MeetC2: Covert C2 framework
https://ift.tt/WlKnkO5
Submitted September 05, 2025 at 08:16AM by shantanu14g
via reddit https://ift.tt/YSEqfGk
https://ift.tt/WlKnkO5
Submitted September 05, 2025 at 08:16AM by shantanu14g
via reddit https://ift.tt/YSEqfGk
Medium
MeetC2 a.k.a Meeting C2
Background: Modern adversaries increasingly hide command-and-control (C2) traffic inside cloud services. We built this proof of concept…
Intercepting Thick Client TCP and TLS Traffic
https://ift.tt/UQGXVb3
Submitted September 05, 2025 at 07:09PM by Ano_F
via reddit https://ift.tt/Lr7vmNC
https://ift.tt/UQGXVb3
Submitted September 05, 2025 at 07:09PM by Ano_F
via reddit https://ift.tt/Lr7vmNC
Medium
Intercepting Thick Client TCP and TLS Traffic
Intercepting and analysing the traffic is one of the important parts of the pentest, whether it’s a mobile, web or desktop application. On…
TLS NoVerify: Bypass All The Things
https://f0rw4rd.github.io/posts/tls-noverify-bypass-all-the-things/
Submitted September 05, 2025 at 11:21PM by _f0rw4rd_
via reddit https://ift.tt/M9X6Aez
https://f0rw4rd.github.io/posts/tls-noverify-bypass-all-the-things/
Submitted September 05, 2025 at 11:21PM by _f0rw4rd_
via reddit https://ift.tt/M9X6Aez
f0rw4rd
TLS NoVerify: Bypass All The Things
Learn how to bypass TLS certificate validation on Linux using LD_PRELOAD for security research and debugging of embedded systems and native applications
The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows
https://ift.tt/yEU9Zzq
Submitted September 06, 2025 at 12:19AM by mabote
via reddit https://ift.tt/8lBpFLz
https://ift.tt/yEU9Zzq
Submitted September 06, 2025 at 12:19AM by mabote
via reddit https://ift.tt/8lBpFLz
GitGuardian Blog - Take Control of Your Secrets Security
The GhostAction Campaign: 3,325 Secrets Stolen Through Compromised GitHub Workflows
On September 5, 2025, GitGuardian discovered GhostAction, a massive supply chain attack affecting 327 GitHub users across 817 repositories. Attackers injected malicious workflows that exfiltrated 3,325 secrets, including PyPI, npm, and DockerHub tokens via…
Stealthy Persistence With Non-Existent Executable File
https://ift.tt/ecF5YlQ
Submitted September 06, 2025 at 12:30PM by Cold-Dinosaur
via reddit https://ift.tt/dZYy8v7
https://ift.tt/ecF5YlQ
Submitted September 06, 2025 at 12:30PM by Cold-Dinosaur
via reddit https://ift.tt/dZYy8v7
Zerosalarium
Stealthy Persistence With Non-Existent Executable File
Exploiting the mechanism that automatically searches for additional executable files when Windows detects that the requested file does not exist
High boy gadget for hackers
https://highboy.com.br/
Submitted September 06, 2025 at 07:42PM by NeighborhoodOdd1886
via reddit https://ift.tt/mX9kxWl
https://highboy.com.br/
Submitted September 06, 2025 at 07:42PM by NeighborhoodOdd1886
via reddit https://ift.tt/mX9kxWl
High Boy
High Boy - Advanced Hardware Hacking Tool
The ultimate device for pentesters and security enthusiasts. RF, NFC, BLE, and IoT analysis in one platform.
