DNI nominee Clayton wins Senate panel’s approval
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
Taiwan to slow mobile data during national resilience drills
Kenya probes hack of president's website after bitcoin ransom demand
Flock Safety kills acoustic system designed to detect 'human distress'
What's New
Top 5 Across All Sources-
DNI nominee Clayton wins Senate panel’s approval
The Record from Recorded Future News · 1h ago -
Cisco Launches Low-Cost AI Models for Source Code Security
SecurityWeek · 1h ago -
Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack
The Record from Recorded Future News · 1h ago
Gigafeed (4925 entries)
DNI nominee Clayton wins Senate panel’s approval The Record from Recorded Future News · 1h ago Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains SecurityWeek · 1h ago How spatial audio works on headphones and speakers - and the best way to experience it Latest news · 1h ago Cisco Launches Low-Cost AI Models for Source Code Security SecurityWeek · 1h ago Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack The Record from Recorded Future News · 1h ago Critical wp2shell WordPress flaws exploited to install webshells BleepingComputer · 2h ago A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots Security Latest · 3h ago AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code The Hacker News · 3h ago Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability Cisco Security Advisory · 3h ago Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next Latest news · 3h ago 90,000 Flock cameras have quietly gone up in the US: What they track and how to check your city Latest news · 3h ago Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities The Hacker News · 4h ago Light's new $299 flip phone has no apps and T9 texting, but aims to connect people Latest news · 4h ago Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC The Hacker News · 4h ago AI agents tricked into recommending malicious GitHub repositories Help Net Security · 4h ago Teleport enhances Identity Security platform with new AI agent behavior controls Help Net Security · 5h ago Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access The Hacker News · 5h ago Closing the Identity Gaps in Critical Infrastructure Security BleepingComputer · 5h ago CVE-2026-58640 Windows NTFS Remote Code Execution Vulnerability MSRC Security Update Guide · 5h ago CVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability MSRC Security Update Guide · 5h ago This Android 17 setting logs suspicious activity on your phone for troubleshooting - turn it on ASAP Latest news · 5h ago JadePuffer returns with ransomware built to target AI models and infrastructure Help Net Security · 5h ago Taiwan to slow mobile data during national resilience drills The Record from Recorded Future News · 5h ago Druva brings backup, recovery and governance to AI workloads Help Net Security · 5h ago Android backups count toward your 15GB Google storage limit now - how to check your settings Latest news · 5h ago Apps targeted at US troops contain Chinese and Russian code Security - Ars Technica · 5h ago Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities The Hacker News · 5h ago An AI Botnet John Hammond · 5h ago Cisco’s open-weight Antares models make vulnerability localization cheaper Help Net Security · 6h ago AT&T's new business plan includes 'unlimited' hotspot data - and starts at $75 per line Latest news · 6h ago A new extortion cocktail: office printers, small ransoms, and BitLocker Securelist · 6h ago Empirical Security Raises $25 Million in Series A Funding SecurityWeek · 6h ago I tested iOS 26 Siri against iOS 27 Siri AI in my car - and it wasn't even close Latest news · 6h ago SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity SecurityWeek · 6h ago Kenya probes hack of president's website after bitcoin ransom demand The Record from Recorded Future News · 7h ago Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs The Hacker News · 7h ago New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication SecurityWeek · 7h ago N-day is Becoming N-Hour. Patching Faster Won't Save You. The Hacker News · 7h ago CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG SecurityWeek · 7h ago New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit The Hacker News · 7h ago Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack SecurityWeek · 7h ago US seizes over 1,000 websites in FIFA World Cup piracy crackdown BleepingComputer · 8h ago Shufti simplifies cross-border compliance with the Glocal Platform Help Net Security · 8h ago SonicWall SMA zero-days were exploited weeks before disclosure Help Net Security · 8h ago Fake FBI agents target people who already got scammed Help Net Security · 8h ago Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data SecurityWeek · 8h ago Critical Palo Alto VPN bug now exploited by Qilin ransomware gang BleepingComputer · 8h ago Best tablets for note-taking 2026: Expert tested and reviewed Latest news · 9h ago T-Mobile will pay for your first month of 5G home internet, and give you up to $200 back - here's how Latest news · 9h ago A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now Security Latest · 9h ago Clover Health Investments Discloses Data Breach SecurityWeek · 9h ago AWS wants GuardDuty to automate the first steps of threat investigations Help Net Security · 9h ago Microsoft shares manual fix for WSUS sync delays and timeouts BleepingComputer · 10h ago Estée Lauder discloses data breach tied to Oracle EBS vulnerability Help Net Security · 10h ago WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning The Hacker News · 10h ago CVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place crypto MSRC Security Update Guide · 10h ago CVE-2026-63796 ocfs2: reject oversized group bitmap descriptors MSRC Security Update Guide · 10h ago CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout() MSRC Security Update Guide · 10h ago CVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2() MSRC Security Update Guide · 10h ago CVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write MSRC Security Update Guide · 10h ago CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. MSRC Security Update Guide · 10h ago CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input. MSRC Security Update Guide · 10h ago Exploitation of ServiceNow Vulnerability Seen Days After Disclosure SecurityWeek · 10h ago CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record MSRC Security Update Guide · 10h ago CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index MSRC Security Update Guide · 10h ago CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location MSRC Security Update Guide · 10h ago CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row MSRC Security Update Guide · 10h ago CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text MSRC Security Update Guide · 10h ago CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record MSRC Security Update Guide · 10h ago CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service MSRC Security Update Guide · 10h ago New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Securelist · 10h ago CVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loop MSRC Security Update Guide · 10h ago CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg MSRC Security Update Guide · 10h ago CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done MSRC Security Update Guide · 10h ago Windows LegacyHive zero-day flaw gets free, unofficial patches BleepingComputer · 11h ago CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q MSRC Security Update Guide · 11h ago Fedora Xfce or Xubuntu: Which is the best Linux desktop? Latest news · 11h ago New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack The Hacker News · 11h ago Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution The Hacker News · 12h ago I wore Meta's $499 prescription Ray-Bans for 6 weeks: They're stylish but not for me Latest news · 19h ago Estée Lauder discloses data breach via Oracle E-Business flaw BleepingComputer · 20h ago SonicWall SMA1000 flaws exploited as zero-days to push custom malware BleepingComputer · 20h ago Hackers steal $23.7 million in crypto from Ostium in off-chain attack BleepingComputer · 20h ago Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes BleepingComputer · 21h ago Want to add Android Auto to your old car? Here are two ways - including one that's under $20 Latest news · 21h ago JadePuffer agentic attacks now target AI model data with ransomware BleepingComputer · 22h ago Flock Safety kills acoustic system designed to detect 'human distress' The Record from Recorded Future News · 23h ago FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware The Hacker News · 1d ago Director of Commerce AI standards office out after three months CyberScoop · 1d ago New HollowGraph malware uses Microsoft Graph for stealthy C2 comms BleepingComputer · 1d ago I tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this much security Latest news · 1d ago Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign The Hacker News · 1d ago The best rugged phones in 2026: Expert tested Latest news · 1d ago An AI agent breached Hugging Face before an AI defender caught it: What users should do next Latest news · 1d ago Why I still recommend Synology's DS225+ NAS - even if it can't replace your cloud storage Latest news · 1d ago Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities Cisco Security Advisory · 1d ago HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 The Hacker News · 1d ago How I configure DNS on Ubuntu Linux distros via the command line - it's easier than you think Latest news · 1d ago Why blocking AI models won’t stop the cyber threats they create CyberScoop · 1d ago Redirect Chain Abuse John Hammond · 1d ago An AI SOC Evaluation Guide for Security Leaders BleepingComputer · 1d ago Pay up or not? Ransomware surge has victims facing tough choices. Security - Ars Technica · 1d ago Cybersecurity Keeps Events 'Uneventful' darkreading · 1d ago Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack Cyber Defense Magazine · 1d ago Microsoft Exchange Hacked, Five Years Later John Hammond · 1d ago How to check if ChatGPT and other AI tools cite your website - and improve your chances in 2026 Latest news · 1d ago ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More The Hacker News · 1d ago I tested 3 blood pressure trackers for a month - only one rivaled my Garmin Index BP Monitor Latest news · 1d ago Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine The Hacker News · 1d ago Hugging Face discloses breach linked to autonomous AI agent BleepingComputer · 1d ago Mythos Didn't Break Your Security Program. Your Exposure Window Could. The Hacker News · 1d ago Microsoft confirms Windows Server Update Services sync delays BleepingComputer · 1d ago Windows KB5121767 OOB update fixes shutdowns on some Dell PCs BleepingComputer · 1d ago The ACLU Is Arming Lawyers to Expose State Surveillance Secrets Security Latest · 1d ago Apps Marketed to US Troops Are Shipping Chinese and Russian Code Security Latest · 1d ago Critical ServiceNow code execution flaw now exploited in attacks BleepingComputer · 1d ago New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction The Hacker News · 1d ago Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs The Hacker News · 1d ago World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent The Hacker News · 1d ago Threat Hunting: A Guide | Recorded Future Recorded Future · 1d ago I got inside FIFA’s Secret World Cup Broadcast Network NetworkChuck · 2d ago Hackers abuse ViPNet software to target Russian govt agencies BleepingComputer · 2d ago Update now: 7-Zip fixes RCE flaw exploitable with malicious archives BleepingComputer · 2d ago WordPress Core "wp2shell" RCE flaws get public exploits, patch now BleepingComputer · 3d ago HackTheBox Logging IppSec · 3d ago Microsoft warns of surge in ACR Stealer attacks on customers BleepingComputer · 3d ago The Future of Age Verification: Your Face Never Leaves Your Device BleepingComputer · 3d ago Your Period Tracker Is (Probably) Spying on You Security Latest · 3d ago Prompt Injection Attacks Are Thwarting AI Hacking Agents Security Latest · 3d ago Abbott Laboratories probes two cyber incidents amid extortion claims BleepingComputer · 3d ago Inc Ransomware Exploits SonicWall SMA Zero-Days darkreading · 3d ago HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload BleepingComputer · 4d ago The Real AI Threat Is Blind Trust darkreading · 4d ago Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks Microsoft Security Blog · 4d ago State officials, election experts pan Trump speech: ‘This is what desperation looks like’ CyberScoop · 4d ago Ernst & Young discloses data breach after support system hack BleepingComputer · 4d ago Leading members of Scattered Spider sentenced in UK to 66 months in jail CyberScoop · 4d ago Inside the Search for "Clean" Residential Proxies for Carding BleepingComputer · 4d ago Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear darkreading · 4d ago UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker Cyber Defense Magazine · 4d ago Google Bets 'Agentic Defense' Strategy Can Outpace Attackers darkreading · 4d ago New Windows LegacyHive zero-day gives hackers admin privileges BleepingComputer · 4d ago Hacking US Elections: The First Tranche of Declassified Election Integrity Documents Cyber Defense Magazine · 4d ago San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores Security Latest · 4d ago Windows Server 2022 reach end of mainstream support in 90 days BleepingComputer · 4d ago MediaArena malvertising: why a quarantine isn’t the end of the incident Heimdal Security Blog · 4d ago US charges two over laundering $43 million from investment fraud BleepingComputer · 4d ago CISA urges immediate action on actively exploited Fortinet flaws BleepingComputer · 4d ago Tracking Advanced Persistent Threat Groups | Recorded Future Recorded Future · 4d ago ACR Stealer: Two observed intrusion chains amid increased threat activity Microsoft Security Blog · 4d ago New ClickLock macOS malware traps users into revealing login password BleepingComputer · 4d ago AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA NetworkChuck · 4d ago Coca-Cola says Fairlife ransomware attack halts US dairy production BleepingComputer · 4d ago Agentic AI: Taming the Unpredictable darkreading · 4d ago 1M+ Emails Use Hidden Text to Dupe AI Security Filters darkreading · 4d ago Now, even Russia's most elite hackers are using Clickfix to infect devices Security - Ars Technica · 4d ago Claude Chrome extension flaw lets malicious extensions trigger AI actions BleepingComputer · 4d ago Program to rotate cyber personnel through federal agencies saw little use CyberScoop · 4d ago New OkoBot framework deploys 20 payloads to steal data, crypto BleepingComputer · 5d ago Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime CyberScoop · 5d ago Least privilege for AI agents: Identity, access, and tool binding Microsoft Security Blog · 5d ago Evil Token Marketplace John Hammond · 5d ago No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE Technical Information Security Content & Discussion · 5d ago [$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking Technical Information Security Content & Discussion · 5d ago AI Agents Broke the Security Playbook. Here's What Replaces It. BleepingComputer · 5d ago 23andMe to pay $18 million in new genetics data breach settlement BleepingComputer · 5d ago HelloNet campaign — new malicious modules launched through the ViPNet update system Securelist · 5d ago Scattered Spider members behind TfL hack get five years in prison BleepingComputer · 5d ago Inside Microsoft’s Record-Breaking 622-Bug Release Cyber Defense Magazine · 5d ago GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration Securelist · 5d ago Windows 11 24H2 Home and Pro reach end of support in 90 days BleepingComputer · 5d ago CISA orders feds to patch actively exploited Oracle flaw by Saturday BleepingComputer · 5d ago Russian hackers trojanize WebEx, Zoom apps to push Starland malware BleepingComputer · 5d ago New Spirals ransomware encrypts victim network in under 24 hours BleepingComputer · 5d ago Payload Podcast 009 - Steven Flores John Hammond · 5d ago Police Disrupt a €140M Cyber Fraud Ring in Spain darkreading · 5d ago ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL Technical Information Security Content & Discussion · 5d ago Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery Microsoft Security Blog · 5d ago AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict Recorded Future · 5d ago Dutch police bust investment fraud ring stealing over €100 million BleepingComputer · 5d ago Forgotten Bootloaders Expose Secure Boot Blind Spot darkreading · 5d ago Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’ Security Latest · 5d ago Security researchers find stalkers abusing Chrome’s sync feature CyberScoop · 5d ago Identity Attacks Overtake Exploits as Top Ransomware Cause darkreading · 5d ago Zoom warns of critical account takeover vulnerability BleepingComputer · 5d ago Windows 0-day drops the same day Microsoft releases record number of patches Security - Ars Technica · 5d ago SonicWall customers under threat as attackers exploit 2 zero-days CyberScoop · 6d ago Google Gemini CLI abused as a hacking agent, malware botnet operator BleepingComputer · 6d ago Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed CyberScoop · 6d ago Guten Tag, Bonjour, Hola to Our European Cyber Defenders! darkreading · 6d ago Black Hat Stories | Shanna Daly, CEO of Torin Cyber Group Black Hat · 6d ago Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife darkreading · 6d ago Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook Cyber Defense Magazine · 6d ago Cisco Advance Notification for Publication of July 15, 2026, Security Advisories Cisco Security Advisory · 6d ago Turning threat intelligence into decisive action with Defender Experts Microsoft Security Blog · 6d ago Cisco RoomOS Security Hardening Release: July 2026 Cisco Security Advisory · 6d ago Cisco Identity Services Engine Path Traversal Vulnerability Cisco Security Advisory · 6d ago Your Home Internet Has a New Owner | Threat Wire Hak5 · 6d ago News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations The Last Watchdog · 6d ago AsyncAPI npm packages infected with credential-stealing malware BleepingComputer · 6d ago Forget the model. When it comes to cybersecurity, it’s all about the harness CyberScoop · 6d ago Claude Flaw Automatically Sends Malicious Prompts to AI Agents darkreading · 6d ago News alert: Insignary’s on-demand SBOM verification boosts software supply chain security The Last Watchdog · 6d ago We built a vulnerability vending machine: AI tokens in, zero-days out BleepingComputer · 6d ago 2-Click Cursor Exploit Enables Dev Environment Takeover darkreading · 6d ago Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure Cyber Defense Magazine · 6d ago OkoBot: new sophisticated malware framework targets cryptocurrency users Securelist · 6d ago CISA warns admins to patch actively exploited SharePoint flaws BleepingComputer · 6d ago HN Security - My Semgrep C/C++ ruleset is ready for prime time again Technical Information Security Content & Discussion · 6d ago The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets Technical Information Security Content & Discussion · 6d ago Microsoft: Some Dell PCs shut down after recent Windows updates BleepingComputer · 6d ago (More) Unauthenticated Arbitrary Code Execution in ServiceNow Technical Information Security Content & Discussion · 6d ago 78% of CFOs Say Payment Blind Spots Increase Customer Friction PYMNTS | Fraud Prevention Archives · 6d ago Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits darkreading · 6d ago US charges alleged operators of Russian bulletproof hosting service BleepingComputer · 6d ago News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions The Last Watchdog · 6d ago Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal darkreading · 6d ago The Shift: A New Era of AI Regulation Recorded Future · 6d ago Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Security - Ars Technica · 6d ago Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes darkreading · 6d ago SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now BleepingComputer · 6d ago Spanish Police take down €140 million cyber fraud ring, arrest four BleepingComputer · 6d ago 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems darkreading · 6d ago Microsoft Patches a Record 570 Security Flaws Krebs on Security · 6d ago Nearly 300 GitHub repos pose as legit software to push malware BleepingComputer · 6d ago Microsoft releases Windows 10 KB5099539 extended security update BleepingComputer · 7d ago Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days BleepingComputer · 7d ago Backdoored TortoiseSVN Installer John Hammond · 7d ago Manage Vendor Risk in a Few Practical Steps darkreading · 7d ago Is Cat7 a SCAM? David Bombal · 7d ago Windows 11 KB5101650 & KB5099414 cumulative updates released BleepingComputer · 7d ago The Gray Area in Your Checkout Is Costing You More Than You Think Blog – Forter · 7d ago What to Expect at Black Hat USA 2026 Black Hat · 7d ago Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown BleepingComputer · 7d ago Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? darkreading · 7d ago LastPass, Bitwarden users targeted with fake security alerts BleepingComputer · 7d ago What Nacha’s amended rules mean for your ACH fraud monitoring Fraud Prevention – Riskified · 7d ago You Don't Have to Run an Exploit to Know If You're Vulnerable BleepingComputer · 7d ago OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Proofpoint News Feed · 7d ago Microsoft Entra ID gets passkeys default authentication starting September BleepingComputer · 7d ago New phishing kits target Microsoft 365 accounts, evade MFA BleepingComputer · 7d ago CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers Cyber Defense Magazine · 7d ago SAP warns of critical flaws in NetWeaver and Commerce Cloud BleepingComputer · 7d ago Smashing the ServiceNow Sandbox – Pre Authentication RCE Technical Information Security Content & Discussion · 7d ago Microsoft starts testing cleaner Windows Search without ads BleepingComputer · 7d ago US sanctions VPN, malware providers for enabling ransomware attacks BleepingComputer · 7d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 7d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 7d ago The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future Recorded Future · 7d ago Context Bombs: Using AI Guardrails as a defensive mechanism Technical Information Security Content & Discussion · 7d ago Defending SaaS-based applications against ShinyHunters OAuth abuse Microsoft Security Blog · 7d ago The US government warns that Russia state hackers are coming after your router Security - Ars Technica · 7d ago CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC) Technical Information Security Content & Discussion · 7d ago Japan's largest taxi operator shuts systems after cyberattack BleepingComputer · 7d ago Cisco's Agents Reason Like a CCIE David Bombal · 7d ago Hackers backdoor Jscrambler npm package with infostealer malware BleepingComputer · 7d ago New CrashStealer malware poses as Apple crash reporting tool BleepingComputer · 8d ago Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID Microsoft Security Blog · 8d ago CISA warns of actively exploited RCE flaws in Joomla extensions BleepingComputer · 8d ago Now, defenders are embracing the prompt injection, too Security - Ars Technica · 8d ago Lessons Learned from CISA’s Recent GitHub Leak Krebs on Security · 8d ago Lidl discloses online shop breach after service provider hack BleepingComputer · 8d ago Breach at the Beach: Play the Ultimate Entra ID CTF BleepingComputer · 8d ago Black Hat Europe 2025 | Compromising The AI Agent Ecosystem Via Its "Universal Connector" Black Hat · 8d ago Hackers find a new trick to collect Microsoft Entra user data without raising red flags Proofpoint News Feed · 8d ago UK charges suspects linked to Russian Coms call spoofing platform BleepingComputer · 8d ago This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!) NahamSec · 8d ago The Threat Mechanism and Mitigation of Pink Vishing Campaigns Cyber Defense Magazine · 8d ago EU sanctions Russian GRU military hackers over cyberattacks BleepingComputer · 8d ago A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance Security Latest · 8d ago Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) Technical Information Security Content & Discussion · 8d ago US and allies warn of Russian critical infrastructure attacks BleepingComputer · 8d ago 85% of CFOs Say Automation Cuts Payments Friction PYMNTS | Fraud Prevention Archives · 8d ago Persistence via Fake AMSI Provider | Playbook & Detection Strategies Technical Information Security Content & Discussion · 8d ago OpenAI temporarily relaxes GPT-5.6 Sol usage limits BleepingComputer · 8d ago Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver Technical Information Security Content & Discussion · 8d ago Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time BleepingComputer · 8d ago Black Hat Europe 2025 | Millions of Intranet Devices Are Facing Silent Takeover (On-Demand Only) Black Hat · 9d ago RedHook Android malware now uses Wireless ADB for shell access BleepingComputer · 9d ago Install GrapheneOS Before Your Phone Becomes the Checkpoint David Bombal · 9d ago Scanning malicious websites with arbitrary number of VPN tunnels (Part 2) Technical Information Security Content & Discussion · 10d ago Black Hat Europe 2025 | Bootstrapping Trust: From Isolated Build Machines to Enclaved CI Pipelines Black Hat · 10d ago HackTheBox - CCTV IppSec · 10d ago Australia warns of global campaign targeting vulnerable CMS platforms BleepingComputer · 10d ago See It Once, Stop It Everywhere Cyber Defense Magazine · 10d ago AI Found a Root Bug in Linux That Everyone Missed for 15 Years Security Latest · 10d ago 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets BleepingComputer · 10d ago NEW AI Hacking Challenges with Andrew Bellini! John Hammond · 10d ago New U-Boot flaws could enable stealthy firmware attacks BleepingComputer · 10d ago Cybercriminals Targeting World Cup Fans Cyber Defense Magazine · 10d ago Ryuk ransomware member pleads guilty in the US, faces 15 years in prison BleepingComputer · 11d ago Police suspects Dutch hackers were involved in Odido breach BleepingComputer · 11d ago Progress urges ShareFile admins to shut down servers over “credible” threat BleepingComputer · 11d ago Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative Microsoft Security Blog · 11d ago Soft Skills for the Job Market: Applying for Jobs The Cyber Mentors · 11d ago Hackers exploit critical auth bypass in Gitea Docker image BleepingComputer · 11d ago Money launderer accused of stealing seized crypto while in prison BleepingComputer · 11d ago Fake Microsoft Installer John Hammond · 11d ago Black Hat Europe 2025 | Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL Black Hat · 11d ago The Replicant in Your Directory: AI Agents and the Identity Security Gap BleepingComputer · 11d ago Top 6 Managed Detection and Response Providers Heimdal Security Blog · 11d ago Can AI-generated adversaries break TTP-based attribution? (arXiv 2026) Technical Information Security Content & Discussion · 11d ago Zimbra urges customers to patch critical web client XSS flaw BleepingComputer · 11d ago Towards CSI: What's the best harness? (arXiv 2026) Technical Information Security Content & Discussion · 11d ago Former ransomware negotiator gets 4 years for BlackCat attacks BleepingComputer · 11d ago Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail CyberScoop · 11d ago June 2026 CVE Landscape Recorded Future · 11d ago LIVE AMA | Summer of CCNA | 07/09/2026 NetworkChuck · 11d ago OpenMandriva Linux says contributor tried to sabotage the project BleepingComputer · 11d ago Patch for Windows Defender 0-day could allow attackers to fill hard disk Security - Ars Technica · 11d ago Injective SDK on npm infected with cryptocurrency wallet stealer BleepingComputer · 11d ago Black Hat Intercepted | Olivia Gallucci, Security Engineer at Datadog Black Hat · 12d ago See you at Black Hat USA 2026! John Hammond · 12d ago Interpol cybercrime crackdown nets 5,800 arrests across 97 countries CyberScoop · 12d ago New Helix vishing group emerges in SharePoint data theft attacks BleepingComputer · 12d ago Microsoft expects more Windows security updates from AI-discovered flaws BleepingComputer · 12d ago GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware Microsoft Security Blog · 12d ago Black Hat Europe 2025 | Ghost In The Stack: Evolving Call Stack Spoofing In A Post-CET Era Black Hat · 12d ago New Forg365 phishing platform uses AI to target Microsoft 365 accounts BleepingComputer · 12d ago 764 splinter group leader sentenced to 40 years in jail CyberScoop · 12d ago Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities Technical Information Security Content & Discussion · 12d ago The Hidden Security Risks of Reduced Summer IT Coverage BleepingComputer · 12d ago A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway Security Latest · 12d ago Microsoft to retire the OWA Light client in Exchange Server BleepingComputer · 12d ago Madison Square Garden Kept a List of Gay Celebrities Security Latest · 12d ago Police arrests 5,800 suspects in global anti-fraud crackdown BleepingComputer · 12d ago AssuranceAmerica data breach exposes records of 6.9 million drivers BleepingComputer · 12d ago Microsoft patches RoguePlanet Defender zero-day vulnerability BleepingComputer · 12d ago RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney Recorded Future · 12d ago Mount Royal University confirms breach as hackers claim attack BleepingComputer · 12d ago Your Payment Routing Rules Are Making Decisions Without You Blog – Forter · 12d ago Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials BleepingComputer · 12d ago Google pays $250K for Linux vulnerability allowing guest VM escapes Security - Ars Technica · 13d ago Black Hat Europe 2025 | ORMageddon: Leaking More Than You Joined For Black Hat · 13d ago Hackers exploit Roundcube flaw to spy on academic researchers BleepingComputer · 13d ago French nonprofit starts global intelligence and research hub for AI cyber threats CyberScoop · 13d ago 1 in 2 devices sold in Africa exfiltrate data to China Technical Information Security Content & Discussion · 13d ago Inside an AI coal mine security camera network powered by plaintext passwords Technical Information Security Content & Discussion · 13d ago News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI The Last Watchdog · 13d ago LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway The Cyber Mentors · 13d ago Protecting Microsoft at AI speed: How SFI proactively hardens our cloud Microsoft Security Blog · 13d ago Entra passkey enrollment vishing targets Microsoft 365 users BleepingComputer · 13d ago Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches Technical Information Security Content & Discussion · 13d ago TeamPCP Attention John Hammond · 13d ago Black Hat Europe 2025 | Breaking AI Inference Systems: Lessons From Pwn2Own Berlin Black Hat · 13d ago 3 Ways AI Powers Service Desk Attacks and How to Prevent Them BleepingComputer · 13d ago Suspected Chinese snoops caught breaking into universities' Roundcube mailservers Proofpoint News Feed · 13d ago Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security · 13d ago DuckDuckGo browser now blocks YouTube video ads BleepingComputer · 13d ago Telco giant KDDI says data breach affects over 12 million people BleepingComputer · 13d ago OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear Security Latest · 13d ago What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out Security Latest · 13d ago CISA orders feds to prioritize patching Langflow auth bypass flaw BleepingComputer · 13d ago Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Heimdal Security Blog · 13d ago Found fast, fixed slow: The gap the AI clearinghouse must close CyberScoop · 13d ago ESET Threat Report H1 2026 WeLiveSecurity · 13d ago ESET Threat Report H1 2026 WeLiveSecurity · 13d ago Ubiquiti warns of new max severity UniFi OS vulnerability BleepingComputer · 13d ago 42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million PYMNTS | Fraud Prevention Archives · 13d ago CISA orders feds to patch max severity ColdFusion flaw by Friday BleepingComputer · 13d ago Hackers can use 9 of the most popular AI tools to assemble massive botnets Security - Ars Technica · 13d ago Bad Epoll: The bug missed by Mythos Technical Information Security Content & Discussion · 13d ago Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire Hak5 · 13d ago The Threat Isn’t the Frontier Model Recorded Future · 13d ago Accenture confirms breach after hacker offers stolen data for sale BleepingComputer · 13d ago Spain arrests suspected hacker linked to Russian hacktivist campaign CyberScoop · 13d ago Deepfake CSAM lawsuit against xAI, Grok expands CyberScoop · 13d ago Chinese hackers develop LONGLEASH malware to expand ORB network BleepingComputer · 14d ago Hidden backdoor in Tenda router firmware grants admin access BleepingComputer · 14d ago Black Hat Intercepted | Anurag Swarnim Yadav, Co-Founder & CTO of QubitAC Black Hat · 14d ago Spain arrests suspected member of pro-Russian hacktivist groups BleepingComputer · 14d ago GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail Technical Information Security Content & Discussion · 14d ago Black Hat Europe 2025 | Nation-Scale SecOps: How CERT PL Scans Poland Black Hat · 14d ago The GitHub Actions Attack Pattern Your CI Security Scanners Miss BleepingComputer · 14d ago Webinar tomorrow: Why modern email attacks require a new approach to defense BleepingComputer · 14d ago New Januscape Linux flaw allows VM escape on Intel, AMD devices BleepingComputer · 14d ago Threat landscape for industrial automation systems. Q1 2026 Securelist · 14d ago Microsoft to enable Windows settings backup by default for orgs BleepingComputer · 14d ago Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities CyberScoop · 14d ago BeyondTrust warns of critical flaws in remote access software BleepingComputer · 14d ago Microsoft testing new Cloud Rebuild Windows 11 recovery feature BleepingComputer · 14d ago Phishing poses as big-brand job interview to steal Google accounts BleepingComputer · 14d ago Fake IT support calls on Microsoft Teams push EtherRAT malware BleepingComputer · 14d ago Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities Cisco Security Advisory · 14d ago Vietnam arrests suspects behind HiAnime anime piracy service BleepingComputer · 15d ago Unveiled: Cisco Deep Reasoning David Bombal · 15d ago News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk The Last Watchdog · 15d ago US Army websites defaced with pro-Kurdish sentiments, insults to Trump CyberScoop · 15d ago Sysdig clocks first documented case of agentic ransomware CyberScoop · 15d ago Open Source Malware John Hammond · 15d ago Black Hat Europe 2025 | Not Just Victims: The Hidden Villains Inside Infostealer Logs Black Hat · 15d ago New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!" Technical Information Security Content & Discussion · 15d ago Software Is Now Written at the Speed of Thought. Security Isn't. BleepingComputer · 15d ago Max severity Adobe ColdFusion flaw now exploited in attacks BleepingComputer · 15d ago I Made an AI Agent That Reverses CVEs While I Sleep NahamSec · 15d ago Cisco Catalyst Center Arbitrary File Read Vulnerability Cisco Security Advisory · 15d ago ICE’s Internal Watchdog Is Now Investigating Online Critics Security Latest · 15d ago Playing Around With ADIDNS RPC Internals Technical Information Security Content & Discussion · 15d ago When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website Securelist · 15d ago Finding vulnerabilities was never the hard part CyberScoop · 15d ago Windows Service - Playbook & Detection Strategies Technical Information Security Content & Discussion · 15d ago THE MOD WORKS! lets improve it John Hammond · 15d ago Why Apple Hide My Email FAILS David Bombal · 16d ago Black Hat Europe 2025 | Taking Control Over Legacy And ERTMS/ETCS Railroad Signaling Systems Black Hat · 16d ago Flipper Zero firmware development continues with community help BleepingComputer · 16d ago New to Linux? This is the best place to start! David Bombal · 16d ago the vibe continues John Hammond · 16d ago Black Hat Europe 2025 | Slashing QUIC's Performance With A Hash DoS Black Hat · 17d ago HackTheBox - DevArea IppSec · 17d ago JadePuffer ransomware used AI agent to automate entire attack BleepingComputer · 17d ago Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email Security Latest · 17d ago let's vibe John Hammond · 17d ago LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud PYMNTS | Fraud Prevention Archives · 17d ago WARNING: AI tracks your face David Bombal · 18d ago NetNut proxy network disrupted, 2 million infected devices cut off BleepingComputer · 18d ago How to scale your patches without scaling your team (the patch wave) Heimdal Security Blog · 18d ago ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit BleepingComputer · 18d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 18d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 18d ago AI didn’t break patching. It showed us patching was already broken. Heimdal Security Blog · 18d ago Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign Securelist · 18d ago EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones Security Latest · 18d ago Someone infected a spyware probe overseer with spyware CyberScoop · 18d ago Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says BleepingComputer · 18d ago Claude Fable relaunch disappoints users with nerfed performance BleepingComputer · 18d ago ClamAV Vulnerabilities Affecting Cisco Products: July 2026 Cisco Security Advisory · 18d ago Fable 5 is back.....run these prompts before July 12th NetworkChuck · 18d ago Newly discovered PamStealer isn't your typical macOS malware Security - Ars Technica · 18d ago FBI Seizes NetNut Proxy Platform, Popa Botnet Krebs on Security · 18d ago It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs Technical Information Security Content & Discussion · 19d ago FIFA was saved this time Technical Information Security Content & Discussion · 19d ago Alleged longstanding member of Scattered Spider extradited to US CyberScoop · 19d ago Google loses final appeal to overturn €4.1 billion EU fine BleepingComputer · 19d ago Celebrating 1 Million Subscribers on July 8th! The Cyber Mentors · 19d ago ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds BleepingComputer · 19d ago Microsoft fixes bug that removed Copilot buttons in Outlook BleepingComputer · 19d ago Cisco finally confirms attackers exploiting Unified CM flaw BleepingComputer · 19d ago CISA: Microsoft SharePoint RCE flaw now actively exploited BleepingComputer · 19d ago Opera rolls out Paste Protect feature to fight ClickFix attacks BleepingComputer · 19d ago Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects Securelist · 19d ago Alleged Scattered Spider hacker extradited to the United States BleepingComputer · 19d ago 42% of Issuers Say Fraud and Disputes Are Driving Up Costs PYMNTS | Fraud Prevention Archives · 19d ago /r/netsec's Q3 2026 Information Security Hiring Thread Technical Information Security Content & Discussion · 19d ago News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks The Last Watchdog · 19d ago Medtronic notifies customers impacted by ShinyHunters data breach BleepingComputer · 19d ago FortiBleed credential-theft campaign linked to Lynx ransomware BleepingComputer · 19d ago Kubota says hackers had month-long access to network systems BleepingComputer · 19d ago ChocoPoc malware delivered via trojanized exploits on GitHub BleepingComputer · 19d ago New ChocoPoC malware targets researchers via trojanized PoC exploits BleepingComputer · 19d ago Researchers spot exploitation of another critical Oracle defect CyberScoop · 19d ago DHS confirms hackers breached HSIN info-sharing platform BleepingComputer · 20d ago Webinar: Why traditional email security is no longer enough BleepingComputer · 20d ago Hackers target Microsoft 365 accounts with 81 million login attempts BleepingComputer · 20d ago NASA inspector general suggests Boeing's Starliner will now be a decade late Security - Ars Technica · 20d ago Cisco Advance Notification for Publication of July 1, 2026, Security Advisories Cisco Security Advisory · 20d ago New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams Proofpoint News Feed · 20d ago Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability Cisco Security Advisory · 20d ago Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) Technical Information Security Content & Discussion · 20d ago Turning Indicators into Intelligence in OpenCTI with Criminal IP BleepingComputer · 20d ago Beyond Usernames John Hammond · 20d ago US lifting export control restrictions on Anthropic’s Mythos, Fable CyberScoop · 20d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 20d ago Over 900 Oracle E-Business instances exposed to ongoing attacks BleepingComputer · 20d ago Microsoft fixes GIF functionality in the Windows Emoji Panel BleepingComputer · 20d ago The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign Securelist · 20d ago Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival Security Latest · 20d ago This phishing kit looks more like BEC-as-a-service CyberScoop · 20d ago Amazon fined $2.25M for withholding evidence from fraud victims BleepingComputer · 20d ago Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes Heimdal Security Blog · 20d ago Adobe patches seven max severity ColdFusion, Campaign flaws BleepingComputer · 20d ago Anthropic to restore Claude Fable access on Wednesday BleepingComputer · 20d ago Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool Recorded Future · 20d ago Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price BleepingComputer · 20d ago New BioShocking attack manipulates AI browser into data theft BleepingComputer · 20d ago Citrix patches a new NetScaler flaw with echoes of CitrixBleed CyberScoop · 20d ago Microsoft accelerates quantum-safe roadmap as risks grow BleepingComputer · 20d ago Malicious PyPI packages give hackers control of Telegram bot servers BleepingComputer · 20d ago Trump budget boss Russell Vought open to re-staffing CISA CyberScoop · 20d ago New attack provides one more reason why AI browsers are a bad idea Security - Ars Technica · 20d ago Is DEFCON for you? David Bombal · 20d ago CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs Technical Information Security Content & Discussion · 20d ago News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks The Last Watchdog · 21d ago JPMorganChase and Amazon Back Aspen Institute Drive Against Scams PYMNTS | Fraud Prevention Archives · 21d ago News alert: OpenMatter launches platform to verify AI activity across enterprise systems The Last Watchdog · 21d ago Fake Perplexity extension on Chrome Web Store tracked searches BleepingComputer · 21d ago Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint News Feed · 21d ago DHS to unveil replacement council for critical infrastructure cybersecurity CyberScoop · 21d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 21d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 21d ago Lessons from the Underground: How to Combat Business Email Compromise BleepingComputer · 21d ago Insurance giant Aflac discloses data breach after subsidiary hack BleepingComputer · 21d ago Mircosoft adds smarter bot protection to Teams meetings BleepingComputer · 21d ago Microsoft adds smarter bot protection to Teams meetings BleepingComputer · 21d ago Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass) Technical Information Security Content & Discussion · 21d ago Kali Linux 2026.2 released with 9 new tools, NetHunter updates BleepingComputer · 21d ago Blackfield ransomware asks Nidec Corporation for $2 million ransom BleepingComputer · 21d ago How ransomware syndicates weaponize corporate-style organization CyberScoop · 21d ago CISA: Windows BlueHammer flaw now exploited by ransomware gangs BleepingComputer · 21d ago US offers $10 million for info on group behind Signal and WhatsApp hacking spree Security - Ars Technica · 21d ago Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs Security Latest · 21d ago Warner bill would create federally vetted list for secure, trustworthy AI agents CyberScoop · 21d ago Nissan discloses employee data breach linked to Oracle zero-day attacks BleepingComputer · 21d ago NAIC says public data stolen in ShinyHunters' PeopleSoft breach BleepingComputer · 21d ago Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs Technical Information Security Content & Discussion · 21d ago WhatsApp rolls out usernames to help users hide their phone number BleepingComputer · 22d ago Supreme Court approves mail-in ballots that arrive after Election Day CyberScoop · 22d ago Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling CyberScoop · 22d ago Microsoft extends Windows Server 2022 hotpatching until October 2027 BleepingComputer · 22d ago U.S. offers $10 million for hackers targeting WhatsApp, Signal users BleepingComputer · 22d ago Agentic AI Has an Identity Problem and Attackers Know It BleepingComputer · 22d ago Critical SimpleHelp flaw exploited to deploy new stealer malware BleepingComputer · 22d ago Hackers now exploit critical Oracle E-Business flaw in attacks BleepingComputer · 22d ago Webinar: Why business email compromise attacks keep succeeding BleepingComputer · 22d ago US seizes hundreds of FIFA World Cup illegal streaming domains BleepingComputer · 22d ago Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change Security Latest · 22d ago What the post-quantum executive order really demands of CISOs CyberScoop · 22d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 22d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 22d ago World Cup Gives Cross-Border Payments Their Super Bowl Moment PYMNTS | Fraud Prevention Archives · 22d ago TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry Trend Micro Research, News, Perspectives · 22d ago Data breach exposes up to 14.2 million email logins at six ISPs BleepingComputer · 23d ago 2026 home lab setup to test malicious links safely for FREE (step by step) David Bombal · 23d ago I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well. Technical Information Security Content & Discussion · 23d ago Dissecting Apple's Sparse Image Format (ASIF) Technical Information Security Content & Discussion · 23d ago A peek into Reddit's anti-spam internals Technical Information Security Content & Discussion · 24d ago HackTheBox - WingData IppSec · 24d ago Clean GitHub repo tricks AI coding agents into running malware BleepingComputer · 24d ago FBI: Russian hackers now target Signal backup recovery keys BleepingComputer · 24d ago CISA sets urgent deadline to fix Cisco flaw exploited in attacks BleepingComputer · 24d ago ATF cancels controversial commercial geolocation contract CyberScoop · 24d ago Polymarket customers lose $3 million in supply-chain attack BleepingComputer · 25d ago Cybersecurity firms targeted by fraudulent OpenAI organization invites BleepingComputer · 25d ago Banks Face a New ACH Fraud Test as Nacha Rules Take Effect PYMNTS | Fraud Prevention Archives · 25d ago Real Folks of Cyber | Pearce Barry | Day in the Life The Cyber Mentors · 25d ago How Dynamic Defense shuts an attacker out without shutting down the business Heimdal Security Blog · 25d ago Your First GRC Agent: A Red Teamer's Walkthrough BleepingComputer · 25d ago Which is Ethernet? What's the difference? David Bombal · 25d ago Name That Toon Contest darkreading · 25d ago Static security has run out of road. The case for Dynamic Defense Heimdal Security Blog · 25d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 25d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 25d ago Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges PYMNTS | Fraud Prevention Archives · 25d ago Anthropic is testing desktop-like Claude Cowork for mobile BleepingComputer · 25d ago Poland busts SIM-swapping gang tied to millions in crypto theft BleepingComputer · 25d ago Getting Started with the TCM Security Academy The Cyber Mentors · 25d ago FCC passes new cybersecurity rules for emergency systems, undersea cables CyberScoop · 25d ago Order-tracking app Shop abused to push callback phishing attacks BleepingComputer · 25d ago Microsoft quietly extends free Windows 10 ESU support to October 2027 BleepingComputer · 26d ago New macOS malware embeds fake errors to confuse AI analysis tools BleepingComputer · 26d ago Federal court rules Trump election-focused executive order illegal CyberScoop · 26d ago PirloTV sports piracy network disrupted as 44 domains seized BleepingComputer · 26d ago CVE-2025-52465 geoserver arbitrary file write vulnerability Technical Information Security Content & Discussion · 26d ago Bluekit phishing kit adopts browser-in-the-middle for login theft BleepingComputer · 26d ago Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract CyberScoop · 26d ago Cisco Finesse Remote File Inclusion Vulnerability Cisco Security Advisory · 26d ago Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack CyberScoop · 26d ago The Four Elevations of Effective Fraud Prevention BleepingComputer · 26d ago Copilot in Excel: Built for the era of Frontier Finance Microsoft 365 Blog · 26d ago Webinar: Why account takeovers remain one of the hardest threats to stop BleepingComputer · 26d ago CargoWise WebTracker - The keys were in the cargo Technical Information Security Content & Discussion · 26d ago Europe Evolves Into Ransomware's Favorite Region darkreading · 26d ago Why patch directives only go so far CyberScoop · 26d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 26d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 26d ago AI Forces Compliance Teams to Rethink Alert Strategy PYMNTS | Fraud Prevention Archives · 26d ago Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge Recorded Future · 26d ago Evaluating Mexico’s New Cybersecurity Plan Recorded Future · 26d ago Google releases new privacy controls for activity history, personalization BleepingComputer · 26d ago DraftKings hacker 'Snoopy' sentenced to 18 months in prison BleepingComputer · 26d ago Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access BleepingComputer · 26d ago Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure darkreading · 26d ago One-two punch delivered in global operation disrupts cybercrime "assembly line" Security - Ars Technica · 26d ago Malicious Edge extension abuses Native Messaging as bridge to malware BleepingComputer · 26d ago 2026 FIFA World Cup Faces Surge in Cyber Threats darkreading · 26d ago Europe’s 800 Exaflop SUPERCOMPUTERS David Bombal · 26d ago Do CISOs Need a Code of Ethics? darkreading · 26d ago Malicious hackers exploit Cisco zero-day for highest access level at communications service provider CyberScoop · 27d ago More Malicious OpenClaw Skills Threaten AI Supply Chain darkreading · 27d ago Exploiting vulnerabilities in Johnson & Johnson web apps Technical Information Security Content & Discussion · 27d ago CISA warns of max severity Ubiquiti flaws exploited in attacks BleepingComputer · 27d ago Amadey, StealC malware operations disrupted in Operation Endgame action BleepingComputer · 27d ago Securing the service desk: Why social engineering attacks keep succeeding BleepingComputer · 27d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 27d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 27d ago In a first, a court takedown goes after two cybercrime tools at once CyberScoop · 27d ago Apple's MacOS Gap Lets Users Disable Security Tools darkreading · 27d ago Breaking the MSP Echo Chamber: The Power of Community Heimdal Security Blog · 27d ago Stealthy Mistic backdoor linked to ransomware access broker KongTuke BleepingComputer · 27d ago Open-source security is posing challenges governments can’t easily solve CyberScoop · 27d ago New at Forter: AI Agents Built to Amplify Your Team Blog – Forter · 27d ago FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems Recorded Future · 27d ago White House drastically shortens deadline for dropping quantum-vulnerable crypto Security - Ars Technica · 27d ago Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks BleepingComputer · 27d ago Tata Electronics confirms cyberattack as hackers leak data BleepingComputer · 27d ago Scope of Salesforce Attacks Expands as Icarus Leaks Data darkreading · 27d ago Windows 11 KB5095093 update rolls out new Point-in-Time restore feature BleepingComputer · 27d ago Healthtech firm Xolis suffers data breach impacting 1.4 million people BleepingComputer · 27d ago 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows darkreading · 27d ago Justice Department seizes infrastructure used by cyber scam and criminal marketplace CyberScoop · 28d ago New macOS ClickFix attack silently mounts DMGs to push infostealer BleepingComputer · 28d ago Scattered Spider Hackers Plead Guilty on Day 1 of Trial Krebs on Security · 28d ago Scattered Spider members plead guilty to hacking Transport for London BleepingComputer · 28d ago Algerian man charged with running two cybercrime marketplaces CyberScoop · 28d ago The Exploit Doesn't Exist. You Can Still Prove It Works Against You BleepingComputer · 28d ago LastPass confirms data breach in Klue supply chain attack BleepingComputer · 28d ago SocGholish Takedown Highlights Malicious TDS Threats darkreading · 28d ago Can AI Agents Find, Trust, and Choose Your Brand? Blog – Forter · 28d ago FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist darkreading · 28d ago Webinar: Why email security teams are drowning in alerts BleepingComputer · 28d ago Cloudflare patches Copy-Fail across every server in two days Technical Information Security Content & Discussion · 28d ago New Cisco RCE was fixed Technical Information Security Content & Discussion · 28d ago The Purchase Scam Tactic Headed for the World Cup | Recorded Future Recorded Future · 28d ago From Langflow to Monero: Inside CVE-2026-33017 Cryptominer Trend Micro Research, News, Perspectives · 28d ago WhatsApp phishing attack uses fake business docs to hack PCs BleepingComputer · 28d ago Court rules SAVE database illegal, orders it dismantled CyberScoop · 28d ago JaredFromSubway MEV bot hacked in $15 million crypto theft BleepingComputer · 28d ago DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories darkreading · 28d ago FFmpeg fixes PixelSmash flaw in widely used video decoder BleepingComputer · 28d ago FortiBleed campaign used custom FortiGate sniffer to steal credentials BleepingComputer · 28d ago They Created a Supercomputer in a Rack? David Bombal · 28d ago Trump executive orders speed up post-quantum migration, boost industry CyberScoop · 28d ago Following user outcry, AMD reinstates memory encryption in consumer CPUs Security - Ars Technica · 28d ago CVE-2026-25860 turn XSS to RCE Technical Information Security Content & Discussion · 29d ago Microsoft says Windows 11 26H2 is coming soon, details upgrade process BleepingComputer · 29d ago Microsoft fixes AutoGen Studio flaw that enabled code execution BleepingComputer · 29d ago Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign darkreading · 29d ago Intel agencies: Frontier AI models will reshape cybersecurity faster than expected CyberScoop · 29d ago Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities Cisco Security Advisory · 29d ago How attackers built a RAT on a Windows machine using its own .NET compiler Heimdal Security Blog · 29d ago He Thought He Was Secure; His Phone Number Was Stolen Anyway darkreading · 29d ago A Glimpse into the “Search Your Target” Market for Stolen Credentials BleepingComputer · 29d ago Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire Hak5 · 29d ago This Hacker Got Paid $50,000+ to Break Frontier AI Models NahamSec · 29d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 29d ago Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense Proofpoint News Feed · 29d ago OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses Proofpoint News Feed · 29d ago Attacker enables RDP, creates admin, erases evidence in ten seconds Heimdal Security Blog · 29d ago Exploiting Auth0 Defaults in XSS Attacks - elttam Technical Information Security Content & Discussion · 29d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 29d ago Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1) Technical Information Security Content & Discussion · 30d ago AryStinger botnet infected thousands of D-Link routers worldwide BleepingComputer · 30d ago Build a Complete Free CCNA Home Lab in 2026 With No Gear David Bombal · 30d ago Broken access control demo David Bombal · 30d ago New Prinz Eugen ransomware prioritizes recent files for encryption BleepingComputer · 31d ago HackTheBox - Nanocorp IppSec · 31d ago Microsoft links Mastra AI supply chain attack to North Korean hackers BleepingComputer · 31d ago Klue OAuth breach victim list grows as Icarus hackers claim attack BleepingComputer · 31d ago shadow AI is terrifying NetworkChuck · 31d ago Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin BleepingComputer · 31d ago Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 Technical Information Security Content & Discussion · 31d ago Texas govt data breach exposes over 3 million driver’s licenses BleepingComputer · 32d ago Soft Skills for the Job Market: Resume Writing The Cyber Mentors · 32d ago Will this replace PoE (Power over Ethernet)? David Bombal · 32d ago OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099) Technical Information Security Content & Discussion · 32d ago Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way BleepingComputer · 32d ago Stressors, AI Forcing Changes to Cybersecurity Teams darkreading · 32d ago Webinar: How attackers bypass MFA and how defenders can respond BleepingComputer · 32d ago Microsoft: June 2026 Windows updates break Recycle Bin prompts BleepingComputer · 32d ago CISA: Splunk Enterprise flaw actively exploited, patch by Sunday BleepingComputer · 32d ago Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration Technical Information Security Content & Discussion · 32d ago NY man charged after harassing college student with AI-generated nudes BleepingComputer · 32d ago CISA warns Fortinet users to secure devices after FortiBleed leak BleepingComputer · 32d ago Microsoft discovers new lightweight backdoor that steals cryptocurrency Security - Ars Technica · 32d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 32d ago Gentlemen ransomware uses multiple EDR killers to disable defenses BleepingComputer · 32d ago Authorities disrupt Evil Corp’s SocGholish botnet CyberScoop · 32d ago Congress tees up No FAKES Act, aiming at AI-generated deepfakes CyberScoop · 32d ago Novo Nordisk Breach Highlights Software Development Pipeline Risk darkreading · 32d ago Apple patches high-severity eavesdropping vulnerability in Beats Studio Buds Security - Ars Technica · 32d ago HTTPS Doesn't Hide This From Your ISP!! NetworkChuck · 32d ago Operation Escaneo Signals Shift in LatAm Threat Landscape darkreading · 33d ago Nintendo confirms data stolen in WebMD subsidiary cyberattack BleepingComputer · 33d ago FIFA Bug Exposes World Cup Streams to Remote Takeover darkreading · 33d ago CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance Technical Information Security Content & Discussion · 33d ago ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm Krebs on Security · 33d ago Salesforce Data Thefts Continue via Klue App Compromise darkreading · 33d ago USB worm spreads crypto-stealing malware via Windows shortcut files BleepingComputer · 33d ago Cisco Just Showed the Future of Networking NetworkChuck · 33d ago How software development’s speed obsession enabled TeamPCP’s chaos crusade CyberScoop · 33d ago Accenture shells out $4.18B on three companies in big industrial cybersecurity push CyberScoop · 33d ago Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks BleepingComputer · 33d ago 5 reasons Microsoft 365 backup isn’t enough for business data protection BleepingComputer · 33d ago Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp BleepingComputer · 33d ago Get Out of Security Debt by Tackling the Exposure Problem darkreading · 33d ago ShapedPlugin update flow hacked to infect WordPress sites BleepingComputer · 33d ago Apple fixes Beats Studio Buds flaw that let hackers spy on conversations BleepingComputer · 33d ago Telegram admits it couldn't police exam-leak channels, India tells court BleepingComputer · 33d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 33d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure Alerts · 33d ago Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT All CISA Advisories · 33d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 33d ago Schneider Electric EasyLogic T150 and Saitel DP All CISA Advisories · 33d ago AVer PTC cameras All CISA Advisories · 33d ago Rockwell Automation FactoryTalk Historian Site Edition All CISA Advisories · 33d ago AzeoTech DAQFactory All CISA Advisories · 33d ago Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products All CISA Advisories · 33d ago Mitsubishi Electric MELSEC iQ-F Series All CISA Advisories · 33d ago Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module All CISA Advisories · 33d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure All CISA Advisories · 33d ago F5 issues out-of-band patches for critical NGINX vulnerabilities BleepingComputer · 33d ago Would you like some malware served at the very top of DuckDuckGo? Technical Information Security Content & Discussion · 33d ago Microsoft fixes Windows Server 2016 security update failures BleepingComputer · 33d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 33d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 33d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 33d ago EU Gets a Head Start in Developing 6G Network Security darkreading · 33d ago Leak confirms OpenAI is testing a ChatGPT for Science subscription BleepingComputer · 33d ago PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM Trend Micro Research, News, Perspectives · 33d ago Google to use UK and EU user IP addresses for ad personalization BleepingComputer · 33d ago Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update Technical Information Security Content & Discussion · 33d ago Massive breach spills credentials for thousands of sensitive networks Security - Ars Technica · 33d ago This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity NahamSec · 34d ago News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies The Last Watchdog · 34d ago News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk The Last Watchdog · 34d ago Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability Cisco Security Advisory · 34d ago Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability Cisco Security Advisory · 34d ago Cisco Webex App Open Redirect Vulnerability Cisco Security Advisory · 34d ago Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April CyberScoop · 34d ago FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. BleepingComputer · 34d ago Why Account Takeovers Are Rising and How to Stop Them BleepingComputer · 34d ago India's Telegram ban hit the UAE too. Here's how to get around it BleepingComputer · 34d ago Microsoft confirms Office apps launch issues after June updates BleepingComputer · 34d ago CISA orders feds to patch max severity Joomla plugin flaw by Friday BleepingComputer · 34d ago QoS Policies to Restrict EDR Traffic and Detection Strategies Technical Information Security Content & Discussion · 34d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 34d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 34d ago Microsoft working on Defender patch for RoguePlanet zero-day BleepingComputer · 34d ago Kodak confirms data breach claimed by ShinyHunters extortion gang BleepingComputer · 34d ago Getting a CVE Without Shipping Slop Technical Information Security Content & Discussion · 34d ago PrizeBuzz phishing network analysis Technical Information Security Content & Discussion · 34d ago State Digital Surveillance Risk Landscape Recorded Future · 34d ago Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Trend Micro Research, News, Perspectives · 34d ago Shark Jacked my LAN 🦈 Hak5 · 34d ago Malicious JetBrains Marketplace plugins steal AI API keys from developers BleepingComputer · 34d ago Lawmakers leery about Trump administration’s Anthropic order CyberScoop · 34d ago News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails The Last Watchdog · 34d ago AI’s constant patching treadmill can be a security problem CyberScoop · 34d ago 27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass Technical Information Security Content & Discussion · 34d ago New Rokarolla Android malware targets 217 banking, crypto apps BleepingComputer · 34d ago News alert: GitGuardian adds endpoint protection as developer laptops become credential troves The Last Watchdog · 34d ago Steam Workshop abused to spread malware via Wallpaper Engine app BleepingComputer · 35d ago Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability Cisco Security Advisory · 35d ago Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability Cisco Security Advisory · 35d ago TCM Security Summer Sale is Here! The Cyber Mentors · 35d ago A case for how to shape ‘ingredient lists’ for AI models CyberScoop · 35d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 35d ago Copilot Cowork is now generally available Microsoft 365 Blog · 35d ago UK to require ID or face scan before you can make social media accounts BleepingComputer · 35d ago GhostTree Attack Abused Recursive Windows Junctions to Hide Malware BleepingComputer · 35d ago FTC warns of record $3.5 billion losses to imposter scams in 2025 BleepingComputer · 35d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 35d ago Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP All CISA Advisories · 35d ago Rockwell Automation RSLinx All CISA Advisories · 35d ago Rockwell Automation FLEX I/O EtherNet/IP Adapters All CISA Advisories · 35d ago Rockwell Automation FactoryTalk Analytics PavilionX All CISA Advisories · 35d ago Rockwell Automation CompactLogix All CISA Advisories · 35d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 35d ago CISA warns of another cPanel plugin flaw exploited in attacks BleepingComputer · 35d ago News alert: Varist announces AI-scale malware detection for healthcare and medical imaging The Last Watchdog · 35d ago Ransomware gang abuses Microsoft Teams relays to hide malicious traffic BleepingComputer · 35d ago Critical Fortinet FortiSandbox flaws now exploited in attacks BleepingComputer · 35d ago Windows version of SprySOCKS Linux malware used to attack govt orgs BleepingComputer · 35d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 35d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 35d ago The State of AI Risk Management in 2026 Heimdal Security Blog · 35d ago iRhythm discloses data breach, says hackers stole patient info BleepingComputer · 35d ago The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine Recorded Future · 35d ago Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability Cisco Security Advisory · 35d ago DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act BleepingComputer · 35d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 35d ago Google exposes China espionage group that’s been lurking in networks undetected since 2023 CyberScoop · 35d ago SimpleHelp bug lets hackers create rogue remote support accounts BleepingComputer · 35d ago Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE Technical Information Security Content & Discussion · 36d ago OptinMonster WordPress plugin hacked in CDN supply-chain attack BleepingComputer · 36d ago Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks BleepingComputer · 36d ago I was wrong about VPNs NetworkChuck · 36d ago Council of Europe investigates ShinyHunters data breach claims BleepingComputer · 36d ago Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat CyberScoop · 36d ago FBI: Fraudsters use couriers to steal money in crypto scams BleepingComputer · 36d ago Vibe coders are gonna vibe code: How CISOs are tackling code sprawl BleepingComputer · 36d ago Chinese hackers breach REDCap servers, steal medical research BleepingComputer · 36d ago SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon Technical Information Security Content & Discussion · 36d ago New attack turned Microsoft 365 Copilot into 1-click data theft tool BleepingComputer · 36d ago Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It Heimdal Security Blog · 36d ago Infinite Campus data breach affects 137,000 school staff accounts BleepingComputer · 36d ago How I Made $30,000 Hacking Broken Access Control NahamSec · 36d ago $30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover NahamSec · 36d ago Webinar: How behavioral AI stops phishing and account takeovers BleepingComputer · 36d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 36d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 36d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 36d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 36d ago FBI disrupts massive AI-powered phishing service using a million URLs BleepingComputer · 37d ago Researcher accidentally gained access to a threat actor-controlled phishing website Technical Information Security Content & Discussion · 37d ago PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs Technical Information Security Content & Discussion · 37d ago Ex-school district employee jailed for hacks on former employer BleepingComputer · 37d ago MeshCentral: From XSS to RCE Technical Information Security Content & Discussion · 37d ago Anthropic disables new models after government calls them a national security concern CyberScoop · 38d ago HackTheBox - VariaType IppSec · 38d ago Chinese hackers hijack auth flow, spy on isolated network for a decade BleepingComputer · 38d ago US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos BleepingComputer · 38d ago Getting the PID from random numbers in PHP Technical Information Security Content & Discussion · 38d ago The Axios npm compromise was visible in registry metadata before anyone ran npm install Technical Information Security Content & Discussion · 38d ago FBI takes down massive China-based cybercrime network that caused $1.9B in losses CyberScoop · 38d ago Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs Technical Information Security Content & Discussion · 38d ago ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed darkreading · 38d ago Maine disables data breach notification portal after fake disclosures BleepingComputer · 38d ago US, France, and Italian authorities shut down massive deepfake porn site CyberScoop · 39d ago phpBB forum fixes auth bypass bug lurking for a decade BleepingComputer · 39d ago Ukrainian national pleads guilty to role in Conti ransomware operation BleepingComputer · 39d ago Conti ransomware group member pleads guilty, faces up to 20 years in prison CyberScoop · 39d ago Over 400 Arch Linux packages compromised to push rootkit, infostealer BleepingComputer · 39d ago ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw CyberScoop · 39d ago Free Compromise Detection for GitHub Repos - Tracebit Community Edition Technical Information Security Content & Discussion · 39d ago Your Next Insider Threat May Be an AI Coworker Heimdal Security Blog · 39d ago Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE) Technical Information Security Content & Discussion · 39d ago Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery Technical Information Security Content & Discussion · 39d ago Early Warning Signs of Supply-Chain Attacks Live in the Dark Web BleepingComputer · 39d ago Claude Fable 5 Doesn't Change the Mythos Security Story darkreading · 39d ago The OSI Model and Its Two Missing Layers Heimdal Security Blog · 39d ago Developers React to the 105-Second Github Chain Reaction | Threat Wire Hak5 · 39d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 39d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 39d ago CyberCorps is adapting to AI. The budget isn’t keeping up. CyberScoop · 39d ago Microsoft fixes Windows update failures linked to WUSA installer BleepingComputer · 39d ago Pharma giant Novo Nordisk discloses breach of clinical trials data BleepingComputer · 39d ago CISA orders feds to patch actively exploited Ivanti flaw by Sunday BleepingComputer · 39d ago Over 73,000 French govt employees affected in Tchap messenger breach BleepingComputer · 39d ago Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs Technical Information Security Content & Discussion · 39d ago Phishing Attack Volume Down 20%, But Risk Still Rising darkreading · 39d ago Governing Claude Enterprise in Environments Where Inline Controls Can't Go Trend Micro Research, News, Perspectives · 39d ago Japanese energy firm loses drive with data of 10.9 million clients BleepingComputer · 39d ago Maine breach portal abused to publish fake data breach disclosures BleepingComputer · 39d ago Oracle mitigates PeopleSoft zero-day exploited in data theft attacks BleepingComputer · 39d ago Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules Technical Information Security Content & Discussion · 40d ago Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure darkreading · 40d ago Any solutions we can use? cybersecurity · 40d ago Russian national charged in connection with Void Blizzard espionage campaign CyberScoop · 40d ago DIY pwnagotchi-like device on esp32 hacking: security in practice · 40d ago Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it Reverse Engineering · 40d ago Possible targeted attack cybersecurity · 40d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline cybersecurity · 40d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 40d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 40d ago Facebook messenger to text cybersecurity · 40d ago Claude Fable 5: mid-tier results on coding tasks Technical Information Security Content & Discussion · 40d ago Authorities dismantle 'AudiA6' ransomware crypto-laundering service BleepingComputer · 40d ago US charges suspected Russian hacker with facilitating cyber campaign For [Blue|Purple] Teams in Cyber Defence · 40d ago Flipper Blackhat + Bjorn hacking: security in practice · 40d ago Segmentation Works for OT If Operators Are Paying Attention darkreading · 40d ago Managing Solution Agents cybersecurity · 40d ago Nottingham University data breach affects over 450,000 students cybersecurity · 40d ago SWGs that support 3rd party external DNS resolver cybersecurity · 40d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers cybersecurity · 40d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game Reverse Engineering · 40d ago Why AI-driven threats are exposing the limits of MSP security stacks BleepingComputer · 40d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG cybersecurity · 40d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia For [Blue|Purple] Teams in Cyber Defence · 40d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch cybersecurity · 40d ago Do you think AI is making hacking easier or harder hacking: security in practice · 40d ago Coupang hit with record $409 million data breach fine in Korea BleepingComputer · 40d ago CISA tells govt agencies to patch critical exploited flaws in 3 days BleepingComputer · 40d ago Phishing awareness training resulting in ignoring company comms? cybersecurity · 40d ago How are you analyzing Android malware nowadays? cybersecurity · 40d ago Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work Technical Information Security Content & Discussion · 40d ago Hackers Exploit Langflow Vulnerability for Remote Code Execution cybersecurity · 40d ago Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research cybersecurity · 40d ago NEED SOME GUIDANCE cybersecurity · 40d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 40d ago Yarbo Android/iOS Mobile Application and Cloud Infrastructure All CISA Advisories · 40d ago Naxclow IoT Platform All CISA Advisories · 40d ago Brickcom Cameras All CISA Advisories · 40d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 40d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Malware Analysis & Reports · 40d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Reverse Engineering · 40d ago What can i do left? PSN hacking: security in practice · 40d ago Help setting up local encryption on my pc cybersecurity · 40d ago Hacking Google with A.I. for $500,000 Technical Information Security Content & Discussion · 40d ago Agentic AI on Cybersecurity cybersecurity · 40d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 40d ago DoD 0-days Typically Come Down to Authorization Failures cybersecurity · 40d ago HDD cybersecurity · 40d ago Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets cybersecurity · 40d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 40d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 40d ago Microsoft fixes BitLocker recovery bug on Windows Server 2025 BleepingComputer · 40d ago Prompt injection: attacking the analyst's AI Technical Information Security Content & Discussion · 40d ago How can we test the firmware code/images security? cybersecurity · 40d ago 20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004 cybersecurity · 40d ago Proxmark5 campaign ending in less than 18 hours. hacking: security in practice · 40d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 For [Blue|Purple] Teams in Cyber Defence · 40d ago GreatXML: GreatXML bitlocker bypass vulnerability For [Blue|Purple] Teams in Cyber Defence · 40d ago GitHub announces npm security changes to tackle supply-chain attacks cybersecurity · 40d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan For [Blue|Purple] Teams in Cyber Defence · 40d ago The ‘Miasma’ worm source code briefly leaked on GitHub cybersecurity · 40d ago CISA Rewrites Federal Patching Requirements for AI Threat Era cybersecurity · 40d ago What is the difference between Regular TLS and Mutual TLS? cybersecurity · 40d ago Every employee's password was stored in a single Excel file cybersecurity · 40d ago Nottingham University data breach affects over 450,000 students BleepingComputer · 40d ago npm v12 is changing how dependencies are installed to reduce supply-chain risk cybersecurity · 40d ago Max severity Ivanti Sentry vulnerability now exploited in attacks BleepingComputer · 40d ago How to bypass speed queen coin slot for washer and dryer hacking: security in practice · 40d ago LIVE: 🕵️ CTF Prize Draw | Cybersecurity The Cyber Mentors · 40d ago Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia? cybersecurity · 40d ago Drive Firmware Security - Phison S11 Reverse Engineering · 40d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue For [Blue|Purple] Teams in Cyber Defence · 40d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion For [Blue|Purple] Teams in Cyber Defence · 40d ago How good Microsoft Defender for storage? cybersecurity · 40d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default For [Blue|Purple] Teams in Cyber Defence · 40d ago GreatXML bitlocker bypass vulnerability cybersecurity · 40d ago Struggle cybersecurity · 40d ago Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications? cybersecurity · 40d ago Chinese, N. Korean Threat Groups Build on Asia-Pacific Success darkreading · 40d ago Recorded Future Launches Impact and Metrics Dashboard Recorded Future · 40d ago Cyber-Enabled Maritime Sanctions Evasion Recorded Future · 40d ago Wiz launches Cloud Security Job Board cybersecurity · 40d ago Physical Project Ideas cybersecurity · 40d ago How can I get into cybersecurity while studying Information Systems Engineering? cybersecurity · 40d ago Miasma-style supply chain attacks For [Blue|Purple] Teams in Cyber Defence · 40d ago Cloud Security job board cybersecurity · 40d ago Continuous learning cybersecurity · 40d ago Self-hosting stuff for when things get ugly hacking: security in practice · 40d ago Path traversal flaw in AI dev platform Langflow exploited in attacks BleepingComputer · 40d ago CISA Rewrites Federal Patching Requirements for AI Threat Era darkreading · 40d ago Angry bug hunter with Microsoft beef drops new Windows 0-day cybersecurity · 40d ago The ‘Miasma’ worm source code briefly leaked on GitHub BleepingComputer · 40d ago OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers CyberScoop · 40d ago Bug Bounty Research Triggers ServiceNow Security Alert darkreading · 40d ago Mid-30s, stuck in web pentesting, and wondering what to do ? cybersecurity · 40d ago GitHub announces npm security changes to tackle supply-chain attacks BleepingComputer · 40d ago AI Risk Worries Insurers & Businesses Alike darkreading · 40d ago Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM cybersecurity · 40d ago Is Microsoft Purview really secure when using Copilot? cybersecurity · 41d ago Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review Technical Information Security Content & Discussion · 41d ago News alert: Cloud security report finds fragmented tools widening the cloud complexity gap The Last Watchdog · 41d ago Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks BleepingComputer · 41d ago Malware Includes Taboo In Text To Prevent LLM Analysis hacking: security in practice · 41d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet For [Blue|Purple] Teams in Cyber Defence · 41d ago Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature? cybersecurity · 41d ago added Mac support for my corporate hacking game, demo on Steam hacking: security in practice · 41d ago IDA 9.4 Beta | Hex-Rays Docs Reverse Engineering · 41d ago Nee academic references for Hashcat's 'Next Big Bang' log cybersecurity · 41d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs For [Blue|Purple] Teams in Cyber Defence · 41d ago CISA released BOD 26-04: A new federal government vulnerability management strategy? cybersecurity · 41d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace For [Blue|Purple] Teams in Cyber Defence · 41d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days cybersecurity · 41d ago IMPACT Roadshow Recap: Getting Ready for Agentic Commerce Blog – Forter · 41d ago added Mac support to my corporate hacking sim. Demo now available on Steam cybersecurity · 41d ago Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet darkreading · 41d ago CISA directive orders agencies to prioritize vulnerability patching in a new way CyberScoop · 41d ago We post-trained a model for offensive security instead of teaching it to refuse Technical Information Security Content & Discussion · 41d ago Catfished hacking: security in practice · 41d ago Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte) cybersecurity · 41d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper Malware Analysis & Reports · 41d ago China-linked JDY botnet expands targeting of U.S. military networks BleepingComputer · 41d ago Students' data taken in major University of Nottingham cyber-attack cybersecurity · 41d ago Has unmanaged external file sharing ever burned you? cybersecurity · 41d ago The 5 Best Practices for Secure Identity Verification BleepingComputer · 41d ago Who Runs the Ransomware Group ‘The Gentlemen?’ Krebs on Security · 41d ago Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers cybersecurity · 41d ago Microsoft patches Exchange Server zero-day exploited in attacks BleepingComputer · 41d ago Trane Tracer HVAC cybersecurity issues Reverse Engineering · 41d ago Need feedback on my presentation cybersecurity · 41d ago Compensating controls besides admin credentials being needed to download software on employee endpoints cybersecurity · 41d ago OpenSSL PKCS#7 CVE-2026-45447 cybersecurity · 41d ago Testing offensive AI agents in a cloud lab with deception tech For [Blue|Purple] Teams in Cyber Defence · 41d ago Presentation Question cybersecurity · 41d ago What did they mean by this? One of us? hacking: security in practice · 41d ago How to Stay Ahead of Deepfake Evolution in 2026 cybersecurity · 41d ago How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026 Technical Information Security Content & Discussion · 41d ago FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster Technical Information Security Content & Discussion · 41d ago Microsoft: Some Windows PCs fail to install latest monthly updates BleepingComputer · 41d ago France’s Government Messaging App Tchap Got Breached cybersecurity · 41d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days BleepingComputer · 41d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap Malware Analysis & Reports · 41d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 41d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 41d ago certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA" Technical Information Security Content & Discussion · 41d ago Where's the fix for MiniPlasma? cybersecurity · 41d ago BlackSun - Defender for Endpoint on macOS Technical Information Security Content & Discussion · 41d ago ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances cybersecurity · 41d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges hacking: security in practice · 41d ago GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline) Technical Information Security Content & Discussion · 41d ago Internships cybersecurity · 41d ago Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS cybersecurity · 41d ago Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows cybersecurity · 41d ago Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam Technical Information Security Content & Discussion · 41d ago Ivanti: Max severity Sentry flaw allows code execution as root BleepingComputer · 41d ago Looking for a Reliable Cybersecurity Provider for a School in North Sydney cybersecurity · 41d ago Early Operational Visibility cybersecurity · 41d ago Benchmarking n-day exploit generation [via AI] For [Blue|Purple] Teams in Cyber Defence · 41d ago how are you actually managing ai agents in production? cybersecurity · 41d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) Reverse Engineering · 41d ago Al app builders: How are you handling security questionnaires when selling your product? cybersecurity · 41d ago [ Removed by Reddit ] cybersecurity · 41d ago How are all of doing with THE AI model thats big news currently?? cybersecurity · 41d ago Whoops! I did it again. I patched Windows Kernel at Milan0day 2026 For [Blue|Purple] Teams in Cyber Defence · 41d ago Microsoft Defender now monitors RPC activity For [Blue|Purple] Teams in Cyber Defence · 41d ago Skill to Scan your Codebase cybersecurity · 41d ago RoguePlanet: RoguePlanet Windows Defender Vulnerability For [Blue|Purple] Teams in Cyber Defence · 41d ago Miasma-style supply chain attacks cybersecurity · 41d ago FCaptcha v1.12: Catching AI Agents That Drive Real Browsers cybersecurity · 41d ago Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones cybersecurity · 41d ago Anthropic rolls out Claude Fable 5, but it's available for a limited time BleepingComputer · 41d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs cybersecurity · 41d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs Technical Information Security Content & Discussion · 41d ago AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say cybersecurity · 41d ago 2026 FIFA World Cup: What Public Safety Officials Need to Know Recorded Future · 41d ago China's Noncombatant Evacuation Operations: 2005–2025 Recorded Future · 41d ago GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 Trend Micro Research, News, Perspectives · 41d ago Huntress Stack (MS Defender or SentinelOne) cybersecurity · 41d ago META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT cybersecurity · 41d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges BleepingComputer · 41d ago OptOutCode – A Privacy4Cars Universal Opt-Out Concept hacking: security in practice · 41d ago I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in) For [Blue|Purple] Teams in Cyber Defence · 41d ago A Record-Breaking Patch Tuesday for June 2026 Krebs on Security · 41d ago The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life darkreading · 41d ago FBI is announcing Operation Riptide cybersecurity · 41d ago Blame AI: Patch Tuesday Hits Record 206 CVEs darkreading · 41d ago ServiceNow confirmed some customer instances were breached. cybersecurity · 41d ago ServiceNow discloses security incident exposing customer data BleepingComputer · 41d ago Which are some of the best Cybersecurity / OT Security events that happen in GCC? cybersecurity · 41d ago OpenClaw AI agent found falling for phishing attacks, spills user data BleepingComputer · 41d ago DF/IR Community cybersecurity · 41d ago Chaotic Eclipse's new RoguePlanet cybersecurity · 41d ago Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address darkreading · 41d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace cybersecurity · 41d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace Malware Analysis & Reports · 41d ago Microsoft breaks Patch Tuesday record with 206 vulnerabilities CyberScoop · 41d ago Thoughts on Automated Compliance? cybersecurity · 41d ago SAP fixes critical flaws in NetWeaver and Commerce Cloud BleepingComputer · 41d ago Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories darkreading · 41d ago A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available cybersecurity · 41d ago Apple’s Siri-AI, or more shouting into the void about “private” agents Technical Information Security Content & Discussion · 42d ago How do you make learning blue team security entertaining ? For [Blue|Purple] Teams in Cyber Defence · 42d ago North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says cybersecurity · 42d ago Microsoft has released a patch for the bitlocker bypass cybersecurity · 42d ago Microsoft releases Windows 10 KB5094127 extended security update BleepingComputer · 42d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. Reverse Engineering · 42d ago Please advices cybersecurity · 42d ago Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws BleepingComputer · 42d ago Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws BleepingComputer · 42d ago soc analyst l1 cybersecurity · 42d ago Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow cybersecurity · 42d ago Looking to move off KnowBe4, what are people actually using these days? cybersecurity · 42d ago Maximizing IOC Impact For [Blue|Purple] Teams in Cyber Defence · 42d ago Windows 11 KB5094126 & KB5093998 cumulative updates released BleepingComputer · 42d ago Too Many Certs, Not Enough Experience — What’s the Best Next Step? cybersecurity · 42d ago Anthropic’s new model is Mythos on a leash CyberScoop · 42d ago Authenticating ARP and NDP cybersecurity · 42d ago Does anyone use rule feeds in 2026? cybersecurity · 42d ago [2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution For [Blue|Purple] Teams in Cyber Defence · 42d ago CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector CyberScoop · 42d ago Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations! cybersecurity · 42d ago Need a vm for practice cybersecurity · 42d ago XBOW tests Anthropic's Mythos Preview for offensive security BleepingComputer · 42d ago Tips/Tricks to WFH as a SOC Analyst? cybersecurity · 42d ago Cybersecurity statistics of the week (June 1st - June 7th) cybersecurity · 42d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks For [Blue|Purple] Teams in Cyber Defence · 42d ago Where can GRC folks learn practical AppSec / DevSecOps without going full engineer? cybersecurity · 42d ago GitHub disables Microsoft repos pushing password-stealing malware BleepingComputer · 42d ago Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs darkreading · 42d ago I almost got “onboarded” into a malware campaign disguised as a job opportunity. cybersecurity · 42d ago Suspected North Korean actors use fake ‘coding assignments’ to steal crypto Proofpoint News Feed · 42d ago University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model cybersecurity · 42d ago AI Blocklist - help cybersecurity · 42d ago New Veeam vulnerability exposes backup servers to RCE attacks BleepingComputer · 42d ago Entra Agent ID from a Security Perspective For [Blue|Purple] Teams in Cyber Defence · 42d ago Cisco customers encounter another SD-WAN zero-day under attack CyberScoop · 42d ago Entra Agent ID from a Security Perspective Technical Information Security Content & Discussion · 42d ago Protecting AI workloads on Linux servers cybersecurity · 42d ago Exposing DoNex Ransomware Secrets with Malcore! cybersecurity · 42d ago What are the different Disaster Recovery scenarios your teams have tested on? cybersecurity · 42d ago someone actually leaked the Miasma supply chain attack toolkit source code on github cybersecurity · 42d ago X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection Technical Information Security Content & Discussion · 42d ago Secrets to PNPT Debrief Success The Cyber Mentors · 42d ago Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility For [Blue|Purple] Teams in Cyber Defence · 42d ago WinGet - Code Execution, Persistence and Detection Strategies cybersecurity · 42d ago WinGet - Code Execution, Persistence and Detection Strategies Technical Information Security Content & Discussion · 42d ago Ransomware attack shuts Illinois high school until Wednesday cybersecurity · 42d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 42d ago Siemens KACO Blueplanet Inverters All CISA Advisories · 42d ago Schneider Electric EcoStruxure Panel Server All CISA Advisories · 42d ago Schneider Electric Modicon Network Managed Switches All CISA Advisories · 42d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 42d ago Ideas for demo cybersecurity · 42d ago French govt messaging service breached in account hijacking attack BleepingComputer · 42d ago Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please? cybersecurity · 42d ago Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares. cybersecurity · 42d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue Technical Information Security Content & Discussion · 42d ago Physical attack device cybersecurity · 42d ago Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer cybersecurity · 42d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 42d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 42d ago IT GRC News? cybersecurity · 42d ago CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day BleepingComputer · 42d ago Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again cybersecurity · 42d ago I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information Technical Information Security Content & Discussion · 42d ago What are the best risk-based vulnerability management tools for tracking active exploitation in 2026? For [Blue|Purple] Teams in Cyber Defence · 42d ago Google patches new Chrome zero-day flaw exploited in the wild BleepingComputer · 42d ago QuasarNix: Reverse Shell Detection with Machine Learning For [Blue|Purple] Teams in Cyber Defence · 42d ago Shifting L7 validation to the edge to stop DB resource exhaustion? cybersecurity · 42d ago Google Patches 5th Chrome Zero-Day Exploited in 2026 cybersecurity · 42d ago AI Agents May Always Fall for Prompt Injections Technical Information Security Content & Discussion · 42d ago Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go For [Blue|Purple] Teams in Cyber Defence · 42d ago EC Council CEH exam advice cybersecurity · 42d ago Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion For [Blue|Purple] Teams in Cyber Defence · 42d ago Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 For [Blue|Purple] Teams in Cyber Defence · 42d ago About NPower vs PerScholas cybersecurity · 42d ago Looking for a vulnerability to learn cybersecurity · 42d ago Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency For [Blue|Purple] Teams in Cyber Defence · 42d ago From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk cybersecurity · 42d ago UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season For [Blue|Purple] Teams in Cyber Defence · 42d ago Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) For [Blue|Purple] Teams in Cyber Defence · 42d ago Visual Studio Code 1.123: Delayed extension auto-updates For [Blue|Purple] Teams in Cyber Defence · 42d ago Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users. For [Blue|Purple] Teams in Cyber Defence · 42d ago Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, For [Blue|Purple] Teams in Cyber Defence · 42d ago Bad USB through charger? cybersecurity · 42d ago Recommendations for Discord community for latest AI security products cybersecurity · 42d ago StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams hacking: security in practice · 42d ago Vulnerability Summary for the Week of June 1, 2026 cybersecurity · 42d ago Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas cybersecurity · 42d ago Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars Recorded Future · 42d ago I feel like ive lost my passion to tinker after 6 years in the industry, anyone else? cybersecurity · 42d ago I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples cybersecurity · 42d ago really need help with project ideas for MSc cybersecurity · 42d ago Which Course for an almost-complete noob? (SANS.edu) cybersecurity · 42d ago NFCShare Android malware spreads via fake banking app updates on GitHub BleepingComputer · 42d ago SoFi confirms third-party data breach at Hong Kong subsidiary cybersecurity · 42d ago AI Slop Will Kill Cybersecurity Storytelling If We Let It darkreading · 42d ago SoFi confirms third-party data breach at Hong Kong subsidiary BleepingComputer · 42d ago For the 2nd time in weeks, Microsoft packages laced with credential stealer cybersecurity · 42d ago Iran Signed a Ceasefire — Its Hackers Didn't cybersecurity · 42d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages cybersecurity · 42d ago DSPM étude marche cybersecurity · 42d ago CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file cybersecurity · 42d ago New Apple feature automatically changes your compromised passwords BleepingComputer · 42d ago Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks darkreading · 42d ago AppSec / Pentesting job market in Canada for experienced overseas applicants? cybersecurity · 42d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages BleepingComputer · 42d ago Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients. cybersecurity · 42d ago Check Point VPN Flaw Exploited Since Early May darkreading · 42d ago Automation Playbooks - which ones would you not want to live without? cybersecurity · 42d ago Is it necessary/important to Hash and salt API Keys for a strictly internal use tool? cybersecurity · 42d ago Need review on the OMS Cybersecurity program from Georgia Tech? cybersecurity · 42d ago If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk cybersecurity · 42d ago 2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years cybersecurity · 42d ago Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement For [Blue|Purple] Teams in Cyber Defence · 42d ago How do you close an alert cybersecurity · 42d ago Iran Signed a Ceasefire — Its Hackers Didn't darkreading · 43d ago What cybersecurity certifications are great value for money? cybersecurity · 43d ago Boxes for CPENT cybersecurity · 43d ago WhatsApp says it disrupted new NSO spyware phishing attacks BleepingComputer · 43d ago SIEM: is it "SIM" or "SEEM" cybersecurity · 43d ago I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included) cybersecurity · 43d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment Malware Analysis & Reports · 43d ago How justdeleteme and justgetmydata work? cybersecurity · 43d ago Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint CyberScoop · 43d ago GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks. hacking: security in practice · 43d ago I need help - PCI DSS 4.0 requirement 11.6.1 cybersecurity · 43d ago How are you learning agent pen testing? cybersecurity · 43d ago Gogs patches critical zero-day enabling remote code execution BleepingComputer · 43d ago HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified) For [Blue|Purple] Teams in Cyber Defence · 43d ago Cyber security intern cybersecurity · 43d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 43d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 43d ago Introducing Shark Jack Display 🦈 Hak5 · 43d ago Meta to take legal action against Israeli spyware company NSO cybersecurity · 43d ago Critical UniFi OS bug lets hackers gain root without authentication BleepingComputer · 43d ago Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit cybersecurity · 43d ago What's the best way to alert companies of a Glassworm copycat? cybersecurity · 43d ago How To Verify If A Site Is Legit? cybersecurity · 43d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 43d ago What is Flaresolverr cybersecurity · 43d ago Research: defenders using generative AI to simulate malware variants before they exist in the wild cybersecurity · 43d ago Reducing security operations complexity with Wazuh Cloud BleepingComputer · 43d ago How are regulated orgs actually letting engineers use Claude Code / Copilot? cybersecurity · 43d ago Cyber security expo Manchester cybersecurity · 43d ago Content creations was both a blessing and a curse. #bugbounty NahamSec · 43d ago Remote Hiring Opened the Talent Pool — and the Fraud Surface cybersecurity · 43d ago Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it Technical Information Security Content & Discussion · 43d ago Check Point links VPN zero-day attacks to Qilin ransomware gang BleepingComputer · 43d ago This Hacker Made $7,000 Hacking AI With One Email NahamSec · 43d ago EMBA firmware analysis framework v2.0.2 available - Party the big 2k Reverse Engineering · 43d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks cybersecurity · 43d ago What certs should I do during summer of 11th grade? cybersecurity · 43d ago CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) cybersecurity · 43d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 43d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 43d ago Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine cybersecurity · 43d ago Oxford University discloses data breach after careers platform hack cybersecurity · 43d ago Oxford University discloses data breach after careers platform hack BleepingComputer · 43d ago Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing cybersecurity · 43d ago Got this message from “SimBoss” cybersecurity · 43d ago PKCS12 Golang fork cybersecurity · 43d ago The AI security race needs accountability, not overregulation CyberScoop · 43d ago Malware Insights: Miasma Campaign cybersecurity · 43d ago 73 Microsoft GitHub repositories impacted by Miasma malware Malware Analysis & Reports · 43d ago 73 Microsoft GitHub repositories impacted by Miasma malware cybersecurity · 43d ago [Honeypot Research] Looking for volunteers to test telemetry/logs cybersecurity · 43d ago Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏 hacking: security in practice · 43d ago What is the condition of Bug Bounty program in the era of AI. cybersecurity · 43d ago Opening a cloned repo is no longer safe cybersecurity · 43d ago Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse cybersecurity · 43d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 43d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 43d ago Google Colab CLI opens runtimes to Claude Code and Codex cybersecurity · 43d ago VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks cybersecurity · 43d ago Over 20,000 Instagram accounts stolen in Meta AI support hack BleepingComputer · 43d ago The AI governance gap no one is talking about: deployment-stage accountability cybersecurity · 43d ago Security Review Request — TID Linux Kernel Module For [Blue|Purple] Teams in Cyber Defence · 43d ago Building a safe, effective sandbox to enable Codex on Windows For [Blue|Purple] Teams in Cyber Defence · 43d ago Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. For [Blue|Purple] Teams in Cyber Defence · 43d ago About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection For [Blue|Purple] Teams in Cyber Defence · 43d ago BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection For [Blue|Purple] Teams in Cyber Defence · 43d ago Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution. For [Blue|Purple] Teams in Cyber Defence · 43d ago Unauthorized Onlyfans Payment Malware Analysis & Reports · 43d ago Free Study Resources for Comptia Cysa+ cybersecurity · 43d ago What's up with powershellforhackers.com? hacking: security in practice · 43d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 43d ago Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Trend Micro Research, News, Perspectives · 43d ago Hands on with Intelligent Terminal, an AI-powered Windows Terminal BleepingComputer · 43d ago Hi there cybersecurity · 43d ago Final risk-based IT Audit interview round with Director and have no experience. Please help! cybersecurity · 43d ago Needed help cybersecurity · 43d ago HDD Firmware Hacking Part 1 Reverse Engineering · 43d ago [ Removed by Reddit ] cybersecurity · 43d ago UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service. For [Blue|Purple] Teams in Cyber Defence · 43d ago Career advice cybersecurity · 43d ago Do people really click on links from unknown numbers? hacking: security in practice · 44d ago PhD in cyber Security cybersecurity · 44d ago Built a password guessing game. Almost everyone stuck in level 5. cybersecurity · 44d ago OSINT (SOCIAL MEDIA) cybersecurity · 44d ago Beginner KQL project cybersecurity · 44d ago Question about WORM and encryption cybersecurity · 44d ago Update:Certified cyber security cybersecurity · 44d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction Reverse Engineering · 44d ago How to unlock whitelabeled uniview IPcam hacking: security in practice · 44d ago EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server. For [Blue|Purple] Teams in Cyber Defence · 44d ago Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental cybersecurity · 44d ago Can converted video files contain malware? hacking: security in practice · 44d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction) cybersecurity · 44d ago Malware that survives reinstalling the BIOS and OS cybersecurity · 44d ago Am I overthinking the x86 compatibility issues? how much friction am I actually facing? cybersecurity · 44d ago Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure cybersecurity · 44d ago Managing Microsoft Identity Is More Complicated Than It Looks cybersecurity · 44d ago C0XMO botnet spreads via DD-WRT router flaw, kills rival malware BleepingComputer · 44d ago Silent Ransom Group targets law firms with fake IT support calls BleepingComputer · 44d ago Zhiyun Weebil-S Camera Gimbal BLE Protocol Reverse Engineering · 44d ago My work email got subscribed to a bunch of israel newsletters cybersecurity · 44d ago Shadow AI cybersecurity · 44d ago Rate limiting is not enough. What else can I use? cybersecurity · 44d ago How To Avoid Potential Malware From Transferring To New Laptop cybersecurity · 44d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 cybersecurity · 44d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 44d ago Can't decide. cybersecurity · 44d ago looking for partners cybersecurity · 44d ago My edge is changing into bing when I search something cybersecurity · 44d ago Reverse Engineering the Garmin Running Dynamics BLE protocol Reverse Engineering · 44d ago Cybersecurity reality check cybersecurity · 44d ago [ Removed by Reddit ] cybersecurity · 44d ago EDRChoker: Choking The Telemetry Stream to Bypass Defenses Technical Information Security Content & Discussion · 44d ago Information Management cybersecurity · 44d ago Pwnd Blaster: Hacking your PC using your speaker without ever touching it For [Blue|Purple] Teams in Cyber Defence · 44d ago cygor: An modular asset discovery framework written in python to automate the repeating manual work For [Blue|Purple] Teams in Cyber Defence · 44d ago On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts. For [Blue|Purple] Teams in Cyber Defence · 44d ago Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors. For [Blue|Purple] Teams in Cyber Defence · 44d ago Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim For [Blue|Purple] Teams in Cyber Defence · 44d ago Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored) For [Blue|Purple] Teams in Cyber Defence · 44d ago The Privileged Roles Nobody Talks About For [Blue|Purple] Teams in Cyber Defence · 44d ago Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain... For [Blue|Purple] Teams in Cyber Defence · 44d ago Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis For [Blue|Purple] Teams in Cyber Defence · 44d ago 21 Zero-Days in FFmpeg For [Blue|Purple] Teams in Cyber Defence · 44d ago IronWorm Malware cybersecurity · 44d ago Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh? cybersecurity · 44d ago Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh? cybersecurity · 44d ago Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager cybersecurity · 44d ago depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research? For [Blue|Purple] Teams in Cyber Defence · 44d ago PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware Technical Information Security Content & Discussion · 44d ago Is a separate “clean” S3 bucket actually a security boundary for uploaded files? cybersecurity · 44d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass Technical Information Security Content & Discussion · 44d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass cybersecurity · 44d ago CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work For [Blue|Purple] Teams in Cyber Defence · 44d ago PenTest+ Exam cybersecurity · 44d ago Rooted your router lately? hacking: security in practice · 44d ago AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs cybersecurity · 44d ago The Detection & Response Chronicles: Covert Operations Through QEMU For [Blue|Purple] Teams in Cyber Defence · 44d ago The Interesting Case of WSL for Payload Staging For [Blue|Purple] Teams in Cyber Defence · 44d ago The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer For [Blue|Purple] Teams in Cyber Defence · 44d ago Ongoing Targeted Campaign Against US Law Firms For [Blue|Purple] Teams in Cyber Defence · 44d ago New China-Linked Cluster OP-512 For [Blue|Purple] Teams in Cyber Defence · 44d ago Looking for guidance cybersecurity · 45d ago 5$ to whoever can find the email of my old YouTube channel hacking: security in practice · 45d ago Before you attempt any OffSec certification, read what just happened to me cybersecurity · 45d ago Reporting Metrics for Management cybersecurity · 45d ago got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time cybersecurity · 45d ago This company is scaming people hacking: security in practice · 45d ago Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried cybersecurity · 45d ago HackTheBox - Facts IppSec · 45d ago Critical Everest Forms Pro flaw exploited to take over WordPress sites BleepingComputer · 45d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. cybersecurity · 45d ago AI Security Certificates cybersecurity · 45d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. For [Blue|Purple] Teams in Cyber Defence · 45d ago Guys is bug bounty dead? cybersecurity · 45d ago How are folks making it in bug bounty? cybersecurity · 45d ago How useful is it to require at least one uppercase letter in a password? cybersecurity · 45d ago Cyber security ! Is no more ? cybersecurity · 45d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 45d ago MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain For [Blue|Purple] Teams in Cyber Defence · 45d ago Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated For [Blue|Purple] Teams in Cyber Defence · 45d ago Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns For [Blue|Purple] Teams in Cyber Defence · 45d ago About ETW Internals: Architecture, Hooking, Tampering, and Detection For [Blue|Purple] Teams in Cyber Defence · 45d ago PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver For [Blue|Purple] Teams in Cyber Defence · 45d ago Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp For [Blue|Purple] Teams in Cyber Defence · 45d ago Async PICOs and Custom Beacon Wakeups in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 45d ago Enter the WasmForge: Compiling Sliver into WebAssembly For [Blue|Purple] Teams in Cyber Defence · 45d ago staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs For [Blue|Purple] Teams in Cyber Defence · 45d ago Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window For [Blue|Purple] Teams in Cyber Defence · 45d ago Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS For [Blue|Purple] Teams in Cyber Defence · 45d ago BOF Cocktails in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 45d ago Address Translation For [Blue|Purple] Teams in Cyber Defence · 45d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 45d ago Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months cybersecurity · 45d ago Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories cybersecurity · 45d ago Investigation into APT 5 and their inner workings of PLA Troop 61786 For [Blue|Purple] Teams in Cyber Defence · 45d ago How to train employees to feel when something's off? cybersecurity · 45d ago Building A Malware Lab From Scratch Part 2! Malware Analysis & Reports · 45d ago A modular autonomous-agent runtime written in C hacking: security in practice · 45d ago The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy For [Blue|Purple] Teams in Cyber Defence · 45d ago ALERT OVERLOAD cybersecurity · 45d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems For [Blue|Purple] Teams in Cyber Defence · 45d ago Magecart skimmer turns Stripe into a malware command server For [Blue|Purple] Teams in Cyber Defence · 45d ago Security advisory: Brute force attack on Dashlane user accounts For [Blue|Purple] Teams in Cyber Defence · 45d ago Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability For [Blue|Purple] Teams in Cyber Defence · 45d ago A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact). For [Blue|Purple] Teams in Cyber Defence · 45d ago IronWorm: Shai-Hulud's rustier cousin For [Blue|Purple] Teams in Cyber Defence · 45d ago Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate) Reverse Engineering · 45d ago CTO at NCSC Summary: week ending June 7th cybersecurity · 45d ago Weil reportedly pays up to $20 million after hackers steal client data For [Blue|Purple] Teams in Cyber Defence · 45d ago CTO at NCSC Summary: week ending June 7th For [Blue|Purple] Teams in Cyber Defence · 45d ago A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled cybersecurity · 45d ago defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize For [Blue|Purple] Teams in Cyber Defence · 45d ago 1-Click GitHub Token Stealing via a VSCode Bug For [Blue|Purple] Teams in Cyber Defence · 45d ago The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds For [Blue|Purple] Teams in Cyber Defence · 45d ago Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub cybersecurity · 45d ago Detecting npm Native Addon Malware: node-gyp Abuse Malware Analysis & Reports · 45d ago AppSec Engineer Interview Stories cybersecurity · 45d ago [OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps. cybersecurity · 45d ago Multi-layer sandbox for native code execution on Linux with no external deps. For [Blue|Purple] Teams in Cyber Defence · 45d ago Is there a safe way to continue using (unsupported) Windows 10? cybersecurity · 45d ago Is Splunk suitable for smaller Enterprises? cybersecurity · 45d ago Has anyone else had MFA prompt fatigue issues with users? cybersecurity · 45d ago Data Scrubbing from Databases cybersecurity · 45d ago Best Certificates? cybersecurity · 45d ago Rant cybersecurity · 45d ago New York passes data center moratorium and consumer protections as environmental, and housing proposals stall cybersecurity · 45d ago Cyber attackers have a new favorite, the browser cybersecurity · 45d ago Looking to get into cybersecurity in web3 cybersecurity · 45d ago Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests cybersecurity · 45d ago Suspicious Polyfill login prompts pop up on Toshiba, Muji websites BleepingComputer · 45d ago Should i use email 2fa or only auth and phone number? cybersecurity · 45d ago Can I break into cybersecurity with a white collar felony? cybersecurity · 45d ago Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale cybersecurity · 45d ago How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time? cybersecurity · 45d ago What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent? cybersecurity · 45d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers BleepingComputer · 45d ago How Hard is This cybersecurity · 46d ago Reverse Engineering Crazy Taxi, Part 3 Reverse Engineering · 46d ago Ghidra 12.1.2 has been released! Reverse Engineering · 46d ago Installed Fake Codex hidden as a google site cybersecurity · 46d ago Chinese APT deploys new malware to keep access to hacked networks BleepingComputer · 46d ago Virustital scan result help cybersecurity · 46d ago CrowdStrike Turned an AI Wave Into Its Best Quarter Ever cybersecurity · 46d ago Dark web Nemesis Market vendor gets 26 years for selling drugs BleepingComputer · 46d ago ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more hacking: security in practice · 46d ago Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions? cybersecurity · 46d ago I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now cybersecurity · 46d ago Being a Security Engineer? Which AI-powered tools are you using on a daily basis? cybersecurity · 46d ago Over 900 US gas station tank gauge systems exposed to attacks cybersecurity · 46d ago Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person cybersecurity · 46d ago SIEM is broken in the AI agents era cybersecurity · 46d ago TCM Security CTF Walkthrough The Cyber Mentors · 46d ago Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption Technical Information Security Content & Discussion · 46d ago Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected cybersecurity · 46d ago Extending a map tool for Cataclismo Reverse Engineering · 46d ago Over 900 US gas station tank gauge systems exposed to attacks BleepingComputer · 46d ago Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away CyberScoop · 46d ago Keeping Secrets Out of Logs Technical Information Security Content & Discussion · 46d ago Phantom Gyp npm Worm Abuses node-gyp Build Hooks cybersecurity · 46d ago Certified cybersecurity ISC2 cybersecurity · 46d ago Help studying for OSCP cybersecurity · 46d ago The current state of Threat Intelligence Tooling cybersecurity · 46d ago What 2026 DBIR Confirms: Attacks Are Living in the Browser BleepingComputer · 46d ago Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware cybersecurity · 46d ago I've been reverse engineering a lost 2010 horse MMO and I need contributors Reverse Engineering · 46d ago We tested offensive AI agents against deception technology cybersecurity · 46d ago A matter that I have been losing my sleep over cybersecurity · 46d ago Any experience with Rootly or incident.io for cyber incident management? cybersecurity · 46d ago CTIA Study Resources & Preparation Advice? cybersecurity · 46d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 46d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 46d ago Black hat uk vs brucon cybersecurity · 46d ago Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier) Technical Information Security Content & Discussion · 46d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks cybersecurity · 46d ago NIS2 hits railway hard cybersecurity · 46d ago Introducing Package Proxy: supply-chain safety checks without client-side software For [Blue|Purple] Teams in Cyber Defence · 46d ago I need help guys… :( cybersecurity · 46d ago Question from the Seniors cybersecurity · 46d ago China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware cybersecurity · 46d ago AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer For [Blue|Purple] Teams in Cyber Defence · 46d ago Can one reveal the asterisks in an email? hacking: security in practice · 46d ago what certs have u seen in ai security related job posts ? cybersecurity · 46d ago How is the Security Architecture / Strategic IT Security process structured in your organization? cybersecurity · 46d ago Proxmark3 vs Proxmark5 Side by Side hacking: security in practice · 46d ago Should I go for it? hacking: security in practice · 46d ago What's happening in cybersecurity job market in US and Europe these days? cybersecurity · 46d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links Malware Analysis & Reports · 46d ago Has any of you pivoted from GRC to CTI? cybersecurity · 46d ago Up-date-list of cybercrime types? cybersecurity · 46d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks BleepingComputer · 46d ago HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes Reverse Engineering · 46d ago What else should I learn to build a strong cybersecurity foundation? cybersecurity · 46d ago zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS) For [Blue|Purple] Teams in Cyber Defence · 46d ago Hackerone interview cybersecurity · 46d ago Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix cybersecurity · 46d ago The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory For [Blue|Purple] Teams in Cyber Defence · 46d ago VerdantBamboo: Just Another BRICKSTORM in the Firewall For [Blue|Purple] Teams in Cyber Defence · 46d ago AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID For [Blue|Purple] Teams in Cyber Defence · 46d ago MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code For [Blue|Purple] Teams in Cyber Defence · 46d ago IronWorm Supply Chain Malware Hits npm For [Blue|Purple] Teams in Cyber Defence · 46d ago FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel For [Blue|Purple] Teams in Cyber Defence · 46d ago FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad For [Blue|Purple] Teams in Cyber Defence · 46d ago You do surprise me.exe: An unexpected executable in Hola Browser For [Blue|Purple] Teams in Cyber Defence · 46d ago Testing URL Rewriting? cybersecurity · 46d ago Got an internship in IAM with no qualifications and no soft skills cybersecurity · 46d ago Work Hours of DFIR/Cloud Security vs Pentest cybersecurity · 46d ago Narcissistic Tech Leader.... cybersecurity · 46d ago Anyone else's firewall logs just explode after midnight? cybersecurity · 46d ago I'm replacing myself.. at least the boring parts cybersecurity · 46d ago Anyone else dealing with these phantom login attempts from China? cybersecurity · 46d ago Multi-layer sandbox for native code execution on Linux with no external deps. Reverse Engineering · 46d ago Best way to fully clear windows and set everything up securely (pc, accounts etc) cybersecurity · 46d ago IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks cybersecurity · 46d ago Soc analyst cybersecurity · 46d ago Do companies actually require cybersecurity insurance cybersecurity · 46d ago Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header hacking: security in practice · 46d ago Certification Questions | LIVE AMA | Summer of CCNA NetworkChuck · 46d ago Brave Software releases Origin for a paid, bloat-free browsing experience BleepingComputer · 46d ago Hola Browser for Windows compromised to deliver cryptominer BleepingComputer · 46d ago Credit card theft campaign abuses Stripe to host stolen payment info BleepingComputer · 46d ago Hill Dems hammer GOP for $250M CISA budget cut CyberScoop · 46d ago Uncommon/Unusual CrowdStrike Alerts cybersecurity · 46d ago Cyber analyst: law firm or bank cybersecurity · 46d ago best free av and how do i properly setup passwords? cybersecurity · 46d ago Five 9 Vulnerability cybersecurity · 47d ago Failed to verify LHOST error for long links in metasploit hacking: security in practice · 47d ago CVE Lite CLI closes dependency gap — but won't stop modern threats cybersecurity · 47d ago DentaQuest data breach exposed info of 2.6 million accounts BleepingComputer · 47d ago Scope change cybersecurity · 47d ago We just stopped a social engineering attack on our service desk. Here’s how it played out. cybersecurity · 47d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Reverse Engineering · 47d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Technical Information Security Content & Discussion · 47d ago Your AI agent could become your biggest insider threat CyberScoop · 47d ago What is the most underestimated cybersecurity risk right now? cybersecurity · 47d ago Update: Company is paying for any certification, which should I obtain? Except Sans cybersecurity · 47d ago New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification cybersecurity · 47d ago Anyone else's firewall vendor docs a total nightmare? cybersecurity · 47d ago Your opinions about a learning style cybersecurity · 47d ago UN food agency discloses breach affecting 600,000 Gaza households BleepingComputer · 47d ago Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks cybersecurity · 47d ago New IronWorm malware hits 36 packages in npm supply-chain attack cybersecurity · 47d ago Is Marauder available for ESP32-S3 Mini? hacking: security in practice · 47d ago Anyone else see their firewall logs just explode after a cloud update? cybersecurity · 47d ago Gemini whatsapp hacking: security in practice · 47d ago Are certifications necessary to get a job in cybersecurity? cybersecurity · 47d ago China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint News Feed · 47d ago Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass) cybersecurity · 47d ago New IronWorm malware hits 36 packages in npm supply-chain attack BleepingComputer · 47d ago Is retyping and translating textbooks too inefficient for CS/Cybersecurity? cybersecurity · 47d ago Free Microsoft Enterprise Security Assessment: Worth It cybersecurity · 47d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 47d ago How are organizations preparing for AI-generated phishing attacks? cybersecurity · 47d ago Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js Technical Information Security Content & Discussion · 47d ago Inside the race to adapt to an AI-powered security world cybersecurity · 47d ago 127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For cybersecurity · 47d ago Inside the race to adapt to an AI-powered security world CyberScoop · 47d ago Microsoft blames unexpected Windows driver updates on caching issue cybersecurity · 47d ago Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook BleepingComputer · 47d ago Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance) cybersecurity · 47d ago Enter the WasmForge: Compiling Sliver into WebAssembly Technical Information Security Content & Discussion · 47d ago Microsoft blames unexpected Windows driver updates on caching issue BleepingComputer · 47d ago Your CPU model leaks through the browser via WASM timing differences cybersecurity · 47d ago LSASS/Defender/CTFMON analysis For [Blue|Purple] Teams in Cyber Defence · 47d ago Software supply chain attacks: check your dependencies For [Blue|Purple] Teams in Cyber Defence · 47d ago Police dismantles fake ID marketplace used by migrant smugglers BleepingComputer · 47d ago void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies Reverse Engineering · 47d ago Chinese Cybercrime Group in Spotlight for Record Campaign Pace cybersecurity · 47d ago NAVTOR NavBox All CISA Advisories · 47d ago Hitachi Energy MACH HiDraw All CISA Advisories · 47d ago Hitachi Energy ITT600 Explorer All CISA Advisories · 47d ago B&R PPT30 Operating System All CISA Advisories · 47d ago Hitachi Energy RTU500 All CISA Advisories · 47d ago Extremely suspicious behaviour by memu emulator Malware Analysis & Reports · 47d ago Security Engineer 2 interview at Amazon coming up - What to expect? cybersecurity · 47d ago A researcher spent $1,500 testing if LLMs could hack a vulnerable app cybersecurity · 47d ago Help with university internship cybersecurity · 47d ago Are MCP servers becoming the next API security nightmare? cybersecurity · 47d ago Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator For [Blue|Purple] Teams in Cyber Defence · 47d ago Cisco warns of critical Unified CM flaw with PoC exploit code BleepingComputer · 47d ago What's the cybersecurity lesson you learned the hard way? cybersecurity · 47d ago ISO 27001 Surveillance audit vs Full recertification cybersecurity · 47d ago How important it is to get paid Cybersecurity certificates ? cybersecurity · 47d ago Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process cybersecurity · 47d ago Soc to Architecture cybersecurity · 47d ago Does "example file vulnerability" exists? cybersecurity · 47d ago VS code forces 2 hour cool down for most integrations. cybersecurity · 47d ago Company laptop isolated after Brave/Tor alert - should I be worried? cybersecurity · 47d ago Does anyone know how to send false positive to SOCradar ? virus total cybersecurity · 47d ago Looking for people to team up for Bug Bounties & CTFs cybersecurity · 47d ago Signal Without Smartphone cybersecurity · 47d ago I found a trojan on my pc and now im scared my private calls got leaked cybersecurity · 47d ago Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests cybersecurity · 47d ago CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog cybersecurity · 47d ago How do you change users behavior through awareness training? cybersecurity · 47d ago AI-built ransomware toolkit automates EDR evasion, AD discovery cybersecurity · 47d ago 29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection) For [Blue|Purple] Teams in Cyber Defence · 47d ago Safe Rust API for wolfSSL/wolfCOSE hacking: security in practice · 47d ago Safe Rust API for wolfSSL/wolfCOSE cybersecurity · 47d ago Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma) cybersecurity · 47d ago AMD GPU Users might be compromised cybersecurity · 47d ago [ Removed by Reddit ] cybersecurity · 47d ago Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information cybersecurity · 47d ago CISA warns of cyberattacks targeting fuel tank monitoring systems cybersecurity · 47d ago [CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF cybersecurity · 47d ago how to get good at cyber security? cybersecurity · 47d ago Anyone use CrunchAtlas? cybersecurity · 47d ago Prompt monitoring laughs cybersecurity · 47d ago Malicious Payload in ai-sdk-ollama npm Package cybersecurity · 47d ago Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24) cybersecurity · 47d ago Resource Exhaustion hacking: security in practice · 47d ago what the HELL is dsztfso? cybersecurity · 47d ago Open Source - 2500 New MITRE Mutations For [Blue|Purple] Teams in Cyber Defence · 47d ago Yubikey Alternative....? cybersecurity · 47d ago Hiring cybersecurity · 47d ago Malware Malware Analysis & Reports · 47d ago CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing cybersecurity · 47d ago Agent-Ready: How to Prepare Your Site for AI-Driven Commerce Blog – Forter · 47d ago Certification Advice cybersecurity · 47d ago Question about Linux kernel TLS ULP disclosed June 2 to oss-security cybersecurity · 47d ago European authorities crack down on illegal streaming networks CyberScoop · 47d ago An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this? cybersecurity · 47d ago Chinese hackers use new Atlas RAT malware in European cyberattacks BleepingComputer · 47d ago How to Rob a Data Center (new article on data center physical security) cybersecurity · 47d ago Hermes has a Home Assistant skill and it's unreal! NetworkChuck · 47d ago US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server cybersecurity · 47d ago Is it worth taking the EC councils masters program?? Are they legit /2026 cybersecurity · 47d ago Mid-level AppSec engineers: what do you actually study to prep for interviews? cybersecurity · 47d ago Automated Fault Injection Attack Framework Reverse Engineering · 47d ago The U.S. sanctions Nobitex crypto exchange used by ransomware BleepingComputer · 47d ago CISA warns of cyberattacks targeting fuel tank monitoring systems BleepingComputer · 47d ago Season VI of the US Games launches TOMORROW! Technical Information Security Content & Discussion · 47d ago Company is paying for any certification, which should I obtain? cybersecurity · 47d ago DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels CyberScoop · 47d ago Trusting Microsoft with your offensive security repos cybersecurity · 47d ago Automated Fault Injection Attack Framework cybersecurity · 47d ago Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT For [Blue|Purple] Teams in Cyber Defence · 47d ago Bring Your Own RWX Region DLL (BYORWXDLL) For [Blue|Purple] Teams in Cyber Defence · 47d ago Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem For [Blue|Purple] Teams in Cyber Defence · 47d ago APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component For [Blue|Purple] Teams in Cyber Defence · 47d ago NuGet Code Execution As A Service For [Blue|Purple] Teams in Cyber Defence · 47d ago aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies For [Blue|Purple] Teams in Cyber Defence · 47d ago Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor For [Blue|Purple] Teams in Cyber Defence · 47d ago TA4922: The Suspected Chinese Crime Group is Going Global For [Blue|Purple] Teams in Cyber Defence · 47d ago [ Removed by Reddit ] For [Blue|Purple] Teams in Cyber Defence · 47d ago New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute BleepingComputer · 48d ago Physical Biometric device as a security measure..?? cybersecurity · 48d ago Espionage Campaign Targeted Stock Exchange Executive for Five Months For [Blue|Purple] Teams in Cyber Defence · 48d ago Cybersegurança cybersecurity · 48d ago Started Learning Cybersecurity cybersecurity · 48d ago InfraGard Application - Seeking Help | Student cybersecurity · 48d ago x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994) Reverse Engineering · 48d ago Orientación en Ciberseguridad cybersecurity · 48d ago OnionAccelerator: multi-circuit / chunked download acceleration over Tor For [Blue|Purple] Teams in Cyber Defence · 48d ago Anthropic's coordinated vulnerability disclosure dashboard cybersecurity · 48d ago Hands Free: What LLM Driven Vulnerability Research Looks Like cybersecurity · 48d ago HazyBeacon and AWS Lambda Function URL Abuse For [Blue|Purple] Teams in Cyber Defence · 48d ago Real time Cybersecurity failures regarding Quantum computing/cryptography cybersecurity · 48d ago The Server Seizure That Affects Also Iran's Cyber Operations For [Blue|Purple] Teams in Cyber Defence · 48d ago How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad For [Blue|Purple] Teams in Cyber Defence · 48d ago 🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop Malware Analysis & Reports · 48d ago 🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It. cybersecurity · 48d ago 🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network For [Blue|Purple] Teams in Cyber Defence · 48d ago Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2 Reverse Engineering · 48d ago A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out. cybersecurity · 48d ago Cisco Webex Meetings Cross-Site Scripting Vulnerability Cisco Security Advisory · 48d ago CISA warns of active attacks exploiting Android, Linux bugs cybersecurity · 48d ago Found some open ports on a govt site, should i report or stay quiet? cybersecurity · 48d ago What is a good way to keep track of passwords for programs that don't support password managers? cybersecurity · 48d ago CISA warns of active attacks exploiting Android, Linux bugs BleepingComputer · 48d ago ChatGPT Malvertising Campaign Malware Analysis & Reports · 48d ago Cybersecurity statistics of the week (May 25th - May 31st) cybersecurity · 48d ago ASN Emissions Index. Networks ranked by how much noise they create on the internet. cybersecurity · 48d ago Have you sold cve before? cybersecurity · 48d ago EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires Technical Information Security Content & Discussion · 48d ago i want to become a pentester, but i don't know how to cybersecurity · 48d ago Recommendation Malware Analysis & Reports · 48d ago I’m not sure I’m in the right subreddit…. hacking: security in practice · 48d ago The OT Security Problem Nobody Wants to Own cybersecurity · 48d ago Don't Take Wednesday Off When You Manage Vulnerabilities cybersecurity · 48d ago I finally finished a production version after 4 yrds cybersecurity · 48d ago Support role pivot to cloud security cybersecurity · 48d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 48d ago What 345 Days of Untested Exposure Looks Like at a Bank BleepingComputer · 48d ago Took me a decade to turn quantum computing into what hackers can easily learn hacking: security in practice · 48d ago Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6! Malware Analysis & Reports · 48d ago How do you manage your passwords? cybersecurity · 48d ago Mad rush to produce AI driven slop cybersecurity · 48d ago O Tails é seguro para acessar links suspeitos? cybersecurity · 48d ago Took me a decade of work to turn Quantum Computing into a fun videogame hacking: security in practice · 48d ago Interesting- What LLM vuln research looks like Technical Information Security Content & Discussion · 48d ago Cyber Essentials plus + "legacy" network segments cybersecurity · 48d ago Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors For [Blue|Purple] Teams in Cyber Defence · 48d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 48d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 48d ago Acer working to patch max severity zero-days in Wave 7 routers BleepingComputer · 48d ago Hacking your PC using your speaker without ever touching it Reverse Engineering · 48d ago Hacking your PC using your speaker without ever touching it Technical Information Security Content & Discussion · 48d ago Insight for OPSWAT deep CDR cybersecurity · 48d ago Android vs iOS cybersecurity · 48d ago ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account cybersecurity · 48d ago Police dismantles 9 crime groups in illegal streaming crackdown BleepingComputer · 48d ago Security Audits at an MSP cybersecurity · 48d ago [ Removed by Reddit ] cybersecurity · 48d ago Google adds Android protection against AI deepfake scam calls BleepingComputer · 48d ago Passkey registration breaks after moving off localhost.. cybersecurity · 48d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 48d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 48d ago Does your team hire fresh AI engineer who doesn't know anything about Security operations? cybersecurity · 48d ago UARs for Equation (banking system) cybersecurity · 48d ago Simple way how to bypass hotel WiFi? hacking: security in practice · 48d ago VS Code zero-day lets hackers steal GitHub tokens in one click hacking: security in practice · 48d ago Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing Technical Information Security Content & Discussion · 48d ago IoT pentesting cert cybersecurity · 48d ago Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations cybersecurity · 48d ago Experience with Tac Security cybersecurity · 48d ago Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content cybersecurity · 48d ago VS Code zero-day lets hackers steal GitHub tokens in one click BleepingComputer · 48d ago Golang code review notes II - elttam Technical Information Security Content & Discussion · 48d ago Using AI to Secure Its Generated Code Is a Ponzi Scheme Technical Information Security Content & Discussion · 48d ago Found Security Vulnerabilities in my university website cybersecurity · 48d ago burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API) hacking: security in practice · 48d ago Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence cybersecurity · 48d ago AI - Threat to the CyberSec Industry? cybersecurity · 48d ago Built a honeypot platform to catch lateral movement. How are you guys detecting this? cybersecurity · 48d ago How should small SaaS teams safely answer customer security questionnaires? cybersecurity · 48d ago Dependency Cooldowns - Dependency Cooldowns For [Blue|Purple] Teams in Cyber Defence · 48d ago Can AI Do Intelligence Analysis? Apparently Not. cybersecurity · 48d ago PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model cybersecurity · 48d ago Regarding Certified Ethical Hacker (CEH Practical) exam cybersecurity · 48d ago Asking for advices on pursuing first CERTIFICATE cybersecurity · 48d ago I opened my own company and I can't find clients! cybersecurity · 48d ago ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter cybersecurity · 48d ago C2 Frameworks - Threat Hunting in Action with YARA Rules For [Blue|Purple] Teams in Cyber Defence · 48d ago How big of a security risk or exploit would this be? hacking: security in practice · 48d ago Microsoft's Coreutils project brings Linux commands to Windows BleepingComputer · 48d ago Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU? cybersecurity · 48d ago Anyone knows Quad9 dns ? cybersecurity · 48d ago OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models BleepingComputer · 48d ago KTO , Be the only one online -- on any WiFi network hacking: security in practice · 48d ago Critical Kirki flaw exploited to hijack WordPress admin accounts BleepingComputer · 48d ago Over 116,000 Mincraft systems infected in WeedHack malware campaign BleepingComputer · 48d ago Over 116,000 Minecraft systems infected in WeedHack malware campaign BleepingComputer · 48d ago Ransomware tabletop For [Blue|Purple] Teams in Cyber Defence · 48d ago FREE coffee at Cisco Live (I'm giving it away) NetworkChuck · 48d ago I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ? cybersecurity · 48d ago Greynoise swarm cybersecurity · 48d ago SecOT+ certification for free cybersecurity · 48d ago How is the state of the job market for mid-level security engineers? cybersecurity · 48d ago Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things cybersecurity · 48d ago WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total cybersecurity · 48d ago Laid off from TPRM job - need help on the future of my career cybersecurity · 48d ago News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces The Last Watchdog · 48d ago Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 For [Blue|Purple] Teams in Cyber Defence · 48d ago Tracking North Korea Nation-State APT Infrastructure: Kimsuky For [Blue|Purple] Teams in Cyber Defence · 48d ago 새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn For [Blue|Purple] Teams in Cyber Defence · 48d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 48d ago AI-built ransomware toolkit automates EDR evasion, AD discovery BleepingComputer · 48d ago apparently bypassing school systems by playing games hacking: security in practice · 48d ago Anyone compared RoboShadow vs ConnectSecure for vulnerability management? cybersecurity · 48d ago Codex Discovered a Hidden HTTP/2 Bomb For [Blue|Purple] Teams in Cyber Defence · 48d ago Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes Technical Information Security Content & Discussion · 49d ago Top 5 Active Directory Pentesting Tools The Cyber Mentors · 49d ago Any one send vulnerability to MITRE? cybersecurity · 49d ago Need advice for a 30 min Security Apprenticeship interview cybersecurity · 49d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 49d ago Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix For [Blue|Purple] Teams in Cyber Defence · 49d ago UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS cybersecurity · 49d ago Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match cybersecurity · 49d ago We Added a Detection Rule. We Were Not Expecting This. Technical Information Security Content & Discussion · 49d ago Introducing Microsoft Scout: Your always-on personal agent Microsoft 365 Blog · 49d ago Virustotal API as private data source cybersecurity · 49d ago DOD wants to integrate cyber in all operations, and integrate security into AI CyberScoop · 49d ago Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source! Reverse Engineering · 49d ago Microsoft Exchange Online outage causes email delays, failures BleepingComputer · 49d ago Announcing the new Work IQ APIs Microsoft 365 Blog · 49d ago Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases Security | Microsoft Azure Blog | Microsoft Azure · 49d ago Trump administration releases scaled-back AI executive order CyberScoop · 49d ago Account Number Security Flaw cybersecurity · 49d ago Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning? cybersecurity · 49d ago A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth cybersecurity · 49d ago Codex Lives In PowerShell Now NetworkChuck · 49d ago [ Removed by Reddit ] cybersecurity · 49d ago [ Removed by Reddit ] cybersecurity · 49d ago “Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?” For [Blue|Purple] Teams in Cyber Defence · 49d ago Instagram users locked out after Meta AI abused to steal accounts BleepingComputer · 49d ago Phishing simulation platform cybersecurity · 49d ago 1-Click GitHub Token Stealing via a VSCode Bug Technical Information Security Content & Discussion · 49d ago Just task about OSI model cybersecurity · 49d ago FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential The Last Watchdog · 49d ago Need help improving DNS Spy from a security tool angle cybersecurity · 49d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild cybersecurity · 49d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild Technical Information Security Content & Discussion · 49d ago Oracle's first monthly patch update just dropped 77 CVEs. cybersecurity · 49d ago Cleaning up after a legacy service account breach. How are you handling automated secrets discovery? cybersecurity · 49d ago Airbus digital apprenticeship cybersecurity · 49d ago Built a decompiler for exotic legacy programming language opentext Gupta Team Developer Reverse Engineering · 49d ago Always-On Red Teams hacking: security in practice · 49d ago Why the browser is now the front line for AI security BleepingComputer · 49d ago Anthropic expanding access to Project Glasswing CyberScoop · 49d ago Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities cybersecurity · 49d ago [An RX Global Event] Infosecurity Europe darkreading · 49d ago This is a scam and probably a malware/trojan. Path Of Exile 2 builder ... Malware Analysis & Reports · 49d ago CISA flags two-year-old Oracle flaw as actively exploited in attacks BleepingComputer · 49d ago Google fixes one actively exploited Android zero-day, 124 flaws cybersecurity · 49d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 49d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems All CISA Advisories · 49d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 49d ago Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force cybersecurity · 49d ago Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis? cybersecurity · 49d ago Security Architects who who actively use modelling - What's your approach? cybersecurity · 49d ago PAN-OS authentication bypass bug added to list of exploited vulnerabilities cybersecurity · 49d ago Google fixes one actively exploited Android zero-day, 124 flaws BleepingComputer · 49d ago I have extreme anxiety about being hacked cybersecurity · 49d ago Fresher cybersecurity · 49d ago Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif For [Blue|Purple] Teams in Cyber Defence · 49d ago Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand For [Blue|Purple] Teams in Cyber Defence · 49d ago Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach cybersecurity · 49d ago Career advice needed! cybersecurity · 49d ago LLMShare: using shared chatbot pages to distribute malware Malware Analysis & Reports · 49d ago GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure cybersecurity · 49d ago Google sr. security engineer interview cybersecurity · 49d ago Is offensive AI actually changing cybersecurity, or are we overestimating the impact? cybersecurity · 49d ago Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave cybersecurity · 49d ago is emerald chat safe? cybersecurity · 49d ago Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm For [Blue|Purple] Teams in Cyber Defence · 49d ago Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ? cybersecurity · 49d ago ClickJack in the wild cybersecurity · 49d ago NuGet Code Execution As A Service Technical Information Security Content & Discussion · 49d ago Thoughts on A.I assisted Malware Analysis? cybersecurity · 49d ago 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access cybersecurity · 49d ago What articles do you use for cybersecurity news? (2026) cybersecurity · 49d ago Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider? cybersecurity · 49d ago Roadmap and Training Recommodation cybersecurity · 49d ago Attackers are exploiting Palo Alto Networks defect that initially flew under the radar CyberScoop · 49d ago I managed to pull the full system prompt for Meta's Support AI hacking: security in practice · 49d ago Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks BleepingComputer · 49d ago Les anti-triche de niveau noyau et leur risque de sécurité cybersecurity · 49d ago Harassing text messages hacking: security in practice · 49d ago Asked to Send Sensitive Documents via MMS cybersecurity · 49d ago Red Hat npm packages compromised to steal developer credentials BleepingComputer · 49d ago SC-200 compared to CC (isc2) cybersecurity · 49d ago Spain arrests doxer leaking sensitive data of govt employees BleepingComputer · 49d ago running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it! Reverse Engineering · 49d ago Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB) Technical Information Security Content & Discussion · 49d ago Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now cybersecurity · 49d ago Looking to move off KB4, what are people actually using these days? cybersecurity · 49d ago Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight CyberScoop · 49d ago Got my Security+. What's next? cybersecurity · 49d ago I'm Moderating My First Panel… Come see me at Cisco Live NetworkChuck · 49d ago Vulnerability Summary for the Week of May 25, 2026 cybersecurity · 49d ago RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation For [Blue|Purple] Teams in Cyber Defence · 50d ago Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages For [Blue|Purple] Teams in Cyber Defence · 50d ago Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches For [Blue|Purple] Teams in Cyber Defence · 50d ago REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY! hacking: security in practice · 50d ago Malware cybersecurity · 50d ago Dashlane password manager users locked out by brute force attacks BleepingComputer · 50d ago Alternative Search Engine to Utilize in 2026? cybersecurity · 50d ago Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked cybersecurity · 50d ago Miasma: Supply Chain Attack Targeting RedHat npm Packages For [Blue|Purple] Teams in Cyber Defence · 50d ago USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order CyberScoop · 50d ago Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild cybersecurity · 50d ago Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers cybersecurity · 50d ago Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts Krebs on Security · 50d ago Hacking Palo Alto Networks' GlobalProtect VPN with AI hacking: security in practice · 50d ago AI compliance cybersecurity · 50d ago Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm cybersecurity · 50d ago WordPress malware campaign hides payloads in Steam profiles BleepingComputer · 50d ago Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains? cybersecurity · 50d ago MacBook or Windows Laptop for Cybersecurity cybersecurity · 50d ago What's the most creative MFA bypass you've seen? cybersecurity · 50d ago @redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers For [Blue|Purple] Teams in Cyber Defence · 50d ago Research Notes from Building a Windows Event Log Hunting Workflow cybersecurity · 50d ago Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am. hacking: security in practice · 50d ago How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ?? cybersecurity · 50d ago Free AI tools for TPRM? cybersecurity · 50d ago incomplete phone number from togo, need help reporting to police cybersecurity · 50d ago NPM packages from RedHat Compromised cybersecurity · 50d ago Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts cybersecurity · 50d ago Microsoft investigates Office Apps, Teams file access issues BleepingComputer · 50d ago SOC Analyst working towards Threat Intelligence cybersecurity · 50d ago Is XSS possible through PDFs? cybersecurity · 50d ago Race Against Time: Why Faster Vulnerability Alerts Matter BleepingComputer · 50d ago Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider Technical Information Security Content & Discussion · 50d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 50d ago The Next AI Governance Failure Won’t Be the Model cybersecurity · 50d ago Poisoning Claude Code: One GitHub Issue to Break the Supply Chain Technical Information Security Content & Discussion · 50d ago Microsoft MFA Is Down Again cybersecurity · 50d ago Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927) cybersecurity · 50d ago How I Found My First $3,000 AI Vulnerability NahamSec · 50d ago Stealing Passwords via HTML Injection Under a Strict CSP Technical Information Security Content & Discussion · 50d ago Computer logic or Science cybersecurity · 50d ago Critical Windows Netlogon RCE flaw now exploited in attacks BleepingComputer · 50d ago Webinar tomorrow: From alert to resolution in network incident response BleepingComputer · 50d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 50d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 50d ago I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for? cybersecurity · 50d ago What C2s Are You Using cybersecurity · 50d ago Microsoft confirms outage affecting MFA, My Sign-Ins platform BleepingComputer · 50d ago Microsoft fixes outage affecting MFA setup, MySignIn service BleepingComputer · 50d ago Microsoft fixes KB5089549 Windows security update install issues BleepingComputer · 50d ago Best AI LLM for Hacking related stuff hacking: security in practice · 50d ago PNPT Exam cybersecurity · 50d ago Election threats are focused on campaign systems, not voting machines CyberScoop · 50d ago What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification? cybersecurity · 50d ago Feels like most people ignore the wireless layer until it bites them hacking: security in practice · 50d ago Any appsec engineer working in fortune 500? cybersecurity · 50d ago I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next cybersecurity · 50d ago Anyone transition from AWS Data Center Operations to InfoSec? cybersecurity · 50d ago I think my account got hacked but it's weird cybersecurity · 50d ago Subnet discovery through multi-protocol TTL tracing Technical Information Security Content & Discussion · 50d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 50d ago current market for detecting deepfakes? cybersecurity · 50d ago Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched For [Blue|Purple] Teams in Cyber Defence · 50d ago Worried about friend being doxxed on doxbin cybersecurity · 50d ago Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks For [Blue|Purple] Teams in Cyber Defence · 50d ago Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries For [Blue|Purple] Teams in Cyber Defence · 50d ago how to shift from a service based company to a product based one in cybersecurity ? cybersecurity · 50d ago Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA cybersecurity · 50d ago Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking? hacking: security in practice · 50d ago Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign For [Blue|Purple] Teams in Cyber Defence · 50d ago Claude AI user data directory exfiltration via malicious npm package cybersecurity · 50d ago Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from? Reverse Engineering · 50d ago Bitdefender blocking amd stuff? False positive or? cybersecurity · 50d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 50d ago Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet Trend Micro Research, News, Perspectives · 50d ago did they have my password?? what triggers this specific email??? instagram HELP. cybersecurity · 50d ago How to Unpack FlawedAmmyy - Malware Unpacking Tutorial Malware Analysis & Reports · 50d ago ATTENTION: Dashlane may have been breached. (Password manager). cybersecurity · 50d ago Can anyone figure out how to retrieve the recovery key in signal app? hacking: security in practice · 50d ago Norton blocked a “malicious script”? cybersecurity · 50d ago Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts cybersecurity · 50d ago Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive. cybersecurity · 50d ago I wrote about the 5 biggest threats in 2026, curious what this community thinks. cybersecurity · 50d ago MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce? cybersecurity · 50d ago Atomdrift - open-source malware detection for the software supply chain For [Blue|Purple] Teams in Cyber Defence · 50d ago Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions? cybersecurity · 50d ago NetworkChuck cybersecurity · 50d ago LLM for creating phishing tool cybersecurity · 51d ago Why are we still treating IAM like a compliance checkbox? cybersecurity · 51d ago Polyfill pop up? cybersecurity · 51d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Technical Information Security Content & Discussion · 51d ago Building A Malware Lab From Scratch! Malware Analysis & Reports · 51d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Reverse Engineering · 51d ago WP Maps Pro bug exploited to create admin accounts on WordPress sites BleepingComputer · 51d ago SecAI+ difficulty question cybersecurity · 51d ago $730k+ raised on Proxmark5 with 2150 backers hacking: security in practice · 51d ago Could you guys give an honest feedback to a completely automated ssrf attack tool? cybersecurity · 51d ago tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me cybersecurity · 51d ago Microsoft Joined the DMARC Club cybersecurity · 51d ago Help. cybersecurity · 51d ago Vibe Coding Security cybersecurity · 51d ago I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works) hacking: security in practice · 51d ago Looking for a Company to Partner With cybersecurity · 51d ago Best reporting tools? cybersecurity · 51d ago What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months) cybersecurity · 51d ago Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens For [Blue|Purple] Teams in Cyber Defence · 51d ago How Can Polyfill.io Still Act Maliciously? cybersecurity · 51d ago 179 npm Packages Target Cloud and Finance via oob.moika.tech For [Blue|Purple] Teams in Cyber Defence · 51d ago KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4 For [Blue|Purple] Teams in Cyber Defence · 51d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 51d ago Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services For [Blue|Purple] Teams in Cyber Defence · 51d ago TinyLoad v7 - what i added :D (in memory protection using VEH and alot more) Reverse Engineering · 51d ago EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA For [Blue|Purple] Teams in Cyber Defence · 51d ago Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace For [Blue|Purple] Teams in Cyber Defence · 51d ago Signal macOS Desktop App Doesn't Actually Delete Messages When it Should For [Blue|Purple] Teams in Cyber Defence · 51d ago Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan For [Blue|Purple] Teams in Cyber Defence · 51d ago WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD For [Blue|Purple] Teams in Cyber Defence · 51d ago Any idea who's behind this hack? How to resolve it? hacking: security in practice · 51d ago Typosquatted npm packages used to steal cloud and CI/CD secrets For [Blue|Purple] Teams in Cyber Defence · 51d ago Need THM voucher code for cheap? Any known seller? cybersecurity · 51d ago Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2 For [Blue|Purple] Teams in Cyber Defence · 51d ago Malicious npm packages abuse dependency confusion to profile developer environments For [Blue|Purple] Teams in Cyber Defence · 51d ago Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) For [Blue|Purple] Teams in Cyber Defence · 51d ago Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack For [Blue|Purple] Teams in Cyber Defence · 51d ago CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied." For [Blue|Purple] Teams in Cyber Defence · 51d ago Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign For [Blue|Purple] Teams in Cyber Defence · 51d ago SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks. For [Blue|Purple] Teams in Cyber Defence · 51d ago EDR Incident Response Playbook: Containing Local Account Incidents For [Blue|Purple] Teams in Cyber Defence · 51d ago Adversarial Oracles: LLM-Guided EDR Signature Reduction For [Blue|Purple] Teams in Cyber Defence · 51d ago One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF For [Blue|Purple] Teams in Cyber Defence · 51d ago proxy: A lightweight caching proxy for package registries. For [Blue|Purple] Teams in Cyber Defence · 51d ago How OLTs may have exposed entire ISP networks For [Blue|Purple] Teams in Cyber Defence · 51d ago Ghost passwords? cybersecurity · 51d ago Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it hacking: security in practice · 51d ago A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years For [Blue|Purple] Teams in Cyber Defence · 51d ago HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics For [Blue|Purple] Teams in Cyber Defence · 51d ago Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots For [Blue|Purple] Teams in Cyber Defence · 51d ago Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures For [Blue|Purple] Teams in Cyber Defence · 51d ago Lessons from Penetration Tests on Large-Scale Agent Systems For [Blue|Purple] Teams in Cyber Defence · 51d ago pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter. For [Blue|Purple] Teams in Cyber Defence · 51d ago [ Removed by Reddit ] Reverse Engineering · 51d ago Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not. cybersecurity · 51d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 51d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions Technical Information Security Content & Discussion · 51d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions cybersecurity · 51d ago Anyone else having Chatgpt Strikes / Violations while learning cybersecurity? cybersecurity · 51d ago Blue Team tips? hacking: security in practice · 51d ago Working at Cisco, worth it? cybersecurity · 51d ago Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice cybersecurity · 51d ago usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer) Reverse Engineering · 51d ago CIFSwitch: a non-universal Linux local root vulnerability For [Blue|Purple] Teams in Cyber Defence · 51d ago Are you pen testing AI Agents? cybersecurity · 51d ago Question of android malware cybersecurity · 51d ago External attack surface: how are you correlating DNS, SSL, and IP reputation today? cybersecurity · 51d ago edit certified pdf hacking: security in practice · 51d ago how do i properly setup 2fa and bitwarden? cybersecurity · 51d ago Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC) cybersecurity · 51d ago i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested? cybersecurity · 51d ago Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever? cybersecurity · 51d ago I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux) Reverse Engineering · 52d ago Can Steam Cloud Files Transfer Malware cybersecurity · 52d ago I bought an old phone from 2018 and wanna destroy it with viruses for fun Malware Analysis & Reports · 52d ago Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks BleepingComputer · 52d ago HackTheBox - Interpreter IppSec · 52d ago Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension For [Blue|Purple] Teams in Cyber Defence · 52d ago Questions for the cloud security engineers cybersecurity · 52d ago DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database. For [Blue|Purple] Teams in Cyber Defence · 52d ago Visual Studio Extensions Revisited For [Blue|Purple] Teams in Cyber Defence · 52d ago Thoughts on this as a starter and doing bug bounty on the side cybersecurity · 52d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 52d ago How are new SC-200 candidates practicing labs without an E5 Developer tenant? cybersecurity · 52d ago New CIFSwitch Linux flaw gives root on multiple distributions BleepingComputer · 52d ago Everyday hacking in our lives - transportation, work, finances, goods etc hacking: security in practice · 52d ago Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters Technical Information Security Content & Discussion · 52d ago Getting OTP spammed from every app and website I've ever used. Should I be worried? cybersecurity · 52d ago BYOVD and Looting LSASS in the Modern EDR Era For [Blue|Purple] Teams in Cyber Defence · 52d ago A browser tool for checking contractor insurance certificates cybersecurity · 52d ago Am I getting screwed? cybersecurity · 52d ago SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers cybersecurity · 52d ago PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29} cybersecurity · 52d ago CTO at NCSC Summary: week ending May 31st cybersecurity · 52d ago CTO at NCSC Summary: week ending May 31st For [Blue|Purple] Teams in Cyber Defence · 52d ago BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship cybersecurity · 52d ago OffensiveCon26 videos For [Blue|Purple] Teams in Cyber Defence · 52d ago Need suggestion cybersecurity · 52d ago Malware escaped browser without downloading files, then escaped a virtual machine Malware Analysis & Reports · 52d ago [INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety) cybersecurity · 52d ago Was Dave Bittner interviewing an AI? cybersecurity · 52d ago CTF for complete beginner cybersecurity · 52d ago Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques? cybersecurity · 52d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 52d ago AI-Era Cyber Risk Standards cybersecurity · 52d ago BEC Victim - Attacker replied inside a real email thread using a lookalike domain cybersecurity · 52d ago School Survey, (non-paid nothing its free its for my grades) For [Blue|Purple] Teams in Cyber Defence · 52d ago Question for those who transitioned from remote to work from anywhere cybersecurity · 52d ago Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors cybersecurity · 52d ago Do you enjoy what you do or do you wish you could go back in time and change it? cybersecurity · 52d ago Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber? cybersecurity · 52d ago A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.) Technical Information Security Content & Discussion · 52d ago For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year? cybersecurity · 52d ago Name That Toon: Mark of (Cybersecurity) Progress darkreading · 52d ago Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ? cybersecurity · 52d ago Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years? cybersecurity · 52d ago Botnet of more than 17 million devices dismantled cybersecurity · 52d ago Exposed credentials on logs cybersecurity · 52d ago Do you think this is legit or has the website been compromised? hacking: security in practice · 52d ago Introducing Keyhog: The First GPU Accelerated secret scanner Technical Information Security Content & Discussion · 53d ago What do you think is the biggest cybersecurity risk for small businesses in 2026? cybersecurity · 53d ago Wanted to shift to cloud security, but have some questions cybersecurity · 53d ago OffensiveCon26 YouTube Playlist released Technical Information Security Content & Discussion · 53d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments For [Blue|Purple] Teams in Cyber Defence · 53d ago LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms For [Blue|Purple] Teams in Cyber Defence · 53d ago ChatGPT share links abused to host fake outage pages to deliver malware BleepingComputer · 53d ago Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 CyberScoop · 53d ago California AG sues 23andMe over 2023 breach exposing health data BleepingComputer · 53d ago Zero Trust is Overrated? Navigating the Complexity cybersecurity · 53d ago Test API post with flair cybersecurity · 53d ago Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications cybersecurity · 53d ago How Do You Handle the Massive Amount of Information in the CPTS Path? cybersecurity · 53d ago Wanna learn cybersecurity & ethical hacking hacking: security in practice · 53d ago LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting For [Blue|Purple] Teams in Cyber Defence · 53d ago Help an upcoming cybersecurity engineer! cybersecurity · 53d ago Repeated Microsoft MFA attempts even after password change cybersecurity · 53d ago I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but Malware Analysis & Reports · 53d ago Do you guys take paper notes or digital ones during studying ? hacking: security in practice · 53d ago What Is Device Intelligence and How Does It Stop Fraud? cybersecurity · 53d ago [FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE) cybersecurity · 53d ago Federal audit reveals NIST’s NVD is plagued by poor planning and duplication CyberScoop · 53d ago Ghidra 12.1.1 has been released! Reverse Engineering · 53d ago IBM commits $5 billion to secure open-source software cybersecurity · 53d ago Structuring an AI-Assisted Pentesting Homelab for a Final Year Project cybersecurity · 53d ago Are teams actually monitoring LLM traffic in production environments? cybersecurity · 53d ago How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA) cybersecurity · 53d ago Raspberry pi cybersecurity · 53d ago Asia's Cyber Insurance Market Shows Signs of Life darkreading · 53d ago What is the biggest obstacle to using AI safely in a company? cybersecurity · 53d ago From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market BleepingComputer · 53d ago Dutch govt disrupts malware botnet with 17 million infected devices BleepingComputer · 53d ago Advice going forward cybersecurity · 53d ago MCP Firewall help cybersecurity · 53d ago I wanted to shift to security but people told me the market is extremely bad, is that true? cybersecurity · 53d ago Best Personality Type/Traits for Working in Cyber Security cybersecurity · 53d ago Identifying attack patterns through kernel frame callstacks For [Blue|Purple] Teams in Cyber Defence · 53d ago A fake freelance job interview almost installed malware on my PC cybersecurity · 53d ago Is there a viable career path here or am I just being delusional? cybersecurity · 53d ago With Complex Cloud Integrations, Small Errors Lead to Major Compromises darkreading · 53d ago What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks cybersecurity · 53d ago Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness For [Blue|Purple] Teams in Cyber Defence · 53d ago Google Chrome adds session cookie theft protection for all users BleepingComputer · 53d ago 'The Com' Cyberattacks Support Violence & Sexploitation darkreading · 53d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 53d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 53d ago How do enterprises actually prevent developers from exfiltrating source code? cybersecurity · 53d ago Man sent to prison for selling data of 7 millions elderly Americans BleepingComputer · 53d ago I have a datastealer malware cybersecurity · 53d ago Dúvida de carreira. cybersecurity · 53d ago US charges Google security engineer with Polymarket insider trading BleepingComputer · 53d ago Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace cybersecurity · 53d ago Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated cybersecurity · 53d ago is SIEM really needed here ? cybersecurity · 53d ago Decompiled an app, found a bunch of secrets, what now? cybersecurity · 53d ago What safety boundary would you expect from a local AI incident investigation tool? For [Blue|Purple] Teams in Cyber Defence · 53d ago Can someone give me a correct method for learning reverse engineering? cybersecurity · 53d ago 1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog Technical Information Security Content & Discussion · 53d ago Authenticated RCE via Argument Injection in Gogs (NOT FIXED) For [Blue|Purple] Teams in Cyber Defence · 53d ago Charter Communications data breach affects 4.9 million accounts BleepingComputer · 53d ago Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months cybersecurity · 53d ago GRC Advise cybersecurity · 53d ago [ Removed by Reddit ] cybersecurity · 53d ago Did something happen to haveibeenpwned? Any alternatives? cybersecurity · 53d ago I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found. Technical Information Security Content & Discussion · 53d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 53d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 53d ago How do people actually modify mobile games to increase their power? hacking: security in practice · 53d ago Why I Built My Own LLM Benchmark for THOR Finding Triage For [Blue|Purple] Teams in Cyber Defence · 53d ago RAT SUSPECTED cybersecurity · 53d ago Casdoor contains multiple authentication bypass and access management vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 53d ago The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents For [Blue|Purple] Teams in Cyber Defence · 53d ago GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations For [Blue|Purple] Teams in Cyber Defence · 53d ago Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies For [Blue|Purple] Teams in Cyber Defence · 53d ago Malware seller hunted across three continents For [Blue|Purple] Teams in Cyber Defence · 53d ago Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims For [Blue|Purple] Teams in Cyber Defence · 53d ago Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers For [Blue|Purple] Teams in Cyber Defence · 53d ago Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network For [Blue|Purple] Teams in Cyber Defence · 53d ago How do people afford certificate s? cybersecurity · 53d ago I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed? cybersecurity · 53d ago Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint) Reverse Engineering · 53d ago Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. cybersecurity · 53d ago Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 53d ago Phone Forwarding cybersecurity · 53d ago Opinions on running Full Microsoft E5 Security Stack cybersecurity · 53d ago Claiming "XDR" cybersecurity · 53d ago Typosquatted npm packages used to steal cloud and CI/CD secrets cybersecurity · 53d ago Why Loyalty Programs Are Quietly Becoming a Security Blind Spot hacking: security in practice · 53d ago Fooling around with encrypted reasoning blobs Technical Information Security Content & Discussion · 53d ago CALIF: An AI audit of FreeBSD Technical Information Security Content & Discussion · 53d ago Microsoft security cybersecurity · 53d ago Need help regarding building a home lab cybersecurity · 53d ago Should I turn on passwordless accounts for all my Microsoft accounts? cybersecurity · 53d ago Transitioning from AWS Data Center Operations to Security Engineering cybersecurity · 53d ago CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries Technical Information Security Content & Discussion · 53d ago Probably the wrong place. cybersecurity · 53d ago Anthropic confirms Claude Mythos-class models will roll out to the public BleepingComputer · 53d ago What after IT helpdesk? cybersecurity · 53d ago As Global Powers Explore Humanoid Robots, Cyber-Risk Looms darkreading · 53d ago News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit The Last Watchdog · 53d ago Ajuda pessoal hacking: security in practice · 53d ago VMP 3.5+ Internal Architecture & Heap Dispatch Analysis Reverse Engineering · 53d ago GreyVibe hackers use ChatGPT, Gemini to power cyberattacks BleepingComputer · 53d ago How are you security-testing API changes before production without slowing CI/CD? cybersecurity · 53d ago Are we trusting update repos or are you all extra paranoid now as well? cybersecurity · 53d ago Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops cybersecurity · 53d ago BTMOB Android malware service generates custom phishing payloads BleepingComputer · 53d ago Prevent supply chain attacks cybersecurity · 53d ago The C-suite job that's burning people out faster than any other For [Blue|Purple] Teams in Cyber Defence · 53d ago New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation For [Blue|Purple] Teams in Cyber Defence · 53d ago Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems cybersecurity · 53d ago SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer For [Blue|Purple] Teams in Cyber Defence · 53d ago FBI warns of fake FIFA websites running World Cup fraud schemes cybersecurity · 53d ago Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances For [Blue|Purple] Teams in Cyber Defence · 53d ago Hackers are trying to steal Signal users' backups in new wave of phishing attacks cybersecurity · 53d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN Technical Information Security Content & Discussion · 53d ago Samy Kamkar on building viruses, his arrest and privacy in the LLM era hacking: security in practice · 53d ago 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface For [Blue|Purple] Teams in Cyber Defence · 53d ago FBI warns of fake FIFA websites running World Cup fraud schemes BleepingComputer · 54d ago Visual Studio Extensions Revisited Technical Information Security Content & Discussion · 54d ago Dutch Raid Fails to Dent Russian Bulletproof Host darkreading · 54d ago APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026 For [Blue|Purple] Teams in Cyber Defence · 54d ago Incident Response Testing Preparation cybersecurity · 54d ago Introducing Microsoft 365 Business with Copilot: The new standard for small business Microsoft 365 Blog · 54d ago Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference cybersecurity · 54d ago House panel poised to hold hearing centered on AI impact on cyber CyberScoop · 54d ago [Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥 cybersecurity · 54d ago Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure For [Blue|Purple] Teams in Cyber Defence · 54d ago Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake For [Blue|Purple] Teams in Cyber Defence · 54d ago 3rd Party NFC cards.. secure? cybersecurity · 54d ago Vulnerability Management Tickets & SLA cybersecurity · 54d ago Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket CyberScoop · 54d ago Defending at Machine-Speed: Building AI Threat Readiness cybersecurity · 54d ago AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved cybersecurity · 54d ago HEAD request body processing leading cybersecurity · 54d ago Hackers exploit FortiClient EMS flaw to push infostealer malware BleepingComputer · 54d ago Malicious npm Package Stole Files From Claude AI User Directory via GitHub cybersecurity · 54d ago Does anyone have an app like substack to keep being updated and engaging within the cyber domain? cybersecurity · 54d ago Zero Trust Implementation Guidelines For [Blue|Purple] Teams in Cyber Defence · 54d ago [ Removed by Reddit ] hacking: security in practice · 54d ago What’s an attack vector people massively underestimate in 2026? cybersecurity · 54d ago We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7 cybersecurity · 54d ago Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP) Technical Information Security Content & Discussion · 54d ago Is this considered a bug or something else entirely? hacking: security in practice · 54d ago Agentic AI Isn't Risky; the Way Orgs Deploy It Is darkreading · 54d ago A Deeper Look at GLASSWORM's Solana Variant Malware Analysis & Reports · 54d ago A Deeper Look at GLASSWORM's Solana Variant cybersecurity · 54d ago How 