Nebula Security's banner
Nebula Security's profile picture

Nebula Security

@nebusecurity5,904 subscribers

Secure the planet | YC S26

Shorts

GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as long as it runs Linux, from IoT to mobile to desktop, is affected. Read how we won $92,337 bug bounty with GhostLock and see our exploit on Github. Link below

GhostLock (CVE-2026-43499) is a 15yr old kernel 0-day we used in IonStack full chain exploit. Everything around you, as long as it runs Linux, from IoT to mobile to desktop, is affected. Read how we won $92,337 bug bounty with GhostLock and see our exploit on Github. Link below

144,892 Aufrufe

Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0. nginx-rift has been patched, but our security agent Vega has found a new 0 day. We will release the full technical writeup with ASLR bypass 30 days after the patch on

Introducing nginx-poolslip, a fresh RCE for the the latest nginx release 1.31.0. nginx-rift has been patched, but our security agent Vega has found a new 0 day. We will release the full technical writeup with ASLR bypass 30 days after the patch on

484,693 Aufrufe

Since V8 had heap sandbox, Chrome renderer RCE usually means chaining 2 bugs Today we bring the Spear of Longinus 1 bug, 100% success, no heap spray, found in 40+ major versions, arbitrary renderer read/write + V8 sandbox escape Our CVE-2026-6307 writeup

Since V8 had heap sandbox, Chrome renderer RCE usually means chaining 2 bugs Today we bring the Spear of Longinus 1 bug, 100% success, no heap spray, found in 40+ major versions, arbitrary renderer read/write + V8 sandbox escape Our CVE-2026-6307 writeup

49,495 Aufrufe

Videos

Keine weiteren Inhalte verfügbar