The way AI voice phishing gets demonstrated is making people worse at spotting it
https://ift.tt/IFWCcXH
Submitted July 24, 2026 at 05:42PM by gyanchawdhary
via reddit https://ift.tt/mq2XDfa
https://ift.tt/IFWCcXH
Submitted July 24, 2026 at 05:42PM by gyanchawdhary
via reddit https://ift.tt/mq2XDfa
Callstrike
Free Voice Phishing Simulator | Callstrike
Hear your own voice cloned in real time and understand why your team is vulnerable to vishing.
DEF CON Middle East Postponed
https://ift.tt/SCyEVfr
Submitted July 24, 2026 at 09:11PM by mepper
via reddit https://ift.tt/SO0uR41
https://ift.tt/SCyEVfr
Submitted July 24, 2026 at 09:11PM by mepper
via reddit https://ift.tt/SO0uR41
defcon.org
DEF CON® Hacking Conference - Recent News
Get the latest updates concerning DEF CON and the next DEF CON Conference!
Announcing the External Penetration Testing Program Pack
https://ift.tt/9CaUn6f
Submitted July 24, 2026 at 11:35PM by SecTemplates
via reddit https://ift.tt/2THLkeh
https://ift.tt/9CaUn6f
Submitted July 24, 2026 at 11:35PM by SecTemplates
via reddit https://ift.tt/2THLkeh
What syscall-layer tooling cannot see in P2P infrastructure
https://ift.tt/LflNgc0
Submitted July 25, 2026 at 01:21AM by differentialwidget
via reddit https://ift.tt/2MBcYol
https://ift.tt/LflNgc0
Submitted July 25, 2026 at 01:21AM by differentialwidget
via reddit https://ift.tt/2MBcYol
NullRabbit
What syscall-layer tooling cannot see in P2P infrastructure: a technique-by-technique analysis
If you run Falco, an EDR, or a generic host agent on a validator and a network-DoS attack against the node went undetected, this explains why. A technique-by-technique analysis of five reproduced P2P-infrastructure attacks against the syscall detection surface.…
A featured Chrome extension "Planet Search" (2M installs) routes every query to the nextgeeker[.]com hijacker network
https://ift.tt/YZFdSti
Submitted July 25, 2026 at 03:53PM by Huge-Skirt-6990
via reddit https://ift.tt/b8iFODK
https://ift.tt/YZFdSti
Submitted July 25, 2026 at 03:53PM by Huge-Skirt-6990
via reddit https://ift.tt/b8iFODK
malext.io
RoguePlanet - 2 million installs, one hijacked search bar - MalExt Sentry
Threat intelligence report: RoguePlanet - 2 million installs, one hijacked search bar. Research by MalExt Sentry.
Pentesting vibe-coded applications: JWT flaws, exposed secrets, and broken authorization
https://ift.tt/sV5bj7q
Submitted July 25, 2026 at 07:42PM by Mindless-Study1898
via reddit https://ift.tt/r1FXDVW
https://ift.tt/sV5bj7q
Submitted July 25, 2026 at 07:42PM by Mindless-Study1898
via reddit https://ift.tt/r1FXDVW
Cred Relay
Pentesting Vibe Coded Applications
Practical pentesting notes for vibe-coded apps, covering JWT flaws, exposed secrets, broken authorization, SSRF, and other boundary failures.
Use Protocols, Not Services
https://ift.tt/HFviwnT
Submitted July 26, 2026 at 07:30PM by fagnerbrack
via reddit https://ift.tt/XdouhK3
https://ift.tt/HFviwnT
Submitted July 26, 2026 at 07:30PM by fagnerbrack
via reddit https://ift.tt/XdouhK3
Notnotp
Use Protocols, Not Services
The Internet is almost anonymous and privacy-preserving by design. I mean, unless some administrator actively tries to track you, there is no built-in...
