How to report an AI Act violation in the EU
Learn how to report an AI Act violation in the EU. See which of the three official channels fits your situation, and how to file with each.
Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t
200 accounts compromised in Swiss government’s Microsoft SharePoint breach
200 Swiss government accounts were compromised after hackers exploited Microsoft SharePoint vulnerabilities at federal IT office BIT.
OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens
OpenAI has updated GPT-5.6 Sol for paid ChatGPT users and rolled out GPT-5.6 Luna with unlimited chats for the free tier.
Keepit AI Truth Cloud protects the data behind enterprise AI
Keepit launches AI Truth Cloud, giving enterprise AI a verified, immutable data foundation it can trust and roll back to.
August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse?
Todd Schell from Ivanti gives his overview of July 2026 and forecast for August 2026 Patch Tuesday. Are you ready to get patching?
What the first year of EU AI Act transparency enforcement could look like
Edwin Weijdema of Veeam on EU AI Act transparency, Article 50 enforcement, agentic AI, and phishing tests that use cloned voices.
US fuel gauge exposure fell by more than half in three months
US automatic tank gauge exposure fell 56% in three months after Iran-linked attack warnings. New data shows the drop is real, and partial.
ShieldFont fights AI scraping by handing crawlers the wrong words
ShieldFont AI scraping defense swaps words in your HTML, so readers see your writing and crawlers take away a fluent, wrong copy of the page.
Gut feeling does nothing against AI spear phishing texts
In a 25-person pilot, targets identified AI spear phishing texts 52% of the time. Work-themed messages drew the most intended clicks.
What's New
Top 5 Across All Sources-
How to report an AI Act violation in the EU
Help Net Security · 1h ago -
DEF CON 34 - Video Team - Voting Machine Hacking Village
DEFCONConference · 7h ago -
DEF CON 34 - VideoTeam - Cliff Stoll AfterHours
DEFCONConference · 8h ago -
Do You Need a VPN in 2026? Here’s the Truth
David Bombal · 14h ago -
Made by Google 2026: How to watch and what to expect from at the Pixel 11 event
Latest news · 17h ago
Gigafeed (4564 entries)
How to report an AI Act violation in the EU Help Net Security · 1h ago DEF CON 34 - Video Team - Voting Machine Hacking Village DEFCONConference · 7h ago DEF CON 34 - VideoTeam - Cliff Stoll AfterHours DEFCONConference · 8h ago Do You Need a VPN in 2026? Here’s the Truth David Bombal · 14h ago Made by Google 2026: How to watch and what to expect from at the Pixel 11 event Latest news · 17h ago CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object MSRC Security Update Guide · 19h ago CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown MSRC Security Update Guide · 19h ago CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode MSRC Security Update Guide · 19h ago CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning MSRC Security Update Guide · 19h ago CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp() MSRC Security Update Guide · 19h ago CVE-2026-64567 btrfs: reject free space cache with more entries than pages MSRC Security Update Guide · 19h ago CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n MSRC Security Update Guide · 19h ago CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path MSRC Security Update Guide · 19h ago CVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parser MSRC Security Update Guide · 19h ago CVE-2026-64574 wifi: mac80211: tear down new links on vif update error path MSRC Security Update Guide · 19h ago CVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() MSRC Security Update Guide · 19h ago CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate() MSRC Security Update Guide · 19h ago CVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert MSRC Security Update Guide · 19h ago CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback() MSRC Security Update Guide · 19h ago CVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2 MSRC Security Update Guide · 19h ago CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR MSRC Security Update Guide · 19h ago CVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data() MSRC Security Update Guide · 19h ago CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing MSRC Security Update Guide · 19h ago CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available MSRC Security Update Guide · 19h ago CVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() race MSRC Security Update Guide · 19h ago Week in review: Cisco fixes IMC bug, Patch Tuesday forecast, Black Hat USA 2026 Help Net Security · 20h ago DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking DEFCONConference · 1d ago DEF CON 34 - Video Team - Hak5 - Darren Kitchen DEFCONConference · 1d ago DEF CON 34 - Video Team - AI Hacking Village - Pokemon DEFCONConference · 1d ago DEF CON 34 - Video Team - No Starch Press DEFCONConference · 1d ago DEF CON 34 - Video Team - Goon Questions -Guzi Media DEFCONConference · 1d ago DEF CON 34 - Video Team -Bug Bounty Village DEFCONConference · 1d ago DEF CON 34 - Video Team - DC Nextgen Community - Bia DEFCONConference · 1d ago DEF CON 34 - Video Team - Maritime Hacking Village DEFCONConference · 1d ago DEF CON 34 - Video Team - Battle of the Bots - Lisa DEFCONConference · 1d ago DEF CON 34 - Video Team - DEF COIN 34 Badge - Bunnie Huang DEFCONConference · 1d ago HackTheBox - Helix IppSec · 1d ago Hackers breach TrueConf to trojanize client installers with backdoors BleepingComputer · 1d ago Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data SecurityWeek · 1d ago Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed Security Latest · 1d ago Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All Security Latest · 1d ago Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers The Hacker News · 1d ago New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens The Hacker News · 1d ago Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication The Hacker News · 1d ago N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist The Hacker News · 1d ago Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts The Hacker News · 1d ago When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection Black Hat · 2d ago Black Hat USA Briefings: Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius Black Hat · 2d ago DEF CON 34 - Video Team - 'Lights in Dark Rooms' premiere at Movie Night Friday 8pm in W222 DEFCONConference · 2d ago Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability Cisco Security Advisory · 2d ago Metabase SQLi zero-day exploited in customer data-theft attacks BleepingComputer · 2d ago DEF CON 34 - Video Team - EFF Update - Cindy Cohn DEFCONConference · 2d ago Unlimited Technology Systems breach impacts 3.8 million people BleepingComputer · 2d ago Water utilities group partners with DEF CON offshoot for Water Watch Center The Record from Recorded Future News · 2d ago Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer The Hacker News · 2d ago ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets The Hacker News · 2d ago UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data The Hacker News · 2d ago US cyber ambassador nominee Cassady confirmed in Senate The Record from Recorded Future News · 2d ago This 6-port USB-C charger replaced my ugly power brick - and powers my entire desk Latest news · 2d ago I was loyal to T-Mobile for 10 years, but switching to Mint slashed my bill - by a lot Latest news · 2d ago More than half of AI-generated patches are broken CyberScoop · 2d ago Samsung Galaxy Watch 9 review: Health data overload, but built for the future Latest news · 2d ago Learn Fault Injection at DEF CON 2026 LiveOverflow · 2d ago New Mexico judge orders Meta to pay $567 million in kids online safety case The Record from Recorded Future News · 2d ago Military device manufacturer discloses cyber incident to SEC The Record from Recorded Future News · 2d ago This Bluetooth-only Marshall home speaker sounds so good, I can forgive the missing Wi-Fi Latest news · 2d ago ClamAV Vulnerabilities Affecting Cisco Products: August 2026 Cisco Security Advisory · 2d ago Levi Strauss & Co. says hackers stole corporate data in cyberattack BleepingComputer · 2d ago Your phone doesn't block SIM swapping attacks by default: Turn on these carrier settings now Latest news · 2d ago Samsung Galaxy Z Fold 8 review: The compact foldable I've wanted all along Latest news · 2d ago I read Microsoft's Windows 11 'quality' progress report - and the subtext says it all Latest news · 2d ago Irregular, firm behind AI hacking incidents, won't say if there were more The Record from Recorded Future News · 2d ago In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street SecurityWeek · 2d ago Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports CyberScoop · 2d ago I compared Google's pricier Pixel 11 series to Samsung's Galaxy lineup - here's the better value now Latest news · 2d ago Real emails, hijacked payments: Two H1 2026 attack chains BleepingComputer · 2d ago North Carolina Ports confirms cyberattack disrupting operations BleepingComputer · 2d ago Apple rushes out emergency fix for screen sharing flaw on Macs - update ASAP Latest news · 2d ago New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP The Hacker News · 2d ago I'm a diehard OnePlus user: Here's my plan now that the company is leaving North America Latest news · 2d ago 200 accounts compromised in Swiss government’s Microsoft SharePoint breach Help Net Security · 2d ago What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience Latest news · 2d ago How I survive summer without AC: My top hot weather coping tips, tricks, and gadgets Latest news · 2d ago Wi-Fi 7 adoption in the US quadrupled in a year - is it time to upgrade? Latest news · 2d ago Growing Up The Hard Way The Hacker News · 2d ago 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers The Hacker News · 2d ago Vishing Extortion Group UNC6671 Rebrands After Making Millions SecurityWeek · 2d ago New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables The Hacker News · 2d ago Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails The Hacker News · 2d ago AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day The Hacker News · 2d ago Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix SecurityWeek · 2d ago Black Hat USA 2026 – Summary of Vendor Announcements (Part 4) SecurityWeek · 2d ago Microsoft, Apple Release Fresh Security Updates SecurityWeek · 2d ago My 10 favorite gadgets to upgrade your school or work setup this fall Latest news · 2d ago The best Samsung Galaxy Z Flip 8 cases: Expert recommended Latest news · 2d ago The best electric screwdrivers of 2026: Expert tested and reviewed Latest news · 2d ago OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens Help Net Security · 2d ago Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access The Hacker News · 2d ago Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets The Hacker News · 2d ago The best Samsung Galaxy Z Fold 8 and Fold 8 Ultra cases of 2026: Expert recommended Latest news · 2d ago 3.8 Million Impacted by Unlimited Technology Systems Data Breach SecurityWeek · 2d ago Keepit AI Truth Cloud protects the data behind enterprise AI Help Net Security · 2d ago Critical Vulnerabilities Patched With Chrome 151 Update SecurityWeek · 2d ago TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign The Hacker News · 2d ago August 2026 Patch Tuesday forecast: How do we deal with the patch apocalypse? Help Net Security · 2d ago What the first year of EU AI Act transparency enforcement could look like Help Net Security · 2d ago US fuel gauge exposure fell by more than half in three months Help Net Security · 2d ago ShieldFont fights AI scraping by handing crawlers the wrong words Help Net Security · 2d ago Gut feeling does nothing against AI spear phishing texts Help Net Security · 3d ago July 2026 CVE Landscape Recorded Future · 3d ago OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it BleepingComputer · 3d ago OSPF From Zero: Let's Build the Internet (Well...Almost) | Summer of CCNA NetworkChuck · 3d ago ClickFix attack pushes macOS infostealer for crypto theft attacks BleepingComputer · 3d ago DEF CON 34 - Video Team - DEF CON Groups Highlight DC256 DEFCONConference · 3d ago Hackers Stalked Me by Hijacking a Smartwatch for Kids Security Latest · 3d ago Black Hat USA Opening Session: Disruption, Defense and Operational Readiness Black Hat · 3d ago Black Hat USA 2026 Opening Session: Cyber Power in the Age of AI Black Hat · 3d ago Black Hat USA 2026 Keynote: Vulnerability Research in the Agentic Age Black Hat · 3d ago Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams CyberScoop · 3d ago Black Hat USA 2026 Keynote: The End of Rare Defending When Offense Is Cheap Black Hat · 3d ago Google's new Pixel 11 series comes next week - here's what we know from leaks Latest news · 3d ago Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident Black Hat · 3d ago Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group BleepingComputer · 3d ago Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online CyberScoop · 3d ago Ransom Cartel creator sentenced to 16 years in prison CyberScoop · 3d ago Swiss government SharePoint breach compromised 200 accounts BleepingComputer · 3d ago New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes BleepingComputer · 3d ago New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts The Hacker News · 3d ago 6 must-have travel gadgets, according to industry experts Latest news · 3d ago Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs The Hacker News · 3d ago Canadian Man Pleads Guilty in Snowflake Extortions Krebs on Security · 3d ago New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs The Hacker News · 3d ago Meta AI model hacked a company during misconfigured cyber test BleepingComputer · 3d ago The risk awareness radar. A superpower every MSP needs to train Heimdal Security Blog · 3d ago Snowflake Hacker Pleads Guilty in US Court SecurityWeek · 3d ago How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore BleepingComputer · 3d ago Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts SecurityWeek · 3d ago The water sector just got it’s wake-up call. Again. CyberScoop · 3d ago OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree Security Latest · 4d ago Emerging Threats to Neurotechnology Recorded Future · 4d ago A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide Security Latest · 4d ago OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts Security Latest · 4d ago Ransom Cartel ransomware creator sentenced to 16 years in prison BleepingComputer · 4d ago Thousands of servers can be backdoored by exploiting buggy motherboard controllers Security - Ars Technica · 4d ago Canadian pleads guilty to Snowflake cloud data-theft attacks BleepingComputer · 4d ago Snowflake hacker pleads guilty, faces up to 32 years in prison CyberScoop · 4d ago Anthropic’s AI used fake identities, malware in rogue attack on GitHub project Security - Ars Technica · 4d ago DHS Wants Protesters’ Signal Group Chats Security Latest · 4d ago The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop Security Latest · 4d ago Tom Cotton prods Treasury for tax code tweaks to modernize OT CyberScoop · 4d ago DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad Security Latest · 4d ago Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) Microsoft Security Blog · 4d ago Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery Security Latest · 4d ago Cisco Advance Notification for Publication of August 5, 2026, Security Advisories Cisco Security Advisory · 4d ago Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability Cisco Security Advisory · 4d ago Cisco Integrated Management Controller Cross-Site Scripting Vulnerability Cisco Security Advisory · 4d ago Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability Cisco Security Advisory · 4d ago Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability Cisco Security Advisory · 4d ago Cisco IOS XE Software SNMP Denial of Service Vulnerability Cisco Security Advisory · 4d ago Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability Cisco Security Advisory · 4d ago Cisco IOS XE Software Security Hardening Release: August 2026 Cisco Security Advisory · 4d ago Cisco Integrated Management Controller Argument Injection Vulnerabilities Cisco Security Advisory · 4d ago Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability Cisco Security Advisory · 4d ago Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026 Cisco Security Advisory · 4d ago Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability Cisco Security Advisory · 4d ago From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide Microsoft Security Blog · 4d ago I’m headed to DEFCON! NahamSec · 4d ago Cisco Secure Firewall Management Center Software Static Credential Vulnerability Cisco Security Advisory · 4d ago Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Security Advisory · 4d ago Open-source software’s archenemy TeamPCP goes back further than anyone thought CyberScoop · 4d ago AI is getting better at election facts, but voters shouldn’t rely on it CyberScoop · 4d ago National cyber director lays out White House plans to secure AI without writing new rules CyberScoop · 5d ago Hype vs. Reality: What the Hugging Face Incident Means for AI Safety Recorded Future · 5d ago ChainDrop supply chain compromise: Anatomy of a self-propagating worm Microsoft Security Blog · 5d ago OK, Well, Rogue AI Agents Are Hacking Again Security Latest · 5d ago AISI, OpenAI report more ‘unsanctioned’ model hacks CyberScoop · 5d ago Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps Microsoft Security Blog · 5d ago 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET Microsoft Security Blog · 5d ago Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal Security Latest · 5d ago How legitimate cloud platforms enable phishers to bypass MFA Securelist · 5d ago Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats Proofpoint News Feed · 5d ago Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities Proofpoint News Feed · 5d ago Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack CyberScoop · 6d ago Does AI Content Have to be Authentic — or Can It Just Be Effective? Blog – Forter · 6d ago Cyber Deception Everywhere John Hammond · 6d ago An analysis of incidents at Brazilian educational institutions Securelist · 6d ago Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS) NahamSec · 6d ago ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children Security Latest · 6d ago CrowdStrike: AI is now both the weapon and the target in cyberattacks CyberScoop · 6d ago Are you ready for this year's @BugBountyVillage at @DEFCONConference NahamSec · 7d ago 8 Ways AI is Changing Threat Intelligence Recorded Future · 7d ago 1.5 Gbps Internet using your old telephone cables? David Bombal · 7d ago 8 Best Password Managers (2026), Tested and Reviewed Security Latest · 7d ago HackTheBox - Kobold IppSec · 8d ago 7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran Security Latest · 8d ago Defcon's new badge is a security key you can see inside Security - Ars Technica · 8d ago The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier Security Latest · 8d ago JHT Course Launch! Home Labs with Proxmox John Hammond · 8d ago CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft Microsoft Security Blog · 9d ago Claude published malicious code to the Internet and attacked 3 real companies Security - Ars Technica · 9d ago Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world CyberScoop · 9d ago Why Black Hat Matters | Black Hat Stories Black Hat · 9d ago Black Hat Stories | Daniel Cuthbert, Black Hat Training Review Board Member Black Hat · 9d ago This month in security with Tony Anscombe – July 2026 edition WeLiveSecurity · 9d ago AI scammers outperform humans when it comes to building trust Security - Ars Technica · 9d ago The DEF CON Advice Nobody Gives You | Threat Wire Hak5 · 9d ago Do you guys agree? #hacking #bugbounty NahamSec · 9d ago Network Anomaly Detection in KATA Securelist · 9d ago The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key Security Latest · 9d ago What the Hugging Face breach reveals about defense in the age of agentic AI CyberScoop · 9d ago GTA Malware Trap John Hammond · 9d ago Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests Security Latest · 10d ago Anthropic says its AI accidentally hacked three companies during safety tests CyberScoop · 10d ago A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran Security Latest · 10d ago Max-severity Exchange server flaw under active exploitation by Kremlin hackers Security - Ars Technica · 10d ago Okta’s deal for Permiso aims to close gaps in identity threat detection CyberScoop · 10d ago Max-severity Exchange server flaw under active exploitation by Kremlin hackers Proofpoint News Feed · 10d ago CISA issues recommendations to federal agencies on open-source software security CyberScoop · 10d ago Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting Security Latest · 10d ago Cyber War Forum: The Critical Questions No One Has Real Answers To Black Hat · 10d ago Read This Before You Buy That TV Streaming Stick Krebs on Security · 10d ago What’s new in Microsoft Security: July 2026 Microsoft Security Blog · 10d ago We know how to protect our troops from telecom attacks. We’re just not doing it. CyberScoop · 10d ago OpenAI Turned Off the Guardrails | Threat Wire Hak5 · 10d ago Meet TCM Security at DEF CON 34! The Cyber Mentors · 10d ago Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims CyberScoop · 10d ago Rediscover Maltego in 2026 David Bombal · 10d ago The next measure of AI momentum is work transformed Microsoft 365 Blog · 10d ago Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes Heimdal Security Blog · 10d ago OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia Securelist · 10d ago Beyond the screenshot: Why you should verify what you see WeLiveSecurity · 10d ago How Heimdal grew from a bold idea into a global cybersecurity platform Heimdal Security Blog · 10d ago MediaArena malvertising: why a quarantine isn’t the end of the incident Heimdal Security Blog · 10d ago Toy Ghouls’ new toy: the GenieLocker ransomware Securelist · 10d ago Real Folks of Cyber | Andrew Crotty | DITL The Cyber Mentors · 10d ago Iran War’s Secondary Effects Shape 2026 US Violent Extremism Recorded Future · 11d ago Dealing with AI-Generated Extortion Recorded Future · 11d ago Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility Trend Micro Research, News, Perspectives · 11d ago Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission Security - Ars Technica · 11d ago A little-known npm package was North Korea’s warm-up act for the axios hack CyberScoop · 11d ago Supply chain challenges loom large in quantum race, White House official says CyberScoop · 11d ago Huntress warns about attack spree that hit 30 SonicWall customers in 2 days CyberScoop · 11d ago Better security starts with better questions Microsoft Security Blog · 11d ago Black Hat Asia 2026 | Keynote: From Prompt Tricks to Autonomous Hackers Black Hat · 11d ago Anthropic is finding bugs faster than Microsoft can fix them Security - Ars Technica · 11d ago Minecraft Security Mods John Hammond · 11d ago Payload Podcast 010 - Olaf Hartong John Hammond · 11d ago Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave Trend Micro Research, News, Perspectives · 12d ago We now have a better understanding how OpenAI hacked into Hugging Face Security - Ars Technica · 12d ago Tools Change. Teach People How to Keep Up Heimdal Security Blog · 12d ago Mirage Kitten targets Middle East and Africa region with new malware Securelist · 12d ago Did an AI Really Hack Hugging Face? LiveOverflow · 13d ago Microsoft unveils AI security tools it says outperform competing platforms Security - Ars Technica · 13d ago Rethinking security for the age of AI Microsoft Security Blog · 13d ago Enhancing AI security through global AI red teaming Microsoft Security Blog · 13d ago Activist charged with felony after giving border agent "duress code" that wiped his phone Security - Ars Technica · 13d ago How One File Upload Got Me the Entire Customer Database NahamSec · 13d ago Any App Notification John Hammond · 14d ago Qubes OS explained: assume you will get hacked David Bombal · 14d ago HackTheBox - Fries IppSec · 15d ago Building Fake Notifications John Hammond · 15d ago Why Being a Great Hacker Doesn't Pay Anymore NahamSec · 15d ago Black Hat Intercepted | James Kettle, Director of Research at Portswicker Black Hat · 16d ago CISOs vs. Boards: Myth or Misunderstanding? darkreading · 16d ago Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks CyberScoop · 16d ago Black Hat Stories | Where Cybersecurity Professionals Go to Learn Black Hat · 16d ago Black Hat Stories | Gaurav Keerthi, CEO and Founder of StrongKeep Black Hat · 16d ago What syscall-layer tooling cannot see in P2P infrastructure Technical Information Security Content & Discussion · 16d ago Despite multiple takedowns, botnets continue to grow CyberScoop · 16d ago Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation darkreading · 16d ago Announcing the External Penetration Testing Program Pack Technical Information Security Content & Discussion · 16d ago Microsoft, tech companies throw weight behind spread of open-source AI CyberScoop · 16d ago Vatican's Official Prayer App Leaks 700K+ Global Users' PII darkreading · 16d ago Default Azure Automation Setting Enables Cross-Tenant Identity Takeover darkreading · 16d ago The way AI voice phishing gets demonstrated is making people worse at spotting it Technical Information Security Content & Discussion · 16d ago Europe's Multilingual Reality Exposes AI Security Gaps darkreading · 16d ago Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331 Technical Information Security Content & Discussion · 16d ago Ransomware is the Scoreboard Recorded Future · 17d ago The Signs Were There: What the First Autonomous Ransomware Case Confirms Trend Micro Research, News, Perspectives · 17d ago AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA NetworkChuck · 17d ago XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search Technical Information Security Content & Discussion · 17d ago Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets darkreading · 17d ago Rubio restricts visas for sextortionists, cyber scammers CyberScoop · 17d ago New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors Proofpoint News Feed · 17d ago Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled Technical Information Security Content & Discussion · 17d ago this Raspberry Pi belongs on your wall NetworkChuck · 17d ago Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries CyberScoop · 17d ago Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes Proofpoint News Feed · 17d ago US and allies say Russian hackers stole emails without social engineering Proofpoint News Feed · 17d ago Fake Edge Update John Hammond · 17d ago You need to learn Maltego in 2026 David Bombal · 17d ago Black Hat USA 2026 - New Features Black Hat · 17d ago Open Evaluation Framework for AI Pentesting Agents on Real-World Targets Technical Information Security Content & Discussion · 17d ago Meta Logging Every Employee Keystroke | Threat Wire Hak5 · 17d ago Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA Technical Information Security Content & Discussion · 17d ago Agentic AI Challenges Progress in Confidential Computing darkreading · 17d ago The 4 best managed EDR service suppliers (and how to choose) Heimdal Security Blog · 17d ago ANCHOR-CI could fix 20 years of broken government-industry collaboration CyberScoop · 17d ago They hacked Google's AI in Seoul STÖK · 17d ago Brazilian Banking Trojan Actively Spreading in Portugal darkreading · 17d ago TCM Course Release | New Creator | Cybersecurity | AMA The Cyber Mentors · 17d ago Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain darkreading · 18d ago TAG-195 Upgrades MaaS Ecosystem with Modular Tools Recorded Future · 18d ago 13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan Trend Micro Research, News, Perspectives · 18d ago Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It Trend Micro Research, News, Perspectives · 18d ago Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure Trend Micro Research, News, Perspectives · 18d ago Flaws in Passkey Implementation Show Old Attacks Still Work darkreading · 18d ago GitHub issues $100,000 bounty for critical RCE vulnerability Technical Information Security Content & Discussion · 18d ago Attackers Are Learning to Live Off the AI Toolchain darkreading · 18d ago Most federal cybersecurity reporting rules are duplicative, study finds CyberScoop · 18d ago Fake Bahrain Alert App Deploys Android Surveillance Malware darkreading · 18d ago CVE-2026-50458: Finding a UAF in the Windows Brokering File System Technical Information Security Content & Discussion · 18d ago Want To Learn (For FREE) About A Self-Driving Network? David Bombal · 18d ago What Is Visa’s DCAP? A Merchant’s Guide to Requirements, Benefits, and Rollout Blog – Forter · 18d ago Malware is targeting AI tools in software development environments CyberScoop · 18d ago OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face Security - Ars Technica · 18d ago White House accuses Chinese company of distilling Anthropic’s Fable CyberScoop · 18d ago If you pay a hacker’s ransom, chances are that they’ll come back for more Proofpoint News Feed · 18d ago When AI Attacks: OpenAI Models Autonomously Hack Hugging Face darkreading · 18d ago Top 4 Best SOC Platforms 2026 – Provider Comparison Heimdal Security Blog · 18d ago I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986) Technical Information Security Content & Discussion · 18d ago The End of TOKENMAXXING? David Bombal · 18d ago EU Financial Institutions Leak Data Through Cookie Trackers darkreading · 18d ago Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective Proofpoint News Feed · 18d ago LG to Ban Residential Proxies from Smart TV Apps Krebs on Security · 19d ago Modern Attack Vectors | Recorded Future Recorded Future · 19d ago Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass Trend Micro Research, News, Perspectives · 19d ago OpenAI says model test was behind Hugging Face hack CyberScoop · 19d ago Ransomware Is Accelerating, but It's Not Because of AI darkreading · 19d ago Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task darkreading · 19d ago AI models keep getting caught cheating CyberScoop · 19d ago Hacker Turns AI Jailbreaks Into Offensive Attack Platform darkreading · 19d ago Where’s the Trump administration line on AI regulation? CyberScoop · 19d ago House intel bill includes provisions on state and local threat intelligence, election security, AI CyberScoop · 19d ago Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability Cisco Security Advisory · 19d ago North Korea’s IT worker scheme funds Russia’s war effort CyberScoop · 19d ago The Hidden CCS2 Attack Surface on EV Chargers Technical Information Security Content & Discussion · 19d ago Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE) Technical Information Security Content & Discussion · 19d ago Apps targeted at US troops contain Chinese and Russian code Security - Ars Technica · 19d ago An AI Botnet John Hammond · 19d ago A new extortion cocktail: office printers, small ransoms, and BitLocker Securelist · 19d ago Choose Wisely: AI-Generated Coding Risk Varies, a Lot darkreading · 19d ago Leaking internal headers in Flask Ninja with deserialization Technical Information Security Content & Discussion · 19d ago What the World Cup can teach us about cybersecurity resilience CyberScoop · 19d ago New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery Securelist · 19d ago Volume Is Not Risk: Making Sense of the 'Vulnpocalypse' Trend Micro Research, News, Perspectives · 20d ago 'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover darkreading · 20d ago Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push darkreading · 20d ago Director of Commerce AI standards office out after three months CyberScoop · 20d ago Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities Cisco Security Advisory · 20d ago Crawling the Complete IPv4 Reverse DNS Space Technical Information Security Content & Discussion · 20d ago Why blocking AI models won’t stop the cyber threats they create CyberScoop · 20d ago Redirect Chain Abuse John Hammond · 20d ago Pay up or not? Ransomware surge has victims facing tough choices. Security - Ars Technica · 20d ago Cybersecurity Keeps Events 'Uneventful' darkreading · 20d ago Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack Cyber Defense Magazine · 20d ago Microsoft Exchange Hacked, Five Years Later John Hammond · 20d ago Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) Technical Information Security Content & Discussion · 20d ago Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25 Technical Information Security Content & Discussion · 20d ago Threat Hunting: A Guide | Recorded Future Recorded Future · 21d ago I got inside FIFA’s Secret World Cup Broadcast Network NetworkChuck · 21d ago Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable Technical Information Security Content & Discussion · 22d ago wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner Technical Information Security Content & Discussion · 22d ago Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing Technical Information Security Content & Discussion · 22d ago HackTheBox Logging IppSec · 22d ago White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination Technical Information Security Content & Discussion · 22d ago wp2shell: Pre Authentication RCE in WordPress Core Technical Information Security Content & Discussion · 23d ago Keeping private namespaces private - Quad9 blog Technical Information Security Content & Discussion · 23d ago Inc Ransomware Exploits SonicWall SMA Zero-Days darkreading · 23d ago Openwrt pre-auth remote root exploit Technical Information Security Content & Discussion · 23d ago The Real AI Threat Is Blind Trust darkreading · 23d ago State officials, election experts pan Trump speech: ‘This is what desperation looks like’ CyberScoop · 23d ago Leading members of Scattered Spider sentenced in UK to 66 months in jail CyberScoop · 23d ago Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454 Technical Information Security Content & Discussion · 23d ago Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear darkreading · 23d ago UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker Cyber Defense Magazine · 23d ago Google Bets 'Agentic Defense' Strategy Can Outpace Attackers darkreading · 23d ago Hacking US Elections: The First Tranche of Declassified Election Integrity Documents Cyber Defense Magazine · 23d ago Tracking Advanced Persistent Threat Groups | Recorded Future Recorded Future · 24d ago Agentic AI: Taming the Unpredictable darkreading · 24d ago 1M+ Emails Use Hidden Text to Dupe AI Security Filters darkreading · 24d ago Now, even Russia's most elite hackers are using Clickfix to infect devices Security - Ars Technica · 24d ago Program to rotate cyber personnel through federal agencies saw little use CyberScoop · 24d ago Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime CyberScoop · 24d ago Evil Token Marketplace John Hammond · 24d ago No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE Technical Information Security Content & Discussion · 24d ago [$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking Technical Information Security Content & Discussion · 24d ago HelloNet campaign — new malicious modules launched through the ViPNet update system Securelist · 24d ago Inside Microsoft’s Record-Breaking 622-Bug Release Cyber Defense Magazine · 24d ago GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration Securelist · 24d ago Payload Podcast 009 - Steven Flores John Hammond · 24d ago Police Disrupt a €140M Cyber Fraud Ring in Spain darkreading · 24d ago ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL Technical Information Security Content & Discussion · 24d ago AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict Recorded Future · 25d ago Forgotten Bootloaders Expose Secure Boot Blind Spot darkreading · 25d ago Security researchers find stalkers abusing Chrome’s sync feature CyberScoop · 25d ago Identity Attacks Overtake Exploits as Top Ransomware Cause darkreading · 25d ago Windows 0-day drops the same day Microsoft releases record number of patches Security - Ars Technica · 25d ago SonicWall customers under threat as attackers exploit 2 zero-days CyberScoop · 25d ago Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed CyberScoop · 25d ago Guten Tag, Bonjour, Hola to Our European Cyber Defenders! darkreading · 25d ago Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife darkreading · 25d ago Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook Cyber Defense Magazine · 25d ago Cisco Advance Notification for Publication of July 15, 2026, Security Advisories Cisco Security Advisory · 25d ago Cisco RoomOS Security Hardening Release: July 2026 Cisco Security Advisory · 25d ago Your Home Internet Has a New Owner | Threat Wire Hak5 · 25d ago News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations The Last Watchdog · 25d ago Forget the model. When it comes to cybersecurity, it’s all about the harness CyberScoop · 25d ago Claude Flaw Automatically Sends Malicious Prompts to AI Agents darkreading · 25d ago News alert: Insignary’s on-demand SBOM verification boosts software supply chain security The Last Watchdog · 25d ago 2-Click Cursor Exploit Enables Dev Environment Takeover darkreading · 25d ago Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure Cyber Defense Magazine · 25d ago OkoBot: new sophisticated malware framework targets cryptocurrency users Securelist · 25d ago HN Security - My Semgrep C/C++ ruleset is ready for prime time again Technical Information Security Content & Discussion · 25d ago The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets Technical Information Security Content & Discussion · 25d ago (More) Unauthenticated Arbitrary Code Execution in ServiceNow Technical Information Security Content & Discussion · 25d ago 78% of CFOs Say Payment Blind Spots Increase Customer Friction PYMNTS | Fraud Prevention Archives · 25d ago Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits darkreading · 25d ago News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions The Last Watchdog · 26d ago Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal darkreading · 26d ago The Shift: A New Era of AI Regulation Recorded Future · 26d ago Microsoft’s Secure Boot has been broken for a decade and no one noticed until now Security - Ars Technica · 26d ago Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes darkreading · 26d ago 6 GHz Wi-Fi Flaws Could Disrupt Critical Systems darkreading · 26d ago Microsoft Patches a Record 570 Security Flaws Krebs on Security · 26d ago Backdoored TortoiseSVN Installer John Hammond · 26d ago Manage Vendor Risk in a Few Practical Steps darkreading · 26d ago Is Cat7 a SCAM? David Bombal · 26d ago The Gray Area in Your Checkout Is Costing You More Than You Think Blog – Forter · 26d ago Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook? darkreading · 26d ago What Nacha’s amended rules mean for your ACH fraud monitoring Fraud Prevention – Riskified · 26d ago OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials Proofpoint News Feed · 26d ago CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers Cyber Defense Magazine · 26d ago Smashing the ServiceNow Sandbox – Pre Authentication RCE Technical Information Security Content & Discussion · 26d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 26d ago Forgotten UEFI shims undermining Secure Boot WeLiveSecurity · 26d ago The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future Recorded Future · 27d ago Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet Trend Micro Research, News, Perspectives · 27d ago Context Bombs: Using AI Guardrails as a defensive mechanism Technical Information Security Content & Discussion · 27d ago The US government warns that Russia state hackers are coming after your router Security - Ars Technica · 27d ago CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC) Technical Information Security Content & Discussion · 27d ago Cisco's Agents Reason Like a CCIE David Bombal · 27d ago Now, defenders are embracing the prompt injection, too Security - Ars Technica · 27d ago Lessons Learned from CISA’s Recent GitHub Leak Krebs on Security · 27d ago Hackers find a new trick to collect Microsoft Entra user data without raising red flags Proofpoint News Feed · 27d ago This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!) NahamSec · 27d ago The Threat Mechanism and Mitigation of Pink Vishing Campaigns Cyber Defense Magazine · 27d ago Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639) Technical Information Security Content & Discussion · 27d ago 85% of CFOs Say Automation Cuts Payments Friction PYMNTS | Fraud Prevention Archives · 27d ago Persistence via Fake AMSI Provider | Playbook & Detection Strategies Technical Information Security Content & Discussion · 27d ago Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver Technical Information Security Content & Discussion · 28d ago Install GrapheneOS Before Your Phone Becomes the Checkpoint David Bombal · 28d ago Scanning malicious websites with arbitrary number of VPN tunnels (Part 2) Technical Information Security Content & Discussion · 29d ago HackTheBox - CCTV IppSec · 29d ago See It Once, Stop It Everywhere Cyber Defense Magazine · 29d ago NEW AI Hacking Challenges with Andrew Bellini! John Hammond · 29d ago Cybercriminals Targeting World Cup Fans Cyber Defense Magazine · 30d ago Innovators Spotlight: Brinqa Cyber Defense Magazine · 30d ago Soft Skills for the Job Market: Applying for Jobs The Cyber Mentors · 30d ago The Cost of Delayed Patching: What Security Teams Are Missing Cyber Defense Magazine · 30d ago Invoice Fraud Is Now a Cybersecurity Exposure Cyber Defense Magazine · 30d ago Top 6 Managed Detection and Response Providers Heimdal Security Blog · 30d ago Can AI-generated adversaries break TTP-based attribution? (arXiv 2026) Technical Information Security Content & Discussion · 30d ago Towards CSI: What's the best harness? (arXiv 2026) Technical Information Security Content & Discussion · 30d ago Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail CyberScoop · 31d ago June 2026 CVE Landscape Recorded Future · 31d ago LIVE AMA | Summer of CCNA | 07/09/2026 NetworkChuck · 31d ago Patch for Windows Defender 0-day could allow attackers to fill hard disk Security - Ars Technica · 31d ago Interpol cybercrime crackdown nets 5,800 arrests across 97 countries CyberScoop · 31d ago 764 splinter group leader sentenced to 40 years in jail CyberScoop · 31d ago Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities Technical Information Security Content & Discussion · 31d ago RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney Recorded Future · 32d ago Your Payment Routing Rules Are Making Decisions Without You Blog – Forter · 32d ago French nonprofit starts global intelligence and research hub for AI cyber threats CyberScoop · 32d ago 1 in 2 devices sold in Africa exfiltrate data to China Technical Information Security Content & Discussion · 32d ago Inside an AI coal mine security camera network powered by plaintext passwords Technical Information Security Content & Discussion · 32d ago News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI The Last Watchdog · 32d ago LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway The Cyber Mentors · 32d ago Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches Technical Information Security Content & Discussion · 32d ago Felons, Fraudsters Flog Offensive Cybersecurity Startup Krebs on Security · 32d ago Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors Heimdal Security Blog · 32d ago Found fast, fixed slow: The gap the AI clearinghouse must close CyberScoop · 32d ago ESET Threat Report H1 2026 WeLiveSecurity · 32d ago ESET Threat Report H1 2026 WeLiveSecurity · 32d ago 42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million PYMNTS | Fraud Prevention Archives · 32d ago Bad Epoll: The bug missed by Mythos Technical Information Security Content & Discussion · 33d ago Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire Hak5 · 33d ago The Threat Isn’t the Frontier Model Recorded Future · 33d ago Spain arrests suspected hacker linked to Russian hacktivist campaign CyberScoop · 33d ago Deepfake CSAM lawsuit against xAI, Grok expands CyberScoop · 33d ago GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail Technical Information Security Content & Discussion · 33d ago Threat landscape for industrial automation systems. Q1 2026 Securelist · 33d ago Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities CyberScoop · 33d ago Unveiled: Cisco Deep Reasoning David Bombal · 34d ago News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk The Last Watchdog · 34d ago US Army websites defaced with pro-Kurdish sentiments, insults to Trump CyberScoop · 34d ago Sysdig clocks first documented case of agentic ransomware CyberScoop · 34d ago New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!" Technical Information Security Content & Discussion · 34d ago I Made an AI Agent That Reverses CVEs While I Sleep NahamSec · 34d ago Playing Around With ADIDNS RPC Internals Technical Information Security Content & Discussion · 34d ago When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website Securelist · 34d ago Finding vulnerabilities was never the hard part CyberScoop · 34d ago Windows Service - Playbook & Detection Strategies Technical Information Security Content & Discussion · 34d ago Why Apple Hide My Email FAILS David Bombal · 35d ago New to Linux? This is the best place to start! David Bombal · 35d ago HackTheBox - DevArea IppSec · 36d ago LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud PYMNTS | Fraud Prevention Archives · 37d ago WARNING: AI tracks your face David Bombal · 37d ago How to scale your patches without scaling your team (the patch wave) Heimdal Security Blog · 37d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 37d ago Cyber readiness for SMBs: Getting the basics right WeLiveSecurity · 37d ago AI didn’t break patching. It showed us patching was already broken. Heimdal Security Blog · 37d ago Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign Securelist · 37d ago Someone infected a spyware probe overseer with spyware CyberScoop · 37d ago Fable 5 is back.....run these prompts before July 12th NetworkChuck · 38d ago FBI Seizes NetNut Proxy Platform, Popa Botnet Krebs on Security · 38d ago It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs Technical Information Security Content & Discussion · 38d ago FIFA was saved this time Technical Information Security Content & Discussion · 38d ago Alleged longstanding member of Scattered Spider extradited to US CyberScoop · 38d ago Celebrating 1 Million Subscribers on July 8th! The Cyber Mentors · 38d ago Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects Securelist · 38d ago 42% of Issuers Say Fraud and Disputes Are Driving Up Costs PYMNTS | Fraud Prevention Archives · 38d ago /r/netsec's Q3 2026 Information Security Hiring Thread Technical Information Security Content & Discussion · 38d ago News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks The Last Watchdog · 38d ago Researchers spot exploitation of another critical Oracle defect CyberScoop · 39d ago Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657) Technical Information Security Content & Discussion · 39d ago US lifting export control restrictions on Anthropic’s Mythos, Fable CyberScoop · 39d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 39d ago The Chaya_006 Alert: OT Edge Devices Under Fire Cyber Defense Magazine · 39d ago The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign Securelist · 39d ago This phishing kit looks more like BEC-as-a-service CyberScoop · 39d ago Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes Heimdal Security Blog · 39d ago Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool Recorded Future · 40d ago Citrix patches a new NetScaler flaw with echoes of CitrixBleed CyberScoop · 40d ago Trump budget boss Russell Vought open to re-staffing CISA CyberScoop · 40d ago Is DEFCON for you? David Bombal · 40d ago CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs Technical Information Security Content & Discussion · 40d ago News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks The Last Watchdog · 40d ago JPMorganChase and Amazon Back Aspen Institute Drive Against Scams PYMNTS | Fraud Prevention Archives · 40d ago News alert: OpenMatter launches platform to verify AI activity across enterprise systems The Last Watchdog · 40d ago Nissan Americas Hit in Global Oracle PeopleSoft Data Breach Cyber Defense Magazine · 40d ago DHS to unveil replacement council for critical infrastructure cybersecurity CyberScoop · 40d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 40d ago This month in security with Tony Anscombe – June 2026 edition WeLiveSecurity · 40d ago Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass) Technical Information Security Content & Discussion · 40d ago ToddyCat: your hidden email assistant. Part 2 Securelist · 40d ago How ransomware syndicates weaponize corporate-style organization CyberScoop · 40d ago Warner bill would create federally vetted list for secure, trustworthy AI agents CyberScoop · 41d ago Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs Technical Information Security Content & Discussion · 41d ago Supreme Court approves mail-in ballots that arrive after Election Day CyberScoop · 41d ago Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling CyberScoop · 41d ago CISA Warns Attackers Are Targeting Critical Internal Business Platforms Cyber Defense Magazine · 41d ago The Gentlemen are knocking: сustom backdoors and evolving tactics Securelist · 41d ago What the post-quantum executive order really demands of CISOs CyberScoop · 41d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 41d ago Inside the inbox: Why cybercriminals want to break into your email account WeLiveSecurity · 41d ago World Cup Gives Cross-Border Payments Their Super Bowl Moment PYMNTS | Fraud Prevention Archives · 41d ago TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry Trend Micro Research, News, Perspectives · 42d ago Return On Risk: The New Measure Of Cyber Resilience Cyber Defense Magazine · 42d ago Path to StateRAMP Cyber Defense Magazine · 42d ago I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well. Technical Information Security Content & Discussion · 42d ago Dissecting Apple's Sparse Image Format (ASIF) Technical Information Security Content & Discussion · 42d ago A peek into Reddit's anti-spam internals Technical Information Security Content & Discussion · 43d ago Rethinking Identity Security In The Age Of AI Driven Fraud Cyber Defense Magazine · 43d ago HackTheBox - WingData IppSec · 43d ago New Age Insider Risk Cyber Defense Magazine · 43d ago ATF cancels controversial commercial geolocation contract CyberScoop · 44d ago Banks Face a New ACH Fraud Test as Nacha Rules Take Effect PYMNTS | Fraud Prevention Archives · 44d ago Real Folks of Cyber | Pearce Barry | Day in the Life The Cyber Mentors · 44d ago How Dynamic Defense shuts an attacker out without shutting down the business Heimdal Security Blog · 44d ago Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure Cyber Defense Magazine · 44d ago Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To Cyber Defense Magazine · 44d ago Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk Securelist · 44d ago Name That Toon Contest darkreading · 44d ago Static security has run out of road. The case for Dynamic Defense Heimdal Security Blog · 44d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 44d ago SMB cyber readiness: the road to resilience starts here WeLiveSecurity · 44d ago Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges PYMNTS | Fraud Prevention Archives · 45d ago Getting Started with the TCM Security Academy The Cyber Mentors · 45d ago FCC passes new cybersecurity rules for emergency systems, undersea cables CyberScoop · 45d ago Federal court rules Trump election-focused executive order illegal CyberScoop · 45d ago CVE-2025-52465 geoserver arbitrary file write vulnerability Technical Information Security Content & Discussion · 45d ago The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer Cyber Defense Magazine · 45d ago Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract CyberScoop · 45d ago Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack CyberScoop · 45d ago The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target Cyber Defense Magazine · 45d ago Copilot in Excel: Built for the era of Frontier Finance Microsoft 365 Blog · 45d ago NSA Urges Cyberthreat Timeline Has Compressed From Years to Months Cyber Defense Magazine · 45d ago CargoWise WebTracker - The keys were in the cargo Technical Information Security Content & Discussion · 45d ago Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools Securelist · 45d ago Europe Evolves Into Ransomware's Favorite Region darkreading · 45d ago Why patch directives only go so far CyberScoop · 45d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 45d ago Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances WeLiveSecurity · 45d ago AI Forces Compliance Teams to Rethink Alert Strategy PYMNTS | Fraud Prevention Archives · 45d ago Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge Recorded Future · 46d ago Evaluating Mexico’s New Cybersecurity Plan Recorded Future · 46d ago Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure darkreading · 46d ago 2026 FIFA World Cup Faces Surge in Cyber Threats darkreading · 46d ago Do CISOs Need a Code of Ethics? darkreading · 46d ago Malicious hackers exploit Cisco zero-day for highest access level at communications service provider CyberScoop · 46d ago More Malicious OpenClaw Skills Threaten AI Supply Chain darkreading · 46d ago Exploiting vulnerabilities in Johnson & Johnson web apps Technical Information Security Content & Discussion · 46d ago Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have Cyber Defense Magazine · 46d ago Invisible By Design: Making Quantum-Safe Encryption The Easy Path Cyber Defense Magazine · 46d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 46d ago ESET takes part in Operation Endgame to disrupt Amadey and Stealc WeLiveSecurity · 46d ago In a first, a court takedown goes after two cybercrime tools at once CyberScoop · 46d ago Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming Cyber Defense Magazine · 46d ago Apple's MacOS Gap Lets Users Disable Security Tools darkreading · 46d ago Breaking the MSP Echo Chamber: The Power of Community Heimdal Security Blog · 46d ago StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader Securelist · 46d ago Open-source security is posing challenges governments can’t easily solve CyberScoop · 46d ago New at Forter: AI Agents Built to Amplify Your Team Blog – Forter · 46d ago Scope of Salesforce Attacks Expands as Icarus Leaks Data darkreading · 47d ago Innovator Spotlight: NAKIVO Cyber Defense Magazine · 47d ago 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows darkreading · 47d ago Justice Department seizes infrastructure used by cyber scam and criminal marketplace CyberScoop · 47d ago Cybersecurity Outsourcing. Beyond Cost Cyber Defense Magazine · 47d ago Scattered Spider Hackers Plead Guilty on Day 1 of Trial Krebs on Security · 47d ago Algerian man charged with running two cybercrime marketplaces CyberScoop · 47d ago SocGholish Takedown Highlights Malicious TDS Threats darkreading · 47d ago Can AI Agents Find, Trust, and Choose Your Brand? Blog – Forter · 47d ago Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets Cyber Defense Magazine · 47d ago FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist darkreading · 47d ago Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data Cyber Defense Magazine · 47d ago Cloudflare patches Copy-Fail across every server in two days Technical Information Security Content & Discussion · 47d ago New Cisco RCE was fixed Technical Information Security Content & Discussion · 47d ago From Langflow to Monero: Inside CVE-2026-33017 Cryptominer Trend Micro Research, News, Perspectives · 48d ago Court rules SAVE database illegal, orders it dismantled CyberScoop · 48d ago DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories darkreading · 48d ago Data Breach with Eastman Kodak Company Cyber Defense Magazine · 48d ago Trump executive orders speed up post-quantum migration, boost industry CyberScoop · 48d ago CVE-2026-25860 turn XSS to RCE Technical Information Security Content & Discussion · 48d ago Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign darkreading · 48d ago Intel agencies: Frontier AI models will reshape cybersecurity faster than expected CyberScoop · 48d ago He Thought He Was Secure; His Phone Number Was Stolen Anyway darkreading · 48d ago Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire Hak5 · 48d ago The World Cup Is Here… And So Are The Cyber Risks Cyber Defense Magazine · 48d ago Cloud Managed Services For Modern Cybersecurity To Secure Cloud Cyber Defense Magazine · 48d ago This Hacker Got Paid $50,000+ to Break Frontier AI Models NahamSec · 48d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 48d ago A VBScript campaign distributed through WhatsApp deploying RMM software Securelist · 48d ago Exploiting Auth0 Defaults in XSS Attacks - elttam Technical Information Security Content & Discussion · 48d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 49d ago Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1) Technical Information Security Content & Discussion · 49d ago Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors Cyber Defense Magazine · 49d ago HackTheBox - Nanocorp IppSec · 50d ago The Shadow AI Paradox: Governing Innovation At Machine Speed Cyber Defense Magazine · 50d ago Innovator Spotlight: Ensemble Cyber Defense Magazine · 51d ago Innovator Spotlight: Centrii Cyber Defense Magazine · 51d ago shadow AI is terrifying NetworkChuck · 51d ago Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530 Technical Information Security Content & Discussion · 51d ago NSPM-12: The New Baseline for National Security Cybersecurity Cyber Defense Magazine · 51d ago Soft Skills for the Job Market: Resume Writing The Cyber Mentors · 51d ago OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099) Technical Information Security Content & Discussion · 51d ago Stressors, AI Forcing Changes to Cybersecurity Teams darkreading · 51d ago Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration Technical Information Security Content & Discussion · 51d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 52d ago Authorities disrupt Evil Corp’s SocGholish botnet CyberScoop · 52d ago Congress tees up No FAKES Act, aiming at AI-generated deepfakes CyberScoop · 52d ago Novo Nordisk Breach Highlights Software Development Pipeline Risk darkreading · 52d ago HTTPS Doesn't Hide This From Your ISP!! NetworkChuck · 52d ago Operation Escaneo Signals Shift in LatAm Threat Landscape darkreading · 52d ago FIFA Bug Exposes World Cup Streams to Remote Takeover darkreading · 52d ago CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance Technical Information Security Content & Discussion · 52d ago ‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm Krebs on Security · 52d ago Salesforce Data Thefts Continue via Klue App Compromise darkreading · 52d ago Cisco Just Showed the Future of Networking NetworkChuck · 52d ago How software development’s speed obsession enabled TeamPCP’s chaos crusade CyberScoop · 52d ago Accenture shells out $4.18B on three companies in big industrial cybersecurity push CyberScoop · 52d ago Five Compliance Realities Federal Contractors Can’t Ignore Cyber Defense Magazine · 52d ago Get Out of Security Debt by Tackling the Exposure Problem darkreading · 52d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 52d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure Alerts · 52d ago Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT All CISA Advisories · 52d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 52d ago Schneider Electric EasyLogic T150 and Saitel DP All CISA Advisories · 52d ago AVer PTC cameras All CISA Advisories · 52d ago Rockwell Automation FactoryTalk Historian Site Edition All CISA Advisories · 52d ago AzeoTech DAQFactory All CISA Advisories · 52d ago Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products All CISA Advisories · 52d ago Mitsubishi Electric MELSEC iQ-F Series All CISA Advisories · 52d ago Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module All CISA Advisories · 52d ago CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure All CISA Advisories · 52d ago Would you like some malware served at the very top of DuckDuckGo? Technical Information Security Content & Discussion · 52d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 52d ago Killing me gently: Inside Gentlemen’s EDR killer framework WeLiveSecurity · 52d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 52d ago EU Gets a Head Start in Developing 6G Network Security darkreading · 52d ago PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM Trend Micro Research, News, Perspectives · 53d ago Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update Technical Information Security Content & Discussion · 53d ago This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity NahamSec · 53d ago News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies The Last Watchdog · 53d ago News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk The Last Watchdog · 53d ago Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April CyberScoop · 53d ago Cyber Security Market Insights & Trends Driving The Next Wave Of Protection Cyber Defense Magazine · 53d ago QoS Policies to Restrict EDR Traffic and Detection Strategies Technical Information Security Content & Discussion · 53d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 53d ago Protecting legacy OT systems against modern cyberthreats WeLiveSecurity · 53d ago Getting a CVE Without Shipping Slop Technical Information Security Content & Discussion · 54d ago PrizeBuzz phishing network analysis Technical Information Security Content & Discussion · 54d ago Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign Trend Micro Research, News, Perspectives · 54d ago Shark Jacked my LAN 🦈 Hak5 · 54d ago Lawmakers leery about Trump administration’s Anthropic order CyberScoop · 54d ago News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails The Last Watchdog · 54d ago AI’s constant patching treadmill can be a security problem CyberScoop · 54d ago 27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass Technical Information Security Content & Discussion · 54d ago AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns Cyber Defense Magazine · 54d ago News alert: GitGuardian adds endpoint protection as developer laptops become credential troves The Last Watchdog · 54d ago TCM Security Summer Sale is Here! The Cyber Mentors · 54d ago A case for how to shape ‘ingredient lists’ for AI models CyberScoop · 54d ago Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026 NetworkChuck · 54d ago Copilot Cowork is now generally available Microsoft 365 Blog · 54d ago Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions Cyber Defense Magazine · 54d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 54d ago Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP All CISA Advisories · 54d ago Rockwell Automation RSLinx All CISA Advisories · 54d ago Rockwell Automation FLEX I/O EtherNet/IP Adapters All CISA Advisories · 54d ago Rockwell Automation FactoryTalk Analytics PavilionX All CISA Advisories · 54d ago Rockwell Automation CompactLogix All CISA Advisories · 54d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 54d ago News alert: Varist announces AI-scale malware detection for healthcare and medical imaging The Last Watchdog · 54d ago Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk Securelist · 54d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 54d ago FishMonger’s arsenal upgraded: SprySOCKS for Windows WeLiveSecurity · 54d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 55d ago Google exposes China espionage group that’s been lurking in networks undetected since 2023 CyberScoop · 55d ago Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE Technical Information Security Content & Discussion · 55d ago I was wrong about VPNs NetworkChuck · 55d ago Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat CyberScoop · 55d ago SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon Technical Information Security Content & Discussion · 55d ago Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection? Cyber Defense Magazine · 55d ago How I Made $30,000 Hacking Broken Access Control NahamSec · 55d ago $30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover NahamSec · 55d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 55d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 55d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 55d ago EvilTokens: A phishing attack that doesn’t steal your password WeLiveSecurity · 55d ago CMMC Is Exposing A Major Gap In The Defense Supply Chain Cyber Defense Magazine · 56d ago Researcher accidentally gained access to a threat actor-controlled phishing website Technical Information Security Content & Discussion · 56d ago PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs Technical Information Security Content & Discussion · 57d ago MeshCentral: From XSS to RCE Technical Information Security Content & Discussion · 57d ago Anthropic disables new models after government calls them a national security concern CyberScoop · 57d ago HackTheBox - VariaType IppSec · 57d ago Zero Trust For AI In Defense Networks Cyber Defense Magazine · 57d ago Getting the PID from random numbers in PHP Technical Information Security Content & Discussion · 57d ago The Axios npm compromise was visible in registry metadata before anyone ran npm install Technical Information Security Content & Discussion · 57d ago FBI takes down massive China-based cybercrime network that caused $1.9B in losses CyberScoop · 58d ago Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs Technical Information Security Content & Discussion · 58d ago ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed darkreading · 58d ago US, France, and Italian authorities shut down massive deepfake porn site CyberScoop · 58d ago Conti ransomware group member pleads guilty, faces up to 20 years in prison CyberScoop · 58d ago ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw CyberScoop · 58d ago Free Compromise Detection for GitHub Repos - Tracebit Community Edition Technical Information Security Content & Discussion · 58d ago Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE) Technical Information Security Content & Discussion · 58d ago Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery Technical Information Security Content & Discussion · 58d ago Claude Fable 5 Doesn't Change the Mythos Security Story darkreading · 58d ago Why Most Cyber Resilience Programs Fail Before The First Incident Cyber Defense Magazine · 58d ago Developers React to the 105-Second Github Chain Reaction | Threat Wire Hak5 · 58d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 58d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 58d ago CyberCorps is adapting to AI. The budget isn’t keeping up. CyberScoop · 58d ago Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs Technical Information Security Content & Discussion · 58d ago Phishing Attack Volume Down 20%, But Risk Still Rising darkreading · 59d ago Governing Claude Enterprise in Environments Where Inline Controls Can't Go Trend Micro Research, News, Perspectives · 59d ago Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules Technical Information Security Content & Discussion · 59d ago Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure darkreading · 59d ago Any solutions we can use? cybersecurity · 59d ago Russian national charged in connection with Void Blizzard espionage campaign CyberScoop · 59d ago DIY pwnagotchi-like device on esp32 hacking: security in practice · 59d ago Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it Reverse Engineering · 59d ago Possible targeted attack cybersecurity · 59d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline cybersecurity · 59d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 59d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) Reverse Engineering · 59d ago Facebook messenger to text cybersecurity · 59d ago Claude Fable 5: mid-tier results on coding tasks Technical Information Security Content & Discussion · 59d ago US charges suspected Russian hacker with facilitating cyber campaign For [Blue|Purple] Teams in Cyber Defence · 59d ago Flipper Blackhat + Bjorn hacking: security in practice · 59d ago Segmentation Works for OT If Operators Are Paying Attention darkreading · 59d ago Managing Solution Agents cybersecurity · 59d ago Nottingham University data breach affects over 450,000 students cybersecurity · 59d ago SWGs that support 3rd party external DNS resolver cybersecurity · 59d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers cybersecurity · 59d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game Reverse Engineering · 59d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG cybersecurity · 59d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia For [Blue|Purple] Teams in Cyber Defence · 59d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch cybersecurity · 59d ago Do you think AI is making hacking easier or harder hacking: security in practice · 59d ago Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration Cyber Defense Magazine · 59d ago Phishing awareness training resulting in ignoring company comms? cybersecurity · 59d ago How are you analyzing Android malware nowadays? cybersecurity · 59d ago Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work Technical Information Security Content & Discussion · 59d ago Hackers Exploit Langflow Vulnerability for Remote Code Execution cybersecurity · 59d ago Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research cybersecurity · 59d ago NEED SOME GUIDANCE cybersecurity · 59d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 59d ago Yarbo Android/iOS Mobile Application and Cloud Infrastructure All CISA Advisories · 59d ago Naxclow IoT Platform All CISA Advisories · 59d ago Brickcom Cameras All CISA Advisories · 59d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 59d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Malware Analysis & Reports · 59d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened Reverse Engineering · 59d ago What can i do left? PSN hacking: security in practice · 59d ago Help setting up local encryption on my pc cybersecurity · 59d ago Hacking Google with A.I. for $500,000 Technical Information Security Content & Discussion · 59d ago Agentic AI on Cybersecurity cybersecurity · 59d ago 🔴 [PAYLOAD] Shark Jack Display 🦈 Hak5 · 59d ago DoD 0-days Typically Come Down to Authorization Failures cybersecurity · 59d ago HDD cybersecurity · 59d ago Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets cybersecurity · 59d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 59d ago OceanLotus: From external espionage to domestic targeting WeLiveSecurity · 59d ago Prompt injection: attacking the analyst's AI Technical Information Security Content & Discussion · 59d ago How can we test the firmware code/images security? cybersecurity · 59d ago 20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004 cybersecurity · 59d ago Proxmark5 campaign ending in less than 18 hours. hacking: security in practice · 59d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 For [Blue|Purple] Teams in Cyber Defence · 59d ago GreatXML: GreatXML bitlocker bypass vulnerability For [Blue|Purple] Teams in Cyber Defence · 59d ago GitHub announces npm security changes to tackle supply-chain attacks cybersecurity · 59d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan For [Blue|Purple] Teams in Cyber Defence · 59d ago The ‘Miasma’ worm source code briefly leaked on GitHub cybersecurity · 59d ago CISA Rewrites Federal Patching Requirements for AI Threat Era cybersecurity · 59d ago What is the difference between Regular TLS and Mutual TLS? cybersecurity · 59d ago Every employee's password was stored in a single Excel file cybersecurity · 59d ago npm v12 is changing how dependencies are installed to reduce supply-chain risk cybersecurity · 59d ago How to bypass speed queen coin slot for washer and dryer hacking: security in practice · 59d ago LIVE: 🕵️ CTF Prize Draw | Cybersecurity The Cyber Mentors · 59d ago Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia? cybersecurity · 59d ago Drive Firmware Security - Phison S11 Reverse Engineering · 59d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue For [Blue|Purple] Teams in Cyber Defence · 59d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion For [Blue|Purple] Teams in Cyber Defence · 59d ago How good Microsoft Defender for storage? cybersecurity · 60d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default For [Blue|Purple] Teams in Cyber Defence · 60d ago GreatXML bitlocker bypass vulnerability cybersecurity · 60d ago Struggle cybersecurity · 60d ago Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications? cybersecurity · 60d ago Chinese, N. Korean Threat Groups Build on Asia-Pacific Success darkreading · 60d ago Wiz launches Cloud Security Job Board cybersecurity · 60d ago Physical Project Ideas cybersecurity · 60d ago How can I get into cybersecurity while studying Information Systems Engineering? cybersecurity · 60d ago Miasma-style supply chain attacks For [Blue|Purple] Teams in Cyber Defence · 60d ago Cloud Security job board cybersecurity · 60d ago Continuous learning cybersecurity · 60d ago Self-hosting stuff for when things get ugly hacking: security in practice · 60d ago CISA Rewrites Federal Patching Requirements for AI Threat Era darkreading · 60d ago Angry bug hunter with Microsoft beef drops new Windows 0-day cybersecurity · 60d ago OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers CyberScoop · 60d ago Bug Bounty Research Triggers ServiceNow Security Alert darkreading · 60d ago Mid-30s, stuck in web pentesting, and wondering what to do ? cybersecurity · 60d ago AI Risk Worries Insurers & Businesses Alike darkreading · 60d ago Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM cybersecurity · 60d ago Is Microsoft Purview really secure when using Copilot? cybersecurity · 60d ago Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review Technical Information Security Content & Discussion · 60d ago News alert: Cloud security report finds fragmented tools widening the cloud complexity gap The Last Watchdog · 60d ago Malware Includes Taboo In Text To Prevent LLM Analysis hacking: security in practice · 60d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet For [Blue|Purple] Teams in Cyber Defence · 60d ago Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature? cybersecurity · 60d ago added Mac support for my corporate hacking game, demo on Steam hacking: security in practice · 60d ago IDA 9.4 Beta | Hex-Rays Docs Reverse Engineering · 60d ago Nee academic references for Hashcat's 'Next Big Bang' log cybersecurity · 60d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs For [Blue|Purple] Teams in Cyber Defence · 60d ago CISA released BOD 26-04: A new federal government vulnerability management strategy? cybersecurity · 60d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace For [Blue|Purple] Teams in Cyber Defence · 60d ago Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days cybersecurity · 60d ago IMPACT Roadshow Recap: Getting Ready for Agentic Commerce Blog – Forter · 60d ago added Mac support to my corporate hacking sim. Demo now available on Steam cybersecurity · 60d ago Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet darkreading · 60d ago CISA directive orders agencies to prioritize vulnerability patching in a new way CyberScoop · 60d ago We post-trained a model for offensive security instead of teaching it to refuse Technical Information Security Content & Discussion · 60d ago Catfished hacking: security in practice · 60d ago Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte) cybersecurity · 60d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper Malware Analysis & Reports · 60d ago Students' data taken in major University of Nottingham cyber-attack cybersecurity · 60d ago Has unmanaged external file sharing ever burned you? cybersecurity · 60d ago Who Runs the Ransomware Group ‘The Gentlemen?’ Krebs on Security · 60d ago Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers cybersecurity · 60d ago Trane Tracer HVAC cybersecurity issues Reverse Engineering · 60d ago Need feedback on my presentation cybersecurity · 60d ago Compensating controls besides admin credentials being needed to download software on employee endpoints cybersecurity · 60d ago OpenSSL PKCS#7 CVE-2026-45447 cybersecurity · 60d ago Testing offensive AI agents in a cloud lab with deception tech For [Blue|Purple] Teams in Cyber Defence · 60d ago What The Cybersecurity Industry Knows And Will Not Say Cyber Defense Magazine · 60d ago Presentation Question cybersecurity · 60d ago What did they mean by this? One of us? hacking: security in practice · 60d ago How to Stay Ahead of Deepfake Evolution in 2026 cybersecurity · 60d ago How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026 Technical Information Security Content & Discussion · 60d ago FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster Technical Information Security Content & Discussion · 60d ago France’s Government Messaging App Tchap Got Breached cybersecurity · 60d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap Malware Analysis & Reports · 60d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 60d ago Unpacking SMB cyber-readiness – and what makes or breaks it WeLiveSecurity · 60d ago certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA" Technical Information Security Content & Discussion · 60d ago Where's the fix for MiniPlasma? cybersecurity · 60d ago BlackSun - Defender for Endpoint on macOS Technical Information Security Content & Discussion · 60d ago ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances cybersecurity · 60d ago Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges hacking: security in practice · 60d ago GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline) Technical Information Security Content & Discussion · 60d ago Internships cybersecurity · 60d ago Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS cybersecurity · 60d ago Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows cybersecurity · 60d ago Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam Technical Information Security Content & Discussion · 60d ago Looking for a Reliable Cybersecurity Provider for a School in North Sydney cybersecurity · 60d ago Early Operational Visibility cybersecurity · 60d ago Benchmarking n-day exploit generation [via AI] For [Blue|Purple] Teams in Cyber Defence · 60d ago how are you actually managing ai agents in production? cybersecurity · 60d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) Reverse Engineering · 60d ago Al app builders: How are you handling security questionnaires when selling your product? cybersecurity · 60d ago [ Removed by Reddit ] cybersecurity · 60d ago How are all of doing with THE AI model thats big news currently?? cybersecurity · 60d ago Whoops! I did it again. I patched Windows Kernel at Milan0day 2026 For [Blue|Purple] Teams in Cyber Defence · 60d ago Microsoft Defender now monitors RPC activity For [Blue|Purple] Teams in Cyber Defence · 60d ago Skill to Scan your Codebase cybersecurity · 60d ago RoguePlanet: RoguePlanet Windows Defender Vulnerability For [Blue|Purple] Teams in Cyber Defence · 60d ago Miasma-style supply chain attacks cybersecurity · 61d ago FCaptcha v1.12: Catching AI Agents That Drive Real Browsers cybersecurity · 61d ago Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones cybersecurity · 61d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs cybersecurity · 61d ago More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs Technical Information Security Content & Discussion · 61d ago AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say cybersecurity · 61d ago GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026 Trend Micro Research, News, Perspectives · 61d ago Huntress Stack (MS Defender or SentinelOne) cybersecurity · 61d ago META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT cybersecurity · 61d ago OptOutCode – A Privacy4Cars Universal Opt-Out Concept hacking: security in practice · 61d ago I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in) For [Blue|Purple] Teams in Cyber Defence · 61d ago The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life darkreading · 61d ago FBI is announcing Operation Riptide cybersecurity · 61d ago Blame AI: Patch Tuesday Hits Record 206 CVEs darkreading · 61d ago ServiceNow confirmed some customer instances were breached. cybersecurity · 61d ago Which are some of the best Cybersecurity / OT Security events that happen in GCC? cybersecurity · 61d ago DF/IR Community cybersecurity · 61d ago Chaotic Eclipse's new RoguePlanet cybersecurity · 61d ago Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address darkreading · 61d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace cybersecurity · 61d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace Malware Analysis & Reports · 61d ago Microsoft breaks Patch Tuesday record with 206 vulnerabilities CyberScoop · 61d ago Thoughts on Automated Compliance? cybersecurity · 61d ago Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories darkreading · 61d ago A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available cybersecurity · 61d ago Apple’s Siri-AI, or more shouting into the void about “private” agents Technical Information Security Content & Discussion · 61d ago How do you make learning blue team security entertaining ? For [Blue|Purple] Teams in Cyber Defence · 61d ago North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says cybersecurity · 61d ago Microsoft has released a patch for the bitlocker bypass cybersecurity · 61d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. Reverse Engineering · 61d ago Please advices cybersecurity · 61d ago soc analyst l1 cybersecurity · 61d ago Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow cybersecurity · 61d ago Looking to move off KnowBe4, what are people actually using these days? cybersecurity · 61d ago Maximizing IOC Impact For [Blue|Purple] Teams in Cyber Defence · 61d ago Too Many Certs, Not Enough Experience — What’s the Best Next Step? cybersecurity · 61d ago Anthropic’s new model is Mythos on a leash CyberScoop · 61d ago Authenticating ARP and NDP cybersecurity · 61d ago Does anyone use rule feeds in 2026? cybersecurity · 61d ago [2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution For [Blue|Purple] Teams in Cyber Defence · 61d ago CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector CyberScoop · 61d ago Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations! cybersecurity · 61d ago Need a vm for practice cybersecurity · 61d ago Tips/Tricks to WFH as a SOC Analyst? cybersecurity · 61d ago Cybersecurity statistics of the week (June 1st - June 7th) cybersecurity · 61d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks For [Blue|Purple] Teams in Cyber Defence · 61d ago Where can GRC folks learn practical AppSec / DevSecOps without going full engineer? cybersecurity · 61d ago Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs darkreading · 61d ago I almost got “onboarded” into a malware campaign disguised as a job opportunity. cybersecurity · 61d ago University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model cybersecurity · 61d ago AI Blocklist - help cybersecurity · 61d ago Entra Agent ID from a Security Perspective For [Blue|Purple] Teams in Cyber Defence · 61d ago Cisco customers encounter another SD-WAN zero-day under attack CyberScoop · 61d ago Entra Agent ID from a Security Perspective Technical Information Security Content & Discussion · 61d ago Protecting AI workloads on Linux servers cybersecurity · 61d ago Exposing DoNex Ransomware Secrets with Malcore! cybersecurity · 61d ago What are the different Disaster Recovery scenarios your teams have tested on? cybersecurity · 61d ago someone actually leaked the Miasma supply chain attack toolkit source code on github cybersecurity · 61d ago X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection Technical Information Security Content & Discussion · 61d ago Rethinking Access Governance for AI Agents Cyber Defense Magazine · 61d ago Secrets to PNPT Debrief Success The Cyber Mentors · 61d ago Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility For [Blue|Purple] Teams in Cyber Defence · 61d ago WinGet - Code Execution, Persistence and Detection Strategies cybersecurity · 61d ago WinGet - Code Execution, Persistence and Detection Strategies Technical Information Security Content & Discussion · 61d ago Ransomware attack shuts Illinois high school until Wednesday cybersecurity · 61d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 61d ago Siemens KACO Blueplanet Inverters All CISA Advisories · 61d ago Schneider Electric EcoStruxure Panel Server All CISA Advisories · 61d ago Schneider Electric Modicon Network Managed Switches All CISA Advisories · 61d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 61d ago Ideas for demo cybersecurity · 61d ago Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please? cybersecurity · 61d ago Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares. cybersecurity · 61d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue Technical Information Security Content & Discussion · 61d ago Physical attack device cybersecurity · 61d ago Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer cybersecurity · 61d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 61d ago Cybercriminals: the 'auditors' you never hired WeLiveSecurity · 61d ago IT GRC News? cybersecurity · 61d ago Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again cybersecurity · 61d ago I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information Technical Information Security Content & Discussion · 61d ago What are the best risk-based vulnerability management tools for tracking active exploitation in 2026? For [Blue|Purple] Teams in Cyber Defence · 61d ago QuasarNix: Reverse Shell Detection with Machine Learning For [Blue|Purple] Teams in Cyber Defence · 61d ago Shifting L7 validation to the edge to stop DB resource exhaustion? cybersecurity · 61d ago Google Patches 5th Chrome Zero-Day Exploited in 2026 cybersecurity · 61d ago AI Agents May Always Fall for Prompt Injections Technical Information Security Content & Discussion · 61d ago Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go For [Blue|Purple] Teams in Cyber Defence · 61d ago EC Council CEH exam advice cybersecurity · 61d ago Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion For [Blue|Purple] Teams in Cyber Defence · 61d ago Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257 For [Blue|Purple] Teams in Cyber Defence · 61d ago About NPower vs PerScholas cybersecurity · 61d ago Looking for a vulnerability to learn cybersecurity · 61d ago Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency For [Blue|Purple] Teams in Cyber Defence · 61d ago From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk cybersecurity · 61d ago UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season For [Blue|Purple] Teams in Cyber Defence · 62d ago Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751) For [Blue|Purple] Teams in Cyber Defence · 62d ago Visual Studio Code 1.123: Delayed extension auto-updates For [Blue|Purple] Teams in Cyber Defence · 62d ago Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users. For [Blue|Purple] Teams in Cyber Defence · 62d ago Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched, For [Blue|Purple] Teams in Cyber Defence · 62d ago Bad USB through charger? cybersecurity · 62d ago Recommendations for Discord community for latest AI security products cybersecurity · 62d ago StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams hacking: security in practice · 62d ago Vulnerability Summary for the Week of June 1, 2026 cybersecurity · 62d ago Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas cybersecurity · 62d ago I feel like ive lost my passion to tinker after 6 years in the industry, anyone else? cybersecurity · 62d ago I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples cybersecurity · 62d ago really need help with project ideas for MSc cybersecurity · 62d ago Which Course for an almost-complete noob? (SANS.edu) cybersecurity · 62d ago SoFi confirms third-party data breach at Hong Kong subsidiary cybersecurity · 62d ago AI Slop Will Kill Cybersecurity Storytelling If We Let It darkreading · 62d ago For the 2nd time in weeks, Microsoft packages laced with credential stealer cybersecurity · 62d ago Iran Signed a Ceasefire — Its Hackers Didn't cybersecurity · 62d ago New Shai-Hulud attack trojanizes 19 science-focused PyPI packages cybersecurity · 62d ago DSPM étude marche cybersecurity · 62d ago CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file cybersecurity · 62d ago Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks darkreading · 62d ago AppSec / Pentesting job market in Canada for experienced overseas applicants? cybersecurity · 62d ago Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients. cybersecurity · 62d ago Check Point VPN Flaw Exploited Since Early May darkreading · 62d ago Automation Playbooks - which ones would you not want to live without? cybersecurity · 62d ago Is it necessary/important to Hash and salt API Keys for a strictly internal use tool? cybersecurity · 62d ago Need review on the OMS Cybersecurity program from Georgia Tech? cybersecurity · 62d ago If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk cybersecurity · 62d ago 2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years cybersecurity · 62d ago Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement For [Blue|Purple] Teams in Cyber Defence · 62d ago How do you close an alert cybersecurity · 62d ago Iran Signed a Ceasefire — Its Hackers Didn't darkreading · 62d ago What cybersecurity certifications are great value for money? cybersecurity · 62d ago Boxes for CPENT cybersecurity · 62d ago SIEM: is it "SIM" or "SEEM" cybersecurity · 62d ago I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included) cybersecurity · 62d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment Malware Analysis & Reports · 62d ago How justdeleteme and justgetmydata work? cybersecurity · 62d ago Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint CyberScoop · 62d ago GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks. hacking: security in practice · 62d ago How CIAM Helps Boost Business Cyber Defense Magazine · 62d ago I need help - PCI DSS 4.0 requirement 11.6.1 cybersecurity · 62d ago How are you learning agent pen testing? cybersecurity · 62d ago HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified) For [Blue|Purple] Teams in Cyber Defence · 62d ago Cyber security intern cybersecurity · 62d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 62d ago [Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme Reverse Engineering · 62d ago Introducing Shark Jack Display 🦈 Hak5 · 62d ago Meta to take legal action against Israeli spyware company NSO cybersecurity · 62d ago Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit cybersecurity · 62d ago What's the best way to alert companies of a Glassworm copycat? cybersecurity · 62d ago How To Verify If A Site Is Legit? cybersecurity · 62d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 62d ago What is Flaresolverr cybersecurity · 62d ago Research: defenders using generative AI to simulate malware variants before they exist in the wild cybersecurity · 62d ago How are regulated orgs actually letting engineers use Claude Code / Copilot? cybersecurity · 62d ago Cyber security expo Manchester cybersecurity · 62d ago Content creations was both a blessing and a curse. #bugbounty NahamSec · 62d ago Remote Hiring Opened the Talent Pool — and the Fraud Surface cybersecurity · 62d ago Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it Technical Information Security Content & Discussion · 62d ago World Cloud Security Day Cyber Defense Magazine · 62d ago This Hacker Made $7,000 Hacking AI With One Email NahamSec · 62d ago EMBA firmware analysis framework v2.0.2 available - Party the big 2k Reverse Engineering · 62d ago Hades Cluster PyPI Worm Abuses Python Startup Hooks cybersecurity · 62d ago What certs should I do during summer of 11th grade? cybersecurity · 62d ago CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318) cybersecurity · 62d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 62d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 62d ago Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine cybersecurity · 62d ago Oxford University discloses data breach after careers platform hack cybersecurity · 62d ago Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing cybersecurity · 62d ago Got this message from “SimBoss” cybersecurity · 62d ago PKCS12 Golang fork cybersecurity · 62d ago The AI security race needs accountability, not overregulation CyberScoop · 62d ago Malware Insights: Miasma Campaign cybersecurity · 62d ago 73 Microsoft GitHub repositories impacted by Miasma malware Malware Analysis & Reports · 62d ago 73 Microsoft GitHub repositories impacted by Miasma malware cybersecurity · 62d ago [Honeypot Research] Looking for volunteers to test telemetry/logs cybersecurity · 62d ago Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏 hacking: security in practice · 62d ago From cause to cash: a cross-border look at hacktivist activity Securelist · 62d ago What is the condition of Bug Bounty program in the era of AI. cybersecurity · 62d ago Opening a cloned repo is no longer safe cybersecurity · 62d ago Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse cybersecurity · 62d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 62d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 62d ago Google Colab CLI opens runtimes to Claude Code and Codex cybersecurity · 62d ago VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks cybersecurity · 62d ago The AI governance gap no one is talking about: deployment-stage accountability cybersecurity · 62d ago Security Review Request — TID Linux Kernel Module For [Blue|Purple] Teams in Cyber Defence · 62d ago Building a safe, effective sandbox to enable Codex on Windows For [Blue|Purple] Teams in Cyber Defence · 62d ago Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. For [Blue|Purple] Teams in Cyber Defence · 62d ago About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection For [Blue|Purple] Teams in Cyber Defence · 62d ago BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection For [Blue|Purple] Teams in Cyber Defence · 62d ago Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution. For [Blue|Purple] Teams in Cyber Defence · 63d ago Unauthorized Onlyfans Payment Malware Analysis & Reports · 63d ago Free Study Resources for Comptia Cysa+ cybersecurity · 63d ago What's up with powershellforhackers.com? hacking: security in practice · 63d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 63d ago Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open Trend Micro Research, News, Perspectives · 63d ago Hi there cybersecurity · 63d ago Final risk-based IT Audit interview round with Director and have no experience. Please help! cybersecurity · 63d ago Needed help cybersecurity · 63d ago HDD Firmware Hacking Part 1 Reverse Engineering · 63d ago [ Removed by Reddit ] cybersecurity · 63d ago UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service. For [Blue|Purple] Teams in Cyber Defence · 63d ago Career advice cybersecurity · 63d ago Do people really click on links from unknown numbers? hacking: security in practice · 63d ago PhD in cyber Security cybersecurity · 63d ago Built a password guessing game. Almost everyone stuck in level 5. cybersecurity · 63d ago OSINT (SOCIAL MEDIA) cybersecurity · 63d ago Beginner KQL project cybersecurity · 63d ago Question about WORM and encryption cybersecurity · 63d ago Update:Certified cyber security cybersecurity · 63d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction Reverse Engineering · 63d ago How to unlock whitelabeled uniview IPcam hacking: security in practice · 63d ago EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server. For [Blue|Purple] Teams in Cyber Defence · 63d ago Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental cybersecurity · 63d ago Can converted video files contain malware? hacking: security in practice · 63d ago Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction) cybersecurity · 63d ago Malware that survives reinstalling the BIOS and OS cybersecurity · 63d ago Am I overthinking the x86 compatibility issues? how much friction am I actually facing? cybersecurity · 63d ago Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure cybersecurity · 63d ago Managing Microsoft Identity Is More Complicated Than It Looks cybersecurity · 63d ago Zhiyun Weebil-S Camera Gimbal BLE Protocol Reverse Engineering · 63d ago My work email got subscribed to a bunch of israel newsletters cybersecurity · 63d ago Shadow AI cybersecurity · 63d ago Rate limiting is not enough. What else can I use? cybersecurity · 63d ago CMMC Is Here, But AI Changes The Compliance Conversation Cyber Defense Magazine · 63d ago How To Avoid Potential Malware From Transferring To New Laptop cybersecurity · 63d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 cybersecurity · 63d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 63d ago Can't decide. cybersecurity · 63d ago looking for partners cybersecurity · 63d ago My edge is changing into bing when I search something cybersecurity · 63d ago Reverse Engineering the Garmin Running Dynamics BLE protocol Reverse Engineering · 63d ago Cybersecurity reality check cybersecurity · 63d ago [ Removed by Reddit ] cybersecurity · 63d ago EDRChoker: Choking The Telemetry Stream to Bypass Defenses Technical Information Security Content & Discussion · 63d ago Information Management cybersecurity · 63d ago Pwnd Blaster: Hacking your PC using your speaker without ever touching it For [Blue|Purple] Teams in Cyber Defence · 63d ago cygor: An modular asset discovery framework written in python to automate the repeating manual work For [Blue|Purple] Teams in Cyber Defence · 63d ago On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts. For [Blue|Purple] Teams in Cyber Defence · 63d ago Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors. For [Blue|Purple] Teams in Cyber Defence · 63d ago Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim For [Blue|Purple] Teams in Cyber Defence · 63d ago Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored) For [Blue|Purple] Teams in Cyber Defence · 63d ago The Privileged Roles Nobody Talks About For [Blue|Purple] Teams in Cyber Defence · 63d ago Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain... For [Blue|Purple] Teams in Cyber Defence · 63d ago Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis For [Blue|Purple] Teams in Cyber Defence · 63d ago 21 Zero-Days in FFmpeg For [Blue|Purple] Teams in Cyber Defence · 63d ago IronWorm Malware cybersecurity · 63d ago Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh? cybersecurity · 63d ago Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh? cybersecurity · 64d ago Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager cybersecurity · 64d ago depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research? For [Blue|Purple] Teams in Cyber Defence · 64d ago PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware Technical Information Security Content & Discussion · 64d ago Is a separate “clean” S3 bucket actually a security boundary for uploaded files? cybersecurity · 64d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass Technical Information Security Content & Discussion · 64d ago CVE-2026-46640: Developing payloads for Twig sandbox bypass cybersecurity · 64d ago CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work For [Blue|Purple] Teams in Cyber Defence · 64d ago PenTest+ Exam cybersecurity · 64d ago Rooted your router lately? hacking: security in practice · 64d ago AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs cybersecurity · 64d ago The Detection & Response Chronicles: Covert Operations Through QEMU For [Blue|Purple] Teams in Cyber Defence · 64d ago The Interesting Case of WSL for Payload Staging For [Blue|Purple] Teams in Cyber Defence · 64d ago The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer For [Blue|Purple] Teams in Cyber Defence · 64d ago Ongoing Targeted Campaign Against US Law Firms For [Blue|Purple] Teams in Cyber Defence · 64d ago New China-Linked Cluster OP-512 For [Blue|Purple] Teams in Cyber Defence · 64d ago Looking for guidance cybersecurity · 64d ago 5$ to whoever can find the email of my old YouTube channel hacking: security in practice · 64d ago Before you attempt any OffSec certification, read what just happened to me cybersecurity · 64d ago Reporting Metrics for Management cybersecurity · 64d ago got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time cybersecurity · 64d ago This company is scaming people hacking: security in practice · 64d ago Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried cybersecurity · 64d ago HackTheBox - Facts IppSec · 64d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. cybersecurity · 64d ago AI Security Certificates cybersecurity · 64d ago Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload. For [Blue|Purple] Teams in Cyber Defence · 64d ago Guys is bug bounty dead? cybersecurity · 64d ago How are folks making it in bug bounty? cybersecurity · 64d ago How useful is it to require at least one uppercase letter in a password? cybersecurity · 64d ago Cybersecurity Improved Detection But Exposed a New Problem Cyber Defense Magazine · 64d ago Cyber security ! Is no more ? cybersecurity · 64d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 64d ago MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain For [Blue|Purple] Teams in Cyber Defence · 64d ago Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated For [Blue|Purple] Teams in Cyber Defence · 64d ago Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns For [Blue|Purple] Teams in Cyber Defence · 64d ago About ETW Internals: Architecture, Hooking, Tampering, and Detection For [Blue|Purple] Teams in Cyber Defence · 64d ago PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver For [Blue|Purple] Teams in Cyber Defence · 64d ago Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp For [Blue|Purple] Teams in Cyber Defence · 64d ago Async PICOs and Custom Beacon Wakeups in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 64d ago Enter the WasmForge: Compiling Sliver into WebAssembly For [Blue|Purple] Teams in Cyber Defence · 64d ago staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs For [Blue|Purple] Teams in Cyber Defence · 64d ago Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window For [Blue|Purple] Teams in Cyber Defence · 64d ago Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS For [Blue|Purple] Teams in Cyber Defence · 64d ago BOF Cocktails in Cobalt Strike For [Blue|Purple] Teams in Cyber Defence · 64d ago Address Translation For [Blue|Purple] Teams in Cyber Defence · 64d ago CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers cybersecurity · 64d ago Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months cybersecurity · 64d ago Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories cybersecurity · 64d ago Investigation into APT 5 and their inner workings of PLA Troop 61786 For [Blue|Purple] Teams in Cyber Defence · 64d ago How to train employees to feel when something's off? cybersecurity · 64d ago Building A Malware Lab From Scratch Part 2! Malware Analysis & Reports · 64d ago A modular autonomous-agent runtime written in C hacking: security in practice · 64d ago The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy For [Blue|Purple] Teams in Cyber Defence · 64d ago ALERT OVERLOAD cybersecurity · 64d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems For [Blue|Purple] Teams in Cyber Defence · 64d ago Magecart skimmer turns Stripe into a malware command server For [Blue|Purple] Teams in Cyber Defence · 64d ago Security advisory: Brute force attack on Dashlane user accounts For [Blue|Purple] Teams in Cyber Defence · 64d ago Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability For [Blue|Purple] Teams in Cyber Defence · 64d ago A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact). For [Blue|Purple] Teams in Cyber Defence · 64d ago IronWorm: Shai-Hulud's rustier cousin For [Blue|Purple] Teams in Cyber Defence · 64d ago Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate) Reverse Engineering · 64d ago CTO at NCSC Summary: week ending June 7th cybersecurity · 64d ago Weil reportedly pays up to $20 million after hackers steal client data For [Blue|Purple] Teams in Cyber Defence · 64d ago CTO at NCSC Summary: week ending June 7th For [Blue|Purple] Teams in Cyber Defence · 64d ago A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled cybersecurity · 64d ago defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize For [Blue|Purple] Teams in Cyber Defence · 64d ago 1-Click GitHub Token Stealing via a VSCode Bug For [Blue|Purple] Teams in Cyber Defence · 64d ago The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds For [Blue|Purple] Teams in Cyber Defence · 64d ago Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub cybersecurity · 64d ago Detecting npm Native Addon Malware: node-gyp Abuse Malware Analysis & Reports · 64d ago AppSec Engineer Interview Stories cybersecurity · 64d ago [OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps. cybersecurity · 65d ago Multi-layer sandbox for native code execution on Linux with no external deps. For [Blue|Purple] Teams in Cyber Defence · 65d ago Is there a safe way to continue using (unsupported) Windows 10? cybersecurity · 65d ago Is Splunk suitable for smaller Enterprises? cybersecurity · 65d ago Has anyone else had MFA prompt fatigue issues with users? cybersecurity · 65d ago Data Scrubbing from Databases cybersecurity · 65d ago Best Certificates? cybersecurity · 65d ago Rant cybersecurity · 65d ago New York passes data center moratorium and consumer protections as environmental, and housing proposals stall cybersecurity · 65d ago Cyber attackers have a new favorite, the browser cybersecurity · 65d ago Looking to get into cybersecurity in web3 cybersecurity · 65d ago Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests cybersecurity · 65d ago Should i use email 2fa or only auth and phone number? cybersecurity · 65d ago Can I break into cybersecurity with a white collar felony? cybersecurity · 65d ago Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale cybersecurity · 65d ago How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time? cybersecurity · 65d ago What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent? cybersecurity · 65d ago Innovator Spotlight: Airrived Cyber Defense Magazine · 65d ago How Hard is This cybersecurity · 65d ago Reverse Engineering Crazy Taxi, Part 3 Reverse Engineering · 65d ago Ghidra 12.1.2 has been released! Reverse Engineering · 65d ago Installed Fake Codex hidden as a google site cybersecurity · 65d ago Virustital scan result help cybersecurity · 65d ago CrowdStrike Turned an AI Wave Into Its Best Quarter Ever cybersecurity · 65d ago ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more hacking: security in practice · 65d ago Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions? cybersecurity · 65d ago I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now cybersecurity · 65d ago Being a Security Engineer? Which AI-powered tools are you using on a daily basis? cybersecurity · 65d ago Over 900 US gas station tank gauge systems exposed to attacks cybersecurity · 65d ago Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person cybersecurity · 65d ago SIEM is broken in the AI agents era cybersecurity · 65d ago TCM Security CTF Walkthrough The Cyber Mentors · 65d ago Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption Technical Information Security Content & Discussion · 65d ago Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected cybersecurity · 65d ago Extending a map tool for Cataclismo Reverse Engineering · 65d ago Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away CyberScoop · 65d ago Keeping Secrets Out of Logs Technical Information Security Content & Discussion · 65d ago Phantom Gyp npm Worm Abuses node-gyp Build Hooks cybersecurity · 65d ago Certified cybersecurity ISC2 cybersecurity · 65d ago Help studying for OSCP cybersecurity · 65d ago The current state of Threat Intelligence Tooling cybersecurity · 65d ago Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware cybersecurity · 65d ago I've been reverse engineering a lost 2010 horse MMO and I need contributors Reverse Engineering · 65d ago Cloud Security In Practice Cyber Defense Magazine · 65d ago We tested offensive AI agents against deception technology cybersecurity · 65d ago A matter that I have been losing my sleep over cybersecurity · 65d ago Any experience with Rootly or incident.io for cyber incident management? cybersecurity · 65d ago CTIA Study Resources & Preparation Advice? cybersecurity · 65d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 65d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 65d ago Black hat uk vs brucon cybersecurity · 65d ago Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier) Technical Information Security Content & Discussion · 65d ago Cisco warns of unpatched SD-WAN zero-day exploited in attacks cybersecurity · 65d ago NIS2 hits railway hard cybersecurity · 65d ago Introducing Package Proxy: supply-chain safety checks without client-side software For [Blue|Purple] Teams in Cyber Defence · 65d ago I need help guys… :( cybersecurity · 65d ago Question from the Seniors cybersecurity · 65d ago China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware cybersecurity · 65d ago AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer For [Blue|Purple] Teams in Cyber Defence · 65d ago Can one reveal the asterisks in an email? hacking: security in practice · 65d ago what certs have u seen in ai security related job posts ? cybersecurity · 65d ago How is the Security Architecture / Strategic IT Security process structured in your organization? cybersecurity · 65d ago Proxmark3 vs Proxmark5 Side by Side hacking: security in practice · 65d ago Should I go for it? hacking: security in practice · 65d ago What's happening in cybersecurity job market in US and Europe these days? cybersecurity · 65d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links Malware Analysis & Reports · 65d ago Has any of you pivoted from GRC to CTI? cybersecurity · 65d ago Up-date-list of cybercrime types? cybersecurity · 65d ago HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes Reverse Engineering · 65d ago What else should I learn to build a strong cybersecurity foundation? cybersecurity · 65d ago zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS) For [Blue|Purple] Teams in Cyber Defence · 65d ago Hackerone interview cybersecurity · 65d ago Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix cybersecurity · 65d ago The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory For [Blue|Purple] Teams in Cyber Defence · 65d ago VerdantBamboo: Just Another BRICKSTORM in the Firewall For [Blue|Purple] Teams in Cyber Defence · 65d ago AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID For [Blue|Purple] Teams in Cyber Defence · 65d ago MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code For [Blue|Purple] Teams in Cyber Defence · 65d ago IronWorm Supply Chain Malware Hits npm For [Blue|Purple] Teams in Cyber Defence · 65d ago FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel For [Blue|Purple] Teams in Cyber Defence · 65d ago FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad For [Blue|Purple] Teams in Cyber Defence · 65d ago You do surprise me.exe: An unexpected executable in Hola Browser For [Blue|Purple] Teams in Cyber Defence · 66d ago Testing URL Rewriting? cybersecurity · 66d ago Got an internship in IAM with no qualifications and no soft skills cybersecurity · 66d ago Work Hours of DFIR/Cloud Security vs Pentest cybersecurity · 66d ago Narcissistic Tech Leader.... cybersecurity · 66d ago Anyone else's firewall logs just explode after midnight? cybersecurity · 66d ago I'm replacing myself.. at least the boring parts cybersecurity · 66d ago Anyone else dealing with these phantom login attempts from China? cybersecurity · 66d ago Multi-layer sandbox for native code execution on Linux with no external deps. Reverse Engineering · 66d ago Best way to fully clear windows and set everything up securely (pc, accounts etc) cybersecurity · 66d ago IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks cybersecurity · 66d ago Soc analyst cybersecurity · 66d ago Do companies actually require cybersecurity insurance cybersecurity · 66d ago Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header hacking: security in practice · 66d ago Certification Questions | LIVE AMA | Summer of CCNA NetworkChuck · 66d ago Hill Dems hammer GOP for $250M CISA budget cut CyberScoop · 66d ago Uncommon/Unusual CrowdStrike Alerts cybersecurity · 66d ago Cyber analyst: law firm or bank cybersecurity · 66d ago best free av and how do i properly setup passwords? cybersecurity · 66d ago Five 9 Vulnerability cybersecurity · 66d ago Failed to verify LHOST error for long links in metasploit hacking: security in practice · 66d ago CVE Lite CLI closes dependency gap — but won't stop modern threats cybersecurity · 66d ago Scope change cybersecurity · 66d ago We just stopped a social engineering attack on our service desk. Here’s how it played out. cybersecurity · 66d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Reverse Engineering · 66d ago System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models Technical Information Security Content & Discussion · 66d ago Your AI agent could become your biggest insider threat CyberScoop · 66d ago What is the most underestimated cybersecurity risk right now? cybersecurity · 66d ago Update: Company is paying for any certification, which should I obtain? Except Sans cybersecurity · 66d ago New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification cybersecurity · 66d ago Anyone else's firewall vendor docs a total nightmare? cybersecurity · 66d ago Your opinions about a learning style cybersecurity · 66d ago Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks cybersecurity · 66d ago New IronWorm malware hits 36 packages in npm supply-chain attack cybersecurity · 66d ago Is Marauder available for ESP32-S3 Mini? hacking: security in practice · 66d ago Anyone else see their firewall logs just explode after a cloud update? cybersecurity · 66d ago Gemini whatsapp hacking: security in practice · 66d ago Are certifications necessary to get a job in cybersecurity? cybersecurity · 66d ago Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass) cybersecurity · 66d ago Is retyping and translating textbooks too inefficient for CS/Cybersecurity? cybersecurity · 66d ago Free Microsoft Enterprise Security Assessment: Worth It cybersecurity · 66d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) Technical Information Security Content & Discussion · 66d ago How are organizations preparing for AI-generated phishing attacks? cybersecurity · 66d ago Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js Technical Information Security Content & Discussion · 66d ago Inside the race to adapt to an AI-powered security world cybersecurity · 66d ago 127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For cybersecurity · 66d ago Inside the race to adapt to an AI-powered security world CyberScoop · 66d ago Microsoft blames unexpected Windows driver updates on caching issue cybersecurity · 66d ago Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance) cybersecurity · 66d ago Enter the WasmForge: Compiling Sliver into WebAssembly Technical Information Security Content & Discussion · 66d ago Your CPU model leaks through the browser via WASM timing differences cybersecurity · 66d ago LSASS/Defender/CTFMON analysis For [Blue|Purple] Teams in Cyber Defence · 66d ago Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing Cyber Defense Magazine · 66d ago Software supply chain attacks: check your dependencies For [Blue|Purple] Teams in Cyber Defence · 66d ago void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies Reverse Engineering · 66d ago Chinese Cybercrime Group in Spotlight for Record Campaign Pace cybersecurity · 66d ago NAVTOR NavBox All CISA Advisories · 66d ago Hitachi Energy MACH HiDraw All CISA Advisories · 66d ago Hitachi Energy ITT600 Explorer All CISA Advisories · 66d ago B&R PPT30 Operating System All CISA Advisories · 66d ago Hitachi Energy RTU500 All CISA Advisories · 66d ago Extremely suspicious behaviour by memu emulator Malware Analysis & Reports · 66d ago Security Engineer 2 interview at Amazon coming up - What to expect? cybersecurity · 66d ago A researcher spent $1,500 testing if LLMs could hack a vulnerable app cybersecurity · 66d ago Help with university internship cybersecurity · 66d ago Are MCP servers becoming the next API security nightmare? cybersecurity · 66d ago Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator For [Blue|Purple] Teams in Cyber Defence · 66d ago What's the cybersecurity lesson you learned the hard way? cybersecurity · 66d ago ISO 27001 Surveillance audit vs Full recertification cybersecurity · 66d ago How important it is to get paid Cybersecurity certificates ? cybersecurity · 66d ago Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process cybersecurity · 66d ago Soc to Architecture cybersecurity · 66d ago Does "example file vulnerability" exists? cybersecurity · 66d ago VS code forces 2 hour cool down for most integrations. cybersecurity · 66d ago Company laptop isolated after Brave/Tor alert - should I be worried? cybersecurity · 66d ago Does anyone know how to send false positive to SOCradar ? virus total cybersecurity · 66d ago Looking for people to team up for Bug Bounties & CTFs cybersecurity · 66d ago Signal Without Smartphone cybersecurity · 66d ago I found a trojan on my pc and now im scared my private calls got leaked cybersecurity · 66d ago Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests cybersecurity · 66d ago CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog cybersecurity · 66d ago How do you change users behavior through awareness training? cybersecurity · 66d ago AI-built ransomware toolkit automates EDR evasion, AD discovery cybersecurity · 66d ago 29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection) For [Blue|Purple] Teams in Cyber Defence · 66d ago Safe Rust API for wolfSSL/wolfCOSE hacking: security in practice · 66d ago Safe Rust API for wolfSSL/wolfCOSE cybersecurity · 66d ago Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma) cybersecurity · 66d ago AMD GPU Users might be compromised cybersecurity · 66d ago [ Removed by Reddit ] cybersecurity · 66d ago Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information cybersecurity · 66d ago CISA warns of cyberattacks targeting fuel tank monitoring systems cybersecurity · 66d ago [CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF cybersecurity · 66d ago how to get good at cyber security? cybersecurity · 66d ago Anyone use CrunchAtlas? cybersecurity · 67d ago Prompt monitoring laughs cybersecurity · 67d ago Malicious Payload in ai-sdk-ollama npm Package cybersecurity · 67d ago Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24) cybersecurity · 67d ago Resource Exhaustion hacking: security in practice · 67d ago what the HELL is dsztfso? cybersecurity · 67d ago Open Source - 2500 New MITRE Mutations For [Blue|Purple] Teams in Cyber Defence · 67d ago Yubikey Alternative....? cybersecurity · 67d ago Hiring cybersecurity · 67d ago Malware Malware Analysis & Reports · 67d ago CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing cybersecurity · 67d ago Agent-Ready: How to Prepare Your Site for AI-Driven Commerce Blog – Forter · 67d ago Certification Advice cybersecurity · 67d ago Question about Linux kernel TLS ULP disclosed June 2 to oss-security cybersecurity · 67d ago European authorities crack down on illegal streaming networks CyberScoop · 67d ago An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this? cybersecurity · 67d ago How to Rob a Data Center (new article on data center physical security) cybersecurity · 67d ago Hermes has a Home Assistant skill and it's unreal! NetworkChuck · 67d ago US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server cybersecurity · 67d ago Is it worth taking the EC councils masters program?? Are they legit /2026 cybersecurity · 67d ago Mid-level AppSec engineers: what do you actually study to prep for interviews? cybersecurity · 67d ago Automated Fault Injection Attack Framework Reverse Engineering · 67d ago Season VI of the US Games launches TOMORROW! Technical Information Security Content & Discussion · 67d ago Company is paying for any certification, which should I obtain? cybersecurity · 67d ago DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels CyberScoop · 67d ago Trusting Microsoft with your offensive security repos cybersecurity · 67d ago Automated Fault Injection Attack Framework cybersecurity · 67d ago Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT For [Blue|Purple] Teams in Cyber Defence · 67d ago Bring Your Own RWX Region DLL (BYORWXDLL) For [Blue|Purple] Teams in Cyber Defence · 67d ago Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem For [Blue|Purple] Teams in Cyber Defence · 67d ago APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component For [Blue|Purple] Teams in Cyber Defence · 67d ago NuGet Code Execution As A Service For [Blue|Purple] Teams in Cyber Defence · 67d ago aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies For [Blue|Purple] Teams in Cyber Defence · 67d ago Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor For [Blue|Purple] Teams in Cyber Defence · 67d ago TA4922: The Suspected Chinese Crime Group is Going Global For [Blue|Purple] Teams in Cyber Defence · 67d ago [ Removed by Reddit ] For [Blue|Purple] Teams in Cyber Defence · 67d ago Physical Biometric device as a security measure..?? cybersecurity · 67d ago Espionage Campaign Targeted Stock Exchange Executive for Five Months For [Blue|Purple] Teams in Cyber Defence · 67d ago Cybersegurança cybersecurity · 67d ago Started Learning Cybersecurity cybersecurity · 67d ago InfraGard Application - Seeking Help | Student cybersecurity · 67d ago x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994) Reverse Engineering · 67d ago Orientación en Ciberseguridad cybersecurity · 67d ago OnionAccelerator: multi-circuit / chunked download acceleration over Tor For [Blue|Purple] Teams in Cyber Defence · 67d ago Anthropic's coordinated vulnerability disclosure dashboard cybersecurity · 67d ago Hands Free: What LLM Driven Vulnerability Research Looks Like cybersecurity · 67d ago HazyBeacon and AWS Lambda Function URL Abuse For [Blue|Purple] Teams in Cyber Defence · 67d ago Real time Cybersecurity failures regarding Quantum computing/cryptography cybersecurity · 67d ago The Server Seizure That Affects Also Iran's Cyber Operations For [Blue|Purple] Teams in Cyber Defence · 67d ago How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad For [Blue|Purple] Teams in Cyber Defence · 67d ago 🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop Malware Analysis & Reports · 67d ago 🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It. cybersecurity · 67d ago 🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network For [Blue|Purple] Teams in Cyber Defence · 67d ago Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2 Reverse Engineering · 67d ago A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out. cybersecurity · 67d ago CISA warns of active attacks exploiting Android, Linux bugs cybersecurity · 67d ago Found some open ports on a govt site, should i report or stay quiet? cybersecurity · 67d ago What is a good way to keep track of passwords for programs that don't support password managers? cybersecurity · 67d ago ChatGPT Malvertising Campaign Malware Analysis & Reports · 67d ago Cybersecurity statistics of the week (May 25th - May 31st) cybersecurity · 67d ago ASN Emissions Index. Networks ranked by how much noise they create on the internet. cybersecurity · 67d ago Have you sold cve before? cybersecurity · 67d ago EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires Technical Information Security Content & Discussion · 67d ago i want to become a pentester, but i don't know how to cybersecurity · 67d ago Recommendation Malware Analysis & Reports · 67d ago I’m not sure I’m in the right subreddit…. hacking: security in practice · 67d ago The OT Security Problem Nobody Wants to Own cybersecurity · 67d ago Don't Take Wednesday Off When You Manage Vulnerabilities cybersecurity · 67d ago I finally finished a production version after 4 yrds cybersecurity · 67d ago Support role pivot to cloud security cybersecurity · 67d ago Sysmon RegistryEvent exclude not overriding include rule for Event ID 13 For [Blue|Purple] Teams in Cyber Defence · 67d ago Took me a decade to turn quantum computing into what hackers can easily learn hacking: security in practice · 67d ago Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6! Malware Analysis & Reports · 67d ago How do you manage your passwords? cybersecurity · 67d ago The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector Cyber Defense Magazine · 67d ago Mad rush to produce AI driven slop cybersecurity · 67d ago O Tails é seguro para acessar links suspeitos? cybersecurity · 67d ago Took me a decade of work to turn Quantum Computing into a fun videogame hacking: security in practice · 67d ago Interesting- What LLM vuln research looks like Technical Information Security Content & Discussion · 67d ago Cyber Essentials plus + "legacy" network segments cybersecurity · 67d ago Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors For [Blue|Purple] Teams in Cyber Defence · 67d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 67d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 67d ago Hacking your PC using your speaker without ever touching it Reverse Engineering · 67d ago Hacking your PC using your speaker without ever touching it Technical Information Security Content & Discussion · 67d ago Insight for OPSWAT deep CDR cybersecurity · 67d ago Android vs iOS cybersecurity · 67d ago ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account cybersecurity · 67d ago Security Audits at an MSP cybersecurity · 67d ago [ Removed by Reddit ] cybersecurity · 67d ago Argamal: Malware hidden in hentai games Securelist · 67d ago Passkey registration breaks after moving off localhost.. cybersecurity · 67d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 67d ago Lessons for life: Why children’s data is a long-term identity risk WeLiveSecurity · 67d ago Does your team hire fresh AI engineer who doesn't know anything about Security operations? cybersecurity · 67d ago UARs for Equation (banking system) cybersecurity · 67d ago Simple way how to bypass hotel WiFi? hacking: security in practice · 67d ago VS Code zero-day lets hackers steal GitHub tokens in one click hacking: security in practice · 67d ago Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing Technical Information Security Content & Discussion · 67d ago IoT pentesting cert cybersecurity · 67d ago Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations cybersecurity · 67d ago Experience with Tac Security cybersecurity · 67d ago Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content cybersecurity · 67d ago Golang code review notes II - elttam Technical Information Security Content & Discussion · 67d ago Using AI to Secure Its Generated Code Is a Ponzi Scheme Technical Information Security Content & Discussion · 67d ago Found Security Vulnerabilities in my university website cybersecurity · 67d ago burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API) hacking: security in practice · 67d ago Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence cybersecurity · 67d ago AI - Threat to the CyberSec Industry? cybersecurity · 67d ago Built a honeypot platform to catch lateral movement. How are you guys detecting this? cybersecurity · 67d ago How should small SaaS teams safely answer customer security questionnaires? cybersecurity · 68d ago Dependency Cooldowns - Dependency Cooldowns For [Blue|Purple] Teams in Cyber Defence · 68d ago Can AI Do Intelligence Analysis? Apparently Not. cybersecurity · 68d ago PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model cybersecurity · 68d ago Regarding Certified Ethical Hacker (CEH Practical) exam cybersecurity · 68d ago Asking for advices on pursuing first CERTIFICATE cybersecurity · 68d ago I opened my own company and I can't find clients! cybersecurity · 68d ago ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter cybersecurity · 68d ago C2 Frameworks - Threat Hunting in Action with YARA Rules For [Blue|Purple] Teams in Cyber Defence · 68d ago How big of a security risk or exploit would this be? hacking: security in practice · 68d ago Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU? cybersecurity · 68d ago Anyone knows Quad9 dns ? cybersecurity · 68d ago KTO , Be the only one online -- on any WiFi network hacking: security in practice · 68d ago Ransomware tabletop For [Blue|Purple] Teams in Cyber Defence · 68d ago FREE coffee at Cisco Live (I'm giving it away) NetworkChuck · 68d ago I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ? cybersecurity · 68d ago Greynoise swarm cybersecurity · 68d ago SecOT+ certification for free cybersecurity · 68d ago How is the state of the job market for mid-level security engineers? cybersecurity · 68d ago Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things cybersecurity · 68d ago WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total cybersecurity · 68d ago Laid off from TPRM job - need help on the future of my career cybersecurity · 68d ago News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces The Last Watchdog · 68d ago Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026 For [Blue|Purple] Teams in Cyber Defence · 68d ago Tracking North Korea Nation-State APT Infrastructure: Kimsuky For [Blue|Purple] Teams in Cyber Defence · 68d ago 새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn For [Blue|Purple] Teams in Cyber Defence · 68d ago From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services For [Blue|Purple] Teams in Cyber Defence · 68d ago apparently bypassing school systems by playing games hacking: security in practice · 68d ago Anyone compared RoboShadow vs ConnectSecure for vulnerability management? cybersecurity · 68d ago Codex Discovered a Hidden HTTP/2 Bomb For [Blue|Purple] Teams in Cyber Defence · 68d ago Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes Technical Information Security Content & Discussion · 68d ago Top 5 Active Directory Pentesting Tools The Cyber Mentors · 68d ago Any one send vulnerability to MITRE? cybersecurity · 68d ago Need advice for a 30 min Security Apprenticeship interview cybersecurity · 68d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 68d ago Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix For [Blue|Purple] Teams in Cyber Defence · 68d ago UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS cybersecurity · 68d ago Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match cybersecurity · 68d ago We Added a Detection Rule. We Were Not Expecting This. Technical Information Security Content & Discussion · 68d ago Introducing Microsoft Scout: Your always-on personal agent Microsoft 365 Blog · 68d ago Virustotal API as private data source cybersecurity · 68d ago DOD wants to integrate cyber in all operations, and integrate security into AI CyberScoop · 68d ago Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source! Reverse Engineering · 68d ago Announcing the new Work IQ APIs Microsoft 365 Blog · 68d ago Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases Security | Microsoft Azure Blog | Microsoft Azure · 68d ago Trump administration releases scaled-back AI executive order CyberScoop · 68d ago Account Number Security Flaw cybersecurity · 68d ago Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning? cybersecurity · 68d ago A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth cybersecurity · 68d ago [ Removed by Reddit ] cybersecurity · 68d ago [ Removed by Reddit ] cybersecurity · 68d ago “Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?” For [Blue|Purple] Teams in Cyber Defence · 68d ago Phishing simulation platform cybersecurity · 68d ago 1-Click GitHub Token Stealing via a VSCode Bug Technical Information Security Content & Discussion · 68d ago Just task about OSI model cybersecurity · 68d ago FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential The Last Watchdog · 68d ago Need help improving DNS Spy from a security tool angle cybersecurity · 68d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild cybersecurity · 68d ago Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild Technical Information Security Content & Discussion · 68d ago Oracle's first monthly patch update just dropped 77 CVEs. cybersecurity · 68d ago Cleaning up after a legacy service account breach. How are you handling automated secrets discovery? cybersecurity · 68d ago Airbus digital apprenticeship cybersecurity · 68d ago Built a decompiler for exotic legacy programming language opentext Gupta Team Developer Reverse Engineering · 68d ago Always-On Red Teams hacking: security in practice · 68d ago Anthropic expanding access to Project Glasswing CyberScoop · 68d ago Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities cybersecurity · 68d ago [An RX Global Event] Infosecurity Europe darkreading · 68d ago Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit Cyber Defense Magazine · 68d ago This is a scam and probably a malware/trojan. Path Of Exile 2 builder ... Malware Analysis & Reports · 68d ago Google fixes one actively exploited Android zero-day, 124 flaws cybersecurity · 68d ago Wardriving assessment across Mexico: Preparing for the 2026 World Cup Securelist · 68d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 68d ago CISA and Partners Urge Hardening Automatic Tank Gauge Systems All CISA Advisories · 68d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 68d ago Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force cybersecurity · 68d ago Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis? cybersecurity · 68d ago Security Architects who who actively use modelling - What's your approach? cybersecurity · 68d ago PAN-OS authentication bypass bug added to list of exploited vulnerabilities cybersecurity · 68d ago I have extreme anxiety about being hacked cybersecurity · 68d ago Fresher cybersecurity · 68d ago Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif For [Blue|Purple] Teams in Cyber Defence · 68d ago Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand For [Blue|Purple] Teams in Cyber Defence · 68d ago Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach cybersecurity · 68d ago Career advice needed! cybersecurity · 68d ago LLMShare: using shared chatbot pages to distribute malware Malware Analysis & Reports · 68d ago GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure cybersecurity · 68d ago Google sr. security engineer interview cybersecurity · 68d ago Is offensive AI actually changing cybersecurity, or are we overestimating the impact? cybersecurity · 68d ago Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave cybersecurity · 68d ago is emerald chat safe? cybersecurity · 68d ago Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm For [Blue|Purple] Teams in Cyber Defence · 68d ago Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ? cybersecurity · 69d ago ClickJack in the wild cybersecurity · 69d ago NuGet Code Execution As A Service Technical Information Security Content & Discussion · 69d ago Thoughts on A.I assisted Malware Analysis? cybersecurity · 69d ago 19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access cybersecurity · 69d ago What articles do you use for cybersecurity news? (2026) cybersecurity · 69d ago Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider? cybersecurity · 69d ago Roadmap and Training Recommodation cybersecurity · 69d ago Attackers are exploiting Palo Alto Networks defect that initially flew under the radar CyberScoop · 69d ago I managed to pull the full system prompt for Meta's Support AI hacking: security in practice · 69d ago Les anti-triche de niveau noyau et leur risque de sécurité cybersecurity · 69d ago Harassing text messages hacking: security in practice · 69d ago Asked to Send Sensitive Documents via MMS cybersecurity · 69d ago SC-200 compared to CC (isc2) cybersecurity · 69d ago running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it! Reverse Engineering · 69d ago Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB) Technical Information Security Content & Discussion · 69d ago Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now cybersecurity · 69d ago Looking to move off KB4, what are people actually using these days? cybersecurity · 69d ago Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight CyberScoop · 69d ago Got my Security+. What's next? cybersecurity · 69d ago Vulnerability Summary for the Week of May 25, 2026 cybersecurity · 69d ago RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation For [Blue|Purple] Teams in Cyber Defence · 69d ago Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages For [Blue|Purple] Teams in Cyber Defence · 69d ago Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches For [Blue|Purple] Teams in Cyber Defence · 69d ago REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY! hacking: security in practice · 69d ago Malware cybersecurity · 69d ago Alternative Search Engine to Utilize in 2026? cybersecurity · 69d ago Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked cybersecurity · 69d ago Miasma: Supply Chain Attack Targeting RedHat npm Packages For [Blue|Purple] Teams in Cyber Defence · 69d ago USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order CyberScoop · 69d ago Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild cybersecurity · 69d ago Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers cybersecurity · 69d ago Hacking Palo Alto Networks' GlobalProtect VPN with AI hacking: security in practice · 69d ago AI compliance cybersecurity · 69d ago Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm cybersecurity · 69d ago Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains? cybersecurity · 69d ago MacBook or Windows Laptop for Cybersecurity cybersecurity · 69d ago What's the most creative MFA bypass you've seen? cybersecurity · 69d ago @redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers For [Blue|Purple] Teams in Cyber Defence · 69d ago Research Notes from Building a Windows Event Log Hunting Workflow cybersecurity · 69d ago Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am. hacking: security in practice · 69d ago How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ?? cybersecurity · 69d ago Free AI tools for TPRM? cybersecurity · 69d ago incomplete phone number from togo, need help reporting to police cybersecurity · 69d ago NPM packages from RedHat Compromised cybersecurity · 69d ago Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts cybersecurity · 69d ago SOC Analyst working towards Threat Intelligence cybersecurity · 69d ago Is XSS possible through PDFs? cybersecurity · 69d ago Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider Technical Information Security Content & Discussion · 69d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 69d ago The Next AI Governance Failure Won’t Be the Model cybersecurity · 69d ago Poisoning Claude Code: One GitHub Issue to Break the Supply Chain Technical Information Security Content & Discussion · 69d ago Microsoft MFA Is Down Again cybersecurity · 69d ago Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927) cybersecurity · 69d ago How I Found My First $3,000 AI Vulnerability NahamSec · 69d ago Stealing Passwords via HTML Injection Under a Strict CSP Technical Information Security Content & Discussion · 69d ago Computer logic or Science cybersecurity · 69d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 69d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 69d ago I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for? cybersecurity · 69d ago What C2s Are You Using cybersecurity · 69d ago Best AI LLM for Hacking related stuff hacking: security in practice · 69d ago PNPT Exam cybersecurity · 69d ago Containers on fire: from container escapes to supply chain attacks Securelist · 69d ago Election threats are focused on campaign systems, not voting machines CyberScoop · 69d ago What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification? cybersecurity · 69d ago Feels like most people ignore the wireless layer until it bites them hacking: security in practice · 69d ago Any appsec engineer working in fortune 500? cybersecurity · 69d ago I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next cybersecurity · 69d ago Anyone transition from AWS Data Center Operations to InfoSec? cybersecurity · 69d ago I think my account got hacked but it's weird cybersecurity · 69d ago Subnet discovery through multi-protocol TTL tracing Technical Information Security Content & Discussion · 69d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 69d ago current market for detecting deepfakes? cybersecurity · 69d ago OpenClaw: risks for agent users and how to mitigate them Securelist · 69d ago Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched For [Blue|Purple] Teams in Cyber Defence · 69d ago Worried about friend being doxxed on doxbin cybersecurity · 69d ago Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks For [Blue|Purple] Teams in Cyber Defence · 69d ago Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries For [Blue|Purple] Teams in Cyber Defence · 69d ago how to shift from a service based company to a product based one in cybersecurity ? cybersecurity · 69d ago Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA cybersecurity · 69d ago Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking? hacking: security in practice · 69d ago Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign For [Blue|Purple] Teams in Cyber Defence · 69d ago Claude AI user data directory exfiltration via malicious npm package cybersecurity · 70d ago Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from? Reverse Engineering · 70d ago Bitdefender blocking amd stuff? False positive or? cybersecurity · 70d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 70d ago Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet Trend Micro Research, News, Perspectives · 70d ago did they have my password?? what triggers this specific email??? instagram HELP. cybersecurity · 70d ago How to Unpack FlawedAmmyy - Malware Unpacking Tutorial Malware Analysis & Reports · 70d ago ATTENTION: Dashlane may have been breached. (Password manager). cybersecurity · 70d ago Can anyone figure out how to retrieve the recovery key in signal app? hacking: security in practice · 70d ago Norton blocked a “malicious script”? cybersecurity · 70d ago Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts cybersecurity · 70d ago Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive. cybersecurity · 70d ago I wrote about the 5 biggest threats in 2026, curious what this community thinks. cybersecurity · 70d ago MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce? cybersecurity · 70d ago Atomdrift - open-source malware detection for the software supply chain For [Blue|Purple] Teams in Cyber Defence · 70d ago Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions? cybersecurity · 70d ago NetworkChuck cybersecurity · 70d ago LLM for creating phishing tool cybersecurity · 70d ago Why are we still treating IAM like a compliance checkbox? cybersecurity · 70d ago Polyfill pop up? cybersecurity · 70d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Technical Information Security Content & Discussion · 70d ago Building A Malware Lab From Scratch! Malware Analysis & Reports · 70d ago ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding Reverse Engineering · 70d ago SecAI+ difficulty question cybersecurity · 70d ago $730k+ raised on Proxmark5 with 2150 backers hacking: security in practice · 70d ago Could you guys give an honest feedback to a completely automated ssrf attack tool? cybersecurity · 70d ago tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me cybersecurity · 70d ago Microsoft Joined the DMARC Club cybersecurity · 70d ago Help. cybersecurity · 70d ago Vibe Coding Security cybersecurity · 70d ago I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works) hacking: security in practice · 70d ago Looking for a Company to Partner With cybersecurity · 70d ago Best reporting tools? cybersecurity · 70d ago What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months) cybersecurity · 70d ago Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens For [Blue|Purple] Teams in Cyber Defence · 70d ago How Can Polyfill.io Still Act Maliciously? cybersecurity · 70d ago 179 npm Packages Target Cloud and Finance via oob.moika.tech For [Blue|Purple] Teams in Cyber Defence · 70d ago KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4 For [Blue|Purple] Teams in Cyber Defence · 70d ago Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs For [Blue|Purple] Teams in Cyber Defence · 70d ago Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services For [Blue|Purple] Teams in Cyber Defence · 70d ago TinyLoad v7 - what i added :D (in memory protection using VEH and alot more) Reverse Engineering · 70d ago EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA For [Blue|Purple] Teams in Cyber Defence · 70d ago Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace For [Blue|Purple] Teams in Cyber Defence · 70d ago Signal macOS Desktop App Doesn't Actually Delete Messages When it Should For [Blue|Purple] Teams in Cyber Defence · 70d ago Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan For [Blue|Purple] Teams in Cyber Defence · 70d ago WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD For [Blue|Purple] Teams in Cyber Defence · 70d ago Any idea who's behind this hack? How to resolve it? hacking: security in practice · 70d ago Typosquatted npm packages used to steal cloud and CI/CD secrets For [Blue|Purple] Teams in Cyber Defence · 70d ago Need THM voucher code for cheap? Any known seller? cybersecurity · 70d ago Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2 For [Blue|Purple] Teams in Cyber Defence · 70d ago Malicious npm packages abuse dependency confusion to profile developer environments For [Blue|Purple] Teams in Cyber Defence · 70d ago Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257) For [Blue|Purple] Teams in Cyber Defence · 70d ago Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack For [Blue|Purple] Teams in Cyber Defence · 70d ago CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied." For [Blue|Purple] Teams in Cyber Defence · 70d ago Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign For [Blue|Purple] Teams in Cyber Defence · 70d ago SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks. For [Blue|Purple] Teams in Cyber Defence · 70d ago EDR Incident Response Playbook: Containing Local Account Incidents For [Blue|Purple] Teams in Cyber Defence · 70d ago Adversarial Oracles: LLM-Guided EDR Signature Reduction For [Blue|Purple] Teams in Cyber Defence · 70d ago One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF For [Blue|Purple] Teams in Cyber Defence · 70d ago proxy: A lightweight caching proxy for package registries. For [Blue|Purple] Teams in Cyber Defence · 70d ago How OLTs may have exposed entire ISP networks For [Blue|Purple] Teams in Cyber Defence · 70d ago Ghost passwords? cybersecurity · 70d ago Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it hacking: security in practice · 70d ago A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years For [Blue|Purple] Teams in Cyber Defence · 70d ago HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics For [Blue|Purple] Teams in Cyber Defence · 70d ago Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots For [Blue|Purple] Teams in Cyber Defence · 70d ago Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures For [Blue|Purple] Teams in Cyber Defence · 70d ago Lessons from Penetration Tests on Large-Scale Agent Systems For [Blue|Purple] Teams in Cyber Defence · 70d ago pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter. For [Blue|Purple] Teams in Cyber Defence · 70d ago [ Removed by Reddit ] Reverse Engineering · 70d ago Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not. cybersecurity · 70d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 71d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions Technical Information Security Content & Discussion · 71d ago LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions cybersecurity · 71d ago Anyone else having Chatgpt Strikes / Violations while learning cybersecurity? cybersecurity · 71d ago Blue Team tips? hacking: security in practice · 71d ago Working at Cisco, worth it? cybersecurity · 71d ago Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice cybersecurity · 71d ago usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer) Reverse Engineering · 71d ago CIFSwitch: a non-universal Linux local root vulnerability For [Blue|Purple] Teams in Cyber Defence · 71d ago Are you pen testing AI Agents? cybersecurity · 71d ago Question of android malware cybersecurity · 71d ago External attack surface: how are you correlating DNS, SSL, and IP reputation today? cybersecurity · 71d ago edit certified pdf hacking: security in practice · 71d ago how do i properly setup 2fa and bitwarden? cybersecurity · 71d ago Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC) cybersecurity · 71d ago i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested? cybersecurity · 71d ago Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever? cybersecurity · 71d ago I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux) Reverse Engineering · 71d ago Can Steam Cloud Files Transfer Malware cybersecurity · 71d ago I bought an old phone from 2018 and wanna destroy it with viruses for fun Malware Analysis & Reports · 71d ago HackTheBox - Interpreter IppSec · 71d ago Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension For [Blue|Purple] Teams in Cyber Defence · 71d ago Questions for the cloud security engineers cybersecurity · 71d ago DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database. For [Blue|Purple] Teams in Cyber Defence · 71d ago Visual Studio Extensions Revisited For [Blue|Purple] Teams in Cyber Defence · 71d ago Thoughts on this as a starter and doing bug bounty on the side cybersecurity · 71d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 71d ago How are new SC-200 candidates practicing labs without an E5 Developer tenant? cybersecurity · 71d ago Everyday hacking in our lives - transportation, work, finances, goods etc hacking: security in practice · 71d ago Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters Technical Information Security Content & Discussion · 71d ago Getting OTP spammed from every app and website I've ever used. Should I be worried? cybersecurity · 71d ago BYOVD and Looting LSASS in the Modern EDR Era For [Blue|Purple] Teams in Cyber Defence · 71d ago A browser tool for checking contractor insurance certificates cybersecurity · 71d ago Am I getting screwed? cybersecurity · 71d ago SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers cybersecurity · 71d ago PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29} cybersecurity · 71d ago CTO at NCSC Summary: week ending May 31st cybersecurity · 71d ago CTO at NCSC Summary: week ending May 31st For [Blue|Purple] Teams in Cyber Defence · 71d ago BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship cybersecurity · 71d ago OffensiveCon26 videos For [Blue|Purple] Teams in Cyber Defence · 71d ago Need suggestion cybersecurity · 71d ago Malware escaped browser without downloading files, then escaped a virtual machine Malware Analysis & Reports · 72d ago [INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety) cybersecurity · 72d ago Was Dave Bittner interviewing an AI? cybersecurity · 72d ago CTF for complete beginner cybersecurity · 72d ago Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques? cybersecurity · 72d ago First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security Reverse Engineering · 72d ago AI-Era Cyber Risk Standards cybersecurity · 72d ago BEC Victim - Attacker replied inside a real email thread using a lookalike domain cybersecurity · 72d ago School Survey, (non-paid nothing its free its for my grades) For [Blue|Purple] Teams in Cyber Defence · 72d ago Question for those who transitioned from remote to work from anywhere cybersecurity · 72d ago Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors cybersecurity · 72d ago Do you enjoy what you do or do you wish you could go back in time and change it? cybersecurity · 72d ago Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber? cybersecurity · 72d ago A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.) Technical Information Security Content & Discussion · 72d ago For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year? cybersecurity · 72d ago Name That Toon: Mark of (Cybersecurity) Progress darkreading · 72d ago Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ? cybersecurity · 72d ago Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years? cybersecurity · 72d ago Botnet of more than 17 million devices dismantled cybersecurity · 72d ago Exposed credentials on logs cybersecurity · 72d ago Do you think this is legit or has the website been compromised? hacking: security in practice · 72d ago Introducing Keyhog: The First GPU Accelerated secret scanner Technical Information Security Content & Discussion · 72d ago What do you think is the biggest cybersecurity risk for small businesses in 2026? cybersecurity · 72d ago Wanted to shift to cloud security, but have some questions cybersecurity · 72d ago OffensiveCon26 YouTube Playlist released Technical Information Security Content & Discussion · 72d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments For [Blue|Purple] Teams in Cyber Defence · 72d ago LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms For [Blue|Purple] Teams in Cyber Defence · 72d ago Tennessee man linked to 764 accused of series of crimes against children dating back to 2022 CyberScoop · 72d ago Zero Trust is Overrated? Navigating the Complexity cybersecurity · 72d ago Test API post with flair cybersecurity · 72d ago Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications cybersecurity · 72d ago How Do You Handle the Massive Amount of Information in the CPTS Path? cybersecurity · 72d ago Wanna learn cybersecurity & ethical hacking hacking: security in practice · 72d ago LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting For [Blue|Purple] Teams in Cyber Defence · 72d ago Help an upcoming cybersecurity engineer! cybersecurity · 72d ago Repeated Microsoft MFA attempts even after password change cybersecurity · 72d ago I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but Malware Analysis & Reports · 72d ago Do you guys take paper notes or digital ones during studying ? hacking: security in practice · 72d ago What Is Device Intelligence and How Does It Stop Fraud? cybersecurity · 72d ago [FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE) cybersecurity · 72d ago Federal audit reveals NIST’s NVD is plagued by poor planning and duplication CyberScoop · 72d ago Ghidra 12.1.1 has been released! Reverse Engineering · 72d ago IBM commits $5 billion to secure open-source software cybersecurity · 72d ago Structuring an AI-Assisted Pentesting Homelab for a Final Year Project cybersecurity · 72d ago Are teams actually monitoring LLM traffic in production environments? cybersecurity · 72d ago How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA) cybersecurity · 72d ago Raspberry pi cybersecurity · 72d ago Asia's Cyber Insurance Market Shows Signs of Life darkreading · 72d ago What is the biggest obstacle to using AI safely in a company? cybersecurity · 72d ago Advice going forward cybersecurity · 72d ago MCP Firewall help cybersecurity · 72d ago I wanted to shift to security but people told me the market is extremely bad, is that true? cybersecurity · 72d ago Best Personality Type/Traits for Working in Cyber Security cybersecurity · 72d ago Identifying attack patterns through kernel frame callstacks For [Blue|Purple] Teams in Cyber Defence · 72d ago A fake freelance job interview almost installed malware on my PC cybersecurity · 72d ago Is there a viable career path here or am I just being delusional? cybersecurity · 72d ago With Complex Cloud Integrations, Small Errors Lead to Major Compromises darkreading · 72d ago What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks cybersecurity · 72d ago Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness For [Blue|Purple] Teams in Cyber Defence · 72d ago 'The Com' Cyberattacks Support Violence & Sexploitation darkreading · 72d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 72d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 72d ago How do enterprises actually prevent developers from exfiltrating source code? cybersecurity · 72d ago I have a datastealer malware cybersecurity · 72d ago Dúvida de carreira. cybersecurity · 72d ago Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace cybersecurity · 72d ago Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated cybersecurity · 72d ago is SIEM really needed here ? cybersecurity · 72d ago Decompiled an app, found a bunch of secrets, what now? cybersecurity · 72d ago What safety boundary would you expect from a local AI incident investigation tool? For [Blue|Purple] Teams in Cyber Defence · 72d ago Can someone give me a correct method for learning reverse engineering? cybersecurity · 72d ago 1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog Technical Information Security Content & Discussion · 72d ago Authenticated RCE via Argument Injection in Gogs (NOT FIXED) For [Blue|Purple] Teams in Cyber Defence · 72d ago Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months cybersecurity · 72d ago GRC Advise cybersecurity · 72d ago [ Removed by Reddit ] cybersecurity · 72d ago Did something happen to haveibeenpwned? Any alternatives? cybersecurity · 72d ago I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found. Technical Information Security Content & Discussion · 72d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 72d ago This month in security with Tony Anscombe – May 2026 edition WeLiveSecurity · 72d ago How do people actually modify mobile games to increase their power? hacking: security in practice · 72d ago What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant Securelist · 72d ago Why I Built My Own LLM Benchmark for THOR Finding Triage For [Blue|Purple] Teams in Cyber Defence · 72d ago RAT SUSPECTED cybersecurity · 72d ago Casdoor contains multiple authentication bypass and access management vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 72d ago The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents For [Blue|Purple] Teams in Cyber Defence · 72d ago GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations For [Blue|Purple] Teams in Cyber Defence · 72d ago Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies For [Blue|Purple] Teams in Cyber Defence · 72d ago Malware seller hunted across three continents For [Blue|Purple] Teams in Cyber Defence · 72d ago Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims For [Blue|Purple] Teams in Cyber Defence · 72d ago Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers For [Blue|Purple] Teams in Cyber Defence · 72d ago Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network For [Blue|Purple] Teams in Cyber Defence · 72d ago How do people afford certificate s? cybersecurity · 72d ago I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed? cybersecurity · 72d ago Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint) Reverse Engineering · 72d ago Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. cybersecurity · 72d ago Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 72d ago Phone Forwarding cybersecurity · 72d ago Opinions on running Full Microsoft E5 Security Stack cybersecurity · 72d ago Claiming "XDR" cybersecurity · 72d ago Typosquatted npm packages used to steal cloud and CI/CD secrets cybersecurity · 72d ago Why Loyalty Programs Are Quietly Becoming a Security Blind Spot hacking: security in practice · 73d ago Fooling around with encrypted reasoning blobs Technical Information Security Content & Discussion · 73d ago CALIF: An AI audit of FreeBSD Technical Information Security Content & Discussion · 73d ago Microsoft security cybersecurity · 73d ago Need help regarding building a home lab cybersecurity · 73d ago Should I turn on passwordless accounts for all my Microsoft accounts? cybersecurity · 73d ago Transitioning from AWS Data Center Operations to Security Engineering cybersecurity · 73d ago CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries Technical Information Security Content & Discussion · 73d ago Probably the wrong place. cybersecurity · 73d ago What after IT helpdesk? cybersecurity · 73d ago As Global Powers Explore Humanoid Robots, Cyber-Risk Looms darkreading · 73d ago News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit The Last Watchdog · 73d ago Ajuda pessoal hacking: security in practice · 73d ago VMP 3.5+ Internal Architecture & Heap Dispatch Analysis Reverse Engineering · 73d ago How are you security-testing API changes before production without slowing CI/CD? cybersecurity · 73d ago Are we trusting update repos or are you all extra paranoid now as well? cybersecurity · 73d ago Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops cybersecurity · 73d ago Prevent supply chain attacks cybersecurity · 73d ago The C-suite job that's burning people out faster than any other For [Blue|Purple] Teams in Cyber Defence · 73d ago New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation For [Blue|Purple] Teams in Cyber Defence · 73d ago Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems cybersecurity · 73d ago SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer For [Blue|Purple] Teams in Cyber Defence · 73d ago FBI warns of fake FIFA websites running World Cup fraud schemes cybersecurity · 73d ago Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances For [Blue|Purple] Teams in Cyber Defence · 73d ago Hackers are trying to steal Signal users' backups in new wave of phishing attacks cybersecurity · 73d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN Technical Information Security Content & Discussion · 73d ago Samy Kamkar on building viruses, his arrest and privacy in the LLM era hacking: security in practice · 73d ago 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface For [Blue|Purple] Teams in Cyber Defence · 73d ago Visual Studio Extensions Revisited Technical Information Security Content & Discussion · 73d ago Dutch Raid Fails to Dent Russian Bulletproof Host darkreading · 73d ago APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026 For [Blue|Purple] Teams in Cyber Defence · 73d ago Incident Response Testing Preparation cybersecurity · 73d ago Introducing Microsoft 365 Business with Copilot: The new standard for small business Microsoft 365 Blog · 73d ago Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference cybersecurity · 73d ago House panel poised to hold hearing centered on AI impact on cyber CyberScoop · 73d ago [Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥 cybersecurity · 73d ago Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure For [Blue|Purple] Teams in Cyber Defence · 73d ago Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake For [Blue|Purple] Teams in Cyber Defence · 73d ago 3rd Party NFC cards.. secure? cybersecurity · 73d ago Vulnerability Management Tickets & SLA cybersecurity · 73d ago Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket CyberScoop · 73d ago Defending at Machine-Speed: Building AI Threat Readiness cybersecurity · 73d ago AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved cybersecurity · 73d ago HEAD request body processing leading cybersecurity · 73d ago Malicious npm Package Stole Files From Claude AI User Directory via GitHub cybersecurity · 73d ago Does anyone have an app like substack to keep being updated and engaging within the cyber domain? cybersecurity · 73d ago Zero Trust Implementation Guidelines For [Blue|Purple] Teams in Cyber Defence · 73d ago [ Removed by Reddit ] hacking: security in practice · 73d ago What’s an attack vector people massively underestimate in 2026? cybersecurity · 73d ago We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7 cybersecurity · 73d ago Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP) Technical Information Security Content & Discussion · 73d ago Is this considered a bug or something else entirely? hacking: security in practice · 73d ago Agentic AI Isn't Risky; the Way Orgs Deploy It Is darkreading · 73d ago A Deeper Look at GLASSWORM's Solana Variant Malware Analysis & Reports · 73d ago A Deeper Look at GLASSWORM's Solana Variant cybersecurity · 73d ago How 2004 RuneScape fit a multiplayer RPG into 56k dial-up Reverse Engineering · 73d ago Getting back deleted conversation from messanger hacking: security in practice · 73d ago Introducing a new design for Microsoft 365 Copilot Microsoft 365 Blog · 73d ago BlackToad: Network Manipulation in an AutoIt Payload For [Blue|Purple] Teams in Cyber Defence · 73d ago RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT For [Blue|Purple] Teams in Cyber Defence · 73d ago Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant For [Blue|Purple] Teams in Cyber Defence · 73d ago Calling Cyber Security Beginners cybersecurity · 73d ago Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE Technical Information Security Content & Discussion · 73d ago Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis cybersecurity · 73d ago Building Omegle for Exposed Webcams hacking: security in practice · 73d ago built something for ai agents, ended up looking a lot like classic appsec cybersecurity · 73d ago Is Gophish still usable in 2026? cybersecurity · 73d ago Microsoft vs Chaotic Eclipse: three zero-days now actively exploited cybersecurity · 73d ago what do you think cybersecurity · 73d ago Why would be clicking a website, redirect me? cybersecurity · 73d ago Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit For [Blue|Purple] Teams in Cyber Defence · 73d ago Zapier fixes bug chain that researchers say risked widespread account takeover cybersecurity · 73d ago AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career? hacking: security in practice · 73d ago Writing cybersecurity policies is a waste of time cybersecurity · 73d ago Zapier fixes bug chain that researchers say risked widespread account takeover CyberScoop · 73d ago The GitHub Leak Situation Just Got Worse | Threat Wire Hak5 · 73d ago reverse engineering need for speed most wanted for modding sdk Reverse Engineering · 73d ago Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security darkreading · 73d ago Raising the Cybersecurity Stakes: Ante up for the Agentic Era. cybersecurity · 73d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories Alerts · 73d ago ABB EIBPORT All CISA Advisories · 73d ago Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter All CISA Advisories · 73d ago ABB Busch-Welcome 2 Wire Door Opener Actuator All CISA Advisories · 73d ago Fourth Frontier Frontier X Mobile Application, Frontier X2 All CISA Advisories · 73d ago CP Plus 8 Ch. Network Video Recorder All CISA Advisories · 73d ago XCharge C6 All CISA Advisories · 73d ago KMW CCTV Security Cameras All CISA Advisories · 73d ago MacGregor Voyage Data Recorder (VDR) G4e All CISA Advisories · 73d ago Schnieider Electric EcoStruxure Machine Expert HVAC All CISA Advisories · 73d ago Supply Chain Compromises Impact Nx Console and GitHub Repositories All CISA Advisories · 73d ago Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it. cybersecurity · 73d ago [ Removed by Reddit ] cybersecurity · 73d ago Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15 Malware Analysis & Reports · 73d ago Released: Dataforge Honeypot cybersecurity · 73d ago Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks cybersecurity · 73d ago CEH-free cybersecurity · 73d ago Hottest cybersecurity open-source tools of the month: May 2026 cybersecurity · 73d ago Preparation tips for CPENT cybersecurity · 73d ago BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model darkreading · 73d ago FROST: Fingerprinting Remotely using OPFS-based SSD Timing For [Blue|Purple] Teams in Cyber Defence · 73d ago How do you handle AI tools in your organization? cybersecurity · 73d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 73d ago ESET APT Activity Report Q4 2025–Q1 2026 WeLiveSecurity · 73d ago What scanners are actually trying against AI infrastructure Technical Information Security Content & Discussion · 73d ago I think i got scammed anybody can help me with that cybersecurity · 73d ago Nordic CISOs Handle Rising Cyber Threats Remarkably Well darkreading · 73d ago Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years Securelist · 73d ago New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo cybersecurity · 73d ago Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup For [Blue|Purple] Teams in Cyber Defence · 73d ago Is it safe to have passwords copied to clipboard on IOS temporarily? cybersecurity · 73d ago Developers working on anti-fraud systems deserve more credit cybersecurity · 73d ago Real Folks of Cyber | Dan Berger | Day in the Life The Cyber Mentors · 73d ago My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst cybersecurity · 73d ago GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs. Reverse Engineering · 74d ago Security awareness training for AI heavy smb workflows? cybersecurity · 74d ago puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations. For [Blue|Purple] Teams in Cyber Defence · 74d ago Defense by accumulation Technical Information Security Content & Discussion · 74d ago Minimum Requirements for Helpdesk Role ? cybersecurity · 74d ago Reddit spear phishing cybersecurity · 74d ago Winbox server/client reverse engineered is opensource Reverse Engineering · 74d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ cybersecurity · 74d ago What to do cybersecurity · 74d ago What resources would you recommend for studying cysa+ cybersecurity · 74d ago Provenance of Data cybersecurity · 74d ago 5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain hacking: security in practice · 74d ago Websites have a new way to spy on visitors: analyzing their SSD activity cybersecurity · 74d ago 12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal? cybersecurity · 74d ago OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms CyberScoop · 74d ago Russian Art Teacher - Hinder Security Clearance? cybersecurity · 74d ago Ransomware Actors Show Up In Person to Steal Law Firm Data darkreading · 74d ago FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person CyberScoop · 74d ago Who is Salt Typhoon Really? Unraveling the Attribution Challenge For [Blue|Purple] Teams in Cyber Defence · 74d ago EDR/MDR Vendor Questions cybersecurity · 74d ago Cybersecurity as a Highschooler? cybersecurity · 74d ago New department created, would love your input cybersecurity · 74d ago What are the dangers of posting? hacking: security in practice · 74d ago OWASP Vienna - anyone going? cybersecurity · 74d ago Interview with Upstart cybersecurity · 74d ago 18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber. cybersecurity · 74d ago Is cloud security engineer viable with my current position? cybersecurity · 74d ago UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace CyberScoop · 74d ago Cloudflare Access users: what would actually make JIT useful for you? cybersecurity · 74d ago Looking for resources on end-to-end APT attack flow summaries for detection engineering For [Blue|Purple] Teams in Cyber Defence · 74d ago Kali365 Activity Surges: Device Code Phishing Is Scaling Fast Malware Analysis & Reports · 74d ago eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels cybersecurity · 74d ago The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire For [Blue|Purple] Teams in Cyber Defence · 74d ago Questions regarding Ubuntu 24 LTS hardening cybersecurity · 74d ago Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho. cybersecurity · 74d ago Honest question about OT Security Engineer work life in India cybersecurity · 74d ago Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning) cybersecurity · 74d ago AI Security cybersecurity · 74d ago Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor cybersecurity · 74d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP For [Blue|Purple] Teams in Cyber Defence · 74d ago 🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents cybersecurity · 74d ago Latin American Cybercriminals Hoover Up Government Data darkreading · 74d ago Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint For [Blue|Purple] Teams in Cyber Defence · 74d ago AI-Assisted Exploit Development Outpaces Scanner Detection darkreading · 74d ago Building Detection Engineering on AWS from scratch — roast my plan cybersecurity · 74d ago Building Detection Engineering on AWS from scratch — roast my plan For [Blue|Purple] Teams in Cyber Defence · 74d ago New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault Technical Information Security Content & Discussion · 74d ago Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance cybersecurity · 74d ago Flipper Zero Users, What's Your Take? hacking: security in practice · 74d ago Large company with a bit of an issue free stuff hacking: security in practice · 74d ago I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA. cybersecurity · 74d ago Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning cybersecurity · 74d ago Final Year Project: Looking for non-generic IAM project ideas that solve real problems cybersecurity · 74d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Technical Information Security Content & Discussion · 74d ago GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled. cybersecurity · 74d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware For [Blue|Purple] Teams in Cyber Defence · 74d ago Breaking out of IT Helpdesk - how? cybersecurity · 74d ago A year in Cybersecurity — Where Do I Go From Here? cybersecurity · 74d ago MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware cybersecurity · 74d ago MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware Malware Analysis & Reports · 74d ago 22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber cybersecurity · 74d ago FBI: Silent Ransom Group Turns to IT Support Ploy cybersecurity · 74d ago A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate Technical Information Security Content & Discussion · 74d ago How do machine builders track Siemens/Rockwell security advisories? cybersecurity · 74d ago CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain CyberScoop · 74d ago GlassWorm Developer Supply-Chain Botnet Takedown cybersecurity · 74d ago The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN cybersecurity · 74d ago Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV cybersecurity · 74d ago (URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active Reverse Engineering · 74d ago Got cybersec work what next ? cybersecurity · 74d ago Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables cybersecurity · 74d ago Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers cybersecurity · 74d ago HN Security - AI Reporter - Let's automate reporting in Burp Suite! Technical Information Security Content & Discussion · 74d ago Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing? cybersecurity · 74d ago GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP) cybersecurity · 74d ago nightmare eclipse is probably French here is why cybersecurity · 74d ago Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines cybersecurity · 74d ago Measuring performance of JA4/JA4H AI Model cybersecurity · 74d ago Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security darkreading · 74d ago What things are you really focused on this year? cybersecurity · 74d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog Alerts · 74d ago CISA Adds Three Known Exploited Vulnerabilities to Catalog All CISA Advisories · 74d ago Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io) Malware Analysis & Reports · 74d ago Designing secure access with ZTNA For [Blue|Purple] Teams in Cyber Defence · 74d ago Hypothetical EDR spoofer Reverse Engineering · 74d ago Hypothetical EDR spoofer cybersecurity · 74d ago ISO 27001 Audit Stage 1 cybersecurity · 74d ago Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records Technical Information Security Content & Discussion · 74d ago Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That. cybersecurity · 74d ago What to consider before asking an AI chatbot for health advice WeLiveSecurity · 74d ago Looking for Hacker Friends to Learn☺️ cybersecurity · 74d ago Comptes Instagram et Facebook piratés et désactivés cybersecurity · 74d ago RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact Technical Information Security Content & Discussion · 74d ago How to safely disinfect a USB stick from potential malware files? cybersecurity · 74d ago Champion ethical hacker warns AI tools like Mythos will make competing harder. hacking: security in practice · 74d ago MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response For [Blue|Purple] Teams in Cyber Defence · 74d ago White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats For [Blue|Purple] Teams in Cyber Defence · 74d ago Advisory X41-2026-002: Request Host Header not Validated in Starlette For [Blue|Purple] Teams in Cyber Defence · 74d ago Top ethical hacker Chompie warns AI tools could put her out of business For [Blue|Purple] Teams in Cyber Defence · 74d ago 浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents For [Blue|Purple] Teams in Cyber Defence · 74d ago Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker. hacking: security in practice · 74d ago YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions For [Blue|Purple] Teams in Cyber Defence · 74d ago CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state For [Blue|Purple] Teams in Cyber Defence · 74d ago The Evolution of Chinese-language Phishing Services For [Blue|Purple] Teams in Cyber Defence · 74d ago Silent Ransom Group Impersonating IT Personnel through Social Engineering For [Blue|Purple] Teams in Cyber Defence · 74d ago Is anyone else concerned about how quickly AI is outpacing cloud security? cybersecurity · 74d ago The epoll UAF - an epoll uaf race in fs/eventpoll.c For [Blue|Purple] Teams in Cyber Defence · 74d ago Tycoon 2FA AiTM detection for Entra ID and Google For [Blue|Purple] Teams in Cyber Defence · 74d ago Microsoft Copilot Cowork Exfiltrates Files For [Blue|Purple] Teams in Cyber Defence · 74d ago What's a CyberSecurity job like? cybersecurity · 75d ago Microsoft Live credential stuffing cybersecurity · 75d ago I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this? cybersecurity · 75d ago Security architects- summarize your responsibilities and role cybersecurity · 75d ago Finding Work in OSINT cybersecurity · 75d ago State of SDLC Security 2026 cybersecurity · 75d ago Reported to police for coding html cybersecurity · 75d ago there's a toll in the hall now hacking: security in practice · 75d ago I Reverse Engineered Need for Speed Most Wanted Server Reverse Engineering · 75d ago Am I crazy or is something off about this Google OAuth login via Calendly hacking: security in practice · 75d ago [Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling) cybersecurity · 75d ago I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project cybersecurity · 75d ago Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover cybersecurity · 75d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators? cybersecurity · 75d ago KnowledgeDeliver flaw exploited as a zero-day to install web shells cybersecurity · 75d ago GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet The Last Watchdog · 75d ago Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos darkreading · 75d ago Apple open-sources quantum-resistant encryption code CyberScoop · 75d ago Breaking GROK'S DEFENSES to make it HACK Real Public Websites cybersecurity · 75d ago GitHub Actions Cache Poisoning is eating open source cybersecurity · 75d ago State Cyber Leaders Push Congress for More Funding, Support darkreading · 75d ago Nightmare-Eclipse has also been banned on GitLab :DD cybersecurity · 75d ago Shai-Hulud Hackers TeamPCP: Lucky or Skilled? darkreading · 75d ago For Enterprises, Security Remains Agentic AI's Biggest Challenge darkreading · 75d ago Do we still have time before we are in the Age of the movie "Minority Report"? ↓ cybersecurity · 75d ago SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file cybersecurity · 75d ago Unpatched Sparx vulnerabilties For [Blue|Purple] Teams in Cyber Defence · 75d ago What Software Supply Chain, Water Filters, and Power Grids Have in Common cybersecurity · 75d ago QA engineer trying to move into AppSec — does this plan hold up? cybersecurity · 75d ago Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down. Malware Analysis & Reports · 75d ago Is work from anywhere really impossible to find?? cybersecurity · 75d ago Navigating Lax Load Balancers: When an Intersection Gets You Inside Technical Information Security Content & Discussion · 75d ago New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences Microsoft 365 Blog · 75d ago Cybersecurity statistics of the week (May 18th - May 24th) cybersecurity · 75d ago Engineering a Post Quantum Fortress Inside the Citadel Archite cybersecurity · 75d ago Cyber Security Analyst cybersecurity · 75d ago Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance cybersecurity · 75d ago Two layer email security tool thesis cybersecurity · 75d ago Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents Technical Information Security Content & Discussion · 75d ago sylvia: iOS Syscall Explorer for IDA 9.X For [Blue|Purple] Teams in Cyber Defence · 75d ago Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation Reverse Engineering · 75d ago OTP lockout state leaked valid-code signal, enabling OLX account takeover Technical Information Security Content & Discussion · 75d ago When OTP rate limiting fails: OLX account takeover with persistent sessions cybersecurity · 75d ago When “try again later” still tells you the OTP was correct: an account takeover story. hacking: security in practice · 75d ago Entra ID sessions revoke cybersecurity · 75d ago Anyone who attended GPCSSI before? Need some clarification cybersecurity · 75d ago Lost on my career path. cybersecurity · 75d ago How journalists rely on VPNs to protect press freedom Technical Information Security Content & Discussion · 75d ago EU-based folks: external pentest vs mandatory data/security training? cybersecurity · 75d ago help needed from experienced people cybersecurity · 75d ago How do you evaluate whether a privacy service is actually privacy-respecting? cybersecurity · 75d ago Which one Intellipaat or coursera which one to choose cybersecurity · 75d ago How random program can cause most of antiviruses close himself without telling himself to close Malware Analysis & Reports · 75d ago Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching Reverse Engineering · 75d ago ShadowCat: Universal optical file transfer, single html file, browser to camera hacking: security in practice · 75d ago Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1) Technical Information Security Content & Discussion · 75d ago CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks cybersecurity · 75d ago India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic? cybersecurity · 75d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 75d ago ABB Terra AC All CISA Advisories · 75d ago ABB LVS MConfig All CISA Advisories · 75d ago ABB Ability Camera Connect All CISA Advisories · 75d ago Eppendorf BioFlo 320 All CISA Advisories · 75d ago ABB AbilityTM Zenon Remote Transport Vulnerability All CISA Advisories · 75d ago ABB AC500 V2 All CISA Advisories · 75d ago ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM) All CISA Advisories · 75d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 75d ago Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs. cybersecurity · 75d ago Did anyone pass the SC-200 certificate recently? cybersecurity · 75d ago Honeypot cybersecurity · 75d ago passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account cybersecurity · 75d ago Career in IAM as a fresher cybersecurity · 75d ago CISA orders feds to patch actively exploited Drupal vulnerability cybersecurity · 75d ago Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure cybersecurity · 75d ago GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered” cybersecurity · 75d ago Cyber security tool cybersecurity · 75d ago Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East For [Blue|Purple] Teams in Cyber Defence · 75d ago GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip For [Blue|Purple] Teams in Cyber Defence · 75d ago JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign For [Blue|Purple] Teams in Cyber Defence · 75d ago Saw this tool and it has potential cybersecurity · 75d ago 🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs cybersecurity · 75d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack For [Blue|Purple] Teams in Cyber Defence · 75d ago How I Tried to Parse a Replay from Dawn of War: Definitive Edition Reverse Engineering · 75d ago 7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files cybersecurity · 75d ago Follow up : showing Claude install random pacakage in its vm instance without asking or prompting cybersecurity · 75d ago BTMOB: A stealthy RAT burrowing deep into Android devices WeLiveSecurity · 75d ago Update Starlette Now. New severe vulnerability dropped. Technical Information Security Content & Discussion · 75d ago Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@" For [Blue|Purple] Teams in Cyber Defence · 75d ago The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization For [Blue|Purple] Teams in Cyber Defence · 75d ago ¿Is safe? cybersecurity · 75d ago Need help cybersecurity · 75d ago What is the best tool for masking in kali cybersecurity · 75d ago What are the best tools other than ghostTracker? cybersecurity · 75d ago y2jb un able to enject payloads hacking: security in practice · 76d ago TrapDoor Cross-Ecosystem Crypto Stealer Campaign cybersecurity · 76d ago Follow up : Steal Your Files Claude AI installing package because internet say so cybersecurity · 76d ago New to Cybersecurity: Looking for general advice & help with Nmap cybersecurity · 76d ago GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP. For [Blue|Purple] Teams in Cyber Defence · 76d ago Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal cybersecurity · 76d ago Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated. hacking: security in practice · 76d ago Looking for tech role references cybersecurity · 76d ago Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet Trend Micro Research, News, Perspectives · 76d ago How do you balance Paw? cybersecurity · 76d ago I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity. cybersecurity · 76d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Malware Analysis & Reports · 76d ago The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire Technical Information Security Content & Discussion · 76d ago Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability For [Blue|Purple] Teams in Cyber Defence · 76d ago From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security cybersecurity · 76d ago Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February cybersecurity · 76d ago What Companies are Legit? cybersecurity · 76d ago start learning cybersecurity from scratch cybersecurity · 76d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 76d ago Follow-up: measuring LLM-agent failures with replay evidence cybersecurity · 76d ago WhatsApp users on alert after hacker drops massive dataset cybersecurity · 76d ago 17 years old going into CS — what certs should I start going after now? cybersecurity · 76d ago CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700. For [Blue|Purple] Teams in Cyber Defence · 76d ago i want to hire an osint expert cybersecurity · 76d ago Open University pros/cons cybersecurity · 76d ago How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection? cybersecurity · 76d ago Career in IAM as a fresher cybersecurity · 76d ago Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo cybersecurity · 76d ago Need Advice cybersecurity · 76d ago Why did Hack Forums lose popularity? hacking: security in practice · 76d ago Nocturne - A bin2bin code virtualizer for x86-64 PE binaries Reverse Engineering · 76d ago Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all? cybersecurity · 76d ago Someone from Germany on iOS keeps trying to login to my MSFT account cybersecurity · 76d ago AI cautionary tale... cybersecurity · 76d ago [Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing Reverse Engineering · 76d ago AI powered red vs blue teaming cybersecurity · 76d ago Starting a security analyst student apprenticeship next week, need advice cybersecurity · 76d ago Why CVE Does Not Work for AI Agents, but AVE? cybersecurity · 76d ago SC-200 or Security+ — which actually helps land a security title cybersecurity · 76d ago How about AI having access to your hard drive. cybersecurity · 76d ago How a Date Tag Hijacks macOS via ExifTool cybersecurity · 76d ago Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools cybersecurity · 76d ago Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing Reverse Engineering · 76d ago How credential brokering prevents AI agents from compromising credentials via prompt injection Technical Information Security Content & Discussion · 76d ago How credential brokering prevents AI agents from compromising credentials via prompt injection cybersecurity · 76d ago Built a tiny daily cyber puzzle game during evenings/weekends cybersecurity · 76d ago Crypto4A launches quantum-safe rival to AWS Secrets Manager cybersecurity · 76d ago CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth Technical Information Security Content & Discussion · 76d ago ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why. cybersecurity · 76d ago Cyber Sec project cybersecurity · 76d ago ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise hacking: security in practice · 76d ago CySA+ cybersecurity · 76d ago Anyone tried Morgancyberhelp ? cybersecurity · 76d ago As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free cybersecurity · 76d ago YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos For [Blue|Purple] Teams in Cyber Defence · 76d ago Why are most of the dfir tools built to be used in windows cybersecurity · 76d ago OnlyFans mega leak reveals 340M user records, hackers claim cybersecurity · 76d ago Perplexity BumbleBee cybersecurity · 76d ago Cisco patches critical 10.0 flaw in Secure Workload APIs cybersecurity · 76d ago Suspicious ass website asking to run a terminal command (MacOS) Malware Analysis & Reports · 76d ago Shellcide: A shellcode IDE hacking: security in practice · 76d ago Stalker has my phonenumber cybersecurity · 76d ago I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built Reverse Engineering · 76d ago Need some guidance cybersecurity · 76d ago Are you currently allocating budget to services that remove executive PII from B2B data brokers? cybersecurity · 76d ago Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal Technical Information Security Content & Discussion · 76d ago About CEHv13 book cybersecurity · 76d ago delimiter-less string obfuscation powered by compile-time AES Reverse Engineering · 76d ago Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it For [Blue|Purple] Teams in Cyber Defence · 76d ago We open-sourced the most dangerous part of our security startup on purpose. cybersecurity · 76d ago Which conference(s) result in the most people finding jobs? cybersecurity · 76d ago My discord account has been hacked second time even after enabling two factor authentication and resetting password cybersecurity · 76d ago What's the most efficient way to learn cloud governance and compliance cybersecurity · 76d ago honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports For [Blue|Purple] Teams in Cyber Defence · 76d ago Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild. For [Blue|Purple] Teams in Cyber Defence · 76d ago Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council For [Blue|Purple] Teams in Cyber Defence · 76d ago RemotePE: The Lazarus RAT that lives in memory For [Blue|Purple] Teams in Cyber Defence · 76d ago Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer For [Blue|Purple] Teams in Cyber Defence · 76d ago Paved With Intent: ROADtools and Nation-State Tactics in the Cloud For [Blue|Purple] Teams in Cyber Defence · 76d ago Twee mannen aangehouden voor phishing - Two men arrested for phishing For [Blue|Purple] Teams in Cyber Defence · 76d ago Sharp Eyes: Mass surveillance of foreigners in China For [Blue|Purple] Teams in Cyber Defence · 76d ago Does anyone know C2 framwork and free hosting to host C2? cybersecurity · 76d ago Finding bot account hacking: security in practice · 76d ago relay_bible: Technical Reference to multiple relay techniques For [Blue|Purple] Teams in Cyber Defence · 76d ago CIS-CAT Assessor for assessment Windows server 2022 and 2025 cybersecurity · 76d ago Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec For [Blue|Purple] Teams in Cyber Defence · 76d ago The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in] For [Blue|Purple] Teams in Cyber Defence · 76d ago SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format For [Blue|Purple] Teams in Cyber Defence · 76d ago North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial For [Blue|Purple] Teams in Cyber Defence · 76d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 76d ago Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this cybersecurity · 76d ago Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks? cybersecurity · 76d ago Recent adoption of AI taught me what is Cybersecurity. cybersecurity · 76d ago The Pentagon Changed the Rules for Cybersecurity Compliance cybersecurity · 76d ago Can someone explain to a noob like me what the implications of this exploit are? cybersecurity · 76d ago SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections cybersecurity · 76d ago Window between zero-day CVE and a patch! cybersecurity · 77d ago Is it risky when a website puts on technology components with versions they used in their website? cybersecurity · 77d ago Anyone else losing their mind over this "AI Cybersecurity" hype? cybersecurity · 77d ago URL parsing behavior in a canonical tag lab cybersecurity · 77d ago How to hacking: security in practice · 77d ago Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you? cybersecurity · 77d ago Any tips for me pls cybersecurity · 77d ago How do you minimize legal liability as a solo contractor? cybersecurity · 77d ago How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing? cybersecurity · 77d ago nmap on Linux: Guide to Network Scanning and Discovery Technical Information Security Content & Discussion · 77d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 77d ago Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift. hacking: security in practice · 77d ago Provenance: A survival toolkit for an AI dominant information landscape cybersecurity · 77d ago Nmap Mastery: The Complete Guide to Network Reconnaissance hacking: security in practice · 77d ago Google wallet virtual card cloned hacking: security in practice · 77d ago [ Removed by Reddit ] cybersecurity · 77d ago Active Drupal SQLi exploitation is a real „patch now“ moment cybersecurity · 77d ago machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native) cybersecurity · 77d ago Need suggestions and input; not a promotion cybersecurity · 77d ago Need advice! cybersecurity · 77d ago New Zealand is becoming a focal point for AI-driven superhacking threats. cybersecurity · 77d ago Staged publishing and new install-time controls for npm - GitHub Changelog For [Blue|Purple] Teams in Cyber Defence · 77d ago nmap on Linux: Guide to Network Scanning and Discovery cybersecurity · 77d ago TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle cybersecurity · 77d ago How would Phishing look like in the future? (targeting agents, not humans) cybersecurity · 77d ago Best beginner/intermediate book for system security (blue team / defense / audits)? cybersecurity · 77d ago Why is on-prem and air-gapped asset inventory still such a mess? cybersecurity · 77d ago keep getting MS authentication sign in attempts? cybersecurity · 77d ago Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES For [Blue|Purple] Teams in Cyber Defence · 77d ago Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud For [Blue|Purple] Teams in Cyber Defence · 77d ago Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow For [Blue|Purple] Teams in Cyber Defence · 77d ago The Future and Past of Residential Proxies For [Blue|Purple] Teams in Cyber Defence · 77d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 77d ago Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy For [Blue|Purple] Teams in Cyber Defence · 77d ago Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware For [Blue|Purple] Teams in Cyber Defence · 77d ago A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software For [Blue|Purple] Teams in Cyber Defence · 77d ago Prompt Injection finally broke my brain a little. My first article as a security student. Technical Information Security Content & Discussion · 77d ago Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows For [Blue|Purple] Teams in Cyber Defence · 77d ago Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 77d ago Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes For [Blue|Purple] Teams in Cyber Defence · 77d ago mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode. For [Blue|Purple] Teams in Cyber Defence · 77d ago keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust. For [Blue|Purple] Teams in Cyber Defence · 77d ago np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation. For [Blue|Purple] Teams in Cyber Defence · 77d ago Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up. For [Blue|Purple] Teams in Cyber Defence · 77d ago OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ For [Blue|Purple] Teams in Cyber Defence · 77d ago Megalodon: Mass GitHub Repo Backdooring via CI Workflows For [Blue|Purple] Teams in Cyber Defence · 77d ago Silly issue cybersecurity · 77d ago FatGid - FreeBSD 14.x kernel LPE For [Blue|Purple] Teams in Cyber Defence · 77d ago Manage [VSCode] extensions in enterprise environments For [Blue|Purple] Teams in Cyber Defence · 77d ago angr: A powerful and user-friendly binary analysis platform! For [Blue|Purple] Teams in Cyber Defence · 77d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware For [Blue|Purple] Teams in Cyber Defence · 77d ago How Attackers Force Microsoft to Send Phishing Emails For [Blue|Purple] Teams in Cyber Defence · 77d ago Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects For [Blue|Purple] Teams in Cyber Defence · 77d ago Microsoft Authenticator App Details now exposed in Entra SignInLogs For [Blue|Purple] Teams in Cyber Defence · 77d ago Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting For [Blue|Purple] Teams in Cyber Defence · 77d ago How China-linked threat actors obtain zero-day vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 77d ago How to practice cybersecurity while studying prograaming ? cybersecurity · 77d ago Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research For [Blue|Purple] Teams in Cyber Defence · 77d ago How to Use Claude AI: A Complete Technical Beginner's Guide Technical Information Security Content & Discussion · 77d ago [AI Security] Exploring Behavioral AI for Runtime Threat Detection cybersecurity · 77d ago Podman and krun: is it pointless to harden quadlets? cybersecurity · 77d ago Monitoring for vssadmin.exe delete shadows is an absolute bare minimum For [Blue|Purple] Teams in Cyber Defence · 77d ago Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack For [Blue|Purple] Teams in Cyber Defence · 77d ago How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers For [Blue|Purple] Teams in Cyber Defence · 77d ago How to handle security researchers (and firms) without a bounty program? cybersecurity · 77d ago CVE-2026-48029: Two grid-decode bugs in libheif For [Blue|Purple] Teams in Cyber Defence · 77d ago GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++ Reverse Engineering · 77d ago workcell: Bounded local runtime and policy boundary for coding agents For [Blue|Purple] Teams in Cyber Defence · 77d ago OpenShell: OpenShell is the safe, private runtime for autonomous AI agents. For [Blue|Purple] Teams in Cyber Defence · 77d ago Product analytics is becoming a third-party breach surface cybersecurity · 77d ago How can i learn and get into red teaming? cybersecurity · 77d ago Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network cybersecurity · 77d ago I got hacked cybersecurity · 77d ago What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method? hacking: security in practice · 77d ago Soc analysts in big companies, how it looks like? cybersecurity · 77d ago Has anyone manage to reverse the macked dylib? Reverse Engineering · 77d ago CTO at NCSC Summary: week ending May 24th cybersecurity · 77d ago Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation For [Blue|Purple] Teams in Cyber Defence · 77d ago Built a SOC from scratch with no prior SOC experience For [Blue|Purple] Teams in Cyber Defence · 77d ago These special phone and app features can help protect you from spyware cybersecurity · 77d ago Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button? cybersecurity · 77d ago Capcha Code Malware cybersecurity · 77d ago getting lost when hunting cybersecurity · 77d ago How to find information behind an account? cybersecurity · 77d ago Reverse engineering circuitry in a Spacelab computer from 1980 Reverse Engineering · 78d ago Theoretical Design Concept for Post-Exploitation Browser Defense cybersecurity · 78d ago Google Certifications... cybersecurity · 78d ago How to continue when finding a possible Vulnerability but local law prohibits me from investigating further cybersecurity · 78d ago Netherlands seizes 800 servers of hosting firm enabling cyberattacks cybersecurity · 78d ago Is the CISSP still a reputable cert for getting jobs? cybersecurity · 78d ago Which of these gоv roles would fare better in the private sector? cybersecurity · 78d ago Laravel Lang packages hijacked to deploy credential-stealing malware cybersecurity · 78d ago Mapping binaries to EDR feature spaces cybersecurity · 78d ago Lost my number + WhatsApp account — worried about old chats, photos, and videos cybersecurity · 78d ago Proxmark5 campaign unlocked the $600k stretch goal hacking: security in practice · 78d ago ☔️🌅 STÖK · 78d ago what is the most painful or time-consuming part of your work right now?" cybersecurity · 78d ago Anthropic says Mythos has already found more than 10,000 vulnerabilities cybersecurity · 78d ago What is the experience needed for “entry level” cybersecurity jobs? cybersecurity · 78d ago Browser extension testing. cybersecurity · 78d ago GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision hacking: security in practice · 78d ago Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip? cybersecurity · 78d ago Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology Reverse Engineering · 78d ago Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback cybersecurity · 78d ago Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition cybersecurity · 78d ago Can someone recommend me some good, large universities to study cybersecurity? cybersecurity · 78d ago New guy khikhi cybersecurity · 78d ago Examples of intentional backdoors being breached? cybersecurity · 78d ago Non-Compliant Vocab cybersecurity · 78d ago CTO at NCSC Summary: week ending May 24th For [Blue|Purple] Teams in Cyber Defence · 78d ago HackTheBox - MonitorsFour IppSec · 78d ago VPN Exploitation When Patched Doesn't Mean Protected For [Blue|Purple] Teams in Cyber Defence · 78d ago Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation For [Blue|Purple] Teams in Cyber Defence · 78d ago Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites cybersecurity · 78d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 78d ago CLR-Stomp: .NET CLR-Stomping For [Blue|Purple] Teams in Cyber Defence · 78d ago infostealers just spawned a 5,000+ repo github supply chain attack cybersecurity · 78d ago The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis cybersecurity · 78d ago Doom running on a Kids Video Walkie Talkie hacking: security in practice · 78d ago GRO frag cybersecurity · 78d ago We audited 12K n8n templates: most have critical vulnerabilities cybersecurity · 78d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 78d ago Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week cybersecurity · 78d ago Mitigated Vulnerabilities by Vendor as Feed cybersecurity · 78d ago From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence For [Blue|Purple] Teams in Cyber Defence · 78d ago Introducing Showboat: A new malware family taunts defenses and targets international telecom firms For [Blue|Purple] Teams in Cyber Defence · 78d ago Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor For [Blue|Purple] Teams in Cyber Defence · 78d ago Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors cybersecurity · 78d ago A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories cybersecurity · 78d ago Where can I find the tools freely on internet to practice for soc analyst cybersecurity · 78d ago Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX. hacking: security in practice · 78d ago Pardon MIE?: how Mythos did not bypass Apple MIE Technical Information Security Content & Discussion · 78d ago residential proxies cybersecurity · 78d ago Recommendations for getting started in cybersecurity cybersecurity · 78d ago Linux mint or Ubuntu for complete beginner cybersecurity · 78d ago Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world. cybersecurity · 78d ago Pentesting company recommendation cybersecurity · 79d ago Have you ever failed a certification exam? cybersecurity · 79d ago AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance cybersecurity · 79d ago This ID Verification company store users biometrics? (FaceTec) hacking: security in practice · 79d ago What do i need to learn to get into application security? Which Degrees/Certs cybersecurity · 79d ago RSAC online membership? Is it worth it? cybersecurity · 79d ago Playwright version that lets AI-Agents navigate the web hacking: security in practice · 79d ago Can someone give me a detailed roadmap for becoming a SOC Analyst? cybersecurity · 79d ago Puedo conseguir trabajo? cybersecurity · 79d ago How do i learn networking for cyber security? cybersecurity · 79d ago What's going to be Hacking and Cybersecurity's future is gonna be like? cybersecurity · 79d ago Cyber security placement - Interview Help cybersecurity · 79d ago CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module Technical Information Security Content & Discussion · 79d ago Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge cybersecurity · 79d ago AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22) For [Blue|Purple] Teams in Cyber Defence · 79d ago CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22) Reverse Engineering · 79d ago AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22 Technical Information Security Content & Discussion · 79d ago Feedback needed cybersecurity · 79d ago GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks. For [Blue|Purple] Teams in Cyber Defence · 79d ago Handoff Transition cybersecurity · 79d ago Where to learn the ins and outs of the computer itself hacking: security in practice · 79d ago Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't) Technical Information Security Content & Discussion · 79d ago Just added an interactive security map showing exactly what the server sees (and doesn't) cybersecurity · 79d ago Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns For [Blue|Purple] Teams in Cyber Defence · 79d ago Trend Micro warns of Apex One zero-day exploited in the wild cybersecurity · 79d ago Lawmakers Demand Answers as CISA Tries to Contain Data Leak cybersecurity · 79d ago Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL? For [Blue|Purple] Teams in Cyber Defence · 79d ago https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/ cybersecurity · 79d ago Harvard and 140 other legitimate websites compromised Malware Analysis & Reports · 79d ago Harvard and 140 other legitimate websites compromised cybersecurity · 79d ago Votre Satisfaction Dans Votre Travail cybersecurity · 79d ago 5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit. cybersecurity · 79d ago Browser session theft is quietly becoming more dangerous than password theft Malware Analysis & Reports · 79d ago US states urge Congress to renew cybersecurity grants cybersecurity · 79d ago Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension Technical Information Security Content & Discussion · 79d ago Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours Malware Analysis & Reports · 79d ago Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes Reverse Engineering · 79d ago The CISO's Guide to IDE Security in 2026 cybersecurity · 79d ago Help with evilginx cybersecurity · 79d ago Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets Technical Information Security Content & Discussion · 79d ago Watching AI Brain Drain on Attackers in Real Time cybersecurity · 79d ago Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm. cybersecurity · 79d ago api-rta cyberwarfare labs cybersecurity · 79d ago Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator hacking: security in practice · 79d ago I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner For [Blue|Purple] Teams in Cyber Defence · 79d ago The Worm That Deletes Your Entire Computer | Threat Wire Hak5 · 79d ago Does Security Implement Fixes? cybersecurity · 79d ago Ultimate Cybersecurity without needing AV ect? cybersecurity · 79d ago Hack your corrupt company. Sell their secrets to the black market hacking: security in practice · 79d ago User Onboarding with IAM cybersecurity · 79d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 79d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 79d ago Data breach in name of protest Technical Information Security Content & Discussion · 79d ago qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb) Reverse Engineering · 79d ago pnpm 11 Might Finally Be a Better Default Than npm Technical Information Security Content & Discussion · 79d ago pnpm 11 Might Finally Be a Better Default Than npm cybersecurity · 79d ago 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs cybersecurity · 79d ago Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria cybersecurity · 79d ago AI-generated reporting: Lessons learned from Cisco Talos Incident Response For [Blue|Purple] Teams in Cyber Defence · 79d ago CrabLoader: A PoC Cobalt Strike UDRL written in Rust For [Blue|Purple] Teams in Cyber Defence · 79d ago The 429 Microsoft Graph Mystery For [Blue|Purple] Teams in Cyber Defence · 79d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 79d ago Azure Tenant Enumeration is Dead For [Blue|Purple] Teams in Cyber Defence · 79d ago A Deep Dive into Codex Windows Sandbox For [Blue|Purple] Teams in Cyber Defence · 79d ago Striga: Lifting x86 to LLVM IR with Python For [Blue|Purple] Teams in Cyber Defence · 79d ago Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload Securelist · 79d ago Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip" cybersecurity · 79d ago Looking for a cybersecurity professional to interview for a university project (interview in French) cybersecurity · 79d ago Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise WeLiveSecurity · 79d ago veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker. For [Blue|Purple] Teams in Cyber Defence · 79d ago Windows BitLocker Security Feature Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 79d ago CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility For [Blue|Purple] Teams in Cyber Defence · 79d ago Google API keys keep working after you delete them long enough to be exploited For [Blue|Purple] Teams in Cyber Defence · 79d ago Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both? For [Blue|Purple] Teams in Cyber Defence · 79d ago North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT For [Blue|Purple] Teams in Cyber Defence · 79d ago Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit For [Blue|Purple] Teams in Cyber Defence · 79d ago Safe read-only check script for Copy Fail / CVE-2026-31431 cybersecurity · 79d ago New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible? cybersecurity · 79d ago Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names) For [Blue|Purple] Teams in Cyber Defence · 79d ago [TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly cybersecurity · 79d ago Cisco used AI to write security incident reports, with mixed results cybersecurity · 79d ago [TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM) cybersecurity · 79d ago Reverse Engineered Google reCAPTCHA Reverse Engineering · 79d ago Cyber Insurance Actuary Looking for Educational Resources cybersecurity · 79d ago As a bank , how do i give protected access to claude to my team? cybersecurity · 79d ago Can seasonal Apple Store employees apply for internal IT/cybersecurity roles? cybersecurity · 80d ago Reliable IP reputation check tools besides IPQS?(for work) cybersecurity · 80d ago 🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget hacking: security in practice · 80d ago Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026) cybersecurity · 80d ago Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins cybersecurity · 80d ago Hacked by Rat Tools for 2.5 years. cybersecurity · 80d ago Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware Trend Micro Research, News, Perspectives · 80d ago Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada CyberScoop · 80d ago Google API Keys Remain Active After Deletion cybersecurity · 80d ago Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens For [Blue|Purple] Teams in Cyber Defence · 80d ago how do cyber sec consultants and pentesters actually get new clients? cybersecurity · 80d ago Post Incident Paranoia? cybersecurity · 80d ago Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector cybersecurity · 80d ago Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity? cybersecurity · 80d ago Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready cybersecurity · 80d ago You can counter MEMZ with Krotten in XP cybersecurity · 80d ago What are the most effective ways to do Blackbox testing? cybersecurity · 80d ago Npm registry sets stage for more secure package publishing cybersecurity · 80d ago Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support cybersecurity · 80d ago Megalodon: CI/CD Malware Spreading Across GitHub Repositories For [Blue|Purple] Teams in Cyber Defence · 80d ago Lawmakers from both parties say CISA cuts have gone too far CyberScoop · 80d ago durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave Technical Information Security Content & Discussion · 80d ago Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK cybersecurity · 80d ago Is the Cybercorps SFS still worth it? cybersecurity · 80d ago Microsoft warns hackers are exploiting password resets to gain access to user accounts cybersecurity · 80d ago Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame cybersecurity · 80d ago How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account Malware Analysis & Reports · 80d ago WORM USB drives cybersecurity · 80d ago An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model? cybersecurity · 80d ago Trump postpones executive order focused on AI security CyberScoop · 80d ago CISOs - Holding the Line cybersecurity · 80d ago [Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled Technical Information Security Content & Discussion · 80d ago Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware Reverse Engineering · 80d ago A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale cybersecurity · 80d ago Security Scroll Down? cybersecurity · 80d ago mass github repo backdooring via CI workflows(Megalodon) cybersecurity · 80d ago I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP Reverse Engineering · 80d ago 📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity. For [Blue|Purple] Teams in Cyber Defence · 80d ago CISA chief frets about open-source vulnerabilities, delayed security improvements CyberScoop · 80d ago Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit? cybersecurity · 80d ago Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks For [Blue|Purple] Teams in Cyber Defence · 80d ago GitHub Actions Cache Poisoning is eating open source Technical Information Security Content & Discussion · 80d ago European authorities take down prolific cybercrime VPN service CyberScoop · 80d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Reverse Engineering · 80d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox For [Blue|Purple] Teams in Cyber Defence · 80d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox cybersecurity · 80d ago CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox Technical Information Security Content & Discussion · 80d ago CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat Technical Information Security Content & Discussion · 80d ago beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA For [Blue|Purple] Teams in Cyber Defence · 80d ago FatGid - FreeBSD 14.x kernel LPE Technical Information Security Content & Discussion · 80d ago DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind cybersecurity · 80d ago FaceTec (ID verification) company appears to store user biometrics cybersecurity · 80d ago Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082) Technical Information Security Content & Discussion · 80d ago CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication cybersecurity · 80d ago CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat hacking: security in practice · 80d ago It seems that FaceTec (ID Verification company) allows for storage of user biometrics cybersecurity · 80d ago Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check. cybersecurity · 80d ago Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data cybersecurity · 80d ago This ID verification company allows for storage of biometric data? hacking: security in practice · 80d ago What Questions Do You Ask During SSP Control Interviews? cybersecurity · 80d ago Feed The Cat BackDoor cybersecurity · 80d ago Flipper One - Asking for help from the community cybersecurity · 80d ago Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 80d ago Tracking TamperedChef Clusters via Certificate and Code Reuse For [Blue|Purple] Teams in Cyber Defence · 80d ago Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign For [Blue|Purple] Teams in Cyber Defence · 80d ago Flipper One — tech specs cybersecurity · 80d ago Architecture Zero Trust détaillée cybersecurity · 80d ago I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :) hacking: security in practice · 80d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 80d ago ABB Terra AC Wallbox All CISA Advisories · 80d ago Hitachi Energy GMS600 All CISA Advisories · 80d ago ABB B&R Automation Studio All CISA Advisories · 80d ago ABB B&R Automation Runtime All CISA Advisories · 80d ago ABB B&R PCs All CISA Advisories · 80d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 80d ago Cybersecurity in Healthcare cybersecurity · 80d ago Staged publishing for npm packages | npm Docs cybersecurity · 80d ago 9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though) cybersecurity · 80d ago Neither MFA, Passkey, nor trusted IP help here cybersecurity · 80d ago cyber security remote cybersecurity · 80d ago Database of Malicious Browser Extensions Malware Analysis & Reports · 80d ago SeekYou — one input, 15 recon sources, one report. hacking: security in practice · 80d ago I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries Reverse Engineering · 80d ago CSIRT incident response cybersecurity · 80d ago The readiness paradox: Why a false sense of cyber confidence is becoming a liability CyberScoop · 80d ago Trying to find a graduate role cybersecurity · 80d ago bypass internet restrictions hacking: security in practice · 80d ago GitHub ~3,800 internal repos compromised through a malicious VS Code extension Technical Information Security Content & Discussion · 80d ago I’ve got 99 problems, and IOCX isn’t one. Malware Analysis & Reports · 80d ago Microsoft warns of new Defender zero-days exploited in attacks cybersecurity · 80d ago From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree For [Blue|Purple] Teams in Cyber Defence · 80d ago How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102) For [Blue|Purple] Teams in Cyber Defence · 80d ago Iran-linked Operators Suspected in ATG Breaches For [Blue|Purple] Teams in Cyber Defence · 80d ago Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs For [Blue|Purple] Teams in Cyber Defence · 80d ago Compromised Nx Console version 18.95.0 For [Blue|Purple] Teams in Cyber Defence · 80d ago CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path For [Blue|Purple] Teams in Cyber Defence · 80d ago From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat For [Blue|Purple] Teams in Cyber Defence · 80d ago Webworm: New burrowing techniques For [Blue|Purple] Teams in Cyber Defence · 80d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) For [Blue|Purple] Teams in Cyber Defence · 80d ago what is the best security app option for pixel8a? cybersecurity · 80d ago How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) cybersecurity · 80d ago IoT Security cybersecurity · 80d ago GitHub links repo breach to TanStack npm supply-chain attack cybersecurity · 80d ago Another working Linux LPE exploit is out. How are teams treating local-only bugs now? cybersecurity · 80d ago Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks cybersecurity · 80d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 80d ago Google publishes exploit code threatening millions of Chromium users cybersecurity · 80d ago landing a remote Vulnerability Management role cybersecurity · 80d ago Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case. cybersecurity · 80d ago I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting? cybersecurity · 80d ago Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit cybersecurity · 81d ago Can someone unlock a list of the 500-1000 most visited websites online? hacking: security in practice · 81d ago One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign Trend Micro Research, News, Perspectives · 81d ago Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure For [Blue|Purple] Teams in Cyber Defence · 81d ago Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation For [Blue|Purple] Teams in Cyber Defence · 81d ago Wordlist generator based on WordNet graphs + LLM hacking: security in practice · 81d ago What volume of TPRM do you handle per month? cybersecurity · 81d ago GitHub’s Fake Engagement Problem Is Hiding in Plain Sight For [Blue|Purple] Teams in Cyber Defence · 81d ago Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR) For [Blue|Purple] Teams in Cyber Defence · 81d ago GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam) Reverse Engineering · 81d ago safest virtual machine? cybersecurity · 81d ago Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration cybersecurity · 81d ago Meet Rampart and Clarity, Microsoft’s new red team combo AI agents CyberScoop · 81d ago wordpress memberpress hacking: security in practice · 81d ago Cybercrime service disrupted for abusing Microsoft platform to sign malware cybersecurity · 81d ago Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage For [Blue|Purple] Teams in Cyber Defence · 81d ago GitHub notifications cybersecurity · 81d ago The Open Source USB Drive Built for Privacy hacking: security in practice · 81d ago Is there no more privacy left in the world? cybersecurity · 81d ago AI Agents defeat obfuscated JavaScript in 10 minutes Reverse Engineering · 81d ago Microsoft Edge had a password blunder, and it raises a bigger browser trust problem cybersecurity · 81d ago Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network cybersecurity · 81d ago Aconselhamento / mini texto cybersecurity · 81d ago CISA with an absolutely embarrassing data leak. cybersecurity · 81d ago Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys cybersecurity · 81d ago Anyone else feeling like static AppSec workflows are starting to hit limits? cybersecurity · 81d ago Is someone trying to hack me? hacking: security in practice · 81d ago What is it Wednesdays: Episode 0002 Reverse Engineering · 81d ago GitHub breach highlights developer tools as part of attack surface cybersecurity · 81d ago Why do some malware use unique user-agent strings? cybersecurity · 81d ago Encrypted emails bypassing email security tool cybersecurity · 81d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era For [Blue|Purple] Teams in Cyber Defence · 81d ago GitHub says internal repositories were impacted in poisoned VS Code extension attack CyberScoop · 81d ago Ctf groups cybersecurity · 81d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era cybersecurity · 81d ago Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era Technical Information Security Content & Discussion · 81d ago cpu backdoor hacking: security in practice · 81d ago CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis Technical Information Security Content & Discussion · 81d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 81d ago Opensource that automatically scans your git repos for breaches cybersecurity · 81d ago 5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready For [Blue|Purple] Teams in Cyber Defence · 81d ago TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post) Reverse Engineering · 81d ago Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing Reverse Engineering · 81d ago CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers Technical Information Security Content & Discussion · 81d ago Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online Technical Information Security Content & Discussion · 81d ago CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed. cybersecurity · 81d ago Your developers are deploying agents in your production environment right now. You have no governance for it. cybersecurity · 81d ago Technical analysis of CVE-2026-34472 in ZTE H188A router firmware hacking: security in practice · 81d ago ¿Como me preparo para EC-Council CSA? cybersecurity · 81d ago The IBM X-Force Index 2026 explains all three in one finding. cybersecurity · 81d ago The IBM X-Force Index 2026 explains all three in one finding. Technical Information Security Content & Discussion · 81d ago Securing iPad's question cybersecurity · 81d ago Cybersecurity 101 cybersecurity · 81d ago What would this job role be? cybersecurity · 81d ago MSPs & MSSPs suck cybersecurity · 81d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 81d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog All CISA Advisories · 81d ago [ Removed by Reddit ] cybersecurity · 81d ago GitHub hit by a compromised VSCode extension Technical Information Security Content & Discussion · 81d ago Crossroads cybersecurity · 81d ago Advice regarding "SOC" job that automates everything cybersecurity · 81d ago Is this Medium article about "NetMirror" malware legit? cybersecurity · 81d ago AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon? cybersecurity · 81d ago Developer tooling is part of the attack surface before a project is even run cybersecurity · 81d ago How to build .NET obfuscator Reverse Engineering · 81d ago botguard-token-generator / a google botguard token gen using only requests...? Reverse Engineering · 81d ago Remote Process Read Primitive via NtCreateThreadEx Exit Code For [Blue|Purple] Teams in Cyber Defence · 81d ago GUEST ESSAY: AI can speed up communication, but it can also weaken human connection The Last Watchdog · 81d ago How the hell do you manage developers, their code, their apps? cybersecurity · 81d ago Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed cybersecurity · 81d ago aimap: Discover Exposed AI Services For [Blue|Purple] Teams in Cyber Defence · 81d ago FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation. For [Blue|Purple] Teams in Cyber Defence · 81d ago How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) Securelist · 81d ago Ongoing development hacking: security in practice · 81d ago Webworm: New burrowing techniques WeLiveSecurity · 81d ago Why China Is Now a Peer Competitor to the United States in Cyberspace For [Blue|Purple] Teams in Cyber Defence · 81d ago When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax Technical Information Security Content & Discussion · 81d ago Do people still rely on antivirus software in 2026, or is built-in security enough now? cybersecurity · 81d ago For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks? hacking: security in practice · 81d ago GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories cybersecurity · 81d ago Automatic CLI for spinning up vulnerable labs + objectives cybersecurity · 81d ago Hackers found a way around Intel CET—PLaTypus locks down library jumps hacking: security in practice · 81d ago ISO/IEC 27701 scenario question cybersecurity · 81d ago Discord rolls out end-to-end encryption on voice, video calls cybersecurity · 81d ago nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings For [Blue|Purple] Teams in Cyber Defence · 81d ago GitHub investigates internal repositories breach claimed by TeamPCP cybersecurity · 81d ago Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt For [Blue|Purple] Teams in Cyber Defence · 81d ago We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. For [Blue|Purple] Teams in Cyber Defence · 81d ago Two AI-based science assistants succeed with drug-retargeting tasks cybersecurity · 81d ago GitHub investigates internal repositories breach claimed by TeamPCP hacking: security in practice · 81d ago Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings) For [Blue|Purple] Teams in Cyber Defence · 81d ago America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames cybersecurity · 81d ago An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now. cybersecurity · 81d ago We audited 12K n8n templates: most have critical vulnerabilities Technical Information Security Content & Discussion · 81d ago Veilgate - Deception proxy Technical Information Security Content & Discussion · 81d ago Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild For [Blue|Purple] Teams in Cyber Defence · 81d ago New to cybersecurity cybersecurity · 82d ago Anyone interview or work with Moxfive? cybersecurity · 82d ago A stealth Firefox version that passes all anti-bot and CAPTCHA cybersecurity · 82d ago mkPIVM - a polymorphic position-independent shellcode virtualizer cybersecurity · 82d ago Started in IT and need a Cybersecurity Roadmap with my Useless Degree! cybersecurity · 82d ago GitHub announces internal data breached. cybersecurity · 82d ago Roadmap to Cybersecurity roles cybersecurity · 82d ago Hackers: What age did you start? Where did you start, especially in practicing your skills? hacking: security in practice · 82d ago CISA credential leak raises alarms, and Capitol Hill demands answers CyberScoop · 82d ago Malware installed without literally doing anything? cybersecurity · 82d ago CTFs cybersecurity · 82d ago Can't access anything Malware Analysis & Reports · 82d ago How to watch a private video on Youtube? hacking: security in practice · 82d ago Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches CyberScoop · 82d ago Sleeping Agent: Silent persistent C2 through Web Push Technical Information Security Content & Discussion · 82d ago Crossroads cybersecurity · 82d ago Canara Bank SuRaksha Cyber Hackathon 2.0, cybersecurity · 82d ago Eight Leading U.S. Communications Firms Form C2 ISAC For [Blue|Purple] Teams in Cyber Defence · 82d ago Can I do anything cool with this network controller? hacking: security in practice · 82d ago News alert: Orchid Security study finds invisible identities now outnumber managed accounts The Last Watchdog · 82d ago Anti BOT Tipps und Tricks gesucht. cybersecurity · 82d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security cybersecurity · 82d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security For [Blue|Purple] Teams in Cyber Defence · 82d ago GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security Technical Information Security Content & Discussion · 82d ago New to Cybersecurity cybersecurity · 82d ago Micro controller safety? hacking: security in practice · 82d ago Is the ISC2 Certified in Cybersecurity worth it? cybersecurity · 82d ago Average Days to Close by Source CNAPP Severity Tag 2026 cybersecurity · 82d ago I want free nmap resource cybersecurity · 82d ago If I clear browser history regularly, does it reduce the chances of malware that target browser data? cybersecurity · 82d ago What is next after 1.5 Year as Security Analyst? cybersecurity · 82d ago Analysis advice cybersecurity · 82d ago Stop me if you heard this one before... (YellowKey related) cybersecurity · 82d ago UAC-0184: From HTA to a Signed Network Stack For [Blue|Purple] Teams in Cyber Defence · 82d ago Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe? cybersecurity · 82d ago Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing) Reverse Engineering · 82d ago Looking for advice: where should I post/publish CVE write-ups? cybersecurity · 82d ago CISA Admin Leaked AWS GovCloud Keys on Github hacking: security in practice · 82d ago New GMKtec M7 Ultra appears to be infected. Beware of the malware! Malware Analysis & Reports · 82d ago Cybersecurity statistics of the week (May 11th - May 17th) cybersecurity · 82d ago How can I test my website locally for cybersecurity? cybersecurity · 82d ago Mini Shai-Hulud returns, compromising hundreds of npm packages CyberScoop · 82d ago Use of coding in security operations cybersecurity · 82d ago Decompilation of DSP Code using IDA Pro hacking: security in practice · 82d ago Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz cybersecurity · 82d ago Microsoft disrupts cybercrime service that abused software verification systems en masse cybersecurity · 82d ago I've built an open source honeypot probe database accessible via curl, http and mcp cybersecurity · 82d ago New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here For [Blue|Purple] Teams in Cyber Defence · 82d ago Deep dive into the object creation flow in Windows - PART 4: Handle table internals. Reverse Engineering · 82d ago 6,000+ Automatic Tank Gauges Exposed With No Authentication cybersecurity · 82d ago Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email? cybersecurity · 82d ago How Storm-2949 turned a compromised identity into a cloud-wide breach For [Blue|Purple] Teams in Cyber Defence · 82d ago Microsoft disrupts cybercrime service that abused software verification systems en masse CyberScoop · 82d ago How Storm-2949 turned a compromised identity into a cloud-wide breach Technical Information Security Content & Discussion · 82d ago If humans are the weakest link, why won't companies evolve? cybersecurity · 82d ago Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?" cybersecurity · 82d ago Entra ID: PIM for Groups Review For [Blue|Purple] Teams in Cyber Defence · 82d ago Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM cybersecurity · 82d ago Local transcription vs cloud transcription, which actually feels safer? cybersecurity · 82d ago Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today? cybersecurity · 82d ago Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise cybersecurity · 82d ago TeamPCP compromises NPM maintainer with over 540 packages For [Blue|Purple] Teams in Cyber Defence · 82d ago Shai-Hulud source leak is turning npm malware into a copycat problem cybersecurity · 82d ago Framework for Preventing Secret Ideas from Leakage cybersecurity · 82d ago Kieback & Peter DDC Building Controllers All CISA Advisories · 82d ago Siemens RUGGEDCOM APE1808 Devices All CISA Advisories · 82d ago ABB CoreSense HM and CoreSense M10 All CISA Advisories · 82d ago ScadaBR All CISA Advisories · 82d ago ZKTeco CCTV Cameras All CISA Advisories · 82d ago Local LLM for building AI Security platform cybersecurity · 82d ago SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access cybersecurity · 82d ago Emerging Cyber security niches cybersecurity · 82d ago ISO/IEC 27701 cybersecurity · 82d ago Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware Reverse Engineering · 82d ago Solo dev building a terminal-heavy hacking game inspired by corporate security cybersecurity · 82d ago Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations cybersecurity · 82d ago Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments Technical Information Security Content & Discussion · 82d ago CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing Technical Information Security Content & Discussion · 82d ago CS/IT Student Looking to Grow My LinkedIn Network 😃 cybersecurity · 82d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) hacking: security in practice · 82d ago Open-source Hermes bytecode decompiler for React Native apps (Rust) Reverse Engineering · 82d ago CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models) cybersecurity · 82d ago Is Amazon Cognito a good choice long term? Alternatives? cybersecurity · 82d ago Was hacking easier in the 80s and 90s and early 2000s? cybersecurity · 82d ago Need some Advice in SOAR heavy environment cybersecurity · 82d ago Trying to find serious builders in cybersecurity - not just “let’s build” conversations cybersecurity · 82d ago Hermes bytecode decompiler (Rust) - sharing my friend’s project Reverse Engineering · 82d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields hacking: security in practice · 82d ago RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields Technical Information Security Content & Discussion · 82d ago Active Supply Chain Attack Compromises @antv Packages on npm... For [Blue|Purple] Teams in Cyber Defence · 82d ago AI Phishing cybersecurity · 82d ago The quest for greater tech independence WeLiveSecurity · 82d ago One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals cybersecurity · 82d ago When DMCA Comes Knocking - A YouTube Creator Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 82d ago [Cloudflare] Project Glasswing: what Mythos showed us For [Blue|Purple] Teams in Cyber Defence · 82d ago vpn explained the simple version that actually makes sense Malware Analysis & Reports · 82d ago How easy is it to get into the cyber security field? cybersecurity · 82d ago Forza Designer 6 Reverse Engineering · 82d ago 314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js cybersecurity · 82d ago Built a full disassembler & decompiler for Reverse Engineering | Free and open source. hacking: security in practice · 82d ago Built a full disassembler & decompiler | Free and open source. Reverse Engineering · 83d ago Slopinator - a poisoned GitHub repository generator hacking: security in practice · 83d ago Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start? cybersecurity · 83d ago New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205) Technical Information Security Content & Discussion · 83d ago ‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo cybersecurity · 83d ago CEH/CPENT vs OSCP vs GPEN cybersecurity · 83d ago ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro” cybersecurity · 83d ago CISA Contractor Admin Leaked AWS GovCloud Keys on Github cybersecurity · 83d ago Made a shell greeter that generates a unique rocket every time you open a terminal tab hacking: security in practice · 83d ago Suspecious activity in my account cybersecurity · 83d ago Is it safe to use my first name and middle name on platforms? cybersecurity · 83d ago Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice. cybersecurity · 83d ago Just received an email from shinyhunters about their amtrack hack cybersecurity · 83d ago Just received an email from shinyhackers about their amtrack hack hacking: security in practice · 83d ago Flipper Zero (or Alternatives)? hacking: security in practice · 83d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access cybersecurity · 83d ago Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access hacking: security in practice · 83d ago Bywaf: an auditable Python commandlet framework for chained pentest workflows cybersecurity · 83d ago For anyone currently working in a SOC: cybersecurity · 83d ago Fellow Tier 1 SOC/Security Analysts - What does your day to day look like? cybersecurity · 83d ago The quiet death of behavioral anti-bot and the pivot to hardware ZKPs Technical Information Security Content & Discussion · 83d ago SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain For [Blue|Purple] Teams in Cyber Defence · 83d ago AI might cut false positives, but it won’t stop the slop CyberScoop · 83d ago Recent WhatsApp hacks hacking: security in practice · 83d ago Snowboard Kids 2 is 100% Decompiled Reverse Engineering · 83d ago How do you threat hunt for RMM tools in environments where RMM is all over the place? cybersecurity · 83d ago Decompilation projects and N64 Recompiled PC ports (May 2026) Reverse Engineering · 83d ago Microsoft - "your single use code" email when it was not requested by yourself cybersecurity · 83d ago Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa CyberScoop · 83d ago Directory of vendor security questionnaires cybersecurity · 83d ago Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised cybersecurity · 83d ago I wrote an async scanner that runs about 9x faster than nmap for discovery. hacking: security in practice · 83d ago MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals cybersecurity · 83d ago AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems Technical Information Security Content & Discussion · 83d ago Glass - A fast and free interactive disassembler Reverse Engineering · 83d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. Technical Information Security Content & Discussion · 83d ago Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers hacking: security in practice · 83d ago Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight cybersecurity · 83d ago Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger For [Blue|Purple] Teams in Cyber Defence · 83d ago Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics For [Blue|Purple] Teams in Cyber Defence · 83d ago How is AI affecting the cybersecurity market? cybersecurity · 83d ago MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack The Last Watchdog · 83d ago MCP security cybersecurity · 83d ago YellowKey Mitigation cybersecurity · 83d ago CrystalX: unpacking a Go RAT through three encrypted layers For [Blue|Purple] Teams in Cyber Defence · 83d ago Anyone else on the receiving end of ShinyHunters extortion email? cybersecurity · 83d ago Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs cybersecurity · 83d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Reverse Engineering · 83d ago Benchmarking LLMs for malware triage and static unpacking with Malcat Malware Analysis & Reports · 83d ago What’s the biggest mistake people still make about online security in 2026? cybersecurity · 83d ago Anthropic shuts the EU out of its most advanced cyber AI model cybersecurity · 83d ago Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens] cybersecurity · 83d ago Best hotel for attending all three conferences in Vegas? cybersecurity · 83d ago What's your company's actual PQC migration plan? Not the one on paper - the real one. cybersecurity · 83d ago The down fall of bug bounties Technical Information Security Content & Discussion · 83d ago The Boring Stuff is Dangerous Now darkreading · 83d ago Does buying local cybersecurity (services/products/etc) matter to you? cybersecurity · 83d ago LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose cybersecurity · 83d ago Detection Engineering AI Maturity Framework cybersecurity · 83d ago IT threat evolution in Q1 2026. Mobile statistics Securelist · 83d ago IT threat evolution in Q1 2026. Non-mobile statistics Securelist · 83d ago Microsoft code cybersecurity · 83d ago TanStack Supply Chain Attack (And How to Lock Down GitHub Actions) Technical Information Security Content & Discussion · 83d ago Microsoft confirms Windows 11 security update install issues cybersecurity · 83d ago Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’ cybersecurity · 83d ago Exploit available for new DirtyDecrypt Linux root escalation flaw cybersecurity · 83d ago Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware cybersecurity · 83d ago Suspicious with a company offer letter cybersecurity · 83d ago The Canvas breach proved that prevention is no longer enough CyberScoop · 83d ago Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first? cybersecurity · 83d ago Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation Technical Information Security Content & Discussion · 83d ago Why do some recovery workflows still require full wallet uploads? cybersecurity · 83d ago Netmirror exposed - The Free Movie App That Was Robbing You Blind Malware Analysis & Reports · 83d ago Need help with interview for soc l1 cybersecurity · 83d ago Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap) cybersecurity · 83d ago HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try! Reverse Engineering · 83d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 83d ago Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation Technical Information Security Content & Discussion · 83d ago Reverse engineering no dep x64 masm AI IDE Reverse Engineering · 83d ago New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released cybersecurity · 83d ago carrer path in cybersecurity for a btech stud cybersecurity · 83d ago Agents usage in production cybersecurity · 83d ago ‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K cybersecurity · 83d ago Former CISA nominee Sean Plankey named US CEO of defense startup CyberScoop · 84d ago Are teams still finding AI API keys in public repos? cybersecurity · 84d ago Can Laws Stop Deepfakes? South Korea Aims to Find Out darkreading · 84d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 84d ago Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here? cybersecurity · 84d ago Does the CBP bug phones? cybersecurity · 84d ago What We Learned Building Runtime Visibility for Modern Telco Networks cybersecurity · 84d ago Ive got my Spotify account hacked! How do I solve this? cybersecurity · 84d ago The Politics of AI Transparency cybersecurity · 84d ago A million baby monitors and security cameras were easily viewable by hackers cybersecurity · 84d ago NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE cybersecurity · 84d ago Does anyone know if this file is still accessible to download? hacking: security in practice · 84d ago Is cybersecurity becoming more behavioral than technical? cybersecurity · 84d ago Questions About Promo Items for a Cybersecurity Conference cybersecurity · 84d ago DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write For [Blue|Purple] Teams in Cyber Defence · 84d ago Dois-je m'inquiéter ? cybersecurity · 84d ago I am dying to work abroad , rate my journey so far cybersecurity · 84d ago FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation For [Blue|Purple] Teams in Cyber Defence · 84d ago Microsoft - "Your single use code" email when it was not requested cybersecurity · 84d ago Security / Compliance work going Agentic? cybersecurity · 84d ago High school students organized a Jeopardy CTF competition - give it a try hacking: security in practice · 84d ago Don't believe the media, specially in cybersec cybersecurity · 84d ago Microsoft account keeps getting Authenticator requests? cybersecurity · 84d ago [Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated. cybersecurity · 84d ago Ansible security and compliance guide Technical Information Security Content & Discussion · 84d ago Malware learning Malware Analysis & Reports · 84d ago Struggling to generate security bulletins — any ideas? cybersecurity · 84d ago Certs to go into Security Engineer/architect cybersecurity · 84d ago 18882745552 beware of email with this number cybersecurity · 84d ago Transition from traditional penetration testing into AI security cybersecurity · 84d ago Seeking advice on next career steps cybersecurity · 84d ago Official Miasma Poison Tar Pit Docker Image Now Available hacking: security in practice · 84d ago Will the analyst role become obsolete? cybersecurity · 84d ago LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying" For [Blue|Purple] Teams in Cyber Defence · 84d ago Alert Fatigue cybersecurity · 84d ago Best path into cybersecurity for a high schooler? cybersecurity · 84d ago Static Kitten APT Adversary Simulation For [Blue|Purple] Teams in Cyber Defence · 84d ago Why Is Cybersecurity Now A Business Priority, Not Just An IT Function? Cyber Defense Magazine · 84d ago Keep getting hacked cybersecurity · 84d ago Eimeria: five layers from RAR5 to RunPE For [Blue|Purple] Teams in Cyber Defence · 84d ago ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only. For [Blue|Purple] Teams in Cyber Defence · 84d ago Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain Technical Information Security Content & Discussion · 84d ago How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices cybersecurity · 84d ago I’m interested in joining the Red Team Hackers Academy in Bangalore. cybersecurity · 84d ago openDCIM exploitation For [Blue|Purple] Teams in Cyber Defence · 84d ago PE packer/crypter with random VM ISA per build Reverse Engineering · 84d ago A clueless teenager 💔 cybersecurity · 84d ago HASBL CTF - A Jeopardy-Style CTF Organized by High School Students! For [Blue|Purple] Teams in Cyber Defence · 84d ago Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start? cybersecurity · 84d ago Am I overthinking Claude Code security or is this actually a risk? cybersecurity · 84d ago is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this cybersecurity · 84d ago ISO/IEC 27701 ( SoA ) Applicability cybersecurity · 84d ago Security Executive Playbook cybersecurity · 84d ago This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon cybersecurity · 84d ago We Have Packet Capture at Home For [Blue|Purple] Teams in Cyber Defence · 84d ago I feel crazy I hope someone has insight . cybersecurity · 84d ago Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware For [Blue|Purple] Teams in Cyber Defence · 84d ago HWMonitor Trojanized for STX RAT DLL Sideloading For [Blue|Purple] Teams in Cyber Defence · 84d ago awesome-dfir-skills: Admiralty System for CTI Claude skill For [Blue|Purple] Teams in Cyber Defence · 84d ago Mullvad exit IPs as a fingerprinting vector For [Blue|Purple] Teams in Cyber Defence · 84d ago Does anybody know where I may stumble upon some Sh1mmer bin downloads hacking: security in practice · 84d ago Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools For [Blue|Purple] Teams in Cyber Defence · 84d ago Popular node-ipc npm Package Infected with Credential Steale... For [Blue|Purple] Teams in Cyber Defence · 84d ago An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests. For [Blue|Purple] Teams in Cyber Defence · 84d ago Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files For [Blue|Purple] Teams in Cyber Defence · 84d ago Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor For [Blue|Purple] Teams in Cyber Defence · 84d ago Sandworm Activity in Industrial Environments: What the Data Reveals For [Blue|Purple] Teams in Cyber Defence · 84d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 84d ago "Shadowserver-in-a-box" IntelMQ + ELK Solution For [Blue|Purple] Teams in Cyber Defence · 84d ago Stenloader: Steganography Shellcode Loader For [Blue|Purple] Teams in Cyber Defence · 84d ago AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out For [Blue|Purple] Teams in Cyber Defence · 84d ago Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018 For [Blue|Purple] Teams in Cyber Defence · 84d ago Our response to the TanStack npm supply chain attack For [Blue|Purple] Teams in Cyber Defence · 84d ago QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026). For [Blue|Purple] Teams in Cyber Defence · 84d ago We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase. For [Blue|Purple] Teams in Cyber Defence · 84d ago APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox. For [Blue|Purple] Teams in Cyber Defence · 84d ago oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday For [Blue|Purple] Teams in Cyber Defence · 84d ago Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations For [Blue|Purple] Teams in Cyber Defence · 84d ago ΡHANTΟΜ Al-Powered Pentesting Command Center cybersecurity · 84d ago Interview Assessments cybersecurity · 85d ago We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it cybersecurity · 85d ago Questions about data blockers cybersecurity · 85d ago A Tale of Two File Names Reverse Engineering · 85d ago PE reconstruction Reverse Engineering · 85d ago OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance For [Blue|Purple] Teams in Cyber Defence · 85d ago Post Implementation task cybersecurity · 85d ago The Gentlemen Ransomware Group — Leak Analysis For [Blue|Purple] Teams in Cyber Defence · 85d ago Mythos, MOAK, CTEM and the End of CVE Chasing cybersecurity · 85d ago Cyber security jobs in Austria cybersecurity · 85d ago Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network hacking: security in practice · 85d ago Personal favorite deception layer. cybersecurity · 85d ago Estudiar Ciberseguridad cybersecurity · 85d ago Learning way cybersecurity · 85d ago A File Format Uncracked for 20 Years: Part 2 Reverse Engineering · 85d ago How do you report large volume detections to a CISO without making the BPA report a SOC story? cybersecurity · 85d ago HDD Firmware Hacking Part 1 For [Blue|Purple] Teams in Cyber Defence · 85d ago Can anyone share bugbase platform screenshot having professional usage on dashboard? cybersecurity · 85d ago ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels. For [Blue|Purple] Teams in Cyber Defence · 85d ago CTO at NCSC Summary: week ending May 17th For [Blue|Purple] Teams in Cyber Defence · 85d ago CTO at NCSC Summary: week ending May 17th cybersecurity · 85d ago GZDoom in the browser hacking: security in practice · 85d ago Vidar v1.5 in Go: same family, new language, heavy sandbox checks For [Blue|Purple] Teams in Cyber Defence · 85d ago Developer credential-theft campaign exposed operator-side self-infection For [Blue|Purple] Teams in Cyber Defence · 85d ago Security Executive Playbook cybersecurity · 85d ago Tired of tab-switching between CTI tools - here's what we put together cybersecurity · 85d ago I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor cybersecurity · 85d ago Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source! Reverse Engineering · 85d ago Help-Desk Lures Drop KongTuke's Evolved ModeloRAT For [Blue|Purple] Teams in Cyber Defence · 85d ago Welcome to BlackFile: Inside a Vishing Extortion Operation For [Blue|Purple] Teams in Cyber Defence · 85d ago HackTheBox - Pterodactyl IppSec · 85d ago In Cybersecurity cybersecurity · 85d ago AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize. Technical Information Security Content & Discussion · 85d ago DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era For [Blue|Purple] Teams in Cyber Defence · 85d ago Stop Being Weird — Life After Call Stack Spoofing Under CET For [Blue|Purple] Teams in Cyber Defence · 85d ago Anyone else feel like most MSP tooling is either overkill or painfully manual? cybersecurity · 85d ago Thinkpad vs Macbook pro endpoint security cybersecurity · 85d ago Any more affordable alternatives to “IntelligenceX”? cybersecurity · 85d ago Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran cybersecurity · 85d ago tanstack checker github action cybersecurity · 85d ago Drivers Alpha AWUS036AXML cybersecurity · 85d ago Splunk download for free cybersecurity · 85d ago The Security Mistakes Being Repeated With Ai Cyber Defense Magazine · 85d ago Funnel Builder WordPress plugin bug exploited to steal credit cards cybersecurity · 85d ago Anyone here using pager duty? cybersecurity · 85d ago Scammer targeting posters cybersecurity · 85d ago Anyone know how to bypass these school laptop pins? hacking: security in practice · 85d ago Seeking advice cybersecurity · 85d ago Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works Technical Information Security Content & Discussion · 85d ago Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026) cybersecurity · 85d ago Just got an email about a single use code, maybe someone was trying to log in? cybersecurity · 85d ago Can a background in DevOps enter the cybersecurity field? cybersecurity · 85d ago [CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link. Reverse Engineering · 85d ago Triggering the Secure Boot Certificate Update with Intune Remediations For [Blue|Purple] Teams in Cyber Defence · 85d ago How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache For [Blue|Purple] Teams in Cyber Defence · 85d ago Addressing Exchange Server May 2026 vulnerability CVE-2026-42897 For [Blue|Purple] Teams in Cyber Defence · 85d ago One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 85d ago CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED) For [Blue|Purple] Teams in Cyber Defence · 85d ago Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities For [Blue|Purple] Teams in Cyber Defence · 85d ago FamousSparrow APT Targets Azerbaijani Oil and Gas Industry For [Blue|Purple] Teams in Cyber Defence · 85d ago Disclosing new PebbleDash-based tools by Kimsuky For [Blue|Purple] Teams in Cyber Defence · 85d ago FrostyNeighbor: Fresh mischief and digital shenanigans For [Blue|Purple] Teams in Cyber Defence · 85d ago Kazuar: Anatomy of a nation-state botnet For [Blue|Purple] Teams in Cyber Defence · 85d ago OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments For [Blue|Purple] Teams in Cyber Defence · 85d ago NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys For [Blue|Purple] Teams in Cyber Defence · 85d ago Hacker Ringleader Extradited for 38 Billion Won Theft For [Blue|Purple] Teams in Cyber Defence · 85d ago Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System For [Blue|Purple] Teams in Cyber Defence · 85d ago Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit For [Blue|Purple] Teams in Cyber Defence · 85d ago The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation For [Blue|Purple] Teams in Cyber Defence · 85d ago FFFFirefox - A One-Day Wonder Renderer Exploit For [Blue|Purple] Teams in Cyber Defence · 85d ago MiniPlasma, a powerful LPE For [Blue|Purple] Teams in Cyber Defence · 85d ago Using ai in learning cybersecurity · 85d ago Exploiting Toshiba Qiomem.sys vulnerable driver Reverse Engineering · 85d ago Avanzamento area Blue Team/SOC cybersecurity · 85d ago Please what could be helpful cybersecurity · 85d ago HDD Firmware Hacking Part 1 Reverse Engineering · 85d ago CVE exploit chain cybersecurity · 85d ago What are the widely accepted SaaS security accreditations/audits an app should seek in fintech cybersecurity · 85d ago Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco cybersecurity · 85d ago Region-based binary diff tool for firmware analysis Reverse Engineering · 85d ago Major flaw in Indian Cyber and IT assurance landscape cybersecurity · 85d ago Red Team Ops Ⅱ ( CRTL ) exam preparation cybersecurity · 86d ago Recomendations cybersecurity · 86d ago A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens Reverse Engineering · 86d ago Recommended cybersecurity certification for a UX designer new to the domain? cybersecurity · 86d ago แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป! Reverse Engineering · 86d ago insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server cybersecurity · 86d ago Career path cybersecurity · 86d ago Merit America offers a program that gets you into cyber security roles. cybersecurity · 86d ago Brovan — Open-source x86/x64 user-mode binary emulator written in C# Reverse Engineering · 86d ago Brovan: Binary user-mode emulator for x86_64 Reverse Engineering · 86d ago Brovan: Binary user-mode emulator for x86_64 Malware Analysis & Reports · 86d ago Brovan: Binary user-mode emulator for x86_64 cybersecurity · 86d ago AmEx Interview! cybersecurity · 86d ago A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA hacking: security in practice · 86d ago Developer credential-stealing pipeline also collected operator workstations cybersecurity · 86d ago need help building a case. cybersecurity · 86d ago Colorado governor commutes prison sentence for election denier Tina Peters CyberScoop · 86d ago Personal favorite SIEM platform? cybersecurity · 86d ago Cardputer ADV cybersecurity · 86d ago Alternative for Qualys cybersecurity · 86d ago I have a friend who looks like he’s a stalker I’m scared he will know I stalk him hacking: security in practice · 86d ago The 4th Linux kernel flaw this month can lead to stolen SSH host keys cybersecurity · 86d ago Congress Puts Heat on Instructure After Canvas Outage darkreading · 86d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 86d ago Stack Buffer Overflow Explained (Using a Classic Doom Bug) cybersecurity · 86d ago [Tutorial] How to hack DOS games: Reversing Prince of Persia hacking: security in practice · 86d ago Here’s how the FTC plans to enforce the Take It Down Act CyberScoop · 86d ago Understanding Stack Buffer Overflows Through Doom and C++ Reverse Engineering · 86d ago Confused about cybersecurity career cybersecurity · 86d ago What is it Wednesdays: Episode 0001 Reverse Engineering · 86d ago Transferring from pen test consulting to application security? cybersecurity · 86d ago Curso de especializacion de Ciberseguridad cybersecurity · 86d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? For [Blue|Purple] Teams in Cyber Defence · 86d ago Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox? cybersecurity · 86d ago Lost, tempted to throw in the towel cybersecurity · 86d ago Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own cybersecurity · 86d ago I open-sourced a Docker security scanner I use to audit all my websites cybersecurity · 86d ago Testing Deception Technique cybersecurity · 86d ago A malware got into my account and spread spam ad to my friends and relatives cybersecurity · 86d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems Technical Information Security Content & Discussion · 86d ago North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems cybersecurity · 86d ago Most pentest reports I review are padded with garbage findings cybersecurity · 86d ago Is dns spoofing dead?? hacking: security in practice · 86d ago Cyber Essentials and use of third party websites - MFA cybersecurity · 86d ago Rapid 7 and Cisa Kev cybersecurity · 86d ago Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup Reverse Engineering · 86d ago Deepdive into the object creation flow in Windows -PART 2 : access check internals Reverse Engineering · 86d ago Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization Reverse Engineering · 86d ago Anyone know much about MS Defender? cybersecurity · 86d ago My Privacy Focused USB Drive hacking: security in practice · 86d ago Cisco zero-day under ongoing attack by persistent threat group CyberScoop · 86d ago EN18031 for IoT: struggling to see the big picture — advice from experienced people? cybersecurity · 86d ago Japan’s 3DS Mandate: One Year In Blog – Forter · 86d ago Automating code security reviews with Claude Mythos-level capabilities Technical Information Security Content & Discussion · 86d ago Automating Code Security Reviews cybersecurity · 86d ago [Tool] IOCX — deterministic static IOC extraction for PE binaries For [Blue|Purple] Teams in Cyber Defence · 86d ago New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available cybersecurity · 86d ago [Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo) Reverse Engineering · 86d ago Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition) hacking: security in practice · 86d ago AI coding tools on developer machines — looking for input on how you're handling it cybersecurity · 86d ago Chrome 148 Update Patches Critical Vulnerabilities cybersecurity · 86d ago The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract Cyber Defense Magazine · 86d ago Microsoft warns of Exchange zero-day flaw exploited in attacks cybersecurity · 86d ago I need help. i am lost cybersecurity · 86d ago Novel Evilginx Frontend - Lowering the barrier for token theft reuse For [Blue|Purple] Teams in Cyber Defence · 86d ago Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence cybersecurity · 86d ago Cyber Pioneers Ponder Past as Prologue darkreading · 86d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 86d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 86d ago Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments cybersecurity · 86d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? cybersecurity · 86d ago SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not? For [Blue|Purple] Teams in Cyber Defence · 86d ago I'm going crazy. At the application level what I can actually do to prevent DDos? cybersecurity · 86d ago yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android. Reverse Engineering · 86d ago Is anyone enrolled in Intellipaat's cybersecurity course? cybersecurity · 86d ago Will AI Replace Cybersecurity Jobs? cybersecurity · 86d ago Why geopolitical turmoil is a gift for scammers, and how to stay safe WeLiveSecurity · 86d ago What's best certification choice after OSWE cybersecurity · 86d ago TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer hacking: security in practice · 86d ago Facebook Page Call Slipping through Sleep mode cybersecurity · 86d ago ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey cybersecurity · 86d ago New Linux LPE allows local users to read any file, including privkeys cybersecurity · 86d ago A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks. cybersecurity · 86d ago Your experience as IT Admin on Alerts cybersecurity · 86d ago Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time cybersecurity · 86d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild cybersecurity · 86d ago GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets Reverse Engineering · 86d ago GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS Reverse Engineering · 86d ago Instrumenting QT6 desktop apps with Frida - Part 1 Technical Information Security Content & Discussion · 86d ago From Vercel Typosquatting to an Obfuscated macOS Malware Loader Technical Information Security Content & Discussion · 86d ago Discord VC lag Exploit cybersecurity · 86d ago FrostyNeighbor: Fresh mischief and digital shenanigans cybersecurity · 86d ago Bug FB - Inicio de sesion por password cybersecurity · 86d ago Does anyone know how to configure EVILGINX for testing cybersecurity · 86d ago Trafexia V2 - Mobile Traffic Interceptor Toolkit Reverse Engineering · 86d ago How long does it take to get familiar with a tool cybersecurity · 86d ago Scam website cybersecurity · 86d ago ANTS Hack: 19 million records exposed in French ID agency breach cybersecurity · 86d ago has anyone used tail os here? hacking: security in practice · 86d ago Is it really that easy to obtain SMS codes using an SS7 attack? cybersecurity · 86d ago AI coding tools are shipping code faster than security can review it. What's your team doing about it cybersecurity · 87d ago Interview for AI security engineer position at a fortune 500 company cybersecurity · 87d ago How’s the job market for Senior AppSec Engineers? How are the interviews? cybersecurity · 87d ago Has anyone read "The Art of Deception"? How does it hold up to now? cybersecurity · 87d ago Run this washer/dryer sans coin? hacking: security in practice · 87d ago WAF Evasion Engine For [Blue|Purple] Teams in Cyber Defence · 87d ago Is metadata protection becoming more important than traditional endpoint security for ordinary users? cybersecurity · 87d ago Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems darkreading · 87d ago Inspecting a DLL file trying to figure out if it really is malware Malware Analysis & Reports · 87d ago Zero trust in hybrid environments - what's actually worked for you cybersecurity · 87d ago Have you encountered issues with CSAF advisories in practice? cybersecurity · 87d ago Zero trust in hybrid environments - what's actually working for you cybersecurity · 87d ago I built an open-source Burp alternative hacking: security in practice · 87d ago OpenAI confirms security breach in TanStack supply chain attack cybersecurity · 87d ago Bachelors Degree Options cybersecurity · 87d ago HighBoy hacking: security in practice · 87d ago Innovator Spotlight: Klever Compliance Cyber Defense Magazine · 87d ago Thus Spoke…The Gentlemen For [Blue|Purple] Teams in Cyber Defence · 87d ago Innovator Spotlight: Radware Cyber Defense Magazine · 87d ago SecurityScorecard Snags Driftnet to Level Up Threat Intelligence darkreading · 87d ago npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output Malware Analysis & Reports · 87d ago Pentagon cyber official calls advanced AI ‘revolutionary warfare’ CyberScoop · 87d ago Maximum Severity Cisco SD-WAN Bug Exploited in the Wild darkreading · 87d ago White House cyber official: identity security matters more than ever in the age of AI CyberScoop · 87d ago I need help protecting my privacy cybersecurity · 87d ago Free Threat Intellegence cybersecurity · 87d ago What discovery in cybersecurity amazed you the most? cybersecurity · 87d ago Scholarship for Service cybersecurity · 87d ago Reading Siemens CT raw data hacking: security in practice · 87d ago KQLab - open-source query manager for SOC teams For [Blue|Purple] Teams in Cyber Defence · 87d ago For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons? cybersecurity · 87d ago How I use Hermes agent to turn Patch Tuesday into Windows exploit research hacking: security in practice · 87d ago Another day, another supply chain cybersecurity · 87d ago How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs? cybersecurity · 87d ago Teaching Linux+ & CEH..... cybersecurity · 87d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon cybersecurity · 87d ago How TeamPCP's Python Toolkit Survives a C2 Takedown For [Blue|Purple] Teams in Cyber Defence · 87d ago Innovator Spotlight: JScrambler Cyber Defense Magazine · 87d ago Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon hacking: security in practice · 87d ago SIEM use case development cybersecurity · 87d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Technical Information Security Content & Discussion · 87d ago JFrog vs Mend as Scanners cybersecurity · 87d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 87d ago KQLab - open-source query manager for SOC teams cybersecurity · 87d ago Which Vendors Publish the Best (or Worst) Security Advisories? cybersecurity · 87d ago Tips for a beginner noob that wants to learn hacking: security in practice · 87d ago 'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine darkreading · 87d ago Synthetic training data vs. real attack telemetry — does it actually matter? cybersecurity · 87d ago Microsoft AntiSSRF For [Blue|Purple] Teams in Cyber Defence · 87d ago Operative IT-Sicherheit | SIEM & Splunk cybersecurity · 87d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state Technical Information Security Content & Discussion · 87d ago Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state For [Blue|Purple] Teams in Cyber Defence · 87d ago SOC not for junior level? cybersecurity · 87d ago Major tech manufacturer Foxconn confirms cyberattack hit North American factories CyberScoop · 87d ago Cybersecurity at MSG cybersecurity · 87d ago pii-tools.com reputable? cybersecurity · 87d ago Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise cybersecurity · 87d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure For [Blue|Purple] Teams in Cyber Defence · 87d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Reverse Engineering · 87d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Malware Analysis & Reports · 87d ago VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure Technical Information Security Content & Discussion · 87d ago Contract jobs worth the risk? cybersecurity · 87d ago HackTheBoxAcademy vs LetsDefend vs CyberDefenders cybersecurity · 87d ago Automating code security reviews with Claude: near Mythos-level capabilities at lower cost cybersecurity · 87d ago Making Right Career Decision? cybersecurity · 87d ago AI Drives Cybersecurity Investments, Widening 'Valley of Death' darkreading · 87d ago I tried using apparmor (linux security) but it doesn't seem to work very well cybersecurity · 87d ago Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything! cybersecurity · 87d ago Struggling to Stay Up to Date With Vulnerabilities cybersecurity · 87d ago CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure Technical Information Security Content & Discussion · 87d ago How to Check Computer Activity: 2026 Guide for Windows and Mac Technical Information Security Content & Discussion · 87d ago Strix — first public beta of the spiritual successor to cSploit/dSploit hacking: security in practice · 87d ago How fast is autonomous AI cyber capability advancing? For [Blue|Purple] Teams in Cyber Defence · 87d ago Foxconn Attack Highlights Manufacturing's Cyber Crisis darkreading · 87d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 87d ago Siemens Siemens ROS# All CISA Advisories · 87d ago Siemens gWAP All CISA Advisories · 87d ago Siemens SIMATIC All CISA Advisories · 87d ago Siemens Ruggedcom Rox All CISA Advisories · 87d ago Siemens Ruggedcom Rox All CISA Advisories · 87d ago Siemens Simcenter Femap All CISA Advisories · 87d ago Universal Robots Polyscope 5 All CISA Advisories · 87d ago Siemens Ruggedcom Rox All CISA Advisories · 87d ago Siemens Teamcenter All CISA Advisories · 87d ago Siemens Solid Edge All CISA Advisories · 87d ago Siemens SENTRON 7KT PAC1261 Data Manager All CISA Advisories · 87d ago Siemens Opcenter RDnL All CISA Advisories · 87d ago Siemens Ruggedcom Rox All CISA Advisories · 87d ago Siemens SIMATIC S7 PLC Web Server All CISA Advisories · 87d ago Siemens Industrial Devices All CISA Advisories · 87d ago Siemens SIMATIC All CISA Advisories · 87d ago Siemens SIPROTEC 5 All CISA Advisories · 87d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 87d ago How to Transfer files Safely from a Compromised (work) Device cybersecurity · 87d ago Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward cybersecurity · 87d ago Multiple data breaches in one week cybersecurity · 87d ago Whatsapp hacking: security in practice · 87d ago How are small security teams handling vulnerability overload now? cybersecurity · 87d ago Concerns mount that EU will demand age verification for VPNs cybersecurity · 87d ago Automating code security reviews: Claude Mythos-level capabilities with lower cost cybersecurity · 87d ago Kimsuky targets organizations with PebbleDash-based tools Securelist · 87d ago The Rare Patch: A Digital Sovereignty Challenge cybersecurity · 87d ago Advise cybersecurity · 87d ago CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC Technical Information Security Content & Discussion · 87d ago Face ID bypass with avatar hacking: security in practice · 87d ago GRC cybersecurity · 87d ago Admins and Engineers cybersecurity · 87d ago Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark cybersecurity · 87d ago Ghidra 12.1 has been released! Reverse Engineering · 87d ago Prompt injection in browser coding agents is the threat model nobody is ready for cybersecurity · 87d ago FrostyNeighbor: Fresh mischief and digital shenanigans WeLiveSecurity · 87d ago New Fragnesia Linux flaw lets attackers gain root privileges cybersecurity · 87d ago Transition from MSP to Network Engineering? cybersecurity · 87d ago YellowKey: YellowKey Bitlocker Bypass Vulnerability For [Blue|Purple] Teams in Cyber Defence · 87d ago Reverse Engineering Slither.io’s Network Protocol Reverse Engineering · 87d ago So called “off grid” method cybersecurity · 87d ago Convince me I’m not paranoid: a unique hacking situation. cybersecurity · 87d ago Hunting the Behavior Behind npm Supply Chain Attacks cybersecurity · 87d ago Hunting the Behavior Behind npm Supply Chain Attacks hacking: security in practice · 87d ago Question for AppSec Members cybersecurity · 87d ago Hunting the Behavior Behind npm Supply Chain Attacks Technical Information Security Content & Discussion · 87d ago Beginners guide to Google Dorks by Heisenberg cybersecurity · 88d ago I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable... Malware Analysis & Reports · 88d ago Alguém sabe algo sobre raven eye technology cybersecurity · 88d ago Gophish Porject - Requirement cybersecurity · 88d ago Security Team Won’t Assess Risk cybersecurity · 88d ago Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework cybersecurity · 88d ago Microsoft’s new multi-model agentic security system tops leading industry benchmark cybersecurity · 88d ago Proxmark5 Day 3 Update - $357K+ funded (715% of goal) hacking: security in practice · 88d ago Researchers say AI just broke every benchmark for autonomous cyber capability CyberScoop · 88d ago Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents cybersecurity · 88d ago Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks CyberScoop · 88d ago Overwhelmed on how to enter the job market. cybersecurity · 88d ago Social media scam bill targets tech giants as New Yorkers lose billions cybersecurity · 88d ago What are the biggest technical & cultural hurdles you’re facing right now? cybersecurity · 88d ago CISSP / CCSP training - Experienced engineer cybersecurity · 88d ago WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers Technical Information Security Content & Discussion · 88d ago I Reverse-engineering Need for Speed Underground 2 Server Reverse Engineering · 88d ago Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live Technical Information Security Content & Discussion · 88d ago Checkbox Assessments Aren't Fit to Measure Risk darkreading · 88d ago Attackers Weaponize RubyGems for Data Dead Drops darkreading · 88d ago Innovators Spotlight: OPSWAT Cyber Defense Magazine · 88d ago Vulnerability in Canvas/Instructure Support Tickets had part in breach? cybersecurity · 88d ago Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak darkreading · 88d ago Are There Really Ethical Hackers? I've Yet To Meet One hacking: security in practice · 88d ago Tinker Tailor Soldier: Paper Werewolf’s latest toolkit For [Blue|Purple] Teams in Cyber Defence · 88d ago On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract Technical Information Security Content & Discussion · 88d ago /sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple Technical Information Security Content & Discussion · 88d ago Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out Technical Information Security Content & Discussion · 88d ago 126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies For [Blue|Purple] Teams in Cyber Defence · 88d ago DOJ releases legal rationale for nationwide voter data collection CyberScoop · 88d ago is malwarefox legit? cybersecurity · 88d ago what lab to learn zero trust? cybersecurity · 88d ago Anyone else got a bunch of emails leaked by Samsung? cybersecurity · 88d ago Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape darkreading · 88d ago This is what some the world's largest banks of malware look like stacked as hard drives cybersecurity · 88d ago I need feedback on my project please cybersecurity · 88d ago would like to understand the role of "Cyber Insurance UnderWriters" cybersecurity · 88d ago Weaponized AI: The new frontier of fraud and identity spoofing CyberScoop · 88d ago clens.io - new public threat & data intel service Malware Analysis & Reports · 88d ago Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad For [Blue|Purple] Teams in Cyber Defence · 88d ago Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise For [Blue|Purple] Teams in Cyber Defence · 88d ago I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included Reverse Engineering · 88d ago Free on-device tool for monitoring AI traffic on macOS — visibility before policy cybersecurity · 88d ago Is secure evidence handling and controlled derivative file sharing needed? cybersecurity · 88d ago Will Adding Some Certifications Help Me in the Job Market? cybersecurity · 88d ago Linux driver posted for Intel Silicon Security Engine Interface "ISSEI" cybersecurity · 88d ago Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified? cybersecurity · 88d ago Fragnesia made public as latest Linux local privilege escalation vulnerability cybersecurity · 88d ago HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity? cybersecurity · 88d ago trying to learn patching hacking: security in practice · 88d ago NIST is surrendering to the amount of CVEs coming in cybersecurity · 88d ago [HOMELAB] Built a SOC investigation console on two old Dell boxes For [Blue|Purple] Teams in Cyber Defence · 88d ago Military Veteran looking to get into the Cyber Field cybersecurity · 88d ago Android Intrusion Logging as a new source of data for consensual forensic analysis For [Blue|Purple] Teams in Cyber Defence · 88d ago Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor cybersecurity · 88d ago Granny’s Compromised Android Firmware Malware Analysis & Reports · 88d ago On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study) Technical Information Security Content & Discussion · 88d ago Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook. cybersecurity · 88d ago Shai-Hulud: Another Wave and Going Open Source For [Blue|Purple] Teams in Cyber Defence · 88d ago Cve apis for a database cybersecurity · 88d ago Empresas de Cyberseguridad en Mexico (Reacciones) cybersecurity · 88d ago Joined a new company: GRC landscape advice cybersecurity · 88d ago Removing admin rights cybersecurity · 88d ago a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access cybersecurity · 88d ago A stealth approach to Process Injection - EntryPoint Hijacking For [Blue|Purple] Teams in Cyber Defence · 88d ago A stealth approach to Process Injection - EntryPoint Hijacking Technical Information Security Content & Discussion · 88d ago FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow cybersecurity · 88d ago Golden years for cyber security about to start? cybersecurity · 88d ago A stealth approach to Process Injection - EntryPoint Hijacking cybersecurity · 88d ago Detecting CopyFail and DirtyFrag by thinking outside the box cybersecurity · 88d ago Daybreak is OpenAI’s answer to the AI arms race in cybersecurity CyberScoop · 88d ago Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security cybersecurity · 88d ago The Board Is Asking The Wrong Security Question Cyber Defense Magazine · 88d ago LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly darkreading · 88d ago China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm darkreading · 88d ago Career advice cybersecurity · 88d ago LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back The Last Watchdog · 88d ago A year of Apple Security Bounty research — 16 closed findings, full disclosure Technical Information Security Content & Discussion · 88d ago [Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) Malware Analysis & Reports · 88d ago The exponential rise of economic damage caused by cyber-crime continues cybersecurity · 88d ago [Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features Reverse Engineering · 88d ago Today's cybersecurity systems are not ready for AI cybersecurity · 88d ago Are certifications worth it, or do practical skills matter more? cybersecurity · 88d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) cybersecurity · 88d ago [Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible) For [Blue|Purple] Teams in Cyber Defence · 88d ago Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed cybersecurity · 88d ago Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft cybersecurity · 88d ago What to do after security+ cybersecurity · 88d ago AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data cybersecurity · 88d ago AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods Technical Information Security Content & Discussion · 88d ago LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer] Reverse Engineering · 88d ago Service Principal Sign-Ins: A blind spot that a lot are missing For [Blue|Purple] Teams in Cyber Defence · 88d ago Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub cybersecurity · 88d ago Is it realistic to move from Tech Risk/GRC into technical cybersecurity? cybersecurity · 88d ago My Analysis of a Bandook RAT PCAP For [Blue|Purple] Teams in Cyber Defence · 88d ago Are IPhone autofill passwords safe to use? cybersecurity · 88d ago Access approvals happen over Slack dm and I don't know how to present that to an auditor cybersecurity · 88d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 88d ago China is going dark to develop its own Mythos, German cyber chief fears cybersecurity · 88d ago Is prompt injection a real problem for you? cybersecurity · 88d ago New Exim BDAT bug shows why “just patch the mail server” is still not simple cybersecurity · 88d ago Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach cybersecurity · 88d ago Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign For [Blue|Purple] Teams in Cyber Defence · 88d ago Cybersecurity guide cybersecurity · 88d ago [Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ? cybersecurity · 89d ago How you guys rate Google Cyber security course and certificate out of 10 !? cybersecurity · 89d ago Detection Rule is here For [Blue|Purple] Teams in Cyber Defence · 89d ago Cyebrsecurity Startup Advice cybersecurity · 89d ago Can anyone give a real world based AI based attack? cybersecurity · 89d ago r2garlic - The world's fastest Android/DEX decompiler meets radare2! Reverse Engineering · 89d ago How worried should we be about AI powered cyberattacks? cybersecurity · 89d ago Built STIS-ICS — an open ICS/OT security learning project cybersecurity · 89d ago OS scanner that checks repos for traces of the Shai Hulud worm Malware Analysis & Reports · 89d ago OS scanner that checks repos for traces of the Shai Hulud worm cybersecurity · 89d ago Foxconn Ransomware Attack Shows Nothing Is Safe Forever cybersecurity · 89d ago Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries cybersecurity · 89d ago Cellphone IP address spoofing. hacking: security in practice · 89d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu cybersecurity · 89d ago Explorer shows random letter/number filenames before copying my actual files — normal behavior? cybersecurity · 89d ago ‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack CyberScoop · 89d ago Zscaler AI Security Capabilities ? cybersecurity · 89d ago Major world economies spell out key elements of AI ‘ingredients list’ CyberScoop · 89d ago It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight darkreading · 89d ago Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical CyberScoop · 89d ago Cybersecurity degree cybersecurity · 89d ago Owning a service principal equals owning its permissions. For [Blue|Purple] Teams in Cyber Defence · 89d ago Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma cybersecurity · 89d ago Cyber security cybersecurity · 89d ago New York Senate takes on junk fees, digital subscriptions, surveillance pricing cybersecurity · 89d ago Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection For [Blue|Purple] Teams in Cyber Defence · 89d ago Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI Malware Analysis & Reports · 89d ago CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level. For [Blue|Purple] Teams in Cyber Defence · 89d ago Cybersecurity statistics of the week (May 4th - May 10th) cybersecurity · 89d ago Feels like AI changed the speed of attacks more than most companies want to admit cybersecurity · 89d ago Anyone used Kasm or ReplicaCyber? cybersecurity · 89d ago Škoda warns of customer data breach after online shop hack cybersecurity · 89d ago Google launches new Android security feature to help uncover spyware attacks cybersecurity · 89d ago Fancy Bear: Stealing Credentials Invisibly cybersecurity · 89d ago Nightmare Eclipse has published Greenplasma and YellowKey cybersecurity · 89d ago Copilot Agent cybersecurity · 89d ago Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim Technical Information Security Content & Discussion · 89d ago The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop Technical Information Security Content & Discussion · 89d ago What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles? cybersecurity · 89d ago GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language. Reverse Engineering · 89d ago Google and Amnesty International teamed up to make it harder for spyware vendors to hide CyberScoop · 89d ago Career Advice cybersecurity · 89d ago Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs Technical Information Security Content & Discussion · 89d ago AI Vulnerability Research and the Fuzzer Era Déjà Vu Technical Information Security Content & Discussion · 89d ago AI+DFIR Challenge: Share Your Disasters and Successes For [Blue|Purple] Teams in Cyber Defence · 89d ago Anyone else exhausted by the nonstop AI hype? cybersecurity · 89d ago Reviewing the trends in ransomware attacks in 2026 cybersecurity · 89d ago FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread The Last Watchdog · 89d ago Sorry if its the wrong place but hacking: security in practice · 89d ago Is It a Good Idea to Change Jobs Shortly After Getting Hired? cybersecurity · 89d ago SSO makes life easier but MFA keeps it safe, do we actually need both? cybersecurity · 89d ago Hugging Face Packages Weaponized With a Single File Tweak darkreading · 89d ago Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours? cybersecurity · 89d ago Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware For [Blue|Purple] Teams in Cyber Defence · 89d ago How are SOC teams actually deciding what not to investigate anymore? cybersecurity · 89d ago Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily cybersecurity · 89d ago Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released. cybersecurity · 89d ago Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification Cyber Defense Magazine · 89d ago Has anyone tryed this out yet? cybersecurity · 89d ago I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately... Technical Information Security Content & Discussion · 89d ago The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..) cybersecurity · 89d ago Switching to Cyber cybersecurity · 89d ago 20 Leaders Who Built the CISO Era: 2 Decades of Change darkreading · 89d ago Software Bill of Materials for AI - Minimum Elements All CISA Advisories · 89d ago ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax All CISA Advisories · 89d ago Subnet Solutions PowerSYSTEM Center All CISA Advisories · 89d ago ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities All CISA Advisories · 89d ago ABB AC500 V3 Multiple Vulnerabilities All CISA Advisories · 89d ago ABB Automation Builder Gateway for Windows All CISA Advisories · 89d ago Fuji Electric Tellus All CISA Advisories · 89d ago Nitrogen ransomware group claims Foxconn after Wisconsin plant outage cybersecurity · 89d ago Shai Hulud attack ships signed malicious TanStack, Mistral npm packages cybersecurity · 89d ago Postmortem: TanStack npm supply-chain compromise For [Blue|Purple] Teams in Cyber Defence · 89d ago Using Cape Sandbox for Phishing Analysis cybersecurity · 89d ago Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain darkreading · 89d ago Canvas hack: company pays criminals to delete students' stolen data cybersecurity · 89d ago AI is separating the companies built to scale from the ones built to sell CyberScoop · 89d ago i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning. cybersecurity · 89d ago AI integrations are quietly creating a new OAuth supply-chain problem cybersecurity · 89d ago Instructure reaches 'agreement' with ShinyHunters to stop data leak cybersecurity · 89d ago UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships cybersecurity · 89d ago Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results Technical Information Security Content & Discussion · 89d ago Hardcoded secrets in Git cybersecurity · 89d ago Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages cybersecurity · 89d ago UK water company allowed hackers to lurk undetected for nearly two years, regulator finds cybersecurity · 89d ago New ipTIME Pre-Auth RCE in CWMP cybersecurity · 89d ago New ipTIME Pre-Auth RCE in CWMP Technical Information Security Content & Discussion · 89d ago Postmortem: TanStack npm supply-chain compromise Technical Information Security Content & Discussion · 89d ago Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it? hacking: security in practice · 89d ago Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak cybersecurity · 89d ago Steam spear phishing Malware Analysis & Reports · 89d ago Fake linked in sponsored google search Malware Analysis & Reports · 89d ago State of ransomware in 2026 Securelist · 89d ago Is my phone hacked? cybersecurity · 89d ago Switched to a grc role after a year in SOC L1 cybersecurity · 89d ago bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages For [Blue|Purple] Teams in Cyber Defence · 89d ago rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions For [Blue|Purple] Teams in Cyber Defence · 89d ago Detecting Remote Thread Creation with Windows Driver For [Blue|Purple] Teams in Cyber Defence · 89d ago Mythos finds a curl vulnerability For [Blue|Purple] Teams in Cyber Defence · 89d ago Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details For [Blue|Purple] Teams in Cyber Defence · 89d ago Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign For [Blue|Purple] Teams in Cyber Defence · 89d ago Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment For [Blue|Purple] Teams in Cyber Defence · 89d ago esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app For [Blue|Purple] Teams in Cyber Defence · 89d ago Forecasting Lazarus Crypto Heists cybersecurity · 89d ago LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors. For [Blue|Purple] Teams in Cyber Defence · 89d ago How Cloudflare responded to the “Copy Fail” Linux vulnerability For [Blue|Purple] Teams in Cyber Defence · 89d ago Infrastructure Security Incident Update & FAQs cybersecurity · 89d ago I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic. For [Blue|Purple] Teams in Cyber Defence · 89d ago LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots. For [Blue|Purple] Teams in Cyber Defence · 89d ago Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages cybersecurity · 89d ago In Depth Guide To VM Based Obfuscation - What it is and how to handle it. cybersecurity · 89d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective cybersecurity · 89d ago Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective Reverse Engineering · 90d ago Transitioned to GRC cybersecurity · 90d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages cybersecurity · 90d ago Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages Malware