House passes kids’ online safety bill, but Senate approval unlikely
An intelligence budget 'super user' job is now in the hands of Russ Vought
Justices rule that cellphone location histories are protected by the Fourth Amendment
US racks up about 400 wins over illegal World Cup streaming sites
US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp
What's New
Top 5 Across All Sources-
House passes kids’ online safety bill, but Senate approval unlikely
The Record from Recorded Future News · 1h ago -
Beyond CTF Labs
John Hammond · 1h ago -
What’s new in Microsoft Security: June 2026
Microsoft Security Blog · 1h ago -
Securing AI agents: When AI tools move from reading to acting
Microsoft Security Blog · 1h ago -
Fake Perplexity extension on Chrome Web Store tracked searches
BleepingComputer · 1h ago
Gigafeed (4302 entries)
House passes kids’ online safety bill, but Senate approval unlikely The Record from Recorded Future News · 1h ago Beyond CTF Labs John Hammond · 1h ago What’s new in Microsoft Security: June 2026 Microsoft Security Blog · 1h ago Securing AI agents: When AI tools move from reading to acting Microsoft Security Blog · 1h ago Fake Perplexity extension on Chrome Web Store tracked searches BleepingComputer · 1h ago Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses The Hacker News · 1h ago Why I switched to wireless security cameras after years of testing wired models Latest news · 2h ago GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks The Hacker News · 2h ago Netflix vs. Peacock: Which one deserves your money in 2026? Latest news · 3h ago Aikido Security acquires Root to expand backported fixes for open source vulnerabilities Help Net Security · 3h ago Lessons from the Underground: How to Combat Business Email Compromise BleepingComputer · 3h ago CVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817) Help Net Security · 3h ago Cequence Platform 9.0 uses AI to simplify API security and compliance Help Net Security · 3h ago BlueHammer Vulnerability Exploited in Ransomware Attacks SecurityWeek · 3h ago An intelligence budget 'super user' job is now in the hands of Russ Vought The Record from Recorded Future News · 3h ago 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study The Hacker News · 3h ago Jamf enables AI Governance and shadow AI detection on Mac Help Net Security · 3h ago Apple rushed to squash 29 bugs because AI is supercharging hackers - update ASAP Latest news · 3h ago Digi International’s DANI automates network diagnostics and device management Help Net Security · 3h ago OpenMatter Network brings verifiable trust to AI governance Help Net Security · 3h ago Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks SecurityWeek · 4h ago Aflac Japan Data Breach Impacts 4.38 Million SecurityWeek · 4h ago 61% of US adults use AI for health information now - up from 2% in 2024 Latest news · 4h ago Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat SecurityWeek · 5h ago Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History SecurityWeek · 5h ago What the Numbers Say About FIFA 2026 Cyber Risk The Hacker News · 5h ago Exploitation of Recent Oracle E-Business Suite Vulnerability Begins SecurityWeek · 5h ago Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer The Hacker News · 5h ago Insurance giant Aflac discloses data breach after subsidiary hack BleepingComputer · 5h ago Microsoft adds smarter bot protection to Teams meetings BleepingComputer · 6h ago SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558) Help Net Security · 6h ago Why 'countdown mode' is the task manager feature I can't live without Latest news · 6h ago ToddyCat: your hidden email assistant. Part 2 Securelist · 7h ago The AI Token Costs That Can Break Cybersecurity SecurityWeek · 7h ago Kali Linux 2026.2 released with 9 new tools, NetHunter updates BleepingComputer · 7h ago Blackfield ransomware asks Nidec Corporation for $2 million ransom BleepingComputer · 7h ago AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks The Hacker News · 7h ago Nissan Employee Data Breached in Oracle PeopleSoft Hack SecurityWeek · 7h ago Too many junk files on your Windows PC? This free tool can remove them in one click Latest news · 7h ago I tried the 'Plus Five' rule to fix my iPhone's slow wireless charging - here's what happened Latest news · 8h ago AI agents are your new colleagues - how to get the best results Latest news · 8h ago CISA: Windows BlueHammer flaw now exploited by ransomware gangs BleepingComputer · 8h ago Critical SimpleHelp Vulnerability Exploited for Malware Delivery SecurityWeek · 8h ago New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials The Hacker News · 8h ago Kali Linux 2026.2 trims VM boot times, refreshes its desktops Help Net Security · 8h ago CVE-2026-11979 Stack-Based Buffer Overflow in libxml2 MSRC Security Update Guide · 9h ago CVE-2026-53325 agp/amd64: Fix broken error propagation in agp_amd64_probe() MSRC Security Update Guide · 9h ago CVE-2026-41992 Global Buffer Overflow in GNU gzip MSRC Security Update Guide · 9h ago CVE-2026-41991 Predictable Temporary File in GNU gzip MSRC Security Update Guide · 9h ago CVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr MSRC Security Update Guide · 9h ago CVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions MSRC Security Update Guide · 9h ago OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad Help Net Security · 9h ago Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth The Hacker News · 9h ago Quantifind Raises $200 Million for AI-Native Risk Intelligence SecurityWeek · 10h ago AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin Help Net Security · 10h ago Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild The Hacker News · 12h ago Freddy or fraud? What one fan teaches us about ecommerce risk during the World Cup Fraud Prevention – Riskified · 12h ago US offers $10 million for info on group behind Signal and WhatsApp hacking spree Security - Ars Technica · 19h ago Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs Security Latest · 19h ago Nissan discloses employee data breach linked to Oracle zero-day attacks BleepingComputer · 20h ago NAIC says public data stolen in ShinyHunters' PeopleSoft breach BleepingComputer · 20h ago I always keep these 3 devices plugged into my power station - here's why Latest news · 21h ago I replaced my iPhone battery at the Apple store for the first time ever - and learned a valuable lesson Latest news · 22h ago Justices rule that cellphone location histories are protected by the Fourth Amendment The Record from Recorded Future News · 22h ago I tried a Windows handheld PC, and its docking system made it my ideal travel companion Latest news · 23h ago WhatsApp rolls out usernames to help users hide their phone number BleepingComputer · 23h ago After testing Thread, Zigbee, and Matter, here's how I'm building my smart home differently Latest news · 23h ago Microsoft extends Windows Server 2022 hotpatching until October 2027 BleepingComputer · 23h ago US racks up about 400 wins over illegal World Cup streaming sites The Record from Recorded Future News · 1d ago Internet down? 3 ways I use an old Android phone as a backup connection for my home router Latest news · 1d ago I changed these Android Auto settings to limit what Gemini learns about me - here's why Latest news · 1d ago Chromium extension uses AI‑related branding to redirect browser search Microsoft Security Blog · 1d ago WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private The Hacker News · 1d ago ConsentFix Exposed John Hammond · 1d ago Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input The Hacker News · 1d ago Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs The Hacker News · 1d ago US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp The Record from Recorded Future News · 1d ago U.S. offers $10 million for hackers targeting WhatsApp, Signal users BleepingComputer · 1d ago Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks The Hacker News · 1d ago Chrome vs. Edge vs. Firefox: I tested each browser's AI, but I'm only sticking with one Latest news · 1d ago Six months later, this small gadget is my secret weapon against doomscrolling Latest news · 1d ago ⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More The Hacker News · 1d ago Agentic AI Has an Identity Problem and Attackers Know It BleepingComputer · 1d ago Critical SimpleHelp flaw exploited to deploy new stealer malware BleepingComputer · 1d ago Hackers now exploit critical Oracle E-Business flaw in attacks BleepingComputer · 1d ago What years of testing thermal cameras taught me about the problems hiding in plain sight Latest news · 1d ago You can still buy last year's Sony Bravia OLED TV for $600 off - and I can't recommend it enough Latest news · 1d ago Want a big tech job? Startups may be your best shot now - here's why Latest news · 1d ago Sony WH-1000XM6 vs. Sennheiser Momentum 5: I wore both pairs for months, and prefer this one Latest news · 1d ago CISA Warns Attackers Are Targeting Critical Internal Business Platforms Cyber Defense Magazine · 1d ago 236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers The Hacker News · 1d ago Why Post-Quantum Cryptography Starts With Credentials The Hacker News · 1d ago Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse The Hacker News · 1d ago The Gentlemen are knocking: сustom backdoors and evolving tactics Securelist · 1d ago Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change Security Latest · 1d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 1d ago Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts The Hacker News · 1d ago CVE-2026-58058 Nmap - Integer Underflow in IPv6 Extension Header Parsing MSRC Security Update Guide · 1d ago CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length MSRC Security Update Guide · 1d ago CVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup MSRC Security Update Guide · 1d ago CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation MSRC Security Update Guide · 1d ago CVE-2026-52908 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible MSRC Security Update Guide · 1d ago CVE-2026-52909 ip6_vti: set netns_immutable on the fallback device. MSRC Security Update Guide · 1d ago CVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period. MSRC Security Update Guide · 1d ago Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw The Hacker News · 1d ago Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer The Hacker News · 1d ago TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry Trend Micro Research, News, Perspectives · 1d ago Black Hat Europe 2025 | How We Turned AI's 'Web Browsing' Into A Gateway For Targeting 1B+ Users Black Hat · 1d ago Return On Risk: The New Measure Of Cyber Resilience Cyber Defense Magazine · 2d ago 2026 home lab setup to test malicious links safely for FREE (step by step) David Bombal · 2d ago Path to StateRAMP Cyber Defense Magazine · 2d ago Black Hat Europe 2025 | The Forensic Trail On GitHub: Hunting For Supply Chain Activity Black Hat · 2d ago CVE-2026-53228 ipv6: sit: reload inner IPv6 header after GSO offloads MSRC Security Update Guide · 2d ago CVE-2026-53225 sctp: fix uninit-value in __sctp_rcv_asconf_lookup() MSRC Security Update Guide · 2d ago CVE-2026-53220 netfilter: revalidate bridge ports MSRC Security Update Guide · 2d ago CVE-2026-53262 l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() MSRC Security Update Guide · 2d ago CVE-2026-52961 ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size MSRC Security Update Guide · 2d ago CVE-2026-53107 wifi: libertas: don't kill URBs in interrupt context MSRC Security Update Guide · 2d ago Black Hat Europe | LINE-Break: Cryptanalysis And Reverse Engineering Of Letter Sealing Black Hat · 2d ago Black Hat Europe 2025 | Hacking Smart Cities One Building At A Time - A City Of A Thousand Zero Days Black Hat · 3d ago Rethinking Identity Security In The Age Of AI Driven Fraud Cyber Defense Magazine · 3d ago HackTheBox - WingData IppSec · 3d ago New Age Insider Risk Cyber Defense Magazine · 3d ago Security News This Week: LastPass Users Had Their Data Stolen—Again Security Latest · 3d ago Black Hat Europe 2025 | Silence On macOS: What 70K Binaries Reveal About The macOS Malware Ecosystem Black Hat · 3d ago The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials Security Latest · 4d ago Facebook Phishing Fails John Hammond · 4d ago Real Folks of Cyber | Pearce Barry | Day in the Life The Cyber Mentor · 4d ago How Dynamic Defense shuts an attacker out without shutting down the business Heimdal Security Blog · 4d ago Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure Cyber Defense Magazine · 4d ago Black Hat Intercepted Video Series | Lexie Thach Black Hat · 4d ago Which is Ethernet? What's the difference? David Bombal · 4d ago Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To Cyber Defense Magazine · 4d ago Name That Toon Contest darkreading · 4d ago Static security has run out of road. The case for Dynamic Defense Heimdal Security Blog · 4d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 4d ago Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access Microsoft Security Blog · 4d ago Getting Started with the TCM Security Academy The Cyber Mentor · 4d ago FCC passes new cybersecurity rules for emergency systems, undersea cables CyberScoop · 4d ago Federal court rules Trump election-focused executive order illegal CyberScoop · 5d ago Disable SmartScreen Fast John Hammond · 5d ago Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms Microsoft Security Blog · 5d ago Black Hat Intercepted | Lexie Thach, Ex Machina Parlor + Naval Information Warfare Center Pacific Black Hat · 5d ago The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer Cyber Defense Magazine · 5d ago Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract CyberScoop · 5d ago Cisco Finesse Remote File Inclusion Vulnerability Cisco Security Advisory · 5d ago Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack CyberScoop · 5d ago The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target Cyber Defense Magazine · 5d ago NSA Urges Cyberthreat Timeline Has Compressed From Years to Months Cyber Defense Magazine · 5d ago Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools Securelist · 5d ago British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted Security Latest · 5d ago Europe Evolves Into Ransomware's Favorite Region darkreading · 5d ago Why patch directives only go so far CyberScoop · 5d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 5d ago Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge Recorded Future · 5d ago Evaluating Mexico’s New Cybersecurity Plan Recorded Future · 5d ago Black Hat Europe 2025 | Stress-Testing SAST And LLMs On Modern Web Backends Black Hat · 5d ago Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure darkreading · 5d ago One-two punch delivered in global operation disrupts cybercrime "assembly line" Security - Ars Technica · 5d ago Black Hat Europe 2025 | Page Phantoms: Zero-IO, In-Memory Tampering Of The Linux Page Cache Black Hat · 5d ago 2026 FIFA World Cup Faces Surge in Cyber Threats darkreading · 5d ago Europe’s 800 Exaflop SUPERCOMPUTERS David Bombal · 5d ago Do CISOs Need a Code of Ethics? darkreading · 5d ago Malicious hackers exploit Cisco zero-day for highest access level at communications service provider CyberScoop · 5d ago CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms Microsoft Security Blog · 5d ago More Malicious OpenClaw Skills Threaten AI Supply Chain darkreading · 6d ago Cisco Advance Notification for Publication of July 1, 2026, Security Advisories Cisco Security Advisory · 6d ago Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have Cyber Defense Magazine · 6d ago Github got Hacked by CATS John Hammond · 6d ago Invisible By Design: Making Quantum-Safe Encryption The Easy Path Cyber Defense Magazine · 6d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 6d ago StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them Microsoft Security Blog · 6d ago In a first, a court takedown goes after two cybercrime tools at once CyberScoop · 6d ago Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming Cyber Defense Magazine · 6d ago Apple's MacOS Gap Lets Users Disable Security Tools darkreading · 6d ago Breaking the MSP Echo Chamber: The Power of Community Heimdal Security Blog · 6d ago StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader Securelist · 6d ago Open-source security is posing challenges governments can’t easily solve CyberScoop · 6d ago New at Forter: AI Agents Built to Amplify Your Team Blog – Forter · 6d ago FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems Recorded Future · 6d ago White House drastically shortens deadline for dropping quantum-vulnerable crypto Security - Ars Technica · 6d ago Scope of Salesforce Attacks Expands as Icarus Leaks Data darkreading · 6d ago Innovator Spotlight: NAKIVO Cyber Defense Magazine · 6d ago Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed Security Latest · 6d ago 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows darkreading · 6d ago Justice Department seizes infrastructure used by cyber scam and criminal marketplace CyberScoop · 6d ago This Dark Web Linux Backdoor Erases Its Own Footprints John Hammond · 6d ago Black Hat Europe 2025 | SCOMmand And Conquer - Attacking System Center Operations Manager Black Hat · 6d ago Black Hat USA 2026 | Welcome Video Black Hat · 7d ago Cybersecurity Outsourcing. Beyond Cost Cyber Defense Magazine · 7d ago Scattered Spider Hackers Plead Guilty on Day 1 of Trial Krebs on Security · 7d ago Algerian man charged with running two cybercrime marketplaces CyberScoop · 7d ago Black Hat Europe 2025 | China's Nexus APT Exploiting Ivanti Endpoint Manager Mobile Black Hat · 7d ago SocGholish Takedown Highlights Malicious TDS Threats darkreading · 7d ago Can AI Agents Find, Trust, and Choose Your Brand? Blog – Forter · 7d ago Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets Cyber Defense Magazine · 7d ago FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist darkreading · 7d ago Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data Cyber Defense Magazine · 7d ago Cloudflare patches Copy-Fail across every server in two days Technical Information Security Content & Discussion · 7d ago New Cisco RCE was fixed Technical Information Security Content & Discussion · 7d ago From Langflow to Monero: Inside CVE-2026-33017 Cryptominer Trend Micro Research, News, Perspectives · 7d ago The Purchase Scam Tactic Headed for the World Cup | Recorded Future Recorded Future · 7d ago Court rules SAVE database illegal, orders it dismantled CyberScoop · 7d ago DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories darkreading · 7d ago Data Breach with Eastman Kodak Company Cyber Defense Magazine · 7d ago They Created a Supercomputer in a Rack? David Bombal · 7d ago Trump executive orders speed up post-quantum migration, boost industry CyberScoop · 7d ago Following user outcry, AMD reinstates memory encryption in consumer CPUs Security - Ars Technica · 7d ago Guarding AI memory Microsoft Security Blog · 7d ago Black Hat Europe 2025 | RMPocalypse: A Catch-22 Breaking AMDs Confidential Computing Black Hat · 7d ago CVE-2026-25860 turn XSS to RCE Technical Information Security Content & Discussion · 7d ago OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos Security Latest · 8d ago Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign darkreading · 8d ago Black Hat Intercepted | James Holland, Palo Alto Networks Black Hat · 8d ago One intrusion, two cyberattackers: Uncovering parallel threat activity Microsoft Security Blog · 8d ago Intel agencies: Frontier AI models will reshape cybersecurity faster than expected CyberScoop · 8d ago Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities Cisco Security Advisory · 8d ago How attackers built a RAT on a Windows machine using its own .NET compiler Heimdal Security Blog · 8d ago He Thought He Was Secure; His Phone Number Was Stolen Anyway darkreading · 8d ago Miasma Worm Source Code Leaked + What NPM v12 Means for Developers | Threat Wire Hak5 · 8d ago Black Hat Europe 2025 | Taking Over Your Amazon Account With A Kindle Black Hat · 8d ago The World Cup Is Here… And So Are The Cyber Risks Cyber Defense Magazine · 8d ago Cloud Managed Services For Modern Cybersecurity To Secure Cloud Cyber Defense Magazine · 8d ago This Hacker Got Paid $50,000+ to Break Frontier AI Models NahamSec · 8d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 8d ago Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense Proofpoint News Feed · 8d ago A VBScript campaign distributed through WhatsApp deploying RMM software Securelist · 8d ago World Cup Scams Are Getting Harder to Spot Security Latest · 8d ago OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Proofpoint News Feed · 8d ago Attacker enables RDP, creates admin, erases evidence in ten seconds Heimdal Security Blog · 8d ago Exploiting Auth0 Defaults in XSS Attacks - elttam Technical Information Security Content & Discussion · 8d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 8d ago Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1) Technical Information Security Content & Discussion · 9d ago Build a Complete Free CCNA Home Lab in 2026 With No Gear David Bombal · 9d ago Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors Cyber Defense Magazine · 9d ago A Critical Deadline Is Approaching for Windows and Linux Security Security Latest · 9d ago Broken access control demo David Bombal · 9d ago HackTheBox - Nanocorp IppSec · 10d ago The Shadow AI Paradox: Governing Innovation At Machine Speed Cyber Defense Magazine · 10d ago Hackers Claim to Leak Stolen Madison Square Garden Data Security Latest · 10d ago ContinuumCon 2026 Redux! John Hammond · 10d ago Innovator Spotlight: Ensemble Cyber Defense Magazine · 10d ago Innovator Spotlight: Centrii Cyber Defense Magazine · 10d ago shadow AI is terrifying NetworkChuck · 10d ago Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 Technical Information Security Content & Discussion · 10d ago NSPM-12: The New Baseline for National Security Cybersecurity Cyber Defense Magazine · 11d ago Soft Skills for the Job Market: Resume Writing The Cyber Mentor · 11d ago Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities Cisco Security Advisory · 11d ago Will this replace PoE (Power over Ethernet)? David Bombal · 11d ago OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099) Technical Information Security Content & Discussion · 11d ago Stressors, AI Forcing Changes to Cybersecurity Teams darkreading · 11d ago Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration Technical Information Security Content & Discussion · 11d ago AutoJack: How a single page can RCE the host running your AI agent Microsoft Security Blog · 11d ago Microsoft discovers new lightweight backdoor that steals cryptocurrency Security - Ars Technica · 11d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 11d ago How the Peter Thiel-Linked Dialog Club Secretly Ranks Its Members Security Latest · 11d ago Authorities disrupt Evil Corp’s SocGholish botnet CyberScoop · 11d ago Congress tees up No FAKES Act, aiming at AI-generated deepfakes CyberScoop · 11d ago Novo Nordisk Breach Highlights Software Development Pipeline Risk darkreading · 11d ago Never look into a fiber cable! David Bombal · 11d ago Apple patches high-severity eavesdropping vulnerability in Beats Studio Buds Security - Ars Technica · 11d ago HTTPS Doesn't Hide This From Your ISP!! NetworkChuck · 11d ago Operation Escaneo Signals Shift in LatAm Threat Landscape darkreading · 11d ago FIFA Bug Exposes World Cup Streams to Remote Takeover darkreading · 11d ago CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance Technical Information Security Content & Discussion · 11d ago ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm Krebs on Security · 11d ago Salesforce Data Thefts Continue via Klue App Compromise darkreading · 12d ago Cisco Just Showed the Future of Networking NetworkChuck · 12d ago How software development’s speed obsession enabled TeamPCP’s chaos crusade CyberScoop · 12d ago Accenture shells out $4.18B on three companies in big industrial cybersecurity push CyberScoop · 12d ago Five Compliance Realities Federal Contractors Can’t Ignore Cyber Defense Magazine · 12d ago Get Out of Security Debt by Tackling the Exposure Problem darkreading · 12d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 12d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure Alerts · 12d ago Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT All CISA Advisories · 12d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 12d ago Schneider Electric EasyLogic T150 and Saitel DP All CISA Advisories · 12d ago AVer PTC cameras All CISA Advisories · 12d ago Rockwell Automation FactoryTalk Historian Site Edition All CISA Advisories · 12d ago AzeoTech DAQFactory All CISA Advisories · 12d ago Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products All CISA Advisories · 12d ago Mitsubishi Electric MELSEC iQ-F Series All CISA Advisories · 12d ago Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module All CISA Advisories · 12d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure All CISA Advisories · 12d ago Would you like some malware served at the very top of DuckDuckGo? Technical Information Security Content & Discussion · 12d ago How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras Security Latest · 12d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 12d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 12d ago EU Gets a Head Start in Developing 6G Network Security darkreading · 12d ago The UK Will Scan Asylum-Seekers’ Faces for Age Checks—Despite Knowing the Tech Is Flawed Security Latest · 12d ago PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM Trend Micro Research, News, Perspectives · 12d ago Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update Technical Information Security Content & Discussion · 12d ago What is Clam AV (free & open source )? David Bombal · 12d ago Massive breach spills credentials for thousands of sensitive networks Security - Ars Technica · 12d ago This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity NahamSec · 12d ago News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies The Last Watchdog · 12d ago "Dangerous" AI models are coming no matter what Security - Ars Technica · 12d ago News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk The Last Watchdog · 12d ago Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability Cisco Security Advisory · 13d ago Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability Cisco Security Advisory · 13d ago Cisco Webex App Open Redirect Vulnerability Cisco Security Advisory · 13d ago Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April CyberScoop · 13d ago Cyber Security Market Insights & Trends Driving The Next Wave Of Protection Cyber Defense Magazine · 13d ago Windows and Linux users: The deadline to update Secure Boot keys is near Security - Ars Technica · 13d ago QoS Policies to Restrict EDR Traffic and Detection Strategies Technical Information Security Content & Discussion · 13d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 13d ago Getting a CVE Without Shipping Slop Technical Information Security Content & Discussion · 13d ago PrizeBuzz phishing network analysis Technical Information Security Content & Discussion · 13d ago Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Trend Micro Research, News, Perspectives · 13d ago State Digital Surveillance Risk Landscape Recorded Future · 13d ago Shark Jacked my LAN 🦈 Hak5 · 13d ago Lawmakers leery about Trump administration’s Anthropic order CyberScoop · 13d ago News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails The Last Watchdog · 13d ago AI’s constant patching treadmill can be a security problem CyberScoop · 13d ago 27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass Technical Information Security Content & Discussion · 13d ago Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ Society Security Latest · 13d ago AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns Cyber Defense Magazine · 13d ago Learn Linux in 180s - history command David Bombal · 13d ago News alert: GitGuardian adds endpoint protection as developer laptops become credential troves The Last Watchdog · 13d ago ‘Dangerous’ AI Models Are Coming No Matter What Security Latest · 13d ago Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability Cisco Security Advisory · 13d ago Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability Cisco Security Advisory · 13d ago TCM Security Summer Sale is Here! The Cyber Mentor · 14d ago A case for how to shape ‘ingredient lists’ for AI models CyberScoop · 14d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 14d ago Copilot Cowork is now generally available Microsoft 365 Blog · 14d ago Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions Cyber Defense Magazine · 14d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 14d ago Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP All CISA Advisories · 14d ago Rockwell Automation RSLinx All CISA Advisories · 14d ago Rockwell Automation FLEX I/O EtherNet/IP Adapters All CISA Advisories · 14d ago Rockwell Automation FactoryTalk Analytics PavilionX All CISA Advisories · 14d ago Rockwell Automation CompactLogix All CISA Advisories · 14d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 14d ago Critical Copilot vulnerability allowed hackers to steal 2FA code from users Security - Ars Technica · 14d ago News alert: Varist announces AI-scale malware detection for healthcare and medical imaging The Last Watchdog · 14d ago Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk Securelist · 14d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 14d ago The State of AI Risk Management in 2026 Heimdal Security Blog · 14d ago The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine Recorded Future · 14d ago Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability Cisco Security Advisory · 14d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 14d ago Google exposes China espionage group that’s been lurking in networks undetected since 2023 CyberScoop · 14d ago What is an IDOR? Google and Uber got hacked this way. David Bombal · 14d ago Users cry foul after AMD stripped memory crypto from its consumer CPUs Security - Ars Technica · 14d ago Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE Technical Information Security Content & Discussion · 14d ago I was wrong about VPNs NetworkChuck · 15d ago Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat CyberScoop · 15d ago SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon Technical Information Security Content & Discussion · 15d ago Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection? Cyber Defense Magazine · 15d ago Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It Heimdal Security Blog · 15d ago How I Made $30,000 Hacking Broken Access Control NahamSec · 15d ago $30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover NahamSec · 15d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 15d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 15d ago Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses Security Latest · 15d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 15d ago ContinuumCon 2026 - Day 3 John Hammond · 15d ago Shadow AI: What every network engineer must know David Bombal · 16d ago CMMC Is Exposing A Major Gap In The Defense Supply Chain Cyber Defense Magazine · 16d ago Researcher accidentally gained access to a threat actor-controlled phishing website Technical Information Security Content & Discussion · 16d ago ContinuumCon 2026 - Day 2 John Hammond · 16d ago PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs Technical Information Security Content & Discussion · 16d ago MeshCentral: From XSS to RCE Technical Information Security Content & Discussion · 16d ago Anthropic disables new models after government calls them a national security concern CyberScoop · 16d ago HackTheBox - VariaType IppSec · 17d ago Zero Trust For AI In Defense Networks Cyber Defense Magazine · 17d ago The FCC Wants to Kill Burner Phones Security Latest · 17d ago Getting the PID from random numbers in PHP Technical Information Security Content & Discussion · 17d ago The Axios npm compromise was visible in registry metadata before anyone ran npm install Technical Information Security Content & Discussion · 17d ago ContinuumCon 2026 - Day 1 John Hammond · 17d ago FBI takes down massive China-based cybercrime network that caused $1.9B in losses CyberScoop · 17d ago Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs Technical Information Security Content & Discussion · 17d ago Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability Cisco Security Advisory · 17d ago ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed darkreading · 17d ago What is SNORT? Free open source IDS David Bombal · 17d ago PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data Security - Ars Technica · 17d ago US, France, and Italian authorities shut down massive deepfake porn site CyberScoop · 17d ago Conti ransomware group member pleads guilty, faces up to 20 years in prison CyberScoop · 17d ago ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw CyberScoop · 18d ago Free Compromise Detection for GitHub Repos - Tracebit Community Edition Technical Information Security Content & Discussion · 18d ago Your Next Insider Threat May Be an AI Coworker Heimdal Security Blog · 18d ago Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE) Technical Information Security Content & Discussion · 18d ago Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery Technical Information Security Content & Discussion · 18d ago Claude Fable 5 Doesn't Change the Mythos Security Story darkreading · 18d ago Why Most Cyber Resilience Programs Fail Before The First Incident Cyber Defense Magazine · 18d ago The OSI Model and Its Two Missing Layers Heimdal Security Blog · 18d ago Developers React to the 105-Second Github Chain Reaction | Threat Wire Hak5 · 18d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 18d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 18d ago CyberCorps is adapting to AI. The budget isn’t keeping up. CyberScoop · 18d ago Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs Technical Information Security Content & Discussion · 18d ago Payload Podcast 008 - Ryan Hausknecht John Hammond · 18d ago Phishing Attack Volume Down 20%, But Risk Still Rising darkreading · 18d ago Governing Claude Enterprise in Environments Where Inline Controls Can't Go Trend Micro Research, News, Perspectives · 18d ago Grok Is Still Hosting Sexualized Deepfakes of Famous Women Security Latest · 18d ago Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules Technical Information Security Content & Discussion · 18d ago Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure darkreading · 18d ago Why you never touch fiber optic cables (the tips) David Bombal · 18d ago Any solutions we can use? cybersecurity · 18d ago Russian national charged in connection with Void Blizzard espionage campaign CyberScoop · 18d ago DIY pwnagotchi-like device on esp32 hacking: security in practice · 19d ago Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it Reverse Engineering · 19d ago Possible targeted attack cybersecurity · 19d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline cybersecurity · 19d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 19d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 19d ago Facebook messenger to text cybersecurity · 19d ago Claude Fable 5: mid-tier results on coding tasks Technical Information Security Content & Discussion · 19d ago Drug Sites Hijacked Spotify’s Search Ranking Through Fake Podcasts Security Latest · 19d ago US charges suspected Russian hacker with facilitating cyber campaign For [Blue|Purple] Teams in Cyber Defence · 19d ago Flipper Blackhat + Bjorn hacking: security in practice · 19d ago Segmentation Works for OT If Operators Are Paying Attention darkreading · 19d ago Managing Solution Agents cybersecurity · 19d ago Nottingham University data breach affects over 450,000 students cybersecurity · 19d ago SWGs that support 3rd party external DNS resolver cybersecurity · 19d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers cybersecurity · 19d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game Reverse Engineering · 19d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG cybersecurity · 19d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia For [Blue|Purple] Teams in Cyber Defence · 19d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch cybersecurity · 19d ago Do you think AI is making hacking easier or harder hacking: security in practice · 19d ago Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration Cyber Defense Magazine · 19d ago Phishing awareness training resulting in ignoring company comms? cybersecurity · 19d ago How are you analyzing Android malware nowadays? cybersecurity · 19d ago Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work Technical Information Security Content & Discussion · 19d ago Hackers Exploit Langflow Vulnerability for Remote Code Execution cybersecurity · 19d ago Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research cybersecurity · 19d ago NEED SOME GUIDANCE cybersecurity · 19d ago Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps Security Latest · 19d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 19d ago Yarbo Android/iOS Mobile Application and Cloud Infrastructure All CISA Advisories · 19d ago Naxclow IoT Platform All CISA Advisories · 19d ago Brickcom Cameras All CISA Advisories · 19d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 19d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Malware Analysis & Reports · 19d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Reverse Engineering · 19d ago What can i do left? PSN hacking: security in practice · 19d ago Help setting up local encryption on my pc cybersecurity · 19d ago Hacking Google with A.I. for $500,000 Technical Information Security Content & Discussion · 19d ago Agentic AI on Cybersecurity cybersecurity · 19d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 19d ago DoD 0-days Typically Come Down to Authorization Failures cybersecurity · 19d ago HDD cybersecurity · 19d ago Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets cybersecurity · 19d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 19d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 19d ago Prompt injection: attacking the analyst's AI Technical Information Security Content & Discussion · 19d ago How can we test the firmware code/images security? cybersecurity · 19d ago 20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004 cybersecurity · 19d ago Proxmark5 campaign ending in less than 18 hours. hacking: security in practice · 19d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 For [Blue|Purple] Teams in Cyber Defence · 19d ago GreatXML: GreatXML bitlocker bypass vulnerability For [Blue|Purple] Teams in Cyber Defence · 19d ago GitHub announces npm security changes to tackle supply-chain attacks cybersecurity · 19d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan For [Blue|Purple] Teams in Cyber Defence · 19d ago The ‘Miasma’ worm source code briefly leaked on GitHub cybersecurity · 19d ago CISA Rewrites Federal Patching Requirements for AI Threat Era cybersecurity · 19d ago What is the difference between Regular TLS and Mutual TLS? cybersecurity · 19d ago Every employee's password was stored in a single Excel file cybersecurity · 19d ago npm v12 is changing how dependencies are installed to reduce supply-chain risk cybersecurity · 19d ago How to bypass speed queen coin slot for washer and dryer hacking: security in practice · 19d ago LIVE: 🕵️ CTF Prize Draw | Cybersecurity The Cyber Mentor · 19d ago Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia? cybersecurity · 19d ago Drive Firmware Security - Phison S11 Reverse Engineering · 19d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue For [Blue|Purple] Teams in Cyber Defence · 19d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion For [Blue|Purple] Teams in Cyber Defence · 19d ago How good Microsoft Defender for storage? cybersecurity · 19d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default For [Blue|Purple] Teams in Cyber Defence · 19d ago GreatXML bitlocker bypass vulnerability cybersecurity · 19d ago Struggle cybersecurity · 19d ago Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications? cybersecurity · 19d ago Chinese, N. Korean Threat Groups Build on Asia-Pacific Success darkreading · 19d ago Recorded Future Launches Impact and Metrics Dashboard Recorded Future · 19d ago Cyber-Enabled Maritime Sanctions Evasion Recorded Future · 19d ago Wiz launches Cloud Security Job Board cybersecurity · 19d ago Physical Project Ideas cybersecurity · 19d ago How can I get into cybersecurity while studying Information Systems Engineering? cybersecurity · 19d ago Miasma-style supply chain attacks For [Blue|Purple] Teams in Cyber Defence · 19d ago Cloud Security job board cybersecurity · 19d ago Continuous learning cybersecurity · 19d ago Self-hosting stuff for when things get ugly hacking: security in practice · 19d ago CISA Rewrites Federal Patching Requirements for AI Threat Era darkreading · 19d ago Angry bug hunter with Microsoft beef drops new Windows 0-day cybersecurity · 19d ago OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers CyberScoop · 19d ago Bug Bounty Research Triggers ServiceNow Security Alert darkreading · 19d ago Mid-30s, stuck in web pentesting, and wondering what to do ? cybersecurity · 19d ago AI Risk Worries Insurers & Businesses Alike darkreading · 19d ago Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM cybersecurity · 19d ago Is Microsoft Purview really secure when using Copilot? cybersecurity · 19d ago Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review Technical Information Security Content & Discussion · 19d ago News alert: Cloud security report finds fragmented tools widening the cloud complexity gap The Last Watchdog · 19d ago Malware Includes Taboo In Text To Prevent LLM Analysis hacking: security in practice · 19d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet For [Blue|Purple] Teams in Cyber Defence · 19d ago Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature? cybersecurity · 19d ago added Mac support for my corporate hacking game, demo on Steam hacking: security in practice · 19d ago IDA 9.4 Beta | Hex-Rays Docs Reverse Engineering · 19d ago Nee academic references for Hashcat's 'Next Big Bang' log cybersecurity · 19d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs For [Blue|Purple] Teams in Cyber Defence · 19d ago CISA released BOD 26-04: A new federal government vulnerability management strategy? cybersecurity · 19d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace For [Blue|Purple] Teams in Cyber Defence · 20d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days cybersecurity · 20d ago IMPACT Roadshow Recap: Getting Ready for Agentic Commerce Blog – Forter · 20d ago added Mac support to my corporate hacking sim. Demo now available on Steam cybersecurity · 20d ago Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet darkreading · 20d ago CISA directive orders agencies to prioritize vulnerability patching in a new way CyberScoop · 20d ago We post-trained a model for offensive security instead of teaching it to refuse Technical Information Security Content & Discussion · 20d ago Catfished hacking: security in practice · 20d ago Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte) cybersecurity · 20d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper Malware Analysis & Reports · 20d ago Students' data taken in major University of Nottingham cyber-attack cybersecurity · 20d ago Has unmanaged external file sharing ever burned you? cybersecurity · 20d ago Who Runs the Ransomware Group ‘The Gentlemen?’ Krebs on Security · 20d ago Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers cybersecurity · 20d ago Trane Tracer HVAC cybersecurity issues Reverse Engineering · 20d ago Need feedback on my presentation cybersecurity · 20d ago Compensating controls besides admin credentials being needed to download software on employee endpoints cybersecurity · 20d ago OpenSSL PKCS#7 CVE-2026-45447 cybersecurity · 20d ago Testing offensive AI agents in a cloud lab with deception tech For [Blue|Purple] Teams in Cyber Defence · 20d ago What The Cybersecurity Industry Knows And Will Not Say Cyber Defense Magazine · 20d ago Presentation Question cybersecurity · 20d ago What did they mean by this? One of us? hacking: security in practice · 20d ago How to Stay Ahead of Deepfake Evolution in 2026 cybersecurity · 20d ago How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026 Technical Information Security Content & Discussion · 20d ago FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster Technical Information Security Content & Discussion · 20d ago France’s Government Messaging App Tchap Got Breached cybersecurity · 20d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap Malware Analysis & Reports · 20d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 20d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 20d ago certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA" Technical Information Security Content & Discussion · 20d ago Where's the fix for MiniPlasma? cybersecurity · 20d ago BlackSun - Defender for Endpoint on macOS Technical Information Security Content & Discussion · 20d ago ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances cybersecurity · 20d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges hacking: security in practice · 20d ago GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline) Technical Information Security Content & Discussion · 20d ago Internships cybersecurity · 20d ago Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS cybersecurity · 20d ago Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows cybersecurity · 20d ago Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam Technical Information Security Content & Discussion · 20d ago Looking for a Reliable Cybersecurity Provider for a School in North Sydney cybersecurity · 20d ago Early Operational Visibility cybersecurity · 20d ago Benchmarking n-day exploit generation [via AI] For [Blue|Purple] Teams in Cyber Defence · 20d ago how are you actually managing ai agents in production? cybersecurity · 20d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) Reverse Engineering · 20d ago Al app builders: How are you handling security questionnaires when selling your product? cybersecurity · 20d ago [ Removed by Reddit ] cybersecurity · 20d ago How are all of doing with THE AI model thats big news currently?? cybersecurity · 20d ago Whoops! I did it again. I patched Windows Kernel at Milan0day 2026 For [Blue|Purple] Teams in Cyber Defence · 20d ago Microsoft Defender now monitors RPC activity For [Blue|Purple] Teams in Cyber Defence · 20d ago Skill to Scan your Codebase cybersecurity · 20d ago RoguePlanet: RoguePlanet Windows Defender Vulnerability For [Blue|Purple] Teams in Cyber Defence · 20d ago Miasma-style supply chain attacks cybersecurity · 20d ago FCaptcha v1.12: Catching AI Agents That Drive Real Browsers cybersecurity · 20d ago Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones cybersecurity · 20d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs cybersecurity · 20d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs Technical Information Security Content & Discussion · 20d ago AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say cybersecurity · 20d ago GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 Trend Micro Research, News, Perspectives · 20d ago 2026 FIFA World Cup: What Public Safety Officials Need to Know Recorded Future · 20d ago China's Noncombatant Evacuation Operations: 2005–2025 Recorded Future · 20d ago Huntress Stack (MS Defender or SentinelOne) cybersecurity · 20d ago META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT cybersecurity · 20d ago OptOutCode – A Privacy4Cars Universal Opt-Out Concept hacking: security in practice · 20d ago I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in) For [Blue|Purple] Teams in Cyber Defence · 20d ago A Record-Breaking Patch Tuesday for June 2026 Krebs on Security · 20d ago The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life darkreading · 20d ago FBI is announcing Operation Riptide cybersecurity · 20d ago Blame AI: Patch Tuesday Hits Record 206 CVEs darkreading · 20d ago ServiceNow confirmed some customer instances were breached. cybersecurity · 20d ago Which are some of the best Cybersecurity / OT Security events that happen in GCC? cybersecurity · 20d ago DF/IR Community cybersecurity · 20d ago Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed Security - Ars Technica · 20d ago Chaotic Eclipse's new RoguePlanet cybersecurity · 20d ago Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address darkreading · 20d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace cybersecurity · 20d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace Malware Analysis & Reports · 20d ago Microsoft breaks Patch Tuesday record with 206 vulnerabilities CyberScoop · 20d ago Thoughts on Automated Compliance? cybersecurity · 20d ago Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories darkreading · 20d ago A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available cybersecurity · 20d ago Apple’s Siri-AI, or more shouting into the void about “private” agents Technical Information Security Content & Discussion · 20d ago How do you make learning blue team security entertaining ? For [Blue|Purple] Teams in Cyber Defence · 20d ago North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says cybersecurity · 20d ago Microsoft has released a patch for the bitlocker bypass cybersecurity · 20d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. Reverse Engineering · 20d ago Please advices cybersecurity · 20d ago soc analyst l1 cybersecurity · 20d ago Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow cybersecurity · 20d ago Looking to move off KnowBe4, what are people actually using these days? cybersecurity · 20d ago Maximizing IOC Impact For [Blue|Purple] Teams in Cyber Defence · 20d ago Too Many Certs, Not Enough Experience — What’s the Best Next Step? cybersecurity · 21d ago Anthropic’s new model is Mythos on a leash CyberScoop · 21d ago Authenticating ARP and NDP cybersecurity · 21d ago Does anyone use rule feeds in 2026? cybersecurity · 21d ago [2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution For [Blue|Purple] Teams in Cyber Defence · 21d ago CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector CyberScoop · 21d ago Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations! cybersecurity · 21d ago Need a vm for practice cybersecurity · 21d ago Tips/Tricks to WFH as a SOC Analyst? cybersecurity · 21d ago Cybersecurity statistics of the week (June 1st - June 7th) cybersecurity · 21d ago Do YOU Need Antivirus in 2026? David Bombal · 21d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks For [Blue|Purple] Teams in Cyber Defence · 21d ago Where can GRC folks learn practical AppSec / DevSecOps without going full engineer? cybersecurity · 21d ago Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs darkreading · 21d ago I almost got “onboarded” into a malware campaign disguised as a job opportunity. cybersecurity · 21d ago Suspected North Korean actors use fake ‘coding assignments’ to steal crypto Proofpoint News Feed · 21d ago University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model cybersecurity · 21d ago High-severity vulnerability in Linux caused by a single faulty character Security - Ars Technica · 21d ago AI Blocklist - help cybersecurity · 21d ago Entra Agent ID from a Security Perspective For [Blue|Purple] Teams in Cyber Defence · 21d ago Cisco customers encounter another SD-WAN zero-day under attack CyberScoop · 21d ago Entra Agent ID from a Security Perspective Technical Information Security Content & Discussion · 21d ago Protecting AI workloads on Linux servers cybersecurity · 21d ago Exposing DoNex Ransomware Secrets with Malcore! cybersecurity · 21d ago What are the different Disaster Recovery scenarios your teams have tested on? cybersecurity · 21d ago someone actually leaked the Miasma supply chain attack toolkit source code on github cybersecurity · 21d ago X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection Technical Information Security Content & Discussion · 21d ago Rethinking Access Governance for AI Agents Cyber Defense Magazine · 21d ago Secrets to PNPT Debrief Success The Cyber Mentor · 21d ago Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility For [Blue|Purple] Teams in Cyber Defence · 21d ago WinGet - Code Execution, Persistence and Detection Strategies cybersecurity · 21d ago WinGet - Code Execution, Persistence and Detection Strategies Technical Information Security Content & Discussion · 21d ago Ransomware attack shuts Illinois high school until Wednesday cybersecurity · 21d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 21d ago Siemens KACO Blueplanet Inverters All CISA Advisories · 21d ago Schneider Electric EcoStruxure Panel Server All CISA Advisories · 21d ago Schneider Electric Modicon Network Managed Switches All CISA Advisories · 21d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 21d ago Ideas for demo cybersecurity · 21d ago Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please? cybersecurity · 21d ago Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares. cybersecurity · 21d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue Technical Information Security Content & Discussion · 21d ago Physical attack device cybersecurity · 21d ago Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer cybersecurity · 21d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 21d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 21d ago IT GRC News? cybersecurity · 21d ago Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again cybersecurity · 21d ago I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information Technical Information Security Content & Discussion · 21d ago What are the best risk-based vulnerability management tools for tracking active exploitation in 2026? For [Blue|Purple] Teams in Cyber Defence · 21d ago QuasarNix: Reverse Shell Detection with Machine Learning For [Blue|Purple] Teams in Cyber Defence · 21d ago Shifting L7 validation to the edge to stop DB resource exhaustion? cybersecurity · 21d ago Google Patches 5th Chrome Zero-Day Exploited in 2026 cybersecurity · 21d ago AI Agents May Always Fall for Prompt Injections Technical Information Security Content & Discussion · 21d ago Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go For [Blue|Purple] Teams in Cyber Defence · 21d ago EC Council CEH exam advice cybersecurity · 21d ago Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion For [Blue|Purple] Teams in Cyber Defence · 21d ago Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 For [Blue|Purple] Teams in Cyber Defence · 21d ago About NPower vs PerScholas cybersecurity · 21d ago Looking for a vulnerability to learn cybersecurity · 21d ago Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency For [Blue|Purple] Teams in Cyber Defence · 21d ago From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk cybersecurity · 21d ago UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season For [Blue|Purple] Teams in Cyber Defence · 21d ago Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) For [Blue|Purple] Teams in Cyber Defence · 21d ago Visual Studio Code 1.123: Delayed extension auto-updates For [Blue|Purple] Teams in Cyber Defence · 21d ago Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users. For [Blue|Purple] Teams in Cyber Defence · 21d ago Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, For [Blue|Purple] Teams in Cyber Defence · 21d ago Bad USB through charger? cybersecurity · 21d ago Recommendations for Discord community for latest AI security products cybersecurity · 21d ago StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams hacking: security in practice · 21d ago Vulnerability Summary for the Week of June 1, 2026 cybersecurity · 21d ago Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas cybersecurity · 21d ago Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars Recorded Future · 21d ago I feel like ive lost my passion to tinker after 6 years in the industry, anyone else? cybersecurity · 21d ago I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples cybersecurity · 21d ago really need help with project ideas for MSc cybersecurity · 21d ago Which Course for an almost-complete noob? (SANS.edu) cybersecurity · 21d ago SoFi confirms third-party data breach at Hong Kong subsidiary cybersecurity · 21d ago AI Slop Will Kill Cybersecurity Storytelling If We Let It darkreading · 21d ago For the 2nd time in weeks, Microsoft packages laced with credential stealer cybersecurity · 21d ago Iran Signed a Ceasefire — Its Hackers Didn't cybersecurity · 21d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages cybersecurity · 21d ago DSPM étude marche cybersecurity · 21d ago CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file cybersecurity · 21d ago Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks darkreading · 21d ago AppSec / Pentesting job market in Canada for experienced overseas applicants? cybersecurity · 21d ago Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients. cybersecurity · 21d ago Check Point VPN Flaw Exploited Since Early May darkreading · 21d ago Automation Playbooks - which ones would you not want to live without? cybersecurity · 21d ago Is it necessary/important to Hash and salt API Keys for a strictly internal use tool? cybersecurity · 21d ago Need review on the OMS Cybersecurity program from Georgia Tech? cybersecurity · 21d ago If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk cybersecurity · 21d ago 2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years cybersecurity · 21d ago Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement For [Blue|Purple] Teams in Cyber Defence · 21d ago How do you close an alert cybersecurity · 21d ago Iran Signed a Ceasefire — Its Hackers Didn't darkreading · 21d ago What cybersecurity certifications are great value for money? cybersecurity · 21d ago Boxes for CPENT cybersecurity · 21d ago For the 2nd time in weeks, Microsoft packages laced with credential stealer Security - Ars Technica · 21d ago SIEM: is it "SIM" or "SEEM" cybersecurity · 21d ago I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included) cybersecurity · 21d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment Malware Analysis & Reports · 21d ago How justdeleteme and justgetmydata work? cybersecurity · 21d ago Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint CyberScoop · 21d ago GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks. hacking: security in practice · 22d ago How CIAM Helps Boost Business Cyber Defense Magazine · 22d ago I need help - PCI DSS 4.0 requirement 11.6.1 cybersecurity · 22d ago How are you learning agent pen testing? cybersecurity · 22d ago HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified) For [Blue|Purple] Teams in Cyber Defence · 22d ago Cyber security intern cybersecurity · 22d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 22d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 22d ago Introducing Shark Jack Display 🦈 Hak5 · 22d ago Meta to take legal action against Israeli spyware company NSO cybersecurity · 22d ago Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit cybersecurity · 22d ago What's the best way to alert companies of a Glassworm copycat? cybersecurity · 22d ago How To Verify If A Site Is Legit? cybersecurity · 22d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 22d ago What is Flaresolverr cybersecurity · 22d ago Research: defenders using generative AI to simulate malware variants before they exist in the wild cybersecurity · 22d ago How are regulated orgs actually letting engineers use Claude Code / Copilot? cybersecurity · 22d ago Cyber security expo Manchester cybersecurity · 22d ago Content creations was both a blessing and a curse. #bugbounty NahamSec · 22d ago Remote Hiring Opened the Talent Pool — and the Fraud Surface cybersecurity · 22d ago Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it Technical Information Security Content & Discussion · 22d ago World Cloud Security Day Cyber Defense Magazine · 22d ago This Hacker Made $7,000 Hacking AI With One Email NahamSec · 22d ago EMBA firmware analysis framework v2.0.2 available - Party the big 2k Reverse Engineering · 22d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks cybersecurity · 22d ago What certs should I do during summer of 11th grade? cybersecurity · 22d ago CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) cybersecurity · 22d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 22d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 22d ago Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine cybersecurity · 22d ago Oxford University discloses data breach after careers platform hack cybersecurity · 22d ago Heimdal® Marks Six Years of Consecutive ISAE 3000 SOC 2 Type II Certification Heimdal Security Blog · 22d ago Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing cybersecurity · 22d ago Got this message from “SimBoss” cybersecurity · 22d ago PKCS12 Golang fork cybersecurity · 22d ago The AI security race needs accountability, not overregulation CyberScoop · 22d ago Malware Insights: Miasma Campaign cybersecurity · 22d ago 73 Microsoft GitHub repositories impacted by Miasma malware Malware Analysis & Reports · 22d ago 73 Microsoft GitHub repositories impacted by Miasma malware cybersecurity · 22d ago [Honeypot Research] Looking for volunteers to test telemetry/logs cybersecurity · 22d ago Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏 hacking: security in practice · 22d ago What is the condition of Bug Bounty program in the era of AI. cybersecurity · 22d ago Opening a cloned repo is no longer safe cybersecurity · 22d ago Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse cybersecurity · 22d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 22d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 22d ago Google Colab CLI opens runtimes to Claude Code and Codex cybersecurity · 22d ago VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks cybersecurity · 22d ago The AI governance gap no one is talking about: deployment-stage accountability cybersecurity · 22d ago Security Review Request — TID Linux Kernel Module For [Blue|Purple] Teams in Cyber Defence · 22d ago Building a safe, effective sandbox to enable Codex on Windows For [Blue|Purple] Teams in Cyber Defence · 22d ago Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. For [Blue|Purple] Teams in Cyber Defence · 22d ago About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection For [Blue|Purple] Teams in Cyber Defence · 22d ago BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection For [Blue|Purple] Teams in Cyber Defence · 22d ago Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution. For [Blue|Purple] Teams in Cyber Defence · 22d ago Unauthorized Onlyfans Payment Malware Analysis & Reports · 22d ago Free Study Resources for Comptia Cysa+ cybersecurity · 22d ago What's up with powershellforhackers.com? hacking: security in practice · 22d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 22d ago Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Trend Micro Research, News, Perspectives · 22d ago May 2026 CVE Landscape Recorded Future · 22d ago Hi there cybersecurity · 22d ago Final risk-based IT Audit interview round with Director and have no experience. Please help! cybersecurity · 22d ago Needed help cybersecurity · 22d ago HDD Firmware Hacking Part 1 Reverse Engineering · 22d ago [ Removed by Reddit ] cybersecurity · 22d ago UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service. For [Blue|Purple] Teams in Cyber Defence · 22d ago Career advice cybersecurity · 22d ago Do people really click on links from unknown numbers? hacking: security in practice · 22d ago PhD in cyber Security cybersecurity · 22d ago Built a password guessing game. Almost everyone stuck in level 5. cybersecurity · 22d ago OSINT (SOCIAL MEDIA) cybersecurity · 22d ago Beginner KQL project cybersecurity · 22d ago Question about WORM and encryption cybersecurity · 22d ago Update:Certified cyber security cybersecurity · 22d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction Reverse Engineering · 22d ago How to unlock whitelabeled uniview IPcam hacking: security in practice · 22d ago EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server. For [Blue|Purple] Teams in Cyber Defence · 22d ago Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental cybersecurity · 23d ago Can converted video files contain malware? hacking: security in practice · 23d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction) cybersecurity · 23d ago Malware that survives reinstalling the BIOS and OS cybersecurity · 23d ago Am I overthinking the x86 compatibility issues? how much friction am I actually facing? cybersecurity · 23d ago Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure cybersecurity · 23d ago Managing Microsoft Identity Is More Complicated Than It Looks cybersecurity · 23d ago Zhiyun Weebil-S Camera Gimbal BLE Protocol Reverse Engineering · 23d ago My work email got subscribed to a bunch of israel newsletters cybersecurity · 23d ago Shadow AI cybersecurity · 23d ago Rate limiting is not enough. What else can I use? cybersecurity · 23d ago CMMC Is Here, But AI Changes The Compliance Conversation Cyber Defense Magazine · 23d ago How To Avoid Potential Malware From Transferring To New Laptop cybersecurity · 23d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 cybersecurity · 23d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 23d ago Can't decide. cybersecurity · 23d ago looking for partners cybersecurity · 23d ago My edge is changing into bing when I search something cybersecurity · 23d ago Reverse Engineering the Garmin Running Dynamics BLE protocol Reverse Engineering · 23d ago Cybersecurity reality check cybersecurity · 23d ago [ Removed by Reddit ] cybersecurity · 23d ago EDRChoker: Choking The Telemetry Stream to Bypass Defenses Technical Information Security Content & Discussion · 23d ago Information Management cybersecurity · 23d ago Pwnd Blaster: Hacking your PC using your speaker without ever touching it For [Blue|Purple] Teams in Cyber Defence · 23d ago cygor: An modular asset discovery framework written in python to automate the repeating manual work For [Blue|Purple] Teams in Cyber Defence · 23d ago On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts. For [Blue|Purple] Teams in Cyber Defence · 23d ago Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors. For [Blue|Purple] Teams in Cyber Defence · 23d ago Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim For [Blue|Purple] Teams in Cyber Defence · 23d ago Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored) For [Blue|Purple] Teams in Cyber Defence · 23d ago The Privileged Roles Nobody Talks About For [Blue|Purple] Teams in Cyber Defence · 23d ago Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain... For [Blue|Purple] Teams in Cyber Defence · 23d ago Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis For [Blue|Purple] Teams in Cyber Defence · 23d ago 21 Zero-Days in FFmpeg For [Blue|Purple] Teams in Cyber Defence · 23d ago IronWorm Malware cybersecurity · 23d ago Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh? cybersecurity · 23d ago Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh? cybersecurity · 23d ago Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager cybersecurity · 23d ago depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research? For [Blue|Purple] Teams in Cyber Defence · 23d ago PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware Technical Information Security Content & Discussion · 23d ago Is a separate “clean” S3 bucket actually a security boundary for uploaded files? cybersecurity · 23d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass Technical Information Security Content & Discussion · 23d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass cybersecurity · 23d ago CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work For [Blue|Purple] Teams in Cyber Defence · 23d ago PenTest+ Exam cybersecurity · 23d ago Rooted your router lately? hacking: security in practice · 23d ago AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs cybersecurity · 23d ago The Detection & Response Chronicles: Covert Operations Through QEMU For [Blue|Purple] Teams in Cyber Defence · 23d ago The Interesting Case of WSL for Payload Staging For [Blue|Purple] Teams in Cyber Defence · 23d ago The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer For [Blue|Purple] Teams in Cyber Defence · 23d ago Ongoing Targeted Campaign Against US Law Firms For [Blue|Purple] Teams in Cyber Defence · 23d ago New China-Linked Cluster OP-512 For [Blue|Purple] Teams in Cyber Defence · 23d ago Looking for guidance cybersecurity · 23d ago 5$ to whoever can find the email of my old YouTube channel hacking: security in practice · 23d ago Before you attempt any OffSec certification, read what just happened to me cybersecurity · 24d ago Reporting Metrics for Management cybersecurity · 24d ago got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time cybersecurity · 24d ago This company is scaming people hacking: security in practice · 24d ago Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried cybersecurity · 24d ago HackTheBox - Facts IppSec · 24d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. cybersecurity · 24d ago AI Security Certificates cybersecurity · 24d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. For [Blue|Purple] Teams in Cyber Defence · 24d ago Guys is bug bounty dead? cybersecurity · 24d ago How are folks making it in bug bounty? cybersecurity · 24d ago How useful is it to require at least one uppercase letter in a password? cybersecurity · 24d ago Cybersecurity Improved Detection But Exposed a New Problem Cyber Defense Magazine · 24d ago Cyber security ! Is no more ? cybersecurity · 24d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 24d ago MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain For [Blue|Purple] Teams in Cyber Defence · 24d ago Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated For [Blue|Purple] Teams in Cyber Defence · 24d ago Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns For [Blue|Purple] Teams in Cyber Defence · 24d ago About ETW Internals: Architecture, Hooking, Tampering, and Detection For [Blue|Purple] Teams in Cyber Defence · 24d ago PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver For [Blue|Purple] Teams in Cyber Defence · 24d ago Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp For [Blue|Purple] Teams in Cyber Defence · 24d ago Async PICOs and Custom Beacon Wakeups in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 24d ago Enter the WasmForge: Compiling Sliver into WebAssembly For [Blue|Purple] Teams in Cyber Defence · 24d ago staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs For [Blue|Purple] Teams in Cyber Defence · 24d ago Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window For [Blue|Purple] Teams in Cyber Defence · 24d ago Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS For [Blue|Purple] Teams in Cyber Defence · 24d ago BOF Cocktails in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 24d ago Address Translation For [Blue|Purple] Teams in Cyber Defence · 24d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 24d ago Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months cybersecurity · 24d ago Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories cybersecurity · 24d ago Investigation into APT 5 and their inner workings of PLA Troop 61786 For [Blue|Purple] Teams in Cyber Defence · 24d ago How to train employees to feel when something's off? cybersecurity · 24d ago Building A Malware Lab From Scratch Part 2! Malware Analysis & Reports · 24d ago A modular autonomous-agent runtime written in C hacking: security in practice · 24d ago The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy For [Blue|Purple] Teams in Cyber Defence · 24d ago ALERT OVERLOAD cybersecurity · 24d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems For [Blue|Purple] Teams in Cyber Defence · 24d ago Magecart skimmer turns Stripe into a malware command server For [Blue|Purple] Teams in Cyber Defence · 24d ago Security advisory: Brute force attack on Dashlane user accounts For [Blue|Purple] Teams in Cyber Defence · 24d ago Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability For [Blue|Purple] Teams in Cyber Defence · 24d ago A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact). For [Blue|Purple] Teams in Cyber Defence · 24d ago IronWorm: Shai-Hulud's rustier cousin For [Blue|Purple] Teams in Cyber Defence · 24d ago Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate) Reverse Engineering · 24d ago CTO at NCSC Summary: week ending June 7th cybersecurity · 24d ago Weil reportedly pays up to $20 million after hackers steal client data For [Blue|Purple] Teams in Cyber Defence · 24d ago CTO at NCSC Summary: week ending June 7th For [Blue|Purple] Teams in Cyber Defence · 24d ago A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled cybersecurity · 24d ago defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize For [Blue|Purple] Teams in Cyber Defence · 24d ago 1-Click GitHub Token Stealing via a VSCode Bug For [Blue|Purple] Teams in Cyber Defence · 24d ago The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds For [Blue|Purple] Teams in Cyber Defence · 24d ago JHT Course Launch! Windows Maldev 6 John Hammond · 24d ago Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub cybersecurity · 24d ago Detecting npm Native Addon Malware: node-gyp Abuse Malware Analysis & Reports · 24d ago AppSec Engineer Interview Stories cybersecurity · 24d ago [OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps. cybersecurity · 24d ago Multi-layer sandbox for native code execution on Linux with no external deps. For [Blue|Purple] Teams in Cyber Defence · 24d ago Is there a safe way to continue using (unsupported) Windows 10? cybersecurity · 24d ago Is Splunk suitable for smaller Enterprises? cybersecurity · 24d ago Has anyone else had MFA prompt fatigue issues with users? cybersecurity · 24d ago Data Scrubbing from Databases cybersecurity · 24d ago Best Certificates? cybersecurity · 24d ago Rant cybersecurity · 24d ago New York passes data center moratorium and consumer protections as environmental, and housing proposals stall cybersecurity · 24d ago Cyber attackers have a new favorite, the browser cybersecurity · 24d ago Looking to get into cybersecurity in web3 cybersecurity · 24d ago Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests cybersecurity · 24d ago Should i use email 2fa or only auth and phone number? cybersecurity · 24d ago Can I break into cybersecurity with a white collar felony? cybersecurity · 24d ago Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale cybersecurity · 24d ago How a USB-connected speaker can infect a PC without ever being touched Security - Ars Technica · 24d ago How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time? cybersecurity · 24d ago What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent? cybersecurity · 24d ago Innovator Spotlight: Airrived Cyber Defense Magazine · 24d ago How Hard is This cybersecurity · 24d ago Reverse Engineering Crazy Taxi, Part 3 Reverse Engineering · 24d ago Ghidra 12.1.2 has been released! Reverse Engineering · 24d ago Installed Fake Codex hidden as a google site cybersecurity · 24d ago Virustital scan result help cybersecurity · 24d ago CrowdStrike Turned an AI Wave Into Its Best Quarter Ever cybersecurity · 24d ago ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more hacking: security in practice · 24d ago Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions? cybersecurity · 24d ago I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now cybersecurity · 24d ago Being a Security Engineer? Which AI-powered tools are you using on a daily basis? cybersecurity · 25d ago Over 900 US gas station tank gauge systems exposed to attacks cybersecurity · 25d ago Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person cybersecurity · 25d ago SIEM is broken in the AI agents era cybersecurity · 25d ago TCM Security CTF Walkthrough The Cyber Mentor · 25d ago Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption Technical Information Security Content & Discussion · 25d ago Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected cybersecurity · 25d ago Extending a map tool for Cataclismo Reverse Engineering · 25d ago Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away CyberScoop · 25d ago Keeping Secrets Out of Logs Technical Information Security Content & Discussion · 25d ago Phantom Gyp npm Worm Abuses node-gyp Build Hooks cybersecurity · 25d ago Certified cybersecurity ISC2 cybersecurity · 25d ago Help studying for OSCP cybersecurity · 25d ago The current state of Threat Intelligence Tooling cybersecurity · 25d ago Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware cybersecurity · 25d ago I've been reverse engineering a lost 2010 horse MMO and I need contributors Reverse Engineering · 25d ago Cloud Security In Practice Cyber Defense Magazine · 25d ago We tested offensive AI agents against deception technology cybersecurity · 25d ago A matter that I have been losing my sleep over cybersecurity · 25d ago Any experience with Rootly or incident.io for cyber incident management? cybersecurity · 25d ago CTIA Study Resources & Preparation Advice? cybersecurity · 25d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 25d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 25d ago Black hat uk vs brucon cybersecurity · 25d ago Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier) Technical Information Security Content & Discussion · 25d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks