NebuSec's banner
NebuSec's profile picture

NebuSec

@nebusecurity7,160 subscribers

An AI defense system for cyber attack | YC S26

Shorts

Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0. nginx-rift has been patched, but our security agent Vega has found a new 0 day. We will release the full technical writeup with ASLR bypass 30 days after the patch on

Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0. nginx-rift has been patched, but our security agent Vega has found a new 0 day. We will release the full technical writeup with ASLR bypass 30 days after the patch on

487,308 views

GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as long as it runs Linux, from IoT to mobile to desktop, is affected. Read how we won $92,337 bug bounty with GhostLock and see our exploit on Github. Link below

GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as long as it runs Linux, from IoT to mobile to desktop, is affected. Read how we won $92,337 bug bounty with GhostLock and see our exploit on Github. Link below

149,089 views

Since V8 had heap sandbox, Chrome renderer RCE usually means chaining 2 bugs Today we bring the Spear of Longinus 1 bug, 100% success, no heap spray, found in 40+ major versions, arbitrary renderer read/write + V8 sandbox escape Our CVE-2026-6307 writeup

Since V8 had heap sandbox, Chrome renderer RCE usually means chaining 2 bugs Today we bring the Spear of Longinus 1 bug, 100% success, no heap spray, found in 40+ major versions, arbitrary renderer read/write + V8 sandbox escape Our CVE-2026-6307 writeup

51,073 views

Today’s exploit is from a ipv6 UAF, introduced in Nov 2021, fixed on upstream in Aug 2026. Discovered and exploit by NebuSec security pipeline. Exploit in our GitHub:

Today’s exploit is from a ipv6 UAF, introduced in Nov 2021, fixed on upstream in Aug 2026. Discovered and exploit by NebuSec security pipeline. Exploit in our GitHub:

15,667 views

Today's exploit is for the latest Fedora 44, a UAF in netfilter, CVE-2026-52912. It was introduced in Mar 2016 and fixed upstream in May 2026. Discovered and exploited by the NebuSec security pipeline. (RANDOM_KMALLOC_CACHES + SELinux) Exp source code:

Today's exploit is for the latest Fedora 44, a UAF in netfilter, CVE-2026-52912. It was introduced in Mar 2016 and fixed upstream in May 2026. Discovered and exploited by the NebuSec security pipeline. (RANDOM_KMALLOC_CACHES + SELinux) Exp source code:

12,030 views

Videos

No more content to load