Restoring Testability: Handling Complex Scenarios in Burp Suite with a Custom Extension
https://ift.tt/5EfZjtD
Submitted May 22, 2026 at 08:42PM by 0xdea
via reddit https://ift.tt/2kcLZp8
https://ift.tt/5EfZjtD
Submitted May 22, 2026 at 08:42PM by 0xdea
via reddit https://ift.tt/2kcLZp8
HN Security
HN Security - Restoring Testability: Slides, Code & Video - Articles
Hi! Last Thursday, as part of the Burp Extensibility Month on the PortSwigger Discord server, I gave a talk on […]
Just added an interactive security map to my project NoEyes showing exactly what the server sees (and doesn't)
https://ymsniper.github.io/NoEyes/
Submitted May 22, 2026 at 11:41PM by Trick-Resolve-6085
via reddit https://ift.tt/jqROFQy
https://ymsniper.github.io/NoEyes/
Submitted May 22, 2026 at 11:41PM by Trick-Resolve-6085
via reddit https://ift.tt/jqROFQy
AI Security CTF (free, open) - prompt injection, agent workflow hijacking, guardrail bypass - June 17-22
http://kubearmor.io/ctf
Submitted May 23, 2026 at 12:28AM by HighnessAtharva
via reddit https://ift.tt/UmVneh0
http://kubearmor.io/ctf
Submitted May 23, 2026 at 12:28AM by HighnessAtharva
via reddit https://ift.tt/UmVneh0
kubearmor.io
KubeArmor AI Security CTF | KubeArmor
Browser-first CTF landing page for KubeArmor AI security challenges.
CVE-2026-9256 - "nginx-poolslip", another new vulnerability in the rewrite module
https://ift.tt/j6C1ZPc
Submitted May 23, 2026 at 01:15AM by thenickdude
via reddit https://ift.tt/1k39AWL
https://ift.tt/j6C1ZPc
Submitted May 23, 2026 at 01:15AM by thenickdude
via reddit https://ift.tt/1k39AWL
F5
NGINX ngx_http_rewrite_module vulnerability CVE-2026-9256
Security Advisory Description NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Compatible Regular Expression…
Pardon MIE?: how Mythos did not bypass Apple MIE
https://ift.tt/rkvW0F2
Submitted May 23, 2026 at 01:09PM by nindustries
via reddit https://ift.tt/VPS3EFu
https://ift.tt/rkvW0F2
Submitted May 23, 2026 at 01:09PM by nindustries
via reddit https://ift.tt/VPS3EFu
ironpeak.be
Pardon MIE? - ironPeak Blog
How Calif and Anthropic's Mythos cracked Apple's brand-new Memory Integrity Enforcement on the M5 in five days, what the bug actually is, and what defenders and exploit writers should take from it.
How to Use Claude AI: A Complete Technical Beginner's Guide
https://tblogs.site/blog/how-to-use-claude-ai
Submitted May 24, 2026 at 04:30PM by AcanthisittaOk2009
via reddit https://ift.tt/EjADWcl
https://tblogs.site/blog/how-to-use-claude-ai
Submitted May 24, 2026 at 04:30PM by AcanthisittaOk2009
via reddit https://ift.tt/EjADWcl
T-blogs
How to Use Claude AI: A Complete Technical Beginner's Guide
Complete beginner's guide on how to use Claude AI. Master Projects, Artifacts, file uploads, and Anthropic's unique prompting formula.
Prompt Injection finally broke my brain a little. My first article as a security student.
https://ift.tt/8ugMY2V
Submitted May 24, 2026 at 08:18PM by JD_Katz
via reddit https://ift.tt/LqyCcF7
https://ift.tt/8ugMY2V
Submitted May 24, 2026 at 08:18PM by JD_Katz
via reddit https://ift.tt/LqyCcF7
CMX Chat
Prompt Injection Explained Like a Security Student | CMX Chat
A cybersecurity student explains prompt injection, jailbreaks, and AI attack paths in simple terms with real RAG and agent security risks.
nmap on Linux: Guide to Network Scanning and Discovery
https://ift.tt/7rRW3En
Submitted May 25, 2026 at 06:20AM by modelop
via reddit https://ift.tt/dJVYgv5
https://ift.tt/7rRW3En
Submitted May 25, 2026 at 06:20AM by modelop
via reddit https://ift.tt/dJVYgv5
LinuxBlog.io
nmap on Linux: Guide to Network Scanning and Discovery | LinuxBlog.io
A practical guide to nmap on Linux covering host discovery, port and service scanning, OS detection, NSE scripts, output formats, and real-world command combinations sysadmins actually use.
