Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass) - watchTowr Labs
https://ift.tt/LGba8Ye
Submitted January 22, 2026 at 06:00AM by dx7r__
via reddit https://ift.tt/Qv6T37s
https://ift.tt/LGba8Ye
Submitted January 22, 2026 at 06:00AM by dx7r__
via reddit https://ift.tt/Qv6T37s
watchTowr Labs
Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)
Well, well, well - look what we’re back with.
You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV holders.
…
You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV holders.
…
[FREE DATASET] 67K+ domains with technology fingerprints
https://ift.tt/yEMaG1u
Submitted January 22, 2026 at 10:18AM by Upper-Character-6743
via reddit https://ift.tt/ygBt5iK
https://ift.tt/yEMaG1u
Submitted January 22, 2026 at 10:18AM by Upper-Character-6743
via reddit https://ift.tt/ygBt5iK
Dropbox
sample_dec_2025.zip
Shared with Dropbox
Single malformed BRID/HHIT DNS packet can crash ISC BIND
https://ift.tt/wUuTDgp
Submitted January 22, 2026 at 05:25PM by div3rto
via reddit https://ift.tt/W1PBK2u
https://ift.tt/wUuTDgp
Submitted January 22, 2026 at 05:25PM by div3rto
via reddit https://ift.tt/W1PBK2u
AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent
https://ift.tt/5T7ZmGA
Submitted January 22, 2026 at 07:04PM by ulldma
via reddit https://ift.tt/tLHze0G
https://ift.tt/5T7ZmGA
Submitted January 22, 2026 at 07:04PM by ulldma
via reddit https://ift.tt/tLHze0G
The GitHub Blog
AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent
Learn how we are using the newly released GitHub Security Lab Taskflow Agent to triage categories of vulnerabilities.
Intercepting OkHttp at Runtime With Frida
https://ift.tt/t7JEhgq
Submitted January 22, 2026 at 07:47PM by nibblesec
via reddit https://ift.tt/oHSW5fz
https://ift.tt/t7JEhgq
Submitted January 22, 2026 at 07:47PM by nibblesec
via reddit https://ift.tt/oHSW5fz
Doyensec
Intercepting OkHttp at Runtime With Frida - A Practical Guide
OkHttp is the defacto standard HTTP client library for the Android ecosystem. It is therefore crucial for a security analyst to be able to dynamically eavesdrop the traffic generated by this library during testing. While it might seem easy, this task is far…
CVE-2026-22200: Ticket to Shell in osTicket
https://ift.tt/5yKlZW8
Submitted January 22, 2026 at 09:41PM by scopedsecurity
via reddit https://ift.tt/mDrysoK
https://ift.tt/5yKlZW8
Submitted January 22, 2026 at 09:41PM by scopedsecurity
via reddit https://ift.tt/mDrysoK
Horizon3.ai
CVE-2026-22200: Ticket to Shell in osTicket
CVE-2026-22200 impacts osTicket and lets anonymous attackers read arbitrary files and, in some cases, achieve RCE. Patched in osTicket 1.18.3 / 1.17.7.
Firefox / WebRTC Encoded Transforms: UAF via undetached ArrayBuffer / CVE-2025-1432
https://ift.tt/tHqVDuZ
Submitted January 23, 2026 at 12:37PM by MegaManSec2
via reddit https://ift.tt/mn3dej5
https://ift.tt/tHqVDuZ
Submitted January 23, 2026 at 12:37PM by MegaManSec2
via reddit https://ift.tt/mn3dej5
AISLE
AISLE - AI-Native Cybersecurity Platform
AISLE is the world's best AI-native platform, purpose-built to find what others miss, remediate end-to-end, and verify every fix.
Free URL & site security scanner: ScanMalware.com • Scan websites for threats. Would love feedback on detection, reporting, API, UX from the netsec crowd
https://scanmalware.com
Submitted January 23, 2026 at 03:53PM by jonas02
via reddit https://ift.tt/BtVSlDT
https://scanmalware.com
Submitted January 23, 2026 at 03:53PM by jonas02
via reddit https://ift.tt/BtVSlDT
ScanMalware.com
Free URL Scanner - Check Website for Malware | ScanMalware
Instantly scan any URL for malware, phishing, and security threats. Free online website security scanner with real-time analysis, threat detection, and comprehensive vulnerability assessment.