From Theory to Practice: How Small Language Models Are Revolutionizing Human Risk Psychology
https://ift.tt/P1frvWa
Submitted September 07, 2025 at 04:22AM by kaolay
via reddit https://ift.tt/6eBZuAN
https://ift.tt/P1frvWa
Submitted September 07, 2025 at 04:22AM by kaolay
via reddit https://ift.tt/6eBZuAN
Medium
From Theory to Practice: How Small Language Models Are Revolutionizing Cybersecurity Psychology
The human element continues to be cybersecurity’s weakest link. Despite organizations spending over $150 billion annually on security…
Worldcoin Advances Quantum-Secure AMPC With UTEC Peru
https://ift.tt/r7lWM6n
Submitted September 07, 2025 at 12:26PM by woltan_4
via reddit https://ift.tt/HNeAKsu
https://ift.tt/r7lWM6n
Submitted September 07, 2025 at 12:26PM by woltan_4
via reddit https://ift.tt/HNeAKsu
blockchainreporter
Worldcoin Advances Quantum-Secure AMPC With UTEC Peru
Worldcoin joins UTEC Peru to advance AMPC-driven quantum-secure technology to enhance privacy and academic validation for decentralized digital identity.
The Salesloft-Drift Breach: Analyzing the Biggest SaaS Breach of 2025
https://ift.tt/acf6sOH
Submitted September 07, 2025 at 12:47PM by woltan_4
via reddit https://ift.tt/T4WcHqL
https://ift.tt/acf6sOH
Submitted September 07, 2025 at 12:47PM by woltan_4
via reddit https://ift.tt/T4WcHqL
New OpenSecurityTraining2 class: "Bluetooth 2222: Bluetooth reconnaissance with Blue2thprinting" (~8 hours)
https://ost2.fyi/BT2222
Submitted September 07, 2025 at 07:32PM by OpenSecurityTraining
via reddit https://ift.tt/Ze6O9qF
https://ost2.fyi/BT2222
Submitted September 07, 2025 at 07:32PM by OpenSecurityTraining
via reddit https://ift.tt/Ze6O9qF
p.ost2.fyi
Bluetooth 2222: Bluetooth reconnaissance with Blue2thprinting
This class teaches Bluetooth reconnaissance & device identification using the Blue2thprinting software.
New iOS/macOS Critical DNG Image Processing Memory Corruption Exploitation Tutorial
https://ift.tt/Mr6iOa0
Submitted September 08, 2025 at 02:13AM by pwnguide
via reddit https://ift.tt/KEi1C3X
https://ift.tt/Mr6iOa0
Submitted September 08, 2025 at 02:13AM by pwnguide
via reddit https://ift.tt/KEi1C3X
killerPID-BOF
https://ift.tt/41EavSB
Submitted September 08, 2025 at 07:29AM by clod81
via reddit https://ift.tt/LEW7A0K
https://ift.tt/41EavSB
Submitted September 08, 2025 at 07:29AM by clod81
via reddit https://ift.tt/LEW7A0K
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Using AI Agents for Code Auditing: Full Walkthrough on Finding Security Bugs in a Rust REST Server with Hound
https://ift.tt/AIP5FNJ
Submitted September 08, 2025 at 08:28AM by Rude_Ad3947
via reddit https://ift.tt/GFB1a60
https://ift.tt/AIP5FNJ
Submitted September 08, 2025 at 08:28AM by Rude_Ad3947
via reddit https://ift.tt/GFB1a60
Medium
Hunting for Security Bugs in Code with AI Agents: A Full Walkthrough
In my previous article, I introduced Hound, an open-source code auditing tool that models the cognitive and organizational processes of…
GitHub Actions: A Cloudy Day for Security - Part 1
https://ift.tt/f9GQtSN
Submitted September 08, 2025 at 12:10PM by BinarySecurity
via reddit https://ift.tt/sAEUhHJ
https://ift.tt/f9GQtSN
Submitted September 08, 2025 at 12:10PM by BinarySecurity
via reddit https://ift.tt/sAEUhHJ
Binary Security AS
GitHub Actions: A Cloudy Day for Security - Part 1
Binary Security spend a lot of time testing and securing CI/CD setups, especially GitHub Actions. In this two-part series we cover some of the many security considerations when using GitHub Actions, with a focus on securing your CI/CD pipeline against adversaries…