2004 RuneScape fit a multiplayer RPG into 56k dial-up Reverse Engineering · 54d ago Getting back deleted conversation from messanger hacking: security in practice · 54d ago Introducing a new design for Microsoft 365 Copilot Microsoft 365 Blog · 54d ago BlackToad: Network Manipulation in an AutoIt Payload For [Blue|Purple] Teams in Cyber Defence · 54d ago RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT For [Blue|Purple] Teams in Cyber Defence · 54d ago Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant For [Blue|Purple] Teams in Cyber Defence · 54d ago Calling Cyber Security Beginners cybersecurity · 54d ago Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE Technical Information Security Content & Discussion · 54d ago Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis cybersecurity · 54d ago Building Omegle for Exposed Webcams hacking: security in practice · 54d ago built something for ai agents, ended up looking a lot like classic appsec cybersecurity · 54d ago New Gogs zero-day flaw lets hackers get remote code execution BleepingComputer · 54d ago Is Gophish still usable in 2026? cybersecurity · 54d ago Microsoft vs Chaotic Eclipse: three zero-days now actively exploited cybersecurity · 54d ago How SIEM helps MSPs reduce noise and stop threats faster BleepingComputer · 54d ago what do you think cybersecurity · 54d ago Why would be clicking a website, redirect me? cybersecurity · 54d ago Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit For [Blue|Purple] Teams in Cyber Defence · 54d ago Zapier fixes bug chain that researchers say risked widespread account takeover cybersecurity · 54d ago AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career? hacking: security in practice · 54d ago Writing cybersecurity policies is a waste of time cybersecurity · 54d ago Zapier fixes bug chain that researchers say risked widespread account takeover CyberScoop · 54d ago The GitHub Leak Situation Just Got Worse | Threat Wire Hak5 · 54d ago reverse engineering need for speed most wanted for modding sdk Reverse Engineering · 54d ago Romanian gets 5 years in prison for hacking Oregon govt network BleepingComputer · 54d ago Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security darkreading · 54d ago Webinar: Why network incidents take too long to resolve BleepingComputer · 54d ago Raising the Cybersecurity Stakes: Ante up for the Agentic Era. cybersecurity · 54d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories Alerts · 54d ago ABB EIBPORT All CISA Advisories · 54d ago Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter All CISA Advisories · 54d ago ABB Busch-Welcome 2 Wire Door Opener Actuator All CISA Advisories · 54d ago Fourth Frontier Frontier X Mobile Application, Frontier X2 All CISA Advisories · 54d ago CP Plus 8 Ch. Network Video Recorder All CISA Advisories · 54d ago XCharge C6 All CISA Advisories · 54d ago KMW CCTV Security Cameras All CISA Advisories · 54d ago MacGregor Voyage Data Recorder (VDR) G4e All CISA Advisories · 54d ago Schnieider Electric EcoStruxure Machine Expert HVAC All CISA Advisories · 54d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories All CISA Advisories · 54d ago Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it. cybersecurity · 54d ago [ Removed by Reddit ] cybersecurity · 54d ago Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15 Malware Analysis & Reports · 54d ago Released: Dataforge Honeypot cybersecurity · 54d ago Carnival Cruise confirms data breach affecting nearly 6 million people BleepingComputer · 54d ago Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks cybersecurity · 54d ago CEH-free cybersecurity · 54d ago Hottest cybersecurity open-source tools of the month: May 2026 cybersecurity · 54d ago Preparation tips for CPENT cybersecurity · 54d ago Sextortionist sentenced to 33 years for targeting 145 children BleepingComputer · 54d ago BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model darkreading · 54d ago FROST: Fingerprinting Remotely using OPFS-based SSD Timing For [Blue|Purple] Teams in Cyber Defence · 54d ago How do you handle AI tools in your organization? cybersecurity · 54d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 54d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 54d ago What scanners are actually trying against AI infrastructure Technical Information Security Content & Discussion · 54d ago I think i got scammed anybody can help me with that cybersecurity · 54d ago Nordic CISOs Handle Rising Cyber Threats Remarkably Well darkreading · 54d ago New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo cybersecurity · 54d ago Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup For [Blue|Purple] Teams in Cyber Defence · 54d ago Is it safe to have passwords copied to clipboard on IOS temporarily? cybersecurity · 54d ago Developers working on anti-fraud systems deserve more credit cybersecurity · 54d ago Real Folks of Cyber | Dan Berger | Day in the Life The Cyber Mentors · 54d ago My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst cybersecurity · 54d ago GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs. Reverse Engineering · 54d ago Security awareness training for AI heavy smb workflows? cybersecurity · 54d ago puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 54d ago Defense by accumulation Technical Information Security Content & Discussion · 54d ago Minimum Requirements for Helpdesk Role ? cybersecurity · 54d ago Reddit spear phishing cybersecurity · 54d ago Winbox server/client reverse engineered is opensource Reverse Engineering · 54d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ cybersecurity · 54d ago What to do cybersecurity · 54d ago What resources would you recommend for studying cysa+ cybersecurity · 54d ago Provenance of Data cybersecurity · 54d ago GPU mining malware spreads via SEO poisoning, AI chatbots BleepingComputer · 54d ago 5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain hacking: security in practice · 54d ago Websites have a new way to spy on visitors: analyzing their SSD activity cybersecurity · 54d ago 12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal? cybersecurity · 54d ago OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms CyberScoop · 54d ago Russian Art Teacher - Hinder Security Clearance? cybersecurity · 54d ago Ransomware Actors Show Up In Person to Steal Law Firm Data darkreading · 54d ago FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person CyberScoop · 54d ago Who is Salt Typhoon Really? Unraveling the Attribution Challenge For [Blue|Purple] Teams in Cyber Defence · 54d ago EDR/MDR Vendor Questions cybersecurity · 54d ago Cybersecurity as a Highschooler? cybersecurity · 54d ago New department created, would love your input cybersecurity · 54d ago What are the dangers of posting? hacking: security in practice · 54d ago OWASP Vienna - anyone going? cybersecurity · 54d ago Interview with Upstart cybersecurity · 54d ago 18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber. cybersecurity · 54d ago Is cloud security engineer viable with my current position? cybersecurity · 54d ago UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace CyberScoop · 55d ago Cloudflare Access users: what would actually make JIT useful for you? cybersecurity · 55d ago Looking for resources on end-to-end APT attack flow summaries for detection engineering For [Blue|Purple] Teams in Cyber Defence · 55d ago Kali365 Activity Surges: Device Code Phishing Is Scaling Fast Malware Analysis & Reports · 55d ago eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels cybersecurity · 55d ago The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire For [Blue|Purple] Teams in Cyber Defence · 55d ago Questions regarding Ubuntu 24 LTS hardening cybersecurity · 55d ago Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho. cybersecurity · 55d ago Honest question about OT Security Engineer work life in India cybersecurity · 55d ago Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning) cybersecurity · 55d ago AI Security cybersecurity · 55d ago Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor cybersecurity · 55d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP For [Blue|Purple] Teams in Cyber Defence · 55d ago 🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents cybersecurity · 55d ago Latin American Cybercriminals Hoover Up Government Data darkreading · 55d ago Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint For [Blue|Purple] Teams in Cyber Defence · 55d ago AI-Assisted Exploit Development Outpaces Scanner Detection darkreading · 55d ago Building Detection Engineering on AWS from scratch — roast my plan cybersecurity · 55d ago Building Detection Engineering on AWS from scratch — roast my plan For [Blue|Purple] Teams in Cyber Defence · 55d ago New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault Technical Information Security Content & Discussion · 55d ago Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance cybersecurity · 55d ago Flipper Zero Users, What's Your Take? hacking: security in practice · 55d ago Large company with a bit of an issue free stuff hacking: security in practice · 55d ago I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA. cybersecurity · 55d ago Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning cybersecurity · 55d ago Final Year Project: Looking for non-generic IAM project ideas that solve real problems cybersecurity · 55d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Technical Information Security Content & Discussion · 55d ago GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled. cybersecurity · 55d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware For [Blue|Purple] Teams in Cyber Defence · 55d ago Breaking out of IT Helpdesk - how? cybersecurity · 55d ago A year in Cybersecurity — Where Do I Go From Here? cybersecurity · 55d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware cybersecurity · 55d ago MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Malware Analysis & Reports · 55d ago Can you enforce strong Active Directory password rules without frustrating users? BleepingComputer · 55d ago 22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber cybersecurity · 55d ago FBI: Silent Ransom Group Turns to IT Support Ploy cybersecurity · 55d ago A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate Technical Information Security Content & Discussion · 55d ago How do machine builders track Siemens/Rockwell security advisories? cybersecurity · 55d ago CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain CyberScoop · 55d ago Glassworm botnet disrupted after resilient C2 infrastructure takedown BleepingComputer · 55d ago GlassWorm Developer Supply-Chain Botnet Takedown cybersecurity · 55d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN cybersecurity · 55d ago Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV cybersecurity · 55d ago (URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active Reverse Engineering · 55d ago Got cybersec work what next ? cybersecurity · 55d ago Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables cybersecurity · 55d ago Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers cybersecurity · 55d ago HN Security - AI Reporter - Let's automate reporting in Burp Suite! Technical Information Security Content & Discussion · 55d ago Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing? cybersecurity · 55d ago GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP) cybersecurity · 55d ago nightmare eclipse is probably French here is why cybersecurity · 55d ago Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines cybersecurity · 55d ago Measuring performance of JA4/JA4H AI Model cybersecurity · 55d ago Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security darkreading · 55d ago What things are you really focused on this year? cybersecurity · 55d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 55d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 55d ago FBI warns of in-person data theft attacks from extortion gang BleepingComputer · 55d ago Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io) Malware Analysis & Reports · 55d ago Designing secure access with ZTNA For [Blue|Purple] Teams in Cyber Defence · 55d ago Hypothetical EDR spoofer Reverse Engineering · 55d ago Hypothetical EDR spoofer cybersecurity · 55d ago ISO 27001 Audit Stage 1 cybersecurity · 55d ago Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records Technical Information Security Content & Discussion · 55d ago Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That. cybersecurity · 55d ago CISA gives feds 4 days to patch actively exploited cPanel plugin flaw BleepingComputer · 55d ago Dutch police arrests suspect linked to Ajax football club hack BleepingComputer · 55d ago What to consider before asking an AI chatbot for health advice WeLiveSecurity · 55d ago What to consider before asking an AI chatbot for health advice WeLiveSecurity · 55d ago Looking for Hacker Friends to Learn☺️ cybersecurity · 55d ago Comptes Instagram et Facebook piratés et désactivés cybersecurity · 55d ago RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact Technical Information Security Content & Discussion · 55d ago How to safely disinfect a USB stick from potential malware files? cybersecurity · 55d ago Windows 11 KB5089573 update released with performance improvements BleepingComputer · 55d ago Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era Proofpoint News Feed · 55d ago Champion ethical hacker warns AI tools like Mythos will make competing harder. hacking: security in practice · 55d ago MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response For [Blue|Purple] Teams in Cyber Defence · 55d ago White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats For [Blue|Purple] Teams in Cyber Defence · 55d ago Advisory X41-2026-002: Request Host Header not Validated in Starlette For [Blue|Purple] Teams in Cyber Defence · 55d ago Top ethical hacker Chompie warns AI tools could put her out of business For [Blue|Purple] Teams in Cyber Defence · 55d ago 浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents For [Blue|Purple] Teams in Cyber Defence · 55d ago Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker. hacking: security in practice · 55d ago YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions For [Blue|Purple] Teams in Cyber Defence · 55d ago CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state For [Blue|Purple] Teams in Cyber Defence · 55d ago The Evolution of Chinese-language Phishing Services For [Blue|Purple] Teams in Cyber Defence · 55d ago Silent Ransom Group Impersonating IT Personnel through Social Engineering For [Blue|Purple] Teams in Cyber Defence · 55d ago Is anyone else concerned about how quickly AI is outpacing cloud security? cybersecurity · 55d ago The epoll UAF - an epoll uaf race in fs/eventpoll.c For [Blue|Purple] Teams in Cyber Defence · 55d ago Tycoon 2FA AiTM detection for Entra ID and Google For [Blue|Purple] Teams in Cyber Defence · 55d ago Microsoft Copilot Cowork Exfiltrates Files For [Blue|Purple] Teams in Cyber Defence · 55d ago What's a CyberSecurity job like? cybersecurity · 55d ago Microsoft Live credential stuffing cybersecurity · 55d ago I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this? cybersecurity · 55d ago Security architects- summarize your responsibilities and role cybersecurity · 55d ago Finding Work in OSINT cybersecurity · 55d ago State of SDLC Security 2026 cybersecurity · 55d ago Reported to police for coding html cybersecurity · 55d ago there's a toll in the hall now hacking: security in practice · 55d ago I Reverse Engineered Need for Speed Most Wanted Server Reverse Engineering · 55d ago Am I crazy or is something off about this Google OAuth login via Calendly hacking: security in practice · 55d ago [Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling) cybersecurity · 55d ago I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project cybersecurity · 55d ago Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover cybersecurity · 55d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators? cybersecurity · 55d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells cybersecurity · 55d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells BleepingComputer · 55d ago GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet The Last Watchdog · 55d ago Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos darkreading · 55d ago Charter confirms data breach after ShinyHunters extortion threat BleepingComputer · 55d ago Apple open-sources quantum-resistant encryption code CyberScoop · 55d ago Breaking GROK'S DEFENSES to make it HACK Real Public Websites cybersecurity · 55d ago GitHub Actions Cache Poisoning is eating open source cybersecurity · 55d ago State Cyber Leaders Push Congress for More Funding, Support darkreading · 55d ago Nightmare-Eclipse has also been banned on GitLab :DD cybersecurity · 55d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled? darkreading · 55d ago For Enterprises, Security Remains Agentic AI's Biggest Challenge darkreading · 55d ago Do we still have time before we are in the Age of the movie "Minority Report"? ↓ cybersecurity · 56d ago SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file cybersecurity · 56d ago Unpatched Sparx vulnerabilties For [Blue|Purple] Teams in Cyber Defence · 56d ago What Software Supply Chain, Water Filters, and Power Grids Have in Common cybersecurity · 56d ago QA engineer trying to move into AppSec — does this plan hold up? cybersecurity · 56d ago Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down. Malware Analysis & Reports · 56d ago Is work from anywhere really impossible to find?? cybersecurity · 56d ago Navigating Lax Load Balancers: When an Intersection Gets You Inside Technical Information Security Content & Discussion · 56d ago New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences Microsoft 365 Blog · 56d ago Cybersecurity statistics of the week (May 18th - May 24th) cybersecurity · 56d ago Engineering a Post Quantum Fortress Inside the Citadel Archite cybersecurity · 56d ago Cyber Security Analyst cybersecurity · 56d ago Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance cybersecurity · 56d ago Two layer email security tool thesis cybersecurity · 56d ago Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents Technical Information Security Content & Discussion · 56d ago sylvia: iOS Syscall Explorer for IDA 9.X For [Blue|Purple] Teams in Cyber Defence · 56d ago Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation Reverse Engineering · 56d ago OTP lockout state leaked valid-code signal, enabling OLX account takeover Technical Information Security Content & Discussion · 56d ago When OTP rate limiting fails: OLX account takeover with persistent sessions cybersecurity · 56d ago When “try again later” still tells you the OTP was correct: an account takeover story. hacking: security in practice · 56d ago Entra ID sessions revoke cybersecurity · 56d ago Anyone who attended GPCSSI before? Need some clarification cybersecurity · 56d ago How Varonis Atlas integrates Claude Compliance API for AI governance BleepingComputer · 56d ago Lost on my career path. cybersecurity · 56d ago How journalists rely on VPNs to protect press freedom Technical Information Security Content & Discussion · 56d ago EU-based folks: external pentest vs mandatory data/security training? cybersecurity · 56d ago help needed from experienced people cybersecurity · 56d ago How do you evaluate whether a privacy service is actually privacy-respecting? cybersecurity · 56d ago Which one Intellipaat or coursera which one to choose cybersecurity · 56d ago How random program can cause most of antiviruses close himself without telling himself to close Malware Analysis & Reports · 56d ago Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching Reverse Engineering · 56d ago ShadowCat: Universal optical file transfer, single html file, browser to camera hacking: security in practice · 56d ago Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1) Technical Information Security Content & Discussion · 56d ago Microsoft Defender can now automatically isolate hacked endpoints BleepingComputer · 56d ago Webinar: Too many tools are slowing network incident response BleepingComputer · 56d ago CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks cybersecurity · 56d ago India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic? cybersecurity · 56d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 56d ago ABB Terra AC All CISA Advisories · 56d ago ABB LVS MConfig All CISA Advisories · 56d ago ABB Ability Camera Connect All CISA Advisories · 56d ago Eppendorf BioFlo 320 All CISA Advisories · 56d ago ABB AbilityTM Zenon Remote Transport Vulnerability All CISA Advisories · 56d ago ABB AC500 V2 All CISA Advisories · 56d ago ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) All CISA Advisories · 56d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 56d ago Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs. cybersecurity · 56d ago Did anyone pass the SC-200 certificate recently? cybersecurity · 56d ago Honeypot cybersecurity · 56d ago passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account cybersecurity · 56d ago Career in IAM as a fresher cybersecurity · 56d ago CISA orders feds to patch actively exploited Drupal vulnerability cybersecurity · 56d ago Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure cybersecurity · 56d ago GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” cybersecurity · 56d ago Cyber security tool cybersecurity · 56d ago Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East For [Blue|Purple] Teams in Cyber Defence · 56d ago GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip For [Blue|Purple] Teams in Cyber Defence · 56d ago JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign For [Blue|Purple] Teams in Cyber Defence · 56d ago Saw this tool and it has potential cybersecurity · 56d ago 🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs cybersecurity · 56d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack For [Blue|Purple] Teams in Cyber Defence · 56d ago How I Tried to Parse a Replay from Dawn of War: Definitive Edition Reverse Engineering · 56d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files cybersecurity · 56d ago Follow up : showing Claude install random pacakage in its vm instance without asking or prompting cybersecurity · 56d ago BTMOB: A stealthy RAT burrowing deep into Android devices WeLiveSecurity · 56d ago BTMOB: A stealthy RAT burrowing deep into Android devices WeLiveSecurity · 56d ago Update Starlette Now. New severe vulnerability dropped. Technical Information Security Content & Discussion · 56d ago CISA orders feds to patch actively exploited Drupal vulnerability BleepingComputer · 56d ago Microsoft: Domain Controller lookup may fail on Windows Server 2016 BleepingComputer · 56d ago Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@" For [Blue|Purple] Teams in Cyber Defence · 56d ago The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization For [Blue|Purple] Teams in Cyber Defence · 56d ago ¿Is safe? cybersecurity · 56d ago 7-Eleven data breach exposes personal information of 185,000 people BleepingComputer · 56d ago Need help cybersecurity · 56d ago What is the best tool for masking in kali cybersecurity · 56d ago What are the best tools other than ghostTracker? cybersecurity · 56d ago y2jb un able to enject payloads hacking: security in practice · 56d ago TrapDoor Cross-Ecosystem Crypto Stealer Campaign cybersecurity · 56d ago Follow up : Steal Your Files Claude AI installing package because internet say so cybersecurity · 56d ago New to Cybersecurity: Looking for general advice & help with Nmap cybersecurity · 56d ago GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP. For [Blue|Purple] Teams in Cyber Defence · 56d ago Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal cybersecurity · 56d ago Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated. hacking: security in practice · 56d ago Looking for tech role references cybersecurity · 56d ago Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet Trend Micro Research, News, Perspectives · 56d ago How do you balance Paw? cybersecurity · 56d ago I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity. cybersecurity · 56d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Malware Analysis & Reports · 56d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Technical Information Security Content & Discussion · 56d ago Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability For [Blue|Purple] Teams in Cyber Defence · 56d ago From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security cybersecurity · 56d ago Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February cybersecurity · 56d ago What Companies are Legit? cybersecurity · 56d ago start learning cybersecurity from scratch cybersecurity · 56d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 56d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 56d ago WhatsApp users on alert after hacker drops massive dataset cybersecurity · 56d ago 17 years old going into CS — what certs should I start going after now? cybersecurity · 56d ago CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700. For [Blue|Purple] Teams in Cyber Defence · 56d ago i want to hire an osint expert cybersecurity · 56d ago Open University pros/cons cybersecurity · 56d ago How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection? cybersecurity · 56d ago Career in IAM as a fresher cybersecurity · 56d ago Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo cybersecurity · 56d ago Need Advice cybersecurity · 56d ago Why did Hack Forums lose popularity? hacking: security in practice · 57d ago Nocturne - A bin2bin code virtualizer for x86-64 PE binaries Reverse Engineering · 57d ago Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all? cybersecurity · 57d ago Someone from Germany on iOS keeps trying to login to my MSFT account cybersecurity · 57d ago AI cautionary tale... cybersecurity · 57d ago [Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing Reverse Engineering · 57d ago Anthropic’s restricted Claude Mythos model may be coming to Claude Code BleepingComputer · 57d ago AI powered red vs blue teaming cybersecurity · 57d ago Starting a security analyst student apprenticeship next week, need advice cybersecurity · 57d ago Why CVE Does Not Work for AI Agents, but AVE? cybersecurity · 57d ago SC-200 or Security+ — which actually helps land a security title cybersecurity · 57d ago How about AI having access to your hard drive. cybersecurity · 57d ago How a Date Tag Hijacks macOS via ExifTool cybersecurity · 57d ago Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools cybersecurity · 57d ago Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing Reverse Engineering · 57d ago How credential brokering prevents AI agents from compromising credentials via prompt injection Technical Information Security Content & Discussion · 57d ago How credential brokering prevents AI agents from compromising credentials via prompt injection cybersecurity · 57d ago Built a tiny daily cyber puzzle game during evenings/weekends cybersecurity · 57d ago Crypto4A launches quantum-safe rival to AWS Secrets Manager cybersecurity · 57d ago CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth Technical Information Security Content & Discussion · 57d ago ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why. cybersecurity · 57d ago Cyber Sec project cybersecurity · 57d ago ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise hacking: security in practice · 57d ago CySA+ cybersecurity · 57d ago Anyone tried Morgancyberhelp ? cybersecurity · 57d ago As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free cybersecurity · 57d ago YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos For [Blue|Purple] Teams in Cyber Defence · 57d ago Why are most of the dfir tools built to be used in windows cybersecurity · 57d ago OnlyFans mega leak reveals 340M user records, hackers claim cybersecurity · 57d ago Perplexity BumbleBee cybersecurity · 57d ago Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks Krebs on Security · 57d ago Cisco patches critical 10.0 flaw in Secure Workload APIs cybersecurity · 57d ago Suspicious ass website asking to run a terminal command (MacOS) Malware Analysis & Reports · 57d ago Shellcide: A shellcode IDE hacking: security in practice · 57d ago Stalker has my phonenumber cybersecurity · 57d ago FBI warns of Kali365 phishing service targeting Microsoft 365 accounts BleepingComputer · 57d ago I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built Reverse Engineering · 57d ago Need some guidance cybersecurity · 57d ago Are you currently allocating budget to services that remove executive PII from B2B data brokers? cybersecurity · 57d ago Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal Technical Information Security Content & Discussion · 57d ago About CEHv13 book cybersecurity · 57d ago delimiter-less string obfuscation powered by compile-time AES Reverse Engineering · 57d ago Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it For [Blue|Purple] Teams in Cyber Defence · 57d ago We open-sourced the most dangerous part of our security startup on purpose. cybersecurity · 57d ago Which conference(s) result in the most people finding jobs? cybersecurity · 57d ago My discord account has been hacked second time even after enabling two factor authentication and resetting password cybersecurity · 57d ago What's the most efficient way to learn cloud governance and compliance cybersecurity · 57d ago honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports For [Blue|Purple] Teams in Cyber Defence · 57d ago Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild. For [Blue|Purple] Teams in Cyber Defence · 57d ago Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council For [Blue|Purple] Teams in Cyber Defence · 57d ago RemotePE: The Lazarus RAT that lives in memory For [Blue|Purple] Teams in Cyber Defence · 57d ago Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer For [Blue|Purple] Teams in Cyber Defence · 57d ago Paved With Intent: ROADtools and Nation-State Tactics in the Cloud For [Blue|Purple] Teams in Cyber Defence · 57d ago Twee mannen aangehouden voor phishing - Two men arrested for phishing For [Blue|Purple] Teams in Cyber Defence · 57d ago Sharp Eyes: Mass surveillance of foreigners in China For [Blue|Purple] Teams in Cyber Defence · 57d ago Does anyone know C2 framwork and free hosting to host C2? cybersecurity · 57d ago Finding bot account hacking: security in practice · 57d ago relay_bible: Technical Reference to multiple relay techniques For [Blue|Purple] Teams in Cyber Defence · 57d ago CIS-CAT Assessor for assessment Windows server 2022 and 2025 cybersecurity · 57d ago Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec For [Blue|Purple] Teams in Cyber Defence · 57d ago The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in] For [Blue|Purple] Teams in Cyber Defence · 57d ago SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format For [Blue|Purple] Teams in Cyber Defence · 57d ago North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial For [Blue|Purple] Teams in Cyber Defence · 57d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 57d ago Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this cybersecurity · 57d ago Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks? cybersecurity · 57d ago Recent adoption of AI taught me what is Cybersecurity. cybersecurity · 57d ago The Pentagon Changed the Rules for Cybersecurity Compliance cybersecurity · 57d ago Can someone explain to a noob like me what the implications of this exploit are? cybersecurity · 57d ago SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections cybersecurity · 57d ago Window between zero-day CVE and a patch! cybersecurity · 57d ago Is it risky when a website puts on technology components with versions they used in their website? cybersecurity · 57d ago Anyone else losing their mind over this "AI Cybersecurity" hype? cybersecurity · 57d ago URL parsing behavior in a canonical tag lab cybersecurity · 57d ago How to hacking: security in practice · 57d ago Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you? cybersecurity · 57d ago Any tips for me pls cybersecurity · 57d ago How do you minimize legal liability as a solo contractor? cybersecurity · 57d ago How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing? cybersecurity · 57d ago nmap on Linux: Guide to Network Scanning and Discovery Technical Information Security Content & Discussion · 57d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 57d ago Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift. hacking: security in practice · 57d ago Provenance: A survival toolkit for an AI dominant information landscape cybersecurity · 57d ago Nmap Mastery: The Complete Guide to Network Reconnaissance hacking: security in practice · 57d ago Google wallet virtual card cloned hacking: security in practice · 57d ago [ Removed by Reddit ] cybersecurity · 57d ago Active Drupal SQLi exploitation is a real „patch now“ moment cybersecurity · 57d ago machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native) cybersecurity · 57d ago Need suggestions and input; not a promotion cybersecurity · 57d ago Need advice! cybersecurity · 57d ago New Zealand is becoming a focal point for AI-driven superhacking threats. cybersecurity · 58d ago Staged publishing and new install-time controls for npm - GitHub Changelog For [Blue|Purple] Teams in Cyber Defence · 58d ago nmap on Linux: Guide to Network Scanning and Discovery cybersecurity · 58d ago TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle cybersecurity · 58d ago How would Phishing look like in the future? (targeting agents, not humans) cybersecurity · 58d ago Best beginner/intermediate book for system security (blue team / defense / audits)? cybersecurity · 58d ago Why is on-prem and air-gapped asset inventory still such a mess? cybersecurity · 58d ago keep getting MS authentication sign in attempts? cybersecurity · 58d ago Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES For [Blue|Purple] Teams in Cyber Defence · 58d ago Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud For [Blue|Purple] Teams in Cyber Defence · 58d ago Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow For [Blue|Purple] Teams in Cyber Defence · 58d ago The Future and Past of Residential Proxies For [Blue|Purple] Teams in Cyber Defence · 58d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 58d ago Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy For [Blue|Purple] Teams in Cyber Defence · 58d ago Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware For [Blue|Purple] Teams in Cyber Defence · 58d ago A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software For [Blue|Purple] Teams in Cyber Defence · 58d ago Prompt Injection finally broke my brain a little. My first article as a security student. Technical Information Security Content & Discussion · 58d ago Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows For [Blue|Purple] Teams in Cyber Defence · 58d ago Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 58d ago Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes For [Blue|Purple] Teams in Cyber Defence · 58d ago mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. For [Blue|Purple] Teams in Cyber Defence · 58d ago keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust. For [Blue|Purple] Teams in Cyber Defence · 58d ago np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation. For [Blue|Purple] Teams in Cyber Defence · 58d ago Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up. For [Blue|Purple] Teams in Cyber Defence · 58d ago OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ For [Blue|Purple] Teams in Cyber Defence · 58d ago Megalodon: Mass GitHub Repo Backdooring via CI Workflows For [Blue|Purple] Teams in Cyber Defence · 58d ago Silly issue cybersecurity · 58d ago FatGid - FreeBSD 14.x kernel LPE For [Blue|Purple] Teams in Cyber Defence · 58d ago Manage [VSCode] extensions in enterprise environments For [Blue|Purple] Teams in Cyber Defence · 58d ago angr: A powerful and user-friendly binary analysis platform! For [Blue|Purple] Teams in Cyber Defence · 58d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware For [Blue|Purple] Teams in Cyber Defence · 58d ago Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign BleepingComputer · 58d ago How Attackers Force Microsoft to Send Phishing Emails For [Blue|Purple] Teams in Cyber Defence · 58d ago Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects For [Blue|Purple] Teams in Cyber Defence · 58d ago Microsoft Authenticator App Details now exposed in Entra SignInLogs For [Blue|Purple] Teams in Cyber Defence · 58d ago Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting For [Blue|Purple] Teams in Cyber Defence · 58d ago How China-linked threat actors obtain zero-day vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 58d ago How to practice cybersecurity while studying prograaming ? cybersecurity · 58d ago Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research For [Blue|Purple] Teams in Cyber Defence · 58d ago How to Use Claude AI: A Complete Technical Beginner's Guide Technical Information Security Content & Discussion · 58d ago [AI Security] Exploring Behavioral AI for Runtime Threat Detection cybersecurity · 58d ago Podman and krun: is it pointless to harden quadlets? cybersecurity · 58d ago Monitoring for vssadmin.exe delete shadows is an absolute bare minimum For [Blue|Purple] Teams in Cyber Defence · 58d ago Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack For [Blue|Purple] Teams in Cyber Defence · 58d ago How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers For [Blue|Purple] Teams in Cyber Defence · 58d ago How to handle security researchers (and firms) without a bounty program? cybersecurity · 58d ago CVE-2026-48029: Two grid-decode bugs in libheif For [Blue|Purple] Teams in Cyber Defence · 58d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ Reverse Engineering · 58d ago workcell: Bounded local runtime and policy boundary for coding agents For [Blue|Purple] Teams in Cyber Defence · 58d ago OpenShell: OpenShell is the safe, private runtime for autonomous AI agents. For [Blue|Purple] Teams in Cyber Defence · 58d ago Product analytics is becoming a third-party breach surface cybersecurity · 58d ago How can i learn and get into red teaming? cybersecurity · 58d ago Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network cybersecurity · 58d ago I got hacked cybersecurity · 58d ago What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method? hacking: security in practice · 58d ago Soc analysts in big companies, how it looks like? cybersecurity · 58d ago Has anyone manage to reverse the macked dylib? Reverse Engineering · 58d ago CTO at NCSC Summary: week ending May 24th cybersecurity · 58d ago Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation For [Blue|Purple] Teams in Cyber Defence · 58d ago Built a SOC from scratch with no prior SOC experience For [Blue|Purple] Teams in Cyber Defence · 58d ago These special phone and app features can help protect you from spyware cybersecurity · 58d ago Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button? cybersecurity · 58d ago Capcha Code Malware cybersecurity · 58d ago getting lost when hunting cybersecurity · 58d ago How to find information behind an account? cybersecurity · 58d ago Reverse engineering circuitry in a Spacelab computer from 1980 Reverse Engineering · 58d ago Theoretical Design Concept for Post-Exploitation Browser Defense cybersecurity · 58d ago Google Certifications... cybersecurity · 58d ago How to continue when finding a possible Vulnerability but local law prohibits me from investigating further cybersecurity · 58d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks cybersecurity · 58d ago Is the CISSP still a reputable cert for getting jobs? cybersecurity · 58d ago Which of these gоv roles would fare better in the private sector? cybersecurity · 58d ago Laravel Lang packages hijacked to deploy credential-stealing malware cybersecurity · 58d ago Laravel Lang packages hijacked to deploy credential-stealing malware BleepingComputer · 58d ago Mapping binaries to EDR feature spaces cybersecurity · 58d ago Lost my number + WhatsApp account — worried about old chats, photos, and videos cybersecurity · 58d ago Proxmark5 campaign unlocked the $600k stretch goal hacking: security in practice · 58d ago ☔️🌅 STÖK · 58d ago what is the most painful or time-consuming part of your work right now?" cybersecurity · 58d ago Anthropic says Mythos has already found more than 10,000 vulnerabilities cybersecurity · 58d ago What is the experience needed for “entry level” cybersecurity jobs? cybersecurity · 58d ago Browser extension testing. cybersecurity · 59d ago GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision hacking: security in practice · 59d ago Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip? cybersecurity · 59d ago Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology Reverse Engineering · 59d ago Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback cybersecurity · 59d ago Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition cybersecurity · 59d ago Can someone recommend me some good, large universities to study cybersecurity? cybersecurity · 59d ago New guy khikhi cybersecurity · 59d ago Examples of intentional backdoors being breached? cybersecurity · 59d ago Non-Compliant Vocab cybersecurity · 59d ago CTO at NCSC Summary: week ending May 24th For [Blue|Purple] Teams in Cyber Defence · 59d ago HackTheBox - MonitorsFour IppSec · 59d ago VPN Exploitation When Patched Doesn't Mean Protected For [Blue|Purple] Teams in Cyber Defence · 59d ago Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation For [Blue|Purple] Teams in Cyber Defence · 59d ago Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites cybersecurity · 59d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 59d ago CLR-Stomp: .NET CLR-Stomping For [Blue|Purple] Teams in Cyber Defence · 59d ago Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes BleepingComputer · 59d ago infostealers just spawned a 5,000+ repo github supply chain attack cybersecurity · 59d ago The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis cybersecurity · 59d ago Doom running on a Kids Video Walkie Talkie hacking: security in practice · 59d ago GRO frag cybersecurity · 59d ago We audited 12K n8n templates: most have critical vulnerabilities cybersecurity · 59d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 59d ago Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week cybersecurity · 59d ago Mitigated Vulnerabilities by Vendor as Feed cybersecurity · 59d ago From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence For [Blue|Purple] Teams in Cyber Defence · 59d ago Introducing Showboat: A new malware family taunts defenses and targets international telecom firms For [Blue|Purple] Teams in Cyber Defence · 59d ago Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor For [Blue|Purple] Teams in Cyber Defence · 59d ago Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors cybersecurity · 59d ago A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories cybersecurity · 59d ago Where can I find the tools freely on internet to practice for soc analyst cybersecurity · 59d ago Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX. hacking: security in practice · 59d ago Pardon MIE?: how Mythos did not bypass Apple MIE Technical Information Security Content & Discussion · 59d ago residential proxies cybersecurity · 59d ago Recommendations for getting started in cybersecurity cybersecurity · 59d ago Linux mint or Ubuntu for complete beginner cybersecurity · 59d ago Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. cybersecurity · 59d ago Pentesting company recommendation cybersecurity · 59d ago Have you ever failed a certification exam? cybersecurity · 59d ago AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance cybersecurity · 59d ago This ID Verification company store users biometrics? (FaceTec) hacking: security in practice · 59d ago What do i need to learn to get into application security? Which Degrees/Certs cybersecurity · 59d ago RSAC online membership? Is it worth it? cybersecurity · 59d ago Playwright version that lets AI-Agents navigate the web hacking: security in practice · 59d ago Can someone give me a detailed roadmap for becoming a SOC Analyst? cybersecurity · 59d ago Puedo conseguir trabajo? cybersecurity · 59d ago How do i learn networking for cyber security? cybersecurity · 59d ago What's going to be Hacking and Cybersecurity's future is gonna be like? cybersecurity · 59d ago Cyber security placement - Interview Help cybersecurity · 59d ago CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module Technical Information Security Content & Discussion · 59d ago Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge cybersecurity · 59d ago AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22) For [Blue|Purple] Teams in Cyber Defence · 60d ago CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22) Reverse Engineering · 60d ago AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22 Technical Information Security Content & Discussion · 60d ago Feedback needed cybersecurity · 60d ago GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks. For [Blue|Purple] Teams in Cyber Defence · 60d ago Handoff Transition cybersecurity · 60d ago Where to learn the ins and outs of the computer itself hacking: security in practice · 60d ago Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't) Technical Information Security Content & Discussion · 60d ago Just added an interactive security map showing exactly what the server sees (and doesn't) cybersecurity · 60d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks BleepingComputer · 60d ago Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns For [Blue|Purple] Teams in Cyber Defence · 60d ago Trend Micro warns of Apex One zero-day exploited in the wild cybersecurity · 60d ago Lawmakers Demand Answers as CISA Tries to Contain Data Leak cybersecurity · 60d ago Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL? For [Blue|Purple] Teams in Cyber Defence · 60d ago https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/ cybersecurity · 60d ago Harvard and 140 other legitimate websites compromised Malware Analysis & Reports · 60d ago Harvard and 140 other legitimate websites compromised cybersecurity · 60d ago Votre Satisfaction Dans Votre Travail cybersecurity · 60d ago Soft Skills for the Job Market: Communication The Cyber Mentors · 60d ago 5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. cybersecurity · 60d ago Former US execs plead guilty to aiding tech support scammers BleepingComputer · 60d ago Browser session theft is quietly becoming more dangerous than password theft Malware Analysis & Reports · 60d ago US states urge Congress to renew cybersecurity grants cybersecurity · 60d ago Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension Technical Information Security Content & Discussion · 60d ago Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours Malware Analysis & Reports · 60d ago Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes Reverse Engineering · 60d ago The CISO's Guide to IDE Security in 2026 cybersecurity · 60d ago Help with evilginx cybersecurity · 60d ago Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets Technical Information Security Content & Discussion · 60d ago Watching AI Brain Drain on Attackers in Real Time cybersecurity · 60d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 60d ago api-rta cyberwarfare labs cybersecurity · 60d ago Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator hacking: security in practice · 60d ago Trend Micro warns of Apex One zero-day exploited in the wild BleepingComputer · 60d ago I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner For [Blue|Purple] Teams in Cyber Defence · 60d ago The Worm That Deletes Your Entire Computer | Threat Wire Hak5 · 60d ago Drupal: Critical SQL injection flaw now targeted in attacks BleepingComputer · 60d ago Why Chargebacks are Just One Piece of the Fraud Puzzle BleepingComputer · 60d ago Does Security Implement Fixes? cybersecurity · 60d ago Ultimate Cybersecurity without needing AV ect? cybersecurity · 60d ago Hack your corrupt company. Sell their secrets to the black market hacking: security in practice · 60d ago User Onboarding with IAM cybersecurity · 60d ago Ubiquiti patches three max severity UniFi OS vulnerabilities BleepingComputer · 60d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 60d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 60d ago Data breach in name of protest Technical Information Security Content & Discussion · 60d ago qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb) Reverse Engineering · 60d ago pnpm 11 Might Finally Be a Better Default Than npm Technical Information Security Content & Discussion · 60d ago pnpm 11 Might Finally Be a Better Default Than npm cybersecurity · 60d ago 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs cybersecurity · 60d ago Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria cybersecurity · 60d ago AI-generated reporting: Lessons learned from Cisco Talos Incident Response For [Blue|Purple] Teams in Cyber Defence · 60d ago CrabLoader: A PoC Cobalt Strike UDRL written in Rust For [Blue|Purple] Teams in Cyber Defence · 60d ago The 429 Microsoft Graph Mystery For [Blue|Purple] Teams in Cyber Defence · 60d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 60d ago Azure Tenant Enumeration is Dead For [Blue|Purple] Teams in Cyber Defence · 60d ago A Deep Dive into Codex Windows Sandbox For [Blue|Purple] Teams in Cyber Defence · 60d ago Striga: Lifting x86 to LLVM IR with Python For [Blue|Purple] Teams in Cyber Defence · 60d ago Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip" cybersecurity · 60d ago Looking for a cybersecurity professional to interview for a university project (interview in French) cybersecurity · 60d ago US and Canada arrest and charge suspected Kimwolf botnet admin BleepingComputer · 60d ago Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise WeLiveSecurity · 60d ago veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker. For [Blue|Purple] Teams in Cyber Defence · 60d ago Windows BitLocker Security Feature Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 60d ago CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility For [Blue|Purple] Teams in Cyber Defence · 60d ago Google API keys keep working after you delete them long enough to be exploited For [Blue|Purple] Teams in Cyber Defence · 60d ago Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? For [Blue|Purple] Teams in Cyber Defence · 60d ago North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT For [Blue|Purple] Teams in Cyber Defence · 60d ago Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit For [Blue|Purple] Teams in Cyber Defence · 60d ago Safe read-only check script for Copy Fail / CVE-2026-31431 cybersecurity · 60d ago New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible? cybersecurity · 60d ago Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names) For [Blue|Purple] Teams in Cyber Defence · 60d ago [TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly cybersecurity · 60d ago Cisco used AI to write security incident reports, with mixed results cybersecurity · 60d ago [TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM) cybersecurity · 60d ago Reverse Engineered Google reCAPTCHA Reverse Engineering · 60d ago Cyber Insurance Actuary Looking for Educational Resources cybersecurity · 60d ago As a bank , how do i give protected access to claude to my team? cybersecurity · 60d ago Can seasonal Apple Store employees apply for internal IT/cybersecurity roles? cybersecurity · 60d ago Reliable IP reputation check tools besides IPQS?(for work) cybersecurity · 60d ago 🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget hacking: security in practice · 60d ago Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026) cybersecurity · 60d ago Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins cybersecurity · 60d ago Hacked by Rat Tools for 2.5 years. cybersecurity · 60d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Trend Micro Research, News, Perspectives · 60d ago A TL;DR on Dirty Frag #cybersecurity #threatwire @endingwithali Hak5 · 60d ago Google’s Silent AI Install: What They’re Hiding in Your Files #cybersecurity @endi Hak5 · 60d ago Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada CyberScoop · 60d ago Google API Keys Remain Active After Deletion cybersecurity · 60d ago Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens For [Blue|Purple] Teams in Cyber Defence · 60d ago how do cyber sec consultants and pentesters actually get new clients? cybersecurity · 60d ago Post Incident Paranoia? cybersecurity · 60d ago Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector cybersecurity · 60d ago Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity? cybersecurity · 60d ago Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready cybersecurity · 60d ago You can counter MEMZ with Krotten in XP cybersecurity · 60d ago What are the most effective ways to do Blackbox testing? cybersecurity · 60d ago Npm registry sets stage for more secure package publishing cybersecurity · 60d ago Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support cybersecurity · 60d ago Megalodon: CI/CD Malware Spreading Across GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 60d ago Lawmakers from both parties say CISA cuts have gone too far CyberScoop · 60d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave Technical Information Security Content & Discussion · 60d ago Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK cybersecurity · 60d ago Is the Cybercorps SFS still worth it? cybersecurity · 60d ago Microsoft warns hackers are exploiting password resets to gain access to user accounts cybersecurity · 60d ago Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame cybersecurity · 61d ago How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account Malware Analysis & Reports · 61d ago WORM USB drives cybersecurity · 61d ago An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model? cybersecurity · 61d ago Trump postpones executive order focused on AI security CyberScoop · 61d ago CISOs - Holding the Line cybersecurity · 61d ago [Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled Technical Information Security Content & Discussion · 61d ago Google accidentally exposed details of unfixed Chromium flaw BleepingComputer · 61d ago Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware Reverse Engineering · 61d ago A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale cybersecurity · 61d ago Security Scroll Down? cybersecurity · 61d ago mass github repo backdooring via CI workflows(Megalodon) cybersecurity · 61d ago I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP Reverse Engineering · 61d ago 📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity. For [Blue|Purple] Teams in Cyber Defence · 61d ago CISA chief frets about open-source vulnerabilities, delayed security improvements CyberScoop · 61d ago Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit? cybersecurity · 61d ago Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks For [Blue|Purple] Teams in Cyber Defence · 61d ago GitHub Actions Cache Poisoning is eating open source Technical Information Security Content & Discussion · 61d ago European authorities take down prolific cybercrime VPN service CyberScoop · 61d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Reverse Engineering · 61d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox For [Blue|Purple] Teams in Cyber Defence · 61d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox cybersecurity · 61d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Technical Information Security Content & Discussion · 61d ago CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat Technical Information Security Content & Discussion · 61d ago beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA For [Blue|Purple] Teams in Cyber Defence · 61d ago FatGid - FreeBSD 14.x kernel LPE Technical Information Security Content & Discussion · 61d ago DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind cybersecurity · 61d ago FaceTec (ID verification) company appears to store user biometrics cybersecurity · 61d ago Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) Technical Information Security Content & Discussion · 61d ago Apple blocked over $11 billion in App Store fraud in 6 years BleepingComputer · 61d ago CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication cybersecurity · 61d ago CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat hacking: security in practice · 61d ago It seems that FaceTec (ID Verification company) allows for storage of user biometrics cybersecurity · 61d ago Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check. cybersecurity · 61d ago Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data cybersecurity · 61d ago This ID verification company allows for storage of biometric data? hacking: security in practice · 61d ago What Questions Do You Ask During SSP Control Interviews? cybersecurity · 61d ago Feed The Cat BackDoor cybersecurity · 61d ago Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet BleepingComputer · 61d ago Chinese hackers target telcos with new Linux, Windows malware BleepingComputer · 61d ago Max severity Cisco Secure Workload flaw gives Site Admin privileges BleepingComputer · 61d ago Flipper One - Asking for help from the community cybersecurity · 61d ago Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 61d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 61d ago Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign For [Blue|Purple] Teams in Cyber Defence · 61d ago Police seize “First VPN” service used in ransomware, data theft attacks BleepingComputer · 61d ago Flipper One — tech specs cybersecurity · 61d ago Architecture Zero Trust détaillée cybersecurity · 61d ago I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :) hacking: security in practice · 61d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 61d ago ABB Terra AC Wallbox All CISA Advisories · 61d ago Hitachi Energy GMS600 All CISA Advisories · 61d ago ABB B&R Automation Studio All CISA Advisories · 61d ago ABB B&R Automation Runtime All CISA Advisories · 61d ago ABB B&R PCs All CISA Advisories · 61d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 61d ago Cybersecurity in Healthcare cybersecurity · 61d ago Staged publishing for npm packages | npm Docs cybersecurity · 61d ago 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though) cybersecurity · 61d ago Neither MFA, Passkey, nor trusted IP help here cybersecurity · 61d ago cyber security remote cybersecurity · 61d ago Database of Malicious Browser Extensions Malware Analysis & Reports · 61d ago Flipper One project needs community help to build open Linux platform BleepingComputer · 61d ago SeekYou — one input, 15 recon sources, one report. hacking: security in practice · 61d ago I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries Reverse Engineering · 61d ago CSIRT incident response cybersecurity · 61d ago The readiness paradox: Why a false sense of cyber confidence is becoming a liability CyberScoop · 61d ago Trying to find a graduate role cybersecurity · 61d ago bypass internet restrictions hacking: security in practice · 61d ago GitHub ~3,800 internal repos compromised through a malicious VS Code extension Technical Information Security Content & Discussion · 61d ago I’ve got 99 problems, and IOCX isn’t one. Malware Analysis & Reports · 61d ago Microsoft warns of new Defender zero-days exploited in attacks cybersecurity · 61d ago From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree For [Blue|Purple] Teams in Cyber Defence · 61d ago How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102) For [Blue|Purple] Teams in Cyber Defence · 61d ago Iran-linked Operators Suspected in ATG Breaches For [Blue|Purple] Teams in Cyber Defence · 61d ago Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs For [Blue|Purple] Teams in Cyber Defence · 61d ago Compromised Nx Console version 18.95.0 For [Blue|Purple] Teams in Cyber Defence · 61d ago CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path For [Blue|Purple] Teams in Cyber Defence · 61d ago From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat For [Blue|Purple] Teams in Cyber Defence · 61d ago Microsoft warns of new Defender zero-days exploited in attacks BleepingComputer · 61d ago Webworm: New burrowing techniques For [Blue|Purple] Teams in Cyber Defence · 61d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) For [Blue|Purple] Teams in Cyber Defence · 61d ago what is the best security app option for pixel8a? cybersecurity · 61d ago How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) cybersecurity · 61d ago IoT Security cybersecurity · 61d ago GitHub links repo breach to TanStack npm supply-chain attack cybersecurity · 61d ago GitHub links repo breach to TanStack npm supply-chain attack BleepingComputer · 61d ago Another working Linux LPE exploit is out. How are teams treating local-only bugs now? cybersecurity · 61d ago Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks cybersecurity · 61d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 61d ago Google publishes exploit code threatening millions of Chromium users cybersecurity · 61d ago landing a remote Vulnerability Management role cybersecurity · 61d ago Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case. cybersecurity · 61d ago I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting? cybersecurity · 61d ago Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit cybersecurity · 61d ago Can someone unlock a list of the 500-1000 most visited websites online? hacking: security in practice · 61d ago One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign Trend Micro Research, News, Perspectives · 61d ago Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure For [Blue|Purple] Teams in Cyber Defence · 61d ago Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation For [Blue|Purple] Teams in Cyber Defence · 61d ago Wordlist generator based on WordNet graphs + LLM hacking: security in practice · 61d ago What volume of TPRM do you handle per month? cybersecurity · 61d ago GitHub’s Fake Engagement Problem Is Hiding in Plain Sight For [Blue|Purple] Teams in Cyber Defence · 61d ago Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR) For [Blue|Purple] Teams in Cyber Defence · 61d ago Ukraine identifies infostealer operator tied to 28,000 stolen accounts BleepingComputer · 61d ago Hackers bypass SonicWall VPN MFA due to incomplete patching BleepingComputer · 61d ago GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam) Reverse Engineering · 61d ago safest virtual machine? cybersecurity · 61d ago Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration cybersecurity · 61d ago Meet Rampart and Clarity, Microsoft’s new red team combo AI agents CyberScoop · 61d ago wordpress memberpress hacking: security in practice · 61d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware cybersecurity · 61d ago Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage For [Blue|Purple] Teams in Cyber Defence · 61d ago GitHub notifications cybersecurity · 61d ago The Open Source USB Drive Built for Privacy hacking: security in practice · 62d ago Is there no more privacy left in the world? cybersecurity · 62d ago AI Agents defeat obfuscated JavaScript in 10 minutes Reverse Engineering · 62d ago Microsoft Edge had a password blunder, and it raises a bigger browser trust problem cybersecurity · 62d ago Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network cybersecurity · 62d ago Aconselhamento / mini texto cybersecurity · 62d ago CISA with an absolutely embarrassing data leak. cybersecurity · 62d ago Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys cybersecurity · 62d ago Anyone else feeling like static AppSec workflows are starting to hit limits? cybersecurity · 62d ago Is someone trying to hack me? hacking: security in practice · 62d ago What is it Wednesdays: Episode 0002 Reverse Engineering · 62d ago GitHub breach highlights developer tools as part of attack surface cybersecurity · 62d ago Why do some malware use unique user-agent strings? cybersecurity · 62d ago Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability Cisco Security Advisory · 62d ago Encrypted emails bypassing email security tool cybersecurity · 62d ago Grafana breach caused by missed token rotation after TanStack attack BleepingComputer · 62d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era For [Blue|Purple] Teams in Cyber Defence · 62d ago GitHub says internal repositories were impacted in poisoned VS Code extension attack CyberScoop · 62d ago Ctf groups cybersecurity · 62d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era cybersecurity · 62d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era Technical Information Security Content & Discussion · 62d ago cpu backdoor hacking: security in practice · 62d ago CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis Technical Information Security Content & Discussion · 62d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 62d ago Opensource that automatically scans your git repos for breaches cybersecurity · 62d ago 5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready For [Blue|Purple] Teams in Cyber Defence · 62d ago TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post) Reverse Engineering · 62d ago Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing Reverse Engineering · 62d ago Identity Alone Isn't Enough: Why Device Security Has to Share the Load BleepingComputer · 62d ago CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers Technical Information Security Content & Discussion · 62d ago Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online Technical Information Security Content & Discussion · 62d ago CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed. cybersecurity · 62d ago Your developers are deploying agents in your production environment right now. You have no governance for it. cybersecurity · 62d ago Technical analysis of CVE-2026-34472 in ZTE H188A router firmware hacking: security in practice · 62d ago ¿Como me preparo para EC-Council CSA? cybersecurity · 62d ago The IBM X-Force Index 2026 explains all three in one finding. cybersecurity · 62d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 62d ago Securing iPad's question cybersecurity · 62d ago Cybersecurity 101 cybersecurity · 62d ago What would this job role be? cybersecurity · 62d ago Drupal critical update to fix bug with high exploitation risk BleepingComputer · 62d ago MSPs & MSSPs suck cybersecurity · 62d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 62d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog All CISA Advisories · 62d ago [ Removed by Reddit ] cybersecurity · 62d ago GitHub hit by a compromised VSCode extension Technical Information Security Content & Discussion · 62d ago Crossroads cybersecurity · 62d ago Advice regarding "SOC" job that automates everything cybersecurity · 62d ago Is this Medium article about "NetMirror" malware legit? cybersecurity · 62d ago AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon? cybersecurity · 62d ago Developer tooling is part of the attack surface before a project is even run cybersecurity · 62d ago Exploit released for new PinTheft Arch Linux root escalation flaw BleepingComputer · 62d ago How to build .NET obfuscator Reverse Engineering · 62d ago botguard-token-generator / a google botguard token gen using only requests...? Reverse Engineering · 62d ago Remote Process Read Primitive via NtCreateThreadEx Exit Code For [Blue|Purple] Teams in Cyber Defence · 62d ago GUEST ESSAY: AI can speed up communication, but it can also weaken human connection The Last Watchdog · 62d ago How the hell do you manage developers, their code, their apps? cybersecurity · 62d ago Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed cybersecurity · 62d ago aimap: Discover Exposed AI Services For [Blue|Purple] Teams in Cyber Defence · 62d ago FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation. For [Blue|Purple] Teams in Cyber Defence · 62d ago Ongoing development hacking: security in practice · 62d ago Webworm: New burrowing techniques WeLiveSecurity · 62d ago Why China Is Now a Peer Competitor to the United States in Cyberspace For [Blue|Purple] Teams in Cyber Defence · 62d ago When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax Technical Information Security Content & Discussion · 62d ago Do people still rely on antivirus software in 2026, or is built-in security enough now? cybersecurity · 62d ago For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks? hacking: security in practice · 62d ago GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories cybersecurity · 62d ago GitHub confirms breach of 3,800 repos via malicious VSCode extension BleepingComputer · 62d ago Automatic CLI for spinning up vulnerable labs + objectives cybersecurity · 62d ago Hackers found a way around Intel CET—PLaTypus locks down library jumps hacking: security in practice · 62d ago ISO/IEC 27701 scenario question cybersecurity · 62d ago Discord rolls out end-to-end encryption on voice, video calls cybersecurity · 62d ago Microsoft shares mitigation for YellowKey Windows zero-day BleepingComputer · 62d ago nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings For [Blue|Purple] Teams in Cyber Defence · 62d ago GitHub investigates internal repositories breach claimed by TeamPCP cybersecurity · 62d ago Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt For [Blue|Purple] Teams in Cyber Defence · 62d ago We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. For [Blue|Purple] Teams in Cyber Defence · 62d ago Two AI-based science assistants succeed with drug-retargeting tasks cybersecurity · 62d ago GitHub investigates internal repositories breach claimed by TeamPCP hacking: security in practice · 62d ago Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings) For [Blue|Purple] Teams in Cyber Defence · 62d ago America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames cybersecurity · 62d ago An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now. cybersecurity · 62d ago We audited 12K n8n templates: most have critical vulnerabilities Technical Information Security Content & Discussion · 62d ago GitHub investigates internal repositories breach claimed by TeamPCP BleepingComputer · 62d ago Veilgate - Deception proxy Technical Information Security Content & Discussion · 62d ago Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild For [Blue|Purple] Teams in Cyber Defence · 62d ago New to cybersecurity cybersecurity · 62d ago Anyone interview or work with Moxfive? cybersecurity · 62d ago A stealth Firefox version that passes all anti-bot and CAPTCHA cybersecurity · 62d ago mkPIVM - a polymorphic position-independent shellcode virtualizer cybersecurity · 62d ago Started in IT and need a Cybersecurity Roadmap with my Useless Degree! cybersecurity · 62d ago GitHub announces internal data breached. cybersecurity · 62d ago Roadmap to Cybersecurity roles cybersecurity · 62d ago Hackers: What age did you start? Where did you start, especially in practicing your skills? hacking: security in practice · 62d ago CISA credential leak raises alarms, and Capitol Hill demands answers CyberScoop · 62d ago Malware installed without literally doing anything? cybersecurity · 62d ago Max-severity flaw in ChromaDB for AI apps allows server hijacking BleepingComputer · 62d ago CTFs cybersecurity · 62d ago Can't access anything Malware Analysis & Reports · 62d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware BleepingComputer · 62d ago How to watch a private video on Youtube? hacking: security in practice · 62d ago Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches CyberScoop · 62d ago Sleeping Agent: Silent persistent C2 through Web Push Technical Information Security Content & Discussion · 62d ago Crossroads cybersecurity · 62d ago Discord rolls out end-to-end encryption on voice, video calls BleepingComputer · 62d ago Canara Bank SuRaksha Cyber Hackathon 2.0, cybersecurity · 62d ago Eight Leading U.S. Communications Firms Form C2 ISAC For [Blue|Purple] Teams in Cyber Defence · 62d ago Can I do anything cool with this network controller? hacking: security in practice · 62d ago News alert: Orchid Security study finds invisible identities now outnumber managed accounts The Last Watchdog · 62d ago Anti BOT Tipps und Tricks gesucht. cybersecurity · 62d ago FBI: Americans lost over $388 million to scams using crypto ATMs in 2025 BleepingComputer · 62d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security cybersecurity · 62d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 62d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security Technical Information Security Content & Discussion · 62d ago New to Cybersecurity cybersecurity · 62d ago Microsoft Self-Service Password Reset abused in Azure data theft attacks BleepingComputer · 62d ago Micro controller safety? hacking: security in practice · 63d ago Is the ISC2 Certified in Cybersecurity worth it? cybersecurity · 63d ago Average Days to Close by Source CNAPP Severity Tag 2026 cybersecurity · 63d ago I want free nmap resource cybersecurity · 63d ago If I clear browser history regularly, does it reduce the chances of malware that target browser data? cybersecurity · 63d ago What is next after 1.5 Year as Security Analyst? cybersecurity · 63d ago Analysis advice cybersecurity · 63d ago Stop me if you heard this one before... (YellowKey related) cybersecurity · 63d ago UAC-0184: From HTA to a Signed Network Stack For [Blue|Purple] Teams in Cyber Defence · 63d ago Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe? cybersecurity · 63d ago Microsoft plans to improve Windows 11 driver quality in 2026 BleepingComputer · 63d ago Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing) Reverse Engineering · 63d ago Looking for advice: where should I post/publish CVE write-ups? cybersecurity · 63d ago Microsoft blames macOS update for undismissible Teams location prompts BleepingComputer · 63d ago CISA Admin Leaked AWS GovCloud Keys on Github hacking: security in practice · 63d ago New GMKtec M7 Ultra appears to be infected. Beware of the malware! Malware Analysis & Reports · 63d ago Cybersecurity statistics of the week (May 11th - May 17th) cybersecurity · 63d ago How can I test my website locally for cybersecurity? cybersecurity · 63d ago Mini Shai-Hulud returns, compromising hundreds of npm packages CyberScoop · 63d ago Use of coding in security operations cybersecurity · 63d ago Decompilation of DSP Code using IDA Pro hacking: security in practice · 63d ago Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz cybersecurity · 63d ago Microsoft disrupts cybercrime service that abused software verification systems en masse cybersecurity · 63d ago I've built an open source honeypot probe database accessible via curl, http and mcp cybersecurity · 63d ago New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here For [Blue|Purple] Teams in Cyber Defence · 63d ago Deep dive into the object creation flow in Windows - PART 4: Handle table internals. Reverse Engineering · 63d ago 6,000+ Automatic Tank Gauges Exposed With No Authentication cybersecurity · 63d ago Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email? cybersecurity · 63d ago How Storm-2949 turned a compromised identity into a cloud-wide breach For [Blue|Purple] Teams in Cyber Defence · 63d ago Microsoft disrupts cybercrime service that abused software verification systems en masse CyberScoop · 63d ago How Storm-2949 turned a compromised identity into a cloud-wide breach Technical Information Security Content & Discussion · 63d ago If humans are the weakest link, why won't companies evolve? cybersecurity · 63d ago Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?" cybersecurity · 63d ago New Shai-Hulud malware wave compromises 600 npm packages BleepingComputer · 63d ago 7-Eleven confirms data breach claimed by the ShinyHunters gang BleepingComputer · 63d ago Entra ID: PIM for Groups Review For [Blue|Purple] Teams in Cyber Defence · 63d ago Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation BleepingComputer · 63d ago Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM cybersecurity · 63d ago Local transcription vs cloud transcription, which actually feels safer? cybersecurity · 63d ago Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today? cybersecurity · 63d ago Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise cybersecurity · 63d ago TeamPCP compromises NPM maintainer with over 540 packages For [Blue|Purple] Teams in Cyber Defence · 63d ago Shai-Hulud source leak is turning npm malware into a copycat problem cybersecurity · 63d ago Webinar: The hidden bottlenecks in network incident response BleepingComputer · 63d ago Framework for Preventing Secret Ideas from Leakage cybersecurity · 63d ago Kieback & Peter DDC Building Controllers All CISA Advisories · 63d ago Siemens RUGGEDCOM APE1808 Devices All CISA Advisories · 63d ago ABB CoreSense HM and CoreSense M10 All CISA Advisories · 63d ago ScadaBR All CISA Advisories · 63d ago ZKTeco CCTV Cameras All CISA Advisories · 63d ago Local LLM for building AI Security platform cybersecurity · 63d ago SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access cybersecurity · 63d ago Emerging Cyber security niches cybersecurity · 63d ago ISO/IEC 27701 cybersecurity · 63d ago Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware Reverse Engineering · 63d ago Solo dev building a terminal-heavy hacking game inspired by corporate security cybersecurity · 63d ago Microsoft confirms patching issues in restricted Windows networks BleepingComputer · 63d ago Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations cybersecurity · 63d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments Technical Information Security Content & Discussion · 63d ago CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing Technical Information Security Content & Discussion · 63d ago CS/IT Student Looking to Grow My LinkedIn Network 😃 cybersecurity · 63d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) hacking: security in practice · 63d ago Open-source Hermes bytecode decompiler for React Native apps (Rust) Reverse Engineering · 63d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) cybersecurity · 63d ago Is Amazon Cognito a good choice long term? Alternatives? cybersecurity · 63d ago Was hacking easier in the 80s and 90s and early 2000s? cybersecurity · 63d ago Need some Advice in SOAR heavy environment cybersecurity · 63d ago Trying to find serious builders in cybersecurity - not just “let’s build” conversations cybersecurity · 63d ago Hermes bytecode decompiler (Rust) - sharing my friend’s project Reverse Engineering · 63d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields hacking: security in practice · 63d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields Technical Information Security Content & Discussion · 63d ago Active Supply Chain Attack Compromises @antv Packages on npm... For [Blue|Purple] Teams in Cyber Defence · 63d ago AI Phishing cybersecurity · 63d ago The quest for greater tech independence WeLiveSecurity · 63d ago One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals cybersecurity · 63d ago When DMCA Comes Knocking - A YouTube Creator Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 63d ago [Cloudflare] Project Glasswing: what Mythos showed us For [Blue|Purple] Teams in Cyber Defence · 63d ago vpn explained the simple version that actually makes sense Malware Analysis & Reports · 63d ago How easy is it to get into the cyber security field? cybersecurity · 63d ago Forza Designer 6 Reverse Engineering · 63d ago 314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js cybersecurity · 63d ago Built a full disassembler & decompiler for Reverse Engineering | Free and open source. hacking: security in practice · 63d ago Built a full disassembler & decompiler | Free and open source. Reverse Engineering · 63d ago Slopinator - a poisoned GitHub repository generator hacking: security in practice · 63d ago Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start? cybersecurity · 63d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) Technical Information Security Content & Discussion · 63d ago ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo cybersecurity · 63d ago CEH/CPENT vs OSCP vs GPEN cybersecurity · 63d ago ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro” cybersecurity · 63d ago CISA Contractor Admin Leaked AWS GovCloud Keys on Github cybersecurity · 63d ago Made a shell greeter that generates a unique rocket every time you open a terminal tab hacking: security in practice · 63d ago Suspecious activity in my account cybersecurity · 63d ago Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud Trend Micro Research, News, Perspectives · 63d ago Is it safe to use my first name and middle name on platforms? cybersecurity · 63d ago Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice. cybersecurity · 63d ago Just received an email from shinyhunters about their amtrack hack cybersecurity · 63d ago Just received an email from shinyhackers about their amtrack hack hacking: security in practice · 63d ago Flipper Zero (or Alternatives)? hacking: security in practice · 63d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access cybersecurity · 63d ago INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers BleepingComputer · 63d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access hacking: security in practice · 63d ago SHub macOS infostealer variant spoofs Apple security updates BleepingComputer · 63d ago Bywaf: an auditable Python commandlet framework for chained pentest workflows cybersecurity · 63d ago For anyone currently working in a SOC: cybersecurity · 63d ago Fellow Tier 1 SOC/Security Analysts - What does your day to day look like? cybersecurity · 63d ago The quiet death of behavioral anti-bot and the pivot to hardware ZKPs Technical Information Security Content & Discussion · 63d ago SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain For [Blue|Purple] Teams in Cyber Defence · 63d ago AI might cut false positives, but it won’t stop the slop CyberScoop · 63d ago Recent WhatsApp hacks hacking: security in practice · 63d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 63d ago How do you threat hunt for RMM tools in environments where RMM is all over the place? cybersecurity · 63d ago Decompilation projects and N64 Recompiled PC ports (May 2026) Reverse Engineering · 64d ago Microsoft - "your single use code" email when it was not requested by yourself cybersecurity · 64d ago Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa CyberScoop · 64d ago Directory of vendor security questionnaires cybersecurity · 64d ago Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised cybersecurity · 64d ago I wrote an async scanner that runs about 9x faster than nmap for discovery. hacking: security in practice · 64d ago 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees BleepingComputer · 64d ago MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals cybersecurity · 64d ago AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems Technical Information Security Content & Discussion · 64d ago Glass - A fast and free interactive disassembler Reverse Engineering · 64d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. Technical Information Security Content & Discussion · 64d ago Leaked Shai-Hulud malware fuels new npm infostealer campaign BleepingComputer · 64d ago Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers hacking: security in practice · 64d ago Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight cybersecurity · 64d ago Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger For [Blue|Purple] Teams in Cyber Defence · 64d ago Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics For [Blue|Purple] Teams in Cyber Defence · 64d ago How is AI affecting the cybersecurity market? cybersecurity · 64d ago MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack The Last Watchdog · 64d ago MCP security cybersecurity · 64d ago YellowKey Mitigation cybersecurity · 64d ago CrystalX: unpacking a Go RAT through three encrypted layers For [Blue|Purple] Teams in Cyber Defence · 64d ago Anyone else on the receiving end of ShinyHunters extortion email? cybersecurity · 64d ago Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs cybersecurity · 64d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Reverse Engineering · 64d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Malware Analysis & Reports · 64d ago Grafana says stolen GitHub token let hackers steal codebase BleepingComputer · 64d ago What’s the biggest mistake people still make about online security in 2026? cybersecurity · 64d ago Anthropic shuts the EU out of its most advanced cyber AI model cybersecurity · 64d ago Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens] cybersecurity · 64d ago Best hotel for attending all three conferences in Vegas? cybersecurity · 64d ago What's your company's actual PQC migration plan? Not the one on paper - the real one. cybersecurity · 64d ago The down fall of bug bounties Technical Information Security Content & Discussion · 64d ago The Boring Stuff is Dangerous Now darkreading · 64d ago This GitHub README Hijacks Your AI and Spreads Like a Virus NahamSec · 64d ago New video: hacking AI coding assistants and IDEs. #bugbounty #ai NahamSec · 64d ago Does buying local cybersecurity (services/products/etc) matter to you? cybersecurity · 64d ago LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose cybersecurity · 64d ago Detection Engineering AI Maturity Framework cybersecurity · 64d ago Microsoft code cybersecurity · 64d ago TanStack Supply Chain Attack (And How to Lock Down GitHub Actions) Technical Information Security Content & Discussion · 64d ago Microsoft testing adjustable taskbar, Start menu in Windows 11 BleepingComputer · 64d ago Microsoft confirms Windows 11 security update install issues cybersecurity · 64d ago Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ cybersecurity · 64d ago Exploit available for new DirtyDecrypt Linux root escalation flaw cybersecurity · 64d ago Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware cybersecurity · 64d ago Suspicious with a company offer letter cybersecurity · 64d ago The Canvas breach proved that prevention is no longer enough CyberScoop · 64d ago Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first? cybersecurity · 64d ago Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation Technical Information Security Content & Discussion · 64d ago Microsoft confirms Windows 11 security update install issues BleepingComputer · 64d ago Why do some recovery workflows still require full wallet uploads? cybersecurity · 64d ago Netmirror exposed - The Free Movie App That Was Robbing You Blind Malware Analysis & Reports · 64d ago Need help with interview for soc l1 cybersecurity · 64d ago Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap) cybersecurity · 64d ago HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try! Reverse Engineering · 64d ago Exploit available for new DirtyDecrypt Linux root escalation flaw BleepingComputer · 64d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 64d ago Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation Technical Information Security Content & Discussion · 64d ago Reverse engineering no dep x64 masm AI IDE Reverse Engineering · 64d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released cybersecurity · 64d ago carrer path in cybersecurity for a btech stud cybersecurity · 64d ago Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026 BleepingComputer · 64d ago Agents usage in production cybersecurity · 64d ago ‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K cybersecurity · 64d ago Former CISA nominee Sean Plankey named US CEO of defense startup CyberScoop · 64d ago Are teams still finding AI API keys in public repos? cybersecurity · 64d ago Can Laws Stop Deepfakes? South Korea Aims to Find Out darkreading · 64d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 64d ago Agentic Governance: Why It Matters Now Trend Micro Research, News, Perspectives · 64d ago Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here? cybersecurity · 64d ago Does the CBP bug phones? cybersecurity · 64d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released BleepingComputer · 64d ago What We Learned Building Runtime Visibility for Modern Telco Networks cybersecurity · 64d ago Ive got my Spotify account hacked! How do I solve this? cybersecurity · 64d ago The Politics of AI Transparency cybersecurity · 64d ago A million baby monitors and security cameras were easily viewable by hackers cybersecurity · 64d ago NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE cybersecurity · 64d ago Does anyone know if this file is still accessible to download? hacking: security in practice · 64d ago Is cybersecurity becoming more behavioral than technical? cybersecurity · 64d ago Questions About Promo Items for a Cybersecurity Conference cybersecurity · 64d ago DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write For [Blue|Purple] Teams in Cyber Defence · 64d ago Dois-je m'inquiéter ? cybersecurity · 65d ago I am dying to work abroad , rate my journey so far cybersecurity · 65d ago FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation For [Blue|Purple] Teams in Cyber Defence · 65d ago Microsoft - "Your single use code" email when it was not requested cybersecurity · 65d ago Security / Compliance work going Agentic? cybersecurity · 65d ago High school students organized a Jeopardy CTF competition - give it a try hacking: security in practice · 65d ago Don't believe the media, specially in cybersec cybersecurity · 65d ago Microsoft account keeps getting Authenticator requests? cybersecurity · 65d ago [Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated. cybersecurity · 65d ago Ansible security and compliance guide Technical Information Security