Analyzing the Taiwan High-Speed Rail (THSR) TETRA incident (part 1)
https://ift.tt/SK37bxc
Submitted May 26, 2026 at 05:53PM by 2ROT13
via reddit https://ift.tt/ymRhqzg
https://ift.tt/SK37bxc
Submitted May 26, 2026 at 05:53PM by 2ROT13
via reddit https://ift.tt/ymRhqzg
www.midnightblue.nl
Analyzing the Taiwan High-Speed Rail (THSR) TETRA cyber incident (part 1)
Deep dive analysis of the TETRA cyber incident which disrupted operations at Taiwan High Speed Rail (THSR) in April 2026.
How journalists rely on VPNs to protect press freedom
https://freedom.press/issues/how-journalists-rely-on-vpns-to-protect-press-freedom/
Submitted May 26, 2026 at 07:27PM by FreedomofPress
via reddit https://ift.tt/wXu0O2y
https://freedom.press/issues/how-journalists-rely-on-vpns-to-protect-press-freedom/
Submitted May 26, 2026 at 07:27PM by FreedomofPress
via reddit https://ift.tt/wXu0O2y
Freedom of the Press
How journalists rely on VPNs to protect press freedom
Recent attempts to ban VPNs to stop users from evading age-verification laws are a growing threat to journalism
OTP lockout state leaked valid-code signal, enabling OLX account takeover
https://minanagehsalalma.github.io/olx-account-takeover/
Submitted May 26, 2026 at 08:35PM by TheReedemer69
via reddit https://ift.tt/hL0qOHz
https://minanagehsalalma.github.io/olx-account-takeover/
Submitted May 26, 2026 at 08:35PM by TheReedemer69
via reddit https://ift.tt/hL0qOHz
OLX Account Takeover Write-Up
When “Try Again Later” Still Means “You Guessed Right”: OLX account takeover
A polished security write-up about an OLX verification-code flaw that still leaked the correct code during lockout and led to account takeover.
Encrypted DNS in 2026: DoH, DoT, DoQ and DoH3 protocol comparison — including DNS hijacking attack vectors and what each protocol actually prevents
https://ift.tt/fT8tCvV
Submitted May 26, 2026 at 08:46PM by AnywhereOk3723
via reddit https://ift.tt/KBz3LfZ
https://ift.tt/fT8tCvV
Submitted May 26, 2026 at 08:46PM by AnywhereOk3723
via reddit https://ift.tt/KBz3LfZ
Copahost
DNS over HTTPS, DNS over TLS, and DNS over QUIC: Which Encrypted DNS Protocol Should You Use? - Copahost
DNS queries travel in plain text by default — even when your site uses HTTPS. Here's how DoH, DoT, DoQ and DoH3 work, how they compare in performance (real benchmarks from 3,000+ resolvers), and which one is right for your website.
Navigating Lax Load Balancers: When an Intersection Gets You Inside
https://ift.tt/rWMw06h
Submitted May 26, 2026 at 10:05PM by nibblesec
via reddit https://ift.tt/HLo3qB8
https://ift.tt/rWMw06h
Submitted May 26, 2026 at 10:05PM by nibblesec
via reddit https://ift.tt/HLo3qB8
Doyensec
Navigating Lax Load Balancers: When an Intersection Gets You Inside
After our last episode on Multi-SSO Cognito User Pools, we are back with another issue. This time, we are looking at one of those AWS components that is everywhere and rarely questioned deeply enough: the Elastic Load Balancer.
RCE in Strix Agent(Sandbox): A practical guide to prompt injections with impact
https://ift.tt/xoq7uQG
Submitted May 27, 2026 at 02:10PM by security_aaudit
via reddit https://ift.tt/B0C7L3T
https://ift.tt/xoq7uQG
Submitted May 27, 2026 at 02:10PM by security_aaudit
via reddit https://ift.tt/B0C7L3T
baldur.dk
BALDUR. - Security Consultancy
How we discovered an RCE in the AI Pentester Strix (sandbox) and how to find prompt injections with impact.
Threat Intel: Lithuania Investigates B2B Credential Misuse Exposing 600,000 National Registry Records
https://ift.tt/rNt7m5p
Submitted May 27, 2026 at 03:54PM by technadu
via reddit https://ift.tt/KTr5Vs9
https://ift.tt/rNt7m5p
Submitted May 27, 2026 at 03:54PM by technadu
via reddit https://ift.tt/KTr5Vs9
TechNadu
Lithuania Investigates State Registry Breach of 600,000 Records - TechNadu
The Lithuanian Prosecutor General’s Office is investigating the theft of over 600,000 Center of Registers records via compromised institutional credentials.