Windows Defender's vulnerability: Break The Protective Shell Of Windows Defender With The Folder Redirect Technique
https://ift.tt/6JroCz7
Submitted September 08, 2025 at 07:17PM by Cold-Dinosaur
via reddit https://ift.tt/nc4KqjN
https://ift.tt/6JroCz7
Submitted September 08, 2025 at 07:17PM by Cold-Dinosaur
via reddit https://ift.tt/nc4KqjN
Zerosalarium
Break The Protective Shell Of Windows Defender With The Folder Redirect Technique
Exploiting vulnerability in the update mechanism of Windows Defender by using a symbolic link folder. Destroying or injecting code into Defender
Detect Suspicious/Malicious ICMP Echo Traffic - Using Behavioral and Protocol Semantic Analysis
https://ift.tt/I6iBjVU
Submitted September 08, 2025 at 07:00PM by MFMokbel
via reddit https://ift.tt/PqnsmiJ
https://ift.tt/I6iBjVU
Submitted September 08, 2025 at 07:00PM by MFMokbel
via reddit https://ift.tt/PqnsmiJ
PacketSmith
Detect Suspicious/Malicious ICMP Echo Traffic - PacketSmith
Detect Suspicious/Malicious ICMP Echo Traffic Using Behavioral and Protocol Semantic Analysis Introduction With release version 2.0, we have added a new advanced detection module to PacketSmith, with the sole objective of scanning for suspicious/malicious…
NPM Debug and Chalk Packages Compromised
https://ift.tt/ecBq0Zl
Submitted September 08, 2025 at 11:02PM by sheepfiend
via reddit https://ift.tt/1YDRVe7
https://ift.tt/ecBq0Zl
Submitted September 08, 2025 at 11:02PM by sheepfiend
via reddit https://ift.tt/1YDRVe7
www.aikido.dev
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
Department of War Doesn’t Defend its Web Streams From Hackers
https://ift.tt/VLXhHRm
Submitted September 09, 2025 at 12:22AM by eatfruitallday
via reddit https://ift.tt/zUWbrf1
https://ift.tt/VLXhHRm
Submitted September 09, 2025 at 12:22AM by eatfruitallday
via reddit https://ift.tt/zUWbrf1
The Intercept
Department of War Doesn’t Defend its Web Streams From Hackers
The Pentagon publicly posts the stream keys to its Facebook, YouTube, and X channels, exposing livestreams to account takeovers.
A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes
https://ift.tt/IUnD05c
Submitted September 10, 2025 at 01:10AM by 0xggus
via reddit https://ift.tt/CPgw8sc
https://ift.tt/IUnD05c
Submitted September 10, 2025 at 01:10AM by 0xggus
via reddit https://ift.tt/CPgw8sc
[Apple] Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
https://ift.tt/LTIHpGw
Submitted September 10, 2025 at 03:19AM by Pandalicious
via reddit https://ift.tt/pktP5Gc
https://ift.tt/LTIHpGw
Submitted September 10, 2025 at 03:19AM by Pandalicious
via reddit https://ift.tt/pktP5Gc
Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our advanced operating system security to provide industry-first…
Pwn My Ride: Apple CarPlay RCE - iAP2 protocol and CVE-2025-24132 Explained
https://ift.tt/FgpyYm2
Submitted September 10, 2025 at 02:13PM by cov_id19
via reddit https://ift.tt/7tejJMp
https://ift.tt/FgpyYm2
Submitted September 10, 2025 at 02:13PM by cov_id19
via reddit https://ift.tt/7tejJMp
www.oligo.security
Apple CarPlay Hacking Risks: CVE-2025-24132 Explained | Oligo Security
At DefCon, Oligo Security revealed critical Apple CarPlay vulnerabilities, including CVE-2025-24132 in the AirPlay SDK. Learn how attackers exploit iAP2 and AirPlay to compromise connected cars, and why patching delays leave vehicles exposed.