Loading…

Whats The Hax?

Daily intelligence on threats, breaches, and defenders

What's New

Top 5 Across All Sources
  1. Getting a CVE Without Shipping Slop

    Technical Information Security Content & Discussion · 1d ago
  2. PrizeBuzz phishing network analysis

    Technical Information Security Content & Discussion · 1d ago
  3. 27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass

    Technical Information Security Content & Discussion · 1d ago
  4. Empty-ciphertext panic in aws-encryption-provider (CVD with AWS)

    Technical Information Security Content & Discussion · 2d ago
  5. SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon

    Technical Information Security Content & Discussion · 3d ago
Latest
Technical Information Security Content & DiscussionGetting a CVE Without Shipping SlopTechnical Information Security Content & DiscussionPrizeBuzz phishing network analysisTechnical Information Security Content & Discussion27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth BypassTechnical Information Security Content & DiscussionEmpty-ciphertext panic in aws-encryption-provider (CVD with AWS)Technical Information Security Content & DiscussionSearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration WeaponTechnical Information Security Content & DiscussionResearcher accidentally gained access to a threat actor-controlled phishing websiteTechnical Information Security Content & DiscussionPromptSnatcher: AdBlocker stealing Ai Chats - 90k installsTechnical Information Security Content & DiscussionMeshCentral: From XSS to RCETechnical Information Security Content & DiscussionGetting the PID from random numbers in PHPTechnical Information Security Content & DiscussionThe Axios npm compromise was visible in registry metadata before anyone ran npm installTechnical Information Security Content & DiscussionWhy Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr LabsTechnical Information Security Content & DiscussionFree Compromise Detection for GitHub Repos - Tracebit Community EditionTechnical Information Security Content & DiscussionMajor AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)Technical Information Security Content & DiscussionOld Passwords Die Hard: Abusing CREDHIST for offline credential recoveryTechnical Information Security Content & DiscussionMarking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr LabsTechnical Information Security Content & DiscussionDetecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rulescybersecurityAny solutions we can use?hacking: security in practiceDIY pwnagotchi-like device on esp32Reverse EngineeringReverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around itcybersecurityPossible targeted attackTechnical Information Security Content & DiscussionGetting a CVE Without Shipping SlopTechnical Information Security Content & DiscussionPrizeBuzz phishing network analysisTechnical Information Security Content & Discussion27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth BypassTechnical Information Security Content & DiscussionEmpty-ciphertext panic in aws-encryption-provider (CVD with AWS)Technical Information Security Content & DiscussionSearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration WeaponTechnical Information Security Content & DiscussionResearcher accidentally gained access to a threat actor-controlled phishing websiteTechnical Information Security Content & DiscussionPromptSnatcher: AdBlocker stealing Ai Chats - 90k installsTechnical Information Security Content & DiscussionMeshCentral: From XSS to RCETechnical Information Security Content & DiscussionGetting the PID from random numbers in PHPTechnical Information Security Content & DiscussionThe Axios npm compromise was visible in registry metadata before anyone ran npm installTechnical Information Security Content & DiscussionWhy Use App-Level Auth When Every Database Has Auth? (Splunk Enterprise CVE-2026-20253 Pre-Auth RCE) - watchTowr LabsTechnical Information Security Content & DiscussionFree Compromise Detection for GitHub Repos - Tracebit Community EditionTechnical Information Security Content & DiscussionMajor AI Clients Shipping With Broken OAuth Implementations (JUNE 2026 UPDATE)Technical Information Security Content & DiscussionOld Passwords Die Hard: Abusing CREDHIST for offline credential recoveryTechnical Information Security Content & DiscussionMarking Your Own Homework (Check Point Remote Access VPN IKEv1 Authentication Bypass CVE-2026-50751) - watchTowr LabsTechnical Information Security Content & DiscussionDetecting AI-specific threats in Claude Enterprise from the Compliance API: a prefilter + LLM-as-judge pipeline with Sigma rulescybersecurityAny solutions we can use?hacking: security in practiceDIY pwnagotchi-like device on esp32Reverse EngineeringReverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around itcybersecurityPossible targeted attack

By Source

Feeds organized so you can skim by site.

Density Sort
Getting a CVE Without Shipping Slop 1d ago PrizeBuzz phishing network analysis 1d ago 27 Years in the Dark: OpenBSD Fixes Ancient Remote Kernel Auth Bypass 1d ago Empty-ciphertext panic in aws-encryption-provider (CVD with AWS) 2d ago SearchLeak: How We Turned M365 Copilot Into a One-Click Data Exfiltration Weapon 3d ago Researcher accidentally gained access to a threat actor-controlled phishing website 4d ago PromptSnatcher: AdBlocker stealing Ai Chats - 90k installs 4d ago MeshCentral: From XSS to RCE 4d ago Getting the PID from random numbers in PHP 5d ago The Axios npm compromise was visible in registry metadata before anyone ran npm install 5d ago
242 loaded
CY
cybersecurity
6d ago · 1867 items
Any solutions we can use? 6d ago Possible targeted attack 6d ago RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline 6d ago Facebook messenger to text 6d ago Managing Solution Agents 6d ago Nottingham University data breach affects over 450,000 students 6d ago SWGs that support 3rd party external DNS resolver 6d ago Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers 6d ago Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG 7d ago Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch 7d ago
1867 loaded
HS
hacking: security in practice
6d ago · 241 items
DIY pwnagotchi-like device on esp32 6d ago Flipper Blackhat + Bjorn 6d ago Do you think AI is making hacking easier or harder 7d ago What can i do left? PSN 7d ago Proxmark5 campaign ending in less than 18 hours. 7d ago How to bypass speed queen coin slot for washer and dryer 7d ago Self-hosting stuff for when things get ugly 7d ago Malware Includes Taboo In Text To Prevent LLM Analysis 7d ago added Mac support for my corporate hacking game, demo on Steam 7d ago Catfished 7d ago
241 loaded
RE
Reverse Engineering
6d ago · 181 items
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it 6d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) 6d ago [Reverse-Engineering] Skeet CS:GO source code (Gamesense) 6d ago Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game 6d ago I built 99 adversarially malformed PE files to test tool robustness - here’s what happened 7d ago Drive Firmware Security - Phison S11 7d ago IDA 9.4 Beta | Hex-Rays Docs 7d ago Trane Tracer HVAC cybersecurity issues 8d ago 🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS) 8d ago I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS. 8d ago
181 loaded
US charges suspected Russian hacker with facilitating cyber campaign 6d ago Hawkish GOP lawmaker Don Bacon says he was hacked by Russia 7d ago Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025 7d ago GreatXML: GreatXML bitlocker bypass vulnerability 7d ago GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan 7d ago I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue 7d ago [Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion 7d ago GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default 7d ago Miasma-style supply chain attacks 7d ago On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet 7d ago
603 loaded
MA
Malware Analysis & Reports
7d ago · 115 items
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened 7d ago ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper 7d ago WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap 8d ago Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace 8d ago Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment 9d ago 73 Microsoft GitHub repositories impacted by Miasma malware 10d ago Unauthorized Onlyfans Payment 10d ago Building A Malware Lab From Scratch Part 2! 12d ago Detecting npm Native Addon Malware: node-gyp Abuse 12d ago Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links 13d ago
115 loaded

No matching sources found.