The Danger of Multi-SSO AWS Cognito User Pools
https://ift.tt/qSfhLlw
Submitted May 5, 2026 at 04:09PM by nibblesec
via reddit https://ift.tt/NP086qr
https://ift.tt/qSfhLlw
Submitted May 5, 2026 at 04:09PM by nibblesec
via reddit https://ift.tt/NP086qr
Doyensec
The Danger of Multi-SSO AWS Cognito User Pools
After a small detour, the CloudSecTidbits series is back with new episodes. We had the opportunity to present them at the first DEFCON in Singapore few days ago during our DemoLabs sessions. Meeting Singapore’s community was indeed amazing - thanks again…
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud
https://ift.tt/TlWD5H2
Submitted May 5, 2026 at 04:35PM by Mempodipper
via reddit https://ift.tt/UoDWqnE
https://ift.tt/TlWD5H2
Submitted May 5, 2026 at 04:35PM by Mempodipper
via reddit https://ift.tt/UoDWqnE
Searchlight Cyber
Ghosts of Encryption Past – How we Read All Your Emails in Salesforce Marketing Cloud › Searchlight Cyber
Have you noticed that almost every marketing email you receive looks somewhat similar, or has functionality that seems centralised? This is because most corporations have moved to some form of marketing cloud to facilitate sending mass email campaigns. This…
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10
https://ift.tt/PxUtVlH
Submitted May 5, 2026 at 06:06PM by 0xdea
via reddit https://ift.tt/qFXub64
https://ift.tt/PxUtVlH
Submitted May 5, 2026 at 06:06PM by 0xdea
via reddit https://ift.tt/qFXub64
HN Security
HN Security - Extending Burp Suite for fun and profit – The Montoya way – Part 10 - Articles
Setting up the environment + Hello World Inspecting and tampering HTTP requests and responses Inspecting and tampering WebSocket messages Creating […]
Major AI Clients Shipping With Broken OAuth Implementations
https://ift.tt/ZNSJwzq
Submitted May 5, 2026 at 09:21PM by mhat
via reddit https://ift.tt/vrhTwWB
https://ift.tt/ZNSJwzq
Submitted May 5, 2026 at 09:21PM by mhat
via reddit https://ift.tt/vrhTwWB
Redcaller
MCP Client OAuth Refresh-Token Support Matrix | RedCaller Docs
A compatibility matrix tracking OAuth refresh-token support across 14 MCP clients. Covers status, root causes, SDK layers, and server-side workarounds.
DigiCert: Misissued code signing certificates
https://ift.tt/WbgNGk7
Submitted May 5, 2026 at 10:45PM by overandoutage
via reddit https://ift.tt/kxaQuvj
https://ift.tt/WbgNGk7
Submitted May 5, 2026 at 10:45PM by overandoutage
via reddit https://ift.tt/kxaQuvj
bugzilla.mozilla.org
2033170 - DigiCert: Misissued code signing certificates
ASSIGNED (dcbugzillaresponse) in CA Program - CA Certificate Compliance. Last updated 2026-05-04.
Popular DAEMON Tools software infected – supply chain attack ongoing since April 8, 2026
https://ift.tt/tiNeSuT
Submitted May 5, 2026 at 03:09PM by rkhunter_
via reddit https://ift.tt/zPjgCpT
https://ift.tt/tiNeSuT
Submitted May 5, 2026 at 03:09PM by rkhunter_
via reddit https://ift.tt/zPjgCpT
Scan. Secure. Simplify. — Free Web Tools Platform
https://ift.tt/Xetd896
Submitted May 6, 2026 at 01:37AM by Awkward_Republic5784
via reddit https://ift.tt/CbAFIEH
https://ift.tt/Xetd896
Submitted May 6, 2026 at 01:37AM by Awkward_Republic5784
via reddit https://ift.tt/CbAFIEH
7AZZANI
7AZZANI - Free Security Scanner, Speed Test & Developer Tools
100% free online tools: Website Security Scanner, Speed Test, URL Shortener (ShrinkIt), Database Converter, QR Code Generator, Encryption & more.
