Free STIX 2.1 Threat Intel Feed
https://ift.tt/UuVTrYS
Submitted December 19, 2025 at 12:23AM by IwantAMD
via reddit https://ift.tt/tCjV29n
https://ift.tt/UuVTrYS
Submitted December 19, 2025 at 12:23AM by IwantAMD
via reddit https://ift.tt/tCjV29n
pathfinding.cloud - A library of AWS IAM privilege escalation paths
https://ift.tt/UEVn8he
Submitted December 19, 2025 at 12:15AM by sethsec
via reddit https://ift.tt/p9PJZhF
https://ift.tt/UEVn8he
Submitted December 19, 2025 at 12:15AM by sethsec
via reddit https://ift.tt/p9PJZhF
Datadoghq
Introducing Pathfinding.cloud
Introducing Pathfinding.cloud, a library of AWS IAM privilege escalation paths
[Research] Geometric analysis of SHA-256: Finding 68% bit-match pairs through dimensional transformation
https://ift.tt/AonBey7
Submitted December 19, 2025 at 07:31AM by No_Arachnid_5563
via reddit https://ift.tt/ROraUh3
https://ift.tt/AonBey7
Submitted December 19, 2025 at 07:31AM by No_Arachnid_5563
via reddit https://ift.tt/ROraUh3
Remote Desktop access and IP address
https://ift.tt/rHW6oDB
Submitted December 19, 2025 at 07:25AM by Mission_Protection40
via reddit https://ift.tt/rMden9C
https://ift.tt/rHW6oDB
Submitted December 19, 2025 at 07:25AM by Mission_Protection40
via reddit https://ift.tt/rMden9C
TeamViewer
Remote desktop software—fast and secure | TeamViewer
Access your desktop computer or other devices remotely from home or on the road with our AI-enhanced remote desktop software. Trusted, secure, and fast.
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Submitted December 19, 2025 at 01:37PM by AlmondOffSec
via reddit https://ift.tt/gAJFTjb
https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Submitted December 19, 2025 at 01:37PM by AlmondOffSec
via reddit https://ift.tt/gAJFTjb
Gist
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack - writeup.md
Case study: enabling autonomous security assessments with AI (CAI framework)
https://ift.tt/gPqLyWc
Submitted December 19, 2025 at 05:17PM by Obvious-Language4462
via reddit https://ift.tt/c5brlHY
https://ift.tt/gPqLyWc
Submitted December 19, 2025 at 05:17PM by Obvious-Language4462
via reddit https://ift.tt/c5brlHY
Breaking SAPCAR: Four Local Privilege Escalation Bugs in SAR Archive Parsing
https://ift.tt/w3rx72a
Submitted December 19, 2025 at 07:43PM by depierre
via reddit https://ift.tt/z2mhbD7
https://ift.tt/w3rx72a
Submitted December 19, 2025 at 07:43PM by depierre
via reddit https://ift.tt/z2mhbD7
Anvil Secure
Breaking SAPCAR: Four Local Privilege Escalation Bugs in SAR Archive Parsing - Anvil Secure
Principal Security Engineer Tao Sauvage uncovers four SAPCAR bugs, where parsing a SAR archive could lead to local privilege escalation.
Transforming InfoSec - How the next generation of security products should not require any IT knowledge
https://ift.tt/OLwWfEa
Submitted December 20, 2025 at 12:38AM by pathetiq
via reddit https://ift.tt/dQMoCTL
https://ift.tt/OLwWfEa
Submitted December 20, 2025 at 12:38AM by pathetiq
via reddit https://ift.tt/dQMoCTL
Security Autopsy
Transforming Cybersecurity - How the next generation of security products should not require any IT knowledge
We don’t lack cybersecurity ideas. We lack companies hiring juniors and products that are secure by default. These two problems are connected, and until we fix both, we’ll keep talking about a skills shortage while making it impossible to build a secure society.
TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering
https://ift.tt/grE5PyJ
Submitted December 20, 2025 at 02:25AM by _vavkamil_
via reddit https://ift.tt/j3VqpaL
https://ift.tt/grE5PyJ
Submitted December 20, 2025 at 02:25AM by _vavkamil_
via reddit https://ift.tt/j3VqpaL
evilsocket
TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
https://ift.tt/ydpkKhJ
Submitted December 21, 2025 at 04:17PM by ES_CY
via reddit https://ift.tt/Ff5Qd26
https://ift.tt/ydpkKhJ
Submitted December 21, 2025 at 04:17PM by ES_CY
via reddit https://ift.tt/Ff5Qd26
Cyberark
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
In this blog post, we present our approach for uncovering vulnerabilities by combining LLM reasoning with static analysis. By layering an LLM on top of CodeQL, we significantly reduce the...
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514
https://ift.tt/ZbLu20e
Submitted December 22, 2025 at 09:36AM by hfti
via reddit https://ift.tt/BMC1wT4
https://ift.tt/ZbLu20e
Submitted December 22, 2025 at 09:36AM by hfti
via reddit https://ift.tt/BMC1wT4
Amla Labs
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs
A critical vulnerability in mcp-remote affected 558,846 downloads. The bug was client-side, but the attack exploited OAuth dynamic discovery—a trust assumption that breaks for autonomous agents.
