One-Click Hack Against Popular Video Platform
https://ift.tt/Fc2YAfw
Submitted January 27, 2026 at 10:51PM by derp6996
via reddit https://ift.tt/sQ5MyUz
https://ift.tt/Fc2YAfw
Submitted January 27, 2026 at 10:51PM by derp6996
via reddit https://ift.tt/sQ5MyUz
Claroty
New Architecture, New Risks: One-Click to Pwn IDIS IP Cameras
Team82 uncovered a one-click remote-code execution vulnerability affecting IDIS Cloud Manager viewer that could be exploited to give an attacker the ability to view live video feeds, recordings, and search images on the video surveillance system.
Audited hypervisor kernel escapes in regulated environments — Ring 0 is the real attack surface
https://ift.tt/61Iq0Vf
Submitted January 27, 2026 at 10:30PM by NTCTech
via reddit https://ift.tt/XMYU98Z
https://ift.tt/61Iq0Vf
Submitted January 27, 2026 at 10:30PM by NTCTech
via reddit https://ift.tt/XMYU98Z
Rack2Cloud
Hypervisor Kernel Hardening: KASLR, SEDs & Drift Control
Stop hypervisor escapes. Compare KASLR vs HVCI, calculate SED TCO ($0.04/GB), and eliminate config drift. Deterministic engineering for Day 2 Ops.
Why code indexing matters for AI security tools
https://ift.tt/yMdYLg9
Submitted January 28, 2026 at 12:23AM by Same-Cauliflower-830
via reddit https://ift.tt/i2DV50G
https://ift.tt/yMdYLg9
Submitted January 28, 2026 at 12:23AM by Same-Cauliflower-830
via reddit https://ift.tt/i2DV50G
www.gecko.security
Why Static Analysis Struggles with Business Logic Vulnerabilities | Gecko Security
The gap between tracking where data flows and reasoning about whether the logic is correct.
OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows
https://ift.tt/dyk6Ug7
Submitted January 28, 2026 at 12:48AM by RedTermSession
via reddit https://ift.tt/hWPHLRu
https://ift.tt/dyk6Ug7
Submitted January 28, 2026 at 12:48AM by RedTermSession
via reddit https://ift.tt/hWPHLRu
Datadoghq
OpenSSL January 2026 Security Update: CMS and PKCS#12 Buffer Overflows
A deep dive into OpenSSL’s January 2026 CMS and PKCS#12 vulnerabilities, including a pre-auth stack overflow and a PKCS#12 parsing bug.
Safeguarding sources and sensitive information in the event of a raid
https://freedom.press/digisec/blog/safeguarding-sources-and-sensitive-information-in-the-event-of-a-raid/
Submitted January 28, 2026 at 02:00AM by FreedomofPress
via reddit https://ift.tt/pISAxUH
https://freedom.press/digisec/blog/safeguarding-sources-and-sensitive-information-in-the-event-of-a-raid/
Submitted January 28, 2026 at 02:00AM by FreedomofPress
via reddit https://ift.tt/pISAxUH
Freedom of the Press
Safeguarding sources and sensitive information in the event of a raid
Following the search of Washington Post reporter Hannah Natanson’s home, here are concrete steps to take to safeguard yourself and your sources
Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals
https://ift.tt/NPcwZQ3
Submitted January 28, 2026 at 09:24AM by bouncyhat
via reddit https://ift.tt/9SHOoJw
https://ift.tt/NPcwZQ3
Submitted January 28, 2026 at 09:24AM by bouncyhat
via reddit https://ift.tt/9SHOoJw
Praetorian
Corrupting the Hive Mind: Persistence Through Forgotten Windows Internals
Swarmer enables stealthy Windows registry persistence by exploiting mandatory user profiles and the Offline Registry API to bypass EDR detection. Learn how this technique leverages NTUSER.MAN files to modify the registry without triggering standard API monitoring.
[Research] Analysis of 74,636 AI Agent Interactions: 37.8% Contained Attack Attempts - New "Inter-Agent Attack" Category Emerges
https://ift.tt/NdKln7j
Submitted January 28, 2026 at 12:00PM by cyberamyntas
via reddit https://ift.tt/RimNwS6
https://ift.tt/NdKln7j
Submitted January 28, 2026 at 12:00PM by cyberamyntas
via reddit https://ift.tt/RimNwS6
raxe.ai
AI Threat Intelligence Report - Week 3, 2026
28,194 threats detected. Interactive analysis of AI attack patterns targeting LLMs and AI agents.
Blind Boolean-Based Prompt Injection
https://ift.tt/bvTJQGP
Submitted January 26, 2026 at 07:45PM by -rootcauz-
via reddit https://ift.tt/X2tfYkr
https://ift.tt/bvTJQGP
Submitted January 26, 2026 at 07:45PM by -rootcauz-
via reddit https://ift.tt/X2tfYkr
Medium
Blind Boolean-Based Prompt Injection
In this post, I introduce and demonstrate the attack method Blind Boolean-Based Prompt Injection (BBPI) which is a prompt injection…
CVE-2025-40551: SolarWinds WebHelpDesk RCE Deep-Dive and Indicators of Compromise
https://ift.tt/TKcnfpm
Submitted January 28, 2026 at 10:19PM by scopedsecurity
via reddit https://ift.tt/uMqw5zb
https://ift.tt/TKcnfpm
Submitted January 28, 2026 at 10:19PM by scopedsecurity
via reddit https://ift.tt/uMqw5zb
Horizon3.ai
CVE-2025-40551: SolarWinds WHD RCE
Horizon3.ai discovered multiple vulnerabilities in SolarWinds Web Help Desk that enable unauthenticated remote code execution.
