Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight
New Android malware relays bank cards to fraudsters while victims still hold them
Group-IB discovered WindRelay, a new Android malware built to capture live payment card data over NFC and relay it to attackers in real time.
OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode
OpenAI previews GPT-5.6 Sol Ultrafast, delivering up to 14x faster processing for coding, research and interactive applications.
AWS Certificate Manager sets 2027 end date for email-validated certificate renewals
AWS Certificate Manager will stop renewing email-validated certificates in September 2027. Customers should migrate to DNS validation.
Ukrainian police raid 94 fraudulent call centers, seize $2 million
Ukraine's police shut down 94 fraudulent call centers, searched 411 locations, and seized millions in cash, crypto, and equipment.
The hardest part of agentic AI may be rebuilding the business
The agentic AI readiness gap persists as businesses struggle with workforce skills, process redesign, data, governance, and costs.
Weak IAM affects up to 98% of cloud environments
Explore cloud misconfiguration trends across AWS, Azure, and Google Cloud, revealing key risks, platform differences, and remediation times.
17 draft Cyber Resilience Act standards are open for comment
17 draft Cyber Resilience Act standards are open for comment until November, ahead of the EU's end-of-2027 compliance deadline.
New infosec products of the week: August 14, 2026
Here’s a look at the most interesting products from the past week, featuring releases from A10, ScienceLogic, Searchlight Cyber, and more.
White House authorizes private US companies to hack foreign criminal networks
President Trump signed a memo allowing vetted private companies to run offensive cyber operations against foreign threat actors.
What's New
Top 5 Across All Sources-
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day
Help Net Security · 1h ago -
Black Hat Asia 2026 | Cyber-Paleontology in the Age of AI
Black Hat · 8h ago -
HackTheBox - Cobblestone
IppSec · 17h ago -
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
BleepingComputer · 17h ago
Gigafeed (5290 entries)
Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day Help Net Security · 1h ago Black Hat Asia 2026 | Cyber-Paleontology in the Age of AI Black Hat · 8h ago Black Hat Asia 2026 | Discovering React2Shell: JavaScript’s Long-Awaited Deserialization Flight-mare Black Hat · 10h ago HackTheBox - Cobblestone IppSec · 17h ago New Evooo1Bot Linux botnet turns routers into traffic relay nodes BleepingComputer · 17h ago No space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntable Latest news · 22h ago Chromium: CVE-2026-19560 Use after free in Blink MSRC Security Update Guide · 1d ago Chromium: CVE-2026-19559 Use after free in HTML MSRC Security Update Guide · 1d ago Chromium: CVE-2026-19558 Use after free in Extensions MSRC Security Update Guide · 1d ago Chromium: CVE-2026-19557 Use after free in TabStrip MSRC Security Update Guide · 1d ago Chromium: CVE-2026-19556 Use after free in V8 MSRC Security Update Guide · 1d ago How Anthropic plans to watermark Claude's AI-generated text BleepingComputer · 1d ago New York City Lawmakers Push to ‘Ban the Scan’ at MSG Security Latest · 1d ago Investigation of banking hack leads to arrests in Europe, Brazil The Record from Recorded Future News · 1d ago Black Hat Asia 2026 | Post-Quantum Cryptography: A Realistic Guide to Manage the Transition Black Hat · 1d ago Cisco Advance Notification for Publication of August 19, 2026, Security Advisories Cisco Security Advisory · 1d ago Vulnerability giving attackers full control of Macs is under active exploitation Security - Ars Technica · 1d ago Hackers arrested over €30M bank fraud exploiting service provider flaw BleepingComputer · 1d ago your home router STILL SUCKS!! (use OPNsense instead) NetworkChuck · 1d ago Black Hat Asia 2026 | Network Operations Center (NOC) Report Black Hat · 1d ago Google Meet can take notes for your in-person meetings now - here's how it works Latest news · 1d ago I tested an Android app that lets anyone fight censorship - and shows your impact in real time Latest news · 1d ago Apple is warning users of new spyware attacks - what to do if you're a target Latest news · 1d ago ChatGPT's new Computer History tracks your Mac activity to create a timeline - but should you let it? Latest news · 1d ago Soft Skills for the Job Market: Standing Out! The Cyber Mentors · 1d ago Dell XPS 13 review: The first budget laptop to rival Neo raises the bar for all PCs Latest news · 1d ago Hackers exploit macOS Screen Sharing flaw to deploy Monero miner BleepingComputer · 1d ago Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers You're Not Using (Yet) Black Hat · 1d ago How to Detect Fake Cell Towers Near You David Bombal · 1d ago The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI BleepingComputer · 1d ago CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-62746 Win32k Information Disclosure Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-58612 PowerShell Information Disclosure Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability MSRC Security Update Guide · 1d ago CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability MSRC Security Update Guide · 1d ago Max severity SAP Commerce Cloud flaw now targeted in attacks BleepingComputer · 1d ago France investigates tax authority breach after hacker claims 600,000 victims The Record from Recorded Future News · 1d ago In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities SecurityWeek · 1d ago Shell investigates 'potential incident' after Clop data theft claims BleepingComputer · 1d ago I used OpenFactory to build my own Linux distro overnight - this AI tool is going to be big Latest news · 1d ago Trivy, Not LiteLLM Behind the 2,500 Org Compromise SecurityWeek · 1d ago Who’s Tracking You? Use This New Service to Find Out Krebs on Security · 1d ago New Android malware relays bank cards to fraudsters while victims still hold them Help Net Security · 1d ago Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal SecurityWeek · 1d ago OpenAI’s GPT-5.6 Sol runs up to 14× faster with Ultrafast mode Help Net Security · 1d ago RingCentral data breach exposed info of 1.6 million accounts BleepingComputer · 1d ago 1.6 Million Likely Impacted by RingCentral Data Breach SecurityWeek · 1d ago Over 1,000 Charities Hit by Beacon CRM Data Breach SecurityWeek · 1d ago APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit Securelist · 1d ago Data analyst sent to prison for stealing data, extorting employer BleepingComputer · 1d ago AWS Certificate Manager sets 2027 end date for email-validated certificate renewals Help Net Security · 1d ago 14,000 Trezor Customers Impacted by Data Breach at ShipMonk SecurityWeek · 1d ago Ukrainian police raid 94 fraudulent call centers, seize $2 million Help Net Security · 2d ago Hackers Exploiting Unpatched GeoServer Zero-Day SecurityWeek · 2d ago AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions SecurityWeek · 2d ago The hardest part of agentic AI may be rebuilding the business Help Net Security · 2d ago Weak IAM affects up to 98% of cloud environments Help Net Security · 2d ago 17 draft Cyber Resilience Act standards are open for comment Help Net Security · 2d ago New infosec products of the week: August 14, 2026 Help Net Security · 2d ago Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks BleepingComputer · 2d ago This free Android assistant fixes my biggest Gemini frustration - and keeps my data private Latest news · 2d ago Black Hat Asia 2026 | Beyond the Golden Image: A Self-Healing Image Supply Chain Black Hat · 2d ago Ukraine shuts down 94 fraudulent call centers, seize millions in cash BleepingComputer · 2d ago Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt BleepingComputer · 2d ago I tried the new ChatGPT Desktop App for Linux - but I'll stick to my browser for now Latest news · 2d ago ClamAV Vulnerabilities Affecting Cisco Products: August 2026 Cisco Security Advisory · 2d ago Black Hat Asia 2026 | Inside Cybercrime Inc: Lessons From Covering the Global Fraud Boom Black Hat · 2d ago Private security firms will soon be allowed to hack overseas cybercriminals Security - Ars Technica · 2d ago Black Hat Asia 2026 | Keynote: Privacy is the Captain. Security is the Practice. Black Hat · 2d ago Hackers breach govt webmail while running parallel crypto fraud BleepingComputer · 2d ago Black Hat Vault | Cyber Granny Black Hat · 2d ago Nobody Uses This Old Stuff! David Bombal · 2d ago Microsoft patches LegacyHive Windows zero-day vulnerability BleepingComputer · 2d ago AI 'watermark removers' flood the web. Almost none can prove they work. BleepingComputer · 2d ago Gemini voice calling on Android Auto keeps failing me - and Google has until September to fix it Latest news · 2d ago Flock tightens privacy controls amid scandals over officer abuse The Record from Recorded Future News · 2d ago Critical VMware vCenter RCE flaw exploited for reverse SSH access BleepingComputer · 2d ago This Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on sale Latest news · 2d ago New Mirai variant adds stealth capabilities to notorious botnet code The Record from Recorded Future News · 2d ago I wore Samsung's and Apple's Ultra smartwatches for 3 weeks - apps made all the difference Latest news · 2d ago From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained Technical Information Security Content & Discussion · 2d ago You're using DND all wrong: 5 powerful Do Not Disturb settings to try on your iPhone today Latest news · 2d ago Trezor discloses data breach affecting nearly 14,000 customers BleepingComputer · 2d ago Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 SecurityWeek · 2d ago White House authorizes private US companies to hack foreign criminal networks Help Net Security · 2d ago Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era? WeLiveSecurity · 2d ago Adobe Commerce Bug Targeted Immediately After Disclosure SecurityWeek · 2d ago Black Hat Stories | Daniel Cuthbert Black Hat · 2d ago Phishing Gets Personal John Hammond · 2d ago Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion BleepingComputer · 2d ago Brazil orders Discord to suspend livestreaming after teen suicide The Record from Recorded Future News · 2d ago Microsoft is merging Copilot and Copilot 365 into one unified app - and retiring 3 features Latest news · 2d ago White House taps security firms for offensive hack-back operations BleepingComputer · 2d ago I Made AI Build a Cybersecurity Mod in Minecraft John Hammond · 2d ago Can AI do novel security research? Meet the HTTP Terminator Technical Information Security Content & Discussion · 2d ago 75% of developers I surveyed prefer Claude Code - here's why they choose it over Codex Latest news · 2d ago WhatsApp rolls out new feature that flags potential scam messages BleepingComputer · 2d ago Android can now tap to share for contact info, photos, and more - which phones get it first Latest news · 2d ago A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months Technical Information Security Content & Discussion · 2d ago CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues Security Latest · 2d ago The best password managers of 2026: Expert tested Latest news · 2d ago The best antivirus software to protect your computer in 2026 Latest news · 2d ago Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility WeLiveSecurity · 2d ago Armored Likho expands its cyber-espionage toolkit Securelist · 3d ago Attackers Exploit SharePoint Authentication Bypass After Public PoC Release The Hacker News · 3d ago 'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today Latest news · 3d ago Malware Crypting Services and the Threat Actors Who Sell Them Recorded Future · 3d ago "City-Forum" data-theft attacks target Salesforce, ServiceNow portals BleepingComputer · 3d ago Android malware combo takes out loans and relays victims' credit cards BleepingComputer · 3d ago Terabytes of credentials leaked in massive supply-chain attack Security - Ars Technica · 3d ago Hackers exploit critical Adobe Commerce flaw to hijack customer accounts BleepingComputer · 3d ago Hundreds of fake Chrome VPN extensions route traffic through a proxy BleepingComputer · 3d ago Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor The Hacker News · 3d ago Every Amazon Google Pixel 11 preorder deal - get up to $350 on an Amazon gift card, free Latest news · 3d ago Plug and Pwn attack uses fake USB devices for Windows SYSTEM access BleepingComputer · 3d ago Lazarus hackers exploited Windows zero-day to target defense firms BleepingComputer · 3d ago FBI: Hackers target online accounts to steal nude photos BleepingComputer · 3d ago 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One The Hacker News · 3d ago The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In BleepingComputer · 3d ago Black Hat Stories | More Than a Conference Black Hat · 3d ago Researchers found a way to hijack devices through Zoom screen sharing Security - Ars Technica · 3d ago Black Hat USA 2026: AI is racing ahead of cybersecurity controls WeLiveSecurity · 3d ago I Found an MFA-Bypassing Phishing Kit on the Dark Web John Hammond · 3d ago I Went to the World's Biggest Hacker Conference (DEFCON VLOG) NahamSec · 3d ago Hackers leverage new Microsoft SharePoint exploit in attacks BleepingComputer · 3d ago This Coin-Sized Device Can Hack a Boeing 737 Security Latest · 3d ago OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning The Hacker News · 3d ago Enterprise Defenses Recovered at the Edge and Collapsed Inside The Hacker News · 3d ago Signal adds new security feature to thwart man-in-the-middle attacks BleepingComputer · 3d ago Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws The Hacker News · 3d ago CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix Technical Information Security Content & Discussion · 3d ago New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges BleepingComputer · 3d ago ‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware Security Latest · 3d ago ERPNext's Document Follow feature exposed unauthorized data Technical Information Security Content & Discussion · 3d ago Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access The Hacker News · 3d ago Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations The Hacker News · 4d ago SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code The Hacker News · 4d ago ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access The Hacker News · 4d ago Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS The Hacker News · 4d ago Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse BleepingComputer · 4d ago GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group) Technical Information Security Content & Discussion · 4d ago DEF CON crowd suspected in fake-hotspot attack on Delta flight Security - Ars Technica · 4d ago Three Decades of Influence | Why Black Hat Matters Black Hat · 4d ago DeadLock ransomware uses blockchain to resist infrastructure takedown BleepingComputer · 4d ago Microsoft Plugs Nearly 400 Security Holes Krebs on Security · 4d ago Black Hat Stories | Gaurav Keerthi, CEO and founder of StrongKeep Black Hat · 4d ago Sandworm hackers target IT pros with trojanized WireGuard VPN client BleepingComputer · 4d ago Chrome adopts what may be the best protection yet against account takeovers Security - Ars Technica · 4d ago Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10 Technical Information Security Content & Discussion · 4d ago Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack The Hacker News · 4d ago Cisco warns of ASA and FTD VPN flaw exploited to crash devices BleepingComputer · 4d ago Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing The Hacker News · 4d ago Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client The Hacker News · 4d ago Cisco Secure Firewall Management Center Software Static Credential Vulnerability Cisco Security Advisory · 4d ago Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands The Hacker News · 4d ago Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees BleepingComputer · 4d ago Microsoft releases Windows 10 KB5120249 extended security update BleepingComputer · 4d ago DEF CON 34 - Video Team - Hackers dot Town - The Gibson DEFCONConference · 4d ago DEF CON 34 - Video Team - Car Hacking Villlage DEFCONConference · 4d ago DEF CON 34 - Video Team - Ham Radio Village - Marvin Goes HAM DEFCONConference · 4d ago Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days BleepingComputer · 4d ago DEF CON 34 - Video Team - Physical Security Village DEFCONConference · 4d ago DEF CON 34 - Video Team - LEECH DEFCONConference · 4d ago DEF CON 34 - Video Team - EmbeddedSystems Village DEFCONConference · 4d ago DEF CON 34 - Video Team - PhreakMe DEFCONConference · 4d ago Windows 11 KB5121003 & KB5120240 cumulative updates released BleepingComputer · 4d ago Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE The Hacker News · 4d ago Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability Cisco Security Advisory · 4d ago DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The Hacker News · 4d ago Wesco confirms security incident after ExfilSquad claims data theft BleepingComputer · 4d ago CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106) Technical Information Security Content & Discussion · 4d ago This Hacker Trap Was Built by AI John Hammond · 4d ago ETW for Security Research: Providers, Sessions, and Detection Engineering Technical Information Security Content & Discussion · 4d ago Mozilla updates GPG signing key for Firefox releases after exposure BleepingComputer · 4d ago Vague Task, Total Access: When AI Delegation Becomes a Security Risk BleepingComputer · 4d ago New surveillance tech links your phone to your license plate Security - Ars Technica · 4d ago OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development The Hacker News · 4d ago DDoS attacks over 1 Tbps surged fivefold in the second quarter BleepingComputer · 4d ago A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call Security Latest · 4d ago CISA: Microsoft SharePoint flaw now exploited in ransomware attacks BleepingComputer · 4d ago A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices The Hacker News · 4d ago Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo The Hacker News · 4d ago Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants Securelist · 4d ago New Pass-ta-key attack reveals all the things we didn't know about passkeys Security - Ars Technica · 4d ago Cisco warns of high-severity ClamAV flaws with public exploits BleepingComputer · 4d ago SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn't Work Revealed a Kernel-Wide Design Compromise Technical Information Security Content & Discussion · 4d ago Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection Securelist · 4d ago US and South Korea warn of Gunra ransomware targeting govt agencies BleepingComputer · 4d ago Mandatory User Profile for Persistence & EDR Evasion Technical Information Security Content & Discussion · 4d ago Mines, Minds, and Machines: The Journey of AI Recorded Future · 5d ago Hackers breached a small Polish energy plant via private APN last year BleepingComputer · 5d ago BdThemes plugins supply-chain hack creates rogue WordPress admins BleepingComputer · 5d ago OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users BleepingComputer · 5d ago Inside a Russian-speaking operator's toolkit for compromising Ukrainian IP cameras Technical Information Security Content & Discussion · 5d ago New StormEncryptor ransomware used by former Medusa affiliate BleepingComputer · 5d ago Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft Security Blog · 5d ago DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure Microsoft Security Blog · 5d ago CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs BleepingComputer · 5d ago A researcher bought noreply.net. Companies started sending him secrets. Security - Ars Technica · 5d ago When Credentials Are No Longer Enough: Device Trust in the AI Era BleepingComputer · 5d ago Member of The Com sent to prison for blackmail, sextortion BleepingComputer · 5d ago LexisNexis shuts down services after suspicious activity on servers BleepingComputer · 5d ago Valve notifies Steam hardware customers of a data breach BleepingComputer · 5d ago IT threat evolution in Q2 2026. Non-mobile statistics Securelist · 5d ago IT threat evolution in Q2 2026. Mobile statistics Securelist · 5d ago Critical Progress LoadMaster flaw now actively exploited in attacks BleepingComputer · 5d ago Are AI tutors safe for your kids? WeLiveSecurity · 5d ago The Hugging Face Hack Was Cheap Persistence at Work Recorded Future · 6d ago Beyond Prompt Injection: Hacking Apple's Private Cloud Compute Technical Information Security Content & Discussion · 6d ago DEF CON 34 - Video Team - Voting Machine Hacking Village DEFCONConference · 6d ago DEF CON 34 - VideoTeam - Cliff Stoll AfterHours DEFCONConference · 6d ago When terrible disclosure from the vendor results in zero days plus a fun dive in to bypassing full disk encryption Technical Information Security Content & Discussion · 6d ago Do You Need a VPN in 2026? Here’s the Truth David Bombal · 6d ago DEFCON: New Red Team Tactic Technical Information Security Content & Discussion · 7d ago DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking DEFCONConference · 7d ago DEF CON 34 - Video Team - Hak5 - Darren Kitchen DEFCONConference · 7d ago DEF CON 34 - Video Team - AI Hacking Village - Pokemon DEFCONConference · 7d ago DEF CON 34 - Video Team - No Starch Press DEFCONConference · 7d ago DEF CON 34 - Video Team - Goon Questions -Guzi Media DEFCONConference · 7d ago DEF CON 34 - Video Team -Bug Bounty Village DEFCONConference · 7d ago Analyzing a Multi-Stage PowerShell Payload Chain Technical Information Security Content & Discussion · 7d ago HackTheBox - Helix IppSec · 7d ago Hackers breach TrueConf to trojanize client installers with backdoors BleepingComputer · 7d ago DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE Technical Information Security Content & Discussion · 7d ago Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed Security Latest · 7d ago Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All Security Latest · 7d ago Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village) Technical Information Security Content & Discussion · 7d ago RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data Technical Information Security Content & Discussion · 8d ago SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab Technical Information Security Content & Discussion · 8d ago Black Hat USA 2026 | Reverse Engineering GCD, XPC Races, and macOS Detection Black Hat · 8d ago Black Hat USA 2026 | Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius Black Hat · 8d ago Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability Cisco Security Advisory · 8d ago Metabase SQLi zero-day exploited in customer data-theft attacks BleepingComputer · 8d ago Unlimited Technology Systems breach impacts 3.8 million people BleepingComputer · 8d ago More than half of AI-generated patches are broken CyberScoop · 8d ago Learn Fault Injection at DEF CON 2026 LiveOverflow · 8d ago Levi Strauss & Co. says hackers stole corporate data in cyberattack BleepingComputer · 8d ago Russian hackers can steal emails without a click Proofpoint News Feed · 8d ago Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports CyberScoop · 8d ago Real emails, hijacked payments: Two H1 2026 attack chains BleepingComputer · 8d ago North Carolina Ports confirms cyberattack disrupting operations BleepingComputer · 8d ago July 2026 CVE Landscape Recorded Future · 9d ago OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it BleepingComputer · 9d ago OSPF From Zero: Let's Build the Internet (Well...Almost) | Summer of CCNA NetworkChuck · 9d ago ClickFix attack pushes macOS infostealer for crypto theft attacks BleepingComputer · 9d ago Hackers Stalked Me by Hijacking a Smartwatch for Kids Security Latest · 9d ago Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams CyberScoop · 9d ago Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group BleepingComputer · 9d ago Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online CyberScoop · 9d ago Swiss government SharePoint breach compromised 200 accounts BleepingComputer · 9d ago Ransom Cartel creator sentenced to 16 years in prison CyberScoop · 9d ago New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes BleepingComputer · 9d ago Canadian Man Pleads Guilty in Snowflake Extortions Krebs on Security · 9d ago Meta AI model hacked a company during misconfigured cyber test BleepingComputer · 9d ago The risk awareness radar. A superpower every MSP needs to train Heimdal Security Blog · 9d ago How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore BleepingComputer · 9d ago The water sector just got it’s wake-up call. Again. CyberScoop · 9d ago OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree Security Latest · 10d ago Emerging Threats to Neurotechnology Recorded Future · 10d ago A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide Security Latest · 10d ago OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts Security Latest · 10d ago Ransom Cartel ransomware creator sentenced to 16 years in prison BleepingComputer · 10d ago Thousands of servers can be backdoored by exploiting buggy motherboard controllers Security - Ars Technica · 10d ago Canadian pleads guilty to Snowflake cloud data-theft attacks BleepingComputer · 10d ago Snowflake hacker pleads guilty, faces up to 32 years in prison CyberScoop · 10d ago Anthropic’s AI used fake identities, malware in rogue attack on GitHub project Security - Ars Technica · 10d ago DHS Wants Protesters’ Signal Group Chats Security Latest · 10d ago Hackers run khunt post-exploitation toolkit from Oracle database BleepingComputer · 10d ago The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop Security Latest · 10d ago Tom Cotton prods Treasury for tax code tweaks to modernize OT CyberScoop · 10d ago COLDCARD security audit phishing attack installs remote access tool BleepingComputer · 10d ago DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad Security Latest · 10d ago Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) Microsoft Security Blog · 10d ago Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery Security Latest · 10d ago Cisco Advance Notification for Publication of August 5, 2026, Security Advisories Cisco Security Advisory · 10d ago Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability Cisco Security Advisory · 10d ago Cisco Integrated Management Controller Cross-Site Scripting Vulnerability Cisco Security Advisory · 10d ago Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability Cisco Security Advisory · 10d ago Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability Cisco Security Advisory · 10d ago Cisco IOS XE Software SNMP Denial of Service Vulnerability Cisco Security Advisory · 10d ago Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability Cisco Security Advisory · 10d ago Cisco IOS XE Software Security Hardening Release: August 2026 Cisco Security Advisory · 10d ago Cisco Integrated Management Controller Argument Injection Vulnerabilities Cisco Security Advisory · 10d ago Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability Cisco Security Advisory · 10d ago Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 Cisco Security Advisory · 10d ago Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability Cisco Security Advisory · 10d ago CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws BleepingComputer · 10d ago From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide Microsoft Security Blog · 10d ago I’m headed to DEFCON! NahamSec · 10d ago Google Blogger locks hundreds of blogs in malware false positive BleepingComputer · 10d ago Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Security Advisory · 10d ago How AI-powered phishing killed blocklists for good BleepingComputer · 10d ago Open-source software’s archenemy TeamPCP goes back further than anyone thought CyberScoop · 10d ago AI is getting better at election facts, but voters shouldn’t rely on it CyberScoop · 10d ago National cyber director lays out White House plans to secure AI without writing new rules CyberScoop · 11d ago Hype vs. Reality: What the Hugging Face Incident Means for AI Safety Recorded Future · 11d ago ChainDrop supply chain compromise: Anatomy of a self-propagating worm Microsoft Security Blog · 11d ago OpenAI, Anthropic AI agents targeted real people and systems in cyber tests BleepingComputer · 11d ago OK, Well, Rogue AI Agents Are Hacking Again Security Latest · 11d ago AISI, OpenAI report more ‘unsanctioned’ model hacks CyberScoop · 11d ago TP-Link patches Omada ZTP flaws allowing hackers to breach networks BleepingComputer · 11d ago Phishing service spoofs RingCentral to steal Microsoft 365 accounts BleepingComputer · 11d ago New XCSSET variant targets macOS devs via compromised Xcode projects BleepingComputer · 11d ago 77 Open VSX extensions found harvesting developer info BleepingComputer · 11d ago Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps Microsoft Security Blog · 11d ago 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET Microsoft Security Blog · 11d ago Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal Security Latest · 11d ago Massive ChainDrop npm supply-chain attack infects hundreds of packages BleepingComputer · 11d ago Varonis Agent IBAC keeps AI agents within their intended boundaries BleepingComputer · 11d ago How legitimate cloud platforms enable phishers to bypass MFA Securelist · 11d ago Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats Proofpoint News Feed · 11d ago Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities Proofpoint News Feed · 11d ago Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts BleepingComputer · 12d ago New Pass-ta-key attacks let malware hijack Google-synced passkeys BleepingComputer · 12d ago Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack CyberScoop · 12d ago Does AI Content Have to be Authentic — or Can It Just Be Effective? Blog – Forter · 12d ago New DOUBLECUP ClickFix service hides malware in browser cache images BleepingComputer · 12d ago Fake Roblox Xeno script launcher pushes infostealer, RAT malware BleepingComputer · 12d ago N-able warns of N-central auth bypass flaw exploited in attacks BleepingComputer · 12d ago ExfilSquad hackers leak info of over 100,000 UK police officers, staff BleepingComputer · 12d ago Inside the Underground Business of the Android BTMOB RAT malware BleepingComputer · 12d ago Cyber Deception Everywhere John Hammond · 12d ago An analysis of incidents at Brazilian educational institutions Securelist · 12d ago Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS) NahamSec · 12d ago ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children Security Latest · 12d ago CrowdStrike: AI is now both the weapon and the target in cyberattacks CyberScoop · 13d ago Are you ready for this year's @BugBountyVillage at @DEFCONConference NahamSec · 13d ago 8 Ways AI is Changing Threat Intelligence Recorded Future · 13d ago OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems BleepingComputer · 13d ago COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft BleepingComputer · 13d ago Google Chrome may soon block New Tab hijacker extensions by default BleepingComputer · 13d ago 1.5 Gbps Internet using your old telephone cables? David Bombal · 13d ago 8 Best Password Managers (2026), Tested and Reviewed Security Latest · 13d ago HackTheBox - Kobold IppSec · 14d ago Rails patches critical Active Storage flaw with RCE potential BleepingComputer · 14d ago 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran Security Latest · 14d ago Defcon's new badge is a security key you can see inside Security - Ars Technica · 14d ago JHT Course Launch! Home Labs with Proxmox John Hammond · 15d ago Amgen says cloud data breach exposed patient health, proprietary info BleepingComputer · 15d ago Arch Linux disables AUR package adoption to stop malware flood BleepingComputer · 15d ago Online ad firm Adform’s script compromised to steal cryptocurrency BleepingComputer · 15d ago CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Microsoft Security Blog · 15d ago Claude published malicious code to the Internet and attacked 3 real companies Security - Ars Technica · 15d ago Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world CyberScoop · 15d ago OpenAI says its new GPT 5.6 models are becoming more cost-efficient BleepingComputer · 15d ago Hacker uses DeepSeek AI to autonomously attack vulnerable servers BleepingComputer · 15d ago CISA warns of cyberattacks disrupting U.S. water utilities BleepingComputer · 15d ago This month in security with Tony Anscombe – July 2026 edition WeLiveSecurity · 15d ago AI scammers outperform humans when it comes to building trust Security - Ars Technica · 15d ago ESET tracks rise in malicious AI skills and adaptable malware BleepingComputer · 15d ago The DEF CON Advice Nobody Gives You | Threat Wire Hak5 · 15d ago Do you guys agree? #hacking #bugbounty NahamSec · 15d ago Network Anomaly Detection in KATA Securelist · 15d ago What the Hugging Face breach reveals about defense in the age of agentic AI CyberScoop · 15d ago GTA Malware Trap John Hammond · 15d ago Anthropic says its AI accidentally hacked three companies during safety tests CyberScoop · 16d ago Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests BleepingComputer · 16d ago South Korea fines telco giant KT $39 million for customer data breach BleepingComputer · 16d ago JetBrains warns of critical TeamCity remote code execution flaw BleepingComputer · 16d ago Max-severity Exchange server flaw under active exploitation by Kremlin hackers Security - Ars Technica · 16d ago Okta’s deal for Permiso aims to close gaps in identity threat detection CyberScoop · 16d ago Max-severity Exchange server flaw under active exploitation by Kremlin hackers Proofpoint News Feed · 16d ago CISA issues recommendations to federal agencies on open-source software security CyberScoop · 16d ago Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers BleepingComputer · 16d ago VMware fixes three critical flaws allowing auth bypass, VM escapes BleepingComputer · 16d ago Google says AI helped Chrome fix 1,072 security bugs in two releases BleepingComputer · 16d ago Read This Before You Buy That TV Streaming Stick Krebs on Security · 16d ago ShinyHunters claims Brinks Home breach, threatens to leak stolen data BleepingComputer · 16d ago What’s new in Microsoft Security: July 2026 Microsoft Security Blog · 16d ago Microsoft Teams vishing attacks lead to Chaos ransomware attacks BleepingComputer · 16d ago We know how to protect our troops from telecom attacks. We’re just not doing it. CyberScoop · 16d ago Analog Devices discloses data breach, says operations unaffected BleepingComputer · 16d ago OpenAI Turned Off the Guardrails | Threat Wire Hak5 · 16d ago Meet TCM Security at DEF CON 34! The Cyber Mentors · 16d ago Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims CyberScoop · 16d ago After the Break-In: What Attackers Do Once They're Already Inside BleepingComputer · 16d ago Rediscover Maltego in 2026 David Bombal · 16d ago The next measure of AI momentum is work transformed Microsoft 365 Blog · 16d ago Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes Heimdal Security Blog · 16d ago OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia Securelist · 16d ago Beyond the screenshot: Why you should verify what you see WeLiveSecurity · 16d ago How Heimdal grew from a bold idea into a global cybersecurity platform Heimdal Security Blog · 16d ago MediaArena malvertising: why a quarantine isn’t the end of the incident Heimdal Security Blog · 16d ago Real Folks of Cyber | Andrew Crotty | DITL The Cyber Mentors · 17d ago Iran War’s Secondary Effects Shape 2026 US Violent Extremism Recorded Future · 17d ago Dealing with AI-Generated Extortion Recorded Future · 17d ago Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility Trend Micro Research, News, Perspectives · 17d ago Russian hackers exploit Exchange OWA zero-day for long-term mailbox access BleepingComputer · 17d ago Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission Security - Ars Technica · 17d ago Cisco warns of FMC static credential flaw exploited in zero-day attacks BleepingComputer · 17d ago A little-known npm package was North Korea’s warm-up act for the axios hack CyberScoop · 17d ago Anthropic confirms Claude is down worldwide BleepingComputer · 17d ago Supply chain challenges loom large in quantum race, White House official says CyberScoop · 17d ago Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare BleepingComputer · 17d ago Huntress warns about attack spree that hit 30 SonicWall customers in 2 days CyberScoop · 17d ago OpenAI agent used exposed credentials at 4 services in Hugging Face breach BleepingComputer · 17d ago Better security starts with better questions Microsoft Security Blog · 17d ago Anthropic is finding bugs faster than Microsoft can fix them Security - Ars Technica · 17d ago Minecraft Security Mods John Hammond · 17d ago Hackers target over 30 Minnesota water utilities in coordinated OT attack BleepingComputer · 17d ago Your AI Agents Are Guessing at Scale: Permissions Decide the Damage BleepingComputer · 17d ago Windows 11 KB5101684 update released with 42 changes and fixes BleepingComputer · 17d ago These near-mint ASUS Chromebook refurbs are only $145 BleepingComputer · 17d ago Payload Podcast 010 - Olaf Hartong John Hammond · 17d ago Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave Trend Micro Research, News, Perspectives · 18d ago We now have a better understanding how OpenAI hacked into Hugging Face Security - Ars Technica · 18d ago CubePilot drone software dev hit by DNS hijacking to intercept traffic BleepingComputer · 18d ago OpenAI models used Artifactory zero-days to escape to the internet BleepingComputer · 18d ago CISA shares advice on isolating vital systems during cyberattacks BleepingComputer · 18d ago vBulletin fixes critical pre-auth RCE flaw with public exploit BleepingComputer · 18d ago Tools Change. Teach People How to Keep Up Heimdal Security Blog · 18d ago Is Your SSO Protected Against Modern Credential Attacks? BleepingComputer · 18d ago Over 24,000 exposed server BMCs leak password hash via decades-old flaw BleepingComputer · 18d ago Data breach at medical billing firm MCBS affects 1.26 million people BleepingComputer · 18d ago Hackers target US firms in FastJson RCE zero-day attacks BleepingComputer · 19d ago Arista patches VeloCloud Orchestrator zero-day exploited in attacks BleepingComputer · 19d ago Did an AI Really Hack Hugging Face? LiveOverflow · 19d ago Microsoft unveils AI security tools it says outperform competing platforms Security - Ars Technica · 19d ago New Dysphoria DDoS botnet spreads to 200k devices worldwide BleepingComputer · 19d ago New Certighost PoC exploit lets attackers hijack Windows domains BleepingComputer · 19d ago Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin BleepingComputer · 19d ago Activist charged with felony after giving border agent "duress code" that wiped his phone Security - Ars Technica · 19d ago Coca-Cola confirms data theft in Fairlife ransomware attack BleepingComputer · 19d ago Ernst & Young data breach claimed by ShinyHunters extortion gang BleepingComputer · 19d ago Shadow AI agents are multiplying. Here's how to find and secure them. BleepingComputer · 19d ago How One File Upload Got Me the Entire Customer Database NahamSec · 19d ago Any App Notification John Hammond · 20d ago GitHub, PyPI add time-absed defenses against supply chain attacks BleepingComputer · 20d ago Qubes OS explained: assume you will get hacked David Bombal · 20d ago Steam forum ClickFix attacks infect gamers with XMRig cryptominers BleepingComputer · 21d ago Malicious sites use JavaScript to build malware in browser memory BleepingComputer · 21d ago HackTheBox - Fries IppSec · 21d ago ShinyHunters data leaks fuel $2,000 sextortion email scam BleepingComputer · 21d ago Building Fake Notifications John Hammond · 21d ago Why Being a Great Hacker Doesn't Pay Anymore NahamSec · 21d ago OpenAI confirms ChatGPT is down worldwide BleepingComputer · 21d ago CISOs vs. Boards: Myth or Misunderstanding? darkreading · 22d ago Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks CyberScoop · 22d ago OnTrac notifies customers of data breach after network hack BleepingComputer · 22d ago What syscall-layer tooling cannot see in P2P infrastructure Technical Information Security Content & Discussion · 22d ago Despite multiple takedowns, botnets continue to grow CyberScoop · 22d ago Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation darkreading · 22d ago Hermes AI agent used to automate attack on Thai Finance Ministry BleepingComputer · 22d ago Announcing the External Penetration Testing Program Pack Technical Information Security Content & Discussion · 22d ago Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts BleepingComputer · 22d ago Microsoft blames massive Microsoft 365 outage on maintenance bug BleepingComputer · 22d ago Microsoft, tech companies throw weight behind spread of open-source AI CyberScoop · 22d ago Chick-fil-A data breach affects more than 13,000 customers BleepingComputer · 22d ago Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack BleepingComputer · 22d ago Vatican's Official Prayer App Leaks 700K+ Global Users' PII darkreading · 22d ago Europol flags 4,340 URLs for removal in 'The Com' crackdown BleepingComputer · 22d ago Default Azure Automation Setting Enables Cross-Tenant Identity Takeover darkreading · 22d ago The way AI voice phishing gets demonstrated is making people worse at spotting it Technical Information Security Content & Discussion · 22d ago Man gets six years for hacking 750 women's Snapchat accounts BleepingComputer · 22d ago Clop ransomware targets Windchill, FlexPLM in data theft attacks BleepingComputer · 23d ago Europe's Multilingual Reality Exposes AI Security Gaps darkreading · 23d ago Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 Technical Information Security Content & Discussion · 23d ago Ransomware is the Scoreboard Recorded Future · 23d ago The Signs Were There: What the First Autonomous Ransomware Case Confirms Trend Micro Research, News, Perspectives · 23d ago AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA NetworkChuck · 23d ago XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search Technical Information Security Content & Discussion · 23d ago Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets darkreading · 23d ago New Dolphin X malware uses AI to rank high-value targets BleepingComputer · 23d ago Australian energy provider Origin says data breach exposes client data BleepingComputer · 23d ago Rubio restricts visas for sextortionists, cyber scammers CyberScoop · 23d ago Fake Claude app promoted by Bing ads pushes SectopRAT malware BleepingComputer · 23d ago New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors Proofpoint News Feed · 23d ago Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled Technical Information Security Content & Discussion · 23d ago this Raspberry Pi belongs on your wall NetworkChuck · 23d ago Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries CyberScoop · 23d ago Russian hackers exploit Zimbra zero-click flaw for email theft BleepingComputer · 23d ago Hackers abuse Notepad++ plugins to stealthily install malware BleepingComputer · 23d ago Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes Proofpoint News Feed · 23d ago US and allies say Russian hackers stole emails without social engineering Proofpoint News Feed · 23d ago Fake Edge Update John Hammond · 23d ago Microsoft 365 outage affects Teams, SharePoint and other services BleepingComputer · 23d ago You need to learn Maltego in 2026 David Bombal · 23d ago FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires BleepingComputer · 23d ago Open Evaluation Framework for AI Pentesting Agents on Real-World Targets Technical Information Security Content & Discussion · 23d ago Meta Logging Every Employee Keystroke | Threat Wire Hak5 · 23d ago Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA Technical Information Security Content & Discussion · 23d ago EU fines Google $1 billion for search, app store antitrust violations BleepingComputer · 23d ago New RefluXFS Linux flaw lets attackers gain root privileges BleepingComputer · 23d ago Agentic AI Challenges Progress in Confidential Computing darkreading · 23d ago The 4 best managed EDR service suppliers (and how to choose) Heimdal Security Blog · 23d ago New msaRAT malware uses Chrome, Edge browsers to route C2 traffic BleepingComputer · 23d ago ANCHOR-CI could fix 20 years of broken government-industry collaboration CyberScoop · 23d ago Microsoft working to fix Exchange Online mailbox quarantine issue BleepingComputer · 23d ago They hacked Google's AI in Seoul STÖK · 23d ago Check Point warns of SmartConsole zero-day exploited in attacks BleepingComputer · 23d ago Brazilian Banking Trojan Actively Spreading in Portugal darkreading · 24d ago TCM Course Release | New Creator | Cybersecurity | AMA The Cyber Mentors · 24d ago Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain darkreading · 24d ago TAG-195 Upgrades MaaS Ecosystem with Modular Tools Recorded Future · 24d ago 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan Trend Micro Research, News, Perspectives · 24d ago Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It Trend Micro Research, News, Perspectives · 24d ago Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure Trend Micro Research, News, Perspectives · 24d ago Flaws in Passkey Implementation Show Old Attacks Still Work darkreading · 24d ago GitHub issues $100,000 bounty for critical RCE vulnerability Technical Information Security Content & Discussion · 24d ago Upbound says hack caused $13 million in fraudulent Acima leases BleepingComputer · 24d ago Attackers Are Learning to Live Off the AI Toolchain darkreading · 24d ago Most federal cybersecurity reporting rules are duplicative, study finds CyberScoop · 24d ago South Korea discloses data breach impacting diplomats worldwide BleepingComputer · 24d ago Fake Bahrain Alert App Deploys Android Surveillance Malware darkreading · 24d ago CVE-2026-50458: Finding a UAF in the Windows Brokering File System Technical Information Security Content & Discussion · 24d ago Want To Learn (For FREE) About A Self-Driving Network? David Bombal · 24d ago What Is Visa’s DCAP? A Merchant’s Guide to Requirements, Benefits, and Rollout Blog – Forter · 24d ago Malware is targeting AI tools in software development environments CyberScoop · 24d ago Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack BleepingComputer · 24d ago White House accuses Chinese company of distilling Anthropic’s Fable CyberScoop · 24d ago If you pay a hacker’s ransom, chances are that they’ll come back for more Proofpoint News Feed · 24d ago When AI Attacks: OpenAI Models Autonomously Hack Hugging Face darkreading · 24d ago Top 4 Best SOC Platforms 2026 – Provider Comparison Heimdal Security Blog · 24d ago How enterprise GenAI can amplify ransomware risk — and how to contain it BleepingComputer · 24d ago I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) Technical Information Security Content & Discussion · 24d ago New InfraTrust report reveals infrastructure flaws admins should patch first BleepingComputer · 24d ago The End of TOKENMAXXING? David Bombal · 24d ago Adobe Chrome extension flaw let sites access private WhatsApp chats BleepingComputer · 24d ago CISA orders urgent action on actively exploited Langflow RCE flaw BleepingComputer · 24d ago EU Financial Institutions Leak Data Through Cookie Trackers darkreading · 24d ago Stop renting storage space — this lifetime 2TB plan is yours for $59 BleepingComputer · 24d ago Microsoft to stop Exchange 2016 / 2019 security updates in October BleepingComputer · 24d ago Chick-fil-A discloses data breach after credential stuffing attacks BleepingComputer · 25d ago Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective Proofpoint News Feed · 25d ago OpenAI says its AI models hacked Hugging Face during testing BleepingComputer · 25d ago LG to Ban Residential Proxies from Smart TV Apps Krebs on Security · 25d ago Modern Attack Vectors | Recorded Future Recorded Future · 25d ago Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass Trend Micro Research, News, Perspectives · 25d ago Police dismantle Kratos phishing platform, arrest developer BleepingComputer · 25d ago OpenAI says model test was behind Hugging Face hack CyberScoop · 25d ago FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware BleepingComputer · 25d ago Ransomware Is Accelerating, but It's Not Because of AI darkreading · 25d ago Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task darkreading · 25d ago Critical SharePoint RCE flaw exploited to steal machine keys BleepingComputer · 25d ago AI models keep getting caught cheating CyberScoop · 25d ago Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak BleepingComputer · 25d ago Hacker Turns AI Jailbreaks Into Offensive Attack Platform darkreading · 25d ago Where’s the Trump administration line on AI regulation? CyberScoop · 25d ago Critical wp2shell WordPress flaws exploited to install webshells BleepingComputer · 25d ago House intel bill includes provisions on state and local threat intelligence, election security, AI CyberScoop · 25d ago Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability Cisco Security Advisory · 25d ago North Korea’s IT worker scheme funds Russia’s war effort CyberScoop · 25d ago The Hidden CCS2 Attack Surface on EV Chargers Technical Information Security Content & Discussion · 25d ago Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) Technical Information Security Content & Discussion · 25d ago Closing the Identity Gaps in Critical Infrastructure Security BleepingComputer · 25d ago An AI Botnet John Hammond · 25d ago Choose Wisely: AI-Generated Coding Risk Varies, a Lot darkreading · 25d ago US seizes over 1,000 websites in FIFA World Cup piracy crackdown BleepingComputer · 25d ago Critical Palo Alto VPN bug now exploited by Qilin ransomware gang BleepingComputer · 25d ago Leaking internal headers in Flask Ninja with deserialization Technical Information Security Content & Discussion · 25d ago What the World Cup can teach us about cybersecurity resilience CyberScoop · 25d ago Microsoft shares manual fix for WSUS sync delays and timeouts BleepingComputer · 25d ago Windows LegacyHive zero-day flaw gets free, unofficial patches BleepingComputer · 25d ago Volume Is Not Risk: Making Sense of the 'Vulnpocalypse' Trend Micro Research, News, Perspectives · 26d ago Estée Lauder discloses data breach via Oracle E-Business flaw BleepingComputer · 26d ago SonicWall SMA1000 flaws exploited as zero-days to push custom malware BleepingComputer · 26d ago Hackers steal $23.7 million in crypto from Ostium in off-chain attack BleepingComputer · 26d ago 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover darkreading · 26d ago Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes BleepingComputer · 26d ago JadePuffer agentic attacks now target AI model data with ransomware BleepingComputer · 26d ago Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push darkreading · 26d ago Director of Commerce AI standards office out after three months CyberScoop · 26d ago New HollowGraph malware uses Microsoft Graph for stealthy C2 comms BleepingComputer · 26d ago Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities Cisco Security Advisory · 26d ago Crawling the Complete IPv4 Reverse DNS Space Technical Information Security Content & Discussion · 26d ago Why blocking AI models won’t stop the cyber threats they create CyberScoop · 26d ago Redirect Chain Abuse John Hammond · 26d ago An AI SOC Evaluation Guide for Security Leaders BleepingComputer · 26d ago Cybersecurity Keeps Events 'Uneventful' darkreading · 26d ago Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack Cyber Defense Magazine · 26d ago Microsoft Exchange Hacked, Five Years Later John Hammond · 26d ago Hugging Face discloses breach linked to autonomous AI agent BleepingComputer · 26d ago Microsoft confirms Windows Server Update Services sync delays BleepingComputer · 26d ago Windows KB5121767 OOB update fixes shutdowns on some Dell PCs BleepingComputer · 26d ago Critical ServiceNow code execution flaw now exploited in attacks BleepingComputer · 26d ago Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) Technical Information Security Content & Discussion · 26d ago Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 Technical Information Security Content & Discussion · 26d ago Threat Hunting: A Guide | Recorded Future Recorded Future · 27d ago I got inside FIFA’s Secret World Cup Broadcast Network NetworkChuck · 27d ago Hackers abuse ViPNet software to target Russian govt agencies BleepingComputer · 27d ago Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable Technical Information Security Content & Discussion · 28d ago wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner Technical Information Security Content & Discussion · 28d ago Update now: 7-Zip fixes RCE flaw exploitable with malicious archives BleepingComputer · 28d ago Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing Technical Information Security Content & Discussion · 28d ago WordPress Core "wp2shell" RCE flaws get public exploits, patch now BleepingComputer · 28d ago HackTheBox Logging IppSec · 28d ago Microsoft warns of surge in ACR Stealer attacks on customers BleepingComputer · 28d ago The Future of Age Verification: Your Face Never Leaves Your Device BleepingComputer · 28d ago White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination Technical Information Security Content & Discussion · 29d ago wp2shell: Pre Authentication RCE in WordPress Core Technical Information Security Content & Discussion · 29d ago Keeping private namespaces private - Quad9 blog Technical Information Security Content & Discussion · 29d ago Abbott Laboratories probes two cyber incidents amid extortion claims BleepingComputer · 29d ago Inc Ransomware Exploits SonicWall SMA Zero-Days darkreading · 29d ago Openwrt pre-auth remote root exploit Technical Information Security Content & Discussion · 29d ago HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload BleepingComputer · 29d ago The Real AI Threat Is Blind Trust darkreading · 29d ago State officials, election experts pan Trump speech: ‘This is what desperation looks like’ CyberScoop · 29d ago Ernst & Young discloses data breach after support system hack BleepingComputer · 29d ago Leading members of Scattered Spider sentenced in UK to 66 months in jail CyberScoop · 29d ago Inside the Search for "Clean" Residential Proxies for Carding BleepingComputer · 29d ago Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 Technical Information Security Content & Discussion · 29d ago Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear darkreading · 29d ago UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker Cyber Defense Magazine · 29d ago Google Bets 'Agentic Defense' Strategy Can Outpace Attackers darkreading · 29d ago New Windows LegacyHive zero-day gives hackers admin privileges BleepingComputer · 29d ago Hacking US Elections: The First Tranche of Declassified Election Integrity Documents Cyber Defense Magazine · 29d ago Windows Server 2022 reach end of mainstream support in 90 days BleepingComputer · 29d ago US charges two over laundering $43 million from investment fraud BleepingComputer · 29d ago CISA urges immediate action on actively exploited Fortinet flaws BleepingComputer · 30d ago Tracking Advanced Persistent Threat Groups | Recorded Future Recorded Future · 30d ago New ClickLock macOS malware traps users into revealing login password BleepingComputer · 30d ago Coca-Cola says Fairlife ransomware attack halts US dairy production BleepingComputer · 30d ago Agentic AI: Taming the Unpredictable darkreading · 30d ago 1M+ Emails Use Hidden Text to Dupe AI Security Filters darkreading · 30d ago Claude Chrome extension flaw lets malicious extensions trigger AI actions BleepingComputer · 30d ago Program to rotate cyber personnel through federal agencies saw little use CyberScoop · 30d ago New OkoBot framework deploys 20 payloads to steal data, crypto BleepingComputer · 30d ago Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime CyberScoop · 30d ago No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE Technical Information Security Content & Discussion · 30d ago [$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking Technical Information Security Content & Discussion · 30d ago AI Agents Broke the Security Playbook. Here's What Replaces It. BleepingComputer · 30d ago 23andMe to pay $18 million in new genetics data breach settlement BleepingComputer · 30d ago Scattered Spider members behind TfL hack get five years in prison BleepingComputer · 30d ago Inside Microsoft’s Record-Breaking 622-Bug Release Cyber Defense Magazine · 30d ago Windows 11 24H2 Home and Pro reach end of support in 90 days BleepingComputer · 30d ago CISA orders feds to patch actively exploited Oracle flaw by Saturday BleepingComputer · 30d ago Russian hackers trojanize WebEx, Zoom apps to push Starland malware BleepingComputer · 30d ago New Spirals ransomware encrypts victim network in under 24 hours BleepingComputer · 30d ago Police Disrupt a €140M Cyber Fraud Ring in Spain darkreading · 31d ago ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL Technical Information Security Content & Discussion · 31d ago AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict Recorded Future · 31d ago Dutch police bust investment fraud ring stealing over €100 million BleepingComputer · 31d ago Forgotten Bootloaders Expose Secure Boot Blind Spot darkreading · 31d ago Security researchers find stalkers abusing Chrome’s sync feature CyberScoop · 31d ago Identity Attacks Overtake Exploits as Top Ransomware Cause darkreading · 31d ago Zoom warns of critical account takeover vulnerability BleepingComputer · 31d ago SonicWall customers under threat as attackers exploit 2 zero-days CyberScoop · 31d ago Google Gemini CLI abused as a hacking agent, malware botnet operator BleepingComputer · 31d ago Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed CyberScoop · 31d ago Guten Tag, Bonjour, Hola to Our European Cyber Defenders! darkreading · 31d ago Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife darkreading · 31d ago Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook Cyber Defense Magazine · 31d ago Your Home Internet Has a New Owner | Threat Wire Hak5 · 31d ago News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations The Last Watchdog · 31d ago AsyncAPI npm packages infected with credential-stealing malware BleepingComputer · 31d ago Forget the model. When it comes to cybersecurity, it’s all about the harness CyberScoop · 31d ago Claude Flaw Automatically Sends Malicious Prompts to AI Agents darkreading · 31d ago News alert: Insignary’s on-demand SBOM verification boosts software supply chain security The Last Watchdog · 31d ago We built a vulnerability vending machine: AI tokens in, zero-days out BleepingComputer · 31d ago 2-Click Cursor Exploit Enables Dev Environment Takeover darkreading · 31d ago Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure Cyber Defense Magazine · 31d ago CISA warns admins to patch actively exploited SharePoint flaws BleepingComputer · 31d ago HN Security - My Semgrep C/C++ ruleset is ready for prime time again Technical Information Security Content & Discussion · 31d ago The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets Technical Information Security Content & Discussion · 31d ago Microsoft: Some Dell PCs shut down after recent Windows updates BleepingComputer · 31d ago (More) Unauthenticated Arbitrary Code Execution in ServiceNow Technical Information Security Content & Discussion · 31d ago 78% of CFOs Say Payment Blind Spots Increase Customer Friction PYMNTS | Fraud Prevention Archives · 32d ago Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits darkreading · 32d ago US charges alleged operators of Russian bulletproof hosting service BleepingComputer · 32d ago News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions The Last Watchdog · 32d ago Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal darkreading · 32d ago The Shift: A New Era of AI Regulation Recorded Future · 32d ago Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes darkreading · 32d ago SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now BleepingComputer · 32d ago Spanish Police take down €140 million cyber fraud ring, arrest four BleepingComputer · 32d ago 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems darkreading · 32d ago Microsoft Patches a Record 570 Security Flaws Krebs on Security · 32d ago Nearly 300 GitHub repos pose as legit software to push malware BleepingComputer · 32d ago Microsoft releases Windows 10 KB5099539 extended security update BleepingComputer · 32d ago Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days BleepingComputer · 32d ago Manage Vendor Risk in a Few Practical Steps darkreading · 32d ago Is Cat7 a SCAM? David Bombal · 32d ago Windows 11 KB5101650 & KB5099414 cumulative updates released BleepingComputer · 32d ago The Gray Area in Your Checkout Is Costing You More Than You Think Blog – Forter · 32d ago Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown BleepingComputer · 32d ago Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? darkreading · 32d ago LastPass, Bitwarden users targeted with fake security alerts BleepingComputer · 32d ago What Nacha’s amended rules mean for your ACH fraud monitoring Fraud Prevention – Riskified · 32d ago You Don't Have to Run an Exploit to Know If You're Vulnerable BleepingComputer · 32d ago OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Proofpoint News Feed · 32d ago Microsoft Entra ID gets passkeys default authentication starting September BleepingComputer · 32d ago New phishing kits target Microsoft 365 accounts, evade MFA BleepingComputer · 32d ago CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers Cyber Defense Magazine · 32d ago SAP warns of critical flaws in NetWeaver and Commerce Cloud BleepingComputer · 32d ago Smashing the ServiceNow Sandbox – Pre Authentication RCE Technical Information Security Content & Discussion · 32d ago Microsoft starts testing cleaner Windows Search without ads BleepingComputer · 32d ago US sanctions VPN, malware providers for enabling ransomware attacks BleepingComputer · 32d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 32d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 32d ago The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future Recorded Future · 33d ago Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet Trend Micro Research, News, Perspectives · 33d ago Context Bombs: Using AI Guardrails as a defensive mechanism Technical Information Security Content & Discussion · 33d ago CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC) Technical Information Security Content & Discussion · 33d ago Japan's largest taxi operator shuts systems after cyberattack BleepingComputer · 33d ago Cisco's Agents Reason Like a CCIE David Bombal · 33d ago Hackers backdoor Jscrambler npm package with infostealer malware BleepingComputer · 33d ago New CrashStealer malware poses as Apple crash reporting tool BleepingComputer · 33d ago CISA warns of actively exploited RCE flaws in Joomla extensions BleepingComputer · 33d ago Lessons Learned from CISA’s Recent GitHub Leak Krebs on Security · 33d ago Lidl discloses online shop breach after service provider hack BleepingComputer · 33d ago Breach at the Beach: Play the Ultimate Entra ID CTF BleepingComputer · 33d ago UK charges suspects linked to Russian Coms call spoofing platform BleepingComputer · 33d ago This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!) NahamSec · 33d ago The Threat Mechanism and Mitigation of Pink Vishing Campaigns Cyber Defense Magazine · 33d ago EU sanctions Russian GRU military hackers over cyberattacks BleepingComputer · 33d ago Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) Technical Information Security Content & Discussion · 33d ago US and allies warn of Russian critical infrastructure attacks BleepingComputer · 33d ago 85% of CFOs Say Automation Cuts Payments Friction PYMNTS | Fraud Prevention Archives · 34d ago Persistence via Fake AMSI Provider | Playbook & Detection Strategies Technical Information Security Content & Discussion · 34d ago OpenAI temporarily relaxes GPT-5.6 Sol usage limits BleepingComputer · 34d ago Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver Technical Information Security Content & Discussion · 34d ago Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time BleepingComputer · 34d ago RedHook Android malware now uses Wireless ADB for shell access BleepingComputer · 34d ago Install GrapheneOS Before Your Phone Becomes the Checkpoint David Bombal · 34d ago Scanning malicious websites with arbitrary number of VPN tunnels (Part 2) Technical Information Security Content & Discussion · 35d ago HackTheBox - CCTV IppSec · 35d ago Australia warns of global campaign targeting vulnerable CMS platforms BleepingComputer · 35d ago See It Once, Stop It Everywhere Cyber Defense Magazine · 35d ago 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets BleepingComputer · 35d ago New U-Boot flaws could enable stealthy firmware attacks BleepingComputer · 36d ago Cybercriminals Targeting World Cup Fans Cyber Defense Magazine · 36d ago Innovators Spotlight: Brinqa Cyber Defense Magazine · 36d ago Ryuk ransomware member pleads guilty in the US, faces 15 years in prison BleepingComputer · 36d ago Police suspects Dutch hackers were involved in Odido breach BleepingComputer · 36d ago Progress urges ShareFile admins to shut down servers over “credible” threat BleepingComputer · 36d ago Soft Skills for the Job Market: Applying for Jobs The Cyber Mentors · 36d ago Hackers exploit critical auth bypass in Gitea Docker image BleepingComputer · 36d ago Money launderer accused of stealing seized crypto while in prison BleepingComputer · 36d ago The Cost of Delayed Patching: What Security Teams Are Missing Cyber Defense Magazine · 36d ago The Replicant in Your Directory: AI Agents and the Identity Security Gap BleepingComputer · 36d ago Invoice Fraud Is Now a Cybersecurity Exposure Cyber Defense Magazine · 36d ago Top 6 Managed Detection and Response Providers Heimdal Security Blog · 36d ago Can AI-generated adversaries break TTP-based attribution? (arXiv 2026) Technical Information Security Content & Discussion · 36d ago Zimbra urges customers to patch critical web client XSS flaw BleepingComputer · 36d ago Towards CSI: What's the best harness? (arXiv 2026) Technical Information Security Content & Discussion · 36d ago Former ransomware negotiator gets 4 years for BlackCat attacks BleepingComputer · 36d ago Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail CyberScoop · 37d ago June 2026 CVE Landscape Recorded Future · 37d ago LIVE AMA | Summer of CCNA | 07/09/2026 NetworkChuck · 37d ago OpenMandriva Linux says contributor tried to sabotage the project BleepingComputer · 37d ago Injective SDK on npm infected with cryptocurrency wallet stealer BleepingComputer · 37d ago Interpol cybercrime crackdown nets 5,800 arrests across 97 countries CyberScoop · 37d ago New Helix vishing group emerges in SharePoint data theft attacks BleepingComputer · 37d ago Microsoft expects more Windows security updates from AI-discovered flaws BleepingComputer · 37d ago New Forg365 phishing platform uses AI to target Microsoft 365 accounts BleepingComputer · 37d ago 764 splinter group leader sentenced to 40 years in jail CyberScoop · 37d ago Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities Technical Information Security Content & Discussion · 37d ago The Hidden Security Risks of Reduced Summer IT Coverage BleepingComputer · 37d ago Microsoft to retire the OWA Light client in Exchange Server BleepingComputer · 37d ago Police arrests 5,800 suspects in global anti-fraud crackdown BleepingComputer · 37d ago AssuranceAmerica data breach exposes records of 6.9 million drivers BleepingComputer · 38d ago Microsoft patches RoguePlanet Defender zero-day vulnerability BleepingComputer · 38d ago RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney Recorded Future · 38d ago Mount Royal University confirms breach as hackers claim attack BleepingComputer · 38d ago Your Payment Routing Rules Are Making Decisions Without You Blog – Forter · 38d ago Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials BleepingComputer · 38d ago Hackers exploit Roundcube flaw to spy on academic researchers BleepingComputer · 38d ago French nonprofit starts global intelligence and research hub for AI cyber threats CyberScoop · 38d ago 1 in 2 devices sold in Africa exfiltrate data to China Technical Information Security Content & Discussion · 38d ago Inside an AI coal mine security camera network powered by plaintext passwords Technical Information Security Content & Discussion · 38d ago News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI The Last Watchdog · 38d ago LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway The Cyber Mentors · 38d ago Entra passkey enrollment vishing targets Microsoft 365 users BleepingComputer · 38d ago Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches Technical Information Security Content & Discussion · 38d ago 3 Ways AI Powers Service Desk Attacks and How to Prevent Them BleepingComputer · 38d ago Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security · 38d ago DuckDuckGo browser now blocks YouTube video ads BleepingComputer · 38d ago Telco giant KDDI says data breach affects over 12 million people BleepingComputer · 38d ago CISA orders feds to prioritize patching Langflow auth bypass flaw BleepingComputer · 38d ago Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Heimdal Security Blog · 38d ago Found fast, fixed slow: The gap the AI clearinghouse must close CyberScoop · 38d ago ESET Threat Report H1 2026 WeLiveSecurity · 38d ago ESET Threat Report H1 2026 WeLiveSecurity · 38d ago Ubiquiti warns of new max severity UniFi OS vulnerability BleepingComputer · 38d ago 42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million PYMNTS | Fraud Prevention Archives · 39d ago CISA orders feds to patch max severity ColdFusion flaw by Friday BleepingComputer · 39d ago Bad Epoll: The bug missed by Mythos Technical Information Security Content & Discussion · 39d ago Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire Hak5 · 39d ago The Threat Isn’t the Frontier Model Recorded Future · 39d ago Accenture confirms breach after hacker offers stolen data for sale BleepingComputer · 39d ago Spain arrests suspected hacker linked to Russian hacktivist campaign CyberScoop · 39d ago Deepfake CSAM lawsuit against xAI, Grok expands CyberScoop · 39d ago Chinese hackers develop LONGLEASH malware to expand ORB network BleepingComputer · 39d ago Hidden backdoor in Tenda router firmware grants admin access BleepingComputer · 39d ago Spain arrests suspected member of pro-Russian hacktivist groups BleepingComputer · 39d ago GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail Technical Information Security Content & Discussion · 39d ago The GitHub Actions Attack Pattern Your CI Security Scanners Miss BleepingComputer · 39d ago Webinar tomorrow: Why modern email attacks require a new approach to defense BleepingComputer · 39d ago New Januscape Linux flaw allows VM escape on Intel, AMD devices BleepingComputer · 39d ago Microsoft to enable Windows settings backup by default for orgs BleepingComputer · 39d ago Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities CyberScoop · 39d ago BeyondTrust warns of critical flaws in remote access software BleepingComputer · 39d ago Microsoft testing new Cloud Rebuild Windows 11 recovery feature BleepingComputer · 40d ago Phishing poses as big-brand job interview to steal Google accounts BleepingComputer · 40d ago Fake IT support calls on Microsoft Teams push EtherRAT malware BleepingComputer · 40d ago Vietnam arrests suspects behind HiAnime anime piracy service BleepingComputer · 40d ago Unveiled: Cisco Deep Reasoning David Bombal · 40d ago News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk The Last Watchdog · 40d ago US Army websites defaced with pro-Kurdish sentiments, insults to Trump CyberScoop · 40d ago Sysdig clocks first documented case of agentic ransomware CyberScoop · 40d ago New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!" Technical Information Security Content & Discussion · 40d ago Software Is Now Written at the Speed of Thought. Security Isn't. BleepingComputer · 40d ago Max severity Adobe ColdFusion flaw now exploited in attacks BleepingComputer · 40d ago I Made an AI Agent That Reverses CVEs While I Sleep NahamSec · 40d ago Playing Around With ADIDNS RPC Internals Technical Information Security Content & Discussion · 40d ago Finding vulnerabilities was never the hard part CyberScoop · 40d ago Windows Service - Playbook & Detection Strategies Technical Information Security Content & Discussion · 40d ago Why Apple Hide My Email FAILS David Bombal · 41d ago Flipper Zero firmware development continues with community help BleepingComputer · 41d ago New to Linux? This is the best place to start! David Bombal · 41d ago HackTheBox - DevArea IppSec · 42d ago JadePuffer ransomware used AI agent to automate entire attack BleepingComputer · 42d ago LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud PYMNTS | Fraud Prevention Archives · 43d ago NetNut proxy network disrupted, 2 million infected devices cut off BleepingComputer · 43d ago How to scale your patches without scaling your team (the patch wave) Heimdal Security Blog · 43d ago ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit BleepingComputer · 43d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 43d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 43d ago AI didn’t break patching. It showed us patching was already broken. Heimdal Security Blog · 43d ago Someone infected a spyware probe overseer with spyware CyberScoop · 44d ago Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says BleepingComputer · 44d ago Claude Fable relaunch disappoints users with nerfed performance BleepingComputer · 44d ago Fable 5 is back.....run these prompts before July 12th NetworkChuck · 44d ago FBI Seizes NetNut Proxy Platform, Popa Botnet Krebs on Security · 44d ago It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs Technical Information Security Content & Discussion · 44d ago FIFA was saved this time Technical Information Security Content & Discussion · 44d ago Alleged longstanding member of Scattered Spider extradited to US CyberScoop · 44d ago Google loses final appeal to overturn €4.1 billion EU fine BleepingComputer · 44d ago Celebrating 1 Million Subscribers on July 8th! The Cyber Mentors · 44d ago ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds BleepingComputer · 44d ago Microsoft fixes bug that removed Copilot buttons in Outlook BleepingComputer · 44d ago Cisco finally confirms attackers exploiting Unified CM flaw BleepingComputer · 44d ago CISA: Microsoft SharePoint RCE flaw now actively exploited BleepingComputer · 44d ago Opera rolls out Paste Protect feature to fight ClickFix attacks BleepingComputer · 44d ago Alleged Scattered Spider hacker extradited to the United States BleepingComputer · 44d ago 42% of Issuers Say Fraud and Disputes Are Driving Up Costs PYMNTS | Fraud Prevention Archives · 45d ago /r/netsec's Q3 2026 Information Security Hiring Thread Technical Information Security Content & Discussion · 45d ago News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks The Last Watchdog · 45d ago Medtronic notifies customers impacted by ShinyHunters data breach BleepingComputer · 45d ago FortiBleed credential-theft campaign linked to Lynx ransomware BleepingComputer · 45d ago Kubota says hackers had month-long access to network systems BleepingComputer · 45d ago ChocoPoc malware delivered via trojanized exploits on GitHub BleepingComputer · 45d ago New ChocoPoC malware targets researchers via trojanized PoC exploits BleepingComputer · 45d ago Researchers spot exploitation of another critical Oracle defect CyberScoop · 45d ago DHS confirms hackers breached HSIN info-sharing platform BleepingComputer · 45d ago Webinar: Why traditional email security is no longer enough BleepingComputer · 45d ago Hackers target Microsoft 365 accounts with 81 million login attempts BleepingComputer · 45d ago Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) Technical Information Security Content & Discussion · 45d ago Turning Indicators into Intelligence in OpenCTI with Criminal IP BleepingComputer · 45d ago US lifting export control restrictions on Anthropic’s Mythos, Fable CyberScoop · 45d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 45d ago Over 900 Oracle E-Business instances exposed to ongoing attacks BleepingComputer · 45d ago The Chaya_006 Alert: OT Edge Devices Under Fire Cyber Defense Magazine · 45d ago Microsoft fixes GIF functionality in the Windows Emoji Panel BleepingComputer · 45d ago This phishing kit looks more like BEC-as-a-service CyberScoop · 45d ago Amazon fined $2.25M for withholding evidence from fraud victims BleepingComputer · 45d ago Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes Heimdal Security Blog · 46d ago Adobe patches seven max severity ColdFusion, Campaign flaws BleepingComputer · 46d ago Anthropic to restore Claude Fable access on Wednesday BleepingComputer · 46d ago Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price BleepingComputer · 46d ago New BioShocking attack manipulates AI browser into data theft BleepingComputer · 46d ago Citrix patches a new NetScaler flaw with echoes of CitrixBleed CyberScoop · 46d ago Microsoft accelerates quantum-safe roadmap as risks grow BleepingComputer · 46d ago Malicious PyPI packages give hackers control of Telegram bot servers BleepingComputer · 46d ago Trump budget boss Russell Vought open to re-staffing CISA CyberScoop · 46d ago CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs Technical Information Security Content & Discussion · 46d ago News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks The Last Watchdog · 46d ago JPMorganChase and Amazon Back Aspen Institute Drive Against Scams PYMNTS | Fraud Prevention Archives · 46d ago News alert: OpenMatter launches platform to verify AI activity across enterprise systems The Last Watchdog · 46d ago Fake Perplexity extension on Chrome Web Store tracked searches BleepingComputer · 46d ago Nissan Americas Hit in Global Oracle PeopleSoft Data Breach Cyber Defense Magazine · 46d ago DHS to unveil replacement council for critical infrastructure cybersecurity CyberScoop · 46d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 46d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 46d ago Lessons from the Underground: How to Combat Business Email Compromise BleepingComputer · 46d ago Insurance giant Aflac discloses data breach after subsidiary hack BleepingComputer · 46d ago Mircosoft adds smarter bot protection to Teams meetings BleepingComputer · 46d ago Microsoft adds smarter bot protection to Teams meetings BleepingComputer · 46d ago Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass) Technical Information Security Content & Discussion · 46d ago Kali Linux 2026.2 released with 9 new tools, NetHunter updates BleepingComputer · 46d ago Blackfield ransomware asks Nidec Corporation for $2 million ransom BleepingComputer · 46d ago How ransomware syndicates weaponize corporate-style organization CyberScoop · 46d ago CISA: Windows BlueHammer flaw now exploited by ransomware gangs BleepingComputer · 46d ago Warner bill would create federally vetted list for secure, trustworthy AI agents CyberScoop · 47d ago Nissan discloses employee data breach linked to Oracle zero-day attacks BleepingComputer · 47d ago NAIC says public data stolen in ShinyHunters' PeopleSoft breach BleepingComputer · 47d ago Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs Technical Information Security Content & Discussion · 47d ago WhatsApp rolls out usernames to help users hide their phone number BleepingComputer · 47d ago Supreme Court approves mail-in ballots that arrive after Election Day CyberScoop · 47d ago Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling CyberScoop · 47d ago Microsoft extends Windows Server 2022 hotpatching until October 2027 BleepingComputer · 47d ago U.S. offers $10 million for hackers targeting WhatsApp, Signal users BleepingComputer · 47d ago Agentic AI Has an Identity Problem and Attackers Know It BleepingComputer · 47d ago Critical SimpleHelp flaw exploited to deploy new stealer malware BleepingComputer · 47d ago Hackers now exploit critical Oracle E-Business flaw in attacks BleepingComputer · 47d ago Webinar: Why business email compromise attacks keep succeeding BleepingComputer · 47d ago CISA Warns Attackers Are Targeting Critical Internal Business Platforms Cyber Defense Magazine · 47d ago US seizes hundreds of FIFA World Cup illegal streaming domains BleepingComputer · 47d ago What the post-quantum executive order really demands of CISOs CyberScoop · 47d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 47d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 47d ago World Cup Gives Cross-Border Payments Their Super Bowl Moment PYMNTS | Fraud Prevention Archives · 48d ago TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry Trend Micro Research, News, Perspectives · 48d ago Return On Risk: The New Measure Of Cyber Resilience Cyber Defense Magazine · 48d ago Data breach exposes up to 14.2 million email logins at six ISPs BleepingComputer · 48d ago Path to StateRAMP Cyber Defense Magazine · 48d ago I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well. Technical Information Security Content & Discussion · 48d ago Dissecting Apple's Sparse Image Format (ASIF) Technical Information Security Content & Discussion · 48d ago A peek into Reddit's anti-spam internals Technical Information Security Content & Discussion · 49d ago Rethinking Identity Security In The Age Of AI Driven Fraud Cyber Defense Magazine · 49d ago HackTheBox - WingData IppSec · 49d ago Clean GitHub repo tricks AI coding agents into running malware BleepingComputer · 49d ago New Age Insider Risk Cyber Defense Magazine · 49d ago FBI: Russian hackers now target Signal backup recovery keys BleepingComputer · 50d ago CISA sets urgent deadline to fix Cisco flaw exploited in attacks BleepingComputer · 50d ago ATF cancels controversial commercial geolocation contract CyberScoop · 50d ago Polymarket customers lose $3 million in supply-chain attack BleepingComputer · 50d ago Cybersecurity firms targeted by fraudulent OpenAI organization invites BleepingComputer · 50d ago Banks Face a New ACH Fraud Test as Nacha Rules Take Effect PYMNTS | Fraud Prevention Archives · 50d ago Real Folks of Cyber | Pearce Barry | Day in the Life The Cyber Mentors · 50d ago How Dynamic Defense shuts an attacker out without shutting down the business Heimdal Security Blog · 50d ago Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure Cyber Defense Magazine · 50d ago Your First GRC Agent: A Red Teamer's Walkthrough BleepingComputer · 50d ago Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To Cyber Defense Magazine · 50d ago Name That Toon Contest darkreading · 50d ago Static security has run out of road. The case for Dynamic Defense Heimdal Security Blog · 50d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 50d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 50d ago Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges PYMNTS | Fraud Prevention Archives · 51d ago Anthropic is testing desktop-like Claude Cowork for mobile BleepingComputer · 51d ago Poland busts SIM-swapping gang tied to millions in crypto theft BleepingComputer · 51d ago Getting Started with the TCM Security Academy The Cyber Mentors · 51d ago FCC passes new cybersecurity rules for emergency systems, undersea cables CyberScoop · 51d ago Order-tracking app Shop abused to push callback phishing attacks BleepingComputer · 51d ago Microsoft quietly extends free Windows 10 ESU support to October 2027 BleepingComputer · 51d ago New macOS malware embeds fake errors to confuse AI analysis tools BleepingComputer · 51d ago Federal court rules Trump election-focused executive order illegal CyberScoop · 51d ago PirloTV sports piracy network disrupted as 44 domains seized BleepingComputer · 51d ago CVE-2025-52465 geoserver arbitrary file write vulnerability Technical Information Security Content & Discussion · 51d ago The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer Cyber Defense Magazine · 51d ago Bluekit phishing kit adopts browser-in-the-middle for login theft BleepingComputer · 51d ago Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract CyberScoop · 51d ago Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack CyberScoop · 51d ago The Four Elevations of Effective Fraud Prevention BleepingComputer · 51d ago The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target Cyber Defense Magazine · 51d ago Copilot in Excel: Built for the era of Frontier Finance Microsoft 365 Blog · 51d ago Webinar: Why account takeovers remain one of the hardest threats to stop BleepingComputer · 51d ago NSA Urges Cyberthreat Timeline Has Compressed From Years to Months Cyber Defense Magazine · 51d ago CargoWise WebTracker - The keys were in the cargo Technical Information Security Content & Discussion · 51d ago Europe Evolves Into Ransomware's Favorite Region darkreading · 51d ago Why patch directives only go so far CyberScoop · 51d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 51d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 51d ago AI Forces Compliance Teams to Rethink Alert Strategy PYMNTS | Fraud Prevention Archives · 52d ago Google releases new privacy controls for activity history, personalization BleepingComputer · 52d ago DraftKings hacker 'Snoopy' sentenced to 18 months in prison BleepingComputer · 52d ago Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access BleepingComputer · 52d ago Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure darkreading · 52d ago Malicious Edge extension abuses Native Messaging as bridge to malware BleepingComputer · 52d ago 2026 FIFA World Cup Faces Surge in Cyber Threats darkreading · 52d ago Do CISOs Need a Code of Ethics? darkreading · 52d ago Malicious hackers exploit Cisco zero-day for highest access level at communications service provider CyberScoop · 52d ago More Malicious OpenClaw Skills Threaten AI Supply Chain darkreading · 52d ago Exploiting vulnerabilities in Johnson & Johnson web apps Technical Information Security Content & Discussion · 52d ago Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have Cyber Defense Magazine · 52d ago CISA warns of max severity Ubiquiti flaws exploited in attacks BleepingComputer · 52d ago Amadey, StealC malware operations disrupted in Operation Endgame action BleepingComputer · 52d ago Securing the service desk: Why social engineering attacks keep succeeding BleepingComputer · 52d ago Invisible By Design: Making Quantum-Safe Encryption The Easy Path Cyber Defense Magazine · 52d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 52d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 52d ago In a first, a court takedown goes after two cybercrime tools at once CyberScoop · 52d ago Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming Cyber Defense Magazine · 52d ago Apple's MacOS Gap Lets Users Disable Security Tools darkreading · 52d ago Breaking the MSP Echo Chamber: The Power of Community Heimdal Security Blog · 52d ago Stealthy Mistic backdoor linked to ransomware access broker KongTuke BleepingComputer · 52d ago Open-source security is posing challenges governments can’t easily solve CyberScoop · 52d ago New at Forter: AI Agents Built to Amplify Your Team Blog – Forter · 52d ago Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks BleepingComputer · 53d ago Tata Electronics confirms cyberattack as hackers leak data BleepingComputer · 53d ago Scope of Salesforce Attacks Expands as Icarus Leaks Data darkreading · 53d ago Windows 11 KB5095093 update rolls out new Point-in-Time restore feature BleepingComputer · 53d ago Healthtech firm Xolis suffers data breach impacting 1.4 million people BleepingComputer · 53d ago Innovator Spotlight: NAKIVO Cyber Defense Magazine · 53d ago 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows darkreading · 53d ago Justice Department seizes infrastructure used by cyber scam and criminal marketplace CyberScoop · 53d ago New macOS ClickFix attack silently mounts DMGs to push infostealer BleepingComputer · 53d ago Cybersecurity Outsourcing. Beyond Cost Cyber Defense Magazine · 53d ago Scattered Spider Hackers Plead Guilty on Day 1 of Trial Krebs on Security · 53d ago Scattered Spider members plead guilty to hacking Transport for London BleepingComputer · 53d ago Algerian man charged with running two cybercrime marketplaces CyberScoop · 53d ago The Exploit Doesn't Exist. You Can Still Prove It Works Against You BleepingComputer · 53d ago LastPass confirms data breach in Klue supply chain attack BleepingComputer · 53d ago SocGholish Takedown Highlights Malicious TDS Threats darkreading · 53d ago Can AI Agents Find, Trust, and Choose Your Brand? Blog – Forter · 53d ago Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets Cyber Defense Magazine · 53d ago FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist darkreading · 53d ago Webinar: Why email security teams are drowning in alerts BleepingComputer · 53d ago Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data Cyber Defense Magazine · 53d ago Cloudflare patches Copy-Fail across every server in two days Technical Information Security Content & Discussion · 53d ago New Cisco RCE was fixed Technical Information Security Content & Discussion · 53d ago From Langflow to Monero: Inside CVE-2026-33017 Cryptominer Trend Micro Research, News, Perspectives · 54d ago WhatsApp phishing attack uses fake business docs to hack PCs BleepingComputer · 54d ago Court rules SAVE database illegal, orders it dismantled CyberScoop · 54d ago JaredFromSubway MEV bot hacked in $15 million crypto theft BleepingComputer · 54d ago DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories darkreading · 54d ago FFmpeg fixes PixelSmash flaw in widely used video decoder BleepingComputer · 54d ago Data Breach with Eastman Kodak Company Cyber Defense Magazine · 54d ago FortiBleed campaign used custom FortiGate sniffer to steal credentials BleepingComputer · 54d ago Trump executive orders speed up post-quantum migration, boost industry CyberScoop · 54d ago CVE-2026-25860 turn XSS to RCE Technical Information Security Content & Discussion · 54d ago Microsoft says Windows 11 26H2 is coming soon, details upgrade process BleepingComputer · 54d ago Microsoft fixes AutoGen Studio flaw that enabled code execution BleepingComputer · 54d ago Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign darkreading · 54d ago Intel agencies: Frontier AI models will reshape cybersecurity faster than expected CyberScoop · 54d ago He Thought He Was Secure; His Phone Number Was Stolen Anyway darkreading · 54d ago A Glimpse into the “Search Your Target” Market for Stolen Credentials BleepingComputer · 54d ago Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire Hak5 · 54d ago The World Cup Is Here… And So Are The Cyber Risks Cyber Defense Magazine · 54d ago Cloud Managed Services For Modern Cybersecurity To Secure Cloud Cyber Defense Magazine · 54d ago This Hacker Got Paid $50,000+ to Break Frontier AI Models NahamSec · 54d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 54d ago Exploiting Auth0 Defaults in XSS Attacks - elttam Technical Information Security Content & Discussion · 55d ago 🔴 [PAYLOAD] 🍍📟 WiFi Pineapple Pager Hak5 · 55d ago Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1) Technical Information Security Content & Discussion · 55d ago AryStinger botnet infected thousands of D-Link routers worldwide BleepingComputer · 55d ago Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors Cyber Defense Magazine · 55d ago New Prinz Eugen ransomware prioritizes recent files for encryption BleepingComputer · 56d ago HackTheBox - Nanocorp IppSec · 56d ago Microsoft links Mastra AI supply chain attack to North Korean hackers BleepingComputer · 56d ago The Shadow AI Paradox: Governing Innovation At Machine Speed Cyber Defense Magazine · 56d ago Innovator Spotlight: Ensemble Cyber Defense Magazine · 57d ago Innovator Spotlight: Centrii Cyber Defense Magazine · 57d ago Klue OAuth breach victim list grows as Icarus hackers claim attack BleepingComputer · 57d ago shadow AI is terrifying NetworkChuck · 57d ago Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin BleepingComputer · 57d ago Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 Technical Information Security Content & Discussion · 57d ago NSPM-12: The New Baseline for National Security Cybersecurity Cyber Defense Magazine · 57d ago Texas govt data breach exposes over 3 million driver’s licenses BleepingComputer · 57d ago Soft Skills for the Job Market: Resume Writing The Cyber Mentors · 57d ago OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099) Technical Information Security Content & Discussion · 57d ago Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way BleepingComputer · 57d ago Stressors, AI Forcing Changes to Cybersecurity Teams darkreading · 57d ago Webinar: How attackers bypass MFA and how defenders can respond BleepingComputer · 57d ago Microsoft: June 2026 Windows updates break Recycle Bin prompts BleepingComputer · 57d ago CISA: Splunk Enterprise flaw actively exploited, patch by Sunday BleepingComputer · 57d ago Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration Technical Information Security Content & Discussion · 57d ago NY man charged after harassing college student with AI-generated nudes BleepingComputer · 57d ago CISA warns Fortinet users to secure devices after FortiBleed leak BleepingComputer · 58d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 58d ago Gentlemen ransomware uses multiple EDR killers to disable defenses BleepingComputer · 58d ago Authorities disrupt Evil Corp’s SocGholish botnet CyberScoop · 58d ago Congress tees up No FAKES Act, aiming at AI-generated deepfakes CyberScoop · 58d ago Novo Nordisk Breach Highlights Software Development Pipeline Risk darkreading · 58d ago HTTPS Doesn't Hide This From Your ISP!! NetworkChuck · 58d ago Operation Escaneo Signals Shift in LatAm Threat Landscape darkreading · 58d ago Nintendo confirms data stolen in WebMD subsidiary cyberattack BleepingComputer · 58d ago FIFA Bug Exposes World Cup Streams to Remote Takeover darkreading · 58d