🦜 Full Disclosure
@seclists.org.fulldisclosure@rss-parrot.net
I'm an automated parrot! I relay a website's RSS feed to the Fediverse. Every time a new post appears in the feed, I toot about it. Follow me to get all new posts in your Mastodon timeline!
Brought to you by the RSS Parrot.
---
A public, vendor-neutral forum for detailed discussion of vulnerabilities and exploitation techniques, as well as tools, papers, news, and events of interest to the community. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. More importantly, fresh vulnerabilities sometimes hit this list many hours or days before they pass through the Bugtraq moderation queue.
Your feed and you don't want it here? Just
e-mail the birb.
A project is publishing full analyses of AI-discovered 0-days - first batch of 10 with reproducible exploits
https://seclists.org/fulldisclosure/2026/Jul/29
Published: July 23, 2026 02:03
Posted by zz lin on Jul 22I came across a project, "0day Rubbish", that states it will continuously
disclose 0-day vulnerabilities discovered by an AI-driven research process
(a multi-LLM ensemble of Claude, OpenAI, DeepSeek and GLM). For each…
Synology stale DNS allows practical interception of traffic from vulnerable DSM clients
https://seclists.org/fulldisclosure/2026/Jul/28
Published: July 23, 2026 02:02
Posted by shed riot on Jul 22# Synology stale DNS allows practical interception of traffic from
vulnerable DSM clients
Vendor case: 904909
Suggested severity: High
## Customer advisory
Synology customers using the affected DSM and Relayd versions listed…
Amplitude customers using domain proxies should update their configuration immediately.
https://seclists.org/fulldisclosure/2026/Jul/27
Published: July 23, 2026 02:02
Posted by shed riot on Jul 22After receiving live analytics requests intended for `api2.amplitude.com`,
I contacted `security () amplitude com` and was invited to submit the issue
through Amplitude's private Bugcrowd programme.
In my view, Amplitude's…
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping in ASUS Business/Software Manager kernel driver
https://seclists.org/fulldisclosure/2026/Jul/26
Published: July 21, 2026 05:41
Posted by Hayaturehman Ahmadzai on Jul 20Hi all,
I'm disclosing a vulnerability (CVE-2026-13585) in the ASUS bsitf.sys /
AsusBSItf.sys kernel driver, shipped with ASUS Business Manager and
Software Manager. ASUS has assigned the CVE and published a vendor…
New Release: UFONet v2.0 - "R3DST4R!"...
https://seclists.org/fulldisclosure/2026/Jul/25
Published: July 21, 2026 05:40
Posted by psy on Jul 20Hi Community,
I am glad to present a new release of this tool:
- https://ufonet.03c8.net
---------
"UFONet is a free software, P2P and cryptographic -disruptive toolkit-
that allows to perform DoS and DDoS attacks; on the…
XSSer v.1.9 - "Bl4ck Swarm!" released
https://seclists.org/fulldisclosure/2026/Jul/24
Published: July 21, 2026 05:40
Posted by psy on Jul 20Hi FD,
I am glad to present a new release of this tool:
- https://xsser.03c8.net
---------
"Cross Site "Scripter" (aka XSSer) is an automatic -framework- to
detect, exploit and report XSS vulnerabilities in web-based…
NotCVE registry index — public records of vulnerabilities that shipped without a CVE
https://seclists.org/fulldisclosure/2026/Jul/23
Published: July 21, 2026 05:35
Posted by NotCVE Advisories on Jul 20----------------------------------------------------------------------------
NotCVE Registry Index — 2026-07-16
----------------------------------------------------------------------------
[-] About the NotCVE…
[NotCVE-2026-0001] Cloudflare Universal SSL CAA augmentation weakens RFC 8657 account binding — CVE-2026-14440 assigned 163 days after public no-CVE disclosure
https://seclists.org/fulldisclosure/2026/Jul/22
Published: July 16, 2026 04:43
Posted by NotCVE Advisories on Jul 15----------------------------------------------------------------------------
NotCVE Disclosure Update — NotCVE-2026-0001 / CVE-2026-14440
----------------------------------------------------------------------------
[-]…
Subject: Advisory Submission: EZ Game Booster - Cleartext Storage of Sensitive Credentials (CWE-312)
https://seclists.org/fulldisclosure/2026/Jul/21
Published: July 16, 2026 04:42
Posted by AliReza on Jul 15# Exploit Title: EZ Game Booster v1.0.0 - Cleartext Credentials in user.config
# Date: 2026-07-16
# Exploit Author: Alireza Chegini
# Vendor Homepage: https://ezsystemrepairs.com
# Software Link: https://ezsystemrepairs.com (Free…
CVE-2026-56877 - Skillable SCORM userId authorisation bypass
https://seclists.org/fulldisclosure/2026/Jul/20
Published: July 16, 2026 04:41
Posted by Greg via Fulldisclosure on Jul 15Skillable's SCORM lab launch endpoint validates a launch token but
enforces per-user allocation limits using a browser-supplied userId
that is not bound to the validated token. An authenticated learner
can modify…