Why AI agent containers need a syscall-level observer: the prompt injection blind spot
https://ift.tt/Uxsve5A
Submitted February 21, 2026 at 01:21AM by M4r10_h4ck
via reddit https://ift.tt/NjIMYfP
https://ift.tt/Uxsve5A
Submitted February 21, 2026 at 01:21AM by M4r10_h4ck
via reddit https://ift.tt/NjIMYfP
Medium
Runtime Tracing for AI Agents: What Your OpenClaw Agent Actually Does Inside the Container
Autonomous AI agents run 24/7 with shell access, network connectivity, and full filesystem permissions. We built Azazel, an eBPF-based…
People-search sites + adtech = potential PII leakage vector (reporting option inside)
https://ift.tt/7akJsD6
Submitted February 21, 2026 at 03:44AM by 1pro_complainer
via reddit https://ift.tt/9ry8Xcf
https://ift.tt/7akJsD6
Submitted February 21, 2026 at 03:44AM by 1pro_complainer
via reddit https://ift.tt/9ry8Xcf
How a single typo led to RCE in Firefox
https://ift.tt/iVXxQyH
Submitted February 22, 2026 at 04:49PM by campuscodi
via reddit https://ift.tt/oIglRNv
https://ift.tt/iVXxQyH
Submitted February 22, 2026 at 04:49PM by campuscodi
via reddit https://ift.tt/oIglRNv
kqx.io
How a single typo led to RCE in Firefox – kqx
A technical writeup on a 0day vulnerability I reported inside SpiderMonkey, Firefox's JS engine
Malicious Chrome extension targeting Apple App Store Connect developers through fake ASO service - full analysis
https://ift.tt/AYXqITW
Submitted February 23, 2026 at 03:41AM by Huge-Skirt-6990
via reddit https://ift.tt/QK8lVgo
https://ift.tt/AYXqITW
Submitted February 23, 2026 at 03:41AM by Huge-Skirt-6990
via reddit https://ift.tt/QK8lVgo
Scary datapoints re network visibility in Dragos annual report on OT cyberattacks
https://www.ot.today/red-flags-for-ot-abound-in-dragos-review-2025-a-30809
Submitted February 23, 2026 at 09:10AM by WatermanReports
via reddit https://ift.tt/pWKwMyZ
https://www.ot.today/red-flags-for-ot-abound-in-dragos-review-2025-a-30809
Submitted February 23, 2026 at 09:10AM by WatermanReports
via reddit https://ift.tt/pWKwMyZ
www.ot.today
Red Flags for OT Abound in Dragos Review of 2025
There is a silent epidemic of ransomware attacks on commercial operational technology systems, which are mischaracterized as IT incidents even though they impact
I built a network security analyzer using information geometry (Riemannian manifolds) instead of traditional rule-based detection
https://ift.tt/vykZ7CS
Submitted February 23, 2026 at 11:05AM by Former-Oil-4621
via reddit https://ift.tt/Westwky
https://ift.tt/vykZ7CS
Submitted February 23, 2026 at 11:05AM by Former-Oil-4621
via reddit https://ift.tt/Westwky
consultoria.aivoix.mx
VicK Consultoría en Tecnología | Ciberseguridad Geométrica
VicK Consultoría en Tecnología - Soluciones de ciberseguridad, verificación de firmas, PKI y autenticación biométrica basadas en geometría natural.
Have you tried turning it off and on again? On bricking OT devices (part 2)
https://ift.tt/BERu4q7
Submitted February 23, 2026 at 04:55PM by 2ROT13
via reddit https://ift.tt/AsWcmYj
https://ift.tt/BERu4q7
Submitted February 23, 2026 at 04:55PM by 2ROT13
via reddit https://ift.tt/AsWcmYj
www.midnightblue.nl
Have you tried turning it off and on again? On bricking OT devices (part 2)
A discussion of the recent cyber attacks against a number of targets connected to Polands electric grid.