Arctic Wolf Observes Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts | Arctic Wolf
https://ift.tt/LtM9lEK
Submitted January 23, 2026 at 06:19PM by SleepingProcess
via reddit https://ift.tt/Tmkof9A
https://ift.tt/LtM9lEK
Submitted January 23, 2026 at 06:19PM by SleepingProcess
via reddit https://ift.tt/Tmkof9A
Arctic Wolf
Arctic Wolf Observes Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts | Arctic Wolf
Arctic Wolf has observed a new cluster of automated malicious activity involving unauthorized firewall configuration changes on FortiGate devices.
Organized Traffer Gang on the Rise Targeting Web3 Employees and Crypto Holders
https://ift.tt/7vtZWwc
Submitted January 23, 2026 at 07:33PM by CyberMasterV
via reddit https://ift.tt/YvcSXtn
https://ift.tt/7vtZWwc
Submitted January 23, 2026 at 07:33PM by CyberMasterV
via reddit https://ift.tt/YvcSXtn
Blogspot
Organized Traffer Gang on the Rise Targeting Web3 Employees and Crypto Holders
Author(s): Vlad Pasca, Radu-Emanuel Chiscariu Sophisticated cybercriminal operation targets cryptocurrency users and Web3 employees Malwa...
Syd - Air-Gapped Red and blueteam
http://sydsec.co.uk
Submitted January 23, 2026 at 07:19PM by Glass-Ant-6041
via reddit https://ift.tt/Z6f09NC
http://sydsec.co.uk
Submitted January 23, 2026 at 07:19PM by Glass-Ant-6041
via reddit https://ift.tt/Z6f09NC
www.sydsec.co.uk
Syd - Air-Gapped Cybersecurity AI
Free, open-source AI for security pros in air-gapped environments.
Y2K38 as a security risk for vulnerable systems today. Not in 12 years, but right now.
https://ift.tt/JHZmxT0
Submitted January 24, 2026 at 12:44AM by JollyCartoonist3702
via reddit https://ift.tt/ElFRPT3
https://ift.tt/JHZmxT0
Submitted January 24, 2026 at 12:44AM by JollyCartoonist3702
via reddit https://ift.tt/ElFRPT3
Bitsight
Forward to the Past: The Y2K38 Problem Ahead | Bitsight
The Y2K38 problem threatens legacy 32-bit systems in 2038. Understand the risks, affected systems, and mitigation strategies.
Correctly interpreting DMARC, SPF, and DKIM enforcement in DNS security
https://ift.tt/SZDau4K
Submitted January 24, 2026 at 03:31AM by Odd_Woodpecker_6286
via reddit https://ift.tt/C7MrXg6
https://ift.tt/SZDau4K
Submitted January 24, 2026 at 03:31AM by Odd_Woodpecker_6286
via reddit https://ift.tt/C7MrXg6
www.it-help.tech
DNS Security Best Practices: Defend Your Domain with DMARC, SPF & DKIM
Learn how to set up DMARC, SPF, & DKIM for robust DNS security. Protect your business email from spoofing, phishing, and BEC attacks with these best practices.
Prompt injection is No 1 Security threat for most systems.
https://ift.tt/KwLIPdo
Submitted January 24, 2026 at 03:47PM by Suchitra_idumina
via reddit https://ift.tt/Qkd3TJI
https://ift.tt/KwLIPdo
Submitted January 24, 2026 at 03:47PM by Suchitra_idumina
via reddit https://ift.tt/Qkd3TJI
Antijection
Prompt Injection: The Security Vulnerability That Can Compromise Your Entire System
Understanding the #1 LLM security threat before it takes down your database
BREAKMEIFYOUCAN! - Exploiting Keyspace Reduction and Relay Attacks in 3DES and AES-protected NFC Technologies
https://ift.tt/GYWipRS
Submitted January 25, 2026 at 06:48AM by netsec_burn
via reddit https://ift.tt/g8sFAjJ
https://ift.tt/GYWipRS
Submitted January 25, 2026 at 06:48AM by netsec_burn
via reddit https://ift.tt/g8sFAjJ
BREAKMEIFYOUCAN!
