August 10, 2026
- Most WAFs and reverse proxies fall to HTTP/2 request-body bypasses. New research shows protocol-specific framing and inspection gaps break body inspection across nearly all tested products, with Nginx + libmodsecurity3 holding up best (lab.ctbb.show).
· Offensive & Exploitation
in ResetNightmare PoC Drops at Black Hat: One Kerberos Flaw, Any Account's Password Reset
July 29, 2026
- LLM-driven vulnerability research keeps landing real CVEs. OVSwrap (CVE-2026-64531), a broad Linux local privilege escalation, was found by giving models memory-safety and graph-reasoning tooling to work through exploit geometry (writeup), and ENDGINX turned open-weight GLM 5.1/5.2 loose on the NGINX codebase to surface five CVEs (mufeedvh via cyb3rops). Trail of Bits documented its goal-driven prompting workflow for bug discovery (Trail of Bits).
· AI & Model Security
in Artifactory Zero-Days Confirmed as the Hugging Face AI Agent's Escape Route
July 27, 2026
- A working RCE for NGINX CVE-2026-42533 was open-sourced. Researchers released their implementation for what they describe as a powerful bug that yields both an information leak and code execution (@cyb3rops).
· Vulnerabilities & Exploits
in Two Live Exploits and a Bench of Fresh Offensive Tooling
June 20, 2026
- F5 shipped out-of-band fixes for two critical NGINX Open Source RCE flaws, including CVE-2026-42530 (CVSS 9.2), a use-after-free in the HTTP/3 QUIC module triggerable by a remote unauthenticated attacker. No exploitation reported yet, but the QUIC path warrants prompt patching. The Hacker News, CVE
· Vulnerabilities & Exploits
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
- F5 shipped out-of-band patches for two critical NGINX Open Source flaws, including CVE-2026-42530 (CVSS 9.2), a use-after-free in the HTTP/3 QUIC module (
ngx_http_v3_module) that a remote unauthenticated attacker can trigger for code execution (The Hacker News, BleepingComputer).
· Vulnerabilities & Exploits
in FortiBleed Burns 70,000+ Fortinet Edge Devices While a Leaked GitHub Token Guts Novo Nordisk