RSS 238
- When Encryption Isn’t Really Encryption
- Less panic patching, more precision
- Adversarial Oracles: LLM-Guided EDR Signature Reduction
- Grading on a curve: How to assess a pentest
- Visual Studio Extensions Revisited
- 2026 World Cup: Discussing The World’s Biggest Game’s Attack Surface
- DICOM, Pydicom, GDCM, and Orthanc: A technical tour of what really happens in the heap
- From Exploit Code to Production Detection: Building a CVE-2026-31431 (Copy Fail) detection with Agents
- Out of the Crypt: The Evolving Cyber Extortion Economy
- MediaArea heap-based buffer overflow vulnerabilities
- Bad Habits: An ANTISOC Operation
- Investigating suspicious AI workflows in Microsoft Entra Agent ID: Autonomous agents
- Introducing EvidenceForge: Synthetic security logs that don’t look (as) fake
- How to detect HTTP/2 abuse in Apache web server logs
- Comparing AI Application Security Testing Platforms
- Module Stomping PIC
- Intelligence Insights: May 2026
- PCI DSS, Telephone Payments, and the Problems With VoIP
- Exploring Agent based Cloud Review Capabilities
- Critical vulnerability in Mirasvit Cache Warmer for Magento
- Breaking Tenant Boundaries, When Path Traversal Isn't About the Filesystem
- AWS Security Digest #262 - Not private
- Navigating Lax Load Balancers: When an Intersection Gets You Inside
- Remove SPNs and Fix Kerberoasting
- Negative-Days with Vulnerability Spoiler Alert: Three Months Later
- HTB: MonitorsFour
- How to Secure Your Enterprise LLM Deployment
- The Good, the Bad and the Ugly in Cybersecurity – Week 21
- RemotePE: The Lazarus RAT that lives in memory
- Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
- We hardened zizmor's GitHub Actions static analyzer
- Paved With Intent: ROADtools and Nation-State Tactics in the Cloud
- Securing AI agents: Why guardrail placement is a key design decision
- Striga: Lifting x86 to LLVM IR with Python
- Shai-Hulud Is Back, and This Time It Ate the Whole Ecosystem
- Unpatchable Vulnerabilities of Kubernetes: CVE-2021-25740
- Tracking TamperedChef Clusters via Certificate and Code Reuse
- SVD-2026-0515: Third-Party Package Updates in Splunk User Behavior Analytics - May 2026
- SVD-2026-0512: Third-Party Package Updates in Splunk AppDynamics Private Synthetic Agent (PSA) - May 2026
- Reduce CVE noise with OpenVEX assessments in Datadog
- Parallel Intelligence and Cognitive Warfare
- durabletask: TeamPCP's Latest PyPi Compromise
- TP-Link, Photoshop, OpenVPN, Norton VPN vulnerabilities
- From PDB strings to MaaS: Tracking a commodity BadIIS ecosystem used by Chinese-speaking threat
- Coverage-Driven Sustained Testing (CDST): A Graph-Oriented Model for Open-Ended Agentic Workflows
- When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
- How OLTs may have exposed entire ISP networks
- Distinguished paper award for Phoenix!