Threat Intel: ShinyHunters Leaks 9.4GB Database of 7-Eleven Franchisee Systems Post-Extortion Refusal
https://ift.tt/tKh6kbm
Submitted May 25, 2026 at 05:27PM by technadu
via reddit https://ift.tt/rDxU1OV
https://ift.tt/tKh6kbm
Submitted May 25, 2026 at 05:27PM by technadu
via reddit https://ift.tt/rDxU1OV
TechNadu
7-Eleven Data Breach Claimed by ShinyHunters Exposes 185K+ Accounts - TechNadu
7-Eleven experienced a data breach exposing 185,300 accounts after a pay or leak extortion campaign by ShinyHunters targeted systems storing franchisee documents.
How credential brokering prevents AI agents from compromising credentials via prompt injection
https://ift.tt/8FES7wW
Submitted May 25, 2026 at 08:39PM by finncmdbar
via reddit https://ift.tt/BTAs4Xi
https://ift.tt/8FES7wW
Submitted May 25, 2026 at 08:39PM by finncmdbar
via reddit https://ift.tt/BTAs4Xi
Infisical Blog
Credential Brokering for AI Agents, Explained | Infisial
A simple guide to credential brokering for AI agents: protect against prompt injection by keeping credentials away from the agent.
CVE-2021-21735: ZTE H168N wizard whitelist exposed PPPoE and WLAN secrets pre-auth
https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/
Submitted May 25, 2026 at 08:17PM by TheReedemer69
via reddit https://ift.tt/pCaxWn5
https://minanagehsalalma.github.io/cve-2021-21735-zte-zxhn-h168n-admin-compromise/
Submitted May 25, 2026 at 08:17PM by TheReedemer69
via reddit https://ift.tt/pCaxWn5
Mina Zekry
Unauthenticated Information Leak to Full Admin Compromise on ZTE ZXHN H168N (CVE-2021-21735)
A first-person disclosure analysis of CVE-2021-21735 on the ZTE ZXHN H168N V3.5, covering the wizard-page leak, firmware whitelist failure, and the included bulk PoC.
The War Between Wars: How an IRGC Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
https://ift.tt/cUumk5N
Submitted May 26, 2026 at 04:48AM by GelosSnake
via reddit https://ift.tt/nh06PtO
https://ift.tt/cUumk5N
Submitted May 26, 2026 at 04:48AM by GelosSnake
via reddit https://ift.tt/nh06PtO
Profero | Rapid-IR
The War Between Wars: How an IRGC Cyber Front Runs Destructive OT and IT Attacks Under Cover of a Ceasefire
An IRGC-directed persona sabotaged industrial refrigeration and staged a disk-wipe campaign at Israeli facilities during a ceasefire. How the operation unfolded, and how to find the actor before it reaches your plant floor.
Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
https://ift.tt/SK37bxc
Submitted May 26, 2026 at 05:53PM by 2ROT13
via reddit https://ift.tt/ymRhqzg
https://ift.tt/SK37bxc
Submitted May 26, 2026 at 05:53PM by 2ROT13
via reddit https://ift.tt/ymRhqzg
www.midnightblue.nl
Analyzing the Taiwan High-Speed Rail (THSR) TETRA cyber incident (part 1)
Deep dive analysis of the TETRA cyber incident which disrupted operations at Taiwan High Speed Rail (THSR) in April 2026.
How journalists rely on VPNs to protect press freedom
https://freedom.press/issues/how-journalists-rely-on-vpns-to-protect-press-freedom/
Submitted May 26, 2026 at 07:27PM by FreedomofPress
via reddit https://ift.tt/wXu0O2y
https://freedom.press/issues/how-journalists-rely-on-vpns-to-protect-press-freedom/
Submitted May 26, 2026 at 07:27PM by FreedomofPress
via reddit https://ift.tt/wXu0O2y
Freedom of the Press
How journalists rely on VPNs to protect press freedom
Recent attempts to ban VPNs to stop users from evading age-verification laws are a growing threat to journalism
OTP lockout state leaked valid-code signal, enabling OLX account takeover
https://minanagehsalalma.github.io/olx-account-takeover/
Submitted May 26, 2026 at 08:35PM by TheReedemer69
via reddit https://ift.tt/hL0qOHz
https://minanagehsalalma.github.io/olx-account-takeover/
Submitted May 26, 2026 at 08:35PM by TheReedemer69
via reddit https://ift.tt/hL0qOHz
OLX Account Takeover Write-Up
When “Try Again Later” Still Means “You Guessed Right”: OLX account takeover
A polished security write-up about an OLX verification-code flaw that still leaked the correct code during lockout and led to account takeover.
