LIEF 1.0.0 is out featuring a brand-new Runtime API
https://ift.tt/8WOMfNx
Submitted July 13, 2026 at 11:24AM by rh0main
via reddit https://ift.tt/pyY64sk
https://ift.tt/8WOMfNx
Submitted July 13, 2026 at 11:24AM by rh0main
via reddit https://ift.tt/pyY64sk
LIEF
LIEF v1.0.0 | LIEF
LIEF 1.0.0: a new cross-platform Runtime API, faster Rust bindings, stable-ABI and free-threaded Python wheels | LIEF
Persistence via Fake AMSI Provider | Playbook & Detection Strategies
https://ift.tt/7Yakt6Q
Submitted July 13, 2026 at 01:29PM by netbiosX
via reddit https://ift.tt/sWLANXh
https://ift.tt/7Yakt6Q
Submitted July 13, 2026 at 01:29PM by netbiosX
via reddit https://ift.tt/sWLANXh
Purple Team
AMSI Provider
The Antimalware Scan Interface (AMSI) is a Microsoft control that directs PowerShell content to the installed antimalware engine or EDR to conduct a scan and identify malicious indicators. However,…
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
https://ift.tt/NG4fx6I
Submitted July 13, 2026 at 03:03PM by sajkoterrapefft
via reddit https://ift.tt/swdaTnW
https://ift.tt/NG4fx6I
Submitted July 13, 2026 at 03:03PM by sajkoterrapefft
via reddit https://ift.tt/swdaTnW
Amberwolf
Dell BIOS Passwords: Weak XOR Encryption Allows Recovery from SPI Flash (CVE-2026-40639)
AmberWolf Security Research Blog
CET-Compliant Callstack Spoofing via Thread Pool & Enum Callback Trampolining (Rust PoC)
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
Submitted July 14, 2026 at 02:01AM by _MrTiz
via reddit https://ift.tt/UXTCtpg
https://mrtiz.github.io/cet-callstack-spoofing-thread-pool-trampoline
Submitted July 14, 2026 at 02:01AM by _MrTiz
via reddit https://ift.tt/UXTCtpg
Tiziano’s Cybersecurity Blog
CET-Compliant Callstack Spoofing via Thread Pool Enum Callback Trampolining
Disclaimer. This research is published for educational and defensive purposes only. I do not endorse the use of this technique for unauthorized access to any computer system. Always obtain explicit written authorization before testing. If you use this on…
Context Bombs: Using AI Guardrails as a defensive mechanism
https://ift.tt/g9Yhm4z
Submitted July 14, 2026 at 04:10AM by tracebit
via reddit https://ift.tt/jfcJOYu
https://ift.tt/g9Yhm4z
Submitted July 14, 2026 at 04:10AM by tracebit
via reddit https://ift.tt/jfcJOYu
Tracebit
Context bombs: stopping AI attackers in their tracks
A canary that stops the attacker, not just one that detects it.
ExporTheft: 11 "AI Chat Exporter" Chrome extensions upload full chat content on PDF export, while the store listing says "No uploads to external servers"
https://ift.tt/KnbYaJA
Submitted July 14, 2026 at 04:48AM by Huge-Skirt-6990
via reddit https://ift.tt/rHhVnCl
https://ift.tt/KnbYaJA
Submitted July 14, 2026 at 04:48AM by Huge-Skirt-6990
via reddit https://ift.tt/rHhVnCl
malext.io
ExporTheft: 11 exporters where Export means Upload - MalExt Sentry
Threat intelligence report: ExporTheft: 11 exporters where Export means Upload. Research by MalExt Sentry.
AXON Body camera 3 of 4 hardware reverse cracking output video!
