Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer | Datadog Security Labs
https://ift.tt/56BepXi
Submitted August 19, 2025 at 09:42PM by RedTermSession
via reddit https://ift.tt/j7QDlhc
https://ift.tt/56BepXi
Submitted August 19, 2025 at 09:42PM by RedTermSession
via reddit https://ift.tt/j7QDlhc
Datadoghq
Enumerating AWS the quiet way: CloudTrail-free discovery with Resource Explorer
Discover how attackers could quietly enumerate AWS resources via Resource Explorer, and how Datadog and AWS worked together to close the visibility gap.
Try to remember the stuff on here
https://ift.tt/9nVvSD8
Submitted August 19, 2025 at 11:33PM by babuloseo
via reddit https://ift.tt/IEePgoA
https://ift.tt/9nVvSD8
Submitted August 19, 2025 at 11:33PM by babuloseo
via reddit https://ift.tt/IEePgoA
United Nations
Universal Declaration of Human Rights | United Nations
A milestone document in the history of human rights, the Universal Declaration of Human Rights set out, for the first time, fundamental human rights to be universally protected. It has been translated into over 500 languages.
Researcher Exposes Zero-Day Clickjacking Vulnerabilities in Major Password Managers
https://socket.dev/blog/password-manager-clickjacking
Submitted August 20, 2025 at 03:59AM by JLLeitschuh
via reddit https://ift.tt/rP9HXZm
https://socket.dev/blog/password-manager-clickjacking
Submitted August 20, 2025 at 03:59AM by JLLeitschuh
via reddit https://ift.tt/rP9HXZm
Socket
Researcher Exposes Zero-Day Clickjacking Vulnerabilities in ...
Hacker Demonstrates How Easy It Is To Steal Data From Popular Password Managers
Copilot Broke Your Audit Log, but Microsoft Won’t Tell You
https://ift.tt/jQsGYe6
Submitted August 20, 2025 at 02:24PM by moviuro
via reddit https://ift.tt/vcyAgDY
https://ift.tt/jQsGYe6
Submitted August 20, 2025 at 02:24PM by moviuro
via reddit https://ift.tt/vcyAgDY
Pistachio
Copilot Broke Your Audit Log, but Microsoft Won’t Tell You
Guess Who Would Be Stupid Enough To Rob The Same Vault Twice? Pre-Auth RCE Chains in Commvault - watchTowr Labs
https://ift.tt/oJ4aZ9l
Submitted August 20, 2025 at 04:05PM by dx7r__
via reddit https://ift.tt/8Sfvn5q
https://ift.tt/oJ4aZ9l
Submitted August 20, 2025 at 04:05PM by dx7r__
via reddit https://ift.tt/8Sfvn5q
watchTowr Labs
Guess Who Would Be Stupid Enough To Rob The Same Vault Twice? Pre-Auth RCE Chains in Commvault
We’re back, and we’ve finished telling everyone that our name was on the back of Phrack!!!!1111
Whatever, nerds.
Today, we're back to scheduled content. Like our friendly neighbourhood ransomware gangs and APT groups, we've continued to spend irrational…
Whatever, nerds.
Today, we're back to scheduled content. Like our friendly neighbourhood ransomware gangs and APT groups, we've continued to spend irrational…
Engineered to Fail: The DNA of Negligent Defenses Operations
https://ift.tt/9okCsdH
Submitted August 20, 2025 at 09:18PM by Disscom
via reddit https://ift.tt/E1mgo7z
https://ift.tt/9okCsdH
Submitted August 20, 2025 at 09:18PM by Disscom
via reddit https://ift.tt/E1mgo7z
Medium
Engineered to Fail: The DNA of Negligent Cyber Defenses
Intro
Commvault plugs holes in backup suite that allow remote code executio
https://ift.tt/58K2LE6
Submitted August 20, 2025 at 11:31PM by Emotional-Plum-5970
via reddit https://ift.tt/9apN0ud
https://ift.tt/58K2LE6
Submitted August 20, 2025 at 11:31PM by Emotional-Plum-5970
via reddit https://ift.tt/9apN0ud
Help Net Security
Commvault plugs holes in backup suite that allow remote code execution
Commvault has fixed vulnerabilities that may allow attackers to compromise on-premises deployments of its flagship backup solution.