Another exposed Supabase DB strikes: 20k+ attendees and FULL write access
https://ift.tt/OXfBalj
Submitted February 23, 2026 at 11:29PM by therafort
via reddit https://ift.tt/WBDFs6I
https://ift.tt/OXfBalj
Submitted February 23, 2026 at 11:29PM by therafort
via reddit https://ift.tt/WBDFs6I
obaid’s longer thoughts
The Arts Council of Pakistan has a database of 20k+ attendees and full write access completely exposed. Right now.
And as I click publish on this post, the database is still, publicly exposed and has not been patched.
Form 4 filings are one of the most underused data sources in retail investing. Here's a practical guide to reading them.
https://moneysense.ai
Submitted 2026-02-24T04:56:14+00:00 by arrremayu
via reddit https://ift.tt/pbgDhuQ
https://moneysense.ai
Submitted 2026-02-24T04:56:14+00:00 by arrremayu
via reddit https://ift.tt/pbgDhuQ
MoneySense.ai
Analyze Any Stock Filing in Minutes | MoneySense.ai
AI-powered stock filing analysis across 7 global markets. Upload any filing and get instant insights in plain English.
Using Passkeys for more than just Auth
https://ift.tt/EB5s984
Submitted 2026-02-24T13:26:10+00:00 by seanieb
via reddit https://ift.tt/9kqcv1L
https://ift.tt/EB5s984
Submitted 2026-02-24T13:26:10+00:00 by seanieb
via reddit https://ift.tt/9kqcv1L
conic.al
Passkeys and the Quiet Revolution in Corporate Crypto — Sean Byrne
Passkeys solve the authentication problem corporate IT has been fighting for decades. But the more interesting story is what happens when every employee has a hardware-backed key generation and storage facility in their pocket.
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148 – Mozilla Hacks - the Web developer blog
https://ift.tt/pJdWTFh
Submitted 2026-02-24T14:50:37+00:00 by evilpies
via reddit https://ift.tt/a8CiFMQ
https://ift.tt/pJdWTFh
Submitted 2026-02-24T14:50:37+00:00 by evilpies
via reddit https://ift.tt/a8CiFMQ
Mozilla Hacks – the Web developer blog
Goodbye innerHTML, Hello setHTML: Stronger XSS Protection in Firefox 148
Cross-site scripting (XSS) remains one of the most prevalent vulnerabilities on the web. The new standardized Sanitizer API provides a straightforward way for web developers to sanitize untrusted HTML before inserting it into the DOM. Firefox 148 is the first…
AI Agent Threat Intel (Feb 2026 month to date): Tool chain escalation displaces instruction override as #1 technique, agent-targeting attacks hit 26.4% - 91K production interactions
https://ift.tt/NHaYnBV
Submitted 2026-02-24T17:30:20+00:00 by cyberamyntas
via reddit https://ift.tt/qTIQ5RU
https://ift.tt/NHaYnBV
Submitted 2026-02-24T17:30:20+00:00 by cyberamyntas
via reddit https://ift.tt/qTIQ5RU
raxe.ai
AI Threat Intelligence Report | RAXE Labs
Monthly AI threat intelligence report with interactive analysis of attack patterns targeting AI agents and LLMs.
ROP the ROM: Exploiting a Stack Buffer Overflow on STM32H5 in Multiple Ways
https://ift.tt/ecKRE8P
Submitted 2026-02-24T17:04:22+00:00 by gquere
via reddit https://ift.tt/PBldMSv
https://ift.tt/ecKRE8P
Submitted 2026-02-24T17:04:22+00:00 by gquere
via reddit https://ift.tt/PBldMSv
Chrome CVE made me go digging and I found a container image in prod that hasn't been updated since 2023
https://ift.tt/glKUuxL
Submitted 2026-02-24T22:32:04+00:00 by proigor1024
via reddit https://ift.tt/l79RWhs
https://ift.tt/glKUuxL
Submitted 2026-02-24T22:32:04+00:00 by proigor1024
via reddit https://ift.tt/l79RWhs
Starkiller Phishing Kit: Why MFA Fails Against Real-Time Reverse Proxies — Technical Analysis + Rust PoC for TLS Fingerprinting
https://ift.tt/a0Bq2T5
Submitted 2026-02-25T06:15:44+00:00 by Reversed-Engineer-01
via reddit https://ift.tt/vtsGo6w
https://ift.tt/a0Bq2T5
Submitted 2026-02-25T06:15:44+00:00 by Reversed-Engineer-01
via reddit https://ift.tt/vtsGo6w
TURN Server Security Best Practices - hardening checklist, IP range tables, and deployment patterns
https://ift.tt/eBmVZ1X
Submitted 2026-02-25T10:06:18+00:00 by EnableSecurity
via reddit https://ift.tt/YRzVpo4
https://ift.tt/eBmVZ1X
Submitted 2026-02-25T10:06:18+00:00 by EnableSecurity
via reddit https://ift.tt/YRzVpo4
Enable Security
TURN Server Security Best Practices
TURN server security guide for any implementation. Hardening checklist, IP range block lists, rate limiting, and deployment patterns for production WebRTC systems.
