Dissecting a Multi-Stage macOS Infostealer #MacSyncStealer #macOSMalware #Infostealer #MalwareAnalysis #GatekeeperBypass https://blog.threatuniverse.co.uk/posts/usersyncworker-macos-infostealer/
Rhys Downing
Dissecting a Multi-Stage macOS Infostealer
Deep dive into MacSync Stealer (UserSyncWorker variant), a MaaS infostealer featuring Gatekeeper bypass via notarized Swift dropper, code signature validation, and multi-layer payload obfuscation
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction #OSF #OpenSource #Software #Foundation #Technology https://osf.io/jd392/overview
OSF
The Kaoru Method: Linearizing SHA-256 via Universal Fractional Space Mapping and Carry Reconstruction
This paper presents a groundbreaking cryptanalytic framework for the SHA-256 hash function. By mapping the 2^32 modular addition space into a fractional domain [0, 1), I demonstrate that the non-linear "noise" generated by modular overflows is not random…
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks #UEFIFlaw #DMAAttacks #MotherboardSecurity #IOMMUvulnerability #EarlyBootAttacks https://www.nexaspecs.com/2025/12/critical-uefi-flaw-exposes-motherboards.html
NexasPecs
Critical UEFI Flaw Exposes Motherboards to Early-Boot DMA Attacks
Explore our extensive archive of in-depth tech reviews, scientific breakthroughs, and cybersecurity analysis. Find the specs, facts, and expert insig
😡2
When WebSockets Lead to RCE in CurseForge #CurseForge #RCE #WebSocket #Vulnerability #Cybersecurity https://elliott.diy/blog/curseforge/
elliott.diy
When WebSockets Lead to RCE in CurseForge
An unauthenticated local WebSocket server in the CurseForge launcher allowed any website to trigger remote code execution via attacker-controlled JVM arguments.
CSRF Protection without Tokens or Hidden Form Fields #CSRFProtection #FetchMetadata #WebSecurity #Microdot #OWASP https://blog.miguelgrinberg.com/post/csrf-protection-without-tokens-or-hidden-form-fields
Miguelgrinberg
CSRF Protection without Tokens or Hidden Form Fields
A couple of months ago, I received a request from a random Internet user to add CSRF protection to my little web framework Microdot, and I thought it was a fantastic idea.When I set off to do this…
Jupyter Notebook for testing collisions on SHA-256 https://osf.io/2gdzq/files/dqghk
OSF
FIRST_REAL_COLISION_SHA_256_ENGLISH.ipynb
💩3🤡1
Merry Christmas Day! Have a MongoDB security incident. https://doublepulsar.com/merry-christmas-day-have-a-mongodb-security-incident-9537f54289eb
Medium
Merry Christmas Day! Have a MongoDB security incident.
Somebody from Elastic Security decided to post an exploit for CVE-2025–14847 on Christmas Day.
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks https://bobdahacker.com/blog/petlibro
Bobdahacker
Petlibro: Your Pet Feeder Is Feeding Data To Anyone Who Asks
How I found critical vulnerabilities in Petlibro smart pet feeders allowing complete account takeover via broken OAuth, access to anyone's pet data, device hijacking, and private audio recordings - and how they're still leaving the auth bypass active for…
Evading Elastic EDR's call stack signatures with call gadgets https://offsec.almond.consulting/evading-elastic-callstack-signatures.html
Prepared Statements? Prepared to Be Vulnerable. https://blog.mantrainfosec.com/blog/18/prepared-statements-prepared-to-be-vulnerable
Introducing MCP-Scan: Protecting MCP with Invariant https://invariantlabs.ai/blog/introducing-mcp-scan
invariantlabs.ai
Introducing MCP-Scan: Protecting MCP with Invariant
Today we are launching MCP-Scan, a security scanner designed to protect your agentic systems from MCP-based security vulnerabilities, including Tool Poisoning Attacks and MCP Rug Pulls.
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools #39C3 #GnuPG #CryptoFlaws #SecurityResearch #Unpatched https://www.heise.de/en/news/39C3-Multiple-vulnerabilities-in-GnuPG-and-other-cryptographic-tools-11125362.html
c't Magazin
39C3: Multiple vulnerabilities in GnuPG and other cryptographic tools
Security researchers have found various security-relevant errors in GnuPG and similar programs. Many of the vulnerabilities are (still) not fixed.
Security-first SSRF protection for Node.js outbound HTTP requests https://www.npmjs.com/package/nullspace
The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance https://mehmetince.net/the-story-of-a-perfect-exploit-chain-six-bugs-that-looked-harmless-until-they-became-pre-auth-rce-in-a-security-appliance/
Mehmet Ince @mdisec - Vulnerability Researcher | Building security products | Security Advisor | Amateur Muay Thai fighter
The Story of a Perfect Exploit Chain: Six Bugs That Looked Harmless Until They Became Pre-Auth RCE in a Security Appliance - Mehmet…
It was May 2024, and our internal security team was evaluating the LogPoint SIEM/SOAR platform to replace our existing platform, potentially. As part of a habit I’ve built over the years —and honestly, part of our 3rd party due diligence— I gave myself 24…
MongoBleed: CVE-2025-14847 Memory Corruption in MongoDB. Your Database Talks Back https://phoenix.security/mongobleed-vulnerability-cve-2025-14847/
Phoenix Security
MongoBleed: CVE-2025-14847 Memory Corruption in MongoDB. Your Database Talks Back
MongoBleed vulnerability (CVE-2025-14847) leaks MongoDB heap memory without auth via zlib. See affected versions, exposure, and fixes.
Tailscale Security - A Threat-Based Hardening Guide for Growing Companies #TailscaleSecurity #ThreatModeling #NetworkHardening #AccessControl #ComplianceAudit https://www.adversis.io/blogs/tailscale-hardening-guide
www.adversis.io
Tailscale Security - A Hardening Guide for Growing Companies
A threat analysis and compliance mapping guide for Tailscale deployments. Check out tailsnitch to audit your setup
Reverse engineering my cloud-connected e-scooter and finding the master key to unlock all scooters https://blog.nns.ee/2026/01/06/aike-ble/
blog.nns.ee
Reverse engineering my cloud-connected e-scooter and finding the master key to unlock all scooters | nns.ee
Ethical Hacking and Cybersecurity Blog
Zen and the Art of Microcode Hacking https://bughunters.google.com/blog/zen-and-the-art-of-microcode-hacking
Google
Blog: Zen and the Art of Microcode Hacking
This blog post covers the full details of EntrySign, the AMD Zen microcode signature validation vulnerability recently discovered by the Google Security team.
Digital Forensics: Basic Linux Analysis After Data Exfiltration https://hackers-arise.com/digital-forensics-basic-linux-analysis-after-data-exfiltration/