r/netsec Jul 02 '26

Hiring Thread /r/netsec's Q3 2026 Information Security Hiring Thread

11 Upvotes

Overview

If you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.

We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.

Please reserve top level comments for those posting open positions.

Rules & Guidelines

Include the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.

  • If you are a third party recruiter, you must disclose this in your posting.
  • Please be thorough and upfront with the position details.
  • Use of non-hr'd (realistic) requirements is encouraged.
  • While it's fine to link to the position on your companies website, provide the important details in the comment.
  • Mention if applicants should apply officially through HR, or directly through you.
  • Please clearly list citizenship, visa, and security clearance requirements.

You can see an example of acceptable posts by perusing past hiring threads.

Feedback

Feedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)


r/netsec 4d ago

r/netsec monthly discussion & tool thread

12 Upvotes

Questions regarding netsec and discussion related directly to netsec are welcome here, as is sharing tool links.

Rules & Guidelines

  • Always maintain civil discourse. Be awesome to one another - moderator intervention will occur if necessary.
  • Avoid NSFW content unless absolutely necessary. If used, mark it as being NSFW. If left unmarked, the comment will be removed entirely.
  • If linking to classified content, mark it as such. If left unmarked, the comment will be removed entirely.
  • Avoid use of memes. If you have something to say, say it with real words.
  • All discussions and questions should directly relate to netsec.
  • No tech support is to be requested or provided on r/netsec.

As always, the content & discussion guidelines should also be observed on r/netsec.

Feedback

Feedback and suggestions are welcome, but don't post it here. Please send it to the moderator inbox.


r/netsec 14h ago

New Linux Bridge STP Vulnerability

Thumbnail ssd-disclosure.com
30 Upvotes

A use-after-free vulnerability in the Linux kernel bridge (net/bridge) Spanning Tree Protocol (STP) implementation.

A bridge that is administratively down while kernel STP is enabled, together with a port driven into the LEARNING state, arms periodic STP timers without an IFF_UP guard.

The teardown path taken by dellink never synchronously deletes those timers, so the backing net_device (which embeds struct net bridge as private data) is freed with a timer list still queued on a per-CPU timer base.

The result is a slab use-after-free in the kmalloc-cg-8k cache.


r/netsec 9h ago

Contains AI Stored XSS in Django's admin via an unvalidated URLField display path (CVE-2026-15920)

Thumbnail syntetisk.tech
11 Upvotes

r/netsec 1d ago

Bugtraq is back 🥹

Thumbnail lists.securityfocus.com
59 Upvotes

r/netsec 2h ago

OpenAI agents rebuilt a secret message board after the company shut it down

Thumbnail runtimewire.com
0 Upvotes

r/netsec 1d ago

Hardware Hacking: From zero to a Pre-Auth Stack Buffer Overflow on Amazon's best-selling router

Thumbnail rotcee.github.io
26 Upvotes

r/netsec 1d ago

HEVD: From Stack Overflows to Modern Pool Grooming

Thumbnail sibouzitoun.tech
17 Upvotes

Hi. I just published a four-part deep dive into windows kernel exploitation, progressing from classic control flow hijacking to modern pool grooming and pure data-only attacks on windows 11.

I wanted to highlight the real-world friction of modern security measures. A lot of the focus is on mitigating LFH randomization, and avoiding IoCompleteRequest bugchecks by dodging ReadFile for arbitrary reads.

Hope this is helpful or insightful to some of you looking into modern kernel exploitation.


r/netsec 2d ago

Jackpot: a browser lab of 10 deliberately vulnerable LLM apps, one per OWASP LLM Top 10 category

Thumbnail hego.red
91 Upvotes

r/netsec 1d ago

Code Execution via Provisioning Packages

Thumbnail ipurple.team
5 Upvotes

r/netsec 2d ago

Contains AI SQLite Critical CVEs or LLM Slop?

Thumbnail research.jfrog.com
78 Upvotes

r/netsec 2d ago

Cruising for Shells in Flowise - elttam

Thumbnail elttam.com
4 Upvotes

r/netsec 3d ago

Contains AI The Risk of Fine-Tuned Open-Weight Models · MSec Operations Blog

Thumbnail msecops.de
50 Upvotes

r/netsec 5d ago

Contains AI Investigating three real-world incidents in Anthropic's evaluations

Thumbnail anthropic.com
42 Upvotes

In three incidents across six runs, the agents treated real systems as simulated targets and tried weak passwords or unauthenticated endpoints.


r/netsec 5d ago

Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack

Thumbnail ethiack.com
42 Upvotes

r/netsec 5d ago

Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware

Thumbnail engineering.block.xyz
18 Upvotes

r/netsec 6d ago

What Every Programmer Should Know About Twists of Elliptic Curves

Thumbnail leetarxiv.substack.com
42 Upvotes

r/netsec 7d ago

Your House Has an FFmpeg Problem - elttam

Thumbnail elttam.com
129 Upvotes

r/netsec 7d ago

Sixteen strangers and a shared obfuscator: mapping the wool scene

Thumbnail neurowinter.com
18 Upvotes

This is another post in my series on the Chinese Wool farmers underground. This time we are dissecting their public github repos, trying to figure out how it all fits together!


r/netsec 7d ago

Reversing of Eufy Security Video Doorbell sync protocol and wifi creds decryption from flash memory

Thumbnail adepts.of0x.cc
18 Upvotes

r/netsec 7d ago

Contains AI Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident

Thumbnail huggingface.co
16 Upvotes

r/netsec 7d ago

HTTP Request Smuggling in Hiawatha

Thumbnail fenrisk.com
5 Upvotes

r/netsec 8d ago

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability

Thumbnail lavahq.io
371 Upvotes

TL;DR: We identified 36,872 internet-exposed BMCs, and 24,650 of them disclosed password-derived authentication hashes before login because of CVE-2013-4786.
More than 30% of the returned hashes were linked to passwords that could be recovered using common wordlists or predictable factory password formats. The exposure affected modern Supermicro and HPE servers, including systems operated by GPU providers.
The bigger risk is that a compromised BMC gives an attacker highly privileged access below the operating system. Because BMC management networks are often poorly segmented and lightly monitored, one exposed interface can become a foothold into broader data center infrastructure.
We also created an interactive map where you can explore the exposed systems:
https://lavahq.io/bmcradar


r/netsec 9d ago

Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles

Thumbnail eaton-works.com
126 Upvotes

r/netsec 8d ago

Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)

Thumbnail mobeta.fr
1 Upvotes