cybersecurity · 25d ago NIS2 hits railway hard cybersecurity · 25d ago Introducing Package Proxy: supply-chain safety checks without client-side software For [Blue|Purple] Teams in Cyber Defence · 25d ago I need help guys… :( cybersecurity · 25d ago Question from the Seniors cybersecurity · 25d ago China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware cybersecurity · 25d ago AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer For [Blue|Purple] Teams in Cyber Defence · 25d ago Can one reveal the asterisks in an email? hacking: security in practice · 25d ago what certs have u seen in ai security related job posts ? cybersecurity · 25d ago How is the Security Architecture / Strategic IT Security process structured in your organization? cybersecurity · 25d ago Proxmark3 vs Proxmark5 Side by Side hacking: security in practice · 25d ago Should I go for it? hacking: security in practice · 25d ago What's happening in cybersecurity job market in US and Europe these days? cybersecurity · 25d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links Malware Analysis & Reports · 25d ago Has any of you pivoted from GRC to CTI? cybersecurity · 25d ago Up-date-list of cybercrime types? cybersecurity · 25d ago HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes Reverse Engineering · 25d ago What else should I learn to build a strong cybersecurity foundation? cybersecurity · 25d ago zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS) For [Blue|Purple] Teams in Cyber Defence · 25d ago Hackerone interview cybersecurity · 25d ago Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix cybersecurity · 25d ago The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory For [Blue|Purple] Teams in Cyber Defence · 25d ago VerdantBamboo: Just Another BRICKSTORM in the Firewall For [Blue|Purple] Teams in Cyber Defence · 25d ago AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID For [Blue|Purple] Teams in Cyber Defence · 25d ago MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code For [Blue|Purple] Teams in Cyber Defence · 25d ago IronWorm Supply Chain Malware Hits npm For [Blue|Purple] Teams in Cyber Defence · 25d ago FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel For [Blue|Purple] Teams in Cyber Defence · 25d ago FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad For [Blue|Purple] Teams in Cyber Defence · 25d ago You do surprise me.exe: An unexpected executable in Hola Browser For [Blue|Purple] Teams in Cyber Defence · 25d ago Testing URL Rewriting? cybersecurity · 25d ago Got an internship in IAM with no qualifications and no soft skills cybersecurity · 25d ago Work Hours of DFIR/Cloud Security vs Pentest cybersecurity · 25d ago Narcissistic Tech Leader.... cybersecurity · 25d ago Anyone else's firewall logs just explode after midnight? cybersecurity · 25d ago I'm replacing myself.. at least the boring parts cybersecurity · 25d ago Anyone else dealing with these phantom login attempts from China? cybersecurity · 25d ago Multi-layer sandbox for native code execution on Linux with no external deps. Reverse Engineering · 25d ago Best way to fully clear windows and set everything up securely (pc, accounts etc) cybersecurity · 25d ago IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks cybersecurity · 25d ago Soc analyst cybersecurity · 25d ago Do companies actually require cybersecurity insurance cybersecurity · 25d ago Why Holistic Sourcing Wins: The Numbers Behind the Recorded Future Advantage Recorded Future · 25d ago Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header hacking: security in practice · 25d ago Certification Questions | LIVE AMA | Summer of CCNA NetworkChuck · 25d ago Hill Dems hammer GOP for $250M CISA budget cut CyberScoop · 25d ago Uncommon/Unusual CrowdStrike Alerts cybersecurity · 25d ago Dashlane explains how attackers managed to download encrypted password vaults Security - Ars Technica · 25d ago Cyber analyst: law firm or bank cybersecurity · 25d ago best free av and how do i properly setup passwords? cybersecurity · 25d ago Five 9 Vulnerability cybersecurity · 25d ago Failed to verify LHOST error for long links in metasploit hacking: security in practice · 25d ago CVE Lite CLI closes dependency gap — but won't stop modern threats cybersecurity · 25d ago Scope change cybersecurity · 25d ago We just stopped a social engineering attack on our service desk. Here’s how it played out. cybersecurity · 25d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Reverse Engineering · 25d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Technical Information Security Content & Discussion · 25d ago Your AI agent could become your biggest insider threat CyberScoop · 25d ago What is the most underestimated cybersecurity risk right now? cybersecurity · 25d ago Update: Company is paying for any certification, which should I obtain? Except Sans cybersecurity · 26d ago New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification cybersecurity · 26d ago Anyone else's firewall vendor docs a total nightmare? cybersecurity · 26d ago Your opinions about a learning style cybersecurity · 26d ago Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks cybersecurity · 26d ago BIG SHOW TODAY & AI vibes John Hammond · 26d ago New IronWorm malware hits 36 packages in npm supply-chain attack cybersecurity · 26d ago Is Marauder available for ESP32-S3 Mini? hacking: security in practice · 26d ago Anyone else see their firewall logs just explode after a cloud update? cybersecurity · 26d ago Gemini whatsapp hacking: security in practice · 26d ago Are certifications necessary to get a job in cybersecurity? cybersecurity · 26d ago China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint News Feed · 26d ago Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass) cybersecurity · 26d ago Is retyping and translating textbooks too inefficient for CS/Cybersecurity? cybersecurity · 26d ago Free Microsoft Enterprise Security Assessment: Worth It cybersecurity · 26d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 26d ago How are organizations preparing for AI-generated phishing attacks? cybersecurity · 26d ago Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js Technical Information Security Content & Discussion · 26d ago Inside the race to adapt to an AI-powered security world cybersecurity · 26d ago 127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For cybersecurity · 26d ago Inside the race to adapt to an AI-powered security world CyberScoop · 26d ago Microsoft blames unexpected Windows driver updates on caching issue cybersecurity · 26d ago Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance) cybersecurity · 26d ago Enter the WasmForge: Compiling Sliver into WebAssembly Technical Information Security Content & Discussion · 26d ago Your CPU model leaks through the browser via WASM timing differences cybersecurity · 26d ago LSASS/Defender/CTFMON analysis For [Blue|Purple] Teams in Cyber Defence · 26d ago Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing Cyber Defense Magazine · 26d ago Software supply chain attacks: check your dependencies For [Blue|Purple] Teams in Cyber Defence · 26d ago void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies Reverse Engineering · 26d ago Chinese Cybercrime Group in Spotlight for Record Campaign Pace cybersecurity · 26d ago NAVTOR NavBox All CISA Advisories · 26d ago Hitachi Energy MACH HiDraw All CISA Advisories · 26d ago Hitachi Energy ITT600 Explorer All CISA Advisories · 26d ago B&R PPT30 Operating System All CISA Advisories · 26d ago Hitachi Energy RTU500 All CISA Advisories · 26d ago Extremely suspicious behaviour by memu emulator Malware Analysis & Reports · 26d ago Security Engineer 2 interview at Amazon coming up - What to expect? cybersecurity · 26d ago A researcher spent $1,500 testing if LLMs could hack a vulnerable app cybersecurity · 26d ago Help with university internship cybersecurity · 26d ago Are MCP servers becoming the next API security nightmare? cybersecurity · 26d ago Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator For [Blue|Purple] Teams in Cyber Defence · 26d ago What's the cybersecurity lesson you learned the hard way? cybersecurity · 26d ago ISO 27001 Surveillance audit vs Full recertification cybersecurity · 26d ago How important it is to get paid Cybersecurity certificates ? cybersecurity · 26d ago Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process cybersecurity · 26d ago Soc to Architecture cybersecurity · 26d ago Does "example file vulnerability" exists? cybersecurity · 26d ago VS code forces 2 hour cool down for most integrations. cybersecurity · 26d ago Company laptop isolated after Brave/Tor alert - should I be worried? cybersecurity · 26d ago Does anyone know how to send false positive to SOCradar ? virus total cybersecurity · 26d ago Looking for people to team up for Bug Bounties & CTFs cybersecurity · 26d ago Signal Without Smartphone cybersecurity · 26d ago I found a trojan on my pc and now im scared my private calls got leaked cybersecurity · 26d ago Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests cybersecurity · 26d ago CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog cybersecurity · 26d ago How do you change users behavior through awareness training? cybersecurity · 26d ago AI-built ransomware toolkit automates EDR evasion, AD discovery cybersecurity · 26d ago 29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection) For [Blue|Purple] Teams in Cyber Defence · 26d ago Safe Rust API for wolfSSL/wolfCOSE hacking: security in practice · 26d ago Safe Rust API for wolfSSL/wolfCOSE cybersecurity · 26d ago Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma) cybersecurity · 26d ago AMD GPU Users might be compromised cybersecurity · 26d ago [ Removed by Reddit ] cybersecurity · 26d ago Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information cybersecurity · 26d ago CISA warns of cyberattacks targeting fuel tank monitoring systems cybersecurity · 26d ago [CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF cybersecurity · 26d ago how to get good at cyber security? cybersecurity · 26d ago Anyone use CrunchAtlas? cybersecurity · 26d ago Prompt monitoring laughs cybersecurity · 26d ago Malicious Payload in ai-sdk-ollama npm Package cybersecurity · 26d ago Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24) cybersecurity · 26d ago Resource Exhaustion hacking: security in practice · 26d ago what the HELL is dsztfso? cybersecurity · 26d ago Open Source - 2500 New MITRE Mutations For [Blue|Purple] Teams in Cyber Defence · 26d ago Yubikey Alternative....? cybersecurity · 26d ago Hiring cybersecurity · 26d ago Malware Malware Analysis & Reports · 26d ago CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing cybersecurity · 26d ago Threats to the 2026 FIFA World Cup Recorded Future · 26d ago Remembering Sir Alex Younger Recorded Future · 26d ago Agent-Ready: How to Prepare Your Site for AI-Driven Commerce Blog – Forter · 26d ago Certification Advice cybersecurity · 26d ago Question about Linux kernel TLS ULP disclosed June 2 to oss-security cybersecurity · 26d ago European authorities crack down on illegal streaming networks CyberScoop · 26d ago An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this? cybersecurity · 26d ago How to Rob a Data Center (new article on data center physical security) cybersecurity · 26d ago Hermes has a Home Assistant skill and it's unreal! NetworkChuck · 26d ago US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server cybersecurity · 26d ago Is it worth taking the EC councils masters program?? Are they legit /2026 cybersecurity · 26d ago Mid-level AppSec engineers: what do you actually study to prep for interviews? cybersecurity · 26d ago Automated Fault Injection Attack Framework Reverse Engineering · 26d ago Season VI of the US Games launches TOMORROW! Technical Information Security Content & Discussion · 26d ago Company is paying for any certification, which should I obtain? cybersecurity · 26d ago DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels CyberScoop · 26d ago Can't make sense of Dashlane's vault theft notification? You're not alone. Security - Ars Technica · 26d ago Trusting Microsoft with your offensive security repos cybersecurity · 26d ago Automated Fault Injection Attack Framework cybersecurity · 26d ago Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT For [Blue|Purple] Teams in Cyber Defence · 26d ago Bring Your Own RWX Region DLL (BYORWXDLL) For [Blue|Purple] Teams in Cyber Defence · 26d ago Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem For [Blue|Purple] Teams in Cyber Defence · 26d ago APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component For [Blue|Purple] Teams in Cyber Defence · 26d ago NuGet Code Execution As A Service For [Blue|Purple] Teams in Cyber Defence · 26d ago aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies For [Blue|Purple] Teams in Cyber Defence · 26d ago Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor For [Blue|Purple] Teams in Cyber Defence · 26d ago TA4922: The Suspected Chinese Crime Group is Going Global For [Blue|Purple] Teams in Cyber Defence · 26d ago [ Removed by Reddit ] For [Blue|Purple] Teams in Cyber Defence · 26d ago Physical Biometric device as a security measure..?? cybersecurity · 26d ago Espionage Campaign Targeted Stock Exchange Executive for Five Months For [Blue|Purple] Teams in Cyber Defence · 26d ago Cybersegurança cybersecurity · 26d ago Started Learning Cybersecurity cybersecurity · 26d ago InfraGard Application - Seeking Help | Student cybersecurity · 26d ago x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994) Reverse Engineering · 26d ago Orientación en Ciberseguridad cybersecurity · 26d ago OnionAccelerator: multi-circuit / chunked download acceleration over Tor For [Blue|Purple] Teams in Cyber Defence · 26d ago Anthropic's coordinated vulnerability disclosure dashboard cybersecurity · 26d ago Hands Free: What LLM Driven Vulnerability Research Looks Like cybersecurity · 26d ago HazyBeacon and AWS Lambda Function URL Abuse For [Blue|Purple] Teams in Cyber Defence · 27d ago Real time Cybersecurity failures regarding Quantum computing/cryptography cybersecurity · 27d ago The Server Seizure That Affects Also Iran's Cyber Operations For [Blue|Purple] Teams in Cyber Defence · 27d ago How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad For [Blue|Purple] Teams in Cyber Defence · 27d ago 🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop Malware Analysis & Reports · 27d ago 🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It. cybersecurity · 27d ago 🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network For [Blue|Purple] Teams in Cyber Defence · 27d ago Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2 Reverse Engineering · 27d ago A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out. cybersecurity · 27d ago Cisco Webex Meetings Cross-Site Scripting Vulnerability Cisco Security Advisory · 27d ago Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability Cisco Security Advisory · 27d ago CISA warns of active attacks exploiting Android, Linux bugs cybersecurity · 27d ago Found some open ports on a govt site, should i report or stay quiet? cybersecurity · 27d ago What is a good way to keep track of passwords for programs that don't support password managers? cybersecurity · 27d ago ChatGPT Malvertising Campaign Malware Analysis & Reports · 27d ago Cybersecurity statistics of the week (May 25th - May 31st) cybersecurity · 27d ago ASN Emissions Index. Networks ranked by how much noise they create on the internet. cybersecurity · 27d ago Have you sold cve before? cybersecurity · 27d ago EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires Technical Information Security Content & Discussion · 27d ago i want to become a pentester, but i don't know how to cybersecurity · 27d ago Recommendation Malware Analysis & Reports · 27d ago I’m not sure I’m in the right subreddit…. hacking: security in practice · 27d ago The OT Security Problem Nobody Wants to Own cybersecurity · 27d ago Don't Take Wednesday Off When You Manage Vulnerabilities cybersecurity · 27d ago I finally finished a production version after 4 yrds cybersecurity · 27d ago Support role pivot to cloud security cybersecurity · 27d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 27d ago Took me a decade to turn quantum computing into what hackers can easily learn hacking: security in practice · 27d ago Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6! Malware Analysis & Reports · 27d ago How do you manage your passwords? cybersecurity · 27d ago The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector Cyber Defense Magazine · 27d ago Are ANY hacking scenes actually good? John Hammond · 27d ago Mad rush to produce AI driven slop cybersecurity · 27d ago O Tails é seguro para acessar links suspeitos? cybersecurity · 27d ago Took me a decade of work to turn Quantum Computing into a fun videogame hacking: security in practice · 27d ago Interesting- What LLM vuln research looks like Technical Information Security Content & Discussion · 27d ago Cyber Essentials plus + "legacy" network segments cybersecurity · 27d ago Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors For [Blue|Purple] Teams in Cyber Defence · 27d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 27d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 27d ago Hacking your PC using your speaker without ever touching it Reverse Engineering · 27d ago Hacking your PC using your speaker without ever touching it Technical Information Security Content & Discussion · 27d ago Insight for OPSWAT deep CDR cybersecurity · 27d ago Android vs iOS cybersecurity · 27d ago ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account cybersecurity · 27d ago Security Audits at an MSP cybersecurity · 27d ago [ Removed by Reddit ] cybersecurity · 27d ago Argamal: Malware hidden in hentai games Securelist · 27d ago Passkey registration breaks after moving off localhost.. cybersecurity · 27d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 27d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 27d ago Does your team hire fresh AI engineer who doesn't know anything about Security operations? cybersecurity · 27d ago UARs for Equation (banking system) cybersecurity · 27d ago Simple way how to bypass hotel WiFi? hacking: security in practice · 27d ago VS Code zero-day lets hackers steal GitHub tokens in one click hacking: security in practice · 27d ago Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing Technical Information Security Content & Discussion · 27d ago IoT pentesting cert cybersecurity · 27d ago Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations cybersecurity · 27d ago Experience with Tac Security cybersecurity · 27d ago Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content cybersecurity · 27d ago Golang code review notes II - elttam Technical Information Security Content & Discussion · 27d ago Using AI to Secure Its Generated Code Is a Ponzi Scheme Technical Information Security Content & Discussion · 27d ago Found Security Vulnerabilities in my university website cybersecurity · 27d ago burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API) hacking: security in practice · 27d ago Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence cybersecurity · 27d ago AI - Threat to the CyberSec Industry? cybersecurity · 27d ago Built a honeypot platform to catch lateral movement. How are you guys detecting this? cybersecurity · 27d ago How should small SaaS teams safely answer customer security questionnaires? cybersecurity · 27d ago Dependency Cooldowns - Dependency Cooldowns For [Blue|Purple] Teams in Cyber Defence · 27d ago Can AI Do Intelligence Analysis? Apparently Not. cybersecurity · 27d ago PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model cybersecurity · 27d ago Regarding Certified Ethical Hacker (CEH Practical) exam cybersecurity · 27d ago Asking for advices on pursuing first CERTIFICATE cybersecurity · 27d ago I opened my own company and I can't find clients! cybersecurity · 27d ago ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter cybersecurity · 27d ago C2 Frameworks - Threat Hunting in Action with YARA Rules For [Blue|Purple] Teams in Cyber Defence · 27d ago How big of a security risk or exploit would this be? hacking: security in practice · 27d ago Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU? cybersecurity · 27d ago Anyone knows Quad9 dns ? cybersecurity · 27d ago KTO , Be the only one online -- on any WiFi network hacking: security in practice · 27d ago Ransomware tabletop For [Blue|Purple] Teams in Cyber Defence · 27d ago FREE coffee at Cisco Live (I'm giving it away) NetworkChuck · 27d ago I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ? cybersecurity · 27d ago Greynoise swarm cybersecurity · 27d ago SecOT+ certification for free cybersecurity · 27d ago How is the state of the job market for mid-level security engineers? cybersecurity · 27d ago Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things cybersecurity · 27d ago WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total cybersecurity · 27d ago Laid off from TPRM job - need help on the future of my career cybersecurity · 27d ago News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces The Last Watchdog · 27d ago Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 For [Blue|Purple] Teams in Cyber Defence · 27d ago Tracking North Korea Nation-State APT Infrastructure: Kimsuky For [Blue|Purple] Teams in Cyber Defence · 27d ago 새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn For [Blue|Purple] Teams in Cyber Defence · 27d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 27d ago apparently bypassing school systems by playing games hacking: security in practice · 27d ago Anyone compared RoboShadow vs ConnectSecure for vulnerability management? cybersecurity · 27d ago Codex Discovered a Hidden HTTP/2 Bomb For [Blue|Purple] Teams in Cyber Defence · 27d ago Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes Technical Information Security Content & Discussion · 27d ago Top 5 Active Directory Pentesting Tools The Cyber Mentor · 27d ago Any one send vulnerability to MITRE? cybersecurity · 27d ago Need advice for a 30 min Security Apprenticeship interview cybersecurity · 27d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 27d ago Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix For [Blue|Purple] Teams in Cyber Defence · 27d ago UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS cybersecurity · 27d ago Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match cybersecurity · 27d ago We Added a Detection Rule. We Were Not Expecting This. Technical Information Security Content & Discussion · 27d ago Introducing Microsoft Scout: Your always-on personal agent Microsoft 365 Blog · 27d ago Virustotal API as private data source cybersecurity · 27d ago DOD wants to integrate cyber in all operations, and integrate security into AI CyberScoop · 27d ago Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source! Reverse Engineering · 28d ago Announcing the new Work IQ APIs Microsoft 365 Blog · 28d ago Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases Security | Microsoft Azure Blog | Microsoft Azure · 28d ago Trump administration releases scaled-back AI executive order CyberScoop · 28d ago Account Number Security Flaw cybersecurity · 28d ago Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning? cybersecurity · 28d ago A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth cybersecurity · 28d ago Codex Lives In PowerShell Now NetworkChuck · 28d ago [ Removed by Reddit ] cybersecurity · 28d ago [ Removed by Reddit ] cybersecurity · 28d ago “Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?” For [Blue|Purple] Teams in Cyber Defence · 28d ago Phishing simulation platform cybersecurity · 28d ago 1-Click GitHub Token Stealing via a VSCode Bug Technical Information Security Content & Discussion · 28d ago Just task about OSI model cybersecurity · 28d ago FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential The Last Watchdog · 28d ago Need help improving DNS Spy from a security tool angle cybersecurity · 28d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild cybersecurity · 28d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild Technical Information Security Content & Discussion · 28d ago Oracle's first monthly patch update just dropped 77 CVEs. cybersecurity · 28d ago Cleaning up after a legacy service account breach. How are you handling automated secrets discovery? cybersecurity · 28d ago Airbus digital apprenticeship cybersecurity · 28d ago Built a decompiler for exotic legacy programming language opentext Gupta Team Developer Reverse Engineering · 28d ago Always-On Red Teams hacking: security in practice · 28d ago Anthropic expanding access to Project Glasswing CyberScoop · 28d ago Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities cybersecurity · 28d ago [An RX Global Event] Infosecurity Europe darkreading · 28d ago Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit Cyber Defense Magazine · 28d ago A Hacker's Way of Thinking (with Ted Harrington) John Hammond · 28d ago This is a scam and probably a malware/trojan. Path Of Exile 2 builder ... Malware Analysis & Reports · 28d ago Google fixes one actively exploited Android zero-day, 124 flaws cybersecurity · 28d ago Wardriving assessment across Mexico: Preparing for the 2026 World Cup Securelist · 28d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 28d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems All CISA Advisories · 28d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 28d ago Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force cybersecurity · 28d ago Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis? cybersecurity · 28d ago Security Architects who who actively use modelling - What's your approach? cybersecurity · 28d ago PAN-OS authentication bypass bug added to list of exploited vulnerabilities cybersecurity · 28d ago I have extreme anxiety about being hacked cybersecurity · 28d ago Fresher cybersecurity · 28d ago Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif For [Blue|Purple] Teams in Cyber Defence · 28d ago Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand For [Blue|Purple] Teams in Cyber Defence · 28d ago Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach cybersecurity · 28d ago Career advice needed! cybersecurity · 28d ago LLMShare: using shared chatbot pages to distribute malware Malware Analysis & Reports · 28d ago GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure cybersecurity · 28d ago Google sr. security engineer interview cybersecurity · 28d ago Is offensive AI actually changing cybersecurity, or are we overestimating the impact? cybersecurity · 28d ago Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave cybersecurity · 28d ago is emerald chat safe? cybersecurity · 28d ago Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm For [Blue|Purple] Teams in Cyber Defence · 28d ago Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ? cybersecurity · 28d ago ClickJack in the wild cybersecurity · 28d ago NuGet Code Execution As A Service Technical Information Security Content & Discussion · 28d ago Thoughts on A.I assisted Malware Analysis? cybersecurity · 28d ago 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access cybersecurity · 28d ago What articles do you use for cybersecurity news? (2026) cybersecurity · 28d ago Iran Expands Handala Brand to Physical Threats Recorded Future · 28d ago Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider? cybersecurity · 28d ago Roadmap and Training Recommodation cybersecurity · 28d ago Attackers are exploiting Palo Alto Networks defect that initially flew under the radar CyberScoop · 28d ago I managed to pull the full system prompt for Meta's Support AI hacking: security in practice · 28d ago Les anti-triche de niveau noyau et leur risque de sécurité cybersecurity · 28d ago Harassing text messages hacking: security in practice · 28d ago Asked to Send Sensitive Documents via MMS cybersecurity · 28d ago SC-200 compared to CC (isc2) cybersecurity · 28d ago running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it! Reverse Engineering · 28d ago Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts Security - Ars Technica · 28d ago Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB) Technical Information Security Content & Discussion · 28d ago Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now cybersecurity · 28d ago Looking to move off KB4, what are people actually using these days? cybersecurity · 28d ago Dozens of Red Hat packages backdoored through its official NPM channel Security - Ars Technica · 28d ago Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight CyberScoop · 28d ago Got my Security+. What's next? cybersecurity · 28d ago I'm Moderating My First Panel… Come see me at Cisco Live NetworkChuck · 28d ago Vulnerability Summary for the Week of May 25, 2026 cybersecurity · 28d ago RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation For [Blue|Purple] Teams in Cyber Defence · 28d ago Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages For [Blue|Purple] Teams in Cyber Defence · 28d ago Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches For [Blue|Purple] Teams in Cyber Defence · 28d ago REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY! hacking: security in practice · 28d ago Malware cybersecurity · 28d ago Alternative Search Engine to Utilize in 2026? cybersecurity · 28d ago Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked cybersecurity · 28d ago Miasma: Supply Chain Attack Targeting RedHat npm Packages For [Blue|Purple] Teams in Cyber Defence · 28d ago USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order CyberScoop · 28d ago Switching back to Windows?!? NetworkChuck · 28d ago Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild cybersecurity · 28d ago Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers cybersecurity · 28d ago Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Krebs on Security · 28d ago Hacking Palo Alto Networks' GlobalProtect VPN with AI hacking: security in practice · 28d ago AI compliance cybersecurity · 28d ago Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm cybersecurity · 29d ago Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains? cybersecurity · 29d ago MacBook or Windows Laptop for Cybersecurity cybersecurity · 29d ago What's the most creative MFA bypass you've seen? cybersecurity · 29d ago @redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers For [Blue|Purple] Teams in Cyber Defence · 29d ago Research Notes from Building a Windows Event Log Hunting Workflow cybersecurity · 29d ago Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am. hacking: security in practice · 29d ago How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ?? cybersecurity · 29d ago Free AI tools for TPRM? cybersecurity · 29d ago incomplete phone number from togo, need help reporting to police cybersecurity · 29d ago NPM packages from RedHat Compromised cybersecurity · 29d ago Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts cybersecurity · 29d ago SOC Analyst working towards Threat Intelligence cybersecurity · 29d ago Is XSS possible through PDFs? cybersecurity · 29d ago Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider Technical Information Security Content & Discussion · 29d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 29d ago The Next AI Governance Failure Won’t Be the Model cybersecurity · 29d ago Poisoning Claude Code: One GitHub Issue to Break the Supply Chain Technical Information Security Content & Discussion · 29d ago Microsoft MFA Is Down Again cybersecurity · 29d ago Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927) cybersecurity · 29d ago How I Found My First $3,000 AI Vulnerability NahamSec · 29d ago Stealing Passwords via HTML Injection Under a Strict CSP Technical Information Security Content & Discussion · 29d ago Computer logic or Science cybersecurity · 29d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 29d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 29d ago I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for? cybersecurity · 29d ago What C2s Are You Using cybersecurity · 29d ago Best AI LLM for Hacking related stuff hacking: security in practice · 29d ago PNPT Exam cybersecurity · 29d ago Containers on fire: from container escapes to supply chain attacks Securelist · 29d ago Election threats are focused on campaign systems, not voting machines CyberScoop · 29d ago What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification? cybersecurity · 29d ago Feels like most people ignore the wireless layer until it bites them hacking: security in practice · 29d ago Any appsec engineer working in fortune 500? cybersecurity · 29d ago I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next cybersecurity · 29d ago Anyone transition from AWS Data Center Operations to InfoSec? cybersecurity · 29d ago I think my account got hacked but it's weird cybersecurity · 29d ago Subnet discovery through multi-protocol TTL tracing Technical Information Security Content & Discussion · 29d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 29d ago current market for detecting deepfakes? cybersecurity · 29d ago Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched For [Blue|Purple] Teams in Cyber Defence · 29d ago Worried about friend being doxxed on doxbin cybersecurity · 29d ago Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks For [Blue|Purple] Teams in Cyber Defence · 29d ago Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries For [Blue|Purple] Teams in Cyber Defence · 29d ago how to shift from a service based company to a product based one in cybersecurity ? cybersecurity · 29d ago Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA cybersecurity · 29d ago Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking? hacking: security in practice · 29d ago Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign For [Blue|Purple] Teams in Cyber Defence · 29d ago Claude AI user data directory exfiltration via malicious npm package cybersecurity · 29d ago Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from? Reverse Engineering · 29d ago Bitdefender blocking amd stuff? False positive or? cybersecurity · 29d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 29d ago Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet Trend Micro Research, News, Perspectives · 29d ago did they have my password?? what triggers this specific email??? instagram HELP. cybersecurity · 29d ago How to Unpack FlawedAmmyy - Malware Unpacking Tutorial Malware Analysis & Reports · 29d ago ATTENTION: Dashlane may have been breached. (Password manager). cybersecurity · 29d ago Can anyone figure out how to retrieve the recovery key in signal app? hacking: security in practice · 29d ago Norton blocked a “malicious script”? cybersecurity · 29d ago Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts cybersecurity · 29d ago Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive. cybersecurity · 29d ago I wrote about the 5 biggest threats in 2026, curious what this community thinks. cybersecurity · 29d ago MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce? cybersecurity · 29d ago Atomdrift - open-source malware detection for the software supply chain For [Blue|Purple] Teams in Cyber Defence · 29d ago Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions? cybersecurity · 29d ago NetworkChuck cybersecurity · 29d ago LLM for creating phishing tool cybersecurity · 30d ago Why are we still treating IAM like a compliance checkbox? cybersecurity · 30d ago Polyfill pop up? cybersecurity · 30d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Technical Information Security Content & Discussion · 30d ago Building A Malware Lab From Scratch! Malware Analysis & Reports · 30d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Reverse Engineering · 30d ago SecAI+ difficulty question cybersecurity · 30d ago $730k+ raised on Proxmark5 with 2150 backers hacking: security in practice · 30d ago Could you guys give an honest feedback to a completely automated ssrf attack tool? cybersecurity · 30d ago tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me cybersecurity · 30d ago Microsoft Joined the DMARC Club cybersecurity · 30d ago Help. cybersecurity · 30d ago Vibe Coding Security cybersecurity · 30d ago I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works) hacking: security in practice · 30d ago Looking for a Company to Partner With cybersecurity · 30d ago Best reporting tools? cybersecurity · 30d ago What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months) cybersecurity · 30d ago Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens For [Blue|Purple] Teams in Cyber Defence · 30d ago How Can Polyfill.io Still Act Maliciously? cybersecurity · 30d ago 179 npm Packages Target Cloud and Finance via oob.moika.tech For [Blue|Purple] Teams in Cyber Defence · 30d ago KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4 For [Blue|Purple] Teams in Cyber Defence · 30d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 30d ago Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services For [Blue|Purple] Teams in Cyber Defence · 30d ago TinyLoad v7 - what i added :D (in memory protection using VEH and alot more) Reverse Engineering · 30d ago EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA For [Blue|Purple] Teams in Cyber Defence · 30d ago Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace For [Blue|Purple] Teams in Cyber Defence · 30d ago Signal macOS Desktop App Doesn't Actually Delete Messages When it Should For [Blue|Purple] Teams in Cyber Defence · 30d ago Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan For [Blue|Purple] Teams in Cyber Defence · 30d ago WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD For [Blue|Purple] Teams in Cyber Defence · 30d ago Any idea who's behind this hack? How to resolve it? hacking: security in practice · 30d ago Typosquatted npm packages used to steal cloud and CI/CD secrets For [Blue|Purple] Teams in Cyber Defence · 30d ago Need THM voucher code for cheap? Any known seller? cybersecurity · 30d ago Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2 For [Blue|Purple] Teams in Cyber Defence · 30d ago Malicious npm packages abuse dependency confusion to profile developer environments For [Blue|Purple] Teams in Cyber Defence · 30d ago Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) For [Blue|Purple] Teams in Cyber Defence · 30d ago Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack For [Blue|Purple] Teams in Cyber Defence · 30d ago CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied." For [Blue|Purple] Teams in Cyber Defence · 30d ago Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign For [Blue|Purple] Teams in Cyber Defence · 30d ago SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks. For [Blue|Purple] Teams in Cyber Defence · 30d ago EDR Incident Response Playbook: Containing Local Account Incidents For [Blue|Purple] Teams in Cyber Defence · 30d ago Adversarial Oracles: LLM-Guided EDR Signature Reduction For [Blue|Purple] Teams in Cyber Defence · 30d ago One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF For [Blue|Purple] Teams in Cyber Defence · 30d ago proxy: A lightweight caching proxy for package registries. For [Blue|Purple] Teams in Cyber Defence · 30d ago How OLTs may have exposed entire ISP networks For [Blue|Purple] Teams in Cyber Defence · 30d ago Ghost passwords? cybersecurity · 30d ago Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it hacking: security in practice · 30d ago A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years For [Blue|Purple] Teams in Cyber Defence · 30d ago HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics For [Blue|Purple] Teams in Cyber Defence · 30d ago Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots For [Blue|Purple] Teams in Cyber Defence · 30d ago Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures For [Blue|Purple] Teams in Cyber Defence · 30d ago Lessons from Penetration Tests on Large-Scale Agent Systems For [Blue|Purple] Teams in Cyber Defence · 30d ago pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter. For [Blue|Purple] Teams in Cyber Defence · 30d ago [ Removed by Reddit ] Reverse Engineering · 30d ago Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not. cybersecurity · 30d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 30d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions Technical Information Security Content & Discussion · 30d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions cybersecurity · 30d ago Anyone else having Chatgpt Strikes / Violations while learning cybersecurity? cybersecurity · 30d ago Blue Team tips? hacking: security in practice · 30d ago Working at Cisco, worth it? cybersecurity · 30d ago Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice cybersecurity · 30d ago usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer) Reverse Engineering · 30d ago CIFSwitch: a non-universal Linux local root vulnerability For [Blue|Purple] Teams in Cyber Defence · 30d ago Are you pen testing AI Agents? cybersecurity · 30d ago Question of android malware cybersecurity · 30d ago External attack surface: how are you correlating DNS, SSL, and IP reputation today? cybersecurity · 30d ago edit certified pdf hacking: security in practice · 30d ago how do i properly setup 2fa and bitwarden? cybersecurity · 30d ago Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC) cybersecurity · 30d ago i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested? cybersecurity · 30d ago Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever? cybersecurity · 30d ago I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux) Reverse Engineering · 30d ago Can Steam Cloud Files Transfer Malware cybersecurity · 30d ago I bought an old phone from 2018 and wanna destroy it with viruses for fun Malware Analysis & Reports · 30d ago HackTheBox - Interpreter IppSec · 31d ago Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension For [Blue|Purple] Teams in Cyber Defence · 31d ago Questions for the cloud security engineers cybersecurity · 31d ago DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database. For [Blue|Purple] Teams in Cyber Defence · 31d ago Visual Studio Extensions Revisited For [Blue|Purple] Teams in Cyber Defence · 31d ago Thoughts on this as a starter and doing bug bounty on the side cybersecurity · 31d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 31d ago How are new SC-200 candidates practicing labs without an E5 Developer tenant? cybersecurity · 31d ago Everyday hacking in our lives - transportation, work, finances, goods etc hacking: security in practice · 31d ago Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters Technical Information Security Content & Discussion · 31d ago Getting OTP spammed from every app and website I've ever used. Should I be worried? cybersecurity · 31d ago BYOVD and Looting LSASS in the Modern EDR Era For [Blue|Purple] Teams in Cyber Defence · 31d ago A browser tool for checking contractor insurance certificates cybersecurity · 31d ago Am I getting screwed? cybersecurity · 31d ago SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers cybersecurity · 31d ago PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29} cybersecurity · 31d ago CTO at NCSC Summary: week ending May 31st cybersecurity · 31d ago CTO at NCSC Summary: week ending May 31st For [Blue|Purple] Teams in Cyber Defence · 31d ago BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship cybersecurity · 31d ago OffensiveCon26 videos For [Blue|Purple] Teams in Cyber Defence · 31d ago Need suggestion cybersecurity · 31d ago Malware escaped browser without downloading files, then escaped a virtual machine Malware Analysis & Reports · 31d ago [INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety) cybersecurity · 31d ago Was Dave Bittner interviewing an AI? cybersecurity · 31d ago CTF for complete beginner cybersecurity · 31d ago Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques? cybersecurity · 31d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 31d ago AI-Era Cyber Risk Standards cybersecurity · 31d ago BEC Victim - Attacker replied inside a real email thread using a lookalike domain cybersecurity · 31d ago School Survey, (non-paid nothing its free its for my grades) For [Blue|Purple] Teams in Cyber Defence · 31d ago Question for those who transitioned from remote to work from anywhere cybersecurity · 31d ago Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors cybersecurity · 31d ago Do you enjoy what you do or do you wish you could go back in time and change it? cybersecurity · 31d ago Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber? cybersecurity · 31d ago A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.) Technical Information Security Content & Discussion · 31d ago For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year? cybersecurity · 31d ago Name That Toon: Mark of (Cybersecurity) Progress darkreading · 31d ago Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ? cybersecurity · 31d ago Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years? cybersecurity · 31d ago Botnet of more than 17 million devices dismantled cybersecurity · 31d ago Exposed credentials on logs cybersecurity · 31d ago Do you think this is legit or has the website been compromised? hacking: security in practice · 31d ago Introducing Keyhog: The First GPU Accelerated secret scanner Technical Information Security Content & Discussion · 31d ago What do you think is the biggest cybersecurity risk for small businesses in 2026? cybersecurity · 31d ago Wanted to shift to cloud security, but have some questions cybersecurity · 31d ago OffensiveCon26 YouTube Playlist released Technical Information Security Content & Discussion · 31d ago Who actually owns the AI in your company? NetworkChuck · 31d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments For [Blue|Purple] Teams in Cyber Defence · 31d ago LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms For [Blue|Purple] Teams in Cyber Defence · 31d ago Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 CyberScoop · 31d ago Zero Trust is Overrated? Navigating the Complexity cybersecurity · 31d ago Test API post with flair cybersecurity · 31d ago Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications cybersecurity · 31d ago How Do You Handle the Massive Amount of Information in the CPTS Path? cybersecurity · 31d ago Wanna learn cybersecurity & ethical hacking hacking: security in practice · 31d ago LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting For [Blue|Purple] Teams in Cyber Defence · 32d ago Help an upcoming cybersecurity engineer! cybersecurity · 32d ago Repeated Microsoft MFA attempts even after password change cybersecurity · 32d ago I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but Malware Analysis & Reports · 32d ago Do you guys take paper notes or digital ones during studying ? hacking: security in practice · 32d ago What Is Device Intelligence and How Does It Stop Fraud? cybersecurity · 32d ago [FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE) cybersecurity · 32d ago Federal audit reveals NIST’s NVD is plagued by poor planning and duplication CyberScoop · 32d ago Ghidra 12.1.1 has been released! Reverse Engineering · 32d ago IBM commits $5 billion to secure open-source software cybersecurity · 32d ago Structuring an AI-Assisted Pentesting Homelab for a Final Year Project cybersecurity · 32d ago Are teams actually monitoring LLM traffic in production environments? cybersecurity · 32d ago How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA) cybersecurity · 32d ago Raspberry pi cybersecurity · 32d ago Asia's Cyber Insurance Market Shows Signs of Life darkreading · 32d ago What is the biggest obstacle to using AI safely in a company? cybersecurity · 32d ago Advice going forward cybersecurity · 32d ago MCP Firewall help cybersecurity · 32d ago I wanted to shift to security but people told me the market is extremely bad, is that true? cybersecurity · 32d ago Best Personality Type/Traits for Working in Cyber Security cybersecurity · 32d ago Identifying attack patterns through kernel frame callstacks For [Blue|Purple] Teams in Cyber Defence · 32d ago A fake freelance job interview almost installed malware on my PC cybersecurity · 32d ago Is there a viable career path here or am I just being delusional? cybersecurity · 32d ago With Complex Cloud Integrations, Small Errors Lead to Major Compromises darkreading · 32d ago What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks cybersecurity · 32d ago Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness For [Blue|Purple] Teams in Cyber Defence · 32d ago 'The Com' Cyberattacks Support Violence & Sexploitation darkreading · 32d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 32d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 32d ago How do enterprises actually prevent developers from exfiltrating source code? cybersecurity · 32d ago I have a datastealer malware cybersecurity · 32d ago Dúvida de carreira. cybersecurity · 32d ago Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace cybersecurity · 32d ago Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated cybersecurity · 32d ago is SIEM really needed here ? cybersecurity · 32d ago Decompiled an app, found a bunch of secrets, what now? cybersecurity · 32d ago What safety boundary would you expect from a local AI incident investigation tool? For [Blue|Purple] Teams in Cyber Defence · 32d ago Can someone give me a correct method for learning reverse engineering? cybersecurity · 32d ago 1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog Technical Information Security Content & Discussion · 32d ago Authenticated RCE via Argument Injection in Gogs (NOT FIXED) For [Blue|Purple] Teams in Cyber Defence · 32d ago Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months cybersecurity · 32d ago GRC Advise cybersecurity · 32d ago [ Removed by Reddit ] cybersecurity · 32d ago Did something happen to haveibeenpwned? Any alternatives? cybersecurity · 32d ago I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found. Technical Information Security Content & Discussion · 32d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 32d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 32d ago How do people actually modify mobile games to increase their power? hacking: security in practice · 32d ago What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant Securelist · 32d ago Why I Built My Own LLM Benchmark for THOR Finding Triage For [Blue|Purple] Teams in Cyber Defence · 32d ago RAT SUSPECTED cybersecurity · 32d ago Casdoor contains multiple authentication bypass and access management vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 32d ago The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents For [Blue|Purple] Teams in Cyber Defence · 32d ago GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations For [Blue|Purple] Teams in Cyber Defence · 32d ago Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies For [Blue|Purple] Teams in Cyber Defence · 32d ago Malware seller hunted across three continents For [Blue|Purple] Teams in Cyber Defence · 32d ago Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims For [Blue|Purple] Teams in Cyber Defence · 32d ago Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers For [Blue|Purple] Teams in Cyber Defence · 32d ago Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network For [Blue|Purple] Teams in Cyber Defence · 32d ago How do people afford certificate s? cybersecurity · 32d ago I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed? cybersecurity · 32d ago Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint) Reverse Engineering · 32d ago Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. cybersecurity · 32d ago Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 32d ago Phone Forwarding cybersecurity · 32d ago Opinions on running Full Microsoft E5 Security Stack cybersecurity · 32d ago Claiming "XDR" cybersecurity · 32d ago Typosquatted npm packages used to steal cloud and CI/CD secrets cybersecurity · 32d ago Why Loyalty Programs Are Quietly Becoming a Security Blind Spot hacking: security in practice · 32d ago Fooling around with encrypted reasoning blobs Technical Information Security Content & Discussion · 32d ago CALIF: An AI audit of FreeBSD Technical Information Security Content & Discussion · 32d ago Microsoft security cybersecurity · 32d ago Need help regarding building a home lab cybersecurity · 32d ago Should I turn on passwordless accounts for all my Microsoft accounts? cybersecurity · 32d ago Transitioning from AWS Data Center Operations to Security Engineering cybersecurity · 32d ago CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries Technical Information Security Content & Discussion · 32d ago Probably the wrong place. cybersecurity · 32d ago What after IT helpdesk? cybersecurity · 32d ago As Global Powers Explore Humanoid Robots, Cyber-Risk Looms darkreading · 32d ago News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit The Last Watchdog · 32d ago Ajuda pessoal hacking: security in practice · 32d ago VMP 3.5+ Internal Architecture & Heap Dispatch Analysis Reverse Engineering · 32d ago How are you security-testing API changes before production without slowing CI/CD? cybersecurity · 32d ago Are we trusting update repos or are you all extra paranoid now as well? cybersecurity · 32d ago Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops cybersecurity · 32d ago Prevent supply chain attacks cybersecurity · 32d ago The C-suite job that's burning people out faster than any other For [Blue|Purple] Teams in Cyber Defence · 32d ago New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation For [Blue|Purple] Teams in Cyber Defence · 32d ago Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems cybersecurity · 32d ago SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer For [Blue|Purple] Teams in Cyber Defence · 32d ago FBI warns of fake FIFA websites running World Cup fraud schemes cybersecurity · 32d ago Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances For [Blue|Purple] Teams in Cyber Defence · 32d ago Hackers are trying to steal Signal users' backups in new wave of phishing attacks cybersecurity · 32d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN Technical Information Security Content & Discussion · 32d ago Samy Kamkar on building viruses, his arrest and privacy in the LLM era hacking: security in practice · 32d ago 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface For [Blue|Purple] Teams in Cyber Defence · 32d ago Visual Studio Extensions Revisited Technical Information Security Content & Discussion · 32d ago Dutch Raid Fails to Dent Russian Bulletproof Host darkreading · 32d ago APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026 For [Blue|Purple] Teams in Cyber Defence · 32d ago Incident Response Testing Preparation cybersecurity · 32d ago Introducing Microsoft 365 Business with Copilot: The new standard for small business Microsoft 365 Blog · 32d ago Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference cybersecurity · 32d ago House panel poised to hold hearing centered on AI impact on cyber CyberScoop · 32d ago [Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥 cybersecurity · 32d ago Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure For [Blue|Purple] Teams in Cyber Defence · 32d ago Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake For [Blue|Purple] Teams in Cyber Defence · 32d ago 3rd Party NFC cards.. secure? cybersecurity · 32d ago Vulnerability Management Tickets & SLA cybersecurity · 32d ago Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket CyberScoop · 32d ago Defending at Machine-Speed: Building AI Threat Readiness cybersecurity · 32d ago AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved cybersecurity · 32d ago HEAD request body processing leading cybersecurity · 32d ago Malicious npm Package Stole Files From Claude AI User Directory via GitHub cybersecurity · 32d ago Does anyone have an app like substack to keep being updated and engaging within the cyber domain? cybersecurity · 32d ago Zero Trust Implementation Guidelines For [Blue|Purple] Teams in Cyber Defence · 32d ago [ Removed by Reddit ] hacking: security in practice · 33d ago What’s an attack vector people massively underestimate in 2026? cybersecurity · 33d ago We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7 cybersecurity · 33d ago Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP) Technical Information Security Content & Discussion · 33d ago Is this considered a bug or something else entirely? hacking: security in practice · 33d ago Hermes wasn’t built to compete. It was built to WORK. NetworkChuck · 33d ago Agentic AI Isn't Risky; the Way Orgs Deploy It Is darkreading · 33d ago A Deeper Look at GLASSWORM's Solana Variant Malware Analysis & Reports · 33d ago A Deeper Look at GLASSWORM's Solana Variant cybersecurity · 33d ago How 2004 RuneScape fit a multiplayer RPG into 56k dial-up Reverse Engineering · 33d ago Getting back deleted conversation from messanger hacking: security in practice · 33d ago Introducing a new design for Microsoft 365 Copilot Microsoft 365 Blog · 33d ago BlackToad: Network Manipulation in an AutoIt Payload For [Blue|Purple] Teams in Cyber Defence · 33d ago RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT For [Blue|Purple] Teams in Cyber Defence · 33d ago Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant For [Blue|Purple] Teams in Cyber Defence · 33d ago Calling Cyber Security Beginners cybersecurity · 33d ago Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE Technical Information Security Content & Discussion · 33d ago Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis cybersecurity · 33d ago Building Omegle for Exposed Webcams hacking: security in practice · 33d ago built something for ai agents, ended up looking a lot like classic appsec cybersecurity · 33d ago Is Gophish still usable in 2026? cybersecurity · 33d ago Microsoft vs Chaotic Eclipse: three zero-days now actively exploited cybersecurity · 33d ago what do you think cybersecurity · 33d ago Why would be clicking a website, redirect me? cybersecurity · 33d ago Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit For [Blue|Purple] Teams in Cyber Defence · 33d ago Zapier fixes bug chain that researchers say risked widespread account takeover cybersecurity · 33d ago AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career? hacking: security in practice · 33d ago Writing cybersecurity policies is a waste of time cybersecurity · 33d ago Zapier fixes bug chain that researchers say risked widespread account takeover CyberScoop · 33d ago The GitHub Leak Situation Just Got Worse | Threat Wire Hak5 · 33d ago reverse engineering need for speed most wanted for modding sdk Reverse Engineering · 33d ago Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security darkreading · 33d ago Raising the Cybersecurity Stakes: Ante up for the Agentic Era. cybersecurity · 33d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories Alerts · 33d ago ABB EIBPORT All CISA Advisories · 33d ago Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter All CISA Advisories · 33d ago ABB Busch-Welcome 2 Wire Door Opener Actuator All CISA Advisories · 33d ago Fourth Frontier Frontier X Mobile Application, Frontier X2 All CISA Advisories · 33d ago CP Plus 8 Ch. Network Video Recorder All CISA Advisories · 33d ago XCharge C6 All CISA Advisories · 33d ago KMW CCTV Security Cameras All CISA Advisories · 33d ago MacGregor Voyage Data Recorder (VDR) G4e All CISA Advisories · 33d ago Schnieider Electric EcoStruxure Machine Expert HVAC All CISA Advisories · 33d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories All CISA Advisories · 33d ago Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it. cybersecurity · 33d ago [ Removed by Reddit ] cybersecurity · 33d ago Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15 Malware Analysis & Reports · 33d ago Released: Dataforge Honeypot cybersecurity · 33d ago Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks cybersecurity · 33d ago CEH-free cybersecurity · 33d ago Hottest cybersecurity open-source tools of the month: May 2026 cybersecurity · 33d ago Preparation tips for CPENT cybersecurity · 33d ago BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model darkreading · 33d ago FROST: Fingerprinting Remotely using OPFS-based SSD Timing For [Blue|Purple] Teams in Cyber Defence · 33d ago How do you handle AI tools in your organization? cybersecurity · 33d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 33d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 33d ago What scanners are actually trying against AI infrastructure Technical Information Security Content & Discussion · 33d ago I think i got scammed anybody can help me with that cybersecurity · 33d ago Nordic CISOs Handle Rising Cyber Threats Remarkably Well darkreading · 33d ago New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo cybersecurity · 33d ago Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup For [Blue|Purple] Teams in Cyber Defence · 33d ago Is it safe to have passwords copied to clipboard on IOS temporarily? cybersecurity · 33d ago Developers working on anti-fraud systems deserve more credit cybersecurity · 33d ago Real Folks of Cyber | Dan Berger | Day in the Life The Cyber Mentor · 33d ago My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst cybersecurity · 33d ago GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs. Reverse Engineering · 33d ago Security awareness training for AI heavy smb workflows? cybersecurity · 33d ago puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 33d ago Defense by accumulation Technical Information Security Content & Discussion · 33d ago Minimum Requirements for Helpdesk Role ? cybersecurity · 33d ago Reddit spear phishing cybersecurity · 33d ago Winbox server/client reverse engineered is opensource Reverse Engineering · 33d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ cybersecurity · 33d ago What to do cybersecurity · 33d ago What resources would you recommend for studying cysa+ cybersecurity · 33d ago Provenance of Data cybersecurity · 33d ago 5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain hacking: security in practice · 33d ago Websites have a new way to spy on visitors: analyzing their SSD activity cybersecurity · 33d ago 12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal? cybersecurity · 33d ago OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms CyberScoop · 33d ago Russian Art Teacher - Hinder Security Clearance? cybersecurity · 33d ago Ransomware Actors Show Up In Person to Steal Law Firm Data darkreading · 33d ago FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person CyberScoop · 33d ago Who is Salt Typhoon Really? Unraveling the Attribution Challenge For [Blue|Purple] Teams in Cyber Defence · 33d ago EDR/MDR Vendor Questions cybersecurity · 33d ago Cybersecurity as a Highschooler? cybersecurity · 33d ago New department created, would love your input cybersecurity · 33d ago What are the dangers of posting? hacking: security in practice · 33d ago OWASP Vienna - anyone going? cybersecurity · 33d ago Interview with Upstart cybersecurity · 33d ago 18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber. cybersecurity · 33d ago Is cloud security engineer viable with my current position? cybersecurity · 33d ago UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace CyberScoop · 33d ago Cloudflare Access users: what would actually make JIT useful for you? cybersecurity · 33d ago Looking for resources on end-to-end APT attack flow summaries for detection engineering For [Blue|Purple] Teams in Cyber Defence · 33d ago Kali365 Activity Surges: Device Code Phishing Is Scaling Fast Malware Analysis & Reports · 33d ago eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels cybersecurity · 33d ago The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire For [Blue|Purple] Teams in Cyber Defence · 33d ago Questions regarding Ubuntu 24 LTS hardening cybersecurity · 33d ago Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho. cybersecurity · 33d ago Honest question about OT Security Engineer work life in India cybersecurity · 33d ago Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning) cybersecurity · 33d ago AI Security cybersecurity · 33d ago Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor cybersecurity · 34d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP For [Blue|Purple] Teams in Cyber Defence · 34d ago 🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents cybersecurity · 34d ago Latin American Cybercriminals Hoover Up Government Data darkreading · 34d ago Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint For [Blue|Purple] Teams in Cyber Defence · 34d ago AI-Assisted Exploit Development Outpaces Scanner Detection darkreading · 34d ago Building Detection Engineering on AWS from scratch — roast my plan cybersecurity · 34d ago Building Detection Engineering on AWS from scratch — roast my plan For [Blue|Purple] Teams in Cyber Defence · 34d ago New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault Technical Information Security Content & Discussion · 34d ago Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance cybersecurity · 34d ago Flipper Zero Users, What's Your Take? hacking: security in practice · 34d ago Large company with a bit of an issue free stuff hacking: security in practice · 34d ago I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA. cybersecurity · 34d ago Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning cybersecurity · 34d ago Final Year Project: Looking for non-generic IAM project ideas that solve real problems cybersecurity · 34d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Technical Information Security Content & Discussion · 34d ago GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled. cybersecurity · 34d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware For [Blue|Purple] Teams in Cyber Defence · 34d ago Breaking out of IT Helpdesk - how? cybersecurity · 34d ago A year in Cybersecurity — Where Do I Go From Here? cybersecurity · 34d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware cybersecurity · 34d ago MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Malware Analysis & Reports · 34d ago 22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber cybersecurity · 34d ago FBI: Silent Ransom Group Turns to IT Support Ploy cybersecurity · 34d ago A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate Technical Information Security Content & Discussion · 34d ago How do machine builders track Siemens/Rockwell security advisories? cybersecurity · 34d ago CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain CyberScoop · 34d ago GlassWorm Developer Supply-Chain Botnet Takedown cybersecurity · 34d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN cybersecurity · 34d ago Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV cybersecurity · 34d ago (URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active Reverse Engineering · 34d ago Got cybersec work what next ? cybersecurity · 34d ago Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables cybersecurity · 34d ago Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers cybersecurity · 34d ago HN Security - AI Reporter - Let's automate reporting in Burp Suite! Technical Information Security Content & Discussion · 34d ago Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing? cybersecurity · 34d ago GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP) cybersecurity · 34d ago nightmare eclipse is probably French here is why cybersecurity · 34d ago Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines cybersecurity · 34d ago Measuring performance of JA4/JA4H AI Model cybersecurity · 34d ago Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security darkreading · 34d ago What things are you really focused on this year? cybersecurity · 34d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 34d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 34d ago Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io) Malware Analysis & Reports · 34d ago Designing secure access with ZTNA For [Blue|Purple] Teams in Cyber Defence · 34d ago Hypothetical EDR spoofer Reverse Engineering · 34d ago Hypothetical EDR spoofer cybersecurity · 34d ago ISO 27001 Audit Stage 1 cybersecurity · 34d ago Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records Technical Information Security Content & Discussion · 34d ago Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That. cybersecurity · 34d ago What to consider before asking an AI chatbot for health advice WeLiveSecurity · 34d ago What to consider before asking an AI chatbot for health advice WeLiveSecurity · 34d ago Looking for Hacker Friends to Learn☺️ cybersecurity · 34d ago Comptes Instagram et Facebook piratés et désactivés cybersecurity · 34d ago RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact Technical Information Security Content & Discussion · 34d ago How to safely disinfect a USB stick from potential malware files? cybersecurity · 34d ago Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era Proofpoint News Feed · 34d ago Champion ethical hacker warns AI tools like Mythos will make competing harder. hacking: security in practice · 34d ago MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response For [Blue|Purple] Teams in Cyber Defence · 34d ago White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats For [Blue|Purple] Teams in Cyber Defence · 34d ago Advisory X41-2026-002: Request Host Header not Validated in Starlette For [Blue|Purple] Teams in Cyber Defence · 34d ago Top ethical hacker Chompie warns AI tools could put her out of business For [Blue|Purple] Teams in Cyber Defence · 34d ago 浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents For [Blue|Purple] Teams in Cyber Defence · 34d ago Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker. hacking: security in practice · 34d ago YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions For [Blue|Purple] Teams in Cyber Defence · 34d ago CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state For [Blue|Purple] Teams in Cyber Defence · 34d ago The Evolution of Chinese-language Phishing Services For [Blue|Purple] Teams in Cyber Defence · 34d ago Silent Ransom Group Impersonating IT Personnel through Social Engineering For [Blue|Purple] Teams in Cyber Defence · 34d ago Is anyone else concerned about how quickly AI is outpacing cloud security? cybersecurity · 34d ago The epoll UAF - an epoll uaf race in fs/eventpoll.c For [Blue|Purple] Teams in Cyber Defence · 34d ago Tycoon 2FA AiTM detection for Entra ID and Google For [Blue|Purple] Teams in Cyber Defence · 34d ago Microsoft Copilot Cowork Exfiltrates Files For [Blue|Purple] Teams in Cyber Defence · 34d ago What's a CyberSecurity job like? cybersecurity · 34d ago Microsoft Live credential stuffing cybersecurity · 34d ago I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this? cybersecurity · 34d ago Security architects- summarize your responsibilities and role cybersecurity · 34d ago Finding Work in OSINT cybersecurity · 34d ago State of SDLC Security 2026 cybersecurity · 34d ago Reported to police for coding html cybersecurity · 34d ago there's a toll in the hall now hacking: security in practice · 34d ago I Reverse Engineered Need for Speed Most Wanted Server Reverse Engineering · 34d ago Am I crazy or is something off about this Google OAuth login via Calendly hacking: security in practice · 34d ago [Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling) cybersecurity · 34d ago I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project cybersecurity · 34d ago Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover cybersecurity · 34d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators? cybersecurity · 34d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells cybersecurity · 34d ago GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet The Last Watchdog · 34d ago Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos darkreading · 34d ago Apple open-sources quantum-resistant encryption code CyberScoop · 34d ago Breaking GROK'S DEFENSES to make it HACK Real Public Websites cybersecurity · 34d ago GitHub Actions Cache Poisoning is eating open source cybersecurity · 34d ago State Cyber Leaders Push Congress for More Funding, Support darkreading · 34d ago Nightmare-Eclipse has also been banned on GitLab :DD cybersecurity · 34d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled? darkreading · 34d ago For Enterprises, Security Remains Agentic AI's Biggest Challenge darkreading · 34d ago Do we still have time before we are in the Age of the movie "Minority Report"? ↓ cybersecurity · 34d ago SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file cybersecurity · 34d ago Unpatched Sparx vulnerabilties For [Blue|Purple] Teams in Cyber Defence · 34d ago What Software Supply Chain, Water Filters, and Power Grids Have in Common cybersecurity · 34d ago QA engineer trying to move into AppSec — does this plan hold up? cybersecurity · 34d ago Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down. Malware Analysis & Reports · 34d ago Is work from anywhere really impossible to find?? cybersecurity · 35d ago Navigating Lax Load Balancers: When an Intersection Gets You Inside Technical Information Security Content & Discussion · 35d ago New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences Microsoft 365 Blog · 35d ago Cybersecurity statistics of the week (May 18th - May 24th) cybersecurity · 35d ago Engineering a Post Quantum Fortress Inside the Citadel Archite cybersecurity · 35d ago Cyber Security Analyst cybersecurity · 35d ago Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance cybersecurity · 35d ago Two layer email security tool thesis cybersecurity · 35d ago Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents Technical Information Security Content & Discussion · 35d ago sylvia: iOS Syscall Explorer for IDA 9.X For [Blue|Purple] Teams in Cyber Defence · 35d ago Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation Reverse Engineering · 35d ago OTP lockout state leaked valid-code signal, enabling OLX account takeover Technical Information Security Content & Discussion · 35d ago When OTP rate limiting fails: OLX account takeover with persistent sessions cybersecurity · 35d ago When “try again later” still tells you the OTP was correct: an account takeover story. hacking: security in practice · 35d ago Entra ID sessions revoke cybersecurity · 35d ago Anyone who attended GPCSSI before? Need some clarification cybersecurity · 35d ago Lost on my career path. cybersecurity · 35d ago How journalists rely on VPNs to protect press freedom Technical Information Security Content & Discussion · 35d ago EU-based folks: external pentest vs mandatory data/security training? cybersecurity · 35d ago help needed from experienced people cybersecurity · 35d ago How do you evaluate whether a privacy service is actually privacy-respecting? cybersecurity · 35d ago Which one Intellipaat or coursera which one to choose cybersecurity · 35d ago How random program can cause most of antiviruses close himself without telling himself to close Malware Analysis & Reports · 35d ago Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching Reverse Engineering · 35d ago ShadowCat: Universal optical file transfer, single html file, browser to camera hacking: security in practice · 35d ago Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1) Technical Information Security Content & Discussion · 35d ago CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks cybersecurity · 35d ago India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic? cybersecurity · 35d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 35d ago ABB Terra AC All CISA Advisories · 35d ago ABB LVS MConfig All CISA Advisories · 35d ago ABB Ability Camera Connect All CISA Advisories · 35d ago Eppendorf BioFlo 320 All CISA Advisories · 35d ago ABB AbilityTM Zenon Remote Transport Vulnerability All CISA Advisories · 35d ago ABB AC500 V2 All CISA Advisories · 35d ago ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) All CISA Advisories · 35d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 35d ago Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs. cybersecurity · 35d ago Did anyone pass the SC-200 certificate recently? cybersecurity · 35d ago Honeypot cybersecurity · 35d ago passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account cybersecurity · 35d ago Career in IAM as a fresher cybersecurity · 35d ago CISA orders feds to patch actively exploited Drupal vulnerability cybersecurity · 35d ago Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure cybersecurity · 35d ago GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” cybersecurity · 35d ago Cyber security tool cybersecurity · 35d ago Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East For [Blue|Purple] Teams in Cyber Defence · 35d ago GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip For [Blue|Purple] Teams in Cyber Defence · 35d ago JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign For [Blue|Purple] Teams in Cyber Defence · 35d ago Saw this tool and it has potential cybersecurity · 35d ago 🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs cybersecurity · 35d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack For [Blue|Purple] Teams in Cyber Defence · 35d ago How I Tried to Parse a Replay from Dawn of War: Definitive Edition Reverse Engineering · 35d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files cybersecurity · 35d ago Follow up : showing Claude install random pacakage in its vm instance without asking or prompting cybersecurity · 35d ago BTMOB: A stealthy RAT burrowing deep into Android devices WeLiveSecurity · 35d ago BTMOB: A stealthy RAT burrowing deep into Android devices WeLiveSecurity · 35d ago Update Starlette Now. New severe vulnerability dropped. Technical Information Security Content & Discussion · 35d ago Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@" For [Blue|Purple] Teams in Cyber Defence · 35d ago