With the rise of SaaS and cloud applications, the browser has become the new workplace. That's where net-security comes in.
https://ift.tt/7HQDyhk
Submitted March 24, 2026 at 06:16PM by Academic-Soup2604
via reddit https://ift.tt/6KJYyO1
https://ift.tt/7HQDyhk
Submitted March 24, 2026 at 06:16PM by Academic-Soup2604
via reddit https://ift.tt/6KJYyO1
Scalefusion
Secure Web Gateway (SWG) Solution - Veltar
Veltar's secure web gateway software blocks web threats, controls internet use, and restricts cloud app login to corporate domains across endpoints.
We rewrote SoftHSMv2 (the default PKCS#11 software HSM) in Rust — 617+ tests, PQC support, memory-safe key handling
https://craton-co.github.io/blog/why-we-rewrote-softhsm/
Submitted March 24, 2026 at 07:49PM by Open_Introduction860
via reddit https://ift.tt/8BSsk6K
https://craton-co.github.io/blog/why-we-rewrote-softhsm/
Submitted March 24, 2026 at 07:49PM by Open_Introduction860
via reddit https://ift.tt/8BSsk6K
Craton Software Company
Why We Rewrote SoftHSMv2 in Rust
Craton HSM is a memory-safe, post-quantum-ready PKCS#11 software HSM in Rust — a modern replacement for the unmaintained SoftHSMv2.
We scanned 900 MCP configs on GitHub. 75% had security problems.
https://ift.tt/OCWsgw1
Submitted March 24, 2026 at 10:11PM by sixcommissioner
via reddit https://ift.tt/28V7Uuo
https://ift.tt/OCWsgw1
Submitted March 24, 2026 at 10:11PM by sixcommissioner
via reddit https://ift.tt/28V7Uuo
Orchesis
We scanned 900 MCP configs on GitHub. 75% had security problems.
We scanned 900+ MCP configurations on GitHub. 75% failed basic security checks.
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM
https://ift.tt/Ax8kONl
Submitted March 25, 2026 at 12:33AM by lirantal
via reddit https://ift.tt/TE8KR3s
https://ift.tt/Ax8kONl
Submitted March 25, 2026 at 12:33AM by lirantal
via reddit https://ift.tt/TE8KR3s
Snyk
How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM | Snyk
On March 24, 2026, threat actor known as TeamPCP published backdoored versions of the litellm Python package after stealing PyPI credentials via a compromised Trivy GitHub Action in LiteLLM's CI/CD pipeline. Here's what happened, how the three-stage malware…
Corelan: Debugging - WinDBG & WinDBGX Fundamentals -
https://ift.tt/28xr3Yd
Submitted March 25, 2026 at 02:03AM by maurosoria
via reddit https://ift.tt/sG3Riq0
https://ift.tt/28xr3Yd
Submitted March 25, 2026 at 02:03AM by maurosoria
via reddit https://ift.tt/sG3Riq0
Corelan | Exploit Development & Vulnerability Research
Debugging - WinDBG & WinDBGX Fundamentals
[toc] IntroductionIs AI an evolution or a revolution? Or both? Those are interesting questions. Speaking of AI - even ChatGPT and Grok agree: A debugger is the one of the most (if not the most) important tool for exploit developers, malware analysts, and…
The Age-Gated Internet: Child Safety, Identity Infrastructure, and the Not So Quiet Re-Architecting of the Web
https://ift.tt/aPhv3Vg
Submitted March 25, 2026 at 03:51AM by wayne_horkan
via reddit https://ift.tt/9KXWNT4
https://ift.tt/aPhv3Vg
Submitted March 25, 2026 at 03:51AM by wayne_horkan
via reddit https://ift.tt/9KXWNT4
Horkan
The Age-Gated Internet: Child Safety, Identity Infrastructure, and the Not So Quiet Re-Architecting of the Web
Governments around the world are introducing age-verification and youth social-media laws, but these policies may be doing far more than protecting children. They are quietly pushing identity into operating systems, app stores, and the core infrastructure…
Security firm Cybereason open-sourced their Linux EDR agent
https://cybereason-public.github.io/owLSM/
Submitted March 25, 2026 at 12:55PM by More_Implement1639
via reddit https://ift.tt/zRVroA9
https://cybereason-public.github.io/owLSM/
Submitted March 25, 2026 at 12:55PM by More_Implement1639
via reddit https://ift.tt/zRVroA9
Reddit
From the netsec community on Reddit: Security firm Cybereason open-sourced their Linux EDR agent
Posted by More_Implement1639 - 4 votes and 2 comments
Stackfield Desktop App: RCE via Path Traversal and Arbitrary File Write (CVE-2026-28373)
https://ift.tt/bZrVCO6
Submitted March 25, 2026 at 03:07PM by MrTuxracer
via reddit https://ift.tt/QHPLjEx
https://ift.tt/bZrVCO6
Submitted March 25, 2026 at 03:07PM by MrTuxracer
via reddit https://ift.tt/QHPLjEx
RCE Security | Penetration Tests. Source Code Reviews. IT Security Audits.
