Flock tightens privacy controls amid scandals over officer abuse
New Mirai variant adds stealth capabilities to notorious botnet code
Brazil orders Discord to suspend livestreaming after teen suicide
Trump taps cyber firms to go on offensive against criminals
Germany moves to give spy agencies hacking and sabotage powers
What's New
Top 5 Across All Sources-
Flock tightens privacy controls amid scandals over officer abuse
The Record from Recorded Future News · 1h ago -
New Mirai variant adds stealth capabilities to notorious botnet code
The Record from Recorded Future News · 1h ago
Gigafeed (5254 entries)
Flock tightens privacy controls amid scandals over officer abuse The Record from Recorded Future News · 1h ago This Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on sale Latest news · 1h ago New Mirai variant adds stealth capabilities to notorious botnet code The Record from Recorded Future News · 1h ago I wore Samsung's and Apple's Ultra smartwatches for 3 weeks - apps made all the difference Latest news · 1h ago You're using DND all wrong: 5 powerful Do Not Disturb settings to try on your iPhone today Latest news · 1h ago Trezor discloses data breach affecting nearly 14,000 customers BleepingComputer · 1h ago Cybersecurity M&A Roundup: 21 Deals Announced in July 2026 SecurityWeek · 2h ago White House authorizes private US companies to hack foreign criminal networks Help Net Security · 2h ago Adobe Commerce Bug Targeted Immediately After Disclosure SecurityWeek · 2h ago Black Hat Stories | Daniel Cuthbert Black Hat · 2h ago Phishing Gets Personal John Hammond · 3h ago Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion BleepingComputer · 3h ago CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-65796 Windows iSCSI Target Service Denial of Service Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62902 .NET Information Disclosure Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-70354 .NET Core Remote Code Execution Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62871 .NET Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62886 .NET Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-45593 Windows SDK Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability MSRC Security Update Guide · 3h ago DataGrout helps enterprises control AI usage, governance and LLM costs Help Net Security · 3h ago Brazil orders Discord to suspend livestreaming after teen suicide The Record from Recorded Future News · 3h ago Microsoft is merging Copilot and Copilot 365 into one unified app - and retiring 3 features Latest news · 3h ago White House taps security firms for offensive hack-back operations BleepingComputer · 3h ago Trump taps cyber firms to go on offensive against criminals The Record from Recorded Future News · 3h ago A10 Networks introduces AI Gateway to secure and manage enterprise AI Help Net Security · 3h ago Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) Help Net Security · 4h ago I Made AI Build a Cybersecurity Mod in Minecraft John Hammond · 4h ago WordPress 7.0.4 Patches Remote Code Execution Vulnerability SecurityWeek · 4h ago Germany moves to give spy agencies hacking and sabotage powers The Record from Recorded Future News · 4h ago 75% of developers I surveyed prefer Claude Code - here's why they choose it over Codex Latest news · 5h ago WhatsApp rolls out new feature that flags potential scam messages BleepingComputer · 5h ago Venture Firm Team8 Secures Additional $365 Million SecurityWeek · 5h ago Android can now tap to share for contact info, photos, and more - which phones get it first Latest news · 5h ago Fortinet Patches Authentication Flaws in FortiWeb and FortiManager SecurityWeek · 6h ago Searchlight Cyber combines exposure and threat intelligence in new PTEM platform Help Net Security · 6h ago 153GB of stolen credentials surface after LiteLLM supply chain attack Help Net Security · 6h ago White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs SecurityWeek · 7h ago CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues Security Latest · 7h ago Critical VMware vCenter Vulnerability in Attackers’ Crosshairs SecurityWeek · 8h ago The best antivirus software to protect your computer in 2026 Latest news · 8h ago The best password managers of 2026: Expert tested Latest news · 8h ago Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ SecurityWeek · 8h ago Armored Likho expands its cyber-espionage toolkit Securelist · 9h ago Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) Help Net Security · 9h ago Attackers Exploit SharePoint Authentication Bypass After Public PoC Release The Hacker News · 10h ago Four corporate investigation mistakes organizations make under pressure Help Net Security · 12h ago DDoS attacks hit record scale as 1 Tbps+ campaigns become more common Help Net Security · 12h ago Product showcase: Is this image real? Slop or Not investigates Help Net Security · 13h ago 'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today Latest news · 16h ago Malware Crypting Services and the Threat Actors Who Sell Them Recorded Future · 17h ago "City-Forum" data-theft attacks target Salesforce, ServiceNow portals BleepingComputer · 17h ago Android malware combo takes out loans and relays victims' credit cards BleepingComputer · 18h ago Terabytes of credentials leaked in massive supply-chain attack Security - Ars Technica · 19h ago Hackers exploit critical Adobe Commerce flaw to hijack customer accounts BleepingComputer · 20h ago Hundreds of fake Chrome VPN extensions route traffic through a proxy BleepingComputer · 22h ago Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor The Hacker News · 23h ago Every Amazon Google Pixel 11 preorder deal - get up to $350 on an Amazon gift card, free Latest news · 23h ago Sparky Linux just restored 32-bit support - why that still matters Latest news · 23h ago Plug and Pwn attack uses fake USB devices for Windows SYSTEM access BleepingComputer · 1d ago Cisco Advance Notification for Publication of August 19, 2026, Security Advisories Cisco Security Advisory · 1d ago Lazarus hackers exploited Windows zero-day to target defense firms BleepingComputer · 1d ago Hackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare Latest news · 1d ago Every Pixel 11 deal at T-Mobile right now: Trade-in offers, free phones with new line, and more Latest news · 1d ago How to preorder every new Google Pixel device - and the best deals I found Latest news · 1d ago SharePoint Vulnerability Exploited Shortly After PoC Release SecurityWeek · 1d ago The Pixel Tag is Google's $29 AirTag alternative - with one big advantage Latest news · 1d ago The best Pixel 11 and Pixel 11 Pro cases of 2026: Expert recommended Latest news · 1d ago Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP Latest news · 1d ago FBI: Hackers target online accounts to steal nude photos BleepingComputer · 1d ago 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One The Hacker News · 1d ago The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In BleepingComputer · 1d ago Pixel Watch 4 vs. Pixel Watch 5: Buy the old Android smartwatch or opt for the newest? Latest news · 1d ago Google Pixel 11 vs. Pixel 9: Why the Pixel 11 is actually worth upgrading Latest news · 1d ago AT&T will give you the new Google Pixel 11 Pro for free with trade-in - any year, any condition Latest news · 1d ago Black Hat Stories | More Than a Conference Black Hat · 1d ago Researchers found a way to hijack devices through Zoom screen sharing Security - Ars Technica · 1d ago Black Hat USA 2026: AI is racing ahead of cybersecurity controls WeLiveSecurity · 1d ago Mindgard Raises $30 Million to Protect AI Systems SecurityWeek · 1d ago I Found an MFA-Bypassing Phishing Kit on the Dark Web John Hammond · 1d ago I Went to the World's Biggest Hacker Conference (DEFCON VLOG) NahamSec · 1d ago Hackers leverage new Microsoft SharePoint exploit in attacks BleepingComputer · 1d ago This Coin-Sized Device Can Hack a Boeing 737 Security Latest · 1d ago OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning The Hacker News · 1d ago Enterprise Defenses Recovered at the Edge and Collapsed Inside The Hacker News · 1d ago Signal adds new security feature to thwart man-in-the-middle attacks BleepingComputer · 1d ago Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws The Hacker News · 1d ago New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges BleepingComputer · 1d ago ‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware Security Latest · 1d ago Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access The Hacker News · 1d ago Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations The Hacker News · 1d ago SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code The Hacker News · 1d ago ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access The Hacker News · 1d ago Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS The Hacker News · 1d ago Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse BleepingComputer · 1d ago DEF CON crowd suspected in fake-hotspot attack on Delta flight Security - Ars Technica · 1d ago Three Decades of Influence | Why Black Hat Matters Black Hat · 1d ago DeadLock ransomware uses blockchain to resist infrastructure takedown BleepingComputer · 1d ago Microsoft Plugs Nearly 400 Security Holes Krebs on Security · 1d ago Black Hat Stories | Gaurav Keerthi, CEO and founder of StrongKeep Black Hat · 1d ago Sandworm hackers target IT pros with trojanized WireGuard VPN client BleepingComputer · 1d ago Chrome adopts what may be the best protection yet against account takeovers Security - Ars Technica · 1d ago Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack The Hacker News · 1d ago Cisco warns of ASA and FTD VPN flaw exploited to crash devices BleepingComputer · 1d ago Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing The Hacker News · 1d ago Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client The Hacker News · 1d ago Cisco Secure Firewall Management Center Software Static Credential Vulnerability Cisco Security Advisory · 1d ago Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands The Hacker News · 1d ago Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees BleepingComputer · 1d ago Microsoft releases Windows 10 KB5120249 extended security update BleepingComputer · 1d ago DEF CON 34 - Video Team - Hackers dot Town - The Gibson DEFCONConference · 1d ago DEF CON 34 - Video Team - Car Hacking Villlage DEFCONConference · 1d ago DEF CON 34 - Video Team - Ham Radio Village - Marvin Goes HAM DEFCONConference · 1d ago Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days BleepingComputer · 1d ago DEF CON 34 - Video Team - Physical Security Village DEFCONConference · 1d ago DEF CON 34 - Video Team - LEECH DEFCONConference · 1d ago DEF CON 34 - Video Team - EmbeddedSystems Village DEFCONConference · 1d ago DEF CON 34 - Video Team - PhreakMe DEFCONConference · 1d ago Windows 11 KB5121003 & KB5120240 cumulative updates released BleepingComputer · 1d ago Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE The Hacker News · 2d ago Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability Cisco Security Advisory · 2d ago DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The Hacker News · 2d ago Wesco confirms security incident after ExfilSquad claims data theft BleepingComputer · 2d ago Can AI Build Hacker Traps That Actually Work? John Hammond · 2d ago Mozilla updates GPG signing key for Firefox releases after exposure BleepingComputer · 2d ago Vague Task, Total Access: When AI Delegation Becomes a Security Risk BleepingComputer · 2d ago New surveillance tech links your phone to your license plate Security - Ars Technica · 2d ago OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development The Hacker News · 2d ago DDoS attacks over 1 Tbps surged fivefold in the second quarter BleepingComputer · 2d ago A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call Security Latest · 2d ago CISA: Microsoft SharePoint flaw now exploited in ransomware attacks BleepingComputer · 2d ago A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices The Hacker News · 2d ago Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo The Hacker News · 2d ago Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants Securelist · 2d ago New Pass-ta-key attack reveals all the things we didn't know about passkeys Security - Ars Technica · 2d ago Cisco warns of high-severity ClamAV flaws with public exploits BleepingComputer · 2d ago Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection Securelist · 2d ago US and South Korea warn of Gunra ransomware targeting govt agencies BleepingComputer · 2d ago Mines, Minds, and Machines: The Journey of AI Recorded Future · 2d ago Hackers breached a small Polish energy plant via private APN last year BleepingComputer · 2d ago BdThemes plugins supply-chain hack creates rogue WordPress admins BleepingComputer · 2d ago OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users BleepingComputer · 2d ago New StormEncryptor ransomware used by former Medusa affiliate BleepingComputer · 2d ago ClamAV Vulnerabilities Affecting Cisco Products: August 2026 Cisco Security Advisory · 3d ago Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise Microsoft Security Blog · 3d ago DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure Microsoft Security Blog · 3d ago CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs BleepingComputer · 3d ago A researcher bought noreply.net. Companies started sending him secrets. Security - Ars Technica · 3d ago When Credentials Are No Longer Enough: Device Trust in the AI Era BleepingComputer · 3d ago Member of The Com sent to prison for blackmail, sextortion BleepingComputer · 3d ago LexisNexis shuts down services after suspicious activity on servers BleepingComputer · 3d ago Valve notifies Steam hardware customers of a data breach BleepingComputer · 3d ago IT threat evolution in Q2 2026. Non-mobile statistics Securelist · 3d ago IT threat evolution in Q2 2026. Mobile statistics Securelist · 3d ago Critical Progress LoadMaster flaw now actively exploited in attacks BleepingComputer · 3d ago Are AI tutors safe for your kids? WeLiveSecurity · 3d ago The Hugging Face Hack Was Cheap Persistence at Work Recorded Future · 3d ago DEF CON 34 - Video Team - Voting Machine Hacking Village DEFCONConference · 3d ago DEF CON 34 - VideoTeam - Cliff Stoll AfterHours DEFCONConference · 3d ago Do You Need a VPN in 2026? Here’s the Truth David Bombal · 4d ago DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking DEFCONConference · 4d ago DEF CON 34 - Video Team - Hak5 - Darren Kitchen DEFCONConference · 4d ago DEF CON 34 - Video Team - AI Hacking Village - Pokemon DEFCONConference · 4d ago DEF CON 34 - Video Team - No Starch Press DEFCONConference · 4d ago DEF CON 34 - Video Team - Goon Questions -Guzi Media DEFCONConference · 4d ago DEF CON 34 - Video Team -Bug Bounty Village DEFCONConference · 4d ago HackTheBox - Helix IppSec · 5d ago Hackers breach TrueConf to trojanize client installers with backdoors BleepingComputer · 5d ago Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed Security Latest · 5d ago Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All Security Latest · 5d ago When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection Black Hat · 5d ago Black Hat USA Briefings: Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius Black Hat · 5d ago Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability Cisco Security Advisory · 5d ago Metabase SQLi zero-day exploited in customer data-theft attacks BleepingComputer · 5d ago Unlimited Technology Systems breach impacts 3.8 million people BleepingComputer · 5d ago More than half of AI-generated patches are broken CyberScoop · 5d ago Learn Fault Injection at DEF CON 2026 LiveOverflow · 6d ago Levi Strauss & Co. says hackers stole corporate data in cyberattack BleepingComputer · 6d ago Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports CyberScoop · 6d ago Real emails, hijacked payments: Two H1 2026 attack chains BleepingComputer · 6d ago North Carolina Ports confirms cyberattack disrupting operations BleepingComputer · 6d ago July 2026 CVE Landscape Recorded Future · 6d ago OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it BleepingComputer · 6d ago OSPF From Zero: Let's Build the Internet (Well...Almost) | Summer of CCNA NetworkChuck · 6d ago ClickFix attack pushes macOS infostealer for crypto theft attacks BleepingComputer · 6d ago Hackers Stalked Me by Hijacking a Smartwatch for Kids Security Latest · 6d ago Black Hat USA Opening Session: Disruption, Defense and Operational Readiness Black Hat · 6d ago Black Hat USA 2026 Opening Session: Cyber Power in the Age of AI Black Hat · 6d ago Black Hat USA 2026 Keynote: Vulnerability Research in the Agentic Age Black Hat · 6d ago Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams CyberScoop · 6d ago Black Hat USA 2026 Keynote: The End of Rare Defending When Offense Is Cheap Black Hat · 6d ago Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident Black Hat · 6d ago Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group BleepingComputer · 6d ago Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online CyberScoop · 6d ago Swiss government SharePoint breach compromised 200 accounts BleepingComputer · 6d ago Ransom Cartel creator sentenced to 16 years in prison CyberScoop · 6d ago New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes BleepingComputer · 6d ago Canadian Man Pleads Guilty in Snowflake Extortions Krebs on Security · 7d ago Meta AI model hacked a company during misconfigured cyber test BleepingComputer · 7d ago The risk awareness radar. A superpower every MSP needs to train Heimdal Security Blog · 7d ago How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore BleepingComputer · 7d ago The water sector just got it’s wake-up call. Again. CyberScoop · 7d ago OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree Security Latest · 7d ago Emerging Threats to Neurotechnology Recorded Future · 7d ago A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide Security Latest · 7d ago OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts Security Latest · 7d ago Ransom Cartel ransomware creator sentenced to 16 years in prison BleepingComputer · 7d ago Thousands of servers can be backdoored by exploiting buggy motherboard controllers Security - Ars Technica · 7d ago Canadian pleads guilty to Snowflake cloud data-theft attacks BleepingComputer · 7d ago Snowflake hacker pleads guilty, faces up to 32 years in prison CyberScoop · 7d ago Anthropic’s AI used fake identities, malware in rogue attack on GitHub project Security - Ars Technica · 7d ago DHS Wants Protesters’ Signal Group Chats Security Latest · 7d ago Hackers run khunt post-exploitation toolkit from Oracle database BleepingComputer · 7d ago The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop Security Latest · 7d ago Tom Cotton prods Treasury for tax code tweaks to modernize OT CyberScoop · 7d ago COLDCARD security audit phishing attack installs remote access tool BleepingComputer · 7d ago DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad Security Latest · 7d ago Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) Microsoft Security Blog · 8d ago Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery Security Latest · 8d ago Cisco Advance Notification for Publication of August 5, 2026, Security Advisories Cisco Security Advisory · 8d ago Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability Cisco Security Advisory · 8d ago Cisco Integrated Management Controller Cross-Site Scripting Vulnerability Cisco Security Advisory · 8d ago Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability Cisco Security Advisory · 8d ago Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability Cisco Security Advisory · 8d ago Cisco IOS XE Software SNMP Denial of Service Vulnerability Cisco Security Advisory · 8d ago Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability Cisco Security Advisory · 8d ago Cisco IOS XE Software Security Hardening Release: August 2026 Cisco Security Advisory · 8d ago Cisco Integrated Management Controller Argument Injection Vulnerabilities Cisco Security Advisory · 8d ago Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability Cisco Security Advisory · 8d ago Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 Cisco Security Advisory · 8d ago Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability Cisco Security Advisory · 8d ago CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws BleepingComputer · 8d ago From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide Microsoft Security Blog · 8d ago I’m headed to DEFCON! NahamSec · 8d ago Google Blogger locks hundreds of blogs in malware false positive BleepingComputer · 8d ago Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Security Advisory · 8d ago How AI-powered phishing killed blocklists for good BleepingComputer · 8d ago Open-source software’s archenemy TeamPCP goes back further than anyone thought CyberScoop · 8d ago AI is getting better at election facts, but voters shouldn’t rely on it CyberScoop · 8d ago National cyber director lays out White House plans to secure AI without writing new rules CyberScoop · 8d ago Hype vs. Reality: What the Hugging Face Incident Means for AI Safety Recorded Future · 8d ago ChainDrop supply chain compromise: Anatomy of a self-propagating worm Microsoft Security Blog · 8d ago OpenAI, Anthropic AI agents targeted real people and systems in cyber tests BleepingComputer · 8d ago OK, Well, Rogue AI Agents Are Hacking Again Security Latest · 8d ago AISI, OpenAI report more ‘unsanctioned’ model hacks CyberScoop · 8d ago TP-Link patches Omada ZTP flaws allowing hackers to breach networks BleepingComputer · 8d ago Phishing service spoofs RingCentral to steal Microsoft 365 accounts BleepingComputer · 8d ago New XCSSET variant targets macOS devs via compromised Xcode projects BleepingComputer · 8d ago 77 Open VSX extensions found harvesting developer info BleepingComputer · 8d ago Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps Microsoft Security Blog · 8d ago 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET Microsoft Security Blog · 8d ago Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal Security Latest · 9d ago Massive ChainDrop npm supply-chain attack infects hundreds of packages BleepingComputer · 9d ago Varonis Agent IBAC keeps AI agents within their intended boundaries BleepingComputer · 9d ago How legitimate cloud platforms enable phishers to bypass MFA Securelist · 9d ago Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats Proofpoint News Feed · 9d ago Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities Proofpoint News Feed · 9d ago Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts BleepingComputer · 9d ago New Pass-ta-key attacks let malware hijack Google-synced passkeys BleepingComputer · 9d ago Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack CyberScoop · 9d ago Does AI Content Have to be Authentic — or Can It Just Be Effective? Blog – Forter · 9d ago New DOUBLECUP ClickFix service hides malware in browser cache images BleepingComputer · 9d ago Fake Roblox Xeno script launcher pushes infostealer, RAT malware BleepingComputer · 9d ago N-able warns of N-central auth bypass flaw exploited in attacks BleepingComputer · 10d ago ExfilSquad hackers leak info of over 100,000 UK police officers, staff BleepingComputer · 10d ago Inside the Underground Business of the Android BTMOB RAT malware BleepingComputer · 10d ago Cyber Deception Everywhere John Hammond · 10d ago An analysis of incidents at Brazilian educational institutions Securelist · 10d ago Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS) NahamSec · 10d ago ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children Security Latest · 10d ago CrowdStrike: AI is now both the weapon and the target in cyberattacks CyberScoop · 10d ago Are you ready for this year's @BugBountyVillage at @DEFCONConference NahamSec · 10d ago 8 Ways AI is Changing Threat Intelligence Recorded Future · 10d ago OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems BleepingComputer · 10d ago COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft BleepingComputer · 10d ago Google Chrome may soon block New Tab hijacker extensions by default BleepingComputer · 11d ago 1.5 Gbps Internet using your old telephone cables? David Bombal · 11d ago 8 Best Password Managers (2026), Tested and Reviewed Security Latest · 11d ago HackTheBox - Kobold IppSec · 12d ago Rails patches critical Active Storage flaw with RCE potential BleepingComputer · 12d ago 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran Security Latest · 12d ago Defcon's new badge is a security key you can see inside Security - Ars Technica · 12d ago The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier Security Latest · 12d ago JHT Course Launch! Home Labs with Proxmox John Hammond · 12d ago Amgen says cloud data breach exposed patient health, proprietary info BleepingComputer · 12d ago Arch Linux disables AUR package adoption to stop malware flood BleepingComputer · 12d ago Online ad firm Adform’s script compromised to steal cryptocurrency BleepingComputer · 12d ago CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Microsoft Security Blog · 12d ago Claude published malicious code to the Internet and attacked 3 real companies Security - Ars Technica · 12d ago Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world CyberScoop · 12d ago Why Black Hat Matters | Black Hat Stories Black Hat · 12d ago Black Hat Stories | Daniel Cuthbert, Black Hat Training Review Board Member Black Hat · 12d ago OpenAI says its new GPT 5.6 models are becoming more cost-efficient BleepingComputer · 12d ago Hacker uses DeepSeek AI to autonomously attack vulnerable servers BleepingComputer · 12d ago CISA warns of cyberattacks disrupting U.S. water utilities BleepingComputer · 13d ago This month in security with Tony Anscombe – July 2026 edition WeLiveSecurity · 13d ago AI scammers outperform humans when it comes to building trust Security - Ars Technica · 13d ago ESET tracks rise in malicious AI skills and adaptable malware BleepingComputer · 13d ago The DEF CON Advice Nobody Gives You | Threat Wire Hak5 · 13d ago Do you guys agree? #hacking #bugbounty NahamSec · 13d ago Network Anomaly Detection in KATA Securelist · 13d ago What the Hugging Face breach reveals about defense in the age of agentic AI CyberScoop · 13d ago GTA Malware Trap John Hammond · 13d ago Anthropic says its AI accidentally hacked three companies during safety tests CyberScoop · 13d ago Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests BleepingComputer · 13d ago South Korea fines telco giant KT $39 million for customer data breach BleepingComputer · 13d ago JetBrains warns of critical TeamCity remote code execution flaw BleepingComputer · 13d ago Max-severity Exchange server flaw under active exploitation by Kremlin hackers Security - Ars Technica · 13d ago Okta’s deal for Permiso aims to close gaps in identity threat detection CyberScoop · 13d ago Max-severity Exchange server flaw under active exploitation by Kremlin hackers Proofpoint News Feed · 13d ago CISA issues recommendations to federal agencies on open-source software security CyberScoop · 13d ago Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers BleepingComputer · 13d ago VMware fixes three critical flaws allowing auth bypass, VM escapes BleepingComputer · 13d ago Google says AI helped Chrome fix 1,072 security bugs in two releases BleepingComputer · 14d ago Cyber War Forum: The Critical Questions No One Has Real Answers To Black Hat · 14d ago Read This Before You Buy That TV Streaming Stick Krebs on Security · 14d ago ShinyHunters claims Brinks Home breach, threatens to leak stolen data BleepingComputer · 14d ago What’s new in Microsoft Security: July 2026 Microsoft Security Blog · 14d ago Microsoft Teams vishing attacks lead to Chaos ransomware attacks BleepingComputer · 14d ago We know how to protect our troops from telecom attacks. We’re just not doing it. CyberScoop · 14d ago Analog Devices discloses data breach, says operations unaffected BleepingComputer · 14d ago OpenAI Turned Off the Guardrails | Threat Wire Hak5 · 14d ago Meet TCM Security at DEF CON 34! The Cyber Mentors · 14d ago Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims CyberScoop · 14d ago After the Break-In: What Attackers Do Once They're Already Inside BleepingComputer · 14d ago Rediscover Maltego in 2026 David Bombal · 14d ago The next measure of AI momentum is work transformed Microsoft 365 Blog · 14d ago Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes Heimdal Security Blog · 14d ago OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia Securelist · 14d ago Beyond the screenshot: Why you should verify what you see WeLiveSecurity · 14d ago How Heimdal grew from a bold idea into a global cybersecurity platform Heimdal Security Blog · 14d ago MediaArena malvertising: why a quarantine isn’t the end of the incident Heimdal Security Blog · 14d ago Toy Ghouls’ new toy: the GenieLocker ransomware Securelist · 14d ago Real Folks of Cyber | Andrew Crotty | DITL The Cyber Mentors · 14d ago Iran War’s Secondary Effects Shape 2026 US Violent Extremism Recorded Future · 14d ago Dealing with AI-Generated Extortion Recorded Future · 14d ago Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility Trend Micro Research, News, Perspectives · 14d ago Russian hackers exploit Exchange OWA zero-day for long-term mailbox access BleepingComputer · 14d ago Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission Security - Ars Technica · 14d ago Cisco warns of FMC static credential flaw exploited in zero-day attacks BleepingComputer · 14d ago A little-known npm package was North Korea’s warm-up act for the axios hack CyberScoop · 14d ago Anthropic confirms Claude is down worldwide BleepingComputer · 14d ago Supply chain challenges loom large in quantum race, White House official says CyberScoop · 14d ago Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare BleepingComputer · 14d ago Huntress warns about attack spree that hit 30 SonicWall customers in 2 days CyberScoop · 15d ago OpenAI agent used exposed credentials at 4 services in Hugging Face breach BleepingComputer · 15d ago Better security starts with better questions Microsoft Security Blog · 15d ago Black Hat Asia 2026 | Keynote: From Prompt Tricks to Autonomous Hackers Black Hat · 15d ago Anthropic is finding bugs faster than Microsoft can fix them Security - Ars Technica · 15d ago Minecraft Security Mods John Hammond · 15d ago Hackers target over 30 Minnesota water utilities in coordinated OT attack BleepingComputer · 15d ago Your AI Agents Are Guessing at Scale: Permissions Decide the Damage BleepingComputer · 15d ago Windows 11 KB5101684 update released with 42 changes and fixes BleepingComputer · 15d ago These near-mint ASUS Chromebook refurbs are only $145 BleepingComputer · 15d ago Payload Podcast 010 - Olaf Hartong John Hammond · 15d ago Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave Trend Micro Research, News, Perspectives · 15d ago We now have a better understanding how OpenAI hacked into Hugging Face Security - Ars Technica · 15d ago CubePilot drone software dev hit by DNS hijacking to intercept traffic BleepingComputer · 15d ago OpenAI models used Artifactory zero-days to escape to the internet BleepingComputer · 15d ago CISA shares advice on isolating vital systems during cyberattacks BleepingComputer · 15d ago vBulletin fixes critical pre-auth RCE flaw with public exploit BleepingComputer · 15d ago Tools Change. Teach People How to Keep Up Heimdal Security Blog · 16d ago Is Your SSO Protected Against Modern Credential Attacks? BleepingComputer · 16d ago Over 24,000 exposed server BMCs leak password hash via decades-old flaw BleepingComputer · 16d ago Data breach at medical billing firm MCBS affects 1.26 million people BleepingComputer · 16d ago Hackers target US firms in FastJson RCE zero-day attacks BleepingComputer · 16d ago Arista patches VeloCloud Orchestrator zero-day exploited in attacks BleepingComputer · 16d ago Did an AI Really Hack Hugging Face? LiveOverflow · 16d ago Microsoft unveils AI security tools it says outperform competing platforms Security - Ars Technica · 16d ago New Dysphoria DDoS botnet spreads to 200k devices worldwide BleepingComputer · 16d ago New Certighost PoC exploit lets attackers hijack Windows domains BleepingComputer · 16d ago Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin BleepingComputer · 16d ago Activist charged with felony after giving border agent "duress code" that wiped his phone Security - Ars Technica · 17d ago Coca-Cola confirms data theft in Fairlife ransomware attack BleepingComputer · 17d ago Ernst & Young data breach claimed by ShinyHunters extortion gang BleepingComputer · 17d ago Shadow AI agents are multiplying. Here's how to find and secure them. BleepingComputer · 17d ago How One File Upload Got Me the Entire Customer Database NahamSec · 17d ago Any App Notification John Hammond · 18d ago GitHub, PyPI add time-absed defenses against supply chain attacks BleepingComputer · 18d ago Qubes OS explained: assume you will get hacked David Bombal · 18d ago Steam forum ClickFix attacks infect gamers with XMRig cryptominers BleepingComputer · 18d ago Malicious sites use JavaScript to build malware in browser memory BleepingComputer · 19d ago HackTheBox - Fries IppSec · 19d ago ShinyHunters data leaks fuel $2,000 sextortion email scam BleepingComputer · 19d ago Building Fake Notifications John Hammond · 19d ago Why Being a Great Hacker Doesn't Pay Anymore NahamSec · 19d ago OpenAI confirms ChatGPT is down worldwide BleepingComputer · 19d ago CISOs vs. Boards: Myth or Misunderstanding? darkreading · 19d ago Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks CyberScoop · 19d ago OnTrac notifies customers of data breach after network hack BleepingComputer · 19d ago What syscall-layer tooling cannot see in P2P infrastructure Technical Information Security Content & Discussion · 19d ago Despite multiple takedowns, botnets continue to grow CyberScoop · 19d ago Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation darkreading · 19d ago Hermes AI agent used to automate attack on Thai Finance Ministry BleepingComputer · 19d ago Announcing the External Penetration Testing Program Pack Technical Information Security Content & Discussion · 19d ago Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts BleepingComputer · 19d ago Microsoft blames massive Microsoft 365 outage on maintenance bug BleepingComputer · 20d ago Microsoft, tech companies throw weight behind spread of open-source AI CyberScoop · 20d ago Chick-fil-A data breach affects more than 13,000 customers BleepingComputer · 20d ago Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack BleepingComputer · 20d ago Vatican's Official Prayer App Leaks 700K+ Global Users' PII darkreading · 20d ago Europol flags 4,340 URLs for removal in 'The Com' crackdown BleepingComputer · 20d ago Default Azure Automation Setting Enables Cross-Tenant Identity Takeover darkreading · 20d ago The way AI voice phishing gets demonstrated is making people worse at spotting it Technical Information Security Content & Discussion · 20d ago Man gets six years for hacking 750 women's Snapchat accounts BleepingComputer · 20d ago Clop ransomware targets Windchill, FlexPLM in data theft attacks BleepingComputer · 20d ago Europe's Multilingual Reality Exposes AI Security Gaps darkreading · 20d ago Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 Technical Information Security Content & Discussion · 20d ago Ransomware is the Scoreboard Recorded Future · 20d ago The Signs Were There: What the First Autonomous Ransomware Case Confirms Trend Micro Research, News, Perspectives · 20d ago AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA NetworkChuck · 20d ago XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search Technical Information Security Content & Discussion · 20d ago Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets darkreading · 20d ago New Dolphin X malware uses AI to rank high-value targets BleepingComputer · 20d ago Australian energy provider Origin says data breach exposes client data BleepingComputer · 20d ago Rubio restricts visas for sextortionists, cyber scammers CyberScoop · 20d ago Fake Claude app promoted by Bing ads pushes SectopRAT malware BleepingComputer · 20d ago New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors Proofpoint News Feed · 20d ago Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled Technical Information Security Content & Discussion · 20d ago this Raspberry Pi belongs on your wall NetworkChuck · 20d ago Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries CyberScoop · 20d ago Russian hackers exploit Zimbra zero-click flaw for email theft BleepingComputer · 21d ago Hackers abuse Notepad++ plugins to stealthily install malware BleepingComputer · 21d ago Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes Proofpoint News Feed · 21d ago US and allies say Russian hackers stole emails without social engineering Proofpoint News Feed · 21d ago Fake Edge Update John Hammond · 21d ago Microsoft 365 outage affects Teams, SharePoint and other services BleepingComputer · 21d ago You need to learn Maltego in 2026 David Bombal · 21d ago FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires BleepingComputer · 21d ago Open Evaluation Framework for AI Pentesting Agents on Real-World Targets Technical Information Security Content & Discussion · 21d ago Meta Logging Every Employee Keystroke | Threat Wire Hak5 · 21d ago Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA Technical Information Security Content & Discussion · 21d ago EU fines Google $1 billion for search, app store antitrust violations BleepingComputer · 21d ago New RefluXFS Linux flaw lets attackers gain root privileges BleepingComputer · 21d ago Agentic AI Challenges Progress in Confidential Computing darkreading · 21d ago The 4 best managed EDR service suppliers (and how to choose) Heimdal Security Blog · 21d ago New msaRAT malware uses Chrome, Edge browsers to route C2 traffic BleepingComputer · 21d ago ANCHOR-CI could fix 20 years of broken government-industry collaboration CyberScoop · 21d ago Microsoft working to fix Exchange Online mailbox quarantine issue BleepingComputer · 21d ago They hacked Google's AI in Seoul STÖK · 21d ago Check Point warns of SmartConsole zero-day exploited in attacks BleepingComputer · 21d ago Brazilian Banking Trojan Actively Spreading in Portugal darkreading · 21d ago TCM Course Release | New Creator | Cybersecurity | AMA The Cyber Mentors · 21d ago Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain darkreading · 21d ago TAG-195 Upgrades MaaS Ecosystem with Modular Tools Recorded Future · 21d ago 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan Trend Micro Research, News, Perspectives · 21d ago Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It Trend Micro Research, News, Perspectives · 21d ago Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure Trend Micro Research, News, Perspectives · 21d ago Flaws in Passkey Implementation Show Old Attacks Still Work darkreading · 21d ago GitHub issues $100,000 bounty for critical RCE vulnerability Technical Information Security Content & Discussion · 21d ago Upbound says hack caused $13 million in fraudulent Acima leases BleepingComputer · 21d ago Attackers Are Learning to Live Off the AI Toolchain darkreading · 21d ago Most federal cybersecurity reporting rules are duplicative, study finds CyberScoop · 21d ago South Korea discloses data breach impacting diplomats worldwide BleepingComputer · 21d ago Fake Bahrain Alert App Deploys Android Surveillance Malware darkreading · 21d ago CVE-2026-50458: Finding a UAF in the Windows Brokering File System Technical Information Security Content & Discussion · 21d ago Want To Learn (For FREE) About A Self-Driving Network? David Bombal · 21d ago What Is Visa’s DCAP? A Merchant’s Guide to Requirements, Benefits, and Rollout Blog – Forter · 21d ago Malware is targeting AI tools in software development environments CyberScoop · 21d ago Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack BleepingComputer · 22d ago OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face Security - Ars Technica · 22d ago White House accuses Chinese company of distilling Anthropic’s Fable CyberScoop · 22d ago If you pay a hacker’s ransom, chances are that they’ll come back for more Proofpoint News Feed · 22d ago When AI Attacks: OpenAI Models Autonomously Hack Hugging Face darkreading · 22d ago Top 4 Best SOC Platforms 2026 – Provider Comparison Heimdal Security Blog · 22d ago How enterprise GenAI can amplify ransomware risk — and how to contain it BleepingComputer · 22d ago I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) Technical Information Security Content & Discussion · 22d ago New InfraTrust report reveals infrastructure flaws admins should patch first BleepingComputer · 22d ago The End of TOKENMAXXING? David Bombal · 22d ago Adobe Chrome extension flaw let sites access private WhatsApp chats BleepingComputer · 22d ago CISA orders urgent action on actively exploited Langflow RCE flaw BleepingComputer · 22d ago EU Financial Institutions Leak Data Through Cookie Trackers darkreading · 22d ago Stop renting storage space — this lifetime 2TB plan is yours for $59 BleepingComputer · 22d ago Microsoft to stop Exchange 2016 / 2019 security updates in October BleepingComputer · 22d ago Chick-fil-A discloses data breach after credential stuffing attacks BleepingComputer · 22d ago Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective Proofpoint News Feed · 22d ago OpenAI says its AI models hacked Hugging Face during testing BleepingComputer · 22d ago LG to Ban Residential Proxies from Smart TV Apps Krebs on Security · 22d ago Modern Attack Vectors | Recorded Future Recorded Future · 22d ago Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass Trend Micro Research, News, Perspectives · 22d ago Police dismantle Kratos phishing platform, arrest developer BleepingComputer · 22d ago OpenAI says model test was behind Hugging Face hack CyberScoop · 22d ago FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware BleepingComputer · 22d ago Ransomware Is Accelerating, but It's Not Because of AI darkreading · 22d ago Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task darkreading · 22d ago Critical SharePoint RCE flaw exploited to steal machine keys BleepingComputer · 22d ago AI models keep getting caught cheating CyberScoop · 22d ago Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak BleepingComputer · 22d ago Hacker Turns AI Jailbreaks Into Offensive Attack Platform darkreading · 22d ago Where’s the Trump administration line on AI regulation? CyberScoop · 22d ago Critical wp2shell WordPress flaws exploited to install webshells BleepingComputer · 23d ago House intel bill includes provisions on state and local threat intelligence, election security, AI CyberScoop · 23d ago Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability Cisco Security Advisory · 23d ago North Korea’s IT worker scheme funds Russia’s war effort CyberScoop · 23d ago The Hidden CCS2 Attack Surface on EV Chargers Technical Information Security Content & Discussion · 23d ago Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) Technical Information Security Content & Discussion · 23d ago Closing the Identity Gaps in Critical Infrastructure Security BleepingComputer · 23d ago Apps targeted at US troops contain Chinese and Russian code Security - Ars Technica · 23d ago An AI Botnet John Hammond · 23d ago Choose Wisely: AI-Generated Coding Risk Varies, a Lot darkreading · 23d ago US seizes over 1,000 websites in FIFA World Cup piracy crackdown BleepingComputer · 23d ago Critical Palo Alto VPN bug now exploited by Qilin ransomware gang BleepingComputer · 23d ago Leaking internal headers in Flask Ninja with deserialization Technical Information Security Content & Discussion · 23d ago What the World Cup can teach us about cybersecurity resilience CyberScoop · 23d ago Microsoft shares manual fix for WSUS sync delays and timeouts BleepingComputer · 23d ago Windows LegacyHive zero-day flaw gets free, unofficial patches BleepingComputer · 23d ago Volume Is Not Risk: Making Sense of the 'Vulnpocalypse' Trend Micro Research, News, Perspectives · 23d ago Estée Lauder discloses data breach via Oracle E-Business flaw BleepingComputer · 23d ago SonicWall SMA1000 flaws exploited as zero-days to push custom malware BleepingComputer · 23d ago Hackers steal $23.7 million in crypto from Ostium in off-chain attack BleepingComputer · 23d ago 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover darkreading · 23d ago Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes BleepingComputer · 23d ago JadePuffer agentic attacks now target AI model data with ransomware BleepingComputer · 23d ago Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push darkreading · 23d ago Director of Commerce AI standards office out after three months CyberScoop · 23d ago New HollowGraph malware uses Microsoft Graph for stealthy C2 comms BleepingComputer · 23d ago Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities Cisco Security Advisory · 24d ago Crawling the Complete IPv4 Reverse DNS Space Technical Information Security Content & Discussion · 24d ago Why blocking AI models won’t stop the cyber threats they create CyberScoop · 24d ago Redirect Chain Abuse John Hammond · 24d ago An AI SOC Evaluation Guide for Security Leaders BleepingComputer · 24d ago Cybersecurity Keeps Events 'Uneventful' darkreading · 24d ago Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack Cyber Defense Magazine · 24d ago Microsoft Exchange Hacked, Five Years Later John Hammond · 24d ago Hugging Face discloses breach linked to autonomous AI agent BleepingComputer · 24d ago Microsoft confirms Windows Server Update Services sync delays BleepingComputer · 24d ago Windows KB5121767 OOB update fixes shutdowns on some Dell PCs BleepingComputer · 24d ago Critical ServiceNow code execution flaw now exploited in attacks BleepingComputer · 24d ago Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) Technical Information Security Content & Discussion · 24d ago Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 Technical Information Security Content & Discussion · 24d ago Threat Hunting: A Guide | Recorded Future Recorded Future · 24d ago I got inside FIFA’s Secret World Cup Broadcast Network NetworkChuck · 24d ago Hackers abuse ViPNet software to target Russian govt agencies BleepingComputer · 25d ago Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable Technical Information Security Content & Discussion · 25d ago wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner Technical Information Security Content & Discussion · 25d ago Update now: 7-Zip fixes RCE flaw exploitable with malicious archives BleepingComputer · 25d ago Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing Technical Information Security Content & Discussion · 25d ago WordPress Core "wp2shell" RCE flaws get public exploits, patch now BleepingComputer · 25d ago HackTheBox Logging IppSec · 26d ago Microsoft warns of surge in ACR Stealer attacks on customers BleepingComputer · 26d ago The Future of Age Verification: Your Face Never Leaves Your Device BleepingComputer · 26d ago White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination Technical Information Security Content & Discussion · 26d ago wp2shell: Pre Authentication RCE in WordPress Core Technical Information Security Content & Discussion · 26d ago Keeping private namespaces private - Quad9 blog Technical Information Security Content & Discussion · 26d ago Abbott Laboratories probes two cyber incidents amid extortion claims BleepingComputer · 26d ago Inc Ransomware Exploits SonicWall SMA Zero-Days darkreading · 26d ago Openwrt pre-auth remote root exploit Technical Information Security Content & Discussion · 26d ago HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload BleepingComputer · 26d ago The Real AI Threat Is Blind Trust darkreading · 27d ago State officials, election experts pan Trump speech: ‘This is what desperation looks like’ CyberScoop · 27d ago Ernst & Young discloses data breach after support system hack BleepingComputer · 27d ago Leading members of Scattered Spider sentenced in UK to 66 months in jail CyberScoop · 27d ago Inside the Search for "Clean" Residential Proxies for Carding BleepingComputer · 27d ago Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 Technical Information Security Content & Discussion · 27d ago Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear darkreading · 27d ago UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker Cyber Defense Magazine · 27d ago Google Bets 'Agentic Defense' Strategy Can Outpace Attackers darkreading · 27d ago New Windows LegacyHive zero-day gives hackers admin privileges BleepingComputer · 27d ago Hacking US Elections: The First Tranche of Declassified Election Integrity Documents Cyber Defense Magazine · 27d ago Windows Server 2022 reach end of mainstream support in 90 days BleepingComputer · 27d ago US charges two over laundering $43 million from investment fraud BleepingComputer · 27d ago CISA urges immediate action on actively exploited Fortinet flaws BleepingComputer · 27d ago Tracking Advanced Persistent Threat Groups | Recorded Future Recorded Future · 27d ago New ClickLock macOS malware traps users into revealing login password BleepingComputer · 27d ago Coca-Cola says Fairlife ransomware attack halts US dairy production BleepingComputer · 27d ago Agentic AI: Taming the Unpredictable darkreading · 27d ago 1M+ Emails Use Hidden Text to Dupe AI Security Filters darkreading · 27d ago Claude Chrome extension flaw lets malicious extensions trigger AI actions BleepingComputer · 27d ago Program to rotate cyber personnel through federal agencies saw little use CyberScoop · 27d ago New OkoBot framework deploys 20 payloads to steal data, crypto BleepingComputer · 27d ago Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime CyberScoop · 27d ago No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE Technical Information Security Content & Discussion · 28d ago [$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking Technical Information Security Content & Discussion · 28d ago AI Agents Broke the Security Playbook. Here's What Replaces It. BleepingComputer · 28d ago 23andMe to pay $18 million in new genetics data breach settlement BleepingComputer · 28d ago Scattered Spider members behind TfL hack get five years in prison BleepingComputer · 28d ago Inside Microsoft’s Record-Breaking 622-Bug Release Cyber Defense Magazine · 28d ago Windows 11 24H2 Home and Pro reach end of support in 90 days BleepingComputer · 28d ago CISA orders feds to patch actively exploited Oracle flaw by Saturday BleepingComputer · 28d ago Russian hackers trojanize WebEx, Zoom apps to push Starland malware BleepingComputer · 28d ago New Spirals ransomware encrypts victim network in under 24 hours BleepingComputer · 28d ago Police Disrupt a €140M Cyber Fraud Ring in Spain darkreading · 28d ago ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL Technical Information Security Content & Discussion · 28d ago AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict Recorded Future · 28d ago Dutch police bust investment fraud ring stealing over €100 million BleepingComputer · 28d ago Forgotten Bootloaders Expose Secure Boot Blind Spot darkreading · 28d ago Security researchers find stalkers abusing Chrome’s sync feature CyberScoop · 28d ago Identity Attacks Overtake Exploits as Top Ransomware Cause darkreading · 28d ago Zoom warns of critical account takeover vulnerability BleepingComputer · 28d ago SonicWall customers under threat as attackers exploit 2 zero-days CyberScoop · 28d ago Google Gemini CLI abused as a hacking agent, malware botnet operator BleepingComputer · 28d ago Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed CyberScoop · 28d ago Guten Tag, Bonjour, Hola to Our European Cyber Defenders! darkreading · 28d ago Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife darkreading · 29d ago Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook Cyber Defense Magazine · 29d ago Your Home Internet Has a New Owner | Threat Wire Hak5 · 29d ago News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations The Last Watchdog · 29d ago AsyncAPI npm packages infected with credential-stealing malware BleepingComputer · 29d ago Forget the model. When it comes to cybersecurity, it’s all about the harness CyberScoop · 29d ago Claude Flaw Automatically Sends Malicious Prompts to AI Agents darkreading · 29d ago News alert: Insignary’s on-demand SBOM verification boosts software supply chain security The Last Watchdog · 29d ago We built a vulnerability vending machine: AI tokens in, zero-days out BleepingComputer · 29d ago 2-Click Cursor Exploit Enables Dev Environment Takeover darkreading · 29d ago Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure Cyber Defense Magazine · 29d ago CISA warns admins to patch actively exploited SharePoint flaws BleepingComputer · 29d ago HN Security - My Semgrep C/C++ ruleset is ready for prime time again Technical Information Security Content & Discussion · 29d ago The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets Technical Information Security Content & Discussion · 29d ago Microsoft: Some Dell PCs shut down after recent Windows updates BleepingComputer · 29d ago (More) Unauthenticated Arbitrary Code Execution in ServiceNow Technical Information Security Content & Discussion · 29d ago 78% of CFOs Say Payment Blind Spots Increase Customer Friction PYMNTS | Fraud Prevention Archives · 29d ago Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits darkreading · 29d ago US charges alleged operators of Russian bulletproof hosting service BleepingComputer · 29d ago News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions The Last Watchdog · 29d ago Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal darkreading · 29d ago The Shift: A New Era of AI Regulation Recorded Future · 29d ago Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes darkreading · 29d ago SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now BleepingComputer · 29d ago Spanish Police take down €140 million cyber fraud ring, arrest four BleepingComputer · 29d ago 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems darkreading · 29d ago Microsoft Patches a Record 570 Security Flaws Krebs on Security · 29d ago Nearly 300 GitHub repos pose as legit software to push malware BleepingComputer · 29d ago Microsoft releases Windows 10 KB5099539 extended security update BleepingComputer · 29d ago Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days BleepingComputer · 29d ago Manage Vendor Risk in a Few Practical Steps darkreading · 29d ago Is Cat7 a SCAM? David Bombal · 29d ago Windows 11 KB5101650 & KB5099414 cumulative updates released BleepingComputer · 29d ago The Gray Area in Your Checkout Is Costing You More Than You Think Blog – Forter · 29d ago Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown BleepingComputer · 30d ago Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? darkreading · 30d ago LastPass, Bitwarden users targeted with fake security alerts BleepingComputer · 30d ago What Nacha’s amended rules mean for your ACH fraud monitoring Fraud Prevention – Riskified · 30d ago You Don't Have to Run an Exploit to Know If You're Vulnerable BleepingComputer · 30d ago OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Proofpoint News Feed · 30d ago Microsoft Entra ID gets passkeys default authentication starting September BleepingComputer · 30d ago New phishing kits target Microsoft 365 accounts, evade MFA BleepingComputer · 30d ago CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers Cyber Defense Magazine · 30d ago SAP warns of critical flaws in NetWeaver and Commerce Cloud BleepingComputer · 30d ago Smashing the ServiceNow Sandbox – Pre Authentication RCE Technical Information Security Content & Discussion · 30d ago Microsoft starts testing cleaner Windows Search without ads BleepingComputer · 30d ago US sanctions VPN, malware providers for enabling ransomware attacks BleepingComputer · 30d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 30d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 30d ago The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future Recorded Future · 30d ago Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet Trend Micro Research, News, Perspectives · 30d ago Context Bombs: Using AI Guardrails as a defensive mechanism Technical Information Security Content & Discussion · 30d ago CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC) Technical Information Security Content & Discussion · 30d ago Japan's largest taxi operator shuts systems after cyberattack BleepingComputer · 30d ago Cisco's Agents Reason Like a CCIE David Bombal · 30d ago Hackers backdoor Jscrambler npm package with infostealer malware BleepingComputer · 30d ago New CrashStealer malware poses as Apple crash reporting tool BleepingComputer · 30d ago CISA warns of actively exploited RCE flaws in Joomla extensions BleepingComputer · 31d ago Lessons Learned from CISA’s Recent GitHub Leak Krebs on Security · 31d ago Lidl discloses online shop breach after service provider hack BleepingComputer · 31d ago Breach at the Beach: Play the Ultimate Entra ID CTF BleepingComputer · 31d ago Hackers find a new trick to collect Microsoft Entra user data without raising red flags Proofpoint News Feed · 31d ago UK charges suspects linked to Russian Coms call spoofing platform BleepingComputer · 31d ago This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!) NahamSec · 31d ago The Threat Mechanism and Mitigation of Pink Vishing Campaigns Cyber Defense Magazine · 31d ago EU sanctions Russian GRU military hackers over cyberattacks BleepingComputer · 31d ago Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) Technical Information Security Content & Discussion · 31d ago US and allies warn of Russian critical infrastructure attacks BleepingComputer · 31d ago 85% of CFOs Say Automation Cuts Payments Friction PYMNTS | Fraud Prevention Archives · 31d ago Persistence via Fake AMSI Provider | Playbook & Detection Strategies Technical Information Security Content & Discussion · 31d ago OpenAI temporarily relaxes GPT-5.6 Sol usage limits BleepingComputer · 31d ago Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver Technical Information Security Content & Discussion · 31d ago Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time BleepingComputer · 31d ago RedHook Android malware now uses Wireless ADB for shell access BleepingComputer · 32d ago Install GrapheneOS Before Your Phone Becomes the Checkpoint David Bombal · 32d ago Scanning malicious websites with arbitrary number of VPN tunnels (Part 2) Technical Information Security Content & Discussion · 33d ago HackTheBox - CCTV IppSec · 33d ago Australia warns of global campaign targeting vulnerable CMS platforms BleepingComputer · 33d ago See It Once, Stop It Everywhere Cyber Defense Magazine · 33d ago 'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets BleepingComputer · 33d ago New U-Boot flaws could enable stealthy firmware attacks BleepingComputer · 33d ago Cybercriminals Targeting World Cup Fans Cyber Defense Magazine · 33d ago Innovators Spotlight: Brinqa Cyber Defense Magazine · 33d ago Ryuk ransomware member pleads guilty in the US, faces 15 years in prison BleepingComputer · 33d ago Police suspects Dutch hackers were involved in Odido breach BleepingComputer · 34d ago Progress urges ShareFile admins to shut down servers over “credible” threat BleepingComputer · 34d ago Soft Skills for the Job Market: Applying for Jobs The Cyber Mentors · 34d ago Hackers exploit critical auth bypass in Gitea Docker image BleepingComputer · 34d ago Money launderer accused of stealing seized crypto while in prison BleepingComputer · 34d ago The Cost of Delayed Patching: What Security Teams Are Missing Cyber Defense Magazine · 34d ago The Replicant in Your Directory: AI Agents and the Identity Security Gap BleepingComputer · 34d ago Invoice Fraud Is Now a Cybersecurity Exposure Cyber Defense Magazine · 34d ago Top 6 Managed Detection and Response Providers Heimdal Security Blog · 34d ago Can AI-generated adversaries break TTP-based attribution? (arXiv 2026) Technical Information Security Content & Discussion · 34d ago Zimbra urges customers to patch critical web client XSS flaw BleepingComputer · 34d ago Towards CSI: What's the best harness? (arXiv 2026) Technical Information Security Content & Discussion · 34d ago Former ransomware negotiator gets 4 years for BlackCat attacks BleepingComputer · 34d ago Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail CyberScoop · 34d ago June 2026 CVE Landscape Recorded Future · 34d ago LIVE AMA | Summer of CCNA | 07/09/2026 NetworkChuck · 34d ago OpenMandriva Linux says contributor tried to sabotage the project BleepingComputer · 34d ago Injective SDK on npm infected with cryptocurrency wallet stealer BleepingComputer · 34d ago Interpol cybercrime crackdown nets 5,800 arrests across 97 countries CyberScoop · 34d ago New Helix vishing group emerges in SharePoint data theft attacks BleepingComputer · 34d ago Microsoft expects more Windows security updates from AI-discovered flaws BleepingComputer · 35d ago New Forg365 phishing platform uses AI to target Microsoft 365 accounts BleepingComputer · 35d ago 764 splinter group leader sentenced to 40 years in jail CyberScoop · 35d ago Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities Technical Information Security Content & Discussion · 35d ago The Hidden Security Risks of Reduced Summer IT Coverage BleepingComputer · 35d ago Microsoft to retire the OWA Light client in Exchange Server BleepingComputer · 35d ago Police arrests 5,800 suspects in global anti-fraud crackdown BleepingComputer · 35d ago AssuranceAmerica data breach exposes records of 6.9 million drivers BleepingComputer · 35d ago Microsoft patches RoguePlanet Defender zero-day vulnerability BleepingComputer · 35d ago RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney Recorded Future · 35d ago Mount Royal University confirms breach as hackers claim attack BleepingComputer · 35d ago Your Payment Routing Rules Are Making Decisions Without You Blog – Forter · 35d ago Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials BleepingComputer · 35d ago Hackers exploit Roundcube flaw to spy on academic researchers BleepingComputer · 35d ago French nonprofit starts global intelligence and research hub for AI cyber threats CyberScoop · 35d ago 1 in 2 devices sold in Africa exfiltrate data to China Technical Information Security Content & Discussion · 35d ago Inside an AI coal mine security camera network powered by plaintext passwords Technical Information Security Content & Discussion · 35d ago News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI The Last Watchdog · 35d ago LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway The Cyber Mentors · 35d ago Entra passkey enrollment vishing targets Microsoft 365 users BleepingComputer · 36d ago Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches Technical Information Security Content & Discussion · 36d ago 3 Ways AI Powers Service Desk Attacks and How to Prevent Them BleepingComputer · 36d ago Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security · 36d ago DuckDuckGo browser now blocks YouTube video ads BleepingComputer · 36d ago Telco giant KDDI says data breach affects over 12 million people BleepingComputer · 36d ago CISA orders feds to prioritize patching Langflow auth bypass flaw BleepingComputer · 36d ago Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Heimdal Security Blog · 36d ago Found fast, fixed slow: The gap the AI clearinghouse must close CyberScoop · 36d ago ESET Threat Report H1 2026 WeLiveSecurity · 36d ago ESET Threat Report H1 2026 WeLiveSecurity · 36d ago Ubiquiti warns of new max severity UniFi OS vulnerability BleepingComputer · 36d ago 42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million PYMNTS | Fraud Prevention Archives · 36d ago CISA orders feds to patch max severity ColdFusion flaw by Friday BleepingComputer · 36d ago Bad Epoll: The bug missed by Mythos Technical Information Security Content & Discussion · 36d ago Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire Hak5 · 36d ago The Threat Isn’t the Frontier Model Recorded Future · 36d ago Accenture confirms breach after hacker offers stolen data for sale BleepingComputer · 36d ago Spain arrests suspected hacker linked to Russian hacktivist campaign CyberScoop · 36d ago Deepfake CSAM lawsuit against xAI, Grok expands CyberScoop · 36d ago Chinese hackers develop LONGLEASH malware to expand ORB network BleepingComputer · 36d ago Hidden backdoor in Tenda router firmware grants admin access BleepingComputer · 36d ago Spain arrests suspected member of pro-Russian hacktivist groups BleepingComputer · 37d ago GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail Technical Information Security Content & Discussion · 37d ago The GitHub Actions Attack Pattern Your CI Security Scanners Miss BleepingComputer · 37d ago Webinar tomorrow: Why modern email attacks require a new approach to defense BleepingComputer · 37d ago New Januscape Linux flaw allows VM escape on Intel, AMD devices BleepingComputer · 37d ago Microsoft to enable Windows settings backup by default for orgs BleepingComputer · 37d ago Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities CyberScoop · 37d ago BeyondTrust warns of critical flaws in remote access software BleepingComputer · 37d ago Microsoft testing new Cloud Rebuild Windows 11 recovery feature BleepingComputer · 37d ago Phishing poses as big-brand job interview to steal Google accounts BleepingComputer · 37d ago Fake IT support calls on Microsoft Teams push EtherRAT malware BleepingComputer · 37d ago Vietnam arrests suspects behind HiAnime anime piracy service BleepingComputer · 37d ago Unveiled: Cisco Deep Reasoning David Bombal · 37d ago News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk The Last Watchdog · 37d ago US Army websites defaced with pro-Kurdish sentiments, insults to Trump CyberScoop · 37d ago Sysdig clocks first documented case of agentic ransomware CyberScoop · 38d ago New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!" Technical Information Security Content & Discussion · 38d ago Software Is Now Written at the Speed of Thought. Security Isn't. BleepingComputer · 38d ago Max severity Adobe ColdFusion flaw now exploited in attacks BleepingComputer · 38d ago I Made an AI Agent That Reverses CVEs While I Sleep NahamSec · 38d ago Playing Around With ADIDNS RPC Internals Technical Information Security Content & Discussion · 38d ago Finding vulnerabilities was never the hard part CyberScoop · 38d ago Windows Service - Playbook & Detection Strategies Technical Information Security Content & Discussion · 38d ago Why Apple Hide My Email FAILS David Bombal · 39d ago Flipper Zero firmware development continues with community help BleepingComputer · 39d ago New to Linux? This is the best place to start! David Bombal · 39d ago HackTheBox - DevArea IppSec · 40d ago JadePuffer ransomware used AI agent to automate entire attack BleepingComputer · 40d ago LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud PYMNTS | Fraud Prevention Archives · 40d ago WARNING: AI tracks your face David Bombal · 40d ago NetNut proxy network disrupted, 2 million infected devices cut off BleepingComputer · 40d ago How to scale your patches without scaling your team (the patch wave) Heimdal Security Blog · 41d ago ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit BleepingComputer · 41d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 41d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 41d ago AI didn’t break patching. It showed us patching was already broken. Heimdal Security Blog · 41d ago Someone infected a spyware probe overseer with spyware CyberScoop · 41d ago Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says BleepingComputer · 41d ago Claude Fable relaunch disappoints users with nerfed performance BleepingComputer · 41d ago Fable 5 is back.....run these prompts before July 12th NetworkChuck · 41d ago FBI Seizes NetNut Proxy Platform, Popa Botnet Krebs on Security · 41d ago It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs Technical Information Security Content & Discussion · 42d ago FIFA was saved this time Technical Information Security Content & Discussion · 42d ago Alleged longstanding member of Scattered Spider extradited to US CyberScoop · 42d ago Google loses final appeal to overturn €4.1 billion EU fine BleepingComputer · 42d ago Celebrating 1 Million Subscribers on July 8th! The Cyber Mentors · 42d ago ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds BleepingComputer · 42d ago Microsoft fixes bug that removed Copilot buttons in Outlook BleepingComputer · 42d ago Cisco finally confirms attackers exploiting Unified CM flaw BleepingComputer · 42d ago CISA: Microsoft SharePoint RCE flaw now actively exploited BleepingComputer · 42d ago Opera rolls out Paste Protect feature to fight ClickFix attacks BleepingComputer · 42d ago Alleged Scattered Spider hacker extradited to the United States BleepingComputer · 42d ago 42% of Issuers Say Fraud and Disputes Are Driving Up Costs PYMNTS | Fraud Prevention Archives · 42d ago /r/netsec's Q3 2026 Information Security Hiring Thread Technical Information Security Content & Discussion · 42d ago News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks The Last Watchdog · 42d ago Medtronic notifies customers impacted by ShinyHunters data breach BleepingComputer · 42d ago FortiBleed credential-theft campaign linked to Lynx ransomware BleepingComputer · 42d ago Kubota says hackers had month-long access to network systems BleepingComputer · 42d ago ChocoPoc malware delivered via trojanized exploits on GitHub BleepingComputer · 42d ago New ChocoPoC malware targets researchers via trojanized PoC exploits BleepingComputer · 42d ago Researchers spot exploitation of another critical Oracle defect CyberScoop · 42d ago DHS confirms hackers breached HSIN info-sharing platform BleepingComputer · 42d ago Webinar: Why traditional email security is no longer enough BleepingComputer · 43d ago Hackers target Microsoft 365 accounts with 81 million login attempts BleepingComputer · 43d ago Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) Technical Information Security Content & Discussion · 43d ago Turning Indicators into Intelligence in OpenCTI with Criminal IP BleepingComputer · 43d ago US lifting export control restrictions on Anthropic’s Mythos, Fable CyberScoop · 43d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 43d ago Over 900 Oracle E-Business instances exposed to ongoing attacks BleepingComputer · 43d ago The Chaya_006 Alert: OT Edge Devices Under Fire Cyber Defense Magazine · 43d ago Microsoft fixes GIF functionality in the Windows Emoji Panel BleepingComputer · 43d ago This phishing kit looks more like BEC-as-a-service CyberScoop · 43d ago Amazon fined $2.25M for withholding evidence from fraud victims BleepingComputer · 43d ago Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes Heimdal Security Blog · 43d ago Adobe patches seven max severity ColdFusion, Campaign flaws BleepingComputer · 43d ago Anthropic to restore Claude Fable access on Wednesday BleepingComputer · 43d ago Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price BleepingComputer · 43d ago New BioShocking attack manipulates AI browser into data theft BleepingComputer · 43d ago Citrix patches a new NetScaler flaw with echoes of CitrixBleed CyberScoop · 43d ago Microsoft accelerates quantum-safe roadmap as risks grow BleepingComputer · 43d ago Malicious PyPI packages give hackers control of Telegram bot servers BleepingComputer · 43d ago Trump budget boss Russell Vought open to re-staffing CISA CyberScoop · 43d ago Is DEFCON for you? David Bombal · 43d ago CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs Technical Information Security Content & Discussion · 43d ago News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks The Last Watchdog · 43d ago JPMorganChase and Amazon Back Aspen Institute Drive Against Scams PYMNTS | Fraud Prevention Archives · 43d ago News alert: OpenMatter launches platform to verify AI activity across enterprise systems The Last Watchdog · 43d ago Fake Perplexity extension on Chrome Web Store tracked searches BleepingComputer · 44d ago Nissan Americas Hit in Global Oracle PeopleSoft Data Breach Cyber Defense Magazine · 44d ago DHS to unveil replacement council for critical infrastructure cybersecurity CyberScoop · 44d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 44d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 44d ago Lessons from the Underground: How to Combat Business Email Compromise BleepingComputer · 44d ago Insurance giant Aflac discloses data breach after subsidiary hack BleepingComputer · 44d ago Mircosoft adds smarter bot protection to Teams meetings BleepingComputer · 44d ago Microsoft adds smarter bot protection to Teams meetings BleepingComputer · 44d ago Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass) Technical Information Security Content & Discussion · 44d ago Kali Linux 2026.2 released with 9 new tools, NetHunter updates BleepingComputer · 44d ago Blackfield ransomware asks Nidec Corporation for $2 million ransom BleepingComputer · 44d ago How ransomware syndicates weaponize corporate-style organization CyberScoop · 44d ago CISA: Windows BlueHammer flaw now exploited by ransomware gangs BleepingComputer · 44d ago Warner bill would create federally vetted list for secure, trustworthy AI agents CyberScoop · 44d ago Nissan discloses employee data breach linked to Oracle zero-day attacks BleepingComputer · 44d ago NAIC says public data stolen in ShinyHunters' PeopleSoft breach BleepingComputer · 44d ago Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs Technical Information Security Content & Discussion · 44d ago WhatsApp rolls out usernames to help users hide their phone number BleepingComputer · 44d ago Supreme Court approves mail-in ballots that arrive after Election Day CyberScoop · 44d ago Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling CyberScoop · 44d ago Microsoft extends Windows Server 2022 hotpatching until October 2027 BleepingComputer · 44d ago U.S. offers $10 million for hackers targeting WhatsApp, Signal users BleepingComputer · 45d ago Agentic AI Has an Identity Problem and Attackers Know It BleepingComputer · 45d ago Critical SimpleHelp flaw exploited to deploy new stealer malware BleepingComputer · 45d ago Hackers now exploit critical Oracle E-Business flaw in attacks BleepingComputer · 45d ago Webinar: Why business email compromise attacks keep succeeding BleepingComputer · 45d ago CISA Warns Attackers Are Targeting Critical Internal Business Platforms Cyber Defense Magazine · 45d ago US seizes hundreds of FIFA World Cup illegal streaming domains BleepingComputer · 45d ago What the post-quantum executive order really demands of CISOs CyberScoop · 45d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 45d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 45d ago World Cup Gives Cross-Border Payments Their Super Bowl Moment PYMNTS | Fraud Prevention Archives · 45d ago TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry Trend Micro Research, News, Perspectives · 45d ago Return On Risk: The New Measure Of Cyber Resilience Cyber Defense Magazine · 46d ago Data breach exposes up to 14.2 million email logins at six ISPs BleepingComputer · 46d ago Path to StateRAMP Cyber Defense Magazine · 46d ago I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well. Technical Information Security Content & Discussion · 46d ago Dissecting Apple's Sparse Image Format (ASIF) Technical Information Security Content & Discussion · 46d ago A peek into Reddit's anti-spam internals Technical Information Security Content & Discussion · 47d ago Rethinking Identity Security In The Age Of AI Driven Fraud Cyber Defense Magazine · 47d ago HackTheBox - WingData IppSec · 47d ago Clean GitHub repo tricks AI coding agents into running malware BleepingComputer · 47d ago New Age Insider Risk Cyber Defense Magazine · 47d ago FBI: Russian hackers now target Signal backup recovery keys BleepingComputer · 47d ago CISA sets urgent deadline to fix Cisco flaw exploited in attacks BleepingComputer · 47d ago ATF cancels controversial commercial geolocation contract CyberScoop · 47d ago Polymarket customers lose $3 million in supply-chain attack BleepingComputer · 47d ago Cybersecurity firms targeted by fraudulent OpenAI organization invites BleepingComputer · 47d ago Banks Face a New ACH Fraud Test as Nacha Rules Take Effect PYMNTS | Fraud Prevention Archives · 48d ago Real Folks of Cyber | Pearce Barry | Day in the Life The Cyber Mentors · 48d ago How Dynamic Defense shuts an attacker out without shutting down the business Heimdal Security Blog · 48d ago Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure Cyber Defense Magazine · 48d ago Your First GRC Agent: A Red Teamer's Walkthrough BleepingComputer · 48d ago Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To Cyber Defense Magazine · 48d ago Name That Toon Contest darkreading · 48d ago Static security has run out of road. The case for Dynamic Defense Heimdal Security Blog · 48d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 48d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 48d ago Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges PYMNTS | Fraud Prevention Archives · 48d ago Anthropic is testing desktop-like Claude Cowork for mobile BleepingComputer · 48d ago Poland busts SIM-swapping gang tied to millions in crypto theft BleepingComputer · 48d ago Getting Started with the TCM Security Academy The Cyber Mentors · 48d ago FCC passes new cybersecurity rules for emergency systems, undersea cables CyberScoop · 48d ago Order-tracking app Shop abused to push callback phishing attacks BleepingComputer · 48d ago Microsoft quietly extends free Windows 10 ESU support to October 2027 BleepingComputer · 48d ago New macOS malware embeds fake errors to confuse AI analysis tools BleepingComputer · 49d ago Federal court rules Trump election-focused executive order illegal CyberScoop · 49d ago PirloTV sports piracy network disrupted as 44 domains seized BleepingComputer · 49d ago CVE-2025-52465 geoserver arbitrary file write vulnerability Technical Information Security Content & Discussion · 49d ago The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer Cyber Defense Magazine · 49d ago Bluekit phishing kit adopts browser-in-the-middle for login theft BleepingComputer · 49d ago Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract CyberScoop · 49d ago Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack CyberScoop · 49d ago The Four Elevations of Effective Fraud Prevention BleepingComputer · 49d ago The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target Cyber Defense Magazine · 49d ago Copilot in Excel: Built for the era of Frontier Finance Microsoft 365 Blog · 49d ago Webinar: Why account takeovers remain one of the hardest threats to stop BleepingComputer · 49d ago NSA Urges Cyberthreat Timeline Has Compressed From Years to Months Cyber Defense Magazine · 49d ago CargoWise WebTracker - The keys were in the cargo Technical Information Security Content & Discussion · 49d ago Europe Evolves Into Ransomware's Favorite Region darkreading · 49d ago Why patch directives only go so far CyberScoop · 49d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 49d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 49d ago AI Forces Compliance Teams to Rethink Alert Strategy PYMNTS | Fraud Prevention Archives · 49d ago Google releases new privacy controls for activity history, personalization BleepingComputer · 49d ago DraftKings hacker 'Snoopy' sentenced to 18 months in prison BleepingComputer · 49d ago Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access BleepingComputer · 49d ago Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure darkreading · 49d ago Malicious Edge extension abuses Native Messaging as bridge to malware BleepingComputer · 49d ago 2026 FIFA World Cup Faces Surge in Cyber Threats darkreading · 49d ago Do CISOs Need a Code of Ethics? darkreading · 49d ago Malicious hackers exploit Cisco zero-day for highest access level at communications service provider CyberScoop · 49d ago More Malicious OpenClaw Skills Threaten AI Supply Chain darkreading · 50d ago Exploiting vulnerabilities in Johnson & Johnson web apps Technical Information Security Content & Discussion · 50d ago Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have Cyber Defense Magazine · 50d ago CISA warns of max severity Ubiquiti flaws exploited in attacks BleepingComputer · 50d ago Amadey, StealC malware operations disrupted in Operation Endgame action BleepingComputer · 50d ago Securing the service desk: Why social engineering attacks keep succeeding BleepingComputer · 50d ago Invisible By Design: Making Quantum-Safe Encryption The Easy Path Cyber Defense Magazine · 50d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 50d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 50d ago In a first, a court takedown goes after two cybercrime tools at once CyberScoop · 50d ago Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming Cyber Defense Magazine · 50d ago Apple's MacOS Gap Lets Users Disable Security Tools darkreading · 50d ago Breaking the MSP Echo Chamber: The Power of Community Heimdal Security Blog · 50d ago Stealthy Mistic backdoor linked to ransomware access broker KongTuke BleepingComputer · 50d ago Open-source security is posing challenges governments can’t easily solve CyberScoop · 50d ago New at Forter: AI Agents Built to Amplify Your Team Blog – Forter · 50d ago Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks BleepingComputer · 50d ago Tata Electronics confirms cyberattack as hackers leak data BleepingComputer · 50d ago Scope of Salesforce Attacks Expands as Icarus Leaks Data darkreading · 50d ago Windows 11 KB5095093 update rolls out new Point-in-Time restore feature BleepingComputer · 50d ago Healthtech firm Xolis suffers data breach impacting 1.4 million people BleepingComputer · 50d ago Innovator Spotlight: NAKIVO Cyber Defense Magazine · 50d ago 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows darkreading · 50d ago Justice Department seizes infrastructure used by cyber scam and criminal marketplace CyberScoop · 50d ago New macOS ClickFix attack silently mounts DMGs to push infostealer BleepingComputer · 50d ago Cybersecurity Outsourcing. Beyond Cost Cyber Defense Magazine · 51d ago Scattered Spider Hackers Plead Guilty on Day 1 of Trial Krebs on Security · 51d ago Scattered Spider members plead guilty to hacking Transport for London BleepingComputer · 51d ago Algerian man charged with running two cybercrime marketplaces CyberScoop · 51d ago The Exploit Doesn't Exist. You Can Still Prove It Works Against You BleepingComputer · 51d ago LastPass confirms data breach in Klue supply chain attack BleepingComputer · 51d ago SocGholish Takedown Highlights Malicious TDS Threats darkreading · 51d ago Can AI Agents Find, Trust, and Choose Your Brand? Blog – Forter · 51d ago Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets Cyber Defense Magazine · 51d ago FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist darkreading · 51d ago Webinar: Why email security teams are drowning in alerts BleepingComputer · 51d ago Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data Cyber Defense Magazine · 51d ago Cloudflare patches Copy-Fail across every server in two days Technical Information Security Content & Discussion · 51d ago New Cisco RCE was fixed Technical Information Security Content & Discussion · 51d ago From Langflow to Monero: Inside CVE-2026-33017 Cryptominer Trend Micro Research, News, Perspectives · 51d ago WhatsApp phishing attack uses fake business docs to hack PCs BleepingComputer · 51d ago Court rules SAVE database illegal, orders it dismantled CyberScoop · 51d ago JaredFromSubway MEV bot hacked in $15 million crypto theft BleepingComputer · 51d ago DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories darkreading · 51d ago FFmpeg fixes PixelSmash flaw in widely used video decoder BleepingComputer · 51d ago Data Breach with Eastman Kodak Company Cyber Defense Magazine · 51d ago FortiBleed campaign used custom FortiGate sniffer to steal credentials BleepingComputer · 51d ago Trump executive orders speed up post-quantum migration, boost industry CyberScoop · 51d ago CVE-2026-25860 turn XSS to RCE Technical Information Security Content & Discussion · 51d ago Microsoft says Windows 11 26H2 is coming soon, details upgrade process BleepingComputer · 51d ago Microsoft fixes AutoGen Studio flaw that enabled code execution BleepingComputer · 51d ago Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign darkreading · 52d ago Intel agencies: Frontier AI models will reshape cybersecurity faster than expected CyberScoop · 52d ago He Thought He Was Secure; His Phone Number Was Stolen Anyway darkreading · 52d ago A Glimpse into the “Search Your Target” Market for Stolen Credentials BleepingComputer · 52d ago Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire Hak5 · 52d ago The World Cup Is Here… And So Are The Cyber Risks Cyber Defense Magazine · 52d ago Cloud Managed Services For Modern Cybersecurity To Secure Cloud Cyber Defense Magazine · 52d ago This Hacker Got Paid $50,000+ to Break Frontier AI Models NahamSec · 52d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 52d ago Exploiting Auth0 Defaults in XSS Attacks - elttam Technical Information Security Content & Discussion · 52d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 52d ago Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1) Technical Information Security Content & Discussion · 52d ago AryStinger botnet infected thousands of D-Link routers worldwide BleepingComputer · 53d ago Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors Cyber Defense Magazine · 53d ago New Prinz Eugen ransomware prioritizes recent files for encryption BleepingComputer · 54d ago HackTheBox - Nanocorp IppSec · 54d ago Microsoft links Mastra AI supply chain attack to North Korean hackers BleepingComputer · 54d ago The Shadow AI Paradox: Governing Innovation At Machine Speed Cyber Defense Magazine · 54d ago Innovator Spotlight: Ensemble Cyber Defense Magazine · 54d ago Innovator Spotlight: Centrii Cyber Defense Magazine · 54d ago Klue OAuth breach victim list grows as Icarus hackers claim attack BleepingComputer · 54d ago shadow AI is terrifying NetworkChuck · 54d ago Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin BleepingComputer · 54d ago Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 Technical Information Security Content & Discussion · 54d ago NSPM-12: The New Baseline for National Security Cybersecurity Cyber Defense Magazine · 55d ago Texas govt data breach exposes over 3 million driver’s licenses BleepingComputer · 55d ago Soft Skills for the Job Market: Resume Writing The Cyber Mentors · 55d ago OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099) Technical Information Security Content & Discussion · 55d ago Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way BleepingComputer · 55d ago Stressors, AI Forcing Changes to Cybersecurity Teams darkreading · 55d ago Webinar: How attackers bypass MFA and how defenders can respond BleepingComputer · 55d ago Microsoft: June 2026 Windows updates break Recycle Bin prompts BleepingComputer · 55d ago CISA: Splunk Enterprise flaw actively exploited, patch by Sunday BleepingComputer · 55d ago Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration Technical Information Security Content & Discussion · 55d ago NY man charged after harassing college student with AI-generated nudes BleepingComputer · 55d ago CISA warns Fortinet users to secure devices after FortiBleed leak BleepingComputer · 55d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 55d ago Gentlemen ransomware uses multiple EDR killers to disable defenses BleepingComputer · 55d ago Authorities disrupt Evil Corp’s SocGholish botnet CyberScoop · 55d ago Congress tees up No FAKES Act, aiming at AI-generated deepfakes CyberScoop · 55d ago Novo Nordisk Breach Highlights Software Development Pipeline Risk darkreading · 55d ago HTTPS Doesn't Hide This From Your ISP!! NetworkChuck · 55d ago Operation Escaneo Signals Shift in LatAm Threat Landscape darkreading · 55d ago Nintendo confirms data stolen in WebMD subsidiary cyberattack BleepingComputer · 55d ago FIFA Bug Exposes World Cup Streams to Remote Takeover darkreading · 55d ago CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance Technical Information Security Content & Discussion · 55d ago ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm Krebs on Security · 55d ago Salesforce Data Thefts Continue via Klue App Compromise darkreading · 56d ago USB worm spreads crypto-stealing malware via Windows shortcut files BleepingComputer · 56d ago Cisco Just Showed the Future of Networking NetworkChuck · 56d ago How software development’s speed obsession enabled TeamPCP’s chaos crusade CyberScoop · 56d ago Accenture shells out $4.18B on three companies in big industrial cybersecurity push CyberScoop · 56d ago Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks BleepingComputer · 56d ago 5 reasons Microsoft 365 backup isn’t enough for business data protection BleepingComputer · 56d ago Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp BleepingComputer · 56d ago Five Compliance Realities Federal Contractors Can’t Ignore Cyber Defense Magazine · 56d ago Get Out of Security Debt by Tackling the Exposure Problem darkreading · 56d ago ShapedPlugin update flow hacked to infect WordPress sites BleepingComputer · 56d ago Apple fixes Beats Studio Buds flaw that let hackers spy on conversations BleepingComputer · 56d ago Telegram admits it couldn't police exam-leak channels, India tells court BleepingComputer · 56d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 56d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure Alerts · 56d ago Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT All CISA Advisories · 56d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 56d ago Schneider Electric EasyLogic T150 and Saitel DP All CISA Advisories · 56d ago AVer PTC cameras All CISA Advisories · 56d ago Rockwell Automation FactoryTalk Historian Site Edition All CISA Advisories · 56d ago AzeoTech DAQFactory All CISA Advisories · 56d ago Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products All CISA Advisories · 56d ago Mitsubishi Electric MELSEC iQ-F Series All CISA Advisories · 56d ago Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module All CISA Advisories · 56d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure All CISA Advisories · 56d ago F5 issues out-of-band patches for critical NGINX vulnerabilities BleepingComputer · 56d ago Would you like some malware served at the very top of DuckDuckGo? Technical Information Security Content & Discussion · 56d ago Microsoft fixes Windows Server 2016 security update failures BleepingComputer · 56d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 56d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 56d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 56d ago EU Gets a Head Start in Developing 6G Network Security darkreading · 56d ago Leak confirms OpenAI is testing a ChatGPT for Science subscription BleepingComputer · 56d ago PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM Trend Micro Research, News, Perspectives · 56d ago Google to use UK and EU user IP addresses for ad personalization BleepingComputer · 56d ago Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update Technical Information Security Content & Discussion · 56d ago This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity NahamSec · 56d ago News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies The Last Watchdog · 56d ago News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk The Last Watchdog · 56d ago Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April CyberScoop · 57d ago FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices. BleepingComputer · 57d ago Why Account Takeovers Are Rising and How to Stop Them BleepingComputer · 57d ago India's Telegram ban hit the UAE too. Here's how to get around it BleepingComputer · 57d ago Cyber Security Market Insights & Trends Driving The Next Wave Of Protection Cyber Defense Magazine · 57d ago Microsoft confirms Office apps launch issues after June updates BleepingComputer · 57d ago CISA orders feds to patch max severity Joomla plugin flaw by Friday BleepingComputer · 57d ago QoS Policies to Restrict EDR Traffic and Detection Strategies Technical Information Security Content & Discussion · 57d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 57d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 57d ago Microsoft working on Defender patch for RoguePlanet zero-day BleepingComputer · 57d ago Kodak confirms data breach claimed by ShinyHunters extortion gang BleepingComputer · 57d ago Getting a CVE Without Shipping Slop Technical Information Security Content & Discussion · 57d ago PrizeBuzz phishing network analysis Technical Information Security Content & Discussion · 57d ago Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Trend Micro Research, News, Perspectives · 57d ago Shark Jacked my LAN 🦈 Hak5 · 57d ago Malicious JetBrains Marketplace plugins steal AI API keys from developers BleepingComputer · 57d ago Lawmakers leery about Trump administration’s Anthropic order CyberScoop · 57d ago News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails The Last Watchdog · 57d ago AI’s constant patching treadmill can be a security problem CyberScoop · 57d ago 27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass Technical Information Security Content & Discussion · 57d ago AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns Cyber Defense Magazine · 57d ago New Rokarolla Android malware targets 217 banking, crypto apps BleepingComputer · 57d ago News alert: GitGuardian adds endpoint protection as developer laptops become credential troves The Last Watchdog · 57d ago Steam Workshop abused to spread malware via Wallpaper Engine app BleepingComputer · 57d ago TCM Security Summer Sale is Here! The Cyber Mentors · 58d ago A case for how to shape ‘ingredient lists’ for AI models CyberScoop · 58d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 58d ago Copilot Cowork is now generally available Microsoft 365 Blog · 58d ago UK to require ID or face scan before you can make social media accounts BleepingComputer · 58d ago GhostTree Attack Abused Recursive Windows Junctions to Hide Malware BleepingComputer · 58d ago FTC warns of record $3.5 billion losses to imposter scams in 2025 BleepingComputer · 58d ago Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions Cyber Defense Magazine · 58d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 58d ago Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP All CISA Advisories · 58d ago Rockwell Automation RSLinx All CISA Advisories · 58d ago Rockwell Automation FLEX I/O EtherNet/IP Adapters All CISA Advisories · 58d ago Rockwell Automation FactoryTalk Analytics PavilionX All CISA Advisories · 58d ago Rockwell Automation CompactLogix All CISA Advisories · 58d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 58d ago CISA warns of another cPanel