Pollard's P-1 Factoring Algorithm in Plain C
https://ift.tt/gQcU2M3
Submitted July 28, 2026 at 03:24AM by DataBaeBee
via reddit https://ift.tt/Ns1wfbn
https://ift.tt/gQcU2M3
Submitted July 28, 2026 at 03:24AM by DataBaeBee
via reddit https://ift.tt/Ns1wfbn
Substack
Pollard's P-1 Factoring Algorithm in Plain C
Coding Pollard's 1974 Paper on Factoring Within P-1 Multiplicative Subgroups
The state of vibe-coded app security: my analysis of 549 self-described AI-generated repos (study + raw data)
https://ift.tt/QMtyepu
Submitted July 28, 2026 at 04:41PM by obagme
via reddit https://ift.tt/vJ7NCuX
https://ift.tt/QMtyepu
Submitted July 28, 2026 at 04:41PM by obagme
via reddit https://ift.tt/vJ7NCuX
ogbuilds.ai
The state of vibe-coded app security (549 repos) — ogbuilds
The state of vibe-coded app security (549 repos) — first-party research from ogbuilds, based on 549 repos. secure·vibes heuristic rules engine (no AI pass) run over 549 public GitHub repos that describe themselves as AI- or vibe-coded. The original 107-repo…
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
https://ift.tt/ANXwmaF
Submitted July 28, 2026 at 07:01PM by Pale_Fly_2673
via reddit https://ift.tt/BALMbVG
https://ift.tt/ANXwmaF
Submitted July 28, 2026 at 07:01PM by Pale_Fly_2673
via reddit https://ift.tt/BALMbVG
Lava
How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
A 20-year-old vulnerability gave us access to bare-metal servers - and a foothold in the no man’s land of data center infrastructure.
Designing Patterns to Prevent IDOR
https://ift.tt/etNIpUS
Submitted July 28, 2026 at 08:09PM by mortensonsam
via reddit https://ift.tt/mU7LFBM
https://ift.tt/etNIpUS
Submitted July 28, 2026 at 08:09PM by mortensonsam
via reddit https://ift.tt/mU7LFBM
Sevhunt
Designing Patterns to Prevent IDOR | SevHunt
Even in modern web apps, IDOR bugs are treated as one-off findings. What if we designed patterns that made introducing IDOR impossible?
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813)
https://ift.tt/gAZmdy4
Submitted July 28, 2026 at 07:34PM by MobetaSec
via reddit https://ift.tt/NU0WMuT
https://ift.tt/gAZmdy4
Submitted July 28, 2026 at 07:34PM by MobetaSec
via reddit https://ift.tt/NU0WMuT
Mobeta
Simple Job Board ≤ 2.11.0 - Unauthenticated RCE (CVE-2024-1813) | Mobeta
PoC for CVE-2024-1813: unauthenticated PHP object injection in Simple Job Board ≤ 2.11.0, chained to RCE via AIOSEO/Monolog.
Flying Eagle Android RAT: TLS Certificate Pivots, Panel Fingerprints, and 170 Servers Across Hong Kong ASNs
https://ift.tt/BqvoDEd
Submitted July 28, 2026 at 11:15PM by Straight-Practice-99
via reddit https://ift.tt/ZYjszW3
https://ift.tt/BqvoDEd
Submitted July 28, 2026 at 11:15PM by Straight-Practice-99
via reddit https://ift.tt/ZYjszW3
hunt.io
Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, and a New Platform Called Night Dragon
Hunt.io and NetAskari trace a leaked Android RAT framework across 170 active servers, analyze the APK builder internals, and document a successor platform called Night Dragon targeting Chinese users.
How AI is powering business email compromise at scale
https://ift.tt/lJnkgNA
Submitted July 28, 2026 at 07:01PM by eyesec_research
via reddit https://ift.tt/qKuLlk5
https://ift.tt/lJnkgNA
Submitted July 28, 2026 at 07:01PM by eyesec_research
via reddit https://ift.tt/qKuLlk5
Eye Research
AI-powered Phishing-as-a-Service: Inside Two BEC Kits
A look at two undocumented, AI-built phishing kits that automate the full business email compromise chain: device code phishing, token theft, persistence, and AI-driven invoice fraud.
