VED 2026: after CFI - data only
https://ift.tt/NIgFXVx
Submitted October 04, 2025 at 10:04AM by hardenedvault
via reddit https://ift.tt/DbOhd6R
https://ift.tt/NIgFXVx
Submitted October 04, 2025 at 10:04AM by hardenedvault
via reddit https://ift.tt/DbOhd6R
hardenedvault.net
VED 2026: after CFI - data only
after CFI - data only The exploitation techniques and mitigation has been evolving rapidly since the paper “Smash the Stack for Fun and Profit” released in Phrack Issue 49.
Upcoming Technical Security Talks & Workshops at BsidesNoVA – Oct 10–11 (Arlington VA)
https://bsidesnova.org
Submitted October 05, 2025 at 09:34PM by JackfruitDirect6803
via reddit https://ift.tt/mxr3ga8
https://bsidesnova.org
Submitted October 05, 2025 at 09:34PM by JackfruitDirect6803
via reddit https://ift.tt/mxr3ga8
Analyzing The Salesloft-Drift Breach
https://ift.tt/HykKMFv
Submitted October 06, 2025 at 01:11PM by Comfortable-Site8626
via reddit https://ift.tt/2hPsUvz
https://ift.tt/HykKMFv
Submitted October 06, 2025 at 01:11PM by Comfortable-Site8626
via reddit https://ift.tt/2hPsUvz
Taking remote control over industrial generators
https://ift.tt/jT5q2Vz
Submitted October 06, 2025 at 08:56PM by EatonZ
via reddit https://ift.tt/KLFaPpN
https://ift.tt/jT5q2Vz
Submitted October 06, 2025 at 08:56PM by EatonZ
via reddit https://ift.tt/KLFaPpN
Eaton-Works
Taking remote control over industrial generators
Industrial generator smart platform had insecure APIs that could enable remote control by anyone.
Well, Well, Well. It’s Another Day. (Oracle E-Business Suite Pre-Auth RCE Chain - CVE-2025-61882) - watchTowr Labs
https://ift.tt/6Rzdmax
Submitted October 06, 2025 at 11:13PM by dx7r__
via reddit https://ift.tt/70Sq3c6
https://ift.tt/6Rzdmax
Submitted October 06, 2025 at 11:13PM by dx7r__
via reddit https://ift.tt/70Sq3c6
watchTowr Labs
Well, Well, Well. It’s Another Day. (Oracle E-Business Suite Pre-Auth RCE Chain - CVE-2025-61882)
We bet you thought you’d be allowed to sit there, breathe, and savour the few moments of peace you’d earned after a painful week in cyber security.
Obviously, you were horribly wrong, and you need to wake up now - we’re back, it’s all on fire,
Obviously, you were horribly wrong, and you need to wake up now - we’re back, it’s all on fire,
Looking for community advice...
https://ift.tt/EYyb2rt
Submitted October 07, 2025 at 11:36PM by Expensive-Mix-4170
via reddit https://ift.tt/mkCrLAy
https://ift.tt/EYyb2rt
Submitted October 07, 2025 at 11:36PM by Expensive-Mix-4170
via reddit https://ift.tt/mkCrLAy
seclists.org
Full Disclosure: Re: [FD]
: "Glass Cage" – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201,…
: "Glass Cage" – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201,…
Bash a newline: Exploiting SSH via ProxyCommand, again (CVE-2025-61984)
https://ift.tt/J7reE4d
Submitted October 08, 2025 at 04:14PM by albinowax
via reddit https://ift.tt/WzdKgRl
https://ift.tt/J7reE4d
Submitted October 08, 2025 at 04:14PM by albinowax
via reddit https://ift.tt/WzdKgRl
Look mom HR application, look mom no job - phishing using Zoom docs to harvest Gmail creds
https://ift.tt/X0RupOL
Submitted October 08, 2025 at 06:33PM by unknownhad
via reddit https://ift.tt/X8OiNT7
https://ift.tt/X0RupOL
Submitted October 08, 2025 at 06:33PM by unknownhad
via reddit https://ift.tt/X8OiNT7
Himanshu Anand :: Threat Notes
look mom HR application look mom no job
TLDR
I have recieved a legit Zoom doc email from HR “while on job hunt” . It redirected to a site with a fake “bot protection” gate and then to a Gmail credential phish. The attackers exfiltrate creds live over WebSocket and even validate them in the backend.…
I have recieved a legit Zoom doc email from HR “while on job hunt” . It redirected to a site with a fake “bot protection” gate and then to a Gmail credential phish. The attackers exfiltrate creds live over WebSocket and even validate them in the backend.…
Why I Fired My AI Security Assistant (Sort Of)
https://ift.tt/pVMXJ5l
Submitted October 08, 2025 at 10:06PM by mdulin2
via reddit https://ift.tt/MOCmIp5
https://ift.tt/pVMXJ5l
Submitted October 08, 2025 at 10:06PM by mdulin2
via reddit https://ift.tt/MOCmIp5
Strikeout Security Blog
Why I Fired My AI Security Assistant (Sort Of)
LLMs can speed up security tasks like code comprehension and proof of concept creation. But, over-reliance risks missing subtle vulnerabilities and weakening core skills. How do we use LLMs optimally?
