Bad Epoll: The bug missed by Mythos
https://ift.tt/U1xr4ZW
Submitted July 8, 2026 at 06:41AM by sanxiyn
via reddit https://ift.tt/OZSdTA6
https://ift.tt/U1xr4ZW
Submitted July 8, 2026 at 06:41AM by sanxiyn
via reddit https://ift.tt/OZSdTA6
Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
https://byteray-ai.github.io/drift-corpus
Submitted July 8, 2026 at 09:54PM by Emergency_Stable_923
via reddit https://ift.tt/oRVDqWN
https://byteray-ai.github.io/drift-corpus
Submitted July 8, 2026 at 09:54PM by Emergency_Stable_923
via reddit https://ift.tt/oRVDqWN
Reddit
From the netsec community on Reddit: Drift Corpus: binary diffs of 240+ 2026 Windows kernel patches
Posted by Emergency_Stable_923 - 5 votes and 3 comments
1 in 2 devices sold in Africa exfiltrate data to China
https://ift.tt/462UpD0
Submitted July 8, 2026 at 11:19PM by AdTemporary2475
via reddit https://ift.tt/QaGRTCh
https://ift.tt/462UpD0
Submitted July 8, 2026 at 11:19PM by AdTemporary2475
via reddit https://ift.tt/QaGRTCh
Nowsecure
What the Transsion Telemetry Research Means for Mobile Security - NowSecure
1-in-2 phones sold in Africa ship a hidden telemetry framework that encrypts whole-device activity to shalltry.com Transsion is the world's fourth-largest
Why the HTTP QUERY Method Is a Bad Idea, and Accept-Query Is Why
https://ift.tt/yUvS6ip
Submitted July 9, 2026 at 02:36PM by theMiddleBlue
via reddit https://ift.tt/l6qzy0j
https://ift.tt/yUvS6ip
Submitted July 9, 2026 at 02:36PM by theMiddleBlue
via reddit https://ift.tt/l6qzy0j
Sicuranext Blog
Why the HTTP QUERY Method Is a Bad Idea, and Accept-Query Is Why
In June 2026 the IETF published RFC 10008 and gave HTTP a new method: QUERY. New HTTP methods are rare. Most engineers have not seen one added in about twenty years, so this is worth understanding before it shows up in your stack.
At first, when I saw this…
At first, when I saw this…
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
https://ift.tt/lNBgUGn
Submitted July 9, 2026 at 07:58PM by CyberMasterV
via reddit https://ift.tt/abmovyU
https://ift.tt/lNBgUGn
Submitted July 9, 2026 at 07:58PM by CyberMasterV
via reddit https://ift.tt/abmovyU
Blogspot
Suspected Russian Threat Actor Impersonates Legitimate Crypto Wallets to Deploy Remote Utilities
Author(s): Vlad Pasca Executive Summary Threat actor distributes malicious cryptocurrency wallets (Anchor, Zec, Iota, Onto, Dark, and Stella...
Inside an AI coal mine security camera network powered by plaintext passwords
https://ift.tt/HeqkS4V
Submitted July 8, 2026 at 10:50PM by EatonZ
via reddit https://ift.tt/plmnPNF
https://ift.tt/HeqkS4V
Submitted July 8, 2026 at 10:50PM by EatonZ
via reddit https://ift.tt/plmnPNF
Eaton-Works
Inside an AI coal mine security camera network powered by plaintext passwords
Coal India’s intelligent CCTV platform developed by DeepSight AI Labs and Accenture had plaintext passwords and no API authentication.
