Unlocking free WiFi on British Airways
https://ift.tt/6dri7AZ
Submitted October 22, 2025 at 11:08AM by arch-choot
via reddit https://ift.tt/mYflDt5
https://ift.tt/6dri7AZ
Submitted October 22, 2025 at 11:08AM by arch-choot
via reddit https://ift.tt/mYflDt5
saxrag
Unlocking free WiFi on British Airways
I was recently flying between HKG & LHR via British Airways. I’d done the same flight back in 2023, and remember relying on the in-flight entertainment for the 14 hour journey. However, this time on my way to London, they had an interesting offer: Free WiFi…
How ZeroPath's AI Code Scanner Won Over the curl Project with 170 Valid Bug Reports
https://ift.tt/6Ec7SAx
Submitted October 22, 2025 at 11:05AM by MegaManSec2
via reddit https://ift.tt/uOW3pQq
https://ift.tt/6Ec7SAx
Submitted October 22, 2025 at 11:05AM by MegaManSec2
via reddit https://ift.tt/uOW3pQq
Zeropath
How ZeroPath's AI Code Scanner Won Over the curl Project with 170 Valid Bug Reports - ZeroPath Blog
ZeroPath's AI-based static analyzer uncovered 170 verified issues in curl, from C footguns to logic and RFC compliance bugs across HTTP/3, SMTP, IMAP, TFTP, Telnet, and SSH/SFTP, with curl maintainer Daniel Stenberg praising the quality -- proof that AI source…
The security paradox of local LLMs
https://ift.tt/9VJSzfp
Submitted October 22, 2025 at 06:16PM by jakozaur
via reddit https://ift.tt/O6eZfMl
https://ift.tt/9VJSzfp
Submitted October 22, 2025 at 06:16PM by jakozaur
via reddit https://ift.tt/O6eZfMl
Quesma
The security paradox of local LLMs - Quesma Blog
Local LLMs prioritize privacy over security. Our research reveals a 95% backdoor injection success rate.
Cryptographic Issues in Cloudflare's Circl FourQ Implementation (CVE-2025-8556)
https://ift.tt/0OzmkH5
Submitted October 22, 2025 at 06:16PM by sh0oki
via reddit https://ift.tt/I7dismb
https://ift.tt/0OzmkH5
Submitted October 22, 2025 at 06:16PM by sh0oki
via reddit https://ift.tt/I7dismb
www.botanica.software
CVE-2025-8556 - Cryptographic Issues in Cloudflare’s CIRCL FourQ Implementation
2 min read
From Path Traversal to Supply Chain Compromise: Breaking MCP Server Hosting
https://ift.tt/sEOXTVy
Submitted October 22, 2025 at 07:29PM by mabote
via reddit https://ift.tt/pvyjbtL
https://ift.tt/sEOXTVy
Submitted October 22, 2025 at 07:29PM by mabote
via reddit https://ift.tt/pvyjbtL
GitGuardian Blog - Take Control of Your Secrets Security
From Path Traversal to Supply Chain Compromise: Breaking MCP Server Hosting
We found a path traversal vulnerability in Smithery.ai that compromised over 3,000 MCP servers and exposed thousands of API keys. Here's how a single Docker build bug nearly triggered one of the largest AI supply chain attacks to date.
Hey defenders — what are your “Nine Pillars” of security? (Chicago workshop + happy hour, Oct 29)
https://ift.tt/OnaMZNl
Submitted October 22, 2025 at 11:57PM by RedLeggTeam
via reddit https://ift.tt/LOsHqpZ
https://ift.tt/OnaMZNl
Submitted October 22, 2025 at 11:57PM by RedLeggTeam
via reddit https://ift.tt/LOsHqpZ
Redlegg
RedLegg | Workshop | The 9 Pillars of Practical Paranoia
Join Chris Young's workshop to discover the 9 core principles of infrastructure security. They are proven, repeatable, and often ignored.
