Submissions are still open!
If you've been sitting on a bug, technique, war story, weird research rabbit hole, or beautifully cursed idea: now is the time.
Write something worth archiving.
Phrack CFP closes June 30.
More details on how to submit at https://t.co/FiWJH1fEMG
[#POC2026] CFT 👈 WANTED
We’re looking for deep, practical, hands-on trainings from you
Exploit development, browser, kernel, AI security — surprise us.
CFT deadline: 26th June
More info: https://t.co/d94HoJc4hy
🚨 Introducing "ITScape" (CVE-2026-46316)
A Guest-to-Host Escape in KVM/arm64. Guest-side actions alone exploit a use-after-free to run root-privileged code in the host kernel.
Unlike the commonly published QEMU escapes, the bug lives in in-kernel KVM, not QEMU. On a successful exploit, commands run with host kernel privilege rather than the privilege of a user process, threatening the guest-host isolation of multi-tenant arm64 public clouds.
To the best of public knowledge, the first Guest-to-Host Escape Exploit targeting in-kernel KVM/arm64.
Details: https://t.co/CtZOQEzIdg
What does a kernel MTE panic actually look like on Apple Silicon? We built tooling to find out — and to make it KASAN-style useful.
Pointer tag, memory tag, tag map. All in the panic output.
👉 https://t.co/7NQ3IZj2A6
#AppleSilicon#MTE#KernelSecurity#iOSSecurity
Interested in becoming a speaker at Offensivecon Tokyo? You have three months to submit your talk on an innovative offensive security topic.
More information here 👉️ https://t.co/ynVQnUBDrj
Sergey Bratus @sergeybratus is kicking off the @IEEESSP workshops by remembering our friend and fellow hacker FX of Phenoelit @41414141, one of the leaders of #langsec
BREAKING NEWS - Jui-jitsu battle and domain war today in Berlin over control of https://t.co/Zmk3X7tgio. skyper vs BSDaemon in an underground fight club in Berlin. The prize? Admin-C/Owner-C entry of https://t.co/Zmk3X7tgio. Livestream TBA - stay tuned for the URL.
Microsoft Edge's Enhanced Security Mode was designed to be the ultimate defense when browsing unfamiliar websites.
Zellic researchers @eternalsakura13 and R1nd0 found 23 RCEs in it.
Their target? DrumBrake, Microsoft's WebAssembly interpreter.
The irony? This security feature became a massive attack surface itself.
These findings span type confusion, out-of-bounds memory access, use-after-free, and critical control flow errors.
TAPOcalypse Now: Exploiting TP-Link Smart Devices From Anywhere https://t.co/uL6MSjMAVF
Details exploitation via LAN, through browser, and against the cloud account.
Some of the reported vulnerabilities are fixed, for others the vendor didn't provide a fix by embargo expiry.