How much latency does a Throwing Star LAN Tap add to packet capture? (practical numbers appreciated)
https://amzn.to/4oZoxUI
Submitted November 09, 2025 at 02:49AM by JMarkG
via reddit https://ift.tt/mxRIJtL
https://amzn.to/4oZoxUI
Submitted November 09, 2025 at 02:49AM by JMarkG
via reddit https://ift.tt/mxRIJtL
Reddit
From the netsec community on Reddit: [ Removed by moderator ]
Posted by JMarkG - 8 votes and 7 comments
Update] VulScan-MCP: Now shows detailed CVE denoscriptions, severity, and mitigation steps
https://marketplace.visualstudio.com/items?itemName=abhishekrai43.vulscan-mcp-vscode
Submitted November 09, 2025 at 10:42AM by FeelingResolution806
via reddit https://ift.tt/nrC4TiY
https://marketplace.visualstudio.com/items?itemName=abhishekrai43.vulscan-mcp-vscode
Submitted November 09, 2025 at 10:42AM by FeelingResolution806
via reddit https://ift.tt/nrC4TiY
Visualstudio
VulScan-MCP Security Scanner - Visual Studio Marketplace
Extension for Visual Studio Code - Security vulnerability scanner for dependencies. Checks CVEs from NVD/OSV databases and provides remediation steps. Supports npm, pip, Maven, Go, and more.
One Simple Mistake, Thousands at Risk - How Common Misconfigurations Could Lead to Massive Data Exposure
https://ift.tt/eF1bJoS
Submitted November 10, 2025 at 04:56PM by we-we-we
via reddit https://ift.tt/vrbCV7e
https://ift.tt/eF1bJoS
Submitted November 10, 2025 at 04:56PM by we-we-we
via reddit https://ift.tt/vrbCV7e
Medium
The Burn Notice, Part 3/5 | One Simple Mistake, Thousands at Risk
How Common Misconfigurations Could Lead to Massive Data Exposure
HTTP Request Smuggling in Kestrel via chunk extensions (CVE-2025-55315)
https://ift.tt/STlvMWo
Submitted November 10, 2025 at 09:26PM by albinowax
via reddit https://ift.tt/PnDLmhc
https://ift.tt/STlvMWo
Submitted November 10, 2025 at 09:26PM by albinowax
via reddit https://ift.tt/PnDLmhc
Praetorian
How I Found the Worst ASP.NET Vulnerability — A $10K Bug (CVE-2025-55315)
Introduction Earlier this year, I earned a $10,000 bounty from Microsoft after discovering a critical HTTP request smuggling vulnerability in ASP.NET Core’s Kestrel server (CVE-2025-55315). The vulnerability garnered significant media attention after Microsoft…
[DISCLOSURE] DoorDash Enabled 5-Year XSS/HTML Injection Flaw via Official Email; VDP Misclassified Report for 15 Months
https://ift.tt/bmoykfL
Submitted November 10, 2025 at 10:00PM by east0n12
via reddit https://ift.tt/BvbUPMu
https://ift.tt/bmoykfL
Submitted November 10, 2025 at 10:00PM by east0n12
via reddit https://ift.tt/BvbUPMu
GitLab
index.md · 54535fa7b497e13100aa14f32a46f6aedb4aaf28 · Martin Ferech / DoorDash-Disclosure-Public · GitLab
No Leak, No Problem - Bypassing ASLR with a ROP Chain to Gain RCE
https://ift.tt/B7GLowz
Submitted November 12, 2025 at 12:48PM by parzel
via reddit https://ift.tt/Hk5vPeT
https://ift.tt/B7GLowz
Submitted November 12, 2025 at 12:48PM by parzel
via reddit https://ift.tt/Hk5vPeT
Modzero
No Leak, No Problem - Bypassing ASLR with a ROP Chain to Gain RCE
MacOS Infection Vector: Using AppleScripts to bypass Gatekeeper
https://pberba.github.io/security/2025/11/11/macos-infection-vector-applenoscript-bypass-gatekeeper/
Submitted November 12, 2025 at 02:49PM by dashboard_monkey
via reddit https://ift.tt/ZWYPRsr
https://pberba.github.io/security/2025/11/11/macos-infection-vector-applenoscript-bypass-gatekeeper/
Submitted November 12, 2025 at 02:49PM by dashboard_monkey
via reddit https://ift.tt/ZWYPRsr
pepe berba
MacOS Infection Vector: Using AppleScripts to bypass Gatekeeper
A look at how threat actors are abusing AppleScript .scpt files to deliver macOS malware, from fake documents to browser update lures, and how these noscripts ...