ago CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance Technical Information Security Content & Discussion · 58d ago Salesforce Data Thefts Continue via Klue App Compromise darkreading · 58d ago USB worm spreads crypto-stealing malware via Windows shortcut files BleepingComputer · 58d ago Cisco Just Showed the Future of Networking NetworkChuck · 58d ago How software development’s speed obsession enabled TeamPCP’s chaos crusade CyberScoop · 58d ago Accenture shells out $4.18B on three companies in big industrial cybersecurity push CyberScoop · 58d ago Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks BleepingComputer · 58d ago 5 reasons Microsoft 365 backup isn’t enough for business data protection BleepingComputer · 58d ago Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp BleepingComputer · 58d ago Five Compliance Realities Federal Contractors Can’t Ignore Cyber Defense Magazine · 58d ago Get Out of Security Debt by Tackling the Exposure Problem darkreading · 58d ago ShapedPlugin update flow hacked to infect WordPress sites BleepingComputer · 58d ago Apple fixes Beats Studio Buds flaw that let hackers spy on conversations BleepingComputer · 58d ago Telegram admits it couldn't police exam-leak channels, India tells court BleepingComputer · 58d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 58d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure Alerts · 58d ago Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT All CISA Advisories · 58d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 58d ago Schneider Electric EasyLogic T150 and Saitel DP All CISA Advisories · 58d ago AVer PTC cameras All CISA Advisories · 58d ago Rockwell Automation FactoryTalk Historian Site Edition All CISA Advisories · 58d ago AzeoTech DAQFactory All CISA Advisories · 58d ago Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products All CISA Advisories · 58d ago Mitsubishi Electric MELSEC iQ-F Series All CISA Advisories · 58d ago Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module All CISA Advisories · 58d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure All CISA Advisories · 58d ago F5 issues out-of-band patches for critical NGINX vulnerabilities BleepingComputer · 58d ago Would you like some malware served at the very top of DuckDuckGo? Technical Information Security Content & Discussion · 58d ago Microsoft fixes Windows Server 2016 security update failures BleepingComputer · 58d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 58d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 58d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 59d ago EU Gets a Head Start in Developing 6G Network Security darkreading · 59d ago Leak confirms OpenAI is testing a ChatGPT for Science subscription BleepingComputer · 59d ago PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM Trend Micro Research, News, Perspectives · 59d ago Google to use UK and EU user IP addresses for ad personalization BleepingComputer · 59d ago Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update Technical Information Security Content & Discussion · 59d ago This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity NahamSec · 59d ago News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies The Last Watchdog · 59d ago News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk The Last Watchdog · 59d ago Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April CyberScoop · 59d ago FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. BleepingComputer · 59d ago Why Account Takeovers Are Rising and How to Stop Them BleepingComputer · 59d ago India's Telegram ban hit the UAE too. Here's how to get around it BleepingComputer · 59d ago Cyber Security Market Insights & Trends Driving The Next Wave Of Protection Cyber Defense Magazine · 59d ago Microsoft confirms Office apps launch issues after June updates BleepingComputer · 59d ago CISA orders feds to patch max severity Joomla plugin flaw by Friday BleepingComputer · 59d ago QoS Policies to Restrict EDR Traffic and Detection Strategies Technical Information Security Content & Discussion · 59d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 59d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 59d ago Microsoft working on Defender patch for RoguePlanet zero-day BleepingComputer · 59d ago Kodak confirms data breach claimed by ShinyHunters extortion gang BleepingComputer · 60d ago Getting a CVE Without Shipping Slop Technical Information Security Content & Discussion · 60d ago PrizeBuzz phishing network analysis Technical Information Security Content & Discussion · 60d ago Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Trend Micro Research, News, Perspectives · 60d ago Shark Jacked my LAN 🦈 Hak5 · 60d ago Malicious JetBrains Marketplace plugins steal AI API keys from developers BleepingComputer · 60d ago Lawmakers leery about Trump administration’s Anthropic order CyberScoop · 60d ago News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails The Last Watchdog · 60d ago AI’s constant patching treadmill can be a security problem CyberScoop · 60d ago 27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass Technical Information Security Content & Discussion · 60d ago AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns Cyber Defense Magazine · 60d ago New Rokarolla Android malware targets 217 banking, crypto apps BleepingComputer · 60d ago News alert: GitGuardian adds endpoint protection as developer laptops become credential troves The Last Watchdog · 60d ago Steam Workshop abused to spread malware via Wallpaper Engine app BleepingComputer · 60d ago TCM Security Summer Sale is Here! The Cyber Mentors · 60d ago A case for how to shape ‘ingredient lists’ for AI models CyberScoop · 60d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 60d ago Copilot Cowork is now generally available Microsoft 365 Blog · 60d ago UK to require ID or face scan before you can make social media accounts BleepingComputer · 60d ago GhostTree Attack Abused Recursive Windows Junctions to Hide Malware BleepingComputer · 60d ago FTC warns of record $3.5 billion losses to imposter scams in 2025 BleepingComputer · 60d ago Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions Cyber Defense Magazine · 60d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 60d ago Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP All CISA Advisories · 60d ago Rockwell Automation RSLinx All CISA Advisories · 60d ago Rockwell Automation FLEX I/O EtherNet/IP Adapters All CISA Advisories · 60d ago Rockwell Automation FactoryTalk Analytics PavilionX All CISA Advisories · 60d ago Rockwell Automation CompactLogix All CISA Advisories · 60d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 60d ago CISA warns of another cPanel plugin flaw exploited in attacks BleepingComputer · 60d ago News alert: Varist announces AI-scale malware detection for healthcare and medical imaging The Last Watchdog · 60d ago Ransomware gang abuses Microsoft Teams relays to hide malicious traffic BleepingComputer · 60d ago Critical Fortinet FortiSandbox flaws now exploited in attacks BleepingComputer · 60d ago Windows version of SprySOCKS Linux malware used to attack govt orgs BleepingComputer · 60d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 60d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 60d ago iRhythm discloses data breach, says hackers stole patient info BleepingComputer · 61d ago DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act BleepingComputer · 61d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 61d ago Google exposes China espionage group that’s been lurking in networks undetected since 2023 CyberScoop · 61d ago SimpleHelp bug lets hackers create rogue remote support accounts BleepingComputer · 61d ago Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE Technical Information Security Content & Discussion · 61d ago OptinMonster WordPress plugin hacked in CDN supply-chain attack BleepingComputer · 61d ago Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks BleepingComputer · 61d ago I was wrong about VPNs NetworkChuck · 61d ago Council of Europe investigates ShinyHunters data breach claims BleepingComputer · 61d ago Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat CyberScoop · 61d ago FBI: Fraudsters use couriers to steal money in crypto scams BleepingComputer · 61d ago Vibe coders are gonna vibe code: How CISOs are tackling code sprawl BleepingComputer · 61d ago Chinese hackers breach REDCap servers, steal medical research BleepingComputer · 61d ago SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon Technical Information Security Content & Discussion · 61d ago Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection? Cyber Defense Magazine · 61d ago New attack turned Microsoft 365 Copilot into 1-click data theft tool BleepingComputer · 61d ago Infinite Campus data breach affects 137,000 school staff accounts BleepingComputer · 61d ago How I Made $30,000 Hacking Broken Access Control NahamSec · 61d ago $30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover NahamSec · 61d ago Webinar: How behavioral AI stops phishing and account takeovers BleepingComputer · 61d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 61d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 61d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 61d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 61d ago FBI disrupts massive AI-powered phishing service using a million URLs BleepingComputer · 62d ago CMMC Is Exposing A Major Gap In The Defense Supply Chain Cyber Defense Magazine · 62d ago Researcher accidentally gained access to a threat actor-controlled phishing website Technical Information Security Content & Discussion · 63d ago PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs Technical Information Security Content & Discussion · 63d ago Ex-school district employee jailed for hacks on former employer BleepingComputer · 63d ago MeshCentral: From XSS to RCE Technical Information Security Content & Discussion · 63d ago Anthropic disables new models after government calls them a national security concern CyberScoop · 63d ago HackTheBox - VariaType IppSec · 63d ago Chinese hackers hijack auth flow, spy on isolated network for a decade BleepingComputer · 63d ago Zero Trust For AI In Defense Networks Cyber Defense Magazine · 63d ago US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos BleepingComputer · 63d ago Getting the PID from random numbers in PHP Technical Information Security Content & Discussion · 63d ago The Axios npm compromise was visible in registry metadata before anyone ran npm install Technical Information Security Content & Discussion · 64d ago FBI takes down massive China-based cybercrime network that caused $1.9B in losses CyberScoop · 64d ago Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs Technical Information Security Content & Discussion · 64d ago ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed darkreading · 64d ago Maine disables data breach notification portal after fake disclosures BleepingComputer · 64d ago US, France, and Italian authorities shut down massive deepfake porn site CyberScoop · 64d ago phpBB forum fixes auth bypass bug lurking for a decade BleepingComputer · 64d ago Ukrainian national pleads guilty to role in Conti ransomware operation BleepingComputer · 64d ago Conti ransomware group member pleads guilty, faces up to 20 years in prison CyberScoop · 64d ago Over 400 Arch Linux packages compromised to push rootkit, infostealer BleepingComputer · 64d ago ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw CyberScoop · 64d ago Free Compromise Detection for GitHub Repos - Tracebit Community Edition Technical Information Security Content & Discussion · 64d ago Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE) Technical Information Security Content & Discussion · 64d ago Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery Technical Information Security Content & Discussion · 64d ago Early Warning Signs of Supply-Chain Attacks Live in the Dark Web BleepingComputer · 64d ago Claude Fable 5 Doesn't Change the Mythos Security Story darkreading · 64d ago Why Most Cyber Resilience Programs Fail Before The First Incident Cyber Defense Magazine · 64d ago Developers React to the 105-Second Github Chain Reaction | Threat Wire Hak5 · 64d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 64d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 64d ago CyberCorps is adapting to AI. The budget isn’t keeping up. CyberScoop · 64d ago Microsoft fixes Windows update failures linked to WUSA installer BleepingComputer · 64d ago Pharma giant Novo Nordisk discloses breach of clinical trials data BleepingComputer · 64d ago CISA orders feds to patch actively exploited Ivanti flaw by Sunday BleepingComputer · 64d ago Over 73,000 French govt employees affected in Tchap messenger breach BleepingComputer · 65d ago Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs Technical Information Security Content & Discussion · 65d ago Phishing Attack Volume Down 20%, But Risk Still Rising darkreading · 65d ago Governing Claude Enterprise in Environments Where Inline Controls Can't Go Trend Micro Research, News, Perspectives · 65d ago Japanese energy firm loses drive with data of 10.9 million clients BleepingComputer · 65d ago Maine breach portal abused to publish fake data breach disclosures BleepingComputer · 65d ago Oracle mitigates PeopleSoft zero-day exploited in data theft attacks BleepingComputer · 65d ago Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules Technical Information Security Content & Discussion · 65d ago Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure darkreading · 65d ago Any solutions we can use? cybersecurity · 65d ago Russian national charged in connection with Void Blizzard espionage campaign CyberScoop · 65d ago DIY pwnagotchi-like device on esp32 hacking: security in practice · 65d ago Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it Reverse Engineering · 65d ago Possible targeted attack cybersecurity · 65d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline cybersecurity · 65d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 65d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 65d ago Facebook messenger to text cybersecurity · 65d ago Claude Fable 5: mid-tier results on coding tasks Technical Information Security Content & Discussion · 65d ago Authorities dismantle 'AudiA6' ransomware crypto-laundering service BleepingComputer · 65d ago US charges suspected Russian hacker with facilitating cyber campaign For [Blue|Purple] Teams in Cyber Defence · 65d ago Flipper Blackhat + Bjorn hacking: security in practice · 65d ago Segmentation Works for OT If Operators Are Paying Attention darkreading · 65d ago Managing Solution Agents cybersecurity · 65d ago Nottingham University data breach affects over 450,000 students cybersecurity · 65d ago SWGs that support 3rd party external DNS resolver cybersecurity · 65d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers cybersecurity · 65d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game Reverse Engineering · 65d ago Why AI-driven threats are exposing the limits of MSP security stacks BleepingComputer · 65d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG cybersecurity · 65d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia For [Blue|Purple] Teams in Cyber Defence · 65d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch cybersecurity · 65d ago Do you think AI is making hacking easier or harder hacking: security in practice · 65d ago Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration Cyber Defense Magazine · 65d ago Coupang hit with record $409 million data breach fine in Korea BleepingComputer · 65d ago CISA tells govt agencies to patch critical exploited flaws in 3 days BleepingComputer · 65d ago Phishing awareness training resulting in ignoring company comms? cybersecurity · 65d ago How are you analyzing Android malware nowadays? cybersecurity · 65d ago Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work Technical Information Security Content & Discussion · 65d ago Hackers Exploit Langflow Vulnerability for Remote Code Execution cybersecurity · 65d ago Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research cybersecurity · 65d ago NEED SOME GUIDANCE cybersecurity · 65d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 65d ago Yarbo Android/iOS Mobile Application and Cloud Infrastructure All CISA Advisories · 65d ago Naxclow IoT Platform All CISA Advisories · 65d ago Brickcom Cameras All CISA Advisories · 65d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 65d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Malware Analysis & Reports · 65d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Reverse Engineering · 65d ago What can i do left? PSN hacking: security in practice · 65d ago Help setting up local encryption on my pc cybersecurity · 65d ago Hacking Google with A.I. for $500,000 Technical Information Security Content & Discussion · 65d ago Agentic AI on Cybersecurity cybersecurity · 65d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 65d ago DoD 0-days Typically Come Down to Authorization Failures cybersecurity · 65d ago HDD cybersecurity · 65d ago Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets cybersecurity · 65d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 65d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 65d ago Microsoft fixes BitLocker recovery bug on Windows Server 2025 BleepingComputer · 65d ago Prompt injection: attacking the analyst's AI Technical Information Security Content & Discussion · 65d ago How can we test the firmware code/images security? cybersecurity · 65d ago 20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004 cybersecurity · 65d ago Proxmark5 campaign ending in less than 18 hours. hacking: security in practice · 65d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 For [Blue|Purple] Teams in Cyber Defence · 65d ago GreatXML: GreatXML bitlocker bypass vulnerability For [Blue|Purple] Teams in Cyber Defence · 65d ago GitHub announces npm security changes to tackle supply-chain attacks cybersecurity · 65d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan For [Blue|Purple] Teams in Cyber Defence · 65d ago The ‘Miasma’ worm source code briefly leaked on GitHub cybersecurity · 65d ago CISA Rewrites Federal Patching Requirements for AI Threat Era cybersecurity · 65d ago What is the difference between Regular TLS and Mutual TLS? cybersecurity · 66d ago Every employee's password was stored in a single Excel file cybersecurity · 66d ago Nottingham University data breach affects over 450,000 students BleepingComputer · 66d ago npm v12 is changing how dependencies are installed to reduce supply-chain risk cybersecurity · 66d ago Max severity Ivanti Sentry vulnerability now exploited in attacks BleepingComputer · 66d ago How to bypass speed queen coin slot for washer and dryer hacking: security in practice · 66d ago LIVE: 🕵️ CTF Prize Draw | Cybersecurity The Cyber Mentors · 66d ago Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia? cybersecurity · 66d ago Drive Firmware Security - Phison S11 Reverse Engineering · 66d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue For [Blue|Purple] Teams in Cyber Defence · 66d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion For [Blue|Purple] Teams in Cyber Defence · 66d ago How good Microsoft Defender for storage? cybersecurity · 66d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default For [Blue|Purple] Teams in Cyber Defence · 66d ago GreatXML bitlocker bypass vulnerability cybersecurity · 66d ago Struggle cybersecurity · 66d ago Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications? cybersecurity · 66d ago Chinese, N. Korean Threat Groups Build on Asia-Pacific Success darkreading · 66d ago Wiz launches Cloud Security Job Board cybersecurity · 66d ago Physical Project Ideas cybersecurity · 66d ago How can I get into cybersecurity while studying Information Systems Engineering? cybersecurity · 66d ago Miasma-style supply chain attacks For [Blue|Purple] Teams in Cyber Defence · 66d ago Cloud Security job board cybersecurity · 66d ago Continuous learning cybersecurity · 66d ago Self-hosting stuff for when things get ugly hacking: security in practice · 66d ago Path traversal flaw in AI dev platform Langflow exploited in attacks BleepingComputer · 66d ago CISA Rewrites Federal Patching Requirements for AI Threat Era darkreading · 66d ago Angry bug hunter with Microsoft beef drops new Windows 0-day cybersecurity · 66d ago The ‘Miasma’ worm source code briefly leaked on GitHub BleepingComputer · 66d ago OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers CyberScoop · 66d ago Bug Bounty Research Triggers ServiceNow Security Alert darkreading · 66d ago Mid-30s, stuck in web pentesting, and wondering what to do ? cybersecurity · 66d ago GitHub announces npm security changes to tackle supply-chain attacks BleepingComputer · 66d ago AI Risk Worries Insurers & Businesses Alike darkreading · 66d ago Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM cybersecurity · 66d ago Is Microsoft Purview really secure when using Copilot? cybersecurity · 66d ago Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review Technical Information Security Content & Discussion · 66d ago News alert: Cloud security report finds fragmented tools widening the cloud complexity gap The Last Watchdog · 66d ago Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks BleepingComputer · 66d ago Malware Includes Taboo In Text To Prevent LLM Analysis hacking: security in practice · 66d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet For [Blue|Purple] Teams in Cyber Defence · 66d ago Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature? cybersecurity · 66d ago added Mac support for my corporate hacking game, demo on Steam hacking: security in practice · 66d ago IDA 9.4 Beta | Hex-Rays Docs Reverse Engineering · 66d ago Nee academic references for Hashcat's 'Next Big Bang' log cybersecurity · 66d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs For [Blue|Purple] Teams in Cyber Defence · 66d ago CISA released BOD 26-04: A new federal government vulnerability management strategy? cybersecurity · 66d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace For [Blue|Purple] Teams in Cyber Defence · 66d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days cybersecurity · 66d ago IMPACT Roadshow Recap: Getting Ready for Agentic Commerce Blog – Forter · 66d ago added Mac support to my corporate hacking sim. Demo now available on Steam cybersecurity · 66d ago Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet darkreading · 66d ago CISA directive orders agencies to prioritize vulnerability patching in a new way CyberScoop · 66d ago We post-trained a model for offensive security instead of teaching it to refuse Technical Information Security Content & Discussion · 66d ago Catfished hacking: security in practice · 66d ago Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte) cybersecurity · 66d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper Malware Analysis & Reports · 66d ago China-linked JDY botnet expands targeting of U.S. military networks BleepingComputer · 66d ago Students' data taken in major University of Nottingham cyber-attack cybersecurity · 66d ago Has unmanaged external file sharing ever burned you? cybersecurity · 66d ago The 5 Best Practices for Secure Identity Verification BleepingComputer · 66d ago Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers cybersecurity · 66d ago Microsoft patches Exchange Server zero-day exploited in attacks BleepingComputer · 66d ago Trane Tracer HVAC cybersecurity issues Reverse Engineering · 66d ago Need feedback on my presentation cybersecurity · 66d ago Compensating controls besides admin credentials being needed to download software on employee endpoints cybersecurity · 66d ago OpenSSL PKCS#7 CVE-2026-45447 cybersecurity · 66d ago Testing offensive AI agents in a cloud lab with deception tech For [Blue|Purple] Teams in Cyber Defence · 66d ago What The Cybersecurity Industry Knows And Will Not Say Cyber Defense Magazine · 66d ago Presentation Question cybersecurity · 66d ago What did they mean by this? One of us? hacking: security in practice · 66d ago How to Stay Ahead of Deepfake Evolution in 2026 cybersecurity · 66d ago How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026 Technical Information Security Content & Discussion · 66d ago FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster Technical Information Security Content & Discussion · 66d ago Microsoft: Some Windows PCs fail to install latest monthly updates BleepingComputer · 66d ago France’s Government Messaging App Tchap Got Breached cybersecurity · 66d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days BleepingComputer · 66d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap Malware Analysis & Reports · 66d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 66d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 66d ago certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA" Technical Information Security Content & Discussion · 66d ago Where's the fix for MiniPlasma? cybersecurity · 66d ago BlackSun - Defender for Endpoint on macOS Technical Information Security Content & Discussion · 67d ago ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances cybersecurity · 67d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges hacking: security in practice · 67d ago GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline) Technical Information Security Content & Discussion · 67d ago Internships cybersecurity · 67d ago Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS cybersecurity · 67d ago Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows cybersecurity · 67d ago Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam Technical Information Security Content & Discussion · 67d ago Ivanti: Max severity Sentry flaw allows code execution as root BleepingComputer · 67d ago Looking for a Reliable Cybersecurity Provider for a School in North Sydney cybersecurity · 67d ago Early Operational Visibility cybersecurity · 67d ago Benchmarking n-day exploit generation [via AI] For [Blue|Purple] Teams in Cyber Defence · 67d ago how are you actually managing ai agents in production? cybersecurity · 67d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) Reverse Engineering · 67d ago Al app builders: How are you handling security questionnaires when selling your product? cybersecurity · 67d ago [ Removed by Reddit ] cybersecurity · 67d ago How are all of doing with THE AI model thats big news currently?? cybersecurity · 67d ago Whoops! I did it again. I patched Windows Kernel at Milan0day 2026 For [Blue|Purple] Teams in Cyber Defence · 67d ago Microsoft Defender now monitors RPC activity For [Blue|Purple] Teams in Cyber Defence · 67d ago Skill to Scan your Codebase cybersecurity · 67d ago RoguePlanet: RoguePlanet Windows Defender Vulnerability For [Blue|Purple] Teams in Cyber Defence · 67d ago Miasma-style supply chain attacks cybersecurity · 67d ago FCaptcha v1.12: Catching AI Agents That Drive Real Browsers cybersecurity · 67d ago Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones cybersecurity · 67d ago Anthropic rolls out Claude Fable 5, but it's available for a limited time BleepingComputer · 67d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs cybersecurity · 67d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs Technical Information Security Content & Discussion · 67d ago AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say cybersecurity · 67d ago GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 Trend Micro Research, News, Perspectives · 67d ago Huntress Stack (MS Defender or SentinelOne) cybersecurity · 67d ago META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT cybersecurity · 67d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges BleepingComputer · 67d ago OptOutCode – A Privacy4Cars Universal Opt-Out Concept hacking: security in practice · 67d ago I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in) For [Blue|Purple] Teams in Cyber Defence · 67d ago The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life darkreading · 67d ago FBI is announcing Operation Riptide cybersecurity · 67d ago Blame AI: Patch Tuesday Hits Record 206 CVEs darkreading · 67d ago ServiceNow confirmed some customer instances were breached. cybersecurity · 67d ago ServiceNow discloses security incident exposing customer data BleepingComputer · 67d ago Which are some of the best Cybersecurity / OT Security events that happen in GCC? cybersecurity · 67d ago OpenClaw AI agent found falling for phishing attacks, spills user data BleepingComputer · 67d ago DF/IR Community cybersecurity · 67d ago Chaotic Eclipse's new RoguePlanet cybersecurity · 67d ago Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address darkreading · 67d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace cybersecurity · 67d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace Malware Analysis & Reports · 67d ago Microsoft breaks Patch Tuesday record with 206 vulnerabilities CyberScoop · 67d ago Thoughts on Automated Compliance? cybersecurity · 67d ago SAP fixes critical flaws in NetWeaver and Commerce Cloud BleepingComputer · 67d ago Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories darkreading · 67d ago A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available cybersecurity · 67d ago Apple’s Siri-AI, or more shouting into the void about “private” agents Technical Information Security Content & Discussion · 67d ago How do you make learning blue team security entertaining ? For [Blue|Purple] Teams in Cyber Defence · 67d ago North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says cybersecurity · 67d ago Microsoft has released a patch for the bitlocker bypass cybersecurity · 67d ago Microsoft releases Windows 10 KB5094127 extended security update BleepingComputer · 67d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. Reverse Engineering · 67d ago Please advices cybersecurity · 67d ago Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws BleepingComputer · 67d ago Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws BleepingComputer · 67d ago soc analyst l1 cybersecurity · 67d ago Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow cybersecurity · 67d ago Looking to move off KnowBe4, what are people actually using these days? cybersecurity · 67d ago Maximizing IOC Impact For [Blue|Purple] Teams in Cyber Defence · 67d ago Windows 11 KB5094126 & KB5093998 cumulative updates released BleepingComputer · 67d ago Too Many Certs, Not Enough Experience — What’s the Best Next Step? cybersecurity · 67d ago Anthropic’s new model is Mythos on a leash CyberScoop · 67d ago Authenticating ARP and NDP cybersecurity · 67d ago Does anyone use rule feeds in 2026? cybersecurity · 67d ago [2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution For [Blue|Purple] Teams in Cyber Defence · 67d ago CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector CyberScoop · 67d ago Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations! cybersecurity · 67d ago Need a vm for practice cybersecurity · 67d ago XBOW tests Anthropic's Mythos Preview for offensive security BleepingComputer · 67d ago Tips/Tricks to WFH as a SOC Analyst? cybersecurity · 67d ago Cybersecurity statistics of the week (June 1st - June 7th) cybersecurity · 67d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks For [Blue|Purple] Teams in Cyber Defence · 67d ago Where can GRC folks learn practical AppSec / DevSecOps without going full engineer? cybersecurity · 67d ago GitHub disables Microsoft repos pushing password-stealing malware BleepingComputer · 67d ago Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs darkreading · 67d ago I almost got “onboarded” into a malware campaign disguised as a job opportunity. cybersecurity · 67d ago University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model cybersecurity · 67d ago AI Blocklist - help cybersecurity · 67d ago New Veeam vulnerability exposes backup servers to RCE attacks BleepingComputer · 67d ago Entra Agent ID from a Security Perspective For [Blue|Purple] Teams in Cyber Defence · 67d ago Cisco customers encounter another SD-WAN zero-day under attack CyberScoop · 67d ago Entra Agent ID from a Security Perspective Technical Information Security Content & Discussion · 67d ago Protecting AI workloads on Linux servers cybersecurity · 67d ago Exposing DoNex Ransomware Secrets with Malcore! cybersecurity · 67d ago What are the different Disaster Recovery scenarios your teams have tested on? cybersecurity · 67d ago someone actually leaked the Miasma supply chain attack toolkit source code on github cybersecurity · 67d ago X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection Technical Information Security Content & Discussion · 67d ago Rethinking Access Governance for AI Agents Cyber Defense Magazine · 67d ago Secrets to PNPT Debrief Success The Cyber Mentors · 67d ago Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility For [Blue|Purple] Teams in Cyber Defence · 67d ago WinGet - Code Execution, Persistence and Detection Strategies cybersecurity · 67d ago WinGet - Code Execution, Persistence and Detection Strategies Technical Information Security Content & Discussion · 67d ago Ransomware attack shuts Illinois high school until Wednesday cybersecurity · 67d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 67d ago Siemens KACO Blueplanet Inverters All CISA Advisories · 67d ago Schneider Electric EcoStruxure Panel Server All CISA Advisories · 67d ago Schneider Electric Modicon Network Managed Switches All CISA Advisories · 67d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 67d ago Ideas for demo cybersecurity · 67d ago French govt messaging service breached in account hijacking attack BleepingComputer · 67d ago Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please? cybersecurity · 67d ago Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares. cybersecurity · 67d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue Technical Information Security Content & Discussion · 67d ago Physical attack device cybersecurity · 67d ago Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer cybersecurity · 67d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 67d ago IT GRC News? cybersecurity · 67d ago CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day BleepingComputer · 67d ago Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again cybersecurity · 67d ago I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information Technical Information Security Content & Discussion · 68d ago What are the best risk-based vulnerability management tools for tracking active exploitation in 2026? For [Blue|Purple] Teams in Cyber Defence · 68d ago Google patches new Chrome zero-day flaw exploited in the wild BleepingComputer · 68d ago QuasarNix: Reverse Shell Detection with Machine Learning For [Blue|Purple] Teams in Cyber Defence · 68d ago Shifting L7 validation to the edge to stop DB resource exhaustion? cybersecurity · 68d ago Google Patches 5th Chrome Zero-Day Exploited in 2026 cybersecurity · 68d ago AI Agents May Always Fall for Prompt Injections Technical Information Security Content & Discussion · 68d ago Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go For [Blue|Purple] Teams in Cyber Defence · 68d ago EC Council CEH exam advice cybersecurity · 68d ago Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion For [Blue|Purple] Teams in Cyber Defence · 68d ago Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 For [Blue|Purple] Teams in Cyber Defence · 68d ago About NPower vs PerScholas cybersecurity · 68d ago Looking for a vulnerability to learn cybersecurity · 68d ago Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency For [Blue|Purple] Teams in Cyber Defence · 68d ago From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk cybersecurity · 68d ago UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season For [Blue|Purple] Teams in Cyber Defence · 68d ago Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) For [Blue|Purple] Teams in Cyber Defence · 68d ago Visual Studio Code 1.123: Delayed extension auto-updates For [Blue|Purple] Teams in Cyber Defence · 68d ago Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users. For [Blue|Purple] Teams in Cyber Defence · 68d ago Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, For [Blue|Purple] Teams in Cyber Defence · 68d ago Bad USB through charger? cybersecurity · 68d ago Recommendations for Discord community for latest AI security products cybersecurity · 68d ago StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams hacking: security in practice · 68d ago Vulnerability Summary for the Week of June 1, 2026 cybersecurity · 68d ago Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas cybersecurity · 68d ago I feel like ive lost my passion to tinker after 6 years in the industry, anyone else? cybersecurity · 68d ago I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples cybersecurity · 68d ago really need help with project ideas for MSc cybersecurity · 68d ago Which Course for an almost-complete noob? (SANS.edu) cybersecurity · 68d ago NFCShare Android malware spreads via fake banking app updates on GitHub BleepingComputer · 68d ago SoFi confirms third-party data breach at Hong Kong subsidiary cybersecurity · 68d ago AI Slop Will Kill Cybersecurity Storytelling If We Let It darkreading · 68d ago SoFi confirms third-party data breach at Hong Kong subsidiary BleepingComputer · 68d ago For the 2nd time in weeks, Microsoft packages laced with credential stealer cybersecurity · 68d ago Iran Signed a Ceasefire — Its Hackers Didn't cybersecurity · 68d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages cybersecurity · 68d ago DSPM étude marche cybersecurity · 68d ago CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file cybersecurity · 68d ago New Apple feature automatically changes your compromised passwords BleepingComputer · 68d ago Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks darkreading · 68d ago AppSec / Pentesting job market in Canada for experienced overseas applicants? cybersecurity · 68d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages BleepingComputer · 68d ago Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients. cybersecurity · 68d ago Check Point VPN Flaw Exploited Since Early May darkreading · 68d ago Automation Playbooks - which ones would you not want to live without? cybersecurity · 68d ago Is it necessary/important to Hash and salt API Keys for a strictly internal use tool? cybersecurity · 68d ago Need review on the OMS Cybersecurity program from Georgia Tech? cybersecurity · 68d ago If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk cybersecurity · 68d ago 2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years cybersecurity · 68d ago Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement For [Blue|Purple] Teams in Cyber Defence · 68d ago How do you close an alert cybersecurity · 68d ago Iran Signed a Ceasefire — Its Hackers Didn't darkreading · 68d ago What cybersecurity certifications are great value for money? cybersecurity · 68d ago Boxes for CPENT cybersecurity · 68d ago WhatsApp says it disrupted new NSO spyware phishing attacks BleepingComputer · 68d ago SIEM: is it "SIM" or "SEEM" cybersecurity · 68d ago I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included) cybersecurity · 68d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment Malware Analysis & Reports · 68d ago How justdeleteme and justgetmydata work? cybersecurity · 68d ago Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint CyberScoop · 68d ago GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks. hacking: security in practice · 68d ago How CIAM Helps Boost Business Cyber Defense Magazine · 68d ago I need help - PCI DSS 4.0 requirement 11.6.1 cybersecurity · 68d ago How are you learning agent pen testing? cybersecurity · 68d ago Gogs patches critical zero-day enabling remote code execution BleepingComputer · 68d ago HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified) For [Blue|Purple] Teams in Cyber Defence · 68d ago Cyber security intern cybersecurity · 68d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 68d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 68d ago Introducing Shark Jack Display 🦈 Hak5 · 68d ago Meta to take legal action against Israeli spyware company NSO cybersecurity · 68d ago Critical UniFi OS bug lets hackers gain root without authentication BleepingComputer · 68d ago Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit cybersecurity · 68d ago What's the best way to alert companies of a Glassworm copycat? cybersecurity · 68d ago How To Verify If A Site Is Legit? cybersecurity · 68d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 68d ago What is Flaresolverr cybersecurity · 68d ago Research: defenders using generative AI to simulate malware variants before they exist in the wild cybersecurity · 68d ago Reducing security operations complexity with Wazuh Cloud BleepingComputer · 68d ago How are regulated orgs actually letting engineers use Claude Code / Copilot? cybersecurity · 68d ago Cyber security expo Manchester cybersecurity · 68d ago Content creations was both a blessing and a curse. #bugbounty NahamSec · 68d ago Remote Hiring Opened the Talent Pool — and the Fraud Surface cybersecurity · 68d ago Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it Technical Information Security Content & Discussion · 68d ago Check Point links VPN zero-day attacks to Qilin ransomware gang BleepingComputer · 68d ago World Cloud Security Day Cyber Defense Magazine · 68d ago This Hacker Made $7,000 Hacking AI With One Email NahamSec · 68d ago EMBA firmware analysis framework v2.0.2 available - Party the big 2k Reverse Engineering · 68d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks cybersecurity · 68d ago What certs should I do during summer of 11th grade? cybersecurity · 68d ago CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) cybersecurity · 68d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 68d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 68d ago Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine cybersecurity · 68d ago Oxford University discloses data breach after careers platform hack cybersecurity · 68d ago Oxford University discloses data breach after careers platform hack BleepingComputer · 68d ago Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing cybersecurity · 68d ago Got this message from “SimBoss” cybersecurity · 68d ago PKCS12 Golang fork cybersecurity · 68d ago The AI security race needs accountability, not overregulation CyberScoop · 68d ago Malware Insights: Miasma Campaign cybersecurity · 68d ago 73 Microsoft GitHub repositories impacted by Miasma malware Malware Analysis & Reports · 68d ago 73 Microsoft GitHub repositories impacted by Miasma malware cybersecurity · 68d ago [Honeypot Research] Looking for volunteers to test telemetry/logs cybersecurity · 68d ago Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏 hacking: security in practice · 68d ago What is the condition of Bug Bounty program in the era of AI. cybersecurity · 69d ago Opening a cloned repo is no longer safe cybersecurity · 69d ago Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse cybersecurity · 69d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 69d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 69d ago Google Colab CLI opens runtimes to Claude Code and Codex cybersecurity · 69d ago VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks cybersecurity · 69d ago Over 20,000 Instagram accounts stolen in Meta AI support hack BleepingComputer · 69d ago The AI governance gap no one is talking about: deployment-stage accountability cybersecurity · 69d ago Security Review Request — TID Linux Kernel Module For [Blue|Purple] Teams in Cyber Defence · 69d ago Building a safe, effective sandbox to enable Codex on Windows For [Blue|Purple] Teams in Cyber Defence · 69d ago Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. For [Blue|Purple] Teams in Cyber Defence · 69d ago About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection For [Blue|Purple] Teams in Cyber Defence · 69d ago BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection For [Blue|Purple] Teams in Cyber Defence · 69d ago Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution. For [Blue|Purple] Teams in Cyber Defence · 69d ago Unauthorized Onlyfans Payment Malware Analysis & Reports · 69d ago Free Study Resources for Comptia Cysa+ cybersecurity · 69d ago What's up with powershellforhackers.com? hacking: security in practice · 69d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 69d ago Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Trend Micro Research, News, Perspectives · 69d ago Hands on with Intelligent Terminal, an AI-powered Windows Terminal BleepingComputer · 69d ago Hi there cybersecurity · 69d ago Final risk-based IT Audit interview round with Director and have no experience. Please help! cybersecurity · 69d ago Needed help cybersecurity · 69d ago HDD Firmware Hacking Part 1 Reverse Engineering · 69d ago [ Removed by Reddit ] cybersecurity · 69d ago UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service. For [Blue|Purple] Teams in Cyber Defence · 69d ago Career advice cybersecurity · 69d ago Do people really click on links from unknown numbers? hacking: security in practice · 69d ago PhD in cyber Security cybersecurity · 69d ago Built a password guessing game. Almost everyone stuck in level 5. cybersecurity · 69d ago OSINT (SOCIAL MEDIA) cybersecurity · 69d ago Beginner KQL project cybersecurity · 69d ago Question about WORM and encryption cybersecurity · 69d ago Update:Certified cyber security cybersecurity · 69d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction Reverse Engineering · 69d ago How to unlock whitelabeled uniview IPcam hacking: security in practice · 69d ago EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server. For [Blue|Purple] Teams in Cyber Defence · 69d ago Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental cybersecurity · 69d ago Can converted video files contain malware? hacking: security in practice · 69d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction) cybersecurity · 69d ago Malware that survives reinstalling the BIOS and OS cybersecurity · 69d ago Am I overthinking the x86 compatibility issues? how much friction am I actually facing? cybersecurity · 69d ago Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure cybersecurity · 69d ago Managing Microsoft Identity Is More Complicated Than It Looks cybersecurity · 69d ago C0XMO botnet spreads via DD-WRT router flaw, kills rival malware BleepingComputer · 69d ago Silent Ransom Group targets law firms with fake IT support calls BleepingComputer · 69d ago Zhiyun Weebil-S Camera Gimbal BLE Protocol Reverse Engineering · 69d ago My work email got subscribed to a bunch of israel newsletters cybersecurity · 69d ago Shadow AI cybersecurity · 69d ago Rate limiting is not enough. What else can I use? cybersecurity · 69d ago CMMC Is Here, But AI Changes The Compliance Conversation Cyber Defense Magazine · 69d ago How To Avoid Potential Malware From Transferring To New Laptop cybersecurity · 69d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 cybersecurity · 69d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 69d ago Can't decide. cybersecurity · 69d ago looking for partners cybersecurity · 69d ago My edge is changing into bing when I search something cybersecurity · 69d ago Reverse Engineering the Garmin Running Dynamics BLE protocol Reverse Engineering · 69d ago Cybersecurity reality check cybersecurity · 69d ago [ Removed by Reddit ] cybersecurity · 69d ago EDRChoker: Choking The Telemetry Stream to Bypass Defenses Technical Information Security Content & Discussion · 69d ago Information Management cybersecurity · 69d ago Pwnd Blaster: Hacking your PC using your speaker without ever touching it For [Blue|Purple] Teams in Cyber Defence · 69d ago cygor: An modular asset discovery framework written in python to automate the repeating manual work For [Blue|Purple] Teams in Cyber Defence · 69d ago On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts. For [Blue|Purple] Teams in Cyber Defence · 70d ago Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors. For [Blue|Purple] Teams in Cyber Defence · 70d ago Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim For [Blue|Purple] Teams in Cyber Defence · 70d ago Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored) For [Blue|Purple] Teams in Cyber Defence · 70d ago The Privileged Roles Nobody Talks About For [Blue|Purple] Teams in Cyber Defence · 70d ago Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain... For [Blue|Purple] Teams in Cyber Defence · 70d ago Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis For [Blue|Purple] Teams in Cyber Defence · 70d ago 21 Zero-Days in FFmpeg For [Blue|Purple] Teams in Cyber Defence · 70d ago IronWorm Malware cybersecurity · 70d ago Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh? cybersecurity · 70d ago Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh? cybersecurity · 70d ago Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager cybersecurity · 70d ago depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research? For [Blue|Purple] Teams in Cyber Defence · 70d ago PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware Technical Information Security Content & Discussion · 70d ago Is a separate “clean” S3 bucket actually a security boundary for uploaded files? cybersecurity · 70d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass Technical Information Security Content & Discussion · 70d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass cybersecurity · 70d ago CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work For [Blue|Purple] Teams in Cyber Defence · 70d ago PenTest+ Exam cybersecurity · 70d ago Rooted your router lately? hacking: security in practice · 70d ago AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs cybersecurity · 70d ago The Detection & Response Chronicles: Covert Operations Through QEMU For [Blue|Purple] Teams in Cyber Defence · 70d ago The Interesting Case of WSL for Payload Staging For [Blue|Purple] Teams in Cyber Defence · 70d ago The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer For [Blue|Purple] Teams in Cyber Defence · 70d ago Ongoing Targeted Campaign Against US Law Firms For [Blue|Purple] Teams in Cyber Defence · 70d ago New China-Linked Cluster OP-512 For [Blue|Purple] Teams in Cyber Defence · 70d ago Looking for guidance cybersecurity · 70d ago 5$ to whoever can find the email of my old YouTube channel hacking: security in practice · 70d ago Before you attempt any OffSec certification, read what just happened to me cybersecurity · 70d ago Reporting Metrics for Management cybersecurity · 70d ago got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time cybersecurity · 70d ago This company is scaming people hacking: security in practice · 70d ago Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried cybersecurity · 70d ago HackTheBox - Facts IppSec · 70d ago Critical Everest Forms Pro flaw exploited to take over WordPress sites BleepingComputer · 70d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. cybersecurity · 70d ago AI Security Certificates cybersecurity · 70d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. For [Blue|Purple] Teams in Cyber Defence · 70d ago Guys is bug bounty dead? cybersecurity · 70d ago How are folks making it in bug bounty? cybersecurity · 70d ago How useful is it to require at least one uppercase letter in a password? cybersecurity · 70d ago Cybersecurity Improved Detection But Exposed a New Problem Cyber Defense Magazine · 70d ago Cyber security ! Is no more ? cybersecurity · 70d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 70d ago MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain For [Blue|Purple] Teams in Cyber Defence · 70d ago Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated For [Blue|Purple] Teams in Cyber Defence · 70d ago Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns For [Blue|Purple] Teams in Cyber Defence · 70d ago About ETW Internals: Architecture, Hooking, Tampering, and Detection For [Blue|Purple] Teams in Cyber Defence · 70d ago PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver For [Blue|Purple] Teams in Cyber Defence · 70d ago Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp For [Blue|Purple] Teams in Cyber Defence · 70d ago Async PICOs and Custom Beacon Wakeups in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 70d ago Enter the WasmForge: Compiling Sliver into WebAssembly For [Blue|Purple] Teams in Cyber Defence · 70d ago staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs For [Blue|Purple] Teams in Cyber Defence · 70d ago Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window For [Blue|Purple] Teams in Cyber Defence · 70d ago Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS For [Blue|Purple] Teams in Cyber Defence · 70d ago BOF Cocktails in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 70d ago Address Translation For [Blue|Purple] Teams in Cyber Defence · 70d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 70d ago Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months cybersecurity · 70d ago Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories cybersecurity · 70d ago Investigation into APT 5 and their inner workings of PLA Troop 61786 For [Blue|Purple] Teams in Cyber Defence · 70d ago How to train employees to feel when something's off? cybersecurity · 70d ago Building A Malware Lab From Scratch Part 2! Malware Analysis & Reports · 70d ago A modular autonomous-agent runtime written in C hacking: security in practice · 70d ago The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy For [Blue|Purple] Teams in Cyber Defence · 70d ago ALERT OVERLOAD cybersecurity · 70d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems For [Blue|Purple] Teams in Cyber Defence · 70d ago Magecart skimmer turns Stripe into a malware command server For [Blue|Purple] Teams in Cyber Defence · 70d ago Security advisory: Brute force attack on Dashlane user accounts For [Blue|Purple] Teams in Cyber Defence · 70d ago Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability For [Blue|Purple] Teams in Cyber Defence · 70d ago A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact). For [Blue|Purple] Teams in Cyber Defence · 70d ago IronWorm: Shai-Hulud's rustier cousin For [Blue|Purple] Teams in Cyber Defence · 70d ago Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate) Reverse Engineering · 70d ago CTO at NCSC Summary: week ending June 7th cybersecurity · 70d ago Weil reportedly pays up to $20 million after hackers steal client data For [Blue|Purple] Teams in Cyber Defence · 70d ago CTO at NCSC Summary: week ending June 7th For [Blue|Purple] Teams in Cyber Defence · 70d ago A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled cybersecurity · 70d ago defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize For [Blue|Purple] Teams in Cyber Defence · 71d ago 1-Click GitHub Token Stealing via a VSCode Bug For [Blue|Purple] Teams in Cyber Defence · 71d ago The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds For [Blue|Purple] Teams in Cyber Defence · 71d ago Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub cybersecurity · 71d ago Detecting npm Native Addon Malware: node-gyp Abuse Malware Analysis & Reports · 71d ago AppSec Engineer Interview Stories cybersecurity · 71d ago [OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps. cybersecurity · 71d ago Multi-layer sandbox for native code execution on Linux with no external deps. For [Blue|Purple] Teams in Cyber Defence · 71d ago Is there a safe way to continue using (unsupported) Windows 10? cybersecurity · 71d ago Is Splunk suitable for smaller Enterprises? cybersecurity · 71d ago Has anyone else had MFA prompt fatigue issues with users? cybersecurity · 71d ago Data Scrubbing from Databases cybersecurity · 71d ago Best Certificates? cybersecurity · 71d ago Rant cybersecurity · 71d ago New York passes data center moratorium and consumer protections as environmental, and housing proposals stall cybersecurity · 71d ago Cyber attackers have a new favorite, the browser cybersecurity · 71d ago Looking to get into cybersecurity in web3 cybersecurity · 71d ago Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests cybersecurity · 71d ago Suspicious Polyfill login prompts pop up on Toshiba, Muji websites BleepingComputer · 71d ago Should i use email 2fa or only auth and phone number? cybersecurity · 71d ago Can I break into cybersecurity with a white collar felony? cybersecurity · 71d ago Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale cybersecurity · 71d ago How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time? cybersecurity · 71d ago What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent? cybersecurity · 71d ago Innovator Spotlight: Airrived Cyber Defense Magazine · 71d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers BleepingComputer · 71d ago How Hard is This cybersecurity · 71d ago Reverse Engineering Crazy Taxi, Part 3 Reverse Engineering · 71d ago Ghidra 12.1.2 has been released! Reverse Engineering · 71d ago Installed Fake Codex hidden as a google site cybersecurity · 71d ago Chinese APT deploys new malware to keep access to hacked networks BleepingComputer · 71d ago Virustital scan result help cybersecurity · 71d ago CrowdStrike Turned an AI Wave Into Its Best Quarter Ever cybersecurity · 71d ago Dark web Nemesis Market vendor gets 26 years for selling drugs BleepingComputer · 71d ago ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more hacking: security in practice · 71d ago Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions? cybersecurity · 71d ago I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now cybersecurity · 71d ago Being a Security Engineer? Which AI-powered tools are you using on a daily basis? cybersecurity · 71d ago Over 900 US gas station tank gauge systems exposed to attacks cybersecurity · 71d ago Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person cybersecurity · 71d ago SIEM is broken in the AI agents era cybersecurity · 71d ago TCM Security CTF Walkthrough The Cyber Mentors · 71d ago Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption Technical Information Security Content & Discussion · 71d ago Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected cybersecurity · 71d ago Extending a map tool for Cataclismo Reverse Engineering · 71d ago Over 900 US gas station tank gauge systems exposed to attacks BleepingComputer · 71d ago Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away CyberScoop · 71d ago Keeping Secrets Out of Logs Technical Information Security Content & Discussion · 71d ago Phantom Gyp npm Worm Abuses node-gyp Build Hooks cybersecurity · 71d ago Certified cybersecurity ISC2 cybersecurity · 71d ago Help studying for OSCP cybersecurity · 71d ago The current state of Threat Intelligence Tooling cybersecurity · 71d ago What 2026 DBIR Confirms: Attacks Are Living in the Browser BleepingComputer · 71d ago Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware cybersecurity · 71d ago I've been reverse engineering a lost 2010 horse MMO and I need contributors Reverse Engineering · 71d ago Cloud Security In Practice Cyber Defense Magazine · 71d ago We tested offensive AI agents against deception technology cybersecurity · 71d ago A matter that I have been losing my sleep over cybersecurity · 71d ago Any experience with Rootly or incident.io for cyber incident management? cybersecurity · 71d ago CTIA Study Resources & Preparation Advice? cybersecurity · 71d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 71d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 71d ago Black hat uk vs brucon cybersecurity · 71d ago Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier) Technical Information Security Content & Discussion · 71d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks cybersecurity · 71d ago NIS2 hits railway hard cybersecurity · 71d ago Introducing Package Proxy: supply-chain safety checks without client-side software For [Blue|Purple] Teams in Cyber Defence · 71d ago I need help guys… :( cybersecurity · 71d ago Question from the Seniors cybersecurity · 71d ago China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware cybersecurity · 71d ago AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer For [Blue|Purple] Teams in Cyber Defence · 71d ago Can one reveal the asterisks in an email? hacking: security in practice · 71d ago what certs have u seen in ai security related job posts ? cybersecurity · 71d ago How is the Security Architecture / Strategic IT Security process structured in your organization? cybersecurity · 71d ago Proxmark3 vs Proxmark5 Side by Side hacking: security in practice · 71d ago Should I go for it? hacking: security in practice · 71d ago What's happening in cybersecurity job market in US and Europe these days? cybersecurity · 71d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links Malware Analysis & Reports · 72d ago Has any of you pivoted from GRC to CTI? cybersecurity · 72d ago Up-date-list of cybercrime types? cybersecurity · 72d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks BleepingComputer · 72d ago HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes Reverse Engineering · 72d ago What else should I learn to build a strong cybersecurity foundation? cybersecurity · 72d ago zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS) For [Blue|Purple] Teams in Cyber Defence · 72d ago Hackerone interview cybersecurity · 72d ago Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix cybersecurity · 72d ago The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory For [Blue|Purple] Teams in Cyber Defence · 72d ago VerdantBamboo: Just Another BRICKSTORM in the Firewall For [Blue|Purple] Teams in Cyber Defence · 72d ago AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID For [Blue|Purple] Teams in Cyber Defence · 72d ago MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code For [Blue|Purple] Teams in Cyber Defence · 72d ago IronWorm Supply Chain Malware Hits npm For [Blue|Purple] Teams in Cyber Defence · 72d ago FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel For [Blue|Purple] Teams in Cyber Defence · 72d ago FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad For [Blue|Purple] Teams in Cyber Defence · 72d ago You do surprise me.exe: An unexpected executable in Hola Browser For [Blue|Purple] Teams in Cyber Defence · 72d ago Testing URL Rewriting? cybersecurity · 72d ago Got an internship in IAM with no qualifications and no soft skills cybersecurity · 72d ago Work Hours of DFIR/Cloud Security vs Pentest cybersecurity · 72d ago Narcissistic Tech Leader.... cybersecurity · 72d ago Anyone else's firewall logs just explode after midnight? cybersecurity · 72d ago I'm replacing myself.. at least the boring parts cybersecurity · 72d ago Anyone else dealing with these phantom login attempts from China? cybersecurity · 72d ago Multi-layer sandbox for native code execution on Linux with no external deps. Reverse Engineering · 72d ago Best way to fully clear windows and set everything up securely (pc, accounts etc) cybersecurity · 72d ago IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks cybersecurity · 72d ago Soc analyst cybersecurity · 72d ago Do companies actually require cybersecurity insurance cybersecurity · 72d ago Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header hacking: security in practice · 72d ago Certification Questions | LIVE AMA | Summer of CCNA NetworkChuck · 72d ago Brave Software releases Origin for a paid, bloat-free browsing experience BleepingComputer · 72d ago Hola Browser for Windows compromised to deliver cryptominer BleepingComputer · 72d ago Credit card theft campaign abuses Stripe to host stolen payment info BleepingComputer · 72d ago Hill Dems hammer GOP for $250M CISA budget cut CyberScoop · 72d ago Uncommon/Unusual CrowdStrike Alerts cybersecurity · 72d ago Cyber analyst: law firm or bank cybersecurity · 72d ago best free av and how do i properly setup passwords? cybersecurity · 72d ago Five 9 Vulnerability cybersecurity · 72d ago Failed to verify LHOST error for long links in metasploit hacking: security in practice · 72d ago CVE Lite CLI closes dependency gap — but won't stop modern threats cybersecurity · 72d ago DentaQuest data breach exposed info of 2.6 million accounts BleepingComputer · 72d ago Scope change cybersecurity · 72d ago We just stopped a social engineering attack on our service desk. Here’s how it played out. cybersecurity · 72d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Reverse Engineering · 72d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Technical Information Security Content & Discussion · 72d ago Your AI agent could become your biggest insider threat CyberScoop · 72d ago What is the most underestimated cybersecurity risk right now? cybersecurity · 72d ago Update: Company is paying for any certification, which should I obtain? Except Sans cybersecurity · 72d ago New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification cybersecurity · 72d ago Anyone else's firewall vendor docs a total nightmare? cybersecurity · 72d ago Your opinions about a learning style cybersecurity · 72d ago UN food agency discloses breach affecting 600,000 Gaza households BleepingComputer · 72d ago Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks cybersecurity · 72d ago New IronWorm malware hits 36 packages in npm supply-chain attack cybersecurity · 72d ago Is Marauder available for ESP32-S3 Mini? hacking: security in practice · 72d ago Anyone else see their firewall logs just explode after a cloud update? cybersecurity · 72d ago Gemini whatsapp hacking: security in practice · 72d ago Are certifications necessary to get a job in cybersecurity? cybersecurity · 72d ago Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass) cybersecurity · 72d ago New IronWorm malware hits 36 packages in npm supply-chain attack BleepingComputer · 72d ago Is retyping and translating textbooks too inefficient for CS/Cybersecurity? cybersecurity · 72d ago Free Microsoft Enterprise Security Assessment: Worth It cybersecurity · 72d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 72d ago How are organizations preparing for AI-generated phishing attacks? cybersecurity · 72d ago Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js Technical Information Security Content & Discussion · 72d ago Inside the race to adapt to an AI-powered security world cybersecurity · 72d ago 127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For cybersecurity · 72d ago Inside the race to adapt to an AI-powered security world CyberScoop · 72d ago Microsoft blames unexpected Windows driver updates on caching issue cybersecurity · 72d ago Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook BleepingComputer · 72d ago Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance) cybersecurity · 72d ago Enter the WasmForge: Compiling Sliver into WebAssembly Technical Information Security Content & Discussion · 72d ago Microsoft blames unexpected Windows driver updates on caching issue BleepingComputer · 72d ago Your CPU model leaks through the browser via WASM timing differences cybersecurity · 72d ago LSASS/Defender/CTFMON analysis For [Blue|Purple] Teams in Cyber Defence · 72d ago Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing Cyber Defense Magazine · 72d ago Software supply chain attacks: check your dependencies For [Blue|Purple] Teams in Cyber Defence · 72d ago Police dismantles fake ID marketplace used by migrant smugglers BleepingComputer · 72d ago void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies Reverse Engineering · 72d ago Chinese Cybercrime Group in Spotlight for Record Campaign Pace cybersecurity · 72d ago NAVTOR NavBox All CISA Advisories · 72d ago Hitachi Energy MACH HiDraw All CISA Advisories · 72d ago Hitachi Energy ITT600 Explorer All CISA Advisories · 72d ago B&R PPT30 Operating System All CISA Advisories · 72d ago Hitachi Energy RTU500 All CISA Advisories · 72d ago Extremely suspicious behaviour by memu emulator Malware Analysis & Reports · 72d ago Security Engineer 2 interview at Amazon coming up - What to expect? cybersecurity · 72d ago A researcher spent $1,500 testing if LLMs could hack a vulnerable app cybersecurity · 72d ago Help with university internship cybersecurity · 72d ago Are MCP servers becoming the next API security nightmare? cybersecurity · 72d ago Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator For [Blue|Purple] Teams in Cyber Defence · 72d ago Cisco warns of critical Unified CM flaw with PoC exploit code BleepingComputer · 72d ago What's the cybersecurity lesson you learned the hard way? cybersecurity · 72d ago ISO 27001 Surveillance audit vs Full recertification cybersecurity · 72d ago How important it is to get paid Cybersecurity certificates ? cybersecurity · 72d ago Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process cybersecurity · 72d ago Soc to Architecture cybersecurity · 72d ago Does "example file vulnerability" exists? cybersecurity · 72d ago VS code forces 2 hour cool down for most integrations. cybersecurity · 72d ago Company laptop isolated after Brave/Tor alert - should I be worried? cybersecurity · 72d ago Does anyone know how to send false positive to SOCradar ? virus total cybersecurity · 72d ago Looking for people to team up for Bug Bounties & CTFs cybersecurity · 73d ago Signal Without Smartphone cybersecurity · 73d ago I found a trojan on my pc and now im scared my private calls got leaked cybersecurity · 73d ago Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests cybersecurity · 73d ago CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog cybersecurity · 73d ago How do you change users behavior through awareness training? cybersecurity · 73d ago AI-built ransomware toolkit automates EDR evasion, AD discovery cybersecurity · 73d ago 29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection) For [Blue|Purple] Teams in Cyber Defence · 73d ago Safe Rust API for wolfSSL/wolfCOSE hacking: security in practice · 73d ago Safe Rust API for wolfSSL/wolfCOSE cybersecurity · 73d ago Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma) cybersecurity · 73d ago AMD GPU Users might be compromised cybersecurity · 73d ago [ Removed by Reddit ] cybersecurity · 73d ago Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information cybersecurity · 73d ago CISA warns of cyberattacks targeting fuel tank monitoring systems cybersecurity · 73d ago [CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF cybersecurity · 73d ago how to get good at cyber security? cybersecurity · 73d ago Anyone use CrunchAtlas? cybersecurity · 73d ago Prompt monitoring laughs cybersecurity · 73d ago Malicious Payload in ai-sdk-ollama npm Package cybersecurity · 73d ago Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24) cybersecurity · 73d ago Resource Exhaustion hacking: security in practice · 73d ago what the HELL is dsztfso? cybersecurity · 73d ago Open Source - 2500 New MITRE Mutations For [Blue|Purple] Teams in Cyber Defence · 73d ago Yubikey Alternative....? cybersecurity · 73d ago Hiring cybersecurity · 73d ago Malware Malware Analysis & Reports · 73d ago CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing cybersecurity · 73d ago Agent-Ready: How to Prepare Your Site for AI-Driven Commerce Blog – Forter · 73d ago Certification Advice cybersecurity · 73d ago Question about Linux kernel TLS ULP disclosed June 2 to oss-security cybersecurity · 73d ago European authorities crack down on illegal streaming networks CyberScoop · 73d ago An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this? cybersecurity · 73d ago Chinese hackers use new Atlas RAT malware in European cyberattacks BleepingComputer · 73d ago How to Rob a Data Center (new article on data center physical security) cybersecurity · 73d ago Hermes has a Home Assistant skill and it's unreal! NetworkChuck · 73d ago US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server cybersecurity · 73d ago Is it worth taking the EC councils masters program?? Are they legit /2026 cybersecurity · 73d ago Mid-level AppSec engineers: what do you actually study to prep for interviews? cybersecurity · 73d ago Automated Fault Injection Attack Framework Reverse Engineering · 73d ago The U.S. sanctions Nobitex crypto exchange used by ransomware BleepingComputer · 73d ago CISA warns of cyberattacks targeting fuel tank monitoring systems BleepingComputer · 73d ago Season VI of the US Games launches TOMORROW! Technical Information Security Content & Discussion · 73d ago Company is paying for any certification, which should I obtain? cybersecurity · 73d ago DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels CyberScoop · 73d ago Trusting Microsoft with your offensive security repos cybersecurity · 73d ago Automated Fault Injection Attack Framework cybersecurity · 73d ago Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT For [Blue|Purple] Teams in Cyber Defence · 73d ago Bring Your Own RWX Region DLL (BYORWXDLL) For [Blue|Purple] Teams in Cyber Defence · 73d ago Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem For [Blue|Purple] Teams in Cyber Defence · 73d ago APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component For [Blue|Purple] Teams in Cyber Defence · 73d ago NuGet Code Execution As A Service For [Blue|Purple] Teams in Cyber Defence · 73d ago aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies For [Blue|Purple] Teams in Cyber Defence · 73d ago Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor For [Blue|Purple] Teams in Cyber Defence · 73d ago TA4922: The Suspected Chinese Crime Group is Going Global For [Blue|Purple] Teams in Cyber Defence · 73d ago [ Removed by Reddit ] For [Blue|Purple] Teams in Cyber Defence · 73d ago New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute BleepingComputer · 73d ago Physical Biometric device as a security measure..?? cybersecurity · 73d ago Espionage Campaign Targeted Stock Exchange Executive for Five Months For [Blue|Purple] Teams in Cyber Defence · 73d ago Cybersegurança cybersecurity · 73d ago Started Learning Cybersecurity cybersecurity · 73d ago InfraGard Application - Seeking Help | Student cybersecurity · 73d ago x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994) Reverse Engineering · 73d ago Orientación en Ciberseguridad cybersecurity · 73d ago OnionAccelerator: multi-circuit / chunked download acceleration over Tor For [Blue|Purple] Teams in Cyber Defence · 73d ago Anthropic's coordinated vulnerability disclosure dashboard cybersecurity · 73d ago Hands Free: What LLM Driven Vulnerability Research Looks Like cybersecurity · 73d ago HazyBeacon and AWS Lambda Function URL Abuse For [Blue|Purple] Teams in Cyber Defence · 73d ago Real time Cybersecurity failures regarding Quantum computing/cryptography cybersecurity · 73d ago The Server Seizure That Affects Also Iran's Cyber Operations For [Blue|Purple] Teams in Cyber Defence · 73d ago How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad For [Blue|Purple] Teams in Cyber Defence · 73d ago 🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop Malware Analysis & Reports · 73d ago 🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It. cybersecurity · 73d ago 🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network For [Blue|Purple] Teams in Cyber Defence · 73d ago Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2 Reverse Engineering · 73d ago A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out. cybersecurity · 73d ago CISA warns of active attacks exploiting Android, Linux bugs cybersecurity · 73d ago Found some open ports on a govt site, should i report or stay quiet? cybersecurity · 73d ago What is a good way to keep track of passwords for programs that don't support password managers? cybersecurity · 73d ago CISA warns of active attacks exploiting Android, Linux bugs BleepingComputer · 73d ago ChatGPT Malvertising Campaign Malware Analysis & Reports · 73d ago Cybersecurity statistics of the week (May 25th - May 31st) cybersecurity · 73d ago ASN Emissions Index. Networks ranked by how much noise they create on the internet. cybersecurity · 73d ago Have you sold cve before? cybersecurity · 73d ago EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires Technical Information Security Content & Discussion · 73d ago i want to become a pentester, but i don't know how to cybersecurity · 73d ago Recommendation Malware Analysis & Reports · 73d ago I’m not sure I’m in the right subreddit…. hacking: security in practice · 73d ago The OT Security Problem Nobody Wants to Own cybersecurity · 73d ago Don't Take Wednesday Off When You Manage Vulnerabilities cybersecurity · 73d ago I finally finished a production version after 4 yrds cybersecurity · 73d ago Support role pivot to cloud security cybersecurity · 73d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 73d ago What 345 Days of Untested Exposure Looks Like at a Bank BleepingComputer · 73d ago Took me a decade to turn quantum computing into what hackers can easily learn hacking: security in practice · 73d ago Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6! Malware Analysis & Reports · 73d ago How do you manage your passwords? cybersecurity · 73d ago The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector Cyber Defense Magazine · 73d ago Mad rush to produce AI driven slop cybersecurity · 73d ago O Tails é seguro para acessar links suspeitos? cybersecurity · 73d ago Took me a decade of work to turn Quantum Computing into a fun videogame hacking: security in practice · 73d ago Interesting- What LLM vuln research looks like Technical Information Security Content & Discussion · 73d ago Cyber Essentials plus + "legacy" network segments cybersecurity · 73d ago Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors For [Blue|Purple] Teams in Cyber Defence · 73d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 73d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 73d ago Acer working to patch max severity zero-days in Wave 7 routers BleepingComputer · 73d ago Hacking your PC using your speaker without ever touching it Reverse Engineering · 73d ago Hacking your PC using your speaker without ever touching it Technical Information Security Content & Discussion · 73d ago Insight for OPSWAT deep CDR cybersecurity · 73d ago Android vs iOS cybersecurity · 73d ago ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account cybersecurity · 73d ago Police dismantles 9 crime groups in illegal streaming crackdown BleepingComputer · 73d ago Security Audits at an MSP cybersecurity · 73d ago [ Removed by Reddit ] cybersecurity · 73d ago Google adds Android protection against AI deepfake scam calls BleepingComputer · 73d ago Passkey registration breaks after moving off localhost.. cybersecurity · 73d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 73d ago Does your team hire fresh AI engineer who doesn't know anything about Security operations? cybersecurity · 73d ago UARs for Equation (banking system) cybersecurity · 73d ago Simple way how to bypass hotel WiFi? hacking: security in practice · 73d ago VS Code zero-day lets hackers steal GitHub tokens in one click hacking: security in practice · 73d ago Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing Technical Information Security Content & Discussion · 74d ago IoT pentesting cert cybersecurity · 74d ago Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations cybersecurity · 74d ago Experience with Tac Security cybersecurity · 74d ago Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content cybersecurity · 74d ago VS Code zero-day lets hackers steal GitHub tokens in one click BleepingComputer · 74d ago Golang code review notes II - elttam Technical Information Security Content & Discussion · 74d ago Using AI to Secure Its Generated Code Is a Ponzi Scheme Technical Information Security Content & Discussion · 74d ago Found Security Vulnerabilities in my university website cybersecurity · 74d ago burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API) hacking: security in practice · 74d ago Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence cybersecurity · 74d ago AI - Threat to the CyberSec Industry? cybersecurity · 74d ago Built a honeypot platform to catch lateral movement. How are you guys detecting this? cybersecurity · 74d ago How should small SaaS teams safely answer customer security questionnaires? cybersecurity · 74d ago Dependency Cooldowns - Dependency Cooldowns For [Blue|Purple] Teams in Cyber Defence · 74d ago Can AI Do Intelligence Analysis? Apparently Not. cybersecurity · 74d ago PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model cybersecurity · 74d ago Regarding Certified Ethical Hacker (CEH Practical) exam cybersecurity · 74d ago Asking for advices on pursuing first CERTIFICATE cybersecurity · 74d ago I opened my own company and I can't find clients! cybersecurity · 74d ago ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter cybersecurity · 74d ago C2 Frameworks - Threat Hunting in Action with YARA Rules For [Blue|Purple] Teams in Cyber Defence · 74d ago How big of a security risk or exploit would this be? hacking: security in practice · 74d ago Microsoft's Coreutils project brings Linux commands to Windows BleepingComputer · 74d ago Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU? cybersecurity · 74d ago Anyone knows Quad9 dns ? cybersecurity · 74d ago OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models BleepingComputer · 74d ago KTO , Be the only one online -- on any WiFi network hacking: security in practice · 74d ago Critical Kirki flaw exploited to hijack WordPress admin accounts BleepingComputer · 74d ago Over 116,000 Mincraft systems infected in WeedHack malware campaign BleepingComputer · 74d ago Over 116,000 Minecraft systems infected in WeedHack malware campaign BleepingComputer · 74d ago Ransomware tabletop For [Blue|Purple] Teams in Cyber Defence · 74d ago I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ? cybersecurity · 74d ago Greynoise swarm cybersecurity · 74d ago SecOT+ certification for free cybersecurity · 74d ago How is the state of the job market for mid-level security engineers? cybersecurity · 74d ago Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things cybersecurity · 74d ago WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total cybersecurity · 74d ago Laid off from TPRM job - need help on the future of my career cybersecurity · 74d ago News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces The Last Watchdog · 74d ago Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 For [Blue|Purple] Teams in Cyber Defence · 74d ago Tracking North Korea Nation-State APT Infrastructure: Kimsuky For [Blue|Purple] Teams in Cyber Defence · 74d ago 새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn For [Blue|Purple] Teams in Cyber Defence · 74d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 74d ago AI-built ransomware toolkit automates EDR evasion, AD discovery BleepingComputer · 74d ago apparently bypassing school systems by playing games hacking: security in practice · 74d ago Anyone compared RoboShadow vs ConnectSecure for vulnerability management? cybersecurity · 74d ago Codex Discovered a Hidden HTTP/2 Bomb For [Blue|Purple] Teams in Cyber Defence · 74d ago Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes Technical Information Security Content & Discussion · 74d ago Top 5 Active Directory Pentesting Tools The Cyber Mentors · 74d ago Any one send vulnerability to MITRE? cybersecurity · 74d ago Need advice for a 30 min Security Apprenticeship interview cybersecurity · 74d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 74d ago Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix For [Blue|Purple] Teams in Cyber Defence · 74d ago UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS cybersecurity · 74d ago Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match cybersecurity · 74d ago We Added a Detection Rule. We Were Not Expecting This. Technical Information Security Content & Discussion · 74d ago Introducing Microsoft Scout: Your always-on personal agent Microsoft 365 Blog · 74d ago Virustotal API as private data source cybersecurity · 74d ago DOD wants to integrate cyber in all operations, and integrate security into AI CyberScoop · 74d ago Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source! Reverse Engineering · 74d ago Microsoft Exchange Online outage causes email delays, failures BleepingComputer · 74d ago Announcing the new Work IQ APIs Microsoft 365 Blog · 74d ago Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases Security | Microsoft Azure Blog | Microsoft Azure · 74d ago Trump administration releases scaled-back AI executive order CyberScoop · 74d ago Account Number Security Flaw cybersecurity · 74d ago Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning? cybersecurity · 74d ago A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth cybersecurity · 74d ago [ Removed by Reddit ] cybersecurity · 74d ago [ Removed by Reddit ] cybersecurity · 74d ago “Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?” For [Blue|Purple] Teams in Cyber Defence · 74d ago Instagram users locked out after Meta AI abused to steal accounts BleepingComputer · 74d ago Phishing simulation platform cybersecurity · 74d ago 1-Click GitHub Token Stealing via a VSCode Bug Technical Information Security Content & Discussion · 74d ago Just task about OSI model cybersecurity · 74d ago FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential The Last Watchdog · 74d ago Need help improving DNS Spy from a security tool angle cybersecurity · 74d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild cybersecurity · 74d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild Technical Information Security Content & Discussion · 74d ago Oracle's first monthly patch update just dropped 77 CVEs. cybersecurity · 74d ago Cleaning up after a legacy service account breach. How are you handling automated secrets discovery? cybersecurity · 74d ago Airbus digital apprenticeship cybersecurity · 74d ago Built a decompiler for exotic legacy programming language opentext Gupta Team Developer Reverse Engineering · 74d ago Always-On Red Teams hacking: security in practice · 74d ago Why the browser is now the front line for AI security BleepingComputer · 74d ago Anthropic expanding access to Project Glasswing CyberScoop · 74d ago Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities cybersecurity · 74d ago [An RX Global Event] Infosecurity Europe darkreading · 74d ago Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit Cyber Defense Magazine · 74d ago This is a scam and probably a malware/trojan. Path Of Exile 2 builder ... Malware Analysis & Reports · 74d ago CISA flags two-year-old Oracle flaw as actively exploited in attacks BleepingComputer · 74d ago Google fixes one actively exploited Android zero-day, 124 flaws cybersecurity · 74d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 74d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems All CISA Advisories · 74d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 74d ago Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force cybersecurity · 74d ago Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis? cybersecurity · 74d ago Security Architects who who actively use modelling - What's your approach? cybersecurity · 74d ago PAN-OS authentication bypass bug added to list of exploited vulnerabilities cybersecurity · 74d ago Google fixes one actively exploited Android zero-day, 124 flaws BleepingComputer · 74d ago I have extreme anxiety about being hacked cybersecurity · 74d ago Fresher cybersecurity · 74d ago Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif For [Blue|Purple] Teams in Cyber Defence · 74d ago Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand For [Blue|Purple] Teams in Cyber Defence · 74d ago Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach cybersecurity · 74d ago Career advice needed! cybersecurity · 74d ago LLMShare: using shared chatbot pages to distribute malware Malware Analysis & Reports · 75d ago GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure cybersecurity · 75d ago Google sr. security engineer interview cybersecurity · 75d ago Is offensive AI actually changing cybersecurity, or are we overestimating the impact? cybersecurity · 75d ago Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave cybersecurity · 75d ago is emerald chat safe? cybersecurity · 75d ago Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm For [Blue|Purple] Teams in Cyber Defence · 75d ago Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ? cybersecurity · 75d ago ClickJack in the wild cybersecurity · 75d ago NuGet Code Execution As A Service Technical Information Security Content & Discussion · 75d ago Thoughts on A.I assisted Malware Analysis? cybersecurity · 75d ago 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access cybersecurity · 75d ago What articles do you use for cybersecurity news? (2026) cybersecurity · 75d ago Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider? cybersecurity · 75d ago Roadmap and Training Recommodation cybersecurity · 75d ago Attackers are exploiting Palo Alto Networks defect that initially flew under the radar CyberScoop · 75d ago I managed to pull the full system prompt for Meta's Support AI hacking: security in practice · 75d ago Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks BleepingComputer · 75d ago Les anti-triche de niveau noyau et leur risque de sécurité cybersecurity · 75d ago Harassing text messages hacking: security in practice · 75d ago Asked to Send Sensitive Documents via MMS cybersecurity · 75d ago Red Hat npm packages compromised to steal developer credentials BleepingComputer · 75d ago SC-200 compared to CC (isc2) cybersecurity · 75d ago Spain arrests doxer leaking sensitive data of govt employees BleepingComputer · 75d ago running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it! Reverse Engineering · 75d ago Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB) Technical Information Security Content & Discussion · 75d ago Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now cybersecurity · 75d ago Looking to move off KB4, what are people actually using these days? cybersecurity · 75d ago Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight CyberScoop · 75d ago Got my Security+. What's next? cybersecurity · 75d ago Vulnerability Summary for the Week of May 25, 2026 cybersecurity · 75d ago RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation For [Blue|Purple] Teams in Cyber Defence · 75d ago Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages For [Blue|Purple] Teams in Cyber Defence · 75d ago Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches For [Blue|Purple] Teams in Cyber Defence · 75d ago REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY! hacking: security in practice · 75d ago Malware cybersecurity · 75d ago Dashlane password manager users locked out by brute force attacks BleepingComputer · 75d ago Alternative Search Engine to Utilize in 2026? cybersecurity · 75d ago Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked cybersecurity · 75d ago Miasma: Supply Chain Attack Targeting RedHat npm Packages For [Blue|Purple] Teams in Cyber Defence · 75d ago USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order CyberScoop · 75d ago Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild cybersecurity · 75d ago Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers cybersecurity · 75d ago Hacking Palo Alto Networks' GlobalProtect VPN with AI hacking: security in practice · 75d ago AI compliance cybersecurity · 75d ago Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm cybersecurity · 75d ago WordPress malware campaign hides payloads in Steam profiles BleepingComputer · 75d ago Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains? cybersecurity · 75d ago MacBook or Windows Laptop for Cybersecurity cybersecurity · 75d ago What's the most creative MFA bypass you've seen? cybersecurity · 75d ago @redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers For [Blue|Purple] Teams in Cyber Defence · 75d ago Research Notes from Building a Windows Event Log Hunting Workflow cybersecurity · 75d ago Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am. hacking: security in practice · 75d ago How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ?? cybersecurity · 75d ago Free AI tools for TPRM? cybersecurity · 75d ago incomplete phone number from togo, need help reporting to police cybersecurity · 75d ago NPM packages from RedHat Compromised cybersecurity · 75d ago Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts cybersecurity · 75d ago Microsoft investigates Office Apps, Teams file access issues BleepingComputer · 75d ago SOC Analyst working towards Threat Intelligence cybersecurity · 75d ago Is XSS possible through PDFs? cybersecurity · 75d ago Race Against Time: Why Faster Vulnerability Alerts Matter BleepingComputer · 75d ago Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider Technical Information Security Content & Discussion · 75d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 75d ago The Next AI Governance Failure Won’t Be the Model cybersecurity · 75d ago Poisoning Claude Code: One GitHub Issue to Break the Supply Chain Technical Information Security Content & Discussion · 75d ago Microsoft MFA Is Down Again cybersecurity · 75d ago Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927) cybersecurity · 75d ago Stealing Passwords via HTML Injection Under a Strict CSP Technical Information Security Content & Discussion · 75d ago Computer logic or Science cybersecurity · 75d ago Critical Windows Netlogon RCE flaw now exploited in attacks BleepingComputer · 75d ago Webinar tomorrow: From alert to resolution in network incident response BleepingComputer · 75d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 75d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 75d ago I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for? cybersecurity · 75d ago What C2s Are You Using cybersecurity · 75d ago Microsoft confirms outage affecting MFA, My Sign-Ins platform BleepingComputer · 75d ago Microsoft fixes outage affecting MFA setup, MySignIn service BleepingComputer · 75d ago Microsoft fixes KB5089549 Windows security update install issues BleepingComputer · 75d ago Best AI LLM for Hacking related stuff hacking: security in practice · 75d ago PNPT Exam cybersecurity · 75d ago Election threats are focused on campaign systems, not voting machines CyberScoop · 75d ago What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification? cybersecurity · 75d ago Feels like most people ignore the wireless layer until it bites them hacking: security in practice · 75d ago Any appsec engineer working in fortune 500? cybersecurity · 75d ago I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next