Privescing a Laptop with BitLocker + PIN
https://ift.tt/d1t5nBD
Submitted October 23, 2025 at 09:04PM by gquere
via reddit https://ift.tt/qTQVJd5
https://ift.tt/d1t5nBD
Submitted October 23, 2025 at 09:04PM by gquere
via reddit https://ift.tt/qTQVJd5
My AWS Account Got Hacked - Here Is What Happened
https://ift.tt/R74Ha1J
Submitted October 24, 2025 at 02:27AM by zvikizviki
via reddit https://ift.tt/tPCz6lN
https://ift.tt/R74Ha1J
Submitted October 24, 2025 at 02:27AM by zvikizviki
via reddit https://ift.tt/tPCz6lN
Zvi Wexlstein
My AWS Account Got Hacked - Here is What Happened
A detailed account of how my personal AWS account was compromised, the attack timeline, and lessons learned from a cloud security incident.
LockBit is attempting a comeback as a new ransomware variant "ChuongDong" targeting Windows, Linux, and ESXi
https://ift.tt/amp1UQE
Submitted October 24, 2025 at 08:47AM by rkhunter_
via reddit https://ift.tt/3Kq4uzg
https://ift.tt/amp1UQE
Submitted October 24, 2025 at 08:47AM by rkhunter_
via reddit https://ift.tt/3Kq4uzg
Check Point Blog
LockBit 5.0: Ransomware Gang Returns in Force
After a major takedown, LockBit is back with version 5.0, targeting Windows, Linux, and ESXi systems worldwide. Check Point Research reveals new victims.
TARMAGEDDON (CVE-2025-62518): RCE Vulnerability Highlights the challenges of open source abandonware
https://ift.tt/ySaKLBq
Submitted October 24, 2025 at 12:10PM by ukindom
via reddit https://ift.tt/KCoW7NL
https://ift.tt/ySaKLBq
Submitted October 24, 2025 at 12:10PM by ukindom
via reddit https://ift.tt/KCoW7NL
Edera
CVE-2025-62518 Shows the Cost of Open Source Abandonware
Edera uncovers TARmageddon (CVE-2025-62518), a Rust async-tar RCE flaw exposing the real dangers of open-source abandonware and supply chain security.
Pentesting Next.js Server Actions
https://ift.tt/Xb29coU
Submitted October 25, 2025 at 01:42AM by ok_bye_now_
via reddit https://ift.tt/hD30X1n
https://ift.tt/Xb29coU
Submitted October 25, 2025 at 01:42AM by ok_bye_now_
via reddit https://ift.tt/hD30X1n
www.adversis.io
Pentesting Next.js Server Actions
Adversis releases a Burp Extension for NextJS Hash-to-Function Mapping
Account takeover exploit write-up for Magento SessionReaper
https://ift.tt/Z9btPNj
Submitted October 25, 2025 at 01:48PM by AdAccording4827
via reddit https://ift.tt/d5DYEbN
https://ift.tt/Z9btPNj
Submitted October 25, 2025 at 01:48PM by AdAccording4827
via reddit https://ift.tt/d5DYEbN
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
https://ift.tt/DWaTpN6
Submitted October 26, 2025 at 05:16PM by AlmondOffSec
via reddit https://ift.tt/PBWryfK
https://ift.tt/DWaTpN6
Submitted October 26, 2025 at 05:16PM by AlmondOffSec
via reddit https://ift.tt/PBWryfK
samcurry.net
Hacking the World Poker Tour: Inside ClubWPT Gold’s Back Office
In June, 2025, Shubs Shah and I discovered a vulnerability in the online poker website ClubWPT Gold which would have allowed an attacker to fully access the core back office application that is used for all administrative site functionality.
