Training Solo: On the Limitations of Domain Isolation Against Spectre-v2 Attacks
Comments ⌘ Read more
DCShadow Attacks: Subverting Active Directory Replication for Stealthy Persistence
Technique that allows adversaries to manipulate directory data by simulating the behavior of a legitimate Doma … ⌘ Read more
Master CRLF Injection: The Underrated Bug with Dangerous Potential
Learn how attackers exploit CRLF Injection to manipulate HTTP responses, hijack headers and unlock hidden vulnerabilities in modern web…
[Continue rea … ⌘ Read more
A Guide to SQL Injection Attacks: Hackers Don’t Want You to Know This!
Imagine your website as a big toy box filled with treasures — like user info, passwords, or blog posts — and you’ve got a robot helper…
[Contin … ⌘ Read more
Stop Uncapped Cloud Billing
This emerging community was created when its author got a single-day cloud bill of $97k due to a DoS attack that killed his small business.
i love it when k-pop girls get to do unusual genres. you ever wanted to hear a k-pop girl group do something massive attack-ish with a bit of breakbeat? well we got it https://www.youtube.com/watch?v=jy0qJC6IbgY
Secure your Python applications: Best practices for developers
Practical security tips every Python developer should know — from dependency safety to protecting against injection attacks and securing…
[Continue reading on InfoSec Write … ⌘ Read more
**IDOR Attacks Made Simple: How Hackers Access Unauthorized Data **
IDOR Attacks Made Simple: How Hackers Access Unauthorized Data 🔐
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/idor-attacks-made-simple-h … ⌘ Read more
So, the “AI” bots have reached my website. Looks like they’re just slowly crawling everything at the moment – no DDoS-like attack yet. I wonder if that has something to do with my website being 100% static HTML. There are no GET parameters they can tweak and, at the end of the day, there’s not that much data on my server anyway … And maybe they have no idea what stagit is, so it doesn’t trigger “standard behavior”, like “this is a Gitea instance, let’s crawl this like crazy!”?
** The $2500 bug: Remote Code Execution via Supply Chain Attack** ⌘ Read more
Does anyone else wakes up to their feet being groomed and attacked every morning 🌅 ⌘ Read more
**Path Traversal Attack: How I Accessed Admin Secrets **
Path Traversal Attack: How I Accessed Admin Secrets 📂
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/path-traversal-attack-how-i-accessed-admin-secrets-fa5de1865031?source … ⌘ Read more
Top 5 Open Source Tools to Scan Your Code for Vulnerabilities
These tools help you find security flaws in your code before attackers do.
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/top-5-open-source-tools-to-s … ⌘ Read more
How to Create a Botnet Using One Tool: A Proof of Concept for Educational Purposes Aspiring…
Learn how attackers build and control botnets — safely and ethically — using … ⌘ Read more
CNCF Announces Graduation of in-toto Security Framework, Enhancing Software Supply Chain Integrity Across Industries
NYU Tandon-developed software security framework achieves highest CNCF maturity level, combating rising software supply chain attacks SAN FRANCISCO, CA, April 23, 2025 – The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native… ⌘ Read more
@aelaraji@aelaraji.com sounds like a panic attack to me 🤯
Also, I should cut down on coffee. Seriously, I’ve nearly had a … I honestly don’t know what it was; A Panic attack? A heart attack? I dunno, I just felt like my heart and lungs were so about to burst I had to go for a run to cope.
