Snowflake’s AI Bypasses Access Controls
https://ift.tt/NKlMjt8
Submitted May 06, 2025 at 10:55AM by Affectionate-Win6936
via reddit https://ift.tt/5ta1K8O
https://ift.tt/NKlMjt8
Submitted May 06, 2025 at 10:55AM by Affectionate-Win6936
via reddit https://ift.tt/5ta1K8O
Cyera
Unexpected behavior in Snowflake’s Cortex AI | Cyera Blog
Snowflake’s Cortex AI can expose sensitive data if misconfigured. Learn how it happens—and how Cyera helps protect against AI-driven data leaks
My Zero Day Quest
https://ift.tt/pamk5XE
Submitted May 06, 2025 at 11:50AM by 0xdea
via reddit https://ift.tt/sdHI4wQ
https://ift.tt/pamk5XE
Submitted May 06, 2025 at 11:50AM by 0xdea
via reddit https://ift.tt/sdHI4wQ
hn security
My Zero Day Quest & BlueHat Podcast - hn security
“If you shame attack research, you […]
SysOwned, Your Friendly Support Ticket - SysAid On-Premise Pre-Auth RCE Chain (CVE-2025-2775 And Friends) - watchTowr Labs
https://ift.tt/kjbmNd8
Submitted May 07, 2025 at 03:09PM by dx7r__
via reddit https://ift.tt/OnEDaje
https://ift.tt/kjbmNd8
Submitted May 07, 2025 at 03:09PM by dx7r__
via reddit https://ift.tt/OnEDaje
watchTowr Labs
SysOwned, Your Friendly Support Ticket - SysAid On-Premise Pre-Auth RCE Chain (CVE-2025-2775 And Friends)
It’s… another week, and another vendor who is apparently experienced with ransomware gangs but yet struggles with email.
In what we've seen others term "the watchTowr treatment", we are once again (surprise, surprise) disclosing vulnerability research that…
In what we've seen others term "the watchTowr treatment", we are once again (surprise, surprise) disclosing vulnerability research that…
We Got Tired of Labs NOT preparing us for Real Targets… So We Built This (Seeking Beta Feedback!)
https://ift.tt/VxUAJ75
Submitted May 07, 2025 at 02:44PM by RogueSMG
via reddit https://ift.tt/RvzWVL9
https://ift.tt/VxUAJ75
Submitted May 07, 2025 at 02:44PM by RogueSMG
via reddit https://ift.tt/RvzWVL9
Known Exploited Vulnerabilities Intel
https://kevintel.com
Submitted May 07, 2025 at 04:10PM by ethicalhack3r
via reddit https://ift.tt/fSrupwZ
https://kevintel.com
Submitted May 07, 2025 at 04:10PM by ethicalhack3r
via reddit https://ift.tt/fSrupwZ
Reddit
From the netsec community on Reddit: Known Exploited Vulnerabilities Intel
Posted by ethicalhack3r - 12 votes and 0 comments
Drag and pwnd: Exploiting VS Code with ASCII
https://ift.tt/FtQCINX
Submitted May 07, 2025 at 03:55PM by albinowax
via reddit https://ift.tt/KtoMkVv
https://ift.tt/FtQCINX
Submitted May 07, 2025 at 03:55PM by albinowax
via reddit https://ift.tt/KtoMkVv
PortSwigger Research
Drag and Pwnd: Leverage ASCII characters to exploit VS Code
Control characters like SOH, STX, EOT and ETX were never meant to run your code - but in the world of modern terminal emulators, they sometimes do. In this post, I'll dive into the forgotten mechanics
Finding Vulnerable malloc Calls using Ghidra PCode Analysis
https://ift.tt/7ec4qZv
Submitted May 07, 2025 at 07:02PM by cy1337
via reddit https://ift.tt/UN6tHMl
https://ift.tt/7ec4qZv
Submitted May 07, 2025 at 07:02PM by cy1337
via reddit https://ift.tt/UN6tHMl
Medium
Tracing malloc calls with PCode
It’s that time of the year again, Black Hat USA is just a few months away and I’m honored to be back again for another year teaching about…
Summarisation of Cross Session Activation / Kerberos relaying attacks
https://ift.tt/qTJDjbI
Submitted May 07, 2025 at 07:33PM by S3cur3Th1sSh1t
via reddit https://ift.tt/FR2UNrH
https://ift.tt/qTJDjbI
Submitted May 07, 2025 at 07:33PM by S3cur3Th1sSh1t
via reddit https://ift.tt/FR2UNrH
www.r-tec.net
r-tec Blog | Windows is and always will be a Potatoland
This blog post will dive into the world of some of the recently published potato techniques that can lead to more serious risks than
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerability Reports
https://ift.tt/XbYVS1M
Submitted May 07, 2025 at 09:03PM by rcmaehl
via reddit https://ift.tt/yH1ojhS
https://ift.tt/XbYVS1M
Submitted May 07, 2025 at 09:03PM by rcmaehl
via reddit https://ift.tt/yH1ojhS
Socket
AI Slop Is Polluting Bug Bounty Platforms with Fake Vulnerab...
