Habr•October 2, 2026•🇷🇺Translated from Russian

Rust Researcher Builds AI Pipeline to Test 900 Vulnerability Hypotheses Across Crates and Linux Kernel

Sergey Gordeychik, co-founder of CyberOK and SCADA StrangeLove, set out to evaluate remaining classes of bugs in Rust programs after selecting the language for a high-speed packet-processing project. Because the language promises memory safety through ownership, borrowing, and lifetimes, he wanted to understand what errors still occur at crate boundaries and in application logic that the compiler cannot enforce.

He created the Damn Vulnerable Rust Application containing classic issues such as access-control bypasses, OS command injection, SSRF, path traversal, secret leakage, and double-free conditions. A threat model listing concrete prohibitions guided subsequent testing. Initial runs of conventional security tools produced limited results, prompting Gordeychik to integrate LLM-based agents.

The resulting rust-in-peace pipeline runs three independent analysis passes plus a dedicated SAST stage. One pass follows an explicit threat model, another performs blind exploration, and the third replays historical CVE patterns and prior findings. Surviving hypotheses are validated through API tests, fuzzing, or instrumented execution. Failed proof-of-concept attempts feed lessons back into the harness via the LESSONS.md file, which agents consult on later runs.

Early experiments on the vulnerable application achieved 9-of-9 detection once hints were removed and Rust-specific questions added. When applied to real crates, the system surfaced a plausible but ultimately false scenario in x509-parser involving an empty RSA value; the dangerous path was blocked earlier inside asn1-rs. After requiring explicit dependency citations, the pipeline produced actionable results in lopdf and other format parsers.

Across a sample of 50 candidates the three passes generated 80 hits that reduced to 20 confirmed findings after manual triage: 15 with working PoCs and five verified through source analysis. Nine findings appeared in all three passes. The research also contributed a patch to the Linux kernel and was presented at the ZeroNights conference.

Static-analysis coverage was measured with Semgrep and CodeQL rule sets; both showed limited reach against the parser-logic bugs that interested the researcher. The final architecture therefore retains single-pass discoveries rather than relying on majority voting, because eight of the twenty findings would have been lost under a consensus rule.

Related articles

Security NEXT•Vulnerabilities & Exploits

Critical Zero-Day Vulnerability in FortiMail Allows Unauthenticated File Writes

Fortinet disclosed a critical zero-day vulnerability in its FortiMail email security product that is already being exploited in attacks. The flaw, tracked as CVE-2026-104286, affects the graphical user interface component and stems from improper sanitization of path traversal and NULL byte sequences. Attackers can craft malicious HTTP requests to write arbitrary files to the system without authentication. The vulnerability received a CVSS v3.1 base score of 9.8, classifying it as Critical. Fortinet discovered the issue internally but has also received reports of active exploitation. Planned patches include FortiMail 8.0.2, 7.6.7, and 7.4.9, while users on the 7.2 branch are advised to migrate to 7.4 or later.

Habr•Vulnerabilities & Exploits

Six Months After tun0 Leak: Which Android VPN Clients Fixed Server Address Exposure and Which Ignored It

A detailed investigation reveals that Android VPN clients suffer from two distinct server address leaks when split tunneling is enabled. The first leak, tied to an unprotected local SOCKS proxy on 127.0.0.1, was quickly mitigated by most Xray and sing-box based clients through random ports and passwords. The second, more persistent leak allows excluded applications to bind sockets directly to the tun0 interface and discover the VPN server IP without root or special permissions. Only TeapodStream and OlConnect implemented owner-UID checks using ConnectivityManager.getConnectionOwnerUid, yet both initially mishandled the INVALID_UID response returned for excluded apps. AmneziaVPN has unmerged pull requests that correctly reject unknown owners, while sing-box offers a manual package_name_regex rule. v2rayNG closed the report as not planned, and major clients including WireGuard for Android, Mullvad, Proton VPN and others have issued no statements.

Habr•Vulnerabilities & Exploits

Part 2: How Third-Party Developers Closed the tun0 Leak in AmneziaVPN on Android

Third-party contributors to AmneziaVPN have detailed their fix for a VPN tunnel bypass affecting excluded applications on Android. The vulnerability allows any app, even those disallowed from the VPN, to bind sockets directly to the tun0 interface using SO_BINDTODEVICE and thereby discover the VPN server address. The team implemented a packet filter inside the client that queries Android via ConnectivityManager.getConnectionOwnerUid to determine packet ownership and drops traffic from unknown UIDs. The solution was integrated into both the Xray and AmneziaWG traffic paths, with the AmneziaWG hook placed inside amneziawg-go after packet parsing. Testing with leak_probe.py showed zero successful bypass attempts out of six methods when the filter was active, compared to six out of six without it. The developers submitted three pull requests and released a side-loaded test build, while noting remaining limitations such as raw sockets and tethering scenarios.

BoletimSec•Vulnerabilities & Exploits

Cisco Confirms Active Exploitation of CVE-2026-76504 in Catalyst SD-WAN Manager

Cisco has confirmed that the critical vulnerability CVE-2026-76504 in Catalyst SD-WAN Manager has been exploited in attacks throughout September. The flaw carries a CVSS score of 9.8 and allows attackers to gain full administrator access without any credentials by bypassing API authentication through malformed URI encoding. The issue affects the login session handling mechanism, enabling forged requests to grant netadmin privileges by default. Similar URI manipulation techniques were observed earlier this month in Oracle PeopleSoft attacks. Patches are available across multiple release trains including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, while older installations must migrate to supported versions. Cisco recommends restricting access to trusted hosts and placing the Manager behind firewalls until updates are applied. The vulnerability was discovered during routine support operations and verified by Cisco's Product Security Incident Response Team.