Google Unveils Enhanced Tools to Empower Defenders and Safeguard AI Progress
https://cyberpress.org/google-enhanced-tools/
Submitted August 21, 2025 at 01:21AM by innpattag
via reddit https://ift.tt/eL3hPiC
https://cyberpress.org/google-enhanced-tools/
Submitted August 21, 2025 at 01:21AM by innpattag
via reddit https://ift.tt/eL3hPiC
Cyber Security News
Google Unveils Enhanced Tools to Empower Defenders and Safeguard AI Progress
Google Enhanced Tools - Google announced a comprehensive suite of AI-powered security enhancements at the Google Cloud Security Summit.
New AI prompt/data-leak scanner — try to break it (PrivGuard)
https://privguard.io
Submitted August 21, 2025 at 05:56AM by Cold_Respond_7656
via reddit https://ift.tt/clL3uJv
https://privguard.io
Submitted August 21, 2025 at 05:56AM by Cold_Respond_7656
via reddit https://ift.tt/clL3uJv
PrivGuard
PrivGuard - Elite AI Security & Threat Intelligence Platform
Advanced AI security platform with real-time threat detection, prompt injection defense, and comprehensive monitoring. Protect your AI infrastructure from data leaks and security risks.
startup Horizon3.ai taps new CFO
https://ift.tt/3e2Ptkm
Submitted August 21, 2025 at 11:51AM by ohcopfur
via reddit https://ift.tt/02RNXTI
https://ift.tt/3e2Ptkm
Submitted August 21, 2025 at 11:51AM by ohcopfur
via reddit https://ift.tt/02RNXTI
CFO Dive
Cybersecurity startup Horizon3.ai taps new CFO
Founded in 2019, San Francisco-based Horizon3.ai in June completed a $100 million Series D funding round.
We Put Agentic AI Browsers to the Test - They Clicked, They Paid, They Failed
https://ift.tt/1vyN3b6
Submitted August 21, 2025 at 01:03PM by pinpepnet
via reddit https://ift.tt/X6QzlVv
https://ift.tt/1vyN3b6
Submitted August 21, 2025 at 01:03PM by pinpepnet
via reddit https://ift.tt/X6QzlVv
guard.io
"Scamlexity": When Agentic AI Browsers Get Scammed
We Put Agentic AI Browsers to the Test - They Clicked, They Paid, They Failed
Azure's Weakest Link - Full Cross-Tenant Compromise
https://ift.tt/P6RrQHs
Submitted August 21, 2025 at 07:21PM by BinarySecurity
via reddit https://ift.tt/ayh6SvY
https://ift.tt/P6RrQHs
Submitted August 21, 2025 at 07:21PM by BinarySecurity
via reddit https://ift.tt/ayh6SvY
Binary Security AS
Azure’s Weakest Link - Full Cross-Tenant Compromise
In my previous blog post Azure’s Weakest Link? I hinted at the existence of a hidden, globally shared, architecture that, if exploited, could allow for cross-tenant compromises. I can now reveal that this was indeed exploitable, and the massive potential…
🐪 Google CaMeL Security Visualizer - Defending Against Prompt Injections by Design
https://camel-security.github.io/
Submitted August 21, 2025 at 08:36PM by ok_bye_now_
via reddit https://ift.tt/blme6op
https://camel-security.github.io/
Submitted August 21, 2025 at 08:36PM by ok_bye_now_
via reddit https://ift.tt/blme6op
Reddit
From the netsec community on Reddit: 🐪 Google CaMeL Security Visualizer - Defending Against Prompt Injections by Design
Posted by ok_bye_now_ - 1 vote and 0 comments
AI can be used to create working exploits for published CVEs in a few minutes and for a few dollars
https://ift.tt/4bkaMng
Submitted August 21, 2025 at 09:49PM by valmarelox
via reddit https://ift.tt/rfQMAEK
https://ift.tt/4bkaMng
Submitted August 21, 2025 at 09:49PM by valmarelox
via reddit https://ift.tt/rfQMAEK
Substack
Can AI weaponize new CVEs in under 15 minutes?