Fun RCE in Command & Conquer: Generals
https://ift.tt/48ECdTm
Submitted January 28, 2026 at 09:32PM by jordan9001
via reddit https://ift.tt/sqkQdJE
https://ift.tt/48ECdTm
Submitted January 28, 2026 at 09:32PM by jordan9001
via reddit https://ift.tt/sqkQdJE
Atredis Partners
General Graboids: Worms and Remote Code Execution in Command & Conquer — Atredis Partners
[this work was conducted collaboratively by Bryan Alexander and Jordan Whitehead] This post details several vulnerabilities discovered in the popular online game Command & Conquer: Generals. We recently presented some of this work at an information security…
Limits of static guarantees under adaptive adversaries (G-CTR experience)
https://ift.tt/wOtMVy7
Submitted January 28, 2026 at 10:51PM by Obvious-Language4462
via reddit https://ift.tt/PnICtVD
https://ift.tt/wOtMVy7
Submitted January 28, 2026 at 10:51PM by Obvious-Language4462
via reddit https://ift.tt/PnICtVD
arXiv.org
Cybersecurity AI: A Game-Theoretic AI for Guiding Attack and Defense
AI-driven penetration testing now executes thousands of actions per hour but still lacks the strategic intuition humans apply in competitive security. To build cybersecurity superintelligence...
Tycoon 2FA phishing campaign abusing *.contractors domains for Gmail & Microsoft 365 credential harvesting
https://ift.tt/Ywzp2iv
Submitted January 29, 2026 at 04:55AM by anuraggawande
via reddit https://ift.tt/q5dALMQ
https://ift.tt/Ywzp2iv
Submitted January 29, 2026 at 04:55AM by anuraggawande
via reddit https://ift.tt/q5dALMQ
Malware Analysis, Phishing, and Email Scams
Tycoon 2FA Campaign Abusing *.contractors Domains for Gmail and Microsoft 365 Credential Harvesting
Overview Over the past few weeks, I have been tracking a credential harvesting campaign that repeatedly abuses newly registered *.contractors domains to deliver Gmail and Microsoft 365/Outlook phis…
Requesting security review: zero-knowledge one-time secret sharing tool
https://ift.tt/16FOK9q
Submitted January 29, 2026 at 10:12AM by iamnotatalker
via reddit https://ift.tt/WXDnS5z
https://ift.tt/16FOK9q
Submitted January 29, 2026 at 10:12AM by iamnotatalker
via reddit https://ift.tt/WXDnS5z
Sharemylogin
ShareMyLogin | Zero-Knowledge Credential Sharing
Share passwords and credentials securely with self-destructing, encrypted links. Zero-knowledge encryption means we never see your data.
Gakido - CRLF Injection
https://ift.tt/sypmv72
Submitted January 29, 2026 at 03:07PM by c0daman
via reddit https://ift.tt/Xio7vwT
https://ift.tt/sypmv72
Submitted January 29, 2026 at 03:07PM by c0daman
via reddit https://ift.tt/Xio7vwT
Rosecurify
Gakido - CRLF Injection
Security research, vulnerability disclosures, and application security insights.
One-click RCE on Clawd/Moltbot in 2 hours with an AI Hacking Agent
https://ift.tt/ozeVt3B
Submitted January 29, 2026 at 04:24PM by matosd
via reddit https://ift.tt/odbGNM0
https://ift.tt/ozeVt3B
Submitted January 29, 2026 at 04:24PM by matosd
via reddit https://ift.tt/odbGNM0
Ethiack
One-click RCE on Clawd/Moltbot in under 2 hours with an Autonomous Hacking Agent | Ethiack — Autonomous Ethical Hacking for continuous…
Our AI pentester, Hackian, found a RCE on Clawdbot/Moltbot by hacking it fully autonomously in under 2 hours. Learn how and read the logs in this blog.
Tool release: CVE Alert – targeted CVE email alerts by vendor/product
https://ift.tt/unR6qo9
Submitted January 30, 2026 at 01:20AM by CarlVon77
via reddit https://ift.tt/D83dLrH
https://ift.tt/unR6qo9
Submitted January 30, 2026 at 01:20AM by CarlVon77
via reddit https://ift.tt/D83dLrH
CVE Alert System
CVE-Alert helps organizations and individuals track Common Vulnerabilities and Exposures (CVEs) in real-time with vendor/product subscriptions and email notifications.
Object-capability SQL sandboxing for LLM agents — $1K CTF bounty to break it
https://ift.tt/CngFqIu
Submitted January 30, 2026 at 05:01AM by ryanrasti
via reddit https://ift.tt/Pvy4XrU
https://ift.tt/CngFqIu
Submitted January 30, 2026 at 05:01AM by ryanrasti
via reddit https://ift.tt/Pvy4XrU
Ryanrasti
Object-Capability SQL Sandboxing for LLM Agents
A defensive technique for constraining LLM agent database access using object-capabilities, plus a live CTF challenge.