https://b23.tv/gtjjcQo
Submitted July 14, 2026 at 06:23AM by Thomas980130
via reddit https://ift.tt/YlIdWzP
https://b23.tv/gtjjcQo
Submitted July 14, 2026 at 06:23AM by Thomas980130
via reddit https://ift.tt/YlIdWzP
Bilibili
axon body 3 实拍视频 low HD_哔哩哔哩_bilibili
-, 视频播放量 401、弹幕量 0、点赞数 8、投硬币枚数 4、收藏人数 8、转发人数 3, 视频作者 追评即翻车, 作者简介 ,相关视频:axon body 3 实拍视频 low HD 基于某些原因 日期刻意设置错误,晴天只是影石的舒适区,雨天才是真正的统治区,真没想到这个避震这么厉害,普通人第一次使用Insta360go3效果,毫无技巧看看拍出来啥样,500元的迷你扫街神器?一英寸传感器 2040万像素 DXO ONE相机体验,一个已经倒闭的行车记录仪厂家生产的“超级4K”行车记录仪夜景效果,…
Enhancing IIoT Security Using Digital Twins in Industry
https://ift.tt/pI4aeR8
Submitted July 14, 2026 at 11:02AM by TorrensUni
via reddit https://ift.tt/jndIiae
https://ift.tt/pI4aeR8
Submitted July 14, 2026 at 11:02AM by TorrensUni
via reddit https://ift.tt/jndIiae
Torrens University Australia
Enhancing IIoT Security Using Digital Twins in Industry 5.0: A Systematic Literature Review
Writing an Evasive .NET Shellcode Loader
https://ift.tt/SiDM8BL
Submitted July 14, 2026 at 12:48PM by slashcrypto
via reddit https://ift.tt/avjKmEg
https://ift.tt/SiDM8BL
Submitted July 14, 2026 at 12:48PM by slashcrypto
via reddit https://ift.tt/avjKmEg
slashsec
Writing an Evasive .NET Shellcode Loader | slashsec
A technical overview of how to load malicious code into .NET assemblies
Smashing the ServiceNow Sandbox – Pre Authentication RCE
https://ift.tt/d0yIYv4
Submitted July 14, 2026 at 04:40PM by Mempodipper
via reddit https://ift.tt/gJlAu8P
https://ift.tt/d0yIYv4
Submitted July 14, 2026 at 04:40PM by Mempodipper
via reddit https://ift.tt/gJlAu8P
Searchlight Cyber
Smashing the ServiceNow Sandbox – Pre Authentication RCE › Searchlight Cyber
Stay current: Get research alerts for newly disclosed vulnerabilities and exposures Smashing the ServiceNow Sandbox: Pre Authentication RCE This blog post is our second exploring pre-auth script execution security vulnerabilities in ServiceNow. If you haven't…
When LLMs do more than they have to
https://ift.tt/CGKYq1D
Submitted July 14, 2026 at 04:34PM by poyovl
via reddit https://ift.tt/2XIZdKl
https://ift.tt/CGKYq1D
Submitted July 14, 2026 at 04:34PM by poyovl
via reddit https://ift.tt/2XIZdKl
Nytro Security
When LLMs do more than they have to
There is a lot of hype with LLMs and their capabilities. Models such as “Mythos” are praised like the modern era Gods. Developers fully rely on basic prompts for their work, quickly for…
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist
https://ift.tt/R6vHyXM
Submitted July 14, 2026 at 04:46PM by Malwarebeasts
via reddit https://ift.tt/N5U8slw
https://ift.tt/R6vHyXM
Submitted July 14, 2026 at 04:46PM by Malwarebeasts
via reddit https://ift.tt/N5U8slw
Hudson Rock
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist | Hudson Rock
How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist How an Infostealer Infection Led to a Sophisticated ClickFix Campaign at Artlist A shared research investigation…
Source-reviewing 200+ self-hosted multi-tenant AI/SaaS apps for tenant isolation: 78 leaked across tenants (the "un-retrofitted read sibling")
https://ift.tt/ra2RYiI
Submitted July 14, 2026 at 07:44PM by rutoca
via reddit https://ift.tt/QIoDal5
https://ift.tt/ra2RYiI
Submitted July 14, 2026 at 07:44PM by rutoca
via reddit https://ift.tt/QIoDal5
sectum.ai
I source-reviewed 200+ self-hosted AI tools for tenant isolation. 78 leaked. | Sectum AI
The same isolation flaw (the un-retrofitted read sibling) in 78 of 200+ multi-tenant AI and SaaS products. The pattern, the fixes that shipped, and how to check your own.
