IPVanish VPN macOS Privilege Escalation
https://ift.tt/Qph0Dsn
Submitted March 3, 2026 at 10:50PM by appsec1337
via reddit https://ift.tt/HT0bpuz
https://ift.tt/Qph0Dsn
Submitted March 3, 2026 at 10:50PM by appsec1337
via reddit https://ift.tt/HT0bpuz
SecureLayer7 - Offensive Security, API Scanner & Attack Surface Management
IPVanish VPN macOS Privilege Escalation
The IPVanish VPN application for macOS contains a critical privilege escalation vulnerability that allows any unprivileged local process to execute arbitrary code as root without user interaction....
Generate 45+ honeytokens with no sign-up required and no paywall
https://ift.tt/9l8aECX
Submitted March 3, 2026 at 10:47PM by nwqd
via reddit https://ift.tt/p18WThG
https://ift.tt/9l8aECX
Submitted March 3, 2026 at 10:47PM by nwqd
via reddit https://ift.tt/p18WThG
NeroSwarm - Deception-as-a-Service
Free Cyber Deception Lab Tools | NeroSwarm Lab
Use the Deception Lab to launch practical security utilities, including honeytoken creation, reputation analysis, and guided deception testing workflows.
Phishing Lures Utilizing a Single Google Cloud Storage Bucket
https://ift.tt/7ptkufP
Submitted March 4, 2026 at 12:14AM by anuraggawande
via reddit https://ift.tt/Je832BH
https://ift.tt/7ptkufP
Submitted March 4, 2026 at 12:14AM by anuraggawande
via reddit https://ift.tt/Je832BH
Malware Analysis, Phishing, and Email Scams
Analysis of an Integrated Phishing Campaign Utilizing Google Cloud Infrastructure
In recent weeks, a highly organized phishing campaign has surfaced, characterized by its use of legitimate Google infrastructure to bypass standard security filters. I have identified more than 25 …
Free Exploit Development CTFs + Walkthroughs Based On Real CVEs
https://ift.tt/AH52VxZ
Submitted March 4, 2026 at 03:04AM by Prior-Penalty
via reddit https://ift.tt/OTsEnJM
https://ift.tt/AH52VxZ
Submitted March 4, 2026 at 03:04AM by Prior-Penalty
via reddit https://ift.tt/OTsEnJM
Zeropath
ZeroPath Exploit Development CTFs - ZeroPath Blog
Learn to exploit complex real-world vulnerabilities with zeropath-ctf, a set of self-contained exploit development exercises based on CVEs from the CISA Known Exploited Vulnerabilities list, powered by ZeroPath's shapeshifter vulnerability generation suite.
How we built high speed threat hunting for email security
https://ift.tt/n439OJ1
Submitted March 4, 2026 at 08:35AM by jkamdjou
via reddit https://ift.tt/Slx89ia
https://ift.tt/n439OJ1
Submitted March 4, 2026 at 08:35AM by jkamdjou
via reddit https://ift.tt/Slx89ia
sublime.security
How we built high speed threat hunting for email security · Blog · Sublime Security
Technical deep dive into how we boosted speeds for historical threat hunting and detection backtesting
Intent-Based Access Control (IBAC) – FGA for AI Agent Permissions
https://ibac.dev
Submitted March 4, 2026 at 10:16AM by ok_bye_now_
via reddit https://ift.tt/BjEsFx8
https://ibac.dev
Submitted March 4, 2026 at 10:16AM by ok_bye_now_
via reddit https://ift.tt/BjEsFx8
Reddit
From the netsec community on Reddit: Intent-Based Access Control (IBAC) – FGA for AI Agent Permissions
Posted by ok_bye_now_ - 0 votes and 1 comment
7-day intensive for security professionals looking to upskill on securing frontier AI systems (Apr 20-26 | Singapore)
https://aisb.dev
Submitted March 4, 2026 at 01:06PM by POPTARTdoesTAEKWONDO
via reddit https://ift.tt/sujIX6W
https://aisb.dev
Submitted March 4, 2026 at 01:06PM by POPTARTdoesTAEKWONDO
via reddit https://ift.tt/sujIX6W
aisb.dev
AI Security Bootcamp
A 7-day intensive program for security professionals shaping how we secure emerging AI systems.