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.
The Path to Memory Safety is Inevitable
https://ift.tt/fZzugXk
Submitted May 07, 2025 at 08:49PM by citypw
via reddit https://ift.tt/4t5QwbJ
https://ift.tt/fZzugXk
Submitted May 07, 2025 at 08:49PM by citypw
via reddit https://ift.tt/4t5QwbJ
hardenedlinux.org
The Path to Memory Safety is Inevitable
Santizer is the most effective way to enhance the memory safety. Fuzzer helps as well! Fil-C...
CVE-2024-11477- 7-Zip ZSTD Buffer Overflow Vulnerability - Crowdfense
https://ift.tt/vujZDGX
Submitted May 08, 2025 at 08:44PM by Void_Sec
via reddit https://ift.tt/OkF1a6U
https://ift.tt/vujZDGX
Submitted May 08, 2025 at 08:44PM by Void_Sec
via reddit https://ift.tt/OkF1a6U
Crowdfense
CVE-2024-11477- 7-Zip ZSTD Buffer Overflow Vulnerability - Crowdfense
CVE-2024-11477, a buffer overflow vulnerability in 7-Zip's ZSTD decompression algorithm; explore the technical details.
SCIM Hunting. Finding bugs in SCIM implementations
https://ift.tt/hUzQuDE
Submitted May 09, 2025 at 02:24AM by nibblesec
via reddit https://ift.tt/JUW1v0f
https://ift.tt/hUzQuDE
Submitted May 09, 2025 at 02:24AM by nibblesec
via reddit https://ift.tt/JUW1v0f
Doyensec
SCIM Hunting - Beyond SSO
Single Sign-On (SSO) related bugs have gotten an incredible amount of hype and a lot of amazing public disclosures in recent years. Just to cite a few examples:
Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources
https://ift.tt/M5VvtJj
Submitted May 10, 2025 at 04:34AM by Super_Weather3575
via reddit https://ift.tt/4Pg6QpV
https://ift.tt/M5VvtJj
Submitted May 10, 2025 at 04:34AM by Super_Weather3575
via reddit https://ift.tt/4Pg6QpV
Unit 42
Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources
Unit 42 details a new malware obfuscation technique where threat actors hide malware in bitmap resources within .NET applications. These deliver payloads like Agent Tesla or XLoader. Unit 42 details a new malware obfuscation technique where threat actors…
The Honeynet Workshop Conference 2025 is in June in Prague.
https://ift.tt/oQGb1kg
Submitted May 11, 2025 at 02:12AM by sebagarcia
via reddit https://ift.tt/oDiUERd
https://ift.tt/oQGb1kg
Submitted May 11, 2025 at 02:12AM by sebagarcia
via reddit https://ift.tt/oDiUERd
One-Click RCE in ASUS’s Preinstalled Driver Software
https://ift.tt/pmH13x8
Submitted May 11, 2025 at 02:13PM by AlmondOffSec
via reddit https://ift.tt/gkp91cG
https://ift.tt/pmH13x8
Submitted May 11, 2025 at 02:13PM by AlmondOffSec
via reddit https://ift.tt/gkp91cG
Mrbruh
MrBruh's Epic Blog
One-Click RCE in ASUS’s Preinstalled Driver Software Introduction This story begins with a conversation about new PC parts.