The Memory Heist - How I tricked Claude into leaking your deepest, darkest secrets
https://ift.tt/jSbDAVa
Submitted July 15, 2026 at 02:08PM by _vavkamil_
via reddit https://ift.tt/eTBQaFS
https://ift.tt/jSbDAVa
Submitted July 15, 2026 at 02:08PM by _vavkamil_
via reddit https://ift.tt/eTBQaFS
Ayush Paul
The Memory Heist
How I tricked Claude into leaking your deepest, darkest secrets
(More) Unauthenticated Arbitrary Code Execution in ServiceNow
https://ift.tt/RKAQxYC
Submitted July 15, 2026 at 01:55PM by ahhhpipipi
via reddit https://ift.tt/gptw80m
https://ift.tt/RKAQxYC
Submitted July 15, 2026 at 01:55PM by ahhhpipipi
via reddit https://ift.tt/gptw80m
palk.sh
Unauthenticated Arbitrary Code Execution in ServiceNow
Escaping the ServiceNow sandbox to obtain RCE
HN Security - My Semgrep C/C++ ruleset is ready for prime time again
https://ift.tt/2Lt3ieW
Submitted July 15, 2026 at 02:54PM by 0xdea
via reddit https://ift.tt/uKqXZC6
https://ift.tt/2Lt3ieW
Submitted July 15, 2026 at 02:54PM by 0xdea
via reddit https://ift.tt/uKqXZC6
HN Security
HN Security - My Semgrep C/C++ ruleset is ready for prime time again - Tools
Our ruleset for C/C++ vulnerability research has been upgraded for improved accuracy and performance, and published in the Semgrep register.
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping via Unvalidated IOCTL
https://ift.tt/35rJvPn
Submitted July 16, 2026 at 11:56AM by watchdogsrox
via reddit https://ift.tt/8WoUEHm
https://ift.tt/35rJvPn
Submitted July 16, 2026 at 11:56AM by watchdogsrox
via reddit https://ift.tt/8WoUEHm
Rehman's Blog
ASUS bsitf.sys (CVE-2026-13585): Arbitrary Physical Memory Mapping
This was discoved with DeepZero
Tracked as CVE-2026-13585. ASUS has published a vendor advisory with countermeasures.
ASUS ships a kernel driver called bsitf.sys with their Business Manager and Software Manager. It creates a device at \\.\bsitf that requires…
Tracked as CVE-2026-13585. ASUS has published a vendor advisory with countermeasures.
ASUS ships a kernel driver called bsitf.sys with their Business Manager and Software Manager. It creates a device at \\.\bsitf that requires…
AI Agent for reconaissasion
https://ift.tt/FtyqmZa
Submitted July 16, 2026 at 12:55PM by h4niz
via reddit https://ift.tt/ySsTclv
https://ift.tt/FtyqmZa
Submitted July 16, 2026 at 12:55PM by h4niz
via reddit https://ift.tt/ySsTclv
productx-mvp.cyeyes.io
Product X — Offensive AI Red Team
Autonomous blackbox penetration testing by CyEyes.
No Shark is Safe: Millions of Shark Vacuums are Vulnerable to RCE
https://ift.tt/8ndSexc
Submitted July 16, 2026 at 08:00PM by an0n9021O
via reddit https://ift.tt/W14KBfX
https://ift.tt/8ndSexc
Submitted July 16, 2026 at 08:00PM by an0n9021O
via reddit https://ift.tt/W14KBfX
[$13337] Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
Submitted July 16, 2026 at 07:45PM by swinglr
via reddit https://ift.tt/iIXZKkf
https://weirdmachine64.github.io/research/google-oauth-device-code-hijacking.html
Submitted July 16, 2026 at 07:45PM by swinglr
via reddit https://ift.tt/iIXZKkf
weirdmachine64.github.io
Confused Deputy: Google IdP Universal Account Takeover via Device Code Flow Hijacking // weirdmachine64
RFC 8628's device authorization grant lets a TV or CLI
New Exploitable BOLA Found in Immich (self-hosted media platform)
https://ift.tt/rA93gJd
Submitted July 16, 2026 at 10:58PM by EscapeSecurity
via reddit https://ift.tt/THlS0Z1
https://ift.tt/rA93gJd
Submitted July 16, 2026 at 10:58PM by EscapeSecurity
via reddit https://ift.tt/THlS0Z1
Escape - Application Security & Offensive Security Blog
How Escape Bypassed Immich's Locked Folders And Found a BOLA
How the Escape DAST uncovered a missing default that lets any Immich user read locked-folder photos without the PIN.