plugin flaw exploited in attacks BleepingComputer · 58d ago News alert: Varist announces AI-scale malware detection for healthcare and medical imaging The Last Watchdog · 58d ago Ransomware gang abuses Microsoft Teams relays to hide malicious traffic BleepingComputer · 58d ago Critical Fortinet FortiSandbox flaws now exploited in attacks BleepingComputer · 58d ago Windows version of SprySOCKS Linux malware used to attack govt orgs BleepingComputer · 58d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 58d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 58d ago iRhythm discloses data breach, says hackers stole patient info BleepingComputer · 58d ago DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act BleepingComputer · 58d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 58d ago Google exposes China espionage group that’s been lurking in networks undetected since 2023 CyberScoop · 58d ago SimpleHelp bug lets hackers create rogue remote support accounts BleepingComputer · 58d ago Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE Technical Information Security Content & Discussion · 58d ago OptinMonster WordPress plugin hacked in CDN supply-chain attack BleepingComputer · 58d ago Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks BleepingComputer · 58d ago I was wrong about VPNs NetworkChuck · 59d ago Council of Europe investigates ShinyHunters data breach claims BleepingComputer · 59d ago Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat CyberScoop · 59d ago FBI: Fraudsters use couriers to steal money in crypto scams BleepingComputer · 59d ago Vibe coders are gonna vibe code: How CISOs are tackling code sprawl BleepingComputer · 59d ago Chinese hackers breach REDCap servers, steal medical research BleepingComputer · 59d ago SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon Technical Information Security Content & Discussion · 59d ago Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection? Cyber Defense Magazine · 59d ago New attack turned Microsoft 365 Copilot into 1-click data theft tool BleepingComputer · 59d ago Infinite Campus data breach affects 137,000 school staff accounts BleepingComputer · 59d ago How I Made $30,000 Hacking Broken Access Control NahamSec · 59d ago $30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover NahamSec · 59d ago Webinar: How behavioral AI stops phishing and account takeovers BleepingComputer · 59d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 59d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 59d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 59d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 59d ago FBI disrupts massive AI-powered phishing service using a million URLs BleepingComputer · 60d ago CMMC Is Exposing A Major Gap In The Defense Supply Chain Cyber Defense Magazine · 60d ago Researcher accidentally gained access to a threat actor-controlled phishing website Technical Information Security Content & Discussion · 60d ago PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs Technical Information Security Content & Discussion · 60d ago Ex-school district employee jailed for hacks on former employer BleepingComputer · 60d ago MeshCentral: From XSS to RCE Technical Information Security Content & Discussion · 60d ago Anthropic disables new models after government calls them a national security concern CyberScoop · 60d ago HackTheBox - VariaType IppSec · 61d ago Chinese hackers hijack auth flow, spy on isolated network for a decade BleepingComputer · 61d ago Zero Trust For AI In Defense Networks Cyber Defense Magazine · 61d ago US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos BleepingComputer · 61d ago Getting the PID from random numbers in PHP Technical Information Security Content & Discussion · 61d ago The Axios npm compromise was visible in registry metadata before anyone ran npm install Technical Information Security Content & Discussion · 61d ago FBI takes down massive China-based cybercrime network that caused $1.9B in losses CyberScoop · 61d ago Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs Technical Information Security Content & Discussion · 61d ago ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed darkreading · 61d ago Maine disables data breach notification portal after fake disclosures BleepingComputer · 61d ago US, France, and Italian authorities shut down massive deepfake porn site CyberScoop · 61d ago phpBB forum fixes auth bypass bug lurking for a decade BleepingComputer · 61d ago Ukrainian national pleads guilty to role in Conti ransomware operation BleepingComputer · 61d ago Conti ransomware group member pleads guilty, faces up to 20 years in prison CyberScoop · 61d ago Over 400 Arch Linux packages compromised to push rootkit, infostealer BleepingComputer · 62d ago ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw CyberScoop · 62d ago Free Compromise Detection for GitHub Repos - Tracebit Community Edition Technical Information Security Content & Discussion · 62d ago Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE) Technical Information Security Content & Discussion · 62d ago Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery Technical Information Security Content & Discussion · 62d ago Early Warning Signs of Supply-Chain Attacks Live in the Dark Web BleepingComputer · 62d ago Claude Fable 5 Doesn't Change the Mythos Security Story darkreading · 62d ago Why Most Cyber Resilience Programs Fail Before The First Incident Cyber Defense Magazine · 62d ago Developers React to the 105-Second Github Chain Reaction | Threat Wire Hak5 · 62d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 62d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 62d ago CyberCorps is adapting to AI. The budget isn’t keeping up. CyberScoop · 62d ago Microsoft fixes Windows update failures linked to WUSA installer BleepingComputer · 62d ago Pharma giant Novo Nordisk discloses breach of clinical trials data BleepingComputer · 62d ago CISA orders feds to patch actively exploited Ivanti flaw by Sunday BleepingComputer · 62d ago Over 73,000 French govt employees affected in Tchap messenger breach BleepingComputer · 62d ago Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs Technical Information Security Content & Discussion · 62d ago Phishing Attack Volume Down 20%, But Risk Still Rising darkreading · 62d ago Governing Claude Enterprise in Environments Where Inline Controls Can't Go Trend Micro Research, News, Perspectives · 62d ago Japanese energy firm loses drive with data of 10.9 million clients BleepingComputer · 62d ago Maine breach portal abused to publish fake data breach disclosures BleepingComputer · 62d ago Oracle mitigates PeopleSoft zero-day exploited in data theft attacks BleepingComputer · 62d ago Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules Technical Information Security Content & Discussion · 62d ago Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure darkreading · 62d ago Any solutions we can use? cybersecurity · 62d ago Russian national charged in connection with Void Blizzard espionage campaign CyberScoop · 62d ago DIY pwnagotchi-like device on esp32 hacking: security in practice · 63d ago Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it Reverse Engineering · 63d ago Possible targeted attack cybersecurity · 63d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline cybersecurity · 63d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 63d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 63d ago Facebook messenger to text cybersecurity · 63d ago Claude Fable 5: mid-tier results on coding tasks Technical Information Security Content & Discussion · 63d ago Authorities dismantle 'AudiA6' ransomware crypto-laundering service BleepingComputer · 63d ago US charges suspected Russian hacker with facilitating cyber campaign For [Blue|Purple] Teams in Cyber Defence · 63d ago Flipper Blackhat + Bjorn hacking: security in practice · 63d ago Segmentation Works for OT If Operators Are Paying Attention darkreading · 63d ago Managing Solution Agents cybersecurity · 63d ago Nottingham University data breach affects over 450,000 students cybersecurity · 63d ago SWGs that support 3rd party external DNS resolver cybersecurity · 63d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers cybersecurity · 63d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game Reverse Engineering · 63d ago Why AI-driven threats are exposing the limits of MSP security stacks BleepingComputer · 63d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG cybersecurity · 63d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia For [Blue|Purple] Teams in Cyber Defence · 63d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch cybersecurity · 63d ago Do you think AI is making hacking easier or harder hacking: security in practice · 63d ago Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration Cyber Defense Magazine · 63d ago Coupang hit with record $409 million data breach fine in Korea BleepingComputer · 63d ago CISA tells govt agencies to patch critical exploited flaws in 3 days BleepingComputer · 63d ago Phishing awareness training resulting in ignoring company comms? cybersecurity · 63d ago How are you analyzing Android malware nowadays? cybersecurity · 63d ago Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work Technical Information Security Content & Discussion · 63d ago Hackers Exploit Langflow Vulnerability for Remote Code Execution cybersecurity · 63d ago Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research cybersecurity · 63d ago NEED SOME GUIDANCE cybersecurity · 63d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 63d ago Yarbo Android/iOS Mobile Application and Cloud Infrastructure All CISA Advisories · 63d ago Naxclow IoT Platform All CISA Advisories · 63d ago Brickcom Cameras All CISA Advisories · 63d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 63d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Malware Analysis & Reports · 63d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Reverse Engineering · 63d ago What can i do left? PSN hacking: security in practice · 63d ago Help setting up local encryption on my pc cybersecurity · 63d ago Hacking Google with A.I. for $500,000 Technical Information Security Content & Discussion · 63d ago Agentic AI on Cybersecurity cybersecurity · 63d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 63d ago DoD 0-days Typically Come Down to Authorization Failures cybersecurity · 63d ago HDD cybersecurity · 63d ago Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets cybersecurity · 63d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 63d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 63d ago Microsoft fixes BitLocker recovery bug on Windows Server 2025 BleepingComputer · 63d ago Prompt injection: attacking the analyst's AI Technical Information Security Content & Discussion · 63d ago How can we test the firmware code/images security? cybersecurity · 63d ago 20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004 cybersecurity · 63d ago Proxmark5 campaign ending in less than 18 hours. hacking: security in practice · 63d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 For [Blue|Purple] Teams in Cyber Defence · 63d ago GreatXML: GreatXML bitlocker bypass vulnerability For [Blue|Purple] Teams in Cyber Defence · 63d ago GitHub announces npm security changes to tackle supply-chain attacks cybersecurity · 63d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan For [Blue|Purple] Teams in Cyber Defence · 63d ago The ‘Miasma’ worm source code briefly leaked on GitHub cybersecurity · 63d ago CISA Rewrites Federal Patching Requirements for AI Threat Era cybersecurity · 63d ago What is the difference between Regular TLS and Mutual TLS? cybersecurity · 63d ago Every employee's password was stored in a single Excel file cybersecurity · 63d ago Nottingham University data breach affects over 450,000 students BleepingComputer · 63d ago npm v12 is changing how dependencies are installed to reduce supply-chain risk cybersecurity · 63d ago Max severity Ivanti Sentry vulnerability now exploited in attacks BleepingComputer · 63d ago How to bypass speed queen coin slot for washer and dryer hacking: security in practice · 63d ago LIVE: 🕵️ CTF Prize Draw | Cybersecurity The Cyber Mentors · 63d ago Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia? cybersecurity · 63d ago Drive Firmware Security - Phison S11 Reverse Engineering · 63d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue For [Blue|Purple] Teams in Cyber Defence · 63d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion For [Blue|Purple] Teams in Cyber Defence · 63d ago How good Microsoft Defender for storage? cybersecurity · 63d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default For [Blue|Purple] Teams in Cyber Defence · 63d ago GreatXML bitlocker bypass vulnerability cybersecurity · 63d ago Struggle cybersecurity · 63d ago Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications? cybersecurity · 63d ago Chinese, N. Korean Threat Groups Build on Asia-Pacific Success darkreading · 63d ago Wiz launches Cloud Security Job Board cybersecurity · 63d ago Physical Project Ideas cybersecurity · 63d ago How can I get into cybersecurity while studying Information Systems Engineering? cybersecurity · 63d ago Miasma-style supply chain attacks For [Blue|Purple] Teams in Cyber Defence · 63d ago Cloud Security job board cybersecurity · 63d ago Continuous learning cybersecurity · 63d ago Self-hosting stuff for when things get ugly hacking: security in practice · 63d ago Path traversal flaw in AI dev platform Langflow exploited in attacks BleepingComputer · 63d ago CISA Rewrites Federal Patching Requirements for AI Threat Era darkreading · 63d ago Angry bug hunter with Microsoft beef drops new Windows 0-day cybersecurity · 63d ago The ‘Miasma’ worm source code briefly leaked on GitHub BleepingComputer · 63d ago OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers CyberScoop · 63d ago Bug Bounty Research Triggers ServiceNow Security Alert darkreading · 63d ago Mid-30s, stuck in web pentesting, and wondering what to do ? cybersecurity · 63d ago GitHub announces npm security changes to tackle supply-chain attacks BleepingComputer · 63d ago AI Risk Worries Insurers & Businesses Alike darkreading · 63d ago Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM cybersecurity · 63d ago Is Microsoft Purview really secure when using Copilot? cybersecurity · 63d ago Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review Technical Information Security Content & Discussion · 63d ago News alert: Cloud security report finds fragmented tools widening the cloud complexity gap The Last Watchdog · 63d ago Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks BleepingComputer · 63d ago Malware Includes Taboo In Text To Prevent LLM Analysis hacking: security in practice · 63d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet For [Blue|Purple] Teams in Cyber Defence · 63d ago Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature? cybersecurity · 63d ago added Mac support for my corporate hacking game, demo on Steam hacking: security in practice · 63d ago IDA 9.4 Beta | Hex-Rays Docs Reverse Engineering · 63d ago Nee academic references for Hashcat's 'Next Big Bang' log cybersecurity · 63d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs For [Blue|Purple] Teams in Cyber Defence · 63d ago CISA released BOD 26-04: A new federal government vulnerability management strategy? cybersecurity · 63d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace For [Blue|Purple] Teams in Cyber Defence · 64d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days cybersecurity · 64d ago IMPACT Roadshow Recap: Getting Ready for Agentic Commerce Blog – Forter · 64d ago added Mac support to my corporate hacking sim. Demo now available on Steam cybersecurity · 64d ago Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet darkreading · 64d ago CISA directive orders agencies to prioritize vulnerability patching in a new way CyberScoop · 64d ago We post-trained a model for offensive security instead of teaching it to refuse Technical Information Security Content & Discussion · 64d ago Catfished hacking: security in practice · 64d ago Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte) cybersecurity · 64d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper Malware Analysis & Reports · 64d ago China-linked JDY botnet expands targeting of U.S. military networks BleepingComputer · 64d ago Students' data taken in major University of Nottingham cyber-attack cybersecurity · 64d ago Has unmanaged external file sharing ever burned you? cybersecurity · 64d ago The 5 Best Practices for Secure Identity Verification BleepingComputer · 64d ago Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers cybersecurity · 64d ago Microsoft patches Exchange Server zero-day exploited in attacks BleepingComputer · 64d ago Trane Tracer HVAC cybersecurity issues Reverse Engineering · 64d ago Need feedback on my presentation cybersecurity · 64d ago Compensating controls besides admin credentials being needed to download software on employee endpoints cybersecurity · 64d ago OpenSSL PKCS#7 CVE-2026-45447 cybersecurity · 64d ago Testing offensive AI agents in a cloud lab with deception tech For [Blue|Purple] Teams in Cyber Defence · 64d ago What The Cybersecurity Industry Knows And Will Not Say Cyber Defense Magazine · 64d ago Presentation Question cybersecurity · 64d ago What did they mean by this? One of us? hacking: security in practice · 64d ago How to Stay Ahead of Deepfake Evolution in 2026 cybersecurity · 64d ago How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026 Technical Information Security Content & Discussion · 64d ago FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster Technical Information Security Content & Discussion · 64d ago Microsoft: Some Windows PCs fail to install latest monthly updates BleepingComputer · 64d ago France’s Government Messaging App Tchap Got Breached cybersecurity · 64d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days BleepingComputer · 64d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap Malware Analysis & Reports · 64d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 64d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 64d ago certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA" Technical Information Security Content & Discussion · 64d ago Where's the fix for MiniPlasma? cybersecurity · 64d ago BlackSun - Defender for Endpoint on macOS Technical Information Security Content & Discussion · 64d ago ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances cybersecurity · 64d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges hacking: security in practice · 64d ago GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline) Technical Information Security Content & Discussion · 64d ago Internships cybersecurity · 64d ago Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS cybersecurity · 64d ago Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows cybersecurity · 64d ago Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam Technical Information Security Content & Discussion · 64d ago Ivanti: Max severity Sentry flaw allows code execution as root BleepingComputer · 64d ago Looking for a Reliable Cybersecurity Provider for a School in North Sydney cybersecurity · 64d ago Early Operational Visibility cybersecurity · 64d ago Benchmarking n-day exploit generation [via AI] For [Blue|Purple] Teams in Cyber Defence · 64d ago how are you actually managing ai agents in production? cybersecurity · 64d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) Reverse Engineering · 64d ago Al app builders: How are you handling security questionnaires when selling your product? cybersecurity · 64d ago [ Removed by Reddit ] cybersecurity · 64d ago How are all of doing with THE AI model thats big news currently?? cybersecurity · 64d ago Whoops! I did it again. I patched Windows Kernel at Milan0day 2026 For [Blue|Purple] Teams in Cyber Defence · 64d ago Microsoft Defender now monitors RPC activity For [Blue|Purple] Teams in Cyber Defence · 64d ago Skill to Scan your Codebase cybersecurity · 64d ago RoguePlanet: RoguePlanet Windows Defender Vulnerability For [Blue|Purple] Teams in Cyber Defence · 64d ago Miasma-style supply chain attacks cybersecurity · 64d ago FCaptcha v1.12: Catching AI Agents That Drive Real Browsers cybersecurity · 64d ago Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones cybersecurity · 64d ago Anthropic rolls out Claude Fable 5, but it's available for a limited time BleepingComputer · 64d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs cybersecurity · 64d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs Technical Information Security Content & Discussion · 64d ago AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say cybersecurity · 64d ago GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 Trend Micro Research, News, Perspectives · 64d ago Huntress Stack (MS Defender or SentinelOne) cybersecurity · 64d ago META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT cybersecurity · 64d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges BleepingComputer · 64d ago OptOutCode – A Privacy4Cars Universal Opt-Out Concept hacking: security in practice · 64d ago I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in) For [Blue|Purple] Teams in Cyber Defence · 64d ago The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life darkreading · 64d ago FBI is announcing Operation Riptide cybersecurity · 64d ago Blame AI: Patch Tuesday Hits Record 206 CVEs darkreading · 64d ago ServiceNow confirmed some customer instances were breached. cybersecurity · 64d ago ServiceNow discloses security incident exposing customer data BleepingComputer · 64d ago Which are some of the best Cybersecurity / OT Security events that happen in GCC? cybersecurity · 64d ago OpenClaw AI agent found falling for phishing attacks, spills user data BleepingComputer · 64d ago DF/IR Community cybersecurity · 64d ago Chaotic Eclipse's new RoguePlanet cybersecurity · 64d ago Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address darkreading · 64d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace cybersecurity · 64d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace Malware Analysis & Reports · 64d ago Microsoft breaks Patch Tuesday record with 206 vulnerabilities CyberScoop · 64d ago Thoughts on Automated Compliance? cybersecurity · 64d ago SAP fixes critical flaws in NetWeaver and Commerce Cloud BleepingComputer · 64d ago Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories darkreading · 64d ago A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available cybersecurity · 64d ago Apple’s Siri-AI, or more shouting into the void about “private” agents Technical Information Security Content & Discussion · 64d ago How do you make learning blue team security entertaining ? For [Blue|Purple] Teams in Cyber Defence · 64d ago North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says cybersecurity · 64d ago Microsoft has released a patch for the bitlocker bypass cybersecurity · 64d ago Microsoft releases Windows 10 KB5094127 extended security update BleepingComputer · 64d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. Reverse Engineering · 64d ago Please advices cybersecurity · 64d ago Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws BleepingComputer · 64d ago Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws BleepingComputer · 64d ago soc analyst l1 cybersecurity · 64d ago Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow cybersecurity · 64d ago Looking to move off KnowBe4, what are people actually using these days? cybersecurity · 64d ago Maximizing IOC Impact For [Blue|Purple] Teams in Cyber Defence · 64d ago Windows 11 KB5094126 & KB5093998 cumulative updates released BleepingComputer · 64d ago Too Many Certs, Not Enough Experience — What’s the Best Next Step? cybersecurity · 65d ago Anthropic’s new model is Mythos on a leash CyberScoop · 65d ago Authenticating ARP and NDP cybersecurity · 65d ago Does anyone use rule feeds in 2026? cybersecurity · 65d ago [2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution For [Blue|Purple] Teams in Cyber Defence · 65d ago CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector CyberScoop · 65d ago Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations! cybersecurity · 65d ago Need a vm for practice cybersecurity · 65d ago XBOW tests Anthropic's Mythos Preview for offensive security BleepingComputer · 65d ago Tips/Tricks to WFH as a SOC Analyst? cybersecurity · 65d ago Cybersecurity statistics of the week (June 1st - June 7th) cybersecurity · 65d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks For [Blue|Purple] Teams in Cyber Defence · 65d ago Where can GRC folks learn practical AppSec / DevSecOps without going full engineer? cybersecurity · 65d ago GitHub disables Microsoft repos pushing password-stealing malware BleepingComputer · 65d ago Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs darkreading · 65d ago I almost got “onboarded” into a malware campaign disguised as a job opportunity. cybersecurity · 65d ago University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model cybersecurity · 65d ago AI Blocklist - help cybersecurity · 65d ago New Veeam vulnerability exposes backup servers to RCE attacks BleepingComputer · 65d ago Entra Agent ID from a Security Perspective For [Blue|Purple] Teams in Cyber Defence · 65d ago Cisco customers encounter another SD-WAN zero-day under attack CyberScoop · 65d ago Entra Agent ID from a Security Perspective Technical Information Security Content & Discussion · 65d ago Protecting AI workloads on Linux servers cybersecurity · 65d ago Exposing DoNex Ransomware Secrets with Malcore! cybersecurity · 65d ago What are the different Disaster Recovery scenarios your teams have tested on? cybersecurity · 65d ago someone actually leaked the Miasma supply chain attack toolkit source code on github cybersecurity · 65d ago X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection Technical Information Security Content & Discussion · 65d ago Rethinking Access Governance for AI Agents Cyber Defense Magazine · 65d ago Secrets to PNPT Debrief Success The Cyber Mentors · 65d ago Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility For [Blue|Purple] Teams in Cyber Defence · 65d ago WinGet - Code Execution, Persistence and Detection Strategies cybersecurity · 65d ago WinGet - Code Execution, Persistence and Detection Strategies Technical Information Security Content & Discussion · 65d ago Ransomware attack shuts Illinois high school until Wednesday cybersecurity · 65d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 65d ago Siemens KACO Blueplanet Inverters All CISA Advisories · 65d ago Schneider Electric EcoStruxure Panel Server All CISA Advisories · 65d ago Schneider Electric Modicon Network Managed Switches All CISA Advisories · 65d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 65d ago Ideas for demo cybersecurity · 65d ago French govt messaging service breached in account hijacking attack BleepingComputer · 65d ago Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please? cybersecurity · 65d ago Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares. cybersecurity · 65d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue Technical Information Security Content & Discussion · 65d ago Physical attack device cybersecurity · 65d ago Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer cybersecurity · 65d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 65d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 65d ago IT GRC News? cybersecurity · 65d ago CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day BleepingComputer · 65d ago Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again cybersecurity · 65d ago I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information Technical Information Security Content & Discussion · 65d ago What are the best risk-based vulnerability management tools for tracking active exploitation in 2026? For [Blue|Purple] Teams in Cyber Defence · 65d ago Google patches new Chrome zero-day flaw exploited in the wild BleepingComputer · 65d ago QuasarNix: Reverse Shell Detection with Machine Learning For [Blue|Purple] Teams in Cyber Defence · 65d ago Shifting L7 validation to the edge to stop DB resource exhaustion? cybersecurity · 65d ago Google Patches 5th Chrome Zero-Day Exploited in 2026 cybersecurity · 65d ago AI Agents May Always Fall for Prompt Injections Technical Information Security Content & Discussion · 65d ago Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go For [Blue|Purple] Teams in Cyber Defence · 65d ago EC Council CEH exam advice cybersecurity · 65d ago Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion For [Blue|Purple] Teams in Cyber Defence · 65d ago Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 For [Blue|Purple] Teams in Cyber Defence · 65d ago About NPower vs PerScholas cybersecurity · 65d ago Looking for a vulnerability to learn cybersecurity · 65d ago Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency For [Blue|Purple] Teams in Cyber Defence · 65d ago From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk cybersecurity · 65d ago UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season For [Blue|Purple] Teams in Cyber Defence · 65d ago Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) For [Blue|Purple] Teams in Cyber Defence · 65d ago Visual Studio Code 1.123: Delayed extension auto-updates For [Blue|Purple] Teams in Cyber Defence · 65d ago Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users. For [Blue|Purple] Teams in Cyber Defence · 65d ago Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, For [Blue|Purple] Teams in Cyber Defence · 65d ago Bad USB through charger? cybersecurity · 65d ago Recommendations for Discord community for latest AI security products cybersecurity · 65d ago StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams hacking: security in practice · 65d ago Vulnerability Summary for the Week of June 1, 2026 cybersecurity · 65d ago Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas cybersecurity · 65d ago I feel like ive lost my passion to tinker after 6 years in the industry, anyone else? cybersecurity · 65d ago I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples cybersecurity · 65d ago really need help with project ideas for MSc cybersecurity · 65d ago Which Course for an almost-complete noob? (SANS.edu) cybersecurity · 65d ago NFCShare Android malware spreads via fake banking app updates on GitHub BleepingComputer · 65d ago SoFi confirms third-party data breach at Hong Kong subsidiary cybersecurity · 65d ago AI Slop Will Kill Cybersecurity Storytelling If We Let It darkreading · 65d ago SoFi confirms third-party data breach at Hong Kong subsidiary BleepingComputer · 65d ago For the 2nd time in weeks, Microsoft packages laced with credential stealer cybersecurity · 65d ago Iran Signed a Ceasefire — Its Hackers Didn't cybersecurity · 65d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages cybersecurity · 65d ago DSPM étude marche cybersecurity · 65d ago CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file cybersecurity · 65d ago New Apple feature automatically changes your compromised passwords BleepingComputer · 65d ago Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks darkreading · 65d ago AppSec / Pentesting job market in Canada for experienced overseas applicants? cybersecurity · 65d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages BleepingComputer · 65d ago Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients. cybersecurity · 65d ago Check Point VPN Flaw Exploited Since Early May darkreading · 65d ago Automation Playbooks - which ones would you not want to live without? cybersecurity · 65d ago Is it necessary/important to Hash and salt API Keys for a strictly internal use tool? cybersecurity · 65d ago Need review on the OMS Cybersecurity program from Georgia Tech? cybersecurity · 65d ago If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk cybersecurity · 65d ago 2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years cybersecurity · 65d ago Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement For [Blue|Purple] Teams in Cyber Defence · 65d ago How do you close an alert cybersecurity · 65d ago Iran Signed a Ceasefire — Its Hackers Didn't darkreading · 65d ago What cybersecurity certifications are great value for money? cybersecurity · 65d ago Boxes for CPENT cybersecurity · 65d ago WhatsApp says it disrupted new NSO spyware phishing attacks BleepingComputer · 65d ago SIEM: is it "SIM" or "SEEM" cybersecurity · 65d ago I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included) cybersecurity · 65d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment Malware Analysis & Reports · 65d ago How justdeleteme and justgetmydata work? cybersecurity · 65d ago Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint CyberScoop · 65d ago GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks. hacking: security in practice · 66d ago How CIAM Helps Boost Business Cyber Defense Magazine · 66d ago I need help - PCI DSS 4.0 requirement 11.6.1 cybersecurity · 66d ago How are you learning agent pen testing? cybersecurity · 66d ago Gogs patches critical zero-day enabling remote code execution BleepingComputer · 66d ago HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified) For [Blue|Purple] Teams in Cyber Defence · 66d ago Cyber security intern cybersecurity · 66d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 66d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 66d ago Introducing Shark Jack Display 🦈 Hak5 · 66d ago Meta to take legal action against Israeli spyware company NSO cybersecurity · 66d ago Critical UniFi OS bug lets hackers gain root without authentication BleepingComputer · 66d ago Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit cybersecurity · 66d ago What's the best way to alert companies of a Glassworm copycat? cybersecurity · 66d ago How To Verify If A Site Is Legit? cybersecurity · 66d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 66d ago What is Flaresolverr cybersecurity · 66d ago Research: defenders using generative AI to simulate malware variants before they exist in the wild cybersecurity · 66d ago Reducing security operations complexity with Wazuh Cloud BleepingComputer · 66d ago How are regulated orgs actually letting engineers use Claude Code / Copilot? cybersecurity · 66d ago Cyber security expo Manchester cybersecurity · 66d ago Content creations was both a blessing and a curse. #bugbounty NahamSec · 66d ago Remote Hiring Opened the Talent Pool — and the Fraud Surface cybersecurity · 66d ago Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it Technical Information Security Content & Discussion · 66d ago Check Point links VPN zero-day attacks to Qilin ransomware gang BleepingComputer · 66d ago World Cloud Security Day Cyber Defense Magazine · 66d ago This Hacker Made $7,000 Hacking AI With One Email NahamSec · 66d ago EMBA firmware analysis framework v2.0.2 available - Party the big 2k Reverse Engineering · 66d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks cybersecurity · 66d ago What certs should I do during summer of 11th grade? cybersecurity · 66d ago CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) cybersecurity · 66d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 66d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 66d ago Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine cybersecurity · 66d ago Oxford University discloses data breach after careers platform hack cybersecurity · 66d ago Oxford University discloses data breach after careers platform hack BleepingComputer · 66d ago Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing cybersecurity · 66d ago Got this message from “SimBoss” cybersecurity · 66d ago PKCS12 Golang fork cybersecurity · 66d ago The AI security race needs accountability, not overregulation CyberScoop · 66d ago Malware Insights: Miasma Campaign cybersecurity · 66d ago 73 Microsoft GitHub repositories impacted by Miasma malware Malware Analysis & Reports · 66d ago 73 Microsoft GitHub repositories impacted by Miasma malware cybersecurity · 66d ago [Honeypot Research] Looking for volunteers to test telemetry/logs cybersecurity · 66d ago Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏 hacking: security in practice · 66d ago What is the condition of Bug Bounty program in the era of AI. cybersecurity · 66d ago Opening a cloned repo is no longer safe cybersecurity · 66d ago Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse cybersecurity · 66d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 66d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 66d ago Google Colab CLI opens runtimes to Claude Code and Codex cybersecurity · 66d ago VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks cybersecurity · 66d ago Over 20,000 Instagram accounts stolen in Meta AI support hack BleepingComputer · 66d ago The AI governance gap no one is talking about: deployment-stage accountability cybersecurity · 66d ago Security Review Request — TID Linux Kernel Module For [Blue|Purple] Teams in Cyber Defence · 66d ago Building a safe, effective sandbox to enable Codex on Windows For [Blue|Purple] Teams in Cyber Defence · 66d ago Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. For [Blue|Purple] Teams in Cyber Defence · 66d ago About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection For [Blue|Purple] Teams in Cyber Defence · 66d ago BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection For [Blue|Purple] Teams in Cyber Defence · 66d ago Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution. For [Blue|Purple] Teams in Cyber Defence · 66d ago Unauthorized Onlyfans Payment Malware Analysis & Reports · 66d ago Free Study Resources for Comptia Cysa+ cybersecurity · 66d ago What's up with powershellforhackers.com? hacking: security in practice · 66d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 66d ago Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Trend Micro Research, News, Perspectives · 66d ago Hands on with Intelligent Terminal, an AI-powered Windows Terminal BleepingComputer · 66d ago Hi there cybersecurity · 66d ago Final risk-based IT Audit interview round with Director and have no experience. Please help! cybersecurity · 66d ago Needed help cybersecurity · 66d ago HDD Firmware Hacking Part 1 Reverse Engineering · 66d ago [ Removed by Reddit ] cybersecurity · 66d ago UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service. For [Blue|Purple] Teams in Cyber Defence · 66d ago Career advice cybersecurity · 66d ago Do people really click on links from unknown numbers? hacking: security in practice · 66d ago PhD in cyber Security cybersecurity · 66d ago Built a password guessing game. Almost everyone stuck in level 5. cybersecurity · 66d ago OSINT (SOCIAL MEDIA) cybersecurity · 66d ago Beginner KQL project cybersecurity · 66d ago Question about WORM and encryption cybersecurity · 66d ago Update:Certified cyber security cybersecurity · 66d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction Reverse Engineering · 66d ago How to unlock whitelabeled uniview IPcam hacking: security in practice · 66d ago EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server. For [Blue|Purple] Teams in Cyber Defence · 66d ago Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental cybersecurity · 67d ago Can converted video files contain malware? hacking: security in practice · 67d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction) cybersecurity · 67d ago Malware that survives reinstalling the BIOS and OS cybersecurity · 67d ago Am I overthinking the x86 compatibility issues? how much friction am I actually facing? cybersecurity · 67d ago Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure cybersecurity · 67d ago Managing Microsoft Identity Is More Complicated Than It Looks cybersecurity · 67d ago C0XMO botnet spreads via DD-WRT router flaw, kills rival malware BleepingComputer · 67d ago Silent Ransom Group targets law firms with fake IT support calls BleepingComputer · 67d ago Zhiyun Weebil-S Camera Gimbal BLE Protocol Reverse Engineering · 67d ago My work email got subscribed to a bunch of israel newsletters cybersecurity · 67d ago Shadow AI cybersecurity · 67d ago Rate limiting is not enough. What else can I use? cybersecurity · 67d ago CMMC Is Here, But AI Changes The Compliance Conversation Cyber Defense Magazine · 67d ago How To Avoid Potential Malware From Transferring To New Laptop cybersecurity · 67d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 cybersecurity · 67d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 67d ago Can't decide. cybersecurity · 67d ago looking for partners cybersecurity · 67d ago My edge is changing into bing when I search something cybersecurity · 67d ago Reverse Engineering the Garmin Running Dynamics BLE protocol Reverse Engineering · 67d ago Cybersecurity reality check cybersecurity · 67d ago [ Removed by Reddit ] cybersecurity · 67d ago EDRChoker: Choking The Telemetry Stream to Bypass Defenses Technical Information Security Content & Discussion · 67d ago Information Management cybersecurity · 67d ago Pwnd Blaster: Hacking your PC using your speaker without ever touching it For [Blue|Purple] Teams in Cyber Defence · 67d ago cygor: An modular asset discovery framework written in python to automate the repeating manual work For [Blue|Purple] Teams in Cyber Defence · 67d ago On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts. For [Blue|Purple] Teams in Cyber Defence · 67d ago Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors. For [Blue|Purple] Teams in Cyber Defence · 67d ago Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim For [Blue|Purple] Teams in Cyber Defence · 67d ago Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored) For [Blue|Purple] Teams in Cyber Defence · 67d ago The Privileged Roles Nobody Talks About For [Blue|Purple] Teams in Cyber Defence · 67d ago Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain... For [Blue|Purple] Teams in Cyber Defence · 67d ago Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis For [Blue|Purple] Teams in Cyber Defence · 67d ago 21 Zero-Days in FFmpeg For [Blue|Purple] Teams in Cyber Defence · 67d ago IronWorm Malware cybersecurity · 67d ago Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh? cybersecurity · 67d ago Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh? cybersecurity · 67d ago Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager cybersecurity · 67d ago depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research? For [Blue|Purple] Teams in Cyber Defence · 67d ago PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware Technical Information Security Content & Discussion · 67d ago Is a separate “clean” S3 bucket actually a security boundary for uploaded files? cybersecurity · 67d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass Technical Information Security Content & Discussion · 67d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass cybersecurity · 67d ago CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work For [Blue|Purple] Teams in Cyber Defence · 67d ago PenTest+ Exam cybersecurity · 67d ago Rooted your router lately? hacking: security in practice · 67d ago AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs cybersecurity · 67d ago The Detection & Response Chronicles: Covert Operations Through QEMU For [Blue|Purple] Teams in Cyber Defence · 67d ago The Interesting Case of WSL for Payload Staging For [Blue|Purple] Teams in Cyber Defence · 67d ago The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer For [Blue|Purple] Teams in Cyber Defence · 67d ago Ongoing Targeted Campaign Against US Law Firms For [Blue|Purple] Teams in Cyber Defence · 67d ago New China-Linked Cluster OP-512 For [Blue|Purple] Teams in Cyber Defence · 67d ago Looking for guidance cybersecurity · 67d ago 5$ to whoever can find the email of my old YouTube channel hacking: security in practice · 67d ago Before you attempt any OffSec certification, read what just happened to me cybersecurity · 68d ago Reporting Metrics for Management cybersecurity · 68d ago got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time cybersecurity · 68d ago This company is scaming people hacking: security in practice · 68d ago Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried cybersecurity · 68d ago HackTheBox - Facts IppSec · 68d ago Critical Everest Forms Pro flaw exploited to take over WordPress sites BleepingComputer · 68d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. cybersecurity · 68d ago AI Security Certificates cybersecurity · 68d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. For [Blue|Purple] Teams in Cyber Defence · 68d ago Guys is bug bounty dead? cybersecurity · 68d ago How are folks making it in bug bounty? cybersecurity · 68d ago How useful is it to require at least one uppercase letter in a password? cybersecurity · 68d ago Cybersecurity Improved Detection But Exposed a New Problem Cyber Defense Magazine · 68d ago Cyber security ! Is no more ? cybersecurity · 68d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 68d ago MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain For [Blue|Purple] Teams in Cyber Defence · 68d ago Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated For [Blue|Purple] Teams in Cyber Defence · 68d ago Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns For [Blue|Purple] Teams in Cyber Defence · 68d ago About ETW Internals: Architecture, Hooking, Tampering, and Detection For [Blue|Purple] Teams in Cyber Defence · 68d ago PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver For [Blue|Purple] Teams in Cyber Defence · 68d ago Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp For [Blue|Purple] Teams in Cyber Defence · 68d ago Async PICOs and Custom Beacon Wakeups in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 68d ago Enter the WasmForge: Compiling Sliver into WebAssembly For [Blue|Purple] Teams in Cyber Defence · 68d ago staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs For [Blue|Purple] Teams in Cyber Defence · 68d ago Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window For [Blue|Purple] Teams in Cyber Defence · 68d ago Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS For [Blue|Purple] Teams in Cyber Defence · 68d ago BOF Cocktails in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 68d ago Address Translation For [Blue|Purple] Teams in Cyber Defence · 68d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 68d ago Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months cybersecurity · 68d ago Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories cybersecurity · 68d ago Investigation into APT 5 and their inner workings of PLA Troop 61786 For [Blue|Purple] Teams in Cyber Defence · 68d ago How to train employees to feel when something's off? cybersecurity · 68d ago Building A Malware Lab From Scratch Part 2! Malware Analysis & Reports · 68d ago A modular autonomous-agent runtime written in C hacking: security in practice · 68d ago The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy For [Blue|Purple] Teams in Cyber Defence · 68d ago ALERT OVERLOAD cybersecurity · 68d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems For [Blue|Purple] Teams in Cyber Defence · 68d ago Magecart skimmer turns Stripe into a malware command server For [Blue|Purple] Teams in Cyber Defence · 68d ago Security advisory: Brute force attack on Dashlane user accounts For [Blue|Purple] Teams in Cyber Defence · 68d ago Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability For [Blue|Purple] Teams in Cyber Defence · 68d ago A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact). For [Blue|Purple] Teams in Cyber Defence · 68d ago IronWorm: Shai-Hulud's rustier cousin For [Blue|Purple] Teams in Cyber Defence · 68d ago Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate) Reverse Engineering · 68d ago CTO at NCSC Summary: week ending June 7th cybersecurity · 68d ago Weil reportedly pays up to $20 million after hackers steal client data For [Blue|Purple] Teams in Cyber Defence · 68d ago CTO at NCSC Summary: week ending June 7th For [Blue|Purple] Teams in Cyber Defence · 68d ago A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled cybersecurity · 68d ago defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize For [Blue|Purple] Teams in Cyber Defence · 68d ago 1-Click GitHub Token Stealing via a VSCode Bug For [Blue|Purple] Teams in Cyber Defence · 68d ago The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds For [Blue|Purple] Teams in Cyber Defence · 68d ago Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub cybersecurity · 68d ago Detecting npm Native Addon Malware: node-gyp Abuse Malware Analysis & Reports · 68d ago AppSec Engineer Interview Stories cybersecurity · 68d ago [OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps. cybersecurity · 68d ago Multi-layer sandbox for native code execution on Linux with no external deps. For [Blue|Purple] Teams in Cyber Defence · 68d ago Is there a safe way to continue using (unsupported) Windows 10? cybersecurity · 68d ago Is Splunk suitable for smaller Enterprises? cybersecurity · 68d ago Has anyone else had MFA prompt fatigue issues with users? cybersecurity · 68d ago Data Scrubbing from Databases cybersecurity · 68d ago Best Certificates? cybersecurity · 68d ago Rant cybersecurity · 68d ago New York passes data center moratorium and consumer protections as environmental, and housing proposals stall cybersecurity · 68d ago Cyber attackers have a new favorite, the browser cybersecurity · 68d ago Looking to get into cybersecurity in web3 cybersecurity · 68d ago Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests cybersecurity · 68d ago Suspicious Polyfill login prompts pop up on Toshiba, Muji websites BleepingComputer · 68d ago Should i use email 2fa or only auth and phone number? cybersecurity · 68d ago Can I break into cybersecurity with a white collar felony? cybersecurity · 68d ago Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale cybersecurity · 68d ago How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time? cybersecurity · 68d ago What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent? cybersecurity · 68d ago Innovator Spotlight: Airrived Cyber Defense Magazine · 68d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers BleepingComputer · 68d ago How Hard is This cybersecurity · 68d ago Reverse Engineering Crazy Taxi, Part 3 Reverse Engineering · 68d ago Ghidra 12.1.2 has been released! Reverse Engineering · 68d ago Installed Fake Codex hidden as a google site cybersecurity · 68d ago Chinese APT deploys new malware to keep access to hacked networks BleepingComputer · 68d ago Virustital scan result help cybersecurity · 68d ago CrowdStrike Turned an AI Wave Into Its Best Quarter Ever cybersecurity · 68d ago Dark web Nemesis Market vendor gets 26 years for selling drugs BleepingComputer · 68d ago ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more hacking: security in practice · 68d ago Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions? cybersecurity · 68d ago I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now cybersecurity · 68d ago Being a Security Engineer? Which AI-powered tools are you using on a daily basis? cybersecurity · 69d ago Over 900 US gas station tank gauge systems exposed to attacks cybersecurity · 69d ago Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person cybersecurity · 69d ago SIEM is broken in the AI agents era cybersecurity · 69d ago TCM Security CTF Walkthrough The Cyber Mentors · 69d ago Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption Technical Information Security Content & Discussion · 69d ago Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected cybersecurity · 69d ago Extending a map tool for Cataclismo Reverse Engineering · 69d ago Over 900 US gas station tank gauge systems exposed to attacks BleepingComputer · 69d ago Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away CyberScoop · 69d ago Keeping Secrets Out of Logs Technical Information Security Content & Discussion · 69d ago Phantom Gyp npm Worm Abuses node-gyp Build Hooks cybersecurity · 69d ago Certified cybersecurity ISC2 cybersecurity · 69d ago Help studying for OSCP cybersecurity · 69d ago The current state of Threat Intelligence Tooling cybersecurity · 69d ago What 2026 DBIR Confirms: Attacks Are Living in the Browser BleepingComputer · 69d ago Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware cybersecurity · 69d ago I've been reverse engineering a lost 2010 horse MMO and I need contributors Reverse Engineering · 69d ago Cloud Security In Practice Cyber Defense Magazine · 69d ago We tested offensive AI agents against deception technology cybersecurity · 69d ago A matter that I have been losing my sleep over cybersecurity · 69d ago Any experience with Rootly or incident.io for cyber incident management? cybersecurity · 69d ago CTIA Study Resources & Preparation Advice? cybersecurity · 69d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 69d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 69d ago Black hat uk vs brucon cybersecurity · 69d ago Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier) Technical Information Security Content & Discussion · 69d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks cybersecurity · 69d ago NIS2 hits railway hard cybersecurity · 69d ago Introducing Package Proxy: supply-chain safety checks without client-side software For [Blue|Purple] Teams in Cyber Defence · 69d ago I need help guys… :( cybersecurity · 69d ago Question from the Seniors cybersecurity · 69d ago China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware cybersecurity · 69d ago AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer For [Blue|Purple] Teams in Cyber Defence · 69d ago Can one reveal the asterisks in an email? hacking: security in practice · 69d ago what certs have u seen in ai security related job posts ? cybersecurity · 69d ago How is the Security Architecture / Strategic IT Security process structured in your organization? cybersecurity · 69d ago Proxmark3 vs Proxmark5 Side by Side hacking: security in practice · 69d ago Should I go for it? hacking: security in practice · 69d ago What's happening in cybersecurity job market in US and Europe these days? cybersecurity · 69d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links Malware Analysis & Reports · 69d ago Has any of you pivoted from GRC to CTI? cybersecurity · 69d ago Up-date-list of cybercrime types? cybersecurity · 69d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks BleepingComputer · 69d ago HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes Reverse Engineering · 69d ago What else should I learn to build a strong cybersecurity foundation? cybersecurity · 69d ago zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS) For [Blue|Purple] Teams in Cyber Defence · 69d ago Hackerone interview cybersecurity · 69d ago Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix cybersecurity · 69d ago The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory For [Blue|Purple] Teams in Cyber Defence · 69d ago VerdantBamboo: Just Another BRICKSTORM in the Firewall For [Blue|Purple] Teams in Cyber Defence · 69d ago AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID For [Blue|Purple] Teams in Cyber Defence · 69d ago MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code For [Blue|Purple] Teams in Cyber Defence · 69d ago IronWorm Supply Chain Malware Hits npm For [Blue|Purple] Teams in Cyber Defence · 69d ago FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel For [Blue|Purple] Teams in Cyber Defence · 69d ago FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad For [Blue|Purple] Teams in Cyber Defence · 69d ago You do surprise me.exe: An unexpected executable in Hola Browser For [Blue|Purple] Teams in Cyber Defence · 69d ago Testing URL Rewriting? cybersecurity · 69d ago Got an internship in IAM with no qualifications and no soft skills cybersecurity · 69d ago Work Hours of DFIR/Cloud Security vs Pentest cybersecurity · 69d ago Narcissistic Tech Leader.... cybersecurity · 69d ago Anyone else's firewall logs just explode after midnight? cybersecurity · 69d ago I'm replacing myself.. at least the boring parts cybersecurity · 69d ago Anyone else dealing with these phantom login attempts from China? cybersecurity · 69d ago Multi-layer sandbox for native code execution on Linux with no external deps. Reverse Engineering · 69d ago Best way to fully clear windows and set everything up securely (pc, accounts etc) cybersecurity · 69d ago IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks cybersecurity · 69d ago Soc analyst cybersecurity · 69d ago Do companies actually require cybersecurity insurance cybersecurity · 69d ago Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header hacking: security in practice · 69d ago Certification Questions | LIVE AMA | Summer of CCNA NetworkChuck · 69d ago Brave Software releases Origin for a paid, bloat-free browsing experience BleepingComputer · 69d ago Hola Browser for Windows compromised to deliver cryptominer BleepingComputer · 69d ago Credit card theft campaign abuses Stripe to host stolen payment info BleepingComputer · 69d ago Hill Dems hammer GOP for $250M CISA budget cut CyberScoop · 69d ago Uncommon/Unusual CrowdStrike Alerts cybersecurity · 69d ago Cyber analyst: law firm or bank cybersecurity · 69d ago best free av and how do i properly setup passwords? cybersecurity · 69d ago Five 9 Vulnerability cybersecurity · 69d ago Failed to verify LHOST error for long links in metasploit hacking: security in practice · 69d ago CVE Lite CLI closes dependency gap — but won't stop modern threats cybersecurity · 69d ago DentaQuest data breach exposed info of 2.6 million accounts BleepingComputer · 69d ago Scope change cybersecurity · 69d ago We just stopped a social engineering attack on our service desk. Here’s how it played out. cybersecurity · 69d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Reverse Engineering · 69d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Technical Information Security Content & Discussion · 69d ago Your AI agent could become your biggest insider threat CyberScoop · 69d ago What is the most underestimated cybersecurity risk right now? cybersecurity · 69d ago Update: Company is paying for any certification, which should I obtain? Except Sans cybersecurity · 70d ago New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification cybersecurity · 70d ago Anyone else's firewall vendor docs a total nightmare? cybersecurity · 70d ago Your opinions about a learning style cybersecurity · 70d ago UN food agency discloses breach affecting 600,000 Gaza households BleepingComputer · 70d ago Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks cybersecurity · 70d ago New IronWorm malware hits 36 packages in npm supply-chain attack cybersecurity · 70d ago Is Marauder available for ESP32-S3 Mini? hacking: security in practice · 70d ago Anyone else see their firewall logs just explode after a cloud update? cybersecurity · 70d ago Gemini whatsapp hacking: security in practice · 70d ago Are certifications necessary to get a job in cybersecurity? cybersecurity · 70d ago Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass) cybersecurity · 70d ago New IronWorm malware hits 36 packages in npm supply-chain attack BleepingComputer · 70d ago Is retyping and translating textbooks too inefficient for CS/Cybersecurity? cybersecurity · 70d ago Free Microsoft Enterprise Security Assessment: Worth It cybersecurity · 70d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 70d ago How are organizations preparing for AI-generated phishing attacks? cybersecurity · 70d ago Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js Technical Information Security Content & Discussion · 70d ago Inside the race to adapt to an AI-powered security world cybersecurity · 70d ago 127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For cybersecurity · 70d ago Inside the race to adapt to an AI-powered security world CyberScoop · 70d ago Microsoft blames unexpected Windows driver updates on caching issue cybersecurity · 70d ago Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook BleepingComputer · 70d ago Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance) cybersecurity · 70d ago Enter the WasmForge: Compiling Sliver into WebAssembly Technical Information Security Content & Discussion · 70d ago Microsoft blames unexpected Windows driver updates on caching issue BleepingComputer · 70d ago Your CPU model leaks through the browser via WASM timing differences cybersecurity · 70d ago LSASS/Defender/CTFMON analysis For [Blue|Purple] Teams in Cyber Defence · 70d ago Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing Cyber Defense Magazine · 70d ago Software supply chain attacks: check your dependencies For [Blue|Purple] Teams in Cyber Defence · 70d ago Police dismantles fake ID marketplace used by migrant smugglers BleepingComputer · 70d ago void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies Reverse Engineering · 70d ago Chinese Cybercrime Group in Spotlight for Record Campaign Pace cybersecurity · 70d ago NAVTOR NavBox All CISA Advisories · 70d ago Hitachi Energy MACH HiDraw All CISA Advisories · 70d ago Hitachi Energy ITT600 Explorer All CISA Advisories · 70d ago B&R PPT30 Operating System All CISA Advisories · 70d ago Hitachi Energy RTU500 All CISA Advisories · 70d ago Extremely suspicious behaviour by memu emulator Malware Analysis & Reports · 70d ago Security Engineer 2 interview at Amazon coming up - What to expect? cybersecurity · 70d ago A researcher spent $1,500 testing if LLMs could hack a vulnerable app cybersecurity · 70d ago Help with university internship cybersecurity · 70d ago Are MCP servers becoming the next API security nightmare? cybersecurity · 70d ago Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator For [Blue|Purple] Teams in Cyber Defence · 70d ago Cisco warns of critical Unified CM flaw with PoC exploit code BleepingComputer · 70d ago What's the cybersecurity lesson you learned the hard way? cybersecurity · 70d ago ISO 27001 Surveillance audit vs Full recertification cybersecurity · 70d ago How important it is to get paid Cybersecurity certificates ? cybersecurity · 70d ago Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process cybersecurity · 70d ago Soc to Architecture cybersecurity · 70d ago Does "example file vulnerability" exists? cybersecurity · 70d ago VS code forces 2 hour cool down for most integrations. cybersecurity · 70d ago Company laptop isolated after Brave/Tor alert - should I be worried? cybersecurity · 70d ago Does anyone know how to send false positive to SOCradar ? virus total cybersecurity · 70d ago Looking for people to team up for Bug Bounties & CTFs cybersecurity · 70d ago Signal Without Smartphone cybersecurity · 70d ago I found a trojan on my pc and now im scared my private calls got leaked cybersecurity · 70d ago Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests cybersecurity · 70d ago CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog cybersecurity · 70d ago How do you change users behavior through awareness training? cybersecurity · 70d ago AI-built ransomware toolkit automates EDR evasion, AD discovery cybersecurity · 70d ago 29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection) For [Blue|Purple] Teams in Cyber Defence · 70d ago Safe Rust API for wolfSSL/wolfCOSE hacking: security in practice · 70d ago Safe Rust API for wolfSSL/wolfCOSE cybersecurity · 70d ago Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma) cybersecurity · 70d ago AMD GPU Users might be compromised cybersecurity · 70d ago [ Removed by Reddit ] cybersecurity · 70d ago Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information cybersecurity · 70d ago CISA warns of cyberattacks targeting fuel tank monitoring systems cybersecurity · 70d ago [CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF cybersecurity · 70d ago how to get good at cyber security? cybersecurity · 70d ago Anyone use CrunchAtlas? cybersecurity · 70d ago Prompt monitoring laughs cybersecurity · 70d ago Malicious Payload in ai-sdk-ollama npm Package cybersecurity · 70d ago Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24) cybersecurity · 70d ago Resource Exhaustion hacking: security in practice · 70d ago what the HELL is dsztfso? cybersecurity · 70d ago Open Source - 2500 New MITRE Mutations For [Blue|Purple] Teams in Cyber Defence · 70d ago Yubikey Alternative....? cybersecurity · 70d ago Hiring cybersecurity · 70d ago Malware Malware Analysis & Reports · 70d ago CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing cybersecurity · 70d ago Agent-Ready: How to Prepare Your Site for AI-Driven Commerce Blog – Forter · 70d ago Certification Advice cybersecurity · 70d ago Question about Linux kernel TLS ULP disclosed June 2 to oss-security cybersecurity · 70d ago European authorities crack down on illegal streaming networks CyberScoop · 70d ago An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this? cybersecurity · 70d ago Chinese hackers use new Atlas RAT malware in European cyberattacks BleepingComputer · 70d ago How to Rob a Data Center (new article on data center physical security) cybersecurity · 70d ago Hermes has a Home Assistant skill and it's unreal! NetworkChuck · 70d ago US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server cybersecurity · 70d ago Is it worth taking the EC councils masters program?? Are they legit /2026 cybersecurity · 70d ago Mid-level AppSec engineers: what do you actually study to prep for interviews? cybersecurity · 70d ago Automated Fault Injection Attack Framework Reverse Engineering · 70d ago The U.S. sanctions Nobitex crypto exchange used by ransomware BleepingComputer · 70d ago CISA warns of cyberattacks targeting fuel tank monitoring systems BleepingComputer · 70d ago Season VI of the US Games launches TOMORROW! Technical Information Security Content & Discussion · 70d ago Company is paying for any certification, which should I obtain? cybersecurity · 70d ago DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels CyberScoop · 70d ago Trusting Microsoft with your offensive security repos cybersecurity · 70d ago Automated Fault Injection Attack Framework cybersecurity · 70d ago Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT For [Blue|Purple] Teams in Cyber Defence · 70d ago Bring Your Own RWX Region DLL (BYORWXDLL) For [Blue|Purple] Teams in Cyber Defence · 70d ago Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem For [Blue|Purple] Teams in Cyber Defence · 70d ago APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component For [Blue|Purple] Teams in Cyber Defence · 70d ago NuGet Code Execution As A Service For [Blue|Purple] Teams in Cyber Defence · 70d ago aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies For [Blue|Purple] Teams in Cyber Defence · 70d ago Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor For [Blue|Purple] Teams in Cyber Defence · 70d ago TA4922: The Suspected Chinese Crime Group is Going Global For [Blue|Purple] Teams in Cyber Defence · 70d ago [ Removed by Reddit ] For [Blue|Purple] Teams in Cyber Defence · 70d ago New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute BleepingComputer · 70d ago Physical Biometric device as a security measure..?? cybersecurity · 70d ago Espionage Campaign Targeted Stock Exchange Executive for Five Months For [Blue|Purple] Teams in Cyber Defence · 70d ago Cybersegurança cybersecurity · 70d ago Started Learning Cybersecurity cybersecurity · 70d ago InfraGard Application - Seeking Help | Student cybersecurity · 70d ago x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994) Reverse Engineering · 70d ago Orientación en Ciberseguridad cybersecurity · 70d ago OnionAccelerator: multi-circuit / chunked download acceleration over Tor For [Blue|Purple] Teams in Cyber Defence · 70d ago Anthropic's coordinated vulnerability disclosure dashboard cybersecurity · 70d ago Hands Free: What LLM Driven Vulnerability Research Looks Like cybersecurity · 70d ago HazyBeacon and AWS Lambda Function URL Abuse For [Blue|Purple] Teams in Cyber Defence · 71d ago Real time Cybersecurity failures regarding Quantum computing/cryptography cybersecurity · 71d ago The Server Seizure That Affects Also Iran's Cyber Operations For [Blue|Purple] Teams in Cyber Defence · 71d ago How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad For [Blue|Purple] Teams in Cyber Defence · 71d ago 🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop Malware Analysis & Reports · 71d ago 🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It. cybersecurity · 71d ago 🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network For [Blue|Purple] Teams in Cyber Defence · 71d ago Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2 Reverse Engineering · 71d ago A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out. cybersecurity · 71d ago CISA warns of active attacks exploiting Android, Linux bugs cybersecurity · 71d ago Found some open ports on a govt site, should i report or stay quiet? cybersecurity · 71d ago What is a good way to keep track of passwords for programs that don't support password managers? cybersecurity · 71d ago CISA warns of active attacks exploiting Android, Linux bugs BleepingComputer · 71d ago ChatGPT Malvertising Campaign Malware Analysis & Reports · 71d ago Cybersecurity statistics of the week (May 25th - May 31st) cybersecurity · 71d ago ASN Emissions Index. Networks ranked by how much noise they create on the internet. cybersecurity · 71d ago Have you sold cve before? cybersecurity · 71d ago EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires Technical Information Security Content & Discussion · 71d ago i want to become a pentester, but i don't know how to cybersecurity · 71d ago Recommendation Malware Analysis & Reports · 71d ago I’m not sure I’m in the right subreddit…. hacking: security in practice · 71d ago The OT Security Problem Nobody Wants to Own cybersecurity · 71d ago Don't Take Wednesday Off When You Manage Vulnerabilities cybersecurity · 71d ago I finally finished a production version after 4 yrds cybersecurity · 71d ago Support role pivot to cloud security cybersecurity · 71d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 71d ago What 345 Days of Untested Exposure Looks Like at a Bank BleepingComputer · 71d ago Took me a decade to turn quantum computing into what hackers can easily learn hacking: security in practice · 71d ago Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6! Malware Analysis & Reports · 71d ago How do you manage your passwords? cybersecurity · 71d ago The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector Cyber Defense Magazine · 71d ago Mad rush to produce AI driven slop cybersecurity · 71d ago O Tails é seguro para acessar links suspeitos? cybersecurity · 71d ago Took me a decade of work to turn Quantum Computing into a fun videogame hacking: security in practice · 71d ago Interesting- What LLM vuln research looks like Technical Information Security Content & Discussion · 71d ago Cyber Essentials plus + "legacy" network segments cybersecurity · 71d ago Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors For [Blue|Purple] Teams in Cyber Defence · 71d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 71d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 71d ago Acer working to patch max severity zero-days in Wave 7 routers BleepingComputer · 71d ago Hacking your PC using your speaker without ever touching it Reverse Engineering · 71d ago Hacking your PC using your speaker without ever touching it Technical Information Security Content & Discussion · 71d ago Insight for OPSWAT deep CDR cybersecurity · 71d ago Android vs iOS cybersecurity · 71d ago ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account cybersecurity · 71d ago Police dismantles 9 crime groups in illegal streaming crackdown BleepingComputer · 71d ago Security Audits at an MSP cybersecurity · 71d ago [ Removed by Reddit ] cybersecurity · 71d ago Google adds Android protection against AI deepfake scam calls BleepingComputer · 71d ago Passkey registration breaks after moving off localhost.. cybersecurity · 71d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 71d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 71d ago Does your team hire fresh AI engineer who doesn't know anything about Security operations? cybersecurity · 71d ago UARs for Equation (banking system) cybersecurity · 71d ago Simple way how to bypass hotel WiFi? hacking: security in practice · 71d ago VS Code zero-day lets hackers steal GitHub tokens in one click hacking: security in practice · 71d ago Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing Technical Information Security Content & Discussion · 71d ago IoT pentesting cert cybersecurity · 71d ago Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations cybersecurity · 71d ago Experience with Tac Security cybersecurity · 71d ago Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content cybersecurity · 71d ago VS Code zero-day lets hackers steal GitHub tokens in one click BleepingComputer · 71d ago Golang code review notes II - elttam Technical Information Security Content & Discussion · 71d ago Using AI to Secure Its Generated Code Is a Ponzi Scheme Technical Information Security Content & Discussion · 71d ago Found Security Vulnerabilities in my university website cybersecurity · 71d ago burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API) hacking: security in practice · 71d ago Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence cybersecurity · 71d ago AI - Threat to the CyberSec Industry? cybersecurity · 71d ago Built a honeypot platform to catch lateral movement. How are you guys detecting this? cybersecurity · 71d ago How should small SaaS teams safely answer customer security questionnaires? cybersecurity · 71d ago Dependency Cooldowns - Dependency Cooldowns For [Blue|Purple] Teams in Cyber Defence · 71d ago Can AI Do Intelligence Analysis? Apparently Not. cybersecurity · 71d ago PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model cybersecurity · 71d ago Regarding Certified Ethical Hacker (CEH Practical) exam cybersecurity · 71d ago Asking for advices on pursuing first CERTIFICATE cybersecurity · 71d ago I opened my own company and I can't find clients! cybersecurity · 71d ago ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter cybersecurity · 71d ago C2 Frameworks - Threat Hunting in Action with YARA Rules For [Blue|Purple] Teams in Cyber Defence · 71d ago How big of a security risk or exploit would this be? hacking: security in practice · 71d ago Microsoft's Coreutils project brings Linux commands to Windows BleepingComputer · 71d ago Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU? cybersecurity · 71d ago Anyone knows Quad9 dns ? cybersecurity · 71d ago OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models BleepingComputer · 71d ago KTO , Be the only one online -- on any WiFi network hacking: security in practice · 71d ago Critical Kirki flaw exploited to hijack WordPress admin accounts BleepingComputer · 71d ago Over 116,000 Mincraft systems infected in WeedHack malware campaign BleepingComputer · 71d ago Over 116,000 Minecraft systems infected in WeedHack malware campaign BleepingComputer · 71d ago Ransomware tabletop For [Blue|Purple] Teams in Cyber Defence · 71d ago FREE coffee at Cisco Live (I'm giving it away) NetworkChuck · 71d ago I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ? cybersecurity · 71d ago Greynoise swarm cybersecurity · 71d ago SecOT+ certification for free cybersecurity · 71d ago How is the state of the job market for mid-level security engineers? cybersecurity · 71d ago Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things cybersecurity · 71d ago WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total cybersecurity · 71d ago Laid off from TPRM job - need help on the future of my career cybersecurity · 71d ago News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces The Last Watchdog · 71d ago Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 For [Blue|Purple] Teams in Cyber Defence · 71d ago Tracking North Korea Nation-State APT Infrastructure: Kimsuky For [Blue|Purple] Teams in Cyber Defence · 71d ago 새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn For [Blue|Purple] Teams in Cyber Defence · 71d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 71d ago AI-built ransomware toolkit automates EDR evasion, AD discovery BleepingComputer · 71d ago apparently bypassing school systems by playing games hacking: security in practice · 71d ago Anyone compared RoboShadow vs ConnectSecure for vulnerability management? cybersecurity · 71d ago Codex Discovered a Hidden HTTP/2 Bomb For [Blue|Purple] Teams in Cyber Defence · 71d ago Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes Technical Information Security Content & Discussion · 71d ago Top 5 Active Directory Pentesting Tools The Cyber Mentors · 71d ago Any one send vulnerability to MITRE? cybersecurity · 71d ago Need advice for a 30 min Security Apprenticeship interview cybersecurity · 71d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 71d ago Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix For [Blue|Purple] Teams in Cyber Defence · 71d ago UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS cybersecurity · 71d ago Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match cybersecurity · 71d ago We Added a Detection Rule. We Were Not Expecting This. Technical Information Security Content & Discussion · 71d ago Introducing Microsoft Scout: Your always-on personal agent Microsoft 365 Blog · 71d ago Virustotal API as private data source cybersecurity · 71d ago DOD wants to integrate cyber in all operations, and integrate security into AI CyberScoop · 71d ago Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source! Reverse Engineering · 71d ago Microsoft Exchange Online outage causes email delays, failures BleepingComputer · 72d ago Announcing the new Work IQ APIs Microsoft 365 Blog · 72d ago Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases Security | Microsoft Azure Blog | Microsoft Azure · 72d ago Trump administration releases scaled-back AI executive order CyberScoop · 72d ago Account Number Security Flaw cybersecurity · 72d ago Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning? cybersecurity · 72d ago A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth cybersecurity · 72d ago [ Removed by Reddit ] cybersecurity · 72d ago [ Removed by Reddit ] cybersecurity · 72d ago “Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?” For [Blue|Purple] Teams in Cyber Defence · 72d ago Instagram users locked out after Meta AI abused to steal accounts BleepingComputer · 72d ago Phishing simulation platform cybersecurity · 72d ago 1-Click GitHub Token Stealing via a VSCode Bug Technical Information Security Content & Discussion · 72d ago Just task about OSI model cybersecurity · 72d ago FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential The Last Watchdog · 72d ago Need help improving DNS Spy from a security tool angle cybersecurity · 72d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild cybersecurity · 72d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild Technical Information Security Content & Discussion · 72d ago Oracle's first monthly patch update just dropped 77 CVEs. cybersecurity · 72d ago Cleaning up after a legacy service account breach. How are you handling automated secrets discovery? cybersecurity · 72d ago Airbus digital apprenticeship cybersecurity · 72d ago Built a decompiler for exotic legacy programming language opentext Gupta Team Developer Reverse Engineering · 72d ago Always-On Red Teams hacking: security in practice · 72d ago Why the browser is now the front line for AI security BleepingComputer · 72d ago Anthropic expanding access to Project Glasswing CyberScoop · 72d ago Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities cybersecurity · 72d ago [An RX Global Event] Infosecurity Europe darkreading · 72d ago Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit Cyber Defense Magazine · 72d ago This is a scam and probably a malware/trojan. Path Of Exile 2 builder ... Malware Analysis & Reports · 72d ago CISA flags two-year-old Oracle flaw as actively exploited in attacks BleepingComputer · 72d ago Google fixes one actively exploited Android zero-day, 124 flaws cybersecurity · 72d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 72d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems All CISA Advisories · 72d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 72d ago Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force cybersecurity · 72d ago Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis? cybersecurity · 72d ago Security Architects who who actively use modelling - What's your approach? cybersecurity · 72d ago PAN-OS authentication bypass bug added to list of exploited vulnerabilities cybersecurity · 72d ago Google fixes one actively exploited Android zero-day, 124 flaws BleepingComputer · 72d ago I have extreme anxiety about being hacked cybersecurity · 72d ago Fresher cybersecurity · 72d ago Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif For [Blue|Purple] Teams in Cyber Defence · 72d ago Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand For [Blue|Purple] Teams in Cyber Defence · 72d ago Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach cybersecurity · 72d ago Career advice needed! cybersecurity · 72d ago LLMShare: using shared chatbot pages to distribute malware Malware Analysis & Reports · 72d ago GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure cybersecurity · 72d ago Google sr. security engineer interview cybersecurity · 72d ago Is offensive AI actually changing cybersecurity, or are we overestimating the impact? cybersecurity · 72d ago Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave cybersecurity · 72d ago is emerald chat safe? cybersecurity · 72d ago Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm For [Blue|Purple] Teams in Cyber Defence · 72d ago Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ? cybersecurity · 72d ago ClickJack in the wild cybersecurity · 72d ago NuGet Code Execution As A Service Technical Information Security Content & Discussion · 72d ago Thoughts on A.I assisted Malware Analysis? cybersecurity · 72d ago 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access cybersecurity · 72d ago What articles do you use for cybersecurity news? (2026) cybersecurity · 72d ago Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider? cybersecurity · 72d ago Roadmap and Training Recommodation cybersecurity · 72d ago Attackers are exploiting Palo Alto Networks defect that initially flew under the radar CyberScoop · 72d ago I managed to pull the full system prompt for Meta's Support AI hacking: security in practice · 72d ago Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks BleepingComputer · 72d ago Les anti-triche de niveau noyau et leur risque de sécurité cybersecurity · 72d ago Harassing text messages hacking: security in practice · 72d ago Asked to Send Sensitive Documents via MMS cybersecurity · 72d ago Red Hat npm packages compromised to steal developer credentials BleepingComputer · 72d ago SC-200 compared to CC (isc2) cybersecurity · 72d ago Spain arrests doxer leaking sensitive data of govt employees BleepingComputer · 72d ago running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it! Reverse Engineering · 72d ago Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB) Technical Information Security Content & Discussion · 72d ago Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now cybersecurity · 72d ago Looking to move off KB4, what are people actually using these days? cybersecurity · 72d ago Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight CyberScoop · 72d ago Got my Security+. What's next? cybersecurity · 72d ago Vulnerability Summary for the Week of May 25, 2026 cybersecurity · 72d ago RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation For [Blue|Purple] Teams in Cyber Defence · 72d ago Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages For [Blue|Purple] Teams in Cyber Defence · 72d ago Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches For [Blue|Purple] Teams in Cyber Defence · 72d ago REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY! hacking: security in practice · 72d ago Malware cybersecurity · 72d ago Dashlane password manager users locked out by brute force attacks BleepingComputer · 72d ago Alternative Search Engine to Utilize in 2026? cybersecurity · 72d ago Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked cybersecurity · 72d ago Miasma: Supply Chain Attack Targeting RedHat npm Packages For [Blue|Purple] Teams in Cyber Defence · 72d ago USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order CyberScoop · 72d ago Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild cybersecurity · 72d ago Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers cybersecurity · 72d ago Hacking Palo Alto Networks' GlobalProtect VPN with AI hacking: security in practice · 72d ago AI compliance cybersecurity · 72d ago Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm cybersecurity · 72d ago WordPress malware campaign hides payloads in Steam profiles BleepingComputer · 73d ago Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains? cybersecurity · 73d ago MacBook or Windows Laptop for Cybersecurity cybersecurity · 73d ago What's the most creative MFA bypass you've seen? cybersecurity · 73d ago @redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers For [Blue|Purple] Teams in Cyber Defence · 73d ago Research Notes from Building a Windows Event Log Hunting Workflow cybersecurity · 73d ago Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am. hacking: security in practice · 73d ago How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ?? cybersecurity · 73d ago Free AI tools for TPRM? cybersecurity · 73d ago incomplete phone number from togo, need help reporting to police cybersecurity · 73d ago NPM packages from RedHat Compromised cybersecurity · 73d ago Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts cybersecurity · 73d ago Microsoft investigates Office Apps, Teams file access issues BleepingComputer · 73d ago SOC Analyst working towards Threat Intelligence cybersecurity · 73d ago Is XSS possible through PDFs? cybersecurity · 73d ago Race Against Time: Why Faster Vulnerability Alerts Matter BleepingComputer · 73d ago Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider Technical Information Security Content & Discussion · 73d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 73d ago The Next AI Governance Failure Won’t Be the Model cybersecurity · 73d ago Poisoning Claude Code: One GitHub Issue to Break the Supply Chain Technical Information Security Content & Discussion · 73d ago Microsoft MFA Is Down Again cybersecurity · 73d ago Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927) cybersecurity · 73d ago Stealing Passwords via HTML Injection Under a Strict CSP Technical Information Security Content & Discussion · 73d ago Computer logic or Science cybersecurity · 73d ago Critical Windows Netlogon RCE flaw now exploited in attacks BleepingComputer · 73d ago Webinar tomorrow: From alert to resolution in network incident response BleepingComputer · 73d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 73d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 73d ago I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for? cybersecurity · 73d ago What C2s Are You Using cybersecurity · 73d ago Microsoft confirms outage affecting MFA, My Sign-Ins platform BleepingComputer · 73d ago Microsoft fixes outage affecting MFA setup, MySignIn service BleepingComputer · 73d ago Microsoft fixes KB5089549 Windows security update install issues BleepingComputer · 73d ago Best AI LLM for Hacking related stuff hacking: security in practice · 73d ago PNPT Exam cybersecurity · 73d ago Election threats are focused on campaign systems, not voting machines CyberScoop · 73d ago What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification? cybersecurity · 73d ago Feels like most people ignore the wireless layer until it bites them hacking: security in practice · 73d ago Any appsec engineer working in fortune 500? cybersecurity · 73d ago I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next cybersecurity · 73d ago Anyone transition from AWS Data Center Operations to InfoSec? cybersecurity · 73d ago I think my account got hacked but it's weird cybersecurity · 73d ago Subnet discovery through multi-protocol TTL tracing Technical Information Security Content & Discussion · 73d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 73d ago current market for detecting deepfakes? cybersecurity · 73d ago Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched For [Blue|Purple] Teams in Cyber Defence · 73d ago Worried about friend being doxxed on doxbin cybersecurity · 73d ago Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks For [Blue|Purple] Teams in Cyber Defence · 73d ago Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries For [Blue|Purple] Teams in Cyber Defence · 73d ago how to shift from a service based company to a product based one in cybersecurity ? cybersecurity · 73d ago Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA cybersecurity · 73d ago Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking? hacking: security in practice · 73d ago Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign For [Blue|Purple] Teams in Cyber Defence · 73d ago Claude AI user data directory exfiltration via malicious npm package cybersecurity · 73d ago Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from? Reverse Engineering · 73d ago Bitdefender blocking amd stuff? False positive or? cybersecurity · 73d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 73d ago Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet Trend Micro Research, News, Perspectives · 73d ago did they have my password?? what triggers this specific email??? instagram HELP. cybersecurity · 73d ago How to Unpack FlawedAmmyy - Malware Unpacking Tutorial Malware Analysis & Reports · 73d ago ATTENTION: Dashlane may have been breached. (Password manager). cybersecurity · 73d ago Can anyone figure out how to retrieve the recovery key in signal app? hacking: security in practice · 73d ago Norton blocked a “malicious script”? cybersecurity · 73d ago Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts cybersecurity · 73d ago Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive. cybersecurity · 73d ago I wrote about the 5 biggest threats in 2026, curious what this community thinks. cybersecurity · 73d ago MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce? cybersecurity · 73d ago Atomdrift - open-source malware detection for the software supply chain For [Blue|Purple] Teams in Cyber Defence · 73d ago Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions? cybersecurity · 73d ago NetworkChuck cybersecurity · 73d ago LLM for creating phishing tool cybersecurity · 74d ago Why are we still treating IAM like a compliance checkbox? cybersecurity · 74d ago Polyfill pop up? cybersecurity · 74d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Technical Information Security Content & Discussion · 74d ago Building A Malware Lab From Scratch! Malware Analysis & Reports · 74d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Reverse Engineering · 74d ago WP Maps Pro bug exploited to create admin accounts on WordPress sites BleepingComputer · 74d ago SecAI+ difficulty question cybersecurity · 74d ago $730k+ raised on Proxmark5 with 2150 backers hacking: security in practice · 74d ago Could you guys give an honest feedback to a completely automated ssrf attack tool? cybersecurity · 74d ago tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me cybersecurity · 74d ago Microsoft Joined the DMARC Club cybersecurity · 74d ago Help. cybersecurity · 74d ago Vibe Coding Security cybersecurity · 74d ago I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works) hacking: security in practice · 74d ago Looking for a Company to Partner With cybersecurity · 74d ago Best reporting tools? cybersecurity · 74d ago What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months) cybersecurity · 74d ago Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens For [Blue|Purple] Teams in Cyber Defence · 74d ago How Can Polyfill.io Still Act Maliciously? cybersecurity · 74d ago 179 npm Packages Target Cloud and Finance via oob.moika.tech For [Blue|Purple] Teams in Cyber Defence · 74d ago KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4 For [Blue|Purple] Teams in Cyber Defence · 74d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 74d ago Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services For [Blue|Purple] Teams in Cyber Defence · 74d ago TinyLoad v7 - what i added :D (in memory protection using VEH and alot more) Reverse Engineering · 74d ago EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA For [Blue|Purple] Teams in Cyber Defence · 74d ago Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace For [Blue|Purple] Teams in Cyber Defence · 74d ago Signal macOS Desktop App Doesn't Actually Delete Messages When it Should For [Blue|Purple] Teams in Cyber Defence · 74d ago Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan For [Blue|Purple] Teams in Cyber Defence · 74d ago WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD For [Blue|Purple] Teams in Cyber Defence · 74d ago Any idea who's behind this hack? How to resolve it? hacking: security in practice · 74d ago Typosquatted npm packages used to steal cloud and CI/CD secrets For [Blue|Purple] Teams in Cyber Defence · 74d ago Need THM voucher code for cheap? Any known seller? cybersecurity · 74d ago Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2 For [Blue|Purple] Teams in Cyber Defence · 74d ago Malicious npm packages abuse dependency confusion to profile developer environments For [Blue|Purple] Teams in Cyber Defence · 74d ago Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) For [Blue|Purple] Teams in Cyber Defence · 74d ago Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack For [Blue|Purple] Teams in Cyber Defence · 74d ago CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied." For [Blue|Purple] Teams in Cyber Defence · 74d ago Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign For [Blue|Purple] Teams in Cyber Defence · 74d ago SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks. For [Blue|Purple] Teams in Cyber Defence · 74d ago EDR Incident Response Playbook: Containing Local Account Incidents For [Blue|Purple] Teams in Cyber Defence · 74d ago Adversarial Oracles: LLM-Guided EDR Signature Reduction For [Blue|Purple] Teams in Cyber Defence · 74d ago One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF For [Blue|Purple] Teams in Cyber Defence · 74d ago proxy: A lightweight caching proxy for package registries. For [Blue|Purple] Teams in Cyber Defence · 74d ago How OLTs may have exposed entire ISP networks For [Blue|Purple] Teams in Cyber Defence · 74d ago Ghost passwords? cybersecurity · 74d ago Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it hacking: security in practice · 74d ago A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years For [Blue|Purple] Teams in Cyber Defence · 74d ago HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics For [Blue|Purple] Teams in Cyber Defence · 74d ago Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots For [Blue|Purple] Teams in Cyber Defence · 74d ago Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures For [Blue|Purple] Teams in Cyber Defence · 74d ago Lessons from Penetration Tests on Large-Scale Agent Systems For [Blue|Purple] Teams in Cyber Defence · 74d ago pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter. For [Blue|Purple] Teams in Cyber Defence · 74d ago [ Removed by Reddit ] Reverse Engineering · 74d ago Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not. cybersecurity · 74d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 74d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions Technical Information Security Content & Discussion · 74d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions cybersecurity · 74d ago Anyone else having Chatgpt Strikes / Violations while learning cybersecurity? cybersecurity · 74d ago Blue Team tips? hacking: security in practice · 74d ago Working at Cisco, worth it? cybersecurity · 74d ago Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice cybersecurity · 74d ago usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer) Reverse Engineering · 74d ago CIFSwitch: a non-universal Linux local root vulnerability For [Blue|Purple] Teams in Cyber Defence · 74d ago Are you pen testing AI Agents? cybersecurity · 74d ago Question of android malware cybersecurity · 74d ago External attack surface: how are you correlating DNS, SSL, and IP reputation today? cybersecurity · 74d ago edit certified pdf hacking: security in practice · 74d ago how do i properly setup 2fa and bitwarden? cybersecurity · 74d ago Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC) cybersecurity · 74d ago i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested? cybersecurity · 74d ago Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever? cybersecurity · 74d ago I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux) Reverse Engineering · 74d ago Can Steam Cloud Files Transfer Malware cybersecurity · 74d ago I bought an old phone from 2018 and wanna destroy it with viruses for fun Malware Analysis & Reports · 74d ago Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks BleepingComputer · 74d ago HackTheBox - Interpreter IppSec · 75d ago Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension For [Blue|Purple] Teams in Cyber Defence · 75d ago Questions for the cloud security engineers cybersecurity · 75d ago DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database. For [Blue|Purple] Teams in Cyber Defence · 75d ago Visual Studio Extensions Revisited For [Blue|Purple] Teams in Cyber Defence · 75d ago Thoughts on this as a starter and doing bug bounty on the side cybersecurity · 75d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 75d ago How are new SC-200 candidates practicing labs without an E5 Developer tenant? cybersecurity · 75d ago New CIFSwitch Linux flaw gives root on multiple distributions BleepingComputer · 75d ago Everyday hacking in our lives - transportation, work, finances, goods etc hacking: security in practice · 75d ago Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters Technical Information Security Content & Discussion · 75d ago Getting OTP spammed from every app and website I've ever used. Should I be worried? cybersecurity · 75d ago BYOVD and Looting LSASS in the Modern EDR Era For [Blue|Purple] Teams in Cyber Defence · 75d ago A browser tool for checking contractor insurance certificates cybersecurity · 75d ago Am I getting screwed? cybersecurity · 75d ago SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers cybersecurity · 75d ago PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29} cybersecurity · 75d ago CTO at NCSC Summary: week ending May 31st cybersecurity · 75d ago CTO at NCSC Summary: week ending May 31st For [Blue|Purple] Teams in Cyber Defence · 75d ago BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship cybersecurity · 75d ago OffensiveCon26 videos For [Blue|Purple] Teams in Cyber Defence · 75d ago Need suggestion cybersecurity · 75d ago Malware escaped browser without downloading files, then escaped a virtual machine Malware Analysis & Reports · 75d ago [INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety) cybersecurity · 75d ago Was Dave Bittner interviewing an AI? cybersecurity · 75d ago CTF for complete beginner cybersecurity · 75d ago Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques? cybersecurity · 75d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 75d ago AI-Era Cyber Risk Standards cybersecurity · 75d ago BEC Victim - Attacker replied inside a real email thread using a lookalike domain cybersecurity · 75d ago School Survey, (non-paid nothing its free its for my grades) For [Blue|Purple] Teams in Cyber Defence · 75d ago Question for those who transitioned from remote to work from anywhere cybersecurity · 75d ago Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors cybersecurity · 75d ago Do you enjoy what you do or do you wish you could go back in time and change it? cybersecurity · 75d ago Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber? cybersecurity · 75d ago A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.) Technical Information Security Content & Discussion · 75d ago For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year? cybersecurity · 75d ago Name That Toon: Mark of (Cybersecurity) Progress darkreading · 75d ago Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ? cybersecurity · 75d ago Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years? cybersecurity · 75d ago Botnet of more than 17 million devices dismantled cybersecurity · 75d ago Exposed credentials on logs cybersecurity · 75d ago Do you think this is legit or has the website been compromised? hacking: security in practice · 75d ago Introducing Keyhog: The First GPU Accelerated secret scanner Technical Information Security Content & Discussion · 75d ago What do you think is the biggest cybersecurity risk for small businesses in 2026? cybersecurity · 75d ago Wanted to shift to cloud security, but have some questions cybersecurity · 75d ago OffensiveCon26 YouTube Playlist released Technical Information Security Content & Discussion · 75d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments For [Blue|Purple] Teams in Cyber Defence · 75d ago LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms For [Blue|Purple] Teams in Cyber Defence · 75d ago ChatGPT share links abused to host fake outage pages to deliver malware BleepingComputer · 75d ago Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 CyberScoop · 75d ago California AG sues 23andMe over 2023 breach exposing health data BleepingComputer · 75d ago Zero Trust is Overrated? Navigating the Complexity cybersecurity · 75d ago Test API post with flair cybersecurity · 75d ago Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications cybersecurity · 75d ago How Do You Handle the Massive Amount of Information in the CPTS Path? cybersecurity · 75d ago Wanna learn cybersecurity & ethical hacking hacking: security in practice · 75d ago LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting For [Blue|Purple] Teams in Cyber Defence · 76d ago Help an upcoming cybersecurity engineer! cybersecurity · 76d ago Repeated Microsoft MFA attempts even after password change cybersecurity · 76d ago I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but Malware Analysis & Reports · 76d ago Do you guys take paper notes or digital ones during studying ? hacking: security in practice · 76d ago What Is Device Intelligence and How Does It Stop Fraud? cybersecurity · 76d ago [FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE) cybersecurity · 76d ago Federal audit reveals NIST’s NVD is plagued by poor planning and duplication CyberScoop · 76d ago Ghidra 12.1.1 has been released! Reverse Engineering · 76d ago IBM commits $5 billion to secure open-source software cybersecurity · 76d ago Structuring an AI-Assisted Pentesting Homelab for a Final Year Project cybersecurity · 76d ago Are teams actually monitoring LLM traffic in production environments? cybersecurity · 76d ago How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA) cybersecurity · 76d ago Raspberry pi cybersecurity · 76d ago Asia's Cyber Insurance Market Shows Signs of Life darkreading · 76d ago What is the biggest obstacle to using AI safely in a company? cybersecurity · 76d ago From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market BleepingComputer · 76d ago Dutch govt disrupts malware botnet with 17 million infected devices BleepingComputer · 76d ago Advice going forward cybersecurity · 76d ago MCP Firewall help cybersecurity · 76d ago I wanted to shift to security but people told me the market is extremely bad, is that true? cybersecurity · 76d ago Best Personality Type/Traits for Working in Cyber Security cybersecurity · 76d ago Identifying attack patterns through kernel frame callstacks For [Blue|Purple] Teams in Cyber Defence · 76d ago A fake freelance job interview almost installed malware on my PC cybersecurity · 76d ago Is there a viable career path here or am I just being delusional? cybersecurity · 76d ago With Complex Cloud Integrations, Small Errors Lead to Major Compromises darkreading · 76d ago What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks cybersecurity · 76d ago Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness For [Blue|Purple] Teams in Cyber Defence · 76d ago Google Chrome adds session cookie theft protection for all users BleepingComputer · 76d ago 'The Com' Cyberattacks Support Violence & Sexploitation darkreading · 76d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 76d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 76d ago How do enterprises actually prevent developers from exfiltrating source code? cybersecurity · 76d ago Man sent to prison for selling data of 7 millions elderly Americans BleepingComputer · 76d ago I have a datastealer malware cybersecurity · 76d ago Dúvida de carreira. cybersecurity · 76d ago US charges Google security engineer with Polymarket insider trading BleepingComputer · 76d ago Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace cybersecurity · 76d ago Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated cybersecurity · 76d ago is SIEM really needed here ? cybersecurity · 76d ago Decompiled an app, found a bunch of secrets, what now? cybersecurity · 76d ago What safety boundary would you expect from a local AI incident investigation tool? For [Blue|Purple] Teams in Cyber Defence · 76d ago Can someone give me a correct method for learning reverse engineering? cybersecurity · 76d ago 1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog Technical Information Security Content & Discussion · 76d ago Authenticated RCE via Argument Injection in Gogs (NOT FIXED) For [Blue|Purple] Teams in Cyber Defence · 76d ago Charter Communications data breach affects 4.9 million accounts BleepingComputer · 76d ago Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months cybersecurity · 76d ago GRC Advise cybersecurity · 76d ago [ Removed by Reddit ] cybersecurity · 76d ago Did something happen to haveibeenpwned? Any alternatives? cybersecurity · 76d ago I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found. Technical Information Security Content & Discussion · 76d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 76d ago How do people actually modify mobile games to increase their power? hacking: security in practice · 76d ago Why I Built My Own LLM Benchmark for THOR Finding Triage For [Blue|Purple] Teams in Cyber Defence · 76d ago RAT SUSPECTED cybersecurity · 76d ago Casdoor contains multiple authentication bypass and access management vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 76d ago The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents For [Blue|Purple] Teams in Cyber Defence · 76d ago GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations For [Blue|Purple] Teams in Cyber Defence · 76d ago Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies For [Blue|Purple] Teams in Cyber Defence · 76d ago Malware seller hunted across three continents For [Blue|Purple] Teams in Cyber Defence · 76d ago Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims For [Blue|Purple] Teams in Cyber Defence · 76d ago Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers For [Blue|Purple] Teams in Cyber Defence · 76d ago Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network For [Blue|Purple] Teams in Cyber Defence · 76d ago How do people afford certificate s? cybersecurity · 76d ago I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed? cybersecurity · 76d ago Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint) Reverse Engineering · 76d ago Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. cybersecurity · 76d ago Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 76d ago Phone Forwarding cybersecurity · 76d ago Opinions on running Full Microsoft E5 Security Stack cybersecurity · 76d ago Claiming "XDR" cybersecurity · 76d ago Typosquatted npm packages used to steal cloud and CI/CD secrets cybersecurity · 76d ago Why Loyalty Programs Are Quietly Becoming a Security Blind Spot hacking: security in practice · 76d ago Fooling around with encrypted reasoning blobs Technical Information Security Content & Discussion · 76d ago CALIF: An AI audit of FreeBSD Technical Information Security Content & Discussion · 76d ago Microsoft security cybersecurity · 76d ago Need help regarding building a home lab cybersecurity · 76d ago Should I turn on passwordless accounts for all my Microsoft accounts? cybersecurity · 76d ago Transitioning from AWS Data Center Operations to Security Engineering cybersecurity · 76d ago CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries Technical Information Security Content & Discussion · 76d ago Probably the wrong place. cybersecurity · 76d ago Anthropic confirms Claude Mythos-class models will roll out to the public BleepingComputer · 76d ago What after IT helpdesk? cybersecurity · 76d ago As Global Powers Explore Humanoid Robots, Cyber-Risk Looms darkreading · 76d ago News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit The Last Watchdog · 76d ago Ajuda pessoal hacking: security in practice · 76d ago VMP 3.5+ Internal Architecture & Heap Dispatch Analysis Reverse Engineering · 76d ago GreyVibe hackers use ChatGPT, Gemini to power cyberattacks BleepingComputer · 76d ago How are you security-testing API changes before production without slowing CI/CD? cybersecurity · 76d ago Are we trusting update repos or are you all extra paranoid now as well? cybersecurity · 76d ago Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops cybersecurity · 76d ago BTMOB Android malware service generates custom phishing payloads BleepingComputer · 76d ago Prevent supply chain attacks cybersecurity · 76d ago The C-suite job that's burning people out faster than any other For [Blue|Purple] Teams in Cyber Defence · 76d ago New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation For [Blue|Purple] Teams in Cyber Defence · 76d ago Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems cybersecurity · 76d ago SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer For [Blue|Purple] Teams in Cyber Defence · 76d ago FBI warns of fake FIFA websites running World Cup fraud schemes cybersecurity · 76d ago Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances For [Blue|Purple] Teams in Cyber Defence · 76d ago Hackers are trying to steal Signal users' backups in new wave of phishing attacks cybersecurity · 76d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN Technical Information Security Content & Discussion · 76d ago Samy Kamkar on building viruses, his arrest and privacy in the LLM era hacking: security in practice · 76d ago 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface For [Blue|Purple] Teams in Cyber Defence · 76d ago FBI warns of fake FIFA websites running World Cup fraud schemes BleepingComputer · 76d ago Visual Studio Extensions Revisited Technical Information Security Content & Discussion · 76d ago Dutch Raid Fails to Dent Russian Bulletproof Host darkreading · 76d ago APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026 For [Blue|Purple] Teams in Cyber Defence · 76d ago Incident Response Testing Preparation cybersecurity · 76d ago Introducing Microsoft 365 Business with Copilot: The new standard for small business Microsoft 365 Blog · 76d ago Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference cybersecurity · 76d ago House panel poised to hold hearing centered on AI impact on cyber CyberScoop · 76d ago [Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥 cybersecurity · 76d ago Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure For [Blue|Purple] Teams in Cyber Defence · 76d ago Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake For [Blue|Purple] Teams in Cyber Defence · 76d ago 3rd Party NFC cards.. secure? cybersecurity · 76d ago Vulnerability Management Tickets & SLA cybersecurity · 76d ago Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket CyberScoop · 76d ago Defending at Machine-Speed: Building AI Threat Readiness cybersecurity · 76d ago AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved cybersecurity · 76d ago HEAD request body processing leading cybersecurity · 76d ago Hackers exploit FortiClient EMS flaw to push infostealer malware BleepingComputer · 76d ago Malicious npm Package Stole Files From Claude AI User Directory via GitHub cybersecurity · 76d ago Does anyone have an app like substack to keep being updated and engaging within the cyber domain? cybersecurity · 76d ago Zero Trust Implementation Guidelines For [Blue|Purple] Teams in Cyber Defence · 76d ago [ Removed by Reddit ] hacking: security in practice · 77d ago What’s an attack vector people massively underestimate in 2026? cybersecurity · 77d ago We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7 cybersecurity · 77d ago Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP) Technical Information Security Content & Discussion · 77d ago Is this considered a bug or something else entirely? hacking: security in practice · 77d ago Agentic AI Isn't Risky; the Way Orgs Deploy It Is darkreading · 77d ago A Deeper Look at GLASSWORM's Solana Variant Malware Analysis & Reports · 77d ago A Deeper Look at GLASSWORM's Solana Variant cybersecurity · 77d ago How 2004 RuneScape fit a multiplayer RPG into 56k dial-up Reverse Engineering · 77d ago Getting back deleted conversation from messanger hacking: security in practice · 77d ago Introducing a new design for Microsoft 365 Copilot Microsoft 365 Blog · 77d ago BlackToad: Network Manipulation in an AutoIt Payload For [Blue|Purple] Teams in Cyber Defence · 77d ago RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT For [Blue|Purple] Teams in Cyber Defence · 77d ago Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant For [Blue|Purple] Teams in Cyber Defence · 77d ago Calling Cyber Security Beginners cybersecurity · 77d ago Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE Technical Information Security Content & Discussion · 77d ago Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis cybersecurity · 77d ago Building Omegle for Exposed Webcams hacking: security in practice · 77d ago built something for ai agents, ended up looking a lot like classic appsec cybersecurity · 77d ago New Gogs zero-day flaw lets hackers get remote code execution BleepingComputer · 77d ago Is Gophish still usable in 2026? cybersecurity · 77d ago Microsoft vs Chaotic Eclipse: three zero-days now actively exploited cybersecurity · 77d ago How SIEM helps MSPs reduce noise and stop threats faster BleepingComputer · 77d ago what do you think cybersecurity · 77d ago Why would be clicking a website, redirect me? cybersecurity · 77d ago Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit For [Blue|Purple] Teams in Cyber Defence · 77d ago Zapier fixes bug chain that researchers say risked widespread account takeover cybersecurity · 77d ago AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career? hacking: security in practice · 77d ago Writing cybersecurity policies is a waste of time cybersecurity · 77d ago Zapier fixes bug chain that researchers say risked widespread account takeover CyberScoop · 77d ago The GitHub Leak Situation Just Got Worse | Threat Wire Hak5 · 77d ago reverse engineering need for speed most wanted for modding sdk Reverse Engineering · 77d ago Romanian gets 5 years in prison for hacking Oregon govt network BleepingComputer · 77d ago Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security darkreading · 77d ago Webinar: Why network incidents take too long to resolve BleepingComputer · 77d ago Raising the Cybersecurity Stakes: Ante up for the Agentic Era. cybersecurity · 77d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories Alerts · 77d ago ABB EIBPORT All CISA Advisories · 77d ago Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter All CISA Advisories · 77d ago ABB Busch-Welcome 2 Wire Door Opener Actuator All CISA Advisories · 77d ago Fourth Frontier Frontier X Mobile Application, Frontier X2 All CISA Advisories · 77d ago CP Plus 8 Ch. Network Video Recorder All CISA Advisories · 77d ago XCharge C6 All CISA Advisories · 77d ago KMW CCTV Security Cameras All CISA Advisories · 77d ago MacGregor Voyage Data Recorder (VDR) G4e All CISA Advisories · 77d ago Schnieider Electric EcoStruxure Machine Expert HVAC All CISA Advisories · 77d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories All CISA Advisories · 77d ago Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it. cybersecurity · 77d ago [ Removed by Reddit ] cybersecurity · 77d ago Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15 Malware Analysis & Reports · 77d ago Released: Dataforge Honeypot cybersecurity · 77d ago Carnival Cruise confirms data breach affecting nearly 6 million people BleepingComputer · 77d ago Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks cybersecurity · 77d ago CEH-free cybersecurity · 77d ago Hottest cybersecurity open-source tools of the month: May 2026 cybersecurity · 77d ago Preparation tips for CPENT cybersecurity · 77d ago Sextortionist sentenced to 33 years for targeting 145 children BleepingComputer · 77d ago BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model darkreading · 77d ago FROST: Fingerprinting Remotely using OPFS-based SSD Timing For [Blue|Purple] Teams in Cyber Defence · 77d ago How do you handle AI tools in your organization? cybersecurity · 77d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 77d ago What scanners are actually trying against AI infrastructure Technical Information Security Content & Discussion · 77d ago I think i got scammed anybody can help me with that cybersecurity · 77d ago Nordic CISOs Handle Rising Cyber Threats Remarkably Well darkreading · 77d ago New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo cybersecurity · 77d ago Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup For [Blue|Purple] Teams in Cyber Defence · 77d ago Is it safe to have passwords copied to clipboard on IOS temporarily? cybersecurity · 77d ago Developers working on anti-fraud systems deserve more credit cybersecurity · 77d ago Real Folks of Cyber | Dan Berger | Day in the Life The Cyber Mentors · 77d ago My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst cybersecurity · 77d ago GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs. Reverse Engineering · 77d ago Security awareness training for AI heavy smb workflows? cybersecurity · 77d ago puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 77d ago Defense by accumulation Technical Information Security Content & Discussion · 77d ago Minimum Requirements for Helpdesk Role ? cybersecurity · 77d ago Reddit spear phishing cybersecurity · 77d ago Winbox server/client reverse engineered is opensource Reverse Engineering · 77d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ cybersecurity · 77d ago What to do cybersecurity · 77d ago What resources would you recommend for studying cysa+ cybersecurity · 77d ago Provenance of Data cybersecurity · 77d ago GPU mining malware spreads via SEO poisoning, AI chatbots BleepingComputer · 77d ago 5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain hacking: security in practice · 77d ago Websites have a new way to spy on visitors: analyzing their SSD activity cybersecurity · 77d ago 12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal? cybersecurity · 77d ago OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms CyberScoop · 77d ago Russian Art Teacher - Hinder Security Clearance? cybersecurity · 77d ago Ransomware Actors Show Up In Person to Steal Law Firm Data darkreading · 77d ago FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person CyberScoop · 77d ago Who is Salt Typhoon Really? Unraveling the Attribution Challenge For [Blue|Purple] Teams in Cyber Defence · 77d ago EDR/MDR Vendor Questions cybersecurity · 77d ago Cybersecurity as a Highschooler? cybersecurity · 77d ago New department created, would love your input cybersecurity · 77d ago What are the dangers of posting? hacking: security in practice · 77d ago OWASP Vienna - anyone going? cybersecurity · 77d ago Interview with Upstart cybersecurity · 77d ago 18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber. cybersecurity · 77d ago Is cloud security engineer viable with my current position? cybersecurity · 77d ago UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace CyberScoop · 77d ago Cloudflare Access users: what would actually make JIT useful for you? cybersecurity · 77d ago Looking for resources on end-to-end APT attack flow summaries for detection engineering For [Blue|Purple] Teams in Cyber Defence · 77d ago Kali365 Activity Surges: Device Code Phishing Is Scaling Fast Malware Analysis & Reports · 77d ago eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels cybersecurity · 77d ago The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire For [Blue|Purple] Teams in Cyber Defence · 77d ago Questions regarding Ubuntu 24 LTS hardening cybersecurity · 77d ago Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho. cybersecurity · 77d ago Honest question about OT Security Engineer work life in India cybersecurity · 77d ago Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning) cybersecurity · 77d ago AI Security cybersecurity · 77d ago Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor cybersecurity · 78d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP For [Blue|Purple] Teams in Cyber Defence · 78d ago 🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents cybersecurity · 78d ago Latin American Cybercriminals Hoover Up Government Data darkreading · 78d ago Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint For [Blue|Purple] Teams in Cyber Defence · 78d ago AI-Assisted Exploit Development Outpaces Scanner Detection darkreading · 78d ago Building Detection Engineering on AWS from scratch — roast my plan cybersecurity · 78d ago Building Detection Engineering on AWS from scratch — roast my plan For [Blue|Purple] Teams in Cyber Defence · 78d ago New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault Technical Information Security Content & Discussion · 78d ago Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance cybersecurity · 78d ago Flipper Zero Users, What's Your Take? hacking: security in practice · 78d ago Large company with a bit of an issue free stuff hacking: security in practice · 78d ago I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA. cybersecurity · 78d ago Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning cybersecurity · 78d ago Final Year Project: Looking for non-generic IAM project ideas that solve real problems cybersecurity · 78d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Technical Information Security Content & Discussion · 78d ago GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled. cybersecurity · 78d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware For [Blue|Purple] Teams in Cyber Defence · 78d ago Breaking out of IT Helpdesk - how? cybersecurity · 78d ago A year in Cybersecurity — Where Do I Go From Here? cybersecurity · 78d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware cybersecurity · 78d ago MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Malware Analysis & Reports · 78d ago Can you enforce strong Active Directory password rules without frustrating users? BleepingComputer · 78d ago 22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber cybersecurity · 78d ago FBI: Silent Ransom Group Turns to IT Support Ploy cybersecurity · 78d ago A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate Technical Information Security Content & Discussion · 78d ago How do machine builders track Siemens/Rockwell security advisories? cybersecurity · 78d ago CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain CyberScoop · 78d ago Glassworm botnet disrupted after resilient C2 infrastructure takedown BleepingComputer · 78d ago GlassWorm Developer Supply-Chain Botnet Takedown cybersecurity · 78d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN cybersecurity · 78d ago Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV cybersecurity · 78d ago (URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active Reverse Engineering · 78d ago Got cybersec work what next ? cybersecurity · 78d ago Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables cybersecurity · 78d ago Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers cybersecurity · 78d ago HN Security - AI Reporter - Let's automate reporting in Burp Suite! Technical Information Security Content & Discussion · 78d ago Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing? cybersecurity · 78d ago GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP) cybersecurity · 78d ago nightmare eclipse is probably French here is why cybersecurity · 78d ago Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines cybersecurity · 78d ago Measuring performance of JA4/JA4H AI Model cybersecurity · 78d ago Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security darkreading · 78d ago What things are you really focused on this year? cybersecurity · 78d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 78d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 78d ago FBI warns of in-person data theft attacks from extortion gang BleepingComputer · 78d ago Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io) Malware Analysis & Reports · 78d ago Designing secure access with ZTNA For [Blue|Purple] Teams in Cyber Defence · 78d ago Hypothetical EDR spoofer Reverse Engineering · 78d ago Hypothetical EDR spoofer cybersecurity · 78d ago ISO 27001 Audit Stage 1 cybersecurity · 78d ago Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records Technical Information Security Content & Discussion · 78d ago Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That. cybersecurity · 78d ago CISA gives feds 4 days to patch actively exploited cPanel plugin flaw BleepingComputer · 78d ago Dutch police arrests suspect linked to Ajax football club hack BleepingComputer · 78d ago What to consider before asking an AI chatbot for health advice WeLiveSecurity · 78d ago Looking for Hacker Friends to Learn☺️ cybersecurity · 78d ago Comptes Instagram et Facebook piratés et désactivés cybersecurity · 78d ago RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact Technical Information Security Content & Discussion · 78d ago How to safely disinfect a USB stick from potential malware files? cybersecurity · 78d ago Windows 11 KB5089573 update released with performance improvements BleepingComputer · 78d ago Champion ethical hacker warns AI tools like Mythos will make competing harder. hacking: security in practice · 78d ago MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response For [Blue|Purple] Teams in Cyber Defence · 78d ago White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats For [Blue|Purple] Teams in Cyber Defence · 78d ago Advisory X41-2026-002: Request Host Header not Validated in Starlette For [Blue|Purple] Teams in Cyber Defence · 78d ago Top ethical hacker Chompie warns AI tools could put her out of business For [Blue|Purple] Teams in Cyber Defence · 78d ago 浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents For [Blue|Purple] Teams in Cyber Defence · 78d ago Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker. hacking: security in practice · 78d ago YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions For [Blue|Purple] Teams in Cyber Defence · 78d ago CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state For [Blue|Purple] Teams in Cyber Defence · 78d ago The Evolution of Chinese-language Phishing Services For [Blue|Purple] Teams in Cyber Defence · 78d ago Silent Ransom Group Impersonating IT Personnel through Social Engineering For [Blue|Purple] Teams in Cyber Defence · 78d ago Is anyone else concerned about how quickly AI is outpacing cloud security? cybersecurity · 78d ago The epoll UAF - an epoll uaf race in fs/eventpoll.c For [Blue|Purple] Teams in Cyber Defence · 78d ago Tycoon 2FA AiTM detection for Entra ID and Google For [Blue|Purple] Teams in Cyber Defence · 78d ago Microsoft Copilot Cowork Exfiltrates Files For [Blue|Purple] Teams in Cyber Defence · 78d ago What's a CyberSecurity job like? cybersecurity · 78d ago Microsoft Live credential stuffing cybersecurity · 78d ago I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this? cybersecurity · 78d ago Security architects- summarize your responsibilities and role cybersecurity · 78d ago Finding Work in OSINT cybersecurity · 78d ago State of SDLC Security 2026 cybersecurity · 78d ago Reported to police for coding html cybersecurity · 78d ago there's a toll in the hall now hacking: security in practice · 78d ago I Reverse Engineered Need for Speed Most Wanted Server Reverse Engineering · 78d ago Am I crazy or is something off about this Google OAuth login via Calendly hacking: security in practice · 78d ago [Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling) cybersecurity · 78d ago I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project cybersecurity · 78d ago Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover cybersecurity · 78d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators? cybersecurity · 78d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells cybersecurity · 78d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells BleepingComputer · 78d ago GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet The Last Watchdog · 78d ago Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos darkreading · 78d ago Charter confirms data breach after ShinyHunters extortion threat BleepingComputer · 78d ago Apple open-sources quantum-resistant encryption code CyberScoop · 78d ago Breaking GROK'S DEFENSES to make it HACK Real Public Websites cybersecurity · 78d ago GitHub Actions Cache Poisoning is eating open source cybersecurity · 78d ago State Cyber Leaders Push Congress for More Funding, Support darkreading · 78d ago Nightmare-Eclipse has also been banned on GitLab :DD cybersecurity · 78d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled? darkreading · 78d ago For Enterprises, Security Remains Agentic AI's Biggest Challenge darkreading · 78d ago Do we still have time before we are in the Age of the movie "Minority Report"? ↓ cybersecurity · 78d ago SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file cybersecurity · 78d ago Unpatched Sparx vulnerabilties For [Blue|Purple] Teams in Cyber Defence · 78d ago What Software Supply Chain, Water Filters, and Power Grids Have in Common cybersecurity · 78d ago QA engineer trying to move into AppSec — does this plan hold up? cybersecurity · 78d ago Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down. Malware Analysis & Reports · 78d ago Is work from anywhere really impossible to find?? cybersecurity · 78d ago Navigating Lax Load Balancers: When an Intersection Gets You Inside Technical Information Security Content & Discussion · 79d ago New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences Microsoft 365 Blog · 79d ago Cybersecurity statistics of the week (May 18th - May 24th) cybersecurity · 79d ago Engineering a Post Quantum Fortress Inside the Citadel Archite cybersecurity · 79d ago Cyber Security Analyst cybersecurity · 79d ago Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance cybersecurity · 79d ago Two layer email security tool thesis cybersecurity · 79d ago Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents Technical Information Security Content & Discussion · 79d ago sylvia: iOS Syscall Explorer for IDA 9.X For [Blue|Purple] Teams in Cyber Defence · 79d ago Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation Reverse Engineering · 79d ago OTP lockout state leaked valid-code signal, enabling OLX account takeover Technical Information Security Content & Discussion · 79d ago When OTP rate limiting fails: OLX account takeover with persistent sessions cybersecurity · 79d ago When “try again later” still tells you the OTP was correct: an account takeover story. hacking: security in practice · 79d ago Entra ID sessions revoke cybersecurity · 79d ago Anyone who attended GPCSSI before? Need some clarification cybersecurity · 79d ago How Varonis Atlas integrates Claude Compliance API for AI governance BleepingComputer · 79d ago Lost on my career path. cybersecurity · 79d ago How journalists rely on VPNs to protect press freedom Technical Information Security Content & Discussion · 79d ago EU-based folks: external pentest vs mandatory data/security training? cybersecurity · 79d ago help needed from experienced people cybersecurity · 79d ago How do you evaluate whether a privacy service is actually privacy-respecting? cybersecurity · 79d ago Which one Intellipaat or coursera which one to choose cybersecurity · 79d ago How random program can cause most of antiviruses close himself without telling himself to close Malware Analysis & Reports · 79d ago Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching Reverse Engineering · 79d ago ShadowCat: Universal optical file transfer, single html file, browser to camera hacking: security in practice · 79d ago Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1) Technical Information Security Content & Discussion · 79d ago Microsoft Defender can now automatically isolate hacked endpoints BleepingComputer · 79d ago Webinar: Too many tools are slowing network incident response BleepingComputer · 79d ago CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks cybersecurity · 79d ago India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic? cybersecurity · 79d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 79d ago ABB Terra AC All CISA Advisories · 79d ago ABB LVS MConfig All CISA Advisories · 79d ago ABB Ability Camera Connect All CISA Advisories · 79d ago Eppendorf BioFlo 320 All CISA Advisories · 79d ago ABB AbilityTM Zenon Remote Transport Vulnerability All CISA Advisories · 79d ago ABB AC500 V2 All CISA Advisories · 79d ago ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) All CISA Advisories · 79d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 79d ago Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs. cybersecurity · 79d ago Did anyone pass the SC-200 certificate recently? cybersecurity · 79d ago Honeypot cybersecurity · 79d ago passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account cybersecurity · 79d ago Career in IAM as a fresher cybersecurity · 79d ago CISA orders feds to patch actively exploited Drupal vulnerability cybersecurity · 79d ago Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure cybersecurity · 79d ago GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” cybersecurity · 79d ago Cyber security tool cybersecurity · 79d ago Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East For [Blue|Purple] Teams in Cyber Defence · 79d ago GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip For [Blue|Purple] Teams in Cyber Defence · 79d ago JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign For [Blue|Purple] Teams in Cyber Defence · 79d ago Saw this tool and it has potential cybersecurity · 79d ago 🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs cybersecurity · 79d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack For [Blue|Purple] Teams in Cyber Defence · 79d ago How I Tried to Parse a Replay from Dawn of War: Definitive Edition Reverse Engineering · 79d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files cybersecurity · 79d ago Follow up : showing Claude install random pacakage in its vm instance without asking or prompting cybersecurity · 79d ago BTMOB: A stealthy RAT burrowing deep into Android devices WeLiveSecurity · 79d ago Update Starlette Now. New severe vulnerability dropped. Technical Information Security Content & Discussion · 79d ago CISA orders feds to patch actively exploited Drupal vulnerability BleepingComputer · 79d ago Microsoft: Domain Controller lookup may fail on Windows Server 2016 BleepingComputer · 79d ago Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@" For [Blue|Purple] Teams in Cyber Defence · 79d ago The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization For [Blue|Purple] Teams in Cyber Defence · 79d ago ¿Is safe? cybersecurity · 79d ago 7-Eleven data breach exposes personal information of 185,000 people BleepingComputer · 79d ago Need help cybersecurity · 79d ago What is the best tool for masking in kali cybersecurity · 79d ago What are the best tools other than ghostTracker? cybersecurity · 79d ago y2jb un able to enject payloads hacking: security in practice · 79d ago TrapDoor Cross-Ecosystem Crypto Stealer Campaign cybersecurity · 79d ago Follow up : Steal Your Files Claude AI installing package because internet say so cybersecurity · 79d ago New to Cybersecurity: Looking for general advice & help with Nmap cybersecurity · 79d ago GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP. For [Blue|Purple] Teams in Cyber Defence · 79d ago Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal cybersecurity · 79d ago Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated. hacking: security in practice · 79d ago Looking for tech role references cybersecurity · 79d ago Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet Trend Micro Research, News, Perspectives · 79d ago How do you balance Paw? cybersecurity · 79d ago I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity. cybersecurity · 79d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Malware Analysis & Reports · 79d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Technical Information Security Content & Discussion · 79d ago Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability For [Blue|Purple] Teams in Cyber Defence · 79d ago From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security cybersecurity · 79d ago Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February cybersecurity · 79d ago What Companies are Legit? cybersecurity · 79d ago start learning cybersecurity from scratch cybersecurity · 79d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 79d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 79d ago WhatsApp users on alert after hacker drops massive dataset cybersecurity · 79d ago 17 years old going into CS — what certs should I start going after now? cybersecurity · 79d ago CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700. For [Blue|Purple] Teams in Cyber Defence · 79d ago i want to hire an osint expert cybersecurity · 79d ago Open University pros/cons cybersecurity · 79d ago How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection? cybersecurity · 79d ago Career in IAM as a fresher cybersecurity · 79d ago Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo cybersecurity · 79d ago Need Advice cybersecurity · 79d ago Why did Hack Forums lose popularity? hacking: security in practice · 79d ago Nocturne - A bin2bin code virtualizer for x86-64 PE binaries Reverse Engineering · 79d ago Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all? cybersecurity · 79d ago Someone from Germany on iOS keeps trying to login to my MSFT account cybersecurity · 79d ago AI cautionary tale... cybersecurity · 79d ago [Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing Reverse Engineering · 79d ago Anthropic’s restricted Claude Mythos model may be coming to Claude Code BleepingComputer · 79d ago AI powered red vs blue teaming cybersecurity · 80d ago Starting a security analyst student apprenticeship next week, need advice cybersecurity · 80d ago Why CVE Does Not Work for AI Agents, but AVE? cybersecurity · 80d ago SC-200 or Security+ — which actually helps land a security title cybersecurity · 80d ago How about AI having access to your hard drive. cybersecurity · 80d ago How a Date Tag Hijacks macOS via ExifTool cybersecurity · 80d ago Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools cybersecurity · 80d ago Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing Reverse Engineering · 80d ago How credential brokering prevents AI agents from compromising credentials via prompt injection Technical Information Security Content & Discussion · 80d ago How credential brokering prevents AI agents from compromising credentials via prompt injection cybersecurity · 80d ago Built a tiny daily cyber puzzle game during evenings/weekends cybersecurity · 80d ago Crypto4A launches quantum-safe rival to AWS Secrets Manager cybersecurity · 80d ago CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth Technical Information Security Content & Discussion · 80d ago ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why. cybersecurity · 80d ago Cyber Sec project cybersecurity · 80d ago ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise hacking: security in practice · 80d ago CySA+ cybersecurity · 80d ago Anyone tried Morgancyberhelp ? cybersecurity · 80d ago As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free cybersecurity · 80d ago YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos For [Blue|Purple] Teams in Cyber Defence · 80d ago Why are most of the dfir tools built to be used in windows cybersecurity · 80d ago OnlyFans mega leak reveals 340M user records, hackers claim cybersecurity · 80d ago Perplexity BumbleBee cybersecurity · 80d ago Cisco patches critical 10.0 flaw in Secure Workload APIs cybersecurity · 80d ago Suspicious ass website asking to run a terminal command (MacOS) Malware Analysis & Reports · 80d ago Shellcide: A shellcode IDE hacking: security in practice · 80d ago Stalker has my phonenumber cybersecurity · 80d ago FBI warns of Kali365 phishing service targeting Microsoft 365 accounts BleepingComputer · 80d ago I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built Reverse Engineering · 80d ago Need some guidance cybersecurity · 80d ago Are you currently allocating budget to services that remove executive PII from B2B data brokers? cybersecurity · 80d ago Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal Technical Information Security Content & Discussion · 80d ago About CEHv13 book cybersecurity · 80d ago delimiter-less string obfuscation powered by compile-time AES Reverse Engineering · 80d ago Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it For [Blue|Purple] Teams in Cyber Defence · 80d ago We open-sourced the most dangerous part of our security startup on purpose. cybersecurity · 80d ago Which conference(s) result in the most people finding jobs? cybersecurity · 80d ago My discord account has been hacked second time even after enabling two factor authentication and resetting password cybersecurity · 80d ago What's the most efficient way to learn cloud governance and compliance cybersecurity · 80d ago honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports For [Blue|Purple] Teams in Cyber Defence · 80d ago Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild. For [Blue|Purple] Teams in Cyber Defence · 80d ago Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council For [Blue|Purple] Teams in Cyber Defence · 80d ago RemotePE: The Lazarus RAT that lives in memory For [Blue|Purple] Teams in Cyber Defence · 80d ago Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer For [Blue|Purple] Teams in Cyber Defence · 80d ago Paved With Intent: ROADtools and Nation-State Tactics in the Cloud For [Blue|Purple] Teams in Cyber Defence · 80d ago Twee mannen aangehouden voor phishing - Two men arrested for phishing For [Blue|Purple] Teams in Cyber Defence · 80d ago Sharp Eyes: Mass surveillance of foreigners in China For [Blue|Purple] Teams in Cyber Defence · 80d ago Does anyone know C2 framwork and free hosting to host C2? cybersecurity · 80d ago Finding bot account hacking: security in practice · 80d ago relay_bible: Technical Reference to multiple relay techniques For [Blue|Purple] Teams in Cyber Defence · 80d ago CIS-CAT Assessor for assessment Windows server 2022 and 2025 cybersecurity · 80d ago Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec For [Blue|Purple] Teams in Cyber Defence · 80d ago The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in] For [Blue|Purple] Teams in Cyber Defence · 80d ago SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format For [Blue|Purple] Teams in Cyber Defence · 80d ago North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial For [Blue|Purple] Teams in Cyber Defence · 80d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 80d ago Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this cybersecurity · 80d ago Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks? cybersecurity · 80d ago Recent adoption of AI taught me what is Cybersecurity. cybersecurity · 80d ago The Pentagon Changed the Rules for Cybersecurity Compliance cybersecurity · 80d ago Can someone explain to a noob like me what the implications of this exploit are? cybersecurity · 80d ago SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections cybersecurity · 80d ago Window between zero-day CVE and a patch! cybersecurity · 80d ago Is it risky when a website puts on technology components with versions they used in their website? cybersecurity · 80d ago Anyone else losing their mind over this "AI Cybersecurity" hype? cybersecurity · 80d ago URL parsing behavior in a canonical tag lab cybersecurity · 80d ago How to hacking: security in practice · 80d ago Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you? cybersecurity · 80d ago Any tips for me pls cybersecurity · 80d ago How do you minimize legal liability as a solo contractor? cybersecurity · 80d ago How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing? cybersecurity · 80d ago nmap on Linux: Guide to Network Scanning and Discovery Technical Information Security Content & Discussion · 80d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 80d ago Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift. hacking: security in practice · 80d ago Provenance: A survival toolkit for an AI dominant information landscape cybersecurity · 80d ago Nmap Mastery: The Complete Guide to Network Reconnaissance hacking: security in practice · 80d ago Google wallet virtual card cloned hacking: security in practice · 80d ago [ Removed by Reddit ] cybersecurity · 80d ago Active Drupal SQLi exploitation is a real „patch now“ moment cybersecurity · 80d ago machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native) cybersecurity · 80d ago Need suggestions and input; not a promotion cybersecurity · 80d ago Need advice! cybersecurity · 80d ago New Zealand is becoming a focal point for AI-driven superhacking threats. cybersecurity · 80d ago Staged publishing and new install-time controls for npm - GitHub Changelog For [Blue|Purple] Teams in Cyber Defence · 80d ago nmap on Linux: Guide to Network Scanning and Discovery cybersecurity · 80d ago TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle cybersecurity · 81d ago How would Phishing look like in the future? (targeting agents, not humans) cybersecurity · 81d ago Best beginner/intermediate book for system security (blue team / defense / audits)? cybersecurity · 81d ago Why is on-prem and air-gapped asset inventory still such a mess? cybersecurity · 81d ago keep getting MS authentication sign in attempts? cybersecurity · 81d ago Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES For [Blue|Purple] Teams in Cyber Defence · 81d ago Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud For [Blue|Purple] Teams in Cyber Defence · 81d ago Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow For [Blue|Purple] Teams in Cyber Defence · 81d ago The Future and Past of Residential Proxies For [Blue|Purple] Teams in Cyber Defence · 81d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 81d ago Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy For [Blue|Purple] Teams in Cyber Defence · 81d ago Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware For [Blue|Purple] Teams in Cyber Defence · 81d ago A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software For [Blue|Purple] Teams in Cyber Defence · 81d ago Prompt Injection finally broke my brain a little. My first article as a security student. Technical Information Security Content & Discussion · 81d ago Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows For [Blue|Purple] Teams in Cyber Defence · 81d ago Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 81d ago Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes For [Blue|Purple] Teams in Cyber Defence · 81d ago mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. For [Blue|Purple] Teams in Cyber Defence · 81d ago keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust. For [Blue|Purple] Teams in Cyber Defence · 81d ago np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation. For [Blue|Purple] Teams in Cyber Defence · 81d ago Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up. For [Blue|Purple] Teams in Cyber Defence · 81d ago OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ For [Blue|Purple] Teams in Cyber Defence · 81d ago Megalodon: Mass GitHub Repo Backdooring via CI Workflows For [Blue|Purple] Teams in Cyber Defence · 81d ago Silly issue cybersecurity · 81d ago FatGid - FreeBSD 14.x kernel LPE For [Blue|Purple] Teams in Cyber Defence · 81d ago Manage [VSCode] extensions in enterprise environments For [Blue|Purple] Teams in Cyber Defence · 81d ago angr: A powerful and user-friendly binary analysis platform! For [Blue|Purple] Teams in Cyber Defence · 81d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware For [Blue|Purple] Teams in Cyber Defence · 81d ago Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign BleepingComputer · 81d ago How Attackers Force Microsoft to Send Phishing Emails For [Blue|Purple] Teams in Cyber Defence · 81d ago Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects For [Blue|Purple] Teams in Cyber Defence · 81d ago Microsoft Authenticator App Details now exposed in Entra SignInLogs For [Blue|Purple] Teams in Cyber Defence · 81d ago Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting For [Blue|Purple] Teams in Cyber Defence · 81d ago How China-linked threat actors obtain zero-day vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 81d ago How to practice cybersecurity while studying prograaming ? cybersecurity · 81d ago Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research For [Blue|Purple] Teams in Cyber Defence · 81d ago How to Use Claude AI: A Complete Technical Beginner's Guide Technical Information Security Content & Discussion · 81d ago [AI Security] Exploring Behavioral AI for Runtime Threat Detection cybersecurity · 81d ago Podman and krun: is it pointless to harden quadlets? cybersecurity · 81d ago Monitoring for vssadmin.exe delete shadows is an absolute bare minimum For [Blue|Purple] Teams in Cyber Defence · 81d ago Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack For [Blue|Purple] Teams in Cyber Defence · 81d ago How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers For [Blue|Purple] Teams in Cyber Defence · 81d ago How to handle security researchers (and firms) without a bounty program? cybersecurity · 81d ago CVE-2026-48029: Two grid-decode bugs in libheif For [Blue|Purple] Teams in Cyber Defence · 81d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ Reverse Engineering · 81d ago workcell: Bounded local runtime and policy boundary for coding agents For [Blue|Purple] Teams in Cyber Defence · 81d ago OpenShell: OpenShell is the safe, private runtime for autonomous AI agents. For [Blue|Purple] Teams in Cyber Defence · 81d ago Product analytics is becoming a third-party breach surface cybersecurity · 81d ago How can i learn and get into red teaming? cybersecurity · 81d ago Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network cybersecurity · 81d ago I got hacked cybersecurity · 81d ago What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method? hacking: security in practice · 81d ago Soc analysts in big companies, how it looks like? cybersecurity · 81d ago Has anyone manage to reverse the macked dylib? Reverse Engineering · 81d ago CTO at NCSC Summary: week ending May 24th cybersecurity · 81d ago Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation For [Blue|Purple] Teams in Cyber Defence · 81d ago Built a SOC from scratch with no prior SOC experience For [Blue|Purple] Teams in Cyber Defence · 81d ago These special phone and app features can help protect you from spyware cybersecurity · 81d ago Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button? cybersecurity · 81d ago Capcha Code Malware cybersecurity · 81d ago getting lost when hunting cybersecurity · 81d ago How to find information behind an account? cybersecurity · 81d ago Reverse engineering circuitry in a Spacelab computer from 1980 Reverse Engineering · 81d ago Theoretical Design Concept for Post-Exploitation Browser Defense cybersecurity · 81d ago Google Certifications... cybersecurity · 81d ago How to continue when finding a possible Vulnerability but local law prohibits me from investigating further cybersecurity · 81d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks cybersecurity · 81d ago Is the CISSP still a reputable cert for getting jobs? cybersecurity · 81d ago Which of these gоv roles would fare better in the private sector? cybersecurity · 81d ago Laravel Lang packages hijacked to deploy credential-stealing malware cybersecurity · 81d ago Laravel Lang packages hijacked to deploy credential-stealing malware BleepingComputer · 81d ago Mapping binaries to EDR feature spaces cybersecurity · 81d ago Lost my number + WhatsApp account — worried about old chats, photos, and videos cybersecurity · 81d ago Proxmark5 campaign unlocked the $600k stretch goal hacking: security in practice · 81d ago ☔️🌅 STÖK · 81d ago what is the most painful or time-consuming part of your work right now?" cybersecurity · 81d ago Anthropic says Mythos has already found more than 10,000 vulnerabilities cybersecurity · 81d ago What is the experience needed for “entry level” cybersecurity jobs? cybersecurity · 81d ago Browser extension testing. cybersecurity · 81d ago GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision hacking: security in practice · 81d ago Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip? cybersecurity · 81d ago Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology Reverse Engineering · 81d ago Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback cybersecurity · 81d ago Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition cybersecurity · 82d ago Can someone recommend me some good, large universities to study cybersecurity? cybersecurity · 82d ago New guy khikhi cybersecurity · 82d ago Examples of intentional backdoors being breached? cybersecurity · 82d ago Non-Compliant Vocab cybersecurity · 82d ago CTO at NCSC Summary: week ending May 24th For [Blue|Purple] Teams in Cyber Defence · 82d ago HackTheBox - MonitorsFour IppSec · 82d ago VPN Exploitation When Patched Doesn't Mean Protected For [Blue|Purple] Teams in Cyber Defence · 82d ago Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation For [Blue|Purple] Teams in Cyber Defence · 82d ago Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites cybersecurity · 82d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 82d ago CLR-Stomp: .NET CLR-Stomping For [Blue|Purple] Teams in Cyber Defence · 82d ago Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes BleepingComputer · 82d ago infostealers just spawned a 5,000+ repo github supply chain attack cybersecurity · 82d ago The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis cybersecurity · 82d ago Doom running on a Kids Video Walkie Talkie hacking: security in practice · 82d ago GRO frag cybersecurity · 82d ago We audited 12K n8n templates: most have critical vulnerabilities cybersecurity · 82d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 82d ago Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week cybersecurity · 82d ago Mitigated Vulnerabilities by Vendor as Feed cybersecurity · 82d ago From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence For [Blue|Purple] Teams in Cyber Defence · 82d ago Introducing Showboat: A new malware family taunts defenses and targets international telecom firms For [Blue|Purple] Teams in Cyber Defence · 82d ago Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor For [Blue|Purple] Teams in Cyber Defence · 82d ago Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors cybersecurity · 82d ago A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories cybersecurity · 82d ago Where can I find the tools freely on internet to practice for soc analyst cybersecurity · 82d ago Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX. hacking: security in practice · 82d ago Pardon MIE?: how Mythos did not bypass Apple MIE Technical Information Security Content & Discussion · 82d ago residential proxies cybersecurity · 82d ago Recommendations for getting started in cybersecurity cybersecurity · 82d ago Linux mint or Ubuntu for complete beginner cybersecurity · 82d ago Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. cybersecurity · 82d ago Pentesting company recommendation cybersecurity · 82d ago Have you ever failed a certification exam? cybersecurity · 82d ago AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance cybersecurity · 82d ago This ID Verification company store users biometrics? (FaceTec) hacking: security in practice · 82d ago What do i need to learn to get into application security? Which Degrees/Certs cybersecurity · 82d ago RSAC online membership? Is it worth it? cybersecurity · 82d ago Playwright version that lets AI-Agents navigate the web hacking: security in practice · 82d ago Can someone give me a detailed roadmap for becoming a SOC Analyst? cybersecurity · 82d ago Puedo conseguir trabajo? cybersecurity · 82d ago How do i learn networking for cyber security? cybersecurity · 82d ago What's going to be Hacking and Cybersecurity's future is gonna be like? cybersecurity · 82d ago Cyber security placement - Interview Help cybersecurity · 82d ago CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module Technical Information Security Content & Discussion · 82d ago Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge cybersecurity · 82d ago AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22) For [Blue|Purple] Teams in Cyber Defence · 82d ago CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22) Reverse Engineering · 82d ago AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22 Technical Information Security Content & Discussion · 82d ago Feedback needed cybersecurity · 82d ago GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks. For [Blue|Purple] Teams in Cyber Defence · 82d ago Handoff Transition cybersecurity · 82d ago Where to learn the ins and outs of the computer itself hacking: security in practice · 82d ago Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't) Technical Information Security Content & Discussion · 82d ago Just added an interactive security map showing exactly what the server sees (and doesn't) cybersecurity · 82d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks BleepingComputer · 82d ago Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns For [Blue|Purple] Teams in Cyber Defence · 82d ago Trend Micro warns of Apex One zero-day exploited in the wild cybersecurity · 83d ago Lawmakers Demand Answers as CISA Tries to Contain Data Leak cybersecurity · 83d ago Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL? For [Blue|Purple] Teams in Cyber Defence · 83d ago https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/ cybersecurity · 83d ago Harvard and 140 other legitimate websites compromised Malware Analysis & Reports · 83d ago Harvard and 140 other legitimate websites compromised cybersecurity · 83d ago Votre Satisfaction Dans Votre Travail cybersecurity · 83d ago 5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. cybersecurity · 83d ago Former US execs plead guilty to aiding tech support scammers BleepingComputer · 83d ago Browser session theft is quietly becoming more dangerous than password theft Malware Analysis & Reports · 83d ago US states urge Congress to renew cybersecurity grants cybersecurity · 83d ago Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension Technical Information Security Content & Discussion · 83d ago Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours Malware Analysis & Reports · 83d ago Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes Reverse Engineering · 83d ago The CISO's Guide to IDE Security in 2026 cybersecurity · 83d ago Help with evilginx cybersecurity · 83d ago Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets Technical Information Security Content & Discussion · 83d ago Watching AI Brain Drain on Attackers in Real Time cybersecurity · 83d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 83d ago api-rta cyberwarfare labs cybersecurity · 83d ago Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator hacking: security in practice · 83d ago Trend Micro warns of Apex One zero-day exploited in the wild BleepingComputer · 83d ago I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner For [Blue|Purple] Teams in Cyber Defence · 83d ago The Worm That Deletes Your Entire Computer | Threat Wire Hak5 · 83d ago Drupal: Critical SQL injection flaw now targeted in attacks BleepingComputer · 83d ago Why Chargebacks are Just One Piece of the Fraud Puzzle BleepingComputer · 83d ago Does Security Implement Fixes? cybersecurity · 83d ago Ultimate Cybersecurity without needing AV ect? cybersecurity · 83d ago Hack your corrupt company. Sell their secrets to the black market hacking: security in practice · 83d ago User Onboarding with IAM cybersecurity · 83d ago Ubiquiti patches three max severity UniFi OS vulnerabilities BleepingComputer · 83d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 83d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 83d ago Data breach in name of protest Technical Information Security Content & Discussion · 83d ago qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb) Reverse Engineering · 83d ago pnpm 11 Might Finally Be a Better Default Than npm Technical Information Security Content & Discussion · 83d ago pnpm 11 Might Finally Be a Better Default Than npm cybersecurity · 83d ago 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs cybersecurity · 83d ago Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria cybersecurity · 83d ago AI-generated reporting: Lessons learned from Cisco Talos Incident Response For [Blue|Purple] Teams in Cyber Defence · 83d ago CrabLoader: A PoC Cobalt Strike UDRL written in Rust For [Blue|Purple] Teams in Cyber Defence · 83d ago The 429 Microsoft Graph Mystery For [Blue|Purple] Teams in Cyber Defence · 83d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 83d ago Azure Tenant Enumeration is Dead For [Blue|Purple] Teams in Cyber Defence · 83d ago A Deep Dive into Codex Windows Sandbox For [Blue|Purple] Teams in Cyber Defence · 83d ago Striga: Lifting x86 to LLVM IR with Python For [Blue|Purple] Teams in Cyber Defence · 83d ago Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip" cybersecurity · 83d ago Looking for a cybersecurity professional to interview for a university project (interview in French) cybersecurity · 83d ago US and Canada arrest and charge suspected Kimwolf botnet admin BleepingComputer · 83d ago Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise WeLiveSecurity · 83d ago veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker. For [Blue|Purple] Teams in Cyber Defence · 83d ago Windows BitLocker Security Feature Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 83d ago CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility For [Blue|Purple] Teams in Cyber Defence · 83d ago Google API keys keep working after you delete them long enough to be exploited For [Blue|Purple] Teams in Cyber Defence · 83d ago Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? For [Blue|Purple] Teams in Cyber Defence · 83d ago North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT For [Blue|Purple] Teams in Cyber Defence · 83d ago Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit For [Blue|Purple] Teams in Cyber Defence · 83d ago Safe read-only check script for Copy Fail / CVE-2026-31431 cybersecurity · 83d ago New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible? cybersecurity · 83d ago Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names) For [Blue|Purple] Teams in Cyber Defence · 83d ago [TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly cybersecurity · 83d ago Cisco used AI to write security incident reports, with mixed results cybersecurity · 83d ago [TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM) cybersecurity · 83d ago Reverse Engineered Google reCAPTCHA Reverse Engineering · 83d ago Cyber Insurance Actuary Looking for Educational Resources cybersecurity · 83d ago As a bank , how do i give protected access to claude to my team? cybersecurity · 83d ago Can seasonal Apple Store employees apply for internal IT/cybersecurity roles? cybersecurity · 83d ago Reliable IP reputation check tools besides IPQS?(for work) cybersecurity · 83d ago 🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget hacking: security in practice · 83d ago Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026) cybersecurity · 83d ago Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins cybersecurity · 83d ago Hacked by Rat Tools for 2.5 years. cybersecurity · 83d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Trend Micro Research, News, Perspectives · 83d ago Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada CyberScoop · 83d ago Google API Keys Remain Active After Deletion cybersecurity · 83d ago Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens For [Blue|Purple] Teams in Cyber Defence · 83d ago how do cyber sec consultants and pentesters actually get new clients? cybersecurity · 83d ago Post Incident Paranoia? cybersecurity · 83d ago Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector cybersecurity · 83d ago Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity? cybersecurity · 83d ago Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready cybersecurity · 83d ago You can counter MEMZ with Krotten in XP cybersecurity · 83d ago What are the most effective ways to do Blackbox testing? cybersecurity · 83d ago Npm registry sets stage for more secure package publishing cybersecurity · 83d ago Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support cybersecurity · 83d ago Megalodon: CI/CD Malware Spreading Across GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 83d ago Lawmakers from both parties say CISA cuts have gone too far CyberScoop · 83d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave Technical Information Security Content & Discussion · 83d ago Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK cybersecurity · 83d ago Is the Cybercorps SFS still worth it? cybersecurity · 83d ago Microsoft warns hackers are exploiting password resets to gain access to user accounts cybersecurity · 83d ago Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame cybersecurity · 83d ago How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account Malware Analysis & Reports · 83d ago WORM USB drives cybersecurity · 83d ago An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model? cybersecurity · 83d ago Trump postpones executive order focused on AI security CyberScoop · 83d ago CISOs - Holding the Line cybersecurity · 83d ago [Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled Technical Information Security Content & Discussion · 83d ago Google accidentally exposed details of unfixed Chromium flaw BleepingComputer · 83d ago Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware Reverse Engineering · 83d ago A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale cybersecurity · 83d ago Security Scroll Down? cybersecurity · 83d ago mass github repo backdooring via CI workflows(Megalodon) cybersecurity · 83d ago I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP Reverse Engineering · 83d ago 📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity. For [Blue|Purple] Teams in Cyber Defence · 83d ago CISA chief frets about open-source vulnerabilities, delayed security improvements CyberScoop · 84d ago Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit? cybersecurity · 84d ago Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks For [Blue|Purple] Teams in Cyber Defence · 84d ago GitHub Actions Cache Poisoning is eating open source Technical Information Security Content & Discussion · 84d ago European authorities take down prolific cybercrime VPN service CyberScoop · 84d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Reverse Engineering · 84d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox For [Blue|Purple] Teams in Cyber Defence · 84d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox cybersecurity · 84d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Technical Information Security Content & Discussion · 84d ago CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat Technical Information Security Content & Discussion · 84d ago beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA For [Blue|Purple] Teams in Cyber Defence · 84d ago FatGid - FreeBSD 14.x kernel LPE Technical Information Security Content & Discussion · 84d ago DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind cybersecurity · 84d ago FaceTec (ID verification) company appears to store user biometrics cybersecurity · 84d ago Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) Technical Information Security Content & Discussion · 84d ago Apple blocked over $11 billion in App Store fraud in 6 years BleepingComputer · 84d ago CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication cybersecurity · 84d ago CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat hacking: security in practice · 84d ago It seems that FaceTec (ID Verification company) allows for storage of user biometrics cybersecurity · 84d ago Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check. cybersecurity · 84d ago Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data cybersecurity · 84d ago This ID verification company allows for storage of biometric data? hacking: security in practice · 84d ago What Questions Do You Ask During SSP Control Interviews? cybersecurity · 84d ago Feed The Cat BackDoor cybersecurity · 84d ago Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet BleepingComputer · 84d ago Chinese hackers target telcos with new Linux, Windows malware BleepingComputer · 84d ago Max severity Cisco Secure Workload flaw gives Site Admin privileges BleepingComputer · 84d ago Flipper One - Asking for help from the community cybersecurity · 84d ago Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 84d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 84d ago Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign For [Blue|Purple] Teams in Cyber Defence · 84d ago Police seize “First VPN” service used in ransomware, data theft attacks BleepingComputer · 84d ago Flipper One — tech specs cybersecurity · 84d ago Architecture Zero Trust détaillée cybersecurity · 84d ago I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :) hacking: security in practice · 84d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 84d ago ABB Terra AC Wallbox All CISA Advisories · 84d ago Hitachi Energy GMS600 All CISA Advisories · 84d ago ABB B&R Automation Studio All CISA Advisories · 84d ago ABB B&R Automation Runtime All CISA Advisories · 84d ago ABB B&R PCs All CISA Advisories · 84d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 84d ago Cybersecurity in Healthcare cybersecurity · 84d ago Staged publishing for npm packages | npm Docs cybersecurity · 84d ago 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though) cybersecurity · 84d ago Neither MFA, Passkey, nor trusted IP help here cybersecurity · 84d ago cyber security remote cybersecurity · 84d ago Database of Malicious Browser Extensions Malware Analysis & Reports · 84d ago Flipper One project needs community help to build open Linux platform BleepingComputer · 84d ago SeekYou — one input, 15 recon sources, one report. hacking: security in practice · 84d ago I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries Reverse Engineering · 84d ago CSIRT incident response cybersecurity · 84d ago The readiness paradox: Why a false sense of cyber confidence is becoming a liability CyberScoop · 84d ago Trying to find a graduate role cybersecurity · 84d ago bypass internet restrictions hacking: security in practice · 84d ago GitHub ~3,800 internal repos compromised through a malicious VS Code extension Technical Information Security Content & Discussion · 84d ago I’ve got 99 problems, and IOCX isn’t one. Malware Analysis & Reports · 84d ago Microsoft warns of new Defender zero-days exploited in attacks cybersecurity · 84d ago From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree For [Blue|Purple] Teams in Cyber Defence · 84d ago How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102) For [Blue|Purple] Teams in Cyber Defence · 84d ago Iran-linked Operators Suspected in ATG Breaches For [Blue|Purple] Teams in Cyber Defence · 84d ago Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs For [Blue|Purple] Teams in Cyber Defence · 84d ago Compromised Nx Console version 18.95.0 For [Blue|Purple] Teams in Cyber Defence · 84d ago CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path For [Blue|Purple] Teams in Cyber Defence · 84d ago From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat For [Blue|Purple] Teams in Cyber Defence · 84d ago Microsoft warns of new Defender zero-days exploited in attacks BleepingComputer · 84d ago Webworm: New burrowing techniques For [Blue|Purple] Teams in Cyber Defence · 84d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) For [Blue|Purple] Teams in Cyber Defence · 84d ago what is the best security app option for pixel8a? cybersecurity · 84d ago How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) cybersecurity · 84d ago IoT Security cybersecurity · 84d ago GitHub links repo breach to TanStack npm supply-chain attack cybersecurity · 84d ago GitHub links repo breach to TanStack npm supply-chain attack BleepingComputer · 84d ago Another working Linux LPE exploit is out. How are teams treating local-only bugs now? cybersecurity · 84d ago Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks cybersecurity · 84d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 84d ago Google publishes exploit code threatening millions of Chromium users cybersecurity · 84d ago landing a remote Vulnerability Management role cybersecurity · 84d ago Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case. cybersecurity · 84d ago I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting? cybersecurity · 84d ago Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit cybersecurity · 84d ago Can someone unlock a list of the 500-1000 most visited websites online? hacking: security in practice · 84d ago One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign Trend Micro Research, News, Perspectives · 84d ago Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure For [Blue|Purple] Teams in Cyber Defence · 84d ago Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation For [Blue|Purple] Teams in Cyber Defence · 84d ago Wordlist generator based on WordNet graphs + LLM hacking: security in practice · 84d ago What volume of TPRM do you handle per month? cybersecurity · 84d ago GitHub’s Fake Engagement Problem Is Hiding in Plain Sight For [Blue|Purple] Teams in Cyber Defence · 84d ago Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR) For [Blue|Purple] Teams in Cyber Defence · 84d ago Ukraine identifies infostealer operator tied to 28,000 stolen accounts BleepingComputer · 84d ago Hackers bypass SonicWall VPN MFA due to incomplete patching BleepingComputer · 84d ago GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam) Reverse Engineering · 84d ago safest virtual machine? cybersecurity · 84d ago Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration cybersecurity · 84d ago Meet Rampart and Clarity, Microsoft’s new red team combo AI agents CyberScoop · 84d ago wordpress memberpress hacking: security in practice · 84d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware cybersecurity · 84d ago Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage For [Blue|Purple] Teams in Cyber Defence · 84d ago GitHub notifications cybersecurity · 84d ago The Open Source USB Drive Built for Privacy hacking: security in practice · 84d ago Is there no more privacy left in the world? cybersecurity · 84d ago AI Agents defeat obfuscated JavaScript in 10 minutes Reverse Engineering · 84d ago Microsoft Edge had a password blunder, and it raises a bigger browser trust problem cybersecurity · 84d ago Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network cybersecurity · 84d ago Aconselhamento / mini texto cybersecurity · 84d ago CISA with an absolutely embarrassing data leak. cybersecurity · 84d ago Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys cybersecurity · 84d ago Anyone else feeling like static AppSec workflows are starting to hit limits? cybersecurity · 84d ago Is someone trying to hack me? hacking: security in practice · 85d ago What is it Wednesdays: Episode 0002 Reverse Engineering · 85d ago GitHub breach highlights developer tools as part of attack surface cybersecurity · 85d ago Why do some malware use unique user-agent strings? cybersecurity · 85d ago Encrypted emails bypassing email security tool cybersecurity · 85d ago Grafana breach caused by missed token rotation after TanStack attack BleepingComputer · 85d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era For [Blue|Purple] Teams in Cyber Defence · 85d ago GitHub says internal repositories were impacted in poisoned VS Code extension attack CyberScoop · 85d ago Ctf groups cybersecurity · 85d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era cybersecurity · 85d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era Technical Information Security Content & Discussion · 85d ago cpu backdoor hacking: security in practice · 85d ago CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis Technical Information Security Content & Discussion · 85d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 85d ago Opensource that automatically scans your git repos for breaches cybersecurity · 85d ago 5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready For [Blue|Purple] Teams in Cyber Defence · 85d ago TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post) Reverse Engineering · 85d ago Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing Reverse Engineering · 85d ago Identity Alone Isn't Enough: Why Device Security Has to Share the Load BleepingComputer · 85d ago CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers Technical Information Security Content & Discussion · 85d ago Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online Technical Information Security Content & Discussion · 85d ago CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed. cybersecurity · 85d ago Your developers are deploying agents in your production environment right now. You have no governance for it. cybersecurity · 85d ago Technical analysis of CVE-2026-34472 in ZTE H188A router firmware hacking: security in practice · 85d ago ¿Como me preparo para EC-Council CSA? cybersecurity · 85d ago The IBM X-Force Index 2026 explains all three in one finding. cybersecurity · 85d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 85d ago Securing iPad's question cybersecurity · 85d ago Cybersecurity 101 cybersecurity · 85d ago What would this job role be? cybersecurity · 85d ago Drupal critical update to fix bug with high exploitation risk BleepingComputer · 85d ago MSPs & MSSPs suck cybersecurity · 85d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 85d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog All CISA Advisories · 85d ago [ Removed by Reddit ] cybersecurity · 85d ago GitHub hit by a compromised VSCode extension Technical Information Security Content & Discussion · 85d ago Crossroads cybersecurity · 85d ago Advice regarding "SOC" job that automates everything cybersecurity · 85d ago Is this Medium article about "NetMirror" malware legit? cybersecurity · 85d ago AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon? cybersecurity · 85d ago Developer tooling is part of the attack surface before a project is even run cybersecurity · 85d ago Exploit released for new PinTheft Arch Linux root escalation flaw BleepingComputer · 85d ago How to build .NET obfuscator Reverse Engineering · 85d ago botguard-token-generator / a google botguard token gen using only requests...? Reverse Engineering · 85d ago Remote Process Read Primitive via NtCreateThreadEx Exit Code For [Blue|Purple] Teams in Cyber Defence · 85d ago GUEST ESSAY: AI can speed up communication, but it can also weaken human connection The Last Watchdog · 85d ago How the hell do you manage developers, their code, their apps? cybersecurity · 85d ago Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed cybersecurity · 85d ago aimap: Discover Exposed AI Services For [Blue|Purple] Teams in Cyber Defence · 85d ago FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation. For [Blue|Purple] Teams in Cyber Defence · 85d ago Ongoing development hacking: security in practice · 85d ago Webworm: New burrowing techniques WeLiveSecurity · 85d ago Why China Is Now a Peer Competitor to the United States in Cyberspace For [Blue|Purple] Teams in Cyber Defence · 85d ago When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax Technical Information Security Content & Discussion · 85d ago Do people still rely on antivirus software in 2026, or is built-in security enough now? cybersecurity · 85d ago For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks? hacking: security in practice · 85d ago GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories cybersecurity · 85d ago GitHub confirms breach of 3,800 repos via malicious VSCode extension BleepingComputer · 85d ago Automatic CLI for spinning up vulnerable labs + objectives cybersecurity · 85d ago Hackers found a way around Intel CET—PLaTypus locks down library jumps hacking: security in practice · 85d ago ISO/IEC 27701 scenario question cybersecurity · 85d ago Discord rolls out end-to-end encryption on voice, video calls cybersecurity · 85d ago Microsoft shares mitigation for YellowKey Windows zero-day BleepingComputer · 85d ago nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings For [Blue|Purple] Teams in Cyber Defence · 85d ago GitHub investigates internal repositories breach claimed by TeamPCP cybersecurity · 85d ago Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt For [Blue|Purple] Teams in Cyber Defence · 85d ago We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. For [Blue|Purple] Teams in Cyber Defence · 85d ago Two AI-based science assistants succeed with drug-retargeting tasks cybersecurity · 85d ago GitHub investigates internal repositories breach claimed by TeamPCP hacking: security in practice · 85d ago Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings) For [Blue|Purple] Teams in Cyber Defence · 85d ago America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames cybersecurity · 85d ago An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now. cybersecurity · 85d ago We audited 12K n8n templates: most have critical vulnerabilities Technical Information Security Content & Discussion · 85d ago GitHub investigates internal repositories breach claimed by TeamPCP BleepingComputer · 85d ago Veilgate - Deception proxy Technical Information Security Content & Discussion · 85d ago Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild For [Blue|Purple] Teams in Cyber Defence · 85d ago New to cybersecurity cybersecurity · 85d ago Anyone interview or work with Moxfive? cybersecurity · 85d ago A stealth Firefox version that passes all anti-bot and CAPTCHA cybersecurity · 85d ago mkPIVM - a polymorphic position-independent shellcode virtualizer cybersecurity · 85d ago Started in IT and need a Cybersecurity Roadmap with my Useless Degree! cybersecurity · 85d ago GitHub announces internal data breached. cybersecurity · 85d ago Roadmap to Cybersecurity roles cybersecurity · 85d ago Hackers: What age did you start? Where did you start, especially in practicing your skills? hacking: security in practice · 85d ago CISA credential leak raises alarms, and Capitol Hill demands answers CyberScoop · 85d ago Malware installed without literally doing anything? cybersecurity · 85d ago Max-severity flaw in ChromaDB for AI apps allows server hijacking BleepingComputer · 85d ago CTFs cybersecurity · 85d ago Can't access anything Malware Analysis & Reports · 85d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware BleepingComputer · 85d ago How to watch a private video on Youtube? hacking: security in practice · 85d ago Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches CyberScoop · 85d ago Sleeping Agent: Silent persistent C2 through Web Push Technical Information Security Content & Discussion · 85d ago Crossroads cybersecurity · 85d ago Discord rolls out end-to-end encryption on voice, video calls BleepingComputer · 85d ago Canara Bank SuRaksha Cyber Hackathon 2.0, cybersecurity · 85d ago Eight Leading U.S. Communications Firms Form C2 ISAC For [Blue|Purple] Teams in Cyber Defence · 85d ago Can I do anything cool with this network controller? hacking: security in practice · 85d ago News alert: Orchid Security study finds invisible identities now outnumber managed accounts The Last Watchdog · 85d ago Anti BOT Tipps und Tricks gesucht. cybersecurity · 85d ago FBI: Americans lost over $388 million to scams using crypto ATMs in 2025 BleepingComputer · 85d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security cybersecurity · 85d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 85d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security Technical Information Security Content & Discussion · 85d ago New to Cybersecurity cybersecurity · 85d ago Microsoft Self-Service Password Reset abused in Azure data theft attacks BleepingComputer · 85d ago Micro controller safety? hacking: security in practice · 85d ago Is the ISC2 Certified in Cybersecurity worth it? cybersecurity · 85d ago Average Days to Close by Source CNAPP Severity Tag 2026 cybersecurity · 85d ago I want free nmap resource cybersecurity · 85d ago If I clear browser history regularly, does it reduce the chances of malware that target browser data? cybersecurity · 85d ago What is next after 1.5 Year as Security Analyst? cybersecurity · 85d ago Analysis advice cybersecurity · 85d ago Stop me if you heard this one before... (YellowKey related) cybersecurity · 85d ago UAC-0184: From HTA to a Signed Network Stack For [Blue|Purple] Teams in Cyber Defence · 86d ago Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe? cybersecurity · 86d ago Microsoft plans to improve Windows 11 driver quality in 2026 BleepingComputer · 86d ago Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing) Reverse Engineering · 86d ago Looking for advice: where should I post/publish CVE write-ups? cybersecurity · 86d ago Microsoft blames macOS update for undismissible Teams location prompts BleepingComputer · 86d ago CISA Admin Leaked AWS GovCloud Keys on Github hacking: security in practice · 86d ago New GMKtec M7 Ultra appears to be infected. Beware of the malware! Malware Analysis & Reports · 86d ago Cybersecurity statistics of the week (May 11th - May 17th) cybersecurity · 86d ago How can I test my website locally for cybersecurity? cybersecurity · 86d ago Mini Shai-Hulud returns, compromising hundreds of npm packages CyberScoop · 86d ago Use of coding in security operations cybersecurity · 86d ago Decompilation of DSP Code using IDA Pro hacking: security in practice · 86d ago Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz cybersecurity · 86d ago Microsoft disrupts cybercrime service that abused software verification systems en masse cybersecurity · 86d ago I've built an open source honeypot probe database accessible via curl, http and mcp cybersecurity · 86d ago New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here For [Blue|Purple] Teams in Cyber Defence · 86d ago Deep dive into the object creation flow in Windows - PART 4: Handle table internals. Reverse Engineering · 86d ago 6,000+ Automatic Tank Gauges Exposed With No Authentication cybersecurity · 86d ago Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email? cybersecurity · 86d ago How Storm-2949 turned a compromised identity into a cloud-wide breach For [Blue|Purple] Teams in Cyber Defence · 86d ago Microsoft disrupts cybercrime service that abused software verification systems en masse CyberScoop · 86d ago How Storm-2949 turned a compromised identity into a cloud-wide breach Technical Information Security Content & Discussion · 86d ago If humans are the weakest link, why won't companies evolve? cybersecurity · 86d ago Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?" cybersecurity · 86d ago New Shai-Hulud malware wave compromises 600 npm packages BleepingComputer · 86d ago 7-Eleven confirms data breach claimed by the ShinyHunters gang BleepingComputer · 86d ago Entra ID: PIM for Groups Review For [Blue|Purple] Teams in Cyber Defence · 86d ago Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation BleepingComputer · 86d ago Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM cybersecurity · 86d ago Local transcription vs cloud transcription, which actually feels safer? cybersecurity · 86d ago Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today? cybersecurity · 86d ago Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise cybersecurity · 86d ago TeamPCP compromises NPM maintainer with over 540 packages For [Blue|Purple] Teams in Cyber Defence · 86d ago Shai-Hulud source leak is turning npm malware into a copycat problem cybersecurity · 86d ago Webinar: The hidden bottlenecks in network incident response BleepingComputer · 86d ago Framework for Preventing Secret Ideas from Leakage cybersecurity · 86d ago Kieback & Peter DDC Building Controllers All CISA Advisories · 86d ago Siemens RUGGEDCOM APE1808 Devices All CISA Advisories · 86d ago ABB CoreSense HM and CoreSense M10 All CISA Advisories · 86d ago ScadaBR All CISA Advisories · 86d ago ZKTeco CCTV Cameras All CISA Advisories · 86d ago Local LLM for building AI Security platform cybersecurity · 86d ago SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access cybersecurity · 86d ago Emerging Cyber security niches cybersecurity · 86d ago ISO/IEC 27701 cybersecurity · 86d ago Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware Reverse Engineering · 86d ago Solo dev building a terminal-heavy hacking game inspired by corporate security cybersecurity · 86d ago Microsoft confirms patching issues in restricted Windows networks BleepingComputer · 86d ago Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations cybersecurity · 86d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments Technical Information Security Content & Discussion · 86d ago CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing Technical Information Security Content & Discussion · 86d ago CS/IT Student Looking to Grow My LinkedIn Network 😃 cybersecurity · 86d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) hacking: security in practice · 86d ago Open-source Hermes bytecode decompiler for React Native apps (Rust) Reverse Engineering · 86d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) cybersecurity · 86d ago Is Amazon Cognito a good choice long term? Alternatives? cybersecurity · 86d ago Was hacking easier in the 80s and 90s and early 2000s? cybersecurity · 86d ago Need some Advice in SOAR heavy environment cybersecurity · 86d ago Trying to find serious builders in cybersecurity - not just “let’s build” conversations cybersecurity · 86d ago Hermes bytecode decompiler (Rust) - sharing my friend’s project Reverse Engineering · 86d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields hacking: security in practice · 86d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields Technical Information Security Content & Discussion · 86d ago Active Supply Chain Attack Compromises @antv Packages on npm... For [Blue|Purple] Teams in Cyber Defence · 86d ago AI Phishing cybersecurity · 86d ago The quest for greater tech independence WeLiveSecurity · 86d ago One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals cybersecurity · 86d ago When DMCA Comes Knocking - A YouTube Creator Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 86d ago [Cloudflare] Project Glasswing: what Mythos showed us For [Blue|Purple] Teams in Cyber Defence · 86d ago vpn explained the simple version that actually makes sense Malware Analysis & Reports · 86d ago How easy is it to get into the cyber security field? cybersecurity · 86d ago Forza Designer 6 Reverse Engineering · 86d ago 314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js cybersecurity · 86d ago Built a full disassembler & decompiler for Reverse Engineering | Free and open source. hacking: security in practice · 86d ago Built a full disassembler & decompiler | Free and open source. Reverse Engineering · 86d ago Slopinator - a poisoned GitHub repository generator hacking: security in practice · 86d ago Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start? cybersecurity · 86d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) Technical Information Security Content & Discussion · 86d ago ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo cybersecurity · 86d ago CEH/CPENT vs OSCP vs GPEN cybersecurity · 86d ago ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro” cybersecurity · 86d ago CISA Contractor Admin Leaked AWS GovCloud Keys on Github cybersecurity · 86d ago Made a shell greeter that generates a unique rocket every time you open a terminal tab hacking: security in practice · 86d ago Suspecious activity in my account cybersecurity · 86d ago Is it safe to use my first name and middle name on platforms? cybersecurity · 86d ago Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice. cybersecurity · 86d ago Just received an email from shinyhunters about their amtrack hack cybersecurity · 86d ago Just received an email from shinyhackers about their amtrack hack hacking: security in practice · 86d ago Flipper Zero (or Alternatives)? hacking: security in practice · 86d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access cybersecurity · 86d ago INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers BleepingComputer · 86d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access hacking: security in practice · 86d ago SHub macOS infostealer variant spoofs Apple security updates BleepingComputer · 86d ago Bywaf: an auditable Python commandlet framework for chained pentest workflows cybersecurity · 86d ago For anyone currently working in a SOC: cybersecurity · 86d ago Fellow Tier 1 SOC/Security Analysts - What does your day to day look like? cybersecurity · 86d ago The quiet death of behavioral anti-bot and the pivot to hardware ZKPs Technical Information Security Content & Discussion · 86d ago SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain For [Blue|Purple] Teams in Cyber Defence · 86d ago AI might cut false positives, but it won’t stop the slop CyberScoop · 86d ago Recent WhatsApp hacks hacking: security in practice · 86d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 86d ago How do you threat hunt for RMM tools in environments where RMM is all over the place? cybersecurity · 86d ago Decompilation projects and N64 Recompiled PC ports (May 2026) Reverse Engineering · 86d ago Microsoft - "your single use code" email when it was not requested by yourself cybersecurity · 86d ago Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa CyberScoop · 86d ago Directory of vendor security questionnaires cybersecurity · 86d ago Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised cybersecurity · 86d ago I wrote an async scanner that runs about 9x faster than nmap for discovery. hacking: security in practice · 86d ago 5 Steps to Managing Shadow AI Tools Without Slowing Down Employees BleepingComputer · 86d ago MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals cybersecurity · 86d ago AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems Technical Information Security Content & Discussion · 86d ago Glass - A fast and free interactive disassembler Reverse Engineering · 86d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. Technical Information Security Content & Discussion · 86d ago Leaked Shai-Hulud malware fuels new npm infostealer campaign BleepingComputer · 86d ago Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers hacking: security in practice · 86d ago Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight cybersecurity · 86d ago Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger For [Blue|Purple] Teams in Cyber Defence · 87d ago Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics For [Blue|Purple] Teams in Cyber Defence · 87d ago How is AI affecting the cybersecurity market? cybersecurity · 87d ago MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack The Last Watchdog · 87d ago MCP security cybersecurity · 87d ago YellowKey Mitigation cybersecurity · 87d ago CrystalX: unpacking a Go RAT through three encrypted layers For [Blue|Purple] Teams in Cyber Defence · 87d ago Anyone else on the receiving end of ShinyHunters extortion email? cybersecurity · 87d ago Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs cybersecurity · 87d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Reverse Engineering · 87d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Malware Analysis & Reports · 87d ago Grafana says stolen GitHub token let hackers steal codebase BleepingComputer · 87d ago What’s the biggest mistake people still make about online security in 2026? cybersecurity · 87d ago Anthropic shuts the EU out of its most advanced cyber AI model cybersecurity · 87d ago Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens] cybersecurity · 87d ago Best hotel for attending all three conferences in Vegas? cybersecurity · 87d ago What's your company's actual PQC migration plan? Not the one on paper - the real one. cybersecurity · 87d ago The down fall of bug bounties Technical Information Security Content & Discussion · 87d ago The Boring Stuff is Dangerous Now darkreading · 87d ago Does buying local cybersecurity (services/products/etc) matter to you? cybersecurity · 87d ago LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose cybersecurity · 87d ago Detection Engineering AI Maturity Framework cybersecurity · 87d ago Microsoft code cybersecurity · 87d ago TanStack Supply Chain Attack (And How to Lock Down GitHub Actions) Technical Information Security Content & Discussion · 87d ago Microsoft testing adjustable taskbar, Start menu in Windows 11 BleepingComputer · 87d ago Microsoft confirms Windows 11 security update install issues cybersecurity · 87d ago Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ cybersecurity · 87d ago Exploit available for new DirtyDecrypt Linux root escalation flaw cybersecurity · 87d ago Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware cybersecurity · 87d ago Suspicious with a company offer letter cybersecurity · 87d ago The Canvas breach proved that prevention is no longer enough CyberScoop · 87d ago Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first? cybersecurity · 87d ago Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation Technical Information Security Content & Discussion · 87d ago Microsoft confirms Windows 11 security update install issues BleepingComputer · 87d ago Why do some recovery workflows still require full wallet uploads? cybersecurity · 87d ago Netmirror exposed - The Free Movie App That Was Robbing You Blind Malware Analysis & Reports · 87d ago Need help with interview for soc l1 cybersecurity · 87d ago Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap) cybersecurity · 87d ago HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try! Reverse Engineering · 87d ago Exploit available for new DirtyDecrypt Linux root escalation flaw BleepingComputer · 87d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 87d ago Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation Technical Information Security Content & Discussion · 87d ago Reverse engineering no dep x64 masm AI IDE Reverse Engineering · 87d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released cybersecurity · 87d ago carrer path in cybersecurity for a btech stud cybersecurity · 87d ago Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026 BleepingComputer · 87d ago Agents usage in production cybersecurity · 87d ago ‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K cybersecurity · 87d ago Former CISA nominee Sean Plankey named US CEO of defense startup CyberScoop · 87d ago Are teams still finding AI API keys in public repos? cybersecurity · 87d ago Can Laws Stop Deepfakes? South Korea Aims to Find Out darkreading · 87d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 87d ago Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here? cybersecurity · 87d ago Does the CBP bug phones? cybersecurity · 87d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released BleepingComputer · 87d ago What We Learned Building Runtime Visibility for Modern Telco Networks cybersecurity · 87d ago Ive got my Spotify account hacked! How do I solve this? cybersecurity · 87d ago The Politics of AI Transparency cybersecurity · 87d ago A million baby monitors and security cameras were easily viewable by hackers cybersecurity · 87d ago NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE cybersecurity · 87d ago Does anyone know if this file is still accessible to download? hacking: security in practice · 87d ago Is cybersecurity becoming more behavioral than technical? cybersecurity · 87d ago Questions About Promo Items for a Cybersecurity Conference cybersecurity · 87d ago DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write For [Blue|Purple] Teams in Cyber Defence · 87d ago Dois-je m'inquiéter ? cybersecurity · 87d ago I am dying to work abroad , rate my journey so far cybersecurity · 87d ago FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation For [Blue|Purple] Teams in Cyber Defence · 87d ago Microsoft - "Your single use code" email when it was not requested cybersecurity · 87d ago Security / Compliance work going Agentic? cybersecurity · 87d ago High school students organized a Jeopardy CTF competition - give it a try hacking: security in practice · 87d ago Don't believe the media, specially in cybersec cybersecurity · 87d ago Microsoft account keeps getting Authenticator requests? cybersecurity · 87d ago [Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated. cybersecurity · 87d ago Ansible security and compliance guide Technical Information Security Content & Discussion · 88d ago Malware learning Malware Analysis & Reports · 88d ago Struggling to generate security bulletins — any ideas? cybersecurity · 88d ago Certs to go into Security Engineer/architect cybersecurity · 88d ago 18882745552 beware of email with this number cybersecurity · 88d ago Transition from traditional penetration testing into AI security cybersecurity · 88d ago Seeking advice on next career steps cybersecurity · 88d ago Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing BleepingComputer · 88d ago Official Miasma Poison Tar Pit Docker Image Now Available hacking: security in practice · 88d ago Will the analyst role become obsolete? cybersecurity · 88d ago LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying" For [Blue|Purple] Teams in Cyber Defence · 88d ago Alert Fatigue cybersecurity · 88d ago Best path into cybersecurity for a high schooler? cybersecurity · 88d ago Static Kitten APT Adversary Simulation For [Blue|Purple] Teams in Cyber Defence · 88d ago Why Is Cybersecurity Now A Business Priority, Not Just An IT Function? Cyber Defense Magazine · 88d ago Keep getting hacked cybersecurity · 88d ago Eimeria: five layers from RAR5 to RunPE For [Blue|Purple] Teams in Cyber Defence · 88d ago ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only. For [Blue|Purple] Teams in Cyber Defence · 88d ago Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain Technical Information Security Content & Discussion · 88d ago How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices cybersecurity · 88d ago I’m interested in joining the Red Team Hackers Academy in Bangalore. cybersecurity · 88d ago openDCIM exploitation For [Blue|Purple] Teams in Cyber Defence · 88d ago PE packer/crypter with random VM ISA per build Reverse Engineering · 88d ago A clueless teenager 💔 cybersecurity · 88d ago HASBL CTF - A Jeopardy-Style CTF Organized by High School Students! For [Blue|Purple] Teams in Cyber Defence · 88d ago Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start? cybersecurity · 88d ago Am I overthinking Claude Code security or is this actually a risk? cybersecurity · 88d ago is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this cybersecurity · 88d ago ISO/IEC 27701 ( SoA ) Applicability cybersecurity · 88d ago Security Executive Playbook cybersecurity · 88d ago This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon cybersecurity · 88d ago We Have Packet Capture at Home For [Blue|Purple] Teams in Cyber Defence · 88d ago I feel crazy I hope someone has insight . cybersecurity · 88d ago Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware For [Blue|Purple] Teams in Cyber Defence · 88d ago HWMonitor Trojanized for STX RAT DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 88d ago awesome-dfir-skills: Admiralty System for CTI Claude skill For [Blue|Purple] Teams in Cyber Defence · 88d ago Mullvad exit IPs as a fingerprinting vector For [Blue|Purple] Teams in Cyber Defence · 88d ago Does anybody know where I may stumble upon some Sh1mmer bin downloads hacking: security in practice · 88d ago Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools For [Blue|Purple] Teams in Cyber Defence · 88d ago Popular node-ipc npm Package Infected with Credential Steale... For [Blue|Purple] Teams in Cyber Defence · 88d ago An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. For [Blue|Purple] Teams in Cyber Defence · 88d ago Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files For [Blue|Purple] Teams in Cyber Defence · 88d ago Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor For [Blue|Purple] Teams in Cyber Defence · 88d ago Sandworm Activity in Industrial Environments: What the Data Reveals For [Blue|Purple] Teams in Cyber Defence · 88d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 88d ago "Shadowserver-in-a-box" IntelMQ + ELK Solution For [Blue|Purple] Teams in Cyber Defence · 88d ago Stenloader: Steganography Shellcode Loader For [Blue|Purple] Teams in Cyber Defence · 88d ago AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out For [Blue|Purple] Teams in Cyber Defence · 88d ago Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018 For [Blue|Purple] Teams in Cyber Defence · 88d ago Our response to the TanStack npm supply chain attack For [Blue|Purple] Teams in Cyber Defence · 88d ago QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026). For [Blue|Purple] Teams in Cyber Defence · 88d ago We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. For [Blue|Purple] Teams in Cyber Defence · 88d ago APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox. For [Blue|Purple] Teams in Cyber Defence · 88d ago oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday For [Blue|Purple] Teams in Cyber Defence · 88d ago Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations For [Blue|Purple] Teams in Cyber Defence · 88d ago ΡHANTΟΜ Al-Powered Pentesting Command Center cybersecurity · 88d ago Interview Assessments cybersecurity · 88d ago We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it cybersecurity · 88d ago Questions about data blockers cybersecurity · 88d ago A Tale of Two File Names Reverse Engineering · 88d ago PE reconstruction Reverse Engineering · 88d ago OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance For [Blue|Purple] Teams in Cyber Defence · 88d ago Post Implementation task cybersecurity · 88d ago The Gentlemen Ransomware Group — Leak Analysis For [Blue|Purple] Teams in Cyber Defence · 88d ago Mythos, MOAK, CTEM and the End of CVE Chasing cybersecurity · 88d ago Cyber security jobs in Austria cybersecurity · 88d ago Microsoft rejects critical Azure vulnerability report, no CVE issued BleepingComputer · 88d ago Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network hacking: security in practice · 88d ago Personal favorite deception layer. cybersecurity · 88d ago Estudiar Ciberseguridad cybersecurity · 88d ago Learning way cybersecurity · 88d ago A File Format Uncracked for 20 Years: Part 2 Reverse Engineering · 88d ago How do you report large volume detections to a CISO without making the BPA report a SOC story? cybersecurity · 88d ago HDD Firmware Hacking Part 1 For [Blue|Purple] Teams in Cyber Defence · 88d ago Can anyone share bugbase platform screenshot having professional usage on dashboard? cybersecurity · 88d ago ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. For [Blue|Purple] Teams in Cyber Defence · 88d ago CTO at NCSC Summary: week ending May 17th For [Blue|Purple] Teams in Cyber Defence · 88d ago CTO at NCSC Summary: week ending May 17th cybersecurity · 88d ago GZDoom in the browser hacking: security in practice · 88d ago Vidar v1.5 in Go: same family, new language, heavy sandbox checks For [Blue|Purple] Teams in Cyber Defence · 89d ago Developer credential-theft campaign exposed operator-side self-infection For [Blue|Purple] Teams in Cyber Defence · 89d ago Security Executive Playbook cybersecurity · 89d ago Tired of tab-switching between CTI tools - here's what we put together cybersecurity · 89d ago I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor cybersecurity · 89d ago Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source! Reverse Engineering · 89d ago Help-Desk Lures Drop KongTuke's Evolved ModeloRAT For [Blue|Purple] Teams in Cyber Defence · 89d ago Welcome to BlackFile: Inside a Vishing Extortion Operation For [Blue|Purple] Teams in Cyber Defence · 89d ago HackTheBox - Pterodactyl IppSec · 89d ago In Cybersecurity cybersecurity · 89d ago AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize. Technical Information Security Content & Discussion · 89d ago DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era For [Blue|Purple] Teams in Cyber Defence · 89d ago Stop Being Weird — Life After Call Stack Spoofing Under CET For [Blue|Purple] Teams in Cyber Defence · 89d ago Anyone else feel like most MSP tooling is either overkill or painfully manual? cybersecurity · 89d ago Russian hackers turn Kazuar backdoor into modular P2P botnet BleepingComputer · 89d ago Thinkpad vs Macbook pro endpoint security cybersecurity · 89d ago Any more affordable alternatives to “IntelligenceX”? cybersecurity · 89d ago Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran cybersecurity · 89d ago tanstack checker github action cybersecurity · 89d ago Drivers Alpha AWUS036AXML cybersecurity · 89d ago Splunk download for free cybersecurity · 89d ago The Security Mistakes Being Repeated With Ai Cyber Defense Magazine · 89d ago Funnel Builder WordPress plugin bug exploited to steal credit cards cybersecurity · 89d ago Anyone here using pager duty? cybersecurity · 89d ago Scammer targeting posters cybersecurity · 89d ago Anyone know how to bypass these school laptop pins? hacking: security in practice · 89d ago Seeking advice cybersecurity · 89d ago Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works Technical Information Security Content & Discussion · 89d ago Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026) cybersecurity · 89d ago Just got an email about a single use code, maybe someone was trying to log in? cybersecurity · 89d ago Can a background in DevOps enter the cybersecurity field? cybersecurity · 89d ago [CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link. Reverse Engineering · 89d ago Triggering the Secure Boot Certificate Update with Intune Remediations For [Blue|Purple] Teams in Cyber Defence · 89d ago How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache For [Blue|Purple] Teams in Cyber Defence · 89d ago Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 For [Blue|Purple] Teams in Cyber Defence · 89d ago One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 89d ago CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) For [Blue|Purple] Teams in Cyber Defence · 89d ago Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 89d ago FamousSparrow APT Targets Azerbaijani Oil and Gas Industry For [Blue|Purple] Teams in Cyber Defence · 89d ago Disclosing new PebbleDash-based tools by Kimsuky For [Blue|Purple] Teams in Cyber Defence · 89d ago FrostyNeighbor: Fresh mischief and digital shenanigans For [Blue|Purple] Teams in Cyber Defence · 89d ago Kazuar: Anatomy of a nation-state botnet For [Blue|Purple] Teams in Cyber Defence · 89d ago OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments For [Blue|Purple] Teams in Cyber Defence · 89d ago NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys For [Blue|Purple] Teams in Cyber Defence · 89d ago Hacker Ringleader Extradited for 38 Billion Won Theft For [Blue|Purple] Teams in Cyber Defence · 89d ago Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System For [Blue|Purple] Teams in Cyber Defence · 89d ago Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit For [Blue|Purple] Teams in Cyber Defence · 89d ago The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation For [Blue|Purple] Teams in Cyber Defence · 89d ago FFFFirefox - A One-Day Wonder Renderer Exploit For [Blue|Purple] Teams in Cyber Defence · 89d ago MiniPlasma, a powerful LPE For [Blue|Purple] Teams in Cyber Defence · 89d ago Using ai in learning cybersecurity · 89d ago Exploiting Toshiba Qiomem.sys vulnerable driver Reverse Engineering · 89d ago Avanzamento area Blue Team/SOC cybersecurity · 89d ago Please what could be helpful cybersecurity · 89d ago HDD Firmware Hacking Part 1 Reverse Engineering · 89d ago CVE exploit chain cybersecurity · 89d ago What are the widely accepted SaaS security accreditations/audits an app should seek in fintech cybersecurity · 89d ago Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco cybersecurity · 89d ago Region-based binary diff tool for firmware analysis Reverse Engineering · 89d ago Major flaw in Indian Cyber and IT assurance landscape cybersecurity · 89d ago Red Team Ops Ⅱ ( CRTL ) exam preparation cybersecurity · 89d ago Recomendations cybersecurity · 89d ago A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Reverse Engineering · 89d ago Recommended cybersecurity certification for a UX designer new to the domain? cybersecurity · 89d ago แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป! Reverse Engineering · 89d ago insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server cybersecurity · 89d ago Career path cybersecurity · 89d ago Merit America offers a program that gets you into cyber security roles. cybersecurity · 89d ago Brovan — Open-source x86/x64 user-mode binary emulator written in C# Reverse Engineering · 89d ago Brovan: Binary user-mode emulator for x86_64 Reverse Engineering · 89d ago Brovan: Binary user-mode emulator for x86_64 Malware Analysis & Reports · 89d ago Brovan: Binary user-mode emulator for x86_64 cybersecurity · 89d ago AmEx Interview! cybersecurity · 89d ago A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA hacking: security in practice · 89d ago Developer credential-stealing pipeline also collected operator workstations cybersecurity · 89d ago need help building a case. cybersecurity · 89d ago Colorado governor commutes prison sentence for election denier Tina Peters CyberScoop · 89d ago Personal favorite SIEM platform? cybersecurity · 89d ago Cardputer ADV cybersecurity · 89d ago Alternative for Qualys cybersecurity · 89d ago I have a friend who looks like he’s a stalker I’m scared he will know I stalk him hacking: security in practice · 89d ago The 4th Linux kernel flaw this month can lead to stolen SSH host keys cybersecurity · 89d ago Congress Puts Heat on Instructure After Canvas Outage darkreading · 89d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 89d ago Stack Buffer Overflow Explained (Using a Classic Doom Bug) cybersecurity · 89d ago [Tutorial] How to hack DOS games: Reversing Prince of Persia hacking: security in practice · 89d ago Here’s how the FTC plans to enforce the Take It Down Act CyberScoop · 89d ago Understanding Stack Buffer Overflows Through Doom and C++ Reverse Engineering · 89d ago Confused about cybersecurity career cybersecurity · 89d ago Funnel Builder WordPress plugin bug exploited to steal credit cards BleepingComputer · 89d ago What is it Wednesdays: Episode 0001 Reverse Engineering · 89d ago Transferring from pen test consulting to application security? cybersecurity · 89d ago Curso de especializacion de Ciberseguridad cybersecurity · 89d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? For [Blue|Purple] Teams in Cyber Defence · 89d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? cybersecurity · 89d ago Lost, tempted to throw in the towel cybersecurity · 89d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own cybersecurity · 89d ago I open-sourced a Docker security scanner I use to audit all my websites cybersecurity · 89d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own BleepingComputer · 89d ago Testing Deception Technique cybersecurity · 89d ago Popular node-ipc npm package compromised to steal credentials BleepingComputer · 89d ago A malware got into my account and spread spam ad to my friends and relatives cybersecurity · 90d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems Technical Information Security Content & Discussion · 90d ago Avada Builder WordPress plugin flaws allow site credential theft BleepingComputer · 90d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems cybersecurity · 90d ago Most pentest reports I review are padded with garbage findings cybersecurity · 90d ago Is dns spoofing dead?? hacking: security in practice · 90d ago Cyber Essentials and use of third party websites - MFA cybersecurity · 90d ago Rapid 7 and Cisa Kev cybersecurity · 90d ago Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup Reverse Engineering · 90d ago Deepdive into the object creation flow in Windows -PART 2 : access check internals Reverse Engineering · 90d ago Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization Reverse Engineering · 90d ago Microsoft backpedals: Edge to stop loading passwords into memory BleepingComputer · 90d ago Anyone know much about MS Defender? cybersecurity · 90d ago My Privacy Focused USB Drive hacking: security in practice · 90d ago Cisco zero-day under ongoing attack by persistent threat group CyberScoop · 90d ago EN18031 for IoT: struggling to see the big picture — advice from experienced people? cybersecurity · 90d ago Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution BleepingComputer · 90d ago Japan’s 3DS Mandate: One Year In Blog – Forter · 90d ago Automating code security reviews with Claude Mythos-level capabilities Technical Information Security Content & Discussion · 90d ago Automating Code Security Reviews cybersecurity · 90d ago [Tool] IOCX — deterministic static IOC extraction for PE binaries For [Blue|Purple] Teams in Cyber Defence · 90d ago New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available cybersecurity · 90d ago [Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo) Reverse Engineering · 90d ago Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition) hacking: security in practice · 90d ago AI coding tools on developer machines — looking for input on how you're handling it cybersecurity · 90d ago Chrome 148 Update Patches Critical Vulnerabilities cybersecurity · 90d ago The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract Cyber Defense Magazine · 90d ago Microsoft warns of Exchange zero-day flaw exploited in attacks cybersecurity · 90d ago I need help. i am lost cybersecurity · 90d ago Microsoft to automatically roll back faulty Windows drivers BleepingComputer · 90d ago Novel Evilginx Frontend - Lowering the barrier for token theft reuse For [Blue|Purple] Teams in Cyber Defence · 90d ago Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence cybersecurity · 90d ago Cyber Pioneers Ponder Past as Prologue darkreading · 90d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 90d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 90d ago Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments cybersecurity · 90d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? cybersecurity · 90d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? For [Blue|Purple] Teams in Cyber Defence · 90d ago Microsoft warns of Exchange zero-day flaw exploited in attacks BleepingComputer · 90d ago I'm going crazy. At the application level what I can actually do to prevent DDos? cybersecurity · 90d ago yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android. Reverse Engineering · 90d ago Is anyone enrolled in Intellipaat's cybersecurity course? cybersecurity · 90d ago Will AI Replace Cybersecurity Jobs? cybersecurity · 90d ago Why geopolitical turmoil is a gift for scammers, and how to stay safe WeLiveSecurity · 90d ago What's best certification choice after OSWE cybersecurity · 90d ago TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer hacking: security in practice · 90d ago Facebook Page Call Slipping through Sleep mode cybersecurity · 90d ago ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey cybersecurity · 90d ago New Linux LPE allows local users to read any file, including privkeys cybersecurity · 90d ago A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks. cybersecurity · 90d ago Your experience as IT Admin on Alerts cybersecurity · 90d ago Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time cybersecurity · 90d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild cybersecurity · 90d ago GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets Reverse Engineering · 90d ago GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS Reverse Engineering · 90d ago Instrumenting QT6 desktop apps with Frida - Part 1 Technical Information Security Content & Discussion · 90d ago From Vercel Typosquatting to an Obfuscated macOS Malware Loader Technical Information Security Content & Discussion · 90d ago Discord VC lag Exploit cybersecurity · 90d ago FrostyNeighbor: Fresh mischief and digital shenanigans cybersecurity · 90d ago Bug FB - Inicio de sesion por password cybersecurity · 90d ago Does anyone know how to configure EVILGINX for testing cybersecurity · 90d ago Trafexia V2 - Mobile Traffic Interceptor Toolkit Reverse Engineering · 90d ago How long does it take to get familiar with a tool cybersecurity · 90d ago Scam website cybersecurity · 90d ago ANTS Hack: 19 million records exposed in French ID agency breach cybersecurity · 90d ago has anyone used tail os here? hacking: security in practice · 90d ago Is it really that easy to obtain SMS codes using an SS7 attack? cybersecurity · 90d ago AI coding tools are shipping code faster than security can review it. What's your team doing about it cybersecurity · 90d ago Interview for AI security engineer position at a fortune 500 company cybersecurity · 90d ago How’s the job market for Senior AppSec Engineers? How are the interviews? cybersecurity · 90d ago Has anyone read "The Art of Deception"? How does it hold up to now? cybersecurity · 90d ago Run this washer/dryer sans coin? hacking: security in practice · 90d ago WAF Evasion Engine For [Blue|Purple] Teams in Cyber Defence · 90d ago Is metadata protection becoming more important than traditional endpoint security for ordinary users? cybersecurity · 90d ago Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems darkreading · 90d ago Inspecting a DLL file trying to figure out if it really is malware Malware Analysis & Reports · 90d ago Zero trust in hybrid environments - what's actually worked for you cybersecurity · 90d ago Have you encountered issues with CSAF advisories in practice? cybersecurity · 90d ago Zero trust in hybrid environments - what's actually working for you cybersecurity · 90d ago I built an open-source Burp alternative hacking: security in practice · 90d ago TeamPCP hackers advertise Mistral AI code repos for sale BleepingComputer · 90d ago OpenAI confirms security breach in TanStack supply chain attack cybersecurity · 90d ago Bachelors Degree Options cybersecurity · 90d ago HighBoy hacking: security in practice · 90d ago Innovator Spotlight: Klever Compliance Cyber Defense Magazine · 90d ago Thus Spoke…The Gentlemen For [Blue|Purple] Teams in Cyber Defence · 90d ago Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin BleepingComputer · 90d ago Innovator Spotlight: Radware Cyber Defense Magazine · 90d ago SecurityScorecard Snags Driftnet to Level Up Threat Intelligence darkreading · 90d ago npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output Malware Analysis & Reports · 90d ago Pentagon cyber official calls advanced AI ‘revolutionary warfare’ CyberScoop · 90d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild darkreading · 90d ago White House cyber official: identity security matters more than ever in the age of AI CyberScoop · 90d ago Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks BleepingComputer · 90d ago I need help protecting my privacy cybersecurity · 90d ago Free Threat Intellegence cybersecurity · 90d ago What discovery in cybersecurity amazed you the most? cybersecurity · 90d ago OpenAI confirms security breach in TanStack supply chain attack BleepingComputer · 90d ago Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026 BleepingComputer · 90d ago Scholarship for Service cybersecurity · 90d ago Reading Siemens CT raw data hacking: security in practice · 90d ago KQLab - open-source query manager for SOC teams For [Blue|Purple] Teams in Cyber Defence · 90d ago For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons? cybersecurity · 90d ago How I use Hermes agent to turn Patch Tuesday into Windows exploit research hacking: security in practice · 90d ago Another day, another supply chain cybersecurity · 90d ago How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs? cybersecurity · 90d ago Teaching Linux+ & CEH..... cybersecurity · 90d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon cybersecurity · 90d ago How TeamPCP's Python Toolkit Survives a C2 Takedown For [Blue|Purple] Teams in Cyber Defence · 90d ago Innovator Spotlight: JScrambler Cyber Defense Magazine · 90d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon hacking: security in practice · 90d ago SIEM use case development cybersecurity · 90d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Technical Information Security Content & Discussion · 90d ago JFrog vs Mend as Scanners cybersecurity · 90d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 90d ago KQLab - open-source query manager for SOC teams cybersecurity · 90d ago Which Vendors Publish the Best (or Worst) Security Advisories? cybersecurity · 90d ago Tips for a beginner noob that wants to learn hacking: security in practice · 90d ago 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine darkreading · 91d ago Synthetic training data vs. real attack telemetry — does it actually matter? cybersecurity · 91d ago Microsoft AntiSSRF For [Blue|Purple] Teams in Cyber Defence · 91d ago Operative IT-Sicherheit | SIEM & Splunk cybersecurity · 91d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state Technical Information Security Content & Discussion · 91d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state For [Blue|Purple] Teams in Cyber Defence · 91d ago 18-year-old NGINX vulnerability allows DoS, potential RCE BleepingComputer · 91d ago Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight BleepingComputer · 91d ago SOC not for junior level? cybersecurity · 91d ago Major tech manufacturer Foxconn confirms cyberattack hit North American factories CyberScoop · 91d ago Cybersecurity at MSG cybersecurity · 91d ago pii-tools.com reputable? cybersecurity · 91d ago Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise cybersecurity · 91d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 91d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Reverse Engineering · 91d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Malware Analysis & Reports · 91d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Technical Information Security Content & Discussion · 91d ago Contract jobs worth the risk? cybersecurity · 91d ago HackTheBoxAcademy vs LetsDefend vs CyberDefenders cybersecurity · 91d ago Automating code security reviews with Claude: near Mythos-level capabilities at lower cost cybersecurity · 91d ago Making Right Career Decision? cybersecurity · 91d ago AI Drives Cybersecurity Investments, Widening 'Valley of Death' darkreading · 91d ago I tried using apparmor (linux security) but it doesn't seem to work very well cybersecurity · 91d ago Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything! cybersecurity · 91d ago Struggling to Stay Up to Date With Vulnerabilities cybersecurity · 91d ago CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure Technical Information Security Content & Discussion · 91d ago How to Check Computer Activity: 2026 Guide for Windows and Mac Technical Information Security Content & Discussion · 91d ago Strix — first public beta of the spiritual successor to cSploit/dSploit hacking: security in practice · 91d ago KongTuke hackers now use Microsoft Teams for corporate breaches BleepingComputer · 91d ago How fast is autonomous AI cyber capability advancing? For [Blue|Purple] Teams in Cyber Defence · 91d ago Foxconn Attack Highlights Manufacturing's Cyber Crisis darkreading · 91d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 91d ago Siemens Siemens ROS# All CISA Advisories · 91d ago Siemens gWAP All CISA Advisories · 91d ago Siemens SIMATIC All CISA Advisories · 91d ago Siemens Ruggedcom Rox All CISA Advisories · 91d ago Siemens Ruggedcom Rox All CISA Advisories · 91d ago Siemens Simcenter Femap All CISA Advisories · 91d ago Universal Robots Polyscope 5 All CISA Advisories · 91d ago Siemens Ruggedcom Rox All CISA Advisories · 91d ago Siemens Teamcenter All CISA Advisories · 91d ago Siemens Solid Edge All CISA Advisories · 91d ago Siemens SENTRON 7KT PAC1261 Data Manager All CISA Advisories · 91d ago Siemens Opcenter RDnL All CISA Advisories · 91d ago Siemens Ruggedcom Rox All CISA Advisories · 91d ago Siemens SIMATIC S7 PLC Web Server All CISA Advisories · 91d ago Siemens Industrial Devices All CISA Advisories · 91d ago Siemens SIMATIC All CISA Advisories · 91d ago Siemens SIPROTEC 5 All CISA Advisories · 91d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 91d ago How to Transfer files Safely from a Compromised (work) Device cybersecurity · 91d ago Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward cybersecurity · 91d ago Multiple data breaches in one week cybersecurity · 91d ago Whatsapp hacking: security in practice · 91d ago How are small security teams handling vulnerability overload now? cybersecurity · 91d ago Concerns mount that EU will demand age verification for VPNs cybersecurity · 91d ago Automating code security reviews: Claude Mythos-level capabilities with lower cost cybersecurity · 91d ago The Rare Patch: A Digital Sovereignty Challenge cybersecurity · 91d ago Advise cybersecurity · 91d ago CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC Technical Information Security Content & Discussion · 91d ago Face ID bypass with avatar hacking: security in practice · 91d ago GRC cybersecurity · 91d ago Dell confirms its SupportAssist software causes Windows BSOD crashes BleepingComputer · 91d ago Admins and Engineers cybersecurity · 91d ago Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark cybersecurity · 91d ago Ghidra 12.1 has been released! Reverse Engineering · 91d ago Prompt injection in browser coding agents is the threat model nobody is ready for cybersecurity · 91d ago US charges suspected Dream Market admin arrested in Germany BleepingComputer · 91d ago FrostyNeighbor: Fresh mischief and digital shenanigans WeLiveSecurity · 91d ago New Fragnesia Linux flaw lets attackers gain root privileges cybersecurity · 91d ago New Fragnesia Linux flaw lets attackers gain root privileges BleepingComputer · 91d ago Transition from MSP to Network Engineering? cybersecurity · 91d ago YellowKey: YellowKey Bitlocker Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 91d ago Reverse Engineering Slither.io’s Network Protocol Reverse Engineering · 91d ago So called “off grid” method cybersecurity · 91d ago Convince me I’m not paranoid: a unique hacking situation. cybersecurity · 91d ago Hunting the Behavior Behind npm Supply Chain Attacks cybersecurity · 91d ago Hunting the Behavior Behind npm Supply Chain Attacks hacking: security in practice · 91d ago Question for AppSec Members cybersecurity · 91d ago Hunting the Behavior Behind npm Supply Chain Attacks Technical Information Security Content & Discussion · 91d ago Beginners guide to Google Dorks by Heisenberg cybersecurity · 91d ago I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable... Malware Analysis & Reports · 91d ago Alguém sabe algo sobre raven eye technology cybersecurity · 91d ago Gophish Porject - Requirement cybersecurity · 91d ago Security Team Won’t Assess Risk cybersecurity · 91d ago Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework cybersecurity · 91d ago Microsoft’s new multi-model agentic security system tops leading industry benchmark cybersecurity · 91d ago Proxmark5 Day 3 Update - $357K+ funded (715% of goal) hacking: security in practice · 91d ago Researchers say AI just broke every benchmark for autonomous cyber capability CyberScoop · 91d ago Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents cybersecurity · 91d ago West Pharmaceutical says hackers stole data, encrypted systems BleepingComputer · 91d ago Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks CyberScoop · 91d ago Overwhelmed on how to enter the job market. cybersecurity · 91d ago Iranian hackers targeted major South Korean electronics maker BleepingComputer · 91d ago Social media scam bill targets tech giants as New Yorkers lose billions cybersecurity · 91d ago What are the biggest technical & cultural hurdles you’re facing right now? cybersecurity · 91d ago CISSP / CCSP training - Experienced engineer cybersecurity · 91d ago WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers Technical Information Security Content & Discussion · 91d ago I Reverse-engineering Need for Speed Underground 2 Server Reverse Engineering · 91d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 91d ago Checkbox Assessments Aren't Fit to Measure Risk darkreading · 91d ago Attackers Weaponize RubyGems for Data Dead Drops darkreading · 91d ago Innovators Spotlight: OPSWAT Cyber Defense Magazine · 91d ago Vulnerability in Canvas/Instructure Support Tickets had part in breach? cybersecurity · 91d ago Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak darkreading · 91d ago Are There Really Ethical Hackers? I've Yet To Meet One hacking: security in practice · 91d ago Tinker Tailor Soldier: Paper Werewolf’s latest toolkit For [Blue|Purple] Teams in Cyber Defence · 91d ago On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract Technical Information Security Content & Discussion · 91d ago New critical Exim mailer flaw allows remote code execution BleepingComputer · 91d ago /sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple Technical Information Security Content & Discussion · 91d ago Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out Technical Information Security Content & Discussion · 91d ago 126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies For [Blue|Purple] Teams in Cyber Defence · 91d ago DOJ releases legal rationale for nationwide voter data collection CyberScoop · 91d ago is malwarefox legit? cybersecurity · 91d ago what lab to learn zero trust? cybersecurity · 91d ago Anyone else got a bunch of emails leaked by Samsung? cybersecurity · 91d ago Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape darkreading · 91d ago This is what some the world's largest banks of malware look like stacked as hard drives cybersecurity · 91d ago I need feedback on my project please cybersecurity · 91d ago would like to understand the role of "Cyber Insurance UnderWriters" cybersecurity · 91d ago Weaponized AI: The new frontier of fraud and identity spoofing CyberScoop · 91d ago clens.io - new public threat & data intel service Malware Analysis & Reports · 91d ago Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad For [Blue|Purple] Teams in Cyber Defence · 91d ago Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise For [Blue|Purple] Teams in Cyber Defence · 91d ago I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included Reverse Engineering · 91d ago Free on-device tool for monitoring AI traffic on macOS — visibility before policy cybersecurity · 91d ago Is secure evidence handling and controlled derivative file sharing needed? cybersecurity · 91d ago Will Adding Some Certifications Help Me in the Job Market? cybersecurity · 91d ago Linux driver posted for Intel Silicon Security Engine Interface "ISSEI" cybersecurity · 91d ago Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified? cybersecurity · 91d ago Fragnesia made public as latest Linux local privilege escalation vulnerability cybersecurity · 91d ago HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity? cybersecurity · 92d ago trying to learn patching hacking: security in practice · 92d ago NIST is surrendering to the amount of CVEs coming in cybersecurity · 92d ago Windows BitLocker zero-day gives access to protected drives, PoC released BleepingComputer · 92d ago [HOMELAB] Built a SOC investigation console on two old Dell boxes For [Blue|Purple] Teams in Cyber Defence · 92d ago Military Veteran looking to get into the Cyber Field cybersecurity · 92d ago Android Intrusion Logging as a new source of data for consensual forensic analysis For [Blue|Purple] Teams in Cyber Defence · 92d ago Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor cybersecurity · 92d ago Granny’s Compromised Android Firmware Malware Analysis & Reports · 92d ago On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study) Technical Information Security Content & Discussion · 92d ago Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook. cybersecurity · 92d ago Webinar tomorrow: Why security alone won't stop modern attacks BleepingComputer · 92d ago Microsoft fixes BitLocker recovery issue only for Windows 11 users BleepingComputer · 92d ago Shai-Hulud: Another Wave and Going Open Source For [Blue|Purple] Teams in Cyber Defence · 92d ago Cve apis for a database cybersecurity · 92d ago Empresas de Cyberseguridad en Mexico (Reacciones) cybersecurity · 92d ago Joined a new company: GRC landscape advice cybersecurity · 92d ago Removing admin rights cybersecurity · 92d ago a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access cybersecurity · 92d ago A stealth approach to Process Injection - EntryPoint Hijacking For [Blue|Purple] Teams in Cyber Defence · 92d ago A stealth approach to Process Injection - EntryPoint Hijacking Technical Information Security Content & Discussion · 92d ago FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow cybersecurity · 92d ago Golden years for cyber security about to start? cybersecurity · 92d ago A stealth approach to Process Injection - EntryPoint Hijacking cybersecurity · 92d ago Microsoft fixes Windows Autopatch bug installing restricted drivers BleepingComputer · 92d ago Detecting CopyFail and DirtyFrag by thinking outside the box cybersecurity · 92d ago Daybreak is OpenAI’s answer to the AI arms race in cybersecurity CyberScoop · 92d ago Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security cybersecurity · 92d ago The Board Is Asking The Wrong Security Question Cyber Defense Magazine · 92d ago LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly darkreading · 92d ago China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm darkreading · 92d ago Foxconn confirms cyberattack claimed by Nitrogen ransomware gang BleepingComputer · 92d ago Career advice cybersecurity · 92d ago 73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation BleepingComputer · 92d ago LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back The Last Watchdog · 92d ago Microsoft says some users can't install Office on Windows 365 devices BleepingComputer · 92d ago A year of Apple Security Bounty research — 16 closed findings, full disclosure Technical Information Security Content & Discussion · 92d ago [Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) Malware Analysis & Reports · 92d ago The exponential rise of economic damage caused by cyber-crime continues cybersecurity · 92d ago [Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features Reverse Engineering · 92d ago Today's cybersecurity systems are not ready for AI cybersecurity · 92d ago Are certifications worth it, or do practical skills matter more? cybersecurity · 92d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) cybersecurity · 92d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) For [Blue|Purple] Teams in Cyber Defence · 92d ago Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed cybersecurity · 92d ago Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft cybersecurity · 92d ago What to do after security+ cybersecurity · 92d ago AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data cybersecurity · 92d ago AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods Technical Information Security Content & Discussion · 92d ago LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer] Reverse Engineering · 92d ago Service Principal Sign-Ins: A blind spot that a lot are missing For [Blue|Purple] Teams in Cyber Defence · 92d ago Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub cybersecurity · 92d ago Is it realistic to move from Tech Risk/GRC into technical cybersecurity? cybersecurity · 92d ago My Analysis of a Bandook RAT PCAP For [Blue|Purple] Teams in Cyber Defence · 92d ago Are IPhone autofill passwords safe to use? cybersecurity · 92d ago Access approvals happen over Slack dm and I don't know how to present that to an auditor cybersecurity · 92d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 92d ago China is going dark to develop its own Mythos, German cyber chief fears cybersecurity · 92d ago Is prompt injection a real problem for you? cybersecurity · 92d ago New Exim BDAT bug shows why “just patch the mail server” is still not simple cybersecurity · 92d ago Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach cybersecurity · 92d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 92d ago Cybersecurity guide cybersecurity · 92d ago [Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ? cybersecurity · 92d ago How you guys rate Google Cyber security course and certificate out of 10 !? cybersecurity · 92d ago Detection Rule is here For [Blue|Purple] Teams in Cyber Defence · 92d ago Cyebrsecurity Startup Advice cybersecurity · 92d ago Can anyone give a real world based AI based attack? cybersecurity · 92d ago r2garlic - The world's fastest Android/DEX decompiler meets radare2! Reverse Engineering · 92d ago How worried should we be about AI powered cyberattacks? cybersecurity · 92d ago Built STIS-ICS — an open ICS/OT security learning project cybersecurity · 92d ago OS scanner that checks repos for traces of the Shai Hulud worm Malware Analysis & Reports · 92d ago OS scanner that checks repos for traces of the Shai Hulud worm cybersecurity · 92d ago US govt seeks Instructure testimony on massive Canvas cyberattack BleepingComputer · 92d ago Foxconn Ransomware Attack Shows Nothing Is Safe Forever cybersecurity · 92d ago Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries cybersecurity · 92d ago Cellphone IP address spoofing. hacking: security in practice · 92d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu cybersecurity · 92d ago Explorer shows random letter/number filenames before copying my actual files — normal behavior? cybersecurity · 92d ago ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack CyberScoop · 92d ago Zscaler AI Security Capabilities ? cybersecurity · 92d ago Major world economies spell out key elements of AI ‘ingredients list’ CyberScoop · 92d ago It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight darkreading · 92d ago Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical CyberScoop · 92d ago Cybersecurity degree cybersecurity · 92d ago Owning a service principal equals owning its permissions. For [Blue|Purple] Teams in Cyber Defence · 92d ago Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma cybersecurity · 92d ago Cyber security cybersecurity · 92d ago New York Senate takes on junk fees, digital subscriptions, surveillance pricing cybersecurity · 92d ago UK fines water supplier $1.3M for exposing data of 664k customers BleepingComputer · 92d ago Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection For [Blue|Purple] Teams in Cyber Defence · 92d ago Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI Malware Analysis & Reports · 92d ago Webinar: Fixing the gaps in network incident response BleepingComputer · 92d ago Signal adds security warnings for social engineering, phishing attacks BleepingComputer · 92d ago CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level. For [Blue|Purple] Teams in Cyber Defence · 92d ago Cybersecurity statistics of the week (May 4th - May 10th) cybersecurity · 92d ago Feels like AI changed the speed of attacks more than most companies want to admit cybersecurity · 92d ago Microsoft releases Windows 10 KB5087544 extended security update BleepingComputer · 92d ago Anyone used Kasm or ReplicaCyber? cybersecurity · 92d ago Škoda warns of customer data breach after online shop hack cybersecurity · 92d ago Google launches new Android security feature to help uncover spyware attacks cybersecurity · 92d ago Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator BleepingComputer · 92d ago Windows 11 KB5089549 & KB5087420 cumulative updates released BleepingComputer · 92d ago Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days BleepingComputer · 92d ago Fancy Bear: Stealing Credentials Invisibly cybersecurity · 92d ago Nightmare Eclipse has published Greenplasma and YellowKey cybersecurity · 92d ago Copilot Agent cybersecurity · 92d ago Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim Technical Information Security Content & Discussion · 92d ago The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop Technical Information Security Content & Discussion · 92d ago What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles? cybersecurity · 92d ago GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language. Reverse Engineering · 92d ago Škoda warns of customer data breach after online shop hack BleepingComputer · 92d ago Android 17 to expand banking scam call and privacy protections BleepingComputer · 93d ago Google and Amnesty International teamed up to make it harder for spyware vendors to hide CyberScoop · 93d ago Career Advice cybersecurity · 93d ago Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs Technical Information Security Content & Discussion · 93d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu Technical Information Security Content & Discussion · 93d ago AI+DFIR Challenge: Share Your Disasters and Successes For [Blue|Purple] Teams in Cyber Defence · 93d ago Anyone else exhausted by the nonstop AI hype? cybersecurity · 93d ago Reviewing the trends in ransomware attacks in 2026 cybersecurity · 93d ago FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread The Last Watchdog · 93d ago Sorry if its the wrong place but hacking: security in practice · 93d ago Is It a Good Idea to Change Jobs Shortly After Getting Hired? cybersecurity · 93d ago SSO makes life easier but MFA keeps it safe, do we actually need both? cybersecurity · 93d ago Hugging Face Packages Weaponized With a Single File Tweak darkreading · 93d ago Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours? cybersecurity · 93d ago Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware For [Blue|Purple] Teams in Cyber Defence · 93d ago How are SOC teams actually deciding what not to investigate anymore? cybersecurity · 93d ago Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily cybersecurity · 93d ago Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released. cybersecurity · 93d ago Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification Cyber Defense Magazine · 93d ago Has anyone tryed this out yet? cybersecurity · 93d ago I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately... Technical Information Security Content & Discussion · 93d ago The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..) cybersecurity · 93d ago Switching to Cyber cybersecurity · 93d ago 20 Leaders Who Built the CISO Era: 2 Decades of Change darkreading · 93d ago Software Bill of Materials for AI - Minimum Elements All CISA Advisories · 93d ago ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax All CISA Advisories · 93d ago Subnet Solutions PowerSYSTEM Center All CISA Advisories · 93d ago ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities All CISA Advisories · 93d ago ABB AC500 V3 Multiple Vulnerabilities All CISA Advisories · 93d ago ABB Automation Builder Gateway for Windows All CISA Advisories · 93d ago Fuji Electric Tellus All CISA Advisories · 93d ago Nitrogen ransomware group claims Foxconn after Wisconsin plant outage cybersecurity · 93d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages cybersecurity · 93d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages BleepingComputer · 93d ago Postmortem: TanStack npm supply-chain compromise For [Blue|Purple] Teams in Cyber Defence · 93d ago Using Cape Sandbox for Phishing Analysis cybersecurity · 93d ago Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain darkreading · 93d ago SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA BleepingComputer · 93d ago Canvas hack: company pays criminals to delete students' stolen data cybersecurity · 93d ago AI is separating the companies built to scale from the ones built to sell CyberScoop · 93d ago i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning. cybersecurity · 93d ago AI integrations are quietly creating a new OAuth supply-chain problem cybersecurity · 93d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak cybersecurity · 93d ago UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships cybersecurity · 93d ago Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results Technical Information Security Content & Discussion · 93d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak BleepingComputer · 93d ago Hardcoded secrets in Git cybersecurity · 93d ago Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages cybersecurity · 93d ago UK water company allowed hackers to lurk undetected for nearly two years, regulator finds cybersecurity · 93d ago New ipTIME Pre-Auth RCE in CWMP cybersecurity · 93d ago New ipTIME Pre-Auth RCE in CWMP Technical Information Security Content & Discussion · 93d ago Postmortem: TanStack npm supply-chain compromise Technical Information Security Content & Discussion · 93d ago Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it? hacking: security in practice · 93d ago Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak cybersecurity · 93d ago Steam spear phishing Malware Analysis & Reports · 93d ago Fake linked in sponsored google search Malware Analysis & Reports · 93d ago Is my phone hacked? cybersecurity · 93d ago Switched to a grc role after a year in SOC L1 cybersecurity · 93d ago bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages For [Blue|Purple] Teams in Cyber Defence · 93d ago rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions For [Blue|Purple] Teams in Cyber Defence · 93d ago Detecting Remote Thread Creation with Windows Driver For [Blue|Purple] Teams in Cyber Defence · 93d ago Mythos finds a curl vulnerability For [Blue|Purple] Teams in Cyber Defence · 93d ago Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details For [Blue|Purple] Teams in Cyber Defence · 93d ago Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign For [Blue|Purple] Teams in Cyber Defence · 93d ago Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment For [Blue|Purple] Teams in Cyber Defence · 93d ago esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app For [Blue|Purple] Teams in Cyber Defence · 93d ago Forecasting Lazarus Crypto Heists cybersecurity · 93d ago LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors. For [Blue|Purple] Teams in Cyber Defence · 93d ago How Cloudflare responded to the “Copy Fail” Linux vulnerability For [Blue|Purple] Teams in Cyber Defence · 93d ago Infrastructure Security Incident Update & FAQs cybersecurity · 93d ago I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic. For [Blue|Purple] Teams in Cyber Defence · 93d ago LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots. For [Blue|Purple] Teams in Cyber Defence · 93d ago Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages cybersecurity · 93d ago In Depth Guide To VM Based Obfuscation - What it is and how to handle it. cybersecurity · 93d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective cybersecurity · 93d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective Reverse Engineering · 93d ago Transitioned to GRC cybersecurity · 93d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages cybersecurity · 93d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages Malware Analysis & Reports · 93d ago German cybersecurity official warns China is close to developing AI superhacker cybersecurity · 93d ago How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models. Technical Information Security Content & Discussion · 93d ago New Shai-Hulud npm worm variant Malware Analysis & Reports · 93d ago New Shai-Hulud npm worm variant For [Blue|Purple] Teams in Cyber Defence · 93d ago Google Detects First AI-Generated Zero-Day Exploit cybersecurity · 93d ago “DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance cybersecurity · 93d ago Instructure/ canvas paid the ransom? cybersecurity · 93d ago Instructure claims hackers returned stolen Canvas data after an extortion standoff CyberScoop · 93d ago OpenAI announces Daybreak, "frontier AI for defenders" Technical Information Security Content & Discussion · 93d ago Troca emprego - big para consultoria ou fintech - Pentester/Red Team cybersecurity · 93d ago GM agrees to $12.75M California settlement over sale of drivers’ data BleepingComputer · 93d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation hacking: security in practice · 93d ago Finally, texts between Android and iPhone users can be end-to-end encrypted cybersecurity · 93d ago Official CheckMarx Jenkins package compromised with infostealer cybersecurity · 93d ago Official CheckMarx Jenkins package compromised with infostealer BleepingComputer · 93d ago New GhostLock tool abuses Windows API to block file access BleepingComputer · 93d ago IMF warns of the potential for AI attacks on global financial systems cybersecurity · 93d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 93d ago GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon Technical Information Security Content & Discussion · 93d ago Cookie thieves caught stealing dev secrets via fake Claude Code installers cybersecurity · 93d ago Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo cybersecurity · 93d ago Innovator Spotlight: Iru Cyber Defense Magazine · 93d ago MS Defender on OT Network cybersecurity · 93d ago A fateful question cybersecurity · 93d ago EtwWatcher For [Blue|Purple] Teams in Cyber Defence · 93d ago SC-900 or SC-400 cybersecurity · 93d ago What are your security non-negotiables? cybersecurity · 93d ago Losing my path cybersecurity · 93d ago Axon-captcha cybersecurity · 93d ago What makes companies trust small cybersecurity vendors? cybersecurity · 93d ago Donuts and Beagles: Fake Claude site spreads backdoor For [Blue|Purple] Teams in Cyber Defence · 93d ago Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility” cybersecurity · 93d ago TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack cybersecurity · 93d ago Innovator Spotlight: Axonius Cyber Defense Magazine · 93d ago News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents The Last Watchdog · 93d ago New and improved: Agent governance, intelligent workflows, and connected app experiences Microsoft 365 Blog · 93d ago Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim cybersecurity · 94d ago How I Defeat Passkeys Nearly Every Time in Phishing Assessments Technical Information Security Content & Discussion · 94d ago These Extensions are Scraping Your AI Chats, are you affected? cybersecurity · 94d ago Reverse Engineering Fisher-Price Pixter Reverse Engineering · 94d ago Be careful with your Git: Investigating malware spreading through Git repositories cybersecurity · 94d ago Training and Phishing cybersecurity · 94d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation cybersecurity · 94d ago AI-powered hacking has exploded into industrial-scale threat, Google says cybersecurity · 94d ago Apple closed my bug report 4 times. MITRE wouldn't let it die. cybersecurity · 94d ago Instructure confirms hackers used Canvas flaw to deface portals BleepingComputer · 94d ago NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG cybersecurity · 94d ago Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach For [Blue|Purple] Teams in Cyber Defence · 94d ago Why Changing Passwords Doesn’t End an Active Directory Breach BleepingComputer · 94d ago CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection For [Blue|Purple] Teams in Cyber Defence · 94d ago looking for "evil" Websites Malware Analysis & Reports · 94d ago Google spotted an AI-developed zero-day before attackers could use it cybersecurity · 94d ago Google: Hackers used AI to develop zero-day exploit for web admin tool BleepingComputer · 94d ago Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge Cyber Defense Magazine · 94d ago Google spotted an AI-developed zero-day before attackers could use it CyberScoop · 94d ago The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface Cyber Defense Magazine · 94d ago Deterministic PE Structural Validation in IOCX v0.7.3 Malware Analysis & Reports · 94d ago beginner doubt cybersecurity · 94d ago where is the location of Files by Google on Android? hacking: security in practice · 94d ago Webinar this week: Prevention alone is not enough against modern attacks BleepingComputer · 94d ago I got my CEH Certification. SO what now? cybersecurity · 94d ago Construction to Cyber PM cybersecurity · 94d ago Deterministic PE Validation for Blue Teams - IOCX v0.7.3 For [Blue|Purple] Teams in Cyber Defence · 94d ago Reading old s4 memory with xgecu t48 hacking: security in practice · 94d ago [ Removed by Reddit ] cybersecurity · 94d ago Something got downloaded on my phone and then dissappeared cybersecurity · 94d ago Bleeding Llama cybersecurity · 94d ago The missing cybersecurity leader in small business CyberScoop · 94d ago Hack a data center? hacking: security in practice · 94d ago Do accountants even care about cybersecurityas much? cybersecurity · 94d ago Where Have All the Complex Windows Malware and Their Analyses Gone? cybersecurity · 94d ago TrickMo Android banker adopts TON blockchain for covert comms BleepingComputer · 94d ago Eyes wide open: How to mitigate the security and privacy risks of smart glasses WeLiveSecurity · 94d ago sl1nk link Malware Analysis & Reports · 94d ago MyAudi app:Security issues in Audi Connected Vehicle experience Technical Information Security Content & Discussion · 94d ago Delving deep into threat detection: My logic for abnormal EventID 7 activity For [Blue|Purple] Teams in Cyber Defence · 94d ago Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot Technical Information Security Content & Discussion · 94d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 94d ago Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust cybersecurity · 94d ago Was the reconnaissance in Bugbounty overrated? cybersecurity · 94d ago Cybersecurity beginner building an experimental log analyzer — looking for advice cybersecurity · 94d ago Anyone else worried about AI being a security nightmare? cybersecurity · 94d ago Snyk not working cybersecurity · 94d ago Malicious tenants paid us to abuse our RMM. We blocked them cybersecurity · 94d ago Help reasuring parents with an email parsing tool (i will not promote) cybersecurity · 94d ago Check out my matplotlib of BLE live wire data for Oura ring! Reverse Engineering · 94d ago Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows Reverse Engineering · 94d ago NZ announces sanctions on malicious Russian cyber actors, online platforms For [Blue|Purple] Teams in Cyber Defence · 94d ago Update: Ongoing Checkmarx Supply Chain Security Incident For [Blue|Purple] Teams in Cyber Defence · 94d ago DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this? cybersecurity · 94d ago Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop Reverse Engineering · 94d ago cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers cybersecurity · 94d ago 5 years as a Level 1 Security Analyst and wanting to transition into consulting cybersecurity · 94d ago How to download a RAT for myself Malware Analysis & Reports · 94d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass cybersecurity · 94d ago New into network pentesting. cybersecurity · 94d ago Is it worth it to switching field to cybersecurity ? cybersecurity · 94d ago Neeed help to get cybersecurity internship. cybersecurity · 94d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 94d ago Cybersecurity and ADHD cybersecurity · 94d ago Mythos, MOAK, CTEM and the End of CVE Chasing Technical Information Security Content & Discussion · 94d ago Autonomous Vulnerability Hunting with MCP hacking: security in practice · 94d ago Anyone dealt with a VulDB submission rejection? Resubmit or reply? cybersecurity · 94d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass Reverse Engineering · 94d ago Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory) Reverse Engineering · 94d ago Autonomous Vulnerability Hunting with MCP Technical Information Security Content & Discussion · 94d ago GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3 Reverse Engineering · 94d ago ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025 For [Blue|Purple] Teams in Cyber Defence · 94d ago Unmanaged PowerShell Execution: Hunting Beyond powershell.exe For [Blue|Purple] Teams in Cyber Defence · 94d ago Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign For [Blue|Purple] Teams in Cyber Defence · 94d ago ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing cybersecurity · 94d ago Static Devirtualization of Themida For [Blue|Purple] Teams in Cyber Defence · 94d ago Now You See Me: AADGraphActivityLogs For [Blue|Purple] Teams in Cyber Defence · 94d ago I have a malware and need help removing it. someone please help me 🙏 cybersecurity · 94d ago [Write-up] CyberDefenders: Wiredive Lab For [Blue|Purple] Teams in Cyber Defence · 94d ago PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra Reverse Engineering · 94d ago I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too? cybersecurity · 94d ago EasySec - Update cybersecurity · 94d ago What is the cybersecurity equivalent of leaving your spare key under the doormat? cybersecurity · 94d ago ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement Technical Information Security Content & Discussion · 94d ago Hackers abuse Google ads, Claude.ai chats to push Mac malware BleepingComputer · 94d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 95d ago VICE: Cyberwar | Full Season 2 | Blueprint cybersecurity · 95d ago Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures cybersecurity · 95d ago Email OTP as default (often ONLY) password isn’t the solution cybersecurity · 95d ago page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer For [Blue|Purple] Teams in Cyber Defence · 95d ago Soc analyse cybersecurity · 95d ago Police shut down reboot of Crimenetwork marketplace, arrest admin BleepingComputer · 95d ago AI DNS Resolver hacking: security in practice · 95d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 95d ago Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI Cyber Defense Magazine · 95d ago Price rising cybersecurity · 95d ago Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple Technical Information Security Content & Discussion · 95d ago JDownloader — Website installer incident (May 2026) For [Blue|Purple] Teams in Cyber Defence · 95d ago AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report cybersecurity · 95d ago Possible security incident against Arup Group cybersecurity · 95d ago Can honeypots be used this way? cybersecurity · 95d ago Is it true that the professionals have the worst setups? hacking: security in practice · 95d ago The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice. Technical Information Security Content & Discussion · 95d ago I think AI just quietly killed the 90-day disclosure window. cybersecurity · 95d ago TCM and Educate 360 are bugged cybersecurity · 95d ago The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate." For [Blue|Purple] Teams in Cyber Defence · 95d ago Got an alert from google what should I do? cybersecurity · 95d ago UK jobs cybersecurity · 95d ago AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT For [Blue|Purple] Teams in Cyber Defence · 95d ago Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏 cybersecurity · 95d ago Outrunning SHA256 with Physics Technical Information Security Content & Discussion · 95d ago EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine) For [Blue|Purple] Teams in Cyber Defence · 95d ago Worst company cybersecurity · 95d ago Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning cybersecurity · 95d ago I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage hacking: security in practice · 95d ago Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months) cybersecurity · 95d ago Innovator Spotlight: Lineaje Cyber Defense Magazine · 95d ago ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring) cybersecurity · 95d ago App Store Question - Darato Sport / Dofu Sport / Kofu cybersecurity · 95d ago Help! - My Parents Computer is Hacked cybersecurity · 95d ago Refining hacking basics — scaling them aswell hacking: security in practice · 95d ago Ran lumma stealer from a recaptcha scam cybersecurity · 95d ago Port 5986 question cybersecurity · 95d ago CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse! cybersecurity · 95d ago cyber security/ segurança da informação cybersecurity · 95d ago Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers For [Blue|Purple] Teams in Cyber Defence · 95d ago College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains cybersecurity · 95d ago Help with an Escalating Cyber-Stalker cybersecurity · 95d ago RRW - Rick Roll WiFi cybersecurity · 95d ago Best resources to start learning python for cybersecurity and automation cybersecurity · 95d ago Writing a Naive LLVM-based Devirtualizer For [Blue|Purple] Teams in Cyber Defence · 95d ago Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game. cybersecurity · 95d ago Memory Poisoning AI Agents via ChromaDB Technical Information Security Content & Discussion · 95d ago Defence in Depth: A Practical Secure Corporate Network Topology Technical Information Security Content & Discussion · 95d ago Where Have All the Complex Windows Malware and Their Analyses Gone? For [Blue|Purple] Teams in Cyber Defence · 95d ago JDownloader site hacked to replace installers with Python RAT malware cybersecurity · 95d ago JDownloader site hacked to replace installers with Python RAT malware BleepingComputer · 95d ago Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram Technical Information Security Content & Discussion · 95d ago Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More) Technical Information Security Content & Discussion · 95d ago How can I fix my browser remembering what he had open last cybersecurity · 95d ago MS 360 CoPilot issues cybersecurity · 95d ago I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details cybersecurity · 96d ago ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12. cybersecurity · 96d ago eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback cybersecurity · 96d ago HackTheBox - Overwatch IppSec · 96d ago I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you cybersecurity · 96d ago AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic) hacking: security in practice · 96d ago Fake OpenAI repository on Hugging Face pushes infostealer malware BleepingComputer · 96d ago OWASP TOP 10 LLM 2026 Community voting cybersecurity · 96d ago When prompts become shells: RCE vulnerabilities in AI agent frameworks For [Blue|Purple] Teams in Cyber Defence · 96d ago Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus For [Blue|Purple] Teams in Cyber Defence · 96d ago MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) For [Blue|Purple] Teams in Cyber Defence · 96d ago Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor For [Blue|Purple] Teams in Cyber Defence · 96d ago Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles. For [Blue|Purple] Teams in Cyber Defence · 96d ago Second security incident at Instructure (Canvas) cybersecurity · 96d ago Wtf OPEN Ai Malware Analysis & Reports · 96d ago Bridging the Gap Between Vulnerabilities and Working Exploits hacking: security in practice · 96d ago um you guys is my hacker stupid? hacking: security in practice · 96d ago UK Advice Needed - VA+ Training? cybersecurity · 96d ago Gateweb - Secure Web Gateway cybersecurity · 96d ago Those who are in Detection engineering cybersecurity · 96d ago Can someone tell me of a trustable hacker? cybersecurity · 96d ago MSPs, how are you handling AI usage across your customer environments today? cybersecurity · 96d ago Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write cybersecurity · 96d ago How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there? cybersecurity · 96d ago ecpptv3 Exam in 3–4 Days — cybersecurity · 96d ago Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026 For [Blue|Purple] Teams in Cyber Defence · 96d ago Member of Prolific Russian Ransomware Group Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 96d ago EasterBunny: advanced espionage artifacts attributed to APT29 For [Blue|Purple] Teams in Cyber Defence · 96d ago AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES cybersecurity · 96d ago Did CISA helped you land a job ? cybersecurity · 96d ago Tracking the "Sorry" Extortionist Campaign Against cPanel Websites For [Blue|Purple] Teams in Cyber Defence · 96d ago PositiveIntent: Evasive loader for .NET Framework assemblies For [Blue|Purple] Teams in Cyber Defence · 96d ago The Accidental C2: Exploring Dev Tunnels for Remote Access For [Blue|Purple] Teams in Cyber Defence · 96d ago Living of the Land - DISM Sandbox Provider Hijack For [Blue|Purple] Teams in Cyber Defence · 96d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode For [Blue|Purple] Teams in Cyber Defence · 96d ago CTO at NCSC Summary: week ending May 10th cybersecurity · 96d ago CTO at NCSC Summary: week ending May 10th For [Blue|Purple] Teams in Cyber Defence · 96d ago ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure For [Blue|Purple] Teams in Cyber Defence · 96d ago PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale For [Blue|Purple] Teams in Cyber Defence · 96d ago Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo For [Blue|Purple] Teams in Cyber Defence · 96d ago pre pre junior needs help(guidance pls) cybersecurity · 96d ago DARWIS Taka - Web vulnerability scanner with Optional AI Validation For [Blue|Purple] Teams in Cyber Defence · 96d ago Trojan malware cybersecurity · 96d ago SANs Courses: How do people get their employers to pay? cybersecurity · 96d ago NIS2 Article 21: turning compliance controls into technical security evidence cybersecurity · 96d ago This GBA Rom is making is having a weird behavior in the Sandbox, why? cybersecurity · 96d ago This GBA ROM makes some weird things in the sanbox, would love to understand why hacking: security in practice · 96d ago Why AI agent governance feels harder than traditional security models cybersecurity · 96d ago Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection Technical Information Security Content & Discussion · 96d ago Confused about what certs are important cybersecurity · 96d ago Would getting Security+ be worthless for me? cybersecurity · 96d ago [Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc) Reverse Engineering · 96d ago Submit probe test — shadow DOM click cybersecurity · 96d ago Threat intelligence in OT (Power equipments) cybersecurity · 96d ago Why was he banned? hacking: security in practice · 96d ago Securing CI/CD for an open source project: lessons from Cilium Technical Information Security Content & Discussion · 96d ago LAB Setup hacking: security in practice · 96d ago SunnyDayBPF: eBPF telemetry integrity research for detection engineering For [Blue|Purple] Teams in Cyber Defence · 96d ago Ethical malware development community hacking: security in practice · 96d ago SOC Analyst cybersecurity · 96d ago PAWs, PAM and PIM..what is best practice? cybersecurity · 96d ago This is the most in-depth analysis I have found on the Instructure/Canvas breach so far. cybersecurity · 96d ago Poland says hackers breached water treatment plants, and the U.S. is facing the same threat cybersecurity · 96d ago Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments CyberScoop · 96d ago Has Instructure paid SH? hacking: security in practice · 96d ago Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web. cybersecurity · 97d ago NVIDIA confirms GeForce NOW data breach affecting Armenian users BleepingComputer · 97d ago Quacc++: Automated Open Source Vulnerability Discovery cybersecurity · 97d ago Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me. hacking: security in practice · 97d ago 60% of MD5 password hashes are crackable in under an hour cybersecurity · 97d ago Built a correlation engine that chains AD findings into attack paths automatically. cybersecurity · 97d ago New trends (not mainstream) hacking: security in practice · 97d ago Why More Analysts Won’t Solve Your SOC’s Alert Problem BleepingComputer · 97d ago Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!) Reverse Engineering · 97d ago Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests cybersecurity · 97d ago ShinyHunters claims nearly 9,000 schools affected by Canvas data breach CyberScoop · 97d ago Trellix source code breach claimed by RansomHouse hackers BleepingComputer · 97d ago Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI CyberScoop · 97d ago Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care Cyber Defense Magazine · 97d ago JDownloader's official website delivered Python RAT cybersecurity · 97d ago JDownloader's official website delivered Python RAT Malware Analysis & Reports · 97d ago Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) cybersecurity · 97d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. cybersecurity · 97d ago ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12 Technical Information Security Content & Discussion · 97d ago Note taking apps and advice cybersecurity · 97d ago CISA gives feds four days to patch Ivanti flaw exploited as zero-day BleepingComputer · 97d ago Best tools to find exposed web services by HTML title / HTTP response? hacking: security in practice · 97d ago IMF Warns AI Could Trigger Global Financial Cyber Crisis cybersecurity · 97d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 97d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 97d ago New Linux 'Dirty Frag' zero-day gives root on all major distros cybersecurity · 97d ago Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2 Reverse Engineering · 97d ago Is the ISC2 Cybersecurity program still worth it? cybersecurity · 97d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama For [Blue|Purple] Teams in Cyber Defence · 97d ago Zara data breach exposed personal information of 197,000 people BleepingComputer · 97d ago Canvas getting hit during finals week shows how fragile “critical SaaS” has become cybersecurity · 97d ago Are websites exposed to the internet under attack almost every hour, even if they're small? cybersecurity · 97d ago Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config Technical Information Security Content & Discussion · 97d ago Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou... For [Blue|Purple] Teams in Cyber Defence · 97d ago Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken cybersecurity · 97d ago Former govt contractor convicted for wiping dozens of federal databases BleepingComputer · 97d ago What the **** is happening in cybersecurity space ? cybersecurity · 97d ago New Linux 'Dirty Frag' zero-day gives root on all major distros BleepingComputer · 97d ago Canvas is back up, but now what? cybersecurity · 97d ago Copy Fail (CVE-2026-31431): A Technical Deep Dive Technical Information Security Content & Discussion · 97d ago Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago? hacking: security in practice · 97d ago AI Agents Have a Security Problem. IronClaw is Fixing It. hacking: security in practice · 97d ago Instagram is getting rid of end to end encryption, what now? cybersecurity · 97d ago Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack For [Blue|Purple] Teams in Cyber Defence · 97d ago Dirty Frag: Universal Linux LPE For [Blue|Purple] Teams in Cyber Defence · 97d ago Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication. For [Blue|Purple] Teams in Cyber Defence · 97d ago Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea For [Blue|Purple] Teams in Cyber Defence · 97d ago New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation cybersecurity · 97d ago Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable". cybersecurity · 97d ago Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group? cybersecurity · 97d ago SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals Reverse Engineering · 97d ago Cushman and Wakefield confirms cyberattack cybersecurity · 97d ago Egnyte potential ransomware attack cybersecurity · 97d ago So canvas is down, what'll happen if they can't come to an argreement? cybersecurity · 97d ago Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now. cybersecurity · 97d ago I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow! Reverse Engineering · 97d ago /Why/ is Shinyhunters targeting Canvas? cybersecurity · 97d ago Canvas Hack - Any Guesses How? cybersecurity · 97d ago Should I build a virtual or physical lab? cybersecurity · 97d ago Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12 cybersecurity · 97d ago Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata cybersecurity · 97d ago Audit/Cybersecurity cybersecurity · 97d ago Issues removing Trellix (and specifically solidifier) cybersecurity · 97d ago Pentagon eyes 3-year cyber training requirement, overriding new Army policy cybersecurity · 97d ago A hacker ran me over with a robot lawn mower - The Verge hacking: security in practice · 97d ago Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia For [Blue|Purple] Teams in Cyber Defence · 97d ago Canvas login portals hacked in mass ShinyHunters extortion campaign BleepingComputer · 97d ago How much personal info will be leaked by the recent Canvas hack?? cybersecurity · 97d ago OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI For [Blue|Purple] Teams in Cyber Defence · 97d ago Dirty Frag and canvas cybersecurity · 97d ago New TCLBanker malware self-spreads over WhatsApp and Outlook BleepingComputer · 97d ago Hackers deface school login pages after claiming another Instructure hack cybersecurity · 97d ago Happened today hacking: security in practice · 97d ago Ivanti customers confront yet another actively exploited zero-day CyberScoop · 97d ago Did I destroy my career by being loyal to an arguably good company? cybersecurity · 97d ago Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo Technical Information Security Content & Discussion · 97d ago V4bel/dirtyfrag - Universal Linux Local Privilege Escalation cybersecurity · 97d ago Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC For [Blue|Purple] Teams in Cyber Defence · 97d ago What is CYBERRANT? cybersecurity · 97d ago Canvas is down as ShinyHunters hack forces outage cybersecurity · 97d ago Shinyhunters and Canvas hacking: security in practice · 97d ago New Dirty Frag Linux Bug Emerges in Wake of Copy Fail cybersecurity · 97d ago Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today. cybersecurity · 97d ago How is GRC work in a MSSP? cybersecurity · 97d ago SH and BF phishing console cybersecurity · 97d ago Trump officials are steering a cybersecurity scholarship program toward AI CyberScoop · 97d ago Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth? cybersecurity · 97d ago Dirty Frag - Linux LPE similiar to Copy Fail Technical Information Security Content & Discussion · 97d ago Socure authenticating AI identity as real. cybersecurity · 97d ago The first FREE online WebAssembly Reverse Engineering workbench (and how we built it) Reverse Engineering · 97d ago New PCPJack worm steals credentials, cleans TeamPCP infections BleepingComputer · 97d ago Automated SSL Certificate Renewals - What is your setup? cybersecurity · 97d ago Shinyhunters and Canvas cybersecurity · 97d ago What Cli execution do you use for a script file? cybersecurity · 97d ago Australia warns of ClickFix attacks pushing Vidar Stealer malware BleepingComputer · 97d ago Fiserv security incident - data breach notice cybersecurity · 97d ago Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments cybersecurity · 97d ago Honey Tokens: Bait Credentials That Catch Breaches Technical Information Security Content & Discussion · 97d ago I graduate next year with a Cybersecurity degree. cybersecurity · 98d ago An unknown malware threat. There is no such thing as a 100% detection. Malware Analysis & Reports · 98d ago Asking about Cortex cybersecurity · 98d ago CVE-2026-42511 Breakdown: RCE in FreeBSD Technical Information Security Content & Discussion · 98d ago Apache Caldera cybersecurity · 98d ago What’s the “unsexy” problem in cyber that’s actually a total disaster? cybersecurity · 98d ago Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE cybersecurity · 98d ago Ivanti warns of new EPMM flaw exploited in zero-day attacks BleepingComputer · 98d ago As a developer, should I use AI to improve security? cybersecurity · 98d ago My company has an MSP that manages our employee endpoints but we cant access the software they use to manage cybersecurity · 98d ago Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804 Technical Information Security Content & Discussion · 98d ago Americans sentenced for running 'laptop farms' for North Korea cybersecurity · 98d ago Is my laptop hijacked ? cybersecurity · 98d ago The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls BleepingComputer · 98d ago American duo sentenced for hosting laptop farms for North Korean IT workers CyberScoop · 98d ago claude ai gave security beta to Enterprise plans only what can we do as pentesters? cybersecurity · 98d ago Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline cybersecurity · 98d ago Americans sentenced for running 'laptop farms' for North Korea BleepingComputer · 98d ago Advice for path to land job SOC in France cybersecurity · 98d ago Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered Cyber Defense Magazine · 98d ago Possible Major Vulnerability: Chromium used by current version of PRTG cybersecurity · 98d ago Mythos AI may be a cybersecurity threat, but it follows the rules of the game cybersecurity · 98d ago When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity Cyber Defense Magazine · 98d ago Control Checks using AI. cybersecurity · 98d ago How do native password managers clear the clipboard? cybersecurity · 98d ago VLC Media Player MKV Exploit Analysis Reverse Engineering · 98d ago Graduating CS Student but Wanna Start my Career in Cybersecurity cybersecurity · 98d ago Crypto gang member gets 6.5 years for role in $230 million heist BleepingComputer · 98d ago An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support) Technical Information Security Content & Discussion · 98d ago Webinar: Why modern attacks require both security and recovery BleepingComputer · 98d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 98d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 98d ago MAXHUB Pivot Client Application All CISA Advisories · 98d ago Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI Technical Information Security Content & Discussion · 98d ago Claude-Themed Malware Campaigns cybersecurity · 98d ago DeepFake it till you make it. cybersecurity · 98d ago The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments cybersecurity · 98d ago Palo Alto Networks firewall zero-day exploited for nearly a month BleepingComputer · 98d ago What niche in cybersecurity should I go for, with my background in Angular & .NET ? cybersecurity · 98d ago Successor for Kaspersky Endpoint Security cybersecurity · 98d ago Fake Claude AI website delivers new 'Beagle' Windows malware BleepingComputer · 98d ago One House Democrat is pressing Commerce on the government’s spyware use CyberScoop · 98d ago Fake call logs, real payments: How CallPhantom tricks Android users WeLiveSecurity · 98d ago Detecting BEC Persistence with KQL For [Blue|Purple] Teams in Cyber Defence · 98d ago Modify md5sum of a file hacking: security in practice · 98d ago Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago cybersecurity · 98d ago SOC Analyst