While researching last months N-able N-central exploit (CVE-2026-18577, on KEV), we found and reported a new authentication bypass chain (CVE-2026-86206 and CVE-2026-86207). Patched and disclosed by the vendor over the weekend, we have published full details on the @rapid7 blog: https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed/
Project Glasswing:
Claiming to have found 26 thousand real vulnerabilities but only 0.8% of them have resulted in a real fix in a real project after five months is dire. They blame it on the human independent review bottleneck, but human experts being paid for their time definitely have a higher throughput than that when working with data that’s actually actionable.
The assigned-at-Claude severity ratings are also dire. It assigns “high” or “critical” to 91% of findings. Most findings in the real world are low or medium. This should be especially true when using a magic machine to shake out every last little issue that was overlooked by humans focused on the biggest risks.
[Edit: I should be more careful and note that this figure is calculated only from findings which have received a second opinion from project maintainers, which is much higher than the 0.8% fixed rate but much less than the entire dataset, so there’s probably bias towards reviewing those with critical ratings first. However, the maintainers found the high/critical rate to be quite inflated.]
Together this implies it’s generating thousands of trivial or nonsensical findings and labeling them HIGH DANGER CRITICAL MUST FIX, and the human independent verifiers are sifting for the rare needle in this haystack worth passing on. This isn’t really an improvement over the high-noise automated scanners we already had
(This is a corporate blog of someone with their own vulnerability management services to sell, so apply an appropriate number of grains of salt to their analysis. Filter keywords: AI LLM Anthropic)
However, one notable feature of the current AI era is the absence of any definitive such boundaries. While AI tools have flattened the difficulty landscape now in many areas of the subject, thus destroying the ability to locate promising new problems in that area, there are no clear frontiers that are separating the "AI-feasible" problems from the "AI-hard" problems (which certainly still exist, given that the difficulty level of problems are unbounded, and can even be undecidable). This is in part due to the rapidly changing nature of the technology, but also compounded by the refusal of AI companies to disclose their negative results, or reveal the process towards obtaining their solutions.
In fact, it is now the identification of a promising problem which is the scarce and precious resource. We have now seen that even the rumor of someone working on a problem can trigger a massive amount of AI-powered effort to flatten it before the original research project has time to reach its full potential. The incentives may now be pointing in the direction of no longer sharing any promising research directions with the broader community, which would reverse centuries of traditions of open science and do serious long-term damage to the future of the field. (3/4)
"One guy in #Sweden built a #searchengine to fight Google, and it works.
It's called #MarginaliaSearch.
It runs its own #crawler and builds its own #index instead of borrowing Bing's. It has no ads, no investors, and no loans.
What it does differently: it ranks for text-heavy, non-commercial pages. Personal blogs. Old university pages.
The weird corners SEO strangled. Every result tells you whether the page uses affiliate links and JavaScript, and you can filter them out.
There's an "explore" mode that just shows you random sites from the index. It's open source under AGPL, so you can host your own copy.
It's keyword-based, so don't type a full question at it. Type two nouns and see where you land. Every #searchengine now shows you the same twelve #monetizedpages."
OVERPASS is an unauth RCE in the SAP kernel (CVE-2026-44756) and S4GET is a preauth RCE in the SAP NetWeaver's Message Server (CVE-2026-58240).
Both have a very high CVSS and are likely to be exploited.
https://onapsis.com/blog/sap-overpass-remediation/
https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
Hey everyone! 🌹
> Lalu here: Openly sharing @entrypoint_fr 's open CFP & registration to help them kick-start nicely this new cool and red-focused event!
> Finding the right speakers and audience is hard, even more now that AI makes things feel "less special",. But some people are still making this happen, let's join forces! 🍀
---
Join & Apply to Entrypoint by @synacktiv a conference entirely dedicated to **Red Teaming**, coming to Paris on March 19–20, 2027 at Le Dernier Étage.