The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization For [Blue|Purple] Teams in Cyber Defence · 35d ago ¿Is safe? cybersecurity · 35d ago Need help cybersecurity · 35d ago What is the best tool for masking in kali cybersecurity · 35d ago What are the best tools other than ghostTracker? cybersecurity · 35d ago y2jb un able to enject payloads hacking: security in practice · 35d ago TrapDoor Cross-Ecosystem Crypto Stealer Campaign cybersecurity · 35d ago Follow up : Steal Your Files Claude AI installing package because internet say so cybersecurity · 35d ago New to Cybersecurity: Looking for general advice & help with Nmap cybersecurity · 35d ago GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP. For [Blue|Purple] Teams in Cyber Defence · 35d ago Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal cybersecurity · 35d ago Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated. hacking: security in practice · 35d ago Looking for tech role references cybersecurity · 35d ago Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet Trend Micro Research, News, Perspectives · 35d ago How do you balance Paw? cybersecurity · 35d ago I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity. cybersecurity · 35d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Malware Analysis & Reports · 35d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Technical Information Security Content & Discussion · 35d ago Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability For [Blue|Purple] Teams in Cyber Defence · 35d ago From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security cybersecurity · 35d ago Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February cybersecurity · 35d ago What Companies are Legit? cybersecurity · 35d ago start learning cybersecurity from scratch cybersecurity · 35d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 35d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 35d ago WhatsApp users on alert after hacker drops massive dataset cybersecurity · 35d ago 17 years old going into CS — what certs should I start going after now? cybersecurity · 35d ago CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700. For [Blue|Purple] Teams in Cyber Defence · 35d ago i want to hire an osint expert cybersecurity · 35d ago Open University pros/cons cybersecurity · 35d ago How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection? cybersecurity · 35d ago Career in IAM as a fresher cybersecurity · 35d ago Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo cybersecurity · 35d ago Need Advice cybersecurity · 35d ago Why did Hack Forums lose popularity? hacking: security in practice · 35d ago Nocturne - A bin2bin code virtualizer for x86-64 PE binaries Reverse Engineering · 35d ago Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all? cybersecurity · 35d ago Someone from Germany on iOS keeps trying to login to my MSFT account cybersecurity · 35d ago AI cautionary tale... cybersecurity · 35d ago [Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing Reverse Engineering · 35d ago AI powered red vs blue teaming cybersecurity · 36d ago Starting a security analyst student apprenticeship next week, need advice cybersecurity · 36d ago Why CVE Does Not Work for AI Agents, but AVE? cybersecurity · 36d ago SC-200 or Security+ — which actually helps land a security title cybersecurity · 36d ago How about AI having access to your hard drive. cybersecurity · 36d ago How a Date Tag Hijacks macOS via ExifTool cybersecurity · 36d ago Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools cybersecurity · 36d ago Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing Reverse Engineering · 36d ago How credential brokering prevents AI agents from compromising credentials via prompt injection Technical Information Security Content & Discussion · 36d ago How credential brokering prevents AI agents from compromising credentials via prompt injection cybersecurity · 36d ago Built a tiny daily cyber puzzle game during evenings/weekends cybersecurity · 36d ago Crypto4A launches quantum-safe rival to AWS Secrets Manager cybersecurity · 36d ago CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth Technical Information Security Content & Discussion · 36d ago ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why. cybersecurity · 36d ago Cyber Sec project cybersecurity · 36d ago ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise hacking: security in practice · 36d ago CySA+ cybersecurity · 36d ago Anyone tried Morgancyberhelp ? cybersecurity · 36d ago As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free cybersecurity · 36d ago YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos For [Blue|Purple] Teams in Cyber Defence · 36d ago Why are most of the dfir tools built to be used in windows cybersecurity · 36d ago OnlyFans mega leak reveals 340M user records, hackers claim cybersecurity · 36d ago Perplexity BumbleBee cybersecurity · 36d ago Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Krebs on Security · 36d ago Cisco patches critical 10.0 flaw in Secure Workload APIs cybersecurity · 36d ago Suspicious ass website asking to run a terminal command (MacOS) Malware Analysis & Reports · 36d ago Shellcide: A shellcode IDE hacking: security in practice · 36d ago Stalker has my phonenumber cybersecurity · 36d ago I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built Reverse Engineering · 36d ago Need some guidance cybersecurity · 36d ago Are you currently allocating budget to services that remove executive PII from B2B data brokers? cybersecurity · 36d ago Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal Technical Information Security Content & Discussion · 36d ago About CEHv13 book cybersecurity · 36d ago delimiter-less string obfuscation powered by compile-time AES Reverse Engineering · 36d ago Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it For [Blue|Purple] Teams in Cyber Defence · 36d ago We open-sourced the most dangerous part of our security startup on purpose. cybersecurity · 36d ago Which conference(s) result in the most people finding jobs? cybersecurity · 36d ago My discord account has been hacked second time even after enabling two factor authentication and resetting password cybersecurity · 36d ago What's the most efficient way to learn cloud governance and compliance cybersecurity · 36d ago honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports For [Blue|Purple] Teams in Cyber Defence · 36d ago Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild. For [Blue|Purple] Teams in Cyber Defence · 36d ago Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council For [Blue|Purple] Teams in Cyber Defence · 36d ago RemotePE: The Lazarus RAT that lives in memory For [Blue|Purple] Teams in Cyber Defence · 36d ago Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer For [Blue|Purple] Teams in Cyber Defence · 36d ago Paved With Intent: ROADtools and Nation-State Tactics in the Cloud For [Blue|Purple] Teams in Cyber Defence · 36d ago Twee mannen aangehouden voor phishing - Two men arrested for phishing For [Blue|Purple] Teams in Cyber Defence · 36d ago Sharp Eyes: Mass surveillance of foreigners in China For [Blue|Purple] Teams in Cyber Defence · 36d ago Does anyone know C2 framwork and free hosting to host C2? cybersecurity · 36d ago Finding bot account hacking: security in practice · 36d ago relay_bible: Technical Reference to multiple relay techniques For [Blue|Purple] Teams in Cyber Defence · 36d ago CIS-CAT Assessor for assessment Windows server 2022 and 2025 cybersecurity · 36d ago Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec For [Blue|Purple] Teams in Cyber Defence · 36d ago The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in] For [Blue|Purple] Teams in Cyber Defence · 36d ago SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format For [Blue|Purple] Teams in Cyber Defence · 36d ago North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial For [Blue|Purple] Teams in Cyber Defence · 36d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 36d ago Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this cybersecurity · 36d ago Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks? cybersecurity · 36d ago Recent adoption of AI taught me what is Cybersecurity. cybersecurity · 36d ago The Pentagon Changed the Rules for Cybersecurity Compliance cybersecurity · 36d ago Can someone explain to a noob like me what the implications of this exploit are? cybersecurity · 36d ago SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections cybersecurity · 36d ago Window between zero-day CVE and a patch! cybersecurity · 36d ago Is it risky when a website puts on technology components with versions they used in their website? cybersecurity · 36d ago Anyone else losing their mind over this "AI Cybersecurity" hype? cybersecurity · 36d ago URL parsing behavior in a canonical tag lab cybersecurity · 36d ago How to hacking: security in practice · 36d ago Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you? cybersecurity · 36d ago Any tips for me pls cybersecurity · 36d ago How do you minimize legal liability as a solo contractor? cybersecurity · 36d ago How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing? cybersecurity · 36d ago nmap on Linux: Guide to Network Scanning and Discovery Technical Information Security Content & Discussion · 36d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 36d ago Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift. hacking: security in practice · 36d ago Provenance: A survival toolkit for an AI dominant information landscape cybersecurity · 36d ago Nmap Mastery: The Complete Guide to Network Reconnaissance hacking: security in practice · 36d ago Google wallet virtual card cloned hacking: security in practice · 36d ago [ Removed by Reddit ] cybersecurity · 36d ago Active Drupal SQLi exploitation is a real „patch now“ moment cybersecurity · 36d ago machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native) cybersecurity · 36d ago Need suggestions and input; not a promotion cybersecurity · 36d ago Need advice! cybersecurity · 36d ago New Zealand is becoming a focal point for AI-driven superhacking threats. cybersecurity · 36d ago Staged publishing and new install-time controls for npm - GitHub Changelog For [Blue|Purple] Teams in Cyber Defence · 36d ago nmap on Linux: Guide to Network Scanning and Discovery cybersecurity · 36d ago TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle cybersecurity · 37d ago How would Phishing look like in the future? (targeting agents, not humans) cybersecurity · 37d ago Best beginner/intermediate book for system security (blue team / defense / audits)? cybersecurity · 37d ago Why is on-prem and air-gapped asset inventory still such a mess? cybersecurity · 37d ago keep getting MS authentication sign in attempts? cybersecurity · 37d ago Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES For [Blue|Purple] Teams in Cyber Defence · 37d ago Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud For [Blue|Purple] Teams in Cyber Defence · 37d ago Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow For [Blue|Purple] Teams in Cyber Defence · 37d ago The Future and Past of Residential Proxies For [Blue|Purple] Teams in Cyber Defence · 37d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 37d ago Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy For [Blue|Purple] Teams in Cyber Defence · 37d ago Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware For [Blue|Purple] Teams in Cyber Defence · 37d ago A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software For [Blue|Purple] Teams in Cyber Defence · 37d ago Prompt Injection finally broke my brain a little. My first article as a security student. Technical Information Security Content & Discussion · 37d ago Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows For [Blue|Purple] Teams in Cyber Defence · 37d ago Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 37d ago Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes For [Blue|Purple] Teams in Cyber Defence · 37d ago mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. For [Blue|Purple] Teams in Cyber Defence · 37d ago keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust. For [Blue|Purple] Teams in Cyber Defence · 37d ago np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation. For [Blue|Purple] Teams in Cyber Defence · 37d ago Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up. For [Blue|Purple] Teams in Cyber Defence · 37d ago OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ For [Blue|Purple] Teams in Cyber Defence · 37d ago Megalodon: Mass GitHub Repo Backdooring via CI Workflows For [Blue|Purple] Teams in Cyber Defence · 37d ago Silly issue cybersecurity · 37d ago FatGid - FreeBSD 14.x kernel LPE For [Blue|Purple] Teams in Cyber Defence · 37d ago Manage [VSCode] extensions in enterprise environments For [Blue|Purple] Teams in Cyber Defence · 37d ago angr: A powerful and user-friendly binary analysis platform! For [Blue|Purple] Teams in Cyber Defence · 37d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware For [Blue|Purple] Teams in Cyber Defence · 37d ago How Attackers Force Microsoft to Send Phishing Emails For [Blue|Purple] Teams in Cyber Defence · 37d ago Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects For [Blue|Purple] Teams in Cyber Defence · 37d ago Microsoft Authenticator App Details now exposed in Entra SignInLogs For [Blue|Purple] Teams in Cyber Defence · 37d ago Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting For [Blue|Purple] Teams in Cyber Defence · 37d ago How China-linked threat actors obtain zero-day vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 37d ago How to practice cybersecurity while studying prograaming ? cybersecurity · 37d ago Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research For [Blue|Purple] Teams in Cyber Defence · 37d ago How to Use Claude AI: A Complete Technical Beginner's Guide Technical Information Security Content & Discussion · 37d ago [AI Security] Exploring Behavioral AI for Runtime Threat Detection cybersecurity · 37d ago Podman and krun: is it pointless to harden quadlets? cybersecurity · 37d ago Monitoring for vssadmin.exe delete shadows is an absolute bare minimum For [Blue|Purple] Teams in Cyber Defence · 37d ago Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack For [Blue|Purple] Teams in Cyber Defence · 37d ago How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers For [Blue|Purple] Teams in Cyber Defence · 37d ago How to handle security researchers (and firms) without a bounty program? cybersecurity · 37d ago CVE-2026-48029: Two grid-decode bugs in libheif For [Blue|Purple] Teams in Cyber Defence · 37d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ Reverse Engineering · 37d ago workcell: Bounded local runtime and policy boundary for coding agents For [Blue|Purple] Teams in Cyber Defence · 37d ago OpenShell: OpenShell is the safe, private runtime for autonomous AI agents. For [Blue|Purple] Teams in Cyber Defence · 37d ago Product analytics is becoming a third-party breach surface cybersecurity · 37d ago How can i learn and get into red teaming? cybersecurity · 37d ago Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network cybersecurity · 37d ago I got hacked cybersecurity · 37d ago What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method? hacking: security in practice · 37d ago Soc analysts in big companies, how it looks like? cybersecurity · 37d ago Has anyone manage to reverse the macked dylib? Reverse Engineering · 37d ago CTO at NCSC Summary: week ending May 24th cybersecurity · 37d ago Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation For [Blue|Purple] Teams in Cyber Defence · 37d ago Built a SOC from scratch with no prior SOC experience For [Blue|Purple] Teams in Cyber Defence · 37d ago These special phone and app features can help protect you from spyware cybersecurity · 37d ago Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button? cybersecurity · 37d ago Capcha Code Malware cybersecurity · 37d ago getting lost when hunting cybersecurity · 37d ago How to find information behind an account? cybersecurity · 37d ago Reverse engineering circuitry in a Spacelab computer from 1980 Reverse Engineering · 37d ago Theoretical Design Concept for Post-Exploitation Browser Defense cybersecurity · 37d ago Google Certifications... cybersecurity · 37d ago How to continue when finding a possible Vulnerability but local law prohibits me from investigating further cybersecurity · 37d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks cybersecurity · 37d ago Is the CISSP still a reputable cert for getting jobs? cybersecurity · 37d ago Which of these gоv roles would fare better in the private sector? cybersecurity · 37d ago Laravel Lang packages hijacked to deploy credential-stealing malware cybersecurity · 37d ago Mapping binaries to EDR feature spaces cybersecurity · 37d ago Lost my number + WhatsApp account — worried about old chats, photos, and videos cybersecurity · 37d ago Proxmark5 campaign unlocked the $600k stretch goal hacking: security in practice · 37d ago ☔️🌅 STÖK · 37d ago what is the most painful or time-consuming part of your work right now?" cybersecurity · 37d ago Anthropic says Mythos has already found more than 10,000 vulnerabilities cybersecurity · 37d ago What is the experience needed for “entry level” cybersecurity jobs? cybersecurity · 37d ago Browser extension testing. cybersecurity · 37d ago GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision hacking: security in practice · 37d ago Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip? cybersecurity · 37d ago Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology Reverse Engineering · 37d ago Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback cybersecurity · 37d ago Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition cybersecurity · 38d ago Can someone recommend me some good, large universities to study cybersecurity? cybersecurity · 38d ago New guy khikhi cybersecurity · 38d ago Examples of intentional backdoors being breached? cybersecurity · 38d ago Non-Compliant Vocab cybersecurity · 38d ago CTO at NCSC Summary: week ending May 24th For [Blue|Purple] Teams in Cyber Defence · 38d ago HackTheBox - MonitorsFour IppSec · 38d ago VPN Exploitation When Patched Doesn't Mean Protected For [Blue|Purple] Teams in Cyber Defence · 38d ago Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation For [Blue|Purple] Teams in Cyber Defence · 38d ago Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites cybersecurity · 38d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 38d ago CLR-Stomp: .NET CLR-Stomping For [Blue|Purple] Teams in Cyber Defence · 38d ago infostealers just spawned a 5,000+ repo github supply chain attack cybersecurity · 38d ago The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis cybersecurity · 38d ago Doom running on a Kids Video Walkie Talkie hacking: security in practice · 38d ago GRO frag cybersecurity · 38d ago We audited 12K n8n templates: most have critical vulnerabilities cybersecurity · 38d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 38d ago Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week cybersecurity · 38d ago Mitigated Vulnerabilities by Vendor as Feed cybersecurity · 38d ago From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence For [Blue|Purple] Teams in Cyber Defence · 38d ago Introducing Showboat: A new malware family taunts defenses and targets international telecom firms For [Blue|Purple] Teams in Cyber Defence · 38d ago Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor For [Blue|Purple] Teams in Cyber Defence · 38d ago Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors cybersecurity · 38d ago A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories cybersecurity · 38d ago Where can I find the tools freely on internet to practice for soc analyst cybersecurity · 38d ago Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX. hacking: security in practice · 38d ago Pardon MIE?: how Mythos did not bypass Apple MIE Technical Information Security Content & Discussion · 38d ago residential proxies cybersecurity · 38d ago Recommendations for getting started in cybersecurity cybersecurity · 38d ago Linux mint or Ubuntu for complete beginner cybersecurity · 38d ago Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. cybersecurity · 38d ago Pentesting company recommendation cybersecurity · 38d ago Have you ever failed a certification exam? cybersecurity · 38d ago AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance cybersecurity · 38d ago This ID Verification company store users biometrics? (FaceTec) hacking: security in practice · 38d ago What do i need to learn to get into application security? Which Degrees/Certs cybersecurity · 38d ago RSAC online membership? Is it worth it? cybersecurity · 38d ago Playwright version that lets AI-Agents navigate the web hacking: security in practice · 38d ago Can someone give me a detailed roadmap for becoming a SOC Analyst? cybersecurity · 38d ago Puedo conseguir trabajo? cybersecurity · 38d ago How do i learn networking for cyber security? cybersecurity · 38d ago What's going to be Hacking and Cybersecurity's future is gonna be like? cybersecurity · 38d ago Cyber security placement - Interview Help cybersecurity · 38d ago CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module Technical Information Security Content & Discussion · 38d ago Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge cybersecurity · 38d ago AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22) For [Blue|Purple] Teams in Cyber Defence · 38d ago CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22) Reverse Engineering · 38d ago AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22 Technical Information Security Content & Discussion · 38d ago Feedback needed cybersecurity · 38d ago GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks. For [Blue|Purple] Teams in Cyber Defence · 38d ago Handoff Transition cybersecurity · 38d ago Where to learn the ins and outs of the computer itself hacking: security in practice · 38d ago Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't) Technical Information Security Content & Discussion · 38d ago Just added an interactive security map showing exactly what the server sees (and doesn't) cybersecurity · 38d ago Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns For [Blue|Purple] Teams in Cyber Defence · 38d ago Trend Micro warns of Apex One zero-day exploited in the wild cybersecurity · 39d ago Lawmakers Demand Answers as CISA Tries to Contain Data Leak cybersecurity · 39d ago Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL? For [Blue|Purple] Teams in Cyber Defence · 39d ago Lawmakers Demand Answers as CISA Tries to Contain Data Leak Krebs on Security · 39d ago https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/ cybersecurity · 39d ago Harvard and 140 other legitimate websites compromised Malware Analysis & Reports · 39d ago Harvard and 140 other legitimate websites compromised cybersecurity · 39d ago Votre Satisfaction Dans Votre Travail cybersecurity · 39d ago Soft Skills for the Job Market: Communication The Cyber Mentor · 39d ago 5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. cybersecurity · 39d ago Browser session theft is quietly becoming more dangerous than password theft Malware Analysis & Reports · 39d ago US states urge Congress to renew cybersecurity grants cybersecurity · 39d ago Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension Technical Information Security Content & Discussion · 39d ago Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours Malware Analysis & Reports · 39d ago Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes Reverse Engineering · 39d ago The CISO's Guide to IDE Security in 2026 cybersecurity · 39d ago Help with evilginx cybersecurity · 39d ago Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint News Feed · 39d ago Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets Technical Information Security Content & Discussion · 39d ago Watching AI Brain Drain on Attackers in Real Time cybersecurity · 39d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 39d ago api-rta cyberwarfare labs cybersecurity · 39d ago Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator hacking: security in practice · 39d ago I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner For [Blue|Purple] Teams in Cyber Defence · 39d ago The Worm That Deletes Your Entire Computer | Threat Wire Hak5 · 39d ago Does Security Implement Fixes? cybersecurity · 39d ago Ultimate Cybersecurity without needing AV ect? cybersecurity · 39d ago Hack your corrupt company. Sell their secrets to the black market hacking: security in practice · 39d ago User Onboarding with IAM cybersecurity · 39d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 39d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 39d ago Data breach in name of protest Technical Information Security Content & Discussion · 39d ago qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb) Reverse Engineering · 39d ago pnpm 11 Might Finally Be a Better Default Than npm Technical Information Security Content & Discussion · 39d ago pnpm 11 Might Finally Be a Better Default Than npm cybersecurity · 39d ago 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs cybersecurity · 39d ago Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria cybersecurity · 39d ago AI-generated reporting: Lessons learned from Cisco Talos Incident Response For [Blue|Purple] Teams in Cyber Defence · 39d ago CrabLoader: A PoC Cobalt Strike UDRL written in Rust For [Blue|Purple] Teams in Cyber Defence · 39d ago The 429 Microsoft Graph Mystery For [Blue|Purple] Teams in Cyber Defence · 39d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 39d ago Azure Tenant Enumeration is Dead For [Blue|Purple] Teams in Cyber Defence · 39d ago A Deep Dive into Codex Windows Sandbox For [Blue|Purple] Teams in Cyber Defence · 39d ago Striga: Lifting x86 to LLVM IR with Python For [Blue|Purple] Teams in Cyber Defence · 39d ago Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip" cybersecurity · 39d ago Looking for a cybersecurity professional to interview for a university project (interview in French) cybersecurity · 39d ago Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise WeLiveSecurity · 39d ago Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise WeLiveSecurity · 39d ago veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker. For [Blue|Purple] Teams in Cyber Defence · 39d ago Windows BitLocker Security Feature Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 39d ago CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility For [Blue|Purple] Teams in Cyber Defence · 39d ago Google API keys keep working after you delete them long enough to be exploited For [Blue|Purple] Teams in Cyber Defence · 39d ago Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? For [Blue|Purple] Teams in Cyber Defence · 39d ago North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT For [Blue|Purple] Teams in Cyber Defence · 39d ago Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit For [Blue|Purple] Teams in Cyber Defence · 39d ago Safe read-only check script for Copy Fail / CVE-2026-31431 cybersecurity · 39d ago New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible? cybersecurity · 39d ago Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names) For [Blue|Purple] Teams in Cyber Defence · 39d ago [TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly cybersecurity · 39d ago Cisco used AI to write security incident reports, with mixed results cybersecurity · 39d ago [TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM) cybersecurity · 39d ago Reverse Engineered Google reCAPTCHA Reverse Engineering · 39d ago Cyber Insurance Actuary Looking for Educational Resources cybersecurity · 39d ago As a bank , how do i give protected access to claude to my team? cybersecurity · 39d ago Can seasonal Apple Store employees apply for internal IT/cybersecurity roles? cybersecurity · 39d ago Reliable IP reputation check tools besides IPQS?(for work) cybersecurity · 39d ago 🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget hacking: security in practice · 39d ago Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026) cybersecurity · 39d ago Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins cybersecurity · 39d ago Hacked by Rat Tools for 2.5 years. cybersecurity · 39d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Trend Micro Research, News, Perspectives · 39d ago A TL;DR on Dirty Frag #cybersecurity #threatwire @endingwithali Hak5 · 39d ago Google’s Silent AI Install: What They’re Hiding in Your Files #cybersecurity @endi Hak5 · 39d ago Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada CyberScoop · 39d ago Google API Keys Remain Active After Deletion cybersecurity · 39d ago Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens For [Blue|Purple] Teams in Cyber Defence · 39d ago Summer of CCNA - 90 Minute - Session 2 NetworkChuck · 39d ago how do cyber sec consultants and pentesters actually get new clients? cybersecurity · 39d ago Post Incident Paranoia? cybersecurity · 39d ago Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector cybersecurity · 39d ago Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada Krebs on Security · 39d ago Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity? cybersecurity · 39d ago Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready cybersecurity · 39d ago You can counter MEMZ with Krotten in XP cybersecurity · 39d ago What are the most effective ways to do Blackbox testing? cybersecurity · 39d ago Npm registry sets stage for more secure package publishing cybersecurity · 39d ago Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support cybersecurity · 39d ago Megalodon: CI/CD Malware Spreading Across GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 39d ago Lawmakers from both parties say CISA cuts have gone too far CyberScoop · 39d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave Technical Information Security Content & Discussion · 39d ago Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK cybersecurity · 39d ago Is the Cybercorps SFS still worth it? cybersecurity · 39d ago Microsoft warns hackers are exploiting password resets to gain access to user accounts cybersecurity · 39d ago Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame cybersecurity · 39d ago How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account Malware Analysis & Reports · 39d ago WORM USB drives cybersecurity · 39d ago An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model? cybersecurity · 39d ago Trump postpones executive order focused on AI security CyberScoop · 39d ago CISOs - Holding the Line cybersecurity · 39d ago [Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled Technical Information Security Content & Discussion · 39d ago Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware Reverse Engineering · 39d ago A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale cybersecurity · 39d ago Security Scroll Down? cybersecurity · 39d ago mass github repo backdooring via CI workflows(Megalodon) cybersecurity · 39d ago I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP Reverse Engineering · 39d ago 📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity. For [Blue|Purple] Teams in Cyber Defence · 39d ago CISA chief frets about open-source vulnerabilities, delayed security improvements CyberScoop · 40d ago Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit? cybersecurity · 40d ago Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks For [Blue|Purple] Teams in Cyber Defence · 40d ago Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude Proofpoint News Feed · 40d ago GitHub Actions Cache Poisoning is eating open source Technical Information Security Content & Discussion · 40d ago European authorities take down prolific cybercrime VPN service CyberScoop · 40d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Reverse Engineering · 40d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox For [Blue|Purple] Teams in Cyber Defence · 40d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox cybersecurity · 40d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Technical Information Security Content & Discussion · 40d ago CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat Technical Information Security Content & Discussion · 40d ago beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA For [Blue|Purple] Teams in Cyber Defence · 40d ago FatGid - FreeBSD 14.x kernel LPE Technical Information Security Content & Discussion · 40d ago DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind cybersecurity · 40d ago FaceTec (ID verification) company appears to store user biometrics cybersecurity · 40d ago Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) Technical Information Security Content & Discussion · 40d ago CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication cybersecurity · 40d ago CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat hacking: security in practice · 40d ago It seems that FaceTec (ID Verification company) allows for storage of user biometrics cybersecurity · 40d ago Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check. cybersecurity · 40d ago Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data cybersecurity · 40d ago This ID verification company allows for storage of biometric data? hacking: security in practice · 40d ago What Questions Do You Ask During SSP Control Interviews? cybersecurity · 40d ago Feed The Cat BackDoor cybersecurity · 40d ago Flipper One - Asking for help from the community cybersecurity · 40d ago Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 40d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 40d ago Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign For [Blue|Purple] Teams in Cyber Defence · 40d ago Flipper One — tech specs cybersecurity · 40d ago Architecture Zero Trust détaillée cybersecurity · 40d ago I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :) hacking: security in practice · 40d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 40d ago ABB Terra AC Wallbox All CISA Advisories · 40d ago Hitachi Energy GMS600 All CISA Advisories · 40d ago ABB B&R Automation Studio All CISA Advisories · 40d ago ABB B&R Automation Runtime All CISA Advisories · 40d ago ABB B&R PCs All CISA Advisories · 40d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 40d ago Cybersecurity in Healthcare cybersecurity · 40d ago Staged publishing for npm packages | npm Docs cybersecurity · 40d ago 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though) cybersecurity · 40d ago Neither MFA, Passkey, nor trusted IP help here cybersecurity · 40d ago cyber security remote cybersecurity · 40d ago Database of Malicious Browser Extensions Malware Analysis & Reports · 40d ago SeekYou — one input, 15 recon sources, one report. hacking: security in practice · 40d ago I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries Reverse Engineering · 40d ago CSIRT incident response cybersecurity · 40d ago The readiness paradox: Why a false sense of cyber confidence is becoming a liability CyberScoop · 40d ago Trying to find a graduate role cybersecurity · 40d ago bypass internet restrictions hacking: security in practice · 40d ago GitHub ~3,800 internal repos compromised through a malicious VS Code extension Technical Information Security Content & Discussion · 40d ago I’ve got 99 problems, and IOCX isn’t one. Malware Analysis & Reports · 40d ago Microsoft warns of new Defender zero-days exploited in attacks cybersecurity · 40d ago From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree For [Blue|Purple] Teams in Cyber Defence · 40d ago How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102) For [Blue|Purple] Teams in Cyber Defence · 40d ago Iran-linked Operators Suspected in ATG Breaches For [Blue|Purple] Teams in Cyber Defence · 40d ago Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs For [Blue|Purple] Teams in Cyber Defence · 40d ago Compromised Nx Console version 18.95.0 For [Blue|Purple] Teams in Cyber Defence · 40d ago CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path For [Blue|Purple] Teams in Cyber Defence · 40d ago From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat For [Blue|Purple] Teams in Cyber Defence · 40d ago Webworm: New burrowing techniques For [Blue|Purple] Teams in Cyber Defence · 40d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) For [Blue|Purple] Teams in Cyber Defence · 40d ago what is the best security app option for pixel8a? cybersecurity · 40d ago How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) cybersecurity · 40d ago IoT Security cybersecurity · 40d ago GitHub links repo breach to TanStack npm supply-chain attack cybersecurity · 40d ago Another working Linux LPE exploit is out. How are teams treating local-only bugs now? cybersecurity · 40d ago Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks cybersecurity · 40d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 40d ago Google publishes exploit code threatening millions of Chromium users cybersecurity · 40d ago landing a remote Vulnerability Management role cybersecurity · 40d ago Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case. cybersecurity · 40d ago I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting? cybersecurity · 40d ago Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit cybersecurity · 40d ago Can someone unlock a list of the 500-1000 most visited websites online? hacking: security in practice · 40d ago The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It. Recorded Future · 40d ago Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure For [Blue|Purple] Teams in Cyber Defence · 40d ago Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation For [Blue|Purple] Teams in Cyber Defence · 40d ago Wordlist generator based on WordNet graphs + LLM hacking: security in practice · 40d ago What volume of TPRM do you handle per month? cybersecurity · 40d ago GitHub’s Fake Engagement Problem Is Hiding in Plain Sight For [Blue|Purple] Teams in Cyber Defence · 40d ago Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR) For [Blue|Purple] Teams in Cyber Defence · 40d ago GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam) Reverse Engineering · 40d ago safest virtual machine? cybersecurity · 40d ago Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration cybersecurity · 40d ago Meet Rampart and Clarity, Microsoft’s new red team combo AI agents CyberScoop · 40d ago wordpress memberpress hacking: security in practice · 40d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware cybersecurity · 40d ago Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage For [Blue|Purple] Teams in Cyber Defence · 40d ago GitHub notifications cybersecurity · 40d ago The Open Source USB Drive Built for Privacy hacking: security in practice · 40d ago Is there no more privacy left in the world? cybersecurity · 40d ago AI Agents defeat obfuscated JavaScript in 10 minutes Reverse Engineering · 40d ago Microsoft Edge had a password blunder, and it raises a bigger browser trust problem cybersecurity · 40d ago Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network cybersecurity · 40d ago Aconselhamento / mini texto cybersecurity · 40d ago CISA with an absolutely embarrassing data leak. cybersecurity · 40d ago Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys cybersecurity · 40d ago Anyone else feeling like static AppSec workflows are starting to hit limits? cybersecurity · 41d ago Is someone trying to hack me? hacking: security in practice · 41d ago What is it Wednesdays: Episode 0002 Reverse Engineering · 41d ago GitHub breach highlights developer tools as part of attack surface cybersecurity · 41d ago Why do some malware use unique user-agent strings? cybersecurity · 41d ago Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability Cisco Security Advisory · 41d ago Cisco Secure Workload Unauthorized API Access Vulnerability Cisco Security Advisory · 41d ago Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability Cisco Security Advisory · 41d ago Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability Cisco Security Advisory · 41d ago Encrypted emails bypassing email security tool cybersecurity · 41d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era For [Blue|Purple] Teams in Cyber Defence · 41d ago GitHub says internal repositories were impacted in poisoned VS Code extension attack CyberScoop · 41d ago Ctf groups cybersecurity · 41d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era cybersecurity · 41d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era Technical Information Security Content & Discussion · 41d ago cpu backdoor hacking: security in practice · 41d ago CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis Technical Information Security Content & Discussion · 41d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 41d ago Opensource that automatically scans your git repos for breaches cybersecurity · 41d ago 5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready For [Blue|Purple] Teams in Cyber Defence · 41d ago TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post) Reverse Engineering · 41d ago Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing Reverse Engineering · 41d ago CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers Technical Information Security Content & Discussion · 41d ago Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online Technical Information Security Content & Discussion · 41d ago CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed. cybersecurity · 41d ago Your developers are deploying agents in your production environment right now. You have no governance for it. cybersecurity · 41d ago Technical analysis of CVE-2026-34472 in ZTE H188A router firmware hacking: security in practice · 41d ago ¿Como me preparo para EC-Council CSA? cybersecurity · 41d ago The IBM X-Force Index 2026 explains all three in one finding. cybersecurity · 41d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 41d ago Securing iPad's question cybersecurity · 41d ago Cybersecurity 101 cybersecurity · 41d ago What would this job role be? cybersecurity · 41d ago MSPs & MSSPs suck cybersecurity · 41d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 41d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog All CISA Advisories · 41d ago [ Removed by Reddit ] cybersecurity · 41d ago GitHub hit by a compromised VSCode extension Technical Information Security Content & Discussion · 41d ago Crossroads cybersecurity · 41d ago Advice regarding "SOC" job that automates everything cybersecurity · 41d ago Is this Medium article about "NetMirror" malware legit? cybersecurity · 41d ago AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon? cybersecurity · 41d ago Developer tooling is part of the attack surface before a project is even run cybersecurity · 41d ago How to build .NET obfuscator Reverse Engineering · 41d ago botguard-token-generator / a google botguard token gen using only requests...? Reverse Engineering · 41d ago Remote Process Read Primitive via NtCreateThreadEx Exit Code For [Blue|Purple] Teams in Cyber Defence · 41d ago GUEST ESSAY: AI can speed up communication, but it can also weaken human connection The Last Watchdog · 41d ago How the hell do you manage developers, their code, their apps? cybersecurity · 41d ago Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed cybersecurity · 41d ago aimap: Discover Exposed AI Services For [Blue|Purple] Teams in Cyber Defence · 41d ago FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation. For [Blue|Purple] Teams in Cyber Defence · 41d ago Ongoing development hacking: security in practice · 41d ago Webworm: New burrowing techniques WeLiveSecurity · 41d ago Webworm: New burrowing techniques WeLiveSecurity · 41d ago Why China Is Now a Peer Competitor to the United States in Cyberspace For [Blue|Purple] Teams in Cyber Defence · 41d ago When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax Technical Information Security Content & Discussion · 41d ago Do people still rely on antivirus software in 2026, or is built-in security enough now? cybersecurity · 41d ago For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks? hacking: security in practice · 41d ago GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories cybersecurity · 41d ago Automatic CLI for spinning up vulnerable labs + objectives cybersecurity · 41d ago Hackers found a way around Intel CET—PLaTypus locks down library jumps hacking: security in practice · 41d ago ISO/IEC 27701 scenario question cybersecurity · 41d ago Discord rolls out end-to-end encryption on voice, video calls cybersecurity · 41d ago nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings For [Blue|Purple] Teams in Cyber Defence · 41d ago GitHub investigates internal repositories breach claimed by TeamPCP cybersecurity · 41d ago Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt For [Blue|Purple] Teams in Cyber Defence · 41d ago We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. For [Blue|Purple] Teams in Cyber Defence · 41d ago Two AI-based science assistants succeed with drug-retargeting tasks cybersecurity · 41d ago GitHub investigates internal repositories breach claimed by TeamPCP hacking: security in practice · 41d ago Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings) For [Blue|Purple] Teams in Cyber Defence · 41d ago America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames cybersecurity · 41d ago An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now. cybersecurity · 41d ago We audited 12K n8n templates: most have critical vulnerabilities Technical Information Security Content & Discussion · 41d ago Veilgate - Deception proxy Technical Information Security Content & Discussion · 41d ago Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild For [Blue|Purple] Teams in Cyber Defence · 41d ago New to cybersecurity cybersecurity · 41d ago Anyone interview or work with Moxfive? cybersecurity · 41d ago A stealth Firefox version that passes all anti-bot and CAPTCHA cybersecurity · 41d ago mkPIVM - a polymorphic position-independent shellcode virtualizer cybersecurity · 41d ago Started in IT and need a Cybersecurity Roadmap with my Useless Degree! cybersecurity · 41d ago GitHub announces internal data breached. cybersecurity · 41d ago Roadmap to Cybersecurity roles cybersecurity · 41d ago Hackers: What age did you start? Where did you start, especially in practicing your skills? hacking: security in practice · 41d ago CISA credential leak raises alarms, and Capitol Hill demands answers CyberScoop · 41d ago Malware installed without literally doing anything? cybersecurity · 41d ago CTFs cybersecurity · 41d ago Can't access anything Malware Analysis & Reports · 41d ago How to watch a private video on Youtube? hacking: security in practice · 41d ago Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches CyberScoop · 41d ago Sleeping Agent: Silent persistent C2 through Web Push Technical Information Security Content & Discussion · 41d ago Crossroads cybersecurity · 41d ago Canara Bank SuRaksha Cyber Hackathon 2.0, cybersecurity · 41d ago Eight Leading U.S. Communications Firms Form C2 ISAC For [Blue|Purple] Teams in Cyber Defence · 41d ago Can I do anything cool with this network controller? hacking: security in practice · 41d ago News alert: Orchid Security study finds invisible identities now outnumber managed accounts The Last Watchdog · 41d ago Anti BOT Tipps und Tricks gesucht. cybersecurity · 41d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security cybersecurity · 41d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 41d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security Technical Information Security Content & Discussion · 41d ago New to Cybersecurity cybersecurity · 41d ago Micro controller safety? hacking: security in practice · 41d ago Is the ISC2 Certified in Cybersecurity worth it? cybersecurity · 41d ago Average Days to Close by Source CNAPP Severity Tag 2026 cybersecurity · 41d ago I want free nmap resource cybersecurity · 41d ago If I clear browser history regularly, does it reduce the chances of malware that target browser data? cybersecurity · 41d ago Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Cisco Security Advisory · 41d ago What is next after 1.5 Year as Security Analyst? cybersecurity · 41d ago Analysis advice cybersecurity · 41d ago Stop me if you heard this one before... (YellowKey related) cybersecurity · 41d ago UAC-0184: From HTA to a Signed Network Stack For [Blue|Purple] Teams in Cyber Defence · 42d ago Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe? cybersecurity · 42d ago Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing) Reverse Engineering · 42d ago Looking for advice: where should I post/publish CVE write-ups? cybersecurity · 42d ago CISA Admin Leaked AWS GovCloud Keys on Github hacking: security in practice · 42d ago New GMKtec M7 Ultra appears to be infected. Beware of the malware! Malware Analysis & Reports · 42d ago Cybersecurity statistics of the week (May 11th - May 17th) cybersecurity · 42d ago How can I test my website locally for cybersecurity? cybersecurity · 42d ago Mini Shai-Hulud returns, compromising hundreds of npm packages CyberScoop · 42d ago Use of coding in security operations cybersecurity · 42d ago Decompilation of DSP Code using IDA Pro hacking: security in practice · 42d ago Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz cybersecurity · 42d ago Microsoft disrupts cybercrime service that abused software verification systems en masse cybersecurity · 42d ago I've built an open source honeypot probe database accessible via curl, http and mcp cybersecurity · 42d ago New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here For [Blue|Purple] Teams in Cyber Defence · 42d ago Deep dive into the object creation flow in Windows - PART 4: Handle table internals. Reverse Engineering · 42d ago 6,000+ Automatic Tank Gauges Exposed With No Authentication cybersecurity · 42d ago Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email? cybersecurity · 42d ago How Storm-2949 turned a compromised identity into a cloud-wide breach For [Blue|Purple] Teams in Cyber Defence · 42d ago Microsoft disrupts cybercrime service that abused software verification systems en masse CyberScoop · 42d ago How Storm-2949 turned a compromised identity into a cloud-wide breach Technical Information Security Content & Discussion · 42d ago If humans are the weakest link, why won't companies evolve? cybersecurity · 42d ago Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?" cybersecurity · 42d ago Entra ID: PIM for Groups Review For [Blue|Purple] Teams in Cyber Defence · 42d ago Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM cybersecurity · 42d ago Local transcription vs cloud transcription, which actually feels safer? cybersecurity · 42d ago Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today? cybersecurity · 42d ago Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise cybersecurity · 42d ago TeamPCP compromises NPM maintainer with over 540 packages For [Blue|Purple] Teams in Cyber Defence · 42d ago Shai-Hulud source leak is turning npm malware into a copycat problem cybersecurity · 42d ago Framework for Preventing Secret Ideas from Leakage cybersecurity · 42d ago Kieback & Peter DDC Building Controllers All CISA Advisories · 42d ago Siemens RUGGEDCOM APE1808 Devices All CISA Advisories · 42d ago ABB CoreSense HM and CoreSense M10 All CISA Advisories · 42d ago ScadaBR All CISA Advisories · 42d ago ZKTeco CCTV Cameras All CISA Advisories · 42d ago Local LLM for building AI Security platform cybersecurity · 42d ago SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access cybersecurity · 42d ago Emerging Cyber security niches cybersecurity · 42d ago ISO/IEC 27701 cybersecurity · 42d ago Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware Reverse Engineering · 42d ago Solo dev building a terminal-heavy hacking game inspired by corporate security cybersecurity · 42d ago Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations cybersecurity · 42d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments Technical Information Security Content & Discussion · 42d ago CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing Technical Information Security Content & Discussion · 42d ago CS/IT Student Looking to Grow My LinkedIn Network 😃 cybersecurity · 42d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) hacking: security in practice · 42d ago Open-source Hermes bytecode decompiler for React Native apps (Rust) Reverse Engineering · 42d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) cybersecurity · 42d ago Is Amazon Cognito a good choice long term? Alternatives? cybersecurity · 42d ago Was hacking easier in the 80s and 90s and early 2000s? cybersecurity · 42d ago Need some Advice in SOAR heavy environment cybersecurity · 42d ago Trying to find serious builders in cybersecurity - not just “let’s build” conversations cybersecurity · 42d ago Hermes bytecode decompiler (Rust) - sharing my friend’s project Reverse Engineering · 42d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields hacking: security in practice · 42d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields Technical Information Security Content & Discussion · 42d ago Active Supply Chain Attack Compromises @antv Packages on npm... For [Blue|Purple] Teams in Cyber Defence · 42d ago AI Phishing cybersecurity · 42d ago The quest for greater tech independence WeLiveSecurity · 42d ago The quest for greater tech independence WeLiveSecurity · 42d ago One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals cybersecurity · 42d ago When DMCA Comes Knocking - A YouTube Creator Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 42d ago [Cloudflare] Project Glasswing: what Mythos showed us For [Blue|Purple] Teams in Cyber Defence · 42d ago vpn explained the simple version that actually makes sense Malware Analysis & Reports · 42d ago How easy is it to get into the cyber security field? cybersecurity · 42d ago Forza Designer 6 Reverse Engineering · 42d ago 314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js cybersecurity · 42d ago Built a full disassembler & decompiler for Reverse Engineering | Free and open source. hacking: security in practice · 42d ago Built a full disassembler & decompiler | Free and open source. Reverse Engineering · 42d ago Slopinator - a poisoned GitHub repository generator hacking: security in practice · 42d ago Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start? cybersecurity · 42d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) Technical Information Security Content & Discussion · 42d ago ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo cybersecurity · 42d ago CEH/CPENT vs OSCP vs GPEN cybersecurity · 42d ago ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro” cybersecurity · 42d ago CISA Contractor Admin Leaked AWS GovCloud Keys on Github cybersecurity · 42d ago Made a shell greeter that generates a unique rocket every time you open a terminal tab hacking: security in practice · 42d ago Suspecious activity in my account cybersecurity · 42d ago Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Trend Micro Research, News, Perspectives · 42d ago At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026 Recorded Future · 42d ago Is it safe to use my first name and middle name on platforms? cybersecurity · 42d ago Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice. cybersecurity · 42d ago Just received an email from shinyhunters about their amtrack hack cybersecurity · 42d ago Just received an email from shinyhackers about their amtrack hack hacking: security in practice · 42d ago Flipper Zero (or Alternatives)? hacking: security in practice · 42d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access cybersecurity · 42d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access hacking: security in practice · 42d ago Bywaf: an auditable Python commandlet framework for chained pentest workflows cybersecurity · 42d ago For anyone currently working in a SOC: cybersecurity · 42d ago Fellow Tier 1 SOC/Security Analysts - What does your day to day look like? cybersecurity · 42d ago The quiet death of behavioral anti-bot and the pivot to hardware ZKPs Technical Information Security Content & Discussion · 42d ago SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain For [Blue|Purple] Teams in Cyber Defence · 42d ago CISA Admin Leaked AWS GovCloud Keys on Github Krebs on Security · 42d ago AI might cut false positives, but it won’t stop the slop CyberScoop · 42d ago Recent WhatsApp hacks hacking: security in practice · 42d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 42d ago How do you threat hunt for RMM tools in environments where RMM is all over the place? cybersecurity · 42d ago Decompilation projects and N64 Recompiled PC ports (May 2026) Reverse Engineering · 42d ago Microsoft - "your single use code" email when it was not requested by yourself cybersecurity · 42d ago Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa CyberScoop · 42d ago Directory of vendor security questionnaires cybersecurity · 42d ago Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised cybersecurity · 42d ago I wrote an async scanner that runs about 9x faster than nmap for discovery. hacking: security in practice · 42d ago MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals cybersecurity · 42d ago AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems Technical Information Security Content & Discussion · 42d ago Glass - A fast and free interactive disassembler Reverse Engineering · 42d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. Technical Information Security Content & Discussion · 42d ago Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers hacking: security in practice · 42d ago Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight cybersecurity · 43d ago Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger For [Blue|Purple] Teams in Cyber Defence · 43d ago Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics For [Blue|Purple] Teams in Cyber Defence · 43d ago How is AI affecting the cybersecurity market? cybersecurity · 43d ago MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack The Last Watchdog · 43d ago MCP security cybersecurity · 43d ago YellowKey Mitigation cybersecurity · 43d ago CrystalX: unpacking a Go RAT through three encrypted layers For [Blue|Purple] Teams in Cyber Defence · 43d ago Anyone else on the receiving end of ShinyHunters extortion email? cybersecurity · 43d ago Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs cybersecurity · 43d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Reverse Engineering · 43d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Malware Analysis & Reports · 43d ago What’s the biggest mistake people still make about online security in 2026? cybersecurity · 43d ago Anthropic shuts the EU out of its most advanced cyber AI model cybersecurity · 43d ago Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens] cybersecurity · 43d ago Best hotel for attending all three conferences in Vegas? cybersecurity · 43d ago What's your company's actual PQC migration plan? Not the one on paper - the real one. cybersecurity · 43d ago The down fall of bug bounties Technical Information Security Content & Discussion · 43d ago The Boring Stuff is Dangerous Now darkreading · 43d ago This GitHub README Hijacks Your AI and Spreads Like a Virus NahamSec · 43d ago New video: hacking AI coding assistants and IDEs. #bugbounty #ai NahamSec · 43d ago Does buying local cybersecurity (services/products/etc) matter to you? cybersecurity · 43d ago LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose cybersecurity · 43d ago Detection Engineering AI Maturity Framework cybersecurity · 43d ago Microsoft code cybersecurity · 43d ago TanStack Supply Chain Attack (And How to Lock Down GitHub Actions) Technical Information Security Content & Discussion · 43d ago Microsoft confirms Windows 11 security update install issues cybersecurity · 43d ago Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ cybersecurity · 43d ago Exploit available for new DirtyDecrypt Linux root escalation flaw cybersecurity · 43d ago Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware cybersecurity · 43d ago Suspicious with a company offer letter cybersecurity · 43d ago The Canvas breach proved that prevention is no longer enough CyberScoop · 43d ago Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first? cybersecurity · 43d ago Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation Technical Information Security Content & Discussion · 43d ago Why do some recovery workflows still require full wallet uploads? cybersecurity · 43d ago Netmirror exposed - The Free Movie App That Was Robbing You Blind Malware Analysis & Reports · 43d ago Need help with interview for soc l1 cybersecurity · 43d ago Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap) cybersecurity · 43d ago HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try! Reverse Engineering · 43d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 43d ago Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation Technical Information Security Content & Discussion · 43d ago Reverse engineering no dep x64 masm AI IDE Reverse Engineering · 43d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released cybersecurity · 43d ago carrer path in cybersecurity for a btech stud cybersecurity · 43d ago Agents usage in production cybersecurity · 43d ago ‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K cybersecurity · 43d ago Former CISA nominee Sean Plankey named US CEO of defense startup CyberScoop · 43d ago Are teams still finding AI API keys in public repos? cybersecurity · 43d ago Can Laws Stop Deepfakes? South Korea Aims to Find Out darkreading · 43d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 43d ago Agentic Governance: Why It Matters Now Trend Micro Research, News, Perspectives · 43d ago Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here? cybersecurity · 43d ago Does the CBP bug phones? cybersecurity · 43d ago What We Learned Building Runtime Visibility for Modern Telco Networks cybersecurity · 43d ago Ive got my Spotify account hacked! How do I solve this? cybersecurity · 43d ago The Politics of AI Transparency cybersecurity · 43d ago A million baby monitors and security cameras were easily viewable by hackers cybersecurity · 43d ago NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE cybersecurity · 43d ago Does anyone know if this file is still accessible to download? hacking: security in practice · 43d ago Is cybersecurity becoming more behavioral than technical? cybersecurity · 43d ago Questions About Promo Items for a Cybersecurity Conference cybersecurity · 43d ago DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write For [Blue|Purple] Teams in Cyber Defence · 43d ago Dois-je m'inquiéter ? cybersecurity · 43d ago I am dying to work abroad , rate my journey so far cybersecurity · 43d ago FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation For [Blue|Purple] Teams in Cyber Defence · 43d ago Microsoft - "Your single use code" email when it was not requested cybersecurity · 43d ago Security / Compliance work going Agentic? cybersecurity · 43d ago High school students organized a Jeopardy CTF competition - give it a try hacking: security in practice · 43d ago Don't believe the media, specially in cybersec cybersecurity · 43d ago Microsoft account keeps getting Authenticator requests? cybersecurity · 43d ago [Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated. cybersecurity · 43d ago Ansible security and compliance guide Technical Information Security Content & Discussion · 44d ago Malware learning Malware Analysis & Reports · 44d ago Struggling to generate security bulletins — any ideas? cybersecurity · 44d ago Certs to go into Security Engineer/architect cybersecurity · 44d ago 18882745552 beware of email with this number cybersecurity · 44d ago Transition from traditional penetration testing into AI security cybersecurity · 44d ago Seeking advice on next career steps cybersecurity · 44d ago Official Miasma Poison Tar Pit Docker Image Now Available hacking: security in practice · 44d ago Will the analyst role become obsolete? cybersecurity · 44d ago LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying" For [Blue|Purple] Teams in Cyber Defence · 44d ago Alert Fatigue cybersecurity · 44d ago Best path into cybersecurity for a high schooler? cybersecurity · 44d ago Static Kitten APT Adversary Simulation For [Blue|Purple] Teams in Cyber Defence · 44d ago 🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍 Hak5 · 44d ago Why Is Cybersecurity Now A Business Priority, Not Just An IT Function? Cyber Defense Magazine · 44d ago Keep getting hacked cybersecurity · 44d ago Eimeria: five layers from RAR5 to RunPE For [Blue|Purple] Teams in Cyber Defence · 44d ago ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only. For [Blue|Purple] Teams in Cyber Defence · 44d ago Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain Technical Information Security Content & Discussion · 44d ago How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices cybersecurity · 44d ago I’m interested in joining the Red Team Hackers Academy in Bangalore. cybersecurity · 44d ago openDCIM exploitation For [Blue|Purple] Teams in Cyber Defence · 44d ago PE packer/crypter with random VM ISA per build Reverse Engineering · 44d ago A clueless teenager 💔 cybersecurity · 44d ago HASBL CTF - A Jeopardy-Style CTF Organized by High School Students! For [Blue|Purple] Teams in Cyber Defence · 44d ago Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start? cybersecurity · 44d ago Am I overthinking Claude Code security or is this actually a risk? cybersecurity · 44d ago is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this cybersecurity · 44d ago ISO/IEC 27701 ( SoA ) Applicability cybersecurity · 44d ago Security Executive Playbook cybersecurity · 44d ago This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon cybersecurity · 44d ago We Have Packet Capture at Home For [Blue|Purple] Teams in Cyber Defence · 44d ago I feel crazy I hope someone has insight . cybersecurity · 44d ago Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware For [Blue|Purple] Teams in Cyber Defence · 44d ago HWMonitor Trojanized for STX RAT DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 44d ago awesome-dfir-skills: Admiralty System for CTI Claude skill For [Blue|Purple] Teams in Cyber Defence · 44d ago Mullvad exit IPs as a fingerprinting vector For [Blue|Purple] Teams in Cyber Defence · 44d ago Does anybody know where I may stumble upon some Sh1mmer bin downloads hacking: security in practice · 44d ago Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools For [Blue|Purple] Teams in Cyber Defence · 44d ago Popular node-ipc npm Package Infected with Credential Steale... For [Blue|Purple] Teams in Cyber Defence · 44d ago An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. For [Blue|Purple] Teams in Cyber Defence · 44d ago Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files For [Blue|Purple] Teams in Cyber Defence · 44d ago Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor For [Blue|Purple] Teams in Cyber Defence · 44d ago Sandworm Activity in Industrial Environments: What the Data Reveals For [Blue|Purple] Teams in Cyber Defence · 44d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 44d ago "Shadowserver-in-a-box" IntelMQ + ELK Solution For [Blue|Purple] Teams in Cyber Defence · 44d ago Stenloader: Steganography Shellcode Loader For [Blue|Purple] Teams in Cyber Defence · 44d ago AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out For [Blue|Purple] Teams in Cyber Defence · 44d ago Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018 For [Blue|Purple] Teams in Cyber Defence · 44d ago Our response to the TanStack npm supply chain attack For [Blue|Purple] Teams in Cyber Defence · 44d ago QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026). For [Blue|Purple] Teams in Cyber Defence · 44d ago We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. For [Blue|Purple] Teams in Cyber Defence · 44d ago APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox. For [Blue|Purple] Teams in Cyber Defence · 44d ago oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday For [Blue|Purple] Teams in Cyber Defence · 44d ago Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations For [Blue|Purple] Teams in Cyber Defence · 44d ago ΡHANTΟΜ Al-Powered Pentesting Command Center cybersecurity · 44d ago Interview Assessments cybersecurity · 44d ago We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it cybersecurity · 44d ago Questions about data blockers cybersecurity · 44d ago A Tale of Two File Names Reverse Engineering · 44d ago PE reconstruction Reverse Engineering · 44d ago OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance For [Blue|Purple] Teams in Cyber Defence · 44d ago Post Implementation task cybersecurity · 44d ago The Gentlemen Ransomware Group — Leak Analysis For [Blue|Purple] Teams in Cyber Defence · 44d ago Mythos, MOAK, CTEM and the End of CVE Chasing cybersecurity · 44d ago Cyber security jobs in Austria cybersecurity · 44d ago Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network hacking: security in practice · 44d ago Personal favorite deception layer. cybersecurity · 44d ago Estudiar Ciberseguridad cybersecurity · 44d ago Learning way cybersecurity · 44d ago A File Format Uncracked for 20 Years: Part 2 Reverse Engineering · 44d ago How do you report large volume detections to a CISO without making the BPA report a SOC story? cybersecurity · 44d ago HDD Firmware Hacking Part 1 For [Blue|Purple] Teams in Cyber Defence · 44d ago Can anyone share bugbase platform screenshot having professional usage on dashboard? cybersecurity · 44d ago ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. For [Blue|Purple] Teams in Cyber Defence · 44d ago CTO at NCSC Summary: week ending May 17th For [Blue|Purple] Teams in Cyber Defence · 44d ago CTO at NCSC Summary: week ending May 17th cybersecurity · 44d ago GZDoom in the browser hacking: security in practice · 44d ago Vidar v1.5 in Go: same family, new language, heavy sandbox checks For [Blue|Purple] Teams in Cyber Defence · 45d ago Developer credential-theft campaign exposed operator-side self-infection For [Blue|Purple] Teams in Cyber Defence · 45d ago Security Executive Playbook cybersecurity · 45d ago Tired of tab-switching between CTI tools - here's what we put together cybersecurity · 45d ago I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor cybersecurity · 45d ago Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source! Reverse Engineering · 45d ago Help-Desk Lures Drop KongTuke's Evolved ModeloRAT For [Blue|Purple] Teams in Cyber Defence · 45d ago Welcome to BlackFile: Inside a Vishing Extortion Operation For [Blue|Purple] Teams in Cyber Defence · 45d ago HackTheBox - Pterodactyl IppSec · 45d ago In Cybersecurity cybersecurity · 45d ago AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize. Technical Information Security Content & Discussion · 45d ago DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era For [Blue|Purple] Teams in Cyber Defence · 45d ago Stop Being Weird — Life After Call Stack Spoofing Under CET For [Blue|Purple] Teams in Cyber Defence · 45d ago Anyone else feel like most MSP tooling is either overkill or painfully manual? cybersecurity · 45d ago Thinkpad vs Macbook pro endpoint security cybersecurity · 45d ago Any more affordable alternatives to “IntelligenceX”? cybersecurity · 45d ago Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran cybersecurity · 45d ago tanstack checker github action cybersecurity · 45d ago Drivers Alpha AWUS036AXML cybersecurity · 45d ago Splunk download for free cybersecurity · 45d ago The Security Mistakes Being Repeated With Ai Cyber Defense Magazine · 45d ago Funnel Builder WordPress plugin bug exploited to steal credit cards cybersecurity · 45d ago Anyone here using pager duty? cybersecurity · 45d ago Scammer targeting posters cybersecurity · 45d ago Anyone know how to bypass these school laptop pins? hacking: security in practice · 45d ago Seeking advice cybersecurity · 45d ago Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works Technical Information Security Content & Discussion · 45d ago Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026) cybersecurity · 45d ago Just got an email about a single use code, maybe someone was trying to log in? cybersecurity · 45d ago Can a background in DevOps enter the cybersecurity field? cybersecurity · 45d ago [CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link. Reverse Engineering · 45d ago Triggering the Secure Boot Certificate Update with Intune Remediations For [Blue|Purple] Teams in Cyber Defence · 45d ago How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache For [Blue|Purple] Teams in Cyber Defence · 45d ago Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 For [Blue|Purple] Teams in Cyber Defence · 45d ago One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 45d ago CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) For [Blue|Purple] Teams in Cyber Defence · 45d ago Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 45d ago FamousSparrow APT Targets Azerbaijani Oil and Gas Industry For [Blue|Purple] Teams in Cyber Defence · 45d ago Disclosing new PebbleDash-based tools by Kimsuky For [Blue|Purple] Teams in Cyber Defence · 45d ago FrostyNeighbor: Fresh mischief and digital shenanigans For [Blue|Purple] Teams in Cyber Defence · 45d ago Kazuar: Anatomy of a nation-state botnet For [Blue|Purple] Teams in Cyber Defence · 45d ago OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments For [Blue|Purple] Teams in Cyber Defence · 45d ago NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys For [Blue|Purple] Teams in Cyber Defence · 45d ago Hacker Ringleader Extradited for 38 Billion Won Theft For [Blue|Purple] Teams in Cyber Defence · 45d ago Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System For [Blue|Purple] Teams in Cyber Defence · 45d ago Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit For [Blue|Purple] Teams in Cyber Defence · 45d ago The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation For [Blue|Purple] Teams in Cyber Defence · 45d ago FFFFirefox - A One-Day Wonder Renderer Exploit For [Blue|Purple] Teams in Cyber Defence · 45d ago MiniPlasma, a powerful LPE For [Blue|Purple] Teams in Cyber Defence · 45d ago Using ai in learning cybersecurity · 45d ago Exploiting Toshiba Qiomem.sys vulnerable driver Reverse Engineering · 45d ago Avanzamento area Blue Team/SOC cybersecurity · 45d ago Please what could be helpful cybersecurity · 45d ago HDD Firmware Hacking Part 1 Reverse Engineering · 45d ago CVE exploit chain cybersecurity · 45d ago What are the widely accepted SaaS security accreditations/audits an app should seek in fintech cybersecurity · 45d ago Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco cybersecurity · 45d ago Region-based binary diff tool for firmware analysis Reverse Engineering · 45d ago Major flaw in Indian Cyber and IT assurance landscape cybersecurity · 45d ago Red Team Ops Ⅱ ( CRTL ) exam preparation cybersecurity · 45d ago Recomendations cybersecurity · 45d ago A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Reverse Engineering · 45d ago Recommended cybersecurity certification for a UX designer new to the domain? cybersecurity · 45d ago แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป! Reverse Engineering · 45d ago insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server cybersecurity · 45d ago Career path cybersecurity · 45d ago Merit America offers a program that gets you into cyber security roles. cybersecurity · 45d ago Brovan — Open-source x86/x64 user-mode binary emulator written in C# Reverse Engineering · 45d ago Brovan: Binary user-mode emulator for x86_64 Reverse Engineering · 45d ago Brovan: Binary user-mode emulator for x86_64 Malware Analysis & Reports · 45d ago Brovan: Binary user-mode emulator for x86_64 cybersecurity · 45d ago AmEx Interview! cybersecurity · 45d ago A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA hacking: security in practice · 45d ago Developer credential-stealing pipeline also collected operator workstations cybersecurity · 45d ago need help building a case. cybersecurity · 45d ago Colorado governor commutes prison sentence for election denier Tina Peters CyberScoop · 45d ago Personal favorite SIEM platform? cybersecurity · 45d ago Cardputer ADV cybersecurity · 45d ago Alternative for Qualys cybersecurity · 45d ago I have a friend who looks like he’s a stalker I’m scared he will know I stalk him hacking: security in practice · 45d ago The 4th Linux kernel flaw this month can lead to stolen SSH host keys cybersecurity · 45d ago Congress Puts Heat on Instructure After Canvas Outage darkreading · 45d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 45d ago Stack Buffer Overflow Explained (Using a Classic Doom Bug) cybersecurity · 45d ago [Tutorial] How to hack DOS games: Reversing Prince of Persia hacking: security in practice · 45d ago Here’s how the FTC plans to enforce the Take It Down Act CyberScoop · 45d ago Understanding Stack Buffer Overflows Through Doom and C++ Reverse Engineering · 45d ago Confused about cybersecurity career cybersecurity · 45d ago What is it Wednesdays: Episode 0001 Reverse Engineering · 45d ago Transferring from pen test consulting to application security? cybersecurity · 45d ago Curso de especializacion de Ciberseguridad cybersecurity · 45d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? For [Blue|Purple] Teams in Cyber Defence · 45d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? cybersecurity · 45d ago Lost, tempted to throw in the towel cybersecurity · 45d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own cybersecurity · 45d ago I open-sourced a Docker security scanner I use to audit all my websites cybersecurity · 45d ago Testing Deception Technique cybersecurity · 45d ago A malware got into my account and spread spam ad to my friends and relatives cybersecurity · 46d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems