Последние посты

Security Harvester
22 сент., 18:06
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/@secharvesterBleepingComputerEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsThe EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
Security Harvester
22 сент., 18:06
Leaked GitHub App private keys let researchers impersonate 440 apps including CDC and BuildBuddy https://blog.gitguardian.com/github-app-private-keys-leaked/@secharvesterGitGuardian Blog - Take Control of Your Secrets SecurityGitHub App Private Keys: 474 Leaked Keys Still WorkGitGuardian tested thousands of leaked GitHub App private keys and found 474 valid ones, some with admin access to entire organizations. CDC and BuildBuddy were among those affected. See the findings.
Security Harvester
22 сент., 18:06
Breaking Down Appsec Part 5: You Have no Business Here (Business Logic Flaws) https://pigeonsec.substack.com/p/breaking-down-appsec-part-5-you-have@secharvesterSubstackBreaking Down Appsec Part 5: You Have no Business Here (Business Logic Flaws)Appsec is about where everything could go wrong, not just about the latest hacks
Security Harvester
22 сент., 15:09
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight https://www.wired.com/story/a-tool-for-tracking-ai-integrated-malware-uncovered-an-autonomous-command-system/@secharvesterWIREDA New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in SightCisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.
Security Harvester
22 сент., 12:08
I reverse-engineered Intel's NPU stack and got custom C kernels running on its programmable SHAVE cores https://github.com/hsfzxjy/npunlock@secharvesterGitHubGitHub - hsfzxjy/npunlock: Write and run custom C kernels for Intel Core Ultra NPUs, without OpenVINOWrite and run custom C kernels for Intel Core Ultra NPUs, without OpenVINO - hsfzxjy/npunlock
Security Harvester
22 сент., 12:08
CVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS) https://daubois.dev/blog/cve-2026-45756-symfony-jsonpath-redos/@secharvesterdaubois.devCVE-2026-45756: attacker-controlled regex in Symfony JsonPath filters (ReDoS)A JSONPath filter taken from a query string lets an attacker pick the regex a Symfony app runs, once per node in the document.
Security Harvester
22 сент., 12:08
Updated hardware-compliance-handbook - open-source, fact-checked EU CRA/RED/NIS2/CSA reference. Added a dedicated /sbom/ folder (CycloneDX + SPDX examples, VEX). Also doubles as a Claude Skill. https://github.com/Platanor/hardware-compliance-handbook@secharvesterGitHubGitHub - Platanor/hardware-compliance-handbook: AI-ready knowledge base of security & compliance regulations for hardware and connected…AI-ready knowledge base of security & compliance regulations for hardware and connected-device manufacturers - structured, indexed, and machine-readable for LLMs and agents. - Platanor/hard...
Security Harvester
22 сент., 09:08
vCenter pre-auth RCE: CVE-2026-59309/59310 https://mobeta.fr/blog/vcenter-cve-2026-59309-cve-2026-59310/@secharvesterMobetavCenter pre-auth RCE: CVE-2026-59309/59310 | MobetaCVE-2026-59309 & CVE-2026-59310: patch-diffing VMware vCenter reveals two pre-auth 9.8 bugs - an auth bypass and a syslog path traversal to RCE.
Security Harvester
22 сент., 06:10
MacOS offensive security, detection engineering, and solo Apple research https://joinpwn.com/ama/olivia-gallucci@secharvesterPWNOlivia Gallucci AMA: Hacking macOS & Offensive Security | PWNSecurity engineer Olivia Gallucci on macOS internals, detection engineering, offensive security, and doing solo Apple research.
Security Harvester
22 сент., 06:09
FBI confirmed malicious cyber activity on a supertanker last week. Most coverage missed what allegedly happened inside the engine room OT systems. https://abxdefense.substack.com/p/someone-hacked-a-supertankers-engine@secharvesterSubstackSomeone Hacked a Supertanker's Engine Room. Here's What That Actually Means.Last week the FBI and US Coast Guard boarded two oil tankers in the Gulf of Mexico after finding evidence of malicious cyber activity on both vessels.
