Content Paint

security research

CVE for “Damn Vulnerable Web Application” rejected after troubling, bemusing hackers

"To the 731 people who have DVWA exposed to the internet, I apologise for CVE-2023-39848, I recommend you temporarily remove them from the internet till I can create a patch."

22,600+ emails = 599 vulnerabilities. Security disclosure triage is HARD

Security researchers regularly chafe at the deafening silence when they report a critical vulnerability in software: White Hats simply wanting to help organisations fix their cybersecurity all too often still find themselves being ignored – or worse, threatened with legal action when trying to help publicly exposed organisations that have not

ChatGPT used to create elusive "polymorphic" malware

The ChatGPT API "bypasses every content filter there is"

Landmark Arm Morello CPU now available for testing

New CHERI instruction set allegedly eliminates almost all memory safety issues.

What's all the fuss about Microsoft "Symbols"?

"Releasing symbols is a step towards making Office easier for researchers to audit."

Department of Justice: We won't sue "good faith" hackers, promise, maybe

Don't go wild on Shodan just yet though...

Thousands of AWS customers leaking data CIDR block scan reveals

"If you open a service to the world, at least use decent authorization and authentication"

Search the site

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.