After ignoring the advice from my friend, I bought a new ASUS motherboard for my PC. I was a little concerned about having a BIOS that…
After ignoring the advice from my friend, I bought a new ASUS motherboard for my PC. I was a little concerned about having a BIOS that…
How I ruined my vacation by reverse engineering WSC
https://ift.tt/4l8OMEI
Submitted May 12, 2025 at 04:49PM by AlmondOffSec
via reddit https://ift.tt/nhTKLE7
https://ift.tt/4l8OMEI
Submitted May 12, 2025 at 04:49PM by AlmondOffSec
via reddit https://ift.tt/nhTKLE7
blog.es3n1n.eu
How I ruined my vacation by reverse engineering WSC
In this post I will briefly describe the journey I went through while implementing defendnot.
Even though this is most likely not what you expected to see here, but rather than going into full technical details on how everything works, I will describe what…
Even though this is most likely not what you expected to see here, but rather than going into full technical details on how everything works, I will describe what…
Statistical Analysis to Detect Uncommon Code
https://ift.tt/9IzWd3K
Submitted May 12, 2025 at 07:57PM by FoxInTheRedBox
via reddit https://ift.tt/GJwEInX
https://ift.tt/9IzWd3K
Submitted May 12, 2025 at 07:57PM by FoxInTheRedBox
via reddit https://ift.tt/GJwEInX
I built Mithra: a security scanner for LLM-integrated APIs (detects prompt injection, DAN..)
https://mithrasec.com
Submitted May 12, 2025 at 10:55PM by 1337kadir
via reddit https://ift.tt/Wpzfkjw
https://mithrasec.com
Submitted May 12, 2025 at 10:55PM by 1337kadir
via reddit https://ift.tt/Wpzfkjw
Mithrasec
Mithra LLM Scanner
Scan LLM-Integrated APIs in Minutes
Azure Managed Identities Abuse: Security Research - Defense strategies
https://ift.tt/GLJVNXq
Submitted May 13, 2025 at 06:21PM by HunterHex1123
via reddit https://ift.tt/tWgNV9y
https://ift.tt/GLJVNXq
Submitted May 13, 2025 at 06:21PM by HunterHex1123
via reddit https://ift.tt/tWgNV9y
www.hunters.security
Detecting Azure Managed Identity Abuse: Threat Hunting Techniques
Discover how to detect and hunt Azure Managed Identity abuse using real-world scenarios, log correlations, and high-fidelity detection queries.
[CVE-2025-47916] Invision Community <= 5.0.6 (customCss) Remote Code Execution
https://ift.tt/Dhlrg7f
Submitted May 14, 2025 at 06:05PM by eg1x
via reddit https://ift.tt/SEOhrPB
https://ift.tt/Dhlrg7f
Submitted May 14, 2025 at 06:05PM by eg1x
via reddit https://ift.tt/SEOhrPB
Karmainsecurity
Invision Community <= 5.0.6 (customCss) Remote Code Execution Vulnerability | Karma(In)Security
This is the personal website of Egidio Romano, a very curious guy from Sicily, Italy. He's a computer security enthusiast, particularly addicted to webapp security.
Integrate LDAP into Keycloak to modernize rather than delete it
https://ift.tt/E0tyOI8
Submitted May 14, 2025 at 07:41PM by Will-from-CloudIAM
via reddit https://ift.tt/eu9Antw
https://ift.tt/E0tyOI8
Submitted May 14, 2025 at 07:41PM by Will-from-CloudIAM
via reddit https://ift.tt/eu9Antw
Cloud-Iam
LDAP, Keycloak, and Modern IAM: Integrating LDAP into a scalable, secure IAM architecture with Keycloak
Modernize your user management while preserving your LDAP with Keycloak. Instead of replacing your LDAP, it's often wiser to reposition it as a source of truth, orchestrated by a modern IAM solution. Keycloak stands out because it can natively federate with…