TrashTalk.me - A new secure way to chat
https://trashtalk.me
Submitted June 24, 2025 at 11:14PM by merklerkmanitee
via reddit https://ift.tt/i5Xlo8z
https://trashtalk.me
Submitted June 24, 2025 at 11:14PM by merklerkmanitee
via reddit https://ift.tt/i5Xlo8z
Reddit
From the netsec community on Reddit: TrashTalk.me - A new secure way to chat
Posted by merklerkmanitee - 0 votes and 2 comments
Cryptominers’ Anatomy: Shutting Down Mining Botnets
https://ift.tt/LEZo1sJ
Submitted June 24, 2025 at 11:10PM by Narrow_Rooster_630
via reddit https://ift.tt/XOdWbrL
https://ift.tt/LEZo1sJ
Submitted June 24, 2025 at 11:10PM by Narrow_Rooster_630
via reddit https://ift.tt/XOdWbrL
Akamai
Cryptominers’ Anatomy: Shutting Down Mining Botnets | Akamai
In the final installment of Cryptominers’ Anatomy, Akamai researchers analyze cryptominers and reveal a novel technique to shut down mining botnet campaigns.
Security Benchmarking Authorization Policy Engines
https://ift.tt/fXxNqzl
Submitted June 25, 2025 at 02:42PM by nibblesec
via reddit https://ift.tt/gM60OZN
https://ift.tt/fXxNqzl
Submitted June 25, 2025 at 02:42PM by nibblesec
via reddit https://ift.tt/gM60OZN
Goteleport
Security Benchmarking Authorization Policy Engines: Rego, Cedar, OpenFGA & Teleport ACD
Explore how the Security Policy Evaluation Framework (SPEF) enables automated, dynamic security benchmarking of leading authorization engines—Rego, Cedar, OpenFGA, and Teleport ACD. Developed by Doyensec with support from Teleport, SPEF tests for vulnerabilities…
Deleting a file in Wire doesn’t remove it from servers — and other findings
https://ift.tt/CcOrZKg
Submitted June 25, 2025 at 03:24PM by AlmondOffSec
via reddit https://ift.tt/4WO3U8e
https://ift.tt/CcOrZKg
Submitted June 25, 2025 at 03:24PM by AlmondOffSec
via reddit https://ift.tt/4WO3U8e
How to Set Up Your Own WireGuard VPN on a VPS (Beginner-Friendly Tutorial)
https://ift.tt/KJXx0uB
Submitted June 25, 2025 at 08:14PM by kongwenbin
via reddit https://ift.tt/zxtuN1Q
https://ift.tt/KJXx0uB
Submitted June 25, 2025 at 08:14PM by kongwenbin
via reddit https://ift.tt/zxtuN1Q
My Learning Journey
How to Set Up Your Own WireGuard VPN on a VPS (Beginner-Friendly Tutorial)
Beginner-friendly Step-by-step guide to setting up a WireGuard VPN on a VPS. Ideal for bug bounty hunters and privacy-focused users.
We built a smart, searchable infosec library indexing 20+ years of resources
https://talkback.sh
Submitted June 26, 2025 at 10:16AM by elttam
via reddit https://ift.tt/enixObw
https://talkback.sh
Submitted June 26, 2025 at 10:16AM by elttam
via reddit https://ift.tt/enixObw
Talkback
Talkback is a smart infosec resource aggregator, designed to help security enthusiasts, practitioners and researchers be more productive.