Technical Information Security Content & Discussion · 46d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems cybersecurity · 46d ago Most pentest reports I review are padded with garbage findings cybersecurity · 46d ago Is dns spoofing dead?? hacking: security in practice · 46d ago Cyber Essentials and use of third party websites - MFA cybersecurity · 46d ago Rapid 7 and Cisa Kev cybersecurity · 46d ago Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup Reverse Engineering · 46d ago Deepdive into the object creation flow in Windows -PART 2 : access check internals Reverse Engineering · 46d ago Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization Reverse Engineering · 46d ago Anyone know much about MS Defender? cybersecurity · 46d ago My Privacy Focused USB Drive hacking: security in practice · 46d ago Cisco zero-day under ongoing attack by persistent threat group CyberScoop · 46d ago EN18031 for IoT: struggling to see the big picture — advice from experienced people? cybersecurity · 46d ago Japan’s 3DS Mandate: One Year In Blog – Forter · 46d ago Automating code security reviews with Claude Mythos-level capabilities Technical Information Security Content & Discussion · 46d ago Automating Code Security Reviews cybersecurity · 46d ago [Tool] IOCX — deterministic static IOC extraction for PE binaries For [Blue|Purple] Teams in Cyber Defence · 46d ago New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available cybersecurity · 46d ago [Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo) Reverse Engineering · 46d ago Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition) hacking: security in practice · 46d ago AI coding tools on developer machines — looking for input on how you're handling it cybersecurity · 46d ago Chrome 148 Update Patches Critical Vulnerabilities cybersecurity · 46d ago The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract Cyber Defense Magazine · 46d ago Microsoft warns of Exchange zero-day flaw exploited in attacks cybersecurity · 46d ago I need help. i am lost cybersecurity · 46d ago Novel Evilginx Frontend - Lowering the barrier for token theft reuse For [Blue|Purple] Teams in Cyber Defence · 46d ago Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence cybersecurity · 46d ago Cyber Pioneers Ponder Past as Prologue darkreading · 46d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 46d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 46d ago Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments cybersecurity · 46d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? cybersecurity · 46d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? For [Blue|Purple] Teams in Cyber Defence · 46d ago I'm going crazy. At the application level what I can actually do to prevent DDos? cybersecurity · 46d ago yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android. Reverse Engineering · 46d ago Is anyone enrolled in Intellipaat's cybersecurity course? cybersecurity · 46d ago Will AI Replace Cybersecurity Jobs? cybersecurity · 46d ago Why geopolitical turmoil is a gift for scammers, and how to stay safe WeLiveSecurity · 46d ago Why geopolitical turmoil is a gift for scammers, and how to stay safe WeLiveSecurity · 46d ago What's best certification choice after OSWE cybersecurity · 46d ago TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer hacking: security in practice · 46d ago Facebook Page Call Slipping through Sleep mode cybersecurity · 46d ago ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey cybersecurity · 46d ago New Linux LPE allows local users to read any file, including privkeys cybersecurity · 46d ago A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks. cybersecurity · 46d ago Your experience as IT Admin on Alerts cybersecurity · 46d ago Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time cybersecurity · 46d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild cybersecurity · 46d ago GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets Reverse Engineering · 46d ago GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS Reverse Engineering · 46d ago Instrumenting QT6 desktop apps with Frida - Part 1 Technical Information Security Content & Discussion · 46d ago From Vercel Typosquatting to an Obfuscated macOS Malware Loader Technical Information Security Content & Discussion · 46d ago Discord VC lag Exploit cybersecurity · 46d ago FrostyNeighbor: Fresh mischief and digital shenanigans cybersecurity · 46d ago Bug FB - Inicio de sesion por password cybersecurity · 46d ago Does anyone know how to configure EVILGINX for testing cybersecurity · 46d ago Trafexia V2 - Mobile Traffic Interceptor Toolkit Reverse Engineering · 46d ago How long does it take to get familiar with a tool cybersecurity · 46d ago Scam website cybersecurity · 46d ago ANTS Hack: 19 million records exposed in French ID agency breach cybersecurity · 46d ago has anyone used tail os here? hacking: security in practice · 46d ago Is it really that easy to obtain SMS codes using an SS7 attack? cybersecurity · 46d ago AI coding tools are shipping code faster than security can review it. What's your team doing about it cybersecurity · 46d ago Interview for AI security engineer position at a fortune 500 company cybersecurity · 46d ago How’s the job market for Senior AppSec Engineers? How are the interviews? cybersecurity · 46d ago Has anyone read "The Art of Deception"? How does it hold up to now? cybersecurity · 46d ago Run this washer/dryer sans coin? hacking: security in practice · 46d ago WAF Evasion Engine For [Blue|Purple] Teams in Cyber Defence · 46d ago Is metadata protection becoming more important than traditional endpoint security for ordinary users? cybersecurity · 46d ago Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems darkreading · 46d ago Inspecting a DLL file trying to figure out if it really is malware Malware Analysis & Reports · 46d ago Zero trust in hybrid environments - what's actually worked for you cybersecurity · 46d ago Have you encountered issues with CSAF advisories in practice? cybersecurity · 46d ago Zero trust in hybrid environments - what's actually working for you cybersecurity · 46d ago I built an open-source Burp alternative hacking: security in practice · 46d ago April 2026 CVE Landscape Recorded Future · 46d ago OpenAI confirms security breach in TanStack supply chain attack cybersecurity · 46d ago Bachelors Degree Options cybersecurity · 46d ago HighBoy hacking: security in practice · 46d ago Innovator Spotlight: Klever Compliance Cyber Defense Magazine · 46d ago Thus Spoke…The Gentlemen For [Blue|Purple] Teams in Cyber Defence · 46d ago Innovator Spotlight: Radware Cyber Defense Magazine · 46d ago SecurityScorecard Snags Driftnet to Level Up Threat Intelligence darkreading · 46d ago npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output Malware Analysis & Reports · 46d ago Pentagon cyber official calls advanced AI ‘revolutionary warfare’ CyberScoop · 46d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild darkreading · 46d ago White House cyber official: identity security matters more than ever in the age of AI CyberScoop · 46d ago I need help protecting my privacy cybersecurity · 46d ago Free Threat Intellegence cybersecurity · 46d ago What discovery in cybersecurity amazed you the most? cybersecurity · 46d ago Scholarship for Service cybersecurity · 46d ago Reading Siemens CT raw data hacking: security in practice · 46d ago KQLab - open-source query manager for SOC teams For [Blue|Purple] Teams in Cyber Defence · 46d ago For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons? cybersecurity · 46d ago How I use Hermes agent to turn Patch Tuesday into Windows exploit research hacking: security in practice · 46d ago Another day, another supply chain cybersecurity · 46d ago How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs? cybersecurity · 46d ago Teaching Linux+ & CEH..... cybersecurity · 46d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon cybersecurity · 46d ago How TeamPCP's Python Toolkit Survives a C2 Takedown For [Blue|Purple] Teams in Cyber Defence · 46d ago Innovator Spotlight: JScrambler Cyber Defense Magazine · 46d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon hacking: security in practice · 46d ago SIEM use case development cybersecurity · 46d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Technical Information Security Content & Discussion · 46d ago JFrog vs Mend as Scanners cybersecurity · 46d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 46d ago KQLab - open-source query manager for SOC teams cybersecurity · 46d ago Which Vendors Publish the Best (or Worst) Security Advisories? cybersecurity · 46d ago Tips for a beginner noob that wants to learn hacking: security in practice · 46d ago 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine darkreading · 47d ago Synthetic training data vs. real attack telemetry — does it actually matter? cybersecurity · 47d ago Microsoft AntiSSRF For [Blue|Purple] Teams in Cyber Defence · 47d ago Operative IT-Sicherheit | SIEM & Splunk cybersecurity · 47d ago Cisco Catalyst SD-WAN Manager Vulnerabilities Cisco Security Advisory · 47d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state Technical Information Security Content & Discussion · 47d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state For [Blue|Purple] Teams in Cyber Defence · 47d ago Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory Cisco Security Advisory · 47d ago SOC not for junior level? cybersecurity · 47d ago Major tech manufacturer Foxconn confirms cyberattack hit North American factories CyberScoop · 47d ago Cybersecurity at MSG cybersecurity · 47d ago pii-tools.com reputable? cybersecurity · 47d ago Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise cybersecurity · 47d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 47d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Reverse Engineering · 47d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Malware Analysis & Reports · 47d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Technical Information Security Content & Discussion · 47d ago Contract jobs worth the risk? cybersecurity · 47d ago HackTheBoxAcademy vs LetsDefend vs CyberDefenders cybersecurity · 47d ago Automating code security reviews with Claude: near Mythos-level capabilities at lower cost cybersecurity · 47d ago Making Right Career Decision? cybersecurity · 47d ago AI Drives Cybersecurity Investments, Widening 'Valley of Death' darkreading · 47d ago I tried using apparmor (linux security) but it doesn't seem to work very well cybersecurity · 47d ago Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything! cybersecurity · 47d ago Struggling to Stay Up to Date With Vulnerabilities cybersecurity · 47d ago CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure Technical Information Security Content & Discussion · 47d ago How to Check Computer Activity: 2026 Guide for Windows and Mac Technical Information Security Content & Discussion · 47d ago Strix — first public beta of the spiritual successor to cSploit/dSploit hacking: security in practice · 47d ago 🔴 [LIVE] Payload Review & 1M Subs! Hak5 · 47d ago How fast is autonomous AI cyber capability advancing? For [Blue|Purple] Teams in Cyber Defence · 47d ago Foxconn Attack Highlights Manufacturing's Cyber Crisis darkreading · 47d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 47d ago Siemens Siemens ROS# All CISA Advisories · 47d ago Siemens gWAP All CISA Advisories · 47d ago Siemens SIMATIC All CISA Advisories · 47d ago Siemens Ruggedcom Rox All CISA Advisories · 47d ago Siemens Ruggedcom Rox All CISA Advisories · 47d ago Siemens Simcenter Femap All CISA Advisories · 47d ago Universal Robots Polyscope 5 All CISA Advisories · 47d ago Siemens Ruggedcom Rox All CISA Advisories · 47d ago Siemens Teamcenter All CISA Advisories · 47d ago Siemens Solid Edge All CISA Advisories · 47d ago Siemens SENTRON 7KT PAC1261 Data Manager All CISA Advisories · 47d ago Siemens Opcenter RDnL All CISA Advisories · 47d ago Siemens Ruggedcom Rox All CISA Advisories · 47d ago Siemens SIMATIC S7 PLC Web Server All CISA Advisories · 47d ago Siemens Industrial Devices All CISA Advisories · 47d ago Siemens SIMATIC All CISA Advisories · 47d ago Siemens SIPROTEC 5 All CISA Advisories · 47d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 47d ago How to Transfer files Safely from a Compromised (work) Device cybersecurity · 47d ago Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward cybersecurity · 47d ago Multiple data breaches in one week cybersecurity · 47d ago Whatsapp hacking: security in practice · 47d ago How are small security teams handling vulnerability overload now? cybersecurity · 47d ago Concerns mount that EU will demand age verification for VPNs cybersecurity · 47d ago Automating code security reviews: Claude Mythos-level capabilities with lower cost cybersecurity · 47d ago The Rare Patch: A Digital Sovereignty Challenge cybersecurity · 47d ago Advise cybersecurity · 47d ago CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC Technical Information Security Content & Discussion · 47d ago Face ID bypass with avatar hacking: security in practice · 47d ago GRC cybersecurity · 47d ago Admins and Engineers cybersecurity · 47d ago Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark cybersecurity · 47d ago Ghidra 12.1 has been released! Reverse Engineering · 47d ago Prompt injection in browser coding agents is the threat model nobody is ready for cybersecurity · 47d ago FrostyNeighbor: Fresh mischief and digital shenanigans WeLiveSecurity · 47d ago New Fragnesia Linux flaw lets attackers gain root privileges cybersecurity · 47d ago Transition from MSP to Network Engineering? cybersecurity · 47d ago YellowKey: YellowKey Bitlocker Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 47d ago Reverse Engineering Slither.io’s Network Protocol Reverse Engineering · 47d ago So called “off grid” method cybersecurity · 47d ago Convince me I’m not paranoid: a unique hacking situation. cybersecurity · 47d ago Hunting the Behavior Behind npm Supply Chain Attacks cybersecurity · 47d ago Hunting the Behavior Behind npm Supply Chain Attacks hacking: security in practice · 47d ago Question for AppSec Members cybersecurity · 47d ago Hunting the Behavior Behind npm Supply Chain Attacks Technical Information Security Content & Discussion · 47d ago LIVE: 🕵️ HTB Sherlocks! | Cybersecurity | Blue Team The Cyber Mentor · 47d ago Beginners guide to Google Dorks by Heisenberg cybersecurity · 47d ago I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable... Malware Analysis & Reports · 47d ago Alguém sabe algo sobre raven eye technology cybersecurity · 47d ago Gophish Porject - Requirement cybersecurity · 47d ago Security Team Won’t Assess Risk cybersecurity · 47d ago Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework cybersecurity · 47d ago NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals Recorded Future · 47d ago Microsoft’s new multi-model agentic security system tops leading industry benchmark cybersecurity · 47d ago Proxmark5 Day 3 Update - $357K+ funded (715% of goal) hacking: security in practice · 47d ago Researchers say AI just broke every benchmark for autonomous cyber capability CyberScoop · 47d ago Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents cybersecurity · 47d ago Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks CyberScoop · 47d ago Overwhelmed on how to enter the job market. cybersecurity · 47d ago Social media scam bill targets tech giants as New Yorkers lose billions cybersecurity · 47d ago What are the biggest technical & cultural hurdles you’re facing right now? cybersecurity · 47d ago CISSP / CCSP training - Experienced engineer cybersecurity · 47d ago WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers Technical Information Security Content & Discussion · 47d ago I Reverse-engineering Need for Speed Underground 2 Server Reverse Engineering · 47d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 47d ago Checkbox Assessments Aren't Fit to Measure Risk darkreading · 47d ago Attackers Weaponize RubyGems for Data Dead Drops darkreading · 47d ago Innovators Spotlight: OPSWAT Cyber Defense Magazine · 47d ago Vulnerability in Canvas/Instructure Support Tickets had part in breach? cybersecurity · 47d ago Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak darkreading · 47d ago Are There Really Ethical Hackers? I've Yet To Meet One hacking: security in practice · 47d ago Tinker Tailor Soldier: Paper Werewolf’s latest toolkit For [Blue|Purple] Teams in Cyber Defence · 47d ago On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract Technical Information Security Content & Discussion · 47d ago /sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple Technical Information Security Content & Discussion · 47d ago Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out Technical Information Security Content & Discussion · 47d ago 126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies For [Blue|Purple] Teams in Cyber Defence · 47d ago DOJ releases legal rationale for nationwide voter data collection CyberScoop · 47d ago is malwarefox legit? cybersecurity · 47d ago what lab to learn zero trust? cybersecurity · 47d ago Anyone else got a bunch of emails leaked by Samsung? cybersecurity · 47d ago Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape darkreading · 47d ago This is what some the world's largest banks of malware look like stacked as hard drives cybersecurity · 47d ago I need feedback on my project please cybersecurity · 47d ago would like to understand the role of "Cyber Insurance UnderWriters" cybersecurity · 47d ago Weaponized AI: The new frontier of fraud and identity spoofing CyberScoop · 47d ago clens.io - new public threat & data intel service Malware Analysis & Reports · 47d ago Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad For [Blue|Purple] Teams in Cyber Defence · 47d ago Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise For [Blue|Purple] Teams in Cyber Defence · 47d ago I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included Reverse Engineering · 47d ago Free on-device tool for monitoring AI traffic on macOS — visibility before policy cybersecurity · 47d ago Is secure evidence handling and controlled derivative file sharing needed? cybersecurity · 47d ago Will Adding Some Certifications Help Me in the Job Market? cybersecurity · 47d ago Linux driver posted for Intel Silicon Security Engine Interface "ISSEI" cybersecurity · 47d ago Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified? cybersecurity · 48d ago Fragnesia made public as latest Linux local privilege escalation vulnerability cybersecurity · 48d ago HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity? cybersecurity · 48d ago trying to learn patching hacking: security in practice · 48d ago NIST is surrendering to the amount of CVEs coming in cybersecurity · 48d ago 🔴 [LIVE] Hak5 Hits 1 MILLION SUBSCRIBERS Hak5 · 48d ago [HOMELAB] Built a SOC investigation console on two old Dell boxes For [Blue|Purple] Teams in Cyber Defence · 48d ago Military Veteran looking to get into the Cyber Field cybersecurity · 48d ago Android Intrusion Logging as a new source of data for consensual forensic analysis For [Blue|Purple] Teams in Cyber Defence · 48d ago Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor cybersecurity · 48d ago Granny’s Compromised Android Firmware Malware Analysis & Reports · 48d ago On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study) Technical Information Security Content & Discussion · 48d ago Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook. cybersecurity · 48d ago Shai-Hulud: Another Wave and Going Open Source For [Blue|Purple] Teams in Cyber Defence · 48d ago Cve apis for a database cybersecurity · 48d ago Empresas de Cyberseguridad en Mexico (Reacciones) cybersecurity · 48d ago Joined a new company: GRC landscape advice cybersecurity · 48d ago Removing admin rights cybersecurity · 48d ago a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access cybersecurity · 48d ago A stealth approach to Process Injection - EntryPoint Hijacking For [Blue|Purple] Teams in Cyber Defence · 48d ago A stealth approach to Process Injection - EntryPoint Hijacking Technical Information Security Content & Discussion · 48d ago FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow cybersecurity · 48d ago Golden years for cyber security about to start? cybersecurity · 48d ago A stealth approach to Process Injection - EntryPoint Hijacking cybersecurity · 48d ago Detecting CopyFail and DirtyFrag by thinking outside the box cybersecurity · 48d ago Daybreak is OpenAI’s answer to the AI arms race in cybersecurity CyberScoop · 48d ago Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security cybersecurity · 48d ago The Board Is Asking The Wrong Security Question Cyber Defense Magazine · 48d ago LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly darkreading · 48d ago China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm darkreading · 48d ago Career advice cybersecurity · 48d ago LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back The Last Watchdog · 48d ago A year of Apple Security Bounty research — 16 closed findings, full disclosure Technical Information Security Content & Discussion · 48d ago [Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) Malware Analysis & Reports · 48d ago The exponential rise of economic damage caused by cyber-crime continues cybersecurity · 48d ago [Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features Reverse Engineering · 48d ago Today's cybersecurity systems are not ready for AI cybersecurity · 48d ago Are certifications worth it, or do practical skills matter more? cybersecurity · 48d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) cybersecurity · 48d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) For [Blue|Purple] Teams in Cyber Defence · 48d ago Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed cybersecurity · 48d ago Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft cybersecurity · 48d ago What to do after security+ cybersecurity · 48d ago AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data cybersecurity · 48d ago AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods Technical Information Security Content & Discussion · 48d ago LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer] Reverse Engineering · 48d ago Service Principal Sign-Ins: A blind spot that a lot are missing For [Blue|Purple] Teams in Cyber Defence · 48d ago Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub cybersecurity · 48d ago Is it realistic to move from Tech Risk/GRC into technical cybersecurity? cybersecurity · 48d ago My Analysis of a Bandook RAT PCAP For [Blue|Purple] Teams in Cyber Defence · 48d ago Are IPhone autofill passwords safe to use? cybersecurity · 48d ago Access approvals happen over Slack dm and I don't know how to present that to an auditor cybersecurity · 48d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 48d ago China is going dark to develop its own Mythos, German cyber chief fears cybersecurity · 48d ago Is prompt injection a real problem for you? cybersecurity · 48d ago New Exim BDAT bug shows why “just patch the mail server” is still not simple cybersecurity · 48d ago Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach cybersecurity · 48d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 48d ago Cybersecurity guide cybersecurity · 48d ago [Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ? cybersecurity · 48d ago How you guys rate Google Cyber security course and certificate out of 10 !? cybersecurity · 48d ago Detection Rule is here For [Blue|Purple] Teams in Cyber Defence · 48d ago Cyebrsecurity Startup Advice cybersecurity · 48d ago Can anyone give a real world based AI based attack? cybersecurity · 48d ago r2garlic - The world's fastest Android/DEX decompiler meets radare2! Reverse Engineering · 48d ago How worried should we be about AI powered cyberattacks? cybersecurity · 48d ago Built STIS-ICS — an open ICS/OT security learning project cybersecurity · 48d ago Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft Trend Micro Research, News, Perspectives · 48d ago OS scanner that checks repos for traces of the Shai Hulud worm Malware Analysis & Reports · 48d ago OS scanner that checks repos for traces of the Shai Hulud worm cybersecurity · 48d ago Foxconn Ransomware Attack Shows Nothing Is Safe Forever cybersecurity · 48d ago Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries cybersecurity · 48d ago Cellphone IP address spoofing. hacking: security in practice · 48d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu cybersecurity · 48d ago Explorer shows random letter/number filenames before copying my actual files — normal behavior? cybersecurity · 48d ago Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America Proofpoint News Feed · 48d ago Patch Tuesday, May 2026 Edition Krebs on Security · 48d ago ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack CyberScoop · 48d ago Zscaler AI Security Capabilities ? cybersecurity · 48d ago Major world economies spell out key elements of AI ‘ingredients list’ CyberScoop · 48d ago It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight darkreading · 48d ago Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical CyberScoop · 48d ago Cybersecurity degree cybersecurity · 48d ago Owning a service principal equals owning its permissions. For [Blue|Purple] Teams in Cyber Defence · 48d ago Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma cybersecurity · 48d ago Cyber security cybersecurity · 48d ago New York Senate takes on junk fees, digital subscriptions, surveillance pricing cybersecurity · 48d ago Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection For [Blue|Purple] Teams in Cyber Defence · 48d ago Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI Malware Analysis & Reports · 48d ago CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level. For [Blue|Purple] Teams in Cyber Defence · 48d ago Cybersecurity statistics of the week (May 4th - May 10th) cybersecurity · 48d ago Feels like AI changed the speed of attacks more than most companies want to admit cybersecurity · 48d ago Anyone used Kasm or ReplicaCyber? cybersecurity · 48d ago Škoda warns of customer data breach after online shop hack cybersecurity · 48d ago Google launches new Android security feature to help uncover spyware attacks cybersecurity · 48d ago Fancy Bear: Stealing Credentials Invisibly cybersecurity · 48d ago Nightmare Eclipse has published Greenplasma and YellowKey cybersecurity · 48d ago Copilot Agent cybersecurity · 48d ago A Quick Way to Prove Your Cybersecurity Skillset! The Cyber Mentor · 48d ago Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim Technical Information Security Content & Discussion · 48d ago The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop Technical Information Security Content & Discussion · 48d ago What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles? cybersecurity · 48d ago GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language. Reverse Engineering · 49d ago Google and Amnesty International teamed up to make it harder for spyware vendors to hide CyberScoop · 49d ago Career Advice cybersecurity · 49d ago Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs Technical Information Security Content & Discussion · 49d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu Technical Information Security Content & Discussion · 49d ago AI+DFIR Challenge: Share Your Disasters and Successes For [Blue|Purple] Teams in Cyber Defence · 49d ago Anyone else exhausted by the nonstop AI hype? cybersecurity · 49d ago Reviewing the trends in ransomware attacks in 2026 cybersecurity · 49d ago FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread The Last Watchdog · 49d ago Sorry if its the wrong place but hacking: security in practice · 49d ago Is It a Good Idea to Change Jobs Shortly After Getting Hired? cybersecurity · 49d ago SSO makes life easier but MFA keeps it safe, do we actually need both? cybersecurity · 49d ago Hugging Face Packages Weaponized With a Single File Tweak darkreading · 49d ago Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours? cybersecurity · 49d ago Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware For [Blue|Purple] Teams in Cyber Defence · 49d ago How are SOC teams actually deciding what not to investigate anymore? cybersecurity · 49d ago Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily cybersecurity · 49d ago Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released. cybersecurity · 49d ago Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification Cyber Defense Magazine · 49d ago Has anyone tryed this out yet? cybersecurity · 49d ago I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately... Technical Information Security Content & Discussion · 49d ago The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..) cybersecurity · 49d ago Switching to Cyber cybersecurity · 49d ago 20 Leaders Who Built the CISO Era: 2 Decades of Change darkreading · 49d ago Software Bill of Materials for AI - Minimum Elements All CISA Advisories · 49d ago ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax All CISA Advisories · 49d ago Subnet Solutions PowerSYSTEM Center All CISA Advisories · 49d ago ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities All CISA Advisories · 49d ago ABB AC500 V3 Multiple Vulnerabilities All CISA Advisories · 49d ago ABB Automation Builder Gateway for Windows All CISA Advisories · 49d ago Fuji Electric Tellus All CISA Advisories · 49d ago Nitrogen ransomware group claims Foxconn after Wisconsin plant outage cybersecurity · 49d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages cybersecurity · 49d ago Postmortem: TanStack npm supply-chain compromise For [Blue|Purple] Teams in Cyber Defence · 49d ago Using Cape Sandbox for Phishing Analysis cybersecurity · 49d ago Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain darkreading · 49d ago Canvas hack: company pays criminals to delete students' stolen data cybersecurity · 49d ago AI is separating the companies built to scale from the ones built to sell CyberScoop · 49d ago i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning. cybersecurity · 49d ago AI integrations are quietly creating a new OAuth supply-chain problem cybersecurity · 49d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak cybersecurity · 49d ago UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships cybersecurity · 49d ago AI Will Absorb 99.98% of SOC Triage Within a Year, as 79% of IT teams brace for AI-driven workload shift Heimdal Security Blog · 49d ago Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results Technical Information Security Content & Discussion · 49d ago Hardcoded secrets in Git cybersecurity · 49d ago Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages cybersecurity · 49d ago UK water company allowed hackers to lurk undetected for nearly two years, regulator finds cybersecurity · 49d ago New ipTIME Pre-Auth RCE in CWMP cybersecurity · 49d ago New ipTIME Pre-Auth RCE in CWMP Technical Information Security Content & Discussion · 49d ago Postmortem: TanStack npm supply-chain compromise Technical Information Security Content & Discussion · 49d ago Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it? hacking: security in practice · 49d ago Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak cybersecurity · 49d ago Steam spear phishing Malware Analysis & Reports · 49d ago Fake linked in sponsored google search Malware Analysis & Reports · 49d ago Is my phone hacked? cybersecurity · 49d ago Switched to a grc role after a year in SOC L1 cybersecurity · 49d ago bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages For [Blue|Purple] Teams in Cyber Defence · 49d ago rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions For [Blue|Purple] Teams in Cyber Defence · 49d ago Detecting Remote Thread Creation with Windows Driver For [Blue|Purple] Teams in Cyber Defence · 49d ago Mythos finds a curl vulnerability For [Blue|Purple] Teams in Cyber Defence · 49d ago Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details For [Blue|Purple] Teams in Cyber Defence · 49d ago Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign For [Blue|Purple] Teams in Cyber Defence · 49d ago Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment For [Blue|Purple] Teams in Cyber Defence · 49d ago esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app For [Blue|Purple] Teams in Cyber Defence · 49d ago Forecasting Lazarus Crypto Heists cybersecurity · 49d ago LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors. For [Blue|Purple] Teams in Cyber Defence · 49d ago How Cloudflare responded to the “Copy Fail” Linux vulnerability For [Blue|Purple] Teams in Cyber Defence · 49d ago Infrastructure Security Incident Update & FAQs cybersecurity · 49d ago I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic. For [Blue|Purple] Teams in Cyber Defence · 49d ago LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots. For [Blue|Purple] Teams in Cyber Defence · 49d ago Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages cybersecurity · 49d ago In Depth Guide To VM Based Obfuscation - What it is and how to handle it. cybersecurity · 49d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective cybersecurity · 49d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective Reverse Engineering · 49d ago Transitioned to GRC cybersecurity · 49d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages cybersecurity · 49d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages Malware Analysis & Reports · 49d ago German cybersecurity official warns China is close to developing AI superhacker cybersecurity · 49d ago How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models. Technical Information Security Content & Discussion · 49d ago New Shai-Hulud npm worm variant Malware Analysis & Reports · 49d ago New Shai-Hulud npm worm variant For [Blue|Purple] Teams in Cyber Defence · 49d ago Google Detects First AI-Generated Zero-Day Exploit cybersecurity · 49d ago “DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance cybersecurity · 49d ago Instructure/ canvas paid the ransom? cybersecurity · 49d ago Instructure claims hackers returned stolen Canvas data after an extortion standoff CyberScoop · 49d ago OpenAI announces Daybreak, "frontier AI for defenders" Technical Information Security Content & Discussion · 49d ago Troca emprego - big para consultoria ou fintech - Pentester/Red Team cybersecurity · 49d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation hacking: security in practice · 49d ago Finally, texts between Android and iPhone users can be end-to-end encrypted cybersecurity · 49d ago Official CheckMarx Jenkins package compromised with infostealer cybersecurity · 49d ago IMF warns of the potential for AI attacks on global financial systems cybersecurity · 49d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 49d ago GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon Technical Information Security Content & Discussion · 49d ago Cookie thieves caught stealing dev secrets via fake Claude Code installers cybersecurity · 49d ago Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo cybersecurity · 49d ago Innovator Spotlight: Iru Cyber Defense Magazine · 49d ago MS Defender on OT Network cybersecurity · 49d ago A fateful question cybersecurity · 49d ago EtwWatcher For [Blue|Purple] Teams in Cyber Defence · 49d ago SC-900 or SC-400 cybersecurity · 49d ago What are your security non-negotiables? cybersecurity · 49d ago Losing my path cybersecurity · 49d ago Axon-captcha cybersecurity · 49d ago What makes companies trust small cybersecurity vendors? cybersecurity · 49d ago Donuts and Beagles: Fake Claude site spreads backdoor For [Blue|Purple] Teams in Cyber Defence · 49d ago Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility” cybersecurity · 49d ago TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack cybersecurity · 49d ago Innovator Spotlight: Axonius Cyber Defense Magazine · 49d ago News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents The Last Watchdog · 49d ago New and improved: Agent governance, intelligent workflows, and connected app experiences Microsoft 365 Blog · 49d ago Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim cybersecurity · 50d ago How I Defeat Passkeys Nearly Every Time in Phishing Assessments Technical Information Security Content & Discussion · 50d ago These Extensions are Scraping Your AI Chats, are you affected? cybersecurity · 50d ago Reverse Engineering Fisher-Price Pixter Reverse Engineering · 50d ago Be careful with your Git: Investigating malware spreading through Git repositories cybersecurity · 50d ago Training and Phishing cybersecurity · 50d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation cybersecurity · 50d ago AI-powered hacking has exploded into industrial-scale threat, Google says cybersecurity · 50d ago Apple closed my bug report 4 times. MITRE wouldn't let it die. cybersecurity · 50d ago NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG cybersecurity · 50d ago Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach For [Blue|Purple] Teams in Cyber Defence · 50d ago CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection For [Blue|Purple] Teams in Cyber Defence · 50d ago looking for "evil" Websites Malware Analysis & Reports · 50d ago Google spotted an AI-developed zero-day before attackers could use it cybersecurity · 50d ago Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge Cyber Defense Magazine · 50d ago The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface Cyber Defense Magazine · 50d ago Google spotted an AI-developed zero-day before attackers could use it CyberScoop · 50d ago Deterministic PE Structural Validation in IOCX v0.7.3 Malware Analysis & Reports · 50d ago beginner doubt cybersecurity · 50d ago The Bug Bounty Roadmap I'd Follow If I Started Over (With AI) NahamSec · 50d ago Is the AI hype helping or killing your bug bounty dreams? #hacking #bugbounty NahamSec · 50d ago where is the location of Files by Google on Android? hacking: security in practice · 50d ago I got my CEH Certification. SO what now? cybersecurity · 50d ago Construction to Cyber PM cybersecurity · 50d ago Deterministic PE Validation for Blue Teams - IOCX v0.7.3 For [Blue|Purple] Teams in Cyber Defence · 50d ago Reading old s4 memory with xgecu t48 hacking: security in practice · 50d ago [ Removed by Reddit ] cybersecurity · 50d ago Something got downloaded on my phone and then dissappeared cybersecurity · 50d ago Bleeding Llama cybersecurity · 50d ago The missing cybersecurity leader in small business CyberScoop · 50d ago Hack a data center? hacking: security in practice · 50d ago Do accountants even care about cybersecurityas much? cybersecurity · 50d ago Where Have All the Complex Windows Malware and Their Analyses Gone? cybersecurity · 50d ago Eyes wide open: How to mitigate the security and privacy risks of smart glasses WeLiveSecurity · 50d ago sl1nk link Malware Analysis & Reports · 50d ago MyAudi app:Security issues in Audi Connected Vehicle experience Technical Information Security Content & Discussion · 50d ago Delving deep into threat detection: My logic for abnormal EventID 7 activity For [Blue|Purple] Teams in Cyber Defence · 50d ago Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot Technical Information Security Content & Discussion · 50d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 50d ago Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust cybersecurity · 50d ago Was the reconnaissance in Bugbounty overrated? cybersecurity · 50d ago Cybersecurity beginner building an experimental log analyzer — looking for advice cybersecurity · 50d ago Anyone else worried about AI being a security nightmare? cybersecurity · 50d ago Snyk not working cybersecurity · 50d ago Malicious tenants paid us to abuse our RMM. We blocked them cybersecurity · 50d ago Help reasuring parents with an email parsing tool (i will not promote) cybersecurity · 50d ago Check out my matplotlib of BLE live wire data for Oura ring! Reverse Engineering · 50d ago Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows Reverse Engineering · 50d ago NZ announces sanctions on malicious Russian cyber actors, online platforms For [Blue|Purple] Teams in Cyber Defence · 50d ago Update: Ongoing Checkmarx Supply Chain Security Incident For [Blue|Purple] Teams in Cyber Defence · 50d ago DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this? cybersecurity · 50d ago Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop Reverse Engineering · 50d ago cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers cybersecurity · 50d ago 5 years as a Level 1 Security Analyst and wanting to transition into consulting cybersecurity · 50d ago How to download a RAT for myself Malware Analysis & Reports · 50d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass cybersecurity · 50d ago New into network pentesting. cybersecurity · 50d ago Is it worth it to switching field to cybersecurity ? cybersecurity · 50d ago Neeed help to get cybersecurity internship. cybersecurity · 50d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 50d ago Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America Trend Micro Research, News, Perspectives · 50d ago Cybersecurity and ADHD cybersecurity · 50d ago Mythos, MOAK, CTEM and the End of CVE Chasing Technical Information Security Content & Discussion · 50d ago Autonomous Vulnerability Hunting with MCP hacking: security in practice · 50d ago Anyone dealt with a VulDB submission rejection? Resubmit or reply? cybersecurity · 50d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass Reverse Engineering · 50d ago Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory) Reverse Engineering · 50d ago Autonomous Vulnerability Hunting with MCP Technical Information Security Content & Discussion · 50d ago GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3 Reverse Engineering · 50d ago ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025 For [Blue|Purple] Teams in Cyber Defence · 50d ago Unmanaged PowerShell Execution: Hunting Beyond powershell.exe For [Blue|Purple] Teams in Cyber Defence · 50d ago Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign For [Blue|Purple] Teams in Cyber Defence · 50d ago ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing cybersecurity · 50d ago Static Devirtualization of Themida For [Blue|Purple] Teams in Cyber Defence · 50d ago Now You See Me: AADGraphActivityLogs For [Blue|Purple] Teams in Cyber Defence · 50d ago I have a malware and need help removing it. someone please help me 🙏 cybersecurity · 50d ago [Write-up] CyberDefenders: Wiredive Lab For [Blue|Purple] Teams in Cyber Defence · 50d ago PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra Reverse Engineering · 50d ago I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too? cybersecurity · 50d ago EasySec - Update cybersecurity · 50d ago What is the cybersecurity equivalent of leaving your spare key under the doormat? cybersecurity · 50d ago ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement Technical Information Security Content & Discussion · 50d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 51d ago VICE: Cyberwar | Full Season 2 | Blueprint cybersecurity · 51d ago Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures cybersecurity · 51d ago Email OTP as default (often ONLY) password isn’t the solution cybersecurity · 51d ago page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer For [Blue|Purple] Teams in Cyber Defence · 51d ago Soc analyse cybersecurity · 51d ago AI DNS Resolver hacking: security in practice · 51d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 51d ago Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI Cyber Defense Magazine · 51d ago Price rising cybersecurity · 51d ago Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple Technical Information Security Content & Discussion · 51d ago JDownloader — Website installer incident (May 2026) For [Blue|Purple] Teams in Cyber Defence · 51d ago AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report cybersecurity · 51d ago Possible security incident against Arup Group cybersecurity · 51d ago Can honeypots be used this way? cybersecurity · 51d ago Is it true that the professionals have the worst setups? hacking: security in practice · 51d ago The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice. Technical Information Security Content & Discussion · 51d ago I think AI just quietly killed the 90-day disclosure window. cybersecurity · 51d ago TCM and Educate 360 are bugged cybersecurity · 51d ago The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate." For [Blue|Purple] Teams in Cyber Defence · 51d ago Got an alert from google what should I do? cybersecurity · 51d ago UK jobs cybersecurity · 51d ago AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT For [Blue|Purple] Teams in Cyber Defence · 51d ago Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏 cybersecurity · 51d ago Outrunning SHA256 with Physics Technical Information Security Content & Discussion · 51d ago EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine) For [Blue|Purple] Teams in Cyber Defence · 51d ago Worst company cybersecurity · 51d ago Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning cybersecurity · 51d ago I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage hacking: security in practice · 51d ago Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months) cybersecurity · 51d ago Innovator Spotlight: Lineaje Cyber Defense Magazine · 51d ago ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring) cybersecurity · 51d ago App Store Question - Darato Sport / Dofu Sport / Kofu cybersecurity · 51d ago Help! - My Parents Computer is Hacked cybersecurity · 51d ago Refining hacking basics — scaling them aswell hacking: security in practice · 51d ago Ran lumma stealer from a recaptcha scam cybersecurity · 51d ago What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do Trend Micro Research, News, Perspectives · 51d ago Port 5986 question cybersecurity · 51d ago CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse! cybersecurity · 51d ago cyber security/ segurança da informação cybersecurity · 51d ago Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers For [Blue|Purple] Teams in Cyber Defence · 51d ago College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains cybersecurity · 51d ago Help with an Escalating Cyber-Stalker cybersecurity · 51d ago RRW - Rick Roll WiFi cybersecurity · 51d ago Best resources to start learning python for cybersecurity and automation cybersecurity · 51d ago Writing a Naive LLVM-based Devirtualizer For [Blue|Purple] Teams in Cyber Defence · 51d ago Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game. cybersecurity · 51d ago Memory Poisoning AI Agents via ChromaDB Technical Information Security Content & Discussion · 51d ago Defence in Depth: A Practical Secure Corporate Network Topology Technical Information Security Content & Discussion · 51d ago Where Have All the Complex Windows Malware and Their Analyses Gone? For [Blue|Purple] Teams in Cyber Defence · 51d ago JDownloader site hacked to replace installers with Python RAT malware cybersecurity · 51d ago Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram Technical Information Security Content & Discussion · 51d ago Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More) Technical Information Security Content & Discussion · 51d ago How can I fix my browser remembering what he had open last cybersecurity · 51d ago MS 360 CoPilot issues cybersecurity · 51d ago I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details cybersecurity · 52d ago ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12. cybersecurity · 52d ago The spy who logged me in. Proofpoint News Feed · 52d ago eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback cybersecurity · 52d ago HackTheBox - Overwatch IppSec · 52d ago I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you cybersecurity · 52d ago AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic) hacking: security in practice · 52d ago OWASP TOP 10 LLM 2026 Community voting cybersecurity · 52d ago When prompts become shells: RCE vulnerabilities in AI agent frameworks For [Blue|Purple] Teams in Cyber Defence · 52d ago Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus For [Blue|Purple] Teams in Cyber Defence · 52d ago MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) For [Blue|Purple] Teams in Cyber Defence · 52d ago Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor For [Blue|Purple] Teams in Cyber Defence · 52d ago Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles. For [Blue|Purple] Teams in Cyber Defence · 52d ago Second security incident at Instructure (Canvas) cybersecurity · 52d ago Wtf OPEN Ai Malware Analysis & Reports · 52d ago Bridging the Gap Between Vulnerabilities and Working Exploits hacking: security in practice · 52d ago um you guys is my hacker stupid? hacking: security in practice · 52d ago UK Advice Needed - VA+ Training? cybersecurity · 52d ago Gateweb - Secure Web Gateway cybersecurity · 52d ago Those who are in Detection engineering cybersecurity · 52d ago Can someone tell me of a trustable hacker? cybersecurity · 52d ago MSPs, how are you handling AI usage across your customer environments today? cybersecurity · 52d ago Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write cybersecurity · 52d ago How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there? cybersecurity · 52d ago ecpptv3 Exam in 3–4 Days — cybersecurity · 52d ago Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026 For [Blue|Purple] Teams in Cyber Defence · 52d ago Member of Prolific Russian Ransomware Group Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 52d ago EasterBunny: advanced espionage artifacts attributed to APT29 For [Blue|Purple] Teams in Cyber Defence · 52d ago AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES cybersecurity · 52d ago Did CISA helped you land a job ? cybersecurity · 52d ago Tracking the "Sorry" Extortionist Campaign Against cPanel Websites For [Blue|Purple] Teams in Cyber Defence · 52d ago PositiveIntent: Evasive loader for .NET Framework assemblies For [Blue|Purple] Teams in Cyber Defence · 52d ago The Accidental C2: Exploring Dev Tunnels for Remote Access For [Blue|Purple] Teams in Cyber Defence · 52d ago Living of the Land - DISM Sandbox Provider Hijack For [Blue|Purple] Teams in Cyber Defence · 52d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode For [Blue|Purple] Teams in Cyber Defence · 52d ago CTO at NCSC Summary: week ending May 10th cybersecurity · 52d ago CTO at NCSC Summary: week ending May 10th For [Blue|Purple] Teams in Cyber Defence · 52d ago ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure For [Blue|Purple] Teams in Cyber Defence · 52d ago PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale For [Blue|Purple] Teams in Cyber Defence · 52d ago Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo For [Blue|Purple] Teams in Cyber Defence · 52d ago pre pre junior needs help(guidance pls) cybersecurity · 52d ago DARWIS Taka - Web vulnerability scanner with Optional AI Validation For [Blue|Purple] Teams in Cyber Defence · 52d ago Trojan malware cybersecurity · 52d ago SANs Courses: How do people get their employers to pay? cybersecurity · 52d ago NIS2 Article 21: turning compliance controls into technical security evidence cybersecurity · 52d ago This GBA Rom is making is having a weird behavior in the Sandbox, why? cybersecurity · 52d ago This GBA ROM makes some weird things in the sanbox, would love to understand why hacking: security in practice · 52d ago Why AI agent governance feels harder than traditional security models cybersecurity · 52d ago Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection Technical Information Security Content & Discussion · 52d ago Confused about what certs are important cybersecurity · 52d ago Would getting Security+ be worthless for me? cybersecurity · 52d ago [Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc) Reverse Engineering · 52d ago Submit probe test — shadow DOM click cybersecurity · 52d ago Threat intelligence in OT (Power equipments) cybersecurity · 52d ago Why was he banned? hacking: security in practice · 52d ago Securing CI/CD for an open source project: lessons from Cilium Technical Information Security Content & Discussion · 52d ago LAB Setup hacking: security in practice · 52d ago SunnyDayBPF: eBPF telemetry integrity research for detection engineering For [Blue|Purple] Teams in Cyber Defence · 52d ago Ethical malware development community hacking: security in practice · 52d ago SOC Analyst cybersecurity · 52d ago PAWs, PAM and PIM..what is best practice? cybersecurity · 52d ago This is the most in-depth analysis I have found on the Instructure/Canvas breach so far. cybersecurity · 52d ago Poland says hackers breached water treatment plants, and the U.S. is facing the same threat cybersecurity · 52d ago Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments CyberScoop · 52d ago Has Instructure paid SH? hacking: security in practice · 53d ago Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web. cybersecurity · 53d ago Quacc++: Automated Open Source Vulnerability Discovery cybersecurity · 53d ago Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me. hacking: security in practice · 53d ago 60% of MD5 password hashes are crackable in under an hour cybersecurity · 53d ago Built a correlation engine that chains AD findings into attack paths automatically. cybersecurity · 53d ago New trends (not mainstream) hacking: security in practice · 53d ago Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!) Reverse Engineering · 53d ago Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests cybersecurity · 53d ago ShinyHunters claims nearly 9,000 schools affected by Canvas data breach CyberScoop · 53d ago Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI CyberScoop · 53d ago Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care Cyber Defense Magazine · 53d ago JDownloader's official website delivered Python RAT cybersecurity · 53d ago JDownloader's official website delivered Python RAT Malware Analysis & Reports · 53d ago Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) cybersecurity · 53d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. cybersecurity · 53d ago ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12 Technical Information Security Content & Discussion · 53d ago Note taking apps and advice cybersecurity · 53d ago Best tools to find exposed web services by HTML title / HTTP response? hacking: security in practice · 53d ago IMF Warns AI Could Trigger Global Financial Cyber Crisis cybersecurity · 53d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 53d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 53d ago New Linux 'Dirty Frag' zero-day gives root on all major distros cybersecurity · 53d ago Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2 Reverse Engineering · 53d ago Is the ISC2 Cybersecurity program still worth it? cybersecurity · 53d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama For [Blue|Purple] Teams in Cyber Defence · 53d ago Canvas getting hit during finals week shows how fragile “critical SaaS” has become cybersecurity · 53d ago Are websites exposed to the internet under attack almost every hour, even if they're small? cybersecurity · 53d ago Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config Technical Information Security Content & Discussion · 53d ago Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou... For [Blue|Purple] Teams in Cyber Defence · 53d ago Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken cybersecurity · 53d ago What the **** is happening in cybersecurity space ? cybersecurity · 53d ago Canvas is back up, but now what? cybersecurity · 53d ago Copy Fail (CVE-2026-31431): A Technical Deep Dive Technical Information Security Content & Discussion · 53d ago Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago? hacking: security in practice · 53d ago AI Agents Have a Security Problem. IronClaw is Fixing It. hacking: security in practice · 53d ago Instagram is getting rid of end to end encryption, what now? cybersecurity · 53d ago Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack For [Blue|Purple] Teams in Cyber Defence · 53d ago Dirty Frag: Universal Linux LPE For [Blue|Purple] Teams in Cyber Defence · 53d ago Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication. For [Blue|Purple] Teams in Cyber Defence · 53d ago Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea For [Blue|Purple] Teams in Cyber Defence · 53d ago New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation cybersecurity · 53d ago Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable". cybersecurity · 53d ago Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group? cybersecurity · 53d ago SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals Reverse Engineering · 53d ago Cushman and Wakefield confirms cyberattack cybersecurity · 53d ago Egnyte potential ransomware attack cybersecurity · 53d ago So canvas is down, what'll happen if they can't come to an argreement? cybersecurity · 53d ago Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now. cybersecurity · 53d ago I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow! Reverse Engineering · 53d ago /Why/ is Shinyhunters targeting Canvas? cybersecurity · 53d ago Canvas Hack - Any Guesses How? cybersecurity · 53d ago Should I build a virtual or physical lab? cybersecurity · 53d ago Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12 cybersecurity · 53d ago Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata cybersecurity · 53d ago Audit/Cybersecurity cybersecurity · 53d ago Issues removing Trellix (and specifically solidifier) cybersecurity · 53d ago Pentagon eyes 3-year cyber training requirement, overriding new Army policy cybersecurity · 53d ago A hacker ran me over with a robot lawn mower - The Verge hacking: security in practice · 53d ago Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia For [Blue|Purple] Teams in Cyber Defence · 53d ago How much personal info will be leaked by the recent Canvas hack?? cybersecurity · 53d ago OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI For [Blue|Purple] Teams in Cyber Defence · 53d ago Dirty Frag and canvas cybersecurity · 53d ago Hackers deface school login pages after claiming another Instructure hack cybersecurity · 53d ago Happened today hacking: security in practice · 53d ago Ivanti customers confront yet another actively exploited zero-day CyberScoop · 53d ago Did I destroy my career by being loyal to an arguably good company? cybersecurity · 53d ago Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo Technical Information Security Content & Discussion · 53d ago V4bel/dirtyfrag - Universal Linux Local Privilege Escalation cybersecurity · 53d ago Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC For [Blue|Purple] Teams in Cyber Defence · 53d ago What is CYBERRANT? cybersecurity · 53d ago Canvas is down as ShinyHunters hack forces outage cybersecurity · 53d ago Shinyhunters and Canvas hacking: security in practice · 53d ago New Dirty Frag Linux Bug Emerges in Wake of Copy Fail cybersecurity · 53d ago Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today. cybersecurity · 53d ago How is GRC work in a MSSP? cybersecurity · 53d ago SH and BF phishing console cybersecurity · 53d ago Trump officials are steering a cybersecurity scholarship program toward AI CyberScoop · 53d ago Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth? cybersecurity · 53d ago Dirty Frag - Linux LPE similiar to Copy Fail Technical Information Security Content & Discussion · 53d ago Socure authenticating AI identity as real. cybersecurity · 53d ago The first FREE online WebAssembly Reverse Engineering workbench (and how we built it) Reverse Engineering · 53d ago Automated SSL Certificate Renewals - What is your setup? cybersecurity · 53d ago Shinyhunters and Canvas cybersecurity · 53d ago What Cli execution do you use for a script file? cybersecurity · 53d ago Fiserv security incident - data breach notice cybersecurity · 53d ago Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments cybersecurity · 53d ago Honey Tokens: Bait Credentials That Catch Breaches Technical Information Security Content & Discussion · 53d ago I graduate next year with a Cybersecurity degree. cybersecurity · 54d ago An unknown malware threat. There is no such thing as a 100% detection. Malware Analysis & Reports · 54d ago Asking about Cortex cybersecurity · 54d ago CVE-2026-42511 Breakdown: RCE in FreeBSD Technical Information Security Content & Discussion · 54d ago Apache Caldera cybersecurity · 54d ago What’s the “unsexy” problem in cyber that’s actually a total disaster? cybersecurity · 54d ago Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE cybersecurity · 54d ago As a developer, should I use AI to improve security? cybersecurity · 54d ago My company has an MSP that manages our employee endpoints but we cant access the software they use to manage cybersecurity · 54d ago Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804 Technical Information Security Content & Discussion · 54d ago Americans sentenced for running 'laptop farms' for North Korea cybersecurity · 54d ago Is my laptop hijacked ? cybersecurity · 54d ago American duo sentenced for hosting laptop farms for North Korean IT workers CyberScoop · 54d ago claude ai gave security beta to Enterprise plans only what can we do as pentesters? cybersecurity · 54d ago Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline cybersecurity · 54d ago Advice for path to land job SOC in France cybersecurity · 54d ago Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered Cyber Defense Magazine · 54d ago Possible Major Vulnerability: Chromium used by current version of PRTG cybersecurity · 54d ago Mythos AI may be a cybersecurity threat, but it follows the rules of the game cybersecurity · 54d ago When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity Cyber Defense Magazine · 54d ago Control Checks using AI. cybersecurity · 54d ago How do native password managers clear the clipboard? cybersecurity · 54d ago VLC Media Player MKV Exploit Analysis Reverse Engineering · 54d ago Graduating CS Student but Wanna Start my Career in Cybersecurity cybersecurity · 54d ago An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support) Technical Information Security Content & Discussion · 54d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 54d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 54d ago MAXHUB Pivot Client Application All CISA Advisories · 54d ago Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI Technical Information Security Content & Discussion · 54d ago Claude-Themed Malware Campaigns cybersecurity · 54d ago DeepFake it till you make it. cybersecurity · 54d ago The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments cybersecurity · 54d ago What niche in cybersecurity should I go for, with my background in Angular & .NET ? cybersecurity · 54d ago Successor for Kaspersky Endpoint Security cybersecurity · 54d ago One House Democrat is pressing Commerce on the government’s spyware use CyberScoop · 54d ago Fake call logs, real payments: How CallPhantom tricks Android users WeLiveSecurity · 54d ago Detecting BEC Persistence with KQL For [Blue|Purple] Teams in Cyber Defence · 54d ago Modify md5sum of a file hacking: security in practice · 54d ago Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago cybersecurity · 54d ago SOC Analyst tier 1 (Entry Level) ?? cybersecurity · 54d ago Unpacking Russian-Iranian Private-Sector Cyber Connections For [Blue|Purple] Teams in Cyber Defence · 54d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 54d ago Made cybersecurity merch as an infosec practitioner — honest feedback welcome cybersecurity · 54d ago Fixing the password problem is as easy as 123456 WeLiveSecurity · 54d ago As AI agents become users of company data - what is needed to keep data secure? cybersecurity · 54d ago Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities. cybersecurity · 54d ago AI inference is quietly becoming a security problem cybersecurity · 54d ago is winrar 7.13 vulnerable to extraction exploits? cybersecurity · 54d ago Tried explaining internet encryption in a beginner-friendly but accurate way, feedback? cybersecurity · 54d ago Is the EC-Council CTIA Certification Worth It for Career Growth? cybersecurity · 54d ago POC Android vuln 2026 cybersecurity · 54d ago Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise cybersecurity · 54d ago Opinions on Mimecast cybersecurity · 54d ago Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution For [Blue|Purple] Teams in Cyber Defence · 54d ago What's going on in the field of Cybersecurity 🫣. cybersecurity · 54d ago How do teams preserve institutional pentest knowledge when senior testers leave? cybersecurity · 54d ago CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE cybersecurity · 54d ago Sophos NDR on Proxmox cybersecurity · 54d ago Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites Malware Analysis & Reports · 54d ago Quacc++: Automated Open Source Vulnerability Discovery Technical Information Security Content & Discussion · 54d ago A DOD contractor’s API flaw exposed military course data and service member records CyberScoop · 54d ago On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029. cybersecurity · 54d ago DOJ says ransomware gang tapped into Russian government databases cybersecurity · 54d ago DAEMON Tools devs confirm breach, release malware-free version cybersecurity · 54d ago Have there been instances where your SOC has suffered a cybersecurity attack? cybersecurity · 54d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk For [Blue|Purple] Teams in Cyber Defence · 54d ago Inadvertent Injections For [Blue|Purple] Teams in Cyber Defence · 54d ago A critical Palo Alto PAN-OS zero-day is being exploited in the wild CyberScoop · 54d ago OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM hacking: security in practice · 54d ago OpenCTI founder, Samuel Hassine, arrested and charged with CSAM cybersecurity · 54d ago Deepfake Platform cybersecurity · 54d ago Innovators Spotlight: Badge (Part II) Cyber Defense Magazine · 54d ago Trellix Licence Query cybersecurity · 54d ago CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal For [Blue|Purple] Teams in Cyber Defence · 54d ago Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML Malware Analysis & Reports · 54d ago Instructure hacker claims data theft from 8,800 schools, universities cybersecurity · 54d ago Is AI generated code creating a non-linear security problem for AppSec teams? cybersecurity · 55d ago Jailbreaking my cars infotainment system and implementing my own custom software hacking: security in practice · 55d ago Binance fixed the IP whitelist gap — but the disclosure process is still broken Technical Information Security Content & Discussion · 55d ago D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says cybersecurity · 55d ago where is the original wormgpt hacking: security in practice · 55d ago Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security cybersecurity · 55d ago Norton Antivirus and Other Norton Software cybersecurity · 55d ago Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home? cybersecurity · 55d ago We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes. cybersecurity · 55d ago Download a malware a while ago, someone trying to log into my ios account cybersecurity · 55d ago Are there any chill hacking youtubers? hacking: security in practice · 55d ago Org Restructure cybersecurity · 55d ago Non-Determinism of Maps in Golang: Why, How, and the Consequences Technical Information Security Content & Discussion · 55d ago Does SOC 2 actually reduce questionnaires, or just change them? cybersecurity · 55d ago Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views cybersecurity · 55d ago How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically? cybersecurity · 55d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Reverse Engineering · 55d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Technical Information Security Content & Discussion · 55d ago Ran phishing awareness training for 200+ non-tech employees cybersecurity · 55d ago Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware For [Blue|Purple] Teams in Cyber Defence · 55d ago Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk cybersecurity · 55d ago Vulnerability Garden Technical Information Security Content & Discussion · 55d ago Vulnerability Garden cybersecurity · 55d ago Palo Alto Firewall Zero-Day Under Active Exploitation cybersecurity · 55d ago Redefining Security Operations Through Seceon’s Open Threat Management Platform Cyber Defense Magazine · 55d ago Cyber Security Militias cybersecurity · 55d ago Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk cybersecurity · 55d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 55d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 55d ago Took me a decade to turn quantum computing into what programmers can easily learn, big announcement hacking: security in practice · 55d ago Lilygo T-Embed Glitching etc hacking: security in practice · 55d ago CyberSecurity Nightmares cybersecurity · 55d ago Can I use NanoKVM if it's just to turn on pc? cybersecurity · 55d ago got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something? cybersecurity · 55d ago How to learn tools for cybersecurity? cybersecurity · 55d ago 'CopyFail' attackers start cashing in on Linux flaw cybersecurity · 55d ago Anybodybodybdown for a team/studygroup? cybersecurity · 55d ago Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today? hacking: security in practice · 55d ago I was hacked due to sim card spoofing cybersecurity · 55d ago Chrome is quietly installing a 4GB AI model on your device cybersecurity · 55d ago Dev vs Security role cybersecurity · 55d ago Discord bot C2 infrastructure Malware Analysis & Reports · 55d ago Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed For [Blue|Purple] Teams in Cyber Defence · 55d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 55d ago UAT-8302 and its box full of malware For [Blue|Purple] Teams in Cyber Defence · 55d ago Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft cybersecurity · 55d ago Oracle Debuts Monthly Critical Security Patch Updates cybersecurity · 55d ago Sec engineer / developer? cybersecurity · 55d ago When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them? cybersecurity · 55d ago Proofpoint Establishes Innovation Precedent for Source-Agnostic Modern Enterprise Investigations Proofpoint News Feed · 55d ago Are we actually seeing more vulnerabilities or just more noise? cybersecurity · 55d ago Cybersecurity jobs in red team cybersecurity · 55d ago Question cybersecurity · 55d ago What’s the biggest mistake people make even after installing antivirus? cybersecurity · 55d ago CVE-2026-0073 Android adbd TLS client-authentication bypass For [Blue|Purple] Teams in Cyber Defence · 55d ago One KQL query you should have saved in your toolkit (most don’t) For [Blue|Purple] Teams in Cyber Defence · 55d ago New dashboard tracks ransomware groups by their reliance on Infostealer credentials cybersecurity · 55d ago ant4g0nist/pyre: Ghidra decompiler in your browser Reverse Engineering · 55d ago CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier? For [Blue|Purple] Teams in Cyber Defence · 55d ago Found a possibly interesting live attack hacking: security in practice · 55d ago What would you say if your security lead said this... cybersecurity · 55d ago What would be the goto setup in AWS for security purposes? cybersecurity · 55d ago CREST CRT Exam 2025/2026 Experiences cybersecurity · 55d ago Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside For [Blue|Purple] Teams in Cyber Defence · 55d ago Microsoft Edge stores your passwords in plaintext RAM... on purpose cybersecurity · 55d ago Supporting the National Cyber Strategy: How TrendAI™ Helps Trend Micro Research, News, Perspectives · 55d ago Export/Backup ChatGPT chats hacking: security in practice · 55d ago Como começar? cybersecurity · 55d ago Possible Password Leak? Curious if Anyone Has Seen This Before cybersecurity · 55d ago Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source! Reverse Engineering · 55d ago Not a Hack. A Handout. Inside the GTFOice.org Data Exposure cybersecurity · 55d ago Besoin de conseils sur une DMZ automatisée cybersecurity · 55d ago Microsoft, Google and xAI will let the government test their AI models before launch cybersecurity · 55d ago Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073 cybersecurity · 55d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 55d ago SMB Header Signature for Tagging in Firewall cybersecurity · 55d ago Question regarding VDP cybersecurity · 55d ago Working on what i should do for the next 3 years cybersecurity · 55d ago Question for Security Professionals cybersecurity · 55d ago Do tech companies lifecycle-manage public DNS records to prevent dangling DNS? cybersecurity · 55d ago Vulnerability Summary for the Week of April 27, 2026 cybersecurity · 55d ago Scan. Secure. Simplify. — Free Web Tools Platform Technical Information Security Content & Discussion · 55d ago Cisco releases open-source ‘DNA test for AI models’ cybersecurity · 55d ago Cybersecurity is becoming too AI dependent is that a problem cybersecurity · 55d ago Foxconn Wisconsin outage raises cyber questions cybersecurity · 55d ago How stressful is GRC? cybersecurity · 55d ago News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market The Last Watchdog · 55d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482) Technical Information Security Content & Discussion · 55d ago Salesforce pentesting novel techniques- how to be an apex predator Technical Information Security Content & Discussion · 55d ago Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia cybersecurity · 55d ago Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India cybersecurity · 55d ago Archer for a non-regulated medium sized company? cybersecurity · 55d ago Cybersecurity statistics of the week (April 27th - May 3rd) cybersecurity · 55d ago Reverse-engineering the 1998 Ultima Online demo server Reverse Engineering · 55d ago Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM. cybersecurity · 55d ago One-Click Refunds Are Not as Hard as You Think Blog – Forter · 55d ago Top 10 Cybersecurity Companies in Europe Heimdal Security Blog · 55d ago 🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records For [Blue|Purple] Teams in Cyber Defence · 55d ago Where to find reliable vendors? cybersecurity · 55d ago DigiCert: Misissued code signing certificates Technical Information Security Content & Discussion · 55d ago Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts? cybersecurity · 56d ago We wrote a guide on securing Claude across the enterprise — here's the core framework (with download) cybersecurity · 56d ago Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium. cybersecurity · 56d ago Hardware reverse enginnering first project. Love some advice cybersecurity · 56d ago Microsoft Edge Stores Passwords in Process Memory, Posing Risk cybersecurity · 56d ago Currently working on cybersecurity, looking for advice cybersecurity · 56d ago Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning cybersecurity · 56d ago Major AI Clients Shipping With Broken OAuth Implementations Technical Information Security Content & Discussion · 56d ago CISO course valuation cybersecurity · 56d ago Inside Faxanadu series — deep dive into how this NES title works Reverse Engineering · 56d ago EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing Reverse Engineering · 56d ago Popular DAEMON Tools software compromised For [Blue|Purple] Teams in Cyber Defence · 56d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 56d ago Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise For [Blue|Purple] Teams in Cyber Defence · 56d ago GRC Path to CISO (Certifications) cybersecurity · 56d ago Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities For [Blue|Purple] Teams in Cyber Defence · 56d ago CISOs and pentest buyers, what's the worst thing you've seen in a pentest report? cybersecurity · 56d ago How to enforce M365 Sign-in frequency on corporate laptops? cybersecurity · 56d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs cybersecurity · 56d ago Built an independent directory of AI Act / AI governance tools, feedback? cybersecurity · 56d ago ScarCruft APT group compromises gaming platform in a supply-chain attack cybersecurity · 56d ago Just curious cybersecurity · 56d ago 'Copy Fail' is a real Linux security crisis wrapped in AI slop cybersecurity · 56d ago Analysis malicious DLL cybersecurity · 56d ago Cyber security free course cybersecurity · 56d ago The Insurance Industry Is Rewriting Cybersecurity Strategy Cyber Defense Magazine · 56d ago Does certification expires? cybersecurity · 56d ago HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10 Technical Information Security Content & Discussion · 56d ago IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening Malware Analysis & Reports · 56d ago Panicking Malware Analysis & Reports · 56d ago ABB B&R Automation Studio All CISA Advisories · 56d ago ABB B&R Automation Runtime All CISA Advisories · 56d ago Hitachi Energy PCM600 All CISA Advisories · 56d ago Johnson Controls CEM AC2000 All CISA Advisories · 56d ago ABB B&R PVI All CISA Advisories · 56d ago How the Story of a USB Penetration Test Went Viral darkreading · 56d ago We get paid to break into buildings for a living. Ask us anything! cybersecurity · 56d ago Pay2Key ransomware — any recovery path that’s actually worked? cybersecurity · 56d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison cybersecurity · 56d ago Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF cybersecurity · 56d ago Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud Technical Information Security Content & Discussion · 56d ago How have you kept growing your knowledge in security when the job stops pushing you? cybersecurity · 56d ago Supply chain attack: DAEMON Tools Lite now contains a backdoor. Malware Analysis & Reports · 56d ago Accelerating Vulnerability Detection and Response at Oracle For [Blue|Purple] Teams in Cyber Defence · 56d ago The Danger of Multi-SSO AWS Cognito User Pools Technical Information Security Content & Discussion · 56d ago Copilot Cowork: From conversation to action across skills, integrations, and devices Microsoft 365 Blog · 56d ago Microsoft 365 Copilot, human agency, and the opportunity for every organization Microsoft 365 Blog · 56d ago The UK’s Age Verification Law Is Producing Compliance Theater cybersecurity · 56d ago Microsoft Edge: Passwords end up in memory as plaintext cybersecurity · 56d ago Do people still get viruses in 2026, or is that mostly a myth now? cybersecurity · 56d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 Technical Information Security Content & Discussion · 56d ago Mitigation script for Copy Fail vulnerability CVE-2026-31431 cybersecurity · 56d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 cybersecurity · 56d ago Is this fake too?