New Infection Chain and ConfuserEx-Based Obfuscation for DarkCloud Stealer
https://unit42.paloaltonetworks.com/new-darkcloud-stealer-infection-chain
Submitted August 07, 2025 at 08:08PM by Super_Weather3575
via reddit https://ift.tt/j0dAMDK
https://unit42.paloaltonetworks.com/new-darkcloud-stealer-infection-chain
Submitted August 07, 2025 at 08:08PM by Super_Weather3575
via reddit https://ift.tt/j0dAMDK
Unit 42
New Infection Chain and ConfuserEx-Based Obfuscation for DarkCloud Stealer
DarkCloud Stealer's delivery has shifted. We explore three different attack chains that use ConfuserEx obfuscation and a final payload in Visual Basic 6.
Greedy Bear —Massive Crypto Wallet Attack Spans Across Multiple Vectors
https://ift.tt/QI0boBV
Submitted August 07, 2025 at 07:47PM by Ok-Inflation-4706
via reddit https://ift.tt/jnIDC5i
https://ift.tt/QI0boBV
Submitted August 07, 2025 at 07:47PM by Ok-Inflation-4706
via reddit https://ift.tt/jnIDC5i
Medium
GreedyBear: 650 Attack Tools, One Coordinated Campaign
Today Koi exposes one of the most notorious attack groups we’ve yet to encounter — Greedy Bear. The group lunched a coordinated attack…
We replaced passwords with something worse
https://blog.danielh.cc/blog/passwords
Submitted August 08, 2025 at 01:06AM by innpattag
via reddit https://ift.tt/giaApKY
https://blog.danielh.cc/blog/passwords
Submitted August 08, 2025 at 01:06AM by innpattag
via reddit https://ift.tt/giaApKY
blog.danielh.cc
We replaced passwords with something worse | Blog - Daniel Huang
where my words occasionally escape /dev/null
CVE-2024-12718: Path Escape via Python’s tarfile Extraction Filters
https://ift.tt/v86YEiC
Submitted August 08, 2025 at 01:05AM by innpattag
via reddit https://ift.tt/FoMTqXC
https://ift.tt/v86YEiC
Submitted August 08, 2025 at 01:05AM by innpattag
via reddit https://ift.tt/FoMTqXC
Upwind | Cloud Security Happens at Runtime
CVE-2024-12718: Path Escape via Python’s tarfile Extraction Filters - Upwind
A newly disclosed vulnerability in Python’s standard library, CVE-2024-12718, allows attackers to modify file metadata or file permissions outside the
Prompt injection engineering for attackers: Exploiting GitHub Copilot
https://ift.tt/bRdJVBy
Submitted August 08, 2025 at 02:14AM by rkhunter_
via reddit https://ift.tt/Qc84XLS
https://ift.tt/bRdJVBy
Submitted August 08, 2025 at 02:14AM by rkhunter_
via reddit https://ift.tt/Qc84XLS
The Trail of Bits Blog
Prompt injection engineering for attackers: Exploiting GitHub Copilot
Prompt injection pervades discussions about security for LLMs and AI agents. But there is little public information on how to write powerful, discreet, and reliable prompt injection exploits. In this post, we will design and implement a prompt injection exploit…
Blog: Exploiting Retbleed in the real world
https://ift.tt/MtCPWj0
Submitted August 08, 2025 at 03:07AM by sirdarckcat
via reddit https://ift.tt/DVtsg5i
https://ift.tt/MtCPWj0
Submitted August 08, 2025 at 03:07AM by sirdarckcat
via reddit https://ift.tt/DVtsg5i
Google
Blog: Exploiting Retbleed in the real world
Curious to hear about our experience exploiting Retbleed (a security vulnerability affecting modern CPUs)? Then check out this post to see how we pushed the boundaries of Retbleed exploitation and understand more about the security implications of this exploit…
Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications
https://ift.tt/m57jsPZ
Submitted August 08, 2025 at 03:00AM by vaizor
via reddit https://ift.tt/bZGd8Jr
https://ift.tt/m57jsPZ
Submitted August 08, 2025 at 03:00AM by vaizor
via reddit https://ift.tt/bZGd8Jr
Eye Research
Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications
The Eye Security Research team has uncovered a new critical misconfiguration that exposed sensitive data at internal Microsoft applications.