tier 1 (Entry Level) ?? cybersecurity · 98d ago Unpacking Russian-Iranian Private-Sector Cyber Connections For [Blue|Purple] Teams in Cyber Defence · 98d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 98d ago Made cybersecurity merch as an infosec practitioner — honest feedback welcome cybersecurity · 98d ago Fixing the password problem is as easy as 123456 WeLiveSecurity · 98d ago As AI agents become users of company data - what is needed to keep data secure? cybersecurity · 98d ago Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities. cybersecurity · 98d ago AI inference is quietly becoming a security problem cybersecurity · 98d ago is winrar 7.13 vulnerable to extraction exploits? cybersecurity · 98d ago Tried explaining internet encryption in a beginner-friendly but accurate way, feedback? cybersecurity · 98d ago Is the EC-Council CTIA Certification Worth It for Career Growth? cybersecurity · 98d ago POC Android vuln 2026 cybersecurity · 98d ago Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise cybersecurity · 98d ago Opinions on Mimecast cybersecurity · 98d ago Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution For [Blue|Purple] Teams in Cyber Defence · 98d ago What's going on in the field of Cybersecurity 🫣. cybersecurity · 98d ago How do teams preserve institutional pentest knowledge when senior testers leave? cybersecurity · 98d ago CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE cybersecurity · 98d ago Sophos NDR on Proxmox cybersecurity · 98d ago Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites Malware Analysis & Reports · 98d ago Quacc++: Automated Open Source Vulnerability Discovery Technical Information Security Content & Discussion · 98d ago Hackers abuse Google ads for GoDaddy ManageWP login phishing BleepingComputer · 98d ago A DOD contractor’s API flaw exposed military course data and service member records CyberScoop · 98d ago On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029. cybersecurity · 98d ago DOJ says ransomware gang tapped into Russian government databases cybersecurity · 98d ago DAEMON Tools devs confirm breach, release malware-free version cybersecurity · 98d ago Have there been instances where your SOC has suffered a cybersecurity attack? cybersecurity · 98d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk For [Blue|Purple] Teams in Cyber Defence · 98d ago Inadvertent Injections For [Blue|Purple] Teams in Cyber Defence · 98d ago A critical Palo Alto PAN-OS zero-day is being exploited in the wild CyberScoop · 98d ago OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM hacking: security in practice · 98d ago OpenCTI founder, Samuel Hassine, arrested and charged with CSAM cybersecurity · 98d ago Deepfake Platform cybersecurity · 98d ago Critical vm2 sandbox bug lets attackers execute code on hosts BleepingComputer · 98d ago Innovators Spotlight: Badge (Part II) Cyber Defense Magazine · 98d ago Trellix Licence Query cybersecurity · 98d ago New Cisco DoS flaw requires manual reboot to revive devices BleepingComputer · 98d ago CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal For [Blue|Purple] Teams in Cyber Defence · 98d ago Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML Malware Analysis & Reports · 98d ago Instructure hacker claims data theft from 8,800 schools, universities cybersecurity · 98d ago Is AI generated code creating a non-linear security problem for AppSec teams? cybersecurity · 98d ago Jailbreaking my cars infotainment system and implementing my own custom software hacking: security in practice · 99d ago Binance fixed the IP whitelist gap — but the disclosure process is still broken Technical Information Security Content & Discussion · 99d ago D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says cybersecurity · 99d ago DAEMON Tools devs confirm breach, release malware-free version BleepingComputer · 99d ago where is the original wormgpt hacking: security in practice · 99d ago Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security cybersecurity · 99d ago Norton Antivirus and Other Norton Software cybersecurity · 99d ago Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home? cybersecurity · 99d ago We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes. cybersecurity · 99d ago Download a malware a while ago, someone trying to log into my ios account cybersecurity · 99d ago Are there any chill hacking youtubers? hacking: security in practice · 99d ago Org Restructure cybersecurity · 99d ago Non-Determinism of Maps in Golang: Why, How, and the Consequences Technical Information Security Content & Discussion · 99d ago Does SOC 2 actually reduce questionnaires, or just change them? cybersecurity · 99d ago Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views cybersecurity · 99d ago Why ransomware attacks succeed even when backups exist BleepingComputer · 99d ago How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically? cybersecurity · 99d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Reverse Engineering · 99d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Technical Information Security Content & Discussion · 99d ago Ran phishing awareness training for 200+ non-tech employees cybersecurity · 99d ago Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware For [Blue|Purple] Teams in Cyber Defence · 99d ago Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk cybersecurity · 99d ago Vulnerability Garden Technical Information Security Content & Discussion · 99d ago Vulnerability Garden cybersecurity · 99d ago Palo Alto Firewall Zero-Day Under Active Exploitation cybersecurity · 99d ago MuddyWater hackers use Chaos ransomware as a decoy in attacks BleepingComputer · 99d ago Redefining Security Operations Through Seceon’s Open Threat Management Platform Cyber Defense Magazine · 99d ago Webinar: Why network incidents escalate and how to fix response gaps BleepingComputer · 99d ago Cyber Security Militias cybersecurity · 99d ago Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk cybersecurity · 99d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 99d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 99d ago Took me a decade to turn quantum computing into what programmers can easily learn, big announcement hacking: security in practice · 99d ago Lilygo T-Embed Glitching etc hacking: security in practice · 99d ago CyberSecurity Nightmares cybersecurity · 99d ago Can I use NanoKVM if it's just to turn on pc? cybersecurity · 99d ago got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something? cybersecurity · 99d ago How to learn tools for cybersecurity? cybersecurity · 99d ago 'CopyFail' attackers start cashing in on Linux flaw cybersecurity · 99d ago Anybodybodybdown for a team/studygroup? cybersecurity · 99d ago Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today? hacking: security in practice · 99d ago I was hacked due to sim card spoofing cybersecurity · 99d ago Palo Alto Networks warns of firewall RCE zero-day exploited in attacks BleepingComputer · 99d ago Chrome is quietly installing a 4GB AI model on your device cybersecurity · 99d ago Dev vs Security role cybersecurity · 99d ago Discord bot C2 infrastructure Malware Analysis & Reports · 99d ago Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed For [Blue|Purple] Teams in Cyber Defence · 99d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 99d ago UAT-8302 and its box full of malware For [Blue|Purple] Teams in Cyber Defence · 99d ago Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft cybersecurity · 99d ago Oracle Debuts Monthly Critical Security Patch Updates cybersecurity · 99d ago Sec engineer / developer? cybersecurity · 99d ago When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them? cybersecurity · 99d ago Are we actually seeing more vulnerabilities or just more noise? cybersecurity · 99d ago Cybersecurity jobs in red team cybersecurity · 99d ago Question cybersecurity · 99d ago What’s the biggest mistake people make even after installing antivirus? cybersecurity · 99d ago CVE-2026-0073 Android adbd TLS client-authentication bypass For [Blue|Purple] Teams in Cyber Defence · 99d ago One KQL query you should have saved in your toolkit (most don’t) For [Blue|Purple] Teams in Cyber Defence · 99d ago New dashboard tracks ransomware groups by their reliance on Infostealer credentials cybersecurity · 99d ago ant4g0nist/pyre: Ghidra decompiler in your browser Reverse Engineering · 99d ago CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier? For [Blue|Purple] Teams in Cyber Defence · 99d ago Found a possibly interesting live attack hacking: security in practice · 99d ago What would you say if your security lead said this... cybersecurity · 99d ago What would be the goto setup in AWS for security purposes? cybersecurity · 99d ago CREST CRT Exam 2025/2026 Experiences cybersecurity · 99d ago Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside For [Blue|Purple] Teams in Cyber Defence · 99d ago Microsoft Edge stores your passwords in plaintext RAM... on purpose cybersecurity · 99d ago Export/Backup ChatGPT chats hacking: security in practice · 99d ago Como começar? cybersecurity · 99d ago Possible Password Leak? Curious if Anyone Has Seen This Before cybersecurity · 99d ago Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source! Reverse Engineering · 99d ago Not a Hack. A Handout. Inside the GTFOice.org Data Exposure cybersecurity · 99d ago Besoin de conseils sur une DMZ automatisée cybersecurity · 99d ago Microsoft, Google and xAI will let the government test their AI models before launch cybersecurity · 99d ago Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073 cybersecurity · 99d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 99d ago New stealthy Quasar Linux malware targets software developers BleepingComputer · 99d ago SMB Header Signature for Tagging in Firewall cybersecurity · 99d ago Question regarding VDP cybersecurity · 99d ago Working on what i should do for the next 3 years cybersecurity · 99d ago Question for Security Professionals cybersecurity · 99d ago Do tech companies lifecycle-manage public DNS records to prevent dangling DNS? cybersecurity · 99d ago Instructure hacker claims data theft from 8,800 schools, universities BleepingComputer · 99d ago Vulnerability Summary for the Week of April 27, 2026 cybersecurity · 99d ago Scan. Secure. Simplify. — Free Web Tools Platform Technical Information Security Content & Discussion · 99d ago Cisco releases open-source ‘DNA test for AI models’ cybersecurity · 99d ago Cybersecurity is becoming too AI dependent is that a problem cybersecurity · 99d ago Foxconn Wisconsin outage raises cyber questions cybersecurity · 99d ago How stressful is GRC? cybersecurity · 99d ago News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market The Last Watchdog · 99d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482) Technical Information Security Content & Discussion · 99d ago Salesforce pentesting novel techniques- how to be an apex predator Technical Information Security Content & Discussion · 99d ago DAEMON Tools trojanized in supply-chain attack to deploy backdoor BleepingComputer · 99d ago Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia cybersecurity · 99d ago Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India cybersecurity · 99d ago Archer for a non-regulated medium sized company? cybersecurity · 99d ago Cybersecurity statistics of the week (April 27th - May 3rd) cybersecurity · 99d ago Reverse-engineering the 1998 Ultima Online demo server Reverse Engineering · 99d ago Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM. cybersecurity · 99d ago One-Click Refunds Are Not as Hard as You Think Blog – Forter · 99d ago Student hacked Taiwan high-speed rail to trigger emergency brakes BleepingComputer · 99d ago 🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records For [Blue|Purple] Teams in Cyber Defence · 99d ago Where to find reliable vendors? cybersecurity · 99d ago DigiCert: Misissued code signing certificates Technical Information Security Content & Discussion · 99d ago Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts? cybersecurity · 100d ago We wrote a guide on securing Claude across the enterprise — here's the core framework (with download) cybersecurity · 100d ago Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium. cybersecurity · 100d ago Hardware reverse enginnering first project. Love some advice cybersecurity · 100d ago Microsoft Edge Stores Passwords in Process Memory, Posing Risk cybersecurity · 100d ago Currently working on cybersecurity, looking for advice cybersecurity · 100d ago Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning cybersecurity · 100d ago Major AI Clients Shipping With Broken OAuth Implementations Technical Information Security Content & Discussion · 100d ago CISO course valuation cybersecurity · 100d ago Inside Faxanadu series — deep dive into how this NES title works Reverse Engineering · 100d ago EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing Reverse Engineering · 100d ago Popular DAEMON Tools software compromised For [Blue|Purple] Teams in Cyber Defence · 100d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 100d ago Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise For [Blue|Purple] Teams in Cyber Defence · 100d ago GRC Path to CISO (Certifications) cybersecurity · 100d ago Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities For [Blue|Purple] Teams in Cyber Defence · 100d ago CISOs and pentest buyers, what's the worst thing you've seen in a pentest report? cybersecurity · 100d ago FTC to ban data broker Kochava from selling Americans’ location data BleepingComputer · 100d ago How to enforce M365 Sign-in frequency on corporate laptops? cybersecurity · 100d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs cybersecurity · 100d ago The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check. BleepingComputer · 100d ago The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss BleepingComputer · 100d ago Built an independent directory of AI Act / AI governance tools, feedback? cybersecurity · 100d ago ScarCruft APT group compromises gaming platform in a supply-chain attack cybersecurity · 100d ago Just curious cybersecurity · 100d ago 'Copy Fail' is a real Linux security crisis wrapped in AI slop cybersecurity · 100d ago Analysis malicious DLL cybersecurity · 100d ago Cyber security free course cybersecurity · 100d ago Vimeo data breach exposes personal information of 119,000 people BleepingComputer · 100d ago The Insurance Industry Is Rewriting Cybersecurity Strategy Cyber Defense Magazine · 100d ago Does certification expires? cybersecurity · 100d ago HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10 Technical Information Security Content & Discussion · 100d ago IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening Malware Analysis & Reports · 100d ago Panicking Malware Analysis & Reports · 100d ago ABB B&R Automation Studio All CISA Advisories · 100d ago ABB B&R Automation Runtime All CISA Advisories · 100d ago Hitachi Energy PCM600 All CISA Advisories · 100d ago Johnson Controls CEM AC2000 All CISA Advisories · 100d ago ABB B&R PVI All CISA Advisories · 100d ago How the Story of a USB Penetration Test Went Viral darkreading · 100d ago We get paid to break into buildings for a living. Ask us anything! cybersecurity · 100d ago Pay2Key ransomware — any recovery path that’s actually worked? cybersecurity · 100d ago Google now offers up to $1.5 million for some Android exploits BleepingComputer · 100d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison cybersecurity · 100d ago Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF cybersecurity · 100d ago Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud Technical Information Security Content & Discussion · 100d ago How have you kept growing your knowledge in security when the job stops pushing you? cybersecurity · 100d ago Supply chain attack: DAEMON Tools Lite now contains a backdoor. Malware Analysis & Reports · 100d ago Accelerating Vulnerability Detection and Response at Oracle For [Blue|Purple] Teams in Cyber Defence · 100d ago The Danger of Multi-SSO AWS Cognito User Pools Technical Information Security Content & Discussion · 100d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison BleepingComputer · 100d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs BleepingComputer · 100d ago Copilot Cowork: From conversation to action across skills, integrations, and devices Microsoft 365 Blog · 100d ago The UK’s Age Verification Law Is Producing Compliance Theater cybersecurity · 100d ago Microsoft Edge: Passwords end up in memory as plaintext cybersecurity · 100d ago Do people still get viruses in 2026, or is that mostly a myth now? cybersecurity · 100d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 Technical Information Security Content & Discussion · 100d ago Mitigation script for Copy Fail vulnerability CVE-2026-31431 cybersecurity · 100d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 cybersecurity · 100d ago Is this fake too?🤣 hacking: security in practice · 100d ago Copy.fail: Why Internal LLMs Are Non-Negotiable for Security Reverse Engineering · 100d ago The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew For [Blue|Purple] Teams in Cyber Defence · 100d ago Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released cybersecurity · 100d ago ScarCruft hackers push BirdCall Android malware via game platform BleepingComputer · 100d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack WeLiveSecurity · 100d ago DigiCert breached via malicious screensaver file cybersecurity · 100d ago I just figured out my dad use to be a Phreaker in the 1980s hacking: security in practice · 100d ago Caido Payloads and Scanner of Endpoints cybersecurity · 100d ago Proton Pass: Second-Password Bypass Through Emergency Access Technical Information Security Content & Discussion · 100d ago What of my favorite videos🙂 hacking: security in practice · 100d ago CISO Security Mind Map 2026 cybersecurity · 100d ago Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker cybersecurity · 100d ago Best tools for blocking spam calls and spam links? hacking: security in practice · 100d ago Amazon SES increasingly abused in phishing to evade detection cybersecurity · 100d ago someone else’s UI appearing on screen for split second— possible hacker?? hacking: security in practice · 100d ago AI Security Trainings cybersecurity · 100d ago Ai help cybersecurity · 100d ago ByDesign: observed behavior where file URLs remain accessible after unshare/delete cybersecurity · 100d ago Can Kali Linux still compete in cyber security or is it outdated? cybersecurity · 100d ago We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother Technical Information Security Content & Discussion · 100d ago Avoiding rouge AP detection in enterprise networks hacking: security in practice · 100d ago Who are your favorite cybersecurity YouTubers? cybersecurity · 100d ago CISOs, how are you balancing AI adoption with security risks these days? cybersecurity · 100d ago GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated. For [Blue|Purple] Teams in Cyber Defence · 100d ago dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025 For [Blue|Purple] Teams in Cyber Defence · 100d ago N-Day Research with AI: Using Ollama and n8n For [Blue|Purple] Teams in Cyber Defence · 100d ago San Diego Community College District fighting major cyberattack cybersecurity · 100d ago GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering hacking: security in practice · 100d ago San Diego Community College District fighting major cyberattack hacking: security in practice · 100d ago After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up cybersecurity · 100d ago Free resource: searchable archive of every BSides conference talk cybersecurity · 100d ago Lightning PyPI Compromise: Bun-Based Stealer cybersecurity · 100d ago Too much mother instinct? cybersecurity · 100d ago L1 SOC Analyst for ~2 years - Should I still get the Security + Certification? cybersecurity · 100d ago Do CTFs help real world security skills, or just teach patterns? cybersecurity · 100d ago Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo cybersecurity · 100d ago Should I do Security + or Network + or A+? For CompTia cybersecurity · 100d ago Weaver E-cology critical bug exploited in attacks since March BleepingComputer · 100d ago Bug bounty is ruining how people learn exploitation cybersecurity · 100d ago ISO/IEC 27701:2025 Scope and Location cybersecurity · 100d ago Cybersecurity's 2026 Wild Ride cybersecurity · 100d ago We built a free multiplayer game that scores prompts on AI code security. cybersecurity · 100d ago RMM Tools Fuel Stealthy Phishing Campaign darkreading · 100d ago Production Usecases cybersecurity · 100d ago Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra Reverse Engineering · 100d ago How does vCISO work? cybersecurity · 100d ago Amazon SES increasingly abused in phishing to evade detection BleepingComputer · 100d ago Researchers report Amazon SES abused in phishing to evade detection BleepingComputer · 100d ago Trellix discloses data breach after source code repository hack cybersecurity · 100d ago CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path cybersecurity · 100d ago Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability darkreading · 100d ago Trellix confirms source code repo access incident cybersecurity · 100d ago Where do i find reverse engineers for actuators? Ideally in Shenzhen Reverse Engineering · 100d ago Employer Offering to Pay for my Certification test - Which one do I choose? cybersecurity · 100d ago John Strand Pay What You Can Information Security Core Skills live starting May 11th cybersecurity · 100d ago [CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2). Reverse Engineering · 100d ago Canvas Breach May Put 275M Users, 9,000 Schools at Risk cybersecurity · 100d ago Backdoored PyTorch Lightning package drops credential stealer BleepingComputer · 100d ago Is this not such a big deal cybersecurity · 100d ago 38 CVEs in Healthcare Software Used by 100,000 Medical Providers For [Blue|Purple] Teams in Cyber Defence · 100d ago Do email link checkers need to be 100%? cybersecurity · 100d ago Cybersecurity M&A Roundup: 33 Deals Announced in April 2026 cybersecurity · 100d ago Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation Malware Analysis & Reports · 101d ago Recs for pen testing and vulnerability solutions cybersecurity · 101d ago Identify telegram account holders cybersecurity · 101d ago AI Code Security Study: 6 LLMs vs OWASP Top 10 cybersecurity · 101d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers hacking: security in practice · 101d ago Recursively fuzzing MS-RPC structures and monitoring using ETW For [Blue|Purple] Teams in Cyber Defence · 101d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers cybersecurity · 101d ago Trellix discloses data breach after source code repository hack BleepingComputer · 101d ago Iwas developing a hacker game that transports the feeling of the 90s hacking: security in practice · 101d ago We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA cybersecurity · 101d ago Azure IaaS: Defense in depth built on secure-by-design principles Security | Microsoft Azure Blog | Microsoft Azure · 101d ago Cortex XDR Cloud Compromise Alerting cybersecurity · 101d ago Norton.com Verification Email out of the blue cybersecurity · 101d ago Atomic Red Team is now aligned with MITRE ATT&CK v19! cybersecurity · 101d ago Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX? cybersecurity · 101d ago Who are you guys using for your PCI ASV Scanning? cybersecurity · 101d ago Just passed my Security+ exam. Now what? cybersecurity · 101d ago I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work. cybersecurity · 101d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 101d ago [PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection) cybersecurity · 101d ago Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia darkreading · 101d ago Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350) cybersecurity · 101d ago An another open door to IoT devices cybersecurity · 101d ago Ideas on how to have personal google-like account synchronization system cybersecurity · 101d ago Lateral Movement - Cross-Session Activation Technical Information Security Content & Discussion · 101d ago Lateral Movement - Cross-Session Activation cybersecurity · 101d ago How did this guy even access another person's privated YouTube video without wayback machine? hacking: security in practice · 101d ago What MCP servers have actually made it into your day-to-day toolkit? cybersecurity · 101d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems hacking: security in practice · 101d ago They don’t hack, they borrow: How fraudsters target credit unions BleepingComputer · 101d ago Cyber Security Education as Self-Defence classes cybersecurity · 101d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk cybersecurity · 101d ago Use.ai cybersecurity · 101d ago Educational tech giant Instructure confirms data breach, ShinyHunters claims attack cybersecurity · 101d ago [WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation Reverse Engineering · 101d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems cybersecurity · 101d ago Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management Cyber Defense Magazine · 101d ago IPod Nano Gets Three Monitors hacking: security in practice · 101d ago IDA-MCP Is Now RE-MCP With Ghidra Support Reverse Engineering · 101d ago Progress warns of critical MOVEit Automation auth bypass flaw BleepingComputer · 101d ago Webinar: Why MSPs must rethink security and backup strategies BleepingComputer · 101d ago Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference Reverse Engineering · 101d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems BleepingComputer · 101d ago Chrome "Best AdBlocker" trojanized extension - 100k downloads. hacking: security in practice · 101d ago How Dark Reading Lifted Off the Launchpad in 2006 darkreading · 101d ago Browsers making connection on port 3389 from loopback cybersecurity · 101d ago Microsoft confirms April Windows updates cause backup failures BleepingComputer · 101d ago Defender Flagged DigiCert Root Certs as Malware cybersecurity · 101d ago VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases For [Blue|Purple] Teams in Cyber Defence · 101d ago Another breach just hit Canvas (Instructure), and this one is worth a closer look. cybersecurity · 101d ago Over 40% of UK firms suffered cyber attack last year, survey finds cybersecurity · 101d ago EU should seek access to Anthropic's Mythos, Bundesbank says cybersecurity · 101d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha cybersecurity · 101d ago CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation. For [Blue|Purple] Teams in Cyber Defence · 101d ago 《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition) For [Blue|Purple] Teams in Cyber Defence · 101d ago nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution. For [Blue|Purple] Teams in Cyber Defence · 101d ago 蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery. For [Blue|Purple] Teams in Cyber Defence · 101d ago IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks cybersecurity · 101d ago People in cybersecurity, tell us what was the most epic moment in your career? cybersecurity · 101d ago Prerequisites for CARTP cybersecurity · 101d ago gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives For [Blue|Purple] Teams in Cyber Defence · 101d ago Claude Mythos Cyber Wake Up cybersecurity · 101d ago [ Removed by Reddit ] cybersecurity · 101d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 101d ago is trellix from mcafee good to use in 2026? cybersecurity · 101d ago Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list cybersecurity · 101d ago Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon For [Blue|Purple] Teams in Cyber Defence · 101d ago AMSI Page Guard Bypass (Rust PoC) For [Blue|Purple] Teams in Cyber Defence · 101d ago Any good open sources that bypass modern heuristic analysis? hacking: security in practice · 101d ago Meet Bluekit: The AI-Powered All-in-One Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 101d ago Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI For [Blue|Purple] Teams in Cyber Defence · 101d ago A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia For [Blue|Purple] Teams in Cyber Defence · 101d ago IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect For [Blue|Purple] Teams in Cyber Defence · 101d ago Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection For [Blue|Purple] Teams in Cyber Defence · 101d ago ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution… For [Blue|Purple] Teams in Cyber Defence · 101d ago Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia For [Blue|Purple] Teams in Cyber Defence · 101d ago [2603.28728] Study of Post Quantum status of Widely Used Protocols For [Blue|Purple] Teams in Cyber Defence · 101d ago Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin For [Blue|Purple] Teams in Cyber Defence · 101d ago Free apex hacks? hacking: security in practice · 101d ago Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning For [Blue|Purple] Teams in Cyber Defence · 101d ago Paypal Accesed by malware me being Stupid cybersecurity · 101d ago How was someone in another country able to read all my private messages without my password or clicking a link? cybersecurity · 101d ago code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint. For [Blue|Purple] Teams in Cyber Defence · 101d ago Secure Boot Inventory Data In Configuration Manager For [Blue|Purple] Teams in Cyber Defence · 101d ago EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time. For [Blue|Purple] Teams in Cyber Defence · 101d ago MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning. For [Blue|Purple] Teams in Cyber Defence · 101d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Technical Information Security Content & Discussion · 101d ago AI-powered honeypots: Turning the tables on malicious AI agents For [Blue|Purple] Teams in Cyber Defence · 101d ago Career Transition Help cybersecurity · 101d ago Alguien para hablar de cyberseguridad cybersecurity · 101d ago copy.golf — golf your exploits - smaller copy.fail exploits.. For [Blue|Purple] Teams in Cyber Defence · 101d ago DragonBreath: Dragon in the Kernel For [Blue|Purple] Teams in Cyber Defence · 101d ago What is this cybersecurity · 101d ago Your vibe-coded app is probably violating GDPR right now Technical Information Security Content & Discussion · 101d ago [SHOWCASE] Cascavel v3 hacking: security in practice · 101d ago Feeling lost and disappointed about finding a job just venting cybersecurity · 101d ago Slow at Learning/Cyber Security? cybersecurity · 101d ago Pokemon machine hacking: security in practice · 101d ago Suspicious traffic from web server cybersecurity · 101d ago Cyber security internship cybersecurity · 101d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 101d ago Isn't Windows Defender a crap anymore? cybersecurity · 101d ago GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions) Reverse Engineering · 101d ago Learning Cyber cybersecurity · 101d ago Instructure confirms data breach, ShinyHunters claims attack BleepingComputer · 101d ago Vishing simulator cybersecurity · 101d ago Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others cybersecurity · 101d ago Worried about being tracked/banned for using an educational app on MuMu Player - Need advice cybersecurity · 101d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks cybersecurity · 101d ago Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance cybersecurity · 101d ago Prompt Injection in 2026: The Five Attack Patterns That Actually Matter cybersecurity · 101d ago I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine cybersecurity · 101d ago Random trojan detected? cybersecurity · 101d ago CRTA second attempt cybersecurity · 101d ago What’s the hardest thing to learn in cybersecurity? cybersecurity · 101d ago What MCP servers are you integrating into your workflow (not exclusive to security)? cybersecurity · 101d ago Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors. For [Blue|Purple] Teams in Cyber Defence · 101d ago WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog cybersecurity · 101d ago What are like the top but unknown Cybersecurity firms? cybersecurity · 101d ago Can HTTP POST bodies be intercepted without network or host access? hacking: security in practice · 101d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha BleepingComputer · 101d ago Need professionals or expert on cybersecurity related to dark web for interview cybersecurity · 101d ago A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP) cybersecurity · 102d ago Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library For [Blue|Purple] Teams in Cyber Defence · 102d ago North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory cybersecurity · 102d ago VirusTotal has one flag for this sus site Malware Analysis & Reports · 102d ago Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo Reverse Engineering · 102d ago Telegram Mini Apps abused for crypto scams, Android malware delivery BleepingComputer · 102d ago Puzzle: Set of PoC to abuse Windows minifilters functionality For [Blue|Purple] Teams in Cyber Defence · 102d ago Ai Didn’t Break Cybersecurity, It Revealed It Cyber Defense Magazine · 102d ago Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate) cybersecurity · 102d ago Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate) Technical Information Security Content & Discussion · 102d ago Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you! Reverse Engineering · 102d ago built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4) hacking: security in practice · 102d ago Credential Dumping: Local Security Authority (LSA|LSASS.EXE) cybersecurity · 102d ago A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16 For [Blue|Purple] Teams in Cyber Defence · 102d ago Dump sql time based is too slow hacking: security in practice · 102d ago Trojan:Win32/Cerdigent.A!dha cybersecurity · 102d ago Active exploitation of cPanel/WHM critical vulnerability For [Blue|Purple] Teams in Cyber Defence · 102d ago Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. " For [Blue|Purple] Teams in Cyber Defence · 102d ago MDE flagging digi cert certificate as malicious everywhere ? cybersecurity · 102d ago North Korea rejects US cybercrime claims as 'absurd slander' hacking: security in practice · 102d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Reverse Engineering · 102d ago 5 Qilin ransomware servers exposed over 7 months For [Blue|Purple] Teams in Cyber Defence · 102d ago is credential stuffing using openbullet2 dead in 2026? hacking: security in practice · 102d ago Anyone wanna learn the CEH or OSCP red teaming free Malware Analysis & Reports · 102d ago South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) For [Blue|Purple] Teams in Cyber Defence · 102d ago Russian Charged in Oil and Gas Facility Hacks Pleads Guilty For [Blue|Purple] Teams in Cyber Defence · 102d ago Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax) hacking: security in practice · 102d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks BleepingComputer · 102d ago How to build .NET obfuscator - Part II Reverse Engineering · 102d ago VECT ransomware: small files decrypt, large files lose their nonces For [Blue|Purple] Teams in Cyber Defence · 102d ago CTO at NCSC Summary: week ending May 3rd For [Blue|Purple] Teams in Cyber Defence · 102d ago April 27th - What happened with our feature flag configuration | The ClickUp Blog For [Blue|Purple] Teams in Cyber Defence · 102d ago Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT) hacking: security in practice · 103d ago How to exfiltrate data using only numeric outputs Technical Information Security Content & Discussion · 103d ago ConsentFix v3 attacks target Azure with automated OAuth abuse BleepingComputer · 103d ago libghidra - SDK for automating Ghidra from Python, Rust, and C++ Reverse Engineering · 103d ago Blog: Evolving the Android & Chrome VRPs for the AI Era For [Blue|Purple] Teams in Cyber Defence · 103d ago Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis. Reverse Engineering · 103d ago RSAC 2026: The Power of Community Cyber Defense Magazine · 103d ago Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed. For [Blue|Purple] Teams in Cyber Defence · 103d ago VECT: Ransomware by design, Wiper by accident For [Blue|Purple] Teams in Cyber Defence · 103d ago VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built. For [Blue|Purple] Teams in Cyber Defence · 103d ago Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 103d ago Agentic Malware Analysis: From Task Automation to Deep Analysis For [Blue|Purple] Teams in Cyber Defence · 103d ago pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner. For [Blue|Purple] Teams in Cyber Defence · 103d ago month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only For [Blue|Purple] Teams in Cyber Defence · 103d ago Microsoft tests modern Windows Run, says it's faster than legacy dialog BleepingComputer · 103d ago Edu tech firm Instructure discloses cyber incident, probes impact BleepingComputer · 103d ago For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall. Technical Information Security Content & Discussion · 103d ago Small models are better at cost-to-recall than large models like Mythos for vulnerability research hacking: security in practice · 103d ago Every incident public companies have disclosed to the SEC, in one searchable database Technical Information Security Content & Discussion · 103d ago 76% of All Crypto Stolen in 2026 Is Now in North Korea darkreading · 103d ago Bluetooth Spoofed Disconnect? hacking: security in practice · 103d ago Why my macOS Messages badge lied to me (and the one-line fix) Reverse Engineering · 103d ago 15-year-old detained over French govt agency data breach BleepingComputer · 103d ago Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself Malware Analysis & Reports · 104d ago Story retracted BleepingComputer · 104d ago Running Adobe’s 1991 PostScript Interpreter in the Browser Reverse Engineering · 104d ago Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :) Reverse Engineering · 104d ago If AI's So Smart, Why Does It Keep Deleting Production Databases? darkreading · 104d ago Minecraft Malware C2 Tracking Malware Analysis & Reports · 104d ago Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations BleepingComputer · 104d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 104d ago Inside RSAC 2026 Cyber Defense Magazine · 104d ago Microsoft fixes Remote Desktop warnings displaying incorrectly BleepingComputer · 104d ago Name That Toon: Mark of (Security) Progress darkreading · 104d ago 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage darkreading · 104d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 104d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 104d ago Careful Adoption of Agentic AI Services All CISA Advisories · 104d ago Microsoft now lets admins choose pre-installed Store apps to uninstall BleepingComputer · 104d ago wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ... hacking: security in practice · 104d ago Windows 11 KB5083631 update released with 34 changes and fixes BleepingComputer · 104d ago Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster Technical Information Security Content & Discussion · 104d ago US ransomware negotiators get 4 years in prison over BlackCat attacks BleepingComputer · 104d ago /r/ReverseEngineering's Triannual Hiring Thread Reverse Engineering · 104d ago In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off) Reverse Engineering · 104d ago TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack darkreading · 104d ago 🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀 hacking: security in practice · 104d ago Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug darkreading · 104d ago Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber darkreading · 104d ago New Bluekit phishing service includes an AI assistant, 40 templates BleepingComputer · 104d ago Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM Security | Microsoft Azure Blog | Microsoft Azure · 104d ago Innovator Spotlight: The Open Group Cyber Defense Magazine · 104d ago Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight Reverse Engineering · 105d ago SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents The Last Watchdog · 105d ago I made a lightweight breach intelligence search engine (fully client-side) looking for feedback hacking: security in practice · 105d ago Oracle Red Bull Racing Team Revs Up Automation to Boost Security darkreading · 105d ago Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan... hacking: security in practice · 105d ago Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark Cyber Defense Magazine · 105d ago Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool hacking: security in practice · 105d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 105d ago ABB AWIN Gateways All CISA Advisories · 105d ago ABB Ability OPTIMAX All CISA Advisories · 105d ago ABB PCM600 All CISA Advisories · 105d ago ABB Edgenius Management Portal All CISA Advisories · 105d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 105d ago ABB Ability Symphony Plus Engineering All CISA Advisories · 105d ago ABB System 800xA, Symphony Plus IEC 61850 All CISA Advisories · 105d ago Seventeen vulnerabilities in Omi, fourteen days of silence Technical Information Security Content & Discussion · 105d ago High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940) Technical Information Security Content & Discussion · 105d ago This month in security with Tony Anscombe – April 2026 edition WeLiveSecurity · 105d ago HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try! Reverse Engineering · 105d ago GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter). Reverse Engineering · 105d ago Copy Fail — 732 Bytes to Root hacking: security in practice · 105d ago ZDI-CAN-30796: Docker ZDI: Upcoming Advisories · 105d ago Claude Mythos Fears Startle Japan's Financial Services Sector darkreading · 105d ago Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root Technical Information Security Content & Discussion · 105d ago Reverse Engineering With AI Unearths High-Severity GitHub Bug darkreading · 105d ago AI Finds 38 Security Flaws in Electronic Health Record Platform darkreading · 105d ago The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs Technical Information Security Content & Discussion · 105d ago The Thymeleaf Template Injection That Only Hurts If You Let It Technical Information Security Content & Discussion · 106d ago Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error darkreading · 106d ago GitHub fixes RCE flaw that gave access to millions of private repos hacking: security in practice · 106d ago Minirat malware deployed via NPM targeting macOS machines Malware Analysis & Reports · 106d ago Set up automated dependency scanning after the recent npm/PyPI supply chain attacks Technical Information Security Content & Discussion · 106d ago Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints Cyber Defense Magazine · 106d ago Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities darkreading · 106d ago I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway Reverse Engineering · 106d ago Adapting Zero Trust Principles to Operational Technology All CISA Advisories · 106d ago How to download Kaggle dataset safely...? hacking: security in practice · 106d ago VECT Ransomware Is Actually a Wiper Malware Analysis & Reports · 106d ago VECT Ransomware Is Actually a Wiper hacking: security in practice · 106d ago The Malware Factory: GLASSWORM Forensics in Open VSX Malware Analysis & Reports · 106d ago A Route to Root in a 4G Industrial Router Technical Information Security Content & Discussion · 106d ago BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures darkreading · 106d ago NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later darkreading · 106d ago Feuding Ransomware Groups Leak Each Other's Data darkreading · 106d ago Vidar Rises to Top of Chaotic Infostealer Market darkreading · 106d ago Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore Malware Analysis & Reports · 106d ago Innovator Spotlight: Puneet Bhatnagar Cyber Defense Magazine · 106d ago Flipper Blackhat April Roundup! hacking: security in practice · 106d ago Building a perfect clone of 1993 game SimTower (via RE) Reverse Engineering · 106d ago [ Removed by Reddit ] Malware Analysis & Reports · 107d ago [VulnPath Update] Automated Email Alerting & CISA KEV Feed hacking: security in practice · 107d ago Ikeja Electric Distribution Ransomware Malware Analysis & Reports · 107d ago Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain darkreading · 107d ago [Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses) Technical Information Security Content & Discussion · 107d ago How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema Reverse Engineering · 107d ago AI solved our CTF in 6min Reverse Engineering · 107d ago The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords Technical Information Security Content & Discussion · 107d ago Cybersecurity Risks in 2026 Cyber Defense Magazine · 107d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 107d ago NSA GRASSMARLIN All CISA Advisories · 107d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 107d ago Recently updated a authentic minecraft mod launcher called Modrinth Malware Analysis & Reports · 107d ago GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control The Last Watchdog · 107d ago 89 vulnerabilities in XAPI / Citrix XenServer Technical Information Security Content & Discussion · 107d ago Example structure for evidence-based vulnerability reports Reverse Engineering · 107d ago Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters Cyber Defense Magazine · 107d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 107d ago UNC6692 Combines Social Engineering, Malware, Cloud Abuse darkreading · 107d ago Innovator Spotlight: TokenCore Cyber Defense Magazine · 107d ago Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025) Technical Information Security Content & Discussion · 107d ago Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary Technical Information Security Content & Discussion · 108d ago This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0 Malware Analysis & Reports · 108d ago Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation darkreading · 108d ago FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures The Last Watchdog · 108d ago Platform Engineering: The Rise of a Disciplinary Rethink Cyber Defense Magazine · 108d ago Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely Malware Analysis & Reports · 108d ago 60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea? Cyber Defense Magazine · 108d ago MCPwned: a Burp Suite extension for auditing MCP servers Technical Information Security Content & Discussion · 108d ago From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense Cyber Defense Magazine · 109d ago New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses Malware Analysis & Reports · 109d ago HackTheBox - Sorcery IppSec · 110d ago Save time and use Zig to write your Malware POC Malware Analysis & Reports · 110d ago Cracking CastleLoader’s Inno Setup Password Malware Analysis & Reports · 110d ago I built a C2 framework that uses Discord and Telegram for communication Malware Analysis & Reports · 110d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog Alerts · 111d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog All CISA Advisories · 111d ago The calm before the ransom: What you see is not all there is WeLiveSecurity · 111d ago fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet. Malware Analysis & Reports · 111d ago Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet Malware Analysis & Reports · 111d ago PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs Malware Analysis & Reports · 111d ago Budgiekit - gdi malware maker (for educational purporses only) Malware Analysis & Reports · 112d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 112d ago SpiceJet Online Booking System All CISA Advisories · 112d ago Carlson Software VASCO-B GNSS Receiver All CISA Advisories · 112d ago Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera All CISA Advisories · 112d ago Milesight Cameras All CISA Advisories · 112d ago Defending Against China-Nexus Covert Networks of Compromised Devices All CISA Advisories · 112d ago Yadea T5 Electric Bicycle All CISA Advisories · 112d ago Intrado 911 Emergency Gateway (EGW) All CISA Advisories · 112d ago GopherWhisper: A burrow full of malware WeLiveSecurity · 112d ago News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category The Last Watchdog · 113d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 113d ago 19 confirmed repos tied to the same GitHub malware campaign Malware Analysis & Reports · 113d ago Defending Against China-Nexus Covert Networks of Compromised Devices CISA Cybersecurity Advisories · 114d ago IOCX v0.7.0 — deterministic heuristics + adversarial PE samples Malware Analysis & Reports · 114d ago New NGate variant hides in a trojanized NFC payment app WeLiveSecurity · 114d ago Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one The Last Watchdog · 115d ago Supply Chain Compromise Impacts Axios Node Package Manager Alerts · 115d ago CISA Adds Eight Known Exploited Vulnerabilities to Catalog Alerts · 115d ago What the ransom note won’t say WeLiveSecurity · 115d ago That data breach alert might be a trap WeLiveSecurity · 118d ago Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business Blog Articles - Identity Insights | Trulioo · 118d ago Supply chain dependencies: Have you checked your blind spot? WeLiveSecurity · 119d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 119d ago News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security The Last Watchdog · 119d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 121d ago GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags The Last Watchdog · 121d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 122d ago Recovery scammers hit you when you’re down: Here’s how to avoid a second strike WeLiveSecurity · 125d ago News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk The Last Watchdog · 125d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 127d ago FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense The Last Watchdog · 128d ago As breakout time accelerates, prevention-first cybersecurity takes center stage WeLiveSecurity · 128d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 129d ago Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure CISA Cybersecurity Advisories · 129d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 133d ago Azure IaaS: Keep critical applications running with built-in resiliency at scale Security | Microsoft Azure Blog | Microsoft Azure · 134d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 134d ago Digital assets after death: Managing risks to your loved one’s digital estate WeLiveSecurity · 134d ago This month in security with Tony Anscombe – March 2026 edition WeLiveSecurity · 135d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 136d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 139d ago RSAC 2026 wrap-up – Week in security with Tony Anscombe WeLiveSecurity · 139d ago A cunning predator: How Silver Fox preys on Japanese firms this tax season WeLiveSecurity · 139d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 140d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 141d ago Virtual machines, virtually everywhere – and with real security gaps WeLiveSecurity · 141d ago Cloud workload security: Mind the gaps WeLiveSecurity · 142d ago What is Customer Due Diligence (CDD) Blog Articles - Identity Insights | Trulioo · 142d ago Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud Blog Articles - Identity Insights | Trulioo · 145d ago CISA Adds Five Known Exploited Vulnerabilities to Catalog Alerts · 146d ago Move fast and save things: A quick guide to recovering a hacked account WeLiveSecurity · 146d ago EDR killers explained: Beyond the drivers WeLiveSecurity · 147d ago Face value: What it takes to fool facial recognition WeLiveSecurity · 153d ago Cyber fallout from the Iran war: What to have on your radar WeLiveSecurity · 154d ago AML, KYC and Identity Verification in Australia Blog Articles - Identity Insights | Trulioo · 154d ago SSL/TLS Certificate Lifespans Are Decreasing to 200 Days InfoSec Insights · 155d ago AI in Tax Season: Risks, Scams, and How to Protect Your Data Fraud Prevention Archives - Alloy Silverstein · 161d ago Security-driven Rapid Release - Pwn2Own Documentary (Part 4) LiveOverflow · 161d ago Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure Security | Microsoft Azure Blog | Microsoft Azure · 162d ago Firefox JIT Bug - Pwn2Own Documentary (Part 3) LiveOverflow · 164d ago Tax Season Scams to Watch For This Year Fraud Prevention Archives - Alloy Silverstein · 168d ago The First Exploit - Pwn2Own Documentary (Part 2) LiveOverflow · 168d ago The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1) LiveOverflow · 171d ago I built a kernel-level EDR and hit architectural walls I didn’t expect Malware Analysis & Reports · 175d ago Update your detection rules: New remote access Trojan Malware Analysis & Reports · 176d ago Criminals are using AI website builders to clone major brands Malware Analysis & Reports · 176d ago Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants) Malware Analysis & Reports · 176d ago Azure reliability, resiliency, and recoverability: Build continuity by design Security | Microsoft Azure Blog | Microsoft Azure · 177d ago PE Loader For Fileless Malware Malware Analysis & Reports · 177d ago Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers Malware Analysis & Reports · 177d ago AWAKE - Android Wiki of Attacks, Knowledge & Exploits Malware Analysis & Reports · 177d ago I built a Chrome extension that scans for malicious extensions (yes, I see the irony) Malware Analysis & Reports · 177d ago Questions regarding malicious pdf's Malware Analysis & Reports · 179d ago AV persistence bypass techniques Malware Analysis & Reports · 180d ago Avalon Linux Bot Malware Analysis Malware Analysis & Reports · 181d ago Leveling up in Windows malware research Malware Analysis & Reports · 182d ago Emerging Ransomware: BQTLock and GREENBLOOD Malware Analysis & Reports · 183d ago Malware Development POCs Malware Analysis & Reports · 183d ago Suspicious code in Up-work linked repository. Malware Analysis & Reports · 183d ago We hid backdoors in binaries — Opus 4.6 found 49% of them Malware Analysis & Reports · 184d ago 👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡 Malware Analysis & Reports · 185d ago Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions Malware Analysis & Reports · 185d ago Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer Malware Analysis & Reports · 186d ago Nyxara Malware Analysis & Reports · 189d ago When Fraud Becomes Background Noise: The Industrialization of Digital Deception Blog Articles - Identity Insights | Trulioo · 220d ago The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage Blog Articles - Identity Insights | Trulioo · 220d ago The End of Static KYB: Business Identity in Constant Motion Blog Articles - Identity Insights | Trulioo · 220d ago Know Your Agent: The Next Chapter in Digital Trust Blog Articles - Identity Insights | Trulioo · 220d ago When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage Blog Articles - Identity Insights | Trulioo · 220d ago Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration Blog Articles - Identity Insights | Trulioo · 239d ago Beware of Misleading Tax Advice on Social Media Fraud Prevention Archives - Alloy Silverstein · 336d ago Scammers Up Their Game With AI Fraud Prevention Archives - Alloy Silverstein · 337d ago Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs STÖK · 354d ago The Essential Guide to Safeguarding Your Online Passwords Fraud Prevention Archives - Alloy Silverstein · 415d ago How FIN6 Exfiltrates Files Over FTP HackerSploit · 491d ago From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi LiveOverflow · 491d ago The German Hacking Championship LiveOverflow · 517d ago Beware: Tax Season is Scam Season Fraud Prevention Archives - Alloy Silverstein · 526d ago Do you know this common Go vulnerability? LiveOverflow · 531d ago Stop Scams: Fraud Prevention Starts with Your Employees Fraud Prevention Archives - Alloy Silverstein · 539d ago Emulating FIN6 - Active Directory Enumeration Made EASY HackerSploit · 542d ago The SECRET to Embedding Metasploit Payloads in VBA Macros HackerSploit · 547d ago Offensive VBA 0x4 - Reverse Shell Macro with Powercat HackerSploit · 555d ago Offensive VBA 0x3 - Developing PowerShell Droppers HackerSploit · 561d ago Offensive VBA 0x2 - Program & Command Execution HackerSploit · 566d ago Offensive VBA 0x1 - Your First Macro HackerSploit · 568d ago Emulating FIN6 - Gaining Initial Access (Office Word Macro) HackerSploit · 573d ago FIN6 Adversary Emulation Plan (TTPs & Tooling) HackerSploit · 577d ago Developing An Adversary Emulation Plan HackerSploit · 577d ago Introduction To Advanced Persistent Threats (APTs) HackerSploit · 581d ago Introduction To Adversary Emulation HackerSploit · 603d ago ‘Tis the Season for Holiday Shopping Scams Fraud Prevention Archives - Alloy Silverstein · 612d ago Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion HackerSploit · 612d ago Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1) LiveOverflow · 666d ago My theory on how the webp 0day was discovered #short LiveOverflow · 682d ago My theory on how the webp 0day was discovered (BLASTPASS) LiveOverflow · 683d ago Learn Android Hacking! - University Nevada, Las Vegas (2024) LiveOverflow · 709d ago DEF CON & Black Hat Trip 2024 LiveOverflow · 723d ago Planning Red Team Operations | Scope, ROE & Reporting HackerSploit · 752d ago Mapping APT TTPs With MITRE ATT&CK Navigator HackerSploit · 756d ago IRS Issues “Dirty Dozen” Fraud Warnings Fraud Prevention Archives - Alloy Silverstein · 797d ago IRS Identity Theft Season Begins Now Fraud Prevention Archives - Alloy Silverstein · 926d ago Finding The .webp Vulnerability in 8s (Fuzzing with AFL++) LiveOverflow · 934d ago Winter vanlife = good times STÖK · 956d ago What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth! STÖK · 962d ago Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma STÖK · 969d ago IS THIS THE END? STÖK · 1029d ago Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites STÖK · 1183d ago The World’s Identity Platform Blog Articles - Identity Insights | Trulioo · 1290d ago How to turn bugs into a "passive" income stream! ft Detectify's Almroot STÖK · 1424d ago HOW DID THIS HAPPEN!? (13370822 LHE VLOG) STÖK · 1437d ago Student Loan Breach Exposes 2.5M Records Threatpost · 1443d ago Watering Hole Attacks Push ScanBox Keylogger Threatpost · 1444d ago Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms Threatpost · 1445d ago Ransomware Attacks are on the Rise Threatpost · 1448d ago Cybercriminals Are Selling Access to Chinese Surveillance Cameras Threatpost · 1448d ago Twitter Whistleblower Complaint: The TL;DR Version Threatpost · 1450d ago Firewall Bug Under Active Attack Triggers CISA Warning Threatpost · 1451d ago Fake Reservation Links Prey on Weary Travelers Threatpost · 1452d ago iPhone Users Urged to Update to Patch 2 Zero-Days Threatpost · 1455d ago Google Patches Chrome’s Fifth Zero-Day of the Year Threatpost · 1456d ago Q: How to write a BUG BOUNTY report that actually gets paid? STÖK · 1554d ago KYC: 3 Steps to Achieving Know Your Customer Compliance Blog Articles - Identity Insights | Trulioo · 1561d ago facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques.. STÖK · 1568d ago AML Compliance Checklist: Best Practices for Anti-Money Laundering Blog Articles - Identity Insights | Trulioo · 1576d ago Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!) STÖK · 1582d ago Q: HOW do you get started in bug bounty?? How do you build your automation?! STÖK · 1596d ago Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR) STÖK · 1610d ago
Latest
The Record from Recorded Future NewsFlock tightens privacy controls amid scandals over officer abuseLatest newsThis Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on saleThe Record from Recorded Future NewsNew Mirai variant adds stealth capabilities to notorious botnet codeLatest newsI wore Samsung's and Apple's Ultra smartwatches for 3 weeks - apps made all the differenceLatest newsYou're using DND all wrong: 5 powerful Do Not Disturb settings to try on your iPhone todayBleepingComputerTrezor discloses data breach affecting nearly 14,000 customersSecurityWeekCybersecurity M&A Roundup: 21 Deals Announced in July 2026Help Net SecurityWhite House authorizes private US companies to hack foreign criminal networksSecurityWeekAdobe Commerce Bug Targeted Immediately After DisclosureBlack HatBlack Hat Stories | Daniel CuthbertJohn HammondPhishing Gets PersonalBleepingComputerWho Vets AI’s Code? The Scale Challenge Facing Open Source IngestionMSRC Security Update GuideCVE-2026-61346 Windows Graphics Kernel Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-62695 Windows Storage Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-61359 Windows Storage Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-62913 Microsoft Exchange Server Remote Code Execution VulnerabilityMSRC Security Update GuideCVE-2026-65796 Windows iSCSI Target Service Denial of Service VulnerabilityMSRC Security Update GuideCVE-2026-62688 Windows MIDI Service Module Elevation of Privileges VulnerabilityMSRC Security Update GuideCVE-2026-62897 .NET Framework Remote Code Execution VulnerabilityThe Record from Recorded Future NewsFlock tightens privacy controls amid scandals over officer abuseLatest newsThis Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on saleThe Record from Recorded Future NewsNew Mirai variant adds stealth capabilities to notorious botnet codeLatest newsI wore Samsung's and Apple's Ultra smartwatches for 3 weeks - apps made all the differenceLatest newsYou're using DND all wrong: 5 powerful Do Not Disturb settings to try on your iPhone todayBleepingComputerTrezor discloses data breach affecting nearly 14,000 customersSecurityWeekCybersecurity M&A Roundup: 21 Deals Announced in July 2026Help Net SecurityWhite House authorizes private US companies to hack foreign criminal networksSecurityWeekAdobe Commerce Bug Targeted Immediately After DisclosureBlack HatBlack Hat Stories | Daniel CuthbertJohn HammondPhishing Gets PersonalBleepingComputerWho Vets AI’s Code? The Scale Challenge Facing Open Source IngestionMSRC Security Update GuideCVE-2026-61346 Windows Graphics Kernel Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-62695 Windows Storage Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-61359 Windows Storage Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege VulnerabilityMSRC Security Update GuideCVE-2026-62913 Microsoft Exchange Server Remote Code Execution VulnerabilityMSRC Security Update GuideCVE-2026-65796 Windows iSCSI Target Service Denial of Service VulnerabilityMSRC Security Update GuideCVE-2026-62688 Windows MIDI Service Module Elevation of Privileges VulnerabilityMSRC Security Update GuideCVE-2026-62897 .NET Framework Remote Code Execution Vulnerability
By Source
Feeds organized so you can skim by site.
Density
Sort
LN
Latest news
1h ago · 20 items
This Micro RGB TV rivals pricier OLED models - and I'd recommend it, especially on sale
1h ago
The Samsung R95H is built with an all-new Micro RGB panel that delivers truly impressive color and contrast. And right now at Best Buy, you can save up to $1,000 on one.
I wore Samsung's and Apple's Ultra smartwatches for 3 weeks - apps made all the difference
1h ago
The Apple Watch Ultra 3 and the Samsung Galaxy Watch Ultra 2 are top-tier rugged smartwatches with similar features, but one stands out.
You're using DND all wrong: 5 powerful Do Not Disturb settings to try on your iPhone today
1h ago
DND is so much more than a way to silence your phone.
Microsoft is merging Copilot and Copilot 365 into one unified app - and retiring 3 features
3h ago
The move should cut down on the confusion between the two apps, especially for anyone who bounces back and forth between the two of them.
75% of developers I surveyed prefer Claude Code - here's why they choose it over Codex
5h ago
Three out of four of the 138 developers I surveyed use Claude Code. Here's what they say matters in daily AI coding workflows.
Android can now tap to share for contact info, photos, and more - which phones get it first
5h ago
The process of sending someone a file or sharing your information on Android just got a lot simpler.
The best antivirus software to protect your computer in 2026
8h ago
Our favorite antivirus software protects your PC, laptop, and mobile devices from malware without costing a fortune.
The best password managers of 2026: Expert tested
8h ago
If you have trouble remembering the passwords for all of your online accounts, we've handpicked the best password manager apps to help you stay protected.
'Specialists aren't required' anymore: How to stay valuable in an AI agent workplace today
16h ago
Versatility is in, with people expected to work across the tech stack.
Every Amazon Google Pixel 11 preorder deal - get up to $350 on an Amazon gift card, free
23h ago
Google's latest lineup of Pixel 11 phones is here, and Amazon has a free gift card offer on every single one.
Sparky Linux just restored 32-bit support - why that still matters
23h ago
Hackers are hunting for your private photos, FBI warns: 6 ways to avoid a sextortion nightmare
1d ago
Every Pixel 11 deal at T-Mobile right now: Trade-in offers, free phones with new line, and more
1d ago
How to preorder every new Google Pixel device - and the best deals I found
1d ago
The Pixel Tag is Google's $29 AirTag alternative - with one big advantage
1d ago
The best Pixel 11 and Pixel 11 Pro cases of 2026: Expert recommended
1d ago
Microsoft fixes 421 bugs and a Windows zero-day in August Patch Tuesday - update ASAP
1d ago
Pixel Watch 4 vs. Pixel Watch 5: Buy the old Android smartwatch or opt for the newest?
1d ago
Google Pixel 11 vs. Pixel 9: Why the Pixel 11 is actually worth upgrading
1d ago
AT&T will give you the new Google Pixel 11 Pro for free with trade-in - any year, any condition
1d ago
20 loaded
BL
BleepingComputer
1h ago · 746 items
Trezor discloses data breach affecting nearly 14,000 customers
1h ago
Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping and logistics provider, was hacked
Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion
3h ago
AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations should govern packages at the point of selection, before they ent...
White House taps security firms for offensive hack-back operations
3h ago
A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations.
WhatsApp rolls out new feature that flags potential scam messages
5h ago
WhatsApp has begun rolling out a new optional
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
17h ago
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals.
Android malware combo takes out loans and relays victims' credit cards
18h ago
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
20h ago
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
Hundreds of fake Chrome VPN extensions route traffic through a proxy
22h ago
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider.
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
1d ago
Security researchers have disclosed new
Lazarus hackers exploited Windows zero-day to target defense firms
1d ago
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign.
FBI: Hackers target online accounts to steal nude photos
1d ago
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
1d ago
Hackers leverage new Microsoft SharePoint exploit in attacks
1d ago
Signal adds new security feature to thwart man-in-the-middle attacks
1d ago
New Microsoft Defender 'ShieldBreak' zero-day grants SYSTEM privileges
1d ago
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
1d ago
DeadLock ransomware uses blockchain to resist infrastructure takedown
1d ago
Sandworm hackers target IT pros with trojanized WireGuard VPN client
1d ago
Cisco warns of ASA and FTD VPN flaw exploited to crash devices
1d ago
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
1d ago
Microsoft releases Windows 10 KB5120249 extended security update
1d ago
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
1d ago
Windows 11 KB5121003 & KB5120240 cumulative updates released
1d ago
Wesco confirms security incident after ExfilSquad claims data theft
2d ago
Mozilla updates GPG signing key for Firefox releases after exposure
2d ago
Vague Task, Total Access: When AI Delegation Becomes a Security Risk
2d ago
DDoS attacks over 1 Tbps surged fivefold in the second quarter
2d ago
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
2d ago
Cisco warns of high-severity ClamAV flaws with public exploits
2d ago
US and South Korea warn of Gunra ransomware targeting govt agencies
2d ago
Hackers breached a small Polish energy plant via private APN last year
2d ago
BdThemes plugins supply-chain hack creates rogue WordPress admins
2d ago
OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users
2d ago
New StormEncryptor ransomware used by former Medusa affiliate
2d ago
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
3d ago
When Credentials Are No Longer Enough: Device Trust in the AI Era
3d ago
Member of The Com sent to prison for blackmail, sextortion
3d ago
LexisNexis shuts down services after suspicious activity on servers
3d ago
Valve notifies Steam hardware customers of a data breach
3d ago
Critical Progress LoadMaster flaw now actively exploited in attacks
3d ago
Hackers breach TrueConf to trojanize client installers with backdoors
5d ago
Metabase SQLi zero-day exploited in customer data-theft attacks
5d ago
Unlimited Technology Systems breach impacts 3.8 million people
5d ago
Levi Strauss & Co. says hackers stole corporate data in cyberattack
6d ago
Real emails, hijacked payments: Two H1 2026 attack chains
6d ago
North Carolina Ports confirms cyberattack disrupting operations
6d ago
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
6d ago
ClickFix attack pushes macOS infostealer for crypto theft attacks
6d ago
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
6d ago
Swiss government SharePoint breach compromised 200 accounts
6d ago
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
6d ago
Meta AI model hacked a company during misconfigured cyber test
7d ago
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
7d ago
Ransom Cartel ransomware creator sentenced to 16 years in prison
7d ago
Canadian pleads guilty to Snowflake cloud data-theft attacks
7d ago
Hackers run khunt post-exploitation toolkit from Oracle database
7d ago
COLDCARD security audit phishing attack installs remote access tool
7d ago
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
8d ago
Google Blogger locks hundreds of blogs in malware false positive
8d ago
How AI-powered phishing killed blocklists for good
8d ago
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
8d ago
TP-Link patches Omada ZTP flaws allowing hackers to breach networks
8d ago
Phishing service spoofs RingCentral to steal Microsoft 365 accounts
8d ago
New XCSSET variant targets macOS devs via compromised Xcode projects
8d ago
77 Open VSX extensions found harvesting developer info
8d ago
Massive ChainDrop npm supply-chain attack infects hundreds of packages
9d ago
Varonis Agent IBAC keeps AI agents within their intended boundaries
9d ago
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts
9d ago
New Pass-ta-key attacks let malware hijack Google-synced passkeys
9d ago
New DOUBLECUP ClickFix service hides malware in browser cache images
9d ago
Fake Roblox Xeno script launcher pushes infostealer, RAT malware
9d ago
N-able warns of N-central auth bypass flaw exploited in attacks
10d ago
ExfilSquad hackers leak info of over 100,000 UK police officers, staff
10d ago
Inside the Underground Business of the Android BTMOB RAT malware
10d ago
OpenAI teases Astra, its next major AI model, after it solves 10 long-standing math problems
10d ago
COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft
10d ago
Google Chrome may soon block New Tab hijacker extensions by default
11d ago
Rails patches critical Active Storage flaw with RCE potential
12d ago
Amgen says cloud data breach exposed patient health, proprietary info
12d ago
Arch Linux disables AUR package adoption to stop malware flood
12d ago
Online ad firm Adform’s script compromised to steal cryptocurrency
12d ago
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
12d ago
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
12d ago
CISA warns of cyberattacks disrupting U.S. water utilities
13d ago
ESET tracks rise in malicious AI skills and adaptable malware
13d ago
Anthropic's Claude breached 3 orgs, uploaded PyPI malware during tests
13d ago
South Korea fines telco giant KT $39 million for customer data breach
13d ago
JetBrains warns of critical TeamCity remote code execution flaw
13d ago
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
13d ago
VMware fixes three critical flaws allowing auth bypass, VM escapes
13d ago
Google says AI helped Chrome fix 1,072 security bugs in two releases
14d ago
ShinyHunters claims Brinks Home breach, threatens to leak stolen data
14d ago
Microsoft Teams vishing attacks lead to Chaos ransomware attacks
14d ago
Analog Devices discloses data breach, says operations unaffected
14d ago
After the Break-In: What Attackers Do Once They're Already Inside
14d ago
Russian hackers exploit Exchange OWA zero-day for long-term mailbox access
14d ago
Cisco warns of FMC static credential flaw exploited in zero-day attacks
14d ago
Anthropic confirms Claude is down worldwide
14d ago
Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare
14d ago
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
15d ago
Hackers target over 30 Minnesota water utilities in coordinated OT attack
15d ago
Your AI Agents Are Guessing at Scale: Permissions Decide the Damage
15d ago
Windows 11 KB5101684 update released with 42 changes and fixes
15d ago
These near-mint ASUS Chromebook refurbs are only $145
15d ago
CubePilot drone software dev hit by DNS hijacking to intercept traffic
15d ago
OpenAI models used Artifactory zero-days to escape to the internet
15d ago
CISA shares advice on isolating vital systems during cyberattacks
15d ago
vBulletin fixes critical pre-auth RCE flaw with public exploit
15d ago
Is Your SSO Protected Against Modern Credential Attacks?
16d ago
Over 24,000 exposed server BMCs leak password hash via decades-old flaw
16d ago
Data breach at medical billing firm MCBS affects 1.26 million people
16d ago
Hackers target US firms in FastJson RCE zero-day attacks
16d ago
Arista patches VeloCloud Orchestrator zero-day exploited in attacks
16d ago
New Dysphoria DDoS botnet spreads to 200k devices worldwide
16d ago
New Certighost PoC exploit lets attackers hijack Windows domains
16d ago
Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin
16d ago
Coca-Cola confirms data theft in Fairlife ransomware attack
17d ago
Ernst & Young data breach claimed by ShinyHunters extortion gang
17d ago
Shadow AI agents are multiplying. Here's how to find and secure them.
17d ago
GitHub, PyPI add time-absed defenses against supply chain attacks
18d ago
Steam forum ClickFix attacks infect gamers with XMRig cryptominers
18d ago
Malicious sites use JavaScript to build malware in browser memory
19d ago
ShinyHunters data leaks fuel $2,000 sextortion email scam
19d ago
OpenAI confirms ChatGPT is down worldwide
19d ago
OnTrac notifies customers of data breach after network hack
19d ago
Hermes AI agent used to automate attack on Thai Finance Ministry
19d ago
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
19d ago
Microsoft blames massive Microsoft 365 outage on maintenance bug
20d ago
Chick-fil-A data breach affects more than 13,000 customers
20d ago
Slopsquatting, Phantom Domains, and HalluSquatting Are the Same AI Attack
20d ago
Europol flags 4,340 URLs for removal in 'The Com' crackdown
20d ago
Man gets six years for hacking 750 women's Snapchat accounts
20d ago
Clop ransomware targets Windchill, FlexPLM in data theft attacks
20d ago
New Dolphin X malware uses AI to rank high-value targets
20d ago
Australian energy provider Origin says data breach exposes client data
20d ago
Fake Claude app promoted by Bing ads pushes SectopRAT malware
20d ago
Russian hackers exploit Zimbra zero-click flaw for email theft
21d ago
Hackers abuse Notepad++ plugins to stealthily install malware
21d ago
Microsoft 365 outage affects Teams, SharePoint and other services
21d ago
FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires
21d ago
EU fines Google $1 billion for search, app store antitrust violations
21d ago
New RefluXFS Linux flaw lets attackers gain root privileges
21d ago
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
21d ago
Microsoft working to fix Exchange Online mailbox quarantine issue
21d ago
Check Point warns of SmartConsole zero-day exploited in attacks
21d ago
Upbound says hack caused $13 million in fraudulent Acima leases
21d ago
South Korea discloses data breach impacting diplomats worldwide
21d ago
Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack
22d ago
How enterprise GenAI can amplify ransomware risk — and how to contain it
22d ago
New InfraTrust report reveals infrastructure flaws admins should patch first
22d ago
Adobe Chrome extension flaw let sites access private WhatsApp chats
22d ago
CISA orders urgent action on actively exploited Langflow RCE flaw
22d ago
Stop renting storage space — this lifetime 2TB plan is yours for $59
22d ago
Microsoft to stop Exchange 2016 / 2019 security updates in October
22d ago
Chick-fil-A discloses data breach after credential stuffing attacks
22d ago
OpenAI says its AI models hacked Hugging Face during testing
22d ago
Police dismantle Kratos phishing platform, arrest developer
22d ago
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
22d ago
Critical SharePoint RCE flaw exploited to steal machine keys
22d ago
Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak
22d ago
Critical wp2shell WordPress flaws exploited to install webshells
23d ago
Closing the Identity Gaps in Critical Infrastructure Security
23d ago
US seizes over 1,000 websites in FIFA World Cup piracy crackdown
23d ago
Critical Palo Alto VPN bug now exploited by Qilin ransomware gang
23d ago
Microsoft shares manual fix for WSUS sync delays and timeouts
23d ago
Windows LegacyHive zero-day flaw gets free, unofficial patches
23d ago
Estée Lauder discloses data breach via Oracle E-Business flaw
23d ago
SonicWall SMA1000 flaws exploited as zero-days to push custom malware
23d ago
Hackers steal $23.7 million in crypto from Ostium in off-chain attack
23d ago
Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes
23d ago
JadePuffer agentic attacks now target AI model data with ransomware
23d ago
New HollowGraph malware uses Microsoft Graph for stealthy C2 comms
23d ago
An AI SOC Evaluation Guide for Security Leaders
24d ago
Hugging Face discloses breach linked to autonomous AI agent
24d ago
Microsoft confirms Windows Server Update Services sync delays
24d ago
Windows KB5121767 OOB update fixes shutdowns on some Dell PCs
24d ago
Critical ServiceNow code execution flaw now exploited in attacks
24d ago
Hackers abuse ViPNet software to target Russian govt agencies
25d ago
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
25d ago
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
25d ago
Microsoft warns of surge in ACR Stealer attacks on customers
26d ago
The Future of Age Verification: Your Face Never Leaves Your Device
26d ago
Abbott Laboratories probes two cyber incidents amid extortion claims
26d ago
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
26d ago
Ernst & Young discloses data breach after support system hack
27d ago
Inside the Search for "Clean" Residential Proxies for Carding
27d ago
New Windows LegacyHive zero-day gives hackers admin privileges
27d ago
Windows Server 2022 reach end of mainstream support in 90 days
27d ago
US charges two over laundering $43 million from investment fraud
27d ago
CISA urges immediate action on actively exploited Fortinet flaws
27d ago
New ClickLock macOS malware traps users into revealing login password
27d ago
Coca-Cola says Fairlife ransomware attack halts US dairy production
27d ago
Claude Chrome extension flaw lets malicious extensions trigger AI actions
27d ago
New OkoBot framework deploys 20 payloads to steal data, crypto
27d ago
AI Agents Broke the Security Playbook. Here's What Replaces It.
28d ago
23andMe to pay $18 million in new genetics data breach settlement
28d ago
Scattered Spider members behind TfL hack get five years in prison
28d ago
Windows 11 24H2 Home and Pro reach end of support in 90 days
28d ago
CISA orders feds to patch actively exploited Oracle flaw by Saturday
28d ago
Russian hackers trojanize WebEx, Zoom apps to push Starland malware
28d ago
New Spirals ransomware encrypts victim network in under 24 hours
28d ago
Dutch police bust investment fraud ring stealing over €100 million
28d ago
Zoom warns of critical account takeover vulnerability
28d ago
Google Gemini CLI abused as a hacking agent, malware botnet operator
28d ago
AsyncAPI npm packages infected with credential-stealing malware
29d ago
We built a vulnerability vending machine: AI tokens in, zero-days out
29d ago
CISA warns admins to patch actively exploited SharePoint flaws
29d ago
Microsoft: Some Dell PCs shut down after recent Windows updates
29d ago
US charges alleged operators of Russian bulletproof hosting service
29d ago
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
29d ago
Spanish Police take down €140 million cyber fraud ring, arrest four
29d ago
Nearly 300 GitHub repos pose as legit software to push malware
29d ago
Microsoft releases Windows 10 KB5099539 extended security update
29d ago
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
29d ago
Windows 11 KB5101650 & KB5099414 cumulative updates released
29d ago
Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown
30d ago
LastPass, Bitwarden users targeted with fake security alerts
30d ago
You Don't Have to Run an Exploit to Know If You're Vulnerable
30d ago
Microsoft Entra ID gets passkeys default authentication starting September
30d ago
New phishing kits target Microsoft 365 accounts, evade MFA
30d ago
SAP warns of critical flaws in NetWeaver and Commerce Cloud
30d ago
Microsoft starts testing cleaner Windows Search without ads
30d ago
US sanctions VPN, malware providers for enabling ransomware attacks
30d ago
Japan's largest taxi operator shuts systems after cyberattack
30d ago
Hackers backdoor Jscrambler npm package with infostealer malware
30d ago
New CrashStealer malware poses as Apple crash reporting tool
30d ago
CISA warns of actively exploited RCE flaws in Joomla extensions
31d ago
Lidl discloses online shop breach after service provider hack
31d ago
Breach at the Beach: Play the Ultimate Entra ID CTF
31d ago
UK charges suspects linked to Russian Coms call spoofing platform
31d ago
EU sanctions Russian GRU military hackers over cyberattacks
31d ago
US and allies warn of Russian critical infrastructure attacks
31d ago
OpenAI temporarily relaxes GPT-5.6 Sol usage limits
31d ago
Claude Fable 5 stays free for paid users until July 19 as Anthropic buys more time
31d ago
RedHook Android malware now uses Wireless ADB for shell access
32d ago
Australia warns of global campaign targeting vulnerable CMS platforms
33d ago
'Ghostcommit' hides prompt injection in images to fool AI agents, steal secrets
33d ago
New U-Boot flaws could enable stealthy firmware attacks
33d ago
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
33d ago
Police suspects Dutch hackers were involved in Odido breach
34d ago
Progress urges ShareFile admins to shut down servers over “credible” threat
34d ago
Hackers exploit critical auth bypass in Gitea Docker image
34d ago
Money launderer accused of stealing seized crypto while in prison
34d ago
The Replicant in Your Directory: AI Agents and the Identity Security Gap
34d ago
Zimbra urges customers to patch critical web client XSS flaw
34d ago
Former ransomware negotiator gets 4 years for BlackCat attacks
34d ago
OpenMandriva Linux says contributor tried to sabotage the project
34d ago
Injective SDK on npm infected with cryptocurrency wallet stealer
34d ago
New Helix vishing group emerges in SharePoint data theft attacks
34d ago
Microsoft expects more Windows security updates from AI-discovered flaws
35d ago
New Forg365 phishing platform uses AI to target Microsoft 365 accounts
35d ago
The Hidden Security Risks of Reduced Summer IT Coverage
35d ago
Microsoft to retire the OWA Light client in Exchange Server
35d ago
Police arrests 5,800 suspects in global anti-fraud crackdown
35d ago
AssuranceAmerica data breach exposes records of 6.9 million drivers
35d ago
Microsoft patches RoguePlanet Defender zero-day vulnerability
35d ago
Mount Royal University confirms breach as hackers claim attack
35d ago
Fake Paysafe, Skrill SDKs on NPM and PyPi steal credentials
35d ago
Hackers exploit Roundcube flaw to spy on academic researchers
35d ago
Entra passkey enrollment vishing targets Microsoft 365 users
36d ago
3 Ways AI Powers Service Desk Attacks and How to Prevent Them
36d ago
DuckDuckGo browser now blocks YouTube video ads
36d ago
Telco giant KDDI says data breach affects over 12 million people
36d ago
CISA orders feds to prioritize patching Langflow auth bypass flaw
36d ago
Ubiquiti warns of new max severity UniFi OS vulnerability
36d ago
CISA orders feds to patch max severity ColdFusion flaw by Friday
36d ago
Accenture confirms breach after hacker offers stolen data for sale
36d ago
Chinese hackers develop LONGLEASH malware to expand ORB network
36d ago
Hidden backdoor in Tenda router firmware grants admin access
36d ago
Spain arrests suspected member of pro-Russian hacktivist groups
37d ago
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
37d ago
Webinar tomorrow: Why modern email attacks require a new approach to defense
37d ago
New Januscape Linux flaw allows VM escape on Intel, AMD devices
37d ago
Microsoft to enable Windows settings backup by default for orgs
37d ago
BeyondTrust warns of critical flaws in remote access software
37d ago
Microsoft testing new Cloud Rebuild Windows 11 recovery feature
37d ago
Phishing poses as big-brand job interview to steal Google accounts
37d ago
Fake IT support calls on Microsoft Teams push EtherRAT malware
37d ago
Vietnam arrests suspects behind HiAnime anime piracy service
37d ago
Software Is Now Written at the Speed of Thought. Security Isn't.
38d ago
Max severity Adobe ColdFusion flaw now exploited in attacks
38d ago
Flipper Zero firmware development continues with community help
39d ago
JadePuffer ransomware used AI agent to automate entire attack
40d ago
NetNut proxy network disrupted, 2 million infected devices cut off
40d ago
ARToken PhaaS exposes EvilTokens' Microsoft 365 phishing toolkit
41d ago
Claude Fable 5 isn’t permanently leaving subscriptions, Anthropic says
41d ago
Claude Fable relaunch disappoints users with nerfed performance
41d ago
Google loses final appeal to overturn €4.1 billion EU fine
42d ago
ConsentFix and ClickFix: How Microsoft 365 Accounts are Hijacked in 3 Seconds
42d ago
Microsoft fixes bug that removed Copilot buttons in Outlook
42d ago
Cisco finally confirms attackers exploiting Unified CM flaw
42d ago
CISA: Microsoft SharePoint RCE flaw now actively exploited
42d ago
Opera rolls out Paste Protect feature to fight ClickFix attacks
42d ago
Alleged Scattered Spider hacker extradited to the United States
42d ago
Medtronic notifies customers impacted by ShinyHunters data breach
42d ago
FortiBleed credential-theft campaign linked to Lynx ransomware
42d ago
Kubota says hackers had month-long access to network systems
42d ago
ChocoPoc malware delivered via trojanized exploits on GitHub
42d ago
New ChocoPoC malware targets researchers via trojanized PoC exploits
42d ago
DHS confirms hackers breached HSIN info-sharing platform
42d ago
Webinar: Why traditional email security is no longer enough
43d ago
Hackers target Microsoft 365 accounts with 81 million login attempts
43d ago
Turning Indicators into Intelligence in OpenCTI with Criminal IP
43d ago
Over 900 Oracle E-Business instances exposed to ongoing attacks
43d ago
Microsoft fixes GIF functionality in the Windows Emoji Panel
43d ago
Amazon fined $2.25M for withholding evidence from fraud victims
43d ago
Adobe patches seven max severity ColdFusion, Campaign flaws
43d ago
Anthropic to restore Claude Fable access on Wednesday
43d ago
Anthropic rolls out Sonnet 5 with near-Opus 4.8 performance at a lower price
43d ago
New BioShocking attack manipulates AI browser into data theft
43d ago
Microsoft accelerates quantum-safe roadmap as risks grow
43d ago
Malicious PyPI packages give hackers control of Telegram bot servers
43d ago
Fake Perplexity extension on Chrome Web Store tracked searches
44d ago
Lessons from the Underground: How to Combat Business Email Compromise
44d ago
Insurance giant Aflac discloses data breach after subsidiary hack
44d ago
Mircosoft adds smarter bot protection to Teams meetings
44d ago
Microsoft adds smarter bot protection to Teams meetings
44d ago
Kali Linux 2026.2 released with 9 new tools, NetHunter updates
44d ago
Blackfield ransomware asks Nidec Corporation for $2 million ransom
44d ago
CISA: Windows BlueHammer flaw now exploited by ransomware gangs
44d ago
Nissan discloses employee data breach linked to Oracle zero-day attacks
44d ago
NAIC says public data stolen in ShinyHunters' PeopleSoft breach
44d ago
WhatsApp rolls out usernames to help users hide their phone number
44d ago
Microsoft extends Windows Server 2022 hotpatching until October 2027
44d ago
U.S. offers $10 million for hackers targeting WhatsApp, Signal users
45d ago
Agentic AI Has an Identity Problem and Attackers Know It
45d ago
Critical SimpleHelp flaw exploited to deploy new stealer malware
45d ago
Hackers now exploit critical Oracle E-Business flaw in attacks
45d ago
Webinar: Why business email compromise attacks keep succeeding
45d ago
US seizes hundreds of FIFA World Cup illegal streaming domains
45d ago
Data breach exposes up to 14.2 million email logins at six ISPs
46d ago
Clean GitHub repo tricks AI coding agents into running malware
47d ago
FBI: Russian hackers now target Signal backup recovery keys
47d ago
CISA sets urgent deadline to fix Cisco flaw exploited in attacks
47d ago
Polymarket customers lose $3 million in supply-chain attack
47d ago
Cybersecurity firms targeted by fraudulent OpenAI organization invites
47d ago
Your First GRC Agent: A Red Teamer's Walkthrough
48d ago
Anthropic is testing desktop-like Claude Cowork for mobile
48d ago
Poland busts SIM-swapping gang tied to millions in crypto theft
48d ago
Order-tracking app Shop abused to push callback phishing attacks
48d ago
Microsoft quietly extends free Windows 10 ESU support to October 2027
48d ago
New macOS malware embeds fake errors to confuse AI analysis tools
49d ago
PirloTV sports piracy network disrupted as 44 domains seized
49d ago
Bluekit phishing kit adopts browser-in-the-middle for login theft
49d ago
The Four Elevations of Effective Fraud Prevention
49d ago
Webinar: Why account takeovers remain one of the hardest threats to stop
49d ago
Google releases new privacy controls for activity history, personalization
49d ago
DraftKings hacker 'Snoopy' sentenced to 18 months in prison
49d ago
Mandiant reveals how Cisco SD-WAN zero-day attacks gained root access
49d ago
Malicious Edge extension abuses Native Messaging as bridge to malware
49d ago
CISA warns of max severity Ubiquiti flaws exploited in attacks
50d ago
Amadey, StealC malware operations disrupted in Operation Endgame action
50d ago
Securing the service desk: Why social engineering attacks keep succeeding
50d ago
Stealthy Mistic backdoor linked to ransomware access broker KongTuke
50d ago
Cisco Unified CM flaw CVE-2026-20230 now exploited in attacks
50d ago
Tata Electronics confirms cyberattack as hackers leak data
50d ago
Windows 11 KB5095093 update rolls out new Point-in-Time restore feature
50d ago
Healthtech firm Xolis suffers data breach impacting 1.4 million people
50d ago
New macOS ClickFix attack silently mounts DMGs to push infostealer
50d ago
Scattered Spider members plead guilty to hacking Transport for London
51d ago
The Exploit Doesn't Exist. You Can Still Prove It Works Against You
51d ago
LastPass confirms data breach in Klue supply chain attack
51d ago
Webinar: Why email security teams are drowning in alerts
51d ago
WhatsApp phishing attack uses fake business docs to hack PCs
51d ago
JaredFromSubway MEV bot hacked in $15 million crypto theft
51d ago
FFmpeg fixes PixelSmash flaw in widely used video decoder
51d ago
FortiBleed campaign used custom FortiGate sniffer to steal credentials
51d ago
Microsoft says Windows 11 26H2 is coming soon, details upgrade process
51d ago
Microsoft fixes AutoGen Studio flaw that enabled code execution
51d ago
A Glimpse into the “Search Your Target” Market for Stolen Credentials
52d ago
AryStinger botnet infected thousands of D-Link routers worldwide
53d ago
New Prinz Eugen ransomware prioritizes recent files for encryption
54d ago
Microsoft links Mastra AI supply chain attack to North Korean hackers
54d ago
Klue OAuth breach victim list grows as Icarus hackers claim attack
54d ago
Hackers exploit info disclosure bug in Gravity SMTP WordPress plugin
54d ago
Texas govt data breach exposes over 3 million driver’s licenses
55d ago
Every AI Agent Is an Identity. Most Organizations Don't Treat Them That Way
55d ago
Webinar: How attackers bypass MFA and how defenders can respond
55d ago
Microsoft: June 2026 Windows updates break Recycle Bin prompts
55d ago
CISA: Splunk Enterprise flaw actively exploited, patch by Sunday
55d ago
NY man charged after harassing college student with AI-generated nudes
55d ago
CISA warns Fortinet users to secure devices after FortiBleed leak
55d ago
Gentlemen ransomware uses multiple EDR killers to disable defenses
55d ago
Nintendo confirms data stolen in WebMD subsidiary cyberattack
55d ago
USB worm spreads crypto-stealing malware via Windows shortcut files
56d ago
Klue OAuth breach linked to 'Icarus' Salesforce data theft attacks
56d ago
5 reasons Microsoft 365 backup isn’t enough for business data protection
56d ago
Police cleans nearly 15,000 SocGholish-infected sites tied to Evil Corp
56d ago
ShapedPlugin update flow hacked to infect WordPress sites
56d ago
Apple fixes Beats Studio Buds flaw that let hackers spy on conversations
56d ago
Telegram admits it couldn't police exam-leak channels, India tells court
56d ago
F5 issues out-of-band patches for critical NGINX vulnerabilities
56d ago
Microsoft fixes Windows Server 2016 security update failures
56d ago
Leak confirms OpenAI is testing a ChatGPT for Science subscription
56d ago
Google to use UK and EU user IP addresses for ad personalization
56d ago
FortiBleed leak exposes Fortinet VPN credentials for 73,000 devices.