Read “Windows Registry Manipulation“ by ONESithuation
https://ift.tt/aMdWmFY
Submitted June 26, 2025 at 10:07AM by Johny166xz
via reddit https://ift.tt/hN6L4zV
https://ift.tt/aMdWmFY
Submitted June 26, 2025 at 10:07AM by Johny166xz
via reddit https://ift.tt/hN6L4zV
Medium
Windows Registry Manipulation
Episode 01
Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork - Putting Millions at Risk
https://ift.tt/Tdj6bVm
Submitted June 26, 2025 at 04:43PM by Most-Anywhere-6651
via reddit https://ift.tt/ZYFaiSp
https://ift.tt/Tdj6bVm
Submitted June 26, 2025 at 04:43PM by Most-Anywhere-6651
via reddit https://ift.tt/ZYFaiSp
Medium
Marketplace Takeover: How We Could’ve Taken Over Every Developer Using a VSCode Fork; Putting Millions at Risk
TL;DR: We discovered a critical vulnerability in open-vsx.org — the open-source VS Code extension marketplace used by over 8,000,000…
Scanning Beyond the Patch: A Public-Interest Hunt for Hidden Shells
https://ift.tt/YMgyR2h
Submitted June 26, 2025 at 07:21PM by 0x5h4un
via reddit https://ift.tt/ukmlabS
https://ift.tt/YMgyR2h
Submitted June 26, 2025 at 07:21PM by 0x5h4un
via reddit https://ift.tt/ukmlabS
disclosing.observer
Scanning Beyond the Patch: A Public-Interest Hunt for Hidden Shells - Disclosing.Observer
Even after patching, many edge devices remain compromised. This post explores how to ethically scan for backdoors left behind.
When Your Login Page Becomes the Frontline: Lessons from a Real-World DDoS Attack
https://ift.tt/JNWniZm
Submitted June 26, 2025 at 10:08PM by Will-from-CloudIAM
via reddit https://ift.tt/qc6aH2t
https://ift.tt/JNWniZm
Submitted June 26, 2025 at 10:08PM by Will-from-CloudIAM
via reddit https://ift.tt/qc6aH2t
Cloud-Iam
Our resilience against cyber attacks
As an IAM SaaS company, our work often remains in the shadows—until something goes wrong. Today, I want to shed light on how we handle security at the very first layer all IAM systems have: the login page. Specifically, I’ll walk you through an incident we…
Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails
https://ift.tt/JW1rmL7
Submitted June 27, 2025 at 10:16AM by No-Reputation7691
via reddit https://ift.tt/1lLWtij
https://ift.tt/JW1rmL7
Submitted June 27, 2025 at 10:16AM by No-Reputation7691
via reddit https://ift.tt/1lLWtij
Varonis
Ongoing Campaign Abuses Microsoft 365’s Direct Send to Deliver Phishing Emails
Varonis Threat Labs uncovered a phishing campaign with M365's Direct Send feature that spoofs internal users without ever needing to compromise an account.
Pertama Digital Partners Netsec To Strengthen Digital Security For Govt And Private Sector
https://ift.tt/jwqfYrs
Submitted June 27, 2025 at 03:04PM by hectormoodya
via reddit https://ift.tt/cJNVwG0
https://ift.tt/jwqfYrs
Submitted June 27, 2025 at 03:04PM by hectormoodya
via reddit https://ift.tt/cJNVwG0
BusinessToday
Pertama Digital Partners Netsec To Strengthen Digital Security For Govt And Private Sector - BusinessToday
Pertama Digital Bhd (PDB) is collaborating with Netsec Sdn Bhd to enhance the security, resilience and performance of digital platforms for both the government and private sectors. In a statement, PDB said this partnership addresses the rising complexity…
Demystifying MCP (Model Context Protocol): 3 Common Misconceptions
https://ift.tt/3AuLs5D
Submitted June 27, 2025 at 06:52PM by hectormoodya
via reddit https://ift.tt/ieL57m9
https://ift.tt/3AuLs5D
Submitted June 27, 2025 at 06:52PM by hectormoodya
via reddit https://ift.tt/ieL57m9
www.pynt.io
Demystifying MCP (Model Context Protocol): 3 Common Mis
in this article, we delve deeper into three commonly misunderstood aspects of MCP, providing clarity to help developers, integrators, and security professionals safely leverage MCP-based technologies.