SquareX launches open-source toolkits to defend browsers
https://ift.tt/Llpy691
Submitted August 08, 2025 at 11:20AM by shadowlurker_6
via reddit https://ift.tt/jfr7iDS
https://ift.tt/Llpy691
Submitted August 08, 2025 at 11:20AM by shadowlurker_6
via reddit https://ift.tt/jfr7iDS
ChannelLife Australia
SquareX launches open-source toolkits to defend browsers
SquareX launches two open-source toolkits to help security teams simulate and defend against browser-based attacks that evade traditional enterprise defences.
The Mental Material Revolution: Why Engineers Need to Become Cognitive Architects
https://ift.tt/0j47F1p
Submitted August 08, 2025 at 07:25PM by gabibeyo
via reddit https://ift.tt/Qak3LOr
https://ift.tt/0j47F1p
Submitted August 08, 2025 at 07:25PM by gabibeyo
via reddit https://ift.tt/Qak3LOr
Medium
The Mental Material Revolution: Why Engineers Need to Become Cognitive Architects
How context engineering is reshaping the future of AI development — and why your emotional intelligence might be your most valuable asset
The Silent Security Crisis: How AI Coding Assistants Are Creating Perfect Attack Blueprints
https://ift.tt/oXWnCqt
Submitted August 08, 2025 at 07:21PM by gabibeyo
via reddit https://ift.tt/CPYwmqe
https://ift.tt/oXWnCqt
Submitted August 08, 2025 at 07:21PM by gabibeyo
via reddit https://ift.tt/CPYwmqe
Medium
The Silent Security Crisis: How AI Coding Assistants Are Creating Perfect Attack Blueprints
The era of patient, methodical reconnaissance is over. Your AI coding assistant has already done all the work for attackers.
Unclaimed Google Play Store package
http://example.com
Submitted August 08, 2025 at 10:11PM by Accomplished-Dig4025
via reddit https://ift.tt/L1dEeqv
http://example.com
Submitted August 08, 2025 at 10:11PM by Accomplished-Dig4025
via reddit https://ift.tt/L1dEeqv
Reddit
[ Removed by moderator ] : r/netsec
540K subscribers in the netsec community. /r/netsec is a community-curated aggregator of technical information security content. Our mission is to extract signal from the noise — to provide value to security practitioners, students, researchers, and hackers…
Theori AIxCC writeup , 0day in sqlite + more
https://ift.tt/8rpl0gc
Submitted August 09, 2025 at 02:13AM by supernetworks
via reddit https://ift.tt/KhQl19s
https://ift.tt/8rpl0gc
Submitted August 09, 2025 at 02:13AM by supernetworks
via reddit https://ift.tt/KhQl19s
theori.io
Inside the brain of a hacking robot: Exploring traces | AI Cyber Challenge - Theori BLOG
Agent trajectory walkthroughs of a fully autonomous hacking system | AI for Security, AIxCC
Vulnerability Management Program - How to implement SLA and its processes
https://ift.tt/iQsASVb
Submitted August 09, 2025 at 08:58PM by pathetiq
via reddit https://ift.tt/TsGP3iu
https://ift.tt/iQsASVb
Submitted August 09, 2025 at 08:58PM by pathetiq
via reddit https://ift.tt/TsGP3iu
Security Autopsy
Vulnerability Management Program - How to implement SLA and its processes
Defining good SLAs is a tough challenge, but it’s at the heart of any solid vulnerability management program. This article helps internal security teams set clear SLAs, define the right metrics, and adjust their ticketing system to build a successful vulnerability…
Pentest Trick: Out of sight, out of mind with Windows Long File Names
https://ift.tt/MaSXfIN
Submitted August 10, 2025 at 07:58AM by Cold-Dinosaur
via reddit https://ift.tt/UgCuXF2
https://ift.tt/MaSXfIN
Submitted August 10, 2025 at 07:58AM by Cold-Dinosaur