Security Harvester
22 сент., 06:09
Inside BambooToken’s Linux implant: shell and file control over MQTT https://app.reverser.space/p/duckie/inside-bambootoken-s-linux-implant-shell-and-file@secharvesterreverser.spaceInside BambooToken’s Linux implant: shell and file control over MQTT | Reverser SpaceBambooToken turns an MQTT broker into a remote-control hub for Linux. Behind a 59-byte configuration blob, hex-encoded topics, and repeating XOR lies a backdoor built...
Security Harvester
22 сент., 06:09
Hatchet OAuth state CSRF — CVE-2026-61687 https://vulnso.com/vuln/hatchet-unauthenticated-oauth-state-csrf-login-csrf-via-empty-state-collision-in-validateoauthstate@secharvesterVulnsoHatchet - Unauthenticated OAuth state CSRF / login-CSRF via empty-state collision in ValidateOAuthState### Summary Hatchet version v0.86.26 and below is vulnerable to OAuth state CSRF (login CSRF / account fixation). The vulnerable code clears the session `oauth_state_<integration>` value to the empty string `""` after a successful OAuth callback rather…
Security Harvester
22 сент., 03:09
Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/@secharvesterArs TechnicaMuse, Meta's extraordinarily privileged AI assistant, has a serious 0-dayA simple ClickFix attack is only one way to completely hijack the new agent.
Security Harvester
22 сент., 00:09
PureRAT – msbuild.exe Execution, C2 Extraction & .NET Evasion https://github.com/kaandemir993/PureRAT-msbuild.exe--C2-Extraction--Net-Evasion-Analysis@secharvesterGitHubGitHub - kaandemir993/PureRAT-msbuild.exe--C2-Extraction--Net-Evasion-Analysis: Reverse engineering analysis of PureRAT, a multi…Reverse engineering analysis of PureRAT, a multi-stage RAT that executes via msbuild.exe and communicates with C2 servers at pure8s.ddnsfree.com and 52.241.248.38. Uses .NET evasion techniques (Dis...
Security Harvester
22 сент., 00:09
Vulnerability Summary for the Week of September 14, 2026 https://www.cisa.gov/news-events/bulletins/sb26-264@secharvesterCybersecurity and Infrastructure Security Agency CISAVulnerability Summary for the Week of September 14, 2026 | CISAHigh Vulnerabilities PrimaryVendor -- Product Description Published CVSS Score Source Info
Security Harvester
22 сент., 00:09
Turns out 40% of MCP servers have zero authentication, and even the ones that do are broken https://p0.dev/blog/nobody-built-mcp-servers-to-hold-identity-they-do-anyway/@secharvesterP0 SecurityNobody built MCP servers to hold identity. They do anyway. - P0 SecurityThe identity plane your agents run on is whatever the last MCP server someone installed decided it should be. That is not the layer to leave to chance.
Security Harvester
21 сент., 21:09
Beyond MCP: A Workspace for Reverse Engineering https://reverser.space/blog/why-reverse-engineering-agents-need-a-shared-workspace@secharvesterreverser.spaceBeyond MCP: A Workspace for Reverse Engineering | Reverser SpaceAgents trace code while analysts verify findings. Shared sessions keep annotations, notes, and research history available when another analyst joins.
Security Harvester
21 сент., 21:09
Implant Encryption via the Dump Encoding Library https://ipurple.team/2026/09/21/dump-encoding-library/@secharvesterPurple TeamDump Encoding LibraryThe Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic impleme…
Security Harvester
21 сент., 21:09
Implant Encryption via the Dump Encoding Library https://ipurple.team/2026/09/21/dump-encoding-library/@secharvesterPurple TeamDump Encoding LibraryThe Windows Error Reporting Dump Encoding Library (WerEnc.dll) is a Microsoft signed DLL that can be abused by threat actors to encrypt their implant using a trusted Microsoft cryptographic impleme…
Security Harvester
21 сент., 21:09
Windows Exploitation Techniques: Dangling COM Object Registrations https://projectzero.google/2026/09/windows-dangling-com.html@secharvesterprojectzero.googleWindows Exploitation Techniques: Dangling COM Object RegistrationsThis short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in...
