F5 Data Breach: What Happened and How It Impacts You
https://ift.tt/vAGZDSJ
Submitted October 19, 2025 at 09:02PM by digitalgiant01
via reddit https://ift.tt/IfBOcla
https://ift.tt/vAGZDSJ
Submitted October 19, 2025 at 09:02PM by digitalgiant01
via reddit https://ift.tt/IfBOcla
My Data Breach Attorney
F5 Data Breach | Trusted Data Breach Lawyers
Impacted by the F5 data breach? You may be ennoscriptd to legal compensation. My Data Breach Attorney can help protect your rights.
How a fake AI recruiter delivers five staged malware disguised as a dream job
https://ift.tt/DhIYmTB
Submitted October 20, 2025 at 05:06PM by shantanu14g
via reddit https://ift.tt/N9OefUa
https://ift.tt/DhIYmTB
Submitted October 20, 2025 at 05:06PM by shantanu14g
via reddit https://ift.tt/N9OefUa
Medium
How a fake AI recruiter delivers five staged malware disguised as a dream job
Overview
Tunneling WireGuard over HTTPS using Wstunnel
https://ift.tt/aptBOzK
Submitted October 20, 2025 at 11:07PM by 0bs1d1an-
via reddit https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/?utm_source=ifttt
https://ift.tt/aptBOzK
Submitted October 20, 2025 at 11:07PM by 0bs1d1an-
via reddit https://www.reddit.com/r/netsec/comments/1obogco/tunneling_wireguard_over_https_using_wstunnel/?utm_source=ifttt
Better-Auth Critical Account Takeover via Unauthenticated API Key Creation (CVE-2025-61928)
https://ift.tt/j4B7YzV
Submitted October 21, 2025 at 01:14AM by Prior-Penalty
via reddit https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/?utm_source=ifttt
https://ift.tt/j4B7YzV
Submitted October 21, 2025 at 01:14AM by Prior-Penalty
via reddit https://www.reddit.com/r/netsec/comments/1obrlhi/betterauth_critical_account_takeover_via/?utm_source=ifttt
CVE-2025-8078: ZYXEL Remote Code Execution via CLI Command Injection
https://ift.tt/bWekTsn
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/RUmZYdi
https://ift.tt/bWekTsn
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/RUmZYdi
Rainpwn
CVE-2025-8078: Remote Code Execution via CLI Command Injection
An undocumented parameter of the "web-auth" command could allow an authenticated attacker to execute commands remotely due to improper input sanitization, potentially resulting in full device compromise.
CVE-2025-9133: ZYXEL Configuration Exposure via Authorization Bypass
https://ift.tt/D6F7h0n
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/BtHJrea
https://ift.tt/D6F7h0n
Submitted October 21, 2025 at 11:07AM by Advanced_Rough8330
via reddit https://ift.tt/BtHJrea
Rainpwn
CVE-2025-9133: Configuration Exposure via Authorization Bypass
A vulnerability in the zysh-cgi component of the USG/ATP Series allows a low-privileged, semi-authenticated attacker to access the device’s configuration, bypassing authorization controls. This issue arises due to missing authorization checks and an incomplete…
[Article] Kerberos Security: Attacks and Detection
https://ift.tt/QeCdSq8
Submitted October 21, 2025 at 01:33PM by caster0x00
via reddit https://ift.tt/ol9x2ck
https://ift.tt/QeCdSq8
Submitted October 21, 2025 at 01:33PM by caster0x00
via reddit https://ift.tt/ol9x2ck
Caster
Parallax: Kerberos Security
This is research on detecting attacks on Kerberos using traffic analysis.
Stealth BGP Hijacks with uRPF Filtering
https://ift.tt/nb7raXt
Submitted October 21, 2025 at 05:20PM by krizhanovsky
via reddit https://ift.tt/nVcz6vP
https://ift.tt/nb7raXt
Submitted October 21, 2025 at 05:20PM by krizhanovsky
via reddit https://ift.tt/nVcz6vP
Microsoft 365 Copilot - Arbitrary Data Exfiltration Via Mermaid Diagrams
https://ift.tt/93UVGxw
Submitted October 21, 2025 at 06:30PM by logueadam
via reddit https://ift.tt/X3PeI1R
https://ift.tt/93UVGxw
Submitted October 21, 2025 at 06:30PM by logueadam
via reddit https://ift.tt/X3PeI1R
Casting a Net(ty) for Bugs, and Catching a Big One (CVE-2025-59419)
https://ift.tt/QT3uNGD
Submitted October 22, 2025 at 03:41AM by va_start
via reddit https://ift.tt/x0wMLuZ
https://ift.tt/QT3uNGD
Submitted October 22, 2025 at 03:41AM by va_start
via reddit https://ift.tt/x0wMLuZ
Depthfirst
DepthFirst | Casting a Net(ty) for Bugs, and Catching a Big One (CVE-2025-59419)
Our security agent found a business logic flaw in how Netty handled one of the internet's oldest and most trusted protocols. To understand the vulnerability, we need to take a quick journey back to the humble beginnings of email.
Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236)
https://ift.tt/26M8cVP
Submitted October 22, 2025 at 11:24AM by Mempodipper
via reddit https://ift.tt/6pCvFtz
https://ift.tt/26M8cVP
Submitted October 22, 2025 at 11:24AM by Mempodipper
via reddit https://ift.tt/6pCvFtz
Searchlight Cyber
Why nested deserialization is STILL harmful – Magento RCE (CVE-2025-54236) › Searchlight Cyber
Magento is still one of the most popular e-commerce solutions in use on the internet, estimated to be running on more than 130,000 websites. It is also offered as an enterprise offering by Adobe under the name Adobe Commerce, which receives automatic patching.…
Unlocking free WiFi on British Airways
https://ift.tt/6dri7AZ
Submitted October 22, 2025 at 11:08AM by arch-choot
via reddit https://ift.tt/mYflDt5
https://ift.tt/6dri7AZ
Submitted October 22, 2025 at 11:08AM by arch-choot
via reddit https://ift.tt/mYflDt5
saxrag
Unlocking free WiFi on British Airways
I was recently flying between HKG & LHR via British Airways. I’d done the same flight back in 2023, and remember relying on the in-flight entertainment for the 14 hour journey. However, this time on my way to London, they had an interesting offer: Free WiFi…
How ZeroPath's AI Code Scanner Won Over the curl Project with 170 Valid Bug Reports
https://ift.tt/6Ec7SAx
Submitted October 22, 2025 at 11:05AM by MegaManSec2
via reddit https://ift.tt/uOW3pQq
https://ift.tt/6Ec7SAx
Submitted October 22, 2025 at 11:05AM by MegaManSec2
via reddit https://ift.tt/uOW3pQq
Zeropath
How ZeroPath's AI Code Scanner Won Over the curl Project with 170 Valid Bug Reports - ZeroPath Blog
ZeroPath's AI-based static analyzer uncovered 170 verified issues in curl, from C footguns to logic and RFC compliance bugs across HTTP/3, SMTP, IMAP, TFTP, Telnet, and SSH/SFTP, with curl maintainer Daniel Stenberg praising the quality -- proof that AI source…
The security paradox of local LLMs
https://ift.tt/9VJSzfp
Submitted October 22, 2025 at 06:16PM by jakozaur
via reddit https://ift.tt/O6eZfMl
https://ift.tt/9VJSzfp
Submitted October 22, 2025 at 06:16PM by jakozaur
via reddit https://ift.tt/O6eZfMl
Quesma
The security paradox of local LLMs - Quesma Blog
Local LLMs prioritize privacy over security. Our research reveals a 95% backdoor injection success rate.
Cryptographic Issues in Cloudflare's Circl FourQ Implementation (CVE-2025-8556)
https://ift.tt/0OzmkH5
Submitted October 22, 2025 at 06:16PM by sh0oki
via reddit https://ift.tt/I7dismb
https://ift.tt/0OzmkH5
Submitted October 22, 2025 at 06:16PM by sh0oki
via reddit https://ift.tt/I7dismb
www.botanica.software
CVE-2025-8556 - Cryptographic Issues in Cloudflare’s CIRCL FourQ Implementation
2 min read
From Path Traversal to Supply Chain Compromise: Breaking MCP Server Hosting
https://ift.tt/sEOXTVy
Submitted October 22, 2025 at 07:29PM by mabote
via reddit https://ift.tt/pvyjbtL
https://ift.tt/sEOXTVy
Submitted October 22, 2025 at 07:29PM by mabote
via reddit https://ift.tt/pvyjbtL
GitGuardian Blog - Take Control of Your Secrets Security
From Path Traversal to Supply Chain Compromise: Breaking MCP Server Hosting
We found a path traversal vulnerability in Smithery.ai that compromised over 3,000 MCP servers and exposed thousands of API keys. Here's how a single Docker build bug nearly triggered one of the largest AI supply chain attacks to date.
Hey defenders — what are your “Nine Pillars” of security? (Chicago workshop + happy hour, Oct 29)
https://ift.tt/OnaMZNl
Submitted October 22, 2025 at 11:57PM by RedLeggTeam
via reddit https://ift.tt/LOsHqpZ
https://ift.tt/OnaMZNl
Submitted October 22, 2025 at 11:57PM by RedLeggTeam
via reddit https://ift.tt/LOsHqpZ
Redlegg
RedLegg | Workshop | The 9 Pillars of Practical Paranoia
Join Chris Young's workshop to discover the 9 core principles of infrastructure security. They are proven, repeatable, and often ignored.
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers | Brave
https://ift.tt/j1YWhHk
Submitted October 23, 2025 at 04:29PM by givafux
via reddit https://ift.tt/5DcpGbf
https://ift.tt/j1YWhHk
Submitted October 23, 2025 at 04:29PM by givafux
via reddit https://ift.tt/5DcpGbf
Brave
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers | Brave
AI browsers remain vulnerable to prompt injection attacks via screenshots and hidden content, allowing attackers to exploit users' authenticated sessions.
Modding And Distributing Mobile Apps with Frida
https://ift.tt/W5XiqpZ
Submitted October 23, 2025 at 07:32PM by Traditional_Steak841
via reddit https://ift.tt/H0RkaKv
https://ift.tt/W5XiqpZ
Submitted October 23, 2025 at 07:32PM by Traditional_Steak841
via reddit https://ift.tt/H0RkaKv
Pit's Proof Of Concept
Modding And Distributing Mobile Apps with Frida
Walkthrough of how to embed frida noscripts in apps to distribute proper mods. Supports frida 17+.
Leveraging Machine Learning to Enhance Acoustic Eavesdropping Attacks (Blog Series)
https://ift.tt/TURjHwa
Submitted October 23, 2025 at 07:27PM by cc-sw
via reddit https://ift.tt/wE64UAV
https://ift.tt/TURjHwa
Submitted October 23, 2025 at 07:27PM by cc-sw
via reddit https://ift.tt/wE64UAV
Privescing a Laptop with BitLocker + PIN
https://ift.tt/d1t5nBD
Submitted October 23, 2025 at 09:04PM by gquere
via reddit https://ift.tt/qTQVJd5
https://ift.tt/d1t5nBD
Submitted October 23, 2025 at 09:04PM by gquere
via reddit https://ift.tt/qTQVJd5