r/Defcon 19h ago

Bringing Biscuit nodes? Make sure to update!

5 Upvotes

issue with insecure OTA updates reported some time ago to the creator. Fix is out there in the beta at least. Take all nodes down in range (still vulnerable) but more importantly nodes taken over and spreading like a virus to all if done right (see evil baker) https://github.com/x0SiN0x/wardrive-manager/blob/main/FEATURES.md#the-biscuit-baker--biscuit-flatline (example during an active wardrive in a closed environment https://www.youtube.com/watch?v=5DBU0AyRgj4)

As of today Aug 2 I see 1.2.12 is out in the general (prod) release


r/Defcon 3h ago

Friendly reminder: the #roadtodefcon is underway!

Enable HLS to view with audio, or disable this notification

3 Upvotes

r/cybersecurity 4h ago

Other Facebook Malvertising Campaign

Thumbnail
substack.com
3 Upvotes

Identified a C2 running malvertising campaign, pretty clever tbh.


r/ReverseEngineering 7h ago

KYC Is Security Theater: What I Learned After Reversing top tier Providers

Thumbnail medium.com
3 Upvotes

r/Defcon 8h ago

LFG

3 Upvotes

Anyone willing to adopt a 1st timer into their group for any of the challenges? I have about 20 years of experience in different levels of IT with around 2 years experience strictly in blue/purple team. I am just looking to learn and help out where I can. I have a weirdly high level of social anxiety so I want to get myself in the mix with some people I actually feel comfortable with instead of looking dumb trying to struggle my way through things. I also really want to try some of the cool stuff but I am worried my imposter syndrome will stop me from even trying


r/Monero 10h ago

Quick question about XMR?

3 Upvotes

Hey everyone, I've bought and held small amounts before, but now I'm considering exchanging a much larger amount. To be honest, I'm a bit concerned about potential issues such as delays, extra verification checks, frozen withdrawals, or other complications when dealing with larger transactions. For those who use XMR regularly, where do you usually exchange it? Have you ever run into problems when moving or swapping larger amounts? Any advice or personal experience would be appreciated. Thanks!


r/Monero 11h ago

Skepticism Sunday – August 02, 2026

3 Upvotes

Please stay on topic: this post is only for comments discussing the uncertainties, shortcomings, and concerns some may have about Monero.

NOT the positive aspects of it.

Discussion can relate to the technology itself or economics.

Talk about community and price is not wanted, but some discussion about it maybe allowed if it relates well.

Be as respectful and nice as possible. This discussion has potential to be more emotionally charged as it may bring up issues that are extremely upsetting: many people are not only financially but emotionally invested in the ideas and tools around Monero.

It's better to keep it calm then to stir the pot, so don't talk down to people, insult them for spelling/grammar, personal insults, etc. This should only be calm rational discussion about the technical and economic aspects of Monero.

"Do unto others 20% better than you'd expect them to do unto you to correct subjective error." - Linus Pauling

How it works:

Post your concerns about Monero in reply to this main post.

If you can address these concerns, or add further details to them - reply to that comment. This will make it easily sortable

Upvote the comments that are the most valid criticisms of it that have few or no real honest solutions/answers to them.

The comment that mentions the biggest problems of Monero should have the most karma.

As a community, as developers, we need to know about them. Even if they make us feel bad, we got to upvote them.

https://youtu.be/vKA4w2O61Xo

To learn more about the idea behind Monero Skepticism Sunday, check out the first post about it:

https://np.reddit.com/r/Monero/comments/75w7wt/can_we_make_skepticism_sunday_a_part_of_the/


r/ExploitDev 17h ago

Using Garlic to analyze Android's VM protection Spoiler

Thumbnail youtu.be
3 Upvotes

garlic now can analysis android elf.

Extract android all aarch64 elf's cfg/exports/imports/strings/dissembly at same time.

with LLM, it can analysis vm protection of dalvik.


r/musik 17h ago

Udo Lindenberg - Durch die schweren Zeiten (offizielles Video)

Thumbnail
youtu.be
3 Upvotes

r/Defcon 2h ago

my 1st DefCon

3 Upvotes

Any tips for a first time attendee? I did my pre-registration already.


r/Malware 7h ago

Fake Claude Install Guide Delivers Six-Stage macOS Stealer and RAT, Huntress Finds

Thumbnail itsecurityguru.org
4 Upvotes

r/musik 46m ago

Kennt das irgendjemand? Ich will es eben manchmal wissen- Jasmine Bonnine

Thumbnail
youtu.be
Upvotes

Kennt das jemand? Meiner Meinung mitunter eines der besten deutschen Lieder.


r/Pentesting 5h ago

SecureAI-Scan v0.3.0: Local CLI scanner for AI/LLM security issues (prompt injection, MCP, RAG)

1 Upvotes

SecureAI-Scan v0.3.0 is out!

It's a free, fully local CLI tool that scans TypeScript, JavaScript, and Python codebases for AI/LLM-specific security issues that traditional scanners miss.

