Fine-grained HTTP filtering for Claude Code
https://ift.tt/VdkZawq
Submitted September 13, 2025 at 02:46AM by ammarbandukwala
via reddit https://ift.tt/vdrKF5O
https://ift.tt/VdkZawq
Submitted September 13, 2025 at 02:46AM by ammarbandukwala
via reddit https://ift.tt/vdrKF5O
ammar.io
Fine-grained HTTP filtering for Claude Code
Default‑deny HTTP(S) for dev tools and AI agents. Script rules in JS or shell, log every request, and keep egress within your policy.
🛡️ I’ve started a Pentesting Weekly Digest — would love your feedback & thoughts!
https://ift.tt/RBQLJzc
Submitted September 13, 2025 at 11:22AM by Western-Fox-5184
via reddit https://ift.tt/pNSuhtq
https://ift.tt/RBQLJzc
Submitted September 13, 2025 at 11:22AM by Western-Fox-5184
via reddit https://ift.tt/pNSuhtq
Substack
Pentesting Weekly Digest — September 8–12, 2025
Welcome to the first issue of Pentesting Weekly Digest — your curated roundup of the most important news, tools, and vulnerabilities from the world of penetration testing and cybersecurity.
WSASS - Old But Gold, Dumping LSASS With Windows Error Reporting On Modern Windows 11
https://ift.tt/3gLhplH
Submitted September 13, 2025 at 01:08PM by Cold-Dinosaur
via reddit https://ift.tt/Z3aHAb6
https://ift.tt/3gLhplH
Submitted September 13, 2025 at 01:08PM by Cold-Dinosaur
via reddit https://ift.tt/Z3aHAb6
Zerosalarium
Old But Gold, Dumping LSASS With Windows Error Reporting On Modern Windows 11
Use the offensive tool WSASS to dump the LSASS memory area by exploiting the vulnerability in WerFaultSecure.exe
2025 Supabase Security Best Practices Guide - Common Misconfigs from Recent Pentests.
https://ift.tt/PvNqBem
Submitted September 15, 2025 at 12:37AM by thatsabingo98
via reddit https://ift.tt/URy4xW1
https://ift.tt/PvNqBem
Submitted September 15, 2025 at 12:37AM by thatsabingo98
via reddit https://ift.tt/URy4xW1
Pentestly.io
Harden Your Supabase: Lessons from Real-World Pentests | Pentestly.io Blog
Harden Supabase with the following cheat-sheet with clear steps for RLS, schemas, Edge Functions, Storage, CORS and tokens. Built from real audits.
New OpenSecurityTraining2 class: "TPM 2.0 Programming using Python and the tpm2-pytss libraries" (~13 hours)
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 04:05AM by OpenSecurityTraining
via reddit https://ift.tt/Qy3jIVb
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 04:05AM by OpenSecurityTraining
via reddit https://ift.tt/Qy3jIVb
p.ost2.fyi
TPM 2.0 Programming using Python and the tpm2-pytss libraries
This course provides a comprehensive introduction to Trusted Platform Module (TPM) 2.0 programming using the Python-based tpm2-pytss library.
New OpenSecurityTraining2 class: "TPM 2.0 Programming using Python and the tpm2-pytss libraries" (~13 hours)
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 05:00AM by OpenSecurityTraining
via reddit https://ift.tt/dY6Ihvt
https://ost2.fyi/TC2202
Submitted September 15, 2025 at 05:00AM by OpenSecurityTraining
via reddit https://ift.tt/dY6Ihvt
p.ost2.fyi
TPM 2.0 Programming using Python and the tpm2-pytss libraries
This course provides a comprehensive introduction to Trusted Platform Module (TPM) 2.0 programming using the Python-based tpm2-pytss library.
Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic…
https://ift.tt/15mUQJf
Submitted September 15, 2025 at 06:18AM by thewatcher_
via reddit https://ift.tt/QmDYpAa
https://ift.tt/15mUQJf
Submitted September 15, 2025 at 06:18AM by thewatcher_
via reddit https://ift.tt/QmDYpAa
Medium
Strategies for Analyzing Native Code in Android Applications: Combining Ghidra and Symbolic…
In my work analyzing native code in Android applications, I often try different techniques. Some work, others not so much. I’ve realized I…
pyLDAPGui - Python based GUI for browsing LDAP
https://ift.tt/RC6Q1mZ
Submitted September 15, 2025 at 06:55AM by ZephrX112
via reddit https://ift.tt/oY6KTG0
https://ift.tt/RC6Q1mZ
Submitted September 15, 2025 at 06:55AM by ZephrX112
via reddit https://ift.tt/oY6KTG0
ZephrSec - Adventures In Information Security
pyLDAPGui - How It was Born
Python-based LDAP browser with GUI for AD pentesting & red teaming. Cross-platform PoC tool for exporting, searching & BloodHound integration.