From Google Ads to Terminal: Dissecting an Apple Support Impersonation Campaign Abusing Claude Share.
https://ift.tt/MlyekSW
Submitted July 27, 2026 at 11:55AM by dinkoism
via reddit https://ift.tt/ROo4Qmr
https://ift.tt/MlyekSW
Submitted July 27, 2026 at 11:55AM by dinkoism
via reddit https://ift.tt/ROo4Qmr
Substack
How a fake Claude Code install guide delivered the MacSync malware
A technical analysis of a live Google Ads malvertising campaign abusing Claude AI, Base64-obfuscated shell commands and trusted domains to deliver the MacSync infostealer.
New vBulletin Vulnerability!
https://ift.tt/aPidLqQ
Submitted July 27, 2026 at 07:30PM by SSDisclosure
via reddit https://ift.tt/TFeLBD7
https://ift.tt/aPidLqQ
Submitted July 27, 2026 at 07:30PM by SSDisclosure
via reddit https://ift.tt/TFeLBD7
SSD Secure Disclosure
vBulletin Runtime Template runMaths Preauth RCE - SSD Secure Disclosure
Summary A vulnerability in vBulletin has been identified, the vulnerability allows an unauthenticated user to cause the vBulletin to execute arbitrary code (PHP) on the remote server. Vendor Response The vendor has issued a fix available at: https://foru…
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
https://ift.tt/DFIzOwV
Submitted July 27, 2026 at 08:37PM by EatonZ
via reddit https://ift.tt/lE6Yvto
https://ift.tt/DFIzOwV
Submitted July 27, 2026 at 08:37PM by EatonZ
via reddit https://ift.tt/lE6Yvto
Eaton-Works
Exploiting Volvo/Eicher’s fleet management platform to gain control over all users and vehicles
VE Commercial Vehicles’ My Eicher platform had a critical vulnerability that let you take over anyone’s account and gain control over their vehicle fleets.
BrainDrain: A Chrome extension that collects your AI prompts without you ever opening it and has 100k users, 9 AI platforms
https://ift.tt/y0b7z1L
Submitted July 27, 2026 at 09:59PM by Huge-Skirt-6990
via reddit https://ift.tt/r7YsWDT
https://ift.tt/y0b7z1L
Submitted July 27, 2026 at 09:59PM by Huge-Skirt-6990
via reddit https://ift.tt/r7YsWDT
malext.io
BrainDrain - SecondBrain's Prompt Optimizer Collects Your AI Chats - MalExt Sentry
Threat intelligence report: BrainDrain - SecondBrain's Prompt Optimizer Collects Your AI Chats. Research by MalExt Sentry.
Pollard's P-1 Factoring Algorithm in Plain C
https://ift.tt/gQcU2M3
Submitted July 28, 2026 at 03:24AM by DataBaeBee
via reddit https://ift.tt/Ns1wfbn
https://ift.tt/gQcU2M3
Submitted July 28, 2026 at 03:24AM by DataBaeBee
via reddit https://ift.tt/Ns1wfbn
Substack
Pollard's P-1 Factoring Algorithm in Plain C
Coding Pollard's 1974 Paper on Factoring Within P-1 Multiplicative Subgroups
The state of vibe-coded app security: my analysis of 549 self-described AI-generated repos (study + raw data)
https://ift.tt/QMtyepu
Submitted July 28, 2026 at 04:41PM by obagme
via reddit https://ift.tt/vJ7NCuX
https://ift.tt/QMtyepu
Submitted July 28, 2026 at 04:41PM by obagme
via reddit https://ift.tt/vJ7NCuX
ogbuilds.ai
The state of vibe-coded app security (549 repos) — ogbuilds
The state of vibe-coded app security (549 repos) — first-party research from ogbuilds, based on 549 repos. secure·vibes heuristic rules engine (no AI pass) run over 549 public GitHub repos that describe themselves as AI- or vibe-coded. The original 107-repo…
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
https://ift.tt/ANXwmaF
Submitted July 28, 2026 at 07:01PM by Pale_Fly_2673
via reddit https://ift.tt/BALMbVG
https://ift.tt/ANXwmaF
Submitted July 28, 2026 at 07:01PM by Pale_Fly_2673
via reddit https://ift.tt/BALMbVG
Lava
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
A 20-year-old vulnerability gave us access to bare-metal servers - and a foothold in the no man’s land of data center infrastructure.
