On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
Published two Apple disclosures today (links below). Both confirmed by Apple, both scheduled for "Faβ¦
AI tools, cybersecurity and development news aggregated from top sources β saved permanently with unique URLs.
On vendor disclosure timelines, bounty programme incentive misalignment, and the psychological contract
Published two Apple disclosures today (links below). Both confirmed by Apple, both scheduled for "Faβ¦
/sbin/ping -G sweepmax has no bounds check on macOS: deterministic BSS out-of-bounds write, confirmed by Apple
The -s flag in /sbin/ping has a maxpayload bounds check. -G sweepmax doesn't. An #ifndef __APPLE__ bβ¦
On-prem vs IaaS vs PaaS vs SaaS for self-hosted IAM (Keycloak case study)
submitted by /u/Will-from-CloudIAM [link] [comments]β¦
A stealth approach to Process Injection - EntryPoint Hijacking
submitted by /u/netbiosX [link] [comments]β¦
A year of Apple Security Bounty research β 16 closed findings, full disclosure
Spent 2024β2025 filing Apple Security Bounty reports. All 16 are now closed. I've written up every oβ¦
AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods
Recently saw a post '20 common AI-coded app vulnerabilities', and thought to myself that 20 is nice β¦
Sharing a hands-on lab inspired by the recent Canvas security incident β looking for collaborators
After reading about the recent Canvas incident: https://www.kqed.org/news/12083265/canvas-hack-instrβ¦
Dead.Letter (CVE-2026-45185) How XBOW found an unauthenticated RCE on Exim
submitted by /u/fede_k [link] [comments]β¦
The Algorithm Goes to War: Inside the AI Cyberweapon Revolution That Governments Cannot Stop
submitted by /u/monotvtv [link] [comments]β¦
Malicious Coding Agent Skills and the Risk of Dynamic Context | Datadog Security Labs
submitted by /u/RedTermSession [link] [comments]β¦
AI Vulnerability Research and the Fuzzer Era DΓ©jΓ Vu
submitted by /u/Void_Sec [link] [comments]β¦
I spent a weekend trying to get OpenClaw to leak my own personal data and it caught me immediately...
submitted by /u/choochilla44 [link] [comments]β¦