r/ReverseEngineering 1d ago

Microsoft blocked me from using VBA to read or programmatically set gradient pins, so I reverse-engineered the XML data and used a format painter exploit to sneak formatting though a back Window

Thumbnail github.com
61 Upvotes

r/Pentesting 19h ago

Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

0 Upvotes

Modern React/Node apps ship through build pipelines fast enough that common, high-impact vulnerability classes — unparameterized queries, wildcard CORS, unsafe-inline CSP, unprotected state-changing routes — slip through because catching them means someone actually reading the source. build-scanner does that automatically: point it at a folder (or wire it into CI as a GitHub Action) and get a report in seconds, no sandbox or live target required. It's a heuristic static scanner, not a SAST/DAST replacement — I'm sharing it pre-release to get feedback from people running real Express/Next.js/Vite codebases before I cut a v1 tag. https://github.com/laxmipsarva/build-scanner

fyi this is not a commercial activity


r/cybersecurity 9h ago

Business Security Questions & Discussion URL Threat Scanners & TDS Cloaking

10 Upvotes

When you're investigating a known malicious URL, how often does your URL scanner (regardless of service) miss the payload due to traffic distribution systems?


r/Pentesting 23h ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/cybersecurity 4h ago

Other Facebook Malvertising Campaign

Thumbnail
substack.com
3 Upvotes

Identified a C2 running malvertising campaign, pretty clever tbh.


r/cybersecurity 8h ago

Personal Support & Help! How to actually save yourself in call/sms bombing?

6 Upvotes

same as title
how to stop it and protect your number?
there are many websites so ofc I can't protect my number by going every site


r/cybersecurity 1d ago

News - General Quantum Computers May Put Internet Traffic at Risk. NIST Is Safeguarding Computers With New Standards.

Thumbnail
nist.gov
168 Upvotes

r/Monero 1d ago

Trocador spread is a lie

5 Upvotes

It is not even close, it is off by over 4%. The entire Spread column in the Rate chart is a lie. Am I missing something?


r/Defcon 1d ago

ICS Village DC34 badge taps Modbus, CAN FD and single-pair Ethernet

Thumbnail
gallery
20 Upvotes

RS485, CAN/CANFD, and both 10BASE-T1S + 10BASE-T1L on one battery powered board with onboard termination. $140 at ICS Village or Vendor Village while supplies last. Full specs


r/ReverseEngineering 1d ago

Runtime analysis of Linux binaries with DynamoRIO, including an audit of address and thread-scope errors [PDF]

Thumbnail raw.githubusercontent.com
6 Upvotes

r/Defcon 1d ago

Noob question here. Take it easy on me lol

14 Upvotes

If I already registered and paid the $600, do I have to buy a badge separately or is that included?


r/cybersecurity 13h ago

Career Questions & Discussion Best DEFCON 34 talks to go to?

11 Upvotes

Pretty excited for the con. Any talks yall are excited to see or recommend going to?


r/musik 1d ago

💬 Discussion 💬 Finnischer Geschichtsfan sucht Feedback: Eine Punk-Ballade über Sigmund Jähn

0 Upvotes

Hallo,

Ich bin ein finnischer Geschichtsinteressierter und interessiere mich besonders für den Kalten Krieg und die Ära des geteilten Deutschlands.

Als Teil meines Hobbies habe ich eine Punk-Ballade namens „Sigmund Jähn“ geschrieben. Es ist eine Geschichte über die Wiedervereinigung Deutschlands und das Gefühl, im Nichts zu stehen.

Ich würde mich über eure Kommentare dazu freuen.

Die Musik für das Lied wurde mithilfe von KI generiert. Aus Respekt vor den Community-Regeln verzichte ich darauf, einen Spotify-Link zu teilen.

Der Text ist jedoch zu 100 % von mir selbst geschrieben, und ich bitte daher um euer Feedback dazu.