Towards CSI: What's the best harness? (arXiv 2026)
https://ift.tt/0lDG82i
Submitted July 10, 2026 at 03:19PM by Obvious-Language4462
via reddit https://ift.tt/5Fxepsv
https://ift.tt/0lDG82i
Submitted July 10, 2026 at 03:19PM by Obvious-Language4462
via reddit https://ift.tt/5Fxepsv
Can AI-generated adversaries break TTP-based attribution? (arXiv 2026)
https://ift.tt/0vxnsbB
Submitted July 10, 2026 at 05:20PM by Obvious-Language4462
via reddit https://ift.tt/mhDpvrT
https://ift.tt/0vxnsbB
Submitted July 10, 2026 at 05:20PM by Obvious-Language4462
via reddit https://ift.tt/mhDpvrT
Closing the Timing Gap: Defensive Temporal Observability
https://ift.tt/EblsGwR
Submitted July 11, 2026 at 02:16AM by Standard-964
via reddit https://ift.tt/L8Wmvsr
https://ift.tt/EblsGwR
Submitted July 11, 2026 at 02:16AM by Standard-964
via reddit https://ift.tt/L8Wmvsr
arXiv.org
A Systematic Survey of Security Threats and Defenses in LLM-Based...
Agentic AI systems introduce a security surface that is qualitatively different from that of stateless LLMs. They persist memory, invoke external tools, coordinate with peer agents, and operate...
Inside Raton RAT: A Commodity Trojan That Tries to Do Everything
https://ift.tt/EuPZ0zA
Submitted July 11, 2026 at 03:46AM by SpectreTv
via reddit https://ift.tt/Gmga2KO
https://ift.tt/EuPZ0zA
Submitted July 11, 2026 at 03:46AM by SpectreTv
via reddit https://ift.tt/Gmga2KO
Decodalabs
Inside Raton RAT: A Commodity Trojan That Tries to Do Everything
Static analysis of a .NET RAT that ships browser credential theft, Discord token harvesting, cryptocurrency wallet draining, and a Jigsaw-inspired ransomware module in a single 2.5 MB executable.
Scanning malicious websites with arbitrary number of VPN tunnels (Part 2)
https://ift.tt/TOC4fiB
Submitted July 11, 2026 at 09:43PM by moonlightelite
via reddit https://ift.tt/ZTJiyoU
https://ift.tt/TOC4fiB
Submitted July 11, 2026 at 09:43PM by moonlightelite
via reddit https://ift.tt/ZTJiyoU
Substack
Scanning malicious websites with 'infinite' number of VPN tunnels (Part 2)
(Part 1 here)
CVE-2026-47291: Windows Critical Unauthenticated Remote Code Execution in HTTP.sys
https://byteray-ai.github.io/drift-corpus/item/http_a10f1434-http-report-20260629-001610.html
Submitted July 12, 2026 at 08:07PM by Emergency_Stable_923
via reddit https://ift.tt/kmMnYBV
https://byteray-ai.github.io/drift-corpus/item/http_a10f1434-http-report-20260629-001610.html
Submitted July 12, 2026 at 08:07PM by Emergency_Stable_923
via reddit https://ift.tt/kmMnYBV
Reddit
From the netsec community on Reddit: CVE-2026-47291: Windows Critical Unauthenticated Remote Code Execution in HTTP.sys
Posted by Emergency_Stable_923 - 1 vote and 0 comments
Vulnerability in Realtek driver allows DMA controller abuse from user mode with no additional hardware or driver
https://zwclose.github.io/2026/07/08/rtsper2.html
Submitted July 13, 2026 at 02:09AM by zwclose
via reddit https://ift.tt/Y2qpucD
https://zwclose.github.io/2026/07/08/rtsper2.html
Submitted July 13, 2026 at 02:09AM by zwclose
via reddit https://ift.tt/Y2qpucD
ZwClose
Vulnerabilities of Realtek SD card reader driver, part2
This is the second part of my write-up on vulnerabilities in the Realtek SD card reader driver. In this part, I will show how exposing device registers to non-privileged users can lead to access to physical memory. The post focuses solely on the DMA vulnerability…
LIEF 1.0.0 is out featuring a brand-new Runtime API
https://ift.tt/8WOMfNx
Submitted July 13, 2026 at 11:24AM by rh0main
via reddit https://ift.tt/pyY64sk
https://ift.tt/8WOMfNx
