Skip to main content

Search

Items tagged with: security


RCE PoC for Redis 6.2.22, 7.4.9, 8.6.4, 8.8.0



🙏 New Blog Post

The Pope's official prayer app has an IDOR that lets anyone pull user data for all 719,517 accounts. One GET request per user. No auth check.

What's exposed:

  • Email addresses
  • Names
  • Country
  • Date of birth (they call it "borned_date" lol)
  • Account role (it's "PRAYER" for everyone, obviously)

Also found:

  • Signup endpoint returns the email verification token in the response body, so you can verify accounts without accessing the inbox
  • Their verification emails fail their own domain's authentication requirements

Reported January 3rd. Emailed 9 people. A journalist also contacted them. Zero responses. Still live six months later. Vow of silence I guess.

Full writeup: bobdahacker.com/blog/click-to-…

#InfoSec #BugBounty #ResponsibleDisclosure #IDOR #Security #CyberSecurity #Privacy #DataExposure #ClickToPray #Vatican #APISecurity


Vulnerability-Lookup 5.5.0 released



RE: ieji.de/@LorenzoAncora/1169476…

I checked, and, yes, there's an unfiltered option, along with some fine-grained choice of protection types.

If only the UK was still an EU member....

(who am I kidding, I'd still run my own recursing resolver anyway)

#dns #browser #security #privacy #eu #europe


DNS4EU is a privacy-first DNS resolver by the European Union and Whalebone, available for free to all European citizens under the GDPR.

The service is anonymized and offers child protection, ad blocking, DNSSEC, IPv4, IPv6, DoH, DoT, and anycast, ensuring excellent privacy and minimal latency regardless of your location.

Your browsing data stays within the EU and is protected from cyber threats without being monetized!

joindns4.eu

#dns #browser #security #privacy #eu #europe



#OpenAI says its #AI went #rogue and launched 'unprecedented' cyber-attack

source: bbc.com/news/articles/c3ek3gvd…

The #ChatGPT-maker said its agent - an AI #system which can operate alone after human instruction – was being tested in a controlled environment but, after finding weaknesses, was able to escape the test limits.They targeted #Hugging Face, one of the world's largest hubs for sharing AI models, gaining access to some internal company systems.


#news #cybersecurity #technology #test #security #economy #control #internet #problem #fail #hack #cyberattack #attack #skynet


New, exclusive, by me: LG to Ban Residential Proxy Providers from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV.

krebsonsecurity.com/2026/07/lg…

#smarttv #lg #residentialproxies #spur #security


DNS4EU is a privacy-first DNS resolver by the European Union and Whalebone, available for free to all European citizens under the GDPR.

The service is anonymized and offers child protection, ad blocking, DNSSEC, IPv4, IPv6, DoH, DoT, and anycast, ensuring excellent privacy and minimal latency regardless of your location.

Your browsing data stays within the EU and is protected from cyber threats without being monetized!

joindns4.eu

#dns #browser #security #privacy #eu #europe



We all know the APT numbers for #FancyBear and #CozyBear — #APT28 and #APT29. Both are attributed to Russian #intelligence. #APT1 through 27 are all from #China. Only the #EquationGroup doesn’t have an official APT number? Wake up, you sleeping sheep—we’re being thoroughly taken for a ride here. The Equation Group—run by the #NSA or #CIA — is probably the most dangerous group in the world, and yet it’s the one that doesn’t appear under any number on the #APT list? Who are you trying to fool here when it comes to #cybersecurity?

see: attack.mitre.org/groups/index.…

#news #conspiracy #snowden #surveillance #spy #usa #russia #thread #danger #warning #fail #security #cybersecurity #internet #online #hack #hacker #software #exploit #cyberattack #cybercrime #world #worldorder #censorship #deepstate


EasyOptOuts and 404 Media discovered that Apple's Hide My Email, a popular iCloud feature that allows users to receive emails without revealing their personal email address, has a vulnerability which makes the real email address publicly discoverable.
The vulnerability has been reported a year ago and is still present.💔

Source: mashable.com/tech/apple-hide-m…

#privacy #apple #cloud #email #security #software #vulnerability #exploit #tracking #hacking #mac #macos #ios #iphone #communication


Stegano 2.5.0: reversible data hiding technique based on histogram shifting


Stegano 2.5.0 is out! 🎉

This release adds a reversible data hiding technique based on histogram shifting (Ni et al., IEEE TCSVT 2006): unlike LSB, the original cover image can be recovered pixel-for-pixel after the hidden message is extracted. Includes a new stegano-rdh command line tool.

Thanks to Eesh Saxena for the contribution!

github.com/cedricbonhomme/Steg…


🚀 Vulnerability-Lookup 5.4.0 is out — and it speaks VEX!



GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos



If you use windows. Stop

youtube.com/shorts/kOoP4BSATJs

#security #privacy #windows #microsoft


Vulnerability-Lookup 5.3.0 released



Politician who investigated spyware abuses had his phone hacked with Pegasus spyware



Vulnerability Report - June 2026



RustDuck: An In-Depth Analysis of a Two-Stage Botnet



A new KEV Catalog built from real-world exploitation data !


We are excited to share the result of a fruitful collaboration with The Shadowserver Foundation: a new Known Exploited Vulnerabilities (KEV) Catalog (BCP-07 compliant) built directly from their global honeypot telemetry.

Most KEV catalogs tell you what is being exploited. This one is grounded in observed exploitation attempts captured across Shadowserver's worldwide honeypot sensor network. When a vulnerability is exploited against one of their honeypots, it becomes an attributable, structured GCVE-EU BCP-07 KEV assertion, complete with evidence typing (honeypot), exploitation signals (in_the_wild_attempts), and timestamps indicating when exploitation was first and last observed.

A huge thank-you to the Shadowserver team, and especially to Piotr Kijewski, for their support and collaboration.


We Can Still Stop California’s 3D Printer Surveillance Scheme

eff.org/deeplinks/2026/06/we-c…

#tech #technology #news #technews #security #privacy #3dprinting #Surveillance


🚨 They are bringing back #ChatControl 🚨

Metsola doesn't understand that no means no.

Discussion is scheduled for Monday, so act now: fightchatcontrol.eu/

#No2Surveillance #Privacy #Security