Content & Discussion · 65d ago Malware learning Malware Analysis & Reports · 65d ago Struggling to generate security bulletins — any ideas? cybersecurity · 65d ago Certs to go into Security Engineer/architect cybersecurity · 65d ago 18882745552 beware of email with this number cybersecurity · 65d ago Transition from traditional penetration testing into AI security cybersecurity · 65d ago Seeking advice on next career steps cybersecurity · 65d ago Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing BleepingComputer · 65d ago Official Miasma Poison Tar Pit Docker Image Now Available hacking: security in practice · 65d ago Will the analyst role become obsolete? cybersecurity · 65d ago LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying" For [Blue|Purple] Teams in Cyber Defence · 65d ago Alert Fatigue cybersecurity · 65d ago Best path into cybersecurity for a high schooler? cybersecurity · 65d ago Static Kitten APT Adversary Simulation For [Blue|Purple] Teams in Cyber Defence · 65d ago 🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍 Hak5 · 65d ago Keep getting hacked cybersecurity · 65d ago Eimeria: five layers from RAR5 to RunPE For [Blue|Purple] Teams in Cyber Defence · 65d ago ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only. For [Blue|Purple] Teams in Cyber Defence · 65d ago Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain Technical Information Security Content & Discussion · 65d ago How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices cybersecurity · 65d ago I’m interested in joining the Red Team Hackers Academy in Bangalore. cybersecurity · 65d ago openDCIM exploitation For [Blue|Purple] Teams in Cyber Defence · 65d ago PE packer/crypter with random VM ISA per build Reverse Engineering · 65d ago A clueless teenager 💔 cybersecurity · 65d ago HASBL CTF - A Jeopardy-Style CTF Organized by High School Students! For [Blue|Purple] Teams in Cyber Defence · 65d ago Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start? cybersecurity · 65d ago Am I overthinking Claude Code security or is this actually a risk? cybersecurity · 65d ago is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this cybersecurity · 65d ago ISO/IEC 27701 ( SoA ) Applicability cybersecurity · 65d ago Security Executive Playbook cybersecurity · 65d ago This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon cybersecurity · 65d ago We Have Packet Capture at Home For [Blue|Purple] Teams in Cyber Defence · 65d ago I feel crazy I hope someone has insight . cybersecurity · 65d ago Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware For [Blue|Purple] Teams in Cyber Defence · 65d ago HWMonitor Trojanized for STX RAT DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 65d ago awesome-dfir-skills: Admiralty System for CTI Claude skill For [Blue|Purple] Teams in Cyber Defence · 65d ago Mullvad exit IPs as a fingerprinting vector For [Blue|Purple] Teams in Cyber Defence · 65d ago Does anybody know where I may stumble upon some Sh1mmer bin downloads hacking: security in practice · 65d ago Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools For [Blue|Purple] Teams in Cyber Defence · 65d ago Popular node-ipc npm Package Infected with Credential Steale... For [Blue|Purple] Teams in Cyber Defence · 65d ago An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. For [Blue|Purple] Teams in Cyber Defence · 65d ago Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files For [Blue|Purple] Teams in Cyber Defence · 65d ago Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor For [Blue|Purple] Teams in Cyber Defence · 65d ago Sandworm Activity in Industrial Environments: What the Data Reveals For [Blue|Purple] Teams in Cyber Defence · 65d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 65d ago "Shadowserver-in-a-box" IntelMQ + ELK Solution For [Blue|Purple] Teams in Cyber Defence · 65d ago Stenloader: Steganography Shellcode Loader For [Blue|Purple] Teams in Cyber Defence · 65d ago AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out For [Blue|Purple] Teams in Cyber Defence · 65d ago Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018 For [Blue|Purple] Teams in Cyber Defence · 65d ago Our response to the TanStack npm supply chain attack For [Blue|Purple] Teams in Cyber Defence · 65d ago QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026). For [Blue|Purple] Teams in Cyber Defence · 65d ago We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. For [Blue|Purple] Teams in Cyber Defence · 65d ago APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox. For [Blue|Purple] Teams in Cyber Defence · 65d ago oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday For [Blue|Purple] Teams in Cyber Defence · 65d ago Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations For [Blue|Purple] Teams in Cyber Defence · 65d ago ΡHANTΟΜ Al-Powered Pentesting Command Center cybersecurity · 65d ago Interview Assessments cybersecurity · 65d ago We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it cybersecurity · 65d ago Questions about data blockers cybersecurity · 65d ago A Tale of Two File Names Reverse Engineering · 65d ago PE reconstruction Reverse Engineering · 65d ago OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance For [Blue|Purple] Teams in Cyber Defence · 65d ago Post Implementation task cybersecurity · 65d ago The Gentlemen Ransomware Group — Leak Analysis For [Blue|Purple] Teams in Cyber Defence · 65d ago Mythos, MOAK, CTEM and the End of CVE Chasing cybersecurity · 65d ago Cyber security jobs in Austria cybersecurity · 65d ago Microsoft rejects critical Azure vulnerability report, no CVE issued BleepingComputer · 65d ago Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network hacking: security in practice · 65d ago Personal favorite deception layer. cybersecurity · 65d ago Estudiar Ciberseguridad cybersecurity · 65d ago Learning way cybersecurity · 65d ago A File Format Uncracked for 20 Years: Part 2 Reverse Engineering · 66d ago How do you report large volume detections to a CISO without making the BPA report a SOC story? cybersecurity · 66d ago HDD Firmware Hacking Part 1 For [Blue|Purple] Teams in Cyber Defence · 66d ago Can anyone share bugbase platform screenshot having professional usage on dashboard? cybersecurity · 66d ago ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. For [Blue|Purple] Teams in Cyber Defence · 66d ago CTO at NCSC Summary: week ending May 17th For [Blue|Purple] Teams in Cyber Defence · 66d ago CTO at NCSC Summary: week ending May 17th cybersecurity · 66d ago GZDoom in the browser hacking: security in practice · 66d ago Vidar v1.5 in Go: same family, new language, heavy sandbox checks For [Blue|Purple] Teams in Cyber Defence · 66d ago Developer credential-theft campaign exposed operator-side self-infection For [Blue|Purple] Teams in Cyber Defence · 66d ago Security Executive Playbook cybersecurity · 66d ago Tired of tab-switching between CTI tools - here's what we put together cybersecurity · 66d ago I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor cybersecurity · 66d ago Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source! Reverse Engineering · 66d ago Help-Desk Lures Drop KongTuke's Evolved ModeloRAT For [Blue|Purple] Teams in Cyber Defence · 66d ago Welcome to BlackFile: Inside a Vishing Extortion Operation For [Blue|Purple] Teams in Cyber Defence · 66d ago HackTheBox - Pterodactyl IppSec · 66d ago In Cybersecurity cybersecurity · 66d ago AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize. Technical Information Security Content & Discussion · 66d ago DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era For [Blue|Purple] Teams in Cyber Defence · 66d ago Stop Being Weird — Life After Call Stack Spoofing Under CET For [Blue|Purple] Teams in Cyber Defence · 66d ago Anyone else feel like most MSP tooling is either overkill or painfully manual? cybersecurity · 66d ago Russian hackers turn Kazuar backdoor into modular P2P botnet BleepingComputer · 66d ago Thinkpad vs Macbook pro endpoint security cybersecurity · 66d ago Any more affordable alternatives to “IntelligenceX”? cybersecurity · 66d ago Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran cybersecurity · 66d ago tanstack checker github action cybersecurity · 66d ago Drivers Alpha AWUS036AXML cybersecurity · 66d ago Splunk download for free cybersecurity · 66d ago Funnel Builder WordPress plugin bug exploited to steal credit cards cybersecurity · 66d ago Anyone here using pager duty? cybersecurity · 66d ago Scammer targeting posters cybersecurity · 66d ago Anyone know how to bypass these school laptop pins? hacking: security in practice · 66d ago Seeking advice cybersecurity · 66d ago Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works Technical Information Security Content & Discussion · 66d ago Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026) cybersecurity · 66d ago Just got an email about a single use code, maybe someone was trying to log in? cybersecurity · 66d ago Can a background in DevOps enter the cybersecurity field? cybersecurity · 66d ago [CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link. Reverse Engineering · 66d ago Triggering the Secure Boot Certificate Update with Intune Remediations For [Blue|Purple] Teams in Cyber Defence · 66d ago How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache For [Blue|Purple] Teams in Cyber Defence · 66d ago Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 For [Blue|Purple] Teams in Cyber Defence · 66d ago One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 66d ago CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) For [Blue|Purple] Teams in Cyber Defence · 66d ago Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 66d ago FamousSparrow APT Targets Azerbaijani Oil and Gas Industry For [Blue|Purple] Teams in Cyber Defence · 66d ago Disclosing new PebbleDash-based tools by Kimsuky For [Blue|Purple] Teams in Cyber Defence · 66d ago FrostyNeighbor: Fresh mischief and digital shenanigans For [Blue|Purple] Teams in Cyber Defence · 66d ago Kazuar: Anatomy of a nation-state botnet For [Blue|Purple] Teams in Cyber Defence · 66d ago OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments For [Blue|Purple] Teams in Cyber Defence · 66d ago NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys For [Blue|Purple] Teams in Cyber Defence · 66d ago Hacker Ringleader Extradited for 38 Billion Won Theft For [Blue|Purple] Teams in Cyber Defence · 66d ago Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System For [Blue|Purple] Teams in Cyber Defence · 66d ago Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit For [Blue|Purple] Teams in Cyber Defence · 66d ago The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation For [Blue|Purple] Teams in Cyber Defence · 66d ago FFFFirefox - A One-Day Wonder Renderer Exploit For [Blue|Purple] Teams in Cyber Defence · 66d ago MiniPlasma, a powerful LPE For [Blue|Purple] Teams in Cyber Defence · 66d ago Using ai in learning cybersecurity · 66d ago Exploiting Toshiba Qiomem.sys vulnerable driver Reverse Engineering · 66d ago Avanzamento area Blue Team/SOC cybersecurity · 66d ago Please what could be helpful cybersecurity · 66d ago HDD Firmware Hacking Part 1 Reverse Engineering · 66d ago CVE exploit chain cybersecurity · 66d ago What are the widely accepted SaaS security accreditations/audits an app should seek in fintech cybersecurity · 66d ago Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco cybersecurity · 66d ago Region-based binary diff tool for firmware analysis Reverse Engineering · 66d ago Major flaw in Indian Cyber and IT assurance landscape cybersecurity · 66d ago Red Team Ops Ⅱ ( CRTL ) exam preparation cybersecurity · 66d ago Recomendations cybersecurity · 66d ago A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Reverse Engineering · 66d ago Recommended cybersecurity certification for a UX designer new to the domain? cybersecurity · 66d ago แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป! Reverse Engineering · 66d ago insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server cybersecurity · 66d ago Career path cybersecurity · 66d ago Merit America offers a program that gets you into cyber security roles. cybersecurity · 66d ago Brovan — Open-source x86/x64 user-mode binary emulator written in C# Reverse Engineering · 66d ago Brovan: Binary user-mode emulator for x86_64 Reverse Engineering · 66d ago Brovan: Binary user-mode emulator for x86_64 Malware Analysis & Reports · 66d ago Brovan: Binary user-mode emulator for x86_64 cybersecurity · 66d ago AmEx Interview! cybersecurity · 66d ago A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA hacking: security in practice · 66d ago Developer credential-stealing pipeline also collected operator workstations cybersecurity · 66d ago need help building a case. cybersecurity · 66d ago Colorado governor commutes prison sentence for election denier Tina Peters CyberScoop · 66d ago Personal favorite SIEM platform? cybersecurity · 66d ago Cardputer ADV cybersecurity · 66d ago Alternative for Qualys cybersecurity · 66d ago I have a friend who looks like he’s a stalker I’m scared he will know I stalk him hacking: security in practice · 66d ago The 4th Linux kernel flaw this month can lead to stolen SSH host keys cybersecurity · 66d ago Congress Puts Heat on Instructure After Canvas Outage darkreading · 66d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 66d ago Stack Buffer Overflow Explained (Using a Classic Doom Bug) cybersecurity · 66d ago [Tutorial] How to hack DOS games: Reversing Prince of Persia hacking: security in practice · 66d ago Here’s how the FTC plans to enforce the Take It Down Act CyberScoop · 66d ago Understanding Stack Buffer Overflows Through Doom and C++ Reverse Engineering · 66d ago Confused about cybersecurity career cybersecurity · 66d ago Funnel Builder WordPress plugin bug exploited to steal credit cards BleepingComputer · 66d ago What is it Wednesdays: Episode 0001 Reverse Engineering · 66d ago Transferring from pen test consulting to application security? cybersecurity · 67d ago Curso de especializacion de Ciberseguridad cybersecurity · 67d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? For [Blue|Purple] Teams in Cyber Defence · 67d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? cybersecurity · 67d ago Lost, tempted to throw in the towel cybersecurity · 67d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own cybersecurity · 67d ago I open-sourced a Docker security scanner I use to audit all my websites cybersecurity · 67d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own BleepingComputer · 67d ago Testing Deception Technique cybersecurity · 67d ago Popular node-ipc npm package compromised to steal credentials BleepingComputer · 67d ago A malware got into my account and spread spam ad to my friends and relatives cybersecurity · 67d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems Technical Information Security Content & Discussion · 67d ago Avada Builder WordPress plugin flaws allow site credential theft BleepingComputer · 67d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems cybersecurity · 67d ago Most pentest reports I review are padded with garbage findings cybersecurity · 67d ago Is dns spoofing dead?? hacking: security in practice · 67d ago Cyber Essentials and use of third party websites - MFA cybersecurity · 67d ago Rapid 7 and Cisa Kev cybersecurity · 67d ago Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup Reverse Engineering · 67d ago Deepdive into the object creation flow in Windows -PART 2 : access check internals Reverse Engineering · 67d ago Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization Reverse Engineering · 67d ago Microsoft backpedals: Edge to stop loading passwords into memory BleepingComputer · 67d ago Anyone know much about MS Defender? cybersecurity · 67d ago My Privacy Focused USB Drive hacking: security in practice · 67d ago Cisco zero-day under ongoing attack by persistent threat group CyberScoop · 67d ago EN18031 for IoT: struggling to see the big picture — advice from experienced people? cybersecurity · 67d ago Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution BleepingComputer · 67d ago Japan’s 3DS Mandate: One Year In Blog – Forter · 67d ago Automating code security reviews with Claude Mythos-level capabilities Technical Information Security Content & Discussion · 67d ago Automating Code Security Reviews cybersecurity · 67d ago [Tool] IOCX — deterministic static IOC extraction for PE binaries For [Blue|Purple] Teams in Cyber Defence · 67d ago New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available cybersecurity · 67d ago [Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo) Reverse Engineering · 67d ago Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition) hacking: security in practice · 67d ago AI coding tools on developer machines — looking for input on how you're handling it cybersecurity · 67d ago Chrome 148 Update Patches Critical Vulnerabilities cybersecurity · 67d ago Microsoft warns of Exchange zero-day flaw exploited in attacks cybersecurity · 67d ago I need help. i am lost cybersecurity · 67d ago Microsoft to automatically roll back faulty Windows drivers BleepingComputer · 67d ago Novel Evilginx Frontend - Lowering the barrier for token theft reuse For [Blue|Purple] Teams in Cyber Defence · 67d ago Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence cybersecurity · 67d ago Cyber Pioneers Ponder Past as Prologue darkreading · 67d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 67d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 67d ago Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments cybersecurity · 67d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? cybersecurity · 67d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? For [Blue|Purple] Teams in Cyber Defence · 67d ago Microsoft warns of Exchange zero-day flaw exploited in attacks BleepingComputer · 67d ago I'm going crazy. At the application level what I can actually do to prevent DDos? cybersecurity · 67d ago yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android. Reverse Engineering · 67d ago Is anyone enrolled in Intellipaat's cybersecurity course? cybersecurity · 67d ago Will AI Replace Cybersecurity Jobs? cybersecurity · 67d ago Why geopolitical turmoil is a gift for scammers, and how to stay safe WeLiveSecurity · 67d ago What's best certification choice after OSWE cybersecurity · 67d ago TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer hacking: security in practice · 67d ago Facebook Page Call Slipping through Sleep mode cybersecurity · 67d ago ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey cybersecurity · 67d ago New Linux LPE allows local users to read any file, including privkeys cybersecurity · 67d ago A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks. cybersecurity · 67d ago Your experience as IT Admin on Alerts cybersecurity · 67d ago Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time cybersecurity · 67d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild cybersecurity · 67d ago GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets Reverse Engineering · 67d ago GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS Reverse Engineering · 67d ago Instrumenting QT6 desktop apps with Frida - Part 1 Technical Information Security Content & Discussion · 67d ago From Vercel Typosquatting to an Obfuscated macOS Malware Loader Technical Information Security Content & Discussion · 67d ago Discord VC lag Exploit cybersecurity · 67d ago FrostyNeighbor: Fresh mischief and digital shenanigans cybersecurity · 67d ago Bug FB - Inicio de sesion por password cybersecurity · 67d ago Does anyone know how to configure EVILGINX for testing cybersecurity · 67d ago Trafexia V2 - Mobile Traffic Interceptor Toolkit Reverse Engineering · 67d ago How long does it take to get familiar with a tool cybersecurity · 67d ago Scam website cybersecurity · 67d ago ANTS Hack: 19 million records exposed in French ID agency breach cybersecurity · 67d ago has anyone used tail os here? hacking: security in practice · 67d ago Is it really that easy to obtain SMS codes using an SS7 attack? cybersecurity · 67d ago AI coding tools are shipping code faster than security can review it. What's your team doing about it cybersecurity · 67d ago Interview for AI security engineer position at a fortune 500 company cybersecurity · 67d ago How’s the job market for Senior AppSec Engineers? How are the interviews? cybersecurity · 67d ago Has anyone read "The Art of Deception"? How does it hold up to now? cybersecurity · 67d ago Run this washer/dryer sans coin? hacking: security in practice · 67d ago WAF Evasion Engine For [Blue|Purple] Teams in Cyber Defence · 67d ago Is metadata protection becoming more important than traditional endpoint security for ordinary users? cybersecurity · 67d ago Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems darkreading · 67d ago Inspecting a DLL file trying to figure out if it really is malware Malware Analysis & Reports · 67d ago Zero trust in hybrid environments - what's actually worked for you cybersecurity · 67d ago Have you encountered issues with CSAF advisories in practice? cybersecurity · 67d ago Zero trust in hybrid environments - what's actually working for you cybersecurity · 67d ago I built an open-source Burp alternative hacking: security in practice · 67d ago TeamPCP hackers advertise Mistral AI code repos for sale BleepingComputer · 67d ago OpenAI confirms security breach in TanStack supply chain attack cybersecurity · 67d ago Bachelors Degree Options cybersecurity · 67d ago HighBoy hacking: security in practice · 67d ago Thus Spoke…The Gentlemen For [Blue|Purple] Teams in Cyber Defence · 67d ago Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin BleepingComputer · 67d ago SecurityScorecard Snags Driftnet to Level Up Threat Intelligence darkreading · 67d ago npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output Malware Analysis & Reports · 67d ago Pentagon cyber official calls advanced AI ‘revolutionary warfare’ CyberScoop · 67d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild darkreading · 67d ago White House cyber official: identity security matters more than ever in the age of AI CyberScoop · 67d ago Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks BleepingComputer · 67d ago I need help protecting my privacy cybersecurity · 67d ago Free Threat Intellegence cybersecurity · 67d ago What discovery in cybersecurity amazed you the most? cybersecurity · 67d ago OpenAI confirms security breach in TanStack supply chain attack BleepingComputer · 68d ago Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026 BleepingComputer · 68d ago Scholarship for Service cybersecurity · 68d ago Reading Siemens CT raw data hacking: security in practice · 68d ago KQLab - open-source query manager for SOC teams For [Blue|Purple] Teams in Cyber Defence · 68d ago For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons? cybersecurity · 68d ago How I use Hermes agent to turn Patch Tuesday into Windows exploit research hacking: security in practice · 68d ago Another day, another supply chain cybersecurity · 68d ago How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs? cybersecurity · 68d ago Teaching Linux+ & CEH..... cybersecurity · 68d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon cybersecurity · 68d ago How TeamPCP's Python Toolkit Survives a C2 Takedown For [Blue|Purple] Teams in Cyber Defence · 68d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon hacking: security in practice · 68d ago SIEM use case development cybersecurity · 68d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Technical Information Security Content & Discussion · 68d ago JFrog vs Mend as Scanners cybersecurity · 68d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 68d ago KQLab - open-source query manager for SOC teams cybersecurity · 68d ago Which Vendors Publish the Best (or Worst) Security Advisories? cybersecurity · 68d ago Tips for a beginner noob that wants to learn hacking: security in practice · 68d ago 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine darkreading · 68d ago Synthetic training data vs. real attack telemetry — does it actually matter? cybersecurity · 68d ago Microsoft AntiSSRF For [Blue|Purple] Teams in Cyber Defence · 68d ago Operative IT-Sicherheit | SIEM & Splunk cybersecurity · 68d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state Technical Information Security Content & Discussion · 68d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state For [Blue|Purple] Teams in Cyber Defence · 68d ago 18-year-old NGINX vulnerability allows DoS, potential RCE BleepingComputer · 68d ago Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight BleepingComputer · 68d ago SOC not for junior level? cybersecurity · 68d ago Major tech manufacturer Foxconn confirms cyberattack hit North American factories CyberScoop · 68d ago Cybersecurity at MSG cybersecurity · 68d ago pii-tools.com reputable? cybersecurity · 68d ago Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise cybersecurity · 68d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 68d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Reverse Engineering · 68d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Malware Analysis & Reports · 68d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Technical Information Security Content & Discussion · 68d ago Contract jobs worth the risk? cybersecurity · 68d ago HackTheBoxAcademy vs LetsDefend vs CyberDefenders cybersecurity · 68d ago Automating code security reviews with Claude: near Mythos-level capabilities at lower cost cybersecurity · 68d ago Making Right Career Decision? cybersecurity · 68d ago AI Drives Cybersecurity Investments, Widening 'Valley of Death' darkreading · 68d ago I tried using apparmor (linux security) but it doesn't seem to work very well cybersecurity · 68d ago Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything! cybersecurity · 68d ago Struggling to Stay Up to Date With Vulnerabilities cybersecurity · 68d ago CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure Technical Information Security Content & Discussion · 68d ago How to Check Computer Activity: 2026 Guide for Windows and Mac Technical Information Security Content & Discussion · 68d ago Strix — first public beta of the spiritual successor to cSploit/dSploit hacking: security in practice · 68d ago KongTuke hackers now use Microsoft Teams for corporate breaches BleepingComputer · 68d ago How fast is autonomous AI cyber capability advancing? For [Blue|Purple] Teams in Cyber Defence · 68d ago Foxconn Attack Highlights Manufacturing's Cyber Crisis darkreading · 68d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 68d ago Siemens Siemens ROS# All CISA Advisories · 68d ago Siemens gWAP All CISA Advisories · 68d ago Siemens SIMATIC All CISA Advisories · 68d ago Siemens Ruggedcom Rox All CISA Advisories · 68d ago Siemens Ruggedcom Rox All CISA Advisories · 68d ago Siemens Simcenter Femap All CISA Advisories · 68d ago Universal Robots Polyscope 5 All CISA Advisories · 68d ago Siemens Ruggedcom Rox All CISA Advisories · 68d ago Siemens Teamcenter All CISA Advisories · 68d ago Siemens Solid Edge All CISA Advisories · 68d ago Siemens SENTRON 7KT PAC1261 Data Manager All CISA Advisories · 68d ago Siemens Opcenter RDnL All CISA Advisories · 68d ago Siemens Ruggedcom Rox All CISA Advisories · 68d ago Siemens SIMATIC S7 PLC Web Server All CISA Advisories · 68d ago Siemens Industrial Devices All CISA Advisories · 68d ago Siemens SIMATIC All CISA Advisories · 68d ago Siemens SIPROTEC 5 All CISA Advisories · 68d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 68d ago How to Transfer files Safely from a Compromised (work) Device cybersecurity · 68d ago Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward cybersecurity · 68d ago Multiple data breaches in one week cybersecurity · 68d ago Whatsapp hacking: security in practice · 68d ago How are small security teams handling vulnerability overload now? cybersecurity · 68d ago Concerns mount that EU will demand age verification for VPNs cybersecurity · 68d ago Automating code security reviews: Claude Mythos-level capabilities with lower cost cybersecurity · 68d ago The Rare Patch: A Digital Sovereignty Challenge cybersecurity · 68d ago Advise cybersecurity · 68d ago CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC Technical Information Security Content & Discussion · 68d ago Face ID bypass with avatar hacking: security in practice · 68d ago GRC cybersecurity · 68d ago Dell confirms its SupportAssist software causes Windows BSOD crashes BleepingComputer · 68d ago Admins and Engineers cybersecurity · 68d ago Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark cybersecurity · 68d ago Ghidra 12.1 has been released! Reverse Engineering · 68d ago Prompt injection in browser coding agents is the threat model nobody is ready for cybersecurity · 68d ago US charges suspected Dream Market admin arrested in Germany BleepingComputer · 68d ago FrostyNeighbor: Fresh mischief and digital shenanigans WeLiveSecurity · 68d ago New Fragnesia Linux flaw lets attackers gain root privileges cybersecurity · 68d ago New Fragnesia Linux flaw lets attackers gain root privileges BleepingComputer · 68d ago Transition from MSP to Network Engineering? cybersecurity · 68d ago YellowKey: YellowKey Bitlocker Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 68d ago Reverse Engineering Slither.io’s Network Protocol Reverse Engineering · 68d ago So called “off grid” method cybersecurity · 68d ago Convince me I’m not paranoid: a unique hacking situation. cybersecurity · 68d ago Hunting the Behavior Behind npm Supply Chain Attacks cybersecurity · 68d ago Hunting the Behavior Behind npm Supply Chain Attacks hacking: security in practice · 68d ago Question for AppSec Members cybersecurity · 68d ago Hunting the Behavior Behind npm Supply Chain Attacks Technical Information Security Content & Discussion · 68d ago LIVE: 🕵️ HTB Sherlocks! | Cybersecurity | Blue Team The Cyber Mentors · 68d ago Beginners guide to Google Dorks by Heisenberg cybersecurity · 68d ago I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable... Malware Analysis & Reports · 68d ago Alguém sabe algo sobre raven eye technology cybersecurity · 68d ago Gophish Porject - Requirement cybersecurity · 68d ago Security Team Won’t Assess Risk cybersecurity · 68d ago Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework cybersecurity · 68d ago Microsoft’s new multi-model agentic security system tops leading industry benchmark cybersecurity · 68d ago Proxmark5 Day 3 Update - $357K+ funded (715% of goal) hacking: security in practice · 68d ago Researchers say AI just broke every benchmark for autonomous cyber capability CyberScoop · 68d ago Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents cybersecurity · 68d ago West Pharmaceutical says hackers stole data, encrypted systems BleepingComputer · 68d ago Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks CyberScoop · 68d ago Overwhelmed on how to enter the job market. cybersecurity · 68d ago Iranian hackers targeted major South Korean electronics maker BleepingComputer · 68d ago Social media scam bill targets tech giants as New Yorkers lose billions cybersecurity · 68d ago What are the biggest technical & cultural hurdles you’re facing right now? cybersecurity · 68d ago CISSP / CCSP training - Experienced engineer cybersecurity · 68d ago WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers Technical Information Security Content & Discussion · 68d ago I Reverse-engineering Need for Speed Underground 2 Server Reverse Engineering · 68d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 68d ago Checkbox Assessments Aren't Fit to Measure Risk darkreading · 68d ago Attackers Weaponize RubyGems for Data Dead Drops darkreading · 68d ago Vulnerability in Canvas/Instructure Support Tickets had part in breach? cybersecurity · 68d ago Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak darkreading · 68d ago Are There Really Ethical Hackers? I've Yet To Meet One hacking: security in practice · 68d ago Tinker Tailor Soldier: Paper Werewolf’s latest toolkit For [Blue|Purple] Teams in Cyber Defence · 68d ago On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract Technical Information Security Content & Discussion · 68d ago New critical Exim mailer flaw allows remote code execution BleepingComputer · 68d ago /sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple Technical Information Security Content & Discussion · 68d ago Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out Technical Information Security Content & Discussion · 68d ago 126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies For [Blue|Purple] Teams in Cyber Defence · 68d ago DOJ releases legal rationale for nationwide voter data collection CyberScoop · 68d ago is malwarefox legit? cybersecurity · 68d ago what lab to learn zero trust? cybersecurity · 68d ago Anyone else got a bunch of emails leaked by Samsung? cybersecurity · 68d ago Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape darkreading · 69d ago This is what some the world's largest banks of malware look like stacked as hard drives cybersecurity · 69d ago I need feedback on my project please cybersecurity · 69d ago would like to understand the role of "Cyber Insurance UnderWriters" cybersecurity · 69d ago Weaponized AI: The new frontier of fraud and identity spoofing CyberScoop · 69d ago clens.io - new public threat & data intel service Malware Analysis & Reports · 69d ago Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad For [Blue|Purple] Teams in Cyber Defence · 69d ago Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise For [Blue|Purple] Teams in Cyber Defence · 69d ago I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included Reverse Engineering · 69d ago Free on-device tool for monitoring AI traffic on macOS — visibility before policy cybersecurity · 69d ago Is secure evidence handling and controlled derivative file sharing needed? cybersecurity · 69d ago Will Adding Some Certifications Help Me in the Job Market? cybersecurity · 69d ago Linux driver posted for Intel Silicon Security Engine Interface "ISSEI" cybersecurity · 69d ago Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified? cybersecurity · 69d ago Fragnesia made public as latest Linux local privilege escalation vulnerability cybersecurity · 69d ago HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity? cybersecurity · 69d ago trying to learn patching hacking: security in practice · 69d ago NIST is surrendering to the amount of CVEs coming in cybersecurity · 69d ago Windows BitLocker zero-day gives access to protected drives, PoC released BleepingComputer · 69d ago [HOMELAB] Built a SOC investigation console on two old Dell boxes For [Blue|Purple] Teams in Cyber Defence · 69d ago Military Veteran looking to get into the Cyber Field cybersecurity · 69d ago Android Intrusion Logging as a new source of data for consensual forensic analysis For [Blue|Purple] Teams in Cyber Defence · 69d ago Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor cybersecurity · 69d ago Granny’s Compromised Android Firmware Malware Analysis & Reports · 69d ago On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study) Technical Information Security Content & Discussion · 69d ago Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook. cybersecurity · 69d ago Webinar tomorrow: Why security alone won't stop modern attacks BleepingComputer · 69d ago Microsoft fixes BitLocker recovery issue only for Windows 11 users BleepingComputer · 69d ago Shai-Hulud: Another Wave and Going Open Source For [Blue|Purple] Teams in Cyber Defence · 69d ago Cve apis for a database cybersecurity · 69d ago Empresas de Cyberseguridad en Mexico (Reacciones) cybersecurity · 69d ago Joined a new company: GRC landscape advice cybersecurity · 69d ago Removing admin rights cybersecurity · 69d ago a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access cybersecurity · 69d ago A stealth approach to Process Injection - EntryPoint Hijacking For [Blue|Purple] Teams in Cyber Defence · 69d ago A stealth approach to Process Injection - EntryPoint Hijacking Technical Information Security Content & Discussion · 69d ago FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow cybersecurity · 69d ago Golden years for cyber security about to start? cybersecurity · 69d ago A stealth approach to Process Injection - EntryPoint Hijacking cybersecurity · 69d ago Microsoft fixes Windows Autopatch bug installing restricted drivers BleepingComputer · 69d ago Detecting CopyFail and DirtyFrag by thinking outside the box cybersecurity · 69d ago Daybreak is OpenAI’s answer to the AI arms race in cybersecurity CyberScoop · 69d ago Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security cybersecurity · 69d ago LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly darkreading · 69d ago China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm darkreading · 69d ago Foxconn confirms cyberattack claimed by Nitrogen ransomware gang BleepingComputer · 69d ago Career advice cybersecurity · 69d ago 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation BleepingComputer · 69d ago LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back The Last Watchdog · 69d ago Microsoft says some users can't install Office on Windows 365 devices BleepingComputer · 69d ago A year of Apple Security Bounty research — 16 closed findings, full disclosure Technical Information Security Content & Discussion · 69d ago [Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) Malware Analysis & Reports · 69d ago The exponential rise of economic damage caused by cyber-crime continues cybersecurity · 69d ago [Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features Reverse Engineering · 69d ago Today's cybersecurity systems are not ready for AI cybersecurity · 69d ago Are certifications worth it, or do practical skills matter more? cybersecurity · 69d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) cybersecurity · 69d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) For [Blue|Purple] Teams in Cyber Defence · 69d ago Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed cybersecurity · 69d ago Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft cybersecurity · 69d ago What to do after security+ cybersecurity · 69d ago AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data cybersecurity · 69d ago AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods Technical Information Security Content & Discussion · 69d ago LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer] Reverse Engineering · 69d ago Service Principal Sign-Ins: A blind spot that a lot are missing For [Blue|Purple] Teams in Cyber Defence · 69d ago Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub cybersecurity · 69d ago Is it realistic to move from Tech Risk/GRC into technical cybersecurity? cybersecurity · 69d ago My Analysis of a Bandook RAT PCAP For [Blue|Purple] Teams in Cyber Defence · 69d ago Are IPhone autofill passwords safe to use? cybersecurity · 69d ago Access approvals happen over Slack dm and I don't know how to present that to an auditor cybersecurity · 69d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 69d ago China is going dark to develop its own Mythos, German cyber chief fears cybersecurity · 69d ago Is prompt injection a real problem for you? cybersecurity · 69d ago New Exim BDAT bug shows why “just patch the mail server” is still not simple cybersecurity · 69d ago Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach cybersecurity · 69d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 69d ago Cybersecurity guide cybersecurity · 69d ago [Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ? cybersecurity · 69d ago How you guys rate Google Cyber security course and certificate out of 10 !? cybersecurity · 69d ago Detection Rule is here For [Blue|Purple] Teams in Cyber Defence · 69d ago Cyebrsecurity Startup Advice cybersecurity · 69d ago Can anyone give a real world based AI based attack? cybersecurity · 69d ago r2garlic - The world's fastest Android/DEX decompiler meets radare2! Reverse Engineering · 69d ago How worried should we be about AI powered cyberattacks? cybersecurity · 69d ago Built STIS-ICS — an open ICS/OT security learning project cybersecurity · 69d ago Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft Trend Micro Research, News, Perspectives · 69d ago OS scanner that checks repos for traces of the Shai Hulud worm Malware Analysis & Reports · 69d ago OS scanner that checks repos for traces of the Shai Hulud worm cybersecurity · 69d ago US govt seeks Instructure testimony on massive Canvas cyberattack BleepingComputer · 69d ago Foxconn Ransomware Attack Shows Nothing Is Safe Forever cybersecurity · 69d ago Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries cybersecurity · 69d ago Cellphone IP address spoofing. hacking: security in practice · 69d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu cybersecurity · 69d ago Explorer shows random letter/number filenames before copying my actual files — normal behavior? cybersecurity · 69d ago ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack CyberScoop · 69d ago Zscaler AI Security Capabilities ? cybersecurity · 69d ago Major world economies spell out key elements of AI ‘ingredients list’ CyberScoop · 69d ago It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight darkreading · 69d ago Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical CyberScoop · 69d ago Cybersecurity degree cybersecurity · 69d ago Owning a service principal equals owning its permissions. For [Blue|Purple] Teams in Cyber Defence · 69d ago Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma cybersecurity · 69d ago Cyber security cybersecurity · 69d ago New York Senate takes on junk fees, digital subscriptions, surveillance pricing cybersecurity · 69d ago UK fines water supplier $1.3M for exposing data of 664k customers BleepingComputer · 69d ago Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection For [Blue|Purple] Teams in Cyber Defence · 69d ago Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI Malware Analysis & Reports · 69d ago Webinar: Fixing the gaps in network incident response BleepingComputer · 69d ago Signal adds security warnings for social engineering, phishing attacks BleepingComputer · 69d ago CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level. For [Blue|Purple] Teams in Cyber Defence · 69d ago Cybersecurity statistics of the week (May 4th - May 10th) cybersecurity · 69d ago Feels like AI changed the speed of attacks more than most companies want to admit cybersecurity · 70d ago Microsoft releases Windows 10 KB5087544 extended security update BleepingComputer · 70d ago Anyone used Kasm or ReplicaCyber? cybersecurity · 70d ago Škoda warns of customer data breach after online shop hack cybersecurity · 70d ago Google launches new Android security feature to help uncover spyware attacks cybersecurity · 70d ago Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator BleepingComputer · 70d ago Windows 11 KB5089549 & KB5087420 cumulative updates released BleepingComputer · 70d ago Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days BleepingComputer · 70d ago Fancy Bear: Stealing Credentials Invisibly cybersecurity · 70d ago Nightmare Eclipse has published Greenplasma and YellowKey cybersecurity · 70d ago Copilot Agent cybersecurity · 70d ago A Quick Way to Prove Your Cybersecurity Skillset! The Cyber Mentors · 70d ago Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim Technical Information Security Content & Discussion · 70d ago The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop Technical Information Security Content & Discussion · 70d ago What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles? cybersecurity · 70d ago GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language. Reverse Engineering · 70d ago Škoda warns of customer data breach after online shop hack BleepingComputer · 70d ago Android 17 to expand banking scam call and privacy protections BleepingComputer · 70d ago Google and Amnesty International teamed up to make it harder for spyware vendors to hide CyberScoop · 70d ago Career Advice cybersecurity · 70d ago Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs Technical Information Security Content & Discussion · 70d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu Technical Information Security Content & Discussion · 70d ago AI+DFIR Challenge: Share Your Disasters and Successes For [Blue|Purple] Teams in Cyber Defence · 70d ago Anyone else exhausted by the nonstop AI hype? cybersecurity · 70d ago Reviewing the trends in ransomware attacks in 2026 cybersecurity · 70d ago FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread The Last Watchdog · 70d ago Sorry if its the wrong place but hacking: security in practice · 70d ago Is It a Good Idea to Change Jobs Shortly After Getting Hired? cybersecurity · 70d ago SSO makes life easier but MFA keeps it safe, do we actually need both? cybersecurity · 70d ago Hugging Face Packages Weaponized With a Single File Tweak darkreading · 70d ago Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours? cybersecurity · 70d ago Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware For [Blue|Purple] Teams in Cyber Defence · 70d ago How are SOC teams actually deciding what not to investigate anymore? cybersecurity · 70d ago Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily cybersecurity · 70d ago Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released. cybersecurity · 70d ago Has anyone tryed this out yet? cybersecurity · 70d ago I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately... Technical Information Security Content & Discussion · 70d ago The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..) cybersecurity · 70d ago Switching to Cyber cybersecurity · 70d ago 20 Leaders Who Built the CISO Era: 2 Decades of Change darkreading · 70d ago Software Bill of Materials for AI - Minimum Elements All CISA Advisories · 70d ago ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax All CISA Advisories · 70d ago Subnet Solutions PowerSYSTEM Center All CISA Advisories · 70d ago ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities All CISA Advisories · 70d ago ABB AC500 V3 Multiple Vulnerabilities All CISA Advisories · 70d ago ABB Automation Builder Gateway for Windows All CISA Advisories · 70d ago Fuji Electric Tellus All CISA Advisories · 70d ago Nitrogen ransomware group claims Foxconn after Wisconsin plant outage cybersecurity · 70d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages cybersecurity · 70d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages BleepingComputer · 70d ago Postmortem: TanStack npm supply-chain compromise For [Blue|Purple] Teams in Cyber Defence · 70d ago Using Cape Sandbox for Phishing Analysis cybersecurity · 70d ago Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain darkreading · 70d ago SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA BleepingComputer · 70d ago Canvas hack: company pays criminals to delete students' stolen data cybersecurity · 70d ago AI is separating the companies built to scale from the ones built to sell CyberScoop · 70d ago i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning. cybersecurity · 70d ago AI integrations are quietly creating a new OAuth supply-chain problem cybersecurity · 70d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak cybersecurity · 70d ago UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships cybersecurity · 70d ago Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results Technical Information Security Content & Discussion · 70d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak BleepingComputer · 70d ago Hardcoded secrets in Git cybersecurity · 70d ago Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages cybersecurity · 70d ago UK water company allowed hackers to lurk undetected for nearly two years, regulator finds cybersecurity · 70d ago New ipTIME Pre-Auth RCE in CWMP cybersecurity · 70d ago New ipTIME Pre-Auth RCE in CWMP Technical Information Security Content & Discussion · 70d ago Postmortem: TanStack npm supply-chain compromise Technical Information Security Content & Discussion · 70d ago Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it? hacking: security in practice · 70d ago Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak cybersecurity · 70d ago Steam spear phishing Malware Analysis & Reports · 70d ago Fake linked in sponsored google search Malware Analysis & Reports · 70d ago Is my phone hacked? cybersecurity · 70d ago Switched to a grc role after a year in SOC L1 cybersecurity · 70d ago bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages For [Blue|Purple] Teams in Cyber Defence · 70d ago rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions For [Blue|Purple] Teams in Cyber Defence · 70d ago Detecting Remote Thread Creation with Windows Driver For [Blue|Purple] Teams in Cyber Defence · 70d ago Mythos finds a curl vulnerability For [Blue|Purple] Teams in Cyber Defence · 70d ago Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details For [Blue|Purple] Teams in Cyber Defence · 70d ago Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign For [Blue|Purple] Teams in Cyber Defence · 70d ago Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment For [Blue|Purple] Teams in Cyber Defence · 70d ago esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app For [Blue|Purple] Teams in Cyber Defence · 70d ago Forecasting Lazarus Crypto Heists cybersecurity · 70d ago LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors. For [Blue|Purple] Teams in Cyber Defence · 70d ago How Cloudflare responded to the “Copy Fail” Linux vulnerability For [Blue|Purple] Teams in Cyber Defence · 70d ago Infrastructure Security Incident Update & FAQs cybersecurity · 70d ago I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic. For [Blue|Purple] Teams in Cyber Defence · 70d ago LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots. For [Blue|Purple] Teams in Cyber Defence · 70d ago Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages cybersecurity · 70d ago In Depth Guide To VM Based Obfuscation - What it is and how to handle it. cybersecurity · 70d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective cybersecurity · 70d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective Reverse Engineering · 70d ago Transitioned to GRC cybersecurity · 70d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages cybersecurity · 70d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages Malware Analysis & Reports · 70d ago German cybersecurity official warns China is close to developing AI superhacker cybersecurity · 70d ago How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models. Technical Information Security Content & Discussion · 70d ago New Shai-Hulud npm worm variant Malware Analysis & Reports · 70d ago New Shai-Hulud npm worm variant For [Blue|Purple] Teams in Cyber Defence · 70d ago Google Detects First AI-Generated Zero-Day Exploit cybersecurity · 70d ago “DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance cybersecurity · 70d ago Instructure/ canvas paid the ransom? cybersecurity · 70d ago Instructure claims hackers returned stolen Canvas data after an extortion standoff CyberScoop · 70d ago OpenAI announces Daybreak, "frontier AI for defenders" Technical Information Security Content & Discussion · 70d ago Troca emprego - big para consultoria ou fintech - Pentester/Red Team cybersecurity · 70d ago GM agrees to $12.75M California settlement over sale of drivers’ data BleepingComputer · 70d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation hacking: security in practice · 70d ago Finally, texts between Android and iPhone users can be end-to-end encrypted cybersecurity · 70d ago Official CheckMarx Jenkins package compromised with infostealer cybersecurity · 70d ago Official CheckMarx Jenkins package compromised with infostealer BleepingComputer · 70d ago New GhostLock tool abuses Windows API to block file access BleepingComputer · 70d ago IMF warns of the potential for AI attacks on global financial systems cybersecurity · 70d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 70d ago GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon Technical Information Security Content & Discussion · 70d ago Cookie thieves caught stealing dev secrets via fake Claude Code installers cybersecurity · 70d ago Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo cybersecurity · 70d ago MS Defender on OT Network cybersecurity · 70d ago A fateful question cybersecurity · 70d ago EtwWatcher For [Blue|Purple] Teams in Cyber Defence · 70d ago SC-900 or SC-400 cybersecurity · 70d ago What are your security non-negotiables? cybersecurity · 70d ago Losing my path cybersecurity · 71d ago Axon-captcha cybersecurity · 71d ago What makes companies trust small cybersecurity vendors? cybersecurity · 71d ago Donuts and Beagles: Fake Claude site spreads backdoor For [Blue|Purple] Teams in Cyber Defence · 71d ago Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility” cybersecurity · 71d ago TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack cybersecurity · 71d ago News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents The Last Watchdog · 71d ago New and improved: Agent governance, intelligent workflows, and connected app experiences Microsoft 365 Blog · 71d ago Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim cybersecurity · 71d ago How I Defeat Passkeys Nearly Every Time in Phishing Assessments Technical Information Security Content & Discussion · 71d ago These Extensions are Scraping Your AI Chats, are you affected? cybersecurity · 71d ago Reverse Engineering Fisher-Price Pixter Reverse Engineering · 71d ago Be careful with your Git: Investigating malware spreading through Git repositories cybersecurity · 71d ago Training and Phishing cybersecurity · 71d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation cybersecurity · 71d ago AI-powered hacking has exploded into industrial-scale threat, Google says cybersecurity · 71d ago Apple closed my bug report 4 times. MITRE wouldn't let it die. cybersecurity · 71d ago Instructure confirms hackers used Canvas flaw to deface portals BleepingComputer · 71d ago NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG cybersecurity · 71d ago Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach For [Blue|Purple] Teams in Cyber Defence · 71d ago Why Changing Passwords Doesn’t End an Active Directory Breach BleepingComputer · 71d ago CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection For [Blue|Purple] Teams in Cyber Defence · 71d ago looking for "evil" Websites Malware Analysis & Reports · 71d ago Google spotted an AI-developed zero-day before attackers could use it cybersecurity · 71d ago Google: Hackers used AI to develop zero-day exploit for web admin tool BleepingComputer · 71d ago Google spotted an AI-developed zero-day before attackers could use it CyberScoop · 71d ago Deterministic PE Structural Validation in IOCX v0.7.3 Malware Analysis & Reports · 71d ago beginner doubt cybersecurity · 71d ago The Bug Bounty Roadmap I'd Follow If I Started Over (With AI) NahamSec · 71d ago Is the AI hype helping or killing your bug bounty dreams? #hacking #bugbounty NahamSec · 71d ago where is the location of Files by Google on Android? hacking: security in practice · 71d ago Webinar this week: Prevention alone is not enough against modern attacks BleepingComputer · 71d ago I got my CEH Certification. SO what now? cybersecurity · 71d ago Construction to Cyber PM cybersecurity · 71d ago Deterministic PE Validation for Blue Teams - IOCX v0.7.3 For [Blue|Purple] Teams in Cyber Defence · 71d ago Reading old s4 memory with xgecu t48 hacking: security in practice · 71d ago [ Removed by Reddit ] cybersecurity · 71d ago Something got downloaded on my phone and then dissappeared cybersecurity · 71d ago Bleeding Llama cybersecurity · 71d ago The missing cybersecurity leader in small business CyberScoop · 71d ago Hack a data center? hacking: security in practice · 71d ago Do accountants even care about cybersecurityas much? cybersecurity · 71d ago Where Have All the Complex Windows Malware and Their Analyses Gone? cybersecurity · 71d ago TrickMo Android banker adopts TON blockchain for covert comms BleepingComputer · 71d ago Eyes wide open: How to mitigate the security and privacy risks of smart glasses WeLiveSecurity · 71d ago sl1nk link Malware Analysis & Reports · 71d ago MyAudi app:Security issues in Audi Connected Vehicle experience Technical Information Security Content & Discussion · 71d ago Delving deep into threat detection: My logic for abnormal EventID 7 activity For [Blue|Purple] Teams in Cyber Defence · 71d ago Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot Technical Information Security Content & Discussion · 71d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 71d ago Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust cybersecurity · 71d ago Was the reconnaissance in Bugbounty overrated? cybersecurity · 71d ago Cybersecurity beginner building an experimental log analyzer — looking for advice cybersecurity · 71d ago Anyone else worried about AI being a security nightmare? cybersecurity · 71d ago Snyk not working cybersecurity · 71d ago Malicious tenants paid us to abuse our RMM. We blocked them cybersecurity · 71d ago Help reasuring parents with an email parsing tool (i will not promote) cybersecurity · 71d ago Check out my matplotlib of BLE live wire data for Oura ring! Reverse Engineering · 71d ago Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows Reverse Engineering · 71d ago NZ announces sanctions on malicious Russian cyber actors, online platforms For [Blue|Purple] Teams in Cyber Defence · 71d ago Update: Ongoing Checkmarx Supply Chain Security Incident For [Blue|Purple] Teams in Cyber Defence · 71d ago DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this? cybersecurity · 71d ago Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop Reverse Engineering · 71d ago cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers cybersecurity · 71d ago 5 years as a Level 1 Security Analyst and wanting to transition into consulting cybersecurity · 71d ago How to download a RAT for myself Malware Analysis & Reports · 71d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass cybersecurity · 71d ago New into network pentesting. cybersecurity · 71d ago Is it worth it to switching field to cybersecurity ? cybersecurity · 71d ago Neeed help to get cybersecurity internship. cybersecurity · 71d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 71d ago Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America Trend Micro Research, News, Perspectives · 71d ago Cybersecurity and ADHD cybersecurity · 71d ago Mythos, MOAK, CTEM and the End of CVE Chasing Technical Information Security Content & Discussion · 71d ago Autonomous Vulnerability Hunting with MCP hacking: security in practice · 71d ago Anyone dealt with a VulDB submission rejection? Resubmit or reply? cybersecurity · 71d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass Reverse Engineering · 71d ago Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory) Reverse Engineering · 71d ago Autonomous Vulnerability Hunting with MCP Technical Information Security Content & Discussion · 71d ago GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3 Reverse Engineering · 71d ago ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025 For [Blue|Purple] Teams in Cyber Defence · 71d ago Unmanaged PowerShell Execution: Hunting Beyond powershell.exe For [Blue|Purple] Teams in Cyber Defence · 71d ago Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign For [Blue|Purple] Teams in Cyber Defence · 71d ago ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing cybersecurity · 71d ago Static Devirtualization of Themida For [Blue|Purple] Teams in Cyber Defence · 71d ago Now You See Me: AADGraphActivityLogs For [Blue|Purple] Teams in Cyber Defence · 71d ago I have a malware and need help removing it. someone please help me 🙏 cybersecurity · 72d ago [Write-up] CyberDefenders: Wiredive Lab For [Blue|Purple] Teams in Cyber Defence · 72d ago PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra Reverse Engineering · 72d ago I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too? cybersecurity · 72d ago EasySec - Update cybersecurity · 72d ago What is the cybersecurity equivalent of leaving your spare key under the doormat? cybersecurity · 72d ago ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement Technical Information Security Content & Discussion · 72d ago Hackers abuse Google ads, Claude.ai chats to push Mac malware BleepingComputer · 72d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 72d ago VICE: Cyberwar | Full Season 2 | Blueprint cybersecurity · 72d ago Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures cybersecurity · 72d ago Email OTP as default (often ONLY) password isn’t the solution cybersecurity · 72d ago page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer For [Blue|Purple] Teams in Cyber Defence · 72d ago Soc analyse cybersecurity · 72d ago Police shut down reboot of Crimenetwork marketplace, arrest admin BleepingComputer · 72d ago AI DNS Resolver hacking: security in practice · 72d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 72d ago Price rising cybersecurity · 72d ago Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple Technical Information Security Content & Discussion · 72d ago JDownloader — Website installer incident (May 2026) For [Blue|Purple] Teams in Cyber Defence · 72d ago AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report cybersecurity · 72d ago Possible security incident against Arup Group cybersecurity · 72d ago Can honeypots be used this way? cybersecurity · 72d ago Is it true that the professionals have the worst setups? hacking: security in practice · 72d ago The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice. Technical Information Security Content & Discussion · 72d ago I think AI just quietly killed the 90-day disclosure window. cybersecurity · 72d ago TCM and Educate 360 are bugged cybersecurity · 72d ago The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate." For [Blue|Purple] Teams in Cyber Defence · 72d ago Got an alert from google what should I do? cybersecurity · 72d ago UK jobs cybersecurity · 72d ago AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT For [Blue|Purple] Teams in Cyber Defence · 72d ago Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏 cybersecurity · 72d ago Outrunning SHA256 with Physics Technical Information Security Content & Discussion · 72d ago EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine) For [Blue|Purple] Teams in Cyber Defence · 72d ago Worst company cybersecurity · 72d ago Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning cybersecurity · 72d ago I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage hacking: security in practice · 72d ago Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months) cybersecurity · 72d ago ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring) cybersecurity · 72d ago App Store Question - Darato Sport / Dofu Sport / Kofu cybersecurity · 72d ago Help! - My Parents Computer is Hacked cybersecurity · 72d ago Refining hacking basics — scaling them aswell hacking: security in practice · 72d ago Ran lumma stealer from a recaptcha scam cybersecurity · 72d ago What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do Trend Micro Research, News, Perspectives · 72d ago Port 5986 question cybersecurity · 72d ago CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse! cybersecurity · 72d ago cyber security/ segurança da informação cybersecurity · 72d ago Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers For [Blue|Purple] Teams in Cyber Defence · 72d ago College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains cybersecurity · 72d ago Help with an Escalating Cyber-Stalker cybersecurity · 72d ago RRW - Rick Roll WiFi cybersecurity · 72d ago Best resources to start learning python for cybersecurity and automation cybersecurity · 72d ago Writing a Naive LLVM-based Devirtualizer For [Blue|Purple] Teams in Cyber Defence · 72d ago Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game. cybersecurity · 72d ago Memory Poisoning AI Agents via ChromaDB Technical Information Security Content & Discussion · 72d ago Defence in Depth: A Practical Secure Corporate Network Topology Technical Information Security Content & Discussion · 72d ago Where Have All the Complex Windows Malware and Their Analyses Gone? For [Blue|Purple] Teams in Cyber Defence · 72d ago JDownloader site hacked to replace installers with Python RAT malware cybersecurity · 72d ago JDownloader site hacked to replace installers with Python RAT malware BleepingComputer · 72d ago Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram Technical Information Security Content & Discussion · 73d ago Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More) Technical Information Security Content & Discussion · 73d ago How can I fix my browser remembering what he had open last cybersecurity · 73d ago MS 360 CoPilot issues cybersecurity · 73d ago I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details cybersecurity · 73d ago ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12. cybersecurity · 73d ago eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback cybersecurity · 73d ago HackTheBox - Overwatch IppSec · 73d ago I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you cybersecurity · 73d ago AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic) hacking: security in practice · 73d ago Fake OpenAI repository on Hugging Face pushes infostealer malware BleepingComputer · 73d ago OWASP TOP 10 LLM 2026 Community voting cybersecurity · 73d ago When prompts become shells: RCE vulnerabilities in AI agent frameworks For [Blue|Purple] Teams in Cyber Defence · 73d ago Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus For [Blue|Purple] Teams in Cyber Defence · 73d ago MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) For [Blue|Purple] Teams in Cyber Defence · 73d ago Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor For [Blue|Purple] Teams in Cyber Defence · 73d ago Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles. For [Blue|Purple] Teams in Cyber Defence · 73d ago Second security incident at Instructure (Canvas) cybersecurity · 73d ago Wtf OPEN Ai Malware Analysis & Reports · 73d ago Bridging the Gap Between Vulnerabilities and Working Exploits hacking: security in practice · 73d ago um you guys is my hacker stupid? hacking: security in practice · 73d ago UK Advice Needed - VA+ Training? cybersecurity · 73d ago Gateweb - Secure Web Gateway cybersecurity · 73d ago Those who are in Detection engineering cybersecurity · 73d ago Can someone tell me of a trustable hacker? cybersecurity · 73d ago MSPs, how are you handling AI usage across your customer environments today? cybersecurity · 73d ago Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write cybersecurity · 73d ago How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there? cybersecurity · 73d ago ecpptv3 Exam in 3–4 Days — cybersecurity · 73d ago Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026 For [Blue|Purple] Teams in Cyber Defence · 73d ago Member of Prolific Russian Ransomware Group Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 73d ago EasterBunny: advanced espionage artifacts attributed to APT29 For [Blue|Purple] Teams in Cyber Defence · 73d ago AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES cybersecurity · 73d ago Did CISA helped you land a job ? cybersecurity · 73d ago Tracking the "Sorry" Extortionist Campaign Against cPanel Websites For [Blue|Purple] Teams in Cyber Defence · 73d ago PositiveIntent: Evasive loader for .NET Framework assemblies For [Blue|Purple] Teams in Cyber Defence · 73d ago The Accidental C2: Exploring Dev Tunnels for Remote Access For [Blue|Purple] Teams in Cyber Defence · 73d ago Living of the Land - DISM Sandbox Provider Hijack For [Blue|Purple] Teams in Cyber Defence · 73d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode For [Blue|Purple] Teams in Cyber Defence · 73d ago CTO at NCSC Summary: week ending May 10th cybersecurity · 73d ago CTO at NCSC Summary: week ending May 10th For [Blue|Purple] Teams in Cyber Defence · 73d ago ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure For [Blue|Purple] Teams in Cyber Defence · 73d ago PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale For [Blue|Purple] Teams in Cyber Defence · 73d ago Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo For [Blue|Purple] Teams in Cyber Defence · 73d ago pre pre junior needs help(guidance pls) cybersecurity · 73d ago DARWIS Taka - Web vulnerability scanner with Optional AI Validation For [Blue|Purple] Teams in Cyber Defence · 73d ago Trojan malware cybersecurity · 73d ago SANs Courses: How do people get their employers to pay? cybersecurity · 73d ago NIS2 Article 21: turning compliance controls into technical security evidence cybersecurity · 73d ago This GBA Rom is making is having a weird behavior in the Sandbox, why? cybersecurity · 73d ago This GBA ROM makes some weird things in the sanbox, would love to understand why hacking: security in practice · 73d ago Why AI agent governance feels harder than traditional security models cybersecurity · 73d ago Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection Technical Information Security Content & Discussion · 73d ago Confused about what certs are important cybersecurity · 73d ago Would getting Security+ be worthless for me? cybersecurity · 73d ago [Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc) Reverse Engineering · 73d ago Submit probe test — shadow DOM click cybersecurity · 73d ago Threat intelligence in OT (Power equipments) cybersecurity · 73d ago Why was he banned? hacking: security in practice · 73d ago Securing CI/CD for an open source project: lessons from Cilium Technical Information Security Content & Discussion · 73d ago LAB Setup hacking: security in practice · 73d ago SunnyDayBPF: eBPF telemetry integrity research for detection engineering For [Blue|Purple] Teams in Cyber Defence · 73d ago Ethical malware development community hacking: security in practice · 74d ago SOC Analyst cybersecurity · 74d ago PAWs, PAM and PIM..what is best practice? cybersecurity · 74d ago This is the most in-depth analysis I have found on the Instructure/Canvas breach so far. cybersecurity · 74d ago Poland says hackers breached water treatment plants, and the U.S. is facing the same threat cybersecurity · 74d ago Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments CyberScoop · 74d ago Has Instructure paid SH? hacking: security in practice · 74d ago Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web. cybersecurity · 74d ago NVIDIA confirms GeForce NOW data breach affecting Armenian users BleepingComputer · 74d ago Quacc++: Automated Open Source Vulnerability Discovery cybersecurity · 74d ago Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me. hacking: security in practice · 74d ago 60% of MD5 password hashes are crackable in under an hour cybersecurity · 74d ago Built a correlation engine that chains AD findings into attack paths automatically. cybersecurity · 74d ago New trends (not mainstream) hacking: security in practice · 74d ago Why More Analysts Won’t Solve Your SOC’s Alert Problem BleepingComputer · 74d ago Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!) Reverse Engineering · 74d ago Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests cybersecurity · 74d ago ShinyHunters claims nearly 9,000 schools affected by Canvas data breach CyberScoop · 74d ago Trellix source code breach claimed by RansomHouse hackers BleepingComputer · 74d ago Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI CyberScoop · 74d ago JDownloader's official website delivered Python RAT cybersecurity · 74d ago JDownloader's official website delivered Python RAT Malware Analysis & Reports · 74d ago Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) cybersecurity · 74d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. cybersecurity · 74d ago ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12 Technical Information Security Content & Discussion · 74d ago Note taking apps and advice cybersecurity · 74d ago CISA gives feds four days to patch Ivanti flaw exploited as zero-day BleepingComputer · 74d ago Best tools to find exposed web services by HTML title / HTTP response? hacking: security in practice · 74d ago IMF Warns AI Could Trigger Global Financial Cyber Crisis cybersecurity · 74d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 74d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 74d ago New Linux 'Dirty Frag' zero-day gives root on all major distros cybersecurity · 74d ago Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2 Reverse Engineering · 74d ago Is the ISC2 Cybersecurity program still worth it? cybersecurity · 74d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama For [Blue|Purple] Teams in Cyber Defence · 74d ago Zara data breach exposed personal information of 197,000 people BleepingComputer · 74d ago Canvas getting hit during finals week shows how fragile “critical SaaS” has become cybersecurity · 74d ago Are websites exposed to the internet under attack almost every hour, even if they're small? cybersecurity · 74d ago Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config Technical Information Security Content & Discussion · 74d ago Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou... For [Blue|Purple] Teams in Cyber Defence · 74d ago Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken cybersecurity · 74d ago Former govt contractor convicted for wiping dozens of federal databases BleepingComputer · 74d ago What the **** is happening in cybersecurity space ? cybersecurity · 74d ago New Linux 'Dirty Frag' zero-day gives root on all major distros BleepingComputer · 74d ago Canvas is back up, but now what? cybersecurity · 74d ago Copy Fail (CVE-2026-31431): A Technical Deep Dive Technical Information Security Content & Discussion · 74d ago Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago? hacking: security in practice · 74d ago AI Agents Have a Security Problem. IronClaw is Fixing It. hacking: security in practice · 74d ago Instagram is getting rid of end to end encryption, what now? cybersecurity · 74d ago Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack For [Blue|Purple] Teams in Cyber Defence · 74d ago Dirty Frag: Universal Linux LPE For [Blue|Purple] Teams in Cyber Defence · 74d ago Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication. For [Blue|Purple] Teams in Cyber Defence · 74d ago Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea For [Blue|Purple] Teams in Cyber Defence · 74d ago New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation cybersecurity · 74d ago Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable". cybersecurity · 74d ago Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group? cybersecurity · 74d ago SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals Reverse Engineering · 74d ago Cushman and Wakefield confirms cyberattack cybersecurity · 74d ago Egnyte potential ransomware attack cybersecurity · 74d ago So canvas is down, what'll happen if they can't come to an argreement? cybersecurity · 74d ago Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now. cybersecurity · 74d ago I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow! Reverse Engineering · 74d ago /Why/ is Shinyhunters targeting Canvas? cybersecurity · 74d ago Canvas Hack - Any Guesses How? cybersecurity · 74d ago Should I build a virtual or physical lab? cybersecurity · 74d ago Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12 cybersecurity · 74d ago Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata cybersecurity · 74d ago Audit/Cybersecurity cybersecurity · 74d ago Issues removing Trellix (and specifically solidifier) cybersecurity · 74d ago Pentagon eyes 3-year cyber training requirement, overriding new Army policy cybersecurity · 74d ago A hacker ran me over with a robot lawn mower - The Verge hacking: security in practice · 74d ago Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia For [Blue|Purple] Teams in Cyber Defence · 74d ago Canvas login portals hacked in mass ShinyHunters extortion campaign BleepingComputer · 74d ago How much personal info will be leaked by the recent Canvas hack?? cybersecurity · 74d ago OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI For [Blue|Purple] Teams in Cyber Defence · 74d ago Dirty Frag and canvas cybersecurity · 74d ago New TCLBanker malware self-spreads over WhatsApp and Outlook BleepingComputer · 74d ago Hackers deface school login pages after claiming another Instructure hack cybersecurity · 74d ago Happened today hacking: security in practice · 74d ago Ivanti customers confront yet another actively exploited zero-day CyberScoop · 74d ago Did I destroy my career by being loyal to an arguably good company? cybersecurity · 74d ago Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo Technical Information Security Content & Discussion · 74d ago V4bel/dirtyfrag - Universal Linux Local Privilege Escalation cybersecurity · 74d ago Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC For [Blue|Purple] Teams in Cyber Defence · 74d ago What is CYBERRANT? cybersecurity · 74d ago Canvas is down as ShinyHunters hack forces outage cybersecurity · 74d ago Shinyhunters and Canvas hacking: security in practice · 74d ago New Dirty Frag Linux Bug Emerges in Wake of Copy Fail cybersecurity · 74d ago Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today. cybersecurity · 74d ago How is GRC work in a MSSP? cybersecurity · 74d ago SH and BF phishing console cybersecurity · 74d ago Trump officials are steering a cybersecurity scholarship program toward AI CyberScoop · 74d ago Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth? cybersecurity · 74d ago Dirty Frag - Linux LPE similiar to Copy Fail Technical Information Security Content & Discussion · 74d ago Socure authenticating AI identity as real. cybersecurity · 75d ago The first FREE online WebAssembly Reverse Engineering workbench (and how we built it) Reverse Engineering · 75d ago New PCPJack worm steals credentials, cleans TeamPCP infections BleepingComputer · 75d ago Automated SSL Certificate Renewals - What is your setup? cybersecurity · 75d ago Shinyhunters and Canvas cybersecurity · 75d ago What Cli execution do you use for a script file? cybersecurity · 75d ago Australia warns of ClickFix attacks pushing Vidar Stealer malware BleepingComputer · 75d ago Fiserv security incident - data breach notice cybersecurity · 75d ago Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments cybersecurity · 75d ago Honey Tokens: Bait Credentials That Catch Breaches Technical Information Security Content & Discussion · 75d ago I graduate next year with a Cybersecurity degree. cybersecurity · 75d ago An unknown malware threat. There is no such thing as a 100% detection. Malware Analysis & Reports · 75d ago Asking about Cortex cybersecurity · 75d ago CVE-2026-42511 Breakdown: RCE in FreeBSD Technical Information Security Content & Discussion · 75d ago Apache Caldera cybersecurity · 75d ago What’s the “unsexy” problem in cyber that’s actually a total disaster? cybersecurity · 75d ago Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE cybersecurity · 75d ago Ivanti warns of new EPMM flaw exploited in zero-day attacks BleepingComputer · 75d ago As a developer, should I use AI to improve security? cybersecurity · 75d ago My company has an MSP that manages our employee endpoints but we cant access the software they use to manage cybersecurity · 75d ago Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804 Technical Information Security Content & Discussion · 75d ago Americans sentenced for running 'laptop farms' for North Korea cybersecurity · 75d ago Is my laptop hijacked ? cybersecurity · 75d ago The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls BleepingComputer · 75d ago American duo sentenced for hosting laptop farms for North Korean IT workers CyberScoop · 75d ago claude ai gave security beta to Enterprise plans only what can we do as pentesters? cybersecurity · 75d ago Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline cybersecurity · 75d ago Americans sentenced for running 'laptop farms' for North Korea BleepingComputer · 75d ago Advice for path to land job SOC in France cybersecurity · 75d ago Possible Major Vulnerability: Chromium used by current version of PRTG cybersecurity · 75d ago Mythos AI may be a cybersecurity threat, but it follows the rules of the game cybersecurity · 75d ago Control Checks using AI. cybersecurity · 75d ago How do native password managers clear the clipboard? cybersecurity · 75d ago VLC Media Player MKV Exploit Analysis Reverse Engineering · 75d ago Graduating CS Student but Wanna Start my Career in Cybersecurity cybersecurity · 75d ago Crypto gang member gets 6.5 years for role in $230 million heist BleepingComputer · 75d ago An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support) Technical Information Security Content & Discussion · 75d ago Webinar: Why modern attacks require both security and recovery BleepingComputer · 75d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 75d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 75d ago MAXHUB Pivot Client Application All CISA Advisories · 75d ago Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI Technical Information Security Content & Discussion · 75d ago Claude-Themed Malware Campaigns cybersecurity · 75d ago DeepFake it till you make it. cybersecurity · 75d ago The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments cybersecurity · 75d ago Palo Alto Networks firewall zero-day exploited for nearly a month BleepingComputer · 75d ago What niche in cybersecurity should I go for, with my background in Angular & .NET ? cybersecurity · 75d ago Successor for Kaspersky Endpoint Security cybersecurity · 75d ago Fake Claude AI website delivers new 'Beagle' Windows malware BleepingComputer · 75d ago One House Democrat is pressing Commerce on the government’s spyware use CyberScoop · 75d ago Fake call logs, real payments: How CallPhantom tricks Android users WeLiveSecurity · 75d ago Detecting BEC Persistence with KQL For [Blue|Purple] Teams in Cyber Defence · 75d ago Modify md5sum of a file hacking: security in practice · 75d ago Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago cybersecurity · 75d ago SOC Analyst tier 1 (Entry Level) ?? cybersecurity · 75d ago Unpacking Russian-Iranian Private-Sector Cyber Connections For [Blue|Purple] Teams in Cyber Defence · 75d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 75d ago Made cybersecurity merch as an infosec practitioner — honest feedback welcome cybersecurity · 75d ago Fixing the password problem is as easy as 123456 WeLiveSecurity · 75d ago As AI agents become users of company data - what is needed to keep data secure? cybersecurity · 75d ago Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities. cybersecurity · 75d ago AI inference is quietly becoming a security problem cybersecurity · 75d ago is winrar 7.13 vulnerable to extraction exploits? cybersecurity · 75d ago Tried explaining internet encryption in a beginner-friendly but accurate way, feedback? cybersecurity · 75d ago Is the EC-Council CTIA Certification Worth It for Career Growth? cybersecurity · 75d ago POC Android vuln 2026 cybersecurity · 75d ago Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise cybersecurity · 75d ago Opinions on Mimecast cybersecurity · 75d ago Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution For [Blue|Purple] Teams in Cyber Defence · 75d ago What's going on in the field of Cybersecurity 🫣. cybersecurity · 75d ago How do teams preserve institutional pentest knowledge when senior testers leave? cybersecurity · 75d ago CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE cybersecurity · 75d ago Sophos NDR on Proxmox cybersecurity · 75d ago Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites Malware Analysis & Reports · 75d ago Quacc++: Automated Open Source Vulnerability Discovery Technical Information Security Content & Discussion · 75d ago Hackers abuse Google ads for GoDaddy ManageWP login phishing BleepingComputer · 75d ago A DOD contractor’s API flaw exposed military course data and service member records CyberScoop · 75d ago On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029. cybersecurity · 75d ago DOJ says ransomware gang tapped into Russian government databases cybersecurity · 75d ago DAEMON Tools devs confirm breach, release malware-free version cybersecurity · 75d ago Have there been instances where your SOC has suffered a cybersecurity attack? cybersecurity · 75d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk For [Blue|Purple] Teams in Cyber Defence · 75d ago Inadvertent Injections For [Blue|Purple] Teams in Cyber Defence · 75d ago A critical Palo Alto PAN-OS zero-day is being exploited in the wild CyberScoop · 75d ago OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM hacking: security in practice · 75d ago OpenCTI founder, Samuel Hassine, arrested and charged with CSAM cybersecurity · 75d ago Deepfake Platform cybersecurity · 75d ago Critical vm2 sandbox bug lets attackers execute code on hosts BleepingComputer · 76d ago Trellix Licence Query cybersecurity · 76d ago New Cisco DoS flaw requires manual reboot to revive devices BleepingComputer · 76d ago CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal For [Blue|Purple] Teams in Cyber Defence · 76d ago Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML Malware Analysis & Reports · 76d ago Instructure hacker claims data theft from 8,800 schools, universities cybersecurity · 76d ago Is AI generated code creating a non-linear security problem for AppSec teams? cybersecurity · 76d ago Jailbreaking my cars infotainment system and implementing my own custom software hacking: security in practice · 76d ago Binance fixed the IP whitelist gap — but the disclosure process is still broken Technical Information Security Content & Discussion · 76d ago D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says cybersecurity · 76d ago DAEMON Tools devs confirm breach, release malware-free version BleepingComputer · 76d ago where is the original wormgpt hacking: security in practice · 76d ago Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security cybersecurity · 76d ago Norton Antivirus and Other Norton Software cybersecurity · 76d ago Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home? cybersecurity · 76d ago We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes. cybersecurity · 76d ago Download a malware a while ago, someone trying to log into my ios account cybersecurity · 76d ago Are there any chill hacking youtubers? hacking: security in practice · 76d ago Org Restructure cybersecurity · 76d ago Non-Determinism of Maps in Golang: Why, How, and the Consequences Technical Information Security Content & Discussion · 76d ago Does SOC 2 actually reduce questionnaires, or just change them? cybersecurity · 76d ago Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views cybersecurity · 76d ago Why ransomware attacks succeed even when backups exist BleepingComputer · 76d ago How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically? cybersecurity · 76d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Reverse Engineering · 76d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Technical Information Security Content & Discussion · 76d ago Ran phishing awareness training for 200+ non-tech employees cybersecurity · 76d ago Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware For [Blue|Purple] Teams in Cyber Defence · 76d ago Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk cybersecurity · 76d ago Vulnerability Garden Technical Information Security Content & Discussion · 76d ago Vulnerability Garden cybersecurity · 76d ago Palo Alto Firewall Zero-Day Under Active Exploitation cybersecurity · 76d ago MuddyWater hackers use Chaos ransomware as a decoy in attacks BleepingComputer · 76d ago Webinar: Why network incidents escalate and how to fix response gaps BleepingComputer · 76d ago Cyber Security Militias cybersecurity · 76d ago Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk cybersecurity · 76d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 76d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 76d ago Took me a decade to turn quantum computing into what programmers can easily learn, big announcement hacking: security in practice · 76d ago Lilygo T-Embed Glitching etc hacking: security in practice · 76d ago CyberSecurity Nightmares cybersecurity · 76d ago Can I use NanoKVM if it's just to turn on pc? cybersecurity · 76d ago got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something? cybersecurity · 76d ago How to learn tools for cybersecurity? cybersecurity · 76d ago 'CopyFail' attackers start cashing in on Linux flaw cybersecurity · 76d ago Anybodybodybdown for a team/studygroup? cybersecurity · 76d ago Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today? hacking: security in practice · 76d ago I was hacked due to sim card spoofing cybersecurity · 76d ago Palo Alto Networks warns of firewall RCE zero-day exploited in attacks BleepingComputer · 76d ago Chrome is quietly installing a 4GB AI model on your device cybersecurity · 76d ago Dev vs Security role cybersecurity · 76d ago Discord bot C2 infrastructure Malware Analysis & Reports · 76d ago Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed For [Blue|Purple] Teams in Cyber Defence · 76d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 76d ago UAT-8302 and its box full of malware For [Blue|Purple] Teams in Cyber Defence · 76d ago Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft cybersecurity · 76d ago Oracle Debuts Monthly Critical Security Patch Updates cybersecurity · 76d ago Sec engineer / developer? cybersecurity · 76d ago When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them? cybersecurity · 76d ago Are we actually seeing more vulnerabilities or just more noise? cybersecurity · 76d ago Cybersecurity jobs in red team cybersecurity · 76d ago Question cybersecurity · 76d ago What’s the biggest mistake people make even after installing antivirus? cybersecurity · 76d ago CVE-2026-0073 Android adbd TLS client-authentication bypass For [Blue|Purple] Teams in Cyber Defence · 76d ago One KQL query you should have saved in your toolkit (most don’t) For [Blue|Purple] Teams in Cyber Defence · 76d ago New dashboard tracks ransomware groups by their reliance on Infostealer credentials cybersecurity · 76d ago ant4g0nist/pyre: Ghidra decompiler in your browser Reverse Engineering · 76d ago CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier? For [Blue|Purple] Teams in Cyber Defence · 76d ago Found a possibly interesting live attack hacking: security in practice · 76d ago What would you say if your security lead said this... cybersecurity · 76d ago What would be the goto setup in AWS for security purposes? cybersecurity · 76d ago CREST CRT Exam 2025/2026 Experiences cybersecurity · 76d ago Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside For [Blue|Purple] Teams in Cyber Defence · 76d ago Microsoft Edge stores your passwords in plaintext RAM... on purpose cybersecurity · 76d ago Supporting the National Cyber Strategy: How TrendAI™ Helps Trend Micro Research, News, Perspectives · 76d ago Export/Backup ChatGPT chats hacking: security in practice · 76d ago Como começar? cybersecurity · 76d ago Possible Password Leak? Curious if Anyone Has Seen This Before cybersecurity · 76d ago Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source! Reverse Engineering · 76d ago Not a Hack. A Handout. Inside the GTFOice.org Data Exposure cybersecurity · 76d ago Besoin de conseils sur une DMZ automatisée cybersecurity · 76d ago Microsoft, Google and xAI will let the government test their AI models before launch cybersecurity · 76d ago Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073 cybersecurity · 76d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 76d ago New stealthy Quasar Linux malware targets software developers BleepingComputer · 76d ago SMB Header Signature for Tagging in Firewall cybersecurity · 76d ago Question regarding VDP cybersecurity · 76d ago Working on what i should do for the next 3 years cybersecurity · 76d ago Question for Security Professionals cybersecurity · 76d ago Do tech companies lifecycle-manage public DNS records to prevent dangling DNS? cybersecurity · 76d ago Instructure hacker claims data theft from 8,800 schools, universities BleepingComputer · 76d ago Vulnerability Summary for the Week of April 27, 2026 cybersecurity · 76d ago Scan. Secure. Simplify. — Free Web Tools Platform Technical Information Security Content & Discussion · 76d ago Cisco releases open-source ‘DNA test for AI models’ cybersecurity · 76d ago Cybersecurity is becoming too AI dependent is that a problem cybersecurity · 76d ago Foxconn Wisconsin outage raises cyber questions cybersecurity · 76d ago How stressful is GRC? cybersecurity · 76d ago News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market The Last Watchdog · 76d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482) Technical Information Security Content & Discussion · 76d ago Salesforce pentesting novel techniques- how to be an apex predator Technical Information Security Content & Discussion · 76d ago DAEMON Tools trojanized in supply-chain attack to deploy backdoor BleepingComputer · 76d ago Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia cybersecurity · 76d ago Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India cybersecurity · 77d ago Archer for a non-regulated medium sized company? cybersecurity · 77d ago Cybersecurity statistics of the week (April 27th - May 3rd) cybersecurity · 77d ago Reverse-engineering the 1998 Ultima Online demo server Reverse Engineering · 77d ago Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM. cybersecurity · 77d ago One-Click Refunds Are Not as Hard as You Think Blog – Forter · 77d ago Student hacked Taiwan high-speed rail to trigger emergency brakes BleepingComputer · 77d ago 🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records For [Blue|Purple] Teams in Cyber Defence · 77d ago Where to find reliable vendors? cybersecurity · 77d ago DigiCert: Misissued code signing certificates Technical Information Security Content & Discussion · 77d ago Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts? cybersecurity · 77d ago We wrote a guide on securing Claude across the enterprise — here's the core framework (with download) cybersecurity · 77d ago Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium. cybersecurity · 77d ago Hardware reverse enginnering first project. Love some advice cybersecurity · 77d ago Microsoft Edge Stores Passwords in Process Memory, Posing Risk cybersecurity · 77d ago Currently working on cybersecurity, looking for advice cybersecurity · 77d ago Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning cybersecurity · 77d ago Major AI Clients Shipping With Broken OAuth Implementations Technical Information Security Content & Discussion · 77d ago CISO course valuation cybersecurity · 77d ago Inside Faxanadu series — deep dive into how this NES title works Reverse Engineering · 77d ago EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing Reverse Engineering · 77d ago Popular DAEMON Tools software compromised For [Blue|Purple] Teams in Cyber Defence · 77d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 77d ago Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise For [Blue|Purple] Teams in Cyber Defence · 77d ago GRC Path to CISO (Certifications) cybersecurity · 77d ago Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities For [Blue|Purple] Teams in Cyber Defence · 77d ago CISOs and pentest buyers, what's the worst thing you've seen in a pentest report? cybersecurity · 77d ago FTC to ban data broker Kochava from selling Americans’ location data BleepingComputer · 77d ago How to enforce M365 Sign-in frequency on corporate laptops? cybersecurity · 77d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs cybersecurity · 77d ago The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check. BleepingComputer · 77d ago The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss BleepingComputer · 77d ago Built an independent directory of AI Act / AI governance tools, feedback? cybersecurity · 77d ago ScarCruft APT group compromises gaming platform in a supply-chain attack cybersecurity · 77d ago Just curious cybersecurity · 77d ago 'Copy Fail' is a real Linux security crisis wrapped in AI slop cybersecurity · 77d ago Analysis malicious DLL cybersecurity · 77d ago Cyber security free course cybersecurity · 77d ago Vimeo data breach exposes personal information of 119,000 people BleepingComputer · 77d ago Does certification expires? cybersecurity · 77d ago HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10 Technical Information Security Content & Discussion · 77d ago IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening Malware Analysis & Reports · 77d ago Panicking Malware Analysis & Reports · 77d ago ABB B&R Automation Studio All CISA Advisories · 77d ago ABB B&R Automation Runtime All CISA Advisories · 77d ago Hitachi Energy PCM600 All CISA Advisories · 77d ago Johnson Controls CEM AC2000 All CISA Advisories · 77d ago ABB B&R PVI All CISA Advisories · 77d ago How the Story of a USB Penetration Test Went Viral darkreading · 77d ago We get paid to break into buildings for a living. Ask us anything! cybersecurity · 77d ago Pay2Key ransomware — any recovery path that’s actually worked? cybersecurity · 77d ago Google now offers up to $1.5 million for some Android exploits BleepingComputer · 77d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison cybersecurity · 77d ago Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF cybersecurity · 77d ago Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud Technical Information Security Content & Discussion · 77d ago How have you kept growing your knowledge in security when the job stops pushing you? cybersecurity · 77d ago Supply chain attack: DAEMON Tools Lite now contains a backdoor. Malware Analysis & Reports · 77d ago Accelerating Vulnerability Detection and Response at Oracle For [Blue|Purple] Teams in Cyber Defence · 77d ago The Danger of Multi-SSO AWS Cognito User Pools Technical Information Security Content & Discussion · 77d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison BleepingComputer · 77d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs BleepingComputer · 77d ago Copilot Cowork: From conversation to action across skills, integrations, and devices Microsoft 365 Blog · 77d ago Microsoft 365 Copilot, human agency, and the opportunity for every organization Microsoft 365 Blog · 77d ago The UK’s Age Verification Law Is Producing Compliance Theater cybersecurity · 77d ago Microsoft Edge: Passwords end up in memory as plaintext cybersecurity · 77d ago Do people still get viruses in 2026, or is that mostly a myth now? cybersecurity · 77d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 Technical Information Security Content & Discussion · 77d ago Mitigation script for Copy Fail vulnerability CVE-2026-31431 cybersecurity · 77d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 cybersecurity · 77d ago Is this fake too?