Introducing IDA-Free-MCP: mcp server for IDA Free version (native)
https://0xshlomil.github.io/introducing-ida-free-mcp/
Submitted February 15, 2026 at 12:15PM by Full_One_4807
via reddit https://ift.tt/Gx9ofUy
https://0xshlomil.github.io/introducing-ida-free-mcp/
Submitted February 15, 2026 at 12:15PM by Full_One_4807
via reddit https://ift.tt/Gx9ofUy
Product engineering teams must own supply chain risk
https://ift.tt/X6QTHIi
Submitted February 15, 2026 at 07:28PM by ArtisticProgrammer11
via reddit https://ift.tt/oPlqxWD
https://ift.tt/X6QTHIi
Submitted February 15, 2026 at 07:28PM by ArtisticProgrammer11
via reddit https://ift.tt/oPlqxWD
www.hyperact.co.uk
Product engineering teams must own supply chain risk
Product teams must own software supply chain risk as third-party dependencies become the primary attack surface. Learn how provenance, attestations, and SLSA make trust explicit, enforceable, and verifiable.
I built a free, open-source platform to learn GenAI security, learning content + hands-on labs against real LLMs (beta, looking for feedback)
https://ift.tt/17MenyD
Submitted February 16, 2026 at 04:09AM by MasterpieceMuch872
via reddit https://ift.tt/QAPk9iz
https://ift.tt/17MenyD
Submitted February 16, 2026 at 04:09AM by MasterpieceMuch872
via reddit https://ift.tt/QAPk9iz
PromptTrace
PromptTrace — GenAI Security Labs
Learn to hack and defend AI systems through hands-on labs. Practice prompt injection, RAG poisoning, and tool exploitation against real LLMs.
sandboxec: A lightweight command sandbox for Linux, secure-by-default, built on Landlock.
https://ift.tt/Xy8pzMZ
Submitted February 16, 2026 at 01:47PM by dwisiswant0
via reddit https://ift.tt/MOgcmsF
https://ift.tt/Xy8pzMZ
Submitted February 16, 2026 at 01:47PM by dwisiswant0
via reddit https://ift.tt/MOgcmsF
GitHub
GitHub - dwisiswant0/sandboxec: A lightweight command sandbox for Linux, secure-by-default, built on Landlock.
A lightweight command sandbox for Linux, secure-by-default, built on Landlock. - dwisiswant0/sandboxec
Architectural Isolation Tradeoffs in the OpenClaw Ecosystem After CVE-2026-25253
https://ift.tt/LINeBbu
Submitted February 16, 2026 at 01:34PM by rsrini7
via reddit https://ift.tt/Fd1eIE5
https://ift.tt/LINeBbu
Submitted February 16, 2026 at 01:34PM by rsrini7
via reddit https://ift.tt/Fd1eIE5
New Joomla! Novarain/Tassos Framework Vulnerabilities Advisory
https://ift.tt/rF3gGCE
Submitted February 16, 2026 at 02:45PM by SSDisclosure
via reddit https://ift.tt/MKIBiDt
https://ift.tt/rF3gGCE
Submitted February 16, 2026 at 02:45PM by SSDisclosure
via reddit https://ift.tt/MKIBiDt
SSD Secure Disclosure
Joomla! Novarain/Tassos Framework Vulnerabilities - SSD Secure Disclosure
Summary Source code review of the Novarain/Tassos Framework revealed three critical primitives – unauthenticated file read, unauthenticated file deletion, and SQL injection leading to arbitrary database read – across five widely deployed Joomla! extensions…
[Analysis] Massive Active GitHub Malware Campaign | Hundreds of Malicious Repositories Identified
https://ift.tt/6jsgzio
Submitted February 16, 2026 at 04:38PM by WanderBetter
via reddit https://ift.tt/dexMQvw
https://ift.tt/6jsgzio
Submitted February 16, 2026 at 04:38PM by WanderBetter
via reddit https://ift.tt/dexMQvw
brennan.day
The Curious Case of the Triton Malware Fork
Today, a weird malware distribution campaign targeting users of omg.lol and Triton, an open-source macOS client of omg.lol, was found. The attack leverages the trust of GitHub, creating a malicious fork where the download link has been replaced with malware…
Security audit for LLM skill files: skillaudit.sh
https://skillaudit.sh/
Submitted February 17, 2026 at 12:11AM by c0daman
via reddit https://ift.tt/zIcxhr6
https://skillaudit.sh/
Submitted February 17, 2026 at 12:11AM by c0daman
via reddit https://ift.tt/zIcxhr6
skillaudit.sh
Security audit for LLM skill files in GitHub repositories
nono - kernel-enforced capability sandbox for AI agents
https://nono.sh
Submitted February 17, 2026 at 01:29AM by DecodeBytes
via reddit https://ift.tt/1OGcthT
https://nono.sh
Submitted February 17, 2026 at 01:29AM by DecodeBytes
via reddit https://ift.tt/1OGcthT
nono.sh
nono - Secure Shell for AI Agents
OS-enforced capability sandbox for running untrusted AI agents. No escape hatch. Works with any AI agent.
When Audits Fail Part 2: From Pre-Auth SSRF to RCE in TRUfusion Enterprise
https://ift.tt/QNbqiwJ
Submitted February 17, 2026 at 02:06AM by MrTuxracer
via reddit https://ift.tt/sOj2zNX
https://ift.tt/QNbqiwJ
Submitted February 17, 2026 at 02:06AM by MrTuxracer
via reddit https://ift.tt/sOj2zNX
RCE Security - Your European Offensive Security Partner
When Audits Fail Part 2: From Pre-Auth SSRF … | RCE Security
A pre-auth SSRF in TRUfusion Enterprise (CVE-2025-32355) allows external attackers to reach internal-only services via a misconfigured reverse proxy. This …
Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services
https://ift.tt/zays2pk
Submitted February 17, 2026 at 06:04AM by Mempodipper
via reddit https://ift.tt/8WE027a
https://ift.tt/zays2pk
Submitted February 17, 2026 at 06:04AM by Mempodipper
via reddit https://ift.tt/8WE027a
Searchlight Cyber
Almost Impossible: Java Deserialization Through Broken Crypto in OpenText Directory Services › Searchlight Cyber
Introduction We recently found ourselves looking into OpenText Directory Services (OTDS). We had seen it present on our customer's attack surface, and it seemed to be an interesting target. OTDS is a Java web application providing authentication and user…
Prompt Injection Standardization: Text Techniques vs Intent
https://ift.tt/ymE6AKF
Submitted February 17, 2026 at 03:20PM by Equivalent_Cover4542
via reddit https://ift.tt/MpBrgUH
https://ift.tt/ymE6AKF
Submitted February 17, 2026 at 03:20PM by Equivalent_Cover4542
via reddit https://ift.tt/MpBrgUH
www.lasso.security
Prompt Injection Standardization: Text Techniques vs Intent
Explore Lasso’s prompt injection taxonomy, distinguishing text-based techniques from attacker intent to standardize AI security defenses.
Prompt Injection Standardization: Text Techniques vs Intent
https://ift.tt/ymE6AKF
Submitted February 17, 2026 at 05:32PM by Equivalent_Cover4542
via reddit https://ift.tt/3DVEAzJ
https://ift.tt/ymE6AKF
Submitted February 17, 2026 at 05:32PM by Equivalent_Cover4542
via reddit https://ift.tt/3DVEAzJ
www.lasso.security
Prompt Injection Standardization: Text Techniques vs Intent
Explore Lasso’s prompt injection taxonomy, distinguishing text-based techniques from attacker intent to standardize AI security defenses.