After the Takedown: Excavating Abuse Infrastructure with DNS Sinkholes
https://ift.tt/uMot4NV
Submitted January 19, 2026 at 01:06AM by 0x5h4un
via reddit https://ift.tt/aQn7ON2
https://ift.tt/uMot4NV
Submitted January 19, 2026 at 01:06AM by 0x5h4un
via reddit https://ift.tt/aQn7ON2
disclosing.observer
After the Takedown: Excavating Abuse Infrastructure with DNS Sinkholes - Disclosing.Observer
DNS sinkholing does not erase abuse infrastructure but captures it at the moment of intervention, creating a stable boundary from which pre-takedown organiza...
"synthetic vulnerabilities" — security flaws unique to AI-generated code
https://ift.tt/AyMqNp1
Submitted January 19, 2026 at 04:38PM by bishwasbhn
via reddit https://ift.tt/i5nhR7z
https://ift.tt/AyMqNp1
Submitted January 19, 2026 at 04:38PM by bishwasbhn
via reddit https://ift.tt/i5nhR7z
Write-up: Cloudflare Zero-day: Accessing Any Host Globally
https://ift.tt/IbniG3T
Submitted January 19, 2026 at 08:02PM by xIsis
via reddit https://ift.tt/2rPoyM6
https://ift.tt/IbniG3T
Submitted January 19, 2026 at 08:02PM by xIsis
via reddit https://ift.tt/2rPoyM6
fearsoff.org
Cloudflare Zero-day: Accessing Any Host Globally
Discover how a Cloudflare WAF bypass in /.well-known/acme-challenge/ exposed origins, its impact, and the fix. A must-read for security pros.
Frida 17.6.0 released – major Android stability improvements, Android 16 support
https://ift.tt/pSRwOk4
Submitted January 19, 2026 at 09:02PM by oleavr
via reddit https://ift.tt/9kPJTXU
https://ift.tt/pSRwOk4
Submitted January 19, 2026 at 09:02PM by oleavr
via reddit https://ift.tt/9kPJTXU
Frida • A world-class dynamic instrumentation toolkit
Frida 17.6.0 Released
Observe and reprogram running programs on Windows, macOS, GNU/Linux, iOS, watchOS, tvOS, Android, FreeBSD, and QNX
Successful Errors: New Code Injection and SSTI Techniques
https://ift.tt/vX6FBgE
Submitted January 18, 2026 at 09:37PM by vladko312
via reddit https://ift.tt/W3N7LXF
https://ift.tt/vX6FBgE
Submitted January 18, 2026 at 09:37PM by vladko312
via reddit https://ift.tt/W3N7LXF
GitHub
GitHub - vladko312/Research_Successful_Errors: Clear and obvious name of the exploitation technique can create a false sense of…
Clear and obvious name of the exploitation technique can create a false sense of familiarity, even if its true potential was never researched, the technique itself is never mentioned and payloads a...
Cloudflare Zero-day: Accessing Any Host Globally
https://ift.tt/IbniG3T
Submitted January 20, 2026 at 04:52PM by albinowax
via reddit https://ift.tt/RHLPq5g
https://ift.tt/IbniG3T
Submitted January 20, 2026 at 04:52PM by albinowax
via reddit https://ift.tt/RHLPq5g
fearsoff.org
Cloudflare Zero-day: Accessing Any Host Globally
Discover how a Cloudflare WAF bypass in /.well-known/acme-challenge/ exposed origins, its impact, and the fix. A must-read for security pros.
