Analysis of the April 2026 Booking.com Supply Chain Breach and ClickFix Tactics
https://ift.tt/tRYqypm
Submitted April 21, 2026 at 01:59AM by CNRC0
via reddit https://ift.tt/7xEHluO
https://ift.tt/tRYqypm
Submitted April 21, 2026 at 01:59AM by CNRC0
via reddit https://ift.tt/7xEHluO
Medium
Booking.com Got Breached. Your Reservation Was the Weapon.
In april 13th 2026, online travel agency booking.com issued a major notification that echoed back to 2021. There was unauthorized access to…
Command Execution via Drag-and-Drop in Terminal Emulators
https://sdushantha.github.io/post/drop-it-like-its-hot
Submitted April 21, 2026 at 11:08AM by rushedcar
via reddit https://ift.tt/c3ubL01
https://sdushantha.github.io/post/drop-it-like-its-hot
Submitted April 21, 2026 at 11:08AM by rushedcar
via reddit https://ift.tt/c3ubL01
Reddit
From the netsec community on Reddit: Command Execution via Drag-and-Drop in Terminal Emulators
Posted by rushedcar - 2 votes and 0 comments
We analysed almost 100 UK charity websites and found that ~1 in 6 are running vulnerable JavaScript dependencies.
https://ift.tt/yx0e9YE
Submitted April 21, 2026 at 04:54PM by JoeTiedeman
via reddit https://ift.tt/0PIlSc3
https://ift.tt/yx0e9YE
Submitted April 21, 2026 at 04:54PM by JoeTiedeman
via reddit https://ift.tt/0PIlSc3
cybaa.io
Web Dependency Risk in UK Health & Charity Websites in 2026 | Cybaa Blog
Cybaa analysed ~90 UK charities and found that **1 in 6 websites are running vulnerable JavaScript dependencies**, including High and Critical severity issues.
P4WNED: How Insecure Defaults in Perforce Expose Source Code Across the Internet
https://ift.tt/tYV09BF
Submitted April 21, 2026 at 08:22PM by sleepface
via reddit https://ift.tt/b6dl2kS
https://ift.tt/tYV09BF
Submitted April 21, 2026 at 08:22PM by sleepface
via reddit https://ift.tt/b6dl2kS
Two new critical Spinnaker vulns allow RCE and production access
https://ift.tt/KpE7FIw
Submitted April 21, 2026 at 11:35PM by Prior-Penalty
via reddit https://ift.tt/Vpcq0Rz
https://ift.tt/KpE7FIw
Submitted April 21, 2026 at 11:35PM by Prior-Penalty
via reddit https://ift.tt/Vpcq0Rz
Zeropath
Critical 10.0 Spinnaker Vulns Allow RCE And Production Compromise - ZeroPath Blog
ZeroPath Research discovered two separate RCE vulnerabilities in Spinnaker (CVE-2026-32604 and CVE-2026-32613) that let low-privilege authenticated users execute code on Clouddriver and Echo, enabling credential theft and pivots into production cloud environments.
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
https://ift.tt/l0bDyf1
Submitted April 22, 2026 at 01:22AM by si9int
via reddit https://ift.tt/vgRmPzV
https://ift.tt/l0bDyf1
Submitted April 22, 2026 at 01:22AM by si9int
via reddit https://ift.tt/vgRmPzV
words.filippo.io
Quantum Computers Are Not a Threat to 128-bit Symmetric Keys
There is no need to update symmetric key sizes as part of the post-quantum transition, due to the details of how Grover's algorithm scales. Most authorities agree.
