The Salesloft-Drift Breach: Analyzing the Biggest SaaS Breach of 2025
https://ift.tt/acf6sOH
Submitted September 07, 2025 at 12:47PM by woltan_4
via reddit https://ift.tt/T4WcHqL
https://ift.tt/acf6sOH
Submitted September 07, 2025 at 12:47PM by woltan_4
via reddit https://ift.tt/T4WcHqL
New OpenSecurityTraining2 class: "Bluetooth 2222: Bluetooth reconnaissance with Blue2thprinting" (~8 hours)
https://ost2.fyi/BT2222
Submitted September 07, 2025 at 07:32PM by OpenSecurityTraining
via reddit https://ift.tt/Ze6O9qF
https://ost2.fyi/BT2222
Submitted September 07, 2025 at 07:32PM by OpenSecurityTraining
via reddit https://ift.tt/Ze6O9qF
p.ost2.fyi
Bluetooth 2222: Bluetooth reconnaissance with Blue2thprinting
This class teaches Bluetooth reconnaissance & device identification using the Blue2thprinting software.
New iOS/macOS Critical DNG Image Processing Memory Corruption Exploitation Tutorial
https://ift.tt/Mr6iOa0
Submitted September 08, 2025 at 02:13AM by pwnguide
via reddit https://ift.tt/KEi1C3X
https://ift.tt/Mr6iOa0
Submitted September 08, 2025 at 02:13AM by pwnguide
via reddit https://ift.tt/KEi1C3X
killerPID-BOF
https://ift.tt/41EavSB
Submitted September 08, 2025 at 07:29AM by clod81
via reddit https://ift.tt/LEW7A0K
https://ift.tt/41EavSB
Submitted September 08, 2025 at 07:29AM by clod81
via reddit https://ift.tt/LEW7A0K
Tier Zero Security
Information Security Services. Offensive Security, Penetration Testing, Mobile and Application, Purple Team, Red Team
Using AI Agents for Code Auditing: Full Walkthrough on Finding Security Bugs in a Rust REST Server with Hound
https://ift.tt/AIP5FNJ
Submitted September 08, 2025 at 08:28AM by Rude_Ad3947
via reddit https://ift.tt/GFB1a60
https://ift.tt/AIP5FNJ
Submitted September 08, 2025 at 08:28AM by Rude_Ad3947
via reddit https://ift.tt/GFB1a60
Medium
Hunting for Security Bugs in Code with AI Agents: A Full Walkthrough
In my previous article, I introduced Hound, an open-source code auditing tool that models the cognitive and organizational processes of…
GitHub Actions: A Cloudy Day for Security - Part 1
https://ift.tt/f9GQtSN
Submitted September 08, 2025 at 12:10PM by BinarySecurity
via reddit https://ift.tt/sAEUhHJ
https://ift.tt/f9GQtSN
Submitted September 08, 2025 at 12:10PM by BinarySecurity
via reddit https://ift.tt/sAEUhHJ
Binary Security AS
GitHub Actions: A Cloudy Day for Security - Part 1
Binary Security spend a lot of time testing and securing CI/CD setups, especially GitHub Actions. In this two-part series we cover some of the many security considerations when using GitHub Actions, with a focus on securing your CI/CD pipeline against adversaries…
Windows Defender's vulnerability: Break The Protective Shell Of Windows Defender With The Folder Redirect Technique
https://ift.tt/6JroCz7
Submitted September 08, 2025 at 07:17PM by Cold-Dinosaur
via reddit https://ift.tt/nc4KqjN
https://ift.tt/6JroCz7
Submitted September 08, 2025 at 07:17PM by Cold-Dinosaur
via reddit https://ift.tt/nc4KqjN
Zerosalarium
Break The Protective Shell Of Windows Defender With The Folder Redirect Technique
Exploiting vulnerability in the update mechanism of Windows Defender by using a symbolic link folder. Destroying or injecting code into Defender