Billion-Dollar Bait & Switch: Exploiting a Race Condition in Blockchain Infrastructure
https://ift.tt/5GOqKJL
Submitted January 21, 2026 at 12:07AM by va_start
via reddit https://ift.tt/oCZUluz
https://ift.tt/5GOqKJL
Submitted January 21, 2026 at 12:07AM by va_start
via reddit https://ift.tt/oCZUluz
Mav Levin Security Research
Billion-Dollar Bait & Switch: Exploiting a Race Condition in Blockchain Infrastructure
Every 12 seconds, risk-free profit is auctioned for millions on the Ethereum network. It’s a brutal, PvP fight. The miners take the majority of the profit, a...
oss-sec: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
https://ift.tt/CIrOxSe
Submitted January 21, 2026 at 12:24PM by farrantt
via reddit https://ift.tt/u4Wdhzb
https://ift.tt/CIrOxSe
Submitted January 21, 2026 at 12:24PM by farrantt
via reddit https://ift.tt/u4Wdhzb
seclists.org
oss-sec: GNU InetUtils Security Advisory: remote authentication by-pass in telnetd
When The Gateway Becomes The Doorway: Pre-Auth RCE in API Management
https://ift.tt/btFzMXO
Submitted January 21, 2026 at 11:38AM by operator_dll
via reddit https://ift.tt/HTUiOLp
https://ift.tt/btFzMXO
Submitted January 21, 2026 at 11:38AM by operator_dll
via reddit https://ift.tt/HTUiOLp
Principlebreach
When The Gateway Becomes The Doorway: Pre-Auth RCE in API Management
Discover how a decade-old vulnerability class leads to pre-authentication Remote Code Execution (RCE) in an enterprise API management platform. This article details the end-to-end compromise of an API Gateway, from initial subdomain reconnaissance and API…
Fake PNB MetLife payment pages abusing UPI & Telegram bots
https://ift.tt/nfu3KpY
Submitted January 21, 2026 at 01:25PM by anuraggawande
via reddit https://ift.tt/UYeA7Rc
https://ift.tt/nfu3KpY
Submitted January 21, 2026 at 01:25PM by anuraggawande
via reddit https://ift.tt/UYeA7Rc
Malware Analysis, Phishing, and Email Scams
Fake “PNB MetLife Payment Gateway” Page Stealing Customer Details and Redirecting Victims to UPI Payments
Overview While actively hunting for phishing site, I came across multiple web pages impersonating PNB MetLife Insurance and presenting themselves as official policy premium payment gateways. This a…
Break LLM Workflows with Claude's Refusal Magic String
https://ift.tt/aTyXzD0
Submitted January 21, 2026 at 08:27PM by RedTermSession
via reddit https://ift.tt/pIMyRa0
https://ift.tt/aTyXzD0
Submitted January 21, 2026 at 08:27PM by RedTermSession
via reddit https://ift.tt/pIMyRa0
hackingthe.cloud
Break LLM Workflows with Claude's Refusal Magic String - Hacking The Cloud
How Anthropic's refusal test string can be abused to stop streaming responses and create sticky failures.
Third-party identity verification provider breach exposes government ID images (Total Wireless / Veriff)
https://ift.tt/pJoObqC
Submitted January 22, 2026 at 12:45AM by Bp121687
via reddit https://ift.tt/3Yn4QxP
https://ift.tt/pJoObqC
Submitted January 22, 2026 at 12:45AM by Bp121687
via reddit https://ift.tt/3Yn4QxP
When the Lab Door Stays Open: Exposed Training Apps Exploited for Fortune 500 Cloud Breaches
https://ift.tt/3slRoiM
Submitted January 21, 2026 at 11:38PM by Street-Plum7312
via reddit https://ift.tt/uZq2WFl
https://ift.tt/3slRoiM
Submitted January 21, 2026 at 11:38PM by Street-Plum7312
via reddit https://ift.tt/uZq2WFl
Pentera
When the Lab Door Stays Open: Exposed Training Apps Exploited for Fortune 500 Cloud Breaches - Pentera
Pentera reveals attackers exploiting exposed cloud training apps with crypto miners in Fortune 500 environments, risking full cloud compromise.
Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass) - watchTowr Labs
https://ift.tt/LGba8Ye
Submitted January 22, 2026 at 06:00AM by dx7r__
via reddit https://ift.tt/Qv6T37s
https://ift.tt/LGba8Ye
Submitted January 22, 2026 at 06:00AM by dx7r__
via reddit https://ift.tt/Qv6T37s
watchTowr Labs
Attackers With Decompilers Strike Again (SmarterTools SmarterMail WT-2026-0001 Auth Bypass)
Well, well, well - look what we’re back with.
