Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
https://ift.tt/Sj5alwF
Submitted May 19, 2026 at 04:43PM by sethsec
via reddit https://ift.tt/i4hQ6D2
https://ift.tt/Sj5alwF
Submitted May 19, 2026 at 04:43PM by sethsec
via reddit https://ift.tt/i4hQ6D2
Datadoghq
Pathfinding Labs: Deploy, test, and learn from 100+ intentionally vulnerable AWS environments
Introducing Pathfinding Labs, a collection of intentionally vulnerable AWS environments for red teamers and blue teamers to deploy, exploit, and use for detection validation.
CVE-2026-34473: Pre-auth ZTE H-series router DoS via CGILua request-body parsing
https://minanagehsalalma.github.io/cve-2026-34473-unauthenticated-dos-zte-routers/
Submitted May 19, 2026 at 04:38PM by TheReedemer69
via reddit https://ift.tt/WNjLyHM
https://minanagehsalalma.github.io/cve-2026-34473-unauthenticated-dos-zte-routers/
Submitted May 19, 2026 at 04:38PM by TheReedemer69
via reddit https://ift.tt/WNjLyHM
minanagehsalalma.github.io
CVE-2026-34473: Unauthenticated Denial of Service in ZTE Routers affecting 140K+ devices worldwide (17+ models)
Technical breakdown of the unauthenticated ZTE router DoS published as CVE-2026-34473.
How Storm-2949 turned a compromised identity into a cloud-wide breach
https://ift.tt/EK2VqS8
Submitted May 19, 2026 at 08:29PM by thewhippersnapper4
via reddit https://ift.tt/PiYxAN2
https://ift.tt/EK2VqS8
Submitted May 19, 2026 at 08:29PM by thewhippersnapper4
via reddit https://ift.tt/PiYxAN2
Microsoft News
How Storm-2949 turned a compromised identity into a cloud-wide breach
Storm-2949 turned stolen credentials into a cloud-wide breach, moving from identity compromise to large-scale data theft without using malware. This incident shows how threat actors can exploit trusted systems to operate undetected.
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
https://ift.tt/ejZCJ3O
Submitted May 20, 2026 at 01:09AM by lohacker0
via reddit https://ift.tt/KjzPXJ4
https://ift.tt/ejZCJ3O
Submitted May 20, 2026 at 01:09AM by lohacker0
via reddit https://ift.tt/KjzPXJ4
Varonis
GhostTree: Unveiling Path Manipulation Techniques to Bypass Windows Security
Varonis Threat Labs discovered a new technique that abuses NTFS junctions to generate infinite file paths, causing EDR products to hang and leave files unscanned.
Sleeping Agent: Silent persistent C2 through Web Push
https://ift.tt/jVWPGig
Submitted May 20, 2026 at 02:28AM by More-Protection-821
via reddit https://ift.tt/WR9FV3G
https://ift.tt/jVWPGig
Submitted May 20, 2026 at 02:28AM by More-Protection-821
via reddit https://ift.tt/WR9FV3G
www.bountyy.fi
Sleeping Agent: Silent persistent C2 through Web Push
Web Push userVisibleOnly was unenforced on Chrome, Edge, and pre-26.5 Safari. A showNotification/close race made the Service Worker silently exploitable as a persistent C2 channel via FCM and WNS. Apple shipped a fix on May 11. The Chromium patch (CL 7767797)…
Veilgate - Deception proxy
https://ift.tt/pobkNjW
Submitted May 20, 2026 at 09:48AM by deffer_function
via reddit https://ift.tt/Gu4FMPe
https://ift.tt/pobkNjW
Submitted May 20, 2026 at 09:48AM by deffer_function
via reddit https://ift.tt/Gu4FMPe
VeilGate
VeilGate - Deception reverse proxy for bot and agent defense
Score traffic, solve PoW challenges for legitimate apps, and route hostile automation into controlled tarpits.
We audited 12K n8n templates: most have critical vulnerabilities
https://ift.tt/LQuNogB
Submitted May 20, 2026 at 10:57AM by theMiddleBlue
via reddit https://ift.tt/FJlGEni
https://ift.tt/LQuNogB
Submitted May 20, 2026 at 10:57AM by theMiddleBlue
via reddit https://ift.tt/FJlGEni
AIronClaw Blog
We audited 12K n8n templates: most have critical vulnerabilities
Static analysis on 12,750 n8n templates from n8n.io and GitHub. 716 expose pre-auth vulnerabilities. Six end-to-end demos: SSRF, SQL injection, RCE.