Detect Suspicious/Malicious ICMP Echo Traffic - Using Behavioral and Protocol Semantic Analysis
https://ift.tt/I6iBjVU
Submitted September 08, 2025 at 07:00PM by MFMokbel
via reddit https://ift.tt/PqnsmiJ
https://ift.tt/I6iBjVU
Submitted September 08, 2025 at 07:00PM by MFMokbel
via reddit https://ift.tt/PqnsmiJ
PacketSmith
Detect Suspicious/Malicious ICMP Echo Traffic - PacketSmith
Detect Suspicious/Malicious ICMP Echo Traffic Using Behavioral and Protocol Semantic Analysis Introduction With release version 2.0, we have added a new advanced detection module to PacketSmith, with the sole objective of scanning for suspicious/malicious…
NPM Debug and Chalk Packages Compromised
https://ift.tt/ecBq0Zl
Submitted September 08, 2025 at 11:02PM by sheepfiend
via reddit https://ift.tt/1YDRVe7
https://ift.tt/ecBq0Zl
Submitted September 08, 2025 at 11:02PM by sheepfiend
via reddit https://ift.tt/1YDRVe7
www.aikido.dev
npm debug and chalk packages compromised
The popular packages debug and chalk on npm have been compromised with malicious code
Department of War Doesn’t Defend its Web Streams From Hackers
https://ift.tt/VLXhHRm
Submitted September 09, 2025 at 12:22AM by eatfruitallday
via reddit https://ift.tt/zUWbrf1
https://ift.tt/VLXhHRm
Submitted September 09, 2025 at 12:22AM by eatfruitallday
via reddit https://ift.tt/zUWbrf1
The Intercept
Department of War Doesn’t Defend its Web Streams From Hackers
The Pentagon publicly posts the stream keys to its Facebook, YouTube, and X channels, exposing livestreams to account takeovers.
A Technical Analysis on How a Chinese Company is Exporting The Great Firewall to Autocratic Regimes
https://ift.tt/IUnD05c
Submitted September 10, 2025 at 01:10AM by 0xggus
via reddit https://ift.tt/CPgw8sc
https://ift.tt/IUnD05c
Submitted September 10, 2025 at 01:10AM by 0xggus
via reddit https://ift.tt/CPgw8sc
[Apple] Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
https://ift.tt/LTIHpGw
Submitted September 10, 2025 at 03:19AM by Pandalicious
via reddit https://ift.tt/pktP5Gc
https://ift.tt/LTIHpGw
Submitted September 10, 2025 at 03:19AM by Pandalicious
via reddit https://ift.tt/pktP5Gc
Memory Integrity Enforcement: A complete vision for memory safety in Apple devices - Apple Security Research
Memory Integrity Enforcement (MIE) is the culmination of an unprecedented design and engineering effort spanning half a decade that combines the unique strengths of Apple silicon hardware with our advanced operating system security to provide industry-first…
Pwn My Ride: Apple CarPlay RCE - iAP2 protocol and CVE-2025-24132 Explained
https://ift.tt/FgpyYm2
Submitted September 10, 2025 at 02:13PM by cov_id19
via reddit https://ift.tt/7tejJMp
https://ift.tt/FgpyYm2
Submitted September 10, 2025 at 02:13PM by cov_id19
via reddit https://ift.tt/7tejJMp
www.oligo.security
Apple CarPlay Hacking Risks: CVE-2025-24132 Explained | Oligo Security
At DefCon, Oligo Security revealed critical Apple CarPlay vulnerabilities, including CVE-2025-24132 in the AirPlay SDK. Learn how attackers exploit iAP2 and AirPlay to compromise connected cars, and why patching delays leave vehicles exposed.