You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV holders.
…
You may recall that merely two weeks ago, we analyzed CVE-2025-52691 - a pre-auth RCE vulnerability in the SmarterTools SmarterMail email solution with a timeline that is typically reserved for KEV holders.
…
[FREE DATASET] 67K+ domains with technology fingerprints
https://ift.tt/yEMaG1u
Submitted January 22, 2026 at 10:18AM by Upper-Character-6743
via reddit https://ift.tt/ygBt5iK
https://ift.tt/yEMaG1u
Submitted January 22, 2026 at 10:18AM by Upper-Character-6743
via reddit https://ift.tt/ygBt5iK
Dropbox
sample_dec_2025.zip
Shared with Dropbox
Single malformed BRID/HHIT DNS packet can crash ISC BIND
https://ift.tt/wUuTDgp
Submitted January 22, 2026 at 05:25PM by div3rto
via reddit https://ift.tt/W1PBK2u
https://ift.tt/wUuTDgp
Submitted January 22, 2026 at 05:25PM by div3rto
via reddit https://ift.tt/W1PBK2u
AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent
https://ift.tt/5T7ZmGA
Submitted January 22, 2026 at 07:04PM by ulldma
via reddit https://ift.tt/tLHze0G
https://ift.tt/5T7ZmGA
Submitted January 22, 2026 at 07:04PM by ulldma
via reddit https://ift.tt/tLHze0G
The GitHub Blog
AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent
Learn how we are using the newly released GitHub Security Lab Taskflow Agent to triage categories of vulnerabilities.
Intercepting OkHttp at Runtime With Frida
https://ift.tt/t7JEhgq
Submitted January 22, 2026 at 07:47PM by nibblesec
via reddit https://ift.tt/oHSW5fz
https://ift.tt/t7JEhgq
Submitted January 22, 2026 at 07:47PM by nibblesec
via reddit https://ift.tt/oHSW5fz
Doyensec
Intercepting OkHttp at Runtime With Frida - A Practical Guide
OkHttp is the defacto standard HTTP client library for the Android ecosystem. It is therefore crucial for a security analyst to be able to dynamically eavesdrop the traffic generated by this library during testing. While it might seem easy, this task is far…
CVE-2026-22200: Ticket to Shell in osTicket
https://ift.tt/5yKlZW8
Submitted January 22, 2026 at 09:41PM by scopedsecurity
via reddit https://ift.tt/mDrysoK
https://ift.tt/5yKlZW8
Submitted January 22, 2026 at 09:41PM by scopedsecurity
via reddit https://ift.tt/mDrysoK
Horizon3.ai
CVE-2026-22200: Ticket to Shell in osTicket
CVE-2026-22200 impacts osTicket and lets anonymous attackers read arbitrary files and, in some cases, achieve RCE. Patched in osTicket 1.18.3 / 1.17.7.
Firefox / WebRTC Encoded Transforms: UAF via undetached ArrayBuffer / CVE-2025-1432
https://ift.tt/tHqVDuZ
Submitted January 23, 2026 at 12:37PM by MegaManSec2
via reddit https://ift.tt/mn3dej5
https://ift.tt/tHqVDuZ
Submitted January 23, 2026 at 12:37PM by MegaManSec2
via reddit https://ift.tt/mn3dej5
AISLE
AISLE - AI-Native Cybersecurity Platform
AISLE is the world's best AI-native platform, purpose-built to find what others miss, remediate end-to-end, and verify every fix.
Free URL & site security scanner: ScanMalware.com • Scan websites for threats. Would love feedback on detection, reporting, API, UX from the netsec crowd
https://scanmalware.com
Submitted January 23, 2026 at 03:53PM by jonas02
via reddit https://ift.tt/BtVSlDT
https://scanmalware.com
Submitted January 23, 2026 at 03:53PM by jonas02
via reddit https://ift.tt/BtVSlDT
ScanMalware.com
Free URL Scanner - Check Website for Malware | ScanMalware
Instantly scan any URL for malware, phishing, and security threats. Free online website security scanner with real-time analysis, threat detection, and comprehensive vulnerability assessment.