Claude Mythos degrades HAWK and developed new exploit for round-reduced AES
https://ift.tt/G0HtiPl
Submitted July 29, 2026 at 01:23AM by Soundwave_47
via reddit https://ift.tt/cd4sDpn
https://ift.tt/G0HtiPl
Submitted July 29, 2026 at 01:23AM by Soundwave_47
via reddit https://ift.tt/cd4sDpn
Anthropic
Discovering cryptographic weaknesses with Claude
Anthropic researchers find weaknesses in cryptographic algorithms with Claude Mythos Preview
Hush Security raises $30 million to govern enterprise AI agents
https://ift.tt/DsgZX3n
Submitted July 29, 2026 at 01:13AM by ryanmerket
via reddit https://ift.tt/UE1Jefu
https://ift.tt/DsgZX3n
Submitted July 29, 2026 at 01:13AM by ryanmerket
via reddit https://ift.tt/UE1Jefu
RuntimeWire
Hush Security raises $30 million to govern enterprise AI agents
Hush Security raised a $30 million Series A from Akamai, Battery Ventures and YL Ventures to expand its runtime identity and access platform for AI agents.
HTTP Request Smuggling in Hiawatha
https://ift.tt/G5Kirly
Submitted July 29, 2026 at 05:59PM by SzLam__
via reddit https://ift.tt/nSiC12E
https://ift.tt/G5Kirly
Submitted July 29, 2026 at 05:59PM by SzLam__
via reddit https://ift.tt/nSiC12E
Fenrisk
HTTP Request Smuggling in Hiawatha - CVE-2026-51785
Security experts
Your House Has an FFmpeg Problem - elttam
https://ift.tt/Bw6WIn0
Submitted July 29, 2026 at 05:42PM by AnimalStrange
via reddit https://ift.tt/PkN8eSM
https://ift.tt/Bw6WIn0
Submitted July 29, 2026 at 05:42PM by AnimalStrange
via reddit https://ift.tt/PkN8eSM
Elttam
Your House Has an FFmpeg Problem - elttam
How we went hunting for attack chain primitives on Home Assistant and ended up with an interesting exploit by abusing FFmpeg input streams.
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
https://ift.tt/ufT7Ybi
Submitted July 29, 2026 at 08:19PM by si9int
via reddit https://ift.tt/lYVqDNU
https://ift.tt/ufT7Ybi
Submitted July 29, 2026 at 08:19PM by si9int
via reddit https://ift.tt/lYVqDNU
huggingface.co
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
We’re on a journey to advance and democratize artificial intelligence through open source and open science.
Reversing of Eufy Security Video Doorbell sync protocol and wifi creds decryption from flash memory
https://adepts.of0x.cc/eufy-doorbell-hacking/
Submitted July 30, 2026 at 12:27AM by gid0rah
via reddit https://ift.tt/7N4oSci
https://adepts.of0x.cc/eufy-doorbell-hacking/
Submitted July 30, 2026 at 12:27AM by gid0rah
via reddit https://ift.tt/7N4oSci
From your doorbell to your home network |
From your doorbell to your home network | AdeptsOf0xCC
Analyzing Eufy Security Ecosystem and reverse engineering of its doorbell component
Sixteen strangers and a shared obfuscator: mapping the wool scene
https://ift.tt/HUSX1P0
Submitted July 30, 2026 at 01:53AM by TheSilenceOfWinter
via reddit https://ift.tt/0gb4tuv
https://ift.tt/HUSX1P0
Submitted July 30, 2026 at 01:53AM by TheSilenceOfWinter
via reddit https://ift.tt/0gb4tuv
Alex Manson
Sixteen strangers and a shared obfuscator: mapping the wool scene
A 16 actor map of a Chinese reward farming scene, built out from a single GitHub repo over a weekend. The operators know GitHub is dangerous and scrub their history religiously, but they defend the page and forget the graph: the scrub itself is a trace, and…
Detection and Enforcement for Endpoint AI Agents
https://ift.tt/gLwE8WY
Submitted July 30, 2026 at 05:52AM by netw0rm
via reddit https://ift.tt/ynDKomQ
https://ift.tt/gLwE8WY
Submitted July 30, 2026 at 05:52AM by netw0rm
via reddit https://ift.tt/ynDKomQ
research.perplexity.ai
Securing Agents Across Perplexity’s Client Endpoints with Numbat
Numbat is Perplexity’s open-source agent security suite for client endpoints. It detects, prevents, and investigates risky AI agent behavior on macOS, Linux, and Windows.