Submitted July 13, 2026 at 11:24AM by rh0main
via reddit https://ift.tt/pyY64sk
LIEF
LIEF v1.0.0 | LIEF
LIEF 1.0.0: a new cross-platform Runtime API, faster Rust bindings, stable-ABI and free-threaded Python wheels | LIEF
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
https://ift.tt/7Yakt6Q
Submitted July 13, 2026 at 01:29PM by netbiosX
via reddit https://ift.tt/sWLANXh
https://ift.tt/7Yakt6Q
Submitted July 13, 2026 at 01:29PM by netbiosX
via reddit https://ift.tt/sWLANXh
Purple Team
AMSI Provider
The Antimalware Scan Interface (AMSI) is a Microsoft control that directs PowerShell content to the installed antimalware engine or EDR to conduct a scan and identify malicious indicators. However,…
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
https://ift.tt/NG4fx6I
Submitted July 13, 2026 at 03:03PM by sajkoterrapefft
via reddit https://ift.tt/swdaTnW
https://ift.tt/NG4fx6I
Submitted July 13, 2026 at 03:03PM by sajkoterrapefft
via reddit https://ift.tt/swdaTnW
Amberwolf
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
AmberWolf Security Research Blog
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
Submitted July 14, 2026 at 02:01AM by _MrTiz
via reddit https://ift.tt/UXTCtpg
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
Submitted July 14, 2026 at 02:01AM by _MrTiz
via reddit https://ift.tt/UXTCtpg
Tiziano’s Cybersecurity Blog
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining
Disclaimer. This research is published for educational and defensive purposes only. I do not endorse the use of this technique for unauthorized access to any computer system. Always obtain explicit written authorization before testing. If you use this on…
Context Bombs: Using AI Guardrails as a defensive mechanism
https://ift.tt/g9Yhm4z
Submitted July 14, 2026 at 04:10AM by tracebit
via reddit https://ift.tt/jfcJOYu
https://ift.tt/g9Yhm4z
Submitted July 14, 2026 at 04:10AM by tracebit
via reddit https://ift.tt/jfcJOYu
Tracebit
Context bombs: stopping AI attackers in their tracks
A canary that stops the attacker, not just one that detects it.
ExporTheft: 11 "AI Chat Exporter" Chrome extensions upload full chat content on PDF export, while the store listing says "No uploads to external servers"
https://ift.tt/KnbYaJA
Submitted July 14, 2026 at 04:48AM by Huge-Skirt-6990
via reddit https://ift.tt/rHhVnCl
https://ift.tt/KnbYaJA
Submitted July 14, 2026 at 04:48AM by Huge-Skirt-6990
via reddit https://ift.tt/rHhVnCl
malext.io
ExporTheft: 11 exporters where Export means Upload - MalExt Sentry
Threat intelligence report: ExporTheft: 11 exporters where Export means Upload. Research by MalExt Sentry.
AXON Body camera 3 of 4 hardware reverse cracking output video!
https://b23.tv/gtjjcQo
Submitted July 14, 2026 at 06:23AM by Thomas980130
via reddit https://ift.tt/YlIdWzP
https://b23.tv/gtjjcQo
Submitted July 14, 2026 at 06:23AM by Thomas980130
via reddit https://ift.tt/YlIdWzP
Bilibili
axon body 3 实拍视频 low HD_哔哩哔哩_bilibili
-, 视频播放量 401、弹幕量 0、点赞数 8、投硬币枚数 4、收藏人数 8、转发人数 3, 视频作者 追评即翻车, 作者简介 ,相关视频:axon body 3 实拍视频 low HD 基于某些原因 日期刻意设置错误,晴天只是影石的舒适区,雨天才是真正的统治区,真没想到这个避震这么厉害,普通人第一次使用Insta360go3效果,毫无技巧看看拍出来啥样,500元的迷你扫街神器?一英寸传感器 2040万像素 DXO ONE相机体验,一个已经倒闭的行车记录仪厂家生产的“超级4K”行车记录仪夜景效果,…
Enhancing IIoT Security Using Digital Twins in Industry
https://ift.tt/pI4aeR8
Submitted July 14, 2026 at 11:02AM by TorrensUni
via reddit https://ift.tt/jndIiae
https://ift.tt/pI4aeR8
Submitted July 14, 2026 at 11:02AM by TorrensUni
via reddit https://ift.tt/jndIiae
Torrens University Australia
Enhancing IIoT Security Using Digital Twins in Industry 5.0: A Systematic Literature Review