The GitHub Security Blindspot: When Your Organisation Members’ Personal Repos Become Your Problem
https://ift.tt/N56PcDf
Submitted November 12, 2025 at 10:46PM by dinkoism
via reddit https://ift.tt/3r7x0zd
https://ift.tt/N56PcDf
Submitted November 12, 2025 at 10:46PM by dinkoism
via reddit https://ift.tt/3r7x0zd
Medium
The GitHub Security Blindspot: When Your Organisation Members’ Personal Repos Become Your Problem
The Security Gap GitHub Doesn’t Want to Talk About
Making .NET Serialization Gadgets by Hand
https://ift.tt/NXRHfA8
Submitted November 13, 2025 at 03:27AM by chicksdigthelongrun
via reddit https://ift.tt/su6pxez
https://ift.tt/NXRHfA8
Submitted November 13, 2025 at 03:27AM by chicksdigthelongrun
via reddit https://ift.tt/su6pxez
VulnCheck
VulnCheck - Outpace Adversaries
Vulnerability intelligence that predicts avenues of attack with speed and accuracy.
Breaking mPDF with regex and logic
https://ift.tt/uhZpgsP
Submitted November 13, 2025 at 04:54AM by ZoltyLis
via reddit https://ift.tt/5yFkiWs
https://ift.tt/uhZpgsP
Submitted November 13, 2025 at 04:54AM by ZoltyLis
via reddit https://ift.tt/5yFkiWs
Medium
Breaking mPDF with regex and logic
Triggering web requests with sanitized input
Dehashed alternative for pentesters/red teamers
https://ift.tt/v0pnNCs
Submitted November 13, 2025 at 04:03PM by Pleasant-Drawer729
via reddit https://ift.tt/dUegrNJ
https://ift.tt/v0pnNCs
Submitted November 13, 2025 at 04:03PM by Pleasant-Drawer729
via reddit https://ift.tt/dUegrNJ
Drawbot: Let’s Hack Something Cute! — Atredis Partners
https://ift.tt/qvMYDu7
Submitted November 14, 2025 at 12:39AM by juken
via reddit https://ift.tt/v2KAE5m
https://ift.tt/qvMYDu7
Submitted November 14, 2025 at 12:39AM by juken
via reddit https://ift.tt/v2KAE5m
Atredis Partners
Drawbot: Let’s Hack Something Cute! — Atredis Partners
The Target A few months ago I realized I was overdue for a fun, quirky hardware project. Every so often I like to see what new and interesting electronic children's toys are out there. When looking, I keep in mind the potential attack surface, typically…
Milvus Proxy Authentication Bypass Vulnerability(CVE-2025-64513)
https://ift.tt/lDj6sdI
Submitted November 14, 2025 at 09:43AM by Fit_Wing3352
via reddit https://ift.tt/faeSWV9
https://ift.tt/lDj6sdI
Submitted November 14, 2025 at 09:43AM by Fit_Wing3352
via reddit https://ift.tt/faeSWV9
🚨 FIRST PUBLIC EVIDENCE: RedTail Cryptominer Targets Docker APIs
https://ift.tt/SMyCdHR
Submitted November 14, 2025 at 01:24PM by mario_candela
via reddit https://ift.tt/db1aM6x
https://ift.tt/SMyCdHR
Submitted November 14, 2025 at 01:24PM by mario_candela
via reddit https://ift.tt/db1aM6x
Beelzebub
RedTail Cryptominer: First Evidence of Docker API Targeting | AI deception platform
AI deception platform: Deceive, Detect, Respond. “You can’t defend. You can’t prevent. The only thing you can do is detect and respond.” Bruce Schneier. We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source…
When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb (??) Auth. Bypass) - watchTowr Labs
https://ift.tt/uFmyZYX
Submitted November 14, 2025 at 07:57PM by dx7r__
via reddit https://ift.tt/gSFoDcB
https://ift.tt/uFmyZYX
Submitted November 14, 2025 at 07:57PM by dx7r__
via reddit https://ift.tt/gSFoDcB
watchTowr Labs
When The Impersonation Function Gets Used To Impersonate Users (Fortinet FortiWeb Auth. Bypass CVE-2025-64446)
The Internet is ablaze, and once again we all have a front-row seat - a bad person, if you can believe it, is doing a bad thing!
