A real Carnival Cruise Line email was serving customers malware
https://ift.tt/u5LGnyt
Submitted 2026-09-10T23:23:43Z by tuxxin
via reddit https://ift.tt/kVwPtnl
https://ift.tt/u5LGnyt
Submitted 2026-09-10T23:23:43Z by tuxxin
via reddit https://ift.tt/kVwPtnl
Tuxxin
A real Carnival Cruise Line email was serving customers malware
A real Carnival booking confirmation passed SPF, DKIM and DMARC while one link served customers malware. The lapsed domain behind it, and what it delivered.
Autonomous Systems Emissions Index
https://ift.tt/VmESiBc
Submitted 2026-09-11T05:51:32Z by Robbedoes_
via reddit https://ift.tt/GcmRoAt
https://ift.tt/VmESiBc
Submitted 2026-09-11T05:51:32Z by Robbedoes_
via reddit https://ift.tt/GcmRoAt
honeylabs.net
Autonomous Systems Emissions Index | HoneyLabs
Networks ranked by how much they probe the internet relative to the address space they announce. Live from open honeypot telemetry.
CSA Zero Trust Microsegmentation Guidance - formalizes topology-defined vs. connection-defined segmentation models
https://ift.tt/xXOhkME
Submitted 2026-09-11T08:36:58Z by PhilipLGriffiths88
via reddit https://ift.tt/dyhTX6t
https://ift.tt/xXOhkME
Submitted 2026-09-11T08:36:58Z by PhilipLGriffiths88
via reddit https://ift.tt/dyhTX6t
cloudsecurityalliance.org
Zero Trust Microsegmentation Guidance | CSA
A Zero Trust microsegmentation guide, with special consideration for agentic AI security & hybrid IT and OT security. Implement lateral movement prevention.
Read the Bits, Not the Integer: msPKI-Certificate-Name-Flag and the ESC4⤍ESC1 Chain
https://ift.tt/5IAd9pK
Submitted 2026-09-11T09:56:57Z by thesecretmyth
via reddit https://ift.tt/Ip9bgOn
https://ift.tt/5IAd9pK
Submitted 2026-09-11T09:56:57Z by thesecretmyth
via reddit https://ift.tt/Ip9bgOn
Uncontrolled Access Control: Compromising Paxton10
https://ift.tt/hRYlMyI
Submitted 2026-09-11T14:56:06Z by craigsblackie
via reddit https://ift.tt/VEhqldB
https://ift.tt/hRYlMyI
Submitted 2026-09-11T14:56:06Z by craigsblackie
via reddit https://ift.tt/VEhqldB
TechAnarchy
Uncontrolled Access Control: Compromising Paxton10
Paxton10 is an access control system widely deployed across commercial buildings in the UK and Europe. This post documents a chain of vulnerabilities that allows a network-adjacent, unauthenticated attacker to obtain operating system command execution on…
An event bus that never drops the critical stuff: QoS and backpressure in pwnproxy
https://ift.tt/wRxcTSm
Submitted 2026-09-11T19:58:51Z by elguapoRoot
via reddit https://ift.tt/AZitMcV
https://ift.tt/wRxcTSm
Submitted 2026-09-11T19:58:51Z by elguapoRoot
via reddit https://ift.tt/AZitMcV
Nextech Solutions
An event bus that never drops the critical stuff: QoS and backpressure in pwnproxy
How we designed pwnproxy's event bus with bounded per-channel, per-subscriber queues, three QoS classes (CRITICAL with retries, IMPORTANT with coalescing, BEST_EFFORT with drops) and a producer that never blocks.
Beltdown2: Escaping the Cursor CLI sandbox
https://ift.tt/MNUqeYG
Submitted 2026-09-12T15:31:47Z by natcoba
via reddit https://ift.tt/bQcGD05
https://ift.tt/MNUqeYG
Submitted 2026-09-12T15:31:47Z by natcoba
via reddit https://ift.tt/bQcGD05
Accomplish
Beltdown2: Escaping the Cursor CLI sandbox — Accomplish Blog
An attacker-controlled workspace/project folder, containing a .git/ directory, can escape the Cursor CLI's macOS sandbox and run code on your Mac with the logged-in user's full authority, no permission prompt, regardless of tool permission mode. The same…
Magento StyleSmuggler RCE: Report Poisoning to Code Execution
https://ift.tt/LyXWvlI
Submitted 2026-09-12T15:46:30Z by adrian_rt
via reddit https://ift.tt/B6wYXJR
https://ift.tt/LyXWvlI
Submitted 2026-09-12T15:46:30Z by adrian_rt
via reddit https://ift.tt/B6wYXJR
FORTBRIDGE
Magento StyleSmuggler RCE: Report Poisoning to Code Execution
Two unauthenticated requests: poison a Magento failure report, then drive the email template system into the DI compiler that includes it.
Locating Flutter's TLS certificate verifier in a stripped libflutter.so without byte signatures
https://ift.tt/HDQY8bz
Submitted 2026-09-13T04:30:09Z by magixer
via reddit https://ift.tt/qSPC1Ls
https://ift.tt/HDQY8bz
Submitted 2026-09-13T04:30:09Z by magixer
via reddit https://ift.tt/qSPC1Ls
crossfyre.io
Flutter doesn't care what Android trusts
Every interception tool works by editing one Android config file. Flutter has never read that file. Here is how we find the function that actually decides, without a byte signature, and what happened when we ran it against every Flutter app on one phone.
A revisit of remote Spectre attacks on Cloudflare Workers
https://ift.tt/EbeRVHI
Submitted 2026-09-12T08:52:12Z by SunnyBadger66
via reddit https://ift.tt/C1LUwsj
https://ift.tt/EbeRVHI
Submitted 2026-09-12T08:52:12Z by SunnyBadger66
via reddit https://ift.tt/C1LUwsj
Cloudflare Blog
A revisit of remote Spectre attacks on Cloudflare Workers
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers.
If you've seen EchelonGraphBot in your logs, here's exactly what it does and how to block it
https://ift.tt/CWxZLpw
Submitted 2026-09-14T00:14:40Z by Foreign_Score_4021
via reddit https://ift.tt/jXLnQ05
https://ift.tt/CWxZLpw
Submitted 2026-09-14T00:14:40Z by Foreign_Score_4021
via reddit https://ift.tt/jXLnQ05
EchelonGraph
Radar — what the open web answers when we ask politely
Reachability, status, TLS and latency for 7,097 public hosts, measured with one identified, rate-limited request and published with the method and the limits.