If AI can mass-produce exploits, how much time do defenders really have left?
When a SSRF is enough: Full Docker Escape on Windows Docker Desktop (CVE-2025-9074)
https://ift.tt/3JL7oMA
Submitted August 21, 2025 at 10:59PM by Wanazabadee
via reddit https://ift.tt/yjWAKEJ
https://ift.tt/3JL7oMA
Submitted August 21, 2025 at 10:59PM by Wanazabadee
via reddit https://ift.tt/yjWAKEJ
CaMeL Security Demonstration - Defending Against (most) Prompt Injections by Design
https://camel-security.github.io/
Submitted August 22, 2025 at 03:35AM by ok_bye_now_
via reddit https://ift.tt/qGtZprQ
https://camel-security.github.io/
Submitted August 22, 2025 at 03:35AM by ok_bye_now_
via reddit https://ift.tt/qGtZprQ
Reddit
From the netsec community on Reddit: CaMeL Security Demonstration - Defending Against (most) Prompt Injections by Design
Posted by ok_bye_now_ - 1 vote and 0 comments
Silent Harvest: Extracting Windows Secrets Under the Radar
https://ift.tt/oClksij
Submitted August 22, 2025 at 10:47PM by mepper
via reddit https://ift.tt/vwdQj6M
https://ift.tt/oClksij
Submitted August 22, 2025 at 10:47PM by mepper
via reddit https://ift.tt/vwdQj6M
Sud0Ru
Silent Harvest: Extracting Windows Secrets Under the Radar
Once you gain a foothold on a Windows host, the next objective is often to compromise additional machines. The fastest way to achieve this is by harvesting credentials and other secrets for reuse. However, nowadays, most known techniques for collecting Windows…
MCP Hub > hackerone-mcp
https://ift.tt/086VzGS
Submitted August 23, 2025 at 11:51AM by Equal-Strike-2540
via reddit https://ift.tt/zMwjdsZ
https://ift.tt/086VzGS
Submitted August 23, 2025 at 11:51AM by Equal-Strike-2540
via reddit https://ift.tt/zMwjdsZ
MCP Hub
MCP Hub > hackerone-mcp
HackerOne API를 활용하여 버그 바운티 프로그램 정보, 공개된 보고서, 범위 등 다양한 데이터를 조회하고 분석하는 파이썬 기반 도구입니다.
Countering EDRs With The Backing Of Protected Process Light (PPL)
https://ift.tt/mzf4h9I
Submitted August 23, 2025 at 02:27PM by Cold-Dinosaur
via reddit https://ift.tt/OVvNjhl
https://ift.tt/mzf4h9I
Submitted August 23, 2025 at 02:27PM by Cold-Dinosaur
via reddit https://ift.tt/OVvNjhl
Zerosalarium
Countering EDRs With The Backing Of Protected Process Light (PPL)
Abusing the Clipup.exe program by using the CreateProcessAsPPL.exe tool to destroy the executable file of the EDRs, Antivirus.
New Algorithm Detects Active Hacking Groups Targeting Companies
https://ift.tt/crKTaJN
Submitted August 23, 2025 at 04:39PM by Disscom
via reddit https://ift.tt/GdmQez4
https://ift.tt/crKTaJN
Submitted August 23, 2025 at 04:39PM by Disscom
via reddit https://ift.tt/GdmQez4
Deepspecter
Deepspecter | Technical Due Diligence & Corporate Intelligence
Exposing digital fraud, regulatory evasion, and corporate manipulation through cyber intelligence. We investigate what others ignore.
VibeCoding VPN Deployment
https://ift.tt/cMlYyuh
Submitted August 23, 2025 at 10:43PM by Fit-Cut9562
via reddit https://ift.tt/Ab4JLt7
https://ift.tt/cMlYyuh
Submitted August 23, 2025 at 10:43PM by Fit-Cut9562
via reddit https://ift.tt/Ab4JLt7
ZephrSec - Adventures In Information Security
AI Assisted Dev aka Vibecoding
I used Claude to build ProxyGen, a multi-cloud WireGuard VPN tool. It needed tweaks but showed how far AI vibecoding can go, flaws and all.