- SHub Reaper | macOS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain
- AWS Security Digest #261 - Pretending
- Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
- HTB: Pterodactyl
- Living Off the Pipeline: Defending Against CI/CD Subversion
- Gremlin Stealer's Evolved Tactics: Hiding in Plain Sight With Resource Files
- Design-Based Vulnerabilities on macOS: Oops, Not a One-Shot Fix
- Ongoing exploitation of Cisco Catalyst SD-WAN vulnerabilities
- Finding Your Way on the Passkey Path
- Critical FunnelKit vulnerability threatens 40,000+ WooCommerce checkouts
- Backdoored node-ipc npm releases steal developer credentials through DNS queries
- Backdoored Cemu release linked to TanStack and Mistral supply chain campaign
- The Convergence of Cloud Secrets & AI Risk
- Your Login Page Is Lying: What AI Agents Find When They Read Your Frontend
- How to Identify and Exploit New Vulnerabilities
- Investigating server compromises with cgroups: A Linux DFIR primer
- A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens
- Microsoft Patch Tuesday – May 2026
- Shai-Hulud Goes Open Source
- Disclosure: Teachable's CDN Is Stealing From Teachers
- Composer vulnerability leaks GitHub tokens, threatens PHP supply chain
- Microsoft Patch Tuesday for May 2026 — Snort rules and prominent vulnerabilities
- The beast needs a cage: What's next for AppSec post-Mythos
- Keys to the Kingdom Live Stripe Credentials Exposed via Unauthenticated OAuth Endpoint
- Nuclei Templates - April 2026
- Go fuzzing was missing half the toolkit. We forked the toolchain to fix it.
- State-sponsored actors, better known as the friends you don’t want
- Slamming the Door on Quick Assist Tech Support Scams and Abuse
- Mini Shai-Hulud Strikes Again: TanStack + more npm Packages Compromised
- Inside AD CS Escalation: Unpacking Advanced Misuse Techniques and Tools
- Flash Alert: EtherRat and TukTuk C2 End in The Gentleman Ransomware
- AWS Security Digest #260 -
- Malicious Coding Agent Skills and the Risk of Dynamic Context
- Personal Software and BaremetalVMM
- The Accidental C2 - Exploring Dev Tunnels for Remote Access
- HTB: Overwatch
- Hunting ClickFix Win + X Variants
- The Good, the Bad and the Ugly in Cybersecurity – Week 19
- Dirty Frag: Linux Kernel Local Privilege Escalation via ESP and RxRPC
- Oh MyAudi!
- Claude Code Cost Tracking: AWS Bedrock vs Pro Max (Part 2) — Tag Propagation, Sydney Migration, Bug Fixes
- Remote Code Execution Vulnerability in Fooocus
- Kubernetes security fundamentals: Secrets
- The New Reality in Cybersecurity: AI Agents, Acceleration, and Asymmetry
- Spring cleaning your browser
- GRC in an AI World - Staying in the Fast Lane Without Losing the Race!
- Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution
- Gibbon v30.0.00: Authenticated SQL Injection and RCE
- The IGVM File Format
- Open-Sourcing 140+ Weaponisable File Type Samples: Test What Your Defences Actually Block
- Swapper – A Pure Regex Match/Replace Burp Extension
- Critical Buffer Overflow Vulnerability in PAN-OS Exploited in-the-Wild
- Insights into the clustering and reuse of phone numbers in scam emails
- Breaking SameSite=Strict in Chrome
- Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years
- [Deprecated] Break LLM Workflows with Claude's Refusal Magic String
- C/C++ checklist challenges, solved
- UAT-8302 and its box full of malware
- CloudZ RAT potentially steals OTP messages using Pheno plugin
- pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
- The Defensive Stack is Exposed: LLMs, Reverse Engineering, and the End of Opaque Defense
- The Danger of Multi-SSO AWS Cognito User Pools
- Paramiko Security Audit
- Redis array type: short story of a long development
- AWS Security Digest #259 - Better late
- Evaluating our Threat Hunting Detection Rules (+ KQL Query Evaluation)
- Chaining ISC DHCP Server Features for Unauthenticated Root Remote Code Execution
- Tuned by Design: Why Detection Engineering Needs Its Own Development Lifecycle
- Essential Data Sources for Detection Beyond the Endpoint
- The Good, the Bad and the Ugly in Cybersecurity – Week 18
- The Life-Dinner Principle in Detection
- 3 ways custom scan checks turn practitioner knowledge into scalable automation
- Discovering Vulnerabilities in Enterprise Audiovisual Hardware
- That AI Extension Helping You Write Emails? It’s Reading Them First
- ARP Around and Find Out: Hijacking GPO UNC Paths for Code Execution and NTLM Relay
- Auditing Application Permissions in Microsoft Entra ID: Hidden Risks, Pitfalls, and Quarkslab's QAZPT Tool
- (CVE-2026-41873) Apache Pony Mail CRLF Injection and SSRF Leading to Full Account Takeover
- When Wi-Fi Encryption Fails: Protecting Your Enterprise from AirSnitch Attacks
- Identifying and containing a data breach
- You’re Not Watching MCPs. Anthropic’s Vulnerability Shows Why You Should Be.