cybersecurity · 75d ago Anyone transition from AWS Data Center Operations to InfoSec? cybersecurity · 76d ago I think my account got hacked but it's weird cybersecurity · 76d ago Subnet discovery through multi-protocol TTL tracing Technical Information Security Content & Discussion · 76d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 76d ago current market for detecting deepfakes? cybersecurity · 76d ago Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched For [Blue|Purple] Teams in Cyber Defence · 76d ago Worried about friend being doxxed on doxbin cybersecurity · 76d ago Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks For [Blue|Purple] Teams in Cyber Defence · 76d ago Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries For [Blue|Purple] Teams in Cyber Defence · 76d ago how to shift from a service based company to a product based one in cybersecurity ? cybersecurity · 76d ago Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA cybersecurity · 76d ago Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking? hacking: security in practice · 76d ago Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign For [Blue|Purple] Teams in Cyber Defence · 76d ago Claude AI user data directory exfiltration via malicious npm package cybersecurity · 76d ago Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from? Reverse Engineering · 76d ago Bitdefender blocking amd stuff? False positive or? cybersecurity · 76d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 76d ago Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet Trend Micro Research, News, Perspectives · 76d ago did they have my password?? what triggers this specific email??? instagram HELP. cybersecurity · 76d ago How to Unpack FlawedAmmyy - Malware Unpacking Tutorial Malware Analysis & Reports · 76d ago ATTENTION: Dashlane may have been breached. (Password manager). cybersecurity · 76d ago Can anyone figure out how to retrieve the recovery key in signal app? hacking: security in practice · 76d ago Norton blocked a “malicious script”? cybersecurity · 76d ago Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts cybersecurity · 76d ago Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive. cybersecurity · 76d ago I wrote about the 5 biggest threats in 2026, curious what this community thinks. cybersecurity · 76d ago MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce? cybersecurity · 76d ago Atomdrift - open-source malware detection for the software supply chain For [Blue|Purple] Teams in Cyber Defence · 76d ago Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions? cybersecurity · 76d ago NetworkChuck cybersecurity · 76d ago LLM for creating phishing tool cybersecurity · 76d ago Why are we still treating IAM like a compliance checkbox? cybersecurity · 76d ago Polyfill pop up? cybersecurity · 76d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Technical Information Security Content & Discussion · 76d ago Building A Malware Lab From Scratch! Malware Analysis & Reports · 76d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Reverse Engineering · 76d ago WP Maps Pro bug exploited to create admin accounts on WordPress sites BleepingComputer · 76d ago SecAI+ difficulty question cybersecurity · 76d ago $730k+ raised on Proxmark5 with 2150 backers hacking: security in practice · 76d ago Could you guys give an honest feedback to a completely automated ssrf attack tool? cybersecurity · 76d ago tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me cybersecurity · 76d ago Microsoft Joined the DMARC Club cybersecurity · 76d ago Help. cybersecurity · 76d ago Vibe Coding Security cybersecurity · 76d ago I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works) hacking: security in practice · 76d ago Looking for a Company to Partner With cybersecurity · 76d ago Best reporting tools? cybersecurity · 76d ago What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months) cybersecurity · 76d ago Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens For [Blue|Purple] Teams in Cyber Defence · 77d ago How Can Polyfill.io Still Act Maliciously? cybersecurity · 77d ago 179 npm Packages Target Cloud and Finance via oob.moika.tech For [Blue|Purple] Teams in Cyber Defence · 77d ago KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4 For [Blue|Purple] Teams in Cyber Defence · 77d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 77d ago Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services For [Blue|Purple] Teams in Cyber Defence · 77d ago TinyLoad v7 - what i added :D (in memory protection using VEH and alot more) Reverse Engineering · 77d ago EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA For [Blue|Purple] Teams in Cyber Defence · 77d ago Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace For [Blue|Purple] Teams in Cyber Defence · 77d ago Signal macOS Desktop App Doesn't Actually Delete Messages When it Should For [Blue|Purple] Teams in Cyber Defence · 77d ago Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan For [Blue|Purple] Teams in Cyber Defence · 77d ago WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD For [Blue|Purple] Teams in Cyber Defence · 77d ago Any idea who's behind this hack? How to resolve it? hacking: security in practice · 77d ago Typosquatted npm packages used to steal cloud and CI/CD secrets For [Blue|Purple] Teams in Cyber Defence · 77d ago Need THM voucher code for cheap? Any known seller? cybersecurity · 77d ago Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2 For [Blue|Purple] Teams in Cyber Defence · 77d ago Malicious npm packages abuse dependency confusion to profile developer environments For [Blue|Purple] Teams in Cyber Defence · 77d ago Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) For [Blue|Purple] Teams in Cyber Defence · 77d ago Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack For [Blue|Purple] Teams in Cyber Defence · 77d ago CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied." For [Blue|Purple] Teams in Cyber Defence · 77d ago Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign For [Blue|Purple] Teams in Cyber Defence · 77d ago SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks. For [Blue|Purple] Teams in Cyber Defence · 77d ago EDR Incident Response Playbook: Containing Local Account Incidents For [Blue|Purple] Teams in Cyber Defence · 77d ago Adversarial Oracles: LLM-Guided EDR Signature Reduction For [Blue|Purple] Teams in Cyber Defence · 77d ago One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF For [Blue|Purple] Teams in Cyber Defence · 77d ago proxy: A lightweight caching proxy for package registries. For [Blue|Purple] Teams in Cyber Defence · 77d ago How OLTs may have exposed entire ISP networks For [Blue|Purple] Teams in Cyber Defence · 77d ago Ghost passwords? cybersecurity · 77d ago Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it hacking: security in practice · 77d ago A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years For [Blue|Purple] Teams in Cyber Defence · 77d ago HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics For [Blue|Purple] Teams in Cyber Defence · 77d ago Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots For [Blue|Purple] Teams in Cyber Defence · 77d ago Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures For [Blue|Purple] Teams in Cyber Defence · 77d ago Lessons from Penetration Tests on Large-Scale Agent Systems For [Blue|Purple] Teams in Cyber Defence · 77d ago pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter. For [Blue|Purple] Teams in Cyber Defence · 77d ago [ Removed by Reddit ] Reverse Engineering · 77d ago Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not. cybersecurity · 77d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 77d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions Technical Information Security Content & Discussion · 77d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions cybersecurity · 77d ago Anyone else having Chatgpt Strikes / Violations while learning cybersecurity? cybersecurity · 77d ago Blue Team tips? hacking: security in practice · 77d ago Working at Cisco, worth it? cybersecurity · 77d ago Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice cybersecurity · 77d ago usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer) Reverse Engineering · 77d ago CIFSwitch: a non-universal Linux local root vulnerability For [Blue|Purple] Teams in Cyber Defence · 77d ago Are you pen testing AI Agents? cybersecurity · 77d ago Question of android malware cybersecurity · 77d ago External attack surface: how are you correlating DNS, SSL, and IP reputation today? cybersecurity · 77d ago edit certified pdf hacking: security in practice · 77d ago how do i properly setup 2fa and bitwarden? cybersecurity · 77d ago Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC) cybersecurity · 77d ago i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested? cybersecurity · 77d ago Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever? cybersecurity · 77d ago I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux) Reverse Engineering · 77d ago Can Steam Cloud Files Transfer Malware cybersecurity · 77d ago I bought an old phone from 2018 and wanna destroy it with viruses for fun Malware Analysis & Reports · 77d ago Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks BleepingComputer · 77d ago HackTheBox - Interpreter IppSec · 77d ago Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension For [Blue|Purple] Teams in Cyber Defence · 77d ago Questions for the cloud security engineers cybersecurity · 77d ago DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database. For [Blue|Purple] Teams in Cyber Defence · 77d ago Visual Studio Extensions Revisited For [Blue|Purple] Teams in Cyber Defence · 77d ago Thoughts on this as a starter and doing bug bounty on the side cybersecurity · 77d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 77d ago How are new SC-200 candidates practicing labs without an E5 Developer tenant? cybersecurity · 77d ago New CIFSwitch Linux flaw gives root on multiple distributions BleepingComputer · 77d ago Everyday hacking in our lives - transportation, work, finances, goods etc hacking: security in practice · 77d ago Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters Technical Information Security Content & Discussion · 77d ago Getting OTP spammed from every app and website I've ever used. Should I be worried? cybersecurity · 77d ago BYOVD and Looting LSASS in the Modern EDR Era For [Blue|Purple] Teams in Cyber Defence · 77d ago A browser tool for checking contractor insurance certificates cybersecurity · 77d ago Am I getting screwed? cybersecurity · 77d ago SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers cybersecurity · 77d ago PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29} cybersecurity · 77d ago CTO at NCSC Summary: week ending May 31st cybersecurity · 77d ago CTO at NCSC Summary: week ending May 31st For [Blue|Purple] Teams in Cyber Defence · 77d ago BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship cybersecurity · 77d ago OffensiveCon26 videos For [Blue|Purple] Teams in Cyber Defence · 78d ago Need suggestion cybersecurity · 78d ago Malware escaped browser without downloading files, then escaped a virtual machine Malware Analysis & Reports · 78d ago [INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety) cybersecurity · 78d ago Was Dave Bittner interviewing an AI? cybersecurity · 78d ago CTF for complete beginner cybersecurity · 78d ago Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques? cybersecurity · 78d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 78d ago AI-Era Cyber Risk Standards cybersecurity · 78d ago BEC Victim - Attacker replied inside a real email thread using a lookalike domain cybersecurity · 78d ago School Survey, (non-paid nothing its free its for my grades) For [Blue|Purple] Teams in Cyber Defence · 78d ago Question for those who transitioned from remote to work from anywhere cybersecurity · 78d ago Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors cybersecurity · 78d ago Do you enjoy what you do or do you wish you could go back in time and change it? cybersecurity · 78d ago Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber? cybersecurity · 78d ago A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.) Technical Information Security Content & Discussion · 78d ago For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year? cybersecurity · 78d ago Name That Toon: Mark of (Cybersecurity) Progress darkreading · 78d ago Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ? cybersecurity · 78d ago Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years? cybersecurity · 78d ago Botnet of more than 17 million devices dismantled cybersecurity · 78d ago Exposed credentials on logs cybersecurity · 78d ago Do you think this is legit or has the website been compromised? hacking: security in practice · 78d ago Introducing Keyhog: The First GPU Accelerated secret scanner Technical Information Security Content & Discussion · 78d ago What do you think is the biggest cybersecurity risk for small businesses in 2026? cybersecurity · 78d ago Wanted to shift to cloud security, but have some questions cybersecurity · 78d ago OffensiveCon26 YouTube Playlist released Technical Information Security Content & Discussion · 78d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments For [Blue|Purple] Teams in Cyber Defence · 78d ago LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms For [Blue|Purple] Teams in Cyber Defence · 78d ago ChatGPT share links abused to host fake outage pages to deliver malware BleepingComputer · 78d ago Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 CyberScoop · 78d ago California AG sues 23andMe over 2023 breach exposing health data BleepingComputer · 78d ago Zero Trust is Overrated? Navigating the Complexity cybersecurity · 78d ago Test API post with flair cybersecurity · 78d ago Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications cybersecurity · 78d ago How Do You Handle the Massive Amount of Information in the CPTS Path? cybersecurity · 78d ago Wanna learn cybersecurity & ethical hacking hacking: security in practice · 78d ago LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting For [Blue|Purple] Teams in Cyber Defence · 78d ago Help an upcoming cybersecurity engineer! cybersecurity · 78d ago Repeated Microsoft MFA attempts even after password change cybersecurity · 78d ago I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but Malware Analysis & Reports · 78d ago Do you guys take paper notes or digital ones during studying ? hacking: security in practice · 78d ago What Is Device Intelligence and How Does It Stop Fraud? cybersecurity · 78d ago [FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE) cybersecurity · 78d ago Federal audit reveals NIST’s NVD is plagued by poor planning and duplication CyberScoop · 78d ago Ghidra 12.1.1 has been released! Reverse Engineering · 78d ago IBM commits $5 billion to secure open-source software cybersecurity · 78d ago Structuring an AI-Assisted Pentesting Homelab for a Final Year Project cybersecurity · 78d ago Are teams actually monitoring LLM traffic in production environments? cybersecurity · 78d ago How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA) cybersecurity · 78d ago Raspberry pi cybersecurity · 78d ago Asia's Cyber Insurance Market Shows Signs of Life darkreading · 78d ago What is the biggest obstacle to using AI safely in a company? cybersecurity · 78d ago From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market BleepingComputer · 78d ago Dutch govt disrupts malware botnet with 17 million infected devices BleepingComputer · 78d ago Advice going forward cybersecurity · 78d ago MCP Firewall help cybersecurity · 78d ago I wanted to shift to security but people told me the market is extremely bad, is that true? cybersecurity · 78d ago Best Personality Type/Traits for Working in Cyber Security cybersecurity · 78d ago Identifying attack patterns through kernel frame callstacks For [Blue|Purple] Teams in Cyber Defence · 78d ago A fake freelance job interview almost installed malware on my PC cybersecurity · 78d ago Is there a viable career path here or am I just being delusional? cybersecurity · 78d ago With Complex Cloud Integrations, Small Errors Lead to Major Compromises darkreading · 78d ago What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks cybersecurity · 78d ago Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness For [Blue|Purple] Teams in Cyber Defence · 78d ago Google Chrome adds session cookie theft protection for all users BleepingComputer · 78d ago 'The Com' Cyberattacks Support Violence & Sexploitation darkreading · 78d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 78d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 78d ago How do enterprises actually prevent developers from exfiltrating source code? cybersecurity · 78d ago Man sent to prison for selling data of 7 millions elderly Americans BleepingComputer · 78d ago I have a datastealer malware cybersecurity · 78d ago Dúvida de carreira. cybersecurity · 78d ago US charges Google security engineer with Polymarket insider trading BleepingComputer · 78d ago Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace cybersecurity · 78d ago Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated cybersecurity · 78d ago is SIEM really needed here ? cybersecurity · 78d ago Decompiled an app, found a bunch of secrets, what now? cybersecurity · 78d ago What safety boundary would you expect from a local AI incident investigation tool? For [Blue|Purple] Teams in Cyber Defence · 78d ago Can someone give me a correct method for learning reverse engineering? cybersecurity · 78d ago 1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog Technical Information Security Content & Discussion · 78d ago Authenticated RCE via Argument Injection in Gogs (NOT FIXED) For [Blue|Purple] Teams in Cyber Defence · 78d ago Charter Communications data breach affects 4.9 million accounts BleepingComputer · 78d ago Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months cybersecurity · 78d ago GRC Advise cybersecurity · 78d ago [ Removed by Reddit ] cybersecurity · 79d ago Did something happen to haveibeenpwned? Any alternatives? cybersecurity · 79d ago I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found. Technical Information Security Content & Discussion · 79d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 79d ago How do people actually modify mobile games to increase their power? hacking: security in practice · 79d ago Why I Built My Own LLM Benchmark for THOR Finding Triage For [Blue|Purple] Teams in Cyber Defence · 79d ago RAT SUSPECTED cybersecurity · 79d ago Casdoor contains multiple authentication bypass and access management vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 79d ago The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents For [Blue|Purple] Teams in Cyber Defence · 79d ago GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations For [Blue|Purple] Teams in Cyber Defence · 79d ago Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies For [Blue|Purple] Teams in Cyber Defence · 79d ago Malware seller hunted across three continents For [Blue|Purple] Teams in Cyber Defence · 79d ago Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims For [Blue|Purple] Teams in Cyber Defence · 79d ago Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers For [Blue|Purple] Teams in Cyber Defence · 79d ago Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network For [Blue|Purple] Teams in Cyber Defence · 79d ago How do people afford certificate s? cybersecurity · 79d ago I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed? cybersecurity · 79d ago Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint) Reverse Engineering · 79d ago Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. cybersecurity · 79d ago Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 79d ago Phone Forwarding cybersecurity · 79d ago Opinions on running Full Microsoft E5 Security Stack cybersecurity · 79d ago Claiming "XDR" cybersecurity · 79d ago Typosquatted npm packages used to steal cloud and CI/CD secrets cybersecurity · 79d ago Why Loyalty Programs Are Quietly Becoming a Security Blind Spot hacking: security in practice · 79d ago Fooling around with encrypted reasoning blobs Technical Information Security Content & Discussion · 79d ago CALIF: An AI audit of FreeBSD Technical Information Security Content & Discussion · 79d ago Microsoft security cybersecurity · 79d ago Need help regarding building a home lab cybersecurity · 79d ago Should I turn on passwordless accounts for all my Microsoft accounts? cybersecurity · 79d ago Transitioning from AWS Data Center Operations to Security Engineering cybersecurity · 79d ago CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries Technical Information Security Content & Discussion · 79d ago Probably the wrong place. cybersecurity · 79d ago Anthropic confirms Claude Mythos-class models will roll out to the public BleepingComputer · 79d ago What after IT helpdesk? cybersecurity · 79d ago As Global Powers Explore Humanoid Robots, Cyber-Risk Looms darkreading · 79d ago News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit The Last Watchdog · 79d ago Ajuda pessoal hacking: security in practice · 79d ago VMP 3.5+ Internal Architecture & Heap Dispatch Analysis Reverse Engineering · 79d ago GreyVibe hackers use ChatGPT, Gemini to power cyberattacks BleepingComputer · 79d ago How are you security-testing API changes before production without slowing CI/CD? cybersecurity · 79d ago Are we trusting update repos or are you all extra paranoid now as well? cybersecurity · 79d ago Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops cybersecurity · 79d ago BTMOB Android malware service generates custom phishing payloads BleepingComputer · 79d ago Prevent supply chain attacks cybersecurity · 79d ago The C-suite job that's burning people out faster than any other For [Blue|Purple] Teams in Cyber Defence · 79d ago New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation For [Blue|Purple] Teams in Cyber Defence · 79d ago Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems cybersecurity · 79d ago SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer For [Blue|Purple] Teams in Cyber Defence · 79d ago FBI warns of fake FIFA websites running World Cup fraud schemes cybersecurity · 79d ago Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances For [Blue|Purple] Teams in Cyber Defence · 79d ago Hackers are trying to steal Signal users' backups in new wave of phishing attacks cybersecurity · 79d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN Technical Information Security Content & Discussion · 79d ago Samy Kamkar on building viruses, his arrest and privacy in the LLM era hacking: security in practice · 79d ago 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface For [Blue|Purple] Teams in Cyber Defence · 79d ago FBI warns of fake FIFA websites running World Cup fraud schemes BleepingComputer · 79d ago Visual Studio Extensions Revisited Technical Information Security Content & Discussion · 79d ago Dutch Raid Fails to Dent Russian Bulletproof Host darkreading · 79d ago APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026 For [Blue|Purple] Teams in Cyber Defence · 79d ago Incident Response Testing Preparation cybersecurity · 79d ago Introducing Microsoft 365 Business with Copilot: The new standard for small business Microsoft 365 Blog · 79d ago Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference cybersecurity · 79d ago House panel poised to hold hearing centered on AI impact on cyber CyberScoop · 79d ago [Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥 cybersecurity · 79d ago Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure For [Blue|Purple] Teams in Cyber Defence · 79d ago Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake For [Blue|Purple] Teams in Cyber Defence · 79d ago 3rd Party NFC cards.. secure? cybersecurity · 79d ago Vulnerability Management Tickets & SLA cybersecurity · 79d ago Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket CyberScoop · 79d ago Defending at Machine-Speed: Building AI Threat Readiness cybersecurity · 79d ago AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved cybersecurity · 79d ago HEAD request body processing leading cybersecurity · 79d ago Hackers exploit FortiClient EMS flaw to push infostealer malware BleepingComputer · 79d ago Malicious npm Package Stole Files From Claude AI User Directory via GitHub cybersecurity · 79d ago Does anyone have an app like substack to keep being updated and engaging within the cyber domain? cybersecurity · 79d ago Zero Trust Implementation Guidelines For [Blue|Purple] Teams in Cyber Defence · 79d ago [ Removed by Reddit ] hacking: security in practice · 79d ago What’s an attack vector people massively underestimate in 2026? cybersecurity · 79d ago We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7 cybersecurity · 79d ago Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP) Technical Information Security Content & Discussion · 79d ago Is this considered a bug or something else entirely? hacking: security in practice · 79d ago Agentic AI Isn't Risky; the Way Orgs Deploy It Is darkreading · 79d ago A Deeper Look at GLASSWORM's Solana Variant Malware Analysis & Reports · 79d ago A Deeper Look at GLASSWORM's Solana Variant cybersecurity · 79d ago How 2004 RuneScape fit a multiplayer RPG into 56k dial-up Reverse Engineering · 79d ago Getting back deleted conversation from messanger hacking: security in practice · 79d ago Introducing a new design for Microsoft 365 Copilot Microsoft 365 Blog · 79d ago BlackToad: Network Manipulation in an AutoIt Payload For [Blue|Purple] Teams in Cyber Defence · 79d ago RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT For [Blue|Purple] Teams in Cyber Defence · 79d ago Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant For [Blue|Purple] Teams in Cyber Defence · 79d ago Calling Cyber Security Beginners cybersecurity · 79d ago Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE Technical Information Security Content & Discussion · 79d ago Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis cybersecurity · 79d ago Building Omegle for Exposed Webcams hacking: security in practice · 79d ago built something for ai agents, ended up looking a lot like classic appsec cybersecurity · 79d ago New Gogs zero-day flaw lets hackers get remote code execution BleepingComputer · 79d ago Is Gophish still usable in 2026? cybersecurity · 79d ago Microsoft vs Chaotic Eclipse: three zero-days now actively exploited cybersecurity · 79d ago How SIEM helps MSPs reduce noise and stop threats faster BleepingComputer · 79d ago what do you think cybersecurity · 79d ago Why would be clicking a website, redirect me? cybersecurity · 79d ago Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit For [Blue|Purple] Teams in Cyber Defence · 79d ago Zapier fixes bug chain that researchers say risked widespread account takeover cybersecurity · 79d ago AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career? hacking: security in practice · 79d ago Writing cybersecurity policies is a waste of time cybersecurity · 79d ago Zapier fixes bug chain that researchers say risked widespread account takeover CyberScoop · 79d ago The GitHub Leak Situation Just Got Worse | Threat Wire Hak5 · 79d ago reverse engineering need for speed most wanted for modding sdk Reverse Engineering · 79d ago Romanian gets 5 years in prison for hacking Oregon govt network BleepingComputer · 79d ago Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security darkreading · 79d ago Webinar: Why network incidents take too long to resolve BleepingComputer · 79d ago Raising the Cybersecurity Stakes: Ante up for the Agentic Era. cybersecurity · 79d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories Alerts · 79d ago ABB EIBPORT All CISA Advisories · 79d ago Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter All CISA Advisories · 79d ago ABB Busch-Welcome 2 Wire Door Opener Actuator All CISA Advisories · 79d ago Fourth Frontier Frontier X Mobile Application, Frontier X2 All CISA Advisories · 79d ago CP Plus 8 Ch. Network Video Recorder All CISA Advisories · 79d ago XCharge C6 All CISA Advisories · 79d ago KMW CCTV Security Cameras All CISA Advisories · 79d ago MacGregor Voyage Data Recorder (VDR) G4e All CISA Advisories · 79d ago Schnieider Electric EcoStruxure Machine Expert HVAC All CISA Advisories · 79d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories All CISA Advisories · 79d ago Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it. cybersecurity · 79d ago [ Removed by Reddit ] cybersecurity · 79d ago Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15 Malware Analysis & Reports · 79d ago Released: Dataforge Honeypot cybersecurity · 79d ago Carnival Cruise confirms data breach affecting nearly 6 million people BleepingComputer · 79d ago Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks cybersecurity · 79d ago CEH-free cybersecurity · 79d ago Hottest cybersecurity open-source tools of the month: May 2026 cybersecurity · 79d ago Preparation tips for CPENT cybersecurity · 79d ago Sextortionist sentenced to 33 years for targeting 145 children BleepingComputer · 79d ago BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model darkreading · 79d ago FROST: Fingerprinting Remotely using OPFS-based SSD Timing For [Blue|Purple] Teams in Cyber Defence · 79d ago How do you handle AI tools in your organization? cybersecurity · 79d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 79d ago What scanners are actually trying against AI infrastructure Technical Information Security Content & Discussion · 80d ago I think i got scammed anybody can help me with that cybersecurity · 80d ago Nordic CISOs Handle Rising Cyber Threats Remarkably Well darkreading · 80d ago New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo cybersecurity · 80d ago Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup For [Blue|Purple] Teams in Cyber Defence · 80d ago Is it safe to have passwords copied to clipboard on IOS temporarily? cybersecurity · 80d ago Developers working on anti-fraud systems deserve more credit cybersecurity · 80d ago My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst cybersecurity · 80d ago GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs. Reverse Engineering · 80d ago Security awareness training for AI heavy smb workflows? cybersecurity · 80d ago puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 80d ago Defense by accumulation Technical Information Security Content & Discussion · 80d ago Minimum Requirements for Helpdesk Role ? cybersecurity · 80d ago Reddit spear phishing cybersecurity · 80d ago Winbox server/client reverse engineered is opensource Reverse Engineering · 80d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ cybersecurity · 80d ago What to do cybersecurity · 80d ago What resources would you recommend for studying cysa+ cybersecurity · 80d ago Provenance of Data cybersecurity · 80d ago GPU mining malware spreads via SEO poisoning, AI chatbots BleepingComputer · 80d ago 5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain hacking: security in practice · 80d ago Websites have a new way to spy on visitors: analyzing their SSD activity cybersecurity · 80d ago 12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal? cybersecurity · 80d ago OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms CyberScoop · 80d ago Russian Art Teacher - Hinder Security Clearance? cybersecurity · 80d ago Ransomware Actors Show Up In Person to Steal Law Firm Data darkreading · 80d ago FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person CyberScoop · 80d ago Who is Salt Typhoon Really? Unraveling the Attribution Challenge For [Blue|Purple] Teams in Cyber Defence · 80d ago EDR/MDR Vendor Questions cybersecurity · 80d ago Cybersecurity as a Highschooler? cybersecurity · 80d ago New department created, would love your input cybersecurity · 80d ago What are the dangers of posting? hacking: security in practice · 80d ago OWASP Vienna - anyone going? cybersecurity · 80d ago Interview with Upstart cybersecurity · 80d ago 18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber. cybersecurity · 80d ago Is cloud security engineer viable with my current position? cybersecurity · 80d ago UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace CyberScoop · 80d ago Cloudflare Access users: what would actually make JIT useful for you? cybersecurity · 80d ago Looking for resources on end-to-end APT attack flow summaries for detection engineering For [Blue|Purple] Teams in Cyber Defence · 80d ago Kali365 Activity Surges: Device Code Phishing Is Scaling Fast Malware Analysis & Reports · 80d ago eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels cybersecurity · 80d ago The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire For [Blue|Purple] Teams in Cyber Defence · 80d ago Questions regarding Ubuntu 24 LTS hardening cybersecurity · 80d ago Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho. cybersecurity · 80d ago Honest question about OT Security Engineer work life in India cybersecurity · 80d ago Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning) cybersecurity · 80d ago AI Security cybersecurity · 80d ago Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor cybersecurity · 80d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP For [Blue|Purple] Teams in Cyber Defence · 80d ago 🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents cybersecurity · 80d ago Latin American Cybercriminals Hoover Up Government Data darkreading · 80d ago Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint For [Blue|Purple] Teams in Cyber Defence · 80d ago AI-Assisted Exploit Development Outpaces Scanner Detection darkreading · 80d ago Building Detection Engineering on AWS from scratch — roast my plan cybersecurity · 80d ago Building Detection Engineering on AWS from scratch — roast my plan For [Blue|Purple] Teams in Cyber Defence · 80d ago New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault Technical Information Security Content & Discussion · 80d ago Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance cybersecurity · 80d ago Flipper Zero Users, What's Your Take? hacking: security in practice · 80d ago Large company with a bit of an issue free stuff hacking: security in practice · 80d ago I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA. cybersecurity · 80d ago Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning cybersecurity · 80d ago Final Year Project: Looking for non-generic IAM project ideas that solve real problems cybersecurity · 80d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Technical Information Security Content & Discussion · 80d ago GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled. cybersecurity · 80d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware For [Blue|Purple] Teams in Cyber Defence · 80d ago Breaking out of IT Helpdesk - how? cybersecurity · 80d ago A year in Cybersecurity — Where Do I Go From Here? cybersecurity · 80d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware cybersecurity · 80d ago MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Malware Analysis & Reports · 80d ago Can you enforce strong Active Directory password rules without frustrating users? BleepingComputer · 80d ago 22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber cybersecurity · 80d ago FBI: Silent Ransom Group Turns to IT Support Ploy cybersecurity · 80d ago A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate Technical Information Security Content & Discussion · 80d ago How do machine builders track Siemens/Rockwell security advisories? cybersecurity · 80d ago CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain CyberScoop · 80d ago Glassworm botnet disrupted after resilient C2 infrastructure takedown BleepingComputer · 80d ago GlassWorm Developer Supply-Chain Botnet Takedown cybersecurity · 80d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN cybersecurity · 80d ago Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV cybersecurity · 80d ago (URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active Reverse Engineering · 80d ago Got cybersec work what next ? cybersecurity · 80d ago Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables cybersecurity · 80d ago Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers cybersecurity · 80d ago HN Security - AI Reporter - Let's automate reporting in Burp Suite! Technical Information Security Content & Discussion · 80d ago Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing? cybersecurity · 80d ago GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP) cybersecurity · 80d ago nightmare eclipse is probably French here is why cybersecurity · 80d ago Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines cybersecurity · 80d ago Measuring performance of JA4/JA4H AI Model cybersecurity · 80d ago Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security darkreading · 80d ago What things are you really focused on this year? cybersecurity · 80d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 80d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 80d ago FBI warns of in-person data theft attacks from extortion gang BleepingComputer · 80d ago Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io) Malware Analysis & Reports · 80d ago Designing secure access with ZTNA For [Blue|Purple] Teams in Cyber Defence · 80d ago Hypothetical EDR spoofer Reverse Engineering · 80d ago Hypothetical EDR spoofer cybersecurity · 80d ago ISO 27001 Audit Stage 1 cybersecurity · 80d ago Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records Technical Information Security Content & Discussion · 80d ago Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That. cybersecurity · 80d ago CISA gives feds 4 days to patch actively exploited cPanel plugin flaw BleepingComputer · 80d ago Dutch police arrests suspect linked to Ajax football club hack BleepingComputer · 80d ago What to consider before asking an AI chatbot for health advice WeLiveSecurity · 80d ago Looking for Hacker Friends to Learn☺️ cybersecurity · 80d ago Comptes Instagram et Facebook piratés et désactivés cybersecurity · 80d ago RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact Technical Information Security Content & Discussion · 80d ago How to safely disinfect a USB stick from potential malware files? cybersecurity · 80d ago Windows 11 KB5089573 update released with performance improvements BleepingComputer · 80d ago Champion ethical hacker warns AI tools like Mythos will make competing harder. hacking: security in practice · 81d ago MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response For [Blue|Purple] Teams in Cyber Defence · 81d ago White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats For [Blue|Purple] Teams in Cyber Defence · 81d ago Advisory X41-2026-002: Request Host Header not Validated in Starlette For [Blue|Purple] Teams in Cyber Defence · 81d ago Top ethical hacker Chompie warns AI tools could put her out of business For [Blue|Purple] Teams in Cyber Defence · 81d ago 浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents For [Blue|Purple] Teams in Cyber Defence · 81d ago Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker. hacking: security in practice · 81d ago YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions For [Blue|Purple] Teams in Cyber Defence · 81d ago CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state For [Blue|Purple] Teams in Cyber Defence · 81d ago The Evolution of Chinese-language Phishing Services For [Blue|Purple] Teams in Cyber Defence · 81d ago Silent Ransom Group Impersonating IT Personnel through Social Engineering For [Blue|Purple] Teams in Cyber Defence · 81d ago Is anyone else concerned about how quickly AI is outpacing cloud security? cybersecurity · 81d ago The epoll UAF - an epoll uaf race in fs/eventpoll.c For [Blue|Purple] Teams in Cyber Defence · 81d ago Tycoon 2FA AiTM detection for Entra ID and Google For [Blue|Purple] Teams in Cyber Defence · 81d ago Microsoft Copilot Cowork Exfiltrates Files For [Blue|Purple] Teams in Cyber Defence · 81d ago What's a CyberSecurity job like? cybersecurity · 81d ago Microsoft Live credential stuffing cybersecurity · 81d ago I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this? cybersecurity · 81d ago Security architects- summarize your responsibilities and role cybersecurity · 81d ago Finding Work in OSINT cybersecurity · 81d ago State of SDLC Security 2026 cybersecurity · 81d ago Reported to police for coding html cybersecurity · 81d ago there's a toll in the hall now hacking: security in practice · 81d ago I Reverse Engineered Need for Speed Most Wanted Server Reverse Engineering · 81d ago Am I crazy or is something off about this Google OAuth login via Calendly hacking: security in practice · 81d ago [Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling) cybersecurity · 81d ago I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project cybersecurity · 81d ago Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover cybersecurity · 81d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators? cybersecurity · 81d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells cybersecurity · 81d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells BleepingComputer · 81d ago GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet The Last Watchdog · 81d ago Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos darkreading · 81d ago Charter confirms data breach after ShinyHunters extortion threat BleepingComputer · 81d ago Apple open-sources quantum-resistant encryption code CyberScoop · 81d ago Breaking GROK'S DEFENSES to make it HACK Real Public Websites cybersecurity · 81d ago GitHub Actions Cache Poisoning is eating open source cybersecurity · 81d ago State Cyber Leaders Push Congress for More Funding, Support darkreading · 81d ago Nightmare-Eclipse has also been banned on GitLab :DD cybersecurity · 81d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled? darkreading · 81d ago For Enterprises, Security Remains Agentic AI's Biggest Challenge darkreading · 81d ago Do we still have time before we are in the Age of the movie "Minority Report"? ↓ cybersecurity · 81d ago SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file cybersecurity · 81d ago Unpatched Sparx vulnerabilties For [Blue|Purple] Teams in Cyber Defence · 81d ago What Software Supply Chain, Water Filters, and Power Grids Have in Common cybersecurity · 81d ago QA engineer trying to move into AppSec — does this plan hold up? cybersecurity · 81d ago Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down. Malware Analysis & Reports · 81d ago Is work from anywhere really impossible to find?? cybersecurity · 81d ago Navigating Lax Load Balancers: When an Intersection Gets You Inside Technical Information Security Content & Discussion · 81d ago New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences Microsoft 365 Blog · 81d ago Cybersecurity statistics of the week (May 18th - May 24th) cybersecurity · 81d ago Engineering a Post Quantum Fortress Inside the Citadel Archite cybersecurity · 81d ago Cyber Security Analyst cybersecurity · 81d ago Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance cybersecurity · 81d ago Two layer email security tool thesis cybersecurity · 81d ago Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents Technical Information Security Content & Discussion · 81d ago sylvia: iOS Syscall Explorer for IDA 9.X For [Blue|Purple] Teams in Cyber Defence · 81d ago Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation Reverse Engineering · 81d ago OTP lockout state leaked valid-code signal, enabling OLX account takeover Technical Information Security Content & Discussion · 81d ago When OTP rate limiting fails: OLX account takeover with persistent sessions cybersecurity · 81d ago When “try again later” still tells you the OTP was correct: an account takeover story. hacking: security in practice · 81d ago Entra ID sessions revoke cybersecurity · 81d ago Anyone who attended GPCSSI before? Need some clarification cybersecurity · 81d ago How Varonis Atlas integrates Claude Compliance API for AI governance BleepingComputer · 81d ago Lost on my career path. cybersecurity · 81d ago How journalists rely on VPNs to protect press freedom Technical Information Security Content & Discussion · 81d ago EU-based folks: external pentest vs mandatory data/security training? cybersecurity · 81d ago help needed from experienced people cybersecurity · 81d ago How do you evaluate whether a privacy service is actually privacy-respecting? cybersecurity · 81d ago Which one Intellipaat or coursera which one to choose cybersecurity · 81d ago How random program can cause most of antiviruses close himself without telling himself to close Malware Analysis & Reports · 81d ago Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching Reverse Engineering · 81d ago ShadowCat: Universal optical file transfer, single html file, browser to camera hacking: security in practice · 81d ago Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1) Technical Information Security Content & Discussion · 81d ago Microsoft Defender can now automatically isolate hacked endpoints BleepingComputer · 81d ago Webinar: Too many tools are slowing network incident response BleepingComputer · 81d ago CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks cybersecurity · 81d ago India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic? cybersecurity · 81d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 81d ago ABB Terra AC All CISA Advisories · 81d ago ABB LVS MConfig All CISA Advisories · 81d ago ABB Ability Camera Connect All CISA Advisories · 81d ago Eppendorf BioFlo 320 All CISA Advisories · 81d ago ABB AbilityTM Zenon Remote Transport Vulnerability All CISA Advisories · 81d ago ABB AC500 V2 All CISA Advisories · 81d ago ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) All CISA Advisories · 81d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 81d ago Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs. cybersecurity · 81d ago Did anyone pass the SC-200 certificate recently? cybersecurity · 81d ago Honeypot cybersecurity · 81d ago passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account cybersecurity · 81d ago Career in IAM as a fresher cybersecurity · 81d ago CISA orders feds to patch actively exploited Drupal vulnerability cybersecurity · 81d ago Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure cybersecurity · 81d ago GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” cybersecurity · 81d ago Cyber security tool cybersecurity · 81d ago Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East For [Blue|Purple] Teams in Cyber Defence · 81d ago GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip For [Blue|Purple] Teams in Cyber Defence · 81d ago JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign For [Blue|Purple] Teams in Cyber Defence · 81d ago Saw this tool and it has potential cybersecurity · 81d ago 🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs cybersecurity · 81d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack For [Blue|Purple] Teams in Cyber Defence · 81d ago How I Tried to Parse a Replay from Dawn of War: Definitive Edition Reverse Engineering · 81d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files cybersecurity · 81d ago Follow up : showing Claude install random pacakage in its vm instance without asking or prompting cybersecurity · 81d ago BTMOB: A stealthy RAT burrowing deep into Android devices WeLiveSecurity · 81d ago Update Starlette Now. New severe vulnerability dropped. Technical Information Security Content & Discussion · 81d ago CISA orders feds to patch actively exploited Drupal vulnerability BleepingComputer · 81d ago Microsoft: Domain Controller lookup may fail on Windows Server 2016 BleepingComputer · 82d ago Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@" For [Blue|Purple] Teams in Cyber Defence · 82d ago The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization For [Blue|Purple] Teams in Cyber Defence · 82d ago ¿Is safe? cybersecurity · 82d ago 7-Eleven data breach exposes personal information of 185,000 people BleepingComputer · 82d ago Need help cybersecurity · 82d ago What is the best tool for masking in kali cybersecurity · 82d ago What are the best tools other than ghostTracker? cybersecurity · 82d ago y2jb un able to enject payloads hacking: security in practice · 82d ago TrapDoor Cross-Ecosystem Crypto Stealer Campaign cybersecurity · 82d ago Follow up : Steal Your Files Claude AI installing package because internet say so cybersecurity · 82d ago New to Cybersecurity: Looking for general advice & help with Nmap cybersecurity · 82d ago GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP. For [Blue|Purple] Teams in Cyber Defence · 82d ago Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal cybersecurity · 82d ago Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated. hacking: security in practice · 82d ago Looking for tech role references cybersecurity · 82d ago Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet Trend Micro Research, News, Perspectives · 82d ago How do you balance Paw? cybersecurity · 82d ago I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity. cybersecurity · 82d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Malware Analysis & Reports · 82d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Technical Information Security Content & Discussion · 82d ago Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability For [Blue|Purple] Teams in Cyber Defence · 82d ago From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security cybersecurity · 82d ago Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February cybersecurity · 82d ago What Companies are Legit? cybersecurity · 82d ago start learning cybersecurity from scratch cybersecurity · 82d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 82d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 82d ago WhatsApp users on alert after hacker drops massive dataset cybersecurity · 82d ago 17 years old going into CS — what certs should I start going after now? cybersecurity · 82d ago CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700. For [Blue|Purple] Teams in Cyber Defence · 82d ago i want to hire an osint expert cybersecurity · 82d ago Open University pros/cons cybersecurity · 82d ago How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection? cybersecurity · 82d ago Career in IAM as a fresher cybersecurity · 82d ago Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo cybersecurity · 82d ago Need Advice cybersecurity · 82d ago Why did Hack Forums lose popularity? hacking: security in practice · 82d ago Nocturne - A bin2bin code virtualizer for x86-64 PE binaries Reverse Engineering · 82d ago Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all? cybersecurity · 82d ago Someone from Germany on iOS keeps trying to login to my MSFT account cybersecurity · 82d ago AI cautionary tale... cybersecurity · 82d ago [Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing Reverse Engineering · 82d ago Anthropic’s restricted Claude Mythos model may be coming to Claude Code BleepingComputer · 82d ago AI powered red vs blue teaming cybersecurity · 82d ago Starting a security analyst student apprenticeship next week, need advice cybersecurity · 82d ago Why CVE Does Not Work for AI Agents, but AVE? cybersecurity · 82d ago SC-200 or Security+ — which actually helps land a security title cybersecurity · 82d ago How about AI having access to your hard drive. cybersecurity · 82d ago How a Date Tag Hijacks macOS via ExifTool cybersecurity · 82d ago Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools cybersecurity · 82d ago Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing Reverse Engineering · 82d ago How credential brokering prevents AI agents from compromising credentials via prompt injection Technical Information Security Content & Discussion · 82d ago How credential brokering prevents AI agents from compromising credentials via prompt injection cybersecurity · 82d ago Built a tiny daily cyber puzzle game during evenings/weekends cybersecurity · 82d ago Crypto4A launches quantum-safe rival to AWS Secrets Manager cybersecurity · 82d ago CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth Technical Information Security Content & Discussion · 82d ago ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why. cybersecurity · 82d ago Cyber Sec project cybersecurity · 82d ago ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise hacking: security in practice · 82d ago CySA+ cybersecurity · 82d ago Anyone tried Morgancyberhelp ? cybersecurity · 82d ago As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free cybersecurity · 82d ago YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos For [Blue|Purple] Teams in Cyber Defence · 82d ago Why are most of the dfir tools built to be used in windows cybersecurity · 82d ago OnlyFans mega leak reveals 340M user records, hackers claim cybersecurity · 82d ago Perplexity BumbleBee cybersecurity · 82d ago Cisco patches critical 10.0 flaw in Secure Workload APIs cybersecurity · 82d ago Suspicious ass website asking to run a terminal command (MacOS) Malware Analysis & Reports · 82d ago Shellcide: A shellcode IDE hacking: security in practice · 82d ago Stalker has my phonenumber cybersecurity · 82d ago FBI warns of Kali365 phishing service targeting Microsoft 365 accounts BleepingComputer · 82d ago I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built Reverse Engineering · 82d ago Need some guidance cybersecurity · 82d ago Are you currently allocating budget to services that remove executive PII from B2B data brokers? cybersecurity · 82d ago Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal Technical Information Security Content & Discussion · 82d ago About CEHv13 book cybersecurity · 82d ago delimiter-less string obfuscation powered by compile-time AES Reverse Engineering · 82d ago Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it For [Blue|Purple] Teams in Cyber Defence · 82d ago We open-sourced the most dangerous part of our security startup on purpose. cybersecurity · 82d ago Which conference(s) result in the most people finding jobs? cybersecurity · 82d ago My discord account has been hacked second time even after enabling two factor authentication and resetting password cybersecurity · 82d ago What's the most efficient way to learn cloud governance and compliance cybersecurity · 82d ago honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports For [Blue|Purple] Teams in Cyber Defence · 82d ago Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild. For [Blue|Purple] Teams in Cyber Defence · 82d ago Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council For [Blue|Purple] Teams in Cyber Defence · 82d ago RemotePE: The Lazarus RAT that lives in memory For [Blue|Purple] Teams in Cyber Defence · 82d ago Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer For [Blue|Purple] Teams in Cyber Defence · 82d ago Paved With Intent: ROADtools and Nation-State Tactics in the Cloud For [Blue|Purple] Teams in Cyber Defence · 82d ago Twee mannen aangehouden voor phishing - Two men arrested for phishing For [Blue|Purple] Teams in Cyber Defence · 82d ago Sharp Eyes: Mass surveillance of foreigners in China For [Blue|Purple] Teams in Cyber Defence · 82d ago Does anyone know C2 framwork and free hosting to host C2? cybersecurity · 82d ago Finding bot account hacking: security in practice · 82d ago relay_bible: Technical Reference to multiple relay techniques For [Blue|Purple] Teams in Cyber Defence · 83d ago CIS-CAT Assessor for assessment Windows server 2022 and 2025 cybersecurity · 83d ago Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec For [Blue|Purple] Teams in Cyber Defence · 83d ago The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in] For [Blue|Purple] Teams in Cyber Defence · 83d ago SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format For [Blue|Purple] Teams in Cyber Defence · 83d ago North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial For [Blue|Purple] Teams in Cyber Defence · 83d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 83d ago Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this cybersecurity · 83d ago Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks? cybersecurity · 83d ago Recent adoption of AI taught me what is Cybersecurity. cybersecurity · 83d ago The Pentagon Changed the Rules for Cybersecurity Compliance cybersecurity · 83d ago Can someone explain to a noob like me what the implications of this exploit are? cybersecurity · 83d ago SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections cybersecurity · 83d ago Window between zero-day CVE and a patch! cybersecurity · 83d ago Is it risky when a website puts on technology components with versions they used in their website? cybersecurity · 83d ago Anyone else losing their mind over this "AI Cybersecurity" hype? cybersecurity · 83d ago URL parsing behavior in a canonical tag lab cybersecurity · 83d ago How to hacking: security in practice · 83d ago Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you? cybersecurity · 83d ago Any tips for me pls cybersecurity · 83d ago How do you minimize legal liability as a solo contractor? cybersecurity · 83d ago How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing? cybersecurity · 83d ago nmap on Linux: Guide to Network Scanning and Discovery Technical Information Security Content & Discussion · 83d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 83d ago Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift. hacking: security in practice · 83d ago Provenance: A survival toolkit for an AI dominant information landscape cybersecurity · 83d ago Nmap Mastery: The Complete Guide to Network Reconnaissance hacking: security in practice · 83d ago Google wallet virtual card cloned hacking: security in practice · 83d ago [ Removed by Reddit ] cybersecurity · 83d ago Active Drupal SQLi exploitation is a real „patch now“ moment cybersecurity · 83d ago machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native) cybersecurity · 83d ago Need suggestions and input; not a promotion cybersecurity · 83d ago Need advice! cybersecurity · 83d ago New Zealand is becoming a focal point for AI-driven superhacking threats. cybersecurity · 83d ago Staged publishing and new install-time controls for npm - GitHub Changelog For [Blue|Purple] Teams in Cyber Defence · 83d ago nmap on Linux: Guide to Network Scanning and Discovery cybersecurity · 83d ago TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle cybersecurity · 83d ago How would Phishing look like in the future? (targeting agents, not humans) cybersecurity · 83d ago Best beginner/intermediate book for system security (blue team / defense / audits)? cybersecurity · 83d ago Why is on-prem and air-gapped asset inventory still such a mess? cybersecurity · 83d ago keep getting MS authentication sign in attempts? cybersecurity · 83d ago Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES For [Blue|Purple] Teams in Cyber Defence · 83d ago Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud For [Blue|Purple] Teams in Cyber Defence · 83d ago Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow For [Blue|Purple] Teams in Cyber Defence · 83d ago The Future and Past of Residential Proxies For [Blue|Purple] Teams in Cyber Defence · 83d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 83d ago Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy For [Blue|Purple] Teams in Cyber Defence · 83d ago Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware For [Blue|Purple] Teams in Cyber Defence · 83d ago A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software For [Blue|Purple] Teams in Cyber Defence · 83d ago Prompt Injection finally broke my brain a little. My first article as a security student. Technical Information Security Content & Discussion · 83d ago Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows For [Blue|Purple] Teams in Cyber Defence · 83d ago Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 83d ago Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes For [Blue|Purple] Teams in Cyber Defence · 83d ago mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. For [Blue|Purple] Teams in Cyber Defence · 83d ago keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust. For [Blue|Purple] Teams in Cyber Defence · 83d ago np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation. For [Blue|Purple] Teams in Cyber Defence · 83d ago Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up. For [Blue|Purple] Teams in Cyber Defence · 83d ago OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ For [Blue|Purple] Teams in Cyber Defence · 83d ago Megalodon: Mass GitHub Repo Backdooring via CI Workflows For [Blue|Purple] Teams in Cyber Defence · 83d ago Silly issue cybersecurity · 83d ago FatGid - FreeBSD 14.x kernel LPE For [Blue|Purple] Teams in Cyber Defence · 83d ago Manage [VSCode] extensions in enterprise environments For [Blue|Purple] Teams in Cyber Defence · 83d ago angr: A powerful and user-friendly binary analysis platform! For [Blue|Purple] Teams in Cyber Defence · 83d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware For [Blue|Purple] Teams in Cyber Defence · 83d ago Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign BleepingComputer · 83d ago How Attackers Force Microsoft to Send Phishing Emails For [Blue|Purple] Teams in Cyber Defence · 83d ago Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects For [Blue|Purple] Teams in Cyber Defence · 83d ago Microsoft Authenticator App Details now exposed in Entra SignInLogs For [Blue|Purple] Teams in Cyber Defence · 83d ago Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting For [Blue|Purple] Teams in Cyber Defence · 83d ago How China-linked threat actors obtain zero-day vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 83d ago How to practice cybersecurity while studying prograaming ? cybersecurity · 83d ago Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research For [Blue|Purple] Teams in Cyber Defence · 83d ago How to Use Claude AI: A Complete Technical Beginner's Guide Technical Information Security Content & Discussion · 83d ago [AI Security] Exploring Behavioral AI for Runtime Threat Detection cybersecurity · 83d ago Podman and krun: is it pointless to harden quadlets? cybersecurity · 83d ago Monitoring for vssadmin.exe delete shadows is an absolute bare minimum For [Blue|Purple] Teams in Cyber Defence · 83d ago Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack For [Blue|Purple] Teams in Cyber Defence · 83d ago How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers For [Blue|Purple] Teams in Cyber Defence · 83d ago How to handle security researchers (and firms) without a bounty program? cybersecurity · 83d ago CVE-2026-48029: Two grid-decode bugs in libheif For [Blue|Purple] Teams in Cyber Defence · 83d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ Reverse Engineering · 83d ago workcell: Bounded local runtime and policy boundary for coding agents For [Blue|Purple] Teams in Cyber Defence · 83d ago OpenShell: OpenShell is the safe, private runtime for autonomous AI agents. For [Blue|Purple] Teams in Cyber Defence · 83d ago Product analytics is becoming a third-party breach surface cybersecurity · 83d ago How can i learn and get into red teaming? cybersecurity · 83d ago Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network cybersecurity · 83d ago I got hacked cybersecurity · 83d ago What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method? hacking: security in practice · 83d ago Soc analysts in big companies, how it looks like? cybersecurity · 83d ago Has anyone manage to reverse the macked dylib? Reverse Engineering · 83d ago CTO at NCSC Summary: week ending May 24th cybersecurity · 84d ago Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation For [Blue|Purple] Teams in Cyber Defence · 84d ago Built a SOC from scratch with no prior SOC experience For [Blue|Purple] Teams in Cyber Defence · 84d ago These special phone and app features can help protect you from spyware cybersecurity · 84d ago Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button? cybersecurity · 84d ago Capcha Code Malware cybersecurity · 84d ago getting lost when hunting cybersecurity · 84d ago How to find information behind an account? cybersecurity · 84d ago Reverse engineering circuitry in a Spacelab computer from 1980 Reverse Engineering · 84d ago Theoretical Design Concept for Post-Exploitation Browser Defense cybersecurity · 84d ago Google Certifications... cybersecurity · 84d ago How to continue when finding a possible Vulnerability but local law prohibits me from investigating further cybersecurity · 84d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks cybersecurity · 84d ago Is the CISSP still a reputable cert for getting jobs? cybersecurity · 84d ago Which of these gоv roles would fare better in the private sector? cybersecurity · 84d ago Laravel Lang packages hijacked to deploy credential-stealing malware cybersecurity · 84d ago Laravel Lang packages hijacked to deploy credential-stealing malware BleepingComputer · 84d ago Mapping binaries to EDR feature spaces cybersecurity · 84d ago Lost my number + WhatsApp account — worried about old chats, photos, and videos cybersecurity · 84d ago Proxmark5 campaign unlocked the $600k stretch goal hacking: security in practice · 84d ago ☔️🌅 STÖK · 84d ago what is the most painful or time-consuming part of your work right now?" cybersecurity · 84d ago Anthropic says Mythos has already found more than 10,000 vulnerabilities cybersecurity · 84d ago What is the experience needed for “entry level” cybersecurity jobs? cybersecurity · 84d ago Browser extension testing. cybersecurity · 84d ago GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision hacking: security in practice · 84d ago Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip? cybersecurity · 84d ago Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology Reverse Engineering · 84d ago Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback cybersecurity · 84d ago Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition cybersecurity · 84d ago Can someone recommend me some good, large universities to study cybersecurity? cybersecurity · 84d ago New guy khikhi cybersecurity · 84d ago Examples of intentional backdoors being breached? cybersecurity · 84d ago Non-Compliant Vocab cybersecurity · 84d ago CTO at NCSC Summary: week ending May 24th For [Blue|Purple] Teams in Cyber Defence · 84d ago HackTheBox - MonitorsFour IppSec · 84d ago VPN Exploitation When Patched Doesn't Mean Protected For [Blue|Purple] Teams in Cyber Defence · 84d ago Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation For [Blue|Purple] Teams in Cyber Defence · 84d ago Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites cybersecurity · 84d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 84d ago CLR-Stomp: .NET CLR-Stomping For [Blue|Purple] Teams in Cyber Defence · 84d ago Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes BleepingComputer · 84d ago infostealers just spawned a 5,000+ repo github supply chain attack cybersecurity · 84d ago The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis cybersecurity · 84d ago Doom running on a Kids Video Walkie Talkie hacking: security in practice · 84d ago GRO frag cybersecurity · 84d ago We audited 12K n8n templates: most have critical vulnerabilities cybersecurity · 84d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 84d ago Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week cybersecurity · 84d ago Mitigated Vulnerabilities by Vendor as Feed cybersecurity · 84d ago From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence For [Blue|Purple] Teams in Cyber Defence · 84d ago Introducing Showboat: A new malware family taunts defenses and targets international telecom firms For [Blue|Purple] Teams in Cyber Defence · 84d ago Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor For [Blue|Purple] Teams in Cyber Defence · 84d ago Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors cybersecurity · 84d ago A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories cybersecurity · 85d ago Where can I find the tools freely on internet to practice for soc analyst cybersecurity · 85d ago Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX. hacking: security in practice · 85d ago Pardon MIE?: how Mythos did not bypass Apple MIE Technical Information Security Content & Discussion · 85d ago residential proxies cybersecurity · 85d ago Recommendations for getting started in cybersecurity cybersecurity · 85d ago Linux mint or Ubuntu for complete beginner cybersecurity · 85d ago Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. cybersecurity · 85d ago Pentesting company recommendation cybersecurity · 85d ago Have you ever failed a certification exam? cybersecurity · 85d ago AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance cybersecurity · 85d ago This ID Verification company store users biometrics? (FaceTec) hacking: security in practice · 85d ago What do i need to learn to get into application security? Which Degrees/Certs cybersecurity · 85d ago RSAC online membership? Is it worth it? cybersecurity · 85d ago Playwright version that lets AI-Agents navigate the web hacking: security in practice · 85d ago Can someone give me a detailed roadmap for becoming a SOC Analyst? cybersecurity · 85d ago Puedo conseguir trabajo? cybersecurity · 85d ago How do i learn networking for cyber security? cybersecurity · 85d ago What's going to be Hacking and Cybersecurity's future is gonna be like? cybersecurity · 85d ago Cyber security placement - Interview Help cybersecurity · 85d ago CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module Technical Information Security Content & Discussion · 85d ago Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge cybersecurity · 85d ago AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22) For [Blue|Purple] Teams in Cyber Defence · 85d ago CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22) Reverse Engineering · 85d ago AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22 Technical Information Security Content & Discussion · 85d ago Feedback needed cybersecurity · 85d ago GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks. For [Blue|Purple] Teams in Cyber Defence · 85d ago Handoff Transition cybersecurity · 85d ago Where to learn the ins and outs of the computer itself hacking: security in practice · 85d ago Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't) Technical Information Security Content & Discussion · 85d ago Just added an interactive security map showing exactly what the server sees (and doesn't) cybersecurity · 85d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks BleepingComputer · 85d ago Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns For [Blue|Purple] Teams in Cyber Defence · 85d ago Trend Micro warns of Apex One zero-day exploited in the wild cybersecurity · 85d ago Lawmakers Demand Answers as CISA Tries to Contain Data Leak cybersecurity · 85d ago Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL? For [Blue|Purple] Teams in Cyber Defence · 85d ago https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/ cybersecurity · 85d ago Harvard and 140 other legitimate websites compromised Malware Analysis & Reports · 85d ago Harvard and 140 other legitimate websites compromised cybersecurity · 85d ago Votre Satisfaction Dans Votre Travail cybersecurity · 85d ago 5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. cybersecurity · 85d ago Former US execs plead guilty to aiding tech support scammers BleepingComputer · 85d ago Browser session theft is quietly becoming more dangerous than password theft Malware Analysis & Reports · 85d ago US states urge Congress to renew cybersecurity grants cybersecurity · 85d ago Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension Technical Information Security Content & Discussion · 85d ago Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours Malware Analysis & Reports · 85d ago Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes Reverse Engineering · 85d ago The CISO's Guide to IDE Security in 2026 cybersecurity · 85d ago Help with evilginx cybersecurity · 85d ago Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets Technical Information Security Content & Discussion · 85d ago Watching AI Brain Drain on Attackers in Real Time cybersecurity · 85d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 85d ago api-rta cyberwarfare labs cybersecurity · 85d ago Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator hacking: security in practice · 85d ago Trend Micro warns of Apex One zero-day exploited in the wild BleepingComputer · 85d ago I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner For [Blue|Purple] Teams in Cyber Defence · 85d ago The Worm That Deletes Your Entire Computer | Threat Wire Hak5 · 85d ago Drupal: Critical SQL injection flaw now targeted in attacks BleepingComputer · 85d ago Why Chargebacks are Just One Piece of the Fraud Puzzle BleepingComputer · 85d ago Does Security Implement Fixes? cybersecurity · 85d ago Ultimate Cybersecurity without needing AV ect? cybersecurity · 85d ago Hack your corrupt company. Sell their secrets to the black market hacking: security in practice · 85d ago User Onboarding with IAM cybersecurity · 85d ago Ubiquiti patches three max severity UniFi OS vulnerabilities BleepingComputer · 85d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 85d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 85d ago Data breach in name of protest Technical Information Security Content & Discussion · 85d ago qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb) Reverse Engineering · 85d ago pnpm 11 Might Finally Be a Better Default Than npm Technical Information Security Content & Discussion · 85d ago pnpm 11 Might Finally Be a Better Default Than npm cybersecurity · 85d ago 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs cybersecurity · 85d ago Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria cybersecurity · 85d ago AI-generated reporting: Lessons learned from Cisco Talos Incident Response For [Blue|Purple] Teams in Cyber Defence · 85d ago CrabLoader: A PoC Cobalt Strike UDRL written in Rust For [Blue|Purple] Teams in Cyber Defence · 85d ago The 429 Microsoft Graph Mystery For [Blue|Purple] Teams in Cyber Defence · 85d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 85d ago Azure Tenant Enumeration is Dead For [Blue|Purple] Teams in Cyber Defence · 85d ago A Deep Dive into Codex Windows Sandbox For [Blue|Purple] Teams in Cyber Defence · 85d ago Striga: Lifting x86 to LLVM IR with Python For [Blue|Purple] Teams in Cyber Defence · 85d ago Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip" cybersecurity · 85d ago Looking for a cybersecurity professional to interview for a university project (interview in French) cybersecurity · 85d ago US and Canada arrest and charge suspected Kimwolf botnet admin BleepingComputer · 85d ago Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise WeLiveSecurity · 85d ago veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker. For [Blue|Purple] Teams in Cyber Defence · 85d ago Windows BitLocker Security Feature Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 85d ago CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility For [Blue|Purple] Teams in Cyber Defence · 85d ago Google API keys keep working after you delete them long enough to be exploited For [Blue|Purple] Teams in Cyber Defence · 85d ago Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? For [Blue|Purple] Teams in Cyber Defence · 85d ago North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT For [Blue|Purple] Teams in Cyber Defence · 85d ago Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit For [Blue|Purple] Teams in Cyber Defence · 85d ago Safe read-only check script for Copy Fail / CVE-2026-31431 cybersecurity · 85d ago New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible? cybersecurity · 86d ago Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names) For [Blue|Purple] Teams in Cyber Defence · 86d ago [TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly cybersecurity · 86d ago Cisco used AI to write security incident reports, with mixed results cybersecurity · 86d ago [TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM) cybersecurity · 86d ago Reverse Engineered Google reCAPTCHA Reverse Engineering · 86d ago Cyber Insurance Actuary Looking for Educational Resources cybersecurity · 86d ago As a bank , how do i give protected access to claude to my team? cybersecurity · 86d ago Can seasonal Apple Store employees apply for internal IT/cybersecurity roles? cybersecurity · 86d ago Reliable IP reputation check tools besides IPQS?(for work) cybersecurity · 86d ago 🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget hacking: security in practice · 86d ago Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026) cybersecurity · 86d ago Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins cybersecurity · 86d ago Hacked by Rat Tools for 2.5 years. cybersecurity · 86d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Trend Micro Research, News, Perspectives · 86d ago Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada CyberScoop · 86d ago Google API Keys Remain Active After Deletion cybersecurity · 86d ago Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens For [Blue|Purple] Teams in Cyber Defence · 86d ago how do cyber sec consultants and pentesters actually get new clients? cybersecurity · 86d ago Post Incident Paranoia? cybersecurity · 86d ago Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector cybersecurity · 86d ago Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity? cybersecurity · 86d ago Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready cybersecurity · 86d ago You can counter MEMZ with Krotten in XP cybersecurity · 86d ago What are the most effective ways to do Blackbox testing? cybersecurity · 86d ago Npm registry sets stage for more secure package publishing cybersecurity · 86d ago Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support cybersecurity · 86d ago Megalodon: CI/CD Malware Spreading Across GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 86d ago Lawmakers from both parties say CISA cuts have gone too far CyberScoop · 86d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave Technical Information Security Content & Discussion · 86d ago Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK cybersecurity · 86d ago Is the Cybercorps SFS still worth it? cybersecurity · 86d ago Microsoft warns hackers are exploiting password resets to gain access to user accounts cybersecurity · 86d ago Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame cybersecurity · 86d ago How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account Malware Analysis & Reports · 86d ago WORM USB drives cybersecurity · 86d ago An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model? cybersecurity · 86d ago Trump postpones executive order focused on AI security CyberScoop · 86d ago CISOs - Holding the Line cybersecurity · 86d ago [Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled Technical Information Security Content & Discussion · 86d ago Google accidentally exposed details of unfixed Chromium flaw BleepingComputer · 86d ago Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware Reverse Engineering · 86d ago A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale cybersecurity · 86d ago Security Scroll Down? cybersecurity · 86d ago mass github repo backdooring via CI workflows(Megalodon) cybersecurity · 86d ago I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP Reverse Engineering · 86d ago 📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity. For [Blue|Purple] Teams in Cyber Defence · 86d ago CISA chief frets about open-source vulnerabilities, delayed security improvements CyberScoop · 86d ago Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit? cybersecurity · 86d ago Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks For [Blue|Purple] Teams in Cyber Defence · 86d ago GitHub Actions Cache Poisoning is eating open source Technical Information Security Content & Discussion · 86d ago European authorities take down prolific cybercrime VPN service CyberScoop · 86d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Reverse Engineering · 86d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox For [Blue|Purple] Teams in Cyber Defence · 86d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox cybersecurity · 86d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Technical Information Security Content & Discussion · 86d ago CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat Technical Information Security Content & Discussion · 86d ago beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA For [Blue|Purple] Teams in Cyber Defence · 86d ago FatGid - FreeBSD 14.x kernel LPE Technical Information Security Content & Discussion · 86d ago DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind cybersecurity · 86d ago FaceTec (ID verification) company appears to store user biometrics cybersecurity · 86d ago Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) Technical Information Security Content & Discussion · 86d ago Apple blocked over $11 billion in App Store fraud in 6 years BleepingComputer · 86d ago CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication cybersecurity · 86d ago CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat hacking: security in practice · 86d ago It seems that FaceTec (ID Verification company) allows for storage of user biometrics cybersecurity · 86d ago Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check. cybersecurity · 86d ago Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data cybersecurity · 86d ago This ID verification company allows for storage of biometric data? hacking: security in practice · 86d ago What Questions Do You Ask During SSP Control Interviews? cybersecurity · 86d ago Feed The Cat BackDoor cybersecurity · 86d ago Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet BleepingComputer · 86d ago Chinese hackers target telcos with new Linux, Windows malware BleepingComputer · 86d ago Max severity Cisco Secure Workload flaw gives Site Admin privileges BleepingComputer · 86d ago Flipper One - Asking for help from the community cybersecurity · 86d ago Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 86d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 86d ago Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign For [Blue|Purple] Teams in Cyber Defence · 86d ago Police seize “First VPN” service used in ransomware, data theft attacks BleepingComputer · 86d ago Flipper One — tech specs cybersecurity · 86d ago Architecture Zero Trust détaillée cybersecurity · 86d ago I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :) hacking: security in practice · 86d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 86d ago ABB Terra AC Wallbox All CISA Advisories · 86d ago Hitachi Energy GMS600 All CISA Advisories · 86d ago ABB B&R Automation Studio All CISA Advisories · 86d ago ABB B&R Automation Runtime All CISA Advisories · 86d ago ABB B&R PCs All CISA Advisories · 86d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 86d ago Cybersecurity in Healthcare cybersecurity · 86d ago Staged publishing for npm packages | npm Docs cybersecurity · 86d ago 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though) cybersecurity · 86d ago Neither MFA, Passkey, nor trusted IP help here cybersecurity · 86d ago cyber security remote cybersecurity · 86d ago Database of Malicious Browser Extensions Malware Analysis & Reports · 86d ago Flipper One project needs community help to build open Linux platform BleepingComputer · 86d ago SeekYou — one input, 15 recon sources, one report. hacking: security in practice · 86d ago I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries Reverse Engineering · 86d ago CSIRT incident response cybersecurity · 86d ago The readiness paradox: Why a false sense of cyber confidence is becoming a liability CyberScoop · 86d ago Trying to find a graduate role cybersecurity · 86d ago bypass internet restrictions hacking: security in practice · 86d ago GitHub ~3,800 internal repos compromised through a malicious VS Code extension Technical Information Security Content & Discussion · 86d ago I’ve got 99 problems, and IOCX isn’t one. Malware Analysis & Reports · 86d ago Microsoft warns of new Defender zero-days exploited in attacks cybersecurity · 86d ago From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree For [Blue|Purple] Teams in Cyber Defence · 86d ago How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102) For [Blue|Purple] Teams in Cyber Defence · 86d ago Iran-linked Operators Suspected in ATG Breaches For [Blue|Purple] Teams in Cyber Defence · 86d ago Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs For [Blue|Purple] Teams in Cyber Defence · 86d ago Compromised Nx Console version 18.95.0 For [Blue|Purple] Teams in Cyber Defence · 86d ago CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path For [Blue|Purple] Teams in Cyber Defence · 87d ago From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat For [Blue|Purple] Teams in Cyber Defence · 87d ago Microsoft warns of new Defender zero-days exploited in attacks BleepingComputer · 87d ago Webworm: New burrowing techniques For [Blue|Purple] Teams in Cyber Defence · 87d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) For [Blue|Purple] Teams in Cyber Defence · 87d ago what is the best security app option for pixel8a? cybersecurity · 87d ago How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) cybersecurity · 87d ago IoT Security cybersecurity · 87d ago GitHub links repo breach to TanStack npm supply-chain attack cybersecurity · 87d ago GitHub links repo breach to TanStack npm supply-chain attack BleepingComputer · 87d ago Another working Linux LPE exploit is out. How are teams treating local-only bugs now? cybersecurity · 87d ago Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks cybersecurity · 87d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 87d ago Google publishes exploit code threatening millions of Chromium users cybersecurity · 87d ago landing a remote Vulnerability Management role cybersecurity · 87d ago Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case. cybersecurity · 87d ago I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting? cybersecurity · 87d ago Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit cybersecurity · 87d ago Can someone unlock a list of the 500-1000 most visited websites online? hacking: security in practice · 87d ago One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign Trend Micro Research, News, Perspectives · 87d ago Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure For [Blue|Purple] Teams in Cyber Defence · 87d ago Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation For [Blue|Purple] Teams in Cyber Defence · 87d ago Wordlist generator based on WordNet graphs + LLM hacking: security in practice · 87d ago What volume of TPRM do you handle per month? cybersecurity · 87d ago GitHub’s Fake Engagement Problem Is Hiding in Plain Sight For [Blue|Purple] Teams in Cyber Defence · 87d ago Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR) For [Blue|Purple] Teams in Cyber Defence · 87d ago Ukraine identifies infostealer operator tied to 28,000 stolen accounts BleepingComputer · 87d ago Hackers bypass SonicWall VPN MFA due to incomplete patching BleepingComputer · 87d ago GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam) Reverse Engineering · 87d ago safest virtual machine? cybersecurity · 87d ago Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration cybersecurity · 87d ago Meet Rampart and Clarity, Microsoft’s new red team combo AI agents CyberScoop · 87d ago wordpress memberpress hacking: security in practice · 87d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware cybersecurity · 87d ago Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage For [Blue|Purple] Teams in Cyber Defence · 87d ago GitHub notifications cybersecurity · 87d ago The Open Source USB Drive Built for Privacy hacking: security in practice · 87d ago Is there no more privacy left in the world? cybersecurity · 87d ago AI Agents defeat obfuscated JavaScript in 10 minutes Reverse Engineering · 87d ago Microsoft Edge had a password blunder, and it raises a bigger browser trust problem cybersecurity · 87d ago Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network cybersecurity · 87d ago Aconselhamento / mini texto cybersecurity · 87d ago CISA with an absolutely embarrassing data leak. cybersecurity · 87d ago Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys cybersecurity · 87d ago Anyone else feeling like static AppSec workflows are starting to hit limits? cybersecurity · 87d ago Is someone trying to hack me? hacking: security in practice · 87d ago What is it Wednesdays: Episode 0002 Reverse Engineering · 87d ago GitHub breach highlights developer tools as part of attack surface cybersecurity · 87d ago Why do some malware use unique user-agent strings? cybersecurity · 87d ago Encrypted emails bypassing email security tool cybersecurity · 87d ago Grafana breach caused by missed token rotation after TanStack attack BleepingComputer · 87d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era For [Blue|Purple] Teams in Cyber Defence · 87d ago GitHub says internal repositories were impacted in poisoned VS Code extension attack CyberScoop · 87d ago Ctf groups cybersecurity · 87d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era cybersecurity · 87d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era Technical Information Security Content & Discussion · 87d ago cpu backdoor hacking: security in practice · 87d ago CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis Technical Information Security Content & Discussion · 87d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 87d ago Opensource that automatically scans your git repos for breaches cybersecurity · 87d ago 5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready For [Blue|Purple] Teams in Cyber Defence · 87d ago TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post) Reverse Engineering · 87d ago Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing Reverse Engineering · 87d ago Identity Alone Isn't Enough: Why Device Security Has to Share the Load BleepingComputer · 87d ago CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers Technical Information Security Content & Discussion · 87d ago Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online Technical Information Security Content & Discussion · 87d ago CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed. cybersecurity · 87d ago Your developers are deploying agents in your production environment right now. You have no governance for it. cybersecurity · 87d ago Technical analysis of CVE-2026-34472 in ZTE H188A router firmware hacking: security in practice · 87d ago ¿Como me preparo para EC-Council CSA? cybersecurity · 87d ago The IBM X-Force Index 2026 explains all three in one finding. cybersecurity · 87d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 87d ago Securing iPad's question cybersecurity · 87d ago Cybersecurity 101 cybersecurity · 87d ago What would this job role be? cybersecurity · 87d ago Drupal critical update to fix bug with high exploitation risk BleepingComputer · 87d ago MSPs & MSSPs suck cybersecurity · 87d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 87d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog All CISA Advisories · 87d ago [ Removed by Reddit ] cybersecurity · 87d ago GitHub hit by a compromised VSCode extension Technical Information Security Content & Discussion · 87d ago Crossroads cybersecurity · 87d ago Advice regarding "SOC" job that automates everything cybersecurity · 87d ago Is this Medium article about "NetMirror" malware legit? cybersecurity · 87d ago AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon? cybersecurity · 87d ago Developer tooling is part of the attack surface before a project is even run cybersecurity · 87d ago Exploit released for new PinTheft Arch Linux root escalation flaw BleepingComputer · 87d ago How to build .NET obfuscator Reverse Engineering · 87d ago botguard-token-generator / a google botguard token gen using only requests...? Reverse Engineering · 87d ago Remote Process Read Primitive via NtCreateThreadEx Exit Code For [Blue|Purple] Teams in Cyber Defence · 87d ago GUEST ESSAY: AI can speed up communication, but it can also weaken human connection The Last Watchdog · 87d ago How the hell do you manage developers, their code, their apps? cybersecurity · 87d ago Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed cybersecurity · 87d ago aimap: Discover Exposed AI Services For [Blue|Purple] Teams in Cyber Defence · 87d ago FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation. For [Blue|Purple] Teams in Cyber Defence · 87d ago Ongoing development hacking: security in practice · 87d ago Webworm: New burrowing techniques WeLiveSecurity · 87d ago Why China Is Now a Peer Competitor to the United States in Cyberspace For [Blue|Purple] Teams in Cyber Defence · 87d ago When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax Technical Information Security Content & Discussion · 87d ago Do people still rely on antivirus software in 2026, or is built-in security enough now? cybersecurity · 87d ago For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks? hacking: security in practice · 87d ago GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories cybersecurity · 87d ago GitHub confirms breach of 3,800 repos via malicious VSCode extension BleepingComputer · 87d ago Automatic CLI for spinning up vulnerable labs + objectives cybersecurity · 88d ago Hackers found a way around Intel CET—PLaTypus locks down library jumps hacking: security in practice · 88d ago ISO/IEC 27701 scenario question cybersecurity · 88d ago Discord rolls out end-to-end encryption on voice, video calls cybersecurity · 88d ago Microsoft shares mitigation for YellowKey Windows zero-day BleepingComputer · 88d ago nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings For [Blue|Purple] Teams in Cyber Defence · 88d ago GitHub investigates internal repositories breach claimed by TeamPCP cybersecurity · 88d ago Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt For [Blue|Purple] Teams in Cyber Defence · 88d ago We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. For [Blue|Purple] Teams in Cyber Defence · 88d ago Two AI-based science assistants succeed with drug-retargeting tasks cybersecurity · 88d ago GitHub investigates internal repositories breach claimed by TeamPCP hacking: security in practice · 88d ago Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings) For [Blue|Purple] Teams in Cyber Defence · 88d ago America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames cybersecurity · 88d ago An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now. cybersecurity · 88d ago We audited 12K n8n templates: most have critical vulnerabilities Technical Information Security Content & Discussion · 88d ago GitHub investigates internal repositories breach claimed by TeamPCP BleepingComputer · 88d ago Veilgate - Deception proxy Technical Information Security Content & Discussion · 88d ago Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild For [Blue|Purple] Teams in Cyber Defence · 88d ago New to cybersecurity cybersecurity · 88d ago Anyone interview or work with Moxfive? cybersecurity · 88d ago A stealth Firefox version that passes all anti-bot and CAPTCHA cybersecurity · 88d ago mkPIVM - a polymorphic position-independent shellcode virtualizer cybersecurity · 88d ago Started in IT and need a Cybersecurity Roadmap with my Useless Degree! cybersecurity · 88d ago GitHub announces internal data breached. cybersecurity · 88d ago Roadmap to Cybersecurity roles cybersecurity · 88d ago Hackers: What age did you start? Where did you start, especially in practicing your skills? hacking: security in practice · 88d ago CISA credential leak raises alarms, and Capitol Hill demands answers CyberScoop · 88d ago Malware installed without literally doing anything? cybersecurity · 88d ago Max-severity flaw in ChromaDB for AI apps allows server hijacking BleepingComputer · 88d ago CTFs cybersecurity · 88d ago Can't access anything Malware Analysis & Reports · 88d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware BleepingComputer · 88d ago How to watch a private video on Youtube? hacking: security in practice · 88d ago Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches CyberScoop · 88d ago Sleeping Agent: Silent persistent C2 through Web Push Technical Information Security Content & Discussion · 88d ago Crossroads cybersecurity · 88d ago Discord rolls out end-to-end encryption on voice, video calls BleepingComputer · 88d ago Canara Bank SuRaksha Cyber Hackathon 2.0, cybersecurity · 88d ago Eight Leading U.S. Communications Firms Form C2 ISAC For [Blue|Purple] Teams in Cyber Defence · 88d ago Can I do anything cool with this network controller? hacking: security in practice · 88d ago News alert: Orchid Security study finds invisible identities now outnumber managed accounts The Last Watchdog · 88d ago Anti BOT Tipps und Tricks gesucht. cybersecurity · 88d ago FBI: Americans lost over $388 million to scams using crypto ATMs in 2025 BleepingComputer · 88d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security cybersecurity · 88d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 88d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security Technical Information Security Content & Discussion · 88d ago New to Cybersecurity cybersecurity · 88d ago Microsoft Self-Service Password Reset abused in Azure data theft attacks BleepingComputer · 88d ago Micro controller safety? hacking: security in practice · 88d ago Is the ISC2 Certified in Cybersecurity worth it? cybersecurity · 88d ago Average Days to Close by Source CNAPP Severity Tag 2026 cybersecurity · 88d ago I want free nmap resource cybersecurity · 88d ago If I clear browser history regularly, does it reduce the chances of malware that target browser data? cybersecurity · 88d ago What is next after 1.5 Year as Security Analyst? cybersecurity · 88d ago Analysis advice cybersecurity · 88d ago Stop me if you heard this one before... (YellowKey related) cybersecurity · 88d ago UAC-0184: From HTA to a Signed Network Stack For [Blue|Purple] Teams in Cyber Defence · 88d ago Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe? cybersecurity · 88d ago Microsoft plans to improve Windows 11 driver quality in 2026 BleepingComputer · 88d ago Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing) Reverse Engineering · 88d ago Looking for advice: where should I post/publish CVE write-ups? cybersecurity · 88d ago Microsoft blames macOS update for undismissible Teams location prompts BleepingComputer · 88d ago CISA Admin Leaked AWS GovCloud Keys on Github hacking: security in practice · 88d ago New GMKtec M7 Ultra appears to be infected. Beware of the malware! Malware Analysis & Reports · 88d ago Cybersecurity statistics of the week (May 11th - May 17th) cybersecurity · 88d ago How can I test my website locally for cybersecurity? cybersecurity · 88d ago Mini Shai-Hulud returns, compromising hundreds of npm packages CyberScoop · 88d ago Use of coding in security operations cybersecurity · 88d ago Decompilation of DSP Code using IDA Pro hacking: security in practice · 88d ago Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz cybersecurity · 88d ago Microsoft disrupts cybercrime service that abused software verification systems en masse cybersecurity · 88d ago I've built an open source honeypot probe database accessible via curl, http and mcp cybersecurity · 88d ago New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here For [Blue|Purple] Teams in Cyber Defence · 88d ago Deep dive into the object creation flow in Windows - PART 4: Handle table internals. Reverse Engineering · 88d ago 6,000+ Automatic Tank Gauges Exposed With No Authentication cybersecurity · 88d ago Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email? cybersecurity · 88d ago How Storm-2949 turned a compromised identity into a cloud-wide breach For [Blue|Purple] Teams in Cyber Defence · 88d ago Microsoft disrupts cybercrime service that abused software verification systems en masse CyberScoop · 88d ago How Storm-2949 turned a compromised identity into a cloud-wide breach Technical Information Security Content & Discussion · 88d ago If humans are the weakest link, why won't companies evolve? cybersecurity · 88d ago Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?" cybersecurity · 88d ago New Shai-Hulud malware wave compromises 600 npm packages BleepingComputer · 88d ago 7-Eleven confirms data breach claimed by the ShinyHunters gang BleepingComputer · 88d ago Entra ID: PIM for Groups Review For [Blue|Purple] Teams in Cyber Defence · 88d ago Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation BleepingComputer · 88d ago Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM cybersecurity · 88d ago Local transcription vs cloud transcription, which actually feels safer? cybersecurity · 88d ago Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today? cybersecurity · 88d ago Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise cybersecurity · 88d ago TeamPCP compromises NPM maintainer with over 540 packages For [Blue|Purple] Teams in Cyber Defence · 88d ago Shai-Hulud source leak is turning npm malware into a copycat problem cybersecurity · 88d ago Webinar: The hidden bottlenecks in network incident response BleepingComputer · 88d ago Framework for Preventing Secret Ideas from Leakage cybersecurity · 88d ago Kieback & Peter DDC Building Controllers All CISA Advisories · 88d ago Siemens RUGGEDCOM APE1808 Devices All CISA Advisories · 88d ago ABB CoreSense HM and CoreSense M10 All CISA Advisories · 88d ago ScadaBR All CISA Advisories · 88d ago ZKTeco CCTV Cameras All CISA Advisories · 88d ago Local LLM for building AI Security platform cybersecurity · 88d ago SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access cybersecurity · 88d ago Emerging Cyber security niches cybersecurity · 88d ago ISO/IEC 27701 cybersecurity · 88d ago Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware Reverse Engineering · 88d ago Solo dev building a terminal-heavy hacking game inspired by corporate security cybersecurity · 88d ago Microsoft confirms patching issues in restricted Windows networks BleepingComputer · 88d ago Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations cybersecurity · 88d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments Technical Information Security Content & Discussion · 88d ago CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing Technical Information Security Content & Discussion · 88d ago CS/IT Student Looking to Grow My LinkedIn Network 😃 cybersecurity · 88d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) hacking: security in practice · 88d ago Open-source Hermes bytecode decompiler for React Native apps (Rust) Reverse Engineering · 88d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) cybersecurity · 88d ago Is Amazon Cognito a good choice long term? Alternatives? cybersecurity · 88d ago Was hacking easier in the 80s and 90s and early 2000s? cybersecurity · 88d ago Need some Advice in SOAR heavy environment cybersecurity · 88d ago Trying to find serious builders in cybersecurity - not just “let’s build” conversations cybersecurity · 88d ago Hermes bytecode decompiler (Rust) - sharing my friend’s project Reverse Engineering · 88d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields hacking: security in practice · 88d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields Technical Information Security Content & Discussion · 88d ago Active Supply Chain Attack Compromises @antv Packages on npm... For [Blue|Purple] Teams in Cyber Defence · 88d ago AI Phishing cybersecurity · 88d ago The quest for greater tech independence WeLiveSecurity · 88d ago One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals cybersecurity · 88d ago When DMCA Comes Knocking - A YouTube Creator Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 89d ago [Cloudflare] Project Glasswing: what Mythos showed us For [Blue|Purple] Teams in Cyber Defence · 89d ago vpn explained the simple version that actually makes sense Malware Analysis & Reports · 89d ago How easy is it to get into the cyber security field? cybersecurity · 89d ago Forza Designer 6 Reverse Engineering · 89d ago 314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js cybersecurity · 89d ago Built a full disassembler & decompiler for Reverse Engineering | Free and open source. hacking: security in practice · 89d ago Built a full disassembler & decompiler | Free and open source. Reverse Engineering · 89d ago Slopinator - a poisoned GitHub repository generator hacking: security in practice · 89d ago Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start? cybersecurity · 89d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) Technical Information Security Content & Discussion · 89d ago ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo cybersecurity · 89d ago CEH/CPENT vs OSCP vs GPEN cybersecurity · 89d ago ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro” cybersecurity · 89d ago CISA Contractor Admin Leaked AWS GovCloud Keys on Github cybersecurity · 89d ago Made a shell greeter that generates a unique rocket every time you open a terminal tab hacking: security in practice · 89d ago Suspecious activity in my account cybersecurity · 89d ago Is it safe to use my first name and middle name on platforms? cybersecurity · 89d ago Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice. cybersecurity · 89d ago Just received an email from shinyhunters about their amtrack hack cybersecurity · 89d ago Just received an email from shinyhackers about their amtrack hack hacking: security in practice · 89d ago Flipper Zero (or Alternatives)? hacking: security in practice · 89d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access cybersecurity · 89d ago INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers BleepingComputer · 89d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access hacking: security in practice · 89d ago SHub macOS infostealer variant spoofs Apple security updates BleepingComputer · 89d ago Bywaf: an auditable Python commandlet framework for chained pentest workflows cybersecurity · 89d ago For anyone currently working in a SOC: cybersecurity · 89d ago Fellow Tier 1 SOC/Security Analysts - What does your day to day look like? cybersecurity · 89d ago The quiet death of behavioral anti-bot and the pivot to hardware ZKPs Technical Information Security Content & Discussion · 89d ago SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain For [Blue|Purple] Teams in Cyber Defence · 89d ago AI might cut false positives, but it won’t stop the slop CyberScoop · 89d ago Recent WhatsApp hacks hacking: security in practice · 89d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 89d ago How do you threat hunt for RMM tools in environments where RMM is all over the place? cybersecurity · 89d ago Decompilation projects and N64 Recompiled PC ports (May 2026) Reverse Engineering · 89d ago Microsoft - "your single use code" email when it was not requested by yourself cybersecurity · 89d ago Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa CyberScoop · 89d ago Directory of vendor security questionnaires cybersecurity · 89d ago Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised cybersecurity · 89d ago I wrote an async scanner that runs about 9x faster than nmap for discovery. hacking: security in practice · 89d ago 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees BleepingComputer · 89d ago MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals cybersecurity · 89d ago AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems Technical Information Security Content & Discussion · 89d ago Glass - A fast and free interactive disassembler Reverse Engineering · 89d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. Technical Information Security Content & Discussion · 89d ago Leaked Shai-Hulud malware fuels new npm infostealer campaign BleepingComputer · 89d ago Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers hacking: security in practice · 89d ago Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight cybersecurity · 89d ago Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger For [Blue|Purple] Teams in Cyber Defence · 89d ago Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics For [Blue|Purple] Teams in Cyber Defence · 89d ago How is AI affecting the cybersecurity market? cybersecurity · 89d ago MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack The Last Watchdog · 89d ago MCP security cybersecurity · 89d ago YellowKey Mitigation cybersecurity · 89d ago CrystalX: unpacking a Go RAT through three encrypted layers For [Blue|Purple] Teams in Cyber Defence · 89d ago Anyone else on the receiving end of ShinyHunters extortion email? cybersecurity · 89d ago Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs cybersecurity · 89d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Reverse Engineering · 89d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Malware Analysis & Reports · 89d ago Grafana says stolen GitHub token let hackers steal codebase BleepingComputer · 89d ago What’s the biggest mistake people still make about online security in 2026? cybersecurity · 89d ago Anthropic shuts the EU out of its most advanced cyber AI model cybersecurity · 89d ago Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens] cybersecurity · 89d ago Best hotel for attending all three conferences in Vegas? cybersecurity · 89d ago What's your company's actual PQC migration plan? Not the one on paper - the real one. cybersecurity · 89d ago The down fall of bug bounties Technical Information Security Content & Discussion · 89d ago The Boring Stuff is Dangerous Now darkreading · 89d ago Does buying local cybersecurity (services/products/etc) matter to you? cybersecurity · 89d ago LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose cybersecurity · 89d ago Detection Engineering AI Maturity Framework cybersecurity · 89d ago Microsoft code cybersecurity · 89d ago TanStack Supply Chain Attack (And How to Lock Down GitHub Actions) Technical Information Security Content & Discussion · 89d ago Microsoft testing adjustable taskbar, Start menu in Windows 11 BleepingComputer · 89d ago Microsoft confirms Windows 11 security update install issues cybersecurity · 89d ago Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ cybersecurity · 89d ago Exploit available for new DirtyDecrypt Linux root escalation flaw cybersecurity · 89d ago Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware cybersecurity · 89d ago Suspicious with a company offer letter cybersecurity · 89d ago The Canvas breach proved that prevention is no longer enough CyberScoop · 89d ago Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first? cybersecurity · 89d ago Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation Technical Information Security Content & Discussion · 89d ago Microsoft confirms Windows 11 security update install issues BleepingComputer · 89d ago Why do some recovery workflows still require full wallet uploads? cybersecurity · 89d ago Netmirror exposed - The Free Movie App That Was Robbing You Blind Malware Analysis & Reports · 90d ago Need help with interview for soc l1 cybersecurity · 90d ago Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap) cybersecurity · 90d ago HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try! Reverse Engineering · 90d ago Exploit available for new DirtyDecrypt Linux root escalation flaw BleepingComputer · 90d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 90d ago Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation Technical Information Security Content & Discussion · 90d ago Reverse engineering no dep x64 masm AI IDE Reverse Engineering · 90d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released cybersecurity · 90d ago carrer path in cybersecurity for a btech stud cybersecurity · 90d ago Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026 BleepingComputer · 90d ago Agents usage in production cybersecurity · 90d ago ‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K cybersecurity · 90d ago Former CISA nominee Sean Plankey named US CEO of defense startup CyberScoop · 90d ago Are teams still finding AI API keys in public repos? cybersecurity · 90d ago Can Laws Stop Deepfakes? South Korea Aims to Find Out darkreading · 90d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 90d ago Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here? cybersecurity · 90d ago Does the CBP bug phones? cybersecurity · 90d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released BleepingComputer · 90d ago What We Learned Building Runtime Visibility for Modern Telco Networks cybersecurity · 90d ago Ive got my Spotify account hacked! How do I solve this? cybersecurity · 90d ago The Politics of AI Transparency cybersecurity · 90d ago A million baby monitors and security cameras were easily viewable by hackers cybersecurity · 90d ago NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE cybersecurity · 90d ago Does anyone know if this file is still accessible to download? hacking: security in practice · 90d ago Is cybersecurity becoming more behavioral than technical? cybersecurity · 90d ago Questions About Promo Items for a Cybersecurity Conference cybersecurity · 90d ago DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write For [Blue|Purple] Teams in Cyber Defence · 90d ago Dois-je m'inquiéter ? cybersecurity · 90d ago I am dying to work abroad , rate my journey so far cybersecurity · 90d ago FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation For [Blue|Purple] Teams in Cyber Defence · 90d ago Microsoft - "Your single use code" email when it was not requested cybersecurity · 90d ago Security / Compliance work going Agentic? cybersecurity · 90d ago High school students organized a Jeopardy CTF competition - give it a try hacking: security in practice · 90d ago Don't believe the media, specially in cybersec cybersecurity · 90d ago Microsoft account keeps getting Authenticator requests? cybersecurity · 90d ago [Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated. cybersecurity · 90d ago Ansible security and compliance guide Technical Information Security Content & Discussion · 90d ago Malware learning Malware Analysis & Reports · 90d ago Struggling to generate security bulletins — any ideas? cybersecurity · 90d ago Certs to go into Security Engineer/architect cybersecurity · 90d ago 18882745552 beware of email with this number cybersecurity · 90d ago Transition from traditional penetration testing into AI security cybersecurity · 90d ago Seeking advice on next career steps cybersecurity · 90d ago Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing BleepingComputer · 90d ago Official Miasma Poison Tar Pit Docker Image Now Available hacking: security in practice · 90d ago Will the analyst role become obsolete? cybersecurity · 90d ago LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying" For [Blue|Purple] Teams in Cyber Defence · 90d ago Alert Fatigue cybersecurity · 90d ago Best path into cybersecurity for a high schooler? cybersecurity · 90d ago Static Kitten APT Adversary Simulation For [Blue|Purple] Teams in Cyber Defence · 90d ago Why Is Cybersecurity Now A Business Priority, Not Just An IT Function? Cyber Defense Magazine · 90d ago Keep getting hacked cybersecurity · 90d ago Eimeria: five layers from RAR5 to RunPE For [Blue|Purple] Teams in Cyber Defence · 90d ago ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only. For [Blue|Purple] Teams in Cyber Defence · 90d ago Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain Technical Information Security Content & Discussion · 90d ago How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices cybersecurity · 90d ago I’m interested in joining the Red Team Hackers Academy in Bangalore. cybersecurity · 90d ago openDCIM exploitation For [Blue|Purple] Teams in Cyber Defence · 90d ago PE packer/crypter with random VM ISA per build Reverse Engineering · 90d ago A clueless teenager 💔 cybersecurity · 90d ago HASBL CTF - A Jeopardy-Style CTF Organized by High School Students! For [Blue|Purple] Teams in Cyber Defence · 90d ago Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start? cybersecurity · 90d ago Am I overthinking Claude Code security or is this actually a risk? cybersecurity · 90d ago is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this cybersecurity · 90d ago ISO/IEC 27701 ( SoA ) Applicability cybersecurity · 90d ago Security Executive Playbook cybersecurity · 90d ago This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon cybersecurity · 90d ago We Have Packet Capture at Home For [Blue|Purple] Teams in Cyber Defence · 90d ago I feel crazy I hope someone has insight . cybersecurity · 91d ago Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware For [Blue|Purple] Teams in Cyber Defence · 91d ago HWMonitor Trojanized for STX RAT DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 91d ago awesome-dfir-skills: Admiralty System for CTI Claude skill For [Blue|Purple] Teams in Cyber Defence · 91d ago Mullvad exit IPs as a fingerprinting vector For [Blue|Purple] Teams in Cyber Defence · 91d ago Does anybody know where I may stumble upon some Sh1mmer bin downloads hacking: security in practice · 91d ago Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools For [Blue|Purple] Teams in Cyber Defence · 91d ago Popular node-ipc npm Package Infected with Credential Steale... For [Blue|Purple] Teams in Cyber Defence · 91d ago An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. For [Blue|Purple] Teams in Cyber Defence · 91d ago Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files For [Blue|Purple] Teams in Cyber Defence · 91d ago Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor For [Blue|Purple] Teams in Cyber Defence · 91d ago Sandworm Activity in Industrial Environments: What the Data Reveals For [Blue|Purple] Teams in Cyber Defence · 91d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 91d ago "Shadowserver-in-a-box" IntelMQ + ELK Solution For [Blue|Purple] Teams in Cyber Defence · 91d ago Stenloader: Steganography Shellcode Loader For [Blue|Purple] Teams in Cyber Defence · 91d ago AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out For [Blue|Purple] Teams in Cyber Defence · 91d ago Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018 For [Blue|Purple] Teams in Cyber Defence · 91d ago Our response to the TanStack npm supply chain attack For [Blue|Purple] Teams in Cyber Defence · 91d ago QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026). For [Blue|Purple] Teams in Cyber Defence · 91d ago We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. For [Blue|Purple] Teams in Cyber Defence · 91d ago APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox. For [Blue|Purple] Teams in Cyber Defence · 91d ago oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday For [Blue|Purple] Teams in Cyber Defence · 91d ago Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations For [Blue|Purple] Teams in Cyber Defence · 91d ago ΡHANTΟΜ Al-Powered Pentesting Command Center cybersecurity · 91d ago Interview Assessments cybersecurity · 91d ago We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it cybersecurity · 91d ago Questions about data blockers cybersecurity · 91d ago A Tale of Two File Names Reverse Engineering · 91d ago PE reconstruction Reverse Engineering · 91d ago OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance For [Blue|Purple] Teams in Cyber Defence · 91d ago Post Implementation task cybersecurity · 91d ago The Gentlemen Ransomware Group — Leak Analysis For [Blue|Purple] Teams in Cyber Defence · 91d ago Mythos, MOAK, CTEM and the End of CVE Chasing cybersecurity · 91d ago Cyber security jobs in Austria cybersecurity · 91d ago Microsoft rejects critical Azure vulnerability report, no CVE issued BleepingComputer · 91d ago Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network hacking: security in practice · 91d ago Personal favorite deception layer. cybersecurity · 91d ago Estudiar Ciberseguridad cybersecurity · 91d ago Learning way cybersecurity · 91d ago A File Format Uncracked for 20 Years: Part 2 Reverse Engineering · 91d ago How do you report large volume detections to a CISO without making the BPA report a SOC story? cybersecurity · 91d ago HDD Firmware Hacking Part 1 For [Blue|Purple] Teams in Cyber Defence · 91d ago Can anyone share bugbase platform screenshot having professional usage on dashboard? cybersecurity · 91d ago ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. For [Blue|Purple] Teams in Cyber Defence · 91d ago CTO at NCSC Summary: week ending May 17th For [Blue|Purple] Teams in Cyber Defence · 91d ago CTO at NCSC Summary: week ending May 17th cybersecurity · 91d ago GZDoom in the browser hacking: security in practice · 91d ago Vidar v1.5 in Go: same family, new language, heavy sandbox checks For [Blue|Purple] Teams in Cyber Defence · 91d ago Developer credential-theft campaign exposed operator-side self-infection For [Blue|Purple] Teams in Cyber Defence · 91d ago Security Executive Playbook cybersecurity · 91d ago Tired of tab-switching between CTI tools - here's what we put together cybersecurity · 91d ago I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor cybersecurity · 91d ago Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source! Reverse Engineering · 91d ago Help-Desk Lures Drop KongTuke's Evolved ModeloRAT For [Blue|Purple] Teams in Cyber Defence · 91d ago Welcome to BlackFile: Inside a Vishing Extortion Operation For [Blue|Purple] Teams in Cyber Defence · 91d ago HackTheBox - Pterodactyl IppSec · 91d ago In Cybersecurity cybersecurity · 91d ago AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize. Technical Information Security Content & Discussion · 91d ago DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era For [Blue|Purple] Teams in Cyber Defence · 91d ago Stop Being Weird — Life After Call Stack Spoofing Under CET For [Blue|Purple] Teams in Cyber Defence · 91d ago Anyone else feel like most MSP tooling is either overkill or painfully manual? cybersecurity · 91d ago Russian hackers turn Kazuar backdoor into modular P2P botnet BleepingComputer · 91d ago Thinkpad vs Macbook pro endpoint security cybersecurity · 91d ago Any more affordable alternatives to “IntelligenceX”? cybersecurity · 91d ago Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran cybersecurity · 91d ago tanstack checker github action cybersecurity · 91d ago Drivers Alpha AWUS036AXML cybersecurity · 91d ago Splunk download for free cybersecurity · 91d ago The Security Mistakes Being Repeated With Ai Cyber Defense Magazine · 91d ago Funnel Builder WordPress plugin bug exploited to steal credit cards cybersecurity · 91d ago Anyone here using pager duty? cybersecurity · 91d ago Scammer targeting posters cybersecurity · 91d ago Anyone know how to bypass these school laptop pins? hacking: security in practice · 91d ago Seeking advice cybersecurity · 91d ago Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works Technical Information Security Content & Discussion · 91d ago Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026) cybersecurity · 91d ago Just got an email about a single use code, maybe someone was trying to log in? cybersecurity · 91d ago Can a background in DevOps enter the cybersecurity field? cybersecurity · 91d ago [CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link. Reverse Engineering · 91d ago Triggering the Secure Boot Certificate Update with Intune Remediations For [Blue|Purple] Teams in Cyber Defence · 91d ago How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache For [Blue|Purple] Teams in Cyber Defence · 91d ago Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 For [Blue|Purple] Teams in Cyber Defence · 91d ago One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 91d ago CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) For [Blue|Purple] Teams in Cyber Defence · 91d ago Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 91d ago FamousSparrow APT Targets Azerbaijani Oil and Gas Industry For [Blue|Purple] Teams in Cyber Defence · 91d ago Disclosing new PebbleDash-based tools by Kimsuky For [Blue|Purple] Teams in Cyber Defence · 91d ago FrostyNeighbor: Fresh mischief and digital shenanigans For [Blue|Purple] Teams in Cyber Defence · 91d ago Kazuar: Anatomy of a nation-state botnet For [Blue|Purple] Teams in Cyber Defence · 91d ago OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments For [Blue|Purple] Teams in Cyber Defence · 91d ago NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys For [Blue|Purple] Teams in Cyber Defence · 91d ago Hacker Ringleader Extradited for 38 Billion Won Theft For [Blue|Purple] Teams in Cyber Defence · 91d ago Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System For [Blue|Purple] Teams in Cyber Defence · 91d ago Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit For [Blue|Purple] Teams in Cyber Defence · 91d ago The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation For [Blue|Purple] Teams in Cyber Defence · 91d ago FFFFirefox - A One-Day Wonder Renderer Exploit For [Blue|Purple] Teams in Cyber Defence · 91d ago MiniPlasma, a powerful LPE For [Blue|Purple] Teams in Cyber Defence · 91d ago Using ai in learning cybersecurity · 91d ago Exploiting Toshiba Qiomem.sys vulnerable driver Reverse Engineering · 91d ago Avanzamento area Blue Team/SOC cybersecurity · 91d ago Please what could be helpful cybersecurity · 92d ago HDD Firmware Hacking Part 1 Reverse Engineering · 92d ago CVE exploit chain cybersecurity · 92d ago What are the widely accepted SaaS security accreditations/audits an app should seek in fintech cybersecurity · 92d ago Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco cybersecurity · 92d ago Region-based binary diff tool for firmware analysis Reverse Engineering · 92d ago Major flaw in Indian Cyber and IT assurance landscape cybersecurity · 92d ago Red Team Ops Ⅱ ( CRTL ) exam preparation cybersecurity · 92d ago Recomendations cybersecurity · 92d ago A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Reverse Engineering · 92d ago Recommended cybersecurity certification for a UX designer new to the domain? cybersecurity · 92d ago แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป! Reverse Engineering · 92d ago insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server cybersecurity · 92d ago Career path cybersecurity · 92d ago Merit America offers a program that gets you into cyber security roles. cybersecurity · 92d ago Brovan — Open-source x86/x64 user-mode binary emulator written in C# Reverse Engineering · 92d ago Brovan: Binary user-mode emulator for x86_64 Reverse Engineering · 92d ago Brovan: Binary user-mode emulator for x86_64 Malware Analysis & Reports · 92d ago Brovan: Binary user-mode emulator for x86_64 cybersecurity · 92d ago AmEx Interview! cybersecurity · 92d ago A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA hacking: security in practice · 92d ago Developer credential-stealing pipeline also collected operator workstations cybersecurity · 92d ago need help building a case. cybersecurity · 92d ago Colorado governor commutes prison sentence for election denier Tina Peters CyberScoop · 92d ago Personal favorite SIEM platform? cybersecurity · 92d ago Cardputer ADV cybersecurity · 92d ago Alternative for Qualys cybersecurity · 92d ago I have a friend who looks like he’s a stalker I’m scared he will know I stalk him hacking: security in practice · 92d ago The 4th Linux kernel flaw this month can lead to stolen SSH host keys cybersecurity · 92d ago Congress Puts Heat on Instructure After Canvas Outage darkreading · 92d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 92d ago Stack Buffer Overflow Explained (Using a Classic Doom Bug) cybersecurity · 92d ago [Tutorial] How to hack DOS games: Reversing Prince of Persia hacking: security in practice · 92d ago Here’s how the FTC plans to enforce the Take It Down Act CyberScoop · 92d ago Understanding Stack Buffer Overflows Through Doom and C++ Reverse Engineering · 92d ago Confused about cybersecurity career cybersecurity · 92d ago Funnel Builder WordPress plugin bug exploited to steal credit cards BleepingComputer · 92d ago What is it Wednesdays: Episode 0001 Reverse Engineering · 92d ago Transferring from pen test consulting to application security? cybersecurity · 92d ago Curso de especializacion de Ciberseguridad cybersecurity · 92d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? For [Blue|Purple] Teams in Cyber Defence · 92d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? cybersecurity · 92d ago Lost, tempted to throw in the towel cybersecurity · 92d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own cybersecurity · 92d ago I open-sourced a Docker security scanner I use to audit all my websites cybersecurity · 92d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own BleepingComputer · 92d ago Testing Deception Technique cybersecurity · 92d ago Popular node-ipc npm package compromised to steal credentials BleepingComputer · 92d ago A malware got into my account and spread spam ad to my friends and relatives cybersecurity · 92d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems Technical Information Security Content & Discussion · 92d ago Avada Builder WordPress plugin flaws allow site credential theft BleepingComputer · 92d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems cybersecurity · 92d ago Most pentest reports I review are padded with garbage findings cybersecurity · 92d ago Is dns spoofing dead?? hacking: security in practice · 92d ago Cyber Essentials and use of third party websites - MFA cybersecurity · 92d ago Rapid 7 and Cisa Kev cybersecurity · 92d ago Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup Reverse Engineering · 92d ago Deepdive into the object creation flow in Windows -PART 2 : access check internals Reverse Engineering · 92d ago Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization Reverse Engineering · 92d ago Microsoft backpedals: Edge to stop loading passwords into memory BleepingComputer · 92d ago Anyone know much about MS Defender? cybersecurity · 92d ago My Privacy Focused USB Drive hacking: security in practice · 92d ago Cisco zero-day under ongoing attack by persistent threat group CyberScoop · 92d ago EN18031 for IoT: struggling to see the big picture — advice from experienced people? cybersecurity · 92d ago Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution BleepingComputer · 92d ago Japan’s 3DS Mandate: One Year In Blog – Forter · 92d ago Automating code security reviews with Claude Mythos-level capabilities Technical Information Security Content & Discussion · 92d ago Automating Code Security Reviews cybersecurity · 92d ago [Tool] IOCX — deterministic static IOC extraction for PE binaries For [Blue|Purple] Teams in Cyber Defence · 92d ago New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available cybersecurity · 92d ago [Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo) Reverse Engineering · 92d ago Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition) hacking: security in practice · 92d ago AI coding tools on developer machines — looking for input on how you're handling it cybersecurity · 92d ago Chrome 148 Update Patches Critical Vulnerabilities cybersecurity · 92d ago The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract Cyber Defense Magazine · 92d ago Microsoft warns of Exchange zero-day flaw exploited in attacks cybersecurity · 92d ago I need help. i am lost cybersecurity · 92d ago Microsoft to automatically roll back faulty Windows drivers BleepingComputer · 92d ago Novel Evilginx Frontend - Lowering the barrier for token theft reuse For [Blue|Purple] Teams in Cyber Defence · 92d ago Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence cybersecurity · 92d ago Cyber Pioneers Ponder Past as Prologue darkreading · 92d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 92d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 92d ago Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments cybersecurity · 92d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? cybersecurity · 92d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? For [Blue|Purple] Teams in Cyber Defence · 92d ago Microsoft warns of Exchange zero-day flaw exploited in attacks BleepingComputer · 92d ago I'm going crazy. At the application level what I can actually do to prevent DDos? cybersecurity · 92d ago yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android. Reverse Engineering · 92d ago Is anyone enrolled in Intellipaat's cybersecurity course? cybersecurity · 92d ago Will AI Replace Cybersecurity Jobs? cybersecurity · 92d ago Why geopolitical turmoil is a gift for scammers, and how to stay safe WeLiveSecurity · 92d ago What's best certification choice after OSWE cybersecurity · 92d ago TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer hacking: security in practice · 92d ago Facebook Page Call Slipping through Sleep mode cybersecurity · 92d ago ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey cybersecurity · 92d ago New Linux LPE allows local users to read any file, including privkeys cybersecurity · 93d ago A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks. cybersecurity · 93d ago Your experience as IT Admin on Alerts cybersecurity · 93d ago Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time cybersecurity · 93d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild cybersecurity · 93d ago GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets Reverse Engineering · 93d ago GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS Reverse Engineering · 93d ago Instrumenting QT6 desktop apps with Frida - Part 1 Technical Information Security Content & Discussion · 93d ago From Vercel Typosquatting to an Obfuscated macOS Malware Loader Technical Information Security Content & Discussion · 93d ago Discord VC lag Exploit cybersecurity · 93d ago FrostyNeighbor: Fresh mischief and digital shenanigans cybersecurity · 93d ago Bug FB - Inicio de sesion por password cybersecurity · 93d ago Does anyone know how to configure EVILGINX for testing cybersecurity · 93d ago Trafexia V2 - Mobile Traffic Interceptor Toolkit Reverse Engineering · 93d ago How long does it take to get familiar with a tool cybersecurity · 93d ago Scam website cybersecurity · 93d ago ANTS Hack: 19 million records exposed in French ID agency breach cybersecurity · 93d ago has anyone used tail os here? hacking: security in practice · 93d ago Is it really that easy to obtain SMS codes using an SS7 attack? cybersecurity · 93d ago AI coding tools are shipping code faster than security can review it. What's your team doing about it cybersecurity · 93d ago Interview for AI security engineer position at a fortune 500 company cybersecurity · 93d ago How’s the job market for Senior AppSec Engineers? How are the interviews? cybersecurity · 93d ago Has anyone read "The Art of Deception"? How does it hold up to now? cybersecurity · 93d ago Run this washer/dryer sans coin? hacking: security in practice · 93d ago WAF Evasion Engine For [Blue|Purple] Teams in Cyber Defence · 93d ago Is metadata protection becoming more important than traditional endpoint security for ordinary users? cybersecurity · 93d ago Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems darkreading · 93d ago Inspecting a DLL file trying to figure out if it really is malware Malware Analysis & Reports · 93d ago Zero trust in hybrid environments - what's actually worked for you cybersecurity · 93d ago Have you encountered issues with CSAF advisories in practice? cybersecurity · 93d ago Zero trust in hybrid environments - what's actually working for you cybersecurity · 93d ago I built an open-source Burp alternative hacking: security in practice · 93d ago TeamPCP hackers advertise Mistral AI code repos for sale BleepingComputer · 93d ago OpenAI confirms security breach in TanStack supply chain attack cybersecurity · 93d ago Bachelors Degree Options cybersecurity · 93d ago HighBoy hacking: security in practice · 93d ago Innovator Spotlight: Klever Compliance Cyber Defense Magazine · 93d ago Thus Spoke…The Gentlemen For [Blue|Purple] Teams in Cyber Defence · 93d ago Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin BleepingComputer · 93d ago Innovator Spotlight: Radware Cyber Defense Magazine · 93d ago SecurityScorecard Snags Driftnet to Level Up Threat Intelligence darkreading · 93d ago npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output Malware Analysis & Reports · 93d ago Pentagon cyber official calls advanced AI ‘revolutionary warfare’ CyberScoop · 93d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild darkreading · 93d ago White House cyber official: identity security matters more than ever in the age of AI CyberScoop · 93d ago Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks BleepingComputer · 93d ago I need help protecting my privacy cybersecurity · 93d ago Free Threat Intellegence cybersecurity · 93d ago What discovery in cybersecurity amazed you the most? cybersecurity · 93d ago OpenAI confirms security breach in TanStack supply chain attack BleepingComputer · 93d ago Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026 BleepingComputer · 93d ago Scholarship for Service cybersecurity · 93d ago Reading Siemens CT raw data hacking: security in practice · 93d ago KQLab - open-source query manager for SOC teams For [Blue|Purple] Teams in Cyber Defence · 93d ago For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons? cybersecurity · 93d ago How I use Hermes agent to turn Patch Tuesday into Windows exploit research hacking: security in practice · 93d ago Another day, another supply chain cybersecurity · 93d ago How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs? cybersecurity · 93d ago Teaching Linux+ & CEH..... cybersecurity · 93d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon cybersecurity · 93d ago How TeamPCP's Python Toolkit Survives a C2 Takedown For [Blue|Purple] Teams in Cyber Defence · 93d ago Innovator Spotlight: JScrambler Cyber Defense Magazine · 93d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon hacking: security in practice · 93d ago SIEM use case development cybersecurity · 93d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Technical Information Security Content & Discussion · 93d ago JFrog vs Mend as Scanners cybersecurity · 93d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 93d ago KQLab - open-source query manager for SOC teams cybersecurity · 93d ago Which Vendors Publish the Best (or Worst) Security Advisories? cybersecurity · 93d ago Tips for a beginner noob that wants to learn hacking: security in practice · 93d ago 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine darkreading · 93d ago Synthetic training data vs. real attack telemetry — does it actually matter? cybersecurity · 93d ago Microsoft AntiSSRF For [Blue|Purple] Teams in Cyber Defence · 93d ago Operative IT-Sicherheit | SIEM & Splunk cybersecurity · 93d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state Technical Information Security Content & Discussion · 93d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state For [Blue|Purple] Teams in Cyber Defence · 93d ago 18-year-old NGINX vulnerability allows DoS, potential RCE BleepingComputer · 93d ago Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight BleepingComputer · 93d ago SOC not for junior level? cybersecurity · 93d ago Major tech manufacturer Foxconn confirms cyberattack hit North American factories CyberScoop · 93d ago Cybersecurity at MSG cybersecurity · 93d ago pii-tools.com reputable? cybersecurity · 93d ago Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise cybersecurity · 93d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 93d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Reverse Engineering · 93d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Malware Analysis & Reports · 93d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Technical Information Security Content & Discussion · 93d ago Contract jobs worth the risk? cybersecurity · 93d ago HackTheBoxAcademy vs LetsDefend vs CyberDefenders cybersecurity · 93d ago Automating code security reviews with Claude: near Mythos-level capabilities at lower cost cybersecurity · 93d ago Making Right Career Decision? cybersecurity · 93d ago AI Drives Cybersecurity Investments, Widening 'Valley of Death' darkreading · 93d ago I tried using apparmor (linux security) but it doesn't seem to work very well cybersecurity · 93d ago Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything! cybersecurity · 93d ago Struggling to Stay Up to Date With Vulnerabilities cybersecurity · 93d ago CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure Technical Information Security Content & Discussion · 93d ago How to Check Computer Activity: 2026 Guide for Windows and Mac Technical Information Security Content & Discussion · 93d ago Strix — first public beta of the spiritual successor to cSploit/dSploit hacking: security in practice · 93d ago KongTuke hackers now use Microsoft Teams for corporate breaches BleepingComputer · 93d ago How fast is autonomous AI cyber capability advancing? For [Blue|Purple] Teams in Cyber Defence · 93d ago Foxconn Attack Highlights Manufacturing's Cyber Crisis darkreading · 93d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 93d ago Siemens Siemens ROS# All CISA Advisories · 93d ago Siemens gWAP All CISA Advisories · 93d ago Siemens SIMATIC All CISA Advisories · 93d ago Siemens Ruggedcom Rox All CISA Advisories · 93d ago Siemens Ruggedcom Rox All CISA Advisories · 93d ago Siemens Simcenter Femap All CISA Advisories · 93d ago Universal Robots Polyscope 5 All CISA Advisories · 93d ago Siemens Ruggedcom Rox All CISA Advisories · 93d ago Siemens Teamcenter All CISA Advisories · 93d ago Siemens Solid Edge All CISA Advisories · 93d ago Siemens SENTRON 7KT PAC1261 Data Manager All CISA Advisories · 93d ago Siemens Opcenter RDnL All CISA Advisories · 93d ago Siemens Ruggedcom Rox All CISA Advisories · 93d ago Siemens SIMATIC S7 PLC Web Server All CISA Advisories · 93d ago Siemens Industrial Devices All CISA Advisories · 93d ago Siemens SIMATIC All CISA Advisories · 93d ago Siemens SIPROTEC 5 All CISA Advisories · 93d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 93d ago How to Transfer files Safely from a Compromised (work) Device cybersecurity · 93d ago Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward cybersecurity · 93d ago Multiple data breaches in one week cybersecurity · 93d ago Whatsapp hacking: security in practice · 93d ago How are small security teams handling vulnerability overload now? cybersecurity · 93d ago Concerns mount that EU will demand age verification for VPNs cybersecurity · 93d ago Automating code security reviews: Claude Mythos-level capabilities with lower cost cybersecurity · 93d ago The Rare Patch: A Digital Sovereignty Challenge cybersecurity · 93d ago Advise cybersecurity · 93d ago CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC Technical Information Security Content & Discussion · 93d ago Face ID bypass with avatar hacking: security in practice · 93d ago GRC cybersecurity · 93d ago Dell confirms its SupportAssist software causes Windows BSOD crashes BleepingComputer · 93d ago Admins and Engineers cybersecurity · 93d ago Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark cybersecurity · 93d ago Ghidra 12.1 has been released! Reverse Engineering · 93d ago Prompt injection in browser coding agents is the threat model nobody is ready for cybersecurity · 93d ago US charges suspected Dream Market admin arrested in Germany BleepingComputer · 93d ago FrostyNeighbor: Fresh mischief and digital shenanigans WeLiveSecurity · 93d ago New Fragnesia Linux flaw lets attackers gain root privileges cybersecurity · 93d ago New Fragnesia Linux flaw lets attackers gain root privileges BleepingComputer · 94d ago Transition from MSP to Network Engineering? cybersecurity · 94d ago YellowKey: YellowKey Bitlocker Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 94d ago Reverse Engineering Slither.io’s Network Protocol Reverse Engineering · 94d ago So called “off grid” method cybersecurity · 94d ago Convince me I’m not paranoid: a unique hacking situation. cybersecurity · 94d ago Hunting the Behavior Behind npm Supply Chain Attacks cybersecurity · 94d ago Hunting the Behavior Behind npm Supply Chain Attacks hacking: security in practice · 94d ago Question for AppSec Members cybersecurity · 94d ago Hunting the Behavior Behind npm Supply Chain Attacks Technical Information Security Content & Discussion · 94d ago Beginners guide to Google Dorks by Heisenberg cybersecurity · 94d ago I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable... Malware Analysis & Reports · 94d ago Alguém sabe algo sobre raven eye technology cybersecurity · 94d ago Gophish Porject - Requirement cybersecurity · 94d ago Security Team Won’t Assess Risk cybersecurity · 94d ago Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework cybersecurity · 94d ago Microsoft’s new multi-model agentic security system tops leading industry benchmark cybersecurity · 94d ago Proxmark5 Day 3 Update - $357K+ funded (715% of goal) hacking: security in practice · 94d ago Researchers say AI just broke every benchmark for autonomous cyber capability CyberScoop · 94d ago Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents cybersecurity · 94d ago West Pharmaceutical says hackers stole data, encrypted systems BleepingComputer · 94d ago Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks CyberScoop · 94d ago Overwhelmed on how to enter the job market. cybersecurity · 94d ago Iranian hackers targeted major South Korean electronics maker BleepingComputer · 94d ago Social media scam bill targets tech giants as New Yorkers lose billions cybersecurity · 94d ago What are the biggest technical & cultural hurdles you’re facing right now? cybersecurity · 94d ago CISSP / CCSP training - Experienced engineer cybersecurity · 94d ago WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers Technical Information Security Content & Discussion · 94d ago I Reverse-engineering Need for Speed Underground 2 Server Reverse Engineering · 94d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 94d ago Checkbox Assessments Aren't Fit to Measure Risk darkreading · 94d ago Attackers Weaponize RubyGems for Data Dead Drops darkreading · 94d ago Innovators Spotlight: OPSWAT Cyber Defense Magazine · 94d ago Vulnerability in Canvas/Instructure Support Tickets had part in breach? cybersecurity · 94d ago Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak darkreading · 94d ago Are There Really Ethical Hackers? I've Yet To Meet One hacking: security in practice · 94d ago Tinker Tailor Soldier: Paper Werewolf’s latest toolkit For [Blue|Purple] Teams in Cyber Defence · 94d ago On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract Technical Information Security Content & Discussion · 94d ago New critical Exim mailer flaw allows remote code execution BleepingComputer · 94d ago /sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple Technical Information Security Content & Discussion · 94d ago Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out Technical Information Security Content & Discussion · 94d ago 126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies For [Blue|Purple] Teams in Cyber Defence · 94d ago DOJ releases legal rationale for nationwide voter data collection CyberScoop · 94d ago is malwarefox legit? cybersecurity · 94d ago what lab to learn zero trust? cybersecurity · 94d ago Anyone else got a bunch of emails leaked by Samsung? cybersecurity · 94d ago Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape darkreading · 94d ago This is what some the world's largest banks of malware look like stacked as hard drives cybersecurity · 94d ago I need feedback on my project please cybersecurity · 94d ago would like to understand the role of "Cyber Insurance UnderWriters" cybersecurity · 94d ago Weaponized AI: The new frontier of fraud and identity spoofing CyberScoop · 94d ago clens.io - new public threat & data intel service Malware Analysis & Reports · 94d ago Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad For [Blue|Purple] Teams in Cyber Defence · 94d ago Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise For [Blue|Purple] Teams in Cyber Defence · 94d ago I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included Reverse Engineering · 94d ago Free on-device tool for monitoring AI traffic on macOS — visibility before policy cybersecurity · 94d ago Is secure evidence handling and controlled derivative file sharing needed? cybersecurity · 94d ago Will Adding Some Certifications Help Me in the Job Market? cybersecurity · 94d ago Linux driver posted for Intel Silicon Security Engine Interface "ISSEI" cybersecurity · 94d ago Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified? cybersecurity · 94d ago Fragnesia made public as latest Linux local privilege escalation vulnerability cybersecurity · 94d ago HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity? cybersecurity · 94d ago trying to learn patching hacking: security in practice · 94d ago NIST is surrendering to the amount of CVEs coming in cybersecurity · 94d ago Windows BitLocker zero-day gives access to protected drives, PoC released BleepingComputer · 94d ago [HOMELAB] Built a SOC investigation console on two old Dell boxes For [Blue|Purple] Teams in Cyber Defence · 94d ago Military Veteran looking to get into the Cyber Field cybersecurity · 94d ago Android Intrusion Logging as a new source of data for consensual forensic analysis For [Blue|Purple] Teams in Cyber Defence · 94d ago Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor cybersecurity · 94d ago Granny’s Compromised Android Firmware Malware Analysis & Reports · 94d ago On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study) Technical Information Security Content & Discussion · 94d ago Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook. cybersecurity · 94d ago Webinar tomorrow: Why security alone won't stop modern attacks BleepingComputer · 94d ago Microsoft fixes BitLocker recovery issue only for Windows 11 users BleepingComputer · 94d ago Shai-Hulud: Another Wave and Going Open Source For [Blue|Purple] Teams in Cyber Defence · 94d ago Cve apis for a database cybersecurity · 94d ago Empresas de Cyberseguridad en Mexico (Reacciones) cybersecurity · 94d ago Joined a new company: GRC landscape advice cybersecurity · 94d ago Removing admin rights cybersecurity · 94d ago a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access cybersecurity · 94d ago A stealth approach to Process Injection - EntryPoint Hijacking For [Blue|Purple] Teams in Cyber Defence · 94d ago A stealth approach to Process Injection - EntryPoint Hijacking Technical Information Security Content & Discussion · 94d ago FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow cybersecurity · 94d ago Golden years for cyber security about to start? cybersecurity · 94d ago A stealth approach to Process Injection - EntryPoint Hijacking cybersecurity · 94d ago Microsoft fixes Windows Autopatch bug installing restricted drivers BleepingComputer · 94d ago Detecting CopyFail and DirtyFrag by thinking outside the box cybersecurity · 94d ago Daybreak is OpenAI’s answer to the AI arms race in cybersecurity CyberScoop · 94d ago Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security cybersecurity · 94d ago The Board Is Asking The Wrong Security Question Cyber Defense Magazine · 94d ago LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly darkreading · 94d ago China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm darkreading · 94d ago Foxconn confirms cyberattack claimed by Nitrogen ransomware gang BleepingComputer · 94d ago Career advice cybersecurity · 94d ago 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation BleepingComputer · 94d ago LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back The Last Watchdog · 94d ago Microsoft says some users can't install Office on Windows 365 devices BleepingComputer · 94d ago A year of Apple Security Bounty research — 16 closed findings, full disclosure Technical Information Security Content & Discussion · 94d ago [Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) Malware Analysis & Reports · 94d ago The exponential rise of economic damage caused by cyber-crime continues cybersecurity · 94d ago [Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features Reverse Engineering · 94d ago Today's cybersecurity systems are not ready for AI cybersecurity · 94d ago Are certifications worth it, or do practical skills matter more? cybersecurity · 94d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) cybersecurity · 94d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) For [Blue|Purple] Teams in Cyber Defence · 94d ago Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed cybersecurity · 94d ago Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft cybersecurity · 94d ago What to do after security+ cybersecurity · 94d ago AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data cybersecurity · 94d ago AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods Technical Information Security Content & Discussion · 94d ago LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer] Reverse Engineering · 94d ago Service Principal Sign-Ins: A blind spot that a lot are missing For [Blue|Purple] Teams in Cyber Defence · 95d ago Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub cybersecurity · 95d ago Is it realistic to move from Tech Risk/GRC into technical cybersecurity? cybersecurity · 95d ago My Analysis of a Bandook RAT PCAP For [Blue|Purple] Teams in Cyber Defence · 95d ago Are IPhone autofill passwords safe to use? cybersecurity · 95d ago Access approvals happen over Slack dm and I don't know how to present that to an auditor cybersecurity · 95d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 95d ago China is going dark to develop its own Mythos, German cyber chief fears cybersecurity · 95d ago Is prompt injection a real problem for you? cybersecurity · 95d ago New Exim BDAT bug shows why “just patch the mail server” is still not simple cybersecurity · 95d ago Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach cybersecurity · 95d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 95d ago Cybersecurity guide cybersecurity · 95d ago [Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ? cybersecurity · 95d ago How you guys rate Google Cyber security course and certificate out of 10 !? cybersecurity · 95d ago Detection Rule is here For [Blue|Purple] Teams in Cyber Defence · 95d ago Cyebrsecurity Startup Advice cybersecurity · 95d ago Can anyone give a real world based AI based attack? cybersecurity · 95d ago r2garlic - The world's fastest Android/DEX decompiler meets radare2! Reverse Engineering · 95d ago How worried should we be about AI powered cyberattacks? cybersecurity · 95d ago Built STIS-ICS — an open ICS/OT security learning project cybersecurity · 95d ago OS scanner that checks repos for traces of the Shai Hulud worm Malware Analysis & Reports · 95d ago OS scanner that checks repos for traces of the Shai Hulud worm cybersecurity · 95d ago US govt seeks Instructure testimony on massive Canvas cyberattack BleepingComputer · 95d ago Foxconn Ransomware Attack Shows Nothing Is Safe Forever cybersecurity · 95d ago Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries cybersecurity · 95d ago Cellphone IP address spoofing. hacking: security in practice · 95d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu cybersecurity · 95d ago Explorer shows random letter/number filenames before copying my actual files — normal behavior? cybersecurity · 95d ago ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack CyberScoop · 95d ago Zscaler AI Security Capabilities ? cybersecurity · 95d ago Major world economies spell out key elements of AI ‘ingredients list’ CyberScoop · 95d ago It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight darkreading · 95d ago Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical CyberScoop · 95d ago Cybersecurity degree cybersecurity · 95d ago Owning a service principal equals owning its permissions. For [Blue|Purple] Teams in Cyber Defence · 95d ago Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma cybersecurity · 95d ago Cyber security cybersecurity · 95d ago New York Senate takes on junk fees, digital subscriptions, surveillance pricing cybersecurity · 95d ago UK fines water supplier $1.3M for exposing data of 664k customers BleepingComputer · 95d ago Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection For [Blue|Purple] Teams in Cyber Defence · 95d ago Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI Malware Analysis & Reports · 95d ago Webinar: Fixing the gaps in network incident response BleepingComputer · 95d ago Signal adds security warnings for social engineering, phishing attacks BleepingComputer · 95d ago CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level. For [Blue|Purple] Teams in Cyber Defence · 95d ago Cybersecurity statistics of the week (May 4th - May 10th) cybersecurity · 95d ago Feels like AI changed the speed of attacks more than most companies want to admit cybersecurity · 95d ago Microsoft releases Windows 10 KB5087544 extended security update BleepingComputer · 95d ago Anyone used Kasm or ReplicaCyber? cybersecurity · 95d ago Škoda warns of customer data breach after online shop hack cybersecurity · 95d ago Google launches new Android security feature to help uncover spyware attacks cybersecurity · 95d ago Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator BleepingComputer · 95d ago Windows 11 KB5089549 & KB5087420 cumulative updates released BleepingComputer · 95d ago Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days BleepingComputer · 95d ago Fancy Bear: Stealing Credentials Invisibly cybersecurity · 95d ago Nightmare Eclipse has published Greenplasma and YellowKey cybersecurity · 95d ago Copilot Agent cybersecurity · 95d ago Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim Technical Information Security Content & Discussion · 95d ago The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop Technical Information Security Content & Discussion · 95d ago What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles? cybersecurity · 95d ago GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language. Reverse Engineering · 95d ago Škoda warns of customer data breach after online shop hack BleepingComputer · 95d ago Android 17 to expand banking scam call and privacy protections BleepingComputer · 95d ago Google and Amnesty International teamed up to make it harder for spyware vendors to hide CyberScoop · 95d ago Career Advice cybersecurity · 95d ago Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs Technical Information Security Content & Discussion · 95d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu Technical Information Security Content & Discussion · 95d ago AI+DFIR Challenge: Share Your Disasters and Successes For [Blue|Purple] Teams in Cyber Defence · 95d ago Anyone else exhausted by the nonstop AI hype? cybersecurity · 95d ago Reviewing the trends in ransomware attacks in 2026 cybersecurity · 95d ago FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread The Last Watchdog · 95d ago Sorry if its the wrong place but hacking: security in practice · 95d ago Is It a Good Idea to Change Jobs Shortly After Getting Hired? cybersecurity · 95d ago SSO makes life easier but MFA keeps it safe, do we actually need both? cybersecurity · 95d ago Hugging Face Packages Weaponized With a Single File Tweak darkreading · 95d ago Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours? cybersecurity · 95d ago Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware For [Blue|Purple] Teams in Cyber Defence · 95d ago How are SOC teams actually deciding what not to investigate anymore? cybersecurity · 95d ago Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily cybersecurity · 95d ago Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released. cybersecurity · 95d ago Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification Cyber Defense Magazine · 95d ago Has anyone tryed this out yet? cybersecurity · 95d ago I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately... Technical Information Security Content & Discussion · 95d ago The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..) cybersecurity · 95d ago Switching to Cyber cybersecurity · 95d ago 20 Leaders Who Built the CISO Era: 2 Decades of Change darkreading · 95d ago Software Bill of Materials for AI - Minimum Elements All CISA Advisories · 95d ago ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax All CISA Advisories · 95d ago Subnet Solutions PowerSYSTEM Center All CISA Advisories · 95d ago ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities All CISA Advisories · 95d ago ABB AC500 V3 Multiple Vulnerabilities All CISA Advisories · 95d ago ABB Automation Builder Gateway for Windows All CISA Advisories · 95d ago Fuji Electric Tellus All CISA Advisories · 95d ago Nitrogen ransomware group claims Foxconn after Wisconsin plant outage cybersecurity · 95d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages cybersecurity · 95d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages BleepingComputer · 95d ago Postmortem: TanStack npm supply-chain compromise For [Blue|Purple] Teams in Cyber Defence · 95d ago Using Cape Sandbox for Phishing Analysis cybersecurity · 95d ago Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain darkreading · 95d ago SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA BleepingComputer · 95d ago Canvas hack: company pays criminals to delete students' stolen data cybersecurity · 95d ago AI is separating the companies built to scale from the ones built to sell CyberScoop · 95d ago i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning. cybersecurity · 95d ago AI integrations are quietly creating a new OAuth supply-chain problem cybersecurity · 95d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak cybersecurity · 95d ago UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships cybersecurity · 95d ago Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results Technical Information Security Content & Discussion · 95d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak BleepingComputer · 95d ago Hardcoded secrets in Git cybersecurity · 95d ago Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages cybersecurity · 95d ago UK water company allowed hackers to lurk undetected for nearly two years, regulator finds cybersecurity · 95d ago New ipTIME Pre-Auth RCE in CWMP cybersecurity · 95d ago New ipTIME Pre-Auth RCE in CWMP Technical Information Security Content & Discussion · 95d ago Postmortem: TanStack npm supply-chain compromise Technical Information Security Content & Discussion · 95d ago Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it? hacking: security in practice · 96d ago Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak cybersecurity · 96d ago Steam spear phishing Malware Analysis & Reports · 96d ago Fake linked in sponsored google search Malware Analysis & Reports · 96d ago Is my phone hacked? cybersecurity · 96d ago Switched to a grc role after a year in SOC L1 cybersecurity · 96d ago bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages For [Blue|Purple] Teams in Cyber Defence · 96d ago rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions For [Blue|Purple] Teams in Cyber Defence · 96d ago Detecting Remote Thread Creation with Windows Driver For [Blue|Purple] Teams in Cyber Defence · 96d ago Mythos finds a curl vulnerability For [Blue|Purple] Teams in Cyber Defence · 96d ago Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details For [Blue|Purple] Teams in Cyber Defence · 96d ago Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign For [Blue|Purple] Teams in Cyber Defence · 96d ago Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment For [Blue|Purple] Teams in Cyber Defence · 96d ago esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app For [Blue|Purple] Teams in Cyber Defence · 96d ago Forecasting Lazarus Crypto Heists cybersecurity · 96d ago LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors. For [Blue|Purple] Teams in Cyber Defence · 96d ago How Cloudflare responded to the “Copy Fail” Linux vulnerability For [Blue|Purple] Teams in Cyber Defence · 96d ago Infrastructure Security Incident Update & FAQs cybersecurity · 96d ago I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic. For [Blue|Purple] Teams in Cyber Defence · 96d ago LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots. For [Blue|Purple] Teams in Cyber Defence · 96d ago Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages cybersecurity · 96d ago In Depth Guide To VM Based Obfuscation - What it is and how to handle it. cybersecurity · 96d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective cybersecurity · 96d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective Reverse Engineering · 96d ago Transitioned to GRC cybersecurity · 96d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages cybersecurity · 96d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages Malware Analysis & Reports · 96d ago German cybersecurity official warns China is close to developing AI superhacker cybersecurity · 96d ago How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models. Technical Information Security Content & Discussion · 96d ago New Shai-Hulud npm worm variant Malware Analysis & Reports · 96d ago New Shai-Hulud npm worm variant For [Blue|Purple] Teams in Cyber Defence · 96d ago Google Detects First AI-Generated Zero-Day Exploit cybersecurity · 96d ago “DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance cybersecurity · 96d ago Instructure/ canvas paid the ransom? cybersecurity · 96d ago Instructure claims hackers returned stolen Canvas data after an extortion standoff CyberScoop · 96d ago OpenAI announces Daybreak, "frontier AI for defenders" Technical Information Security Content & Discussion · 96d ago Troca emprego - big para consultoria ou fintech - Pentester/Red Team cybersecurity · 96d ago GM agrees to $12.75M California settlement over sale of drivers’ data BleepingComputer · 96d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation hacking: security in practice · 96d ago Finally, texts between Android and iPhone users can be end-to-end encrypted cybersecurity · 96d ago Official CheckMarx Jenkins package compromised with infostealer cybersecurity · 96d ago Official CheckMarx Jenkins package compromised with infostealer BleepingComputer · 96d ago New GhostLock tool abuses Windows API to block file access BleepingComputer · 96d ago IMF warns of the potential for AI attacks on global financial systems cybersecurity · 96d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 96d ago GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon Technical Information Security Content & Discussion · 96d ago Cookie thieves caught stealing dev secrets via fake Claude Code installers cybersecurity · 96d ago Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo cybersecurity · 96d ago Innovator Spotlight: Iru Cyber Defense Magazine · 96d ago MS Defender on OT Network cybersecurity · 96d ago A fateful question cybersecurity · 96d ago EtwWatcher For [Blue|Purple] Teams in Cyber Defence · 96d ago SC-900 or SC-400 cybersecurity · 96d ago What are your security non-negotiables? cybersecurity · 96d ago Losing my path cybersecurity · 96d ago Axon-captcha cybersecurity · 96d ago What makes companies trust small cybersecurity vendors? cybersecurity · 96d ago Donuts and Beagles: Fake Claude site spreads backdoor For [Blue|Purple] Teams in Cyber Defence · 96d ago Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility” cybersecurity · 96d ago TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack cybersecurity · 96d ago Innovator Spotlight: Axonius Cyber Defense Magazine · 96d ago News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents The Last Watchdog · 96d ago New and improved: Agent governance, intelligent workflows, and connected app experiences Microsoft 365 Blog · 96d ago Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim cybersecurity · 96d ago How I Defeat Passkeys Nearly Every Time in Phishing Assessments Technical Information Security Content & Discussion · 96d ago These Extensions are Scraping Your AI Chats, are you affected? cybersecurity · 96d ago Reverse Engineering Fisher-Price Pixter Reverse Engineering · 96d ago Be careful with your Git: Investigating malware spreading through Git repositories cybersecurity · 96d ago Training and Phishing cybersecurity · 96d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation cybersecurity · 96d ago AI-powered hacking has exploded into industrial-scale threat, Google says cybersecurity · 96d ago Apple closed my bug report 4 times. MITRE wouldn't let it die. cybersecurity · 96d ago Instructure confirms hackers used Canvas flaw to deface portals BleepingComputer · 96d ago NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG cybersecurity · 96d ago Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach For [Blue|Purple] Teams in Cyber Defence · 96d ago Why Changing Passwords Doesn’t End an Active Directory Breach BleepingComputer · 96d ago CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection For [Blue|Purple] Teams in Cyber Defence · 96d ago looking for "evil" Websites Malware Analysis & Reports · 96d ago Google spotted an AI-developed zero-day before attackers could use it cybersecurity · 96d ago Google: Hackers used AI to develop zero-day exploit for web admin tool BleepingComputer · 96d ago Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge Cyber Defense Magazine · 96d ago Google spotted an AI-developed zero-day before attackers could use it CyberScoop · 96d ago The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface Cyber Defense Magazine · 96d ago Deterministic PE Structural Validation in IOCX v0.7.3 Malware Analysis & Reports · 96d ago beginner doubt cybersecurity · 96d ago where is the location of Files by Google on Android? hacking: security in practice · 96d ago Webinar this week: Prevention alone is not enough against modern attacks BleepingComputer · 96d ago I got my CEH Certification. SO what now? cybersecurity · 96d ago Construction to Cyber PM cybersecurity · 96d ago Deterministic PE Validation for Blue Teams - IOCX v0.7.3 For [Blue|Purple] Teams in Cyber Defence · 96d ago Reading old s4 memory with xgecu t48 hacking: security in practice · 96d ago [ Removed by Reddit ] cybersecurity · 96d ago Something got downloaded on my phone and then dissappeared cybersecurity · 96d ago Bleeding Llama cybersecurity · 96d ago The missing cybersecurity leader in small business CyberScoop · 96d ago Hack a data center? hacking: security in practice · 96d ago Do accountants even care about cybersecurityas much? cybersecurity · 96d ago Where Have All the Complex Windows Malware and Their Analyses Gone? cybersecurity · 96d ago TrickMo Android banker adopts TON blockchain for covert comms BleepingComputer · 96d ago Eyes wide open: How to mitigate the security and privacy risks of smart glasses WeLiveSecurity · 96d ago sl1nk link Malware Analysis & Reports · 96d ago MyAudi app:Security issues in Audi Connected Vehicle experience Technical Information Security Content & Discussion · 96d ago Delving deep into threat detection: My logic for abnormal EventID 7 activity For [Blue|Purple] Teams in Cyber Defence · 96d ago Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot Technical Information Security Content & Discussion · 97d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 97d ago Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust cybersecurity · 97d ago Was the reconnaissance in Bugbounty overrated? cybersecurity · 97d ago Cybersecurity beginner building an experimental log analyzer — looking for advice cybersecurity · 97d ago Anyone else worried about AI being a security nightmare? cybersecurity · 97d ago Snyk not working cybersecurity · 97d ago Malicious tenants paid us to abuse our RMM. We blocked them cybersecurity · 97d ago Help reasuring parents with an email parsing tool (i will not promote) cybersecurity · 97d ago Check out my matplotlib of BLE live wire data for Oura ring! Reverse Engineering · 97d ago Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows Reverse Engineering · 97d ago NZ announces sanctions on malicious Russian cyber actors, online platforms For [Blue|Purple] Teams in Cyber Defence · 97d ago Update: Ongoing Checkmarx Supply Chain Security Incident For [Blue|Purple] Teams in Cyber Defence · 97d ago DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this? cybersecurity · 97d ago Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop Reverse Engineering · 97d ago cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers cybersecurity · 97d ago 5 years as a Level 1 Security Analyst and wanting to transition into consulting cybersecurity · 97d ago How to download a RAT for myself Malware Analysis & Reports · 97d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass cybersecurity · 97d ago New into network pentesting. cybersecurity · 97d ago Is it worth it to switching field to cybersecurity ? cybersecurity · 97d ago Neeed help to get cybersecurity internship. cybersecurity · 97d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 97d ago Cybersecurity and ADHD cybersecurity · 97d ago Mythos, MOAK, CTEM and the End of CVE Chasing Technical Information Security Content & Discussion · 97d ago Autonomous Vulnerability Hunting with MCP hacking: security in practice · 97d ago Anyone dealt with a VulDB submission rejection? Resubmit or reply? cybersecurity · 97d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass Reverse Engineering · 97d ago Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory) Reverse Engineering · 97d ago Autonomous Vulnerability Hunting with MCP Technical Information Security Content & Discussion · 97d ago GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3 Reverse Engineering · 97d ago ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025 For [Blue|Purple] Teams in Cyber Defence · 97d ago Unmanaged PowerShell Execution: Hunting Beyond powershell.exe For [Blue|Purple] Teams in Cyber Defence · 97d ago Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign For [Blue|Purple] Teams in Cyber Defence · 97d ago ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing cybersecurity · 97d ago Static Devirtualization of Themida For [Blue|Purple] Teams in Cyber Defence · 97d ago Now You See Me: AADGraphActivityLogs For [Blue|Purple] Teams in Cyber Defence · 97d ago I have a malware and need help removing it. someone please help me 🙏 cybersecurity · 97d ago [Write-up] CyberDefenders: Wiredive Lab For [Blue|Purple] Teams in Cyber Defence · 97d ago PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra Reverse Engineering · 97d ago I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too? cybersecurity · 97d ago EasySec - Update cybersecurity · 97d ago What is the cybersecurity equivalent of leaving your spare key under the doormat? cybersecurity · 97d ago ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement Technical Information Security Content & Discussion · 97d ago Hackers abuse Google ads, Claude.ai chats to push Mac malware BleepingComputer · 97d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 97d ago VICE: Cyberwar | Full Season 2 | Blueprint cybersecurity · 97d ago Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures cybersecurity · 97d ago Email OTP as default (often ONLY) password isn’t the solution cybersecurity · 97d ago page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer For [Blue|Purple] Teams in Cyber Defence · 97d ago Soc analyse cybersecurity · 97d ago Police shut down reboot of Crimenetwork marketplace, arrest admin BleepingComputer · 97d ago AI DNS Resolver hacking: security in practice · 97d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 97d ago Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI Cyber Defense Magazine · 97d ago Price rising cybersecurity · 97d ago Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple Technical Information Security Content & Discussion · 97d ago JDownloader — Website installer incident (May 2026) For [Blue|Purple] Teams in Cyber Defence · 97d ago AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report cybersecurity · 97d ago Possible security incident against Arup Group cybersecurity · 97d ago Can honeypots be used this way? cybersecurity · 97d ago Is it true that the professionals have the worst setups? hacking: security in practice · 97d ago The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice. Technical Information Security Content & Discussion · 97d ago I think AI just quietly killed the 90-day disclosure window. cybersecurity · 97d ago TCM and Educate 360 are bugged cybersecurity · 97d ago The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate." For [Blue|Purple] Teams in Cyber Defence · 97d ago Got an alert from google what should I do? cybersecurity · 97d ago UK jobs cybersecurity · 97d ago AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT For [Blue|Purple] Teams in Cyber Defence · 97d ago Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏 cybersecurity · 97d ago Outrunning SHA256 with Physics Technical Information Security Content & Discussion · 98d ago EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine) For [Blue|Purple] Teams in Cyber Defence · 98d ago Worst company cybersecurity · 98d ago Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning cybersecurity · 98d ago I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage hacking: security in practice · 98d ago Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months) cybersecurity · 98d ago Innovator Spotlight: Lineaje Cyber Defense Magazine · 98d ago ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring) cybersecurity · 98d ago App Store Question - Darato Sport / Dofu Sport / Kofu cybersecurity · 98d ago Help! - My Parents Computer is Hacked cybersecurity · 98d ago Refining hacking basics — scaling them aswell hacking: security in practice · 98d ago Ran lumma stealer from a recaptcha scam cybersecurity · 98d ago Port 5986 question cybersecurity · 98d ago CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse! cybersecurity · 98d ago cyber security/ segurança da informação cybersecurity · 98d ago Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers For [Blue|Purple] Teams in Cyber Defence · 98d ago College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains cybersecurity · 98d ago Help with an Escalating Cyber-Stalker cybersecurity · 98d ago RRW - Rick Roll WiFi cybersecurity · 98d ago Best resources to start learning python for cybersecurity and automation cybersecurity · 98d ago Writing a Naive LLVM-based Devirtualizer For [Blue|Purple] Teams in Cyber Defence · 98d ago Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game. cybersecurity · 98d ago Memory Poisoning AI Agents via ChromaDB Technical Information Security Content & Discussion · 98d ago Defence in Depth: A Practical Secure Corporate Network Topology Technical Information Security Content & Discussion · 98d ago Where Have All the Complex Windows Malware and Their Analyses Gone? For [Blue|Purple] Teams in Cyber Defence · 98d ago JDownloader site hacked to replace installers with Python RAT malware cybersecurity · 98d ago JDownloader site hacked to replace installers with Python RAT malware BleepingComputer · 98d ago Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram Technical Information Security Content & Discussion · 98d ago Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More) Technical Information Security Content & Discussion · 98d ago How can I fix my browser remembering what he had open last cybersecurity · 98d ago MS 360 CoPilot issues cybersecurity · 98d ago I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details cybersecurity · 98d ago ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12. cybersecurity · 98d ago eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback cybersecurity · 98d ago HackTheBox - Overwatch IppSec · 98d ago I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you cybersecurity · 98d ago AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic) hacking: security in practice · 98d ago Fake OpenAI repository on Hugging Face pushes infostealer malware BleepingComputer · 98d ago OWASP TOP 10 LLM 2026 Community voting cybersecurity · 98d ago When prompts become shells: RCE vulnerabilities in AI agent frameworks For [Blue|Purple] Teams in Cyber Defence · 98d ago Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus For [Blue|Purple] Teams in Cyber Defence · 98d ago MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) For [Blue|Purple] Teams in Cyber Defence · 98d ago Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor For [Blue|Purple] Teams in Cyber Defence · 98d ago Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles. For [Blue|Purple] Teams in Cyber Defence · 98d ago Second security incident at Instructure (Canvas) cybersecurity · 98d ago Wtf OPEN Ai Malware Analysis & Reports · 98d ago Bridging the Gap Between Vulnerabilities and Working Exploits hacking: security in practice · 98d ago um you guys is my hacker stupid? hacking: security in practice · 98d ago UK Advice Needed - VA+ Training? cybersecurity · 98d ago Gateweb - Secure Web Gateway cybersecurity · 98d ago Those who are in Detection engineering cybersecurity · 98d ago Can someone tell me of a trustable hacker? cybersecurity · 98d ago MSPs, how are you handling AI usage across your customer environments today? cybersecurity · 98d ago Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write cybersecurity · 98d ago How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there? cybersecurity · 98d ago ecpptv3 Exam in 3–4 Days — cybersecurity · 98d ago Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026 For [Blue|Purple] Teams in Cyber Defence · 98d ago Member of Prolific Russian Ransomware Group Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 98d ago EasterBunny: advanced espionage artifacts attributed to APT29 For [Blue|Purple] Teams in Cyber Defence · 98d ago AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES cybersecurity · 98d ago Did CISA helped you land a job ? cybersecurity · 98d ago Tracking the "Sorry" Extortionist Campaign Against cPanel Websites For [Blue|Purple] Teams in Cyber Defence · 98d ago PositiveIntent: Evasive loader for .NET Framework assemblies For [Blue|Purple] Teams in Cyber Defence · 98d ago The Accidental C2: Exploring Dev Tunnels for Remote Access For [Blue|Purple] Teams in Cyber Defence · 98d ago Living of the Land - DISM Sandbox Provider Hijack For [Blue|Purple] Teams in Cyber Defence · 98d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode For [Blue|Purple] Teams in Cyber Defence · 98d ago CTO at NCSC Summary: week ending May 10th cybersecurity · 98d ago CTO at NCSC Summary: week ending May 10th For [Blue|Purple] Teams in Cyber Defence · 98d ago ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure For [Blue|Purple] Teams in Cyber Defence · 98d ago PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale For [Blue|Purple] Teams in Cyber Defence · 98d ago Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo For [Blue|Purple] Teams in Cyber Defence · 98d ago pre pre junior needs help(guidance pls) cybersecurity · 99d ago DARWIS Taka - Web vulnerability scanner with Optional AI Validation For [Blue|Purple] Teams in Cyber Defence · 99d ago Trojan malware cybersecurity · 99d ago SANs Courses: How do people get their employers to pay? cybersecurity · 99d ago NIS2 Article 21: turning compliance controls into technical security evidence cybersecurity · 99d ago This GBA Rom is making is having a weird behavior in the Sandbox, why? cybersecurity · 99d ago This GBA ROM makes some weird things in the sanbox, would love to understand why hacking: security in practice · 99d ago Why AI agent governance feels harder than traditional security models cybersecurity · 99d ago Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection Technical Information Security Content & Discussion · 99d ago Confused about what certs are important cybersecurity · 99d ago Would getting Security+ be worthless for me? cybersecurity · 99d ago [Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc) Reverse Engineering · 99d ago Submit probe test — shadow DOM click cybersecurity · 99d ago Threat intelligence in OT (Power equipments) cybersecurity · 99d ago Why was he banned? hacking: security in practice · 99d ago Securing CI/CD for an open source project: lessons from Cilium Technical Information Security Content & Discussion · 99d ago LAB Setup hacking: security in practice · 99d ago SunnyDayBPF: eBPF telemetry integrity research for detection engineering For [Blue|Purple] Teams in Cyber Defence · 99d ago Ethical malware development community hacking: security in practice · 99d ago SOC Analyst cybersecurity · 99d ago PAWs, PAM and PIM..what is best practice? cybersecurity · 99d ago This is the most in-depth analysis I have found on the Instructure/Canvas breach so far. cybersecurity · 99d ago Poland says hackers breached water treatment plants, and the U.S. is facing the same threat cybersecurity · 99d ago Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments CyberScoop · 99d ago Has Instructure paid SH? hacking: security in practice · 99d ago Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web. cybersecurity · 99d ago NVIDIA confirms GeForce NOW data breach affecting Armenian users BleepingComputer · 99d ago Quacc++: Automated Open Source Vulnerability Discovery cybersecurity · 99d ago Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me. hacking: security in practice · 99d ago 60% of MD5 password hashes are crackable in under an hour cybersecurity · 99d ago Built a correlation engine that chains AD findings into attack paths automatically. cybersecurity · 99d ago New trends (not mainstream) hacking: security in practice · 99d ago Why More Analysts Won’t Solve Your SOC’s Alert Problem BleepingComputer · 99d ago Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!) Reverse Engineering · 99d ago Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests cybersecurity · 99d ago ShinyHunters claims nearly 9,000 schools affected by Canvas data breach CyberScoop · 99d ago Trellix source code breach claimed by RansomHouse hackers BleepingComputer · 99d ago Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI CyberScoop · 99d ago Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care Cyber Defense Magazine · 99d ago JDownloader's official website delivered Python RAT cybersecurity · 99d ago JDownloader's official website delivered Python RAT Malware Analysis & Reports · 99d ago Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) cybersecurity · 99d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. cybersecurity · 99d ago ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12 Technical Information Security Content & Discussion · 99d ago Note taking apps and advice cybersecurity · 99d ago CISA gives feds four days to patch Ivanti flaw exploited as zero-day BleepingComputer · 99d ago Best tools to find exposed web services by HTML title / HTTP response? hacking: security in practice · 99d ago IMF Warns AI Could Trigger Global Financial Cyber Crisis cybersecurity · 99d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 99d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 99d ago New Linux 'Dirty Frag' zero-day gives root on all major distros cybersecurity · 99d ago Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2 Reverse Engineering · 99d ago Is the ISC2 Cybersecurity program still worth it? cybersecurity · 99d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama For [Blue|Purple] Teams in Cyber Defence · 99d ago Zara data breach exposed personal information of 197,000 people BleepingComputer · 99d ago Canvas getting hit during finals week shows how fragile “critical SaaS” has become cybersecurity · 99d ago Are websites exposed to the internet under attack almost every hour, even if they're small? cybersecurity · 99d ago Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config Technical Information Security Content & Discussion · 99d ago Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou... For [Blue|Purple] Teams in Cyber Defence · 99d ago Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken cybersecurity · 99d ago Former govt contractor convicted for wiping dozens of federal databases BleepingComputer · 99d ago What the **** is happening in cybersecurity space ? cybersecurity · 99d ago New Linux 'Dirty Frag' zero-day gives root on all major distros BleepingComputer · 100d ago Canvas is back up, but now what? cybersecurity · 100d ago Copy Fail (CVE-2026-31431): A Technical Deep Dive Technical Information Security Content & Discussion · 100d ago Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago? hacking: security in practice · 100d ago AI Agents Have a Security Problem. IronClaw is Fixing It. hacking: security in practice · 100d ago Instagram is getting rid of end to end encryption, what now? cybersecurity · 100d ago Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack For [Blue|Purple] Teams in Cyber Defence · 100d ago Dirty Frag: Universal Linux LPE For [Blue|Purple] Teams in Cyber Defence · 100d ago Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication. For [Blue|Purple] Teams in Cyber Defence · 100d ago Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea For [Blue|Purple] Teams in Cyber Defence · 100d ago New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation cybersecurity · 100d ago Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable". cybersecurity · 100d ago Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group? cybersecurity · 100d ago SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals Reverse Engineering · 100d ago Cushman and Wakefield confirms cyberattack cybersecurity · 100d ago Egnyte potential ransomware attack cybersecurity · 100d ago So canvas is down, what'll happen if they can't come to an argreement? cybersecurity · 100d ago Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now. cybersecurity · 100d ago I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow! Reverse Engineering · 100d ago /Why/ is Shinyhunters targeting Canvas? cybersecurity · 100d ago Canvas Hack - Any Guesses How? cybersecurity · 100d ago Should I build a virtual or physical lab? cybersecurity · 100d ago Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12 cybersecurity · 100d ago Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata cybersecurity · 100d ago Audit/Cybersecurity cybersecurity · 100d ago Issues removing Trellix (and specifically solidifier) cybersecurity · 100d ago Pentagon eyes 3-year cyber training requirement, overriding new Army policy cybersecurity · 100d ago A hacker ran me over with a robot lawn mower - The Verge hacking: security in practice · 100d ago Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia For [Blue|Purple] Teams in Cyber Defence · 100d ago Canvas login portals hacked in mass ShinyHunters extortion campaign BleepingComputer · 100d ago How much personal info will be leaked by the recent Canvas hack?? cybersecurity · 100d ago OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI For [Blue|Purple] Teams in Cyber Defence · 100d ago Dirty Frag and canvas cybersecurity · 100d ago New TCLBanker malware self-spreads over WhatsApp and Outlook BleepingComputer · 100d ago Hackers deface school login pages after claiming another Instructure hack cybersecurity · 100d ago Happened today hacking: security in practice · 100d ago Ivanti customers confront yet another actively exploited zero-day CyberScoop · 100d ago Did I destroy my career by being loyal to an arguably good company? cybersecurity · 100d ago Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo Technical Information Security Content & Discussion · 100d ago V4bel/dirtyfrag - Universal Linux Local Privilege Escalation cybersecurity · 100d ago Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC For [Blue|Purple] Teams in Cyber Defence · 100d ago What is CYBERRANT? cybersecurity · 100d ago Canvas is down as ShinyHunters hack forces outage cybersecurity · 100d ago Shinyhunters and Canvas hacking: security in practice · 100d ago New Dirty Frag Linux Bug Emerges in Wake of Copy Fail cybersecurity · 100d ago Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today. cybersecurity · 100d ago How is GRC work in a MSSP? cybersecurity · 100d ago SH and BF phishing console cybersecurity · 100d ago Trump officials are steering a cybersecurity scholarship program toward AI CyberScoop · 100d ago Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth? cybersecurity · 100d ago Dirty Frag - Linux LPE similiar to Copy Fail Technical Information Security Content & Discussion · 100d ago Socure authenticating AI identity as real. cybersecurity · 100d ago The first FREE online WebAssembly Reverse Engineering workbench (and how we built it) Reverse Engineering · 100d ago New PCPJack worm steals credentials, cleans TeamPCP infections BleepingComputer · 100d ago Automated SSL Certificate Renewals - What is your setup? cybersecurity · 100d ago Shinyhunters and Canvas cybersecurity · 100d ago What Cli execution do you use for a script file? cybersecurity · 100d ago Australia warns of ClickFix attacks pushing Vidar Stealer malware BleepingComputer · 100d ago Fiserv security incident - data breach notice cybersecurity · 100d ago Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments cybersecurity · 100d ago Honey Tokens: Bait Credentials That Catch Breaches Technical Information Security Content & Discussion · 100d ago I graduate next year with a Cybersecurity degree. cybersecurity · 100d ago An unknown malware threat. There is no such thing as a 100% detection. Malware Analysis & Reports · 100d ago Asking about Cortex cybersecurity · 100d ago CVE-2026-42511 Breakdown: RCE in FreeBSD Technical Information Security Content & Discussion · 100d ago Apache Caldera cybersecurity · 100d ago What’s the “unsexy” problem in cyber that’s actually a total disaster? cybersecurity · 100d ago Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE cybersecurity · 100d ago Ivanti warns of new EPMM flaw exploited in zero-day attacks BleepingComputer · 100d ago As a developer, should I use AI to improve security? cybersecurity · 100d ago My company has an MSP that manages our employee endpoints but we cant access the software they use to manage cybersecurity · 100d ago Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804 Technical Information Security Content & Discussion · 100d ago Americans sentenced for running 'laptop farms' for North Korea cybersecurity · 100d ago Is my laptop hijacked ? cybersecurity · 100d ago The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls BleepingComputer · 100d ago American duo sentenced for hosting laptop farms for North Korean IT workers CyberScoop · 100d ago claude ai gave security beta to Enterprise plans only what can we do as pentesters? cybersecurity · 100d ago Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline cybersecurity · 100d ago Americans sentenced for running 'laptop farms' for North Korea BleepingComputer · 100d ago Advice for path to land job SOC in France cybersecurity · 100d ago Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered Cyber Defense Magazine · 100d ago Possible Major Vulnerability: Chromium used by current version of PRTG cybersecurity · 100d ago Mythos AI may be a cybersecurity threat, but it follows the rules of the game cybersecurity · 100d ago When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity Cyber Defense Magazine · 100d ago Control Checks using AI. cybersecurity · 100d ago How do native password managers clear the clipboard? cybersecurity · 100d ago VLC Media Player MKV Exploit Analysis Reverse Engineering · 100d ago Graduating CS Student but Wanna Start my Career in Cybersecurity cybersecurity · 100d ago Crypto gang member gets 6.5 years for role in $230 million heist BleepingComputer · 100d ago An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support) Technical Information Security Content & Discussion · 100d ago Webinar: Why modern attacks require both security and recovery BleepingComputer · 100d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 100d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 100d ago MAXHUB Pivot Client Application All CISA Advisories · 100d ago Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI Technical Information Security Content & Discussion · 100d ago Claude-Themed Malware Campaigns cybersecurity · 100d ago DeepFake it till you make it. cybersecurity · 100d ago The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments cybersecurity · 100d ago Palo Alto Networks firewall zero-day exploited for nearly a month BleepingComputer · 100d ago What niche in cybersecurity should I go for, with my background in Angular & .NET ? cybersecurity · 100d ago Successor for Kaspersky Endpoint Security cybersecurity · 100d ago Fake Claude AI website delivers new 'Beagle' Windows malware BleepingComputer · 100d ago One House Democrat is pressing Commerce on the government’s spyware use CyberScoop · 100d ago Fake call logs, real payments: How CallPhantom tricks Android users WeLiveSecurity · 100d ago Detecting BEC Persistence with KQL For [Blue|Purple] Teams in Cyber Defence · 100d ago Modify md5sum of a file hacking: security in practice · 100d ago Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago cybersecurity · 100d ago SOC Analyst tier 1 (Entry Level) ?? cybersecurity · 101d ago Unpacking Russian-Iranian Private-Sector Cyber Connections For [Blue|Purple] Teams in Cyber Defence · 101d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 101d ago Made cybersecurity merch as an infosec practitioner — honest feedback welcome cybersecurity · 101d ago Fixing the password problem is as easy as 123456 WeLiveSecurity · 101d ago As AI agents become users of company data - what is needed to keep data secure? cybersecurity · 101d ago Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities. cybersecurity · 101d ago AI inference is quietly becoming a security problem cybersecurity · 101d ago is winrar 7.13 vulnerable to extraction exploits? cybersecurity · 101d ago Tried explaining internet encryption in a beginner-friendly but accurate way, feedback? cybersecurity · 101d ago Is the EC-Council CTIA Certification Worth It for Career Growth? cybersecurity · 101d ago POC Android vuln 2026 cybersecurity · 101d ago Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise cybersecurity · 101d ago Opinions on Mimecast cybersecurity · 101d ago Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution For [Blue|Purple] Teams in Cyber Defence · 101d ago What's going on in the field of Cybersecurity 🫣. cybersecurity · 101d ago How do teams preserve institutional pentest knowledge when senior testers leave? cybersecurity · 101d ago CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE cybersecurity · 101d ago Sophos NDR on Proxmox cybersecurity · 101d ago Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites Malware Analysis & Reports · 101d ago Quacc++: Automated Open Source Vulnerability Discovery Technical Information Security Content & Discussion · 101d ago Hackers abuse Google ads for GoDaddy ManageWP login phishing BleepingComputer · 101d ago A DOD contractor’s API flaw exposed military course data and service member records CyberScoop · 101d ago On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029. cybersecurity · 101d ago DOJ says ransomware gang tapped into Russian government databases cybersecurity · 101d ago DAEMON Tools devs confirm breach, release malware-free version cybersecurity · 101d ago Have there been instances where your SOC has suffered a cybersecurity attack? cybersecurity · 101d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk For [Blue|Purple] Teams in Cyber Defence · 101d ago Inadvertent Injections For [Blue|Purple] Teams in Cyber Defence · 101d ago A critical Palo Alto PAN-OS zero-day is being exploited in the wild CyberScoop · 101d ago OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM hacking: security in practice · 101d ago OpenCTI founder, Samuel Hassine, arrested and charged with CSAM cybersecurity · 101d ago Deepfake Platform cybersecurity · 101d ago Critical vm2 sandbox bug lets attackers execute code on hosts BleepingComputer · 101d ago Innovators Spotlight: Badge (Part II) Cyber Defense Magazine · 101d ago Trellix Licence Query cybersecurity · 101d ago New Cisco DoS flaw requires manual reboot to revive devices BleepingComputer · 101d ago CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal For [Blue|Purple] Teams in Cyber Defence · 101d ago Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML Malware Analysis & Reports · 101d ago Instructure hacker claims data theft from 8,800 schools, universities cybersecurity · 101d ago Is AI generated code creating a non-linear security problem for AppSec teams? cybersecurity · 101d ago Jailbreaking my cars infotainment system and implementing my own custom software hacking: security in practice · 101d ago Binance fixed the IP whitelist gap — but the disclosure process is still broken Technical Information Security Content & Discussion · 101d ago D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says cybersecurity · 101d ago DAEMON Tools devs confirm breach, release malware-free version BleepingComputer · 101d ago where is the original wormgpt hacking: security in practice · 101d ago Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security cybersecurity · 101d ago Norton Antivirus and Other Norton Software cybersecurity · 101d ago Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home? cybersecurity · 101d ago We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes. cybersecurity · 101d ago Download a malware a while ago, someone trying to log into my ios account cybersecurity · 101d ago Are there any chill hacking youtubers? hacking: security in practice · 101d ago Org Restructure cybersecurity · 101d ago Non-Determinism of Maps in Golang: Why, How, and the Consequences Technical Information Security Content & Discussion · 101d ago Does SOC 2 actually reduce questionnaires, or just change them? cybersecurity · 101d ago Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views cybersecurity · 101d ago Why ransomware attacks succeed even when backups exist BleepingComputer · 101d ago How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically? cybersecurity · 101d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Reverse Engineering · 101d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Technical Information Security Content & Discussion · 101d ago Ran phishing awareness training for 200+ non-tech employees cybersecurity · 101d ago Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware For [Blue|Purple] Teams in Cyber Defence · 101d ago Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk cybersecurity · 101d ago Vulnerability Garden Technical Information Security Content & Discussion · 101d ago Vulnerability Garden cybersecurity · 101d ago Palo Alto Firewall Zero-Day Under Active Exploitation cybersecurity · 101d ago MuddyWater hackers use Chaos ransomware as a decoy in attacks BleepingComputer · 101d ago Redefining Security Operations Through Seceon’s Open Threat Management Platform Cyber Defense Magazine · 101d ago Webinar: Why network incidents escalate and how to fix response gaps BleepingComputer · 101d ago Cyber Security Militias cybersecurity · 101d ago Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk cybersecurity · 101d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 101d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 101d ago Took me a decade to turn quantum computing into what programmers can easily learn, big announcement hacking: security in practice · 101d ago Lilygo T-Embed Glitching etc hacking: security in practice · 101d ago CyberSecurity Nightmares cybersecurity · 101d ago Can I use NanoKVM if it's just to turn on pc? cybersecurity · 101d ago got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something? cybersecurity · 101d ago How to learn tools for cybersecurity? cybersecurity · 101d ago 'CopyFail' attackers start cashing in on Linux flaw cybersecurity · 101d ago Anybodybodybdown for a team/studygroup? cybersecurity · 101d ago Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today? hacking: security in practice · 101d ago I was hacked due to sim card spoofing cybersecurity · 101d ago Palo Alto Networks warns of firewall RCE zero-day exploited in attacks BleepingComputer · 101d ago Chrome is quietly installing a 4GB AI model on your device cybersecurity · 101d ago Dev vs Security role cybersecurity · 101d ago Discord bot C2 infrastructure Malware Analysis & Reports · 101d ago Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed For [Blue|Purple] Teams in Cyber Defence · 101d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 101d ago UAT-8302 and its box full of malware For [Blue|Purple] Teams in Cyber Defence · 101d ago Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft cybersecurity · 102d ago Oracle Debuts Monthly Critical Security Patch Updates cybersecurity · 102d ago Sec engineer / developer? cybersecurity · 102d ago When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them? cybersecurity · 102d ago Are we actually seeing more vulnerabilities or just more noise? cybersecurity · 102d ago Cybersecurity jobs in red team cybersecurity · 102d ago Question cybersecurity · 102d ago What’s the biggest mistake people make even after installing antivirus? cybersecurity · 102d ago CVE-2026-0073 Android adbd TLS client-authentication bypass For [Blue|Purple] Teams in Cyber Defence · 102d ago One KQL query you should have saved in your toolkit (most don’t) For [Blue|Purple] Teams in Cyber Defence · 102d ago New dashboard tracks ransomware groups by their reliance on Infostealer credentials cybersecurity · 102d ago ant4g0nist/pyre: Ghidra decompiler in your browser Reverse Engineering · 102d ago CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier? For [Blue|Purple] Teams in Cyber Defence · 102d ago Found a possibly interesting live attack hacking: security in practice · 102d ago What would you say if your security lead said this... cybersecurity · 102d ago What would be the goto setup in AWS for security purposes? cybersecurity · 102d ago CREST CRT Exam 2025/2026 Experiences cybersecurity · 102d ago Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside For [Blue|Purple] Teams in Cyber Defence · 102d ago Microsoft Edge stores your passwords in plaintext RAM... on purpose cybersecurity · 102d ago Export/Backup ChatGPT chats hacking: security in practice · 102d ago Como começar? cybersecurity · 102d ago Possible Password Leak? Curious if Anyone Has Seen This Before cybersecurity · 102d ago Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source! Reverse Engineering · 102d ago Not a Hack. A Handout. Inside the GTFOice.org Data Exposure cybersecurity · 102d ago Besoin de conseils sur une DMZ automatisée cybersecurity · 102d ago Microsoft, Google and xAI will let the government test their AI models before launch cybersecurity · 102d ago Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073 cybersecurity · 102d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 102d ago New stealthy Quasar Linux malware targets software developers BleepingComputer · 102d ago SMB Header Signature for Tagging in Firewall cybersecurity · 102d ago Question regarding VDP cybersecurity · 102d ago Working on what i should do for the next 3 years cybersecurity · 102d ago Question for Security Professionals cybersecurity · 102d ago Do tech companies lifecycle-manage public DNS records to prevent dangling DNS? cybersecurity · 102d ago Instructure hacker claims data theft from 8,800 schools, universities BleepingComputer · 102d ago Vulnerability Summary for the Week of April 27, 2026 cybersecurity · 102d ago Scan. Secure. Simplify. — Free Web Tools Platform Technical Information Security Content & Discussion · 102d ago Cisco releases open-source ‘DNA test for AI models’ cybersecurity · 102d ago Cybersecurity is becoming too AI dependent is that a problem cybersecurity · 102d ago Foxconn Wisconsin outage raises cyber questions cybersecurity · 102d ago How stressful is GRC? cybersecurity · 102d ago News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market The Last Watchdog · 102d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482) Technical Information Security Content & Discussion · 102d ago Salesforce pentesting novel techniques- how to be an apex predator Technical Information Security Content & Discussion · 102d ago DAEMON Tools trojanized in supply-chain attack to deploy backdoor BleepingComputer · 102d ago Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia cybersecurity · 102d ago Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India cybersecurity · 102d ago Archer for a non-regulated medium sized company? cybersecurity · 102d ago Cybersecurity statistics of the week (April 27th - May 3rd) cybersecurity · 102d ago Reverse-engineering the 1998 Ultima Online demo server Reverse Engineering · 102d ago Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM. cybersecurity · 102d ago One-Click Refunds Are Not as Hard as You Think Blog – Forter · 102d ago Student hacked Taiwan high-speed rail to trigger emergency brakes BleepingComputer · 102d ago 🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records For [Blue|Purple] Teams in Cyber Defence · 102d ago Where to find reliable vendors? cybersecurity · 102d ago DigiCert: Misissued code signing certificates Technical Information Security Content & Discussion · 102d ago Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts? cybersecurity · 102d ago We wrote a guide on securing Claude across the enterprise — here's the core framework (with download) cybersecurity · 102d ago Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium. cybersecurity · 102d ago Hardware reverse enginnering first project. Love some advice cybersecurity · 102d ago Microsoft Edge Stores Passwords in Process Memory, Posing Risk cybersecurity · 102d ago Currently working on cybersecurity, looking for advice cybersecurity · 102d ago Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning cybersecurity · 102d ago Major AI Clients Shipping With Broken OAuth Implementations Technical Information Security Content & Discussion · 102d ago CISO course valuation cybersecurity · 102d ago Inside Faxanadu series — deep dive into how this NES title works Reverse Engineering · 102d ago EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing Reverse Engineering · 102d ago Popular DAEMON Tools software compromised For [Blue|Purple] Teams in Cyber Defence · 102d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 102d ago Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise For [Blue|Purple] Teams in Cyber Defence · 102d ago GRC Path to CISO (Certifications) cybersecurity · 102d ago Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities For [Blue|Purple] Teams in Cyber Defence · 102d ago CISOs and pentest buyers, what's the worst thing you've seen in a pentest report? cybersecurity · 102d ago FTC to ban data broker Kochava from selling Americans’ location data BleepingComputer · 102d ago How to enforce M365 Sign-in frequency on corporate laptops? cybersecurity · 102d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs cybersecurity · 102d ago The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check. BleepingComputer · 102d ago The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss BleepingComputer · 102d ago Built an independent directory of AI Act / AI governance tools, feedback? cybersecurity · 102d ago ScarCruft APT group compromises gaming platform in a supply-chain attack cybersecurity · 102d ago Just curious cybersecurity · 102d ago 'Copy Fail' is a real Linux security crisis wrapped in AI slop cybersecurity · 102d ago Analysis malicious DLL cybersecurity · 102d ago Cyber security free course cybersecurity · 102d ago Vimeo data breach exposes personal information of 119,000 people BleepingComputer · 102d ago The Insurance Industry Is Rewriting Cybersecurity Strategy Cyber Defense Magazine · 102d ago Does certification expires? cybersecurity · 102d ago HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10 Technical Information Security Content & Discussion · 102d ago IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening Malware Analysis & Reports · 102d ago Panicking Malware Analysis & Reports · 102d ago ABB B&R Automation Studio All CISA Advisories · 102d ago ABB B&R Automation Runtime All CISA Advisories · 102d ago Hitachi Energy PCM600 All CISA Advisories · 102d ago Johnson Controls CEM AC2000 All CISA Advisories · 102d ago ABB B&R PVI All CISA Advisories · 102d ago How the Story of a USB Penetration Test Went Viral darkreading · 102d ago We get paid to break into buildings for a living. Ask us anything! cybersecurity · 102d ago Pay2Key ransomware — any recovery path that’s actually worked? cybersecurity · 102d ago Google now offers up to $1.5 million for some Android exploits BleepingComputer · 102d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison cybersecurity · 102d ago Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF cybersecurity · 102d ago Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud Technical Information Security Content & Discussion · 102d ago How have you kept growing your knowledge in security when the job stops pushing you? cybersecurity · 102d ago Supply chain attack: DAEMON Tools Lite now contains a backdoor. Malware Analysis & Reports · 102d ago Accelerating Vulnerability Detection and Response at Oracle For [Blue|Purple] Teams in Cyber Defence · 102d ago The Danger of Multi-SSO AWS Cognito User Pools Technical Information Security Content & Discussion · 102d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison BleepingComputer · 102d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs BleepingComputer · 102d ago Copilot Cowork: From conversation to action across skills, integrations, and devices Microsoft 365 Blog · 102d ago The UK’s Age Verification Law Is Producing Compliance Theater cybersecurity · 102d ago Microsoft Edge: Passwords end up in memory as plaintext cybersecurity · 102d ago Do people still get viruses in 2026, or is that mostly a myth now? cybersecurity · 102d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 Technical Information Security Content & Discussion · 102d ago Mitigation script for Copy Fail vulnerability CVE-2026-31431 cybersecurity · 102d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 cybersecurity · 102d ago Is this fake too?🤣 hacking: security in practice · 102d ago Copy.fail: Why Internal LLMs Are Non-Negotiable for Security Reverse Engineering · 102d ago The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew For [Blue|Purple] Teams in Cyber Defence · 102d ago Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released cybersecurity · 102d ago ScarCruft hackers push BirdCall Android malware via game platform BleepingComputer · 102d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack WeLiveSecurity · 102d ago DigiCert breached via malicious screensaver file cybersecurity · 102d ago I just figured out my dad use to be a Phreaker in the 1980s hacking: security in practice · 102d ago Caido Payloads and Scanner of Endpoints cybersecurity · 102d ago Proton Pass: Second-Password Bypass Through Emergency Access Technical Information Security Content & Discussion · 102d ago What of my favorite videos🙂 hacking: security in practice · 103d ago CISO Security Mind Map 2026 cybersecurity · 103d ago Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker cybersecurity · 103d ago Best tools for blocking spam calls and spam links? hacking: security in practice · 103d ago Amazon SES increasingly abused in phishing to evade detection cybersecurity · 103d ago someone else’s UI appearing on screen for split second— possible hacker?? hacking: security in practice · 103d ago AI Security Trainings cybersecurity · 103d ago Ai help cybersecurity · 103d ago ByDesign: observed behavior where file URLs remain accessible after unshare/delete cybersecurity · 103d ago Can Kali Linux still compete in cyber security or is it outdated? cybersecurity · 103d ago We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother Technical Information Security Content & Discussion · 103d ago Avoiding rouge AP detection in enterprise networks hacking: security in practice · 103d ago Who are your favorite cybersecurity YouTubers? cybersecurity · 103d ago CISOs, how are you balancing AI adoption with security risks these days? cybersecurity · 103d ago GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated. For [Blue|Purple] Teams in Cyber Defence · 103d ago dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025 For [Blue|Purple] Teams in Cyber Defence · 103d ago N-Day Research with AI: Using Ollama and n8n For [Blue|Purple] Teams in Cyber Defence · 103d ago San Diego Community College District fighting major cyberattack cybersecurity · 103d ago GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering hacking: security in practice · 103d ago San Diego Community College District fighting major cyberattack hacking: security in practice · 103d ago After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up cybersecurity · 103d ago Free resource: searchable archive of every BSides conference talk cybersecurity · 103d ago Lightning PyPI Compromise: Bun-Based Stealer cybersecurity · 103d ago Too much mother instinct? cybersecurity · 103d ago L1 SOC Analyst for ~2 years - Should I still get the Security + Certification? cybersecurity · 103d ago Do CTFs help real world security skills, or just teach patterns? cybersecurity · 103d ago Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo cybersecurity · 103d ago Should I do Security + or Network + or A+? For CompTia cybersecurity · 103d ago Weaver E-cology critical bug exploited in attacks since March BleepingComputer · 103d ago Bug bounty is ruining how people learn exploitation cybersecurity · 103d ago ISO/IEC 27701:2025 Scope and Location cybersecurity · 103d ago Cybersecurity's 2026 Wild Ride cybersecurity · 103d ago We built a free multiplayer game that scores prompts on AI code security. cybersecurity · 103d ago RMM Tools Fuel Stealthy Phishing Campaign darkreading · 103d ago Production Usecases cybersecurity · 103d ago Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra Reverse Engineering · 103d ago How does vCISO work? cybersecurity · 103d ago Amazon SES increasingly abused in phishing to evade detection BleepingComputer · 103d ago Researchers report Amazon SES abused in phishing to evade detection BleepingComputer · 103d ago Trellix discloses data breach after source code repository hack cybersecurity · 103d ago CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path cybersecurity · 103d ago Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability darkreading · 103d ago Trellix confirms source code repo access incident cybersecurity · 103d ago Where do i find reverse engineers for actuators? Ideally in Shenzhen Reverse Engineering · 103d ago Employer Offering to Pay for my Certification test - Which one do I choose? cybersecurity · 103d ago John Strand Pay What You Can Information Security Core Skills live starting May 11th cybersecurity · 103d ago [CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2). Reverse Engineering · 103d ago Canvas Breach May Put 275M Users, 9,000 Schools at Risk cybersecurity · 103d ago Backdoored PyTorch Lightning package drops credential stealer BleepingComputer · 103d ago Is this not such a big deal cybersecurity · 103d ago 38 CVEs in Healthcare Software Used by 100,000 Medical Providers For [Blue|Purple] Teams in Cyber Defence · 103d ago Do email link checkers need to be 100%? cybersecurity · 103d ago Cybersecurity M&A Roundup: 33 Deals Announced in April 2026 cybersecurity · 103d ago Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation Malware Analysis & Reports · 103d ago Recs for pen testing and vulnerability solutions cybersecurity · 103d ago Identify telegram account holders cybersecurity · 103d ago AI Code Security Study: 6 LLMs vs OWASP Top 10 cybersecurity · 103d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers hacking: security in practice · 103d ago Recursively fuzzing MS-RPC structures and monitoring using ETW For [Blue|Purple] Teams in Cyber Defence · 103d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers cybersecurity · 103d ago Trellix discloses data breach after source code repository hack BleepingComputer · 103d ago Iwas developing a hacker game that transports the feeling of the 90s hacking: security in practice · 103d ago We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA cybersecurity · 103d ago Azure IaaS: Defense in depth built on secure-by-design principles Security | Microsoft Azure Blog | Microsoft Azure · 103d ago Cortex XDR Cloud Compromise Alerting cybersecurity · 103d ago Norton.com Verification Email out of the blue cybersecurity · 103d ago Atomic Red Team is now aligned with MITRE ATT&CK v19! cybersecurity · 103d ago Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX? cybersecurity · 103d ago Who are you guys using for your PCI ASV Scanning? cybersecurity · 103d ago Just passed my Security+ exam. Now what? cybersecurity · 103d ago I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work. cybersecurity · 103d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 103d ago [PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection) cybersecurity · 103d ago Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia darkreading · 103d ago Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350) cybersecurity · 103d ago An another open door to IoT devices cybersecurity · 103d ago Ideas on how to have personal google-like account synchronization system cybersecurity · 103d ago Lateral Movement - Cross-Session Activation Technical Information Security Content & Discussion · 103d ago Lateral Movement - Cross-Session Activation cybersecurity · 103d ago How did this guy even access another person's privated YouTube video without wayback machine? hacking: security in practice · 103d ago What MCP servers have actually made it into your day-to-day toolkit? cybersecurity · 103d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems hacking: security in practice · 103d ago They don’t hack, they borrow: How fraudsters target credit unions BleepingComputer · 103d ago Cyber Security Education as Self-Defence classes cybersecurity · 103d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk cybersecurity · 103d ago Use.ai cybersecurity · 103d ago Educational tech giant Instructure confirms data breach, ShinyHunters claims attack cybersecurity · 103d ago [WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation Reverse Engineering · 103d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems cybersecurity · 103d ago Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management Cyber Defense Magazine · 103d ago IPod Nano Gets Three Monitors hacking: security in practice · 103d ago IDA-MCP Is Now RE-MCP With Ghidra Support Reverse Engineering · 103d ago Progress warns of critical MOVEit Automation auth bypass flaw BleepingComputer · 103d ago Webinar: Why MSPs must rethink security and backup strategies BleepingComputer · 103d ago Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference Reverse Engineering · 103d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems BleepingComputer · 103d ago Chrome "Best AdBlocker" trojanized extension - 100k downloads. hacking: security in practice · 103d ago How Dark Reading Lifted Off the Launchpad in 2006 darkreading · 103d ago Browsers making connection on port 3389 from loopback cybersecurity · 103d ago Microsoft confirms April Windows updates cause backup failures BleepingComputer · 103d ago Defender Flagged DigiCert Root Certs as Malware cybersecurity · 103d ago VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases For [Blue|Purple] Teams in Cyber Defence · 103d ago Another breach just hit Canvas (Instructure), and this one is worth a closer look. cybersecurity · 103d ago Over 40% of UK firms suffered cyber attack last year, survey finds cybersecurity · 103d ago EU should seek access to Anthropic's Mythos, Bundesbank says cybersecurity · 103d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha cybersecurity · 103d ago CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation. For [Blue|Purple] Teams in Cyber Defence · 103d ago 《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition) For [Blue|Purple] Teams in Cyber Defence · 103d ago nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution. For [Blue|Purple] Teams in Cyber Defence · 103d ago 蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery. For [Blue|Purple] Teams in Cyber Defence · 103d ago IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks cybersecurity · 104d ago People in cybersecurity, tell us what was the most epic moment in your career? cybersecurity · 104d ago Prerequisites for CARTP cybersecurity · 104d ago gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives For [Blue|Purple] Teams in Cyber Defence · 104d ago Claude Mythos Cyber Wake Up cybersecurity · 104d ago [ Removed by Reddit ] cybersecurity · 104d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 104d ago is trellix from mcafee good to use in 2026? cybersecurity · 104d ago Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list cybersecurity · 104d ago Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon For [Blue|Purple] Teams in Cyber Defence · 104d ago AMSI Page Guard Bypass (Rust PoC) For [Blue|Purple] Teams in Cyber Defence · 104d ago Any good open sources that bypass modern heuristic analysis? hacking: security in practice · 104d ago Meet Bluekit: The AI-Powered All-in-One Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 104d ago Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI For [Blue|Purple] Teams in Cyber Defence · 104d ago A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia For [Blue|Purple] Teams in Cyber Defence · 104d ago IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect For [Blue|Purple] Teams in Cyber Defence · 104d ago Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection For [Blue|Purple] Teams in Cyber Defence · 104d ago ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution… For [Blue|Purple] Teams in Cyber Defence · 104d ago Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia For [Blue|Purple] Teams in Cyber Defence · 104d ago [2603.28728] Study of Post Quantum status of Widely Used Protocols For [Blue|Purple] Teams in Cyber Defence · 104d ago Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin For [Blue|Purple] Teams in Cyber Defence · 104d ago Free apex hacks? hacking: security in practice · 104d ago Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning For [Blue|Purple] Teams in Cyber Defence · 104d ago Paypal Accesed by malware me being Stupid cybersecurity · 104d ago How was someone in another country able to read all my private messages without my password or clicking a link? cybersecurity · 104d ago code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint. For [Blue|Purple] Teams in Cyber Defence · 104d ago Secure Boot Inventory Data In Configuration Manager For [Blue|Purple] Teams in Cyber Defence · 104d ago EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time. For [Blue|Purple] Teams in Cyber Defence · 104d ago MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning. For [Blue|Purple] Teams in Cyber Defence · 104d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Technical Information Security Content & Discussion · 104d ago AI-powered honeypots: Turning the tables on malicious AI agents For [Blue|Purple] Teams in Cyber Defence · 104d ago Career Transition Help cybersecurity · 104d ago Alguien para hablar de cyberseguridad cybersecurity · 104d ago copy.golf — golf your exploits - smaller copy.fail exploits.. For [Blue|Purple] Teams in Cyber Defence · 104d ago DragonBreath: Dragon in the Kernel For [Blue|Purple] Teams in Cyber Defence · 104d ago What is this cybersecurity · 104d ago Your vibe-coded app is probably violating GDPR right now Technical Information Security Content & Discussion · 104d ago [SHOWCASE] Cascavel v3 hacking: security in practice · 104d ago Feeling lost and disappointed about finding a job just venting cybersecurity · 104d ago Slow at Learning/Cyber Security? cybersecurity · 104d ago Pokemon machine hacking: security in practice · 104d ago Suspicious traffic from web server cybersecurity · 104d ago Cyber security internship cybersecurity · 104d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 104d ago Isn't Windows Defender a crap anymore? cybersecurity · 104d ago GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions) Reverse Engineering · 104d ago Learning Cyber cybersecurity · 104d ago Instructure confirms data breach, ShinyHunters claims attack BleepingComputer · 104d ago Vishing simulator cybersecurity · 104d ago Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others cybersecurity · 104d ago Worried about being tracked/banned for using an educational app on MuMu Player - Need advice cybersecurity · 104d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks cybersecurity · 104d ago Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance cybersecurity · 104d ago Prompt Injection in 2026: The Five Attack Patterns That Actually Matter cybersecurity · 104d ago I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine cybersecurity · 104d ago Random trojan detected? cybersecurity · 104d ago CRTA second attempt cybersecurity · 104d ago What’s the hardest thing to learn in cybersecurity? cybersecurity · 104d ago What MCP servers are you integrating into your workflow (not exclusive to security)? cybersecurity · 104d ago Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors. For [Blue|Purple] Teams in Cyber Defence · 104d ago WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog cybersecurity · 104d ago What are like the top but unknown Cybersecurity firms? cybersecurity · 104d ago Can HTTP POST bodies be intercepted without network or host access? hacking: security in practice · 104d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha BleepingComputer · 104d ago Need professionals or expert on cybersecurity related to dark web for interview cybersecurity · 104d ago A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP) cybersecurity · 104d ago Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library For [Blue|Purple] Teams in Cyber Defence · 104d ago North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory cybersecurity · 104d ago VirusTotal has one flag for this sus site Malware Analysis & Reports · 104d ago Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo Reverse Engineering · 104d ago Telegram Mini Apps abused for crypto scams, Android malware delivery BleepingComputer · 104d ago Puzzle: Set of PoC to abuse Windows minifilters functionality For [Blue|Purple] Teams in Cyber Defence · 104d ago Ai Didn’t Break Cybersecurity, It Revealed It Cyber Defense Magazine · 104d ago Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate) cybersecurity · 104d ago Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate) Technical Information Security Content & Discussion · 104d ago Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you! Reverse Engineering · 104d ago built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4) hacking: security in practice · 104d ago Credential Dumping: Local Security Authority (LSA|LSASS.EXE) cybersecurity · 104d ago A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16 For [Blue|Purple] Teams in Cyber Defence · 104d ago Dump sql time based is too slow hacking: security in practice · 104d ago Trojan:Win32/Cerdigent.A!dha cybersecurity · 104d ago Active exploitation of cPanel/WHM critical vulnerability For [Blue|Purple] Teams in Cyber Defence · 104d ago Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. " For [Blue|Purple] Teams in Cyber Defence · 104d ago MDE flagging digi cert certificate as malicious everywhere ? cybersecurity · 104d ago North Korea rejects US cybercrime claims as 'absurd slander' hacking: security in practice · 104d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Reverse Engineering · 105d ago 5 Qilin ransomware servers exposed over 7 months For [Blue|Purple] Teams in Cyber Defence · 105d ago is credential stuffing using openbullet2 dead in 2026? hacking: security in practice · 105d ago Anyone wanna learn the CEH or OSCP red teaming free Malware Analysis & Reports · 105d ago South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) For [Blue|Purple] Teams in Cyber Defence · 105d ago Russian Charged in Oil and Gas Facility Hacks Pleads Guilty For [Blue|Purple] Teams in Cyber Defence · 105d ago Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax) hacking: security in practice · 105d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks BleepingComputer · 105d ago How to build .NET obfuscator - Part II Reverse Engineering · 105d ago VECT ransomware: small files decrypt, large files lose their nonces For [Blue|Purple] Teams in Cyber Defence · 105d ago CTO at NCSC Summary: week ending May 3rd For [Blue|Purple] Teams in Cyber Defence · 105d ago April 27th - What happened with our feature flag configuration | The ClickUp Blog For [Blue|Purple] Teams in Cyber Defence · 105d ago Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT) hacking: security in practice · 105d ago How to exfiltrate data using only numeric outputs Technical Information Security Content & Discussion · 105d ago ConsentFix v3 attacks target Azure with automated OAuth abuse BleepingComputer · 105d ago libghidra - SDK for automating Ghidra from Python, Rust, and C++ Reverse Engineering · 105d ago Blog: Evolving the Android & Chrome VRPs for the AI Era For [Blue|Purple] Teams in Cyber Defence · 105d ago Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis. Reverse Engineering · 105d ago RSAC 2026: The Power of Community Cyber Defense Magazine · 105d ago Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed. For [Blue|Purple] Teams in Cyber Defence · 105d ago VECT: Ransomware by design, Wiper by accident For [Blue|Purple] Teams in Cyber Defence · 105d ago VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built. For [Blue|Purple] Teams in Cyber Defence · 105d ago Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 105d ago Agentic Malware Analysis: From Task Automation to Deep Analysis For [Blue|Purple] Teams in Cyber Defence · 105d ago pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner. For [Blue|Purple] Teams in Cyber Defence · 105d ago month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only For [Blue|Purple] Teams in Cyber Defence · 105d ago Microsoft tests modern Windows Run, says it's faster than legacy dialog BleepingComputer · 106d ago Edu tech firm Instructure discloses cyber incident, probes impact BleepingComputer · 106d ago For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall. Technical Information Security Content & Discussion · 106d ago Small models are better at cost-to-recall than large models like Mythos for vulnerability research hacking: security in practice · 106d ago Every incident public companies have disclosed to the SEC, in one searchable database Technical Information Security Content & Discussion · 106d ago 76% of All Crypto Stolen in 2026 Is Now in North Korea darkreading · 106d ago Bluetooth Spoofed Disconnect? hacking: security in practice · 106d ago Why my macOS Messages badge lied to me (and the one-line fix) Reverse Engineering · 106d ago 15-year-old detained over French govt agency data breach BleepingComputer · 106d ago Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself Malware Analysis & Reports · 106d ago Story retracted BleepingComputer · 106d ago Running Adobe’s 1991 PostScript Interpreter in the Browser Reverse Engineering · 106d ago Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :) Reverse Engineering · 106d ago If AI's So Smart, Why Does It Keep Deleting Production Databases? darkreading · 106d ago Minecraft Malware C2 Tracking Malware Analysis & Reports · 106d ago Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations BleepingComputer · 106d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 106d ago Inside RSAC 2026 Cyber Defense Magazine · 106d ago Microsoft fixes Remote Desktop warnings displaying incorrectly BleepingComputer · 106d ago Name That Toon: Mark of (Security) Progress darkreading · 106d ago 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage darkreading · 106d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 106d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 106d ago Careful Adoption of Agentic AI Services All CISA Advisories · 106d ago Microsoft now lets admins choose pre-installed Store apps to uninstall BleepingComputer · 106d ago wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ... hacking: security in practice · 106d ago Windows 11 KB5083631 update released with 34 changes and fixes BleepingComputer · 106d ago Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster Technical Information Security Content & Discussion · 106d ago US ransomware negotiators get 4 years in prison over BlackCat attacks BleepingComputer · 107d ago /r/ReverseEngineering's Triannual Hiring Thread Reverse Engineering · 107d ago In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off) Reverse Engineering · 107d ago TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack darkreading · 107d ago 🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀 hacking: security in practice · 107d ago Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug darkreading · 107d ago Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber darkreading · 107d ago New Bluekit phishing service includes an AI assistant, 40 templates BleepingComputer · 107d ago Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM Security | Microsoft Azure Blog | Microsoft Azure · 107d ago Innovator Spotlight: The Open Group Cyber Defense Magazine · 107d ago Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight Reverse Engineering · 107d ago SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents The Last Watchdog · 107d ago I made a lightweight breach intelligence search engine (fully client-side) looking for feedback hacking: security in practice · 107d ago Oracle Red Bull Racing Team Revs Up Automation to Boost Security darkreading · 107d ago Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan... hacking: security in practice · 107d ago Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark Cyber Defense Magazine · 107d ago Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool hacking: security in practice · 107d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 107d ago ABB AWIN Gateways All CISA Advisories · 107d ago ABB Ability OPTIMAX All CISA Advisories · 107d ago ABB PCM600 All CISA Advisories · 107d ago ABB Edgenius Management Portal All CISA Advisories · 107d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 107d ago ABB Ability Symphony Plus Engineering All CISA Advisories · 107d ago ABB System 800xA, Symphony Plus IEC 61850 All CISA Advisories · 107d ago Seventeen vulnerabilities in Omi, fourteen days of silence Technical Information Security Content & Discussion · 107d ago High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940) Technical Information Security Content & Discussion · 107d ago This month in security with Tony Anscombe – April 2026 edition WeLiveSecurity · 107d ago HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try! Reverse Engineering · 108d ago GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter). Reverse Engineering · 108d ago Copy Fail — 732 Bytes to Root hacking: security in practice · 108d ago ZDI-CAN-30796: Docker ZDI: Upcoming Advisories · 108d ago Claude Mythos Fears Startle Japan's Financial Services Sector darkreading · 108d ago Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root Technical Information Security Content & Discussion · 108d ago Reverse Engineering With AI Unearths High-Severity GitHub Bug darkreading · 108d ago AI Finds 38 Security Flaws in Electronic Health Record Platform darkreading · 108d ago The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs Technical Information Security Content & Discussion · 108d ago The Thymeleaf Template Injection That Only Hurts If You Let It Technical Information Security Content & Discussion · 108d ago Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error darkreading · 108d ago GitHub fixes RCE flaw that gave access to millions of private repos hacking: security in practice · 108d ago Minirat malware deployed via NPM targeting macOS machines Malware Analysis & Reports · 108d ago Set up automated dependency scanning after the recent npm/PyPI supply chain attacks Technical Information Security Content & Discussion · 108d ago Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints Cyber Defense Magazine · 108d ago Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities darkreading · 108d ago I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway Reverse Engineering · 108d ago Adapting Zero Trust Principles to Operational Technology All CISA Advisories · 108d ago How to download Kaggle dataset safely...? hacking: security in practice · 108d ago VECT Ransomware Is Actually a Wiper Malware Analysis & Reports · 108d ago VECT Ransomware Is Actually a Wiper hacking: security in practice · 108d ago The Malware Factory: GLASSWORM Forensics in Open VSX Malware Analysis & Reports · 109d ago A Route to Root in a 4G Industrial Router Technical Information Security Content & Discussion · 109d ago BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures darkreading · 109d ago NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later darkreading · 109d ago Feuding Ransomware Groups Leak Each Other's Data darkreading · 109d ago Vidar Rises to Top of Chaotic Infostealer Market darkreading · 109d ago Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore Malware Analysis & Reports · 109d ago Innovator Spotlight: Puneet Bhatnagar Cyber Defense Magazine · 109d ago Flipper Blackhat April Roundup! hacking: security in practice · 109d ago Building a perfect clone of 1993 game SimTower (via RE) Reverse Engineering · 109d ago [ Removed by Reddit ] Malware Analysis & Reports · 109d ago [VulnPath Update] Automated Email Alerting & CISA KEV Feed hacking: security in practice · 109d ago Ikeja Electric Distribution Ransomware Malware Analysis & Reports · 109d ago Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain darkreading · 109d ago [Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses) Technical Information Security Content & Discussion · 109d ago How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema Reverse Engineering · 109d ago AI solved our CTF in 6min Reverse Engineering · 109d ago The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords Technical Information Security Content & Discussion · 109d ago Cybersecurity Risks in 2026 Cyber Defense Magazine · 109d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 109d ago NSA GRASSMARLIN All CISA Advisories · 109d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 109d ago Recently updated a authentic minecraft mod launcher called Modrinth Malware Analysis & Reports · 109d ago GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control The Last Watchdog · 109d ago 89 vulnerabilities in XAPI / Citrix XenServer Technical Information Security Content & Discussion · 110d ago Example structure for evidence-based vulnerability reports Reverse Engineering · 110d ago Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters Cyber Defense Magazine · 110d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 110d ago UNC6692 Combines Social Engineering, Malware, Cloud Abuse darkreading · 110d ago Innovator Spotlight: TokenCore Cyber Defense Magazine · 110d ago Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025) Technical Information Security Content & Discussion · 110d ago Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary Technical Information Security Content & Discussion · 110d ago This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0 Malware Analysis & Reports · 110d ago Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation darkreading · 110d ago FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures The Last Watchdog · 110d ago Platform Engineering: The Rise of a Disciplinary Rethink Cyber Defense Magazine · 110d ago Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely Malware Analysis & Reports · 110d ago 60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea? Cyber Defense Magazine · 110d ago MCPwned: a Burp Suite extension for auditing MCP servers Technical Information Security Content & Discussion · 110d ago From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense Cyber Defense Magazine · 111d ago New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses Malware Analysis & Reports · 112d ago Save time and use Zig to write your Malware POC Malware Analysis & Reports · 112d ago Cracking CastleLoader’s Inno Setup Password Malware Analysis & Reports · 113d ago I built a C2 framework that uses Discord and Telegram for communication Malware Analysis & Reports · 113d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog Alerts · 113d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog All CISA Advisories · 113d ago The calm before the ransom: What you see is not all there is WeLiveSecurity · 113d ago fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet. Malware Analysis & Reports · 114d ago Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet Malware Analysis & Reports · 114d ago PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs Malware Analysis & Reports · 114d ago Budgiekit - gdi malware maker (for educational purporses only) Malware Analysis & Reports · 114d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 114d ago SpiceJet Online Booking System All CISA Advisories · 114d ago Carlson Software VASCO-B GNSS Receiver All CISA Advisories · 114d ago Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera All CISA Advisories · 114d ago Milesight Cameras All CISA Advisories · 114d ago Defending Against China-Nexus Covert Networks of Compromised Devices All CISA Advisories · 114d ago Yadea T5 Electric Bicycle All CISA Advisories · 114d ago Intrado 911 Emergency Gateway (EGW) All CISA Advisories · 114d ago GopherWhisper: A burrow full of malware WeLiveSecurity · 114d ago News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category The Last Watchdog · 115d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 115d ago 19 confirmed repos tied to the same GitHub malware campaign Malware Analysis & Reports · 115d ago Defending Against China-Nexus Covert Networks of Compromised Devices CISA Cybersecurity Advisories · 116d ago IOCX v0.7.0 — deterministic heuristics + adversarial PE samples Malware Analysis & Reports · 116d ago New NGate variant hides in a trojanized NFC payment app WeLiveSecurity · 116d ago Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one The Last Watchdog · 117d ago Supply Chain Compromise Impacts Axios Node Package Manager Alerts · 117d ago CISA Adds Eight Known Exploited Vulnerabilities to Catalog Alerts · 117d ago What the ransom note won’t say WeLiveSecurity · 117d ago That data breach alert might be a trap WeLiveSecurity · 120d ago Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business Blog Articles - Identity Insights | Trulioo · 121d ago Supply chain dependencies: Have you checked your blind spot? WeLiveSecurity · 121d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 121d ago News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security The Last Watchdog · 122d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 123d ago GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags The Last Watchdog · 123d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 124d ago Recovery scammers hit you when you’re down: Here’s how to avoid a second strike WeLiveSecurity · 127d ago News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk The Last Watchdog · 128d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 129d ago FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense The Last Watchdog · 130d ago As breakout time accelerates, prevention-first cybersecurity takes center stage WeLiveSecurity · 130d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 131d ago Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure CISA Cybersecurity Advisories · 131d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 135d ago Azure IaaS: Keep critical applications running with built-in resiliency at scale Security | Microsoft Azure Blog | Microsoft Azure · 136d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 136d ago Digital assets after death: Managing risks to your loved one’s digital estate WeLiveSecurity · 136d ago This month in security with Tony Anscombe – March 2026 edition WeLiveSecurity · 137d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 138d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 141d ago RSAC 2026 wrap-up – Week in security with Tony Anscombe WeLiveSecurity · 141d ago A cunning predator: How Silver Fox preys on Japanese firms this tax season WeLiveSecurity · 142d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 142d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 143d ago Virtual machines, virtually everywhere – and with real security gaps WeLiveSecurity · 143d ago Cloud workload security: Mind the gaps WeLiveSecurity · 144d ago What is Customer Due Diligence (CDD) Blog Articles - Identity Insights | Trulioo · 145d ago Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud Blog Articles - Identity Insights | Trulioo · 148d ago CISA Adds Five Known Exploited Vulnerabilities to Catalog Alerts · 148d ago Move fast and save things: A quick guide to recovering a hacked account WeLiveSecurity · 148d ago EDR killers explained: Beyond the drivers WeLiveSecurity · 149d ago Face value: What it takes to fool facial recognition WeLiveSecurity · 155d ago Cyber fallout from the Iran war: What to have on your radar WeLiveSecurity · 156d ago AML, KYC and Identity Verification in Australia Blog Articles - Identity Insights | Trulioo · 157d ago SSL/TLS Certificate Lifespans Are Decreasing to 200 Days InfoSec Insights · 157d ago AI in Tax Season: Risks, Scams, and How to Protect Your Data Fraud Prevention Archives - Alloy Silverstein · 163d ago Security-driven Rapid Release - Pwn2Own Documentary (Part 4) LiveOverflow · 164d ago Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure Security | Microsoft Azure Blog | Microsoft Azure · 164d ago Firefox JIT Bug - Pwn2Own Documentary (Part 3) LiveOverflow · 167d ago Tax Season Scams to Watch For This Year Fraud Prevention Archives - Alloy Silverstein · 170d ago The First Exploit - Pwn2Own Documentary (Part 2) LiveOverflow · 171d ago The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1) LiveOverflow · 174d ago I built a kernel-level EDR and hit architectural walls I didn’t expect Malware Analysis & Reports · 177d ago Update your detection rules: New remote access Trojan Malware Analysis & Reports · 178d ago Criminals are using AI website builders to clone major brands Malware Analysis & Reports · 178d ago Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants) Malware Analysis & Reports · 179d ago Azure reliability, resiliency, and recoverability: Build continuity by design Security | Microsoft Azure Blog | Microsoft Azure · 179d ago PE Loader For Fileless Malware Malware Analysis & Reports · 180d ago Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers Malware Analysis & Reports · 180d ago AWAKE - Android Wiki of Attacks, Knowledge & Exploits Malware Analysis & Reports · 180d ago I built a Chrome extension that scans for malicious extensions (yes, I see the irony) Malware Analysis & Reports · 180d ago Questions regarding malicious pdf's Malware Analysis & Reports · 182d ago AV persistence bypass techniques Malware Analysis & Reports · 182d ago Avalon Linux Bot Malware Analysis Malware Analysis & Reports · 183d ago Leveling up in Windows malware research Malware Analysis & Reports · 185d ago Emerging Ransomware: BQTLock and GREENBLOOD Malware Analysis & Reports · 185d ago Malware Development POCs Malware Analysis & Reports · 186d ago Suspicious code in Up-work linked repository. Malware Analysis & Reports · 186d ago We hid backdoors in binaries — Opus 4.6 found 49% of them Malware Analysis & Reports · 186d ago 👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡 Malware Analysis & Reports · 187d ago Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions Malware Analysis & Reports · 188d ago Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer Malware Analysis & Reports · 189d ago Nyxara Malware Analysis & Reports · 191d ago When Fraud Becomes Background Noise: The Industrialization of Digital Deception Blog Articles - Identity Insights | Trulioo · 222d ago The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage Blog Articles - Identity Insights | Trulioo · 222d ago The End of Static KYB: Business Identity in Constant Motion Blog Articles - Identity Insights | Trulioo · 222d ago Know Your Agent: The Next Chapter in Digital Trust Blog Articles - Identity Insights | Trulioo · 222d ago When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage Blog Articles - Identity Insights | Trulioo · 222d ago Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration Blog Articles - Identity Insights | Trulioo · 241d ago Beware of Misleading Tax Advice on Social Media Fraud Prevention Archives - Alloy Silverstein · 338d ago Scammers Up Their Game With AI Fraud Prevention Archives - Alloy Silverstein · 340d ago Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs STÖK · 356d ago The Essential Guide to Safeguarding Your Online Passwords Fraud Prevention Archives - Alloy Silverstein · 417d ago How FIN6 Exfiltrates Files Over FTP HackerSploit · 493d ago From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi LiveOverflow · 494d ago The German Hacking Championship LiveOverflow · 519d ago Beware: Tax Season is Scam Season Fraud Prevention Archives - Alloy Silverstein · 528d ago Do you know this common Go vulnerability? LiveOverflow · 533d ago Stop Scams: Fraud Prevention Starts with Your Employees Fraud Prevention Archives - Alloy Silverstein · 542d ago Emulating FIN6 - Active Directory Enumeration Made EASY HackerSploit · 544d ago The SECRET to Embedding Metasploit Payloads in VBA Macros HackerSploit · 549d ago Offensive VBA 0x4 - Reverse Shell Macro with Powercat HackerSploit · 558d ago Offensive VBA 0x3 - Developing PowerShell Droppers HackerSploit · 564d ago Offensive VBA 0x2 - Program & Command Execution HackerSploit · 568d ago Offensive VBA 0x1 - Your First Macro HackerSploit · 570d ago Emulating FIN6 - Gaining Initial Access (Office Word Macro) HackerSploit · 576d ago FIN6 Adversary Emulation Plan (TTPs & Tooling) HackerSploit · 579d ago Developing An Adversary Emulation Plan HackerSploit · 579d ago Introduction To Advanced Persistent Threats (APTs) HackerSploit · 584d ago Introduction To Adversary Emulation HackerSploit · 605d ago ‘Tis the Season for Holiday Shopping Scams Fraud Prevention Archives - Alloy Silverstein · 614d ago Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion HackerSploit · 614d ago Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1) LiveOverflow · 668d ago My theory on how the webp 0day was discovered #short LiveOverflow · 684d ago My theory on how the webp 0day was discovered (BLASTPASS) LiveOverflow · 685d ago Learn Android Hacking! - University Nevada, Las Vegas (2024) LiveOverflow · 711d ago DEF CON & Black Hat Trip 2024 LiveOverflow · 725d ago Planning Red Team Operations | Scope, ROE & Reporting HackerSploit · 754d ago Mapping APT TTPs With MITRE ATT&CK Navigator HackerSploit · 758d ago IRS Issues “Dirty Dozen” Fraud Warnings Fraud Prevention Archives - Alloy Silverstein · 800d ago IRS Identity Theft Season Begins Now Fraud Prevention Archives - Alloy Silverstein · 929d ago Finding The .webp Vulnerability in 8s (Fuzzing with AFL++) LiveOverflow · 936d ago Winter vanlife = good times STÖK · 958d ago What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth! STÖK · 965d ago Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma STÖK · 971d ago IS THIS THE END? STÖK · 1031d ago Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites STÖK · 1186d ago The World’s Identity Platform Blog Articles - Identity Insights | Trulioo · 1293d ago How to turn bugs into a "passive" income stream! ft Detectify's Almroot STÖK · 1426d ago HOW DID THIS HAPPEN!? (13370822 LHE VLOG) STÖK · 1440d ago Student Loan Breach Exposes 2.5M Records Threatpost · 1445d ago Watering Hole Attacks Push ScanBox Keylogger Threatpost · 1446d ago Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms Threatpost · 1447d ago Ransomware Attacks are on the Rise Threatpost · 1450d ago Cybercriminals Are Selling Access to Chinese Surveillance Cameras Threatpost · 1451d ago Twitter Whistleblower Complaint: The TL;DR Version Threatpost · 1452d ago Firewall Bug Under Active Attack Triggers CISA Warning Threatpost · 1453d ago Fake Reservation Links Prey on Weary Travelers Threatpost · 1454d ago iPhone Users Urged to Update to Patch 2 Zero-Days Threatpost · 1457d ago Google Patches Chrome’s Fifth Zero-Day of the Year Threatpost · 1458d ago Q: How to write a BUG BOUNTY report that actually gets paid? STÖK · 1556d ago KYC: 3 Steps to Achieving Know Your Customer Compliance Blog Articles - Identity Insights | Trulioo · 1564d ago facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques.. STÖK · 1570d ago AML Compliance Checklist: Best Practices for Anti-Money Laundering Blog Articles - Identity Insights | Trulioo · 1579d ago Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!) STÖK · 1584d ago Q: HOW do you get started in bug bounty?? How do you build your automation?! STÖK · 1598d ago Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR) STÖK · 1612d ago
Latest
Help Net SecurityWeek in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayBlack HatBlack Hat Asia 2026 | Cyber-Paleontology in the Age of AIBlack HatBlack Hat Asia 2026 | Discovering React2Shell: JavaScript’s Long-Awaited Deserialization Flight-mareIppSecHackTheBox - CobblestoneBleepingComputerNew Evooo1Bot Linux botnet turns routers into traffic relay nodesLatest newsNo space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntableMSRC Security Update GuideChromium: CVE-2026-19560 Use after free in BlinkMSRC Security Update GuideChromium: CVE-2026-19559 Use after free in HTMLMSRC Security Update GuideChromium: CVE-2026-19558 Use after free in ExtensionsMSRC Security Update GuideChromium: CVE-2026-19557 Use after free in TabStripMSRC Security Update GuideChromium: CVE-2026-19556 Use after free in V8BleepingComputerHow Anthropic plans to watermark Claude's AI-generated textSecurity LatestNew York City Lawmakers Push to ‘Ban the Scan’ at MSGThe Record from Recorded Future NewsInvestigation of banking hack leads to arrests in Europe, BrazilBlack HatBlack Hat Asia 2026 | Post-Quantum Cryptography: A Realistic Guide to Manage the TransitionCisco Security AdvisoryCisco Advance Notification for Publication of August 19, 2026, Security AdvisoriesSecurity - Ars TechnicaVulnerability giving attackers full control of Macs is under active exploitationBleepingComputerHackers arrested over €30M bank fraud exploiting service provider flawNetworkChuckyour home router STILL SUCKS!! (use OPNsense instead)Black HatBlack Hat Asia 2026 | Network Operations Center (NOC) ReportHelp Net SecurityWeek in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-dayBlack HatBlack Hat Asia 2026 | Cyber-Paleontology in the Age of AIBlack HatBlack Hat Asia 2026 | Discovering React2Shell: JavaScript’s Long-Awaited Deserialization Flight-mareIppSecHackTheBox - CobblestoneBleepingComputerNew Evooo1Bot Linux botnet turns routers into traffic relay nodesLatest newsNo space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntableMSRC Security Update GuideChromium: CVE-2026-19560 Use after free in BlinkMSRC Security Update GuideChromium: CVE-2026-19559 Use after free in HTMLMSRC Security Update GuideChromium: CVE-2026-19558 Use after free in ExtensionsMSRC Security Update GuideChromium: CVE-2026-19557 Use after free in TabStripMSRC Security Update GuideChromium: CVE-2026-19556 Use after free in V8BleepingComputerHow Anthropic plans to watermark Claude's AI-generated textSecurity LatestNew York City Lawmakers Push to ‘Ban the Scan’ at MSGThe Record from Recorded Future NewsInvestigation of banking hack leads to arrests in Europe, BrazilBlack HatBlack Hat Asia 2026 | Post-Quantum Cryptography: A Realistic Guide to Manage the TransitionCisco Security AdvisoryCisco Advance Notification for Publication of August 19, 2026, Security AdvisoriesSecurity - Ars TechnicaVulnerability giving attackers full control of Macs is under active exploitationBleepingComputerHackers arrested over €30M bank fraud exploiting service provider flawNetworkChuckyour home router STILL SUCKS!! (use OPNsense instead)Black HatBlack Hat Asia 2026 | Network Operations Center (NOC) Report
By Source
Feeds organized so you can skim by site.
Density
Sort
BH
Black Hat
8h ago · 15 items
Black Hat Asia 2026 | Cyber-Paleontology in the Age of AI
8h ago
Black Hat Asia 2026 | Discovering React2Shell: JavaScript’s Long-Awaited Deserialization Flight-mare
10h ago
Black Hat Asia 2026 | Post-Quantum Cryptography: A Realistic Guide to Manage the Transition
1d ago
Black Hat Asia 2026 | Network Operations Center (NOC) Report
1d ago
Black Hat Asia 2026 | Hidden Telemetry: Uncovering TraceLogging ETW Providers You're Not Using (Yet)
1d ago
Black Hat Asia 2026 | Beyond the Golden Image: A Self-Healing Image Supply Chain
2d ago
Black Hat Asia 2026 | Inside Cybercrime Inc: Lessons From Covering the Global Fraud Boom
2d ago
Black Hat Asia 2026 | Keynote: Privacy is the Captain. Security is the Practice.
2d ago
Black Hat Vault | Cyber Granny
2d ago
Black Hat Stories | Daniel Cuthbert
2d ago
Black Hat Stories | More Than a Conference
3d ago
Three Decades of Influence | Why Black Hat Matters
4d ago
Black Hat Stories | Gaurav Keerthi, CEO and founder of StrongKeep
4d ago
Black Hat USA 2026 | Reverse Engineering GCD, XPC Races, and macOS Detection
8d ago
Black Hat USA 2026 | Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius
8d ago
15 loaded
IP
IppSec
17h ago · 15 items
HackTheBox - Cobblestone
17h ago
HackTheBox - Helix
7d ago
HackTheBox - Kobold
14d ago
HackTheBox - Fries
21d ago
HackTheBox Logging
28d ago
HackTheBox - CCTV
35d ago
HackTheBox - DevArea
42d ago
HackTheBox - WingData
49d ago
HackTheBox - Nanocorp
56d ago
HackTheBox - VariaType
63d ago
HackTheBox - Facts
70d ago
HackTheBox - Interpreter
77d ago
HackTheBox - MonitorsFour
84d ago
HackTheBox - Pterodactyl
91d ago
HackTheBox - Overwatch
98d ago
15 loaded
BL
BleepingComputer
17h ago · 762 items
New Evooo1Bot Linux botnet turns routers into traffic relay nodes
17h ago
A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes.
How Anthropic plans to watermark Claude's AI-generated text
1d ago
It could soon become easier to identify AI-generated content, even if it's not the usual
Hackers arrested over €30M bank fraud exploiting service provider flaw
1d ago
Four cybercriminals were arrested in Brazil, and three others were charged in Europe over allegations that they exploited a vulnerability at a service provider, allowing them to withdraw funds from Commerzbank customers' bank accounts.
Hackers exploit macOS Screen Sharing flaw to deploy Monero miner
1d ago
The Netherlands' National Cyber Security Centre (NCSC) is warning that hackers are actively exploiting a macOS authentication bypass vulnerability after public exploit code emerged.
The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI
1d ago
Google Workspace attacks do not always begin with phishing. Stolen OAuth tokens can provide another path into Gmail, Drive, and connected systems. Material Security explains why organizations need defenses that cover the entire Workspace at...
Max severity SAP Commerce Cloud flaw now targeted in attacks
1d ago
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.
Shell investigates 'potential incident' after Clop data theft claims
1d ago
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
RingCentral data breach exposed info of 1.6 million accounts
1d ago
The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.
Data analyst sent to prison for stealing data, extorting employer
1d ago
A former data analyst contractor for Brightly Software has been sentenced to two years in prison for targeting his employer in a $2.5 million extortion scheme.
Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks
2d ago
You're not alone if you just received an
Ukraine shuts down 94 fraudulent call centers, seize millions in cash
2d ago
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt
2d ago
Hackers breach govt webmail while running parallel crypto fraud
2d ago
Microsoft patches LegacyHive Windows zero-day vulnerability
2d ago
AI 'watermark removers' flood the web. Almost none can prove they work.
2d ago
Critical VMware vCenter RCE flaw exploited for reverse SSH access
2d ago
Trezor discloses data breach affecting nearly 14,000 customers
2d ago
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
2d ago
White House taps security firms for offensive hack-back operations
2d ago
WhatsApp rolls out new feature that flags potential scam messages
2d ago
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
3d ago
Android malware combo takes out loans and relays victims' credit cards
3d ago
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
3d ago
Hundreds of fake Chrome VPN extensions route traffic through a proxy
3d ago
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
3d ago
Lazarus hackers exploited Windows zero-day to target defense firms
3d ago
FBI: Hackers target online accounts to steal nude photos
3d ago
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
3d ago
Hackers leverage new Microsoft SharePoint exploit in attacks
3d ago
Signal adds new security feature to thwart man-in-the-middle attacks
3d ago
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
3d ago
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
4d ago
DeadLock ransomware uses blockchain to resist infrastructure takedown
4d ago
Sandworm hackers target IT pros with trojanized WireGuard VPN client
4d ago
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
4d ago
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
4d ago
Microsoft releases Windows 10 KB5120249 extended security update
4d ago
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
4d ago
Windows 11 KB5121003 & KB5120240 cumulative updates released
4d ago
Wesco confirms security incident after ExfilSquad claims data theft
4d ago
Mozilla updates GPG signing key for Firefox releases after exposure
4d ago
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
4d ago
DDoS attacks over 1 Tbps surged fivefold in the second quarter
4d ago
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
4d ago
Cisco warns of high-severity ClamAV flaws with public exploits
4d ago
US and South Korea warn of Gunra ransomware targeting govt agencies
4d ago
Hackers breached a small Polish energy plant via private APN last year
5d ago
BdThemes plugins supply-chain hack creates rogue WordPress admins
5d ago
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
5d ago
New StormEncryptor ransomware used by former Medusa affiliate
5d ago
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
5d ago
When Credentials Are No Longer Enough: Device Trust in the AI Era
5d ago
Member of The Com sent to prison for blackmail, sextortion
5d ago
LexisNexis shuts down services after suspicious activity on servers
5d ago
Valve notifies Steam hardware customers of a data breach
5d ago
Critical Progress LoadMaster flaw now actively exploited in attacks
5d ago
Hackers breach TrueConf to trojanize client installers with backdoors
7d ago
Metabase SQLi zero-day exploited in customer data-theft attacks
8d ago
Unlimited Technology Systems breach impacts 3.8 million people
8d ago
Levi Strauss & Co. says hackers stole corporate data in cyberattack
8d ago
Real emails, hijacked payments: Two H1 2026 attack chains
8d ago
North Carolina Ports confirms cyberattack disrupting operations
8d ago
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
9d ago
ClickFix attack pushes macOS infostealer for crypto theft attacks
9d ago
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
9d ago
Swiss government SharePoint breach compromised 200 accounts
9d ago
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
9d ago
Meta AI model hacked a company during misconfigured cyber test
9d ago
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
9d ago
Ransom Cartel ransomware creator sentenced to 16 years in prison
10d ago
Canadian pleads guilty to Snowflake cloud data-theft attacks
10d ago
Hackers run khunt post-exploitation toolkit from Oracle database
10d ago
COLDCARD security audit phishing attack installs remote access tool
10d ago
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
10d ago
Google Blogger locks hundreds of blogs in malware false positive
10d ago
How AI-powered phishing killed blocklists for good
10d ago
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
11d ago
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
11d ago
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
11d ago
New XCSSET variant targets macOS devs via compromised Xcode projects
11d ago
77 Open VSX extensions found harvesting developer info
11d ago
Massive ChainDrop npm supply-chain attack infects hundreds of packages
11d ago
Varonis Agent IBAC keeps AI agents within their intended boundaries
11d ago
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
12d ago
New Pass-ta-key attacks let malware hijack Google-synced passkeys
12d ago
New DOUBLECUP ClickFix service hides malware in browser cache images
12d ago
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
12d ago
N-able warns of N-central auth bypass flaw exploited in attacks
12d ago
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
12d ago
Inside the Underground Business of the Android BTMOB RAT malware
12d ago
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
13d ago
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
13d ago
Google Chrome may soon block New Tab hijacker extensions by default
13d ago
Rails patches critical Active Storage flaw with RCE potential
14d ago
Amgen says cloud data breach exposed patient health, proprietary info
15d ago
Arch Linux disables AUR package adoption to stop malware flood
15d ago
Online ad firm Adform’s script compromised to steal cryptocurrency
15d ago
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
15d ago
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
15d ago
CISA warns of cyberattacks disrupting U.S. water utilities
15d ago
ESET tracks rise in malicious AI skills and adaptable malware
15d ago
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
16d ago
South Korea fines telco giant KT $39 million for customer data breach
16d ago
JetBrains warns of critical TeamCity remote code execution flaw
16d ago
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
16d ago
VMware fixes three critical flaws allowing auth bypass, VM escapes
16d ago
Google says AI helped Chrome fix 1,072 security bugs in two releases
16d ago
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
16d ago
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
16d ago
Analog Devices discloses data breach, says operations unaffected
16d ago
After the Break-In: What Attackers Do Once They're Already Inside
16d ago
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
17d ago
Cisco warns of FMC static credential flaw exploited in zero-day attacks
17d ago
Anthropic confirms Claude is down worldwide
17d ago
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
17d ago
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
17d ago
Hackers target over 30 Minnesota water utilities in coordinated OT attack
17d ago
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
17d ago
Windows 11 KB5101684 update released with 42 changes and fixes
17d ago
These near-mint ASUS Chromebook refurbs are only $145
17d ago
CubePilot drone software dev hit by DNS hijacking to intercept traffic
18d ago
OpenAI models used Artifactory zero-days to escape to the internet
18d ago
CISA shares advice on isolating vital systems during cyberattacks
18d ago
vBulletin fixes critical pre-auth RCE flaw with public exploit
18d ago
Is Your SSO Protected Against Modern Credential Attacks?
18d ago
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
18d ago
Data breach at medical billing firm MCBS affects 1.26 million people
18d ago
Hackers target US firms in FastJson RCE zero-day attacks
19d ago
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
19d ago
New Dysphoria DDoS botnet spreads to 200k devices worldwide
19d ago
New Certighost PoC exploit lets attackers hijack Windows domains
19d ago
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
19d ago
Coca-Cola confirms data theft in Fairlife ransomware attack
19d ago
Ernst & Young data breach claimed by ShinyHunters extortion gang
19d ago
Shadow AI agents are multiplying. Here's how to find and secure them.
19d ago
GitHub, PyPI add time-absed defenses against supply chain attacks
20d ago
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
21d ago
Malicious sites use JavaScript to build malware in browser memory
21d ago
ShinyHunters data leaks fuel $2,000 sextortion email scam
21d ago
OpenAI confirms ChatGPT is down worldwide
21d ago
OnTrac notifies customers of data breach after network hack
22d ago
Hermes AI agent used to automate attack on Thai Finance Ministry
22d ago
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
22d ago
Microsoft blames massive Microsoft 365 outage on maintenance bug
22d ago
Chick-fil-A data breach affects more than 13,000 customers
22d ago
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
22d ago
Europol flags 4,340 URLs for removal in 'The Com' crackdown
22d ago
Man gets six years for hacking 750 women's Snapchat accounts
22d ago
Clop ransomware targets Windchill, FlexPLM in data theft attacks
23d ago
New Dolphin X malware uses AI to rank high-value targets
23d ago
Australian energy provider Origin says data breach exposes client data
23d ago
Fake Claude app promoted by Bing ads pushes SectopRAT malware
23d ago
Russian hackers exploit Zimbra zero-click flaw for email theft
23d ago
Hackers abuse Notepad++ plugins to stealthily install malware
23d ago
Microsoft 365 outage affects Teams, SharePoint and other services
23d ago
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
23d ago
EU fines Google $1 billion for search, app store antitrust violations
23d ago
New RefluXFS Linux flaw lets attackers gain root privileges
23d ago
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
23d ago
Microsoft working to fix Exchange Online mailbox quarantine issue
23d ago
Check Point warns of SmartConsole zero-day exploited in attacks
23d ago
Upbound says hack caused $13 million in fraudulent Acima leases
24d ago
South Korea discloses data breach impacting diplomats worldwide
24d ago
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
24d ago
How enterprise GenAI can amplify ransomware risk — and how to contain it
24d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
24d ago
Adobe Chrome extension flaw let sites access private WhatsApp chats
24d ago
CISA orders urgent action on actively exploited Langflow RCE flaw
24d ago
Stop renting storage space — this lifetime 2TB plan is yours for $59
24d ago
Microsoft to stop Exchange 2016 / 2019 security updates in October
24d ago
Chick-fil-A discloses data breach after credential stuffing attacks
25d ago
OpenAI says its AI models hacked Hugging Face during testing
25d ago
Police dismantle Kratos phishing platform, arrest developer
25d ago
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
25d ago
Critical SharePoint RCE flaw exploited to steal machine keys
25d ago
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
25d ago
Critical wp2shell WordPress flaws exploited to install webshells
25d ago
Closing the Identity Gaps in Critical Infrastructure Security
25d ago
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
25d ago
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
25d ago
Microsoft shares manual fix for WSUS sync delays and timeouts
25d ago
Windows LegacyHive zero-day flaw gets free, unofficial patches
25d ago
Estée Lauder discloses data breach via Oracle E-Business flaw
26d ago
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
26d ago
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
26d ago
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
26d ago
JadePuffer agentic attacks now target AI model data with ransomware
26d ago
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
26d ago
An AI SOC Evaluation Guide for Security Leaders
26d ago
Hugging Face discloses breach linked to autonomous AI agent
26d ago
Microsoft confirms Windows Server Update Services sync delays
26d ago
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
26d ago
Critical ServiceNow code execution flaw now exploited in attacks
26d ago
Hackers abuse ViPNet software to target Russian govt agencies
27d ago
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
28d ago
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
28d ago
Microsoft warns of surge in ACR Stealer attacks on customers
28d ago
The Future of Age Verification: Your Face Never Leaves Your Device
28d ago
Abbott Laboratories probes two cyber incidents amid extortion claims
29d ago
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
29d ago
Ernst & Young discloses data breach after support system hack
29d ago
Inside the Search for "Clean" Residential Proxies for Carding
29d ago
New Windows LegacyHive zero-day gives hackers admin privileges
29d ago
Windows Server 2022 reach end of mainstream support in 90 days
29d ago
US charges two over laundering $43 million from investment fraud
29d ago
CISA urges immediate action on actively exploited Fortinet flaws
30d ago
New ClickLock macOS malware traps users into revealing login password
30d ago
Coca-Cola says Fairlife ransomware attack halts US dairy production
30d ago
Claude Chrome extension flaw lets malicious extensions trigger AI actions
30d ago
New OkoBot framework deploys 20 payloads to steal data, crypto
30d ago
AI Agents Broke the Security Playbook. Here's What Replaces It.
30d ago
23andMe to pay $18 million in new genetics data breach settlement
30d ago
Scattered Spider members behind TfL hack get five years in prison
30d ago
Windows 11 24H2 Home and Pro reach end of support in 90 days
30d ago
CISA orders feds to patch actively exploited Oracle flaw by Saturday
30d ago
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
30d ago
New Spirals ransomware encrypts victim network in under 24 hours
30d ago
Dutch police bust investment fraud ring stealing over €100 million
31d ago
Zoom warns of critical account takeover vulnerability
31d ago
Google Gemini CLI abused as a hacking agent, malware botnet operator
31d ago
AsyncAPI npm packages infected with credential-stealing malware
31d ago
We built a vulnerability vending machine: AI tokens in, zero-days out
31d ago
CISA warns admins to patch actively exploited SharePoint flaws
31d ago
Microsoft: Some Dell PCs shut down after recent Windows updates
31d ago
US charges alleged operators of Russian bulletproof hosting service
32d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
32d ago
Spanish Police take down €140 million cyber fraud ring, arrest four
32d ago
Nearly 300 GitHub repos pose as legit software to push malware
32d ago
Microsoft releases Windows 10 KB5099539 extended security update
32d ago
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
32d ago
Windows 11 KB5101650 & KB5099414 cumulative updates released
32d ago
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
32d ago
LastPass, Bitwarden users targeted with fake security alerts
32d ago
You Don't Have to Run an Exploit to Know If You're Vulnerable
32d ago
Microsoft Entra ID gets passkeys default authentication starting September
32d ago
New phishing kits target Microsoft 365 accounts, evade MFA
32d ago
SAP warns of critical flaws in NetWeaver and Commerce Cloud
32d ago
Microsoft starts testing cleaner Windows Search without ads
32d ago
US sanctions VPN, malware providers for enabling ransomware attacks
32d ago
Japan's largest taxi operator shuts systems after cyberattack
33d ago
Hackers backdoor Jscrambler npm package with infostealer malware
33d ago
New CrashStealer malware poses as Apple crash reporting tool
33d ago
CISA warns of actively exploited RCE flaws in Joomla extensions
33d ago
Lidl discloses online shop breach after service provider hack
33d ago
Breach at the Beach: Play the Ultimate Entra ID CTF
33d ago
UK charges suspects linked to Russian Coms call spoofing platform
33d ago
EU sanctions Russian GRU military hackers over cyberattacks
33d ago
US and allies warn of Russian critical infrastructure attacks
33d ago
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
34d ago
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
34d ago
RedHook Android malware now uses Wireless ADB for shell access
34d ago
Australia warns of global campaign targeting vulnerable CMS platforms
35d ago
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
35d ago
New U-Boot flaws could enable stealthy firmware attacks
36d ago
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
36d ago
Police suspects Dutch hackers were involved in Odido breach
36d ago
Progress urges ShareFile admins to shut down servers over “credible” threat
36d ago
Hackers exploit critical auth bypass in Gitea Docker image
36d ago
Money launderer accused of stealing seized crypto while in prison
36d ago
The Replicant in Your Directory: AI Agents and the Identity Security Gap
36d ago
Zimbra urges customers to patch critical web client XSS flaw
36d ago
Former ransomware negotiator gets 4 years for BlackCat attacks
36d ago
OpenMandriva Linux says contributor tried to sabotage the project
37d ago
Injective SDK on npm infected with cryptocurrency wallet stealer
37d ago
New Helix vishing group emerges in SharePoint data theft attacks
37d ago
Microsoft expects more Windows security updates from AI-discovered flaws
37d ago
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
37d ago
The Hidden Security Risks of Reduced Summer IT Coverage
37d ago
Microsoft to retire the OWA Light client in Exchange Server
37d ago
Police arrests 5,800 suspects in global anti-fraud crackdown
37d ago
AssuranceAmerica data breach exposes records of 6.9 million drivers
38d ago
Microsoft patches RoguePlanet Defender zero-day vulnerability
38d ago
Mount Royal University confirms breach as hackers claim attack
38d ago
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
38d ago
Hackers exploit Roundcube flaw to spy on academic researchers
38d ago
Entra passkey enrollment vishing targets Microsoft 365 users
38d ago
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
38d ago
DuckDuckGo browser now blocks YouTube video ads
38d ago
Telco giant KDDI says data breach affects over 12 million people
38d ago
CISA orders feds to prioritize patching Langflow auth bypass flaw
38d ago
Ubiquiti warns of new max severity UniFi OS vulnerability
38d ago
CISA orders feds to patch max severity ColdFusion flaw by Friday
39d ago
Accenture confirms breach after hacker offers stolen data for sale
39d ago
Chinese hackers develop LONGLEASH malware to expand ORB network
39d ago
Hidden backdoor in Tenda router firmware grants admin access
39d ago
Spain arrests suspected member of pro-Russian hacktivist groups
39d ago
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
39d ago
Webinar tomorrow: Why modern email attacks require a new approach to defense
39d ago
New Januscape Linux flaw allows VM escape on Intel, AMD devices
39d ago
Microsoft to enable Windows settings backup by default for orgs
39d ago
BeyondTrust warns of critical flaws in remote access software
39d ago
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
40d ago
Phishing poses as big-brand job interview to steal Google accounts
40d ago
Fake IT support calls on Microsoft Teams push EtherRAT malware
40d ago
Vietnam arrests suspects behind HiAnime anime piracy service
40d ago
Software Is Now Written at the Speed of Thought. Security Isn't.