The first warning of such behaviour came from the great team at Defused:
As many are now aware, an unnamed (and potentially…
The first warning of such behaviour came from the great team at Defused:
As many are now aware, an unnamed (and potentially…
AT&T Data Breach Settlement Deadline Nears for Claims Up to $7,500
https://ift.tt/VoxLWKl
Submitted November 15, 2025 at 07:24PM by ThinPilot1
via reddit https://ift.tt/YK5eRkh
https://ift.tt/VoxLWKl
Submitted November 15, 2025 at 07:24PM by ThinPilot1
via reddit https://ift.tt/YK5eRkh
Face Scrapper Ai like faceSeek -netsec analysis
https://Faceseek.online
Submitted November 15, 2025 at 06:47PM by Few_Extension6813
via reddit https://ift.tt/KdxOuHa
https://Faceseek.online
Submitted November 15, 2025 at 06:47PM by Few_Extension6813
via reddit https://ift.tt/KdxOuHa
www.faceseek.online
FaceSeek — Face Lookup, Face Search & Facial Recognition Search Online
FaceSeek helps you verify photos, find people, and enhance online safety using ethical face search and advanced facial recognition.
CyberRecon project
https://drive.google.com/file/d/1yI1OSA8OH2CQJRKndv_39DmAqS9HYGzQ/view?usp=drive_link
Submitted November 15, 2025 at 09:54PM by Sufficient_Air5988
via reddit https://ift.tt/ReGZYmN
https://drive.google.com/file/d/1yI1OSA8OH2CQJRKndv_39DmAqS9HYGzQ/view?usp=drive_link
Submitted November 15, 2025 at 09:54PM by Sufficient_Air5988
via reddit https://ift.tt/ReGZYmN
Reddit
From the netsec community on Reddit: [ Removed by moderator ]
Posted by Sufficient_Air5988 - 0 votes and 0 comments
NPMScan - Malicious NPM Package Detection & Security Scanner
https://npmscan.com
Submitted November 16, 2025 at 01:44AM by kryakrya_it
via reddit https://ift.tt/UXn2ZfG
https://npmscan.com
Submitted November 16, 2025 at 01:44AM by kryakrya_it
via reddit https://ift.tt/UXn2ZfG
NPMScan
NPMScan - Malicious NPM Package Detection & Security Scanner
Protect your Node.js projects from supply chain attacks. Scan npm packages for malware and vulnerabilities.
Claude AI ran autonomous espionage operations
https://ift.tt/pNrvRig
Submitted November 16, 2025 at 04:21PM by YouCanDoIt749
via reddit https://ift.tt/P4iQhuX
https://ift.tt/pNrvRig
Submitted November 16, 2025 at 04:21PM by YouCanDoIt749
via reddit https://ift.tt/P4iQhuX
Anthropic
Disrupting the first reported AI-orchestrated cyber espionage campaign
A report describing an a highly sophisticated AI-led cyberattack
Trying to make CCNA learning more engaging for students
https://ift.tt/DcN17nl
Submitted November 16, 2025 at 11:00PM by Sorry_Flatworm_521
via reddit https://ift.tt/2P6z3pl
https://ift.tt/DcN17nl
Submitted November 16, 2025 at 11:00PM by Sorry_Flatworm_521
via reddit https://ift.tt/2P6z3pl
PingMyNetwork
First Gamified Certification Training Platform
Are you ready for your IT career? Train for CCNA, CCNP and others certifications with a complete study plan, real exams and a gamified experience.