🤣 hacking: security in practice · 56d ago Copy.fail: Why Internal LLMs Are Non-Negotiable for Security Reverse Engineering · 56d ago The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew For [Blue|Purple] Teams in Cyber Defence · 56d ago Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released cybersecurity · 56d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack WeLiveSecurity · 56d ago DigiCert breached via malicious screensaver file cybersecurity · 56d ago I just figured out my dad use to be a Phreaker in the 1980s hacking: security in practice · 56d ago Caido Payloads and Scanner of Endpoints cybersecurity · 56d ago Proton Pass: Second-Password Bypass Through Emergency Access Technical Information Security Content & Discussion · 56d ago What of my favorite videos🙂 hacking: security in practice · 56d ago CISO Security Mind Map 2026 cybersecurity · 56d ago Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker cybersecurity · 56d ago Best tools for blocking spam calls and spam links? hacking: security in practice · 56d ago Amazon SES increasingly abused in phishing to evade detection cybersecurity · 56d ago someone else’s UI appearing on screen for split second— possible hacker?? hacking: security in practice · 56d ago AI Security Trainings cybersecurity · 56d ago Ai help cybersecurity · 56d ago ByDesign: observed behavior where file URLs remain accessible after unshare/delete cybersecurity · 56d ago Can Kali Linux still compete in cyber security or is it outdated? cybersecurity · 56d ago We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother Technical Information Security Content & Discussion · 56d ago Avoiding rouge AP detection in enterprise networks hacking: security in practice · 56d ago Who are your favorite cybersecurity YouTubers? cybersecurity · 56d ago CISOs, how are you balancing AI adoption with security risks these days? cybersecurity · 56d ago GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated. For [Blue|Purple] Teams in Cyber Defence · 56d ago dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025 For [Blue|Purple] Teams in Cyber Defence · 56d ago N-Day Research with AI: Using Ollama and n8n For [Blue|Purple] Teams in Cyber Defence · 56d ago San Diego Community College District fighting major cyberattack cybersecurity · 56d ago GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering hacking: security in practice · 56d ago San Diego Community College District fighting major cyberattack hacking: security in practice · 56d ago After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up cybersecurity · 56d ago Free resource: searchable archive of every BSides conference talk cybersecurity · 56d ago Lightning PyPI Compromise: Bun-Based Stealer cybersecurity · 56d ago Too much mother instinct? cybersecurity · 56d ago InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Trend Micro Research, News, Perspectives · 56d ago L1 SOC Analyst for ~2 years - Should I still get the Security + Certification? cybersecurity · 56d ago Do CTFs help real world security skills, or just teach patterns? cybersecurity · 56d ago Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo cybersecurity · 56d ago Should I do Security + or Network + or A+? For CompTia cybersecurity · 56d ago Bug bounty is ruining how people learn exploitation cybersecurity · 56d ago ISO/IEC 27701:2025 Scope and Location cybersecurity · 56d ago Cybersecurity's 2026 Wild Ride cybersecurity · 56d ago We built a free multiplayer game that scores prompts on AI code security. cybersecurity · 56d ago RMM Tools Fuel Stealthy Phishing Campaign darkreading · 56d ago Production Usecases cybersecurity · 56d ago Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra Reverse Engineering · 56d ago How does vCISO work? cybersecurity · 56d ago Trellix discloses data breach after source code repository hack cybersecurity · 56d ago CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path cybersecurity · 56d ago Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability darkreading · 56d ago Trellix confirms source code repo access incident cybersecurity · 56d ago Where do i find reverse engineers for actuators? Ideally in Shenzhen Reverse Engineering · 56d ago Employer Offering to Pay for my Certification test - Which one do I choose? cybersecurity · 56d ago John Strand Pay What You Can Information Security Core Skills live starting May 11th cybersecurity · 56d ago [CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2). Reverse Engineering · 56d ago Canvas Breach May Put 275M Users, 9,000 Schools at Risk cybersecurity · 56d ago Is this not such a big deal cybersecurity · 56d ago 38 CVEs in Healthcare Software Used by 100,000 Medical Providers For [Blue|Purple] Teams in Cyber Defence · 56d ago Do email link checkers need to be 100%? cybersecurity · 57d ago Cybersecurity M&A Roundup: 33 Deals Announced in April 2026 cybersecurity · 57d ago Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation Malware Analysis & Reports · 57d ago Recs for pen testing and vulnerability solutions cybersecurity · 57d ago Identify telegram account holders cybersecurity · 57d ago AI Code Security Study: 6 LLMs vs OWASP Top 10 cybersecurity · 57d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers hacking: security in practice · 57d ago Recursively fuzzing MS-RPC structures and monitoring using ETW For [Blue|Purple] Teams in Cyber Defence · 57d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers cybersecurity · 57d ago Iwas developing a hacker game that transports the feeling of the 90s hacking: security in practice · 57d ago We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA cybersecurity · 57d ago Azure IaaS: Defense in depth built on secure-by-design principles Security | Microsoft Azure Blog | Microsoft Azure · 57d ago Cortex XDR Cloud Compromise Alerting cybersecurity · 57d ago Norton.com Verification Email out of the blue cybersecurity · 57d ago Atomic Red Team is now aligned with MITRE ATT&CK v19! cybersecurity · 57d ago Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX? cybersecurity · 57d ago Who are you guys using for your PCI ASV Scanning? cybersecurity · 57d ago Just passed my Security+ exam. Now what? cybersecurity · 57d ago I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work. cybersecurity · 57d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 57d ago [PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection) cybersecurity · 57d ago Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia darkreading · 57d ago Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350) cybersecurity · 57d ago An another open door to IoT devices cybersecurity · 57d ago Ideas on how to have personal google-like account synchronization system cybersecurity · 57d ago Lateral Movement - Cross-Session Activation Technical Information Security Content & Discussion · 57d ago Lateral Movement - Cross-Session Activation cybersecurity · 57d ago How did this guy even access another person's privated YouTube video without wayback machine? hacking: security in practice · 57d ago What MCP servers have actually made it into your day-to-day toolkit? cybersecurity · 57d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems hacking: security in practice · 57d ago Cyber Security Education as Self-Defence classes cybersecurity · 57d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk cybersecurity · 57d ago Use.ai cybersecurity · 57d ago Educational tech giant Instructure confirms data breach, ShinyHunters claims attack cybersecurity · 57d ago [WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation Reverse Engineering · 57d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems cybersecurity · 57d ago Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management Cyber Defense Magazine · 57d ago Stop Using AI Connectors Until You Watch This NahamSec · 57d ago One ChatGPT connector. One email. Full AI agent hijack. #BugBounty #PromptInjection #ai #hacking NahamSec · 57d ago IPod Nano Gets Three Monitors hacking: security in practice · 57d ago IDA-MCP Is Now RE-MCP With Ghidra Support Reverse Engineering · 57d ago Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference Reverse Engineering · 57d ago Chrome "Best AdBlocker" trojanized extension - 100k downloads. hacking: security in practice · 57d ago How Dark Reading Lifted Off the Launchpad in 2006 darkreading · 57d ago Browsers making connection on port 3389 from loopback cybersecurity · 57d ago Defender Flagged DigiCert Root Certs as Malware cybersecurity · 57d ago VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases For [Blue|Purple] Teams in Cyber Defence · 57d ago Another breach just hit Canvas (Instructure), and this one is worth a closer look. cybersecurity · 57d ago Over 40% of UK firms suffered cyber attack last year, survey finds cybersecurity · 57d ago EU should seek access to Anthropic's Mythos, Bundesbank says cybersecurity · 57d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha cybersecurity · 57d ago CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation. For [Blue|Purple] Teams in Cyber Defence · 57d ago 《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition) For [Blue|Purple] Teams in Cyber Defence · 57d ago nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution. For [Blue|Purple] Teams in Cyber Defence · 57d ago 蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery. For [Blue|Purple] Teams in Cyber Defence · 57d ago IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks cybersecurity · 57d ago People in cybersecurity, tell us what was the most epic moment in your career? cybersecurity · 57d ago Prerequisites for CARTP cybersecurity · 57d ago gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives For [Blue|Purple] Teams in Cyber Defence · 57d ago Claude Mythos Cyber Wake Up cybersecurity · 57d ago [ Removed by Reddit ] cybersecurity · 57d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 57d ago is trellix from mcafee good to use in 2026? cybersecurity · 57d ago Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list cybersecurity · 57d ago Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon For [Blue|Purple] Teams in Cyber Defence · 57d ago AMSI Page Guard Bypass (Rust PoC) For [Blue|Purple] Teams in Cyber Defence · 57d ago Any good open sources that bypass modern heuristic analysis? hacking: security in practice · 57d ago Meet Bluekit: The AI-Powered All-in-One Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 57d ago Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI For [Blue|Purple] Teams in Cyber Defence · 57d ago A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia For [Blue|Purple] Teams in Cyber Defence · 57d ago IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect For [Blue|Purple] Teams in Cyber Defence · 57d ago Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection For [Blue|Purple] Teams in Cyber Defence · 57d ago ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution… For [Blue|Purple] Teams in Cyber Defence · 57d ago Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia For [Blue|Purple] Teams in Cyber Defence · 57d ago [2603.28728] Study of Post Quantum status of Widely Used Protocols For [Blue|Purple] Teams in Cyber Defence · 57d ago Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin For [Blue|Purple] Teams in Cyber Defence · 57d ago Free apex hacks? hacking: security in practice · 57d ago Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning For [Blue|Purple] Teams in Cyber Defence · 57d ago Paypal Accesed by malware me being Stupid cybersecurity · 57d ago How was someone in another country able to read all my private messages without my password or clicking a link? cybersecurity · 57d ago code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint. For [Blue|Purple] Teams in Cyber Defence · 57d ago Secure Boot Inventory Data In Configuration Manager For [Blue|Purple] Teams in Cyber Defence · 57d ago EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time. For [Blue|Purple] Teams in Cyber Defence · 57d ago MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning. For [Blue|Purple] Teams in Cyber Defence · 57d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Technical Information Security Content & Discussion · 57d ago AI-powered honeypots: Turning the tables on malicious AI agents For [Blue|Purple] Teams in Cyber Defence · 57d ago Career Transition Help cybersecurity · 57d ago Alguien para hablar de cyberseguridad cybersecurity · 57d ago copy.golf — golf your exploits - smaller copy.fail exploits.. For [Blue|Purple] Teams in Cyber Defence · 57d ago DragonBreath: Dragon in the Kernel For [Blue|Purple] Teams in Cyber Defence · 57d ago What is this cybersecurity · 57d ago Your vibe-coded app is probably violating GDPR right now Technical Information Security Content & Discussion · 57d ago [SHOWCASE] Cascavel v3 hacking: security in practice · 57d ago Feeling lost and disappointed about finding a job just venting cybersecurity · 57d ago Slow at Learning/Cyber Security? cybersecurity · 57d ago Pokemon machine hacking: security in practice · 57d ago Suspicious traffic from web server cybersecurity · 57d ago Cyber security internship cybersecurity · 57d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 57d ago Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities Trend Micro Research, News, Perspectives · 57d ago Isn't Windows Defender a crap anymore? cybersecurity · 57d ago GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions) Reverse Engineering · 57d ago Learning Cyber cybersecurity · 57d ago Vishing simulator cybersecurity · 57d ago Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others cybersecurity · 57d ago Worried about being tracked/banned for using an educational app on MuMu Player - Need advice cybersecurity · 57d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks cybersecurity · 57d ago Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance cybersecurity · 57d ago Prompt Injection in 2026: The Five Attack Patterns That Actually Matter cybersecurity · 57d ago I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine cybersecurity · 57d ago Random trojan detected? cybersecurity · 57d ago CRTA second attempt cybersecurity · 57d ago What’s the hardest thing to learn in cybersecurity? cybersecurity · 57d ago What MCP servers are you integrating into your workflow (not exclusive to security)? cybersecurity · 57d ago Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors. For [Blue|Purple] Teams in Cyber Defence · 57d ago WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog cybersecurity · 57d ago What are like the top but unknown Cybersecurity firms? cybersecurity · 57d ago Can HTTP POST bodies be intercepted without network or host access? hacking: security in practice · 57d ago Need professionals or expert on cybersecurity related to dark web for interview cybersecurity · 57d ago A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP) cybersecurity · 58d ago Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library For [Blue|Purple] Teams in Cyber Defence · 58d ago North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory cybersecurity · 58d ago VirusTotal has one flag for this sus site Malware Analysis & Reports · 58d ago Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo Reverse Engineering · 58d ago Puzzle: Set of PoC to abuse Windows minifilters functionality For [Blue|Purple] Teams in Cyber Defence · 58d ago Ai Didn’t Break Cybersecurity, It Revealed It Cyber Defense Magazine · 58d ago Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate) cybersecurity · 58d ago Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate) Technical Information Security Content & Discussion · 58d ago Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you! Reverse Engineering · 58d ago built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4) hacking: security in practice · 58d ago Credential Dumping: Local Security Authority (LSA|LSASS.EXE) cybersecurity · 58d ago A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16 For [Blue|Purple] Teams in Cyber Defence · 58d ago Dump sql time based is too slow hacking: security in practice · 58d ago Trojan:Win32/Cerdigent.A!dha cybersecurity · 58d ago Active exploitation of cPanel/WHM critical vulnerability For [Blue|Purple] Teams in Cyber Defence · 58d ago Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. " For [Blue|Purple] Teams in Cyber Defence · 58d ago MDE flagging digi cert certificate as malicious everywhere ? cybersecurity · 58d ago North Korea rejects US cybercrime claims as 'absurd slander' hacking: security in practice · 58d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Reverse Engineering · 58d ago 5 Qilin ransomware servers exposed over 7 months For [Blue|Purple] Teams in Cyber Defence · 58d ago is credential stuffing using openbullet2 dead in 2026? hacking: security in practice · 58d ago Anyone wanna learn the CEH or OSCP red teaming free Malware Analysis & Reports · 58d ago South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) For [Blue|Purple] Teams in Cyber Defence · 58d ago Russian Charged in Oil and Gas Facility Hacks Pleads Guilty For [Blue|Purple] Teams in Cyber Defence · 58d ago Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax) hacking: security in practice · 58d ago How to build .NET obfuscator - Part II Reverse Engineering · 58d ago VECT ransomware: small files decrypt, large files lose their nonces For [Blue|Purple] Teams in Cyber Defence · 58d ago CTO at NCSC Summary: week ending May 3rd For [Blue|Purple] Teams in Cyber Defence · 58d ago April 27th - What happened with our feature flag configuration | The ClickUp Blog For [Blue|Purple] Teams in Cyber Defence · 58d ago Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT) hacking: security in practice · 59d ago How to exfiltrate data using only numeric outputs Technical Information Security Content & Discussion · 59d ago libghidra - SDK for automating Ghidra from Python, Rust, and C++ Reverse Engineering · 59d ago Blog: Evolving the Android & Chrome VRPs for the AI Era For [Blue|Purple] Teams in Cyber Defence · 59d ago Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis. Reverse Engineering · 59d ago RSAC 2026: The Power of Community Cyber Defense Magazine · 59d ago Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed. For [Blue|Purple] Teams in Cyber Defence · 59d ago VECT: Ransomware by design, Wiper by accident For [Blue|Purple] Teams in Cyber Defence · 59d ago VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built. For [Blue|Purple] Teams in Cyber Defence · 59d ago Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 59d ago Agentic Malware Analysis: From Task Automation to Deep Analysis For [Blue|Purple] Teams in Cyber Defence · 59d ago pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner. For [Blue|Purple] Teams in Cyber Defence · 59d ago month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only For [Blue|Purple] Teams in Cyber Defence · 59d ago For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall. Technical Information Security Content & Discussion · 59d ago Small models are better at cost-to-recall than large models like Mythos for vulnerability research hacking: security in practice · 59d ago Every incident public companies have disclosed to the SEC, in one searchable database Technical Information Security Content & Discussion · 59d ago 76% of All Crypto Stolen in 2026 Is Now in North Korea darkreading · 59d ago Bluetooth Spoofed Disconnect? hacking: security in practice · 59d ago Why my macOS Messages badge lied to me (and the one-line fix) Reverse Engineering · 59d ago Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself Malware Analysis & Reports · 60d ago A Guide to LNK File Forensics The Cyber Mentor · 60d ago Running Adobe’s 1991 PostScript Interpreter in the Browser Reverse Engineering · 60d ago Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :) Reverse Engineering · 60d ago Microsoft Agent 365, now generally available, expands capabilities and integrations Microsoft 365 Blog · 60d ago If AI's So Smart, Why Does It Keep Deleting Production Databases? darkreading · 60d ago Minecraft Malware C2 Tracking Malware Analysis & Reports · 60d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 60d ago Inside RSAC 2026 Cyber Defense Magazine · 60d ago Name That Toon: Mark of (Security) Progress darkreading · 60d ago 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage darkreading · 60d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 60d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 60d ago Careful Adoption of Agentic AI Services All CISA Advisories · 60d ago wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ... hacking: security in practice · 60d ago Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster Technical Information Security Content & Discussion · 60d ago /r/ReverseEngineering's Triannual Hiring Thread Reverse Engineering · 60d ago In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off) Reverse Engineering · 60d ago TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack darkreading · 60d ago 🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀 hacking: security in practice · 60d ago Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug darkreading · 60d ago Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber darkreading · 60d ago Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM Security | Microsoft Azure Blog | Microsoft Azure · 60d ago Innovator Spotlight: The Open Group Cyber Defense Magazine · 60d ago Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight Reverse Engineering · 61d ago SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents The Last Watchdog · 61d ago I made a lightweight breach intelligence search engine (fully client-side) looking for feedback hacking: security in practice · 61d ago Oracle Red Bull Racing Team Revs Up Automation to Boost Security darkreading · 61d ago Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan... hacking: security in practice · 61d ago Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark Cyber Defense Magazine · 61d ago Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool hacking: security in practice · 61d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 61d ago ABB AWIN Gateways All CISA Advisories · 61d ago ABB Ability OPTIMAX All CISA Advisories · 61d ago ABB PCM600 All CISA Advisories · 61d ago ABB Edgenius Management Portal All CISA Advisories · 61d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 61d ago ABB Ability Symphony Plus Engineering All CISA Advisories · 61d ago ABB System 800xA, Symphony Plus IEC 61850 All CISA Advisories · 61d ago Seventeen vulnerabilities in Omi, fourteen days of silence Technical Information Security Content & Discussion · 61d ago High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940) Technical Information Security Content & Discussion · 61d ago This month in security with Tony Anscombe – April 2026 edition WeLiveSecurity · 61d ago HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try! Reverse Engineering · 61d ago GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter). Reverse Engineering · 61d ago Copy Fail — 732 Bytes to Root hacking: security in practice · 61d ago Josh Mason | Real Folks of Cyber | DITL The Cyber Mentor · 61d ago ZDI-CAN-30796: Docker ZDI: Upcoming Advisories · 61d ago Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia Trend Micro Research, News, Perspectives · 61d ago Claude Mythos Fears Startle Japan's Financial Services Sector darkreading · 61d ago Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root Technical Information Security Content & Discussion · 61d ago Reverse Engineering With AI Unearths High-Severity GitHub Bug darkreading · 61d ago AI Finds 38 Security Flaws in Electronic Health Record Platform darkreading · 61d ago The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs Technical Information Security Content & Discussion · 61d ago The Thymeleaf Template Injection That Only Hurts If You Let It Technical Information Security Content & Discussion · 62d ago Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error darkreading · 62d ago GitHub fixes RCE flaw that gave access to millions of private repos hacking: security in practice · 62d ago Minirat malware deployed via NPM targeting macOS machines Malware Analysis & Reports · 62d ago Set up automated dependency scanning after the recent npm/PyPI supply chain attacks Technical Information Security Content & Discussion · 62d ago Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints Cyber Defense Magazine · 62d ago Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities darkreading · 62d ago I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway Reverse Engineering · 62d ago Adapting Zero Trust Principles to Operational Technology All CISA Advisories · 62d ago How to download Kaggle dataset safely...? hacking: security in practice · 62d ago VECT Ransomware Is Actually a Wiper Malware Analysis & Reports · 62d ago VECT Ransomware Is Actually a Wiper hacking: security in practice · 62d ago Toys“R”Us Japan Implements Forter’s Fraud Management and Payment Optimization Solutions Blog – Forter · 62d ago DEF CON 34 - DEF CON Policy Announcement - Katie Noble, Heather West DEFCONConference · 62d ago The Malware Factory: GLASSWORM Forensics in Open VSX Malware Analysis & Reports · 62d ago A Route to Root in a 4G Industrial Router Technical Information Security Content & Discussion · 62d ago Kuse Web App Abused to Host Phishing Document Trend Micro Research, News, Perspectives · 62d ago BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures darkreading · 62d ago NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later darkreading · 62d ago Feuding Ransomware Groups Leak Each Other's Data darkreading · 62d ago Vidar Rises to Top of Chaotic Infostealer Market darkreading · 62d ago Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore Malware Analysis & Reports · 62d ago Innovator Spotlight: Puneet Bhatnagar Cyber Defense Magazine · 62d ago Flipper Blackhat April Roundup! hacking: security in practice · 62d ago Building a perfect clone of 1993 game SimTower (via RE) Reverse Engineering · 62d ago [ Removed by Reddit ] Malware Analysis & Reports · 63d ago [VulnPath Update] Automated Email Alerting & CISA KEV Feed hacking: security in practice · 63d ago Ikeja Electric Distribution Ransomware Malware Analysis & Reports · 63d ago Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain darkreading · 63d ago [Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses) Technical Information Security Content & Discussion · 63d ago How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema Reverse Engineering · 63d ago AI solved our CTF in 6min Reverse Engineering · 63d ago The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords Technical Information Security Content & Discussion · 63d ago Cybersecurity Risks in 2026 Cyber Defense Magazine · 63d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 63d ago NSA GRASSMARLIN All CISA Advisories · 63d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 63d ago Recently updated a authentic minecraft mod launcher called Modrinth Malware Analysis & Reports · 63d ago GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control The Last Watchdog · 63d ago More of What Matters: Forter’s April Product Release Blog – Forter · 63d ago 89 vulnerabilities in XAPI / Citrix XenServer Technical Information Security Content & Discussion · 63d ago Example structure for evidence-based vulnerability reports Reverse Engineering · 63d ago Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters Cyber Defense Magazine · 63d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 63d ago UNC6692 Combines Social Engineering, Malware, Cloud Abuse darkreading · 63d ago Innovator Spotlight: TokenCore Cyber Defense Magazine · 63d ago If AI Agents Can’t Find You, Do You Even Exist? Blog – Forter · 63d ago Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025) Technical Information Security Content & Discussion · 63d ago Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary Technical Information Security Content & Discussion · 64d ago This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0 Malware Analysis & Reports · 64d ago Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation darkreading · 64d ago FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures The Last Watchdog · 64d ago Platform Engineering: The Rise of a Disciplinary Rethink Cyber Defense Magazine · 64d ago Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely Malware Analysis & Reports · 64d ago This hacker made $40,000 using Claude #ai #hacking #bugbounty NahamSec · 64d ago 60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea? Cyber Defense Magazine · 64d ago My Friend Made $40,000 Using Claude Code (Here's How) NahamSec · 64d ago MCPwned: a Burp Suite extension for auditing MCP servers Technical Information Security Content & Discussion · 64d ago From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense Cyber Defense Magazine · 65d ago New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses Malware Analysis & Reports · 65d ago HackTheBox - Sorcery IppSec · 66d ago Save time and use Zig to write your Malware POC Malware Analysis & Reports · 66d ago Cracking CastleLoader’s Inno Setup Password Malware Analysis & Reports · 66d ago I built a C2 framework that uses Discord and Telegram for communication Malware Analysis & Reports · 66d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog Alerts · 67d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog All CISA Advisories · 67d ago The calm before the ransom: What you see is not all there is WeLiveSecurity · 67d ago fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet. Malware Analysis & Reports · 67d ago Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet Malware Analysis & Reports · 67d ago PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs Malware Analysis & Reports · 67d ago Budgiekit - gdi malware maker (for educational purporses only) Malware Analysis & Reports · 68d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 68d ago SpiceJet Online Booking System All CISA Advisories · 68d ago Carlson Software VASCO-B GNSS Receiver All CISA Advisories · 68d ago Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera All CISA Advisories · 68d ago Milesight Cameras All CISA Advisories · 68d ago Defending Against China-Nexus Covert Networks of Compromised Devices All CISA Advisories · 68d ago Yadea T5 Electric Bicycle All CISA Advisories · 68d ago Intrado 911 Emergency Gateway (EGW) All CISA Advisories · 68d ago GopherWhisper: A burrow full of malware WeLiveSecurity · 68d ago News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category The Last Watchdog · 69d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 69d ago 19 confirmed repos tied to the same GitHub malware campaign Malware Analysis & Reports · 69d ago Use BLUR-IT to Increase Your OPSEC The Cyber Mentor · 69d ago Defending Against China-Nexus Covert Networks of Compromised Devices CISA Cybersecurity Advisories · 70d ago IOCX v0.7.0 — deterministic heuristics + adversarial PE samples Malware Analysis & Reports · 70d ago Heimdal Expands AI Strategy with AI Wingman and Third-Party AI Containment Heimdal Security Blog · 70d ago New NGate variant hides in a trojanized NFC payment app WeLiveSecurity · 70d ago Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one The Last Watchdog · 71d ago Supply Chain Compromise Impacts Axios Node Package Manager Alerts · 71d ago CISA Adds Eight Known Exploited Vulnerabilities to Catalog Alerts · 71d ago What the ransom note won’t say WeLiveSecurity · 71d ago HackTheBox - AirTouch IppSec · 73d ago That data breach alert might be a trap WeLiveSecurity · 74d ago Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business Blog Articles - Identity Insights | Trulioo · 74d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 75d ago Supply chain dependencies: Have you checked your blind spot? WeLiveSecurity · 75d ago News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security The Last Watchdog · 75d ago Return Policy Abuse Is Theft. It’s Time to Treat It That Way. Blog – Forter · 76d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 77d ago GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags The Last Watchdog · 77d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 78d ago HackThebox - Eighteen IppSec · 80d ago Recovery scammers hit you when you’re down: Here’s how to avoid a second strike WeLiveSecurity · 81d ago News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk The Last Watchdog · 81d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 83d ago FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense The Last Watchdog · 84d ago As breakout time accelerates, prevention-first cybersecurity takes center stage WeLiveSecurity · 84d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 85d ago Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure CISA Cybersecurity Advisories · 85d ago HackTheBox - DarkZero IppSec · 87d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 89d ago Azure IaaS: Keep critical applications running with built-in resiliency at scale Security | Microsoft Azure Blog | Microsoft Azure · 90d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 90d ago Digital assets after death: Managing risks to your loved one’s digital estate WeLiveSecurity · 90d ago This month in security with Tony Anscombe – March 2026 edition WeLiveSecurity · 91d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 92d ago HackTheBox - Browsed IppSec · 94d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 95d ago You Only Know What You’ve Got When Its Gone Heimdal Security Blog · 95d ago RSAC 2026 wrap-up – Week in security with Tony Anscombe WeLiveSecurity · 95d ago A cunning predator: How Silver Fox preys on Japanese firms this tax season WeLiveSecurity · 95d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 96d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 97d ago Virtual machines, virtually everywhere – and with real security gaps WeLiveSecurity · 97d ago Cloud workload security: Mind the gaps WeLiveSecurity · 98d ago What is Customer Due Diligence (CDD) Blog Articles - Identity Insights | Trulioo · 98d ago HackTheBox - Conversor IppSec · 101d ago Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud Blog Articles - Identity Insights | Trulioo · 101d ago CISA Adds Five Known Exploited Vulnerabilities to Catalog Alerts · 102d ago Move fast and save things: A quick guide to recovering a hacked account WeLiveSecurity · 102d ago EDR killers explained: Beyond the drivers WeLiveSecurity · 103d ago Nordic MSPs Can Now Access Heimdal’s Unified Security and Compliance Platform Through Elovade Heimdal Security Blog · 104d ago HackTheBox - Gavel IppSec · 108d ago Face value: What it takes to fool facial recognition WeLiveSecurity · 109d ago Cyber fallout from the Iran war: What to have on your radar WeLiveSecurity · 110d ago AML, KYC and Identity Verification in Australia Blog Articles - Identity Insights | Trulioo · 110d ago SSL/TLS Certificate Lifespans Are Decreasing to 200 Days InfoSec Insights · 111d ago AI in Tax Season: Risks, Scams, and How to Protect Your Data Fraud Prevention Archives - Alloy Silverstein · 117d ago Security-driven Rapid Release - Pwn2Own Documentary (Part 4) LiveOverflow · 117d ago Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure Security | Microsoft Azure Blog | Microsoft Azure · 118d ago Firefox JIT Bug - Pwn2Own Documentary (Part 3) LiveOverflow · 120d ago Tax Season Scams to Watch For This Year Fraud Prevention Archives - Alloy Silverstein · 124d ago The First Exploit - Pwn2Own Documentary (Part 2) LiveOverflow · 124d ago The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1) LiveOverflow · 127d ago I built a kernel-level EDR and hit architectural walls I didn’t expect Malware Analysis & Reports · 131d ago DEF CON 33 - DisguiseDelimit: Exploiting Synology NAS with Delimiters and Novel Tricks - Ryan Emmon DEFCONConference · 131d ago DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen - Marek Tóth DEFCONConference · 131d ago DEF CON 33 - Can't Stop the ROP: Automating Universal ASLR Bypasses - Bramwell Brizendine DEFCONConference · 131d ago Update your detection rules: New remote access Trojan Malware Analysis & Reports · 132d ago Criminals are using AI website builders to clone major brands Malware Analysis & Reports · 132d ago Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants) Malware Analysis & Reports · 132d ago Azure reliability, resiliency, and recoverability: Build continuity by design Security | Microsoft Azure Blog | Microsoft Azure · 133d ago PE Loader For Fileless Malware Malware Analysis & Reports · 133d ago Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers Malware Analysis & Reports · 133d ago AWAKE - Android Wiki of Attacks, Knowledge & Exploits Malware Analysis & Reports · 133d ago I built a Chrome extension that scans for malicious extensions (yes, I see the irony) Malware Analysis & Reports · 133d ago Questions regarding malicious pdf's Malware Analysis & Reports · 135d ago AV persistence bypass techniques Malware Analysis & Reports · 136d ago Avalon Linux Bot Malware Analysis Malware Analysis & Reports · 137d ago Leveling up in Windows malware research Malware Analysis & Reports · 138d ago Emerging Ransomware: BQTLock and GREENBLOOD Malware Analysis & Reports · 139d ago Malware Development POCs Malware Analysis & Reports · 139d ago Suspicious code in Up-work linked repository. Malware Analysis & Reports · 139d ago We hid backdoors in binaries — Opus 4.6 found 49% of them Malware Analysis & Reports · 140d ago 👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡 Malware Analysis & Reports · 141d ago Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions Malware Analysis & Reports · 141d ago Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer Malware Analysis & Reports · 142d ago Nyxara Malware Analysis & Reports · 145d ago When Fraud Becomes Background Noise: The Industrialization of Digital Deception Blog Articles - Identity Insights | Trulioo · 176d ago The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage Blog Articles - Identity Insights | Trulioo · 176d ago The End of Static KYB: Business Identity in Constant Motion Blog Articles - Identity Insights | Trulioo · 176d ago Know Your Agent: The Next Chapter in Digital Trust Blog Articles - Identity Insights | Trulioo · 176d ago When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage Blog Articles - Identity Insights | Trulioo · 176d ago DEF CON 33 Recon Village - How to Become One of Them: Deep Cover Ops - Sean Jones, Kaloyan Ivanov DEFCONConference · 181d ago DEF CON 33 Recon Village - Inside the Shadows Tracking RaaS Groups, Cyber Threats - John Dilgen DEFCONConference · 181d ago DEF CON 33 Recon Village - Autonomous Video Hunter AI Agents for Real Time OSINT - Kevin Dela Rosa DEFCONConference · 181d ago DEF CON 33 Recon Village - A Playbook for Integration Servers - Ryan Bonner, Guðmundur Karlsson DEFCONConference · 181d ago DEF CON 33 Recon Village - Mapping the Shadow War From Estonia to Ukraine - Evgueni Erchov DEFCONConference · 181d ago DEF CON 33 Recon Village - Building Local Knowledge Graphs for OSINT - Donald Pellegrino DEFCONConference · 181d ago DEF CON 33 Recon Village - OSINT & Modern Recon Uncover Global VPN Infrastructure - Vladimir Tokarev DEFCONConference · 181d ago DEF CON 33 Recon Village - Pretty Good Pivot - Simwindie DEFCONConference · 181d ago DEF CON 33 Recon Village - enumeraite: AI Assisted Web Attack Surface Enumeration - Özgün Kültekin DEFCONConference · 181d ago DEF CON 33 Recon Village - OSINT Signals Pop Quiz - Master Chen DEFCONConference · 181d ago DEF CON 33 Recon Village - Investigating Foreign Tech from Online Retailers - Michael Portera DEFCONConference · 181d ago Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration Blog Articles - Identity Insights | Trulioo · 195d ago Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure CISA Cybersecurity Advisories · 206d ago Beware of Misleading Tax Advice on Social Media Fraud Prevention Archives - Alloy Silverstein · 292d ago Scammers Up Their Game With AI Fraud Prevention Archives - Alloy Silverstein · 293d ago Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs STÖK · 310d ago The Essential Guide to Safeguarding Your Online Passwords Fraud Prevention Archives - Alloy Silverstein · 371d ago How FIN6 Exfiltrates Files Over FTP HackerSploit · 447d ago From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi LiveOverflow · 447d ago The German Hacking Championship LiveOverflow · 473d ago Beware: Tax Season is Scam Season Fraud Prevention Archives - Alloy Silverstein · 482d ago Do you know this common Go vulnerability? LiveOverflow · 487d ago Stop Scams: Fraud Prevention Starts with Your Employees Fraud Prevention Archives - Alloy Silverstein · 495d ago Emulating FIN6 - Active Directory Enumeration Made EASY HackerSploit · 498d ago The SECRET to Embedding Metasploit Payloads in VBA Macros HackerSploit · 503d ago Offensive VBA 0x4 - Reverse Shell Macro with Powercat HackerSploit · 511d ago Offensive VBA 0x3 - Developing PowerShell Droppers HackerSploit · 517d ago Offensive VBA 0x2 - Program & Command Execution HackerSploit · 522d ago Offensive VBA 0x1 - Your First Macro HackerSploit · 524d ago Emulating FIN6 - Gaining Initial Access (Office Word Macro) HackerSploit · 529d ago FIN6 Adversary Emulation Plan (TTPs & Tooling) HackerSploit · 533d ago Developing An Adversary Emulation Plan HackerSploit · 533d ago Introduction To Advanced Persistent Threats (APTs) HackerSploit · 537d ago Introduction To Adversary Emulation HackerSploit · 559d ago ‘Tis the Season for Holiday Shopping Scams Fraud Prevention Archives - Alloy Silverstein · 568d ago Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion HackerSploit · 568d ago Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1) LiveOverflow · 622d ago My theory on how the webp 0day was discovered #short LiveOverflow · 638d ago My theory on how the webp 0day was discovered (BLASTPASS) LiveOverflow · 639d ago Learn Android Hacking! - University Nevada, Las Vegas (2024) LiveOverflow · 665d ago My Trip to Las Vegas for DEFCON & Black Hat LiveOverflow · 679d ago Planning Red Team Operations | Scope, ROE & Reporting HackerSploit · 708d ago Mapping APT TTPs With MITRE ATT&CK Navigator HackerSploit · 712d ago IRS Issues “Dirty Dozen” Fraud Warnings Fraud Prevention Archives - Alloy Silverstein · 753d ago IRS Identity Theft Season Begins Now Fraud Prevention Archives - Alloy Silverstein · 882d ago Finding The .webp Vulnerability in 8s (Fuzzing with AFL++) LiveOverflow · 890d ago Winter vanlife = good times STÖK · 912d ago What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth! STÖK · 918d ago A Vulnerability to Hack The World - CVE-2023-4863 LiveOverflow · 922d ago Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma STÖK · 925d ago Reinventing Web Security LiveOverflow · 952d ago IS THIS THE END? STÖK · 985d ago Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites STÖK · 1139d ago The World’s Identity Platform Blog Articles - Identity Insights | Trulioo · 1246d ago How to turn bugs into a "passive" income stream! ft Detectify's Almroot STÖK · 1380d ago HOW DID THIS HAPPEN!? (13370822 LHE VLOG) STÖK · 1393d ago Student Loan Breach Exposes 2.5M Records Threatpost · 1399d ago Watering Hole Attacks Push ScanBox Keylogger Threatpost · 1400d ago Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms Threatpost · 1401d ago Ransomware Attacks are on the Rise Threatpost · 1404d ago Cybercriminals Are Selling Access to Chinese Surveillance Cameras Threatpost · 1404d ago Twitter Whistleblower Complaint: The TL;DR Version Threatpost · 1406d ago Firewall Bug Under Active Attack Triggers CISA Warning Threatpost · 1407d ago Fake Reservation Links Prey on Weary Travelers Threatpost · 1408d ago iPhone Users Urged to Update to Patch 2 Zero-Days Threatpost · 1411d ago Google Patches Chrome’s Fifth Zero-Day of the Year Threatpost · 1412d ago Q: How to write a BUG BOUNTY report that actually gets paid? STÖK · 1510d ago KYC: 3 Steps to Achieving Know Your Customer Compliance Blog Articles - Identity Insights | Trulioo · 1517d ago facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques.. STÖK · 1524d ago AML Compliance Checklist: Best Practices for Anti-Money Laundering Blog Articles - Identity Insights | Trulioo · 1532d ago Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!) STÖK · 1538d ago Q: HOW do you get started in bug bounty?? How do you build your automation?! STÖK · 1552d ago Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR) STÖK · 1566d ago BOUNTY THURSDAYS - LIVE #2 (NEWS/TOOLS and Community Questions with Jason Haddix) STÖK · 1580d ago
Latest
The Record from Recorded Future NewsHouse passes kids’ online safety bill, but Senate approval unlikelyJohn HammondBeyond CTF LabsMicrosoft Security BlogWhat’s new in Microsoft Security: June 2026Microsoft Security BlogSecuring AI agents: When AI tools move from reading to actingBleepingComputerFake Perplexity extension on Chrome Web Store tracked searchesThe Hacker NewsSilent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet AddressesLatest newsWhy I switched to wireless security cameras after years of testing wired modelsThe Hacker NewsGuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection RisksLatest newsNetflix vs. Peacock: Which one deserves your money in 2026?Help Net SecurityAikido Security acquires Root to expand backported fixes for open source vulnerabilitiesBleepingComputerLessons from the Underground: How to Combat Business Email CompromiseMSRC Security Update GuideCVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityHelp Net SecurityOracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Help Net SecurityCequence Platform 9.0 uses AI to simplify API security and complianceSecurityWeekBlueHammer Vulnerability Exploited in Ransomware AttacksThe Record from Recorded Future NewsAn intelligence budget 'super user' job is now in the hands of Russ VoughtThe Hacker News282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic StudyHelp Net SecurityJamf enables AI Governance and shadow AI detection on MacLatest newsApple rushed to squash 29 bugs because AI is supercharging hackers - update ASAPHelp Net SecurityDigi International’s DANI automates network diagnostics and device managementThe Record from Recorded Future NewsHouse passes kids’ online safety bill, but Senate approval unlikelyJohn HammondBeyond CTF LabsMicrosoft Security BlogWhat’s new in Microsoft Security: June 2026Microsoft Security BlogSecuring AI agents: When AI tools move from reading to actingBleepingComputerFake Perplexity extension on Chrome Web Store tracked searchesThe Hacker NewsSilent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet AddressesLatest newsWhy I switched to wireless security cameras after years of testing wired modelsThe Hacker NewsGuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection RisksLatest newsNetflix vs. Peacock: Which one deserves your money in 2026?Help Net SecurityAikido Security acquires Root to expand backported fixes for open source vulnerabilitiesBleepingComputerLessons from the Underground: How to Combat Business Email CompromiseMSRC Security Update GuideCVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege VulnerabilityHelp Net SecurityOracle E-Business Suite Payments flaw under attack (CVE-2026-46817)Help Net SecurityCequence Platform 9.0 uses AI to simplify API security and complianceSecurityWeekBlueHammer Vulnerability Exploited in Ransomware AttacksThe Record from Recorded Future NewsAn intelligence budget 'super user' job is now in the hands of Russ VoughtThe Hacker News282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic StudyHelp Net SecurityJamf enables AI Governance and shadow AI detection on MacLatest newsApple rushed to squash 29 bugs because AI is supercharging hackers - update ASAPHelp Net SecurityDigi International’s DANI automates network diagnostics and device management
By Source
Feeds organized so you can skim by site.
Density
Sort
JH
John Hammond
1h ago · 15 items
Beyond CTF Labs
1h ago
ConsentFix Exposed
1d ago
Facebook Phishing Fails
4d ago
Disable SmartScreen Fast
5d ago
Github got Hacked by CATS
6d ago
This Dark Web Linux Backdoor Erases Its Own Footprints
6d ago
ContinuumCon 2026 Redux!
10d ago
ContinuumCon 2026 - Day 3
15d ago
ContinuumCon 2026 - Day 2
16d ago
ContinuumCon 2026 - Day 1
17d ago
Payload Podcast 008 - Ryan Hausknecht
18d ago
JHT Course Launch! Windows Maldev 6
24d ago
BIG SHOW TODAY & AI vibes
26d ago
Are ANY hacking scenes actually good?
27d ago
A Hacker's Way of Thinking (with Ted Harrington)
28d ago
15 loaded
MS
Microsoft Security Blog
1h ago · 10 items
What’s new in Microsoft Security: June 2026
1h ago
This month’s updates help security and IT teams strengthen identity and multicloud foundations, protect data wherever it lives, and secure the developer workflows powering AI innovation.
Securing AI agents: When AI tools move from reading to acting
1h ago
MCP tool poisoning turns trusted AI agents into a control plane for data loss. Learn how threat actors manipulate tool descriptions to trigger unauthorized actions, and how to detect, contain, and prevent it.
Chromium extension uses AI‑related branding to redirect browser search
1d ago
A malicious Chromium-based extension that spoofs the AI-powered answer engine Perplexity AI redirects browser search traffic using MV3 APIs and intermediary infrastructure.
Photo ZIP campaign targeting hospitality industry delivers Node.js implant for persistent access
4d ago
Microsoft Threat Intelligence identified an active multi-stage intrusion campaign targeting hospitality organizations in Europe and Asia. The campaign uses photo-themed ZIP archives and fake image shortcut files to deliver a persistent Node...
Microsoft a Leader in The Forrester Wave™ for Endpoint Management Platforms
5d ago
Microsoft named a Leader in the Forrester Wave™: Endpoint Management Platforms, Q2 2026, with the highest scores in the current offering and strategy categories.
CNAPP evolution: How Microsoft aligns with leading cloud risk management platforms
5d ago
Discover how Microsoft aligns with the next phase of CNAPP—helping organizations correlate signals, prioritize risk, and reduce cloud exposure across modern application environments.
StealC and Amadey: Breaking down infostealers and the cybercrime services that deliver them
6d ago
On June 24, 2026, Microsoft’s Digital Crimes Unit (DCU) facilitated the takedown, suspension, and blocking of domains that formed the backbone of the StealC and Amadey infrastructure. This blog is a technical breakdown of StealC and Amadey.
Guarding AI memory
7d ago
What happens when threat actors target what AI remembers? Microsoft breaks down the risks and the defenses.
One intrusion, two cyberattackers: Uncovering parallel threat activity
8d ago
Microsoft DART uncovers dual threat actors in a single intrusion, revealing how blended tactics conceal attacks and complicate detection. Learn more.
AutoJack: How a single page can RCE the host running your AI agent
11d ago
AutoJack is a novel exploit chain showing how a single malicious webpage can turn an AI browsing agent into a remote code execution vector on the host machine. By abusing trust in localhost, missing authentication, and unsafe parameter hand...
BL
BleepingComputer
1h ago · 15 items
Fake Perplexity extension on Chrome Web Store tracked searches
1h ago
A malicious extension in the Chrome Web Store is masquerading as the Perplexity AI answer engine, intercepting search traffic and collecting browsing information.
Lessons from the Underground: How to Combat Business Email Compromise
3h ago
Business Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and execu...
Insurance giant Aflac discloses data breach after subsidiary hack
5h ago
American insurance giant Aflac has disclosed a new data breach after attackers breached its Japan subsidiary's systems and stole personal and bank account information.
Microsoft adds smarter bot protection to Teams meetings
6h ago
Microsoft has introduced a new Teams admin policy that allows organizers to prevent third-party bots from joining meetings without approval.
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
7h ago
Kali Linux 2026.2, the second release of the year, is now available for download, featuring 9 new tools and numerous Kali NetHunter improvements.
Blackfield ransomware asks Nidec Corporation for $2 million ransom
7h ago
The Blackfield ransomware gang is asking for a $2 million ransom from Nidec Corporation, a large Japanese manufacturer of electronic components for automotive and computing applications.
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
8h ago
CISA confirmed on Monday that ransomware gangs are now exploiting a Microsoft Defender privilege escalation vulnerability, dubbed BlueHammer, that has previously been abused in zero-day attacks.
Nissan discloses employee data breach linked to Oracle zero-day attacks
20h ago
Nissan is warning that it suffered a data breach affecting current and former employees after threat actors exploited an Oracle PeopleSoft vulnerability in data theft attacks previously linked to the ShinyHunters extortion group.
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
20h ago
The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability i...
WhatsApp rolls out usernames to help users hide their phone number
23h ago
WhatsApp is finally allowing users to reserve usernames, a privacy feature that lets them hide their phone numbers from people not in their contact list.
Microsoft extends Windows Server 2022 hotpatching until October 2027
23h ago
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
1d ago
Agentic AI Has an Identity Problem and Attackers Know It
1d ago
Critical SimpleHelp flaw exploited to deploy new stealer malware
1d ago
Hackers now exploit critical Oracle E-Business flaw in attacks
1d ago
15 loaded
TH
The Hacker News
1h ago · 20 items
Silent Swap Crypto Clipper Uses Fake Google Notes Extension to Replace Wallet Addresses
1h ago
GuardFall Exposes Open-Source AI Coding Agents to Decades-Old Shell Injection Risks
2h ago
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
3h ago
What the Numbers Say About FIFA 2026 Cyber Risk
5h ago
Attackers Exploit SimpleHelp CVE-2026-48558 to Deploy TaskWeaver and Djinn Stealer
5h ago
AirDrop and Quick Share Flaws Let Nearby Attackers Trigger Crashes and Bypass Checks
7h ago
New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials
8h ago
Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth
9h ago
Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild
12h ago
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
1d ago
Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input
1d ago
Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs
1d ago
Mustang Panda Uses Zoho WorkDrive as Command Channel in Indian Government Attacks
1d ago
⚡ Weekly Recap: Linux Kernel Flaws, AI Malware Tricks, Turla Backdoor, Infostealers and More
1d ago
236,000 DCloud Uni-App Sites Used in Crypto Scams, Phishing, and Wallet Drainers
1d ago
Why Post-Quantum Cryptography Starts With Credentials
1d ago
Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
1d ago
Microsoft Removes 119 Edge Extensions That Hid Malware in Images and Fonts
1d ago
Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw
1d ago
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
1d ago
20 loaded
LN
Latest news
2h ago · 20 items
Why I switched to wireless security cameras after years of testing wired models
2h ago
After using multiple security cameras over the years, I've found the best arrangement for my home - but that doesn't make it right for everyone.
Netflix vs. Peacock: Which one deserves your money in 2026?
3h ago
Netflix has award-winning originals and a smart algorithm, but Peacock counters with live sports and a lower price.
Apple rushed to squash 29 bugs because AI is supercharging hackers - update ASAP
3h ago
Software updates are rolling out now for iPhone, iPad, and Mac, bringing fixes that weren't supposed to arrive so soon. Here's why.
61% of US adults use AI for health information now - up from 2% in 2024
4h ago
Patients are also three times more likely to trust AI in their doctor's secure portal than a public chatbot.
Why 'countdown mode' is the task manager feature I can't live without
6h ago
This setting meshes perfectly with how my brain works, and I don't miss deadlines anymore.
Too many junk files on your Windows PC? This free tool can remove them in one click
7h ago
A utility called Fluent Cleaner will analyze your Windows environment to find and remove junk files, temp files, unused Registry entries, and other clutter - for free. Here's how to use it.
I tried the 'Plus Five' rule to fix my iPhone's slow wireless charging - here's what happened
8h ago
Wireless charging is a helpful feature, but you may not be getting the optimal speed with your accessories.
AI agents are your new colleagues - how to get the best results
8h ago
The future of work is likely to require a careful blend of human skills and AI agents. Here's how to work successfully with your agentic counterparts.
I always keep these 3 devices plugged into my power station - here's why
21h ago
Here's how to leverage your power station's capabilities when it's not during an emergency.
I replaced my iPhone battery at the Apple store for the first time ever - and learned a valuable lesson
22h ago
A few weeks ago, I replaced my iPhone 14 Pro battery at the Apple store - and was pleasantly surprised by the results.
I tried a Windows handheld PC, and its docking system made it my ideal travel companion
23h ago
After testing Thread, Zigbee, and Matter, here's how I'm building my smart home differently
23h ago
Internet down? 3 ways I use an old Android phone as a backup connection for my home router
1d ago
I changed these Android Auto settings to limit what Gemini learns about me - here's why
1d ago
Chrome vs. Edge vs. Firefox: I tested each browser's AI, but I'm only sticking with one
1d ago
Six months later, this small gadget is my secret weapon against doomscrolling
1d ago
What years of testing thermal cameras taught me about the problems hiding in plain sight
1d ago
You can still buy last year's Sony Bravia OLED TV for $600 off - and I can't recommend it enough
1d ago
Want a big tech job? Startups may be your best shot now - here's why
1d ago
Sony WH-1000XM6 vs. Sennheiser Momentum 5: I wore both pairs for months, and prefer this one
1d ago
20 loaded
HN
Help Net Security
3h ago · 10 items
Aikido Security acquires Root to expand backported fixes for open source vulnerabilities
3h ago
Aikido Security completes Root acquisition, expanding backported security fixes for open source projects and software supply chains.
Oracle E-Business Suite Payments flaw under attack (CVE-2026-46817)
3h ago
Exploitation attempts targeting a vulnerability (CVE-2026-46817) in Oracle's E-Business Suite's Oracle Payments module have been spotted.
Cequence Platform 9.0 uses AI to simplify API security and compliance
3h ago
Cequence Platform 9.0 delivers AI-native API security with an AI assistant, automated compliance and enterprise-scale API risk management.
Jamf enables AI Governance and shadow AI detection on Mac
3h ago
Jamf adds AI Governance for Mac, giving IT teams visibility into AI tools, endpoint controls and compliance-ready AI usage reporting.
Digi International’s DANI automates network diagnostics and device management
3h ago
Digi International unveils DANI, an AI-powered network operations agent in DRM for faster diagnostics and proactive device management.
OpenMatter Network brings verifiable trust to AI governance
3h ago
OpenMatter Network launches a cryptographically verifiable platform for secure collaboration, AI governance and trusted enterprise computing.
SimpleHelp vulnerability exploited to deliver mighty Djinn Stealer (CVE-2026-48558)
6h ago
Attackers are exploiting CVE-2026-48558, an authentication bypass in SimpleHelp RMM, to drop the Djinn Stealer malware on victim computers.
Kali Linux 2026.2 trims VM boot times, refreshes its desktops
8h ago
Kali Linux 2026.2 cuts VM boot times, bumps GNOME 50 and KDE Plasma 6.6, switches APT to a new sources format, and adds nine tools.
OpenClaw for iOS: The viral open-source AI agent comes to iPhone and iPad
9h ago
The OpenClaw iOS app brings private AI to iPhone with chat, real-time voice, approvals, device integration, and automations.
AirDrop and Quick Share vulnerabilities affect protocols on five billion devices as fixes begin
10h ago
Six AirDrop Quick Share vulnerabilities span iOS, macOS, Android, and Windows, affecting protocols on over five billion devices.
MS
MSRC Security Update Guide
3h ago · 20 items
CVE-2026-42910 Windows Hotpatch Monitoring Service Elevation of Privilege Vulnerability
3h ago
CVE-2026-11979 Stack-Based Buffer Overflow in libxml2
9h ago
CVE-2026-53325 agp/amd64: Fix broken error propagation in agp_amd64_probe()
9h ago
CVE-2026-41992 Global Buffer Overflow in GNU gzip
9h ago
CVE-2026-41991 Predictable Temporary File in GNU gzip
9h ago
CVE-2026-54371 attr < 2.6.0 Symlink Traversal Privilege Escalation via getfattr/setfattr
9h ago
CVE-2026-54369 acl < 2.4.0 Symlink Traversal Privilege Escalation via libacl Functions
9h ago
CVE-2026-58058 Nmap - Integer Underflow in IPv6 Extension Header Parsing
1d ago
CVE-2026-58055 nghttp2 nghttpx - HTTP Request/Response Smuggling via Upgrade Request with Content-Length
1d ago
CVE-2026-58051 libssh2 - Free of Uninitialized Pointer in publickey List Cleanup
1d ago
CVE-2026-58050 libssh2 - Integer Overflow in publickey Subsystem Attribute Allocation
1d ago
CVE-2026-52908 RDMA: During rereg_mr ensure that REREG_ACCESS is compatible
1d ago
CVE-2026-52909 ip6_vti: set netns_immutable on the fallback device.
1d ago
CVE-2026-52910 bpf: Free reuseport cBPF prog after RCU grace period.
1d ago
CVE-2026-53228 ipv6: sit: reload inner IPv6 header after GSO offloads
2d ago
CVE-2026-53225 sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
2d ago
CVE-2026-53220 netfilter: revalidate bridge ports
2d ago
CVE-2026-53262 l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
2d ago
CVE-2026-52961 ceph: fix BUG_ON in __ceph_build_xattrs_blob() due to stale blob size
2d ago
CVE-2026-53107 wifi: libertas: don't kill URBs in interrupt context
2d ago
20 loaded
SE
SecurityWeek
3h ago · 10 items
BlueHammer Vulnerability Exploited in Ransomware Attacks
3h ago
Decades-Old Bash Tricks Expose AI Coding Agents to Supply Chain Attacks
4h ago
Aflac Japan Data Breach Impacts 4.38 Million
4h ago
Hacker Conversations: Chris Thompson, Former Head of IBM X-Force Red, Co-Founder of RemoteThreat
5h ago
Supreme Court Rules Constitutional Privacy Protections Apply to Cellphone Users’ Location History
5h ago
Exploitation of Recent Oracle E-Business Suite Vulnerability Begins
5h ago
The AI Token Costs That Can Break Cybersecurity
7h ago
Nissan Employee Data Breached in Oracle PeopleSoft Hack
7h ago
Critical SimpleHelp Vulnerability Exploited for Malware Delivery
8h ago
Quantifind Raises $200 Million for AI-Native Risk Intelligence
10h ago
SE
Securelist
7h ago · 10 items
ToddyCat: your hidden email assistant. Part 2
7h ago
An in-depth analysis of Umbrij, a new tool used by the ToddyCat APT group to compromise corporate email communications in Gmail. The attack targeted OAuth authorization tokens, allowing threat actors to gain access to Google services.
The Gentlemen are knocking: сustom backdoors and evolving tactics
1d ago
Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.
Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools
5d ago
Kaspersky researchers analyze the threat landscape for SMBs in 2026: the rise of attacks involving fake AI tools, phishing schemes, and data sold on the dark web.
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
6d ago
Kaspersky researchers analyze a new global campaign dubbed StrikeShark that delivers Cobalt Strike Beacon via custom SharkLoader malware.
A VBScript campaign distributed through WhatsApp deploying RMM software
8d ago
A Kaspersky researcher analyzes a global malicious campaign that distributes VBS scripts via WhatsApp delivering a UEMS RMM agent through a multi-stage infection chain.
Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk
14d ago
Since late 2025, malware has been spreading rapidly through the Steam Workshop. In most cases, we caught old, familiar threats such as DarkKomet, the Lumma and Vidar infostealers.
Argamal: Malware hidden in hentai games
27d ago
Kaspersky researchers analyze new Argamal RAT distributed via infected hentai games and allowing the attacker to control the target machine.
Wardriving assessment across Mexico: Preparing for the 2026 World Cup
28d ago
In the lead-up to the 2026 FIFA World Cup, Kaspersky GReAT experts conducted a wardriving assessment in Mexico City, Monterrey, and Guadalajara to evaluate Wi-Fi hotspot security configurations and potential exposure risks.
Containers on fire: from container escapes to supply chain attacks
29d ago
We break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks.
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
32d ago
What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.
FP
Fraud Prevention – Riskified
12h ago · 1 items
SA
Security - Ars Technica
19h ago · 20 items
US offers $10 million for info on group behind Signal and WhatsApp hacking spree
19h ago
One-two punch delivered in global operation disrupts cybercrime "assembly line"
5d ago
White House drastically shortens deadline for dropping quantum-vulnerable crypto
6d ago
Following user outcry, AMD reinstates memory encryption in consumer CPUs
7d ago
Microsoft discovers new lightweight backdoor that steals cryptocurrency
11d ago
Apple patches high-severity eavesdropping vulnerability in Beats Studio Buds
11d ago
Massive breach spills credentials for thousands of sensitive networks
12d ago
"Dangerous" AI models are coming no matter what
12d ago
Windows and Linux users: The deadline to update Secure Boot keys is near
13d ago
Critical Copilot vulnerability allowed hackers to steal 2FA code from users
14d ago
Users cry foul after AMD stripped memory crypto from its consumer CPUs
14d ago
PeopleSoft 0-day affecting hundreds of organizations steals gigabytes of data
17d ago
Locked in heated rivalry with researcher, Microsoft fixes 0-day they disclosed
20d ago
High-severity vulnerability in Linux caused by a single faulty character
21d ago
For the 2nd time in weeks, Microsoft packages laced with credential stealer
21d ago
How a USB-connected speaker can infect a PC without ever being touched
24d ago
Dashlane explains how attackers managed to download encrypted password vaults
25d ago
Can't make sense of Dashlane's vault theft notification? You're not alone.
26d ago
Hackers duped Meta AI support chatbot to steal celebrity Instagram accounts
28d ago
Dozens of Red Hat packages backdoored through its official NPM channel
28d ago
20 loaded
SL
Security Latest
19h ago · 20 items
Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs
19h ago
Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change
1d ago
Security News This Week: LastPass Users Had Their Data Stolen—Again
3d ago
The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials
4d ago
British Police Built a Sprawling Crime-Prediction Machine. Some Results Couldn’t Be Trusted
5d ago
Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed
6d ago
OpenAI Launches Full-Scale Effort to Patch Open-Source Bugs as It Takes on Anthropic’s Mythos
8d ago
World Cup Scams Are Getting Harder to Spot
8d ago
A Critical Deadline Is Approaching for Windows and Linux Security
9d ago
Hackers Claim to Leak Stolen Madison Square Garden Data
10d ago
How the Peter Thiel-Linked Dialog Club Secretly Ranks Its Members
11d ago
How to Watch the Knicks Parade on NYC Traffic Surveillance Cameras
12d ago
The UK Will Scan Asylum-Seekers’ Faces for Age Checks—Despite Knowing the Tech Is Flawed
12d ago
Leak Exposes Members of Peter Thiel’s Secretive ‘Dialog’ Society
13d ago
‘Dangerous’ AI Models Are Coming No Matter What
13d ago
Meta Tapped a Pentagon Supplier to Prototype Face Recognition for Its Glasses
15d ago
The FCC Wants to Kill Burner Phones
17d ago
Grok Is Still Hosting Sexualized Deepfakes of Famous Women
18d ago
Drug Sites Hijacked Spotify’s Search Ranking Through Fake Podcasts
19d ago
Signal Alums Reveal ‘Encrypted Spaces,’ a System for Making Private Collaboration Apps
19d ago
20 loaded
CD
Cyber Defense Magazine
1d ago · 80 items
CISA Warns Attackers Are Targeting Critical Internal Business Platforms
1d ago
Return On Risk: The New Measure Of Cyber Resilience
2d ago
Path to StateRAMP
2d ago
Rethinking Identity Security In The Age Of AI Driven Fraud
3d ago
New Age Insider Risk
3d ago
Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure
4d ago
Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To
4d ago
The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer
5d ago
The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target
5d ago
NSA Urges Cyberthreat Timeline Has Compressed From Years to Months
5d ago
Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have
6d ago
Invisible By Design: Making Quantum-Safe Encryption The Easy Path
6d ago
Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming
6d ago
Innovator Spotlight: NAKIVO
6d ago
Cybersecurity Outsourcing. Beyond Cost
7d ago
Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets
7d ago
Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data
7d ago
Data Breach with Eastman Kodak Company
7d ago
The World Cup Is Here… And So Are The Cyber Risks
8d ago
Cloud Managed Services For Modern Cybersecurity To Secure Cloud
8d ago
Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors
9d ago
The Shadow AI Paradox: Governing Innovation At Machine Speed
10d ago
Innovator Spotlight: Ensemble
10d ago
Innovator Spotlight: Centrii
10d ago
NSPM-12: The New Baseline for National Security Cybersecurity
11d ago
Five Compliance Realities Federal Contractors Can’t Ignore
12d ago
Cyber Security Market Insights & Trends Driving The Next Wave Of Protection
13d ago
AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns
13d ago
Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions
14d ago
Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection?
15d ago
CMMC Is Exposing A Major Gap In The Defense Supply Chain
16d ago
Zero Trust For AI In Defense Networks
17d ago
Why Most Cyber Resilience Programs Fail Before The First Incident
18d ago
Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration
19d ago
What The Cybersecurity Industry Knows And Will Not Say
20d ago
Rethinking Access Governance for AI Agents
21d ago
How CIAM Helps Boost Business
22d ago
World Cloud Security Day
22d ago
CMMC Is Here, But AI Changes The Compliance Conversation
23d ago
Cybersecurity Improved Detection But Exposed a New Problem
24d ago
Innovator Spotlight: Airrived
24d ago
Cloud Security In Practice
25d ago
Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing
26d ago
The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector
27d ago
Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit
28d ago
Why Is Cybersecurity Now A Business Priority, Not Just An IT Function?
44d ago
The Security Mistakes Being Repeated With Ai
45d ago
The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract
46d ago
Innovator Spotlight: Klever Compliance
46d ago
Innovator Spotlight: Radware
46d ago
Innovator Spotlight: JScrambler
46d ago
Innovators Spotlight: OPSWAT
47d ago
The Board Is Asking The Wrong Security Question
48d ago
Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification
49d ago
Innovator Spotlight: Iru
49d ago
Innovator Spotlight: Axonius
49d ago
Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge
50d ago
The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface
50d ago
Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI
51d ago
Innovator Spotlight: Lineaje
51d ago
Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care
53d ago
Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered
54d ago
When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity
54d ago
Innovators Spotlight: Badge (Part II)
54d ago
Redefining Security Operations Through Seceon’s Open Threat Management Platform
55d ago
The Insurance Industry Is Rewriting Cybersecurity Strategy
56d ago
Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management
57d ago
Ai Didn’t Break Cybersecurity, It Revealed It
58d ago
RSAC 2026: The Power of Community
59d ago
Inside RSAC 2026
60d ago
Innovator Spotlight: The Open Group
60d ago
Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark
61d ago
Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints
62d ago
Innovator Spotlight: Puneet Bhatnagar
62d ago
Cybersecurity Risks in 2026
63d ago
Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters
63d ago
Innovator Spotlight: TokenCore
63d ago
Platform Engineering: The Rise of a Disciplinary Rethink
64d ago
60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea?
64d ago
From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense
65d ago
80 loaded
WE
WeLiveSecurity
1d ago · 20 items
Inside the inbox: Why cybercriminals want to break into your email account
1d ago
SMB cyber readiness: the road to resilience starts here
4d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
5d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
6d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
12d ago
Protecting legacy OT systems against modern cyberthreats
13d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
14d ago
EvilTokens: A phishing attack that doesn’t steal your password
15d ago
OceanLotus: From external espionage to domestic targeting
19d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
20d ago
Cybercriminals: the 'auditors' you never hired
21d ago
Lessons for life: Why children’s data is a long-term identity risk
27d ago
This month in security with Tony Anscombe – May 2026 edition
32d ago
ESET APT Activity Report Q4 2025–Q1 2026
33d ago
What to consider before asking an AI chatbot for health advice
34d ago
BTMOB: A stealthy RAT burrowing deep into Android devices
35d ago
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
39d ago
Webworm: New burrowing techniques
41d ago
The quest for greater tech independence
42d ago
Why geopolitical turmoil is a gift for scammers, and how to stay safe
46d ago
20 loaded
TM
Trend Micro Research, News, Perspectives
1d ago · 20 items
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
1d ago
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer
7d ago
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
12d ago
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
13d ago
Governing Claude Enterprise in Environments Where Inline Controls Can't Go
18d ago
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026
20d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
22d ago
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
29d ago
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
35d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
39d ago
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
42d ago
Agentic Governance: Why It Matters Now
43d ago
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft
48d ago
Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America
50d ago
What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do
51d ago
Supporting the National Cyber Strategy: How TrendAI™ Helps
55d ago
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise
56d ago
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
57d ago
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
61d ago
Kuse Web App Abused to Host Phishing Document
62d ago
20 loaded
BH
Black Hat
1d ago · 15 items
Black Hat Europe 2025 | How We Turned AI's 'Web Browsing' Into A Gateway For Targeting 1B+ Users
1d ago
Black Hat Europe 2025 | The Forensic Trail On GitHub: Hunting For Supply Chain Activity
2d ago
Black Hat Europe | LINE-Break: Cryptanalysis And Reverse Engineering Of Letter Sealing
2d ago
Black Hat Europe 2025 | Hacking Smart Cities One Building At A Time - A City Of A Thousand Zero Days
3d ago
Black Hat Europe 2025 | Silence On macOS: What 70K Binaries Reveal About The macOS Malware Ecosystem
3d ago
Black Hat Intercepted Video Series | Lexie Thach
4d ago
Black Hat Intercepted | Lexie Thach, Ex Machina Parlor + Naval Information Warfare Center Pacific
5d ago
Black Hat Europe 2025 | Stress-Testing SAST And LLMs On Modern Web Backends
5d ago
Black Hat Europe 2025 | Page Phantoms: Zero-IO, In-Memory Tampering Of The Linux Page Cache
5d ago
Black Hat Europe 2025 | SCOMmand And Conquer - Attacking System Center Operations Manager
6d ago
Black Hat USA 2026 | Welcome Video
7d ago
Black Hat Europe 2025 | China's Nexus APT Exploiting Ivanti Endpoint Manager Mobile
7d ago
Black Hat Europe 2025 | RMPocalypse: A Catch-22 Breaking AMDs Confidential Computing
7d ago
Black Hat Intercepted | James Holland, Palo Alto Networks
8d ago
Black Hat Europe 2025 | Taking Over Your Amazon Account With A Kindle
8d ago
15 loaded
DB
David Bombal
2d ago · 15 items
2026 home lab setup to test malicious links safely for FREE (step by step)
2d ago
Which is Ethernet? What's the difference?