🤣 hacking: security in practice · 77d ago Copy.fail: Why Internal LLMs Are Non-Negotiable for Security Reverse Engineering · 77d ago The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew For [Blue|Purple] Teams in Cyber Defence · 77d ago Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released cybersecurity · 77d ago ScarCruft hackers push BirdCall Android malware via game platform BleepingComputer · 77d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack WeLiveSecurity · 77d ago DigiCert breached via malicious screensaver file cybersecurity · 77d ago I just figured out my dad use to be a Phreaker in the 1980s hacking: security in practice · 77d ago Caido Payloads and Scanner of Endpoints cybersecurity · 77d ago Proton Pass: Second-Password Bypass Through Emergency Access Technical Information Security Content & Discussion · 77d ago What of my favorite videos🙂 hacking: security in practice · 77d ago CISO Security Mind Map 2026 cybersecurity · 77d ago Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker cybersecurity · 77d ago Best tools for blocking spam calls and spam links? hacking: security in practice · 77d ago Amazon SES increasingly abused in phishing to evade detection cybersecurity · 77d ago someone else’s UI appearing on screen for split second— possible hacker?? hacking: security in practice · 77d ago AI Security Trainings cybersecurity · 77d ago Ai help cybersecurity · 77d ago ByDesign: observed behavior where file URLs remain accessible after unshare/delete cybersecurity · 77d ago Can Kali Linux still compete in cyber security or is it outdated? cybersecurity · 77d ago We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother Technical Information Security Content & Discussion · 77d ago Avoiding rouge AP detection in enterprise networks hacking: security in practice · 77d ago Who are your favorite cybersecurity YouTubers? cybersecurity · 77d ago CISOs, how are you balancing AI adoption with security risks these days? cybersecurity · 77d ago GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated. For [Blue|Purple] Teams in Cyber Defence · 77d ago dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025 For [Blue|Purple] Teams in Cyber Defence · 77d ago N-Day Research with AI: Using Ollama and n8n For [Blue|Purple] Teams in Cyber Defence · 77d ago San Diego Community College District fighting major cyberattack cybersecurity · 77d ago GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering hacking: security in practice · 77d ago San Diego Community College District fighting major cyberattack hacking: security in practice · 77d ago After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up cybersecurity · 77d ago Free resource: searchable archive of every BSides conference talk cybersecurity · 77d ago Lightning PyPI Compromise: Bun-Based Stealer cybersecurity · 77d ago Too much mother instinct? cybersecurity · 77d ago InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise Trend Micro Research, News, Perspectives · 77d ago L1 SOC Analyst for ~2 years - Should I still get the Security + Certification? cybersecurity · 77d ago Do CTFs help real world security skills, or just teach patterns? cybersecurity · 77d ago Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo cybersecurity · 77d ago Should I do Security + or Network + or A+? For CompTia cybersecurity · 77d ago Weaver E-cology critical bug exploited in attacks since March BleepingComputer · 77d ago Bug bounty is ruining how people learn exploitation cybersecurity · 77d ago ISO/IEC 27701:2025 Scope and Location cybersecurity · 77d ago Cybersecurity's 2026 Wild Ride cybersecurity · 77d ago We built a free multiplayer game that scores prompts on AI code security. cybersecurity · 77d ago RMM Tools Fuel Stealthy Phishing Campaign darkreading · 77d ago Production Usecases cybersecurity · 77d ago Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra Reverse Engineering · 77d ago How does vCISO work? cybersecurity · 77d ago Amazon SES increasingly abused in phishing to evade detection BleepingComputer · 77d ago Researchers report Amazon SES abused in phishing to evade detection BleepingComputer · 77d ago Trellix discloses data breach after source code repository hack cybersecurity · 77d ago CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path cybersecurity · 77d ago Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability darkreading · 77d ago Trellix confirms source code repo access incident cybersecurity · 78d ago Where do i find reverse engineers for actuators? Ideally in Shenzhen Reverse Engineering · 78d ago Employer Offering to Pay for my Certification test - Which one do I choose? cybersecurity · 78d ago John Strand Pay What You Can Information Security Core Skills live starting May 11th cybersecurity · 78d ago [CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2). Reverse Engineering · 78d ago Canvas Breach May Put 275M Users, 9,000 Schools at Risk cybersecurity · 78d ago Backdoored PyTorch Lightning package drops credential stealer BleepingComputer · 78d ago Is this not such a big deal cybersecurity · 78d ago 38 CVEs in Healthcare Software Used by 100,000 Medical Providers For [Blue|Purple] Teams in Cyber Defence · 78d ago Do email link checkers need to be 100%? cybersecurity · 78d ago Cybersecurity M&A Roundup: 33 Deals Announced in April 2026 cybersecurity · 78d ago Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation Malware Analysis & Reports · 78d ago Recs for pen testing and vulnerability solutions cybersecurity · 78d ago Identify telegram account holders cybersecurity · 78d ago AI Code Security Study: 6 LLMs vs OWASP Top 10 cybersecurity · 78d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers hacking: security in practice · 78d ago Recursively fuzzing MS-RPC structures and monitoring using ETW For [Blue|Purple] Teams in Cyber Defence · 78d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers cybersecurity · 78d ago Trellix discloses data breach after source code repository hack BleepingComputer · 78d ago Iwas developing a hacker game that transports the feeling of the 90s hacking: security in practice · 78d ago We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA cybersecurity · 78d ago Azure IaaS: Defense in depth built on secure-by-design principles Security | Microsoft Azure Blog | Microsoft Azure · 78d ago Cortex XDR Cloud Compromise Alerting cybersecurity · 78d ago Norton.com Verification Email out of the blue cybersecurity · 78d ago Atomic Red Team is now aligned with MITRE ATT&CK v19! cybersecurity · 78d ago Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX? cybersecurity · 78d ago Who are you guys using for your PCI ASV Scanning? cybersecurity · 78d ago Just passed my Security+ exam. Now what? cybersecurity · 78d ago I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work. cybersecurity · 78d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 78d ago [PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection) cybersecurity · 78d ago Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia darkreading · 78d ago Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350) cybersecurity · 78d ago An another open door to IoT devices cybersecurity · 78d ago Ideas on how to have personal google-like account synchronization system cybersecurity · 78d ago Lateral Movement - Cross-Session Activation Technical Information Security Content & Discussion · 78d ago Lateral Movement - Cross-Session Activation cybersecurity · 78d ago How did this guy even access another person's privated YouTube video without wayback machine? hacking: security in practice · 78d ago What MCP servers have actually made it into your day-to-day toolkit? cybersecurity · 78d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems hacking: security in practice · 78d ago They don’t hack, they borrow: How fraudsters target credit unions BleepingComputer · 78d ago Cyber Security Education as Self-Defence classes cybersecurity · 78d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk cybersecurity · 78d ago Use.ai cybersecurity · 78d ago Educational tech giant Instructure confirms data breach, ShinyHunters claims attack cybersecurity · 78d ago [WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation Reverse Engineering · 78d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems cybersecurity · 78d ago Stop Using AI Connectors Until You Watch This NahamSec · 78d ago One ChatGPT connector. One email. Full AI agent hijack. #BugBounty #PromptInjection #ai #hacking NahamSec · 78d ago IPod Nano Gets Three Monitors hacking: security in practice · 78d ago IDA-MCP Is Now RE-MCP With Ghidra Support Reverse Engineering · 78d ago Progress warns of critical MOVEit Automation auth bypass flaw BleepingComputer · 78d ago Webinar: Why MSPs must rethink security and backup strategies BleepingComputer · 78d ago Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference Reverse Engineering · 78d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems BleepingComputer · 78d ago Chrome "Best AdBlocker" trojanized extension - 100k downloads. hacking: security in practice · 78d ago How Dark Reading Lifted Off the Launchpad in 2006 darkreading · 78d ago Browsers making connection on port 3389 from loopback cybersecurity · 78d ago Microsoft confirms April Windows updates cause backup failures BleepingComputer · 78d ago Defender Flagged DigiCert Root Certs as Malware cybersecurity · 78d ago VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases For [Blue|Purple] Teams in Cyber Defence · 78d ago Another breach just hit Canvas (Instructure), and this one is worth a closer look. cybersecurity · 78d ago Over 40% of UK firms suffered cyber attack last year, survey finds cybersecurity · 78d ago EU should seek access to Anthropic's Mythos, Bundesbank says cybersecurity · 78d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha cybersecurity · 78d ago CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation. For [Blue|Purple] Teams in Cyber Defence · 78d ago 《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition) For [Blue|Purple] Teams in Cyber Defence · 78d ago nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution. For [Blue|Purple] Teams in Cyber Defence · 78d ago 蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery. For [Blue|Purple] Teams in Cyber Defence · 78d ago IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks cybersecurity · 78d ago People in cybersecurity, tell us what was the most epic moment in your career? cybersecurity · 78d ago Prerequisites for CARTP cybersecurity · 78d ago gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives For [Blue|Purple] Teams in Cyber Defence · 78d ago Claude Mythos Cyber Wake Up cybersecurity · 78d ago [ Removed by Reddit ] cybersecurity · 78d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 78d ago is trellix from mcafee good to use in 2026? cybersecurity · 78d ago Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list cybersecurity · 78d ago Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon For [Blue|Purple] Teams in Cyber Defence · 78d ago AMSI Page Guard Bypass (Rust PoC) For [Blue|Purple] Teams in Cyber Defence · 78d ago Any good open sources that bypass modern heuristic analysis? hacking: security in practice · 78d ago Meet Bluekit: The AI-Powered All-in-One Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 78d ago Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI For [Blue|Purple] Teams in Cyber Defence · 78d ago A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia For [Blue|Purple] Teams in Cyber Defence · 78d ago IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect For [Blue|Purple] Teams in Cyber Defence · 78d ago Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection For [Blue|Purple] Teams in Cyber Defence · 78d ago ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution… For [Blue|Purple] Teams in Cyber Defence · 78d ago Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia For [Blue|Purple] Teams in Cyber Defence · 78d ago [2603.28728] Study of Post Quantum status of Widely Used Protocols For [Blue|Purple] Teams in Cyber Defence · 78d ago Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin For [Blue|Purple] Teams in Cyber Defence · 78d ago Free apex hacks? hacking: security in practice · 78d ago Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning For [Blue|Purple] Teams in Cyber Defence · 78d ago Paypal Accesed by malware me being Stupid cybersecurity · 78d ago How was someone in another country able to read all my private messages without my password or clicking a link? cybersecurity · 78d ago code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint. For [Blue|Purple] Teams in Cyber Defence · 78d ago Secure Boot Inventory Data In Configuration Manager For [Blue|Purple] Teams in Cyber Defence · 78d ago EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time. For [Blue|Purple] Teams in Cyber Defence · 78d ago MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning. For [Blue|Purple] Teams in Cyber Defence · 78d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Technical Information Security Content & Discussion · 78d ago AI-powered honeypots: Turning the tables on malicious AI agents For [Blue|Purple] Teams in Cyber Defence · 78d ago Career Transition Help cybersecurity · 78d ago Alguien para hablar de cyberseguridad cybersecurity · 78d ago copy.golf — golf your exploits - smaller copy.fail exploits.. For [Blue|Purple] Teams in Cyber Defence · 78d ago DragonBreath: Dragon in the Kernel For [Blue|Purple] Teams in Cyber Defence · 78d ago What is this cybersecurity · 78d ago Your vibe-coded app is probably violating GDPR right now Technical Information Security Content & Discussion · 78d ago [SHOWCASE] Cascavel v3 hacking: security in practice · 78d ago Feeling lost and disappointed about finding a job just venting cybersecurity · 78d ago Slow at Learning/Cyber Security? cybersecurity · 78d ago Pokemon machine hacking: security in practice · 78d ago Suspicious traffic from web server cybersecurity · 78d ago Cyber security internship cybersecurity · 78d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 78d ago Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities Trend Micro Research, News, Perspectives · 78d ago Isn't Windows Defender a crap anymore? cybersecurity · 78d ago GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions) Reverse Engineering · 78d ago Learning Cyber cybersecurity · 78d ago Instructure confirms data breach, ShinyHunters claims attack BleepingComputer · 78d ago Vishing simulator cybersecurity · 78d ago Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others cybersecurity · 78d ago Worried about being tracked/banned for using an educational app on MuMu Player - Need advice cybersecurity · 78d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks cybersecurity · 78d ago Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance cybersecurity · 78d ago Prompt Injection in 2026: The Five Attack Patterns That Actually Matter cybersecurity · 78d ago I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine cybersecurity · 78d ago Random trojan detected? cybersecurity · 78d ago CRTA second attempt cybersecurity · 78d ago What’s the hardest thing to learn in cybersecurity? cybersecurity · 78d ago What MCP servers are you integrating into your workflow (not exclusive to security)? cybersecurity · 79d ago Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors. For [Blue|Purple] Teams in Cyber Defence · 79d ago WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog cybersecurity · 79d ago What are like the top but unknown Cybersecurity firms? cybersecurity · 79d ago Can HTTP POST bodies be intercepted without network or host access? hacking: security in practice · 79d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha BleepingComputer · 79d ago Need professionals or expert on cybersecurity related to dark web for interview cybersecurity · 79d ago A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP) cybersecurity · 79d ago Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library For [Blue|Purple] Teams in Cyber Defence · 79d ago North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory cybersecurity · 79d ago VirusTotal has one flag for this sus site Malware Analysis & Reports · 79d ago Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo Reverse Engineering · 79d ago Telegram Mini Apps abused for crypto scams, Android malware delivery BleepingComputer · 79d ago Puzzle: Set of PoC to abuse Windows minifilters functionality For [Blue|Purple] Teams in Cyber Defence · 79d ago Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate) cybersecurity · 79d ago Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate) Technical Information Security Content & Discussion · 79d ago Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you! Reverse Engineering · 79d ago built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4) hacking: security in practice · 79d ago Credential Dumping: Local Security Authority (LSA|LSASS.EXE) cybersecurity · 79d ago A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16 For [Blue|Purple] Teams in Cyber Defence · 79d ago Dump sql time based is too slow hacking: security in practice · 79d ago Trojan:Win32/Cerdigent.A!dha cybersecurity · 79d ago Active exploitation of cPanel/WHM critical vulnerability For [Blue|Purple] Teams in Cyber Defence · 79d ago Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. " For [Blue|Purple] Teams in Cyber Defence · 79d ago MDE flagging digi cert certificate as malicious everywhere ? cybersecurity · 79d ago North Korea rejects US cybercrime claims as 'absurd slander' hacking: security in practice · 79d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Reverse Engineering · 79d ago 5 Qilin ransomware servers exposed over 7 months For [Blue|Purple] Teams in Cyber Defence · 79d ago is credential stuffing using openbullet2 dead in 2026? hacking: security in practice · 79d ago Anyone wanna learn the CEH or OSCP red teaming free Malware Analysis & Reports · 79d ago South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) For [Blue|Purple] Teams in Cyber Defence · 79d ago Russian Charged in Oil and Gas Facility Hacks Pleads Guilty For [Blue|Purple] Teams in Cyber Defence · 79d ago Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax) hacking: security in practice · 79d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks BleepingComputer · 79d ago How to build .NET obfuscator - Part II Reverse Engineering · 79d ago VECT ransomware: small files decrypt, large files lose their nonces For [Blue|Purple] Teams in Cyber Defence · 80d ago CTO at NCSC Summary: week ending May 3rd For [Blue|Purple] Teams in Cyber Defence · 80d ago April 27th - What happened with our feature flag configuration | The ClickUp Blog For [Blue|Purple] Teams in Cyber Defence · 80d ago Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT) hacking: security in practice · 80d ago How to exfiltrate data using only numeric outputs Technical Information Security Content & Discussion · 80d ago ConsentFix v3 attacks target Azure with automated OAuth abuse BleepingComputer · 80d ago libghidra - SDK for automating Ghidra from Python, Rust, and C++ Reverse Engineering · 80d ago Blog: Evolving the Android & Chrome VRPs for the AI Era For [Blue|Purple] Teams in Cyber Defence · 80d ago Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis. Reverse Engineering · 80d ago Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed. For [Blue|Purple] Teams in Cyber Defence · 80d ago VECT: Ransomware by design, Wiper by accident For [Blue|Purple] Teams in Cyber Defence · 80d ago VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built. For [Blue|Purple] Teams in Cyber Defence · 80d ago Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 80d ago Agentic Malware Analysis: From Task Automation to Deep Analysis For [Blue|Purple] Teams in Cyber Defence · 80d ago pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner. For [Blue|Purple] Teams in Cyber Defence · 80d ago month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only For [Blue|Purple] Teams in Cyber Defence · 80d ago Microsoft tests modern Windows Run, says it's faster than legacy dialog BleepingComputer · 80d ago Edu tech firm Instructure discloses cyber incident, probes impact BleepingComputer · 80d ago For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall. Technical Information Security Content & Discussion · 80d ago Small models are better at cost-to-recall than large models like Mythos for vulnerability research hacking: security in practice · 80d ago Every incident public companies have disclosed to the SEC, in one searchable database Technical Information Security Content & Discussion · 80d ago 76% of All Crypto Stolen in 2026 Is Now in North Korea darkreading · 80d ago Bluetooth Spoofed Disconnect? hacking: security in practice · 80d ago Why my macOS Messages badge lied to me (and the one-line fix) Reverse Engineering · 81d ago 15-year-old detained over French govt agency data breach BleepingComputer · 81d ago Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself Malware Analysis & Reports · 81d ago Story retracted BleepingComputer · 81d ago Running Adobe’s 1991 PostScript Interpreter in the Browser Reverse Engineering · 81d ago Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :) Reverse Engineering · 81d ago If AI's So Smart, Why Does It Keep Deleting Production Databases? darkreading · 81d ago Minecraft Malware C2 Tracking Malware Analysis & Reports · 81d ago Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations BleepingComputer · 81d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 81d ago Microsoft fixes Remote Desktop warnings displaying incorrectly BleepingComputer · 81d ago Name That Toon: Mark of (Security) Progress darkreading · 81d ago 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage darkreading · 81d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 81d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 81d ago Careful Adoption of Agentic AI Services All CISA Advisories · 81d ago Microsoft now lets admins choose pre-installed Store apps to uninstall BleepingComputer · 81d ago wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ... hacking: security in practice · 81d ago Windows 11 KB5083631 update released with 34 changes and fixes BleepingComputer · 81d ago Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster Technical Information Security Content & Discussion · 81d ago US ransomware negotiators get 4 years in prison over BlackCat attacks BleepingComputer · 81d ago /r/ReverseEngineering's Triannual Hiring Thread Reverse Engineering · 81d ago In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off) Reverse Engineering · 81d ago TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack darkreading · 81d ago 🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀 hacking: security in practice · 81d ago Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug darkreading · 81d ago Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber darkreading · 82d ago New Bluekit phishing service includes an AI assistant, 40 templates BleepingComputer · 82d ago Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM Security | Microsoft Azure Blog | Microsoft Azure · 82d ago Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight Reverse Engineering · 82d ago SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents The Last Watchdog · 82d ago I made a lightweight breach intelligence search engine (fully client-side) looking for feedback hacking: security in practice · 82d ago Oracle Red Bull Racing Team Revs Up Automation to Boost Security darkreading · 82d ago Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan... hacking: security in practice · 82d ago Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool hacking: security in practice · 82d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 82d ago ABB AWIN Gateways All CISA Advisories · 82d ago ABB Ability OPTIMAX All CISA Advisories · 82d ago ABB PCM600 All CISA Advisories · 82d ago ABB Edgenius Management Portal All CISA Advisories · 82d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 82d ago ABB Ability Symphony Plus Engineering All CISA Advisories · 82d ago ABB System 800xA, Symphony Plus IEC 61850 All CISA Advisories · 82d ago Seventeen vulnerabilities in Omi, fourteen days of silence Technical Information Security Content & Discussion · 82d ago High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940) Technical Information Security Content & Discussion · 82d ago This month in security with Tony Anscombe – April 2026 edition WeLiveSecurity · 82d ago HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try! Reverse Engineering · 82d ago GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter). Reverse Engineering · 82d ago Copy Fail — 732 Bytes to Root hacking: security in practice · 82d ago ZDI-CAN-30796: Docker ZDI: Upcoming Advisories · 82d ago Claude Mythos Fears Startle Japan's Financial Services Sector darkreading · 82d ago Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia Trend Micro Research, News, Perspectives · 82d ago Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root Technical Information Security Content & Discussion · 82d ago Reverse Engineering With AI Unearths High-Severity GitHub Bug darkreading · 82d ago AI Finds 38 Security Flaws in Electronic Health Record Platform darkreading · 82d ago The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs Technical Information Security Content & Discussion · 83d ago The Thymeleaf Template Injection That Only Hurts If You Let It Technical Information Security Content & Discussion · 83d ago Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error darkreading · 83d ago GitHub fixes RCE flaw that gave access to millions of private repos hacking: security in practice · 83d ago Minirat malware deployed via NPM targeting macOS machines Malware Analysis & Reports · 83d ago Set up automated dependency scanning after the recent npm/PyPI supply chain attacks Technical Information Security Content & Discussion · 83d ago Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities darkreading · 83d ago I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway Reverse Engineering · 83d ago Adapting Zero Trust Principles to Operational Technology All CISA Advisories · 83d ago How to download Kaggle dataset safely...? hacking: security in practice · 83d ago VECT Ransomware Is Actually a Wiper Malware Analysis & Reports · 83d ago VECT Ransomware Is Actually a Wiper hacking: security in practice · 83d ago Toys“R”Us Japan Implements Forter’s Fraud Management and Payment Optimization Solutions Blog – Forter · 83d ago DEF CON 34 - DEF CON Policy Announcement - Katie Noble, Heather West DEFCONConference · 83d ago The Malware Factory: GLASSWORM Forensics in Open VSX Malware Analysis & Reports · 83d ago A Route to Root in a 4G Industrial Router Technical Information Security Content & Discussion · 83d ago BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures darkreading · 83d ago NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later darkreading · 83d ago Feuding Ransomware Groups Leak Each Other's Data darkreading · 83d ago Vidar Rises to Top of Chaotic Infostealer Market darkreading · 84d ago Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore Malware Analysis & Reports · 84d ago Flipper Blackhat April Roundup! hacking: security in practice · 84d ago Building a perfect clone of 1993 game SimTower (via RE) Reverse Engineering · 84d ago [ Removed by Reddit ] Malware Analysis & Reports · 84d ago [VulnPath Update] Automated Email Alerting & CISA KEV Feed hacking: security in practice · 84d ago Ikeja Electric Distribution Ransomware Malware Analysis & Reports · 84d ago Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain darkreading · 84d ago [Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses) Technical Information Security Content & Discussion · 84d ago How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema Reverse Engineering · 84d ago AI solved our CTF in 6min Reverse Engineering · 84d ago The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords Technical Information Security Content & Discussion · 84d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 84d ago NSA GRASSMARLIN All CISA Advisories · 84d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 84d ago Recently updated a authentic minecraft mod launcher called Modrinth Malware Analysis & Reports · 84d ago GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control The Last Watchdog · 84d ago More of What Matters: Forter’s April Product Release Blog – Forter · 84d ago 89 vulnerabilities in XAPI / Citrix XenServer Technical Information Security Content & Discussion · 84d ago Example structure for evidence-based vulnerability reports Reverse Engineering · 84d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 84d ago UNC6692 Combines Social Engineering, Malware, Cloud Abuse darkreading · 84d ago Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025) Technical Information Security Content & Discussion · 85d ago Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary Technical Information Security Content & Discussion · 85d ago This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0 Malware Analysis & Reports · 85d ago Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation darkreading · 85d ago FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures The Last Watchdog · 85d ago Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely Malware Analysis & Reports · 85d ago MCPwned: a Burp Suite extension for auditing MCP servers Technical Information Security Content & Discussion · 85d ago New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses Malware Analysis & Reports · 87d ago HackTheBox - Sorcery IppSec · 87d ago Save time and use Zig to write your Malware POC Malware Analysis & Reports · 87d ago Cracking CastleLoader’s Inno Setup Password Malware Analysis & Reports · 87d ago I built a C2 framework that uses Discord and Telegram for communication Malware Analysis & Reports · 87d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog Alerts · 88d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog All CISA Advisories · 88d ago The calm before the ransom: What you see is not all there is WeLiveSecurity · 88d ago fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet. Malware Analysis & Reports · 88d ago Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet Malware Analysis & Reports · 88d ago PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs Malware Analysis & Reports · 88d ago Budgiekit - gdi malware maker (for educational purporses only) Malware Analysis & Reports · 89d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 89d ago SpiceJet Online Booking System All CISA Advisories · 89d ago Carlson Software VASCO-B GNSS Receiver All CISA Advisories · 89d ago Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera All CISA Advisories · 89d ago Milesight Cameras All CISA Advisories · 89d ago Defending Against China-Nexus Covert Networks of Compromised Devices All CISA Advisories · 89d ago Yadea T5 Electric Bicycle All CISA Advisories · 89d ago Intrado 911 Emergency Gateway (EGW) All CISA Advisories · 89d ago GopherWhisper: A burrow full of malware WeLiveSecurity · 89d ago News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category The Last Watchdog · 90d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 90d ago 19 confirmed repos tied to the same GitHub malware campaign Malware Analysis & Reports · 90d ago Defending Against China-Nexus Covert Networks of Compromised Devices CISA Cybersecurity Advisories · 91d ago IOCX v0.7.0 — deterministic heuristics + adversarial PE samples Malware Analysis & Reports · 91d ago New NGate variant hides in a trojanized NFC payment app WeLiveSecurity · 91d ago Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one The Last Watchdog · 92d ago Supply Chain Compromise Impacts Axios Node Package Manager Alerts · 92d ago CISA Adds Eight Known Exploited Vulnerabilities to Catalog Alerts · 92d ago What the ransom note won’t say WeLiveSecurity · 92d ago HackTheBox - AirTouch IppSec · 94d ago That data breach alert might be a trap WeLiveSecurity · 95d ago Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business Blog Articles - Identity Insights | Trulioo · 96d ago Supply chain dependencies: Have you checked your blind spot? WeLiveSecurity · 96d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 96d ago News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security The Last Watchdog · 96d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 98d ago GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags The Last Watchdog · 98d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 99d ago HackThebox - Eighteen IppSec · 101d ago Recovery scammers hit you when you’re down: Here’s how to avoid a second strike WeLiveSecurity · 102d ago News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk The Last Watchdog · 102d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 104d ago FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense The Last Watchdog · 105d ago As breakout time accelerates, prevention-first cybersecurity takes center stage WeLiveSecurity · 105d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 106d ago Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure CISA Cybersecurity Advisories · 106d ago HackTheBox - DarkZero IppSec · 108d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 110d ago Azure IaaS: Keep critical applications running with built-in resiliency at scale Security | Microsoft Azure Blog | Microsoft Azure · 111d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 111d ago Digital assets after death: Managing risks to your loved one’s digital estate WeLiveSecurity · 111d ago This month in security with Tony Anscombe – March 2026 edition WeLiveSecurity · 112d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 113d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 116d ago RSAC 2026 wrap-up – Week in security with Tony Anscombe WeLiveSecurity · 116d ago A cunning predator: How Silver Fox preys on Japanese firms this tax season WeLiveSecurity · 116d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 117d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 118d ago Virtual machines, virtually everywhere – and with real security gaps WeLiveSecurity · 118d ago Cloud workload security: Mind the gaps WeLiveSecurity · 119d ago What is Customer Due Diligence (CDD) Blog Articles - Identity Insights | Trulioo · 120d ago Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud Blog Articles - Identity Insights | Trulioo · 122d ago CISA Adds Five Known Exploited Vulnerabilities to Catalog Alerts · 123d ago Move fast and save things: A quick guide to recovering a hacked account WeLiveSecurity · 123d ago EDR killers explained: Beyond the drivers WeLiveSecurity · 124d ago Face value: What it takes to fool facial recognition WeLiveSecurity · 130d ago Cyber fallout from the Iran war: What to have on your radar WeLiveSecurity · 131d ago AML, KYC and Identity Verification in Australia Blog Articles - Identity Insights | Trulioo · 131d ago SSL/TLS Certificate Lifespans Are Decreasing to 200 Days InfoSec Insights · 132d ago AI in Tax Season: Risks, Scams, and How to Protect Your Data Fraud Prevention Archives - Alloy Silverstein · 138d ago Security-driven Rapid Release - Pwn2Own Documentary (Part 4) LiveOverflow · 139d ago Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure Security | Microsoft Azure Blog | Microsoft Azure · 139d ago Firefox JIT Bug - Pwn2Own Documentary (Part 3) LiveOverflow · 142d ago Tax Season Scams to Watch For This Year Fraud Prevention Archives - Alloy Silverstein · 145d ago The First Exploit - Pwn2Own Documentary (Part 2) LiveOverflow · 146d ago The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1) LiveOverflow · 149d ago I built a kernel-level EDR and hit architectural walls I didn’t expect Malware Analysis & Reports · 152d ago DEF CON 33 - DisguiseDelimit: Exploiting Synology NAS with Delimiters and Novel Tricks - Ryan Emmon DEFCONConference · 152d ago DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen - Marek Tóth DEFCONConference · 152d ago DEF CON 33 - Can't Stop the ROP: Automating Universal ASLR Bypasses - Bramwell Brizendine DEFCONConference · 152d ago Update your detection rules: New remote access Trojan Malware Analysis & Reports · 153d ago Criminals are using AI website builders to clone major brands Malware Analysis & Reports · 153d ago Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants) Malware Analysis & Reports · 153d ago Azure reliability, resiliency, and recoverability: Build continuity by design Security | Microsoft Azure Blog | Microsoft Azure · 154d ago PE Loader For Fileless Malware Malware Analysis & Reports · 154d ago Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers Malware Analysis & Reports · 154d ago AWAKE - Android Wiki of Attacks, Knowledge & Exploits Malware Analysis & Reports · 154d ago I built a Chrome extension that scans for malicious extensions (yes, I see the irony) Malware Analysis & Reports · 155d ago Questions regarding malicious pdf's Malware Analysis & Reports · 157d ago AV persistence bypass techniques Malware Analysis & Reports · 157d ago Avalon Linux Bot Malware Analysis Malware Analysis & Reports · 158d ago Leveling up in Windows malware research Malware Analysis & Reports · 159d ago Emerging Ransomware: BQTLock and GREENBLOOD Malware Analysis & Reports · 160d ago Malware Development POCs Malware Analysis & Reports · 160d ago Suspicious code in Up-work linked repository. Malware Analysis & Reports · 160d ago We hid backdoors in binaries — Opus 4.6 found 49% of them Malware Analysis & Reports · 161d ago 👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡 Malware Analysis & Reports · 162d ago Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions Malware Analysis & Reports · 162d ago Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer Malware Analysis & Reports · 164d ago Nyxara Malware Analysis & Reports · 166d ago When Fraud Becomes Background Noise: The Industrialization of Digital Deception Blog Articles - Identity Insights | Trulioo · 197d ago The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage Blog Articles - Identity Insights | Trulioo · 197d ago The End of Static KYB: Business Identity in Constant Motion Blog Articles - Identity Insights | Trulioo · 197d ago Know Your Agent: The Next Chapter in Digital Trust Blog Articles - Identity Insights | Trulioo · 197d ago When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage Blog Articles - Identity Insights | Trulioo · 197d ago DEF CON 33 Recon Village - How to Become One of Them: Deep Cover Ops - Sean Jones, Kaloyan Ivanov DEFCONConference · 202d ago DEF CON 33 Recon Village - Inside the Shadows Tracking RaaS Groups, Cyber Threats - John Dilgen DEFCONConference · 202d ago DEF CON 33 Recon Village - Autonomous Video Hunter AI Agents for Real Time OSINT - Kevin Dela Rosa DEFCONConference · 202d ago DEF CON 33 Recon Village - A Playbook for Integration Servers - Ryan Bonner, Guðmundur Karlsson DEFCONConference · 202d ago DEF CON 33 Recon Village - Mapping the Shadow War From Estonia to Ukraine - Evgueni Erchov DEFCONConference · 202d ago DEF CON 33 Recon Village - Building Local Knowledge Graphs for OSINT - Donald Pellegrino DEFCONConference · 202d ago DEF CON 33 Recon Village - OSINT & Modern Recon Uncover Global VPN Infrastructure - Vladimir Tokarev DEFCONConference · 202d ago DEF CON 33 Recon Village - Pretty Good Pivot - Simwindie DEFCONConference · 202d ago DEF CON 33 Recon Village - enumeraite: AI Assisted Web Attack Surface Enumeration - Özgün Kültekin DEFCONConference · 202d ago DEF CON 33 Recon Village - OSINT Signals Pop Quiz - Master Chen DEFCONConference · 202d ago DEF CON 33 Recon Village - Investigating Foreign Tech from Online Retailers - Michael Portera DEFCONConference · 202d ago Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration Blog Articles - Identity Insights | Trulioo · 216d ago Beware of Misleading Tax Advice on Social Media Fraud Prevention Archives - Alloy Silverstein · 313d ago Scammers Up Their Game With AI Fraud Prevention Archives - Alloy Silverstein · 315d ago Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs STÖK · 331d ago The Essential Guide to Safeguarding Your Online Passwords Fraud Prevention Archives - Alloy Silverstein · 392d ago How FIN6 Exfiltrates Files Over FTP HackerSploit · 468d ago From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi LiveOverflow · 468d ago The German Hacking Championship LiveOverflow · 494d ago Beware: Tax Season is Scam Season Fraud Prevention Archives - Alloy Silverstein · 503d ago Do you know this common Go vulnerability? LiveOverflow · 508d ago Stop Scams: Fraud Prevention Starts with Your Employees Fraud Prevention Archives - Alloy Silverstein · 516d ago Emulating FIN6 - Active Directory Enumeration Made EASY HackerSploit · 519d ago The SECRET to Embedding Metasploit Payloads in VBA Macros HackerSploit · 524d ago Offensive VBA 0x4 - Reverse Shell Macro with Powercat HackerSploit · 532d ago Offensive VBA 0x3 - Developing PowerShell Droppers HackerSploit · 538d ago Offensive VBA 0x2 - Program & Command Execution HackerSploit · 543d ago Offensive VBA 0x1 - Your First Macro HackerSploit · 545d ago Emulating FIN6 - Gaining Initial Access (Office Word Macro) HackerSploit · 550d ago FIN6 Adversary Emulation Plan (TTPs & Tooling) HackerSploit · 554d ago Developing An Adversary Emulation Plan HackerSploit · 554d ago Introduction To Advanced Persistent Threats (APTs) HackerSploit · 558d ago Introduction To Adversary Emulation HackerSploit · 580d ago ‘Tis the Season for Holiday Shopping Scams Fraud Prevention Archives - Alloy Silverstein · 589d ago Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion HackerSploit · 589d ago Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1) LiveOverflow · 643d ago My theory on how the webp 0day was discovered #short LiveOverflow · 659d ago My theory on how the webp 0day was discovered (BLASTPASS) LiveOverflow · 660d ago Learn Android Hacking! - University Nevada, Las Vegas (2024) LiveOverflow · 686d ago My Trip to Las Vegas for DEFCON & Black Hat LiveOverflow · 700d ago Planning Red Team Operations | Scope, ROE & Reporting HackerSploit · 729d ago Mapping APT TTPs With MITRE ATT&CK Navigator HackerSploit · 733d ago IRS Issues “Dirty Dozen” Fraud Warnings Fraud Prevention Archives - Alloy Silverstein · 774d ago IRS Identity Theft Season Begins Now Fraud Prevention Archives - Alloy Silverstein · 903d ago Finding The .webp Vulnerability in 8s (Fuzzing with AFL++) LiveOverflow · 911d ago Winter vanlife = good times STÖK · 933d ago What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth! STÖK · 939d ago A Vulnerability to Hack The World - CVE-2023-4863 LiveOverflow · 943d ago Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma STÖK · 946d ago Reinventing Web Security LiveOverflow · 973d ago IS THIS THE END? STÖK · 1006d ago Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites STÖK · 1160d ago The World’s Identity Platform Blog Articles - Identity Insights | Trulioo · 1267d ago How to turn bugs into a "passive" income stream! ft Detectify's Almroot STÖK · 1401d ago HOW DID THIS HAPPEN!? (13370822 LHE VLOG) STÖK · 1414d ago Student Loan Breach Exposes 2.5M Records Threatpost · 1420d ago Watering Hole Attacks Push ScanBox Keylogger Threatpost · 1421d ago Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms Threatpost · 1422d ago Ransomware Attacks are on the Rise Threatpost · 1425d ago Cybercriminals Are Selling Access to Chinese Surveillance Cameras Threatpost · 1426d ago Twitter Whistleblower Complaint: The TL;DR Version Threatpost · 1427d ago Firewall Bug Under Active Attack Triggers CISA Warning Threatpost · 1428d ago Fake Reservation Links Prey on Weary Travelers Threatpost · 1429d ago iPhone Users Urged to Update to Patch 2 Zero-Days Threatpost · 1432d ago Google Patches Chrome’s Fifth Zero-Day of the Year Threatpost · 1433d ago Q: How to write a BUG BOUNTY report that actually gets paid? STÖK · 1531d ago KYC: 3 Steps to Achieving Know Your Customer Compliance Blog Articles - Identity Insights | Trulioo · 1538d ago facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques.. STÖK · 1545d ago AML Compliance Checklist: Best Practices for Anti-Money Laundering Blog Articles - Identity Insights | Trulioo · 1553d ago Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!) STÖK · 1559d ago Q: HOW do you get started in bug bounty?? How do you build your automation?! STÖK · 1573d ago Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR) STÖK · 1587d ago BOUNTY THURSDAYS - LIVE #2 (NEWS/TOOLS and Community Questions with Jason Haddix) STÖK · 1601d ago
Latest
The Record from Recorded Future NewsDNI nominee Clayton wins Senate panel’s approvalSecurityWeekTrump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply ChainsLatest newsHow spatial audio works on headphones and speakers - and the best way to experience itSecurityWeekCisco Launches Low-Cost AI Models for Source Code SecurityThe Record from Recorded Future NewsSpain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hackBleepingComputerCritical wp2shell WordPress flaws exploited to install webshellsSecurity LatestA Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind SpotsThe Hacker NewsAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeCisco Security AdvisoryCisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation VulnerabilityLatest newsErnst & Young breach exposes client tax data - find out if you're at risk and what to do nextLatest news90,000 Flock cameras have quietly gone up in the US: What they track and how to check your cityThe Hacker NewsGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software VulnerabilitiesLatest newsLight's new $299 flip phone has no apps and T9 texting, but aims to connect peopleThe Hacker NewsCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCHelp Net SecurityAI agents tricked into recommending malicious GitHub repositoriesHelp Net SecurityTeleport enhances Identity Security platform with new AI agent behavior controlsThe Hacker NewsQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessBleepingComputerClosing the Identity Gaps in Critical Infrastructure SecurityMSRC Security Update GuideCVE-2026-58640 Windows NTFS Remote Code Execution VulnerabilityMSRC Security Update GuideCVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityThe Record from Recorded Future NewsDNI nominee Clayton wins Senate panel’s approvalSecurityWeekTrump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply ChainsLatest newsHow spatial audio works on headphones and speakers - and the best way to experience itSecurityWeekCisco Launches Low-Cost AI Models for Source Code SecurityThe Record from Recorded Future NewsSpain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hackBleepingComputerCritical wp2shell WordPress flaws exploited to install webshellsSecurity LatestA Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind SpotsThe Hacker NewsAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeCisco Security AdvisoryCisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation VulnerabilityLatest newsErnst & Young breach exposes client tax data - find out if you're at risk and what to do nextLatest news90,000 Flock cameras have quietly gone up in the US: What they track and how to check your cityThe Hacker NewsGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software VulnerabilitiesLatest newsLight's new $299 flip phone has no apps and T9 texting, but aims to connect peopleThe Hacker NewsCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCHelp Net SecurityAI agents tricked into recommending malicious GitHub repositoriesHelp Net SecurityTeleport enhances Identity Security platform with new AI agent behavior controlsThe Hacker NewsQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessBleepingComputerClosing the Identity Gaps in Critical Infrastructure SecurityMSRC Security Update GuideCVE-2026-58640 Windows NTFS Remote Code Execution VulnerabilityMSRC Security Update GuideCVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
By Source
Feeds organized so you can skim by site.
Density
Sort
SE
SecurityWeek
1h ago · 10 items
Trump Orders Defense Contractors to Map Software, Suppliers Across Critical Supply Chains
1h ago
Cisco Launches Low-Cost AI Models for Source Code Security
1h ago
Empirical Security Raises $25 Million in Series A Funding
6h ago
SecurityWeek Launches Critical Impact Awards to Recognize Excellence in Industrial Cybersecurity
6h ago
New HollowGraph Malware Abuses Microsoft 365 Calendar for C&C Communication
7h ago
CISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG
7h ago
Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack
7h ago
Meta Paid $78,000 Bounty for Vulnerability Exposing Customer Support Data
8h ago
Clover Health Investments Discloses Data Breach
9h ago
Exploitation of ServiceNow Vulnerability Seen Days After Disclosure
10h ago
LN
Latest news
1h ago · 20 items
How spatial audio works on headphones and speakers - and the best way to experience it
1h ago
The best way to experience a 3D soundscape depends on your audio format and device compatibility.
Ernst & Young breach exposes client tax data - find out if you're at risk and what to do next
3h ago
For two weeks, attackers had access to a third-party support ticket system containing customer tax information.
90,000 Flock cameras have quietly gone up in the US: What they track and how to check your city
3h ago
Flock cameras are everywhere - even in my small town, quietly using AI to identify your car and surveil your movements. But did you consent? Probably not.
Light's new $299 flip phone has no apps and T9 texting, but aims to connect people
4h ago
The minimalist brand's new flip phone takes an accessible approach to its brutally minimalist platform - with a gentle touch.
This Android 17 setting logs suspicious activity on your phone for troubleshooting - turn it on ASAP
5h ago
When something suspicious happens on your phone, it helps to have the means to track down what occurred. Android 17 now offers such a feature: Intrusion Logging.
Android backups count toward your 15GB Google storage limit now - how to check your settings
5h ago
An amended Google One storage utilization policy is rolling out now to include your Android device settings in backups, but there's no need to panic. Here are your options.
AT&T's new business plan includes 'unlimited' hotspot data - and starts at $75 per line
6h ago
The monthly price for Business Unlimited Ultimate 3.0 depends on how many phone lines you have - and can include up to 50.
I tested iOS 26 Siri against iOS 27 Siri AI in my car - and it wasn't even close
6h ago
With the iOS 27 public beta on my iPhone, I challenged Siri AI to assist me in the car. Here's how it performed over regular Siri.
Best tablets for note-taking 2026: Expert tested and reviewed
9h ago
We've tested and reviewed the best tablets on the market for note-taking in study sessions, meetings, or when you're feeling creative.
T-Mobile will pay for your first month of 5G home internet, and give you up to $200 back - here's how
9h ago
New T-Mobile 5G Home Internet customers can get their first month on T-Mobile, plus up to $200 back via prepaid Mastercard. We break down the details.
Fedora Xfce or Xubuntu: Which is the best Linux desktop?
11h ago
I wore Meta's $499 prescription Ray-Bans for 6 weeks: They're stylish but not for me
19h ago
Want to add Android Auto to your old car? Here are two ways - including one that's under $20
21h ago
I tested a 4TB quantum-resistant USB drive - but you don't have to spend $3000 for this much security
1d ago
The best rugged phones in 2026: Expert tested
1d ago
An AI agent breached Hugging Face before an AI defender caught it: What users should do next
1d ago
Why I still recommend Synology's DS225+ NAS - even if it can't replace your cloud storage
1d ago
How I configure DNS on Ubuntu Linux distros via the command line - it's easier than you think
1d ago
How to check if ChatGPT and other AI tools cite your website - and improve your chances in 2026
1d ago
I tested 3 blood pressure trackers for a month - only one rivaled my Garmin Index BP Monitor
1d ago
20 loaded
BL
BleepingComputer
2h ago · 586 items
Critical wp2shell WordPress flaws exploited to install webshells
2h ago
Hackers are exploiting the
Closing the Identity Gaps in Critical Infrastructure Security
5h ago
Critical infrastructure attacks often begin with stolen credentials, compromised devices, or trusted accounts. Specops Software explains why Zero Trust should verify both user identities and device trust before granting access to critical s...
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
8h ago
The U.S. Justice Department has seized more than 1,000 websites and blocked 1,970 domains used to stream FIFA World Cup 2026 matches without authorization.
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
8h ago
The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims' networks, according to cybersecurity company Arctic Wolf.
Microsoft shares manual fix for WSUS sync delays and timeouts
10h ago
Microsoft has shared manual mitigations to help IT administrators fix Windows Server Update Services (WSUS) servers affected by a known issue that causes Windows Update scans to fail or time out.
Windows LegacyHive zero-day flaw gets free, unofficial patches
11h ago
Free unofficial patches are available for a recently disclosed Windows zero-day flaw that allows attackers to escalate privileges on up-to-date Windows systems.
Estée Lauder discloses data breach via Oracle E-Business flaw
20h ago
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations.
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
20h ago
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances.
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
20h ago
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol.
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
21h ago
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and Google downgrading two Antigravity findings.
JadePuffer agentic attacks now target AI model data with ransomware
22h ago
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
1d ago
An AI SOC Evaluation Guide for Security Leaders
1d ago
Hugging Face discloses breach linked to autonomous AI agent
1d ago
Microsoft confirms Windows Server Update Services sync delays
1d ago
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
1d ago
Critical ServiceNow code execution flaw now exploited in attacks
1d ago
Hackers abuse ViPNet software to target Russian govt agencies
2d ago
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
2d ago
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
3d ago
Microsoft warns of surge in ACR Stealer attacks on customers
3d ago
The Future of Age Verification: Your Face Never Leaves Your Device
3d ago
Abbott Laboratories probes two cyber incidents amid extortion claims
3d ago
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
4d ago
Ernst & Young discloses data breach after support system hack
4d ago
Inside the Search for "Clean" Residential Proxies for Carding
4d ago
New Windows LegacyHive zero-day gives hackers admin privileges
4d ago
Windows Server 2022 reach end of mainstream support in 90 days
4d ago
US charges two over laundering $43 million from investment fraud
4d ago
CISA urges immediate action on actively exploited Fortinet flaws
4d ago
New ClickLock macOS malware traps users into revealing login password
4d ago
Coca-Cola says Fairlife ransomware attack halts US dairy production
4d ago
Claude Chrome extension flaw lets malicious extensions trigger AI actions
4d ago
New OkoBot framework deploys 20 payloads to steal data, crypto
5d ago
AI Agents Broke the Security Playbook. Here's What Replaces It.
5d ago
23andMe to pay $18 million in new genetics data breach settlement
5d ago
Scattered Spider members behind TfL hack get five years in prison
5d ago
Windows 11 24H2 Home and Pro reach end of support in 90 days
5d ago
CISA orders feds to patch actively exploited Oracle flaw by Saturday
5d ago
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
5d ago
New Spirals ransomware encrypts victim network in under 24 hours
5d ago
Dutch police bust investment fraud ring stealing over €100 million
5d ago
Zoom warns of critical account takeover vulnerability
5d ago
Google Gemini CLI abused as a hacking agent, malware botnet operator
6d ago
AsyncAPI npm packages infected with credential-stealing malware
6d ago
We built a vulnerability vending machine: AI tokens in, zero-days out
6d ago
CISA warns admins to patch actively exploited SharePoint flaws
6d ago
Microsoft: Some Dell PCs shut down after recent Windows updates
6d ago
US charges alleged operators of Russian bulletproof hosting service
6d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
6d ago
Spanish Police take down €140 million cyber fraud ring, arrest four
6d ago
Nearly 300 GitHub repos pose as legit software to push malware
6d ago
Microsoft releases Windows 10 KB5099539 extended security update
7d ago
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
7d ago
Windows 11 KB5101650 & KB5099414 cumulative updates released
7d ago
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
7d ago
LastPass, Bitwarden users targeted with fake security alerts
7d ago
You Don't Have to Run an Exploit to Know If You're Vulnerable
7d ago
Microsoft Entra ID gets passkeys default authentication starting September
7d ago
New phishing kits target Microsoft 365 accounts, evade MFA
7d ago
SAP warns of critical flaws in NetWeaver and Commerce Cloud
7d ago
Microsoft starts testing cleaner Windows Search without ads
7d ago
US sanctions VPN, malware providers for enabling ransomware attacks
7d ago
Japan's largest taxi operator shuts systems after cyberattack
7d ago
Hackers backdoor Jscrambler npm package with infostealer malware
7d ago
New CrashStealer malware poses as Apple crash reporting tool
8d ago
CISA warns of actively exploited RCE flaws in Joomla extensions
8d ago
Lidl discloses online shop breach after service provider hack
8d ago
Breach at the Beach: Play the Ultimate Entra ID CTF
8d ago
UK charges suspects linked to Russian Coms call spoofing platform
8d ago
EU sanctions Russian GRU military hackers over cyberattacks
8d ago
US and allies warn of Russian critical infrastructure attacks
8d ago
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
8d ago
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
8d ago
RedHook Android malware now uses Wireless ADB for shell access
9d ago
Australia warns of global campaign targeting vulnerable CMS platforms
10d ago
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
10d ago
New U-Boot flaws could enable stealthy firmware attacks
10d ago
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
11d ago
Police suspects Dutch hackers were involved in Odido breach
11d ago
Progress urges ShareFile admins to shut down servers over “credible” threat
11d ago
Hackers exploit critical auth bypass in Gitea Docker image
11d ago
Money launderer accused of stealing seized crypto while in prison
11d ago
The Replicant in Your Directory: AI Agents and the Identity Security Gap
11d ago
Zimbra urges customers to patch critical web client XSS flaw
11d ago
Former ransomware negotiator gets 4 years for BlackCat attacks
11d ago
OpenMandriva Linux says contributor tried to sabotage the project
11d ago
Injective SDK on npm infected with cryptocurrency wallet stealer
11d ago
New Helix vishing group emerges in SharePoint data theft attacks
12d ago
Microsoft expects more Windows security updates from AI-discovered flaws
12d ago
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
12d ago
The Hidden Security Risks of Reduced Summer IT Coverage
12d ago
Microsoft to retire the OWA Light client in Exchange Server
12d ago
Police arrests 5,800 suspects in global anti-fraud crackdown
12d ago
AssuranceAmerica data breach exposes records of 6.9 million drivers
12d ago
Microsoft patches RoguePlanet Defender zero-day vulnerability
12d ago
Mount Royal University confirms breach as hackers claim attack
12d ago
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
12d ago
Hackers exploit Roundcube flaw to spy on academic researchers
13d ago
Entra passkey enrollment vishing targets Microsoft 365 users
13d ago
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
13d ago
DuckDuckGo browser now blocks YouTube video ads
13d ago
Telco giant KDDI says data breach affects over 12 million people
13d ago
CISA orders feds to prioritize patching Langflow auth bypass flaw
13d ago
Ubiquiti warns of new max severity UniFi OS vulnerability
13d ago
CISA orders feds to patch max severity ColdFusion flaw by Friday
13d ago
Accenture confirms breach after hacker offers stolen data for sale
13d ago
Chinese hackers develop LONGLEASH malware to expand ORB network
14d ago
Hidden backdoor in Tenda router firmware grants admin access
14d ago
Spain arrests suspected member of pro-Russian hacktivist groups
14d ago
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
14d ago
Webinar tomorrow: Why modern email attacks require a new approach to defense
14d ago
New Januscape Linux flaw allows VM escape on Intel, AMD devices
14d ago
Microsoft to enable Windows settings backup by default for orgs
14d ago
BeyondTrust warns of critical flaws in remote access software
14d ago
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
14d ago
Phishing poses as big-brand job interview to steal Google accounts
14d ago
Fake IT support calls on Microsoft Teams push EtherRAT malware
14d ago
Vietnam arrests suspects behind HiAnime anime piracy service
15d ago
Software Is Now Written at the Speed of Thought. Security Isn't.
15d ago
Max severity Adobe ColdFusion flaw now exploited in attacks
15d ago
Flipper Zero firmware development continues with community help
16d ago
JadePuffer ransomware used AI agent to automate entire attack
17d ago
NetNut proxy network disrupted, 2 million infected devices cut off
18d ago
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
18d ago
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
18d ago
Claude Fable relaunch disappoints users with nerfed performance
18d ago
Google loses final appeal to overturn €4.1 billion EU fine
19d ago
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
19d ago
Microsoft fixes bug that removed Copilot buttons in Outlook
19d ago
Cisco finally confirms attackers exploiting Unified CM flaw
19d ago
CISA: Microsoft SharePoint RCE flaw now actively exploited
19d ago
Opera rolls out Paste Protect feature to fight ClickFix attacks
19d ago
Alleged Scattered Spider hacker extradited to the United States
19d ago
Medtronic notifies customers impacted by ShinyHunters data breach
19d ago
FortiBleed credential-theft campaign linked to Lynx ransomware
19d ago
Kubota says hackers had month-long access to network systems
19d ago
ChocoPoc malware delivered via trojanized exploits on GitHub
19d ago
New ChocoPoC malware targets researchers via trojanized PoC exploits
19d ago
DHS confirms hackers breached HSIN info-sharing platform
20d ago
Webinar: Why traditional email security is no longer enough
20d ago
Hackers target Microsoft 365 accounts with 81 million login attempts
20d ago
Turning Indicators into Intelligence in OpenCTI with Criminal IP
20d ago
Over 900 Oracle E-Business instances exposed to ongoing attacks
20d ago
Microsoft fixes GIF functionality in the Windows Emoji Panel
20d ago
Amazon fined $2.25M for withholding evidence from fraud victims
20d ago
Adobe patches seven max severity ColdFusion, Campaign flaws
20d ago
Anthropic to restore Claude Fable access on Wednesday
20d ago
Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price
20d ago
New BioShocking attack manipulates AI browser into data theft
20d ago
Microsoft accelerates quantum-safe roadmap as risks grow
20d ago
Malicious PyPI packages give hackers control of Telegram bot servers
20d ago
Fake Perplexity extension on Chrome Web Store tracked searches
21d ago
Lessons from the Underground: How to Combat Business Email Compromise
21d ago
Insurance giant Aflac discloses data breach after subsidiary hack
21d ago
Mircosoft adds smarter bot protection to Teams meetings
21d ago
Microsoft adds smarter bot protection to Teams meetings
21d ago
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
21d ago
Blackfield ransomware asks Nidec Corporation for $2 million ransom
21d ago
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
21d ago
Nissan discloses employee data breach linked to Oracle zero-day attacks
21d ago
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
21d ago
WhatsApp rolls out usernames to help users hide their phone number
22d ago
Microsoft extends Windows Server 2022 hotpatching until October 2027
22d ago
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
22d ago
Agentic AI Has an Identity Problem and Attackers Know It
22d ago
Critical SimpleHelp flaw exploited to deploy new stealer malware
22d ago
Hackers now exploit critical Oracle E-Business flaw in attacks
22d ago
Webinar: Why business email compromise attacks keep succeeding
22d ago
US seizes hundreds of FIFA World Cup illegal streaming domains
22d ago
Data breach exposes up to 14.2 million email logins at six ISPs
23d ago
Clean GitHub repo tricks AI coding agents into running malware
24d ago
FBI: Russian hackers now target Signal backup recovery keys
24d ago
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
24d ago
Polymarket customers lose $3 million in supply-chain attack
25d ago
Cybersecurity firms targeted by fraudulent OpenAI organization invites
25d ago
Your First GRC Agent: A Red Teamer's Walkthrough
25d ago
Anthropic is testing desktop-like Claude Cowork for mobile
25d ago
Poland busts SIM-swapping gang tied to millions in crypto theft
25d ago
Order-tracking app Shop abused to push callback phishing attacks
25d ago
Microsoft quietly extends free Windows 10 ESU support to October 2027
26d ago
New macOS malware embeds fake errors to confuse AI analysis tools
26d ago
PirloTV sports piracy network disrupted as 44 domains seized
26d ago
Bluekit phishing kit adopts browser-in-the-middle for login theft
26d ago
The Four Elevations of Effective Fraud Prevention
26d ago
Webinar: Why account takeovers remain one of the hardest threats to stop
26d ago
Google releases new privacy controls for activity history, personalization
26d ago
DraftKings hacker 'Snoopy' sentenced to 18 months in prison
26d ago
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
26d ago
Malicious Edge extension abuses Native Messaging as bridge to malware
26d ago
CISA warns of max severity Ubiquiti flaws exploited in attacks
27d ago
Amadey, StealC malware operations disrupted in Operation Endgame action
27d ago
Securing the service desk: Why social engineering attacks keep succeeding
27d ago
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
27d ago
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
27d ago
Tata Electronics confirms cyberattack as hackers leak data
27d ago
Windows 11 KB5095093 update rolls out new Point-in-Time restore feature
27d ago
Healthtech firm Xolis suffers data breach impacting 1.4 million people
27d ago
New macOS ClickFix attack silently mounts DMGs to push infostealer
28d ago
Scattered Spider members plead guilty to hacking Transport for London
28d ago
The Exploit Doesn't Exist. You Can Still Prove It Works Against You
28d ago
LastPass confirms data breach in Klue supply chain attack
28d ago
Webinar: Why email security teams are drowning in alerts
28d ago
WhatsApp phishing attack uses fake business docs to hack PCs
28d ago
JaredFromSubway MEV bot hacked in $15 million crypto theft
28d ago
FFmpeg fixes PixelSmash flaw in widely used video decoder
28d ago
FortiBleed campaign used custom FortiGate sniffer to steal credentials
28d ago
Microsoft says Windows 11 26H2 is coming soon, details upgrade process
29d ago
Microsoft fixes AutoGen Studio flaw that enabled code execution
29d ago
A Glimpse into the “Search Your Target” Market for Stolen Credentials
29d ago
AryStinger botnet infected thousands of D-Link routers worldwide
30d ago
New Prinz Eugen ransomware prioritizes recent files for encryption
31d ago
Microsoft links Mastra AI supply chain attack to North Korean hackers
31d ago
Klue OAuth breach victim list grows as Icarus hackers claim attack
31d ago
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
31d ago
Texas govt data breach exposes over 3 million driver’s licenses
32d ago
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
32d ago
Webinar: How attackers bypass MFA and how defenders can respond
32d ago
Microsoft: June 2026 Windows updates break Recycle Bin prompts
32d ago
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
32d ago
NY man charged after harassing college student with AI-generated nudes
32d ago
CISA warns Fortinet users to secure devices after FortiBleed leak
32d ago
Gentlemen ransomware uses multiple EDR killers to disable defenses
32d ago
Nintendo confirms data stolen in WebMD subsidiary cyberattack
33d ago
USB worm spreads crypto-stealing malware via Windows shortcut files
33d ago
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
33d ago
5 reasons Microsoft 365 backup isn’t enough for business data protection
33d ago
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
33d ago
ShapedPlugin update flow hacked to infect WordPress sites
33d ago
Apple fixes Beats Studio Buds flaw that let hackers spy on conversations
33d ago
Telegram admits it couldn't police exam-leak channels, India tells court
33d ago
F5 issues out-of-band patches for critical NGINX vulnerabilities
33d ago
Microsoft fixes Windows Server 2016 security update failures
33d ago
Leak confirms OpenAI is testing a ChatGPT for Science subscription
33d ago
Google to use UK and EU user IP addresses for ad personalization
33d ago
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
34d ago
Why Account Takeovers Are Rising and How to Stop Them
34d ago
India's Telegram ban hit the UAE too. Here's how to get around it
34d ago
Microsoft confirms Office apps launch issues after June updates
34d ago
CISA orders feds to patch max severity Joomla plugin flaw by Friday
34d ago
Microsoft working on Defender patch for RoguePlanet zero-day
34d ago
Kodak confirms data breach claimed by ShinyHunters extortion gang
34d ago
Malicious JetBrains Marketplace plugins steal AI API keys from developers
34d ago
New Rokarolla Android malware targets 217 banking, crypto apps
34d ago
Steam Workshop abused to spread malware via Wallpaper Engine app
35d ago
UK to require ID or face scan before you can make social media accounts
35d ago
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
35d ago
FTC warns of record $3.5 billion losses to imposter scams in 2025
35d ago
CISA warns of another cPanel plugin flaw exploited in attacks
35d ago
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
35d ago
Critical Fortinet FortiSandbox flaws now exploited in attacks
35d ago
Windows version of SprySOCKS Linux malware used to attack govt orgs
35d ago
iRhythm discloses data breach, says hackers stole patient info
35d ago
DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
35d ago
SimpleHelp bug lets hackers create rogue remote support accounts
35d ago
OptinMonster WordPress plugin hacked in CDN supply-chain attack
36d ago
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
36d ago
Council of Europe investigates ShinyHunters data breach claims
36d ago
FBI: Fraudsters use couriers to steal money in crypto scams
36d ago
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl
36d ago
Chinese hackers breach REDCap servers, steal medical research
36d ago
New attack turned Microsoft 365 Copilot into 1-click data theft tool
36d ago
Infinite Campus data breach affects 137,000 school staff accounts
36d ago
Webinar: How behavioral AI stops phishing and account takeovers
36d ago
FBI disrupts massive AI-powered phishing service using a million URLs
37d ago
Ex-school district employee jailed for hacks on former employer
37d ago
Chinese hackers hijack auth flow, spy on isolated network for a decade
38d ago
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
38d ago
Maine disables data breach notification portal after fake disclosures
38d ago
phpBB forum fixes auth bypass bug lurking for a decade
39d ago
Ukrainian national pleads guilty to role in Conti ransomware operation
39d ago
Over 400 Arch Linux packages compromised to push rootkit, infostealer
39d ago
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
39d ago
Microsoft fixes Windows update failures linked to WUSA installer
39d ago
Pharma giant Novo Nordisk discloses breach of clinical trials data
39d ago
CISA orders feds to patch actively exploited Ivanti flaw by Sunday
39d ago
Over 73,000 French govt employees affected in Tchap messenger breach
39d ago
Japanese energy firm loses drive with data of 10.9 million clients
39d ago
Maine breach portal abused to publish fake data breach disclosures
39d ago
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
39d ago
Authorities dismantle 'AudiA6' ransomware crypto-laundering service
40d ago
Why AI-driven threats are exposing the limits of MSP security stacks
40d ago
Coupang hit with record $409 million data breach fine in Korea
40d ago
CISA tells govt agencies to patch critical exploited flaws in 3 days
40d ago
Microsoft fixes BitLocker recovery bug on Windows Server 2025
40d ago
Nottingham University data breach affects over 450,000 students
40d ago
Max severity Ivanti Sentry vulnerability now exploited in attacks
40d ago
Path traversal flaw in AI dev platform Langflow exploited in attacks
40d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
40d ago
GitHub announces npm security changes to tackle supply-chain attacks
40d ago
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
41d ago
China-linked JDY botnet expands targeting of U.S. military networks
41d ago
The 5 Best Practices for Secure Identity Verification
41d ago
Microsoft patches Exchange Server zero-day exploited in attacks
41d ago
Microsoft: Some Windows PCs fail to install latest monthly updates
41d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
41d ago
Ivanti: Max severity Sentry flaw allows code execution as root
41d ago
Anthropic rolls out Claude Fable 5, but it's available for a limited time
41d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
41d ago
ServiceNow discloses security incident exposing customer data
41d ago
OpenClaw AI agent found falling for phishing attacks, spills user data
41d ago
SAP fixes critical flaws in NetWeaver and Commerce Cloud
41d ago
Microsoft releases Windows 10 KB5094127 extended security update
42d ago
Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
42d ago
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
42d ago
Windows 11 KB5094126 & KB5093998 cumulative updates released
42d ago
XBOW tests Anthropic's Mythos Preview for offensive security
42d ago
GitHub disables Microsoft repos pushing password-stealing malware
42d ago
New Veeam vulnerability exposes backup servers to RCE attacks
42d ago
French govt messaging service breached in account hijacking attack
42d ago
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
42d ago
Google patches new Chrome zero-day flaw exploited in the wild
42d ago
NFCShare Android malware spreads via fake banking app updates on GitHub
42d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
42d ago
New Apple feature automatically changes your compromised passwords
42d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
42d ago
WhatsApp says it disrupted new NSO spyware phishing attacks
43d ago
Gogs patches critical zero-day enabling remote code execution
43d ago
Critical UniFi OS bug lets hackers gain root without authentication
43d ago
Reducing security operations complexity with Wazuh Cloud
43d ago
Check Point links VPN zero-day attacks to Qilin ransomware gang
43d ago
Oxford University discloses data breach after careers platform hack
43d ago
Over 20,000 Instagram accounts stolen in Meta AI support hack
43d ago
Hands on with Intelligent Terminal, an AI-powered Windows Terminal
43d ago
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
44d ago
Silent Ransom Group targets law firms with fake IT support calls
44d ago
Critical Everest Forms Pro flaw exploited to take over WordPress sites
45d ago
Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
45d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
45d ago
Chinese APT deploys new malware to keep access to hacked networks
46d ago
Dark web Nemesis Market vendor gets 26 years for selling drugs
46d ago
Over 900 US gas station tank gauge systems exposed to attacks
46d ago
What 2026 DBIR Confirms: Attacks Are Living in the Browser
46d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
46d ago
Brave Software releases Origin for a paid, bloat-free browsing experience
46d ago
Hola Browser for Windows compromised to deliver cryptominer
46d ago
Credit card theft campaign abuses Stripe to host stolen payment info
46d ago
DentaQuest data breach exposed info of 2.6 million accounts
47d ago
UN food agency discloses breach affecting 600,000 Gaza households
47d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
47d ago
Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook
47d ago
Microsoft blames unexpected Windows driver updates on caching issue
47d ago
Police dismantles fake ID marketplace used by migrant smugglers
47d ago
Cisco warns of critical Unified CM flaw with PoC exploit code
47d ago
Chinese hackers use new Atlas RAT malware in European cyberattacks
47d ago
The U.S. sanctions Nobitex crypto exchange used by ransomware
47d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
47d ago
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
48d ago
CISA warns of active attacks exploiting Android, Linux bugs
48d ago
What 345 Days of Untested Exposure Looks Like at a Bank
48d ago
Acer working to patch max severity zero-days in Wave 7 routers
48d ago
Police dismantles 9 crime groups in illegal streaming crackdown
48d ago
Google adds Android protection against AI deepfake scam calls
48d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
48d ago
Microsoft's Coreutils project brings Linux commands to Windows
48d ago
OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models
48d ago
Critical Kirki flaw exploited to hijack WordPress admin accounts
48d ago
Over 116,000 Mincraft systems infected in WeedHack malware campaign
48d ago
Over 116,000 Minecraft systems infected in WeedHack malware campaign
48d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
48d ago
Microsoft Exchange Online outage causes email delays, failures
49d ago
Instagram users locked out after Meta AI abused to steal accounts
49d ago
Why the browser is now the front line for AI security
49d ago
CISA flags two-year-old Oracle flaw as actively exploited in attacks
49d ago
Google fixes one actively exploited Android zero-day, 124 flaws
49d ago
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
49d ago
Red Hat npm packages compromised to steal developer credentials
49d ago
Spain arrests doxer leaking sensitive data of govt employees
49d ago
Dashlane password manager users locked out by brute force attacks
50d ago
WordPress malware campaign hides payloads in Steam profiles
50d ago
Microsoft investigates Office Apps, Teams file access issues
50d ago
Race Against Time: Why Faster Vulnerability Alerts Matter
50d ago
Critical Windows Netlogon RCE flaw now exploited in attacks
50d ago
Webinar tomorrow: From alert to resolution in network incident response
50d ago
Microsoft confirms outage affecting MFA, My Sign-Ins platform
50d ago
Microsoft fixes outage affecting MFA setup, MySignIn service
50d ago
Microsoft fixes KB5089549 Windows security update install issues
50d ago
WP Maps Pro bug exploited to create admin accounts on WordPress sites
51d ago
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
52d ago
New CIFSwitch Linux flaw gives root on multiple distributions
52d ago
ChatGPT share links abused to host fake outage pages to deliver malware
53d ago
California AG sues 23andMe over 2023 breach exposing health data
53d ago
From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market
53d ago
Dutch govt disrupts malware botnet with 17 million infected devices
53d ago
Google Chrome adds session cookie theft protection for all users
53d ago
Man sent to prison for selling data of 7 millions elderly Americans
53d ago
US charges Google security engineer with Polymarket insider trading
53d ago
Charter Communications data breach affects 4.9 million accounts
53d ago
Anthropic confirms Claude Mythos-class models will roll out to the public
53d ago
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
53d ago
BTMOB Android malware service generates custom phishing payloads
53d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
54d ago
Hackers exploit FortiClient EMS flaw to push infostealer malware
54d ago
New Gogs zero-day flaw lets hackers get remote code execution
54d ago
How SIEM helps MSPs reduce noise and stop threats faster
54d ago
Romanian gets 5 years in prison for hacking Oregon govt network
54d ago
Webinar: Why network incidents take too long to resolve
54d ago
Carnival Cruise confirms data breach affecting nearly 6 million people
54d ago
Sextortionist sentenced to 33 years for targeting 145 children
54d ago
GPU mining malware spreads via SEO poisoning, AI chatbots
54d ago
Can you enforce strong Active Directory password rules without frustrating users?