Designing Patterns to Prevent IDOR
https://ift.tt/etNIpUS
Submitted July 28, 2026 at 08:09PM by mortensonsam
via reddit https://ift.tt/mU7LFBM
https://ift.tt/etNIpUS
Submitted July 28, 2026 at 08:09PM by mortensonsam
via reddit https://ift.tt/mU7LFBM
Sevhunt
Designing Patterns to Prevent IDOR | SevHunt
Even in modern web apps, IDOR bugs are treated as one-off findings. What if we designed patterns that made introducing IDOR impossible?
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)
https://ift.tt/gAZmdy4
Submitted July 28, 2026 at 07:34PM by MobetaSec
via reddit https://ift.tt/NU0WMuT
https://ift.tt/gAZmdy4
Submitted July 28, 2026 at 07:34PM by MobetaSec
via reddit https://ift.tt/NU0WMuT
Mobeta
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) | Mobeta
PoC for CVE-2024-1813: unauthenticated PHP object injection in Simple Job Board ≤ 2.11.0, chained to RCE via AIOSEO/Monolog.
Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs
https://ift.tt/BqvoDEd
Submitted July 28, 2026 at 11:15PM by Straight-Practice-99
via reddit https://ift.tt/ZYjszW3
https://ift.tt/BqvoDEd
Submitted July 28, 2026 at 11:15PM by Straight-Practice-99
via reddit https://ift.tt/ZYjszW3
hunt.io
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
How AI is powering business email compromise at scale
https://ift.tt/lJnkgNA
Submitted July 28, 2026 at 07:01PM by eyesec_research
via reddit https://ift.tt/qKuLlk5
https://ift.tt/lJnkgNA
Submitted July 28, 2026 at 07:01PM by eyesec_research
via reddit https://ift.tt/qKuLlk5
Eye Research
AI-powered Phishing-as-a-Service: Inside Two BEC Kits
A look at two undocumented, AI-built phishing kits that automate the full business email compromise chain: device code phishing, token theft, persistence, and AI-driven invoice fraud.
Claude Mythos degrades HAWK and developed new exploit for round-reduced AES
https://ift.tt/G0HtiPl
Submitted July 29, 2026 at 01:23AM by Soundwave_47
via reddit https://ift.tt/cd4sDpn
https://ift.tt/G0HtiPl
Submitted July 29, 2026 at 01:23AM by Soundwave_47
via reddit https://ift.tt/cd4sDpn
Anthropic
Discovering cryptographic weaknesses with Claude
Anthropic researchers find weaknesses in cryptographic algorithms with Claude Mythos Preview
Hush Security raises $30 million to govern enterprise AI agents
https://ift.tt/DsgZX3n
Submitted July 29, 2026 at 01:13AM by ryanmerket
via reddit https://ift.tt/UE1Jefu
https://ift.tt/DsgZX3n
Submitted July 29, 2026 at 01:13AM by ryanmerket
via reddit https://ift.tt/UE1Jefu
RuntimeWire
Hush Security raises $30 million to govern enterprise AI agents
Hush Security raised a $30 million Series A from Akamai, Battery Ventures and YL Ventures to expand its runtime identity and access platform for AI agents.
HTTP Request Smuggling in Hiawatha
https://ift.tt/G5Kirly
Submitted July 29, 2026 at 05:59PM by SzLam__
via reddit https://ift.tt/nSiC12E
https://ift.tt/G5Kirly
Submitted July 29, 2026 at 05:59PM by SzLam__
via reddit https://ift.tt/nSiC12E
Fenrisk
HTTP Request Smuggling in Hiawatha - CVE-2026-51785
Security experts