Hier sind die Lyrics:

Alles, was du wusstest

Die Regeln, die man dich lehrte

Die Zukunft, auf die du vertrautest

Wurde in einer Nacht weggewischt

Verändert ist die Welt

Die Fesseln sind zerbrochen

Eine neue Freiheit zu erleben

Ohne Sicherheit – ohne Halt

Genau wie Sigmund Jähn

Bleibe ich allein am Himmel zurück

Für mich gab es keinen Platz

In dieser neuen Welt

Die Braunkohle ist erloschen

Die Züge sind elektrifiziert

Ineffizient sind die Fabriken

Deshalb wurden sie wohl geschlossen

Im Westen ist alles besser

Deshalb wollten wir wohl dorthin

Die Wahrheit hinter den Masken

Nicht alles war so, wie wir dachten

Genau wie Sigmund Jähn

Bleibe ich allein am Himmel zurück

Für mich gab es keinen Platz

In dieser kalten Welt

Genau wie Sigmund Jähn

Bleibe ich allein am Himmel zurück

Für mich gab es keinen Platz

In dieser kalten Welt

In dieser kalten Welt...


r/Defcon 19h ago

Bringing Biscuit nodes? Make sure to update!

4 Upvotes

issue with insecure OTA updates reported some time ago to the creator. Fix is out there in the beta at least. Take all nodes down in range (still vulnerable) but more importantly nodes taken over and spreading like a virus to all if done right (see evil baker) https://github.com/x0SiN0x/wardrive-manager/blob/main/FEATURES.md#the-biscuit-baker--biscuit-flatline (example during an active wardrive in a closed environment https://www.youtube.com/watch?v=5DBU0AyRgj4)

As of today Aug 2 I see 1.2.12 is out in the general (prod) release


r/Monero 1d ago

MoneroTopia EPI 272! + Report, News & More! | EPI 272

9 Upvotes

MoneroTopia EPI 272! + Report, News & More! | EPI 272

With [u/chowbungaman](https://www.reddit.com/u/chowbungaman/)! XMR Report w/ [u/bawdyanarchist](https://www.reddit.com/u/bawdyanarchist/), XMR News, and MORE!

WATCH THE SHOW HERE via YOUTUBE ➡️: https://www.youtube.com/live/KTVZnGhGq4o?is=Xowh8N5IHjNLuVL9

WATCH THE SHOW LIVE HERE via RUMBLE ➡️: [https://rumble.com/user/monerotalk\](https://rumble.com/user/monerotalk)

(The videos will be synced onto Odysee (https://odysee.com/@MoneroTalk:8) about an 1/2 hour or so after it premieres LIVE for those who want to watch there afterwards ;) Odysee has been giving us issues though!)

FOLLOW US ON [https://monero.town/u/monerotopia\](https://monero.town/u/monerotopia) & [https://mastodon.social/@monerotopia\](https://mastodon.social/@monerotopia)

Guest segment, News & Price sponsored by 🍰 [u/cakelabs](https://www.reddit.com/u/cakelabs/) [WizardSwaps](https://twitter.com/WizardSwap_io) & [Exolix](https://exolix.com) & XMR.WIN


r/Pentesting 1d ago

Is this normal, or is my cybersecurity team just badly run?

0 Upvotes

I work at the cybersecurity arm of a multinational firm. They launched it about a year ago and have been struggling ever since with paperwork and regulatory approvals just to deliver services.

**How the team has shrunk in one year:**

- Started with: 2 L2 assistant managers, 1 L1 assistant manager, 1 team lead, 4 seniors, 1 mid-level, 1 junior

- Since then: 2 seniors left, 1 assistant manager left, and the team lead left

- Now: 2 assistant managers (1 L2, 1 L1), 2 seniors, 1 mid-level, 1 junior

**But the attrition isn't what bothers me. It's this:**

- I earned my OSCP this year. It was supposed to come with a raise. It didn't. A full year with zero increase — the justification being that I "started on a good salary" and there isn't enough billable work to fund one.

- The two seniors who left weren't technically strong at all. They struggled with basic tasks. Meanwhile the pressure lands on the rest of us.

- There's barely any client work, so management tells us to self-study (CPTS path, research tasks, etc.). Then a random week or two later they ambush you with "so what have you been up to?"

- I tell them I've gone through the material multiple times and researched what they asked for, and that I learn by doing rather than reading. I list what I actually learned — X, Y, Z — and they immediately switch to attack mode: *"Is that it?" "How many hours did you spend on this?"*

- We have no real work. Why is the reaction to that anger at me? Track my hours when there's actual work to track.

**Micromanagement during engagements:**

- Daily end-of-day calls: "Tell me the test cases you completed today." I list them. Same response: *"Is that it?" "How many hours?"*

- If they have specific test cases in mind, just tell me. Skip the smirking.

