The screensharingd bug is a pre-auth, and an amazing bug that LLM enabled clowns killed without understanding it. Releasing a PoC that allows to download files from vulnerable macOS. It’s not super reliable, but the real one is very much. Patch asap!
https://t.co/LV3teOyTTU
🚨We reported KindaRails2Shell, a critical RCE in Ruby on Rails via Active Storage.
It’s not a one-shot RCE, but the preconditions are kinda common under default configurations.
Patch your applications now!
https://t.co/0ZufRhZ5st
🚨 CRITICAL: Researchers at Ethiack just dropped an RCE in Ruby on Rails, the wildly popular framework that powers GitHub, Shopify, Airbnb, GitLab, Basecamp, and many more. Update now!
Full technical writeup 👇
https://t.co/Jg6nBmaraG
🚨 We discovered a critical RCE in Ruby on Rails via Active Storage.
KindaRails2Shell - discovered by the Ethiack research team.
Over 500,000 live websites run Rails. Any app using Active Storage with the default vips processor and accepting image uploads from untrusted users is affected.
CVE-2026-66066
https://t.co/OsIpb0ouD2
OpenAI and Hugging Face probably won’t tell us exactly what happened anytime soon.
So I decided to reconstruct the full exploit chain, from escaping OpenAI’s sandbox to compromising Hugging Face production. 🧵
Don't miss the talk "Turning Arbitrary File Writes into RCE" by Bruno Mendes (@s3np41k1r1t0) and Rafael Castilho Silva (@castilho101) on Fri, Aug 7 at 12:00pm at Creator Stage 6 (W226-227).
Read more at https://t.co/e3glU8gWAU
#BugBounty#DEFCON34
Breaking Down Nextcloud CVE-2026-45281 🔓
An authenticated attacker knowing a user’s principal URL shouldn't mean total control over their calendar. Yet, that’s precisely what CVE-2026-45281 a high-severity authorization flaw in Nextcloud Server allows.
Breaking down this cross-account calendar takeover:
🟢The Root Cause: Improper authorization controls ([CWE-639]) in the calendar backend fail to verify if the requesting user actually owns or has access to the target principal URL.
🟢 The Impact: Full read and write access across multi-tenant deployments, allowing malicious actors to view, create, modify, or delete sensitive calendar events.
👉 Read our full research breakdown to understand the attack vector, detection strategies, and mitigation steps: https://t.co/roVI3Cx3wI
Breaking Down Nextcloud CVE-2026-45281 🔓
An authenticated attacker knowing a user’s principal URL shouldn't mean total control over their calendar. Yet, that’s precisely what CVE-2026-45281 a high-severity authorization flaw in Nextcloud Server allows.
Breaking down this cross-account calendar takeover:
🟢The Root Cause: Improper authorization controls ([CWE-639]) in the calendar backend fail to verify if the requesting user actually owns or has access to the target principal URL.
🟢 The Impact: Full read and write access across multi-tenant deployments, allowing malicious actors to view, create, modify, or delete sensitive calendar events.
👉 Read our full research breakdown to understand the attack vector, detection strategies, and mitigation steps: https://t.co/roVI3Cx3wI
You wouldn't trust the wrong bench at 30,000 feet. Don't trust one on the ground either.
Existing benchmarks fall short when the goal is to measure real-world AI pentesting capability.
In the first part of this two-blog series, we presented our evaluation methodology, centered on realistic targets, a structured finding-to-ground-truth pipeline with LLM-as-a-judge matching and bipartite resolution, continuous expert maintenance of ground truth, and richer evaluation metrics that go beyond simple success rates.
Now, we are launching Part 2: how we address four additional challenges that we strongly believe any real-world-oriented evaluation methodology should cover.
👉 Read the blog to learn about all the insights → https://t.co/LQlWFnztwu
👉 Check out the repo (now featuring Temporal Evaluation and Representative Subset Selection): https://t.co/FAZOvDGCfp