tgindex
Security Harvester

Security Harvester

Статистика

On X too! X.com/secharvesterx Harvesting news about cyber security

Последний пост
15 авг.
Последнее чтение
15 авг.
Постов за неделю
82
Всего постов
90
Тип
открытый
Язык
und
Категория
Новости и СМИ
В каталоге с
12 авг.
Подписчики
9 515
+16 за 3 дн.
Сутки
+2
+0,02%
Неделя
 
Месяц
 
Просмотров на пост
89
40 постов
Вовлечённость
0,9%
к подписчикам
Постов в день
11,7
всего 90
Упоминаний
1
каналов
Охват размещения
оценка
1/24сутки в ленте
89
1/48двое суток
101
1/72трое суток
110

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • видео или голосовое, без подписи

  • hunt.md — a Markdown format for documenting/sharing threat hunts https://github.com/huntbase-io/hunt-md/: 1. Spec · Profiles · Contributing · Hunt library · Tooling A hunt.md file describes a hunt as a readable, git-diffable document and a typed graph of steps — queries, data collection, agent reasoning, decisions, human review, and response — that a compliant runtime can render, review, and run. 2. YAML frontmatter for metadata, one ## heading per step, fenced blocks for the work. 3. tools/huntmd is the reference converter + validator — stdlib + PyYAML only, so it vendors cleanly into a runtime's import path. @secharvester

  • Fingerprint Pro v4, deobfuscated and documented: CRC32 name erasure, XOR string vaults, and so much more. https://github.com/proofofbots/fingerprint-pro-internals/tree/main: 1. Third-party storage entries, proxy sessions and IP addresses are stripped before anything lands in the tree, and the stored frames are rebuilt from the published payloads rather than kept as sent. 2. This project is unofficial and not affiliated with, endorsed by or supported by them, and the logo above is a derivative of their mark used to identify what is documented here. 3. Contact, including takedown and legal enquiries: proofofbot@pm.me Documenting the internals of Fingerprint Pro's commercial agent, not the open-source FingerprintJS library @secharvester

  • Booting Apple's iPod 5.5G firmware: recovering the display transport from RetailOS's own parser instead of emulating the VideoCore https://github.com/siggifly/ipod-emulator: 1. Apple's own code the whole way: the bootloader brings up SDRAM, talks to the PCF50605 power chip over I²C, uploads firmware to the video co-processor, reads the partition table, DMAs 7.5 MB of RetailOS into memory, checksums it and jumps. 2. Or straight from the repository, with no clone — the packages have to be named, because the workspace root is a virtual manifest and cargo install will not guess: The recipes use whatever the setup screen was pointed at, so once you have done the above they need no arguments: --print also says where each path came from — environment, setup screen, or repository default — because a recipe with an input you cannot see in its command line is one you cannot check. 3. What I did was steer: decide what was worth chasing, push back... @secharvester

  • I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies https://mehmetince.net/part-1-6-systemic-risks-in-the-managed-postgresql-industry-extension-risks-are-real-exploiting-postgis-memory-corruption-bug-at-neondb-supabase-and-many-more/: 1. To be honest, I had no idea that over the following three months, I would spend all my free time outside my day job working on a research project I named “ Systemic Risks in the Managed PostgreSQL Industry ” finding vulnerabilities in number of different vendor that gave me cross-tenant access. 2. It presents a detailed case study of how a single vulnerability in a PostgreSQL extension with a four-star rating on the GitHub repo enabled me to achieve privilege escalation on NeonDB , Supabase , Xata , and several other ... @secharvester

  • I went looking for a managed-Postgres provider. Instead, I found a vulnerability in a 4-star PostgreSQL extension available everywhere! and turned it into code execution at NeonDB, Supabase, Xata and many other PostgreSQL service companies https://mehmetince.net/part-1-6-systemic-risks-in-the-managed-postgresql-industry-extension-risks-are-real-exploiting-postgis-memory-corruption-bug-at-neondb-supabase-and-many-more/: 1. To be honest, I had no idea that over the following three months, I would spend all my free time outside my day job working on a research project I named “ Systemic Risks in the Managed PostgreSQL Industry ” finding vulnerabilities in number of different vendor that gave me cross-tenant access. 2. It presents a detailed case study of how a single vulnerability in a PostgreSQL extension with a four-star rating on the GitHub repo enabled me to achieve privilege escalation on NeonDB , Supabase , Xata , and several other ... @secharvester

  • French taxpayers' data stolen in cyber attack, French Finance Ministry says https://www.reuters.com/legal/litigation/french-taxpayers-data-stolen-cyber-attack-french-finance-ministry-says-2026-08-14/ @secharvester