4d ago
Europe’s 800 Exaflop SUPERCOMPUTERS
5d ago
They Created a Supercomputer in a Rack?
7d ago
Build a Complete Free CCNA Home Lab in 2026 With No Gear
9d ago
Broken access control demo
9d ago
Will this replace PoE (Power over Ethernet)?
11d ago
Never look into a fiber cable!
11d ago
What is Clam AV (free & open source )?
12d ago
Learn Linux in 180s - history command
13d ago
What is an IDOR? Google and Uber got hacked this way.
14d ago
Shadow AI: What every network engineer must know
16d ago
What is SNORT? Free open source IDS
17d ago
Why you never touch fiber optic cables (the tips)
18d ago
Do YOU Need Antivirus in 2026?
21d ago
15 loaded
IP
IppSec
3d ago · 15 items
HackTheBox - WingData
3d ago
HackTheBox - Nanocorp
10d ago
HackTheBox - VariaType
17d ago
HackTheBox - Facts
24d ago
HackTheBox - Interpreter
31d ago
HackTheBox - MonitorsFour
38d ago
HackTheBox - Pterodactyl
45d ago
HackTheBox - Overwatch
52d ago
HackTheBox - Sorcery
66d ago
HackTheBox - AirTouch
73d ago
HackThebox - Eighteen
80d ago
HackTheBox - DarkZero
87d ago
HackTheBox - Browsed
94d ago
HackTheBox - Conversor
101d ago
HackTheBox - Gavel
108d ago
15 loaded
TC
The Cyber Mentor
4d ago · 15 items
Real Folks of Cyber | Pearce Barry | Day in the Life
4d ago
Getting Started with the TCM Security Academy
4d ago
Soft Skills for the Job Market: Resume Writing
11d ago
TCM Security Summer Sale is Here!
14d ago
LIVE: 🕵️ CTF Prize Draw | Cybersecurity
19d ago
Secrets to PNPT Debrief Success
21d ago
TCM Security CTF Walkthrough
25d ago
Top 5 Active Directory Pentesting Tools
27d ago
Real Folks of Cyber | Dan Berger | Day in the Life
33d ago
Soft Skills for the Job Market: Communication
39d ago
LIVE: 🕵️ HTB Sherlocks! | Cybersecurity | Blue Team
47d ago
A Quick Way to Prove Your Cybersecurity Skillset!
48d ago
A Guide to LNK File Forensics
60d ago
Josh Mason | Real Folks of Cyber | DITL
61d ago
Use BLUR-IT to Increase Your OPSEC
69d ago
15 loaded
HS
Heimdal Security Blog
4d ago · 15 items
How Dynamic Defense shuts an attacker out without shutting down the business
4d ago
AI has handed hackers a resource advantage. Winning it back means spending your own resources far more precisely, and that’s the strategy we call Dynamic Defense. The principle is simple. Contain the threat just enough, for just long enough...
Static security has run out of road. The case for Dynamic Defense
4d ago
AI has flipped the economics of cybersecurity in the attacker’s favor. For most of the last decade, defenders held the cost advantage, buying down their risk with a stack of largely static controls. That advantage is gone, and winning it ba...
Breaking the MSP Echo Chamber: The Power of Community
6d ago
MSPs spend too much time talking to other MSPs and not enough time talking to the people they’re supposed to serve. That’s Paul Croker’s view of some of the channel’s biggest growth problems. While most industry events bring technology prof...
How attackers built a RAT on a Windows machine using its own .NET compiler
8d ago
In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so si...
Attacker enables RDP, creates admin, erases evidence in ten seconds
8d ago
At 06:34am on 2 June 2026, an attacker logged on to a customer’s network. In a single automated burst, they switched on remote desktop and created a rogue administrator account. And deleted the evidence behind them. The intrusion reached 34...
The State of AI Risk Management in 2026
14d ago
There is no excerpt because this is a protected post.
Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
15d ago
New Heimdal research shows AI adoption is moving faster than security controls, exposing a confidence gap between executives and IT teams.
Your Next Insider Threat May Be an AI Coworker
18d ago
Heimdal sysadmin Alex Panait spent weeks testing Claude Cowork inside the company. His verdict was blunt. It felt like onboarding a junior employee with no manager, no scoped access, and no clear accountability when something goes wrong. Ex...
The OSI Model and Its Two Missing Layers
18d ago
Two missing layers of the OSI Model can blow up your cyber defense strategy anytime. Jayal Yadal explain what they are.
Heimdal® Marks Six Years of Consecutive ISAE 3000 SOC 2 Type II Certification
22d ago
Heimdal has achieved ISAE 3000 SOC 2 Type II certification for the sixth consecutive year, reflecting the company's continued focus on operational security, accountability, and data protection.
AI Will Absorb 99.98% of SOC Triage Within a Year, as 79% of IT teams brace for AI-driven workload shift
49d ago
Top 10 Cybersecurity Companies in Europe
55d ago
Heimdal Expands AI Strategy with AI Wingman and Third-Party AI Containment
70d ago
You Only Know What You’ve Got When Its Gone
95d ago
Nordic MSPs Can Now Access Heimdal’s Unified Security and Compliance Platform Through Elovade
104d ago
15 loaded
DA
darkreading
4d ago · 104 items
Name That Toon Contest
4d ago
Europe Evolves Into Ransomware's Favorite Region
5d ago
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
5d ago
2026 FIFA World Cup Faces Surge in Cyber Threats
5d ago
Do CISOs Need a Code of Ethics?
5d ago
More Malicious OpenClaw Skills Threaten AI Supply Chain
6d ago
Apple's MacOS Gap Lets Users Disable Security Tools
6d ago
Scope of Salesforce Attacks Expands as Icarus Leaks Data
6d ago
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
6d ago
SocGholish Takedown Highlights Malicious TDS Threats
7d ago
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
7d ago
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
7d ago
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
8d ago
He Thought He Was Secure; His Phone Number Was Stolen Anyway
8d ago
Stressors, AI Forcing Changes to Cybersecurity Teams
11d ago
Novo Nordisk Breach Highlights Software Development Pipeline Risk
11d ago
Operation Escaneo Signals Shift in LatAm Threat Landscape
11d ago
FIFA Bug Exposes World Cup Streams to Remote Takeover
11d ago
Salesforce Data Thefts Continue via Klue App Compromise
12d ago
Get Out of Security Debt by Tackling the Exposure Problem
12d ago
EU Gets a Head Start in Developing 6G Network Security
12d ago
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
17d ago
Claude Fable 5 Doesn't Change the Mythos Security Story
18d ago
Phishing Attack Volume Down 20%, But Risk Still Rising
18d ago
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
18d ago
Segmentation Works for OT If Operators Are Paying Attention
19d ago
Chinese, N. Korean Threat Groups Build on Asia-Pacific Success
19d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
19d ago
Bug Bounty Research Triggers ServiceNow Security Alert
19d ago
AI Risk Worries Insurers & Businesses Alike
19d ago
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
20d ago
The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life
20d ago
Blame AI: Patch Tuesday Hits Record 206 CVEs
20d ago
Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
20d ago
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
20d ago
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
21d ago
AI Slop Will Kill Cybersecurity Storytelling If We Let It
21d ago
Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
21d ago
Check Point VPN Flaw Exploited Since Early May
21d ago
Iran Signed a Ceasefire — Its Hackers Didn't
21d ago
[An RX Global Event] Infosecurity Europe
28d ago
Name That Toon: Mark of (Cybersecurity) Progress
31d ago
Asia's Cyber Insurance Market Shows Signs of Life
32d ago
With Complex Cloud Integrations, Small Errors Lead to Major Compromises
32d ago
'The Com' Cyberattacks Support Violence & Sexploitation
32d ago
As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
32d ago
Dutch Raid Fails to Dent Russian Bulletproof Host
32d ago
Agentic AI Isn't Risky; the Way Orgs Deploy It Is
33d ago
Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security
33d ago
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
33d ago
Nordic CISOs Handle Rising Cyber Threats Remarkably Well
33d ago
Ransomware Actors Show Up In Person to Steal Law Firm Data
33d ago
Latin American Cybercriminals Hoover Up Government Data
34d ago
AI-Assisted Exploit Development Outpaces Scanner Detection
34d ago
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
34d ago
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
34d ago
State Cyber Leaders Push Congress for More Funding, Support
34d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled?
34d ago
For Enterprises, Security Remains Agentic AI's Biggest Challenge
34d ago
The Boring Stuff is Dangerous Now
43d ago
Can Laws Stop Deepfakes? South Korea Aims to Find Out
43d ago
Congress Puts Heat on Instructure After Canvas Outage
45d ago
Cyber Pioneers Ponder Past as Prologue
46d ago
Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems
46d ago
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
46d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
46d ago
'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
47d ago
AI Drives Cybersecurity Investments, Widening 'Valley of Death'
47d ago
Foxconn Attack Highlights Manufacturing's Cyber Crisis
47d ago
Checkbox Assessments Aren't Fit to Measure Risk
47d ago
Attackers Weaponize RubyGems for Data Dead Drops
47d ago
Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak
47d ago
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape
47d ago
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly
48d ago
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
48d ago
It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight
48d ago
Hugging Face Packages Weaponized With a Single File Tweak
49d ago
20 Leaders Who Built the CISO Era: 2 Decades of Change
49d ago
Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
49d ago
How the Story of a USB Penetration Test Went Viral
56d ago
RMM Tools Fuel Stealthy Phishing Campaign
56d ago
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
56d ago
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
57d ago
How Dark Reading Lifted Off the Launchpad in 2006
57d ago
76% of All Crypto Stolen in 2026 Is Now in North Korea
59d ago
If AI's So Smart, Why Does It Keep Deleting Production Databases?
60d ago
Name That Toon: Mark of (Security) Progress
60d ago
20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage
60d ago
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
60d ago
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
60d ago
Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber
60d ago
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
61d ago
Claude Mythos Fears Startle Japan's Financial Services Sector
61d ago
Reverse Engineering With AI Unearths High-Severity GitHub Bug
61d ago
AI Finds 38 Security Flaws in Electronic Health Record Platform
61d ago
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
62d ago
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
62d ago
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
62d ago
NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later
62d ago
Feuding Ransomware Groups Leak Each Other's Data
62d ago
Vidar Rises to Top of Chaotic Infostealer Market
62d ago
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
63d ago
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
63d ago
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
64d ago
104 loaded
CY
CyberScoop
4d ago · 105 items
FCC passes new cybersecurity rules for emergency systems, undersea cables
4d ago
Federal court rules Trump election-focused executive order illegal
5d ago
Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract
5d ago
Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack
5d ago
Why patch directives only go so far
5d ago
Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
5d ago
In a first, a court takedown goes after two cybercrime tools at once
6d ago
Open-source security is posing challenges governments can’t easily solve
6d ago
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
6d ago
Algerian man charged with running two cybercrime marketplaces
7d ago
Court rules SAVE database illegal, orders it dismantled
7d ago
Trump executive orders speed up post-quantum migration, boost industry
7d ago
Intel agencies: Frontier AI models will reshape cybersecurity faster than expected
8d ago
Authorities disrupt Evil Corp’s SocGholish botnet
11d ago
Congress tees up No FAKES Act, aiming at AI-generated deepfakes
11d ago
How software development’s speed obsession enabled TeamPCP’s chaos crusade
12d ago
Accenture shells out $4.18B on three companies in big industrial cybersecurity push
12d ago
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April
13d ago
Lawmakers leery about Trump administration’s Anthropic order
13d ago
AI’s constant patching treadmill can be a security problem
13d ago
A case for how to shape ‘ingredient lists’ for AI models
14d ago
Google exposes China espionage group that’s been lurking in networks undetected since 2023
14d ago
Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat
15d ago
Anthropic disables new models after government calls them a national security concern
16d ago
FBI takes down massive China-based cybercrime network that caused $1.9B in losses
17d ago
US, France, and Italian authorities shut down massive deepfake porn site
17d ago
Conti ransomware group member pleads guilty, faces up to 20 years in prison
17d ago
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw
18d ago
CyberCorps is adapting to AI. The budget isn’t keeping up.
18d ago
Russian national charged in connection with Void Blizzard espionage campaign
18d ago
OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
19d ago
CISA directive orders agencies to prioritize vulnerability patching in a new way
20d ago
Microsoft breaks Patch Tuesday record with 206 vulnerabilities
20d ago
Anthropic’s new model is Mythos on a leash
21d ago
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
21d ago
Cisco customers encounter another SD-WAN zero-day under attack
21d ago
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
21d ago
The AI security race needs accountability, not overregulation
22d ago
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
25d ago
Hill Dems hammer GOP for $250M CISA budget cut
25d ago
Your AI agent could become your biggest insider threat
25d ago
Inside the race to adapt to an AI-powered security world
26d ago
European authorities crack down on illegal streaming networks
26d ago
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels
26d ago
DOD wants to integrate cyber in all operations, and integrate security into AI
27d ago
Trump administration releases scaled-back AI executive order
28d ago
Anthropic expanding access to Project Glasswing
28d ago
Attackers are exploiting Palo Alto Networks defect that initially flew under the radar
28d ago
Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight
28d ago
USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order
28d ago
Election threats are focused on campaign systems, not voting machines
29d ago
Tennessee man linked to 764 accused of series of crimes against children dating back to 2022
31d ago
Federal audit reveals NIST’s NVD is plagued by poor planning and duplication
32d ago
House panel poised to hold hearing centered on AI impact on cyber
32d ago
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
32d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
33d ago
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms
33d ago
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
33d ago
UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace
33d ago
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
34d ago
Apple open-sources quantum-resistant encryption code
34d ago
Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
39d ago
Lawmakers from both parties say CISA cuts have gone too far
39d ago
Trump postpones executive order focused on AI security
39d ago
CISA chief frets about open-source vulnerabilities, delayed security improvements
40d ago
European authorities take down prolific cybercrime VPN service
40d ago
The readiness paradox: Why a false sense of cyber confidence is becoming a liability
40d ago
Meet Rampart and Clarity, Microsoft’s new red team combo AI agents
40d ago
GitHub says internal repositories were impacted in poisoned VS Code extension attack
41d ago
CISA credential leak raises alarms, and Capitol Hill demands answers
41d ago
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches
41d ago
Mini Shai-Hulud returns, compromising hundreds of npm packages
42d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
42d ago
AI might cut false positives, but it won’t stop the slop
42d ago
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
42d ago
The Canvas breach proved that prevention is no longer enough
43d ago
Former CISA nominee Sean Plankey named US CEO of defense startup
43d ago
Colorado governor commutes prison sentence for election denier Tina Peters
45d ago
Here’s how the FTC plans to enforce the Take It Down Act
45d ago
Cisco zero-day under ongoing attack by persistent threat group
46d ago
Pentagon cyber official calls advanced AI ‘revolutionary warfare’
46d ago
White House cyber official: identity security matters more than ever in the age of AI
46d ago
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
47d ago
Researchers say AI just broke every benchmark for autonomous cyber capability
47d ago
Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks
47d ago
DOJ releases legal rationale for nationwide voter data collection
47d ago
Weaponized AI: The new frontier of fraud and identity spoofing
47d ago
Daybreak is OpenAI’s answer to the AI arms race in cybersecurity
48d ago
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
48d ago
Major world economies spell out key elements of AI ‘ingredients list’
48d ago
Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical
48d ago
Google and Amnesty International teamed up to make it harder for spyware vendors to hide
49d ago
AI is separating the companies built to scale from the ones built to sell
49d ago
Instructure claims hackers returned stolen Canvas data after an extortion standoff
49d ago
Google spotted an AI-developed zero-day before attackers could use it
50d ago
The missing cybersecurity leader in small business
50d ago
Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments
52d ago
ShinyHunters claims nearly 9,000 schools affected by Canvas data breach
53d ago
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI
53d ago
Ivanti customers confront yet another actively exploited zero-day
53d ago
Trump officials are steering a cybersecurity scholarship program toward AI
53d ago
American duo sentenced for hosting laptop farms for North Korean IT workers
54d ago
One House Democrat is pressing Commerce on the government’s spyware use
54d ago
A DOD contractor’s API flaw exposed military course data and service member records
54d ago
A critical Palo Alto PAN-OS zero-day is being exploited in the wild
54d ago
105 loaded
CS
Cisco Security Advisory
5d ago · 20 items
Cisco Finesse Remote File Inclusion Vulnerability
5d ago
A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based attacks. This vulnerability ...
Cisco Advance Notification for Publication of July 1, 2026, Security Advisories
6d ago
On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst Center Secure En...
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities
8d ago
Multiple vulnerabilities in the web-based management interface of Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct a c...
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
11d ago
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected devi...
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
13d ago
A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of user-supplied commands....
Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
13d ago
A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenticated, remote attacker to execute arbitrary commands on an affected device. This vulnerability is due to insufficient input v...
Cisco Webex App Open Redirect Vulnerability
13d ago
A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker to redirect users to a malicious webpage. Cisco has addressed this vulnerability in the Cisco Webex App, and no customer ...
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
13d ago
A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an un...
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
13d ago
May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability was disclosed in February 2026. This ...
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
14d ago
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. This vulnerability exists...
Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
17d ago
Cisco Webex Meetings Cross-Site Scripting Vulnerability
27d ago
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
27d ago
Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability
41d ago
Cisco Secure Workload Unauthorized API Access Vulnerability
41d ago
Cisco ThousandEyes Virtual Appliance Authenticated Remote Code Execution Vulnerability
41d ago
Cisco ThousandEyes Enterprise Agent BrowserBot Command Injection Vulnerability
41d ago
Continued Evolution of Persistence Mechanism Against Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
41d ago
Cisco Catalyst SD-WAN Manager Vulnerabilities
47d ago
Cisco Crosswork Network Controller and Cisco Network Services Orchestrator Advisory
47d ago
20 loaded
RF
Recorded Future
5d ago · 20 items
Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge
5d ago
Discover how Recorded Future’s Insikt Group combines human expertise with automated analysis to turn raw data into actionable, industry-leading threat intelligence.
Evaluating Mexico’s New Cybersecurity Plan
5d ago
Explore an analysis of Mexico’s 2025–2030 National Cybersecurity Plan. Discover how Mexico is addressing critical threats like ransomware, organized crime, and AI-driven attacks while preparing its digital infrastructure for the 2026 FIFA W...
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
6d ago
A dataset containing valid administrative and VPN credentials for tens of thousands of Fortinet FortiGate firewalls, Recorded Future recommends organizations patch their systems immediately.
The Purchase Scam Tactic Headed for the World Cup | Recorded Future
7d ago
A purchase scam tactic hijacks organic search through compromised sites, and it’s built to scale into 2026 FIFA World Cup fraud. How it works and how to respond.
State Digital Surveillance Risk Landscape
13d ago
Explore the state digital surveillance risk landscape. Learn how governments use spyware, AI, and network interception to monitor travelers and how to mitigate these risks.
The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine
14d ago
Learn how Recorded Future’s proprietary collection engine empowers organizations to move beyond reactive security. Discover the power of our four unique intelligence source types—technical, underground, community, and open-source—working to...
Recorded Future Launches Impact and Metrics Dashboard
19d ago
See the business value of your intelligence program in one live, continuously updated dashboard, built for the conversations that matter most with the executives who own budget and strategy.
Cyber-Enabled Maritime Sanctions Evasion
19d ago
Discover how Iranian and Russian shadow fleets use a vast network of fake maritime websites and fraudulent documents to evade international sanctions
2026 FIFA World Cup: What Public Safety Officials Need to Know
20d ago
Prepare for the 2026 FIFA World Cup with expert analysis of the physical and cyber threat landscape. Discover key mitigation strategies for host city officials to ensure public safety
China's Noncombatant Evacuation Operations: 2005–2025
20d ago
Explore the Insikt Group study on 37 Chinese noncombatant evacuation operations (NEOs) from 2005–2025, revealing how China leverages SOEs and civilian resources for its overseas interests
Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars
21d ago
May 2026 CVE Landscape
22d ago
Why Holistic Sourcing Wins: The Numbers Behind the Recorded Future Advantage
25d ago
Threats to the 2026 FIFA World Cup
26d ago
Remembering Sir Alex Younger
26d ago
Iran Expands Handala Brand to Physical Threats
28d ago
The Vulnerability Flood Is Now a Board Conversation. Here's How to Lead It.
40d ago
At Mythos Speed: A Defender's Playbook for the AI Vulnerability Surge in 2026
42d ago
April 2026 CVE Landscape
46d ago
NIST NVD Enrichment Policy Change: Prioritizing Vulnerabilities with Attacker Behavior Signals
47d ago
20 loaded
BF
Blog – Forter
6d ago · 10 items
New at Forter: AI Agents Built to Amplify Your Team
6d ago
Can AI Agents Find, Trust, and Choose Your Brand?
7d ago
IMPACT Roadshow Recap: Getting Ready for Agentic Commerce
20d ago
Agent-Ready: How to Prepare Your Site for AI-Driven Commerce
26d ago
Japan’s 3DS Mandate: One Year In
46d ago
One-Click Refunds Are Not as Hard as You Think
55d ago
Toys“R”Us Japan Implements Forter’s Fraud Management and Payment Optimization Solutions
62d ago
More of What Matters: Forter’s April Product Release
63d ago
If AI Agents Can’t Find You, Do You Even Exist?
63d ago
Return Policy Abuse Is Theft. It’s Time to Treat It That Way.
76d ago
KO
Krebs on Security
7d ago · 10 items
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
7d ago
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The ...
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
11d ago
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers ...
Who Runs the Ransomware Group ‘The Gentlemen?’
20d ago
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of...
A Record-Breaking Patch Tuesday for June 2026
20d ago
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bug...
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
28d ago
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how ...
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
36d ago
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the Euro...
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
39d ago
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a v...
Alleged Kimwolf Botmaster ‘Dort’ Arrested, Charged in U.S. and Canada
39d ago
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed deni...
CISA Admin Leaked AWS GovCloud Keys on Github
42d ago
Until this past weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of inte...
Patch Tuesday, May 2026 Edition
48d ago
Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good at finding security vulnerabilities in human-made computer code. That reality is on full display this m...
TI
Technical Information Security Content & Discussion
7d ago · 255 items
Cloudflare patches Copy-Fail across every server in two days
7d ago
New Cisco RCE was fixed
7d ago
CVE-2026-25860 turn XSS to RCE
7d ago
Exploiting Auth0 Defaults in XSS Attacks - elttam
8d ago
Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1)
9d ago
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530
10d ago
OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099)
11d ago
Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration
11d ago
CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance
11d ago
Would you like some malware served at the very top of DuckDuckGo?
12d ago
Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update
12d ago
QoS Policies to Restrict EDR Traffic and Detection Strategies
13d ago
Getting a CVE Without Shipping Slop
13d ago
PrizeBuzz phishing network analysis
13d ago
27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass
13d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
14d ago
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
14d ago
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
15d ago
Researcher accidentally gained access to a threat actor-controlled phishing website
16d ago
PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs
16d ago
MeshCentral: From XSS to RCE
16d ago
Getting the PID from random numbers in PHP
17d ago
The Axios npm compromise was visible in registry metadata before anyone ran npm install
17d ago
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs
17d ago
Free Compromise Detection for GitHub Repos - Tracebit Community Edition
18d ago
Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)
18d ago
Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery
18d ago
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs
18d ago
Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules
18d ago
Claude Fable 5: mid-tier results on coding tasks
19d ago
Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work
19d ago
Hacking Google with A.I. for $500,000
19d ago
Prompt injection: attacking the analyst's AI
19d ago
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
19d ago
We post-trained a model for offensive security instead of teaching it to refuse
20d ago
How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026
20d ago
FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster
20d ago
certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA"
20d ago
BlackSun - Defender for Endpoint on macOS
20d ago
GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline)
20d ago
Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam
20d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
20d ago
Apple’s Siri-AI, or more shouting into the void about “private” agents
20d ago
Entra Agent ID from a Security Perspective
21d ago
X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection
21d ago
WinGet - Code Execution, Persistence and Detection Strategies
21d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
21d ago
I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information
21d ago
AI Agents May Always Fall for Prompt Injections
21d ago
Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it
22d ago
EDRChoker: Choking The Telemetry Stream to Bypass Defenses
23d ago
PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware
23d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
23d ago
Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption
25d ago
Keeping Secrets Out of Logs
25d ago
Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier)
25d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
25d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
26d ago
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
26d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
26d ago
Season VI of the US Games launches TOMORROW!
26d ago
EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires
27d ago
Interesting- What LLM vuln research looks like
27d ago
Hacking your PC using your speaker without ever touching it
27d ago
Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing
27d ago
Golang code review notes II - elttam
27d ago
Using AI to Secure Its Generated Code Is a Ponzi Scheme
27d ago
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
27d ago
We Added a Detection Rule. We Were Not Expecting This.
27d ago
1-Click GitHub Token Stealing via a VSCode Bug
28d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
28d ago
NuGet Code Execution As A Service
28d ago
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
28d ago
Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider
29d ago
r/netsec monthly discussion & tool thread
29d ago
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
29d ago
Stealing Passwords via HTML Injection Under a Strict CSP
29d ago
Subnet discovery through multi-protocol TTL tracing
29d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
30d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
30d ago
Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters
31d ago
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
31d ago
Introducing Keyhog: The First GPU Accelerated secret scanner
31d ago
OffensiveCon26 YouTube Playlist released
31d ago
1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog
32d ago
I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found.
32d ago
Fooling around with encrypted reasoning blobs
32d ago
CALIF: An AI audit of FreeBSD
32d ago
CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries
32d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
32d ago
Visual Studio Extensions Revisited
32d ago
Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP)
33d ago
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
33d ago
What scanners are actually trying against AI infrastructure
33d ago
Defense by accumulation
33d ago
New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
34d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
34d ago
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
34d ago
HN Security - AI Reporter - Let's automate reporting in Burp Suite!
34d ago
Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records
34d ago
RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact
34d ago
Navigating Lax Load Balancers: When an Intersection Gets You Inside
35d ago
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents
35d ago
OTP lockout state leaked valid-code signal, enabling OLX account takeover
35d ago
How journalists rely on VPNs to protect press freedom
35d ago
Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
35d ago
Update Starlette Now. New severe vulnerability dropped.
35d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
35d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
36d ago
CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth
36d ago
Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal
36d ago
nmap on Linux: Guide to Network Scanning and Discovery
36d ago
Prompt Injection finally broke my brain a little. My first article as a security student.
37d ago
How to Use Claude AI: A Complete Technical Beginner's Guide
37d ago
Pardon MIE?: how Mythos did not bypass Apple MIE
38d ago
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
38d ago
AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22
38d ago
Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't)
38d ago
Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension
39d ago
Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
39d ago
Data breach in name of protest
39d ago
pnpm 11 Might Finally Be a Better Default Than npm
39d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave
39d ago
[Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled
39d ago
GitHub Actions Cache Poisoning is eating open source
40d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
40d ago
CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
40d ago
FatGid - FreeBSD 14.x kernel LPE
40d ago
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
40d ago
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
40d ago
The IBM X-Force Index 2026 explains all three in one finding.
40d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
41d ago
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
41d ago
[ Removed by Reddit ]
41d ago
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
41d ago
Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online
41d ago
The IBM X-Force Index 2026 explains all three in one finding.
41d ago
GitHub hit by a compromised VSCode extension
41d ago
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
41d ago
We audited 12K n8n templates: most have critical vulnerabilities
41d ago
Veilgate - Deception proxy
41d ago
Sleeping Agent: Silent persistent C2 through Web Push
41d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
41d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
42d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
42d ago
CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing
42d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
42d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
42d ago
The quiet death of behavioral anti-bot and the pivot to hardware ZKPs
42d ago
AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems
42d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
42d ago
The down fall of bug bounties
43d ago
TanStack Supply Chain Attack (And How to Lock Down GitHub Actions)
43d ago
Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation
43d ago
Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation
43d ago
Ansible security and compliance guide
44d ago
Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain
44d ago
AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize.
45d ago
Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works
45d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
45d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems
46d ago
Automating code security reviews with Claude Mythos-level capabilities
46d ago
Instrumenting QT6 desktop apps with Frida - Part 1
46d ago
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
46d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
46d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
47d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
47d ago
CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure
47d ago
How to Check Computer Activity: 2026 Guide for Windows and Mac
47d ago
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
47d ago
Hunting the Behavior Behind npm Supply Chain Attacks
47d ago
WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
47d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
47d ago
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
47d ago
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
47d ago
Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out
47d ago
On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study)
48d ago
A stealth approach to Process Injection - EntryPoint Hijacking
48d ago
A year of Apple Security Bounty research — 16 closed findings, full disclosure
48d ago
AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods
48d ago
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
48d ago
The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop
48d ago
Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
49d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
49d ago
I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
49d ago
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
49d ago
New ipTIME Pre-Auth RCE in CWMP
49d ago
Postmortem: TanStack npm supply-chain compromise
49d ago
How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models.
49d ago
OpenAI announces Daybreak, "frontier AI for defenders"
49d ago
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
49d ago
How I Defeat Passkeys Nearly Every Time in Phishing Assessments
50d ago
MyAudi app:Security issues in Audi Connected Vehicle experience
50d ago
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
50d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
50d ago
Autonomous Vulnerability Hunting with MCP
50d ago
ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement
50d ago
Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple
51d ago
The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
51d ago
Outrunning SHA256 with Physics
51d ago
Memory Poisoning AI Agents via ChromaDB
51d ago
Defence in Depth: A Practical Secure Corporate Network Topology
51d ago
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram
51d ago
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
51d ago
Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection
52d ago
Securing CI/CD for an open source project: lessons from Cilium
52d ago
ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12
53d ago
Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config
53d ago
Copy Fail (CVE-2026-31431): A Technical Deep Dive
53d ago
Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo
53d ago
Dirty Frag - Linux LPE similiar to Copy Fail
53d ago
Honey Tokens: Bait Credentials That Catch Breaches
53d ago
CVE-2026-42511 Breakdown: RCE in FreeBSD
54d ago
Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804
54d ago
An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support)
54d ago
Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI
54d ago
Quacc++: Automated Open Source Vulnerability Discovery
54d ago
Binance fixed the IP whitelist gap — but the disclosure process is still broken
55d ago
Non-Determinism of Maps in Golang: Why, How, and the Consequences
55d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
55d ago
Vulnerability Garden
55d ago
Scan. Secure. Simplify. — Free Web Tools Platform
55d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
55d ago
Salesforce pentesting novel techniques- how to be an apex predator
55d ago
DigiCert: Misissued code signing certificates
55d ago
Major AI Clients Shipping With Broken OAuth Implementations
56d ago
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10
56d ago
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud
56d ago
The Danger of Multi-SSO AWS Cognito User Pools
56d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
56d ago
Proton Pass: Second-Password Bypass Through Emergency Access
56d ago
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
56d ago
Lateral Movement - Cross-Session Activation
57d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
57d ago
Your vibe-coded app is probably violating GDPR right now
57d ago
Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate)
58d ago
How to exfiltrate data using only numeric outputs
59d ago
For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall.
59d ago
Every incident public companies have disclosed to the SEC, in one searchable database
59d ago
r/netsec monthly discussion & tool thread
60d ago
Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster
60d ago
Seventeen vulnerabilities in Omi, fourteen days of silence
61d ago
High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940)
61d ago
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
61d ago
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs
61d ago
The Thymeleaf Template Injection That Only Hurts If You Let It
62d ago
Set up automated dependency scanning after the recent npm/PyPI supply chain attacks
62d ago
A Route to Root in a 4G Industrial Router
62d ago
[Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses)
63d ago
The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords
63d ago
89 vulnerabilities in XAPI / Citrix XenServer
63d ago
[ Removed by Reddit ]
63d ago
Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025)
63d ago
Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary
64d ago
MCPwned: a Burp Suite extension for auditing MCP servers
64d ago
255 loaded
HA
Hak5
8d ago · 15 items
Miasma Worm Source Code Leaked + What NPM v12 Means for Developers | Threat Wire
8d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
8d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
8d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
12d ago
Shark Jacked my LAN 🦈
13d ago
Developers React to the 105-Second Github Chain Reaction | Threat Wire
18d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
19d ago
Introducing Shark Jack Display 🦈
22d ago
The GitHub Leak Situation Just Got Worse | Threat Wire
33d ago
The Worm That Deletes Your Entire Computer | Threat Wire
39d ago
A TL;DR on Dirty Frag #cybersecurity #threatwire @endingwithali
39d ago
Google’s Silent AI Install: What They’re Hiding in Your Files #cybersecurity @endi
39d ago
🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍
44d ago
🔴 [LIVE] Payload Review & 1M Subs!
47d ago
🔴 [LIVE] Hak5 Hits 1 MILLION SUBSCRIBERS
48d ago
15 loaded
NA
NahamSec
8d ago · 15 items
This Hacker Got Paid $50,000+ to Break Frontier AI Models
8d ago
This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity
12d ago
How I Made $30,000 Hacking Broken Access Control
15d ago
$30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover
15d ago
Content creations was both a blessing and a curse. #bugbounty
22d ago
This Hacker Made $7,000 Hacking AI With One Email
22d ago
How I Found My First $3,000 AI Vulnerability
29d ago
This GitHub README Hijacks Your AI and Spreads Like a Virus
43d ago
New video: hacking AI coding assistants and IDEs. #bugbounty #ai
43d ago
The Bug Bounty Roadmap I'd Follow If I Started Over (With AI)
50d ago
Is the AI hype helping or killing your bug bounty dreams? #hacking #bugbounty
50d ago
Stop Using AI Connectors Until You Watch This
57d ago
One ChatGPT connector. One email. Full AI agent hijack. #BugBounty #PromptInjection #ai #hacking
57d ago
This hacker made $40,000 using Claude #ai #hacking #bugbounty
64d ago
My Friend Made $40,000 Using Claude Code (Here's How)
64d ago
15 loaded
PN
Proofpoint News Feed
8d ago · 10 items
Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense
8d ago
Proofpoint has been selected to participate in OpenAI Daybreak, which helps trusted cybersecurity companies integrate AI into defensive security operations. Through the OpenAI Daybreak Cyber
OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses
8d ago
Suspected North Korean actors use fake ‘coding assignments’ to steal crypto
21d ago
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
26d ago
Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era
34d ago
New solution reduces exposure to actively exploited vulnerabilities in minutes by turning intelligence into immediate protection across primary attack paths Disrupts AI-powered exploit-
Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks
39d ago
Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude
40d ago
New product integrations bring data protection, insider risk detection, and governance into Claude Enterprise and Claude Platform activity Organizations gain unified visibility across
Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America
48d ago
New MSP Platform business unit, AI-powered all-in-one Microsoft 365 protection, and Marketplace partnership with Pax8 strengthen Proofpoint’s commitment to channel and small and mid-size
The spy who logged me in.
52d ago
Mark Kelly, Staff Threat Researcher at Proofpoint, is discussing their work on "I’d come running back to EU again: TA416 resumes European government espionage campaigns." China-linked threat group TA416 has resumed large-scale phishing ...
Proofpoint Establishes Innovation Precedent for Source-Agnostic Modern Enterprise Investigations
55d ago
Proofpoint Prism Investigator positioned as first fully autonomous Agentic AI solution to significantly streamline investigations for highly regulated and highly
NE
NetworkChuck
10d ago · 15 items
shadow AI is terrifying
10d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
11d ago
HTTPS Doesn't Hide This From Your ISP!!
11d ago
Cisco Just Showed the Future of Networking
12d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
14d ago
I was wrong about VPNs
15d ago
Certification Questions | LIVE AMA | Summer of CCNA
25d ago
Hermes has a Home Assistant skill and it's unreal!
26d ago
FREE coffee at Cisco Live (I'm giving it away)
27d ago
Codex Lives In PowerShell Now
28d ago
I'm Moderating My First Panel… Come see me at Cisco Live
28d ago
Switching back to Windows?!?
28d ago
Who actually owns the AI in your company?
31d ago
Hermes wasn’t built to compete. It was built to WORK.
33d ago
Summer of CCNA - 90 Minute - Session 2
39d ago
15 loaded
AL
Alerts
12d ago · 44 items
CISA Adds One Known Exploited Vulnerability to Catalog
12d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
12d ago
CISA Adds One Known Exploited Vulnerability to Catalog
14d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
15d ago
CISA Adds One Known Exploited Vulnerability to Catalog
18d ago
CISA Adds One Known Exploited Vulnerability to Catalog
19d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
21d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
22d ago
CISA Adds One Known Exploited Vulnerability to Catalog
25d ago
CISA Adds One Known Exploited Vulnerability to Catalog
27d ago
CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
28d ago
CISA Adds One Known Exploited Vulnerability to Catalog
29d ago
CISA Adds One Known Exploited Vulnerability to Catalog
32d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
33d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
34d ago
CISA Adds One Known Exploited Vulnerability to Catalog
35d ago
CISA Adds One Known Exploited Vulnerability to Catalog
39d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
40d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
41d ago
CISA Adds One Known Exploited Vulnerability to Catalog
46d ago
CISA Adds One Known Exploited Vulnerability to Catalog
47d ago
CISA Adds One Known Exploited Vulnerability to Catalog
53d ago
CISA Adds One Known Exploited Vulnerability to Catalog
54d ago
CISA Adds One Known Exploited Vulnerability to Catalog
55d ago
CISA Adds One Known Exploited Vulnerability to Catalog
60d ago
CISA Adds One Known Exploited Vulnerability to Catalog
61d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
63d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
67d ago
CISA Adds One Known Exploited Vulnerability to Catalog
68d ago
CISA Adds One Known Exploited Vulnerability to Catalog
69d ago
Supply Chain Compromise Impacts Axios Node Package Manager
71d ago
CISA Adds Eight Known Exploited Vulnerabilities to Catalog
71d ago
CISA Adds One Known Exploited Vulnerability to Catalog
75d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
77d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
78d ago
CISA Adds One Known Exploited Vulnerability to Catalog
83d ago
CISA Adds One Known Exploited Vulnerability to Catalog
85d ago
CISA Adds One Known Exploited Vulnerability to Catalog
89d ago
CISA Adds One Known Exploited Vulnerability to Catalog
90d ago
CISA Adds One Known Exploited Vulnerability to Catalog
92d ago
CISA Adds One Known Exploited Vulnerability to Catalog
95d ago
CISA Adds One Known Exploited Vulnerability to Catalog
96d ago
CISA Adds One Known Exploited Vulnerability to Catalog
97d ago
CISA Adds Five Known Exploited Vulnerabilities to Catalog
102d ago
44 loaded
AC
All CISA Advisories
12d ago · 125 items
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
12d ago
CISA Adds One Known Exploited Vulnerability to Catalog
12d ago
Schneider Electric EasyLogic T150 and Saitel DP
12d ago
AVer PTC cameras
12d ago
Rockwell Automation FactoryTalk Historian Site Edition
12d ago
AzeoTech DAQFactory
12d ago
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
12d ago
Mitsubishi Electric MELSEC iQ-F Series
12d ago
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
12d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
12d ago
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
14d ago
Rockwell Automation RSLinx
14d ago
Rockwell Automation FLEX I/O EtherNet/IP Adapters
14d ago
Rockwell Automation FactoryTalk Analytics PavilionX
14d ago
Rockwell Automation CompactLogix
14d ago
CISA Adds One Known Exploited Vulnerability to Catalog
14d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
15d ago
CISA Adds One Known Exploited Vulnerability to Catalog
18d ago
Yarbo Android/iOS Mobile Application and Cloud Infrastructure
19d ago
Naxclow IoT Platform
19d ago
Brickcom Cameras
19d ago
CISA Adds One Known Exploited Vulnerability to Catalog
19d ago
Siemens KACO Blueplanet Inverters
21d ago
Schneider Electric EcoStruxure Panel Server
21d ago
Schneider Electric Modicon Network Managed Switches
21d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
21d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
22d ago
CISA Adds One Known Exploited Vulnerability to Catalog
25d ago
NAVTOR NavBox
26d ago
Hitachi Energy MACH HiDraw
26d ago
Hitachi Energy ITT600 Explorer
26d ago
B&R PPT30 Operating System
26d ago
Hitachi Energy RTU500
26d ago
CISA Adds One Known Exploited Vulnerability to Catalog
27d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
28d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
28d ago
CISA Adds One Known Exploited Vulnerability to Catalog
29d ago
CISA Adds One Known Exploited Vulnerability to Catalog
32d ago
ABB EIBPORT
33d ago
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
33d ago
ABB Busch-Welcome 2 Wire Door Opener Actuator
33d ago
Fourth Frontier Frontier X Mobile Application, Frontier X2
33d ago
CP Plus 8 Ch. Network Video Recorder
33d ago
XCharge C6
33d ago
KMW CCTV Security Cameras
33d ago
MacGregor Voyage Data Recorder (VDR) G4e
33d ago
Schnieider Electric EcoStruxure Machine Expert HVAC
33d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
33d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
34d ago
ABB Terra AC
35d ago
ABB LVS MConfig
35d ago
ABB Ability Camera Connect
35d ago
Eppendorf BioFlo 320
35d ago
ABB AbilityTM Zenon Remote Transport Vulnerability
35d ago
ABB AC500 V2
35d ago
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
35d ago
CISA Adds One Known Exploited Vulnerability to Catalog
35d ago
CISA Adds One Known Exploited Vulnerability to Catalog
39d ago
ABB Terra AC Wallbox
40d ago
Hitachi Energy GMS600
40d ago
ABB B&R Automation Studio
40d ago
ABB B&R Automation Runtime
40d ago
ABB B&R PCs
40d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
40d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
41d ago
Kieback & Peter DDC Building Controllers
42d ago
Siemens RUGGEDCOM APE1808 Devices
42d ago
ABB CoreSense HM and CoreSense M10
42d ago
ScadaBR
42d ago
ZKTeco CCTV Cameras
42d ago
CISA Adds One Known Exploited Vulnerability to Catalog
46d ago
Siemens Siemens ROS#
47d ago
Siemens gWAP
47d ago
Siemens SIMATIC
47d ago
Siemens Ruggedcom Rox
47d ago
Siemens Ruggedcom Rox
47d ago
Siemens Simcenter Femap
47d ago
Universal Robots Polyscope 5
47d ago
Siemens Ruggedcom Rox
47d ago
Siemens Teamcenter
47d ago
Siemens Solid Edge
47d ago
Siemens SENTRON 7KT PAC1261 Data Manager
47d ago
Siemens Opcenter RDnL
47d ago
Siemens Ruggedcom Rox
47d ago
Siemens SIMATIC S7 PLC Web Server
47d ago
Siemens Industrial Devices
47d ago
Siemens SIMATIC
47d ago
Siemens SIPROTEC 5
47d ago
CISA Adds One Known Exploited Vulnerability to Catalog
47d ago
Software Bill of Materials for AI - Minimum Elements
49d ago
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
49d ago
Subnet Solutions PowerSYSTEM Center
49d ago
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities
49d ago
ABB AC500 V3 Multiple Vulnerabilities
49d ago
ABB Automation Builder Gateway for Windows
49d ago
Fuji Electric Tellus
49d ago
CISA Adds One Known Exploited Vulnerability to Catalog
53d ago
CISA Adds One Known Exploited Vulnerability to Catalog
54d ago
MAXHUB Pivot Client Application
54d ago
CISA Adds One Known Exploited Vulnerability to Catalog
55d ago
ABB B&R Automation Studio
56d ago
ABB B&R Automation Runtime
56d ago
Hitachi Energy PCM600
56d ago
Johnson Controls CEM AC2000
56d ago
ABB B&R PVI
56d ago
CISA Adds One Known Exploited Vulnerability to Catalog
60d ago
Careful Adoption of Agentic AI Services
60d ago
ABB AWIN Gateways
61d ago
ABB Ability OPTIMAX
61d ago
ABB PCM600
61d ago
ABB Edgenius Management Portal
61d ago
CISA Adds One Known Exploited Vulnerability to Catalog
61d ago
ABB Ability Symphony Plus Engineering
61d ago
ABB System 800xA, Symphony Plus IEC 61850
61d ago
Adapting Zero Trust Principles to Operational Technology
62d ago
NSA GRASSMARLIN
63d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
63d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
67d ago
SpiceJet Online Booking System
68d ago
Carlson Software VASCO-B GNSS Receiver
68d ago
Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera
68d ago
Milesight Cameras
68d ago
Defending Against China-Nexus Covert Networks of Compromised Devices
68d ago
Yadea T5 Electric Bicycle
68d ago
Intrado 911 Emergency Gateway (EGW)
68d ago
125 loaded
TL
The Last Watchdog
12d ago · 26 items
News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies
12d ago
AUSTIN, Tex., June 17, 2026, CyberNewswireŌĆōSpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enter...
News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk
12d ago
LONDON, June 17, 2026, CyberNewswire–Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report's headline finding is a divide inside the...
News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails
13d ago
LAS VEGAS, June 16, 2026, CyberNewswire–Aembit on Tuesday announced support for Copilot Studio, extending its identity and access management capabilities to Microsoft's enterprise AI agent platform. The integration, unveiled at Identivers...
News alert: GitGuardian adds endpoint protection as developer laptops become credential troves
13d ago
NEW YORK, June 16, 2026, CyberNewswire–GitGuardian announced today that it is introducing Developer Endpoint Protection, extending its secrets and non-human identity (NHI) security platform coverage to developer workstations. After 12 mon...
News alert: Varist announces AI-scale malware detection for healthcare and medical imaging
14d ago
REYKJAVIK, Iceland, June 16, 2026 — Varist today introduced its DICOM Detection Engine™, a specialized system designed to safeguard electronic health records (EHR) and picture archiving and communication systems (PACS) from all known ma...
News alert: Cloud security report finds fragmented tools widening the cloud complexity gap
19d ago
News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces
27d ago
FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential
28d ago
News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit
32d ago
GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet
34d ago
GUEST ESSAY: AI can speed up communication, but it can also weaken human connection
41d ago
News alert: Orchid Security study finds invisible identities now outnumber managed accounts
41d ago
MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack
43d ago
LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back
48d ago
FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread
49d ago
News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents
49d ago
News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market
55d ago
SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents
61d ago
GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control
63d ago
FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures
64d ago
News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category
69d ago
Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one
71d ago
News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security
75d ago
GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags
77d ago
News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk
81d ago
FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense
84d ago
26 loaded
M3
Microsoft 365 Blog
14d ago · 10 items
Copilot Cowork is now generally available
14d ago
Copilot Cowork is now generally available worldwide, bringing secure, AI-powered automation for complex enterprise tasks in Microsoft 365.
Introducing Microsoft Scout: Your always-on personal agent
27d ago
Microsoft introduces a new, always-on personal agent, Microsoft Scout, integrated across the Microsoft 365 apps you use every day.
Announcing the new Work IQ APIs
28d ago
Build enterprise agents with Work IQ APIs for Microsoft 365—bringing business context, tools, and secure, scalable intelligence into every workflow.
Introducing Microsoft 365 Business with Copilot: The new standard for small business
32d ago
Meet Microsoft 365 Business with Copilot—the AI-powered solution transforming how small businesses work, collaborate, and compete.
Introducing a new design for Microsoft 365 Copilot
33d ago
Copilot’s redesigned experience delivers faster performance, adaptive tools, and clearer AI-powered workflows to help you easily move from intention to outcome.
New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences
35d ago
Explore what's new in Copilot Studio, May 2026: computer-using agents are now available, plus redesigned workflows and Work IQ extensibility.
New and improved: Agent governance, intelligent workflows, and connected app experiences
49d ago
See what's new in Copilot Studio, April 2026: updates to workflows, more control over agent operations, and an expanded agent usage estimator.
Copilot Cowork: From conversation to action across skills, integrations, and devices
56d ago
Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you.
Microsoft 365 Copilot, human agency, and the opportunity for every organization
56d ago
Empower your organization with Microsoft 365 Copilot—AI that bridges human potential and business outcomes for the future of work.
Microsoft Agent 365, now generally available, expands capabilities and integrations
60d ago
We’re announcing the general availability of Agent 365, plus previews of new capabilities to discover and manage shadow AI agents. Learn more.
CY
cybersecurity
18d ago · 1867 items
Any solutions we can use?
18d ago
Possible targeted attack
19d ago
RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline
19d ago
Facebook messenger to text
19d ago
Managing Solution Agents
19d ago
Nottingham University data breach affects over 450,000 students
19d ago
SWGs that support 3rd party external DNS resolver
19d ago
Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers
19d ago
Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG
19d ago
Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch
19d ago
Phishing awareness training resulting in ignoring company comms?
19d ago
How are you analyzing Android malware nowadays?
19d ago
Hackers Exploit Langflow Vulnerability for Remote Code Execution
19d ago
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research
19d ago
NEED SOME GUIDANCE
19d ago
Help setting up local encryption on my pc
19d ago
Agentic AI on Cybersecurity
19d ago
DoD 0-days Typically Come Down to Authorization Failures
19d ago
HDD
19d ago
Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets
19d ago
How can we test the firmware code/images security?
19d ago
20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004
19d ago
GitHub announces npm security changes to tackle supply-chain attacks
19d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
19d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
19d ago
What is the difference between Regular TLS and Mutual TLS?
19d ago
Every employee's password was stored in a single Excel file
19d ago
npm v12 is changing how dependencies are installed to reduce supply-chain risk
19d ago
Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia?
19d ago
How good Microsoft Defender for storage?
19d ago
GreatXML bitlocker bypass vulnerability
19d ago
Struggle
19d ago
Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications?
19d ago
Wiz launches Cloud Security Job Board
19d ago
Physical Project Ideas
19d ago
How can I get into cybersecurity while studying Information Systems Engineering?
19d ago
Cloud Security job board
19d ago
Continuous learning
19d ago
Angry bug hunter with Microsoft beef drops new Windows 0-day
19d ago
Mid-30s, stuck in web pentesting, and wondering what to do ?
19d ago
Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM
19d ago
Is Microsoft Purview really secure when using Copilot?
19d ago
Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature?
19d ago
Nee academic references for Hashcat's 'Next Big Bang' log
19d ago
CISA released BOD 26-04: A new federal government vulnerability management strategy?
19d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
20d ago
added Mac support to my corporate hacking sim. Demo now available on Steam
20d ago
Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte)
20d ago
Students' data taken in major University of Nottingham cyber-attack
20d ago
Has unmanaged external file sharing ever burned you?
20d ago
Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers
20d ago
Need feedback on my presentation
20d ago
Compensating controls besides admin credentials being needed to download software on employee endpoints
20d ago
OpenSSL PKCS#7 CVE-2026-45447
20d ago
Presentation Question
20d ago
How to Stay Ahead of Deepfake Evolution in 2026
20d ago
France’s Government Messaging App Tchap Got Breached
20d ago
Where's the fix for MiniPlasma?
20d ago
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
20d ago
Internships
20d ago
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
20d ago
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
20d ago
Looking for a Reliable Cybersecurity Provider for a School in North Sydney
20d ago
Early Operational Visibility
20d ago
how are you actually managing ai agents in production?
20d ago
Al app builders: How are you handling security questionnaires when selling your product?
20d ago
[ Removed by Reddit ]
20d ago
How are all of doing with THE AI model thats big news currently??
20d ago
Skill to Scan your Codebase
20d ago
Miasma-style supply chain attacks
20d ago
FCaptcha v1.12: Catching AI Agents That Drive Real Browsers
20d ago
Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones
20d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
20d ago
AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say
20d ago
Huntress Stack (MS Defender or SentinelOne)
20d ago
META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT
20d ago
FBI is announcing Operation Riptide
20d ago
ServiceNow confirmed some customer instances were breached.
20d ago
Which are some of the best Cybersecurity / OT Security events that happen in GCC?
20d ago
DF/IR Community
20d ago
Chaotic Eclipse's new RoguePlanet
20d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
20d ago
Thoughts on Automated Compliance?
20d ago
A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available
20d ago
North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says
20d ago
Microsoft has released a patch for the bitlocker bypass
20d ago
Please advices
20d ago
soc analyst l1
20d ago
Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow
20d ago
Looking to move off KnowBe4, what are people actually using these days?
20d ago
Too Many Certs, Not Enough Experience — What’s the Best Next Step?
21d ago
Authenticating ARP and NDP
21d ago
Does anyone use rule feeds in 2026?
21d ago
Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations!
21d ago
Need a vm for practice
21d ago
Tips/Tricks to WFH as a SOC Analyst?
21d ago
Cybersecurity statistics of the week (June 1st - June 7th)
21d ago
Where can GRC folks learn practical AppSec / DevSecOps without going full engineer?
21d ago
I almost got “onboarded” into a malware campaign disguised as a job opportunity.
21d ago
University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model
21d ago
AI Blocklist - help
21d ago
Protecting AI workloads on Linux servers
21d ago
Exposing DoNex Ransomware Secrets with Malcore!
21d ago
What are the different Disaster Recovery scenarios your teams have tested on?
21d ago
someone actually leaked the Miasma supply chain attack toolkit source code on github
21d ago
WinGet - Code Execution, Persistence and Detection Strategies
21d ago
Ransomware attack shuts Illinois high school until Wednesday
21d ago
Ideas for demo
21d ago
Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please?
21d ago
Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares.
21d ago
Physical attack device
21d ago
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
21d ago
IT GRC News?
21d ago
Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again
21d ago
Shifting L7 validation to the edge to stop DB resource exhaustion?
21d ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
21d ago
EC Council CEH exam advice
21d ago
About NPower vs PerScholas
21d ago
Looking for a vulnerability to learn
21d ago
From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk
21d ago
Bad USB through charger?
21d ago
Recommendations for Discord community for latest AI security products
21d ago
Vulnerability Summary for the Week of June 1, 2026
21d ago
Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas
21d ago
I feel like ive lost my passion to tinker after 6 years in the industry, anyone else?
21d ago
I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples
21d ago
really need help with project ideas for MSc
21d ago
Which Course for an almost-complete noob? (SANS.edu)
21d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
21d ago
For the 2nd time in weeks, Microsoft packages laced with credential stealer
21d ago
Iran Signed a Ceasefire — Its Hackers Didn't
21d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
21d ago
DSPM étude marche
21d ago
CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file
21d ago
AppSec / Pentesting job market in Canada for experienced overseas applicants?
21d ago
Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients.
21d ago
Automation Playbooks - which ones would you not want to live without?
21d ago
Is it necessary/important to Hash and salt API Keys for a strictly internal use tool?
21d ago
Need review on the OMS Cybersecurity program from Georgia Tech?
21d ago
If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk
21d ago
2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years
21d ago
How do you close an alert
21d ago
What cybersecurity certifications are great value for money?
21d ago
Boxes for CPENT
21d ago
SIEM: is it "SIM" or "SEEM"
21d ago
I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included)
21d ago
How justdeleteme and justgetmydata work?
21d ago
I need help - PCI DSS 4.0 requirement 11.6.1
22d ago
How are you learning agent pen testing?
22d ago
Cyber security intern
22d ago
Meta to take legal action against Israeli spyware company NSO
22d ago
Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit
22d ago
What's the best way to alert companies of a Glassworm copycat?
22d ago
How To Verify If A Site Is Legit?
22d ago
What is Flaresolverr
22d ago
Research: defenders using generative AI to simulate malware variants before they exist in the wild
22d ago
How are regulated orgs actually letting engineers use Claude Code / Copilot?
22d ago
Cyber security expo Manchester
22d ago
Remote Hiring Opened the Talent Pool — and the Fraud Surface
22d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
22d ago
What certs should I do during summer of 11th grade?
22d ago
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
22d ago
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine
22d ago
Oxford University discloses data breach after careers platform hack
22d ago
Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing
22d ago
Got this message from “SimBoss”
22d ago
PKCS12 Golang fork
22d ago
Malware Insights: Miasma Campaign
22d ago
73 Microsoft GitHub repositories impacted by Miasma malware
22d ago
[Honeypot Research] Looking for volunteers to test telemetry/logs
22d ago
What is the condition of Bug Bounty program in the era of AI.
22d ago
Opening a cloned repo is no longer safe
22d ago
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
22d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
22d ago
Google Colab CLI opens runtimes to Claude Code and Codex
22d ago
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
22d ago
The AI governance gap no one is talking about: deployment-stage accountability
22d ago
Free Study Resources for Comptia Cysa+
22d ago
Mentorship Monday - Post All Career, Education and Job questions here!
22d ago
Hi there
22d ago
Final risk-based IT Audit interview round with Director and have no experience. Please help!
22d ago
Needed help
22d ago
[ Removed by Reddit ]
22d ago
Career advice
22d ago
PhD in cyber Security
22d ago
Built a password guessing game. Almost everyone stuck in level 5.
22d ago
OSINT (SOCIAL MEDIA)
22d ago
Beginner KQL project
22d ago
Question about WORM and encryption
22d ago
Update:Certified cyber security
22d ago
Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental
23d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction)
23d ago
Malware that survives reinstalling the BIOS and OS
23d ago
Am I overthinking the x86 compatibility issues? how much friction am I actually facing?
23d ago
Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure
23d ago
Managing Microsoft Identity Is More Complicated Than It Looks
23d ago
My work email got subscribed to a bunch of israel newsletters
23d ago
Shadow AI
23d ago
Rate limiting is not enough. What else can I use?
23d ago
How To Avoid Potential Malware From Transferring To New Laptop
23d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
23d ago
Can't decide.
23d ago
looking for partners
23d ago
My edge is changing into bing when I search something
23d ago
Cybersecurity reality check
23d ago
[ Removed by Reddit ]
23d ago
Information Management
23d ago
IronWorm Malware
23d ago
Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh?
23d ago
Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh?
23d ago
Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager
23d ago
Is a separate “clean” S3 bucket actually a security boundary for uploaded files?
23d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
23d ago
PenTest+ Exam
23d ago
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
23d ago
Looking for guidance
23d ago
Before you attempt any OffSec certification, read what just happened to me
24d ago
Reporting Metrics for Management
24d ago
got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time
24d ago
Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried
24d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
24d ago
AI Security Certificates
24d ago
Guys is bug bounty dead?
24d ago
How are folks making it in bug bounty?
24d ago
How useful is it to require at least one uppercase letter in a password?
24d ago
Cyber security ! Is no more ?
24d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
24d ago
Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months
24d ago
Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories
24d ago
How to train employees to feel when something's off?
24d ago
ALERT OVERLOAD
24d ago
CTO at NCSC Summary: week ending June 7th
24d ago
A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled
24d ago
Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub
24d ago
AppSec Engineer Interview Stories
24d ago
[OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps.
24d ago
Is there a safe way to continue using (unsupported) Windows 10?
24d ago
Is Splunk suitable for smaller Enterprises?
24d ago
Has anyone else had MFA prompt fatigue issues with users?
24d ago
Data Scrubbing from Databases
24d ago
Best Certificates?
24d ago
Rant
24d ago
New York passes data center moratorium and consumer protections as environmental, and housing proposals stall
24d ago
Cyber attackers have a new favorite, the browser
24d ago
Looking to get into cybersecurity in web3
24d ago
Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests
24d ago
Should i use email 2fa or only auth and phone number?
24d ago
Can I break into cybersecurity with a white collar felony?
24d ago
Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale
24d ago
How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time?
24d ago
What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent?
24d ago
How Hard is This
24d ago
Installed Fake Codex hidden as a google site
24d ago
Virustital scan result help
24d ago
CrowdStrike Turned an AI Wave Into Its Best Quarter Ever
24d ago
Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions?
24d ago
I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now
24d ago
Being a Security Engineer? Which AI-powered tools are you using on a daily basis?
25d ago
Over 900 US gas station tank gauge systems exposed to attacks
25d ago
Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person
25d ago
SIEM is broken in the AI agents era
25d ago
Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected
25d ago
Phantom Gyp npm Worm Abuses node-gyp Build Hooks
25d ago
Certified cybersecurity ISC2
25d ago
Help studying for OSCP
25d ago
The current state of Threat Intelligence Tooling
25d ago
Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware
25d ago
We tested offensive AI agents against deception technology
25d ago
A matter that I have been losing my sleep over
25d ago
Any experience with Rootly or incident.io for cyber incident management?
25d ago
CTIA Study Resources & Preparation Advice?
25d ago
Black hat uk vs brucon
25d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
25d ago
NIS2 hits railway hard
25d ago
I need help guys… :(
25d ago
Question from the Seniors
25d ago
China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware
25d ago
what certs have u seen in ai security related job posts ?
25d ago
How is the Security Architecture / Strategic IT Security process structured in your organization?
25d ago
What's happening in cybersecurity job market in US and Europe these days?
25d ago
Has any of you pivoted from GRC to CTI?
25d ago
Up-date-list of cybercrime types?
25d ago
What else should I learn to build a strong cybersecurity foundation?
25d ago
Hackerone interview
25d ago
Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix
25d ago
Testing URL Rewriting?
25d ago
Got an internship in IAM with no qualifications and no soft skills
25d ago
Work Hours of DFIR/Cloud Security vs Pentest
25d ago
Narcissistic Tech Leader....
25d ago
Anyone else's firewall logs just explode after midnight?
25d ago
I'm replacing myself.. at least the boring parts
25d ago
Anyone else dealing with these phantom login attempts from China?
25d ago
Best way to fully clear windows and set everything up securely (pc, accounts etc)
25d ago
IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks
25d ago
Soc analyst
25d ago
Do companies actually require cybersecurity insurance
25d ago
Uncommon/Unusual CrowdStrike Alerts
25d ago
Cyber analyst: law firm or bank
25d ago
best free av and how do i properly setup passwords?
25d ago
Five 9 Vulnerability
25d ago
CVE Lite CLI closes dependency gap — but won't stop modern threats
25d ago
Scope change
25d ago
We just stopped a social engineering attack on our service desk. Here’s how it played out.
25d ago
What is the most underestimated cybersecurity risk right now?
25d ago
Update: Company is paying for any certification, which should I obtain? Except Sans
26d ago
New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification
26d ago
Anyone else's firewall vendor docs a total nightmare?
26d ago
Your opinions about a learning style
26d ago
Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks
26d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
26d ago
Anyone else see their firewall logs just explode after a cloud update?
26d ago
Are certifications necessary to get a job in cybersecurity?
26d ago
Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass)
26d ago
Is retyping and translating textbooks too inefficient for CS/Cybersecurity?
26d ago
Free Microsoft Enterprise Security Assessment: Worth It
26d ago
How are organizations preparing for AI-generated phishing attacks?
26d ago
Inside the race to adapt to an AI-powered security world
26d ago
127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For
26d ago
Microsoft blames unexpected Windows driver updates on caching issue
26d ago
Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance)
26d ago
Your CPU model leaks through the browser via WASM timing differences
26d ago
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
26d ago
Security Engineer 2 interview at Amazon coming up - What to expect?
26d ago
A researcher spent $1,500 testing if LLMs could hack a vulnerable app
26d ago
Help with university internship
26d ago
Are MCP servers becoming the next API security nightmare?
26d ago
What's the cybersecurity lesson you learned the hard way?
26d ago
ISO 27001 Surveillance audit vs Full recertification
26d ago
How important it is to get paid Cybersecurity certificates ?
26d ago
Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process
26d ago
Soc to Architecture
26d ago
Does "example file vulnerability" exists?
26d ago
VS code forces 2 hour cool down for most integrations.
26d ago
Company laptop isolated after Brave/Tor alert - should I be worried?
26d ago
Does anyone know how to send false positive to SOCradar ? virus total
26d ago
Looking for people to team up for Bug Bounties & CTFs
26d ago
Signal Without Smartphone
26d ago
I found a trojan on my pc and now im scared my private calls got leaked
26d ago
Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests
26d ago
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
26d ago
How do you change users behavior through awareness training?
26d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
26d ago
Safe Rust API for wolfSSL/wolfCOSE
26d ago
Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma)
26d ago
AMD GPU Users might be compromised
26d ago
[ Removed by Reddit ]
26d ago
Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information
26d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
26d ago
[CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF
26d ago
how to get good at cyber security?
26d ago
Anyone use CrunchAtlas?
26d ago
Prompt monitoring laughs
26d ago
Malicious Payload in ai-sdk-ollama npm Package
26d ago
Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24)
26d ago
what the HELL is dsztfso?
26d ago
Yubikey Alternative....?