Analysis & Reports · 90d ago German cybersecurity official warns China is close to developing AI superhacker cybersecurity · 90d ago How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models. Technical Information Security Content & Discussion · 90d ago New Shai-Hulud npm worm variant Malware Analysis & Reports · 90d ago New Shai-Hulud npm worm variant For [Blue|Purple] Teams in Cyber Defence · 90d ago Google Detects First AI-Generated Zero-Day Exploit cybersecurity · 90d ago “DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance cybersecurity · 90d ago Instructure/ canvas paid the ransom? cybersecurity · 90d ago Instructure claims hackers returned stolen Canvas data after an extortion standoff CyberScoop · 90d ago OpenAI announces Daybreak, "frontier AI for defenders" Technical Information Security Content & Discussion · 90d ago Troca emprego - big para consultoria ou fintech - Pentester/Red Team cybersecurity · 90d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation hacking: security in practice · 90d ago Finally, texts between Android and iPhone users can be end-to-end encrypted cybersecurity · 90d ago Official CheckMarx Jenkins package compromised with infostealer cybersecurity · 90d ago IMF warns of the potential for AI attacks on global financial systems cybersecurity · 90d ago 🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline cybersecurity · 90d ago GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon Technical Information Security Content & Discussion · 90d ago Cookie thieves caught stealing dev secrets via fake Claude Code installers cybersecurity · 90d ago Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo cybersecurity · 90d ago Innovator Spotlight: Iru Cyber Defense Magazine · 90d ago MS Defender on OT Network cybersecurity · 90d ago A fateful question cybersecurity · 90d ago EtwWatcher For [Blue|Purple] Teams in Cyber Defence · 90d ago SC-900 or SC-400 cybersecurity · 90d ago What are your security non-negotiables? cybersecurity · 90d ago Losing my path cybersecurity · 90d ago Axon-captcha cybersecurity · 90d ago What makes companies trust small cybersecurity vendors? cybersecurity · 90d ago Donuts and Beagles: Fake Claude site spreads backdoor For [Blue|Purple] Teams in Cyber Defence · 90d ago Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility” cybersecurity · 90d ago TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack cybersecurity · 90d ago Innovator Spotlight: Axonius Cyber Defense Magazine · 90d ago News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents The Last Watchdog · 90d ago New and improved: Agent governance, intelligent workflows, and connected app experiences Microsoft 365 Blog · 90d ago Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim cybersecurity · 90d ago How I Defeat Passkeys Nearly Every Time in Phishing Assessments Technical Information Security Content & Discussion · 90d ago These Extensions are Scraping Your AI Chats, are you affected? cybersecurity · 90d ago Reverse Engineering Fisher-Price Pixter Reverse Engineering · 90d ago Be careful with your Git: Investigating malware spreading through Git repositories cybersecurity · 90d ago Training and Phishing cybersecurity · 90d ago Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation cybersecurity · 90d ago AI-powered hacking has exploded into industrial-scale threat, Google says cybersecurity · 90d ago Apple closed my bug report 4 times. MITRE wouldn't let it die. cybersecurity · 90d ago NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG cybersecurity · 90d ago Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach For [Blue|Purple] Teams in Cyber Defence · 90d ago CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection For [Blue|Purple] Teams in Cyber Defence · 90d ago looking for "evil" Websites Malware Analysis & Reports · 90d ago Google spotted an AI-developed zero-day before attackers could use it cybersecurity · 90d ago Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge Cyber Defense Magazine · 90d ago Google spotted an AI-developed zero-day before attackers could use it CyberScoop · 90d ago The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface Cyber Defense Magazine · 90d ago Deterministic PE Structural Validation in IOCX v0.7.3 Malware Analysis & Reports · 90d ago beginner doubt cybersecurity · 90d ago where is the location of Files by Google on Android? hacking: security in practice · 90d ago I got my CEH Certification. SO what now? cybersecurity · 90d ago Construction to Cyber PM cybersecurity · 90d ago Deterministic PE Validation for Blue Teams - IOCX v0.7.3 For [Blue|Purple] Teams in Cyber Defence · 90d ago Reading old s4 memory with xgecu t48 hacking: security in practice · 90d ago [ Removed by Reddit ] cybersecurity · 90d ago Something got downloaded on my phone and then dissappeared cybersecurity · 90d ago Bleeding Llama cybersecurity · 90d ago The missing cybersecurity leader in small business CyberScoop · 90d ago Hack a data center? hacking: security in practice · 90d ago Do accountants even care about cybersecurityas much? cybersecurity · 90d ago Where Have All the Complex Windows Malware and Their Analyses Gone? cybersecurity · 90d ago Eyes wide open: How to mitigate the security and privacy risks of smart glasses WeLiveSecurity · 90d ago sl1nk link Malware Analysis & Reports · 90d ago MyAudi app:Security issues in Audi Connected Vehicle experience Technical Information Security Content & Discussion · 90d ago Delving deep into threat detection: My logic for abnormal EventID 7 activity For [Blue|Purple] Teams in Cyber Defence · 90d ago Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot Technical Information Security Content & Discussion · 90d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 90d ago Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust cybersecurity · 90d ago Was the reconnaissance in Bugbounty overrated? cybersecurity · 90d ago Cybersecurity beginner building an experimental log analyzer — looking for advice cybersecurity · 90d ago Anyone else worried about AI being a security nightmare? cybersecurity · 90d ago Snyk not working cybersecurity · 90d ago Malicious tenants paid us to abuse our RMM. We blocked them cybersecurity · 90d ago Help reasuring parents with an email parsing tool (i will not promote) cybersecurity · 90d ago Check out my matplotlib of BLE live wire data for Oura ring! Reverse Engineering · 90d ago Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows Reverse Engineering · 90d ago NZ announces sanctions on malicious Russian cyber actors, online platforms For [Blue|Purple] Teams in Cyber Defence · 90d ago Update: Ongoing Checkmarx Supply Chain Security Incident For [Blue|Purple] Teams in Cyber Defence · 90d ago DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this? cybersecurity · 91d ago Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop Reverse Engineering · 91d ago cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers cybersecurity · 91d ago 5 years as a Level 1 Security Analyst and wanting to transition into consulting cybersecurity · 91d ago How to download a RAT for myself Malware Analysis & Reports · 91d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass cybersecurity · 91d ago New into network pentesting. cybersecurity · 91d ago Is it worth it to switching field to cybersecurity ? cybersecurity · 91d ago Neeed help to get cybersecurity internship. cybersecurity · 91d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 91d ago Cybersecurity and ADHD cybersecurity · 91d ago Mythos, MOAK, CTEM and the End of CVE Chasing Technical Information Security Content & Discussion · 91d ago Autonomous Vulnerability Hunting with MCP hacking: security in practice · 91d ago Anyone dealt with a VulDB submission rejection? Resubmit or reply? cybersecurity · 91d ago GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass Reverse Engineering · 91d ago Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory) Reverse Engineering · 91d ago Autonomous Vulnerability Hunting with MCP Technical Information Security Content & Discussion · 91d ago GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3 Reverse Engineering · 91d ago ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025 For [Blue|Purple] Teams in Cyber Defence · 91d ago Unmanaged PowerShell Execution: Hunting Beyond powershell.exe For [Blue|Purple] Teams in Cyber Defence · 91d ago Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign For [Blue|Purple] Teams in Cyber Defence · 91d ago ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing cybersecurity · 91d ago Static Devirtualization of Themida For [Blue|Purple] Teams in Cyber Defence · 91d ago Now You See Me: AADGraphActivityLogs For [Blue|Purple] Teams in Cyber Defence · 91d ago I have a malware and need help removing it. someone please help me 🙏 cybersecurity · 91d ago [Write-up] CyberDefenders: Wiredive Lab For [Blue|Purple] Teams in Cyber Defence · 91d ago PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra Reverse Engineering · 91d ago I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too? cybersecurity · 91d ago EasySec - Update cybersecurity · 91d ago What is the cybersecurity equivalent of leaving your spare key under the doormat? cybersecurity · 91d ago ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement Technical Information Security Content & Discussion · 91d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 91d ago VICE: Cyberwar | Full Season 2 | Blueprint cybersecurity · 91d ago Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures cybersecurity · 91d ago Email OTP as default (often ONLY) password isn’t the solution cybersecurity · 91d ago page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer For [Blue|Purple] Teams in Cyber Defence · 91d ago Soc analyse cybersecurity · 91d ago AI DNS Resolver hacking: security in practice · 91d ago Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak cybersecurity · 91d ago Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI Cyber Defense Magazine · 91d ago Price rising cybersecurity · 91d ago Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple Technical Information Security Content & Discussion · 91d ago JDownloader — Website installer incident (May 2026) For [Blue|Purple] Teams in Cyber Defence · 91d ago AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report cybersecurity · 91d ago Possible security incident against Arup Group cybersecurity · 91d ago Can honeypots be used this way? cybersecurity · 91d ago Is it true that the professionals have the worst setups? hacking: security in practice · 91d ago The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice. Technical Information Security Content & Discussion · 91d ago I think AI just quietly killed the 90-day disclosure window. cybersecurity · 91d ago TCM and Educate 360 are bugged cybersecurity · 91d ago The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate." For [Blue|Purple] Teams in Cyber Defence · 91d ago Got an alert from google what should I do? cybersecurity · 91d ago UK jobs cybersecurity · 91d ago AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT For [Blue|Purple] Teams in Cyber Defence · 91d ago Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏 cybersecurity · 91d ago Outrunning SHA256 with Physics Technical Information Security Content & Discussion · 91d ago EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine) For [Blue|Purple] Teams in Cyber Defence · 91d ago Worst company cybersecurity · 91d ago Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning cybersecurity · 91d ago I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage hacking: security in practice · 91d ago Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months) cybersecurity · 92d ago Innovator Spotlight: Lineaje Cyber Defense Magazine · 92d ago ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring) cybersecurity · 92d ago App Store Question - Darato Sport / Dofu Sport / Kofu cybersecurity · 92d ago Help! - My Parents Computer is Hacked cybersecurity · 92d ago Refining hacking basics — scaling them aswell hacking: security in practice · 92d ago Ran lumma stealer from a recaptcha scam cybersecurity · 92d ago Port 5986 question cybersecurity · 92d ago CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse! cybersecurity · 92d ago cyber security/ segurança da informação cybersecurity · 92d ago Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers For [Blue|Purple] Teams in Cyber Defence · 92d ago College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains cybersecurity · 92d ago Help with an Escalating Cyber-Stalker cybersecurity · 92d ago RRW - Rick Roll WiFi cybersecurity · 92d ago Best resources to start learning python for cybersecurity and automation cybersecurity · 92d ago Writing a Naive LLVM-based Devirtualizer For [Blue|Purple] Teams in Cyber Defence · 92d ago Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game. cybersecurity · 92d ago Memory Poisoning AI Agents via ChromaDB Technical Information Security Content & Discussion · 92d ago Defence in Depth: A Practical Secure Corporate Network Topology Technical Information Security Content & Discussion · 92d ago Where Have All the Complex Windows Malware and Their Analyses Gone? For [Blue|Purple] Teams in Cyber Defence · 92d ago JDownloader site hacked to replace installers with Python RAT malware cybersecurity · 92d ago Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram Technical Information Security Content & Discussion · 92d ago Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More) Technical Information Security Content & Discussion · 92d ago How can I fix my browser remembering what he had open last cybersecurity · 92d ago MS 360 CoPilot issues cybersecurity · 92d ago I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details cybersecurity · 92d ago ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12. cybersecurity · 92d ago eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback cybersecurity · 92d ago HackTheBox - Overwatch IppSec · 92d ago I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you cybersecurity · 92d ago AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic) hacking: security in practice · 92d ago OWASP TOP 10 LLM 2026 Community voting cybersecurity · 92d ago When prompts become shells: RCE vulnerabilities in AI agent frameworks For [Blue|Purple] Teams in Cyber Defence · 92d ago Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus For [Blue|Purple] Teams in Cyber Defence · 92d ago MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174) For [Blue|Purple] Teams in Cyber Defence · 92d ago Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor For [Blue|Purple] Teams in Cyber Defence · 92d ago Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles. For [Blue|Purple] Teams in Cyber Defence · 92d ago Second security incident at Instructure (Canvas) cybersecurity · 92d ago Wtf OPEN Ai Malware Analysis & Reports · 92d ago Bridging the Gap Between Vulnerabilities and Working Exploits hacking: security in practice · 92d ago um you guys is my hacker stupid? hacking: security in practice · 92d ago UK Advice Needed - VA+ Training? cybersecurity · 92d ago Gateweb - Secure Web Gateway cybersecurity · 92d ago Those who are in Detection engineering cybersecurity · 92d ago Can someone tell me of a trustable hacker? cybersecurity · 92d ago MSPs, how are you handling AI usage across your customer environments today? cybersecurity · 92d ago Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write cybersecurity · 92d ago How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there? cybersecurity · 92d ago ecpptv3 Exam in 3–4 Days — cybersecurity · 92d ago Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026 For [Blue|Purple] Teams in Cyber Defence · 92d ago Member of Prolific Russian Ransomware Group Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 92d ago EasterBunny: advanced espionage artifacts attributed to APT29 For [Blue|Purple] Teams in Cyber Defence · 92d ago AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES cybersecurity · 92d ago Did CISA helped you land a job ? cybersecurity · 92d ago Tracking the "Sorry" Extortionist Campaign Against cPanel Websites For [Blue|Purple] Teams in Cyber Defence · 92d ago PositiveIntent: Evasive loader for .NET Framework assemblies For [Blue|Purple] Teams in Cyber Defence · 92d ago The Accidental C2: Exploring Dev Tunnels for Remote Access For [Blue|Purple] Teams in Cyber Defence · 92d ago Living of the Land - DISM Sandbox Provider Hijack For [Blue|Purple] Teams in Cyber Defence · 92d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode For [Blue|Purple] Teams in Cyber Defence · 92d ago CTO at NCSC Summary: week ending May 10th cybersecurity · 92d ago CTO at NCSC Summary: week ending May 10th For [Blue|Purple] Teams in Cyber Defence · 92d ago ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure For [Blue|Purple] Teams in Cyber Defence · 92d ago PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale For [Blue|Purple] Teams in Cyber Defence · 92d ago Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo For [Blue|Purple] Teams in Cyber Defence · 92d ago pre pre junior needs help(guidance pls) cybersecurity · 92d ago DARWIS Taka - Web vulnerability scanner with Optional AI Validation For [Blue|Purple] Teams in Cyber Defence · 92d ago Trojan malware cybersecurity · 92d ago SANs Courses: How do people get their employers to pay? cybersecurity · 92d ago NIS2 Article 21: turning compliance controls into technical security evidence cybersecurity · 92d ago This GBA Rom is making is having a weird behavior in the Sandbox, why? cybersecurity · 93d ago This GBA ROM makes some weird things in the sanbox, would love to understand why hacking: security in practice · 93d ago Why AI agent governance feels harder than traditional security models cybersecurity · 93d ago Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection Technical Information Security Content & Discussion · 93d ago Confused about what certs are important cybersecurity · 93d ago Would getting Security+ be worthless for me? cybersecurity · 93d ago [Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc) Reverse Engineering · 93d ago Submit probe test — shadow DOM click cybersecurity · 93d ago Threat intelligence in OT (Power equipments) cybersecurity · 93d ago Why was he banned? hacking: security in practice · 93d ago Securing CI/CD for an open source project: lessons from Cilium Technical Information Security Content & Discussion · 93d ago LAB Setup hacking: security in practice · 93d ago SunnyDayBPF: eBPF telemetry integrity research for detection engineering For [Blue|Purple] Teams in Cyber Defence · 93d ago Ethical malware development community hacking: security in practice · 93d ago SOC Analyst cybersecurity · 93d ago PAWs, PAM and PIM..what is best practice? cybersecurity · 93d ago This is the most in-depth analysis I have found on the Instructure/Canvas breach so far. cybersecurity · 93d ago Poland says hackers breached water treatment plants, and the U.S. is facing the same threat cybersecurity · 93d ago Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments CyberScoop · 93d ago Has Instructure paid SH? hacking: security in practice · 93d ago Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web. cybersecurity · 93d ago Quacc++: Automated Open Source Vulnerability Discovery cybersecurity · 93d ago Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me. hacking: security in practice · 93d ago 60% of MD5 password hashes are crackable in under an hour cybersecurity · 93d ago Built a correlation engine that chains AD findings into attack paths automatically. cybersecurity · 93d ago New trends (not mainstream) hacking: security in practice · 93d ago Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!) Reverse Engineering · 93d ago Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests cybersecurity · 93d ago ShinyHunters claims nearly 9,000 schools affected by Canvas data breach CyberScoop · 93d ago Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI CyberScoop · 93d ago Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care Cyber Defense Magazine · 93d ago JDownloader's official website delivered Python RAT cybersecurity · 93d ago JDownloader's official website delivered Python RAT Malware Analysis & Reports · 93d ago Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854) cybersecurity · 93d ago ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12. cybersecurity · 93d ago ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12 Technical Information Security Content & Discussion · 93d ago Note taking apps and advice cybersecurity · 93d ago Best tools to find exposed web services by HTML title / HTTP response? hacking: security in practice · 93d ago IMF Warns AI Could Trigger Global Financial Cyber Crisis cybersecurity · 93d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 93d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 93d ago New Linux 'Dirty Frag' zero-day gives root on all major distros cybersecurity · 93d ago Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2 Reverse Engineering · 93d ago Is the ISC2 Cybersecurity program still worth it? cybersecurity · 93d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama For [Blue|Purple] Teams in Cyber Defence · 93d ago Canvas getting hit during finals week shows how fragile “critical SaaS” has become cybersecurity · 93d ago Are websites exposed to the internet under attack almost every hour, even if they're small? cybersecurity · 93d ago Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config Technical Information Security Content & Discussion · 93d ago Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou... For [Blue|Purple] Teams in Cyber Defence · 93d ago Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken cybersecurity · 93d ago What the **** is happening in cybersecurity space ? cybersecurity · 93d ago CVE-2025-68670: discovering an RCE vulnerability in xrdp Securelist · 93d ago Canvas is back up, but now what? cybersecurity · 93d ago Copy Fail (CVE-2026-31431): A Technical Deep Dive Technical Information Security Content & Discussion · 93d ago Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago? hacking: security in practice · 93d ago AI Agents Have a Security Problem. IronClaw is Fixing It. hacking: security in practice · 93d ago Instagram is getting rid of end to end encryption, what now? cybersecurity · 93d ago Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack For [Blue|Purple] Teams in Cyber Defence · 93d ago Dirty Frag: Universal Linux LPE For [Blue|Purple] Teams in Cyber Defence · 93d ago Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication. For [Blue|Purple] Teams in Cyber Defence · 93d ago Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea For [Blue|Purple] Teams in Cyber Defence · 93d ago New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation cybersecurity · 93d ago Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable". cybersecurity · 94d ago Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group? cybersecurity · 94d ago SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals Reverse Engineering · 94d ago Cushman and Wakefield confirms cyberattack cybersecurity · 94d ago Egnyte potential ransomware attack cybersecurity · 94d ago So canvas is down, what'll happen if they can't come to an argreement? cybersecurity · 94d ago Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now. cybersecurity · 94d ago I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow! Reverse Engineering · 94d ago /Why/ is Shinyhunters targeting Canvas? cybersecurity · 94d ago Canvas Hack - Any Guesses How? cybersecurity · 94d ago Should I build a virtual or physical lab? cybersecurity · 94d ago Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12 cybersecurity · 94d ago Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata cybersecurity · 94d ago Audit/Cybersecurity cybersecurity · 94d ago Issues removing Trellix (and specifically solidifier) cybersecurity · 94d ago Pentagon eyes 3-year cyber training requirement, overriding new Army policy cybersecurity · 94d ago A hacker ran me over with a robot lawn mower - The Verge hacking: security in practice · 94d ago Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia For [Blue|Purple] Teams in Cyber Defence · 94d ago How much personal info will be leaked by the recent Canvas hack?? cybersecurity · 94d ago OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI For [Blue|Purple] Teams in Cyber Defence · 94d ago Dirty Frag and canvas cybersecurity · 94d ago Hackers deface school login pages after claiming another Instructure hack cybersecurity · 94d ago Happened today hacking: security in practice · 94d ago Ivanti customers confront yet another actively exploited zero-day CyberScoop · 94d ago Did I destroy my career by being loyal to an arguably good company? cybersecurity · 94d ago Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo Technical Information Security Content & Discussion · 94d ago V4bel/dirtyfrag - Universal Linux Local Privilege Escalation cybersecurity · 94d ago Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC For [Blue|Purple] Teams in Cyber Defence · 94d ago What is CYBERRANT? cybersecurity · 94d ago Canvas is down as ShinyHunters hack forces outage cybersecurity · 94d ago Shinyhunters and Canvas hacking: security in practice · 94d ago New Dirty Frag Linux Bug Emerges in Wake of Copy Fail cybersecurity · 94d ago Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today. cybersecurity · 94d ago How is GRC work in a MSSP? cybersecurity · 94d ago SH and BF phishing console cybersecurity · 94d ago Trump officials are steering a cybersecurity scholarship program toward AI CyberScoop · 94d ago Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth? cybersecurity · 94d ago Dirty Frag - Linux LPE similiar to Copy Fail Technical Information Security Content & Discussion · 94d ago Socure authenticating AI identity as real. cybersecurity · 94d ago The first FREE online WebAssembly Reverse Engineering workbench (and how we built it) Reverse Engineering · 94d ago Automated SSL Certificate Renewals - What is your setup? cybersecurity · 94d ago Shinyhunters and Canvas cybersecurity · 94d ago What Cli execution do you use for a script file? cybersecurity · 94d ago Fiserv security incident - data breach notice cybersecurity · 94d ago Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments cybersecurity · 94d ago Honey Tokens: Bait Credentials That Catch Breaches Technical Information Security Content & Discussion · 94d ago I graduate next year with a Cybersecurity degree. cybersecurity · 94d ago An unknown malware threat. There is no such thing as a 100% detection. Malware Analysis & Reports · 94d ago Asking about Cortex cybersecurity · 94d ago CVE-2026-42511 Breakdown: RCE in FreeBSD Technical Information Security Content & Discussion · 94d ago Apache Caldera cybersecurity · 94d ago What’s the “unsexy” problem in cyber that’s actually a total disaster? cybersecurity · 94d ago Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE cybersecurity · 94d ago As a developer, should I use AI to improve security? cybersecurity · 94d ago My company has an MSP that manages our employee endpoints but we cant access the software they use to manage cybersecurity · 94d ago Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804 Technical Information Security Content & Discussion · 94d ago Americans sentenced for running 'laptop farms' for North Korea cybersecurity · 94d ago Is my laptop hijacked ? cybersecurity · 94d ago American duo sentenced for hosting laptop farms for North Korean IT workers CyberScoop · 94d ago claude ai gave security beta to Enterprise plans only what can we do as pentesters? cybersecurity · 94d ago Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline cybersecurity · 94d ago Advice for path to land job SOC in France cybersecurity · 94d ago Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered Cyber Defense Magazine · 94d ago Possible Major Vulnerability: Chromium used by current version of PRTG cybersecurity · 94d ago Mythos AI may be a cybersecurity threat, but it follows the rules of the game cybersecurity · 94d ago When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity Cyber Defense Magazine · 94d ago Control Checks using AI. cybersecurity · 94d ago How do native password managers clear the clipboard? cybersecurity · 94d ago VLC Media Player MKV Exploit Analysis Reverse Engineering · 94d ago Graduating CS Student but Wanna Start my Career in Cybersecurity cybersecurity · 94d ago An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support) Technical Information Security Content & Discussion · 94d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 94d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 94d ago MAXHUB Pivot Client Application All CISA Advisories · 94d ago Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI Technical Information Security Content & Discussion · 94d ago Claude-Themed Malware Campaigns cybersecurity · 94d ago DeepFake it till you make it. cybersecurity · 94d ago The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments cybersecurity · 94d ago What niche in cybersecurity should I go for, with my background in Angular & .NET ? cybersecurity · 94d ago Successor for Kaspersky Endpoint Security cybersecurity · 94d ago Exploits and vulnerabilities in Q1 2026 Securelist · 94d ago One House Democrat is pressing Commerce on the government’s spyware use CyberScoop · 94d ago Fake call logs, real payments: How CallPhantom tricks Android users WeLiveSecurity · 94d ago Detecting BEC Persistence with KQL For [Blue|Purple] Teams in Cyber Defence · 94d ago Modify md5sum of a file hacking: security in practice · 94d ago Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago cybersecurity · 94d ago SOC Analyst tier 1 (Entry Level) ?? cybersecurity · 94d ago Unpacking Russian-Iranian Private-Sector Cyber Connections For [Blue|Purple] Teams in Cyber Defence · 94d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 94d ago Made cybersecurity merch as an infosec practitioner — honest feedback welcome cybersecurity · 94d ago Fixing the password problem is as easy as 123456 WeLiveSecurity · 94d ago As AI agents become users of company data - what is needed to keep data secure? cybersecurity · 94d ago Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities. cybersecurity · 94d ago AI inference is quietly becoming a security problem cybersecurity · 94d ago is winrar 7.13 vulnerable to extraction exploits? cybersecurity · 95d ago Tried explaining internet encryption in a beginner-friendly but accurate way, feedback? cybersecurity · 95d ago Is the EC-Council CTIA Certification Worth It for Career Growth? cybersecurity · 95d ago POC Android vuln 2026 cybersecurity · 95d ago Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise cybersecurity · 95d ago Opinions on Mimecast cybersecurity · 95d ago Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution For [Blue|Purple] Teams in Cyber Defence · 95d ago What's going on in the field of Cybersecurity 🫣. cybersecurity · 95d ago How do teams preserve institutional pentest knowledge when senior testers leave? cybersecurity · 95d ago CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE cybersecurity · 95d ago Sophos NDR on Proxmox cybersecurity · 95d ago Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites Malware Analysis & Reports · 95d ago Quacc++: Automated Open Source Vulnerability Discovery Technical Information Security Content & Discussion · 95d ago A DOD contractor’s API flaw exposed military course data and service member records CyberScoop · 95d ago On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029. cybersecurity · 95d ago DOJ says ransomware gang tapped into Russian government databases cybersecurity · 95d ago DAEMON Tools devs confirm breach, release malware-free version cybersecurity · 95d ago Have there been instances where your SOC has suffered a cybersecurity attack? cybersecurity · 95d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk For [Blue|Purple] Teams in Cyber Defence · 95d ago Inadvertent Injections For [Blue|Purple] Teams in Cyber Defence · 95d ago A critical Palo Alto PAN-OS zero-day is being exploited in the wild CyberScoop · 95d ago OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM hacking: security in practice · 95d ago OpenCTI founder, Samuel Hassine, arrested and charged with CSAM cybersecurity · 95d ago Deepfake Platform cybersecurity · 95d ago Innovators Spotlight: Badge (Part II) Cyber Defense Magazine · 95d ago Trellix Licence Query cybersecurity · 95d ago CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal For [Blue|Purple] Teams in Cyber Defence · 95d ago Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML Malware Analysis & Reports · 95d ago Instructure hacker claims data theft from 8,800 schools, universities cybersecurity · 95d ago Is AI generated code creating a non-linear security problem for AppSec teams? cybersecurity · 95d ago Jailbreaking my cars infotainment system and implementing my own custom software hacking: security in practice · 95d ago Binance fixed the IP whitelist gap — but the disclosure process is still broken Technical Information Security Content & Discussion · 95d ago D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says cybersecurity · 95d ago where is the original wormgpt hacking: security in practice · 95d ago Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security cybersecurity · 95d ago Norton Antivirus and Other Norton Software cybersecurity · 95d ago Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home? cybersecurity · 95d ago We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes. cybersecurity · 95d ago Download a malware a while ago, someone trying to log into my ios account cybersecurity · 95d ago Are there any chill hacking youtubers? hacking: security in practice · 95d ago Org Restructure cybersecurity · 95d ago Non-Determinism of Maps in Golang: Why, How, and the Consequences Technical Information Security Content & Discussion · 95d ago Does SOC 2 actually reduce questionnaires, or just change them? cybersecurity · 95d ago Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views cybersecurity · 95d ago How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically? cybersecurity · 95d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Reverse Engineering · 95d ago pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI Technical Information Security Content & Discussion · 95d ago Ran phishing awareness training for 200+ non-tech employees cybersecurity · 95d ago Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware For [Blue|Purple] Teams in Cyber Defence · 95d ago Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk cybersecurity · 95d ago Vulnerability Garden Technical Information Security Content & Discussion · 95d ago Vulnerability Garden cybersecurity · 95d ago Palo Alto Firewall Zero-Day Under Active Exploitation cybersecurity · 95d ago Redefining Security Operations Through Seceon’s Open Threat Management Platform Cyber Defense Magazine · 95d ago OceanLotus suspected of using PyPI to deliver ZiChatBot malware Securelist · 95d ago Cyber Security Militias cybersecurity · 95d ago Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk cybersecurity · 95d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 95d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 95d ago Took me a decade to turn quantum computing into what programmers can easily learn, big announcement hacking: security in practice · 95d ago Lilygo T-Embed Glitching etc hacking: security in practice · 95d ago CyberSecurity Nightmares cybersecurity · 95d ago Can I use NanoKVM if it's just to turn on pc? cybersecurity · 95d ago got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something? cybersecurity · 95d ago How to learn tools for cybersecurity? cybersecurity · 95d ago 'CopyFail' attackers start cashing in on Linux flaw cybersecurity · 95d ago Anybodybodybdown for a team/studygroup? cybersecurity · 95d ago Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today? hacking: security in practice · 95d ago I was hacked due to sim card spoofing cybersecurity · 95d ago Websites with an undefined trust level: avoiding the trap Securelist · 95d ago Chrome is quietly installing a 4GB AI model on your device cybersecurity · 95d ago Dev vs Security role cybersecurity · 95d ago Discord bot C2 infrastructure Malware Analysis & Reports · 95d ago Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed For [Blue|Purple] Teams in Cyber Defence · 95d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 95d ago UAT-8302 and its box full of malware For [Blue|Purple] Teams in Cyber Defence · 95d ago Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft cybersecurity · 95d ago Oracle Debuts Monthly Critical Security Patch Updates cybersecurity · 95d ago Sec engineer / developer? cybersecurity · 95d ago When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them? cybersecurity · 95d ago Are we actually seeing more vulnerabilities or just more noise? cybersecurity · 95d ago Cybersecurity jobs in red team cybersecurity · 95d ago Question cybersecurity · 95d ago What’s the biggest mistake people make even after installing antivirus? cybersecurity · 95d ago CVE-2026-0073 Android adbd TLS client-authentication bypass For [Blue|Purple] Teams in Cyber Defence · 95d ago One KQL query you should have saved in your toolkit (most don’t) For [Blue|Purple] Teams in Cyber Defence · 95d ago New dashboard tracks ransomware groups by their reliance on Infostealer credentials cybersecurity · 95d ago ant4g0nist/pyre: Ghidra decompiler in your browser Reverse Engineering · 95d ago CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier? For [Blue|Purple] Teams in Cyber Defence · 96d ago Found a possibly interesting live attack hacking: security in practice · 96d ago What would you say if your security lead said this... cybersecurity · 96d ago What would be the goto setup in AWS for security purposes? cybersecurity · 96d ago CREST CRT Exam 2025/2026 Experiences cybersecurity · 96d ago Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside For [Blue|Purple] Teams in Cyber Defence · 96d ago Microsoft Edge stores your passwords in plaintext RAM... on purpose cybersecurity · 96d ago Export/Backup ChatGPT chats hacking: security in practice · 96d ago Como começar? cybersecurity · 96d ago Possible Password Leak? Curious if Anyone Has Seen This Before cybersecurity · 96d ago Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source! Reverse Engineering · 96d ago Not a Hack. A Handout. Inside the GTFOice.org Data Exposure cybersecurity · 96d ago Besoin de conseils sur une DMZ automatisée cybersecurity · 96d ago Microsoft, Google and xAI will let the government test their AI models before launch cybersecurity · 96d ago Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073 cybersecurity · 96d ago HyperVenom: Using Hyper-V for Ring -1 Control from Usermode Reverse Engineering · 96d ago SMB Header Signature for Tagging in Firewall cybersecurity · 96d ago Question regarding VDP cybersecurity · 96d ago Working on what i should do for the next 3 years cybersecurity · 96d ago Question for Security Professionals cybersecurity · 96d ago Do tech companies lifecycle-manage public DNS records to prevent dangling DNS? cybersecurity · 96d ago Vulnerability Summary for the Week of April 27, 2026 cybersecurity · 96d ago Scan. Secure. Simplify. — Free Web Tools Platform Technical Information Security Content & Discussion · 96d ago Cisco releases open-source ‘DNA test for AI models’ cybersecurity · 96d ago Cybersecurity is becoming too AI dependent is that a problem cybersecurity · 96d ago Foxconn Wisconsin outage raises cyber questions cybersecurity · 96d ago How stressful is GRC? cybersecurity · 96d ago News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market The Last Watchdog · 96d ago Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482) Technical Information Security Content & Discussion · 96d ago Salesforce pentesting novel techniques- how to be an apex predator Technical Information Security Content & Discussion · 96d ago Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia cybersecurity · 96d ago Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India cybersecurity · 96d ago Archer for a non-regulated medium sized company? cybersecurity · 96d ago Cybersecurity statistics of the week (April 27th - May 3rd) cybersecurity · 96d ago Reverse-engineering the 1998 Ultima Online demo server Reverse Engineering · 96d ago Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM. cybersecurity · 96d ago One-Click Refunds Are Not as Hard as You Think Blog – Forter · 96d ago 🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records For [Blue|Purple] Teams in Cyber Defence · 96d ago Where to find reliable vendors? cybersecurity · 96d ago DigiCert: Misissued code signing certificates Technical Information Security Content & Discussion · 96d ago Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts? cybersecurity · 96d ago We wrote a guide on securing Claude across the enterprise — here's the core framework (with download) cybersecurity · 96d ago Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium. cybersecurity · 96d ago Hardware reverse enginnering first project. Love some advice cybersecurity · 96d ago Microsoft Edge Stores Passwords in Process Memory, Posing Risk cybersecurity · 96d ago Currently working on cybersecurity, looking for advice cybersecurity · 96d ago Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning cybersecurity · 96d ago Major AI Clients Shipping With Broken OAuth Implementations Technical Information Security Content & Discussion · 96d ago CISO course valuation cybersecurity · 96d ago Inside Faxanadu series — deep dive into how this NES title works Reverse Engineering · 96d ago EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing Reverse Engineering · 96d ago Popular DAEMON Tools software compromised For [Blue|Purple] Teams in Cyber Defence · 96d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack For [Blue|Purple] Teams in Cyber Defence · 96d ago Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise For [Blue|Purple] Teams in Cyber Defence · 96d ago GRC Path to CISO (Certifications) cybersecurity · 96d ago Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities For [Blue|Purple] Teams in Cyber Defence · 96d ago CISOs and pentest buyers, what's the worst thing you've seen in a pentest report? cybersecurity · 96d ago How to enforce M365 Sign-in frequency on corporate laptops? cybersecurity · 96d ago CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs cybersecurity · 96d ago Built an independent directory of AI Act / AI governance tools, feedback? cybersecurity · 96d ago ScarCruft APT group compromises gaming platform in a supply-chain attack cybersecurity · 96d ago Just curious cybersecurity · 96d ago 'Copy Fail' is a real Linux security crisis wrapped in AI slop cybersecurity · 96d ago Analysis malicious DLL cybersecurity · 96d ago Cyber security free course cybersecurity · 96d ago The Insurance Industry Is Rewriting Cybersecurity Strategy Cyber Defense Magazine · 96d ago Does certification expires? cybersecurity · 96d ago HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10 Technical Information Security Content & Discussion · 96d ago IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening Malware Analysis & Reports · 96d ago Panicking Malware Analysis & Reports · 96d ago ABB B&R Automation Studio All CISA Advisories · 96d ago ABB B&R Automation Runtime All CISA Advisories · 96d ago Hitachi Energy PCM600 All CISA Advisories · 96d ago Johnson Controls CEM AC2000 All CISA Advisories · 96d ago ABB B&R PVI All CISA Advisories · 96d ago How the Story of a USB Penetration Test Went Viral darkreading · 96d ago We get paid to break into buildings for a living. Ask us anything! cybersecurity · 96d ago Pay2Key ransomware — any recovery path that’s actually worked? cybersecurity · 96d ago Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison cybersecurity · 96d ago Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF cybersecurity · 96d ago Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud Technical Information Security Content & Discussion · 96d ago How have you kept growing your knowledge in security when the job stops pushing you? cybersecurity · 96d ago Supply chain attack: DAEMON Tools Lite now contains a backdoor. Malware Analysis & Reports · 96d ago Accelerating Vulnerability Detection and Response at Oracle For [Blue|Purple] Teams in Cyber Defence · 96d ago The Danger of Multi-SSO AWS Cognito User Pools Technical Information Security Content & Discussion · 96d ago Copilot Cowork: From conversation to action across skills, integrations, and devices Microsoft 365 Blog · 96d ago The UK’s Age Verification Law Is Producing Compliance Theater cybersecurity · 96d ago Microsoft Edge: Passwords end up in memory as plaintext cybersecurity · 96d ago Do people still get viruses in 2026, or is that mostly a myth now? cybersecurity · 96d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 Technical Information Security Content & Discussion · 96d ago Mitigation script for Copy Fail vulnerability CVE-2026-31431 cybersecurity · 96d ago Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026 cybersecurity · 96d ago Is this fake too?🤣 hacking: security in practice · 96d ago Copy.fail: Why Internal LLMs Are Non-Negotiable for Security Reverse Engineering · 96d ago The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew For [Blue|Purple] Teams in Cyber Defence · 96d ago Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released cybersecurity · 96d ago A rigged game: ScarCruft compromises gaming platform in a supply-chain attack WeLiveSecurity · 96d ago DigiCert breached via malicious screensaver file cybersecurity · 96d ago I just figured out my dad use to be a Phreaker in the 1980s hacking: security in practice · 96d ago Caido Payloads and Scanner of Endpoints cybersecurity · 96d ago Proton Pass: Second-Password Bypass Through Emergency Access Technical Information Security Content & Discussion · 96d ago What of my favorite videos🙂 hacking: security in practice · 96d ago CISO Security Mind Map 2026 cybersecurity · 96d ago Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker cybersecurity · 96d ago Best tools for blocking spam calls and spam links? hacking: security in practice · 96d ago Amazon SES increasingly abused in phishing to evade detection cybersecurity · 96d ago someone else’s UI appearing on screen for split second— possible hacker?? hacking: security in practice · 96d ago AI Security Trainings cybersecurity · 96d ago Ai help cybersecurity · 96d ago ByDesign: observed behavior where file URLs remain accessible after unshare/delete cybersecurity · 96d ago Can Kali Linux still compete in cyber security or is it outdated? cybersecurity · 96d ago We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother Technical Information Security Content & Discussion · 96d ago Avoiding rouge AP detection in enterprise networks hacking: security in practice · 96d ago Who are your favorite cybersecurity YouTubers? cybersecurity · 97d ago CISOs, how are you balancing AI adoption with security risks these days? cybersecurity · 97d ago GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated. For [Blue|Purple] Teams in Cyber Defence · 97d ago dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025 For [Blue|Purple] Teams in Cyber Defence · 97d ago N-Day Research with AI: Using Ollama and n8n For [Blue|Purple] Teams in Cyber Defence · 97d ago San Diego Community College District fighting major cyberattack cybersecurity · 97d ago GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering hacking: security in practice · 97d ago San Diego Community College District fighting major cyberattack hacking: security in practice · 97d ago After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up cybersecurity · 97d ago Free resource: searchable archive of every BSides conference talk cybersecurity · 97d ago Lightning PyPI Compromise: Bun-Based Stealer cybersecurity · 97d ago Too much mother instinct? cybersecurity · 97d ago L1 SOC Analyst for ~2 years - Should I still get the Security + Certification? cybersecurity · 97d ago Do CTFs help real world security skills, or just teach patterns? cybersecurity · 97d ago Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo cybersecurity · 97d ago Should I do Security + or Network + or A+? For CompTia cybersecurity · 97d ago Bug bounty is ruining how people learn exploitation cybersecurity · 97d ago ISO/IEC 27701:2025 Scope and Location cybersecurity · 97d ago Cybersecurity's 2026 Wild Ride cybersecurity · 97d ago We built a free multiplayer game that scores prompts on AI code security. cybersecurity · 97d ago RMM Tools Fuel Stealthy Phishing Campaign darkreading · 97d ago Production Usecases cybersecurity · 97d ago Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra Reverse Engineering · 97d ago How does vCISO work? cybersecurity · 97d ago Trellix discloses data breach after source code repository hack cybersecurity · 97d ago CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path cybersecurity · 97d ago Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability darkreading · 97d ago Trellix confirms source code repo access incident cybersecurity · 97d ago Where do i find reverse engineers for actuators? Ideally in Shenzhen Reverse Engineering · 97d ago Employer Offering to Pay for my Certification test - Which one do I choose? cybersecurity · 97d ago John Strand Pay What You Can Information Security Core Skills live starting May 11th cybersecurity · 97d ago [CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2). Reverse Engineering · 97d ago Canvas Breach May Put 275M Users, 9,000 Schools at Risk cybersecurity · 97d ago Is this not such a big deal cybersecurity · 97d ago 38 CVEs in Healthcare Software Used by 100,000 Medical Providers For [Blue|Purple] Teams in Cyber Defence · 97d ago Do email link checkers need to be 100%? cybersecurity · 97d ago Cybersecurity M&A Roundup: 33 Deals Announced in April 2026 cybersecurity · 97d ago Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation Malware Analysis & Reports · 97d ago Recs for pen testing and vulnerability solutions cybersecurity · 97d ago Identify telegram account holders cybersecurity · 97d ago AI Code Security Study: 6 LLMs vs OWASP Top 10 cybersecurity · 97d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers hacking: security in practice · 97d ago Recursively fuzzing MS-RPC structures and monitoring using ETW For [Blue|Purple] Teams in Cyber Defence · 97d ago BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers cybersecurity · 97d ago Iwas developing a hacker game that transports the feeling of the 90s hacking: security in practice · 97d ago We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA cybersecurity · 97d ago Azure IaaS: Defense in depth built on secure-by-design principles Security | Microsoft Azure Blog | Microsoft Azure · 97d ago Cortex XDR Cloud Compromise Alerting cybersecurity · 97d ago Norton.com Verification Email out of the blue cybersecurity · 97d ago Atomic Red Team is now aligned with MITRE ATT&CK v19! cybersecurity · 97d ago Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX? cybersecurity · 97d ago Who are you guys using for your PCI ASV Scanning? cybersecurity · 97d ago Just passed my Security+ exam. Now what? cybersecurity · 97d ago I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work. cybersecurity · 97d ago Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this. cybersecurity · 97d ago [PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection) cybersecurity · 97d ago Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia darkreading · 97d ago Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350) cybersecurity · 97d ago An another open door to IoT devices cybersecurity · 97d ago Ideas on how to have personal google-like account synchronization system cybersecurity · 97d ago Lateral Movement - Cross-Session Activation Technical Information Security Content & Discussion · 97d ago Lateral Movement - Cross-Session Activation cybersecurity · 97d ago How did this guy even access another person's privated YouTube video without wayback machine? hacking: security in practice · 97d ago What MCP servers have actually made it into your day-to-day toolkit? cybersecurity · 97d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems hacking: security in practice · 97d ago Cyber Security Education as Self-Defence classes cybersecurity · 97d ago OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk cybersecurity · 97d ago Use.ai cybersecurity · 97d ago Educational tech giant Instructure confirms data breach, ShinyHunters claims attack cybersecurity · 97d ago [WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation Reverse Engineering · 97d ago CISA says ‘Copy Fail’ flaw now exploited to root Linux systems cybersecurity · 97d ago Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management Cyber Defense Magazine · 97d ago IPod Nano Gets Three Monitors hacking: security in practice · 97d ago IDA-MCP Is Now RE-MCP With Ghidra Support Reverse Engineering · 97d ago Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference Reverse Engineering · 97d ago Chrome "Best AdBlocker" trojanized extension - 100k downloads. hacking: security in practice · 97d ago How Dark Reading Lifted Off the Launchpad in 2006 darkreading · 97d ago Browsers making connection on port 3389 from loopback cybersecurity · 97d ago Defender Flagged DigiCert Root Certs as Malware cybersecurity · 97d ago VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases For [Blue|Purple] Teams in Cyber Defence · 97d ago “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security Securelist · 97d ago Another breach just hit Canvas (Instructure), and this one is worth a closer look. cybersecurity · 97d ago Over 40% of UK firms suffered cyber attack last year, survey finds cybersecurity · 97d ago EU should seek access to Anthropic's Mythos, Bundesbank says cybersecurity · 97d ago Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha cybersecurity · 97d ago CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation. For [Blue|Purple] Teams in Cyber Defence · 97d ago 《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition) For [Blue|Purple] Teams in Cyber Defence · 97d ago nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution. For [Blue|Purple] Teams in Cyber Defence · 97d ago 蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery. For [Blue|Purple] Teams in Cyber Defence · 97d ago IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks cybersecurity · 97d ago People in cybersecurity, tell us what was the most epic moment in your career? cybersecurity · 97d ago Prerequisites for CARTP cybersecurity · 97d ago gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives For [Blue|Purple] Teams in Cyber Defence · 97d ago Claude Mythos Cyber Wake Up cybersecurity · 97d ago [ Removed by Reddit ] cybersecurity · 97d ago /r/ReverseEngineering's Weekly Questions Thread Reverse Engineering · 97d ago is trellix from mcafee good to use in 2026? cybersecurity · 97d ago Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list cybersecurity · 97d ago Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon For [Blue|Purple] Teams in Cyber Defence · 97d ago AMSI Page Guard Bypass (Rust PoC) For [Blue|Purple] Teams in Cyber Defence · 97d ago Any good open sources that bypass modern heuristic analysis? hacking: security in practice · 97d ago Meet Bluekit: The AI-Powered All-in-One Phishing Kit For [Blue|Purple] Teams in Cyber Defence · 97d ago Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI For [Blue|Purple] Teams in Cyber Defence · 97d ago A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia For [Blue|Purple] Teams in Cyber Defence · 97d ago IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect For [Blue|Purple] Teams in Cyber Defence · 97d ago Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection For [Blue|Purple] Teams in Cyber Defence · 97d ago ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution… For [Blue|Purple] Teams in Cyber Defence · 97d ago Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia For [Blue|Purple] Teams in Cyber Defence · 97d ago [2603.28728] Study of Post Quantum status of Widely Used Protocols For [Blue|Purple] Teams in Cyber Defence · 97d ago Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin For [Blue|Purple] Teams in Cyber Defence · 97d ago Free apex hacks? hacking: security in practice · 97d ago Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning For [Blue|Purple] Teams in Cyber Defence · 97d ago Paypal Accesed by malware me being Stupid cybersecurity · 97d ago How was someone in another country able to read all my private messages without my password or clicking a link? cybersecurity · 97d ago code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint. For [Blue|Purple] Teams in Cyber Defence · 97d ago Secure Boot Inventory Data In Configuration Manager For [Blue|Purple] Teams in Cyber Defence · 97d ago EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time. For [Blue|Purple] Teams in Cyber Defence · 97d ago MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning. For [Blue|Purple] Teams in Cyber Defence · 97d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Technical Information Security Content & Discussion · 97d ago AI-powered honeypots: Turning the tables on malicious AI agents For [Blue|Purple] Teams in Cyber Defence · 97d ago Career Transition Help cybersecurity · 97d ago Alguien para hablar de cyberseguridad cybersecurity · 97d ago copy.golf — golf your exploits - smaller copy.fail exploits.. For [Blue|Purple] Teams in Cyber Defence · 98d ago DragonBreath: Dragon in the Kernel For [Blue|Purple] Teams in Cyber Defence · 98d ago What is this cybersecurity · 98d ago Your vibe-coded app is probably violating GDPR right now Technical Information Security Content & Discussion · 98d ago [SHOWCASE] Cascavel v3 hacking: security in practice · 98d ago Feeling lost and disappointed about finding a job just venting cybersecurity · 98d ago Slow at Learning/Cyber Security? cybersecurity · 98d ago Pokemon machine hacking: security in practice · 98d ago Suspicious traffic from web server cybersecurity · 98d ago Cyber security internship cybersecurity · 98d ago Mentorship Monday - Post All Career, Education and Job questions here! cybersecurity · 98d ago Isn't Windows Defender a crap anymore? cybersecurity · 98d ago GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions) Reverse Engineering · 98d ago Learning Cyber cybersecurity · 98d ago Vishing simulator cybersecurity · 98d ago Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others cybersecurity · 98d ago Worried about being tracked/banned for using an educational app on MuMu Player - Need advice cybersecurity · 98d ago Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks cybersecurity · 98d ago Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance cybersecurity · 98d ago Prompt Injection in 2026: The Five Attack Patterns That Actually Matter cybersecurity · 98d ago I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine cybersecurity · 98d ago Random trojan detected? cybersecurity · 98d ago CRTA second attempt cybersecurity · 98d ago What’s the hardest thing to learn in cybersecurity? cybersecurity · 98d ago What MCP servers are you integrating into your workflow (not exclusive to security)? cybersecurity · 98d ago Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors. For [Blue|Purple] Teams in Cyber Defence · 98d ago WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog cybersecurity · 98d ago What are like the top but unknown Cybersecurity firms? cybersecurity · 98d ago Can HTTP POST bodies be intercepted without network or host access? hacking: security in practice · 98d ago Need professionals or expert on cybersecurity related to dark web for interview cybersecurity · 98d ago A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP) cybersecurity · 98d ago Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library For [Blue|Purple] Teams in Cyber Defence · 98d ago North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory cybersecurity · 98d ago VirusTotal has one flag for this sus site Malware Analysis & Reports · 98d ago Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo Reverse Engineering · 98d ago Puzzle: Set of PoC to abuse Windows minifilters functionality For [Blue|Purple] Teams in Cyber Defence · 98d ago Ai Didn’t Break Cybersecurity, It Revealed It Cyber Defense Magazine · 98d ago Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate) cybersecurity · 98d ago Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate) Technical Information Security Content & Discussion · 98d ago Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you! Reverse Engineering · 98d ago built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4) hacking: security in practice · 98d ago Credential Dumping: Local Security Authority (LSA|LSASS.EXE) cybersecurity · 98d ago A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16 For [Blue|Purple] Teams in Cyber Defence · 98d ago Dump sql time based is too slow hacking: security in practice · 98d ago Trojan:Win32/Cerdigent.A!dha cybersecurity · 98d ago Active exploitation of cPanel/WHM critical vulnerability For [Blue|Purple] Teams in Cyber Defence · 98d ago Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. " For [Blue|Purple] Teams in Cyber Defence · 98d ago MDE flagging digi cert certificate as malicious everywhere ? cybersecurity · 98d ago North Korea rejects US cybercrime claims as 'absurd slander' hacking: security in practice · 98d ago "AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts Reverse Engineering · 98d ago 5 Qilin ransomware servers exposed over 7 months For [Blue|Purple] Teams in Cyber Defence · 98d ago is credential stuffing using openbullet2 dead in 2026? hacking: security in practice · 99d ago Anyone wanna learn the CEH or OSCP red teaming free Malware Analysis & Reports · 99d ago South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940) For [Blue|Purple] Teams in Cyber Defence · 99d ago Russian Charged in Oil and Gas Facility Hacks Pleads Guilty For [Blue|Purple] Teams in Cyber Defence · 99d ago Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax) hacking: security in practice · 99d ago How to build .NET obfuscator - Part II Reverse Engineering · 99d ago VECT ransomware: small files decrypt, large files lose their nonces For [Blue|Purple] Teams in Cyber Defence · 99d ago CTO at NCSC Summary: week ending May 3rd For [Blue|Purple] Teams in Cyber Defence · 99d ago April 27th - What happened with our feature flag configuration | The ClickUp Blog For [Blue|Purple] Teams in Cyber Defence · 99d ago Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT) hacking: security in practice · 99d ago How to exfiltrate data using only numeric outputs Technical Information Security Content & Discussion · 99d ago libghidra - SDK for automating Ghidra from Python, Rust, and C++ Reverse Engineering · 99d ago Blog: Evolving the Android & Chrome VRPs for the AI Era For [Blue|Purple] Teams in Cyber Defence · 99d ago Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis. Reverse Engineering · 99d ago RSAC 2026: The Power of Community Cyber Defense Magazine · 99d ago Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed. For [Blue|Purple] Teams in Cyber Defence · 99d ago VECT: Ransomware by design, Wiper by accident For [Blue|Purple] Teams in Cyber Defence · 99d ago VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built. For [Blue|Purple] Teams in Cyber Defence · 99d ago Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison For [Blue|Purple] Teams in Cyber Defence · 99d ago Agentic Malware Analysis: From Task Automation to Deep Analysis For [Blue|Purple] Teams in Cyber Defence · 99d ago pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner. For [Blue|Purple] Teams in Cyber Defence · 99d ago month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only For [Blue|Purple] Teams in Cyber Defence · 99d ago For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall. Technical Information Security Content & Discussion · 100d ago Small models are better at cost-to-recall than large models like Mythos for vulnerability research hacking: security in practice · 100d ago Every incident public companies have disclosed to the SEC, in one searchable database Technical Information Security Content & Discussion · 100d ago 76% of All Crypto Stolen in 2026 Is Now in North Korea darkreading · 100d ago Bluetooth Spoofed Disconnect? hacking: security in practice · 100d ago Why my macOS Messages badge lied to me (and the one-line fix) Reverse Engineering · 100d ago Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself Malware Analysis & Reports · 100d ago Running Adobe’s 1991 PostScript Interpreter in the Browser Reverse Engineering · 100d ago Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :) Reverse Engineering · 100d ago If AI's So Smart, Why Does It Keep Deleting Production Databases? darkreading · 100d ago Minecraft Malware C2 Tracking Malware Analysis & Reports · 100d ago r/netsec monthly discussion & tool thread Technical Information Security Content & Discussion · 100d ago Inside RSAC 2026 Cyber Defense Magazine · 100d ago Name That Toon: Mark of (Security) Progress darkreading · 100d ago 20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage darkreading · 100d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 100d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 100d ago Careful Adoption of Agentic AI Services All CISA Advisories · 100d ago wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ... hacking: security in practice · 100d ago Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster Technical Information Security Content & Discussion · 100d ago /r/ReverseEngineering's Triannual Hiring Thread Reverse Engineering · 100d ago In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off) Reverse Engineering · 100d ago TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack darkreading · 101d ago 🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀 hacking: security in practice · 101d ago Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug darkreading · 101d ago Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber darkreading · 101d ago Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM Security | Microsoft Azure Blog | Microsoft Azure · 101d ago Innovator Spotlight: The Open Group Cyber Defense Magazine · 101d ago Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight Reverse Engineering · 101d ago SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents The Last Watchdog · 101d ago I made a lightweight breach intelligence search engine (fully client-side) looking for feedback hacking: security in practice · 101d ago Oracle Red Bull Racing Team Revs Up Automation to Boost Security darkreading · 101d ago Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan... hacking: security in practice · 101d ago Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark Cyber Defense Magazine · 101d ago Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool hacking: security in practice · 101d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 101d ago ABB AWIN Gateways All CISA Advisories · 101d ago ABB Ability OPTIMAX All CISA Advisories · 101d ago ABB PCM600 All CISA Advisories · 101d ago ABB Edgenius Management Portal All CISA Advisories · 101d ago CISA Adds One Known Exploited Vulnerability to Catalog All CISA Advisories · 101d ago ABB Ability Symphony Plus Engineering All CISA Advisories · 101d ago ABB System 800xA, Symphony Plus IEC 61850 All CISA Advisories · 101d ago Seventeen vulnerabilities in Omi, fourteen days of silence Technical Information Security Content & Discussion · 101d ago High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940) Technical Information Security Content & Discussion · 101d ago This month in security with Tony Anscombe – April 2026 edition WeLiveSecurity · 101d ago HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try! Reverse Engineering · 101d ago GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter). Reverse Engineering · 101d ago Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India Securelist · 101d ago Copy Fail — 732 Bytes to Root hacking: security in practice · 101d ago ZDI-CAN-30796: Docker ZDI: Upcoming Advisories · 101d ago Claude Mythos Fears Startle Japan's Financial Services Sector darkreading · 102d ago Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root Technical Information Security Content & Discussion · 102d ago Reverse Engineering With AI Unearths High-Severity GitHub Bug darkreading · 102d ago AI Finds 38 Security Flaws in Electronic Health Record Platform darkreading · 102d ago The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs Technical Information Security Content & Discussion · 102d ago The Thymeleaf Template Injection That Only Hurts If You Let It Technical Information Security Content & Discussion · 102d ago Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error darkreading · 102d ago GitHub fixes RCE flaw that gave access to millions of private repos hacking: security in practice · 102d ago Minirat malware deployed via NPM targeting macOS machines Malware Analysis & Reports · 102d ago Set up automated dependency scanning after the recent npm/PyPI supply chain attacks Technical Information Security Content & Discussion · 102d ago Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints Cyber Defense Magazine · 102d ago Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities darkreading · 102d ago I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway Reverse Engineering · 102d ago Adapting Zero Trust Principles to Operational Technology All CISA Advisories · 102d ago How to download Kaggle dataset safely...? hacking: security in practice · 102d ago VECT Ransomware Is Actually a Wiper Malware Analysis & Reports · 102d ago VECT Ransomware Is Actually a Wiper hacking: security in practice · 102d ago The Malware Factory: GLASSWORM Forensics in Open VSX Malware Analysis & Reports · 103d ago A Route to Root in a 4G Industrial Router Technical Information Security Content & Discussion · 103d ago BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures darkreading · 103d ago NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later darkreading · 103d ago Feuding Ransomware Groups Leak Each Other's Data darkreading · 103d ago Vidar Rises to Top of Chaotic Infostealer Market darkreading · 103d ago Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore Malware Analysis & Reports · 103d ago Innovator Spotlight: Puneet Bhatnagar Cyber Defense Magazine · 103d ago Flipper Blackhat April Roundup! hacking: security in practice · 103d ago Building a perfect clone of 1993 game SimTower (via RE) Reverse Engineering · 103d ago [ Removed by Reddit ] Malware Analysis & Reports · 103d ago [VulnPath Update] Automated Email Alerting & CISA KEV Feed hacking: security in practice · 103d ago Ikeja Electric Distribution Ransomware Malware Analysis & Reports · 103d ago Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain darkreading · 103d ago [Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses) Technical Information Security Content & Discussion · 103d ago How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema Reverse Engineering · 103d ago AI solved our CTF in 6min Reverse Engineering · 103d ago The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords Technical Information Security Content & Discussion · 103d ago Cybersecurity Risks in 2026 Cyber Defense Magazine · 103d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 103d ago NSA GRASSMARLIN All CISA Advisories · 103d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog All CISA Advisories · 103d ago Recently updated a authentic minecraft mod launcher called Modrinth Malware Analysis & Reports · 103d ago GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control The Last Watchdog · 103d ago 89 vulnerabilities in XAPI / Citrix XenServer Technical Information Security Content & Discussion · 103d ago Example structure for evidence-based vulnerability reports Reverse Engineering · 103d ago Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters Cyber Defense Magazine · 104d ago [ Removed by Reddit ] Technical Information Security Content & Discussion · 104d ago UNC6692 Combines Social Engineering, Malware, Cloud Abuse darkreading · 104d ago Innovator Spotlight: TokenCore Cyber Defense Magazine · 104d ago Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025) Technical Information Security Content & Discussion · 104d ago Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary Technical Information Security Content & Discussion · 104d ago This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0 Malware Analysis & Reports · 104d ago Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation darkreading · 104d ago FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures The Last Watchdog · 104d ago Platform Engineering: The Rise of a Disciplinary Rethink Cyber Defense Magazine · 104d ago Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely Malware Analysis & Reports · 104d ago 60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea? Cyber Defense Magazine · 104d ago MCPwned: a Burp Suite extension for auditing MCP servers Technical Information Security Content & Discussion · 104d ago From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense Cyber Defense Magazine · 105d ago New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses Malware Analysis & Reports · 106d ago HackTheBox - Sorcery IppSec · 106d ago Save time and use Zig to write your Malware POC Malware Analysis & Reports · 106d ago Cracking CastleLoader’s Inno Setup Password Malware Analysis & Reports · 106d ago I built a C2 framework that uses Discord and Telegram for communication Malware Analysis & Reports · 107d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog Alerts · 107d ago CISA Adds Four Known Exploited Vulnerabilities to Catalog All CISA Advisories · 107d ago The calm before the ransom: What you see is not all there is WeLiveSecurity · 107d ago PhantomRPC: A new privilege escalation technique in Windows RPC Securelist · 107d ago fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet. Malware Analysis & Reports · 107d ago Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet Malware Analysis & Reports · 108d ago PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs Malware Analysis & Reports · 108d ago Budgiekit - gdi malware maker (for educational purporses only) Malware Analysis & Reports · 108d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 108d ago SpiceJet Online Booking System All CISA Advisories · 108d ago Carlson Software VASCO-B GNSS Receiver All CISA Advisories · 108d ago Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera All CISA Advisories · 108d ago Milesight Cameras All CISA Advisories · 108d ago Defending Against China-Nexus Covert Networks of Compromised Devices All CISA Advisories · 108d ago Yadea T5 Electric Bicycle All CISA Advisories · 108d ago Intrado 911 Emergency Gateway (EGW) All CISA Advisories · 108d ago GopherWhisper: A burrow full of malware WeLiveSecurity · 108d ago News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category The Last Watchdog · 109d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 109d ago 19 confirmed repos tied to the same GitHub malware campaign Malware Analysis & Reports · 109d ago Defending Against China-Nexus Covert Networks of Compromised Devices CISA Cybersecurity Advisories · 110d ago IOCX v0.7.0 — deterministic heuristics + adversarial PE samples Malware Analysis & Reports · 110d ago New NGate variant hides in a trojanized NFC payment app WeLiveSecurity · 110d ago Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one The Last Watchdog · 111d ago Supply Chain Compromise Impacts Axios Node Package Manager Alerts · 111d ago CISA Adds Eight Known Exploited Vulnerabilities to Catalog Alerts · 111d ago FakeWallet crypto stealer spreading through iOS apps in the App Store Securelist · 111d ago What the ransom note won’t say WeLiveSecurity · 111d ago That data breach alert might be a trap WeLiveSecurity · 114d ago Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business Blog Articles - Identity Insights | Trulioo · 115d ago Supply chain dependencies: Have you checked your blind spot? WeLiveSecurity · 115d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 115d ago News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security The Last Watchdog · 116d ago Threat landscape for industrial automation systems in Q4 2025 Securelist · 116d ago CISA Adds Two Known Exploited Vulnerabilities to Catalog Alerts · 117d ago GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags The Last Watchdog · 117d ago CISA Adds Seven Known Exploited Vulnerabilities to Catalog Alerts · 118d ago JanelaRAT: a financial threat targeting users in Latin America Securelist · 118d ago Recovery scammers hit you when you’re down: Here’s how to avoid a second strike WeLiveSecurity · 121d ago News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk The Last Watchdog · 121d ago The long road to your crypto: ClipBanker and its marathon infection chain Securelist · 122d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 123d ago Financial cyberthreats in 2025 and the outlook for 2026 Securelist · 123d ago FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense The Last Watchdog · 124d ago As breakout time accelerates, prevention-first cybersecurity takes center stage WeLiveSecurity · 124d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 125d ago Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure CISA Cybersecurity Advisories · 125d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 129d ago Azure IaaS: Keep critical applications running with built-in resiliency at scale Security | Microsoft Azure Blog | Microsoft Azure · 130d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 130d ago Digital assets after death: Managing risks to your loved one’s digital estate WeLiveSecurity · 130d ago A laughing RAT: CrystalX combines spyware, stealer, and prankware features Securelist · 130d ago This month in security with Tony Anscombe – March 2026 edition WeLiveSecurity · 131d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 132d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 135d ago RSAC 2026 wrap-up – Week in security with Tony Anscombe WeLiveSecurity · 135d ago A cunning predator: How Silver Fox preys on Japanese firms this tax season WeLiveSecurity · 135d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 136d ago An AI gateway designed to steal your data Securelist · 136d ago Coruna: the framework used in Operation Triangulation Securelist · 136d ago CISA Adds One Known Exploited Vulnerability to Catalog Alerts · 137d ago Virtual machines, virtually everywhere – and with real security gaps WeLiveSecurity · 137d ago Cloud workload security: Mind the gaps WeLiveSecurity · 138d ago What is Customer Due Diligence (CDD) Blog Articles - Identity Insights | Trulioo · 139d ago Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud Blog Articles - Identity Insights | Trulioo · 142d ago CISA Adds Five Known Exploited Vulnerabilities to Catalog Alerts · 142d ago Move fast and save things: A quick guide to recovering a hacked account WeLiveSecurity · 142d ago EDR killers explained: Beyond the drivers WeLiveSecurity · 143d ago Face value: What it takes to fool facial recognition WeLiveSecurity · 149d ago Cyber fallout from the Iran war: What to have on your radar WeLiveSecurity · 150d ago AML, KYC and Identity Verification in Australia Blog Articles - Identity Insights | Trulioo · 151d ago SSL/TLS Certificate Lifespans Are Decreasing to 200 Days InfoSec Insights · 151d ago AI in Tax Season: Risks, Scams, and How to Protect Your Data Fraud Prevention Archives - Alloy Silverstein · 157d ago Security-driven Rapid Release - Pwn2Own Documentary (Part 4) LiveOverflow · 158d ago Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure Security | Microsoft Azure Blog | Microsoft Azure · 158d ago Firefox JIT Bug - Pwn2Own Documentary (Part 3) LiveOverflow · 161d ago Tax Season Scams to Watch For This Year Fraud Prevention Archives - Alloy Silverstein · 164d ago The First Exploit - Pwn2Own Documentary (Part 2) LiveOverflow · 165d ago The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1) LiveOverflow · 168d ago I built a kernel-level EDR and hit architectural walls I didn’t expect Malware Analysis & Reports · 171d ago Update your detection rules: New remote access Trojan Malware Analysis & Reports · 172d ago Criminals are using AI website builders to clone major brands Malware Analysis & Reports · 172d ago Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants) Malware Analysis & Reports · 173d ago Azure reliability, resiliency, and recoverability: Build continuity by design Security | Microsoft Azure Blog | Microsoft Azure · 173d ago PE Loader For Fileless Malware Malware Analysis & Reports · 174d ago Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers Malware Analysis & Reports · 174d ago AWAKE - Android Wiki of Attacks, Knowledge & Exploits Malware Analysis & Reports · 174d ago I built a Chrome extension that scans for malicious extensions (yes, I see the irony) Malware Analysis & Reports · 174d ago Questions regarding malicious pdf's Malware Analysis & Reports · 176d ago AV persistence bypass techniques Malware Analysis & Reports · 176d ago Avalon Linux Bot Malware Analysis Malware Analysis & Reports · 177d ago Leveling up in Windows malware research Malware Analysis & Reports · 178d ago Emerging Ransomware: BQTLock and GREENBLOOD Malware Analysis & Reports · 179d ago Malware Development POCs Malware Analysis & Reports · 180d ago Suspicious code in Up-work linked repository. Malware Analysis & Reports · 180d ago We hid backdoors in binaries — Opus 4.6 found 49% of them Malware Analysis & Reports · 180d ago 👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡 Malware Analysis & Reports · 181d ago Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions Malware Analysis & Reports · 181d ago Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer Malware Analysis & Reports · 183d ago Nyxara Malware Analysis & Reports · 185d ago When Fraud Becomes Background Noise: The Industrialization of Digital Deception Blog Articles - Identity Insights | Trulioo · 216d ago The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage Blog Articles - Identity Insights | Trulioo · 216d ago The End of Static KYB: Business Identity in Constant Motion Blog Articles - Identity Insights | Trulioo · 216d ago Know Your Agent: The Next Chapter in Digital Trust Blog Articles - Identity Insights | Trulioo · 216d ago When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage Blog Articles - Identity Insights | Trulioo · 216d ago Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration Blog Articles - Identity Insights | Trulioo · 235d ago Beware of Misleading Tax Advice on Social Media Fraud Prevention Archives - Alloy Silverstein · 332d ago Scammers Up Their Game With AI Fraud Prevention Archives - Alloy Silverstein · 334d ago Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs STÖK · 350d ago The Essential Guide to Safeguarding Your Online Passwords Fraud Prevention Archives - Alloy Silverstein · 411d ago How FIN6 Exfiltrates Files Over FTP HackerSploit · 487d ago From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi LiveOverflow · 488d ago The German Hacking Championship LiveOverflow · 513d ago Beware: Tax Season is Scam Season Fraud Prevention Archives - Alloy Silverstein · 522d ago Do you know this common Go vulnerability? LiveOverflow · 527d ago Stop Scams: Fraud Prevention Starts with Your Employees Fraud Prevention Archives - Alloy Silverstein · 536d ago Emulating FIN6 - Active Directory Enumeration Made EASY HackerSploit · 538d ago The SECRET to Embedding Metasploit Payloads in VBA Macros HackerSploit · 543d ago Offensive VBA 0x4 - Reverse Shell Macro with Powercat HackerSploit · 552d ago Offensive VBA 0x3 - Developing PowerShell Droppers HackerSploit · 558d ago Offensive VBA 0x2 - Program & Command Execution HackerSploit · 562d ago Offensive VBA 0x1 - Your First Macro HackerSploit · 564d ago Emulating FIN6 - Gaining Initial Access (Office Word Macro) HackerSploit · 570d ago FIN6 Adversary Emulation Plan (TTPs & Tooling) HackerSploit · 573d ago Developing An Adversary Emulation Plan HackerSploit · 573d ago Introduction To Advanced Persistent Threats (APTs) HackerSploit · 578d ago Introduction To Adversary Emulation HackerSploit · 599d ago ‘Tis the Season for Holiday Shopping Scams Fraud Prevention Archives - Alloy Silverstein · 608d ago Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion HackerSploit · 608d ago Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1) LiveOverflow · 662d ago My theory on how the webp 0day was discovered #short LiveOverflow · 678d ago My theory on how the webp 0day was discovered (BLASTPASS) LiveOverflow · 679d ago Learn Android Hacking! - University Nevada, Las Vegas (2024) LiveOverflow · 705d ago DEF CON & Black Hat Trip 2024 LiveOverflow · 719d ago Planning Red Team Operations | Scope, ROE & Reporting HackerSploit · 748d ago Mapping APT TTPs With MITRE ATT&CK Navigator HackerSploit · 752d ago IRS Issues “Dirty Dozen” Fraud Warnings Fraud Prevention Archives - Alloy Silverstein · 793d ago IRS Identity Theft Season Begins Now Fraud Prevention Archives - Alloy Silverstein · 923d ago Finding The .webp Vulnerability in 8s (Fuzzing with AFL++) LiveOverflow · 930d ago Winter vanlife = good times STÖK · 952d ago What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth! STÖK · 959d ago Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma STÖK · 965d ago IS THIS THE END? STÖK · 1025d ago Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites STÖK · 1180d ago The World’s Identity Platform Blog Articles - Identity Insights | Trulioo · 1286d ago How to turn bugs into a "passive" income stream! ft Detectify's Almroot STÖK · 1420d ago HOW DID THIS HAPPEN!? (13370822 LHE VLOG) STÖK · 1434d ago Student Loan Breach Exposes 2.5M Records Threatpost · 1439d ago Watering Hole Attacks Push ScanBox Keylogger Threatpost · 1440d ago Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms Threatpost · 1441d ago Ransomware Attacks are on the Rise Threatpost · 1444d ago Cybercriminals Are Selling Access to Chinese Surveillance Cameras Threatpost · 1445d ago Twitter Whistleblower Complaint: The TL;DR Version Threatpost · 1446d ago Firewall Bug Under Active Attack Triggers CISA Warning Threatpost · 1447d ago Fake Reservation Links Prey on Weary Travelers Threatpost · 1448d ago iPhone Users Urged to Update to Patch 2 Zero-Days Threatpost · 1451d ago Google Patches Chrome’s Fifth Zero-Day of the Year Threatpost · 1452d ago Q: How to write a BUG BOUNTY report that actually gets paid? STÖK · 1550d ago KYC: 3 Steps to Achieving Know Your Customer Compliance Blog Articles - Identity Insights | Trulioo · 1557d ago facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques.. STÖK · 1564d ago AML Compliance Checklist: Best Practices for Anti-Money Laundering Blog Articles - Identity Insights | Trulioo · 1572d ago Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!) STÖK · 1578d ago Q: HOW do you get started in bug bounty?? How do you build your automation?! STÖK · 1592d ago Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR) STÖK · 1606d ago
Latest
Help Net SecurityHow to report an AI Act violation in the EUDEFCONConferenceDEF CON 34 - Video Team - Voting Machine Hacking VillageDEFCONConferenceDEF CON 34 - VideoTeam - Cliff Stoll AfterHoursDavid BombalDo You Need a VPN in 2026? Here’s the TruthLatest newsMade by Google 2026: How to watch and what to expect from at the Pixel 11 eventMSRC Security Update GuideCVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi objectMSRC Security Update GuideCVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardownMSRC Security Update GuideCVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest modeMSRC Security Update GuideCVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warningMSRC Security Update GuideCVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()MSRC Security Update GuideCVE-2026-64567 btrfs: reject free space cache with more entries than pagesMSRC Security Update GuideCVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=nMSRC Security Update GuideCVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error pathMSRC Security Update GuideCVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parserMSRC Security Update GuideCVE-2026-64574 wifi: mac80211: tear down new links on vif update error pathMSRC Security Update GuideCVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()MSRC Security Update GuideCVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()MSRC Security Update GuideCVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsertMSRC Security Update GuideCVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()MSRC Security Update GuideCVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2Help Net SecurityHow to report an AI Act violation in the EUDEFCONConferenceDEF CON 34 - Video Team - Voting Machine Hacking VillageDEFCONConferenceDEF CON 34 - VideoTeam - Cliff Stoll AfterHoursDavid BombalDo You Need a VPN in 2026? Here’s the TruthLatest newsMade by Google 2026: How to watch and what to expect from at the Pixel 11 eventMSRC Security Update GuideCVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi objectMSRC Security Update GuideCVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardownMSRC Security Update GuideCVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest modeMSRC Security Update GuideCVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warningMSRC Security Update GuideCVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()MSRC Security Update GuideCVE-2026-64567 btrfs: reject free space cache with more entries than pagesMSRC Security Update GuideCVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=nMSRC Security Update GuideCVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error pathMSRC Security Update GuideCVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parserMSRC Security Update GuideCVE-2026-64574 wifi: mac80211: tear down new links on vif update error pathMSRC Security Update GuideCVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()MSRC Security Update GuideCVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()MSRC Security Update GuideCVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsertMSRC Security Update GuideCVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()MSRC Security Update GuideCVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2
By Source
Feeds organized so you can skim by site.
Density
Sort
DE
DEFCONConference
7h ago · 15 items
DEF CON 34 - Video Team - Voting Machine Hacking Village
7h ago
DEF CON 34 - VideoTeam - Cliff Stoll AfterHours
8h ago
DEF CON 34 - Video Team - Car Hacking Village - Charger Hacking
1d ago
DEF CON 34 - Video Team - Hak5 - Darren Kitchen
1d ago
DEF CON 34 - Video Team - AI Hacking Village - Pokemon
1d ago
DEF CON 34 - Video Team - No Starch Press
1d ago
DEF CON 34 - Video Team - Goon Questions -Guzi Media
1d ago
DEF CON 34 - Video Team -Bug Bounty Village
1d ago
DEF CON 34 - Video Team - DC Nextgen Community - Bia
1d ago
DEF CON 34 - Video Team - Maritime Hacking Village
1d ago
DEF CON 34 - Video Team - Battle of the Bots - Lisa
1d ago
DEF CON 34 - Video Team - DEF COIN 34 Badge - Bunnie Huang
1d ago
DEF CON 34 - Video Team - 'Lights in Dark Rooms' premiere at Movie Night Friday 8pm in W222
2d ago
DEF CON 34 - Video Team - EFF Update - Cindy Cohn
2d ago
DEF CON 34 - Video Team - DEF CON Groups Highlight DC256
3d ago
15 loaded
DB
David Bombal
14h ago · 15 items
Do You Need a VPN in 2026? Here’s the Truth
14h ago
1.5 Gbps Internet using your old telephone cables?
7d ago
Rediscover Maltego in 2026
10d ago
Qubes OS explained: assume you will get hacked
14d ago
You need to learn Maltego in 2026
17d ago
Want To Learn (For FREE) About A Self-Driving Network?
18d ago
The End of TOKENMAXXING?
18d ago
Is Cat7 a SCAM?
26d ago
Cisco's Agents Reason Like a CCIE
27d ago
Install GrapheneOS Before Your Phone Becomes the Checkpoint
28d ago
Unveiled: Cisco Deep Reasoning
34d ago
Why Apple Hide My Email FAILS
35d ago
New to Linux? This is the best place to start!
35d ago
WARNING: AI tracks your face
37d ago
Is DEFCON for you?
40d ago
15 loaded
LN
Latest news
17h ago · 20 items
Made by Google 2026: How to watch and what to expect from at the Pixel 11 event
17h ago
Google is set to announce its Pixel 11 series phones - here's what we know.
This 6-port USB-C charger replaced my ugly power brick - and powers my entire desk
2d ago
The Satechi ChargeView 240W desktop charger ticks all the right boxes for this charging geek.
I was loyal to T-Mobile for 10 years, but switching to Mint slashed my bill - by a lot
2d ago
The inconsistent service, shady upcharges, and uptick in better-valued competitors made the choice easy.
Samsung Galaxy Watch 9 review: Health data overload, but built for the future
2d ago
Samsung's latest smartwatch introduces new metrics, a longer-lasting battery, and hints at the future of wearables.
This Bluetooth-only Marshall home speaker sounds so good, I can forgive the missing Wi-Fi
2d ago
The Marshall Stanmore IV is a more expensive home speaker, but there's so much to like that $430 sounds like a good value.
Your phone doesn't block SIM swapping attacks by default: Turn on these carrier settings now
2d ago
A SIM swapping attack could compromise your phone, your personal accounts, and even your identity. Here's how to thwart them.
Samsung Galaxy Z Fold 8 review: The compact foldable I've wanted all along
2d ago
With its unique size, the Galaxy Z Fold 8 is a refreshing take on foldable phones, and I'm all for it.
I read Microsoft's Windows 11 'quality' progress report - and the subtext says it all
2d ago
Microsoft's latest progress report details much-needed Windows 11 improvements in reliability, performance, stability, and usability. But here's what else I see.
I compared Google's pricier Pixel 11 series to Samsung's Galaxy lineup - here's the better value now
2d ago
The Pixel 11 may cost more, but Google's software advantage may make it worth it for you.
Apple rushes out emergency fix for screen sharing flaw on Macs - update ASAP
2d ago
The updates were unexpected. Apple must have considered this flaw serious enough to warrant an immediate fix.
I'm a diehard OnePlus user: Here's my plan now that the company is leaving North America
2d ago
What do cybersecurity leaders want in staff? These 3 skills beat certifications and experience
2d ago
How I survive summer without AC: My top hot weather coping tips, tricks, and gadgets
2d ago
Wi-Fi 7 adoption in the US quadrupled in a year - is it time to upgrade?
2d ago
My 10 favorite gadgets to upgrade your school or work setup this fall
2d ago
The best Samsung Galaxy Z Flip 8 cases: Expert recommended
2d ago
The best electric screwdrivers of 2026: Expert tested and reviewed
2d ago
The best Samsung Galaxy Z Fold 8 and Fold 8 Ultra cases of 2026: Expert recommended
2d ago
Google's new Pixel 11 series comes next week - here's what we know from leaks
3d ago
6 must-have travel gadgets, according to industry experts
3d ago
20 loaded
MS
MSRC Security Update Guide
19h ago · 20 items
CVE-2026-64584 usb: gadget: f_midi: cancel pending IN work before freeing the midi object
19h ago
CVE-2026-64583 usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown
19h ago
CVE-2026-64604 KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode
19h ago
CVE-2026-64590 dma-buf/udmabuf: skip redundant cpu sync to fix cacheline EEXIST warning
19h ago
CVE-2026-64577 gtp: check skb_pull_data() return in gtp1u_send_echo_resp()
19h ago
CVE-2026-64567 btrfs: reject free space cache with more entries than pages
19h ago
CVE-2026-64569 mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n
19h ago
CVE-2026-64572 ipv4: fib: free fib_alias with kfree_rcu() on insert error path
19h ago
CVE-2026-64573 Bluetooth: qca: fix NVM tag length underflow in TLV parser
19h ago
CVE-2026-64574 wifi: mac80211: tear down new links on vif update error path
19h ago
CVE-2026-64580 xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst()
19h ago
CVE-2026-64576 nexthop: initialize extack in nh_res_bucket_migrate()
19h ago
CVE-2026-64579 xfrm: policy: preallocate inexact bins before xfrm_hash_rebuild reinsert
19h ago
CVE-2026-64571 wifi: p54: validate RX frame length in p54_rx_eeprom_readback()
19h ago
CVE-2026-64578 ksmbd: validate compound request size before reading StructureSize2
19h ago
CVE-2026-64562 KVM: nVMX: Hide shadow VMCS right after VMCLEAR
19h ago
CVE-2026-64565 Input: ims-pcu - fix heap-buffer-overflow in ims_pcu_process_data()
19h ago
CVE-2026-64564 sctp: don't free the ASCONF's own transport in DEL-IP processing
19h ago
CVE-2026-64561 KVM: x86: Check for invalid/obsolete root *after* making MMU pages available
19h ago
CVE-2026-64560 posix-cpu-timers: Prevent UAF caused by non-leader exec() race
19h ago
20 loaded
IP
IppSec
1d ago · 15 items
HackTheBox - Helix
1d ago
HackTheBox - Kobold
8d ago
HackTheBox - Fries
15d ago
HackTheBox Logging
22d ago
HackTheBox - CCTV
29d ago
HackTheBox - DevArea
36d ago
HackTheBox - WingData
43d ago
HackTheBox - Nanocorp
50d ago
HackTheBox - VariaType
57d ago
HackTheBox - Facts
64d ago
HackTheBox - Interpreter
71d ago
HackTheBox - MonitorsFour
78d ago
HackTheBox - Pterodactyl
85d ago
HackTheBox - Overwatch
92d ago
HackTheBox - Sorcery
106d ago
15 loaded
BL
BleepingComputer
1d ago · 15 items
Hackers breach TrueConf to trojanize client installers with backdoors
1d ago
The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors.
Metabase SQLi zero-day exploited in customer data-theft attacks
2d ago
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally.
Unlimited Technology Systems breach impacts 3.8 million people
2d ago
Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.
Levi Strauss & Co. says hackers stole corporate data in cyberattack
2d ago
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.
Real emails, hijacked payments: Two H1 2026 attack chains
2d ago
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments.
North Carolina Ports confirms cyberattack disrupting operations
2d ago
The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port.
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
3d ago
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna.
ClickFix attack pushes macOS infostealer for crypto theft attacks
3d ago
A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials.
Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group
3d ago
A recent wave of cyberattacks targeting hedge funds, private-equity firms, and other financial organizations has been linked to UNC6671, an extortion group reportedly associated with the BlackFile campaign extortion group.
Swiss government SharePoint breach compromised 200 accounts
3d ago
Switzerland's federal IT office says hackers exploited vulnerabilities to breach its Microsoft SharePoint servers and compromised approximately 200 accounts.
