How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack #SupplyChainAttack #XSS #Mintlify #CorporateSecurity #BugBounty https://gist.github.com/hackermondev/5e2cdc32849405fff6b46957747a2d28
Gist
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack
How we pwned X (Twitter), Vercel, Cursor, Discord, and hundreds of companies through a supply-chain attack - writeup.md
👍1
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 #AIAgentSecurity #OAuthFlaw #CVE20256514 #TrustInversion #CapabilityBasedAuth https://amlalabs.com/blog/oauth-cve-2025-6514/
Amla Labs
When OAuth Becomes a Weapon: Lessons from CVE-2025-6514 | Amla Labs
A critical vulnerability in mcp-remote affected 558,846 downloads. The bug was client-side, but the attack exploited OAuth dynamic discovery—a trust assumption that breaks for autonomous agents.
Microsoft Brokering File System Elevation of Privilege Vulnerability #MicrosoftBFS #UseAfterFree #ElevationOfPrivilege #KernelVulnerability #CVE202529970 https://www.pixiepointsecurity.com/blog/nday-cve-2025-29970/
PixiePoint Security
Microsoft Brokering File System Elevation of Privilege Vulnerability | PixiePoint Security
About 2 years ago, Microsoft first released Win32-App-isolation which is a sandbox-like mechanism to further separate application access to resources on Windows clients. Brokering File System (BFS) was released around the same time to specifically …
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets #RustBotnet #ReverseEngineering #C2Honeypot #DockerExploit #DDoSMalware https://beelzebub.ai/blog/rust-ddos-botnet-honeypot-c2-decoding/
Beelzebub
How I Reverse Engineered a Rust Botnet and Built a C2 Honeypot to Monitor Its Targets | AI-Native security platform
AI-Native security platform: Deceive, Detect, Respond. “We turn that hard truth into your tactical advantage. Our AI-based decoys, built using our open-source framework, deceive attackers during lateral movement within the network. While intruders interact…
mediatek? more like media-rekt, amirite. #MediaTekRekt #WiFiVulnerabilities #KernelExploits #VendorDisclosure #CyberSecurity https://blog.coffinsec.com/0days/2025/12/15/more-like-mediarekt-amirite.html
hyprblog
mediatek? more like media-REKT, amirite.
A year-in-review going over 19+ bugs in Mediatek’s MT76xx/MT7915 (and others) wifi chipsets I reported this year, PoCs included!
Detecting Vision-Based AI Agents: Operator and Beyond #VisionAIAgents #BotDetection #BehavioralAnalysis #TimingSignatures #PixelPrecision https://webdecoy.com/blog/detecting-vision-based-ai-agents-operator-computer-use/
Webdecoy
Detecting Vision-Based AI Agents: Operator and Beyond - WebDecoy
Detect Claude Computer Use and OpenAI Operator through timing analysis, cursor patterns, and prompt
Dissecting a Multi-Stage macOS Infostealer #MacSyncStealer #macOSMalware #Infostealer #MalwareAnalysis #GatekeeperBypass https://blog.threatuniverse.co.uk/posts/usersyncworker-macos-infostealer/
Rhys Downing
Dissecting a Multi-Stage macOS Infostealer
Deep dive into MacSync Stealer (UserSyncWorker variant), a MaaS infostealer featuring Gatekeeper bypass via notarized Swift dropper, code signature validation, and multi-layer payload obfuscation
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction #OSF #OpenSource #Software #Foundation #Technology https://osf.io/jd392/overview
OSF
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction
This paper presents a groundbreaking cryptanalytic framework for the SHA-256 hash function. By mapping the 2^32 modular addition space into a fractional domain [0, 1), I demonstrate that the non-linear "noise" generated by modular overflows is not random…
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks #UEFIFlaw #DMAAttacks #MotherboardSecurity #IOMMUvulnerability #EarlyBootAttacks https://www.nexaspecs.com/2025/12/critical-uefi-flaw-exposes-motherboards.html
NexasPecs
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks
Explore our extensive archive of in-depth tech reviews, scientific breakthroughs, and cybersecurity analysis. Find the specs, facts, and expert insig
😡2
When WebSockets Lead to RCE in CurseForge #CurseForge #RCE #WebSocket #Vulnerability #Cybersecurity https://elliott.diy/blog/curseforge/
elliott.diy
When WebSockets Lead to RCE in CurseForge
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
CSRF Protection without Tokens or Hidden Form Fields #CSRFProtection #FetchMetadata #WebSecurity #Microdot #OWASP https://blog.miguelgrinberg.com/post/csrf-protection-without-tokens-or-hidden-form-fields
Miguelgrinberg
CSRF Protection without Tokens or Hidden Form Fields
A couple of months ago, I received a request from a random Internet user to add CSRF protection to my little web framework Microdot, and I thought it was a fantastic idea.When I set off to do this…
Jupyter Notebook for testing collisions on SHA-256 https://osf.io/2gdzq/files/dqghk
OSF
FIRST_REAL_COLISION_SHA_256_ENGLISH.ipynb
💩3🤡1
Merry Christmas Day! Have a MongoDB security incident. https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb
Medium
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks https://bobdahacker.com/blog/petlibro
Bobdahacker
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - and how they're still leaving the auth bypass active for…
Evading Elastic EDR's call stack signatures with call gadgets https://offsec.almond.consulting/evading-elastic-callstack-signatures.html
Prepared Statements? Prepared to Be Vulnerable. https://blog.mantrainfosec.com/blog/18/prepared-statements-prepared-to-be-vulnerable
Introducing MCP-Scan: Protecting MCP with Invariant https://invariantlabs.ai/blog/introducing-mcp-scan
invariantlabs.ai
Introducing MCP-Scan: Protecting MCP with Invariant
Today we are launching MCP-Scan, a security scanner designed to protect your agentic systems from MCP-based security vulnerabilities, including Tool Poisoning Attacks and MCP Rug Pulls.
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools #39C3 #GnuPG #CryptoFlaws #SecurityResearch #Unpatched https://www.heise.de/en/news/39C3-Multiple-vulnerabilities-in-GnuPG-and-other-cryptographic-tools-11125362.html
c't Magazin
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools
Security researchers have found various security-relevant errors in GnuPG and similar programs. Many of the vulnerabilities are (still) not fixed.
Security-first SSRF protection for Node.js outbound HTTP requests https://www.npmjs.com/package/nullspace
The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance https://mehmetince.net/the-story-of-a-perfect-exploit-chain-six-bugs-that-looked-harmless-until-they-became-pre-auth-rce-in-a-security-appliance/
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance - Mehmet…
It was May 2024, and our internal security team was evaluating the LogPoint SIEM/SOAR platform to replace our existing platform, potentially. As part of a habit I’ve built over the years —and honestly, part of our 3rd party due diligence— I gave myself 24…