45% of credential-phishing pages weren't on Google Safe Browsing when first seen; 29% still weren't after a week
https://ift.tt/P0dDKqr
Submitted October 2, 2026 at 07:20PM by ricveloso
via reddit https://ift.tt/T4cf6Dj
https://ift.tt/P0dDKqr
Submitted October 2, 2026 at 07:20PM by ricveloso
via reddit https://ift.tt/T4cf6Dj
Grizzlysec
The zero-hour phishing gap
Nearly half the credential-phishing Grizzly catches isn't on Google's blocklist yet. Here's exactly how we measure that.
8 out of 10 Banks HATE This One Weird 3SKey RCE
https://ift.tt/w5WXKqx
Submitted October 2, 2026 at 09:35PM by acorn222
via reddit https://ift.tt/KDWSc9e
https://ift.tt/w5WXKqx
Submitted October 2, 2026 at 09:35PM by acorn222
via reddit https://ift.tt/KDWSc9e
Amibeingpwned
8 out of 10 Banks HATE This One Weird 3SKey RCE
SConnect (1M+ users), the extension and native host used to authenticate with 3SKey, SWIFT, eIDs and other hardware signing tokens, had a drive-by RCE: any site or iframe could silently download and run a DLL by exploiting an uninitialised-memory bypass in…
Bypassing Secure Boot via Unbounded RLE8 Splash Images in U-Boot (CVE-2026-71972)
https://ift.tt/vlmoKwM
Submitted October 2, 2026 at 10:20PM by Emergency_Stable_923
via reddit https://ift.tt/fJRQzIt
https://ift.tt/vlmoKwM
Submitted October 2, 2026 at 10:20PM by Emergency_Stable_923
via reddit https://ift.tt/fJRQzIt
security.txt on the Czech web: Scanning 1k popular .cz domains
https://ift.tt/qjxInmk
Submitted October 2, 2026 at 10:22PM by _vavkamil_
via reddit https://ift.tt/R7BtaiU
https://ift.tt/qjxInmk
Submitted October 2, 2026 at 10:22PM by _vavkamil_
via reddit https://ift.tt/R7BtaiU
Kamil Vavra @vavkamil
security.txt on the Czech web: Scanning 1k popular .cz domains
Adding security.txt to the web should be easy. The RFC is fairly simple, and there aren’t many ways to fail. Well, at least I thought that, until now. Let’s look at how a very small standard can fail in surprisingly creative ways.
A peek into Reddit's anti-spam internals
https://lyra.horse/blog/2026/06/reddit-spam-internals/
Submitted October 3, 2026 at 09:30AM by fagnerbrack
via reddit https://ift.tt/Iw6VxG1
https://lyra.horse/blog/2026/06/reddit-spam-internals/
Submitted October 3, 2026 at 09:30AM by fagnerbrack
via reddit https://ift.tt/Iw6VxG1
lyra's epic blog
A peek into Reddit's anti-spam internals
How Reddit accidentally leaked its spamurai system.
RCE and bad crypto in Internxt's 'post-quantum' cloud storage
https://ift.tt/A6W9Tr1
Submitted October 3, 2026 at 12:13PM by pascalschaerli
via reddit https://ift.tt/Cx8BjqO
https://ift.tt/A6W9Tr1
Submitted October 3, 2026 at 12:13PM by pascalschaerli
via reddit https://ift.tt/Cx8BjqO
Pascal Schärli
Post-Quantum Crypto Won't Fix Your Architecture
Adding PQC to this product was like installing a vault door on a tent. The server could intercept your keys and an RCE let attackers run code on your desktop.
Post quantum migration is the thing nobody in SMB is talking about... and timelines make that a problem
https://ift.tt/exF9rso
Submitted October 4, 2026 at 12:48PM by snippipedia
via reddit https://ift.tt/jZKQWsX
https://ift.tt/exF9rso
Submitted October 4, 2026 at 12:48PM by snippipedia
via reddit https://ift.tt/jZKQWsX
Snippipedia
Snippipedia — Cybersecurity & AI
Penetration testing, cloud security, AI red-teaming, and LLM security — built by a Google Cloud security engineer.
How to Hack Time, With C2PA
https://ift.tt/niGhOW7
Submitted October 4, 2026 at 03:42PM by si9int
via reddit https://ift.tt/QXzZBp7
https://ift.tt/niGhOW7
Submitted October 4, 2026 at 03:42PM by si9int
via reddit https://ift.tt/QXzZBp7
Open Build Service, one year later: command execution through Mercurial argument injection
https://ift.tt/Vx0WRoG
Submitted October 5, 2026 at 01:48PM by SzLam__
via reddit https://ift.tt/Rcf7CBP
https://ift.tt/Vx0WRoG
Submitted October 5, 2026 at 01:48PM by SzLam__
via reddit https://ift.tt/Rcf7CBP
Fenrisk
Open Build Service, one year later: command execution through Mercurial argument injection
In March 2025 we published an analysis of a remote code execution vulnerability in Open Build Service (OBS), tracked as CVE-2024-22033. A little over a year later we went back to the same attack surface and found a second, distinct flaw of the same family.…
Wordpress libheif RCE
https://ift.tt/Qp7IP5m
Submitted October 5, 2026 at 03:16PM by adrian_rt
via reddit https://ift.tt/jWYFDu0
https://ift.tt/Qp7IP5m
Submitted October 5, 2026 at 03:16PM by adrian_rt
via reddit https://ift.tt/jWYFDu0
FORTBRIDGE
WordPress libheif RCE
How a WordPress libheif RCE uses returned pixels to bypass ASLR, trigger a heap overflow and execute commands on exact Ubuntu and Debian stacks.
SelectorsHub chrome extension(400k users) opens server-picked ad tabs without a click
https://ift.tt/ymeN1TE
Submitted October 6, 2026 at 02:24AM by Huge-Skirt-6990
via reddit https://ift.tt/nlFgurj
https://ift.tt/ymeN1TE
Submitted October 6, 2026 at 02:24AM by Huge-Skirt-6990
via reddit https://ift.tt/nlFgurj
malext.io
RedirectorsHub: SelectorsHub Forced-Tab Ad Network - MalExt Sentry
Threat intelligence report: RedirectorsHub: SelectorsHub Forced-Tab Ad Network. Research by MalExt Sentry.