Vercel OAuth breach analysis: Context.ai compromise, MITRE T1199 trust-chain attack, IOC for Google Workspace admins
https://ift.tt/8fpM5lH
Submitted April 22, 2026 at 04:15AM by haddblack
via reddit https://ift.tt/kBIQ91C
https://ift.tt/8fpM5lH
Submitted April 22, 2026 at 04:15AM by haddblack
via reddit https://ift.tt/kBIQ91C
Reverse-engineering a targeted npm supply chain attack with two-stage C2 — full forensic analysis
https://www.reymom.xyz/blog/security/2026-04-15-supply-chain-attack
Submitted April 22, 2026 at 07:51PM by UnusualRepair9817
via reddit https://ift.tt/6pudz5H
https://www.reymom.xyz/blog/security/2026-04-15-supply-chain-attack
Submitted April 22, 2026 at 07:51PM by UnusualRepair9817
via reddit https://ift.tt/6pudz5H
www.reymom.xyz
Reverse-Engineering a North-Korean-Style Supply Chain Attack Delivered via Fake Web3 Job Interview
Full forensic analysis of a targeted supply chain attack delivered through a fake Web3 job interview. A single npm install silently deployed a two-stage RAT: an initial loader that decrypts a second-stage C2 endpoint, exfiltrates the full process environment…
Extending my access: Abusing installed extensions for post compromise
https://futuresight.club/posts/extending-my-access/
Submitted April 22, 2026 at 03:15PM by futuresightgroup
via reddit https://ift.tt/aUbqZsE
https://futuresight.club/posts/extending-my-access/
Submitted April 22, 2026 at 03:15PM by futuresightgroup
via reddit https://ift.tt/aUbqZsE
Reddit
From the netsec community on Reddit: Extending my access: Abusing installed extensions for post compromise
Posted by futuresightgroup - 2 votes and 0 comments
Pack2TheRoot (CVE-2026-41651): Cross-Distro Local Privilege Escalation Vulnerability
https://ift.tt/kMT2LrY
Submitted April 23, 2026 at 01:36AM by TyrHeimdal
via reddit https://ift.tt/gt91uFj
https://ift.tt/kMT2LrY
Submitted April 23, 2026 at 01:36AM by TyrHeimdal
via reddit https://ift.tt/gt91uFj
Telekom Security
Pack2TheRoot (CVE-2026-41651): Cross-Distro Local Privilege Escalation Vulnerability
Pack2TheRoot (CVE-2026-41651) is a local privilege escalation (LPE) vulnerability that affects multiple Linux distributions in default installations.
Thousands of Live Secrets Found Across Four Cloud Development Environments
https://ift.tt/e65yxV8
Submitted April 23, 2026 at 02:58AM by Grand_Fan_9804
via reddit https://ift.tt/vujhxbi
https://ift.tt/e65yxV8
Submitted April 23, 2026 at 02:58AM by Grand_Fan_9804
via reddit https://ift.tt/vujhxbi
Trufflesecurity
Thousands of Live Secrets Found Across Four Cloud Development Environments ◆ Truffle Security Co.
I scanned 22 million public Cloud Development Environment projects across CodeSandbox, StackBlitz, CodePen, and JSFiddle with TruffleHog, found 8,792 verified, unique secrets, and made over $20,000 in bounties along the way. The most impactful finding was…
Static analysis of PayPal Android app reveals 13 embedded SDKs including Meta SDK and Adobe Analytics inside a payment app
https://ift.tt/FQrIhu0
Submitted April 23, 2026 at 04:41AM by MahereMarley
via reddit https://ift.tt/HSt3dzy
https://ift.tt/FQrIhu0
Submitted April 23, 2026 at 04:41AM by MahereMarley
via reddit https://ift.tt/HSt3dzy
appxpose.app
PayPal Privacy Scan — 13 Trackers, Microphone on a Payment App
Your payment app has 13 trackers — Meta SDK, Google AdMob, Adjust — plus microphone and GPS access. Why?