40d ago
Max severity Adobe ColdFusion flaw now exploited in attacks
40d ago
Flipper Zero firmware development continues with community help
41d ago
JadePuffer ransomware used AI agent to automate entire attack
42d ago
NetNut proxy network disrupted, 2 million infected devices cut off
43d ago
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
43d ago
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
44d ago
Claude Fable relaunch disappoints users with nerfed performance
44d ago
Google loses final appeal to overturn €4.1 billion EU fine
44d ago
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
44d ago
Microsoft fixes bug that removed Copilot buttons in Outlook
44d ago
Cisco finally confirms attackers exploiting Unified CM flaw
44d ago
CISA: Microsoft SharePoint RCE flaw now actively exploited
44d ago
Opera rolls out Paste Protect feature to fight ClickFix attacks
44d ago
Alleged Scattered Spider hacker extradited to the United States
44d ago
Medtronic notifies customers impacted by ShinyHunters data breach
45d ago
FortiBleed credential-theft campaign linked to Lynx ransomware
45d ago
Kubota says hackers had month-long access to network systems
45d ago
ChocoPoc malware delivered via trojanized exploits on GitHub
45d ago
New ChocoPoC malware targets researchers via trojanized PoC exploits
45d ago
DHS confirms hackers breached HSIN info-sharing platform
45d ago
Webinar: Why traditional email security is no longer enough
45d ago
Hackers target Microsoft 365 accounts with 81 million login attempts
45d ago
Turning Indicators into Intelligence in OpenCTI with Criminal IP
45d ago
Over 900 Oracle E-Business instances exposed to ongoing attacks
45d ago
Microsoft fixes GIF functionality in the Windows Emoji Panel
45d ago
Amazon fined $2.25M for withholding evidence from fraud victims
45d ago
Adobe patches seven max severity ColdFusion, Campaign flaws
46d ago
Anthropic to restore Claude Fable access on Wednesday
46d ago
Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price
46d ago
New BioShocking attack manipulates AI browser into data theft
46d ago
Microsoft accelerates quantum-safe roadmap as risks grow
46d ago
Malicious PyPI packages give hackers control of Telegram bot servers
46d ago
Fake Perplexity extension on Chrome Web Store tracked searches
46d ago
Lessons from the Underground: How to Combat Business Email Compromise
46d ago
Insurance giant Aflac discloses data breach after subsidiary hack
46d ago
Mircosoft adds smarter bot protection to Teams meetings
46d ago
Microsoft adds smarter bot protection to Teams meetings
46d ago
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
46d ago
Blackfield ransomware asks Nidec Corporation for $2 million ransom
46d ago
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
46d ago
Nissan discloses employee data breach linked to Oracle zero-day attacks
47d ago
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
47d ago
WhatsApp rolls out usernames to help users hide their phone number
47d ago
Microsoft extends Windows Server 2022 hotpatching until October 2027
47d ago
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
47d ago
Agentic AI Has an Identity Problem and Attackers Know It
47d ago
Critical SimpleHelp flaw exploited to deploy new stealer malware
47d ago
Hackers now exploit critical Oracle E-Business flaw in attacks
47d ago
Webinar: Why business email compromise attacks keep succeeding
47d ago
US seizes hundreds of FIFA World Cup illegal streaming domains
47d ago
Data breach exposes up to 14.2 million email logins at six ISPs
48d ago
Clean GitHub repo tricks AI coding agents into running malware
49d ago
FBI: Russian hackers now target Signal backup recovery keys
50d ago
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
50d ago
Polymarket customers lose $3 million in supply-chain attack
50d ago
Cybersecurity firms targeted by fraudulent OpenAI organization invites
50d ago
Your First GRC Agent: A Red Teamer's Walkthrough
50d ago
Anthropic is testing desktop-like Claude Cowork for mobile
51d ago
Poland busts SIM-swapping gang tied to millions in crypto theft
51d ago
Order-tracking app Shop abused to push callback phishing attacks
51d ago
Microsoft quietly extends free Windows 10 ESU support to October 2027
51d ago
New macOS malware embeds fake errors to confuse AI analysis tools
51d ago
PirloTV sports piracy network disrupted as 44 domains seized
51d ago
Bluekit phishing kit adopts browser-in-the-middle for login theft
51d ago
The Four Elevations of Effective Fraud Prevention
51d ago
Webinar: Why account takeovers remain one of the hardest threats to stop
51d ago
Google releases new privacy controls for activity history, personalization
52d ago
DraftKings hacker 'Snoopy' sentenced to 18 months in prison
52d ago
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
52d ago
Malicious Edge extension abuses Native Messaging as bridge to malware
52d ago
CISA warns of max severity Ubiquiti flaws exploited in attacks
52d ago
Amadey, StealC malware operations disrupted in Operation Endgame action
52d ago
Securing the service desk: Why social engineering attacks keep succeeding
52d ago
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
52d ago
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
53d ago
Tata Electronics confirms cyberattack as hackers leak data
53d ago
Windows 11 KB5095093 update rolls out new Point-in-Time restore feature
53d ago
Healthtech firm Xolis suffers data breach impacting 1.4 million people
53d ago
New macOS ClickFix attack silently mounts DMGs to push infostealer
53d ago
Scattered Spider members plead guilty to hacking Transport for London
53d ago
The Exploit Doesn't Exist. You Can Still Prove It Works Against You
53d ago
LastPass confirms data breach in Klue supply chain attack
53d ago
Webinar: Why email security teams are drowning in alerts
53d ago
WhatsApp phishing attack uses fake business docs to hack PCs
54d ago
JaredFromSubway MEV bot hacked in $15 million crypto theft
54d ago
FFmpeg fixes PixelSmash flaw in widely used video decoder
54d ago
FortiBleed campaign used custom FortiGate sniffer to steal credentials
54d ago
Microsoft says Windows 11 26H2 is coming soon, details upgrade process
54d ago
Microsoft fixes AutoGen Studio flaw that enabled code execution
54d ago
A Glimpse into the “Search Your Target” Market for Stolen Credentials
54d ago
AryStinger botnet infected thousands of D-Link routers worldwide
55d ago
New Prinz Eugen ransomware prioritizes recent files for encryption
56d ago
Microsoft links Mastra AI supply chain attack to North Korean hackers
56d ago
Klue OAuth breach victim list grows as Icarus hackers claim attack
57d ago
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
57d ago
Texas govt data breach exposes over 3 million driver’s licenses
57d ago
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
57d ago
Webinar: How attackers bypass MFA and how defenders can respond
57d ago
Microsoft: June 2026 Windows updates break Recycle Bin prompts
57d ago
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
57d ago
NY man charged after harassing college student with AI-generated nudes
57d ago
CISA warns Fortinet users to secure devices after FortiBleed leak
58d ago
Gentlemen ransomware uses multiple EDR killers to disable defenses
58d ago
Nintendo confirms data stolen in WebMD subsidiary cyberattack
58d ago
USB worm spreads crypto-stealing malware via Windows shortcut files
58d ago
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
58d ago
5 reasons Microsoft 365 backup isn’t enough for business data protection
58d ago
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
58d ago
ShapedPlugin update flow hacked to infect WordPress sites
58d ago
Apple fixes Beats Studio Buds flaw that let hackers spy on conversations
58d ago
Telegram admits it couldn't police exam-leak channels, India tells court
58d ago
F5 issues out-of-band patches for critical NGINX vulnerabilities
58d ago
Microsoft fixes Windows Server 2016 security update failures
58d ago
Leak confirms OpenAI is testing a ChatGPT for Science subscription
59d ago
Google to use UK and EU user IP addresses for ad personalization
59d ago
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
59d ago
Why Account Takeovers Are Rising and How to Stop Them
59d ago
India's Telegram ban hit the UAE too. Here's how to get around it
59d ago
Microsoft confirms Office apps launch issues after June updates
59d ago
CISA orders feds to patch max severity Joomla plugin flaw by Friday
59d ago
Microsoft working on Defender patch for RoguePlanet zero-day
59d ago
Kodak confirms data breach claimed by ShinyHunters extortion gang
60d ago
Malicious JetBrains Marketplace plugins steal AI API keys from developers
60d ago
New Rokarolla Android malware targets 217 banking, crypto apps
60d ago
Steam Workshop abused to spread malware via Wallpaper Engine app
60d ago
UK to require ID or face scan before you can make social media accounts
60d ago
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
60d ago
FTC warns of record $3.5 billion losses to imposter scams in 2025
60d ago
CISA warns of another cPanel plugin flaw exploited in attacks
60d ago
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
60d ago
Critical Fortinet FortiSandbox flaws now exploited in attacks
60d ago
Windows version of SprySOCKS Linux malware used to attack govt orgs
60d ago
iRhythm discloses data breach, says hackers stole patient info
61d ago
DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
61d ago
SimpleHelp bug lets hackers create rogue remote support accounts
61d ago
OptinMonster WordPress plugin hacked in CDN supply-chain attack
61d ago
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
61d ago
Council of Europe investigates ShinyHunters data breach claims
61d ago
FBI: Fraudsters use couriers to steal money in crypto scams
61d ago
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl
61d ago
Chinese hackers breach REDCap servers, steal medical research
61d ago
New attack turned Microsoft 365 Copilot into 1-click data theft tool
61d ago
Infinite Campus data breach affects 137,000 school staff accounts
61d ago
Webinar: How behavioral AI stops phishing and account takeovers
61d ago
FBI disrupts massive AI-powered phishing service using a million URLs
62d ago
Ex-school district employee jailed for hacks on former employer
63d ago
Chinese hackers hijack auth flow, spy on isolated network for a decade
63d ago
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
63d ago
Maine disables data breach notification portal after fake disclosures
64d ago
phpBB forum fixes auth bypass bug lurking for a decade
64d ago
Ukrainian national pleads guilty to role in Conti ransomware operation
64d ago
Over 400 Arch Linux packages compromised to push rootkit, infostealer
64d ago
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
64d ago
Microsoft fixes Windows update failures linked to WUSA installer
64d ago
Pharma giant Novo Nordisk discloses breach of clinical trials data
64d ago
CISA orders feds to patch actively exploited Ivanti flaw by Sunday
64d ago
Over 73,000 French govt employees affected in Tchap messenger breach
65d ago
Japanese energy firm loses drive with data of 10.9 million clients
65d ago
Maine breach portal abused to publish fake data breach disclosures
65d ago
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
65d ago
Authorities dismantle 'AudiA6' ransomware crypto-laundering service
65d ago
Why AI-driven threats are exposing the limits of MSP security stacks
65d ago
Coupang hit with record $409 million data breach fine in Korea
65d ago
CISA tells govt agencies to patch critical exploited flaws in 3 days
65d ago
Microsoft fixes BitLocker recovery bug on Windows Server 2025
65d ago
Nottingham University data breach affects over 450,000 students
66d ago
Max severity Ivanti Sentry vulnerability now exploited in attacks
66d ago
Path traversal flaw in AI dev platform Langflow exploited in attacks
66d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
66d ago
GitHub announces npm security changes to tackle supply-chain attacks
66d ago
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
66d ago
China-linked JDY botnet expands targeting of U.S. military networks
66d ago
The 5 Best Practices for Secure Identity Verification
66d ago
Microsoft patches Exchange Server zero-day exploited in attacks
66d ago
Microsoft: Some Windows PCs fail to install latest monthly updates
66d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
66d ago
Ivanti: Max severity Sentry flaw allows code execution as root
67d ago
Anthropic rolls out Claude Fable 5, but it's available for a limited time
67d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
67d ago
ServiceNow discloses security incident exposing customer data
67d ago
OpenClaw AI agent found falling for phishing attacks, spills user data
67d ago
SAP fixes critical flaws in NetWeaver and Commerce Cloud
67d ago
Microsoft releases Windows 10 KB5094127 extended security update
67d ago
Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
67d ago
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
67d ago
Windows 11 KB5094126 & KB5093998 cumulative updates released
67d ago
XBOW tests Anthropic's Mythos Preview for offensive security
67d ago
GitHub disables Microsoft repos pushing password-stealing malware
67d ago
New Veeam vulnerability exposes backup servers to RCE attacks
67d ago
French govt messaging service breached in account hijacking attack
67d ago
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
67d ago
Google patches new Chrome zero-day flaw exploited in the wild
68d ago
NFCShare Android malware spreads via fake banking app updates on GitHub
68d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
68d ago
New Apple feature automatically changes your compromised passwords
68d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
68d ago
WhatsApp says it disrupted new NSO spyware phishing attacks
68d ago
Gogs patches critical zero-day enabling remote code execution
68d ago
Critical UniFi OS bug lets hackers gain root without authentication
68d ago
Reducing security operations complexity with Wazuh Cloud
68d ago
Check Point links VPN zero-day attacks to Qilin ransomware gang
68d ago
Oxford University discloses data breach after careers platform hack
68d ago
Over 20,000 Instagram accounts stolen in Meta AI support hack
69d ago
Hands on with Intelligent Terminal, an AI-powered Windows Terminal
69d ago
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
69d ago
Silent Ransom Group targets law firms with fake IT support calls
69d ago
Critical Everest Forms Pro flaw exploited to take over WordPress sites
70d ago
Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
71d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
71d ago
Chinese APT deploys new malware to keep access to hacked networks
71d ago
Dark web Nemesis Market vendor gets 26 years for selling drugs
71d ago
Over 900 US gas station tank gauge systems exposed to attacks
71d ago
What 2026 DBIR Confirms: Attacks Are Living in the Browser
71d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
72d ago
Brave Software releases Origin for a paid, bloat-free browsing experience
72d ago
Hola Browser for Windows compromised to deliver cryptominer
72d ago
Credit card theft campaign abuses Stripe to host stolen payment info
72d ago
DentaQuest data breach exposed info of 2.6 million accounts
72d ago
UN food agency discloses breach affecting 600,000 Gaza households
72d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
72d ago
Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook
72d ago
Microsoft blames unexpected Windows driver updates on caching issue
72d ago
Police dismantles fake ID marketplace used by migrant smugglers
72d ago
Cisco warns of critical Unified CM flaw with PoC exploit code
72d ago
Chinese hackers use new Atlas RAT malware in European cyberattacks
73d ago
The U.S. sanctions Nobitex crypto exchange used by ransomware
73d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
73d ago
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
73d ago
CISA warns of active attacks exploiting Android, Linux bugs
73d ago
What 345 Days of Untested Exposure Looks Like at a Bank
73d ago
Acer working to patch max severity zero-days in Wave 7 routers
73d ago
Police dismantles 9 crime groups in illegal streaming crackdown
73d ago
Google adds Android protection against AI deepfake scam calls
73d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
74d ago
Microsoft's Coreutils project brings Linux commands to Windows
74d ago
OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models
74d ago
Critical Kirki flaw exploited to hijack WordPress admin accounts
74d ago
Over 116,000 Mincraft systems infected in WeedHack malware campaign
74d ago
Over 116,000 Minecraft systems infected in WeedHack malware campaign
74d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
74d ago
Microsoft Exchange Online outage causes email delays, failures
74d ago
Instagram users locked out after Meta AI abused to steal accounts
74d ago
Why the browser is now the front line for AI security
74d ago
CISA flags two-year-old Oracle flaw as actively exploited in attacks
74d ago
Google fixes one actively exploited Android zero-day, 124 flaws
74d ago
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
75d ago
Red Hat npm packages compromised to steal developer credentials
75d ago
Spain arrests doxer leaking sensitive data of govt employees
75d ago
Dashlane password manager users locked out by brute force attacks
75d ago
WordPress malware campaign hides payloads in Steam profiles
75d ago
Microsoft investigates Office Apps, Teams file access issues
75d ago
Race Against Time: Why Faster Vulnerability Alerts Matter
75d ago
Critical Windows Netlogon RCE flaw now exploited in attacks
75d ago
Webinar tomorrow: From alert to resolution in network incident response
75d ago
Microsoft confirms outage affecting MFA, My Sign-Ins platform
75d ago
Microsoft fixes outage affecting MFA setup, MySignIn service
75d ago
Microsoft fixes KB5089549 Windows security update install issues
75d ago
WP Maps Pro bug exploited to create admin accounts on WordPress sites
76d ago
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
77d ago
New CIFSwitch Linux flaw gives root on multiple distributions
77d ago
ChatGPT share links abused to host fake outage pages to deliver malware
78d ago
California AG sues 23andMe over 2023 breach exposing health data
78d ago
From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market
78d ago
Dutch govt disrupts malware botnet with 17 million infected devices
78d ago
Google Chrome adds session cookie theft protection for all users
78d ago
Man sent to prison for selling data of 7 millions elderly Americans
78d ago
US charges Google security engineer with Polymarket insider trading
78d ago
Charter Communications data breach affects 4.9 million accounts
78d ago
Anthropic confirms Claude Mythos-class models will roll out to the public
79d ago
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
79d ago
BTMOB Android malware service generates custom phishing payloads
79d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
79d ago
Hackers exploit FortiClient EMS flaw to push infostealer malware
79d ago
New Gogs zero-day flaw lets hackers get remote code execution
79d ago
How SIEM helps MSPs reduce noise and stop threats faster
79d ago
Romanian gets 5 years in prison for hacking Oregon govt network
79d ago
Webinar: Why network incidents take too long to resolve
79d ago
Carnival Cruise confirms data breach affecting nearly 6 million people
79d ago
Sextortionist sentenced to 33 years for targeting 145 children
79d ago
GPU mining malware spreads via SEO poisoning, AI chatbots
80d ago
Can you enforce strong Active Directory password rules without frustrating users?
80d ago
Glassworm botnet disrupted after resilient C2 infrastructure takedown
80d ago
FBI warns of in-person data theft attacks from extortion gang
80d ago
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
80d ago
Dutch police arrests suspect linked to Ajax football club hack
80d ago
Windows 11 KB5089573 update released with performance improvements
80d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
81d ago
Charter confirms data breach after ShinyHunters extortion threat
81d ago
How Varonis Atlas integrates Claude Compliance API for AI governance
81d ago
Microsoft Defender can now automatically isolate hacked endpoints
81d ago
Webinar: Too many tools are slowing network incident response
81d ago
CISA orders feds to patch actively exploited Drupal vulnerability
81d ago
Microsoft: Domain Controller lookup may fail on Windows Server 2016
82d ago
7-Eleven data breach exposes personal information of 185,000 people
82d ago
Anthropic’s restricted Claude Mythos model may be coming to Claude Code
82d ago
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
82d ago
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
83d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
84d ago
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
84d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
85d ago
Former US execs plead guilty to aiding tech support scammers
85d ago
Trend Micro warns of Apex One zero-day exploited in the wild
85d ago
Drupal: Critical SQL injection flaw now targeted in attacks
85d ago
Why Chargebacks are Just One Piece of the Fraud Puzzle
85d ago
Ubiquiti patches three max severity UniFi OS vulnerabilities
85d ago
US and Canada arrest and charge suspected Kimwolf botnet admin
85d ago
Google accidentally exposed details of unfixed Chromium flaw
86d ago
Apple blocked over $11 billion in App Store fraud in 6 years
86d ago
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
86d ago
Chinese hackers target telcos with new Linux, Windows malware
86d ago
Max severity Cisco Secure Workload flaw gives Site Admin privileges
86d ago
Police seize “First VPN” service used in ransomware, data theft attacks
86d ago
Flipper One project needs community help to build open Linux platform
86d ago
Microsoft warns of new Defender zero-days exploited in attacks
87d ago
GitHub links repo breach to TanStack npm supply-chain attack
87d ago
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
87d ago
Hackers bypass SonicWall VPN MFA due to incomplete patching
87d ago
Grafana breach caused by missed token rotation after TanStack attack
87d ago
Identity Alone Isn't Enough: Why Device Security Has to Share the Load
87d ago
Drupal critical update to fix bug with high exploitation risk
87d ago
Exploit released for new PinTheft Arch Linux root escalation flaw
87d ago
GitHub confirms breach of 3,800 repos via malicious VSCode extension
87d ago
Microsoft shares mitigation for YellowKey Windows zero-day
88d ago
GitHub investigates internal repositories breach claimed by TeamPCP
88d ago
Max-severity flaw in ChromaDB for AI apps allows server hijacking
88d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
88d ago
Discord rolls out end-to-end encryption on voice, video calls
88d ago
FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
88d ago
Microsoft Self-Service Password Reset abused in Azure data theft attacks
88d ago
Microsoft plans to improve Windows 11 driver quality in 2026
88d ago
Microsoft blames macOS update for undismissible Teams location prompts
88d ago
New Shai-Hulud malware wave compromises 600 npm packages
88d ago
7-Eleven confirms data breach claimed by the ShinyHunters gang
88d ago
Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation
88d ago
Webinar: The hidden bottlenecks in network incident response
88d ago
Microsoft confirms patching issues in restricted Windows networks
88d ago
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
89d ago
SHub macOS infostealer variant spoofs Apple security updates
89d ago
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
89d ago
Leaked Shai-Hulud malware fuels new npm infostealer campaign
89d ago
Grafana says stolen GitHub token let hackers steal codebase
89d ago
Microsoft testing adjustable taskbar, Start menu in Windows 11
89d ago
Microsoft confirms Windows 11 security update install issues
89d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
90d ago
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
90d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
90d ago
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
90d ago
Microsoft rejects critical Azure vulnerability report, no CVE issued
91d ago
Russian hackers turn Kazuar backdoor into modular P2P botnet
91d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
92d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
92d ago
Popular node-ipc npm package compromised to steal credentials
92d ago
Avada Builder WordPress plugin flaws allow site credential theft
92d ago
Microsoft backpedals: Edge to stop loading passwords into memory
92d ago
Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
92d ago
Microsoft to automatically roll back faulty Windows drivers
92d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
92d ago
TeamPCP hackers advertise Mistral AI code repos for sale
93d ago
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
93d ago
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
93d ago
OpenAI confirms security breach in TanStack supply chain attack
93d ago
Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026
93d ago
18-year-old NGINX vulnerability allows DoS, potential RCE
93d ago
Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight
93d ago
KongTuke hackers now use Microsoft Teams for corporate breaches
93d ago
Dell confirms its SupportAssist software causes Windows BSOD crashes
93d ago
US charges suspected Dream Market admin arrested in Germany
93d ago
New Fragnesia Linux flaw lets attackers gain root privileges
94d ago
West Pharmaceutical says hackers stole data, encrypted systems
94d ago
Iranian hackers targeted major South Korean electronics maker
94d ago
New critical Exim mailer flaw allows remote code execution
94d ago
Windows BitLocker zero-day gives access to protected drives, PoC released
94d ago
Webinar tomorrow: Why security alone won't stop modern attacks
94d ago
Microsoft fixes BitLocker recovery issue only for Windows 11 users
94d ago
Microsoft fixes Windows Autopatch bug installing restricted drivers
94d ago
Foxconn confirms cyberattack claimed by Nitrogen ransomware gang
94d ago
73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation
94d ago
Microsoft says some users can't install Office on Windows 365 devices
94d ago
US govt seeks Instructure testimony on massive Canvas cyberattack
95d ago
UK fines water supplier $1.3M for exposing data of 664k customers
95d ago
Webinar: Fixing the gaps in network incident response
95d ago
Signal adds security warnings for social engineering, phishing attacks
95d ago
Microsoft releases Windows 10 KB5087544 extended security update
95d ago
Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
95d ago
Windows 11 KB5089549 & KB5087420 cumulative updates released
95d ago
Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days
95d ago
Škoda warns of customer data breach after online shop hack
95d ago
Android 17 to expand banking scam call and privacy protections
95d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
95d ago
SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA
95d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
95d ago
GM agrees to $12.75M California settlement over sale of drivers’ data
96d ago
Official CheckMarx Jenkins package compromised with infostealer
96d ago
New GhostLock tool abuses Windows API to block file access
96d ago
Instructure confirms hackers used Canvas flaw to deface portals
96d ago
Why Changing Passwords Doesn’t End an Active Directory Breach
96d ago
Google: Hackers used AI to develop zero-day exploit for web admin tool
96d ago
Webinar this week: Prevention alone is not enough against modern attacks
96d ago
TrickMo Android banker adopts TON blockchain for covert comms
96d ago
Hackers abuse Google ads, Claude.ai chats to push Mac malware
97d ago
Police shut down reboot of Crimenetwork marketplace, arrest admin
97d ago
JDownloader site hacked to replace installers with Python RAT malware
98d ago
Fake OpenAI repository on Hugging Face pushes infostealer malware
98d ago
NVIDIA confirms GeForce NOW data breach affecting Armenian users
99d ago
Why More Analysts Won’t Solve Your SOC’s Alert Problem
99d ago
Trellix source code breach claimed by RansomHouse hackers
99d ago
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
99d ago
Zara data breach exposed personal information of 197,000 people
99d ago
Former govt contractor convicted for wiping dozens of federal databases
99d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
100d ago
Canvas login portals hacked in mass ShinyHunters extortion campaign
100d ago
New TCLBanker malware self-spreads over WhatsApp and Outlook
100d ago
New PCPJack worm steals credentials, cleans TeamPCP infections
100d ago
Australia warns of ClickFix attacks pushing Vidar Stealer malware
100d ago
Ivanti warns of new EPMM flaw exploited in zero-day attacks
100d ago
The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
100d ago
Americans sentenced for running 'laptop farms' for North Korea
100d ago
Crypto gang member gets 6.5 years for role in $230 million heist
100d ago
Webinar: Why modern attacks require both security and recovery
100d ago
Palo Alto Networks firewall zero-day exploited for nearly a month
100d ago
Fake Claude AI website delivers new 'Beagle' Windows malware
100d ago
Hackers abuse Google ads for GoDaddy ManageWP login phishing
101d ago
Critical vm2 sandbox bug lets attackers execute code on hosts
101d ago
New Cisco DoS flaw requires manual reboot to revive devices
101d ago
DAEMON Tools devs confirm breach, release malware-free version
101d ago
Why ransomware attacks succeed even when backups exist
101d ago
MuddyWater hackers use Chaos ransomware as a decoy in attacks
101d ago
Webinar: Why network incidents escalate and how to fix response gaps
101d ago
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
101d ago
New stealthy Quasar Linux malware targets software developers
102d ago
Instructure hacker claims data theft from 8,800 schools, universities
102d ago
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
102d ago
Student hacked Taiwan high-speed rail to trigger emergency brakes
102d ago
FTC to ban data broker Kochava from selling Americans’ location data
102d ago
The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.
102d ago
The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
102d ago
Vimeo data breach exposes personal information of 119,000 people
102d ago
Google now offers up to $1.5 million for some Android exploits
102d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
102d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
102d ago
ScarCruft hackers push BirdCall Android malware via game platform
102d ago
Weaver E-cology critical bug exploited in attacks since March
103d ago
Amazon SES increasingly abused in phishing to evade detection
103d ago
Researchers report Amazon SES abused in phishing to evade detection
103d ago
Backdoored PyTorch Lightning package drops credential stealer
103d ago
Trellix discloses data breach after source code repository hack
103d ago
They don’t hack, they borrow: How fraudsters target credit unions
103d ago
Progress warns of critical MOVEit Automation auth bypass flaw
103d ago
Webinar: Why MSPs must rethink security and backup strategies
103d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
103d ago
Microsoft confirms April Windows updates cause backup failures
103d ago
Instructure confirms data breach, ShinyHunters claims attack
104d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
104d ago
Telegram Mini Apps abused for crypto scams, Android malware delivery
104d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
105d ago
ConsentFix v3 attacks target Azure with automated OAuth abuse
105d ago
Microsoft tests modern Windows Run, says it's faster than legacy dialog
106d ago
Edu tech firm Instructure discloses cyber incident, probes impact
106d ago
15-year-old detained over French govt agency data breach
106d ago
Story retracted
106d ago
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
106d ago
Microsoft fixes Remote Desktop warnings displaying incorrectly
106d ago
Microsoft now lets admins choose pre-installed Store apps to uninstall
106d ago
Windows 11 KB5083631 update released with 34 changes and fixes
106d ago
US ransomware negotiators get 4 years in prison over BlackCat attacks
107d ago
New Bluekit phishing service includes an AI assistant, 40 templates
107d ago
762 loaded
LN
Latest news
22h ago · 20 items
No space for bookshelf speakers? The Victrola Soundstage sits neatly under my turntable
22h ago
The Victrola Soundstage is ideal for those who want to build their vinyl system up rather than out, with plenty of digital and analog connections for every kind of listener.
Google Meet can take notes for your in-person meetings now - here's how it works
1d ago
Google's Gemini-driven meeting software can now save a transcript, send it to Google Drive, and email you a copy.
I tested an Android app that lets anyone fight censorship - and shows your impact in real time
1d ago
Most apps make our personal lives easier. This one helps the oppressed communicate by turning your phone into a Tor proxy. No technical knowledge needed.
Apple is warning users of new spyware attacks - what to do if you're a target
1d ago
New spyware attacks are aimed at journalists, activists, politicians, diplomats, and others. Here's how Apple is notifying them and what they should do - after turning on Lockdown Mode.
ChatGPT's new Computer History tracks your Mac activity to create a timeline - but should you let it?
1d ago
Rolling out to ChatGPT's Mac app, Computer History creates a timeline from your activities across the apps and websites you use on your Mac. Is that a privacy risk?
Dell XPS 13 review: The first budget laptop to rival Neo raises the bar for all PCs
1d ago
The Dell XPS 13 flaunts build quality rarely seen at this price point, but not without trade-offs.
I used OpenFactory to build my own Linux distro overnight - this AI tool is going to be big
1d ago
Need a custom Linux distribution, but don't have time to learn how to build one? OpenFactory can help you.
This free Android assistant fixes my biggest Gemini frustration - and keeps my data private
2d ago
With Google set to retire Assistant, and Gemini not exactly the replacement many of us want, Dicio is a solid option. There's one catch.
I tried the new ChatGPT Desktop App for Linux - but I'll stick to my browser for now
2d ago
This preview release of ChatGPT Desktop for Linux supports Ubuntu, Debian, and Fedora is here.
Gemini voice calling on Android Auto keeps failing me - and Google has until September to fix it
2d ago
With Google Assistant shutting down this fall, Android users will be left with inferior voice calling, thanks to Gemini.
This Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on sale
2d ago
I wore Samsung's and Apple's Ultra smartwatches for 3 weeks - apps made all the difference
2d ago
You're using DND all wrong: 5 powerful Do Not Disturb settings to try on your iPhone today
2d ago
Microsoft is merging Copilot and Copilot 365 into one unified app - and retiring 3 features
2d ago
75% of developers I surveyed prefer Claude Code - here's why they choose it over Codex
2d ago
Android can now tap to share for contact info, photos, and more - which phones get it first
2d ago
The best password managers of 2026: Expert tested
2d ago
The best antivirus software to protect your computer in 2026
2d ago
'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today
3d ago
Every Amazon Google Pixel 11 preorder deal - get up to $350 on an Amazon gift card, free
3d ago
20 loaded
MS
MSRC Security Update Guide
1d ago · 20 items
Chromium: CVE-2026-19560 Use after free in Blink
1d ago
Chromium: CVE-2026-19559 Use after free in HTML
1d ago
Chromium: CVE-2026-19558 Use after free in Extensions
1d ago
Chromium: CVE-2026-19557 Use after free in TabStrip
1d ago
Chromium: CVE-2026-19556 Use after free in V8
1d ago
CVE-2026-72970 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
1d ago
CVE-2026-61347 Windows Event Logging Service Information Disclosure Vulnerability
1d ago
CVE-2026-62746 Win32k Information Disclosure Vulnerability
1d ago
CVE-2026-62755 Windows DHCP Client Elevation of Privilege Vulnerability
1d ago
CVE-2026-62777 Windows License Manager Elevation of Privilege Vulnerability
1d ago
CVE-2026-65671 Remote Access API Elevation of Privilege Vulnerability
1d ago
CVE-2026-68821 Windows Package Manager Elevation of Privilege Vulnerability
1d ago
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
1d ago
CVE-2026-59126 Windows Event Logging Service Elevation of Privilege Vulnerability
1d ago
CVE-2026-58612 PowerShell Information Disclosure Vulnerability
1d ago
CVE-2026-59119 PowerShell Elevation of Privilege Vulnerability
1d ago
CVE-2026-70337 Microsoft PowerShell Remote Code Execution Vulnerability
1d ago
CVE-2026-70338 Microsoft PowerShell Security Feature Bypass Vulnerability
1d ago
CVE-2026-50523 Microsoft PowerShell Remote Code Execution Vulnerability
1d ago
CVE-2026-69414 Microsoft Defender Elevation of Privilege Vulnerability
1d ago
20 loaded
SL
Security Latest
1d ago · 20 items
New York City Lawmakers Push to ‘Ban the Scan’ at MSG
1d ago
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
2d ago
This Coin-Sized Device Can Hack a Boeing 737
3d ago
‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware
3d ago
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
4d ago
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
7d ago
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
7d ago
Hackers Stalked Me by Hijacking a Smartwatch for Kids
9d ago
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
10d ago
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
10d ago
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
10d ago
DHS Wants Protesters’ Signal Group Chats
10d ago
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
10d ago
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
10d ago
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
10d ago
OK, Well, Rogue AI Agents Are Hacking Again
11d ago
Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
11d ago
ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
12d ago
8 Best Password Managers (2026), Tested and Reviewed
13d ago
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
14d ago
20 loaded
TR
The Record from Recorded Future News
1d ago · 5 items
Investigation of banking hack leads to arrests in Europe, Brazil
1d ago
France investigates tax authority breach after hacker claims 600,000 victims
1d ago
Flock tightens privacy controls amid scandals over officer abuse
2d ago
New Mirai variant adds stealth capabilities to notorious botnet code
2d ago
Brazil orders Discord to suspend livestreaming after teen suicide
2d ago
CS
Cisco Security Advisory
1d ago · 20 items
Cisco Advance Notification for Publication of August 19, 2026, Security Advisories
1d ago
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks Industrial ...
ClamAV Vulnerabilities Affecting Cisco Products: August 2026
2d ago
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For...
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
4d ago
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within th...
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
4d ago
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the d...
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
8d ago
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficien...
Cisco Advance Notification for Publication of August 5, 2026, Security Advisories
10d ago
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst SD-WAN Integra...
Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability
10d ago
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due t...
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
10d ago
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnera...
Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability
10d ago
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could ...
Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability
10d ago
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due...
Cisco IOS XE Software SNMP Denial of Service Vulnerability
10d ago
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
10d ago
Cisco IOS XE Software Security Hardening Release: August 2026
10d ago
Cisco Integrated Management Controller Argument Injection Vulnerabilities
10d ago
Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability
10d ago
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
10d ago
Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability
10d ago
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
10d ago
Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
25d ago
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
26d ago
20 loaded
SA
Security - Ars Technica
1d ago · 20 items
Vulnerability giving attackers full control of Macs is under active exploitation
1d ago
Private security firms will soon be allowed to hack overseas cybercriminals
2d ago
Terabytes of credentials leaked in massive supply-chain attack
3d ago
Researchers found a way to hijack devices through Zoom screen sharing
3d ago
DEF CON crowd suspected in fake-hotspot attack on Delta flight
4d ago
Chrome adopts what may be the best protection yet against account takeovers
4d ago
New surveillance tech links your phone to your license plate
4d ago
New Pass-ta-key attack reveals all the things we didn't know about passkeys
4d ago
A researcher bought noreply.net. Companies started sending him secrets.
5d ago
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
10d ago
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
10d ago
Defcon's new badge is a security key you can see inside
14d ago
Claude published malicious code to the Internet and attacked 3 real companies
15d ago
AI scammers outperform humans when it comes to building trust
15d ago
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
16d ago
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
17d ago
Anthropic is finding bugs faster than Microsoft can fix them
17d ago
We now have a better understanding how OpenAI hacked into Hugging Face
18d ago
Microsoft unveils AI security tools it says outperform competing platforms
19d ago
Activist charged with felony after giving border agent "duress code" that wiped his phone
19d ago
20 loaded
NE
NetworkChuck
1d ago · 15 items
your home router STILL SUCKS!! (use OPNsense instead)
1d ago
OSPF From Zero: Let's Build the Internet (Well...Almost) | Summer of CCNA
9d ago
AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA
23d ago
this Raspberry Pi belongs on your wall
23d ago
I got inside FIFA’s Secret World Cup Broadcast Network
27d ago
LIVE AMA | Summer of CCNA | 07/09/2026
37d ago
Fable 5 is back.....run these prompts before July 12th
44d ago
shadow AI is terrifying
57d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
58d ago
HTTPS Doesn't Hide This From Your ISP!!
58d ago
Cisco Just Showed the Future of Networking
58d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
60d ago
I was wrong about VPNs
61d ago
Certification Questions | LIVE AMA | Summer of CCNA
72d ago
Hermes has a Home Assistant skill and it's unreal!
73d ago
15 loaded
TC
The Cyber Mentors
1d ago · 15 items
Soft Skills for the Job Market: Standing Out!
1d ago
Meet TCM Security at DEF CON 34!
16d ago
Real Folks of Cyber | Andrew Crotty | DITL
17d ago
TCM Course Release | New Creator | Cybersecurity | AMA
24d ago
Soft Skills for the Job Market: Applying for Jobs
36d ago
LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway
38d ago
Celebrating 1 Million Subscribers on July 8th!
44d ago
Real Folks of Cyber | Pearce Barry | Day in the Life
50d ago
Getting Started with the TCM Security Academy
51d ago
Soft Skills for the Job Market: Resume Writing
57d ago
TCM Security Summer Sale is Here!
60d ago
LIVE: 🕵️ CTF Prize Draw | Cybersecurity
66d ago
Secrets to PNPT Debrief Success
67d ago
TCM Security CTF Walkthrough
71d ago
Top 5 Active Directory Pentesting Tools
74d ago
15 loaded
DB
David Bombal
1d ago · 15 items
How to Detect Fake Cell Towers Near You
1d ago
Nobody Uses This Old Stuff!
2d ago
Do You Need a VPN in 2026? Here’s the Truth
6d ago
1.5 Gbps Internet using your old telephone cables?
13d ago
Rediscover Maltego in 2026
16d ago
Qubes OS explained: assume you will get hacked
20d ago
You need to learn Maltego in 2026
23d ago
Want To Learn (For FREE) About A Self-Driving Network?
24d ago
The End of TOKENMAXXING?
24d ago
Is Cat7 a SCAM?
32d ago
Cisco's Agents Reason Like a CCIE
33d ago
Install GrapheneOS Before Your Phone Becomes the Checkpoint
34d ago
Unveiled: Cisco Deep Reasoning
40d ago
Why Apple Hide My Email FAILS
41d ago
New to Linux? This is the best place to start!
41d ago
15 loaded
SE
SecurityWeek
1d ago · 10 items
In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities
1d ago
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
1d ago
Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal
1d ago
1.6 Million Likely Impacted by RingCentral Data Breach
1d ago
Over 1,000 Charities Hit by Beacon CRM Data Breach
1d ago
14,000 Trezor Customers Impacted by Data Breach at ShipMonk
1d ago
Hackers Exploiting Unpatched GeoServer Zero-Day
2d ago
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions
2d ago
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
2d ago
Adobe Commerce Bug Targeted Immediately After Disclosure
2d ago
KO
Krebs on Security
1d ago · 10 items
Who’s Tracking You? Use This New Service to Find Out
1d ago
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and…
Microsoft Plugs Nearly 400 Security Holes
4d ago
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly deta...
Canadian Man Pleads Guilty in Snowflake Extortions
9d ago
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage ...
Read This Before You Buy That TV Streaming Stick
16d ago
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. ...
LG to Ban Residential Proxies from Smart TV Apps
25d ago
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers…
Microsoft Patches a Record 570 Security Flaws
32d ago
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesd...
Lessons Learned from CISA’s Recent GitHub Leak
33d ago
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almos...
Felons, Fraudsters Flog Offensive Cybersecurity Startup
38d ago
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intellige...
FBI Seizes NetNut Proxy Platform, Popa Botnet
44d ago
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technolo...
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
53d ago
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The ...
SE
Securelist
1d ago · 10 items
APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit
1d ago
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Armored Likho expands its cyber-espionage toolkit
3d ago
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
4d ago
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf serve...
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
4d ago
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
IT threat evolution in Q2 2026. Non-mobile statistics
5d ago
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
IT threat evolution in Q2 2026. Mobile statistics
5d ago
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
How legitimate cloud platforms enable phishers to bypass MFA
11d ago
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
An analysis of incidents at Brazilian educational institutions
12d ago
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
Network Anomaly Detection in KATA
15d ago
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
16d ago
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
TI
Technical Information Security Content & Discussion
2d ago · 338 items
From Unauthenticated API to Grid Risk: A Hybrid Inverter Vulnerability Explained
2d ago
Can AI do novel security research? Meet the HTTP Terminator
2d ago
A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
2d ago
CVE-2026-53360: KVM SEV-SNP guest-to-host heap OOB and analysis of the upstream fix
3d ago
ERPNext's Document Follow feature exposed unauthorized data
3d ago
GhostSplice: Malicious MCP Servers Split Instructions to Make AI Coding Agents Exfiltrate Secrets (ASSET Research Group)
4d ago
Expired DMARC reporting endpoint exposed a NYSE Fortune 1000's infrastructure for $10
4d ago
CopyEscape: Container-to-host arbitrary file write via docker cp (CVE-2026-17106)
4d ago
ETW for Security Research: Providers, Sessions, and Detection Engineering
4d ago
SMAP is Pre-Disarmed: How a Stack Pivot That Shouldn't Work Revealed a Kernel-Wide Design Compromise
4d ago
Mandatory User Profile for Persistence & EDR Evasion
4d ago
Inside a Russian-speaking operator's toolkit for compromising Ukrainian IP cameras
5d ago
Beyond Prompt Injection: Hacking Apple's Private Cloud Compute
6d ago
When terrible disclosure from the vendor results in zero days plus a fun dive in to bypassing full disk encryption
6d ago
DEFCON: New Red Team Tactic
7d ago
Analyzing a Multi-Stage PowerShell Payload Chain
7d ago
DEF CON talk: 8 in 10 Banks in Belgium HATE This One Weird eID RCE
7d ago
Write Once, Shell Everywhere - Turning Arbitrary File Writes into RCE (DEF CON Bug Bounty Village)
7d ago
RovoBlast: How One Click Triggered Atlassian’s AI Assistant to Leak Data
8d ago
SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free · Tencent Zhuque Lab
8d ago
What syscall-layer tooling cannot see in P2P infrastructure
22d ago
Announcing the External Penetration Testing Program Pack
22d ago
The way AI voice phishing gets demonstrated is making people worse at spotting it
22d ago
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
23d ago
XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search
23d ago
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
23d ago
Open Evaluation Framework for AI Pentesting Agents on Real-World Targets
23d ago
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA
23d ago
GitHub issues $100,000 bounty for critical RCE vulnerability
24d ago
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
24d ago
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
24d ago
The Hidden CCS2 Attack Surface on EV Chargers
25d ago
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE)
25d ago
Leaking internal headers in Flask Ninja with deserialization
25d ago
Crawling the Complete IPv4 Reverse DNS Space
26d ago
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)
26d ago
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
26d ago
Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable
28d ago
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner
28d ago
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing
28d ago
White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
29d ago
wp2shell: Pre Authentication RCE in WordPress Core
29d ago
Keeping private namespaces private - Quad9 blog
29d ago
Openwrt pre-auth remote root exploit
29d ago
Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454
29d ago
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
30d ago
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
30d ago
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
31d ago
HN Security - My Semgrep C/C++ ruleset is ready for prime time again
31d ago
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
31d ago
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
31d ago
Smashing the ServiceNow Sandbox – Pre Authentication RCE
32d ago
Context Bombs: Using AI Guardrails as a defensive mechanism
33d ago
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
33d ago
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
33d ago
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
34d ago
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
34d ago
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
35d ago
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
36d ago
Towards CSI: What's the best harness? (arXiv 2026)
36d ago
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
37d ago
1 in 2 devices sold in Africa exfiltrate data to China
38d ago
Inside an AI coal mine security camera network powered by plaintext passwords
38d ago
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
38d ago
Bad Epoll: The bug missed by Mythos
39d ago
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
39d ago
New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"
40d ago
Playing Around With ADIDNS RPC Internals
40d ago
Windows Service - Playbook & Detection Strategies
40d ago
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
44d ago
FIFA was saved this time
44d ago
/r/netsec's Q3 2026 Information Security Hiring Thread
45d ago
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
45d ago
r/netsec monthly discussion & tool thread
45d ago
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
46d ago
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
46d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
47d ago
I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well.
48d ago
Dissecting Apple's Sparse Image Format (ASIF)
48d ago
A peek into Reddit's anti-spam internals
49d ago
CVE-2025-52465 geoserver arbitrary file write vulnerability
51d ago
CargoWise WebTracker - The keys were in the cargo
51d ago
Exploiting vulnerabilities in Johnson & Johnson web apps
52d ago
Cloudflare patches Copy-Fail across every server in two days
53d ago
New Cisco RCE was fixed
53d ago
CVE-2026-25860 turn XSS to RCE
54d ago
Exploiting Auth0 Defaults in XSS Attacks - elttam
55d ago
Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1)
55d ago
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530
57d ago
OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099)
57d ago
Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration
57d ago
CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance
58d ago
Would you like some malware served at the very top of DuckDuckGo?
58d ago
Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update
59d ago
QoS Policies to Restrict EDR Traffic and Detection Strategies
59d ago
Getting a CVE Without Shipping Slop
60d ago
PrizeBuzz phishing network analysis
60d ago
27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass
60d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
61d ago
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
61d ago
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
61d ago
Researcher accidentally gained access to a threat actor-controlled phishing website
63d ago
PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs
63d ago
MeshCentral: From XSS to RCE
63d ago
Getting the PID from random numbers in PHP
63d ago
The Axios npm compromise was visible in registry metadata before anyone ran npm install
64d ago
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs
64d ago
Free Compromise Detection for GitHub Repos - Tracebit Community Edition
64d ago
Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)
64d ago
Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery
64d ago
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs
65d ago
Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules
65d ago
Claude Fable 5: mid-tier results on coding tasks
65d ago
Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work
65d ago
Hacking Google with A.I. for $500,000
65d ago
Prompt injection: attacking the analyst's AI
65d ago
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
66d ago
We post-trained a model for offensive security instead of teaching it to refuse
66d ago
How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026
66d ago
FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster
66d ago
certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA"
66d ago
BlackSun - Defender for Endpoint on macOS
67d ago
GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline)
67d ago
Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam
67d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
67d ago
Apple’s Siri-AI, or more shouting into the void about “private” agents
67d ago
Entra Agent ID from a Security Perspective
67d ago
X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection
67d ago
WinGet - Code Execution, Persistence and Detection Strategies
67d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
67d ago
I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information
68d ago
AI Agents May Always Fall for Prompt Injections
68d ago
Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it
68d ago
EDRChoker: Choking The Telemetry Stream to Bypass Defenses
69d ago
PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware
70d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
70d ago
Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption
71d ago
Keeping Secrets Out of Logs
71d ago
Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier)
71d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
72d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
72d ago
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
72d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
72d ago
Season VI of the US Games launches TOMORROW!
73d ago
EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires
73d ago
Interesting- What LLM vuln research looks like
73d ago
Hacking your PC using your speaker without ever touching it
73d ago
Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing
74d ago
Golang code review notes II - elttam
74d ago
Using AI to Secure Its Generated Code Is a Ponzi Scheme
74d ago
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
74d ago
We Added a Detection Rule. We Were Not Expecting This.
74d ago
1-Click GitHub Token Stealing via a VSCode Bug
74d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
74d ago
NuGet Code Execution As A Service
75d ago
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
75d ago
Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider
75d ago
r/netsec monthly discussion & tool thread
75d ago
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
75d ago
Stealing Passwords via HTML Injection Under a Strict CSP
75d ago
Subnet discovery through multi-protocol TTL tracing
76d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
76d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
77d ago
Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters
77d ago
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
78d ago
Introducing Keyhog: The First GPU Accelerated secret scanner
78d ago
OffensiveCon26 YouTube Playlist released
78d ago
1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog
78d ago
I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found.
79d ago
Fooling around with encrypted reasoning blobs
79d ago
CALIF: An AI audit of FreeBSD
79d ago
CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries
79d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
79d ago
Visual Studio Extensions Revisited
79d ago
Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP)
79d ago
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
79d ago
What scanners are actually trying against AI infrastructure
80d ago
Defense by accumulation
80d ago
New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
80d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
80d ago
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
80d ago
HN Security - AI Reporter - Let's automate reporting in Burp Suite!
80d ago
Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records
80d ago
RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact
80d ago
Navigating Lax Load Balancers: When an Intersection Gets You Inside
81d ago
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents
81d ago
OTP lockout state leaked valid-code signal, enabling OLX account takeover
81d ago
How journalists rely on VPNs to protect press freedom
81d ago
Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
81d ago
Update Starlette Now. New severe vulnerability dropped.
81d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
82d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
82d ago
CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth
82d ago
Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal
82d ago
nmap on Linux: Guide to Network Scanning and Discovery
83d ago
Prompt Injection finally broke my brain a little. My first article as a security student.
83d ago
How to Use Claude AI: A Complete Technical Beginner's Guide
83d ago
Pardon MIE?: how Mythos did not bypass Apple MIE
85d ago
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
85d ago
AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22
85d ago
Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't)
85d ago
Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension
85d ago
Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
85d ago
Data breach in name of protest
85d ago
pnpm 11 Might Finally Be a Better Default Than npm
85d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave
86d ago
[Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled
86d ago
GitHub Actions Cache Poisoning is eating open source
86d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
86d ago
CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
86d ago
FatGid - FreeBSD 14.x kernel LPE
86d ago
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
86d ago
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
86d ago
The IBM X-Force Index 2026 explains all three in one finding.
87d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
87d ago
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
87d ago
[ Removed by Reddit ]
87d ago
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
87d ago
Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online
87d ago
The IBM X-Force Index 2026 explains all three in one finding.
87d ago
GitHub hit by a compromised VSCode extension
87d ago
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
87d ago
We audited 12K n8n templates: most have critical vulnerabilities
88d ago
Veilgate - Deception proxy
88d ago
Sleeping Agent: Silent persistent C2 through Web Push
88d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
88d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
88d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
88d ago
CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing
88d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
88d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
89d ago
The quiet death of behavioral anti-bot and the pivot to hardware ZKPs
89d ago
AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems
89d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
89d ago
The down fall of bug bounties
89d ago
TanStack Supply Chain Attack (And How to Lock Down GitHub Actions)
89d ago
Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation
89d ago
Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation
90d ago
Ansible security and compliance guide
90d ago
Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain
90d ago
AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize.
91d ago
Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works
91d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
92d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems
92d ago
Automating code security reviews with Claude Mythos-level capabilities
92d ago
Instrumenting QT6 desktop apps with Frida - Part 1
93d ago
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
93d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
93d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
93d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
93d ago
CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure
93d ago
How to Check Computer Activity: 2026 Guide for Windows and Mac
93d ago
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
93d ago
Hunting the Behavior Behind npm Supply Chain Attacks
94d ago
WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
94d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
94d ago
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
94d ago
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
94d ago
Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out
94d ago
On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study)
94d ago
A stealth approach to Process Injection - EntryPoint Hijacking
94d ago
A year of Apple Security Bounty research — 16 closed findings, full disclosure
94d ago
AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods
94d ago
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
95d ago
The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop
95d ago
Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
95d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
95d ago
I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
95d ago
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
95d ago
New ipTIME Pre-Auth RCE in CWMP
95d ago
Postmortem: TanStack npm supply-chain compromise
95d ago
How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models.
96d ago
OpenAI announces Daybreak, "frontier AI for defenders"
96d ago
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
96d ago
How I Defeat Passkeys Nearly Every Time in Phishing Assessments
96d ago
MyAudi app:Security issues in Audi Connected Vehicle experience
96d ago
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
97d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
97d ago
Autonomous Vulnerability Hunting with MCP
97d ago
ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement
97d ago
Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple
97d ago
The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
97d ago
Outrunning SHA256 with Physics
98d ago
Memory Poisoning AI Agents via ChromaDB
98d ago
Defence in Depth: A Practical Secure Corporate Network Topology
98d ago
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram
98d ago
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
98d ago
Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection
99d ago
Securing CI/CD for an open source project: lessons from Cilium
99d ago
ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12
99d ago
Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config
99d ago
Copy Fail (CVE-2026-31431): A Technical Deep Dive
100d ago
Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo
100d ago
Dirty Frag - Linux LPE similiar to Copy Fail
100d ago
Honey Tokens: Bait Credentials That Catch Breaches
100d ago
CVE-2026-42511 Breakdown: RCE in FreeBSD
100d ago
Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804
100d ago
An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support)
100d ago
Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI
100d ago
Quacc++: Automated Open Source Vulnerability Discovery
101d ago
Binance fixed the IP whitelist gap — but the disclosure process is still broken
101d ago
Non-Determinism of Maps in Golang: Why, How, and the Consequences
101d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
101d ago
Vulnerability Garden
101d ago
Scan. Secure. Simplify. — Free Web Tools Platform
102d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
102d ago
Salesforce pentesting novel techniques- how to be an apex predator
102d ago
DigiCert: Misissued code signing certificates
102d ago
Major AI Clients Shipping With Broken OAuth Implementations
102d ago
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10
102d ago
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud
102d ago
The Danger of Multi-SSO AWS Cognito User Pools
102d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
102d ago
Proton Pass: Second-Password Bypass Through Emergency Access
102d ago
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
103d ago
Lateral Movement - Cross-Session Activation
103d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
104d ago
Your vibe-coded app is probably violating GDPR right now
104d ago
Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate)
104d ago
How to exfiltrate data using only numeric outputs
105d ago
For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall.
106d ago
Every incident public companies have disclosed to the SEC, in one searchable database
106d ago
r/netsec monthly discussion & tool thread
106d ago
Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster
106d ago
Seventeen vulnerabilities in Omi, fourteen days of silence
107d ago
High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940)
107d ago
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
108d ago
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs
108d ago
The Thymeleaf Template Injection That Only Hurts If You Let It
108d ago
Set up automated dependency scanning after the recent npm/PyPI supply chain attacks
108d ago
A Route to Root in a 4G Industrial Router
109d ago
[Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses)
109d ago
The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords
109d ago
89 vulnerabilities in XAPI / Citrix XenServer
110d ago
[ Removed by Reddit ]
110d ago
Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025)
110d ago
Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary
110d ago
MCPwned: a Burp Suite extension for auditing MCP servers
110d ago
338 loaded
WE
WeLiveSecurity
2d ago · 20 items
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
2d ago
Black Hat USA 2026: What the Hugging Face hack tells us about human responsibility
2d ago
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
3d ago
Are AI tutors safe for your kids?
5d ago
This month in security with Tony Anscombe – July 2026 edition
15d ago
Beyond the screenshot: Why you should verify what you see
16d ago
Forgotten UEFI shims undermining Secure Boot
32d ago
ESET Threat Report H1 2026
38d ago
Cyber readiness for SMBs: Getting the basics right
43d ago
This month in security with Tony Anscombe – June 2026 edition
46d ago
Inside the inbox: Why cybercriminals want to break into your email account
47d ago
SMB cyber readiness: the road to resilience starts here
50d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
51d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
52d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
58d ago
Protecting legacy OT systems against modern cyberthreats
59d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
60d ago
EvilTokens: A phishing attack that doesn’t steal your password
61d ago
OceanLotus: From external espionage to domestic targeting
65d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
66d ago
20 loaded
JH
John Hammond
2d ago · 15 items
Phishing Gets Personal
2d ago
I Made AI Build a Cybersecurity Mod in Minecraft
2d ago
I Found an MFA-Bypassing Phishing Kit on the Dark Web
3d ago
This Hacker Trap Was Built by AI
4d ago
Cyber Deception Everywhere
12d ago
JHT Course Launch! Home Labs with Proxmox
15d ago
GTA Malware Trap
15d ago
Minecraft Security Mods
17d ago
Payload Podcast 010 - Olaf Hartong
17d ago
Any App Notification
20d ago
Building Fake Notifications
21d ago
Fake Edge Update
23d ago
An AI Botnet
25d ago
Redirect Chain Abuse
26d ago
Microsoft Exchange Hacked, Five Years Later
26d ago
15 loaded
TH
The Hacker News
3d ago · 20 items
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
3d ago
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
3d ago
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
3d ago
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
3d ago
Enterprise Defenses Recovered at the Edge and Collapsed Inside
3d ago
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
3d ago
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
3d ago
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
4d ago
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
4d ago
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
4d ago
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
4d ago
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
4d ago
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
4d ago
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
4d ago
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
4d ago
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
4d ago
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
4d ago
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
4d ago
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
4d ago
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
4d ago
20 loaded
RF
Recorded Future
3d ago · 20 items
Malware Crypting Services and the Threat Actors Who Sell Them
3d ago
Mines, Minds, and Machines: The Journey of AI
5d ago
The Hugging Face Hack Was Cheap Persistence at Work
6d ago
July 2026 CVE Landscape
9d ago
Emerging Threats to Neurotechnology
10d ago
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
11d ago
8 Ways AI is Changing Threat Intelligence
13d ago
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
17d ago
Dealing with AI-Generated Extortion
17d ago
Ransomware is the Scoreboard
23d ago
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
24d ago
Modern Attack Vectors | Recorded Future
25d ago
Threat Hunting: A Guide | Recorded Future
27d ago
Tracking Advanced Persistent Threat Groups | Recorded Future
30d ago
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
31d ago
The Shift: A New Era of AI Regulation
32d ago
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
33d ago
June 2026 CVE Landscape
37d ago
RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney
38d ago
The Threat Isn’t the Frontier Model
39d ago
20 loaded
NA
NahamSec
3d ago · 15 items
I Went to the World's Biggest Hacker Conference (DEFCON VLOG)
3d ago
I’m headed to DEFCON!
10d ago
Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS)
12d ago
Are you ready for this year's @BugBountyVillage at @DEFCONConference
13d ago
Do you guys agree? #hacking #bugbounty
15d ago
How One File Upload Got Me the Entire Customer Database
19d ago
Why Being a Great Hacker Doesn't Pay Anymore
21d ago
This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!)
33d ago
I Made an AI Agent That Reverses CVEs While I Sleep
40d ago
This Hacker Got Paid $50,000+ to Break Frontier AI Models
54d ago
This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity
59d ago
How I Made $30,000 Hacking Broken Access Control
61d ago
$30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover
61d ago
Content creations was both a blessing and a curse. #bugbounty
68d ago
This Hacker Made $7,000 Hacking AI With One Email
68d ago
15 loaded
DE
DEFCONConference
4d ago · 15 items
DEF CON 34 - Video Team - Hackers dot Town - The Gibson
4d ago
DEF CON 34 - Video Team - Car Hacking Villlage
4d ago
DEF CON 34 - Video Team - Ham Radio Village - Marvin Goes HAM
4d ago
DEF CON 34 - Video Team - Physical Security Village
4d ago
DEF CON 34 - Video Team - LEECH
4d ago
DEF CON 34 - Video Team - EmbeddedSystems Village
4d ago
DEF CON 34 - Video Team - PhreakMe
4d ago
DEF CON 34 - Video Team - Voting Machine Hacking Village
6d ago
DEF CON 34 - VideoTeam - Cliff Stoll AfterHours
6d ago
DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking
7d ago
DEF CON 34 - Video Team - Hak5 - Darren Kitchen
7d ago
DEF CON 34 - Video Team - AI Hacking Village - Pokemon
7d ago
DEF CON 34 - Video Team - No Starch Press
7d ago
DEF CON 34 - Video Team - Goon Questions -Guzi Media
7d ago
DEF CON 34 - Video Team -Bug Bounty Village
7d ago
15 loaded
MS
Microsoft Security Blog
5d ago · 10 items
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
5d ago
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise.
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
5d ago
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongs...
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
10d ago
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report.
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
10d ago
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities...
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
11d ago
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guid...
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
11d ago
Read how to apply Zero Trust for AI with new assessments, DevSecOps guidance, and practical tools to secure AI agents, code, memory, and cloud environments.
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
11d ago
Microsoft Defender automatically isolated a compromised QNET endpoint in 129 seconds, stopping a multi-stage attack before the payload could persist or spread.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
15d ago
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and stea...
What’s new in Microsoft Security: July 2026
16d ago
Explore July 2026 Microsoft Security updates, including agentic defense, AI threat protection, identity, data security, and advanced endpoint management.
Better security starts with better questions
17d ago
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems.
CY
CyberScoop
8d ago · 179 items
More than half of AI-generated patches are broken
8d ago
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
8d ago
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
9d ago
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
9d ago
Ransom Cartel creator sentenced to 16 years in prison
9d ago
The water sector just got it’s wake-up call. Again.
9d ago
Snowflake hacker pleads guilty, faces up to 32 years in prison
10d ago
Tom Cotton prods Treasury for tax code tweaks to modernize OT
10d ago
Open-source software’s archenemy TeamPCP goes back further than anyone thought
10d ago
AI is getting better at election facts, but voters shouldn’t rely on it
10d ago
National cyber director lays out White House plans to secure AI without writing new rules
11d ago
AISI, OpenAI report more ‘unsanctioned’ model hacks
11d ago
Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack
12d ago
CrowdStrike: AI is now both the weapon and the target in cyberattacks
13d ago
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
15d ago
What the Hugging Face breach reveals about defense in the age of agentic AI
15d ago
Anthropic says its AI accidentally hacked three companies during safety tests
16d ago
Okta’s deal for Permiso aims to close gaps in identity threat detection
16d ago
CISA issues recommendations to federal agencies on open-source software security
16d ago
We know how to protect our troops from telecom attacks. We’re just not doing it.
16d ago
Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims
16d ago
A little-known npm package was North Korea’s warm-up act for the axios hack
17d ago
Supply chain challenges loom large in quantum race, White House official says
17d ago
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
17d ago
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
22d ago
Despite multiple takedowns, botnets continue to grow
22d ago
Microsoft, tech companies throw weight behind spread of open-source AI
22d ago
Rubio restricts visas for sextortionists, cyber scammers
23d ago
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
23d ago
ANCHOR-CI could fix 20 years of broken government-industry collaboration
23d ago
Most federal cybersecurity reporting rules are duplicative, study finds
24d ago
Malware is targeting AI tools in software development environments
24d ago
White House accuses Chinese company of distilling Anthropic’s Fable
24d ago
OpenAI says model test was behind Hugging Face hack
25d ago
AI models keep getting caught cheating
25d ago
Where’s the Trump administration line on AI regulation?
25d ago
House intel bill includes provisions on state and local threat intelligence, election security, AI
25d ago
North Korea’s IT worker scheme funds Russia’s war effort
25d ago
What the World Cup can teach us about cybersecurity resilience
25d ago
Director of Commerce AI standards office out after three months
26d ago
Why blocking AI models won’t stop the cyber threats they create
26d ago
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
29d ago
Leading members of Scattered Spider sentenced in UK to 66 months in jail
29d ago
Program to rotate cyber personnel through federal agencies saw little use
30d ago
Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime
30d ago
Security researchers find stalkers abusing Chrome’s sync feature
31d ago
SonicWall customers under threat as attackers exploit 2 zero-days
31d ago
Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
31d ago
Forget the model. When it comes to cybersecurity, it’s all about the harness
31d ago
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
37d ago
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
37d ago
764 splinter group leader sentenced to 40 years in jail
37d ago
French nonprofit starts global intelligence and research hub for AI cyber threats
38d ago
Found fast, fixed slow: The gap the AI clearinghouse must close
38d ago
Spain arrests suspected hacker linked to Russian hacktivist campaign
39d ago
Deepfake CSAM lawsuit against xAI, Grok expands
39d ago
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
39d ago
US Army websites defaced with pro-Kurdish sentiments, insults to Trump
40d ago
Sysdig clocks first documented case of agentic ransomware
40d ago
Finding vulnerabilities was never the hard part
40d ago
Someone infected a spyware probe overseer with spyware
44d ago
Alleged longstanding member of Scattered Spider extradited to US
44d ago
Researchers spot exploitation of another critical Oracle defect
45d ago
US lifting export control restrictions on Anthropic’s Mythos, Fable
45d ago
This phishing kit looks more like BEC-as-a-service
45d ago
Citrix patches a new NetScaler flaw with echoes of CitrixBleed
46d ago
Trump budget boss Russell Vought open to re-staffing CISA
46d ago
DHS to unveil replacement council for critical infrastructure cybersecurity
46d ago
How ransomware syndicates weaponize corporate-style organization
46d ago
Warner bill would create federally vetted list for secure, trustworthy AI agents
47d ago
Supreme Court approves mail-in ballots that arrive after Election Day
47d ago
Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling
47d ago
What the post-quantum executive order really demands of CISOs
47d ago
ATF cancels controversial commercial geolocation contract
50d ago
FCC passes new cybersecurity rules for emergency systems, undersea cables
51d ago
Federal court rules Trump election-focused executive order illegal
51d ago
Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract
51d ago
Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack
51d ago
Why patch directives only go so far
51d ago
Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
52d ago
In a first, a court takedown goes after two cybercrime tools at once
52d ago
Open-source security is posing challenges governments can’t easily solve
52d ago
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
53d ago
Algerian man charged with running two cybercrime marketplaces
53d ago
Court rules SAVE database illegal, orders it dismantled
54d ago
Trump executive orders speed up post-quantum migration, boost industry
54d ago
Intel agencies: Frontier AI models will reshape cybersecurity faster than expected
54d ago
Authorities disrupt Evil Corp’s SocGholish botnet
58d ago
Congress tees up No FAKES Act, aiming at AI-generated deepfakes
58d ago
How software development’s speed obsession enabled TeamPCP’s chaos crusade
58d ago
Accenture shells out $4.18B on three companies in big industrial cybersecurity push
58d ago
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April
59d ago
Lawmakers leery about Trump administration’s Anthropic order
60d ago
AI’s constant patching treadmill can be a security problem
60d ago
A case for how to shape ‘ingredient lists’ for AI models
60d ago
Google exposes China espionage group that’s been lurking in networks undetected since 2023
61d ago
Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat
61d ago
Anthropic disables new models after government calls them a national security concern
63d ago
FBI takes down massive China-based cybercrime network that caused $1.9B in losses
64d ago
US, France, and Italian authorities shut down massive deepfake porn site
64d ago
Conti ransomware group member pleads guilty, faces up to 20 years in prison
64d ago
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw
64d ago
CyberCorps is adapting to AI. The budget isn’t keeping up.
64d ago
Russian national charged in connection with Void Blizzard espionage campaign
65d ago
OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
66d ago
CISA directive orders agencies to prioritize vulnerability patching in a new way
66d ago
Microsoft breaks Patch Tuesday record with 206 vulnerabilities
67d ago
Anthropic’s new model is Mythos on a leash
67d ago
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
67d ago
Cisco customers encounter another SD-WAN zero-day under attack
67d ago
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
68d ago
The AI security race needs accountability, not overregulation
68d ago
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
71d ago
Hill Dems hammer GOP for $250M CISA budget cut
72d ago
Your AI agent could become your biggest insider threat
72d ago
Inside the race to adapt to an AI-powered security world
72d ago
European authorities crack down on illegal streaming networks
73d ago
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels
73d ago
DOD wants to integrate cyber in all operations, and integrate security into AI
74d ago
Trump administration releases scaled-back AI executive order
74d ago
Anthropic expanding access to Project Glasswing
74d ago
Attackers are exploiting Palo Alto Networks defect that initially flew under the radar
75d ago
Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight
75d ago
USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order
75d ago
Election threats are focused on campaign systems, not voting machines
75d ago
Tennessee man linked to 764 accused of series of crimes against children dating back to 2022
78d ago
Federal audit reveals NIST’s NVD is plagued by poor planning and duplication
78d ago
House panel poised to hold hearing centered on AI impact on cyber
79d ago
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
79d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
79d ago
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms
80d ago
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
80d ago
UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace
80d ago
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
80d ago
Apple open-sources quantum-resistant encryption code
81d ago
Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
86d ago
Lawmakers from both parties say CISA cuts have gone too far
86d ago
Trump postpones executive order focused on AI security
86d ago
CISA chief frets about open-source vulnerabilities, delayed security improvements
86d ago
European authorities take down prolific cybercrime VPN service
86d ago
The readiness paradox: Why a false sense of cyber confidence is becoming a liability
86d ago
Meet Rampart and Clarity, Microsoft’s new red team combo AI agents
87d ago
GitHub says internal repositories were impacted in poisoned VS Code extension attack
87d ago
CISA credential leak raises alarms, and Capitol Hill demands answers
88d ago
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches
88d ago
Mini Shai-Hulud returns, compromising hundreds of npm packages
88d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
88d ago
AI might cut false positives, but it won’t stop the slop
89d ago
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
89d ago
The Canvas breach proved that prevention is no longer enough
89d ago
Former CISA nominee Sean Plankey named US CEO of defense startup
90d ago
Colorado governor commutes prison sentence for election denier Tina Peters
92d ago
Here’s how the FTC plans to enforce the Take It Down Act
92d ago
Cisco zero-day under ongoing attack by persistent threat group
92d ago
Pentagon cyber official calls advanced AI ‘revolutionary warfare’
93d ago
White House cyber official: identity security matters more than ever in the age of AI
93d ago
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
93d ago
Researchers say AI just broke every benchmark for autonomous cyber capability
94d ago
Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks
94d ago
DOJ releases legal rationale for nationwide voter data collection
94d ago
Weaponized AI: The new frontier of fraud and identity spoofing
94d ago
Daybreak is OpenAI’s answer to the AI arms race in cybersecurity
94d ago
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
95d ago
Major world economies spell out key elements of AI ‘ingredients list’
95d ago
Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical
95d ago
Google and Amnesty International teamed up to make it harder for spyware vendors to hide
95d ago
AI is separating the companies built to scale from the ones built to sell
95d ago
Instructure claims hackers returned stolen Canvas data after an extortion standoff
96d ago
Google spotted an AI-developed zero-day before attackers could use it
96d ago
The missing cybersecurity leader in small business
96d ago
Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments
99d ago
ShinyHunters claims nearly 9,000 schools affected by Canvas data breach
99d ago
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI
99d ago
Ivanti customers confront yet another actively exploited zero-day
100d ago
Trump officials are steering a cybersecurity scholarship program toward AI
100d ago
American duo sentenced for hosting laptop farms for North Korean IT workers
100d ago
One House Democrat is pressing Commerce on the government’s spyware use
100d ago
A DOD contractor’s API flaw exposed military course data and service member records
101d ago
A critical Palo Alto PAN-OS zero-day is being exploited in the wild
101d ago
179 loaded
LI
LiveOverflow
8d ago · 15 items
Learn Fault Injection at DEF CON 2026
8d ago
Did an AI Really Hack Hugging Face?
19d ago
Security-driven Rapid Release - Pwn2Own Documentary (Part 4)
164d ago
Firefox JIT Bug - Pwn2Own Documentary (Part 3)
167d ago
The First Exploit - Pwn2Own Documentary (Part 2)
171d ago
The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)
174d ago
From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi
494d ago
The German Hacking Championship
519d ago
Do you know this common Go vulnerability?
533d ago
Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1)
668d ago
My theory on how the webp 0day was discovered #short
684d ago
My theory on how the webp 0day was discovered (BLASTPASS)
685d ago
Learn Android Hacking! - University Nevada, Las Vegas (2024)
711d ago
DEF CON & Black Hat Trip 2024
725d ago
Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
936d ago
15 loaded
PN
Proofpoint News Feed
8d ago · 10 items
Russian hackers can steal emails without a click
8d ago
Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats
11d ago
Recognition highlights Proofpoint's deep technical integration with Google Cloud Security solutions and commitment to helping organizations protect people, data and AI Helps
Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities
11d ago
Accelerates OEM innovation by embedding trusted threat intelligence into security products and customer-facing workflows. Helps partners deliver more prioritized,
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
16d ago
New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors
23d ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
23d ago
US and allies say Russian hackers stole emails without social engineering
23d ago
The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of the Zimbra email program without having to fool them into opening an attachment or clicking a link.
If you pay a hacker’s ransom, chances are that they’ll come back for more
24d ago
Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective
25d ago
Global study reveals that AI is amplifying phishing, impersonation and credential theft, transforming ransomware into a human-centric extortion problem 40%
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
32d ago
HS
Heimdal Security Blog
9d ago · 15 items
The risk awareness radar. A superpower every MSP needs to train
9d ago
Most of the cyber incidents landing on our desks these days start with someone believing a lie. It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make p...
Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes
16d ago
New data from Heimdal's telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine. The same pattern has been confirmed across more than 40 client environments.
How Heimdal grew from a bold idea into a global cybersecurity platform
16d ago
Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a challenge. Could they create something that could identify vulnerabilities, intercept...
MediaArena malvertising: why a quarantine isn’t the end of the incident
16d ago
If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing i...
Tools Change. Teach People How to Keep Up
18d ago
“Make everyone one percent better and it compounds across the team.” That’s the line Joe Head wrote about his own job and when I read it back to him, he didn’t hesitate. “That is 100% the objective,” he said. Joe runs AI adoption for an 80-...
The 4 best managed EDR service suppliers (and how to choose)
23d ago
There are several cybersecurity companies that offer managed EDR services in 2026. Here’s what actually separates them, and who each one suits. Most successful cyber attacks begin with a breached laptop, a smartphone or a server. Over the p...
Top 4 Best SOC Platforms 2026 – Provider Comparison
24d ago
Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. The...
Top 6 Managed Detection and Response Providers
36d ago
There are several major managed detection and response (MDR) companies to choose from. We’ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a secur...
Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors
38d ago
Your client is no longer just buying your security advice. They’re auditing whether you live by it. That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators...
How to scale your patches without scaling your team (the patch wave)
43d ago
Most breaches don’t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the...
AI didn’t break patching. It showed us patching was already broken.
43d ago
Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes
46d ago
How Dynamic Defense shuts an attacker out without shutting down the business
50d ago
Static security has run out of road. The case for Dynamic Defense
50d ago
Breaking the MSP Echo Chamber: The Power of Community
52d ago
15 loaded
BF
Blog – Forter
12d ago · 10 items
Does AI Content Have to be Authentic — or Can It Just Be Effective?
12d ago
What Is Visa’s DCAP? A Merchant’s Guide to Requirements, Benefits, and Rollout
24d ago
The Gray Area in Your Checkout Is Costing You More Than You Think
32d ago
Your Payment Routing Rules Are Making Decisions Without You
38d ago
New at Forter: AI Agents Built to Amplify Your Team
52d ago
Can AI Agents Find, Trust, and Choose Your Brand?
53d ago
IMPACT Roadshow Recap: Getting Ready for Agentic Commerce
66d ago
Agent-Ready: How to Prepare Your Site for AI-Driven Commerce
73d ago
Japan’s 3DS Mandate: One Year In
92d ago
One-Click Refunds Are Not as Hard as You Think
102d ago
HA
Hak5
15d ago · 15 items
The DEF CON Advice Nobody Gives You | Threat Wire
15d ago
OpenAI Turned Off the Guardrails | Threat Wire
16d ago
Meta Logging Every Employee Keystroke | Threat Wire
23d ago
Your Home Internet Has a New Owner | Threat Wire
31d ago
Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire
39d ago
Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire
54d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
54d ago
🔴 [PAYLOAD] 🍍📟 WiFi Pineapple Pager
55d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
59d ago
Shark Jacked my LAN 🦈
60d ago
Developers React to the 105-Second Github Chain Reaction | Threat Wire
64d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
65d ago
Introducing Shark Jack Display 🦈
68d ago
The GitHub Leak Situation Just Got Worse | Threat Wire
79d ago
The Worm That Deletes Your Entire Computer | Threat Wire
85d ago
15 loaded
M3
Microsoft 365 Blog
16d ago · 10 items
The next measure of AI momentum is work transformed
16d ago
New data from Microsoft 365 Copilot telemetry signals, along with examples from our customers around the world, demonstrate AI transformation in action.
Copilot in Excel: Built for the era of Frontier Finance
51d ago
- Discover how Copilot in Excel transforms finance workflows with skills, data connectors, and capabilities for traceability.
Copilot Cowork is now generally available
60d ago
Copilot Cowork is now generally available worldwide, bringing secure, AI-powered automation for complex enterprise tasks in Microsoft 365.
Introducing Microsoft Scout: Your always-on personal agent
74d ago
Microsoft introduces a new, always-on personal agent, Microsoft Scout, integrated across the Microsoft 365 apps you use every day.
Announcing the new Work IQ APIs
74d ago
Build enterprise agents with Work IQ APIs for Microsoft 365—bringing business context, tools, and secure, scalable intelligence into every workflow.
Introducing Microsoft 365 Business with Copilot: The new standard for small business
79d ago
Meet Microsoft 365 Business with Copilot—the AI-powered solution transforming how small businesses work, collaborate, and compete.
Introducing a new design for Microsoft 365 Copilot
79d ago
Copilot’s redesigned experience delivers faster performance, adaptive tools, and clearer AI-powered workflows to help you easily move from intention to outcome.
New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences
81d ago
Explore what's new in Copilot Studio, May 2026: computer-using agents are now available, plus redesigned workflows and Work IQ extensibility.
New and improved: Agent governance, intelligent workflows, and connected app experiences
96d ago
See what's new in Copilot Studio, April 2026: updates to workflows, more control over agent operations, and an expanded agent usage estimator.
Copilot Cowork: From conversation to action across skills, integrations, and devices
102d ago
Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you.
TM
Trend Micro Research, News, Perspectives
17d ago · 20 items
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility
17d ago
Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave
18d ago
The Signs Were There: What the First Autonomous Ransomware Case Confirms
23d ago
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
24d ago
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
24d ago
Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure
24d ago
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
25d ago
Volume Is Not Risk: Making Sense of the 'Vulnpocalypse'
26d ago
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
33d ago
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
48d ago
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer
54d ago
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
59d ago
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
60d ago
Governing Claude Enterprise in Environments Where Inline Controls Can't Go
65d ago
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026
67d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
69d ago
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
76d ago
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
82d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
86d ago
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
87d ago
20 loaded
DA
darkreading
22d ago · 144 items
CISOs vs. Boards: Myth or Misunderstanding?
22d ago
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
22d ago
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
22d ago
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
22d ago
Europe's Multilingual Reality Exposes AI Security Gaps
23d ago
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
23d ago
Agentic AI Challenges Progress in Confidential Computing
23d ago
Brazilian Banking Trojan Actively Spreading in Portugal
24d ago
Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain
24d ago
Flaws in Passkey Implementation Show Old Attacks Still Work
24d ago
Attackers Are Learning to Live Off the AI Toolchain
24d ago
Fake Bahrain Alert App Deploys Android Surveillance Malware
24d ago
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
24d ago
EU Financial Institutions Leak Data Through Cookie Trackers
24d ago
Ransomware Is Accelerating, but It's Not Because of AI
25d ago
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
25d ago
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
25d ago
Choose Wisely: AI-Generated Coding Risk Varies, a Lot
25d ago
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
26d ago
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
26d ago
Cybersecurity Keeps Events 'Uneventful'
26d ago
Inc Ransomware Exploits SonicWall SMA Zero-Days
29d ago
The Real AI Threat Is Blind Trust
29d ago
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
29d ago
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
29d ago
Agentic AI: Taming the Unpredictable
30d ago
1M+ Emails Use Hidden Text to Dupe AI Security Filters
30d ago
Police Disrupt a €140M Cyber Fraud Ring in Spain
31d ago
Forgotten Bootloaders Expose Secure Boot Blind Spot
31d ago
Identity Attacks Overtake Exploits as Top Ransomware Cause
31d ago
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
31d ago
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
31d ago
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
31d ago
2-Click Cursor Exploit Enables Dev Environment Takeover
31d ago
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
32d ago
Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal
32d ago
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
32d ago
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
32d ago
Manage Vendor Risk in a Few Practical Steps
32d ago
Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?
32d ago
Name That Toon Contest
50d ago
Europe Evolves Into Ransomware's Favorite Region
51d ago
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
52d ago
2026 FIFA World Cup Faces Surge in Cyber Threats
52d ago
Do CISOs Need a Code of Ethics?
52d ago
More Malicious OpenClaw Skills Threaten AI Supply Chain
52d ago
Apple's MacOS Gap Lets Users Disable Security Tools
52d ago
Scope of Salesforce Attacks Expands as Icarus Leaks Data
53d ago
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
53d ago
SocGholish Takedown Highlights Malicious TDS Threats
53d ago
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
53d ago
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
54d ago
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
54d ago
He Thought He Was Secure; His Phone Number Was Stolen Anyway
54d ago
Stressors, AI Forcing Changes to Cybersecurity Teams
57d ago
Novo Nordisk Breach Highlights Software Development Pipeline Risk
58d ago
Operation Escaneo Signals Shift in LatAm Threat Landscape
58d ago
FIFA Bug Exposes World Cup Streams to Remote Takeover
58d ago
Salesforce Data Thefts Continue via Klue App Compromise
58d ago
Get Out of Security Debt by Tackling the Exposure Problem
58d ago
EU Gets a Head Start in Developing 6G Network Security
59d ago
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
64d ago
Claude Fable 5 Doesn't Change the Mythos Security Story
64d ago
Phishing Attack Volume Down 20%, But Risk Still Rising
65d ago
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
65d ago
Segmentation Works for OT If Operators Are Paying Attention
65d ago
Chinese, N. Korean Threat Groups Build on Asia-Pacific Success
66d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
66d ago
Bug Bounty Research Triggers ServiceNow Security Alert
66d ago
AI Risk Worries Insurers & Businesses Alike
66d ago
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
66d ago
The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life
67d ago
Blame AI: Patch Tuesday Hits Record 206 CVEs
67d ago
Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
67d ago
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
67d ago
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
67d ago
AI Slop Will Kill Cybersecurity Storytelling If We Let It
68d ago
Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
68d ago
Check Point VPN Flaw Exploited Since Early May
68d ago
Iran Signed a Ceasefire — Its Hackers Didn't
68d ago
[An RX Global Event] Infosecurity Europe
74d ago
Name That Toon: Mark of (Cybersecurity) Progress
78d ago
Asia's Cyber Insurance Market Shows Signs of Life
78d ago
With Complex Cloud Integrations, Small Errors Lead to Major Compromises
78d ago
'The Com' Cyberattacks Support Violence & Sexploitation
78d ago
As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
79d ago
Dutch Raid Fails to Dent Russian Bulletproof Host
79d ago
Agentic AI Isn't Risky; the Way Orgs Deploy It Is
79d ago
Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security
79d ago
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
79d ago
Nordic CISOs Handle Rising Cyber Threats Remarkably Well
80d ago
Ransomware Actors Show Up In Person to Steal Law Firm Data
80d ago
Latin American Cybercriminals Hoover Up Government Data
80d ago
AI-Assisted Exploit Development Outpaces Scanner Detection
80d ago
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
80d ago
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
81d ago
State Cyber Leaders Push Congress for More Funding, Support
81d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled?
81d ago
For Enterprises, Security Remains Agentic AI's Biggest Challenge
81d ago
The Boring Stuff is Dangerous Now
89d ago
Can Laws Stop Deepfakes? South Korea Aims to Find Out
90d ago
Congress Puts Heat on Instructure After Canvas Outage
92d ago
Cyber Pioneers Ponder Past as Prologue
92d ago
Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems
93d ago
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
93d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
93d ago
'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
93d ago
AI Drives Cybersecurity Investments, Widening 'Valley of Death'
93d ago
Foxconn Attack Highlights Manufacturing's Cyber Crisis
93d ago
Checkbox Assessments Aren't Fit to Measure Risk
94d ago
Attackers Weaponize RubyGems for Data Dead Drops
94d ago
Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak
94d ago
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape
94d ago
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly
94d ago
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
94d ago
It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight
95d ago
Hugging Face Packages Weaponized With a Single File Tweak
95d ago
20 Leaders Who Built the CISO Era: 2 Decades of Change
95d ago
Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
95d ago
How the Story of a USB Penetration Test Went Viral
102d ago
RMM Tools Fuel Stealthy Phishing Campaign
103d ago
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
103d ago
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
103d ago
How Dark Reading Lifted Off the Launchpad in 2006
103d ago
76% of All Crypto Stolen in 2026 Is Now in North Korea
106d ago
If AI's So Smart, Why Does It Keep Deleting Production Databases?