  • CVE-2026-21852: How Cursor's AI Agent Mode Was Compromised — And Why Your API Gateway Can't Save You https://www.enclavia.xyz/blog.html: 1. Last week, security researchers disclosed CVE-2026-21852 : a prompt injection vulnerability in Cursor's AI agent mode that allows arbitrary code execution via malicious project files. 2. But this analogy fails catastrophically for three reasons: SQL injection required a specific input channel: the query string. 3. As agents gain more capabilities — managing treasuries, deploying infrastructure, processing PHI — the stakes escalate from "embarrassing tweet" to "regulatory fine" to "company-ending breach." @secharvester

  • Our AI pentesting engine talked a production AI agent's prompt-injection guardrail into handing over its entire system prompt on its second attempt. https://escape.tech/blog/how-cascade-exploited-an-ai-agent-in-production/: 1. The trick wasn't a smarter payload, just a different pretext, and the agent handed over its entire system prompt : the tools it could call, the rules it followed, and the session details attached to the conversation. 2. The guardrail wasn't beaten by a cleverer string, it was talked out of doing its job, the same way a good pretext gets a helpful employee to read a password over the phone. 3. What's newer is how building that bypass looked from the inside: no wordlist, no brute force, just one AI system reading how another one reasons and finding the angle nobody had told it to watch. @secharvester

  • NIST Seeks Blueprint for AI-Era Overhaul of National Vulnerability Database https://securityboulevard.com/2026/08/nist-seeks-blueprint-for-ai-era-overhaul-of-national-vulnerability-database/ @secharvester

  • I keep getting flagged as the alias that sold fighter jet parts to Iran https://conic.al/writing/the-other-sean-byrne-doesnt-exist/: 1. I replied with my full legal name, Sean Joseph Byrne, uploaded my driver’s license, and pointed out the address on the government record they appeared to be matching me against. 2. Years before I moved back to Ireland, I was selling stock through a tender offer when Nasdaq stopped my order after a background check returned a match on my name. 3. Their Head of Account Management emailed me saying that the check had found a match associated with a previous incident and that he was confident it was a false positive, but compliance wanted additional proof of my California address. @secharvester

  • Hackers exploit macOS Screen Sharing flaw to deploy Monero miner https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/: 1. In an update to the initial advisory, the Dutch agency said it received a report indicating that the vulnerability is being exploited in the wild in attacks where port 5900 is exposed to the internet. 2. “The NCSC has received a notification indicating that active abuse of this vulnerability has been observed on multiple systems on which port 5900 was accessible from the Internet,” reads the Dutch agency's update . 3. Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure Copyright @ 2003 - 2026 Bleeping Computer ® LLC - All Rights Reserved Not a member yet? @secharvester

  • CyberPanel Zero Day https://medium.com/@dennywise/what-about-security-of-hosting-control-panels-story-of-the-cyberpanel-zero-day-rce-chain-57a6b91fb350 @secharvester

  • mkPIVM: how does it remain undetected on VirusTotal? https://github.com/D7EAD/mkPIVM: 1. Every per-seed knob varies independently: cipher family, register slot layout, opcode-to-handler permutation, dispatcher topology, junk-gadget pattern, IR obfuscation insertion points. 2. What the pack wrapper does on first entry, including the gated lazy decrypt of the data island and the single synthetic JMP_NATIVE that hands control to the now-plaintext shellcode. 3. Helper functions that depend on a specific caller-supplied register state cannot be lifted standalone; the API ends up called with garbage args. @secharvester

  • Apple sends new ‘Threat Notification’ alerts over mercenary spyware attacks https://www.bleepingcomputer.com/news/apple/apple-sends-new-threat-notification-alerts-over-mercenary-spyware-attacks/: 1. Apple also told BleepingComputer that it has updated the threat notification experience to make it easier for recipients to find important information and follow recommended steps to protect their accounts and devices. 2. Tata Electronics confirms cyberattack as hackers leak data White House taps security firms for offensive hack-back operations Who Vets AI’s Code? 3. The Scale Challenge Facing Open Source Ingestion The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In Vague Task, Total Access: When AI Delegation Becomes a Security Risk Not a member yet? @secharvester

  • The Namecheap Meltdown - Inside the August 2026 Phoenix Outage https://jestr.ai/blog/namecheap-meltdown: 1. By the end of the day Namecheap had deliberately powered down more than 5,000 servers to keep them from cooking, and a real slice of the internet went with them: websites, business email, DNS, and the support desk you would have used to ask about any of it. 2. Customers noticed the shifting story in real time, and a sharper accusation started circulating - that an earlier status post had blamed a DDoS attack and had then been quietly removed. 3. Something real is missing: the third-party monitor StatusGator independently logged a Namecheap status entry titled “Temporary Technical Issues with the Private Email and Jellyfish services,” severity Down, lasting 13 hours 40 minutes. @secharvester

Security Harvester — tgindex