DEV Community

#infosec

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Critical Gitea RCE Under Active Exploitation: CVE-2026-60004 Turns a Signup Form Into Shell Access

Critical Gitea RCE Under Active Exploitation: CVE-2026-60004 Turns a Signup Form Into Shell Access

Comments
5 min read
I Set Up a Fake Internet to Catch a Trojan: Analyzing FlexenseActivator.exe

I Set Up a Fake Internet to Catch a Trojan: Analyzing FlexenseActivator.exe

Comments
6 min read
The safety penalty: Reclaiming operational sovereignty in the age of AI

The safety penalty: Reclaiming operational sovereignty in the age of AI

1
Comments
1 min read
Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February

Oracle WebLogic Proxy Plug-in Flaw Hits CISA KEV: CVSS 10.0, Unauthenticated, Exploited Since February

Comments
5 min read
Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins

Keycloak CVE-2026-18963: Unauthenticated Password Reset Hands Over Any Account, Including Admins

Comments
5 min read
Why Most ML Firewalls Fail (And How We Fixed It with a Honeypot Feedback Loop)

Why Most ML Firewalls Fail (And How We Fixed It with a Honeypot Feedback Loop)

Comments
4 min read
Three Russian Clusters Are Phishing Auth Flows, Not Passwords: OAuth, App Passwords, and WhatsApp Device Linking

Three Russian Clusters Are Phishing Auth Flows, Not Passwords: OAuth, App Passwords, and WhatsApp Device Linking

Comments
5 min read
Rust Build Scripts Executed Malware From a Crate With 245 Million Downloads

Rust Build Scripts Executed Malware From a Crate With 245 Million Downloads

Comments
5 min read
Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure

Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure

Comments
4 min read
Burp Suite: What It Is, Why We Use It, and How It Works

Burp Suite: What It Is, Why We Use It, and How It Works

Comments
2 min read
Prompt Injection in Copilot Chatbot — Phishing via Client-Controlled Context

Prompt Injection in Copilot Chatbot — Phishing via Client-Controlled Context

Comments
5 min read
The GTA VI leak isn't really about GTA VI — it's an extortion playbook

The GTA VI leak isn't really about GTA VI — it's an extortion playbook

Comments
3 min read
wazuh-siem-sysmon-project

wazuh-siem-sysmon-project

Comments
6 min read
The SolarWinds Attack: When One Compromised Vendor Became a Supply-Chain Crisis

The SolarWinds Attack: When One Compromised Vendor Became a Supply-Chain Crisis

Comments
2 min read
My home computers

My home computers

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.