Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

RCE Vulnerabilities in K8s Ingress Nginx (9.8 CVE for ingress-Nginx)

Undocumented backdoor found in Bluetooth chip used by a billion devices

You might want to stop running atop

You should know this before choosing Next.js

Oracle customers confirm data stolen in alleged cloud breach is valid

NixOS and reproducible builds could have detected the xz backdoor

Blasting Past WebP - An analysis of the NSO BLASTPASS iMessage exploit

Whose code am I running in GitHub Actions?

Rayhunter: A New Open-Source Tool from EFF to Detect Cellular Spying

Problems with the heap

Avoid building a security treadmill

Memory Corruption in Delphi

Password reuse is rampant: nearly half of observed user logins are compromised

Memory safety for web fonts

Landrun: Sandbox any Linux process using Landlock, no root or containers

Chunking Attacks on File Backup Services Using Content-Defined Chunking [pdf]

Thousands of TP-Link Routers Have Been Infected By a Botnet To Spread Malware

Feds Link Cyberheist to 2022 LastPass Hacks

Tunneling corporate firewalls for developers

Towards a test suite for TOTP codes

CVE-2024-9956 – PassKey Account Takeover in All Mobile Browsers

Operationalizing Macaroons

Cloudflare: Trapping misbehaving bots in an AI Labyrinth

Bypassing Authentication Like It’s The ‘90s - Pre-Auth RCE Chain(s) in Kentico Xperience CMS

Shellcode Encoded in UUIDs

Apache Tomcat CVE-2025-24813: What You Need to Know

Private Data and Passwords of Senior U.S. Security Officials Found Online

The insecurity of telecom stacks in the wake of Salt Typhoon

CDC attack mitigation in Plakar

Reviving the modprobe_path Technique: Overcoming search_binary_handler() Patch

More →