Hacking with AI SASTs: An overview of 'AI Security Engineers'
https://ift.tt/LKo0WFS
Submitted October 10, 2025 at 11:47AM by MegaManSec2
via reddit https://ift.tt/Ft0bcuS
https://ift.tt/LKo0WFS
Submitted October 10, 2025 at 11:47AM by MegaManSec2
via reddit https://ift.tt/Ft0bcuS
Joshua.Hu Joshua Rogers’ Scribbles
Hacking with AI SASTs: An overview of ‘AI Security Engineers’ / ‘LLM Security Scanners’ for Penetration Testers and Security Teams
Note: This post is complemented by a presentation I gave at KazHackStan 2025. The slides (which were prepared fewer than 24 hours before the actual presentation) for that talk can be found here, or in pptx format here.
IDA tips for reversing U-Boot
https://ift.tt/uHhOfZ9
Submitted October 10, 2025 at 03:24PM by gquere
via reddit https://ift.tt/cFHSlIk
https://ift.tt/uHhOfZ9
Submitted October 10, 2025 at 03:24PM by gquere
via reddit https://ift.tt/cFHSlIk
CISA Emergency Directive: AI-Powered Phishing Campaign Analysis - 300% Surge, $2.3B Q3 Losses
https://ift.tt/R4bw1fv
Submitted October 10, 2025 at 03:05PM by Street-Time-8159
via reddit https://ift.tt/FU1pxG3
https://ift.tt/R4bw1fv
Submitted October 10, 2025 at 03:05PM by Street-Time-8159
via reddit https://ift.tt/FU1pxG3
Cyber Updates 365
AI Phishing Attacks Surge 300% in US - CISA Emergency Alert - Cyber Updates 365
CISA emergency alert: AI phishing attacks surge 300% targeting US businesses. Expert defense strategies for AI-powered cyber threats in 2025.
Supply Chain Attack Vector Analysis: 250% Surge Prompts CISA Emergency Response
https://ift.tt/qZhwJbf
Submitted October 10, 2025 at 05:27PM by Hot_Lengthiness1173
via reddit https://ift.tt/YDka4ce
https://ift.tt/qZhwJbf
Submitted October 10, 2025 at 05:27PM by Hot_Lengthiness1173
via reddit https://ift.tt/YDka4ce
Cyber Updates 365
Supply Chain Cyber Attacks Surge 250% CISA Alert - Cyber Updates 365
Supply chain cyber attacks surge 250%. CISA emergency directive: 15+ Fortune 500 companies compromised. Massachusetts affected. October 2025.
Living off Node.js Addons
https://ift.tt/87BfSFs
Submitted October 10, 2025 at 07:48PM by ok_bye_now_
via reddit https://ift.tt/ts8XAh4
https://ift.tt/87BfSFs
Submitted October 10, 2025 at 07:48PM by ok_bye_now_
via reddit https://ift.tt/ts8XAh4
www.adversis.io
Living off Node.js Addons
Swap out compiled Node.js addons with your own code and force a legitimate Electron application load your code
More Than DoS (Progress Telerik UI for ASP.NET AJAX Unsafe Reflection CVE-2025-3600) - watchTowr Labs
https://ift.tt/8COIvjy
Submitted October 10, 2025 at 07:46PM by dx7r__
via reddit https://ift.tt/3njvBTW
https://ift.tt/8COIvjy
Submitted October 10, 2025 at 07:46PM by dx7r__
via reddit https://ift.tt/3njvBTW
watchTowr Labs
More Than DoS (Progress Telerik UI for ASP.NET AJAX Unsafe Reflection CVE-2025-3600)
Welcome back. We’re excited to yet again publish memes under the guise of research and inevitably receive hate mail. But today, we’ll be doing something slightly different to normal.
“Wow, watchTowr, will you actually be publishing useful information instead…
“Wow, watchTowr, will you actually be publishing useful information instead…
A Story About Bypassing Air Canada's In-flight Network Restrictions
https://ramsayleung.github.io/en/post/2025/a_story_about_bypassing_air_canadas_in-flight_network_restrictions/
Submitted October 11, 2025 at 08:47AM by SamrayLeung
via reddit https://ift.tt/NdG98kh
https://ramsayleung.github.io/en/post/2025/a_story_about_bypassing_air_canadas_in-flight_network_restrictions/
Submitted October 11, 2025 at 08:47AM by SamrayLeung
via reddit https://ift.tt/NdG98kh
In Pursuit of Simplicity
A Story About Bypassing Air Canada's In-flight Network Restrictions
1 Prologue
A while ago, I took a flight from Canada back to Hong Kong - about 12 hours in total with Air Canada.
