Turning List-Unsubscribe into an SSRF/XSS Gadget
https://ift.tt/K5OTwjt
Submitted December 23, 2025 at 03:43PM by AlmondOffSec
via reddit https://ift.tt/PVnCHaf
https://ift.tt/K5OTwjt
Submitted December 23, 2025 at 03:43PM by AlmondOffSec
via reddit https://ift.tt/PVnCHaf
(Web-)Insecurity Blog
Turning List-Unsubscribe into an SSRF/XSS Gadget
The List-Unsubscribe SMTP header is standardized but often overlooked during security assessments. It allows email clients to provide an easy way for end-users to unsubscribe from mailing lists.
This post discusses how this header can be abused to perform…
This post discusses how this header can be abused to perform…
Guide to preventing the most common enterprise social engineering attacks
https://ift.tt/SBQYe6g
Submitted December 24, 2025 at 03:33AM by One_Asparagus7146
via reddit https://ift.tt/KOJc7VH
https://ift.tt/SBQYe6g
Submitted December 24, 2025 at 03:33AM by One_Asparagus7146
via reddit https://ift.tt/KOJc7VH
Dissecting a Multi-Stage macOS Infostealer
https://ift.tt/tuFwK5x
Submitted December 24, 2025 at 04:25AM by SpectreTv
via reddit https://ift.tt/FwMY81Z
https://ift.tt/tuFwK5x
Submitted December 24, 2025 at 04:25AM by SpectreTv
via reddit https://ift.tt/FwMY81Z
Rhys Downing
Dissecting a Multi-Stage macOS Infostealer
Deep dive into MacSync Stealer (UserSyncWorker variant), a MaaS infostealer featuring Gatekeeper bypass via notarized Swift dropper, code signature validation, and multi-layer payload obfuscation
Availability of old crypto exchange user email addresses? - Help to notify victims of the Bitfinex Hack - Now the largest forfeiture (113000 Bitcoins)
https://ift.tt/Iup8Q6j
Submitted December 24, 2025 at 05:36AM by ExpensivePrompt2902
via reddit https://ift.tt/3KyMqCm
https://ift.tt/Iup8Q6j
Submitted December 24, 2025 at 05:36AM by ExpensivePrompt2902
via reddit https://ift.tt/3KyMqCm
CourtListener
United States v. LICHTENSTEIN, 1:23-cr-00239 - CourtListener.com
Docket for United States v. LICHTENSTEIN, 1:23-cr-00239 — Brought to you by Free Law Project, a non-profit dedicated to creating high quality open legal information.
Linearizing SHA-256 via fractional modular analysis (Kaoru Method)
https://ift.tt/yohHFLz
Submitted December 24, 2025 at 11:03AM by No_Arachnid_5563
via reddit https://ift.tt/gRy8NLn
https://ift.tt/yohHFLz
Submitted December 24, 2025 at 11:03AM by No_Arachnid_5563
via reddit https://ift.tt/gRy8NLn
OSF
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction
This paper presents a groundbreaking cryptanalytic framework for the SHA-256 hash function. By mapping the 2^32 modular addition space into a fractional domain [0, 1), I demonstrate that the non-linear "noise" generated by modular overflows is not random…
Technical Deep Dive: How Early-Boot DMA Attacks are bypassing IOMMU on modern UEFI systems
https://ift.tt/kUwr86G
Submitted December 24, 2025 at 05:05PM by Imaginary-Ad-8278
via reddit https://ift.tt/izk53FI
https://ift.tt/kUwr86G
Submitted December 24, 2025 at 05:05PM by Imaginary-Ad-8278
via reddit https://ift.tt/izk53FI
NexasPecs
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks
Explore our extensive archive of in-depth tech reviews, scientific breakthroughs, and cybersecurity analysis. Find the specs, facts, and expert insig
certgrep: a free CT search engine
https://certgrep.sh/
Submitted December 24, 2025 at 07:37PM by JDBHub
via reddit https://ift.tt/AZ820ON
https://certgrep.sh/
Submitted December 24, 2025 at 07:37PM by JDBHub
via reddit https://ift.tt/AZ820ON
Reddit
From the netsec community on Reddit: certgrep: a free CT search engine
Posted by JDBHub - 4 votes and 0 comments
WebSocket RCE in the CurseForge Launcher
https://ift.tt/bSDRhAr
Submitted December 25, 2025 at 05:29AM by elliott-diy
via reddit https://ift.tt/wMdGXPO
https://ift.tt/bSDRhAr
Submitted December 25, 2025 at 05:29AM by elliott-diy
via reddit https://ift.tt/wMdGXPO
elliott.diy
When WebSockets Lead to RCE in CurseForge
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
CSRF Protection without Tokens or Hidden Form Fields
https://ift.tt/AfSJVwv
Submitted December 25, 2025 at 04:27PM by AlmondOffSec
via reddit https://ift.tt/xYo6c4b
https://ift.tt/AfSJVwv
Submitted December 25, 2025 at 04:27PM by AlmondOffSec
via reddit https://ift.tt/xYo6c4b
Miguelgrinberg
CSRF Protection without Tokens or Hidden Form Fields
A couple of months ago, I received a request from a random Internet user to add CSRF protection to my little web framework Microdot, and I thought it was a fantastic idea.When I set off to do this…
LangGrinch: A Bug in the Library, A Lesson for the Architecture
https://ift.tt/5lUg4rF
Submitted December 26, 2025 at 04:07PM by hfti
via reddit https://ift.tt/03XHplB
https://ift.tt/5lUg4rF
Submitted December 26, 2025 at 04:07PM by hfti
via reddit https://ift.tt/03XHplB
Amla Labs
LangGrinch: A Bug in the Library, A Lesson for the Architecture | Amla Labs
A critical CVE in LangChain shows why credential isolation matters more than perfect code.