Update. This is the face of a cat who got sent home cause he attacked the vet and now has to come back drugged up. ⌘ Read more
SHE SURVIVED! She was attacked by a male cat when I found her downstairs. Thought she would be gone, but she survived!🥹 ⌘ Read more
️ Blind XSS Attack in Production: My Favorite Exploit with a Delayed Surprise
Free Article Link
[Continue reading on InfoSec Write-ups »](https://infosecwriteups.com/%EF%B8%8F-bli … ⌘ Read more
@eapl.me@eapl.me This is one of my concerns too. The moment you post publicly ciphertext, you open yourself up for future attacks on the ciphertext, which you really want to avoid if you can. If you have a read of the Salty.im Spec you’ll note we went to great lengths to protect the user’s privacy as well as their identity and make it incredibly hard to guess at inboxes. It’s still a WIP, but I’d love to see it progressed even further – I truly feel strongly about a purely decentralised messaging ecosystem 👌
(#2zhuzoa) @eapl.me@eapl.me This is one of my concerns too. The moment you post publicly ciphertext, you open yourself up for future attacks on …
@eapl.me @eapl.me This is one of my concerns too. The moment you post publicly ciphertext, you open yourself up for future attacks on the ciphertext, which you really want to avoid if you can. If you have a read of the Salty.im Spec you’ll note we went to great lengths to protect the user’s … ⌘ Read more
There’s one way you can make your super more secure
Super funds are attractive targets for hackers, and recent attacks on funds have put the sector’s security practices under the microscope. ⌘ Read more
Reputation Lag Attack - Computerphile ⌘ Read more
I can live without my phone, survive without my keys, and replace my wallet… But when the cat disappears? Instant heart attack. ⌘ Read more
10 People Who Were Attacked for the Clothes They Wore
Black clothing. A sweatshirt. A “too small” skirt. A “blasphemous” dress. A crop top. Pretentious attire. Hats. A bikini. Jeans. Zoot suits. These clothes outraged some, who associated the articles of clothing with devil worship, immorality, nontraditional attire, and beliefs, attitudes, or behaviors that outraged the spectators. The attacks weren’t really about the victims’ clothing. […]
The post [10 People Who Were Attacke … ⌘ Read more
How Each Pillar of the First Amendment Is Under Attack
Article URL: https://krebsonsecurity.com/2025/03/how-each-pillar-of-the-1st-amendment-is-under-attack/
Comments URL: https://news.ycombinator.com/item?id=43529707
Points: 533
# Comments: 266 ⌘ Read more
@kat@yarn.girlonthemoon.xyz it’s mostly under control now but jesus christ i almost had a panic attack
US government’s attack on free speech, science, and research is causing a brain drain
How do you create a brain drain and lose your status as eminent destination for scientists and researchers? The United States seems to be sending out questionnaires to researchers at universities and research institutes outside of the United States, asking them about their political leanings. Dutch universities are strongly advising Dutch researches not to respond … ⌘ Read more
Hi! i’m a paralyzed cat. When i was just one month old, i was attacked by a dog or a human and my spine was broken. This is how meowmy found me and adopted. Meowmy always helps me with difficulties in my daily life ⌘ Read more
FOSS infrastructure is under attack by AI companies
What do SourceHut, GNOME’s GitLab, and KDE’s GitLab have in common, other than all three of them being forges? Well, it turns out all three of them have been dealing with immense amounts of traffic from “AI” scrapers, who are effectively performing DDoS attacks with such ferocity it’s bringing down the infrastructures of these major open source projects. Being open source, and thus publicly accessible, means these scrapers have … ⌘ Read more
FOSS infrastructure is under attack by AI companies
Article URL: https://thelibre.news/foss-infrastructure-is-under-attack-by-ai-companies/
Comments URL: https://news.ycombinator.com/item?id=43422413
Points: 545
# Comments: 317 ⌘ Read more
Legends of Open Source Under Attack by Leftist Extremists
The most prominent leaders in Free and Open Source Software (from Stallman to Torvalds) are regularly attacked, ostracized, or outright banned by Leftist Extremists. ⌘ Read more