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
https://ift.tt/bFLBQW8
Submitted May 6, 2026 at 01:16AM by we-we-we
via reddit https://ift.tt/rZdPUDh
https://ift.tt/bFLBQW8
Submitted May 6, 2026 at 01:16AM by we-we-we
via reddit https://ift.tt/rZdPUDh
Cyera
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama | Cyera Research
Cyera's research team discovered a critical memory-leak vulnerability in Ollama, the world's most popular platform for running large language models (LLMs) locally.
Salesforce pentesting novel techniques- how to be an apex predator
https://ift.tt/AmzCkZS
Submitted May 6, 2026 at 01:09AM by lowlandsmarch
via reddit https://ift.tt/87tGKTw
https://ift.tt/AmzCkZS
Submitted May 6, 2026 at 01:09AM by lowlandsmarch
via reddit https://ift.tt/87tGKTw
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
https://clearbluejar.github.io/posts/pyghidra-mcp-meets-ghidra-gui-drive-project-wide-re-with-local-ai/
Submitted May 6, 2026 at 07:04PM by onlinereadme
via reddit https://ift.tt/UomwzMZ
https://clearbluejar.github.io/posts/pyghidra-mcp-meets-ghidra-gui-drive-project-wide-re-with-local-ai/
Submitted May 6, 2026 at 07:04PM by onlinereadme
via reddit https://ift.tt/UomwzMZ
clearbluejar
pyghidra-mcp Meets Ghidra GUI: Drive Project-Wide RE with Local AI
pyghidra-mcp v0.2.0 ships a GUI-backed mode that lets a local LLM drive a live Ghidra CodeBrowser at full project scope. Renames, plate comments, and cross-binary pivots land in real time, with every edit tagged in Ghidra’s undo history while the session…
Vulnerability Garden
https://vulnerability.garden
Submitted May 6, 2026 at 06:36PM by mk3s
via reddit https://ift.tt/GSMLbAV
https://vulnerability.garden
Submitted May 6, 2026 at 06:36PM by mk3s
via reddit https://ift.tt/GSMLbAV
Vulnerability Garden 🪴
Vulnerability Garden
A growing list of named vulnerabilities, attack techniques and exploits.
Non-Determinism of Maps in Golang: Why, How, and the Consequences
https://ift.tt/zFdf4nB
Submitted May 6, 2026 at 07:54PM by mdulin2
via reddit https://ift.tt/R45YoNc
https://ift.tt/zFdf4nB
Submitted May 6, 2026 at 07:54PM by mdulin2
via reddit https://ift.tt/R45YoNc
Strikeout Security Blog
Non-Determinism of Maps in Golang: Why, How, and the Consequences
Golang maps have some randomness in them. Why? To make developers not rely on the ordering and prevent hash collision DoS attacks. Read this article to learn more about the design and consequences of this.
Binance fixed the IP whitelist gap — but the disclosure process is still broken
https://blog.technopathy.club/binance-fixed-the-ip-whitelist-gap-the-disclosure-process-is-still-broken
Submitted May 6, 2026 at 10:24PM by oliver-zehentleitner
via reddit https://ift.tt/SRPiMTk
https://blog.technopathy.club/binance-fixed-the-ip-whitelist-gap-the-disclosure-process-is-still-broken
Submitted May 6, 2026 at 10:24PM by oliver-zehentleitner
via reddit https://ift.tt/SRPiMTk
Quacc++: Automated Open Source Vulnerability Discovery
https://ift.tt/RZ71E5b
Submitted May 7, 2026 at 04:04AM by somersetrecon
via reddit https://ift.tt/EzutgGS
https://ift.tt/RZ71E5b
Submitted May 7, 2026 at 04:04AM by somersetrecon
via reddit https://ift.tt/EzutgGS
Somerset Recon
Quacc++ | Open Source Vulnerability Research Tool Powered by Semgrep & Grep.app — Somerset Recon
Quacc++ combines grep.app's massive repo search with Semgrep's static analysis to automate vulnerability hunting across all public GitHub code. Built for security researchers.