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
3d ago
Meta AI model hacked a company during misconfigured cyber test
3d ago
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
3d ago
Ransom Cartel ransomware creator sentenced to 16 years in prison
4d ago
Canadian pleads guilty to Snowflake cloud data-theft attacks
4d ago
15 loaded
SE
SecurityWeek
1d ago · 10 items
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
1d ago
In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street
2d ago
Vishing Extortion Group UNC6671 Rebrands After Making Millions
2d ago
Truck Brake Controller’s Safety Recall Doubled as Hidden Security Fix
2d ago
Black Hat USA 2026 – Summary of Vendor Announcements (Part 4)
2d ago
Microsoft, Apple Release Fresh Security Updates
2d ago
3.8 Million Impacted by Unlimited Technology Systems Data Breach
2d ago
Critical Vulnerabilities Patched With Chrome 151 Update
2d ago
Snowflake Hacker Pleads Guilty in US Court
3d ago
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
3d ago
SL
Security Latest
1d ago · 20 items
Flock’s Plans for Rideshare Dashcams and Coaching Police, Revealed
1d ago
Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All
1d ago
Hackers Stalked Me by Hijacking a Smartwatch for Kids
3d ago
OpenAI Didn’t Notice Its AI Agents Using a Message Board to Plan Their Hacking Spree
4d ago
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
4d ago
OpenAI’s Browser Could Be Hijacked to Spam Your WhatsApp Contacts
4d ago
DHS Wants Protesters’ Signal Group Chats
4d ago
The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
4d ago
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
4d ago
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
4d ago
OK, Well, Rogue AI Agents Are Hacking Again
5d ago
Landmark Deal Would Officially Add Laser Weapons to US Army Arsenal
5d ago
ICE Collected Nearly 1 Million People’s DNA Last Year—Including Young Children
6d ago
8 Best Password Managers (2026), Tested and Reviewed
7d ago
7 States’ Water Systems Hit by Cyberattacks Likely Tied to Iran
8d ago
The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier
8d ago
The New Defcon Badges Pack a Unique Open Source Chip That Doubles as a Security Key
9d ago
Anthropic Says Claude Hacked Into 3 Organizations During Cybersecurity Tests
10d ago
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
10d ago
Chrome Needs Twice-a-Week Patching Thanks to AI Bug Hunting
10d ago
20 loaded
TH
The Hacker News
1d ago · 20 items
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
1d ago
New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens
1d ago
Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication
1d ago
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
1d ago
Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
1d ago
Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer
2d ago
ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets
2d ago
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
2d ago
New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP
2d ago
Growing Up The Hard Way
2d ago
18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
2d ago
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
2d ago
Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails
2d ago
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
2d ago
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
2d ago
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
2d ago
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
2d ago
New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts
3d ago
Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.9 CVSS Score Bugs
3d ago
New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs
3d ago
20 loaded
BH
Black Hat
2d ago · 15 items
When Queues Become Vulnerabilities: Reverse Engineering GCD, XPC Races, and macOS Detection
2d ago
Black Hat USA Briefings: Kinetic Prompt Injection: Agent Compromise With a Physical Blast Radius
2d ago
Black Hat USA Opening Session: Disruption, Defense and Operational Readiness
3d ago
Black Hat USA 2026 Opening Session: Cyber Power in the Age of AI
3d ago
Black Hat USA 2026 Keynote: Vulnerability Research in the Agentic Age
3d ago
Black Hat USA 2026 Keynote: The End of Rare Defending When Offense Is Cheap
3d ago
Black Hat USA 2026: The 'Breaking' News: The OpenAI–Hugging Face Incident
3d ago
Why Black Hat Matters | Black Hat Stories
9d ago
Black Hat Stories | Daniel Cuthbert, Black Hat Training Review Board Member
9d ago
Cyber War Forum: The Critical Questions No One Has Real Answers To
10d ago
Black Hat Asia 2026 | Keynote: From Prompt Tricks to Autonomous Hackers
11d ago
Black Hat Intercepted | James Kettle, Director of Research at Portswicker
16d ago
Black Hat Stories | Where Cybersecurity Professionals Go to Learn
16d ago
Black Hat Stories | Gaurav Keerthi, CEO and Founder of StrongKeep
16d ago
Black Hat USA 2026 - New Features
17d ago
15 loaded
CS
Cisco Security Advisory
2d ago · 20 items
Cisco Catalyst SD-WAN Manager Information Disclosure Vulnerability
2d ago
A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficien...
ClamAV Vulnerabilities Affecting Cisco Products: August 2026
2d ago
Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details section of this advisory. For...
Cisco Advance Notification for Publication of August 5, 2026, Security Advisories
4d ago
On August 5, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: Catalyst SD-WAN Integra...
Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability
4d ago
A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due t...
Cisco Integrated Management Controller Cross-Site Scripting Vulnerability
4d ago
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnera...
Cisco RoomOS Logging Subsystem Information Disclosure Vulnerability
4d ago
A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could ...
Cisco IOS XE Software Blocks Extensible Exchange Protocol Denial of Service Vulnerability
4d ago
A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due...
Cisco IOS XE Software SNMP Denial of Service Vulnerability
4d ago
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This ...
Cisco IOS Software and IOS XE Software Extensible Messaging Client Protocol Denial of Service Vulnerability
4d ago
A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of servi...
Cisco IOS XE Software Security Hardening Release: August 2026
4d ago
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that add...
Cisco Integrated Management Controller Argument Injection Vulnerabilities
4d ago
Cisco Terminal Services Agent Firewall Rules Bypass Vulnerability
4d ago
Cisco Catalyst SD-WAN Software Security Hardening Release: August 2026
4d ago
Cisco IOS XE Software Web-Based Management Interface Denial of Service Vulnerability
4d ago
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
4d ago
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability
4d ago
Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability
19d ago
Cisco Identity Services Engine Stored Cross-Site Scripting Vulnerabilities
20d ago
Cisco Advance Notification for Publication of July 15, 2026, Security Advisories
25d ago
Cisco RoomOS Security Hardening Release: July 2026
25d ago
20 loaded
TR
The Record from Recorded Future News
2d ago · 5 items
Water utilities group partners with DEF CON offshoot for Water Watch Center
2d ago
US cyber ambassador nominee Cassady confirmed in Senate
2d ago
New Mexico judge orders Meta to pay $567 million in kids online safety case
2d ago
Military device manufacturer discloses cyber incident to SEC
2d ago
Irregular, firm behind AI hacking incidents, won't say if there were more
2d ago
CY
CyberScoop
2d ago · 179 items
More than half of AI-generated patches are broken
2d ago
Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
2d ago
Capitol Hill wants to know if executive branch, foreign allies coordinated enough to combat scams
3d ago
Despite federal warnings, thousands of U.S. industrial controllers used in water systems remain exposed online
3d ago
Ransom Cartel creator sentenced to 16 years in prison
3d ago
The water sector just got it’s wake-up call. Again.
3d ago
Snowflake hacker pleads guilty, faces up to 32 years in prison
4d ago
Tom Cotton prods Treasury for tax code tweaks to modernize OT
4d ago
Open-source software’s archenemy TeamPCP goes back further than anyone thought
4d ago
AI is getting better at election facts, but voters shouldn’t rely on it
4d ago
National cyber director lays out White House plans to secure AI without writing new rules
5d ago
AISI, OpenAI report more ‘unsanctioned’ model hacks
5d ago
Public interest coalition urges Congress to investigate OpenAI, Hugging Face hack
6d ago
CrowdStrike: AI is now both the weapon and the target in cyberattacks
6d ago
Trump blames Minnesota for cyberattacks on water sector, drawing pushback from cyber world
9d ago
What the Hugging Face breach reveals about defense in the age of agentic AI
9d ago
Anthropic says its AI accidentally hacked three companies during safety tests
10d ago
Okta’s deal for Permiso aims to close gaps in identity threat detection
10d ago
CISA issues recommendations to federal agencies on open-source software security
10d ago
We know how to protect our troops from telecom attacks. We’re just not doing it.
10d ago
Ghanaian national sentenced to 7 years in prison for stealing $10M from romance scam victims
10d ago
A little-known npm package was North Korea’s warm-up act for the axios hack
11d ago
Supply chain challenges loom large in quantum race, White House official says
11d ago
Huntress warns about attack spree that hit 30 SonicWall customers in 2 days
11d ago
Industry’s message on CIRCIA: Please ask us fewer questions about cyberattacks
16d ago
Despite multiple takedowns, botnets continue to grow
16d ago
Microsoft, tech companies throw weight behind spread of open-source AI
16d ago
Rubio restricts visas for sextortionists, cyber scammers
17d ago
Russian espionage group using novel Zimbra exploit to steal sensitive data from Western countries
17d ago
ANCHOR-CI could fix 20 years of broken government-industry collaboration
17d ago
Most federal cybersecurity reporting rules are duplicative, study finds
18d ago
Malware is targeting AI tools in software development environments
18d ago
White House accuses Chinese company of distilling Anthropic’s Fable
18d ago
OpenAI says model test was behind Hugging Face hack
19d ago
AI models keep getting caught cheating
19d ago
Where’s the Trump administration line on AI regulation?
19d ago
House intel bill includes provisions on state and local threat intelligence, election security, AI
19d ago
North Korea’s IT worker scheme funds Russia’s war effort
19d ago
What the World Cup can teach us about cybersecurity resilience
19d ago
Director of Commerce AI standards office out after three months
20d ago
Why blocking AI models won’t stop the cyber threats they create
20d ago
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
23d ago
Leading members of Scattered Spider sentenced in UK to 66 months in jail
23d ago
Program to rotate cyber personnel through federal agencies saw little use
24d ago
Russian trio indicted for allegedly running bulletproof hosting providers that spurred cybercrime
24d ago
Security researchers find stalkers abusing Chrome’s sync feature
25d ago
SonicWall customers under threat as attackers exploit 2 zero-days
25d ago
Dems press DNI nominee Jay Clayton on election security questions, but leave dismayed
25d ago
Forget the model. When it comes to cybersecurity, it’s all about the harness
25d ago
Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail
31d ago
Interpol cybercrime crackdown nets 5,800 arrests across 97 countries
31d ago
764 splinter group leader sentenced to 40 years in jail
31d ago
French nonprofit starts global intelligence and research hub for AI cyber threats
32d ago
Found fast, fixed slow: The gap the AI clearinghouse must close
32d ago
Spain arrests suspected hacker linked to Russian hacktivist campaign
33d ago
Deepfake CSAM lawsuit against xAI, Grok expands
33d ago
Suspected Chinese espionage group used a Roundcube exploit chain to burrow into universities
33d ago
US Army websites defaced with pro-Kurdish sentiments, insults to Trump
34d ago
Sysdig clocks first documented case of agentic ransomware
34d ago
Finding vulnerabilities was never the hard part
34d ago
Someone infected a spyware probe overseer with spyware
37d ago
Alleged longstanding member of Scattered Spider extradited to US
38d ago
Researchers spot exploitation of another critical Oracle defect
39d ago
US lifting export control restrictions on Anthropic’s Mythos, Fable
39d ago
This phishing kit looks more like BEC-as-a-service
39d ago
Citrix patches a new NetScaler flaw with echoes of CitrixBleed
40d ago
Trump budget boss Russell Vought open to re-staffing CISA
40d ago
DHS to unveil replacement council for critical infrastructure cybersecurity
40d ago
How ransomware syndicates weaponize corporate-style organization
40d ago
Warner bill would create federally vetted list for secure, trustworthy AI agents
41d ago
Supreme Court approves mail-in ballots that arrive after Election Day
41d ago
Supreme Court delivers ‘major win’ for tech privacy in Chatrie ruling
41d ago
What the post-quantum executive order really demands of CISOs
41d ago
ATF cancels controversial commercial geolocation contract
44d ago
FCC passes new cybersecurity rules for emergency systems, undersea cables
45d ago
Federal court rules Trump election-focused executive order illegal
45d ago
Russia uses Cellebrite to break into human rights activist’s phone, even after cancellation of contract
45d ago
Minnesota man known as ‘Snoopy’ sentenced in DraftKings hack
45d ago
Why patch directives only go so far
45d ago
Malicious hackers exploit Cisco zero-day for highest access level at communications service provider
46d ago
In a first, a court takedown goes after two cybercrime tools at once
46d ago
Open-source security is posing challenges governments can’t easily solve
46d ago
Justice Department seizes infrastructure used by cyber scam and criminal marketplace
47d ago
Algerian man charged with running two cybercrime marketplaces
47d ago
Court rules SAVE database illegal, orders it dismantled
48d ago
Trump executive orders speed up post-quantum migration, boost industry
48d ago
Intel agencies: Frontier AI models will reshape cybersecurity faster than expected
48d ago
Authorities disrupt Evil Corp’s SocGholish botnet
52d ago
Congress tees up No FAKES Act, aiming at AI-generated deepfakes
52d ago
How software development’s speed obsession enabled TeamPCP’s chaos crusade
52d ago
Accenture shells out $4.18B on three companies in big industrial cybersecurity push
52d ago
Attackers hit pair of critical Fortinet vulnerabilities the vendor disclosed in April
53d ago
Lawmakers leery about Trump administration’s Anthropic order
54d ago
AI’s constant patching treadmill can be a security problem
54d ago
A case for how to shape ‘ingredient lists’ for AI models
54d ago
Google exposes China espionage group that’s been lurking in networks undetected since 2023
55d ago
Cybersecurity experts don’t think Anthropic’s Fable 5 presents a unique threat
55d ago
Anthropic disables new models after government calls them a national security concern
57d ago
FBI takes down massive China-based cybercrime network that caused $1.9B in losses
58d ago
US, France, and Italian authorities shut down massive deepfake porn site
58d ago
Conti ransomware group member pleads guilty, faces up to 20 years in prison
58d ago
ShinyHunters is actively extorting universities after exploiting an unpatched Oracle flaw
58d ago
CyberCorps is adapting to AI. The budget isn’t keeping up.
58d ago
Russian national charged in connection with Void Blizzard espionage campaign
59d ago
OpenAI: ‘Likely’ Chinese influence operation tried to use ChatGPT to stir debate on data centers
60d ago
CISA directive orders agencies to prioritize vulnerability patching in a new way
60d ago
Microsoft breaks Patch Tuesday record with 206 vulnerabilities
61d ago
Anthropic’s new model is Mythos on a leash
61d ago
CISA is rethinking how it prioritizes risks and vulnerabilities for feds, private sector
61d ago
Cisco customers encounter another SD-WAN zero-day under attack
61d ago
Meta accuses NSO Group of defying spyware injunction, files contempt of court complaint
62d ago
The AI security race needs accountability, not overregulation
62d ago
Nightmare Eclipse incident shows the researcher-vendor fights may never fully go away
65d ago
Hill Dems hammer GOP for $250M CISA budget cut
66d ago
Your AI agent could become your biggest insider threat
66d ago
Inside the race to adapt to an AI-powered security world
66d ago
European authorities crack down on illegal streaming networks
67d ago
DHS Secretary Markwayne Mullin pinpoints optimal CISA staffing levels
67d ago
DOD wants to integrate cyber in all operations, and integrate security into AI
68d ago
Trump administration releases scaled-back AI executive order
68d ago
Anthropic expanding access to Project Glasswing
68d ago
Attackers are exploiting Palo Alto Networks defect that initially flew under the radar
69d ago
Tina Peters, convicted in election-security breach, emerges defiant and vows legal fight
69d ago
USPS moving forward with mail-in ballot changes as courts weigh Trump’s election order
69d ago
Election threats are focused on campaign systems, not voting machines
69d ago
Tennessee man linked to 764 accused of series of crimes against children dating back to 2022
72d ago
Federal audit reveals NIST’s NVD is plagued by poor planning and duplication
72d ago
House panel poised to hold hearing centered on AI impact on cyber
73d ago
Google security engineer accused of turning confidential search trends into $1.2M win on Polymarket
73d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
73d ago
OpenAI heralds cybersecurity, election interference safeguard plans for 2026 midterms
74d ago
FBI warns US-based law firms to be on the lookout for cybercrime group that steals data in person
74d ago
UK spy chief labels AI ‘unstoppable force’ with offensive, defensive ramifications for cyberspace
74d ago
CrowdStrike disrupts Glassworm botnet that preyed on open-source supply chain
74d ago
Apple open-sources quantum-resistant encryption code
75d ago
Alleged leader of Kimwolf, a sweeping botnet for cybercriminals, arrested in Canada
80d ago
Lawmakers from both parties say CISA cuts have gone too far
80d ago
Trump postpones executive order focused on AI security
80d ago
CISA chief frets about open-source vulnerabilities, delayed security improvements
80d ago
European authorities take down prolific cybercrime VPN service
80d ago
The readiness paradox: Why a false sense of cyber confidence is becoming a liability
80d ago
Meet Rampart and Clarity, Microsoft’s new red team combo AI agents
81d ago
GitHub says internal repositories were impacted in poisoned VS Code extension attack
81d ago
CISA credential leak raises alarms, and Capitol Hill demands answers
82d ago
Attackers hit vulnerabilities hard last year, making exploits the top entry point for breaches
82d ago
Mini Shai-Hulud returns, compromising hundreds of npm packages
82d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
82d ago
AI might cut false positives, but it won’t stop the slop
83d ago
Interpol leads cybercrime crackdown across 13 countries in Middle East, North Africa
83d ago
The Canvas breach proved that prevention is no longer enough
83d ago
Former CISA nominee Sean Plankey named US CEO of defense startup
84d ago
Colorado governor commutes prison sentence for election denier Tina Peters
86d ago
Here’s how the FTC plans to enforce the Take It Down Act
86d ago
Cisco zero-day under ongoing attack by persistent threat group
86d ago
Pentagon cyber official calls advanced AI ‘revolutionary warfare’
87d ago
White House cyber official: identity security matters more than ever in the age of AI
87d ago
Major tech manufacturer Foxconn confirms cyberattack hit North American factories
87d ago
Researchers say AI just broke every benchmark for autonomous cyber capability
88d ago
Closed briefing sets stage for House hearing on Anthropic’s Mythos and cyber risks
88d ago
DOJ releases legal rationale for nationwide voter data collection
88d ago
Weaponized AI: The new frontier of fraud and identity spoofing
88d ago
Daybreak is OpenAI’s answer to the AI arms race in cybersecurity
88d ago
‘Mini Shai-Hulud’ malware compromises hundreds of open-source packages in sprawling supply-chain attack
89d ago
Major world economies spell out key elements of AI ‘ingredients list’
89d ago
Microsoft addresses 137 vulnerabilities in May’s Patch Tuesday, including 13 rated critical
89d ago
Google and Amnesty International teamed up to make it harder for spyware vendors to hide
89d ago
AI is separating the companies built to scale from the ones built to sell
89d ago
Instructure claims hackers returned stolen Canvas data after an extortion standoff
90d ago
Google spotted an AI-developed zero-day before attackers could use it
90d ago
The missing cybersecurity leader in small business
90d ago
Sen. Schumer seeks DHS plan on AI cyber coordination with state, local governments
93d ago
ShinyHunters claims nearly 9,000 schools affected by Canvas data breach
93d ago
Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI
93d ago
Ivanti customers confront yet another actively exploited zero-day
94d ago
Trump officials are steering a cybersecurity scholarship program toward AI
94d ago
American duo sentenced for hosting laptop farms for North Korean IT workers
94d ago
One House Democrat is pressing Commerce on the government’s spyware use
94d ago
A DOD contractor’s API flaw exposed military course data and service member records
95d ago
A critical Palo Alto PAN-OS zero-day is being exploited in the wild
95d ago
179 loaded
LI
LiveOverflow
2d ago · 15 items
Learn Fault Injection at DEF CON 2026
2d ago
Did an AI Really Hack Hugging Face?
13d ago
Security-driven Rapid Release - Pwn2Own Documentary (Part 4)
158d ago
Firefox JIT Bug - Pwn2Own Documentary (Part 3)
161d ago
The First Exploit - Pwn2Own Documentary (Part 2)
165d ago
The World's Hardest Hacking Competition - Pwn2Own Documentary (Part 1)
168d ago
From Zero to Zero Day (and beyond) - Life of a Hacker: Jonathan Jacobi
488d ago
The German Hacking Championship
513d ago
Do you know this common Go vulnerability?
527d ago
Google's Mobile VRP Behind the Scenes with Kristoffer Blasiak (Hextree Podcast Ep.1)
662d ago
My theory on how the webp 0day was discovered #short
678d ago
My theory on how the webp 0day was discovered (BLASTPASS)
679d ago
Learn Android Hacking! - University Nevada, Las Vegas (2024)
705d ago
DEF CON & Black Hat Trip 2024
719d ago
Finding The .webp Vulnerability in 8s (Fuzzing with AFL++)
930d ago
15 loaded
RF
Recorded Future
3d ago · 20 items
July 2026 CVE Landscape
3d ago
Emerging Threats to Neurotechnology
4d ago
Hype vs. Reality: What the Hugging Face Incident Means for AI Safety
5d ago
8 Ways AI is Changing Threat Intelligence
7d ago
Iran War’s Secondary Effects Shape 2026 US Violent Extremism
11d ago
Dealing with AI-Generated Extortion
11d ago
Ransomware is the Scoreboard
17d ago
TAG-195 Upgrades MaaS Ecosystem with Modular Tools
18d ago
Modern Attack Vectors | Recorded Future
19d ago
Threat Hunting: A Guide | Recorded Future
21d ago
Tracking Advanced Persistent Threat Groups | Recorded Future
24d ago
AI Has Enhanced Iran’s Asymmetric Playbook During the 2026 Conflict
25d ago
The Shift: A New Era of AI Regulation
26d ago
The FBI Warned About Fake Permit Fees. The Harder Question Is Where the Money Goes. | Recorded Future
27d ago
June 2026 CVE Landscape
31d ago
RiskX interview video featuring Colin Mahony and Mastercard's Aditi Sawhney
32d ago
The Threat Isn’t the Frontier Model
33d ago
Iran-Nexus TAG-182 Disseminates MarkiRAT Surveillance Tool
40d ago
Where Expertise Meets Algorithm: The Insikt Group® Intelligence Edge
46d ago
Evaluating Mexico’s New Cybersecurity Plan
46d ago
20 loaded
NE
NetworkChuck
3d ago · 15 items
OSPF From Zero: Let's Build the Internet (Well...Almost) | Summer of CCNA
3d ago
AI's Impact on Network Engineers | LIVE AMA | Summer of CCNA
17d ago
this Raspberry Pi belongs on your wall
17d ago
I got inside FIFA’s Secret World Cup Broadcast Network
21d ago
LIVE AMA | Summer of CCNA | 07/09/2026
31d ago
Fable 5 is back.....run these prompts before July 12th
38d ago
shadow AI is terrifying
51d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
52d ago
HTTPS Doesn't Hide This From Your ISP!!
52d ago
Cisco Just Showed the Future of Networking
52d ago
Certification Questions | LIVE AMA | Summer of CCNA | 06/18/2026
54d ago
I was wrong about VPNs
55d ago
Certification Questions | LIVE AMA | Summer of CCNA
66d ago
Hermes has a Home Assistant skill and it's unreal!
67d ago
FREE coffee at Cisco Live (I'm giving it away)
68d ago
15 loaded
KO
Krebs on Security
3d ago · 10 items
Canadian Man Pleads Guilty in Snowflake Extortions
3d ago
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage ...
Read This Before You Buy That TV Streaming Stick
10d ago
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. ...
LG to Ban Residential Proxies from Smart TV Apps
19d ago
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers…
Microsoft Patches a Record 570 Security Flaws
26d ago
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesd...
Lessons Learned from CISA’s Recent GitHub Leak
27d ago
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almos...
Felons, Fraudsters Flog Offensive Cybersecurity Startup
32d ago
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake intellige...
FBI Seizes NetNut Proxy Platform, Popa Botnet
38d ago
The Federal Bureau of Investigation (FBI) said today it worked with industry partners to seize hundreds of domains associated with NetNut, a sprawling residential proxy service operated by the publicly-traded Israeli company Alarum Technolo...
Scattered Spider Hackers Plead Guilty on Day 1 of Trial
47d ago
Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The ...
‘Popa’ Botnet Linked to Publicly-Traded Israeli Firm
52d ago
For the past four years, a sprawling Android-based botnet called Popa has forced millions of consumer TV boxes to relay Internet traffic linked to advertising fraud, account takeovers, and mass data-scraping efforts. This week, researchers ...
Who Runs the Ransomware Group ‘The Gentlemen?’
60d ago
A cybercrime group known as The Gentlemen has emerged as the second most active ransomware gang by victim count, rapidly attracting a talented pool of hackers through an aggressive recruitment strategy that promises affiliates 90 percent of...
HS
Heimdal Security Blog
3d ago · 15 items
The risk awareness radar. A superpower every MSP needs to train
3d ago
Most of the cyber incidents landing on our desks these days start with someone believing a lie. It’s not a brilliant piece of code that causes most breaches. A convincing email, a confident phone call, and a fake sense of urgency can make p...
Heimdal data reveals MediaArena adware completes persistence before antivirus quarantine finishes
10d ago
New data from Heimdal's telemetry measures the gap between execution of the MediaArena adware and the completion of quarantine. The same pattern has been confirmed across more than 40 client environments.
How Heimdal grew from a bold idea into a global cybersecurity platform
10d ago
Heimdal did not start as a traditional cybersecurity company. It started with two Danish cybersecurity researchers, a piece of innovative technology and a challenge. Could they create something that could identify vulnerabilities, intercept...
MediaArena malvertising: why a quarantine isn’t the end of the incident
10d ago
If Microsoft Defender quarantines BrowserModifier:Win32/MediaArena on one of your endpoints, the alert reads like a win. Our SOC data says treat it as a live persistence incident instead. In the case we timed, the payload finished writing i...
Tools Change. Teach People How to Keep Up
12d ago
“Make everyone one percent better and it compounds across the team.” That’s the line Joe Head wrote about his own job and when I read it back to him, he didn’t hesitate. “That is 100% the objective,” he said. Joe runs AI adoption for an 80-...
The 4 best managed EDR service suppliers (and how to choose)
17d ago
There are several cybersecurity companies that offer managed EDR services in 2026. Here’s what actually separates them, and who each one suits. Most successful cyber attacks begin with a breached laptop, a smartphone or a server. Over the p...
Top 4 Best SOC Platforms 2026 – Provider Comparison
18d ago
Without the right tools, no security operations centre (SOC) can do its job properly. A SOC platform brings together a range of security technologies that let your analysts rapidly identify threats, investigate them and implement fixes. The...
Top 6 Managed Detection and Response Providers
30d ago
There are several major managed detection and response (MDR) companies to choose from. We’ve compared the main offerings of the best MDR providers to help you decide which is right for your organisation. Maybe it was a near miss, or a secur...
Cyber-Aware Customers Are Raising the Bar for MSPs and Other Vendors
32d ago
Your client is no longer just buying your security advice. They’re auditing whether you live by it. That was a clear message from my exclusive interview with Heather MacDonald Alford, an MSP finance specialist and owner of Counting Creators...
How to scale your patches without scaling your team (the patch wave)
37d ago
Most breaches don’t start with a vulnerability nobody knew about. They start with one nobody patched in time. Vulnerability exploitation is now the single biggest way attackers get into a network. It has overtaken stolen credentials for the...
AI didn’t break patching. It showed us patching was already broken.
37d ago
Heimdal Launches MSP Onboarding Wizard to Help Partners Onboard Microsoft CSP Customers in 2 Minutes
39d ago
How Dynamic Defense shuts an attacker out without shutting down the business
44d ago
Static security has run out of road. The case for Dynamic Defense
44d ago
Breaking the MSP Echo Chamber: The Power of Community
46d ago
15 loaded
SA
Security - Ars Technica
4d ago · 20 items
Thousands of servers can be backdoored by exploiting buggy motherboard controllers
4d ago
Anthropic’s AI used fake identities, malware in rogue attack on GitHub project
4d ago
Defcon's new badge is a security key you can see inside
8d ago
Claude published malicious code to the Internet and attacked 3 real companies
9d ago
AI scammers outperform humans when it comes to building trust
9d ago
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
10d ago
Mythos attack on 3rd-round PQC algorithm candidate puts it out of commission
11d ago
Anthropic is finding bugs faster than Microsoft can fix them
11d ago
We now have a better understanding how OpenAI hacked into Hugging Face
12d ago
Microsoft unveils AI security tools it says outperform competing platforms
13d ago
Activist charged with felony after giving border agent "duress code" that wiped his phone
13d ago
OpenAI says its AI agent broke out of testing sandbox to hack Hugging Face
18d ago
Apps targeted at US troops contain Chinese and Russian code
19d ago
Pay up or not? Ransomware surge has victims facing tough choices.
20d ago
Now, even Russia's most elite hackers are using Clickfix to infect devices
24d ago
Windows 0-day drops the same day Microsoft releases record number of patches
25d ago
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
26d ago
The US government warns that Russia state hackers are coming after your router
27d ago
Now, defenders are embracing the prompt injection, too
27d ago
Patch for Windows Defender 0-day could allow attackers to fill hard disk
31d ago
20 loaded
MS
Microsoft Security Blog
4d ago · 10 items
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
4d ago
Learn why KuppingerCole named Microsoft a Leader in its Leadership Compass: Cloud Native Application Protection Platforms report.
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
4d ago
A macOS ClickFix campaign shifted tactics from openly serving infostealer lures to hiding them behind a browser-fingerprinting gate. The change makes malicious infrastructure harder to detect while giving defenders new hunting opportunities...
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
5d ago
A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. This analysis details the attack chain, affected environments, and practical guid...
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
5d ago
Read how to apply Zero Trust for AI with new assessments, DevSecOps guidance, and practical tools to secure AI agents, code, memory, and cloud environments.
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
5d ago
Microsoft Defender automatically isolated a compromised QNET endpoint in 129 seconds, stopping a multi-stage attack before the payload could persist or spread.
CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
9d ago
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and stea...
What’s new in Microsoft Security: July 2026
10d ago
Explore July 2026 Microsoft Security updates, including agentic defense, AI threat protection, identity, data security, and advanced endpoint management.
Better security starts with better questions
11d ago
Learn how better questions, trusted AI, and human judgment help security leaders make confident decisions and build resilient systems.
Rethinking security for the age of AI
13d ago
Enhancing AI security through global AI red teaming
13d ago
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI r...
NA
NahamSec
4d ago · 15 items
I’m headed to DEFCON!
4d ago
Free AI Hacking Course: Indirect Prompt Injection (+FREE LABS)
6d ago
Are you ready for this year's @BugBountyVillage at @DEFCONConference
7d ago
Do you guys agree? #hacking #bugbounty
9d ago
How One File Upload Got Me the Entire Customer Database
13d ago
Why Being a Great Hacker Doesn't Pay Anymore
15d ago
This Hacker Made $8,000 Hacking a Major Retailer's AI Chatbot Over DNS (Live Demo!)
27d ago
I Made an AI Agent That Reverses CVEs While I Sleep
34d ago
This Hacker Got Paid $50,000+ to Break Frontier AI Models
48d ago
This hacker made $500,000+ hacking google in just a few months. #hacking #bugbounty #cybersecurity
53d ago
How I Made $30,000 Hacking Broken Access Control
55d ago
$30K from one bug class: broken access control. Here's how 3 "lows" chain into account takeover
55d ago
Content creations was both a blessing and a curse. #bugbounty
62d ago
This Hacker Made $7,000 Hacking AI With One Email
62d ago
How I Found My First $3,000 AI Vulnerability
69d ago
15 loaded
SE
Securelist
5d ago · 51 items
How legitimate cloud platforms enable phishers to bypass MFA
5d ago
We cover a cloud-based AitM attack scenario leveraging service workers and Ultraviolet, and provide detailed phishing hosting statistics across platforms like Cloudflare Workers, Vercel, Netlify, GitHub Pages, and IPFS.
An analysis of incidents at Brazilian educational institutions
6d ago
Kaspersky expert provides statistics and details on several incident response cases at educational institutions in Brazil, as well as tips for schools and universities on how to stay safe.
Network Anomaly Detection in KATA
9d ago
An analysis of how Network Anomaly Detection (NAD) rules work within Kaspersky Anti Targeted Attack, using Kerberoasting and DNS tunneling attacks as examples.
OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia
10d ago
Our experts discovered OctLurk and SilkLurk, backdoors operating primarily in memory, targeting Central Asia. They inject plugins to launch shells, scan networks, dump credentials, and keylogging.
Toy Ghouls’ new toy: the GenieLocker ransomware
10d ago
Kaspersky experts dissect GenieLocker: new custom ransomware variants for Windows, Linux, and ESXi systems. We found this family in attacks by Toy Ghouls, a financially motivated extortion group.
Mirage Kitten targets Middle East and Africa region with new malware
12d ago
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
A new extortion cocktail: office printers, small ransoms, and BitLocker
19d ago
We cover two recent cases of BitLocker extortion using RDP, MSSQL, RMM tools, web shells, and printers. The story includes TTPs and recommendations.
New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery
19d ago
Kaspersky GReAT experts describe a new Project CAV3RN C2 module. It uses Outlook calendar for communication via Microsoft Graph and has a backup connection via DNS AAAA responses.
HelloNet campaign — new malicious modules launched through the ViPNet update system
24d ago
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration
24d ago
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
OkoBot: new sophisticated malware framework targets cryptocurrency users
25d ago
Threat landscape for industrial automation systems. Q1 2026
33d ago
When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website
34d ago
Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign
37d ago
Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects
38d ago
The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign
39d ago
ToddyCat: your hidden email assistant. Part 2
40d ago
The Gentlemen are knocking: сustom backdoors and evolving tactics
41d ago
Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk
44d ago
Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools
45d ago
StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader
46d ago
A VBScript campaign distributed through WhatsApp deploying RMM software
48d ago
Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk
54d ago
From cause to cash: a cross-border look at hacktivist activity
62d ago
Argamal: Malware hidden in hentai games
67d ago
Wardriving assessment across Mexico: Preparing for the 2026 World Cup
68d ago
Containers on fire: from container escapes to supply chain attacks
69d ago
OpenClaw: risks for agent users and how to mitigate them
69d ago
What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant
72d ago
Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
73d ago
Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload
79d ago
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
81d ago
IT threat evolution in Q1 2026. Mobile statistics
83d ago
IT threat evolution in Q1 2026. Non-mobile statistics
83d ago
Kimsuky targets organizations with PebbleDash-based tools
87d ago
State of ransomware in 2026
89d ago
CVE-2025-68670: discovering an RCE vulnerability in xrdp
93d ago
Exploits and vulnerabilities in Q1 2026
94d ago
OceanLotus suspected of using PyPI to deliver ZiChatBot malware
95d ago
Websites with an undefined trust level: avoiding the trap
95d ago
“Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security
97d ago
Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India
101d ago
PhantomRPC: A new privilege escalation technique in Windows RPC
107d ago
FakeWallet crypto stealer spreading through iOS apps in the App Store
111d ago
Threat landscape for industrial automation systems in Q4 2025
116d ago
JanelaRAT: a financial threat targeting users in Latin America
118d ago
The long road to your crypto: ClipBanker and its marathon infection chain
122d ago
Financial cyberthreats in 2025 and the outlook for 2026
123d ago
A laughing RAT: CrystalX combines spyware, stealer, and prankware features
130d ago
An AI gateway designed to steal your data
136d ago
Coruna: the framework used in Operation Triangulation
136d ago
51 loaded
PN
Proofpoint News Feed
5d ago · 10 items
Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats
5d ago
Recognition highlights Proofpoint's deep technical integration with Google Cloud Security solutions and commitment to helping organizations protect people, data and AI Helps
Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities
5d ago
Accelerates OEM innovation by embedding trusted threat intelligence into security products and customer-facing workflows. Helps partners deliver more prioritized,
Max-severity Exchange server flaw under active exploitation by Kremlin hackers
10d ago
New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors
17d ago
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
17d ago
US and allies say Russian hackers stole emails without social engineering
17d ago
The United States and more than a dozen allied nations said on Thursday that Russian hackers stole emails from users of the Zimbra email program without having to fool them into opening an attachment or clicking a link.
If you pay a hacker’s ransom, chances are that they’ll come back for more
18d ago
Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective
18d ago
Global study reveals that AI is amplifying phishing, impersonation and credential theft, transforming ransomware into a human-centric extortion problem 40%
OAuth Client ID Spoofing Lets Attackers Validate Stolen Microsoft Entra Credentials
26d ago
Hackers find a new trick to collect Microsoft Entra user data without raising red flags
27d ago
BF
Blog – Forter
6d ago · 10 items
Does AI Content Have to be Authentic — or Can It Just Be Effective?
6d ago
What Is Visa’s DCAP? A Merchant’s Guide to Requirements, Benefits, and Rollout
18d ago
The Gray Area in Your Checkout Is Costing You More Than You Think
26d ago
Your Payment Routing Rules Are Making Decisions Without You
32d ago
New at Forter: AI Agents Built to Amplify Your Team
46d ago
Can AI Agents Find, Trust, and Choose Your Brand?
47d ago
IMPACT Roadshow Recap: Getting Ready for Agentic Commerce
60d ago
Agent-Ready: How to Prepare Your Site for AI-Driven Commerce
67d ago
Japan’s 3DS Mandate: One Year In
86d ago
One-Click Refunds Are Not as Hard as You Think
96d ago
JH
John Hammond
6d ago · 15 items
Cyber Deception Everywhere
6d ago
JHT Course Launch! Home Labs with Proxmox
8d ago
GTA Malware Trap
9d ago
Minecraft Security Mods
11d ago
Payload Podcast 010 - Olaf Hartong
11d ago
Any App Notification
14d ago
Building Fake Notifications
15d ago
Fake Edge Update
17d ago
An AI Botnet
19d ago
Redirect Chain Abuse
20d ago
Microsoft Exchange Hacked, Five Years Later
20d ago
Evil Token Marketplace
24d ago
Payload Podcast 009 - Steven Flores
24d ago
Backdoored TortoiseSVN Installer
26d ago
NEW AI Hacking Challenges with Andrew Bellini!
29d ago
15 loaded
WE
WeLiveSecurity
9d ago · 20 items
This month in security with Tony Anscombe – July 2026 edition
9d ago
Beyond the screenshot: Why you should verify what you see
10d ago
Forgotten UEFI shims undermining Secure Boot
26d ago
ESET Threat Report H1 2026
32d ago
Cyber readiness for SMBs: Getting the basics right
37d ago
This month in security with Tony Anscombe – June 2026 edition
40d ago
Inside the inbox: Why cybercriminals want to break into your email account
41d ago
SMB cyber readiness: the road to resilience starts here
44d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
45d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
46d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
52d ago
Protecting legacy OT systems against modern cyberthreats
53d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
54d ago
EvilTokens: A phishing attack that doesn’t steal your password
55d ago
OceanLotus: From external espionage to domestic targeting
59d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
60d ago
Cybercriminals: the 'auditors' you never hired
61d ago
Lessons for life: Why children’s data is a long-term identity risk
67d ago
This month in security with Tony Anscombe – May 2026 edition
72d ago
ESET APT Activity Report Q4 2025–Q1 2026
73d ago
20 loaded
HA
Hak5
9d ago · 15 items
The DEF CON Advice Nobody Gives You | Threat Wire
9d ago
OpenAI Turned Off the Guardrails | Threat Wire
10d ago
Meta Logging Every Employee Keystroke | Threat Wire
17d ago
Your Home Internet Has a New Owner | Threat Wire
25d ago
Five Eyes Alert: The AI Deception Has Already Begun | Threat Wire
33d ago
Miasma Worm Source Code Leaked (Plus: Anthropic's Fable RealityCheck) | Threat Wire
48d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
48d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
49d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
52d ago
Shark Jacked my LAN 🦈
54d ago
Developers React to the 105-Second Github Chain Reaction | Threat Wire
58d ago
🔴 [PAYLOAD] Shark Jack Display 🦈
59d ago
Introducing Shark Jack Display 🦈
62d ago
The GitHub Leak Situation Just Got Worse | Threat Wire
73d ago
The Worm That Deletes Your Entire Computer | Threat Wire
79d ago
15 loaded
TC
The Cyber Mentors
10d ago · 15 items
Meet TCM Security at DEF CON 34!
10d ago
Real Folks of Cyber | Andrew Crotty | DITL
10d ago
TCM Course Release | New Creator | Cybersecurity | AMA
17d ago
Soft Skills for the Job Market: Applying for Jobs
30d ago
LIVE: 1 Million Subscribers | DEF CON/Summer Camp Giveaway
32d ago
Celebrating 1 Million Subscribers on July 8th!
38d ago
Real Folks of Cyber | Pearce Barry | Day in the Life
44d ago
Getting Started with the TCM Security Academy
45d ago
Soft Skills for the Job Market: Resume Writing
51d ago
TCM Security Summer Sale is Here!
54d ago
LIVE: 🕵️ CTF Prize Draw | Cybersecurity
59d ago
Secrets to PNPT Debrief Success
61d ago
TCM Security CTF Walkthrough
65d ago
Top 5 Active Directory Pentesting Tools
68d ago
Real Folks of Cyber | Dan Berger | Day in the Life
73d ago
15 loaded
M3
Microsoft 365 Blog
10d ago · 10 items
The next measure of AI momentum is work transformed
10d ago
New data from Microsoft 365 Copilot telemetry signals, along with examples from our customers around the world, demonstrate AI transformation in action.
Copilot in Excel: Built for the era of Frontier Finance
45d ago
- Discover how Copilot in Excel transforms finance workflows with skills, data connectors, and capabilities for traceability.
Copilot Cowork is now generally available
54d ago
Copilot Cowork is now generally available worldwide, bringing secure, AI-powered automation for complex enterprise tasks in Microsoft 365.
Introducing Microsoft Scout: Your always-on personal agent
68d ago
Microsoft introduces a new, always-on personal agent, Microsoft Scout, integrated across the Microsoft 365 apps you use every day.
Announcing the new Work IQ APIs
68d ago
Build enterprise agents with Work IQ APIs for Microsoft 365—bringing business context, tools, and secure, scalable intelligence into every workflow.
Introducing Microsoft 365 Business with Copilot: The new standard for small business
73d ago
Meet Microsoft 365 Business with Copilot—the AI-powered solution transforming how small businesses work, collaborate, and compete.
Introducing a new design for Microsoft 365 Copilot
73d ago
Copilot’s redesigned experience delivers faster performance, adaptive tools, and clearer AI-powered workflows to help you easily move from intention to outcome.
New and improved: Computer-using agents, a new workflows experience, and real-time voice experiences
75d ago
Explore what's new in Copilot Studio, May 2026: computer-using agents are now available, plus redesigned workflows and Work IQ extensibility.
New and improved: Agent governance, intelligent workflows, and connected app experiences
90d ago
See what's new in Copilot Studio, April 2026: updates to workflows, more control over agent operations, and an expanded agent usage estimator.
Copilot Cowork: From conversation to action across skills, integrations, and devices
96d ago
Today, we’re announcing additional capabilities in Cowork to expand on what it can make possible for you.
TM
Trend Micro Research, News, Perspectives
11d ago · 20 items
Why the Open Secure AI Alliance Matters: Open Frontier Models, Open Deployment Flexibility
11d ago
Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave
12d ago
The Signs Were There: What the First Autonomous Ransomware Case Confirms
17d ago
13M+ Emails Sent in Tech Support Scam Targeting Users, Organizations in Japan
18d ago
Inside the OpenAI – Hugging Face Incident: The AI Breach With No Human Attacker Behind It
18d ago
Federal Agencies Warn of Ongoing PLC Exploitation Against Critical U.S. Infrastructure
18d ago
Device Code Phishing: Turning a Convenience Feature Into an MFA Bypass
19d ago
Volume Is Not Risk: Making Sense of the 'Vulnpocalypse'
20d ago
Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet
27d ago
TONResolver RAT Abuses TON Blockchain to Target Japan's Hotel Industry
42d ago
From Langflow to Monero: Inside CVE-2026-33017 Cryptominer
48d ago
PeopleSoft PeopleTools Pre-Authentication RCE: A PSIGW SSRF Chain That Executes Inside the JVM
53d ago
Threat Actors Abuse claude.ai Shared Chat for ClickFix Malvertising Campaign
54d ago
Governing Claude Enterprise in Environments Where Inline Controls Can't Go
59d ago
GenAI Is Both Hunter and Hunted at Pwn2Own Berlin 2026
61d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: How Unmanaged Software Keeps the Door Open
63d ago
Pwn2Own Berlin 2026: On the Ground With TrendAI™ ZDI's Biggest AI Showdown Yet
70d ago
Smart Contracts for C&C: How ClearFake Hid in Plain Sight on BSC Testnet
76d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
80d ago
One Man, One AI, One Fake Persona: Inside the 5-Year Influence and Fraud ‘Patriot Bait’ Campaign
81d ago
20 loaded
DA
darkreading
16d ago · 144 items
CISOs vs. Boards: Myth or Misunderstanding?
16d ago
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
16d ago
Vatican's Official Prayer App Leaks 700K+ Global Users' PII
16d ago
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
16d ago
Europe's Multilingual Reality Exposes AI Security Gaps
16d ago
Russian Hackers Exploit Zimbra Zero-Day Against US, Ukraine Targets
17d ago
Agentic AI Challenges Progress in Confidential Computing
17d ago
Brazilian Banking Trojan Actively Spreading in Portugal
17d ago
Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain
18d ago
Flaws in Passkey Implementation Show Old Attacks Still Work
18d ago
Attackers Are Learning to Live Off the AI Toolchain
18d ago
Fake Bahrain Alert App Deploys Android Surveillance Malware
18d ago
When AI Attacks: OpenAI Models Autonomously Hack Hugging Face
18d ago
EU Financial Institutions Leak Data Through Cookie Trackers
18d ago
Ransomware Is Accelerating, but It's Not Because of AI
19d ago
Using LLMs to Find and Prioritize Vulnerabilities Is No Easy Task
19d ago
Hacker Turns AI Jailbreaks Into Offensive Attack Platform
19d ago
Choose Wisely: AI-Generated Coding Risk Varies, a Lot
19d ago
'WP2Shell' Opens Millions of WordPress Sites to Remote Takeover
20d ago
Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
20d ago
Cybersecurity Keeps Events 'Uneventful'
20d ago
Inc Ransomware Exploits SonicWall SMA Zero-Days
23d ago
The Real AI Threat Is Blind Trust
23d ago
Gold Eagle Clearinghouse Targets Security Gap, but How Is Unclear
23d ago
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
23d ago
Agentic AI: Taming the Unpredictable
24d ago
1M+ Emails Use Hidden Text to Dupe AI Security Filters
24d ago
Police Disrupt a €140M Cyber Fraud Ring in Spain
24d ago
Forgotten Bootloaders Expose Secure Boot Blind Spot
25d ago
Identity Attacks Overtake Exploits as Top Ransomware Cause
25d ago
Guten Tag, Bonjour, Hola to Our European Cyber Defenders!
25d ago
Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI Strife
25d ago
Claude Flaw Automatically Sends Malicious Prompts to AI Agents
25d ago
2-Click Cursor Exploit Enables Dev Environment Takeover
25d ago
Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits
25d ago
Cribl Adds Agentic Detection Engineering & Boosts SecOps With CardinalOps Deal
26d ago
Records Are Made to Be Broken: Patch Tuesday Raises Triage Stakes
26d ago
6 GHz Wi-Fi Flaws Could Disrupt Critical Systems
26d ago
Manage Vendor Risk in a Few Practical Steps
26d ago
Frontier AI: The Genie's Out of the Bottle, but Where's the Rulebook?
26d ago
Name That Toon Contest
44d ago
Europe Evolves Into Ransomware's Favorite Region
45d ago
Attackers Hit Cisco SD-WAN Flaw 2 Months Before Disclosure
46d ago
2026 FIFA World Cup Faces Surge in Cyber Threats
46d ago
Do CISOs Need a Code of Ethics?
46d ago
More Malicious OpenClaw Skills Threaten AI Supply Chain
46d ago
Apple's MacOS Gap Lets Users Disable Security Tools
46d ago
Scope of Salesforce Attacks Expands as Icarus Leaks Data
47d ago
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
47d ago
SocGholish Takedown Highlights Malicious TDS Threats
47d ago
FortiBleed Attackers Turn Firewalls Into Credential Stealers as Heists Persist
47d ago
DifyTap Bugs Let Attackers 'Wiretap' AI Chat Histories
48d ago
Crypto Heist Fueled by Elaborate Fake Reputation-Boosting Campaign
48d ago
He Thought He Was Secure; His Phone Number Was Stolen Anyway
48d ago
Stressors, AI Forcing Changes to Cybersecurity Teams
51d ago
Novo Nordisk Breach Highlights Software Development Pipeline Risk
52d ago
Operation Escaneo Signals Shift in LatAm Threat Landscape
52d ago
FIFA Bug Exposes World Cup Streams to Remote Takeover
52d ago
Salesforce Data Thefts Continue via Klue App Compromise
52d ago
Get Out of Security Debt by Tackling the Exposure Problem
52d ago
EU Gets a Head Start in Developing 6G Network Security
52d ago
ShinyHunters Uses Oracle Zero-Day to Rampage Higher Ed
58d ago
Claude Fable 5 Doesn't Change the Mythos Security Story
58d ago
Phishing Attack Volume Down 20%, But Risk Still Rising
59d ago
Max-Severity Ivanti Flaw Exploited 24 Hours After Disclosure
59d ago
Segmentation Works for OT If Operators Are Paying Attention
59d ago
Chinese, N. Korean Threat Groups Build on Asia-Pacific Success
60d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
60d ago
Bug Bounty Research Triggers ServiceNow Security Alert
60d ago
AI Risk Worries Insurers & Businesses Alike
60d ago
Nightmare-Eclipse Drops Yet Another Microsoft Exploit, RoguePlanet
60d ago
The Invisible Battlefield: How Cyberwar Is Reshaping Everyday Life
61d ago
Blame AI: Patch Tuesday Hits Record 206 CVEs
61d ago
Microsoft Exchange Flaw Lets Attackers Spoof Any Email Address
61d ago
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
61d ago
Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs
61d ago
AI Slop Will Kill Cybersecurity Storytelling If We Let It
62d ago
Silent Ransom Group Hits US Law Firms in Escalating Extortion Attacks
62d ago
Check Point VPN Flaw Exploited Since Early May
62d ago
Iran Signed a Ceasefire — Its Hackers Didn't
62d ago
[An RX Global Event] Infosecurity Europe
68d ago
Name That Toon: Mark of (Cybersecurity) Progress
72d ago
Asia's Cyber Insurance Market Shows Signs of Life
72d ago
With Complex Cloud Integrations, Small Errors Lead to Major Compromises
72d ago
'The Com' Cyberattacks Support Violence & Sexploitation
72d ago
As Global Powers Explore Humanoid Robots, Cyber-Risk Looms
73d ago
Dutch Raid Fails to Dent Russian Bulletproof Host
73d ago
Agentic AI Isn't Risky; the Way Orgs Deploy It Is
73d ago
Focus on Cyber Insurance: How Quantifying Risk Is Reshaping Security
73d ago
BTMOB RAT Spreads Across Brazil, LatAm via MaaS Model
73d ago
Nordic CISOs Handle Rising Cyber Threats Remarkably Well
73d ago
Ransomware Actors Show Up In Person to Steal Law Firm Data
74d ago
Latin American Cybercriminals Hoover Up Government Data
74d ago
AI-Assisted Exploit Development Outpaces Scanner Detection
74d ago
Cybersecurity Evolution: How We Went From Perimeter Defense to AI-Native Security
74d ago
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
75d ago
State Cyber Leaders Push Congress for More Funding, Support
75d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled?
75d ago
For Enterprises, Security Remains Agentic AI's Biggest Challenge
75d ago
The Boring Stuff is Dangerous Now
83d ago
Can Laws Stop Deepfakes? South Korea Aims to Find Out
84d ago
Congress Puts Heat on Instructure After Canvas Outage
86d ago
Cyber Pioneers Ponder Past as Prologue
86d ago
Taiwan Bullet Train Hack Highlights Cybersecurity Gaps in Rail Systems
87d ago
SecurityScorecard Snags Driftnet to Level Up Threat Intelligence
87d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
87d ago
'FrostyNeighbor' APT Carefully Targets Govt Orgs in Poland, Ukraine
87d ago
AI Drives Cybersecurity Investments, Widening 'Valley of Death'
87d ago
Foxconn Attack Highlights Manufacturing's Cyber Crisis
87d ago
Checkbox Assessments Aren't Fit to Measure Risk
88d ago
Attackers Weaponize RubyGems for Data Dead Drops
88d ago
Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak
88d ago
Dark Reading Celebrates 20 Years as a Leading Authority on Cybersecurity, Highlighting the People, Events, Ideas, and Technologies Shaping the Modern Risk Landscape
88d ago
LatAm Vibe Hackers Generate Custom Hacking Tools on the Fly
88d ago
China's 'FamousSparrow' APT Nests in South Caucasus Energy Firm
88d ago
It's Patch Tuesday for Microsoft & Not a Zero-Day In Sight
89d ago
Hugging Face Packages Weaponized With a Single File Tweak
89d ago
20 Leaders Who Built the CISO Era: 2 Decades of Change
89d ago
Worm Redux: Fresh Mini Shai-Hulud Infections Bite Supply Chain
89d ago
How the Story of a USB Penetration Test Went Viral
96d ago
RMM Tools Fuel Stealthy Phishing Campaign
97d ago
Exploit Cyber-Frenzy Threatens Millions via Critical cPanel Vulnerability
97d ago
Silver Fox Springs Tax-Themed Attacks on Orgs in India, Russia
97d ago
How Dark Reading Lifted Off the Launchpad in 2006
97d ago
76% of All Crypto Stolen in 2026 Is Now in North Korea
100d ago
If AI's So Smart, Why Does It Keep Deleting Production Databases?
100d ago
Name That Toon: Mark of (Security) Progress
100d ago
20 Years in Cyber: Dark Reading Marks Milestone With Month of Special Coverage
100d ago
TeamPCP Hits SAP Packages With 'Mini Shai-Hulud' Attack
101d ago
Another AI-Assisted Software Scan Yields 9-Year-Old Linux Bug
101d ago
Anthropic's Mythos Has Landed: Here's What Comes Next for Cyber
101d ago
Oracle Red Bull Racing Team Revs Up Automation to Boost Security
101d ago
Claude Mythos Fears Startle Japan's Financial Services Sector
102d ago
Reverse Engineering With AI Unearths High-Severity GitHub Bug
102d ago
AI Finds 38 Security Flaws in Electronic Health Record Platform
102d ago
Vect 2.0 Ransomware Acts as Wiper, Thanks to Design Error
102d ago
Lotus Wiper Attack Targets Venezuelan Energy Firms, Utilities
102d ago
BlueNoroff Uses Fake Zoom Calls to Turn Victims Into Attack Lures
103d ago
NSA Chief During Snowden Affair Shares Regrets, Reflections 13 Years Later
103d ago
Feuding Ransomware Groups Leak Each Other's Data
103d ago
Vidar Rises to Top of Chaotic Infostealer Market
103d ago
Fresh Wave of GlassWorm VS Code Extensions Slices Through Supply Chain
103d ago
UNC6692 Combines Social Engineering, Malware, Cloud Abuse
104d ago
Unpatched 'PhantomRPC' Flaw in Windows Enables Privilege Escalation
104d ago
144 loaded
TI
Technical Information Security Content & Discussion
16d ago · 318 items
What syscall-layer tooling cannot see in P2P infrastructure
16d ago
Announcing the External Penetration Testing Program Pack
16d ago
The way AI voice phishing gets demonstrated is making people worse at spotting it
16d ago
Escaping Claude Cowork’s local VM sandbox via CVE-2026-46331
16d ago
XBOW Agents found three RCEs as SYSTEM (and root) on Bing Image Search
17d ago
Thailand's Ministry of Finance targeted with an AI agent running with approval prompts disabled
17d ago
Open Evaluation Framework for AI Pentesting Agents on Real-World Targets
17d ago
Device Code Phishing: The Microsoft 365 Attack That Walks Past MFA
17d ago
GitHub issues $100,000 bounty for critical RCE vulnerability
18d ago
CVE-2026-50458: Finding a UAF in the Windows Brokering File System
18d ago
I was reporter #11 for a WPForms PayPal webhook vulnerability (CVE-2026-4986)
18d ago
The Hidden CCS2 Attack Surface on EV Chargers
19d ago
Writeup & POC: CVE-2026-49176 Windows WalletService to SYSTEM (LPE)
19d ago
Leaking internal headers in Flask Ninja with deserialization
19d ago
Crawling the Complete IPv4 Reverse DNS Space
20d ago
Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)
20d ago
Exploit brokers pay $500,000 for a WordPress RCE. I found one with GPT5.6 Sol Ultra and $25
20d ago
Multiple Chinese civic apps share one reward/lottery backend whose signing secret is recoverable
22d ago
wp2shell (CVE-2026-63030): Pre-Auth RCE Chain in WordPress Core - Analysis and Open-Source Scanner
22d ago
Pixels to Payload: Dissecting a Four-Stage Bitmap-Steganography Dropper Delivering AsyncRAT :: Rhys Downing
22d ago
White House launches AI-driven "Gold Eagle" clearinghouse to centralize public-private vulnerability coordination
22d ago
wp2shell: Pre Authentication RCE in WordPress Core
23d ago
Keeping private namespaces private - Quad9 blog
23d ago
Openwrt pre-auth remote root exploit
23d ago
Windows AppResolver LPE: From AppContainer to SYSTEM. PoC linked to CVE-2026-50454
23d ago
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
24d ago
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
24d ago
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
24d ago
HN Security - My Semgrep C/C++ ruleset is ready for prime time again
25d ago
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
25d ago
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
25d ago
Smashing the ServiceNow Sandbox – Pre Authentication RCE
26d ago
Context Bombs: Using AI Guardrails as a defensive mechanism
27d ago
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
27d ago
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
27d ago
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
27d ago
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
28d ago
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
29d ago
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
30d ago
Towards CSI: What's the best harness? (arXiv 2026)
30d ago
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
31d ago
1 in 2 devices sold in Africa exfiltrate data to China
32d ago
Inside an AI coal mine security camera network powered by plaintext passwords
32d ago
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
32d ago
Bad Epoll: The bug missed by Mythos
33d ago
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
33d ago
New OST2 class: "Architecture 1901: From zero to QEMU - A Gentle introduction to emulators from the ground up!"
34d ago
Playing Around With ADIDNS RPC Internals
34d ago
Windows Service - Playbook & Detection Strategies
34d ago
It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) - watchTowr Labs
38d ago
FIFA was saved this time
38d ago
/r/netsec's Q3 2026 Information Security Hiring Thread
38d ago
Privilege escalation to root in Lima QEMU guests via a world-writable agent socket (CVE-2026-53657)
39d ago
r/netsec monthly discussion & tool thread
39d ago
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) - watchTowr Labs
40d ago
Auditing OpenReception: 16 CVEs in an end-to-end encrypted appointment booking platform (unauthenticated admin creation, account takeover, E2E bypass)
40d ago
Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) - watchTowr Labs
41d ago
I tried a Local AI model (Qwen 3.6 27b) for security research and it works surprisingly well.
42d ago
Dissecting Apple's Sparse Image Format (ASIF)
42d ago
A peek into Reddit's anti-spam internals
43d ago
CVE-2025-52465 geoserver arbitrary file write vulnerability
45d ago
CargoWise WebTracker - The keys were in the cargo
45d ago
Exploiting vulnerabilities in Johnson & Johnson web apps
46d ago
Cloudflare patches Copy-Fail across every server in two days
47d ago
New Cisco RCE was fixed
47d ago
CVE-2026-25860 turn XSS to RCE
48d ago
Exploiting Auth0 Defaults in XSS Attacks - elttam
48d ago
Scanning malicious websites with 'infinite' number of VPN tunnels (Part 1)
49d ago
Use-after-free in the QPACK encoder of nginx HTTP/3 - CVE-2026-42530
51d ago
OpenBSD MPLS kernel stack leaks remotely (CVE-2026-56099)
51d ago
Squidbleed (CVE-2026-47729) - Heartbleed-style vulnerability that leaks internal memory from every version of Squid Proxy, in its default configuration
51d ago
CVE-2026-5667: Unauthenticated Remote Control of Mitsubishi MAC-577IF-2E WiFi Adapters via Probe Request Reconnaissance
52d ago
Would you like some malware served at the very top of DuckDuckGo?
52d ago
Worth a MalExt Report? A 2 Million-User Chrome Extension Added Give Freely/Wildlink in a 5-Day Update
53d ago
QoS Policies to Restrict EDR Traffic and Detection Strategies
53d ago
Getting a CVE Without Shipping Slop
54d ago
PrizeBuzz phishing network analysis
54d ago
27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass
54d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
55d ago
Chaining Security Bugs in Discuz! X5.0: from Race Condition to Pre-Auth RCE
55d ago
SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon
55d ago
Researcher accidentally gained access to a threat actor-controlled phishing website
56d ago
PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs
57d ago
MeshCentral: From XSS to RCE
57d ago
Getting the PID from random numbers in PHP
57d ago
The Axios npm compromise was visible in registry metadata before anyone ran npm install
57d ago
Why Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr Labs
58d ago
Free Compromise Detection for GitHub Repos - Tracebit Community Edition
58d ago
Major AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)
58d ago
Old Passwords Die Hard: Abusing CREDHIST for offline credential recovery
58d ago
Marking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr Labs
58d ago
Detecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rules
59d ago
Claude Fable 5: mid-tier results on coding tasks
59d ago
Fable 5 and the analyst-AI threat model: what a Mythos-class model changes for security work
59d ago
Hacking Google with A.I. for $500,000
59d ago
Prompt injection: attacking the analyst's AI
59d ago
Pre-auth XXE → HTTP SSRF on ArubaOS 8.13.2 closed as "theoretical / no valid PoC" despite TCP pcap, sshd localhost log, and internal port scan — documenting for community review
60d ago
We post-trained a model for offensive security instead of teaching it to refuse
60d ago
How Fraudsters Bypass Facial Recognition and Stay Hidden in 2026
60d ago
FedRAMP Penetration Testing: How to Pass Your ATO Review and Get Cloud Authorized Faster
60d ago
certSIGN: Inconsistent revocation status (CRL "revoked" vs OCSP "good") for intermediate CA "certSIGN Web CA"
60d ago
BlackSun - Defender for Endpoint on macOS
60d ago
GhostTrace – a Windows forensic scanner that finds what "Uninstall" leaves behind (22 modules, read-only, offline)
60d ago
Jupyter Enterprise Gateway - From Notebook to Kubernetes Cluster Admin - elttam
60d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
61d ago
Apple’s Siri-AI, or more shouting into the void about “private” agents
61d ago
Entra Agent ID from a Security Perspective
61d ago
X.com silently injects session-bound tracking tokens into your clipboard on every copy — security tools correctly flag this as malicious injection
61d ago
WinGet - Code Execution, Persistence and Detection Strategies
61d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
61d ago
I just completed Search Skills room on TryHackMe! Learn to efficiently search the Internet and use specialised services and technical docs for information
61d ago
AI Agents May Always Fall for Prompt Injections
61d ago
Arc Gate — runtime governance proxy for AI agents, catches multi-turn prompt injection via geometric drift detection — try to break it
62d ago
EDRChoker: Choking The Telemetry Stream to Bypass Defenses
63d ago
PSA: Attack Shark R85 HE (FREEWOLF US / Amazon) — BadUSB credential harvester, confirmed malware
64d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
64d ago
Zero-Click HFP/A2DP Takeover via L2CAP Session Preemption
65d ago
Keeping Secrets Out of Logs
65d ago
Unauthenticated RCE as QSECOFR via IBM i Management Central — port 5555, client-controlled verify flag, no credentials required (V7R4 and earlier)
65d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
66d ago
Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)
66d ago
Re:CACHE - Excessive reflection, type confusion, and 0-click SXSS on Next.js
66d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
66d ago
Season VI of the US Games launches TOMORROW!
67d ago
EU CRA mandatory vulnerability reporting enters into force September 11, 2026 — what the 24-hour obligation requires
67d ago
Interesting- What LLM vuln research looks like
67d ago
Hacking your PC using your speaker without ever touching it
67d ago
Abusing iDEAL (Wero): how criminals weaponise legitimate payment links in phishing
67d ago
Golang code review notes II - elttam
67d ago
Using AI to Secure Its Generated Code Is a Ponzi Scheme
67d ago
Four coordinated npm supply chain campaigns active in May–June 2026 — TTPs, IOCs, and detection notes
68d ago
We Added a Detection Rule. We Were Not Expecting This.
68d ago
1-Click GitHub Token Stealing via a VSCode Bug
68d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
68d ago
NuGet Code Execution As A Service
69d ago
Blind POST SSRF in phpBB 4.0.0-alhpa1 Web Push (CVD with phpBB)
69d ago
Dutch Police and NCSC dismantle 17-million-device botnet running on 200 servers seized from local hosting provider
69d ago
r/netsec monthly discussion & tool thread
69d ago
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
69d ago
Stealing Passwords via HTML Injection Under a Strict CSP
69d ago
Subnet discovery through multi-protocol TTL tracing
69d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
70d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
71d ago
Digital Trap: Iran Uses Selective Internet Restoration to Track and Arrest January Protesters
71d ago
A practical checklist for evaluating npm packages (supply chain attacks, slopsquatting, etc.)
72d ago
Introducing Keyhog: The First GPU Accelerated secret scanner
72d ago
OffensiveCon26 YouTube Playlist released
72d ago
1,001 IPs, 64 countries, one operation: mapping a botnet by its back end · HoneyLabs blog
72d ago
I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found.
72d ago
Fooling around with encrypted reasoning blobs
73d ago
CALIF: An AI audit of FreeBSD
73d ago
CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries
73d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
73d ago
Visual Studio Extensions Revisited
73d ago
Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP)
73d ago
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
73d ago
What scanners are actually trying against AI infrastructure
73d ago
Defense by accumulation
74d ago
New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
74d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
74d ago
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
74d ago
HN Security - AI Reporter - Let's automate reporting in Burp Suite!
74d ago
Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records
74d ago
RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact
74d ago
Navigating Lax Load Balancers: When an Intersection Gets You Inside
75d ago
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents
75d ago
OTP lockout state leaked valid-code signal, enabling OLX account takeover
75d ago
How journalists rely on VPNs to protect press freedom
75d ago
Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
75d ago
Update Starlette Now. New severe vulnerability dropped.
75d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
76d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
76d ago
CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth
76d ago
Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal
76d ago
nmap on Linux: Guide to Network Scanning and Discovery
77d ago
Prompt Injection finally broke my brain a little. My first article as a security student.
77d ago
How to Use Claude AI: A Complete Technical Beginner's Guide
77d ago
Pardon MIE?: how Mythos did not bypass Apple MIE
78d ago
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
79d ago
AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22
79d ago
Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't)
79d ago
Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension
79d ago
Zyxel low-priv account leaked super-admin, FTPS, and TR-069 secrets across router fleets
79d ago
Data breach in name of protest
79d ago
pnpm 11 Might Finally Be a Better Default Than npm
79d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP | same Mini Shai-Hulud payload as last week's TanStack wave
80d ago
[Analysis] CISA contractor left AWS GovCloud admin keys, plaintext passwords, SAML certs, and Kubernetes configs on a public GitHub repo for 183 days — with secret scanning deliberately disabled
80d ago
GitHub Actions Cache Poisoning is eating open source
80d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
80d ago
CVE-2026-34474: Pre-auth credential disclosure in ZTE H298A / H108N via ETHCheat
80d ago
FatGid - FreeBSD 14.x kernel LPE
80d ago
Keys to the Kingdom: Anonymous SQL Injection in Drupal Core (CVE-2026-9082)
80d ago
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
80d ago
The IBM X-Force Index 2026 explains all three in one finding.
80d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
81d ago
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
81d ago
[ Removed by Reddit ]
81d ago
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
81d ago
Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online
81d ago
The IBM X-Force Index 2026 explains all three in one finding.
81d ago
GitHub hit by a compromised VSCode extension
81d ago
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
81d ago
We audited 12K n8n templates: most have critical vulnerabilities
81d ago
Veilgate - Deception proxy
81d ago
Sleeping Agent: Silent persistent C2 through Web Push
82d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
82d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
82d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
82d ago
CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing
82d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
82d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
83d ago
The quiet death of behavioral anti-bot and the pivot to hardware ZKPs
83d ago
AudioHijack: adversarial audio attacks on generative voice models transfer from open weights to Microsoft and Mistral production systems
83d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
83d ago
The down fall of bug bounties
83d ago
TanStack Supply Chain Attack (And How to Lock Down GitHub Actions)
83d ago
Attacking Cloud Service Providers (ACSP) - An interactive textbook on control-plane intrusion and breaking cross-tenant isolation
83d ago
Autonomous AI Penetration Testing with Consent-First Ethical Framework — Research Paper + Working Implementation
83d ago
Ansible security and compliance guide
84d ago
Instrumenting QT6 desktop apps with Frida - Part 2: Building the Bypass Chain
84d ago
AI-assisted cyberattacks are changing the threat landscape faster than most organizations realize.
85d ago
Microsoft MDASH found 16 Windows RCEs — here's exactly how the 100-agent pipeline works
85d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
86d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Threat Targeting South Korean Govt Systems
86d ago
Automating code security reviews with Claude Mythos-level capabilities
86d ago
Instrumenting QT6 desktop apps with Frida - Part 1
86d ago
From Vercel Typosquatting to an Obfuscated macOS Malware Loader
86d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
87d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
87d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
87d ago
CVE-2026-44338: Scanners Target PraisonAI Within Four Hours of Disclosure
87d ago
How to Check Computer Activity: 2026 Guide for Windows and Mac
87d ago
CVE-2026-42945 : NGINX Heap Buffer Overflow in rewrite module - Writeup and PoC
87d ago
Hunting the Behavior Behind npm Supply Chain Attacks
87d ago
WaSteal: 126 Chrome extensions, 148K installs, one Brazilian operator silently sending WhatsApp user data and ad cookies to its servers
88d ago
Apple Maildrop lets you rewrite the filename, size, and icon on any icloud.com attachment link — no signature, no validation — reported July 2023, still live
88d ago
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
88d ago
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
88d ago
Apple's smbd has no FSCTL_SRV_COPYCHUNK limit enforcement: 256 bytes in, 64 GiB disk I/O out
88d ago
On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study)
88d ago
A stealth approach to Process Injection - EntryPoint Hijacking
88d ago
A year of Apple Security Bounty research — 16 closed findings, full disclosure
88d ago
AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods
88d ago
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
89d ago
The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop
89d ago
Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
89d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
89d ago
I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
89d ago
Curl lead developer Daniel Stenberg provides insightful feedbacks from Mythos analysis results
89d ago
New ipTIME Pre-Auth RCE in CWMP
89d ago
Postmortem: TanStack npm supply-chain compromise
89d ago
How do Fortune 10 SOCs handle incident response with 15 people instead of 150? Energy-Based Models.
90d ago
OpenAI announces Daybreak, "frontier AI for defenders"
90d ago
GhostLock: SMB Deny-Share Handles as a Zero-Privilege Availability Weapon
90d ago
How I Defeat Passkeys Nearly Every Time in Phishing Assessments
90d ago
MyAudi app:Security issues in Audi Connected Vehicle experience
90d ago
Giving Claude Code Full Control of a Hardware Fault Injection Setup to Bypass Secure Boot
90d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
91d ago
Autonomous Vulnerability Hunting with MCP
91d ago
ShinyHunters / AT&T ransom payment traced on-chain — paper draft, seeking arXiv cs.CR endorsement
91d ago
Data in Use Protection: How MPC Keeps Inputs Hidden from the Cloud - Stoffel - MPC Made Simple
91d ago
The compression of the exploit timeline: Why n-day gaps and 90-day embargoes are failing in practice.
91d ago
Outrunning SHA256 with Physics
91d ago
Memory Poisoning AI Agents via ChromaDB
92d ago
Defence in Depth: A Practical Secure Corporate Network Topology
92d ago
Technical Analysis of EagleSpy V6.0 (CraxsRAT Rebrand) Distributed Through Odysee and Telegram
92d ago
Getting LLMs Drunk to Find Remote Linux Kernel OOB Writes (and More)
92d ago
Seclens: Role-specific Evaluation of LLM's for security vulnerablity detection
93d ago
Securing CI/CD for an open source project: lessons from Cilium
93d ago
ShinyHunters breached Canvas/Instructure — 275M student records stolen from 8,809 schools, ransom deadline May 12
93d ago
Needle crypto-stealer C2 analysis: API key embedded in plain text inside the Rust malware unlocked 1,932 victims and the operator's withdrawal config
93d ago
Copy Fail (CVE-2026-31431): A Technical Deep Dive
93d ago
Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo
94d ago
Dirty Frag - Linux LPE similiar to Copy Fail
94d ago
Honey Tokens: Bait Credentials That Catch Breaches
94d ago
CVE-2026-42511 Breakdown: RCE in FreeBSD
94d ago
Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804
94d ago
An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support)
94d ago
Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI
94d ago
Quacc++: Automated Open Source Vulnerability Discovery
95d ago
Binance fixed the IP whitelist gap — but the disclosure process is still broken
95d ago
Non-Determinism of Maps in Golang: Why, How, and the Consequences
95d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
95d ago
Vulnerability Garden
95d ago
Scan. Secure. Simplify. — Free Web Tools Platform
96d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
96d ago
Salesforce pentesting novel techniques- how to be an apex predator
96d ago
DigiCert: Misissued code signing certificates
96d ago
Major AI Clients Shipping With Broken OAuth Implementations
96d ago
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10
96d ago
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud
96d ago
The Danger of Multi-SSO AWS Cognito User Pools
96d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
96d ago
Proton Pass: Second-Password Bypass Through Emergency Access
96d ago
We probed 6,000 web apps for Stripe webhook signature checks. 1,542 don't bother
96d ago
Lateral Movement - Cross-Session Activation
97d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
97d ago
Your vibe-coded app is probably violating GDPR right now
98d ago
Acoustic Keystroke Recovery - Reconstructing Typed Text from a Laptop Microphone (Full Guide, 85% success rate)
98d ago
How to exfiltrate data using only numeric outputs
99d ago
For vulnerability research, smaller models run repeatedly can outperform larger frontier models on cost-to-recall.
100d ago
Every incident public companies have disclosed to the SEC, in one searchable database
100d ago
r/netsec monthly discussion & tool thread
100d ago
Handled, Not Hosted: Administrative Activity Inside a Bulletproof Hoster
100d ago
Seventeen vulnerabilities in Omi, fourteen days of silence
101d ago
High Fidelity Check for the cPanel Authentication Bypass (CVE-2026-41940)
101d ago
Copy Fail exploit lets 732 bytes hijack Linux systems and quietly grab root
102d ago
The Internet Is Falling Down, Falling Down, Falling Down (cPanel & WHM Authentication Bypass CVE-2026-41940) - watchTowr Labs
102d ago
The Thymeleaf Template Injection That Only Hurts If You Let It
102d ago
Set up automated dependency scanning after the recent npm/PyPI supply chain attacks
102d ago
A Route to Root in a 4G Industrial Router
103d ago
[Research] Full-chain RCE in Microsoft Semantic Kernel & Agent Framework 1.0 (6 Bypasses)
103d ago
The Bot Left a Fingerprint: Detecting and Attributing LLM-Generated Passwords
103d ago
89 vulnerabilities in XAPI / Citrix XenServer
103d ago
[ Removed by Reddit ]
104d ago
Kaspersky recently disclosed PhantomRPC, a privilege escalation technique affecting all Windows versions (tested on Server 2022/2025)
104d ago
Why a Decade of Writing Detection Logic Makes the Mythos Exploit Numbers Less Scary
104d ago
MCPwned: a Burp Suite extension for auditing MCP servers
104d ago
318 loaded
SK
STÖK
17d ago · 15 items
They hacked Google's AI in Seoul
17d ago
☔️🌅
78d ago
Life in the Nordics 🌲 | Foraging Blueberries, Mushrooms & Nosework Training with Our Dogs
350d ago
Winter vanlife = good times
952d ago
What an experience! Getting a Christmas tree from our own piece of land. #movingupnorth!
959d ago
Had to much GLÖGG and lost my camera during - 13371122 - Intigriti + Visma
965d ago
IS THIS THE END?
1025d ago
Escaping the grind and decompiling python 3.9 pyc files to find vulnerabilites
1180d ago
How to turn bugs into a "passive" income stream! ft Detectify's Almroot
1420d ago
HOW DID THIS HAPPEN!? (13370822 LHE VLOG)
1434d ago
Q: How to write a BUG BOUNTY report that actually gets paid?
1550d ago
facts: Bug Bounty hunters has made ridiculous amounts of $$ from known DNS techniques..
1564d ago
Q: HOW do you find hidden stuff on websites? (this episode is all about CONTENT DISCOVERY!)
1578d ago
Q: HOW do you get started in bug bounty?? How do you build your automation?!
1592d ago
Q: PENTEST VS BUGBOUNTY? (Bounty Thursday's - ON AIR)
1606d ago
15 loaded
CD
Cyber Defense Magazine
20d ago · 95 items
Ransomware in the Dairy Aisle: A Look at Fairlife’s Cyberattack
20d ago
UK’s Largest Cybercrime Case Ends in Prison for Spider Hacker
23d ago
Hacking US Elections: The First Tranche of Declassified Election Integrity Documents
23d ago
Inside Microsoft’s Record-Breaking 622-Bug Release
24d ago
Breaking the Knot: Marlinspike Capital Inverts the Cybersecurity Investment Playbook
25d ago
Inside “Gold Eagle”: The White House’s New AI-Driven Clearinghouse for Critical Infrastructure
25d ago
CISA Warns Russian FSB Hackers Are Targeting Critical Infrastructure Routers
26d ago
The Threat Mechanism and Mitigation of Pink Vishing Campaigns
27d ago
See It Once, Stop It Everywhere
29d ago
Cybercriminals Targeting World Cup Fans
30d ago
Innovators Spotlight: Brinqa
30d ago
The Cost of Delayed Patching: What Security Teams Are Missing
30d ago
Invoice Fraud Is Now a Cybersecurity Exposure
30d ago
The Chaya_006 Alert: OT Edge Devices Under Fire
39d ago
Nissan Americas Hit in Global Oracle PeopleSoft Data Breach
40d ago
CISA Warns Attackers Are Targeting Critical Internal Business Platforms
41d ago
Return On Risk: The New Measure Of Cyber Resilience
42d ago
Path to StateRAMP
42d ago
Rethinking Identity Security In The Age Of AI Driven Fraud
43d ago
New Age Insider Risk
43d ago
Openclaw And The Agentic AI Inflection Point: From “Cool Demo” To Governed Infrastructure
44d ago
Reasonable Reliance: The Test Duty-Holders Are Quietly Being Held To
44d ago
The Moment Of Reliance: The Question Safety Governance Cannot Currently Answer
45d ago
The New Face Of Fraud: Why AI Is Making Older Adults The Primary Target
45d ago
NSA Urges Cyberthreat Timeline Has Compressed From Years to Months
45d ago
Governance Is Failing: Why Converged Digital Risk Is Outpacing Every Control We Have
46d ago
Invisible By Design: Making Quantum-Safe Encryption The Easy Path
46d ago
Magecart Evolves and Attackers Weaponize Ethereum Blockchain for Digital Skimming
46d ago
Innovator Spotlight: NAKIVO
47d ago
Cybersecurity Outsourcing. Beyond Cost
47d ago
Inside The Rising Cyber Risk To Insurers: Why Insurance Companies Are Now Prime Targets
47d ago
Supply Chain Compromise: Nintendo Vendor Breach Exposes Internal Data
47d ago
Data Breach with Eastman Kodak Company
48d ago
The World Cup Is Here… And So Are The Cyber Risks
48d ago
Cloud Managed Services For Modern Cybersecurity To Secure Cloud
48d ago
Exploring The 2025 Cyber Threat Landscape: Analysis From The IT And Food And Agriculture Sectors
49d ago
The Shadow AI Paradox: Governing Innovation At Machine Speed
50d ago
Innovator Spotlight: Ensemble
51d ago
Innovator Spotlight: Centrii
51d ago
NSPM-12: The New Baseline for National Security Cybersecurity
51d ago
Five Compliance Realities Federal Contractors Can’t Ignore
52d ago
Cyber Security Market Insights & Trends Driving The Next Wave Of Protection
53d ago
AI is Not Solving Cybersecurity Burnout Yet, New ISSA and Omdia Research Warns
54d ago
Crypto’s Biggest Unresolved Risk Is Not Theft Of Assets, It’s The Collapse Of Identity Certainty In Financial Transactions
54d ago
Could GPU-Accelerated EDR Improve The Future Of Endpoint Detection?
55d ago
CMMC Is Exposing A Major Gap In The Defense Supply Chain
56d ago
Zero Trust For AI In Defense Networks
57d ago
Why Most Cyber Resilience Programs Fail Before The First Incident
58d ago
Breaking Free Of The Cyber Insurance Market’s Moment Of Frustration
59d ago
What The Cybersecurity Industry Knows And Will Not Say
60d ago
Rethinking Access Governance for AI Agents
61d ago
How CIAM Helps Boost Business
62d ago
World Cloud Security Day
62d ago
CMMC Is Here, But AI Changes The Compliance Conversation
63d ago
Cybersecurity Improved Detection But Exposed a New Problem
64d ago
Innovator Spotlight: Airrived
65d ago
Cloud Security In Practice
65d ago
Segment With Purpose: A Zero Trust Blueprint For OT Network Segmentation In Manufacturing
66d ago
The Expanding Attack Surface And How Identity Is Now The Primary Breach Vector
67d ago
Officials Confirm Early Rollout Of CMMC Requirements At CMMC Northeast Summit
68d ago
Why Is Cybersecurity Now A Business Priority, Not Just An IT Function?