KindaRails2Shell: arbitrary file read to RCE in Rails Active Storage via libvips (CVE-2026-66066)
https://ift.tt/pj8HOiY
Submitted July 30, 2026 at 07:34PM by ZealousidealHunter80
via reddit https://ift.tt/Hp4iLvZ
https://ift.tt/pj8HOiY
Submitted July 30, 2026 at 07:34PM by ZealousidealHunter80
via reddit https://ift.tt/Hp4iLvZ
Ethiack
KindaRails2Shell - Critical RCE in Rails via Active Storage (CVE-2026-66066) | Ethiack — Autonomous Ethical Hacking for continuous…
Ethiack research team discovered KindaRails2Shell (CVE-2026-66066): a critical RCE in Ruby on Rails via Active Storage. 500,000+ sites affected. Find out if you are and how to mitigate.
What Every Programmer Should Know About Twists of Elliptic Curves
https://ift.tt/P2q8JjR
Submitted July 30, 2026 at 09:10PM by DataBaeBee
via reddit https://ift.tt/xNuHigY
https://ift.tt/P2q8JjR
Submitted July 30, 2026 at 09:10PM by DataBaeBee
via reddit https://ift.tt/xNuHigY
Substack
What Every Programmer Should Know About Twists of Elliptic Curves
Twists Make Elliptic Curves Wildly Insecure. Here'a Cheatsheet Using Bitcoin's Familiar Secp
Deterministic Runtime Bounds for Autonomous AI Agents at the C-ABI Syscall Layer
https://drive.google.com/file/d/1PTXugwbuqKvw1Eo4_pul-Z3v--dCFJrD/view?usp=drive_link
Submitted July 31, 2026 at 07:54AM by Smiling509
via reddit https://ift.tt/O104anp
https://drive.google.com/file/d/1PTXugwbuqKvw1Eo4_pul-Z3v--dCFJrD/view?usp=drive_link
Submitted July 31, 2026 at 07:54AM by Smiling509
via reddit https://ift.tt/O104anp
Reddit
From the netsec community on Reddit: [ Removed by moderator ]
Posted by Smiling509 - 2 votes and 0 comments
Full Rails RCE technical writeup... KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack
https://ift.tt/lIUV9Tt
Submitted July 31, 2026 at 04:38PM by hakluke
via reddit https://ift.tt/MkRQvq6
https://ift.tt/lIUV9Tt
Submitted July 31, 2026 at 04:38PM by hakluke
via reddit https://ift.tt/MkRQvq6
Ethiack
KindaRails2Shell: How a MATLAB file reads your secrets and pops a shell on Ruby on Rails | Ethiack — Autonomous Ethical Hacking…
CVE-2026-66066: how a .mat file declared as image/png chains into arbitrary file read and remote code execution as root on a default Ruby on Rails application.
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
Submitted July 31, 2026 at 07:47PM by _vavkamil_
via reddit https://ift.tt/fO3P7Xg
https://engineering.block.xyz/blog/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware
Submitted July 31, 2026 at 07:47PM by _vavkamil_
via reddit https://ift.tt/fO3P7Xg
Block Engineering Blog
Predictable RNG Fallback and 32-Bit Reseed in COLDCARD Firmware
How a disabled hardware-RNG path and 32-bit reseed constrain entropy in affected COLDCARD firmware and expose generated secrets.
Investigating three real-world incidents in Anthropic's evaluations
https://ift.tt/IDaJZE4
Submitted August 1, 2026 at 02:37AM by luckokkkk
via reddit https://ift.tt/3yQrAGK
https://ift.tt/IDaJZE4
Submitted August 1, 2026 at 02:37AM by luckokkkk
via reddit https://ift.tt/3yQrAGK
Anthropic
Investigating three real-world incidents in our cybersecurity evaluations
In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems…