Azure's Weakest Link - Five Full Cross-Tenant Compromises
https://ift.tt/k6r4HM1
Submitted October 2, 2026 at 05:45PM by piraterapper
via reddit https://ift.tt/tVhYymq
https://ift.tt/k6r4HM1
Submitted October 2, 2026 at 05:45PM by piraterapper
via reddit https://ift.tt/tVhYymq
Binary Security AS
Azure’s Weakest Link - Five Full Cross-Tenant Compromises
In my previous blog posts, Azure’s Weakest Link? and Azure’s Weakest Link - Full Cross-Tenant Compromise, I gave an overview of the severely insecure architecture behind API Connections in Azure, a part of Azure Logic Apps, and an instance of a full cross…
45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
https://ift.tt/P0dDKqr
Submitted October 2, 2026 at 07:20PM by ricveloso
via reddit https://ift.tt/T4cf6Dj
https://ift.tt/P0dDKqr
Submitted October 2, 2026 at 07:20PM by ricveloso
via reddit https://ift.tt/T4cf6Dj
Grizzlysec
The zero-hour phishing gap
Nearly half the credential-phishing Grizzly catches isn't on Google's blocklist yet. Here's exactly how we measure that.
8 out of 10 Banks HATE This One Weird 3SKey RCE
https://ift.tt/w5WXKqx
Submitted October 2, 2026 at 09:35PM by acorn222
via reddit https://ift.tt/KDWSc9e
https://ift.tt/w5WXKqx
Submitted October 2, 2026 at 09:35PM by acorn222
via reddit https://ift.tt/KDWSc9e
Amibeingpwned
8 out of 10 Banks HATE This One Weird 3SKey RCE
SConnect (1M+ users), the extension and native host used to authenticate with 3SKey, SWIFT, eIDs and other hardware signing tokens, had a drive-by RCE: any site or iframe could silently download and run a DLL by exploiting an uninitialised-memory bypass in…
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
https://ift.tt/vlmoKwM
Submitted October 2, 2026 at 10:20PM by Emergency_Stable_923
via reddit https://ift.tt/fJRQzIt
https://ift.tt/vlmoKwM
Submitted October 2, 2026 at 10:20PM by Emergency_Stable_923
via reddit https://ift.tt/fJRQzIt
security.txt on the Czech web: Scanning 1k popular .cz domains
https://ift.tt/qjxInmk
Submitted October 2, 2026 at 10:22PM by _vavkamil_
via reddit https://ift.tt/R7BtaiU
https://ift.tt/qjxInmk
Submitted October 2, 2026 at 10:22PM by _vavkamil_
via reddit https://ift.tt/R7BtaiU
Kamil Vavra @vavkamil
security.txt on the Czech web: Scanning 1k popular .cz domains
Adding security.txt to the web should be easy. The RFC is fairly simple, and there aren’t many ways to fail. Well, at least I thought that, until now. Let’s look at how a very small standard can fail in surprisingly creative ways.
A peek into Reddit's anti-spam internals
https://lyra.horse/blog/2026/06/reddit-spam-internals/
Submitted October 3, 2026 at 09:30AM by fagnerbrack
via reddit https://ift.tt/Iw6VxG1
https://lyra.horse/blog/2026/06/reddit-spam-internals/
Submitted October 3, 2026 at 09:30AM by fagnerbrack
via reddit https://ift.tt/Iw6VxG1
lyra's epic blog
A peek into Reddit's anti-spam internals
How Reddit accidentally leaked its spamurai system.
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
https://ift.tt/A6W9Tr1
Submitted October 3, 2026 at 12:13PM by pascalschaerli
via reddit https://ift.tt/Cx8BjqO
https://ift.tt/A6W9Tr1
Submitted October 3, 2026 at 12:13PM by pascalschaerli
via reddit https://ift.tt/Cx8BjqO
Pascal Schärli
Post-Quantum Crypto Won't Fix Your Architecture
Adding PQC to this product was like installing a vault door on a tent. The server could intercept your keys and an RCE let attackers run code on your desktop.
Post quantum migration is the thing nobody in SMB is talking about... and timelines make that a problem
https://ift.tt/exF9rso
Submitted October 4, 2026 at 12:48PM by snippipedia
via reddit https://ift.tt/jZKQWsX
https://ift.tt/exF9rso
Submitted October 4, 2026 at 12:48PM by snippipedia
via reddit https://ift.tt/jZKQWsX
Snippipedia
Snippipedia — Cybersecurity & AI
Penetration testing, cloud security, AI red-teaming, and LLM security — built by a Google Cloud security engineer.
How to Hack Time, With C2PA
https://ift.tt/niGhOW7
Submitted October 4, 2026 at 03:42PM by si9int
via reddit https://ift.tt/QXzZBp7
https://ift.tt/niGhOW7
Submitted October 4, 2026 at 03:42PM by si9int
via reddit https://ift.tt/QXzZBp7
Open Build Service, one year later: command execution through Mercurial argument injection
https://ift.tt/Vx0WRoG
Submitted October 5, 2026 at 01:48PM by SzLam__
via reddit https://ift.tt/Rcf7CBP
https://ift.tt/Vx0WRoG
Submitted October 5, 2026 at 01:48PM by SzLam__
via reddit https://ift.tt/Rcf7CBP
Fenrisk
Open Build Service, one year later: command execution through Mercurial argument injection
In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family.…
Wordpress libheif RCE
https://ift.tt/Qp7IP5m
Submitted October 5, 2026 at 03:16PM by adrian_rt
via reddit https://ift.tt/jWYFDu0
https://ift.tt/Qp7IP5m
Submitted October 5, 2026 at 03:16PM by adrian_rt
via reddit https://ift.tt/jWYFDu0
FORTBRIDGE
WordPress libheif RCE
How a WordPress libheif RCE uses returned pixels to bypass ASLR, trigger a heap overflow and execute commands on exact Ubuntu and Debian stacks.
SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
https://ift.tt/ymeN1TE
Submitted October 6, 2026 at 02:24AM by Huge-Skirt-6990
via reddit https://ift.tt/nlFgurj
https://ift.tt/ymeN1TE
Submitted October 6, 2026 at 02:24AM by Huge-Skirt-6990
via reddit https://ift.tt/nlFgurj
malext.io
RedirectorsHub: SelectorsHub Forced-Tab Ad Network - MalExt Sentry
Threat intelligence report: RedirectorsHub: SelectorsHub Forced-Tab Ad Network. Research by MalExt Sentry.
Teaching network intrusion in the funnest way possible
https://ift.tt/PiVj6o3
Submitted October 6, 2026 at 07:27PM by ProjectRedTeam
via reddit https://ift.tt/8BYpGX6
https://ift.tt/PiVj6o3
Submitted October 6, 2026 at 07:27PM by ProjectRedTeam
via reddit https://ift.tt/8BYpGX6
Steampowered
Project RedTeam: Contract Offensive on Steam
A fast paced hacking roguelite built on real cybersecurity tradecraft. Recon targets, steal creds, move laterally, exfiltrate data, and ransom organizations to pay off your "Debts To Be Paid". Over 500 cards and items to discover. High risk, high reward.…
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589) - watchTowr Labs
https://ift.tt/aXb5fm0
Submitted October 6, 2026 at 10:36PM by dx7r__
via reddit https://ift.tt/NHwvXGU
https://ift.tt/aXb5fm0
Submitted October 6, 2026 at 10:36PM by dx7r__
via reddit https://ift.tt/NHwvXGU
watchTowr Labs
You Won’t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)
Welcome back to yet another episode of "security was taken seriously".
Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure…
Being who we are (and constantly being exposed to what we see…), we recognize we have been doomed to eternal damnation as we keep on watching security best practices crumble behind “secure…
Rockstar Games has now been compromised several different ways since 2018, and none of them were a zero-day
https://ift.tt/Od0TKYA
Submitted October 7, 2026 at 01:25AM by lares-hacks
via reddit https://ift.tt/N9piZ1n
https://ift.tt/Od0TKYA
Submitted October 7, 2026 at 01:25AM by lares-hacks
via reddit https://ift.tt/N9piZ1n
Lares
Technical Analysis of the Rockstar Games Compromises: Exploit Chaining and Zero Trust Failures (2018–2026)
What the Rockstar Games security incidents teach defenders about phishing-resistant MFA, SaaS token risk, internal segmentation, and data exfiltration detection.
Bitvulnex: a vulnerable crypto exchange
https://ift.tt/72en0Pj
Submitted October 7, 2026 at 02:59AM by juliocesarfort
via reddit https://ift.tt/ZPBxb9T
https://ift.tt/72en0Pj
Submitted October 7, 2026 at 02:59AM by juliocesarfort
via reddit https://ift.tt/ZPBxb9T
Blazeinfosec
Bitvulnex: a vulnerable crypto exchange | Blaze Labs
Learn crypto exchange security with Bitvulnex, Blaze’s open-source lab featuring 40 planted vulnerabilities, CTF mode, and local Docker installation.