Linearity of SHA-256 and Chaotic Systems
in Self-Defined Dimensions https://osf.io/6yrw8/files/wj9ze
in Self-Defined Dimensions https://osf.io/6yrw8/files/wj9ze
🤪1
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack #Vulnhalla #LLMSecurity #CodeQL #VulnerabilityResearch #FalsePositiveReduction https://www.cyberark.com/resources/threat-research-blog/vulnhalla-picking-the-true-vulnerabilities-from-the-codeql-haystack
Cyberark
Vulnhalla: Picking the true vulnerabilities from the CodeQL haystack
In this blog post, we present our approach for uncovering vulnerabilities by combining LLM reasoning with static analysis. By layering an LLM on top of CodeQL, we significantly reduce the...
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack #SupplyChainAttack #XSS #Mintlify #CorporateSecurity #BugBounty https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Gist
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack - writeup.md
👍1
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 #AIAgentSecurity #OAuthFlaw #CVE20256514 #TrustInversion #CapabilityBasedAuth https://amlalabs.com/blog/oauth-cve-2025-6514/
Amla Labs
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs
A critical vulnerability in mcp-remote affected 558,846 downloads. The bug was client-side, but the attack exploited OAuth dynamic discovery—a trust assumption that breaks for autonomous agents.
Microsoft Brokering File System Elevation of Privilege Vulnerability #MicrosoftBFS #UseAfterFree #ElevationOfPrivilege #KernelVulnerability #CVE202529970 https://www.pixiepointsecurity.com/blog/nday-cve-2025-29970/
PixiePoint Security
Microsoft Brokering File System Elevation of Privilege Vulnerability | PixiePoint Security
About 2 years ago, Microsoft first released Win32-App-isolation which is a sandbox-like mechanism to further separate application access to resources on Windows clients. Brokering File System (BFS) was released around the same time to specifically …
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets #RustBotnet #ReverseEngineering #C2Honeypot #DockerExploit #DDoSMalware https://beelzebub.ai/blog/rust-ddos-botnet-honeypot-c2-decoding/
Beelzebub
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets | AI-Native security platform
AI-Native security platform: Deceive, Detect, Respond. “We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source framework, deceive attackers during lateral movement within the network. While intruders interact…
mediatek? more like media-rekt, amirite. #MediaTekRekt #WiFiVulnerabilities #KernelExploits #VendorDisclosure #CyberSecurity https://blog.coffinsec.com/0days/2025/12/15/more-like-mediarekt-amirite.html
hyprblog
mediatek? more like media-REKT, amirite.
A year-in-review going over 19+ bugs in Mediatek’s MT76xx/MT7915 (and others) wifi chipsets I reported this year, PoCs included!
Detecting Vision-Based AI Agents: Operator and Beyond #VisionAIAgents #BotDetection #BehavioralAnalysis #TimingSignatures #PixelPrecision https://webdecoy.com/blog/detecting-vision-based-ai-agents-operator-computer-use/
Webdecoy
Detecting Vision-Based AI Agents: Operator and Beyond - WebDecoy
Detect Claude Computer Use and OpenAI Operator through timing analysis, cursor patterns, and prompt
Dissecting a Multi-Stage macOS Infostealer #MacSyncStealer #macOSMalware #Infostealer #MalwareAnalysis #GatekeeperBypass https://blog.threatuniverse.co.uk/posts/usersyncworker-macos-infostealer/
Rhys Downing
Dissecting a Multi-Stage macOS Infostealer
Deep dive into MacSync Stealer (UserSyncWorker variant), a MaaS infostealer featuring Gatekeeper bypass via notarized Swift dropper, code signature validation, and multi-layer payload obfuscation
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction #OSF #OpenSource #Software #Foundation #Technology https://osf.io/jd392/overview
OSF
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction
This paper presents a groundbreaking cryptanalytic framework for the SHA-256 hash function. By mapping the 2^32 modular addition space into a fractional domain [0, 1), I demonstrate that the non-linear "noise" generated by modular overflows is not random…
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks #UEFIFlaw #DMAAttacks #MotherboardSecurity #IOMMUvulnerability #EarlyBootAttacks https://www.nexaspecs.com/2025/12/critical-uefi-flaw-exposes-motherboards.html
NexasPecs
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks
Explore our extensive archive of in-depth tech reviews, scientific breakthroughs, and cybersecurity analysis. Find the specs, facts, and expert insig
😡2
When WebSockets Lead to RCE in CurseForge #CurseForge #RCE #WebSocket #Vulnerability #Cybersecurity https://elliott.diy/blog/curseforge/
elliott.diy
When WebSockets Lead to RCE in CurseForge
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
CSRF Protection without Tokens or Hidden Form Fields #CSRFProtection #FetchMetadata #WebSecurity #Microdot #OWASP https://blog.miguelgrinberg.com/post/csrf-protection-without-tokens-or-hidden-form-fields
Miguelgrinberg
CSRF Protection without Tokens or Hidden Form Fields
A couple of months ago, I received a request from a random Internet user to add CSRF protection to my little web framework Microdot, and I thought it was a fantastic idea.When I set off to do this…
Jupyter Notebook for testing collisions on SHA-256 https://osf.io/2gdzq/files/dqghk
OSF
FIRST_REAL_COLISION_SHA_256_ENGLISH.ipynb
💩3🤡1
Merry Christmas Day! Have a MongoDB security incident. https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb
Medium
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks https://bobdahacker.com/blog/petlibro
Bobdahacker
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - and how they're still leaving the auth bypass active for…
Evading Elastic EDR's call stack signatures with call gadgets https://offsec.almond.consulting/evading-elastic-callstack-signatures.html
Prepared Statements? Prepared to Be Vulnerable. https://blog.mantrainfosec.com/blog/18/prepared-statements-prepared-to-be-vulnerable
Introducing MCP-Scan: Protecting MCP with Invariant https://invariantlabs.ai/blog/introducing-mcp-scan
invariantlabs.ai
Introducing MCP-Scan: Protecting MCP with Invariant
Today we are launching MCP-Scan, a security scanner designed to protect your agentic systems from MCP-based security vulnerabilities, including Tool Poisoning Attacks and MCP Rug Pulls.
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools #39C3 #GnuPG #CryptoFlaws #SecurityResearch #Unpatched https://www.heise.de/en/news/39C3-Multiple-vulnerabilities-in-GnuPG-and-other-cryptographic-tools-11125362.html
c't Magazin
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools
Security researchers have found various security-relevant errors in GnuPG and similar programs. Many of the vulnerabilities are (still) not fixed.
Security-first SSRF protection for Node.js outbound HTTP requests https://www.npmjs.com/package/nullspace