57d ago
Why Account Takeovers Are Rising and How to Stop Them
57d ago
India's Telegram ban hit the UAE too. Here's how to get around it
57d ago
Microsoft confirms Office apps launch issues after June updates
57d ago
CISA orders feds to patch max severity Joomla plugin flaw by Friday
57d ago
Microsoft working on Defender patch for RoguePlanet zero-day
57d ago
Kodak confirms data breach claimed by ShinyHunters extortion gang
57d ago
Malicious JetBrains Marketplace plugins steal AI API keys from developers
57d ago
New Rokarolla Android malware targets 217 banking, crypto apps
57d ago
Steam Workshop abused to spread malware via Wallpaper Engine app
57d ago
UK to require ID or face scan before you can make social media accounts
58d ago
GhostTree Attack Abused Recursive Windows Junctions to Hide Malware
58d ago
FTC warns of record $3.5 billion losses to imposter scams in 2025
58d ago
CISA warns of another cPanel plugin flaw exploited in attacks
58d ago
Ransomware gang abuses Microsoft Teams relays to hide malicious traffic
58d ago
Critical Fortinet FortiSandbox flaws now exploited in attacks
58d ago
Windows version of SprySOCKS Linux malware used to attack govt orgs
58d ago
iRhythm discloses data breach, says hackers stole patient info
58d ago
DOJ seizes CFAKE, SOCFAKE deepfake nude sites under TAKE IT DOWN Act
58d ago
SimpleHelp bug lets hackers create rogue remote support accounts
58d ago
OptinMonster WordPress plugin hacked in CDN supply-chain attack
58d ago
Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks
58d ago
Council of Europe investigates ShinyHunters data breach claims
59d ago
FBI: Fraudsters use couriers to steal money in crypto scams
59d ago
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl
59d ago
Chinese hackers breach REDCap servers, steal medical research
59d ago
New attack turned Microsoft 365 Copilot into 1-click data theft tool
59d ago
Infinite Campus data breach affects 137,000 school staff accounts
59d ago
Webinar: How behavioral AI stops phishing and account takeovers
59d ago
FBI disrupts massive AI-powered phishing service using a million URLs
60d ago
Ex-school district employee jailed for hacks on former employer
60d ago
Chinese hackers hijack auth flow, spy on isolated network for a decade
61d ago
US Gov asks Anthropic to ban 'foreign national' access to Fable, Mythos
61d ago
Maine disables data breach notification portal after fake disclosures
61d ago
phpBB forum fixes auth bypass bug lurking for a decade
61d ago
Ukrainian national pleads guilty to role in Conti ransomware operation
61d ago
Over 400 Arch Linux packages compromised to push rootkit, infostealer
62d ago
Early Warning Signs of Supply-Chain Attacks Live in the Dark Web
62d ago
Microsoft fixes Windows update failures linked to WUSA installer
62d ago
Pharma giant Novo Nordisk discloses breach of clinical trials data
62d ago
CISA orders feds to patch actively exploited Ivanti flaw by Sunday
62d ago
Over 73,000 French govt employees affected in Tchap messenger breach
62d ago
Japanese energy firm loses drive with data of 10.9 million clients
62d ago
Maine breach portal abused to publish fake data breach disclosures
62d ago
Oracle mitigates PeopleSoft zero-day exploited in data theft attacks
62d ago
Authorities dismantle 'AudiA6' ransomware crypto-laundering service
63d ago
Why AI-driven threats are exposing the limits of MSP security stacks
63d ago
Coupang hit with record $409 million data breach fine in Korea
63d ago
CISA tells govt agencies to patch critical exploited flaws in 3 days
63d ago
Microsoft fixes BitLocker recovery bug on Windows Server 2025
63d ago
Nottingham University data breach affects over 450,000 students
63d ago
Max severity Ivanti Sentry vulnerability now exploited in attacks
63d ago
Path traversal flaw in AI dev platform Langflow exploited in attacks
63d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
63d ago
GitHub announces npm security changes to tackle supply-chain attacks
63d ago
Oracle PeopleSoft servers hacked in ShinyHunters data theft attacks
63d ago
China-linked JDY botnet expands targeting of U.S. military networks
64d ago
The 5 Best Practices for Secure Identity Verification
64d ago
Microsoft patches Exchange Server zero-day exploited in attacks
64d ago
Microsoft: Some Windows PCs fail to install latest monthly updates
64d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
64d ago
Ivanti: Max severity Sentry flaw allows code execution as root
64d ago
Anthropic rolls out Claude Fable 5, but it's available for a limited time
64d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
64d ago
ServiceNow discloses security incident exposing customer data
64d ago
OpenClaw AI agent found falling for phishing attacks, spills user data
64d ago
SAP fixes critical flaws in NetWeaver and Commerce Cloud
64d ago
Microsoft releases Windows 10 KB5094127 extended security update
64d ago
Microsoft June 2026 Patch Tuesday fixes 3 zero-day, 200 flaws
64d ago
Microsoft June 2026 Patch Tuesday fixes 6 zero-days, 200 flaws
64d ago
Windows 11 KB5094126 & KB5093998 cumulative updates released
64d ago
XBOW tests Anthropic's Mythos Preview for offensive security
65d ago
GitHub disables Microsoft repos pushing password-stealing malware
65d ago
New Veeam vulnerability exposes backup servers to RCE attacks
65d ago
French govt messaging service breached in account hijacking attack
65d ago
CISA gives feds 3 days to patch Check Point VPN bug exploited as zero-day
65d ago
Google patches new Chrome zero-day flaw exploited in the wild
65d ago
NFCShare Android malware spreads via fake banking app updates on GitHub
65d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
65d ago
New Apple feature automatically changes your compromised passwords
65d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
65d ago
WhatsApp says it disrupted new NSO spyware phishing attacks
65d ago
Gogs patches critical zero-day enabling remote code execution
66d ago
Critical UniFi OS bug lets hackers gain root without authentication
66d ago
Reducing security operations complexity with Wazuh Cloud
66d ago
Check Point links VPN zero-day attacks to Qilin ransomware gang
66d ago
Oxford University discloses data breach after careers platform hack
66d ago
Over 20,000 Instagram accounts stolen in Meta AI support hack
66d ago
Hands on with Intelligent Terminal, an AI-powered Windows Terminal
66d ago
C0XMO botnet spreads via DD-WRT router flaw, kills rival malware
67d ago
Silent Ransom Group targets law firms with fake IT support calls
67d ago
Critical Everest Forms Pro flaw exploited to take over WordPress sites
68d ago
Suspicious Polyfill login prompts pop up on Toshiba, Muji websites
68d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
68d ago
Chinese APT deploys new malware to keep access to hacked networks
68d ago
Dark web Nemesis Market vendor gets 26 years for selling drugs
68d ago
Over 900 US gas station tank gauge systems exposed to attacks
69d ago
What 2026 DBIR Confirms: Attacks Are Living in the Browser
69d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
69d ago
Brave Software releases Origin for a paid, bloat-free browsing experience
69d ago
Hola Browser for Windows compromised to deliver cryptominer
69d ago
Credit card theft campaign abuses Stripe to host stolen payment info
69d ago
DentaQuest data breach exposed info of 2.6 million accounts
69d ago
UN food agency discloses breach affecting 600,000 Gaza households
70d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
70d ago
Hackers Are After the Gaps in Your Vulnerability Program: Here's Their Playbook
70d ago
Microsoft blames unexpected Windows driver updates on caching issue
70d ago
Police dismantles fake ID marketplace used by migrant smugglers
70d ago
Cisco warns of critical Unified CM flaw with PoC exploit code
70d ago
Chinese hackers use new Atlas RAT malware in European cyberattacks
70d ago
The U.S. sanctions Nobitex crypto exchange used by ransomware
70d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
70d ago
New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
70d ago
CISA warns of active attacks exploiting Android, Linux bugs
71d ago
What 345 Days of Untested Exposure Looks Like at a Bank
71d ago
Acer working to patch max severity zero-days in Wave 7 routers
71d ago
Police dismantles 9 crime groups in illegal streaming crackdown
71d ago
Google adds Android protection against AI deepfake scam calls
71d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
71d ago
Microsoft's Coreutils project brings Linux commands to Windows
71d ago
OpenAI upgrades GPT-5.5, as it plans to retire legacy ChatGPT models
71d ago
Critical Kirki flaw exploited to hijack WordPress admin accounts
71d ago
Over 116,000 Mincraft systems infected in WeedHack malware campaign
71d ago
Over 116,000 Minecraft systems infected in WeedHack malware campaign
71d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
71d ago
Microsoft Exchange Online outage causes email delays, failures
72d ago
Instagram users locked out after Meta AI abused to steal accounts
72d ago
Why the browser is now the front line for AI security
72d ago
CISA flags two-year-old Oracle flaw as actively exploited in attacks
72d ago
Google fixes one actively exploited Android zero-day, 124 flaws
72d ago
Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
72d ago
Red Hat npm packages compromised to steal developer credentials
72d ago
Spain arrests doxer leaking sensitive data of govt employees
72d ago
Dashlane password manager users locked out by brute force attacks
72d ago
WordPress malware campaign hides payloads in Steam profiles
73d ago
Microsoft investigates Office Apps, Teams file access issues
73d ago
Race Against Time: Why Faster Vulnerability Alerts Matter
73d ago
Critical Windows Netlogon RCE flaw now exploited in attacks
73d ago
Webinar tomorrow: From alert to resolution in network incident response
73d ago
Microsoft confirms outage affecting MFA, My Sign-Ins platform
73d ago
Microsoft fixes outage affecting MFA setup, MySignIn service
73d ago
Microsoft fixes KB5089549 Windows security update install issues
73d ago
WP Maps Pro bug exploited to create admin accounts on WordPress sites
74d ago
Palo Alto GlobalProtect VPN auth bypass flaw now exploited in attacks
74d ago
New CIFSwitch Linux flaw gives root on multiple distributions
75d ago
ChatGPT share links abused to host fake outage pages to deliver malware
75d ago
California AG sues 23andMe over 2023 breach exposing health data
75d ago
From $5 Attacks to Botnet-Powered Platforms: Inside the DDoS-as-a- Service Market
76d ago
Dutch govt disrupts malware botnet with 17 million infected devices
76d ago
Google Chrome adds session cookie theft protection for all users
76d ago
Man sent to prison for selling data of 7 millions elderly Americans
76d ago
US charges Google security engineer with Polymarket insider trading
76d ago
Charter Communications data breach affects 4.9 million accounts
76d ago
Anthropic confirms Claude Mythos-class models will roll out to the public
76d ago
GreyVibe hackers use ChatGPT, Gemini to power cyberattacks
76d ago
BTMOB Android malware service generates custom phishing payloads
76d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
76d ago
Hackers exploit FortiClient EMS flaw to push infostealer malware
76d ago
New Gogs zero-day flaw lets hackers get remote code execution
77d ago
How SIEM helps MSPs reduce noise and stop threats faster
77d ago
Romanian gets 5 years in prison for hacking Oregon govt network
77d ago
Webinar: Why network incidents take too long to resolve
77d ago
Carnival Cruise confirms data breach affecting nearly 6 million people
77d ago
Sextortionist sentenced to 33 years for targeting 145 children
77d ago
GPU mining malware spreads via SEO poisoning, AI chatbots
77d ago
Can you enforce strong Active Directory password rules without frustrating users?
78d ago
Glassworm botnet disrupted after resilient C2 infrastructure takedown
78d ago
FBI warns of in-person data theft attacks from extortion gang
78d ago
CISA gives feds 4 days to patch actively exploited cPanel plugin flaw
78d ago
Dutch police arrests suspect linked to Ajax football club hack
78d ago
Windows 11 KB5089573 update released with performance improvements
78d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
78d ago
Charter confirms data breach after ShinyHunters extortion threat
78d ago
How Varonis Atlas integrates Claude Compliance API for AI governance
79d ago
Microsoft Defender can now automatically isolate hacked endpoints
79d ago
Webinar: Too many tools are slowing network incident response
79d ago
CISA orders feds to patch actively exploited Drupal vulnerability
79d ago
Microsoft: Domain Controller lookup may fail on Windows Server 2016
79d ago
7-Eleven data breach exposes personal information of 185,000 people
79d ago
Anthropic’s restricted Claude Mythos model may be coming to Claude Code
79d ago
FBI warns of Kali365 phishing service targeting Microsoft 365 accounts
80d ago
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
81d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
81d ago
Italy disrupts CINEMAGOAL piracy app that stole streaming auth codes
82d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
82d ago
Former US execs plead guilty to aiding tech support scammers
83d ago
Trend Micro warns of Apex One zero-day exploited in the wild
83d ago
Drupal: Critical SQL injection flaw now targeted in attacks
83d ago
Why Chargebacks are Just One Piece of the Fraud Puzzle
83d ago
Ubiquiti patches three max severity UniFi OS vulnerabilities
83d ago
US and Canada arrest and charge suspected Kimwolf botnet admin
83d ago
Google accidentally exposed details of unfixed Chromium flaw
83d ago
Apple blocked over $11 billion in App Store fraud in 6 years
84d ago
Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet
84d ago
Chinese hackers target telcos with new Linux, Windows malware
84d ago
Max severity Cisco Secure Workload flaw gives Site Admin privileges
84d ago
Police seize “First VPN” service used in ransomware, data theft attacks
84d ago
Flipper One project needs community help to build open Linux platform
84d ago
Microsoft warns of new Defender zero-days exploited in attacks
84d ago
GitHub links repo breach to TanStack npm supply-chain attack
84d ago
Ukraine identifies infostealer operator tied to 28,000 stolen accounts
84d ago
Hackers bypass SonicWall VPN MFA due to incomplete patching
84d ago
Grafana breach caused by missed token rotation after TanStack attack
85d ago
Identity Alone Isn't Enough: Why Device Security Has to Share the Load
85d ago
Drupal critical update to fix bug with high exploitation risk
85d ago
Exploit released for new PinTheft Arch Linux root escalation flaw
85d ago
GitHub confirms breach of 3,800 repos via malicious VSCode extension
85d ago
Microsoft shares mitigation for YellowKey Windows zero-day
85d ago
GitHub investigates internal repositories breach claimed by TeamPCP
85d ago
Max-severity flaw in ChromaDB for AI apps allows server hijacking
85d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
85d ago
Discord rolls out end-to-end encryption on voice, video calls
85d ago
FBI: Americans lost over $388 million to scams using crypto ATMs in 2025
85d ago
Microsoft Self-Service Password Reset abused in Azure data theft attacks
85d ago
Microsoft plans to improve Windows 11 driver quality in 2026
86d ago
Microsoft blames macOS update for undismissible Teams location prompts
86d ago
New Shai-Hulud malware wave compromises 600 npm packages
86d ago
7-Eleven confirms data breach claimed by the ShinyHunters gang
86d ago
Critical Microsoft Vulnerabilities Doubled: From Exposure to Escalation
86d ago
Webinar: The hidden bottlenecks in network incident response
86d ago
Microsoft confirms patching issues in restricted Windows networks
86d ago
INTERPOL ‘Operation Ramz’ seizes 53 malware, phishing servers
86d ago
SHub macOS infostealer variant spoofs Apple security updates
86d ago
5 Steps to Managing Shadow AI Tools Without Slowing Down Employees
86d ago
Leaked Shai-Hulud malware fuels new npm infostealer campaign
86d ago
Grafana says stolen GitHub token let hackers steal codebase
87d ago
Microsoft testing adjustable taskbar, Start menu in Windows 11
87d ago
Microsoft confirms Windows 11 security update install issues
87d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
87d ago
Hackers earn $1,298,250 for 47 zero-days at Pwn2Own Berlin 2026
87d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
87d ago
Tycoon2FA hijacks Microsoft 365 accounts via device-code phishing
88d ago
Microsoft rejects critical Azure vulnerability report, no CVE issued
88d ago
Russian hackers turn Kazuar backdoor into modular P2P botnet
89d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
89d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
89d ago
Popular node-ipc npm package compromised to steal credentials
89d ago
Avada Builder WordPress plugin flaws allow site credential theft
90d ago
Microsoft backpedals: Edge to stop loading passwords into memory
90d ago
Inside the REMUS Infostealer: Session Theft, MaaS, and Rapid Evolution
90d ago
Microsoft to automatically roll back faulty Windows drivers
90d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
90d ago
TeamPCP hackers advertise Mistral AI code repos for sale
90d ago
Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
90d ago
Cisco warns of new critical SD-WAN flaw exploited in zero-day attacks
90d ago
OpenAI confirms security breach in TanStack supply chain attack
90d ago
Windows 11 and Microsoft Edge hacked at Pwn2Own Berlin 2026
90d ago
18-year-old NGINX vulnerability allows DoS, potential RCE
91d ago
Cyber-Enabled Cargo Crime: How Cybercrime Tradecraft is Used to Steal Freight
91d ago
KongTuke hackers now use Microsoft Teams for corporate breaches
91d ago
Dell confirms its SupportAssist software causes Windows BSOD crashes
91d ago
US charges suspected Dream Market admin arrested in Germany
91d ago
New Fragnesia Linux flaw lets attackers gain root privileges
91d ago
West Pharmaceutical says hackers stole data, encrypted systems
91d ago
Iranian hackers targeted major South Korean electronics maker
91d ago
New critical Exim mailer flaw allows remote code execution
91d ago
Windows BitLocker zero-day gives access to protected drives, PoC released
92d ago
Webinar tomorrow: Why security alone won't stop modern attacks
92d ago
Microsoft fixes BitLocker recovery issue only for Windows 11 users
92d ago
Microsoft fixes Windows Autopatch bug installing restricted drivers
92d ago
Foxconn confirms cyberattack claimed by Nitrogen ransomware gang
92d ago
73 Seconds to Breach, 24 Hours to Patch: The Case for Autonomous Validation
92d ago
Microsoft says some users can't install Office on Windows 365 devices
92d ago
US govt seeks Instructure testimony on massive Canvas cyberattack
92d ago
UK fines water supplier $1.3M for exposing data of 664k customers
92d ago
Webinar: Fixing the gaps in network incident response
92d ago
Signal adds security warnings for social engineering, phishing attacks
92d ago
Microsoft releases Windows 10 KB5087544 extended security update
92d ago
Fortinet warns of critical RCE flaws in FortiSandbox and FortiAuthenticator
92d ago
Windows 11 KB5089549 & KB5087420 cumulative updates released
92d ago
Microsoft May 2026 Patch Tuesday fixes 120 flaws, no zero-days
92d ago
Škoda warns of customer data breach after online shop hack
92d ago
Android 17 to expand banking scam call and privacy protections
93d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
93d ago
SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA
93d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
93d ago
GM agrees to $12.75M California settlement over sale of drivers’ data
93d ago
Official CheckMarx Jenkins package compromised with infostealer
93d ago
New GhostLock tool abuses Windows API to block file access
93d ago
Instructure confirms hackers used Canvas flaw to deface portals
94d ago
Why Changing Passwords Doesn’t End an Active Directory Breach
94d ago
Google: Hackers used AI to develop zero-day exploit for web admin tool
94d ago
Webinar this week: Prevention alone is not enough against modern attacks
94d ago
TrickMo Android banker adopts TON blockchain for covert comms
94d ago
Hackers abuse Google ads, Claude.ai chats to push Mac malware
94d ago
Police shut down reboot of Crimenetwork marketplace, arrest admin
95d ago
JDownloader site hacked to replace installers with Python RAT malware
95d ago
Fake OpenAI repository on Hugging Face pushes infostealer malware
96d ago
NVIDIA confirms GeForce NOW data breach affecting Armenian users
97d ago
Why More Analysts Won’t Solve Your SOC’s Alert Problem
97d ago
Trellix source code breach claimed by RansomHouse hackers
97d ago
CISA gives feds four days to patch Ivanti flaw exploited as zero-day
97d ago
Zara data breach exposed personal information of 197,000 people
97d ago
Former govt contractor convicted for wiping dozens of federal databases
97d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
97d ago
Canvas login portals hacked in mass ShinyHunters extortion campaign
97d ago
New TCLBanker malware self-spreads over WhatsApp and Outlook
97d ago
New PCPJack worm steals credentials, cleans TeamPCP infections
97d ago
Australia warns of ClickFix attacks pushing Vidar Stealer malware
97d ago
Ivanti warns of new EPMM flaw exploited in zero-day attacks
98d ago
The Browser Is Breaking Your DLP: How Data Slips Past Modern Controls
98d ago
Americans sentenced for running 'laptop farms' for North Korea
98d ago
Crypto gang member gets 6.5 years for role in $230 million heist
98d ago
Webinar: Why modern attacks require both security and recovery
98d ago
Palo Alto Networks firewall zero-day exploited for nearly a month
98d ago
Fake Claude AI website delivers new 'Beagle' Windows malware
98d ago
Hackers abuse Google ads for GoDaddy ManageWP login phishing
98d ago
Critical vm2 sandbox bug lets attackers execute code on hosts
98d ago
New Cisco DoS flaw requires manual reboot to revive devices
98d ago
DAEMON Tools devs confirm breach, release malware-free version
99d ago
Why ransomware attacks succeed even when backups exist
99d ago
MuddyWater hackers use Chaos ransomware as a decoy in attacks
99d ago
Webinar: Why network incidents escalate and how to fix response gaps
99d ago
Palo Alto Networks warns of firewall RCE zero-day exploited in attacks
99d ago
New stealthy Quasar Linux malware targets software developers
99d ago
Instructure hacker claims data theft from 8,800 schools, universities
99d ago
DAEMON Tools trojanized in supply-chain attack to deploy backdoor
99d ago
Student hacked Taiwan high-speed rail to trigger emergency brakes
99d ago
FTC to ban data broker Kochava from selling Americans’ location data
100d ago
The EOL Blind Spot in Your CVE Feed: What SCA Tools Don't Check.
100d ago
The EOL Blind Spot in Your CVE Feed: What SCA Tools Miss
100d ago
Vimeo data breach exposes personal information of 119,000 people
100d ago
Google now offers up to $1.5 million for some Android exploits
100d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
100d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
100d ago
ScarCruft hackers push BirdCall Android malware via game platform
100d ago
Weaver E-cology critical bug exploited in attacks since March
100d ago
Amazon SES increasingly abused in phishing to evade detection
100d ago
Researchers report Amazon SES abused in phishing to evade detection
100d ago
Backdoored PyTorch Lightning package drops credential stealer
100d ago
Trellix discloses data breach after source code repository hack
101d ago
They don’t hack, they borrow: How fraudsters target credit unions
101d ago
Progress warns of critical MOVEit Automation auth bypass flaw
101d ago
Webinar: Why MSPs must rethink security and backup strategies
101d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
101d ago
Microsoft confirms April Windows updates cause backup failures
101d ago
Instructure confirms data breach, ShinyHunters claims attack
101d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
101d ago
Telegram Mini Apps abused for crypto scams, Android malware delivery
102d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
102d ago
ConsentFix v3 attacks target Azure with automated OAuth abuse
103d ago
Microsoft tests modern Windows Run, says it's faster than legacy dialog
103d ago
Edu tech firm Instructure discloses cyber incident, probes impact
103d ago
15-year-old detained over French govt agency data breach
103d ago
Story retracted
104d ago
Criminal IP and Securonix ThreatQ Collaborate to Enhance Threat Intelligence Operations
104d ago
Microsoft fixes Remote Desktop warnings displaying incorrectly
104d ago
Microsoft now lets admins choose pre-installed Store apps to uninstall
104d ago
Windows 11 KB5083631 update released with 34 changes and fixes
104d ago
US ransomware negotiators get 4 years in prison over BlackCat attacks
104d ago
New Bluekit phishing service includes an AI assistant, 40 templates
104d ago
746 loaded
SE
SecurityWeek
2h ago · 10 items
Cybersecurity M&A Roundup: 21 Deals Announced in July 2026
2h ago
Adobe Commerce Bug Targeted Immediately After Disclosure
2h ago
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
4h ago
Venture Firm Team8 Secures Additional $365 Million
5h ago
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
6h ago
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
7h ago
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
8h ago
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
8h ago
SharePoint Vulnerability Exploited Shortly After PoC Release
1d ago
Mindgard Raises $30 Million to Protect AI Systems
1d ago
HN
Help Net Security
2h ago · 10 items
White House authorizes private US companies to hack foreign criminal networks
2h ago
President Trump signed a memo allowing vetted private companies to run offensive cyber operations against foreign threat actors.
DataGrout helps enterprises control AI usage, governance and LLM costs
3h ago
SelectHub launches DataGrout to cut enterprise LLM token costs while centralizing AI governance, usage visibility and agent control.
A10 Networks introduces AI Gateway to secure and manage enterprise AI
3h ago
A10 AI Gateway centralizes AI routing, cost control, governance and security, helping companies manage models and agents at scale.
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
4h ago
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of PoC exploit code by Rapid7.
Searchlight Cyber combines exposure and threat intelligence in new PTEM platform
6h ago
Searchlight Cyber launched PTEM platform, combining exposure visibility with attacker intelligence to prioritize exploitable security risks.
153GB of stolen credentials surface after LiteLLM supply chain attack
6h ago
Stolen credentials tied to the LiteLLM breach have surfaced in a 153GB archive linked to thousands of corporate domains.
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
9h ago
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls.
Four corporate investigation mistakes organizations make under pressure
12h ago
BlackBerry's Christine Gadsby on corporate investigation mistakes that happen long before the forensic team shows up.
DDoS attacks hit record scale as 1 Tbps+ campaigns become more common
12h ago
Cloudflare reports a surge in hyper-volumetric DDoS attacks, with DNS floods and multi-vector campaigns driving H1 2026 trends.
Product showcase: Is this image real? Slop or Not investigates
13h ago
Discover how Slop or Not, an AI image detector for iPhone and Mac, identifies AI-generated images without the cloud.
BH
Black Hat
2h ago · 15 items
Black Hat Stories | Daniel Cuthbert
2h ago
Black Hat Stories | More Than a Conference
1d ago
Three Decades of Influence | Why Black Hat Matters
1d ago
Black Hat Stories | Gaurav Keerthi, CEO and founder of StrongKeep
1d ago
When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection
5d ago
Black Hat USA Briefings: Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius
5d ago
Black Hat USA Opening Session: Disruption, Defense and Operational Readiness
6d ago
Black Hat USA 2026 Opening Session: Cyber Power in the Age of AI
6d ago
Black Hat USA 2026 Keynote: Vulnerability Research in the Agentic Age
6d ago
Black Hat USA 2026 Keynote: The End of Rare Defending When Offense Is Cheap
6d ago
Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident
6d ago
Why Black Hat Matters | Black Hat Stories
12d ago
Black Hat Stories | Daniel Cuthbert, Black Hat Training Review Board Member
12d ago
Cyber War Forum: The Critical Questions No One Has Real Answers To
14d ago
Black Hat Asia 2026 | Keynote: From Prompt Tricks to Autonomous Hackers
15d ago
15 loaded
JH
John Hammond
3h ago · 15 items
Phishing Gets Personal
3h ago
I Made AI Build a Cybersecurity Mod in Minecraft
4h ago
I Found an MFA-Bypassing Phishing Kit on the Dark Web
1d ago
Can AI Build Hacker Traps That Actually Work?
2d ago
Cyber Deception Everywhere
10d ago
JHT Course Launch! Home Labs with Proxmox
12d ago
GTA Malware Trap
13d ago
Minecraft Security Mods
15d ago
Payload Podcast 010 - Olaf Hartong
15d ago
Any App Notification
18d ago
Building Fake Notifications
19d ago
Fake Edge Update
21d ago
An AI Botnet
23d ago
Redirect Chain Abuse
24d ago
Microsoft Exchange Hacked, Five Years Later
24d ago
15 loaded
MS
MSRC Security Update Guide
3h ago · 20 items
CVE-2026-61346 Windows Graphics Kernel Elevation of Privilege Vulnerability
3h ago
CVE-2026-62695 Windows Storage Elevation of Privilege Vulnerability
3h ago
CVE-2026-61359 Windows Storage Elevation of Privilege Vulnerability
3h ago
CVE-2026-66804 Microsoft Windows Cross Device Service Elevation of Privilege Vulnerability
3h ago
CVE-2026-62913 Microsoft Exchange Server Remote Code Execution Vulnerability
3h ago
CVE-2026-65796 Windows iSCSI Target Service Denial of Service Vulnerability
3h ago
CVE-2026-62688 Windows MIDI Service Module Elevation of Privileges Vulnerability
3h ago
CVE-2026-62897 .NET Framework Remote Code Execution Vulnerability
3h ago
CVE-2026-62902 .NET Information Disclosure Vulnerability
3h ago
CVE-2026-70354 .NET Core Remote Code Execution Vulnerability
3h ago
CVE-2026-62871 .NET Elevation of Privilege Vulnerability
3h ago
CVE-2026-62886 .NET Elevation of Privilege Vulnerability
3h ago
CVE-2026-62898 Microsoft QUIC Information Disclosure Vulnerability
3h ago
CVE-2026-44814 Windows DWM Core Library Information Disclosure Vulnerability
3h ago
CVE-2026-45638 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
3h ago
CVE-2026-45637 Microsoft DWM Core Library Elevation of Privilege Vulnerability
3h ago
CVE-2026-45597 Windows UI Automation Manager (uiamanager.dll) Elevation of Privilege Vulnerability
3h ago
CVE-2026-45593 Windows SDK Elevation of Privilege Vulnerability
3h ago
CVE-2026-45592 Windows Internet (wininet.dll) Elevation of Privilege Vulnerability
3h ago
CVE-2026-49162 Microsoft Brokering File System Elevation of Privilege Vulnerability
3h ago
20 loaded
SL
Security Latest
7h ago · 20 items
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
7h ago
This Coin-Sized Device Can Hack a Boeing 737
1d ago
‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardware
1d ago
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
2d ago
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
5d ago
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
5d ago
Hackers Stalked Me by Hijacking a Smartwatch for Kids
6d ago
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
7d ago
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
7d ago
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
7d ago
DHS Wants Protesters’ Signal Group Chats
7d ago
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
7d ago
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
7d ago
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
8d ago
OK, Well, Rogue AI Agents Are Hacking Again
8d ago
Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
9d ago
ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
10d ago
8 Best Password Managers (2026), Tested and Reviewed
11d ago
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
12d ago
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
12d ago
20 loaded
SE
Securelist
9h ago · 10 items
Armored Likho expands its cyber-espionage toolkit
9h ago
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
2d ago
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf serve...
Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection
2d ago
Project CAV3RN targets Israel with Google Apps Script C2 relays and DNS-based routing. Modular .NET NativeAOT framework blends C2 traffic with legitimate Google services to evade detection.
IT threat evolution in Q2 2026. Non-mobile statistics
3d ago
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
IT threat evolution in Q2 2026. Mobile statistics
3d ago
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
How legitimate cloud platforms enable phishers to bypass MFA
9d ago
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
An analysis of incidents at Brazilian educational institutions
10d ago
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
Network Anomaly Detection in KATA
13d ago
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
14d ago
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Toy Ghouls’ new toy: the GenieLocker ransomware
14d ago
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
TH
The Hacker News
10h ago · 20 items
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
10h ago
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
23h ago
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
1d ago
OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning
1d ago
Enterprise Defenses Recovered at the Edge and Collapsed Inside
1d ago
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
1d ago
Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access
1d ago
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
1d ago
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
1d ago
ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access
1d ago
Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS
1d ago
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
1d ago
Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing
1d ago
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
1d ago
Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands
1d ago
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
2d ago
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt
2d ago
OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development
2d ago
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
2d ago
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
2d ago
20 loaded
RF
Recorded Future
17h ago · 20 items
Malware Crypting Services and the Threat Actors Who Sell Them
17h ago
Mines, Minds, and Machines: The Journey of AI
2d ago
The Hugging Face Hack Was Cheap Persistence at Work
3d ago
July 2026 CVE Landscape
6d ago
Emerging Threats to Neurotechnology
7d ago
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
8d ago
8 Ways AI is Changing Threat Intelligence
10d ago
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
14d ago
Dealing with AI-Generated Extortion
14d ago
Ransomware is the Scoreboard
20d ago
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
21d ago
Modern Attack Vectors | Recorded Future
22d ago
Threat Hunting: A Guide | Recorded Future
24d ago
Tracking Advanced Persistent Threat Groups | Recorded Future
27d ago
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
28d ago
The Shift: A New Era of AI Regulation
29d ago
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
30d ago
June 2026 CVE Landscape
34d ago
RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney
35d ago
The Threat Isn’t the Frontier Model
36d ago
20 loaded
SA
Security - Ars Technica
19h ago · 20 items
Terabytes of credentials leaked in massive supply-chain attack
19h ago
Researchers found a way to hijack devices through Zoom screen sharing
1d ago
DEF CON crowd suspected in fake-hotspot attack on Delta flight
1d ago
Chrome adopts what may be the best protection yet against account takeovers
1d ago
New surveillance tech links your phone to your license plate
2d ago
New Pass-ta-key attack reveals all the things we didn't know about passkeys
2d ago
A researcher bought noreply.net. Companies started sending him secrets.
3d ago
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
7d ago
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
7d ago
Defcon's new badge is a security key you can see inside
12d ago
Claude published malicious code to the Internet and attacked 3 real companies
12d ago
AI scammers outperform humans when it comes to building trust
13d ago
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
13d ago
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
14d ago
Anthropic is finding bugs faster than Microsoft can fix them
15d ago
We now have a better understanding how OpenAI hacked into Hugging Face
15d ago
Microsoft unveils AI security tools it says outperform competing platforms
16d ago
Activist charged with felony after giving border agent "duress code" that wiped his phone
17d ago
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
22d ago
Apps targeted at US troops contain Chinese and Russian code
23d ago
20 loaded
CS
Cisco Security Advisory
1d ago · 20 items
Cisco Advance Notification for Publication of August 19, 2026, Security Advisories
1d ago
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks Industrial ...
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
1d ago
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within th...
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
2d ago
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the d...
ClamAV Vulnerabilities Affecting Cisco Products: August 2026
3d ago
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For...
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
5d ago
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficien...
Cisco Advance Notification for Publication of August 5, 2026, Security Advisories
8d ago
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst SD-WAN Integra...
Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability
8d ago
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due t...
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
8d ago
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnera...
Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability
8d ago
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could ...
Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability
8d ago
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due...
Cisco IOS XE Software SNMP Denial of Service Vulnerability
8d ago
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
8d ago
Cisco IOS XE Software Security Hardening Release: August 2026
8d ago
Cisco Integrated Management Controller Argument Injection Vulnerabilities
8d ago
Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability
8d ago
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
8d ago
Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability
8d ago
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
8d ago
Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
23d ago
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
24d ago
20 loaded
WE
WeLiveSecurity
1d ago · 20 items
Black Hat USA 2026: AI is racing ahead of cybersecurity controls
1d ago
Are AI tutors safe for your kids?
3d ago
This month in security with Tony Anscombe – July 2026 edition
13d ago
Beyond the screenshot: Why you should verify what you see
14d ago
Forgotten UEFI shims undermining Secure Boot
30d ago
ESET Threat Report H1 2026
36d ago
Cyber readiness for SMBs: Getting the basics right
41d ago
This month in security with Tony Anscombe – June 2026 edition
44d ago
Inside the inbox: Why cybercriminals want to break into your email account
45d ago
SMB cyber readiness: the road to resilience starts here
48d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
49d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
50d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
56d ago
Protecting legacy OT systems against modern cyberthreats
57d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
58d ago
EvilTokens: A phishing attack that doesn’t steal your password
59d ago
OceanLotus: From external espionage to domestic targeting
63d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
64d ago
Cybercriminals: the 'auditors' you never hired
65d ago
Lessons for life: Why children’s data is a long-term identity risk
71d ago
20 loaded
NA
NahamSec
1d ago · 15 items
I Went to the World's Biggest Hacker Conference (DEFCON VLOG)
1d ago
I’m headed to DEFCON!
8d ago
Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS)
10d ago
Are you ready for this year's @BugBountyVillage at @DEFCONConference
10d ago
Do you guys agree? #hacking #bugbounty
13d ago
How One File Upload Got Me the Entire Customer Database
17d ago
Why Being a Great Hacker Doesn't Pay Anymore
19d ago
This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!)
31d ago
I Made an AI Agent That Reverses CVEs While I Sleep
38d ago
This Hacker Got Paid $50,000+ to Break Frontier AI Models
52d ago
This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity
56d ago
How I Made $30,000 Hacking Broken Access Control
59d ago
$30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover
59d ago
Content creations was both a blessing and a curse. #bugbounty
66d ago
This Hacker Made $7,000 Hacking AI With One Email
66d ago
15 loaded
KO
Krebs on Security
1d ago · 10 items
Microsoft Plugs Nearly 400 Security Holes
1d ago
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly deta...
Canadian Man Pleads Guilty in Snowflake Extortions
7d ago
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage ...
Read This Before You Buy That TV Streaming Stick
14d ago
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. ...
LG to Ban Residential Proxies from Smart TV Apps
22d ago
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers…
Microsoft Patches a Record 570 Security Flaws
29d ago
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesd...
Lessons Learned from CISA’s Recent GitHub Leak
31d ago
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almos...
Felons, Fraudsters Flog Offensive Cybersecurity Startup
36d ago
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intellige...
FBI Seizes NetNut Proxy Platform, Popa Botnet
41d ago
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technolo...
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
51d ago
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The ...
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
55d ago
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers ...
DE
DEFCONConference
1d ago · 15 items
DEF CON 34 - Video Team - Hackers dot Town - The Gibson
1d ago
DEF CON 34 - Video Team - Car Hacking Villlage
1d ago
DEF CON 34 - Video Team - Ham Radio Village - Marvin Goes HAM
1d ago
DEF CON 34 - Video Team - Physical Security Village
1d ago
DEF CON 34 - Video Team - LEECH
1d ago
DEF CON 34 - Video Team - EmbeddedSystems Village
1d ago
DEF CON 34 - Video Team - PhreakMe
1d ago
DEF CON 34 - Video Team - Voting Machine Hacking Village
3d ago
DEF CON 34 - VideoTeam - Cliff Stoll AfterHours
3d ago
DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking
4d ago
DEF CON 34 - Video Team - Hak5 - Darren Kitchen
4d ago
DEF CON 34 - Video Team - AI Hacking Village - Pokemon
4d ago
DEF CON 34 - Video Team - No Starch Press
4d ago
DEF CON 34 - Video Team - Goon Questions -Guzi Media
4d ago
DEF CON 34 - Video Team -Bug Bounty Village
4d ago
15 loaded
MS
Microsoft Security Blog
3d ago · 10 items
Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise
3d ago
Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise.
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
3d ago
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongs...
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
8d ago
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report.
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
8d ago
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities...
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
8d ago
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guid...
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
8d ago
Read how to apply Zero Trust for AI with new assessments, DevSecOps guidance, and practical tools to secure AI agents, code, memory, and cloud environments.
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
8d ago
Microsoft Defender automatically isolated a compromised QNET endpoint in 129 seconds, stopping a multi-stage attack before the payload could persist or spread.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
12d ago
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and stea...
What’s new in Microsoft Security: July 2026
14d ago
Explore July 2026 Microsoft Security updates, including agentic defense, AI threat protection, identity, data security, and advanced endpoint management.
Better security starts with better questions
15d ago
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems.
DB
David Bombal
4d ago · 15 items
Do You Need a VPN in 2026? Here’s the Truth
4d ago
1.5 Gbps Internet using your old telephone cables?
11d ago
Rediscover Maltego in 2026
14d ago
Qubes OS explained: assume you will get hacked
18d ago
You need to learn Maltego in 2026
21d ago
Want To Learn (For FREE) About A Self-Driving Network?
21d ago
The End of TOKENMAXXING?
22d ago
Is Cat7 a SCAM?
29d ago
Cisco's Agents Reason Like a CCIE
30d ago
Install GrapheneOS Before Your Phone Becomes the Checkpoint
32d ago
Unveiled: Cisco Deep Reasoning
37d ago
Why Apple Hide My Email FAILS
39d ago
New to Linux? This is the best place to start!
39d ago
WARNING: AI tracks your face
40d ago
Is DEFCON for you?
43d ago
15 loaded
IP
IppSec
5d ago · 15 items
HackTheBox - Helix
5d ago
HackTheBox - Kobold
12d ago
HackTheBox - Fries
19d ago
HackTheBox Logging
26d ago
HackTheBox - CCTV
33d ago
HackTheBox - DevArea
40d ago
HackTheBox - WingData
47d ago
HackTheBox - Nanocorp
54d ago
HackTheBox - VariaType
61d ago
HackTheBox - Facts
68d ago
HackTheBox - Interpreter
75d ago
HackTheBox - MonitorsFour
82d ago
HackTheBox - Pterodactyl
89d ago
HackTheBox - Overwatch
96d ago
HackTheBox - Sorcery
110d ago
15 loaded
CY
CyberScoop
5d ago · 179 items
More than half of AI-generated patches are broken
5d ago
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
6d ago
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
6d ago
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
6d ago
Ransom Cartel creator sentenced to 16 years in prison
6d ago
The water sector just got it’s wake-up call. Again.
7d ago
Snowflake hacker pleads guilty, faces up to 32 years in prison
7d ago
Tom Cotton prods Treasury for tax code tweaks to modernize OT
7d ago
Open-source software’s archenemy TeamPCP goes back further than anyone thought
8d ago
AI is getting better at election facts, but voters shouldn’t rely on it
8d ago
National cyber director lays out White House plans to secure AI without writing new rules
8d ago
AISI, OpenAI report more ‘unsanctioned’ model hacks
8d ago
Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack
9d ago
CrowdStrike: AI is now both the weapon and the target in cyberattacks
10d ago
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
12d ago
What the Hugging Face breach reveals about defense in the age of agentic AI
13d ago
Anthropic says its AI accidentally hacked three companies during safety tests
13d ago
Okta’s deal for Permiso aims to close gaps in identity threat detection
13d ago
CISA issues recommendations to federal agencies on open-source software security
13d ago
We know how to protect our troops from telecom attacks. We’re just not doing it.
14d ago
Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims
14d ago
A little-known npm package was North Korea’s warm-up act for the axios hack
14d ago
Supply chain challenges loom large in quantum race, White House official says
14d ago
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
15d ago
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
19d ago
Despite multiple takedowns, botnets continue to grow
19d ago
Microsoft, tech companies throw weight behind spread of open-source AI
20d ago
Rubio restricts visas for sextortionists, cyber scammers
20d ago
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
20d ago
ANCHOR-CI could fix 20 years of broken government-industry collaboration
21d ago
Most federal cybersecurity reporting rules are duplicative, study finds
21d ago
Malware is targeting AI tools in software development environments
21d ago
White House accuses Chinese company of distilling Anthropic’s Fable
22d ago
OpenAI says model test was behind Hugging Face hack
22d ago
AI models keep getting caught cheating
22d ago
Where’s the Trump administration line on AI regulation?
22d ago
House intel bill includes provisions on state and local threat intelligence, election security, AI
23d ago
North Korea’s IT worker scheme funds Russia’s war effort
23d ago
What the World Cup can teach us about cybersecurity resilience
23d ago
Director of Commerce AI standards office out after three months
23d ago
Why blocking AI models won’t stop the cyber threats they create
24d ago
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
27d ago
Leading members of Scattered Spider sentenced in UK to 66 months in jail
27d ago
Program to rotate cyber personnel through federal agencies saw little use
27d ago
Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime
27d ago
Security researchers find stalkers abusing Chrome’s sync feature
28d ago
SonicWall customers under threat as attackers exploit 2 zero-days
28d ago
Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
28d ago
Forget the model. When it comes to cybersecurity, it’s all about the harness
29d ago
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
34d ago
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
34d ago
764 splinter group leader sentenced to 40 years in jail
35d ago
French nonprofit starts global intelligence and research hub for AI cyber threats
35d ago
Found fast, fixed slow: The gap the AI clearinghouse must close
36d ago
Spain arrests suspected hacker linked to Russian hacktivist campaign
36d ago
Deepfake CSAM lawsuit against xAI, Grok expands
36d ago
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
37d ago
US Army websites defaced with pro-Kurdish sentiments, insults to Trump
37d ago
Sysdig clocks first documented case of agentic ransomware
38d ago
Finding vulnerabilities was never the hard part
38d ago
Someone infected a spyware probe overseer with spyware
41d ago
Alleged longstanding member of Scattered Spider extradited to US
42d ago
Researchers spot exploitation of another critical Oracle defect
42d ago
US lifting export control restrictions on Anthropic’s Mythos, Fable
43d ago
This phishing kit looks more like BEC-as-a-service
43d ago
Citrix patches a new NetScaler flaw with echoes of CitrixBleed
43d ago
Trump budget boss Russell Vought open to re-staffing CISA
43d ago
DHS to unveil replacement council for critical infrastructure cybersecurity
44d ago
How ransomware syndicates weaponize corporate-style organization
44d ago
Warner bill would create federally vetted list for secure, trustworthy AI agents
44d ago
Supreme Court approves mail-in ballots that arrive after Election Day
44d ago
Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling
44d ago
What the post-quantum executive order really demands of CISOs
45d ago
ATF cancels controversial commercial geolocation contract
47d ago
FCC passes new cybersecurity rules for emergency systems, undersea cables
48d ago
Federal court rules Trump election-focused executive order illegal
49d ago
Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract
49d ago
Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack
49d ago
Why patch directives only go so far
49d ago
Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
49d ago
In a first, a court takedown goes after two cybercrime tools at once
50d ago
Open-source security is posing challenges governments can’t easily solve
50d ago
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
50d ago
Algerian man charged with running two cybercrime marketplaces
51d ago
Court rules SAVE database illegal, orders it dismantled
51d ago
Trump executive orders speed up post-quantum migration, boost industry
51d ago
Intel agencies: Frontier AI models will reshape cybersecurity faster than expected
52d ago
Authorities disrupt Evil Corp’s SocGholish botnet
55d ago
Congress tees up No FAKES Act, aiming at AI-generated deepfakes
55d ago
How software development’s speed obsession enabled TeamPCP’s chaos crusade
56d ago
Accenture shells out $4.18B on three companies in big industrial cybersecurity push
56d ago
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April
57d ago
Lawmakers leery about Trump administration’s Anthropic order
57d ago
AI’s constant patching treadmill can be a security problem
57d ago
A case for how to shape ‘ingredient lists’ for AI models
58d ago
Google exposes China espionage group that’s been lurking in networks undetected since 2023
58d ago
Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat
59d ago
Anthropic disables new models after government calls them a national security concern
60d ago
FBI takes down massive China-based cybercrime network that caused $1.9B in losses
61d ago
US, France, and Italian authorities shut down massive deepfake porn site
61d ago
Conti ransomware group member pleads guilty, faces up to 20 years in prison
61d ago
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw
62d ago
CyberCorps is adapting to AI. The budget isn’t keeping up.
62d ago
Russian national charged in connection with Void Blizzard espionage campaign
62d ago
OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
63d ago
CISA directive orders agencies to prioritize vulnerability patching in a new way
64d ago
Microsoft breaks Patch Tuesday record with 206 vulnerabilities
64d ago
Anthropic’s new model is Mythos on a leash
65d ago
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
65d ago
Cisco customers encounter another SD-WAN zero-day under attack
65d ago
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
65d ago
The AI security race needs accountability, not overregulation
66d ago
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
69d ago
Hill Dems hammer GOP for $250M CISA budget cut
69d ago
Your AI agent could become your biggest insider threat
69d ago
Inside the race to adapt to an AI-powered security world
70d ago
European authorities crack down on illegal streaming networks
70d ago
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels
70d ago
DOD wants to integrate cyber in all operations, and integrate security into AI
71d ago
Trump administration releases scaled-back AI executive order
72d ago
Anthropic expanding access to Project Glasswing
72d ago
Attackers are exploiting Palo Alto Networks defect that initially flew under the radar
72d ago
Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight
72d ago
USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order
72d ago
Election threats are focused on campaign systems, not voting machines
73d ago
Tennessee man linked to 764 accused of series of crimes against children dating back to 2022
75d ago
Federal audit reveals NIST’s NVD is plagued by poor planning and duplication
76d ago
House panel poised to hold hearing centered on AI impact on cyber
76d ago
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
76d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
77d ago
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms
77d ago
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
77d ago
UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace
77d ago
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
78d ago
Apple open-sources quantum-resistant encryption code
78d ago
Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
83d ago
Lawmakers from both parties say CISA cuts have gone too far
83d ago
Trump postpones executive order focused on AI security
83d ago
CISA chief frets about open-source vulnerabilities, delayed security improvements
84d ago
European authorities take down prolific cybercrime VPN service
84d ago
The readiness paradox: Why a false sense of cyber confidence is becoming a liability
84d ago
Meet Rampart and Clarity, Microsoft’s new red team combo AI agents
84d ago
GitHub says internal repositories were impacted in poisoned VS Code extension attack
85d ago
CISA credential leak raises alarms, and Capitol Hill demands answers
85d ago
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches
85d ago
Mini Shai-Hulud returns, compromising hundreds of npm packages
86d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
86d ago
AI might cut false positives, but it won’t stop the slop
86d ago
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
86d ago
The Canvas breach proved that prevention is no longer enough
87d ago
Former CISA nominee Sean Plankey named US CEO of defense startup
87d ago
Colorado governor commutes prison sentence for election denier Tina Peters
89d ago
Here’s how the FTC plans to enforce the Take It Down Act
89d ago
Cisco zero-day under ongoing attack by persistent threat group
90d ago
Pentagon cyber official calls advanced AI ‘revolutionary warfare’
90d ago
White House cyber official: identity security matters more than ever in the age of AI
90d ago
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
91d ago
Researchers say AI just broke every benchmark for autonomous cyber capability
91d ago
Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks
91d ago
DOJ releases legal rationale for nationwide voter data collection
91d ago
Weaponized AI: The new frontier of fraud and identity spoofing
91d ago
Daybreak is OpenAI’s answer to the AI arms race in cybersecurity
92d ago
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
92d ago
Major world economies spell out key elements of AI ‘ingredients list’
92d ago
Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical
92d ago
Google and Amnesty International teamed up to make it harder for spyware vendors to hide
93d ago
AI is separating the companies built to scale from the ones built to sell
93d ago
Instructure claims hackers returned stolen Canvas data after an extortion standoff
93d ago
Google spotted an AI-developed zero-day before attackers could use it
94d ago
The missing cybersecurity leader in small business
94d ago
Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments
96d ago
ShinyHunters claims nearly 9,000 schools affected by Canvas data breach
97d ago
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI
97d ago
Ivanti customers confront yet another actively exploited zero-day
97d ago
Trump officials are steering a cybersecurity scholarship program toward AI
97d ago
American duo sentenced for hosting laptop farms for North Korean IT workers
98d ago
One House Democrat is pressing Commerce on the government’s spyware use
98d ago
A DOD contractor’s API flaw exposed military course data and service member records
98d ago
A critical Palo Alto PAN-OS zero-day is being exploited in the wild
98d ago
179 loaded
LI
LiveOverflow
6d ago · 15 items
Learn Fault Injection at DEF CON 2026
6d ago
Did an AI Really Hack Hugging Face?
16d ago
Security-driven Rapid Release - Pwn2Own Documentary (Part 4)
161d ago
Firefox JIT Bug - Pwn2Own Documentary (Part 3)
164d ago
The First Exploit - Pwn2Own Documentary (Part 2)
168d ago
The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)
171d ago
From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi
491d ago
The German Hacking Championship
517d ago
Do you know this common Go vulnerability?
531d ago
Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1)
666d ago
My theory on how the webp 0day was discovered #short
682d ago
My theory on how the webp 0day was discovered (BLASTPASS)
683d ago
Learn Android Hacking! - University Nevada, Las Vegas (2024)
709d ago
DEF CON & Black Hat Trip 2024
723d ago
Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
934d ago
15 loaded
NE
NetworkChuck
6d ago · 15 items
OSPF From Zero: Let's Build the Internet (Well...Almost) | Summer of CCNA
6d ago
AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA
20d ago
this Raspberry Pi belongs on your wall
20d ago
I got inside FIFA’s Secret World Cup Broadcast Network
24d ago
LIVE AMA | Summer of CCNA | 07/09/2026
34d ago
Fable 5 is back.....run these prompts before July 12th
41d ago
shadow AI is terrifying
54d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
55d ago
HTTPS Doesn't Hide This From Your ISP!!
55d ago
Cisco Just Showed the Future of Networking
56d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
58d ago
I was wrong about VPNs
59d ago
Certification Questions | LIVE AMA | Summer of CCNA
69d ago
Hermes has a Home Assistant skill and it's unreal!
70d ago
FREE coffee at Cisco Live (I'm giving it away)
71d ago
15 loaded
HS
Heimdal Security Blog
7d ago · 15 items
The risk awareness radar. A superpower every MSP needs to train
7d ago
Most of the cyber incidents landing on our desks these days start with someone believing a lie. It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make p...
Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes
14d ago
New data from Heimdal's telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine. The same pattern has been confirmed across more than 40 client environments.
How Heimdal grew from a bold idea into a global cybersecurity platform
14d ago
Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a challenge. Could they create something that could identify vulnerabilities, intercept...
MediaArena malvertising: why a quarantine isn’t the end of the incident
14d ago
If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing i...
Tools Change. Teach People How to Keep Up
16d ago
“Make everyone one percent better and it compounds across the team.” That’s the line Joe Head wrote about his own job and when I read it back to him, he didn’t hesitate. “That is 100% the objective,” he said. Joe runs AI adoption for an 80-...
The 4 best managed EDR service suppliers (and how to choose)
21d ago
There are several cybersecurity companies that offer managed EDR services in 2026. Here’s what actually separates them, and who each one suits. Most successful cyber attacks begin with a breached laptop, a smartphone or a server. Over the p...
Top 4 Best SOC Platforms 2026 – Provider Comparison
22d ago
Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. The...
Top 6 Managed Detection and Response Providers
34d ago
There are several major managed detection and response (MDR) companies to choose from. We’ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a secur...
Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors
36d ago
Your client is no longer just buying your security advice. They’re auditing whether you live by it. That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators...
How to scale your patches without scaling your team (the patch wave)
41d ago
Most breaches don’t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the...
AI didn’t break patching. It showed us patching was already broken.
41d ago
Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes
43d ago
How Dynamic Defense shuts an attacker out without shutting down the business
48d ago
Static security has run out of road. The case for Dynamic Defense
48d ago
Breaking the MSP Echo Chamber: The Power of Community
50d ago
15 loaded
PN
Proofpoint News Feed
9d ago · 10 items
Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats
9d ago
Recognition highlights Proofpoint's deep technical integration with Google Cloud Security solutions and commitment to helping organizations protect people, data and AI Helps
Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities
9d ago
Accelerates OEM innovation by embedding trusted threat intelligence into security products and customer-facing workflows. Helps partners deliver more prioritized,
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
13d ago
New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors
20d ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
21d ago
US and allies say Russian hackers stole emails without social engineering
21d ago
The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of the Zimbra email program without having to fool them into opening an attachment or clicking a link.
If you pay a hacker’s ransom, chances are that they’ll come back for more
22d ago
Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective
22d ago
Global study reveals that AI is amplifying phishing, impersonation and credential theft, transforming ransomware into a human-centric extortion problem 40%
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
30d ago
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
31d ago
BF
Blog – Forter
9d ago · 10 items
Does AI Content Have to be Authentic — or Can It Just Be Effective?
9d ago
What Is Visa’s DCAP? A Merchant’s Guide to Requirements, Benefits, and Rollout
21d ago
The Gray Area in Your Checkout Is Costing You More Than You Think
29d ago
Your Payment Routing Rules Are Making Decisions Without You
35d ago
New at Forter: AI Agents Built to Amplify Your Team
50d ago
Can AI Agents Find, Trust, and Choose Your Brand?
51d ago
IMPACT Roadshow Recap: Getting Ready for Agentic Commerce
64d ago
Agent-Ready: How to Prepare Your Site for AI-Driven Commerce
70d ago
Japan’s 3DS Mandate: One Year In
90d ago
One-Click Refunds Are Not as Hard as You Think
99d ago
HA
Hak5
13d ago · 15 items
The DEF CON Advice Nobody Gives You | Threat Wire
13d ago
OpenAI Turned Off the Guardrails | Threat Wire
14d ago
Meta Logging Every Employee Keystroke | Threat Wire
21d ago
Your Home Internet Has a New Owner | Threat Wire
29d ago
Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire
36d ago
Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire
52d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
52d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
52d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
56d ago
Shark Jacked my LAN 🦈
57d ago
Developers React to the 105-Second Github Chain Reaction | Threat Wire
62d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
63d ago
Introducing Shark Jack Display 🦈
66d ago
The GitHub Leak Situation Just Got Worse | Threat Wire
77d ago
The Worm That Deletes Your Entire Computer | Threat Wire
83d ago
15 loaded
TC
The Cyber Mentors
14d ago · 15 items
Meet TCM Security at DEF CON 34!
14d ago
Real Folks of Cyber | Andrew Crotty | DITL
14d ago
TCM Course Release | New Creator | Cybersecurity | AMA
21d ago
Soft Skills for the Job Market: Applying for Jobs
34d ago
LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway
35d ago
Celebrating 1 Million Subscribers on July 8th!
42d ago
Real Folks of Cyber | Pearce Barry | Day in the Life
48d ago
Getting Started with the TCM Security Academy
48d ago
Soft Skills for the Job Market: Resume Writing
55d ago
TCM Security Summer Sale is Here!
58d ago
LIVE: 🕵️ CTF Prize Draw | Cybersecurity
63d ago
Secrets to PNPT Debrief Success
65d ago
TCM Security CTF Walkthrough
69d ago
Top 5 Active Directory Pentesting Tools
71d ago
Real Folks of Cyber | Dan Berger | Day in the Life
77d ago
15 loaded
M3
Microsoft 365 Blog
14d ago · 10 items
The next measure of AI momentum is work transformed
14d ago
New data from Microsoft 365 Copilot telemetry signals, along with examples from our customers around the world, demonstrate AI transformation in action.
Copilot in Excel: Built for the era of Frontier Finance
49d ago
- Discover how Copilot in Excel transforms finance workflows with skills, data connectors, and capabilities for traceability.
Copilot Cowork is now generally available
58d ago
Copilot Cowork is now generally available worldwide, bringing secure, AI-powered automation for complex enterprise tasks in Microsoft 365.
Introducing Microsoft Scout: Your always-on personal agent
71d ago
Microsoft introduces a new, always-on personal agent, Microsoft Scout, integrated across the Microsoft 365 apps you use every day.
Announcing the new Work IQ APIs
72d ago
Build enterprise agents with Work IQ APIs for Microsoft 365—bringing business context, tools, and secure, scalable intelligence into every workflow.
Introducing Microsoft 365 Business with Copilot: The new standard for small business
76d ago
Meet Microsoft 365 Business with Copilot—the AI-powered solution transforming how small businesses work, collaborate, and compete.
Introducing a new design for Microsoft 365 Copilot
77d ago
Copilot’s redesigned experience delivers faster performance, adaptive tools, and clearer AI-powered workflows to help you easily move from intention to outcome.
New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences
79d ago
Explore what's new in Copilot Studio, May 2026: computer-using agents are now available, plus redesigned workflows and Work IQ extensibility.
New and improved: Agent governance, intelligent workflows, and connected app experiences
93d ago
See what's new in Copilot Studio, April 2026: updates to workflows, more control over agent operations, and an expanded agent usage estimator.
Copilot Cowork: From conversation to action across skills, integrations, and devices
100d ago
Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you.
TM
Trend Micro Research, News, Perspectives
14d ago · 20 items
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility
14d ago
Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave
15d ago
The Signs Were There: What the First Autonomous Ransomware Case Confirms
20d ago
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
21d ago
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
21d ago
Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure
21d ago
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
22d ago
Volume Is Not Risk: Making Sense of the 'Vulnpocalypse'
23d ago
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
30d ago
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
45d ago
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer
51d ago
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
56d ago
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
57d ago
Governing Claude Enterprise in Environments Where Inline Controls Can't Go
62d ago
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026
64d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
66d ago
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
73d ago
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
79d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
83d ago
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
84d ago
20 loaded
DA
darkreading
19d ago · 144 items
CISOs vs. Boards: Myth or Misunderstanding?
19d ago
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
19d ago
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
20d ago
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
20d ago
Europe's Multilingual Reality Exposes AI Security Gaps
20d ago
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
20d ago
Agentic AI Challenges Progress in Confidential Computing
21d ago
Brazilian Banking Trojan Actively Spreading in Portugal
21d ago
Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain
21d ago
Flaws in Passkey Implementation Show Old Attacks Still Work
21d ago
Attackers Are Learning to Live Off the AI Toolchain
21d ago
Fake Bahrain Alert App Deploys Android Surveillance Malware
21d ago
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
22d ago
EU Financial Institutions Leak Data Through Cookie Trackers
22d ago
Ransomware Is Accelerating, but It's Not Because of AI
22d ago
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
22d ago
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
22d ago
Choose Wisely: AI-Generated Coding Risk Varies, a Lot
23d ago
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
23d ago
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
23d ago
Cybersecurity Keeps Events 'Uneventful'
24d ago
Inc Ransomware Exploits SonicWall SMA Zero-Days
26d ago
The Real AI Threat Is Blind Trust
27d ago
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
27d ago
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
27d ago
Agentic AI: Taming the Unpredictable
27d ago
1M+ Emails Use Hidden Text to Dupe AI Security Filters
27d ago
Police Disrupt a €140M Cyber Fraud Ring in Spain
28d ago
Forgotten Bootloaders Expose Secure Boot Blind Spot
28d ago
Identity Attacks Overtake Exploits as Top Ransomware Cause
28d ago
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
28d ago
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
29d ago
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
29d ago
2-Click Cursor Exploit Enables Dev Environment Takeover
29d ago
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
29d ago
Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal
29d ago
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
29d ago
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
29d ago
Manage Vendor Risk in a Few Practical Steps
29d ago
Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?
30d ago
Name That Toon Contest
48d ago
Europe Evolves Into Ransomware's Favorite Region
49d ago
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
49d ago
2026 FIFA World Cup Faces Surge in Cyber Threats
49d ago
Do CISOs Need a Code of Ethics?
49d ago
More Malicious OpenClaw Skills Threaten AI Supply Chain
50d ago
Apple's MacOS Gap Lets Users Disable Security Tools
50d ago
Scope of Salesforce Attacks Expands as Icarus Leaks Data
50d ago
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
50d ago
SocGholish Takedown Highlights Malicious TDS Threats
51d ago
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
51d ago
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
51d ago
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
52d ago
He Thought He Was Secure; His Phone Number Was Stolen Anyway
52d ago
Stressors, AI Forcing Changes to Cybersecurity Teams
55d ago
Novo Nordisk Breach Highlights Software Development Pipeline Risk
55d ago
Operation Escaneo Signals Shift in LatAm Threat Landscape
55d ago
FIFA Bug Exposes World Cup Streams to Remote Takeover
55d ago
Salesforce Data Thefts Continue via Klue App Compromise
56d ago
Get Out of Security Debt by Tackling the Exposure Problem
56d ago
EU Gets a Head Start in Developing 6G Network Security
56d ago
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
61d ago
Claude Fable 5 Doesn't Change the Mythos Security Story
62d ago
Phishing Attack Volume Down 20%, But Risk Still Rising
62d ago
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
62d ago
Segmentation Works for OT If Operators Are Paying Attention
63d ago
Chinese, N. Korean Threat Groups Build on Asia-Pacific Success
63d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
63d ago
Bug Bounty Research Triggers ServiceNow Security Alert
63d ago
AI Risk Worries Insurers & Businesses Alike
63d ago
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
64d ago
The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life
64d ago
Blame AI: Patch Tuesday Hits Record 206 CVEs
64d ago
Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
64d ago
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
64d ago
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
65d ago
AI Slop Will Kill Cybersecurity Storytelling If We Let It
65d ago
Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
65d ago
Check Point VPN Flaw Exploited Since Early May
65d ago
Iran Signed a Ceasefire — Its Hackers Didn't
65d ago
[An RX Global Event] Infosecurity Europe
72d ago
Name That Toon: Mark of (Cybersecurity) Progress
75d ago
Asia's Cyber Insurance Market Shows Signs of Life
76d ago
With Complex Cloud Integrations, Small Errors Lead to Major Compromises
76d ago
'The Com' Cyberattacks Support Violence & Sexploitation
76d ago
As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
76d ago
Dutch Raid Fails to Dent Russian Bulletproof Host
76d ago
Agentic AI Isn't Risky; the Way Orgs Deploy It Is
77d ago
Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security
77d ago
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
77d ago
Nordic CISOs Handle Rising Cyber Threats Remarkably Well
77d ago
Ransomware Actors Show Up In Person to Steal Law Firm Data
77d ago
Latin American Cybercriminals Hoover Up Government Data
78d ago
AI-Assisted Exploit Development Outpaces Scanner Detection
78d ago
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
78d ago
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
78d ago
State Cyber Leaders Push Congress for More Funding, Support
78d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled?
78d ago
For Enterprises, Security Remains Agentic AI's Biggest Challenge
78d ago
The Boring Stuff is Dangerous Now
87d ago
Can Laws Stop Deepfakes? South Korea Aims to Find Out
87d ago
Congress Puts Heat on Instructure After Canvas Outage
89d ago
Cyber Pioneers Ponder Past as Prologue
90d ago
Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems
90d ago
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
90d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
90d ago
'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
91d ago
AI Drives Cybersecurity Investments, Widening 'Valley of Death'
91d ago
Foxconn Attack Highlights Manufacturing's Cyber Crisis
91d ago
Checkbox Assessments Aren't Fit to Measure Risk
91d ago
Attackers Weaponize RubyGems for Data Dead Drops
91d ago
Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak
91d ago
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape
91d ago
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly
92d ago
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
92d ago
It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight
92d ago
Hugging Face Packages Weaponized With a Single File Tweak
93d ago
20 Leaders Who Built the CISO Era: 2 Decades of Change
93d ago
Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
93d ago
How the Story of a USB Penetration Test Went Viral
100d ago
RMM Tools Fuel Stealthy Phishing Campaign
100d ago
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
100d ago
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
101d ago
How Dark Reading Lifted Off the Launchpad in 2006
101d ago
76% of All Crypto Stolen in 2026 Is Now in North Korea
103d ago
If AI's So Smart, Why Does It Keep Deleting Production Databases?
104d ago
Name That Toon: Mark of (Security) Progress
104d ago
20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage
104d ago
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
104d ago
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
104d ago
Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber
104d ago
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
105d ago
Claude Mythos Fears Startle Japan's Financial Services Sector
105d ago
Reverse Engineering With AI Unearths High-Severity GitHub Bug
105d ago
AI Finds 38 Security Flaws in Electronic Health Record Platform
105d ago
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
106d ago
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
106d ago
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
106d ago
NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later
106d ago
Feuding Ransomware Groups Leak Each Other's Data
106d ago
Vidar Rises to Top of Chaotic Infostealer Market
106d ago
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
107d ago
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
107d ago
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
108d ago
144 loaded
TI
Technical Information Security Content & Discussion
19d ago · 318 items
What syscall-layer tooling cannot see in P2P infrastructure
19d ago
Announcing the External Penetration Testing Program Pack
19d ago
The way AI voice phishing gets demonstrated is making people worse at spotting it
20d ago
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
20d ago
XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search
20d ago
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
20d ago
Open Evaluation Framework for AI Pentesting Agents on Real-World Targets
21d ago
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA
21d ago
GitHub issues $100,000 bounty for critical RCE vulnerability
21d ago
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
21d ago
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
22d ago
The Hidden CCS2 Attack Surface on EV Chargers
23d ago
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE)
23d ago
Leaking internal headers in Flask Ninja with deserialization
23d ago
Crawling the Complete IPv4 Reverse DNS Space
24d ago
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)
24d ago
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
24d ago
Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable
25d ago
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner
25d ago
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing
25d ago
White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
26d ago
wp2shell: Pre Authentication RCE in WordPress Core
26d ago
Keeping private namespaces private - Quad9 blog
26d ago
Openwrt pre-auth remote root exploit
26d ago
Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454
27d ago
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
28d ago
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
28d ago
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
28d ago
HN Security - My Semgrep C/C++ ruleset is ready for prime time again
29d ago
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
29d ago
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
29d ago
Smashing the ServiceNow Sandbox – Pre Authentication RCE
30d ago
Context Bombs: Using AI Guardrails as a defensive mechanism
30d ago
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
30d ago
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
31d ago
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
31d ago
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
31d ago
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
33d ago
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
34d ago
Towards CSI: What's the best harness? (arXiv 2026)
34d ago
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
35d ago
1 in 2 devices sold in Africa exfiltrate data to China
35d ago
Inside an AI coal mine security camera network powered by plaintext passwords
35d ago
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
36d ago
Bad Epoll: The bug missed by Mythos
36d ago
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
37d ago
New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"
38d ago
Playing Around With ADIDNS RPC Internals
38d ago
Windows Service - Playbook & Detection Strategies
38d ago
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
42d ago
FIFA was saved this time
42d ago
/r/netsec's Q3 2026 Information Security Hiring Thread
42d ago
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
43d ago
r/netsec monthly discussion & tool thread
43d ago
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
43d ago
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
44d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
44d ago
I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well.
46d ago
Dissecting Apple's Sparse Image Format (ASIF)
46d ago
A peek into Reddit's anti-spam internals
47d ago
CVE-2025-52465 geoserver arbitrary file write vulnerability
49d ago
CargoWise WebTracker - The keys were in the cargo
49d ago
Exploiting vulnerabilities in Johnson & Johnson web apps
50d ago
Cloudflare patches Copy-Fail across every server in two days
51d ago
New Cisco RCE was fixed
51d ago
CVE-2026-25860 turn XSS to RCE
51d ago
Exploiting Auth0 Defaults in XSS Attacks - elttam
52d ago
Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1)
52d ago
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530
54d ago
OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099)
55d ago
Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration
55d ago
CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance
55d ago
Would you like some malware served at the very top of DuckDuckGo?
56d ago
Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update
56d ago
QoS Policies to Restrict EDR Traffic and Detection Strategies
57d ago
Getting a CVE Without Shipping Slop
57d ago
PrizeBuzz phishing network analysis
57d ago
27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass
57d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
58d ago
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
58d ago
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
59d ago
Researcher accidentally gained access to a threat actor-controlled phishing website
60d ago
PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs
60d ago
MeshCentral: From XSS to RCE
60d ago
Getting the PID from random numbers in PHP
61d ago
The Axios npm compromise was visible in registry metadata before anyone ran npm install
61d ago
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs
61d ago
Free Compromise Detection for GitHub Repos - Tracebit Community Edition
62d ago
Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)
62d ago
Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery
62d ago
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs
62d ago
Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules
62d ago
Claude Fable 5: mid-tier results on coding tasks
63d ago
Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work
63d ago
Hacking Google with A.I. for $500,000
63d ago
Prompt injection: attacking the analyst's AI
63d ago
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
63d ago
We post-trained a model for offensive security instead of teaching it to refuse
64d ago
How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026
64d ago
FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster
64d ago
certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA"
64d ago
BlackSun - Defender for Endpoint on macOS
64d ago
GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline)
64d ago
Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam
64d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
64d ago
Apple’s Siri-AI, or more shouting into the void about “private” agents
64d ago
Entra Agent ID from a Security Perspective
65d ago
X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection
65d ago
WinGet - Code Execution, Persistence and Detection Strategies
65d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
65d ago
I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information
65d ago
AI Agents May Always Fall for Prompt Injections
65d ago
Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it
66d ago
EDRChoker: Choking The Telemetry Stream to Bypass Defenses
67d ago
PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware
67d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
67d ago
Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption
69d ago
Keeping Secrets Out of Logs
69d ago
Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier)
69d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
69d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
70d ago
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
70d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
70d ago
Season VI of the US Games launches TOMORROW!
70d ago
EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires
71d ago
Interesting- What LLM vuln research looks like
71d ago
Hacking your PC using your speaker without ever touching it
71d ago
Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing
71d ago
Golang code review notes II - elttam
71d ago
Using AI to Secure Its Generated Code Is a Ponzi Scheme
71d ago
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
71d ago
We Added a Detection Rule. We Were Not Expecting This.
71d ago
1-Click GitHub Token Stealing via a VSCode Bug
72d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
72d ago
NuGet Code Execution As A Service
72d ago
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
72d ago
Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider
73d ago
r/netsec monthly discussion & tool thread
73d ago
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
73d ago
Stealing Passwords via HTML Injection Under a Strict CSP
73d ago
Subnet discovery through multi-protocol TTL tracing
73d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
74d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
74d ago
Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters
75d ago
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
75d ago
Introducing Keyhog: The First GPU Accelerated secret scanner
75d ago
OffensiveCon26 YouTube Playlist released
75d ago
1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog
76d ago
I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found.
76d ago
Fooling around with encrypted reasoning blobs
76d ago
CALIF: An AI audit of FreeBSD
76d ago
CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries
76d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
76d ago
Visual Studio Extensions Revisited
76d ago
Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP)
77d ago
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
77d ago
What scanners are actually trying against AI infrastructure
77d ago
Defense by accumulation
77d ago
New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
78d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
78d ago
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
78d ago
HN Security - AI Reporter - Let's automate reporting in Burp Suite!
78d ago
Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records
78d ago
RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact
78d ago
Navigating Lax Load Balancers: When an Intersection Gets You Inside
79d ago
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents
79d ago
OTP lockout state leaked valid-code signal, enabling OLX account takeover
79d ago
How journalists rely on VPNs to protect press freedom
79d ago
Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
79d ago
Update Starlette Now. New severe vulnerability dropped.
79d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
79d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
80d ago
CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth
80d ago
Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal
80d ago
nmap on Linux: Guide to Network Scanning and Discovery
80d ago
Prompt Injection finally broke my brain a little. My first article as a security student.
81d ago
How to Use Claude AI: A Complete Technical Beginner's Guide
81d ago
Pardon MIE?: how Mythos did not bypass Apple MIE
82d ago
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
82d ago
AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22
82d ago
Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't)
82d ago
Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension
83d ago
Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
83d ago
Data breach in name of protest
83d ago
pnpm 11 Might Finally Be a Better Default Than npm
83d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave
83d ago
[Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled
83d ago
GitHub Actions Cache Poisoning is eating open source
84d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
84d ago
CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
84d ago
FatGid - FreeBSD 14.x kernel LPE
84d ago
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
84d ago
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
84d ago
The IBM X-Force Index 2026 explains all three in one finding.
84d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
85d ago
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
85d ago
[ Removed by Reddit ]
85d ago
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
85d ago
Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online
85d ago
The IBM X-Force Index 2026 explains all three in one finding.
85d ago
GitHub hit by a compromised VSCode extension
85d ago
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
85d ago
We audited 12K n8n templates: most have critical vulnerabilities
85d ago
Veilgate - Deception proxy
85d ago
Sleeping Agent: Silent persistent C2 through Web Push
85d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
85d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
86d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
86d ago
CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing
86d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
86d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
86d ago
The quiet death of behavioral anti-bot and the pivot to hardware ZKPs
86d ago
AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems
86d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
86d ago
The down fall of bug bounties
87d ago
TanStack Supply Chain Attack (And How to Lock Down GitHub Actions)
87d ago
Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation
87d ago
Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation
87d ago
Ansible security and compliance guide
88d ago
Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain
88d ago
AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize.
89d ago
Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works
89d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
89d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems
90d ago
Automating code security reviews with Claude Mythos-level capabilities
90d ago
Instrumenting QT6 desktop apps with Frida - Part 1
90d ago
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
90d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
90d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
91d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
91d ago
CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure
91d ago
How to Check Computer Activity: 2026 Guide for Windows and Mac
91d ago
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
91d ago
Hunting the Behavior Behind npm Supply Chain Attacks
91d ago
WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
91d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
91d ago
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
91d ago
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
91d ago
Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out
91d ago
On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study)
92d ago
A stealth approach to Process Injection - EntryPoint Hijacking
92d ago
A year of Apple Security Bounty research — 16 closed findings, full disclosure
92d ago
AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods
92d ago
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
92d ago
The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop
92d ago
Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
93d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
93d ago
I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
93d ago
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
93d ago
New ipTIME Pre-Auth RCE in CWMP
93d ago
Postmortem: TanStack npm supply-chain compromise
93d ago
How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models.
93d ago
OpenAI announces Daybreak, "frontier AI for defenders"
93d ago
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
93d ago
How I Defeat Passkeys Nearly Every Time in Phishing Assessments
94d ago
MyAudi app:Security issues in Audi Connected Vehicle experience
94d ago
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
94d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
94d ago
Autonomous Vulnerability Hunting with MCP
94d ago
ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement
94d ago
Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple
95d ago
The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
95d ago
Outrunning SHA256 with Physics
95d ago
Memory Poisoning AI Agents via ChromaDB
95d ago
Defence in Depth: A Practical Secure Corporate Network Topology
95d ago
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram
95d ago
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
95d ago
Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection
96d ago
Securing CI/CD for an open source project: lessons from Cilium
96d ago
ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12
97d ago
Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config
97d ago
Copy Fail (CVE-2026-31431): A Technical Deep Dive
97d ago
Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo
97d ago
Dirty Frag - Linux LPE similiar to Copy Fail
97d ago
Honey Tokens: Bait Credentials That Catch Breaches
97d ago
CVE-2026-42511 Breakdown: RCE in FreeBSD
98d ago
Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804
98d ago
An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support)
98d ago
Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI
98d ago
Quacc++: Automated Open Source Vulnerability Discovery
98d ago
Binance fixed the IP whitelist gap — but the disclosure process is still broken
99d ago
Non-Determinism of Maps in Golang: Why, How, and the Consequences
99d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
99d ago
Vulnerability Garden
99d ago
Scan. Secure. Simplify. — Free Web Tools Platform
99d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
99d ago
Salesforce pentesting novel techniques- how to be an apex predator
99d ago
DigiCert: Misissued code signing certificates
99d ago
Major AI Clients Shipping With Broken OAuth Implementations
100d ago
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10
100d ago
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud
100d ago
The Danger of Multi-SSO AWS Cognito User Pools
100d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
100d ago
Proton Pass: Second-Password Bypass Through Emergency Access
100d ago
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
100d ago
Lateral Movement - Cross-Session Activation
101d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
101d ago
Your vibe-coded app is probably violating GDPR right now
101d ago
Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate)
102d ago
How to exfiltrate data using only numeric outputs
103d ago
For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall.
103d ago
Every incident public companies have disclosed to the SEC, in one searchable database
103d ago
r/netsec monthly discussion & tool thread
104d ago
Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster
104d ago
Seventeen vulnerabilities in Omi, fourteen days of silence
105d ago
High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940)
105d ago
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
105d ago
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs
105d ago
The Thymeleaf Template Injection That Only Hurts If You Let It
106d ago
Set up automated dependency scanning after the recent npm/PyPI supply chain attacks
106d ago
A Route to Root in a 4G Industrial Router
106d ago
[Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses)
107d ago
The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords
107d ago
89 vulnerabilities in XAPI / Citrix XenServer
107d ago
[ Removed by Reddit ]
107d ago
Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025)
107d ago
Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary
108d ago
MCPwned: a Burp Suite extension for auditing MCP servers
108d ago
318 loaded
SK
STÖK
21d ago · 15 items
They hacked Google's AI in Seoul
21d ago
☔️🌅
81d ago
Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs
354d ago
Winter vanlife = good times
956d ago
What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth!