Is It CitrixBleed4? Well, No. Is It Good? Also, No. (Citrix NetScaler Memory Leak & RXSS CVE-2025-12101) - watchTowr Labs
https://ift.tt/Oa8KPmA
Submitted November 12, 2025 at 06:34PM by dx7r__
via reddit https://ift.tt/4bFl8vQ
https://ift.tt/Oa8KPmA
Submitted November 12, 2025 at 06:34PM by dx7r__
via reddit https://ift.tt/4bFl8vQ
watchTowr Labs
Is It CitrixBleed4? Well, No. Is It Good? Also, No. (Citrix NetScaler Memory Leak & RXSS CVE-2025-12101)
There’s an elegance to vulnerability research that feels almost poetic - the quiet dance between chaos and control. It’s the art of peeling back the layers of complexity, not to destroy but to understand; to trace the fragile threads that hold systems together…
The GitHub Security Blindspot: When Your Organisation Members’ Personal Repos Become Your Problem
https://ift.tt/N56PcDf
Submitted November 12, 2025 at 10:46PM by dinkoism
via reddit https://ift.tt/3r7x0zd
https://ift.tt/N56PcDf
Submitted November 12, 2025 at 10:46PM by dinkoism
via reddit https://ift.tt/3r7x0zd
Medium
The GitHub Security Blindspot: When Your Organisation Members’ Personal Repos Become Your Problem
The Security Gap GitHub Doesn’t Want to Talk About
Making .NET Serialization Gadgets by Hand
https://ift.tt/NXRHfA8
Submitted November 13, 2025 at 03:27AM by chicksdigthelongrun
via reddit https://ift.tt/su6pxez
https://ift.tt/NXRHfA8
Submitted November 13, 2025 at 03:27AM by chicksdigthelongrun
via reddit https://ift.tt/su6pxez
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Breaking mPDF with regex and logic
https://ift.tt/uhZpgsP
Submitted November 13, 2025 at 04:54AM by ZoltyLis
via reddit https://ift.tt/5yFkiWs
https://ift.tt/uhZpgsP
Submitted November 13, 2025 at 04:54AM by ZoltyLis
via reddit https://ift.tt/5yFkiWs
Medium
Breaking mPDF with regex and logic
Triggering web requests with sanitized input
Dehashed alternative for pentesters/red teamers
https://ift.tt/v0pnNCs
Submitted November 13, 2025 at 04:03PM by Pleasant-Drawer729
via reddit https://ift.tt/dUegrNJ
https://ift.tt/v0pnNCs
Submitted November 13, 2025 at 04:03PM by Pleasant-Drawer729
via reddit https://ift.tt/dUegrNJ
Drawbot: Let’s Hack Something Cute! — Atredis Partners
https://ift.tt/qvMYDu7
Submitted November 14, 2025 at 12:39AM by juken
via reddit https://ift.tt/v2KAE5m
https://ift.tt/qvMYDu7
Submitted November 14, 2025 at 12:39AM by juken
via reddit https://ift.tt/v2KAE5m
Atredis Partners
Drawbot: Let’s Hack Something Cute! — Atredis Partners
The Target A few months ago I realized I was overdue for a fun, quirky hardware project. Every so often I like to see what new and interesting electronic children's toys are out there. When looking, I keep in mind the potential attack surface, typically…
Milvus Proxy Authentication Bypass Vulnerability(CVE-2025-64513)
https://ift.tt/lDj6sdI
Submitted November 14, 2025 at 09:43AM by Fit_Wing3352
via reddit https://ift.tt/faeSWV9
https://ift.tt/lDj6sdI
Submitted November 14, 2025 at 09:43AM by Fit_Wing3352
via reddit https://ift.tt/faeSWV9
🚨 FIRST PUBLIC EVIDENCE: RedTail Cryptominer Targets Docker APIs
https://ift.tt/SMyCdHR
Submitted November 14, 2025 at 01:24PM by mario_candela
via reddit https://ift.tt/db1aM6x
https://ift.tt/SMyCdHR
Submitted November 14, 2025 at 01:24PM by mario_candela
via reddit https://ift.tt/db1aM6x
Beelzebub
RedTail Cryptominer: First Evidence of Docker API Targeting | AI deception platform
AI deception platform: Deceive, Detect, Respond. “You can’t defend. You can’t prevent. The only thing you can do is detect and respond.” Bruce Schneier. We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source…
When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb (??) Auth. Bypass) - watchTowr Labs
https://ift.tt/uFmyZYX
Submitted November 14, 2025 at 07:57PM by dx7r__
via reddit https://ift.tt/gSFoDcB
https://ift.tt/uFmyZYX
Submitted November 14, 2025 at 07:57PM by dx7r__
via reddit https://ift.tt/gSFoDcB
watchTowr Labs
When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446)
The Internet is ablaze, and once again we all have a front-row seat - a bad person, if you can believe it, is doing a bad thing!