New no nonsense platform for practice security learning
https://ift.tt/Ckjuds5
Submitted October 26, 2025 at 08:28PM by int_over_flow
via reddit https://ift.tt/3eolmAr
https://ift.tt/Ckjuds5
Submitted October 26, 2025 at 08:28PM by int_over_flow
via reddit https://ift.tt/3eolmAr
VantagePoint | Cyber Security Learning Platform
Hack, Learn, Improve… Platform to learn cyber security with real world challenges
Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
https://ift.tt/fRF2ZJw
Submitted October 26, 2025 at 07:33PM by Cold-Dinosaur
via reddit https://ift.tt/bDUOlZH
https://ift.tt/fRF2ZJw
Submitted October 26, 2025 at 07:33PM by Cold-Dinosaur
via reddit https://ift.tt/bDUOlZH
Zerosalarium
Using EDR-Redir To Break EDR Via Bind Link and Cloud Filter
EDR-Redir uses BindLink Filter and Windows Cloud Filter to inject, corrupt, and disable EDRs.
GlobalCVE — OpenSource Unified CVE Data from Around the World
https://Globalcve.xyz
Submitted October 27, 2025 at 09:06AM by reallylonguserthing
via reddit https://ift.tt/zG6PmO5
https://Globalcve.xyz
Submitted October 27, 2025 at 09:06AM by reallylonguserthing
via reddit https://ift.tt/zG6PmO5
Reddit
From the netsec community on Reddit: GlobalCVE — OpenSource Unified CVE Data from Around the World
Posted by reallylonguserthing - 27 votes and 2 comments
CoPHish: New OAuth phishing technique abuses Microsoft Copilot Studio chatbots to create convincing credential theft campaigns
https://ift.tt/LZ6jo8G
Submitted October 27, 2025 at 01:27PM by ForwardPractice4395
via reddit https://ift.tt/6DinBbr
https://ift.tt/LZ6jo8G
Submitted October 27, 2025 at 01:27PM by ForwardPractice4395
via reddit https://ift.tt/6DinBbr
Cyber Updates 365
CoPhish Attack Exploits Microsoft Copilot Studio OAuth Theft - Cyber Updates 365
CoPhish attack exploits Microsoft Copilot Studio to steal OAuth tokens through malicious AI agents targeting Microsoft Entra ID accounts.
Jetty's addPath allows LFI in Windows - Traccar Unauthenticated LFI v5.8-v6.8.1
https://ift.tt/VcWCZYX
Submitted October 27, 2025 at 01:59PM by ezzzzz
via reddit https://ift.tt/ywEumaj
https://ift.tt/VcWCZYX
Submitted October 27, 2025 at 01:59PM by ezzzzz
via reddit https://ift.tt/ywEumaj
Research Blog | Project Black
Traccar Unauthenticated LFI v5.8-v6.8.1
Sometimes you search endlessly and find nothing. Other times, the gold just drops into your lap. This is a story about how we accidentally found a pretty impactful vulnerability.
Vibecoding and the illusion of security
https://ift.tt/KxLpWgy
Submitted October 27, 2025 at 02:43PM by security_aaudit
via reddit https://ift.tt/BbaLeZH
https://ift.tt/KxLpWgy
Submitted October 27, 2025 at 02:43PM by security_aaudit
via reddit https://ift.tt/BbaLeZH
baldur.dk
BALDUR. - Security Consultancy
Vibecoding is fast, but it is secure? We tested current state of the art LLM models against a common security task, namely the MFA implemented in your applications.
[Tool] CVE Daily — concise, vendor-neutral CVE briefs (NVD+OSV, KEV, deps.dev transitive upgrades)
https://cvedaily.com
Submitted October 27, 2025 at 04:27PM by Interesting-Work-980
via reddit https://ift.tt/Y4tzLOx
https://cvedaily.com
Submitted October 27, 2025 at 04:27PM by Interesting-Work-980
via reddit https://ift.tt/Y4tzLOx
CVE Daily
CVE Daily - Latest CVEs
Daily updated CVE summaries with CVSS and CWE tags. Latest update: 2025-12-03T14:15:48.680.
