8 Million Users' AI Conversations Sold for Profit by "Privacy" Extensions #AIPrivacyBreach #BrowserExtensionScam #UrbanVPNSurveillance #DataBrokerage #GoogleEndorsementFail https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection
www.koi.ai
8 Million Users' AI Conversations Sold for Profit by "Privacy" Extensions
Privacy browser extensions misled users and sold 8 million AI chat logs, exposing sensitive conversations for profit without consent.
Attempting Cross Translation Unit Taint Analysis for Firefox #FirefoxSecurity #StaticAnalysis #TaintAnalysis #CTUAnalysis #ClangLimitations https://attackanddefense.dev/2025/12/16/attempting-cross-translation-unit-static-analysis.html
Attack & Defense
Attempting Cross Translation Unit Taint Analysis for Firefox
Preface
GeminiJack Challenge — Prompt Injection Challenge #GeminiJack #PromptInjection #RAGExploitation #LLMSecurity #DataExfiltration https://geminijack.securelayer7.net/
TruffleHog now detects JWTs with public-key signatures and verifies them for liveness #TruffleHog #JWTs #LiveVerification #SecretScanning #PublicKeySecurity https://trufflesecurity.com/blog/trufflehog-now-detects-jwts-with-public-key-signatures-and-verifies-them-for-liveness
Trufflesecurity
TruffleHog now detects JWTs with public-key signatures and verifies them for liveness ◆ Truffle Security Co.
TruffleHog now detects JWTs signed with public-key cryptography and verifies them for liveness. This new detector has already found hundreds of live JWTs for our customers.
Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI-25-097, ZDI-25-096) #PostHog #RCEChain #SSRF #SQLInjection #Zeroday https://mehmetince.net/inside-posthog-how-ssrf-a-clickhouse-sql-escaping-0day-and-default-postgresql-credentials-formed-an-rce-chain-zdi-25-099-zdi-25-097-zdi-25-096/
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
Inside PostHog: How SSRF, a ClickHouse SQL Escaping 0day, and Default PostgreSQL Credentials Formed an RCE Chain (ZDI-25-099, ZDI…
It was yet another day at the office. Our team was internally discussing moving to a different platform analytics solution. Our team was really leaning more towards Posthog. It’s one of the brilliant -I personally believe it’s the best- products on the market.…
AI Model Safety: Emerging Threats Assessment #EmergingThreats #ThreatAssessment #2025Outlook #Cybersecurity #AIInsights https://24882480.fs1.hubspotusercontent-eu1.net/hubfs/24882480/Emerging%20Threats%20Risk%20Assessment%202025.pdf
JUMPSHOT: XM Cyber Uncovers Critical Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent https://xmcyber.com/blog/jumpshot-xm-cyber-uncovers-critical-local-privilege-escalation-cve-2025-34352-in-jumpcloud-agent/
XM Cyber
JUMPSHOT: XM Cyber Uncovers Critical Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent | XM Cyber
Learn more about JUMPSHOT: XM Cyber Uncovers Critical Local Privilege Escalation (CVE-2025-34352) in JumpCloud Agent . Read more on XM Cyber website.
Linearity of SHA-256 and Chaotic Systems
in Self-Defined Dimensions https://osf.io/6yrw8/files/wj9ze
in Self-Defined Dimensions https://osf.io/6yrw8/files/wj9ze
🤪1
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack #Vulnhalla #LLMSecurity #CodeQL #VulnerabilityResearch #FalsePositiveReduction https://www.cyberark.com/resources/threat-research-blog/vulnhalla-picking-the-true-vulnerabilities-from-the-codeql-haystack
Cyberark
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
In this blog post, we present our approach for uncovering vulnerabilities by combining LLM reasoning with static analysis. By layering an LLM on top of CodeQL, we significantly reduce the...
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack #SupplyChainAttack #XSS #Mintlify #CorporateSecurity #BugBounty https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Gist
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack - writeup.md
👍1
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 #AIAgentSecurity #OAuthFlaw #CVE20256514 #TrustInversion #CapabilityBasedAuth https://amlalabs.com/blog/oauth-cve-2025-6514/
Amla Labs
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs
A critical vulnerability in mcp-remote affected 558,846 downloads. The bug was client-side, but the attack exploited OAuth dynamic discovery—a trust assumption that breaks for autonomous agents.