How do you handle daily news fatigue? Looking for feedback on a curation project.
https://ift.tt/TXh2NV6
Submitted December 26, 2025 at 03:37PM by Big-Engineering-9365
via reddit https://ift.tt/NYWy05R
https://ift.tt/TXh2NV6
Submitted December 26, 2025 at 03:37PM by Big-Engineering-9365
via reddit https://ift.tt/NYWy05R
Substack
Threat Road | Alex from Threat Road | Substack
Infosec news that doesn’t make you want to quit tech. Click to read Threat Road, by Alex from Threat Road, a Substack publication. Launched a month ago.
First verified SHA-256 second-preimage collision: Structural analysis of the W-schedule vulnerability
https://ift.tt/Eoxevtr
Submitted December 27, 2025 at 07:33AM by No_Arachnid_5563
via reddit https://ift.tt/NPeMUAq
https://ift.tt/Eoxevtr
Submitted December 27, 2025 at 07:33AM by No_Arachnid_5563
via reddit https://ift.tt/NPeMUAq
OSF
FIRST_REAL_COLISION_SHA_256_ENGLISH.ipynb
Why runtime attacks stay quiet for so long
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 03:26PM by OKAMI_TAMA
via reddit https://ift.tt/M4vZQ3c
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 03:26PM by OKAMI_TAMA
via reddit https://ift.tt/M4vZQ3c
Why runtime attacks stay quiet for so long
https://www.armosec.io/
Submitted December 27, 2025 at 04:05PM by OKAMI_TAMA
via reddit https://ift.tt/Ns1ZPBT
https://www.armosec.io/
Submitted December 27, 2025 at 04:05PM by OKAMI_TAMA
via reddit https://ift.tt/Ns1ZPBT
ARMO
ARMO: Runtime Behavioral Cloud Application Detection & Response (CADR)
Zero-day and every day protection for your cloud applications with a complete explainable & traceable runtime security story.
Mongobleed - CVE-2025-14847
https://ift.tt/AlQUhPw
Submitted December 27, 2025 at 06:45PM by depierre
via reddit https://ift.tt/vnkqSrT
https://ift.tt/AlQUhPw
Submitted December 27, 2025 at 06:45PM by depierre
via reddit https://ift.tt/vnkqSrT
Medium
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
Early warning signs of runtime compromise
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 08:24PM by AviMitz_
via reddit https://ift.tt/mwbp4H3
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 08:24PM by AviMitz_
via reddit https://ift.tt/mwbp4H3
Reddit
From the netsec community on Reddit: Early warning signs of runtime compromise
Posted by AviMitz_ - 0 votes and 0 comments
Implicit execution authority is the real failure mode behind prompt injection
https://ift.tt/uvNExDw
Submitted December 27, 2025 at 11:27PM by anima-core
via reddit https://ift.tt/t7u8j0F
https://ift.tt/uvNExDw
Submitted December 27, 2025 at 11:27PM by anima-core
via reddit https://ift.tt/t7u8j0F
Zenodo
Authority Separation in AI Systems: Structural Guarantees Across Security, Epistemics, Economics, and Safety
This paper introduces authority separation as a foundational architectural principle for AI systems in which language models propose actions but do not authorize execution. We demonstrate that separating generation from execution authority provides structural…
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
https://ift.tt/9rZUbeS
Submitted December 28, 2025 at 01:51AM by AlmondOffSec
via reddit https://ift.tt/oWYciMV
https://ift.tt/9rZUbeS
Submitted December 28, 2025 at 01:51AM by AlmondOffSec
via reddit https://ift.tt/oWYciMV
Bobdahacker
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - and how they're still leaving the auth bypass active for…