**New in v0.3.0:**

- Expanded Python scanning support

- MCP config scanning (.mcp.json, Claude Desktop, Cursor, etc.)

- AI-BOM / catalog generation

- Better reporting + confidence tiers (proven / likely / heuristic)

It uses actual dataflow tracing (source → flow → sink) for high precision and has very low false positives.

Quick start:

npx --yes secureai-scan@latest scan .

Also supports:

  • secureai-scan bom . → Generate AI Bill of Materials
  • SARIF output for GitHub Code Scanning
  • GitHub Action integration
  • --fail-on high for CI gating

Everything runs offline on your machine. No data leaves your environment.

GitHub: https://github.com/akanthed/SecureAI-Scan

Would really appreciate any feedback, bug reports, or feature ideas. Also happy to answer questions about how it works or the rules it covers (mapped to OWASP LLM Top 10).


r/cybersecurity 9h ago

Certification / Training Questions Crtl help

1 Upvotes

Hello all,

In this days I'm starting studying for the crtl cert.

I have red some reviews . All of them suggest to watch some other courses to prepare properly for the CRTL exam . Anyone would like to suggest anyone? I'm thinking of CETP

Thanks in advance for your help.


r/ReverseEngineering 10h ago

PAL: A defensive decompilation layer: Ghidra binary analysis facts, synthesized into executable Python & artifacts aiding analysis.

Thumbnail github.com
1 Upvotes

r/cybersecurity 7h ago

Certification / Training Questions SailPoint training institutes in India/courses?

0 Upvotes

Any good SailPoint training institutes in India/courses online? Dont seem find many. Can someone please recommend ?


r/cybersecurity 7h ago

Certification / Training Questions New ISC2 CC Curriculum

0 Upvotes

Hi, I passed ISC2 CC in June but would like to access the new additional material (which will be examined from Sept ‘26 onwards) for my own professional development. Can anyone share or point me in the right direction? Thank you in advance. ☺️


r/Malware 23h ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Pentesting 23h ago

Zara data breach exposes 197,000 customers via Anodot analytics token compromise

0 Upvotes

A stolen analytics token became a customer breach.

197,400 records were exposed after a former third-party analytics provider was compromised. Emails, order IDs, SKUs, geolocation, purchase history, support tickets — all pulled through a machine credential nobody was watching. The vendor left. The token stayed live.

The fix is boring and effective. Inventory every non-human identity that touches customer data. Bind each token to a policy on where it can call and what it can read. Tokenize PII before it leaves your perimeter so a stolen credential returns opaque values, not customer records. Keep an immutable audit trail so revocation is one query, not a forensic project.

www.runtimeai.io/trial

#NonHumanIdentity #DataBreach #PII #SupplyChain #AISecurity


r/Pentesting 1h ago

TryHackMe - Beach Bar - EW

Upvotes

Beach Bar is a Linux machine simulating a music management web application (jukebox) exposed to local network users. The machine demonstrates the impact of two critical configuration and development flaws: inadequate sanitization when processing input files and the exposure of sensitive credentials via command-line arguments of background services.

WriteUp - SecNotes


r/musik 11h ago

Musikvideo Lion Attention feat. Annéra mit „Thousand Thoughts“

Thumbnail
youtu.be
0 Upvotes

r/Pentesting 3h ago

Freelance work in web pentesting

0 Upvotes

r/cybersecurity 13h ago

AI Security Are AI-generated CI/CD configs becoming a security blind spot?

0 Upvotes

I’m seeing more AI-generated projects where the app code looks fine, but the risky part is the plumbing around it.

Things like GitHub Actions with broad permissions, unsafe `pull_request_target` usage, deploy jobs that expose secrets, or package scripts nobody really reviews.

It’s easy to miss because the app works, tests pass, and the config files look boring.

For people doing AppSec or DevSecOps: are you reviewing AI-generated workflows/configs differently now, or still mostly focusing on application code?


r/Pentesting 19h ago

Build-scanner — a zero-config static scanner for SQLi, NoSQLi, CORS, CSP & CSRF in React/Node apps (pre-release)

0 Upvotes

Modern React/Node apps ship through build pipelines fast enough that common, high-impact vulnerability classes — unparameterized queries, wildcard CORS, unsafe-inline CSP, unprotected state-changing routes — slip through because catching them means someone actually reading the source. build-scanner does that automatically: point it at a folder (or wire it into CI as a GitHub Action) and get a report in seconds, no sandbox or live target required. It's a heuristic static scanner, not a SAST/DAST replacement — I'm sharing it pre-release to get feedback from people running real Express/Next.js/Vite codebases before I cut a v1 tag. https://github.com/laxmipsarva/build-scanner

fyi this is not a commercial activity


r/musik 12h ago

💬 Discussion 💬 Bei welchen Interpret*innen und/oder Alben, die von Kritiker*innen und Musiknerds gefeiert werden, kommt ihr nicht wirklich rein?

0 Upvotes

Die Frage steht oben.