PrimSynth successfully synthesizes multi-primitive exploitation chains with 82.4% strategy synthesis rate (SSR) when the public PoC is available and a 61.3% SSR without the guidance of primitive hypotheses.
arxiv.org
September 3, 2026 at 2:36 PM
I’ve indexed 18,220 software security histories across WordPress core, plugins, and themes.

www.3zerodigital.com/research/wor...

My Book:

www.mdpabel.com/books/wordpr...

#WordPressSecurity #WordPress #VulnerabilityResearch
August 29, 2026 at 7:47 AM
Join the Operation: Maximum Impact Challenge! Earn 2X bounty rewards for vulnerabilities in popular software. Bounties up to $31,200. Submit now and earn big! #BugBounty #VulnerabilityResearch https://www.wordfence.com/blog/2025/09/wordfence-intelligence-weekly-wordpress-vulnerability-report-septem…
www.wordfence.com
September 21, 2025 at 10:44 PM
📰 PortSwigger: Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research PentestHQ #AI #CyberSecurity #EthicalHacking #VulnerabilityResearch #AttackTechniques
Can AI invent new attack techniques? New research from James Kettle and PortSwigger Research
We already know AI can find vulnerabilities. James Kettle, PortSwigger's Director of Research, wanted to answer a harder question: can an autonomous system invent genuinely new attack techniques? To f
portswigger.net
August 12, 2026 at 10:47 AM
🔍Webinar Highlight: Automating PoC Generation with AI
In this clip, we showcase a tool that automates PoC creation, from researching CVEs to generating exploits.

Watch to see it in action! 🔗 youtu.be/_-euI7fCzy0

#CyberSecurity #AI #VulnerabilityResearch #Automation
🔍Webinar Highlight: Automating PoC Generation with AI
YouTube video by Ostorlab Academy
youtu.be
March 24, 2025 at 4:01 PM
The new Offensive Security Research Hub on Pentest-Tools.com (led by Matei Badanoiu) shares the full discovery path: from anomalous behavior to validated vulnerability.

Original research for the hacker community: pentest-tools.com/research

#vulnerabilityresearch #infosec
pentest-tools.com
March 9, 2026 at 3:39 PM
NetSPI Principal Security Consultant Jason Juntunen recently published findings on a Remote Code Execution vulnerability in SailPoint's IQService component.

👉 Read the full technical breakdown: ow.ly/GbT150WmgRg

#proactivesecurity #VulnerabilityResearch
Set Sail: Remote Code Execution in SailPoint IQService via Default Encryption Key
NetSPI discovered a remote code execution vulnerability in SailPoint IQService using default encryption keys. Exploit details, discovery methods, and remediation guidance included.
www.netspi.com
July 8, 2025 at 1:02 PM
Our Technical Director @raptor just shipped v2.0.0 of his #semgrep C/C++ ruleset — now officially included in the @semgrep registry.

Marco built this ruleset back in 2022 to speed up C/C++ #vulnerabilityresearch, and it's since become a go-to reference, featured in several guides and toolkits […]
Original post on infosec.exchange
infosec.exchange
July 15, 2026 at 9:17 AM
Discover the latest insights from vulnerability research on AirDrop and Quick Share. Explore how these popular file-sharing protocols can be improved for better security. Stay informed and protect your data! #Cybersecurity #VulnerabilityResearch

https://arxiv.org/abs/2606.26967
August 17, 2026 at 6:03 PM
Just shipped updates for rhabdomancer, haruspex, and augur. Now compatible with @HexRaysSA IDA 9.3 and @xorpse's idalib-rs 8.0.

These headless #ida plugins are built for #vulnerabilityresearch workflows where you want IDA's power without the GUI. This release brings a bunch of small […]
Original post on infosec.exchange
infosec.exchange
February 20, 2026 at 8:57 AM
My idalib-based "vulnerability divination" tool suite is finally available in the official Hex-Rays Plugins & Apps repository! 🦀

https://plugins.hex-rays.com/search-results?search_term=0xdea

#idapro #idalib #vulnerabilityresearch
#reverseengineering
Hex-Rays - Plugins & Apps
Your description here
plugins.hex-rays.com
March 27, 2025 at 9:01 AM
August 16, 2026 at 6:16 AM
August 14, 2026 at 12:27 AM
August 9, 2026 at 4:16 AM
July 30, 2026 at 6:44 AM
July 3, 2026 at 11:17 AM
June 27, 2026 at 8:16 PM
𝑴𝒊𝒔𝒂𝒅𝒗𝒆𝒏𝒕𝒖𝒓𝒆𝒔 𝒘𝒊𝒕𝒉 𝑪𝒐𝒑𝒊𝒍𝒐𝒕+: 𝑨𝒕𝒕𝒂𝒄𝒌𝒊𝒏𝒈 𝒂𝒏𝒅 𝑬𝒙𝒑𝒍𝒐𝒊𝒕𝒊𝒏𝒈 𝑾𝒊𝒏𝒅𝒐𝒘𝒔 𝑵𝑷𝑼 𝑫𝒓𝒊𝒗𝒆𝒓𝒔
📑 Slides (PDF) – i.blackhat.com/Asia-25/Asia...
𝐹𝑒𝑒𝑙 𝑓𝑟𝑒𝑒 𝑡𝑜 𝑠ℎ𝑎𝑟𝑒 𝑡ℎ𝑖𝑠 𝑤𝑖𝑡ℎ 𝑦𝑜𝑢𝑟 𝑐𝑜𝑙𝑙𝑒𝑎𝑔𝑢𝑒𝑠! 𝐴𝑛𝑑 𝑟𝑒𝑚𝑒𝑚𝑏𝑒𝑟... 𝑆𝑡𝑎𝑦 𝑆𝑎𝑓𝑒 𝑎𝑛𝑑 𝐻𝑎𝑐𝑘 𝑅𝑒𝑠𝑝𝑜𝑛𝑠𝑖𝑏𝑙𝑦! 😎🏴‍☠️
#AIHardware #VulnerabilityResearch #PrivilegeEscalation
June 9, 2025 at 8:14 PM