End-to-End Encryption: Architecturally Necessary
https://ift.tt/Npv1XwY
Submitted June 27, 2025 at 08:15PM by MagicianPutrid5245
via reddit https://ift.tt/vHuGbqd
https://ift.tt/Npv1XwY
Submitted June 27, 2025 at 08:15PM by MagicianPutrid5245
via reddit https://ift.tt/vHuGbqd
RIPE Labs
End-to-End Encryption: Architecturally Necessary
Good intentions don’t always result in good outcomes. This is especially the case with recent suggestions regarding end-to-end-encryption adaptability requirements for number independent communication services. Not only is security an issue, the suggestions…
When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365"
https://ift.tt/WPkXcea
Submitted June 28, 2025 at 01:05AM by parzel
via reddit https://ift.tt/klgSMBw
https://ift.tt/WPkXcea
Submitted June 28, 2025 at 01:05AM by parzel
via reddit https://ift.tt/klgSMBw
Modzero
When Backups Open Backdoors: Accessing Sensitive Cloud Data via "Synology Active Backup for Microsoft 365" / modzero
Leveraging Google's Agent Development Kit for Automated Threat Analysis
https://ift.tt/0FMmPnD
Submitted June 29, 2025 at 07:07AM by blkmanta
via reddit https://ift.tt/Jzr1X9V
https://ift.tt/0FMmPnD
Submitted June 29, 2025 at 07:07AM by blkmanta
via reddit https://ift.tt/Jzr1X9V
manta.black
Leveraging Google Adk For Cyber Intelligence
Over the past month, I’ve been working on a project for the Google ADK agent hackathon. This post provides an overview of my current multi-agent system, used for threat intelligence gathering, processing, and analysis.
Comparing Semgrep Community and Code for Static Analysis
https://ift.tt/0C7j9vN
Submitted June 30, 2025 at 02:56PM by nibblesec
via reddit https://ift.tt/t0xKDS2
https://ift.tt/0C7j9vN
Submitted June 30, 2025 at 02:56PM by nibblesec
via reddit https://ift.tt/t0xKDS2
New free 7h OpenSecurityTraining2 class: "Fuzzing 1001: Introductory white-box fuzzing with AFL++" by Francesco Pollicino is now released
https://ift.tt/FOZLb6j
Submitted June 30, 2025 at 04:30PM by OpenSecurityTraining
via reddit https://ift.tt/8Me96h7
https://ift.tt/FOZLb6j
Submitted June 30, 2025 at 04:30PM by OpenSecurityTraining
via reddit https://ift.tt/8Me96h7
p.ost2.fyi
Fuzzing 1001: Introductory white-box fuzzing with AFL++
Are you looking for an automated way to find bugs in your code? In this course, you'll learn how to use AFL++ to test and identify vulnerabilities, leveraging a white-box approach to make your testing more efficient and targeted. By the end, you'll be ready…
État de l’art sur le phishing Azure en 2025 (partie 1) – Device code flow
https://ift.tt/oFYnEgL
Submitted June 30, 2025 at 07:49PM by MobetaSec
via reddit https://ift.tt/IiFswb8
https://ift.tt/oFYnEgL
Submitted June 30, 2025 at 07:49PM by MobetaSec
via reddit https://ift.tt/IiFswb8
Mobeta
Phishing Azure : Exploiter le Device Code Flow et se protéger
Découvrez comment le device code flow peut être détourné pour du phishing sur Azure Entra ID et comment s’en protéger avec une Conditional Access Policy.
Chrome’s AppBound Cookie Encryption Bypassed via Side-Channel Timing Attack
https://ift.tt/JY0WtlO
Submitted June 30, 2025 at 09:12PM by ES_CY
via reddit https://ift.tt/m78Bbho
https://ift.tt/JY0WtlO
Submitted June 30, 2025 at 09:12PM by ES_CY
via reddit https://ift.tt/m78Bbho
Cyberark
C4 Bomb: Blowing Up Chrome’s AppBound Cookie Encryption
In July 2024, Google introduced a new feature to better protect cookies in Chrome: AppBound Cookie Encryption. This new feature was able to disrupt the world of infostealers, forcing the malware...
C4 Bomb: Blowing Up Chrome’s AppBound Cookie Encryption
https://ift.tt/JY0WtlO
Submitted June 30, 2025 at 10:40PM by ES_CY
via reddit https://ift.tt/y1SIduA
https://ift.tt/JY0WtlO
Submitted June 30, 2025 at 10:40PM by ES_CY
via reddit https://ift.tt/y1SIduA
Cyberark
C4 Bomb: Blowing Up Chrome’s AppBound Cookie Encryption
In July 2024, Google introduced a new feature to better protect cookies in Chrome: AppBound Cookie Encryption. This new feature was able to disrupt the world of infostealers, forcing the malware...