55d ago
Glassworm botnet disrupted after resilient C2 infrastructure takedown
55d ago
FBI warns of in-person data theft attacks from extortion gang
55d ago
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
55d ago
Dutch police arrests suspect linked to Ajax football club hack
55d ago
Windows 11 KB5089573 update released with performance improvements
55d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
55d ago
Charter confirms data breach after ShinyHunters extortion threat
55d ago
How Varonis Atlas integrates Claude Compliance API for AI governance
56d ago
Microsoft Defender can now automatically isolate hacked endpoints
56d ago
Webinar: Too many tools are slowing network incident response
56d ago
CISA orders feds to patch actively exploited Drupal vulnerability
56d ago
Microsoft: Domain Controller lookup may fail on Windows Server 2016
56d ago
7-Eleven data breach exposes personal information of 185,000 people
56d ago
Anthropic’s restricted Claude Mythos model may be coming to Claude Code
57d ago
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
57d ago
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
58d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
58d ago
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
59d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
60d ago
Former US execs plead guilty to aiding tech support scammers
60d ago
Trend Micro warns of Apex One zero-day exploited in the wild
60d ago
Drupal: Critical SQL injection flaw now targeted in attacks
60d ago
Why Chargebacks are Just One Piece of the Fraud Puzzle
60d ago
Ubiquiti patches three max severity UniFi OS vulnerabilities
60d ago
US and Canada arrest and charge suspected Kimwolf botnet admin
60d ago
Google accidentally exposed details of unfixed Chromium flaw
61d ago
Apple blocked over $11 billion in App Store fraud in 6 years
61d ago
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
61d ago
Chinese hackers target telcos with new Linux, Windows malware
61d ago
Max severity Cisco Secure Workload flaw gives Site Admin privileges
61d ago
Police seize “First VPN” service used in ransomware, data theft attacks
61d ago
Flipper One project needs community help to build open Linux platform
61d ago
Microsoft warns of new Defender zero-days exploited in attacks
61d ago
GitHub links repo breach to TanStack npm supply-chain attack
61d ago
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
61d ago
Hackers bypass SonicWall VPN MFA due to incomplete patching
61d ago
Grafana breach caused by missed token rotation after TanStack attack
62d ago
Identity Alone Isn't Enough: Why Device Security Has to Share the Load
62d ago
Drupal critical update to fix bug with high exploitation risk
62d ago
Exploit released for new PinTheft Arch Linux root escalation flaw
62d ago
GitHub confirms breach of 3,800 repos via malicious VSCode extension
62d ago
Microsoft shares mitigation for YellowKey Windows zero-day
62d ago
GitHub investigates internal repositories breach claimed by TeamPCP
62d ago
Max-severity flaw in ChromaDB for AI apps allows server hijacking
62d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
62d ago
Discord rolls out end-to-end encryption on voice, video calls
62d ago
FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
62d ago
Microsoft Self-Service Password Reset abused in Azure data theft attacks
62d ago
Microsoft plans to improve Windows 11 driver quality in 2026
63d ago
Microsoft blames macOS update for undismissible Teams location prompts
63d ago
New Shai-Hulud malware wave compromises 600 npm packages
63d ago
7-Eleven confirms data breach claimed by the ShinyHunters gang
63d ago
Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation
63d ago
Webinar: The hidden bottlenecks in network incident response
63d ago
Microsoft confirms patching issues in restricted Windows networks
63d ago
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
63d ago
SHub macOS infostealer variant spoofs Apple security updates
63d ago
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
64d ago
Leaked Shai-Hulud malware fuels new npm infostealer campaign
64d ago
Grafana says stolen GitHub token let hackers steal codebase
64d ago
Microsoft testing adjustable taskbar, Start menu in Windows 11
64d ago
Microsoft confirms Windows 11 security update install issues
64d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
64d ago
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
64d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
64d ago
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
65d ago
Microsoft rejects critical Azure vulnerability report, no CVE issued
65d ago
Russian hackers turn Kazuar backdoor into modular P2P botnet
66d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
66d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
67d ago
Popular node-ipc npm package compromised to steal credentials
67d ago
Avada Builder WordPress plugin flaws allow site credential theft
67d ago
Microsoft backpedals: Edge to stop loading passwords into memory
67d ago
Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
67d ago
Microsoft to automatically roll back faulty Windows drivers
67d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
67d ago
TeamPCP hackers advertise Mistral AI code repos for sale
67d ago
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
67d ago
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
67d ago
OpenAI confirms security breach in TanStack supply chain attack
68d ago
Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026
68d ago
18-year-old NGINX vulnerability allows DoS, potential RCE
68d ago
Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight
68d ago
KongTuke hackers now use Microsoft Teams for corporate breaches
68d ago
Dell confirms its SupportAssist software causes Windows BSOD crashes
68d ago
US charges suspected Dream Market admin arrested in Germany
68d ago
New Fragnesia Linux flaw lets attackers gain root privileges
68d ago
West Pharmaceutical says hackers stole data, encrypted systems
68d ago
Iranian hackers targeted major South Korean electronics maker
68d ago
New critical Exim mailer flaw allows remote code execution
68d ago
Windows BitLocker zero-day gives access to protected drives, PoC released
69d ago
Webinar tomorrow: Why security alone won't stop modern attacks
69d ago
Microsoft fixes BitLocker recovery issue only for Windows 11 users
69d ago
Microsoft fixes Windows Autopatch bug installing restricted drivers
69d ago
Foxconn confirms cyberattack claimed by Nitrogen ransomware gang
69d ago
73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation
69d ago
Microsoft says some users can't install Office on Windows 365 devices
69d ago
US govt seeks Instructure testimony on massive Canvas cyberattack
69d ago
UK fines water supplier $1.3M for exposing data of 664k customers
69d ago
Webinar: Fixing the gaps in network incident response
69d ago
Signal adds security warnings for social engineering, phishing attacks
69d ago
Microsoft releases Windows 10 KB5087544 extended security update
70d ago
Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
70d ago
Windows 11 KB5089549 & KB5087420 cumulative updates released
70d ago
Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days
70d ago
Škoda warns of customer data breach after online shop hack
70d ago
Android 17 to expand banking scam call and privacy protections
70d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
70d ago
SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA
70d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
70d ago
GM agrees to $12.75M California settlement over sale of drivers’ data
70d ago
Official CheckMarx Jenkins package compromised with infostealer
70d ago
New GhostLock tool abuses Windows API to block file access
70d ago
Instructure confirms hackers used Canvas flaw to deface portals
71d ago
Why Changing Passwords Doesn’t End an Active Directory Breach
71d ago
Google: Hackers used AI to develop zero-day exploit for web admin tool
71d ago
Webinar this week: Prevention alone is not enough against modern attacks
71d ago
TrickMo Android banker adopts TON blockchain for covert comms
71d ago
Hackers abuse Google ads, Claude.ai chats to push Mac malware
72d ago
Police shut down reboot of Crimenetwork marketplace, arrest admin
72d ago
JDownloader site hacked to replace installers with Python RAT malware
72d ago
Fake OpenAI repository on Hugging Face pushes infostealer malware
73d ago
NVIDIA confirms GeForce NOW data breach affecting Armenian users
74d ago
Why More Analysts Won’t Solve Your SOC’s Alert Problem
74d ago
Trellix source code breach claimed by RansomHouse hackers
74d ago
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
74d ago
Zara data breach exposed personal information of 197,000 people
74d ago
Former govt contractor convicted for wiping dozens of federal databases
74d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
74d ago
Canvas login portals hacked in mass ShinyHunters extortion campaign
74d ago
New TCLBanker malware self-spreads over WhatsApp and Outlook
74d ago
New PCPJack worm steals credentials, cleans TeamPCP infections
75d ago
Australia warns of ClickFix attacks pushing Vidar Stealer malware
75d ago
Ivanti warns of new EPMM flaw exploited in zero-day attacks
75d ago
The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
75d ago
Americans sentenced for running 'laptop farms' for North Korea
75d ago
Crypto gang member gets 6.5 years for role in $230 million heist
75d ago
Webinar: Why modern attacks require both security and recovery
75d ago
Palo Alto Networks firewall zero-day exploited for nearly a month
75d ago
Fake Claude AI website delivers new 'Beagle' Windows malware
75d ago
Hackers abuse Google ads for GoDaddy ManageWP login phishing
75d ago
Critical vm2 sandbox bug lets attackers execute code on hosts
76d ago
New Cisco DoS flaw requires manual reboot to revive devices
76d ago
DAEMON Tools devs confirm breach, release malware-free version
76d ago
Why ransomware attacks succeed even when backups exist
76d ago
MuddyWater hackers use Chaos ransomware as a decoy in attacks
76d ago
Webinar: Why network incidents escalate and how to fix response gaps
76d ago
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
76d ago
New stealthy Quasar Linux malware targets software developers
76d ago
Instructure hacker claims data theft from 8,800 schools, universities
76d ago
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
76d ago
Student hacked Taiwan high-speed rail to trigger emergency brakes
77d ago
FTC to ban data broker Kochava from selling Americans’ location data
77d ago
The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.
77d ago
The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
77d ago
Vimeo data breach exposes personal information of 119,000 people
77d ago
Google now offers up to $1.5 million for some Android exploits
77d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
77d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
77d ago
ScarCruft hackers push BirdCall Android malware via game platform
77d ago
Weaver E-cology critical bug exploited in attacks since March
77d ago
Amazon SES increasingly abused in phishing to evade detection
77d ago
Researchers report Amazon SES abused in phishing to evade detection
77d ago
Backdoored PyTorch Lightning package drops credential stealer
78d ago
Trellix discloses data breach after source code repository hack
78d ago
They don’t hack, they borrow: How fraudsters target credit unions
78d ago
Progress warns of critical MOVEit Automation auth bypass flaw
78d ago
Webinar: Why MSPs must rethink security and backup strategies
78d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
78d ago
Microsoft confirms April Windows updates cause backup failures
78d ago
Instructure confirms data breach, ShinyHunters claims attack
78d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
79d ago
Telegram Mini Apps abused for crypto scams, Android malware delivery
79d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
79d ago
ConsentFix v3 attacks target Azure with automated OAuth abuse
80d ago
Microsoft tests modern Windows Run, says it's faster than legacy dialog
80d ago
Edu tech firm Instructure discloses cyber incident, probes impact
80d ago
15-year-old detained over French govt agency data breach
81d ago
Story retracted
81d ago
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
81d ago
Microsoft fixes Remote Desktop warnings displaying incorrectly
81d ago
Microsoft now lets admins choose pre-installed Store apps to uninstall
81d ago
Windows 11 KB5083631 update released with 34 changes and fixes
81d ago
US ransomware negotiators get 4 years in prison over BlackCat attacks
81d ago
New Bluekit phishing service includes an AI assistant, 40 templates
82d ago
586 loaded
SL
Security Latest
3h ago · 20 items
A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots
3h ago
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
9h ago
The ACLU Is Arming Lawyers to Expose State Surveillance Secrets
1d ago
Apps Marketed to US Troops Are Shipping Chinese and Russian Code
1d ago
Your Period Tracker Is (Probably) Spying on You
3d ago
Prompt Injection Attacks Are Thwarting AI Hacking Agents
3d ago
San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores
4d ago
Here’s the Truth About Whether Meta’s NameTag Face Recognition Tech ‘Exists’
5d ago
A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance
8d ago
AI Found a Root Bug in Linux That Everyone Missed for 15 Years
10d ago
A Majority of European Lawmakers Voted Against Letting Big Tech Read Our Messages. They’re Going to Anyway
12d ago
Madison Square Garden Kept a List of Gay Celebrities
12d ago
OnlyFans Models Are Accidentally Making Hacked Government Websites Disappear
13d ago
What Happens if China Hacks the US Water Supply? I Went to a Secret War Game to Find Out
13d ago
ICE’s Internal Watchdog Is Now Investigating Online Critics
15d ago
Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email
17d ago
EU Politicians Investigated Pegasus Spyware. Then It Ended Up on One of Their Phones
18d ago
Claude Helped a Hacker Find a Way to Issue Tickets to Almost Every US Music Festival
20d ago
Meta Contractors Posed as Teens to Prompt Rival Chatbots About Suicide, Sex, and Drugs
21d ago
Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change
22d ago
20 loaded
TH
The Hacker News
3h ago · 20 items
AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code
3h ago
Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities
4h ago
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
4h ago
Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access
5h ago
Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities
5h ago
Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs
7h ago
N-day is Becoming N-Hour. Patching Faster Won't Save You.
7h ago
New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit
7h ago
WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning
10h ago
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
11h ago
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
12h ago
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
1d ago
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
1d ago
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
1d ago
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
1d ago
Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine
1d ago
Mythos Didn't Break Your Security Program. Your Exposure Window Could.
1d ago
New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction
1d ago
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
1d ago
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
1d ago
20 loaded
CS
Cisco Security Advisory
3h ago · 20 items
Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
3h ago
A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local ...
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
1d ago
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. These vulner...
Cisco Advance Notification for Publication of July 15, 2026, Security Advisories
6d ago
On July 15, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Identity Services Engine...
Cisco RoomOS Security Hardening Release: July 2026
6d ago
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses m...
Cisco Identity Services Engine Path Traversal Vulnerability
6d ago
A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating system to either read or ...
Cisco Identity Services Engine Remote Code Execution and Information Disclosure Vulnerabilities
14d ago
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to achieve remote code execution or conduct information disclosure attacks on an affected devi...
Cisco Catalyst Center Arbitrary File Read Vulnerability
15d ago
A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exp...
ClamAV Vulnerabilities Affecting Cisco Products: July 2026
18d ago
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For...
Cisco Advance Notification for Publication of July 1, 2026, Security Advisories
20d ago
On July 1, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst Center Secure En...
Cisco Unified Communications Manager Server-Side Request Forgery Vulnerability
20d ago
A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attacker to conduct server-side request forgery...
Cisco Finesse Remote File Inclusion Vulnerability
26d ago
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Cross-Site Scripting Vulnerabilities
29d ago
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability
34d ago
Cisco Crosswork Network Controller Server-Side Template Injection Vulnerability
34d ago
Cisco Webex App Open Redirect Vulnerability
34d ago
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
35d ago
Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability
35d ago
Cisco Catalyst SD-WAN Manager Arbitrary File Write Vulnerability
35d ago
Cisco Webex Meetings Cross-Site Scripting Vulnerability
48d ago
Cisco Nexus 3000 and 9000 Series Switches Border Gateway Protocol Denial of Service Vulnerability
62d ago
20 loaded
HN
Help Net Security
4h ago · 10 items
AI agents tricked into recommending malicious GitHub repositories
4h ago
7,600 malicious GitHub repositories posed as AI Skills and MCP servers, tricking Claude Code, Gemini, and ChatGPT into recommending malware.
Teleport enhances Identity Security platform with new AI agent behavior controls
5h ago
Teleport expanded its Identity Security platform with AI agent controls, session summaries and risk scoring to prevent misalignment.
JadePuffer returns with ransomware built to target AI models and infrastructure
5h ago
The JadePuffer agentic threat actor is using ENCFORGE, novel ransomware created to target AI and machine learning (ML) infrastructure.
Druva brings backup, recovery and governance to AI workloads
5h ago
Druva launches AI Resilience to protect, govern and recover AI-powered work, backups and enterprise data with new Copilot support.
Cisco’s open-weight Antares models make vulnerability localization cheaper
6h ago
Cisco Antares vulnerability localization models are open-weight, run locally, and cut costs up to 172x versus GPT-5.5 on a new benchmark.
Shufti simplifies cross-border compliance with the Glocal Platform
8h ago
The Shufti Glocal Platform helps organizations manage identity verification, fraud prevention, risk assessment and regulatory compliance.
SonicWall SMA zero-days were exploited weeks before disclosure
8h ago
CVE-2026-15409 and CVE-2026-15410 were exploited since June 22, 2026, allowing threat actors to install custom malware.
Fake FBI agents target people who already got scammed
8h ago
The FBI warns scammers are impersonating IC3 agents using AI deepfake videos and fake websites to steal more money from fraud victims.
AWS wants GuardDuty to automate the first steps of threat investigations
9h ago
Amazon GuardDuty investigation agent analyzes security findings, correlates evidence and delivers AI-powered threat assessments.
Estée Lauder discloses data breach tied to Oracle EBS vulnerability
10h ago
Estée Lauder disclosed a data breach tied to a flaw in the Oracle E-Business Suite (EBS) system it uses for HR operations.
MS
MSRC Security Update Guide
5h ago · 20 items
CVE-2026-58640 Windows NTFS Remote Code Execution Vulnerability
5h ago
CVE-2026-50462 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
5h ago
CVE-2026-63831 mac802154: llsec: add skb_cow_data() before in-place crypto
10h ago
CVE-2026-63796 ocfs2: reject oversized group bitmap descriptors
10h ago
CVE-2026-63800 pNFS: Fix use-after-free in pnfs_update_layout()
10h ago
CVE-2026-63824 KEYS: fix overflow in keyctl_pkey_params_get_2()
10h ago
CVE-2026-3842 Qemu-kvm: hyperv/syndbg: missing mapped-length guard after cpu_physical_memory_map causes host oob write
10h ago
CVE-2026-38755 A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
10h ago
CVE-2026-38754 A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
10h ago
CVE-2026-62299 CoreDNS: rewrite-plugin EDNS0 response-revert nil-pointer panic (remote DoS) when a downstream plugin returns a response with no OPT record
10h ago
CVE-2026-60081 DBI::ProfileData versions before 1.651 for Perl do not limit the path index
10h ago
CVE-2026-15392 DBD::File versions before 1.651 for Perl do not ensure the table file is not a symlink to an untrusted location
10h ago
CVE-2026-60082 DBI versions before 1.651 for Perl do not enforce statement handle consistency with the row
10h ago
CVE-2026-15043 DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text
10h ago
CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record
10h ago
CVE-2026-48863 Libsolv: stack-based buffer overflow in libsolv eddsa pgp signature verification allows denial of service
10h ago
CVE-2026-63827 apparmor: fix use-after-free in rawdata dedup loop
10h ago
CVE-2026-63828 apparmor: mediate the implicit connect of TCP fast open sendmsg
10h ago
CVE-2026-63801 tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
10h ago
CVE-2026-42770 FFC-DH Peer Validation Uses Attacker-Supplied q
11h ago
20 loaded
SA
Security - Ars Technica
5h ago · 20 items
Apps targeted at US troops contain Chinese and Russian code
5h ago
Pay up or not? Ransomware surge has victims facing tough choices.
1d ago
Now, even Russia's most elite hackers are using Clickfix to infect devices
4d ago
Windows 0-day drops the same day Microsoft releases record number of patches
5d ago
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
6d ago
The US government warns that Russia state hackers are coming after your router
7d ago
Now, defenders are embracing the prompt injection, too
8d ago
Patch for Windows Defender 0-day could allow attackers to fill hard disk
11d ago
Google pays $250K for Linux vulnerability allowing guest VM escapes
13d ago
Hackers can use 9 of the most popular AI tools to assemble massive botnets
13d ago
Newly discovered PamStealer isn't your typical macOS malware
18d ago
NASA inspector general suggests Boeing's Starliner will now be a decade late
20d ago
New attack provides one more reason why AI browsers are a bad idea
20d ago
US offers $10 million for info on group behind Signal and WhatsApp hacking spree
21d ago
One-two punch delivered in global operation disrupts cybercrime "assembly line"
26d ago
White House drastically shortens deadline for dropping quantum-vulnerable crypto
27d ago
Following user outcry, AMD reinstates memory encryption in consumer CPUs
28d ago
Microsoft discovers new lightweight backdoor that steals cryptocurrency
32d ago
Apple patches high-severity eavesdropping vulnerability in Beats Studio Buds
32d ago
Massive breach spills credentials for thousands of sensitive networks
33d ago
20 loaded
JH
John Hammond
5h ago · 15 items
An AI Botnet
5h ago
Redirect Chain Abuse
1d ago
Microsoft Exchange Hacked, Five Years Later
1d ago
Evil Token Marketplace
5d ago
Payload Podcast 009 - Steven Flores
5d ago
Backdoored TortoiseSVN Installer
7d ago
NEW AI Hacking Challenges with Andrew Bellini!
10d ago
Fake Microsoft Installer
11d ago
See you at Black Hat USA 2026!
12d ago
TeamPCP Attention
13d ago
Open Source Malware
15d ago
THE MOD WORKS! lets improve it
15d ago
the vibe continues
16d ago
let's vibe
17d ago
Beyond Usernames
20d ago
15 loaded
SE
Securelist
6h ago · 10 items
A new extortion cocktail: office printers, small ransoms, and BitLocker
6h ago
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
10h ago
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
HelloNet campaign — new malicious modules launched through the ViPNet update system
5d ago
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
5d ago
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
OkoBot: new sophisticated malware framework targets cryptocurrency users
6d ago
Kaspersky GReAT experts dissect the new OkoBot campaign targeting cryptocurrency users. This complex framework employs TookPS, exfiltrates seed phrases, monitors Chromium-based browsers, and installs various malware strains, including the R...
Threat landscape for industrial automation systems. Q1 2026
14d ago
This report contains industrial threat statistics for Q1 2026, including industrial threat distribution by type, source, region and industry.
When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website
15d ago
The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.
Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
18d ago
An inside look at the active Armored Likho APT campaign. The attackers are using spear-phishing, AI-generated loaders, and a new Python-based tool, BusySnake Stealer, to target organizations in Russia, Kazakhstan, and Brazil.
Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
19d ago
Kaspersky Compromise Assessment specialists analyze trends from the service’s 2025 projects and provide tips on how to enhance your organization’s security.
The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
20d ago
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.
CY
CyberScoop
1d ago · 140 items
Director of Commerce AI standards office out after three months
1d ago
Why blocking AI models won’t stop the cyber threats they create
1d ago
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
4d ago
Leading members of Scattered Spider sentenced in UK to 66 months in jail
4d ago
Program to rotate cyber personnel through federal agencies saw little use
4d ago
Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime
5d ago
Security researchers find stalkers abusing Chrome’s sync feature
5d ago
SonicWall customers under threat as attackers exploit 2 zero-days
6d ago
Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
6d ago
Forget the model. When it comes to cybersecurity, it’s all about the harness
6d ago
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
11d ago
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
12d ago
764 splinter group leader sentenced to 40 years in jail
12d ago
French nonprofit starts global intelligence and research hub for AI cyber threats
13d ago
Found fast, fixed slow: The gap the AI clearinghouse must close
13d ago
Spain arrests suspected hacker linked to Russian hacktivist campaign
13d ago
Deepfake CSAM lawsuit against xAI, Grok expands
13d ago
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
14d ago
US Army websites defaced with pro-Kurdish sentiments, insults to Trump
15d ago
Sysdig clocks first documented case of agentic ransomware
15d ago
Finding vulnerabilities was never the hard part
15d ago
Someone infected a spyware probe overseer with spyware
18d ago
Alleged longstanding member of Scattered Spider extradited to US
19d ago
Researchers spot exploitation of another critical Oracle defect
19d ago
US lifting export control restrictions on Anthropic’s Mythos, Fable
20d ago
This phishing kit looks more like BEC-as-a-service
20d ago
Citrix patches a new NetScaler flaw with echoes of CitrixBleed
20d ago
Trump budget boss Russell Vought open to re-staffing CISA
20d ago
DHS to unveil replacement council for critical infrastructure cybersecurity
21d ago
How ransomware syndicates weaponize corporate-style organization
21d ago
Warner bill would create federally vetted list for secure, trustworthy AI agents
21d ago
Supreme Court approves mail-in ballots that arrive after Election Day
22d ago
Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling
22d ago
What the post-quantum executive order really demands of CISOs
22d ago
ATF cancels controversial commercial geolocation contract
24d ago
FCC passes new cybersecurity rules for emergency systems, undersea cables
25d ago
Federal court rules Trump election-focused executive order illegal
26d ago
Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract
26d ago
Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack
26d ago
Why patch directives only go so far
26d ago
Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
27d ago
In a first, a court takedown goes after two cybercrime tools at once
27d ago
Open-source security is posing challenges governments can’t easily solve
27d ago
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
28d ago
Algerian man charged with running two cybercrime marketplaces
28d ago
Court rules SAVE database illegal, orders it dismantled
28d ago
Trump executive orders speed up post-quantum migration, boost industry
28d ago
Intel agencies: Frontier AI models will reshape cybersecurity faster than expected
29d ago
Authorities disrupt Evil Corp’s SocGholish botnet
32d ago
Congress tees up No FAKES Act, aiming at AI-generated deepfakes
32d ago
How software development’s speed obsession enabled TeamPCP’s chaos crusade
33d ago
Accenture shells out $4.18B on three companies in big industrial cybersecurity push
33d ago
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April
34d ago
Lawmakers leery about Trump administration’s Anthropic order
34d ago
AI’s constant patching treadmill can be a security problem
34d ago
A case for how to shape ‘ingredient lists’ for AI models
35d ago
Google exposes China espionage group that’s been lurking in networks undetected since 2023
35d ago
Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat
36d ago
Anthropic disables new models after government calls them a national security concern
38d ago
FBI takes down massive China-based cybercrime network that caused $1.9B in losses
38d ago
US, France, and Italian authorities shut down massive deepfake porn site
39d ago
Conti ransomware group member pleads guilty, faces up to 20 years in prison
39d ago
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw
39d ago
CyberCorps is adapting to AI. The budget isn’t keeping up.
39d ago
Russian national charged in connection with Void Blizzard espionage campaign
40d ago
OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
40d ago
CISA directive orders agencies to prioritize vulnerability patching in a new way
41d ago
Microsoft breaks Patch Tuesday record with 206 vulnerabilities
41d ago
Anthropic’s new model is Mythos on a leash
42d ago
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
42d ago
Cisco customers encounter another SD-WAN zero-day under attack
42d ago
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
43d ago
The AI security race needs accountability, not overregulation
43d ago
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
46d ago
Hill Dems hammer GOP for $250M CISA budget cut
46d ago
Your AI agent could become your biggest insider threat
47d ago
Inside the race to adapt to an AI-powered security world
47d ago
European authorities crack down on illegal streaming networks
47d ago
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels
47d ago
DOD wants to integrate cyber in all operations, and integrate security into AI
49d ago
Trump administration releases scaled-back AI executive order
49d ago
Anthropic expanding access to Project Glasswing
49d ago
Attackers are exploiting Palo Alto Networks defect that initially flew under the radar
49d ago
Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight
49d ago
USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order
50d ago
Election threats are focused on campaign systems, not voting machines
50d ago
Tennessee man linked to 764 accused of series of crimes against children dating back to 2022
53d ago
Federal audit reveals NIST’s NVD is plagued by poor planning and duplication
53d ago
House panel poised to hold hearing centered on AI impact on cyber
54d ago
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
54d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
54d ago
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms
54d ago
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
54d ago
UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace
55d ago
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
55d ago
Apple open-sources quantum-resistant encryption code
55d ago
Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
60d ago
Lawmakers from both parties say CISA cuts have gone too far
60d ago
Trump postpones executive order focused on AI security
61d ago
CISA chief frets about open-source vulnerabilities, delayed security improvements
61d ago
European authorities take down prolific cybercrime VPN service
61d ago
The readiness paradox: Why a false sense of cyber confidence is becoming a liability
61d ago
Meet Rampart and Clarity, Microsoft’s new red team combo AI agents
61d ago
GitHub says internal repositories were impacted in poisoned VS Code extension attack
62d ago
CISA credential leak raises alarms, and Capitol Hill demands answers
62d ago
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches
62d ago
Mini Shai-Hulud returns, compromising hundreds of npm packages
63d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
63d ago
AI might cut false positives, but it won’t stop the slop
63d ago
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
64d ago
The Canvas breach proved that prevention is no longer enough
64d ago
Former CISA nominee Sean Plankey named US CEO of defense startup
64d ago
Colorado governor commutes prison sentence for election denier Tina Peters
66d ago
Here’s how the FTC plans to enforce the Take It Down Act
66d ago
Cisco zero-day under ongoing attack by persistent threat group
67d ago
Pentagon cyber official calls advanced AI ‘revolutionary warfare’
67d ago
White House cyber official: identity security matters more than ever in the age of AI
67d ago
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
68d ago
Researchers say AI just broke every benchmark for autonomous cyber capability
68d ago
Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks
68d ago
DOJ releases legal rationale for nationwide voter data collection
68d ago
Weaponized AI: The new frontier of fraud and identity spoofing
69d ago
Daybreak is OpenAI’s answer to the AI arms race in cybersecurity
69d ago
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
69d ago
Major world economies spell out key elements of AI ‘ingredients list’
69d ago
Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical
69d ago
Google and Amnesty International teamed up to make it harder for spyware vendors to hide
70d ago
AI is separating the companies built to scale from the ones built to sell
70d ago
Instructure claims hackers returned stolen Canvas data after an extortion standoff
70d ago
Google spotted an AI-developed zero-day before attackers could use it
71d ago
The missing cybersecurity leader in small business
71d ago
Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments
74d ago
ShinyHunters claims nearly 9,000 schools affected by Canvas data breach
74d ago
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI
74d ago
Ivanti customers confront yet another actively exploited zero-day
74d ago
Trump officials are steering a cybersecurity scholarship program toward AI
74d ago
American duo sentenced for hosting laptop farms for North Korean IT workers
75d ago
One House Democrat is pressing Commerce on the government’s spyware use
75d ago
A DOD contractor’s API flaw exposed military course data and service member records
75d ago
A critical Palo Alto PAN-OS zero-day is being exploited in the wild
75d ago
140 loaded
DA
darkreading
1d ago · 124 items
Cybersecurity Keeps Events 'Uneventful'
1d ago
Inc Ransomware Exploits SonicWall SMA Zero-Days
3d ago
The Real AI Threat Is Blind Trust
4d ago
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
4d ago
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
4d ago
Agentic AI: Taming the Unpredictable
4d ago
1M+ Emails Use Hidden Text to Dupe AI Security Filters
4d ago
Police Disrupt a €140M Cyber Fraud Ring in Spain
5d ago
Forgotten Bootloaders Expose Secure Boot Blind Spot
5d ago
Identity Attacks Overtake Exploits as Top Ransomware Cause
5d ago
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
6d ago
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
6d ago
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
6d ago
2-Click Cursor Exploit Enables Dev Environment Takeover
6d ago
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
6d ago
Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal
6d ago
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
6d ago
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
6d ago
Manage Vendor Risk in a Few Practical Steps
7d ago
Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?
7d ago
Name That Toon Contest
25d ago
Europe Evolves Into Ransomware's Favorite Region
26d ago
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
26d ago
2026 FIFA World Cup Faces Surge in Cyber Threats
26d ago
Do CISOs Need a Code of Ethics?
26d ago
More Malicious OpenClaw Skills Threaten AI Supply Chain
27d ago
Apple's MacOS Gap Lets Users Disable Security Tools
27d ago
Scope of Salesforce Attacks Expands as Icarus Leaks Data
27d ago
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
27d ago
SocGholish Takedown Highlights Malicious TDS Threats
28d ago
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
28d ago
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
28d ago
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
29d ago
He Thought He Was Secure; His Phone Number Was Stolen Anyway
29d ago
Stressors, AI Forcing Changes to Cybersecurity Teams
32d ago
Novo Nordisk Breach Highlights Software Development Pipeline Risk
32d ago
Operation Escaneo Signals Shift in LatAm Threat Landscape
33d ago
FIFA Bug Exposes World Cup Streams to Remote Takeover
33d ago
Salesforce Data Thefts Continue via Klue App Compromise
33d ago
Get Out of Security Debt by Tackling the Exposure Problem
33d ago
EU Gets a Head Start in Developing 6G Network Security
33d ago
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
38d ago
Claude Fable 5 Doesn't Change the Mythos Security Story
39d ago
Phishing Attack Volume Down 20%, But Risk Still Rising
39d ago
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
40d ago
Segmentation Works for OT If Operators Are Paying Attention
40d ago
Chinese, N. Korean Threat Groups Build on Asia-Pacific Success
40d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
40d ago
Bug Bounty Research Triggers ServiceNow Security Alert
40d ago
AI Risk Worries Insurers & Businesses Alike
40d ago
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
41d ago
The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life
41d ago
Blame AI: Patch Tuesday Hits Record 206 CVEs
41d ago
Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
41d ago
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
41d ago
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
42d ago
AI Slop Will Kill Cybersecurity Storytelling If We Let It
42d ago
Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
42d ago
Check Point VPN Flaw Exploited Since Early May
42d ago
Iran Signed a Ceasefire — Its Hackers Didn't
43d ago
[An RX Global Event] Infosecurity Europe
49d ago
Name That Toon: Mark of (Cybersecurity) Progress
52d ago
Asia's Cyber Insurance Market Shows Signs of Life
53d ago
With Complex Cloud Integrations, Small Errors Lead to Major Compromises
53d ago
'The Com' Cyberattacks Support Violence & Sexploitation
53d ago
As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
53d ago
Dutch Raid Fails to Dent Russian Bulletproof Host
54d ago
Agentic AI Isn't Risky; the Way Orgs Deploy It Is
54d ago
Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security
54d ago
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
54d ago
Nordic CISOs Handle Rising Cyber Threats Remarkably Well
54d ago
Ransomware Actors Show Up In Person to Steal Law Firm Data
54d ago
Latin American Cybercriminals Hoover Up Government Data
55d ago
AI-Assisted Exploit Development Outpaces Scanner Detection
55d ago
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
55d ago
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
55d ago
State Cyber Leaders Push Congress for More Funding, Support
55d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled?
55d ago
For Enterprises, Security Remains Agentic AI's Biggest Challenge
55d ago
The Boring Stuff is Dangerous Now
64d ago
Can Laws Stop Deepfakes? South Korea Aims to Find Out
64d ago
Congress Puts Heat on Instructure After Canvas Outage
66d ago
Cyber Pioneers Ponder Past as Prologue
67d ago
Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems
67d ago
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
67d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
67d ago
'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
68d ago
AI Drives Cybersecurity Investments, Widening 'Valley of Death'
68d ago
Foxconn Attack Highlights Manufacturing's Cyber Crisis
68d ago
Checkbox Assessments Aren't Fit to Measure Risk
68d ago
Attackers Weaponize RubyGems for Data Dead Drops
68d ago
Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak
68d ago
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape
69d ago
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly
69d ago
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
69d ago
It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight
69d ago
Hugging Face Packages Weaponized With a Single File Tweak
70d ago
20 Leaders Who Built the CISO Era: 2 Decades of Change
70d ago
Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
70d ago
How the Story of a USB Penetration Test Went Viral
77d ago
RMM Tools Fuel Stealthy Phishing Campaign
77d ago
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
77d ago
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
78d ago
How Dark Reading Lifted Off the Launchpad in 2006
78d ago
76% of All Crypto Stolen in 2026 Is Now in North Korea
80d ago
If AI's So Smart, Why Does It Keep Deleting Production Databases?
81d ago
Name That Toon: Mark of (Security) Progress
81d ago
20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage
81d ago
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
81d ago
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
81d ago
Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber
82d ago
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
82d ago
Claude Mythos Fears Startle Japan's Financial Services Sector
82d ago
Reverse Engineering With AI Unearths High-Severity GitHub Bug
82d ago
AI Finds 38 Security Flaws in Electronic Health Record Platform
82d ago
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
83d ago
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
83d ago
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
83d ago
NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later
83d ago
Feuding Ransomware Groups Leak Each Other's Data
83d ago
Vidar Rises to Top of Chaotic Infostealer Market
84d ago
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
84d ago
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
84d ago
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
85d ago
124 loaded
CD
Cyber Defense Magazine
1d ago · 10 items
Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack
1d ago
UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker
4d ago
Hacking US Elections: The First Tranche of Declassified Election Integrity Documents
4d ago
Inside Microsoft’s Record-Breaking 622-Bug Release
5d ago
Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook
6d ago
Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure
6d ago
CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers
7d ago
The Threat Mechanism and Mitigation of Pink Vishing Campaigns
8d ago
See It Once, Stop It Everywhere
10d ago
Cybercriminals Targeting World Cup Fans
10d ago
RF
Recorded Future
1d ago · 20 items
Threat Hunting: A Guide | Recorded Future
1d ago
Tracking Advanced Persistent Threat Groups | Recorded Future
4d ago
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
5d ago
The Shift: A New Era of AI Regulation
6d ago
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
7d ago
June 2026 CVE Landscape
11d ago
RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney
12d ago
The Threat Isn’t the Frontier Model
13d ago
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
20d ago
Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge
26d ago
Discover how Recorded Future’s Insikt Group combines human expertise with automated analysis to turn raw data into actionable, industry-leading threat intelligence.
Evaluating Mexico’s New Cybersecurity Plan
26d ago
FortiBleed Campaign Exposing Credentials for 73,932 FortiGate Systems
27d ago
The Purchase Scam Tactic Headed for the World Cup | Recorded Future
28d ago
State Digital Surveillance Risk Landscape
34d ago
The Intelligence No One Else Has: Inside Recorded Future’s Proprietary Collection Engine
35d ago
Recorded Future Launches Impact and Metrics Dashboard
40d ago
Cyber-Enabled Maritime Sanctions Evasion
40d ago
2026 FIFA World Cup: What Public Safety Officials Need to Know
41d ago
China's Noncombatant Evacuation Operations: 2005–2025
41d ago
Russia’s Defense-Based Economy Risks Forcing Putin to Fight Wars
42d ago
20 loaded
NE
NetworkChuck
2d ago · 15 items
I got inside FIFA’s Secret World Cup Broadcast Network
2d ago
AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA
4d ago
LIVE AMA | Summer of CCNA | 07/09/2026
11d ago
Fable 5 is back.....run these prompts before July 12th
18d ago
shadow AI is terrifying
31d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
32d ago
HTTPS Doesn't Hide This From Your ISP!!
32d ago
Cisco Just Showed the Future of Networking
33d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
35d ago
I was wrong about VPNs
36d ago
Certification Questions | LIVE AMA | Summer of CCNA
46d ago
Hermes has a Home Assistant skill and it's unreal!
47d ago
FREE coffee at Cisco Live (I'm giving it away)
48d ago
Codex Lives In PowerShell Now
49d ago
I'm Moderating My First Panel… Come see me at Cisco Live
49d ago
15 loaded
IP
IppSec
3d ago · 15 items
HackTheBox Logging
3d ago
HackTheBox - CCTV
10d ago
HackTheBox - DevArea
17d ago
HackTheBox - WingData
24d ago
HackTheBox - Nanocorp
31d ago
HackTheBox - VariaType
38d ago
HackTheBox - Facts
45d ago
HackTheBox - Interpreter
52d ago
HackTheBox - MonitorsFour
59d ago
HackTheBox - Pterodactyl
66d ago
HackTheBox - Overwatch
73d ago
HackTheBox - Sorcery
87d ago
HackTheBox - AirTouch
94d ago
HackThebox - Eighteen
101d ago
HackTheBox - DarkZero
108d ago
15 loaded
MS
Microsoft Security Blog
4d ago · 10 items
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
4d ago
Join Microsoft Security at Black Hat USA 2026 for supply chain research, hands-on security experiences, expert conversations, and our reception.
ACR Stealer: Two observed intrusion chains amid increased threat activity
4d ago
From late April 2026 to mid-June 2026, Microsoft Defender Experts observed increased ACR Stealer activity across customer environments. These campaigns are successfully using ClickFix lures to steal browser credentials, authentication token...
Least privilege for AI agents: Identity, access, and tool binding
5d ago
As AI agents become more autonomous, strong identity, access, and auditing controls are critical to keeping them secure.
Unpacking the AsyncAPI npm supply chain compromise and import-time payload delivery
5d ago
Threat actors compromised AsyncAPI packages and weaponized trusted CI/CD workflows to distribute malware through npm. This analysis breaks down the attack chain, payload delivery, and recommended defenses.
Turning threat intelligence into decisive action with Defender Experts
6d ago
Security teams have never had more visibility, yet rarely have they felt more uncertain. Signal pours in from endpoints, identities, cloud workloads, and a sprawling mix of third-party tools.
Defending SaaS-based applications against ShinyHunters OAuth abuse
7d ago
Microsoft Threat Intelligence identified threat actor activity with overlapping tradecraft commonly associated with ShinyHunters, including voice phishing (vishing), supply-chain compromise, and misconfigured guest access targeting SaaS-bas...
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
8d ago
Starting September 1, 2026, passkeys will become the default authentication experience in Microsoft Entra. Read more about how to prepare.
Securing our future: July 2026 progress report on Microsoft’s Secure Future Initiative
11d ago
Microsoft’s latest Secure Future Initiative report outlines progress on secure foundations, AI-powered defense, and future-ready cybersecurity.
GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware
12d ago
GigaWiper is a destructive backdoor that combines multiple wiping and ransomware-like capabilities into a single operational platform. This blog analyzes how the malware incorporates code from several previously separate malware families an...
Protecting Microsoft at AI speed: How SFI proactively hardens our cloud
13d ago
Learn how Microsoft uses AI to proactively harden its own cloud services through the Secure Future Initiative (SFI).
HS
Heimdal Security Blog
4d ago · 15 items
MediaArena malvertising: why a quarantine isn’t the end of the incident
4d ago
If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing i...
Top 6 Managed Detection and Response Providers
11d ago
There are several major managed detection and response (MDR) companies to choose from. We’ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a secur...
Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors
13d ago
Your client is no longer just buying your security advice. They’re auditing whether you live by it. That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators...
How to scale your patches without scaling your team (the patch wave)
18d ago
Most breaches don’t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the...
AI didn’t break patching. It showed us patching was already broken.
18d ago
Claude Mythos, an AI model from Anthropic, has found 23,019 software vulnerabilities in the past month. Fewer than 1% of them have been patched. That gap is the story. Finding a vulnerability used to be the hard part, the thing that limited...
Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes
20d ago
New feature reduces manual setup, speeds up customer activation, and helps MSPs scale Microsoft CSP estates with less operational work.
How Dynamic Defense shuts an attacker out without shutting down the business
25d ago
AI has handed hackers a resource advantage. Winning it back means spending your own resources far more precisely, and that’s the strategy we call Dynamic Defense. The principle is simple. Contain the threat just enough, for just long enough...
Static security has run out of road. The case for Dynamic Defense
25d ago
AI has flipped the economics of cybersecurity in the attacker’s favor. For most of the last decade, defenders held the cost advantage, buying down their risk with a stack of largely static controls. That advantage is gone, and winning it ba...
Breaking the MSP Echo Chamber: The Power of Community
27d ago
MSPs spend too much time talking to other MSPs and not enough time talking to the people they’re supposed to serve. That’s Paul Croker’s view of some of the channel’s biggest growth problems. While most industry events bring technology prof...
How attackers built a RAT on a Windows machine using its own .NET compiler
29d ago
In May 2026 an attacker compromised a UK medical practice endpoint without delivering a single malicious file. They used PowerShell and the .NET compiler built into Windows to build a Remcos remote access trojan on the machine itself, so si...
Attacker enables RDP, creates admin, erases evidence in ten seconds
29d ago
The State of AI Risk Management in 2026
35d ago
Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
36d ago
Your Next Insider Threat May Be an AI Coworker
39d ago
The OSI Model and Its Two Missing Layers
39d ago
15 loaded
TI
Technical Information Security Content & Discussion
5d ago · 293 items
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
5d ago
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
5d ago
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
5d ago
HN Security - My Semgrep C/C++ ruleset is ready for prime time again
6d ago
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
6d ago
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
6d ago
Smashing the ServiceNow Sandbox – Pre Authentication RCE
7d ago
Context Bombs: Using AI Guardrails as a defensive mechanism
7d ago
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
7d ago
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
8d ago
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
8d ago
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
8d ago
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
10d ago
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
11d ago
Towards CSI: What's the best harness? (arXiv 2026)
11d ago
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
12d ago
1 in 2 devices sold in Africa exfiltrate data to China
13d ago
Inside an AI coal mine security camera network powered by plaintext passwords
13d ago
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
13d ago
Bad Epoll: The bug missed by Mythos
13d ago
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
14d ago
New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"
15d ago
Playing Around With ADIDNS RPC Internals
15d ago
Windows Service - Playbook & Detection Strategies
15d ago
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
19d ago
FIFA was saved this time
19d ago
/r/netsec's Q3 2026 Information Security Hiring Thread
19d ago
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
20d ago
r/netsec monthly discussion & tool thread
20d ago
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
20d ago
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
21d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
21d ago
I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well.
23d ago
Dissecting Apple's Sparse Image Format (ASIF)
23d ago
A peek into Reddit's anti-spam internals
24d ago
CVE-2025-52465 geoserver arbitrary file write vulnerability
26d ago
CargoWise WebTracker - The keys were in the cargo
26d ago
Exploiting vulnerabilities in Johnson & Johnson web apps
27d ago
Cloudflare patches Copy-Fail across every server in two days
28d ago
New Cisco RCE was fixed
28d ago
CVE-2026-25860 turn XSS to RCE
29d ago
Exploiting Auth0 Defaults in XSS Attacks - elttam
29d ago
Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1)
30d ago
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530
31d ago
OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099)
32d ago
Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration
32d ago
CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance
33d ago
Would you like some malware served at the very top of DuckDuckGo?
33d ago
Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update
33d ago
QoS Policies to Restrict EDR Traffic and Detection Strategies
34d ago
Getting a CVE Without Shipping Slop
34d ago
PrizeBuzz phishing network analysis
34d ago
27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass
34d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
35d ago
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
36d ago
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
36d ago
Researcher accidentally gained access to a threat actor-controlled phishing website
37d ago
PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs
37d ago
MeshCentral: From XSS to RCE
37d ago
Getting the PID from random numbers in PHP
38d ago
The Axios npm compromise was visible in registry metadata before anyone ran npm install
38d ago
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs
38d ago
Free Compromise Detection for GitHub Repos - Tracebit Community Edition
39d ago
Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)
39d ago
Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery
39d ago
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs
39d ago
Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules
40d ago
Claude Fable 5: mid-tier results on coding tasks
40d ago
Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work
40d ago
Hacking Google with A.I. for $500,000
40d ago
Prompt injection: attacking the analyst's AI
40d ago
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
41d ago
We post-trained a model for offensive security instead of teaching it to refuse
41d ago
How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026
41d ago
FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster
41d ago
certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA"
41d ago
BlackSun - Defender for Endpoint on macOS
41d ago
GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline)
41d ago
Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam
41d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
41d ago
Apple’s Siri-AI, or more shouting into the void about “private” agents
42d ago
Entra Agent ID from a Security Perspective
42d ago
X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection
42d ago
WinGet - Code Execution, Persistence and Detection Strategies
42d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
42d ago
I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information
42d ago
AI Agents May Always Fall for Prompt Injections
42d ago
Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it
43d ago
EDRChoker: Choking The Telemetry Stream to Bypass Defenses
44d ago
PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware
44d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
44d ago
Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption
46d ago
Keeping Secrets Out of Logs
46d ago
Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier)
46d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
47d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
47d ago
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
47d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
47d ago
Season VI of the US Games launches TOMORROW!
47d ago
EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires
48d ago
Interesting- What LLM vuln research looks like
48d ago
Hacking your PC using your speaker without ever touching it
48d ago
Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing
48d ago
Golang code review notes II - elttam
48d ago
Using AI to Secure Its Generated Code Is a Ponzi Scheme
48d ago
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
49d ago
We Added a Detection Rule. We Were Not Expecting This.
49d ago
1-Click GitHub Token Stealing via a VSCode Bug
49d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
49d ago
NuGet Code Execution As A Service
49d ago
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
49d ago
Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider
50d ago
r/netsec monthly discussion & tool thread
50d ago
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
50d ago
Stealing Passwords via HTML Injection Under a Strict CSP
50d ago
Subnet discovery through multi-protocol TTL tracing
50d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
51d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
51d ago
Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters
52d ago
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
52d ago
Introducing Keyhog: The First GPU Accelerated secret scanner
53d ago
OffensiveCon26 YouTube Playlist released
53d ago
1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog
53d ago
I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found.
53d ago
Fooling around with encrypted reasoning blobs
53d ago
CALIF: An AI audit of FreeBSD
53d ago
CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries
53d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
53d ago
Visual Studio Extensions Revisited
54d ago
Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP)
54d ago
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
54d ago
What scanners are actually trying against AI infrastructure
54d ago
Defense by accumulation
54d ago
New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
55d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
55d ago
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
55d ago
HN Security - AI Reporter - Let's automate reporting in Burp Suite!
55d ago
Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records
55d ago
RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact
55d ago
Navigating Lax Load Balancers: When an Intersection Gets You Inside
56d ago
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents
56d ago
OTP lockout state leaked valid-code signal, enabling OLX account takeover
56d ago
How journalists rely on VPNs to protect press freedom
56d ago
Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
56d ago
Update Starlette Now. New severe vulnerability dropped.
56d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
56d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
57d ago
CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth
57d ago
Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal
57d ago
nmap on Linux: Guide to Network Scanning and Discovery
57d ago
Prompt Injection finally broke my brain a little. My first article as a security student.
58d ago
How to Use Claude AI: A Complete Technical Beginner's Guide
58d ago
Pardon MIE?: how Mythos did not bypass Apple MIE
59d ago
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
59d ago
AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22
60d ago
Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't)
60d ago
Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension
60d ago
Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
60d ago
Data breach in name of protest
60d ago
pnpm 11 Might Finally Be a Better Default Than npm
60d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave
60d ago
[Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled
61d ago
GitHub Actions Cache Poisoning is eating open source
61d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
61d ago
CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
61d ago
FatGid - FreeBSD 14.x kernel LPE
61d ago
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
61d ago
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
61d ago
The IBM X-Force Index 2026 explains all three in one finding.
61d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
62d ago
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
62d ago
[ Removed by Reddit ]
62d ago
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
62d ago
Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online
62d ago
The IBM X-Force Index 2026 explains all three in one finding.
62d ago
GitHub hit by a compromised VSCode extension
62d ago
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
62d ago
We audited 12K n8n templates: most have critical vulnerabilities
62d ago
Veilgate - Deception proxy
62d ago
Sleeping Agent: Silent persistent C2 through Web Push
62d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
62d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
63d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
63d ago
CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing
63d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
63d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
63d ago
The quiet death of behavioral anti-bot and the pivot to hardware ZKPs
63d ago
AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems
64d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
64d ago
The down fall of bug bounties
64d ago
TanStack Supply Chain Attack (And How to Lock Down GitHub Actions)
64d ago
Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation
64d ago
Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation
64d ago
Ansible security and compliance guide
65d ago
Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain
65d ago
AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize.
66d ago
Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works
66d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
66d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems
67d ago
Automating code security reviews with Claude Mythos-level capabilities
67d ago
Instrumenting QT6 desktop apps with Frida - Part 1
67d ago
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
67d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
68d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
68d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
68d ago
CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure
68d ago
How to Check Computer Activity: 2026 Guide for Windows and Mac
68d ago
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
68d ago
Hunting the Behavior Behind npm Supply Chain Attacks
68d ago
WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
68d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
68d ago
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
68d ago
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
68d ago
Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out
68d ago
On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study)
69d ago
A stealth approach to Process Injection - EntryPoint Hijacking
69d ago
A year of Apple Security Bounty research — 16 closed findings, full disclosure
69d ago
AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods
69d ago
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
70d ago
The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop
70d ago
Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
70d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
70d ago
I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
70d ago
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
70d ago
New ipTIME Pre-Auth RCE in CWMP
70d ago
Postmortem: TanStack npm supply-chain compromise
70d ago
How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models.
70d ago
OpenAI announces Daybreak, "frontier AI for defenders"
70d ago
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
70d ago
How I Defeat Passkeys Nearly Every Time in Phishing Assessments
71d ago
MyAudi app:Security issues in Audi Connected Vehicle experience
71d ago
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
71d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
71d ago
Autonomous Vulnerability Hunting with MCP
71d ago
ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement
72d ago
Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple
72d ago
The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
72d ago
Outrunning SHA256 with Physics
72d ago
Memory Poisoning AI Agents via ChromaDB
72d ago
Defence in Depth: A Practical Secure Corporate Network Topology
72d ago
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram
73d ago
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
73d ago
Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection
73d ago
Securing CI/CD for an open source project: lessons from Cilium
73d ago
ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12
74d ago
Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config
74d ago
Copy Fail (CVE-2026-31431): A Technical Deep Dive
74d ago
Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo
74d ago
Dirty Frag - Linux LPE similiar to Copy Fail
74d ago
Honey Tokens: Bait Credentials That Catch Breaches
75d ago
CVE-2026-42511 Breakdown: RCE in FreeBSD
75d ago
Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804
75d ago
An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support)
75d ago
Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI
75d ago
Quacc++: Automated Open Source Vulnerability Discovery
75d ago
Binance fixed the IP whitelist gap — but the disclosure process is still broken
76d ago
Non-Determinism of Maps in Golang: Why, How, and the Consequences
76d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
76d ago
Vulnerability Garden
76d ago
Scan. Secure. Simplify. — Free Web Tools Platform
76d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
76d ago
Salesforce pentesting novel techniques- how to be an apex predator
76d ago
DigiCert: Misissued code signing certificates
77d ago
Major AI Clients Shipping With Broken OAuth Implementations
77d ago
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10
77d ago
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud
77d ago
The Danger of Multi-SSO AWS Cognito User Pools
77d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
77d ago
Proton Pass: Second-Password Bypass Through Emergency Access
77d ago
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
77d ago
Lateral Movement - Cross-Session Activation
78d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
78d ago
Your vibe-coded app is probably violating GDPR right now
78d ago
Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate)
79d ago
How to exfiltrate data using only numeric outputs
80d ago
For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall.
80d ago
Every incident public companies have disclosed to the SEC, in one searchable database
80d ago
r/netsec monthly discussion & tool thread
81d ago
Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster
81d ago
Seventeen vulnerabilities in Omi, fourteen days of silence
82d ago
High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940)
82d ago
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
82d ago
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs
83d ago
The Thymeleaf Template Injection That Only Hurts If You Let It
83d ago
Set up automated dependency scanning after the recent npm/PyPI supply chain attacks
83d ago
A Route to Root in a 4G Industrial Router
83d ago
[Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses)
84d ago
The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords
84d ago
89 vulnerabilities in XAPI / Citrix XenServer
84d ago
[ Removed by Reddit ]
84d ago
Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025)
85d ago
Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary
85d ago
MCPwned: a Burp Suite extension for auditing MCP servers
85d ago
293 loaded
BH
Black Hat
6d ago · 15 items
Black Hat Stories | Shanna Daly, CEO of Torin Cyber Group
6d ago
What to Expect at Black Hat USA 2026
7d ago
Black Hat Europe 2025 | Compromising The AI Agent Ecosystem Via Its "Universal Connector"
8d ago
Black Hat Europe 2025 | Millions of Intranet Devices Are Facing Silent Takeover (On-Demand Only)
9d ago
Black Hat Europe 2025 | Bootstrapping Trust: From Isolated Build Machines to Enclaved CI Pipelines
10d ago
Black Hat Europe 2025 | Pwning .NET Framework Applications Through HTTP Client Proxies And WSDL
11d ago
Black Hat Intercepted | Olivia Gallucci, Security Engineer at Datadog
12d ago
Black Hat Europe 2025 | Ghost In The Stack: Evolving Call Stack Spoofing In A Post-CET Era
12d ago
Black Hat Europe 2025 | ORMageddon: Leaking More Than You Joined For
13d ago
Black Hat Europe 2025 | Breaking AI Inference Systems: Lessons From Pwn2Own Berlin
13d ago
Black Hat Intercepted | Anurag Swarnim Yadav, Co-Founder & CTO of QubitAC
14d ago
Black Hat Europe 2025 | Nation-Scale SecOps: How CERT PL Scans Poland
14d ago
Black Hat Europe 2025 | Not Just Victims: The Hidden Villains Inside Infostealer Logs
15d ago
Black Hat Europe 2025 | Taking Control Over Legacy And ERTMS/ETCS Railroad Signaling Systems
16d ago
Black Hat Europe 2025 | Slashing QUIC's Performance With A Hash DoS
17d ago
15 loaded
HA
Hak5
6d ago · 15 items
Your Home Internet Has a New Owner | Threat Wire
6d ago
Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire
13d ago
Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire
29d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
29d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
29d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
33d ago
Shark Jacked my LAN 🦈
34d ago
Developers React to the 105-Second Github Chain Reaction | Threat Wire
39d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
40d ago
Introducing Shark Jack Display 🦈
43d ago
The GitHub Leak Situation Just Got Worse | Threat Wire
54d ago
The Worm That Deletes Your Entire Computer | Threat Wire
60d ago
A TL;DR on Dirty Frag #cybersecurity #threatwire @endingwithali
60d ago
Google’s Silent AI Install: What They’re Hiding in Your Files #cybersecurity @endi
60d ago
🔴 [PAYLOAD REVIEW] WiFi Pineapple Pager 📟🍍
65d ago
15 loaded
TL
The Last Watchdog
6d ago · 34 items
News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations
6d ago
SAN FRANCISCO, July 15, 2026, CyberNewswire – Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been mi...
News alert: Insignary’s on-demand SBOM verification boosts software supply chain security
6d ago
TORONTO, July 15, 2026, CyberNewswire ŌĆō According to Insignary Inc., a leader in software supply chain security and binary software composition analysis (SCA), most organizations cannot independently verify what is actually inside the sof...
News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions
6d ago
TEL AVIV, Israel, July 14, 2026, CyberNewswire – Tego AI, a cybersecurity company, published new research identifying a potentially critical security weakness in Claude Tag, Anthropic’s native integration between Claude and Slack. Resea...
News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI
13d ago
MELBOURNE, Fla., July 8, 2026, CyberNewswire – OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop stan...
News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk
15d ago
TORONTO, July 6, 2026, CyberNewswire тАУ Insignary, Inc., whose patented binary fingerprint technology has been cited in four Gartner research reports, today announced its recognition as a Sample Vendor for Reachability Analysis in the Gart...
News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks
19d ago
FRANKFURT, July 1, 2026, CyberNewswire – Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing ...
News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks
21d ago
BOSTON, June 30, 2026, CyberNewswire – Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, "Securing Third-Party Marketing in the AI Era," taking place July 8 at 9 AM EDT / 3 PM CEST. Every market...
News alert: OpenMatter launches platform to verify AI activity across enterprise systems
21d ago
MELBOURNE, Fla., June 30, 2026, CyberNewswire – OpenMatter Network today announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don't Trust Data. Prove It. ...
News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies
34d ago
AUSTIN, Tex., June 17, 2026, CyberNewswireŌĆōSpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enter...
News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk
34d ago
LONDON, June 17, 2026, CyberNewswire–Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report's headline finding is a divide inside the...
News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails
34d ago
News alert: GitGuardian adds endpoint protection as developer laptops become credential troves
34d ago
News alert: Varist announces AI-scale malware detection for healthcare and medical imaging
35d ago
News alert: Cloud security report finds fragmented tools widening the cloud complexity gap
41d ago
News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces
48d ago
FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential
49d ago
News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit
53d ago
GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet
55d ago
GUEST ESSAY: AI can speed up communication, but it can also weaken human connection
62d ago
News alert: Orchid Security study finds invisible identities now outnumber managed accounts
62d ago
MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack
64d ago
LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back
69d ago
FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread
70d ago
News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents
71d ago
News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market
76d ago
SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents
82d ago
GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control
84d ago
FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures
85d ago
News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category
90d ago
Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one
92d ago
News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security
96d ago
GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags
98d ago
News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk
102d ago
FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense
105d ago
34 loaded
PF
PYMNTS | Fraud Prevention Archives
6d ago · 10 items
78% of CFOs Say Payment Blind Spots Increase Customer Friction
6d ago
85% of CFOs Say Automation Cuts Payments Friction
8d ago
42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million
13d ago
LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud
17d ago
42% of Issuers Say Fraud and Disputes Are Driving Up Costs
19d ago
JPMorganChase and Amazon Back Aspen Institute Drive Against Scams
21d ago
World Cup Gives Cross-Border Payments Their Super Bowl Moment
22d ago
Banks Face a New ACH Fraud Test as Nacha Rules Take Effect
25d ago
The latest Nacha fraud rules require banks to expand fraud monitoring and adopt broader, risk-based oversight across ACH activity.
Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges
25d ago
Nvidia’s AI blueprint maps connections across accounts and devices to catch the fraud network, not just the charge.
AI Forces Compliance Teams to Rethink Alert Strategy
26d ago
KO
Krebs on Security
6d ago · 10 items
Microsoft Patches a Record 570 Security Flaws
6d ago
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesd...
Lessons Learned from CISA’s Recent GitHub Leak
8d ago
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almos...
Felons, Fraudsters Flog Offensive Cybersecurity Startup
13d ago
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intellige...
FBI Seizes NetNut Proxy Platform, Popa Botnet
18d ago
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technolo...
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
28d ago
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The ...
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
33d ago
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers ...
Who Runs the Ransomware Group ‘The Gentlemen?’
41d ago
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of...
A Record-Breaking Patch Tuesday for June 2026
41d ago
Microsoft today released software updates to plug nearly 200 security holes across its Windows operating systems and supported software, a record number of fixes for the company's monthly Patch Tuesday cycle. Nearly three dozen of those bug...
Hackers Used Meta’s AI Support Bot to Seize Instagram Accounts
50d ago
The Instagram accounts for the Obama White House and the Chief Master Sergeant of the U.S. Space Force were briefly defaced with pro-Iranian images and messages over the weekend, after instructions began circulating on Telegram showing how ...
Netherlands Seizes 800 Servers, Arrests 2 for Aiding Cyberattacks
57d ago
Authorities in the Netherlands have arrested the co-owners of two related Internet hosting companies for operating IT infrastructure used by Russia to carry out cyberattacks, influence operations and disinformation campaigns inside the Euro...
DB
David Bombal
7d ago · 15 items
Is Cat7 a SCAM?
7d ago
Cisco's Agents Reason Like a CCIE
7d ago
Install GrapheneOS Before Your Phone Becomes the Checkpoint
9d ago
Unveiled: Cisco Deep Reasoning
15d ago
Why Apple Hide My Email FAILS
16d ago
New to Linux? This is the best place to start!
16d ago
WARNING: AI tracks your face
18d ago
Is DEFCON for you?
20d ago
2026 home lab setup to test malicious links safely for FREE (step by step)
23d ago
Which is Ethernet? What's the difference?
25d ago
Europe’s 800 Exaflop SUPERCOMPUTERS
26d ago
They Created a Supercomputer in a Rack?
28d ago
Build a Complete Free CCNA Home Lab in 2026 With No Gear
30d ago
Broken access control demo
30d ago
Will this replace PoE (Power over Ethernet)?
32d ago
15 loaded
BF
Blog – Forter
7d ago · 10 items
The Gray Area in Your Checkout Is Costing You More Than You Think
7d ago
Your Payment Routing Rules Are Making Decisions Without You
12d ago
New at Forter: AI Agents Built to Amplify Your Team
27d ago
Can AI Agents Find, Trust, and Choose Your Brand?
28d ago
IMPACT Roadshow Recap: Getting Ready for Agentic Commerce
41d ago
Agent-Ready: How to Prepare Your Site for AI-Driven Commerce
47d ago
Japan’s 3DS Mandate: One Year In
67d ago
One-Click Refunds Are Not as Hard as You Think
77d ago
Toys“R”Us Japan Implements Forter’s Fraud Management and Payment Optimization Solutions
83d ago
More of What Matters: Forter’s April Product Release
84d ago
FP
Fraud Prevention – Riskified
7d ago · 1 items
PN
Proofpoint News Feed
7d ago · 10 items
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
7d ago
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
8d ago
Suspected Chinese snoops caught breaking into universities' Roundcube mailservers
13d ago
Proofpoint researcher tells The Reg: 'We estimate the total volume of targets would be a few dozen'
New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams
20d ago
Cargo theft is evolving with cybercrime. Learn how organized crime is hijacking shipments—from a $400,000 lobster theft to a $500,000 bourbon heist—and what needs to be done.
Defending the Authentication Flow: Device Code Phishing with Selena Larson
21d ago
Host Caleb Tolin sits down with Selena Larson, Staff Threat Researcher and Lead, Intelligence Analysis and Strategy at Proofpoint and Host of the DISCARDED podcast, to discuss the mechanics of device code phishing and the widespread abuse o...
Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense
29d ago
Proofpoint has been selected to participate in OpenAI Daybreak, which helps trusted cybersecurity companies integrate AI into defensive security operations. Through the OpenAI Daybreak Cyber
OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses
29d ago
Suspected North Korean actors use fake ‘coding assignments’ to steal crypto
42d ago
China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa
47d ago
Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era
55d ago
New solution reduces exposure to actively exploited vulnerabilities in minutes by turning intelligence into immediate protection across primary attack paths Disrupts AI-powered exploit-
WE
WeLiveSecurity
7d ago · 20 items
Forgotten UEFI shims undermining Secure Boot
7d ago
ESET Threat Report H1 2026
13d ago
Cyber readiness for SMBs: Getting the basics right
18d ago
This month in security with Tony Anscombe – June 2026 edition
21d ago
Inside the inbox: Why cybercriminals want to break into your email account
22d ago
SMB cyber readiness: the road to resilience starts here
25d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
26d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
27d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
33d ago
Protecting legacy OT systems against modern cyberthreats
34d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
35d ago
EvilTokens: A phishing attack that doesn’t steal your password
36d ago
OceanLotus: From external espionage to domestic targeting
40d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
41d ago
Cybercriminals: the 'auditors' you never hired
42d ago
Lessons for life: Why children’s data is a long-term identity risk
48d ago
This month in security with Tony Anscombe – May 2026 edition
53d ago
ESET APT Activity Report Q4 2025–Q1 2026
54d ago
What to consider before asking an AI chatbot for health advice
55d ago
BTMOB: A stealthy RAT burrowing deep into Android devices
56d ago
20 loaded
WE
WeLiveSecurity
7d ago · 48 items
Forgotten UEFI shims undermining Secure Boot
7d ago
ESET Threat Report H1 2026
13d ago
Cyber readiness for SMBs: Getting the basics right
18d ago
This month in security with Tony Anscombe – June 2026 edition
21d ago
Inside the inbox: Why cybercriminals want to break into your email account
22d ago
SMB cyber readiness: the road to resilience starts here
25d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
26d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
27d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
33d ago
Protecting legacy OT systems against modern cyberthreats
34d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
35d ago
EvilTokens: A phishing attack that doesn’t steal your password
36d ago
OceanLotus: From external espionage to domestic targeting
40d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
41d ago
Cybercriminals: the 'auditors' you never hired
42d ago
Lessons for life: Why children’s data is a long-term identity risk
48d ago
This month in security with Tony Anscombe – May 2026 edition
53d ago
ESET APT Activity Report Q4 2025–Q1 2026
54d ago
What to consider before asking an AI chatbot for health advice
55d ago
BTMOB: A stealthy RAT burrowing deep into Android devices
56d ago
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
60d ago
Webworm: New burrowing techniques
62d ago
The quest for greater tech independence
63d ago
Why geopolitical turmoil is a gift for scammers, and how to stay safe
67d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
68d ago
Eyes wide open: How to mitigate the security and privacy risks of smart glasses
71d ago
Fake call logs, real payments: How CallPhantom tricks Android users
75d ago
Fixing the password problem is as easy as 123456
75d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
77d ago
This month in security with Tony Anscombe – April 2026 edition
82d ago
The calm before the ransom: What you see is not all there is
88d ago
GopherWhisper: A burrow full of malware
89d ago
New NGate variant hides in a trojanized NFC payment app
91d ago
What the ransom note won’t say
92d ago
That data breach alert might be a trap
95d ago
Supply chain dependencies: Have you checked your blind spot?
96d ago
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike
102d ago
As breakout time accelerates, prevention-first cybersecurity takes center stage
105d ago
Digital assets after death: Managing risks to your loved one’s digital estate
111d ago
This month in security with Tony Anscombe – March 2026 edition
112d ago
RSAC 2026 wrap-up – Week in security with Tony Anscombe
116d ago
A cunning predator: How Silver Fox preys on Japanese firms this tax season
116d ago
Virtual machines, virtually everywhere – and with real security gaps
118d ago
Cloud workload security: Mind the gaps
119d ago
Move fast and save things: A quick guide to recovering a hacked account
123d ago
EDR killers explained: Beyond the drivers
124d ago
Face value: What it takes to fool facial recognition
130d ago
Cyber fallout from the Iran war: What to have on your radar
131d ago
48 loaded
NA
NahamSec
8d ago · 15 items
This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!)
8d ago
I Made an AI Agent That Reverses CVEs While I Sleep
15d ago
This Hacker Got Paid $50,000+ to Break Frontier AI Models
29d ago
This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity
34d ago
How I Made $30,000 Hacking Broken Access Control
36d ago
$30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover
36d ago
Content creations was both a blessing and a curse. #bugbounty
43d ago
This Hacker Made $7,000 Hacking AI With One Email
43d ago
How I Found My First $3,000 AI Vulnerability
50d ago
This GitHub README Hijacks Your AI and Spreads Like a Virus
64d ago
New video: hacking AI coding assistants and IDEs. #bugbounty #ai
64d ago
The Bug Bounty Roadmap I'd Follow If I Started Over (With AI)
71d ago
Is the AI hype helping or killing your bug bounty dreams? #hacking #bugbounty
71d ago
Stop Using AI Connectors Until You Watch This
78d ago
One ChatGPT connector. One email. Full AI agent hijack. #BugBounty #PromptInjection #ai #hacking
78d ago
15 loaded
TC
The Cyber Mentors
11d ago · 15 items
Soft Skills for the Job Market: Applying for Jobs
11d ago
LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway
13d ago
Celebrating 1 Million Subscribers on July 8th!
19d ago
Real Folks of Cyber | Pearce Barry | Day in the Life
25d ago
Getting Started with the TCM Security Academy
25d ago
Soft Skills for the Job Market: Resume Writing
32d ago
TCM Security Summer Sale is Here!
35d ago
LIVE: 🕵️ CTF Prize Draw | Cybersecurity
40d ago
Secrets to PNPT Debrief Success
42d ago
TCM Security CTF Walkthrough
46d ago
Top 5 Active Directory Pentesting Tools
49d ago
Real Folks of Cyber | Dan Berger | Day in the Life
54d ago
Soft Skills for the Job Market: Communication
60d ago
LIVE: 🕵️ HTB Sherlocks! | Cybersecurity | Blue Team
68d ago
A Quick Way to Prove Your Cybersecurity Skillset!
70d ago
15 loaded
TM
Trend Micro Research, News, Perspectives
22d ago · 20 items
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
22d ago
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer
28d ago
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
33d ago
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
34d ago
Governing Claude Enterprise in Environments Where Inline Controls Can't Go
39d ago
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026
41d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
43d ago
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
50d ago
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
56d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
60d ago
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
61d ago
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
63d ago
Agentic Governance: Why It Matters Now
64d ago
Analyzing TeamPCP’s Supply Chain Attacks: Checkmarx KICS and elementary-data in CI/CD Credential Theft
69d ago
Vibe Hacking: Two AI-Augmented Campaigns Target Government and Financial Sectors in Latin America
71d ago
What Is the Instructure Canvas Breach? Impact, Risks, and What Institutions Should Do
72d ago
Supporting the National Cyber Strategy: How TrendAI™ Helps
76d ago
InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise
77d ago
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
78d ago
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
82d ago
20 loaded
M3
Microsoft 365 Blog
26d ago · 10 items
Copilot in Excel: Built for the era of Frontier Finance
26d ago
- Discover how Copilot in Excel transforms finance workflows with skills, data connectors, and capabilities for traceability.
Copilot Cowork is now generally available
35d ago
Copilot Cowork is now generally available worldwide, bringing secure, AI-powered automation for complex enterprise tasks in Microsoft 365.
Introducing Microsoft Scout: Your always-on personal agent
49d ago
Microsoft introduces a new, always-on personal agent, Microsoft Scout, integrated across the Microsoft 365 apps you use every day.
Announcing the new Work IQ APIs
49d ago
Build enterprise agents with Work IQ APIs for Microsoft 365—bringing business context, tools, and secure, scalable intelligence into every workflow.
Introducing Microsoft 365 Business with Copilot: The new standard for small business
54d ago
Meet Microsoft 365 Business with Copilot—the AI-powered solution transforming how small businesses work, collaborate, and compete.
Introducing a new design for Microsoft 365 Copilot
54d ago
Copilot’s redesigned experience delivers faster performance, adaptive tools, and clearer AI-powered workflows to help you easily move from intention to outcome.
New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences
56d ago
Explore what's new in Copilot Studio, May 2026: computer-using agents are now available, plus redesigned workflows and Work IQ extensibility.
New and improved: Agent governance, intelligent workflows, and connected app experiences
71d ago
See what's new in Copilot Studio, April 2026: updates to workflows, more control over agent operations, and an expanded agent usage estimator.
Copilot Cowork: From conversation to action across skills, integrations, and devices
77d ago
Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you.
Microsoft 365 Copilot, human agency, and the opportunity for every organization
77d ago
Empower your organization with Microsoft 365 Copilot—AI that bridges human potential and business outcomes for the future of work.