Crafting self masking functions using LLVM
https://ift.tt/2pnErVu
Submitted October 28, 2025 at 01:33PM by gid0rah
via reddit https://ift.tt/oDeuV0m
https://ift.tt/2pnErVu
Submitted October 28, 2025 at 01:33PM by gid0rah
via reddit https://ift.tt/oDeuV0m
MDSec
Function Peekaboo: Crafting self masking functions using LLVM - MDSec
Introduction LLVM compiler infrastructure is powerful because of its modular design, flexibility, and rich intermediate representation (IR) that enables deep analysis and transformation of code. Unlike traditional compilers, LLVM separates...
WSO2 #2: The many ways to bypass authentication in WSO2 products (CVE-2025-9152, CVE-2025-10611, CVE-2025-9804)
https://ift.tt/MnKaeiN
Submitted October 28, 2025 at 12:43PM by crnkovic_
via reddit https://ift.tt/9pecBsO
https://ift.tt/MnKaeiN
Submitted October 28, 2025 at 12:43PM by crnkovic_
via reddit https://ift.tt/9pecBsO
crnkovic.dev
WSO2 #2: The many ways to bypass authentication in WSO2 products
CVE-2025-9152, CVE-2025-10611, and CVE-2025-9804 are critical authentication bypass and privilege escalation vulnerabilities I discovered in WSO2 API Manager and WSO2 Identity Server.
404 to arbitrary file read in WSO2 API Manager (CVE-2025-2905)
https://ift.tt/crfVkaS
Submitted October 28, 2025 at 02:07PM by crnkovic_
via reddit https://ift.tt/boaJQtL
https://ift.tt/crfVkaS
Submitted October 28, 2025 at 02:07PM by crnkovic_
via reddit https://ift.tt/boaJQtL
crnkovic.dev
WSO2 #1: 404 to arbitrary file read
CVE-2025-2905 is a blind XXE vulnerability in WSO2 API Manager and other WSO2 products dependent on WSO2-Synapse.
Brida (Burp-Frida Bridge) 0.6 released! - HN Security
https://ift.tt/W4R6dIm
Submitted October 28, 2025 at 04:05PM by 0xdea
via reddit https://ift.tt/3sDzA1M
https://ift.tt/W4R6dIm
Submitted October 28, 2025 at 04:05PM by 0xdea
via reddit https://ift.tt/3sDzA1M
HN Security
Brida 0.6 released! - HN Security
We are releasing Brida 0.6 that supports Frida 17, which introduced some breaking change in its API.
New Ubuntu Kernel LPE!
https://ift.tt/Fs5gBpU
Submitted October 28, 2025 at 05:14PM by SSDisclosure
via reddit https://ift.tt/7NqIfRC
https://ift.tt/Fs5gBpU
Submitted October 28, 2025 at 05:14PM by SSDisclosure
via reddit https://ift.tt/7NqIfRC
SSD Secure Disclosure
LPE via refcount imbalance in the af_unix of Ubuntu's Kernel - SSD Secure Disclosure
Affected Versions Vendor Response The vendor has released an updated kernel on the 18th of September Credit The vulnerability was disclosed during our TyphoonPWN 2025 Linux category and won first place. Vulnerability Details The vulnerability is caused by…
guys ı ha ve problem
http://google.com
Submitted October 28, 2025 at 05:12PM by Double-Structure4337
via reddit https://ift.tt/60pDfRt
http://google.com
Submitted October 28, 2025 at 05:12PM by Double-Structure4337
via reddit https://ift.tt/60pDfRt
Reddit
From the netsec community on Reddit: guys ı ha ve problem
Posted by Double-Structure4337 - 0 votes and 1 comment
Battling Shadow AI: Prompt Injection for the Good
https://ift.tt/W0aT6DX
Submitted October 28, 2025 at 07:30PM by Far_Ice2481
via reddit https://ift.tt/e7PQjxK
https://ift.tt/W0aT6DX
Submitted October 28, 2025 at 07:30PM by Far_Ice2481
via reddit https://ift.tt/e7PQjxK
Eye Research
Battling Shadow AI: Prompt Injection for the Good
Explore how Eye Security tackles the rising threat of Shadow AI by using prompt injection for good: enhancing data security, boosting AI awareness, and defending corporate intelligence across LLMs like ChatGPT, Claude, and DeepSeek.