Mitigating RCE Impact Like in OpenAI Hack with Defense-in-Depth
@fariskhi explains how defense-in-depth strategies, such as web application and container sandboxing with Landlock, can help reduce the risk and blast radius of RCE, without relying solely on updates or prior knowledge of which component is vulnerable.
This can help contain attacks like the recent OpenAI hack demonstrated through responsible disclosure by @HacktronAI.
AI agents can also help profile application behavior, construct strict security policies, run positive tests, and perform adversarial emulation to validate these defenses.
https://t.co/3Y8E0e0WlP
Comment2Shell: Zero Click Pre-Auth XSS to RCE in WordPress Core
One of our first contributors, @yeraisci_ (Security Researcher at Awesome Motive, Inc. and and current Top 1 of the WordPress bug bounty program), reported a pre-auth XSS vulnerability in WordPress comments that can be escalated to RCE when an administrator visits the injected page.
Read the technical details of CVE-2026-93485, an HTML parser issue in the wpautop() function that was recently fixed in the WordPress 7.1.1 security update
https://t.co/LZlHroivDK
Introducing IDNSEC.
IDNSEC is a cybersecurity research and engineering society initiated by members of the Indonesian security community.
Our mission is to advance Indonesia's cyber defense and security research capabilities, while contributing useful research and engineering work to the global cybersecurity community.
Indonesia has a large and growing security community, with many capable researchers and engineers. We want to create a place where more of that capability can develop into deeper research, engineering, collaboration, and public technical work.
IDNSEC will publish writings in both English and Indonesian, covering security research, vulnerability research, defensive engineering, and analysis of cybersecurity issues relevant to Indonesia and the broader security community
Several research and engineering writings are already in the pipeline.
More about IDNSEC: https://t.co/zUYKuaeKun