Expecting 500 attendees from around the world, all talks will be delivered in **English** to bring together as many international profiles as possible 👌
📍 Venue & Details:
- Event page: https://entrypoint.fr/
- Location: https://ledernieretage.paris/
🎤 Call for Papers
If you have a compelling topic to share, we'd love to hear from you. Submissions are open on the following tracks:
- Advanced Pentesting & Red Teaming : ActiveDirectory, Cloud (AWS/Azure/GCP) exploitation, container escapes, lessons learned (full scenario analysis).
- Supply Chain Attacks : Attacks targeting dependency managers (npm, pip, composer), secrets leaked on public platforms (GitHub).
- CI/CD : Advanced pipeline exploitation, loot techniques.
- Physical Intrusion : Methodologies to reach internal networks / target companies physically.
- Malware & C2 : Evasion techniques, obfuscation, custom C2 infrastructure, implant development.
- Post-Mortem Analysis : Analysis of threat actor exploitation methodologies, complex compromise chains.
- AI-assisted offensive security : Offensive use of AI including agentic red teaming, model-assisted vulnerability research, and AI-driven exploitation in real operations.
🎓 Training Days
4 days of hands-on training (Monday, March 15 – Thursday, March 18) covering the same themes.
🎁 Speaker Perks
To make it as smooth as possible for speakers, here's what is covered:
- Travel expenses
- Accommodation : hotel booked for the duration of the conference
- Speaker dinner : a dedicated evening to hang out with fellow speakers
⁉️ Questions
Feel free to ping @_remsio_ on X/discord or official @entrypoint_fr accounts directly if you have any questions or need more details!
See you in Paris! 🇫🇷✌️
🇭🇺 #Hungary has expelled 10 Russian diplomats who "were engaged in activities in Hungary that are unacceptable for diplomats under the Vienna Convention," Foreign Minister Anita Orbán said in a statement on Tuesday.
https://tvpworld.com/95280737/hungary-expels-10-russian-diplomats-foreign-minister-says
almost every idea i’ve had in my life is better than this can i get a few million dollars of investment (also wtf is wrong with my instagram ads)
Please boost this for as much reach as possible.
Parton Kirk, where #physics genius James Clerk Maxwell is buried, is being put up for sale. The community is attempting a buy out to save this kirk for science and the local community. They have until 31st of October to secure the funds.
Here's the crowd funder link. You can help prevent this kirk from falling into private hands.
Hello London 🇬🇧
The Phrack team is here and we left our mark around the city.
If you can find any of these stickers, email us for a chance of getting a physical copy of Phrack 73 delivered to your doorstep.
Send proof to hunt@phrack.org and have fun!
I’ve factored the RSA keys of a Certificate Authority...
… from the 90s.
docker compose up up down down left right left right b a start
Someone recreated the Windows 98 Disk Defragmenter in your browser.
Multiple drives, different speeds, mechanical HDD sounds, moving colored blocks...
And a Realistic mode where "Windows" occasionally touches the disk, forcing a rescan and losing some progress.
It's not true nostalgia unless you recreate the suffering too.
You have until the 8th at 23:59 to submit to unprompted! What are you waiting for?
This affects the Fediverse.
This affects the Internet.
This is the equivalent of the "rubber hose method" of decryption.
All technical solutions (read: all technology) is subject to politics. To political power. To political interactions.
You cannot rely on purely technical approaches. You have to have social approaches, too. Like. Actual policy and procedure geared around social and political group dynamics.
Like. How will we react when the US Govt requires that @jerry to shut off infosec.exchange servers.
Or how we'll react when a specific Mastodon server is declared part of a terrorist infrastructure. Will federating with it mean any other Mastodon server is now part of the officially designated terrorist network (what then of people that federate with a server that federates with a server that is classified as part of a terrorist network. And so on)
You cannot carry the conceit that tech alone or a purely technical approach will save you.
I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.