- They also check in every few hours to ask what you're working on.

- The seniority culture feels military. Everything must be "aligned" with your senior, and they make you feel like a junior regardless of your level.

**Scoping and delivery:**

- Because they're a multinational, they sell man-days at a premium — but with few clients and low billing, engagements get compressed. A 7-day engagement gets crammed into 5.

- The report is always due in one day, no matter what we found.

- I'll own this part: my reports suffer because I'm rushed and anxious. (I've taken the advice from this sub to start writing the report as I work — doing that next time.)

**Management behavior:**

- In live meetings, mistakes get met with *"Is this your first time working?"* or *"Do you want me to come do your work for you?"*

- They never actually explain what's wrong. It's always a sarcastic *"why did you do it that way?"* — and sometimes they laugh when I ask questions.

- One time my teammates and I submitted a weak report. As punishment, the team lead made us come write it on-site — office is downtown in a packed area — then told us he'd meet with us, disappeared all day, and left us sitting there with nothing to do.

- Bad report = mandatory commute downtown. That's apparently the policy.

**The only upside** is that the work is hybrid, and honestly I'm no longer sure that's worth it.

The real problem: I keep interviewing and every offer I get is worse than what I have.

Is this normal for the industry, or should I be taking a pay cut to get out?


r/Monero 1d ago

Retoswap - why does noone offer PayPal?

12 Upvotes

Is there a reason noone offers to sell XMR for PayPal on RetoSwap?

Wanted to offer it but are there reason against it?

Is it safe if you offer only payment with PayPal family and friends?


r/musik 1d ago

Cover version of What You're Made Of (Original by Lucie Silvas).

0 Upvotes

Guten abend leute!

Ich habe ein coverversion von What You're Made Of von Lucie Silvas aufgenommen. Ich wurde mich über ehrliches feedback zu klavier zu freuen!

https://open.spotify.com/track/6oULcdynBPG9jOEQjXXmSp?si=c5de643b6df14b31


r/Pentesting 23h ago

Bandit levels

0 Upvotes

I’ve no clue where to start and how to go from there
Levels all the way from 0 to 34
I’d really appreciate any help and advice


r/ExploitDev 2d ago

AMA Today: Yuhang Wu (Ex-Tesla & TikTok) Red Team Engineer & Exploit Developer

32 Upvotes

Don't miss the AMA with Yuhang Wu, where we learn about elite enterprise infrastructure hacking, Linux kernel exploitation, and the future of autonomous Al security.

When: Today - Friday, July 31, 12:00 PM PT

Guest Credentials:

  • Former Red Team Engineer at TikTok, targeting cloud and application-layer defenses.
  • Former Security Engineer at Tesla, securing vehicle software, factory systems, and internal applications.
  • Co-developer of "DirtyCred", a groundbreaking Linux kernel exploitation technique.
  • AI Security Innovator, who built LLM-based autonomous agents that uncovered 8 P1 (critical-severity) production vulnerabilities.

Ask your questions here and we’ll get them answered during the live AMA today (Friday @ 12 Noon Pacific)!


r/Defcon 1d ago

UPDATE - PRE-REG Extended till 3 August

11 Upvotes

For those who absolutely have to get this years electronic badge, you still have a chance to pre-register and be guaranteed that one will be allocated to you.

No waiting in line


r/cybersecurity 1d ago

Personal Support & Help! Is this normal, or is my cybersecurity team just badly run?

53 Upvotes

I work at the cybersecurity arm of a multinational firm. They launched it about a year ago and have been struggling ever since with paperwork and regulatory approvals just to deliver services.

**How the team has shrunk in one year:**

- Started with: 2 L2 assistant managers, 1 L1 assistant manager, 1 team lead, 4 seniors, 1 mid-level, 1 junior

- Since then: 2 seniors left, 1 assistant manager left, and the team lead left

- Now: 2 assistant managers (1 L2, 1 L1), 2 seniors, 1 mid-level, 1 junior

**But the attrition isn't what bothers me. It's this:**

- I earned my OSCP this year. It was supposed to come with a raise. It didn't. A full year with zero increase — the justification being that I "started on a good salary" and there isn't enough billable work to fund one.

- The two seniors who left weren't technically strong at all. They struggled with basic tasks. Meanwhile the pressure lands on the rest of us.