Stackfield Desktop App: RCE via Path … | RCE Security
CVE-2026-28373 describes a path traversal vulnerability in the Stackfield desktop app affecting all versions up to 1.10.1 on Windows and macOS. During the …
CVE-2026-33656: EspoCRM ≤ 9.3.3 — Formula engine ACL gap + path traversal → authenticated RCE (full write-up + PoC)
https://ift.tt/nXC46ho
Submitted March 25, 2026 at 06:21PM by JivaSecurity
via reddit https://ift.tt/KTLR2a7
https://ift.tt/nXC46ho
Submitted March 25, 2026 at 06:21PM by JivaSecurity
via reddit https://ift.tt/KTLR2a7
Jiva Security
Formula for Disaster: Chaining EspoCRM's Scripting Engine to Remote Code Execution
EspoCRM v9.3.3: formula engine ACL bypass + unsanitized attachment path = arbitrary file read, arbitrary file write, and RCE as www-data. CVE-2026-33656.
Navia breach exposed HackerOne employee PII due to a BOLA-style access in third-party system
https://ift.tt/5wPN2Ms
Submitted March 25, 2026 at 07:01PM by raptorhunter22
via reddit https://ift.tt/gc21uIY
https://ift.tt/5wPN2Ms
Submitted March 25, 2026 at 07:01PM by raptorhunter22
via reddit https://ift.tt/gc21uIY
The CyberSec Guru
HackerOne Data Breach 2026: The Navia Supply Chain Hack | The CyberSec Guru
HackerOne slams Navia Benefit Solutions after a BOLA vulnerability exposed the SSNs and data of 287 employees. Read the full report
Weaponizing Windows Toast Notifications for Social Engineering
https://ift.tt/uLS49yH
Submitted March 25, 2026 at 09:14PM by netbiosX
via reddit https://ift.tt/E7bqzLU
https://ift.tt/uLS49yH
Submitted March 25, 2026 at 09:14PM by netbiosX
via reddit https://ift.tt/E7bqzLU
Purple Team
Toast Notifications
The Application User Model ID (AUMID) is a unique identifier that Windows assigns to modern applications. It enables Windows to identify which applications should receive notifications, how start m…
Our first pentest on a 100% Vibe coded application : analysis & feedback
https://ift.tt/9cXAfqa
Submitted March 25, 2026 at 09:37PM by Hackmosphere
via reddit https://ift.tt/jN0Ugs6
https://ift.tt/9cXAfqa
Submitted March 25, 2026 at 09:37PM by Hackmosphere
via reddit https://ift.tt/jN0Ugs6
Hackmosphere
Pentest d'une application vibe codée : analyse & résultats
Analyse technique d’un pentest d’application web 100 % vibe codée : découverte de vulnérabilités LFI, IDOR, dépendances vulnérables et risques sécurité liés au code généré par IA.
TP-Link Patches Archer NX Auth Bypass, Still Faces Security Lawsuit
https://ift.tt/IvJCrx2
Submitted March 26, 2026 at 01:10AM by hayrimavi1
via reddit https://ift.tt/uEMCIJ6
https://ift.tt/IvJCrx2
Submitted March 26, 2026 at 01:10AM by hayrimavi1
via reddit https://ift.tt/uEMCIJ6
Factide
TP-Link Patches Archer NX Auth Bypass, Still Faces Security Lawsuit
A missing authentication check in TP-Link’s Archer NX series allows unprivileged attackers to upload firmware. The update lands as the company defends a Texas lawsuit alleging deceptive security claims.