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents
https://ift.tt/fT8tCvV
Submitted May 26, 2026 at 08:46PM by AnywhereOk3723
via reddit https://ift.tt/KBz3LfZ
https://ift.tt/fT8tCvV
Submitted May 26, 2026 at 08:46PM by AnywhereOk3723
via reddit https://ift.tt/KBz3LfZ
Copahost
DNS over HTTPS, DNS over TLS, and DNS over QUIC: Which Encrypted DNS Protocol Should You Use? - Copahost
DNS queries travel in plain text by default — even when your site uses HTTPS. Here's how DoH, DoT, DoQ and DoH3 work, how they compare in performance (real benchmarks from 3,000+ resolvers), and which one is right for your website.
Navigating Lax Load Balancers: When an Intersection Gets You Inside
https://ift.tt/rWMw06h
Submitted May 26, 2026 at 10:05PM by nibblesec
via reddit https://ift.tt/HLo3qB8
https://ift.tt/rWMw06h
Submitted May 26, 2026 at 10:05PM by nibblesec
via reddit https://ift.tt/HLo3qB8
Doyensec
Navigating Lax Load Balancers: When an Intersection Gets You Inside
After our last episode on Multi-SSO Cognito User Pools, we are back with another issue. This time, we are looking at one of those AWS components that is everywhere and rarely questioned deeply enough: the Elastic Load Balancer.
RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact
https://ift.tt/xoq7uQG
Submitted May 27, 2026 at 02:10PM by security_aaudit
via reddit https://ift.tt/B0C7L3T
https://ift.tt/xoq7uQG
Submitted May 27, 2026 at 02:10PM by security_aaudit
via reddit https://ift.tt/B0C7L3T
baldur.dk
BALDUR. - Security Consultancy
How we discovered an RCE in the AI Pentester Strix (sandbox) and how to find prompt injections with impact.
Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records
https://ift.tt/rNt7m5p
Submitted May 27, 2026 at 03:54PM by technadu
via reddit https://ift.tt/KTr5Vs9
https://ift.tt/rNt7m5p
Submitted May 27, 2026 at 03:54PM by technadu
via reddit https://ift.tt/KTr5Vs9
TechNadu
Lithuania Investigates State Registry Breach of 600,000 Records - TechNadu
The Lithuanian Prosecutor General’s Office is investigating the theft of over 600,000 Center of Registers records via compromised institutional credentials.
HN Security - AI Reporter - Let's automate reporting in Burp Suite!
https://ift.tt/epUks4r
Submitted May 27, 2026 at 06:12PM by 0xdea
via reddit https://ift.tt/I26bOqm
https://ift.tt/epUks4r
Submitted May 27, 2026 at 06:12PM by 0xdea
via reddit https://ift.tt/I26bOqm
HN Security
HN Security - AI Reporter - Let's automate reporting in Burp Suite! - Articles
Burp Suite AI Reporter generates vulnerability findings from HTTP pairs using Burp AI or Ollama/OpenAI. Export to Markdown in one click.
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
https://ift.tt/jz0iE3O
Submitted May 27, 2026 at 07:28PM by HexLayer3
via reddit https://ift.tt/moeUEBT
https://ift.tt/jz0iE3O
Submitted May 27, 2026 at 07:28PM by HexLayer3
via reddit https://ift.tt/moeUEBT
ELLIO
Sanctioned, Seized, Still Scanning: Inside a Russian Bulletproof Hosting Network Targeting the EU | ELLIO Blog
On 18 May 2026, Dutch investigators seized more than 800 servers and broke up a hosting operation that prosecutors say powered Russian cyberattacks across the EU. We had spent the previous year watching the same network from the other side. After the seizure…