This monster goes from licking my arm to attacking me, all while purring the whole time ⌘ Read more
C++ creator calls for help to defend programming language from ‘serious attacks’
Bjarne Stroustrup, creator of C++, has issued a call for the C++ community to defend the programming language, which has been shunned by cybersecurity agencies and technical experts in recent years for its memory safety shortcomings. C and C++ are built around manual memory management, which can result in memory safety errors, such as out of bounds reads and writes, though bo … ⌘ Read more
The cat attack ⌘ Read more
PostmarketOS Joins Codeberg’s Fight Against “Right Wing Forces”
Following dubious announcement of attack by “Right Wing Forces” by Git hosting company, a Linux Phone OS project has joined their crusade. ⌘ Read more
Yeah nice try assholes 🤣 #failed #phissing #sms href=”https://we.loveprivacy.club/search?q=%23attack”>#attack**
Yeah nice try assholes 🤣
#failed #phissing #sms #attack ⌘ Read more
New speculative attacks on Apple CPUs
Article URL: https://predictors.fail/
Comments URL: https://news.ycombinator.com/item?id=42856023
Points: 502
# Comments: 180 ⌘ Read more
10 Most Effective Surprise Attacks in Military History
The surprise attack has been a cornerstone of military strategy throughout most of human history. While true surprise attacks are a little more difficult to coordinate on a mass scale in the modern age of warfare, they remain reference points for how to conduct the most effective kind of military campaign: the kind that minimizes […]
The post [10 Most Effective Surprise Attacks in Military History](https://listverse.com/20 … ⌘ Read more
AI bots paralyze Linux news site and others
Apparently, since the beginning of the year, AI bots have been ensuring that websites can only respond to regular inquiries with a delay. The founder of Linux Weekly News (LWN-net), Jonathan Corbet, reports that the news site is therefore often slow to respond. The AI scraper bots cause a DDoS, a distributed denial-of-service attack. At times, the AI bots would clog the lines with hundreds of IP addresses simultaneously as soon as they decided … ⌘ Read more
Attacks on Maven proxy repositories
Learn how specially crafted artifacts can be used to attack Maven repository managers. This post describes PoC exploits that can lead to pre-auth remote code execution and poisoning of the local artifacts in Sonatype Nexus and JFrog Artifactory.
The post Attacks on Maven proxy repositories appeared first on The GitHub Blog. ⌘ Read more
0-click deanonymization attack targeting Signal, Discord, other platforms
Article URL: https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117
Comments URL: https://news.ycombinator.com/item?id=42780816
Points: 503
# Comments: 179 ⌘ Read more
[ANN] Unique 0-click deanonymization attack targeting Signal, Discord and hundreds of platform
Link: https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117
@basses:matrix.org ⌘ Read more
[ANN] Attacks on onion monero nodes with HSDirSniper
Based on connection issues and the monero node trackers, I believe someone is carrying out attacks on monero nodes that have onion addresses using the HSDirSniper attack for tor.
Link: https://farside.link/libreddit/r/Monero/comments/1i2uv5y/
u/jackintosh157 (Reddit) ⌘ Read more
お知らせ:JPCERT/CC Eyes「あなたではなく組織の財産を狙うLinkedIn経由のコンタクトにご用心」 ⌘ Read more
(#tw5ulrq) @bender@bender you’re right the scale wasn’t that large, but analyzing the logs. It definitely was a detox attack. 🤣 I woke up …
@bender you’re right the scale wasn’t that large, but analyzing the logs. It definitely was a detox attack. 🤣 I woke up this morning to see six other small spikes like this which I’ll have to analyze later tonight… ⌘ Read more
**So I need to figure out how to block ASN(s)…
Additionally, I’ thinking of; How to detect DDoS attachs?
Here’s one way I’ve come up that’s qu …**
So I need to figure out how to block ASN(s)…
Additionally, I’ thinking of; How to detect DDoS attachs?
Here’s one way I’ve come up that’s quite simple:
Detecting DDoS attacks by tracking requests across multiple IPs in a sliding window. If total requests exceed a threshold in a given time, flag as potential DDoS. ⌘ Read more