GitHub Actions: A Cloudy Day for Security - Part 2
https://ift.tt/boQ0RaO
Submitted September 15, 2025 at 12:17PM by BinarySecurity
via reddit https://ift.tt/9LmhzHg
https://ift.tt/boQ0RaO
Submitted September 15, 2025 at 12:17PM by BinarySecurity
via reddit https://ift.tt/9LmhzHg
Binary Security AS
GitHub Actions: A Cloudy Day for Security - Part 2
Binary Security spend a lot of time testing and securing CI/CD setups, especially GitHub Actions. In this two-part series we cover some of the many security considerations when using GitHub Actions, with a focus on securing your CI/CD pipeline against adversaries…
Playing with HTTP/2 CONNECT
https://ift.tt/2KC5N3x
Submitted September 15, 2025 at 11:41PM by Kingflomb
via reddit https://ift.tt/vZGgKyB
https://ift.tt/2KC5N3x
Submitted September 15, 2025 at 11:41PM by Kingflomb
via reddit https://ift.tt/vZGgKyB
blog.flomb.net
Playing with HTTP/2 CONNECT
In HTTP/1, the CONNECT method instructs a proxy to establish a TCP tunnel to a requested target. Once the tunnel is up, the proxy blindly forwards raw traffic in both directions. This mechanism is most commonly used to tunnel TLS traffic through forwarding…
ctrl/tinycolor and 40+ NPM Packages Compromised
https://ift.tt/ZCz1a8j
Submitted September 16, 2025 at 07:15AM by kurmiashish
via reddit https://ift.tt/K4rG2Cd
https://ift.tt/ZCz1a8j
Submitted September 16, 2025 at 07:15AM by kurmiashish
via reddit https://ift.tt/K4rG2Cd
www.stepsecurity.io
Shai-Hulud: Self-Replicating Worm Compromises 500+ NPM Packages - StepSecurity
The Shai-Hulud worm has infected over 500 NPM packages including @ctrl/tinycolor in an unprecedented self-propagating supply chain attack. The malware harvests AWS/GCP/Azure credentials using TruffleHog, establishes persistence through GitHub Actions backdoors…
New LG Vulnerability - LG WebOS TV Path Traversal, Authentication Bypass and Full Device Takeover
https://ift.tt/X3pvI5e
Submitted September 16, 2025 at 05:08PM by SSDisclosure
via reddit https://ift.tt/6khyvZp
https://ift.tt/X3pvI5e
Submitted September 16, 2025 at 05:08PM by SSDisclosure
via reddit https://ift.tt/6khyvZp
SSD Secure Disclosure
LG WebOS TV Path Traversal, Authentication Bypass and Full Device Takeover - SSD Secure Disclosure
Affected Versions Vendor Response The vendor has issued an advisory SMR-SEP-2025, available at: https://lgsecurity.lge.com/bulletins/tv in regard to the below described vulnerability Credit The vulnerability was disclosed during our TyphoonPWN 2025 LG Category…
NPM Supply Side Attack - S1ngularity/nx attackers strike again
https://ift.tt/43qGX9O
Submitted September 16, 2025 at 08:56PM by sheepfiend
via reddit https://ift.tt/0N1uoxj
https://ift.tt/43qGX9O
Submitted September 16, 2025 at 08:56PM by sheepfiend
via reddit https://ift.tt/0N1uoxj
www.aikido.dev
S1ngularity/nx attackers strike again
The attackers behind the nx attack have struck again, targeting a large amount of packages, with a first-of-its-kind worm payload.