Exploiting CVE-2025-37947 (Linux kernel's ksmbd)
https://ift.tt/WfBtpe6
Submitted October 08, 2025 at 09:54PM by nibblesec
via reddit https://ift.tt/FvMSzrl
https://ift.tt/WfBtpe6
Submitted October 08, 2025 at 09:54PM by nibblesec
via reddit https://ift.tt/FvMSzrl
Doyensec
ksmbd - Exploiting CVE-2025-37947 (3/3)
This is the last of our posts about ksmbd. For the previous posts, see part1 and part2.
Compliance is a snake eating it's tail, and that's a good thing
https://ift.tt/MCcYpgU
Submitted October 08, 2025 at 11:58PM by Tiny_Ocelot4286
via reddit https://ift.tt/WCIBNZm
https://ift.tt/MCcYpgU
Submitted October 08, 2025 at 11:58PM by Tiny_Ocelot4286
via reddit https://ift.tt/WCIBNZm
Nabla
Compliance is a snake eating it's tail, and that's a good thing
Drawing parallels between niche concepts to the point it seems crazy (And maybe is) is one of the few perks of having impeccable pattern recognition
Active Directory domain (join)own accounts revisited 2025
https://ift.tt/N0BKYJy
Submitted October 08, 2025 at 11:46PM by ivxrehc
via reddit https://ift.tt/FC3jxT8
https://ift.tt/N0BKYJy
Submitted October 08, 2025 at 11:46PM by ivxrehc
via reddit https://ift.tt/FC3jxT8
Shelltrail - Swedish offensive security experts
Active Directory domain (join)own accounts revisited 2025 | Shelltrail - Swedish offensive security experts
The post walks through the usage and the security considerations of domain join accounts used in Active Directory
A Hands-On Edition: Will Supabase Be the Next Firebase (At Least in Terms of Security)?
https://ift.tt/91bIdc5
Submitted October 08, 2025 at 01:28AM by honk_n_stonk
via reddit https://ift.tt/YOlknda
https://ift.tt/91bIdc5
Submitted October 08, 2025 at 01:28AM by honk_n_stonk
via reddit https://ift.tt/YOlknda
M1Tz
A Hands-On Edition: Will Supabase Be the Next Firebase (At Least in Terms of Security)?
It all started with my good colleague @schniggie who’s got my attention with an X post earlier that year. Until then I rarely heared of Supabase, but let us start from the scratch.
Firebase changed the way developers think about backend infrastructure: auth…
Firebase changed the way developers think about backend infrastructure: auth…
From CPU Spikes to Defense
https://ift.tt/OXj68wA
Submitted October 09, 2025 at 08:04PM by Varonis-Dan
via reddit https://ift.tt/c2iHqxz
https://ift.tt/OXj68wA
Submitted October 09, 2025 at 08:04PM by Varonis-Dan
via reddit https://ift.tt/c2iHqxz
Varonis
From CPU Spikes to Defense: How Varonis Prevented a Ransomware Disaster
Discover how Varonis' advanced threat response ensured zero downtime and complete remediation when stopping a ransomware attack.
