The Age-Gated Internet: Child Safety, Identity Infrastructure, and the Not So Quiet Re-Architecting of the Web
https://ift.tt/aPhv3Vg
Submitted March 25, 2026 at 03:51AM by wayne_horkan
via reddit https://ift.tt/9KXWNT4
https://ift.tt/aPhv3Vg
Submitted March 25, 2026 at 03:51AM by wayne_horkan
via reddit https://ift.tt/9KXWNT4
Horkan
The Age-Gated Internet: Child Safety, Identity Infrastructure, and the Not So Quiet Re-Architecting of the Web
Governments around the world are introducing age-verification and youth social-media laws, but these policies may be doing far more than protecting children. They are quietly pushing identity into operating systems, app stores, and the core infrastructure…
Security firm Cybereason open-sourced their Linux EDR agent
https://cybereason-public.github.io/owLSM/
Submitted March 25, 2026 at 12:55PM by More_Implement1639
via reddit https://ift.tt/zRVroA9
https://cybereason-public.github.io/owLSM/
Submitted March 25, 2026 at 12:55PM by More_Implement1639
via reddit https://ift.tt/zRVroA9
Reddit
From the netsec community on Reddit: Security firm Cybereason open-sourced their Linux EDR agent
Posted by More_Implement1639 - 4 votes and 2 comments
Stackfield Desktop App: RCE via Path Traversal and Arbitrary File Write (CVE-2026-28373)
https://ift.tt/bZrVCO6
Submitted March 25, 2026 at 03:07PM by MrTuxracer
via reddit https://ift.tt/QHPLjEx
https://ift.tt/bZrVCO6
Submitted March 25, 2026 at 03:07PM by MrTuxracer
via reddit https://ift.tt/QHPLjEx
RCE Security | Penetration Tests. Source Code Reviews. IT Security Audits.
Stackfield Desktop App: RCE via Path … | RCE Security
CVE-2026-28373 describes a path traversal vulnerability in the Stackfield desktop app affecting all versions up to 1.10.1 on Windows and macOS. During the …
CVE-2026-33656: EspoCRM ≤ 9.3.3 — Formula engine ACL gap + path traversal → authenticated RCE (full write-up + PoC)
https://ift.tt/nXC46ho
Submitted March 25, 2026 at 06:21PM by JivaSecurity
via reddit https://ift.tt/KTLR2a7
https://ift.tt/nXC46ho
Submitted March 25, 2026 at 06:21PM by JivaSecurity
via reddit https://ift.tt/KTLR2a7
Jiva Security
Formula for Disaster: Chaining EspoCRM's Scripting Engine to Remote Code Execution
EspoCRM v9.3.3: formula engine ACL bypass + unsanitized attachment path = arbitrary file read, arbitrary file write, and RCE as www-data. CVE-2026-33656.
Navia breach exposed HackerOne employee PII due to a BOLA-style access in third-party system
https://ift.tt/5wPN2Ms
Submitted March 25, 2026 at 07:01PM by raptorhunter22
via reddit https://ift.tt/gc21uIY
https://ift.tt/5wPN2Ms
Submitted March 25, 2026 at 07:01PM by raptorhunter22
via reddit https://ift.tt/gc21uIY
The CyberSec Guru
HackerOne Data Breach 2026: The Navia Supply Chain Hack | The CyberSec Guru
HackerOne slams Navia Benefit Solutions after a BOLA vulnerability exposed the SSNs and data of 287 employees. Read the full report
Weaponizing Windows Toast Notifications for Social Engineering
https://ift.tt/uLS49yH
Submitted March 25, 2026 at 09:14PM by netbiosX
via reddit https://ift.tt/E7bqzLU
https://ift.tt/uLS49yH
Submitted March 25, 2026 at 09:14PM by netbiosX
via reddit https://ift.tt/E7bqzLU
Purple Team
Toast Notifications
The Application User Model ID (AUMID) is a unique identifier that Windows assigns to modern applications. It enables Windows to identify which applications should receive notifications, how start m…
Our first pentest on a 100% Vibe coded application : analysis & feedback
https://ift.tt/9cXAfqa
Submitted March 25, 2026 at 09:37PM by Hackmosphere
via reddit https://ift.tt/jN0Ugs6
https://ift.tt/9cXAfqa
Submitted March 25, 2026 at 09:37PM by Hackmosphere
via reddit https://ift.tt/jN0Ugs6
Hackmosphere
Pentest d'une application vibe codée : analyse & résultats
Analyse technique d’un pentest d’application web 100 % vibe codée : découverte de vulnérabilités LFI, IDOR, dépendances vulnérables et risques sécurité liés au code généré par IA.
