CVE-2025-11730: Remote Code Execution via DDNS configuration in ZYXEL ATP/USG Series (V5.41)
https://ift.tt/oyJLOYe
Submitted February 05, 2026 at 12:23PM by Advanced_Rough8330
via reddit https://ift.tt/QsO19zX
https://ift.tt/oyJLOYe
Submitted February 05, 2026 at 12:23PM by Advanced_Rough8330
via reddit https://ift.tt/QsO19zX
Rainpwn
CVE-2025-11730: Remote Code Execution via DDNS configuration in ZYXEL ATP/USG Series (V5.41)
A critical vulnerability in Zyxel firewalls, allows remote command execution with root privileges through improper input sanitization in the Dynamic DNS (DDNS) configuration. By injecting shell commands into a user-controlled URL parameter, an authenticated…
New CentOS UAF to LPE vulnerability
https://ift.tt/KC5fob8
Submitted February 05, 2026 at 03:02PM by SSDisclosure
via reddit https://ift.tt/f0pqgQT
https://ift.tt/KC5fob8
Submitted February 05, 2026 at 03:02PM by SSDisclosure
via reddit https://ift.tt/f0pqgQT
SSD Secure Disclosure
Linux Kernel net/sched CAKE Qdisc Use-After-Free LPE - SSD Secure Disclosure
Summary A local user under the CentOS 9 operating system can trigger an use-after-free, which in turn can be used to elevate to root privileges. Vendor Response The vendor has been notified more than 90 days ago and has offered the only feedback that: The…
Yara-X + PacketSmith Detection Module
https://ift.tt/s2jmDGr
Submitted February 05, 2026 at 06:48PM by MFMokbel
via reddit https://ift.tt/SyK93m6
https://ift.tt/s2jmDGr
Submitted February 05, 2026 at 06:48PM by MFMokbel
via reddit https://ift.tt/SyK93m6
PacketSmith
Yara-X + PacketSmith Detection Module - PacketSmith
Yara-X + PacketSmith Detection Module A Sneak Peek Introduction Version 5 of PacketSmith, codenamed Pinus strobus, is the result of extensive R&D to add unique, unparalleled features that matter to network detection engineers, SoC analysts, and malware and…
Django SQL Injection in RasterField lookup (CVE-2026-1207)
https://ift.tt/X0ANszu
Submitted February 06, 2026 at 12:24AM by c0daman
via reddit https://ift.tt/Nd0Jbcl
https://ift.tt/X0ANszu
Submitted February 06, 2026 at 12:24AM by c0daman
via reddit https://ift.tt/Nd0Jbcl
Sentience, Allegedly
https://ift.tt/mxLcUfo
Submitted February 06, 2026 at 05:40AM by RMunizIII
via reddit https://ift.tt/a0hrv5C
https://ift.tt/mxLcUfo
Submitted February 06, 2026 at 05:40AM by RMunizIII
via reddit https://ift.tt/a0hrv5C
Substack
Sentience, Allegedly
Last week, AI founded a lobster-themed religion, developed a drug trade, and started hiring humans. What now?
I reversed Tower of Fantasy's kernel anti-cheat driver while waiting for the game to install. It's a full BYOVD toolkit that's never even loaded.
https://ift.tt/IlfgaQq
Submitted February 06, 2026 at 06:58AM by RadioactiveBlanket
via reddit https://ift.tt/ZVxv8gr
https://ift.tt/IlfgaQq
Submitted February 06, 2026 at 06:58AM by RadioactiveBlanket
via reddit https://ift.tt/ZVxv8gr
Vespalec
Tower of Flaws: Dismantling Tower of Fantasy's Anti-Cheat Driver While Waiting for The Game to Install
How four layers of authentication in a production anti-cheat driver still hand you a complete BYOVD toolkit
Hacking a cheap Wi-Fi toy drone
https://ift.tt/FotCrmq
Submitted February 06, 2026 at 12:40PM by fhackdroid
via reddit https://ift.tt/q169jvr
https://ift.tt/FotCrmq
Submitted February 06, 2026 at 12:40PM by fhackdroid
via reddit https://ift.tt/q169jvr
The RCE that AMD won't fix!
https://mrbruh.com/amd/
Submitted February 06, 2026 at 03:52PM by moviuro
via reddit https://ift.tt/j9VTtpn
https://mrbruh.com/amd/
Submitted February 06, 2026 at 03:52PM by moviuro
via reddit https://ift.tt/j9VTtpn
Mrbruh
MrBruh's Epic Blog
Temporarily taken down due to a request, will be back at a later date :) In the meantime, you can read another of my write-ups here: 1.4 Billion exposed user records via insecure Firebase instances in top Android apps
Experiment demonstrates Al-generated identities bypassing KYC-based verification systems
https://ift.tt/coEUBNt
Submitted February 06, 2026 at 03:49PM by Gullible_Bet_7899
via reddit https://ift.tt/9WvTBtS
https://ift.tt/coEUBNt
Submitted February 06, 2026 at 03:49PM by Gullible_Bet_7899
via reddit https://ift.tt/9WvTBtS
Metaverse Post
Humanity Protocol Experiment Reveals How AI Can Bypass KYC And Exploit Digital Trust
Humanity Protocol’s controlled experiment showed that AI can create convincing fake profiles to bypass identity verification, exposing critical weaknesses in traditional KYC systems and highlighting the growing risk of AI-driven fraud online.