- IR Trends Q1 2026: Phishing reemerges as top initial access vector, as attacks targeting public administration persist
- Bad Apples: Weaponizing native macOS primitives for movement and execution
- Phishing and MFA exploitation: Targeting the keys to the kingdom
- 500,000 Vulnerabilities, 14 That Matter: How Exploit Chain Analysis Cuts Through the Noise
- Microsoft Entra ID: Understanding OAuth App Consent and Permissions
- Some notes on the security properties of the pipe_buffer kernel object
- From a Regular Red Team Exercise to Developing a Custom C2 Channel over MS Teams
- From Code to Pipeline: Wiz Code Now Secures Your Build Environment
- Context.ai OAuth Token Compromise
- Fracturing Software Security With Frontier AI Models
- Threat Hunting via InternetMessageId (+ KQL Queries)
- Detection Visibility Metrics
- AWS Security Digest #257 - Myth not Mythos?
- swic: a simple web interface for calibre
- Pickling the Mailbox: A Deep Dive into CVE-2025-20393
- CFITSIO Fuzzing: Memory Corruptions and a Codex-Assisted Pipeline
- HTB: AirTouch
- SQLite prefixes its temp files with `etilqs_`
- The Good, the Bad and the Ugly in Cybersecurity – Week 16
- We beat Google’s zero-knowledge proof of quantum cryptanalysis
- The Mythos Effect: Preparing for AI-Accelerated Exploitation
- Mythos, Memory Loss, and the Part InfoSec Keeps Missing
- Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)
- Beyond the Perimeter How an On-Premises Domain Admin Compromise Unlocked the Cloud
- Anonymous credentials: an illustrated primer (Part 2)
- Spotting CI/CD misconfigurations before the bots do: Securing GitHub Actions with Datadog IaC Security
- Obfuscation vs the Optimizer: An LLVM Middle-End Arms Race
- A Deep Dive Into Attempted Exploitation of CVE-2023-33538
- The case for dependency cooldowns in a post-axios world
- PowMix botnet targets Czech workforce
- Foxit, LibRaw vulnerabilities
- AI cybersecurity is not proof of work
- Signed, Trusted, and Abused: Proxy Execution via WebView2
- Identity, browsers, and node.js: Everything you missed in the Threat Detection Report miniseries
- Shadow Admins in Active Directory: Hidden Privilege Paths Attackers Exploit
- LmCompatibilityLevel and the PDC Trap
- SVD-2026-0407: Sensitive Information Disclosure in ''_internal'' index in Splunk MCP Server app
- SVD-2026-0405: Third-Party Package Updates in Splunk Enterprise - April 2026
- Business CTF 2022: H2 Request Smuggling and SSTI - Phishtale
- Uni CTF 2022: UNIX socket injection to custom RCE POP chain - Spell Orsterra
- Finding RCE in NodeJS templating engine ‘Eta’ - CVE-2022-25967
- Business CTF 2022: Chaining Self XSS with Cache Poisoning - Felonious Forums
- Performing Supply-Chain Attack in the NodeJS Ecosystem [hands-on exercise]
- The n8n n8mare: How threat actors are misusing AI workflow automation
- Can a Predicted `window.open` Target Really Be That Impactful?