TP-Link Patches Archer NX Auth Bypass, Still Faces Security Lawsuit
https://ift.tt/IvJCrx2
Submitted March 26, 2026 at 01:10AM by hayrimavi1
via reddit https://ift.tt/uEMCIJ6
https://ift.tt/IvJCrx2
Submitted March 26, 2026 at 01:10AM by hayrimavi1
via reddit https://ift.tt/uEMCIJ6
Factide
TP-Link Patches Archer NX Auth Bypass, Still Faces Security Lawsuit
A missing authentication check in TP-Link’s Archer NX series allows unprivileged attackers to upload firmware. The update lands as the company defends a Texas lawsuit alleging deceptive security claims.
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
https://ift.tt/AVOWn26
Submitted March 26, 2026 at 12:54AM by sixcommissioner
via reddit https://ift.tt/2CSw0lu
https://ift.tt/AVOWn26
Submitted March 26, 2026 at 12:54AM by sixcommissioner
via reddit https://ift.tt/2CSw0lu
www.aikido.dev
TeamPCP deploys CanisterWorm on NPM following Trivy compromise
GlassWorm: Part 6. Fake Trezor Suite and Ledger Live for macOS, per-request polymorphic builds.
https://ift.tt/ACIyiWm
Submitted March 26, 2026 at 12:53AM by Willing_Monitor5855
via reddit https://ift.tt/FoqAdpa
https://ift.tt/ACIyiWm
Submitted March 26, 2026 at 12:53AM by Willing_Monitor5855
via reddit https://ift.tt/FoqAdpa
LiteLLM supply chain compromise - a complete analysis
https://ift.tt/6zft5Fo
Submitted March 26, 2026 at 12:51AM by raptorhunter22
via reddit https://ift.tt/kpqfWcN
https://ift.tt/6zft5Fo
Submitted March 26, 2026 at 12:51AM by raptorhunter22
via reddit https://ift.tt/kpqfWcN
The CyberSec Guru
The LiteLLM Supply Chain Attack: A Complete Technical Breakdown | The CyberSec Guru
An in-depth investigative report on the March 2026 LiteLLM supply chain attack. Discover how the Trivy GitHub Actions hack led to a massive PyPI compromise
The Wrong Fix: Why the FCC's Router Ban Misses the Real Threat
https://ift.tt/aIrqucw
Submitted March 26, 2026 at 02:59AM by untraceable-tortoise
via reddit https://ift.tt/3vEqg9K
https://ift.tt/aIrqucw
Submitted March 26, 2026 at 02:59AM by untraceable-tortoise
via reddit https://ift.tt/3vEqg9K
www.marisec.ca
The Wrong Fix: Why the FCC's Router Ban Misses the Real Threat
On March 20th, 2026, the FCC banned the purchase, import and sale of foreign-made routers, citing supply-chain and security concerns. The FCC fails to account for weak credentials and firmware vulnerabilities, which serve as the initial access vectors for…
LiteLLM malware supply chain attack analysis (pt-BR only, sorry)
https://gutem.github.io/notes/anatomia-de-um-infostealer-moderno-tres-amadas-uma-botnet
Submitted March 26, 2026 at 05:43AM by gutem
via reddit https://ift.tt/AOdoWuV
https://gutem.github.io/notes/anatomia-de-um-infostealer-moderno-tres-amadas-uma-botnet
Submitted March 26, 2026 at 05:43AM by gutem
via reddit https://ift.tt/AOdoWuV
gutem.github.io
Anatomia de um Infostealer Moderno: Três Camadas, Uma Botnet
Análise técnica de infostealer encontrado nas versões 1.82.7 e 1.82.8 do pacote LiteLLM
Dangerous by Default: What OpenClaw CVE Record Tells Us About Agentic AI
https://ift.tt/7KnC5ub
Submitted March 26, 2026 at 08:18AM by pi3ch
via reddit https://ift.tt/QwtOxRu
https://ift.tt/7KnC5ub
Submitted March 26, 2026 at 08:18AM by pi3ch
via reddit https://ift.tt/QwtOxRu
SecDim
Dangerous by Default: What OpenClaw CVE Record Tells Us About Agentic AI
Your AI assistant just received a WhatsApp message. It ran a shell command. Then it wrote new code and executed...
