Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Why I no longer have an old-school cert on my HTTPS site

Tachy0n: The Last 0day Jailbreak

I used o3 to find a remote zeroday in the Linux SMB implementation

Education Giant Pearson Hit By Cyberattack Exposing Customer Data

KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS

One-Click RCE in Asus's Preinstalled Driver Software

Most AI Chatbots Easily Tricked Into Giving Dangerous Responses, Study Finds

Multiple Security Issues in Screen

Leeks and Leaks

A critical look at MCP

Those Stealthy Botnets

SMS 2FA is not just insecure, it's also hostile to mountain people

proposal: net/http: add CrossOriginForgeryHandler

Hundreds of E-Commerce Sites Hacked In Supply-Chain Attack

Remote Prompt Injection in Gitlab Duo Leads to Source Code Theft

I ruined my vacation by reverse engineering WSC

Can you trust that permission pop-up on macOS?

Stop Saying "Responsible Disclosure"

Firefox Security Response to pwn2own 2025

Oracle VM VirtualBox – VM Escape via VGA Device

By default, Signal doesn't recall

Breaking the Sound Barrier Part I: Fuzzing CoreAudio with Mach Messages

proposal: net/http: add CrossOriginForgeryHandler

The Path to Memory Safety is Inevitable

DanaBot Malware Devs Infected Their Own PCs

The State of SSL Stacks

curl's CI job for spotting domain squatting

Postman is logging all your secrets and environment variables

"Safe" YAML monster

Introducing oniux: Kernel-level Tor isolation for any Linux app

More →