Google awarded $113,337 USD for a Linux vulnerability discovered by Indonesian security researcher Muhammad Alifa Ramdhan (@n0psledbyte), who works as a Principal Vulnerability Researcher at @starlabs_sg. 🤯
Ramdhan discovered a Linux Local Privilege Escalation (LPE) vulnerability involving a race condition in AF_ALG, the same subsystem later exploited in the famous Copy Fail vulnerability in 2026. He found the issue in 2025 without AI assistance and it was assigned CVE-2025-39964.
His coworker, Bing-Jhong Billy Jheng, was also credited for completing the exploit chain, which enabled both privilege escalation to root and escape from a Docker container. They submitted the exploit to Google kernelCTF and received its highest reward. 💰
Ramdhan is from Tangerang, Indonesia. He graduated from Diponegoro University (@undip) in 2023 and later moved to Singapore to work full time as a vulnerability researcher. 🇮🇩 🇸🇬
idnsec.com/research/linux-lo…
Thousands of websites in Indonesia have been hacked and turned into targeted promotion and marketing channels for the country's billion-dollar illegal gambling industry.
Cybercrime as a Service operations purchase webshells from underground markets or exploit low hanging fruit across government (go[.]id), private sector, and public sector websites. Attackers then inject SEO cloaking to serve different content to search engine crawlers and use AMP pages to redirect visitors searching for gambling related keywords, while keeping the compromised websites looking completely normal to ordinary visitors.
Emyra, a cybersecurity consultant, shares his investigation based on real case studies involving several high profile Indonesian institutions whose websites were compromised and used to promote online gambling.
idnsec.com/research/hacking-…
Mitigating RCE Impact Like in OpenAI Hack with Defense-in-Depth
@fariskhi explains how defense-in-depth strategies, such as web application and container sandboxing with Landlock, can help reduce the risk and blast radius of RCE, without relying solely on updates or prior knowledge of which component is vulnerable.
This can help contain attacks like the recent OpenAI hack demonstrated through responsible disclosure by @HacktronAI.
AI agents can also help profile application behavior, construct strict security policies, run positive tests, and perform adversarial emulation to validate these defenses.
idnsec.com/research/mitigati…
Comment2Shell: Zero Click Pre-Auth XSS to RCE in WordPress Core
One of our first contributors, @yeraisci_ (Security Researcher at Awesome Motive, Inc. and and current Top 1 of the WordPress bug bounty program), reported a pre-auth XSS vulnerability in WordPress comments that can be escalated to RCE when an administrator visits the injected page.
Read the technical details of CVE-2026-93485, an HTML parser issue in the wpautop() function that was recently fixed in the WordPress 7.1.1 security update
idnsec.com/research/comment2…
Introducing IDNSEC.
IDNSEC is a cybersecurity research and engineering society initiated by members of the Indonesian security community.
Our mission is to advance Indonesia's cyber defense and security research capabilities, while contributing useful research and engineering work to the global cybersecurity community.
Indonesia has a large and growing security community, with many capable researchers and engineers. We want to create a place where more of that capability can develop into deeper research, engineering, collaboration, and public technical work.
IDNSEC will publish writings in both English and Indonesian, covering security research, vulnerability research, defensive engineering, and analysis of cybersecurity issues relevant to Indonesia and the broader security community
Several research and engineering writings are already in the pipeline.
More about IDNSEC: idnsec.com/general/introduci…