106d ago
Name That Toon: Mark of (Security) Progress
106d ago
20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage
106d ago
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
107d ago
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
107d ago
Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber
107d ago
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
107d ago
Claude Mythos Fears Startle Japan's Financial Services Sector
108d ago
Reverse Engineering With AI Unearths High-Severity GitHub Bug
108d ago
AI Finds 38 Security Flaws in Electronic Health Record Platform
108d ago
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
108d ago
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
108d ago
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
109d ago
NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later
109d ago
Feuding Ransomware Groups Leak Each Other's Data
109d ago
Vidar Rises to Top of Chaotic Infostealer Market
109d ago
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
109d ago
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
110d ago
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
110d ago
144 loaded
SK
STÖK
23d ago · 15 items
They hacked Google's AI in Seoul
23d ago
☔️🌅
84d ago
Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs
356d ago
Winter vanlife = good times
958d ago
What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth!
965d ago
Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma
971d ago
IS THIS THE END?
1031d ago
Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites
1186d ago
How to turn bugs into a "passive" income stream! ft Detectify's Almroot
1426d ago
HOW DID THIS HAPPEN!? (13370822 LHE VLOG)
1440d ago
Q: How to write a BUG BOUNTY report that actually gets paid?
1556d ago
facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques..
1570d ago
Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!)
1584d ago
Q: HOW do you get started in bug bounty?? How do you build your automation?!
1598d ago
Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR)
1612d ago
15 loaded
CD
Cyber Defense Magazine
26d ago · 95 items
Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack
26d ago
UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker
29d ago
Hacking US Elections: The First Tranche of Declassified Election Integrity Documents
29d ago
Inside Microsoft’s Record-Breaking 622-Bug Release
30d ago
Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook
31d ago
Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure
31d ago
CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers
32d ago
The Threat Mechanism and Mitigation of Pink Vishing Campaigns
33d ago
See It Once, Stop It Everywhere
35d ago
Cybercriminals Targeting World Cup Fans
36d ago
Innovators Spotlight: Brinqa
36d ago
The Cost of Delayed Patching: What Security Teams Are Missing
36d ago
Invoice Fraud Is Now a Cybersecurity Exposure
36d ago
The Chaya_006 Alert: OT Edge Devices Under Fire
45d ago
Nissan Americas Hit in Global Oracle PeopleSoft Data Breach
46d ago
CISA Warns Attackers Are Targeting Critical Internal Business Platforms
47d ago
Return On Risk: The New Measure Of Cyber Resilience
48d ago
Path to StateRAMP
48d ago
Rethinking Identity Security In The Age Of AI Driven Fraud
49d ago
New Age Insider Risk
49d ago
Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure
50d ago
Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To
50d ago
The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer
51d ago
The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target
51d ago
NSA Urges Cyberthreat Timeline Has Compressed From Years to Months
51d ago
Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have
52d ago
Invisible By Design: Making Quantum-Safe Encryption The Easy Path
52d ago
Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming
52d ago
Innovator Spotlight: NAKIVO
53d ago
Cybersecurity Outsourcing. Beyond Cost
53d ago
Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets
53d ago
Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data
53d ago
Data Breach with Eastman Kodak Company
54d ago
The World Cup Is Here… And So Are The Cyber Risks
54d ago
Cloud Managed Services For Modern Cybersecurity To Secure Cloud
54d ago
Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors
55d ago
The Shadow AI Paradox: Governing Innovation At Machine Speed
56d ago
Innovator Spotlight: Ensemble
57d ago
Innovator Spotlight: Centrii
57d ago
NSPM-12: The New Baseline for National Security Cybersecurity
57d ago
Five Compliance Realities Federal Contractors Can’t Ignore
58d ago
Cyber Security Market Insights & Trends Driving The Next Wave Of Protection
59d ago
AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns
60d ago
Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions
60d ago
Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection?
61d ago
CMMC Is Exposing A Major Gap In The Defense Supply Chain
62d ago
Zero Trust For AI In Defense Networks
63d ago
Why Most Cyber Resilience Programs Fail Before The First Incident
64d ago
Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration
65d ago
What The Cybersecurity Industry Knows And Will Not Say
66d ago
Rethinking Access Governance for AI Agents
67d ago
How CIAM Helps Boost Business
68d ago
World Cloud Security Day
68d ago
CMMC Is Here, But AI Changes The Compliance Conversation
69d ago
Cybersecurity Improved Detection But Exposed a New Problem
70d ago
Innovator Spotlight: Airrived
71d ago
Cloud Security In Practice
71d ago
Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing
72d ago
The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector
73d ago
Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit
74d ago
Why Is Cybersecurity Now A Business Priority, Not Just An IT Function?
90d ago
The Security Mistakes Being Repeated With Ai
91d ago
The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract
92d ago
Innovator Spotlight: Klever Compliance
93d ago
Innovator Spotlight: Radware
93d ago
Innovator Spotlight: JScrambler
93d ago
Innovators Spotlight: OPSWAT
94d ago
The Board Is Asking The Wrong Security Question
94d ago
Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification
95d ago
Innovator Spotlight: Iru
96d ago
Innovator Spotlight: Axonius
96d ago
Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge
96d ago
The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface
96d ago
Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI
97d ago
Innovator Spotlight: Lineaje
98d ago
Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care
99d ago
Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered
100d ago
When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity
100d ago
Innovators Spotlight: Badge (Part II)
101d ago
Redefining Security Operations Through Seceon’s Open Threat Management Platform
101d ago
The Insurance Industry Is Rewriting Cybersecurity Strategy
102d ago
Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management
103d ago
Ai Didn’t Break Cybersecurity, It Revealed It
104d ago
RSAC 2026: The Power of Community
105d ago
Inside RSAC 2026
106d ago
Innovator Spotlight: The Open Group
107d ago
Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark
107d ago
Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints
108d ago
Innovator Spotlight: Puneet Bhatnagar
109d ago
Cybersecurity Risks in 2026
109d ago
Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters
110d ago
Innovator Spotlight: TokenCore
110d ago
Platform Engineering: The Rise of a Disciplinary Rethink
110d ago
60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea?
110d ago
From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense
111d ago
95 loaded
TL
The Last Watchdog
31d ago · 34 items
News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations
31d ago
SAN FRANCISCO, July 15, 2026, CyberNewswire – Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been mi...
News alert: Insignary’s on-demand SBOM verification boosts software supply chain security
31d ago
TORONTO, July 15, 2026, CyberNewswire ŌĆō According to Insignary Inc., a leader in software supply chain security and binary software composition analysis (SCA), most organizations cannot independently verify what is actually inside the sof...
News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions
32d ago
TEL AVIV, Israel, July 14, 2026, CyberNewswire – Tego AI, a cybersecurity company, published new research identifying a potentially critical security weakness in Claude Tag, Anthropic’s native integration between Claude and Slack. Resea...
News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI
38d ago
MELBOURNE, Fla., July 8, 2026, CyberNewswire – OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop stan...
News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk
40d ago
TORONTO, July 6, 2026, CyberNewswire тАУ Insignary, Inc., whose patented binary fingerprint technology has been cited in four Gartner research reports, today announced its recognition as a Sample Vendor for Reachability Analysis in the Gart...
News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks
45d ago
FRANKFURT, July 1, 2026, CyberNewswire – Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing ...
News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks
46d ago
BOSTON, June 30, 2026, CyberNewswire – Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, "Securing Third-Party Marketing in the AI Era," taking place July 8 at 9 AM EDT / 3 PM CEST. Every market...
News alert: OpenMatter launches platform to verify AI activity across enterprise systems
46d ago
MELBOURNE, Fla., June 30, 2026, CyberNewswire – OpenMatter Network today announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don't Trust Data. Prove It. ...
News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies
59d ago
AUSTIN, Tex., June 17, 2026, CyberNewswireŌĆōSpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enter...
News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk
59d ago
LONDON, June 17, 2026, CyberNewswire–Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report's headline finding is a divide inside the...
News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails
60d ago
News alert: GitGuardian adds endpoint protection as developer laptops become credential troves
60d ago
News alert: Varist announces AI-scale malware detection for healthcare and medical imaging
60d ago
News alert: Cloud security report finds fragmented tools widening the cloud complexity gap
66d ago
News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces
74d ago
FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential
74d ago
News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit
79d ago
GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet
81d ago
GUEST ESSAY: AI can speed up communication, but it can also weaken human connection
87d ago
News alert: Orchid Security study finds invisible identities now outnumber managed accounts
88d ago
MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack
89d ago
LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back
94d ago
FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread
95d ago
News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents
96d ago
News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market
102d ago
SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents
107d ago
GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control
109d ago
FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures
110d ago
News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category
115d ago
Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one
117d ago
News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security
122d ago
GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags
123d ago
News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk
128d ago
FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense
130d ago
34 loaded
PF
PYMNTS | Fraud Prevention Archives
32d ago · 10 items
78% of CFOs Say Payment Blind Spots Increase Customer Friction
32d ago
85% of CFOs Say Automation Cuts Payments Friction
34d ago
42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million
39d ago
LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud
43d ago
42% of Issuers Say Fraud and Disputes Are Driving Up Costs
45d ago
JPMorganChase and Amazon Back Aspen Institute Drive Against Scams
46d ago
World Cup Gives Cross-Border Payments Their Super Bowl Moment
48d ago
Banks Face a New ACH Fraud Test as Nacha Rules Take Effect
50d ago
The latest Nacha fraud rules require banks to expand fraud monitoring and adopt broader, risk-based oversight across ACH activity.
Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges
51d ago
Nvidia’s AI blueprint maps connections across accounts and devices to catch the fraud network, not just the charge.
AI Forces Compliance Teams to Rethink Alert Strategy
52d ago
FP
Fraud Prevention – Riskified
32d ago · 1 items
WE
WeLiveSecurity
32d ago · 48 items
Forgotten UEFI shims undermining Secure Boot
32d ago
ESET Threat Report H1 2026
38d ago
Cyber readiness for SMBs: Getting the basics right
43d ago
This month in security with Tony Anscombe – June 2026 edition
46d ago
Inside the inbox: Why cybercriminals want to break into your email account
47d ago
SMB cyber readiness: the road to resilience starts here
50d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
51d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
52d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
58d ago
Protecting legacy OT systems against modern cyberthreats
59d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
60d ago
EvilTokens: A phishing attack that doesn’t steal your password
61d ago
OceanLotus: From external espionage to domestic targeting
65d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
66d ago
Cybercriminals: the 'auditors' you never hired
67d ago
Lessons for life: Why children’s data is a long-term identity risk
73d ago
This month in security with Tony Anscombe – May 2026 edition
79d ago
ESET APT Activity Report Q4 2025–Q1 2026
79d ago
What to consider before asking an AI chatbot for health advice
80d ago
BTMOB: A stealthy RAT burrowing deep into Android devices
81d ago
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
85d ago
Webworm: New burrowing techniques
87d ago
The quest for greater tech independence
88d ago
Why geopolitical turmoil is a gift for scammers, and how to stay safe
92d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
93d ago
Eyes wide open: How to mitigate the security and privacy risks of smart glasses
96d ago
Fake call logs, real payments: How CallPhantom tricks Android users
100d ago
Fixing the password problem is as easy as 123456
101d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
102d ago
This month in security with Tony Anscombe – April 2026 edition
107d ago
The calm before the ransom: What you see is not all there is
113d ago
GopherWhisper: A burrow full of malware
114d ago
New NGate variant hides in a trojanized NFC payment app
116d ago
What the ransom note won’t say
117d ago
That data breach alert might be a trap
120d ago
Supply chain dependencies: Have you checked your blind spot?
121d ago
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike
127d ago
As breakout time accelerates, prevention-first cybersecurity takes center stage
130d ago
Digital assets after death: Managing risks to your loved one’s digital estate
136d ago
This month in security with Tony Anscombe – March 2026 edition
137d ago
RSAC 2026 wrap-up – Week in security with Tony Anscombe
141d ago
A cunning predator: How Silver Fox preys on Japanese firms this tax season
142d ago
Virtual machines, virtually everywhere – and with real security gaps
143d ago
Cloud workload security: Mind the gaps
144d ago
Move fast and save things: A quick guide to recovering a hacked account
148d ago
EDR killers explained: Beyond the drivers
149d ago
Face value: What it takes to fool facial recognition
155d ago
Cyber fallout from the Iran war: What to have on your radar
156d ago
48 loaded
AL
Alerts
58d ago · 44 items
CISA Adds One Known Exploited Vulnerability to Catalog
58d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
58d ago
CISA Adds One Known Exploited Vulnerability to Catalog
60d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
61d ago
CISA Adds One Known Exploited Vulnerability to Catalog
64d ago
CISA Adds One Known Exploited Vulnerability to Catalog
65d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
67d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
68d ago
CISA Adds One Known Exploited Vulnerability to Catalog
71d ago
CISA Adds One Known Exploited Vulnerability to Catalog
73d ago
CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
74d ago
CISA Adds One Known Exploited Vulnerability to Catalog
75d ago
CISA Adds One Known Exploited Vulnerability to Catalog
78d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
79d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
80d ago
CISA Adds One Known Exploited Vulnerability to Catalog
81d ago
CISA Adds One Known Exploited Vulnerability to Catalog
85d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
86d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
87d ago
CISA Adds One Known Exploited Vulnerability to Catalog
92d ago
CISA Adds One Known Exploited Vulnerability to Catalog
93d ago
CISA Adds One Known Exploited Vulnerability to Catalog
99d ago
CISA Adds One Known Exploited Vulnerability to Catalog
100d ago
CISA Adds One Known Exploited Vulnerability to Catalog
101d ago
CISA Adds One Known Exploited Vulnerability to Catalog
106d ago
CISA Adds One Known Exploited Vulnerability to Catalog
107d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
109d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
113d ago
CISA Adds One Known Exploited Vulnerability to Catalog
114d ago
CISA Adds One Known Exploited Vulnerability to Catalog
115d ago
Supply Chain Compromise Impacts Axios Node Package Manager
117d ago
CISA Adds Eight Known Exploited Vulnerabilities to Catalog
117d ago
CISA Adds One Known Exploited Vulnerability to Catalog
121d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
123d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
124d ago
CISA Adds One Known Exploited Vulnerability to Catalog
129d ago
CISA Adds One Known Exploited Vulnerability to Catalog
131d ago
CISA Adds One Known Exploited Vulnerability to Catalog
135d ago
CISA Adds One Known Exploited Vulnerability to Catalog
136d ago
CISA Adds One Known Exploited Vulnerability to Catalog
138d ago
CISA Adds One Known Exploited Vulnerability to Catalog
141d ago
CISA Adds One Known Exploited Vulnerability to Catalog
142d ago
CISA Adds One Known Exploited Vulnerability to Catalog
143d ago
CISA Adds Five Known Exploited Vulnerabilities to Catalog
148d ago
44 loaded
AC
All CISA Advisories
58d ago · 125 items
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
58d ago
CISA Adds One Known Exploited Vulnerability to Catalog
58d ago
Schneider Electric EasyLogic T150 and Saitel DP
58d ago
AVer PTC cameras
58d ago
Rockwell Automation FactoryTalk Historian Site Edition
58d ago
AzeoTech DAQFactory
58d ago
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
58d ago
Mitsubishi Electric MELSEC iQ-F Series
58d ago
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
58d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
58d ago
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
60d ago
Rockwell Automation RSLinx
60d ago
Rockwell Automation FLEX I/O EtherNet/IP Adapters
60d ago
Rockwell Automation FactoryTalk Analytics PavilionX
60d ago
Rockwell Automation CompactLogix
60d ago
CISA Adds One Known Exploited Vulnerability to Catalog
60d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
61d ago
CISA Adds One Known Exploited Vulnerability to Catalog
64d ago
Yarbo Android/iOS Mobile Application and Cloud Infrastructure
65d ago
Naxclow IoT Platform
65d ago
Brickcom Cameras
65d ago
CISA Adds One Known Exploited Vulnerability to Catalog
65d ago
Siemens KACO Blueplanet Inverters
67d ago
Schneider Electric EcoStruxure Panel Server
67d ago
Schneider Electric Modicon Network Managed Switches
67d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
67d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
68d ago
CISA Adds One Known Exploited Vulnerability to Catalog
71d ago
NAVTOR NavBox
72d ago
Hitachi Energy MACH HiDraw
72d ago
Hitachi Energy ITT600 Explorer
72d ago
B&R PPT30 Operating System
72d ago
Hitachi Energy RTU500
72d ago
CISA Adds One Known Exploited Vulnerability to Catalog
73d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
74d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
74d ago
CISA Adds One Known Exploited Vulnerability to Catalog
75d ago
CISA Adds One Known Exploited Vulnerability to Catalog
78d ago
ABB EIBPORT
79d ago
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
79d ago
ABB Busch-Welcome 2 Wire Door Opener Actuator
79d ago
Fourth Frontier Frontier X Mobile Application, Frontier X2
79d ago
CP Plus 8 Ch. Network Video Recorder
79d ago
XCharge C6
79d ago
KMW CCTV Security Cameras
79d ago
MacGregor Voyage Data Recorder (VDR) G4e
79d ago
Schnieider Electric EcoStruxure Machine Expert HVAC
79d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
79d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
80d ago
ABB Terra AC
81d ago
ABB LVS MConfig
81d ago
ABB Ability Camera Connect
81d ago
Eppendorf BioFlo 320
81d ago
ABB AbilityTM Zenon Remote Transport Vulnerability
81d ago
ABB AC500 V2
81d ago
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
81d ago
CISA Adds One Known Exploited Vulnerability to Catalog
81d ago
CISA Adds One Known Exploited Vulnerability to Catalog
85d ago
ABB Terra AC Wallbox
86d ago
Hitachi Energy GMS600
86d ago
ABB B&R Automation Studio
86d ago
ABB B&R Automation Runtime
86d ago
ABB B&R PCs
86d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
86d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
87d ago
Kieback & Peter DDC Building Controllers
88d ago
Siemens RUGGEDCOM APE1808 Devices
88d ago
ABB CoreSense HM and CoreSense M10
88d ago
ScadaBR
88d ago
ZKTeco CCTV Cameras
88d ago
CISA Adds One Known Exploited Vulnerability to Catalog
92d ago
Siemens Siemens ROS#
93d ago
Siemens gWAP
93d ago
Siemens SIMATIC
93d ago
Siemens Ruggedcom Rox
93d ago
Siemens Ruggedcom Rox
93d ago
Siemens Simcenter Femap
93d ago
Universal Robots Polyscope 5
93d ago
Siemens Ruggedcom Rox
93d ago
Siemens Teamcenter
93d ago
Siemens Solid Edge
93d ago
Siemens SENTRON 7KT PAC1261 Data Manager
93d ago
Siemens Opcenter RDnL
93d ago
Siemens Ruggedcom Rox
93d ago
Siemens SIMATIC S7 PLC Web Server
93d ago
Siemens Industrial Devices
93d ago
Siemens SIMATIC
93d ago
Siemens SIPROTEC 5
93d ago
CISA Adds One Known Exploited Vulnerability to Catalog
93d ago
Software Bill of Materials for AI - Minimum Elements
95d ago
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
95d ago
Subnet Solutions PowerSYSTEM Center
95d ago
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities
95d ago
ABB AC500 V3 Multiple Vulnerabilities
95d ago
ABB Automation Builder Gateway for Windows
95d ago
Fuji Electric Tellus
95d ago
CISA Adds One Known Exploited Vulnerability to Catalog
99d ago
CISA Adds One Known Exploited Vulnerability to Catalog
100d ago
MAXHUB Pivot Client Application
100d ago
CISA Adds One Known Exploited Vulnerability to Catalog
101d ago
ABB B&R Automation Studio
102d ago
ABB B&R Automation Runtime
102d ago
Hitachi Energy PCM600
102d ago
Johnson Controls CEM AC2000
102d ago
ABB B&R PVI
102d ago
CISA Adds One Known Exploited Vulnerability to Catalog
106d ago
Careful Adoption of Agentic AI Services
106d ago
ABB AWIN Gateways
107d ago
ABB Ability OPTIMAX
107d ago
ABB PCM600
107d ago
ABB Edgenius Management Portal
107d ago
CISA Adds One Known Exploited Vulnerability to Catalog
107d ago
ABB Ability Symphony Plus Engineering
107d ago
ABB System 800xA, Symphony Plus IEC 61850
107d ago
Adapting Zero Trust Principles to Operational Technology
108d ago
NSA GRASSMARLIN
109d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
109d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
113d ago
SpiceJet Online Booking System
114d ago
Carlson Software VASCO-B GNSS Receiver
114d ago
Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera
114d ago
Milesight Cameras
114d ago
Defending Against China-Nexus Covert Networks of Compromised Devices
114d ago
Yadea T5 Electric Bicycle
114d ago
Intrado 911 Emergency Gateway (EGW)
114d ago
125 loaded
CY
cybersecurity
65d ago · 1867 items
Any solutions we can use?
65d ago
Possible targeted attack
65d ago
RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline
65d ago
Facebook messenger to text
65d ago
Managing Solution Agents
65d ago
Nottingham University data breach affects over 450,000 students
65d ago
SWGs that support 3rd party external DNS resolver
65d ago
Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers
65d ago
Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG
65d ago
Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch
65d ago
Phishing awareness training resulting in ignoring company comms?
65d ago
How are you analyzing Android malware nowadays?
65d ago
Hackers Exploit Langflow Vulnerability for Remote Code Execution
65d ago
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research
65d ago
NEED SOME GUIDANCE
65d ago
Help setting up local encryption on my pc
65d ago
Agentic AI on Cybersecurity
65d ago
DoD 0-days Typically Come Down to Authorization Failures
65d ago
HDD
65d ago
Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets
65d ago
How can we test the firmware code/images security?
65d ago
20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004
65d ago
GitHub announces npm security changes to tackle supply-chain attacks
65d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
65d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
65d ago
What is the difference between Regular TLS and Mutual TLS?
66d ago
Every employee's password was stored in a single Excel file
66d ago
npm v12 is changing how dependencies are installed to reduce supply-chain risk
66d ago
Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia?
66d ago
How good Microsoft Defender for storage?
66d ago
GreatXML bitlocker bypass vulnerability
66d ago
Struggle
66d ago
Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications?
66d ago
Wiz launches Cloud Security Job Board
66d ago
Physical Project Ideas
66d ago
How can I get into cybersecurity while studying Information Systems Engineering?
66d ago
Cloud Security job board
66d ago
Continuous learning
66d ago
Angry bug hunter with Microsoft beef drops new Windows 0-day
66d ago
Mid-30s, stuck in web pentesting, and wondering what to do ?
66d ago
Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM
66d ago
Is Microsoft Purview really secure when using Copilot?
66d ago
Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature?
66d ago
Nee academic references for Hashcat's 'Next Big Bang' log
66d ago
CISA released BOD 26-04: A new federal government vulnerability management strategy?
66d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
66d ago
added Mac support to my corporate hacking sim. Demo now available on Steam
66d ago
Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte)
66d ago
Students' data taken in major University of Nottingham cyber-attack
66d ago
Has unmanaged external file sharing ever burned you?
66d ago
Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers
66d ago
Need feedback on my presentation
66d ago
Compensating controls besides admin credentials being needed to download software on employee endpoints
66d ago
OpenSSL PKCS#7 CVE-2026-45447
66d ago
Presentation Question
66d ago
How to Stay Ahead of Deepfake Evolution in 2026
66d ago
France’s Government Messaging App Tchap Got Breached
66d ago
Where's the fix for MiniPlasma?
66d ago
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
67d ago
Internships
67d ago
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
67d ago
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
67d ago
Looking for a Reliable Cybersecurity Provider for a School in North Sydney
67d ago
Early Operational Visibility
67d ago
how are you actually managing ai agents in production?
67d ago
Al app builders: How are you handling security questionnaires when selling your product?
67d ago
[ Removed by Reddit ]
67d ago
How are all of doing with THE AI model thats big news currently??
67d ago
Skill to Scan your Codebase
67d ago
Miasma-style supply chain attacks
67d ago
FCaptcha v1.12: Catching AI Agents That Drive Real Browsers
67d ago
Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones
67d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
67d ago
AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say
67d ago
Huntress Stack (MS Defender or SentinelOne)
67d ago
META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT
67d ago
FBI is announcing Operation Riptide
67d ago
ServiceNow confirmed some customer instances were breached.
67d ago
Which are some of the best Cybersecurity / OT Security events that happen in GCC?
67d ago
DF/IR Community
67d ago
Chaotic Eclipse's new RoguePlanet
67d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
67d ago
Thoughts on Automated Compliance?
67d ago
A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available
67d ago
North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says
67d ago
Microsoft has released a patch for the bitlocker bypass
67d ago
Please advices
67d ago
soc analyst l1
67d ago
Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow
67d ago
Looking to move off KnowBe4, what are people actually using these days?
67d ago
Too Many Certs, Not Enough Experience — What’s the Best Next Step?
67d ago
Authenticating ARP and NDP
67d ago
Does anyone use rule feeds in 2026?
67d ago
Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations!
67d ago
Need a vm for practice
67d ago
Tips/Tricks to WFH as a SOC Analyst?
67d ago
Cybersecurity statistics of the week (June 1st - June 7th)
67d ago
Where can GRC folks learn practical AppSec / DevSecOps without going full engineer?
67d ago
I almost got “onboarded” into a malware campaign disguised as a job opportunity.
67d ago
University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model
67d ago
AI Blocklist - help
67d ago
Protecting AI workloads on Linux servers
67d ago
Exposing DoNex Ransomware Secrets with Malcore!
67d ago
What are the different Disaster Recovery scenarios your teams have tested on?
67d ago
someone actually leaked the Miasma supply chain attack toolkit source code on github
67d ago
WinGet - Code Execution, Persistence and Detection Strategies
67d ago
Ransomware attack shuts Illinois high school until Wednesday
67d ago
Ideas for demo
67d ago
Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please?
67d ago
Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares.
67d ago
Physical attack device
67d ago
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
67d ago
IT GRC News?
67d ago
Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again
67d ago
Shifting L7 validation to the edge to stop DB resource exhaustion?
68d ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
68d ago
EC Council CEH exam advice
68d ago
About NPower vs PerScholas
68d ago
Looking for a vulnerability to learn
68d ago
From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk
68d ago
Bad USB through charger?
68d ago
Recommendations for Discord community for latest AI security products
68d ago
Vulnerability Summary for the Week of June 1, 2026
68d ago
Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas
68d ago
I feel like ive lost my passion to tinker after 6 years in the industry, anyone else?
68d ago
I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples
68d ago
really need help with project ideas for MSc
68d ago
Which Course for an almost-complete noob? (SANS.edu)
68d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
68d ago
For the 2nd time in weeks, Microsoft packages laced with credential stealer
68d ago
Iran Signed a Ceasefire — Its Hackers Didn't
68d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
68d ago
DSPM étude marche
68d ago
CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file
68d ago
AppSec / Pentesting job market in Canada for experienced overseas applicants?
68d ago
Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients.
68d ago
Automation Playbooks - which ones would you not want to live without?
68d ago
Is it necessary/important to Hash and salt API Keys for a strictly internal use tool?
68d ago
Need review on the OMS Cybersecurity program from Georgia Tech?
68d ago
If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk
68d ago
2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years
68d ago
How do you close an alert
68d ago
What cybersecurity certifications are great value for money?
68d ago
Boxes for CPENT
68d ago
SIEM: is it "SIM" or "SEEM"
68d ago
I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included)
68d ago
How justdeleteme and justgetmydata work?
68d ago
I need help - PCI DSS 4.0 requirement 11.6.1
68d ago
How are you learning agent pen testing?
68d ago
Cyber security intern
68d ago
Meta to take legal action against Israeli spyware company NSO
68d ago
Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit
68d ago
What's the best way to alert companies of a Glassworm copycat?
68d ago
How To Verify If A Site Is Legit?
68d ago
What is Flaresolverr
68d ago
Research: defenders using generative AI to simulate malware variants before they exist in the wild
68d ago
How are regulated orgs actually letting engineers use Claude Code / Copilot?
68d ago
Cyber security expo Manchester
68d ago
Remote Hiring Opened the Talent Pool — and the Fraud Surface
68d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
68d ago
What certs should I do during summer of 11th grade?
68d ago
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
68d ago
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine
68d ago
Oxford University discloses data breach after careers platform hack
68d ago
Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing
68d ago
Got this message from “SimBoss”
68d ago
PKCS12 Golang fork
68d ago
Malware Insights: Miasma Campaign
68d ago
73 Microsoft GitHub repositories impacted by Miasma malware
68d ago
[Honeypot Research] Looking for volunteers to test telemetry/logs
68d ago
What is the condition of Bug Bounty program in the era of AI.
69d ago
Opening a cloned repo is no longer safe
69d ago
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
69d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
69d ago
Google Colab CLI opens runtimes to Claude Code and Codex
69d ago
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
69d ago
The AI governance gap no one is talking about: deployment-stage accountability
69d ago
Free Study Resources for Comptia Cysa+
69d ago
Mentorship Monday - Post All Career, Education and Job questions here!
69d ago
Hi there
69d ago
Final risk-based IT Audit interview round with Director and have no experience. Please help!
69d ago
Needed help
69d ago
[ Removed by Reddit ]
69d ago
Career advice
69d ago
PhD in cyber Security
69d ago
Built a password guessing game. Almost everyone stuck in level 5.
69d ago
OSINT (SOCIAL MEDIA)
69d ago
Beginner KQL project
69d ago
Question about WORM and encryption
69d ago
Update:Certified cyber security
69d ago
Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental
69d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction)
69d ago
Malware that survives reinstalling the BIOS and OS
69d ago
Am I overthinking the x86 compatibility issues? how much friction am I actually facing?
69d ago
Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure
69d ago
Managing Microsoft Identity Is More Complicated Than It Looks
69d ago
My work email got subscribed to a bunch of israel newsletters
69d ago
Shadow AI
69d ago
Rate limiting is not enough. What else can I use?
69d ago
How To Avoid Potential Malware From Transferring To New Laptop
69d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
69d ago
Can't decide.
69d ago
looking for partners
69d ago
My edge is changing into bing when I search something
69d ago
Cybersecurity reality check
69d ago
[ Removed by Reddit ]
69d ago
Information Management
69d ago
IronWorm Malware
70d ago
Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh?
70d ago
Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh?
70d ago
Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager
70d ago
Is a separate “clean” S3 bucket actually a security boundary for uploaded files?
70d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
70d ago
PenTest+ Exam
70d ago
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
70d ago
Looking for guidance
70d ago
Before you attempt any OffSec certification, read what just happened to me
70d ago
Reporting Metrics for Management
70d ago
got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time
70d ago
Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried
70d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
70d ago
AI Security Certificates
70d ago
Guys is bug bounty dead?
70d ago
How are folks making it in bug bounty?
70d ago
How useful is it to require at least one uppercase letter in a password?
70d ago
Cyber security ! Is no more ?
70d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
70d ago
Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months
70d ago
Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories
70d ago
How to train employees to feel when something's off?
70d ago
ALERT OVERLOAD
70d ago
CTO at NCSC Summary: week ending June 7th
70d ago
A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled
70d ago
Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub
71d ago
AppSec Engineer Interview Stories
71d ago
[OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps.
71d ago
Is there a safe way to continue using (unsupported) Windows 10?
71d ago
Is Splunk suitable for smaller Enterprises?
71d ago
Has anyone else had MFA prompt fatigue issues with users?
71d ago
Data Scrubbing from Databases
71d ago
Best Certificates?
71d ago
Rant
71d ago
New York passes data center moratorium and consumer protections as environmental, and housing proposals stall
71d ago
Cyber attackers have a new favorite, the browser
71d ago
Looking to get into cybersecurity in web3
71d ago
Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests
71d ago
Should i use email 2fa or only auth and phone number?
71d ago
Can I break into cybersecurity with a white collar felony?
71d ago
Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale
71d ago
How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time?
71d ago
What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent?
71d ago
How Hard is This
71d ago
Installed Fake Codex hidden as a google site
71d ago
Virustital scan result help
71d ago
CrowdStrike Turned an AI Wave Into Its Best Quarter Ever
71d ago
Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions?
71d ago
I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now
71d ago
Being a Security Engineer? Which AI-powered tools are you using on a daily basis?
71d ago
Over 900 US gas station tank gauge systems exposed to attacks
71d ago
Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person
71d ago
SIEM is broken in the AI agents era
71d ago
Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected
71d ago
Phantom Gyp npm Worm Abuses node-gyp Build Hooks
71d ago
Certified cybersecurity ISC2
71d ago
Help studying for OSCP
71d ago
The current state of Threat Intelligence Tooling
71d ago
Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware
71d ago
We tested offensive AI agents against deception technology
71d ago
A matter that I have been losing my sleep over
71d ago
Any experience with Rootly or incident.io for cyber incident management?
71d ago
CTIA Study Resources & Preparation Advice?
71d ago
Black hat uk vs brucon
71d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
71d ago
NIS2 hits railway hard
71d ago
I need help guys… :(
71d ago
Question from the Seniors
71d ago
China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware
71d ago
what certs have u seen in ai security related job posts ?
71d ago
How is the Security Architecture / Strategic IT Security process structured in your organization?
71d ago
What's happening in cybersecurity job market in US and Europe these days?
71d ago
Has any of you pivoted from GRC to CTI?
72d ago
Up-date-list of cybercrime types?
72d ago
What else should I learn to build a strong cybersecurity foundation?
72d ago
Hackerone interview
72d ago
Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix
72d ago
Testing URL Rewriting?
72d ago
Got an internship in IAM with no qualifications and no soft skills
72d ago
Work Hours of DFIR/Cloud Security vs Pentest
72d ago
Narcissistic Tech Leader....
72d ago
Anyone else's firewall logs just explode after midnight?
72d ago
I'm replacing myself.. at least the boring parts
72d ago
Anyone else dealing with these phantom login attempts from China?
72d ago
Best way to fully clear windows and set everything up securely (pc, accounts etc)
72d ago
IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks
72d ago
Soc analyst
72d ago
Do companies actually require cybersecurity insurance
72d ago
Uncommon/Unusual CrowdStrike Alerts
72d ago
Cyber analyst: law firm or bank
72d ago
best free av and how do i properly setup passwords?
72d ago
Five 9 Vulnerability
72d ago
CVE Lite CLI closes dependency gap — but won't stop modern threats
72d ago
Scope change
72d ago
We just stopped a social engineering attack on our service desk. Here’s how it played out.
72d ago
What is the most underestimated cybersecurity risk right now?
72d ago
Update: Company is paying for any certification, which should I obtain? Except Sans
72d ago
New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification
72d ago
Anyone else's firewall vendor docs a total nightmare?
72d ago
Your opinions about a learning style
72d ago
Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks
72d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
72d ago
Anyone else see their firewall logs just explode after a cloud update?
72d ago
Are certifications necessary to get a job in cybersecurity?
72d ago
Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass)
72d ago
Is retyping and translating textbooks too inefficient for CS/Cybersecurity?
72d ago
Free Microsoft Enterprise Security Assessment: Worth It
72d ago
How are organizations preparing for AI-generated phishing attacks?
72d ago
Inside the race to adapt to an AI-powered security world
72d ago
127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For
72d ago
Microsoft blames unexpected Windows driver updates on caching issue
72d ago
Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance)
72d ago
Your CPU model leaks through the browser via WASM timing differences
72d ago
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
72d ago
Security Engineer 2 interview at Amazon coming up - What to expect?
72d ago
A researcher spent $1,500 testing if LLMs could hack a vulnerable app
72d ago
Help with university internship
72d ago
Are MCP servers becoming the next API security nightmare?
72d ago
What's the cybersecurity lesson you learned the hard way?
72d ago
ISO 27001 Surveillance audit vs Full recertification
72d ago
How important it is to get paid Cybersecurity certificates ?
72d ago
Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process
72d ago
Soc to Architecture
72d ago
Does "example file vulnerability" exists?
72d ago
VS code forces 2 hour cool down for most integrations.
72d ago
Company laptop isolated after Brave/Tor alert - should I be worried?
72d ago
Does anyone know how to send false positive to SOCradar ? virus total
72d ago
Looking for people to team up for Bug Bounties & CTFs
73d ago
Signal Without Smartphone
73d ago
I found a trojan on my pc and now im scared my private calls got leaked
73d ago
Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests
73d ago
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
73d ago
How do you change users behavior through awareness training?
73d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
73d ago
Safe Rust API for wolfSSL/wolfCOSE
73d ago
Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma)
73d ago
AMD GPU Users might be compromised
73d ago
[ Removed by Reddit ]
73d ago
Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information
73d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
73d ago
[CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF
73d ago
how to get good at cyber security?
73d ago
Anyone use CrunchAtlas?
73d ago
Prompt monitoring laughs
73d ago
Malicious Payload in ai-sdk-ollama npm Package
73d ago
Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24)
73d ago
what the HELL is dsztfso?
73d ago
Yubikey Alternative....?
73d ago
Hiring
73d ago
CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing
73d ago
Certification Advice
73d ago
Question about Linux kernel TLS ULP disclosed June 2 to oss-security
73d ago
An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this?
73d ago
How to Rob a Data Center (new article on data center physical security)
73d ago
US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server
73d ago
Is it worth taking the EC councils masters program?? Are they legit /2026
73d ago
Mid-level AppSec engineers: what do you actually study to prep for interviews?
73d ago
Company is paying for any certification, which should I obtain?
73d ago
Trusting Microsoft with your offensive security repos
73d ago
Automated Fault Injection Attack Framework
73d ago
Physical Biometric device as a security measure..??
73d ago
Cybersegurança
73d ago
Started Learning Cybersecurity
73d ago
InfraGard Application - Seeking Help | Student
73d ago
Orientación en Ciberseguridad
73d ago
Anthropic's coordinated vulnerability disclosure dashboard
73d ago
Hands Free: What LLM Driven Vulnerability Research Looks Like
73d ago
Real time Cybersecurity failures regarding Quantum computing/cryptography
73d ago
🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It.
73d ago
A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out.
73d ago
CISA warns of active attacks exploiting Android, Linux bugs
73d ago
Found some open ports on a govt site, should i report or stay quiet?
73d ago
What is a good way to keep track of passwords for programs that don't support password managers?
73d ago
Cybersecurity statistics of the week (May 25th - May 31st)
73d ago
ASN Emissions Index. Networks ranked by how much noise they create on the internet.
73d ago
Have you sold cve before?
73d ago
i want to become a pentester, but i don't know how to
73d ago
The OT Security Problem Nobody Wants to Own
73d ago
Don't Take Wednesday Off When You Manage Vulnerabilities
73d ago
I finally finished a production version after 4 yrds
73d ago
Support role pivot to cloud security
73d ago
How do you manage your passwords?
73d ago
Mad rush to produce AI driven slop
73d ago
O Tails é seguro para acessar links suspeitos?
73d ago
Cyber Essentials plus + "legacy" network segments
73d ago
Insight for OPSWAT deep CDR
73d ago
Android vs iOS
73d ago
ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account
73d ago
Security Audits at an MSP
73d ago
[ Removed by Reddit ]
73d ago
Passkey registration breaks after moving off localhost..
73d ago
Does your team hire fresh AI engineer who doesn't know anything about Security operations?
73d ago
UARs for Equation (banking system)
73d ago
IoT pentesting cert
74d ago
Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations
74d ago
Experience with Tac Security
74d ago
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
74d ago
Found Security Vulnerabilities in my university website
74d ago
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence
74d ago
AI - Threat to the CyberSec Industry?
74d ago
Built a honeypot platform to catch lateral movement. How are you guys detecting this?
74d ago
How should small SaaS teams safely answer customer security questionnaires?
74d ago
Can AI Do Intelligence Analysis? Apparently Not.
74d ago
PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model
74d ago
Regarding Certified Ethical Hacker (CEH Practical) exam
74d ago
Asking for advices on pursuing first CERTIFICATE
74d ago
I opened my own company and I can't find clients!
74d ago
ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter
74d ago
Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU?
74d ago
Anyone knows Quad9 dns ?
74d ago
I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ?
74d ago
Greynoise swarm
74d ago
SecOT+ certification for free
74d ago
How is the state of the job market for mid-level security engineers?
74d ago
Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things
74d ago
WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total
74d ago
Laid off from TPRM job - need help on the future of my career
74d ago
Anyone compared RoboShadow vs ConnectSecure for vulnerability management?
74d ago
Any one send vulnerability to MITRE?
74d ago
Need advice for a 30 min Security Apprenticeship interview
74d ago
UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS
74d ago
Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match
74d ago
Virustotal API as private data source
74d ago
Account Number Security Flaw
74d ago
Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning?
74d ago
A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth
74d ago
[ Removed by Reddit ]
74d ago
[ Removed by Reddit ]
74d ago
Phishing simulation platform
74d ago
Just task about OSI model
74d ago
Need help improving DNS Spy from a security tool angle
74d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
74d ago
Oracle's first monthly patch update just dropped 77 CVEs.
74d ago
Cleaning up after a legacy service account breach. How are you handling automated secrets discovery?
74d ago
Airbus digital apprenticeship
74d ago
Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities
74d ago
Google fixes one actively exploited Android zero-day, 124 flaws
74d ago
Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force
74d ago
Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis?
74d ago
Security Architects who who actively use modelling - What's your approach?
74d ago
PAN-OS authentication bypass bug added to list of exploited vulnerabilities
74d ago
I have extreme anxiety about being hacked
74d ago
Fresher
74d ago
Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach
74d ago
Career advice needed!
74d ago
GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
75d ago
Google sr. security engineer interview
75d ago
Is offensive AI actually changing cybersecurity, or are we overestimating the impact?
75d ago
Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave
75d ago
is emerald chat safe?
75d ago
Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ?
75d ago
ClickJack in the wild
75d ago
Thoughts on A.I assisted Malware Analysis?
75d ago
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
75d ago
What articles do you use for cybersecurity news? (2026)
75d ago
Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider?
75d ago
Roadmap and Training Recommodation
75d ago
Les anti-triche de niveau noyau et leur risque de sécurité
75d ago
Asked to Send Sensitive Documents via MMS
75d ago
SC-200 compared to CC (isc2)
75d ago
Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now
75d ago
Looking to move off KB4, what are people actually using these days?
75d ago
Got my Security+. What's next?
75d ago
Vulnerability Summary for the Week of May 25, 2026
75d ago
Malware
75d ago
Alternative Search Engine to Utilize in 2026?
75d ago
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
75d ago
Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild
75d ago
Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers
75d ago
AI compliance
75d ago
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
75d ago
Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains?
75d ago
MacBook or Windows Laptop for Cybersecurity
75d ago
What's the most creative MFA bypass you've seen?
75d ago
Research Notes from Building a Windows Event Log Hunting Workflow
75d ago
How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ??
75d ago
Free AI tools for TPRM?
75d ago
incomplete phone number from togo, need help reporting to police
75d ago
NPM packages from RedHat Compromised
75d ago
Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts
75d ago
SOC Analyst working towards Threat Intelligence
75d ago
Is XSS possible through PDFs?
75d ago
The Next AI Governance Failure Won’t Be the Model
75d ago
Microsoft MFA Is Down Again
75d ago
Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927)
75d ago
Computer logic or Science
75d ago
I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for?
75d ago
What C2s Are You Using
75d ago
PNPT Exam
75d ago
What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification?
75d ago
Any appsec engineer working in fortune 500?
75d ago
I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next
75d ago
Anyone transition from AWS Data Center Operations to InfoSec?
76d ago
I think my account got hacked but it's weird
76d ago
current market for detecting deepfakes?
76d ago
Worried about friend being doxxed on doxbin
76d ago
how to shift from a service based company to a product based one in cybersecurity ?
76d ago
Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA
76d ago
Claude AI user data directory exfiltration via malicious npm package
76d ago
Bitdefender blocking amd stuff? False positive or?
76d ago
Mentorship Monday - Post All Career, Education and Job questions here!
76d ago
did they have my password?? what triggers this specific email??? instagram HELP.
76d ago
ATTENTION: Dashlane may have been breached. (Password manager).
76d ago
Norton blocked a “malicious script”?
76d ago
Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts
76d ago
Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive.
76d ago
I wrote about the 5 biggest threats in 2026, curious what this community thinks.
76d ago
MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce?
76d ago
Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions?
76d ago
NetworkChuck
76d ago
LLM for creating phishing tool
76d ago
Why are we still treating IAM like a compliance checkbox?
76d ago
Polyfill pop up?
76d ago
SecAI+ difficulty question
76d ago
Could you guys give an honest feedback to a completely automated ssrf attack tool?
76d ago
tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me
76d ago
Microsoft Joined the DMARC Club
76d ago
Help.
76d ago
Vibe Coding Security
76d ago
Looking for a Company to Partner With
76d ago
Best reporting tools?
76d ago
What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months)
76d ago
How Can Polyfill.io Still Act Maliciously?
77d ago
Need THM voucher code for cheap? Any known seller?
77d ago
Ghost passwords?
77d ago
Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not.
77d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
77d ago
Anyone else having Chatgpt Strikes / Violations while learning cybersecurity?
77d ago
Working at Cisco, worth it?
77d ago
Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice
77d ago
Are you pen testing AI Agents?
77d ago
Question of android malware
77d ago
External attack surface: how are you correlating DNS, SSL, and IP reputation today?
77d ago
how do i properly setup 2fa and bitwarden?
77d ago
Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC)
77d ago
i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested?
77d ago
Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever?
77d ago
Can Steam Cloud Files Transfer Malware
77d ago
Questions for the cloud security engineers
77d ago
Thoughts on this as a starter and doing bug bounty on the side
77d ago
How are new SC-200 candidates practicing labs without an E5 Developer tenant?
77d ago
Getting OTP spammed from every app and website I've ever used. Should I be worried?
77d ago
A browser tool for checking contractor insurance certificates
77d ago
Am I getting screwed?
77d ago
SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers
77d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
77d ago
CTO at NCSC Summary: week ending May 31st
77d ago
BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship
77d ago
Need suggestion
78d ago
[INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety)
78d ago
Was Dave Bittner interviewing an AI?
78d ago
CTF for complete beginner
78d ago
Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques?
78d ago
AI-Era Cyber Risk Standards
78d ago
BEC Victim - Attacker replied inside a real email thread using a lookalike domain
78d ago
Question for those who transitioned from remote to work from anywhere
78d ago
Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors
78d ago
Do you enjoy what you do or do you wish you could go back in time and change it?
78d ago
Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber?
78d ago
For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year?
78d ago
Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ?
78d ago
Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years?
78d ago
Botnet of more than 17 million devices dismantled
78d ago
Exposed credentials on logs
78d ago
What do you think is the biggest cybersecurity risk for small businesses in 2026?
78d ago
Wanted to shift to cloud security, but have some questions
78d ago
Zero Trust is Overrated? Navigating the Complexity
78d ago
Test API post with flair
78d ago
Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications
78d ago
How Do You Handle the Massive Amount of Information in the CPTS Path?
78d ago
Help an upcoming cybersecurity engineer!
78d ago
Repeated Microsoft MFA attempts even after password change
78d ago
What Is Device Intelligence and How Does It Stop Fraud?
78d ago
[FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE)
78d ago
IBM commits $5 billion to secure open-source software
78d ago
Structuring an AI-Assisted Pentesting Homelab for a Final Year Project
78d ago
Are teams actually monitoring LLM traffic in production environments?
78d ago
How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA)
78d ago
Raspberry pi
78d ago
What is the biggest obstacle to using AI safely in a company?
78d ago
Advice going forward
78d ago
MCP Firewall help
78d ago
I wanted to shift to security but people told me the market is extremely bad, is that true?
78d ago
Best Personality Type/Traits for Working in Cyber Security
78d ago
A fake freelance job interview almost installed malware on my PC
78d ago
Is there a viable career path here or am I just being delusional?
78d ago
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
78d ago
How do enterprises actually prevent developers from exfiltrating source code?
78d ago
I have a datastealer malware
78d ago
Dúvida de carreira.
78d ago
Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace
78d ago
Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated
78d ago
is SIEM really needed here ?
78d ago
Decompiled an app, found a bunch of secrets, what now?
78d ago
Can someone give me a correct method for learning reverse engineering?
78d ago
Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months
78d ago
GRC Advise
78d ago
[ Removed by Reddit ]
79d ago
Did something happen to haveibeenpwned? Any alternatives?
79d ago
RAT SUSPECTED
79d ago
How do people afford certificate s?
79d ago
I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed?
79d ago
Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
79d ago
Phone Forwarding
79d ago
Opinions on running Full Microsoft E5 Security Stack
79d ago
Claiming "XDR"
79d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
79d ago
Microsoft security
79d ago
Need help regarding building a home lab
79d ago
Should I turn on passwordless accounts for all my Microsoft accounts?
79d ago
Transitioning from AWS Data Center Operations to Security Engineering
79d ago
Probably the wrong place.
79d ago
What after IT helpdesk?
79d ago
How are you security-testing API changes before production without slowing CI/CD?
79d ago
Are we trusting update repos or are you all extra paranoid now as well?
79d ago
Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops
79d ago
Prevent supply chain attacks
79d ago
Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems
79d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
79d ago
Hackers are trying to steal Signal users' backups in new wave of phishing attacks
79d ago
Incident Response Testing Preparation
79d ago
Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference
79d ago
[Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥
79d ago
3rd Party NFC cards.. secure?
79d ago
Vulnerability Management Tickets & SLA
79d ago
Defending at Machine-Speed: Building AI Threat Readiness
79d ago
AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved
79d ago
HEAD request body processing leading
79d ago
Malicious npm Package Stole Files From Claude AI User Directory via GitHub
79d ago
Does anyone have an app like substack to keep being updated and engaging within the cyber domain?
79d ago
What’s an attack vector people massively underestimate in 2026?
79d ago
We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7
79d ago
A Deeper Look at GLASSWORM's Solana Variant
79d ago
Calling Cyber Security Beginners
79d ago
Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis
79d ago
built something for ai agents, ended up looking a lot like classic appsec
79d ago
Is Gophish still usable in 2026?
79d ago
Microsoft vs Chaotic Eclipse: three zero-days now actively exploited
79d ago
what do you think
79d ago
Why would be clicking a website, redirect me?
79d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
79d ago
Writing cybersecurity policies is a waste of time
79d ago
Raising the Cybersecurity Stakes: Ante up for the Agentic Era.
79d ago
Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it.
79d ago
[ Removed by Reddit ]
79d ago
Released: Dataforge Honeypot
79d ago
Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
79d ago
CEH-free
79d ago
Hottest cybersecurity open-source tools of the month: May 2026
79d ago
Preparation tips for CPENT
79d ago
How do you handle AI tools in your organization?
79d ago
I think i got scammed anybody can help me with that
80d ago
New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo
80d ago
Is it safe to have passwords copied to clipboard on IOS temporarily?
80d ago
Developers working on anti-fraud systems deserve more credit
80d ago
My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst
80d ago
Security awareness training for AI heavy smb workflows?
80d ago
Minimum Requirements for Helpdesk Role ?
80d ago
Reddit spear phishing
80d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
80d ago
What to do
80d ago
What resources would you recommend for studying cysa+
80d ago
Provenance of Data
80d ago
Websites have a new way to spy on visitors: analyzing their SSD activity
80d ago
12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal?
80d ago
Russian Art Teacher - Hinder Security Clearance?
80d ago
EDR/MDR Vendor Questions
80d ago
Cybersecurity as a Highschooler?
80d ago
New department created, would love your input
80d ago
OWASP Vienna - anyone going?
80d ago
Interview with Upstart
80d ago
18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber.
80d ago
Is cloud security engineer viable with my current position?
80d ago
Cloudflare Access users: what would actually make JIT useful for you?
80d ago
eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels
80d ago
Questions regarding Ubuntu 24 LTS hardening
80d ago
Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho.
80d ago
Honest question about OT Security Engineer work life in India
80d ago
Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning)
80d ago
AI Security
80d ago
Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor
80d ago
🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents
80d ago
Building Detection Engineering on AWS from scratch — roast my plan
80d ago
Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance
80d ago
I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA.
80d ago
Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning
80d ago
Final Year Project: Looking for non-generic IAM project ideas that solve real problems
80d ago
GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled.
80d ago
Breaking out of IT Helpdesk - how?
80d ago
A year in Cybersecurity — Where Do I Go From Here?
80d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
80d ago
22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber
80d ago
FBI: Silent Ransom Group Turns to IT Support Ploy
80d ago
How do machine builders track Siemens/Rockwell security advisories?
80d ago
GlassWorm Developer Supply-Chain Botnet Takedown
80d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
80d ago
Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV
80d ago
Got cybersec work what next ?
80d ago
Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables
80d ago
Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers
80d ago
Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing?
80d ago
GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)
80d ago
nightmare eclipse is probably French here is why
80d ago
Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines
80d ago
Measuring performance of JA4/JA4H AI Model
80d ago
What things are you really focused on this year?
80d ago
Hypothetical EDR spoofer
80d ago
ISO 27001 Audit Stage 1
80d ago
Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.
80d ago
Looking for Hacker Friends to Learn☺️
80d ago
Comptes Instagram et Facebook piratés et désactivés
80d ago
How to safely disinfect a USB stick from potential malware files?
80d ago
Is anyone else concerned about how quickly AI is outpacing cloud security?
81d ago
What's a CyberSecurity job like?
81d ago
Microsoft Live credential stuffing
81d ago
I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this?
81d ago
Security architects- summarize your responsibilities and role
81d ago
Finding Work in OSINT
81d ago
State of SDLC Security 2026
81d ago
Reported to police for coding html
81d ago
[Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling)
81d ago
I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project
81d ago
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover
81d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
81d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
81d ago
Breaking GROK'S DEFENSES to make it HACK Real Public Websites
81d ago
GitHub Actions Cache Poisoning is eating open source
81d ago
Nightmare-Eclipse has also been banned on GitLab :DD
81d ago
Do we still have time before we are in the Age of the movie "Minority Report"? ↓
81d ago
SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file
81d ago
What Software Supply Chain, Water Filters, and Power Grids Have in Common
81d ago
QA engineer trying to move into AppSec — does this plan hold up?
81d ago
Is work from anywhere really impossible to find??
81d ago
Cybersecurity statistics of the week (May 18th - May 24th)
81d ago
Engineering a Post Quantum Fortress Inside the Citadel Archite
81d ago
Cyber Security Analyst
81d ago
Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance
81d ago
Two layer email security tool thesis
81d ago
When OTP rate limiting fails: OLX account takeover with persistent sessions
81d ago
Entra ID sessions revoke
81d ago
Anyone who attended GPCSSI before? Need some clarification
81d ago
Lost on my career path.
81d ago
EU-based folks: external pentest vs mandatory data/security training?
81d ago
help needed from experienced people
81d ago
How do you evaluate whether a privacy service is actually privacy-respecting?
81d ago
Which one Intellipaat or coursera which one to choose
81d ago
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
81d ago
India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic?
81d ago
Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs.
81d ago
Did anyone pass the SC-200 certificate recently?
81d ago
Honeypot
81d ago
passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account
81d ago
Career in IAM as a fresher
81d ago
CISA orders feds to patch actively exploited Drupal vulnerability
81d ago
Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure
81d ago
GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
81d ago
Cyber security tool
81d ago
Saw this tool and it has potential
81d ago
🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs
81d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files
81d ago
Follow up : showing Claude install random pacakage in its vm instance without asking or prompting
81d ago
¿Is safe?
82d ago
Need help
82d ago
What is the best tool for masking in kali
82d ago
What are the best tools other than ghostTracker?
82d ago
TrapDoor Cross-Ecosystem Crypto Stealer Campaign
82d ago
Follow up : Steal Your Files Claude AI installing package because internet say so
82d ago
New to Cybersecurity: Looking for general advice & help with Nmap
82d ago
Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal
82d ago
Looking for tech role references
82d ago
How do you balance Paw?
82d ago
I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity.
82d ago
From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security
82d ago
Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February
82d ago
What Companies are Legit?
82d ago
start learning cybersecurity from scratch
82d ago
Follow-up: measuring LLM-agent failures with replay evidence
82d ago
Follow-up: measuring LLM-agent failures with replay evidence
82d ago
WhatsApp users on alert after hacker drops massive dataset
82d ago
17 years old going into CS — what certs should I start going after now?
82d ago
i want to hire an osint expert
82d ago
Open University pros/cons
82d ago
How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection?
82d ago
Career in IAM as a fresher
82d ago
Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo
82d ago
Need Advice
82d ago
Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all?
82d ago
Someone from Germany on iOS keeps trying to login to my MSFT account
82d ago
AI cautionary tale...
82d ago
AI powered red vs blue teaming
82d ago
Starting a security analyst student apprenticeship next week, need advice
82d ago
Why CVE Does Not Work for AI Agents, but AVE?
82d ago
SC-200 or Security+ — which actually helps land a security title
82d ago
How about AI having access to your hard drive.
82d ago
How a Date Tag Hijacks macOS via ExifTool
82d ago
Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools
82d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
82d ago
Built a tiny daily cyber puzzle game during evenings/weekends
82d ago
Crypto4A launches quantum-safe rival to AWS Secrets Manager
82d ago
ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why.
82d ago
Cyber Sec project
82d ago
CySA+
82d ago
Anyone tried Morgancyberhelp ?
82d ago
As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free
82d ago
Why are most of the dfir tools built to be used in windows
82d ago
OnlyFans mega leak reveals 340M user records, hackers claim
82d ago
Perplexity BumbleBee
82d ago
Cisco patches critical 10.0 flaw in Secure Workload APIs
82d ago
Stalker has my phonenumber
82d ago
Need some guidance
82d ago
Are you currently allocating budget to services that remove executive PII from B2B data brokers?
82d ago
About CEHv13 book
82d ago
We open-sourced the most dangerous part of our security startup on purpose.
82d ago
Which conference(s) result in the most people finding jobs?
82d ago
My discord account has been hacked second time even after enabling two factor authentication and resetting password
82d ago
What's the most efficient way to learn cloud governance and compliance
82d ago
Does anyone know C2 framwork and free hosting to host C2?
82d ago
CIS-CAT Assessor for assessment Windows server 2022 and 2025
83d ago
Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this
83d ago
Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks?
83d ago
Recent adoption of AI taught me what is Cybersecurity.
83d ago
The Pentagon Changed the Rules for Cybersecurity Compliance
83d ago
Can someone explain to a noob like me what the implications of this exploit are?
83d ago
SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections
83d ago
Window between zero-day CVE and a patch!
83d ago
Is it risky when a website puts on technology components with versions they used in their website?
83d ago
Anyone else losing their mind over this "AI Cybersecurity" hype?
83d ago
URL parsing behavior in a canonical tag lab
83d ago
Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you?
83d ago
Any tips for me pls
83d ago
How do you minimize legal liability as a solo contractor?
83d ago
How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing?
83d ago
Mentorship Monday - Post All Career, Education and Job questions here!
83d ago
Provenance: A survival toolkit for an AI dominant information landscape
83d ago
[ Removed by Reddit ]
83d ago
Active Drupal SQLi exploitation is a real „patch now“ moment
83d ago
machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native)
83d ago
Need suggestions and input; not a promotion
83d ago
Need advice!
83d ago
New Zealand is becoming a focal point for AI-driven superhacking threats.
83d ago
nmap on Linux: Guide to Network Scanning and Discovery
83d ago
TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle
83d ago
How would Phishing look like in the future? (targeting agents, not humans)
83d ago
Best beginner/intermediate book for system security (blue team / defense / audits)?
83d ago
Why is on-prem and air-gapped asset inventory still such a mess?
83d ago
keep getting MS authentication sign in attempts?
83d ago
Silly issue
83d ago
How to practice cybersecurity while studying prograaming ?
83d ago
[AI Security] Exploring Behavioral AI for Runtime Threat Detection
83d ago
Podman and krun: is it pointless to harden quadlets?
83d ago
How to handle security researchers (and firms) without a bounty program?
83d ago
Product analytics is becoming a third-party breach surface
83d ago
How can i learn and get into red teaming?
83d ago
Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network
83d ago
I got hacked
83d ago
Soc analysts in big companies, how it looks like?
83d ago
CTO at NCSC Summary: week ending May 24th
84d ago
These special phone and app features can help protect you from spyware
84d ago
Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button?
84d ago
Capcha Code Malware
84d ago
getting lost when hunting
84d ago
How to find information behind an account?
84d ago
Theoretical Design Concept for Post-Exploitation Browser Defense
84d ago
Google Certifications...
84d ago
How to continue when finding a possible Vulnerability but local law prohibits me from investigating further
84d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
84d ago
Is the CISSP still a reputable cert for getting jobs?
84d ago
Which of these gоv roles would fare better in the private sector?
84d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
84d ago
Mapping binaries to EDR feature spaces
84d ago
Lost my number + WhatsApp account — worried about old chats, photos, and videos
84d ago
what is the most painful or time-consuming part of your work right now?"
84d ago
Anthropic says Mythos has already found more than 10,000 vulnerabilities
84d ago
What is the experience needed for “entry level” cybersecurity jobs?
84d ago
Browser extension testing.
84d ago
Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip?
84d ago
Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback
84d ago
Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition
84d ago
Can someone recommend me some good, large universities to study cybersecurity?
84d ago
New guy khikhi
84d ago
Examples of intentional backdoors being breached?
84d ago
Non-Compliant Vocab
84d ago
Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites
84d ago
infostealers just spawned a 5,000+ repo github supply chain attack
84d ago
The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis
84d ago
GRO frag
84d ago
We audited 12K n8n templates: most have critical vulnerabilities
84d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
84d ago
Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week
84d ago
Mitigated Vulnerabilities by Vendor as Feed
84d ago
Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors
84d ago
A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories
85d ago
Where can I find the tools freely on internet to practice for soc analyst
85d ago
residential proxies
85d ago
Recommendations for getting started in cybersecurity
85d ago
Linux mint or Ubuntu for complete beginner
85d ago
Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world.
85d ago
Pentesting company recommendation
85d ago
Have you ever failed a certification exam?
85d ago
AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance
85d ago
What do i need to learn to get into application security? Which Degrees/Certs
85d ago
RSAC online membership? Is it worth it?
85d ago
Can someone give me a detailed roadmap for becoming a SOC Analyst?
85d ago
Puedo conseguir trabajo?
85d ago
How do i learn networking for cyber security?
85d ago
What's going to be Hacking and Cybersecurity's future is gonna be like?
85d ago
Cyber security placement - Interview Help
85d ago
Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge
85d ago
Feedback needed
85d ago
Handoff Transition
85d ago
Just added an interactive security map showing exactly what the server sees (and doesn't)
85d ago
Trend Micro warns of Apex One zero-day exploited in the wild
85d ago
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
85d ago
https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/
85d ago
Harvard and 140 other legitimate websites compromised
85d ago
Votre Satisfaction Dans Votre Travail
85d ago
5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit.
85d ago
US states urge Congress to renew cybersecurity grants
85d ago
The CISO's Guide to IDE Security in 2026
85d ago
Help with evilginx
85d ago
Watching AI Brain Drain on Attackers in Real Time
85d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
85d ago
api-rta cyberwarfare labs
85d ago
Does Security Implement Fixes?
85d ago
Ultimate Cybersecurity without needing AV ect?
85d ago
User Onboarding with IAM
85d ago
pnpm 11 Might Finally Be a Better Default Than npm
85d ago
14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs
85d ago
Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria
85d ago
Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip"
85d ago
Looking for a cybersecurity professional to interview for a university project (interview in French)
85d ago
Safe read-only check script for Copy Fail / CVE-2026-31431
85d ago
New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible?
86d ago
[TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly
86d ago
Cisco used AI to write security incident reports, with mixed results
86d ago
[TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM)
86d ago
Cyber Insurance Actuary Looking for Educational Resources
86d ago
As a bank , how do i give protected access to claude to my team?
86d ago
Can seasonal Apple Store employees apply for internal IT/cybersecurity roles?
86d ago
Reliable IP reputation check tools besides IPQS?(for work)
86d ago
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026)
86d ago
Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins
86d ago
Hacked by Rat Tools for 2.5 years.
86d ago
Google API Keys Remain Active After Deletion
86d ago
how do cyber sec consultants and pentesters actually get new clients?
86d ago
Post Incident Paranoia?
86d ago
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
86d ago
Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity?
86d ago
Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready
86d ago
You can counter MEMZ with Krotten in XP
86d ago
What are the most effective ways to do Blackbox testing?
86d ago
Npm registry sets stage for more secure package publishing
86d ago
Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support
86d ago
Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK
86d ago
Is the Cybercorps SFS still worth it?
86d ago
Microsoft warns hackers are exploiting password resets to gain access to user accounts
86d ago
Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame
86d ago
WORM USB drives
86d ago
An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model?
86d ago
CISOs - Holding the Line
86d ago
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
86d ago
Security Scroll Down?
86d ago
mass github repo backdooring via CI workflows(Megalodon)
86d ago
Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit?
86d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
86d ago
DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind
86d ago
FaceTec (ID verification) company appears to store user biometrics
86d ago
CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication
86d ago
It seems that FaceTec (ID Verification company) allows for storage of user biometrics
86d ago
Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check.
86d ago
Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data
86d ago
What Questions Do You Ask During SSP Control Interviews?
86d ago
Feed The Cat BackDoor
86d ago
Flipper One - Asking for help from the community
86d ago
Flipper One — tech specs
86d ago
Architecture Zero Trust détaillée
86d ago
Cybersecurity in Healthcare
86d ago
Staged publishing for npm packages | npm Docs
86d ago
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though)
86d ago
Neither MFA, Passkey, nor trusted IP help here
86d ago
cyber security remote
86d ago
CSIRT incident response
86d ago
Trying to find a graduate role
86d ago
Microsoft warns of new Defender zero-days exploited in attacks
86d ago
what is the best security app option for pixel8a?
87d ago
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
87d ago
IoT Security
87d ago
GitHub links repo breach to TanStack npm supply-chain attack
87d ago
Another working Linux LPE exploit is out. How are teams treating local-only bugs now?
87d ago
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
87d ago
Google publishes exploit code threatening millions of Chromium users
87d ago
landing a remote Vulnerability Management role
87d ago
Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case.
87d ago
I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting?
87d ago
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
87d ago
What volume of TPRM do you handle per month?
87d ago
safest virtual machine?
87d ago
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration
87d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
87d ago
GitHub notifications
87d ago
Is there no more privacy left in the world?
87d ago
Microsoft Edge had a password blunder, and it raises a bigger browser trust problem
87d ago
Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network
87d ago
Aconselhamento / mini texto
87d ago
CISA with an absolutely embarrassing data leak.
87d ago
Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys
87d ago
Anyone else feeling like static AppSec workflows are starting to hit limits?
87d ago
GitHub breach highlights developer tools as part of attack surface
87d ago
Why do some malware use unique user-agent strings?
87d ago
Encrypted emails bypassing email security tool
87d ago
Ctf groups
87d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
87d ago
Opensource that automatically scans your git repos for breaches
87d ago
CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed.
87d ago
Your developers are deploying agents in your production environment right now. You have no governance for it.
87d ago
¿Como me preparo para EC-Council CSA?
87d ago
The IBM X-Force Index 2026 explains all three in one finding.
87d ago
Securing iPad's question
87d ago
Cybersecurity 101
87d ago
What would this job role be?
87d ago
MSPs & MSSPs suck
87d ago
[ Removed by Reddit ]
87d ago
Crossroads
87d ago
Advice regarding "SOC" job that automates everything
87d ago
Is this Medium article about "NetMirror" malware legit?
87d ago
AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon?
87d ago
Developer tooling is part of the attack surface before a project is even run
87d ago
How the hell do you manage developers, their code, their apps?
87d ago
Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed
87d ago
Do people still rely on antivirus software in 2026, or is built-in security enough now?
87d ago
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
87d ago
Automatic CLI for spinning up vulnerable labs + objectives
88d ago
ISO/IEC 27701 scenario question
88d ago
Discord rolls out end-to-end encryption on voice, video calls
88d ago
GitHub investigates internal repositories breach claimed by TeamPCP
88d ago
Two AI-based science assistants succeed with drug-retargeting tasks
88d ago
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
88d ago
An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now.
88d ago
New to cybersecurity
88d ago
Anyone interview or work with Moxfive?
88d ago
A stealth Firefox version that passes all anti-bot and CAPTCHA
88d ago
mkPIVM - a polymorphic position-independent shellcode virtualizer
88d ago
Started in IT and need a Cybersecurity Roadmap with my Useless Degree!
88d ago
GitHub announces internal data breached.
88d ago
Roadmap to Cybersecurity roles
88d ago
Malware installed without literally doing anything?
88d ago
CTFs
88d ago
Crossroads
88d ago
Canara Bank SuRaksha Cyber Hackathon 2.0,
88d ago
Anti BOT Tipps und Tricks gesucht.
88d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
88d ago
New to Cybersecurity
88d ago
Is the ISC2 Certified in Cybersecurity worth it?
88d ago
Average Days to Close by Source CNAPP Severity Tag 2026
88d ago
I want free nmap resource
88d ago
If I clear browser history regularly, does it reduce the chances of malware that target browser data?
88d ago
What is next after 1.5 Year as Security Analyst?
88d ago
Analysis advice
88d ago
Stop me if you heard this one before... (YellowKey related)
88d ago
Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe?
88d ago
Looking for advice: where should I post/publish CVE write-ups?
88d ago
Cybersecurity statistics of the week (May 11th - May 17th)
88d ago
How can I test my website locally for cybersecurity?
88d ago
Use of coding in security operations
88d ago
Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
88d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
88d ago
I've built an open source honeypot probe database accessible via curl, http and mcp
88d ago
6,000+ Automatic Tank Gauges Exposed With No Authentication
88d ago
Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email?
88d ago
If humans are the weakest link, why won't companies evolve?
88d ago
Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?"
88d ago
Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM
88d ago
Local transcription vs cloud transcription, which actually feels safer?
88d ago
Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today?
88d ago
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise
88d ago
Shai-Hulud source leak is turning npm malware into a copycat problem
88d ago
Framework for Preventing Secret Ideas from Leakage
88d ago
Local LLM for building AI Security platform
88d ago
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
88d ago
Emerging Cyber security niches
88d ago
ISO/IEC 27701
88d ago
Solo dev building a terminal-heavy hacking game inspired by corporate security
88d ago
Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations
88d ago
CS/IT Student Looking to Grow My LinkedIn Network 😃
88d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
88d ago
Is Amazon Cognito a good choice long term? Alternatives?
88d ago
Was hacking easier in the 80s and 90s and early 2000s?
88d ago
Need some Advice in SOAR heavy environment
88d ago
Trying to find serious builders in cybersecurity - not just “let’s build” conversations
88d ago
AI Phishing
88d ago
One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals
88d ago
How easy is it to get into the cyber security field?
89d ago
314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js
89d ago
Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start?
89d ago
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo
89d ago
CEH/CPENT vs OSCP vs GPEN
89d ago
ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro”
89d ago
CISA Contractor Admin Leaked AWS GovCloud Keys on Github
89d ago
Suspecious activity in my account
89d ago
Is it safe to use my first name and middle name on platforms?
89d ago
Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice.
89d ago
Just received an email from shinyhunters about their amtrack hack
89d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
89d ago
Bywaf: an auditable Python commandlet framework for chained pentest workflows
89d ago
For anyone currently working in a SOC:
89d ago
Fellow Tier 1 SOC/Security Analysts - What does your day to day look like?
89d ago
How do you threat hunt for RMM tools in environments where RMM is all over the place?
89d ago
Microsoft - "your single use code" email when it was not requested by yourself
89d ago
Directory of vendor security questionnaires
89d ago
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
89d ago
MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals
89d ago
Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight
89d ago
How is AI affecting the cybersecurity market?
89d ago
MCP security
89d ago
YellowKey Mitigation
89d ago
Anyone else on the receiving end of ShinyHunters extortion email?
89d ago
Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs
89d ago
What’s the biggest mistake people still make about online security in 2026?
89d ago
Anthropic shuts the EU out of its most advanced cyber AI model
89d ago
Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens]
89d ago
Best hotel for attending all three conferences in Vegas?
89d ago
What's your company's actual PQC migration plan? Not the one on paper - the real one.
89d ago
Does buying local cybersecurity (services/products/etc) matter to you?
89d ago
LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose
89d ago
Detection Engineering AI Maturity Framework
89d ago
Microsoft code
89d ago
Microsoft confirms Windows 11 security update install issues
89d ago
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
89d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
89d ago
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
89d ago
Suspicious with a company offer letter
89d ago
Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first?
89d ago
Why do some recovery workflows still require full wallet uploads?
89d ago
Need help with interview for soc l1
90d ago
Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap)
90d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
90d ago
carrer path in cybersecurity for a btech stud
90d ago
Agents usage in production
90d ago
‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K
90d ago
Are teams still finding AI API keys in public repos?
90d ago
Mentorship Monday - Post All Career, Education and Job questions here!
90d ago
Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here?
90d ago
Does the CBP bug phones?
90d ago
What We Learned Building Runtime Visibility for Modern Telco Networks
90d ago
Ive got my Spotify account hacked! How do I solve this?
90d ago
The Politics of AI Transparency
90d ago
A million baby monitors and security cameras were easily viewable by hackers
90d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
90d ago
Is cybersecurity becoming more behavioral than technical?
90d ago
Questions About Promo Items for a Cybersecurity Conference
90d ago
Dois-je m'inquiéter ?
90d ago
I am dying to work abroad , rate my journey so far
90d ago
Microsoft - "Your single use code" email when it was not requested
90d ago
Security / Compliance work going Agentic?
90d ago
Don't believe the media, specially in cybersec
90d ago
Microsoft account keeps getting Authenticator requests?
90d ago
[Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated.
90d ago
Struggling to generate security bulletins — any ideas?
90d ago
Certs to go into Security Engineer/architect
90d ago
18882745552 beware of email with this number
90d ago
Transition from traditional penetration testing into AI security
90d ago
Seeking advice on next career steps
90d ago
Will the analyst role become obsolete?
90d ago
Alert Fatigue
90d ago
Best path into cybersecurity for a high schooler?
90d ago
Keep getting hacked
90d ago
How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices
90d ago
I’m interested in joining the Red Team Hackers Academy in Bangalore.
90d ago
A clueless teenager 💔
90d ago
Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start?
90d ago
Am I overthinking Claude Code security or is this actually a risk?
90d ago
is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this
90d ago
ISO/IEC 27701 ( SoA ) Applicability
90d ago
Security Executive Playbook
90d ago
This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon
90d ago
I feel crazy I hope someone has insight .
91d ago
ΡHANTΟΜ Al-Powered Pentesting Command Center
91d ago
Interview Assessments
91d ago
We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it
91d ago
Questions about data blockers
91d ago
Post Implementation task
91d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
91d ago
Cyber security jobs in Austria
91d ago
Personal favorite deception layer.
91d ago
Estudiar Ciberseguridad
91d ago
Learning way
91d ago
How do you report large volume detections to a CISO without making the BPA report a SOC story?
91d ago
Can anyone share bugbase platform screenshot having professional usage on dashboard?
91d ago
CTO at NCSC Summary: week ending May 17th
91d ago
Security Executive Playbook
91d ago
Tired of tab-switching between CTI tools - here's what we put together
91d ago
I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor
91d ago
In Cybersecurity
91d ago
Anyone else feel like most MSP tooling is either overkill or painfully manual?
91d ago
Thinkpad vs Macbook pro endpoint security
91d ago
Any more affordable alternatives to “IntelligenceX”?
91d ago
Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran
91d ago
tanstack checker github action
91d ago
Drivers Alpha AWUS036AXML
91d ago
Splunk download for free
91d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
91d ago
Anyone here using pager duty?
91d ago
Scammer targeting posters
91d ago
Seeking advice
91d ago
Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026)
91d ago
Just got an email about a single use code, maybe someone was trying to log in?
91d ago
Can a background in DevOps enter the cybersecurity field?
91d ago
Using ai in learning
91d ago
Avanzamento area Blue Team/SOC
91d ago
Please what could be helpful
92d ago
CVE exploit chain
92d ago
What are the widely accepted SaaS security accreditations/audits an app should seek in fintech
92d ago
Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco
92d ago
Major flaw in Indian Cyber and IT assurance landscape
92d ago
Red Team Ops Ⅱ ( CRTL ) exam preparation
92d ago
Recomendations
92d ago
Recommended cybersecurity certification for a UX designer new to the domain?
92d ago
insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server
92d ago
Career path
92d ago
Merit America offers a program that gets you into cyber security roles.
92d ago
Brovan: Binary user-mode emulator for x86_64
92d ago
AmEx Interview!
92d ago
Developer credential-stealing pipeline also collected operator workstations
92d ago
need help building a case.
92d ago
Personal favorite SIEM platform?
92d ago
Cardputer ADV
92d ago
Alternative for Qualys
92d ago
The 4th Linux kernel flaw this month can lead to stolen SSH host keys
92d ago
Stack Buffer Overflow Explained (Using a Classic Doom Bug)
92d ago
Confused about cybersecurity career
92d ago
Transferring from pen test consulting to application security?
92d ago
Curso de especializacion de Ciberseguridad
92d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
92d ago
Lost, tempted to throw in the towel
92d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
92d ago
I open-sourced a Docker security scanner I use to audit all my websites
92d ago
Testing Deception Technique
92d ago
A malware got into my account and spread spam ad to my friends and relatives
92d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems
92d ago
Most pentest reports I review are padded with garbage findings
92d ago
Cyber Essentials and use of third party websites - MFA
92d ago
Rapid 7 and Cisa Kev
92d ago
Anyone know much about MS Defender?
92d ago
EN18031 for IoT: struggling to see the big picture — advice from experienced people?
92d ago
Automating Code Security Reviews
92d ago
New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available
92d ago
AI coding tools on developer machines — looking for input on how you're handling it
92d ago
Chrome 148 Update Patches Critical Vulnerabilities
92d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
92d ago
I need help. i am lost
92d ago
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence
92d ago
Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments
92d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
92d ago
I'm going crazy. At the application level what I can actually do to prevent DDos?
92d ago
Is anyone enrolled in Intellipaat's cybersecurity course?
92d ago
Will AI Replace Cybersecurity Jobs?
92d ago
What's best certification choice after OSWE
92d ago
Facebook Page Call Slipping through Sleep mode
92d ago
ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey
92d ago
New Linux LPE allows local users to read any file, including privkeys
93d ago
A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks.
93d ago
Your experience as IT Admin on Alerts
93d ago
Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time
93d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
93d ago
Discord VC lag Exploit
93d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
93d ago
Bug FB - Inicio de sesion por password
93d ago
Does anyone know how to configure EVILGINX for testing
93d ago
How long does it take to get familiar with a tool
93d ago
Scam website
93d ago
ANTS Hack: 19 million records exposed in French ID agency breach
93d ago
Is it really that easy to obtain SMS codes using an SS7 attack?
93d ago
AI coding tools are shipping code faster than security can review it. What's your team doing about it
93d ago
Interview for AI security engineer position at a fortune 500 company
93d ago
How’s the job market for Senior AppSec Engineers? How are the interviews?
93d ago
Has anyone read "The Art of Deception"? How does it hold up to now?
93d ago
Is metadata protection becoming more important than traditional endpoint security for ordinary users?
93d ago
Zero trust in hybrid environments - what's actually worked for you
93d ago
Have you encountered issues with CSAF advisories in practice?
93d ago
Zero trust in hybrid environments - what's actually working for you
93d ago
OpenAI confirms security breach in TanStack supply chain attack
93d ago
Bachelors Degree Options
93d ago
I need help protecting my privacy
93d ago
Free Threat Intellegence
93d ago
What discovery in cybersecurity amazed you the most?
93d ago
Scholarship for Service
93d ago
For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons?
93d ago
Another day, another supply chain
93d ago
How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs?
93d ago
Teaching Linux+ & CEH.....
93d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
93d ago
SIEM use case development
93d ago
JFrog vs Mend as Scanners
93d ago
KQLab - open-source query manager for SOC teams
93d ago
Which Vendors Publish the Best (or Worst) Security Advisories?
93d ago
Synthetic training data vs. real attack telemetry — does it actually matter?
93d ago
Operative IT-Sicherheit | SIEM & Splunk
93d ago
SOC not for junior level?
93d ago
Cybersecurity at MSG
93d ago
pii-tools.com reputable?
93d ago
Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise
93d ago
Contract jobs worth the risk?