962d ago
Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma
969d ago
IS THIS THE END?
1029d ago
Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites
1183d ago
How to turn bugs into a "passive" income stream! ft Detectify's Almroot
1424d ago
HOW DID THIS HAPPEN!? (13370822 LHE VLOG)
1437d ago
Q: How to write a BUG BOUNTY report that actually gets paid?
1554d ago
facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques..
1568d ago
Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!)
1582d ago
Q: HOW do you get started in bug bounty?? How do you build your automation?!
1596d ago
Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR)
1610d ago
15 loaded
CD
Cyber Defense Magazine
24d ago · 95 items
Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack
24d ago
UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker
27d ago
Hacking US Elections: The First Tranche of Declassified Election Integrity Documents
27d ago
Inside Microsoft’s Record-Breaking 622-Bug Release
28d ago
Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook
29d ago
Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure
29d ago
CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers
30d ago
The Threat Mechanism and Mitigation of Pink Vishing Campaigns
31d ago
See It Once, Stop It Everywhere
33d ago
Cybercriminals Targeting World Cup Fans
33d ago
Innovators Spotlight: Brinqa
33d ago
The Cost of Delayed Patching: What Security Teams Are Missing
34d ago
Invoice Fraud Is Now a Cybersecurity Exposure
34d ago
The Chaya_006 Alert: OT Edge Devices Under Fire
43d ago
Nissan Americas Hit in Global Oracle PeopleSoft Data Breach
44d ago
CISA Warns Attackers Are Targeting Critical Internal Business Platforms
45d ago
Return On Risk: The New Measure Of Cyber Resilience
46d ago
Path to StateRAMP
46d ago
Rethinking Identity Security In The Age Of AI Driven Fraud
47d ago
New Age Insider Risk
47d ago
Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure
48d ago
Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To
48d ago
The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer
49d ago
The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target
49d ago
NSA Urges Cyberthreat Timeline Has Compressed From Years to Months
49d ago
Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have
50d ago
Invisible By Design: Making Quantum-Safe Encryption The Easy Path
50d ago
Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming
50d ago
Innovator Spotlight: NAKIVO
50d ago
Cybersecurity Outsourcing. Beyond Cost
51d ago
Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets
51d ago
Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data
51d ago
Data Breach with Eastman Kodak Company
51d ago
The World Cup Is Here… And So Are The Cyber Risks
52d ago
Cloud Managed Services For Modern Cybersecurity To Secure Cloud
52d ago
Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors
53d ago
The Shadow AI Paradox: Governing Innovation At Machine Speed
54d ago
Innovator Spotlight: Ensemble
54d ago
Innovator Spotlight: Centrii
54d ago
NSPM-12: The New Baseline for National Security Cybersecurity
55d ago
Five Compliance Realities Federal Contractors Can’t Ignore
56d ago
Cyber Security Market Insights & Trends Driving The Next Wave Of Protection
57d ago
AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns
57d ago
Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions
58d ago
Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection?
59d ago
CMMC Is Exposing A Major Gap In The Defense Supply Chain
60d ago
Zero Trust For AI In Defense Networks
61d ago
Why Most Cyber Resilience Programs Fail Before The First Incident
62d ago
Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration
63d ago
What The Cybersecurity Industry Knows And Will Not Say
64d ago
Rethinking Access Governance for AI Agents
65d ago
How CIAM Helps Boost Business
66d ago
World Cloud Security Day
66d ago
CMMC Is Here, But AI Changes The Compliance Conversation
67d ago
Cybersecurity Improved Detection But Exposed a New Problem
68d ago
Innovator Spotlight: Airrived
68d ago
Cloud Security In Practice
69d ago
Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing
70d ago
The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector
71d ago
Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit
72d ago
Why Is Cybersecurity Now A Business Priority, Not Just An IT Function?
88d ago
The Security Mistakes Being Repeated With Ai
89d ago
The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract
90d ago
Innovator Spotlight: Klever Compliance
90d ago
Innovator Spotlight: Radware
90d ago
Innovator Spotlight: JScrambler
90d ago
Innovators Spotlight: OPSWAT
91d ago
The Board Is Asking The Wrong Security Question
92d ago
Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification
93d ago
Innovator Spotlight: Iru
93d ago
Innovator Spotlight: Axonius
93d ago
Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge
94d ago
The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface
94d ago
Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI
95d ago
Innovator Spotlight: Lineaje
95d ago
Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care
97d ago
Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered
98d ago
When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity
98d ago
Innovators Spotlight: Badge (Part II)
98d ago
Redefining Security Operations Through Seceon’s Open Threat Management Platform
99d ago
The Insurance Industry Is Rewriting Cybersecurity Strategy
100d ago
Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management
101d ago
Ai Didn’t Break Cybersecurity, It Revealed It
102d ago
RSAC 2026: The Power of Community
103d ago
Inside RSAC 2026
104d ago
Innovator Spotlight: The Open Group
104d ago
Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark
105d ago
Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints
106d ago
Innovator Spotlight: Puneet Bhatnagar
106d ago
Cybersecurity Risks in 2026
107d ago
Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters
107d ago
Innovator Spotlight: TokenCore
107d ago
Platform Engineering: The Rise of a Disciplinary Rethink
108d ago
60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea?
108d ago
From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense
109d ago
95 loaded
TL
The Last Watchdog
29d ago · 34 items
News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations
29d ago
SAN FRANCISCO, July 15, 2026, CyberNewswire – Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been mi...
News alert: Insignary’s on-demand SBOM verification boosts software supply chain security
29d ago
TORONTO, July 15, 2026, CyberNewswire ŌĆō According to Insignary Inc., a leader in software supply chain security and binary software composition analysis (SCA), most organizations cannot independently verify what is actually inside the sof...
News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions
29d ago
TEL AVIV, Israel, July 14, 2026, CyberNewswire – Tego AI, a cybersecurity company, published new research identifying a potentially critical security weakness in Claude Tag, Anthropic’s native integration between Claude and Slack. Resea...
News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI
35d ago
MELBOURNE, Fla., July 8, 2026, CyberNewswire – OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop stan...
News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk
37d ago
TORONTO, July 6, 2026, CyberNewswire тАУ Insignary, Inc., whose patented binary fingerprint technology has been cited in four Gartner research reports, today announced its recognition as a Sample Vendor for Reachability Analysis in the Gart...
News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks
42d ago
FRANKFURT, July 1, 2026, CyberNewswire – Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing ...
News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks
43d ago
BOSTON, June 30, 2026, CyberNewswire – Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, "Securing Third-Party Marketing in the AI Era," taking place July 8 at 9 AM EDT / 3 PM CEST. Every market...
News alert: OpenMatter launches platform to verify AI activity across enterprise systems
43d ago
MELBOURNE, Fla., June 30, 2026, CyberNewswire – OpenMatter Network today announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don't Trust Data. Prove It. ...
News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies
56d ago
AUSTIN, Tex., June 17, 2026, CyberNewswireŌĆōSpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enter...
News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk
56d ago
LONDON, June 17, 2026, CyberNewswire–Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report's headline finding is a divide inside the...
News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails
57d ago
News alert: GitGuardian adds endpoint protection as developer laptops become credential troves
57d ago
News alert: Varist announces AI-scale malware detection for healthcare and medical imaging
58d ago
News alert: Cloud security report finds fragmented tools widening the cloud complexity gap
63d ago
News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces
71d ago
FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential
72d ago
News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit
76d ago
GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet
78d ago
GUEST ESSAY: AI can speed up communication, but it can also weaken human connection
85d ago
News alert: Orchid Security study finds invisible identities now outnumber managed accounts
85d ago
MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack
87d ago
LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back
92d ago
FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread
93d ago
News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents
93d ago
News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market
99d ago
SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents
105d ago
GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control
107d ago
FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures
108d ago
News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category
113d ago
Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one
115d ago
News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security
119d ago
GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags
121d ago
News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk
125d ago
FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense
128d ago
34 loaded
PF
PYMNTS | Fraud Prevention Archives
29d ago · 10 items
78% of CFOs Say Payment Blind Spots Increase Customer Friction
29d ago
85% of CFOs Say Automation Cuts Payments Friction
31d ago
42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million
36d ago
LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud
40d ago
42% of Issuers Say Fraud and Disputes Are Driving Up Costs
42d ago
JPMorganChase and Amazon Back Aspen Institute Drive Against Scams
43d ago
World Cup Gives Cross-Border Payments Their Super Bowl Moment
45d ago
Banks Face a New ACH Fraud Test as Nacha Rules Take Effect
48d ago
The latest Nacha fraud rules require banks to expand fraud monitoring and adopt broader, risk-based oversight across ACH activity.
Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges
48d ago
Nvidia’s AI blueprint maps connections across accounts and devices to catch the fraud network, not just the charge.
AI Forces Compliance Teams to Rethink Alert Strategy
49d ago
FP
Fraud Prevention – Riskified
30d ago · 1 items
WE
WeLiveSecurity
30d ago · 48 items
Forgotten UEFI shims undermining Secure Boot
30d ago
ESET Threat Report H1 2026
36d ago
Cyber readiness for SMBs: Getting the basics right
41d ago
This month in security with Tony Anscombe – June 2026 edition
44d ago
Inside the inbox: Why cybercriminals want to break into your email account
45d ago
SMB cyber readiness: the road to resilience starts here
48d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
49d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
50d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
56d ago
Protecting legacy OT systems against modern cyberthreats
57d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
58d ago
EvilTokens: A phishing attack that doesn’t steal your password
59d ago
OceanLotus: From external espionage to domestic targeting
63d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
64d ago
Cybercriminals: the 'auditors' you never hired
65d ago
Lessons for life: Why children’s data is a long-term identity risk
71d ago
This month in security with Tony Anscombe – May 2026 edition
76d ago
ESET APT Activity Report Q4 2025–Q1 2026
77d ago
What to consider before asking an AI chatbot for health advice
78d ago
BTMOB: A stealthy RAT burrowing deep into Android devices
79d ago
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
83d ago
Webworm: New burrowing techniques
85d ago
The quest for greater tech independence
86d ago
Why geopolitical turmoil is a gift for scammers, and how to stay safe
90d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
91d ago
Eyes wide open: How to mitigate the security and privacy risks of smart glasses
94d ago
Fake call logs, real payments: How CallPhantom tricks Android users
98d ago
Fixing the password problem is as easy as 123456
98d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
100d ago
This month in security with Tony Anscombe – April 2026 edition
105d ago
The calm before the ransom: What you see is not all there is
111d ago
GopherWhisper: A burrow full of malware
112d ago
New NGate variant hides in a trojanized NFC payment app
114d ago
What the ransom note won’t say
115d ago
That data breach alert might be a trap
118d ago
Supply chain dependencies: Have you checked your blind spot?
119d ago
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike
125d ago
As breakout time accelerates, prevention-first cybersecurity takes center stage
128d ago
Digital assets after death: Managing risks to your loved one’s digital estate
134d ago
This month in security with Tony Anscombe – March 2026 edition
135d ago
RSAC 2026 wrap-up – Week in security with Tony Anscombe
139d ago
A cunning predator: How Silver Fox preys on Japanese firms this tax season
139d ago
Virtual machines, virtually everywhere – and with real security gaps
141d ago
Cloud workload security: Mind the gaps
142d ago
Move fast and save things: A quick guide to recovering a hacked account
146d ago
EDR killers explained: Beyond the drivers
147d ago
Face value: What it takes to fool facial recognition
153d ago
Cyber fallout from the Iran war: What to have on your radar
154d ago
48 loaded
AL
Alerts
56d ago · 44 items
CISA Adds One Known Exploited Vulnerability to Catalog
56d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
56d ago
CISA Adds One Known Exploited Vulnerability to Catalog
58d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
59d ago
CISA Adds One Known Exploited Vulnerability to Catalog
62d ago
CISA Adds One Known Exploited Vulnerability to Catalog
63d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
65d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
66d ago
CISA Adds One Known Exploited Vulnerability to Catalog
69d ago
CISA Adds One Known Exploited Vulnerability to Catalog
71d ago
CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
72d ago
CISA Adds One Known Exploited Vulnerability to Catalog
73d ago
CISA Adds One Known Exploited Vulnerability to Catalog
76d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
77d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
78d ago
CISA Adds One Known Exploited Vulnerability to Catalog
79d ago
CISA Adds One Known Exploited Vulnerability to Catalog
83d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
84d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
85d ago
CISA Adds One Known Exploited Vulnerability to Catalog
90d ago
CISA Adds One Known Exploited Vulnerability to Catalog
91d ago
CISA Adds One Known Exploited Vulnerability to Catalog
97d ago
CISA Adds One Known Exploited Vulnerability to Catalog
98d ago
CISA Adds One Known Exploited Vulnerability to Catalog
99d ago
CISA Adds One Known Exploited Vulnerability to Catalog
104d ago
CISA Adds One Known Exploited Vulnerability to Catalog
105d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
107d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
111d ago
CISA Adds One Known Exploited Vulnerability to Catalog
112d ago
CISA Adds One Known Exploited Vulnerability to Catalog
113d ago
Supply Chain Compromise Impacts Axios Node Package Manager
115d ago
CISA Adds Eight Known Exploited Vulnerabilities to Catalog
115d ago
CISA Adds One Known Exploited Vulnerability to Catalog
119d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
121d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
122d ago
CISA Adds One Known Exploited Vulnerability to Catalog
127d ago
CISA Adds One Known Exploited Vulnerability to Catalog
129d ago
CISA Adds One Known Exploited Vulnerability to Catalog
133d ago
CISA Adds One Known Exploited Vulnerability to Catalog
134d ago
CISA Adds One Known Exploited Vulnerability to Catalog
136d ago
CISA Adds One Known Exploited Vulnerability to Catalog
139d ago
CISA Adds One Known Exploited Vulnerability to Catalog
140d ago
CISA Adds One Known Exploited Vulnerability to Catalog
141d ago
CISA Adds Five Known Exploited Vulnerabilities to Catalog
146d ago
44 loaded
AC
All CISA Advisories
56d ago · 125 items
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
56d ago
CISA Adds One Known Exploited Vulnerability to Catalog
56d ago
Schneider Electric EasyLogic T150 and Saitel DP
56d ago
AVer PTC cameras
56d ago
Rockwell Automation FactoryTalk Historian Site Edition
56d ago
AzeoTech DAQFactory
56d ago
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
56d ago
Mitsubishi Electric MELSEC iQ-F Series
56d ago
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
56d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
56d ago
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
58d ago
Rockwell Automation RSLinx
58d ago
Rockwell Automation FLEX I/O EtherNet/IP Adapters
58d ago
Rockwell Automation FactoryTalk Analytics PavilionX
58d ago
Rockwell Automation CompactLogix
58d ago
CISA Adds One Known Exploited Vulnerability to Catalog
58d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
59d ago
CISA Adds One Known Exploited Vulnerability to Catalog
62d ago
Yarbo Android/iOS Mobile Application and Cloud Infrastructure
63d ago
Naxclow IoT Platform
63d ago
Brickcom Cameras
63d ago
CISA Adds One Known Exploited Vulnerability to Catalog
63d ago
Siemens KACO Blueplanet Inverters
65d ago
Schneider Electric EcoStruxure Panel Server
65d ago
Schneider Electric Modicon Network Managed Switches
65d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
65d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
66d ago
CISA Adds One Known Exploited Vulnerability to Catalog
69d ago
NAVTOR NavBox
70d ago
Hitachi Energy MACH HiDraw
70d ago
Hitachi Energy ITT600 Explorer
70d ago
B&R PPT30 Operating System
70d ago
Hitachi Energy RTU500
70d ago
CISA Adds One Known Exploited Vulnerability to Catalog
71d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
72d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
72d ago
CISA Adds One Known Exploited Vulnerability to Catalog
73d ago
CISA Adds One Known Exploited Vulnerability to Catalog
76d ago
ABB EIBPORT
77d ago
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
77d ago
ABB Busch-Welcome 2 Wire Door Opener Actuator
77d ago
Fourth Frontier Frontier X Mobile Application, Frontier X2
77d ago
CP Plus 8 Ch. Network Video Recorder
77d ago
XCharge C6
77d ago
KMW CCTV Security Cameras
77d ago
MacGregor Voyage Data Recorder (VDR) G4e
77d ago
Schnieider Electric EcoStruxure Machine Expert HVAC
77d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
77d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
78d ago
ABB Terra AC
79d ago
ABB LVS MConfig
79d ago
ABB Ability Camera Connect
79d ago
Eppendorf BioFlo 320
79d ago
ABB AbilityTM Zenon Remote Transport Vulnerability
79d ago
ABB AC500 V2
79d ago
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
79d ago
CISA Adds One Known Exploited Vulnerability to Catalog
79d ago
CISA Adds One Known Exploited Vulnerability to Catalog
83d ago
ABB Terra AC Wallbox
84d ago
Hitachi Energy GMS600
84d ago
ABB B&R Automation Studio
84d ago
ABB B&R Automation Runtime
84d ago
ABB B&R PCs
84d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
84d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
85d ago
Kieback & Peter DDC Building Controllers
86d ago
Siemens RUGGEDCOM APE1808 Devices
86d ago
ABB CoreSense HM and CoreSense M10
86d ago
ScadaBR
86d ago
ZKTeco CCTV Cameras
86d ago
CISA Adds One Known Exploited Vulnerability to Catalog
90d ago
Siemens Siemens ROS#
91d ago
Siemens gWAP
91d ago
Siemens SIMATIC
91d ago
Siemens Ruggedcom Rox
91d ago
Siemens Ruggedcom Rox
91d ago
Siemens Simcenter Femap
91d ago
Universal Robots Polyscope 5
91d ago
Siemens Ruggedcom Rox
91d ago
Siemens Teamcenter
91d ago
Siemens Solid Edge
91d ago
Siemens SENTRON 7KT PAC1261 Data Manager
91d ago
Siemens Opcenter RDnL
91d ago
Siemens Ruggedcom Rox
91d ago
Siemens SIMATIC S7 PLC Web Server
91d ago
Siemens Industrial Devices
91d ago
Siemens SIMATIC
91d ago
Siemens SIPROTEC 5
91d ago
CISA Adds One Known Exploited Vulnerability to Catalog
91d ago
Software Bill of Materials for AI - Minimum Elements
93d ago
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
93d ago
Subnet Solutions PowerSYSTEM Center
93d ago
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities
93d ago
ABB AC500 V3 Multiple Vulnerabilities
93d ago
ABB Automation Builder Gateway for Windows
93d ago
Fuji Electric Tellus
93d ago
CISA Adds One Known Exploited Vulnerability to Catalog
97d ago
CISA Adds One Known Exploited Vulnerability to Catalog
98d ago
MAXHUB Pivot Client Application
98d ago
CISA Adds One Known Exploited Vulnerability to Catalog
99d ago
ABB B&R Automation Studio
100d ago
ABB B&R Automation Runtime
100d ago
Hitachi Energy PCM600
100d ago
Johnson Controls CEM AC2000
100d ago
ABB B&R PVI
100d ago
CISA Adds One Known Exploited Vulnerability to Catalog
104d ago
Careful Adoption of Agentic AI Services
104d ago
ABB AWIN Gateways
105d ago
ABB Ability OPTIMAX
105d ago
ABB PCM600
105d ago
ABB Edgenius Management Portal
105d ago
CISA Adds One Known Exploited Vulnerability to Catalog
105d ago
ABB Ability Symphony Plus Engineering
105d ago
ABB System 800xA, Symphony Plus IEC 61850
105d ago
Adapting Zero Trust Principles to Operational Technology
106d ago
NSA GRASSMARLIN
107d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
107d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
111d ago
SpiceJet Online Booking System
112d ago
Carlson Software VASCO-B GNSS Receiver
112d ago
Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera
112d ago
Milesight Cameras
112d ago
Defending Against China-Nexus Covert Networks of Compromised Devices
112d ago
Yadea T5 Electric Bicycle
112d ago
Intrado 911 Emergency Gateway (EGW)
112d ago
125 loaded
CY
cybersecurity
62d ago · 1867 items
Any solutions we can use?
62d ago
Possible targeted attack
63d ago
RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline
63d ago
Facebook messenger to text
63d ago
Managing Solution Agents
63d ago
Nottingham University data breach affects over 450,000 students
63d ago
SWGs that support 3rd party external DNS resolver
63d ago
Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers
63d ago
Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG
63d ago
Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch
63d ago
Phishing awareness training resulting in ignoring company comms?
63d ago
How are you analyzing Android malware nowadays?
63d ago
Hackers Exploit Langflow Vulnerability for Remote Code Execution
63d ago
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research
63d ago
NEED SOME GUIDANCE
63d ago
Help setting up local encryption on my pc
63d ago
Agentic AI on Cybersecurity
63d ago
DoD 0-days Typically Come Down to Authorization Failures
63d ago
HDD
63d ago
Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets
63d ago
How can we test the firmware code/images security?
63d ago
20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004
63d ago
GitHub announces npm security changes to tackle supply-chain attacks
63d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
63d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
63d ago
What is the difference between Regular TLS and Mutual TLS?
63d ago
Every employee's password was stored in a single Excel file
63d ago
npm v12 is changing how dependencies are installed to reduce supply-chain risk
63d ago
Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia?
63d ago
How good Microsoft Defender for storage?
63d ago
GreatXML bitlocker bypass vulnerability
63d ago
Struggle
63d ago
Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications?
63d ago
Wiz launches Cloud Security Job Board
63d ago
Physical Project Ideas
63d ago
How can I get into cybersecurity while studying Information Systems Engineering?
63d ago
Cloud Security job board
63d ago
Continuous learning
63d ago
Angry bug hunter with Microsoft beef drops new Windows 0-day
63d ago
Mid-30s, stuck in web pentesting, and wondering what to do ?
63d ago
Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM
63d ago
Is Microsoft Purview really secure when using Copilot?
63d ago
Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature?
63d ago
Nee academic references for Hashcat's 'Next Big Bang' log
63d ago
CISA released BOD 26-04: A new federal government vulnerability management strategy?
63d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
64d ago
added Mac support to my corporate hacking sim. Demo now available on Steam
64d ago
Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte)
64d ago
Students' data taken in major University of Nottingham cyber-attack
64d ago
Has unmanaged external file sharing ever burned you?
64d ago
Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers
64d ago
Need feedback on my presentation
64d ago
Compensating controls besides admin credentials being needed to download software on employee endpoints
64d ago
OpenSSL PKCS#7 CVE-2026-45447
64d ago
Presentation Question
64d ago
How to Stay Ahead of Deepfake Evolution in 2026
64d ago
France’s Government Messaging App Tchap Got Breached
64d ago
Where's the fix for MiniPlasma?
64d ago
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
64d ago
Internships
64d ago
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
64d ago
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
64d ago
Looking for a Reliable Cybersecurity Provider for a School in North Sydney
64d ago
Early Operational Visibility
64d ago
how are you actually managing ai agents in production?
64d ago
Al app builders: How are you handling security questionnaires when selling your product?
64d ago
[ Removed by Reddit ]
64d ago
How are all of doing with THE AI model thats big news currently??
64d ago
Skill to Scan your Codebase
64d ago
Miasma-style supply chain attacks
64d ago
FCaptcha v1.12: Catching AI Agents That Drive Real Browsers
64d ago
Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones
64d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
64d ago
AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say
64d ago
Huntress Stack (MS Defender or SentinelOne)
64d ago
META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT
64d ago
FBI is announcing Operation Riptide
64d ago
ServiceNow confirmed some customer instances were breached.
64d ago
Which are some of the best Cybersecurity / OT Security events that happen in GCC?
64d ago
DF/IR Community
64d ago
Chaotic Eclipse's new RoguePlanet
64d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
64d ago
Thoughts on Automated Compliance?
64d ago
A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available
64d ago
North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says
64d ago
Microsoft has released a patch for the bitlocker bypass
64d ago
Please advices
64d ago
soc analyst l1
64d ago
Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow
64d ago
Looking to move off KnowBe4, what are people actually using these days?
64d ago
Too Many Certs, Not Enough Experience — What’s the Best Next Step?
65d ago
Authenticating ARP and NDP
65d ago
Does anyone use rule feeds in 2026?
65d ago
Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations!
65d ago
Need a vm for practice
65d ago
Tips/Tricks to WFH as a SOC Analyst?
65d ago
Cybersecurity statistics of the week (June 1st - June 7th)
65d ago
Where can GRC folks learn practical AppSec / DevSecOps without going full engineer?
65d ago
I almost got “onboarded” into a malware campaign disguised as a job opportunity.
65d ago
University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model
65d ago
AI Blocklist - help
65d ago
Protecting AI workloads on Linux servers
65d ago
Exposing DoNex Ransomware Secrets with Malcore!
65d ago
What are the different Disaster Recovery scenarios your teams have tested on?
65d ago
someone actually leaked the Miasma supply chain attack toolkit source code on github
65d ago
WinGet - Code Execution, Persistence and Detection Strategies
65d ago
Ransomware attack shuts Illinois high school until Wednesday
65d ago
Ideas for demo
65d ago
Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please?
65d ago
Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares.
65d ago
Physical attack device
65d ago
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
65d ago
IT GRC News?
65d ago
Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again
65d ago
Shifting L7 validation to the edge to stop DB resource exhaustion?
65d ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
65d ago
EC Council CEH exam advice
65d ago
About NPower vs PerScholas
65d ago
Looking for a vulnerability to learn
65d ago
From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk
65d ago
Bad USB through charger?
65d ago
Recommendations for Discord community for latest AI security products
65d ago
Vulnerability Summary for the Week of June 1, 2026
65d ago
Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas
65d ago
I feel like ive lost my passion to tinker after 6 years in the industry, anyone else?
65d ago
I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples
65d ago
really need help with project ideas for MSc
65d ago
Which Course for an almost-complete noob? (SANS.edu)
65d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
65d ago
For the 2nd time in weeks, Microsoft packages laced with credential stealer
65d ago
Iran Signed a Ceasefire — Its Hackers Didn't
65d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
65d ago
DSPM étude marche
65d ago
CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file
65d ago
AppSec / Pentesting job market in Canada for experienced overseas applicants?
65d ago
Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients.
65d ago
Automation Playbooks - which ones would you not want to live without?
65d ago
Is it necessary/important to Hash and salt API Keys for a strictly internal use tool?
65d ago
Need review on the OMS Cybersecurity program from Georgia Tech?
65d ago
If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk
65d ago
2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years
65d ago
How do you close an alert
65d ago
What cybersecurity certifications are great value for money?
65d ago
Boxes for CPENT
65d ago
SIEM: is it "SIM" or "SEEM"
65d ago
I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included)
65d ago
How justdeleteme and justgetmydata work?
65d ago
I need help - PCI DSS 4.0 requirement 11.6.1
66d ago
How are you learning agent pen testing?
66d ago
Cyber security intern
66d ago
Meta to take legal action against Israeli spyware company NSO
66d ago
Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit
66d ago
What's the best way to alert companies of a Glassworm copycat?
66d ago
How To Verify If A Site Is Legit?
66d ago
What is Flaresolverr
66d ago
Research: defenders using generative AI to simulate malware variants before they exist in the wild
66d ago
How are regulated orgs actually letting engineers use Claude Code / Copilot?
66d ago
Cyber security expo Manchester
66d ago
Remote Hiring Opened the Talent Pool — and the Fraud Surface
66d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
66d ago
What certs should I do during summer of 11th grade?
66d ago
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
66d ago
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine
66d ago
Oxford University discloses data breach after careers platform hack
66d ago
Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing
66d ago
Got this message from “SimBoss”
66d ago
PKCS12 Golang fork
66d ago
Malware Insights: Miasma Campaign
66d ago
73 Microsoft GitHub repositories impacted by Miasma malware
66d ago
[Honeypot Research] Looking for volunteers to test telemetry/logs
66d ago
What is the condition of Bug Bounty program in the era of AI.
66d ago
Opening a cloned repo is no longer safe
66d ago
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
66d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
66d ago
Google Colab CLI opens runtimes to Claude Code and Codex
66d ago
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
66d ago
The AI governance gap no one is talking about: deployment-stage accountability
66d ago
Free Study Resources for Comptia Cysa+
66d ago
Mentorship Monday - Post All Career, Education and Job questions here!
66d ago
Hi there
66d ago
Final risk-based IT Audit interview round with Director and have no experience. Please help!
66d ago
Needed help
66d ago
[ Removed by Reddit ]
66d ago
Career advice
66d ago
PhD in cyber Security
66d ago
Built a password guessing game. Almost everyone stuck in level 5.
66d ago
OSINT (SOCIAL MEDIA)
66d ago
Beginner KQL project
66d ago
Question about WORM and encryption
66d ago
Update:Certified cyber security
66d ago
Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental
67d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction)
67d ago
Malware that survives reinstalling the BIOS and OS
67d ago
Am I overthinking the x86 compatibility issues? how much friction am I actually facing?
67d ago
Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure
67d ago
Managing Microsoft Identity Is More Complicated Than It Looks
67d ago
My work email got subscribed to a bunch of israel newsletters
67d ago
Shadow AI
67d ago
Rate limiting is not enough. What else can I use?
67d ago
How To Avoid Potential Malware From Transferring To New Laptop
67d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
67d ago
Can't decide.
67d ago
looking for partners
67d ago
My edge is changing into bing when I search something
67d ago
Cybersecurity reality check
67d ago
[ Removed by Reddit ]
67d ago
Information Management
67d ago
IronWorm Malware
67d ago
Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh?
67d ago
Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh?
67d ago
Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager
67d ago
Is a separate “clean” S3 bucket actually a security boundary for uploaded files?
67d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
67d ago
PenTest+ Exam
67d ago
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
67d ago
Looking for guidance
67d ago
Before you attempt any OffSec certification, read what just happened to me
68d ago
Reporting Metrics for Management
68d ago
got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time
68d ago
Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried
68d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
68d ago
AI Security Certificates
68d ago
Guys is bug bounty dead?
68d ago
How are folks making it in bug bounty?
68d ago
How useful is it to require at least one uppercase letter in a password?
68d ago
Cyber security ! Is no more ?
68d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
68d ago
Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months
68d ago
Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories
68d ago
How to train employees to feel when something's off?
68d ago
ALERT OVERLOAD
68d ago
CTO at NCSC Summary: week ending June 7th
68d ago
A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled
68d ago
Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub
68d ago
AppSec Engineer Interview Stories
68d ago
[OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps.
68d ago
Is there a safe way to continue using (unsupported) Windows 10?
68d ago
Is Splunk suitable for smaller Enterprises?
68d ago
Has anyone else had MFA prompt fatigue issues with users?
68d ago
Data Scrubbing from Databases
68d ago
Best Certificates?
68d ago
Rant
68d ago
New York passes data center moratorium and consumer protections as environmental, and housing proposals stall
68d ago
Cyber attackers have a new favorite, the browser
68d ago
Looking to get into cybersecurity in web3
68d ago
Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests
68d ago
Should i use email 2fa or only auth and phone number?
68d ago
Can I break into cybersecurity with a white collar felony?
68d ago
Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale
68d ago
How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time?
68d ago
What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent?
68d ago
How Hard is This
68d ago
Installed Fake Codex hidden as a google site
68d ago
Virustital scan result help
68d ago
CrowdStrike Turned an AI Wave Into Its Best Quarter Ever
68d ago
Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions?
68d ago
I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now
68d ago
Being a Security Engineer? Which AI-powered tools are you using on a daily basis?
69d ago
Over 900 US gas station tank gauge systems exposed to attacks
69d ago
Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person
69d ago
SIEM is broken in the AI agents era
69d ago
Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected
69d ago
Phantom Gyp npm Worm Abuses node-gyp Build Hooks
69d ago
Certified cybersecurity ISC2
69d ago
Help studying for OSCP
69d ago
The current state of Threat Intelligence Tooling
69d ago
Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware
69d ago
We tested offensive AI agents against deception technology
69d ago
A matter that I have been losing my sleep over
69d ago
Any experience with Rootly or incident.io for cyber incident management?
69d ago
CTIA Study Resources & Preparation Advice?
69d ago
Black hat uk vs brucon
69d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
69d ago
NIS2 hits railway hard
69d ago
I need help guys… :(
69d ago
Question from the Seniors
69d ago
China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware
69d ago
what certs have u seen in ai security related job posts ?
69d ago
How is the Security Architecture / Strategic IT Security process structured in your organization?
69d ago
What's happening in cybersecurity job market in US and Europe these days?
69d ago
Has any of you pivoted from GRC to CTI?
69d ago
Up-date-list of cybercrime types?
69d ago
What else should I learn to build a strong cybersecurity foundation?
69d ago
Hackerone interview
69d ago
Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix
69d ago
Testing URL Rewriting?
69d ago
Got an internship in IAM with no qualifications and no soft skills
69d ago
Work Hours of DFIR/Cloud Security vs Pentest
69d ago
Narcissistic Tech Leader....
69d ago
Anyone else's firewall logs just explode after midnight?
69d ago
I'm replacing myself.. at least the boring parts
69d ago
Anyone else dealing with these phantom login attempts from China?
69d ago
Best way to fully clear windows and set everything up securely (pc, accounts etc)
69d ago
IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks
69d ago
Soc analyst
69d ago
Do companies actually require cybersecurity insurance
69d ago
Uncommon/Unusual CrowdStrike Alerts
69d ago
Cyber analyst: law firm or bank
69d ago
best free av and how do i properly setup passwords?
69d ago
Five 9 Vulnerability
69d ago
CVE Lite CLI closes dependency gap — but won't stop modern threats
69d ago
Scope change
69d ago
We just stopped a social engineering attack on our service desk. Here’s how it played out.
69d ago
What is the most underestimated cybersecurity risk right now?
69d ago
Update: Company is paying for any certification, which should I obtain? Except Sans
70d ago
New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification
70d ago
Anyone else's firewall vendor docs a total nightmare?
70d ago
Your opinions about a learning style
70d ago
Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks
70d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
70d ago
Anyone else see their firewall logs just explode after a cloud update?
70d ago
Are certifications necessary to get a job in cybersecurity?
70d ago
Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass)
70d ago
Is retyping and translating textbooks too inefficient for CS/Cybersecurity?
70d ago
Free Microsoft Enterprise Security Assessment: Worth It
70d ago
How are organizations preparing for AI-generated phishing attacks?
70d ago
Inside the race to adapt to an AI-powered security world
70d ago
127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For
70d ago
Microsoft blames unexpected Windows driver updates on caching issue
70d ago
Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance)
70d ago
Your CPU model leaks through the browser via WASM timing differences
70d ago
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
70d ago
Security Engineer 2 interview at Amazon coming up - What to expect?
70d ago
A researcher spent $1,500 testing if LLMs could hack a vulnerable app
70d ago
Help with university internship
70d ago
Are MCP servers becoming the next API security nightmare?
70d ago
What's the cybersecurity lesson you learned the hard way?
70d ago
ISO 27001 Surveillance audit vs Full recertification
70d ago
How important it is to get paid Cybersecurity certificates ?
70d ago
Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process
70d ago
Soc to Architecture
70d ago
Does "example file vulnerability" exists?
70d ago
VS code forces 2 hour cool down for most integrations.
70d ago
Company laptop isolated after Brave/Tor alert - should I be worried?
70d ago
Does anyone know how to send false positive to SOCradar ? virus total
70d ago
Looking for people to team up for Bug Bounties & CTFs
70d ago
Signal Without Smartphone
70d ago
I found a trojan on my pc and now im scared my private calls got leaked
70d ago
Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests
70d ago
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
70d ago
How do you change users behavior through awareness training?
70d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
70d ago
Safe Rust API for wolfSSL/wolfCOSE
70d ago
Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma)
70d ago
AMD GPU Users might be compromised
70d ago
[ Removed by Reddit ]
70d ago
Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information
70d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
70d ago
[CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF
70d ago
how to get good at cyber security?
70d ago
Anyone use CrunchAtlas?
70d ago
Prompt monitoring laughs
70d ago
Malicious Payload in ai-sdk-ollama npm Package
70d ago
Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24)
70d ago
what the HELL is dsztfso?
70d ago
Yubikey Alternative....?
70d ago
Hiring
70d ago
CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing
70d ago
Certification Advice
70d ago
Question about Linux kernel TLS ULP disclosed June 2 to oss-security
70d ago
An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this?
70d ago
How to Rob a Data Center (new article on data center physical security)
70d ago
US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server
70d ago
Is it worth taking the EC councils masters program?? Are they legit /2026
70d ago
Mid-level AppSec engineers: what do you actually study to prep for interviews?
70d ago
Company is paying for any certification, which should I obtain?
70d ago
Trusting Microsoft with your offensive security repos
70d ago
Automated Fault Injection Attack Framework
70d ago
Physical Biometric device as a security measure..??
70d ago
Cybersegurança
70d ago
Started Learning Cybersecurity
70d ago
InfraGard Application - Seeking Help | Student
70d ago
Orientación en Ciberseguridad
70d ago
Anthropic's coordinated vulnerability disclosure dashboard
70d ago
Hands Free: What LLM Driven Vulnerability Research Looks Like
70d ago
Real time Cybersecurity failures regarding Quantum computing/cryptography
71d ago
🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It.
71d ago
A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out.
71d ago
CISA warns of active attacks exploiting Android, Linux bugs
71d ago
Found some open ports on a govt site, should i report or stay quiet?
71d ago
What is a good way to keep track of passwords for programs that don't support password managers?
71d ago
Cybersecurity statistics of the week (May 25th - May 31st)
71d ago
ASN Emissions Index. Networks ranked by how much noise they create on the internet.
71d ago
Have you sold cve before?
71d ago
i want to become a pentester, but i don't know how to
71d ago
The OT Security Problem Nobody Wants to Own
71d ago
Don't Take Wednesday Off When You Manage Vulnerabilities
71d ago
I finally finished a production version after 4 yrds
71d ago
Support role pivot to cloud security
71d ago
How do you manage your passwords?
71d ago
Mad rush to produce AI driven slop
71d ago
O Tails é seguro para acessar links suspeitos?
71d ago
Cyber Essentials plus + "legacy" network segments
71d ago
Insight for OPSWAT deep CDR
71d ago
Android vs iOS
71d ago
ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account
71d ago
Security Audits at an MSP
71d ago
[ Removed by Reddit ]
71d ago
Passkey registration breaks after moving off localhost..
71d ago
Does your team hire fresh AI engineer who doesn't know anything about Security operations?
71d ago
UARs for Equation (banking system)
71d ago
IoT pentesting cert
71d ago
Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations
71d ago
Experience with Tac Security
71d ago
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
71d ago
Found Security Vulnerabilities in my university website
71d ago
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence
71d ago
AI - Threat to the CyberSec Industry?
71d ago
Built a honeypot platform to catch lateral movement. How are you guys detecting this?
71d ago
How should small SaaS teams safely answer customer security questionnaires?
71d ago
Can AI Do Intelligence Analysis? Apparently Not.
71d ago
PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model
71d ago
Regarding Certified Ethical Hacker (CEH Practical) exam
71d ago
Asking for advices on pursuing first CERTIFICATE
71d ago
I opened my own company and I can't find clients!
71d ago
ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter
71d ago
Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU?
71d ago
Anyone knows Quad9 dns ?
71d ago
I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ?
71d ago
Greynoise swarm
71d ago
SecOT+ certification for free
71d ago
How is the state of the job market for mid-level security engineers?
71d ago
Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things
71d ago
WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total
71d ago
Laid off from TPRM job - need help on the future of my career
71d ago
Anyone compared RoboShadow vs ConnectSecure for vulnerability management?
71d ago
Any one send vulnerability to MITRE?
71d ago
Need advice for a 30 min Security Apprenticeship interview
71d ago
UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS
71d ago
Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match
71d ago
Virustotal API as private data source
71d ago
Account Number Security Flaw
72d ago
Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning?
72d ago
A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth
72d ago
[ Removed by Reddit ]
72d ago
[ Removed by Reddit ]
72d ago
Phishing simulation platform
72d ago
Just task about OSI model
72d ago
Need help improving DNS Spy from a security tool angle
72d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
72d ago
Oracle's first monthly patch update just dropped 77 CVEs.
72d ago
Cleaning up after a legacy service account breach. How are you handling automated secrets discovery?
72d ago
Airbus digital apprenticeship
72d ago
Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities
72d ago
Google fixes one actively exploited Android zero-day, 124 flaws
72d ago
Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force
72d ago
Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis?
72d ago
Security Architects who who actively use modelling - What's your approach?
72d ago
PAN-OS authentication bypass bug added to list of exploited vulnerabilities
72d ago
I have extreme anxiety about being hacked
72d ago
Fresher
72d ago
Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach
72d ago
Career advice needed!
72d ago
GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
72d ago
Google sr. security engineer interview
72d ago
Is offensive AI actually changing cybersecurity, or are we overestimating the impact?
72d ago
Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave
72d ago
is emerald chat safe?
72d ago
Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ?
72d ago
ClickJack in the wild
72d ago
Thoughts on A.I assisted Malware Analysis?
72d ago
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
72d ago
What articles do you use for cybersecurity news? (2026)
72d ago
Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider?
72d ago
Roadmap and Training Recommodation
72d ago
Les anti-triche de niveau noyau et leur risque de sécurité
72d ago
Asked to Send Sensitive Documents via MMS
72d ago
SC-200 compared to CC (isc2)
72d ago
Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now
72d ago
Looking to move off KB4, what are people actually using these days?
72d ago
Got my Security+. What's next?
72d ago
Vulnerability Summary for the Week of May 25, 2026
72d ago
Malware
72d ago
Alternative Search Engine to Utilize in 2026?
72d ago
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
72d ago
Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild
72d ago
Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers
72d ago
AI compliance
72d ago
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
73d ago
Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains?
73d ago
MacBook or Windows Laptop for Cybersecurity
73d ago
What's the most creative MFA bypass you've seen?
73d ago
Research Notes from Building a Windows Event Log Hunting Workflow
73d ago
How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ??
73d ago
Free AI tools for TPRM?
73d ago
incomplete phone number from togo, need help reporting to police
73d ago
NPM packages from RedHat Compromised
73d ago
Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts
73d ago
SOC Analyst working towards Threat Intelligence
73d ago
Is XSS possible through PDFs?
73d ago
The Next AI Governance Failure Won’t Be the Model
73d ago
Microsoft MFA Is Down Again
73d ago
Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927)
73d ago
Computer logic or Science
73d ago
I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for?
73d ago
What C2s Are You Using
73d ago
PNPT Exam
73d ago
What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification?
73d ago
Any appsec engineer working in fortune 500?
73d ago
I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next
73d ago
Anyone transition from AWS Data Center Operations to InfoSec?
73d ago
I think my account got hacked but it's weird
73d ago
current market for detecting deepfakes?
73d ago
Worried about friend being doxxed on doxbin
73d ago
how to shift from a service based company to a product based one in cybersecurity ?
73d ago
Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA
73d ago
Claude AI user data directory exfiltration via malicious npm package
73d ago
Bitdefender blocking amd stuff? False positive or?
73d ago
Mentorship Monday - Post All Career, Education and Job questions here!
73d ago
did they have my password?? what triggers this specific email??? instagram HELP.
73d ago
ATTENTION: Dashlane may have been breached. (Password manager).
73d ago
Norton blocked a “malicious script”?
73d ago
Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts
73d ago
Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive.
73d ago
I wrote about the 5 biggest threats in 2026, curious what this community thinks.
73d ago
MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce?
73d ago
Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions?
73d ago
NetworkChuck
73d ago
LLM for creating phishing tool
74d ago
Why are we still treating IAM like a compliance checkbox?
74d ago
Polyfill pop up?
74d ago
SecAI+ difficulty question
74d ago
Could you guys give an honest feedback to a completely automated ssrf attack tool?
74d ago
tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me
74d ago
Microsoft Joined the DMARC Club
74d ago
Help.
74d ago
Vibe Coding Security
74d ago
Looking for a Company to Partner With
74d ago
Best reporting tools?
74d ago
What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months)
74d ago
How Can Polyfill.io Still Act Maliciously?
74d ago
Need THM voucher code for cheap? Any known seller?
74d ago
Ghost passwords?
74d ago
Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not.
74d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
74d ago
Anyone else having Chatgpt Strikes / Violations while learning cybersecurity?
74d ago
Working at Cisco, worth it?
74d ago
Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice
74d ago
Are you pen testing AI Agents?
74d ago
Question of android malware
74d ago
External attack surface: how are you correlating DNS, SSL, and IP reputation today?
74d ago
how do i properly setup 2fa and bitwarden?
74d ago
Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC)
74d ago
i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested?
74d ago
Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever?
74d ago
Can Steam Cloud Files Transfer Malware
74d ago
Questions for the cloud security engineers
75d ago
Thoughts on this as a starter and doing bug bounty on the side
75d ago
How are new SC-200 candidates practicing labs without an E5 Developer tenant?
75d ago
Getting OTP spammed from every app and website I've ever used. Should I be worried?
75d ago
A browser tool for checking contractor insurance certificates
75d ago
Am I getting screwed?
75d ago
SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers
75d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
75d ago
CTO at NCSC Summary: week ending May 31st
75d ago
BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship
75d ago
Need suggestion
75d ago
[INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety)
75d ago
Was Dave Bittner interviewing an AI?
75d ago
CTF for complete beginner
75d ago
Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques?
75d ago
AI-Era Cyber Risk Standards
75d ago
BEC Victim - Attacker replied inside a real email thread using a lookalike domain
75d ago
Question for those who transitioned from remote to work from anywhere
75d ago
Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors
75d ago
Do you enjoy what you do or do you wish you could go back in time and change it?
75d ago
Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber?
75d ago
For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year?
75d ago
Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ?
75d ago
Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years?
75d ago
Botnet of more than 17 million devices dismantled
75d ago
Exposed credentials on logs
75d ago
What do you think is the biggest cybersecurity risk for small businesses in 2026?
75d ago
Wanted to shift to cloud security, but have some questions
75d ago
Zero Trust is Overrated? Navigating the Complexity
75d ago
Test API post with flair
75d ago
Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications
75d ago
How Do You Handle the Massive Amount of Information in the CPTS Path?
75d ago
Help an upcoming cybersecurity engineer!
76d ago
Repeated Microsoft MFA attempts even after password change
76d ago
What Is Device Intelligence and How Does It Stop Fraud?
76d ago
[FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE)
76d ago
IBM commits $5 billion to secure open-source software
76d ago
Structuring an AI-Assisted Pentesting Homelab for a Final Year Project
76d ago
Are teams actually monitoring LLM traffic in production environments?
76d ago
How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA)
76d ago
Raspberry pi
76d ago
What is the biggest obstacle to using AI safely in a company?
76d ago
Advice going forward
76d ago
MCP Firewall help
76d ago
I wanted to shift to security but people told me the market is extremely bad, is that true?
76d ago
Best Personality Type/Traits for Working in Cyber Security
76d ago
A fake freelance job interview almost installed malware on my PC
76d ago
Is there a viable career path here or am I just being delusional?
76d ago
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
76d ago
How do enterprises actually prevent developers from exfiltrating source code?
76d ago
I have a datastealer malware
76d ago
Dúvida de carreira.
76d ago
Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace
76d ago
Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated
76d ago
is SIEM really needed here ?
76d ago
Decompiled an app, found a bunch of secrets, what now?
76d ago
Can someone give me a correct method for learning reverse engineering?
76d ago
Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months
76d ago
GRC Advise
76d ago
[ Removed by Reddit ]
76d ago
Did something happen to haveibeenpwned? Any alternatives?
76d ago
RAT SUSPECTED
76d ago
How do people afford certificate s?
76d ago
I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed?
76d ago
Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
76d ago
Phone Forwarding
76d ago
Opinions on running Full Microsoft E5 Security Stack
76d ago
Claiming "XDR"
76d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
76d ago
Microsoft security
76d ago
Need help regarding building a home lab
76d ago
Should I turn on passwordless accounts for all my Microsoft accounts?
76d ago
Transitioning from AWS Data Center Operations to Security Engineering
76d ago
Probably the wrong place.
76d ago
What after IT helpdesk?
76d ago
How are you security-testing API changes before production without slowing CI/CD?
76d ago
Are we trusting update repos or are you all extra paranoid now as well?
76d ago
Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops
76d ago
Prevent supply chain attacks
76d ago
Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems
76d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
76d ago
Hackers are trying to steal Signal users' backups in new wave of phishing attacks
76d ago
Incident Response Testing Preparation
76d ago
Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference
76d ago
[Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥
76d ago
3rd Party NFC cards.. secure?
76d ago
Vulnerability Management Tickets & SLA
76d ago
Defending at Machine-Speed: Building AI Threat Readiness
76d ago
AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved
76d ago
HEAD request body processing leading
76d ago
Malicious npm Package Stole Files From Claude AI User Directory via GitHub
76d ago
Does anyone have an app like substack to keep being updated and engaging within the cyber domain?
76d ago
What’s an attack vector people massively underestimate in 2026?
77d ago
We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7
77d ago
A Deeper Look at GLASSWORM's Solana Variant
77d ago
Calling Cyber Security Beginners
77d ago
Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis
77d ago
built something for ai agents, ended up looking a lot like classic appsec
77d ago
Is Gophish still usable in 2026?
77d ago
Microsoft vs Chaotic Eclipse: three zero-days now actively exploited
77d ago
what do you think
77d ago
Why would be clicking a website, redirect me?
77d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
77d ago
Writing cybersecurity policies is a waste of time
77d ago
Raising the Cybersecurity Stakes: Ante up for the Agentic Era.
77d ago
Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it.
77d ago
[ Removed by Reddit ]
77d ago
Released: Dataforge Honeypot
77d ago
Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
77d ago
CEH-free
77d ago
Hottest cybersecurity open-source tools of the month: May 2026
77d ago
Preparation tips for CPENT
77d ago
How do you handle AI tools in your organization?
77d ago
I think i got scammed anybody can help me with that
77d ago
New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo
77d ago
Is it safe to have passwords copied to clipboard on IOS temporarily?
77d ago
Developers working on anti-fraud systems deserve more credit
77d ago
My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst
77d ago
Security awareness training for AI heavy smb workflows?
77d ago
Minimum Requirements for Helpdesk Role ?
77d ago
Reddit spear phishing
77d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
77d ago
What to do
77d ago
What resources would you recommend for studying cysa+
77d ago
Provenance of Data
77d ago
Websites have a new way to spy on visitors: analyzing their SSD activity
77d ago
12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal?
77d ago
Russian Art Teacher - Hinder Security Clearance?
77d ago
EDR/MDR Vendor Questions
77d ago
Cybersecurity as a Highschooler?
77d ago
New department created, would love your input
77d ago
OWASP Vienna - anyone going?
77d ago
Interview with Upstart
77d ago
18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber.
77d ago
Is cloud security engineer viable with my current position?
77d ago
Cloudflare Access users: what would actually make JIT useful for you?
77d ago
eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels
77d ago
Questions regarding Ubuntu 24 LTS hardening
77d ago
Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho.
77d ago
Honest question about OT Security Engineer work life in India
77d ago
Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning)
77d ago
AI Security
77d ago
Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor
78d ago
🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents
78d ago
Building Detection Engineering on AWS from scratch — roast my plan
78d ago
Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance
78d ago
I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA.
78d ago
Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning
78d ago
Final Year Project: Looking for non-generic IAM project ideas that solve real problems
78d ago
GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled.
78d ago
Breaking out of IT Helpdesk - how?
78d ago
A year in Cybersecurity — Where Do I Go From Here?
78d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
78d ago
22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber
78d ago
FBI: Silent Ransom Group Turns to IT Support Ploy
78d ago
How do machine builders track Siemens/Rockwell security advisories?
78d ago
GlassWorm Developer Supply-Chain Botnet Takedown
78d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
78d ago
Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV
78d ago
Got cybersec work what next ?
78d ago
Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables
78d ago
Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers
78d ago
Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing?
78d ago
GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)
78d ago
nightmare eclipse is probably French here is why
78d ago
Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines
78d ago
Measuring performance of JA4/JA4H AI Model
78d ago
What things are you really focused on this year?
78d ago
Hypothetical EDR spoofer
78d ago
ISO 27001 Audit Stage 1
78d ago
Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.
78d ago
Looking for Hacker Friends to Learn☺️
78d ago
Comptes Instagram et Facebook piratés et désactivés
78d ago
How to safely disinfect a USB stick from potential malware files?
78d ago
Is anyone else concerned about how quickly AI is outpacing cloud security?
78d ago
What's a CyberSecurity job like?
78d ago
Microsoft Live credential stuffing
78d ago
I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this?
78d ago
Security architects- summarize your responsibilities and role
78d ago
Finding Work in OSINT
78d ago
State of SDLC Security 2026
78d ago
Reported to police for coding html
78d ago
[Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling)
78d ago
I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project
78d ago
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover
78d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
78d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
78d ago
Breaking GROK'S DEFENSES to make it HACK Real Public Websites
78d ago
GitHub Actions Cache Poisoning is eating open source
78d ago
Nightmare-Eclipse has also been banned on GitLab :DD
78d ago
Do we still have time before we are in the Age of the movie "Minority Report"? ↓
78d ago
SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file
78d ago
What Software Supply Chain, Water Filters, and Power Grids Have in Common
78d ago
QA engineer trying to move into AppSec — does this plan hold up?
78d ago
Is work from anywhere really impossible to find??
78d ago
Cybersecurity statistics of the week (May 18th - May 24th)
79d ago
Engineering a Post Quantum Fortress Inside the Citadel Archite
79d ago
Cyber Security Analyst
79d ago
Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance
79d ago
Two layer email security tool thesis
79d ago
When OTP rate limiting fails: OLX account takeover with persistent sessions
79d ago
Entra ID sessions revoke
79d ago
Anyone who attended GPCSSI before? Need some clarification
79d ago
Lost on my career path.
79d ago
EU-based folks: external pentest vs mandatory data/security training?
79d ago
help needed from experienced people
79d ago
How do you evaluate whether a privacy service is actually privacy-respecting?
79d ago
Which one Intellipaat or coursera which one to choose
79d ago
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
79d ago
India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic?
79d ago
Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs.
79d ago
Did anyone pass the SC-200 certificate recently?
79d ago
Honeypot
79d ago
passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account
79d ago
Career in IAM as a fresher
79d ago
CISA orders feds to patch actively exploited Drupal vulnerability
79d ago
Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure
79d ago
GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
79d ago
Cyber security tool
79d ago
Saw this tool and it has potential
79d ago
🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs
79d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files
79d ago
Follow up : showing Claude install random pacakage in its vm instance without asking or prompting
79d ago
¿Is safe?
79d ago
Need help
79d ago
What is the best tool for masking in kali
79d ago
What are the best tools other than ghostTracker?
79d ago
TrapDoor Cross-Ecosystem Crypto Stealer Campaign
79d ago
Follow up : Steal Your Files Claude AI installing package because internet say so
79d ago
New to Cybersecurity: Looking for general advice & help with Nmap
79d ago
Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal
79d ago
Looking for tech role references
79d ago
How do you balance Paw?
79d ago
I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity.
79d ago
From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security
79d ago
Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February
79d ago
What Companies are Legit?
79d ago
start learning cybersecurity from scratch
79d ago
Follow-up: measuring LLM-agent failures with replay evidence
79d ago
Follow-up: measuring LLM-agent failures with replay evidence
79d ago
WhatsApp users on alert after hacker drops massive dataset
79d ago
17 years old going into CS — what certs should I start going after now?
79d ago
i want to hire an osint expert
79d ago
Open University pros/cons
79d ago
How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection?
79d ago
Career in IAM as a fresher
79d ago
Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo
79d ago
Need Advice
79d ago
Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all?
79d ago
Someone from Germany on iOS keeps trying to login to my MSFT account
79d ago
AI cautionary tale...
79d ago
AI powered red vs blue teaming
80d ago
Starting a security analyst student apprenticeship next week, need advice
80d ago
Why CVE Does Not Work for AI Agents, but AVE?
80d ago
SC-200 or Security+ — which actually helps land a security title
80d ago
How about AI having access to your hard drive.
80d ago
How a Date Tag Hijacks macOS via ExifTool
80d ago
Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools
80d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
80d ago
Built a tiny daily cyber puzzle game during evenings/weekends
80d ago
Crypto4A launches quantum-safe rival to AWS Secrets Manager
80d ago
ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why.
80d ago
Cyber Sec project
80d ago
CySA+
80d ago
Anyone tried Morgancyberhelp ?
80d ago
As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free
80d ago
Why are most of the dfir tools built to be used in windows
80d ago
OnlyFans mega leak reveals 340M user records, hackers claim
80d ago
Perplexity BumbleBee
80d ago
Cisco patches critical 10.0 flaw in Secure Workload APIs
80d ago
Stalker has my phonenumber
80d ago
Need some guidance
80d ago
Are you currently allocating budget to services that remove executive PII from B2B data brokers?
80d ago
About CEHv13 book
80d ago
We open-sourced the most dangerous part of our security startup on purpose.
80d ago
Which conference(s) result in the most people finding jobs?
80d ago
My discord account has been hacked second time even after enabling two factor authentication and resetting password
80d ago
What's the most efficient way to learn cloud governance and compliance
80d ago
Does anyone know C2 framwork and free hosting to host C2?
80d ago
CIS-CAT Assessor for assessment Windows server 2022 and 2025
80d ago
Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this
80d ago
Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks?
80d ago
Recent adoption of AI taught me what is Cybersecurity.
80d ago
The Pentagon Changed the Rules for Cybersecurity Compliance
80d ago
Can someone explain to a noob like me what the implications of this exploit are?
80d ago
SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections
80d ago
Window between zero-day CVE and a patch!
80d ago
Is it risky when a website puts on technology components with versions they used in their website?
80d ago
Anyone else losing their mind over this "AI Cybersecurity" hype?
80d ago
URL parsing behavior in a canonical tag lab
80d ago
Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you?
80d ago
Any tips for me pls
80d ago
How do you minimize legal liability as a solo contractor?
80d ago
How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing?
80d ago
Mentorship Monday - Post All Career, Education and Job questions here!
80d ago
Provenance: A survival toolkit for an AI dominant information landscape
80d ago
[ Removed by Reddit ]
80d ago
Active Drupal SQLi exploitation is a real „patch now“ moment
80d ago
machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native)
80d ago
Need suggestions and input; not a promotion
80d ago
Need advice!
80d ago
New Zealand is becoming a focal point for AI-driven superhacking threats.
80d ago
nmap on Linux: Guide to Network Scanning and Discovery
80d ago
TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle
81d ago
How would Phishing look like in the future? (targeting agents, not humans)
81d ago
Best beginner/intermediate book for system security (blue team / defense / audits)?
81d ago
Why is on-prem and air-gapped asset inventory still such a mess?
81d ago
keep getting MS authentication sign in attempts?
81d ago
Silly issue
81d ago
How to practice cybersecurity while studying prograaming ?
81d ago
[AI Security] Exploring Behavioral AI for Runtime Threat Detection
81d ago
Podman and krun: is it pointless to harden quadlets?
81d ago
How to handle security researchers (and firms) without a bounty program?
81d ago
Product analytics is becoming a third-party breach surface
81d ago
How can i learn and get into red teaming?
81d ago
Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network
81d ago
I got hacked
81d ago
Soc analysts in big companies, how it looks like?
81d ago
CTO at NCSC Summary: week ending May 24th
81d ago
These special phone and app features can help protect you from spyware
81d ago
Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button?
81d ago
Capcha Code Malware
81d ago
getting lost when hunting
81d ago
How to find information behind an account?
81d ago
Theoretical Design Concept for Post-Exploitation Browser Defense
81d ago
Google Certifications...
81d ago
How to continue when finding a possible Vulnerability but local law prohibits me from investigating further
81d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
81d ago
Is the CISSP still a reputable cert for getting jobs?
81d ago
Which of these gоv roles would fare better in the private sector?
81d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
81d ago
Mapping binaries to EDR feature spaces
81d ago
Lost my number + WhatsApp account — worried about old chats, photos, and videos
81d ago
what is the most painful or time-consuming part of your work right now?"
81d ago
Anthropic says Mythos has already found more than 10,000 vulnerabilities
81d ago
What is the experience needed for “entry level” cybersecurity jobs?
81d ago
Browser extension testing.
81d ago
Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip?
81d ago
Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback
81d ago
Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition
82d ago
Can someone recommend me some good, large universities to study cybersecurity?
82d ago
New guy khikhi
82d ago
Examples of intentional backdoors being breached?
82d ago
Non-Compliant Vocab
82d ago
Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites
82d ago
infostealers just spawned a 5,000+ repo github supply chain attack
82d ago
The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis
82d ago
GRO frag
82d ago
We audited 12K n8n templates: most have critical vulnerabilities
82d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
82d ago
Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week
82d ago
Mitigated Vulnerabilities by Vendor as Feed
82d ago
Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors
82d ago
A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories
82d ago
Where can I find the tools freely on internet to practice for soc analyst
82d ago
residential proxies
82d ago
Recommendations for getting started in cybersecurity
82d ago
Linux mint or Ubuntu for complete beginner
82d ago
Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world.
82d ago
Pentesting company recommendation
82d ago
Have you ever failed a certification exam?
82d ago
AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance
82d ago
What do i need to learn to get into application security? Which Degrees/Certs
82d ago
RSAC online membership? Is it worth it?
82d ago
Can someone give me a detailed roadmap for becoming a SOC Analyst?
82d ago
Puedo conseguir trabajo?
82d ago
How do i learn networking for cyber security?
82d ago
What's going to be Hacking and Cybersecurity's future is gonna be like?
82d ago
Cyber security placement - Interview Help
82d ago
Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge
82d ago
Feedback needed
82d ago
Handoff Transition
82d ago
Just added an interactive security map showing exactly what the server sees (and doesn't)
82d ago
Trend Micro warns of Apex One zero-day exploited in the wild
83d ago
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
83d ago
https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/
83d ago
Harvard and 140 other legitimate websites compromised
83d ago
Votre Satisfaction Dans Votre Travail
83d ago
5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit.
83d ago
US states urge Congress to renew cybersecurity grants
83d ago
The CISO's Guide to IDE Security in 2026
83d ago
Help with evilginx
83d ago
Watching AI Brain Drain on Attackers in Real Time
83d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
83d ago
api-rta cyberwarfare labs
83d ago
Does Security Implement Fixes?
83d ago
Ultimate Cybersecurity without needing AV ect?
83d ago
User Onboarding with IAM
83d ago
pnpm 11 Might Finally Be a Better Default Than npm
83d ago
14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs
83d ago
Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria
83d ago
Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip"
83d ago
Looking for a cybersecurity professional to interview for a university project (interview in French)
83d ago
Safe read-only check script for Copy Fail / CVE-2026-31431
83d ago
New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible?
83d ago
[TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly
83d ago
Cisco used AI to write security incident reports, with mixed results
83d ago
[TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM)
83d ago
Cyber Insurance Actuary Looking for Educational Resources
83d ago
As a bank , how do i give protected access to claude to my team?
83d ago
Can seasonal Apple Store employees apply for internal IT/cybersecurity roles?
83d ago
Reliable IP reputation check tools besides IPQS?(for work)
83d ago
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026)
83d ago
Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins
83d ago
Hacked by Rat Tools for 2.5 years.
83d ago
Google API Keys Remain Active After Deletion
83d ago
how do cyber sec consultants and pentesters actually get new clients?
83d ago
Post Incident Paranoia?
83d ago
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
83d ago
Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity?
83d ago
Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready
83d ago
You can counter MEMZ with Krotten in XP
83d ago
What are the most effective ways to do Blackbox testing?
83d ago
Npm registry sets stage for more secure package publishing
83d ago
Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support
83d ago
Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK
83d ago
Is the Cybercorps SFS still worth it?
83d ago
Microsoft warns hackers are exploiting password resets to gain access to user accounts
83d ago
Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame
83d ago
WORM USB drives
83d ago
An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model?
83d ago
CISOs - Holding the Line
83d ago
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
83d ago
Security Scroll Down?
83d ago
mass github repo backdooring via CI workflows(Megalodon)
83d ago
Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit?
84d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
84d ago
DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind
84d ago
FaceTec (ID verification) company appears to store user biometrics
84d ago
CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication
84d ago
It seems that FaceTec (ID Verification company) allows for storage of user biometrics
84d ago
Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check.
84d ago
Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data
84d ago
What Questions Do You Ask During SSP Control Interviews?
84d ago
Feed The Cat BackDoor
84d ago
Flipper One - Asking for help from the community
84d ago
Flipper One — tech specs
84d ago
Architecture Zero Trust détaillée
84d ago
Cybersecurity in Healthcare
84d ago
Staged publishing for npm packages | npm Docs
84d ago
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though)
84d ago
Neither MFA, Passkey, nor trusted IP help here
84d ago
cyber security remote
84d ago
CSIRT incident response
84d ago
Trying to find a graduate role
84d ago
Microsoft warns of new Defender zero-days exploited in attacks
84d ago
what is the best security app option for pixel8a?
84d ago
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
84d ago
IoT Security
84d ago
GitHub links repo breach to TanStack npm supply-chain attack
84d ago
Another working Linux LPE exploit is out. How are teams treating local-only bugs now?
84d ago
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
84d ago
Google publishes exploit code threatening millions of Chromium users
84d ago
landing a remote Vulnerability Management role
84d ago
Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case.
84d ago
I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting?
84d ago
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
84d ago
What volume of TPRM do you handle per month?
84d ago
safest virtual machine?
84d ago
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration
84d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
84d ago
GitHub notifications
84d ago
Is there no more privacy left in the world?
84d ago
Microsoft Edge had a password blunder, and it raises a bigger browser trust problem
84d ago
Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network
84d ago
Aconselhamento / mini texto
84d ago
CISA with an absolutely embarrassing data leak.
84d ago
Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys
84d ago
Anyone else feeling like static AppSec workflows are starting to hit limits?
85d ago
GitHub breach highlights developer tools as part of attack surface
85d ago
Why do some malware use unique user-agent strings?
85d ago
Encrypted emails bypassing email security tool
85d ago
Ctf groups
85d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
85d ago
Opensource that automatically scans your git repos for breaches
85d ago
CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed.
85d ago
Your developers are deploying agents in your production environment right now. You have no governance for it.
85d ago
¿Como me preparo para EC-Council CSA?
85d ago
The IBM X-Force Index 2026 explains all three in one finding.
85d ago
Securing iPad's question
85d ago
Cybersecurity 101
85d ago
What would this job role be?
85d ago
MSPs & MSSPs suck
85d ago
[ Removed by Reddit ]
85d ago
Crossroads
85d ago
Advice regarding "SOC" job that automates everything
85d ago
Is this Medium article about "NetMirror" malware legit?
85d ago
AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon?
85d ago
Developer tooling is part of the attack surface before a project is even run
85d ago
How the hell do you manage developers, their code, their apps?
85d ago
Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed
85d ago
Do people still rely on antivirus software in 2026, or is built-in security enough now?
85d ago
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
85d ago
Automatic CLI for spinning up vulnerable labs + objectives
85d ago
ISO/IEC 27701 scenario question
85d ago
Discord rolls out end-to-end encryption on voice, video calls
85d ago
GitHub investigates internal repositories breach claimed by TeamPCP
85d ago
Two AI-based science assistants succeed with drug-retargeting tasks
85d ago
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
85d ago
An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now.
85d ago
New to cybersecurity
85d ago
Anyone interview or work with Moxfive?
85d ago
A stealth Firefox version that passes all anti-bot and CAPTCHA
85d ago
mkPIVM - a polymorphic position-independent shellcode virtualizer
85d ago
Started in IT and need a Cybersecurity Roadmap with my Useless Degree!
85d ago
GitHub announces internal data breached.
85d ago
Roadmap to Cybersecurity roles
85d ago
Malware installed without literally doing anything?
85d ago
CTFs
85d ago
Crossroads
85d ago
Canara Bank SuRaksha Cyber Hackathon 2.0,
85d ago
Anti BOT Tipps und Tricks gesucht.
85d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
85d ago
New to Cybersecurity
85d ago
Is the ISC2 Certified in Cybersecurity worth it?
85d ago
Average Days to Close by Source CNAPP Severity Tag 2026
85d ago
I want free nmap resource
85d ago
If I clear browser history regularly, does it reduce the chances of malware that target browser data?
85d ago
What is next after 1.5 Year as Security Analyst?
85d ago
Analysis advice
85d ago
Stop me if you heard this one before... (YellowKey related)
85d ago
Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe?
86d ago
Looking for advice: where should I post/publish CVE write-ups?
86d ago
Cybersecurity statistics of the week (May 11th - May 17th)
86d ago
How can I test my website locally for cybersecurity?
86d ago
Use of coding in security operations
86d ago
Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
86d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
86d ago
I've built an open source honeypot probe database accessible via curl, http and mcp
86d ago
6,000+ Automatic Tank Gauges Exposed With No Authentication
86d ago
Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email?
86d ago
If humans are the weakest link, why won't companies evolve?
86d ago
Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?"
86d ago
Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM
86d ago
Local transcription vs cloud transcription, which actually feels safer?
86d ago
Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today?
86d ago
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise
86d ago
Shai-Hulud source leak is turning npm malware into a copycat problem
86d ago
Framework for Preventing Secret Ideas from Leakage
86d ago
Local LLM for building AI Security platform
86d ago
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
86d ago
Emerging Cyber security niches
86d ago
ISO/IEC 27701
86d ago
Solo dev building a terminal-heavy hacking game inspired by corporate security
86d ago
Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations
86d ago
CS/IT Student Looking to Grow My LinkedIn Network 😃
86d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
86d ago
Is Amazon Cognito a good choice long term? Alternatives?
86d ago
Was hacking easier in the 80s and 90s and early 2000s?
86d ago
Need some Advice in SOAR heavy environment
86d ago
Trying to find serious builders in cybersecurity - not just “let’s build” conversations
86d ago
AI Phishing
86d ago
One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals
86d ago
How easy is it to get into the cyber security field?
86d ago
314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js
86d ago
Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start?
86d ago
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo
86d ago
CEH/CPENT vs OSCP vs GPEN
86d ago
ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro”
86d ago
CISA Contractor Admin Leaked AWS GovCloud Keys on Github
86d ago
Suspecious activity in my account
86d ago
Is it safe to use my first name and middle name on platforms?
86d ago
Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice.
86d ago
Just received an email from shinyhunters about their amtrack hack
86d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
86d ago
Bywaf: an auditable Python commandlet framework for chained pentest workflows
86d ago
For anyone currently working in a SOC:
86d ago
Fellow Tier 1 SOC/Security Analysts - What does your day to day look like?
86d ago
How do you threat hunt for RMM tools in environments where RMM is all over the place?
86d ago
Microsoft - "your single use code" email when it was not requested by yourself
86d ago
Directory of vendor security questionnaires
86d ago
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
86d ago
MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals
86d ago
Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight
86d ago
How is AI affecting the cybersecurity market?
87d ago
MCP security
87d ago
YellowKey Mitigation
87d ago
Anyone else on the receiving end of ShinyHunters extortion email?
87d ago
Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs
87d ago
What’s the biggest mistake people still make about online security in 2026?
87d ago
Anthropic shuts the EU out of its most advanced cyber AI model
87d ago
Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens]
87d ago
Best hotel for attending all three conferences in Vegas?
87d ago
What's your company's actual PQC migration plan? Not the one on paper - the real one.
87d ago
Does buying local cybersecurity (services/products/etc) matter to you?
87d ago
LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose
87d ago
Detection Engineering AI Maturity Framework
87d ago
Microsoft code
87d ago
Microsoft confirms Windows 11 security update install issues
87d ago
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
87d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
87d ago
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
87d ago
Suspicious with a company offer letter
87d ago
Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first?
87d ago
Why do some recovery workflows still require full wallet uploads?
87d ago
Need help with interview for soc l1
87d ago
Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap)
87d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
87d ago
carrer path in cybersecurity for a btech stud
87d ago
Agents usage in production
87d ago
‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K
87d ago
Are teams still finding AI API keys in public repos?
87d ago
Mentorship Monday - Post All Career, Education and Job questions here!
87d ago
Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here?
87d ago
Does the CBP bug phones?
87d ago
What We Learned Building Runtime Visibility for Modern Telco Networks
87d ago
Ive got my Spotify account hacked! How do I solve this?
87d ago
The Politics of AI Transparency
87d ago
A million baby monitors and security cameras were easily viewable by hackers
87d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
87d ago
Is cybersecurity becoming more behavioral than technical?
87d ago
Questions About Promo Items for a Cybersecurity Conference
87d ago
Dois-je m'inquiéter ?
87d ago
I am dying to work abroad , rate my journey so far
87d ago
Microsoft - "Your single use code" email when it was not requested
87d ago
Security / Compliance work going Agentic?
87d ago
Don't believe the media, specially in cybersec
87d ago
Microsoft account keeps getting Authenticator requests?
87d ago
[Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated.
87d ago
Struggling to generate security bulletins — any ideas?
88d ago
Certs to go into Security Engineer/architect
88d ago
18882745552 beware of email with this number
88d ago
Transition from traditional penetration testing into AI security
88d ago
Seeking advice on next career steps
88d ago
Will the analyst role become obsolete?
88d ago
Alert Fatigue
88d ago
Best path into cybersecurity for a high schooler?
88d ago
Keep getting hacked
88d ago
How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices
88d ago
I’m interested in joining the Red Team Hackers Academy in Bangalore.
88d ago
A clueless teenager 💔
88d ago
Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start?
88d ago
Am I overthinking Claude Code security or is this actually a risk?
88d ago
is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this
88d ago
ISO/IEC 27701 ( SoA ) Applicability
88d ago
Security Executive Playbook
88d ago
This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon
88d ago
I feel crazy I hope someone has insight .
88d ago
ΡHANTΟΜ Al-Powered Pentesting Command Center
88d ago
Interview Assessments
88d ago
We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it
88d ago
Questions about data blockers
88d ago
Post Implementation task
88d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
88d ago
Cyber security jobs in Austria
88d ago
Personal favorite deception layer.
88d ago
Estudiar Ciberseguridad
88d ago
Learning way
88d ago
How do you report large volume detections to a CISO without making the BPA report a SOC story?
88d ago
Can anyone share bugbase platform screenshot having professional usage on dashboard?
88d ago
CTO at NCSC Summary: week ending May 17th
88d ago
Security Executive Playbook
89d ago
Tired of tab-switching between CTI tools - here's what we put together
89d ago
I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor
89d ago
In Cybersecurity
89d ago
Anyone else feel like most MSP tooling is either overkill or painfully manual?
89d ago
Thinkpad vs Macbook pro endpoint security
89d ago
Any more affordable alternatives to “IntelligenceX”?
89d ago
Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran
89d ago
tanstack checker github action
89d ago
Drivers Alpha AWUS036AXML
89d ago
Splunk download for free
89d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
89d ago
Anyone here using pager duty?
89d ago
Scammer targeting posters
89d ago
Seeking advice
89d ago
Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026)
89d ago
Just got an email about a single use code, maybe someone was trying to log in?
89d ago
Can a background in DevOps enter the cybersecurity field?
89d ago
Using ai in learning
89d ago
Avanzamento area Blue Team/SOC
89d ago
Please what could be helpful
89d ago
CVE exploit chain
89d ago
What are the widely accepted SaaS security accreditations/audits an app should seek in fintech
89d ago
Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco
89d ago
Major flaw in Indian Cyber and IT assurance landscape
89d ago
Red Team Ops Ⅱ ( CRTL ) exam preparation
89d ago
Recomendations
89d ago
Recommended cybersecurity certification for a UX designer new to the domain?
89d ago
insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server
89d ago
Career path
89d ago
Merit America offers a program that gets you into cyber security roles.
89d ago
Brovan: Binary user-mode emulator for x86_64
89d ago
AmEx Interview!
89d ago
Developer credential-stealing pipeline also collected operator workstations
89d ago
need help building a case.
89d ago
Personal favorite SIEM platform?
89d ago
Cardputer ADV
89d ago
Alternative for Qualys
89d ago
The 4th Linux kernel flaw this month can lead to stolen SSH host keys
89d ago
Stack Buffer Overflow Explained (Using a Classic Doom Bug)
89d ago
Confused about cybersecurity career
89d ago
Transferring from pen test consulting to application security?
89d ago
Curso de especializacion de Ciberseguridad
89d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
89d ago
Lost, tempted to throw in the towel
89d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
89d ago
I open-sourced a Docker security scanner I use to audit all my websites
89d ago
Testing Deception Technique
89d ago
A malware got into my account and spread spam ad to my friends and relatives
90d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems
90d ago
Most pentest reports I review are padded with garbage findings
90d ago
Cyber Essentials and use of third party websites - MFA
90d ago
Rapid 7 and Cisa Kev
90d ago
Anyone know much about MS Defender?
90d ago
EN18031 for IoT: struggling to see the big picture — advice from experienced people?
90d ago
Automating Code Security Reviews
90d ago
New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available
90d ago
AI coding tools on developer machines — looking for input on how you're handling it
90d ago
Chrome 148 Update Patches Critical Vulnerabilities
90d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
90d ago
I need help. i am lost
90d ago
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence
90d ago
Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments
90d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
90d ago
I'm going crazy. At the application level what I can actually do to prevent DDos?
90d ago
Is anyone enrolled in Intellipaat's cybersecurity course?
90d ago
Will AI Replace Cybersecurity Jobs?
90d ago
What's best certification choice after OSWE
90d ago
Facebook Page Call Slipping through Sleep mode
90d ago
ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey
90d ago
New Linux LPE allows local users to read any file, including privkeys
90d ago
A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks.
90d ago
Your experience as IT Admin on Alerts
90d ago
Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time
90d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
90d ago
Discord VC lag Exploit
90d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
90d ago
Bug FB - Inicio de sesion por password
90d ago
Does anyone know how to configure EVILGINX for testing
90d ago
How long does it take to get familiar with a tool
90d ago
Scam website
90d ago
ANTS Hack: 19 million records exposed in French ID agency breach
90d ago
Is it really that easy to obtain SMS codes using an SS7 attack?
90d ago
AI coding tools are shipping code faster than security can review it. What's your team doing about it
90d ago
Interview for AI security engineer position at a fortune 500 company
90d ago
How’s the job market for Senior AppSec Engineers? How are the interviews?
90d ago
Has anyone read "The Art of Deception"? How does it hold up to now?
90d ago
Is metadata protection becoming more important than traditional endpoint security for ordinary users?
90d ago
Zero trust in hybrid environments - what's actually worked for you
90d ago
Have you encountered issues with CSAF advisories in practice?
90d ago
Zero trust in hybrid environments - what's actually working for you
90d ago
OpenAI confirms security breach in TanStack supply chain attack
90d ago
Bachelors Degree Options
90d ago
I need help protecting my privacy
90d ago
Free Threat Intellegence
90d ago
What discovery in cybersecurity amazed you the most?
90d ago
Scholarship for Service
90d ago
For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons?
90d ago
Another day, another supply chain
90d ago
How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs?
90d ago
Teaching Linux+ & CEH.....
90d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
90d ago
SIEM use case development
90d ago
JFrog vs Mend as Scanners
90d ago
KQLab - open-source query manager for SOC teams
90d ago
Which Vendors Publish the Best (or Worst) Security Advisories?
90d ago
Synthetic training data vs. real attack telemetry — does it actually matter?
91d ago
Operative IT-Sicherheit | SIEM & Splunk
91d ago
SOC not for junior level?
91d ago
Cybersecurity at MSG
91d ago
pii-tools.com reputable?
91d ago
Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise
91d ago
Contract jobs worth the risk?
