Arctic Wolf Observes Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts | Arctic Wolf
https://ift.tt/LtM9lEK
Submitted January 23, 2026 at 06:19PM by SleepingProcess
via reddit https://ift.tt/Tmkof9A
https://ift.tt/LtM9lEK
Submitted January 23, 2026 at 06:19PM by SleepingProcess
via reddit https://ift.tt/Tmkof9A
Arctic Wolf
Arctic Wolf Observes Malicious Configuration Changes On Fortinet FortiGate Devices via SSO Accounts | Arctic Wolf
Arctic Wolf has observed a new cluster of automated malicious activity involving unauthorized firewall configuration changes on FortiGate devices.
Organized Traffer Gang on the Rise Targeting Web3 Employees and Crypto Holders
https://ift.tt/7vtZWwc
Submitted January 23, 2026 at 07:33PM by CyberMasterV
via reddit https://ift.tt/YvcSXtn
https://ift.tt/7vtZWwc
Submitted January 23, 2026 at 07:33PM by CyberMasterV
via reddit https://ift.tt/YvcSXtn
Blogspot
Organized Traffer Gang on the Rise Targeting Web3 Employees and Crypto Holders
Author(s): Vlad Pasca, Radu-Emanuel Chiscariu Sophisticated cybercriminal operation targets cryptocurrency users and Web3 employees Malwa...
Syd - Air-Gapped Red and blueteam
https://sydsec.co.uk
Submitted January 23, 2026 at 07:19PM by Glass-Ant-6041
via reddit https://ift.tt/Z6f09NC
https://sydsec.co.uk
Submitted January 23, 2026 at 07:19PM by Glass-Ant-6041
via reddit https://ift.tt/Z6f09NC
www.sydsec.co.uk
Syd - Air-Gapped Cybersecurity AI
Free, open-source AI for security pros in air-gapped environments.
Y2K38 as a security risk for vulnerable systems today. Not in 12 years, but right now.
https://ift.tt/JHZmxT0
Submitted January 24, 2026 at 12:44AM by JollyCartoonist3702
via reddit https://ift.tt/ElFRPT3
https://ift.tt/JHZmxT0
Submitted January 24, 2026 at 12:44AM by JollyCartoonist3702
via reddit https://ift.tt/ElFRPT3
Bitsight
Forward to the Past: The Y2K38 Problem Ahead | Bitsight
The Y2K38 problem threatens legacy 32-bit systems in 2038. Understand the risks, affected systems, and mitigation strategies.
Correctly interpreting DMARC, SPF, and DKIM enforcement in DNS security
https://ift.tt/SZDau4K
Submitted January 24, 2026 at 03:31AM by Odd_Woodpecker_6286
via reddit https://ift.tt/C7MrXg6
https://ift.tt/SZDau4K
Submitted January 24, 2026 at 03:31AM by Odd_Woodpecker_6286
via reddit https://ift.tt/C7MrXg6
www.it-help.tech
DNS Security Best Practices: Defend Your Domain with DMARC, SPF & DKIM
Learn how to set up DMARC, SPF, & DKIM for robust DNS security. Protect your business email from spoofing, phishing, and BEC attacks with these best practices.
Prompt injection is No 1 Security threat for most systems.
https://ift.tt/KwLIPdo
Submitted January 24, 2026 at 03:47PM by Suchitra_idumina
via reddit https://ift.tt/Qkd3TJI
https://ift.tt/KwLIPdo
Submitted January 24, 2026 at 03:47PM by Suchitra_idumina
via reddit https://ift.tt/Qkd3TJI
Antijection
Prompt Injection: The Security Vulnerability That Can Compromise Your Entire System
Understanding the #1 LLM security threat before it takes down your database
BREAKMEIFYOUCAN! - Exploiting Keyspace Reduction and Relay Attacks in 3DES and AES-protected NFC Technologies
https://ift.tt/GYWipRS
Submitted January 25, 2026 at 06:48AM by netsec_burn
via reddit https://ift.tt/g8sFAjJ
https://ift.tt/GYWipRS
Submitted January 25, 2026 at 06:48AM by netsec_burn
via reddit https://ift.tt/g8sFAjJ
BREAKMEIFYOUCAN!