Tool: AST-based security scanner for AI-generated code (MCP server)
https://ift.tt/mc6CoVt
Submitted February 06, 2026 at 09:55PM by NoButterfly9145
via reddit https://ift.tt/rbwKiQ3
https://ift.tt/mc6CoVt
Submitted February 06, 2026 at 09:55PM by NoButterfly9145
via reddit https://ift.tt/rbwKiQ3
AI Agents’ Most Downloaded Skill Is Discovered to Be an Infostealer
https://ift.tt/ahdy5Hm
Submitted February 06, 2026 at 11:40PM by Malwarebeasts
via reddit https://ift.tt/eyDM3Gk
https://ift.tt/ahdy5Hm
Submitted February 06, 2026 at 11:40PM by Malwarebeasts
via reddit https://ift.tt/eyDM3Gk
InfoStealers
AI Agents’ Most Downloaded Skill Is Discovered to Be an Infostealer
Stay informed with the latest insights in our Infostealers weekly report. Explore key findings, trends and data on info-stealing activities.
crypto-scanner: Open-source CLI tool to find quantum-vulnerable cryptography in your codebase
https://ift.tt/JxXf0lT
Submitted February 07, 2026 at 07:11AM by MindlessConclusion42
via reddit https://ift.tt/fWoIhw8
https://ift.tt/JxXf0lT
Submitted February 07, 2026 at 07:11AM by MindlessConclusion42
via reddit https://ift.tt/fWoIhw8
PyPI
crypto-scanner
CLI tool for scanning cryptographic usage and generating quantum-vulnerability risk assessments
trappsec: open source framework for API deception
https://trappsec.dev
Submitted February 07, 2026 at 08:29PM by nikhil-salgaonkar
via reddit https://ift.tt/e98Binm
https://trappsec.dev
Submitted February 07, 2026 at 08:29PM by nikhil-salgaonkar
via reddit https://ift.tt/e98Binm
trappsec
Introduction
deception as a developer tool
Cloud Deception Management Platform (Open-source Cloud Canaries)
https://ift.tt/JiIyn7d
Submitted February 08, 2026 at 12:50AM by John_Earle
via reddit https://ift.tt/RjlcIgX
https://ift.tt/JiIyn7d
Submitted February 08, 2026 at 12:50AM by John_Earle
via reddit https://ift.tt/RjlcIgX
Vimeo
Coalmine[Alpha] WebUI Walkthrough Overview
This is an early alpha of Coalmine an opensource cloud canary management tool
New OSS secret scanner: Kingfisher (Rust) validates exposed creds + maps permissions
https://ift.tt/f1iAVZt
Submitted February 07, 2026 at 11:48PM by micksmix
via reddit https://ift.tt/8XakdWU
https://ift.tt/f1iAVZt
Submitted February 07, 2026 at 11:48PM by micksmix
via reddit https://ift.tt/8XakdWU
MongoDB
Introducing Kingfisher: Real-Time Secret Detection And Validation
Discover Kingfisher, MongoDB’s open-source tool for security and DevOps engineers to detect and validate exposed secrets in code and repositories.
macOS Touch ID/Bio-metric kill switch like iPhone has - PanicLock
https://paniclock.github.io/
Submitted February 08, 2026 at 04:34PM by seanieb
via reddit https://ift.tt/zhldLjF
https://paniclock.github.io/
Submitted February 08, 2026 at 04:34PM by seanieb
via reddit https://ift.tt/zhldLjF
paniclock.github.io
PanicLock - Panic Button for Your Mac
PanicLock - Keep Touch ID for daily convenience, get instant password-only security when you need it. Your Mac's escape hatch for border crossings, protests, and high-risk situations.
OverTheWire Bandit: a complete walkthrough with in-depth explanations
https://ift.tt/pNfMbB0
Submitted February 08, 2026 at 08:20PM by shelltief
via reddit https://ift.tt/HkGMuBT
https://ift.tt/pNfMbB0
Submitted February 08, 2026 at 08:20PM by shelltief
via reddit https://ift.tt/HkGMuBT
Defense Evasion: The Service Run Failed Successfully
https://ift.tt/6osVSMU
Submitted February 08, 2026 at 07:51PM by Cold-Dinosaur
via reddit https://ift.tt/TDtxJLw
https://ift.tt/6osVSMU
Submitted February 08, 2026 at 07:51PM by Cold-Dinosaur
via reddit https://ift.tt/TDtxJLw
Zerosalarium
Defense Evasion: The Service Run Failed Successfully
RecoverIt uses penetration testing techniques to exploit service failure recovery functions to trigger the execution of malicious payloads.
Vouch: earn the right to submit a pull request
https://ift.tt/OlQyVsC
Submitted February 08, 2026 at 11:58PM by jpcaparas
via reddit https://ift.tt/QmnGFis
https://ift.tt/OlQyVsC
Submitted February 08, 2026 at 11:58PM by jpcaparas
via reddit https://ift.tt/QmnGFis
Medium
Vouch: earn the right to submit a pull request
Mitchell Hashimoto got tired of AI PR slop, so he built Vouch: a trust management system that could change how open source handles…