HN Security - AI Reporter - Let's automate reporting in Burp Suite!
https://ift.tt/epUks4r
Submitted May 27, 2026 at 06:12PM by 0xdea
via reddit https://ift.tt/I26bOqm
https://ift.tt/epUks4r
Submitted May 27, 2026 at 06:12PM by 0xdea
via reddit https://ift.tt/I26bOqm
HN Security
HN Security - AI Reporter - Let's automate reporting in Burp Suite! - Articles
Burp Suite AI Reporter generates vulnerability findings from HTTP pairs using Burp AI or Ollama/OpenAI. Export to Markdown in one click.
A week after Dutch FIOD seized 800+ servers, the hosting network's ASN (AS209847) is still scanning at its normal daily rate
https://ift.tt/jz0iE3O
Submitted May 27, 2026 at 07:28PM by HexLayer3
via reddit https://ift.tt/moeUEBT
https://ift.tt/jz0iE3O
Submitted May 27, 2026 at 07:28PM by HexLayer3
via reddit https://ift.tt/moeUEBT
ELLIO
Sanctioned, Seized, Still Scanning: Inside a Russian Bulletproof Hosting Network Targeting the EU | ELLIO Blog
On 18 May 2026, Dutch investigators seized more than 800 servers and broke up a hosting operation that prosecutors say powered Russian cyberattacks across the EU. We had spent the previous year watching the same network from the other side. After the seizure…
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
https://ift.tt/EJAhQyY
Submitted May 27, 2026 at 08:01PM by beyonderdabas
via reddit https://ift.tt/nUKZGNq
https://ift.tt/EJAhQyY
Submitted May 27, 2026 at 08:01PM by beyonderdabas
via reddit https://ift.tt/nUKZGNq
Mohit Dabas's Blog
MalShark: MCP-Powered Malware Traffic Analysis — Benchmarked Against Real Malware
New Phishing Technique - Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
https://ift.tt/YD4f3Fa
Submitted May 27, 2026 at 09:19PM by phishullc
via reddit https://ift.tt/wEAvG2J
https://ift.tt/YD4f3Fa
Submitted May 27, 2026 at 09:19PM by phishullc
via reddit https://ift.tt/wEAvG2J
PhishU
Vaultjacking: One Captured PIN, the Entire Google Password Manager Vault
An end-to-end Adversary-in-the-Middle attack against synced passkeys in the PhishU Framework. Capture the GPM PIN at sign-in, add an operator-owned passkey for persistence, then unlock the entire synced credential vault from the operator's own infrastructure.
Defense by accumulation
https://ift.tt/PcOgC24
Submitted May 28, 2026 at 08:31AM by ok_bye_now_
via reddit https://ift.tt/kW0KBVJ
https://ift.tt/PcOgC24
Submitted May 28, 2026 at 08:31AM by ok_bye_now_
via reddit https://ift.tt/kW0KBVJ
Puck
Defense by accumulation
Sixty-four years of credential security, and why the first hour of every incident is still the same question.
What scanners are actually trying against AI infrastructure
https://ift.tt/gPxGcZB
Submitted May 28, 2026 at 12:41PM by Honeylabs
via reddit https://ift.tt/tE32fr5
https://ift.tt/gPxGcZB
Submitted May 28, 2026 at 12:41PM by Honeylabs
via reddit https://ift.tt/tE32fr5
honeylabs.net
What scanners are actually trying against AI infrastructure · HoneyLabs blog
Three weeks of one Dutch ASN sending 3,861 hits at Anthropic-proxy paths. Port 11434 (Ollama) holding 50-80 distinct source IPs per week since March. A single 45-minute sweep from one IP that lists credential paths for Claude, Codex, Gemini, DeepSeek, DashScope…
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
https://ift.tt/PcKqX9m
Submitted May 28, 2026 at 08:22PM by albinowax
via reddit https://ift.tt/2ehPEWq
https://ift.tt/PcKqX9m
Submitted May 28, 2026 at 08:22PM by albinowax
via reddit https://ift.tt/2ehPEWq
blog.lexfo.fr
Drupal PostgreSQL SQL Injection: From SELECT-Only to RCE
<p>Turning a SELECT-only PostgreSQL SQL injection into remote command execution when the injected role is a PostgreSQL superuser.</p>
Threat Intel: Kemper Corporation Hit by ShinyHunters Salesforce Extortion Campaign (269k Accounts Ingested by HIBP)
https://ift.tt/XjP1h7g
Submitted May 28, 2026 at 09:31PM by technadu
via reddit https://ift.tt/6QCBwR8
https://ift.tt/XjP1h7g
Submitted May 28, 2026 at 09:31PM by technadu
via reddit https://ift.tt/6QCBwR8
TechNadu
Kemper Corporation Exposes 270K Emails Following ShinyHunters Breach Claim - TechNadu
The April 2026 Kemper Corporation Salesforce data breach, orchestrated by ShinyHunters via social engineering, exposed 269,000 sensitive consumer records.
