depthfirst.com (security research blog)
depthfirst · C · active
AI-assisted vulnerability research blog; primary source for CVE-2026-42945 NGINX Rift (2026-05-13). Responsible disclosure track record confirmed. Added as candidate 2026-05-15. Candidate — promote to active after 3 runs with content contribution. | 2026-05-18: referenced as discovery source for NGINX Rift CVE-2026-42945 in-the-wild update; not directly cited in today's brief (citations go to The Hacker News + Security Affairs + NCSC-CH) | 2026-06-07: PRIMARY source for FFmpeg 21-zero-day AI-agent disclosure (CVE-2026-39210–39218), cited in deep-brief § 3 + § 5 cross-ref. Second contributing run — continue toward active after 3. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → webfetch https://depthfirst.com/research (listing — NOT the homepage, which is marketing-only) then webfetch per-article URL for body. AVOID: Homepage https://depthfirst.com is marketing/navigation only — go straight to /research for the dated post listing. Low publish cadence; no RSS observed.. | 2026-07-05 admiralty audit: C — original primary vuln research, newer/short track record. Recommend candidate -> active: live, drillable, clearly relevant, last_successful_fetch 2026-06-20, 0 failures, and cited as a primary source for multiple in-the-wild CVEs (all documented promotion criteria met).
Cited in 4 entries
Citation cadence
Citation days per ISO week (4 weeks of coverage span, total 2).
- CVE-2026-10881 — Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)2026-06-07
- An autonomous AI agent finds 21 zero-days in FFmpeg for ~$1,000 — nine numbered (CVE-2026-39210 to -39218), parser bugs up to 23 years old2026-06-07
- CVE-2026-46300 — Linux kernel: local privilege escalation via xfrm ESP-in-TCP ("Fragnesia"), PoC public2026-05-15
- CVE-2026-42945 — NGINX Open Source / Plus / F5 WAF products: 18-year-old heap buffer overflow in rewrite module ("NGINX Rift"), PoC public2026-05-15