Common Entra ID Security Assessment Findings – Part 1: Foreign Enterprise Applications With Privileged API Permissions
https://ift.tt/A9Orn4f
Submitted March 26, 2026 at 02:38PM by GonzoZH
via reddit https://ift.tt/gEGO4FP
https://ift.tt/A9Orn4f
Submitted March 26, 2026 at 02:38PM by GonzoZH
via reddit https://ift.tt/gEGO4FP
Magento PolyShell – Unauthenticated File Upload to RCE in Magento (APSB25-94)
https://ift.tt/ZBKm0fW
Submitted March 26, 2026 at 02:51PM by Mempodipper
via reddit https://ift.tt/AdXg8Wm
https://ift.tt/ZBKm0fW
Submitted March 26, 2026 at 02:51PM by Mempodipper
via reddit https://ift.tt/AdXg8Wm
Searchlight Cyber
Magento PolyShell – Unauthenticated File Upload to RCE in Magento (APSB25-94) › Searchlight Cyber
Magento remains one of the most popular e-commerce solutions in use on the internet, estimated to be running on more than 130,000 websites. It is also offered as an enterprise offering by Adobe under the name Adobe Commerce, which receives automatic patching.…
Making NTLM-Relaying Relevant Again by Attacking Web Servers with WebRelayX
https://ift.tt/hQ2SbyG
Submitted March 26, 2026 at 06:23PM by seccore_gmbh
via reddit https://ift.tt/O9NpF1Q
https://ift.tt/hQ2SbyG
Submitted March 26, 2026 at 06:23PM by seccore_gmbh
via reddit https://ift.tt/O9NpF1Q
SecCore GmbH
NTLM-Relaying in 2026 | SecCore
NTLM-Relaying is a common attack vector in internal networks. In this blog post, we will show that even in 2026, there are still many scenarios where NTLM-Relaying can be successfully performed, and we will provide some insights into how to mitigate these…
Exploiting AQL Injection Vulnerabilities in ArangoDB
https://ift.tt/5BHjXLb
Submitted March 26, 2026 at 10:19PM by anvilventures
via reddit https://ift.tt/HeY8MAU
https://ift.tt/5BHjXLb
Submitted March 26, 2026 at 10:19PM by anvilventures
via reddit https://ift.tt/HeY8MAU
Anvil Secure
Exploiting AQL Injection Vulnerabilities in ArangoDB - Anvil Secure
Daniel Kachakil, Principal Security Engineer, explores AQL injection vulnerabilities in ArangoDB and introduces a new tool: aqlmap.
The Age-Gated Internet: Child Safety, Identity Infrastructure, and the Not So Quiet Re-Architecting of the Web
https://ift.tt/Vwto6vX
Submitted March 26, 2026 at 09:40PM by wayne_horkan
via reddit https://ift.tt/ywB1pLC
https://ift.tt/Vwto6vX
Submitted March 26, 2026 at 09:40PM by wayne_horkan
via reddit https://ift.tt/ywB1pLC
Horkan
The Age-Gated Internet: Child Safety, Identity Infrastructure, and the Not So Quiet Re-Architecting of the Web
Governments around the world are introducing age-verification and youth social-media laws, but these policies may be doing far more than protecting children. They are quietly pushing identity into operating systems, app stores, and the core infrastructure…
What I Learned from a $2,000 Pen Test
https://ift.tt/4M13EzC
Submitted March 26, 2026 at 09:38PM by punkpeye
via reddit https://ift.tt/48VvH2E
https://ift.tt/4M13EzC
Submitted March 26, 2026 at 09:38PM by punkpeye
via reddit https://ift.tt/48VvH2E
Glama – MCP Hosting Platform
How a series of overnight attacks revealed a card testing vulnerability – and the countermeasures that actually worked.
PROTOCOLO DELTA SWORD: Full Disclosure de Persistência Zero-Day e Omissão Corporativa (Google/Samsung)
https://drive.google.com/drive/folders/1S5BTn5KxTmDEgrkjr2pIk3xanL05C9PG
Submitted March 27, 2026 at 01:53AM by PastAcanthisitta3863
via reddit https://ift.tt/IOvsGtp
https://drive.google.com/drive/folders/1S5BTn5KxTmDEgrkjr2pIk3xanL05C9PG
Submitted March 27, 2026 at 01:53AM by PastAcanthisitta3863
via reddit https://ift.tt/IOvsGtp
Reddit
From the netsec community on Reddit: PROTOCOLO DELTA SWORD: Full Disclosure de Persistência Zero-Day e Omissão Corporativa (Google/Samsung)
Posted by PastAcanthisitta3863 - 3 votes and 0 comments