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
https://ift.tt/AVOWn26
Submitted March 26, 2026 at 12:54AM by sixcommissioner
via reddit https://ift.tt/2CSw0lu
https://ift.tt/AVOWn26
Submitted March 26, 2026 at 12:54AM by sixcommissioner
via reddit https://ift.tt/2CSw0lu
www.aikido.dev
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
GlassWorm: Part 6. Fake Trezor Suite and Ledger Live for macOS, per-request polymorphic builds.
https://ift.tt/ACIyiWm
Submitted March 26, 2026 at 12:53AM by Willing_Monitor5855
via reddit https://ift.tt/FoqAdpa
https://ift.tt/ACIyiWm
Submitted March 26, 2026 at 12:53AM by Willing_Monitor5855
via reddit https://ift.tt/FoqAdpa
LiteLLM supply chain compromise - a complete analysis
https://ift.tt/6zft5Fo
Submitted March 26, 2026 at 12:51AM by raptorhunter22
via reddit https://ift.tt/kpqfWcN
https://ift.tt/6zft5Fo
Submitted March 26, 2026 at 12:51AM by raptorhunter22
via reddit https://ift.tt/kpqfWcN
The CyberSec Guru
The LiteLLM Supply Chain Attack: A Complete Technical Breakdown | The CyberSec Guru
An in-depth investigative report on the March 2026 LiteLLM supply chain attack. Discover how the Trivy GitHub Actions hack led to a massive PyPI compromise
The Wrong Fix: Why the FCC's Router Ban Misses the Real Threat
https://ift.tt/aIrqucw
Submitted March 26, 2026 at 02:59AM by untraceable-tortoise
via reddit https://ift.tt/3vEqg9K
https://ift.tt/aIrqucw
Submitted March 26, 2026 at 02:59AM by untraceable-tortoise
via reddit https://ift.tt/3vEqg9K
www.marisec.ca
The Wrong Fix: Why the FCC's Router Ban Misses the Real Threat
On March 20th, 2026, the FCC banned the purchase, import and sale of foreign-made routers, citing supply-chain and security concerns. The FCC fails to account for weak credentials and firmware vulnerabilities, which serve as the initial access vectors for…
LiteLLM malware supply chain attack analysis (pt-BR only, sorry)
https://gutem.github.io/notes/anatomia-de-um-infostealer-moderno-tres-amadas-uma-botnet
Submitted March 26, 2026 at 05:43AM by gutem
via reddit https://ift.tt/AOdoWuV
https://gutem.github.io/notes/anatomia-de-um-infostealer-moderno-tres-amadas-uma-botnet
Submitted March 26, 2026 at 05:43AM by gutem
via reddit https://ift.tt/AOdoWuV
gutem.github.io
Anatomia de um Infostealer Moderno: Três Camadas, Uma Botnet
Análise técnica de infostealer encontrado nas versões 1.82.7 e 1.82.8 do pacote LiteLLM
Dangerous by Default: What OpenClaw CVE Record Tells Us About Agentic AI
https://ift.tt/7KnC5ub
Submitted March 26, 2026 at 08:18AM by pi3ch
via reddit https://ift.tt/QwtOxRu
https://ift.tt/7KnC5ub
Submitted March 26, 2026 at 08:18AM by pi3ch
via reddit https://ift.tt/QwtOxRu
SecDim
Dangerous by Default: What OpenClaw CVE Record Tells Us About Agentic AI
Your AI assistant just received a WhatsApp message. It ran a shell command. Then it wrote new code and executed...
Common Entra ID Security Assessment Findings – Part 1: Foreign Enterprise Applications With Privileged API Permissions
https://ift.tt/A9Orn4f
Submitted March 26, 2026 at 02:38PM by GonzoZH
via reddit https://ift.tt/gEGO4FP
https://ift.tt/A9Orn4f
Submitted March 26, 2026 at 02:38PM by GonzoZH
via reddit https://ift.tt/gEGO4FP
Magento PolyShell – Unauthenticated File Upload to RCE in Magento (APSB25-94)
https://ift.tt/ZBKm0fW
Submitted March 26, 2026 at 02:51PM by Mempodipper
via reddit https://ift.tt/AdXg8Wm
https://ift.tt/ZBKm0fW
Submitted March 26, 2026 at 02:51PM by Mempodipper
via reddit https://ift.tt/AdXg8Wm
Searchlight Cyber
Magento PolyShell – Unauthenticated File Upload to RCE in Magento (APSB25-94) › Searchlight Cyber
Magento remains one of the most popular e-commerce solutions in use on the internet, estimated to be running on more than 130,000 websites. It is also offered as an enterprise offering by Adobe under the name Adobe Commerce, which receives automatic patching.…