Next.js Windows RCE PoC https://github.com/rafabd1/CVE-2026-75604-poc
wat
https://spring.io/security/cve-2026-59270
Spring Security's embedded UnboundID LDAP server (
UnboundIdContainer) unconditionally registers an administrative credential and binds its listener to all available network interfaces.An attacker who could reach the LDAP listener port could authenticate using the well-known administrative bind DN, and then read or modify entries in the in-memory directory.
Partner: Open this for me?
Me: What are the magic words?
Partner: Please?
Me: ...
Partner: ...
Me: Squeamish...
Partner: ...
Me: Ossifrage.
Partner: looks up "Squeamish Ossifrage"
Partner: NERD!
Hope you're having a better day than the folks at Ziggo who pushed a remote firmware update that bricked eleven thousand customers' cable modems. https://tweakers.net/nieuws/251384/ziggo-vervangt-11000-modems-van-zakelijke-klanten-vanwege-technisch-defect.html
(in case you were wondering why we were offline for much of Monday...)
I've recently scanned DKIM keys for vulnerabilities, more extensively than previous scans. DKIM keys with the Debian OpenSSL bug are still very common. So are too-short RSA keys (quite a few 512 and even 384 bit keys, and *many* 768 bit, which is still difficult to break, but possible).
Also, a notable number publish a private key in their DKIM record. (This is only a problem if they actually use the same key elsewhere correctly.)
I tried disclosing things, but manual disclosure impractical for thousands of affected hosts and automated disclosure is difficult (plenty without security.txt, security@ often is rejected).
Replies to disclosures also show a common misunderstanding: People believe they are unaffected saying these keys are old and unused. This shows a fundamental confusion about how digital signatures work. Attackers don't care if you use insecure keys as long as they can use them.
Some stats for the latest scan: https://monitor.badkeys.info/dkim/2026-08-11-dkim-badkeys.html
Both Xcancel and Nitter have had cease and desist letter from Twitter. You can still follow Twitter account on Mastodon via account@bird.makeup and the like. Eg @c_c_krebs
this wild defcon talk is finally out
researchers created a fake defi startup, hired lazarus it workers, put them into a sandbox and recorded their tooling, workflows, and faces from inside the operation
starts at 5:46:09
https://www.youtube.com/live/_uYQr8hfpbI?t=20770
New on Insinuator: Part 1 of a four-part series on token theft in Microsoft Entra ID, accompanying ERNW White Paper 80.
The target is no longer the password or even MFA, but the token issued once authentication succeeds.
Part 1 covers the threat landscape and the techniques: direct token theft and PRT abuse, AiTM phishing, device code phishing, consent phishing, ClickFix and the ConsentFix family, plus where Microsoft's defense-in-depth strategy still leaves gaps.
By Niklas Kerner.
I guess throwing up a message like this is easier than optimizing your code
Modeling ELFs into SQL for execution https://fzakaria.com/2026/08/23/your-executable-is-a-sqlite-database