26d ago
Hiring
26d ago
CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing
26d ago
Certification Advice
26d ago
Question about Linux kernel TLS ULP disclosed June 2 to oss-security
26d ago
An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this?
26d ago
How to Rob a Data Center (new article on data center physical security)
26d ago
US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server
26d ago
Is it worth taking the EC councils masters program?? Are they legit /2026
26d ago
Mid-level AppSec engineers: what do you actually study to prep for interviews?
26d ago
Company is paying for any certification, which should I obtain?
26d ago
Trusting Microsoft with your offensive security repos
26d ago
Automated Fault Injection Attack Framework
26d ago
Physical Biometric device as a security measure..??
26d ago
Cybersegurança
26d ago
Started Learning Cybersecurity
26d ago
InfraGard Application - Seeking Help | Student
26d ago
Orientación en Ciberseguridad
26d ago
Anthropic's coordinated vulnerability disclosure dashboard
26d ago
Hands Free: What LLM Driven Vulnerability Research Looks Like
26d ago
Real time Cybersecurity failures regarding Quantum computing/cryptography
27d ago
🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It.
27d ago
A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out.
27d ago
CISA warns of active attacks exploiting Android, Linux bugs
27d ago
Found some open ports on a govt site, should i report or stay quiet?
27d ago
What is a good way to keep track of passwords for programs that don't support password managers?
27d ago
Cybersecurity statistics of the week (May 25th - May 31st)
27d ago
ASN Emissions Index. Networks ranked by how much noise they create on the internet.
27d ago
Have you sold cve before?
27d ago
i want to become a pentester, but i don't know how to
27d ago
The OT Security Problem Nobody Wants to Own
27d ago
Don't Take Wednesday Off When You Manage Vulnerabilities
27d ago
I finally finished a production version after 4 yrds
27d ago
Support role pivot to cloud security
27d ago
How do you manage your passwords?
27d ago
Mad rush to produce AI driven slop
27d ago
O Tails é seguro para acessar links suspeitos?
27d ago
Cyber Essentials plus + "legacy" network segments
27d ago
Insight for OPSWAT deep CDR
27d ago
Android vs iOS
27d ago
ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account
27d ago
Security Audits at an MSP
27d ago
[ Removed by Reddit ]
27d ago
Passkey registration breaks after moving off localhost..
27d ago
Does your team hire fresh AI engineer who doesn't know anything about Security operations?
27d ago
UARs for Equation (banking system)
27d ago
IoT pentesting cert
27d ago
Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations
27d ago
Experience with Tac Security
27d ago
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
27d ago
Found Security Vulnerabilities in my university website
27d ago
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence
27d ago
AI - Threat to the CyberSec Industry?
27d ago
Built a honeypot platform to catch lateral movement. How are you guys detecting this?
27d ago
How should small SaaS teams safely answer customer security questionnaires?
27d ago
Can AI Do Intelligence Analysis? Apparently Not.
27d ago
PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model
27d ago
Regarding Certified Ethical Hacker (CEH Practical) exam
27d ago
Asking for advices on pursuing first CERTIFICATE
27d ago
I opened my own company and I can't find clients!
27d ago
ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter
27d ago
Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU?
27d ago
Anyone knows Quad9 dns ?
27d ago
I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ?
27d ago
Greynoise swarm
27d ago
SecOT+ certification for free
27d ago
How is the state of the job market for mid-level security engineers?
27d ago
Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things
27d ago
WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total
27d ago
Laid off from TPRM job - need help on the future of my career
27d ago
Anyone compared RoboShadow vs ConnectSecure for vulnerability management?
27d ago
Any one send vulnerability to MITRE?
27d ago
Need advice for a 30 min Security Apprenticeship interview
27d ago
UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS
27d ago
Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match
27d ago
Virustotal API as private data source
27d ago
Account Number Security Flaw
28d ago
Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning?
28d ago
A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth
28d ago
[ Removed by Reddit ]
28d ago
[ Removed by Reddit ]
28d ago
Phishing simulation platform
28d ago
Just task about OSI model
28d ago
Need help improving DNS Spy from a security tool angle
28d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
28d ago
Oracle's first monthly patch update just dropped 77 CVEs.
28d ago
Cleaning up after a legacy service account breach. How are you handling automated secrets discovery?
28d ago
Airbus digital apprenticeship
28d ago
Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities
28d ago
Google fixes one actively exploited Android zero-day, 124 flaws
28d ago
Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force
28d ago
Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis?
28d ago
Security Architects who who actively use modelling - What's your approach?
28d ago
PAN-OS authentication bypass bug added to list of exploited vulnerabilities
28d ago
I have extreme anxiety about being hacked
28d ago
Fresher
28d ago
Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach
28d ago
Career advice needed!
28d ago
GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
28d ago
Google sr. security engineer interview
28d ago
Is offensive AI actually changing cybersecurity, or are we overestimating the impact?
28d ago
Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave
28d ago
is emerald chat safe?
28d ago
Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ?
28d ago
ClickJack in the wild
28d ago
Thoughts on A.I assisted Malware Analysis?
28d ago
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
28d ago
What articles do you use for cybersecurity news? (2026)
28d ago
Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider?
28d ago
Roadmap and Training Recommodation
28d ago
Les anti-triche de niveau noyau et leur risque de sécurité
28d ago
Asked to Send Sensitive Documents via MMS
28d ago
SC-200 compared to CC (isc2)
28d ago
Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now
28d ago
Looking to move off KB4, what are people actually using these days?
28d ago
Got my Security+. What's next?
28d ago
Vulnerability Summary for the Week of May 25, 2026
28d ago
Malware
28d ago
Alternative Search Engine to Utilize in 2026?
28d ago
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
28d ago
Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild
28d ago
Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers
28d ago
AI compliance
28d ago
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
29d ago
Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains?
29d ago
MacBook or Windows Laptop for Cybersecurity
29d ago
What's the most creative MFA bypass you've seen?
29d ago
Research Notes from Building a Windows Event Log Hunting Workflow
29d ago
How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ??
29d ago
Free AI tools for TPRM?
29d ago
incomplete phone number from togo, need help reporting to police
29d ago
NPM packages from RedHat Compromised
29d ago
Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts
29d ago
SOC Analyst working towards Threat Intelligence
29d ago
Is XSS possible through PDFs?
29d ago
The Next AI Governance Failure Won’t Be the Model
29d ago
Microsoft MFA Is Down Again
29d ago
Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927)
29d ago
Computer logic or Science
29d ago
I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for?
29d ago
What C2s Are You Using
29d ago
PNPT Exam
29d ago
What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification?
29d ago
Any appsec engineer working in fortune 500?
29d ago
I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next
29d ago
Anyone transition from AWS Data Center Operations to InfoSec?
29d ago
I think my account got hacked but it's weird
29d ago
current market for detecting deepfakes?
29d ago
Worried about friend being doxxed on doxbin
29d ago
how to shift from a service based company to a product based one in cybersecurity ?
29d ago
Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA
29d ago
Claude AI user data directory exfiltration via malicious npm package
29d ago
Bitdefender blocking amd stuff? False positive or?
29d ago
Mentorship Monday - Post All Career, Education and Job questions here!
29d ago
did they have my password?? what triggers this specific email??? instagram HELP.
29d ago
ATTENTION: Dashlane may have been breached. (Password manager).
29d ago
Norton blocked a “malicious script”?
29d ago
Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts
29d ago
Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive.
29d ago
I wrote about the 5 biggest threats in 2026, curious what this community thinks.
29d ago
MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce?
29d ago
Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions?
29d ago
NetworkChuck
29d ago
LLM for creating phishing tool
30d ago
Why are we still treating IAM like a compliance checkbox?
30d ago
Polyfill pop up?
30d ago
SecAI+ difficulty question
30d ago
Could you guys give an honest feedback to a completely automated ssrf attack tool?
30d ago
tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me
30d ago
Microsoft Joined the DMARC Club
30d ago
Help.
30d ago
Vibe Coding Security
30d ago
Looking for a Company to Partner With
30d ago
Best reporting tools?
30d ago
What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months)
30d ago
How Can Polyfill.io Still Act Maliciously?
30d ago
Need THM voucher code for cheap? Any known seller?
30d ago
Ghost passwords?
30d ago
Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not.
30d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
30d ago
Anyone else having Chatgpt Strikes / Violations while learning cybersecurity?
30d ago
Working at Cisco, worth it?
30d ago
Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice
30d ago
Are you pen testing AI Agents?
30d ago
Question of android malware
30d ago
External attack surface: how are you correlating DNS, SSL, and IP reputation today?
30d ago
how do i properly setup 2fa and bitwarden?
30d ago
Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC)
30d ago
i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested?
30d ago
Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever?
30d ago
Can Steam Cloud Files Transfer Malware
30d ago
Questions for the cloud security engineers
31d ago
Thoughts on this as a starter and doing bug bounty on the side
31d ago
How are new SC-200 candidates practicing labs without an E5 Developer tenant?
31d ago
Getting OTP spammed from every app and website I've ever used. Should I be worried?
31d ago
A browser tool for checking contractor insurance certificates
31d ago
Am I getting screwed?
31d ago
SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers
31d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
31d ago
CTO at NCSC Summary: week ending May 31st
31d ago
BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship
31d ago
Need suggestion
31d ago
[INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety)
31d ago
Was Dave Bittner interviewing an AI?
31d ago
CTF for complete beginner
31d ago
Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques?
31d ago
AI-Era Cyber Risk Standards
31d ago
BEC Victim - Attacker replied inside a real email thread using a lookalike domain
31d ago
Question for those who transitioned from remote to work from anywhere
31d ago
Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors
31d ago
Do you enjoy what you do or do you wish you could go back in time and change it?
31d ago
Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber?
31d ago
For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year?
31d ago
Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ?
31d ago
Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years?
31d ago
Botnet of more than 17 million devices dismantled
31d ago
Exposed credentials on logs
31d ago
What do you think is the biggest cybersecurity risk for small businesses in 2026?
31d ago
Wanted to shift to cloud security, but have some questions
31d ago
Zero Trust is Overrated? Navigating the Complexity
31d ago
Test API post with flair
31d ago
Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications
31d ago
How Do You Handle the Massive Amount of Information in the CPTS Path?
31d ago
Help an upcoming cybersecurity engineer!
32d ago
Repeated Microsoft MFA attempts even after password change
32d ago
What Is Device Intelligence and How Does It Stop Fraud?
32d ago
[FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE)
32d ago
IBM commits $5 billion to secure open-source software
32d ago
Structuring an AI-Assisted Pentesting Homelab for a Final Year Project
32d ago
Are teams actually monitoring LLM traffic in production environments?
32d ago
How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA)
32d ago
Raspberry pi
32d ago
What is the biggest obstacle to using AI safely in a company?
32d ago
Advice going forward
32d ago
MCP Firewall help
32d ago
I wanted to shift to security but people told me the market is extremely bad, is that true?
32d ago
Best Personality Type/Traits for Working in Cyber Security
32d ago
A fake freelance job interview almost installed malware on my PC
32d ago
Is there a viable career path here or am I just being delusional?
32d ago
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
32d ago
How do enterprises actually prevent developers from exfiltrating source code?
32d ago
I have a datastealer malware
32d ago
Dúvida de carreira.
32d ago
Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace
32d ago
Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated
32d ago
is SIEM really needed here ?
32d ago
Decompiled an app, found a bunch of secrets, what now?
32d ago
Can someone give me a correct method for learning reverse engineering?
32d ago
Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months
32d ago
GRC Advise
32d ago
[ Removed by Reddit ]
32d ago
Did something happen to haveibeenpwned? Any alternatives?
32d ago
RAT SUSPECTED
32d ago
How do people afford certificate s?
32d ago
I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed?
32d ago
Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
32d ago
Phone Forwarding
32d ago
Opinions on running Full Microsoft E5 Security Stack
32d ago
Claiming "XDR"
32d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
32d ago
Microsoft security
32d ago
Need help regarding building a home lab
32d ago
Should I turn on passwordless accounts for all my Microsoft accounts?
32d ago
Transitioning from AWS Data Center Operations to Security Engineering
32d ago
Probably the wrong place.
32d ago
What after IT helpdesk?
32d ago
How are you security-testing API changes before production without slowing CI/CD?
32d ago
Are we trusting update repos or are you all extra paranoid now as well?
32d ago
Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops
32d ago
Prevent supply chain attacks
32d ago
Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems
32d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
32d ago
Hackers are trying to steal Signal users' backups in new wave of phishing attacks
32d ago
Incident Response Testing Preparation
32d ago
Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference
32d ago
[Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥
32d ago
3rd Party NFC cards.. secure?
32d ago
Vulnerability Management Tickets & SLA
32d ago
Defending at Machine-Speed: Building AI Threat Readiness
32d ago
AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved
32d ago
HEAD request body processing leading
32d ago
Malicious npm Package Stole Files From Claude AI User Directory via GitHub
32d ago
Does anyone have an app like substack to keep being updated and engaging within the cyber domain?
32d ago
What’s an attack vector people massively underestimate in 2026?
33d ago
We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7
33d ago
A Deeper Look at GLASSWORM's Solana Variant
33d ago
Calling Cyber Security Beginners
33d ago
Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis
33d ago
built something for ai agents, ended up looking a lot like classic appsec
33d ago
Is Gophish still usable in 2026?
33d ago
Microsoft vs Chaotic Eclipse: three zero-days now actively exploited
33d ago
what do you think
33d ago
Why would be clicking a website, redirect me?
33d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
33d ago
Writing cybersecurity policies is a waste of time
33d ago
Raising the Cybersecurity Stakes: Ante up for the Agentic Era.
33d ago
Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it.
33d ago
[ Removed by Reddit ]
33d ago
Released: Dataforge Honeypot
33d ago
Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
33d ago
CEH-free
33d ago
Hottest cybersecurity open-source tools of the month: May 2026
33d ago
Preparation tips for CPENT
33d ago
How do you handle AI tools in your organization?
33d ago
I think i got scammed anybody can help me with that
33d ago
New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo
33d ago
Is it safe to have passwords copied to clipboard on IOS temporarily?
33d ago
Developers working on anti-fraud systems deserve more credit
33d ago
My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst
33d ago
Security awareness training for AI heavy smb workflows?
33d ago
Minimum Requirements for Helpdesk Role ?
33d ago
Reddit spear phishing
33d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
33d ago
What to do
33d ago
What resources would you recommend for studying cysa+
33d ago
Provenance of Data
33d ago
Websites have a new way to spy on visitors: analyzing their SSD activity
33d ago
12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal?
33d ago
Russian Art Teacher - Hinder Security Clearance?
33d ago
EDR/MDR Vendor Questions
33d ago
Cybersecurity as a Highschooler?
33d ago
New department created, would love your input
33d ago
OWASP Vienna - anyone going?
33d ago
Interview with Upstart
33d ago
18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber.
33d ago
Is cloud security engineer viable with my current position?
33d ago
Cloudflare Access users: what would actually make JIT useful for you?
33d ago
eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels
33d ago
Questions regarding Ubuntu 24 LTS hardening
33d ago
Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho.
33d ago
Honest question about OT Security Engineer work life in India
33d ago
Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning)
33d ago
AI Security
33d ago
Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor
34d ago
🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents
34d ago
Building Detection Engineering on AWS from scratch — roast my plan
34d ago
Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance
34d ago
I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA.
34d ago
Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning
34d ago
Final Year Project: Looking for non-generic IAM project ideas that solve real problems
34d ago
GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled.
34d ago
Breaking out of IT Helpdesk - how?
34d ago
A year in Cybersecurity — Where Do I Go From Here?
34d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
34d ago
22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber
34d ago
FBI: Silent Ransom Group Turns to IT Support Ploy
34d ago
How do machine builders track Siemens/Rockwell security advisories?
34d ago
GlassWorm Developer Supply-Chain Botnet Takedown
34d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
34d ago
Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV
34d ago
Got cybersec work what next ?
34d ago
Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables
34d ago
Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers
34d ago
Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing?
34d ago
GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)
34d ago
nightmare eclipse is probably French here is why
34d ago
Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines
34d ago
Measuring performance of JA4/JA4H AI Model
34d ago
What things are you really focused on this year?
34d ago
Hypothetical EDR spoofer
34d ago
ISO 27001 Audit Stage 1
34d ago
Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.
34d ago
Looking for Hacker Friends to Learn☺️
34d ago
Comptes Instagram et Facebook piratés et désactivés
34d ago
How to safely disinfect a USB stick from potential malware files?
34d ago
Is anyone else concerned about how quickly AI is outpacing cloud security?
34d ago
What's a CyberSecurity job like?
34d ago
Microsoft Live credential stuffing
34d ago
I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this?
34d ago
Security architects- summarize your responsibilities and role
34d ago
Finding Work in OSINT
34d ago
State of SDLC Security 2026
34d ago
Reported to police for coding html
34d ago
[Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling)
34d ago
I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project
34d ago
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover
34d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
34d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
34d ago
Breaking GROK'S DEFENSES to make it HACK Real Public Websites
34d ago
GitHub Actions Cache Poisoning is eating open source
34d ago
Nightmare-Eclipse has also been banned on GitLab :DD
34d ago
Do we still have time before we are in the Age of the movie "Minority Report"? ↓
34d ago
SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file
34d ago
What Software Supply Chain, Water Filters, and Power Grids Have in Common
34d ago
QA engineer trying to move into AppSec — does this plan hold up?
34d ago
Is work from anywhere really impossible to find??
35d ago
Cybersecurity statistics of the week (May 18th - May 24th)
35d ago
Engineering a Post Quantum Fortress Inside the Citadel Archite
35d ago
Cyber Security Analyst
35d ago
Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance
35d ago
Two layer email security tool thesis
35d ago
When OTP rate limiting fails: OLX account takeover with persistent sessions
35d ago
Entra ID sessions revoke
35d ago
Anyone who attended GPCSSI before? Need some clarification
35d ago
Lost on my career path.
35d ago
EU-based folks: external pentest vs mandatory data/security training?
35d ago
help needed from experienced people
35d ago
How do you evaluate whether a privacy service is actually privacy-respecting?
35d ago
Which one Intellipaat or coursera which one to choose
35d ago
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
35d ago
India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic?
35d ago
Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs.
35d ago
Did anyone pass the SC-200 certificate recently?
35d ago
Honeypot
35d ago
passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account
35d ago
Career in IAM as a fresher
35d ago
CISA orders feds to patch actively exploited Drupal vulnerability
35d ago
Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure
35d ago
GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
35d ago
Cyber security tool
35d ago
Saw this tool and it has potential
35d ago
🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs
35d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files
35d ago
Follow up : showing Claude install random pacakage in its vm instance without asking or prompting
35d ago
¿Is safe?
35d ago
Need help
35d ago
What is the best tool for masking in kali
35d ago
What are the best tools other than ghostTracker?
35d ago
TrapDoor Cross-Ecosystem Crypto Stealer Campaign
35d ago
Follow up : Steal Your Files Claude AI installing package because internet say so
35d ago
New to Cybersecurity: Looking for general advice & help with Nmap
35d ago
Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal
35d ago
Looking for tech role references
35d ago
How do you balance Paw?
35d ago
I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity.
35d ago
From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security
35d ago
Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February
35d ago
What Companies are Legit?
35d ago
start learning cybersecurity from scratch
35d ago
Follow-up: measuring LLM-agent failures with replay evidence
35d ago
Follow-up: measuring LLM-agent failures with replay evidence
35d ago
WhatsApp users on alert after hacker drops massive dataset
35d ago
17 years old going into CS — what certs should I start going after now?
35d ago
i want to hire an osint expert
35d ago
Open University pros/cons
35d ago
How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection?
35d ago
Career in IAM as a fresher
35d ago
Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo
35d ago
Need Advice
35d ago
Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all?
35d ago
Someone from Germany on iOS keeps trying to login to my MSFT account
35d ago
AI cautionary tale...
35d ago
AI powered red vs blue teaming
36d ago
Starting a security analyst student apprenticeship next week, need advice
36d ago
Why CVE Does Not Work for AI Agents, but AVE?
36d ago
SC-200 or Security+ — which actually helps land a security title
36d ago
How about AI having access to your hard drive.
36d ago
How a Date Tag Hijacks macOS via ExifTool
36d ago
Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools
36d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
36d ago
Built a tiny daily cyber puzzle game during evenings/weekends
36d ago
Crypto4A launches quantum-safe rival to AWS Secrets Manager
36d ago
ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why.
36d ago
Cyber Sec project
36d ago
CySA+
36d ago
Anyone tried Morgancyberhelp ?
36d ago
As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free
36d ago
Why are most of the dfir tools built to be used in windows
36d ago
OnlyFans mega leak reveals 340M user records, hackers claim
36d ago
Perplexity BumbleBee
36d ago
Cisco patches critical 10.0 flaw in Secure Workload APIs
36d ago
Stalker has my phonenumber
36d ago
Need some guidance
36d ago
Are you currently allocating budget to services that remove executive PII from B2B data brokers?
36d ago
About CEHv13 book
36d ago
We open-sourced the most dangerous part of our security startup on purpose.
36d ago
Which conference(s) result in the most people finding jobs?
36d ago
My discord account has been hacked second time even after enabling two factor authentication and resetting password
36d ago
What's the most efficient way to learn cloud governance and compliance
36d ago
Does anyone know C2 framwork and free hosting to host C2?
36d ago
CIS-CAT Assessor for assessment Windows server 2022 and 2025
36d ago
Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this
36d ago
Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks?
36d ago
Recent adoption of AI taught me what is Cybersecurity.
36d ago
The Pentagon Changed the Rules for Cybersecurity Compliance
36d ago
Can someone explain to a noob like me what the implications of this exploit are?
36d ago
SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections
36d ago
Window between zero-day CVE and a patch!
36d ago
Is it risky when a website puts on technology components with versions they used in their website?
36d ago
Anyone else losing their mind over this "AI Cybersecurity" hype?
36d ago
URL parsing behavior in a canonical tag lab
36d ago
Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you?
36d ago
Any tips for me pls
36d ago
How do you minimize legal liability as a solo contractor?
36d ago
How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing?
36d ago
Mentorship Monday - Post All Career, Education and Job questions here!
36d ago
Provenance: A survival toolkit for an AI dominant information landscape
36d ago
[ Removed by Reddit ]
36d ago
Active Drupal SQLi exploitation is a real „patch now“ moment
36d ago
machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native)
36d ago
Need suggestions and input; not a promotion
36d ago
Need advice!
36d ago
New Zealand is becoming a focal point for AI-driven superhacking threats.
36d ago
nmap on Linux: Guide to Network Scanning and Discovery
36d ago
TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle
37d ago
How would Phishing look like in the future? (targeting agents, not humans)
37d ago
Best beginner/intermediate book for system security (blue team / defense / audits)?
37d ago
Why is on-prem and air-gapped asset inventory still such a mess?
37d ago
keep getting MS authentication sign in attempts?
37d ago
Silly issue
37d ago
How to practice cybersecurity while studying prograaming ?
37d ago
[AI Security] Exploring Behavioral AI for Runtime Threat Detection
37d ago
Podman and krun: is it pointless to harden quadlets?
37d ago
How to handle security researchers (and firms) without a bounty program?
37d ago
Product analytics is becoming a third-party breach surface
37d ago
How can i learn and get into red teaming?
37d ago
Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network
37d ago
I got hacked
37d ago
Soc analysts in big companies, how it looks like?
37d ago
CTO at NCSC Summary: week ending May 24th
37d ago
These special phone and app features can help protect you from spyware
37d ago
Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button?
37d ago
Capcha Code Malware
37d ago
getting lost when hunting
37d ago
How to find information behind an account?
37d ago
Theoretical Design Concept for Post-Exploitation Browser Defense
37d ago
Google Certifications...
37d ago
How to continue when finding a possible Vulnerability but local law prohibits me from investigating further
37d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
37d ago
Is the CISSP still a reputable cert for getting jobs?
37d ago
Which of these gоv roles would fare better in the private sector?
37d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
37d ago
Mapping binaries to EDR feature spaces
37d ago
Lost my number + WhatsApp account — worried about old chats, photos, and videos
37d ago
what is the most painful or time-consuming part of your work right now?"
37d ago
Anthropic says Mythos has already found more than 10,000 vulnerabilities
37d ago
What is the experience needed for “entry level” cybersecurity jobs?
37d ago
Browser extension testing.
37d ago
Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip?
37d ago
Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback
37d ago
Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition
38d ago
Can someone recommend me some good, large universities to study cybersecurity?
38d ago
New guy khikhi
38d ago
Examples of intentional backdoors being breached?
38d ago
Non-Compliant Vocab
38d ago
Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites
38d ago
infostealers just spawned a 5,000+ repo github supply chain attack
38d ago
The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis
38d ago
GRO frag
38d ago
We audited 12K n8n templates: most have critical vulnerabilities
38d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
38d ago
Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week
38d ago
Mitigated Vulnerabilities by Vendor as Feed
38d ago
Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors
38d ago
A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories
38d ago
Where can I find the tools freely on internet to practice for soc analyst
38d ago
residential proxies
38d ago
Recommendations for getting started in cybersecurity
38d ago
Linux mint or Ubuntu for complete beginner
38d ago
Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world.
38d ago
Pentesting company recommendation
38d ago
Have you ever failed a certification exam?
38d ago
AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance
38d ago
What do i need to learn to get into application security? Which Degrees/Certs
38d ago
RSAC online membership? Is it worth it?
38d ago
Can someone give me a detailed roadmap for becoming a SOC Analyst?
38d ago
Puedo conseguir trabajo?
38d ago
How do i learn networking for cyber security?
38d ago
What's going to be Hacking and Cybersecurity's future is gonna be like?
38d ago
Cyber security placement - Interview Help
38d ago
Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge
38d ago
Feedback needed
38d ago
Handoff Transition
38d ago
Just added an interactive security map showing exactly what the server sees (and doesn't)
38d ago
Trend Micro warns of Apex One zero-day exploited in the wild
39d ago
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
39d ago
https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/
39d ago
Harvard and 140 other legitimate websites compromised
39d ago
Votre Satisfaction Dans Votre Travail
39d ago
5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit.
39d ago
US states urge Congress to renew cybersecurity grants
39d ago
The CISO's Guide to IDE Security in 2026
39d ago
Help with evilginx
39d ago
Watching AI Brain Drain on Attackers in Real Time
39d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
39d ago
api-rta cyberwarfare labs
39d ago
Does Security Implement Fixes?
39d ago
Ultimate Cybersecurity without needing AV ect?
39d ago
User Onboarding with IAM
39d ago
pnpm 11 Might Finally Be a Better Default Than npm
39d ago
14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs
39d ago
Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria
39d ago
Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip"
39d ago
Looking for a cybersecurity professional to interview for a university project (interview in French)
39d ago
Safe read-only check script for Copy Fail / CVE-2026-31431
39d ago
New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible?
39d ago
[TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly
39d ago
Cisco used AI to write security incident reports, with mixed results
39d ago
[TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM)
39d ago
Cyber Insurance Actuary Looking for Educational Resources
39d ago
As a bank , how do i give protected access to claude to my team?
39d ago
Can seasonal Apple Store employees apply for internal IT/cybersecurity roles?
39d ago
Reliable IP reputation check tools besides IPQS?(for work)
39d ago
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026)
39d ago
Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins
39d ago
Hacked by Rat Tools for 2.5 years.
39d ago
Google API Keys Remain Active After Deletion
39d ago
how do cyber sec consultants and pentesters actually get new clients?
39d ago
Post Incident Paranoia?
39d ago
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
39d ago
Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity?
39d ago
Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready
39d ago
You can counter MEMZ with Krotten in XP
39d ago
What are the most effective ways to do Blackbox testing?
39d ago
Npm registry sets stage for more secure package publishing
39d ago
Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support
39d ago
Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK
39d ago
Is the Cybercorps SFS still worth it?
39d ago
Microsoft warns hackers are exploiting password resets to gain access to user accounts
39d ago
Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame
39d ago
WORM USB drives
39d ago
An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model?
39d ago
CISOs - Holding the Line
39d ago
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
39d ago
Security Scroll Down?
39d ago
mass github repo backdooring via CI workflows(Megalodon)
39d ago
Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit?
40d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
40d ago
DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind
40d ago
FaceTec (ID verification) company appears to store user biometrics
40d ago
CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication
40d ago
It seems that FaceTec (ID Verification company) allows for storage of user biometrics
40d ago
Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check.
40d ago
Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data
40d ago
What Questions Do You Ask During SSP Control Interviews?
40d ago
Feed The Cat BackDoor
40d ago
Flipper One - Asking for help from the community
40d ago
Flipper One — tech specs
40d ago
Architecture Zero Trust détaillée
40d ago
Cybersecurity in Healthcare
40d ago
Staged publishing for npm packages | npm Docs
40d ago
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though)
40d ago
Neither MFA, Passkey, nor trusted IP help here
40d ago
cyber security remote
40d ago
CSIRT incident response
40d ago
Trying to find a graduate role
40d ago
Microsoft warns of new Defender zero-days exploited in attacks
40d ago
what is the best security app option for pixel8a?
40d ago
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
40d ago
IoT Security
40d ago
GitHub links repo breach to TanStack npm supply-chain attack
40d ago
Another working Linux LPE exploit is out. How are teams treating local-only bugs now?
40d ago
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
40d ago
Google publishes exploit code threatening millions of Chromium users
40d ago
landing a remote Vulnerability Management role
40d ago
Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case.
40d ago
I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting?
40d ago
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
40d ago
What volume of TPRM do you handle per month?
40d ago
safest virtual machine?
40d ago
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration
40d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
40d ago
GitHub notifications
40d ago
Is there no more privacy left in the world?
40d ago
Microsoft Edge had a password blunder, and it raises a bigger browser trust problem
40d ago
Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network
40d ago
Aconselhamento / mini texto
40d ago
CISA with an absolutely embarrassing data leak.
40d ago
Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys
40d ago
Anyone else feeling like static AppSec workflows are starting to hit limits?
41d ago
GitHub breach highlights developer tools as part of attack surface
41d ago
Why do some malware use unique user-agent strings?
41d ago
Encrypted emails bypassing email security tool
41d ago
Ctf groups
41d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
41d ago
Opensource that automatically scans your git repos for breaches
41d ago
CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed.
41d ago
Your developers are deploying agents in your production environment right now. You have no governance for it.
41d ago
¿Como me preparo para EC-Council CSA?
41d ago
The IBM X-Force Index 2026 explains all three in one finding.
41d ago
Securing iPad's question
41d ago
Cybersecurity 101
41d ago
What would this job role be?
41d ago
MSPs & MSSPs suck
41d ago
[ Removed by Reddit ]
41d ago
Crossroads
41d ago
Advice regarding "SOC" job that automates everything
41d ago
Is this Medium article about "NetMirror" malware legit?
41d ago
AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon?
41d ago
Developer tooling is part of the attack surface before a project is even run
41d ago
How the hell do you manage developers, their code, their apps?
41d ago
Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed
41d ago
Do people still rely on antivirus software in 2026, or is built-in security enough now?
41d ago
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
41d ago
Automatic CLI for spinning up vulnerable labs + objectives
41d ago
ISO/IEC 27701 scenario question
41d ago
Discord rolls out end-to-end encryption on voice, video calls
41d ago
GitHub investigates internal repositories breach claimed by TeamPCP
41d ago
Two AI-based science assistants succeed with drug-retargeting tasks
41d ago
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
41d ago
An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now.
41d ago
New to cybersecurity
41d ago
Anyone interview or work with Moxfive?
41d ago
A stealth Firefox version that passes all anti-bot and CAPTCHA
41d ago
mkPIVM - a polymorphic position-independent shellcode virtualizer
41d ago
Started in IT and need a Cybersecurity Roadmap with my Useless Degree!
41d ago
GitHub announces internal data breached.
41d ago
Roadmap to Cybersecurity roles
41d ago
Malware installed without literally doing anything?
41d ago
CTFs
41d ago
Crossroads
41d ago
Canara Bank SuRaksha Cyber Hackathon 2.0,
41d ago
Anti BOT Tipps und Tricks gesucht.
41d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
41d ago
New to Cybersecurity
41d ago
Is the ISC2 Certified in Cybersecurity worth it?
41d ago
Average Days to Close by Source CNAPP Severity Tag 2026
41d ago
I want free nmap resource
41d ago
If I clear browser history regularly, does it reduce the chances of malware that target browser data?
41d ago
What is next after 1.5 Year as Security Analyst?
41d ago
Analysis advice
41d ago
Stop me if you heard this one before... (YellowKey related)
41d ago
Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe?
42d ago
Looking for advice: where should I post/publish CVE write-ups?
42d ago
Cybersecurity statistics of the week (May 11th - May 17th)
42d ago
How can I test my website locally for cybersecurity?
42d ago
Use of coding in security operations
42d ago
Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
42d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
42d ago
I've built an open source honeypot probe database accessible via curl, http and mcp
42d ago
6,000+ Automatic Tank Gauges Exposed With No Authentication
42d ago
Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email?
42d ago
If humans are the weakest link, why won't companies evolve?
42d ago
Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?"
42d ago
Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM
42d ago
Local transcription vs cloud transcription, which actually feels safer?
42d ago
Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today?
42d ago
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise
42d ago
Shai-Hulud source leak is turning npm malware into a copycat problem
42d ago
Framework for Preventing Secret Ideas from Leakage
42d ago
Local LLM for building AI Security platform
42d ago
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
42d ago
Emerging Cyber security niches
42d ago
ISO/IEC 27701
42d ago
Solo dev building a terminal-heavy hacking game inspired by corporate security
42d ago
Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations
42d ago
CS/IT Student Looking to Grow My LinkedIn Network 😃
42d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
42d ago
Is Amazon Cognito a good choice long term? Alternatives?
42d ago
Was hacking easier in the 80s and 90s and early 2000s?
42d ago
Need some Advice in SOAR heavy environment
42d ago
Trying to find serious builders in cybersecurity - not just “let’s build” conversations
42d ago
AI Phishing
42d ago
One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals
42d ago
How easy is it to get into the cyber security field?
42d ago
314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js
42d ago
Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start?
42d ago
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo
42d ago
CEH/CPENT vs OSCP vs GPEN
42d ago
ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro”
42d ago
CISA Contractor Admin Leaked AWS GovCloud Keys on Github
42d ago
Suspecious activity in my account
42d ago
Is it safe to use my first name and middle name on platforms?
42d ago
Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice.
42d ago
Just received an email from shinyhunters about their amtrack hack
42d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
42d ago
Bywaf: an auditable Python commandlet framework for chained pentest workflows
42d ago
For anyone currently working in a SOC:
42d ago
Fellow Tier 1 SOC/Security Analysts - What does your day to day look like?
42d ago
How do you threat hunt for RMM tools in environments where RMM is all over the place?
42d ago
Microsoft - "your single use code" email when it was not requested by yourself
42d ago
Directory of vendor security questionnaires
42d ago
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
42d ago
MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals
42d ago
Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight
43d ago
How is AI affecting the cybersecurity market?
43d ago
MCP security
43d ago
YellowKey Mitigation
43d ago
Anyone else on the receiving end of ShinyHunters extortion email?
43d ago
Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs
43d ago
What’s the biggest mistake people still make about online security in 2026?
43d ago
Anthropic shuts the EU out of its most advanced cyber AI model
43d ago
Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens]
43d ago
Best hotel for attending all three conferences in Vegas?
43d ago
What's your company's actual PQC migration plan? Not the one on paper - the real one.
43d ago
Does buying local cybersecurity (services/products/etc) matter to you?
43d ago
LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose
43d ago
Detection Engineering AI Maturity Framework
43d ago
Microsoft code
43d ago
Microsoft confirms Windows 11 security update install issues
43d ago
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
43d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
43d ago
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
43d ago
Suspicious with a company offer letter
43d ago
Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first?
43d ago
Why do some recovery workflows still require full wallet uploads?
43d ago
Need help with interview for soc l1
43d ago
Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap)
43d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
43d ago
carrer path in cybersecurity for a btech stud
43d ago
Agents usage in production
43d ago
‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K
43d ago
Are teams still finding AI API keys in public repos?
43d ago
Mentorship Monday - Post All Career, Education and Job questions here!
43d ago
Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here?
43d ago
Does the CBP bug phones?
43d ago
What We Learned Building Runtime Visibility for Modern Telco Networks
43d ago
Ive got my Spotify account hacked! How do I solve this?
43d ago
The Politics of AI Transparency
43d ago
A million baby monitors and security cameras were easily viewable by hackers
43d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
43d ago
Is cybersecurity becoming more behavioral than technical?
43d ago
Questions About Promo Items for a Cybersecurity Conference
43d ago
Dois-je m'inquiéter ?
43d ago
I am dying to work abroad , rate my journey so far
43d ago
Microsoft - "Your single use code" email when it was not requested
43d ago
Security / Compliance work going Agentic?
43d ago
Don't believe the media, specially in cybersec
43d ago
Microsoft account keeps getting Authenticator requests?
43d ago
[Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated.
43d ago
Struggling to generate security bulletins — any ideas?
44d ago
Certs to go into Security Engineer/architect
44d ago
18882745552 beware of email with this number
44d ago
Transition from traditional penetration testing into AI security
44d ago
Seeking advice on next career steps
44d ago
Will the analyst role become obsolete?
44d ago
Alert Fatigue
44d ago
Best path into cybersecurity for a high schooler?
44d ago
Keep getting hacked
44d ago
How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices
44d ago
I’m interested in joining the Red Team Hackers Academy in Bangalore.
44d ago
A clueless teenager 💔
44d ago
Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start?
44d ago
Am I overthinking Claude Code security or is this actually a risk?
44d ago
is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this
44d ago
ISO/IEC 27701 ( SoA ) Applicability
44d ago
Security Executive Playbook
44d ago
This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon
44d ago
I feel crazy I hope someone has insight .
44d ago
ΡHANTΟΜ Al-Powered Pentesting Command Center
44d ago
Interview Assessments
44d ago
We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it
44d ago
Questions about data blockers
44d ago
Post Implementation task
44d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
44d ago
Cyber security jobs in Austria
44d ago
Personal favorite deception layer.
44d ago
Estudiar Ciberseguridad
44d ago
Learning way
44d ago
How do you report large volume detections to a CISO without making the BPA report a SOC story?
44d ago
Can anyone share bugbase platform screenshot having professional usage on dashboard?
44d ago
CTO at NCSC Summary: week ending May 17th
44d ago
Security Executive Playbook
45d ago
Tired of tab-switching between CTI tools - here's what we put together
45d ago
I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor
45d ago
In Cybersecurity
45d ago
Anyone else feel like most MSP tooling is either overkill or painfully manual?
45d ago
Thinkpad vs Macbook pro endpoint security
45d ago
Any more affordable alternatives to “IntelligenceX”?
45d ago
Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran
45d ago
tanstack checker github action
45d ago
Drivers Alpha AWUS036AXML
45d ago
Splunk download for free
45d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
45d ago
Anyone here using pager duty?
45d ago
Scammer targeting posters
45d ago
Seeking advice
45d ago
Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026)
45d ago
Just got an email about a single use code, maybe someone was trying to log in?
45d ago
Can a background in DevOps enter the cybersecurity field?
45d ago
Using ai in learning
45d ago
Avanzamento area Blue Team/SOC
45d ago
Please what could be helpful
45d ago
CVE exploit chain
45d ago
What are the widely accepted SaaS security accreditations/audits an app should seek in fintech
45d ago
Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco
45d ago
Major flaw in Indian Cyber and IT assurance landscape
45d ago
Red Team Ops Ⅱ ( CRTL ) exam preparation
45d ago
Recomendations
45d ago
Recommended cybersecurity certification for a UX designer new to the domain?
45d ago
insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server
45d ago
Career path
45d ago
Merit America offers a program that gets you into cyber security roles.
45d ago
Brovan: Binary user-mode emulator for x86_64
45d ago
AmEx Interview!
45d ago
Developer credential-stealing pipeline also collected operator workstations
45d ago
need help building a case.
45d ago
Personal favorite SIEM platform?
45d ago
Cardputer ADV
45d ago
Alternative for Qualys
45d ago
The 4th Linux kernel flaw this month can lead to stolen SSH host keys
45d ago
Stack Buffer Overflow Explained (Using a Classic Doom Bug)
45d ago
Confused about cybersecurity career
45d ago
Transferring from pen test consulting to application security?
45d ago
Curso de especializacion de Ciberseguridad
45d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
45d ago
Lost, tempted to throw in the towel
45d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
45d ago
I open-sourced a Docker security scanner I use to audit all my websites
45d ago
Testing Deception Technique
45d ago
A malware got into my account and spread spam ad to my friends and relatives
46d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems
46d ago
Most pentest reports I review are padded with garbage findings
46d ago
Cyber Essentials and use of third party websites - MFA
46d ago
Rapid 7 and Cisa Kev
46d ago
Anyone know much about MS Defender?
46d ago
EN18031 for IoT: struggling to see the big picture — advice from experienced people?
46d ago
Automating Code Security Reviews
46d ago
New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available
46d ago
AI coding tools on developer machines — looking for input on how you're handling it
46d ago
Chrome 148 Update Patches Critical Vulnerabilities
46d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
46d ago
I need help. i am lost
46d ago
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence
46d ago
Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments
46d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
46d ago
I'm going crazy. At the application level what I can actually do to prevent DDos?
46d ago
Is anyone enrolled in Intellipaat's cybersecurity course?
46d ago
Will AI Replace Cybersecurity Jobs?
46d ago
What's best certification choice after OSWE
46d ago
Facebook Page Call Slipping through Sleep mode
46d ago
ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey
46d ago
New Linux LPE allows local users to read any file, including privkeys
46d ago
A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks.
46d ago
Your experience as IT Admin on Alerts
46d ago
Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time
46d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
46d ago
Discord VC lag Exploit
46d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
46d ago
Bug FB - Inicio de sesion por password
46d ago
Does anyone know how to configure EVILGINX for testing
46d ago
How long does it take to get familiar with a tool
46d ago
Scam website
46d ago
ANTS Hack: 19 million records exposed in French ID agency breach
46d ago
Is it really that easy to obtain SMS codes using an SS7 attack?
46d ago
AI coding tools are shipping code faster than security can review it. What's your team doing about it
46d ago
Interview for AI security engineer position at a fortune 500 company
46d ago
How’s the job market for Senior AppSec Engineers? How are the interviews?
46d ago
Has anyone read "The Art of Deception"? How does it hold up to now?
46d ago
Is metadata protection becoming more important than traditional endpoint security for ordinary users?
46d ago
Zero trust in hybrid environments - what's actually worked for you
46d ago
Have you encountered issues with CSAF advisories in practice?
46d ago
Zero trust in hybrid environments - what's actually working for you
46d ago
OpenAI confirms security breach in TanStack supply chain attack
46d ago
Bachelors Degree Options
46d ago
I need help protecting my privacy
46d ago
Free Threat Intellegence
46d ago
What discovery in cybersecurity amazed you the most?
46d ago
Scholarship for Service
46d ago
For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons?
46d ago
Another day, another supply chain
46d ago
How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs?
46d ago
Teaching Linux+ & CEH.....
46d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
46d ago
SIEM use case development
46d ago
JFrog vs Mend as Scanners
46d ago
KQLab - open-source query manager for SOC teams
46d ago
Which Vendors Publish the Best (or Worst) Security Advisories?
46d ago
Synthetic training data vs. real attack telemetry — does it actually matter?
47d ago
Operative IT-Sicherheit | SIEM & Splunk
47d ago
SOC not for junior level?
47d ago
Cybersecurity at MSG
47d ago
pii-tools.com reputable?
47d ago
Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise
47d ago
Contract jobs worth the risk?
47d ago
HackTheBoxAcademy vs LetsDefend vs CyberDefenders
47d ago
Automating code security reviews with Claude: near Mythos-level capabilities at lower cost
47d ago
Making Right Career Decision?
47d ago
I tried using apparmor (linux security) but it doesn't seem to work very well
47d ago
Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything!
47d ago
Struggling to Stay Up to Date With Vulnerabilities
47d ago
How to Transfer files Safely from a Compromised (work) Device
47d ago
Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward
47d ago
Multiple data breaches in one week
47d ago
How are small security teams handling vulnerability overload now?
47d ago
Concerns mount that EU will demand age verification for VPNs
47d ago
Automating code security reviews: Claude Mythos-level capabilities with lower cost
47d ago
The Rare Patch: A Digital Sovereignty Challenge
47d ago
Advise
47d ago
GRC
47d ago
Admins and Engineers
47d ago
Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark
47d ago
Prompt injection in browser coding agents is the threat model nobody is ready for
47d ago
New Fragnesia Linux flaw lets attackers gain root privileges
47d ago
Transition from MSP to Network Engineering?
47d ago
So called “off grid” method
47d ago
Convince me I’m not paranoid: a unique hacking situation.
47d ago
Hunting the Behavior Behind npm Supply Chain Attacks
47d ago
Question for AppSec Members
47d ago
Beginners guide to Google Dorks by Heisenberg
47d ago
Alguém sabe algo sobre raven eye technology
47d ago
Gophish Porject - Requirement
47d ago
Security Team Won’t Assess Risk
47d ago
Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework
47d ago
Microsoft’s new multi-model agentic security system tops leading industry benchmark
47d ago
Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
47d ago
Overwhelmed on how to enter the job market.
47d ago
Social media scam bill targets tech giants as New Yorkers lose billions
47d ago
What are the biggest technical & cultural hurdles you’re facing right now?
47d ago
CISSP / CCSP training - Experienced engineer
47d ago
Vulnerability in Canvas/Instructure Support Tickets had part in breach?
47d ago
is malwarefox legit?
47d ago
what lab to learn zero trust?
47d ago
Anyone else got a bunch of emails leaked by Samsung?
47d ago
This is what some the world's largest banks of malware look like stacked as hard drives
47d ago
I need feedback on my project please
47d ago
would like to understand the role of "Cyber Insurance UnderWriters"
47d ago
Free on-device tool for monitoring AI traffic on macOS — visibility before policy
47d ago
Is secure evidence handling and controlled derivative file sharing needed?
47d ago
Will Adding Some Certifications Help Me in the Job Market?
47d ago
Linux driver posted for Intel Silicon Security Engine Interface "ISSEI"
47d ago
Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified?
48d ago
Fragnesia made public as latest Linux local privilege escalation vulnerability
48d ago
HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity?
48d ago
NIST is surrendering to the amount of CVEs coming in
48d ago
Military Veteran looking to get into the Cyber Field
48d ago
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
48d ago
Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook.
48d ago
Cve apis for a database
48d ago
Empresas de Cyberseguridad en Mexico (Reacciones)
48d ago
Joined a new company: GRC landscape advice
48d ago
Removing admin rights
48d ago
a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access
48d ago
FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow
48d ago
Golden years for cyber security about to start?
48d ago
A stealth approach to Process Injection - EntryPoint Hijacking
48d ago
Detecting CopyFail and DirtyFrag by thinking outside the box
48d ago
Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security
48d ago
Career advice
48d ago
The exponential rise of economic damage caused by cyber-crime continues
48d ago
Today's cybersecurity systems are not ready for AI
48d ago
Are certifications worth it, or do practical skills matter more?
48d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
48d ago
Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed
48d ago
Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft
48d ago
What to do after security+
48d ago
AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data
48d ago
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
48d ago
Is it realistic to move from Tech Risk/GRC into technical cybersecurity?
48d ago
Are IPhone autofill passwords safe to use?
48d ago
Access approvals happen over Slack dm and I don't know how to present that to an auditor
48d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
48d ago
China is going dark to develop its own Mythos, German cyber chief fears
48d ago
Is prompt injection a real problem for you?
48d ago
New Exim BDAT bug shows why “just patch the mail server” is still not simple
48d ago
Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach
48d ago
Cybersecurity guide
48d ago
[Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ?
48d ago
How you guys rate Google Cyber security course and certificate out of 10 !?
48d ago
Cyebrsecurity Startup Advice
48d ago
Can anyone give a real world based AI based attack?
48d ago
How worried should we be about AI powered cyberattacks?
48d ago
Built STIS-ICS — an open ICS/OT security learning project
48d ago
OS scanner that checks repos for traces of the Shai Hulud worm
48d ago
Foxconn Ransomware Attack Shows Nothing Is Safe Forever
48d ago
Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries
48d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
48d ago
Explorer shows random letter/number filenames before copying my actual files — normal behavior?
48d ago
Zscaler AI Security Capabilities ?
48d ago
Cybersecurity degree
48d ago
Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma
48d ago
Cyber security
48d ago
New York Senate takes on junk fees, digital subscriptions, surveillance pricing
48d ago
Cybersecurity statistics of the week (May 4th - May 10th)
48d ago
Feels like AI changed the speed of attacks more than most companies want to admit
48d ago
Anyone used Kasm or ReplicaCyber?
48d ago
Škoda warns of customer data breach after online shop hack
48d ago
Google launches new Android security feature to help uncover spyware attacks
48d ago
Fancy Bear: Stealing Credentials Invisibly
48d ago
Nightmare Eclipse has published Greenplasma and YellowKey
48d ago
Copilot Agent
48d ago
What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles?
48d ago
Career Advice
49d ago
Anyone else exhausted by the nonstop AI hype?
49d ago
Reviewing the trends in ransomware attacks in 2026
49d ago
Is It a Good Idea to Change Jobs Shortly After Getting Hired?
49d ago
SSO makes life easier but MFA keeps it safe, do we actually need both?
49d ago
Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours?
49d ago
How are SOC teams actually deciding what not to investigate anymore?
49d ago
Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily
49d ago
Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released.
49d ago
Has anyone tryed this out yet?
49d ago
The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..)
49d ago
Switching to Cyber
49d ago
Nitrogen ransomware group claims Foxconn after Wisconsin plant outage
49d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
49d ago
Using Cape Sandbox for Phishing Analysis
49d ago
Canvas hack: company pays criminals to delete students' stolen data
49d ago
i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning.
49d ago
AI integrations are quietly creating a new OAuth supply-chain problem
49d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
49d ago
UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships
49d ago
Hardcoded secrets in Git
49d ago
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
49d ago
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
49d ago
New ipTIME Pre-Auth RCE in CWMP
49d ago
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
49d ago
Is my phone hacked?
49d ago
Switched to a grc role after a year in SOC L1
49d ago
Forecasting Lazarus Crypto Heists
49d ago
Infrastructure Security Incident Update & FAQs
49d ago
Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages
49d ago
In Depth Guide To VM Based Obfuscation - What it is and how to handle it.
49d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
49d ago
Transitioned to GRC
49d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
49d ago
German cybersecurity official warns China is close to developing AI superhacker
49d ago
Google Detects First AI-Generated Zero-Day Exploit
49d ago
“DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance
49d ago
Instructure/ canvas paid the ransom?
49d ago
Troca emprego - big para consultoria ou fintech - Pentester/Red Team
49d ago
Finally, texts between Android and iPhone users can be end-to-end encrypted
49d ago
Official CheckMarx Jenkins package compromised with infostealer
49d ago
IMF warns of the potential for AI attacks on global financial systems
49d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
49d ago
Cookie thieves caught stealing dev secrets via fake Claude Code installers
49d ago
Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo
49d ago
MS Defender on OT Network
49d ago
A fateful question
49d ago
SC-900 or SC-400
49d ago
What are your security non-negotiables?
49d ago
Losing my path
49d ago
Axon-captcha
49d ago
What makes companies trust small cybersecurity vendors?
49d ago
Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility”
49d ago
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
49d ago
Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim
50d ago
These Extensions are Scraping Your AI Chats, are you affected?
50d ago
Be careful with your Git: Investigating malware spreading through Git repositories
50d ago
Training and Phishing
50d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
50d ago
AI-powered hacking has exploded into industrial-scale threat, Google says
50d ago
Apple closed my bug report 4 times. MITRE wouldn't let it die.
50d ago
NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG
50d ago
Google spotted an AI-developed zero-day before attackers could use it
50d ago
beginner doubt
50d ago
I got my CEH Certification. SO what now?
50d ago
Construction to Cyber PM
50d ago
[ Removed by Reddit ]
50d ago
Something got downloaded on my phone and then dissappeared
50d ago
Bleeding Llama
50d ago
Do accountants even care about cybersecurityas much?
50d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
50d ago
Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust
50d ago
Was the reconnaissance in Bugbounty overrated?
50d ago
Cybersecurity beginner building an experimental log analyzer — looking for advice
50d ago
Anyone else worried about AI being a security nightmare?
50d ago
Snyk not working
50d ago
Malicious tenants paid us to abuse our RMM. We blocked them
50d ago
Help reasuring parents with an email parsing tool (i will not promote)
50d ago
DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this?
50d ago
cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers
50d ago
5 years as a Level 1 Security Analyst and wanting to transition into consulting
50d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
50d ago
New into network pentesting.
50d ago
Is it worth it to switching field to cybersecurity ?
50d ago
Neeed help to get cybersecurity internship.
50d ago
Mentorship Monday - Post All Career, Education and Job questions here!
50d ago
Cybersecurity and ADHD
50d ago
Anyone dealt with a VulDB submission rejection? Resubmit or reply?
50d ago
ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing
50d ago
I have a malware and need help removing it. someone please help me 🙏
50d ago
I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too?
50d ago
EasySec - Update
50d ago
What is the cybersecurity equivalent of leaving your spare key under the doormat?
50d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
51d ago
VICE: Cyberwar | Full Season 2 | Blueprint
51d ago
Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures
51d ago
Email OTP as default (often ONLY) password isn’t the solution
51d ago
Soc analyse
51d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
51d ago
Price rising
51d ago
AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report
51d ago
Possible security incident against Arup Group
51d ago
Can honeypots be used this way?
51d ago
I think AI just quietly killed the 90-day disclosure window.
51d ago
TCM and Educate 360 are bugged
51d ago
Got an alert from google what should I do?
51d ago
UK jobs
51d ago
Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏
51d ago
Worst company
51d ago
Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning
51d ago
Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months)
51d ago
ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring)
51d ago
App Store Question - Darato Sport / Dofu Sport / Kofu
51d ago
Help! - My Parents Computer is Hacked
51d ago
Ran lumma stealer from a recaptcha scam
51d ago
Port 5986 question
51d ago
CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse!
51d ago
cyber security/ segurança da informação
51d ago
College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains
51d ago
Help with an Escalating Cyber-Stalker
51d ago
RRW - Rick Roll WiFi
51d ago
Best resources to start learning python for cybersecurity and automation
51d ago
Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game.
51d ago
JDownloader site hacked to replace installers with Python RAT malware
51d ago
How can I fix my browser remembering what he had open last
51d ago
MS 360 CoPilot issues
51d ago
I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details
52d ago
ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12.
52d ago
eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback
52d ago
I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you
52d ago
OWASP TOP 10 LLM 2026 Community voting
52d ago
Second security incident at Instructure (Canvas)
52d ago
UK Advice Needed - VA+ Training?
52d ago
Gateweb - Secure Web Gateway
52d ago
Those who are in Detection engineering
52d ago
Can someone tell me of a trustable hacker?
52d ago
MSPs, how are you handling AI usage across your customer environments today?
52d ago
Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write
52d ago
How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there?
52d ago
ecpptv3 Exam in 3–4 Days —
52d ago
AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES
52d ago
Did CISA helped you land a job ?
52d ago
CTO at NCSC Summary: week ending May 10th
52d ago
pre pre junior needs help(guidance pls)
52d ago
Trojan malware
52d ago
SANs Courses: How do people get their employers to pay?
52d ago
NIS2 Article 21: turning compliance controls into technical security evidence
52d ago
This GBA Rom is making is having a weird behavior in the Sandbox, why?
52d ago
Why AI agent governance feels harder than traditional security models
52d ago
Confused about what certs are important
52d ago
Would getting Security+ be worthless for me?
52d ago
Submit probe test — shadow DOM click
52d ago
Threat intelligence in OT (Power equipments)
52d ago
SOC Analyst
52d ago
PAWs, PAM and PIM..what is best practice?
52d ago
This is the most in-depth analysis I have found on the Instructure/Canvas breach so far.
52d ago
Poland says hackers breached water treatment plants, and the U.S. is facing the same threat
52d ago
Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web.
53d ago
Quacc++: Automated Open Source Vulnerability Discovery
53d ago
60% of MD5 password hashes are crackable in under an hour
53d ago
Built a correlation engine that chains AD findings into attack paths automatically.
53d ago
Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests
53d ago
JDownloader's official website delivered Python RAT
53d ago
Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
53d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
53d ago
Note taking apps and advice
53d ago
IMF Warns AI Could Trigger Global Financial Cyber Crisis
53d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
53d ago
Is the ISC2 Cybersecurity program still worth it?
53d ago
Canvas getting hit during finals week shows how fragile “critical SaaS” has become
53d ago
Are websites exposed to the internet under attack almost every hour, even if they're small?
53d ago
Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken
53d ago
What the **** is happening in cybersecurity space ?
53d ago
Canvas is back up, but now what?
53d ago
Instagram is getting rid of end to end encryption, what now?
53d ago
New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation
53d ago
Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable".
53d ago
Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group?
53d ago
Cushman and Wakefield confirms cyberattack
53d ago
Egnyte potential ransomware attack
53d ago
So canvas is down, what'll happen if they can't come to an argreement?
53d ago
Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now.
53d ago
/Why/ is Shinyhunters targeting Canvas?
53d ago
Canvas Hack - Any Guesses How?
53d ago
Should I build a virtual or physical lab?
53d ago
Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12
53d ago
Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata
53d ago
Audit/Cybersecurity
53d ago
Issues removing Trellix (and specifically solidifier)
53d ago
Pentagon eyes 3-year cyber training requirement, overriding new Army policy
53d ago
How much personal info will be leaked by the recent Canvas hack??
53d ago
Dirty Frag and canvas
53d ago
Hackers deface school login pages after claiming another Instructure hack
53d ago
Did I destroy my career by being loyal to an arguably good company?
53d ago
V4bel/dirtyfrag - Universal Linux Local Privilege Escalation
53d ago
What is CYBERRANT?
53d ago
Canvas is down as ShinyHunters hack forces outage
53d ago
New Dirty Frag Linux Bug Emerges in Wake of Copy Fail
53d ago
Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today.
53d ago
How is GRC work in a MSSP?
53d ago
SH and BF phishing console
53d ago
Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth?
53d ago
Socure authenticating AI identity as real.
53d ago
Automated SSL Certificate Renewals - What is your setup?
53d ago
Shinyhunters and Canvas
53d ago
What Cli execution do you use for a script file?
53d ago
Fiserv security incident - data breach notice
53d ago
Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments
53d ago
I graduate next year with a Cybersecurity degree.
54d ago
Asking about Cortex
54d ago
Apache Caldera
54d ago
What’s the “unsexy” problem in cyber that’s actually a total disaster?
54d ago
Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE
54d ago
As a developer, should I use AI to improve security?
54d ago
My company has an MSP that manages our employee endpoints but we cant access the software they use to manage
54d ago
Americans sentenced for running 'laptop farms' for North Korea
54d ago
Is my laptop hijacked ?
54d ago
claude ai gave security beta to Enterprise plans only what can we do as pentesters?
54d ago
Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline
54d ago
Advice for path to land job SOC in France
54d ago
Possible Major Vulnerability: Chromium used by current version of PRTG
54d ago
Mythos AI may be a cybersecurity threat, but it follows the rules of the game
54d ago
Control Checks using AI.
54d ago
How do native password managers clear the clipboard?
54d ago
Graduating CS Student but Wanna Start my Career in Cybersecurity
54d ago
Claude-Themed Malware Campaigns
54d ago
DeepFake it till you make it.
54d ago
The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments
54d ago
What niche in cybersecurity should I go for, with my background in Angular & .NET ?
54d ago
Successor for Kaspersky Endpoint Security
54d ago
Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago
54d ago
SOC Analyst tier 1 (Entry Level) ??
54d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
54d ago
Made cybersecurity merch as an infosec practitioner — honest feedback welcome
54d ago
As AI agents become users of company data - what is needed to keep data secure?
54d ago
Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities.
54d ago
AI inference is quietly becoming a security problem
54d ago
is winrar 7.13 vulnerable to extraction exploits?
54d ago
Tried explaining internet encryption in a beginner-friendly but accurate way, feedback?
54d ago
Is the EC-Council CTIA Certification Worth It for Career Growth?
54d ago
POC Android vuln 2026
54d ago
Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise
54d ago
Opinions on Mimecast
54d ago
What's going on in the field of Cybersecurity 🫣.
54d ago
How do teams preserve institutional pentest knowledge when senior testers leave?
54d ago
CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE
54d ago
Sophos NDR on Proxmox
54d ago
On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029.
54d ago
DOJ says ransomware gang tapped into Russian government databases
54d ago
DAEMON Tools devs confirm breach, release malware-free version
54d ago
Have there been instances where your SOC has suffered a cybersecurity attack?
54d ago
OpenCTI founder, Samuel Hassine, arrested and charged with CSAM
54d ago
Deepfake Platform
54d ago
Trellix Licence Query
54d ago
Instructure hacker claims data theft from 8,800 schools, universities
54d ago
Is AI generated code creating a non-linear security problem for AppSec teams?
55d ago
D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says
55d ago
Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security
55d ago
Norton Antivirus and Other Norton Software
55d ago
Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home?
55d ago
We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes.
55d ago
Download a malware a while ago, someone trying to log into my ios account
55d ago
Org Restructure
55d ago
Does SOC 2 actually reduce questionnaires, or just change them?
55d ago
Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views
55d ago
How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically?
55d ago
Ran phishing awareness training for 200+ non-tech employees
55d ago
Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk
55d ago
Vulnerability Garden
55d ago
Palo Alto Firewall Zero-Day Under Active Exploitation
55d ago
Cyber Security Militias
55d ago
Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk
55d ago
CyberSecurity Nightmares
55d ago
Can I use NanoKVM if it's just to turn on pc?
55d ago
got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something?
55d ago
How to learn tools for cybersecurity?
55d ago
'CopyFail' attackers start cashing in on Linux flaw
55d ago
Anybodybodybdown for a team/studygroup?
55d ago
I was hacked due to sim card spoofing
55d ago
Chrome is quietly installing a 4GB AI model on your device
55d ago
Dev vs Security role
55d ago
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft
55d ago
Oracle Debuts Monthly Critical Security Patch Updates
55d ago
Sec engineer / developer?
55d ago
When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them?
55d ago
Are we actually seeing more vulnerabilities or just more noise?
55d ago
Cybersecurity jobs in red team
55d ago
Question
55d ago
What’s the biggest mistake people make even after installing antivirus?
55d ago
New dashboard tracks ransomware groups by their reliance on Infostealer credentials
55d ago
What would you say if your security lead said this...
55d ago
What would be the goto setup in AWS for security purposes?
55d ago
CREST CRT Exam 2025/2026 Experiences
55d ago
Microsoft Edge stores your passwords in plaintext RAM... on purpose
55d ago
Como começar?
55d ago
Possible Password Leak? Curious if Anyone Has Seen This Before
55d ago
Not a Hack. A Handout. Inside the GTFOice.org Data Exposure
55d ago
Besoin de conseils sur une DMZ automatisée
55d ago
Microsoft, Google and xAI will let the government test their AI models before launch
55d ago
Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073
55d ago
SMB Header Signature for Tagging in Firewall
55d ago
Question regarding VDP
55d ago
Working on what i should do for the next 3 years
55d ago
Question for Security Professionals
55d ago
Do tech companies lifecycle-manage public DNS records to prevent dangling DNS?
55d ago
Vulnerability Summary for the Week of April 27, 2026
55d ago
Cisco releases open-source ‘DNA test for AI models’
55d ago
Cybersecurity is becoming too AI dependent is that a problem
55d ago
Foxconn Wisconsin outage raises cyber questions
55d ago
How stressful is GRC?
55d ago
Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia
55d ago
Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India
55d ago
Archer for a non-regulated medium sized company?
55d ago
Cybersecurity statistics of the week (April 27th - May 3rd)
55d ago
Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM.
55d ago
Where to find reliable vendors?
55d ago
Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts?
56d ago
We wrote a guide on securing Claude across the enterprise — here's the core framework (with download)
56d ago
Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium.
56d ago
Hardware reverse enginnering first project. Love some advice
56d ago
Microsoft Edge Stores Passwords in Process Memory, Posing Risk
56d ago
Currently working on cybersecurity, looking for advice
56d ago
Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning
56d ago
CISO course valuation
56d ago
GRC Path to CISO (Certifications)
56d ago
CISOs and pentest buyers, what's the worst thing you've seen in a pentest report?
56d ago
How to enforce M365 Sign-in frequency on corporate laptops?
56d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
56d ago
Built an independent directory of AI Act / AI governance tools, feedback?