BREAKMEIFYOUCAN! - Exploiting Keyspace Reduction and Relay Attacks in 3DES and AES-protected NFC Technologies
Exploiting Keyspace Reduction and Relay Attacks in 3DES and AES-protected NFC Technologies. Reducing 2TDEA keyspace from 2¹¹² to 2²⁸.
Husn Canaries - Defense-in-Depth for AI Coding Assistant Governance
https://husncanary.com/
Submitted January 25, 2026 at 01:05PM by 0xRaindrop
via reddit https://ift.tt/HWv05uD
https://husncanary.com/
Submitted January 25, 2026 at 01:05PM by 0xRaindrop
via reddit https://ift.tt/HWv05uD
Husn Canaries
Husn Canaries - Defense-in-Depth for AI Coding Assistant Governance
Research by Ehab Hussein & Mohamed Samy from IOActive on detecting unauthorized AI analysis of your code.
cvsweb.openbsd.org fights AI crawler bots by redirecting hotlinking requests to theannoyingsite.com (labelled "Malware" by eero), gets blacklisted by eero, too, for "Phishing & Deception"
https://ift.tt/jpDm63U
Submitted January 25, 2026 at 10:16PM by Mcnst
via reddit https://ift.tt/lnvkDes
https://ift.tt/jpDm63U
Submitted January 25, 2026 at 10:16PM by Mcnst
via reddit https://ift.tt/lnvkDes
Your Vibe Coded AI App Can Bankrupt You
https://ift.tt/iy1Seap
Submitted January 26, 2026 at 12:31AM by utku1337
via reddit https://ift.tt/kINLoDB
https://ift.tt/iy1Seap
Submitted January 26, 2026 at 12:31AM by utku1337
via reddit https://ift.tt/kINLoDB
Substack
Your Vibe Coded AI App Can Bankrupt You
Vibe coders may not realize they could wake up to a $20,000 cloud bill. This article explains the risks and how to avoid them.
địt mẹ mày morphisec: When Malware Authors Taunt Security Researchers
https://ift.tt/GZSTV2B
Submitted January 26, 2026 at 02:04AM by GelosSnake
via reddit https://ift.tt/VLJrU1M
https://ift.tt/GZSTV2B
Submitted January 26, 2026 at 02:04AM by GelosSnake
via reddit https://ift.tt/VLJrU1M
profero.io
địt mẹ mày morphisec: When Malware Authors Taunt Security Researchers
The complete analysis of Vietnamese Stealer a Python-based info stealer using Telegram as a C2.
/r/netsec's Q1 2026 Information Security Hiring Thread
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.iss.onention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted January 26, 2026 at 06:59AM by netsec_burn
via reddit https://ift.tt/9KF12cT
OverviewIf you have open positions at your company for information security professionals and would like to hire from the /r/netsec user base, please leave a comment detailing any open job listings at your company.We would also like to encourage you to post internship positions as well. Many of our readers are currently in school or are just finishing their education.Please reserve top level comments for those posting open positions.Rules & GuidelinesInclude the company name in the post. If you want to be topsykret, go recruit elsewhere. Include the geographic location of the position along with the availability of relocation assistance or remote work.If you are a third party recruiter, you must disclose this in your posting.Please be thorough and upfront with the position details.Use of non-hr'd (realistic) requirements is encouraged.While it's fine to link to the position on your companies website, provide the important details in the comment.iss.onention if applicants should apply officially through HR, or directly through you.Please clearly list citizenship, visa, and security clearance requirements.You can see an example of acceptable posts by perusing past hiring threads.FeedbackFeedback and suggestions are welcome, but please don't hijack this thread (use moderator mail instead.)