Interestingly, the plane actually had WiFi:
However, the WiFi had restrictions. For Aeroplan…
A while ago, I took a flight from Canada back to Hong Kong - about 12 hours in total with Air Canada.
Interestingly, the plane actually had WiFi:
However, the WiFi had restrictions. For Aeroplan…
IAmAntimalware: Inject Malicious Code Into Antivirus
https://ift.tt/XZ63jhU
Submitted October 11, 2025 at 03:15PM by Cold-Dinosaur
via reddit https://ift.tt/oElHtbh
https://ift.tt/XZ63jhU
Submitted October 11, 2025 at 03:15PM by Cold-Dinosaur
via reddit https://ift.tt/oElHtbh
Zerosalarium
IAmAntimalware: Inject Malicious Code Into Antivirus
IAmAntimalware employs new red team techniques by cloning services of Antivirus. Allow inject code into processes whitelisted, protected by Antivirus
Blind Enumeration of gRPC Services
https://ift.tt/Wu3Sv8Z
Submitted October 12, 2025 at 09:08AM by ok_bye_now_
via reddit https://ift.tt/0RUYFyJ
https://ift.tt/Wu3Sv8Z
Submitted October 12, 2025 at 09:08AM by ok_bye_now_
via reddit https://ift.tt/0RUYFyJ
www.adversis.io
Blind Enumeration of gRPC Services
When you're handed an SDK with no documentation and told "the backend is secure because it's proprietary," grpc-scan helps prove otherwise
LLM Honeypot vs. Cryptojacking: Understanding the Enemy
https://ift.tt/EWtUe5A
Submitted October 13, 2025 at 08:34PM by mario_candela
via reddit https://ift.tt/S7w5uaI
https://ift.tt/EWtUe5A
Submitted October 13, 2025 at 08:34PM by mario_candela
via reddit https://ift.tt/S7w5uaI
Beelzebub
LLM Honeypot vs. Cryptojacking: Understanding the Enemy | AI deception platform
AI deception platform: Deceive, Detect, Respond. “You can’t defend. You can’t prevent. The only thing you can do is detect and respond.” Bruce Schneier. We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source…
(DEF CON 33) How I hacked over 1,000 car dealerships across the US
https://ift.tt/XaOvzxb
Submitted October 13, 2025 at 09:13PM by EatonZ
via reddit https://ift.tt/UIJVEyw
https://ift.tt/XaOvzxb
Submitted October 13, 2025 at 09:13PM by EatonZ
via reddit https://ift.tt/UIJVEyw
Eaton-Works
(DEF CON 33) How I hacked over 1,000 car dealerships across the US
On August 10, 2025 at DEF CON 33 in Las Vegas, I presented what could possibly be the biggest vulnerability I may ever discover in the automotive industry. Read and watch how I managed to take over a top automaker’s entire dealer ecosystem.
Finding Critical Bugs in Adobe Experience Manager
https://ift.tt/Vs7QcIu
Submitted October 14, 2025 at 09:45AM by Mempodipper
via reddit https://ift.tt/9INK45i
https://ift.tt/Vs7QcIu
Submitted October 14, 2025 at 09:45AM by Mempodipper
via reddit https://ift.tt/9INK45i
Searchlight Cyber
Finding Critical Bugs in Adobe Experience Manager › Searchlight Cyber
Adobe Experience Manager is one of the most popular CMSes around. Given its widespread use throughout the enterprise, you likely interact with AEM-based sites almost every day. From a security perspective, AEM presents an interesting target. AEM's popularity…
Streamlining Vulnerability Research with the idalib Rust Bindings for IDA 9.2 - HN Security
https://ift.tt/ZkU5dEl
Submitted October 14, 2025 at 01:57PM by 0xdea
via reddit https://ift.tt/Hq0lSmv
https://ift.tt/ZkU5dEl
Submitted October 14, 2025 at 01:57PM by 0xdea
via reddit https://ift.tt/Hq0lSmv
HN Security
Streamlining Vulnerability Research with the idalib Rust Bindings for IDA 9.2 - HN Security
HN Security's Technical Director Marco Ivaldi walks through using idalib's Rust bindings with IDA 9.2 to streamline vulnerability research.