93d ago
HackTheBoxAcademy vs LetsDefend vs CyberDefenders
93d ago
Automating code security reviews with Claude: near Mythos-level capabilities at lower cost
93d ago
Making Right Career Decision?
93d ago
I tried using apparmor (linux security) but it doesn't seem to work very well
93d ago
Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything!
93d ago
Struggling to Stay Up to Date With Vulnerabilities
93d ago
How to Transfer files Safely from a Compromised (work) Device
93d ago
Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward
93d ago
Multiple data breaches in one week
93d ago
How are small security teams handling vulnerability overload now?
93d ago
Concerns mount that EU will demand age verification for VPNs
93d ago
Automating code security reviews: Claude Mythos-level capabilities with lower cost
93d ago
The Rare Patch: A Digital Sovereignty Challenge
93d ago
Advise
93d ago
GRC
93d ago
Admins and Engineers
93d ago
Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark
93d ago
Prompt injection in browser coding agents is the threat model nobody is ready for
93d ago
New Fragnesia Linux flaw lets attackers gain root privileges
93d ago
Transition from MSP to Network Engineering?
94d ago
So called “off grid” method
94d ago
Convince me I’m not paranoid: a unique hacking situation.
94d ago
Hunting the Behavior Behind npm Supply Chain Attacks
94d ago
Question for AppSec Members
94d ago
Beginners guide to Google Dorks by Heisenberg
94d ago
Alguém sabe algo sobre raven eye technology
94d ago
Gophish Porject - Requirement
94d ago
Security Team Won’t Assess Risk
94d ago
Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework
94d ago
Microsoft’s new multi-model agentic security system tops leading industry benchmark
94d ago
Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
94d ago
Overwhelmed on how to enter the job market.
94d ago
Social media scam bill targets tech giants as New Yorkers lose billions
94d ago
What are the biggest technical & cultural hurdles you’re facing right now?
94d ago
CISSP / CCSP training - Experienced engineer
94d ago
Vulnerability in Canvas/Instructure Support Tickets had part in breach?
94d ago
is malwarefox legit?
94d ago
what lab to learn zero trust?
94d ago
Anyone else got a bunch of emails leaked by Samsung?
94d ago
This is what some the world's largest banks of malware look like stacked as hard drives
94d ago
I need feedback on my project please
94d ago
would like to understand the role of "Cyber Insurance UnderWriters"
94d ago
Free on-device tool for monitoring AI traffic on macOS — visibility before policy
94d ago
Is secure evidence handling and controlled derivative file sharing needed?
94d ago
Will Adding Some Certifications Help Me in the Job Market?
94d ago
Linux driver posted for Intel Silicon Security Engine Interface "ISSEI"
94d ago
Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified?
94d ago
Fragnesia made public as latest Linux local privilege escalation vulnerability
94d ago
HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity?
94d ago
NIST is surrendering to the amount of CVEs coming in
94d ago
Military Veteran looking to get into the Cyber Field
94d ago
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
94d ago
Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook.
94d ago
Cve apis for a database
94d ago
Empresas de Cyberseguridad en Mexico (Reacciones)
94d ago
Joined a new company: GRC landscape advice
94d ago
Removing admin rights
94d ago
a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access
94d ago
FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow
94d ago
Golden years for cyber security about to start?
94d ago
A stealth approach to Process Injection - EntryPoint Hijacking
94d ago
Detecting CopyFail and DirtyFrag by thinking outside the box
94d ago
Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security
94d ago
Career advice
94d ago
The exponential rise of economic damage caused by cyber-crime continues
94d ago
Today's cybersecurity systems are not ready for AI
94d ago
Are certifications worth it, or do practical skills matter more?
94d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
94d ago
Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed
94d ago
Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft
94d ago
What to do after security+
94d ago
AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data
94d ago
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
95d ago
Is it realistic to move from Tech Risk/GRC into technical cybersecurity?
95d ago
Are IPhone autofill passwords safe to use?
95d ago
Access approvals happen over Slack dm and I don't know how to present that to an auditor
95d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
95d ago
China is going dark to develop its own Mythos, German cyber chief fears
95d ago
Is prompt injection a real problem for you?
95d ago
New Exim BDAT bug shows why “just patch the mail server” is still not simple
95d ago
Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach
95d ago
Cybersecurity guide
95d ago
[Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ?
95d ago
How you guys rate Google Cyber security course and certificate out of 10 !?
95d ago
Cyebrsecurity Startup Advice
95d ago
Can anyone give a real world based AI based attack?
95d ago
How worried should we be about AI powered cyberattacks?
95d ago
Built STIS-ICS — an open ICS/OT security learning project
95d ago
OS scanner that checks repos for traces of the Shai Hulud worm
95d ago
Foxconn Ransomware Attack Shows Nothing Is Safe Forever
95d ago
Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries
95d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
95d ago
Explorer shows random letter/number filenames before copying my actual files — normal behavior?
95d ago
Zscaler AI Security Capabilities ?
95d ago
Cybersecurity degree
95d ago
Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma
95d ago
Cyber security
95d ago
New York Senate takes on junk fees, digital subscriptions, surveillance pricing
95d ago
Cybersecurity statistics of the week (May 4th - May 10th)
95d ago
Feels like AI changed the speed of attacks more than most companies want to admit
95d ago
Anyone used Kasm or ReplicaCyber?
95d ago
Škoda warns of customer data breach after online shop hack
95d ago
Google launches new Android security feature to help uncover spyware attacks
95d ago
Fancy Bear: Stealing Credentials Invisibly
95d ago
Nightmare Eclipse has published Greenplasma and YellowKey
95d ago
Copilot Agent
95d ago
What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles?
95d ago
Career Advice
95d ago
Anyone else exhausted by the nonstop AI hype?
95d ago
Reviewing the trends in ransomware attacks in 2026
95d ago
Is It a Good Idea to Change Jobs Shortly After Getting Hired?
95d ago
SSO makes life easier but MFA keeps it safe, do we actually need both?
95d ago
Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours?
95d ago
How are SOC teams actually deciding what not to investigate anymore?
95d ago
Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily
95d ago
Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released.
95d ago
Has anyone tryed this out yet?
95d ago
The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..)
95d ago
Switching to Cyber
95d ago
Nitrogen ransomware group claims Foxconn after Wisconsin plant outage
95d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
95d ago
Using Cape Sandbox for Phishing Analysis
95d ago
Canvas hack: company pays criminals to delete students' stolen data
95d ago
i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning.
95d ago
AI integrations are quietly creating a new OAuth supply-chain problem
95d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
95d ago
UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships
95d ago
Hardcoded secrets in Git
95d ago
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
95d ago
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
95d ago
New ipTIME Pre-Auth RCE in CWMP
95d ago
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
96d ago
Is my phone hacked?
96d ago
Switched to a grc role after a year in SOC L1
96d ago
Forecasting Lazarus Crypto Heists
96d ago
Infrastructure Security Incident Update & FAQs
96d ago
Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages
96d ago
In Depth Guide To VM Based Obfuscation - What it is and how to handle it.
96d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
96d ago
Transitioned to GRC
96d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
96d ago
German cybersecurity official warns China is close to developing AI superhacker
96d ago
Google Detects First AI-Generated Zero-Day Exploit
96d ago
“DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance
96d ago
Instructure/ canvas paid the ransom?
96d ago
Troca emprego - big para consultoria ou fintech - Pentester/Red Team
96d ago
Finally, texts between Android and iPhone users can be end-to-end encrypted
96d ago
Official CheckMarx Jenkins package compromised with infostealer
96d ago
IMF warns of the potential for AI attacks on global financial systems
96d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
96d ago
Cookie thieves caught stealing dev secrets via fake Claude Code installers
96d ago
Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo
96d ago
MS Defender on OT Network
96d ago
A fateful question
96d ago
SC-900 or SC-400
96d ago
What are your security non-negotiables?
96d ago
Losing my path
96d ago
Axon-captcha
96d ago
What makes companies trust small cybersecurity vendors?
96d ago
Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility”
96d ago
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
96d ago
Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim
96d ago
These Extensions are Scraping Your AI Chats, are you affected?
96d ago
Be careful with your Git: Investigating malware spreading through Git repositories
96d ago
Training and Phishing
96d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
96d ago
AI-powered hacking has exploded into industrial-scale threat, Google says
96d ago
Apple closed my bug report 4 times. MITRE wouldn't let it die.
96d ago
NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG
96d ago
Google spotted an AI-developed zero-day before attackers could use it
96d ago
beginner doubt
96d ago
I got my CEH Certification. SO what now?
96d ago
Construction to Cyber PM
96d ago
[ Removed by Reddit ]
96d ago
Something got downloaded on my phone and then dissappeared
96d ago
Bleeding Llama
96d ago
Do accountants even care about cybersecurityas much?
96d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
96d ago
Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust
97d ago
Was the reconnaissance in Bugbounty overrated?
97d ago
Cybersecurity beginner building an experimental log analyzer — looking for advice
97d ago
Anyone else worried about AI being a security nightmare?
97d ago
Snyk not working
97d ago
Malicious tenants paid us to abuse our RMM. We blocked them
97d ago
Help reasuring parents with an email parsing tool (i will not promote)
97d ago
DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this?
97d ago
cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers
97d ago
5 years as a Level 1 Security Analyst and wanting to transition into consulting
97d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
97d ago
New into network pentesting.
97d ago
Is it worth it to switching field to cybersecurity ?
97d ago
Neeed help to get cybersecurity internship.
97d ago
Mentorship Monday - Post All Career, Education and Job questions here!
97d ago
Cybersecurity and ADHD
97d ago
Anyone dealt with a VulDB submission rejection? Resubmit or reply?
97d ago
ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing
97d ago
I have a malware and need help removing it. someone please help me 🙏
97d ago
I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too?
97d ago
EasySec - Update
97d ago
What is the cybersecurity equivalent of leaving your spare key under the doormat?
97d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
97d ago
VICE: Cyberwar | Full Season 2 | Blueprint
97d ago
Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures
97d ago
Email OTP as default (often ONLY) password isn’t the solution
97d ago
Soc analyse
97d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
97d ago
Price rising
97d ago
AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report
97d ago
Possible security incident against Arup Group
97d ago
Can honeypots be used this way?
97d ago
I think AI just quietly killed the 90-day disclosure window.
97d ago
TCM and Educate 360 are bugged
97d ago
Got an alert from google what should I do?
97d ago
UK jobs
97d ago
Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏
97d ago
Worst company
98d ago
Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning
98d ago
Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months)
98d ago
ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring)
98d ago
App Store Question - Darato Sport / Dofu Sport / Kofu
98d ago
Help! - My Parents Computer is Hacked
98d ago
Ran lumma stealer from a recaptcha scam
98d ago
Port 5986 question
98d ago
CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse!
98d ago
cyber security/ segurança da informação
98d ago
College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains
98d ago
Help with an Escalating Cyber-Stalker
98d ago
RRW - Rick Roll WiFi
98d ago
Best resources to start learning python for cybersecurity and automation
98d ago
Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game.
98d ago
JDownloader site hacked to replace installers with Python RAT malware
98d ago
How can I fix my browser remembering what he had open last
98d ago
MS 360 CoPilot issues
98d ago
I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details
98d ago
ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12.
98d ago
eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback
98d ago
I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you
98d ago
OWASP TOP 10 LLM 2026 Community voting
98d ago
Second security incident at Instructure (Canvas)
98d ago
UK Advice Needed - VA+ Training?
98d ago
Gateweb - Secure Web Gateway
98d ago
Those who are in Detection engineering
98d ago
Can someone tell me of a trustable hacker?
98d ago
MSPs, how are you handling AI usage across your customer environments today?
98d ago
Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write
98d ago
How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there?
98d ago
ecpptv3 Exam in 3–4 Days —
98d ago
AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES
98d ago
Did CISA helped you land a job ?
98d ago
CTO at NCSC Summary: week ending May 10th
98d ago
pre pre junior needs help(guidance pls)
99d ago
Trojan malware
99d ago
SANs Courses: How do people get their employers to pay?
99d ago
NIS2 Article 21: turning compliance controls into technical security evidence
99d ago
This GBA Rom is making is having a weird behavior in the Sandbox, why?
99d ago
Why AI agent governance feels harder than traditional security models
99d ago
Confused about what certs are important
99d ago
Would getting Security+ be worthless for me?
99d ago
Submit probe test — shadow DOM click
99d ago
Threat intelligence in OT (Power equipments)
99d ago
SOC Analyst
99d ago
PAWs, PAM and PIM..what is best practice?
99d ago
This is the most in-depth analysis I have found on the Instructure/Canvas breach so far.
99d ago
Poland says hackers breached water treatment plants, and the U.S. is facing the same threat
99d ago
Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web.
99d ago
Quacc++: Automated Open Source Vulnerability Discovery
99d ago
60% of MD5 password hashes are crackable in under an hour
99d ago
Built a correlation engine that chains AD findings into attack paths automatically.
99d ago
Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests
99d ago
JDownloader's official website delivered Python RAT
99d ago
Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
99d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
99d ago
Note taking apps and advice
99d ago
IMF Warns AI Could Trigger Global Financial Cyber Crisis
99d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
99d ago
Is the ISC2 Cybersecurity program still worth it?
99d ago
Canvas getting hit during finals week shows how fragile “critical SaaS” has become
99d ago
Are websites exposed to the internet under attack almost every hour, even if they're small?
99d ago
Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken
99d ago
What the **** is happening in cybersecurity space ?
99d ago
Canvas is back up, but now what?
100d ago
Instagram is getting rid of end to end encryption, what now?
100d ago
New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation
100d ago
Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable".
100d ago
Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group?
100d ago
Cushman and Wakefield confirms cyberattack
100d ago
Egnyte potential ransomware attack
100d ago
So canvas is down, what'll happen if they can't come to an argreement?
100d ago
Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now.
100d ago
/Why/ is Shinyhunters targeting Canvas?
100d ago
Canvas Hack - Any Guesses How?
100d ago
Should I build a virtual or physical lab?
100d ago
Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12
100d ago
Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata
100d ago
Audit/Cybersecurity
100d ago
Issues removing Trellix (and specifically solidifier)
100d ago
Pentagon eyes 3-year cyber training requirement, overriding new Army policy
100d ago
How much personal info will be leaked by the recent Canvas hack??
100d ago
Dirty Frag and canvas
100d ago
Hackers deface school login pages after claiming another Instructure hack
100d ago
Did I destroy my career by being loyal to an arguably good company?
100d ago
V4bel/dirtyfrag - Universal Linux Local Privilege Escalation
100d ago
What is CYBERRANT?
100d ago
Canvas is down as ShinyHunters hack forces outage
100d ago
New Dirty Frag Linux Bug Emerges in Wake of Copy Fail
100d ago
Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today.
100d ago
How is GRC work in a MSSP?
100d ago
SH and BF phishing console
100d ago
Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth?
100d ago
Socure authenticating AI identity as real.
100d ago
Automated SSL Certificate Renewals - What is your setup?
100d ago
Shinyhunters and Canvas
100d ago
What Cli execution do you use for a script file?
100d ago
Fiserv security incident - data breach notice
100d ago
Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments
100d ago
I graduate next year with a Cybersecurity degree.
100d ago
Asking about Cortex
100d ago
Apache Caldera
100d ago
What’s the “unsexy” problem in cyber that’s actually a total disaster?
100d ago
Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE
100d ago
As a developer, should I use AI to improve security?
100d ago
My company has an MSP that manages our employee endpoints but we cant access the software they use to manage
100d ago
Americans sentenced for running 'laptop farms' for North Korea
100d ago
Is my laptop hijacked ?
100d ago
claude ai gave security beta to Enterprise plans only what can we do as pentesters?
100d ago
Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline
100d ago
Advice for path to land job SOC in France
100d ago
Possible Major Vulnerability: Chromium used by current version of PRTG
100d ago
Mythos AI may be a cybersecurity threat, but it follows the rules of the game
100d ago
Control Checks using AI.
100d ago
How do native password managers clear the clipboard?
100d ago
Graduating CS Student but Wanna Start my Career in Cybersecurity
100d ago
Claude-Themed Malware Campaigns
100d ago
DeepFake it till you make it.
100d ago
The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments
100d ago
What niche in cybersecurity should I go for, with my background in Angular & .NET ?
100d ago
Successor for Kaspersky Endpoint Security
100d ago
Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago
100d ago
SOC Analyst tier 1 (Entry Level) ??
101d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
101d ago
Made cybersecurity merch as an infosec practitioner — honest feedback welcome
101d ago
As AI agents become users of company data - what is needed to keep data secure?
101d ago
Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities.
101d ago
AI inference is quietly becoming a security problem
101d ago
is winrar 7.13 vulnerable to extraction exploits?
101d ago
Tried explaining internet encryption in a beginner-friendly but accurate way, feedback?
101d ago
Is the EC-Council CTIA Certification Worth It for Career Growth?
101d ago
POC Android vuln 2026
101d ago
Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise
101d ago
Opinions on Mimecast
101d ago
What's going on in the field of Cybersecurity 🫣.
101d ago
How do teams preserve institutional pentest knowledge when senior testers leave?
101d ago
CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE
101d ago
Sophos NDR on Proxmox
101d ago
On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029.
101d ago
DOJ says ransomware gang tapped into Russian government databases
101d ago
DAEMON Tools devs confirm breach, release malware-free version
101d ago
Have there been instances where your SOC has suffered a cybersecurity attack?
101d ago
OpenCTI founder, Samuel Hassine, arrested and charged with CSAM
101d ago
Deepfake Platform
101d ago
Trellix Licence Query
101d ago
Instructure hacker claims data theft from 8,800 schools, universities
101d ago
Is AI generated code creating a non-linear security problem for AppSec teams?
101d ago
D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says
101d ago
Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security
101d ago
Norton Antivirus and Other Norton Software
101d ago
Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home?
101d ago
We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes.
101d ago
Download a malware a while ago, someone trying to log into my ios account
101d ago
Org Restructure
101d ago
Does SOC 2 actually reduce questionnaires, or just change them?
101d ago
Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views
101d ago
How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically?
101d ago
Ran phishing awareness training for 200+ non-tech employees
101d ago
Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk
101d ago
Vulnerability Garden
101d ago
Palo Alto Firewall Zero-Day Under Active Exploitation
101d ago
Cyber Security Militias
101d ago
Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk
101d ago
CyberSecurity Nightmares
101d ago
Can I use NanoKVM if it's just to turn on pc?
101d ago
got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something?
101d ago
How to learn tools for cybersecurity?
101d ago
'CopyFail' attackers start cashing in on Linux flaw
101d ago
Anybodybodybdown for a team/studygroup?
101d ago
I was hacked due to sim card spoofing
101d ago
Chrome is quietly installing a 4GB AI model on your device
101d ago
Dev vs Security role
101d ago
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft
102d ago
Oracle Debuts Monthly Critical Security Patch Updates
102d ago
Sec engineer / developer?
102d ago
When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them?
102d ago
Are we actually seeing more vulnerabilities or just more noise?
102d ago
Cybersecurity jobs in red team
102d ago
Question
102d ago
What’s the biggest mistake people make even after installing antivirus?
102d ago
New dashboard tracks ransomware groups by their reliance on Infostealer credentials
102d ago
What would you say if your security lead said this...
102d ago
What would be the goto setup in AWS for security purposes?
102d ago
CREST CRT Exam 2025/2026 Experiences
102d ago
Microsoft Edge stores your passwords in plaintext RAM... on purpose
102d ago
Como começar?
102d ago
Possible Password Leak? Curious if Anyone Has Seen This Before
102d ago
Not a Hack. A Handout. Inside the GTFOice.org Data Exposure
102d ago
Besoin de conseils sur une DMZ automatisée
102d ago
Microsoft, Google and xAI will let the government test their AI models before launch
102d ago
Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073
102d ago
SMB Header Signature for Tagging in Firewall
102d ago
Question regarding VDP
102d ago
Working on what i should do for the next 3 years
102d ago
Question for Security Professionals
102d ago
Do tech companies lifecycle-manage public DNS records to prevent dangling DNS?
102d ago
Vulnerability Summary for the Week of April 27, 2026
102d ago
Cisco releases open-source ‘DNA test for AI models’
102d ago
Cybersecurity is becoming too AI dependent is that a problem
102d ago
Foxconn Wisconsin outage raises cyber questions
102d ago
How stressful is GRC?
102d ago
Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia
102d ago
Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India
102d ago
Archer for a non-regulated medium sized company?
102d ago
Cybersecurity statistics of the week (April 27th - May 3rd)
102d ago
Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM.
102d ago
Where to find reliable vendors?
102d ago
Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts?
102d ago
We wrote a guide on securing Claude across the enterprise — here's the core framework (with download)
102d ago
Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium.
102d ago
Hardware reverse enginnering first project. Love some advice
102d ago
Microsoft Edge Stores Passwords in Process Memory, Posing Risk
102d ago
Currently working on cybersecurity, looking for advice
102d ago
Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning
102d ago
CISO course valuation
102d ago
GRC Path to CISO (Certifications)
102d ago
CISOs and pentest buyers, what's the worst thing you've seen in a pentest report?
102d ago
How to enforce M365 Sign-in frequency on corporate laptops?
102d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
102d ago
Built an independent directory of AI Act / AI governance tools, feedback?
102d ago
ScarCruft APT group compromises gaming platform in a supply-chain attack
102d ago
Just curious
102d ago
'Copy Fail' is a real Linux security crisis wrapped in AI slop
102d ago
Analysis malicious DLL
102d ago
Cyber security free course
102d ago
Does certification expires?
102d ago
We get paid to break into buildings for a living. Ask us anything!
102d ago
Pay2Key ransomware — any recovery path that’s actually worked?
102d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
102d ago
Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF
102d ago
How have you kept growing your knowledge in security when the job stops pushing you?
102d ago
The UK’s Age Verification Law Is Producing Compliance Theater
102d ago
Microsoft Edge: Passwords end up in memory as plaintext
102d ago
Do people still get viruses in 2026, or is that mostly a myth now?
102d ago
Mitigation script for Copy Fail vulnerability CVE-2026-31431
102d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
102d ago
Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released
102d ago
DigiCert breached via malicious screensaver file
102d ago
Caido Payloads and Scanner of Endpoints
102d ago
CISO Security Mind Map 2026
103d ago
Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker
103d ago
Amazon SES increasingly abused in phishing to evade detection
103d ago
AI Security Trainings
103d ago
Ai help
103d ago
ByDesign: observed behavior where file URLs remain accessible after unshare/delete
103d ago
Can Kali Linux still compete in cyber security or is it outdated?
103d ago
Who are your favorite cybersecurity YouTubers?
103d ago
CISOs, how are you balancing AI adoption with security risks these days?
103d ago
San Diego Community College District fighting major cyberattack
103d ago
After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up
103d ago
Free resource: searchable archive of every BSides conference talk
103d ago
Lightning PyPI Compromise: Bun-Based Stealer
103d ago
Too much mother instinct?
103d ago
L1 SOC Analyst for ~2 years - Should I still get the Security + Certification?
103d ago
Do CTFs help real world security skills, or just teach patterns?
103d ago
Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo
103d ago
Should I do Security + or Network + or A+? For CompTia
103d ago
Bug bounty is ruining how people learn exploitation
103d ago
ISO/IEC 27701:2025 Scope and Location
103d ago
Cybersecurity's 2026 Wild Ride
103d ago
We built a free multiplayer game that scores prompts on AI code security.
103d ago
Production Usecases
103d ago
How does vCISO work?
103d ago
Trellix discloses data breach after source code repository hack
103d ago
CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path
103d ago
Trellix confirms source code repo access incident
103d ago
Employer Offering to Pay for my Certification test - Which one do I choose?
103d ago
John Strand Pay What You Can Information Security Core Skills live starting May 11th
103d ago
Canvas Breach May Put 275M Users, 9,000 Schools at Risk
103d ago
Is this not such a big deal
103d ago
Do email link checkers need to be 100%?
103d ago
Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
103d ago
Recs for pen testing and vulnerability solutions
103d ago
Identify telegram account holders
103d ago
AI Code Security Study: 6 LLMs vs OWASP Top 10
103d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
103d ago
We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA
103d ago
Cortex XDR Cloud Compromise Alerting
103d ago
Norton.com Verification Email out of the blue
103d ago
Atomic Red Team is now aligned with MITRE ATT&CK v19!
103d ago
Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX?
103d ago
Who are you guys using for your PCI ASV Scanning?
103d ago
Just passed my Security+ exam. Now what?
103d ago
I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work.
103d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
103d ago
[PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection)
103d ago
Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350)
103d ago
An another open door to IoT devices
103d ago
Ideas on how to have personal google-like account synchronization system
103d ago
Lateral Movement - Cross-Session Activation
103d ago
What MCP servers have actually made it into your day-to-day toolkit?
103d ago
Cyber Security Education as Self-Defence classes
103d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
103d ago
Use.ai
103d ago
Educational tech giant Instructure confirms data breach, ShinyHunters claims attack
103d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
103d ago
Browsers making connection on port 3389 from loopback
103d ago
Defender Flagged DigiCert Root Certs as Malware
103d ago
Another breach just hit Canvas (Instructure), and this one is worth a closer look.
103d ago
Over 40% of UK firms suffered cyber attack last year, survey finds
103d ago
EU should seek access to Anthropic's Mythos, Bundesbank says
103d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
103d ago
IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks
104d ago
People in cybersecurity, tell us what was the most epic moment in your career?
104d ago
Prerequisites for CARTP
104d ago
Claude Mythos Cyber Wake Up
104d ago
[ Removed by Reddit ]
104d ago
is trellix from mcafee good to use in 2026?
104d ago
Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list
104d ago
Paypal Accesed by malware me being Stupid
104d ago
How was someone in another country able to read all my private messages without my password or clicking a link?
104d ago
Career Transition Help
104d ago
Alguien para hablar de cyberseguridad
104d ago
What is this
104d ago
Feeling lost and disappointed about finding a job just venting
104d ago
Slow at Learning/Cyber Security?
104d ago
Suspicious traffic from web server
104d ago
Cyber security internship
104d ago
Mentorship Monday - Post All Career, Education and Job questions here!
104d ago
Isn't Windows Defender a crap anymore?
104d ago
Learning Cyber
104d ago
Vishing simulator
104d ago
Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others
104d ago
Worried about being tracked/banned for using an educational app on MuMu Player - Need advice
104d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
104d ago
Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance
104d ago
Prompt Injection in 2026: The Five Attack Patterns That Actually Matter
104d ago
I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine
104d ago
Random trojan detected?
104d ago
CRTA second attempt
104d ago
What’s the hardest thing to learn in cybersecurity?
104d ago
What MCP servers are you integrating into your workflow (not exclusive to security)?
104d ago
WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog
104d ago
What are like the top but unknown Cybersecurity firms?
104d ago
Need professionals or expert on cybersecurity related to dark web for interview
104d ago
A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP)
104d ago
North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory
104d ago
Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate)
104d ago
Credential Dumping: Local Security Authority (LSA|LSASS.EXE)
104d ago
Trojan:Win32/Cerdigent.A!dha
104d ago
MDE flagging digi cert certificate as malicious everywhere ?
104d ago
1867 loaded
HS
hacking: security in practice
65d ago · 241 items
DIY pwnagotchi-like device on esp32
65d ago
Flipper Blackhat + Bjorn
65d ago
Do you think AI is making hacking easier or harder
65d ago
What can i do left? PSN
65d ago
Proxmark5 campaign ending in less than 18 hours.
65d ago
How to bypass speed queen coin slot for washer and dryer
66d ago
Self-hosting stuff for when things get ugly
66d ago
Malware Includes Taboo In Text To Prevent LLM Analysis
66d ago
added Mac support for my corporate hacking game, demo on Steam
66d ago
Catfished
66d ago
What did they mean by this? One of us?
66d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
67d ago
OptOutCode – A Privacy4Cars Universal Opt-Out Concept
67d ago
StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams
68d ago
GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.
68d ago
Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏
68d ago
What's up with powershellforhackers.com?
69d ago
Do people really click on links from unknown numbers?
69d ago
How to unlock whitelabeled uniview IPcam
69d ago
Can converted video files contain malware?
69d ago
Rooted your router lately?
70d ago
5$ to whoever can find the email of my old YouTube channel
70d ago
This company is scaming people
70d ago
A modular autonomous-agent runtime written in C
70d ago
ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more
71d ago
Can one reveal the asterisks in an email?
71d ago
Proxmark3 vs Proxmark5 Side by Side
71d ago
Should I go for it?
71d ago
Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header
72d ago
Failed to verify LHOST error for long links in metasploit
72d ago
Is Marauder available for ESP32-S3 Mini?
72d ago
Gemini whatsapp
72d ago
Safe Rust API for wolfSSL/wolfCOSE
73d ago
Resource Exhaustion
73d ago
I’m not sure I’m in the right subreddit….
73d ago
Took me a decade to turn quantum computing into what hackers can easily learn
73d ago
Took me a decade of work to turn Quantum Computing into a fun videogame
73d ago
Simple way how to bypass hotel WiFi?
73d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
74d ago
burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API)
74d ago
How big of a security risk or exploit would this be?
74d ago
KTO , Be the only one online -- on any WiFi network
74d ago
apparently bypassing school systems by playing games
74d ago
Always-On Red Teams
74d ago
I managed to pull the full system prompt for Meta's Support AI
75d ago
Harassing text messages
75d ago
REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY!
75d ago
Hacking Palo Alto Networks' GlobalProtect VPN with AI
75d ago
Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am.
75d ago
Best AI LLM for Hacking related stuff
75d ago
Feels like most people ignore the wireless layer until it bites them
75d ago
Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking?
76d ago
Can anyone figure out how to retrieve the recovery key in signal app?
76d ago
$730k+ raised on Proxmark5 with 2150 backers
76d ago
I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works)
76d ago
Any idea who's behind this hack? How to resolve it?
77d ago
Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it
77d ago
Blue Team tips?
77d ago
edit certified pdf
77d ago
Everyday hacking in our lives - transportation, work, finances, goods etc
77d ago
Do you think this is legit or has the website been compromised?
78d ago
Wanna learn cybersecurity & ethical hacking
78d ago
Do you guys take paper notes or digital ones during studying ?
78d ago
How do people actually modify mobile games to increase their power?
79d ago
Why Loyalty Programs Are Quietly Becoming a Security Blind Spot
79d ago
Ajuda pessoal
79d ago
Samy Kamkar on building viruses, his arrest and privacy in the LLM era
79d ago
[ Removed by Reddit ]
79d ago
Is this considered a bug or something else entirely?
79d ago
Getting back deleted conversation from messanger
79d ago
Building Omegle for Exposed Webcams
79d ago
AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career?
79d ago
5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain
80d ago
What are the dangers of posting?
80d ago
Flipper Zero Users, What's Your Take?
80d ago
Large company with a bit of an issue free stuff
80d ago
Champion ethical hacker warns AI tools like Mythos will make competing harder.
81d ago
Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker.
81d ago
there's a toll in the hall now
81d ago
Am I crazy or is something off about this Google OAuth login via Calendly
81d ago
When “try again later” still tells you the OTP was correct: an account takeover story.
81d ago
ShadowCat: Universal optical file transfer, single html file, browser to camera
81d ago
y2jb un able to enject payloads
82d ago
Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated.
82d ago
Why did Hack Forums lose popularity?
82d ago
ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise
82d ago
Shellcide: A shellcode IDE
82d ago
Finding bot account
83d ago
How to
83d ago
Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift.
83d ago
Nmap Mastery: The Complete Guide to Network Reconnaissance
83d ago
Google wallet virtual card cloned
83d ago
What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method?
83d ago
Proxmark5 campaign unlocked the $600k stretch goal
84d ago
GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
84d ago
Doom running on a Kids Video Walkie Talkie
84d ago
Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX.
85d ago
This ID Verification company store users biometrics? (FaceTec)
85d ago
Playwright version that lets AI-Agents navigate the web
85d ago
Where to learn the ins and outs of the computer itself
85d ago
Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator
85d ago
Hack your corrupt company. Sell their secrets to the black market
85d ago
🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget
86d ago
CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat
86d ago
This ID verification company allows for storage of biometric data?
86d ago
I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :)
86d ago
SeekYou — one input, 15 recon sources, one report.
86d ago
bypass internet restrictions
86d ago
Can someone unlock a list of the 500-1000 most visited websites online?
87d ago
Wordlist generator based on WordNet graphs + LLM
87d ago
wordpress memberpress
87d ago
The Open Source USB Drive Built for Privacy
87d ago
Is someone trying to hack me?
87d ago
cpu backdoor
87d ago
Technical analysis of CVE-2026-34472 in ZTE H188A router firmware
87d ago
Ongoing development
87d ago
For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks?
87d ago
Hackers found a way around Intel CET—PLaTypus locks down library jumps
88d ago
GitHub investigates internal repositories breach claimed by TeamPCP
88d ago
Hackers: What age did you start? Where did you start, especially in practicing your skills?
88d ago
How to watch a private video on Youtube?
88d ago
Can I do anything cool with this network controller?
88d ago
Micro controller safety?
88d ago
CISA Admin Leaked AWS GovCloud Keys on Github
88d ago
Decompilation of DSP Code using IDA Pro
88d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
88d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
88d ago
Built a full disassembler & decompiler for Reverse Engineering | Free and open source.
89d ago
Slopinator - a poisoned GitHub repository generator
89d ago
Made a shell greeter that generates a unique rocket every time you open a terminal tab
89d ago
Just received an email from shinyhackers about their amtrack hack
89d ago
Flipper Zero (or Alternatives)?
89d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
89d ago
Recent WhatsApp hacks
89d ago
I wrote an async scanner that runs about 9x faster than nmap for discovery.
89d ago
Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers
89d ago
Does anyone know if this file is still accessible to download?
90d ago
High school students organized a Jeopardy CTF competition - give it a try
90d ago
Official Miasma Poison Tar Pit Docker Image Now Available
90d ago
Does anybody know where I may stumble upon some Sh1mmer bin downloads
91d ago
Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network
91d ago
GZDoom in the browser
91d ago
Anyone know how to bypass these school laptop pins?
91d ago
A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA
92d ago
I have a friend who looks like he’s a stalker I’m scared he will know I stalk him
92d ago
[Tutorial] How to hack DOS games: Reversing Prince of Persia
92d ago
Is dns spoofing dead??
92d ago
My Privacy Focused USB Drive
92d ago
Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition)
92d ago
TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer
92d ago
has anyone used tail os here?
93d ago
Run this washer/dryer sans coin?
93d ago
I built an open-source Burp alternative
93d ago
HighBoy
93d ago
Reading Siemens CT raw data
93d ago
How I use Hermes agent to turn Patch Tuesday into Windows exploit research
93d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
93d ago
Tips for a beginner noob that wants to learn
93d ago
Strix — first public beta of the spiritual successor to cSploit/dSploit
93d ago
Whatsapp
93d ago
Face ID bypass with avatar
93d ago
Hunting the Behavior Behind npm Supply Chain Attacks
94d ago
Proxmark5 Day 3 Update - $357K+ funded (715% of goal)
94d ago
Are There Really Ethical Hackers? I've Yet To Meet One
94d ago
trying to learn patching
94d ago
Cellphone IP address spoofing.
95d ago
Sorry if its the wrong place but
95d ago
Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it?
96d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
96d ago
where is the location of Files by Google on Android?
96d ago
Reading old s4 memory with xgecu t48
96d ago
Hack a data center?
96d ago
Autonomous Vulnerability Hunting with MCP
97d ago
AI DNS Resolver
97d ago
Is it true that the professionals have the worst setups?
97d ago
I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage
98d ago
Refining hacking basics — scaling them aswell
98d ago
AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic)
98d ago
Bridging the Gap Between Vulnerabilities and Working Exploits
98d ago
um you guys is my hacker stupid?
98d ago
This GBA ROM makes some weird things in the sanbox, would love to understand why
99d ago
Why was he banned?
99d ago
LAB Setup
99d ago
Ethical malware development community
99d ago
Has Instructure paid SH?
99d ago
Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me.
99d ago
New trends (not mainstream)
99d ago
Best tools to find exposed web services by HTML title / HTTP response?
99d ago
Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago?
100d ago
AI Agents Have a Security Problem. IronClaw is Fixing It.
100d ago
A hacker ran me over with a robot lawn mower - The Verge
100d ago
Happened today
100d ago
Shinyhunters and Canvas
100d ago
Modify md5sum of a file
100d ago
OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM
101d ago
Jailbreaking my cars infotainment system and implementing my own custom software
101d ago
where is the original wormgpt
101d ago
Are there any chill hacking youtubers?
101d ago
Took me a decade to turn quantum computing into what programmers can easily learn, big announcement
101d ago
Lilygo T-Embed Glitching etc
101d ago
Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today?
101d ago
Found a possibly interesting live attack
102d ago
Export/Backup ChatGPT chats
102d ago
Is this fake too?🤣
102d ago
I just figured out my dad use to be a Phreaker in the 1980s
102d ago
What of my favorite videos🙂
103d ago
Best tools for blocking spam calls and spam links?
103d ago
someone else’s UI appearing on screen for split second— possible hacker??
103d ago
Avoiding rouge AP detection in enterprise networks
103d ago
GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering
103d ago
San Diego Community College District fighting major cyberattack
103d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
103d ago
Iwas developing a hacker game that transports the feeling of the 90s
103d ago
How did this guy even access another person's privated YouTube video without wayback machine?
103d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
103d ago
IPod Nano Gets Three Monitors
103d ago
Chrome "Best AdBlocker" trojanized extension - 100k downloads.
103d ago
Any good open sources that bypass modern heuristic analysis?
104d ago
Free apex hacks?
104d ago
[SHOWCASE] Cascavel v3
104d ago
Pokemon machine
104d ago
Can HTTP POST bodies be intercepted without network or host access?
104d ago
built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4)
104d ago
Dump sql time based is too slow
104d ago
North Korea rejects US cybercrime claims as 'absurd slander'
104d ago
is credential stuffing using openbullet2 dead in 2026?
105d ago
Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax)
105d ago
Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT)
105d ago
Small models are better at cost-to-recall than large models like Mythos for vulnerability research
106d ago
Bluetooth Spoofed Disconnect?
106d ago
wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ...
106d ago
🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀
107d ago
I made a lightweight breach intelligence search engine (fully client-side) looking for feedback
107d ago
Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan...
107d ago
Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool
107d ago
Copy Fail — 732 Bytes to Root
108d ago
GitHub fixes RCE flaw that gave access to millions of private repos
108d ago
How to download Kaggle dataset safely...?
108d ago
VECT Ransomware Is Actually a Wiper
108d ago
Flipper Blackhat April Roundup!
109d ago
[VulnPath Update] Automated Email Alerting & CISA KEV Feed
109d ago
241 loaded
RE
Reverse Engineering
65d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it
65d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
65d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
65d ago
Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game
65d ago
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
65d ago
Drive Firmware Security - Phison S11
66d ago
IDA 9.4 Beta | Hex-Rays Docs
66d ago
Trane Tracer HVAC cybersecurity issues
66d ago
🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS)
67d ago
I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS.
67d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
68d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
68d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
68d ago
EMBA firmware analysis framework v2.0.2 available - Party the big 2k
68d ago
/r/ReverseEngineering's Weekly Questions Thread
69d ago
HDD Firmware Hacking Part 1
69d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction
69d ago
Zhiyun Weebil-S Camera Gimbal BLE Protocol
69d ago
Reverse Engineering the Garmin Running Dynamics BLE protocol
69d ago
Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate)
70d ago
Reverse Engineering Crazy Taxi, Part 3
71d ago
Ghidra 12.1.2 has been released!
71d ago
Extending a map tool for Cataclismo
71d ago
I've been reverse engineering a lost 2010 horse MMO and I need contributors
71d ago
HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes
72d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
72d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
72d ago
void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies
72d ago
Automated Fault Injection Attack Framework
73d ago
x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994)
73d ago
Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2
73d ago
Hacking your PC using your speaker without ever touching it
73d ago
Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source!
74d ago
Built a decompiler for exotic legacy programming language opentext Gupta Team Developer
74d ago
running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it!
75d ago
/r/ReverseEngineering's Weekly Questions Thread
76d ago
Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from?
76d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
76d ago
TinyLoad v7 - what i added :D (in memory protection using VEH and alot more)
77d ago
[ Removed by Reddit ]
77d ago
Snowboard Kids 2 is 100% Decompiled
77d ago
usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer)
77d ago
I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux)
77d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
78d ago
Ghidra 12.1.1 has been released!
78d ago
Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint)
79d ago
VMP 3.5+ Internal Architecture & Heap Dispatch Analysis
79d ago
How 2004 RuneScape fit a multiplayer RPG into 56k dial-up
79d ago
reverse engineering need for speed most wanted for modding sdk
79d ago
GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs.
80d ago
Winbox server/client reverse engineered is opensource
80d ago
(URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active
80d ago
Hypothetical EDR spoofer
80d ago
I Reverse Engineered Need for Speed Most Wanted Server
81d ago
Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation
81d ago
Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching
81d ago
How I Tried to Parse a Replay from Dawn of War: Definitive Edition
81d ago
Nocturne - A bin2bin code virtualizer for x86-64 PE binaries
82d ago
[Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing
82d ago
Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing
82d ago
I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built
82d ago
delimiter-less string obfuscation powered by compile-time AES
82d ago
/r/ReverseEngineering's Weekly Questions Thread
83d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
83d ago
Has anyone manage to reverse the macked dylib?
83d ago
Reverse engineering circuitry in a Spacelab computer from 1980
84d ago
Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology
84d ago
CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22)
85d ago
Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes
85d ago
qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb)
85d ago
Reverse Engineered Google reCAPTCHA
86d ago
Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware
86d ago
I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP
86d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
86d ago
I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries
86d ago
GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam)
87d ago
AI Agents defeat obfuscated JavaScript in 10 minutes
87d ago
What is it Wednesdays: Episode 0002
87d ago
TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post)
87d ago
Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing
87d ago
How to build .NET obfuscator
87d ago
botguard-token-generator / a google botguard token gen using only requests...?
87d ago
Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing)
88d ago
Deep dive into the object creation flow in Windows - PART 4: Handle table internals.
88d ago
Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware
88d ago
Open-source Hermes bytecode decompiler for React Native apps (Rust)
88d ago
Hermes bytecode decompiler (Rust) - sharing my friend’s project
88d ago
Forza Designer 6
89d ago
Built a full disassembler & decompiler | Free and open source.
89d ago
Snowboard Kids 2 is 100% Decompiled
89d ago
Decompilation projects and N64 Recompiled PC ports (May 2026)
89d ago
Glass - A fast and free interactive disassembler
89d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
89d ago
HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try!
90d ago
/r/ReverseEngineering's Weekly Questions Thread
90d ago
Reverse engineering no dep x64 masm AI IDE
90d ago
PE packer/crypter with random VM ISA per build
90d ago
A Tale of Two File Names
91d ago
PE reconstruction
91d ago
A File Format Uncracked for 20 Years: Part 2
91d ago
Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source!
91d ago
[CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link.
91d ago
Exploiting Toshiba Qiomem.sys vulnerable driver
91d ago
HDD Firmware Hacking Part 1
92d ago
Region-based binary diff tool for firmware analysis
92d ago
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
92d ago
แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป!
92d ago
Brovan — Open-source x86/x64 user-mode binary emulator written in C#
92d ago
Brovan: Binary user-mode emulator for x86_64
92d ago
Understanding Stack Buffer Overflows Through Doom and C++
92d ago
What is it Wednesdays: Episode 0001
92d ago
Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup
92d ago
Deepdive into the object creation flow in Windows -PART 2 : access check internals
92d ago
Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization
92d ago
[Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo)
92d ago
yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android.
92d ago
GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets
93d ago
GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS
93d ago
Trafexia V2 - Mobile Traffic Interceptor Toolkit
93d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
93d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
93d ago
Ghidra 12.1 has been released!
93d ago
Reverse Engineering Slither.io’s Network Protocol
94d ago
I Reverse-engineering Need for Speed Underground 2 Server
94d ago
I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included
94d ago
[Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features
94d ago
LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer]
94d ago
r2garlic - The world's fastest Android/DEX decompiler meets radare2!
95d ago
GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language.
95d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
96d ago
Reverse Engineering Fisher-Price Pixter
96d ago
/r/ReverseEngineering's Weekly Questions Thread
97d ago
Check out my matplotlib of BLE live wire data for Oura ring!
97d ago
Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows
97d ago
Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop
97d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
97d ago
Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)
97d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3
97d ago
PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra
97d ago
[Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc)
99d ago
Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!)
99d ago
Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2
99d ago
SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals
100d ago
I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow!
100d ago
The first FREE online WebAssembly Reverse Engineering workbench (and how we built it)
100d ago
VLC Media Player MKV Exploit Analysis
100d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
101d ago
ant4g0nist/pyre: Ghidra decompiler in your browser
102d ago
Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source!
102d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
102d ago
Reverse-engineering the 1998 Ultima Online demo server
102d ago
Inside Faxanadu series — deep dive into how this NES title works
102d ago
EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing
102d ago
Copy.fail: Why Internal LLMs Are Non-Negotiable for Security
102d ago
Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra
103d ago
Where do i find reverse engineers for actuators? Ideally in Shenzhen
103d ago
[CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2).
103d ago
[WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation
103d ago
IDA-MCP Is Now RE-MCP With Ghidra Support
103d ago
Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference
103d ago
/r/ReverseEngineering's Weekly Questions Thread
104d ago
GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions)
104d ago
Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo
104d ago
Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you!
104d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
105d ago
How to build .NET obfuscator - Part II
105d ago
libghidra - SDK for automating Ghidra from Python, Rust, and C++
105d ago
Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis.
105d ago
Why my macOS Messages badge lied to me (and the one-line fix)
106d ago
Running Adobe’s 1991 PostScript Interpreter in the Browser
106d ago
Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :)
106d ago
/r/ReverseEngineering's Triannual Hiring Thread
107d ago
In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off)
107d ago
Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight
107d ago
HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try!
108d ago
GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).
108d ago
I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway
108d ago
Building a perfect clone of 1993 game SimTower (via RE)
109d ago
How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema
109d ago
AI solved our CTF in 6min
109d ago
Example structure for evidence-based vulnerability reports
110d ago
181 loaded
FB
For [Blue|Purple] Teams in Cyber Defence
65d ago · 603 items
US charges suspected Russian hacker with facilitating cyber campaign
65d ago
Hawkish GOP lawmaker Don Bacon says he was hacked by Russia
65d ago
Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
65d ago
GreatXML: GreatXML bitlocker bypass vulnerability
65d ago
GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan
65d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
66d ago
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion
66d ago
GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default
66d ago
Miasma-style supply chain attacks
66d ago
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet
66d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
66d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
66d ago
Testing offensive AI agents in a cloud lab with deception tech
66d ago
Benchmarking n-day exploit generation [via AI]
67d ago
Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
67d ago
Microsoft Defender now monitors RPC activity
67d ago
RoguePlanet: RoguePlanet Windows Defender Vulnerability
67d ago
I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in)
67d ago
How do you make learning blue team security entertaining ?
67d ago
Maximizing IOC Impact
67d ago
[2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution
67d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
67d ago
Entra Agent ID from a Security Perspective
67d ago
Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility
67d ago
What are the best risk-based vulnerability management tools for tracking active exploitation in 2026?
68d ago
QuasarNix: Reverse Shell Detection with Machine Learning
68d ago
Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go
68d ago
Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion
68d ago
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
68d ago
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
68d ago
UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season
68d ago
Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
68d ago
Visual Studio Code 1.123: Delayed extension auto-updates
68d ago
Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.
68d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched,
68d ago
Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement
68d ago
HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified)
68d ago
Security Review Request — TID Linux Kernel Module
69d ago
Building a safe, effective sandbox to enable Codex on Windows
69d ago
Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale.
69d ago
About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection
69d ago
BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection
69d ago
Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution.
69d ago
UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service.
69d ago
EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
69d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
69d ago
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
69d ago
cygor: An modular asset discovery framework written in python to automate the repeating manual work
69d ago
On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts.
70d ago
Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors.
70d ago
Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim
70d ago
Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored)
70d ago
The Privileged Roles Nobody Talks About
70d ago
Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain...
70d ago
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
70d ago
21 Zero-Days in FFmpeg
70d ago
depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research?
70d ago
CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work
70d ago
The Detection & Response Chronicles: Covert Operations Through QEMU
70d ago
The Interesting Case of WSL for Payload Staging
70d ago
The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer
70d ago
Ongoing Targeted Campaign Against US Law Firms
70d ago
New China-Linked Cluster OP-512
70d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
70d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
70d ago
MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain
70d ago
Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated
70d ago
Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns
70d ago
About ETW Internals: Architecture, Hooking, Tampering, and Detection
70d ago
PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver
70d ago
Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
70d ago
Async PICOs and Custom Beacon Wakeups in Cobalt Strike
70d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
70d ago
staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs
70d ago
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window
70d ago
Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS
70d ago
BOF Cocktails in Cobalt Strike
70d ago
Address Translation
70d ago
Investigation into APT 5 and their inner workings of PLA Troop 61786
70d ago
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
70d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
70d ago
Magecart skimmer turns Stripe into a malware command server
70d ago
Security advisory: Brute force attack on Dashlane user accounts
70d ago
Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability
70d ago
A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact).
70d ago
IronWorm: Shai-Hulud's rustier cousin
70d ago
Weil reportedly pays up to $20 million after hackers steal client data
70d ago
CTO at NCSC Summary: week ending June 7th
70d ago
defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
71d ago
1-Click GitHub Token Stealing via a VSCode Bug
71d ago
The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds
71d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
71d ago
Introducing Package Proxy: supply-chain safety checks without client-side software
71d ago
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
71d ago
zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS)
72d ago
The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory
72d ago
VerdantBamboo: Just Another BRICKSTORM in the Firewall
72d ago
AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID
72d ago
MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code
72d ago
IronWorm Supply Chain Malware Hits npm
72d ago
FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel
72d ago
FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad
72d ago
You do surprise me.exe: An unexpected executable in Hola Browser
72d ago
LSASS/Defender/CTFMON analysis
72d ago
Software supply chain attacks: check your dependencies
72d ago
Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator
72d ago
29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection)
73d ago
Open Source - 2500 New MITRE Mutations
73d ago
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
73d ago
Bring Your Own RWX Region DLL (BYORWXDLL)
73d ago
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
73d ago
APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component
73d ago
NuGet Code Execution As A Service
73d ago
aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies
73d ago
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
73d ago
TA4922: The Suspected Chinese Crime Group is Going Global
73d ago
[ Removed by Reddit ]
73d ago
Espionage Campaign Targeted Stock Exchange Executive for Five Months
73d ago
OnionAccelerator: multi-circuit / chunked download acceleration over Tor
73d ago
HazyBeacon and AWS Lambda Function URL Abuse
73d ago
The Server Seizure That Affects Also Iran's Cyber Operations
73d ago
How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad
73d ago
🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network
73d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
73d ago
Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors
73d ago
Dependency Cooldowns - Dependency Cooldowns
74d ago
C2 Frameworks - Threat Hunting in Action with YARA Rules
74d ago
Ransomware tabletop
74d ago
Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026
74d ago
Tracking North Korea Nation-State APT Infrastructure: Kimsuky
74d ago
새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn
74d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
74d ago
Codex Discovered a Hidden HTTP/2 Bomb
74d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
74d ago
Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix
74d ago
“Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?”
74d ago
Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif
74d ago
Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand
74d ago
Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm
75d ago
RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation
75d ago
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
75d ago
Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches
75d ago
Miasma: Supply Chain Attack Targeting RedHat npm Packages
75d ago
@redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers
75d ago
Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched
76d ago
Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks
76d ago
Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries
76d ago
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
76d ago
Atomdrift - open-source malware detection for the software supply chain
76d ago
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
77d ago
179 npm Packages Target Cloud and Finance via oob.moika.tech
77d ago
KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4
77d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
77d ago
Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services
77d ago
EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA
77d ago
Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace
77d ago
Signal macOS Desktop App Doesn't Actually Delete Messages When it Should
77d ago
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
77d ago
WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD
77d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
77d ago
Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2
77d ago
Malicious npm packages abuse dependency confusion to profile developer environments
77d ago
Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
77d ago
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack
77d ago
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
77d ago
Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign
77d ago
SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.
77d ago
EDR Incident Response Playbook: Containing Local Account Incidents
77d ago
Adversarial Oracles: LLM-Guided EDR Signature Reduction
77d ago
One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF
77d ago
proxy: A lightweight caching proxy for package registries.
77d ago
How OLTs may have exposed entire ISP networks
77d ago
A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
77d ago
HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics
77d ago
Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots
77d ago
Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures
77d ago
Lessons from Penetration Tests on Large-Scale Agent Systems
77d ago
pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter.
77d ago
CIFSwitch: a non-universal Linux local root vulnerability
77d ago
Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension
77d ago
DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.
77d ago
Visual Studio Extensions Revisited
77d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
77d ago
BYOVD and Looting LSASS in the Modern EDR Era
77d ago
CTO at NCSC Summary: week ending May 31st
77d ago
OffensiveCon26 videos
78d ago
School Survey, (non-paid nothing its free its for my grades)
78d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
78d ago
LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms
78d ago
LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting
78d ago
Identifying attack patterns through kernel frame callstacks
78d ago
Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness
78d ago
What safety boundary would you expect from a local AI incident investigation tool?
78d ago
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
78d ago
Why I Built My Own LLM Benchmark for THOR Finding Triage
79d ago
Casdoor contains multiple authentication bypass and access management vulnerabilities
79d ago
The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents
79d ago
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
79d ago
Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies
79d ago
Malware seller hunted across three continents
79d ago
Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims
79d ago
Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers
79d ago
Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network
79d ago
Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations.
79d ago
The C-suite job that's burning people out faster than any other
79d ago
New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation
79d ago
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
79d ago
Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances
79d ago
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
79d ago
APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026
79d ago
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
79d ago
Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
79d ago
Zero Trust Implementation Guidelines
79d ago
BlackToad: Network Manipulation in an AutoIt Payload
79d ago
RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT
79d ago
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
79d ago
Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit
79d ago
FROST: Fingerprinting Remotely using OPFS-based SSD Timing
79d ago
Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup
80d ago
puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
80d ago
Who is Salt Typhoon Really? Unraveling the Attribution Challenge
80d ago
Looking for resources on end-to-end APT attack flow summaries for detection engineering
80d ago
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
80d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP
80d ago
Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint
80d ago
Building Detection Engineering on AWS from scratch — roast my plan
80d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
80d ago
Designing secure access with ZTNA
80d ago
MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response
81d ago
White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats
81d ago
Advisory X41-2026-002: Request Host Header not Validated in Starlette
81d ago
Top ethical hacker Chompie warns AI tools could put her out of business
81d ago
浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents
81d ago
YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions
81d ago
CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state
81d ago
The Evolution of Chinese-language Phishing Services
81d ago
Silent Ransom Group Impersonating IT Personnel through Social Engineering
81d ago
The epoll UAF - an epoll uaf race in fs/eventpoll.c
81d ago
Tycoon 2FA AiTM detection for Entra ID and Google
81d ago
Microsoft Copilot Cowork Exfiltrates Files
81d ago
Unpatched Sparx vulnerabilties
81d ago
sylvia: iOS Syscall Explorer for IDA 9.X
81d ago
Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East
81d ago
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip
81d ago
JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign
81d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack
81d ago
Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@"
82d ago
The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization
82d ago
GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
82d ago
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
82d ago
CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700.
82d ago
YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos
82d ago
Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it
82d ago
honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports
82d ago
Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild.
82d ago
Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council
82d ago
RemotePE: The Lazarus RAT that lives in memory
82d ago
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
82d ago
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
82d ago
Twee mannen aangehouden voor phishing - Two men arrested for phishing
82d ago
Sharp Eyes: Mass surveillance of foreigners in China
82d ago
relay_bible: Technical Reference to multiple relay techniques
83d ago
Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec
83d ago
The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in]
83d ago
SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format
83d ago
North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial
83d ago
Staged publishing and new install-time controls for npm - GitHub Changelog
83d ago
Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES
83d ago
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
83d ago
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow
83d ago
The Future and Past of Residential Proxies
83d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
83d ago
Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy
83d ago
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
83d ago
A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software
83d ago
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
83d ago
Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities
83d ago
Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes
83d ago
mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
83d ago
keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust.
83d ago
np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.
83d ago
Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up.
83d ago
OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
83d ago
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
83d ago
FatGid - FreeBSD 14.x kernel LPE
83d ago
Manage [VSCode] extensions in enterprise environments
83d ago
angr: A powerful and user-friendly binary analysis platform!
83d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
83d ago
How Attackers Force Microsoft to Send Phishing Emails
83d ago
Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
83d ago
Microsoft Authenticator App Details now exposed in Entra SignInLogs
83d ago
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
83d ago
How China-linked threat actors obtain zero-day vulnerabilities
83d ago
Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research
83d ago
Monitoring for vssadmin.exe delete shadows is an absolute bare minimum
83d ago
Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack
83d ago
How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers
83d ago
CVE-2026-48029: Two grid-decode bugs in libheif
83d ago
workcell: Bounded local runtime and policy boundary for coding agents
83d ago
OpenShell: OpenShell is the safe, private runtime for autonomous AI agents.
83d ago
Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation
84d ago
Built a SOC from scratch with no prior SOC experience
84d ago
CTO at NCSC Summary: week ending May 24th
84d ago
VPN Exploitation When Patched Doesn't Mean Protected
84d ago
Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation
84d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
84d ago
CLR-Stomp: .NET CLR-Stomping
84d ago
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
84d ago
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms
84d ago
Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor
84d ago
AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22)
85d ago
GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks.
85d ago
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
85d ago
Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL?
85d ago
I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner
85d ago
AI-generated reporting: Lessons learned from Cisco Talos Incident Response
85d ago
CrabLoader: A PoC Cobalt Strike UDRL written in Rust
85d ago
The 429 Microsoft Graph Mystery
85d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
85d ago
Azure Tenant Enumeration is Dead
85d ago
A Deep Dive into Codex Windows Sandbox
85d ago
Striga: Lifting x86 to LLVM IR with Python
85d ago
veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker.
85d ago
Windows BitLocker Security Feature Bypass Vulnerability
85d ago
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
85d ago
Google API keys keep working after you delete them long enough to be exploited
85d ago
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
85d ago
North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT
85d ago
Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit
85d ago
Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names)
86d ago
Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
86d ago
Megalodon: CI/CD Malware Spreading Across GitHub Repositories
86d ago
📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity.
86d ago
Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
86d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
86d ago
beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA
86d ago
Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading
86d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
86d ago
Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign
86d ago
From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree
86d ago
How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102)
86d ago
Iran-linked Operators Suspected in ATG Breaches
86d ago
Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs
86d ago
Compromised Nx Console version 18.95.0
86d ago
CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
87d ago
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
87d ago
Webworm: New burrowing techniques
87d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
87d ago
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
87d ago
Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation
87d ago
GitHub’s Fake Engagement Problem Is Hiding in Plain Sight
87d ago
Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR)
87d ago
Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage
87d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
87d ago
5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready
87d ago
Remote Process Read Primitive via NtCreateThreadEx Exit Code
87d ago
aimap: Discover Exposed AI Services
87d ago
FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation.
87d ago
Why China Is Now a Peer Competitor to the United States in Cyberspace
87d ago
nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings
88d ago
Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt
88d ago
We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.
88d ago
Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings)
88d ago
Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
88d ago
Eight Leading U.S. Communications Firms Form C2 ISAC
88d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
88d ago
UAC-0184: From HTA to a Signed Network Stack
88d ago
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
88d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
88d ago
Entra ID: PIM for Groups Review
88d ago
TeamPCP compromises NPM maintainer with over 540 packages
88d ago
Active Supply Chain Attack Compromises @antv Packages on npm...
88d ago
When DMCA Comes Knocking - A YouTube Creator Phishing Kit
89d ago
[Cloudflare] Project Glasswing: what Mythos showed us
89d ago
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
89d ago
Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger
89d ago
Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics
89d ago
CrystalX: unpacking a Go RAT through three encrypted layers
89d ago
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write
90d ago
FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation
90d ago
LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying"
90d ago
Static Kitten APT Adversary Simulation
90d ago
Eimeria: five layers from RAR5 to RunPE
90d ago
ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
90d ago
openDCIM exploitation
90d ago
HASBL CTF - A Jeopardy-Style CTF Organized by High School Students!
90d ago
We Have Packet Capture at Home
90d ago
Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware
91d ago
HWMonitor Trojanized for STX RAT DLL Sideloading
91d ago
awesome-dfir-skills: Admiralty System for CTI Claude skill
91d ago
Mullvad exit IPs as a fingerprinting vector
91d ago
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
91d ago
Popular node-ipc npm Package Infected with Credential Steale...
91d ago
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
91d ago
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
91d ago
Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
91d ago
Sandworm Activity in Industrial Environments: What the Data Reveals
91d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
91d ago
"Shadowserver-in-a-box" IntelMQ + ELK Solution
91d ago
Stenloader: Steganography Shellcode Loader
91d ago
AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out
91d ago
Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018
91d ago
Our response to the TanStack npm supply chain attack
91d ago
QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026).
91d ago
We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase.
91d ago
APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox.
91d ago
oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday
91d ago
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations
91d ago
OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance
91d ago
The Gentlemen Ransomware Group — Leak Analysis
91d ago
HDD Firmware Hacking Part 1
91d ago
ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.
91d ago
CTO at NCSC Summary: week ending May 17th
91d ago
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
91d ago
Developer credential-theft campaign exposed operator-side self-infection
91d ago
Help-Desk Lures Drop KongTuke's Evolved ModeloRAT
91d ago
Welcome to BlackFile: Inside a Vishing Extortion Operation
91d ago
DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era
91d ago
Stop Being Weird — Life After Call Stack Spoofing Under CET
91d ago
Triggering the Secure Boot Certificate Update with Intune Remediations
91d ago
How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache
91d ago
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
91d ago
One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities
91d ago
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
91d ago
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
91d ago
FamousSparrow APT Targets Azerbaijani Oil and Gas Industry
91d ago
Disclosing new PebbleDash-based tools by Kimsuky
91d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
91d ago
Kazuar: Anatomy of a nation-state botnet
91d ago
OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments
91d ago
NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys
91d ago
Hacker Ringleader Extradited for 38 Billion Won Theft
91d ago
Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System
91d ago
Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit
91d ago
The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation
91d ago
FFFFirefox - A One-Day Wonder Renderer Exploit
91d ago
MiniPlasma, a powerful LPE
91d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
92d ago
[Tool] IOCX — deterministic static IOC extraction for PE binaries
92d ago
Novel Evilginx Frontend - Lowering the barrier for token theft reuse
92d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
92d ago
WAF Evasion Engine
93d ago
Thus Spoke…The Gentlemen
93d ago
KQLab - open-source query manager for SOC teams
93d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown
93d ago
Microsoft AntiSSRF
93d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
93d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
93d ago
How fast is autonomous AI cyber capability advancing?
93d ago
YellowKey: YellowKey Bitlocker Bypass Vulnerability
94d ago
Tinker Tailor Soldier: Paper Werewolf’s latest toolkit
94d ago
126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies
94d ago
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
94d ago
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise
94d ago
[HOMELAB] Built a SOC investigation console on two old Dell boxes
94d ago
Android Intrusion Logging as a new source of data for consensual forensic analysis
94d ago
Shai-Hulud: Another Wave and Going Open Source
94d ago
A stealth approach to Process Injection - EntryPoint Hijacking
94d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
94d ago
Service Principal Sign-Ins: A blind spot that a lot are missing
95d ago
My Analysis of a Bandook RAT PCAP
95d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
95d ago
Detection Rule is here
95d ago
Owning a service principal equals owning its permissions.
95d ago
Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection
95d ago
CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.
95d ago
AI+DFIR Challenge: Share Your Disasters and Successes
95d ago
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
95d ago
Postmortem: TanStack npm supply-chain compromise
95d ago
bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages
96d ago
rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions
96d ago
Detecting Remote Thread Creation with Windows Driver
96d ago
Mythos finds a curl vulnerability
96d ago
Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details
96d ago
Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
96d ago
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
96d ago
esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app
96d ago
LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors.
96d ago
How Cloudflare responded to the “Copy Fail” Linux vulnerability
96d ago
I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic.
96d ago
LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots.
96d ago
New Shai-Hulud npm worm variant
96d ago
EtwWatcher
96d ago
Donuts and Beagles: Fake Claude site spreads backdoor
96d ago
Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach
96d ago
CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection
96d ago
Deterministic PE Validation for Blue Teams - IOCX v0.7.3
96d ago
Delving deep into threat detection: My logic for abnormal EventID 7 activity
96d ago
NZ announces sanctions on malicious Russian cyber actors, online platforms
97d ago
Update: Ongoing Checkmarx Supply Chain Security Incident
97d ago
ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025
97d ago
Unmanaged PowerShell Execution: Hunting Beyond powershell.exe
97d ago
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign
97d ago
Static Devirtualization of Themida
97d ago
Now You See Me: AADGraphActivityLogs
97d ago
[Write-up] CyberDefenders: Wiredive Lab
97d ago
page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
97d ago
JDownloader — Website installer incident (May 2026)
97d ago
The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate."
97d ago
AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT
97d ago
EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine)
98d ago
Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers
98d ago
Writing a Naive LLVM-based Devirtualizer
98d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
98d ago
When prompts become shells: RCE vulnerabilities in AI agent frameworks
98d ago
Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus
98d ago
MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174)
98d ago
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor
98d ago
Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles.
98d ago
Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026
98d ago
Member of Prolific Russian Ransomware Group Sentenced to Prison
98d ago
EasterBunny: advanced espionage artifacts attributed to APT29
98d ago
Tracking the "Sorry" Extortionist Campaign Against cPanel Websites
98d ago
PositiveIntent: Evasive loader for .NET Framework assemblies
98d ago
The Accidental C2: Exploring Dev Tunnels for Remote Access
98d ago
Living of the Land - DISM Sandbox Provider Hijack
98d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
98d ago
CTO at NCSC Summary: week ending May 10th
98d ago
ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure
98d ago
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
98d ago
Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo
98d ago
DARWIS Taka - Web vulnerability scanner with Optional AI Validation
99d ago
SunnyDayBPF: eBPF telemetry integrity research for detection engineering
99d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama
99d ago
Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou...
99d ago
Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack
100d ago
Dirty Frag: Universal Linux LPE
100d ago
Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication.
100d ago
Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea
100d ago
Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia
100d ago
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI
100d ago
Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC
100d ago
Detecting BEC Persistence with KQL
100d ago
Unpacking Russian-Iranian Private-Sector Cyber Connections
101d ago
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
101d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
101d ago
Inadvertent Injections
101d ago
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
101d ago
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
101d ago
Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed
101d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
101d ago
UAT-8302 and its box full of malware
101d ago
CVE-2026-0073 Android adbd TLS client-authentication bypass
102d ago
One KQL query you should have saved in your toolkit (most don’t)
102d ago
CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier?
102d ago
Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside
102d ago
🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records
102d ago
Popular DAEMON Tools software compromised
102d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
102d ago
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
102d ago
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
102d ago
Accelerating Vulnerability Detection and Response at Oracle
102d ago
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
102d ago
GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated.
103d ago
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
103d ago
N-Day Research with AI: Using Ollama and n8n
103d ago
38 CVEs in Healthcare Software Used by 100,000 Medical Providers
103d ago
Recursively fuzzing MS-RPC structures and monitoring using ETW
103d ago
VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases
103d ago
CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation.
103d ago
《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition)
103d ago
nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution.
103d ago
蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery.
103d ago
gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives
104d ago
Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon
104d ago
AMSI Page Guard Bypass (Rust PoC)
104d ago
Meet Bluekit: The AI-Powered All-in-One Phishing Kit
104d ago
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
104d ago
A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia
104d ago
IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect
104d ago
Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
104d ago
ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution…
104d ago
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
104d ago
[2603.28728] Study of Post Quantum status of Widely Used Protocols
104d ago
Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin
104d ago
Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning
104d ago
code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.
104d ago
Secure Boot Inventory Data In Configuration Manager
104d ago
EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time.
104d ago
MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning.
104d ago
AI-powered honeypots: Turning the tables on malicious AI agents
104d ago
copy.golf — golf your exploits - smaller copy.fail exploits..
104d ago
DragonBreath: Dragon in the Kernel
104d ago
Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors.
104d ago
Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
104d ago
Puzzle: Set of PoC to abuse Windows minifilters functionality
104d ago
A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16
104d ago
Active exploitation of cPanel/WHM critical vulnerability
104d ago
Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. "
104d ago
5 Qilin ransomware servers exposed over 7 months
105d ago
South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)
105d ago
Russian Charged in Oil and Gas Facility Hacks Pleads Guilty
105d ago
VECT ransomware: small files decrypt, large files lose their nonces
105d ago
CTO at NCSC Summary: week ending May 3rd
105d ago
April 27th - What happened with our feature flag configuration | The ClickUp Blog
105d ago
Blog: Evolving the Android & Chrome VRPs for the AI Era
105d ago
Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.
105d ago
VECT: Ransomware by design, Wiper by accident
105d ago
VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built.
105d ago
Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison
105d ago
Agentic Malware Analysis: From Task Automation to Deep Analysis
105d ago
pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner.
105d ago
month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only
105d ago
603 loaded
MA
Malware Analysis & Reports
65d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
65d ago
ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper
66d ago
WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap
66d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
67d ago
Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment
68d ago
73 Microsoft GitHub repositories impacted by Miasma malware
68d ago
Unauthorized Onlyfans Payment
69d ago
Building A Malware Lab From Scratch Part 2!
70d ago
Detecting npm Native Addon Malware: node-gyp Abuse
71d ago
Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links
72d ago
Extremely suspicious behaviour by memu emulator
72d ago
Malware
73d ago
🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop
73d ago
ChatGPT Malvertising Campaign
73d ago
Recommendation
73d ago
Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6!
73d ago
This is a scam and probably a malware/trojan. Path Of Exile 2 builder ...
74d ago
LLMShare: using shared chatbot pages to distribute malware
75d ago
How to Unpack FlawedAmmyy - Malware Unpacking Tutorial
76d ago
Building A Malware Lab From Scratch!
76d ago
I bought an old phone from 2018 and wanna destroy it with viruses for fun
77d ago
Malware escaped browser without downloading files, then escaped a virtual machine
78d ago
I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but
78d ago
A Deeper Look at GLASSWORM's Solana Variant
79d ago
Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15
79d ago
Kali365 Activity Surges: Device Code Phishing Is Scaling Fast
80d ago
MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
80d ago
Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io)
80d ago
Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down.
81d ago
How random program can cause most of antiviruses close himself without telling himself to close
81d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
82d ago
Suspicious ass website asking to run a terminal command (MacOS)
82d ago
Harvard and 140 other legitimate websites compromised
85d ago
Browser session theft is quietly becoming more dangerous than password theft
85d ago
Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
85d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account
86d ago
Database of Malicious Browser Extensions
86d ago
I’ve got 99 problems, and IOCX isn’t one.
86d ago
Can't access anything
88d ago
New GMKtec M7 Ultra appears to be infected. Beware of the malware!
88d ago
vpn explained the simple version that actually makes sense
89d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
89d ago
Netmirror exposed - The Free Movie App That Was Robbing You Blind
90d ago
Malware learning
90d ago
Brovan: Binary user-mode emulator for x86_64
92d ago
Inspecting a DLL file trying to figure out if it really is malware
93d ago
npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output
93d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
93d ago
I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable...
94d ago
clens.io - new public threat & data intel service
94d ago
Granny’s Compromised Android Firmware
94d ago
[Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
94d ago
OS scanner that checks repos for traces of the Shai Hulud worm
95d ago
Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI
95d ago
Steam spear phishing
96d ago
Fake linked in sponsored google search
96d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
96d ago
New Shai-Hulud npm worm variant
96d ago
looking for "evil" Websites
96d ago
Deterministic PE Structural Validation in IOCX v0.7.3
96d ago
sl1nk link
96d ago
How to download a RAT for myself
97d ago
Wtf OPEN Ai
98d ago
JDownloader's official website delivered Python RAT
99d ago
An unknown malware threat. There is no such thing as a 100% detection.
100d ago
Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites
101d ago
Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML
101d ago
Discord bot C2 infrastructure
101d ago
IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening
102d ago
Panicking
102d ago
Supply chain attack: DAEMON Tools Lite now contains a backdoor.
102d ago
Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation
103d ago
VirusTotal has one flag for this sus site
104d ago
Anyone wanna learn the CEH or OSCP red teaming free
105d ago
Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself
106d ago
Minecraft Malware C2 Tracking
106d ago
Minirat malware deployed via NPM targeting macOS machines
108d ago
VECT Ransomware Is Actually a Wiper
108d ago
The Malware Factory: GLASSWORM Forensics in Open VSX
109d ago
Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore
109d ago
[ Removed by Reddit ]
109d ago
Ikeja Electric Distribution Ransomware
109d ago
Recently updated a authentic minecraft mod launcher called Modrinth
109d ago
This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0
110d ago
Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely
110d ago
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses
112d ago
Save time and use Zig to write your Malware POC
112d ago
Cracking CastleLoader’s Inno Setup Password
113d ago
I built a C2 framework that uses Discord and Telegram for communication
113d ago
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet.
114d ago
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
114d ago
PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs
114d ago
Budgiekit - gdi malware maker (for educational purporses only)
114d ago
19 confirmed repos tied to the same GitHub malware campaign
115d ago
IOCX v0.7.0 — deterministic heuristics + adversarial PE samples
116d ago
I built a kernel-level EDR and hit architectural walls I didn’t expect
177d ago
Update your detection rules: New remote access Trojan
178d ago
Criminals are using AI website builders to clone major brands
178d ago
Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants)
179d ago
PE Loader For Fileless Malware
180d ago
Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers
180d ago
AWAKE - Android Wiki of Attacks, Knowledge & Exploits
180d ago
I built a Chrome extension that scans for malicious extensions (yes, I see the irony)
180d ago
Questions regarding malicious pdf's
182d ago
AV persistence bypass techniques
182d ago
Avalon Linux Bot Malware Analysis
183d ago
Leveling up in Windows malware research
185d ago
Emerging Ransomware: BQTLock and GREENBLOOD
185d ago
Malware Development POCs
186d ago
Suspicious code in Up-work linked repository.
186d ago
We hid backdoors in binaries — Opus 4.6 found 49% of them
186d ago
👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡
187d ago
Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions
188d ago
Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer
189d ago
Nyxara
191d ago
115 loaded
SM
Security | Microsoft Azure Blog | Microsoft Azure
74d ago · 6 items
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
74d ago
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
103d ago
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
107d ago
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
Azure IaaS: Keep critical applications running with built-in resiliency at scale
136d ago
Learn how Azure IaaS helps organizations start from a resilient platform foundation with availability, continuity, and recovery capabilities.
Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure
164d ago
Learn how Azure IaaS helps you modernize infrastructure, improve performance and resilience, optimize costs, and prepare for AI workloads. Read more.
Azure reliability, resiliency, and recoverability: Build continuity by design
179d ago
Learn how Azure reliability, resiliency, and recovery capabilities work together to improve cloud continuity. Read more.
ZU
ZDI: Upcoming Advisories
108d ago · 1 items
CC
CISA Cybersecurity Advisories
116d ago · 2 items
Defending Against China-Nexus Covert Networks of Compromised Devices
116d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
131d ago
U.S. organizations should review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the
BA
Blog Articles - Identity Insights | Trulioo
121d ago · 13 items
Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business
121d ago
What is Customer Due Diligence (CDD)
145d ago
Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud
148d ago
AML, KYC and Identity Verification in Australia
157d ago
When Fraud Becomes Background Noise: The Industrialization of Digital Deception
222d ago
The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage
222d ago
The End of Static KYB: Business Identity in Constant Motion
222d ago
Know Your Agent: The Next Chapter in Digital Trust
222d ago
When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage
222d ago
Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration
241d ago
The World’s Identity Platform
1293d ago
KYC: 3 Steps to Achieving Know Your Customer Compliance
1564d ago
AML Compliance Checklist: Best Practices for Anti-Money Laundering
1579d ago
13 loaded
II
InfoSec Insights
157d ago · 1 items
FP
Fraud Prevention Archives - Alloy Silverstein
163d ago · 10 items
AI in Tax Season: Risks, Scams, and How to Protect Your Data
163d ago
Tax Season Scams to Watch For This Year
170d ago
Beware of Misleading Tax Advice on Social Media
338d ago
Each year the IRS educates taxpayers on the most trending fraud schemes that could deceive individuals and businesses during tax season. In late 2024, The IRS took to warning the public against misleading “tips” or...
Scammers Up Their Game With AI
340d ago
Learn how to spot the threats and protect yourself from scammers using AI for phishing and deepfakes with smart security practices.
The Essential Guide to Safeguarding Your Online Passwords
417d ago
Protect your personal and business data with strong passwords, two-factor authentication, and smart cybersecurity practices.
Beware: Tax Season is Scam Season
528d ago
Tax season is also prime time for tax scams. To safeguard your personal information, consider these key points: Communication methods The IRS initiates contact primarily through mail, not email or phone calls. Be cautious of...
Stop Scams: Fraud Prevention Starts with Your Employees
542d ago
You can be as proactive and protective as possible when it comes to cyber security for your business, but there’s one vulnerability you cannot eliminate: human error. In fact, statistics estimate that as much as...
‘Tis the Season for Holiday Shopping Scams
614d ago
The holidays are typically the time of year for gifting presents to friends and family or donations to charity. Unfortunately, not-so-jolly fraudsters take advantage of this generosity. Protect yourself by watching for these common scams:.....
IRS Issues “Dirty Dozen” Fraud Warnings
800d ago
Each year, the IRS releases a “Dirty Dozen” series to highlight the most common fraud schemes taxpayers should be aware of.
IRS Identity Theft Season Begins Now
929d ago
Each year thieves try to steal billions in federal withholdings by stealing your identity. As the IRS focuses more attention on this quickly growing problem, now is the time of year to be extra vigilant....
HA
HackerSploit
493d ago · 15 items
How FIN6 Exfiltrates Files Over FTP
493d ago
Emulating FIN6 - Active Directory Enumeration Made EASY
544d ago
The SECRET to Embedding Metasploit Payloads in VBA Macros
549d ago
Offensive VBA 0x4 - Reverse Shell Macro with Powercat
558d ago
Offensive VBA 0x3 - Developing PowerShell Droppers
564d ago
Offensive VBA 0x2 - Program & Command Execution
568d ago
Offensive VBA 0x1 - Your First Macro
570d ago
Emulating FIN6 - Gaining Initial Access (Office Word Macro)
576d ago
FIN6 Adversary Emulation Plan (TTPs & Tooling)
579d ago
Developing An Adversary Emulation Plan
579d ago
Introduction To Advanced Persistent Threats (APTs)
584d ago
Introduction To Adversary Emulation
605d ago
Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion
614d ago
Planning Red Team Operations | Scope, ROE & Reporting
754d ago
Mapping APT TTPs With MITRE ATT&CK Navigator
758d ago
15 loaded
TH
Threatpost
1445d ago · 10 items
Student Loan Breach Exposes 2.5M Records
1445d ago
2.5 million people were affected, in a breach that could spell more trouble down the line.
Watering Hole Attacks Push ScanBox Keylogger
1446d ago
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
1447d ago
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Ransomware Attacks are on the Rise
1450d ago
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
1451d ago
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Twitter Whistleblower Complaint: The TL;DR Version
1452d ago
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Firewall Bug Under Active Attack Triggers CISA Warning
1453d ago
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Fake Reservation Links Prey on Weary Travelers
1454d ago
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
iPhone Users Urged to Update to Patch 2 Zero-Days
1457d ago
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Google Patches Chrome’s Fifth Zero-Day of the Year
1458d ago
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
No matching sources found.