The first warning of such behaviour came from the great team at Defused:
As many are now aware, an unnamed (and potentially…
The first warning of such behaviour came from the great team at Defused:
As many are now aware, an unnamed (and potentially…
AT&T Data Breach Settlement Deadline Nears for Claims Up to $7,500
https://ift.tt/VoxLWKl
Submitted November 15, 2025 at 07:24PM by ThinPilot1
via reddit https://ift.tt/YK5eRkh
https://ift.tt/VoxLWKl
Submitted November 15, 2025 at 07:24PM by ThinPilot1
via reddit https://ift.tt/YK5eRkh
Face Scrapper Ai like faceSeek -netsec analysis
https://Faceseek.online
Submitted November 15, 2025 at 06:47PM by Few_Extension6813
via reddit https://ift.tt/KdxOuHa
https://Faceseek.online
Submitted November 15, 2025 at 06:47PM by Few_Extension6813
via reddit https://ift.tt/KdxOuHa
www.faceseek.online
FaceSeek — Face Lookup, Face Search & Facial Recognition Search Online
FaceSeek helps you verify photos, find people, and enhance online safety using ethical face search and advanced facial recognition.
CyberRecon project
https://drive.google.com/file/d/1yI1OSA8OH2CQJRKndv_39DmAqS9HYGzQ/view?usp=drive_link
Submitted November 15, 2025 at 09:54PM by Sufficient_Air5988
via reddit https://ift.tt/ReGZYmN
https://drive.google.com/file/d/1yI1OSA8OH2CQJRKndv_39DmAqS9HYGzQ/view?usp=drive_link
Submitted November 15, 2025 at 09:54PM by Sufficient_Air5988
via reddit https://ift.tt/ReGZYmN
Reddit
From the netsec community on Reddit: [ Removed by moderator ]
Posted by Sufficient_Air5988 - 0 votes and 0 comments
NPMScan - Malicious NPM Package Detection & Security Scanner
https://npmscan.com
Submitted November 16, 2025 at 01:44AM by kryakrya_it
via reddit https://ift.tt/UXn2ZfG
https://npmscan.com
Submitted November 16, 2025 at 01:44AM by kryakrya_it
via reddit https://ift.tt/UXn2ZfG
NPMScan
NPMScan - Malicious NPM Package Detection & Security Scanner
Protect your Node.js projects from supply chain attacks. Scan npm packages for malware and vulnerabilities.
Claude AI ran autonomous espionage operations
https://ift.tt/pNrvRig
Submitted November 16, 2025 at 04:21PM by YouCanDoIt749
via reddit https://ift.tt/P4iQhuX
https://ift.tt/pNrvRig
Submitted November 16, 2025 at 04:21PM by YouCanDoIt749
via reddit https://ift.tt/P4iQhuX
Anthropic
Disrupting the first reported AI-orchestrated cyber espionage campaign
A report describing an a highly sophisticated AI-led cyberattack