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
https://ift.tt/epJ4WUg
Submitted May 20, 2026 at 02:07PM by nibblesec
via reddit https://ift.tt/EZN3uUp
https://ift.tt/epJ4WUg
Submitted May 20, 2026 at 02:07PM by nibblesec
via reddit https://ift.tt/EZN3uUp
Doyensec
When Filenames Become Attack Surfaces: Weaponizing NASA's CFITSIO Extended Filename Syntax
This research was recently presented at BSides Luxembourg 2026. This blogpost documents our findings presented during the talk. The BSides slides are posted here. Today, we’re also releasing the Docker-based playground utilized for the demos so anyone interested…
GitHub hit by a compromised VSCode extension
https://ift.tt/sIu6QYp
Submitted May 20, 2026 at 05:05PM by acdha
via reddit https://ift.tt/knZ4W9Q
https://ift.tt/sIu6QYp
Submitted May 20, 2026 at 05:05PM by acdha
via reddit https://ift.tt/knZ4W9Q
Nitter
GitHub (@github)
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious…
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious…
CVE-2026-34472: Pre-auth credential exposure and auth bypass in ZTE H188A V6 routers
https://minanagehsalalma.github.io/cve-2026-34472-auth-bypass-zte-h188a-router/
Submitted May 20, 2026 at 07:19PM by TheReedemer69
via reddit https://ift.tt/nGZ27r4
https://minanagehsalalma.github.io/cve-2026-34472-auth-bypass-zte-h188a-router/
Submitted May 20, 2026 at 07:19PM by TheReedemer69
via reddit https://ift.tt/nGZ27r4
minanagehsalalma.github.io
CVE-2026-34472: ZTE H188A Auth Bypass via Leaked Credentials
Observed exploit path: unauthenticated wizard requests disclose admin, WLAN, and PPPoE credentials. Those leaked secrets then become a direct path to management-interface auth bypass.
Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online
https://ift.tt/8MJ9jnt
Submitted May 20, 2026 at 07:10PM by Beginning-Wish-4273
via reddit https://ift.tt/lhNioOb
https://ift.tt/8MJ9jnt
Submitted May 20, 2026 at 07:10PM by Beginning-Wish-4273
via reddit https://ift.tt/lhNioOb
Iran News Wire
Iran Wants to Tax the Internet Flowing Through the Strait of Hormuz While Restricting Its Own Citizens Online
Iran’s plan to “tax the internet” in the Strait of Hormuz highlights the regime’s push to profit from global data cables while restricting citizens online.
The IBM X-Force Index 2026 explains all three in one finding.
https://ift.tt/Kv82Hmu
Submitted May 20, 2026 at 06:45PM by dhakalster123
via reddit https://ift.tt/hfEvX4c
https://ift.tt/Kv82Hmu
Submitted May 20, 2026 at 06:45PM by dhakalster123
via reddit https://ift.tt/hfEvX4c
Hitechies — AI, Crypto, Security & Dev News for Tech Profession
Grafana breached yesterday. Vercel last month. Stryker in March. IBM just published why.
IBM X-Force Index 2026: supply chain attacks 4x in 5 years. 50% of global orgs had an AI-related security incident. North America most attacked for first time in 6 years. The common thread is preventable.
Score by collisions, patch by panic: defensive architecture for the post-90-day-disclosure era
https://ift.tt/eCzWPsI
Submitted May 20, 2026 at 08:16PM by unknownhad
via reddit https://ift.tt/2bpu3ek
https://ift.tt/eCzWPsI
Submitted May 20, 2026 at 08:16PM by unknownhad
via reddit https://ift.tt/2bpu3ek
Himanshu Anand :: Threat Notes
score by collisions, patch by panic
TLDR; Score severity by collision count. Researchers ship patches not just reports. Companies redesign for a world where the exploit lands before the patch. No magic. No vendor pitch. Just the playbook.
The last post went further than I expected. NYT’s Hard…
The last post went further than I expected. NYT’s Hard…
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
https://ift.tt/I7MBj5o
Submitted May 20, 2026 at 07:52PM by FanImmediate5874
via reddit https://ift.tt/hjOA8u7
https://ift.tt/I7MBj5o
Submitted May 20, 2026 at 07:52PM by FanImmediate5874
via reddit https://ift.tt/hjOA8u7
ZeroDay Brief
CVE-2026-45585: Windows BitLocker — YellowKey Recovery Bypass Analysis
CVE-2026-45585 (CVSS 6.8): YellowKey bypasses BitLocker encryption via Windows Recovery Environment. No password cracking. No TPM exploit. Just a maintenance request the OS processed exactly as designed.
The IBM X-Force Index 2026 explains all three in one finding.
https://ift.tt/Kv82Hmu
Submitted May 21, 2026 at 11:48AM by dhakalster123
via reddit https://ift.tt/WklTKbF
https://ift.tt/Kv82Hmu
Submitted May 21, 2026 at 11:48AM by dhakalster123
via reddit https://ift.tt/WklTKbF
Hitechies — AI, Crypto, Security & Dev News for Tech Profession
Grafana breached yesterday. Vercel last month. Stryker in March. IBM just published why.
IBM X-Force Index 2026: supply chain attacks 4x in 5 years. 50% of global orgs had an AI-related security incident. North America most attacked for first time in 6 years. The common thread is preventable.