Security intelligence
Community
Security community
Follow community discussions from netsec, blue team, cybersecurity, reverse engineering, hacking, and malware research communities.
Serbia Allegedly Hits 14 Activists With Pegasus Spyware
Technical Information Security Content & Discussion · 2d ago ↗sources
Any solutions we can use?
DIY pwnagotchi-like device on esp32hacking: security in practice · Community
↗
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around itReverse Engineering · Community
↗
US charges suspected Russian hacker with facilitating cyber campaignFor [Blue|Purple] Teams in Cyber Defence · Community
↗
Complete index
Source grid
Every loaded article, grouped by its original feed. Search scans source names and headlines.
Density
Sort
Serbia Allegedly Hits 14 Activists With Pegasus Spyware
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for you
Getting Agents to tell on themselves
From fake interview to signed ClickOnce: inside a three-payload Windows chain (Part 2)
The Validator Can Lie: SSRF Beyond URL Validation (GitLab, Mealie, Apache ShenYu, Thumbor)
From Patch to Exploit; Using Claude Code to reverse engineer an n-day in Papercut NG
r/netsec monthly discussion & tool thread
Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586
Authentication bypass in EOL Proxmox VE 7 release
GeoNetwork - Pre-Auth RCE via Unauthenticated File Upload and Unsafe XSLT Processor (4 CVEs, 121 government deployments, all patched)
Don’t Let Abliteration Abliterate Your Bug Hunting: Discovering Verdict Bias in Uncensored Models
Privilege escalation from IIS AppPool to NT Authority/SYSTEM via AD CS RPC endpoint
Anatomy of a ServiceNow Red Team
UniBLEed: Unauthenticated Root RCE on Any Unitree G1 Humanoid Robot Within Bluetooth Range
A fake resume invoked China’s defence tech elite, then installed VShell
LLM-Driven Reverse Engineering vs Iterative LLM Obfuscation
PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure
Chaining three public V8 bugs to escape the V8 sandbox and recover a real Google v8CTF flag
☢️ Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator
Ruby Marshal Kick-off Gadgets - elttam
Any solutions we can use?
Possible targeted attack
RoguePlanet: Windows Zero-Day That Weaponizes Defender's Own Quarantine Pipeline
Facebook messenger to text
Managing Solution Agents
Nottingham University data breach affects over 450,000 students
SWGs that support 3rd party external DNS resolver
Sub:jugation - Hijacking Cloud Identities by Recycling Namespaces in Global OIDC Issuers
Chrome extensions with 10M+ installations are actively vulnerable to UXSS & UXSG
Cybersecurity researchers aren't happy about the guardrails on Anthropic's Fable | TechCrunch
Phishing awareness training resulting in ignoring company comms?
How are you analyzing Android malware nowadays?
Hackers Exploit Langflow Vulnerability for Remote Code Execution
Chaotic Eclipse Strikes Again: New Zero-Day Unlocks BitLocker in Four Hours of Research
NEED SOME GUIDANCE
Help setting up local encryption on my pc
Agentic AI on Cybersecurity
DoD 0-days Typically Come Down to Authorization Failures
HDD
Plzz Helpp - Say you're trying to build a toolkit that checks for LLM vulnerability do y'all know any trustable datasets
DIY pwnagotchi-like device on esp32
Flipper Blackhat + Bjorn
Do you think AI is making hacking easier or harder
What can i do left? PSN
Proxmark5 campaign ending in less than 18 hours.
How to bypass speed queen coin slot for washer and dryer
Self-hosting stuff for when things get ugly
Malware Includes Taboo In Text To Prevent LLM Analysis
added Mac support for my corporate hacking game, demo on Steam
Catfished
What did they mean by this? One of us?
Microsoft Defender 'RoguePlanet' zero-day grants SYSTEM privileges
OptOutCode – A Privacy4Cars Universal Opt-Out Concept
StumbleTV: Omegle/ChatRoulette but for accidentally exposed webcams
GitHub - Teycir/ApiHunter: Async API security scanner in Rust for CORS, CSP, GraphQL, JWT, OpenAPI, and active API posture checks.
Heyy ik it sounds dumb but can we just get access to one's gaming acc?🙏
What's up with powershellforhackers.com?
Do people really click on links from unknown numbers?
How to unlock whitelabeled uniview IPcam
Can converted video files contain malware?