Tracking DPRK operator IPs over time by snooping on mailboxes
https://ift.tt/wXh1gjW
Submitted 2026-02-25T12:31:10+00:00 by -nbsp-
via reddit https://ift.tt/OjRLnrW
https://ift.tt/wXh1gjW
Submitted 2026-02-25T12:31:10+00:00 by -nbsp-
via reddit https://ift.tt/OjRLnrW
kmsec.uk
Tracking DPRK operator IPs over time | kmsec.uk
FAMOUS CHOLLIMA's temporary email usage leaks IP addresses (opsec mistakes part 3)
I rendered 1,418 Unicode confusable pairs across 230 system fonts. 82 are pixel-identical, and the font your site uses determines which ones.
https://paultendo.github.io/posts/confusable-vision-visual-similarity/
Submitted 2026-02-25T12:27:57+00:00 by paultendo
via reddit https://ift.tt/73vPMkJ
https://paultendo.github.io/posts/confusable-vision-visual-similarity/
Submitted 2026-02-25T12:27:57+00:00 by paultendo
via reddit https://ift.tt/73vPMkJ
paultendo.github.io
I rendered 1,418 Unicode confusable pairs across 230 fonts. Most aren't confusable to the eye.
confusable-vision renders every TR39 confusable pair across 230 macOS system fonts and measures visual similarity with SSIM. 96.5% of confusables.txt is not high-risk, but 82 pairs are pixel-identical in at least one font.
Large-Scale Online Deanonymization with LLMs
https://ift.tt/ThEeqYg
Submitted 2026-02-25T14:08:30+00:00 by MyFest
via reddit https://ift.tt/IJqlwEQ
https://ift.tt/ThEeqYg
Submitted 2026-02-25T14:08:30+00:00 by MyFest
via reddit https://ift.tt/IJqlwEQ
Substack
Large-Scale Online Deanonymization with LLMs
We measure the capabilities of LLMs to deanonymize users online.
Active deception against AI pentesting agents: context saturation, tarpitting benchmarks, and cited research
https://ift.tt/aJkjcxh
Submitted 2026-02-25T18:47:38+00:00 by AdventurousPlum7945
via reddit https://ift.tt/jRCiLNZ
https://ift.tt/aJkjcxh
Submitted 2026-02-25T18:47:38+00:00 by AdventurousPlum7945
via reddit https://ift.tt/jRCiLNZ
portspoof.io
AI Agents Are Scanning Your Network. Here's What Stops Them.
AI agents now run 80-90% of attack campaigns autonomously. Active deception exhausts them by flooding context windows, draining budgets, and freezing pipelines.
Enterprise Evaluation Framework for OpenClaw (and other autonomous AI agents)
https://ift.tt/WfqYh68
Submitted 2026-02-25T19:53:56+00:00 by HobbyGamerDev
via reddit https://ift.tt/dYlEc0W
https://ift.tt/WfqYh68
Submitted 2026-02-25T19:53:56+00:00 by HobbyGamerDev
via reddit https://ift.tt/dYlEc0W
www.onyx.app
OpenClaw Enterprise Evaluation Framework | CLAW-10
A 10-dimension scoring matrix for evaluating OpenClaw in enterprise environments. Evidence-based ratings across identity, sandboxing, and compliance.