Dissecting a Multi-Stage macOS Infostealer
https://ift.tt/tuFwK5x
Submitted December 24, 2025 at 04:25AM by SpectreTv
via reddit https://ift.tt/FwMY81Z
https://ift.tt/tuFwK5x
Submitted December 24, 2025 at 04:25AM by SpectreTv
via reddit https://ift.tt/FwMY81Z
Rhys Downing
Dissecting a Multi-Stage macOS Infostealer
Deep dive into MacSync Stealer (UserSyncWorker variant), a MaaS infostealer featuring Gatekeeper bypass via notarized Swift dropper, code signature validation, and multi-layer payload obfuscation
Availability of old crypto exchange user email addresses? - Help to notify victims of the Bitfinex Hack - Now the largest forfeiture (113000 Bitcoins)
https://ift.tt/Iup8Q6j
Submitted December 24, 2025 at 05:36AM by ExpensivePrompt2902
via reddit https://ift.tt/3KyMqCm
https://ift.tt/Iup8Q6j
Submitted December 24, 2025 at 05:36AM by ExpensivePrompt2902
via reddit https://ift.tt/3KyMqCm
CourtListener
United States v. LICHTENSTEIN, 1:23-cr-00239 - CourtListener.com
Docket for United States v. LICHTENSTEIN, 1:23-cr-00239 — Brought to you by Free Law Project, a non-profit dedicated to creating high quality open legal information.
Linearizing SHA-256 via fractional modular analysis (Kaoru Method)
https://ift.tt/yohHFLz
Submitted December 24, 2025 at 11:03AM by No_Arachnid_5563
via reddit https://ift.tt/gRy8NLn
https://ift.tt/yohHFLz
Submitted December 24, 2025 at 11:03AM by No_Arachnid_5563
via reddit https://ift.tt/gRy8NLn
OSF
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction
This paper presents a groundbreaking cryptanalytic framework for the SHA-256 hash function. By mapping the 2^32 modular addition space into a fractional domain [0, 1), I demonstrate that the non-linear "noise" generated by modular overflows is not random…
Technical Deep Dive: How Early-Boot DMA Attacks are bypassing IOMMU on modern UEFI systems
https://ift.tt/kUwr86G
Submitted December 24, 2025 at 05:05PM by Imaginary-Ad-8278
via reddit https://ift.tt/izk53FI
https://ift.tt/kUwr86G
Submitted December 24, 2025 at 05:05PM by Imaginary-Ad-8278
via reddit https://ift.tt/izk53FI
NexasPecs
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks
Explore our extensive archive of in-depth tech reviews, scientific breakthroughs, and cybersecurity analysis. Find the specs, facts, and expert insig
certgrep: a free CT search engine
https://certgrep.sh/
Submitted December 24, 2025 at 07:37PM by JDBHub
via reddit https://ift.tt/AZ820ON
https://certgrep.sh/
Submitted December 24, 2025 at 07:37PM by JDBHub
via reddit https://ift.tt/AZ820ON
Reddit
From the netsec community on Reddit: certgrep: a free CT search engine
Posted by JDBHub - 44 votes and 4 comments
WebSocket RCE in the CurseForge Launcher
https://ift.tt/bSDRhAr
Submitted December 25, 2025 at 05:29AM by elliott-diy
via reddit https://ift.tt/wMdGXPO
https://ift.tt/bSDRhAr
Submitted December 25, 2025 at 05:29AM by elliott-diy
via reddit https://ift.tt/wMdGXPO
elliott.diy
When WebSockets Lead to RCE in CurseForge
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
CSRF Protection without Tokens or Hidden Form Fields
https://ift.tt/AfSJVwv
Submitted December 25, 2025 at 04:27PM by AlmondOffSec
via reddit https://ift.tt/xYo6c4b
https://ift.tt/AfSJVwv
Submitted December 25, 2025 at 04:27PM by AlmondOffSec
via reddit https://ift.tt/xYo6c4b
Miguelgrinberg
CSRF Protection without Tokens or Hidden Form Fields
A couple of months ago, I received a request from a random Internet user to add CSRF protection to my little web framework Microdot, and I thought it was a fantastic idea.When I set off to do this…
LangGrinch: A Bug in the Library, A Lesson for the Architecture
https://ift.tt/5lUg4rF
Submitted December 26, 2025 at 04:07PM by hfti
via reddit https://ift.tt/03XHplB
https://ift.tt/5lUg4rF
Submitted December 26, 2025 at 04:07PM by hfti
via reddit https://ift.tt/03XHplB
Amla Labs
LangGrinch: A Bug in the Library, A Lesson for the Architecture | Amla Labs
A critical CVE in LangChain shows why credential isolation matters more than perfect code.
How do you handle daily news fatigue? Looking for feedback on a curation project.
https://ift.tt/TXh2NV6
Submitted December 26, 2025 at 03:37PM by Big-Engineering-9365
via reddit https://ift.tt/NYWy05R
https://ift.tt/TXh2NV6
Submitted December 26, 2025 at 03:37PM by Big-Engineering-9365
via reddit https://ift.tt/NYWy05R
Substack
Threat Road | Alex from Threat Road | Substack
Infosec news that doesn’t make you want to quit tech. Click to read Threat Road, by Alex from Threat Road, a Substack publication. Launched 2 months ago.