Intents Android (1/2) : fonctionnement, sécurité et exemples d'attaques
https://ift.tt/xfCGv6y
Submitted October 14, 2025 at 04:58PM by MobetaSec
via reddit https://ift.tt/B3Xgpyu
https://ift.tt/xfCGv6y
Submitted October 14, 2025 at 04:58PM by MobetaSec
via reddit https://ift.tt/B3Xgpyu
Mobeta
Intents Android (1/2) : fonctionnement, sécurité et exemples d'attaques | Mobeta
Les Intents Android mal configurés peuvent exposer vos données. Découvrez comment éviter l’intent hijacking et sécuriser vos applications.
BombShell: UEFI shell vulnerabilities allow attackers to bypass Secure Boot on Framework Devices
https://ift.tt/5dUKuMI
Submitted October 14, 2025 at 11:52PM by Titokhan
via reddit https://ift.tt/Vm1CBhJ
https://ift.tt/5dUKuMI
Submitted October 14, 2025 at 11:52PM by Titokhan
via reddit https://ift.tt/Vm1CBhJ
Eclypsium | Supply Chain Security for the Modern Enterprise
BombShell: The Signed Backdoor Hiding in Plain Sight on Framework Devices
Eclypsium researchers have discovered UEFI shells, authorized via Secure Boot, on Framework laptops. The UEFI shells contain capabilities that allow attackers to bypass Secure Boot on roughly 200,000 affected Framework laptops and desktops.
MCP Snitch - The MCP Security Tool You Probably Need
https://ift.tt/ynvW7Uz
Submitted October 15, 2025 at 02:03AM by ok_bye_now_
via reddit https://ift.tt/DOd0PsZ
https://ift.tt/ynvW7Uz
Submitted October 15, 2025 at 02:03AM by ok_bye_now_
via reddit https://ift.tt/DOd0PsZ
www.adversis.io
The MCP Security Tool You Probably Need - MCP Snitch
The Model Context Protocol (MCP) has rapidly emerged as the standard for connecting AI agents to external tools and services. However, as the recent GitHub MCP vulnerability demonstrated, the protocol's power comes with significant security challenges. Malicious…
MORPHEUS – An AI code security analyzer that learns new vulnerabilities on its own
https://ift.tt/JCzHDpu
Submitted October 15, 2025 at 03:57AM by Far_Improvement_9437
via reddit https://ift.tt/IkvJ9hi
https://ift.tt/JCzHDpu
Submitted October 15, 2025 at 03:57AM by Far_Improvement_9437
via reddit https://ift.tt/IkvJ9hi
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit – Kyntra Blog
https://ift.tt/q5Bg8Ut
Submitted October 15, 2025 at 07:17PM by rkhunter_
via reddit https://ift.tt/Uqurk25
https://ift.tt/q5Bg8Ut
Submitted October 15, 2025 at 07:17PM by rkhunter_
via reddit https://ift.tt/Uqurk25
blog.kyntra.io
Singularity: Deep Dive into a Modern Stealth Linux Kernel Rootkit – Kyntra Blog
Deep dive into a modern stealth Linux kernel rootkit with advanced evasion and persistence techniques
yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242) - watchTowr Labs
https://ift.tt/71rZjNy
Submitted October 16, 2025 at 03:36PM by dx7r__
via reddit https://ift.tt/HFXSuMT
https://ift.tt/71rZjNy
Submitted October 16, 2025 at 03:36PM by dx7r__
via reddit https://ift.tt/HFXSuMT
watchTowr Labs
yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)
Note from editor: Before we begin, a big welcome to McCaulay Hudson, the newest member of the watchTowr Labs team with his inaugural blog post! Welcome to the mayhem, McCaulay!
Today is the 8th of November 1996, and we’re thrilled to be exploring this new…
Today is the 8th of November 1996, and we’re thrilled to be exploring this new…
Free to use , passive subdomain enumerator
https://ift.tt/vIFxb3c
Submitted October 16, 2025 at 06:29PM by Mparigas
via reddit https://ift.tt/JcmXkwB
https://ift.tt/vIFxb3c
Submitted October 16, 2025 at 06:29PM by Mparigas
via reddit https://ift.tt/JcmXkwB
yup.gr
yup.gr | Random Tools
A collection of free, tools focused on security and convenience, including SSL validation, Base64 encoding, and more.
Exploiting browser cache smuggling with COM Hijacking and steganography
https://ift.tt/8nL6MXw
Submitted October 17, 2025 at 02:18AM by not_wet_now
via reddit https://ift.tt/xHsGlQA
https://ift.tt/8nL6MXw
Submitted October 17, 2025 at 02:18AM by not_wet_now
via reddit https://ift.tt/xHsGlQA
Medium
Revisiting Browser Cache Smuggling
I recently came across an article detailing a campaign using browser cache smuggling and ClickFix to deliver malware to a system. I found…