LLM Security Automation Isn’t a Drop-In Scanner Yet
https://ift.tt/mJtWekN
Submitted April 23, 2026 at 11:53AM by lirantal
via reddit https://ift.tt/QjhouKg
https://ift.tt/mJtWekN
Submitted April 23, 2026 at 11:53AM by lirantal
via reddit https://ift.tt/QjhouKg
Liran Tal
LLM Security Automation Isn’t a Drop-In Scanner Yet
An LLM Security Scanning and Review is a strong assist but a weeak gate. Why a `/security-review` slash command or agent harness is not a drop-in replacement for deterministic scanners yet: nondeterminism, confabulation, latency, cost, exploitability of generated…
OAuth 2.0 BCP §4.14 reuse detection in practice — race vs theft disambiguation
https://ift.tt/gSpW1Dj
Submitted April 23, 2026 at 09:27PM by No_Ask_468
via reddit https://ift.tt/CUqotmb
https://ift.tt/gSpW1Dj
Submitted April 23, 2026 at 09:27PM by No_Ask_468
via reddit https://ift.tt/CUqotmb
CVE-2026-34621: Adobe Acrobat Reader zero-day was on VirusTotal for 136 days before Adobe named it a CVE
https://ift.tt/Xdiwxcb
Submitted April 23, 2026 at 11:57PM by TakesThisSeriously
via reddit https://ift.tt/zjgPDWi
https://ift.tt/Xdiwxcb
Submitted April 23, 2026 at 11:57PM by TakesThisSeriously
via reddit https://ift.tt/zjgPDWi
Nefariousplan
CVE-2026-34621 Revisited: The 136-Day Detection Lie
On November 28, 2025, someone uploaded a PDF to VirusTotal. The filename was Invoice540.pdf. Thirteen of sixty-four antivirus engines flagged it. The other fifty-one saw a document.
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
https://ift.tt/XAsOaHu
Submitted April 24, 2026 at 04:10AM by ApprehensiveEssay222
via reddit https://ift.tt/udhyLoK
https://ift.tt/XAsOaHu
Submitted April 24, 2026 at 04:10AM by ApprehensiveEssay222
via reddit https://ift.tt/udhyLoK
Socket
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain ...
Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.
UK Biobank Health Data of 500K Listed for Sale in China
https://ift.tt/jqJuIAs
Submitted April 24, 2026 at 03:59AM by QuantumQuicksilver
via reddit https://ift.tt/Uki2ngA
https://ift.tt/jqJuIAs
Submitted April 24, 2026 at 03:59AM by QuantumQuicksilver
via reddit https://ift.tt/Uki2ngA
Verity
Verity - UK Biobank Health Data of 500K Listed for Sale in China
The U.K. government confirmed on Thursday that anonymized health data from UK Biobank had been found listed for sale on Xianyu, a Chinese e-commerce platform owned by Alibaba. Three separate listin...
Why Pure-LLM CTFs Don't Work: A Hybrid Architecture for AI Security Challenges
https://ift.tt/shqpeRL
Submitted April 24, 2026 at 07:35AM by harbinger-alpha
via reddit https://ift.tt/KmBk8so
https://ift.tt/shqpeRL
Submitted April 24, 2026 at 07:35AM by harbinger-alpha
via reddit https://ift.tt/KmBk8so
Wraith
Why Pure-LLM CTFs Don't Work: A Hybrid Architecture for AI Security Challenges
Pure-LLM CTFs are unreliable because model alignment training fights your characters. Pure-deterministic CTFs teach pattern matching, not attack patterns. Here's the hybrid approach the Wraith Academy uses, and why it took a few iterations to get there.
Fixing the Exploit Didn’t Fix the System: An Exploration of Trust Boundaries
https://ift.tt/ldYX54b
Submitted April 24, 2026 at 08:29AM by iamnotafermiparadox
via reddit https://ift.tt/sD5rkxA
https://ift.tt/ldYX54b
Submitted April 24, 2026 at 08:29AM by iamnotafermiparadox
via reddit https://ift.tt/sD5rkxA
Substack
The Internal Tool We All Build
Introduction: Why This Exists
What Really Happened In There? A Tamper-Evident Audit Trail for AI Agents
https://ift.tt/w1cXkSF
Submitted April 24, 2026 at 03:03PM by Remote_Parsnip_5827
via reddit https://ift.tt/qfNJSdK
https://ift.tt/w1cXkSF
Submitted April 24, 2026 at 03:03PM by Remote_Parsnip_5827
via reddit https://ift.tt/qfNJSdK
nono.sh
What Really Happened In There? A Tamper-Evident Audit Trail for AI Agents
How nono records every action an AI agent makes in an append-only Merkle tree the agent itself cannot reach, and lets anyone verify after the fact — with cryptographic proof — that the record was not forged, edited, or truncated.