Loading...

Tag trends are in beta. Feedback? Thoughts? Email me at [email protected]

Is sandboxing sufficient to contain rogue agents?

Major rsync upgrade in Debian because of 33 CVEs

ESXi Exploitation in the Wild

Pastoralist, a tool to manage package overrides, including security fixes

Be alert: targeted attacks on prominent Rustaceans

Flock cameras are riddled with security vulnerabilities and hardcoded creds

Fake Express Packages on npm Spread a Linux Worm

What happened to the Snowden archive

Sourcehut account takeover via build logs (XSS in ansi2html)

Apple Reference Image: A New Approach for Verified Photography

GitHub Actions leaking secrets when Miri output is cached

Revealing the details of how OpenAI agents hacked Hugging Face

I don't like passkeys

Sandboxing with minimal effort

stack unwinding can lead to leakless code execution

SAML: A fractal of bad design

I Found a $113,337 Af_alg Linux Local Privilege Escalation Before Copy Fail

Understanding NvPCRs in systemd v262

Cross-Site Scripting (XSS) Cheat Sheet

Rare Not Random Using Token Efficiency for Secrets Scanning

Package Manager Trends

attezt: device attestation, PKCS11 and ACME

Forgejo <=16.0.3 Critical RCE

The Cuckoo's Egg

Security Incident – BGP Hijacking

Getting root on OnePlus 15 from an untrusted app

Bulk AbuseIPDB reporting using command-line tools

LuaRocks Security Incident September 2026

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

Knowledge Retention & Sharing in DF/IR

More →