How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Submitted December 19, 2025 at 01:37PM by AlmondOffSec
via reddit https://ift.tt/gAJFTjb
https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Submitted December 19, 2025 at 01:37PM by AlmondOffSec
via reddit https://ift.tt/gAJFTjb
Gist
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack - writeup.md
Case study: enabling autonomous security assessments with AI (CAI framework)
https://ift.tt/gPqLyWc
Submitted December 19, 2025 at 05:17PM by Obvious-Language4462
via reddit https://ift.tt/c5brlHY
https://ift.tt/gPqLyWc
Submitted December 19, 2025 at 05:17PM by Obvious-Language4462
via reddit https://ift.tt/c5brlHY
Breaking SAPCAR: Four Local Privilege Escalation Bugs in SAR Archive Parsing
https://ift.tt/w3rx72a
Submitted December 19, 2025 at 07:43PM by depierre
via reddit https://ift.tt/z2mhbD7
https://ift.tt/w3rx72a
Submitted December 19, 2025 at 07:43PM by depierre
via reddit https://ift.tt/z2mhbD7
Anvil Secure
Breaking SAPCAR: Four Local Privilege Escalation Bugs in SAR Archive Parsing - Anvil Secure
Principal Security Engineer Tao Sauvage uncovers four SAPCAR bugs, where parsing a SAR archive could lead to local privilege escalation.
Transforming InfoSec - How the next generation of security products should not require any IT knowledge
https://ift.tt/OLwWfEa
Submitted December 20, 2025 at 12:38AM by pathetiq
via reddit https://ift.tt/dQMoCTL
https://ift.tt/OLwWfEa
Submitted December 20, 2025 at 12:38AM by pathetiq
via reddit https://ift.tt/dQMoCTL
Security Autopsy
Transforming Cybersecurity - How the next generation of security products should not require any IT knowledge
We don’t lack cybersecurity ideas. We lack companies hiring juniors and products that are secure by default. These two problems are connected, and until we fix both, we’ll keep talking about a skills shortage while making it impossible to build a secure society.
TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering
https://ift.tt/grE5PyJ
Submitted December 20, 2025 at 02:25AM by _vavkamil_
via reddit https://ift.tt/j3VqpaL
https://ift.tt/grE5PyJ
Submitted December 20, 2025 at 02:25AM by _vavkamil_
via reddit https://ift.tt/j3VqpaL
evilsocket
TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy in the Era of AI Assisted Reverse Engineering
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
https://ift.tt/ydpkKhJ
Submitted December 21, 2025 at 04:17PM by ES_CY
via reddit https://ift.tt/Ff5Qd26
https://ift.tt/ydpkKhJ
Submitted December 21, 2025 at 04:17PM by ES_CY
via reddit https://ift.tt/Ff5Qd26
Cyberark
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
In this blog post, we present our approach for uncovering vulnerabilities by combining LLM reasoning with static analysis. By layering an LLM on top of CodeQL, we significantly reduce the...
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514
https://ift.tt/ZbLu20e
Submitted December 22, 2025 at 09:36AM by hfti
via reddit https://ift.tt/BMC1wT4
https://ift.tt/ZbLu20e
Submitted December 22, 2025 at 09:36AM by hfti
via reddit https://ift.tt/BMC1wT4
Amla Labs
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs
A critical vulnerability in mcp-remote affected 558,846 downloads. The bug was client-side, but the attack exploited OAuth dynamic discovery—a trust assumption that breaks for autonomous agents.
Cyberctf.space - Early Access Open
https://cyberctf.space
Submitted December 22, 2025 at 02:55PM by Royal_Independent517
via reddit https://ift.tt/SBI0Gzp
https://cyberctf.space
Submitted December 22, 2025 at 02:55PM by Royal_Independent517
via reddit https://ift.tt/SBI0Gzp
cyberctf.space
CyberCTF – Launching Soon
CyberCTF.space is launching soon. Join the waitlist for early access to hands-on cybersecurity CTF and Blue Team labs.
Microsoft Brokering File System Elevation of Privilege Vulnerability (CVE--2025-29970)
https://ift.tt/GoeYAv3
Submitted December 22, 2025 at 03:39PM by buherator
via reddit https://ift.tt/TKyrkCb
https://ift.tt/GoeYAv3
Submitted December 22, 2025 at 03:39PM by buherator
via reddit https://ift.tt/TKyrkCb
PixiePoint Security
Microsoft Brokering File System Elevation of Privilege Vulnerability | PixiePoint Security
About 2 years ago, Microsoft first released Win32-App-isolation which is a sandbox-like mechanism to further separate application access to resources on Windows clients. Brokering File System (BFS) was released around the same time to specifically …
I caught a Rust DDoS botnet on my honeypot, reverse engineered it, and now I'm monitoring its targets in real-time
https://ift.tt/wnWibJ8
Submitted December 22, 2025 at 09:17PM by mario_candela
via reddit https://ift.tt/AMg1h2N
https://ift.tt/wnWibJ8
Submitted December 22, 2025 at 09:17PM by mario_candela
via reddit https://ift.tt/AMg1h2N
Beelzebub
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets | AI deception platform
AI deception platform: Deceive, Detect, Respond. “You can’t defend. You can’t prevent. The only thing you can do is detect and respond.” Bruce Schneier. We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source…
19+ Vulnerabilities + PoCs for the MediaTek MT7622 Wifi Driver
https://ift.tt/5LwAo4Z
Submitted December 23, 2025 at 12:11AM by ahigherporpoise
via reddit https://ift.tt/64fBkEW
https://ift.tt/5LwAo4Z
Submitted December 23, 2025 at 12:11AM by ahigherporpoise
via reddit https://ift.tt/64fBkEW
hyprblog
mediatek? more like media-REKT, amirite.