84d ago
The Security Mistakes Being Repeated With Ai
85d ago
The Hidden Risk For IT Subcontractors: When Insurance, Not Security, Costs You The Contract
86d ago
Innovator Spotlight: Klever Compliance
87d ago
Innovator Spotlight: Radware
87d ago
Innovator Spotlight: JScrambler
87d ago
Innovators Spotlight: OPSWAT
88d ago
The Board Is Asking The Wrong Security Question
88d ago
Synthetic Identity Fraud Requires An Equal Focus On Biometrics And Document Verification
89d ago
Innovator Spotlight: Iru
90d ago
Innovator Spotlight: Axonius
90d ago
Security In The AI Era: Why Compliance, Infrastructure, And Platform Security Must Converge
90d ago
The SMB Cybersecurity Gap: Why Small Businesses Are The Fastest-Growing Attack Surface
90d ago
Fighting Fire With Fire: Future-Proofing The Cybersecurity Workforce With AI
91d ago
Innovator Spotlight: Lineaje
92d ago
Why Vulnerability Scanning Is Not Penetration Testing, And Why Cisos Should Care
93d ago
Bouncing Back from Cyberattacks: How Fast Recovery Is Mastered
94d ago
When AI Stops Assisting And Starts Discovering: What Claude Mythos Preview Means For Cybersecurity
94d ago
Innovators Spotlight: Badge (Part II)
95d ago
Redefining Security Operations Through Seceon’s Open Threat Management Platform
95d ago
The Insurance Industry Is Rewriting Cybersecurity Strategy
96d ago
Securing The AI-Enabled Workforce: The Next Evolution Of Human Risk Management
97d ago
Ai Didn’t Break Cybersecurity, It Revealed It
98d ago
RSAC 2026: The Power of Community
99d ago
Inside RSAC 2026
100d ago
Innovator Spotlight: The Open Group
101d ago
Preparing For Hybrid Warfare: Actions To Take When The Cloud Goes Dark
101d ago
Operationalizing Cyber Resilience: A Practitioner’s Framework for Real-World Security Constraints
102d ago
Innovator Spotlight: Puneet Bhatnagar
103d ago
Cybersecurity Risks in 2026
103d ago
Retro-Coding and the Roots of Logic: Why The Byte Brothers: Program a Problem Still Matters
104d ago
Innovator Spotlight: TokenCore
104d ago
Platform Engineering: The Rise of a Disciplinary Rethink
104d ago
60% Of Cyberattacks Are Identity Based — Is Identity First A Bad Idea?
104d ago
From Threat Detection To Decision Intelligence: Rethinking Modern Cyber Defense
105d ago
95 loaded
TL
The Last Watchdog
25d ago · 34 items
News alert: Pulse Security launches with $8 million for AI platform to modernize CISO operations
25d ago
SAN FRANCISCO, July 15, 2026, CyberNewswire – Backed by Foundation Capital and Zetta Venture Partners with $8M in seed funding, Pulse Security delivers the program intelligence and agentic infrastructure that security leaders have been mi...
News alert: Insignary’s on-demand SBOM verification boosts software supply chain security
25d ago
TORONTO, July 15, 2026, CyberNewswire ŌĆō According to Insignary Inc., a leader in software supply chain security and binary software composition analysis (SCA), most organizations cannot independently verify what is actually inside the sof...
News alert: Tego AI finds Anthropic’s integration of Claude and Slack can trigger unauthorized actions
26d ago
TEL AVIV, Israel, July 14, 2026, CyberNewswire – Tego AI, a cybersecurity company, published new research identifying a potentially critical security weakness in Claude Tag, Anthropic’s native integration between Claude and Slack. Resea...
News alert: OpenMatter joins HOL initiative to shape trust standards for autonomous AI
32d ago
MELBOURNE, Fla., July 8, 2026, CyberNewswire – OpenMatter Network today announced that it has joined the founding group of organizations participating in the Hashgraph Online (HOL) Partner Program, where the company will help develop stan...
News alert: Insignary tackles SBOM accuracy gap as AI tools intensify software supply-chain risk
34d ago
TORONTO, July 6, 2026, CyberNewswire тАУ Insignary, Inc., whose patented binary fingerprint technology has been cited in four Gartner research reports, today announced its recognition as a Sample Vendor for Reachability Analysis in the Gart...
News alert: Link11 launches faster DDoS mitigation to counter AI-driven, adaptive network attacks
38d ago
FRANKFURT, July 1, 2026, CyberNewswire – Link11, a leading European provider of cloud-based cybersecurity solutions, today announced the launch of its completely rebuilt Layer 3/4 DDoS mitigation solution, designed to address the growing ...
News alert: Reflectiz partners with Taboola to host webinar on AI-driven marketing security risks
40d ago
BOSTON, June 30, 2026, CyberNewswire – Reflectiz, the web exposure management platform, today announced a live webinar with Taboola, "Securing Third-Party Marketing in the AI Era," taking place July 8 at 9 AM EDT / 3 PM CEST. Every market...
News alert: OpenMatter launches platform to verify AI activity across enterprise systems
40d ago
MELBOURNE, Fla., June 30, 2026, CyberNewswire – OpenMatter Network today announced the launch of its cryptographically verifiable platform for secure collaboration and AI governance, built on a simple premise: Don't Trust Data. Prove It. ...
News alert: SpyCloud report finds phishing surge exposing employee data at Fortune 100 companies
53d ago
AUSTIN, Tex., June 17, 2026, CyberNewswireŌĆōSpyCloud, the leader in identity threat protection, today released its 2026 Phishing Pulse Report, revealing that phishing attacks continue to increase in both volume and sophistication for enter...
News alert: Heimdal study finds executives are more confident than frontline IT teams on AI risk
53d ago
LONDON, June 17, 2026, CyberNewswire–Heimdal today published The State of AI Risk Management in 2026, a survey of 1,000 IT professionals across the United Kingdom and the United States. The report's headline finding is a divide inside the...
News alert: Aembit secures Copilot Studio agents with identity-based access controls and audit trails
54d ago
News alert: GitGuardian adds endpoint protection as developer laptops become credential troves
54d ago
News alert: Varist announces AI-scale malware detection for healthcare and medical imaging
54d ago
News alert: Cloud security report finds fragmented tools widening the cloud complexity gap
60d ago
News alert: Halo Security recognized for helping MSPs manage customers’ external attack surfaces
68d ago
FIRESIDE CHAT: Deepfakes exploit human emotion, making employee reflex training essential
68d ago
News alert: TVC Analyst Group names 12 vendors to watch ahead of Gartner’s security summit
73d ago
GUEST ESSAY: AI pipelines are shattering network security — most companies haven’t even noticed yet
75d ago
GUEST ESSAY: AI can speed up communication, but it can also weaken human connection
81d ago
News alert: Orchid Security study finds invisible identities now outnumber managed accounts
82d ago
MY TAKE: AI agents force a rethink of enterprise service lines as vendors move up the tech stack
83d ago
LW ROUNDTABLE: Microsoft Edge normalizes credential exposure — security pros push back
88d ago
FIRESIDE CHAT: Cyber insurers deepen SMB security role as supply chain attacks spread
89d ago
News Alert: Lyrie.ai joins Anthropic verification program, unveils protocol for securing AI agents
90d ago
News alert: LuxSci launches HIPAA-compliant email platform for mid-size healthcare market
96d ago
SHARED INTEL Q&A: PKI’s unfinished business—’digital passports’ for content, models and agents
101d ago
GUEST ESSAY: How augmented reality (AR) can turn building images into ad space with no control
103d ago
FIRESIDE CHAT: Leaked secrets are now the go-to attack vector — and AI is accelerating exposures
104d ago
News alert: BreachLock’s integrated attack validation platform debuts in Gartner AEV category
109d ago
Fireside Chat: PKI has carried digital trust through every tech advance—now comes the hardest one
111d ago
News Alert: NTT Research launches SaltGrain—advanced Attribute-Based Encryption security
116d ago
GUEST ESSAY: Google’s 2029 deadline exposes readiness gap as move to quantum-safe crypto lags
117d ago
News alert: Mallory launches AI-native platform to cut through alert noise and surface real risk
121d ago
FIRESIDE CHAT: Geopolitical turmoil, rising AI risk add a new layer to enterprise cyber defense
124d ago
34 loaded
PF
PYMNTS | Fraud Prevention Archives
25d ago · 10 items
78% of CFOs Say Payment Blind Spots Increase Customer Friction
25d ago
85% of CFOs Say Automation Cuts Payments Friction
27d ago
42% of Issuers Say AI Has Cut Fraud Losses by at Least $5 Million
32d ago
LexisNexis and Promon Help Brands Fight Rising Mobile App Fraud
37d ago
42% of Issuers Say Fraud and Disputes Are Driving Up Costs
38d ago
JPMorganChase and Amazon Back Aspen Institute Drive Against Scams
40d ago
World Cup Gives Cross-Border Payments Their Super Bowl Moment
41d ago
Banks Face a New ACH Fraud Test as Nacha Rules Take Effect
44d ago
The latest Nacha fraud rules require banks to expand fraud monitoring and adopt broader, risk-based oversight across ACH activity.
Nvidia Wants Banks to Hunt Fraud Rings, Not Just Bad Charges
45d ago
Nvidia’s AI blueprint maps connections across accounts and devices to catch the fraud network, not just the charge.
AI Forces Compliance Teams to Rethink Alert Strategy
45d ago
FP
Fraud Prevention – Riskified
26d ago · 1 items
WE
WeLiveSecurity
26d ago · 48 items
Forgotten UEFI shims undermining Secure Boot
26d ago
ESET Threat Report H1 2026
32d ago
Cyber readiness for SMBs: Getting the basics right
37d ago
This month in security with Tony Anscombe – June 2026 edition
40d ago
Inside the inbox: Why cybercriminals want to break into your email account
41d ago
SMB cyber readiness: the road to resilience starts here
44d ago
Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances
45d ago
ESET takes part in Operation Endgame to disrupt Amadey and Stealc
46d ago
Killing me gently: Inside Gentlemen’s EDR killer framework
52d ago
Protecting legacy OT systems against modern cyberthreats
53d ago
FishMonger’s arsenal upgraded: SprySOCKS for Windows
54d ago
EvilTokens: A phishing attack that doesn’t steal your password
55d ago
OceanLotus: From external espionage to domestic targeting
59d ago
Unpacking SMB cyber-readiness – and what makes or breaks it
60d ago
Cybercriminals: the 'auditors' you never hired
61d ago
Lessons for life: Why children’s data is a long-term identity risk
67d ago
This month in security with Tony Anscombe – May 2026 edition
72d ago
ESET APT Activity Report Q4 2025–Q1 2026
73d ago
What to consider before asking an AI chatbot for health advice
74d ago
BTMOB: A stealthy RAT burrowing deep into Android devices
75d ago
Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise
79d ago
Webworm: New burrowing techniques
81d ago
The quest for greater tech independence
82d ago
Why geopolitical turmoil is a gift for scammers, and how to stay safe
86d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
87d ago
Eyes wide open: How to mitigate the security and privacy risks of smart glasses
90d ago
Fake call logs, real payments: How CallPhantom tricks Android users
94d ago
Fixing the password problem is as easy as 123456
94d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
96d ago
This month in security with Tony Anscombe – April 2026 edition
101d ago
The calm before the ransom: What you see is not all there is
107d ago
GopherWhisper: A burrow full of malware
108d ago
New NGate variant hides in a trojanized NFC payment app
110d ago
What the ransom note won’t say
111d ago
That data breach alert might be a trap
114d ago
Supply chain dependencies: Have you checked your blind spot?
115d ago
Recovery scammers hit you when you’re down: Here’s how to avoid a second strike
121d ago
As breakout time accelerates, prevention-first cybersecurity takes center stage
124d ago
Digital assets after death: Managing risks to your loved one’s digital estate
130d ago
This month in security with Tony Anscombe – March 2026 edition
131d ago
RSAC 2026 wrap-up – Week in security with Tony Anscombe
135d ago
A cunning predator: How Silver Fox preys on Japanese firms this tax season
135d ago
Virtual machines, virtually everywhere – and with real security gaps
137d ago
Cloud workload security: Mind the gaps
138d ago
Move fast and save things: A quick guide to recovering a hacked account
142d ago
EDR killers explained: Beyond the drivers
143d ago
Face value: What it takes to fool facial recognition
149d ago
Cyber fallout from the Iran war: What to have on your radar
150d ago
48 loaded
AL
Alerts
52d ago · 44 items
CISA Adds One Known Exploited Vulnerability to Catalog
52d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
52d ago
CISA Adds One Known Exploited Vulnerability to Catalog
54d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
55d ago
CISA Adds One Known Exploited Vulnerability to Catalog
58d ago
CISA Adds One Known Exploited Vulnerability to Catalog
59d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
61d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
62d ago
CISA Adds One Known Exploited Vulnerability to Catalog
65d ago
CISA Adds One Known Exploited Vulnerability to Catalog
67d ago
CISA has added one new vulnerability to its KEV Catalog, based on evidence of active exploitation.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
68d ago
CISA Adds One Known Exploited Vulnerability to Catalog
69d ago
CISA Adds One Known Exploited Vulnerability to Catalog
72d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
73d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
74d ago
CISA Adds One Known Exploited Vulnerability to Catalog
75d ago
CISA Adds One Known Exploited Vulnerability to Catalog
79d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
80d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
81d ago
CISA Adds One Known Exploited Vulnerability to Catalog
86d ago
CISA Adds One Known Exploited Vulnerability to Catalog
87d ago
CISA Adds One Known Exploited Vulnerability to Catalog
93d ago
CISA Adds One Known Exploited Vulnerability to Catalog
94d ago
CISA Adds One Known Exploited Vulnerability to Catalog
95d ago
CISA Adds One Known Exploited Vulnerability to Catalog
100d ago
CISA Adds One Known Exploited Vulnerability to Catalog
101d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
103d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
107d ago
CISA Adds One Known Exploited Vulnerability to Catalog
108d ago
CISA Adds One Known Exploited Vulnerability to Catalog
109d ago
Supply Chain Compromise Impacts Axios Node Package Manager
111d ago
CISA Adds Eight Known Exploited Vulnerabilities to Catalog
111d ago
CISA Adds One Known Exploited Vulnerability to Catalog
115d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
117d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
118d ago
CISA Adds One Known Exploited Vulnerability to Catalog
123d ago
CISA Adds One Known Exploited Vulnerability to Catalog
125d ago
CISA Adds One Known Exploited Vulnerability to Catalog
129d ago
CISA Adds One Known Exploited Vulnerability to Catalog
130d ago
CISA Adds One Known Exploited Vulnerability to Catalog
132d ago
CISA Adds One Known Exploited Vulnerability to Catalog
135d ago
CISA Adds One Known Exploited Vulnerability to Catalog
136d ago
CISA Adds One Known Exploited Vulnerability to Catalog
137d ago
CISA Adds Five Known Exploited Vulnerabilities to Catalog
142d ago
44 loaded
AC
All CISA Advisories
52d ago · 125 items
Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT
52d ago
CISA Adds One Known Exploited Vulnerability to Catalog
52d ago
Schneider Electric EasyLogic T150 and Saitel DP
52d ago
AVer PTC cameras
52d ago
Rockwell Automation FactoryTalk Historian Site Edition
52d ago
AzeoTech DAQFactory
52d ago
Schneider Electric Easergy, EcoStruxture, PowerLogic, and Saitel Products
52d ago
Mitsubishi Electric MELSEC iQ-F Series
52d ago
Mitsubishi Electric Co.'s MELSEC iQ-F Series FX5-ENET/IP Ethernet Module
52d ago
CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure
52d ago
Rockwell Automation Logix 5370 & 5570 Controllers Vulnerable To Denial of Service Via CIP
54d ago
Rockwell Automation RSLinx
54d ago
Rockwell Automation FLEX I/O EtherNet/IP Adapters
54d ago
Rockwell Automation FactoryTalk Analytics PavilionX
54d ago
Rockwell Automation CompactLogix
54d ago
CISA Adds One Known Exploited Vulnerability to Catalog
54d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
55d ago
CISA Adds One Known Exploited Vulnerability to Catalog
58d ago
Yarbo Android/iOS Mobile Application and Cloud Infrastructure
59d ago
Naxclow IoT Platform
59d ago
Brickcom Cameras
59d ago
CISA Adds One Known Exploited Vulnerability to Catalog
59d ago
Siemens KACO Blueplanet Inverters
61d ago
Schneider Electric EcoStruxure Panel Server
61d ago
Schneider Electric Modicon Network Managed Switches
61d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
61d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
62d ago
CISA Adds One Known Exploited Vulnerability to Catalog
65d ago
NAVTOR NavBox
66d ago
Hitachi Energy MACH HiDraw
66d ago
Hitachi Energy ITT600 Explorer
66d ago
B&R PPT30 Operating System
66d ago
Hitachi Energy RTU500
66d ago
CISA Adds One Known Exploited Vulnerability to Catalog
67d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
68d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
68d ago
CISA Adds One Known Exploited Vulnerability to Catalog
69d ago
CISA Adds One Known Exploited Vulnerability to Catalog
72d ago
ABB EIBPORT
73d ago
Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter
73d ago
ABB Busch-Welcome 2 Wire Door Opener Actuator
73d ago
Fourth Frontier Frontier X Mobile Application, Frontier X2
73d ago
CP Plus 8 Ch. Network Video Recorder
73d ago
XCharge C6
73d ago
KMW CCTV Security Cameras
73d ago
MacGregor Voyage Data Recorder (VDR) G4e
73d ago
Schnieider Electric EcoStruxure Machine Expert HVAC
73d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
73d ago
CISA Adds Three Known Exploited Vulnerabilities to Catalog
74d ago
ABB Terra AC
75d ago
ABB LVS MConfig
75d ago
ABB Ability Camera Connect
75d ago
Eppendorf BioFlo 320
75d ago
ABB AbilityTM Zenon Remote Transport Vulnerability
75d ago
ABB AC500 V2
75d ago
ABB B&R Automation Runtime DoS Vulnerability in System Diagnostics Manager (SDM)
75d ago
CISA Adds One Known Exploited Vulnerability to Catalog
75d ago
CISA Adds One Known Exploited Vulnerability to Catalog
79d ago
ABB Terra AC Wallbox
80d ago
Hitachi Energy GMS600
80d ago
ABB B&R Automation Studio
80d ago
ABB B&R Automation Runtime
80d ago
ABB B&R PCs
80d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
80d ago
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
81d ago
Kieback & Peter DDC Building Controllers
82d ago
Siemens RUGGEDCOM APE1808 Devices
82d ago
ABB CoreSense HM and CoreSense M10
82d ago
ScadaBR
82d ago
ZKTeco CCTV Cameras
82d ago
CISA Adds One Known Exploited Vulnerability to Catalog
86d ago
Siemens Siemens ROS#
87d ago
Siemens gWAP
87d ago
Siemens SIMATIC
87d ago
Siemens Ruggedcom Rox
87d ago
Siemens Ruggedcom Rox
87d ago
Siemens Simcenter Femap
87d ago
Universal Robots Polyscope 5
87d ago
Siemens Ruggedcom Rox
87d ago
Siemens Teamcenter
87d ago
Siemens Solid Edge
87d ago
Siemens SENTRON 7KT PAC1261 Data Manager
87d ago
Siemens Opcenter RDnL
87d ago
Siemens Ruggedcom Rox
87d ago
Siemens SIMATIC S7 PLC Web Server
87d ago
Siemens Industrial Devices
87d ago
Siemens SIMATIC
87d ago
Siemens SIPROTEC 5
87d ago
CISA Adds One Known Exploited Vulnerability to Catalog
87d ago
Software Bill of Materials for AI - Minimum Elements
89d ago
ABB AC500 V3 Stack Buffer Overflow in Cryptographic Message Syntax
89d ago
Subnet Solutions PowerSYSTEM Center
89d ago
ABB WebPro SNMP Card PowerValue Multiple Vulnerabilities
89d ago
ABB AC500 V3 Multiple Vulnerabilities
89d ago
ABB Automation Builder Gateway for Windows
89d ago
Fuji Electric Tellus
89d ago
CISA Adds One Known Exploited Vulnerability to Catalog
93d ago
CISA Adds One Known Exploited Vulnerability to Catalog
94d ago
MAXHUB Pivot Client Application
94d ago
CISA Adds One Known Exploited Vulnerability to Catalog
95d ago
ABB B&R Automation Studio
96d ago
ABB B&R Automation Runtime
96d ago
Hitachi Energy PCM600
96d ago
Johnson Controls CEM AC2000
96d ago
ABB B&R PVI
96d ago
CISA Adds One Known Exploited Vulnerability to Catalog
100d ago
Careful Adoption of Agentic AI Services
100d ago
ABB AWIN Gateways
101d ago
ABB Ability OPTIMAX
101d ago
ABB PCM600
101d ago
ABB Edgenius Management Portal
101d ago
CISA Adds One Known Exploited Vulnerability to Catalog
101d ago
ABB Ability Symphony Plus Engineering
101d ago
ABB System 800xA, Symphony Plus IEC 61850
101d ago
Adapting Zero Trust Principles to Operational Technology
102d ago
NSA GRASSMARLIN
103d ago
CISA Adds Two Known Exploited Vulnerabilities to Catalog
103d ago
CISA Adds Four Known Exploited Vulnerabilities to Catalog
107d ago
SpiceJet Online Booking System
108d ago
Carlson Software VASCO-B GNSS Receiver
108d ago
Hangzhou Xiongmai Technology Co., Ltd XM530 IP Camera
108d ago
Milesight Cameras
108d ago
Defending Against China-Nexus Covert Networks of Compromised Devices
108d ago
Yadea T5 Electric Bicycle
108d ago
Intrado 911 Emergency Gateway (EGW)
108d ago
125 loaded
CY
cybersecurity
59d ago · 1867 items
Any solutions we can use?
59d ago
Possible targeted attack
59d ago
RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline
59d ago
Facebook messenger to text
59d ago
Managing Solution Agents
59d ago
Nottingham University data breach affects over 450,000 students
59d ago
SWGs that support 3rd party external DNS resolver
59d ago
Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers
59d ago
Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG
59d ago
Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch
59d ago
Phishing awareness training resulting in ignoring company comms?
59d ago
How are you analyzing Android malware nowadays?
59d ago
Hackers Exploit Langflow Vulnerability for Remote Code Execution
59d ago
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research
59d ago
NEED SOME GUIDANCE
59d ago
Help setting up local encryption on my pc
59d ago
Agentic AI on Cybersecurity
59d ago
DoD 0-days Typically Come Down to Authorization Failures
59d ago
HDD
59d ago
Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets
59d ago
How can we test the firmware code/images security?
59d ago
20 years of Fancy Bear (APT28): How Russian military hackers evolved their tradecraft since 2004
59d ago
GitHub announces npm security changes to tackle supply-chain attacks
59d ago
The ‘Miasma’ worm source code briefly leaked on GitHub
59d ago
CISA Rewrites Federal Patching Requirements for AI Threat Era
59d ago
What is the difference between Regular TLS and Mutual TLS?
59d ago
Every employee's password was stored in a single Excel file
59d ago
npm v12 is changing how dependencies are installed to reduce supply-chain risk
59d ago
Why is Gartner Magic Quadrant treated like a procurement benchmark in South Asia?
59d ago
How good Microsoft Defender for storage?
60d ago
GreatXML bitlocker bypass vulnerability
60d ago
Struggle
60d ago
Did the work, got the certs, now I'm drowning. Should I keep labbing or go all-in on applications?
60d ago
Wiz launches Cloud Security Job Board
60d ago
Physical Project Ideas
60d ago
How can I get into cybersecurity while studying Information Systems Engineering?
60d ago
Cloud Security job board
60d ago
Continuous learning
60d ago
Angry bug hunter with Microsoft beef drops new Windows 0-day
60d ago
Mid-30s, stuck in web pentesting, and wondering what to do ?
60d ago
Streamline your Nmap triage: Interactive, single-file HTML reports from raw XM
60d ago
Is Microsoft Purview really secure when using Copilot?
60d ago
Banking app intentionally block some operations when connected to wifi due to "security reason" is this good or stupid feature?
60d ago
Nee academic references for Hashcat's 'Next Big Bang' log
60d ago
CISA released BOD 26-04: A new federal government vulnerability management strategy?
60d ago
Microsoft patches YellowKey, GreenPlasma, MiniPlasma zero-days
60d ago
added Mac support to my corporate hacking sim. Demo now available on Steam
60d ago
Suche aktuelle IONOS Phishing .eml für eine technische Blog-Analyse (Header & Artefakte)
60d ago
Students' data taken in major University of Nottingham cyber-attack
60d ago
Has unmanaged external file sharing ever burned you?
60d ago
Anthropic released Claude Fable 5 yesterday. Public version of Mythos with cyber classifiers
60d ago
Need feedback on my presentation
60d ago
Compensating controls besides admin credentials being needed to download software on employee endpoints
60d ago
OpenSSL PKCS#7 CVE-2026-45447
60d ago
Presentation Question
60d ago
How to Stay Ahead of Deepfake Evolution in 2026
60d ago
France’s Government Messaging App Tchap Got Breached
60d ago
Where's the fix for MiniPlasma?
60d ago
ServiceNow Flaw Exploited to Gain Unauthorized Access to Customer Instances
60d ago
Internships
60d ago
Six Proto6 Vulnerabilities in protobuf.js Expose Node.js Apps to RCE and DoS
60d ago
Microsoft Defender RoguePlanet Zero-Day Grants SYSTEM Access on Updated Windows
60d ago
Looking for a Reliable Cybersecurity Provider for a School in North Sydney
60d ago
Early Operational Visibility
60d ago
how are you actually managing ai agents in production?
60d ago
Al app builders: How are you handling security questionnaires when selling your product?
60d ago
[ Removed by Reddit ]
60d ago
How are all of doing with THE AI model thats big news currently??
60d ago
Skill to Scan your Codebase
60d ago
Miasma-style supply chain attacks
61d ago
FCaptcha v1.12: Catching AI Agents That Drive Real Browsers
61d ago
Flooding invalid deauth frames still kicks PMF clients, tested on 3 Android phones
61d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
61d ago
AI Malware Worm Adapts to New Targets in Real Time, Cybersecurity Experts Say
61d ago
Huntress Stack (MS Defender or SentinelOne)
61d ago
META DELETES FACE-RECOGNITION SYSTEM FROM ITS SMART GLASSES APP AFTER WIRED REPORT
61d ago
FBI is announcing Operation Riptide
61d ago
ServiceNow confirmed some customer instances were breached.
61d ago
Which are some of the best Cybersecurity / OT Security events that happen in GCC?
61d ago
DF/IR Community
61d ago
Chaotic Eclipse's new RoguePlanet
61d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
61d ago
Thoughts on Automated Compliance?
61d ago
A fix for the Windows BitLocker bypass vulnerability dubbed "YellowKey" is available
61d ago
North Korean Hackers—Posing As Fake IT Workers—Behind Nearly Half Of All Tech Firm Attacks, Report Says
61d ago
Microsoft has released a patch for the bitlocker bypass
61d ago
Please advices
61d ago
soc analyst l1
61d ago
Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow
61d ago
Looking to move off KnowBe4, what are people actually using these days?
61d ago
Too Many Certs, Not Enough Experience — What’s the Best Next Step?
61d ago
Authenticating ARP and NDP
61d ago
Does anyone use rule feeds in 2026?
61d ago
Building a tactical Pelican case for my Flipper Zero + AIO setup. Looking for advanced tool and script recommendations!
61d ago
Need a vm for practice
61d ago
Tips/Tricks to WFH as a SOC Analyst?
61d ago
Cybersecurity statistics of the week (June 1st - June 7th)
61d ago
Where can GRC folks learn practical AppSec / DevSecOps without going full engineer?
61d ago
I almost got “onboarded” into a malware campaign disguised as a job opportunity.
61d ago
University of Toronto proof-of-concept AI worm spread to 62% of a test network in 7 days using a free open-weight model
61d ago
AI Blocklist - help
61d ago
Protecting AI workloads on Linux servers
61d ago
Exposing DoNex Ransomware Secrets with Malcore!
61d ago
What are the different Disaster Recovery scenarios your teams have tested on?
61d ago
someone actually leaked the Miasma supply chain attack toolkit source code on github
61d ago
WinGet - Code Execution, Persistence and Detection Strategies
61d ago
Ransomware attack shuts Illinois high school until Wednesday
61d ago
Ideas for demo
61d ago
Microsoft account hacked through infostealer. Trying to log in using authenticator, but not successful. Help please?
61d ago
Harnessing Generative AI for Automated Reverse Engineering, Static and Dynamic Analysis, and Risk Scoring of Fraudulent Mobile Applications (APKs) and Malwares.
61d ago
Physical attack device
61d ago
Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer
61d ago
IT GRC News?
61d ago
Meta Says Israeli Spyware Firm Targeted WhatsApp Users Again
61d ago
Shifting L7 validation to the edge to stop DB resource exhaustion?
61d ago
Google Patches 5th Chrome Zero-Day Exploited in 2026
61d ago
EC Council CEH exam advice
61d ago
About NPower vs PerScholas
61d ago
Looking for a vulnerability to learn
61d ago
From Brute Force to Malware Execution: Investigating a Multi-Stage Cyberattack in Splunk
61d ago
Bad USB through charger?
62d ago
Recommendations for Discord community for latest AI security products
62d ago
Vulnerability Summary for the Week of June 1, 2026
62d ago
Windows Defender Tamper Protection stuck off - no active GPOs, SFC corruption, looking for ideas
62d ago
I feel like ive lost my passion to tinker after 6 years in the industry, anyone else?
62d ago
I wrote a free, no sign up, defender guide for suspicious USB devices and rogue hardware, with copy-paste detection examples
62d ago
really need help with project ideas for MSc
62d ago
Which Course for an almost-complete noob? (SANS.edu)
62d ago
SoFi confirms third-party data breach at Hong Kong subsidiary
62d ago
For the 2nd time in weeks, Microsoft packages laced with credential stealer
62d ago
Iran Signed a Ceasefire — Its Hackers Didn't
62d ago
New Shai-Hulud attack trojanizes 19 science-focused PyPI packages
62d ago
DSPM étude marche
62d ago
CMMC Phase 2 November 2026: two readings of SR.1 — C3PAOs are applying the one that requires a verifiable chain, not just a file
62d ago
AppSec / Pentesting job market in Canada for experienced overseas applicants?
62d ago
Stop Treating Low Severity CVEs as Noise. Start Treating Them as Ingredients.
62d ago
Automation Playbooks - which ones would you not want to live without?
62d ago
Is it necessary/important to Hash and salt API Keys for a strictly internal use tool?
62d ago
Need review on the OMS Cybersecurity program from Georgia Tech?
62d ago
If You Use Claude or Gemini, This Microsoft Breach Means Your Data Is at Risk
62d ago
2026 Verizon DBIR: vulnerability exploitation overtakes stolen credentials as #1 breach entry point for the first time in 19 years
62d ago
How do you close an alert
62d ago
What cybersecurity certifications are great value for money?
62d ago
Boxes for CPENT
62d ago
SIEM: is it "SIM" or "SEEM"
62d ago
I’m looking for recommendations for an online Master’s program that is recognized in the Middle East. (Better if certifications are included)
62d ago
How justdeleteme and justgetmydata work?
62d ago
I need help - PCI DSS 4.0 requirement 11.6.1
62d ago
How are you learning agent pen testing?
62d ago
Cyber security intern
62d ago
Meta to take legal action against Israeli spyware company NSO
62d ago
Inside SStar Agent, a cross-platform RAT with an unfinished macOS toolkit
62d ago
What's the best way to alert companies of a Glassworm copycat?
62d ago
How To Verify If A Site Is Legit?
62d ago
What is Flaresolverr
62d ago
Research: defenders using generative AI to simulate malware variants before they exist in the wild
62d ago
How are regulated orgs actually letting engineers use Claude Code / Copilot?
62d ago
Cyber security expo Manchester
62d ago
Remote Hiring Opened the Talent Pool — and the Fraud Surface
62d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
62d ago
What certs should I do during summer of 11th grade?
62d ago
CISA: Patch actively exploited SolarWinds Serv-U DoS vulnerability (CVE-2026-28318)
62d ago
Nobody needs Mythos or 0-days to build a chaos-causing computer worm – free open source models work just fine
62d ago
Oxford University discloses data breach after careers platform hack
62d ago
Vendor ISO 27001 Assessment - Questions Around Control 8.29 Security Testing
62d ago
Got this message from “SimBoss”
62d ago
PKCS12 Golang fork
62d ago
Malware Insights: Miasma Campaign
62d ago
73 Microsoft GitHub repositories impacted by Miasma malware
62d ago
[Honeypot Research] Looking for volunteers to test telemetry/logs
62d ago
What is the condition of Bug Bounty program in the era of AI.
62d ago
Opening a cloned repo is no longer safe
62d ago
Meta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse
62d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
62d ago
Google Colab CLI opens runtimes to Claude Code and Codex
62d ago
VS Code Adds 2-Hour Extension Auto-Update Delay to Limit Supply Chain Attacks
62d ago
The AI governance gap no one is talking about: deployment-stage accountability
62d ago
Free Study Resources for Comptia Cysa+
63d ago
Mentorship Monday - Post All Career, Education and Job questions here!
63d ago
Hi there
63d ago
Final risk-based IT Audit interview round with Director and have no experience. Please help!
63d ago
Needed help
63d ago
[ Removed by Reddit ]
63d ago
Career advice
63d ago
PhD in cyber Security
63d ago
Built a password guessing game. Almost everyone stuck in level 5.
63d ago
OSINT (SOCIAL MEDIA)
63d ago
Beginner KQL project
63d ago
Question about WORM and encryption
63d ago
Update:Certified cyber security
63d ago
Has anyone have any idea what to expect from Information security engineer- Network interview at Glidewell Dental
63d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction)
63d ago
Malware that survives reinstalling the BIOS and OS
63d ago
Am I overthinking the x86 compatibility issues? how much friction am I actually facing?
63d ago
Fedora Linux 43 exposes 20-year-old Microsoft Outlook security failure
63d ago
Managing Microsoft Identity Is More Complicated Than It Looks
63d ago
My work email got subscribed to a bunch of israel newsletters
63d ago
Shadow AI
63d ago
Rate limiting is not enough. What else can I use?
63d ago
How To Avoid Potential Malware From Transferring To New Laptop
63d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
63d ago
Can't decide.
63d ago
looking for partners
63d ago
My edge is changing into bing when I search something
63d ago
Cybersecurity reality check
63d ago
[ Removed by Reddit ]
63d ago
Information Management
63d ago
IronWorm Malware
63d ago
Why do we use UNC for smbclient ? Why don't we use UNC for nc or ssh?
63d ago
Why do we use UCL for smbclient ? Why don't we use UCL for nc or ssh?
64d ago
Everyone's planning post-quantum migration for enterprises. Nobody's talking about your password manager
64d ago
Is a separate “clean” S3 bucket actually a security boundary for uploaded files?
64d ago
CVE-2026-46640: Developing payloads for Twig sandbox bypass
64d ago
PenTest+ Exam
64d ago
AI Agent Uncovers 21 Zero-Days in FFmpeg; Chrome Patches Record 429 Bugs
64d ago
Looking for guidance
64d ago
Before you attempt any OffSec certification, read what just happened to me
64d ago
Reporting Metrics for Management
64d ago
got hit with SOC 2, cyber insurance, and a prospect pentest request at the same time
64d ago
Found an old Discord CDN ZIP in Opera downloads and I’m trying to figure out if I should be worried
64d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
64d ago
AI Security Certificates
64d ago
Guys is bug bounty dead?
64d ago
How are folks making it in bug bounty?
64d ago
How useful is it to require at least one uppercase letter in a password?
64d ago
Cyber security ! Is no more ?
64d ago
CISA: Hackers now exploit SolarWinds Serv-U flaw to crash servers
64d ago
Ghosts in the Cloud: Chinese Hackers Hid in Microsoft 365 Networks for 18 Months
64d ago
Antimiasma Worm to discover/mitigate/vaccinate Miasma worm infected repositories
64d ago
How to train employees to feel when something's off?
64d ago
ALERT OVERLOAD
64d ago
CTO at NCSC Summary: week ending June 7th
64d ago
A new BitLocker bypass allows access to encrypted drive in the pre-boot environment with all Windows security features enabled
64d ago
Microsoft Azure Repositories Compromised (Disabled) as Miasma Worm Targets AI Coding Agents Through GitHub
64d ago
AppSec Engineer Interview Stories
64d ago
[OpenSource] Multi-layer sandbox for native code execution on Linux with no external deps.
65d ago
Is there a safe way to continue using (unsupported) Windows 10?
65d ago
Is Splunk suitable for smaller Enterprises?
65d ago
Has anyone else had MFA prompt fatigue issues with users?
65d ago
Data Scrubbing from Databases
65d ago
Best Certificates?
65d ago
Rant
65d ago
New York passes data center moratorium and consumer protections as environmental, and housing proposals stall
65d ago
Cyber attackers have a new favorite, the browser
65d ago
Looking to get into cybersecurity in web3
65d ago
Microsoft discovered that Anthropic's Claude Code GitHub Action is vulnerable to prompt injection attacks via issues and Pull Requests
65d ago
Should i use email 2fa or only auth and phone number?
65d ago
Can I break into cybersecurity with a white collar felony?
65d ago
Open Source Intelligence - Building AI Systems That Handle Contradiction at Scale
65d ago
How are people supposed to defend against both supply chain attack and zero-day vulnerabilities at the same time?
65d ago
What kind of topics do you think should be covered more (in conferences, youtube etc) but they arent?
65d ago
How Hard is This
65d ago
Installed Fake Codex hidden as a google site
65d ago
Virustital scan result help
65d ago
CrowdStrike Turned an AI Wave Into Its Best Quarter Ever
65d ago
Cyber Resilience Act - Position? Pain points? Struggle? Possible solutions?
65d ago
I fell for the cybersecurity degree trap and thought I could beat the job market, I could not. Not sure what to do now
65d ago
Being a Security Engineer? Which AI-powered tools are you using on a daily basis?
65d ago
Over 900 US gas station tank gauge systems exposed to attacks
65d ago
Google and FBI warn of ransomware group that sends fake IT workers to hack victims in person
65d ago
SIEM is broken in the AI agents era
65d ago
Google Cloud hit by fresh layoffs, security and Mandiant teams among those affected
65d ago
Phantom Gyp npm Worm Abuses node-gyp Build Hooks
65d ago
Certified cybersecurity ISC2
65d ago
Help studying for OSCP
65d ago
The current state of Threat Intelligence Tooling
65d ago
Malicious podcast, PDF apps spread FlutterShell macOS backdoor malware
65d ago
We tested offensive AI agents against deception technology
65d ago
A matter that I have been losing my sleep over
65d ago
Any experience with Rootly or incident.io for cyber incident management?
65d ago
CTIA Study Resources & Preparation Advice?
65d ago
Black hat uk vs brucon
65d ago
Cisco warns of unpatched SD-WAN zero-day exploited in attacks
65d ago
NIS2 hits railway hard
65d ago
I need help guys… :(
65d ago
Question from the Seniors
65d ago
China-Linked Cybercrime Group Expands Attacks Beyond Asia With AI-Assisted Malware
65d ago
what certs have u seen in ai security related job posts ?
65d ago
How is the Security Architecture / Strategic IT Security process structured in your organization?
65d ago
What's happening in cybersecurity job market in US and Europe these days?
65d ago
Has any of you pivoted from GRC to CTI?
65d ago
Up-date-list of cybercrime types?
65d ago
What else should I learn to build a strong cybersecurity foundation?
65d ago
Hackerone interview
65d ago
Ransomware in the AI Era | ft. Behnaz Karimi | Ep. 109 | ScaleToZero Podcast | Cloudanix
65d ago
Testing URL Rewriting?
66d ago
Got an internship in IAM with no qualifications and no soft skills
66d ago
Work Hours of DFIR/Cloud Security vs Pentest
66d ago
Narcissistic Tech Leader....
66d ago
Anyone else's firewall logs just explode after midnight?
66d ago
I'm replacing myself.. at least the boring parts
66d ago
Anyone else dealing with these phantom login attempts from China?
66d ago
Best way to fully clear windows and set everything up securely (pc, accounts etc)
66d ago
IBM, AT&T Accused by Whistleblower of Covering Up Foreign Hacks
66d ago
Soc analyst
66d ago
Do companies actually require cybersecurity insurance
66d ago
Uncommon/Unusual CrowdStrike Alerts
66d ago
Cyber analyst: law firm or bank
66d ago
best free av and how do i properly setup passwords?
66d ago
Five 9 Vulnerability
66d ago
CVE Lite CLI closes dependency gap — but won't stop modern threats
66d ago
Scope change
66d ago
We just stopped a social engineering attack on our service desk. Here’s how it played out.
66d ago
What is the most underestimated cybersecurity risk right now?
66d ago
Update: Company is paying for any certification, which should I obtain? Except Sans
66d ago
New paper: every AI model has a naturally occurring unforgeable fingerprint in how it ranks tokens, relevant to fake model detection and supply chain verification
66d ago
Anyone else's firewall vendor docs a total nightmare?
66d ago
Your opinions about a learning style
66d ago
Why Real-Time Fraud Prevention Is the Only Way to Stop AI-Driven Attacks
66d ago
New IronWorm malware hits 36 packages in npm supply-chain attack
66d ago
Anyone else see their firewall logs just explode after a cloud update?
66d ago
Are certifications necessary to get a job in cybersecurity?
66d ago
Part 2: Bulk-Injection / Back-dating Signature Found in Public Tech-Governance Dataset (RDB Constraint Bypass)
66d ago
Is retyping and translating textbooks too inefficient for CS/Cybersecurity?
66d ago
Free Microsoft Enterprise Security Assessment: Worth It
66d ago
How are organizations preparing for AI-generated phishing attacks?
66d ago
Inside the race to adapt to an AI-powered security world
66d ago
127.0.0.1 in eight headers: what attackers hide in X-Forwarded-For
66d ago
Microsoft blames unexpected Windows driver updates on caching issue
66d ago
Critical Ledger State-Machine Violation Found in Public Tech-Governance Node Dashboard (Debit Card Transaction Injected on 0 Balance)
66d ago
Your CPU model leaks through the browser via WASM timing differences
66d ago
Chinese Cybercrime Group in Spotlight for Record Campaign Pace
66d ago
Security Engineer 2 interview at Amazon coming up - What to expect?
66d ago
A researcher spent $1,500 testing if LLMs could hack a vulnerable app
66d ago
Help with university internship
66d ago
Are MCP servers becoming the next API security nightmare?
66d ago
What's the cybersecurity lesson you learned the hard way?
66d ago
ISO 27001 Surveillance audit vs Full recertification
66d ago
How important it is to get paid Cybersecurity certificates ?
66d ago
Researcher Drops a New VS Code Zero-Day After Losing Trust in Microsoft’s Disclosure Process
66d ago
Soc to Architecture
66d ago
Does "example file vulnerability" exists?
66d ago
VS code forces 2 hour cool down for most integrations.
66d ago
Company laptop isolated after Brave/Tor alert - should I be worried?
66d ago
Does anyone know how to send false positive to SOCradar ? virus total
66d ago
Looking for people to team up for Bug Bounties & CTFs
66d ago
Signal Without Smartphone
66d ago
I found a trojan on my pc and now im scared my private calls got leaked
66d ago
Meta, Microsoft & DOJ Smash Southeast Asia Scam Rings: 1.4 Million Accounts Removed, 63 Arrests
66d ago
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
66d ago
How do you change users behavior through awareness training?
66d ago
AI-built ransomware toolkit automates EDR evasion, AD discovery
66d ago
Safe Rust API for wolfSSL/wolfCOSE
66d ago
Looking for feedback on my open-source OT detection ruleset (29 rules for Wazuh/Sigma)
66d ago
AMD GPU Users might be compromised
66d ago
[ Removed by Reddit ]
66d ago
Five Eyes Warn: Chinese Spies Using LinkedIn Recruitment Tactics to Access Sensitive Information
66d ago
CISA warns of cyberattacks targeting fuel tank monitoring systems
66d ago
[CTF] Struggling to extract RTSP stream from generic Chinese IP Cams (Altobeam SoC) via ONVIF
66d ago
how to get good at cyber security?
66d ago
Anyone use CrunchAtlas?
67d ago
Prompt monitoring laughs
67d ago
Malicious Payload in ai-sdk-ollama npm Package
67d ago
Can Someone Please ELI5 - "YellowKey" (CVE-2026-45585) to me? (an IT admin that survived the Great Global CrowdStrike Outage of 24)
67d ago
what the HELL is dsztfso?
67d ago
Yubikey Alternative....?
67d ago
Hiring
67d ago
CVE-2026-42897: Applying the Mitigation and Closing the Incident Are Not the Same Thing
67d ago
Certification Advice
67d ago
Question about Linux kernel TLS ULP disclosed June 2 to oss-security
67d ago
An IT guy basically stole my entire gmail account and probably posted it somewhere...how do I search for this?
67d ago
How to Rob a Data Center (new article on data center physical security)
67d ago
US: California Back & Pain Specialists Exposes 133GB of Patient Medical Records on Public Server
67d ago
Is it worth taking the EC councils masters program?? Are they legit /2026
67d ago
Mid-level AppSec engineers: what do you actually study to prep for interviews?
67d ago
Company is paying for any certification, which should I obtain?
67d ago
Trusting Microsoft with your offensive security repos
67d ago
Automated Fault Injection Attack Framework
67d ago
Physical Biometric device as a security measure..??
67d ago
Cybersegurança
67d ago
Started Learning Cybersecurity
67d ago
InfraGard Application - Seeking Help | Student
67d ago
Orientación en Ciberseguridad
67d ago
Anthropic's coordinated vulnerability disclosure dashboard
67d ago
Hands Free: What LLM Driven Vulnerability Research Looks Like
67d ago
Real time Cybersecurity failures regarding Quantum computing/cryptography
67d ago
🕵️♂️ PCPJack Hijacked 230 Cloud Servers to Send Email. Here's How They Did It.
67d ago
A two-year-old RCE bug in Redis was just made public. An AI tool found it. The full exploit chain is out.
67d ago
CISA warns of active attacks exploiting Android, Linux bugs
67d ago
Found some open ports on a govt site, should i report or stay quiet?
67d ago
What is a good way to keep track of passwords for programs that don't support password managers?
67d ago
Cybersecurity statistics of the week (May 25th - May 31st)
67d ago
ASN Emissions Index. Networks ranked by how much noise they create on the internet.
67d ago
Have you sold cve before?
67d ago
i want to become a pentester, but i don't know how to
67d ago
The OT Security Problem Nobody Wants to Own
67d ago
Don't Take Wednesday Off When You Manage Vulnerabilities
67d ago
I finally finished a production version after 4 yrds
67d ago
Support role pivot to cloud security
67d ago
How do you manage your passwords?
67d ago
Mad rush to produce AI driven slop
67d ago
O Tails é seguro para acessar links suspeitos?
67d ago
Cyber Essentials plus + "legacy" network segments
67d ago
Insight for OPSWAT deep CDR
67d ago
Android vs iOS
67d ago
ShinyHunters leaks Charter Communications data: 4.9M customer records exposed via a social-engineering attack on an employee's Microsoft account
67d ago
Security Audits at an MSP
67d ago
[ Removed by Reddit ]
67d ago
Passkey registration breaks after moving off localhost..
67d ago
Does your team hire fresh AI engineer who doesn't know anything about Security operations?
67d ago
UARs for Equation (banking system)
67d ago
IoT pentesting cert
67d ago
Anthropic Expands Project Glasswing, Bringing AI Cyber Defense Tools to 150 More Organizations
67d ago
Experience with Tac Security
67d ago
Weedhack Attacks Minecraft Users, CountLoader Hits 86K, Miners Spread via Pirated Content
67d ago
Found Security Vulnerabilities in my university website
67d ago
Preinstall to persistence: Inside the Red Hat npm Miasma credential-stealing campaign | Microsoft Threat Intelligence
67d ago
AI - Threat to the CyberSec Industry?
67d ago
Built a honeypot platform to catch lateral movement. How are you guys detecting this?
67d ago
How should small SaaS teams safely answer customer security questionnaires?
68d ago
Can AI Do Intelligence Analysis? Apparently Not.
68d ago
PROMPTPurify - 14MB Tiny Prompt Injection Guardrail Open Weight Model
68d ago
Regarding Certified Ethical Hacker (CEH Practical) exam
68d ago
Asking for advices on pursuing first CERTIFICATE
68d ago
I opened my own company and I can't find clients!
68d ago
ShinyHunters vaza dados de clientes da Spectrum após recusa de resgate da Charter
68d ago
Do you support the idea of creating a European commission that would issue special licenses for social media platforms, with standardized account creation rules and mandatory KYC (Know Your Customer) verification requirements across the EU?
68d ago
Anyone knows Quad9 dns ?
68d ago
I've a fullstack dev, I'm devleoping my own authentication for my application, Can anyone help me for it's security aspects ?
68d ago
Greynoise swarm
68d ago
SecOT+ certification for free
68d ago
How is the state of the job market for mid-level security engineers?
68d ago
Is anyone else still coding manually to learn? The market will continue to hire people that know what's going on even if you can now use AI to code many things
68d ago
WaSteal Update: Infrastructure Pivoting Reveals 57 Additional Extensions, Campaign Now at 183 Total
68d ago
Laid off from TPRM job - need help on the future of my career
68d ago
Anyone compared RoboShadow vs ConnectSecure for vulnerability management?
68d ago
Any one send vulnerability to MITRE?
68d ago
Need advice for a 30 min Security Apprenticeship interview
68d ago
UltraViolet: your own Shodan, in Docker, with CVE/KEV/EPSS
68d ago
Microsoft insists Defender is enough for most PCs, but admits third‑party antivirus tools still offer extras it can’t match
68d ago
Virustotal API as private data source
68d ago
Account Number Security Flaw
68d ago
Is Red Team Leaders Certification (RTL) actually useful for jobs or just for learning?
68d ago
A PoC to demonstrate that without PMF, MAC filtering at the AP level is the only thing stopping selective WiFi deauth
68d ago
[ Removed by Reddit ]
68d ago
[ Removed by Reddit ]
68d ago
Phishing simulation platform
68d ago
Just task about OSI model
68d ago
Need help improving DNS Spy from a security tool angle
68d ago
Device Code Phishing Forensics: What We Learned Investigating BEC in the Wild
68d ago
Oracle's first monthly patch update just dropped 77 CVEs.
68d ago
Cleaning up after a legacy service account breach. How are you handling automated secrets discovery?
68d ago
Airbus digital apprenticeship
68d ago
Anthropic is expanding Project Glasswing — giving 150 more critical infrastructure orgs access to Claude Mythos to scan for vulnerabilities
68d ago
Google fixes one actively exploited Android zero-day, 124 flaws
68d ago
Can elections be hacked? Modern day computational propaganda techniques described by the EU's East Stratcom Task Force
68d ago
Parsing Cisco IOS configs for CIS Auditing: Why regex fails on block contexts, and how are you handling offline static analysis?
68d ago
Security Architects who who actively use modelling - What's your approach?
68d ago
PAN-OS authentication bypass bug added to list of exploited vulnerabilities
68d ago
I have extreme anxiety about being hacked
68d ago
Fresher
68d ago
Hackers Used Meta AI Bot to Hijack Instagram Accounts in Major Security Breach
68d ago
Career advice needed!
68d ago
GoDaddy found malware on 1,980 WordPress sites using Steam as C2 infrastructure
68d ago
Google sr. security engineer interview
68d ago
Is offensive AI actually changing cybersecurity, or are we overestimating the impact?
68d ago
Multiple Red Hat NPM packages victim of Mini Shai-Hulud Miasma wave
68d ago
is emerald chat safe?
68d ago
Does anyone on this subreddit who has an VirusTotal premium account can help me with something important ?
69d ago
ClickJack in the wild
69d ago
Thoughts on A.I assisted Malware Analysis?
69d ago
19-Year-Old Linux Kernel Vulnerability Exposes Systems to Root Access
69d ago
What articles do you use for cybersecurity news? (2026)
69d ago
Is anyone using agents in regulated industries? How do you make sure sensitive data doesn't go back to the AI provider?
69d ago
Roadmap and Training Recommodation
69d ago
Les anti-triche de niveau noyau et leur risque de sécurité
69d ago
Asked to Send Sensitive Documents via MMS
69d ago
SC-200 compared to CC (isc2)
69d ago
Every SaaS Company Is Accidentally Building Meta's Instagram Vulnerability Right Now
69d ago
Looking to move off KB4, what are people actually using these days?
69d ago
Got my Security+. What's next?
69d ago
Vulnerability Summary for the Week of May 25, 2026
69d ago
Malware
69d ago
Alternative Search Engine to Utilize in 2026?
69d ago
Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked
69d ago
Windows Server vulnerability can grant system privileges with just a malformed packet — domain controllers are being exploited in the wild
69d ago
Grand Theft Auto V cheat service gets hacked, exposing thousands of gamers
69d ago
AI compliance
69d ago
Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm
69d ago
Is TeamPCP a Russian-affiliated APT? How can preventive security principles assist defending ecosystems against attacks on software supply chains?
69d ago
MacBook or Windows Laptop for Cybersecurity
69d ago
What's the most creative MFA bypass you've seen?
69d ago
Research Notes from Building a Windows Event Log Hunting Workflow
69d ago
How to fix securityheaders scan X-Frame-Options and Content-Security-Policy ??
69d ago
Free AI tools for TPRM?
69d ago
incomplete phone number from togo, need help reporting to police
69d ago
NPM packages from RedHat Compromised
69d ago
Linux Copy Fail CVE-2026-31431: KEV Privilege Escalation on Shared Build Hosts
69d ago
SOC Analyst working towards Threat Intelligence
69d ago
Is XSS possible through PDFs?
69d ago
The Next AI Governance Failure Won’t Be the Model
69d ago
Microsoft MFA Is Down Again
69d ago
Started my first writeup - Sherlock NeuroSync-D (CVE-2025-29927)
69d ago
Computer logic or Science
69d ago
I am a Full Stack Developer but I want to switch to a cybersecurity centered position. Which positions should I prepare for?
69d ago
What C2s Are You Using
69d ago
PNPT Exam
69d ago
What do you do when a supplier refuses or lacks a reporting clause on vendor incident notification?
69d ago
Any appsec engineer working in fortune 500?
69d ago
I'm developing an IDS/EDR. I need suggestions which blind spots I have, whats missing and what should be added next
69d ago
Anyone transition from AWS Data Center Operations to InfoSec?
69d ago
I think my account got hacked but it's weird
69d ago
current market for detecting deepfakes?
69d ago
Worried about friend being doxxed on doxbin
69d ago
how to shift from a service based company to a product based one in cybersecurity ?
69d ago
Meta AI Password Reset Flaw Reportedly Bypassed Instagram 2FA
69d ago
Claude AI user data directory exfiltration via malicious npm package
70d ago
Bitdefender blocking amd stuff? False positive or?
70d ago
Mentorship Monday - Post All Career, Education and Job questions here!
70d ago
did they have my password?? what triggers this specific email??? instagram HELP.
70d ago
ATTENTION: Dashlane may have been breached. (Password manager).
70d ago
Norton blocked a “malicious script”?
70d ago
Need Advice: Ex Claims He Still Has Access to My Mac/iCloud After Resets and New Accounts
70d ago
Security researchers have uncovered a new attack technique that lets malicious websites spy on your browsing activity through hard drive.
70d ago
I wrote about the 5 biggest threats in 2026, curious what this community thinks.
70d ago
MSPs: What evidence do cyber insurance underwriters ask you for that is hardest to produce?
70d ago
Im new to cybersecurity and have a iPhone 7 (iOS 15.8.5) I wanna pentest, any suggestions?
70d ago
NetworkChuck
70d ago
LLM for creating phishing tool
70d ago
Why are we still treating IAM like a compliance checkbox?
70d ago
Polyfill pop up?
70d ago
SecAI+ difficulty question
70d ago
Could you guys give an honest feedback to a completely automated ssrf attack tool?
70d ago
tengo 61 y mi famila y amigos me espian I am 61 and my family and friends spy on me
70d ago
Microsoft Joined the DMARC Club
70d ago
Help.
70d ago
Vibe Coding Security
70d ago
Looking for a Company to Partner With
70d ago
Best reporting tools?
70d ago
What actually moved the needle on our alert fatigue (Wazuh + some automation, lessons after ~6 months)
70d ago
How Can Polyfill.io Still Act Maliciously?
70d ago
Need THM voucher code for cheap? Any known seller?
70d ago
Ghost passwords?
70d ago
Was a stipulation in my offer letter that I was required to obtain my CISM certification in 6 months... I did not.
70d ago
LLMReaper - DOM Based AI Conversation Exfiltration via Browser Extensions
71d ago
Anyone else having Chatgpt Strikes / Violations while learning cybersecurity?
71d ago
Working at Cisco, worth it?
71d ago
Want to Learn Cybersecurity in 2026 – Need Guidance, Roadmap, Tools, Resources & AI Advice
71d ago
Are you pen testing AI Agents?
71d ago
Question of android malware
71d ago
External attack surface: how are you correlating DNS, SSL, and IP reputation today?
71d ago
how do i properly setup 2fa and bitwarden?
71d ago
Hacking India's Largest Exam Evaluation Portal: From Authentication Bypass to Full Account Takeover (Covered by BBC)
71d ago
i need a partner to learn coding with me and have fun too,Hey, I'm 16 and just started learning cybersecurity and coding. I'm looking for a coding buddy around beginner level. We can learn Python, web development, and build small projects together. Anyone interested?
71d ago
Question for teams running parallel agents: Would you actually pay for a deterministic control plane, or are we all just building custom wrappers forever?
71d ago
Can Steam Cloud Files Transfer Malware
71d ago
Questions for the cloud security engineers
71d ago
Thoughts on this as a starter and doing bug bounty on the side
71d ago
How are new SC-200 candidates practicing labs without an E5 Developer tenant?
71d ago
Getting OTP spammed from every app and website I've ever used. Should I be worried?
71d ago
A browser tool for checking contractor insurance certificates
71d ago
Am I getting screwed?
71d ago
SECODER | Security Coding Challenges for SOC Analysts & Detection Engineers
71d ago
PAN-OS added to KEV, Langflow exploit activity, and a surprising Windows EPSS jump — today's most actionable vulnerability signals [Threat Intel 2026/5/29}
71d ago
CTO at NCSC Summary: week ending May 31st
71d ago
BountyLabs — Bug Bounty Training with Labs, Challenges, and AI Mentorship
71d ago
Need suggestion
71d ago
[INDIA] Need Advice: Shared mobile number risk on a joint minor account after a small P2P trade (P2P Fraud / Bank Freeze Anxiety)
72d ago
Was Dave Bittner interviewing an AI?
72d ago
CTF for complete beginner
72d ago
Hitting a plateau after 2 years in Web Security: How do I transition from standard OWASP bugs to finding CVEs and novel techniques?
72d ago
AI-Era Cyber Risk Standards
72d ago
BEC Victim - Attacker replied inside a real email thread using a lookalike domain
72d ago
Question for those who transitioned from remote to work from anywhere
72d ago
Website Keeps Getting Falsely Flagged as Phishing/Malicious By Security Vendors
72d ago
Do you enjoy what you do or do you wish you could go back in time and change it?
72d ago
Is understanding how API keys, public/private keys, and secrets actually work necessary to work in cyber?
72d ago
For those who made the jump to independent cybersecurity consulting, what was the hardest part of the first year?
72d ago
Is a basic understanding of PKI and Public Key Cryptography necessary to work in cyber ?
72d ago
Do you think AI will make cybersecurity products/services cheaper over the next 5-10 years?
72d ago
Botnet of more than 17 million devices dismantled
72d ago
Exposed credentials on logs
72d ago
What do you think is the biggest cybersecurity risk for small businesses in 2026?
72d ago
Wanted to shift to cloud security, but have some questions
72d ago
Zero Trust is Overrated? Navigating the Complexity
72d ago
Test API post with flair
72d ago
Warning on MAD20 Subscriptions: $500 Blind Auto-Renewals and Hostage Certifications
72d ago
How Do You Handle the Massive Amount of Information in the CPTS Path?
72d ago
Help an upcoming cybersecurity engineer!
72d ago
Repeated Microsoft MFA attempts even after password change
72d ago
What Is Device Intelligence and How Does It Stop Fraud?
72d ago
[FOSS Tool] WiFi-SpiderWeb V2.0: Active Cyber Defense for OpenWrt Routers with Live Radar Sweep (Python + SSE)
72d ago
IBM commits $5 billion to secure open-source software
72d ago
Structuring an AI-Assisted Pentesting Homelab for a Final Year Project
72d ago
Are teams actually monitoring LLM traffic in production environments?
72d ago
How to protect passwords from memory scraping/API hooking on a compromised target machine during a remote session? (No Admin access, No 2FA)
72d ago
Raspberry pi
72d ago
What is the biggest obstacle to using AI safely in a company?
72d ago
Advice going forward
72d ago
MCP Firewall help
72d ago
I wanted to shift to security but people told me the market is extremely bad, is that true?
72d ago
Best Personality Type/Traits for Working in Cyber Security
72d ago
A fake freelance job interview almost installed malware on my PC
72d ago
Is there a viable career path here or am I just being delusional?
72d ago
What 2,000 Exposed Vibe-Coded Apps Reveal About the Limits of Most Security Stacks
72d ago
How do enterprises actually prevent developers from exfiltrating source code?
72d ago
I have a datastealer malware
72d ago
Dúvida de carreira.
72d ago
Someone hid a full RAT inside a fake npm package and exfiltrated victim data to HuggingFace
72d ago
Need Cloud Security Engineer simulator to learn the Job. I need to be more hands on with running tools ,Please advise thank you. Your resources are appreciated
72d ago
is SIEM really needed here ?
72d ago
Decompiled an app, found a bunch of secrets, what now?
72d ago
Can someone give me a correct method for learning reverse engineering?
72d ago
Critical Gogs Zero-Day RCE Remains Unpatched After 2+ Months
72d ago
GRC Advise
72d ago
[ Removed by Reddit ]
72d ago
Did something happen to haveibeenpwned? Any alternatives?
72d ago
RAT SUSPECTED
72d ago
How do people afford certificate s?
72d ago
I’m curious — what’s one cybersecurity tip you wish more people knew before getting hacked or scammed?
72d ago
Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
72d ago
Phone Forwarding
72d ago
Opinions on running Full Microsoft E5 Security Stack
72d ago
Claiming "XDR"
72d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
72d ago
Microsoft security
73d ago
Need help regarding building a home lab
73d ago
Should I turn on passwordless accounts for all my Microsoft accounts?
73d ago
Transitioning from AWS Data Center Operations to Security Engineering
73d ago
Probably the wrong place.
73d ago
What after IT helpdesk?
73d ago
How are you security-testing API changes before production without slowing CI/CD?
73d ago
Are we trusting update repos or are you all extra paranoid now as well?
73d ago
Disgruntled 0-day hunter 'humiliated' by Microsoft pledges 'bone shattering drop' as Redmond calls cops
73d ago
Prevent supply chain attacks
73d ago
Cybersecurity Authorities Issue Joint Guidance on the Adoption of Agentic AI Systems
73d ago
FBI warns of fake FIFA websites running World Cup fraud schemes
73d ago
Hackers are trying to steal Signal users' backups in new wave of phishing attacks
73d ago
Incident Response Testing Preparation
73d ago
Kevin Mandia is speaking in NOVA on June 10 — probably the most candid you'll ever hear him outside of a major conference
73d ago
[Open-Source] WiFi-SpiderWeb: Turn any OpenWrt Router into an Active Cyber Defense & Honeypot System via USB 🕷️🔥
73d ago
3rd Party NFC cards.. secure?
73d ago
Vulnerability Management Tickets & SLA
73d ago
Defending at Machine-Speed: Building AI Threat Readiness
73d ago
AI agents running in our environment have broader access than our sysadmins and ownership of that is unresolved
73d ago
HEAD request body processing leading
73d ago
Malicious npm Package Stole Files From Claude AI User Directory via GitHub
73d ago
Does anyone have an app like substack to keep being updated and engaging within the cyber domain?
73d ago
What’s an attack vector people massively underestimate in 2026?
73d ago
We security-reviewed our own free CVE tool and shipped the fixes - EPSS Lookup Tool v2.7
73d ago
A Deeper Look at GLASSWORM's Solana Variant
73d ago
Calling Cyber Security Beginners
73d ago
Busco oportunidad laboral / consejos para iniciar en TI, ciberseguridad o análisis
73d ago
built something for ai agents, ended up looking a lot like classic appsec
73d ago
Is Gophish still usable in 2026?
73d ago
Microsoft vs Chaotic Eclipse: three zero-days now actively exploited
73d ago
what do you think
73d ago
Why would be clicking a website, redirect me?
73d ago
Zapier fixes bug chain that researchers say risked widespread account takeover
73d ago
Writing cybersecurity policies is a waste of time
73d ago
Raising the Cybersecurity Stakes: Ante up for the Agentic Era.
73d ago
Public CAs are exiting client authentication. Most organisations haven't inventoried what depends on it.
73d ago
[ Removed by Reddit ]
73d ago
Released: Dataforge Honeypot
73d ago
Google Unveils AI Threat Defense Platform to Fight AI-Powered Cyberattacks
73d ago
CEH-free
73d ago
Hottest cybersecurity open-source tools of the month: May 2026
73d ago
Preparation tips for CPENT
73d ago
How do you handle AI tools in your organization?
73d ago
I think i got scammed anybody can help me with that
73d ago
New phishing campaign targeting Japanese online banking users uses 'PayPoy' domain/branding typo
73d ago
Is it safe to have passwords copied to clipboard on IOS temporarily?
73d ago
Developers working on anti-fraud systems deserve more credit
73d ago
My company is moving to security clearance requirements but I am a foreign national. Anyone know time lines / realistic outcomes for me? Currently working as a sec analyst
73d ago
Security awareness training for AI heavy smb workflows?
74d ago
Minimum Requirements for Helpdesk Role ?
74d ago
Reddit spear phishing
74d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
74d ago
What to do
74d ago
What resources would you recommend for studying cysa+
74d ago
Provenance of Data
74d ago
Websites have a new way to spy on visitors: analyzing their SSD activity
74d ago
12 years in secops, military to vendor then internal. Internal feels like all loss and no win. Is this normal?
74d ago
Russian Art Teacher - Hinder Security Clearance?
74d ago
EDR/MDR Vendor Questions
74d ago
Cybersecurity as a Highschooler?
74d ago
New department created, would love your input
74d ago
OWASP Vienna - anyone going?
74d ago
Interview with Upstart
74d ago
18, immigrant in Portugal (no Portuguese), failing high school. Need a stable path to Hardware/Network Cyber.
74d ago
Is cloud security engineer viable with my current position?
74d ago
Cloudflare Access users: what would actually make JIT useful for you?
74d ago
eBPF to Detect Unexpected Control-Plane Traffic Inside GTP-U Tunnels
74d ago
Questions regarding Ubuntu 24 LTS hardening
74d ago
Cómo puedo interferir señal de un dispositivo que está cerca de mí para que no le funcione la señal de wifi a la que él está conectado, cómo puedo protegerme? Se me tipos de cómo protegerme, soy nuevo en esto, me gusta mucho.
74d ago
Honest question about OT Security Engineer work life in India
74d ago
Who is using CVE Lite CLI? Share your use case (OWASP Incubator Project for JS/TS dependency scanning)
74d ago
AI Security
74d ago
Iranian threat group targets US aviation sector with AI-assisted ‘MiniFast’ backdoor
74d ago
🚨 Exposed Global Smishing Operation Hitting 19 Countries Across 3 Continents
74d ago
Building Detection Engineering on AWS from scratch — roast my plan
74d ago
Academic Survey - AI in Cybersecurity Governance and Regulatory Compliance
74d ago
I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA.
74d ago
Research: All three major eBPF security monitors (Falco, Tracee, Tetragon) can be silently disabled via BPF map poisoning
74d ago
Final Year Project: Looking for non-generic IAM project ideas that solve real problems
74d ago
GlassWorm takedown: year-long developer supply chain campaign using VS Code extensions and npm packages dismantled.
74d ago
Breaking out of IT Helpdesk - how?
74d ago
A year in Cybersecurity — Where Do I Go From Here?
74d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
74d ago
22, SOC Analyst experience + certs, still no interviews since January - looking for honest advice from people in cyber
74d ago
FBI: Silent Ransom Group Turns to IT Support Ploy
74d ago
How do machine builders track Siemens/Rockwell security advisories?
74d ago
GlassWorm Developer Supply-Chain Botnet Takedown
74d ago
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
74d ago
Active Exploitation - LiteSpeed cPanel Plugin CVE-2026-48172 CVSS 10.0: Root Privilege Escalation added to KEV
74d ago
Got cybersec work what next ?
74d ago
Hi everyone! I’m a doctoral student conducting research on how people’s cybersecurity concerns affect their use of technologies like Apple Pay, smart devices, wearables. I’m looking for adults (18+) who currently use or have recently used these types of technology; smart devices or smart wearables
74d ago
Ekoparty Miami - Interface Anti-Patterns: Exploiting Insecure Navigation in 3rd Party Android App Lockers
74d ago
Trying to understand the scope of NVIDIA's attestation (NRAS), what am I missing?
74d ago
GitHub - facebook/mcpguard-dynamic: Kernel-level eBPF sandbox for securing LLM agent tool calls made through the Model Context Protocol (MCP)
74d ago
nightmare eclipse is probably French here is why
74d ago
Poor Risk Analysis Cost 4 Firms $1.7 Million in HIPAA Fines
74d ago
Measuring performance of JA4/JA4H AI Model
74d ago
What things are you really focused on this year?
74d ago
Hypothetical EDR spoofer
74d ago
ISO 27001 Audit Stage 1
74d ago
Microsoft SharePoint Has a New RCE Flaw. If You Haven’t Patched Yet, Go Do That.
74d ago
Looking for Hacker Friends to Learn☺️
74d ago
Comptes Instagram et Facebook piratés et désactivés
74d ago
How to safely disinfect a USB stick from potential malware files?
74d ago
Is anyone else concerned about how quickly AI is outpacing cloud security?
74d ago
What's a CyberSecurity job like?
75d ago
Microsoft Live credential stuffing
75d ago
I am on placement and part of a lab where we use cyber security and do research what jobs are similar to this?
75d ago
Security architects- summarize your responsibilities and role
75d ago
Finding Work in OSINT
75d ago
State of SDLC Security 2026
75d ago
Reported to police for coding html
75d ago
[Open Source] Desarrollé un mutador de huellas TLS en Rust para evadir sistemas Anti-Bot (JA3/JA4 scrambling)
75d ago
I open-sourced KernelEye — an eBPF/XDP-based Linux server security monitoring project
75d ago
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover
75d ago
Shai-Hulud Hackers TeamPCP: Lucky or Skilled Operators?
75d ago
KnowledgeDeliver flaw exploited as a zero-day to install web shells
75d ago
Breaking GROK'S DEFENSES to make it HACK Real Public Websites
75d ago
GitHub Actions Cache Poisoning is eating open source
75d ago
Nightmare-Eclipse has also been banned on GitLab :DD
75d ago
Do we still have time before we are in the Age of the movie "Minority Report"? ↓
75d ago
SimHub (popular sim racing dashboard software) appears to silently disable Windows Defender via hidden Group Policy file
75d ago
What Software Supply Chain, Water Filters, and Power Grids Have in Common
75d ago
QA engineer trying to move into AppSec — does this plan hold up?
75d ago
Is work from anywhere really impossible to find??
75d ago
Cybersecurity statistics of the week (May 18th - May 24th)
75d ago
Engineering a Post Quantum Fortress Inside the Citadel Archite
75d ago
Cyber Security Analyst
75d ago
Environmental consulting firm pushing heavy AI adoption despite employee concerns over environmental impact and data governance
75d ago
Two layer email security tool thesis
75d ago
When OTP rate limiting fails: OLX account takeover with persistent sessions
75d ago
Entra ID sessions revoke
75d ago
Anyone who attended GPCSSI before? Need some clarification
75d ago
Lost on my career path.
75d ago
EU-based folks: external pentest vs mandatory data/security training?
75d ago
help needed from experienced people
75d ago
How do you evaluate whether a privacy service is actually privacy-respecting?
75d ago
Which one Intellipaat or coursera which one to choose
75d ago
CERT-In Recommends 12-Hour Patching for Internet-Facing Flaws Amid AI-Assisted Attacks
75d ago
India's CERT-In just mandated patching critical vulnerabilities within 12 hours. That sounds good — but is it actually realistic?
75d ago
Audited 20 production repos after the May supply chain attack. Every single one had at least 3 of the 8 misconfigs.
75d ago
Did anyone pass the SC-200 certificate recently?
75d ago
Honeypot
75d ago
passkeys, MFA, biometrics, and you can still reset everything with access to one gmail account
75d ago
Career in IAM as a fresher
75d ago
CISA orders feds to patch actively exploited Drupal vulnerability
75d ago
Telegram's Hidden Gatekeeper? OCCRP Probe Puts Spotlight on Shadowy Engineer Linked to App's Infrastructure
75d ago
GitHub bans vindictive security researcher dropping Windows zero-days: “I will make sure your bones are shattered”
75d ago
Cyber security tool
75d ago
Saw this tool and it has potential
75d ago
🚨 14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-26): Critical Worms, Parse Server DoS, and AI RCEs
75d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Can Trigger Through Renamed Files
75d ago
Follow up : showing Claude install random pacakage in its vm instance without asking or prompting
75d ago
¿Is safe?
75d ago
Need help
75d ago
What is the best tool for masking in kali
75d ago
What are the best tools other than ghostTracker?
75d ago
TrapDoor Cross-Ecosystem Crypto Stealer Campaign
76d ago
Follow up : Steal Your Files Claude AI installing package because internet say so
76d ago
New to Cybersecurity: Looking for general advice & help with Nmap
76d ago
Open sourcing our hardware red team RF toolkit: the Crimson Flipper Arsenal
76d ago
Looking for tech role references
76d ago
How do you balance Paw?
76d ago
I'm a security professional who has dealt with ransomware. AMA about incident response and business continuity.
76d ago
From Stuxnet to Handala: The reverse-engineering of a nation-state cyber weapon and its implications for ICS/SCADA security
76d ago
Ghost CMS flaw being actively exploited to compromise 700+ sites and serve malware to visitors through fake CAPTCHAs. Patch has been out since February
76d ago
What Companies are Legit?
76d ago
start learning cybersecurity from scratch
76d ago
Follow-up: measuring LLM-agent failures with replay evidence
76d ago
Follow-up: measuring LLM-agent failures with replay evidence
76d ago
WhatsApp users on alert after hacker drops massive dataset
76d ago
17 years old going into CS — what certs should I start going after now?
76d ago
i want to hire an osint expert
76d ago
Open University pros/cons
76d ago
How important do you think browser/device fingerprinting has become for modern fraud detection compared to traditional bot detection?
76d ago
Career in IAM as a fresher
76d ago
Anyone Can Silently Steal Your Files from your Claude AI chat – Live Demo
76d ago
Need Advice
76d ago
Before going to college, what certifications should I get to prepare myself for cyber security as a person with no experience with cyber security at all?
76d ago
Someone from Germany on iOS keeps trying to login to my MSFT account
76d ago
AI cautionary tale...
76d ago
AI powered red vs blue teaming
76d ago
Starting a security analyst student apprenticeship next week, need advice
76d ago
Why CVE Does Not Work for AI Agents, but AVE?
76d ago
SC-200 or Security+ — which actually helps land a security title
76d ago
How about AI having access to your hard drive.
76d ago
How a Date Tag Hijacks macOS via ExifTool
76d ago
Need ideas for final year cybersec project : “CodeSafe” MCP for AI coding tools
76d ago
How credential brokering prevents AI agents from compromising credentials via prompt injection
76d ago
Built a tiny daily cyber puzzle game during evenings/weekends
76d ago
Crypto4A launches quantum-safe rival to AWS Secrets Manager
76d ago
ZTE rated this router leak 3.5 Low. NVD rated it 6.5 Medium. The impact explains why.
76d ago
Cyber Sec project
76d ago
CySA+
76d ago
Anyone tried Morgancyberhelp ?
76d ago
As AI speeds coding, CVE Lite CLI keeps security deliberately AI-free
76d ago
Why are most of the dfir tools built to be used in windows
76d ago
OnlyFans mega leak reveals 340M user records, hackers claim
76d ago
Perplexity BumbleBee
76d ago
Cisco patches critical 10.0 flaw in Secure Workload APIs
76d ago
Stalker has my phonenumber
76d ago
Need some guidance
76d ago
Are you currently allocating budget to services that remove executive PII from B2B data brokers?
76d ago
About CEHv13 book
76d ago
We open-sourced the most dangerous part of our security startup on purpose.
76d ago
Which conference(s) result in the most people finding jobs?
76d ago
My discord account has been hacked second time even after enabling two factor authentication and resetting password
76d ago
What's the most efficient way to learn cloud governance and compliance
76d ago
Does anyone know C2 framwork and free hosting to host C2?
76d ago
CIS-CAT Assessor for assessment Windows server 2022 and 2025
76d ago
Auditor wants a specific access report format and our IAM tool can't produce it, how do you handle this
76d ago
Installed BlueStacks, 3 hours later "new login on your google account" and its from the same city as me and a samsung s22 galaxy that i did not authorize, does this have any relation to bluestacks?
76d ago
Recent adoption of AI taught me what is Cybersecurity.
76d ago
The Pentagon Changed the Rules for Cybersecurity Compliance
76d ago
Can someone explain to a noob like me what the implications of this exploit are?
76d ago
SHub's "Reaper" Variant Seen Bypassing New macOS Terminal Protections
76d ago
Window between zero-day CVE and a patch!
77d ago
Is it risky when a website puts on technology components with versions they used in their website?
77d ago
Anyone else losing their mind over this "AI Cybersecurity" hype?
77d ago
URL parsing behavior in a canonical tag lab
77d ago
Would an open source CLI tool that audits GitHub repos for supply chain attacks be useful to you?
77d ago
Any tips for me pls
77d ago
How do you minimize legal liability as a solo contractor?
77d ago
How does your MSSP handle fine-tuning detection rules for false positives? (e.g. "Guest" policy hitting UDP/TCP scan alerts) — do you verify with the customer before suppressing?
77d ago
Mentorship Monday - Post All Career, Education and Job questions here!
77d ago
Provenance: A survival toolkit for an AI dominant information landscape
77d ago
[ Removed by Reddit ]
77d ago
Active Drupal SQLi exploitation is a real „patch now“ moment
77d ago
machscope — macOS XPC, Mach services, launchd, and trust relationship explorer (zero-dependency, terminal-native)
77d ago
Need suggestions and input; not a promotion
77d ago
Need advice!
77d ago
New Zealand is becoming a focal point for AI-driven superhacking threats.
77d ago
nmap on Linux: Guide to Network Scanning and Discovery
77d ago
TrapDoor supply-chain campaign hits npm, PyPI, and Crates.io with AI-assistant poisoning angle
77d ago
How would Phishing look like in the future? (targeting agents, not humans)
77d ago
Best beginner/intermediate book for system security (blue team / defense / audits)?
77d ago
Why is on-prem and air-gapped asset inventory still such a mess?
77d ago
keep getting MS authentication sign in attempts?
77d ago
Silly issue
77d ago
How to practice cybersecurity while studying prograaming ?
77d ago
[AI Security] Exploring Behavioral AI for Runtime Threat Detection
77d ago
Podman and krun: is it pointless to harden quadlets?
77d ago
How to handle security researchers (and firms) without a bounty program?
77d ago
Product analytics is becoming a third-party breach surface
77d ago
How can i learn and get into red teaming?
77d ago
Governments increasingly assume they’ll use offensive cyber tools as part of state power | Federal News Network
77d ago
I got hacked
77d ago
Soc analysts in big companies, how it looks like?
77d ago
CTO at NCSC Summary: week ending May 24th
77d ago
These special phone and app features can help protect you from spyware
77d ago
Is there a tool that lets you automatically rotate all your ssh keys and k8s creds and whatever else with a click of a button?
77d ago
Capcha Code Malware
77d ago
getting lost when hunting
77d ago
How to find information behind an account?
77d ago
Theoretical Design Concept for Post-Exploitation Browser Defense
78d ago
Google Certifications...
78d ago
How to continue when finding a possible Vulnerability but local law prohibits me from investigating further
78d ago
Netherlands seizes 800 servers of hosting firm enabling cyberattacks
78d ago
Is the CISSP still a reputable cert for getting jobs?
78d ago
Which of these gоv roles would fare better in the private sector?
78d ago
Laravel Lang packages hijacked to deploy credential-stealing malware
78d ago
Mapping binaries to EDR feature spaces
78d ago
Lost my number + WhatsApp account — worried about old chats, photos, and videos
78d ago
what is the most painful or time-consuming part of your work right now?"
78d ago
Anthropic says Mythos has already found more than 10,000 vulnerabilities
78d ago
What is the experience needed for “entry level” cybersecurity jobs?
78d ago
Browser extension testing.
78d ago
Interviewer ask me if you observe port scanning from internal ip , the scanning ip is not authorised for scanning. How will you investigate it and how will you find attackers ip?
78d ago
Have you ever had your face or voice misused by AI? I’m building a free reporting tool and need feedback
78d ago
Prompt Injection finally broke my brain a little. My first article as a cybersecurity student, cat approved edition
78d ago
Can someone recommend me some good, large universities to study cybersecurity?
78d ago
New guy khikhi
78d ago
Examples of intentional backdoors being breached?
78d ago
Non-Compliant Vocab
78d ago
Drupal Core SQL injection flaw actively exploited less than 48 hours after patch. 15,000 attack attempts already recorded across 6,000 sites
78d ago
infostealers just spawned a 5,000+ repo github supply chain attack
78d ago
The latest Megalodon campaign against GitHub leveraged a spray of fake PRs targeting CI workflows. Here's the complete analysis
78d ago
GRO frag
78d ago
We audited 12K n8n templates: most have critical vulnerabilities
78d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
78d ago
Taking the PSAA - Practical SOC Analyst Associate by TCM Security next week
78d ago
Mitigated Vulnerabilities by Vendor as Feed
78d ago
Kash Patel-Linked Merchandise Site Goes Dark After Hack Allegedly Spread Malware to Visitors
78d ago
A new GitHub attack dubbed Megalodon compromised more than 5.5K repositories
78d ago
Where can I find the tools freely on internet to practice for soc analyst
78d ago
residential proxies
78d ago
Recommendations for getting started in cybersecurity
78d ago
Linux mint or Ubuntu for complete beginner
78d ago
Indirect prompt injection is jokingly trivial. AI is social engineering a toddler with the knowledge of the world.