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers | Brave
https://ift.tt/j1YWhHk
Submitted October 23, 2025 at 04:29PM by givafux
via reddit https://ift.tt/5DcpGbf
https://ift.tt/j1YWhHk
Submitted October 23, 2025 at 04:29PM by givafux
via reddit https://ift.tt/5DcpGbf
Brave
Unseeable prompt injections in screenshots: more vulnerabilities in Comet and other AI browsers | Brave
AI browsers remain vulnerable to prompt injection attacks via screenshots and hidden content, allowing attackers to exploit users' authenticated sessions.
Modding And Distributing Mobile Apps with Frida
https://ift.tt/W5XiqpZ
Submitted October 23, 2025 at 07:32PM by Traditional_Steak841
via reddit https://ift.tt/H0RkaKv
https://ift.tt/W5XiqpZ
Submitted October 23, 2025 at 07:32PM by Traditional_Steak841
via reddit https://ift.tt/H0RkaKv
Pit's Proof Of Concept
Modding And Distributing Mobile Apps with Frida
Walkthrough of how to embed frida noscripts in apps to distribute proper mods. Supports frida 17+.
Leveraging Machine Learning to Enhance Acoustic Eavesdropping Attacks (Blog Series)
https://ift.tt/TURjHwa
Submitted October 23, 2025 at 07:27PM by cc-sw
via reddit https://ift.tt/wE64UAV
https://ift.tt/TURjHwa
Submitted October 23, 2025 at 07:27PM by cc-sw
via reddit https://ift.tt/wE64UAV
Privescing a Laptop with BitLocker + PIN
https://ift.tt/d1t5nBD
Submitted October 23, 2025 at 09:04PM by gquere
via reddit https://ift.tt/qTQVJd5
https://ift.tt/d1t5nBD
Submitted October 23, 2025 at 09:04PM by gquere
via reddit https://ift.tt/qTQVJd5
My AWS Account Got Hacked - Here Is What Happened
https://ift.tt/R74Ha1J
Submitted October 24, 2025 at 02:27AM by zvikizviki
via reddit https://ift.tt/tPCz6lN
https://ift.tt/R74Ha1J
Submitted October 24, 2025 at 02:27AM by zvikizviki
via reddit https://ift.tt/tPCz6lN
Zvi Wexlstein
My AWS Account Got Hacked - Here is What Happened
A detailed account of how my personal AWS account was compromised, the attack timeline, and lessons learned from a cloud security incident.
LockBit is attempting a comeback as a new ransomware variant "ChuongDong" targeting Windows, Linux, and ESXi
https://ift.tt/amp1UQE
Submitted October 24, 2025 at 08:47AM by rkhunter_
via reddit https://ift.tt/3Kq4uzg
https://ift.tt/amp1UQE
Submitted October 24, 2025 at 08:47AM by rkhunter_
via reddit https://ift.tt/3Kq4uzg
Check Point Blog
LockBit 5.0: Ransomware Gang Returns in Force
After a major takedown, LockBit is back with version 5.0, targeting Windows, Linux, and ESXi systems worldwide. Check Point Research reveals new victims.
TARMAGEDDON (CVE-2025-62518): RCE Vulnerability Highlights the challenges of open source abandonware
https://ift.tt/ySaKLBq
Submitted October 24, 2025 at 12:10PM by ukindom
via reddit https://ift.tt/KCoW7NL
https://ift.tt/ySaKLBq
Submitted October 24, 2025 at 12:10PM by ukindom
via reddit https://ift.tt/KCoW7NL
Edera
CVE-2025-62518 Shows the Cost of Open Source Abandonware
Edera uncovers TARmageddon (CVE-2025-62518), a Rust async-tar RCE flaw exposing the real dangers of open-source abandonware and supply chain security.