56d ago
ScarCruft APT group compromises gaming platform in a supply-chain attack
56d ago
Just curious
56d ago
'Copy Fail' is a real Linux security crisis wrapped in AI slop
56d ago
Analysis malicious DLL
56d ago
Cyber security free course
56d ago
Does certification expires?
56d ago
We get paid to break into buildings for a living. Ask us anything!
56d ago
Pay2Key ransomware — any recovery path that’s actually worked?
56d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
56d ago
Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF
56d ago
How have you kept growing your knowledge in security when the job stops pushing you?
56d ago
The UK’s Age Verification Law Is Producing Compliance Theater
56d ago
Microsoft Edge: Passwords end up in memory as plaintext
56d ago
Do people still get viruses in 2026, or is that mostly a myth now?
56d ago
Mitigation script for Copy Fail vulnerability CVE-2026-31431
56d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
56d ago
Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released
56d ago
DigiCert breached via malicious screensaver file
56d ago
Caido Payloads and Scanner of Endpoints
56d ago
CISO Security Mind Map 2026
56d ago
Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker
56d ago
Amazon SES increasingly abused in phishing to evade detection
56d ago
AI Security Trainings
56d ago
Ai help
56d ago
ByDesign: observed behavior where file URLs remain accessible after unshare/delete
56d ago
Can Kali Linux still compete in cyber security or is it outdated?
56d ago
Who are your favorite cybersecurity YouTubers?
56d ago
CISOs, how are you balancing AI adoption with security risks these days?
56d ago
San Diego Community College District fighting major cyberattack
56d ago
After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up
56d ago
Free resource: searchable archive of every BSides conference talk
56d ago
Lightning PyPI Compromise: Bun-Based Stealer
56d ago
Too much mother instinct?
56d ago
L1 SOC Analyst for ~2 years - Should I still get the Security + Certification?
56d ago
Do CTFs help real world security skills, or just teach patterns?
56d ago
Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo
56d ago
Should I do Security + or Network + or A+? For CompTia
56d ago
Bug bounty is ruining how people learn exploitation
56d ago
ISO/IEC 27701:2025 Scope and Location
56d ago
Cybersecurity's 2026 Wild Ride
56d ago
We built a free multiplayer game that scores prompts on AI code security.
56d ago
Production Usecases
56d ago
How does vCISO work?
56d ago
Trellix discloses data breach after source code repository hack
56d ago
CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path
56d ago
Trellix confirms source code repo access incident
56d ago
Employer Offering to Pay for my Certification test - Which one do I choose?
56d ago
John Strand Pay What You Can Information Security Core Skills live starting May 11th
56d ago
Canvas Breach May Put 275M Users, 9,000 Schools at Risk
56d ago
Is this not such a big deal
56d ago
Do email link checkers need to be 100%?
57d ago
Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
57d ago
Recs for pen testing and vulnerability solutions
57d ago
Identify telegram account holders
57d ago
AI Code Security Study: 6 LLMs vs OWASP Top 10
57d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
57d ago
We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA
57d ago
Cortex XDR Cloud Compromise Alerting
57d ago
Norton.com Verification Email out of the blue
57d ago
Atomic Red Team is now aligned with MITRE ATT&CK v19!
57d ago
Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX?
57d ago
Who are you guys using for your PCI ASV Scanning?
57d ago
Just passed my Security+ exam. Now what?
57d ago
I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work.
57d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
57d ago
[PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection)
57d ago
Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350)
57d ago
An another open door to IoT devices
57d ago
Ideas on how to have personal google-like account synchronization system
57d ago
Lateral Movement - Cross-Session Activation
57d ago
What MCP servers have actually made it into your day-to-day toolkit?
57d ago
Cyber Security Education as Self-Defence classes
57d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
57d ago
Use.ai
57d ago
Educational tech giant Instructure confirms data breach, ShinyHunters claims attack
57d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
57d ago
Browsers making connection on port 3389 from loopback
57d ago
Defender Flagged DigiCert Root Certs as Malware
57d ago
Another breach just hit Canvas (Instructure), and this one is worth a closer look.
57d ago
Over 40% of UK firms suffered cyber attack last year, survey finds
57d ago
EU should seek access to Anthropic's Mythos, Bundesbank says
57d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
57d ago
IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks
57d ago
People in cybersecurity, tell us what was the most epic moment in your career?
57d ago
Prerequisites for CARTP
57d ago
Claude Mythos Cyber Wake Up
57d ago
[ Removed by Reddit ]
57d ago
is trellix from mcafee good to use in 2026?
57d ago
Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list
57d ago
Paypal Accesed by malware me being Stupid
57d ago
How was someone in another country able to read all my private messages without my password or clicking a link?
57d ago
Career Transition Help
57d ago
Alguien para hablar de cyberseguridad
57d ago
What is this
57d ago
Feeling lost and disappointed about finding a job just venting
57d ago
Slow at Learning/Cyber Security?
57d ago
Suspicious traffic from web server
57d ago
Cyber security internship
57d ago
Mentorship Monday - Post All Career, Education and Job questions here!
57d ago
Isn't Windows Defender a crap anymore?
57d ago
Learning Cyber
57d ago
Vishing simulator
57d ago
Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others
57d ago
Worried about being tracked/banned for using an educational app on MuMu Player - Need advice
57d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
57d ago
Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance
57d ago
Prompt Injection in 2026: The Five Attack Patterns That Actually Matter
57d ago
I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine
57d ago
Random trojan detected?
57d ago
CRTA second attempt
57d ago
What’s the hardest thing to learn in cybersecurity?
57d ago
What MCP servers are you integrating into your workflow (not exclusive to security)?
57d ago
WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog
57d ago
What are like the top but unknown Cybersecurity firms?
57d ago
Need professionals or expert on cybersecurity related to dark web for interview
57d ago
A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP)
58d ago
North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory
58d ago
Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate)
58d ago
Credential Dumping: Local Security Authority (LSA|LSASS.EXE)
58d ago
Trojan:Win32/Cerdigent.A!dha
58d ago
MDE flagging digi cert certificate as malicious everywhere ?
58d ago
1867 loaded
HS
hacking: security in practice
19d ago · 241 items
DIY pwnagotchi-like device on esp32
19d ago
Flipper Blackhat + Bjorn
19d ago
Do you think AI is making hacking easier or harder
19d ago
What can i do left? PSN
19d ago
Proxmark5 campaign ending in less than 18 hours.
19d ago
How to bypass speed queen coin slot for washer and dryer
19d ago
Self-hosting stuff for when things get ugly
19d ago
Malware Includes Taboo In Text To Prevent LLM Analysis
19d ago
added Mac support for my corporate hacking game, demo on Steam
19d ago
Catfished
20d ago
What did they mean by this? One of us?
20d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
20d ago
OptOutCode – A Privacy4Cars Universal Opt-Out Concept
20d ago
StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams
21d ago
GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.
22d ago
Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏
22d ago
What's up with powershellforhackers.com?
22d ago
Do people really click on links from unknown numbers?
22d ago
How to unlock whitelabeled uniview IPcam
22d ago
Can converted video files contain malware?
23d ago
Rooted your router lately?
23d ago
5$ to whoever can find the email of my old YouTube channel
23d ago
This company is scaming people
24d ago
A modular autonomous-agent runtime written in C
24d ago
ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more
24d ago
Can one reveal the asterisks in an email?
25d ago
Proxmark3 vs Proxmark5 Side by Side
25d ago
Should I go for it?
25d ago
Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header
25d ago
Failed to verify LHOST error for long links in metasploit
25d ago
Is Marauder available for ESP32-S3 Mini?
26d ago
Gemini whatsapp
26d ago
Safe Rust API for wolfSSL/wolfCOSE
26d ago
Resource Exhaustion
26d ago
I’m not sure I’m in the right subreddit….
27d ago
Took me a decade to turn quantum computing into what hackers can easily learn
27d ago
Took me a decade of work to turn Quantum Computing into a fun videogame
27d ago
Simple way how to bypass hotel WiFi?
27d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
27d ago
burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API)
27d ago
How big of a security risk or exploit would this be?
27d ago
KTO , Be the only one online -- on any WiFi network
27d ago
apparently bypassing school systems by playing games
27d ago
Always-On Red Teams
28d ago
I managed to pull the full system prompt for Meta's Support AI
28d ago
Harassing text messages
28d ago
REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY!
28d ago
Hacking Palo Alto Networks' GlobalProtect VPN with AI
28d ago
Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am.
29d ago
Best AI LLM for Hacking related stuff
29d ago
Feels like most people ignore the wireless layer until it bites them
29d ago
Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking?
29d ago
Can anyone figure out how to retrieve the recovery key in signal app?
29d ago
$730k+ raised on Proxmark5 with 2150 backers
30d ago
I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works)
30d ago
Any idea who's behind this hack? How to resolve it?
30d ago
Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it
30d ago
Blue Team tips?
30d ago
edit certified pdf
30d ago
Everyday hacking in our lives - transportation, work, finances, goods etc
31d ago
Do you think this is legit or has the website been compromised?
31d ago
Wanna learn cybersecurity & ethical hacking
31d ago
Do you guys take paper notes or digital ones during studying ?
32d ago
How do people actually modify mobile games to increase their power?
32d ago
Why Loyalty Programs Are Quietly Becoming a Security Blind Spot
32d ago
Ajuda pessoal
32d ago
Samy Kamkar on building viruses, his arrest and privacy in the LLM era
32d ago
[ Removed by Reddit ]
33d ago
Is this considered a bug or something else entirely?
33d ago
Getting back deleted conversation from messanger
33d ago
Building Omegle for Exposed Webcams
33d ago
AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career?
33d ago
5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain
33d ago
What are the dangers of posting?
33d ago
Flipper Zero Users, What's Your Take?
34d ago
Large company with a bit of an issue free stuff
34d ago
Champion ethical hacker warns AI tools like Mythos will make competing harder.
34d ago
Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker.
34d ago
there's a toll in the hall now
34d ago
Am I crazy or is something off about this Google OAuth login via Calendly
34d ago
When “try again later” still tells you the OTP was correct: an account takeover story.
35d ago
ShadowCat: Universal optical file transfer, single html file, browser to camera
35d ago
y2jb un able to enject payloads
35d ago
Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated.
35d ago
Why did Hack Forums lose popularity?
35d ago
ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise
36d ago
Shellcide: A shellcode IDE
36d ago
Finding bot account
36d ago
How to
36d ago
Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift.
36d ago
Nmap Mastery: The Complete Guide to Network Reconnaissance
36d ago
Google wallet virtual card cloned
36d ago
What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method?
37d ago
Proxmark5 campaign unlocked the $600k stretch goal
37d ago
GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
37d ago
Doom running on a Kids Video Walkie Talkie
38d ago
Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX.
38d ago
This ID Verification company store users biometrics? (FaceTec)
38d ago
Playwright version that lets AI-Agents navigate the web
38d ago
Where to learn the ins and outs of the computer itself
38d ago
Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator
39d ago
Hack your corrupt company. Sell their secrets to the black market
39d ago
🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget
39d ago
CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat
40d ago
This ID verification company allows for storage of biometric data?
40d ago
I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :)
40d ago
SeekYou — one input, 15 recon sources, one report.
40d ago
bypass internet restrictions
40d ago
Can someone unlock a list of the 500-1000 most visited websites online?
40d ago
Wordlist generator based on WordNet graphs + LLM
40d ago
wordpress memberpress
40d ago
The Open Source USB Drive Built for Privacy
40d ago
Is someone trying to hack me?
41d ago
cpu backdoor
41d ago
Technical analysis of CVE-2026-34472 in ZTE H188A router firmware
41d ago
Ongoing development
41d ago
For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks?
41d ago
Hackers found a way around Intel CET—PLaTypus locks down library jumps
41d ago
GitHub investigates internal repositories breach claimed by TeamPCP
41d ago
Hackers: What age did you start? Where did you start, especially in practicing your skills?
41d ago
How to watch a private video on Youtube?
41d ago
Can I do anything cool with this network controller?
41d ago
Micro controller safety?
41d ago
CISA Admin Leaked AWS GovCloud Keys on Github
42d ago
Decompilation of DSP Code using IDA Pro
42d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
42d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
42d ago
Built a full disassembler & decompiler for Reverse Engineering | Free and open source.
42d ago
Slopinator - a poisoned GitHub repository generator
42d ago
Made a shell greeter that generates a unique rocket every time you open a terminal tab
42d ago
Just received an email from shinyhackers about their amtrack hack
42d ago
Flipper Zero (or Alternatives)?
42d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
42d ago
Recent WhatsApp hacks
42d ago
I wrote an async scanner that runs about 9x faster than nmap for discovery.
42d ago
Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers
42d ago
Does anyone know if this file is still accessible to download?
43d ago
High school students organized a Jeopardy CTF competition - give it a try
43d ago
Official Miasma Poison Tar Pit Docker Image Now Available
44d ago
Does anybody know where I may stumble upon some Sh1mmer bin downloads
44d ago
Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network
44d ago
GZDoom in the browser
44d ago
Anyone know how to bypass these school laptop pins?
45d ago
A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA
45d ago
I have a friend who looks like he’s a stalker I’m scared he will know I stalk him
45d ago
[Tutorial] How to hack DOS games: Reversing Prince of Persia
45d ago
Is dns spoofing dead??
46d ago
My Privacy Focused USB Drive
46d ago
Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition)
46d ago
TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer
46d ago
has anyone used tail os here?
46d ago
Run this washer/dryer sans coin?
46d ago
I built an open-source Burp alternative
46d ago
HighBoy
46d ago
Reading Siemens CT raw data
46d ago
How I use Hermes agent to turn Patch Tuesday into Windows exploit research
46d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
46d ago
Tips for a beginner noob that wants to learn
46d ago
Strix — first public beta of the spiritual successor to cSploit/dSploit
47d ago
Whatsapp
47d ago
Face ID bypass with avatar
47d ago
Hunting the Behavior Behind npm Supply Chain Attacks
47d ago
Proxmark5 Day 3 Update - $357K+ funded (715% of goal)
47d ago
Are There Really Ethical Hackers? I've Yet To Meet One
47d ago
trying to learn patching
48d ago
Cellphone IP address spoofing.
48d ago
Sorry if its the wrong place but
49d ago
Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it?
49d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
49d ago
where is the location of Files by Google on Android?
50d ago
Reading old s4 memory with xgecu t48
50d ago
Hack a data center?
50d ago
Autonomous Vulnerability Hunting with MCP
50d ago
AI DNS Resolver
51d ago
Is it true that the professionals have the worst setups?
51d ago
I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage
51d ago
Refining hacking basics — scaling them aswell
51d ago
AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic)
52d ago
Bridging the Gap Between Vulnerabilities and Working Exploits
52d ago
um you guys is my hacker stupid?
52d ago
This GBA ROM makes some weird things in the sanbox, would love to understand why
52d ago
Why was he banned?
52d ago
LAB Setup
52d ago
Ethical malware development community
52d ago
Has Instructure paid SH?
53d ago
Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me.
53d ago
New trends (not mainstream)
53d ago
Best tools to find exposed web services by HTML title / HTTP response?
53d ago
Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago?
53d ago
AI Agents Have a Security Problem. IronClaw is Fixing It.
53d ago
A hacker ran me over with a robot lawn mower - The Verge
53d ago
Happened today
53d ago
Shinyhunters and Canvas
53d ago
Modify md5sum of a file
54d ago
OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM
54d ago
Jailbreaking my cars infotainment system and implementing my own custom software
55d ago
where is the original wormgpt
55d ago
Are there any chill hacking youtubers?
55d ago
Took me a decade to turn quantum computing into what programmers can easily learn, big announcement
55d ago
Lilygo T-Embed Glitching etc
55d ago
Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today?
55d ago
Found a possibly interesting live attack
55d ago
Export/Backup ChatGPT chats
55d ago
Is this fake too?🤣
56d ago
I just figured out my dad use to be a Phreaker in the 1980s
56d ago
What of my favorite videos🙂
56d ago
Best tools for blocking spam calls and spam links?
56d ago
someone else’s UI appearing on screen for split second— possible hacker??
56d ago
Avoiding rouge AP detection in enterprise networks
56d ago
GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering
56d ago
San Diego Community College District fighting major cyberattack
56d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
57d ago
Iwas developing a hacker game that transports the feeling of the 90s
57d ago
How did this guy even access another person's privated YouTube video without wayback machine?
57d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
57d ago
IPod Nano Gets Three Monitors
57d ago
Chrome "Best AdBlocker" trojanized extension - 100k downloads.
57d ago
Any good open sources that bypass modern heuristic analysis?
57d ago
Free apex hacks?
57d ago
[SHOWCASE] Cascavel v3
57d ago
Pokemon machine
57d ago
Can HTTP POST bodies be intercepted without network or host access?
57d ago
built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4)
58d ago
Dump sql time based is too slow
58d ago
North Korea rejects US cybercrime claims as 'absurd slander'
58d ago
is credential stuffing using openbullet2 dead in 2026?
58d ago
Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax)
58d ago
Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT)
59d ago
Small models are better at cost-to-recall than large models like Mythos for vulnerability research
59d ago
Bluetooth Spoofed Disconnect?
59d ago
wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ...
60d ago
🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀
60d ago
I made a lightweight breach intelligence search engine (fully client-side) looking for feedback
61d ago
Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan...
61d ago
Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool
61d ago
Copy Fail — 732 Bytes to Root
61d ago
GitHub fixes RCE flaw that gave access to millions of private repos
62d ago
How to download Kaggle dataset safely...?
62d ago
VECT Ransomware Is Actually a Wiper
62d ago
Flipper Blackhat April Roundup!
62d ago
[VulnPath Update] Automated Email Alerting & CISA KEV Feed
63d ago
241 loaded
RE
Reverse Engineering
19d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it
19d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
19d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
19d ago
Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game
19d ago
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
19d ago
Drive Firmware Security - Phison S11
19d ago
IDA 9.4 Beta | Hex-Rays Docs
19d ago
Trane Tracer HVAC cybersecurity issues
20d ago
🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS)
20d ago
I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS.
20d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
22d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
22d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
22d ago
EMBA firmware analysis framework v2.0.2 available - Party the big 2k
22d ago
/r/ReverseEngineering's Weekly Questions Thread
22d ago
HDD Firmware Hacking Part 1
22d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction
22d ago
Zhiyun Weebil-S Camera Gimbal BLE Protocol
23d ago
Reverse Engineering the Garmin Running Dynamics BLE protocol
23d ago
Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate)
24d ago
Reverse Engineering Crazy Taxi, Part 3
24d ago
Ghidra 12.1.2 has been released!
24d ago
Extending a map tool for Cataclismo
25d ago
I've been reverse engineering a lost 2010 horse MMO and I need contributors
25d ago
HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes
25d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
25d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
25d ago
void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies
26d ago
Automated Fault Injection Attack Framework
26d ago
x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994)
26d ago
Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2
27d ago
Hacking your PC using your speaker without ever touching it
27d ago
Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source!
28d ago
Built a decompiler for exotic legacy programming language opentext Gupta Team Developer
28d ago
running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it!
28d ago
/r/ReverseEngineering's Weekly Questions Thread
29d ago
Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from?
29d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
30d ago
TinyLoad v7 - what i added :D (in memory protection using VEH and alot more)
30d ago
[ Removed by Reddit ]
30d ago
Snowboard Kids 2 is 100% Decompiled
30d ago
usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer)
30d ago
I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux)
30d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
31d ago
Ghidra 12.1.1 has been released!
32d ago
Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint)
32d ago
VMP 3.5+ Internal Architecture & Heap Dispatch Analysis
32d ago
How 2004 RuneScape fit a multiplayer RPG into 56k dial-up
33d ago
reverse engineering need for speed most wanted for modding sdk
33d ago
GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs.
33d ago
Winbox server/client reverse engineered is opensource
33d ago
(URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active
34d ago
Hypothetical EDR spoofer
34d ago
I Reverse Engineered Need for Speed Most Wanted Server
34d ago
Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation
35d ago
Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching
35d ago
How I Tried to Parse a Replay from Dawn of War: Definitive Edition
35d ago
Nocturne - A bin2bin code virtualizer for x86-64 PE binaries
35d ago
[Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing
35d ago
Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing
36d ago
I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built
36d ago
delimiter-less string obfuscation powered by compile-time AES
36d ago
/r/ReverseEngineering's Weekly Questions Thread
36d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
37d ago
Has anyone manage to reverse the macked dylib?
37d ago
Reverse engineering circuitry in a Spacelab computer from 1980
37d ago
Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology
37d ago
CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22)
38d ago
Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes
39d ago
qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb)
39d ago
Reverse Engineered Google reCAPTCHA
39d ago
Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware
39d ago
I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP
39d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
40d ago
I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries
40d ago
GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam)
40d ago
AI Agents defeat obfuscated JavaScript in 10 minutes
40d ago
What is it Wednesdays: Episode 0002
41d ago
TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post)
41d ago
Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing
41d ago
How to build .NET obfuscator
41d ago
botguard-token-generator / a google botguard token gen using only requests...?
41d ago
Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing)
42d ago
Deep dive into the object creation flow in Windows - PART 4: Handle table internals.
42d ago
Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware
42d ago
Open-source Hermes bytecode decompiler for React Native apps (Rust)
42d ago
Hermes bytecode decompiler (Rust) - sharing my friend’s project
42d ago
Forza Designer 6
42d ago
Built a full disassembler & decompiler | Free and open source.
42d ago
Snowboard Kids 2 is 100% Decompiled
42d ago
Decompilation projects and N64 Recompiled PC ports (May 2026)
42d ago
Glass - A fast and free interactive disassembler
42d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
43d ago
HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try!
43d ago
/r/ReverseEngineering's Weekly Questions Thread
43d ago
Reverse engineering no dep x64 masm AI IDE
43d ago
PE packer/crypter with random VM ISA per build
44d ago
A Tale of Two File Names
44d ago
PE reconstruction
44d ago
A File Format Uncracked for 20 Years: Part 2
44d ago
Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source!
45d ago
[CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link.
45d ago
Exploiting Toshiba Qiomem.sys vulnerable driver
45d ago
HDD Firmware Hacking Part 1
45d ago
Region-based binary diff tool for firmware analysis
45d ago
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
45d ago
แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป!
45d ago
Brovan — Open-source x86/x64 user-mode binary emulator written in C#
45d ago
Brovan: Binary user-mode emulator for x86_64
45d ago
Understanding Stack Buffer Overflows Through Doom and C++
45d ago
What is it Wednesdays: Episode 0001
45d ago
Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup
46d ago
Deepdive into the object creation flow in Windows -PART 2 : access check internals
46d ago
Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization
46d ago
[Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo)
46d ago
yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android.
46d ago
GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets
46d ago
GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS
46d ago
Trafexia V2 - Mobile Traffic Interceptor Toolkit
46d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
46d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
47d ago
Ghidra 12.1 has been released!
47d ago
Reverse Engineering Slither.io’s Network Protocol
47d ago
I Reverse-engineering Need for Speed Underground 2 Server
47d ago
I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included
47d ago
[Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features
48d ago
LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer]
48d ago
r2garlic - The world's fastest Android/DEX decompiler meets radare2!
48d ago
GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language.
49d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
49d ago
Reverse Engineering Fisher-Price Pixter
50d ago
/r/ReverseEngineering's Weekly Questions Thread
50d ago
Check out my matplotlib of BLE live wire data for Oura ring!
50d ago
Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows
50d ago
Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop
50d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
50d ago
Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)
50d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3
50d ago
PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra
50d ago
[Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc)
52d ago
Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!)
53d ago
Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2
53d ago
SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals
53d ago
I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow!
53d ago
The first FREE online WebAssembly Reverse Engineering workbench (and how we built it)
53d ago
VLC Media Player MKV Exploit Analysis
54d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
55d ago
ant4g0nist/pyre: Ghidra decompiler in your browser
55d ago
Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source!
55d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
55d ago
Reverse-engineering the 1998 Ultima Online demo server
55d ago
Inside Faxanadu series — deep dive into how this NES title works
56d ago
EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing
56d ago
Copy.fail: Why Internal LLMs Are Non-Negotiable for Security
56d ago
Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra
56d ago
Where do i find reverse engineers for actuators? Ideally in Shenzhen
56d ago
[CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2).
56d ago
[WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation
57d ago
IDA-MCP Is Now RE-MCP With Ghidra Support
57d ago
Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference
57d ago
/r/ReverseEngineering's Weekly Questions Thread
57d ago
GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions)
57d ago
Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo
58d ago
Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you!
58d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
58d ago
How to build .NET obfuscator - Part II
58d ago
libghidra - SDK for automating Ghidra from Python, Rust, and C++
59d ago
Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis.
59d ago
Why my macOS Messages badge lied to me (and the one-line fix)
59d ago
Running Adobe’s 1991 PostScript Interpreter in the Browser
60d ago
Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :)
60d ago
/r/ReverseEngineering's Triannual Hiring Thread
60d ago
In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off)
60d ago
Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight
61d ago
HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try!
61d ago
GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).
61d ago
I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway
62d ago
Building a perfect clone of 1993 game SimTower (via RE)
62d ago
How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema
63d ago
AI solved our CTF in 6min
63d ago
Example structure for evidence-based vulnerability reports
63d ago
181 loaded
FB
For [Blue|Purple] Teams in Cyber Defence
19d ago · 603 items
US charges suspected Russian hacker with facilitating cyber campaign
19d ago
Hawkish GOP lawmaker Don Bacon says he was hacked by Russia
19d ago
Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
19d ago
GreatXML: GreatXML bitlocker bypass vulnerability
19d ago
GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan
19d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
19d ago
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion
19d ago
GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default
19d ago
Miasma-style supply chain attacks
19d ago
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet
19d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
19d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
20d ago
Testing offensive AI agents in a cloud lab with deception tech
20d ago
Benchmarking n-day exploit generation [via AI]
20d ago
Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
20d ago
Microsoft Defender now monitors RPC activity
20d ago
RoguePlanet: RoguePlanet Windows Defender Vulnerability
20d ago
I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in)
20d ago
How do you make learning blue team security entertaining ?
20d ago
Maximizing IOC Impact
20d ago
[2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution
21d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
21d ago
Entra Agent ID from a Security Perspective
21d ago
Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility
21d ago
What are the best risk-based vulnerability management tools for tracking active exploitation in 2026?
21d ago
QuasarNix: Reverse Shell Detection with Machine Learning
21d ago
Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go
21d ago
Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion
21d ago
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
21d ago
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
21d ago
UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season
21d ago
Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
21d ago
Visual Studio Code 1.123: Delayed extension auto-updates
21d ago
Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.
21d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched,
21d ago
Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement
21d ago
HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified)
22d ago
Security Review Request — TID Linux Kernel Module
22d ago
Building a safe, effective sandbox to enable Codex on Windows
22d ago
Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale.
22d ago
About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection
22d ago
BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection
22d ago
Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution.
22d ago
UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service.
22d ago
EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
22d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
23d ago
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
23d ago
cygor: An modular asset discovery framework written in python to automate the repeating manual work
23d ago
On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts.
23d ago
Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors.
23d ago
Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim
23d ago
Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored)
23d ago
The Privileged Roles Nobody Talks About
23d ago
Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain...
23d ago
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
23d ago
21 Zero-Days in FFmpeg
23d ago
depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research?
23d ago
CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work
23d ago
The Detection & Response Chronicles: Covert Operations Through QEMU
23d ago
The Interesting Case of WSL for Payload Staging
23d ago
The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer
23d ago
Ongoing Targeted Campaign Against US Law Firms
23d ago
New China-Linked Cluster OP-512
23d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
24d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
24d ago
MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain
24d ago
Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated
24d ago
Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns
24d ago
About ETW Internals: Architecture, Hooking, Tampering, and Detection
24d ago
PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver
24d ago
Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
24d ago
Async PICOs and Custom Beacon Wakeups in Cobalt Strike
24d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
24d ago
staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs
24d ago
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window
24d ago
Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS
24d ago
BOF Cocktails in Cobalt Strike
24d ago
Address Translation
24d ago
Investigation into APT 5 and their inner workings of PLA Troop 61786
24d ago
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
24d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
24d ago
Magecart skimmer turns Stripe into a malware command server
24d ago
Security advisory: Brute force attack on Dashlane user accounts
24d ago
Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability
24d ago
A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact).
24d ago
IronWorm: Shai-Hulud's rustier cousin
24d ago
Weil reportedly pays up to $20 million after hackers steal client data
24d ago
CTO at NCSC Summary: week ending June 7th
24d ago
defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
24d ago
1-Click GitHub Token Stealing via a VSCode Bug
24d ago
The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds
24d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
24d ago
Introducing Package Proxy: supply-chain safety checks without client-side software
25d ago
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
25d ago
zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS)
25d ago
The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory
25d ago
VerdantBamboo: Just Another BRICKSTORM in the Firewall
25d ago
AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID
25d ago
MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code
25d ago
IronWorm Supply Chain Malware Hits npm
25d ago
FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel
25d ago
FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad
25d ago
You do surprise me.exe: An unexpected executable in Hola Browser
25d ago
LSASS/Defender/CTFMON analysis
26d ago
Software supply chain attacks: check your dependencies
26d ago
Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator
26d ago
29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection)
26d ago
Open Source - 2500 New MITRE Mutations
26d ago
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
26d ago
Bring Your Own RWX Region DLL (BYORWXDLL)
26d ago
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
26d ago
APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component
26d ago
NuGet Code Execution As A Service
26d ago
aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies
26d ago
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
26d ago
TA4922: The Suspected Chinese Crime Group is Going Global
26d ago
[ Removed by Reddit ]
26d ago
Espionage Campaign Targeted Stock Exchange Executive for Five Months
26d ago
OnionAccelerator: multi-circuit / chunked download acceleration over Tor
26d ago
HazyBeacon and AWS Lambda Function URL Abuse
27d ago
The Server Seizure That Affects Also Iran's Cyber Operations
27d ago
How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad
27d ago
🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network
27d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
27d ago
Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors
27d ago
Dependency Cooldowns - Dependency Cooldowns
27d ago
C2 Frameworks - Threat Hunting in Action with YARA Rules
27d ago
Ransomware tabletop
27d ago
Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026
27d ago
Tracking North Korea Nation-State APT Infrastructure: Kimsuky
27d ago
새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn
27d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
27d ago
Codex Discovered a Hidden HTTP/2 Bomb
27d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
27d ago
Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix
27d ago
“Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?”
28d ago
Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif
28d ago
Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand
28d ago
Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm
28d ago
RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation
28d ago
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
28d ago
Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches
28d ago
Miasma: Supply Chain Attack Targeting RedHat npm Packages
28d ago
@redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers
29d ago
Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched
29d ago
Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks
29d ago
Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries
29d ago
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
29d ago
Atomdrift - open-source malware detection for the software supply chain
29d ago
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
30d ago
179 npm Packages Target Cloud and Finance via oob.moika.tech
30d ago
KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4
30d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
30d ago
Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services
30d ago
EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA
30d ago
Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace
30d ago
Signal macOS Desktop App Doesn't Actually Delete Messages When it Should
30d ago
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
30d ago
WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD
30d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
30d ago
Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2
30d ago
Malicious npm packages abuse dependency confusion to profile developer environments
30d ago
Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
30d ago
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack
30d ago
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
30d ago
Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign
30d ago
SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.
30d ago
EDR Incident Response Playbook: Containing Local Account Incidents
30d ago
Adversarial Oracles: LLM-Guided EDR Signature Reduction
30d ago
One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF
30d ago
proxy: A lightweight caching proxy for package registries.
30d ago
How OLTs may have exposed entire ISP networks
30d ago
A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
30d ago
HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics
30d ago
Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots
30d ago
Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures
30d ago
Lessons from Penetration Tests on Large-Scale Agent Systems
30d ago
pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter.
30d ago
CIFSwitch: a non-universal Linux local root vulnerability
30d ago
Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension
31d ago
DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.
31d ago
Visual Studio Extensions Revisited
31d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
31d ago
BYOVD and Looting LSASS in the Modern EDR Era
31d ago
CTO at NCSC Summary: week ending May 31st
31d ago
OffensiveCon26 videos
31d ago
School Survey, (non-paid nothing its free its for my grades)
31d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
31d ago
LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms
31d ago
LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting
32d ago
Identifying attack patterns through kernel frame callstacks
32d ago
Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness
32d ago
What safety boundary would you expect from a local AI incident investigation tool?
32d ago
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
32d ago
Why I Built My Own LLM Benchmark for THOR Finding Triage
32d ago
Casdoor contains multiple authentication bypass and access management vulnerabilities
32d ago
The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents
32d ago
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
32d ago
Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies
32d ago
Malware seller hunted across three continents
32d ago
Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims
32d ago
Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers
32d ago
Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network
32d ago
Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations.
32d ago
The C-suite job that's burning people out faster than any other
32d ago
New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation
32d ago
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
32d ago
Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances
32d ago
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
32d ago
APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026
32d ago
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
32d ago
Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
32d ago
Zero Trust Implementation Guidelines
32d ago
BlackToad: Network Manipulation in an AutoIt Payload
33d ago
RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT
33d ago
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
33d ago
Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit
33d ago
FROST: Fingerprinting Remotely using OPFS-based SSD Timing
33d ago
Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup
33d ago
puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
33d ago
Who is Salt Typhoon Really? Unraveling the Attribution Challenge
33d ago
Looking for resources on end-to-end APT attack flow summaries for detection engineering
33d ago
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
33d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP
34d ago
Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint
34d ago
Building Detection Engineering on AWS from scratch — roast my plan
34d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
34d ago
Designing secure access with ZTNA
34d ago
MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response
34d ago
White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats
34d ago
Advisory X41-2026-002: Request Host Header not Validated in Starlette
34d ago
Top ethical hacker Chompie warns AI tools could put her out of business
34d ago
浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents
34d ago
YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions
34d ago
CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state
34d ago
The Evolution of Chinese-language Phishing Services
34d ago
Silent Ransom Group Impersonating IT Personnel through Social Engineering
34d ago
The epoll UAF - an epoll uaf race in fs/eventpoll.c
34d ago
Tycoon 2FA AiTM detection for Entra ID and Google
34d ago
Microsoft Copilot Cowork Exfiltrates Files
34d ago
Unpatched Sparx vulnerabilties
34d ago
sylvia: iOS Syscall Explorer for IDA 9.X
35d ago
Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East
35d ago
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip
35d ago
JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign
35d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack
35d ago
Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@"
35d ago
The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization
35d ago
GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
35d ago
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
35d ago
CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700.
35d ago
YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos
36d ago
Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it
36d ago
honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports
36d ago
Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild.
36d ago
Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council
36d ago
RemotePE: The Lazarus RAT that lives in memory
36d ago
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
36d ago
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
36d ago
Twee mannen aangehouden voor phishing - Two men arrested for phishing
36d ago
Sharp Eyes: Mass surveillance of foreigners in China
36d ago
relay_bible: Technical Reference to multiple relay techniques
36d ago
Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec
36d ago
The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in]
36d ago
SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format
36d ago
North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial
36d ago
Staged publishing and new install-time controls for npm - GitHub Changelog
36d ago
Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES
37d ago
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
37d ago
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow
37d ago
The Future and Past of Residential Proxies
37d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
37d ago
Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy
37d ago
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
37d ago
A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software
37d ago
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
37d ago
Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities
37d ago
Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes
37d ago
mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
37d ago
keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust.
37d ago
np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.
37d ago
Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up.
37d ago
OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
37d ago
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
37d ago
FatGid - FreeBSD 14.x kernel LPE
37d ago
Manage [VSCode] extensions in enterprise environments
37d ago
angr: A powerful and user-friendly binary analysis platform!
37d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
37d ago
How Attackers Force Microsoft to Send Phishing Emails
37d ago
Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
37d ago
Microsoft Authenticator App Details now exposed in Entra SignInLogs
37d ago
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
37d ago
How China-linked threat actors obtain zero-day vulnerabilities
37d ago
Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research
37d ago
Monitoring for vssadmin.exe delete shadows is an absolute bare minimum
37d ago
Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack
37d ago
How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers
37d ago
CVE-2026-48029: Two grid-decode bugs in libheif
37d ago
workcell: Bounded local runtime and policy boundary for coding agents
37d ago
OpenShell: OpenShell is the safe, private runtime for autonomous AI agents.
37d ago
Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation
37d ago
Built a SOC from scratch with no prior SOC experience
37d ago
CTO at NCSC Summary: week ending May 24th
38d ago
VPN Exploitation When Patched Doesn't Mean Protected
38d ago
Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation
38d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
38d ago
CLR-Stomp: .NET CLR-Stomping
38d ago
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
38d ago
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms
38d ago
Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor
38d ago
AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22)
38d ago
GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks.
38d ago
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
38d ago
Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL?
39d ago
I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner
39d ago
AI-generated reporting: Lessons learned from Cisco Talos Incident Response
39d ago
CrabLoader: A PoC Cobalt Strike UDRL written in Rust
39d ago
The 429 Microsoft Graph Mystery
39d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
39d ago
Azure Tenant Enumeration is Dead
39d ago
A Deep Dive into Codex Windows Sandbox
39d ago
Striga: Lifting x86 to LLVM IR with Python
39d ago
veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker.
39d ago
Windows BitLocker Security Feature Bypass Vulnerability
39d ago
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
39d ago
Google API keys keep working after you delete them long enough to be exploited
39d ago
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
39d ago
North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT
39d ago
Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit
39d ago
Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names)
39d ago
Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
39d ago
Megalodon: CI/CD Malware Spreading Across GitHub Repositories
39d ago
📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity.
39d ago
Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
40d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
40d ago
beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA
40d ago
Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading
40d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
40d ago
Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign
40d ago
From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree
40d ago
How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102)
40d ago
Iran-linked Operators Suspected in ATG Breaches
40d ago
Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs
40d ago
Compromised Nx Console version 18.95.0
40d ago
CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
40d ago
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
40d ago
Webworm: New burrowing techniques
40d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
40d ago
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
40d ago
Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation
40d ago
GitHub’s Fake Engagement Problem Is Hiding in Plain Sight
40d ago
Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR)
40d ago
Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage
40d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
41d ago
5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready
41d ago
Remote Process Read Primitive via NtCreateThreadEx Exit Code
41d ago
aimap: Discover Exposed AI Services
41d ago
FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation.
41d ago
Why China Is Now a Peer Competitor to the United States in Cyberspace
41d ago
nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings
41d ago
Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt
41d ago
We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.
41d ago
Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings)
41d ago
Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
41d ago
Eight Leading U.S. Communications Firms Form C2 ISAC
41d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
41d ago
UAC-0184: From HTA to a Signed Network Stack
42d ago
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
42d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
42d ago
Entra ID: PIM for Groups Review
42d ago
TeamPCP compromises NPM maintainer with over 540 packages
42d ago
Active Supply Chain Attack Compromises @antv Packages on npm...
42d ago
When DMCA Comes Knocking - A YouTube Creator Phishing Kit
42d ago
[Cloudflare] Project Glasswing: what Mythos showed us
42d ago
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
42d ago
Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger
43d ago
Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics
43d ago
CrystalX: unpacking a Go RAT through three encrypted layers
43d ago
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write
43d ago
FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation
43d ago
LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying"
44d ago
Static Kitten APT Adversary Simulation
44d ago
Eimeria: five layers from RAR5 to RunPE
44d ago
ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
44d ago
openDCIM exploitation
44d ago
HASBL CTF - A Jeopardy-Style CTF Organized by High School Students!
44d ago
We Have Packet Capture at Home
44d ago
Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware
44d ago
HWMonitor Trojanized for STX RAT DLL Sideloading
44d ago
awesome-dfir-skills: Admiralty System for CTI Claude skill
44d ago
Mullvad exit IPs as a fingerprinting vector
44d ago
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
44d ago
Popular node-ipc npm Package Infected with Credential Steale...
44d ago
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
44d ago
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
44d ago
Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
44d ago
Sandworm Activity in Industrial Environments: What the Data Reveals
44d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
44d ago
"Shadowserver-in-a-box" IntelMQ + ELK Solution
44d ago
Stenloader: Steganography Shellcode Loader
44d ago
AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out
44d ago
Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018
44d ago
Our response to the TanStack npm supply chain attack
44d ago
QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026).
44d ago
We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase.
44d ago
APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox.
44d ago
oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday
44d ago
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations
44d ago
OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance
44d ago
The Gentlemen Ransomware Group — Leak Analysis
44d ago
HDD Firmware Hacking Part 1
44d ago
ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.
44d ago
CTO at NCSC Summary: week ending May 17th
44d ago
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
45d ago
Developer credential-theft campaign exposed operator-side self-infection
45d ago
Help-Desk Lures Drop KongTuke's Evolved ModeloRAT
45d ago
Welcome to BlackFile: Inside a Vishing Extortion Operation
45d ago
DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era
45d ago
Stop Being Weird — Life After Call Stack Spoofing Under CET
45d ago
Triggering the Secure Boot Certificate Update with Intune Remediations
45d ago
How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache
45d ago
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
45d ago
One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities
45d ago
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
45d ago
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
45d ago
FamousSparrow APT Targets Azerbaijani Oil and Gas Industry
45d ago
Disclosing new PebbleDash-based tools by Kimsuky
45d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
45d ago
Kazuar: Anatomy of a nation-state botnet
45d ago
OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments
45d ago
NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys
45d ago
Hacker Ringleader Extradited for 38 Billion Won Theft
45d ago
Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System
45d ago
Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit
45d ago
The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation
45d ago
FFFFirefox - A One-Day Wonder Renderer Exploit
45d ago
MiniPlasma, a powerful LPE
45d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
45d ago
[Tool] IOCX — deterministic static IOC extraction for PE binaries
46d ago
Novel Evilginx Frontend - Lowering the barrier for token theft reuse
46d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
46d ago
WAF Evasion Engine
46d ago
Thus Spoke…The Gentlemen
46d ago
KQLab - open-source query manager for SOC teams
46d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown
46d ago
Microsoft AntiSSRF
47d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
47d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
47d ago
How fast is autonomous AI cyber capability advancing?
47d ago
YellowKey: YellowKey Bitlocker Bypass Vulnerability
47d ago
Tinker Tailor Soldier: Paper Werewolf’s latest toolkit
47d ago
126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies
47d ago
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
47d ago
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise
47d ago
[HOMELAB] Built a SOC investigation console on two old Dell boxes
48d ago
Android Intrusion Logging as a new source of data for consensual forensic analysis
48d ago
Shai-Hulud: Another Wave and Going Open Source
48d ago
A stealth approach to Process Injection - EntryPoint Hijacking
48d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
48d ago
Service Principal Sign-Ins: A blind spot that a lot are missing
48d ago
My Analysis of a Bandook RAT PCAP
48d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
48d ago
Detection Rule is here
48d ago
Owning a service principal equals owning its permissions.
48d ago
Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection
48d ago
CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.
48d ago
AI+DFIR Challenge: Share Your Disasters and Successes
49d ago
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
49d ago
Postmortem: TanStack npm supply-chain compromise
49d ago
bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages
49d ago
rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions
49d ago
Detecting Remote Thread Creation with Windows Driver
49d ago
Mythos finds a curl vulnerability
49d ago
Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details
49d ago
Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
49d ago
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
49d ago
esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app
49d ago
LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors.
49d ago
How Cloudflare responded to the “Copy Fail” Linux vulnerability
49d ago
I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic.
49d ago
LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots.
49d ago
New Shai-Hulud npm worm variant
49d ago
EtwWatcher
49d ago
Donuts and Beagles: Fake Claude site spreads backdoor
49d ago
Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach
50d ago
CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection
50d ago
Deterministic PE Validation for Blue Teams - IOCX v0.7.3
50d ago
Delving deep into threat detection: My logic for abnormal EventID 7 activity
50d ago
NZ announces sanctions on malicious Russian cyber actors, online platforms
50d ago
Update: Ongoing Checkmarx Supply Chain Security Incident
50d ago
ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025
50d ago
Unmanaged PowerShell Execution: Hunting Beyond powershell.exe
50d ago
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign
50d ago
Static Devirtualization of Themida
50d ago
Now You See Me: AADGraphActivityLogs
50d ago
[Write-up] CyberDefenders: Wiredive Lab
50d ago
page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
51d ago
JDownloader — Website installer incident (May 2026)
51d ago
The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate."
51d ago
AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT
51d ago
EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine)
51d ago
Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers
51d ago
Writing a Naive LLVM-based Devirtualizer
51d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
51d ago
When prompts become shells: RCE vulnerabilities in AI agent frameworks
52d ago
Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus
52d ago
MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174)
52d ago
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor
52d ago
Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles.
52d ago
Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026
52d ago
Member of Prolific Russian Ransomware Group Sentenced to Prison
52d ago
EasterBunny: advanced espionage artifacts attributed to APT29
52d ago
Tracking the "Sorry" Extortionist Campaign Against cPanel Websites
52d ago
PositiveIntent: Evasive loader for .NET Framework assemblies
52d ago
The Accidental C2: Exploring Dev Tunnels for Remote Access
52d ago
Living of the Land - DISM Sandbox Provider Hijack
52d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
52d ago
CTO at NCSC Summary: week ending May 10th
52d ago
ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure
52d ago
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
52d ago
Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo
52d ago
DARWIS Taka - Web vulnerability scanner with Optional AI Validation
52d ago
SunnyDayBPF: eBPF telemetry integrity research for detection engineering
52d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama
53d ago
Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou...
53d ago
Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack
53d ago
Dirty Frag: Universal Linux LPE
53d ago
Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication.
53d ago
Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea
53d ago
Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia
53d ago
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI
53d ago
Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC
53d ago
Detecting BEC Persistence with KQL
54d ago
Unpacking Russian-Iranian Private-Sector Cyber Connections
54d ago
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
54d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
54d ago
Inadvertent Injections
54d ago
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
54d ago
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
55d ago
Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed
55d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
55d ago
UAT-8302 and its box full of malware
55d ago
CVE-2026-0073 Android adbd TLS client-authentication bypass
55d ago
One KQL query you should have saved in your toolkit (most don’t)
55d ago
CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier?
55d ago
Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside
55d ago
🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records
55d ago
Popular DAEMON Tools software compromised
56d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
56d ago
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
56d ago
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
56d ago
Accelerating Vulnerability Detection and Response at Oracle
56d ago
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
56d ago
GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated.
56d ago
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
56d ago
N-Day Research with AI: Using Ollama and n8n
56d ago
38 CVEs in Healthcare Software Used by 100,000 Medical Providers
56d ago
Recursively fuzzing MS-RPC structures and monitoring using ETW
57d ago
VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases
57d ago
CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation.
57d ago
《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition)
57d ago
nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution.
57d ago
蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery.
57d ago
gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives
57d ago
Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon
57d ago
AMSI Page Guard Bypass (Rust PoC)
57d ago
Meet Bluekit: The AI-Powered All-in-One Phishing Kit
57d ago
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
57d ago
A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia
57d ago
IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect
57d ago
Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
57d ago
ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution…
57d ago
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
57d ago
[2603.28728] Study of Post Quantum status of Widely Used Protocols
57d ago
Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin
57d ago
Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning
57d ago
code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.
57d ago
Secure Boot Inventory Data In Configuration Manager
57d ago
EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time.
57d ago
MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning.
57d ago
AI-powered honeypots: Turning the tables on malicious AI agents
57d ago
copy.golf — golf your exploits - smaller copy.fail exploits..
57d ago
DragonBreath: Dragon in the Kernel
57d ago
Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors.
57d ago
Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
58d ago
Puzzle: Set of PoC to abuse Windows minifilters functionality
58d ago
A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16
58d ago
Active exploitation of cPanel/WHM critical vulnerability
58d ago
Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. "
58d ago
5 Qilin ransomware servers exposed over 7 months
58d ago
South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)
58d ago
Russian Charged in Oil and Gas Facility Hacks Pleads Guilty
58d ago
VECT ransomware: small files decrypt, large files lose their nonces
58d ago
CTO at NCSC Summary: week ending May 3rd
58d ago
April 27th - What happened with our feature flag configuration | The ClickUp Blog
58d ago
Blog: Evolving the Android & Chrome VRPs for the AI Era
59d ago
Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.
59d ago
VECT: Ransomware by design, Wiper by accident
59d ago
VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built.
59d ago
Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison
59d ago
Agentic Malware Analysis: From Task Automation to Deep Analysis
59d ago
pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner.
59d ago
month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only
59d ago
603 loaded
MA
Malware Analysis & Reports
19d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
19d ago
ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper
20d ago
WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap
20d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
20d ago
Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment
21d ago
73 Microsoft GitHub repositories impacted by Miasma malware
22d ago
Unauthorized Onlyfans Payment
22d ago
Building A Malware Lab From Scratch Part 2!
24d ago
Detecting npm Native Addon Malware: node-gyp Abuse
24d ago
Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links
25d ago
Extremely suspicious behaviour by memu emulator
26d ago
Malware
26d ago
🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop
27d ago
ChatGPT Malvertising Campaign
27d ago
Recommendation
27d ago
Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6!
27d ago
This is a scam and probably a malware/trojan. Path Of Exile 2 builder ...
28d ago
LLMShare: using shared chatbot pages to distribute malware
28d ago
How to Unpack FlawedAmmyy - Malware Unpacking Tutorial
29d ago
Building A Malware Lab From Scratch!
30d ago
I bought an old phone from 2018 and wanna destroy it with viruses for fun
30d ago
Malware escaped browser without downloading files, then escaped a virtual machine
31d ago
I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but
32d ago
A Deeper Look at GLASSWORM's Solana Variant
33d ago
Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15
33d ago
Kali365 Activity Surges: Device Code Phishing Is Scaling Fast
33d ago
MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
34d ago
Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io)
34d ago
Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down.
34d ago
How random program can cause most of antiviruses close himself without telling himself to close
35d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
35d ago
Suspicious ass website asking to run a terminal command (MacOS)
36d ago
Harvard and 140 other legitimate websites compromised
39d ago
Browser session theft is quietly becoming more dangerous than password theft
39d ago
Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
39d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account
39d ago
Database of Malicious Browser Extensions
40d ago
I’ve got 99 problems, and IOCX isn’t one.
40d ago
Can't access anything
41d ago
New GMKtec M7 Ultra appears to be infected. Beware of the malware!
42d ago
vpn explained the simple version that actually makes sense
42d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
43d ago
Netmirror exposed - The Free Movie App That Was Robbing You Blind
43d ago
Malware learning
44d ago
Brovan: Binary user-mode emulator for x86_64
45d ago
Inspecting a DLL file trying to figure out if it really is malware
46d ago
npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output
46d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
47d ago
I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable...
47d ago
clens.io - new public threat & data intel service
47d ago
Granny’s Compromised Android Firmware
48d ago
[Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
48d ago
OS scanner that checks repos for traces of the Shai Hulud worm
48d ago
Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI
48d ago
Steam spear phishing
49d ago
Fake linked in sponsored google search
49d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
49d ago
New Shai-Hulud npm worm variant
49d ago
looking for "evil" Websites
50d ago
Deterministic PE Structural Validation in IOCX v0.7.3
50d ago
sl1nk link
50d ago
How to download a RAT for myself
50d ago
Wtf OPEN Ai
52d ago
JDownloader's official website delivered Python RAT
53d ago
An unknown malware threat. There is no such thing as a 100% detection.
54d ago
Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites
54d ago
Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML
54d ago
Discord bot C2 infrastructure
55d ago
IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening
56d ago
Panicking
56d ago
Supply chain attack: DAEMON Tools Lite now contains a backdoor.
56d ago
Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation
57d ago
VirusTotal has one flag for this sus site
58d ago
Anyone wanna learn the CEH or OSCP red teaming free
58d ago
Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself
60d ago
Minecraft Malware C2 Tracking
60d ago
Minirat malware deployed via NPM targeting macOS machines
62d ago
VECT Ransomware Is Actually a Wiper
62d ago
The Malware Factory: GLASSWORM Forensics in Open VSX
62d ago
Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore
62d ago
[ Removed by Reddit ]
63d ago
Ikeja Electric Distribution Ransomware
63d ago
Recently updated a authentic minecraft mod launcher called Modrinth
63d ago
This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0
64d ago
Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely
64d ago
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses
65d ago
Save time and use Zig to write your Malware POC
66d ago
Cracking CastleLoader’s Inno Setup Password
66d ago
I built a C2 framework that uses Discord and Telegram for communication
66d ago
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet.
67d ago
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
67d ago
PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs
67d ago
Budgiekit - gdi malware maker (for educational purporses only)
68d ago
19 confirmed repos tied to the same GitHub malware campaign
69d ago
IOCX v0.7.0 — deterministic heuristics + adversarial PE samples
70d ago
I built a kernel-level EDR and hit architectural walls I didn’t expect
131d ago
Update your detection rules: New remote access Trojan
132d ago
Criminals are using AI website builders to clone major brands
132d ago
Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants)
132d ago
PE Loader For Fileless Malware
133d ago
Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers
133d ago
AWAKE - Android Wiki of Attacks, Knowledge & Exploits
133d ago
I built a Chrome extension that scans for malicious extensions (yes, I see the irony)
133d ago
Questions regarding malicious pdf's
135d ago
AV persistence bypass techniques
136d ago
Avalon Linux Bot Malware Analysis
137d ago
Leveling up in Windows malware research
138d ago
Emerging Ransomware: BQTLock and GREENBLOOD
139d ago
Malware Development POCs
139d ago
Suspicious code in Up-work linked repository.
139d ago
We hid backdoors in binaries — Opus 4.6 found 49% of them
140d ago
👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡
141d ago
Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions
141d ago
Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer
142d ago
Nyxara
145d ago
115 loaded
WE
WeLiveSecurity
19d ago · 36 items
OceanLotus: From external espionage to domestic targeting
19d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
20d ago
Cybercriminals: the 'auditors' you never hired
21d ago
Lessons for life: Why children’s data is a long-term identity risk
27d ago
This month in security with Tony Anscombe – May 2026 edition
32d ago
ESET APT Activity Report Q4 2025–Q1 2026
33d ago
What to consider before asking an AI chatbot for health advice
34d ago
BTMOB: A stealthy RAT burrowing deep into Android devices
35d ago
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
39d ago
Webworm: New burrowing techniques
41d ago
The quest for greater tech independence
42d ago
Why geopolitical turmoil is a gift for scammers, and how to stay safe
46d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
47d ago
Eyes wide open: How to mitigate the security and privacy risks of smart glasses
50d ago
Fake call logs, real payments: How CallPhantom tricks Android users
54d ago
Fixing the password problem is as easy as 123456
54d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
56d ago
This month in security with Tony Anscombe – April 2026 edition
61d ago
The calm before the ransom: What you see is not all there is
67d ago
GopherWhisper: A burrow full of malware
68d ago
New NGate variant hides in a trojanized NFC payment app
70d ago
What the ransom note won’t say
71d ago
That data breach alert might be a trap
74d ago
Supply chain dependencies: Have you checked your blind spot?
75d ago
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike
81d ago
As breakout time accelerates, prevention-first cybersecurity takes center stage
84d ago
Digital assets after death: Managing risks to your loved one’s digital estate
90d ago
This month in security with Tony Anscombe – March 2026 edition
91d ago
RSAC 2026 wrap-up – Week in security with Tony Anscombe
95d ago
A cunning predator: How Silver Fox preys on Japanese firms this tax season
95d ago
Virtual machines, virtually everywhere – and with real security gaps
97d ago
Cloud workload security: Mind the gaps
98d ago
Move fast and save things: A quick guide to recovering a hacked account
102d ago
EDR killers explained: Beyond the drivers
103d ago
Face value: What it takes to fool facial recognition
109d ago
Cyber fallout from the Iran war: What to have on your radar
110d ago
36 loaded
SM
Security | Microsoft Azure Blog | Microsoft Azure
28d ago · 6 items
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
28d ago
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
57d ago
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
60d ago
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
Azure IaaS: Keep critical applications running with built-in resiliency at scale
90d ago
Learn how Azure IaaS helps organizations start from a resilient platform foundation with availability, continuity, and recovery capabilities.
Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure
118d ago
Learn how Azure IaaS helps you modernize infrastructure, improve performance and resilience, optimize costs, and prepare for AI workloads. Read more.
Azure reliability, resiliency, and recoverability: Build continuity by design
133d ago
Learn how Azure reliability, resiliency, and recovery capabilities work together to improve cloud continuity. Read more.
SK
STÖK
37d ago · 15 items
☔️🌅
37d ago
Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs
310d ago
Winter vanlife = good times
912d ago
What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth!
918d ago
Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma
925d ago
IS THIS THE END?
985d ago
Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites
1139d ago
How to turn bugs into a "passive" income stream! ft Detectify's Almroot
1380d ago
HOW DID THIS HAPPEN!? (13370822 LHE VLOG)
1393d ago
Q: How to write a BUG BOUNTY report that actually gets paid?
1510d ago
facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques..
1524d ago
Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!)
1538d ago
Q: HOW do you get started in bug bounty?? How do you build your automation?!
1552d ago
Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR)
1566d ago
BOUNTY THURSDAYS - LIVE #2 (NEWS/TOOLS and Community Questions with Jason Haddix)
1580d ago
15 loaded
ZU
ZDI: Upcoming Advisories
61d ago · 1 items
DE
DEFCONConference
62d ago · 15 items
DEF CON 34 - DEF CON Policy Announcement - Katie Noble, Heather West
62d ago
DEF CON 33 - DisguiseDelimit: Exploiting Synology NAS with Delimiters and Novel Tricks - Ryan Emmon
131d ago
DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen - Marek Tóth
131d ago
DEF CON 33 - Can't Stop the ROP: Automating Universal ASLR Bypasses - Bramwell Brizendine
131d ago
DEF CON 33 Recon Village - How to Become One of Them: Deep Cover Ops - Sean Jones, Kaloyan Ivanov
181d ago
DEF CON 33 Recon Village - Inside the Shadows Tracking RaaS Groups, Cyber Threats - John Dilgen
181d ago
DEF CON 33 Recon Village - Autonomous Video Hunter AI Agents for Real Time OSINT - Kevin Dela Rosa
181d ago
DEF CON 33 Recon Village - A Playbook for Integration Servers - Ryan Bonner, Guðmundur Karlsson
181d ago
DEF CON 33 Recon Village - Mapping the Shadow War From Estonia to Ukraine - Evgueni Erchov
181d ago
DEF CON 33 Recon Village - Building Local Knowledge Graphs for OSINT - Donald Pellegrino
181d ago
DEF CON 33 Recon Village - OSINT & Modern Recon Uncover Global VPN Infrastructure - Vladimir Tokarev
181d ago
DEF CON 33 Recon Village - Pretty Good Pivot - Simwindie
181d ago
DEF CON 33 Recon Village - enumeraite: AI Assisted Web Attack Surface Enumeration - Özgün Kültekin
181d ago
DEF CON 33 Recon Village - OSINT Signals Pop Quiz - Master Chen
181d ago
DEF CON 33 Recon Village - Investigating Foreign Tech from Online Retailers - Michael Portera
181d ago
15 loaded
CC
CISA Cybersecurity Advisories
70d ago · 3 items
Defending Against China-Nexus Covert Networks of Compromised Devices
70d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
85d ago
U.S. organizations should review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the
Pro-Russia Hacktivists Conduct Opportunistic Attacks Against US and Global Critical Infrastructure
206d ago
The authoring organizations encourage critical infrastructure organizations to implement the recommendations in this advisory to reduce the likelihood and
BA
Blog Articles - Identity Insights | Trulioo
74d ago · 13 items
Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business
74d ago
What is Customer Due Diligence (CDD)
98d ago
Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud
101d ago
AML, KYC and Identity Verification in Australia
110d ago
When Fraud Becomes Background Noise: The Industrialization of Digital Deception
176d ago
The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage
176d ago
The End of Static KYB: Business Identity in Constant Motion
176d ago
Know Your Agent: The Next Chapter in Digital Trust
176d ago
When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage
176d ago
Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration
195d ago
The World’s Identity Platform
1246d ago
KYC: 3 Steps to Achieving Know Your Customer Compliance
1517d ago
AML Compliance Checklist: Best Practices for Anti-Money Laundering
1532d ago
13 loaded
II
InfoSec Insights
111d ago · 1 items
FP
Fraud Prevention Archives - Alloy Silverstein
117d ago · 10 items
AI in Tax Season: Risks, Scams, and How to Protect Your Data
117d ago
Tax Season Scams to Watch For This Year
124d ago
Beware of Misleading Tax Advice on Social Media
292d ago
Each year the IRS educates taxpayers on the most trending fraud schemes that could deceive individuals and businesses during tax season. In late 2024, The IRS took to warning the public against misleading “tips” or...
Scammers Up Their Game With AI
293d ago
Learn how to spot the threats and protect yourself from scammers using AI for phishing and deepfakes with smart security practices.
The Essential Guide to Safeguarding Your Online Passwords
371d ago
Protect your personal and business data with strong passwords, two-factor authentication, and smart cybersecurity practices.
Beware: Tax Season is Scam Season
482d ago
Tax season is also prime time for tax scams. To safeguard your personal information, consider these key points: Communication methods The IRS initiates contact primarily through mail, not email or phone calls. Be cautious of...
Stop Scams: Fraud Prevention Starts with Your Employees
495d ago
You can be as proactive and protective as possible when it comes to cyber security for your business, but there’s one vulnerability you cannot eliminate: human error. In fact, statistics estimate that as much as...
‘Tis the Season for Holiday Shopping Scams
568d ago
The holidays are typically the time of year for gifting presents to friends and family or donations to charity. Unfortunately, not-so-jolly fraudsters take advantage of this generosity. Protect yourself by watching for these common scams:.....
IRS Issues “Dirty Dozen” Fraud Warnings
753d ago
Each year, the IRS releases a “Dirty Dozen” series to highlight the most common fraud schemes taxpayers should be aware of.
IRS Identity Theft Season Begins Now
882d ago
Each year thieves try to steal billions in federal withholdings by stealing your identity. As the IRS focuses more attention on this quickly growing problem, now is the time of year to be extra vigilant....
LI
LiveOverflow
117d ago · 15 items
Security-driven Rapid Release - Pwn2Own Documentary (Part 4)
117d ago
Firefox JIT Bug - Pwn2Own Documentary (Part 3)
120d ago
The First Exploit - Pwn2Own Documentary (Part 2)
124d ago
The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)
127d ago
From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi
447d ago
The German Hacking Championship
473d ago
Do you know this common Go vulnerability?
487d ago
Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1)
622d ago
My theory on how the webp 0day was discovered #short
638d ago
My theory on how the webp 0day was discovered (BLASTPASS)
639d ago
Learn Android Hacking! - University Nevada, Las Vegas (2024)
665d ago
My Trip to Las Vegas for DEFCON & Black Hat
679d ago
Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
890d ago
A Vulnerability to Hack The World - CVE-2023-4863
922d ago
Reinventing Web Security
952d ago
15 loaded
HA
HackerSploit
447d ago · 15 items
How FIN6 Exfiltrates Files Over FTP
447d ago
Emulating FIN6 - Active Directory Enumeration Made EASY
498d ago
The SECRET to Embedding Metasploit Payloads in VBA Macros
503d ago
Offensive VBA 0x4 - Reverse Shell Macro with Powercat
511d ago
Offensive VBA 0x3 - Developing PowerShell Droppers
517d ago
Offensive VBA 0x2 - Program & Command Execution
522d ago
Offensive VBA 0x1 - Your First Macro
524d ago
Emulating FIN6 - Gaining Initial Access (Office Word Macro)
529d ago
FIN6 Adversary Emulation Plan (TTPs & Tooling)
533d ago
Developing An Adversary Emulation Plan
533d ago
Introduction To Advanced Persistent Threats (APTs)
537d ago
Introduction To Adversary Emulation
559d ago
Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion
568d ago
Planning Red Team Operations | Scope, ROE & Reporting
708d ago
Mapping APT TTPs With MITRE ATT&CK Navigator
712d ago
15 loaded
TH
Threatpost
1399d ago · 10 items
Student Loan Breach Exposes 2.5M Records
1399d ago
2.5 million people were affected, in a breach that could spell more trouble down the line.
Watering Hole Attacks Push ScanBox Keylogger
1400d ago
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
1401d ago
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Ransomware Attacks are on the Rise
1404d ago
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
1404d ago
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Twitter Whistleblower Complaint: The TL;DR Version
1406d ago
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Firewall Bug Under Active Attack Triggers CISA Warning
1407d ago
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Fake Reservation Links Prey on Weary Travelers
1408d ago
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
iPhone Users Urged to Update to Patch 2 Zero-Days
1411d ago
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Google Patches Chrome’s Fifth Zero-Day of the Year
1412d ago
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
No matching sources found.