Kerberoasting
https://ift.tt/cW6iGV8
Submitted September 10, 2025 at 05:30PM by feross
via reddit https://ift.tt/dzViFEG
https://ift.tt/cW6iGV8
Submitted September 10, 2025 at 05:30PM by feross
via reddit https://ift.tt/dzViFEG
A Few Thoughts on Cryptographic Engineering
Kerberoasting
I learn about cryptographic vulnerabilities all the time, and they generally fill me with some combination of jealousy (“oh, why didn’t I think of that”) or else they impress me w…
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
https://thedfirreport.com/2025/09/08/blurring-the-lines-intrusion-shows-connection-with-three-major-ransomware-gangs/
Submitted September 10, 2025 at 07:27PM by gdraperi
via reddit https://ift.tt/wsF83WL
https://thedfirreport.com/2025/09/08/blurring-the-lines-intrusion-shows-connection-with-three-major-ransomware-gangs/
Submitted September 10, 2025 at 07:27PM by gdraperi
via reddit https://ift.tt/wsF83WL
The DFIR Report
Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Key Takeaways The intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped SectopRAT malware. The threat actor d…
You Already Have Our Personal Data, Take Our Phone Calls Too (FreePBX CVE-2025-57819) - watchTowr Labs
https://ift.tt/AUIKJ20
Submitted September 10, 2025 at 08:19PM by dx7r__
via reddit https://ift.tt/sp93hnH
https://ift.tt/AUIKJ20
Submitted September 10, 2025 at 08:19PM by dx7r__
via reddit https://ift.tt/sp93hnH
watchTowr Labs
You Already Have Our Personal Data, Take Our Phone Calls Too (FreePBX CVE-2025-57819)
We’re back - it’s a day, in a month, in a year - and once again, something has happened.
In this week’s episode of “the Internet is made of string and there is literally no evidence to suggest otherwise”, we present even further evidence that as a
In this week’s episode of “the Internet is made of string and there is literally no evidence to suggest otherwise”, we present even further evidence that as a
Stealing the keys from the octopus: Exfiltrate Git Credentials in Argocd
https://futuresight.club/posts/0x00_exfiltrate_git_credentials_argocd.html
Submitted September 11, 2025 at 03:02AM by Hakyza
via reddit https://ift.tt/YxsKMW6
https://futuresight.club/posts/0x00_exfiltrate_git_credentials_argocd.html
Submitted September 11, 2025 at 03:02AM by Hakyza
via reddit https://ift.tt/YxsKMW6
Reddit
From the netsec community on Reddit: Stealing the keys from the octopus: Exfiltrate Git Credentials in Argocd
Posted by Hakyza - 11 votes and 1 comment
Practice spotting typo squatted domains (Browser game: Typosquat Detective)
https://ift.tt/XICcsiL
Submitted September 11, 2025 at 03:09PM by unknownhad
via reddit https://ift.tt/BMh9U5l
https://ift.tt/XICcsiL
Submitted September 11, 2025 at 03:09PM by unknownhad
via reddit https://ift.tt/BMh9U5l
Inboxfuscation - a free, open-source obfuscation and detection framework to help security teams detect and stop Unicode-obfuscated Microsoft Exchange inbox rules
https://ift.tt/V0nepzh
Submitted September 11, 2025 at 08:12PM by permis0
via reddit https://ift.tt/ip82yhW
https://ift.tt/V0nepzh
Submitted September 11, 2025 at 08:12PM by permis0
via reddit https://ift.tt/ip82yhW
permiso.io
Inboxfuscation: Because Rules Are Meant to Be Broken
Permiso launches Inboxfuscation, an open-source tool enabling organizations to detect Unicode-obfuscated Microsoft Exchange inbox rules and secure Microsoft 365.
Windows KASLR Bypass - CVE-2025-53136
https://ift.tt/5wq6WjM
Submitted September 11, 2025 at 09:39PM by Void_Sec
via reddit https://ift.tt/4XVEZRL
https://ift.tt/5wq6WjM
Submitted September 11, 2025 at 09:39PM by Void_Sec
via reddit https://ift.tt/4XVEZRL
Crowdfense
NT OS Kernel Information Disclosure Vulnerability - CVE-2025-53136 - Crowdfense
Bidding farewell to one of the last kernel address leaks, CVE-2025-53136. Even patches can open new doors for exploitation.
IDOR: How I Could Delete Any Product Image on an E-Commerce Platform
https://ift.tt/Ta4soCI
Submitted September 12, 2025 at 08:07AM by General_Speaker9653
via reddit https://ift.tt/qhkd8nm
https://ift.tt/Ta4soCI
Submitted September 12, 2025 at 08:07AM by General_Speaker9653
via reddit https://ift.tt/qhkd8nm
Medium
IDOR: How I Could Delete Any Product Image on an E-Commerce Platform
Hello folks,