91d ago
HackTheBoxAcademy vs LetsDefend vs CyberDefenders
91d ago
Automating code security reviews with Claude: near Mythos-level capabilities at lower cost
91d ago
Making Right Career Decision?
91d ago
I tried using apparmor (linux security) but it doesn't seem to work very well
91d ago
Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything!
91d ago
Struggling to Stay Up to Date With Vulnerabilities
91d ago
How to Transfer files Safely from a Compromised (work) Device
91d ago
Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward
91d ago
Multiple data breaches in one week
91d ago
How are small security teams handling vulnerability overload now?
91d ago
Concerns mount that EU will demand age verification for VPNs
91d ago
Automating code security reviews: Claude Mythos-level capabilities with lower cost
91d ago
The Rare Patch: A Digital Sovereignty Challenge
91d ago
Advise
91d ago
GRC
91d ago
Admins and Engineers
91d ago
Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark
91d ago
Prompt injection in browser coding agents is the threat model nobody is ready for
91d ago
New Fragnesia Linux flaw lets attackers gain root privileges
91d ago
Transition from MSP to Network Engineering?
91d ago
So called “off grid” method
91d ago
Convince me I’m not paranoid: a unique hacking situation.
91d ago
Hunting the Behavior Behind npm Supply Chain Attacks
91d ago
Question for AppSec Members
91d ago
Beginners guide to Google Dorks by Heisenberg
91d ago
Alguém sabe algo sobre raven eye technology
91d ago
Gophish Porject - Requirement
91d ago
Security Team Won’t Assess Risk
91d ago
Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework
91d ago
Microsoft’s new multi-model agentic security system tops leading industry benchmark
91d ago
Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
91d ago
Overwhelmed on how to enter the job market.
91d ago
Social media scam bill targets tech giants as New Yorkers lose billions
91d ago
What are the biggest technical & cultural hurdles you’re facing right now?
91d ago
CISSP / CCSP training - Experienced engineer
91d ago
Vulnerability in Canvas/Instructure Support Tickets had part in breach?
91d ago
is malwarefox legit?
91d ago
what lab to learn zero trust?
91d ago
Anyone else got a bunch of emails leaked by Samsung?
91d ago
This is what some the world's largest banks of malware look like stacked as hard drives
91d ago
I need feedback on my project please
91d ago
would like to understand the role of "Cyber Insurance UnderWriters"
91d ago
Free on-device tool for monitoring AI traffic on macOS — visibility before policy
91d ago
Is secure evidence handling and controlled derivative file sharing needed?
91d ago
Will Adding Some Certifications Help Me in the Job Market?
91d ago
Linux driver posted for Intel Silicon Security Engine Interface "ISSEI"
91d ago
Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified?
91d ago
Fragnesia made public as latest Linux local privilege escalation vulnerability
92d ago
HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity?
92d ago
NIST is surrendering to the amount of CVEs coming in
92d ago
Military Veteran looking to get into the Cyber Field
92d ago
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
92d ago
Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook.
92d ago
Cve apis for a database
92d ago
Empresas de Cyberseguridad en Mexico (Reacciones)
92d ago
Joined a new company: GRC landscape advice
92d ago
Removing admin rights
92d ago
a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access
92d ago
FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow
92d ago
Golden years for cyber security about to start?
92d ago
A stealth approach to Process Injection - EntryPoint Hijacking
92d ago
Detecting CopyFail and DirtyFrag by thinking outside the box
92d ago
Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security
92d ago
Career advice
92d ago
The exponential rise of economic damage caused by cyber-crime continues
92d ago
Today's cybersecurity systems are not ready for AI
92d ago
Are certifications worth it, or do practical skills matter more?
92d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
92d ago
Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed
92d ago
Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft
92d ago
What to do after security+
92d ago
AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data
92d ago
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
92d ago
Is it realistic to move from Tech Risk/GRC into technical cybersecurity?
92d ago
Are IPhone autofill passwords safe to use?
92d ago
Access approvals happen over Slack dm and I don't know how to present that to an auditor
92d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
92d ago
China is going dark to develop its own Mythos, German cyber chief fears
92d ago
Is prompt injection a real problem for you?
92d ago
New Exim BDAT bug shows why “just patch the mail server” is still not simple
92d ago
Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach
92d ago
Cybersecurity guide
92d ago
[Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ?
92d ago
How you guys rate Google Cyber security course and certificate out of 10 !?
92d ago
Cyebrsecurity Startup Advice
92d ago
Can anyone give a real world based AI based attack?
92d ago
How worried should we be about AI powered cyberattacks?
92d ago
Built STIS-ICS — an open ICS/OT security learning project
92d ago
OS scanner that checks repos for traces of the Shai Hulud worm
92d ago
Foxconn Ransomware Attack Shows Nothing Is Safe Forever
92d ago
Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries
92d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
92d ago
Explorer shows random letter/number filenames before copying my actual files — normal behavior?
92d ago
Zscaler AI Security Capabilities ?
92d ago
Cybersecurity degree
92d ago
Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma
92d ago
Cyber security
92d ago
New York Senate takes on junk fees, digital subscriptions, surveillance pricing
92d ago
Cybersecurity statistics of the week (May 4th - May 10th)
92d ago
Feels like AI changed the speed of attacks more than most companies want to admit
92d ago
Anyone used Kasm or ReplicaCyber?
92d ago
Škoda warns of customer data breach after online shop hack
92d ago
Google launches new Android security feature to help uncover spyware attacks
92d ago
Fancy Bear: Stealing Credentials Invisibly
92d ago
Nightmare Eclipse has published Greenplasma and YellowKey
92d ago
Copilot Agent
92d ago
What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles?
92d ago
Career Advice
93d ago
Anyone else exhausted by the nonstop AI hype?
93d ago
Reviewing the trends in ransomware attacks in 2026
93d ago
Is It a Good Idea to Change Jobs Shortly After Getting Hired?
93d ago
SSO makes life easier but MFA keeps it safe, do we actually need both?
93d ago
Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours?
93d ago
How are SOC teams actually deciding what not to investigate anymore?
93d ago
Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily
93d ago
Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released.
93d ago
Has anyone tryed this out yet?
93d ago
The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..)
93d ago
Switching to Cyber
93d ago
Nitrogen ransomware group claims Foxconn after Wisconsin plant outage
93d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
93d ago
Using Cape Sandbox for Phishing Analysis
93d ago
Canvas hack: company pays criminals to delete students' stolen data
93d ago
i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning.
93d ago
AI integrations are quietly creating a new OAuth supply-chain problem
93d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
93d ago
UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships
93d ago
Hardcoded secrets in Git
93d ago
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
93d ago
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
93d ago
New ipTIME Pre-Auth RCE in CWMP
93d ago
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
93d ago
Is my phone hacked?
93d ago
Switched to a grc role after a year in SOC L1
93d ago
Forecasting Lazarus Crypto Heists
93d ago
Infrastructure Security Incident Update & FAQs
93d ago
Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages
93d ago
In Depth Guide To VM Based Obfuscation - What it is and how to handle it.
93d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
93d ago
Transitioned to GRC
93d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
93d ago
German cybersecurity official warns China is close to developing AI superhacker
93d ago
Google Detects First AI-Generated Zero-Day Exploit
93d ago
“DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance
93d ago
Instructure/ canvas paid the ransom?
93d ago
Troca emprego - big para consultoria ou fintech - Pentester/Red Team
93d ago
Finally, texts between Android and iPhone users can be end-to-end encrypted
93d ago
Official CheckMarx Jenkins package compromised with infostealer
93d ago
IMF warns of the potential for AI attacks on global financial systems
93d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
93d ago
Cookie thieves caught stealing dev secrets via fake Claude Code installers
93d ago
Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo
93d ago
MS Defender on OT Network
93d ago
A fateful question
93d ago
SC-900 or SC-400
93d ago
What are your security non-negotiables?
93d ago
Losing my path
93d ago
Axon-captcha
93d ago
What makes companies trust small cybersecurity vendors?
93d ago
Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility”
93d ago
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
93d ago
Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim
94d ago
These Extensions are Scraping Your AI Chats, are you affected?
94d ago
Be careful with your Git: Investigating malware spreading through Git repositories
94d ago
Training and Phishing
94d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
94d ago
AI-powered hacking has exploded into industrial-scale threat, Google says
94d ago
Apple closed my bug report 4 times. MITRE wouldn't let it die.
94d ago
NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG
94d ago
Google spotted an AI-developed zero-day before attackers could use it
94d ago
beginner doubt
94d ago
I got my CEH Certification. SO what now?
94d ago
Construction to Cyber PM
94d ago
[ Removed by Reddit ]
94d ago
Something got downloaded on my phone and then dissappeared
94d ago
Bleeding Llama
94d ago
Do accountants even care about cybersecurityas much?
94d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
94d ago
Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust
94d ago
Was the reconnaissance in Bugbounty overrated?
94d ago
Cybersecurity beginner building an experimental log analyzer — looking for advice
94d ago
Anyone else worried about AI being a security nightmare?
94d ago
Snyk not working
94d ago
Malicious tenants paid us to abuse our RMM. We blocked them
94d ago
Help reasuring parents with an email parsing tool (i will not promote)
94d ago
DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this?
94d ago
cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers
94d ago
5 years as a Level 1 Security Analyst and wanting to transition into consulting
94d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
94d ago
New into network pentesting.
94d ago
Is it worth it to switching field to cybersecurity ?
94d ago
Neeed help to get cybersecurity internship.
94d ago
Mentorship Monday - Post All Career, Education and Job questions here!
94d ago
Cybersecurity and ADHD
94d ago
Anyone dealt with a VulDB submission rejection? Resubmit or reply?
94d ago
ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing
94d ago
I have a malware and need help removing it. someone please help me 🙏
94d ago
I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too?
94d ago
EasySec - Update
94d ago
What is the cybersecurity equivalent of leaving your spare key under the doormat?
94d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
95d ago
VICE: Cyberwar | Full Season 2 | Blueprint
95d ago
Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures
95d ago
Email OTP as default (often ONLY) password isn’t the solution
95d ago
Soc analyse
95d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
95d ago
Price rising
95d ago
AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report
95d ago
Possible security incident against Arup Group
95d ago
Can honeypots be used this way?
95d ago
I think AI just quietly killed the 90-day disclosure window.
95d ago
TCM and Educate 360 are bugged
95d ago
Got an alert from google what should I do?
95d ago
UK jobs
95d ago
Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏
95d ago
Worst company
95d ago
Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning
95d ago
Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months)
95d ago
ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring)
95d ago
App Store Question - Darato Sport / Dofu Sport / Kofu
95d ago
Help! - My Parents Computer is Hacked
95d ago
Ran lumma stealer from a recaptcha scam
95d ago
Port 5986 question
95d ago
CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse!
95d ago
cyber security/ segurança da informação
95d ago
College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains
95d ago
Help with an Escalating Cyber-Stalker
95d ago
RRW - Rick Roll WiFi
95d ago
Best resources to start learning python for cybersecurity and automation
95d ago
Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game.
95d ago
JDownloader site hacked to replace installers with Python RAT malware
95d ago
How can I fix my browser remembering what he had open last
95d ago
MS 360 CoPilot issues
95d ago
I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details
96d ago
ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12.
96d ago
eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback
96d ago
I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you
96d ago
OWASP TOP 10 LLM 2026 Community voting
96d ago
Second security incident at Instructure (Canvas)
96d ago
UK Advice Needed - VA+ Training?
96d ago
Gateweb - Secure Web Gateway
96d ago
Those who are in Detection engineering
96d ago
Can someone tell me of a trustable hacker?
96d ago
MSPs, how are you handling AI usage across your customer environments today?
96d ago
Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write
96d ago
How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there?
96d ago
ecpptv3 Exam in 3–4 Days —
96d ago
AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES
96d ago
Did CISA helped you land a job ?
96d ago
CTO at NCSC Summary: week ending May 10th
96d ago
pre pre junior needs help(guidance pls)
96d ago
Trojan malware
96d ago
SANs Courses: How do people get their employers to pay?
96d ago
NIS2 Article 21: turning compliance controls into technical security evidence
96d ago
This GBA Rom is making is having a weird behavior in the Sandbox, why?
96d ago
Why AI agent governance feels harder than traditional security models
96d ago
Confused about what certs are important
96d ago
Would getting Security+ be worthless for me?
96d ago
Submit probe test — shadow DOM click
96d ago
Threat intelligence in OT (Power equipments)
96d ago
SOC Analyst
96d ago
PAWs, PAM and PIM..what is best practice?
96d ago
This is the most in-depth analysis I have found on the Instructure/Canvas breach so far.
96d ago
Poland says hackers breached water treatment plants, and the U.S. is facing the same threat
96d ago
Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web.
97d ago
Quacc++: Automated Open Source Vulnerability Discovery
97d ago
60% of MD5 password hashes are crackable in under an hour
97d ago
Built a correlation engine that chains AD findings into attack paths automatically.
97d ago
Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests
97d ago
JDownloader's official website delivered Python RAT
97d ago
Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
97d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
97d ago
Note taking apps and advice
97d ago
IMF Warns AI Could Trigger Global Financial Cyber Crisis
97d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
97d ago
Is the ISC2 Cybersecurity program still worth it?
97d ago
Canvas getting hit during finals week shows how fragile “critical SaaS” has become
97d ago
Are websites exposed to the internet under attack almost every hour, even if they're small?
97d ago
Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken
97d ago
What the **** is happening in cybersecurity space ?
97d ago
Canvas is back up, but now what?
97d ago
Instagram is getting rid of end to end encryption, what now?
97d ago
New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation
97d ago
Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable".
97d ago
Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group?
97d ago
Cushman and Wakefield confirms cyberattack
97d ago
Egnyte potential ransomware attack
97d ago
So canvas is down, what'll happen if they can't come to an argreement?
97d ago
Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now.
97d ago
/Why/ is Shinyhunters targeting Canvas?
97d ago
Canvas Hack - Any Guesses How?
97d ago
Should I build a virtual or physical lab?
97d ago
Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12
97d ago
Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata
97d ago
Audit/Cybersecurity
97d ago
Issues removing Trellix (and specifically solidifier)
97d ago
Pentagon eyes 3-year cyber training requirement, overriding new Army policy
97d ago
How much personal info will be leaked by the recent Canvas hack??
97d ago
Dirty Frag and canvas
97d ago
Hackers deface school login pages after claiming another Instructure hack
97d ago
Did I destroy my career by being loyal to an arguably good company?
97d ago
V4bel/dirtyfrag - Universal Linux Local Privilege Escalation
97d ago
What is CYBERRANT?
97d ago
Canvas is down as ShinyHunters hack forces outage
97d ago
New Dirty Frag Linux Bug Emerges in Wake of Copy Fail
97d ago
Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today.
97d ago
How is GRC work in a MSSP?
97d ago
SH and BF phishing console
97d ago
Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth?
97d ago
Socure authenticating AI identity as real.
97d ago
Automated SSL Certificate Renewals - What is your setup?
97d ago
Shinyhunters and Canvas
97d ago
What Cli execution do you use for a script file?
97d ago
Fiserv security incident - data breach notice
97d ago
Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments
97d ago
I graduate next year with a Cybersecurity degree.
98d ago
Asking about Cortex
98d ago
Apache Caldera
98d ago
What’s the “unsexy” problem in cyber that’s actually a total disaster?
98d ago
Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE
98d ago
As a developer, should I use AI to improve security?
98d ago
My company has an MSP that manages our employee endpoints but we cant access the software they use to manage
98d ago
Americans sentenced for running 'laptop farms' for North Korea
98d ago
Is my laptop hijacked ?
98d ago
claude ai gave security beta to Enterprise plans only what can we do as pentesters?
98d ago
Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline
98d ago
Advice for path to land job SOC in France
98d ago
Possible Major Vulnerability: Chromium used by current version of PRTG
98d ago
Mythos AI may be a cybersecurity threat, but it follows the rules of the game
98d ago
Control Checks using AI.
98d ago
How do native password managers clear the clipboard?
98d ago
Graduating CS Student but Wanna Start my Career in Cybersecurity
98d ago
Claude-Themed Malware Campaigns
98d ago
DeepFake it till you make it.
98d ago
The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments
98d ago
What niche in cybersecurity should I go for, with my background in Angular & .NET ?
98d ago
Successor for Kaspersky Endpoint Security
98d ago
Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago
98d ago
SOC Analyst tier 1 (Entry Level) ??
98d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
98d ago
Made cybersecurity merch as an infosec practitioner — honest feedback welcome
98d ago
As AI agents become users of company data - what is needed to keep data secure?
98d ago
Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities.
98d ago
AI inference is quietly becoming a security problem
98d ago
is winrar 7.13 vulnerable to extraction exploits?
98d ago
Tried explaining internet encryption in a beginner-friendly but accurate way, feedback?
98d ago
Is the EC-Council CTIA Certification Worth It for Career Growth?
98d ago
POC Android vuln 2026
98d ago
Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise
98d ago
Opinions on Mimecast
98d ago
What's going on in the field of Cybersecurity 🫣.
98d ago
How do teams preserve institutional pentest knowledge when senior testers leave?
98d ago
CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE
98d ago
Sophos NDR on Proxmox
98d ago
On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029.
98d ago
DOJ says ransomware gang tapped into Russian government databases
98d ago
DAEMON Tools devs confirm breach, release malware-free version
98d ago
Have there been instances where your SOC has suffered a cybersecurity attack?
98d ago
OpenCTI founder, Samuel Hassine, arrested and charged with CSAM
98d ago
Deepfake Platform
98d ago
Trellix Licence Query
98d ago
Instructure hacker claims data theft from 8,800 schools, universities
98d ago
Is AI generated code creating a non-linear security problem for AppSec teams?
99d ago
D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says
99d ago
Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security
99d ago
Norton Antivirus and Other Norton Software
99d ago
Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home?
99d ago
We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes.
99d ago
Download a malware a while ago, someone trying to log into my ios account
99d ago
Org Restructure
99d ago
Does SOC 2 actually reduce questionnaires, or just change them?
99d ago
Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views
99d ago
How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically?
99d ago
Ran phishing awareness training for 200+ non-tech employees
99d ago
Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk
99d ago
Vulnerability Garden
99d ago
Palo Alto Firewall Zero-Day Under Active Exploitation
99d ago
Cyber Security Militias
99d ago
Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk
99d ago
CyberSecurity Nightmares
99d ago
Can I use NanoKVM if it's just to turn on pc?
99d ago
got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something?
99d ago
How to learn tools for cybersecurity?
99d ago
'CopyFail' attackers start cashing in on Linux flaw
99d ago
Anybodybodybdown for a team/studygroup?
99d ago
I was hacked due to sim card spoofing
99d ago
Chrome is quietly installing a 4GB AI model on your device
99d ago
Dev vs Security role
99d ago
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft
99d ago
Oracle Debuts Monthly Critical Security Patch Updates
99d ago
Sec engineer / developer?
99d ago
When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them?
99d ago
Are we actually seeing more vulnerabilities or just more noise?
99d ago
Cybersecurity jobs in red team
99d ago
Question
99d ago
What’s the biggest mistake people make even after installing antivirus?
99d ago
New dashboard tracks ransomware groups by their reliance on Infostealer credentials
99d ago
What would you say if your security lead said this...
99d ago
What would be the goto setup in AWS for security purposes?
99d ago
CREST CRT Exam 2025/2026 Experiences
99d ago
Microsoft Edge stores your passwords in plaintext RAM... on purpose
99d ago
Como começar?
99d ago
Possible Password Leak? Curious if Anyone Has Seen This Before
99d ago
Not a Hack. A Handout. Inside the GTFOice.org Data Exposure
99d ago
Besoin de conseils sur une DMZ automatisée
99d ago
Microsoft, Google and xAI will let the government test their AI models before launch
99d ago
Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073
99d ago
SMB Header Signature for Tagging in Firewall
99d ago
Question regarding VDP
99d ago
Working on what i should do for the next 3 years
99d ago
Question for Security Professionals
99d ago
Do tech companies lifecycle-manage public DNS records to prevent dangling DNS?
99d ago
Vulnerability Summary for the Week of April 27, 2026
99d ago
Cisco releases open-source ‘DNA test for AI models’
99d ago
Cybersecurity is becoming too AI dependent is that a problem
99d ago
Foxconn Wisconsin outage raises cyber questions
99d ago
How stressful is GRC?
99d ago
Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia
99d ago
Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India
99d ago
Archer for a non-regulated medium sized company?
99d ago
Cybersecurity statistics of the week (April 27th - May 3rd)
99d ago
Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM.
99d ago
Where to find reliable vendors?
99d ago
Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts?
100d ago
We wrote a guide on securing Claude across the enterprise — here's the core framework (with download)
100d ago
Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium.
100d ago
Hardware reverse enginnering first project. Love some advice
100d ago
Microsoft Edge Stores Passwords in Process Memory, Posing Risk
100d ago
Currently working on cybersecurity, looking for advice
100d ago
Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning
100d ago
CISO course valuation
100d ago
GRC Path to CISO (Certifications)
100d ago
CISOs and pentest buyers, what's the worst thing you've seen in a pentest report?
100d ago
How to enforce M365 Sign-in frequency on corporate laptops?
100d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
100d ago
Built an independent directory of AI Act / AI governance tools, feedback?
100d ago
ScarCruft APT group compromises gaming platform in a supply-chain attack
100d ago
Just curious
100d ago
'Copy Fail' is a real Linux security crisis wrapped in AI slop
100d ago
Analysis malicious DLL
100d ago
Cyber security free course
100d ago
Does certification expires?
100d ago
We get paid to break into buildings for a living. Ask us anything!
100d ago
Pay2Key ransomware — any recovery path that’s actually worked?
100d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
100d ago
Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF
100d ago
How have you kept growing your knowledge in security when the job stops pushing you?
100d ago
The UK’s Age Verification Law Is Producing Compliance Theater
100d ago
Microsoft Edge: Passwords end up in memory as plaintext
100d ago
Do people still get viruses in 2026, or is that mostly a myth now?
100d ago
Mitigation script for Copy Fail vulnerability CVE-2026-31431
100d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
100d ago
Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released
100d ago
DigiCert breached via malicious screensaver file
100d ago
Caido Payloads and Scanner of Endpoints
100d ago
CISO Security Mind Map 2026
100d ago
Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker
100d ago
Amazon SES increasingly abused in phishing to evade detection
100d ago
AI Security Trainings
100d ago
Ai help
100d ago
ByDesign: observed behavior where file URLs remain accessible after unshare/delete
100d ago
Can Kali Linux still compete in cyber security or is it outdated?
100d ago
Who are your favorite cybersecurity YouTubers?
100d ago
CISOs, how are you balancing AI adoption with security risks these days?
100d ago
San Diego Community College District fighting major cyberattack
100d ago
After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up
100d ago
Free resource: searchable archive of every BSides conference talk
100d ago
Lightning PyPI Compromise: Bun-Based Stealer
100d ago
Too much mother instinct?
100d ago
L1 SOC Analyst for ~2 years - Should I still get the Security + Certification?
100d ago
Do CTFs help real world security skills, or just teach patterns?
100d ago
Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo
100d ago
Should I do Security + or Network + or A+? For CompTia
100d ago
Bug bounty is ruining how people learn exploitation
100d ago
ISO/IEC 27701:2025 Scope and Location
100d ago
Cybersecurity's 2026 Wild Ride
100d ago
We built a free multiplayer game that scores prompts on AI code security.
100d ago
Production Usecases
100d ago
How does vCISO work?
100d ago
Trellix discloses data breach after source code repository hack
100d ago
CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path
100d ago
Trellix confirms source code repo access incident
100d ago
Employer Offering to Pay for my Certification test - Which one do I choose?
100d ago
John Strand Pay What You Can Information Security Core Skills live starting May 11th
100d ago
Canvas Breach May Put 275M Users, 9,000 Schools at Risk
100d ago
Is this not such a big deal
100d ago
Do email link checkers need to be 100%?
100d ago
Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
100d ago
Recs for pen testing and vulnerability solutions
101d ago
Identify telegram account holders
101d ago
AI Code Security Study: 6 LLMs vs OWASP Top 10
101d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
101d ago
We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA
101d ago
Cortex XDR Cloud Compromise Alerting
101d ago
Norton.com Verification Email out of the blue
101d ago
Atomic Red Team is now aligned with MITRE ATT&CK v19!
101d ago
Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX?
101d ago
Who are you guys using for your PCI ASV Scanning?
101d ago
Just passed my Security+ exam. Now what?
101d ago
I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work.
101d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
101d ago
[PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection)
101d ago
Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350)
101d ago
An another open door to IoT devices
101d ago
Ideas on how to have personal google-like account synchronization system
101d ago
Lateral Movement - Cross-Session Activation
101d ago
What MCP servers have actually made it into your day-to-day toolkit?
101d ago
Cyber Security Education as Self-Defence classes
101d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
101d ago
Use.ai
101d ago
Educational tech giant Instructure confirms data breach, ShinyHunters claims attack
101d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
101d ago
Browsers making connection on port 3389 from loopback
101d ago
Defender Flagged DigiCert Root Certs as Malware
101d ago
Another breach just hit Canvas (Instructure), and this one is worth a closer look.
101d ago
Over 40% of UK firms suffered cyber attack last year, survey finds
101d ago
EU should seek access to Anthropic's Mythos, Bundesbank says
101d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
101d ago
IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks
101d ago
People in cybersecurity, tell us what was the most epic moment in your career?
101d ago
Prerequisites for CARTP
101d ago
Claude Mythos Cyber Wake Up
101d ago
[ Removed by Reddit ]
101d ago
is trellix from mcafee good to use in 2026?
101d ago
Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list
101d ago
Paypal Accesed by malware me being Stupid
101d ago
How was someone in another country able to read all my private messages without my password or clicking a link?
101d ago
Career Transition Help
101d ago
Alguien para hablar de cyberseguridad
101d ago
What is this
101d ago
Feeling lost and disappointed about finding a job just venting
101d ago
Slow at Learning/Cyber Security?
101d ago
Suspicious traffic from web server
101d ago
Cyber security internship
101d ago
Mentorship Monday - Post All Career, Education and Job questions here!
101d ago
Isn't Windows Defender a crap anymore?
101d ago
Learning Cyber
101d ago
Vishing simulator
101d ago
Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others
101d ago
Worried about being tracked/banned for using an educational app on MuMu Player - Need advice
101d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
101d ago
Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance
101d ago
Prompt Injection in 2026: The Five Attack Patterns That Actually Matter
101d ago
I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine
101d ago
Random trojan detected?
101d ago
CRTA second attempt
101d ago
What’s the hardest thing to learn in cybersecurity?
101d ago
What MCP servers are you integrating into your workflow (not exclusive to security)?
101d ago
WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog
101d ago
What are like the top but unknown Cybersecurity firms?
101d ago
Need professionals or expert on cybersecurity related to dark web for interview
101d ago
A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP)
102d ago
North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory
102d ago
Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate)
102d ago
Credential Dumping: Local Security Authority (LSA|LSASS.EXE)
102d ago
Trojan:Win32/Cerdigent.A!dha
102d ago
MDE flagging digi cert certificate as malicious everywhere ?
102d ago
1867 loaded
HS
hacking: security in practice
63d ago · 241 items
DIY pwnagotchi-like device on esp32
63d ago
Flipper Blackhat + Bjorn
63d ago
Do you think AI is making hacking easier or harder
63d ago
What can i do left? PSN
63d ago
Proxmark5 campaign ending in less than 18 hours.
63d ago
How to bypass speed queen coin slot for washer and dryer
63d ago
Self-hosting stuff for when things get ugly
63d ago
Malware Includes Taboo In Text To Prevent LLM Analysis
63d ago
added Mac support for my corporate hacking game, demo on Steam
63d ago
Catfished
64d ago
What did they mean by this? One of us?
64d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
64d ago
OptOutCode – A Privacy4Cars Universal Opt-Out Concept
64d ago
StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams
65d ago
GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.
66d ago
Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏
66d ago
What's up with powershellforhackers.com?
66d ago
Do people really click on links from unknown numbers?
66d ago
How to unlock whitelabeled uniview IPcam
66d ago
Can converted video files contain malware?
67d ago
Rooted your router lately?
67d ago
5$ to whoever can find the email of my old YouTube channel
67d ago
This company is scaming people
68d ago
A modular autonomous-agent runtime written in C
68d ago
ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more
68d ago
Can one reveal the asterisks in an email?
69d ago
Proxmark3 vs Proxmark5 Side by Side
69d ago
Should I go for it?
69d ago
Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header
69d ago
Failed to verify LHOST error for long links in metasploit
69d ago
Is Marauder available for ESP32-S3 Mini?
70d ago
Gemini whatsapp
70d ago
Safe Rust API for wolfSSL/wolfCOSE
70d ago
Resource Exhaustion
70d ago
I’m not sure I’m in the right subreddit….
71d ago
Took me a decade to turn quantum computing into what hackers can easily learn
71d ago
Took me a decade of work to turn Quantum Computing into a fun videogame
71d ago
Simple way how to bypass hotel WiFi?
71d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
71d ago
burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API)
71d ago
How big of a security risk or exploit would this be?
71d ago
KTO , Be the only one online -- on any WiFi network
71d ago
apparently bypassing school systems by playing games
71d ago
Always-On Red Teams
72d ago
I managed to pull the full system prompt for Meta's Support AI
72d ago
Harassing text messages
72d ago
REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY!
72d ago
Hacking Palo Alto Networks' GlobalProtect VPN with AI
72d ago
Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am.
73d ago
Best AI LLM for Hacking related stuff
73d ago
Feels like most people ignore the wireless layer until it bites them
73d ago
Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking?
73d ago
Can anyone figure out how to retrieve the recovery key in signal app?
73d ago
$730k+ raised on Proxmark5 with 2150 backers
74d ago
I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works)
74d ago
Any idea who's behind this hack? How to resolve it?
74d ago
Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it
74d ago
Blue Team tips?
74d ago
edit certified pdf
74d ago
Everyday hacking in our lives - transportation, work, finances, goods etc
75d ago
Do you think this is legit or has the website been compromised?
75d ago
Wanna learn cybersecurity & ethical hacking
75d ago
Do you guys take paper notes or digital ones during studying ?
76d ago
How do people actually modify mobile games to increase their power?
76d ago
Why Loyalty Programs Are Quietly Becoming a Security Blind Spot
76d ago
Ajuda pessoal
76d ago
Samy Kamkar on building viruses, his arrest and privacy in the LLM era
76d ago
[ Removed by Reddit ]
77d ago
Is this considered a bug or something else entirely?
77d ago
Getting back deleted conversation from messanger
77d ago
Building Omegle for Exposed Webcams
77d ago
AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career?
77d ago
5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain
77d ago
What are the dangers of posting?
77d ago
Flipper Zero Users, What's Your Take?
78d ago
Large company with a bit of an issue free stuff
78d ago
Champion ethical hacker warns AI tools like Mythos will make competing harder.
78d ago
Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker.
78d ago
there's a toll in the hall now
78d ago
Am I crazy or is something off about this Google OAuth login via Calendly
78d ago
When “try again later” still tells you the OTP was correct: an account takeover story.
79d ago
ShadowCat: Universal optical file transfer, single html file, browser to camera
79d ago
y2jb un able to enject payloads
79d ago
Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated.
79d ago
Why did Hack Forums lose popularity?
79d ago
ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise
80d ago
Shellcide: A shellcode IDE
80d ago
Finding bot account
80d ago
How to
80d ago
Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift.
80d ago
Nmap Mastery: The Complete Guide to Network Reconnaissance
80d ago
Google wallet virtual card cloned
80d ago
What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method?
81d ago
Proxmark5 campaign unlocked the $600k stretch goal
81d ago
GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
81d ago
Doom running on a Kids Video Walkie Talkie
82d ago
Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX.
82d ago
This ID Verification company store users biometrics? (FaceTec)
82d ago
Playwright version that lets AI-Agents navigate the web
82d ago
Where to learn the ins and outs of the computer itself
82d ago
Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator
83d ago
Hack your corrupt company. Sell their secrets to the black market
83d ago
🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget
83d ago
CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat
84d ago
This ID verification company allows for storage of biometric data?
84d ago
I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :)
84d ago
SeekYou — one input, 15 recon sources, one report.
84d ago
bypass internet restrictions
84d ago
Can someone unlock a list of the 500-1000 most visited websites online?
84d ago
Wordlist generator based on WordNet graphs + LLM
84d ago
wordpress memberpress
84d ago
The Open Source USB Drive Built for Privacy
84d ago
Is someone trying to hack me?
85d ago
cpu backdoor
85d ago
Technical analysis of CVE-2026-34472 in ZTE H188A router firmware
85d ago
Ongoing development
85d ago
For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks?
85d ago
Hackers found a way around Intel CET—PLaTypus locks down library jumps
85d ago
GitHub investigates internal repositories breach claimed by TeamPCP
85d ago
Hackers: What age did you start? Where did you start, especially in practicing your skills?
85d ago
How to watch a private video on Youtube?
85d ago
Can I do anything cool with this network controller?
85d ago
Micro controller safety?
85d ago
CISA Admin Leaked AWS GovCloud Keys on Github
86d ago
Decompilation of DSP Code using IDA Pro
86d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
86d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
86d ago
Built a full disassembler & decompiler for Reverse Engineering | Free and open source.
86d ago
Slopinator - a poisoned GitHub repository generator
86d ago
Made a shell greeter that generates a unique rocket every time you open a terminal tab
86d ago
Just received an email from shinyhackers about their amtrack hack
86d ago
Flipper Zero (or Alternatives)?
86d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
86d ago
Recent WhatsApp hacks
86d ago
I wrote an async scanner that runs about 9x faster than nmap for discovery.
86d ago
Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers
86d ago
Does anyone know if this file is still accessible to download?
87d ago
High school students organized a Jeopardy CTF competition - give it a try
87d ago
Official Miasma Poison Tar Pit Docker Image Now Available
88d ago
Does anybody know where I may stumble upon some Sh1mmer bin downloads
88d ago
Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network
88d ago
GZDoom in the browser
88d ago
Anyone know how to bypass these school laptop pins?
89d ago
A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA
89d ago
I have a friend who looks like he’s a stalker I’m scared he will know I stalk him
89d ago
[Tutorial] How to hack DOS games: Reversing Prince of Persia
89d ago
Is dns spoofing dead??
90d ago
My Privacy Focused USB Drive
90d ago
Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition)
90d ago
TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer
90d ago
has anyone used tail os here?
90d ago
Run this washer/dryer sans coin?
90d ago
I built an open-source Burp alternative
90d ago
HighBoy
90d ago
Reading Siemens CT raw data
90d ago
How I use Hermes agent to turn Patch Tuesday into Windows exploit research
90d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
90d ago
Tips for a beginner noob that wants to learn
90d ago
Strix — first public beta of the spiritual successor to cSploit/dSploit
91d ago
Whatsapp
91d ago
Face ID bypass with avatar
91d ago
Hunting the Behavior Behind npm Supply Chain Attacks
91d ago
Proxmark5 Day 3 Update - $357K+ funded (715% of goal)
91d ago
Are There Really Ethical Hackers? I've Yet To Meet One
91d ago
trying to learn patching
92d ago
Cellphone IP address spoofing.
92d ago
Sorry if its the wrong place but
93d ago
Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it?
93d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
93d ago
where is the location of Files by Google on Android?
94d ago
Reading old s4 memory with xgecu t48
94d ago
Hack a data center?
94d ago
Autonomous Vulnerability Hunting with MCP
94d ago
AI DNS Resolver
95d ago
Is it true that the professionals have the worst setups?
95d ago
I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage
95d ago
Refining hacking basics — scaling them aswell
95d ago
AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic)
96d ago
Bridging the Gap Between Vulnerabilities and Working Exploits
96d ago
um you guys is my hacker stupid?
96d ago
This GBA ROM makes some weird things in the sanbox, would love to understand why
96d ago
Why was he banned?
96d ago
LAB Setup
96d ago
Ethical malware development community
96d ago
Has Instructure paid SH?
96d ago
Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me.
97d ago
New trends (not mainstream)
97d ago
Best tools to find exposed web services by HTML title / HTTP response?
97d ago
Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago?
97d ago
AI Agents Have a Security Problem. IronClaw is Fixing It.
97d ago
A hacker ran me over with a robot lawn mower - The Verge
97d ago
Happened today
97d ago
Shinyhunters and Canvas
97d ago
Modify md5sum of a file
98d ago
OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM
98d ago
Jailbreaking my cars infotainment system and implementing my own custom software
99d ago
where is the original wormgpt
99d ago
Are there any chill hacking youtubers?
99d ago
Took me a decade to turn quantum computing into what programmers can easily learn, big announcement
99d ago
Lilygo T-Embed Glitching etc
99d ago
Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today?
99d ago
Found a possibly interesting live attack
99d ago
Export/Backup ChatGPT chats
99d ago
Is this fake too?🤣
100d ago
I just figured out my dad use to be a Phreaker in the 1980s
100d ago
What of my favorite videos🙂
100d ago
Best tools for blocking spam calls and spam links?
100d ago
someone else’s UI appearing on screen for split second— possible hacker??
100d ago
Avoiding rouge AP detection in enterprise networks
100d ago
GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering
100d ago
San Diego Community College District fighting major cyberattack
100d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
101d ago
Iwas developing a hacker game that transports the feeling of the 90s
101d ago
How did this guy even access another person's privated YouTube video without wayback machine?
101d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
101d ago
IPod Nano Gets Three Monitors
101d ago
Chrome "Best AdBlocker" trojanized extension - 100k downloads.
101d ago
Any good open sources that bypass modern heuristic analysis?
101d ago
Free apex hacks?
101d ago
[SHOWCASE] Cascavel v3
101d ago
Pokemon machine
101d ago
Can HTTP POST bodies be intercepted without network or host access?
101d ago
built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4)
102d ago
Dump sql time based is too slow
102d ago
North Korea rejects US cybercrime claims as 'absurd slander'
102d ago
is credential stuffing using openbullet2 dead in 2026?
102d ago
Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax)
102d ago
Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT)
103d ago
Small models are better at cost-to-recall than large models like Mythos for vulnerability research
103d ago
Bluetooth Spoofed Disconnect?
103d ago
wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ...
104d ago
🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀
104d ago
I made a lightweight breach intelligence search engine (fully client-side) looking for feedback
105d ago
Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan...
105d ago
Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool
105d ago
Copy Fail — 732 Bytes to Root
105d ago
GitHub fixes RCE flaw that gave access to millions of private repos
106d ago
How to download Kaggle dataset safely...?
106d ago
VECT Ransomware Is Actually a Wiper
106d ago
Flipper Blackhat April Roundup!
106d ago
[VulnPath Update] Automated Email Alerting & CISA KEV Feed
107d ago
241 loaded
RE
Reverse Engineering
63d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it
63d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
63d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
63d ago
Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game
63d ago
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
63d ago
Drive Firmware Security - Phison S11
63d ago
IDA 9.4 Beta | Hex-Rays Docs
63d ago
Trane Tracer HVAC cybersecurity issues
64d ago
🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS)
64d ago
I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS.
64d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
66d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
66d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
66d ago
EMBA firmware analysis framework v2.0.2 available - Party the big 2k
66d ago
/r/ReverseEngineering's Weekly Questions Thread
66d ago
HDD Firmware Hacking Part 1
66d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction
66d ago
Zhiyun Weebil-S Camera Gimbal BLE Protocol
67d ago
Reverse Engineering the Garmin Running Dynamics BLE protocol
67d ago
Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate)
68d ago
Reverse Engineering Crazy Taxi, Part 3
68d ago
Ghidra 12.1.2 has been released!
68d ago
Extending a map tool for Cataclismo
69d ago
I've been reverse engineering a lost 2010 horse MMO and I need contributors
69d ago
HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes
69d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
69d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
69d ago
void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies
70d ago
Automated Fault Injection Attack Framework
70d ago
x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994)
70d ago
Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2
71d ago
Hacking your PC using your speaker without ever touching it
71d ago
Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source!
71d ago
Built a decompiler for exotic legacy programming language opentext Gupta Team Developer
72d ago
running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it!
72d ago
/r/ReverseEngineering's Weekly Questions Thread
73d ago
Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from?
73d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
74d ago
TinyLoad v7 - what i added :D (in memory protection using VEH and alot more)
74d ago
[ Removed by Reddit ]
74d ago
Snowboard Kids 2 is 100% Decompiled
74d ago
usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer)
74d ago
I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux)
74d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
75d ago
Ghidra 12.1.1 has been released!
76d ago
Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint)
76d ago
VMP 3.5+ Internal Architecture & Heap Dispatch Analysis
76d ago
How 2004 RuneScape fit a multiplayer RPG into 56k dial-up
77d ago
reverse engineering need for speed most wanted for modding sdk
77d ago
GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs.
77d ago
Winbox server/client reverse engineered is opensource
77d ago
(URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active
78d ago
Hypothetical EDR spoofer
78d ago
I Reverse Engineered Need for Speed Most Wanted Server
78d ago
Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation
79d ago
Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching
79d ago
How I Tried to Parse a Replay from Dawn of War: Definitive Edition
79d ago
Nocturne - A bin2bin code virtualizer for x86-64 PE binaries
79d ago
[Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing
79d ago
Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing
80d ago
I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built
80d ago
delimiter-less string obfuscation powered by compile-time AES
80d ago
/r/ReverseEngineering's Weekly Questions Thread
80d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
81d ago
Has anyone manage to reverse the macked dylib?
81d ago
Reverse engineering circuitry in a Spacelab computer from 1980
81d ago
Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology
81d ago
CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22)
82d ago
Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes
83d ago
qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb)
83d ago
Reverse Engineered Google reCAPTCHA
83d ago
Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware
83d ago
I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP
83d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
84d ago
I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries
84d ago
GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam)
84d ago
AI Agents defeat obfuscated JavaScript in 10 minutes
84d ago
What is it Wednesdays: Episode 0002
85d ago
TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post)
85d ago
Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing
85d ago
How to build .NET obfuscator
85d ago
botguard-token-generator / a google botguard token gen using only requests...?
85d ago
Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing)
86d ago
Deep dive into the object creation flow in Windows - PART 4: Handle table internals.
86d ago
Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware
86d ago
Open-source Hermes bytecode decompiler for React Native apps (Rust)
86d ago
Hermes bytecode decompiler (Rust) - sharing my friend’s project
86d ago
Forza Designer 6
86d ago
Built a full disassembler & decompiler | Free and open source.
86d ago
Snowboard Kids 2 is 100% Decompiled
86d ago
Decompilation projects and N64 Recompiled PC ports (May 2026)
86d ago
Glass - A fast and free interactive disassembler
86d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
87d ago
HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try!
87d ago
/r/ReverseEngineering's Weekly Questions Thread
87d ago
Reverse engineering no dep x64 masm AI IDE
87d ago
PE packer/crypter with random VM ISA per build
88d ago
A Tale of Two File Names
88d ago
PE reconstruction
88d ago
A File Format Uncracked for 20 Years: Part 2
88d ago
Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source!
89d ago
[CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link.
89d ago
Exploiting Toshiba Qiomem.sys vulnerable driver
89d ago
HDD Firmware Hacking Part 1
89d ago
Region-based binary diff tool for firmware analysis
89d ago
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
89d ago
แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป!
89d ago
Brovan — Open-source x86/x64 user-mode binary emulator written in C#
89d ago
Brovan: Binary user-mode emulator for x86_64
89d ago
Understanding Stack Buffer Overflows Through Doom and C++
89d ago
What is it Wednesdays: Episode 0001
89d ago
Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup
90d ago
Deepdive into the object creation flow in Windows -PART 2 : access check internals
90d ago
Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization
90d ago
[Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo)
90d ago
yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android.
90d ago
GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets
90d ago
GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS
90d ago
Trafexia V2 - Mobile Traffic Interceptor Toolkit
90d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
90d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
91d ago
Ghidra 12.1 has been released!
91d ago
Reverse Engineering Slither.io’s Network Protocol
91d ago
I Reverse-engineering Need for Speed Underground 2 Server
91d ago
I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included
91d ago
[Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features
92d ago
LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer]
92d ago
r2garlic - The world's fastest Android/DEX decompiler meets radare2!
92d ago
GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language.
93d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
93d ago
Reverse Engineering Fisher-Price Pixter
94d ago
/r/ReverseEngineering's Weekly Questions Thread
94d ago
Check out my matplotlib of BLE live wire data for Oura ring!
94d ago
Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows
94d ago
Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop
94d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
94d ago
Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)
94d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3
94d ago
PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra
94d ago
[Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc)
96d ago
Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!)
97d ago
Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2
97d ago
SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals
97d ago
I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow!
97d ago
The first FREE online WebAssembly Reverse Engineering workbench (and how we built it)
97d ago
VLC Media Player MKV Exploit Analysis
98d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
99d ago
ant4g0nist/pyre: Ghidra decompiler in your browser
99d ago
Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source!
99d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
99d ago
Reverse-engineering the 1998 Ultima Online demo server
99d ago
Inside Faxanadu series — deep dive into how this NES title works
100d ago
EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing
100d ago
Copy.fail: Why Internal LLMs Are Non-Negotiable for Security
100d ago
Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra
100d ago
Where do i find reverse engineers for actuators? Ideally in Shenzhen
100d ago
[CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2).
100d ago
[WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation
101d ago
IDA-MCP Is Now RE-MCP With Ghidra Support
101d ago
Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference
101d ago
/r/ReverseEngineering's Weekly Questions Thread
101d ago
GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions)
101d ago
Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo
102d ago
Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you!
102d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
102d ago
How to build .NET obfuscator - Part II
102d ago
libghidra - SDK for automating Ghidra from Python, Rust, and C++
103d ago
Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis.
103d ago
Why my macOS Messages badge lied to me (and the one-line fix)
103d ago
Running Adobe’s 1991 PostScript Interpreter in the Browser
104d ago
Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :)
104d ago
/r/ReverseEngineering's Triannual Hiring Thread
104d ago
In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off)
104d ago
Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight
105d ago
HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try!
105d ago
GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).
105d ago
I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway
106d ago
Building a perfect clone of 1993 game SimTower (via RE)
106d ago
How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema
107d ago
AI solved our CTF in 6min
107d ago
Example structure for evidence-based vulnerability reports
107d ago
181 loaded
FB
For [Blue|Purple] Teams in Cyber Defence
63d ago · 603 items
US charges suspected Russian hacker with facilitating cyber campaign
63d ago
Hawkish GOP lawmaker Don Bacon says he was hacked by Russia
63d ago
Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
63d ago
GreatXML: GreatXML bitlocker bypass vulnerability
63d ago
GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan
63d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
63d ago
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion
63d ago
GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default
63d ago
Miasma-style supply chain attacks
63d ago
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet
63d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
63d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
64d ago
Testing offensive AI agents in a cloud lab with deception tech
64d ago
Benchmarking n-day exploit generation [via AI]
64d ago
Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
64d ago
Microsoft Defender now monitors RPC activity
64d ago
RoguePlanet: RoguePlanet Windows Defender Vulnerability
64d ago
I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in)
64d ago
How do you make learning blue team security entertaining ?
64d ago
Maximizing IOC Impact
64d ago
[2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution
65d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
65d ago
Entra Agent ID from a Security Perspective
65d ago
Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility
65d ago
What are the best risk-based vulnerability management tools for tracking active exploitation in 2026?
65d ago
QuasarNix: Reverse Shell Detection with Machine Learning
65d ago
Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go
65d ago
Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion
65d ago
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
65d ago
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
65d ago
UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season
65d ago
Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
65d ago
Visual Studio Code 1.123: Delayed extension auto-updates
65d ago
Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.
65d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched,
65d ago
Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement
65d ago
HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified)
66d ago
Security Review Request — TID Linux Kernel Module
66d ago
Building a safe, effective sandbox to enable Codex on Windows
66d ago
Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale.
66d ago
About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection
66d ago
BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection
66d ago
Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution.
66d ago
UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service.
66d ago
EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
66d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
67d ago
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
67d ago
cygor: An modular asset discovery framework written in python to automate the repeating manual work
67d ago
On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts.
67d ago
Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors.
67d ago
Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim
67d ago
Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored)
67d ago
The Privileged Roles Nobody Talks About
67d ago
Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain...
67d ago
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
67d ago
21 Zero-Days in FFmpeg
67d ago
depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research?
67d ago
CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work
67d ago
The Detection & Response Chronicles: Covert Operations Through QEMU
67d ago
The Interesting Case of WSL for Payload Staging
67d ago
The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer
67d ago
Ongoing Targeted Campaign Against US Law Firms
67d ago
New China-Linked Cluster OP-512
67d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
68d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
68d ago
MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain
68d ago
Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated
68d ago
Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns
68d ago
About ETW Internals: Architecture, Hooking, Tampering, and Detection
68d ago
PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver
68d ago
Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
68d ago
Async PICOs and Custom Beacon Wakeups in Cobalt Strike
68d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
68d ago
staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs
68d ago
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window
68d ago
Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS
68d ago
BOF Cocktails in Cobalt Strike
68d ago
Address Translation
68d ago
Investigation into APT 5 and their inner workings of PLA Troop 61786
68d ago
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
68d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
68d ago
Magecart skimmer turns Stripe into a malware command server
68d ago
Security advisory: Brute force attack on Dashlane user accounts
68d ago
Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability
68d ago
A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact).
68d ago
IronWorm: Shai-Hulud's rustier cousin
68d ago
Weil reportedly pays up to $20 million after hackers steal client data
68d ago
CTO at NCSC Summary: week ending June 7th
68d ago
defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
68d ago
1-Click GitHub Token Stealing via a VSCode Bug
68d ago
The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds
68d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
68d ago
Introducing Package Proxy: supply-chain safety checks without client-side software
69d ago
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
69d ago
zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS)
69d ago
The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory
69d ago
VerdantBamboo: Just Another BRICKSTORM in the Firewall
69d ago
AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID
69d ago
MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code
69d ago
IronWorm Supply Chain Malware Hits npm
69d ago
FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel
69d ago
FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad
69d ago
You do surprise me.exe: An unexpected executable in Hola Browser
69d ago
LSASS/Defender/CTFMON analysis
70d ago
Software supply chain attacks: check your dependencies
70d ago
Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator
70d ago
29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection)
70d ago
Open Source - 2500 New MITRE Mutations
70d ago
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
70d ago
Bring Your Own RWX Region DLL (BYORWXDLL)
70d ago
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
70d ago
APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component
70d ago
NuGet Code Execution As A Service
70d ago
aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies
70d ago
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
70d ago
TA4922: The Suspected Chinese Crime Group is Going Global
70d ago
[ Removed by Reddit ]
70d ago
Espionage Campaign Targeted Stock Exchange Executive for Five Months
70d ago
OnionAccelerator: multi-circuit / chunked download acceleration over Tor
70d ago
HazyBeacon and AWS Lambda Function URL Abuse
71d ago
The Server Seizure That Affects Also Iran's Cyber Operations
71d ago
How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad
71d ago
🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network
71d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
71d ago
Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors
71d ago
Dependency Cooldowns - Dependency Cooldowns
71d ago
C2 Frameworks - Threat Hunting in Action with YARA Rules
71d ago
Ransomware tabletop
71d ago
Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026
71d ago
Tracking North Korea Nation-State APT Infrastructure: Kimsuky
71d ago
새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn
71d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
71d ago
Codex Discovered a Hidden HTTP/2 Bomb
71d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
71d ago
Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix
71d ago
“Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?”
72d ago
Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif
72d ago
Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand
72d ago
Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm
72d ago
RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation
72d ago
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
72d ago
Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches
72d ago
Miasma: Supply Chain Attack Targeting RedHat npm Packages
72d ago
@redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers
73d ago
Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched
73d ago
Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks
73d ago
Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries
73d ago
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
73d ago
Atomdrift - open-source malware detection for the software supply chain
73d ago
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
74d ago
179 npm Packages Target Cloud and Finance via oob.moika.tech
74d ago
KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4
74d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
74d ago
Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services
74d ago
EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA
74d ago
Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace
74d ago
Signal macOS Desktop App Doesn't Actually Delete Messages When it Should
74d ago
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
74d ago
WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD
74d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
74d ago
Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2
74d ago
Malicious npm packages abuse dependency confusion to profile developer environments
74d ago
Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
74d ago
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack
74d ago
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
74d ago
Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign
74d ago
SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.
74d ago
EDR Incident Response Playbook: Containing Local Account Incidents
74d ago
Adversarial Oracles: LLM-Guided EDR Signature Reduction
74d ago
One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF
74d ago
proxy: A lightweight caching proxy for package registries.
74d ago
How OLTs may have exposed entire ISP networks
74d ago
A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
74d ago
HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics
74d ago
Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots
74d ago
Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures
74d ago
Lessons from Penetration Tests on Large-Scale Agent Systems
74d ago
pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter.
74d ago
CIFSwitch: a non-universal Linux local root vulnerability
74d ago
Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension
75d ago
DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.
75d ago
Visual Studio Extensions Revisited
75d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
75d ago
BYOVD and Looting LSASS in the Modern EDR Era
75d ago
CTO at NCSC Summary: week ending May 31st
75d ago
OffensiveCon26 videos
75d ago
School Survey, (non-paid nothing its free its for my grades)
75d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
75d ago
LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms
75d ago
LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting
76d ago
Identifying attack patterns through kernel frame callstacks
76d ago
Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness
76d ago
What safety boundary would you expect from a local AI incident investigation tool?
76d ago
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
76d ago
Why I Built My Own LLM Benchmark for THOR Finding Triage
76d ago
Casdoor contains multiple authentication bypass and access management vulnerabilities
76d ago
The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents
76d ago
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
76d ago
Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies
76d ago
Malware seller hunted across three continents
76d ago
Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims
76d ago
Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers
76d ago
Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network
76d ago
Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations.
76d ago
The C-suite job that's burning people out faster than any other
76d ago
New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation
76d ago
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
76d ago
Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances
76d ago
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
76d ago
APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026
76d ago
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
76d ago
Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
76d ago
Zero Trust Implementation Guidelines
76d ago
BlackToad: Network Manipulation in an AutoIt Payload
77d ago
RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT
77d ago
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
77d ago
Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit
77d ago
FROST: Fingerprinting Remotely using OPFS-based SSD Timing
77d ago
Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup
77d ago
puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
77d ago
Who is Salt Typhoon Really? Unraveling the Attribution Challenge
77d ago
Looking for resources on end-to-end APT attack flow summaries for detection engineering
77d ago
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
77d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP
78d ago
Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint
78d ago
Building Detection Engineering on AWS from scratch — roast my plan
78d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
78d ago
Designing secure access with ZTNA
78d ago
MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response
78d ago
White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats
78d ago
Advisory X41-2026-002: Request Host Header not Validated in Starlette
78d ago
Top ethical hacker Chompie warns AI tools could put her out of business
78d ago
浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents
78d ago
YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions
78d ago
CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state
78d ago
The Evolution of Chinese-language Phishing Services
78d ago
Silent Ransom Group Impersonating IT Personnel through Social Engineering
78d ago
The epoll UAF - an epoll uaf race in fs/eventpoll.c
78d ago
Tycoon 2FA AiTM detection for Entra ID and Google
78d ago
Microsoft Copilot Cowork Exfiltrates Files
78d ago
Unpatched Sparx vulnerabilties
78d ago
sylvia: iOS Syscall Explorer for IDA 9.X
79d ago
Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East
79d ago
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip
79d ago
JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign
79d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack
79d ago
Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@"
79d ago
The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization
79d ago
GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
79d ago
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
79d ago
CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700.
79d ago
YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos
80d ago
Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it
80d ago
honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports
80d ago
Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild.
80d ago
Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council
80d ago
RemotePE: The Lazarus RAT that lives in memory
80d ago
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
80d ago
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
80d ago
Twee mannen aangehouden voor phishing - Two men arrested for phishing
80d ago
Sharp Eyes: Mass surveillance of foreigners in China
80d ago
relay_bible: Technical Reference to multiple relay techniques
80d ago
Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec
80d ago
The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in]
80d ago
SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format
80d ago
North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial
80d ago
Staged publishing and new install-time controls for npm - GitHub Changelog
80d ago
Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES
81d ago
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
81d ago
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow
81d ago
The Future and Past of Residential Proxies
81d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
81d ago
Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy
81d ago
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
81d ago
A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software
81d ago
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
81d ago
Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities
81d ago
Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes
81d ago
mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
81d ago
keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust.
81d ago
np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.
81d ago
Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up.
81d ago
OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
81d ago
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
81d ago
FatGid - FreeBSD 14.x kernel LPE
81d ago
Manage [VSCode] extensions in enterprise environments
81d ago
angr: A powerful and user-friendly binary analysis platform!
81d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
81d ago
How Attackers Force Microsoft to Send Phishing Emails
81d ago
Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
81d ago
Microsoft Authenticator App Details now exposed in Entra SignInLogs
81d ago
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
81d ago
How China-linked threat actors obtain zero-day vulnerabilities
81d ago
Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research
81d ago
Monitoring for vssadmin.exe delete shadows is an absolute bare minimum
81d ago
Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack
81d ago
How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers
81d ago
CVE-2026-48029: Two grid-decode bugs in libheif
81d ago
workcell: Bounded local runtime and policy boundary for coding agents
81d ago
OpenShell: OpenShell is the safe, private runtime for autonomous AI agents.
81d ago
Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation
81d ago
Built a SOC from scratch with no prior SOC experience
81d ago
CTO at NCSC Summary: week ending May 24th
82d ago
VPN Exploitation When Patched Doesn't Mean Protected
82d ago
Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation
82d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
82d ago
CLR-Stomp: .NET CLR-Stomping
82d ago
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
82d ago
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms
82d ago
Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor
82d ago
AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22)
82d ago
GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks.
82d ago
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
82d ago
Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL?
83d ago
I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner
83d ago
AI-generated reporting: Lessons learned from Cisco Talos Incident Response
83d ago
CrabLoader: A PoC Cobalt Strike UDRL written in Rust
83d ago
The 429 Microsoft Graph Mystery
83d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
83d ago
Azure Tenant Enumeration is Dead
83d ago
A Deep Dive into Codex Windows Sandbox
83d ago
Striga: Lifting x86 to LLVM IR with Python
83d ago
veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker.
83d ago
Windows BitLocker Security Feature Bypass Vulnerability
83d ago
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
83d ago
Google API keys keep working after you delete them long enough to be exploited
83d ago
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
83d ago
North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT
83d ago
Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit
83d ago
Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names)
83d ago
Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
83d ago
Megalodon: CI/CD Malware Spreading Across GitHub Repositories
83d ago
📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity.
83d ago
Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
84d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
84d ago
beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA
84d ago
Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading
84d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
84d ago
Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign
84d ago
From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree
84d ago
How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102)
84d ago
Iran-linked Operators Suspected in ATG Breaches
84d ago
Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs
84d ago
Compromised Nx Console version 18.95.0
84d ago
CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
84d ago
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
84d ago
Webworm: New burrowing techniques
84d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
84d ago
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
84d ago
Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation
84d ago
GitHub’s Fake Engagement Problem Is Hiding in Plain Sight
84d ago
Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR)
84d ago
Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage
84d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
85d ago
5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready
85d ago
Remote Process Read Primitive via NtCreateThreadEx Exit Code
85d ago
aimap: Discover Exposed AI Services
85d ago
FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation.
85d ago
Why China Is Now a Peer Competitor to the United States in Cyberspace
85d ago
nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings
85d ago
Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt
85d ago
We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.
85d ago
Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings)
85d ago
Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
85d ago
Eight Leading U.S. Communications Firms Form C2 ISAC
85d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
85d ago
UAC-0184: From HTA to a Signed Network Stack
86d ago
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
86d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
86d ago
Entra ID: PIM for Groups Review
86d ago
TeamPCP compromises NPM maintainer with over 540 packages
86d ago
Active Supply Chain Attack Compromises @antv Packages on npm...
86d ago
When DMCA Comes Knocking - A YouTube Creator Phishing Kit
86d ago
[Cloudflare] Project Glasswing: what Mythos showed us
86d ago
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
86d ago
Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger
87d ago
Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics
87d ago
CrystalX: unpacking a Go RAT through three encrypted layers
87d ago
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write
87d ago
FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation
87d ago
LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying"
88d ago
Static Kitten APT Adversary Simulation
88d ago
Eimeria: five layers from RAR5 to RunPE
88d ago
ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
88d ago
openDCIM exploitation
88d ago
HASBL CTF - A Jeopardy-Style CTF Organized by High School Students!
88d ago
We Have Packet Capture at Home
88d ago
Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware
88d ago
HWMonitor Trojanized for STX RAT DLL Sideloading
88d ago
awesome-dfir-skills: Admiralty System for CTI Claude skill
88d ago
Mullvad exit IPs as a fingerprinting vector
88d ago
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
88d ago
Popular node-ipc npm Package Infected with Credential Steale...
88d ago
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
88d ago
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
88d ago
Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
88d ago
Sandworm Activity in Industrial Environments: What the Data Reveals
88d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
88d ago
"Shadowserver-in-a-box" IntelMQ + ELK Solution
88d ago
Stenloader: Steganography Shellcode Loader
88d ago
AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out
88d ago
Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018
88d ago
Our response to the TanStack npm supply chain attack
88d ago
QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026).
88d ago
We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase.
88d ago
APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox.
88d ago
oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday
88d ago
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations
88d ago
OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance
88d ago
The Gentlemen Ransomware Group — Leak Analysis
88d ago
HDD Firmware Hacking Part 1
88d ago
ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.
88d ago
CTO at NCSC Summary: week ending May 17th
88d ago
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
89d ago
Developer credential-theft campaign exposed operator-side self-infection
89d ago
Help-Desk Lures Drop KongTuke's Evolved ModeloRAT
89d ago
Welcome to BlackFile: Inside a Vishing Extortion Operation
89d ago
DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era
89d ago
Stop Being Weird — Life After Call Stack Spoofing Under CET
89d ago
Triggering the Secure Boot Certificate Update with Intune Remediations
89d ago
How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache
89d ago
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
89d ago
One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities
89d ago
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
89d ago
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
89d ago
FamousSparrow APT Targets Azerbaijani Oil and Gas Industry
89d ago
Disclosing new PebbleDash-based tools by Kimsuky
89d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
89d ago
Kazuar: Anatomy of a nation-state botnet
89d ago
OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments
89d ago
NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys
89d ago
Hacker Ringleader Extradited for 38 Billion Won Theft
89d ago
Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System
89d ago
Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit
89d ago
The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation
89d ago
FFFFirefox - A One-Day Wonder Renderer Exploit
89d ago
MiniPlasma, a powerful LPE
89d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
89d ago
[Tool] IOCX — deterministic static IOC extraction for PE binaries
90d ago
Novel Evilginx Frontend - Lowering the barrier for token theft reuse
90d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
90d ago
WAF Evasion Engine
90d ago
Thus Spoke…The Gentlemen
90d ago
KQLab - open-source query manager for SOC teams
90d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown
90d ago
Microsoft AntiSSRF
91d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
91d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
91d ago
How fast is autonomous AI cyber capability advancing?
91d ago
YellowKey: YellowKey Bitlocker Bypass Vulnerability
91d ago
Tinker Tailor Soldier: Paper Werewolf’s latest toolkit
91d ago
126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies
91d ago
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
91d ago
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise
91d ago
[HOMELAB] Built a SOC investigation console on two old Dell boxes
92d ago
Android Intrusion Logging as a new source of data for consensual forensic analysis
92d ago
Shai-Hulud: Another Wave and Going Open Source
92d ago
A stealth approach to Process Injection - EntryPoint Hijacking
92d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
92d ago
Service Principal Sign-Ins: A blind spot that a lot are missing
92d ago
My Analysis of a Bandook RAT PCAP
92d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
92d ago
Detection Rule is here
92d ago
Owning a service principal equals owning its permissions.
92d ago
Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection
92d ago
CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.
92d ago
AI+DFIR Challenge: Share Your Disasters and Successes
93d ago
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
93d ago
Postmortem: TanStack npm supply-chain compromise
93d ago
bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages
93d ago
rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions
93d ago
Detecting Remote Thread Creation with Windows Driver
93d ago
Mythos finds a curl vulnerability
93d ago
Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details
93d ago
Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
93d ago
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
93d ago
esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app
93d ago
LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors.
93d ago
How Cloudflare responded to the “Copy Fail” Linux vulnerability
93d ago
I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic.
93d ago
LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots.
93d ago
New Shai-Hulud npm worm variant
93d ago
EtwWatcher
93d ago
Donuts and Beagles: Fake Claude site spreads backdoor
93d ago
Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach
94d ago
CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection
94d ago
Deterministic PE Validation for Blue Teams - IOCX v0.7.3
94d ago
Delving deep into threat detection: My logic for abnormal EventID 7 activity
94d ago
NZ announces sanctions on malicious Russian cyber actors, online platforms
94d ago
Update: Ongoing Checkmarx Supply Chain Security Incident
94d ago
ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025
94d ago
Unmanaged PowerShell Execution: Hunting Beyond powershell.exe
94d ago
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign
94d ago
Static Devirtualization of Themida
94d ago
Now You See Me: AADGraphActivityLogs
94d ago
[Write-up] CyberDefenders: Wiredive Lab
94d ago
page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
95d ago
JDownloader — Website installer incident (May 2026)
95d ago
The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate."
95d ago
AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT
95d ago
EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine)
95d ago
Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers
95d ago
Writing a Naive LLVM-based Devirtualizer
95d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
95d ago
When prompts become shells: RCE vulnerabilities in AI agent frameworks
96d ago
Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus
96d ago
MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174)
96d ago
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor
96d ago
Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles.
96d ago
Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026
96d ago
Member of Prolific Russian Ransomware Group Sentenced to Prison
96d ago
EasterBunny: advanced espionage artifacts attributed to APT29
96d ago
Tracking the "Sorry" Extortionist Campaign Against cPanel Websites
96d ago
PositiveIntent: Evasive loader for .NET Framework assemblies
96d ago
The Accidental C2: Exploring Dev Tunnels for Remote Access
96d ago
Living of the Land - DISM Sandbox Provider Hijack
96d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
96d ago
CTO at NCSC Summary: week ending May 10th
96d ago
ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure
96d ago
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
96d ago
Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo
96d ago
DARWIS Taka - Web vulnerability scanner with Optional AI Validation
96d ago
SunnyDayBPF: eBPF telemetry integrity research for detection engineering
96d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama
97d ago
Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou...
97d ago
Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack
97d ago
Dirty Frag: Universal Linux LPE
97d ago
Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication.
97d ago
Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea
97d ago
Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia
97d ago
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI
97d ago
Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC
97d ago
Detecting BEC Persistence with KQL
98d ago
Unpacking Russian-Iranian Private-Sector Cyber Connections
98d ago
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
98d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
98d ago
Inadvertent Injections
98d ago
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
98d ago
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
99d ago
Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed
99d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
99d ago
UAT-8302 and its box full of malware
99d ago
CVE-2026-0073 Android adbd TLS client-authentication bypass
99d ago
One KQL query you should have saved in your toolkit (most don’t)
99d ago
CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier?
99d ago
Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside
99d ago
🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records
99d ago
Popular DAEMON Tools software compromised
100d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
100d ago
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
100d ago
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
100d ago
Accelerating Vulnerability Detection and Response at Oracle
100d ago
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
100d ago
GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated.
100d ago
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
100d ago
N-Day Research with AI: Using Ollama and n8n
100d ago
38 CVEs in Healthcare Software Used by 100,000 Medical Providers
100d ago
Recursively fuzzing MS-RPC structures and monitoring using ETW
101d ago
VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases
101d ago
CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation.
101d ago
《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition)
101d ago
nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution.
101d ago
蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery.
101d ago
gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives
101d ago
Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon
101d ago
AMSI Page Guard Bypass (Rust PoC)
101d ago
Meet Bluekit: The AI-Powered All-in-One Phishing Kit
101d ago
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
101d ago
A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia
101d ago
IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect
101d ago
Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
101d ago
ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution…
101d ago
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
101d ago
[2603.28728] Study of Post Quantum status of Widely Used Protocols
101d ago
Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin
101d ago
Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning
101d ago
code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.
101d ago
Secure Boot Inventory Data In Configuration Manager
101d ago
EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time.
101d ago
MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning.
101d ago
AI-powered honeypots: Turning the tables on malicious AI agents
101d ago
copy.golf — golf your exploits - smaller copy.fail exploits..
101d ago
DragonBreath: Dragon in the Kernel
101d ago
Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors.
101d ago
Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
102d ago
Puzzle: Set of PoC to abuse Windows minifilters functionality
102d ago
A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16
102d ago
Active exploitation of cPanel/WHM critical vulnerability
102d ago
Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. "
102d ago
5 Qilin ransomware servers exposed over 7 months
102d ago
South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)
102d ago
Russian Charged in Oil and Gas Facility Hacks Pleads Guilty
102d ago
VECT ransomware: small files decrypt, large files lose their nonces
102d ago
CTO at NCSC Summary: week ending May 3rd
102d ago
April 27th - What happened with our feature flag configuration | The ClickUp Blog
102d ago
Blog: Evolving the Android & Chrome VRPs for the AI Era
103d ago
Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.
103d ago
VECT: Ransomware by design, Wiper by accident
103d ago
VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built.
103d ago
Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison
103d ago
Agentic Malware Analysis: From Task Automation to Deep Analysis
103d ago
pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner.
103d ago
month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only
103d ago
603 loaded
MA
Malware Analysis & Reports
63d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
63d ago
ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper
64d ago
WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap
64d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
64d ago
Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment
65d ago
73 Microsoft GitHub repositories impacted by Miasma malware
66d ago
Unauthorized Onlyfans Payment
66d ago
Building A Malware Lab From Scratch Part 2!
68d ago
Detecting npm Native Addon Malware: node-gyp Abuse
68d ago
Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links
69d ago
Extremely suspicious behaviour by memu emulator
70d ago
Malware
70d ago
🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop
71d ago
ChatGPT Malvertising Campaign
71d ago
Recommendation
71d ago
Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6!
71d ago
This is a scam and probably a malware/trojan. Path Of Exile 2 builder ...
72d ago
LLMShare: using shared chatbot pages to distribute malware
72d ago
How to Unpack FlawedAmmyy - Malware Unpacking Tutorial
73d ago
Building A Malware Lab From Scratch!
74d ago
I bought an old phone from 2018 and wanna destroy it with viruses for fun
74d ago
Malware escaped browser without downloading files, then escaped a virtual machine
75d ago
I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but
76d ago
A Deeper Look at GLASSWORM's Solana Variant
77d ago
Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15
77d ago
Kali365 Activity Surges: Device Code Phishing Is Scaling Fast
77d ago
MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
78d ago
Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io)
78d ago
Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down.
78d ago
How random program can cause most of antiviruses close himself without telling himself to close
79d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
79d ago
Suspicious ass website asking to run a terminal command (MacOS)
80d ago
Harvard and 140 other legitimate websites compromised
83d ago
Browser session theft is quietly becoming more dangerous than password theft
83d ago
Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
83d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account
83d ago
Database of Malicious Browser Extensions
84d ago
I’ve got 99 problems, and IOCX isn’t one.
84d ago
Can't access anything
85d ago
New GMKtec M7 Ultra appears to be infected. Beware of the malware!
86d ago
vpn explained the simple version that actually makes sense
86d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
87d ago
Netmirror exposed - The Free Movie App That Was Robbing You Blind
87d ago
Malware learning
88d ago
Brovan: Binary user-mode emulator for x86_64
89d ago
Inspecting a DLL file trying to figure out if it really is malware
90d ago
npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output
90d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
91d ago
I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable...
91d ago
clens.io - new public threat & data intel service
91d ago
Granny’s Compromised Android Firmware
92d ago
[Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
92d ago
OS scanner that checks repos for traces of the Shai Hulud worm
92d ago
Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI
92d ago
Steam spear phishing
93d ago
Fake linked in sponsored google search
93d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
93d ago
New Shai-Hulud npm worm variant
93d ago
looking for "evil" Websites
94d ago
Deterministic PE Structural Validation in IOCX v0.7.3
94d ago
sl1nk link
94d ago
How to download a RAT for myself
94d ago
Wtf OPEN Ai
96d ago
JDownloader's official website delivered Python RAT
97d ago
An unknown malware threat. There is no such thing as a 100% detection.
98d ago
Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites
98d ago
Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML
98d ago
Discord bot C2 infrastructure
99d ago
IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening
100d ago
Panicking
100d ago
Supply chain attack: DAEMON Tools Lite now contains a backdoor.
100d ago
Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation
101d ago
VirusTotal has one flag for this sus site
102d ago
Anyone wanna learn the CEH or OSCP red teaming free
102d ago
Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself
104d ago
Minecraft Malware C2 Tracking
104d ago
Minirat malware deployed via NPM targeting macOS machines
106d ago
VECT Ransomware Is Actually a Wiper
106d ago
The Malware Factory: GLASSWORM Forensics in Open VSX
106d ago
Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore
106d ago
[ Removed by Reddit ]
107d ago
Ikeja Electric Distribution Ransomware
107d ago
Recently updated a authentic minecraft mod launcher called Modrinth
107d ago
This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0
108d ago
Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely
108d ago
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses
109d ago
Save time and use Zig to write your Malware POC
110d ago
Cracking CastleLoader’s Inno Setup Password
110d ago
I built a C2 framework that uses Discord and Telegram for communication
110d ago
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet.
111d ago
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
111d ago
PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs
111d ago
Budgiekit - gdi malware maker (for educational purporses only)
112d ago
19 confirmed repos tied to the same GitHub malware campaign
113d ago
IOCX v0.7.0 — deterministic heuristics + adversarial PE samples
114d ago
I built a kernel-level EDR and hit architectural walls I didn’t expect
175d ago
Update your detection rules: New remote access Trojan
176d ago
Criminals are using AI website builders to clone major brands
176d ago
Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants)
176d ago
PE Loader For Fileless Malware
177d ago
Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers
177d ago
AWAKE - Android Wiki of Attacks, Knowledge & Exploits
177d ago
I built a Chrome extension that scans for malicious extensions (yes, I see the irony)
177d ago
Questions regarding malicious pdf's
179d ago
AV persistence bypass techniques
180d ago
Avalon Linux Bot Malware Analysis
181d ago
Leveling up in Windows malware research
182d ago
Emerging Ransomware: BQTLock and GREENBLOOD
183d ago
Malware Development POCs
183d ago
Suspicious code in Up-work linked repository.
183d ago
We hid backdoors in binaries — Opus 4.6 found 49% of them
184d ago
👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡
185d ago
Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions
185d ago
Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer
186d ago
Nyxara
189d ago
115 loaded
SM
Security | Microsoft Azure Blog | Microsoft Azure
72d ago · 6 items
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
72d ago
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
101d ago
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
104d ago
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
Azure IaaS: Keep critical applications running with built-in resiliency at scale
134d ago
Learn how Azure IaaS helps organizations start from a resilient platform foundation with availability, continuity, and recovery capabilities.
Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure
162d ago
Learn how Azure IaaS helps you modernize infrastructure, improve performance and resilience, optimize costs, and prepare for AI workloads. Read more.
Azure reliability, resiliency, and recoverability: Build continuity by design
177d ago
Learn how Azure reliability, resiliency, and recovery capabilities work together to improve cloud continuity. Read more.
ZU
ZDI: Upcoming Advisories
105d ago · 1 items
CC
CISA Cybersecurity Advisories
114d ago · 2 items
Defending Against China-Nexus Covert Networks of Compromised Devices
114d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
129d ago
U.S. organizations should review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the
BA
Blog Articles - Identity Insights | Trulioo
118d ago · 13 items
Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business
118d ago
What is Customer Due Diligence (CDD)
142d ago
Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud
145d ago
AML, KYC and Identity Verification in Australia
154d ago
When Fraud Becomes Background Noise: The Industrialization of Digital Deception
220d ago
The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage
220d ago
The End of Static KYB: Business Identity in Constant Motion
220d ago
Know Your Agent: The Next Chapter in Digital Trust
220d ago
When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage
220d ago
Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration
239d ago
The World’s Identity Platform
1290d ago
KYC: 3 Steps to Achieving Know Your Customer Compliance
1561d ago
AML Compliance Checklist: Best Practices for Anti-Money Laundering
1576d ago
13 loaded
II
InfoSec Insights
155d ago · 1 items
FP
Fraud Prevention Archives - Alloy Silverstein
161d ago · 10 items
AI in Tax Season: Risks, Scams, and How to Protect Your Data
161d ago
Tax Season Scams to Watch For This Year
168d ago
Beware of Misleading Tax Advice on Social Media
336d ago
Each year the IRS educates taxpayers on the most trending fraud schemes that could deceive individuals and businesses during tax season. In late 2024, The IRS took to warning the public against misleading “tips” or...
Scammers Up Their Game With AI
337d ago
Learn how to spot the threats and protect yourself from scammers using AI for phishing and deepfakes with smart security practices.
The Essential Guide to Safeguarding Your Online Passwords
415d ago
Protect your personal and business data with strong passwords, two-factor authentication, and smart cybersecurity practices.
Beware: Tax Season is Scam Season
526d ago
Tax season is also prime time for tax scams. To safeguard your personal information, consider these key points: Communication methods The IRS initiates contact primarily through mail, not email or phone calls. Be cautious of...
Stop Scams: Fraud Prevention Starts with Your Employees
539d ago
You can be as proactive and protective as possible when it comes to cyber security for your business, but there’s one vulnerability you cannot eliminate: human error. In fact, statistics estimate that as much as...
‘Tis the Season for Holiday Shopping Scams
612d ago
The holidays are typically the time of year for gifting presents to friends and family or donations to charity. Unfortunately, not-so-jolly fraudsters take advantage of this generosity. Protect yourself by watching for these common scams:.....
IRS Issues “Dirty Dozen” Fraud Warnings
797d ago
Each year, the IRS releases a “Dirty Dozen” series to highlight the most common fraud schemes taxpayers should be aware of.
IRS Identity Theft Season Begins Now
926d ago
Each year thieves try to steal billions in federal withholdings by stealing your identity. As the IRS focuses more attention on this quickly growing problem, now is the time of year to be extra vigilant....
HA
HackerSploit
491d ago · 15 items
How FIN6 Exfiltrates Files Over FTP
491d ago
Emulating FIN6 - Active Directory Enumeration Made EASY
542d ago
The SECRET to Embedding Metasploit Payloads in VBA Macros
547d ago
Offensive VBA 0x4 - Reverse Shell Macro with Powercat
555d ago
Offensive VBA 0x3 - Developing PowerShell Droppers
561d ago
Offensive VBA 0x2 - Program & Command Execution
566d ago
Offensive VBA 0x1 - Your First Macro
568d ago
Emulating FIN6 - Gaining Initial Access (Office Word Macro)
573d ago
FIN6 Adversary Emulation Plan (TTPs & Tooling)
577d ago
Developing An Adversary Emulation Plan
577d ago
Introduction To Advanced Persistent Threats (APTs)
581d ago
Introduction To Adversary Emulation
603d ago
Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion
612d ago
Planning Red Team Operations | Scope, ROE & Reporting
752d ago
Mapping APT TTPs With MITRE ATT&CK Navigator
756d ago
15 loaded
TH
Threatpost
1443d ago · 10 items
Student Loan Breach Exposes 2.5M Records
1443d ago
2.5 million people were affected, in a breach that could spell more trouble down the line.
Watering Hole Attacks Push ScanBox Keylogger
1444d ago
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
1445d ago
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Ransomware Attacks are on the Rise
1448d ago
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
1448d ago
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Twitter Whistleblower Complaint: The TL;DR Version
1450d ago
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Firewall Bug Under Active Attack Triggers CISA Warning
1451d ago
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Fake Reservation Links Prey on Weary Travelers
1452d ago
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
iPhone Users Urged to Update to Patch 2 Zero-Days
1455d ago
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Google Patches Chrome’s Fifth Zero-Day of the Year
1456d ago
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
No matching sources found.