Security News
- SHA Pinning Is Not Enough
- Turning a Raspberry Pi into a "Poor Man's" Enterprise IDS/NSM using Zeek and Suricata
- red team sandbox with real detection
- The [LinkedIn browsergate] Attack: How it works
- Your terminal is lying to you: escape sequence attacks from the 90s that still work.
- Mongoose: Preauth RCE and mTLS Bypass on Millions of Devices
- You’re Not Supposed To ShareFile With Everyone (Progress ShareFile Pre-Auth RCE Chain CVE-2026-2699 & CVE-2026-2701) - watchTowr Labs
- 4 unpatched CVEs in CrewAI chain prompt injection → sandbox bypass → RCE on host
- Cisco source code stolen by ShinyHunters via Trivy supply-chain attack. AWS keys breached, 300+ repos cloned and more
- r/netsec monthly discussion & tool thread