First verified SHA-256 second-preimage collision: Structural analysis of the W-schedule vulnerability
https://ift.tt/Eoxevtr
Submitted December 27, 2025 at 07:33AM by No_Arachnid_5563
via reddit https://ift.tt/NPeMUAq
https://ift.tt/Eoxevtr
Submitted December 27, 2025 at 07:33AM by No_Arachnid_5563
via reddit https://ift.tt/NPeMUAq
OSF
FIRST_REAL_COLISION_SHA_256_ENGLISH.ipynb
Why runtime attacks stay quiet for so long
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 03:26PM by OKAMI_TAMA
via reddit https://ift.tt/M4vZQ3c
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 03:26PM by OKAMI_TAMA
via reddit https://ift.tt/M4vZQ3c
Why runtime attacks stay quiet for so long
https://www.armosec.io/
Submitted December 27, 2025 at 04:05PM by OKAMI_TAMA
via reddit https://ift.tt/Ns1ZPBT
https://www.armosec.io/
Submitted December 27, 2025 at 04:05PM by OKAMI_TAMA
via reddit https://ift.tt/Ns1ZPBT
ARMO
ARMO: Runtime Behavioral Cloud Application Detection & Response (CADR)
Zero-day and every day protection for your cloud applications with a complete explainable & traceable runtime security story.
Mongobleed - CVE-2025-14847
https://ift.tt/AlQUhPw
Submitted December 27, 2025 at 06:45PM by depierre
via reddit https://ift.tt/vnkqSrT
https://ift.tt/AlQUhPw
Submitted December 27, 2025 at 06:45PM by depierre
via reddit https://ift.tt/vnkqSrT
Medium
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
Early warning signs of runtime compromise
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 08:24PM by AviMitz_
via reddit https://ift.tt/mwbp4H3
https://ift.tt/ai9uv3X
Submitted December 27, 2025 at 08:24PM by AviMitz_
via reddit https://ift.tt/mwbp4H3
Reddit
From the netsec community on Reddit: Early warning signs of runtime compromise
Posted by AviMitz_ - 0 votes and 0 comments
Implicit execution authority is the real failure mode behind prompt injection
https://ift.tt/uvNExDw
Submitted December 27, 2025 at 11:27PM by anima-core
via reddit https://ift.tt/t7u8j0F
https://ift.tt/uvNExDw
Submitted December 27, 2025 at 11:27PM by anima-core
via reddit https://ift.tt/t7u8j0F
Zenodo
Authority Separation in AI Systems: Structural Guarantees Across Security, Epistemics, Economics, and Safety
This paper introduces authority separation as a foundational architectural principle for AI systems in which language models propose actions but do not authorize execution. We demonstrate that separating generation from execution authority provides structural…
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
https://ift.tt/9rZUbeS
Submitted December 28, 2025 at 01:51AM by AlmondOffSec
via reddit https://ift.tt/oWYciMV
https://ift.tt/9rZUbeS
Submitted December 28, 2025 at 01:51AM by AlmondOffSec
via reddit https://ift.tt/oWYciMV
Bobdahacker
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - and how they're still leaving the auth bypass active for…
Identity misuse that looks completely normal
https://www.armosec.io/
Submitted December 28, 2025 at 12:52PM by Additional_Bar8316
via reddit https://ift.tt/146c7tj
https://www.armosec.io/
Submitted December 28, 2025 at 12:52PM by Additional_Bar8316
via reddit https://ift.tt/146c7tj
ARMO
ARMO: Runtime Behavioral Cloud Application Detection & Response (CADR)
Zero-day and every day protection for your cloud applications with a complete explainable & traceable runtime security story.
Detecting unknown MCPs in local dev environments
https://example.com
Submitted December 29, 2025 at 07:51PM by Ok-Guide-4239
via reddit https://ift.tt/u534Eti
https://example.com
Submitted December 29, 2025 at 07:51PM by Ok-Guide-4239
via reddit https://ift.tt/u534Eti
Reddit
From the netsec community on Reddit: [ Removed by moderator ]
Posted by Ok-Guide-4239 - 7 votes and 4 comments
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools
https://ift.tt/EPXWtlN
Submitted December 29, 2025 at 11:58PM by LordAlfredo
via reddit https://ift.tt/4xMVSAb
https://ift.tt/EPXWtlN
Submitted December 29, 2025 at 11:58PM by LordAlfredo
via reddit https://ift.tt/4xMVSAb
c't Magazin
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools
Security researchers have found various security-relevant errors in GnuPG and similar programs. Many of the vulnerabilities are (still) not fixed.
Mitigating npm supply chain attacks using local Levenshtein distance and metadata analysis
https://pchavali09.github.io/posts/npm-guard/
Submitted December 30, 2025 at 03:36AM by WestCoralVoice
via reddit https://ift.tt/JTvyCbu
https://pchavali09.github.io/posts/npm-guard/
Submitted December 30, 2025 at 03:36AM by WestCoralVoice
via reddit https://ift.tt/JTvyCbu
Pavan Chavali
Vibe Coding, Phantom Dependencies, and Why You Need a Bouncer for npm
AI coding introduces "Phantom Dependencies" that bypass traditional scanners. Learn how npm-guard blocks malicious packages at the shell level before execution.
RMM Abuse in a Crypto Wallet Distribution Campaign
https://ift.tt/WvIL4Cf
Submitted December 31, 2025 at 02:33AM by anuraggawande
via reddit https://ift.tt/z4kyFxe
https://ift.tt/WvIL4Cf
Submitted December 31, 2025 at 02:33AM by anuraggawande
via reddit https://ift.tt/z4kyFxe
Malware Analysis, Phishing, and Email Scams
RMM Abuse in a Crypto Wallet Distribution Campaign
Analysis of a Suspicious “Eternl Desktop” MSI Installer Dropping LogMeIn Resolve Overview A professionally written announcement email titled “Eternl Desktop Is Live — Secure Execution for Atrium &a…