Microsoft Brokering File System Elevation of Privilege Vulnerability #MicrosoftBFS #UseAfterFree #ElevationOfPrivilege #KernelVulnerability #CVE202529970 https://www.pixiepointsecurity.com/blog/nday-cve-2025-29970/
PixiePoint Security
Microsoft Brokering File System Elevation of Privilege Vulnerability | PixiePoint Security
About 2 years ago, Microsoft first released Win32-App-isolation which is a sandbox-like mechanism to further separate application access to resources on Windows clients. Brokering File System (BFS) was released around the same time to specifically …
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets #RustBotnet #ReverseEngineering #C2Honeypot #DockerExploit #DDoSMalware https://beelzebub.ai/blog/rust-ddos-botnet-honeypot-c2-decoding/
Beelzebub
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets | AI-Native security platform
AI-Native security platform: Deceive, Detect, Respond. “We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source framework, deceive attackers during lateral movement within the network. While intruders interact…
mediatek? more like media-rekt, amirite. #MediaTekRekt #WiFiVulnerabilities #KernelExploits #VendorDisclosure #CyberSecurity https://blog.coffinsec.com/0days/2025/12/15/more-like-mediarekt-amirite.html
hyprblog
mediatek? more like media-REKT, amirite.
A year-in-review going over 19+ bugs in Mediatek’s MT76xx/MT7915 (and others) wifi chipsets I reported this year, PoCs included!
Detecting Vision-Based AI Agents: Operator and Beyond #VisionAIAgents #BotDetection #BehavioralAnalysis #TimingSignatures #PixelPrecision https://webdecoy.com/blog/detecting-vision-based-ai-agents-operator-computer-use/
Webdecoy
Detecting Vision-Based AI Agents: Operator and Beyond - WebDecoy
Detect Claude Computer Use and OpenAI Operator through timing analysis, cursor patterns, and prompt
Dissecting a Multi-Stage macOS Infostealer #MacSyncStealer #macOSMalware #Infostealer #MalwareAnalysis #GatekeeperBypass https://blog.threatuniverse.co.uk/posts/usersyncworker-macos-infostealer/
Rhys Downing
Dissecting a Multi-Stage macOS Infostealer
Deep dive into MacSync Stealer (UserSyncWorker variant), a MaaS infostealer featuring Gatekeeper bypass via notarized Swift dropper, code signature validation, and multi-layer payload obfuscation
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction #OSF #OpenSource #Software #Foundation #Technology https://osf.io/jd392/overview
OSF
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction
This paper presents a groundbreaking cryptanalytic framework for the SHA-256 hash function. By mapping the 2^32 modular addition space into a fractional domain [0, 1), I demonstrate that the non-linear "noise" generated by modular overflows is not random…
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks #UEFIFlaw #DMAAttacks #MotherboardSecurity #IOMMUvulnerability #EarlyBootAttacks https://www.nexaspecs.com/2025/12/critical-uefi-flaw-exposes-motherboards.html
NexasPecs
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks
Explore our extensive archive of in-depth tech reviews, scientific breakthroughs, and cybersecurity analysis. Find the specs, facts, and expert insig
😡2
When WebSockets Lead to RCE in CurseForge #CurseForge #RCE #WebSocket #Vulnerability #Cybersecurity https://elliott.diy/blog/curseforge/
elliott.diy
When WebSockets Lead to RCE in CurseForge
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
CSRF Protection without Tokens or Hidden Form Fields #CSRFProtection #FetchMetadata #WebSecurity #Microdot #OWASP https://blog.miguelgrinberg.com/post/csrf-protection-without-tokens-or-hidden-form-fields
Miguelgrinberg
CSRF Protection without Tokens or Hidden Form Fields
A couple of months ago, I received a request from a random Internet user to add CSRF protection to my little web framework Microdot, and I thought it was a fantastic idea.When I set off to do this…