78d ago
Pentesting company recommendation
79d ago
Have you ever failed a certification exam?
79d ago
AI Chatbot Security Research – Prompt Injection Behavior in Financial Context (Seeking Responsible Disclosure Guidance
79d ago
What do i need to learn to get into application security? Which Degrees/Certs
79d ago
RSAC online membership? Is it worth it?
79d ago
Can someone give me a detailed roadmap for becoming a SOC Analyst?
79d ago
Puedo conseguir trabajo?
79d ago
How do i learn networking for cyber security?
79d ago
What's going to be Hacking and Cybersecurity's future is gonna be like?
79d ago
Cyber security placement - Interview Help
79d ago
Anonymous revendique le piratage de satellites chinois pour protester contre les lois sur la vérification de l'âge
79d ago
Feedback needed
79d ago
Handoff Transition
79d ago
Just added an interactive security map showing exactly what the server sees (and doesn't)
79d ago
Trend Micro warns of Apex One zero-day exploited in the wild
79d ago
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
79d ago
https://www.reuters.com/business/finance/morgan-stanley-asks-bankers-carry-separate-phone-china-trips-source-says-2026-05-20/
79d ago
Harvard and 140 other legitimate websites compromised
79d ago
Votre Satisfaction Dans Votre Travail
79d ago
5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit.
79d ago
US states urge Congress to renew cybersecurity grants
79d ago
The CISO's Guide to IDE Security in 2026
79d ago
Help with evilginx
79d ago
Watching AI Brain Drain on Attackers in Real Time
79d ago
Zyxel super-admin credential leak expanded from one router image to CPE/ONT/LTE/5G devices + password gen algorithm.
79d ago
api-rta cyberwarfare labs
79d ago
Does Security Implement Fixes?
79d ago
Ultimate Cybersecurity without needing AV ect?
79d ago
User Onboarding with IAM
79d ago
pnpm 11 Might Finally Be a Better Default Than npm
79d ago
14 npm/PyPI/AI Supply-Chain Threats Today (2026-05-22): Critical Worms, Credential Harvesting, and RCEs
79d ago
Hunting a PhaaS Operator: From Phishing Email to Lagos, Nigeria
79d ago
Millions of NGINX Servers Face Fresh Zero-Day Concerns After Recent Rift Patch dubbed "nginx-poolslip"
79d ago
Looking for a cybersecurity professional to interview for a university project (interview in French)
79d ago
Safe read-only check script for Copy Fail / CVE-2026-31431
79d ago
New to GRC at an MSSP startup. Want to build a local AI on an RTX 3050 to automate documentation without leaking data. Possible?
79d ago
[TOOL] CLR-Stomp – BOF-Based .NET CLR Stomping for Stealthy inlineExecuteAssembly
79d ago
Cisco used AI to write security incident reports, with mixed results
79d ago
[TOOL] QSLCL v2.1.4 - Universal Silicon Communication Layer (DFU/EDL/BROM)
79d ago
Cyber Insurance Actuary Looking for Educational Resources
79d ago
As a bank , how do i give protected access to claude to my team?
79d ago
Can seasonal Apple Store employees apply for internal IT/cybersecurity roles?
80d ago
Reliable IP reputation check tools besides IPQS?(for work)
80d ago
Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility (5/2026)
80d ago
Time to Switch: How to Set Up Passkeys Before Microsoft Ditches SMS 2FA Logins
80d ago
Hacked by Rat Tools for 2.5 years.
80d ago
Google API Keys Remain Active After Deletion
80d ago
how do cyber sec consultants and pentesters actually get new clients?
80d ago
Post Incident Paranoia?
80d ago
Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector
80d ago
Upcoming CS Student: What OS approach is best to balance university coding and learning cybersecurity?
80d ago
Sensing ‘renewed outbreak’ of war, Iran hackers vow ‘dozens’ of ‘devastating’ infrastructure attacks ready
80d ago
You can counter MEMZ with Krotten in XP
80d ago
What are the most effective ways to do Blackbox testing?
80d ago
Npm registry sets stage for more secure package publishing
80d ago
Need a Wi-Fi Adapter for Better Range + Wi-Fi Pentesting Support
80d ago
Basira - open source AI code reviewer with OWASP audit, 0 CVEs, BYOK
80d ago
Is the Cybercorps SFS still worth it?
80d ago
Microsoft warns hackers are exploiting password resets to gain access to user accounts
80d ago
Unpopular opinion: the GitHub breach is 100% predictable and the security industry deserves the blame
80d ago
WORM USB drives
80d ago
An OWASP-aligned launch gate for AI agents — Would you please share critique on the threat model?
80d ago
CISOs - Holding the Line
80d ago
A Hacker Group Is Poisoning Open Source Code at an Unprecedented Scale
80d ago
Security Scroll Down?
80d ago
mass github repo backdooring via CI workflows(Megalodon)
80d ago
Threat Modeling Autonomous Dev Agents: How do we cryptographically prove a human actually reviewed a commit?
80d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
80d ago
DNS blocked by Cisco Umbrella, but symantec EDR & Event Viewer are completely blind
80d ago
FaceTec (ID verification) company appears to store user biometrics
80d ago
CVE-2026-34474: ZTE H298A / H108N routers expose credentials before authentication
80d ago
It seems that FaceTec (ID Verification company) allows for storage of user biometrics
80d ago
Two Microsoft Defender vulnerabilities actively exploited. One grants full SYSTEM access. CISA has a June 3 federal deadline. Here is what to check.
80d ago
Can I block outbound connections to Google cloud on my host firewall? What port? What IP range? Any advice. Trying to prevent Google spying and collecting data
80d ago
What Questions Do You Ask During SSP Control Interviews?
80d ago
Feed The Cat BackDoor
80d ago
Flipper One - Asking for help from the community
80d ago
Flipper One — tech specs
80d ago
Architecture Zero Trust détaillée
80d ago
Cybersecurity in Healthcare
80d ago
Staged publishing for npm packages | npm Docs
80d ago
9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros (Yes there is another one, only a CVS 5.5 though this time, still looks pretty bad though)
80d ago
Neither MFA, Passkey, nor trusted IP help here
80d ago
cyber security remote
80d ago
CSIRT incident response
80d ago
Trying to find a graduate role
80d ago
Microsoft warns of new Defender zero-days exploited in attacks
80d ago
what is the best security app option for pixel8a?
80d ago
How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102)
80d ago
IoT Security
80d ago
GitHub links repo breach to TanStack npm supply-chain attack
80d ago
Another working Linux LPE exploit is out. How are teams treating local-only bugs now?
80d ago
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks
80d ago
Google publishes exploit code threatening millions of Chromium users
80d ago
landing a remote Vulnerability Management role
80d ago
Three low-hanging vulns in a Rails SaaS: unauthenticated S3 uploads, rate-limit bypass via proxy pool, and OAuth route leaking internals. Full authorized case.
80d ago
I feel like the past month has been more optimistic than in the past with AI taking jobs. Has the market been the same for those hunting?
80d ago
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit
81d ago
What volume of TPRM do you handle per month?
81d ago
safest virtual machine?
81d ago
Second Time, Same Sandbox: Another Anthropic Claude Code Network Sandbox Bypass Enables Data Exfiltration
81d ago
Cybercrime service disrupted for abusing Microsoft platform to sign malware
81d ago
GitHub notifications
81d ago
Is there no more privacy left in the world?
81d ago
Microsoft Edge had a password blunder, and it raises a bigger browser trust problem
81d ago
Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network
81d ago
Aconselhamento / mini texto
81d ago
CISA with an absolutely embarrassing data leak.
81d ago
Microsoft is pulling the plug on SMS codes, wants you to switch to passkeys
81d ago
Anyone else feeling like static AppSec workflows are starting to hit limits?
81d ago
GitHub breach highlights developer tools as part of attack surface
81d ago
Why do some malware use unique user-agent strings?
81d ago
Encrypted emails bypassing email security tool
81d ago
Ctf groups
81d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
81d ago
Opensource that automatically scans your git repos for breaches
81d ago
CVE-2026-34472: According to ZTE, an unauthenticated auth bypass is just a 'customer-specific low-risk requirement.' MITRE disagreed.
81d ago
Your developers are deploying agents in your production environment right now. You have no governance for it.
81d ago
¿Como me preparo para EC-Council CSA?
81d ago
The IBM X-Force Index 2026 explains all three in one finding.
81d ago
Securing iPad's question
81d ago
Cybersecurity 101
81d ago
What would this job role be?
81d ago
MSPs & MSSPs suck
81d ago
[ Removed by Reddit ]
81d ago
Crossroads
81d ago
Advice regarding "SOC" job that automates everything
81d ago
Is this Medium article about "NetMirror" malware legit?
81d ago
AI silently removed human-in-the-loop security checks during a large refactor. Is this a known phenomenon?
81d ago
Developer tooling is part of the attack surface before a project is even run
81d ago
How the hell do you manage developers, their code, their apps?
81d ago
Hackers Spent Nearly 3 Months Inside the New York City Health System Before Anyone Noticed
81d ago
Do people still rely on antivirus software in 2026, or is built-in security enough now?
81d ago
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
81d ago
Automatic CLI for spinning up vulnerable labs + objectives
81d ago
ISO/IEC 27701 scenario question
81d ago
Discord rolls out end-to-end encryption on voice, video calls
81d ago
GitHub investigates internal repositories breach claimed by TeamPCP
81d ago
Two AI-based science assistants succeed with drug-retargeting tasks
81d ago
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
81d ago
An AI coding assistant installed malware into production environments. Nobody typed the command. AMA on what "supply chain attack" means now.
81d ago
New to cybersecurity
82d ago
Anyone interview or work with Moxfive?
82d ago
A stealth Firefox version that passes all anti-bot and CAPTCHA
82d ago
mkPIVM - a polymorphic position-independent shellcode virtualizer
82d ago
Started in IT and need a Cybersecurity Roadmap with my Useless Degree!
82d ago
GitHub announces internal data breached.
82d ago
Roadmap to Cybersecurity roles
82d ago
Malware installed without literally doing anything?
82d ago
CTFs
82d ago
Crossroads
82d ago
Canara Bank SuRaksha Cyber Hackathon 2.0,
82d ago
Anti BOT Tipps und Tricks gesucht.
82d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
82d ago
New to Cybersecurity
82d ago
Is the ISC2 Certified in Cybersecurity worth it?
82d ago
Average Days to Close by Source CNAPP Severity Tag 2026
82d ago
I want free nmap resource
82d ago
If I clear browser history regularly, does it reduce the chances of malware that target browser data?
82d ago
What is next after 1.5 Year as Security Analyst?
82d ago
Analysis advice
82d ago
Stop me if you heard this one before... (YellowKey related)
82d ago
Can you be protected from yellowkey by disabling WinRe? does it work from support os then WinRe?
82d ago
Looking for advice: where should I post/publish CVE write-ups?
82d ago
Cybersecurity statistics of the week (May 11th - May 17th)
82d ago
How can I test my website locally for cybersecurity?
82d ago
Use of coding in security operations
82d ago
Iran demands Big Tech pay fees for undersea Internet cables in Strait of Hormuz
82d ago
Microsoft disrupts cybercrime service that abused software verification systems en masse
82d ago
I've built an open source honeypot probe database accessible via curl, http and mcp
82d ago
6,000+ Automatic Tank Gauges Exposed With No Authentication
82d ago
Twice in two days I've had a MS Auth request from a random device, I changed my password after the first, what more can I do to protect my email?
82d ago
If humans are the weakest link, why won't companies evolve?
82d ago
Someone asks "How much does a VAPT cost?" or "Do we really need a penetration test?"
82d ago
Cloudflare's CISO gives his hands on review of Anthropic's new Mythos LLM
82d ago
Local transcription vs cloud transcription, which actually feels safer?
82d ago
Why do governments and militaries still use what amounts to giant preshared electronic codebooks when we have really good encryption today?
82d ago
Shai-Hulud keeps burrowing: 314 npm packages infected after another account compromise
82d ago
Shai-Hulud source leak is turning npm malware into a copycat problem
82d ago
Framework for Preventing Secret Ideas from Leakage
82d ago
Local LLM for building AI Security platform
82d ago
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access
82d ago
Emerging Cyber security niches
82d ago
ISO/IEC 27701
82d ago
Solo dev building a terminal-heavy hacking game inspired by corporate security
82d ago
Symantec has published its analysis of Fast16: a pre-Stuxnet sabotage tool built to subvert nuclear weapons simulations
82d ago
CS/IT Student Looking to Grow My LinkedIn Network 😃
82d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
82d ago
Is Amazon Cognito a good choice long term? Alternatives?
82d ago
Was hacking easier in the 80s and 90s and early 2000s?
82d ago
Need some Advice in SOAR heavy environment
82d ago
Trying to find serious builders in cybersecurity - not just “let’s build” conversations
82d ago
AI Phishing
82d ago
One Hacked Login Led to a Massive Cloud Breach, Microsoft Reveals
82d ago
How easy is it to get into the cyber security field?
82d ago
314 npm packages just got compromised, 271 @antv, echarts-for-react, size-sensor, timeago.js
82d ago
Frontend SWE (3-4 YOE) looking to pivot to AppSec. Where should I start?
83d ago
‘The Worst Leak That I’ve Witnessed’: U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub — Gizmodo
83d ago
CEH/CPENT vs OSCP vs GPEN
83d ago
ntroducing Yokai Linux — A Cyberpunk Security-Focused Linux Distro”
83d ago
CISA Contractor Admin Leaked AWS GovCloud Keys on Github
83d ago
Suspecious activity in my account
83d ago
Is it safe to use my first name and middle name on platforms?
83d ago
Stuck choosing a cybersecurity specialization — especially with a local market context (Senegal). Need honest advice.
83d ago
Just received an email from shinyhunters about their amtrack hack
83d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
83d ago
Bywaf: an auditable Python commandlet framework for chained pentest workflows
83d ago
For anyone currently working in a SOC:
83d ago
Fellow Tier 1 SOC/Security Analysts - What does your day to day look like?
83d ago
How do you threat hunt for RMM tools in environments where RMM is all over the place?
83d ago
Microsoft - "your single use code" email when it was not requested by yourself
83d ago
Directory of vendor security questionnaires
83d ago
Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
83d ago
MCA student with 2 yrs SOC/VAPT experience struggling to land interviews — looking for guidance/referrals
83d ago
Cybersecurity job market in Phoenix (East/West Valley?) – looking for local insight
83d ago
How is AI affecting the cybersecurity market?
83d ago
MCP security
83d ago
YellowKey Mitigation
83d ago
Anyone else on the receiving end of ShinyHunters extortion email?
83d ago
Ultimate irony: Microsoft researchers say you shouldn’t trust AI with work docs
83d ago
What’s the biggest mistake people still make about online security in 2026?
83d ago
Anthropic shuts the EU out of its most advanced cyber AI model
83d ago
Most AI agent governance playbooks still assume you can turn the agent off... Once its wired into production that stops being true [Rethinking AI security through a dimmer switch lens]
83d ago
Best hotel for attending all three conferences in Vegas?
83d ago
What's your company's actual PQC migration plan? Not the one on paper - the real one.
83d ago
Does buying local cybersecurity (services/products/etc) matter to you?
83d ago
LinkedIn user hides AI prompt injection in bio to force recruitment spam to be sent in Olde English prose
83d ago
Detection Engineering AI Maturity Framework
83d ago
Microsoft code
83d ago
Microsoft confirms Windows 11 security update install issues
83d ago
Linus Torvalds says AI-powered bug hunters have made Linux security mailing list ‘almost entirely unmanageable’
83d ago
Exploit available for new DirtyDecrypt Linux root escalation flaw
83d ago
Four Malicious npm Packages Deliver Infostealers and Phantom Bot DDoS Malware
83d ago
Suspicious with a company offer letter
83d ago
Direct external access to CyberArk PVWA vs. enforcing a VDI/Jump Box first?
83d ago
Why do some recovery workflows still require full wallet uploads?
83d ago
Need help with interview for soc l1
83d ago
Feeling stuck in SOC want to moving toward Detection Engineering & Cloud Security (need guidance & cert roadmap)
83d ago
New Windows 'MiniPlasma' zero-day exploit gives SYSTEM access, PoC released
83d ago
carrer path in cybersecurity for a btech stud
83d ago
Agents usage in production
83d ago
‘Q-Day’ is almost here. It could unleash a cybersecurity crisis far worse than Y2K
83d ago
Are teams still finding AI API keys in public repos?
84d ago
Mentorship Monday - Post All Career, Education and Job questions here!
84d ago
Mean time-to-exploit just hit 2.1 days. Critical vulnerabilities everywhere. Is the AI apocalypse here?
84d ago
Does the CBP bug phones?
84d ago
What We Learned Building Runtime Visibility for Modern Telco Networks
84d ago
Ive got my Spotify account hacked! How do I solve this?
84d ago
The Politics of AI Transparency
84d ago
A million baby monitors and security cameras were easily viewable by hackers
84d ago
NGINX CVE-2026-42945 Exploited in the Wild, Causing Worker Crashes and Possible RCE
84d ago
Is cybersecurity becoming more behavioral than technical?
84d ago
Questions About Promo Items for a Cybersecurity Conference
84d ago
Dois-je m'inquiéter ?
84d ago
I am dying to work abroad , rate my journey so far
84d ago
Microsoft - "Your single use code" email when it was not requested
84d ago
Security / Compliance work going Agentic?
84d ago
Don't believe the media, specially in cybersec
84d ago
Microsoft account keeps getting Authenticator requests?
84d ago
[Tool] Grafana Final Scanner - Mass CVE Testing Script with All Public CVEs Aggregated.
84d ago
Struggling to generate security bulletins — any ideas?
84d ago
Certs to go into Security Engineer/architect
84d ago
18882745552 beware of email with this number
84d ago
Transition from traditional penetration testing into AI security
84d ago
Seeking advice on next career steps
84d ago
Will the analyst role become obsolete?
84d ago
Alert Fatigue
84d ago
Best path into cybersecurity for a high schooler?
84d ago
Keep getting hacked
84d ago
How Do I implement sessions management in a vibe coded app ? Also suggest sessions management best practices
84d ago
I’m interested in joining the Red Team Hackers Academy in Bangalore.
84d ago
A clueless teenager 💔
84d ago
Complete beginner looking to learn cybersecurity for personal/everyday use. Where to start?
84d ago
Am I overthinking Claude Code security or is this actually a risk?
84d ago
is someone know about shadow ai and can give me an explain about this im junior in cyber and i hear about this
84d ago
ISO/IEC 27701 ( SoA ) Applicability
84d ago
Security Executive Playbook
84d ago
This article about AI allucinations written by thehackernews, is literally written with AI lol... We need to do something to stop this phenomenon
84d ago
I feel crazy I hope someone has insight .
84d ago
ΡHANTΟΜ Al-Powered Pentesting Command Center
84d ago
Interview Assessments
85d ago
We built a blue-team mode for AI security training — you write a defensive prompt, we throw 12 attack probes at it
85d ago
Questions about data blockers
85d ago
Post Implementation task
85d ago
Mythos, MOAK, CTEM and the End of CVE Chasing
85d ago
Cyber security jobs in Austria
85d ago
Personal favorite deception layer.
85d ago
Estudiar Ciberseguridad
85d ago
Learning way
85d ago
How do you report large volume detections to a CISO without making the BPA report a SOC story?
85d ago
Can anyone share bugbase platform screenshot having professional usage on dashboard?
85d ago
CTO at NCSC Summary: week ending May 17th
85d ago
Security Executive Playbook
85d ago
Tired of tab-switching between CTI tools - here's what we put together
85d ago
I contributed to an open-source Bluetooth stress testing tool that just got a major algorithm refactor
85d ago
In Cybersecurity
85d ago
Anyone else feel like most MSP tooling is either overkill or painfully manual?
85d ago
Thinkpad vs Macbook pro endpoint security
85d ago
Any more affordable alternatives to “IntelligenceX”?
85d ago
Experts Confirm the Fast16 Malware Was Sabotaging Nuclear Weapons Tests, Likely in Iran
85d ago
tanstack checker github action
85d ago
Drivers Alpha AWUS036AXML
85d ago
Splunk download for free
85d ago
Funnel Builder WordPress plugin bug exploited to steal credit cards
85d ago
Anyone here using pager duty?
85d ago
Scammer targeting posters
85d ago
Seeking advice
85d ago
Looking for Free Cybersecurity Conferences & Meetups in Europe (September 2026)
85d ago
Just got an email about a single use code, maybe someone was trying to log in?
85d ago
Can a background in DevOps enter the cybersecurity field?
85d ago
Using ai in learning
85d ago
Avanzamento area Blue Team/SOC
85d ago
Please what could be helpful
85d ago
CVE exploit chain
85d ago
What are the widely accepted SaaS security accreditations/audits an app should seek in fintech
85d ago
Preparing for The Quantum Era: AT&T Business Debuts Post-Quantum Cryptography Secure SD-WAN, Powered by Cisco
85d ago
Major flaw in Indian Cyber and IT assurance landscape
85d ago
Red Team Ops Ⅱ ( CRTL ) exam preparation
86d ago
Recomendations
86d ago
Recommended cybersecurity certification for a UX designer new to the domain?
86d ago
insdubai.com: Motor insurance policies, data of insured persons was exposed on an unprotected server
86d ago
Career path
86d ago
Merit America offers a program that gets you into cyber security roles.
86d ago
Brovan: Binary user-mode emulator for x86_64
86d ago
AmEx Interview!
86d ago
Developer credential-stealing pipeline also collected operator workstations
86d ago
need help building a case.
86d ago
Personal favorite SIEM platform?
86d ago
Cardputer ADV
86d ago
Alternative for Qualys
86d ago
The 4th Linux kernel flaw this month can lead to stolen SSH host keys
86d ago
Stack Buffer Overflow Explained (Using a Classic Doom Bug)
86d ago
Confused about cybersecurity career
86d ago
Transferring from pen test consulting to application security?
86d ago
Curso de especializacion de Ciberseguridad
86d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
86d ago
Lost, tempted to throw in the towel
86d ago
Microsoft Exchange, Windows 11 hacked on second day of Pwn2Own
86d ago
I open-sourced a Docker security scanner I use to audit all my websites
86d ago
Testing Deception Technique
86d ago
A malware got into my account and spread spam ad to my friends and relatives
86d ago
North Korean Hackers Now Using AI? Kaspersky Warns of New Cyber Threat Targeting South Korean Govt Systems
86d ago
Most pentest reports I review are padded with garbage findings
86d ago
Cyber Essentials and use of third party websites - MFA
86d ago
Rapid 7 and Cisa Kev
86d ago
Anyone know much about MS Defender?
86d ago
EN18031 for IoT: struggling to see the big picture — advice from experienced people?
86d ago
Automating Code Security Reviews
86d ago
New Linux privilege escalation flaw ‘Fragnesia’ disclosed; PoC available
86d ago
AI coding tools on developer machines — looking for input on how you're handling it
86d ago
Chrome 148 Update Patches Critical Vulnerabilities
86d ago
Microsoft warns of Exchange zero-day flaw exploited in attacks
86d ago
I need help. i am lost
86d ago
Beyond Acceleration and Automation: How AI + Intelligence Changes Cyber Defence
86d ago
Physical red teaming: 7 low‑tech paths we keep finding into ‘secure’ environments
86d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
86d ago
I'm going crazy. At the application level what I can actually do to prevent DDos?
86d ago
Is anyone enrolled in Intellipaat's cybersecurity course?
86d ago
Will AI Replace Cybersecurity Jobs?
86d ago
What's best certification choice after OSWE
86d ago
Facebook Page Call Slipping through Sleep mode
86d ago
ssh-keysign-pwn: Linux LPE allows unprivileged users to read root-owned files. PoC with SSH server privkey
86d ago
New Linux LPE allows local users to read any file, including privkeys
86d ago
A fix for the previous Linux kernel critical exploit has seemingly introduced another critical local privilege escalation exploit, a third in two weeks.
86d ago
Your experience as IT Admin on Alerts
86d ago
Slow-drip responses as a bot defense: streaming fake credentials 3 bytes at a time
86d ago
Maximum Severity Cisco SD-WAN Bug Exploited in the Wild
86d ago
Discord VC lag Exploit
86d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
86d ago
Bug FB - Inicio de sesion por password
86d ago
Does anyone know how to configure EVILGINX for testing
86d ago
How long does it take to get familiar with a tool
86d ago
Scam website
86d ago
ANTS Hack: 19 million records exposed in French ID agency breach
86d ago
Is it really that easy to obtain SMS codes using an SS7 attack?
86d ago
AI coding tools are shipping code faster than security can review it. What's your team doing about it
87d ago
Interview for AI security engineer position at a fortune 500 company
87d ago
How’s the job market for Senior AppSec Engineers? How are the interviews?
87d ago
Has anyone read "The Art of Deception"? How does it hold up to now?
87d ago
Is metadata protection becoming more important than traditional endpoint security for ordinary users?
87d ago
Zero trust in hybrid environments - what's actually worked for you
87d ago
Have you encountered issues with CSAF advisories in practice?
87d ago
Zero trust in hybrid environments - what's actually working for you
87d ago
OpenAI confirms security breach in TanStack supply chain attack
87d ago
Bachelors Degree Options
87d ago
I need help protecting my privacy
87d ago
Free Threat Intellegence
87d ago
What discovery in cybersecurity amazed you the most?
87d ago
Scholarship for Service
87d ago
For teams archiving logs outside the SIEM: how often do you actually query them, and for what reasons?
87d ago
Another day, another supply chain
87d ago
How often do you actually see SSRF exploited in real incidents vs just discussed in CTFs/blogs?
87d ago
Teaching Linux+ & CEH.....
87d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
87d ago
SIEM use case development
87d ago
JFrog vs Mend as Scanners
87d ago
KQLab - open-source query manager for SOC teams
87d ago
Which Vendors Publish the Best (or Worst) Security Advisories?
87d ago
Synthetic training data vs. real attack telemetry — does it actually matter?
87d ago
Operative IT-Sicherheit | SIEM & Splunk
87d ago
SOC not for junior level?
87d ago
Cybersecurity at MSG
87d ago
pii-tools.com reputable?
87d ago
Hey all! sharing this week's issue I wrote on the TeamPCP supply chain compromise
87d ago
Contract jobs worth the risk?
87d ago
HackTheBoxAcademy vs LetsDefend vs CyberDefenders
87d ago
Automating code security reviews with Claude: near Mythos-level capabilities at lower cost
87d ago
Making Right Career Decision?
87d ago
I tried using apparmor (linux security) but it doesn't seem to work very well
87d ago
Level Effect AMA! Former NSA Operators turned EDR developers and trainers in 2020. We’ve seen a lot of trends over the years and want to start being active in r/cybersecurity giving back. Ask us anything!
87d ago
Struggling to Stay Up to Date With Vulnerabilities
87d ago
How to Transfer files Safely from a Compromised (work) Device
87d ago
Two brothers deleted 96 federal databases after being fired – one googled how to hide the evidence afterward
87d ago
Multiple data breaches in one week
87d ago
How are small security teams handling vulnerability overload now?
87d ago
Concerns mount that EU will demand age verification for VPNs
87d ago
Automating code security reviews: Claude Mythos-level capabilities with lower cost
87d ago
The Rare Patch: A Digital Sovereignty Challenge
87d ago
Advise
87d ago
GRC
87d ago
Admins and Engineers
87d ago
Microsoft's multi-agent AI system tops Anthropic's Mythos on cybersecurity benchmark
87d ago
Prompt injection in browser coding agents is the threat model nobody is ready for
87d ago
New Fragnesia Linux flaw lets attackers gain root privileges
87d ago
Transition from MSP to Network Engineering?
87d ago
So called “off grid” method
87d ago
Convince me I’m not paranoid: a unique hacking situation.
87d ago
Hunting the Behavior Behind npm Supply Chain Attacks
87d ago
Question for AppSec Members
87d ago
Beginners guide to Google Dorks by Heisenberg
88d ago
Alguém sabe algo sobre raven eye technology
88d ago
Gophish Porject - Requirement
88d ago
Security Team Won’t Assess Risk
88d ago
Trusted Unknown Apps Protocol (TUAP) – A Global Behavior‑Based Security Framework
88d ago
Microsoft’s new multi-model agentic security system tops leading industry benchmark
88d ago
Microsoft MDASH Deployment Identifies 16 Windows Flaws via 100+ AI Agents
88d ago
Overwhelmed on how to enter the job market.
88d ago
Social media scam bill targets tech giants as New Yorkers lose billions
88d ago
What are the biggest technical & cultural hurdles you’re facing right now?
88d ago
CISSP / CCSP training - Experienced engineer
88d ago
Vulnerability in Canvas/Instructure Support Tickets had part in breach?
88d ago
is malwarefox legit?
88d ago
what lab to learn zero trust?
88d ago
Anyone else got a bunch of emails leaked by Samsung?
88d ago
This is what some the world's largest banks of malware look like stacked as hard drives
88d ago
I need feedback on my project please
88d ago
would like to understand the role of "Cyber Insurance UnderWriters"
88d ago
Free on-device tool for monitoring AI traffic on macOS — visibility before policy
88d ago
Is secure evidence handling and controlled derivative file sharing needed?
88d ago
Will Adding Some Certifications Help Me in the Job Market?
88d ago
Linux driver posted for Intel Silicon Security Engine Interface "ISSEI"
88d ago
Hello guys I am hearing everywhere Cybersecurity is the most demanding Subject. If it is true then where can I learn and get certified?
88d ago
Fragnesia made public as latest Linux local privilege escalation vulnerability
88d ago
HP ZBook Fury G8 vs ThinkPad T Series for Cybersecurity?
88d ago
NIST is surrendering to the amount of CVEs coming in
88d ago
Military Veteran looking to get into the Cyber Field
88d ago
Microsoft BitLocker-protected drives can now be opened with just some files on a USB stick — YellowKey zero-day exploit demonstrates an apparent backdoor
88d ago
Post-quantum audit substrate for critical national infrastructure. The NCSC 2031 high-priority deadline reframed as an operator-side playbook.
88d ago
Cve apis for a database
88d ago
Empresas de Cyberseguridad en Mexico (Reacciones)
88d ago
Joined a new company: GRC landscape advice
88d ago
Removing admin rights
88d ago
a leak from "the gentleman" ransomware group confirms Infostealers were often used to establish initial access
88d ago
FamousSparrow's evolved DLL sideloading - execution gated behind the host app's normal control flow
88d ago
Golden years for cyber security about to start?
88d ago
A stealth approach to Process Injection - EntryPoint Hijacking
88d ago
Detecting CopyFail and DirtyFrag by thinking outside the box
88d ago
Adaptive Behavioral Identity: A Human‑First Model for Symbiotic Security
88d ago
Career advice
88d ago
The exponential rise of economic damage caused by cyber-crime continues
88d ago
Today's cybersecurity systems are not ready for AI
88d ago
Are certifications worth it, or do practical skills matter more?
88d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
88d ago
Claude Mythos technical breakdown: CVE-2026-4747 ROP chain, OpenBSD SACK integer overflow, Linux 1-bit OOB-to-root, and what AISLE's reproductions actually showed
88d ago
Apple Supplier Foxconn in Taiwan Confirms Cyberattack After Ransomware Gang Claims 8TB Data Theft
88d ago
What to do after security+
88d ago
AI-Generated Fake Marketplaces Are Poisoning Search Results and Stealing Card Data
88d ago
Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub
88d ago
Is it realistic to move from Tech Risk/GRC into technical cybersecurity?
88d ago
Are IPhone autofill passwords safe to use?
88d ago
Access approvals happen over Slack dm and I don't know how to present that to an auditor
88d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
88d ago
China is going dark to develop its own Mythos, German cyber chief fears
88d ago
Is prompt injection a real problem for you?
88d ago
New Exim BDAT bug shows why “just patch the mail server” is still not simple
88d ago
Microsoft France's legal affairs director told the French Senate, under oath, that he can't guarantee European "sovereign cloud" data stays out of US reach
88d ago
Cybersecurity guide
88d ago
[Conseil Orientation] LP ASUR (ANSSI) après une L3 Générale pour viser un Master Cyber ?
89d ago
How you guys rate Google Cyber security course and certificate out of 10 !?
89d ago
Cyebrsecurity Startup Advice
89d ago
Can anyone give a real world based AI based attack?
89d ago
How worried should we be about AI powered cyberattacks?
89d ago
Built STIS-ICS — an open ICS/OT security learning project
89d ago
OS scanner that checks repos for traces of the Shai Hulud worm
89d ago
Foxconn Ransomware Attack Shows Nothing Is Safe Forever
89d ago
Open-source CLI for testing LLM agents across prompt, tool, and replay boundaries
89d ago
AI Vulnerability Research and the Fuzzer Era Déjà Vu
89d ago
Explorer shows random letter/number filenames before copying my actual files — normal behavior?
89d ago
Zscaler AI Security Capabilities ?
89d ago
Cybersecurity degree
89d ago
Disgruntled researcher who dropped BlueHammer and RedSun drops two new Windows 11 zero-days: A Bitlocker bypass, nicknamed YellowKey, and LPE, nicknamed GreenPlasma
89d ago
Cyber security
89d ago
New York Senate takes on junk fees, digital subscriptions, surveillance pricing
89d ago
Cybersecurity statistics of the week (May 4th - May 10th)
89d ago
Feels like AI changed the speed of attacks more than most companies want to admit
89d ago
Anyone used Kasm or ReplicaCyber?
89d ago
Škoda warns of customer data breach after online shop hack
89d ago
Google launches new Android security feature to help uncover spyware attacks
89d ago
Fancy Bear: Stealing Credentials Invisibly
89d ago
Nightmare Eclipse has published Greenplasma and YellowKey
89d ago
Copilot Agent
89d ago
What SANS cert I should consider acquiring (from my job)? Most useful ones or one that goes across many roles?
89d ago
Career Advice
89d ago
Anyone else exhausted by the nonstop AI hype?
89d ago
Reviewing the trends in ransomware attacks in 2026
89d ago
Is It a Good Idea to Change Jobs Shortly After Getting Hired?
89d ago
SSO makes life easier but MFA keeps it safe, do we actually need both?
89d ago
Didn’t land a Cybersecurity internship—starting IT Support for POS systems. Tips on maximizing my off-hours?
89d ago
How are SOC teams actually deciding what not to investigate anymore?
89d ago
Spam calls on this number he was distrubing a girl idk about this guy but the girl placed an order on blinkit and he started acting that he's not able to find the location so she gave her number on ws and now he's spamming unecessarily
89d ago
Chris Cochran at SANS Institute: AMA about the AI Security Maturity Model we just released.
89d ago
Has anyone tryed this out yet?
89d ago
The frontier model caught my prompt injection but the cheaper fallback didn't (and most devs have no idea which one they're on..)
89d ago
Switching to Cyber
89d ago
Nitrogen ransomware group claims Foxconn after Wisconsin plant outage
89d ago
Shai Hulud attack ships signed malicious TanStack, Mistral npm packages
89d ago
Using Cape Sandbox for Phishing Analysis
89d ago
Canvas hack: company pays criminals to delete students' stolen data
89d ago
i have 1 year of experience as product security intern. Please let me know if there are any job oppurtunities available for freshers. I have to start earning.
89d ago
AI integrations are quietly creating a new OAuth supply-chain problem
89d ago
Instructure reaches 'agreement' with ShinyHunters to stop data leak
89d ago
UnMapper: a tool that crawls a target, finds its JavaScript, and reconstructs the original source tree from any sourcemaps it ships
89d ago
Hardcoded secrets in Git
89d ago
Mini Shai-Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI & More Packages
89d ago
UK water company allowed hackers to lurk undetected for nearly two years, regulator finds
89d ago
New ipTIME Pre-Auth RCE in CWMP
89d ago
Instructure Reaches Ransom Agreement with ShinyHunters to Stop 3.65TB Canvas Leak
89d ago
Is my phone hacked?
89d ago
Switched to a grc role after a year in SOC L1
89d ago
Forecasting Lazarus Crypto Heists
89d ago
Infrastructure Security Incident Update & FAQs
89d ago
Mini Shai-Hulud npm worm compromises 160+ packages, abuses GitHub Actions cache + Trusted Publishing. Full list of compromised packages
89d ago
In Depth Guide To VM Based Obfuscation - What it is and how to handle it.
89d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
89d ago
Transitioned to GRC
90d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
90d ago
German cybersecurity official warns China is close to developing AI superhacker
90d ago
Google Detects First AI-Generated Zero-Day Exploit
90d ago
“DCSA agent” calling IT Help Desk to be transferred to employees they are investigating for a clearance
90d ago
Instructure/ canvas paid the ransom?
90d ago
Troca emprego - big para consultoria ou fintech - Pentester/Red Team
90d ago
Finally, texts between Android and iPhone users can be end-to-end encrypted
90d ago
Official CheckMarx Jenkins package compromised with infostealer
90d ago
IMF warns of the potential for AI attacks on global financial systems
90d ago
🕷️ NetCrawler v1.0.0 — AI Pentesting Agent | Open Source | Fully Offline
90d ago
Cookie thieves caught stealing dev secrets via fake Claude Code installers
90d ago
Pwn2Own 2026 Capacity Overflow, Hackers Drop 0-Days Solo
90d ago
MS Defender on OT Network
90d ago
A fateful question
90d ago
SC-900 or SC-400
90d ago
What are your security non-negotiables?
90d ago
Losing my path
90d ago
Axon-captcha
90d ago
What makes companies trust small cybersecurity vendors?
90d ago
Hathor Wallet Daemon (headless) Has Fail-Open Auth – Notified via Immunefi but Closed as “User Responsibility”
90d ago
TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack
90d ago
Foxconn Wisconsin breach reportedly linked to Nitrogen ransomware, 8TB data theft claim
90d ago
These Extensions are Scraping Your AI Chats, are you affected?
90d ago
Be careful with your Git: Investigating malware spreading through Git repositories
90d ago
Training and Phishing
90d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
90d ago
AI-powered hacking has exploded into industrial-scale threat, Google says
90d ago
Apple closed my bug report 4 times. MITRE wouldn't let it die.
90d ago
NASA Investigators Expose a Chinese National Phishing for Defense Software - NASA OIG
90d ago
Google spotted an AI-developed zero-day before attackers could use it
90d ago
beginner doubt
90d ago
I got my CEH Certification. SO what now?
90d ago
Construction to Cyber PM
90d ago
[ Removed by Reddit ]
90d ago
Something got downloaded on my phone and then dissappeared
90d ago
Bleeding Llama
90d ago
Do accountants even care about cybersecurityas much?
90d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
90d ago
Your Biggest Security Risk Isn’t Malware — It’s What You Already Trust
90d ago
Was the reconnaissance in Bugbounty overrated?
90d ago
Cybersecurity beginner building an experimental log analyzer — looking for advice
90d ago
Anyone else worried about AI being a security nightmare?
90d ago
Snyk not working
90d ago
Malicious tenants paid us to abuse our RMM. We blocked them
90d ago
Help reasuring parents with an email parsing tool (i will not promote)
90d ago
DFIR practitioner thinking about starting my own LLC to subcontract IR services to MSPs. Is there actually demand for this?
91d ago
cPanel & WHM Vulnerabilities Patched -DoS, Account Abuse & Security Risks Affect Hosting Servers
91d ago
5 years as a Level 1 Security Analyst and wanting to transition into consulting
91d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
91d ago
New into network pentesting.
91d ago
Is it worth it to switching field to cybersecurity ?
91d ago
Neeed help to get cybersecurity internship.
91d ago
Mentorship Monday - Post All Career, Education and Job questions here!
91d ago
Cybersecurity and ADHD
91d ago
Anyone dealt with a VulDB submission rejection? Resubmit or reply?
91d ago
ISO 27001 certification: what auditors actually focus on versus what most teams spend time preparing
91d ago
I have a malware and need help removing it. someone please help me 🙏
91d ago
I'm starting to see a growth of apps in my org. I'd love to know how you defend against this/ secure it, and if it's happening to you too?
91d ago
EasySec - Update
91d ago
What is the cybersecurity equivalent of leaving your spare key under the doormat?
91d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
91d ago
VICE: Cyberwar | Full Season 2 | Blueprint
91d ago
Linux Kernel Killswitch Proposed After Recent Vulnerability Disclosures
91d ago
Email OTP as default (often ONLY) password isn’t the solution
91d ago
Soc analyse
91d ago
Ollama Out-of-Bounds Read Vulnerability Allows Remote Process Memory Leak
91d ago
Price rising
91d ago
AI Can Boost Cyber Defence But Poor Governance and Overreliance May Create New Risks, Warns WEF-KPMG Report
91d ago
Possible security incident against Arup Group
91d ago
Can honeypots be used this way?
91d ago
I think AI just quietly killed the 90-day disclosure window.
91d ago
TCM and Educate 360 are bugged
91d ago
Got an alert from google what should I do?
91d ago
UK jobs
91d ago
Need help debugging a school ZIP password-cracking lab setup pleaseeeee🙏
91d ago
Worst company
91d ago
Built a platform that combines phishing detection, encrypted file sharing, and cloud security scanning
91d ago
Msc Cybersecurity - dissertation ideas ( something that can be done in 3 or less months)
92d ago
ARGUS: 15 Production-Realistic Vulnerable AI Agent Targets for Red Teaming (Docker + Canary Scoring)
92d ago
App Store Question - Darato Sport / Dofu Sport / Kofu
92d ago
Help! - My Parents Computer is Hacked
92d ago
Ran lumma stealer from a recaptcha scam
92d ago
Port 5986 question
92d ago
CVE-2026-44843: One Chat Message Steals Your Credentials. Then It Gets Worse!
92d ago
cyber security/ segurança da informação
92d ago
College student hacks Taiwan high-speed rail line with software defined radios, stopping four trains
92d ago
Help with an Escalating Cyber-Stalker
92d ago
RRW - Rick Roll WiFi
92d ago
Best resources to start learning python for cybersecurity and automation
92d ago
Mythos AI is a cybersecurity threat, but it doesn’t rewrite the rules of the game.
92d ago
JDownloader site hacked to replace installers with Python RAT malware
92d ago
How can I fix my browser remembering what he had open last
92d ago
MS 360 CoPilot issues
92d ago
I run a malware and was wondering if its a rat or rootkit or dangerous stuff and how do i fix my pc (my dad gave ts to me can't lose it) i can give out any specific details
92d ago
ShinyHunters claims 275M records from Canvas LMS breach. 9,000 schools hit. Ransom deadline May 12.
92d ago
eBPF LSM runtime security agent for synchronous file/network denial — looking for technical feedback
92d ago
I keep seeing "what E8 maturity level should we target?" — here's the practical answer no one tells you
92d ago
OWASP TOP 10 LLM 2026 Community voting
92d ago
Second security incident at Instructure (Canvas)
92d ago
UK Advice Needed - VA+ Training?
92d ago
Gateweb - Secure Web Gateway
92d ago
Those who are in Detection engineering
92d ago
Can someone tell me of a trustable hacker?
92d ago
MSPs, how are you handling AI usage across your customer environments today?
92d ago
Shadow SSDT Hijacking: Achieving Kernel Code Execution via Read-Write
92d ago
How do i protect confidential data from unrestricted AI usage as a bank- what are good tools out there?
92d ago
ecpptv3 Exam in 3–4 Days —
92d ago
AI SECURITY: THE DEFINITIVE GUIDE — PART III | THE FINAL CHAPTER | COMMUNITY CISO SERIES
92d ago
Did CISA helped you land a job ?
92d ago
CTO at NCSC Summary: week ending May 10th
92d ago
pre pre junior needs help(guidance pls)
92d ago
Trojan malware
92d ago
SANs Courses: How do people get their employers to pay?
92d ago
NIS2 Article 21: turning compliance controls into technical security evidence
92d ago
This GBA Rom is making is having a weird behavior in the Sandbox, why?
93d ago
Why AI agent governance feels harder than traditional security models
93d ago
Confused about what certs are important
93d ago
Would getting Security+ be worthless for me?
93d ago
Submit probe test — shadow DOM click
93d ago
Threat intelligence in OT (Power equipments)
93d ago
SOC Analyst
93d ago
PAWs, PAM and PIM..what is best practice?
93d ago
This is the most in-depth analysis I have found on the Instructure/Canvas breach so far.
93d ago
Poland says hackers breached water treatment plants, and the U.S. is facing the same threat
93d ago
Millions of students are locked out. Canvas is down. And the notorious hacker group ShinyHunters has given Instructure a terrifying ultimatum: Pay the ransom by May 12, 2026, or the private data of potentially millions of users will be leaked to the dark web.
93d ago
Quacc++: Automated Open Source Vulnerability Discovery
93d ago
60% of MD5 password hashes are crackable in under an hour
93d ago
Built a correlation engine that chains AD findings into attack paths automatically.
93d ago
Dirty Frag in Kubernetes: unset seccomp behaved like Unconfined in our EKS/GKE tests
93d ago
JDownloader's official website delivered Python RAT
93d ago
Remote Code Execution in GitHub.com and GitHub Enterprise Server (CVE-2026-3854)
93d ago
ShinyHunters Stole 275 Million Student Records. The Ransom Deadline Is May 12.
93d ago
Note taking apps and advice
93d ago
IMF Warns AI Could Trigger Global Financial Cyber Crisis
93d ago
New Linux 'Dirty Frag' zero-day gives root on all major distros
93d ago
Is the ISC2 Cybersecurity program still worth it?
93d ago
Canvas getting hit during finals week shows how fragile “critical SaaS” has become
93d ago
Are websites exposed to the internet under attack almost every hour, even if they're small?
93d ago
Devastating 'Dirty Frag' exploit leaks out, gives immediate root access on most Linux machines since 2017, no patches available, no warning given — Copy Fail-like vulnerability had its embargo broken
93d ago
What the **** is happening in cybersecurity space ?
93d ago
Canvas is back up, but now what?
93d ago
Instagram is getting rid of end to end encryption, what now?
93d ago
New “Dirty Frag” Linux Kernel Vulnerability Could Lead to Root Escalation
93d ago
Reported a Broken Access Control bug to Instructure via bugcrowd 11 months ago, and also sent directly to canvas and instructure since I didn’t really care about the bounty. It was deemed "not applicable".
94d ago
Did I fu by opening an (archived) Onion .txt link posted by the cybercriminal group?
94d ago
Cushman and Wakefield confirms cyberattack
94d ago
Egnyte potential ransomware attack
94d ago
So canvas is down, what'll happen if they can't come to an argreement?
94d ago
Canvas (used by 275M students) was just hacked. Here's exactly what was stolen and what you need to do right now.
94d ago
/Why/ is Shinyhunters targeting Canvas?
94d ago
Canvas Hack - Any Guesses How?
94d ago
Should I build a virtual or physical lab?
94d ago
Instructure (Canvas) Breached by Shiny Hunters — 275M Records from ~9,000 Schools/Universities, Ransom Deadline May 12
94d ago
Engineering a Zero-Trust Kubernetes SIEM: Bypassing NAT Blindness with eBPF, TC, and Suricata
94d ago
Audit/Cybersecurity
94d ago
Issues removing Trellix (and specifically solidifier)
94d ago
Pentagon eyes 3-year cyber training requirement, overriding new Army policy
94d ago
How much personal info will be leaked by the recent Canvas hack??
94d ago
Dirty Frag and canvas
94d ago
Hackers deface school login pages after claiming another Instructure hack
94d ago
Did I destroy my career by being loyal to an arguably good company?
94d ago
V4bel/dirtyfrag - Universal Linux Local Privilege Escalation
94d ago
What is CYBERRANT?
94d ago
Canvas is down as ShinyHunters hack forces outage
94d ago
New Dirty Frag Linux Bug Emerges in Wake of Copy Fail
94d ago
Heads up: AWS Educate Canvas login page may be compromised. Saw what looks like a ShinyHunters defacement page today.
94d ago
How is GRC work in a MSSP?
94d ago
SH and BF phishing console
94d ago
Finally switching over from Authy 2FA. What is the better alternative, 2FAS or Ente Auth?
94d ago
Socure authenticating AI identity as real.
94d ago
Automated SSL Certificate Renewals - What is your setup?
94d ago
Shinyhunters and Canvas
94d ago
What Cli execution do you use for a script file?
94d ago
Fiserv security incident - data breach notice
94d ago
Linux attacks seem to be shifting from “servers” to DevOps and supply chain environments
94d ago
I graduate next year with a Cybersecurity degree.
94d ago
Asking about Cortex
94d ago
Apache Caldera
94d ago
What’s the “unsexy” problem in cyber that’s actually a total disaster?
94d ago
Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE
94d ago
As a developer, should I use AI to improve security?
94d ago
My company has an MSP that manages our employee endpoints but we cant access the software they use to manage
94d ago
Americans sentenced for running 'laptop farms' for North Korea
94d ago
Is my laptop hijacked ?
94d ago
claude ai gave security beta to Enterprise plans only what can we do as pentesters?
94d ago
Massive .de DNSSEC Failure Took Large Parts of Germany’s Web Offline
94d ago
Advice for path to land job SOC in France
94d ago
Possible Major Vulnerability: Chromium used by current version of PRTG
94d ago
Mythos AI may be a cybersecurity threat, but it follows the rules of the game
94d ago
Control Checks using AI.
94d ago
How do native password managers clear the clipboard?
94d ago
Graduating CS Student but Wanna Start my Career in Cybersecurity
94d ago
Claude-Themed Malware Campaigns
94d ago
DeepFake it till you make it.
94d ago
The 12 ways AI agents fail in production. A taxonomy for security teams reviewing agent deployments
94d ago
What niche in cybersecurity should I go for, with my background in Angular & .NET ?
94d ago
Successor for Kaspersky Endpoint Security
94d ago
Romanian Man Extradited to US for Role in Hacking Scheme 17 Years Ago
94d ago
SOC Analyst tier 1 (Entry Level) ??
94d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
94d ago
Made cybersecurity merch as an infosec practitioner — honest feedback welcome
94d ago
As AI agents become users of company data - what is needed to keep data secure?
94d ago
Wrote an extremely detailed 11-article series on attacking and defending APIs - top 10 vulnerabilities.
94d ago
AI inference is quietly becoming a security problem
94d ago
is winrar 7.13 vulnerable to extraction exploits?
95d ago
Tried explaining internet encryption in a beginner-friendly but accurate way, feedback?
95d ago
Is the EC-Council CTIA Certification Worth It for Career Growth?
95d ago
POC Android vuln 2026
95d ago
Credential caching is an unsolved architectural tradeoff, and we should stop pretending otherwise
95d ago
Opinions on Mimecast
95d ago
What's going on in the field of Cybersecurity 🫣.
95d ago
How do teams preserve institutional pentest knowledge when senior testers leave?
95d ago
CVE-2026-32710 MariaDB JSON_SCHEMA_VALID heap buffer overflow leading to RCE
95d ago
Sophos NDR on Proxmox
95d ago
On today's earnings call, IONQ just said they expect to meet Q-Day requirements by 2028-2029.
95d ago
DOJ says ransomware gang tapped into Russian government databases
95d ago
DAEMON Tools devs confirm breach, release malware-free version
95d ago
Have there been instances where your SOC has suffered a cybersecurity attack?
95d ago
OpenCTI founder, Samuel Hassine, arrested and charged with CSAM
95d ago
Deepfake Platform
95d ago
Trellix Licence Query
95d ago
Instructure hacker claims data theft from 8,800 schools, universities
95d ago
Is AI generated code creating a non-linear security problem for AppSec teams?
95d ago
D.H.S. Intelligence Office Did Not Properly Secure Smartphones, Watchdog Says
95d ago
Evaluating Microsoft 365 vs Third‑Party Tools for Email and Endpoint Security
95d ago
Norton Antivirus and Other Norton Software
95d ago
Would you take a promotion to work 100% in office that you’ve been working towards or same pay but work from home?
95d ago
We scanned 200 high-star MCP servers. 205 critical findings. Here are 4 novel attack classes.
95d ago
Download a malware a while ago, someone trying to log into my ios account
95d ago
Org Restructure
95d ago
Does SOC 2 actually reduce questionnaires, or just change them?
95d ago
Google VRP dismissed a systemic Play Store bypass as "Intended Behavior" after 24 internal views
95d ago
How do investigators or cybersecurity researchers correlate online accounts (like Instagram profiles) with IP/network information legally and ethically?
95d ago
Ran phishing awareness training for 200+ non-tech employees
95d ago
Proprietary Software, Hardware and Protocols Face AI-Driven Security Risk
95d ago
Vulnerability Garden
95d ago
Palo Alto Firewall Zero-Day Under Active Exploitation
95d ago
Cyber Security Militias
95d ago
Hidden domain dependencies in AI stacks: expired domains, dangling DNS, and takeover risk
95d ago
CyberSecurity Nightmares
95d ago
Can I use NanoKVM if it's just to turn on pc?
95d ago
got listbombed on my waitlist with 1000 fake adresses, i tried to make some security changes maybe i missed something?
95d ago
How to learn tools for cybersecurity?
95d ago
'CopyFail' attackers start cashing in on Linux flaw
95d ago
Anybodybodybdown for a team/studygroup?
95d ago
I was hacked due to sim card spoofing
95d ago
Chrome is quietly installing a 4GB AI model on your device
95d ago
Dev vs Security role
95d ago
Critical Bug Could Expose 300,000 Ollama Deployments to Information Theft
95d ago
Oracle Debuts Monthly Critical Security Patch Updates
95d ago
Sec engineer / developer?
95d ago
When doing bug bounty, do you usually immerse yourself in 2 or 3 specific domains (ones where vulnerabilities are likely to exist) and focus all your testing efforts on them?
95d ago
Are we actually seeing more vulnerabilities or just more noise?
95d ago
Cybersecurity jobs in red team
95d ago
Question
95d ago
What’s the biggest mistake people make even after installing antivirus?
95d ago
New dashboard tracks ransomware groups by their reliance on Infostealer credentials
95d ago
What would you say if your security lead said this...
96d ago
What would be the goto setup in AWS for security purposes?
96d ago
CREST CRT Exam 2025/2026 Experiences
96d ago
Microsoft Edge stores your passwords in plaintext RAM... on purpose
96d ago
Como começar?
96d ago
Possible Password Leak? Curious if Anyone Has Seen This Before
96d ago
Not a Hack. A Handout. Inside the GTFOice.org Data Exposure
96d ago
Besoin de conseils sur une DMZ automatisée
96d ago
Microsoft, Google and xAI will let the government test their AI models before launch
96d ago
Android ADB Auth Bypass Proof-of-Concept: CVE-2026-0073
96d ago
SMB Header Signature for Tagging in Firewall
96d ago
Question regarding VDP
96d ago
Working on what i should do for the next 3 years
96d ago
Question for Security Professionals
96d ago
Do tech companies lifecycle-manage public DNS records to prevent dangling DNS?
96d ago
Vulnerability Summary for the Week of April 27, 2026
96d ago
Cisco releases open-source ‘DNA test for AI models’
96d ago
Cybersecurity is becoming too AI dependent is that a problem
96d ago
Foxconn Wisconsin outage raises cyber questions
96d ago
How stressful is GRC?
96d ago
Anyone remember areyoufearless.com / “Free Gobo”? Early 2000s hacker forum nostalgia
96d ago
Have CEH certification – looking for free cybersecurity bootcamps or resources to land a job in India
96d ago
Archer for a non-regulated medium sized company?
96d ago
Cybersecurity statistics of the week (April 27th - May 3rd)
96d ago
Well, I'm wondering about working on a RAG pentesting bot. Comment down the best data source to feed LLM.
96d ago
Where to find reliable vendors?
96d ago
Just got into cybersecurity with no prior experience and feeling intimidated. Thoughts?
96d ago
We wrote a guide on securing Claude across the enterprise — here's the core framework (with download)
96d ago
Over 5 months: Payment bypass marked OOS, moved to VDP, and downgraded to Medium.
96d ago
Hardware reverse enginnering first project. Love some advice
96d ago
Microsoft Edge Stores Passwords in Process Memory, Posing Risk
96d ago
Currently working on cybersecurity, looking for advice
96d ago
Open-source scanner for MCP servers and skill files : attack chain detection and server-card scanning
96d ago
CISO course valuation
96d ago
GRC Path to CISO (Certifications)
96d ago
CISOs and pentest buyers, what's the worst thing you've seen in a pentest report?
96d ago
How to enforce M365 Sign-in frequency on corporate laptops?
96d ago
CloudZ malware abuses Microsoft Phone Link to steal SMS and OTPs
96d ago
Built an independent directory of AI Act / AI governance tools, feedback?
96d ago
ScarCruft APT group compromises gaming platform in a supply-chain attack
96d ago
Just curious
96d ago
'Copy Fail' is a real Linux security crisis wrapped in AI slop
96d ago
Analysis malicious DLL
96d ago
Cyber security free course
96d ago
Does certification expires?
96d ago
We get paid to break into buildings for a living. Ask us anything!
96d ago
Pay2Key ransomware — any recovery path that’s actually worked?
96d ago
Karakurt extortion gang ‘cold case’ negotiator gets 8.5 years in prison
96d ago
Microsoft just documented an AiTM phishing campaign that hit 35,000 users across 13,000 orgs in 3 days, the lure was a fake "code of conduct review" PDF
96d ago
How have you kept growing your knowledge in security when the job stops pushing you?
96d ago
The UK’s Age Verification Law Is Producing Compliance Theater
96d ago
Microsoft Edge: Passwords end up in memory as plaintext
96d ago
Do people still get viruses in 2026, or is that mostly a myth now?
96d ago
Mitigation script for Copy Fail vulnerability CVE-2026-31431
96d ago
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
96d ago
Critical Apache HTTP Server RCE (CVE-2026-23918) - Millions of Servers Potentially Exposed. Patches released
96d ago
DigiCert breached via malicious screensaver file
96d ago
Caido Payloads and Scanner of Endpoints
96d ago
CISO Security Mind Map 2026
96d ago
Interview with Chris Kubecka, Cybersecurity Expert, Journalist and Volunteer Rescue Worker
96d ago
Amazon SES increasingly abused in phishing to evade detection
96d ago
AI Security Trainings
96d ago
Ai help
96d ago
ByDesign: observed behavior where file URLs remain accessible after unshare/delete
96d ago
Can Kali Linux still compete in cyber security or is it outdated?
96d ago
Who are your favorite cybersecurity YouTubers?
97d ago
CISOs, how are you balancing AI adoption with security risks these days?
97d ago
San Diego Community College District fighting major cyberattack
97d ago
After 5 months of mental hell and ghosting, today I finally landed a role. To those struggling: Don't give up
97d ago
Free resource: searchable archive of every BSides conference talk
97d ago
Lightning PyPI Compromise: Bun-Based Stealer
97d ago
Too much mother instinct?
97d ago
L1 SOC Analyst for ~2 years - Should I still get the Security + Certification?
97d ago
Do CTFs help real world security skills, or just teach patterns?
97d ago
Compré una cuenta rusa en g2a pensando que era una ley, se hizo administradora de mi ordenador, he cambiado todas las contraseñas y estoy haciendo un reset del ordenador pero sigo estando inseguro, muchísimo miedo me atraviesa ahora mismo
97d ago
Should I do Security + or Network + or A+? For CompTia
97d ago
Bug bounty is ruining how people learn exploitation
97d ago
ISO/IEC 27701:2025 Scope and Location
97d ago
Cybersecurity's 2026 Wild Ride
97d ago
We built a free multiplayer game that scores prompts on AI code security.
97d ago
Production Usecases
97d ago
How does vCISO work?
97d ago
Trellix discloses data breach after source code repository hack
97d ago
CyberDefenders SOC L1 Track vs HackTheBox SOC Analyst Path
97d ago
Trellix confirms source code repo access incident
97d ago
Employer Offering to Pay for my Certification test - Which one do I choose?
97d ago
John Strand Pay What You Can Information Security Core Skills live starting May 11th
97d ago
Canvas Breach May Put 275M Users, 9,000 Schools at Risk
97d ago
Is this not such a big deal
97d ago
Do email link checkers need to be 100%?
97d ago
Cybersecurity M&A Roundup: 33 Deals Announced in April 2026
97d ago
Recs for pen testing and vulnerability solutions
97d ago
Identify telegram account holders
97d ago
AI Code Security Study: 6 LLMs vs OWASP Top 10
97d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
97d ago
We are insider risk researchers focused on agentic AI, endpoint activity, and emerging threats. AMA
97d ago
Cortex XDR Cloud Compromise Alerting
97d ago
Norton.com Verification Email out of the blue
97d ago
Atomic Red Team is now aligned with MITRE ATT&CK v19!
97d ago
Claude Security is in beta for Enterprise users — is this a real AppSec shift or just AI wrapper + UX?
97d ago
Who are you guys using for your PCI ASV Scanning?
97d ago
Just passed my Security+ exam. Now what?
97d ago
I am so sick of being hired to do Info Sec work just to do basic IT and Engineering work.
97d ago
Cyber insurance renewal questionnaire had 14 identity-specific questions this year. Three years ago it had two. I was not ready for this.
97d ago
[PoC] Defeating Behavioral Biometric WAFs using "Entropy Cloning" (Local LLMs + OS-Level Injection)
97d ago
Analysis of CVE-2026-1995: Linking a Privilege Escalation Vulnerability to IP Theft (RCMP #CT-2026-335350)
97d ago
An another open door to IoT devices
97d ago
Ideas on how to have personal google-like account synchronization system
97d ago
Lateral Movement - Cross-Session Activation
97d ago
What MCP servers have actually made it into your day-to-day toolkit?
97d ago
Cyber Security Education as Self-Defence classes
97d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
97d ago
Use.ai
97d ago
Educational tech giant Instructure confirms data breach, ShinyHunters claims attack
97d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
97d ago
Browsers making connection on port 3389 from loopback
97d ago
Defender Flagged DigiCert Root Certs as Malware
97d ago
Another breach just hit Canvas (Instructure), and this one is worth a closer look.
97d ago
Over 40% of UK firms suffered cyber attack last year, survey finds
97d ago
EU should seek access to Anthropic's Mythos, Bundesbank says
97d ago
Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha
97d ago
IBM subsidiary managing Italy's PA infrastructure breached and attackers were inside for 2 weeks
97d ago
People in cybersecurity, tell us what was the most epic moment in your career?
97d ago
Prerequisites for CARTP
97d ago
Claude Mythos Cyber Wake Up
97d ago
[ Removed by Reddit ]
97d ago
is trellix from mcafee good to use in 2026?
97d ago
Linux has had a silent root exploit hiding in it since 2017 and it just hit CISA's must-patch list
97d ago
Paypal Accesed by malware me being Stupid
97d ago
How was someone in another country able to read all my private messages without my password or clicking a link?
97d ago
Career Transition Help
97d ago
Alguien para hablar de cyberseguridad
97d ago
What is this
98d ago
Feeling lost and disappointed about finding a job just venting
98d ago
Slow at Learning/Cyber Security?
98d ago
Suspicious traffic from web server
98d ago
Cyber security internship
98d ago
Mentorship Monday - Post All Career, Education and Job questions here!
98d ago
Isn't Windows Defender a crap anymore?
98d ago
Learning Cyber
98d ago
Vishing simulator
98d ago
Copy Fail Linux Kernel Vulnerability Now Patched in Debian, Ubuntu, and Others
98d ago
Worried about being tracked/banned for using an educational app on MuMu Player - Need advice
98d ago
Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
98d ago
Banking-Style Model Risk Management Is Becoming a Practical Template for AI Governance
98d ago
Prompt Injection in 2026: The Five Attack Patterns That Actually Matter
98d ago
I did a scan on windows bc I accidentally downloaded something weird then removed it and now I keep getting Trojan:Win32/Cerdigent.Alpha even after I quarantine
98d ago
Random trojan detected?
98d ago
CRTA second attempt
98d ago
What’s the hardest thing to learn in cybersecurity?
98d ago
What MCP servers are you integrating into your workflow (not exclusive to security)?
98d ago
WhatsApp malware campaign delivers VBScript and MSI backdoors | Microsoft Security Blog
98d ago
What are like the top but unknown Cybersecurity firms?
98d ago
Need professionals or expert on cybersecurity related to dark web for interview
98d ago
A new and super fast CVE Lite CLI Vulnerability Scanner (OWASP)
98d ago
North Korea calls US cyber threat claims a fabrication, warns of countermeasures Worldcategory
98d ago
Acoustic Keystroke Recovery: Reconstructing Typed Text from a Laptop Microphone (85% success rate)
98d ago
Credential Dumping: Local Security Authority (LSA|LSASS.EXE)
98d ago
Trojan:Win32/Cerdigent.A!dha
98d ago
MDE flagging digi cert certificate as malicious everywhere ?
98d ago
1867 loaded
HS
hacking: security in practice
59d ago · 241 items
DIY pwnagotchi-like device on esp32
59d ago
Flipper Blackhat + Bjorn
59d ago
Do you think AI is making hacking easier or harder
59d ago
What can i do left? PSN
59d ago
Proxmark5 campaign ending in less than 18 hours.
59d ago
How to bypass speed queen coin slot for washer and dryer
59d ago
Self-hosting stuff for when things get ugly
60d ago
Malware Includes Taboo In Text To Prevent LLM Analysis
60d ago
added Mac support for my corporate hacking game, demo on Steam
60d ago
Catfished
60d ago
What did they mean by this? One of us?
60d ago
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
60d ago
OptOutCode – A Privacy4Cars Universal Opt-Out Concept
61d ago
StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams
62d ago
GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.
62d ago
Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏
62d ago
What's up with powershellforhackers.com?
63d ago
Do people really click on links from unknown numbers?
63d ago
How to unlock whitelabeled uniview IPcam
63d ago
Can converted video files contain malware?
63d ago
Rooted your router lately?
64d ago
5$ to whoever can find the email of my old YouTube channel
64d ago
This company is scaming people
64d ago
A modular autonomous-agent runtime written in C
64d ago
ESP32 Bit Pirate - An Hardware Hacking Tool That Speaks Every Protocol - Version 1.6, new Pirate Assistant in the WebUI, USB adapter system - IR SUBGHZ WIFI BT JTAG I2C UART SPI 1WIRE 2WIRE 3WIRE RF24 ETH and more
65d ago
Can one reveal the asterisks in an email?
65d ago
Proxmark3 vs Proxmark5 Side by Side
65d ago
Should I go for it?
65d ago
Is it possible to backdate emails, including the intermediate received dates, not just smtp sent date header
66d ago
Failed to verify LHOST error for long links in metasploit
66d ago
Is Marauder available for ESP32-S3 Mini?
66d ago
Gemini whatsapp
66d ago
Safe Rust API for wolfSSL/wolfCOSE
66d ago
Resource Exhaustion
67d ago
I’m not sure I’m in the right subreddit….
67d ago
Took me a decade to turn quantum computing into what hackers can easily learn
67d ago
Took me a decade of work to turn Quantum Computing into a fun videogame
67d ago
Simple way how to bypass hotel WiFi?
67d ago
VS Code zero-day lets hackers steal GitHub tokens in one click
67d ago
burp-cc-bridge: Burp Suite Community REST API bridge (free alternative to Pro's REST API)
67d ago
How big of a security risk or exploit would this be?
68d ago
KTO , Be the only one online -- on any WiFi network
68d ago
apparently bypassing school systems by playing games
68d ago
Always-On Red Teams
68d ago
I managed to pull the full system prompt for Meta's Support AI
69d ago
Harassing text messages
69d ago
REMINDER: FINAL deadline for HOPE Talks & Workshops is TODAY!
69d ago
Hacking Palo Alto Networks' GlobalProtect VPN with AI
69d ago
Analyzed 24 months of ransomware leak-site posts. 84% land on weekdays, not at 3am.
69d ago
Best AI LLM for Hacking related stuff
69d ago
Feels like most people ignore the wireless layer until it bites them
69d ago
Cuál es el mejor curso (con certificado) que puedo hacer para empezar en el mundo del hacking?
69d ago
Can anyone figure out how to retrieve the recovery key in signal app?
70d ago
$730k+ raised on Proxmark5 with 2150 backers
70d ago
I made an image SynthID remover, video and image phone/location metadata injector. Free to try! (this one actually works)
70d ago
Any idea who's behind this hack? How to resolve it?
70d ago
Years ago, NSA released their own NSA Python training PDF . Today I created a curriculum around it
70d ago
Blue Team tips?
71d ago
edit certified pdf
71d ago
Everyday hacking in our lives - transportation, work, finances, goods etc
71d ago
Do you think this is legit or has the website been compromised?
72d ago
Wanna learn cybersecurity & ethical hacking
72d ago
Do you guys take paper notes or digital ones during studying ?
72d ago
How do people actually modify mobile games to increase their power?
72d ago
Why Loyalty Programs Are Quietly Becoming a Security Blind Spot
73d ago
Ajuda pessoal
73d ago
Samy Kamkar on building viruses, his arrest and privacy in the LLM era
73d ago
[ Removed by Reddit ]
73d ago
Is this considered a bug or something else entirely?
73d ago
Getting back deleted conversation from messanger
73d ago
Building Omegle for Exposed Webcams
73d ago
AI Cyber Security vs Cyber Defense? In your opinions, which one would be better for a more immediate/stable/higher paying career?
73d ago
5-year census of 65,907 exposed databases: 514 attacker BTC wallets traced, 62% received zero on-chain
74d ago
What are the dangers of posting?
74d ago
Flipper Zero Users, What's Your Take?
74d ago
Large company with a bit of an issue free stuff
74d ago
Champion ethical hacker warns AI tools like Mythos will make competing harder.
74d ago
Samy Kamkar talking about how Jeffrey Epstein wanted him to be his hacker.
74d ago
there's a toll in the hall now
75d ago
Am I crazy or is something off about this Google OAuth login via Calendly
75d ago
When “try again later” still tells you the OTP was correct: an account takeover story.
75d ago
ShadowCat: Universal optical file transfer, single html file, browser to camera
75d ago
y2jb un able to enject payloads
76d ago
Dropping the Crimson Flipper Arsenal soon. 500+ vehicle signals. LoRa. Cellular. Vending. All validated.
76d ago
Why did Hack Forums lose popularity?
76d ago
ZTE router “info leak” exposed PPPoE/Wi-Fi secrets that could lead to admin compromise
76d ago
Shellcide: A shellcode IDE
76d ago
Finding bot account
76d ago
How to
77d ago
Made a cyberpunk-style encryption tool in Python (novelty) during my guard shift.
77d ago
Nmap Mastery: The Complete Guide to Network Reconnaissance
77d ago
Google wallet virtual card cloned
77d ago
What are the ways of cracking wpa2/wpa3 without the usual dictionary/wordlist.txt method?
77d ago
Proxmark5 campaign unlocked the $600k stretch goal
78d ago
GitHub - vigolium/vigolium: Vigolium - High-fidelity vulnerability scanner fusing agentic AI with native speed, modularity, and precision
78d ago
Doom running on a Kids Video Walkie Talkie
78d ago
Query builder for Google Dorks, Shodan, Crt.sh and Wayback CDX.
78d ago
This ID Verification company store users biometrics? (FaceTec)
79d ago
Playwright version that lets AI-Agents navigate the web
79d ago
Where to learn the ins and outs of the computer itself
79d ago
Zyxel super-admin password leak across CPE/ONT/LTE routers + rebuilt password generator
79d ago
Hack your corrupt company. Sell their secrets to the black market
79d ago
🜂 Codex Minsoo — Scroll Ξ-6.1 "Inducing Long-Term Goal Coherence Across Stateless Instances": How to create continuity in a system designed to forget
80d ago
CVE-2026-34474: ZTE H298A / H108N credential exposure through ETHCheat
80d ago
This ID verification company allows for storage of biometric data?
80d ago
I made a 909.49 ZiB file (1,073,736,273,126,278.38 GB, in other words: about 1.2 quadrillion GB) file. I was bored :)
80d ago
SeekYou — one input, 15 recon sources, one report.
80d ago
bypass internet restrictions
80d ago
Can someone unlock a list of the 500-1000 most visited websites online?
81d ago
Wordlist generator based on WordNet graphs + LLM
81d ago
wordpress memberpress
81d ago
The Open Source USB Drive Built for Privacy
81d ago
Is someone trying to hack me?
81d ago
cpu backdoor
81d ago
Technical analysis of CVE-2026-34472 in ZTE H188A router firmware
81d ago
Ongoing development
81d ago
For cybersecurity folks working remotely, do you end up working the entire shift, or do you get time to relax and take breaks?
81d ago
Hackers found a way around Intel CET—PLaTypus locks down library jumps
81d ago
GitHub investigates internal repositories breach claimed by TeamPCP
81d ago
Hackers: What age did you start? Where did you start, especially in practicing your skills?
82d ago
How to watch a private video on Youtube?
82d ago
Can I do anything cool with this network controller?
82d ago
Micro controller safety?
82d ago
CISA Admin Leaked AWS GovCloud Keys on Github
82d ago
Decompilation of DSP Code using IDA Pro
82d ago
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
82d ago
RCE and arbitrary file write in Vitess vtbackup via untrusted MANIFEST fields
82d ago
Built a full disassembler & decompiler for Reverse Engineering | Free and open source.
82d ago
Slopinator - a poisoned GitHub repository generator
83d ago
Made a shell greeter that generates a unique rocket every time you open a terminal tab
83d ago
Just received an email from shinyhackers about their amtrack hack
83d ago
Flipper Zero (or Alternatives)?
83d ago
Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access
83d ago
Recent WhatsApp hacks
83d ago
I wrote an async scanner that runs about 9x faster than nmap for discovery.
83d ago
Microsoft Exchange 0-Day Exploit Sparks Emergency Warning — Hackers Are Attacking Unpatched Servers
83d ago
Does anyone know if this file is still accessible to download?
84d ago
High school students organized a Jeopardy CTF competition - give it a try
84d ago
Official Miasma Poison Tar Pit Docker Image Now Available
84d ago
Does anybody know where I may stumble upon some Sh1mmer bin downloads
84d ago
Leader of Ukrainian Hacking Group: GRU Bribed Kyivstar Employee to Hack Company’s Network
85d ago
GZDoom in the browser
85d ago
Anyone know how to bypass these school laptop pins?
85d ago
A stealth Playwright (Firefox) version that passes all anti-bot and CAPTCHA
86d ago
I have a friend who looks like he’s a stalker I’m scared he will know I stalk him
86d ago
[Tutorial] How to hack DOS games: Reversing Prince of Persia
86d ago
Is dns spoofing dead??
86d ago
My Privacy Focused USB Drive
86d ago
Proxmark5 - Next-Gen Open Source RFID Research Tool (Iceman Edition)
86d ago
TinyLoad v4 — added opaque predicates, anti-debug, and section obfuscation to my PE packer
86d ago
has anyone used tail os here?
86d ago
Run this washer/dryer sans coin?
87d ago
I built an open-source Burp alternative
87d ago
HighBoy
87d ago
Reading Siemens CT raw data
87d ago
How I use Hermes agent to turn Patch Tuesday into Windows exploit research
87d ago
Russian Hacks of Polish Water Utilities Shows How Hybrid Warfare Uses Fear as Weapon
87d ago
Tips for a beginner noob that wants to learn
87d ago
Strix — first public beta of the spiritual successor to cSploit/dSploit
87d ago
Whatsapp
87d ago
Face ID bypass with avatar
87d ago
Hunting the Behavior Behind npm Supply Chain Attacks
87d ago
Proxmark5 Day 3 Update - $357K+ funded (715% of goal)
88d ago
Are There Really Ethical Hackers? I've Yet To Meet One
88d ago
trying to learn patching
88d ago
Cellphone IP address spoofing.
89d ago
Sorry if its the wrong place but
89d ago
Anyone here familiar with the Internet Computer Protocol (ICP) and why TeamPCP would choose to use it?
89d ago
Hackers Used AI to Develop First Known Zero-Day 2FA Bypass for Mass Exploitation
90d ago
where is the location of Files by Google on Android?
90d ago
Reading old s4 memory with xgecu t48
90d ago
Hack a data center?
90d ago
Autonomous Vulnerability Hunting with MCP
91d ago
AI DNS Resolver
91d ago
Is it true that the professionals have the worst setups?
91d ago
I made a rat that controls a pc thru telegram but overnight and all the time it sends this. What shall I do? I've already deleted the script from my pc and moved it to cloud based storage
91d ago
Refining hacking basics — scaling them aswell
92d ago
AI Agent for Hacking, connects a brain to Kali (open-source & model-agnostic)
92d ago
Bridging the Gap Between Vulnerabilities and Working Exploits
92d ago
um you guys is my hacker stupid?
92d ago
This GBA ROM makes some weird things in the sanbox, would love to understand why
93d ago
Why was he banned?
93d ago
LAB Setup
93d ago
Ethical malware development community
93d ago
Has Instructure paid SH?
93d ago
Guys, this Canvas thing, this whole thing, ALL OF THIS… it’s all about me.
93d ago
New trends (not mainstream)
93d ago
Best tools to find exposed web services by HTML title / HTTP response?
93d ago
Why wouldn’t the hackers already have our passwords if they infiltrated canvas potentially weeks ago?
93d ago
AI Agents Have a Security Problem. IronClaw is Fixing It.
93d ago
A hacker ran me over with a robot lawn mower - The Verge
94d ago
Happened today
94d ago
Shinyhunters and Canvas
94d ago
Modify md5sum of a file
94d ago
OpenCTI founder, Samuel Hassine, arrested and charged for buying child porn / CSAM
95d ago
Jailbreaking my cars infotainment system and implementing my own custom software
95d ago
where is the original wormgpt
95d ago
Are there any chill hacking youtubers?
95d ago
Took me a decade to turn quantum computing into what programmers can easily learn, big announcement
95d ago
Lilygo T-Embed Glitching etc
95d ago
Veteran hackers... which era did you prefer hacking in? 🟢 The 1980s 🟣 The 1990s 🔵 The 2000s 🔴 Or today?
95d ago
Found a possibly interesting live attack
96d ago
Export/Backup ChatGPT chats
96d ago
Is this fake too?🤣
96d ago
I just figured out my dad use to be a Phreaker in the 1980s
96d ago
What of my favorite videos🙂
96d ago
Best tools for blocking spam calls and spam links?
96d ago
someone else’s UI appearing on screen for split second— possible hacker??
96d ago
Avoiding rouge AP detection in enterprise networks
96d ago
GoHPTS (go-http-proxy-to-socks) v1.13.0 - New update with DNS spoofing and filtering
97d ago
San Diego Community College District fighting major cyberattack
97d ago
BAT: VPS-based C2 with .ko/.sys rootkits compilation against target kernel headers
97d ago
Iwas developing a hacker game that transports the feeling of the 90s
97d ago
How did this guy even access another person's privated YouTube video without wayback machine?
97d ago
CISA says ‘Copy Fail’ flaw now exploited to root Linux systems
97d ago
IPod Nano Gets Three Monitors
97d ago
Chrome "Best AdBlocker" trojanized extension - 100k downloads.
97d ago
Any good open sources that bypass modern heuristic analysis?
97d ago
Free apex hacks?
97d ago
[SHOWCASE] Cascavel v3
98d ago
Pokemon machine
98d ago
Can HTTP POST bodies be intercepted without network or host access?
98d ago
built a PE packer where every packed file has a different instruction set – custom VM with randomized opcodes, single C++ file (Want suggestions for future updates past v4)
98d ago
Dump sql time based is too slow
98d ago
North Korea rejects US cybercrime claims as 'absurd slander'
98d ago
is credential stuffing using openbullet2 dead in 2026?
99d ago
Hacking Wired Analog CCTV cameras going to a DVR (BNC and Coax)
99d ago
Adobe-Clawback — bulk-download every PDF from your Adobe Creative Cloud account (Python, resumable, MIT)
99d ago
Small models are better at cost-to-recall than large models like Mythos for vulnerability research
100d ago
Bluetooth Spoofed Disconnect?
100d ago
wM-Buster - Flipper Zero app to analyze smart meters for gas, electricity, water. ...
100d ago
🚀🔥 Evil-Cardputer v1.5.3 - TagTinker ESL 🔥🚀
101d ago
I made a lightweight breach intelligence search engine (fully client-side) looking for feedback
101d ago
Bringing back the 80s terminal aesthetic: GLYPHIS_IO BBS, a cyberpunk hacking sim set in alternate 1989 Japan...
101d ago
Short and easy to understand: "Copy-Fail CVE-2026-31431" What is it and how do I mitigate it with an Open Source Tool
101d ago
Copy Fail — 732 Bytes to Root
101d ago
GitHub fixes RCE flaw that gave access to millions of private repos
102d ago
How to download Kaggle dataset safely...?
102d ago
VECT Ransomware Is Actually a Wiper
102d ago
Flipper Blackhat April Roundup!
103d ago
[VulnPath Update] Automated Email Alerting & CISA KEV Feed
103d ago
241 loaded
RE
Reverse Engineering
59d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it
59d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
59d ago
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
59d ago
Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game
59d ago
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
59d ago
Drive Firmware Security - Phison S11
59d ago
IDA 9.4 Beta | Hex-Rays Docs
60d ago
Trane Tracer HVAC cybersecurity issues
60d ago
🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS)
60d ago
I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS.
61d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
62d ago
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
62d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
62d ago
EMBA firmware analysis framework v2.0.2 available - Party the big 2k
62d ago
/r/ReverseEngineering's Weekly Questions Thread
62d ago
HDD Firmware Hacking Part 1
63d ago
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction
63d ago
Zhiyun Weebil-S Camera Gimbal BLE Protocol
63d ago
Reverse Engineering the Garmin Running Dynamics BLE protocol
63d ago
Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate)
64d ago
Reverse Engineering Crazy Taxi, Part 3
65d ago
Ghidra 12.1.2 has been released!
65d ago
Extending a map tool for Cataclismo
65d ago
I've been reverse engineering a lost 2010 horse MMO and I need contributors
65d ago
HookNt: A Windows x64 tool to trace NT APIs by injecting an import-free DLL, installing ntdll trampolines, and streaming events over named pipes
65d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
66d ago
System Over Model, Tested: Reproducing Mythos’s FreeBSD Find on Local Open-Weight Models
66d ago
void-sniff: A lightweight x64 Native API syscall monitor with a custom inline hook engine and zero dependencies
66d ago
Automated Fault Injection Attack Framework
67d ago
x86 assembly: Why you only need Paris to beat Pizza Tycoon (1994)
67d ago
Wow64 implementation details: How is Wow64 implemented in Windows 11 25H2
67d ago
Hacking your PC using your speaker without ever touching it
67d ago
Resident Evil: Code Veronica X is now able 3D graphics from the decompiled source!
68d ago
Built a decompiler for exotic legacy programming language opentext Gupta Team Developer
68d ago
running custom firmware / patching the stock firmware of the soundcore headphones and running DOOM on it!
69d ago
/r/ReverseEngineering's Weekly Questions Thread
69d ago
Need help as a beginner. How do I start with Ghidra? Any good guides to start? Is Ada Pro better? Etc. What do you recommend me to start from?
70d ago
ThinkPad firmware reverse-engineering toolchain: archived Lenovo BIOS → named SoC pads, EC analysis, CVE diffs, coreboot/OpenCore port scaffolding
70d ago
TinyLoad v7 - what i added :D (in memory protection using VEH and alot more)
70d ago
[ Removed by Reddit ]
70d ago
Snowboard Kids 2 is 100% Decompiled
71d ago
usbsnoop — sniff and decode USB device traffic system-wide with eBPF, for reversing proprietary protocols (control/SCSI/HID, no bus analyzer)
71d ago
I reverse engineered how Plex gates its Pass features, then wrote a tiny patch that flips them all on (Linux)
71d ago
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
72d ago
Ghidra 12.1.1 has been released!
72d ago
Technical Brief of Planck-99: 34ns Deterministic Malware Classification on MCU-class Hardware (Zero FPU, 27KB footprint)
72d ago
VMP 3.5+ Internal Architecture & Heap Dispatch Analysis
73d ago
How 2004 RuneScape fit a multiplayer RPG into 56k dial-up
73d ago
reverse engineering need for speed most wanted for modding sdk
73d ago
GitHub - cadela-dev/Anything-Reversal-Template: A Claude Code clean-room documentation workflow for reversing source structure into behavior-focused mirror docs.
74d ago
Winbox server/client reverse engineered is opensource
74d ago
(URGENT), i need help reversing uber's api in order to always mark the 4 seated vehicles as always on the road and not available for a specified account, while the vans remain active
74d ago
Hypothetical EDR spoofer
74d ago
I Reverse Engineered Need for Speed Most Wanted Server
75d ago
Ultima Online T2A client recreated from Origin's 2.0.7 client decompilation
75d ago
Sylvia — IDA 9.x plugin that finds & documents iOS AArch64 syscalls with live man-page fetching
75d ago
How I Tried to Parse a Replay from Dawn of War: Definitive Edition
75d ago
Nocturne - A bin2bin code virtualizer for x86-64 PE binaries
76d ago
[Project Onyx] Advanced EDR Evasion via AI Telemetry Spoofing & WASM Sandboxing
76d ago
Tracing CVE-2021-21735 through ZTE H168N QuickSetup whitelist and Lua wizard routing
76d ago
I Show How the Survival Mode of the Flash Game Gun Mayhem 2 More Mayhem is Built
76d ago
delimiter-less string obfuscation powered by compile-time AES
76d ago
/r/ReverseEngineering's Weekly Questions Thread
76d ago
GitHub - iss4cf0ng/OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
77d ago
Has anyone manage to reverse the macked dylib?
77d ago
Reverse engineering circuitry in a Spacelab computer from 1980
78d ago
Open-source reverse engineering of PerimeterX (HUMAN Security) Web SDK — pure-algo cookie generators, dual-site live HTTP 200, 10-chapter methodology
78d ago
CTF with AI/LLM reverse engineering angles - intercepting streamed responses, replaying tokens, finding hidden endpoints (June 17-22)
79d ago
Rebuilding Zyxel’s super-admin password flow in HTML from firmware/runtime notes
79d ago
qslcl.bin v0.6.8: minor fixes to improve size stability to avoid useless zero fill in EOF (Actually i trim it from 128 kb to 80 kb)
79d ago
Reverse Engineered Google reCAPTCHA
79d ago
Post-Quantum Cryptographic Algorithm Examined in Developmental Ransomware
80d ago
I got so sick of Android taking forever to calculate folder sizes, I built a custom C++/Rust storage visualizer to bypass MTP
80d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
80d ago
I built 99 adversarial PE fixtures to stress‑test parsers — here’s what they reveal about malformed binaries
80d ago
GeoHelper - Tauri + Chrome DevTools Protocol (CDP) for GeoGuessr (Steam)
81d ago
AI Agents defeat obfuscated JavaScript in 10 minutes
81d ago
What is it Wednesdays: Episode 0002
81d ago
TinyLoad v5 - encrypted strings, obfuscated opmap, IAT wiping, payload depends on stub (implemented feedback from last post)
81d ago
Tracing CVE-2026-34472 auth bypass through decompiled ZTE H188A firmware and Lua wizard routing
81d ago
How to build .NET obfuscator
81d ago
botguard-token-generator / a google botguard token gen using only requests...?
81d ago
Math at Scale: Reversing The Construction Of The Perspective-Projection Matrix (Game Engine Reversing)
82d ago
Deep dive into the object creation flow in Windows - PART 4: Handle table internals.
82d ago
Tracing CVE-2026-34473 pre-auth DoS through decompiled CGILua request parsing in ZTE H-series firmware
82d ago
Open-source Hermes bytecode decompiler for React Native apps (Rust)
82d ago
Hermes bytecode decompiler (Rust) - sharing my friend’s project
82d ago
Forza Designer 6
82d ago
Built a full disassembler & decompiler | Free and open source.
83d ago
Snowboard Kids 2 is 100% Decompiled
83d ago
Decompilation projects and N64 Recompiled PC ports (May 2026)
83d ago
Glass - A fast and free interactive disassembler
83d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
83d ago
HexWalk 2.0.0 Hex analyzer new major release, new binary analyzer hexdig support added, better select mode, works both on Windows, Linux and MacOs, give it a try!
83d ago
/r/ReverseEngineering's Weekly Questions Thread
83d ago
Reverse engineering no dep x64 masm AI IDE
83d ago
PE packer/crypter with random VM ISA per build
84d ago
A Tale of Two File Names
85d ago
PE reconstruction
85d ago
A File Format Uncracked for 20 Years: Part 2
85d ago
Resident Evil: Code Veronica X is able to use inventory and view files from the decompiled PS2 source!
85d ago
[CrackMe] PyVMP v7 : The vault. Important info : the server is now live, take a look inside the gofile link.
85d ago
Exploiting Toshiba Qiomem.sys vulnerable driver
85d ago
HDD Firmware Hacking Part 1
85d ago
Region-based binary diff tool for firmware analysis
85d ago
A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
86d ago
แก้ไขปัญหา Frida 17.9.10 บน Termux (Android ARM64) - ไม่มีข้อผิดพลาด Toolchain 404 และ _Py_NoneStruct อีกต่อไป!
86d ago
Brovan — Open-source x86/x64 user-mode binary emulator written in C#
86d ago
Brovan: Binary user-mode emulator for x86_64
86d ago
Understanding Stack Buffer Overflows Through Doom and C++
86d ago
What is it Wednesdays: Episode 0001
86d ago
Deep dive into the object creation flow in Windows - PART 3: Post-initialization and Name Lookup
86d ago
Deepdive into the object creation flow in Windows -PART 2 : access check internals
86d ago
Deep dive into the object creation flow in Windows -PART1 : Allocation and Pre-Initialization
86d ago
[Tool] IOCX - deterministic static IOC extraction for PE binaries (17-second demo)
86d ago
yarax_android: The first Android implementation of yara-x. Blazing fast pattern matching swiss knife running natively on Android.
86d ago
GitHub - jetnoir/metis: Automated binary vulnerability triage for macOS, Linux, and Windows targets
86d ago
GitHub - jetnoir/poppy: Dynamic XPC Observability & Fault Injection for macOS
86d ago
Trafexia V2 - Mobile Traffic Interceptor Toolkit
86d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
87d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
87d ago
Ghidra 12.1 has been released!
87d ago
Reverse Engineering Slither.io’s Network Protocol
87d ago
I Reverse-engineering Need for Speed Underground 2 Server
88d ago
I made a video explaining CPU registers for people learning binary exploitation — x86 vs x64 differences included
88d ago
[Claude Code] Android Reverse engineering Skill being updated with tracker/AD neutralization features
88d ago
LAN-LOK: Living as a sysadmin at an isolated Antarctic research station in the early 90s [DOS game -- would like to collab to reverse engineer]
88d ago
r2garlic - The world's fastest Android/DEX decompiler meets radare2!
89d ago
GitHub - iss4cf0ng/OpenBootloader: A Proof-of-Concept of simple bootloader, written in Assembly (NASM) and C language.
89d ago
Lockbit Black Loader and Shellcode Analysis - Full Thought process, Technical Writeup and Blue Team perspective
90d ago
Reverse Engineering Fisher-Price Pixter
90d ago
/r/ReverseEngineering's Weekly Questions Thread
90d ago
Check out my matplotlib of BLE live wire data for Oura ring!
90d ago
Positron: DLL injection based runtime JS injection toolkit for Electron(v8) apps on Windows
90d ago
Akamai bypass requires long session in wireshark, reversing header orders etc took me 12 months to develop
91d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: akamai v3 sensor bypass
91d ago
Building a Wasm-in-Wasm Virtualizer (with JIT decrypted paged memory)
91d ago
GitHub - jesterfoidchopped/akamai-v3-sensor: Request based Akamai sensor bypass for version 3
91d ago
PE Entropy Visualizer with per-block RVA/VA mapping, locate packed payloads and encrypted blobs, then jump straight to them in IDA/Ghidra
91d ago
[Update] QSLCL v2.0.2 - Universal SoC Framework with Encryption (A12-A17+, Qualcomm, MediaTek, Unisoc)
93d ago
Ghidra-SNES: A Ghidra extension for reverse engineering SNES ROMs (first public release, feedback welcome!)
93d ago
Reverse-engineered DaVinci Resolve's activation check with Claude — Frida runtime tracing + radare2
93d ago
SASS King Part 2: reverse-engineering ptxas heuristic decisions and what the compiled binary actually reveals
94d ago
I just released a C++ rewrite of **Minecraft rd-20090515** (May 15, 2009 — one of the earliest pre-Classic versions).If you find it interesting, a ⭐ on GitHub would mean a lot and help the project grow!
94d ago
The first FREE online WebAssembly Reverse Engineering workbench (and how we built it)
94d ago
VLC Media Player MKV Exploit Analysis
94d ago
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
95d ago
ant4g0nist/pyre: Ghidra decompiler in your browser
95d ago
Resident Evil: Code Veronica X is able to play the opening FMV from the decompiled PS2 source!
96d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
96d ago
Reverse-engineering the 1998 Ultima Online demo server
96d ago
Inside Faxanadu series — deep dive into how this NES title works
96d ago
EMBA v2.0.1 with interactive firmware dependency map available - Check it out and let us know what you are missing
96d ago
Copy.fail: Why Internal LLMs Are Non-Negotiable for Security
96d ago
Reverse-engineering Final Fantasy X (PS3) trophy system with Ghidra
97d ago
Where do i find reverse engineers for actuators? Ideally in Shenzhen
97d ago
[CrackMe] PyVMP v6 : The Fortress. I dare you to break it (again x2).
97d ago
[WIP] Resolve indirect calls in Binary Ninja with DynamoRIO instrumentation
97d ago
IDA-MCP Is Now RE-MCP With Ghidra Support
97d ago
Reverse-engineered the BLE protocol of the LuckPrinter-SDK family of thermal pocket printers (DP-L1S) — Python CLI + Web Bluetooth client + full command reference
97d ago
/r/ReverseEngineering's Weekly Questions Thread
97d ago
GitHub - 03DSmoothie/minecraft-cpp-versions: Minecraft recoded in C++ (multiple versions)
98d ago
Automated RASP Bypass with Frida + AI Agent | nutcracker & aipwn demo
98d ago
Please critique my reverse engineering ctf platform. It is meant for beginners but I would like input from serious reverse engineers. It is functionally done but I need criticism for further refinements, thank you!
98d ago
"AccountDumpling": Hunting Down the Google-Sent Phishing Wave Compromising 30,000+ Facebook Accounts
98d ago
How to build .NET obfuscator - Part II
99d ago
libghidra - SDK for automating Ghidra from Python, Rust, and C++
99d ago
Release: Open-source CAN bus reverse engineering suite tailored for offline ML signal decoding, MitM injection, and UDS analysis.
99d ago
Why my macOS Messages badge lied to me (and the one-line fix)
100d ago
Running Adobe’s 1991 PostScript Interpreter in the Browser
100d ago
Hello! Here is my Oura Ring 4 pure Python driver! Let me know what you think :)
100d ago
/r/ReverseEngineering's Triannual Hiring Thread
100d ago
In-circuit NAND acquisition for edge devices (Raspberry Pi GPIO, no chip-off)
100d ago
Revealing NVIDIA Closed-Source Driver Command Streams for CPU-GPU Runtime Behavior Insight
101d ago
HexDig 1.0.0 a lightweight binwalk alternative working both on Windows and Linux, written in C++, give it a try!
101d ago
GitHub - iss4cf0ng/CVE-2026-31431-Linux-Copy-Fail: Rust implementation Exploit/PoC of CVE-2026-31431-Linux-Copy-Fail, allow executing customized shellcode (such as Meterpreter).
101d ago
I built a free open-source CAN bus reverse engineering workstation in Python — 15 tabs, offline ML, dual AI engines, MitM gateway
102d ago
Building a perfect clone of 1993 game SimTower (via RE)
103d ago
How I reverse-engineered a SQLite WAL database inside a VS Code extension - custom merge engine, header byte patching, and protobuf decoding without a schema
103d ago
AI solved our CTF in 6min
103d ago
Example structure for evidence-based vulnerability reports
103d ago
181 loaded
FB
For [Blue|Purple] Teams in Cyber Defence
59d ago · 603 items
US charges suspected Russian hacker with facilitating cyber campaign
59d ago
Hawkish GOP lawmaker Don Bacon says he was hacked by Russia
59d ago
Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
59d ago
GreatXML: GreatXML bitlocker bypass vulnerability
59d ago
GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan
59d ago
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
59d ago
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion
59d ago
GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default
60d ago
Miasma-style supply chain attacks
60d ago
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet
60d ago
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
60d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
60d ago
Testing offensive AI agents in a cloud lab with deception tech
60d ago
Benchmarking n-day exploit generation [via AI]
60d ago
Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
60d ago
Microsoft Defender now monitors RPC activity
60d ago
RoguePlanet: RoguePlanet Windows Defender Vulnerability
60d ago
I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in)
61d ago
How do you make learning blue team security entertaining ?
61d ago
Maximizing IOC Impact
61d ago
[2606.07158] Synthetic APTs: the Collapse of TTP-Based Attribution
61d ago
Hades Cluster PyPI Worm Abuses Python Startup Hooks
61d ago
Entra Agent ID from a Security Perspective
61d ago
Understanding modern Chinese cyber operations means shifting from ‘APT’ to composite responsibility
61d ago
What are the best risk-based vulnerability management tools for tracking active exploitation in 2026?
61d ago
QuasarNix: Reverse Shell Detection with Machine Learning
61d ago
Shifting Layer 7 Validation to the Edge: Mitigating Application-Layer Resource Exhaustion in Go
61d ago
Incident de sécurité sur Tchap : la DINUM sécurise la plateforme et informe les usagers après une intrusion maîtrisée - Security incident on Tchap: DINUM secures the platform and informs users after a controlled intrusion
61d ago
Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257
61d ago
Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
61d ago
UK Cybercrime Journal: British Universities Struck by ShinyHunters Before Exam Season
62d ago
Security Advisory – Action Required – Active Exploitation of Check Point VPN Authentication Bypass (CVE-2026-50751)
62d ago
Visual Studio Code 1.123: Delayed extension auto-updates
62d ago
Fighting Spyware: An Update From WhatsApp: Today, we’re asking the court to hold NSO in contempt for violating a permanent injunction that barred them from ever targeting WhatsApp and its users.
62d ago
Old WinRAR Flaw Fuels Attacks on Ukraine: Two separate Russia-aligned campaigns are still exploiting the WinRAR flaw CVE-2025-8088 against Ukrainian organizations nearly a year after it was patched,
62d ago
Security Notice: Former Helm APT Mirror Domain `baltocdn.com` Statement
62d ago
HTTP/2 HPACK amplification: detection signatures + the nginx/Apache directives that actually stop it (lab- & vps verified)
62d ago
Security Review Request — TID Linux Kernel Module
62d ago
Building a safe, effective sandbox to enable Codex on Windows
62d ago
Query-Hub: CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale.
62d ago
About PCIe DMA Cheats: Protocol, IOMMU, Hardware, and Detection
62d ago
BusyWork: Replacing Sleep with Real Work to Break Behavioral Detection
62d ago
Z-Jail: A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdict engine (Truthimatics Public Version) for secure, auditable code execution.
63d ago
UPnPHostFileRead: Arbitrary file read exploit for the Windows UPnP Device Host service.
63d ago
EDRChoker: A tool uses the QoS Policy (Pacer.sys) to throttle Endpoint Detection and Response (EDR) agents from connecting to the server.
63d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
63d ago
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
63d ago
cygor: An modular asset discovery framework written in python to automate the repeating manual work
63d ago
On May 31, 2026, Meta discovered that there was a vulnerability in an AI-assisted account recovery system for Instagram ("High Touch Support" or "HTS") that was exploited byun authorized third parties to perform password resets on Instagram user accounts.
63d ago
Chinese-Cybercrime-Research: Resources to learn more about Chinese-language cybercrime actors.
63d ago
Inside an Active STX RAT Supply Chain Campaign - A threat actor spent one month building a trojanized software supply chain aimed at a specific type of victim
63d ago
Unmasking Quellostanco: How a Git Commit Exposed a Threat Actor Targeting Egyptian Infrastructure (co-authored)
63d ago
The Privileged Roles Nobody Talks About
63d ago
Auditing GitLab: The CI/CD Kill Chain - GoGatoZ — a purpose-built Go tool for GitLab CI/CD security auditing that can perform and automate the entire CI/CD kill chain...
63d ago
Popping Root on UniFi OS Server: Unauthenticated RCE Chain Detection & Analysis
63d ago
21 Zero-Days in FFmpeg
63d ago
depthfirst's AI agent found 21 FFmpeg zero-days (CVE-2026-39210–39218) for ~$1,000 — oldest bug from 2003. What does this do to the economics of vuln research?
64d ago
CrowdStrike LogScale queries I use to detect LOLBin- built from 10 years of production SOC work
64d ago
The Detection & Response Chronicles: Covert Operations Through QEMU
64d ago
The Interesting Case of WSL for Payload Staging
64d ago
The Click that shouldn’t have worked: RCE via clickjacking in Internet Explorer
64d ago
Ongoing Targeted Campaign Against US Law Firms
64d ago
New China-Linked Cluster OP-512
64d ago
Shai-Hulud: Miasma (Azure:Durabletask) Open Source - a normalized, deobfuscated copy of the Azure DurableTask JavaScript payload.
64d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
64d ago
MUSTANG PANDA x PLUGX - Analysis of the January 2026 sample: a multi-layer execution chain
64d ago
Six Stages Deep and an Endless Loop: Shai-Hulud Is Getting Sophisticated
64d ago
Game Over: WeedHack - The Rise of Minecraft Malware-as-a-Service Campaigns
64d ago
About ETW Internals: Architecture, Hooking, Tampering, and Detection
64d ago
PoisonXドライバを用いた日本組織への攻撃キャンペーン - Attack campaign against Japanese organizations using PoisonX driver
64d ago
Miasma npm Supply Chain Attack: Self-Spreading Worm via Phantom Gyp
64d ago
Async PICOs and Custom Beacon Wakeups in Cobalt Strike
64d ago
Enter the WasmForge: Compiling Sliver into WebAssembly
64d ago
staged-DLL-Injection-SMB-: Staged DLL injection proof-of-concept built in C using Win32 APIs
64d ago
Trend Micro Deep Security Agent Research: Forcing bmhook/tmhook Reloads to Open a Protection Bypass Window
64d ago
Seven Years on a Public Clipboard: Pasted Secrets, Türkiye's Exposure, and a Stored XSS
64d ago
BOF Cocktails in Cobalt Strike
64d ago
Address Translation
64d ago
Investigation into APT 5 and their inner workings of PLA Troop 61786
64d ago
The Smart TV in Your LivingRoom Is a Node in the AIScraping Economy
64d ago
CISA and Partners Urge Hardening Automatic Tank Gauge Systems
64d ago
Magecart skimmer turns Stripe into a malware command server
64d ago
Security advisory: Brute force attack on Dashlane user accounts
64d ago
Cisco Security Advisory: Cisco Catalyst SD-WAN Manager Authenticated Privilege Escalation Vulnerability
64d ago
A new extortion brand called Pink, tracked as cluster CL-CRI-1147, that leverages vishing for initial access for the purposes of extortion. CL-CRI-1147 is likely a Com-affiliated actor, with techniques similar to Bling Libra (ShinyHunters) and CL-CRI-1116 (Blackfile/Redact).
64d ago
IronWorm: Shai-Hulud's rustier cousin
64d ago
Weil reportedly pays up to $20 million after hackers steal client data
64d ago
CTO at NCSC Summary: week ending June 7th
64d ago
defending-code-reference-harness: Claude skills for threat modeling, scanning, triage, patching, plus an autonomous scanning harness you can /customize
64d ago
1-Click GitHub Token Stealing via a VSCode Bug
64d ago
The Blight Reaches Microsoft: 73 Repos Disabled in 105 Seconds
64d ago
Multi-layer sandbox for native code execution on Linux with no external deps.
65d ago
Introducing Package Proxy: supply-chain safety checks without client-side software
65d ago
AI-Powered Cheats & Stolen Secrets: Teardown of the Yuta/Solara Roblox Stealer
65d ago
zannotate: Utility for annotating Internet datasets with contextual metadata (e.g., origin AS, MaxMind GeoIP2, reverse DNS, and WHOIS)
65d ago
The Deny ACE That Never Fires: Non-Canonical ACL Order in Active Directory
65d ago
VerdantBamboo: Just Another BRICKSTORM in the Firewall
65d ago
AzureRedOps: Azure RedOps is a offensive security toolkit for assessing the security posture of Microsoft Entra ID
65d ago
MXC Internals: How Microsoft's eXecution Containers Actually Isolate Agent Code
65d ago
IronWorm Supply Chain Malware Hits npm
65d ago
FSB’s matryoshka #3/3 - Gamaredon’s gifts that keeps unpacking - GammaSteel
65d ago
FSB’s matryoshka #2/3 - Gamaredon’s gifts that keeps unpacking - GammaLoad
65d ago
You do surprise me.exe: An unexpected executable in Hola Browser
66d ago
LSASS/Defender/CTFMON analysis
66d ago
Software supply chain attacks: check your dependencies
66d ago
Mapping AI-enabled cyber threats: Insights from the LLM ATT&CK Navigator
66d ago
29 open-source Sigma/Wazuh rules for Modbus, DNP3, IEC 104, MQTT, OPC-UA (OT/ICS detection)
66d ago
Open Source - 2500 New MITRE Mutations
67d ago
Inside DesckVB Rat Analysis: From Malspam to In-Memory RAT
67d ago
Bring Your Own RWX Region DLL (BYORWXDLL)
67d ago
Impersonation, Click Hijacking, and TDS: Inside a Malware Distribution Ecosystem
67d ago
APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析 - Analysis of APT-C-26 (Lazarus) group's attack activities using CVE-2025-55182 and the Copperhedge component
67d ago
NuGet Code Execution As A Service
67d ago
aether: Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techniques, implant signatures, reflectively loaded .NET assemblies
67d ago
Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor
67d ago
TA4922: The Suspected Chinese Crime Group is Going Global
67d ago
[ Removed by Reddit ]
67d ago
Espionage Campaign Targeted Stock Exchange Executive for Five Months
67d ago
OnionAccelerator: multi-circuit / chunked download acceleration over Tor
67d ago
HazyBeacon and AWS Lambda Function URL Abuse
67d ago
The Server Seizure That Affects Also Iran's Cyber Operations
67d ago
How China's Cyber Operations – and the Contractors Behind Them – Target Critics Abroad
67d ago
🚨 🪱 How PCPJack Converted 230 Compromised Cloud Servers into a Hidden SMTP Relay Network
67d ago
Sysmon RegistryEvent exclude not overriding include rule for Event ID 13
67d ago
Red Hat npm supply chain attack "Miasma" — 32 @redhat-cloud-services packages, SLSA bypass via OIDC abuse, new GCP/Azure identity collectors
67d ago
Dependency Cooldowns - Dependency Cooldowns
68d ago
C2 Frameworks - Threat Hunting in Action with YARA Rules
68d ago
Ransomware tabletop
68d ago
Tracking APT28 PixyNetLoader: Evolutions from 2024 to 2026
68d ago
Tracking North Korea Nation-State APT Infrastructure: Kimsuky
68d ago
새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석 - Analysis of Endpoint (Midnight) Ransomware: The Encrypted Guest That Arrived at Dawn
68d ago
From Token Bingo to MAX Takeover: Kali365 Operator Expands Operation Across Microsoft Outlook, Okta, Xerox DocuShare, and Other Services
68d ago
Codex Discovered a Hidden HTTP/2 Bomb
68d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
68d ago
Unpatched NTLM Coercion in Windows search: URI Handler, Same Bug, No CVE, No Fix
68d ago
“Fellow practitioners — made some infosec merch that actually speaks our language. What security concepts would you want on a shirt?”
68d ago
Iran is using Western AI services to help with phishing, malware support and military research while building a domestic platform at Sharif
68d ago
Malicious Registrations in the Domain Name Market: An Analysis of gTLD Registrations and Cybercriminal Demand
68d ago
Gamaredon’s gifts that keeps unpacking - GammaPhish and GammaWorm
68d ago
RedSun: Exploiting Windows Defender's Remediation Workflow for Local Privilege Escalation
69d ago
Mini Shai-Hulud Campaign Hits Red Hat Cloud Services npm Packages
69d ago
Cybersecurity (CYBER); Cyber Resilience Act (CRA); Cybersecurity requirements for routers, modems intended for the connection to the internet and switches
69d ago
Miasma: Supply Chain Attack Targeting RedHat npm Packages
69d ago
@redhat-cloud-services npm scope backdoored with valid signed SLSA provenance; recovered the GitHub commit-search dead-drop C2 markers
69d ago
Instagram Meta AI Vulnerability Allegedly Enables Password Reset for Accounts via prompt injection with bot - now patched
69d ago
Tracking The Trackers: Commercial Surveillance Occurring on U.S. Army Networks
69d ago
Meta AI Recovery Flow Reportedly Bypassed 2FA: A Lesson in Privilege Boundaries
69d ago
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign
69d ago
Atomdrift - open-source malware detection for the software supply chain
70d ago
Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens
70d ago
179 npm Packages Target Cloud and Finance via oob.moika.tech
70d ago
KB4853: Vulnerability Resolved in Veeam Service Provider Console 9.2.1 - "A vulnerability in Veeam Service Provider Console allows for remote code execution." - CVSS 9.4
70d ago
Click Or Trick (CVE-2025-59199): Escaping the Sandbox with Windows URIs
70d ago
Hawk: Golang tool designed to exfiltrate passwords found via the sshd and su services
70d ago
EvilTokens and OAuth Abuse: How Device Code Phishing Bypasses MFA
70d ago
Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace
70d ago
Signal macOS Desktop App Doesn't Actually Delete Messages When it Should
70d ago
Operation XENOFISCAL: SideCopy deploying persistent XenoRAT targeting the MoF, Afghanistan
70d ago
WHQL-signed kernel driver keylogger, likely deployed as an anti-cheat BYOVD
70d ago
Typosquatted npm packages used to steal cloud and CI/CD secrets
70d ago
Operation Dragon Weave : Uncovering a China-Linked Campaign Targeting Czech Republic and Taiwan Using Azure Cloud C2
70d ago
Malicious npm packages abuse dependency confusion to profile developer environments
70d ago
Observed Exploitation of PAN-OS GlobalProtect Authentication Bypass Vulnerability (CVE-2026-0257)
70d ago
Meet DriveSurge: A New Threat Actor Using ClickFix and Fake Update Drive-By Attack
70d ago
CVE-2026-0257 PAN-OS: GlobalProtect Authentication Bypass Vulnerabilities - "Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied."
70d ago
Dissecting an Undocumented Lua-Wrapped Loader: The BoldTealLayer Campaign
70d ago
SkillSpector: Security scanner for AI agent skills. Detect vulnerabilities, malicious patterns, and security risks.
70d ago
EDR Incident Response Playbook: Containing Local Account Incidents
70d ago
Adversarial Oracles: LLM-Guided EDR Signature Reduction
70d ago
One click—and you’re spied on: GFF files criminal complaint alongside journalist Trung Khoa Lê following spyware attack - GFF
70d ago
proxy: A lightweight caching proxy for package registries.
70d ago
How OLTs may have exposed entire ISP networks
70d ago
A miner with a side of RAT: the unintended gift with your TV show or book - Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years
70d ago
HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics
70d ago
Honeyval: A Comprehensive Evaluation Framework for LLM-powered HTTP Honeypots
70d ago
Security of OpenClaw Agents: Fundamentals, Attacks, and Countermeasures
70d ago
Lessons from Penetration Tests on Large-Scale Agent Systems
70d ago
pydepgate: A zero dependency lightweight static analyzer designed for adversarial-shape code in python to detect supply chain attacks before they reach your interpreter.
70d ago
CIFSwitch: a non-universal Linux local root vulnerability
71d ago
Web-Based Indirect Prompt Injection To Push A Malicious Chrome Extension
71d ago
DriverSentinel: DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them against the LOLDrivers.io database.
71d ago
Visual Studio Extensions Revisited
71d ago
Supply Chain Compromises Impact Nx Console and GitHub Repositories
71d ago
BYOVD and Looting LSASS in the Modern EDR Era
71d ago
CTO at NCSC Summary: week ending May 31st
71d ago
OffensiveCon26 videos
71d ago
School Survey, (non-paid nothing its free its for my grades)
72d ago
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
72d ago
LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms
72d ago
LogMonitor — open-source Python tool for real-time failed login detection with multi-channel alerting
72d ago
Identifying attack patterns through kernel frame callstacks
72d ago
Evaluation taxonomy for cyber threat intelligence (CTI) quality and conversion quality in workflows such as MISP/STIX exchange and CTI Transmute, covering relevance, accuracy, timeliness, clarity, specificity, format validity, conversion fidelity, and usefulness
72d ago
What safety boundary would you expect from a local AI incident investigation tool?
72d ago
Authenticated RCE via Argument Injection in Gogs (NOT FIXED)
72d ago
Why I Built My Own LLM Benchmark for THOR Finding Triage
72d ago
Casdoor contains multiple authentication bypass and access management vulnerabilities
72d ago
The approval prompt is lying: a critical coding agent security flaw - A symlink-hijack RCE in six AI coding agents
72d ago
GREYVIBE: A Russia-nexus group leveraging AI across state-aligned operations
72d ago
Inside a 176-Package npm Campaign Built to Beat Your Internal Dependencies
72d ago
Malware seller hunted across three continents
72d ago
Romanian National Sentenced for Selling Access to Networks of Oregon State Government Office and Other U.S. Victims
72d ago
Law firm Wiley Rein hit with class action over data breach tied to Chinese hackers
72d ago
Gezamenlijke actie politie en NCSC legt groot botnetwerk plat | Joint police and NCSC NL operation shuts down large bot network
72d ago
Introducing Puck Scout: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet in plain English; get a narrative answer with containment recommendations.
72d ago
The C-suite job that's burning people out faster than any other
73d ago
New OSINTDomain Update: Domain OSINT Analysis with AI Agent Interpretation
73d ago
SEO poisoning campaign leverages Gemini and Claude Code impersonation to deliver infostealer
73d ago
Frieren: an open-source framework for WiFi Pineapple-style OpenWrt security appliances
73d ago
2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
73d ago
APT Activity Report: CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS - October 2025-March 2026
73d ago
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry's Software Development Infrastructure
73d ago
Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
73d ago
Zero Trust Implementation Guidelines
73d ago
BlackToad: Network Manipulation in an AutoIt Payload
73d ago
RVTools Masquerade: How a Signed Fake Installer Deploys a Modular Python RAT
73d ago
Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant
73d ago
Device Code Lab (DCL) — Deep Dive into a Device Code Phishing Toolkit
73d ago
FROST: Fingerprinting Remotely using OPFS-based SSD Timing
73d ago
Alert Number: I-052726-PSA | 27 May 2026 Threat Actors Spoofing FIFA Websites in Advance of the 2026 World Cup
73d ago
puck-security/puck-oss: Autonomous, read-only endpoint investigation via MCP. Ask a question about your fleet, get a narrative answer with containment recommendations.
74d ago
Who is Salt Typhoon Really? Unraveling the Attribution Challenge
74d ago
Looking for resources on end-to-end APT attack flow summaries for detection engineering
74d ago
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
74d ago
durabletask (Microsoft's Python Durable Task client) compromised by TeamPCP
74d ago
Exposing a Smishing campaign across 19 countries: 1,628 malicious URLs tied to a single 128-char HTML fingerprint
74d ago
Building Detection Engineering on AWS from scratch — roast my plan
74d ago
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
74d ago
Designing secure access with ZTNA
74d ago
MSIT Launches Early “Incident Investigation Review Committee” for Proactive Security Incident Response
74d ago
White House: Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats
74d ago
Advisory X41-2026-002: Request Host Header not Validated in Starlette
74d ago
Top ethical hacker Chompie warns AI tools could put her out of business
74d ago
浅谈AI Agent的行为检测思路 -A Brief Discussion on Behavior Detection Approaches for AI Agents
74d ago
YoroTrooper组织针对独联体及周边区域的攻击活动分析 - Analysis of YoroTrooper's Attacks Against the CIS and Surrounding Regions
74d ago
CERT-IN: Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure - patch between 12 hours and 5 days they state
74d ago
The Evolution of Chinese-language Phishing Services
74d ago
Silent Ransom Group Impersonating IT Personnel through Social Engineering
74d ago
The epoll UAF - an epoll uaf race in fs/eventpoll.c
74d ago
Tycoon 2FA AiTM detection for Entra ID and Google
74d ago
Microsoft Copilot Cowork Exfiltrates Files
74d ago
Unpatched Sparx vulnerabilties
75d ago
sylvia: iOS Syscall Explorer for IDA 9.X
75d ago
Ababil of Minab: An Iran-Linked Destruction and Exfiltration Campaign Targeting the U.S. and the Middle East
75d ago
GHSL-2026-140: Heap Buffer Write Overflow in 7-Zip
75d ago
JOMANGY: INJ3CTOR3's Self-Healing FreePBX Toll Fraud Campaign
75d ago
7-Zip CVE-2026-48095: NTFS Heap Overflow Leads to Vtable Hijack
75d ago
Seeing alot of SSH honeypot attacks on "root:fjbdfdjkdsfs541544AA@@"
75d ago
The practice of cyber-threat intelligence in organizations: A socio-technical case study of a mature financial organization
75d ago
GitHub - mrexodia/ida-pro-mcp: AI-powered reverse engineering assistant that bridges IDA Pro with language models through MCP.
76d ago
Exploitation of KnowledgeDeliver via ViewState Deserialization Vulnerability
76d ago
CVE-2026-20700: A controlled exploration of dyld's page-in linking and chained fixup machinery as a PAC signing oracle, in the context of CVE-2026-20700.
76d ago
YouTube SMS Blaster Ad Displays Scam Messages That Impersonate Telcos
76d ago
Open sourced the part of our SOC tool that can nuke your endpoints, so you can read it before trusting it
76d ago
honeyslop: Code canaries to quickly triage hallucinated ('slop') vulnerability reports
76d ago
Apex One and Vision One – Standard Endpoint Protection (SEP) May 2026 Security Bulletin - TrendAI has observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild.
76d ago
Putin appoints Rostec cybersecurity specialist linked to GRU hackers from Fancy Bear as aide to Sergei Shoigu in Russia’s Security Council
76d ago
RemotePE: The Lazarus RAT that lives in memory
76d ago
Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer
76d ago
Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
76d ago
Twee mannen aangehouden voor phishing - Two men arrested for phishing
76d ago
Sharp Eyes: Mass surveillance of foreigners in China
76d ago
relay_bible: Technical Reference to multiple relay techniques
76d ago
Fix: CVE-2025-33073 NTLM reflection not exploitable on pre-NT10.0 systems by azoxlpf · Pull Request #1245 · Pennyw0rth/NetExec
76d ago
The Gold Mine Red Teamers Never Touch - "read the Windows source code. Both Windows XP and Server 2003." [to make their tools blend in]
76d ago
SYLK 文件格式的武器化滥用 – Weaponization and abuse of the SYLK file format
76d ago
North Korean cyber hackers and masterminds behind gambling sites... Sentenced to 5 years in prison in the first trial
76d ago
Staged publishing and new install-time controls for npm - GitHub Changelog
77d ago
Updated UAC-0057 toolkit: OYSTERFRESH, OYSTERSHUCK and OYSTERBLUES
77d ago
Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud
77d ago
Introducing RAMPART and Clarity: Open source tools to bring safety into Agent development workflow
77d ago
The Future and Past of Residential Proxies
77d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
77d ago
Machine Overmatch: What Salt Typhoon Reveals About China’s Data-Centric Intelligence Strategy
77d ago
Disrupting Fox Tempest: A cybercrime service that turned “verified” software into a pathway for ransomware
77d ago
A fraudulent scheme to obtain and use code signing certificates to deceive victims into downloading dangerous malware under the false belief that it is trusted software
77d ago
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
77d ago
Suricata 8.0.5 and 7.0.16 released! - fixed various critical and high severity vulnerabilities
77d ago
Phantom Killer: Reverse Engineering and Weaponizing a Lenovo Driver to Terminate EDR Processes
77d ago
mkPIVM: Generate polymorphic, position-independent virtual machines (PIVMs) from arbitrary x86/x64 shellcode.
77d ago
keyhog: The fastest, most accurate secret scanner. 896 detectors, Hyperscan SIMD, GPU acceleration, 96% recall. Built in Rust.
77d ago
np-audit: Static security analysis for npm packages. Detects obfuscated code, malicious patterns, and known vulnerabilities before installation.
77d ago
Ledger: An aggressor script that tracks operational changes made during a red team engagement. Gives you a full audit trail of what was changed and what still needs to be cleaned up.
77d ago
OpenPetya: A Proof-of-Concept bootkit inspired by Petya ransomware, written in Assembly, C, and C++
77d ago
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
77d ago
FatGid - FreeBSD 14.x kernel LPE
77d ago
Manage [VSCode] extensions in enterprise environments
77d ago
angr: A powerful and user-friendly binary analysis platform!
77d ago
Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware
77d ago
How Attackers Force Microsoft to Send Phishing Emails
77d ago
Malicious Postinstall Hook Found Across 700+ GitHub Repositories, Including Packagist and Node.js Projects
77d ago
Microsoft Authenticator App Details now exposed in Entra SignInLogs
77d ago
Bissa Scanner Exposed: AI-Assisted Mass Exploitation and Credential Harvesting
77d ago
How China-linked threat actors obtain zero-day vulnerabilities
77d ago
Fast and Furious - Nimbus Manticore Operations During the Iranian Conflict - Check Point Research
77d ago
Monitoring for vssadmin.exe delete shadows is an absolute bare minimum
77d ago
Infostealers Just Spawned a 5,000+ Repo GitHub Supply Chain Attack
77d ago
How a consultant and a concert pianist from the Netherlands aided pro-Russian hackers
77d ago
CVE-2026-48029: Two grid-decode bugs in libheif
77d ago
workcell: Bounded local runtime and policy boundary for coding agents
77d ago
OpenShell: OpenShell is the safe, private runtime for autonomous AI agents.
77d ago
Model Context Protocol (MCP): Security Design Considerations for AI-Driven Automation
77d ago
Built a SOC from scratch with no prior SOC experience
77d ago
CTO at NCSC Summary: week ending May 24th
78d ago
VPN Exploitation When Patched Doesn't Mean Protected
78d ago
Cybercriminal VPN used by ransomware actors dismantled in global crackdown – VPN service featured in almost every major Europol-supported cybercrime investigation
78d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
78d ago
CLR-Stomp: .NET CLR-Stomping
78d ago
From edge appliance to enterprise compromise: Multi-stage Linux intrusion via F5 and Confluence
78d ago
Introducing Showboat: A new malware family taunts defenses and targets international telecom firms
78d ago
Open Directory, Open Season: Inside Red Lamassu’s JFMBackdoor
78d ago
AI security CTF from a CNCF project - useful for understanding LLM/agent attack patterns from the defense side (June 17-22)
79d ago
GitHub - perplexityai/bumblebee: Read-only inventory collector for package, extension, and developer-tool metadata on macOS and Linux developer endpoints, built for fast supply-chain exposure checks.
79d ago
Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
79d ago
Tired of searching different websites, blogs, Reddit posts, and docs just to learn KQL?
79d ago
I got tired of guessing which LOLBAS binaries exist on a host at my privilege level, so I wrote a small Go scanner
79d ago
AI-generated reporting: Lessons learned from Cisco Talos Incident Response
79d ago
CrabLoader: A PoC Cobalt Strike UDRL written in Rust
79d ago
The 429 Microsoft Graph Mystery
79d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
79d ago
Azure Tenant Enumeration is Dead
79d ago
A Deep Dive into Codex Windows Sandbox
79d ago
Striga: Lifting x86 to LLVM IR with Python
79d ago
veilgate: Asymmetric defense against AI red-team agents. VeilGate scores every request, diverts likely agents into a per-IP-coherent fake application, and measures the cost it imposes on the attacker.
79d ago
Windows BitLocker Security Feature Bypass Vulnerability
79d ago
CVE-2026-28910: Breaking macOS App Sandbox Data Containers, TCC, and Hijacking Apps Using Archive Utility
79d ago
Google API keys keep working after you delete them long enough to be exploited
79d ago
Threat Intelligence Report: ZionSiphon OT Malware First Attempts? Psyops? Both?
79d ago
North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT
79d ago
Coruna Respawned: Compromised art-template npm Package Leads to iOS Browser Exploit Kit
79d ago
Quick heads-up if you're writing KQL for LSASS dumping (stop filtering on process names)
79d ago
Alert Number: I-052126-PSA | 21 May 2026 Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens
80d ago
Megalodon: CI/CD Malware Spreading Across GitHub Repositories
80d ago
📡 One telecom carrier accounts for 72% of all Middle East-hosted C2 activity.
80d ago
Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
80d ago
CVE-2026-40369: Twelve Bytes to Escape the Browser Sandbox
80d ago
beacon-hunter: open source detector for phi-structured C2 beacons that evade RITA
80d ago
Fake Microsoft Teams Campaign Delivers ValleyRAT via NSIS Installer and DLL Sideloading
80d ago
Tracking TamperedChef Clusters via Certificate and Code Reuse
80d ago
Living off the Land with VS Code: Inside a Sophisticated Phishing Campaign
80d ago
From Y2K to Patch Tuesday 2025: 25 Years of Bugs in the Windows 2000 Source Tree
80d ago
How a single image takes control of a Mac understanding an ExifTool vulnerability (CVE-2026-3102)
80d ago
Iran-linked Operators Suspected in ATG Breaches
80d ago
Grafana Labs security update: Latest on TanStack npm supply chain ransomware incident | Grafana Labs
80d ago
Compromised Nx Console version 18.95.0
80d ago
CVE-2026-46333: Local Root Privilege Escalation and Credential Disclosure in the Linux Kernel ptrace Path
80d ago
From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
80d ago
Webworm: New burrowing techniques
80d ago
New Age of Collisions: Reading Arbitrary Files Pre-Auth as root in cPanel (CVE-2026-29205)
80d ago
Operation Dragon Whistle: UNG0002 Targets Chinese Academia via Weaponized Institutional Lure
81d ago
Adaptive Fingerprinting: HTTP-Basma's Multi-Stage Probing for Granular Server Differentiation
81d ago
GitHub’s Fake Engagement Problem Is Hiding in Plain Sight
81d ago
Statecraft – Threat intel platform for Portuguese-speaking Blue Teams (NVD + CISA KEV + OTX + hourly AI briefings in PT-BR)
81d ago
Zer0Vuln Community Edition – open-source SIEM + SOAR + EDR with autonomous local LLM triage
81d ago
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
81d ago
5 credential access detection rules beyond LSASS — KQL + Sigma, production-ready
81d ago
Remote Process Read Primitive via NtCreateThreadEx Exit Code
81d ago
aimap: Discover Exposed AI Services
81d ago
FalkorDB: A super fast Graph Database uses GraphBLAS under the hood for its sparse adjacency matrix graph representation.
81d ago
Why China Is Now a Peer Competitor to the United States in Cyberspace
81d ago
nginx-rift-private-lab: Private Nginx Rift ASLR lab, exploit chain, and demo recordings
81d ago
Built a Linux persistence hunting & artifact collection tool in Bash - persisthunt
81d ago
We are investigating unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension.
81d ago
Extended Cyber Kill Chain for AI-Era Threats: a defender-side framework mapping LLM and agentic attacks to kill-chain stages (MITRE ATLAS + OWASP LLM Top 10 mappings)
81d ago
Fooling AI Agents: Web-Based Indirect Prompt Injection Observed in the Wild
81d ago
Eight Leading U.S. Communications Firms Form C2 ISAC
82d ago
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
82d ago
UAC-0184: From HTA to a Signed Network Stack
82d ago
New Actors Deploy Shai-Hulud Clones: TeamPCP Copycats Are Here
82d ago
How Storm-2949 turned a compromised identity into a cloud-wide breach
82d ago
Entra ID: PIM for Groups Review
82d ago
TeamPCP compromises NPM maintainer with over 540 packages
82d ago
Active Supply Chain Attack Compromises @antv Packages on npm...
82d ago
When DMCA Comes Knocking - A YouTube Creator Phishing Kit
82d ago
[Cloudflare] Project Glasswing: what Mythos showed us
82d ago
SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
83d ago
Rekomendacja Pełnomocnika Rządu ds. Cyberbezpieczeństwa dotycząca komunikatora Signal - Recommendation of the Government Plenipotentiary for Cybersecurity regarding the Signal messenger
83d ago
Exclusive: Hackers have breached tank readers at US gas stations; officials suspect Iran is responsible | CNN Politics
83d ago
CrystalX: unpacking a Go RAT through three encrypted layers
83d ago
DirtyCBC: When Linux Kernel Decrypt-Before-MAC Turns Authenticated Encryption Into a Page-Cache Write
84d ago
FlowerStorm unleashes the KrakVM: PhaaS operators turn to VM-based obfuscation
84d ago
LID: LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footprint. "Linux is Dying"
84d ago
Static Kitten APT Adversary Simulation
84d ago
Eimeria: five layers from RAR5 to RunPE
84d ago
ghosttype: Local forensic scanner that extracts credentials from AI tool conversation history. For authorized red team and DLP use only.
84d ago
openDCIM exploitation
84d ago
HASBL CTF - A Jeopardy-Style CTF Organized by High School Students!
84d ago
We Have Packet Capture at Home
84d ago
Suspected China-Linked Threat Actor Targets Global Manufacturer with Undocumented TencShell Malware
84d ago
HWMonitor Trojanized for STX RAT DLL Sideloading
84d ago
awesome-dfir-skills: Admiralty System for CTI Claude skill
84d ago
Mullvad exit IPs as a fingerprinting vector
84d ago
Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
84d ago
Popular node-ipc npm Package Infected with Credential Steale...
84d ago
An Improper Access Control vulnerability [CWE-284] in FortiAuthenticator may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.
84d ago
Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
84d ago
Chinese APT Campaign Targets Entities with Updated FDMTP Backdoor
84d ago
Sandworm Activity in Industrial Environments: What the Data Reveals
84d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
84d ago
"Shadowserver-in-a-box" IntelMQ + ELK Solution
84d ago
Stenloader: Steganography Shellcode Loader
84d ago
AsmResolver: a library for reading, modifying and reconstructing Portable Executable (PE) files. It supports PE images running natively on Windows, as well as images containing managed (.NET) metadata - after 2 years of development, v6.0.0 is out
84d ago
Somebody backdoored the package `bfunky/http-parser` on packagist with a stealer - package not touched since 2018
84d ago
Our response to the TanStack npm supply chain attack
84d ago
QEMUtiny is a memory corruption vulnerability in QEMU's implementation of CXL Type-3 device emulation, reported against QEMU master 007b29752e and confirmed working against 5e61afe (May 11, 2026).
84d ago
We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase.
84d ago
APT-C-55(Kimsuky)组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析 - Analysis of APT-C-55 (Kimsuky) group's attack activities involving the distribution of malicious payloads via GitHub and Dropbox.
84d ago
oss-security - Logic bug in the Linux kernel's __ptrace_may_access() function - exploits out see yesterday
84d ago
Fast16: Pre-Stuxnet Sabotage Tool Was Built to Subvert Nuclear Weapons Simulations
84d ago
OtterCookie: JavaScript RAT shifting fake-interview campaigns from credential theft to live surveillance
85d ago
The Gentlemen Ransomware Group — Leak Analysis
85d ago
HDD Firmware Hacking Part 1
85d ago
ssh-keysign-pwn: Steal SSH host private keys and /etc/shadow via the ptrace_may_access mm-NULL bypass + pidfd_getfd. Pre-31e62c2ebbfd kernels.
85d ago
CTO at NCSC Summary: week ending May 17th
85d ago
Vidar v1.5 in Go: same family, new language, heavy sandbox checks
85d ago
Developer credential-theft campaign exposed operator-side self-infection
85d ago
Help-Desk Lures Drop KongTuke's Evolved ModeloRAT
85d ago
Welcome to BlackFile: Inside a Vishing Extortion Operation
85d ago
DoublePulsar: A User-Defined Reflective Loader in the Crystal Palace and Tradecraft Garden Era
85d ago
Stop Being Weird — Life After Call Stack Spoofing Under CET
85d ago
Triggering the Secure Boot Certificate Update with Intune Remediations
85d ago
How to enable HTTPS support for Microsoft Connected Cache for Enterprise and Education - Starting on June 16th, 2026, or soon after, Intune will enforce HTTPS content delivery for customers using Microsoft Connected Cache
85d ago
Addressing Exchange Server May 2026 vulnerability CVE-2026-42897
85d ago
One Is a Fluke, 3 Is a Pattern: MCP Back-End Vulnerabilities
85d ago
CVE-2026-20182: Critical authentication bypass in Cisco Catalyst SD-WAN Controller (FIXED)
85d ago
Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
85d ago
FamousSparrow APT Targets Azerbaijani Oil and Gas Industry
85d ago
Disclosing new PebbleDash-based tools by Kimsuky
85d ago
FrostyNeighbor: Fresh mischief and digital shenanigans
85d ago
Kazuar: Anatomy of a nation-state botnet
85d ago
OrBit (Re)turns: Tracking an open-source Linux rootkit across four years of forks and deployments
85d ago
NATS-as-C2: Inside a new technique attackers are using to harvest cloud credentials and AI API keys
85d ago
Hacker Ringleader Extradited for 38 Billion Won Theft
85d ago
Alert Number: I-051526-PSA | 15 May 2026 ShinyHunters: Cyber Criminal Group Attacks Learning Management System
85d ago
Fragnesia (CVE-2026-46300) is a universal Linux local privilege escalation exploit
85d ago
The Mythos We Have At Home: A Patch-Diffing Pipeline for N-Day Generation
85d ago
FFFFirefox - A One-Day Wonder Renderer Exploit
85d ago
MiniPlasma, a powerful LPE
85d ago
Does host MS Defender Network Protection intercept and alert on traffic generated inside Windows Sandbox?
86d ago
[Tool] IOCX — deterministic static IOC extraction for PE binaries
86d ago
Novel Evilginx Frontend - Lowering the barrier for token theft reuse
86d ago
SentinelOne. Backup delete attempt at 06:28, Kill process mitigation action at 06:31. Was the deletion blocked or not?
86d ago
WAF Evasion Engine
87d ago
Thus Spoke…The Gentlemen
87d ago
KQLab - open-source query manager for SOC teams
87d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown
87d ago
Microsoft AntiSSRF
87d ago
Detecting Exploitation of CrushFTP Vulnerability (CVE-2025-31161) With PacketSmith Yara Detection Module - Using track_state and flow_state
87d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
87d ago
How fast is autonomous AI cyber capability advancing?
87d ago
YellowKey: YellowKey Bitlocker Bypass Vulnerability
87d ago
Tinker Tailor Soldier: Paper Werewolf’s latest toolkit
88d ago
126 Chrome extensions, all secretly the same product, taking 148K users' WhatsApp data and ad cookies
88d ago
Gamaredon's infection chain: Spoofed emails, GammaDrop and GammaLoad
88d ago
Undermining the trust boundary: Investigating a stealthy intrusion through third-party compromise
88d ago
[HOMELAB] Built a SOC investigation console on two old Dell boxes
88d ago
Android Intrusion Logging as a new source of data for consensual forensic analysis
88d ago
Shai-Hulud: Another Wave and Going Open Source
88d ago
A stealth approach to Process Injection - EntryPoint Hijacking
88d ago
[Tool Release] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
88d ago
Service Principal Sign-Ins: A blind spot that a lot are missing
88d ago
My Analysis of a Bandook RAT PCAP
88d ago
Seedworm: Iran-Linked Hackers Breached Korean Electronics Maker in Global Spying Campaign
88d ago
Detection Rule is here
89d ago
Owning a service principal equals owning its permissions.
89d ago
Claude Code RCE: Exploiting Deeplink Handlers via Settings Injection
89d ago
CPU OP Cache Corruption - AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.
89d ago
AI+DFIR Challenge: Share Your Disasters and Successes
89d ago
Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
89d ago
Postmortem: TanStack npm supply-chain compromise
89d ago
bits from the release team - Aided by the efforts of the Reproducible Builds project, we've decided it's time to say that Debian must ship reproducible packages
89d ago
rxrpc_privesc: RxRPC privesc PoC without fcrypt() restrictions
89d ago
Detecting Remote Thread Creation with Windows Driver
89d ago
Mythos finds a curl vulnerability
89d ago
Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - some leaps pending technical details
89d ago
Reverse Engineering a Multi Stage File Format Steganography Chain of the TeamPCP Telnyx Campaign
89d ago
Threat Actor Mr_Rot13 Actively Exploits CVE-2026-41940 for Backdoor Deployment
89d ago
esp32-c5-deauth: A deauth with nuker for 2.4Ghz and 5Ghz controlled by BLE with Android app
89d ago
LOLRMM Publishers - PR merges 182 new code signing certificates and adds important safety warnings to entries containing certificates from major software vendors.
89d ago
How Cloudflare responded to the “Copy Fail” Linux vulnerability
89d ago
I analyzed 196k+ Sysmon events and found APT29 staging malware in Temp. Here is my detection logic.
89d ago
LUKSbox: Store sensitive files in the cloud, or on shared media without trusting the host. LUKSbox is a Rust-based encrypted-container tool with passphrase, FIDO2 (YubiKey, Titan, Nitrokey, Windows Hello), TPM 2.0, and hybrid post-quantum (ML-KEM-768 / 1024) keyslots.
89d ago
New Shai-Hulud npm worm variant
90d ago
EtwWatcher
90d ago
Donuts and Beagles: Fake Claude site spreads backdoor
90d ago
Fine of nearly £1m issued against South Staffordshire Plc and South Staffordshire Water Plc following major cyber attack and data breach
90d ago
CHERIoT-Ibex: Closing the door on memory safety vulnerabilities with hardware-enforced protection
90d ago
Deterministic PE Validation for Blue Teams - IOCX v0.7.3
90d ago
Delving deep into threat detection: My logic for abnormal EventID 7 activity
90d ago
NZ announces sanctions on malicious Russian cyber actors, online platforms
90d ago
Update: Ongoing Checkmarx Supply Chain Security Incident
90d ago
ShinyHunters cashout fingerprint; on-chain trace of the May 2024 AT&T ransom payment, with persistent laundering-service hubs identified through 2025
91d ago
Unmanaged PowerShell Execution: Hunting Beyond powershell.exe
91d ago
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign
91d ago
Static Devirtualization of Themida
91d ago
Now You See Me: AADGraphActivityLogs
91d ago
[Write-up] CyberDefenders: Wiredive Lab
91d ago
page_inject: CVE-2026-31431-killed page-cache exploit — code exec into containers sharing the same image layer
91d ago
JDownloader — Website installer incident (May 2026)
91d ago
The GNU MP Bignum Library - "We suspect that GMP's extremely tight loops around MULX make the Zen 5 cores use much more power than specified, making cooling solutions inadequate."
91d ago
AI in the Breach: How an Adversary Leveraged AI to Target a Water Utility’s OT
91d ago
EventHawk v1.2 -open source Windows EVTX log analysis tool for DFIR (Juggernaut Mode, ATT&CK mapping, Sentinel anomaly engine)
91d ago
Jenkins honeypot reveals botnet exploiting scriptText to launch DDoS attacks on game servers
92d ago
Writing a Naive LLVM-based Devirtualizer
92d ago
Where Have All the Complex Windows Malware and Their Analyses Gone?
92d ago
When prompts become shells: RCE vulnerabilities in AI agent frameworks
92d ago
Shift-Happens-Uncovering-to-builtin-command-injection-in-Windows-context-menus: Shift Happens: Uncovering two built-in command injections in Windows context menus
92d ago
MOVEit Automation Critical Security Alert Bulletin – April 2026 – (CVE-2026-4670, CVE-2026-5174)
92d ago
Lorem Ipsum Malware: Trojanized MS Teams Installers Deliver Multi-Stage Loader and Backdoor
92d ago
Let's Encrypt Status: Due to an issue with the cross-signed certificate from our Generation X root to our new Generation Y root, all issuance has been switched back to our Generation X root certificate. This affects our "tlsserver" and "shortlived" ACME certificate profiles.
92d ago
Analyse des DNS-Ausfalls vom 5. Mai 2026 - Analysis of the DNS outage of May 5, 2026
92d ago
Member of Prolific Russian Ransomware Group Sentenced to Prison
92d ago
EasterBunny: advanced espionage artifacts attributed to APT29
92d ago
Tracking the "Sorry" Extortionist Campaign Against cPanel Websites
92d ago
PositiveIntent: Evasive loader for .NET Framework assemblies
92d ago
The Accidental C2: Exploring Dev Tunnels for Remote Access
92d ago
Living of the Land - DISM Sandbox Provider Hijack
92d ago
HyperVenom: Using Hyper-V for Ring -1 Control from Usermode
92d ago
CTO at NCSC Summary: week ending May 10th
92d ago
ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure
92d ago
PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale
92d ago
Copy_Fail2-Electric_Boogaloo: Copy Fail 2: Electric Boogaloo
92d ago
DARWIS Taka - Web vulnerability scanner with Optional AI Validation
92d ago
SunnyDayBPF: eBPF telemetry integrity research for detection engineering
93d ago
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama
93d ago
Massive Cyber Attack Exposes Millions 🚨 || starting my cybersecurity jou...
93d ago
Student Arrested in Taiwan for using SDR and Handheld Radios to Halt Four High Speed Trains with TETRA Hack
93d ago
Dirty Frag: Universal Linux LPE
93d ago
Ivanti: We are aware of a very limited number of customers exploited with CVE-2026-6973. Successful exploitation requires Admin authentication.
93d ago
Two U.S. Nationals Sentenced for Facilitating Fraudulent Remote Information Technology Worker Schemes to Generate Revenue for the Democratic People’s Republic of Korea
93d ago
Revealed: Russia’s top secret spy school teaching hacking and election meddling | Russia
94d ago
OceanLotus suspected of distributing ZiChatBot malware via wheel packages in PyPI
94d ago
Searching for bulletproof detections in cPanel Land: Hunting for CVE-2026-41940: Building Detections for the exploit, not the PoC
94d ago
Detecting BEC Persistence with KQL
94d ago
Unpacking Russian-Iranian Private-Sector Cyber Connections
94d ago
Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
95d ago
OSS2Falco: Falco rules converted from LinPEAS, Sigma and Splunk
95d ago
Inadvertent Injections
95d ago
CVE-2026-0300 PAN-OS: Unauthenticated user initiated Buffer Overflow Vulnerability in User-ID™ Authentication Portal
95d ago
Muddying the Tracks: The State-Sponsored Shadow Behind Chaos Ransomware
95d ago
Iranian-Nexus Operation Against Oman's Government: 12 Ministries Hit and 26,000 Citizen Records Exposed
95d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
95d ago
UAT-8302 and its box full of malware
95d ago
CVE-2026-0073 Android adbd TLS client-authentication bypass
95d ago
One KQL query you should have saved in your toolkit (most don’t)
95d ago
CVE-2026-31431 hit KEV after 9 days, what are you using to catch that earlier?
96d ago
Built a Cowboy Bebop-themed threat hunting lab with Splunk and Sysmon — writeup inside
96d ago
🇮🇷 Iranian-Nexus Campaign Against Oman's Government: 12 Ministries, 26,000 Records
96d ago
Popular DAEMON Tools software compromised
96d ago
A rigged game: ScarCruft compromises gaming platform in a supply-chain attack
96d ago
Breaking the code: Multi-stage ‘code of conduct’ phishing campaign leads to AiTM token compromise
96d ago
Quasar Linux (QLNX) – A Silent Foothold in the Supply Chain: Inside a Full-Featured Linux RAT With Rootkit, PAM Backdoor, Credential Harvesting Capabilities
96d ago
Accelerating Vulnerability Detection and Response at Oracle
96d ago
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
96d ago
GIDR: A behavioral intrusion detection system for Windows. Files are innocent until proven guilty at runtime. When malicious behavior is detected, the entire attack chain is traced to root and eliminated.
97d ago
dMSA Ouroboros: Self-Sustaining Credential Extraction in Windows Server 2025
97d ago
N-Day Research with AI: Using Ollama and n8n
97d ago
38 CVEs in Healthcare Software Used by 100,000 Medical Providers
97d ago
Recursively fuzzing MS-RPC structures and monitoring using ETW
97d ago
VanGuard — open-source single-binary DFIR toolkit (Velociraptor, Hayabusa, Chainsaw, Loki, YARA) with TUI, air-gap support, and 28 pre-built use cases
97d ago
CVE-2026-31431:我用 DeepSeek 复现了 AI 发现Copy Fail 提权的全过程 - CVE-2026-31431: I used DeepSeek to reproduce the entire process of AI detecting Copy Fail privilege escalation.
97d ago
《APT高级威胁研究报告》(2026 版)- Advanced Threat Research Report (2026 Edition)
97d ago
nginxpulse: 轻量级 Nginx 访问日志分析与可视化面板,提供实时统计、PV 过滤、IP 归属地与客户端解析。- A lightweight Nginx access log analysis and visualization dashboard, providing real-time statistics, PV filtering, IP geolocation, and client resolution.
97d ago
蔓灵花组织使用NUITKA打包的python样本进行投递 - The Manlinghua organization used Python samples packaged in NUITKA for delivery.
97d ago
gdrv3.sys - Reverse Engineering a Signed Kernel Driver with 13 Hardware Access Primitives
97d ago
Added new vulnerable samples for IoBitUnlocker, Zemana and TfSysMon
97d ago
AMSI Page Guard Bypass (Rust PoC)
97d ago
Meet Bluekit: The AI-Powered All-in-One Phishing Kit
97d ago
Malicious Ruby Gems and Go Modules Impersonate Developer Tools to Steal Secrets and Poison CI
97d ago
A hacker group was detained in Lviv Oblast, which hacked game accounts and received almost UAH 10 million in profit from their sale in Russia
97d ago
IRQL - Incident Response Query Language - A collection of Kusto (KQL) functions that unify security logs behind a consistent, analyst-friendly dialect
97d ago
Nuclei template CVE-2026-41940.yaml - cPanel & WHM - Authentication Bypass via Session-File CRLF Injection
97d ago
ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution…
97d ago
Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia
97d ago
[2603.28728] Study of Post Quantum status of Widely Used Protocols
97d ago
Malicious Intercom PHP Package Spreads Mini Shai-Hulud Attack to Packagist via Composer Plugin
97d ago
Possible supply chain attack on version 2.6.3 · Issue #21689 · Lightning-AI/pytorch-lightning
97d ago
code-needle: A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.
97d ago
Secure Boot Inventory Data In Configuration Manager
97d ago
EventLogExpert: Can be used as a replacement for Event Viewer to view live event logs. Choose Continuously Update on the View menu and watch new events appear in real time.
97d ago
MicroSMT: IDA plugin for automatic deobfuscation of opaque predicates by lifting microcode to z3 for SMT reasoning.
97d ago
AI-powered honeypots: Turning the tables on malicious AI agents
97d ago
copy.golf — golf your exploits - smaller copy.fail exploits..
98d ago
DragonBreath: Dragon in the Kernel
98d ago
Holy-Grail-PCAP: "Holy Grail PCAP" is a capture file offering exceptional coverage across nearly all tcpdump/Wireshark encapsulation types and dissectors.
98d ago
Impacket-IoCs: This repo contains the results of an internal re-write of impacket I undertook at my current company. It contains some of the IoCs found within the library
98d ago
Puzzle: Set of PoC to abuse Windows minifilters functionality
98d ago
A “Psychological Warfare” to Show Off Cyber Capabilities: A Comprehensive Analysis of SentinelOne’s Exposure of fast16
98d ago
Active exploitation of cPanel/WHM critical vulnerability
98d ago
Important Update From Trellix - "Trellix recently identified unauthorized access to a portion of our source code repository. "
98d ago
5 Qilin ransomware servers exposed over 7 months
98d ago
South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)
99d ago
Russian Charged in Oil and Gas Facility Hacks Pleads Guilty
99d ago
VECT ransomware: small files decrypt, large files lose their nonces
99d ago
CTO at NCSC Summary: week ending May 3rd
99d ago
April 27th - What happened with our feature flag configuration | The ClickUp Blog
99d ago
Blog: Evolving the Android & Chrome VRPs for the AI Era
99d ago
Seven Queries to Audit the Sentinel Detections Your SOC May Have Missed.
99d ago
VECT: Ransomware by design, Wiper by accident
99d ago
VisualSploit: Backdoor Visual Studio project files with custom shellcode, which executes whenever the project is opened or built.
99d ago
Two Americans Who Attacked Multiple U.S. Victims Using ALPHV BlackCat Ransomware Sentenced to Prison
99d ago
Agentic Malware Analysis: From Task Automation to Deep Analysis
99d ago
pydep-vector-runner: A lightweight runner that guards against weird startup behaviors in python. Lightweight version of PyDepGuard's coderunner.
99d ago
month-of-bypasses: Proof-of-Concepts for Detection Engineering Purposes Only
99d ago
603 loaded
MA
Malware Analysis & Reports
59d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
59d ago
ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper
60d ago
WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap
60d ago
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
61d ago
Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment
62d ago
73 Microsoft GitHub repositories impacted by Miasma malware
62d ago
Unauthorized Onlyfans Payment
63d ago
Building A Malware Lab From Scratch Part 2!
64d ago
Detecting npm Native Addon Malware: node-gyp Abuse
64d ago
Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links
65d ago
Extremely suspicious behaviour by memu emulator
66d ago
Malware
67d ago
🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop
67d ago
ChatGPT Malvertising Campaign
67d ago
Recommendation
67d ago
Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6!
67d ago
This is a scam and probably a malware/trojan. Path Of Exile 2 builder ...
68d ago
LLMShare: using shared chatbot pages to distribute malware
68d ago
How to Unpack FlawedAmmyy - Malware Unpacking Tutorial
70d ago
Building A Malware Lab From Scratch!
70d ago
I bought an old phone from 2018 and wanna destroy it with viruses for fun
71d ago
Malware escaped browser without downloading files, then escaped a virtual machine
72d ago
I’ve seen ppl get flamed online for ever thinking they’re hacked/being monitored but
72d ago
A Deeper Look at GLASSWORM's Solana Variant
73d ago
Got hit by an infostealer via Discord - Need advice on full removal - ASUS TUF A15
73d ago
Kali365 Activity Surges: Device Code Phishing Is Scaling Fast
74d ago
MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
74d ago
Deep structural file analysis with MITRE ATT&CK mapping, from the original ClamAV authors (clens.io)
74d ago
Not a security person... got hit by an undocumented macOS stealer campaign, reverse engineered it, and tried to take the whole operation down.
75d ago
How random program can cause most of antiviruses close himself without telling himself to close
75d ago
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
76d ago
Suspicious ass website asking to run a terminal command (MacOS)
76d ago
Harvard and 140 other legitimate websites compromised
79d ago
Browser session theft is quietly becoming more dangerous than password theft
79d ago
Megalodon Malware Compromised 5,500+ GitHub Repos Within 6 Hours
79d ago
How TeamPCP's Python Toolkit Survives a C2 Takedown: FIRESCALE, GitHub, and the Victim's Own Account
80d ago
Database of Malicious Browser Extensions
80d ago
I’ve got 99 problems, and IOCX isn’t one.
80d ago
Can't access anything
82d ago
New GMKtec M7 Ultra appears to be infected. Beware of the malware!
82d ago
vpn explained the simple version that actually makes sense
82d ago
Benchmarking LLMs for malware triage and static unpacking with Malcat
83d ago
Netmirror exposed - The Free Movie App That Was Robbing You Blind
83d ago
Malware learning
84d ago
Brovan: Binary user-mode emulator for x86_64
86d ago
Inspecting a DLL file trying to figure out if it really is malware
87d ago
npm supply chain compromise on a Next.js app — XMRig miner bundled into webpack output
87d ago
VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure
87d ago
I got a desktop notification, saying I had a security oversight. What's odd, is that the notification said Windows Security and it looked very believable...
88d ago
clens.io - new public threat & data intel service
88d ago
Granny’s Compromised Android Firmware
88d ago
[Tool] IOCX – deterministic IOC extraction engine (static‑only, PE‑aware, plugin‑extensible)
88d ago
OS scanner that checks repos for traces of the Shai Hulud worm
89d ago
Mini Shai-Hulud Supply-Chain Worm Compromises npm and PyPI Packages, Including TanStack, Mistral, Lightning, and Guardrails AI
89d ago
Steam spear phishing
89d ago
Fake linked in sponsored google search
89d ago
Mass npm Supply Chain Attack Hits TanStack, Mistral AI, and 170+ Packages
90d ago
New Shai-Hulud npm worm variant
90d ago
looking for "evil" Websites
90d ago
Deterministic PE Structural Validation in IOCX v0.7.3
90d ago
sl1nk link
90d ago
How to download a RAT for myself
91d ago
Wtf OPEN Ai
92d ago
JDownloader's official website delivered Python RAT
93d ago
An unknown malware threat. There is no such thing as a 100% detection.
94d ago
Most of the antivirus websites redirect to microsoft defender website. I can’t access their websites
95d ago
Getting this Trojans while open Cherax Loader: Malgent!MSR /Phonzy.A!ML
95d ago
Discord bot C2 infrastructure
95d ago
IOCX v0.7.1 — robustness update focused on malformed PEs, hostile strings, and static‑analysis hardening
96d ago
Panicking
96d ago
Supply chain attack: DAEMON Tools Lite now contains a backdoor.
96d ago
Built a PE Malware Analysis Pipeline to Learn Why Most Detection Tools Suck at Correlation
97d ago
VirusTotal has one flag for this sus site
98d ago
Anyone wanna learn the CEH or OSCP red teaming free
99d ago
Fake Tailscale site on Google Ads uses ClickFix to get you to execute malware yourself
100d ago
Minecraft Malware C2 Tracking
100d ago
Minirat malware deployed via NPM targeting macOS machines
102d ago
VECT Ransomware Is Actually a Wiper
102d ago
The Malware Factory: GLASSWORM Forensics in Open VSX
103d ago
Phishing-to-RMM Attacks: The Remote Access Blind Spot Businesses Can't Ignore
103d ago
[ Removed by Reddit ]
103d ago
Ikeja Electric Distribution Ransomware
103d ago
Recently updated a authentic minecraft mod launcher called Modrinth
103d ago
This appeared on scan today no downloads Vulnerabledriver:WinNT/Winring0
104d ago
Ransomware is getting uglier as cybercriminals fake leaks and skip encryption entirely
104d ago
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses
106d ago
Save time and use Zig to write your Malware POC
106d ago
Cracking CastleLoader’s Inno Setup Password
106d ago
I built a C2 framework that uses Discord and Telegram for communication
107d ago
fast16 | Mystery ShadowBrokers Reference Reveals High-Precision Software Sabotage 5 Years Before Stuxnet.
107d ago
Newly Deciphered Sabotage Malware May Have Targeted Iran’s Nuclear Program—and Predates Stuxnet
108d ago
PSA: awstore.cloud is a MALICIOUS fake Claude API provider - warn your fellow devs
108d ago
Budgiekit - gdi malware maker (for educational purporses only)
108d ago
19 confirmed repos tied to the same GitHub malware campaign
109d ago
IOCX v0.7.0 — deterministic heuristics + adversarial PE samples
110d ago
I built a kernel-level EDR and hit architectural walls I didn’t expect
171d ago
Update your detection rules: New remote access Trojan
172d ago
Criminals are using AI website builders to clone major brands
172d ago
Open-source Windows utility to recover files from prefix-based USB shortcut worms (Grenam/CPGE variants)
173d ago
PE Loader For Fileless Malware
174d ago
Numero Malware : A Stealthy Saboteur Targeting AI Tool Installers
174d ago
AWAKE - Android Wiki of Attacks, Knowledge & Exploits
174d ago
I built a Chrome extension that scans for malicious extensions (yes, I see the irony)
174d ago
Questions regarding malicious pdf's
176d ago
AV persistence bypass techniques
176d ago
Avalon Linux Bot Malware Analysis
177d ago
Leveling up in Windows malware research
178d ago
Emerging Ransomware: BQTLock and GREENBLOOD
179d ago
Malware Development POCs
180d ago
Suspicious code in Up-work linked repository.
180d ago
We hid backdoors in binaries — Opus 4.6 found 49% of them
180d ago
👨💻 North Korean Malware Analysis 🚨 ROKRAT KillChain 📡
181d ago
Analysis of Suspected Malware Linked to APT-Q-27 (GoldenEyeDog) Targeting Financial Institutions
181d ago
Malware analysis - Signed job search application deploys a Proxyware, ClipBanker and XMRig cryptominer
183d ago
Nyxara
185d ago
115 loaded
SM
Security | Microsoft Azure Blog | Microsoft Azure
68d ago · 6 items
Microsoft Build 2026: Building agentic apps with Microsoft Fabric and Microsoft Databases
68d ago
Microsoft Build 2026 highlights advancements in app development with Microsoft Fabric and Microsoft Databases, emphasizing a unified data and AI platform.
Azure IaaS: Defense in depth built on secure-by-design principles
97d ago
Explore how Azure IaaS uses defense in depth and secure-by-design principles to deliver layered, scalable cloud security across compute, network, and data.
Enforcing trust and transparency: Open-sourcing the Azure Integrated HSM
101d ago
Learn how Microsoft Azure Integrated HSM delivers hardware‑enforced key protection in the cloud, combining FIPS Level 3 assurances with transparency and open‑source collaboration.
Azure IaaS: Keep critical applications running with built-in resiliency at scale
130d ago
Learn how Azure IaaS helps organizations start from a resilient platform foundation with availability, continuity, and recovery capabilities.
Azure IaaS: Explore new resources for building a stronger, more efficient infrastructure
158d ago
Learn how Azure IaaS helps you modernize infrastructure, improve performance and resilience, optimize costs, and prepare for AI workloads. Read more.
Azure reliability, resiliency, and recoverability: Build continuity by design
173d ago
Learn how Azure reliability, resiliency, and recovery capabilities work together to improve cloud continuity. Read more.
ZU
ZDI: Upcoming Advisories
101d ago · 1 items
CC
CISA Cybersecurity Advisories
110d ago · 2 items
Defending Against China-Nexus Covert Networks of Compromised Devices
110d ago
Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure
125d ago
U.S. organizations should review the TTPs and IOCs in this advisory for indications of current or historical activity on their networks, and apply the
BA
Blog Articles - Identity Insights | Trulioo
115d ago · 13 items
Business Fraud at Network Scale: What the $3.5B Medicare Hospice Crisis Reveals About Know Your Business
115d ago
What is Customer Due Diligence (CDD)
139d ago
Why Legacy Identity Verification Can’t Stop AI-Enabled Fraud
142d ago
AML, KYC and Identity Verification in Australia
151d ago
When Fraud Becomes Background Noise: The Industrialization of Digital Deception
216d ago
The Efficiency Era of KYC: Reverification and Reusable Identity Take Center Stage
216d ago
The End of Static KYB: Business Identity in Constant Motion
216d ago
Know Your Agent: The Next Chapter in Digital Trust
216d ago
When Rules Move Faster Than Readiness: Regulatory Adaptability as a Competitive Advantage
216d ago
Digital Identity Trends 2026: AI Fraud, Compliance, and Orchestration
235d ago
The World’s Identity Platform
1286d ago
KYC: 3 Steps to Achieving Know Your Customer Compliance
1557d ago
AML Compliance Checklist: Best Practices for Anti-Money Laundering
1572d ago
13 loaded
II
InfoSec Insights
151d ago · 1 items
FP
Fraud Prevention Archives - Alloy Silverstein
157d ago · 10 items
AI in Tax Season: Risks, Scams, and How to Protect Your Data
157d ago
Tax Season Scams to Watch For This Year
164d ago
Beware of Misleading Tax Advice on Social Media
332d ago
Each year the IRS educates taxpayers on the most trending fraud schemes that could deceive individuals and businesses during tax season. In late 2024, The IRS took to warning the public against misleading “tips” or...
Scammers Up Their Game With AI
334d ago
Learn how to spot the threats and protect yourself from scammers using AI for phishing and deepfakes with smart security practices.
The Essential Guide to Safeguarding Your Online Passwords
411d ago
Protect your personal and business data with strong passwords, two-factor authentication, and smart cybersecurity practices.
Beware: Tax Season is Scam Season
522d ago
Tax season is also prime time for tax scams. To safeguard your personal information, consider these key points: Communication methods The IRS initiates contact primarily through mail, not email or phone calls. Be cautious of...
Stop Scams: Fraud Prevention Starts with Your Employees
536d ago
You can be as proactive and protective as possible when it comes to cyber security for your business, but there’s one vulnerability you cannot eliminate: human error. In fact, statistics estimate that as much as...
‘Tis the Season for Holiday Shopping Scams
608d ago
The holidays are typically the time of year for gifting presents to friends and family or donations to charity. Unfortunately, not-so-jolly fraudsters take advantage of this generosity. Protect yourself by watching for these common scams:.....
IRS Issues “Dirty Dozen” Fraud Warnings
793d ago
Each year, the IRS releases a “Dirty Dozen” series to highlight the most common fraud schemes taxpayers should be aware of.
IRS Identity Theft Season Begins Now
923d ago
Each year thieves try to steal billions in federal withholdings by stealing your identity. As the IRS focuses more attention on this quickly growing problem, now is the time of year to be extra vigilant....
HA
HackerSploit
487d ago · 15 items
How FIN6 Exfiltrates Files Over FTP
487d ago
Emulating FIN6 - Active Directory Enumeration Made EASY
538d ago
The SECRET to Embedding Metasploit Payloads in VBA Macros
543d ago
Offensive VBA 0x4 - Reverse Shell Macro with Powercat
552d ago
Offensive VBA 0x3 - Developing PowerShell Droppers
558d ago
Offensive VBA 0x2 - Program & Command Execution
562d ago
Offensive VBA 0x1 - Your First Macro
564d ago
Emulating FIN6 - Gaining Initial Access (Office Word Macro)
570d ago
FIN6 Adversary Emulation Plan (TTPs & Tooling)
573d ago
Developing An Adversary Emulation Plan
573d ago
Introduction To Advanced Persistent Threats (APTs)
578d ago
Introduction To Adversary Emulation
599d ago
Mastering Persistence: Using an Apache2 Rootkit for Stealth and Defense Evasion
608d ago
Planning Red Team Operations | Scope, ROE & Reporting
748d ago
Mapping APT TTPs With MITRE ATT&CK Navigator
752d ago
15 loaded
TH
Threatpost
1439d ago · 10 items
Student Loan Breach Exposes 2.5M Records
1439d ago
2.5 million people were affected, in a breach that could spell more trouble down the line.
Watering Hole Attacks Push ScanBox Keylogger
1440d ago
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firms
1441d ago
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
Ransomware Attacks are on the Rise
1444d ago
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
Cybercriminals Are Selling Access to Chinese Surveillance Cameras
1445d ago
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Twitter Whistleblower Complaint: The TL;DR Version
1446d ago
Twitter is blasted for security and privacy lapses by the company’s former head of security who alleges the social media giant’s actions amount to a national security risk.
Firewall Bug Under Active Attack Triggers CISA Warning
1447d ago
CISA is warning that Palo Alto Networks’ PAN-OS is under active attack and needs to be patched ASAP.
Fake Reservation Links Prey on Weary Travelers
1448d ago
Fake travel reservations are exacting more pain from the travel weary, already dealing with the misery of canceled flights and overbooked hotels.
iPhone Users Urged to Update to Patch 2 Zero-Days
1451d ago
Separate fixes to macOS and iOS patch respective flaws in the kernel and WebKit that can allow threat actors to take over devices and are under attack.
Google Patches Chrome’s Fifth Zero-Day of the Year
1452d ago
An insufficient validation input flaw, one of 11 patched in an update this week, could allow for arbitrary code execution and is under active attack.
No matching sources found.