Pentesting Next.js Server Actions
https://ift.tt/Xb29coU
Submitted October 25, 2025 at 01:42AM by ok_bye_now_
via reddit https://ift.tt/hD30X1n
https://ift.tt/Xb29coU
Submitted October 25, 2025 at 01:42AM by ok_bye_now_
via reddit https://ift.tt/hD30X1n
www.adversis.io
Pentesting Next.js Server Actions
Adversis releases a Burp Extension for NextJS Hash-to-Function Mapping
Account takeover exploit write-up for Magento SessionReaper
https://ift.tt/Z9btPNj
Submitted October 25, 2025 at 01:48PM by AdAccording4827
via reddit https://ift.tt/d5DYEbN
https://ift.tt/Z9btPNj
Submitted October 25, 2025 at 01:48PM by AdAccording4827
via reddit https://ift.tt/d5DYEbN
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
https://ift.tt/DWaTpN6
Submitted October 26, 2025 at 05:16PM by AlmondOffSec
via reddit https://ift.tt/PBWryfK
https://ift.tt/DWaTpN6
Submitted October 26, 2025 at 05:16PM by AlmondOffSec
via reddit https://ift.tt/PBWryfK
samcurry.net
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
In June, 2025, Shubs Shah and I discovered a vulnerability in the online poker website ClubWPT Gold which would have allowed an attacker to fully access the core back office application that is used for all administrative site functionality.
New no nonsense platform for practice security learning
https://ift.tt/Ckjuds5
Submitted October 26, 2025 at 08:28PM by int_over_flow
via reddit https://ift.tt/3eolmAr
https://ift.tt/Ckjuds5
Submitted October 26, 2025 at 08:28PM by int_over_flow
via reddit https://ift.tt/3eolmAr
VantagePoint | Cyber Security Learning Platform
Hack, Learn, Improve… Platform to learn cyber security with real world challenges
Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
https://ift.tt/fRF2ZJw
Submitted October 26, 2025 at 07:33PM by Cold-Dinosaur
via reddit https://ift.tt/bDUOlZH
https://ift.tt/fRF2ZJw
Submitted October 26, 2025 at 07:33PM by Cold-Dinosaur
via reddit https://ift.tt/bDUOlZH
Zerosalarium
Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
EDR-Redir uses BindLink Filter and Windows Cloud Filter to inject, corrupt, and disable EDRs.
GlobalCVE — OpenSource Unified CVE Data from Around the World
https://Globalcve.xyz
Submitted October 27, 2025 at 09:06AM by reallylonguserthing
via reddit https://ift.tt/zG6PmO5
https://Globalcve.xyz
Submitted October 27, 2025 at 09:06AM by reallylonguserthing
via reddit https://ift.tt/zG6PmO5
Reddit
From the netsec community on Reddit: GlobalCVE — OpenSource Unified CVE Data from Around the World
Posted by reallylonguserthing - 27 votes and 2 comments
CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://ift.tt/LZ6jo8G
Submitted October 27, 2025 at 01:27PM by ForwardPractice4395
via reddit https://ift.tt/6DinBbr
https://ift.tt/LZ6jo8G
Submitted October 27, 2025 at 01:27PM by ForwardPractice4395
via reddit https://ift.tt/6DinBbr
Cyber Updates 365
CoPhish Attack Exploits Microsoft Copilot Studio OAuth Theft - Cyber Updates 365
CoPhish attack exploits Microsoft Copilot Studio to steal OAuth tokens through malicious AI agents targeting Microsoft Entra ID accounts.
Jetty's addPath allows LFI in Windows - Traccar Unauthenticated LFI v5.8-v6.8.1
https://ift.tt/VcWCZYX
Submitted October 27, 2025 at 01:59PM by ezzzzz
via reddit https://ift.tt/ywEumaj
https://ift.tt/VcWCZYX
Submitted October 27, 2025 at 01:59PM by ezzzzz
via reddit https://ift.tt/ywEumaj
Research Blog | Project Black
Traccar Unauthenticated LFI v5.8-v6.8.1
Sometimes you search endlessly and find nothing. Other times, the gold just drops into your lap. This is a story about how we accidentally found a pretty impactful vulnerability.