Dissecting DCOM part 1
https://ift.tt/wWckqg3
Submitted September 17, 2025 at 12:19AM by bagaudin
via reddit https://ift.tt/LFxOjN4
https://ift.tt/wWckqg3
Submitted September 17, 2025 at 12:19AM by bagaudin
via reddit https://ift.tt/LFxOjN4
Synacktiv
Dissecting DCOM part 1
Why I’m going back to the AI Agent Security Summit
https://ift.tt/k0u8Lgw
Submitted September 17, 2025 at 05:34AM by Zemgineer2084
via reddit https://ift.tt/dWZGSc2
https://ift.tt/k0u8Lgw
Submitted September 17, 2025 at 05:34AM by Zemgineer2084
via reddit https://ift.tt/dWZGSc2
Zenity | Secure AI Agents Everywhere
AI Agent Security | AI Agent Security Summit 2025 | Zenity
After launching in NYC, the AI Agent Security Summit heads to San Francisco to continue shaping how enterprises secure the next wave of AI.
Hosting a website on a disposable vape
https://bogdanthegeek.github.io/blog/projects/vapeserver/
Submitted September 17, 2025 at 04:04PM by Titokhan
via reddit https://ift.tt/ih4GkyQ
https://bogdanthegeek.github.io/blog/projects/vapeserver/
Submitted September 17, 2025 at 04:04PM by Titokhan
via reddit https://ift.tt/ih4GkyQ
BogdanTheGeek's Blog
Hosting a WebSite on a Disposable Vape
Someone's trash is another person's web server.
Tiantong-1 and satphone security (part 1)
https://ift.tt/g1hNqr7
Submitted September 17, 2025 at 03:34PM by 2ROT13
via reddit https://ift.tt/niMsOHA
https://ift.tt/g1hNqr7
Submitted September 17, 2025 at 03:34PM by 2ROT13
via reddit https://ift.tt/niMsOHA
www.midnightblue.nl
Tiantong-1 and satphone security: part 1
First part in a series, delving into the previously unexplored Tiantong-1 satellite system, Huawei's Mate 60 Pro smartphone, and general satphone security.
VPN IPv6 leak
https://ift.tt/ZnSPlx1
Submitted September 17, 2025 at 03:34PM by anagogistis
via reddit https://ift.tt/xfY1O7C
https://ift.tt/ZnSPlx1
Submitted September 17, 2025 at 03:34PM by anagogistis
via reddit https://ift.tt/xfY1O7C
Anagogistis
PureVPN IPv6 leak
In late August 2025, I submitted two security reports to PureVPN under their VDP. Three weeks later, I’ve received no response, so I decided to publish the findings to inform other users.
The issues affect both their GUI (v2.10.0) and CLI (v2.0.1) clients…
The issues affect both their GUI (v2.10.0) and CLI (v2.0.1) clients…
Practical guide for hunters: how leaked webhooks are abused and how to defend them
https://ift.tt/0Bg25GV
Submitted September 17, 2025 at 06:05PM by unknownhad
via reddit https://ift.tt/90DQvOX
https://ift.tt/0Bg25GV
Submitted September 17, 2025 at 06:05PM by unknownhad
via reddit https://ift.tt/90DQvOX
Terminal
A step by step guide how to hack webhooks
Practical guide for hunters and defenders: hunting webhooks, detection, PoC examples and mitigations.
BIDI Swap: Unmasking the Art of URL Misleading with Bidirectional Text Tricks
https://ift.tt/yoJ7h0E
Submitted September 17, 2025 at 08:44PM by lohacker0
via reddit https://ift.tt/vySqtuJ
https://ift.tt/yoJ7h0E
Submitted September 17, 2025 at 08:44PM by lohacker0
via reddit https://ift.tt/vySqtuJ
Varonis
BIDI Swap: Unmasking the Art of URL Misleading with Bidirectional Text Tricks
Varonis reveals a decade-old Unicode flaw that enables BiDi URL spoofing and poses phishing risks. Learn how attackers exploit RTL/LTR noscripts and browser gaps.
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
https://ift.tt/DRluX7h
Submitted September 17, 2025 at 08:42PM by mepper
via reddit https://ift.tt/Xq0L1St
https://ift.tt/DRluX7h
Submitted September 17, 2025 at 08:42PM by mepper
via reddit https://ift.tt/Xq0L1St
dirkjanm.io
One Token to rule them all - obtaining Global Admin in every Entra ID tenant via Actor tokens
While preparing for my Black Hat and DEF CON talks in July of this year, I found the most impactful Entra ID vulnerability that I will probably ever find. One that could have allowed me to compromise every Entra ID tenant in the world (except probably those…