Submitted January 26, 2026 at 06:59AM by netsec_burn
via reddit https://ift.tt/9KF12cT
Reddit
From the netsec community on Reddit
Explore this post and more from the netsec community
Certificate Transparency as Communication Channel
https://latedeployment.github.io/posts/certificate-transparency-as-communication-channel/
Submitted January 26, 2026 at 12:52AM by MembershipOptimal777
via reddit https://ift.tt/alvrwKd
https://latedeployment.github.io/posts/certificate-transparency-as-communication-channel/
Submitted January 26, 2026 at 12:52AM by MembershipOptimal777
via reddit https://ift.tt/alvrwKd
A lazy blog
Certificate Transparency as Communication Channel
This is part three of the Certificate Transparency series.
Introduction
Described here is a way to leverage the infrastructure used to validate certificates in order to distribute messages through the Certificate Transparency Logs.
Introduction
Described here is a way to leverage the infrastructure used to validate certificates in order to distribute messages through the Certificate Transparency Logs.
"Open sesame": Critical vulnerabilities in dormakaba physical access control system enable unlocking arbitrary doors
https://ift.tt/bdiNeZk
Submitted January 26, 2026 at 04:21PM by 0x9000
via reddit https://ift.tt/51WADZR
https://ift.tt/bdiNeZk
Submitted January 26, 2026 at 04:21PM by 0x9000
via reddit https://ift.tt/51WADZR
SEC Consult
Hands-Free Lockpicking: Critical Vulnerabilities in dormakaba’s Physical Access Control System
AI Finds Vulnerability Chain Leading to Account Takeover and Leaked Bookings
https://ift.tt/saj4HeA
Submitted January 26, 2026 at 07:14PM by Same-Cauliflower-830
via reddit https://ift.tt/gmEYGpl
https://ift.tt/saj4HeA
Submitted January 26, 2026 at 07:14PM by Same-Cauliflower-830
via reddit https://ift.tt/gmEYGpl
www.gecko.security
How Broken Access Controls in Cal.com Leaked Millions of Bookings and Enabled Complete Account Takeover | Gecko Security
Gecko's AI security engineer discovered critical chained vulnerabilities in Cal.com Cloud that allowed complete account takeover and exposed all booking data.
After reporting vulnerabilities found in MDT, Microsoft chose to retire the service rather than fix the issues... Admins should follow the defensive recommendations to mitigate the issues if they choose to continue using the software or can’t migrate to a different solution.
https://ift.tt/6lgExRB
Submitted January 26, 2026 at 07:04PM by TheDarthSnarf
via reddit https://ift.tt/jiLETyK
https://ift.tt/6lgExRB
Submitted January 26, 2026 at 07:04PM by TheDarthSnarf
via reddit https://ift.tt/jiLETyK
SpecterOps
Task Failed Successfully - Microsoft’s “Immediate” Retirement of MDT - SpecterOps
After reporting vulnerabilities found in MDT, Microsoft chose to retire the service rather than fix the issues. As of January 6, 2025, Microsoft stopped supporting MDT and will no longer provide updates, including security patches.
Bypassing Windows Administrator Protection
https://ift.tt/l7TnPW5
Submitted January 26, 2026 at 11:26PM by thewhippersnapper4
via reddit https://ift.tt/gZbyEd8
https://ift.tt/l7TnPW5
Submitted January 26, 2026 at 11:26PM by thewhippersnapper4
via reddit https://ift.tt/gZbyEd8
projectzero.google
Bypassing Windows Administrator Protection - Project Zero
A headline feature introduced in the latest release of Windows 11, 25H2 is Administrator Protection. The goal of this feature is to replace User Account Cont...
Kubernetes Remote Code Execution Via Nodes/Proxy GET Permission
https://ift.tt/0sANbd9
Submitted January 27, 2026 at 02:08AM by safeaim
via reddit https://ift.tt/rZpwWsl
https://ift.tt/0sANbd9
Submitted January 27, 2026 at 02:08AM by safeaim
via reddit https://ift.tt/rZpwWsl
Graham Helton
Kubernetes Remote Code Execution
Via Nodes/Proxy GET Permission
Via Nodes/Proxy GET Permission
An authorization bypass in
Kubernetes RBAC allows for nodes/proxy GET permissions to execute
commands in any Pod in the cluster.
Kubernetes RBAC allows for nodes/proxy GET permissions to execute
commands in any Pod in the cluster.