via reddit https://ift.tt/UgCuXF2
Zerosalarium
Pentest Trick: Out of sight, out of mind with Windows Long File Names
Abusing Windows file names that exceed 260 characters to bypass the EDR's sample collection tool by the pentester. Redteam trick
AI-Powered Code Security Reviews for DevSecOps with Claude
https://ift.tt/MYoLzbf
Submitted August 11, 2025 at 12:33PM by mostafahussein
via reddit https://ift.tt/VbwtpKH
https://ift.tt/MYoLzbf
Submitted August 11, 2025 at 12:33PM by mostafahussein
via reddit https://ift.tt/VbwtpKH
Medium
AI-Powered Code Security Reviews for DevSecOps with Claude
Software is being built faster than ever, and that makes it easier for security issues to slip through. That’s why catching flaws early in…
Building an Autonomous AI Pentester: What Worked, What Didn’t, and Why It Matters
https://ift.tt/KCBXdlb
Submitted August 11, 2025 at 05:21PM by lenafuks
via reddit https://ift.tt/jrY0NEp
https://ift.tt/KCBXdlb
Submitted August 11, 2025 at 05:21PM by lenafuks
via reddit https://ift.tt/jrY0NEp
www.ultrared.ai
I Built an AI Hacker. It Failed Spectacularly | ULTRA RED Blog
Test Suite
https://ift.tt/mNOlxet
Submitted August 11, 2025 at 07:59PM by RealAspect2373
via reddit https://ift.tt/fQs9H5p
https://ift.tt/mNOlxet
Submitted August 11, 2025 at 07:59PM by RealAspect2373
via reddit https://ift.tt/fQs9H5p
Zenodo
Hybrid Computational Framework for Quantum and Resonance Simulation (Confirmed Test Results)
www.github.com/mandcony/quantoniumos It includes: RFT transform & symbolic state stability metrics Binary ↔ symbolic latency numbers Cross-platform reproducibility proof Cryptanalysis & randomness test results (Avalanche, NIST SP 800-22, Dieharder, TestU01)…
From Drone Strike to File Recovery: Outsmarting a Nation State
https://ift.tt/tUAeJmR
Submitted August 11, 2025 at 11:07PM by GelosSnake
via reddit https://ift.tt/2TgFpzj
https://ift.tt/tUAeJmR
Submitted August 11, 2025 at 11:07PM by GelosSnake
via reddit https://ift.tt/2TgFpzj
profero.io
From Drone Strike to File Recovery: Outsmarting a Nation State
Walk through our investigation workflow, cryptographic analysis, and end-to-end data-recovery strategy, proving that "encrypted" doesn't mean unrecoverable
FREE SECURITY CAREER EVENT
https://lu.ma/f6wn6ckp
Submitted August 12, 2025 at 11:02AM by ruthless0x0x
via reddit https://ift.tt/GD14pTN
https://lu.ma/f6wn6ckp
Submitted August 12, 2025 at 11:02AM by ruthless0x0x
via reddit https://ift.tt/GD14pTN
Luma
Unlock Cybersecurity Jobs - 2025 Ethical Hacking Careers · Luma
Want a high-paying, future-proof career in cybersecurity? Join us for an interactive session where industry experts breaks down everything you need to launch…
Windows OOBE Breakout Revived
https://ift.tt/Medqi9T
Submitted August 12, 2025 at 03:04PM by doitsukara
via reddit https://ift.tt/3Am9PsQ
https://ift.tt/Medqi9T
Submitted August 12, 2025 at 03:04PM by doitsukara
via reddit https://ift.tt/3Am9PsQ
blog.kanbach.org
Windows OOBE Breakout Revived
IT-Security and stuff - Windows OOBE Breakout Revived
Active Directory Enumeration – ADWS
https://ift.tt/Qiy0EZm
Submitted August 12, 2025 at 07:59PM by netbiosX
via reddit https://ift.tt/GFZjx16
https://ift.tt/Qiy0EZm
Submitted August 12, 2025 at 07:59PM by netbiosX
via reddit https://ift.tt/GFZjx16
Purple Team
Active Directory Enumeration – ADWS
Microsoft introduced Active Directory Web Services (ADWS) in Windows Server 2008 R2 as a method to provide an interface to instances for querying and managing Active Directory over a network. The s…