Keycloak is vulnerable to a critical unauthenticated account takeover (CVE-2026-18963)
I reproduced the bug locally; interesting one (power of LLM, I think)
https://t.co/hBuQe28aEm
🚨 Placebo : An internet chat community with a strong emphasis on Freedom of Speech.
Dark Web: http://placebordtyjrxo3mmlfg5i4mwsotzguplvblb6b775gs2x7lnftfrid[.]onion
Dread Announcement: https://dreadytofatroptsdj6io7l3xptbet6onoyno2yv7jicoxknyazubrad[.]onion/post/6bc511a93be8bd7a5f6c
CertiGhost (CVE-2026-54121) deserves much more attention than it is getting right now, from my point of view.
In a common/default AD CS setup, a low-privileged domain user can create a rogue machine account, trick the CA into issuing a certificate with the identity of a Domain Controller, authenticate as that DC via PKINIT, gain replication access and basically compromise the whole domain.
So if you run on-prem Active Directory with AD CS and your CA is still unpatched, an ordinary domain user may currently have a path to the highest privileges in your domain.
Patch it, obviously, or apply the temporary mitigation. But if you patched only recently, the harder and from my point of view more important question is: did someone already exploit it?
A patch closes the hole. It does not unfuck a domain that was already compromised.
I put a list of things I would check in the first reply.
Overview:
https://t.co/NHaJD5hlFi
Technical details:
https://t.co/ucGrc2SLbJ
PoC:
https://t.co/nvWARPtmso
Microsoft advisory:
https://t.co/kYoXWRKTyz
Temporary mitigation:
https://t.co/hVOHBYO5hD
⏰ It's CHALLENGE O'CLOCK!
👉 Capture the flag before Monday the 3rd of August
👉 Win €400 in SWAG prizes
👉 We'll release a tip for every 100 likes on this tweet
Thanks @silent_web3_ (zerodaysbooks) for the challenge 👇
https://t.co/0Yfuj4Ol9q
Building Your Own Drone (For Pentest) - Part 4
In the final part we show how credentials, password hashes, and network intelligence can be captured by targeting wireless devices and protocols. It's a different approach to wireless security for pentesters that targets both Wi-Fi and Bluetooth devices
We also covered vulnerabilities that system administrators and defenders should be aware of. Hopefully this encourages more organizations to replace outdated and vulnerable devices
https://t.co/9Pyg8Vkv8Q
@three_cube@_aircorridor
Open-sourcing our RCE implementation for CVE-2026-42533! This is an incredibly powerful NGINX bug that provides both info leak and an out-of-bounds heap write primitives (so, yes, ASLR bypass!).
F5 released the security advisory a week ago on July 15th. Fun fact: this bug appears to have been found concurrently by multiple groups. Our team at @depthfirstlabs caught it using our internal systems, right alongside CVE-2026-42530, a separate issue in NGINX’s HTTP/3 QPACK implementation.
Wtf, Kimi k3 found 0-day in latest Redis Only in 27 minutes,
also got near zero-click arbitrary command execution in Telegram Desktop & iOS.
Kimi didn’t just find the bug it built working authenticated RCE exploits for multiple Redis versions, including one that bypasses the fix in 8.8.0.
It also achieved near zero-click arbitrary command execution in Telegram Desktop & iOS (ASLR pinned).
The researcher even said it found real vulns in latest Chrome and WeChat.
I use kimi for AI-driven vulnerability research, it really work
🚨 A Go-based PoC scanner is available for CVE-2026-43499, also known as GhostLock, a Linux kernel use-after-free vulnerability that may allow local privilege escalation.
GitHub: https://t.co/8ilFwMAyUV
The tool includes a passive scan mode and a PoC trigger that may cause a kernel panic or system crash.
It is no secret that hidden parameters can lead to all sorts of vulnerabilities, such as SQLi, XSS & SSTI! 😎
But you have to find them first... 😓
In our comprehensive guide, we've uncovered the top 5 common ways to uncover unreferenced parameters in your target, including a list of common tooling to help you automate these 5 methods.
Check it out! 👇
https://t.co/areeGv7UYS
Finally a solid Mistral Uncensored model that actually run locally on
4.37 GB low-end hardware with zero refusals
Runs smoothly on my old RX 570.
It’s responsive, stable in long chats, and actually follows instructions without random refusals.
Q4_K_M quant gives surprisingly good quality while staying inside 8GB VRAM.
feels like the model actually listens instead of arguing.
Perfect if you want more control without buying a new GPU.