A year-in-review going over 19+ bugs in Mediatek’s MT76xx/MT7915 (and others) wifi chipsets I reported this year, PoCs included!
how to hack discord, vercel and more with one easy trick - eva's site
https://ift.tt/Ev4oXAx
Submitted December 22, 2025 at 11:52PM by jrwren
via reddit https://ift.tt/5kY7qCa
https://ift.tt/Ev4oXAx
Submitted December 22, 2025 at 11:52PM by jrwren
via reddit https://ift.tt/5kY7qCa
Thank you reddit (u/broadexample) - updated version of my STIX feed
https://ift.tt/mrxPpqL
Submitted December 23, 2025 at 12:50AM by Clear_Ask9073
via reddit https://ift.tt/52Z7u8q
https://ift.tt/mrxPpqL
Submitted December 23, 2025 at 12:50AM by Clear_Ask9073
via reddit https://ift.tt/52Z7u8q
How Websites can detection Vision-Based AI Agents like Claude Computer Use and OpenAI Operator
https://ift.tt/Pc8iqwA
Submitted December 23, 2025 at 12:28AM by cport1
via reddit https://ift.tt/QB8pHYn
https://ift.tt/Pc8iqwA
Submitted December 23, 2025 at 12:28AM by cport1
via reddit https://ift.tt/QB8pHYn
Webdecoy
Detecting Vision-Based AI Agents: Operator and Beyond - WebDecoy
Detect Claude Computer Use and OpenAI Operator through timing analysis, cursor patterns, and prompt
Your Supabase Is Public
https://ift.tt/SBAqmnU
Submitted December 23, 2025 at 03:56AM by delsudo
via reddit https://ift.tt/xM3e5Ta
https://ift.tt/SBAqmnU
Submitted December 23, 2025 at 03:56AM by delsudo
via reddit https://ift.tt/xM3e5Ta
Skilldeliver
Your Supabase Is Public
I was chatting with a close friend of mine and he sent me a link to his new SaaS that he's developing.
Turning List-Unsubscribe into an SSRF/XSS Gadget
https://ift.tt/K5OTwjt
Submitted December 23, 2025 at 03:43PM by AlmondOffSec
via reddit https://ift.tt/PVnCHaf
https://ift.tt/K5OTwjt
Submitted December 23, 2025 at 03:43PM by AlmondOffSec
via reddit https://ift.tt/PVnCHaf
(Web-)Insecurity Blog
Turning List-Unsubscribe into an SSRF/XSS Gadget
The List-Unsubscribe SMTP header is standardized but often overlooked during security assessments. It allows email clients to provide an easy way for end-users to unsubscribe from mailing lists.
This post discusses how this header can be abused to perform…
This post discusses how this header can be abused to perform…
Guide to preventing the most common enterprise social engineering attacks
https://ift.tt/SBQYe6g
Submitted December 24, 2025 at 03:33AM by One_Asparagus7146
via reddit https://ift.tt/KOJc7VH
https://ift.tt/SBQYe6g
Submitted December 24, 2025 at 03:33AM by One_Asparagus7146
via reddit https://ift.tt/KOJc7VH
Dissecting a Multi-Stage macOS Infostealer
https://ift.tt/tuFwK5x
Submitted December 24, 2025 at 04:25AM by SpectreTv
via reddit https://ift.tt/FwMY81Z
https://ift.tt/tuFwK5x
Submitted December 24, 2025 at 04:25AM by SpectreTv
via reddit https://ift.tt/FwMY81Z
Rhys Downing
Dissecting a Multi-Stage macOS Infostealer
Deep dive into MacSync Stealer (UserSyncWorker variant), a MaaS infostealer featuring Gatekeeper bypass via notarized Swift dropper, code signature validation, and multi-layer payload obfuscation
Availability of old crypto exchange user email addresses? - Help to notify victims of the Bitfinex Hack - Now the largest forfeiture (113000 Bitcoins)
https://ift.tt/Iup8Q6j
Submitted December 24, 2025 at 05:36AM by ExpensivePrompt2902
via reddit https://ift.tt/3KyMqCm
https://ift.tt/Iup8Q6j
Submitted December 24, 2025 at 05:36AM by ExpensivePrompt2902
via reddit https://ift.tt/3KyMqCm
CourtListener
United States v. LICHTENSTEIN, 1:23-cr-00239 - CourtListener.com
Docket for United States v. LICHTENSTEIN, 1:23-cr-00239 — Brought to you by Free Law Project, a non-profit dedicated to creating high quality open legal information.
Linearizing SHA-256 via fractional modular analysis (Kaoru Method)
https://ift.tt/yohHFLz
Submitted December 24, 2025 at 11:03AM by No_Arachnid_5563
via reddit https://ift.tt/gRy8NLn
https://ift.tt/yohHFLz
Submitted December 24, 2025 at 11:03AM by No_Arachnid_5563
via reddit https://ift.tt/gRy8NLn
OSF
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction
This paper presents a groundbreaking cryptanalytic framework for the SHA-256 hash function. By mapping the 2^32 modular addition space into a fractional domain [0, 1), I demonstrate that the non-linear "noise" generated by modular overflows is not random…
Technical Deep Dive: How Early-Boot DMA Attacks are bypassing IOMMU on modern UEFI systems
https://ift.tt/kUwr86G
Submitted December 24, 2025 at 05:05PM by Imaginary-Ad-8278
via reddit https://ift.tt/izk53FI
https://ift.tt/kUwr86G
Submitted December 24, 2025 at 05:05PM by Imaginary-Ad-8278
via reddit https://ift.tt/izk53FI
NexasPecs
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks
Explore our extensive archive of in-depth tech reviews, scientific breakthroughs, and cybersecurity analysis. Find the specs, facts, and expert insig