Security Flaws In Carmaker's Web Portal Let a Hacker Remotely Unlock Cars

Some minor bugs in Proton's new Authenticator app

I'm concerned (excerpt)

Silver State Goes Dark as Cyberattack Knocks Nevada Websites Offline

Unpacking Passkeys Pwned: Possibly the most specious research in decades

Emailing a one-time code is worse than passwords

Phrack 72

Doge uploaded live copy of Social Security database to 'vulnerable' cloud server

Maintainers of Last Resort

The vulnerability might be in the proof-of-concept

Is it possible to allow sideloading and keep users safe?

When Flatpak's Sandbox Cracks

SystemD Service Hardening

Inspecting OpenPGP certificates

That 16B password story (a.k.a. "data troll")

Ghrc.io appears to be malicious

I hacked Monster Energy

Introduction to Unikernel: Building, deploying lightweight, secure applications

Rethinking the Linux cloud stack for confidential VMs

libxml2 Maintainer Ends Embargoed Vulnerability Reports, Citing Unsustainable Burden

Phishing Training Is Pretty Pointless, Researchers Find

PyPI Preventing Domain Resurrection Attacks

Marshal madness: A brief history of Ruby deserialization exploits

Abusing Entra OAuth for fun and access to internal Microsoft applications

pure: A static analysis file format checker for Zip files

Why are anime catgirls blocking my access to the Linux kernel?

How to rig elections [video]

Unikernel Guide: Build and Deploy Lightweight, Secure Apps

MadeYouReset: Turning HTTP/2 Server Against Itself

maybenot: a framework for traffic analysis defenses

More →