Using Zeek with AWS Traffic Mirroring and Kafka
https://ift.tt/nwb5RXz
Submitted March 4, 2026 at 03:14PM by awlzl
via reddit https://ift.tt/xm2yfBY
https://ift.tt/nwb5RXz
Submitted March 4, 2026 at 03:14PM by awlzl
via reddit https://ift.tt/xm2yfBY
A single operator with basic skills used an open-source AI platform to breach 600+ FortiGate devices across 55 countries. No zero-days. Just weak passwords and an AI copilot. Full breakdown of CyberStrikeAI, the developer's MSS ties, and all 21 server IOCs.
https://ift.tt/E1RP4Ls
Submitted March 4, 2026 at 06:47PM by LostPrune2143
via reddit https://ift.tt/CHRsn5D
https://ift.tt/E1RP4Ls
Submitted March 4, 2026 at 06:47PM by LostPrune2143
via reddit https://ift.tt/CHRsn5D
blog.barrack.ai
CyberStrikeAI: the AI Attack Platform Behind the 600+ FortiGate Breach | Barrack.ai
An open-source AI offensive security platform, built by a developer with ties to China's MSS, was used in a campaign that compromised 600+ FortiGate devices across 55 countries. Full technical breakdown.
Built a header echo + TLS interception detector to score ISP-level surveillance — looking for feedback on the methodology
https://ift.tt/bKjISwl
Submitted March 5, 2026 at 04:47AM by Beneficial-Jelly3365
via reddit https://ift.tt/0WP9iVE
https://ift.tt/bKjISwl
Submitted March 5, 2026 at 04:47AM by Beneficial-Jelly3365
via reddit https://ift.tt/0WP9iVE
ismyispspying.com
Is My ISP Spying? — Free Privacy Test
Test for supercookies, header injection, DNS hijacking, and TLS interception in seconds.
Your Duolingo Is Talking to ByteDance: Cracking the Pangle SDK's Encryption
https://ift.tt/IdwMsLZ
Submitted March 5, 2026 at 06:32AM by AdTemporary2475
via reddit https://ift.tt/z3woxet
https://ift.tt/IdwMsLZ
Submitted March 5, 2026 at 06:32AM by AdTemporary2475
via reddit https://ift.tt/z3woxet
Buchodi's Threat Intel
Your Duolingo Is Talking to ByteDance: Cracking the Pangle SDK's Encryption
When you open Duolingo to practice Spanish, BeReal to share a photo, or Character.AI to chat with a bot, you probably don't expect your battery level, storage capacity, and internal IP address to be sent to ByteDance, the company behind TikTok.
But that's…
But that's…
Normalized Certificate Transparency logs as a daily JSON dataset
https://ift.tt/1Dh4QkJ
Submitted March 5, 2026 at 07:44AM by heffmann
via reddit https://ift.tt/6dEOVzg
https://ift.tt/1Dh4QkJ
Submitted March 5, 2026 at 07:44AM by heffmann
via reddit https://ift.tt/6dEOVzg
hefftools.dev
ct-cert-feed
Bulk download normalized Certificate Transparency (CT) log snapshots as deterministic daily JSON.
we at codeant found a bug in pac4j-jwt (auth bypass)
https://ift.tt/ce0B6x4
Submitted March 5, 2026 at 01:01PM by charankmed
via reddit https://ift.tt/rTg3zsX
https://ift.tt/ce0B6x4
Submitted March 5, 2026 at 01:01PM by charankmed
via reddit https://ift.tt/rTg3zsX
www.codeant.ai
Critical Auth Bypass in pac4j-jwt: Full PoC Using Only a Public Key
CodeAnt AI found a critical authentication bypass in pac4j-jwt where an attacker can impersonate any user using only the RSA public key. Full PoC and disclosure.