Cyberctf.space - Early Access Open
https://cyberctf.space
Submitted December 22, 2025 at 02:55PM by Royal_Independent517
via reddit https://ift.tt/SBI0Gzp
https://cyberctf.space
Submitted December 22, 2025 at 02:55PM by Royal_Independent517
via reddit https://ift.tt/SBI0Gzp
cyberctf.space
CyberCTF – Launching Soon
CyberCTF.space is launching soon. Join the waitlist for early access to hands-on cybersecurity CTF and Blue Team labs.
Microsoft Brokering File System Elevation of Privilege Vulnerability (CVE--2025-29970)
https://ift.tt/GoeYAv3
Submitted December 22, 2025 at 03:39PM by buherator
via reddit https://ift.tt/TKyrkCb
https://ift.tt/GoeYAv3
Submitted December 22, 2025 at 03:39PM by buherator
via reddit https://ift.tt/TKyrkCb
PixiePoint Security
Microsoft Brokering File System Elevation of Privilege Vulnerability | PixiePoint Security
About 2 years ago, Microsoft first released Win32-App-isolation which is a sandbox-like mechanism to further separate application access to resources on Windows clients. Brokering File System (BFS) was released around the same time to specifically …
I caught a Rust DDoS botnet on my honeypot, reverse engineered it, and now I'm monitoring its targets in real-time
https://ift.tt/wnWibJ8
Submitted December 22, 2025 at 09:17PM by mario_candela
via reddit https://ift.tt/AMg1h2N
https://ift.tt/wnWibJ8
Submitted December 22, 2025 at 09:17PM by mario_candela
via reddit https://ift.tt/AMg1h2N
Beelzebub
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets | AI deception platform
AI deception platform: Deceive, Detect, Respond. “You can’t defend. You can’t prevent. The only thing you can do is detect and respond.” Bruce Schneier. We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source…
19+ Vulnerabilities + PoCs for the MediaTek MT7622 Wifi Driver
https://ift.tt/5LwAo4Z
Submitted December 23, 2025 at 12:11AM by ahigherporpoise
via reddit https://ift.tt/64fBkEW
https://ift.tt/5LwAo4Z
Submitted December 23, 2025 at 12:11AM by ahigherporpoise
via reddit https://ift.tt/64fBkEW
hyprblog
mediatek? more like media-REKT, amirite.
A year-in-review going over 19+ bugs in Mediatek’s MT76xx/MT7915 (and others) wifi chipsets I reported this year, PoCs included!
how to hack discord, vercel and more with one easy trick - eva's site
https://ift.tt/Ev4oXAx
Submitted December 22, 2025 at 11:52PM by jrwren
via reddit https://ift.tt/5kY7qCa
https://ift.tt/Ev4oXAx
Submitted December 22, 2025 at 11:52PM by jrwren
via reddit https://ift.tt/5kY7qCa
Thank you reddit (u/broadexample) - updated version of my STIX feed
https://ift.tt/mrxPpqL
Submitted December 23, 2025 at 12:50AM by Clear_Ask9073
via reddit https://ift.tt/52Z7u8q
https://ift.tt/mrxPpqL
Submitted December 23, 2025 at 12:50AM by Clear_Ask9073
via reddit https://ift.tt/52Z7u8q
How Websites can detection Vision-Based AI Agents like Claude Computer Use and OpenAI Operator
https://ift.tt/Pc8iqwA
Submitted December 23, 2025 at 12:28AM by cport1
via reddit https://ift.tt/QB8pHYn
https://ift.tt/Pc8iqwA
Submitted December 23, 2025 at 12:28AM by cport1
via reddit https://ift.tt/QB8pHYn
Webdecoy
Detecting Vision-Based AI Agents: Operator and Beyond - WebDecoy
Detect Claude Computer Use and OpenAI Operator through timing analysis, cursor patterns, and prompt
Your Supabase Is Public
https://ift.tt/SBAqmnU
Submitted December 23, 2025 at 03:56AM by delsudo
via reddit https://ift.tt/xM3e5Ta
https://ift.tt/SBAqmnU
Submitted December 23, 2025 at 03:56AM by delsudo
via reddit https://ift.tt/xM3e5Ta
Skilldeliver
Your Supabase Is Public
I was chatting with a close friend of mine and he sent me a link to his new SaaS that he's developing.
Turning List-Unsubscribe into an SSRF/XSS Gadget
https://ift.tt/K5OTwjt
Submitted December 23, 2025 at 03:43PM by AlmondOffSec
via reddit https://ift.tt/PVnCHaf
https://ift.tt/K5OTwjt
Submitted December 23, 2025 at 03:43PM by AlmondOffSec
via reddit https://ift.tt/PVnCHaf
(Web-)Insecurity Blog
Turning List-Unsubscribe into an SSRF/XSS Gadget
The List-Unsubscribe SMTP header is standardized but often overlooked during security assessments. It allows email clients to provide an easy way for end-users to unsubscribe from mailing lists.
This post discusses how this header can be abused to perform…
This post discusses how this header can be abused to perform…
Guide to preventing the most common enterprise social engineering attacks
https://ift.tt/SBQYe6g
Submitted December 24, 2025 at 03:33AM by One_Asparagus7146
via reddit https://ift.tt/KOJc7VH
https://ift.tt/SBQYe6g
Submitted December 24, 2025 at 03:33AM by One_Asparagus7146
via reddit https://ift.tt/KOJc7VH