- Slacker Slash: Bypassing Bun Security Middleware via Normalization Desync
- Chaining service key leakage and path confusion in LangSmith (Resolved)
- Authenticated Arbitrary File Read via Race Condition leads to 0-Click Account Take Over on n8n
- The Dot-Dot-Slash That Frameworks Hand You: CSPT Across Every Major Frontend Framework
- Detect runtime threats in Python Lambda functions with Datadog AAP
- BSIM explained once and for all!
- Primer on GitHub Actions Security - Threat Model, Attacks and Defenses (Part 1/2)
- Securing the Software Supply Chain: How SentinelOne’s AI EDR Autonomously Blocked the CPU-Z Watering Hole Cyber Attack
- Benchmarking Self-Hosted LLMs for Offensive Security
- State-sponsored threats: Different objectives, similar access paths
- Microsoft Patch Tuesday for April 2026 - Snort Rule and Prominent Vulnerabilities
- Intercepting WCF Traffic with wcfproxy
- Microsoft Patch Tuesday – April 2026
- Mythos and its impact on security
- Citrix Breakout When Restricted Means Nothing
- Binary Ninja 5.3 (Jotunheim)
- AWS Security Digest #256 - TY Mythos
- JitterDropper
- Fixing ESC8 - Web Enrollment is enabled over HTTP and HTTPS, and Channel Binding is disabled
- LibreNMS < 26.3.0 Authenticated RCE & XSS
- Validating Browser Defences with Push Security and delivr.to
- IrDA
- HTB: Eighteen
- Introducing our open source AI-native SAST
- The Good, the Bad and the Ugly in Cybersecurity – Week 15
- Security’s Blind Spot: Physical Keyloggers That Bypass Antivirus Entirely
- Bypassing LLM Supervisor Agents Through Indirect Prompt Injection
- 283 - The Future
- Tearing down a car telematic unit (and finding an accident on Facebook)
- Edge Decay: How a Failing Perimeter Is Fueling Modern Intrusions
- Master C and C++ with our new Testing Handbook chapter
- IAM the Captain Now – Hijacking Azure Identity Access
- Unpatchable Vulnerabilities of Kubernetes: CVE-2020-8562
- From the field to the report and back again: How incident responders can use the Year in Review
- The threat hunter’s gambit
- How We Cut LLM Costs by 59% With Prompt Caching
- Scanscope: Visualizing Port Scan Results Using Machine Learning Methods
- Crystal Mask
- Ingress NGINX is EOL: A practical guide for migrating to Kubernetes Gateway API
- CI/CD security: How to secure your GitHub ecosystem
- CI/CD security: threat modeling using a MITRE-style threat matrix
- Cracks in the Bedrock: Agent God Mode
- New Lua-based malware “LucidRook” observed in targeted attacks against Taiwanese organizations
- AI in cybersecurity: The good, the bad, and the FUD
- Scroll trīgintā sextus
- Year in Review: Vulnerabilities old and new and something React2
- Yandex Services Source Code Leak
- What we learned about TEE security from auditing WhatsApp's Private Inference
- What enables malicious models?
- Using KServe to deploy malicious models
- The Trojan horse of cybercrime: Weaponizing SaaS notification pipelines
- Reversing ELFs on TryHackMe: Crackme8
- Remote Session Enumeration via Undocumented Windows APIs
- PrivEsc: Abusing the Service Control Manager for Stealthy & Persistent LPE
- Model Confusion - Weaponizing ML models for red teams and bounty hunters
- Kernel Drivers, Process Protection, and ...Bears?
- Introducing the Offsec ML Playbook v0.1
- Introducing MacNoise!
- Cracks in the Bedrock: Escaping the AWS AgentCore Sandbox
- Building a Detection Foundation: Part 5 - Correlation in Practice
- Adversaries sometimes compute gradients. Other times, they rob you.
- What is LLM Penetration Testing? A Complete Guide
- Understanding Current Threats to Kubernetes Environments
- HTB: DarkZero
- Six Accounts, One Actor: Inside the prt-scan Supply Chain Campaign