BREAKMEIFYOUCAN! - Exploiting Keyspace Reduction and Relay Attacks in 3DES and AES-protected NFC Technologies
Exploiting Keyspace Reduction and Relay Attacks in 3DES and AES-protected NFC Technologies. Reducing 2TDEA keyspace from 2¹¹² to 2²⁸.
Husn Canaries - Defense-in-Depth for AI Coding Assistant Governance
https://husncanary.com/
Submitted January 25, 2026 at 01:05PM by 0xRaindrop
via reddit https://ift.tt/HWv05uD
https://husncanary.com/
Submitted January 25, 2026 at 01:05PM by 0xRaindrop
via reddit https://ift.tt/HWv05uD
Husn Canaries
Husn Canaries - Defense-in-Depth for AI Coding Assistant Governance
Research by Ehab Hussein & Mohamed Samy from IOActive on detecting unauthorized AI analysis of your code.
cvsweb.openbsd.org fights AI crawler bots by redirecting hotlinking requests to theannoyingsite.com (labelled "Malware" by eero), gets blacklisted by eero, too, for "Phishing & Deception"
https://ift.tt/jpDm63U
Submitted January 25, 2026 at 10:16PM by Mcnst
via reddit https://ift.tt/lnvkDes
https://ift.tt/jpDm63U
Submitted January 25, 2026 at 10:16PM by Mcnst
via reddit https://ift.tt/lnvkDes
Your Vibe Coded AI App Can Bankrupt You
https://ift.tt/iy1Seap
Submitted January 26, 2026 at 12:31AM by utku1337
via reddit https://ift.tt/kINLoDB
https://ift.tt/iy1Seap
Submitted January 26, 2026 at 12:31AM by utku1337
via reddit https://ift.tt/kINLoDB
Substack
Your Vibe Coded AI App Can Bankrupt You
Vibe coders may not realize they could wake up to a $20,000 cloud bill. This article explains the risks and how to avoid them.
địt mẹ mày morphisec: When Malware Authors Taunt Security Researchers
https://ift.tt/GZSTV2B
Submitted January 26, 2026 at 02:04AM by GelosSnake
via reddit https://ift.tt/VLJrU1M
https://ift.tt/GZSTV2B
Submitted January 26, 2026 at 02:04AM by GelosSnake
via reddit https://ift.tt/VLJrU1M
profero.io
địt mẹ mày morphisec: When Malware Authors Taunt Security Researchers
The complete analysis of Vietnamese Stealer a Python-based info stealer using Telegram as a C2.
/r/netsec's Q1 2026 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted January 26, 2026 at 06:59AM by netsec_burn
via reddit https://ift.tt/9KF12cT
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.Mention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted January 26, 2026 at 06:59AM by netsec_burn
via reddit https://ift.tt/9KF12cT
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
Certificate Transparency as Communication Channel
https://latedeployment.github.io/posts/certificate-transparency-as-communication-channel/
Submitted January 26, 2026 at 12:52AM by MembershipOptimal777
via reddit https://ift.tt/alvrwKd
https://latedeployment.github.io/posts/certificate-transparency-as-communication-channel/
Submitted January 26, 2026 at 12:52AM by MembershipOptimal777
via reddit https://ift.tt/alvrwKd
A lazy blog
Certificate Transparency as Communication Channel
This is part three of the Certificate Transparency series.
Introduction
Described here is a way to leverage the infrastructure used to validate certificates in order to distribute messages through the Certificate Transparency Logs.
Introduction
Described here is a way to leverage the infrastructure used to validate certificates in order to distribute messages through the Certificate Transparency Logs.