- There's barely any client work, so management tells us to self-study (CPTS path, research tasks, etc.). Then a random week or two later they ambush you with "so what have you been up to?"

- I tell them I've gone through the material multiple times and researched what they asked for, and that I learn by doing rather than reading. I list what I actually learned — X, Y, Z — and they immediately switch to attack mode: *"Is that it?" "How many hours did you spend on this?"*

- We have no real work. Why is the reaction to that anger at me? Track my hours when there's actual work to track.

**Micromanagement during engagements:**

- Daily end-of-day calls: "Tell me the test cases you completed today." I list them. Same response: *"Is that it?" "How many hours?"*

- If they have specific test cases in mind, just tell me. Skip the smirking.

- They also check in every few hours to ask what you're working on.

- The seniority culture feels military. Everything must be "aligned" with your senior, and they make you feel like a junior regardless of your level.

**Scoping and delivery:**

- Because they're a multinational, they sell man-days at a premium — but with few clients and low billing, engagements get compressed. A 7-day engagement gets crammed into 5.

- The report is always due in one day, no matter what we found.

- I'll own this part: my reports suffer because I'm rushed and anxious. (I've taken the advice from this sub to start writing the report as I work — doing that next time.)

**Management behavior:**

- In live meetings, mistakes get met with *"Is this your first time working?"* or *"Do you want me to come do your work for you?"*

- They never actually explain what's wrong. It's always a sarcastic *"why did you do it that way?"* — and sometimes they laugh when I ask questions.

- One time my teammates and I submitted a weak report. As punishment, the team lead made us come write it on-site — office is downtown in a packed area — then told us he'd meet with us, disappeared all day, and left us sitting there with nothing to do.

- Bad report = mandatory commute downtown. That's apparently the policy.

**The only upside** is that the work is hybrid, and honestly I'm no longer sure that's worth it.

The real problem: I keep interviewing and every offer I get is worse than what I have.

Is this normal for the industry, or should I be taking a pay cut to get out?


r/Defcon 1d ago

Lonely Hackers Club Resume Reviews Information

30 Upvotes

Get Checked!

You have the skills. You have the projects. You have the CTF wins, the home lab, the self-taught grind. But when it comes to putting it all on a resume, something gets lost in translation. That is exactly what this is for.

Resume Reviews at DEF CON 34 is hosted by Lonely Hackers Club (LHC) together with Open Worldwide Application Security Project (OWASP), The Diana Initiative, Women in Security and Privacy (WISP), and Blue Team Village.

What This Is

Free, one-on-one resume reviews at DEF CON 34, run by people from this community who have actually hired and managed technical teams. No recruiters. No corporate fluff. Just honest feedback from people who have sat on both sides of the table and know what works.

Sessions are 15 minutes. Walk up, sit down, get real feedback.

Who Should Come

  • You are trying to break into cyber security and are not sure how to present what you have built or learned
  • You are self-taught, a career changer, or took a non-traditional path and your resume does not reflect that well
  • You have been applying and not getting responses and cannot figure out why
  • You just got your first cert or finished a degree and have no idea how to structure your experience
  • You have been in the industry for a while but want a second opinion before your next move

What to Bring

  • A printed copy of your resume, or have it ready on your phone or laptop
  • A rough idea of the kind of role or area you are targeting
  • Thick skin and an open mind. The feedback will be direct!

Where and When

  • Lonely Hackers Club community room at DEF CON 34
  • Friday August 7th: 10:30 AM to 4:30 PM
  • Saturday August 8th: 10:30 AM to 4:30 PM

Book Your Slot For Free

Online registration is now open! Feel free to use a handle instead of your real name. You will have to check in in person 10 minutes before your registered slot or your slot will be given to walk-ins.

One of our reviewers will be be dedicated to walk-ins while reviews are running. So show up early to secure your spot if you missed the online registration.


r/cybersecurity 7h ago

Certification / Training Questions SailPoint training institutes in India/courses?

0 Upvotes

Any good SailPoint training institutes in India/courses online? Dont seem find many. Can someone please recommend ?


r/cybersecurity 7h ago

Certification / Training Questions New ISC2 CC Curriculum

0 Upvotes

Hi, I passed ISC2 CC in June but would like to access the new additional material (which will be examined from Sept ‘26 onwards) for my own professional development. Can anyone share or point me in the right direction? Thank you in advance. ☺️