Approve Once, Exploit Forever: The Trust Persistence Problem in Claude Code, Codex and Gemini-CLI
https://ift.tt/kSbQ63g
Submitted May 7, 2026 at 05:29PM by V01d01
via reddit https://ift.tt/lNyxPkH
https://ift.tt/kSbQ63g
Submitted May 7, 2026 at 05:29PM by V01d01
via reddit https://ift.tt/lNyxPkH
mindgard.ai
Persistent Trust Flaws in AI Coding Agents | Mindgard - Mindgard
Mindgard Research found persistent trust flaws in AI coding agents that can let changed project configs execute without re-approval.
An AI security auditor that red-teams PRs to find exploits, not just patterns (open-source + Ollama support)
https://ift.tt/0HnGdqw
Submitted May 7, 2026 at 05:39PM by itzdeeni
via reddit https://ift.tt/7YBZbRe
https://ift.tt/0HnGdqw
Submitted May 7, 2026 at 05:39PM by itzdeeni
via reddit https://ift.tt/7YBZbRe
Bypassing Bitlocker under 5 min using downgrade attack on CVE-2025-48804
https://ift.tt/wW27GfZ
Submitted May 7, 2026 at 08:07PM by Intrinsec_
via reddit https://ift.tt/PDoUTfI
https://ift.tt/wW27GfZ
Submitted May 7, 2026 at 08:07PM by Intrinsec_
via reddit https://ift.tt/PDoUTfI
INTRINSEC
Contournement BitLocker : la réalité des downgrade attacks
Découvrez le contournement BitLocker et la réalité des downgrade attacks face à la vulnérabilité CVE-2025-48804.
CVE-2026-42511 Breakdown: RCE in FreeBSD
https://ift.tt/HUzSNfP
Submitted May 7, 2026 at 10:04PM by MegaManSec2
via reddit https://ift.tt/kEnfCLy
https://ift.tt/HUzSNfP
Submitted May 7, 2026 at 10:04PM by MegaManSec2
via reddit https://ift.tt/kEnfCLy
AISLE
AISLE Finds 21-Year-Old FreeBSD RCE Hidden in dhclient
Learn how AISLE discovered a command injection to root RCE vulnerability in FreeBSD.
Honey Tokens: Bait Credentials That Catch Breaches
https://ift.tt/sODkMgH
Submitted May 7, 2026 at 10:42PM by finncmdbar
via reddit https://ift.tt/Gfbvj4N
https://ift.tt/sODkMgH
Submitted May 7, 2026 at 10:42PM by finncmdbar
via reddit https://ift.tt/Gfbvj4N
Infisical Blog
Infisical Honey Tokens: Bait Credentials That Catch Breaches
Honey tokens are fake credentials that alert you of breaches when attackers use them.
Dirty Frag - Linux LPE similiar to Copy Fail
https://ift.tt/lVONU9X
Submitted May 8, 2026 at 01:19AM by sheepfiend
via reddit https://ift.tt/K2MwUsB
https://ift.tt/lVONU9X
Submitted May 8, 2026 at 01:19AM by sheepfiend
via reddit https://ift.tt/K2MwUsB
Vuink.com
Search code, repositories, users, issues, pull requests...
This document describes the Dirty Frag vulnerability class, first discovered and reported by Hyunwoo Kim (@v4bel), which can obtain root privileges on.
Kernel LPE Vulnerability Published Early Due To Third-Party Breaking Embargo
https://ift.tt/54VMNw8
Submitted May 8, 2026 at 02:52AM by LordAlfredo
via reddit https://ift.tt/bFcWEvT
https://ift.tt/54VMNw8
Submitted May 8, 2026 at 02:52AM by LordAlfredo
via reddit https://ift.tt/bFcWEvT
LWN.net
Dirty Frag: a zero-day universal Linux LPE
Hyunwoo Kim has announced the Dirty Frag security flaw, a local-privilege-escalation (LPE) vuln [...]