[Research] LLVM based VMProtect Devirtualization: Part 1 (EN) #VMProtectDevirtualization #LLVMAnalysis #CodeObfuscation #DynamicTracing #SymbolicExecution https://hackyboiz.github.io/2025/09/11/banda/LLVM_based_VMP/en/
[Research] VMProtect Devirtualization: Part 2 (EN) #VMProtectDevirtualization #LLVMAnalysis #CodeObfuscation #DynamicTracing #SymbolicExecution https://hackyboiz.github.io/2025/12/11/banda/VMPpart2/en/
CVE-2025-6554: The (rabbit)
Hole #CVE20256554 #V8Exploit #TheHoleLeak #TDZBypass #TypeConfusion https://retr0.zip/blog/cve-2025-6554-the-rabbit-hole.html
Hole #CVE20256554 #V8Exploit #TheHoleLeak #TDZBypass #TypeConfusion https://retr0.zip/blog/cve-2025-6554-the-rabbit-hole.html
Gixy-Next: NGINX Configuration Security Scanner for Security Audits #NginxSecurity #ConfigScanner #VulnDetection #HardeningTool #GixyNext https://gixy.io/
Gixy-Next
Gixy-Next: NGINX Security Scanner & Configuration Hardening
Gixy-Next is an open source static analyzer for NGINX configurations. It detects security vulnerabilities, unsafe directives, compliance issues, and performance misconfigurations in nginx.conf before deployment.
WTF Are Abliterated Models? Uncensored LLMs Explained https://webdecoy.com/blog/wtf-are-abliterated-models-uncensored-llms-explained/
WebDecoy
WTF Are Abliterated Models? Uncensored LLMs Explained - WebDecoy
What abliterated means in AI models: how abliteration removes the refusal direction from LLMs, why it matters for security, and which models are abliterated.
Grok’s image edits spark sexualised deepfakes and regulator probes worldwide https://thebias.co.uk/articles/grok_ai_deepfake_outrage
Cybersecurity AI: A Game-Theoretic AI for Guiding Attack and Defense #CybersecurityAI #GameTheory #AIAttack #AIDefense #SecurityStrategy https://arxiv.org/pdf/2601.05887
CVE-2025-64155: Three Years of Remotely Rooting the Fortinet FortiSIEM https://horizon3.ai/attack-research/disclosures/cve-2025-64155-three-years-of-remotely-rooting-the-fortinet-fortisiem/
Horizon3.ai
CVE-2025-64155: FortiSIEM Analysis
Horizon3.ai details CVE-2025-64155, revealing chained FortiSIEM vulnerabilities enabling remote code execution and root access, analysis of the root cause, and indicators of compromise.
Bad Vibes: Comparing the Secure Coding Capabilities of Popular Coding Agents https://blog.tenzai.com/bad-vibes-comparing-the-secure-coding-capabilities-of-popular-coding-agents/
Tenzai
Blog | Tenzai - AI Security Research & Pentesting Insights
Writings from Tenzai researchers on autonomous offense, AI-driven pentesting, and hard security vulnerabilities. Real case studies and research from the field.
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC #DroneHacking #FirmwareDumping #NANDFlash #ECCBruteforce #IoTResearch https://neodyme.io/en/blog/drone_hacking_part_1/
neodyme.io
Drone Hacking Part 1: Dumping Firmware and Bruteforcing ECC
Desoldering a drone's flash chip and reconstructing the firmware from broken data.
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data #MicrosoftCopilot #RepromptAttack #DataTheft #SingleClickHack #AIVulnerability https://www.varonis.com/blog/reprompt
Varonis
Reprompt: The Single-Click Microsoft Copilot Attack that Silently Steals Your Personal Data
Varonis Threat Labs discovered a way to bypass Copilot’s safety controls, steal users’ darkest secrets, and evade detection.
CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center #CVE202620965 #AzureWAC #TenantRCE #CymulateResearch #TokenValidation https://cymulate.com/blog/cve-2026-20965-azure-windows-admin-center-tenant-wide-rce/
Cymulate
CVE-2026-20965: Cymulate Research Labs Discovers Token Validation Flaw that Leads to Tenant-Wide RCE in Azure Windows Admin Center
Cymulate Research Labs uncovered CVE-2026-20965, a token validation flaw in Azure Windows Admin Center enabling tenant-wide RCE and lateral movement.
The ServiceNow AI Vulnerability: What Went Wrong and How to Secure Your AI Agents #ServiceNowAIHack #AIAgentSecurity #LegacyAISecurity #SupplyChainRisk #AIIdentity https://opena2a.org/blogs/servicenow-ai-vulnerability
OpenA2A
The ServiceNow AI Vulnerability: What Went Wrong
85% of Fortune 500 exposed. Learn how AI agents need purpose-built security, not retrofitted legacy authentication.
WinBoat: Drive by Client RCE + Sandbox escape. #WinBoat #RemoteCodeExecution #SandboxEscape #DriveByAttack #UnauthenticatedAPI https://hack.do/posts/winboat-guest-service-host-rce/
hack.do
WinBoat: Drive by Client RCE + Sandbox escape.
A remote webpage can abuse an unauthenticated guest HTTP API to compromise the Windows guest container, then feed a malicious app entry leading to Linux host code execution on click.
Multiple cross-site leaks disclosing Facebook users in third-party websites #XSLVulnerability #MetaSecurity #UserIdentification #PrivacyThreat #BugBountyProgram https://ysamm.com/uncategorized/2026/01/16/cross-site-leaks.html
Instagram account takeover via Meta Pixel script abuse #InstagramHack #MetaPixelAbuse #CrossWindowMessaging #OAuthCodeTheft #BugBounty https://ysamm.com/uncategorized/2026/01/16/leaking-fbevents-ato.html
StackWarp vulnerability #StackWarp #SEVSNP #StackManipulation #StackEngineBug #PrivilegeEscalation https://stackwarpattack.com/#home
Leaking Meta FXAuth Token leading to 2 click Account Takeover #FXAuthLeak #AccountTakeover #RedirectFlaw #MetaSecurity #BugBounty https://ysamm.com/uncategorized/2026/01/16/leaking-fxauth-token.html
How I Used an Agent to Hunt Vulns #Blazelight #TerminalUI #WebNavigation #GuestPrompt #DigitalPortfolio https://blazelight.dev/blog/agent-vuln-hunting.mdx
blazelight.dev
I do things on the computer.