Reverse engineered BLE protocol of a $7 generic Chinese smart ring from Temu, and built an iOS app around it
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
[Reverse-Engineering] Skeet CS:GO source code (Gamesense)
Giulio Zausa's MMO-CHIP Makes Reverse Engineering Old Silicon Chips a Multiplayer Game
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
Drive Firmware Security - Phison S11
IDA 9.4 Beta | Hex-Rays Docs
Trane Tracer HVAC cybersecurity issues
🚀 Release PyMemoryEditor v2.0 — read, write and scan the memory of any running process, in pure Python (Windows, Linux & macOS)
I reverse engineered Lofree Hypace mouse firmware flashing protocol to bypass their official web based configuration on MacOS.
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
[Tool/Writeup] PureBasic FLIRT Signature for IDA Pro — demo + crackme
First Public Analysis of the BoldTealLayer Loader: A Custom Lua Script that Blinds Windows Security
EMBA firmware analysis framework v2.0.2 available - Party the big 2k
/r/ReverseEngineering's Weekly Questions Thread
HDD Firmware Hacking Part 1
Independent Post-Quantum KEM and Digital Signature Suite in C++ (NSLD Reduction
Zhiyun Weebil-S Camera Gimbal BLE Protocol
Reverse Engineering the Garmin Running Dynamics BLE protocol
Finally! A modern Android menu template with ImGui + Zygisk + all major hooking libraries (Dobby, KittyMemory, Substrate)
US charges suspected Russian hacker with facilitating cyber campaign
Hawkish GOP lawmaker Don Bacon says he was hacked by Russia
Oops, I Weaponized the Database: Abusing AI Features in SQL Server 2025
GreatXML: GreatXML bitlocker bypass vulnerability
GreatXML a bitlocker that seems to only work if you ever had Defender Offline Scan
I found 23 Chrome extensions hijacking 758,000 users' searches for affiliate revenue
[Op Report] From SSA Phish to AdaptixC2: A Multi-RAT Intrusion
GhostTrace – CLI forensic scanner for Windows: 22 modules, MITRE ATT&CK mapped, read-only by default
Miasma-style supply chain attacks
On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is present, the switch will incorrectly decapsulate and forward other unexpected tunneled packet
More Evidence That Words Don't Mean What We Thought They Meant (Ivanti Sentry Pre-Auth OS Command Injection CVE-2026-10520) - watchTowr Labs
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
Testing offensive AI agents in a cloud lab with deception tech
Benchmarking n-day exploit generation [via AI]
Whoops! I did it again. I patched Windows Kernel at Milan0day 2026
Microsoft Defender now monitors RPC activity
RoguePlanet: RoguePlanet Windows Defender Vulnerability
I triaged this pattern hundreds of times. Here's the KQL that actually works (with noise reduction built in)
How do you make learning blue team security entertaining ?
Maximizing IOC Impact
I built 99 adversarially malformed PE files to test tool robustness - here’s what happened
ClickFix attack in the wild — fake Cloudflare CAPTCHA delivering obfuscated PowerShell dropper
WordPress malware in official WooCommerce theme (Kiosko): hidden admin users and corrupted sitemap
Inside the DPRK-Linked Backdoor Loitering in the VS Code Marketplace
Fake Interview deploys stealthy cross platform (macOS/Windows) through npm package install in take home assessment
73 Microsoft GitHub repositories impacted by Miasma malware
Unauthorized Onlyfans Payment
Building A Malware Lab From Scratch Part 2!
Detecting npm Native Addon Malware: node-gyp Abuse
Microsoft Warns of GPU Cryptojacking Campaign Spread Through AI Chatbot Links
Extremely suspicious behaviour by memu emulator
Malware
🚨 PCPJack's SMTP Toolkit Dissected: 3 Deployer Generations, Multi-Arch Chisel, and a Full EHLO/STARTTLS Verification Loop
ChatGPT Malvertising Campaign
Recommendation
Welp, we got a VMware antidetect ransomware/spyware/trojan before GTA 6!
This is a scam and probably a malware/trojan. Path Of Exile 2 builder ...
LLMShare: using shared chatbot pages to distribute malware
How to Unpack FlawedAmmyy - Malware Unpacking Tutorial
Building A Malware Lab From Scratch!
No matching sources found.