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
https://ift.tt/APscjif
Submitted May 29, 2026 at 01:00AM by acorn222
via reddit https://ift.tt/ZyYHDi7
https://ift.tt/APscjif
Submitted May 29, 2026 at 01:00AM by acorn222
via reddit https://ift.tt/ZyYHDi7
Amibeingpwned
The Word 'Toad' Gave Any Website Full Control of Chrome's Most Popular VPN
Urban VPN's Chrome extension accepted commands from any website via postMessage with no origin validation. Any page could disconnect your VPN, reroute your traffic, disable security features, and more - silently, with zero user interaction.
Visual Studio Extensions Revisited
https://ift.tt/n0EBztU
Submitted May 29, 2026 at 12:34AM by gid0rah
via reddit https://ift.tt/yehgrSc
https://ift.tt/n0EBztU
Submitted May 29, 2026 at 12:34AM by gid0rah
via reddit https://ift.tt/yehgrSc
MDSec
Visual Studio Extensions Revisited - MDSec
28/05/2026 Introduction A few years ago we looked at how Visual Studio Code extensions could be used for initial access in red team engagements; at the time, the results were...
CoreEvent GraphQL API – BOLA/IDOR exposing 10k+ records (PII, ticket QR codes) via unauthenticated queries
https://parl0v.github.io/vulnerabilities/writeups/coreevent/
Submitted May 29, 2026 at 06:12AM by Jipp2109
via reddit https://ift.tt/2eqUtzB
https://parl0v.github.io/vulnerabilities/writeups/coreevent/
Submitted May 29, 2026 at 06:12AM by Jipp2109
via reddit https://ift.tt/2eqUtzB
parl0v
CoreEvent GraphQL API – Broken Access Control (IDOR / BOLA)
Broken access control in GraphQL API allowing unauthorized access to orders and event data.
Fooling around with encrypted reasoning blobs
https://ift.tt/YAFbecO
Submitted May 29, 2026 at 09:30AM by feross
via reddit https://ift.tt/BMZLjOE
https://ift.tt/YAFbecO
Submitted May 29, 2026 at 09:30AM by feross
via reddit https://ift.tt/BMZLjOE
A Few Thoughts on Cryptographic Engineering
Fooling around with encrypted reasoning blobs
This is a quick post I wanted to write about a “hobby project” I spent a weekend on. It has little to do with real cryptography, and mostly doesn’t expose a particularly exciting …
CALIF: An AI audit of FreeBSD
https://ift.tt/lPLY2vn
Submitted May 29, 2026 at 09:10AM by maurosoria
via reddit https://ift.tt/BqdHLpw
https://ift.tt/lPLY2vn
Submitted May 29, 2026 at 09:10AM by maurosoria
via reddit https://ift.tt/BqdHLpw
blog.calif.io
An AI audit of FreeBSD
15 kernel bugs, including 3 RCEs, 5 LPEs, and 1 bhyve escape.
I evaluated 5 LLM agents on patching real-world CVEs. Here is what I found.
https://giovannigatti.github.io/cve-bench/
Submitted May 29, 2026 at 01:02PM by Fickle-Box1433
via reddit https://ift.tt/7l3GiOH
https://giovannigatti.github.io/cve-bench/
Submitted May 29, 2026 at 01:02PM by Fickle-Box1433
via reddit https://ift.tt/7l3GiOH
giovannigatti.github.io
I Tested Whether AI Can Fix Security Vulnerabilities. Well, It's Complicated.
Benchmarking LLMs on real-world CVE patching