AL
Alerts
33d ago · 44 items
CISA Adds One Known Exploited Vulnerability to Catalog
33d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
33d ago
CISA Adds One Known Exploited Vulnerability to Catalog
35d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
36d ago
CISA Adds One Known Exploited Vulnerability to Catalog
39d ago
CISA Adds One Known Exploited Vulnerability to Catalog
40d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
42d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
43d ago
CISA Adds One Known Exploited Vulnerability to Catalog
46d ago
CISA Adds One Known Exploited Vulnerability to Catalog
48d ago
CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
49d ago
CISA Adds One Known Exploited Vulnerability to Catalog
50d ago
CISA Adds One Known Exploited Vulnerability to Catalog
53d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
54d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
55d ago
CISA Adds One Known Exploited Vulnerability to Catalog
56d ago
CISA Adds One Known Exploited Vulnerability to Catalog
60d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
61d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
62d ago
CISA Adds One Known Exploited Vulnerability to Catalog
67d ago
CISA Adds One Known Exploited Vulnerability to Catalog
68d ago
CISA Adds One Known Exploited Vulnerability to Catalog
74d ago
CISA Adds One Known Exploited Vulnerability to Catalog
75d ago
CISA Adds One Known Exploited Vulnerability to Catalog
76d ago
CISA Adds One Known Exploited Vulnerability to Catalog
81d ago
CISA Adds One Known Exploited Vulnerability to Catalog
82d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
84d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
88d ago
CISA Adds One Known Exploited Vulnerability to Catalog
89d ago
CISA Adds One Known Exploited Vulnerability to Catalog
90d ago
Supply Chain Compromise Impacts Axios Node Package Manager
92d ago
CISA Adds Eight Known Exploited Vulnerabilities to Catalog
92d ago
CISA Adds One Known Exploited Vulnerability to Catalog
96d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
98d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
99d ago
CISA Adds One Known Exploited Vulnerability to Catalog
104d ago
CISA Adds One Known Exploited Vulnerability to Catalog
106d ago
CISA Adds One Known Exploited Vulnerability to Catalog
110d ago
CISA Adds One Known Exploited Vulnerability to Catalog
111d ago
CISA Adds One Known Exploited Vulnerability to Catalog
113d ago
CISA Adds One Known Exploited Vulnerability to Catalog
116d ago
CISA Adds One Known Exploited Vulnerability to Catalog
117d ago
CISA Adds One Known Exploited Vulnerability to Catalog
118d ago
CISA Adds Five Known Exploited Vulnerabilities to Catalog
123d ago
44 loaded
AC
All CISA Advisories
33d ago · 125 items
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
33d ago
CISA Adds One Known Exploited Vulnerability to Catalog
33d ago
Schneider Electric EasyLogic T150 and Saitel DP
33d ago
AVer PTC cameras
33d ago
Rockwell Automation FactoryTalk Historian Site Edition
33d ago
AzeoTech DAQFactory
33d ago
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
33d ago
Mitsubishi Electric MELSEC iQ-F Series
33d ago
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
33d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
33d ago
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
35d ago
Rockwell Automation RSLinx
35d ago
Rockwell Automation FLEX I/O EtherNet/IP Adapters
35d ago
Rockwell Automation FactoryTalk Analytics PavilionX
35d ago
Rockwell Automation CompactLogix
35d ago
CISA Adds One Known Exploited Vulnerability to Catalog
35d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
36d ago
CISA Adds One Known Exploited Vulnerability to Catalog
39d ago
Yarbo Android/iOS Mobile Application and Cloud Infrastructure
40d ago
Naxclow IoT Platform
40d ago
Brickcom Cameras
40d ago
CISA Adds One Known Exploited Vulnerability to Catalog
40d ago
Siemens KACO Blueplanet Inverters
42d ago
Schneider Electric EcoStruxure Panel Server
42d ago
Schneider Electric Modicon Network Managed Switches
42d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
42d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
43d ago
CISA Adds One Known Exploited Vulnerability to Catalog
46d ago
NAVTOR NavBox
47d ago
Hitachi Energy MACH HiDraw
47d ago
Hitachi Energy ITT600 Explorer
47d ago
B&R PPT30 Operating System
47d ago
Hitachi Energy RTU500
47d ago
CISA Adds One Known Exploited Vulnerability to Catalog
48d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
49d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
49d ago
CISA Adds One Known Exploited Vulnerability to Catalog
50d ago
CISA Adds One Known Exploited Vulnerability to Catalog
53d ago
ABB EIBPORT
54d ago
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
54d ago
ABB Busch-Welcome 2 Wire Door Opener Actuator
54d ago
Fourth Frontier Frontier X Mobile Application, Frontier X2
54d ago
CP Plus 8 Ch. Network Video Recorder
54d ago
XCharge C6
54d ago
KMW CCTV Security Cameras
54d ago
MacGregor Voyage Data Recorder (VDR) G4e
54d ago
Schnieider Electric EcoStruxure Machine Expert HVAC
54d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
54d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
55d ago
ABB Terra AC
56d ago
ABB LVS MConfig
56d ago
ABB Ability Camera Connect
56d ago
Eppendorf BioFlo 320
56d ago
ABB AbilityTM Zenon Remote Transport Vulnerability
56d ago
ABB AC500 V2
56d ago
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
56d ago
CISA Adds One Known Exploited Vulnerability to Catalog
56d ago
CISA Adds One Known Exploited Vulnerability to Catalog
60d ago
ABB Terra AC Wallbox
61d ago
Hitachi Energy GMS600
61d ago
ABB B&R Automation Studio
61d ago
ABB B&R Automation Runtime
61d ago
ABB B&R PCs
61d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
61d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
62d ago
Kieback & Peter DDC Building Controllers
63d ago
Siemens RUGGEDCOM APE1808 Devices
63d ago
ABB CoreSense HM and CoreSense M10
63d ago
ScadaBR
63d ago
ZKTeco CCTV Cameras
63d ago
CISA Adds One Known Exploited Vulnerability to Catalog
67d ago
Siemens Siemens ROS#
68d ago
Siemens gWAP
68d ago
Siemens SIMATIC
68d ago
Siemens Ruggedcom Rox
68d ago
Siemens Ruggedcom Rox
68d ago
Siemens Simcenter Femap
68d ago
Universal Robots Polyscope 5
68d ago
Siemens Ruggedcom Rox
68d ago
Siemens Teamcenter
68d ago
Siemens Solid Edge
68d ago
Siemens SENTRON 7KT PAC1261 Data Manager
68d ago
Siemens Opcenter RDnL
68d ago
Siemens Ruggedcom Rox
68d ago
Siemens SIMATIC S7 PLC Web Server
68d ago
Siemens Industrial Devices
68d ago
Siemens SIMATIC
68d ago
Siemens SIPROTEC 5
68d ago
CISA Adds One Known Exploited Vulnerability to Catalog
68d ago
Software Bill of Materials for AI - Minimum Elements
70d ago
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
70d ago
Subnet Solutions PowerSYSTEM Center
70d ago
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities
70d ago
ABB AC500 V3 Multiple Vulnerabilities
70d ago
ABB Automation Builder Gateway for Windows
70d ago
Fuji Electric Tellus
70d ago
CISA Adds One Known Exploited Vulnerability to Catalog
74d ago
CISA Adds One Known Exploited Vulnerability to Catalog
75d ago
MAXHUB Pivot Client Application
75d ago
CISA Adds One Known Exploited Vulnerability to Catalog
76d ago
ABB B&R Automation Studio
77d ago
ABB B&R Automation Runtime
77d ago
Hitachi Energy PCM600
77d ago
Johnson Controls CEM AC2000
77d ago
ABB B&R PVI
77d ago
CISA Adds One Known Exploited Vulnerability to Catalog
81d ago
Careful Adoption of Agentic AI Services
81d ago
ABB AWIN Gateways
82d ago
ABB Ability OPTIMAX
82d ago
ABB PCM600
82d ago
ABB Edgenius Management Portal
82d ago
CISA Adds One Known Exploited Vulnerability to Catalog
82d ago
ABB Ability Symphony Plus Engineering
82d ago
ABB System 800xA, Symphony Plus IEC 61850
82d ago
Adapting Zero Trust Principles to Operational Technology
83d ago
NSA GRASSMARLIN
84d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
84d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
88d ago
SpiceJet Online Booking System
89d ago
Carlson Software VASCO-B GNSS Receiver
89d ago
Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera
89d ago
Milesight Cameras
89d ago
Defending Against China-Nexus Covert Networks of Compromised Devices
89d ago
Yadea T5 Electric Bicycle
89d ago
Intrado 911 Emergency Gateway (EGW)
89d ago
125 loaded
CY
cybersecurity
40d ago · 1867 items
Any solutions we can use?
40d ago
Possible targeted attack
40d ago
RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline
40d ago
Facebook messenger to text
40d ago
Managing Solution Agents
40d ago
Nottingham University data breach affects over 450,000 students
40d ago
SWGs that support 3rd party external DNS resolver
40d ago
Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers
40d ago
Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG
40d ago
Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch
40d ago
Phishing awareness training resulting in ignoring company comms?
40d ago
How are you analyzing Android malware nowadays?
40d ago
Hackers Exploit Langflow Vulnerability for Remote Code Execution
40d ago
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research
40d ago
NEED SOME GUIDANCE
40d ago
Help setting up local encryption on my pc
40d ago
Agentic AI on Cybersecurity
40d ago
DoD 0-days Typically Come Down to Authorization Failures
40d ago
HDD
40d ago
Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets
40d ago
How can we test the firmware code/images security?
40d ago
20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004
40d ago
GitHub announces npm security changes to tackle supply-chain attacks
40d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
40d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
40d ago
What is the difference between Regular TLS and Mutual TLS?
40d ago
Every employee's password was stored in a single Excel file
40d ago
npm v12 is changing how dependencies are installed to reduce supply-chain risk
40d ago
Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia?
40d ago
How good Microsoft Defender for storage?
40d ago
GreatXML bitlocker bypass vulnerability
40d ago
Struggle
40d ago
Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications?
40d ago
Wiz launches Cloud Security Job Board
40d ago
Physical Project Ideas
40d ago
How can I get into cybersecurity while studying Information Systems Engineering?
40d ago
Cloud Security job board
40d ago
Continuous learning
40d ago
Angry bug hunter with Microsoft beef drops new Windows 0-day
40d ago
Mid-30s, stuck in web pentesting, and wondering what to do ?
40d ago
Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM
40d ago
Is Microsoft Purview really secure when using Copilot?
41d ago
Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature?
41d ago
Nee academic references for Hashcat's 'Next Big Bang' log
41d ago
CISA released BOD 26-04: A new federal government vulnerability management strategy?
41d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
41d ago
added Mac support to my corporate hacking sim. Demo now available on Steam
41d ago
Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte)
41d ago
Students' data taken in major University of Nottingham cyber-attack
41d ago
Has unmanaged external file sharing ever burned you?
41d ago
Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers
41d ago
Need feedback on my presentation
41d ago
Compensating controls besides admin credentials being needed to download software on employee endpoints
41d ago
OpenSSL PKCS#7 CVE-2026-45447
41d ago
Presentation Question
41d ago
How to Stay Ahead of Deepfake Evolution in 2026
41d ago
France’s Government Messaging App Tchap Got Breached
41d ago
Where's the fix for MiniPlasma?
41d ago
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
41d ago
Internships
41d ago
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
41d ago
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
41d ago
Looking for a Reliable Cybersecurity Provider for a School in North Sydney
41d ago
Early Operational Visibility
41d ago
how are you actually managing ai agents in production?
41d ago
Al app builders: How are you handling security questionnaires when selling your product?
41d ago
[ Removed by Reddit ]
41d ago
How are all of doing with THE AI model thats big news currently??
41d ago
Skill to Scan your Codebase
41d ago
Miasma-style supply chain attacks
41d ago
FCaptcha v1.12: Catching AI Agents That Drive Real Browsers
41d ago
Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones
41d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
41d ago
AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say
41d ago
Huntress Stack (MS Defender or SentinelOne)
41d ago
META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT
41d ago
FBI is announcing Operation Riptide
41d ago
ServiceNow confirmed some customer instances were breached.
41d ago
Which are some of the best Cybersecurity / OT Security events that happen in GCC?
41d ago
DF/IR Community
41d ago
Chaotic Eclipse's new RoguePlanet
41d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
41d ago
Thoughts on Automated Compliance?
41d ago
A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available
41d ago
North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says
42d ago
Microsoft has released a patch for the bitlocker bypass
42d ago
Please advices
42d ago
soc analyst l1
42d ago
Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow
42d ago
Looking to move off KnowBe4, what are people actually using these days?
42d ago
Too Many Certs, Not Enough Experience — What’s the Best Next Step?
42d ago
Authenticating ARP and NDP
42d ago
Does anyone use rule feeds in 2026?
42d ago
Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations!
42d ago
Need a vm for practice
42d ago
Tips/Tricks to WFH as a SOC Analyst?
42d ago
Cybersecurity statistics of the week (June 1st - June 7th)
42d ago
Where can GRC folks learn practical AppSec / DevSecOps without going full engineer?
42d ago
I almost got “onboarded” into a malware campaign disguised as a job opportunity.
42d ago
University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model
42d ago
AI Blocklist - help
42d ago
Protecting AI workloads on Linux servers
42d ago
Exposing DoNex Ransomware Secrets with Malcore!
42d ago
What are the different Disaster Recovery scenarios your teams have tested on?
42d ago
someone actually leaked the Miasma supply chain attack toolkit source code on github
42d ago
WinGet - Code Execution, Persistence and Detection Strategies
42d ago
Ransomware attack shuts Illinois high school until Wednesday
42d ago
Ideas for demo
42d ago
Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please?
42d ago
Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares.
42d ago
Physical attack device
42d ago
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
42d ago
IT GRC News?
42d ago
Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again
42d ago
Shifting L7 validation to the edge to stop DB resource exhaustion?
42d ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
42d ago
EC Council CEH exam advice
42d ago
About NPower vs PerScholas
42d ago
Looking for a vulnerability to learn
42d ago
From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk
42d ago
Bad USB through charger?
42d ago
Recommendations for Discord community for latest AI security products
42d ago
Vulnerability Summary for the Week of June 1, 2026
42d ago
Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas
42d ago
I feel like ive lost my passion to tinker after 6 years in the industry, anyone else?
42d ago
I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples
42d ago
really need help with project ideas for MSc
42d ago
Which Course for an almost-complete noob? (SANS.edu)
42d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
42d ago
For the 2nd time in weeks, Microsoft packages laced with credential stealer
42d ago
Iran Signed a Ceasefire — Its Hackers Didn't
42d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
42d ago
DSPM étude marche
42d ago
CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file
42d ago
AppSec / Pentesting job market in Canada for experienced overseas applicants?
42d ago
Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients.
42d ago
Automation Playbooks - which ones would you not want to live without?
42d ago
Is it necessary/important to Hash and salt API Keys for a strictly internal use tool?
42d ago
Need review on the OMS Cybersecurity program from Georgia Tech?
42d ago
If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk
42d ago
2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years
42d ago
How do you close an alert
42d ago
What cybersecurity certifications are great value for money?
43d ago
Boxes for CPENT
43d ago
SIEM: is it "SIM" or "SEEM"
43d ago
I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included)
43d ago
How justdeleteme and justgetmydata work?
43d ago
I need help - PCI DSS 4.0 requirement 11.6.1
43d ago
How are you learning agent pen testing?
43d ago
Cyber security intern
43d ago
Meta to take legal action against Israeli spyware company NSO
43d ago
Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit
43d ago
What's the best way to alert companies of a Glassworm copycat?
43d ago
How To Verify If A Site Is Legit?
43d ago
What is Flaresolverr
43d ago
Research: defenders using generative AI to simulate malware variants before they exist in the wild
43d ago
How are regulated orgs actually letting engineers use Claude Code / Copilot?
43d ago
Cyber security expo Manchester
43d ago
Remote Hiring Opened the Talent Pool — and the Fraud Surface
43d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
43d ago
What certs should I do during summer of 11th grade?
43d ago
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
43d ago
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine
43d ago
Oxford University discloses data breach after careers platform hack
43d ago
Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing
43d ago
Got this message from “SimBoss”
43d ago
PKCS12 Golang fork
43d ago
Malware Insights: Miasma Campaign
43d ago
73 Microsoft GitHub repositories impacted by Miasma malware
43d ago
[Honeypot Research] Looking for volunteers to test telemetry/logs
43d ago
What is the condition of Bug Bounty program in the era of AI.
43d ago
Opening a cloned repo is no longer safe
43d ago
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
43d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
43d ago
Google Colab CLI opens runtimes to Claude Code and Codex
43d ago
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
43d ago
The AI governance gap no one is talking about: deployment-stage accountability
43d ago
Free Study Resources for Comptia Cysa+
43d ago
Mentorship Monday - Post All Career, Education and Job questions here!
43d ago
Hi there
43d ago
Final risk-based IT Audit interview round with Director and have no experience. Please help!
43d ago
Needed help
43d ago
[ Removed by Reddit ]
43d ago
Career advice
43d ago
PhD in cyber Security
44d ago
Built a password guessing game. Almost everyone stuck in level 5.
44d ago
OSINT (SOCIAL MEDIA)
44d ago
Beginner KQL project
44d ago
Question about WORM and encryption
44d ago
Update:Certified cyber security
44d ago
Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental
44d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction)
44d ago
Malware that survives reinstalling the BIOS and OS
44d ago
Am I overthinking the x86 compatibility issues? how much friction am I actually facing?
44d ago
Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure
44d ago
Managing Microsoft Identity Is More Complicated Than It Looks
44d ago
My work email got subscribed to a bunch of israel newsletters
44d ago
Shadow AI
44d ago
Rate limiting is not enough. What else can I use?
44d ago
How To Avoid Potential Malware From Transferring To New Laptop
44d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
44d ago
Can't decide.
44d ago
looking for partners
44d ago
My edge is changing into bing when I search something
44d ago
Cybersecurity reality check
44d ago
[ Removed by Reddit ]
44d ago
Information Management
44d ago
IronWorm Malware
44d ago
Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh?
44d ago
Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh?
44d ago
Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager
44d ago
Is a separate “clean” S3 bucket actually a security boundary for uploaded files?
44d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
44d ago
PenTest+ Exam
44d ago
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
44d ago
Looking for guidance
45d ago
Before you attempt any OffSec certification, read what just happened to me
45d ago
Reporting Metrics for Management
45d ago
got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time
45d ago
Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried
45d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
45d ago
AI Security Certificates
45d ago
Guys is bug bounty dead?
45d ago
How are folks making it in bug bounty?
45d ago
How useful is it to require at least one uppercase letter in a password?
45d ago
Cyber security ! Is no more ?
45d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
45d ago
Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months
45d ago
Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories
45d ago
How to train employees to feel when something's off?
45d ago
ALERT OVERLOAD
45d ago
CTO at NCSC Summary: week ending June 7th
45d ago
A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled
45d ago
Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub
45d ago
AppSec Engineer Interview Stories
45d ago
[OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps.
45d ago
Is there a safe way to continue using (unsupported) Windows 10?
45d ago
Is Splunk suitable for smaller Enterprises?
45d ago
Has anyone else had MFA prompt fatigue issues with users?
45d ago
Data Scrubbing from Databases
45d ago
Best Certificates?
45d ago
Rant
45d ago
New York passes data center moratorium and consumer protections as environmental, and housing proposals stall
45d ago
Cyber attackers have a new favorite, the browser
45d ago
Looking to get into cybersecurity in web3
45d ago
Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests
45d ago
Should i use email 2fa or only auth and phone number?
45d ago
Can I break into cybersecurity with a white collar felony?
45d ago
Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale
45d ago
How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time?
45d ago
What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent?
45d ago
How Hard is This
46d ago
Installed Fake Codex hidden as a google site
46d ago
Virustital scan result help
46d ago
CrowdStrike Turned an AI Wave Into Its Best Quarter Ever
46d ago
Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions?
46d ago
I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now
46d ago
Being a Security Engineer? Which AI-powered tools are you using on a daily basis?
46d ago
Over 900 US gas station tank gauge systems exposed to attacks
46d ago
Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person
46d ago
SIEM is broken in the AI agents era
46d ago
Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected
46d ago
Phantom Gyp npm Worm Abuses node-gyp Build Hooks
46d ago
Certified cybersecurity ISC2
46d ago
Help studying for OSCP
46d ago
The current state of Threat Intelligence Tooling
46d ago
Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware
46d ago
We tested offensive AI agents against deception technology
46d ago
A matter that I have been losing my sleep over
46d ago
Any experience with Rootly or incident.io for cyber incident management?
46d ago
CTIA Study Resources & Preparation Advice?
46d ago
Black hat uk vs brucon
46d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
46d ago
NIS2 hits railway hard
46d ago
I need help guys… :(
46d ago
Question from the Seniors
46d ago
China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware
46d ago
what certs have u seen in ai security related job posts ?
46d ago
How is the Security Architecture / Strategic IT Security process structured in your organization?
46d ago
What's happening in cybersecurity job market in US and Europe these days?
46d ago
Has any of you pivoted from GRC to CTI?
46d ago
Up-date-list of cybercrime types?
46d ago
What else should I learn to build a strong cybersecurity foundation?
46d ago
Hackerone interview
46d ago
Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix
46d ago
Testing URL Rewriting?
46d ago
Got an internship in IAM with no qualifications and no soft skills
46d ago
Work Hours of DFIR/Cloud Security vs Pentest
46d ago
Narcissistic Tech Leader....
46d ago
Anyone else's firewall logs just explode after midnight?
46d ago
I'm replacing myself.. at least the boring parts
46d ago
Anyone else dealing with these phantom login attempts from China?
46d ago
Best way to fully clear windows and set everything up securely (pc, accounts etc)
46d ago
IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks
46d ago
Soc analyst
46d ago
Do companies actually require cybersecurity insurance
46d ago
Uncommon/Unusual CrowdStrike Alerts
46d ago
Cyber analyst: law firm or bank
46d ago
best free av and how do i properly setup passwords?
46d ago
Five 9 Vulnerability
47d ago
CVE Lite CLI closes dependency gap — but won't stop modern threats
47d ago
Scope change
47d ago
We just stopped a social engineering attack on our service desk. Here’s how it played out.
47d ago
What is the most underestimated cybersecurity risk right now?
47d ago
Update: Company is paying for any certification, which should I obtain? Except Sans
47d ago
New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification
47d ago
Anyone else's firewall vendor docs a total nightmare?
47d ago
Your opinions about a learning style
47d ago
Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks
47d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
47d ago
Anyone else see their firewall logs just explode after a cloud update?
47d ago
Are certifications necessary to get a job in cybersecurity?
47d ago
Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass)
47d ago
Is retyping and translating textbooks too inefficient for CS/Cybersecurity?
47d ago
Free Microsoft Enterprise Security Assessment: Worth It
47d ago
How are organizations preparing for AI-generated phishing attacks?
47d ago
Inside the race to adapt to an AI-powered security world
47d ago
127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For
47d ago
Microsoft blames unexpected Windows driver updates on caching issue
47d ago
Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance)
47d ago
Your CPU model leaks through the browser via WASM timing differences
47d ago
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
47d ago
Security Engineer 2 interview at Amazon coming up - What to expect?
47d ago
A researcher spent $1,500 testing if LLMs could hack a vulnerable app
47d ago
Help with university internship
47d ago
Are MCP servers becoming the next API security nightmare?
47d ago
What's the cybersecurity lesson you learned the hard way?
47d ago
ISO 27001 Surveillance audit vs Full recertification
47d ago
How important it is to get paid Cybersecurity certificates ?
47d ago
Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process
47d ago
Soc to Architecture
47d ago
Does "example file vulnerability" exists?
47d ago
VS code forces 2 hour cool down for most integrations.
47d ago
Company laptop isolated after Brave/Tor alert - should I be worried?
47d ago
Does anyone know how to send false positive to SOCradar ? virus total
47d ago
Looking for people to team up for Bug Bounties & CTFs
47d ago
Signal Without Smartphone
47d ago
I found a trojan on my pc and now im scared my private calls got leaked
47d ago
Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests
47d ago
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
47d ago
How do you change users behavior through awareness training?
47d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
47d ago
Safe Rust API for wolfSSL/wolfCOSE
47d ago
Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma)
47d ago
AMD GPU Users might be compromised
47d ago
[ Removed by Reddit ]
47d ago
Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information
47d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
47d ago
[CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF
47d ago
how to get good at cyber security?
47d ago
Anyone use CrunchAtlas?
47d ago
Prompt monitoring laughs
47d ago
Malicious Payload in ai-sdk-ollama npm Package
47d ago
Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24)
47d ago
what the HELL is dsztfso?
47d ago
Yubikey Alternative....?
47d ago
Hiring
47d ago
CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing
47d ago
Certification Advice
47d ago
Question about Linux kernel TLS ULP disclosed June 2 to oss-security
47d ago
An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this?
47d ago
How to Rob a Data Center (new article on data center physical security)
47d ago
US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server
47d ago
Is it worth taking the EC councils masters program?? Are they legit /2026
47d ago
Mid-level AppSec engineers: what do you actually study to prep for interviews?
47d ago
Company is paying for any certification, which should I obtain?
47d ago
Trusting Microsoft with your offensive security repos
47d ago
Automated Fault Injection Attack Framework
47d ago
Physical Biometric device as a security measure..??
48d ago
Cybersegurança
48d ago
Started Learning Cybersecurity
48d ago
InfraGard Application - Seeking Help | Student
48d ago
Orientación en Ciberseguridad
48d ago
Anthropic's coordinated vulnerability disclosure dashboard
48d ago
Hands Free: What LLM Driven Vulnerability Research Looks Like
48d ago
Real time Cybersecurity failures regarding Quantum computing/cryptography
48d ago
🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It.
48d ago
A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out.
48d ago
CISA warns of active attacks exploiting Android, Linux bugs
48d ago
Found some open ports on a govt site, should i report or stay quiet?
48d ago
What is a good way to keep track of passwords for programs that don't support password managers?
48d ago
Cybersecurity statistics of the week (May 25th - May 31st)
48d ago
ASN Emissions Index. Networks ranked by how much noise they create on the internet.
48d ago
Have you sold cve before?
48d ago
i want to become a pentester, but i don't know how to
48d ago
The OT Security Problem Nobody Wants to Own
48d ago
Don't Take Wednesday Off When You Manage Vulnerabilities
48d ago
I finally finished a production version after 4 yrds
48d ago
Support role pivot to cloud security
48d ago
How do you manage your passwords?
48d ago
Mad rush to produce AI driven slop
48d ago
O Tails é seguro para acessar links suspeitos?
48d ago
Cyber Essentials plus + "legacy" network segments
48d ago
Insight for OPSWAT deep CDR
48d ago
Android vs iOS
48d ago
ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account
48d ago
Security Audits at an MSP
48d ago
[ Removed by Reddit ]
48d ago
Passkey registration breaks after moving off localhost..
48d ago
Does your team hire fresh AI engineer who doesn't know anything about Security operations?
48d ago
UARs for Equation (banking system)
48d ago
IoT pentesting cert
48d ago
Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations
48d ago
Experience with Tac Security
48d ago
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
48d ago
Found Security Vulnerabilities in my university website
48d ago
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence
48d ago
AI - Threat to the CyberSec Industry?
48d ago
Built a honeypot platform to catch lateral movement. How are you guys detecting this?
48d ago
How should small SaaS teams safely answer customer security questionnaires?
48d ago
Can AI Do Intelligence Analysis? Apparently Not.
48d ago
PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model
48d ago
Regarding Certified Ethical Hacker (CEH Practical) exam
48d ago
Asking for advices on pursuing first CERTIFICATE
48d ago
I opened my own company and I can't find clients!
48d ago
ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter
48d ago
Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU?
48d ago
Anyone knows Quad9 dns ?
48d ago
I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ?
48d ago
Greynoise swarm
48d ago
SecOT+ certification for free
48d ago
How is the state of the job market for mid-level security engineers?
48d ago
Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things
48d ago
WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total
48d ago
Laid off from TPRM job - need help on the future of my career
48d ago
Anyone compared RoboShadow vs ConnectSecure for vulnerability management?
48d ago
Any one send vulnerability to MITRE?
49d ago
Need advice for a 30 min Security Apprenticeship interview
49d ago
UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS
49d ago
Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match
49d ago
Virustotal API as private data source
49d ago
Account Number Security Flaw
49d ago
Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning?
49d ago
A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth
49d ago
[ Removed by Reddit ]
49d ago
[ Removed by Reddit ]
49d ago
Phishing simulation platform
49d ago
Just task about OSI model
49d ago
Need help improving DNS Spy from a security tool angle
49d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
49d ago
Oracle's first monthly patch update just dropped 77 CVEs.
49d ago
Cleaning up after a legacy service account breach. How are you handling automated secrets discovery?
49d ago
Airbus digital apprenticeship
49d ago
Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities
49d ago
Google fixes one actively exploited Android zero-day, 124 flaws
49d ago
Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force
49d ago
Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis?
49d ago
Security Architects who who actively use modelling - What's your approach?
49d ago
PAN-OS authentication bypass bug added to list of exploited vulnerabilities
49d ago
I have extreme anxiety about being hacked
49d ago
Fresher
49d ago
Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach
49d ago
Career advice needed!
49d ago
GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
49d ago
Google sr. security engineer interview
49d ago
Is offensive AI actually changing cybersecurity, or are we overestimating the impact?
49d ago
Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave
49d ago
is emerald chat safe?
49d ago
Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ?
49d ago
ClickJack in the wild
49d ago
Thoughts on A.I assisted Malware Analysis?
49d ago
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
49d ago
What articles do you use for cybersecurity news? (2026)
49d ago
Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider?
49d ago
Roadmap and Training Recommodation
49d ago
Les anti-triche de niveau noyau et leur risque de sécurité
49d ago
Asked to Send Sensitive Documents via MMS
49d ago
SC-200 compared to CC (isc2)
49d ago
Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now
49d ago
Looking to move off KB4, what are people actually using these days?
49d ago
Got my Security+. What's next?
49d ago
Vulnerability Summary for the Week of May 25, 2026
49d ago
Malware
50d ago
Alternative Search Engine to Utilize in 2026?
50d ago
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
50d ago
Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild
50d ago
Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers
50d ago
AI compliance
50d ago
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
50d ago
Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains?
50d ago
MacBook or Windows Laptop for Cybersecurity
50d ago
What's the most creative MFA bypass you've seen?
50d ago
Research Notes from Building a Windows Event Log Hunting Workflow
50d ago
How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ??
50d ago
Free AI tools for TPRM?
50d ago
incomplete phone number from togo, need help reporting to police
50d ago
NPM packages from RedHat Compromised
50d ago
Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts
50d ago
SOC Analyst working towards Threat Intelligence
50d ago
Is XSS possible through PDFs?
50d ago
The Next AI Governance Failure Won’t Be the Model
50d ago
Microsoft MFA Is Down Again
50d ago
Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927)
50d ago
Computer logic or Science
50d ago
I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for?
50d ago
What C2s Are You Using
50d ago
PNPT Exam
50d ago
What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification?
50d ago
Any appsec engineer working in fortune 500?
50d ago
I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next
50d ago
Anyone transition from AWS Data Center Operations to InfoSec?
50d ago
I think my account got hacked but it's weird
50d ago
current market for detecting deepfakes?
50d ago
Worried about friend being doxxed on doxbin
50d ago
how to shift from a service based company to a product based one in cybersecurity ?
50d ago
Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA
50d ago
Claude AI user data directory exfiltration via malicious npm package
50d ago
Bitdefender blocking amd stuff? False positive or?
50d ago
Mentorship Monday - Post All Career, Education and Job questions here!
50d ago
did they have my password?? what triggers this specific email??? instagram HELP.
50d ago
ATTENTION: Dashlane may have been breached. (Password manager).
50d ago
Norton blocked a “malicious script”?
50d ago
Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts
50d ago
Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive.
50d ago
I wrote about the 5 biggest threats in 2026, curious what this community thinks.
50d ago
MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce?
50d ago
Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions?
50d ago
NetworkChuck
50d ago
LLM for creating phishing tool
51d ago
Why are we still treating IAM like a compliance checkbox?
51d ago
Polyfill pop up?
51d ago
SecAI+ difficulty question
51d ago
Could you guys give an honest feedback to a completely automated ssrf attack tool?
51d ago
tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me
51d ago
Microsoft Joined the DMARC Club
51d ago
Help.
51d ago
Vibe Coding Security
51d ago
Looking for a Company to Partner With
51d ago
Best reporting tools?
51d ago
What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months)
51d ago
How Can Polyfill.io Still Act Maliciously?
51d ago
Need THM voucher code for cheap? Any known seller?
51d ago
Ghost passwords?
51d ago
Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not.
51d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
51d ago
Anyone else having Chatgpt Strikes / Violations while learning cybersecurity?
51d ago
Working at Cisco, worth it?
51d ago
Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice
51d ago
Are you pen testing AI Agents?
51d ago
Question of android malware
51d ago
External attack surface: how are you correlating DNS, SSL, and IP reputation today?
51d ago
how do i properly setup 2fa and bitwarden?
51d ago
Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC)
51d ago
i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested?
51d ago
Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever?
51d ago
Can Steam Cloud Files Transfer Malware
52d ago
Questions for the cloud security engineers
52d ago
Thoughts on this as a starter and doing bug bounty on the side
52d ago
How are new SC-200 candidates practicing labs without an E5 Developer tenant?
52d ago
Getting OTP spammed from every app and website I've ever used. Should I be worried?
52d ago
A browser tool for checking contractor insurance certificates
52d ago
Am I getting screwed?
52d ago
SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers
52d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
52d ago
CTO at NCSC Summary: week ending May 31st
52d ago
BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship
52d ago
Need suggestion
52d ago
[INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety)
52d ago
Was Dave Bittner interviewing an AI?
52d ago
CTF for complete beginner
52d ago
Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques?
52d ago
AI-Era Cyber Risk Standards
52d ago
BEC Victim - Attacker replied inside a real email thread using a lookalike domain
52d ago
Question for those who transitioned from remote to work from anywhere
52d ago
Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors
52d ago
Do you enjoy what you do or do you wish you could go back in time and change it?
52d ago
Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber?
52d ago
For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year?
52d ago
Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ?
52d ago
Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years?
52d ago
Botnet of more than 17 million devices dismantled
52d ago
Exposed credentials on logs
52d ago
What do you think is the biggest cybersecurity risk for small businesses in 2026?
53d ago
Wanted to shift to cloud security, but have some questions
53d ago
Zero Trust is Overrated? Navigating the Complexity
53d ago
Test API post with flair
53d ago
Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications
53d ago
How Do You Handle the Massive Amount of Information in the CPTS Path?
53d ago
Help an upcoming cybersecurity engineer!
53d ago
Repeated Microsoft MFA attempts even after password change
53d ago
What Is Device Intelligence and How Does It Stop Fraud?
53d ago
[FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE)
53d ago
IBM commits $5 billion to secure open-source software
53d ago
Structuring an AI-Assisted Pentesting Homelab for a Final Year Project
53d ago
Are teams actually monitoring LLM traffic in production environments?
53d ago
How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA)
53d ago
Raspberry pi
53d ago
What is the biggest obstacle to using AI safely in a company?
53d ago
Advice going forward
53d ago
MCP Firewall help
53d ago
I wanted to shift to security but people told me the market is extremely bad, is that true?
53d ago
Best Personality Type/Traits for Working in Cyber Security
53d ago
A fake freelance job interview almost installed malware on my PC
53d ago
Is there a viable career path here or am I just being delusional?
53d ago
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
53d ago
How do enterprises actually prevent developers from exfiltrating source code?
53d ago
I have a datastealer malware
53d ago
Dúvida de carreira.
53d ago
Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace
53d ago
Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated
53d ago
is SIEM really needed here ?
53d ago
Decompiled an app, found a bunch of secrets, what now?
53d ago
Can someone give me a correct method for learning reverse engineering?
53d ago
Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months
53d ago
GRC Advise
53d ago
[ Removed by Reddit ]
53d ago
Did something happen to haveibeenpwned? Any alternatives?
53d ago
RAT SUSPECTED
53d ago
How do people afford certificate s?
53d ago
I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed?
53d ago
Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
53d ago
Phone Forwarding
53d ago
Opinions on running Full Microsoft E5 Security Stack
53d ago
Claiming "XDR"
53d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
53d ago
Microsoft security
53d ago
Need help regarding building a home lab
53d ago
Should I turn on passwordless accounts for all my Microsoft accounts?
53d ago
Transitioning from AWS Data Center Operations to Security Engineering
53d ago
Probably the wrong place.
53d ago
What after IT helpdesk?
53d ago
How are you security-testing API changes before production without slowing CI/CD?
53d ago
Are we trusting update repos or are you all extra paranoid now as well?
53d ago
Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops
53d ago
Prevent supply chain attacks
53d ago
Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems
53d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
53d ago
Hackers are trying to steal Signal users' backups in new wave of phishing attacks
53d ago
Incident Response Testing Preparation
54d ago
Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference
54d ago
[Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥
54d ago
3rd Party NFC cards.. secure?
54d ago
Vulnerability Management Tickets & SLA
54d ago
Defending at Machine-Speed: Building AI Threat Readiness
54d ago
AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved
54d ago
HEAD request body processing leading
54d ago
Malicious npm Package Stole Files From Claude AI User Directory via GitHub
54d ago
Does anyone have an app like substack to keep being updated and engaging within the cyber domain?
54d ago
What’s an attack vector people massively underestimate in 2026?
54d ago
We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7
54d ago
A Deeper Look at GLASSWORM's Solana Variant
54d ago
Calling Cyber Security Beginners
54d ago
Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis
54d ago
built something for ai agents, ended up looking a lot like classic appsec
54d ago
Is Gophish still usable in 2026?
54d ago
Microsoft vs Chaotic Eclipse: three zero-days now actively exploited
54d ago
what do you think
54d ago
Why would be clicking a website, redirect me?
54d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
54d ago
Writing cybersecurity policies is a waste of time
54d ago
Raising the Cybersecurity Stakes: Ante up for the Agentic Era.
54d ago
Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it.
54d ago
[ Removed by Reddit ]
54d ago
Released: Dataforge Honeypot
54d ago
Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
54d ago
CEH-free
54d ago
Hottest cybersecurity open-source tools of the month: May 2026
54d ago
Preparation tips for CPENT
54d ago
How do you handle AI tools in your organization?
54d ago
I think i got scammed anybody can help me with that
54d ago
New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo
54d ago
Is it safe to have passwords copied to clipboard on IOS temporarily?
54d ago
Developers working on anti-fraud systems deserve more credit
54d ago
My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst
54d ago
Security awareness training for AI heavy smb workflows?
54d ago
Minimum Requirements for Helpdesk Role ?
54d ago
Reddit spear phishing
54d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
54d ago
What to do
54d ago
What resources would you recommend for studying cysa+
54d ago
Provenance of Data
54d ago
Websites have a new way to spy on visitors: analyzing their SSD activity
54d ago
12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal?
54d ago
Russian Art Teacher - Hinder Security Clearance?
54d ago
EDR/MDR Vendor Questions
54d ago
Cybersecurity as a Highschooler?
54d ago
New department created, would love your input
54d ago
OWASP Vienna - anyone going?
54d ago
Interview with Upstart
54d ago
18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber.
54d ago
Is cloud security engineer viable with my current position?
54d ago
Cloudflare Access users: what would actually make JIT useful for you?
55d ago
eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels
55d ago
Questions regarding Ubuntu 24 LTS hardening
55d ago
Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho.
55d ago
Honest question about OT Security Engineer work life in India
55d ago
Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning)
55d ago
AI Security
55d ago
Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor
55d ago
🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents
55d ago
Building Detection Engineering on AWS from scratch — roast my plan
55d ago
Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance
55d ago
I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA.
55d ago
Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning
55d ago
Final Year Project: Looking for non-generic IAM project ideas that solve real problems
55d ago
GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled.
55d ago
Breaking out of IT Helpdesk - how?
55d ago
A year in Cybersecurity — Where Do I Go From Here?
55d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
55d ago
22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber
55d ago
FBI: Silent Ransom Group Turns to IT Support Ploy
55d ago
How do machine builders track Siemens/Rockwell security advisories?
55d ago
GlassWorm Developer Supply-Chain Botnet Takedown
55d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
55d ago
Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV
55d ago
Got cybersec work what next ?
55d ago
Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables
55d ago
Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers
55d ago
Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing?
55d ago
GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)
55d ago
nightmare eclipse is probably French here is why
55d ago
Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines
55d ago
Measuring performance of JA4/JA4H AI Model
55d ago
What things are you really focused on this year?
55d ago
Hypothetical EDR spoofer
55d ago
ISO 27001 Audit Stage 1
55d ago
Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.
55d ago
Looking for Hacker Friends to Learn☺️
55d ago
Comptes Instagram et Facebook piratés et désactivés
55d ago
How to safely disinfect a USB stick from potential malware files?
55d ago
Is anyone else concerned about how quickly AI is outpacing cloud security?
55d ago
What's a CyberSecurity job like?
55d ago
Microsoft Live credential stuffing
55d ago
I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this?
55d ago
Security architects- summarize your responsibilities and role
55d ago
Finding Work in OSINT
55d ago
State of SDLC Security 2026
55d ago
Reported to police for coding html
55d ago
[Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling)
55d ago
I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project
55d ago
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover
55d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
55d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
55d ago
Breaking GROK'S DEFENSES to make it HACK Real Public Websites
55d ago
GitHub Actions Cache Poisoning is eating open source
55d ago
Nightmare-Eclipse has also been banned on GitLab :DD
55d ago
Do we still have time before we are in the Age of the movie "Minority Report"? ↓
56d ago
SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file
56d ago
What Software Supply Chain, Water Filters, and Power Grids Have in Common
56d ago
QA engineer trying to move into AppSec — does this plan hold up?
56d ago
Is work from anywhere really impossible to find??
56d ago
Cybersecurity statistics of the week (May 18th - May 24th)
56d ago
Engineering a Post Quantum Fortress Inside the Citadel Archite
56d ago
Cyber Security Analyst
56d ago
Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance
56d ago
Two layer email security tool thesis
56d ago
When OTP rate limiting fails: OLX account takeover with persistent sessions
56d ago
Entra ID sessions revoke
56d ago
Anyone who attended GPCSSI before? Need some clarification
56d ago
Lost on my career path.
56d ago
EU-based folks: external pentest vs mandatory data/security training?
56d ago
help needed from experienced people
56d ago
How do you evaluate whether a privacy service is actually privacy-respecting?
56d ago
Which one Intellipaat or coursera which one to choose
56d ago
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
56d ago
India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic?
56d ago
Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs.
56d ago
Did anyone pass the SC-200 certificate recently?
56d ago
Honeypot
56d ago
passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account
56d ago
Career in IAM as a fresher
56d ago
CISA orders feds to patch actively exploited Drupal vulnerability
56d ago
Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure
56d ago
GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
56d ago
Cyber security tool
56d ago
Saw this tool and it has potential
56d ago
🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs
56d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files
56d ago
Follow up : showing Claude install random pacakage in its vm instance without asking or prompting
56d ago
¿Is safe?
56d ago
Need help
56d ago
What is the best tool for masking in kali
56d ago
What are the best tools other than ghostTracker?
56d ago
TrapDoor Cross-Ecosystem Crypto Stealer Campaign
56d ago
Follow up : Steal Your Files Claude AI installing package because internet say so
56d ago
New to Cybersecurity: Looking for general advice & help with Nmap
56d ago
Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal
56d ago
Looking for tech role references
56d ago
How do you balance Paw?
56d ago
I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity.
56d ago
From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security
56d ago
Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February
56d ago
What Companies are Legit?
56d ago
start learning cybersecurity from scratch
56d ago
Follow-up: measuring LLM-agent failures with replay evidence
56d ago
Follow-up: measuring LLM-agent failures with replay evidence
56d ago
WhatsApp users on alert after hacker drops massive dataset
56d ago
17 years old going into CS — what certs should I start going after now?
56d ago
i want to hire an osint expert
56d ago
Open University pros/cons
56d ago
How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection?
56d ago
Career in IAM as a fresher
56d ago
Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo
56d ago
Need Advice
56d ago
Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all?
57d ago
Someone from Germany on iOS keeps trying to login to my MSFT account
57d ago
AI cautionary tale...
57d ago
AI powered red vs blue teaming
57d ago
Starting a security analyst student apprenticeship next week, need advice
57d ago
Why CVE Does Not Work for AI Agents, but AVE?
57d ago
SC-200 or Security+ — which actually helps land a security title
57d ago
How about AI having access to your hard drive.
57d ago
How a Date Tag Hijacks macOS via ExifTool
57d ago
Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools
57d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
57d ago
Built a tiny daily cyber puzzle game during evenings/weekends
57d ago
Crypto4A launches quantum-safe rival to AWS Secrets Manager
57d ago
ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why.
57d ago
Cyber Sec project
57d ago
CySA+
57d ago
Anyone tried Morgancyberhelp ?
57d ago
As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free
57d ago
Why are most of the dfir tools built to be used in windows
57d ago
OnlyFans mega leak reveals 340M user records, hackers claim
57d ago
Perplexity BumbleBee
57d ago
Cisco patches critical 10.0 flaw in Secure Workload APIs
57d ago
Stalker has my phonenumber
57d ago
Need some guidance
57d ago
Are you currently allocating budget to services that remove executive PII from B2B data brokers?
57d ago
About CEHv13 book
57d ago
We open-sourced the most dangerous part of our security startup on purpose.
57d ago
Which conference(s) result in the most people finding jobs?
57d ago
My discord account has been hacked second time even after enabling two factor authentication and resetting password
57d ago
What's the most efficient way to learn cloud governance and compliance
57d ago
Does anyone know C2 framwork and free hosting to host C2?
57d ago
CIS-CAT Assessor for assessment Windows server 2022 and 2025
57d ago
Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this
57d ago
Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks?
57d ago
Recent adoption of AI taught me what is Cybersecurity.
57d ago
The Pentagon Changed the Rules for Cybersecurity Compliance
57d ago
Can someone explain to a noob like me what the implications of this exploit are?
57d ago
SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections
57d ago
Window between zero-day CVE and a patch!
57d ago
Is it risky when a website puts on technology components with versions they used in their website?
57d ago
Anyone else losing their mind over this "AI Cybersecurity" hype?
57d ago
URL parsing behavior in a canonical tag lab
57d ago
Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you?
57d ago
Any tips for me pls
57d ago
How do you minimize legal liability as a solo contractor?
57d ago
How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing?
57d ago
Mentorship Monday - Post All Career, Education and Job questions here!
57d ago
Provenance: A survival toolkit for an AI dominant information landscape
57d ago
[ Removed by Reddit ]
57d ago
Active Drupal SQLi exploitation is a real „patch now“ moment
57d ago
machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native)
57d ago
Need suggestions and input; not a promotion
57d ago
Need advice!
57d ago
New Zealand is becoming a focal point for AI-driven superhacking threats.
58d ago
nmap on Linux: Guide to Network Scanning and Discovery
58d ago
TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle
58d ago
How would Phishing look like in the future? (targeting agents, not humans)
58d ago
Best beginner/intermediate book for system security (blue team / defense / audits)?
58d ago
Why is on-prem and air-gapped asset inventory still such a mess?
58d ago
keep getting MS authentication sign in attempts?
58d ago
Silly issue
58d ago
How to practice cybersecurity while studying prograaming ?
58d ago
[AI Security] Exploring Behavioral AI for Runtime Threat Detection
58d ago
Podman and krun: is it pointless to harden quadlets?
58d ago
How to handle security researchers (and firms) without a bounty program?
58d ago
Product analytics is becoming a third-party breach surface
58d ago
How can i learn and get into red teaming?
58d ago
Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network
58d ago
I got hacked
58d ago
Soc analysts in big companies, how it looks like?
58d ago
CTO at NCSC Summary: week ending May 24th
58d ago
These special phone and app features can help protect you from spyware
58d ago
Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button?
58d ago
Capcha Code Malware
58d ago
getting lost when hunting
58d ago
How to find information behind an account?
58d ago
Theoretical Design Concept for Post-Exploitation Browser Defense
58d ago
Google Certifications...
58d ago
How to continue when finding a possible Vulnerability but local law prohibits me from investigating further
58d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
58d ago
Is the CISSP still a reputable cert for getting jobs?
58d ago
Which of these gоv roles would fare better in the private sector?
58d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
58d ago
Mapping binaries to EDR feature spaces
58d ago
Lost my number + WhatsApp account — worried about old chats, photos, and videos
58d ago
what is the most painful or time-consuming part of your work right now?"
58d ago
Anthropic says Mythos has already found more than 10,000 vulnerabilities
58d ago
What is the experience needed for “entry level” cybersecurity jobs?
58d ago
Browser extension testing.
59d ago
Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip?
59d ago
Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback
59d ago
Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition
59d ago
Can someone recommend me some good, large universities to study cybersecurity?
59d ago
New guy khikhi
59d ago
Examples of intentional backdoors being breached?
59d ago
Non-Compliant Vocab
59d ago
Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites
59d ago
infostealers just spawned a 5,000+ repo github supply chain attack
59d ago
The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis
59d ago
GRO frag
59d ago
We audited 12K n8n templates: most have critical vulnerabilities
59d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
59d ago
Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week
59d ago
Mitigated Vulnerabilities by Vendor as Feed
59d ago
Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors
59d ago
A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories
59d ago
Where can I find the tools freely on internet to practice for soc analyst
59d ago
residential proxies
59d ago
Recommendations for getting started in cybersecurity
59d ago
Linux mint or Ubuntu for complete beginner
59d ago
Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world.
59d ago
Pentesting company recommendation
59d ago
Have you ever failed a certification exam?
59d ago
AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance
59d ago
What do i need to learn to get into application security? Which Degrees/Certs
59d ago
RSAC online membership? Is it worth it?
59d ago
Can someone give me a detailed roadmap for becoming a SOC Analyst?
59d ago
Puedo conseguir trabajo?
59d ago
How do i learn networking for cyber security?
59d ago
What's going to be Hacking and Cybersecurity's future is gonna be like?
59d ago
Cyber security placement - Interview Help
59d ago
Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge
59d ago
Feedback needed
60d ago
Handoff Transition
60d ago
Just added an interactive security map showing exactly what the server sees (and doesn't)
60d ago
Trend Micro warns of Apex One zero-day exploited in the wild
60d ago
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
60d ago
https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/
60d ago
Harvard and 140 other legitimate websites compromised
60d ago
Votre Satisfaction Dans Votre Travail
60d ago
5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit.
60d ago
US states urge Congress to renew cybersecurity grants
60d ago
The CISO's Guide to IDE Security in 2026
60d ago
Help with evilginx
60d ago
Watching AI Brain Drain on Attackers in Real Time
60d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
60d ago
api-rta cyberwarfare labs
60d ago
Does Security Implement Fixes?
60d ago
Ultimate Cybersecurity without needing AV ect?
60d ago
User Onboarding with IAM
60d ago
pnpm 11 Might Finally Be a Better Default Than npm
60d ago
14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs
60d ago
Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria
60d ago
Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip"
60d ago
Looking for a cybersecurity professional to interview for a university project (interview in French)
60d ago
Safe read-only check script for Copy Fail / CVE-2026-31431
60d ago
New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible?
60d ago
[TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly
60d ago
Cisco used AI to write security incident reports, with mixed results
60d ago
[TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM)
60d ago
Cyber Insurance Actuary Looking for Educational Resources
60d ago
As a bank , how do i give protected access to claude to my team?
60d ago
Can seasonal Apple Store employees apply for internal IT/cybersecurity roles?
60d ago
Reliable IP reputation check tools besides IPQS?(for work)
60d ago
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026)
60d ago
Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins
60d ago
Hacked by Rat Tools for 2.5 years.
60d ago
Google API Keys Remain Active After Deletion
60d ago
how do cyber sec consultants and pentesters actually get new clients?
60d ago
Post Incident Paranoia?
60d ago
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
60d ago
Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity?
60d ago
Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready
60d ago
You can counter MEMZ with Krotten in XP
60d ago
What are the most effective ways to do Blackbox testing?
60d ago
Npm registry sets stage for more secure package publishing
60d ago
Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support
60d ago
Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK
60d ago
Is the Cybercorps SFS still worth it?
60d ago
Microsoft warns hackers are exploiting password resets to gain access to user accounts
60d ago
Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame
61d ago
WORM USB drives
61d ago
An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model?
61d ago
CISOs - Holding the Line
61d ago
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
61d ago
Security Scroll Down?
61d ago
mass github repo backdooring via CI workflows(Megalodon)
61d ago
Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit?
61d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
61d ago
DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind
61d ago
FaceTec (ID verification) company appears to store user biometrics
61d ago
CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication
61d ago
It seems that FaceTec (ID Verification company) allows for storage of user biometrics
61d ago
Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check.
61d ago
Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data
61d ago
What Questions Do You Ask During SSP Control Interviews?
61d ago
Feed The Cat BackDoor
61d ago
Flipper One - Asking for help from the community
61d ago
Flipper One — tech specs
61d ago
Architecture Zero Trust détaillée
61d ago
Cybersecurity in Healthcare
61d ago
Staged publishing for npm packages | npm Docs
61d ago
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though)
61d ago
Neither MFA, Passkey, nor trusted IP help here
61d ago
cyber security remote
61d ago
CSIRT incident response
61d ago
Trying to find a graduate role
61d ago
Microsoft warns of new Defender zero-days exploited in attacks
61d ago
what is the best security app option for pixel8a?
61d ago
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
61d ago
IoT Security
61d ago
GitHub links repo breach to TanStack npm supply-chain attack
61d ago
Another working Linux LPE exploit is out. How are teams treating local-only bugs now?
61d ago
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
61d ago
Google publishes exploit code threatening millions of Chromium users
61d ago
landing a remote Vulnerability Management role
61d ago
Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case.
61d ago
I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting?
61d ago
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
61d ago
What volume of TPRM do you handle per month?
61d ago
safest virtual machine?
61d ago
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration
61d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
61d ago
GitHub notifications
61d ago
Is there no more privacy left in the world?
62d ago
Microsoft Edge had a password blunder, and it raises a bigger browser trust problem
62d ago
Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network
62d ago
Aconselhamento / mini texto
62d ago
CISA with an absolutely embarrassing data leak.
62d ago
Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys
62d ago
Anyone else feeling like static AppSec workflows are starting to hit limits?
62d ago
GitHub breach highlights developer tools as part of attack surface
62d ago
Why do some malware use unique user-agent strings?
62d ago
Encrypted emails bypassing email security tool
62d ago
Ctf groups
62d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
62d ago
Opensource that automatically scans your git repos for breaches
62d ago
CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed.
62d ago
Your developers are deploying agents in your production environment right now. You have no governance for it.
62d ago
¿Como me preparo para EC-Council CSA?
62d ago
The IBM X-Force Index 2026 explains all three in one finding.
62d ago
Securing iPad's question
62d ago
Cybersecurity 101
62d ago
What would this job role be?
62d ago
MSPs & MSSPs suck
62d ago
[ Removed by Reddit ]
62d ago
Crossroads
62d ago
Advice regarding "SOC" job that automates everything
62d ago
Is this Medium article about "NetMirror" malware legit?
62d ago
AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon?
62d ago
Developer tooling is part of the attack surface before a project is even run
62d ago
How the hell do you manage developers, their code, their apps?
62d ago
Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed
62d ago
Do people still rely on antivirus software in 2026, or is built-in security enough now?
62d ago
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
62d ago
Automatic CLI for spinning up vulnerable labs + objectives
62d ago
ISO/IEC 27701 scenario question
62d ago
Discord rolls out end-to-end encryption on voice, video calls
62d ago
GitHub investigates internal repositories breach claimed by TeamPCP
62d ago
Two AI-based science assistants succeed with drug-retargeting tasks
62d ago
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
62d ago
An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now.
62d ago
New to cybersecurity
62d ago
Anyone interview or work with Moxfive?
62d ago
A stealth Firefox version that passes all anti-bot and CAPTCHA
62d ago
mkPIVM - a polymorphic position-independent shellcode virtualizer
62d ago
Started in IT and need a Cybersecurity Roadmap with my Useless Degree!
62d ago
GitHub announces internal data breached.
62d ago
Roadmap to Cybersecurity roles
62d ago
Malware installed without literally doing anything?
62d ago
CTFs
62d ago
Crossroads
62d ago
Canara Bank SuRaksha Cyber Hackathon 2.0,
62d ago
Anti BOT Tipps und Tricks gesucht.
62d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
62d ago
New to Cybersecurity
62d ago
Is the ISC2 Certified in Cybersecurity worth it?
63d ago
Average Days to Close by Source CNAPP Severity Tag 2026
63d ago
I want free nmap resource
63d ago
If I clear browser history regularly, does it reduce the chances of malware that target browser data?
63d ago
What is next after 1.5 Year as Security Analyst?
63d ago
Analysis advice
63d ago
Stop me if you heard this one before... (YellowKey related)
63d ago
Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe?
63d ago
Looking for advice: where should I post/publish CVE write-ups?
63d ago
Cybersecurity statistics of the week (May 11th - May 17th)
63d ago
How can I test my website locally for cybersecurity?
63d ago
Use of coding in security operations
63d ago
Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
63d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
63d ago
I've built an open source honeypot probe database accessible via curl, http and mcp
63d ago
6,000+ Automatic Tank Gauges Exposed With No Authentication
63d ago
Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email?
63d ago
If humans are the weakest link, why won't companies evolve?
63d ago
Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?"
63d ago
Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM
63d ago
Local transcription vs cloud transcription, which actually feels safer?
63d ago
Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today?
63d ago
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise
63d ago
Shai-Hulud source leak is turning npm malware into a copycat problem
63d ago
Framework for Preventing Secret Ideas from Leakage
63d ago
Local LLM for building AI Security platform
63d ago
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
63d ago
Emerging Cyber security niches
63d ago
ISO/IEC 27701
63d ago
Solo dev building a terminal-heavy hacking game inspired by corporate security
63d ago
Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations
63d ago
CS/IT Student Looking to Grow My LinkedIn Network 😃
63d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
63d ago
Is Amazon Cognito a good choice long term? Alternatives?
63d ago
Was hacking easier in the 80s and 90s and early 2000s?
63d ago
Need some Advice in SOAR heavy environment
63d ago
Trying to find serious builders in cybersecurity - not just “let’s build” conversations
63d ago
AI Phishing
63d ago
One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals
63d ago
How easy is it to get into the cyber security field?
63d ago
314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js
63d ago
Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start?
63d ago
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo
63d ago
CEH/CPENT vs OSCP vs GPEN
63d ago
ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro”
63d ago
CISA Contractor Admin Leaked AWS GovCloud Keys on Github
63d ago
Suspecious activity in my account
63d ago
Is it safe to use my first name and middle name on platforms?
63d ago
Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice.
63d ago
Just received an email from shinyhunters about their amtrack hack
63d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
63d ago
Bywaf: an auditable Python commandlet framework for chained pentest workflows
63d ago
For anyone currently working in a SOC:
63d ago
Fellow Tier 1 SOC/Security Analysts - What does your day to day look like?
63d ago
How do you threat hunt for RMM tools in environments where RMM is all over the place?
63d ago
Microsoft - "your single use code" email when it was not requested by yourself
64d ago
Directory of vendor security questionnaires
64d ago
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
64d ago
MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals
64d ago
Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight
64d ago
How is AI affecting the cybersecurity market?
64d ago
MCP security
64d ago
YellowKey Mitigation
64d ago
Anyone else on the receiving end of ShinyHunters extortion email?
64d ago
Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs
64d ago
What’s the biggest mistake people still make about online security in 2026?
64d ago
Anthropic shuts the EU out of its most advanced cyber AI model
64d ago
Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens]
64d ago
Best hotel for attending all three conferences in Vegas?
64d ago
What's your company's actual PQC migration plan? Not the one on paper - the real one.
64d ago
Does buying local cybersecurity (services/products/etc) matter to you?
64d ago
LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose
64d ago
Detection Engineering AI Maturity Framework
64d ago
Microsoft code
64d ago
Microsoft confirms Windows 11 security update install issues
64d ago
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
64d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
64d ago
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
64d ago
Suspicious with a company offer letter
64d ago
Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first?
64d ago
Why do some recovery workflows still require full wallet uploads?
64d ago
Need help with interview for soc l1
64d ago
Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap)
64d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
64d ago
carrer path in cybersecurity for a btech stud
64d ago
Agents usage in production
64d ago
‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K
64d ago
Are teams still finding AI API keys in public repos?
64d ago
Mentorship Monday - Post All Career, Education and Job questions here!
64d ago
Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here?
64d ago
Does the CBP bug phones?
64d ago
What We Learned Building Runtime Visibility for Modern Telco Networks
64d ago
Ive got my Spotify account hacked! How do I solve this?
64d ago
The Politics of AI Transparency
64d ago
A million baby monitors and security cameras were easily viewable by hackers
64d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
64d ago
Is cybersecurity becoming more behavioral than technical?
64d ago
Questions About Promo Items for a Cybersecurity Conference
64d ago
Dois-je m'inquiéter ?
65d ago
I am dying to work abroad , rate my journey so far
65d ago
Microsoft - "Your single use code" email when it was not requested
65d ago
Security / Compliance work going Agentic?
65d ago
Don't believe the media, specially in cybersec
65d ago
Microsoft account keeps getting Authenticator requests?
65d ago
[Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated.
65d ago
Struggling to generate security bulletins — any ideas?
65d ago
Certs to go into Security Engineer/architect
65d ago
18882745552 beware of email with this number
65d ago
Transition from traditional penetration testing into AI security
65d ago
Seeking advice on next career steps
65d ago
Will the analyst role become obsolete?
65d ago
Alert Fatigue
65d ago
Best path into cybersecurity for a high schooler?
65d ago
Keep getting hacked
65d ago
How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices
65d ago
I’m interested in joining the Red Team Hackers Academy in Bangalore.
65d ago
A clueless teenager 💔
65d ago
Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start?
65d ago
Am I overthinking Claude Code security or is this actually a risk?
65d ago
is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this
65d ago
ISO/IEC 27701 ( SoA ) Applicability
65d ago
Security Executive Playbook
65d ago
This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon
65d ago
I feel crazy I hope someone has insight .
65d ago
ΡHANTΟΜ Al-Powered Pentesting Command Center
65d ago
Interview Assessments
65d ago
We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it
65d ago
Questions about data blockers
65d ago
Post Implementation task
65d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
65d ago
Cyber security jobs in Austria
65d ago
Personal favorite deception layer.
65d ago
Estudiar Ciberseguridad
65d ago
Learning way
65d ago
How do you report large volume detections to a CISO without making the BPA report a SOC story?
66d ago
Can anyone share bugbase platform screenshot having professional usage on dashboard?
66d ago
CTO at NCSC Summary: week ending May 17th
66d ago
Security Executive Playbook
66d ago
Tired of tab-switching between CTI tools - here's what we put together
66d ago
I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor
66d ago
In Cybersecurity
66d ago
Anyone else feel like most MSP tooling is either overkill or painfully manual?
66d ago
Thinkpad vs Macbook pro endpoint security
66d ago
Any more affordable alternatives to “IntelligenceX”?
66d ago
Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran
66d ago
tanstack checker github action
66d ago
Drivers Alpha AWUS036AXML
66d ago
Splunk download for free
66d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
66d ago
Anyone here using pager duty?
66d ago
Scammer targeting posters
66d ago
Seeking advice
66d ago
Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026)
66d ago
Just got an email about a single use code, maybe someone was trying to log in?
66d ago
Can a background in DevOps enter the cybersecurity field?
66d ago
Using ai in learning
66d ago
Avanzamento area Blue Team/SOC
66d ago
Please what could be helpful
66d ago
CVE exploit chain
66d ago
What are the widely accepted SaaS security accreditations/audits an app should seek in fintech
66d ago
Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco
66d ago
Major flaw in Indian Cyber and IT assurance landscape
66d ago
Red Team Ops Ⅱ ( CRTL ) exam preparation
66d ago
Recomendations
66d ago
Recommended cybersecurity certification for a UX designer new to the domain?
66d ago
insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server
66d ago
Career path
66d ago
Merit America offers a program that gets you into cyber security roles.
66d ago
Brovan: Binary user-mode emulator for x86_64
66d ago
AmEx Interview!
66d ago
Developer credential-stealing pipeline also collected operator workstations
66d ago
need help building a case.
66d ago
Personal favorite SIEM platform?
66d ago
Cardputer ADV
66d ago
Alternative for Qualys
66d ago
The 4th Linux kernel flaw this month can lead to stolen SSH host keys
66d ago
Stack Buffer Overflow Explained (Using a Classic Doom Bug)
66d ago
Confused about cybersecurity career
66d ago
Transferring from pen test consulting to application security?
67d ago
Curso de especializacion de Ciberseguridad
67d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
67d ago
Lost, tempted to throw in the towel
67d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
67d ago
I open-sourced a Docker security scanner I use to audit all my websites
67d ago
Testing Deception Technique
67d ago
A malware got into my account and spread spam ad to my friends and relatives
67d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems
67d ago
Most pentest reports I review are padded with garbage findings
67d ago
Cyber Essentials and use of third party websites - MFA
67d ago
Rapid 7 and Cisa Kev
67d ago
Anyone know much about MS Defender?
67d ago
EN18031 for IoT: struggling to see the big picture — advice from experienced people?
67d ago
Automating Code Security Reviews
67d ago
New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available
67d ago
AI coding tools on developer machines — looking for input on how you're handling it
67d ago
Chrome 148 Update Patches Critical Vulnerabilities
67d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
67d ago
I need help. i am lost
67d ago
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence
67d ago
Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments
67d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
67d ago
I'm going crazy. At the application level what I can actually do to prevent DDos?
67d ago
Is anyone enrolled in Intellipaat's cybersecurity course?
67d ago
Will AI Replace Cybersecurity Jobs?
67d ago
What's best certification choice after OSWE
67d ago
Facebook Page Call Slipping through Sleep mode
67d ago
ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey
67d ago
New Linux LPE allows local users to read any file, including privkeys
67d ago
A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks.
67d ago
Your experience as IT Admin on Alerts
67d ago
Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time
67d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
67d ago
Discord VC lag Exploit
67d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
67d ago
Bug FB - Inicio de sesion por password
67d ago
Does anyone know how to configure EVILGINX for testing
67d ago
How long does it take to get familiar with a tool
67d ago
Scam website
67d ago
ANTS Hack: 19 million records exposed in French ID agency breach
67d ago
Is it really that easy to obtain SMS codes using an SS7 attack?
67d ago
AI coding tools are shipping code faster than security can review it. What's your team doing about it
67d ago
Interview for AI security engineer position at a fortune 500 company
67d ago
How’s the job market for Senior AppSec Engineers? How are the interviews?
67d ago
Has anyone read "The Art of Deception"? How does it hold up to now?
67d ago
Is metadata protection becoming more important than traditional endpoint security for ordinary users?
67d ago
Zero trust in hybrid environments - what's actually worked for you
67d ago
Have you encountered issues with CSAF advisories in practice?
67d ago
Zero trust in hybrid environments - what's actually working for you
67d ago
OpenAI confirms security breach in TanStack supply chain attack
67d ago
Bachelors Degree Options
67d ago
I need help protecting my privacy
67d ago
Free Threat Intellegence
67d ago
What discovery in cybersecurity amazed you the most?
67d ago
Scholarship for Service
68d ago
For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons?
68d ago
Another day, another supply chain
68d ago
How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs?
68d ago
Teaching Linux+ & CEH.....
68d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
68d ago
SIEM use case development
68d ago
JFrog vs Mend as Scanners
68d ago
KQLab - open-source query manager for SOC teams
68d ago
Which Vendors Publish the Best (or Worst) Security Advisories?
68d ago
Synthetic training data vs. real attack telemetry — does it actually matter?
68d ago
Operative IT-Sicherheit | SIEM & Splunk
68d ago
SOC not for junior level?
68d ago
Cybersecurity at MSG
68d ago
pii-tools.com reputable?
68d ago
Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise
68d ago
Contract jobs worth the risk?
68d ago
HackTheBoxAcademy vs LetsDefend vs CyberDefenders
68d ago
Automating code security reviews with Claude: near Mythos-level capabilities at lower cost
68d ago
Making Right Career Decision?
68d ago
I tried using apparmor (linux security) but it doesn't seem to work very well
68d ago
Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything!
68d ago
Struggling to Stay Up to Date With Vulnerabilities
68d ago
How to Transfer files Safely from a Compromised (work) Device
68d ago
Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward
68d ago
Multiple data breaches in one week
68d ago
How are small security teams handling vulnerability overload now?
68d ago
Concerns mount that EU will demand age verification for VPNs
68d ago
Automating code security reviews: Claude Mythos-level capabilities with lower cost
68d ago
The Rare Patch: A Digital Sovereignty Challenge
68d ago
Advise
68d ago
GRC
68d ago
Admins and Engineers
68d ago
Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark
68d ago
Prompt injection in browser coding agents is the threat model nobody is ready for
68d ago
New Fragnesia Linux flaw lets attackers gain root privileges
68d ago
Transition from MSP to Network Engineering?
68d ago
So called “off grid” method
68d ago
Convince me I’m not paranoid: a unique hacking situation.
68d ago
Hunting the Behavior Behind npm Supply Chain Attacks
68d ago
Question for AppSec Members
68d ago
Beginners guide to Google Dorks by Heisenberg
68d ago
Alguém sabe algo sobre raven eye technology
68d ago
Gophish Porject - Requirement
68d ago
Security Team Won’t Assess Risk
68d ago
Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework
68d ago
Microsoft’s new multi-model agentic security system tops leading industry benchmark
68d ago
Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
68d ago
Overwhelmed on how to enter the job market.
68d ago
Social media scam bill targets tech giants as New Yorkers lose billions
68d ago
What are the biggest technical & cultural hurdles you’re facing right now?
68d ago
CISSP / CCSP training - Experienced engineer
68d ago
Vulnerability in Canvas/Instructure Support Tickets had part in breach?
68d ago
is malwarefox legit?
68d ago
what lab to learn zero trust?
68d ago
Anyone else got a bunch of emails leaked by Samsung?
68d ago
This is what some the world's largest banks of malware look like stacked as hard drives
69d ago
I need feedback on my project please
69d ago
would like to understand the role of "Cyber Insurance UnderWriters"
69d ago
Free on-device tool for monitoring AI traffic on macOS — visibility before policy
69d ago
Is secure evidence handling and controlled derivative file sharing needed?
69d ago
Will Adding Some Certifications Help Me in the Job Market?
69d ago
Linux driver posted for Intel Silicon Security Engine Interface "ISSEI"
69d ago
Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified?
69d ago
Fragnesia made public as latest Linux local privilege escalation vulnerability
69d ago
HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity?
69d ago
NIST is surrendering to the amount of CVEs coming in
69d ago
Military Veteran looking to get into the Cyber Field
69d ago
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
69d ago
Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook.
69d ago
Cve apis for a database
69d ago
Empresas de Cyberseguridad en Mexico (Reacciones)
69d ago
Joined a new company: GRC landscape advice
69d ago
Removing admin rights
69d ago
a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access
69d ago
FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow
69d ago
Golden years for cyber security about to start?
69d ago
A stealth approach to Process Injection - EntryPoint Hijacking
69d ago
Detecting CopyFail and DirtyFrag by thinking outside the box
69d ago
Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security
69d ago
Career advice
69d ago
The exponential rise of economic damage caused by cyber-crime continues
69d ago
Today's cybersecurity systems are not ready for AI
69d ago
Are certifications worth it, or do practical skills matter more?
69d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
69d ago
Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed
69d ago
Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft
69d ago
What to do after security+
69d ago
AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data
69d ago
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
69d ago
Is it realistic to move from Tech Risk/GRC into technical cybersecurity?
69d ago
Are IPhone autofill passwords safe to use?
69d ago
Access approvals happen over Slack dm and I don't know how to present that to an auditor
69d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
69d ago
China is going dark to develop its own Mythos, German cyber chief fears
69d ago
Is prompt injection a real problem for you?
69d ago
New Exim BDAT bug shows why “just patch the mail server” is still not simple
69d ago
Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach
69d ago
Cybersecurity guide
69d ago
[Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ?
69d ago
How you guys rate Google Cyber security course and certificate out of 10 !?
69d ago
Cyebrsecurity Startup Advice
69d ago
Can anyone give a real world based AI based attack?
69d ago
How worried should we be about AI powered cyberattacks?
69d ago
Built STIS-ICS — an open ICS/OT security learning project
69d ago
OS scanner that checks repos for traces of the Shai Hulud worm
69d ago
Foxconn Ransomware Attack Shows Nothing Is Safe Forever
69d ago
Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries
69d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
69d ago
Explorer shows random letter/number filenames before copying my actual files — normal behavior?
69d ago
Zscaler AI Security Capabilities ?
69d ago
Cybersecurity degree
69d ago
Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma
69d ago
Cyber security
69d ago
New York Senate takes on junk fees, digital subscriptions, surveillance pricing
69d ago
Cybersecurity statistics of the week (May 4th - May 10th)
69d ago
Feels like AI changed the speed of attacks more than most companies want to admit
70d ago
Anyone used Kasm or ReplicaCyber?
70d ago
Škoda warns of customer data breach after online shop hack
70d ago
Google launches new Android security feature to help uncover spyware attacks
70d ago
Fancy Bear: Stealing Credentials Invisibly
70d ago
Nightmare Eclipse has published Greenplasma and YellowKey
70d ago
Copilot Agent
70d ago
What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles?
70d ago
Career Advice
70d ago
Anyone else exhausted by the nonstop AI hype?
70d ago
Reviewing the trends in ransomware attacks in 2026
70d ago
Is It a Good Idea to Change Jobs Shortly After Getting Hired?
70d ago
SSO makes life easier but MFA keeps it safe, do we actually need both?
70d ago
Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours?
70d ago
How are SOC teams actually deciding what not to investigate anymore?
70d ago
Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily
70d ago
Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released.
70d ago
Has anyone tryed this out yet?
70d ago
The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..)
70d ago
Switching to Cyber
70d ago
Nitrogen ransomware group claims Foxconn after Wisconsin plant outage
70d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
70d ago
Using Cape Sandbox for Phishing Analysis
70d ago
Canvas hack: company pays criminals to delete students' stolen data
70d ago
i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning.
70d ago
AI integrations are quietly creating a new OAuth supply-chain problem
70d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
70d ago
UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships
70d ago
Hardcoded secrets in Git
70d ago
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
70d ago
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
70d ago
New ipTIME Pre-Auth RCE in CWMP
70d ago
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
70d ago
Is my phone hacked?
70d ago
Switched to a grc role after a year in SOC L1
70d ago
Forecasting Lazarus Crypto Heists
70d ago
Infrastructure Security Incident Update & FAQs
70d ago
Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages
70d ago
In Depth Guide To VM Based Obfuscation - What it is and how to handle it.
70d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
70d ago
Transitioned to GRC
70d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
70d ago
German cybersecurity official warns China is close to developing AI superhacker
70d ago
Google Detects First AI-Generated Zero-Day Exploit
70d ago
“DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance
70d ago
Instructure/ canvas paid the ransom?
70d ago
Troca emprego - big para consultoria ou fintech - Pentester/Red Team
70d ago
Finally, texts between Android and iPhone users can be end-to-end encrypted
70d ago
Official CheckMarx Jenkins package compromised with infostealer
70d ago
IMF warns of the potential for AI attacks on global financial systems
70d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
70d ago
Cookie thieves caught stealing dev secrets via fake Claude Code installers
70d ago
Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo
70d ago
MS Defender on OT Network
70d ago
A fateful question
70d ago
SC-900 or SC-400
70d ago
What are your security non-negotiables?
70d ago
Losing my path
71d ago
Axon-captcha
71d ago
What makes companies trust small cybersecurity vendors?
71d ago
Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility”
71d ago
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
71d ago
Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim
71d ago
These Extensions are Scraping Your AI Chats, are you affected?
71d ago
Be careful with your Git: Investigating malware spreading through Git repositories
71d ago
Training and Phishing
71d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
71d ago
AI-powered hacking has exploded into industrial-scale threat, Google says
71d ago
Apple closed my bug report 4 times. MITRE wouldn't let it die.
71d ago
NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG
71d ago
Google spotted an AI-developed zero-day before attackers could use it
71d ago
beginner doubt
71d ago
I got my CEH Certification. SO what now?
71d ago
Construction to Cyber PM
71d ago
[ Removed by Reddit ]
71d ago
Something got downloaded on my phone and then dissappeared
71d ago
Bleeding Llama
71d ago
Do accountants even care about cybersecurityas much?