Reposecu: Free 3-in-1 SAST Scanner for GitHub (Semgrep + Trivy + Detect-Secrets) – Beta Feedback Welcome
http://reposecu.com
Submitted November 17, 2025 at 12:31AM by enesbilenn
via reddit https://ift.tt/A79CicR
http://reposecu.com
Submitted November 17, 2025 at 12:31AM by enesbilenn
via reddit https://ift.tt/A79CicR
Reposecu
RepoSecu - Advanced Security Scanning Platform
Scan your repositories for security vulnerabilities using Semgrep, Trivy, and Detect Secrets.
what do you guys think of this undocumented behavior of "web for pentester 1?"
https://ift.tt/fse95z4
Submitted November 17, 2025 at 07:32AM by UnableProperty9526
via reddit https://ift.tt/f2SF1tw
https://ift.tt/fse95z4
Submitted November 17, 2025 at 07:32AM by UnableProperty9526
via reddit https://ift.tt/f2SF1tw
Medium
How I Accidentally Discovered an Undocumented Behavior in “Web for Pentester 1”
Most security labs are built around predictable, well-documented vulnerabilities. But every once in a while, during experimentation, you…
A Cracker Barrel vulnerability
https://ift.tt/sPYr7oW
Submitted November 17, 2025 at 09:15PM by EatonZ
via reddit https://ift.tt/6yMXoUA
https://ift.tt/sPYr7oW
Submitted November 17, 2025 at 09:15PM by EatonZ
via reddit https://ift.tt/6yMXoUA
Eaton-Works
A Cracker Barrel vulnerability
Cracking open the rewards admin panel.
PacketSmith X.509 Certificate Extractor (TLS over TCP and DTLS) - How To
https://ift.tt/K8LDMZs
Submitted November 17, 2025 at 08:52PM by MFMokbel
via reddit https://ift.tt/BiwtFGl
https://ift.tt/K8LDMZs
Submitted November 17, 2025 at 08:52PM by MFMokbel
via reddit https://ift.tt/BiwtFGl
PacketSmith
X.509 Certificate Extractor - PacketSmith
X.509 Certificate Extractor (TLS over TCP and DTLS) Introduction Release 4.0 introduces a new capability: the scanning of TCP and UDP streams for x.509 certificates. You can now either export these certificates to disk or dissect their attributes and output…
N-able N-central: From N-days to 0-days
https://ift.tt/z9vU7Vn
Submitted November 18, 2025 at 12:17AM by scopedsecurity
via reddit https://ift.tt/p7IBMyC
https://ift.tt/z9vU7Vn
Submitted November 18, 2025 at 12:17AM by scopedsecurity
via reddit https://ift.tt/p7IBMyC
Horizon3.ai
N-able N-central: From N-days to 0-days
Root cause analysis for N-able N-central CVE-2025-9163 and CVE-2025-11700 which allow for reading files and and potentially compromising the N-central database which stores client credentials, API keys, and more.
Gotchas in Email Parsing - Lessons from Jakarta Mail
https://ift.tt/bP8pGzH
Submitted November 18, 2025 at 03:36PM by AnimalStrange
via reddit https://ift.tt/xAYFSC9
https://ift.tt/bP8pGzH
Submitted November 18, 2025 at 03:36PM by AnimalStrange
via reddit https://ift.tt/xAYFSC9
Elttam
Gotchas in Email Parsing - Lessons From Jakarta Mail - elttam
elttam is a globally recognised, independent information security company, renowned for our advanced technical security assessments.
ShadowRay 2.0: Active Global Campaign Hijacks Ray AI Infrastructure Into Self-Propagating Botnet | Oligo Security
https://ift.tt/9mCc1Lw
Submitted November 18, 2025 at 08:58PM by cov_id19
via reddit https://ift.tt/TqswiYN
https://ift.tt/9mCc1Lw
Submitted November 18, 2025 at 08:58PM by cov_id19
via reddit https://ift.tt/TqswiYN
www.oligo.security
ShadowRay 2.0: Active Global Campaign Hijacks Ray AI Infrastructure Into Self-Propagating Botnet | Oligo Security
Oligo Security uncovers ShadowRay 2.0, an active global campaign exploiting Ray to hijack AI infrastructure and create a self-propagating botnet.