Security Analysis of a medical device: Methods and Findings
https://ift.tt/0PUJax5
Submitted October 09, 2025 at 09:17PM by cc-sw
via reddit https://ift.tt/wG769TL
https://ift.tt/0PUJax5
Submitted October 09, 2025 at 09:17PM by cc-sw
via reddit https://ift.tt/wG769TL
Hacking with AI SASTs: An overview of 'AI Security Engineers'
https://ift.tt/LKo0WFS
Submitted October 10, 2025 at 11:47AM by MegaManSec2
via reddit https://ift.tt/Ft0bcuS
https://ift.tt/LKo0WFS
Submitted October 10, 2025 at 11:47AM by MegaManSec2
via reddit https://ift.tt/Ft0bcuS
Joshua.Hu Joshua Rogers’ Scribbles
Hacking with AI SASTs: An overview of ‘AI Security Engineers’ / ‘LLM Security Scanners’ for Penetration Testers and Security Teams
Note: This post is complemented by a presentation I gave at KazHackStan 2025. The slides (which were prepared fewer than 24 hours before the actual presentation) for that talk can be found here, or in pptx format here.
IDA tips for reversing U-Boot
https://ift.tt/uHhOfZ9
Submitted October 10, 2025 at 03:24PM by gquere
via reddit https://ift.tt/cFHSlIk
https://ift.tt/uHhOfZ9
Submitted October 10, 2025 at 03:24PM by gquere
via reddit https://ift.tt/cFHSlIk
CISA Emergency Directive: AI-Powered Phishing Campaign Analysis - 300% Surge, $2.3B Q3 Losses
https://ift.tt/R4bw1fv
Submitted October 10, 2025 at 03:05PM by Street-Time-8159
via reddit https://ift.tt/FU1pxG3
https://ift.tt/R4bw1fv
Submitted October 10, 2025 at 03:05PM by Street-Time-8159
via reddit https://ift.tt/FU1pxG3
Cyber Updates 365
AI Phishing Attacks Surge 300% in US - CISA Emergency Alert - Cyber Updates 365
CISA emergency alert: AI phishing attacks surge 300% targeting US businesses. Expert defense strategies for AI-powered cyber threats in 2025.
Supply Chain Attack Vector Analysis: 250% Surge Prompts CISA Emergency Response
https://ift.tt/qZhwJbf
Submitted October 10, 2025 at 05:27PM by Hot_Lengthiness1173
via reddit https://ift.tt/YDka4ce
https://ift.tt/qZhwJbf
Submitted October 10, 2025 at 05:27PM by Hot_Lengthiness1173
via reddit https://ift.tt/YDka4ce
Cyber Updates 365
Supply Chain Cyber Attacks Surge 250% CISA Alert - Cyber Updates 365
Supply chain cyber attacks surge 250%. CISA emergency directive: 15+ Fortune 500 companies compromised. Massachusetts affected. October 2025.
Living off Node.js Addons
https://ift.tt/87BfSFs
Submitted October 10, 2025 at 07:48PM by ok_bye_now_
via reddit https://ift.tt/ts8XAh4
https://ift.tt/87BfSFs
Submitted October 10, 2025 at 07:48PM by ok_bye_now_
via reddit https://ift.tt/ts8XAh4
www.adversis.io
Living off Node.js Addons
Swap out compiled Node.js addons with your own code and force a legitimate Electron application load your code
More Than DoS (Progress Telerik UI for ASP.NET AJAX Unsafe Reflection CVE-2025-3600) - watchTowr Labs
https://ift.tt/8COIvjy
Submitted October 10, 2025 at 07:46PM by dx7r__
via reddit https://ift.tt/3njvBTW
https://ift.tt/8COIvjy
Submitted October 10, 2025 at 07:46PM by dx7r__
via reddit https://ift.tt/3njvBTW
watchTowr Labs
More Than DoS (Progress Telerik UI for ASP.NET AJAX Unsafe Reflection CVE-2025-3600)
Welcome back. We’re excited to yet again publish memes under the guise of research and inevitably receive hate mail. But today, we’ll be doing something slightly different to normal.
“Wow, watchTowr, will you actually be publishing useful information instead…
“Wow, watchTowr, will you actually be publishing useful information instead…