71d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
71d ago
Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust
71d ago
Was the reconnaissance in Bugbounty overrated?
71d ago
Cybersecurity beginner building an experimental log analyzer — looking for advice
71d ago
Anyone else worried about AI being a security nightmare?
71d ago
Snyk not working
71d ago
Malicious tenants paid us to abuse our RMM. We blocked them
71d ago
Help reasuring parents with an email parsing tool (i will not promote)
71d ago
DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this?
71d ago
cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers
71d ago
5 years as a Level 1 Security Analyst and wanting to transition into consulting
71d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
71d ago
New into network pentesting.
71d ago
Is it worth it to switching field to cybersecurity ?
71d ago
Neeed help to get cybersecurity internship.
71d ago
Mentorship Monday - Post All Career, Education and Job questions here!
71d ago
Cybersecurity and ADHD
71d ago
Anyone dealt with a VulDB submission rejection? Resubmit or reply?
71d ago
ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing
71d ago
I have a malware and need help removing it. someone please help me 🙏
72d ago
I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too?
72d ago
EasySec - Update
72d ago
What is the cybersecurity equivalent of leaving your spare key under the doormat?
72d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
72d ago
VICE: Cyberwar | Full Season 2 | Blueprint
72d ago
Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures
72d ago
Email OTP as default (often ONLY) password isn’t the solution
72d ago
Soc analyse
72d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
72d ago
Price rising
72d ago
AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report
72d ago
Possible security incident against Arup Group
72d ago
Can honeypots be used this way?
72d ago
I think AI just quietly killed the 90-day disclosure window.
72d ago
TCM and Educate 360 are bugged
72d ago
Got an alert from google what should I do?
72d ago
UK jobs
72d ago
Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏
72d ago
Worst company
72d ago
Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning
72d ago
Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months)
72d ago
ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring)
72d ago
App Store Question - Darato Sport / Dofu Sport / Kofu
72d ago
Help! - My Parents Computer is Hacked
72d ago
Ran lumma stealer from a recaptcha scam
72d ago
Port 5986 question
72d ago
CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse!
72d ago
cyber security/ segurança da informação
72d ago
College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains
72d ago
Help with an Escalating Cyber-Stalker
72d ago
RRW - Rick Roll WiFi
72d ago
Best resources to start learning python for cybersecurity and automation
72d ago
Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game.
72d ago
JDownloader site hacked to replace installers with Python RAT malware
72d ago
How can I fix my browser remembering what he had open last
73d ago
MS 360 CoPilot issues
73d ago
I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details
73d ago
ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12.
73d ago
eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback
73d ago
I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you
73d ago
OWASP TOP 10 LLM 2026 Community voting
73d ago
Second security incident at Instructure (Canvas)
73d ago
UK Advice Needed - VA+ Training?
73d ago
Gateweb - Secure Web Gateway
73d ago
Those who are in Detection engineering
73d ago
Can someone tell me of a trustable hacker?
73d ago
MSPs, how are you handling AI usage across your customer environments today?
73d ago
Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write
73d ago
How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there?
73d ago
ecpptv3 Exam in 3–4 Days —
73d ago
AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES
73d ago
Did CISA helped you land a job ?
73d ago
CTO at NCSC Summary: week ending May 10th
73d ago
pre pre junior needs help(guidance pls)
73d ago
Trojan malware
73d ago
SANs Courses: How do people get their employers to pay?
73d ago
NIS2 Article 21: turning compliance controls into technical security evidence
73d ago
This GBA Rom is making is having a weird behavior in the Sandbox, why?
73d ago
Why AI agent governance feels harder than traditional security models
73d ago
Confused about what certs are important
73d ago
Would getting Security+ be worthless for me?
73d ago
Submit probe test — shadow DOM click
73d ago
Threat intelligence in OT (Power equipments)
73d ago
SOC Analyst
74d ago
PAWs, PAM and PIM..what is best practice?
74d ago
This is the most in-depth analysis I have found on the Instructure/Canvas breach so far.
74d ago
Poland says hackers breached water treatment plants, and the U.S. is facing the same threat
74d ago
Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web.
74d ago
Quacc++: Automated Open Source Vulnerability Discovery
74d ago
60% of MD5 password hashes are crackable in under an hour
74d ago
Built a correlation engine that chains AD findings into attack paths automatically.
74d ago
Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests
74d ago
JDownloader's official website delivered Python RAT
74d ago
Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
74d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
74d ago
Note taking apps and advice
74d ago
IMF Warns AI Could Trigger Global Financial Cyber Crisis
74d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
74d ago
Is the ISC2 Cybersecurity program still worth it?
74d ago
Canvas getting hit during finals week shows how fragile “critical SaaS” has become
74d ago
Are websites exposed to the internet under attack almost every hour, even if they're small?
74d ago
Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken
74d ago
What the **** is happening in cybersecurity space ?
74d ago
Canvas is back up, but now what?
74d ago
Instagram is getting rid of end to end encryption, what now?
74d ago
New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation
74d ago
Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable".
74d ago
Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group?
74d ago
Cushman and Wakefield confirms cyberattack
74d ago
Egnyte potential ransomware attack
74d ago
So canvas is down, what'll happen if they can't come to an argreement?
74d ago
Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now.
74d ago
/Why/ is Shinyhunters targeting Canvas?
74d ago
Canvas Hack - Any Guesses How?
74d ago
Should I build a virtual or physical lab?
74d ago
Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12
74d ago
Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata
74d ago
Audit/Cybersecurity
74d ago
Issues removing Trellix (and specifically solidifier)
74d ago
Pentagon eyes 3-year cyber training requirement, overriding new Army policy
74d ago
How much personal info will be leaked by the recent Canvas hack??
74d ago
Dirty Frag and canvas
74d ago
Hackers deface school login pages after claiming another Instructure hack
74d ago
Did I destroy my career by being loyal to an arguably good company?
74d ago
V4bel/dirtyfrag - Universal Linux Local Privilege Escalation
74d ago
What is CYBERRANT?
74d ago
Canvas is down as ShinyHunters hack forces outage
74d ago
New Dirty Frag Linux Bug Emerges in Wake of Copy Fail
74d ago
Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today.
74d ago
How is GRC work in a MSSP?
74d ago
SH and BF phishing console
74d ago
Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth?
74d ago
Socure authenticating AI identity as real.
75d ago
Automated SSL Certificate Renewals - What is your setup?
75d ago
Shinyhunters and Canvas
75d ago
What Cli execution do you use for a script file?
75d ago
Fiserv security incident - data breach notice
75d ago
Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments
75d ago
I graduate next year with a Cybersecurity degree.
75d ago
Asking about Cortex
75d ago
Apache Caldera
75d ago
What’s the “unsexy” problem in cyber that’s actually a total disaster?
75d ago
Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE
75d ago
As a developer, should I use AI to improve security?
75d ago
My company has an MSP that manages our employee endpoints but we cant access the software they use to manage
75d ago
Americans sentenced for running 'laptop farms' for North Korea
75d ago
Is my laptop hijacked ?
75d ago
claude ai gave security beta to Enterprise plans only what can we do as pentesters?
75d ago
Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline
75d ago
Advice for path to land job SOC in France
75d ago
Possible Major Vulnerability: Chromium used by current version of PRTG
75d ago
Mythos AI may be a cybersecurity threat, but it follows the rules of the game
75d ago
Control Checks using AI.
75d ago
How do native password managers clear the clipboard?
75d ago
Graduating CS Student but Wanna Start my Career in Cybersecurity
75d ago
Claude-Themed Malware Campaigns
75d ago
DeepFake it till you make it.
75d ago
The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments
75d ago
What niche in cybersecurity should I go for, with my background in Angular & .NET ?
75d ago
Successor for Kaspersky Endpoint Security
75d ago
Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago
75d ago
SOC Analyst tier 1 (Entry Level) ??
75d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
75d ago
Made cybersecurity merch as an infosec practitioner — honest feedback welcome
75d ago
As AI agents become users of company data - what is needed to keep data secure?
75d ago
Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities.
75d ago
AI inference is quietly becoming a security problem
75d ago
is winrar 7.13 vulnerable to extraction exploits?
75d ago
Tried explaining internet encryption in a beginner-friendly but accurate way, feedback?
75d ago
Is the EC-Council CTIA Certification Worth It for Career Growth?
75d ago
POC Android vuln 2026
75d ago
Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise
75d ago
Opinions on Mimecast
75d ago
What's going on in the field of Cybersecurity 🫣.
75d ago
How do teams preserve institutional pentest knowledge when senior testers leave?
75d ago
CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE
75d ago
Sophos NDR on Proxmox
75d ago
On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029.
75d ago
DOJ says ransomware gang tapped into Russian government databases
75d ago
DAEMON Tools devs confirm breach, release malware-free version
75d ago
Have there been instances where your SOC has suffered a cybersecurity attack?
75d ago
OpenCTI founder, Samuel Hassine, arrested and charged with CSAM
75d ago
Deepfake Platform
75d ago
Trellix Licence Query
76d ago
Instructure hacker claims data theft from 8,800 schools, universities
76d ago
Is AI generated code creating a non-linear security problem for AppSec teams?
76d ago
D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says
76d ago
Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security
76d ago
Norton Antivirus and Other Norton Software
76d ago
Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home?
76d ago
We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes.
76d ago
Download a malware a while ago, someone trying to log into my ios account
76d ago
Org Restructure
76d ago
Does SOC 2 actually reduce questionnaires, or just change them?
76d ago
Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views
76d ago
How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically?
76d ago
Ran phishing awareness training for 200+ non-tech employees
76d ago
Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk
76d ago
Vulnerability Garden
76d ago
Palo Alto Firewall Zero-Day Under Active Exploitation
76d ago
Cyber Security Militias
76d ago
Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk
76d ago
CyberSecurity Nightmares
76d ago
Can I use NanoKVM if it's just to turn on pc?
76d ago
got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something?
76d ago
How to learn tools for cybersecurity?
76d ago
'CopyFail' attackers start cashing in on Linux flaw
76d ago
Anybodybodybdown for a team/studygroup?
76d ago
I was hacked due to sim card spoofing
76d ago
Chrome is quietly installing a 4GB AI model on your device
76d ago
Dev vs Security role
76d ago
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft
76d ago
Oracle Debuts Monthly Critical Security Patch Updates
76d ago
Sec engineer / developer?
76d ago
When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them?
76d ago
Are we actually seeing more vulnerabilities or just more noise?
76d ago
Cybersecurity jobs in red team
76d ago
Question
76d ago
What’s the biggest mistake people make even after installing antivirus?
76d ago
New dashboard tracks ransomware groups by their reliance on Infostealer credentials
76d ago
What would you say if your security lead said this...
76d ago
What would be the goto setup in AWS for security purposes?
76d ago
CREST CRT Exam 2025/2026 Experiences
76d ago
Microsoft Edge stores your passwords in plaintext RAM... on purpose
76d ago
Como começar?
76d ago
Possible Password Leak? Curious if Anyone Has Seen This Before
76d ago
Not a Hack. A Handout. Inside the GTFOice.org Data Exposure
76d ago
Besoin de conseils sur une DMZ automatisée
76d ago
Microsoft, Google and xAI will let the government test their AI models before launch
76d ago
Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073
76d ago
SMB Header Signature for Tagging in Firewall
76d ago
Question regarding VDP
76d ago
Working on what i should do for the next 3 years
76d ago
Question for Security Professionals
76d ago
Do tech companies lifecycle-manage public DNS records to prevent dangling DNS?
76d ago
Vulnerability Summary for the Week of April 27, 2026
76d ago
Cisco releases open-source ‘DNA test for AI models’
76d ago
Cybersecurity is becoming too AI dependent is that a problem
76d ago
Foxconn Wisconsin outage raises cyber questions
76d ago
How stressful is GRC?
76d ago
Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia
76d ago
Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India
77d ago
Archer for a non-regulated medium sized company?
77d ago
Cybersecurity statistics of the week (April 27th - May 3rd)
77d ago
Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM.
77d ago
Where to find reliable vendors?
77d ago
Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts?
77d ago
We wrote a guide on securing Claude across the enterprise — here's the core framework (with download)
77d ago
Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium.
77d ago
Hardware reverse enginnering first project. Love some advice
77d ago
Microsoft Edge Stores Passwords in Process Memory, Posing Risk
77d ago
Currently working on cybersecurity, looking for advice
77d ago
Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning
77d ago
CISO course valuation
77d ago
GRC Path to CISO (Certifications)
77d ago
CISOs and pentest buyers, what's the worst thing you've seen in a pentest report?
77d ago
How to enforce M365 Sign-in frequency on corporate laptops?
77d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
77d ago
Built an independent directory of AI Act / AI governance tools, feedback?
77d ago
ScarCruft APT group compromises gaming platform in a supply-chain attack
77d ago
Just curious
77d ago
'Copy Fail' is a real Linux security crisis wrapped in AI slop
77d ago
Analysis malicious DLL
77d ago
Cyber security free course
77d ago
Does certification expires?
77d ago
We get paid to break into buildings for a living. Ask us anything!
77d ago
Pay2Key ransomware — any recovery path that’s actually worked?
77d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
77d ago
Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF
77d ago
How have you kept growing your knowledge in security when the job stops pushing you?
77d ago
The UK’s Age Verification Law Is Producing Compliance Theater
77d ago
Microsoft Edge: Passwords end up in memory as plaintext
77d ago
Do people still get viruses in 2026, or is that mostly a myth now?
77d ago
Mitigation script for Copy Fail vulnerability CVE-2026-31431
77d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
77d ago
Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released
77d ago
DigiCert breached via malicious screensaver file
77d ago
Caido Payloads and Scanner of Endpoints
77d ago
CISO Security Mind Map 2026
77d ago
Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker
77d ago
Amazon SES increasingly abused in phishing to evade detection
77d ago
AI Security Trainings
77d ago
Ai help
77d ago
ByDesign: observed behavior where file URLs remain accessible after unshare/delete
77d ago
Can Kali Linux still compete in cyber security or is it outdated?
77d ago
Who are your favorite cybersecurity YouTubers?
77d ago
CISOs, how are you balancing AI adoption with security risks these days?
77d ago
San Diego Community College District fighting major cyberattack
77d ago
After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up
77d ago
Free resource: searchable archive of every BSides conference talk
77d ago
Lightning PyPI Compromise: Bun-Based Stealer
77d ago
Too much mother instinct?
77d ago
L1 SOC Analyst for ~2 years - Should I still get the Security + Certification?
77d ago
Do CTFs help real world security skills, or just teach patterns?
77d ago
Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo
77d ago
Should I do Security + or Network + or A+? For CompTia
77d ago
Bug bounty is ruining how people learn exploitation
77d ago
ISO/IEC 27701:2025 Scope and Location
77d ago
Cybersecurity's 2026 Wild Ride
77d ago
We built a free multiplayer game that scores prompts on AI code security.
77d ago
Production Usecases
77d ago
How does vCISO work?
77d ago
Trellix discloses data breach after source code repository hack
77d ago
CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path
77d ago
Trellix confirms source code repo access incident
78d ago
Employer Offering to Pay for my Certification test - Which one do I choose?
78d ago
John Strand Pay What You Can Information Security Core Skills live starting May 11th
78d ago
Canvas Breach May Put 275M Users, 9,000 Schools at Risk
78d ago
Is this not such a big deal
78d ago
Do email link checkers need to be 100%?
78d ago
Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
78d ago
Recs for pen testing and vulnerability solutions
78d ago
Identify telegram account holders
78d ago
AI Code Security Study: 6 LLMs vs OWASP Top 10
78d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
78d ago
We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA
78d ago
Cortex XDR Cloud Compromise Alerting
78d ago
Norton.com Verification Email out of the blue
78d ago
Atomic Red Team is now aligned with MITRE ATT&CK v19!
78d ago
Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX?
78d ago
Who are you guys using for your PCI ASV Scanning?
78d ago
Just passed my Security+ exam. Now what?
78d ago
I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work.
78d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
78d ago
[PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection)
78d ago
Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350)
78d ago
An another open door to IoT devices
78d ago
Ideas on how to have personal google-like account synchronization system
78d ago
Lateral Movement - Cross-Session Activation
78d ago
What MCP servers have actually made it into your day-to-day toolkit?
78d ago
Cyber Security Education as Self-Defence classes
78d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
78d ago
Use.ai
78d ago
Educational tech giant Instructure confirms data breach, ShinyHunters claims attack
78d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
78d ago
Browsers making connection on port 3389 from loopback
78d ago
Defender Flagged DigiCert Root Certs as Malware
78d ago
Another breach just hit Canvas (Instructure), and this one is worth a closer look.
78d ago
Over 40% of UK firms suffered cyber attack last year, survey finds
78d ago
EU should seek access to Anthropic's Mythos, Bundesbank says
78d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
78d ago
IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks
78d ago
People in cybersecurity, tell us what was the most epic moment in your career?
78d ago
Prerequisites for CARTP
78d ago
Claude Mythos Cyber Wake Up
78d ago
[ Removed by Reddit ]
78d ago
is trellix from mcafee good to use in 2026?
78d ago
Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list
78d ago
Paypal Accesed by malware me being Stupid
78d ago
How was someone in another country able to read all my private messages without my password or clicking a link?
78d ago
Career Transition Help
78d ago
Alguien para hablar de cyberseguridad
78d ago
What is this
78d ago
Feeling lost and disappointed about finding a job just venting
78d ago
Slow at Learning/Cyber Security?
78d ago
Suspicious traffic from web server
78d ago
Cyber security internship
78d ago
Mentorship Monday - Post All Career, Education and Job questions here!
78d ago
Isn't Windows Defender a crap anymore?
78d ago
Learning Cyber
78d ago
Vishing simulator
78d ago
Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others
78d ago
Worried about being tracked/banned for using an educational app on MuMu Player - Need advice
78d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
78d ago
Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance
78d ago
Prompt Injection in 2026: The Five Attack Patterns That Actually Matter
78d ago
I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine
78d ago
Random trojan detected?
78d ago
CRTA second attempt
78d ago
What’s the hardest thing to learn in cybersecurity?
78d ago
What MCP servers are you integrating into your workflow (not exclusive to security)?
79d ago
WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog
79d ago
What are like the top but unknown Cybersecurity firms?
79d ago
Need professionals or expert on cybersecurity related to dark web for interview
79d ago
A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP)
79d ago
North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory
79d ago
Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate)
79d ago
Credential Dumping: Local Security Authority (LSA|LSASS.EXE)
79d ago
Trojan:Win32/Cerdigent.A!dha
79d ago
MDE flagging digi cert certificate as malicious everywhere ?
79d ago
1867 loaded
HS
hacking: security in practice
40d ago · 241 items
DIY pwnagotchi-like device on esp32
40d ago
Flipper Blackhat + Bjorn
40d ago
Do you think AI is making hacking easier or harder
40d ago
What can i do left? PSN
40d ago
Proxmark5 campaign ending in less than 18 hours.
40d ago
How to bypass speed queen coin slot for washer and dryer
40d ago
Self-hosting stuff for when things get ugly
40d ago
Malware Includes Taboo In Text To Prevent LLM Analysis
41d ago
added Mac support for my corporate hacking game, demo on Steam
41d ago
Catfished
41d ago
What did they mean by this? One of us?
41d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
41d ago
OptOutCode – A Privacy4Cars Universal Opt-Out Concept
41d ago
StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams
42d ago
GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.
43d ago
Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏
43d ago
What's up with powershellforhackers.com?
43d ago
Do people really click on links from unknown numbers?
44d ago
How to unlock whitelabeled uniview IPcam
44d ago
Can converted video files contain malware?
44d ago
Rooted your router lately?
44d ago
5$ to whoever can find the email of my old YouTube channel
45d ago
This company is scaming people
45d ago
A modular autonomous-agent runtime written in C
45d ago
ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more
46d ago
Can one reveal the asterisks in an email?
46d ago
Proxmark3 vs Proxmark5 Side by Side
46d ago
Should I go for it?
46d ago
Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header
46d ago
Failed to verify LHOST error for long links in metasploit
47d ago
Is Marauder available for ESP32-S3 Mini?
47d ago
Gemini whatsapp
47d ago
Safe Rust API for wolfSSL/wolfCOSE
47d ago
Resource Exhaustion
47d ago
I’m not sure I’m in the right subreddit….
48d ago
Took me a decade to turn quantum computing into what hackers can easily learn
48d ago
Took me a decade of work to turn Quantum Computing into a fun videogame
48d ago
Simple way how to bypass hotel WiFi?
48d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
48d ago
burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API)
48d ago
How big of a security risk or exploit would this be?
48d ago
KTO , Be the only one online -- on any WiFi network
48d ago
apparently bypassing school systems by playing games
48d ago
Always-On Red Teams
49d ago
I managed to pull the full system prompt for Meta's Support AI
49d ago
Harassing text messages
49d ago
REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY!
50d ago
Hacking Palo Alto Networks' GlobalProtect VPN with AI
50d ago
Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am.
50d ago
Best AI LLM for Hacking related stuff
50d ago
Feels like most people ignore the wireless layer until it bites them
50d ago
Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking?
50d ago
Can anyone figure out how to retrieve the recovery key in signal app?
50d ago
$730k+ raised on Proxmark5 with 2150 backers
51d ago
I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works)
51d ago
Any idea who's behind this hack? How to resolve it?
51d ago
Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it
51d ago
Blue Team tips?
51d ago
edit certified pdf
51d ago
Everyday hacking in our lives - transportation, work, finances, goods etc
52d ago
Do you think this is legit or has the website been compromised?
52d ago
Wanna learn cybersecurity & ethical hacking
53d ago
Do you guys take paper notes or digital ones during studying ?
53d ago
How do people actually modify mobile games to increase their power?
53d ago
Why Loyalty Programs Are Quietly Becoming a Security Blind Spot
53d ago
Ajuda pessoal
53d ago
Samy Kamkar on building viruses, his arrest and privacy in the LLM era
53d ago
[ Removed by Reddit ]
54d ago
Is this considered a bug or something else entirely?
54d ago
Getting back deleted conversation from messanger
54d ago
Building Omegle for Exposed Webcams
54d ago
AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career?
54d ago
5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain
54d ago
What are the dangers of posting?
54d ago
Flipper Zero Users, What's Your Take?
55d ago
Large company with a bit of an issue free stuff
55d ago
Champion ethical hacker warns AI tools like Mythos will make competing harder.
55d ago
Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker.
55d ago
there's a toll in the hall now
55d ago
Am I crazy or is something off about this Google OAuth login via Calendly
55d ago
When “try again later” still tells you the OTP was correct: an account takeover story.
56d ago
ShadowCat: Universal optical file transfer, single html file, browser to camera
56d ago
y2jb un able to enject payloads
56d ago
Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated.
56d ago
Why did Hack Forums lose popularity?
57d ago
ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise
57d ago
Shellcide: A shellcode IDE
57d ago
Finding bot account
57d ago
How to
57d ago
Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift.
57d ago
Nmap Mastery: The Complete Guide to Network Reconnaissance
57d ago
Google wallet virtual card cloned
57d ago
What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method?
58d ago
Proxmark5 campaign unlocked the $600k stretch goal
58d ago
GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
59d ago
Doom running on a Kids Video Walkie Talkie
59d ago
Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX.
59d ago
This ID Verification company store users biometrics? (FaceTec)
59d ago
Playwright version that lets AI-Agents navigate the web
59d ago
Where to learn the ins and outs of the computer itself
60d ago
Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator
60d ago
Hack your corrupt company. Sell their secrets to the black market
60d ago
🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget
60d ago
CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat
61d ago
This ID verification company allows for storage of biometric data?
61d ago
I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :)
61d ago
SeekYou — one input, 15 recon sources, one report.
61d ago
bypass internet restrictions
61d ago
Can someone unlock a list of the 500-1000 most visited websites online?
61d ago
Wordlist generator based on WordNet graphs + LLM
61d ago
wordpress memberpress
61d ago
The Open Source USB Drive Built for Privacy
62d ago
Is someone trying to hack me?
62d ago
cpu backdoor
62d ago
Technical analysis of CVE-2026-34472 in ZTE H188A router firmware
62d ago
Ongoing development
62d ago
For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks?
62d ago
Hackers found a way around Intel CET—PLaTypus locks down library jumps
62d ago
GitHub investigates internal repositories breach claimed by TeamPCP
62d ago
Hackers: What age did you start? Where did you start, especially in practicing your skills?
62d ago
How to watch a private video on Youtube?
62d ago
Can I do anything cool with this network controller?
62d ago
Micro controller safety?
63d ago
CISA Admin Leaked AWS GovCloud Keys on Github
63d ago
Decompilation of DSP Code using IDA Pro
63d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
63d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
63d ago
Built a full disassembler & decompiler for Reverse Engineering | Free and open source.
63d ago
Slopinator - a poisoned GitHub repository generator
63d ago
Made a shell greeter that generates a unique rocket every time you open a terminal tab
63d ago
Just received an email from shinyhackers about their amtrack hack
63d ago
Flipper Zero (or Alternatives)?
63d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
63d ago
Recent WhatsApp hacks
63d ago
I wrote an async scanner that runs about 9x faster than nmap for discovery.
64d ago
Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers
64d ago
Does anyone know if this file is still accessible to download?
64d ago
High school students organized a Jeopardy CTF competition - give it a try
65d ago
Official Miasma Poison Tar Pit Docker Image Now Available
65d ago
Does anybody know where I may stumble upon some Sh1mmer bin downloads
65d ago
Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network
65d ago
GZDoom in the browser
66d ago
Anyone know how to bypass these school laptop pins?
66d ago
A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA
66d ago
I have a friend who looks like he’s a stalker I’m scared he will know I stalk him
66d ago
[Tutorial] How to hack DOS games: Reversing Prince of Persia
66d ago
Is dns spoofing dead??
67d ago
My Privacy Focused USB Drive
67d ago
Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition)
67d ago
TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer
67d ago
has anyone used tail os here?
67d ago
Run this washer/dryer sans coin?
67d ago
I built an open-source Burp alternative
67d ago
HighBoy
67d ago
Reading Siemens CT raw data
68d ago
How I use Hermes agent to turn Patch Tuesday into Windows exploit research
68d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
68d ago
Tips for a beginner noob that wants to learn
68d ago
Strix — first public beta of the spiritual successor to cSploit/dSploit
68d ago
Whatsapp
68d ago
Face ID bypass with avatar
68d ago
Hunting the Behavior Behind npm Supply Chain Attacks
68d ago
Proxmark5 Day 3 Update - $357K+ funded (715% of goal)
68d ago
Are There Really Ethical Hackers? I've Yet To Meet One
68d ago
trying to learn patching
69d ago
Cellphone IP address spoofing.
69d ago
Sorry if its the wrong place but
70d ago
Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it?
70d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
70d ago
where is the location of Files by Google on Android?
71d ago
Reading old s4 memory with xgecu t48
71d ago
Hack a data center?
71d ago
Autonomous Vulnerability Hunting with MCP
71d ago
AI DNS Resolver
72d ago
Is it true that the professionals have the worst setups?
72d ago
I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage
72d ago
Refining hacking basics — scaling them aswell
72d ago
AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic)
73d ago
Bridging the Gap Between Vulnerabilities and Working Exploits
73d ago
um you guys is my hacker stupid?
73d ago
This GBA ROM makes some weird things in the sanbox, would love to understand why
73d ago
Why was he banned?
73d ago
LAB Setup
73d ago
Ethical malware development community
74d ago
Has Instructure paid SH?
74d ago
Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me.
74d ago
New trends (not mainstream)
74d ago
Best tools to find exposed web services by HTML title / HTTP response?
74d ago
Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago?
74d ago
AI Agents Have a Security Problem. IronClaw is Fixing It.
74d ago
A hacker ran me over with a robot lawn mower - The Verge
74d ago
Happened today
74d ago
Shinyhunters and Canvas
74d ago
Modify md5sum of a file
75d ago
OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM
75d ago
Jailbreaking my cars infotainment system and implementing my own custom software
76d ago
where is the original wormgpt
76d ago
Are there any chill hacking youtubers?
76d ago
Took me a decade to turn quantum computing into what programmers can easily learn, big announcement
76d ago
Lilygo T-Embed Glitching etc
76d ago
Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today?
76d ago
Found a possibly interesting live attack
76d ago
Export/Backup ChatGPT chats
76d ago
Is this fake too?🤣
77d ago
I just figured out my dad use to be a Phreaker in the 1980s
77d ago
What of my favorite videos🙂
77d ago
Best tools for blocking spam calls and spam links?
77d ago
someone else’s UI appearing on screen for split second— possible hacker??
77d ago
Avoiding rouge AP detection in enterprise networks
77d ago
GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering
77d ago
San Diego Community College District fighting major cyberattack
77d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
78d ago
Iwas developing a hacker game that transports the feeling of the 90s
78d ago
How did this guy even access another person's privated YouTube video without wayback machine?
78d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
78d ago
IPod Nano Gets Three Monitors
78d ago
Chrome "Best AdBlocker" trojanized extension - 100k downloads.
78d ago
Any good open sources that bypass modern heuristic analysis?
78d ago
Free apex hacks?
78d ago
[SHOWCASE] Cascavel v3
78d ago
Pokemon machine
78d ago
Can HTTP POST bodies be intercepted without network or host access?
79d ago
built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4)
79d ago
Dump sql time based is too slow
79d ago
North Korea rejects US cybercrime claims as 'absurd slander'
79d ago
is credential stuffing using openbullet2 dead in 2026?
79d ago
Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax)
79d ago
Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT)
80d ago
Small models are better at cost-to-recall than large models like Mythos for vulnerability research
80d ago
Bluetooth Spoofed Disconnect?
80d ago
wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ...
81d ago
🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀
81d ago
I made a lightweight breach intelligence search engine (fully client-side) looking for feedback
82d ago
Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan...
82d ago
Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool
82d ago
Copy Fail — 732 Bytes to Root
82d ago
GitHub fixes RCE flaw that gave access to millions of private repos
83d ago
How to download Kaggle dataset safely...?
83d ago
VECT Ransomware Is Actually a Wiper
83d ago
Flipper Blackhat April Roundup!
84d ago
[VulnPath Update] Automated Email Alerting & CISA KEV Feed
84d ago
241 loaded
RE
Reverse Engineering
40d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it
40d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
40d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
40d ago
Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game
40d ago
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
40d ago
Drive Firmware Security - Phison S11
40d ago
IDA 9.4 Beta | Hex-Rays Docs
41d ago
Trane Tracer HVAC cybersecurity issues
41d ago
🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS)
41d ago
I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS.
42d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
43d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
43d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
43d ago
EMBA firmware analysis framework v2.0.2 available - Party the big 2k
43d ago
/r/ReverseEngineering's Weekly Questions Thread
43d ago
HDD Firmware Hacking Part 1
43d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction
44d ago
Zhiyun Weebil-S Camera Gimbal BLE Protocol
44d ago
Reverse Engineering the Garmin Running Dynamics BLE protocol
44d ago
Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate)
45d ago
Reverse Engineering Crazy Taxi, Part 3
46d ago
Ghidra 12.1.2 has been released!
46d ago
Extending a map tool for Cataclismo
46d ago
I've been reverse engineering a lost 2010 horse MMO and I need contributors
46d ago
HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes
46d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
46d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
47d ago
void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies
47d ago
Automated Fault Injection Attack Framework
47d ago
x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994)
48d ago
Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2
48d ago
Hacking your PC using your speaker without ever touching it
48d ago
Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source!
49d ago
Built a decompiler for exotic legacy programming language opentext Gupta Team Developer
49d ago
running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it!
49d ago
/r/ReverseEngineering's Weekly Questions Thread
50d ago
Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from?
50d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
51d ago
TinyLoad v7 - what i added :D (in memory protection using VEH and alot more)
51d ago
[ Removed by Reddit ]
51d ago
Snowboard Kids 2 is 100% Decompiled
51d ago
usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer)
51d ago
I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux)
52d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
52d ago
Ghidra 12.1.1 has been released!
53d ago
Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint)
53d ago
VMP 3.5+ Internal Architecture & Heap Dispatch Analysis
53d ago
How 2004 RuneScape fit a multiplayer RPG into 56k dial-up
54d ago
reverse engineering need for speed most wanted for modding sdk
54d ago
GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs.
54d ago
Winbox server/client reverse engineered is opensource
54d ago
(URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active
55d ago
Hypothetical EDR spoofer
55d ago
I Reverse Engineered Need for Speed Most Wanted Server
55d ago
Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation
56d ago
Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching
56d ago
How I Tried to Parse a Replay from Dawn of War: Definitive Edition
56d ago
Nocturne - A bin2bin code virtualizer for x86-64 PE binaries
57d ago
[Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing
57d ago
Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing
57d ago
I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built
57d ago
delimiter-less string obfuscation powered by compile-time AES
57d ago
/r/ReverseEngineering's Weekly Questions Thread
57d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
58d ago
Has anyone manage to reverse the macked dylib?
58d ago
Reverse engineering circuitry in a Spacelab computer from 1980
58d ago
Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology
59d ago
CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22)
60d ago
Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes
60d ago
qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb)
60d ago
Reverse Engineered Google reCAPTCHA
60d ago
Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware
61d ago
I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP
61d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
61d ago
I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries
61d ago
GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam)
61d ago
AI Agents defeat obfuscated JavaScript in 10 minutes
62d ago
What is it Wednesdays: Episode 0002
62d ago
TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post)
62d ago
Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing
62d ago
How to build .NET obfuscator
62d ago
botguard-token-generator / a google botguard token gen using only requests...?
62d ago
Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing)
63d ago
Deep dive into the object creation flow in Windows - PART 4: Handle table internals.
63d ago
Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware
63d ago
Open-source Hermes bytecode decompiler for React Native apps (Rust)
63d ago
Hermes bytecode decompiler (Rust) - sharing my friend’s project
63d ago
Forza Designer 6
63d ago
Built a full disassembler & decompiler | Free and open source.
63d ago
Snowboard Kids 2 is 100% Decompiled
63d ago
Decompilation projects and N64 Recompiled PC ports (May 2026)
64d ago
Glass - A fast and free interactive disassembler
64d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
64d ago
HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try!
64d ago
/r/ReverseEngineering's Weekly Questions Thread
64d ago
Reverse engineering no dep x64 masm AI IDE
64d ago
PE packer/crypter with random VM ISA per build
65d ago
A Tale of Two File Names
65d ago
PE reconstruction
65d ago
A File Format Uncracked for 20 Years: Part 2
66d ago
Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source!
66d ago
[CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link.
66d ago
Exploiting Toshiba Qiomem.sys vulnerable driver
66d ago
HDD Firmware Hacking Part 1
66d ago
Region-based binary diff tool for firmware analysis
66d ago
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
66d ago
แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป!
66d ago
Brovan — Open-source x86/x64 user-mode binary emulator written in C#
66d ago
Brovan: Binary user-mode emulator for x86_64
66d ago
Understanding Stack Buffer Overflows Through Doom and C++
66d ago
What is it Wednesdays: Episode 0001
66d ago
Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup
67d ago
Deepdive into the object creation flow in Windows -PART 2 : access check internals
67d ago
Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization
67d ago
[Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo)
67d ago
yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android.
67d ago
GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets
67d ago
GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS
67d ago
Trafexia V2 - Mobile Traffic Interceptor Toolkit
67d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
68d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
68d ago
Ghidra 12.1 has been released!
68d ago
Reverse Engineering Slither.io’s Network Protocol
68d ago
I Reverse-engineering Need for Speed Underground 2 Server
68d ago
I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included
69d ago
[Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features
69d ago
LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer]
69d ago
r2garlic - The world's fastest Android/DEX decompiler meets radare2!
69d ago
GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language.
70d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
70d ago
Reverse Engineering Fisher-Price Pixter
71d ago
/r/ReverseEngineering's Weekly Questions Thread
71d ago
Check out my matplotlib of BLE live wire data for Oura ring!
71d ago
Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows
71d ago
Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop
71d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
71d ago
Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)
71d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3
71d ago
PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra
72d ago
[Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc)
73d ago
Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!)
74d ago
Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2
74d ago
SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals
74d ago
I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow!
74d ago
The first FREE online WebAssembly Reverse Engineering workbench (and how we built it)
75d ago
VLC Media Player MKV Exploit Analysis
75d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
76d ago
ant4g0nist/pyre: Ghidra decompiler in your browser
76d ago
Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source!
76d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
76d ago
Reverse-engineering the 1998 Ultima Online demo server
77d ago
Inside Faxanadu series — deep dive into how this NES title works
77d ago
EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing
77d ago
Copy.fail: Why Internal LLMs Are Non-Negotiable for Security
77d ago
Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra
77d ago
Where do i find reverse engineers for actuators? Ideally in Shenzhen
78d ago
[CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2).
78d ago
[WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation
78d ago
IDA-MCP Is Now RE-MCP With Ghidra Support
78d ago
Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference
78d ago
/r/ReverseEngineering's Weekly Questions Thread
78d ago
GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions)
78d ago
Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo
79d ago
Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you!
79d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
79d ago
How to build .NET obfuscator - Part II
79d ago
libghidra - SDK for automating Ghidra from Python, Rust, and C++
80d ago
Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis.
80d ago
Why my macOS Messages badge lied to me (and the one-line fix)
81d ago
Running Adobe’s 1991 PostScript Interpreter in the Browser
81d ago
Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :)
81d ago
/r/ReverseEngineering's Triannual Hiring Thread
81d ago
In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off)
81d ago
Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight
82d ago
HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try!
82d ago
GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).
82d ago
I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway
83d ago
Building a perfect clone of 1993 game SimTower (via RE)
84d ago
How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema
84d ago
AI solved our CTF in 6min
84d ago
Example structure for evidence-based vulnerability reports
84d ago
181 loaded
FB
For [Blue|Purple] Teams in Cyber Defence
40d ago · 603 items
US charges suspected Russian hacker with facilitating cyber campaign
40d ago
Hawkish GOP lawmaker Don Bacon says he was hacked by Russia
40d ago
Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
40d ago
GreatXML: GreatXML bitlocker bypass vulnerability
40d ago
GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan
40d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
40d ago
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion
40d ago
GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default
40d ago
Miasma-style supply chain attacks
40d ago
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet
41d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
41d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
41d ago
Testing offensive AI agents in a cloud lab with deception tech
41d ago
Benchmarking n-day exploit generation [via AI]
41d ago
Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
41d ago
Microsoft Defender now monitors RPC activity
41d ago
RoguePlanet: RoguePlanet Windows Defender Vulnerability
41d ago
I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in)
41d ago
How do you make learning blue team security entertaining ?
42d ago
Maximizing IOC Impact
42d ago
[2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution
42d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
42d ago
Entra Agent ID from a Security Perspective
42d ago
Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility
42d ago
What are the best risk-based vulnerability management tools for tracking active exploitation in 2026?
42d ago
QuasarNix: Reverse Shell Detection with Machine Learning
42d ago
Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go
42d ago
Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion
42d ago
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
42d ago
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
42d ago
UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season
42d ago
Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
42d ago
Visual Studio Code 1.123: Delayed extension auto-updates
42d ago
Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.
42d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched,
42d ago
Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement
42d ago
HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified)
43d ago
Security Review Request — TID Linux Kernel Module
43d ago
Building a safe, effective sandbox to enable Codex on Windows
43d ago
Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale.
43d ago
About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection
43d ago
BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection
43d ago
Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution.
43d ago
UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service.
43d ago
EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
44d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
44d ago
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
44d ago
cygor: An modular asset discovery framework written in python to automate the repeating manual work
44d ago
On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts.
44d ago
Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors.
44d ago
Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim
44d ago
Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored)
44d ago
The Privileged Roles Nobody Talks About
44d ago
Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain...
44d ago
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
44d ago
21 Zero-Days in FFmpeg
44d ago
depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research?
44d ago
CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work
44d ago
The Detection & Response Chronicles: Covert Operations Through QEMU
44d ago
The Interesting Case of WSL for Payload Staging
44d ago
The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer
44d ago
Ongoing Targeted Campaign Against US Law Firms
44d ago
New China-Linked Cluster OP-512
44d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
45d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
45d ago
MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain
45d ago
Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated
45d ago
Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns
45d ago
About ETW Internals: Architecture, Hooking, Tampering, and Detection
45d ago
PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver
45d ago
Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
45d ago
Async PICOs and Custom Beacon Wakeups in Cobalt Strike
45d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
45d ago
staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs
45d ago
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window
45d ago
Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS
45d ago
BOF Cocktails in Cobalt Strike
45d ago
Address Translation
45d ago
Investigation into APT 5 and their inner workings of PLA Troop 61786
45d ago
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
45d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
45d ago
Magecart skimmer turns Stripe into a malware command server
45d ago
Security advisory: Brute force attack on Dashlane user accounts
45d ago
Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability
45d ago
A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact).
45d ago
IronWorm: Shai-Hulud's rustier cousin
45d ago
Weil reportedly pays up to $20 million after hackers steal client data
45d ago
CTO at NCSC Summary: week ending June 7th
45d ago
defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
45d ago
1-Click GitHub Token Stealing via a VSCode Bug
45d ago
The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds
45d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
45d ago
Introducing Package Proxy: supply-chain safety checks without client-side software
46d ago
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
46d ago
zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS)
46d ago
The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory
46d ago
VerdantBamboo: Just Another BRICKSTORM in the Firewall
46d ago
AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID
46d ago
MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code
46d ago
IronWorm Supply Chain Malware Hits npm
46d ago
FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel
46d ago
FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad
46d ago
You do surprise me.exe: An unexpected executable in Hola Browser
46d ago
LSASS/Defender/CTFMON analysis
47d ago
Software supply chain attacks: check your dependencies
47d ago
Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator
47d ago
29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection)
47d ago
Open Source - 2500 New MITRE Mutations
47d ago
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
47d ago
Bring Your Own RWX Region DLL (BYORWXDLL)
47d ago
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
47d ago
APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component
47d ago
NuGet Code Execution As A Service
47d ago
aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies
47d ago
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
47d ago
TA4922: The Suspected Chinese Crime Group is Going Global
47d ago
[ Removed by Reddit ]
47d ago
Espionage Campaign Targeted Stock Exchange Executive for Five Months
48d ago
OnionAccelerator: multi-circuit / chunked download acceleration over Tor
48d ago
HazyBeacon and AWS Lambda Function URL Abuse
48d ago
The Server Seizure That Affects Also Iran's Cyber Operations
48d ago
How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad
48d ago
🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network
48d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
48d ago
Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors
48d ago
Dependency Cooldowns - Dependency Cooldowns
48d ago
C2 Frameworks - Threat Hunting in Action with YARA Rules
48d ago
Ransomware tabletop
48d ago
Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026
48d ago
Tracking North Korea Nation-State APT Infrastructure: Kimsuky
48d ago
새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn
48d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
48d ago
Codex Discovered a Hidden HTTP/2 Bomb
48d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
49d ago
Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix
49d ago
“Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?”
49d ago
Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif
49d ago
Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand
49d ago
Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm
49d ago
RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation
50d ago
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
50d ago
Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches
50d ago
Miasma: Supply Chain Attack Targeting RedHat npm Packages
50d ago
@redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers
50d ago
Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched
50d ago
Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks
50d ago
Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries
50d ago
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
50d ago
Atomdrift - open-source malware detection for the software supply chain
50d ago
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
51d ago
179 npm Packages Target Cloud and Finance via oob.moika.tech
51d ago
KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4
51d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
51d ago
Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services
51d ago
EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA
51d ago
Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace
51d ago
Signal macOS Desktop App Doesn't Actually Delete Messages When it Should
51d ago
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
51d ago
WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD
51d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
51d ago
Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2
51d ago
Malicious npm packages abuse dependency confusion to profile developer environments
51d ago
Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
51d ago
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack
51d ago
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
51d ago
Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign
51d ago
SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.
51d ago
EDR Incident Response Playbook: Containing Local Account Incidents
51d ago
Adversarial Oracles: LLM-Guided EDR Signature Reduction
51d ago
One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF
51d ago
proxy: A lightweight caching proxy for package registries.
51d ago
How OLTs may have exposed entire ISP networks
51d ago
A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
51d ago
HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics
51d ago
Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots
51d ago
Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures
51d ago
Lessons from Penetration Tests on Large-Scale Agent Systems
51d ago
pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter.
51d ago
CIFSwitch: a non-universal Linux local root vulnerability
51d ago
Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension
52d ago
DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.
52d ago
Visual Studio Extensions Revisited
52d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
52d ago
BYOVD and Looting LSASS in the Modern EDR Era
52d ago
CTO at NCSC Summary: week ending May 31st
52d ago
OffensiveCon26 videos
52d ago
School Survey, (non-paid nothing its free its for my grades)
52d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
53d ago
LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms
53d ago
LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting
53d ago
Identifying attack patterns through kernel frame callstacks
53d ago
Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness
53d ago
What safety boundary would you expect from a local AI incident investigation tool?
53d ago
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
53d ago
Why I Built My Own LLM Benchmark for THOR Finding Triage
53d ago
Casdoor contains multiple authentication bypass and access management vulnerabilities
53d ago
The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents
53d ago
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
53d ago
Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies
53d ago
Malware seller hunted across three continents
53d ago
Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims
53d ago
Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers
53d ago
Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network
53d ago
Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations.
53d ago
The C-suite job that's burning people out faster than any other
53d ago
New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation
53d ago
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
53d ago
Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances
53d ago
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
53d ago
APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026
54d ago
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
54d ago
Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
54d ago
Zero Trust Implementation Guidelines
54d ago
BlackToad: Network Manipulation in an AutoIt Payload
54d ago
RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT
54d ago
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
54d ago
Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit
54d ago
FROST: Fingerprinting Remotely using OPFS-based SSD Timing
54d ago
Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup
54d ago
puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
54d ago
Who is Salt Typhoon Really? Unraveling the Attribution Challenge
54d ago
Looking for resources on end-to-end APT attack flow summaries for detection engineering
55d ago
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
55d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP
55d ago
Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint
55d ago
Building Detection Engineering on AWS from scratch — roast my plan
55d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
55d ago
Designing secure access with ZTNA
55d ago
MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response
55d ago
White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats
55d ago
Advisory X41-2026-002: Request Host Header not Validated in Starlette
55d ago
Top ethical hacker Chompie warns AI tools could put her out of business
55d ago
浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents
55d ago
YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions
55d ago
CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state
55d ago
The Evolution of Chinese-language Phishing Services
55d ago
Silent Ransom Group Impersonating IT Personnel through Social Engineering
55d ago
The epoll UAF - an epoll uaf race in fs/eventpoll.c
55d ago
Tycoon 2FA AiTM detection for Entra ID and Google
55d ago
Microsoft Copilot Cowork Exfiltrates Files
55d ago
Unpatched Sparx vulnerabilties
56d ago
sylvia: iOS Syscall Explorer for IDA 9.X
56d ago
Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East
56d ago
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip
56d ago
JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign
56d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack
56d ago
Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@"
56d ago
The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization
56d ago
GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
56d ago
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
56d ago
CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700.
56d ago
YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos
57d ago
Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it
57d ago
honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports
57d ago
Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild.
57d ago
Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council
57d ago
RemotePE: The Lazarus RAT that lives in memory
57d ago
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
57d ago
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
57d ago
Twee mannen aangehouden voor phishing - Two men arrested for phishing
57d ago
Sharp Eyes: Mass surveillance of foreigners in China
57d ago
relay_bible: Technical Reference to multiple relay techniques
57d ago
Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec
57d ago
The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in]
57d ago
SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format
57d ago
North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial
57d ago
Staged publishing and new install-time controls for npm - GitHub Changelog
58d ago
Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES
58d ago
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
58d ago
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow
58d ago
The Future and Past of Residential Proxies
58d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
58d ago
Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy
58d ago
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
58d ago
A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software
58d ago
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
58d ago
Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities
58d ago
Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes
58d ago
mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
58d ago
keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust.
58d ago
np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.
58d ago
Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up.
58d ago
OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
58d ago
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
58d ago
FatGid - FreeBSD 14.x kernel LPE
58d ago
Manage [VSCode] extensions in enterprise environments
58d ago
angr: A powerful and user-friendly binary analysis platform!
58d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
58d ago
How Attackers Force Microsoft to Send Phishing Emails
58d ago
Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
58d ago
Microsoft Authenticator App Details now exposed in Entra SignInLogs
58d ago
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
58d ago
How China-linked threat actors obtain zero-day vulnerabilities
58d ago
Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research
58d ago
Monitoring for vssadmin.exe delete shadows is an absolute bare minimum
58d ago
Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack
58d ago
How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers
58d ago
CVE-2026-48029: Two grid-decode bugs in libheif
58d ago
workcell: Bounded local runtime and policy boundary for coding agents
58d ago
OpenShell: OpenShell is the safe, private runtime for autonomous AI agents.
58d ago
Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation
58d ago
Built a SOC from scratch with no prior SOC experience
58d ago
CTO at NCSC Summary: week ending May 24th
59d ago
VPN Exploitation When Patched Doesn't Mean Protected
59d ago
Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation
59d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
59d ago
CLR-Stomp: .NET CLR-Stomping
59d ago
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
59d ago
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms
59d ago
Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor
59d ago
AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22)
60d ago
GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks.
60d ago
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
60d ago
Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL?
60d ago
I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner
60d ago
AI-generated reporting: Lessons learned from Cisco Talos Incident Response
60d ago
CrabLoader: A PoC Cobalt Strike UDRL written in Rust
60d ago
The 429 Microsoft Graph Mystery
60d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
60d ago
Azure Tenant Enumeration is Dead
60d ago
A Deep Dive into Codex Windows Sandbox
60d ago
Striga: Lifting x86 to LLVM IR with Python
60d ago
veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker.
60d ago
Windows BitLocker Security Feature Bypass Vulnerability
60d ago
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
60d ago
Google API keys keep working after you delete them long enough to be exploited
60d ago
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
60d ago
North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT
60d ago
Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit
60d ago
Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names)
60d ago
Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
60d ago
Megalodon: CI/CD Malware Spreading Across GitHub Repositories
60d ago
📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity.
61d ago
Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
61d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
61d ago
beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA
61d ago
Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading
61d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
61d ago
Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign
61d ago
From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree
61d ago
How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102)
61d ago
Iran-linked Operators Suspected in ATG Breaches
61d ago
Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs
61d ago
Compromised Nx Console version 18.95.0
61d ago
CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
61d ago
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
61d ago
Webworm: New burrowing techniques
61d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
61d ago
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
61d ago
Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation
61d ago
GitHub’s Fake Engagement Problem Is Hiding in Plain Sight
61d ago
Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR)
61d ago
Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage
61d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
62d ago
5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready
62d ago
Remote Process Read Primitive via NtCreateThreadEx Exit Code
62d ago
aimap: Discover Exposed AI Services
62d ago
FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation.
62d ago
Why China Is Now a Peer Competitor to the United States in Cyberspace
62d ago
nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings
62d ago
Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt
62d ago
We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.
62d ago
Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings)
62d ago
Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
62d ago
Eight Leading U.S. Communications Firms Form C2 ISAC
62d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
62d ago
UAC-0184: From HTA to a Signed Network Stack
63d ago
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
63d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
63d ago
Entra ID: PIM for Groups Review
63d ago
TeamPCP compromises NPM maintainer with over 540 packages
63d ago
Active Supply Chain Attack Compromises @antv Packages on npm...
63d ago
When DMCA Comes Knocking - A YouTube Creator Phishing Kit
63d ago
[Cloudflare] Project Glasswing: what Mythos showed us
63d ago
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
63d ago
Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger
64d ago
Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics
64d ago
CrystalX: unpacking a Go RAT through three encrypted layers
64d ago
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write
64d ago
FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation
65d ago
LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying"
65d ago
Static Kitten APT Adversary Simulation
65d ago
Eimeria: five layers from RAR5 to RunPE
65d ago
ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
65d ago
openDCIM exploitation
65d ago
HASBL CTF - A Jeopardy-Style CTF Organized by High School Students!
65d ago
We Have Packet Capture at Home
65d ago
Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware
65d ago
HWMonitor Trojanized for STX RAT DLL Sideloading
65d ago
awesome-dfir-skills: Admiralty System for CTI Claude skill
65d ago
Mullvad exit IPs as a fingerprinting vector
65d ago
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
65d ago
Popular node-ipc npm Package Infected with Credential Steale...
65d ago
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
65d ago
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
65d ago
Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
65d ago
Sandworm Activity in Industrial Environments: What the Data Reveals
65d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
65d ago
"Shadowserver-in-a-box" IntelMQ + ELK Solution
65d ago
Stenloader: Steganography Shellcode Loader
65d ago
AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out
65d ago
Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018
65d ago
Our response to the TanStack npm supply chain attack
65d ago
QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026).
65d ago
We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase.
65d ago
APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox.
65d ago
oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday
65d ago
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations
65d ago
OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance
65d ago
The Gentlemen Ransomware Group — Leak Analysis
65d ago
HDD Firmware Hacking Part 1
66d ago
ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.
66d ago
CTO at NCSC Summary: week ending May 17th
66d ago
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
66d ago
Developer credential-theft campaign exposed operator-side self-infection
66d ago
Help-Desk Lures Drop KongTuke's Evolved ModeloRAT
66d ago
Welcome to BlackFile: Inside a Vishing Extortion Operation
66d ago
DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era
66d ago
Stop Being Weird — Life After Call Stack Spoofing Under CET
66d ago
Triggering the Secure Boot Certificate Update with Intune Remediations
66d ago
How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache
66d ago
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
66d ago
One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities
66d ago
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
66d ago
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
66d ago
FamousSparrow APT Targets Azerbaijani Oil and Gas Industry
66d ago
Disclosing new PebbleDash-based tools by Kimsuky
66d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
66d ago
Kazuar: Anatomy of a nation-state botnet
66d ago
OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments
66d ago
NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys
66d ago
Hacker Ringleader Extradited for 38 Billion Won Theft
66d ago
Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System
66d ago
Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit
66d ago
The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation
66d ago
FFFFirefox - A One-Day Wonder Renderer Exploit
66d ago
MiniPlasma, a powerful LPE
66d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
67d ago
[Tool] IOCX — deterministic static IOC extraction for PE binaries
67d ago
Novel Evilginx Frontend - Lowering the barrier for token theft reuse
67d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
67d ago
WAF Evasion Engine
67d ago
Thus Spoke…The Gentlemen
67d ago
KQLab - open-source query manager for SOC teams
68d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown
68d ago
Microsoft AntiSSRF
68d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
68d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
68d ago
How fast is autonomous AI cyber capability advancing?
68d ago
YellowKey: YellowKey Bitlocker Bypass Vulnerability
68d ago
Tinker Tailor Soldier: Paper Werewolf’s latest toolkit
68d ago
126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies
68d ago
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
69d ago
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise
69d ago
[HOMELAB] Built a SOC investigation console on two old Dell boxes
69d ago
Android Intrusion Logging as a new source of data for consensual forensic analysis
69d ago
Shai-Hulud: Another Wave and Going Open Source
69d ago
A stealth approach to Process Injection - EntryPoint Hijacking
69d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
69d ago
Service Principal Sign-Ins: A blind spot that a lot are missing
69d ago
My Analysis of a Bandook RAT PCAP
69d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
69d ago
Detection Rule is here
69d ago
Owning a service principal equals owning its permissions.
69d ago
Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection
69d ago
CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.
69d ago
AI+DFIR Challenge: Share Your Disasters and Successes
70d ago
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
70d ago
Postmortem: TanStack npm supply-chain compromise
70d ago
bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages
70d ago
rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions
70d ago
Detecting Remote Thread Creation with Windows Driver
70d ago
Mythos finds a curl vulnerability
70d ago
Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details
70d ago
Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
70d ago
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
70d ago
esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app
70d ago
LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors.
70d ago
How Cloudflare responded to the “Copy Fail” Linux vulnerability
70d ago
I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic.
70d ago
LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots.
70d ago
New Shai-Hulud npm worm variant
70d ago
EtwWatcher
70d ago
Donuts and Beagles: Fake Claude site spreads backdoor
71d ago
Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach
71d ago
CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection
71d ago
Deterministic PE Validation for Blue Teams - IOCX v0.7.3
71d ago
Delving deep into threat detection: My logic for abnormal EventID 7 activity
71d ago
NZ announces sanctions on malicious Russian cyber actors, online platforms
71d ago
Update: Ongoing Checkmarx Supply Chain Security Incident
71d ago
ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025
71d ago
Unmanaged PowerShell Execution: Hunting Beyond powershell.exe
71d ago
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign
71d ago
Static Devirtualization of Themida
71d ago
Now You See Me: AADGraphActivityLogs
71d ago
[Write-up] CyberDefenders: Wiredive Lab
72d ago
page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
72d ago
JDownloader — Website installer incident (May 2026)
72d ago
The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate."
72d ago
AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT
72d ago
EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine)
72d ago
Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers
72d ago
Writing a Naive LLVM-based Devirtualizer
72d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
72d ago
When prompts become shells: RCE vulnerabilities in AI agent frameworks
73d ago
Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus
73d ago
MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174)
73d ago
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor
73d ago
Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles.
73d ago
Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026
73d ago
Member of Prolific Russian Ransomware Group Sentenced to Prison
73d ago
EasterBunny: advanced espionage artifacts attributed to APT29
73d ago
Tracking the "Sorry" Extortionist Campaign Against cPanel Websites
73d ago
PositiveIntent: Evasive loader for .NET Framework assemblies
73d ago
The Accidental C2: Exploring Dev Tunnels for Remote Access
73d ago
Living of the Land - DISM Sandbox Provider Hijack
73d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
73d ago
CTO at NCSC Summary: week ending May 10th
73d ago
ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure
73d ago
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
73d ago
Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo
73d ago
DARWIS Taka - Web vulnerability scanner with Optional AI Validation
73d ago
SunnyDayBPF: eBPF telemetry integrity research for detection engineering
73d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama
74d ago
Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou...
74d ago
Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack
74d ago
Dirty Frag: Universal Linux LPE
74d ago
Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication.
74d ago
Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea
74d ago
Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia
74d ago
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI
74d ago
Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC
74d ago
Detecting BEC Persistence with KQL
75d ago
Unpacking Russian-Iranian Private-Sector Cyber Connections
75d ago
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
75d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
75d ago
Inadvertent Injections
75d ago
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
76d ago
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
76d ago
Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed
76d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
76d ago
UAT-8302 and its box full of malware
76d ago
CVE-2026-0073 Android adbd TLS client-authentication bypass
76d ago
One KQL query you should have saved in your toolkit (most don’t)
76d ago
CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier?
76d ago
Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside
76d ago
🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records
77d ago
Popular DAEMON Tools software compromised
77d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
77d ago
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
77d ago
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
77d ago
Accelerating Vulnerability Detection and Response at Oracle
77d ago
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
77d ago
GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated.
77d ago
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
77d ago
N-Day Research with AI: Using Ollama and n8n
77d ago
38 CVEs in Healthcare Software Used by 100,000 Medical Providers
78d ago
Recursively fuzzing MS-RPC structures and monitoring using ETW
78d ago
VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases
78d ago
CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation.
78d ago
《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition)
78d ago
nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution.
78d ago
蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery.
78d ago
gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives
78d ago
Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon
78d ago
AMSI Page Guard Bypass (Rust PoC)
78d ago
Meet Bluekit: The AI-Powered All-in-One Phishing Kit
78d ago
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
78d ago
A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia
78d ago
IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect
78d ago
Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
78d ago
ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution…
78d ago
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
78d ago
[2603.28728] Study of Post Quantum status of Widely Used Protocols
78d ago
Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin
78d ago
Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning
78d ago
code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.
78d ago
Secure Boot Inventory Data In Configuration Manager
78d ago
EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time.
78d ago
MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning.
78d ago
AI-powered honeypots: Turning the tables on malicious AI agents
78d ago
copy.golf — golf your exploits - smaller copy.fail exploits..
78d ago
DragonBreath: Dragon in the Kernel
78d ago
Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors.
79d ago
Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
79d ago
Puzzle: Set of PoC to abuse Windows minifilters functionality
79d ago
A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16
79d ago
Active exploitation of cPanel/WHM critical vulnerability
79d ago
Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. "
79d ago
5 Qilin ransomware servers exposed over 7 months
79d ago
South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)
79d ago
Russian Charged in Oil and Gas Facility Hacks Pleads Guilty
79d ago
VECT ransomware: small files decrypt, large files lose their nonces
80d ago
CTO at NCSC Summary: week ending May 3rd
80d ago
April 27th - What happened with our feature flag configuration | The ClickUp Blog
80d ago
Blog: Evolving the Android & Chrome VRPs for the AI Era
80d ago
Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.
80d ago
VECT: Ransomware by design, Wiper by accident
80d ago
VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built.
80d ago
Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison
80d ago
Agentic Malware Analysis: From Task Automation to Deep Analysis
80d ago
pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner.
80d ago
month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only
80d ago
603 loaded
MA
Malware Analysis & Reports
40d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
40d ago
ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper
41d ago
WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap
41d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
41d ago
Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment
43d ago
73 Microsoft GitHub repositories impacted by Miasma malware
43d ago
Unauthorized Onlyfans Payment
43d ago
Building A Malware Lab From Scratch Part 2!
45d ago
Detecting npm Native Addon Malware: node-gyp Abuse
45d ago
Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links
46d ago
Extremely suspicious behaviour by memu emulator
47d ago
Malware
47d ago
🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop
48d ago
ChatGPT Malvertising Campaign
48d ago
Recommendation
48d ago
Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6!
48d ago
This is a scam and probably a malware/trojan. Path Of Exile 2 builder ...
49d ago
LLMShare: using shared chatbot pages to distribute malware
49d ago
How to Unpack FlawedAmmyy - Malware Unpacking Tutorial
50d ago
Building A Malware Lab From Scratch!
51d ago
I bought an old phone from 2018 and wanna destroy it with viruses for fun
52d ago
Malware escaped browser without downloading files, then escaped a virtual machine
52d ago
I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but
53d ago
A Deeper Look at GLASSWORM's Solana Variant
54d ago
Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15
54d ago
Kali365 Activity Surges: Device Code Phishing Is Scaling Fast
55d ago
MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
55d ago
Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io)
55d ago
Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down.
56d ago
How random program can cause most of antiviruses close himself without telling himself to close
56d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
56d ago
Suspicious ass website asking to run a terminal command (MacOS)
57d ago
Harvard and 140 other legitimate websites compromised
60d ago
Browser session theft is quietly becoming more dangerous than password theft
60d ago
Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
60d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account
61d ago
Database of Malicious Browser Extensions
61d ago
I’ve got 99 problems, and IOCX isn’t one.
61d ago
Can't access anything
62d ago
New GMKtec M7 Ultra appears to be infected. Beware of the malware!
63d ago
vpn explained the simple version that actually makes sense
63d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
64d ago
Netmirror exposed - The Free Movie App That Was Robbing You Blind
64d ago
Malware learning
65d ago
Brovan: Binary user-mode emulator for x86_64
66d ago
Inspecting a DLL file trying to figure out if it really is malware
67d ago
npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output
67d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
68d ago
I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable...
68d ago
clens.io - new public threat & data intel service
69d ago
Granny’s Compromised Android Firmware
69d ago
[Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
69d ago
OS scanner that checks repos for traces of the Shai Hulud worm
69d ago
Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI
69d ago
Steam spear phishing
70d ago
Fake linked in sponsored google search
70d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
70d ago
New Shai-Hulud npm worm variant
70d ago
looking for "evil" Websites
71d ago
Deterministic PE Structural Validation in IOCX v0.7.3
71d ago
sl1nk link
71d ago
How to download a RAT for myself
71d ago
Wtf OPEN Ai
73d ago
JDownloader's official website delivered Python RAT
74d ago
An unknown malware threat. There is no such thing as a 100% detection.
75d ago
Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites
75d ago
Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML
76d ago
Discord bot C2 infrastructure
76d ago
IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening
77d ago
Panicking
77d ago
Supply chain attack: DAEMON Tools Lite now contains a backdoor.
77d ago
Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation
78d ago
VirusTotal has one flag for this sus site
79d ago
Anyone wanna learn the CEH or OSCP red teaming free
79d ago
Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself
81d ago
Minecraft Malware C2 Tracking
81d ago
Minirat malware deployed via NPM targeting macOS machines
83d ago
VECT Ransomware Is Actually a Wiper
83d ago
The Malware Factory: GLASSWORM Forensics in Open VSX
83d ago
Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore
84d ago
[ Removed by Reddit ]
84d ago
Ikeja Electric Distribution Ransomware
84d ago
Recently updated a authentic minecraft mod launcher called Modrinth
84d ago
This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0
85d ago
Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely
85d ago
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses
87d ago
Save time and use Zig to write your Malware POC
87d ago
Cracking CastleLoader’s Inno Setup Password
87d ago
I built a C2 framework that uses Discord and Telegram for communication
87d ago
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet.
88d ago
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
88d ago
PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs
88d ago
Budgiekit - gdi malware maker (for educational purporses only)
89d ago
19 confirmed repos tied to the same GitHub malware campaign
90d ago
IOCX v0.7.0 — deterministic heuristics + adversarial PE samples
91d ago
I built a kernel-level EDR and hit architectural walls I didn’t expect
152d ago
Update your detection rules: New remote access Trojan
153d ago
Criminals are using AI website builders to clone major brands
153d ago
Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants)
153d ago
PE Loader For Fileless Malware
154d ago
Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers
154d ago
AWAKE - Android Wiki of Attacks, Knowledge & Exploits
154d ago
I built a Chrome extension that scans for malicious extensions (yes, I see the irony)
155d ago
Questions regarding malicious pdf's
157d ago
AV persistence bypass techniques
157d ago
Avalon Linux Bot Malware Analysis
158d ago
Leveling up in Windows malware research
159d ago
Emerging Ransomware: BQTLock and GREENBLOOD
160d ago
Malware Development POCs
160d ago
Suspicious code in Up-work linked repository.
160d ago
We hid backdoors in binaries — Opus 4.6 found 49% of them
161d ago
👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡
162d ago
Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions
162d ago
Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer
164d ago
Nyxara
166d ago
115 loaded
SM
Security | Microsoft Azure Blog | Microsoft Azure
49d ago · 6 items
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
49d ago
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
78d ago
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
82d ago
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
Azure IaaS: Keep critical applications running with built-in resiliency at scale
111d ago
Learn how Azure IaaS helps organizations start from a resilient platform foundation with availability, continuity, and recovery capabilities.
Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure
139d ago
Learn how Azure IaaS helps you modernize infrastructure, improve performance and resilience, optimize costs, and prepare for AI workloads. Read more.
Azure reliability, resiliency, and recoverability: Build continuity by design
154d ago
Learn how Azure reliability, resiliency, and recovery capabilities work together to improve cloud continuity. Read more.
SK
STÖK
58d ago · 15 items
☔️🌅
58d ago
Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs
331d ago
Winter vanlife = good times
933d ago
What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth!
939d ago
Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma
946d ago
IS THIS THE END?
1006d ago
Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites
1160d ago
How to turn bugs into a "passive" income stream! ft Detectify's Almroot
1401d ago
HOW DID THIS HAPPEN!? (13370822 LHE VLOG)
1414d ago
Q: How to write a BUG BOUNTY report that actually gets paid?
1531d ago
facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques..
1545d ago
Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!)
1559d ago
Q: HOW do you get started in bug bounty?? How do you build your automation?!
1573d ago
Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR)
1587d ago
BOUNTY THURSDAYS - LIVE #2 (NEWS/TOOLS and Community Questions with Jason Haddix)
1601d ago
15 loaded
ZU
ZDI: Upcoming Advisories
82d ago · 1 items
DE
DEFCONConference
83d ago · 15 items
DEF CON 34 - DEF CON Policy Announcement - Katie Noble, Heather West
83d ago
DEF CON 33 - DisguiseDelimit: Exploiting Synology NAS with Delimiters and Novel Tricks - Ryan Emmon
152d ago
DEF CON 33 - Browser Extension Clickjacking: One Click and Your Credit Card Is Stolen - Marek Tóth
152d ago
DEF CON 33 - Can't Stop the ROP: Automating Universal ASLR Bypasses - Bramwell Brizendine
152d ago
DEF CON 33 Recon Village - How to Become One of Them: Deep Cover Ops - Sean Jones, Kaloyan Ivanov
202d ago
DEF CON 33 Recon Village - Inside the Shadows Tracking RaaS Groups, Cyber Threats - John Dilgen
202d ago
DEF CON 33 Recon Village - Autonomous Video Hunter AI Agents for Real Time OSINT - Kevin Dela Rosa
202d ago
DEF CON 33 Recon Village - A Playbook for Integration Servers - Ryan Bonner, Guðmundur Karlsson
202d ago
DEF CON 33 Recon Village - Mapping the Shadow War From Estonia to Ukraine - Evgueni Erchov
202d ago
DEF CON 33 Recon Village - Building Local Knowledge Graphs for OSINT - Donald Pellegrino
202d ago
DEF CON 33 Recon Village - OSINT & Modern Recon Uncover Global VPN Infrastructure - Vladimir Tokarev
202d ago
DEF CON 33 Recon Village - Pretty Good Pivot - Simwindie
202d ago
DEF CON 33 Recon Village - enumeraite: AI Assisted Web Attack Surface Enumeration - Özgün Kültekin
202d ago
DEF CON 33 Recon Village - OSINT Signals Pop Quiz - Master Chen
202d ago
DEF CON 33 Recon Village - Investigating Foreign Tech from Online Retailers - Michael Portera
202d ago
15 loaded
CC
CISA Cybersecurity Advisories
91d ago · 2 items
Defending Against China-Nexus Covert Networks of Compromised Devices
91d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
106d ago
U.S. organizations should review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the
BA
Blog Articles - Identity Insights | Trulioo
96d ago · 13 items
Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business
96d ago
What is Customer Due Diligence (CDD)
120d ago
Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud
122d ago
AML, KYC and Identity Verification in Australia
131d ago
When Fraud Becomes Background Noise: The Industrialization of Digital Deception
197d ago
The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage
197d ago
The End of Static KYB: Business Identity in Constant Motion
197d ago
Know Your Agent: The Next Chapter in Digital Trust
197d ago
When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage
197d ago
Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration
216d ago
The World’s Identity Platform
1267d ago
KYC: 3 Steps to Achieving Know Your Customer Compliance
1538d ago
AML Compliance Checklist: Best Practices for Anti-Money Laundering
1553d ago
13 loaded
II
InfoSec Insights
132d ago · 1 items
FP
Fraud Prevention Archives - Alloy Silverstein
138d ago · 10 items
AI in Tax Season: Risks, Scams, and How to Protect Your Data
138d ago
Tax Season Scams to Watch For This Year
145d ago
Beware of Misleading Tax Advice on Social Media
313d ago
Each year the IRS educates taxpayers on the most trending fraud schemes that could deceive individuals and businesses during tax season. In late 2024, The IRS took to warning the public against misleading “tips” or...
Scammers Up Their Game With AI
315d ago
Learn how to spot the threats and protect yourself from scammers using AI for phishing and deepfakes with smart security practices.
The Essential Guide to Safeguarding Your Online Passwords
392d ago
Protect your personal and business data with strong passwords, two-factor authentication, and smart cybersecurity practices.
Beware: Tax Season is Scam Season
503d ago
Tax season is also prime time for tax scams. To safeguard your personal information, consider these key points: Communication methods The IRS initiates contact primarily through mail, not email or phone calls. Be cautious of...
Stop Scams: Fraud Prevention Starts with Your Employees
516d ago
You can be as proactive and protective as possible when it comes to cyber security for your business, but there’s one vulnerability you cannot eliminate: human error. In fact, statistics estimate that as much as...
‘Tis the Season for Holiday Shopping Scams
589d ago
The holidays are typically the time of year for gifting presents to friends and family or donations to charity. Unfortunately, not-so-jolly fraudsters take advantage of this generosity. Protect yourself by watching for these common scams:.....
IRS Issues “Dirty Dozen” Fraud Warnings
774d ago
Each year, the IRS releases a “Dirty Dozen” series to highlight the most common fraud schemes taxpayers should be aware of.
IRS Identity Theft Season Begins Now
903d ago
Each year thieves try to steal billions in federal withholdings by stealing your identity. As the IRS focuses more attention on this quickly growing problem, now is the time of year to be extra vigilant....
LI
LiveOverflow
139d ago · 15 items
Security-driven Rapid Release - Pwn2Own Documentary (Part 4)
139d ago
Firefox JIT Bug - Pwn2Own Documentary (Part 3)
142d ago
The First Exploit - Pwn2Own Documentary (Part 2)
146d ago
The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)
149d ago
From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi
468d ago
The German Hacking Championship
494d ago
Do you know this common Go vulnerability?
508d ago
Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1)
643d ago
My theory on how the webp 0day was discovered #short
659d ago
My theory on how the webp 0day was discovered (BLASTPASS)
660d ago
Learn Android Hacking! - University Nevada, Las Vegas (2024)
686d ago
My Trip to Las Vegas for DEFCON & Black Hat
700d ago
Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
911d ago
A Vulnerability to Hack The World - CVE-2023-4863
943d ago
Reinventing Web Security
973d ago
15 loaded
HA
HackerSploit
468d ago · 15 items
How FIN6 Exfiltrates Files Over FTP
468d ago
Emulating FIN6 - Active Directory Enumeration Made EASY
519d ago
The SECRET to Embedding Metasploit Payloads in VBA Macros
524d ago
Offensive VBA 0x4 - Reverse Shell Macro with Powercat
532d ago
Offensive VBA 0x3 - Developing PowerShell Droppers
538d ago
Offensive VBA 0x2 - Program & Command Execution
543d ago
Offensive VBA 0x1 - Your First Macro
545d ago
Emulating FIN6 - Gaining Initial Access (Office Word Macro)
550d ago
FIN6 Adversary Emulation Plan (TTPs & Tooling)
554d ago
Developing An Adversary Emulation Plan
554d ago
Introduction To Advanced Persistent Threats (APTs)
558d ago
Introduction To Adversary Emulation
580d ago
Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion
589d ago
Planning Red Team Operations | Scope, ROE & Reporting
729d ago
Mapping APT TTPs With MITRE ATT&CK Navigator
733d ago
15 loaded
TH
Threatpost
1420d ago · 10 items
Student Loan Breach Exposes 2.5M Records
1420d ago
2.5 million people were affected, in a breach that could spell more trouble down the line.
Watering Hole Attacks Push ScanBox Keylogger
1421d ago
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
1422d ago
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Ransomware Attacks are on the Rise
1425d ago
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
1426d ago
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Twitter Whistleblower Complaint: The TL;DR Version
1427d ago
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Firewall Bug Under Active Attack Triggers CISA Warning
1428d ago
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Fake Reservation Links Prey on Weary Travelers
1429d ago
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
iPhone Users Urged to Update to Patch 2 Zero-Days
1432d ago
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Google Patches Chrome’s Fifth Zero-Day of the Year
1433d ago
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
No matching sources found.