How I automated a full recon → secrets scan → cloud misconfiguration pipeline without writing a single parser
https://ift.tt/z1JpZA3
Submitted March 5, 2026 at 06:26PM by Deep-Bandicoot-7090
via reddit https://ift.tt/hd1S7It
https://ift.tt/z1JpZA3
Submitted March 5, 2026 at 06:26PM by Deep-Bandicoot-7090
via reddit https://ift.tt/hd1S7It
ShipSec Studio
ShipSec Studio | No-Code Security Automation Platform
Build reliable security workflows without code. Visual automation, Temporal-powered execution, and AI assistance.
2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk
https://ift.tt/YtKUj08
Submitted March 5, 2026 at 07:18PM by guedou
via reddit https://ift.tt/1JINYDX
https://ift.tt/YtKUj08
Submitted March 5, 2026 at 07:18PM by guedou
via reddit https://ift.tt/1JINYDX
GitGuardian Blog - Take Control of Your Secrets Security
2,622 Valid Certificates Exposed: A Google-GitGuardian Study Maps Private Key Leaks to Real-World Risk
GitGuardian partnered with Google to answer: what happens when private keys leak? Using Certificate Transparency, we mapped about 1M leaked keys to 140k certificates. Result: 2,622 were valid as of September 2025, exposing major organizations. Our disclosure…
YGGtorrent — Fin de partie [French]
https://yggleak.top/fr/home/ygg-dossier
Submitted March 5, 2026 at 06:47PM by moviuro
via reddit https://ift.tt/xutqUS8
https://yggleak.top/fr/home/ygg-dossier
Submitted March 5, 2026 at 06:47PM by moviuro
via reddit https://ift.tt/xutqUS8
yggleak.top
YGGtorrent — Fin de partie — YGGLeak
Exposer ce qui devrait l'etre.
HPD (Hex Packet Decoder) now have AI feature – looking for feedback
https://hpd.gasmi.net
Submitted March 5, 2026 at 08:22PM by Secure-Ad2104
via reddit https://ift.tt/9sWdBjZ
https://hpd.gasmi.net
Submitted March 5, 2026 at 08:22PM by Secure-Ad2104
via reddit https://ift.tt/9sWdBjZ
hpd.gasmi.net
Hex Packet Decoder
Network packet decoder
Credential Protection for AI Agents: The Phantom Token Pattern
https://ift.tt/HY92zfq
Submitted March 5, 2026 at 10:27PM by DecodeBytes
via reddit https://ift.tt/y7q2ZMX
https://ift.tt/HY92zfq
Submitted March 5, 2026 at 10:27PM by DecodeBytes
via reddit https://ift.tt/y7q2ZMX
nono.sh
nono - Next-Generation Agent Security
Kernel-enforced isolation, network filtering, immutable auditing, and atomic rollbacks for AI agents - built into the nono CLI and native SDKs.
Model Context Protocol (MCP) Authentication and Authorization
https://ift.tt/89NkIO0
Submitted March 6, 2026 at 06:13PM by nibblesec
via reddit https://ift.tt/Qz8dgIr
https://ift.tt/89NkIO0
Submitted March 6, 2026 at 06:13PM by nibblesec
via reddit https://ift.tt/Qz8dgIr
Doyensec
The MCP AuthN/Z Nightmare
This article shares our perspective on the current state of authentication and authorization in enterprise-ready, remote MCP server deployments.
Hardening Firefox with Anthropic’s Red Team
https://ift.tt/TRNzgfE
Submitted March 6, 2026 at 07:57PM by evilpies
via reddit https://ift.tt/y8Yid0k
https://ift.tt/TRNzgfE
Submitted March 6, 2026 at 07:57PM by evilpies
via reddit https://ift.tt/y8Yid0k
The Mozilla Blog
An emerging technique, pressure-tested by Firefox engineers
For more than two decades, Firefox has been one of the most scrutinized and security-hardened codebases on the web. Open source means our code is visible,